summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | tor-rtcompat: Implement new_handle() using TcpSockFd.Gabriela Moldovan2025-01-154-3/+16
| | |
* | | tor-rtcompat: Add the ability to get a StreamOps handle.Gabriela Moldovan2025-01-158-1/+78
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Needed for cases where we wrap an object that implements `StreamOps` in an external type, thereby losing access to the `StreamOps` functionality. For example, during the channel handshake, we `.split()` the stream that implements `StreamOps`, which leaves us with a `SplitSink` and a `SplitStream`, neither of which implement `StreamOps`. Getting a handle to the underlying object that implements `StreamOps` (for example, a file handle) *before* the stream is `.split()` enables us to use `StreamOps` to manipulate the underlying split stream. This commit also introduces a special `UnsupportedStreamOpsHandle`, which is a type that implements `StreamOps`, but always returns an error. This type is meant to simplify error handling and usage, and is meant to be used in cases where `StreamOps` is not supported. TODO: the name of this type is pretty confusing (it's very similar to `UnsupportedStreamOp`, which is an error type), and should probably be renamed to something else (`NoOpStreamOpsHandle`, `BrokenStreamOpsHandle`, `DummyStreamOpsHandle` come to mind...). Note: this changes the `StreamOps` trait to be slightly different from what I originally envisioned in !2660 and #1769
* | | tor-proto: Add KistParams type built from NetParameters.Gabriela Moldovan2025-01-153-0/+63
| | | | | | | | | | | | | | | | | | | | | | | | Note: this commit makes `tor-proto` depend on `tor-netdir` (because it adds a `KistParams` type that is buildable from `NetParameters`, which is defined in `tor-netdir`). Closes #1729
* | | tor-netdir: Add KIST consensus params.Gabriela Moldovan2025-01-151-0/+26
| |/ |/| | | | | | | | | These are tentative, so I haven't added them to param-spec yet. Part of #1729
* | tor-rtmock: drop_reentrancy test: Run under miri tooIan Jackson2025-01-151-8/+14
| |
* | tor-rtmock: Explicitly manage the lifetime of the futureIan Jackson2025-01-151-0/+7
| | | | | | | | | | | | | | | | | | | | | | Previously, if r is Pending, `fut` is moved out of (stored in `task.fut`), whereas if r is Ready, it is retained and then dropped at the end of the loop iteration. This is quite subtle, and involves `fut` being in a "maybe moved out of" state (which cannot be represented in Rust's surface type system) after the block with the `data` lock. Let's write code that more clearly ensures that the compiler DTRT.
* | tor-rtmock: Add a test case for Future drop entrancyIan Jackson2025-01-151-0/+34
| | | | | | | | | | This passes right now, but only because the lifetime of the `fut` variable in `execute_until_first_stall` happens to be right.
* | tor-rtmock: Avoid misleading task dumps by careful drop sequencingIan Jackson2025-01-151-9/+34
| |
* | tor-rtmock: Add some more tracing / debug outputIan Jackson2025-01-151-1/+9
| |
* | tor-rtmock: Explain a difficulty with test trace outputIan Jackson2025-01-151-0/+5
| |
* | tor-proto: Add traced_test to test casesIan Jackson2025-01-152-0/+22
| | | | | | | | (We don't add it to the handful of unit tests that don't use an executor.)
* | Merge branch 'mistrust-fileaccess' into 'main'Nick Mathewson2025-01-143-92/+518
|\ \ | |/ |/| | | | | | | | | fs-mistrust: Facilities for file access Closes #1746 See merge request tpo/core/arti!2707
| * file_access: Refactor APIs to consume self.Nick Mathewson2025-01-141-7/+16
| | | | | | | | | | This approach makes it even less likely for people to store a FileAccess for repeated use.
| * file_access: Make link-following behavior explicitly controlled.Nick Mathewson2025-01-141-8/+38
| |
| * Documentation fixes from GabiNick Mathewson2025-01-141-5/+3
| |
| * fs-mistrust: Try more to explain what FileAccess is for.Nick Mathewson2025-01-141-3/+7
| |
| * fs-mistrust: Follow symlinks when using file-access outside a CheckedDir.Nick Mathewson2025-01-141-9/+98
| | | | | | | | | | | | When we're not bound to a CheckedDir, it doesn't make sense to forbid following symlinks, so long as their targets are also sensible.
| * fs-mistrust: Add FileAccess for Verifier (and Mistrust).Nick Mathewson2025-01-142-9/+42
| |
| * fs-mistrust: Have Verifier check methods take self by reference.Nick Mathewson2025-01-141-2/+2
| | | | | | | | There is no reason for these to consume self.
| * fs-mistrust: Add ability to create files with chosen mode.Nick Mathewson2025-01-141-10/+117
| |
| * fs-mistrust: Clean up documentation.Nick Mathewson2025-01-141-15/+13
| |
| * fs-mistrust: Move file access methods on CheckedDir to FileAccess.Nick Mathewson2025-01-142-69/+168
| | | | | | | | | | These are the methods which we'd like to give new options in #1746; we can move other methods later if we want to.
| * fs-mistrust: Define a (stub) FileAccess type.Nick Mathewson2025-01-143-0/+38
| | | | | | | | | | We're going to move functionality and configuration functions here to implement #1746.
| * fs-mistrust::CheckedDir: Refactor some common code.Nick Mathewson2025-01-141-22/+32
| |
| * fs-mistrust: Add test for (not) opening symlink from CheckedDir.Nick Mathewson2025-01-141-1/+10
| |
| * fs-mistrust: clarify doc for a private function.Nick Mathewson2025-01-141-0/+2
| |
* | arti-relay: fix rust/clippy lintsSteven Engler2025-01-144-4/+34
| |
* | arti-relay: add rust/clippy lintsSteven Engler2025-01-143-0/+71
|/
* tor-key-forge: Add missing semver.md entries.Gabriela Moldovan2025-01-131-0/+3
|
* tor-relay-crypto: Remove TODO about validating cert extensions.Gabriela Moldovan2025-01-131-2/+0
| | | | | | | There is no need for validation here. If any validation is required, it will be handled by the calling code. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2672?commit_id=10845d5e6a06d4d9548d536846eb470128d8a7d4#note_3147517
* tor-key-forge: Remove no longer needed ItemType impl for KeyUnknownCert.Gabriela Moldovan2025-01-131-9/+0
| | | | | No longer used, because we're now using `ParsedEd25519Cert` instead of `KeyUnknownCert` to represent parsed but not yet validated certs.
* tor-keymgr: Use ParsedEd25519Cert when decoding certs.Gabriela Moldovan2025-01-133-12/+13
| | | | | | | This helps us get rid of our uses of `KeyUnknownCert`. Needed because `KeyUnknownCert` can't readily be converted back to `EncodedEd25519Cert` (while `ParsedEd25519Cert` *can* -- see the `certs` module from `tor-relay-crypto`).
* tor-relay-crypto: Use the new cert_type() function to get the cert type.Gabriela Moldovan2025-01-131-2/+8
|
* tor-relay-crypto: Use the high-level cert types instead of EncodedEd25519Cert.Gabriela Moldovan2025-01-131-2/+4
| | | | | | | This will come in handy later on, when we start using these function in conjunction with `KeyMgr::get_or_generate_key_and_cert`, which expects the `make_certificate` callback to return a type that implements `ToEncodableCert`.
* tor-relay-crypto: Implement ToEncodableCert for the relay cert types.Gabriela Moldovan2025-01-132-0/+92
| | | | Closes #1777
* tor-relay-crypto: Add high-level cert types.Gabriela Moldovan2025-01-132-1/+41
| | | | | | These will be the `ToEncodableCert`s we write to the keystore. Part of #1777
* tor-key-forge: Implement ItemType for ParsedEd25519Cert.Gabriela Moldovan2025-01-131-0/+9
| | | | | This will enable us to retrieve it from the keystore as an `ErasedKey` (side note, we should rename `ErasedKey` to `ErasedItem`).
* tor-key-forge: Add wrappers for various cert types.Gabriela Moldovan2025-01-132-3/+115
|
* tor-key-forge: Fill out the InvalidCertError type.Gabriela Moldovan2025-01-132-1/+20
| | | | We'll soon use this.
* tor-cert: Add experimental API for building EncodedEd25519Certs.Gabriela Moldovan2025-01-131-0/+17
| | | | | | | | | | | | | | | | This will enable us to deserialize byte slices as `EncodedEd25519Certs`. Needed because this type will be used to representing a parsed + validated cert retrieved from the keystore. Technically, we *could* do without this function by defining a separate newtype wrapper over `Vec<u8>` to represent the validated cert data, but IMO adding a second encoded ed25519 cert type in another crate might be confusing later down the line (because the two types will be nearly identical, and are bound to eventually diverge in terms of API and implementation). Part of #1137
* tor-keymgr: Fix cert handling tests.Gabriela Moldovan2025-01-133-25/+64
| | | | | | This updates and reenables the cert management tests. Part of #1768
* tor-key-forge: Fix typo in doc comment.Gabriela Moldovan2025-01-131-1/+1
|
* tor-cert: Remove no-longer-needed experimental API.Gabriela Moldovan2025-01-131-12/+0
| | | | Part of #1768
* tor-keymgr: Use Ed25519Cert::decode to parse the certs.Gabriela Moldovan2025-01-134-4/+18
|
* tor-keymgr: Add cert parse error variant.Gabriela Moldovan2025-01-134-2/+20
| | | | | | | This will soon be used, when we modify the `ArtiNativeKeystore` cert lookup code to actually parse certificates before returning them. Part of #1768
* tor-key-forge: Add ItemType impl for KeyUnknownCert.Gabriela Moldovan2025-01-131-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `KeyUnknownCert` will soon be used as the `ToEncodableCert::ParsedCert` type for Tor ed25519 certs. For example, the `ToEncodableCert` impl for `RelaySigningKeyCert` will look like this: ```rust pub struct RelaySigningKeyCert(EncodedEd25519Cert); impl ToEncodableCert<RelaySigningKeypair> for RelaySigningKeyCert { type ParsedCert = KeyUnknownCert; type EncodableCert = EncodedEd25519Cert; type SigningKey = RelayIdentityKeypair; fn validate( cert: Self::ParsedCert, subject: &RelaySigningKeypair, signed_with: &Self::SigningKey, ) -> Result<Self, InvalidCertError> { // TODO: validate `KeyUnknownCert` // and convert it to an EncodedEd25519Cert // (we don't yet an easy way to perform this conversion) } fn to_encodable_cert(self) -> Self::EncodableCert { self.0 } } ```
* tor-key-forge: Split out ItemType as a separate trait.Gabriela Moldovan2025-01-137-28/+57
| | | | | | | | This is necessary because `ParsedCert`s will not be `EncodableItem`s. This is because we cannot (and don't want to) write certificates that have not yet been validated to the keystore. They do need to be retrievable from the keystore though, so we also change `ErasedKey` to be `Box<dyn ItemType>` instead.
* tor-key-forge: Distinguish between parsed certs and encodable certs.Gabriela Moldovan2025-01-132-12/+16
| | | | | | | | | | | | | | | We need two different types to represent * certs that have been parsed, but not yet validated (`KeyUnknownCert`) * newly generated encodable certs (`EncodedEd25519Cert`) Currently, we don't use `KeyUnknownCert` anywhere, and instead use `EncodedEd25519Cert` to represent "parsed" but not-yet-validated certs. This approach is wrong and relies on a broken (no-op) `EncodedEd25519Cert::from_bytes` implementation. A future commit will address this problem by replacing `EncodedEd25519Cert::from_bytes` with `Ed25519Cert::decode` to actually parse the cert upon retrieving it from the keystore.
* tor-keymgr: Replace from_encodable_cert with validation function.Gabriela Moldovan2025-01-132-22/+7
| | | | | | | | In practice, we won't be able to obtain an `ToEncodableCert` type from an `EncodableItem` cert without validating it first, so we need to collapse `validate` into `from_encodable_cert`. Part of #1768
* tor-key-forge: Export some additional tor-cert types.Gabriela Moldovan2025-01-131-3/+3
| | | | This will soon be used.