summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | tor-proto: Add CtrlMsg for setting kist options (fmt).Gabriela Moldovan2025-01-151-1/+3
| | |
* | | tor-proto: Add CtrlMsg for setting kist options.Gabriela Moldovan2025-01-151-1/+8
| | |
* | | tor-rtcompat: Fix doc warning.Gabriela Moldovan2025-01-151-1/+1
| | |
* | | tor-proto: Pass a StreamOps handle to the channel reactor.Gabriela Moldovan2025-01-153-2/+16
| | |
* | | tor-rtcompat: Big invasive change adding StreamOps bound everywhere.Gabriela Moldovan2025-01-1511-21/+34
| | | | | | | | | | | | | | | | | | This is unfortunately necessary, because after the channel handshake, we need to give the channel reactor a `StreamOps` handle to the underlying stream.
* | | tor-rtcompat: Implement StreamOps for TLS stream types.Gabriela Moldovan2025-01-152-1/+22
| | |
* | | tor-rtmock: Implement StreamOps for MockTlsStream (fmt).Gabriela Moldovan2025-01-151-1/+3
| | |
* | | tor-rtmock: Implement StreamOps for MockTlsStream.Gabriela Moldovan2025-01-151-1/+14
| | | | | | | | | | | | | | | We're about to add a trait bound that forces `MockTlsStream` to impl `StreamOps`.
* | | tor-rtcompat: Implement StreamOps for Framed.Gabriela Moldovan2025-01-152-0/+14
| | |
* | | tor-rtcompat: Implement new_handle() using TcpSockFd (fmt).Gabriela Moldovan2025-01-151-1/+3
| | |
* | | tor-rtcompat: Implement new_handle() using TcpSockFd.Gabriela Moldovan2025-01-154-3/+16
| | |
* | | tor-rtcompat: Add the ability to get a StreamOps handle.Gabriela Moldovan2025-01-158-1/+78
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Needed for cases where we wrap an object that implements `StreamOps` in an external type, thereby losing access to the `StreamOps` functionality. For example, during the channel handshake, we `.split()` the stream that implements `StreamOps`, which leaves us with a `SplitSink` and a `SplitStream`, neither of which implement `StreamOps`. Getting a handle to the underlying object that implements `StreamOps` (for example, a file handle) *before* the stream is `.split()` enables us to use `StreamOps` to manipulate the underlying split stream. This commit also introduces a special `UnsupportedStreamOpsHandle`, which is a type that implements `StreamOps`, but always returns an error. This type is meant to simplify error handling and usage, and is meant to be used in cases where `StreamOps` is not supported. TODO: the name of this type is pretty confusing (it's very similar to `UnsupportedStreamOp`, which is an error type), and should probably be renamed to something else (`NoOpStreamOpsHandle`, `BrokenStreamOpsHandle`, `DummyStreamOpsHandle` come to mind...). Note: this changes the `StreamOps` trait to be slightly different from what I originally envisioned in !2660 and #1769
* | | tor-proto: Add KistParams type built from NetParameters.Gabriela Moldovan2025-01-153-0/+63
| | | | | | | | | | | | | | | | | | | | | | | | Note: this commit makes `tor-proto` depend on `tor-netdir` (because it adds a `KistParams` type that is buildable from `NetParameters`, which is defined in `tor-netdir`). Closes #1729
* | | tor-netdir: Add KIST consensus params.Gabriela Moldovan2025-01-151-0/+26
| |/ |/| | | | | | | | | These are tentative, so I haven't added them to param-spec yet. Part of #1729
* | tor-rtmock: drop_reentrancy test: Run under miri tooIan Jackson2025-01-151-8/+14
| |
* | tor-rtmock: Explicitly manage the lifetime of the futureIan Jackson2025-01-151-0/+7
| | | | | | | | | | | | | | | | | | | | | | Previously, if r is Pending, `fut` is moved out of (stored in `task.fut`), whereas if r is Ready, it is retained and then dropped at the end of the loop iteration. This is quite subtle, and involves `fut` being in a "maybe moved out of" state (which cannot be represented in Rust's surface type system) after the block with the `data` lock. Let's write code that more clearly ensures that the compiler DTRT.
* | tor-rtmock: Add a test case for Future drop entrancyIan Jackson2025-01-151-0/+34
| | | | | | | | | | This passes right now, but only because the lifetime of the `fut` variable in `execute_until_first_stall` happens to be right.
* | tor-rtmock: Avoid misleading task dumps by careful drop sequencingIan Jackson2025-01-151-9/+34
| |
* | tor-rtmock: Add some more tracing / debug outputIan Jackson2025-01-151-1/+9
| |
* | tor-rtmock: Explain a difficulty with test trace outputIan Jackson2025-01-151-0/+5
| |
* | tor-proto: Add traced_test to test casesIan Jackson2025-01-152-0/+22
| | | | | | | | (We don't add it to the handful of unit tests that don't use an executor.)
* | Merge branch 'mistrust-fileaccess' into 'main'Nick Mathewson2025-01-143-92/+518
|\ \ | |/ |/| | | | | | | | | fs-mistrust: Facilities for file access Closes #1746 See merge request tpo/core/arti!2707
| * file_access: Refactor APIs to consume self.Nick Mathewson2025-01-141-7/+16
| | | | | | | | | | This approach makes it even less likely for people to store a FileAccess for repeated use.
| * file_access: Make link-following behavior explicitly controlled.Nick Mathewson2025-01-141-8/+38
| |
| * Documentation fixes from GabiNick Mathewson2025-01-141-5/+3
| |
| * fs-mistrust: Try more to explain what FileAccess is for.Nick Mathewson2025-01-141-3/+7
| |
| * fs-mistrust: Follow symlinks when using file-access outside a CheckedDir.Nick Mathewson2025-01-141-9/+98
| | | | | | | | | | | | When we're not bound to a CheckedDir, it doesn't make sense to forbid following symlinks, so long as their targets are also sensible.
| * fs-mistrust: Add FileAccess for Verifier (and Mistrust).Nick Mathewson2025-01-142-9/+42
| |
| * fs-mistrust: Have Verifier check methods take self by reference.Nick Mathewson2025-01-141-2/+2
| | | | | | | | There is no reason for these to consume self.
| * fs-mistrust: Add ability to create files with chosen mode.Nick Mathewson2025-01-141-10/+117
| |
| * fs-mistrust: Clean up documentation.Nick Mathewson2025-01-141-15/+13
| |
| * fs-mistrust: Move file access methods on CheckedDir to FileAccess.Nick Mathewson2025-01-142-69/+168
| | | | | | | | | | These are the methods which we'd like to give new options in #1746; we can move other methods later if we want to.
| * fs-mistrust: Define a (stub) FileAccess type.Nick Mathewson2025-01-143-0/+38
| | | | | | | | | | We're going to move functionality and configuration functions here to implement #1746.
| * fs-mistrust::CheckedDir: Refactor some common code.Nick Mathewson2025-01-141-22/+32
| |
| * fs-mistrust: Add test for (not) opening symlink from CheckedDir.Nick Mathewson2025-01-141-1/+10
| |
| * fs-mistrust: clarify doc for a private function.Nick Mathewson2025-01-141-0/+2
| |
* | arti-relay: fix rust/clippy lintsSteven Engler2025-01-144-4/+34
| |
* | arti-relay: add rust/clippy lintsSteven Engler2025-01-143-0/+71
|/
* tor-key-forge: Add missing semver.md entries.Gabriela Moldovan2025-01-131-0/+3
|
* tor-relay-crypto: Remove TODO about validating cert extensions.Gabriela Moldovan2025-01-131-2/+0
| | | | | | | There is no need for validation here. If any validation is required, it will be handled by the calling code. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2672?commit_id=10845d5e6a06d4d9548d536846eb470128d8a7d4#note_3147517
* tor-key-forge: Remove no longer needed ItemType impl for KeyUnknownCert.Gabriela Moldovan2025-01-131-9/+0
| | | | | No longer used, because we're now using `ParsedEd25519Cert` instead of `KeyUnknownCert` to represent parsed but not yet validated certs.
* tor-keymgr: Use ParsedEd25519Cert when decoding certs.Gabriela Moldovan2025-01-133-12/+13
| | | | | | | This helps us get rid of our uses of `KeyUnknownCert`. Needed because `KeyUnknownCert` can't readily be converted back to `EncodedEd25519Cert` (while `ParsedEd25519Cert` *can* -- see the `certs` module from `tor-relay-crypto`).
* tor-relay-crypto: Use the new cert_type() function to get the cert type.Gabriela Moldovan2025-01-131-2/+8
|
* tor-relay-crypto: Use the high-level cert types instead of EncodedEd25519Cert.Gabriela Moldovan2025-01-131-2/+4
| | | | | | | This will come in handy later on, when we start using these function in conjunction with `KeyMgr::get_or_generate_key_and_cert`, which expects the `make_certificate` callback to return a type that implements `ToEncodableCert`.
* tor-relay-crypto: Implement ToEncodableCert for the relay cert types.Gabriela Moldovan2025-01-132-0/+92
| | | | Closes #1777
* tor-relay-crypto: Add high-level cert types.Gabriela Moldovan2025-01-132-1/+41
| | | | | | These will be the `ToEncodableCert`s we write to the keystore. Part of #1777
* tor-key-forge: Implement ItemType for ParsedEd25519Cert.Gabriela Moldovan2025-01-131-0/+9
| | | | | This will enable us to retrieve it from the keystore as an `ErasedKey` (side note, we should rename `ErasedKey` to `ErasedItem`).
* tor-key-forge: Add wrappers for various cert types.Gabriela Moldovan2025-01-132-3/+115
|
* tor-key-forge: Fill out the InvalidCertError type.Gabriela Moldovan2025-01-132-1/+20
| | | | We'll soon use this.
* tor-cert: Add experimental API for building EncodedEd25519Certs.Gabriela Moldovan2025-01-131-0/+17
| | | | | | | | | | | | | | | | This will enable us to deserialize byte slices as `EncodedEd25519Certs`. Needed because this type will be used to representing a parsed + validated cert retrieved from the keystore. Technically, we *could* do without this function by defining a separate newtype wrapper over `Vec<u8>` to represent the validated cert data, but IMO adding a second encoded ed25519 cert type in another crate might be confusing later down the line (because the two types will be nearly identical, and are bound to eventually diverge in terms of API and implementation). Part of #1137