| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Also set a better error message when validating channel target.
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This trickles down to the tor-proto channel handshake code. But, the
real need is in the channel builder in order to validate the outbound
channel target.
Fixes #2440
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
It used to be only with the feature = relay but since client can have
that feature enabled, we now validate based on channel outbound type
instead.
Related to #2440
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
Log IDs
See merge request tpo/core/arti!3872
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-proto: Move CREATE_FAST handling to a helper
See merge request tpo/core/arti!3869
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Clippy has started warning about this since we moved the CREATE_FAST
handling to a helper, so this resolves that.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Fix formatting from previous code movement.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This moves the code, changes the indentation, and wraps the result in an
`Ok()`.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This had already been resolved.
|
| | |/ / / /
|/| | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This was previously advancing time by more than intended (I think the
intention here was to use something like
`MockRuntime::jump_wallclock()`, but that function has no effect on
sleeping futures, so I think we should continue using `advance_by()`).
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Allow compile-time selection of rustls CryptoProvider; use aws-lc-rs by default.
Closes #2448
See merge request tpo/core/arti!3857
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
When using rustls, previously we'd check to see whether the
application had installed a CryptoProvider (as it is required to
do). If not, we'd log a warning and install a Ring provider.
But now, we want to enable other kinds of providers,
so this behavior isn't practical any more.
(See #2448 for discussion.)
Closes #2448.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-error/arti: add logging.protocol_warnings for TorProtocolViolation
See merge request tpo/core/arti!3805
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
in event_report!
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
From opara's comment:
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3844#note_3388789
Keep the low level AuthLogDigest type alias and return it. The callsite
is the one deciding if the returned digest is a Clog or a Slog.
Related to #2441
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Introduce those types in order to avoid mixing them up as the previous
AuthLogDigest was just a type alias over [u8; 32]
Fixes #2441
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Fix the testdata2 situation
See merge request tpo/core/arti!3861
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adds a manual test case for happy families in microdesc with
parse2. Manual in the sense that we hardcode a microdescriptor taken
from the wild here, as testdata2 does not contain them at the current
moment, which is unfortunate but reported.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adjust the family value for the microdesc test to the one
actually found in testdata2/.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the microdesc test EC keys with the new ones from
testdata2/ while also changing the encoding from a byte array to the
base64 value found in the microdesc itself.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the microdesc onion key with the new one from
testdata2.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit removes the assert_eq for mds[6]. The reason for this was
to have a test case with happy families set. However, these values were
manually hacked into the respective file which is not the correct way.
Instead, we will test this in a separate test that will be added later,
as the current testdata2/ is not capable of this. This is an already
reported chutney issue.
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This removes unused imports as well as the read_b64 and to_der helper
functions which are all no longer used.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the dir_auth_cross_cert() test case with the new
constants, replacing the longclaw ones.
The replacement also involves a slight refactoring on the way how we
obtain the encoded and decoded variable, namely because we have the data
in a PEM encoded string now and no longer in separate file, making the
use of read_b64 impossible.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the invalid outer signature test case by copying the
outer signature of the alternative certificate into our test object,
which should obviously render this to a failure.
It also updates the test vectors to the constant ones because it moves
away from longclaw.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the invalid cross-cert test case by copying the
cross-cert from the alternative cert into our test object, resulting in
a failure.
Of course this also updates the other test vectors to use the constants
declared above, as this moves away from longclaw.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the inconsistent fingerprint test case that tests
whether the fingerprint matches with the identity RSA key. For this, we
load the alternative authority cert and move its identity key into the
identity key of the canonical cert.
Of course, this also replaces the other test vectors that are now
required for this change because it moves away from longclaw.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adds a new constant to the parse2 authcert unit tests,
ALTERNATIVE_AUTHCERT_RAW, with the idea being to be different than
AUTHCERT_RAW, which we will utilize in order to mix up cross-cert
objects from one authcert with the one of another one in order to see it
fail.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit updates the "trivial" test cases in the dir_auth_signature
unit tests, namely the ones concerning the outer signature as well as
the timestamp tolerance. A follow-up commit will also update the more
tricky ones, such as the ones testing inconsistent cross-certificates,
etc.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit constifies VALID_SYSTEM_TIME, a timestamp indicating a point
in time at which the certificate is valid. We will need this to test
timestamp validation.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit replaces the longclaw test vectors in dir_auth_cert with the
ones we constified previously and represent the ones found in
testdata2/.
It may look a bit odd that we replaced the file includes for the public
keys but this is because those files should have never existed in
testdata2/ in the first place and were only added by accident, meaning
that the current approach is the correct one.
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit replaces a File::open with the AUTHCERT_RAW constant in the
dir_auth_cert test because that is obviously less error prone.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adds `const AUTHCERT_RAW` which `include_str`'s the actual
raw authcert we will use for parsing test purposes. The reason for that
being that a single include_str! of the same file is obviously better
than multiple ones.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit constifies the authcert test vectors by extracting them from
testdata2/keys/authority_certificate.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adds a to_rsa_id() helper function to the authcert tests in
order to convert a hex-encoded RSA identity to an RsaIdentity. It will
be required later on for converting the test vector values to the inner
representations and this function is helpful here because it avoids us
to do repetitive unwrapping and RsaIdentity::from_hex calls, which
overall increase the length/readability.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adds the pem_to_rsa_pk helper function to the authcert tests
in order to convert a PEM encoded RSA public key to the internal data
structure. It will be required later on in order to convert the test
vector strings to internal representations.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This commit adds a to_system_time helper function accepting an &str in
the Iso8601TimeSp format and converting it to a SystemTime to the
authcert test cases. It will be required later on in order to
conveniently convert human readable timestamps to the test vectors
expected from parsed data.
|