summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | tor-netdoc: Replace AuthCert::verify_selfcert implIan Jackson2026-04-012-47/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Get rid of the version in poc. Instead, implement the same functionality in terms of AuthCert::verify, outside poc.
| * | | | | | tor-netdoc: authcert: Test encoding and signing methodIan Jackson2026-04-011-0/+43
| | | | | | |
| * | | | | | tor-netdoc: authcert: Provide encoding and signing methodIan Jackson2026-04-011-1/+26
| | | | | | |
| * | | | | | tor-netdoc: RsaSha1Signature: Provide signing methodIan Jackson2026-04-011-0/+82
| | | | | | |
| * | | | | | tor-netdoc: Provide `new` methods for CrossCert and AuthCertIan Jackson2026-04-011-0/+60
| | | | | | |
| * | | | | | tor-netdoc: Turn AuthCertSignature into RsaSignatureIan Jackson2026-04-013-26/+47
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These are in fact just a completely normal RSA signature like in the spec! Move the type to the types module, and rename it. Leave a compatibility alias.
| * | | | | | tor-netdoc: derive enncoding for AuthCert, AuthCertSignature[s]Ian Jackson2026-04-011-2/+5
| | | | | | |
| * | | | | | tor-netdoc: implement encoding function for raw_data_objectIan Jackson2026-04-011-1/+10
| | | | | | |
| * | | | | | tor-netdoc: Move raw_data_object to new container moduleIan Jackson2026-04-015-12/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This will allow us to use it for encoding as well as parsing.
| * | | | | | tor-netdoc: impl encoding traits for authcert cross-cert typesIan Jackson2026-04-011-1/+19
| | | | | | |
| * | | | | | tor-netdoc: impl encoding traits for rsa::PublicKeyIan Jackson2026-04-012-0/+28
| | | | | | |
| * | | | | | tor-netdoc: Provide ItemEncoder::text_sofar()Ian Jackson2026-04-012-0/+6
| | | | | | |
| * | | | | | tor-netdoc: Provide ItemEncoder::object() taking an ItemObjectEncodableIan Jackson2026-04-013-0/+18
| | | | | | |
| * | | | | | tor-netdoc: impl From<RsaIdentity> for the fingerprint typesIan Jackson2026-04-012-4/+9
| | | | | | |
| * | | | | | tor-netdoc: encode derive: Fix handling of optionality.Ian Jackson2026-04-011-7/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We mustn't use selector.selector() because that's for multiplicity, not optionality. In pracctice, it goes wrong with Vec<u8>.
| * | | | | | tor-netdoc: encode derive: Use paste_spanned to improve an error messageIan Jackson2026-04-011-1/+3
| | | | | | |
| * | | | | | tor-netdoc: Fix a wrong "what does this end" commentIan Jackson2026-04-011-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This was a c&p error, I think.
| * | | | | | tor-netdoc: authcert: Debug CrossCertObject in hexIan Jackson2026-04-011-1/+3
| | | | | | |
| * | | | | | tor-netdoc: Constructor: Fix it so it actually worksIan Jackson2026-04-012-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The hidden __non_exhaustive field has to be pub. And, fix the use site, currently AuthCert.
| * | | | | | tor-netdoc: encode: re-export netdoc_ordering_check for macrosIan Jackson2026-04-011-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Otherwise deriving NetdocEncodable doesn't work outside this crate.
| * | | | | | tor-netdoc: encode derive: Use $P for ResultIan Jackson2026-03-311-1/+1
| | | | | | |
| * | | | | | tor-netdoc: Fix typo in doc commentIan Jackson2026-03-311-1/+1
| | |_|_|/ / | |/| | | |
* | | | | | Merge branch 'relay-crypto-dep' into 'main'David Goulet2026-04-011-5/+11
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | proto: Make tor-relay-crypto an optional dependency Closes #2450 See merge request tpo/core/arti!3848
| * | | | | | proto: Run cargo-sortGabriela Moldovan2026-04-011-3/+3
| | | | | | |
| * | | | | | proto: Make tor-relay-crypto an optional dependency (fmt)Gabriela Moldovan2026-04-011-1/+7
| | | | | | |
| * | | | | | proto: Make tor-relay-crypto an optional dependencyGabriela Moldovan2026-04-011-2/+2
| |/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We only need this for `relay` builds. Closes #2450
* | | | | | arti-relay: Remove no-longer needed implsGabriela Moldovan2026-04-012-26/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The specifiers are local to the crate, so we don't need the `valid_until` accessors anymore.
* | | | | | arti-relay: Make the key specifiers pub(crate)Gabriela Moldovan2026-04-011-14/+14
| | | | | | | | | | | | | | | | | | | | | | | | These no longer need to be `pub` now that they're in `arti-relay`.
* | | | | | arti-relay: Move all key specifiers to a new keys module (fmt)Gabriela Moldovan2026-04-012-17/+13
| | | | | |
* | | | | | arti-relay: Move all key specifiers to a new keys moduleGabriela Moldovan2026-04-015-328/+334
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This extracts the key specifier types out of `tor-relay-crypto`, which * makes the code layout consistent with the hidden service crates (the key specifiers are defined in a `keys` module in `tor-hsservice`, while the key wrapper types live in `tor-hscrypto::pk`) * helps reduce the API surface: the key specifiers are only used in `arti-relay`, so we can move them there and make them `pub(crate)` instead of `pub`
* | | | | | relay-crypto: Make the certs module non-pubGabriela Moldovan2026-04-011-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | This doesn't really need to be public.
* | | | | | proto: Add key specifier types for the ntor keysGabriela Moldovan2026-04-011-0/+31
|/ / / / / | | | | | | | | | | | | | | | Part of #2451
* | | | | Merge branch 'authcert-encode-prep' into 'main'Ian Jackson2026-03-319-28/+32
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: Renamings preparatory to authcert encoder See merge request tpo/core/arti!3826
| * | | | | tor-netdoc: Rename `AuthCertUnverified::verify_self_signed`Ian Jackson2026-03-314-16/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This method verifies all the signatures, and checks that the signing authority is in the provided list. Anyway, authcerts aren't really self-signed: they're a signature by KS_auth_id_rsa on KP_auth_sign_rsa. Note that there is also a `verify_selfcert` method which does only some of the checks, and has some code duplication. That will be cleaned up later.
| * | | | | tor-netdoc: encoder: Rename .object() method to .object_bytesIan Jackson2026-03-316-12/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With the introduction of the derives for document encoding, we now have a trait ItemObjectEncodable. We will want a method on ItemEncoder that takes an ItemObjectEncodable, and that should be called `object` since it's a better approach than working ad-hoc with tor_bytes::Writeable. (For example, an ItemObjectEncodable knows its own label.) So, rename `object` to `object_bytes`.
* | | | | | Merge branch 'deps-wasm' into 'main'David Goulet2026-03-311-1/+1
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | Update getrandom dependeency See merge request tpo/core/arti!3837
| * | | | | Update getrandom dependeencyIan Jackson2026-03-311-1/+1
| | | | | |
* | | | | | Merge branch 'fixes_mr3791' into 'main'David Goulet2026-03-3116-469/+613
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | Address post-merge comments from nickm's review in mr 3791 See merge request tpo/core/arti!3802
| * | | | | proto: Add debug_assert_eq() when building AuthenticateDavid Goulet2026-03-301-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | cell: Add Authenticate::BODY_LEN as a public constDavid Goulet2026-03-302-2/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We use this constant value when building the AUTHENTICATE cell to optimize the memory allocation as this won't ever change. Signed-off-by: David Goulet <[email protected]>
| * | | | | linkspec: Rename has_all_public_addresses()David Goulet2026-03-302-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | proto: Import read_msg() instead of refering to itDavid Goulet2026-03-301-19/+4
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | proto: Improve check_relay_identities() documentationDavid Goulet2026-03-301-3/+7
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | linkspec: Rename has_all_reachable_addresses()David Goulet2026-03-302-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | linkspec: Rename has_all_valid_port() to has_all_nonzero_port()David Goulet2026-03-302-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | linkspec: Move has_all_valid_port() and has_all_reachable_addresses() into ↵David Goulet2026-03-302-35/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ChanTarget Signed-off-by: David Goulet <[email protected]>
| * | | | | proto: Rename RelayIdentities to RelayChannelAuthMaterialDavid Goulet2026-03-3010-108/+136
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This object contains a melting pot of public keys, private keys and certificates. Rename it to reflect that it is channel authentication material and not "identities. https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3791#note_3374454 Signed-off-by: David Goulet <[email protected]>
| * | | | | proto: Remove noop function for initiator channelDavid Goulet2026-03-301-12/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | No need to call `set_authenticated()` for a relay initiator channel because relay initiator channel are always authenticated and thus the underlying channel cell codec will always use the R2R restricted message set. This is only useful to a relay responder channel. The naming of that function is not great actually and should probably change. Signed-off-by: David Goulet <[email protected]>
| * | | | | proto: Rename many variables with more fine grained namingDavid Goulet2026-03-307-127/+144
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Mostly, identity a `ChanTarget` as a "target" since we juggle with PeerInfo and OwnedChanTarget nowadays. All certificate and keys have very specific names which attempts to match the spec as much as possible. Signed-off-by: David Goulet <[email protected]>
| * | | | | proto: Transform inner into verified after verificationDavid Goulet2026-03-302-20/+17
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Only get the inner generic unverified channel into a verified channel after the actual verification in the relay responder handshake. Some variables needed a rename as this was dangerously named. No behavior change. https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3791#note_3374481 Signed-off-by: David Goulet <[email protected]>