| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This comment adds a second associated type `KeyPair` to ToEncodableKey. For a
`ToEncodableKey` which represents a (secret) KeyPair, this type is Self. For
a `ToEncodableKey` which represents a public key, this is the `ToEncodableKey`
whose `Key` is the pair of which this is the public part.
This is essentially a "type level pointer" from the ToEncodableKey for a
public key to the ToEncodableKey for its secret key.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This commit adds a new method `get_keypair_specifier()` to `KeySpecifier`.
This method is used to indicate when one KeySpecifier (e.g. `KP_hs_id`) is the
public part of another keypair (e.g. `KS_hs_id`). It will return the
containing keypair in this case, and `None` otherwise.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
FooKeypairSpecifier` instances
This adds the following trivial `From` instances:
- tor_hsservice: impl From<&HsIdPublicKeySpecifier> for HsIdKeypairSpecifier
- tor_hsservice: impl From<&BlindIdPublicKeySpecifier> for BlindIdKeypairSpecifier
- tor_hscrypto::pk: impl From<HsBlindIdKeypair> for HsBlindIdKey
- tor_llcrypto::pk::ed25519: impl From<ExpandedKeypair> for PublicKey
- tor_keymgr::mgr: impl From<TestKey> for TestPublicKey
- tor::hscrypto::pk: impl From<HsIdKeypair> for HsIdKey
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Ticket #1509 will probably get rid of this constant,
but for now we may as well put it in one place.
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Here we make sure that we can actually skip over other proxy formats
in the future.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
Renamed address to tcp_address, and made it optional, so that later
we can have a unix_path, etc.
On deser side, add support for unrecognized listener types.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
This is done so that we can make "not authenticated" a non-internal
error, under the theory that someday unauthenticated connections
might be exposed.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This belongs in a spec, but adding things to a spec is slow and
fraught. Instead we'll put it here for now and move it later.
There are some XXXXs about "finalizing" the design that we need to
resolve before we can merge !2373 and implement stream creation in
`arti-rpc-client-core`.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Currently this behaves the same as get_proxy_info,
but this may change in the future, if we introduce RPC-unsuitable
proxy ports.
(Also rename the get_proxy_info method to avoid x_ prefix.)
|
| | | |
| | |
| | |
| | |
| | | |
There's a blocking TODO here about exposing socks error codes that
I still need to solve.
|
| |/ /
| |
| |
| |
| |
| | |
Requires #1523.
Implements #1524.
|
| |/
|
|
|
|
|
|
| |
This effectively reverts 71e3d52f5aeb34ca7bca80053079a8c7505b99ac,
which was itself a revert of disabling this test the first time.
Sadly it still doesn't seem to be reliable. We have agreed on IRC to
disable it for now.
|
| |\
| |
| |
| |
| |
| |
| | |
arti: Make the config watcher debounce interval configurable.
Closes #1589
See merge request tpo/core/arti!2387
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Previously, the `reload_cfg::test::watch_multiple` test would take about
3s to run. This test modifies 3 files and waits for the corresponding
`reconfigure()` events to fire. Because of the
`sleep(DEBOUNCE_INTERVAL)` in `run_watcher`, it would wind up waiting
for about 1s for each of them.
This makes the event debouncing optional, and disables it in the tests.
Closes #1589
|
| | |
| |
| |
| | |
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| | |
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| | |
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Everything copied in the previous commits to tor-keys is now removed and
tor-keys crate is used accross the code.
Minor changes to tor-keys to accomodate this change.
Part of #1137
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
As stated in the comment added in this commit, this is temporary as we
want tor-hscrypto to start using tor-keys and define these
implementation there.
Part of #1137
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Move EncodableKey, ToEncodableKey and Keygen to tor-keys crate from
tor-keymgr.
To pull this off, an err.rs was added taken from tor-keymgr but stripped
down to what was needed only. No code was changed in any of the files
copied from tor-keymgr.
Our deftly macro now auto implement these traits for the key wrapper
type created. This gives the ability of the wrapper to be used by a
tor-keymgr::Keystore.
In order to pull this off, most of the SSH code has been moved into this
crate (ssh.rs) meaning that its ABI/API now resides in the tor-keys
trait outside of tor-keymgr.
Note that Sealed was not put back because the deftly macro is designed
to be used outside of this crate and thus implementing EncodableKey. The
alternative is that we would need to force all arti keys to be declared
in this crate which is not great because it then exposes all these key
types to the world outside their subsystem.
Part of #1137
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| | |
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| | |
Some object use path where put explicitly in order to avoid the macro
user to need to import "ed25519" module.
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The derive ed25519 keypair macro now implements the keymgr trait so the
key wrapper can now be used with a keystore without needing to specify
it in the tor-keymgr crate.
For this to work, a slight change to the KeygenRng trait was needed as
in to expect the CryptoRngCore trait which is what ed25519-dalek
requires.
And also, the removal of the Sealed trait since now it is accepted to
implement these traits outside tor-keymgr.
Fixes #1137
Signed-off-by: David Goulet <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
At this commit, we also add a derive-deftly macro for ed25519 keypair
along a helper macro that can define a wrapper around a lower-level
ed25519::Keypair.
Part of #1137
Signed-off-by: David Goulet <[email protected]>
|
| |\ \
| | |
| | |
| | |
| | | |
Remove semver.md files.
See merge request tpo/core/arti!2385
|
| | | |
| | |
| | |
| | | |
The 1.2.7 release is out so we won't be needing these anymore.
|
| |\ \ \
| |_|/
|/| |
| | |
| | |
| | |
| | | |
arti: Write the test config atomically.
Closes #1549
See merge request tpo/core/arti!2375
|
| | | |
| | |
| | |
| | | |
This reverts commit ececf6be2eaffc201666cd3413dc19c025be66de.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The flakiness from the `watch_single_file` test was caused by the race
between the config write, and the fake SIGHUP "signal" sent on
`sighup_tx`: sometimes, the sighup would get handled between creating
the config file and writing its contents. In those cases, the config
received in `TestModule::reconfigure` would be `Default::default()`,
which caused an assertion to fail (because the test is expecting to
receive the `ArtiConfig` it wrote to disk).
Closes #1549
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2374#note_3070500
|
| | | |
| | |
| | |
| | | |
Nothing uses this yet.
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
I realised a way this could happen without there being a bug.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
Including testing that uncommenting the example generates a config
with tracking enabled, and that the example low_water is the default
value for the example max.
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Tests are not entirely trivial and will come in a moment.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
* In arti, memquota simply turns on in memquota arti-client
* In arti-client, add an (unconditional) dependency on tor-memquota,
and have the memquota feature turn on the feature in tor-memquota.
|