aboutsummaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | keymgr: Preserve item metadata when converting to TestPublicKey (fmt)Gabriela Moldovan2026-03-171-1/+4
| | | |
* | | | keymgr: Preserve item metadata when converting to TestPublicKeyGabriela Moldovan2026-03-171-1/+3
| | | | | | | | | | | | | | | | This will enable us to test the provenance of public keys.
* | | | keymgr: Update cert testsGabriela Moldovan2026-03-171-1/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed now that `get_or_generate_key_and_cert()` uses the keypair specifier when generating the subject key. Without this the cert retrieval tests fail because `get_or_generate_key_and_cert()` now requires the subject key specifier to have an associated keypair specifier ("KeyCertificateSpecifier has no keypair specifier for the subject key?"). Note that even with this patch, the `get_cert_entry()` test still fails because of a bug in the `get_*()` family of functions. This will be fixed in a future commit.
* | | | keymgr: Use the keypair specifier when generating keys.Gabriela Moldovan2026-03-171-1/+9
| |/ / |/| | | | | | | | | | | | | | | | | When generating a new keypair, we want to use the keypair specifier of the subject key. Fixes a bug where this code was incorrectly generating a keypair using the specifier of the public key type (the resulting generated key had a `kp_` prefix instead of `ks_`).
* | | keymgr, key-forge: Use our ssh-* forksGabriela Moldovan2026-03-162-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Upstream `ssh-key` is missing some important features we need for arti-relay: * a bug fix without which we can't convert deserialized RSA keys to their rsa counterparts: https://github.com/RustCrypto/SSH/pull/318 * @wesleyac 's patch https://github.com/RustCrypto/SSH/pull/412 for allowing insecure (1024 bits long) RSA keys (needed because the relay KS_relayid_rsa identity keys are 1024 bits long) We plan to switch back to mainline `ssh-key` when `ssh-key 0.7.0` comes out. See the discussion in #2398 for more details.
* | | Merge branch 'circ-react-logs' into 'main'David Goulet2026-03-162-2/+44
|\ \ \ | | | | | | | | | | | | | | | | proto: Add more logging to the new circuit reactors See merge request tpo/core/arti!3776
| * | | proto: Add more logging to the new circuit reactorsGabriela Moldovan2026-03-122-2/+44
| | | |
* | | | Merge branch 'typos' into 'main'opara2026-03-1642-54/+54
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Fix various typos See merge request tpo/core/arti!3781
| * | | | Fix grammar typosTobias Stoeckmann2026-03-156-9/+9
| | | | |
| * | | | Fix word duplicate typosTobias Stoeckmann2026-03-1540-46/+46
| | | | |
* | | | | Merge branch 'rpc-su-v2' into 'main'Nick Mathewson2026-03-1616-73/+444
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | RPC: Provide superuser mode Closes #2285 See merge request tpo/core/arti!3743
| * | | | | rpc-client: Run cbindgen to regenerate C header.Nick Mathewson2026-03-161-0/+20
| | | | | |
| * | | | | rpc-client: add support to prefer/require su permissionNick Mathewson2026-03-165-2/+114
| | | | | |
| * | | | | rpc: Add support for set_dormant.Nick Mathewson2026-03-163-7/+60
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is not exactly the most _urgent_ superuser functionality, but it is probably the easiest to implement.
| * | | | | rpc: Implement superuser mode.Nick Mathewson2026-03-164-7/+50
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When connection point provides superuser support, provide a (currently inert) RpcSuperuser object to the RPC session.
| * | | | | rpc: add a "superuser" element to connect points.Nick Mathewson2026-03-162-0/+45
| | | | | | | | | | | | | | | | | | | | | | | | Currently does nothing.
| * | | | | rpc: Do not allow a connection to be authenticated twiceNick Mathewson2026-03-164-10/+24
| | | | | | | | | | | | | | | | | | | | | | | | This makes it a little easier to drop unwanted capabilities.
| * | | | | rpc: Move responsibility for Session creation to ConnectionNick Mathewson2026-03-165-64/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The Connection will know the options that the listener was created with, as opposed to RpcMgr, which is the same for every listener.
| * | | | | rpc: Add su capability to RpcSession, and methods to get/drop itNick Mathewson2026-03-161-2/+108
| | |/ / / | |/| | | | | | | | | | | | | | | | | | (For now, the su capability doesn't actually do anything, and there is no ability to actually have a session start with one.)
* | | | | Fix windows cargo warningsTobias Stoeckmann2026-03-152-1/+4
| | | | | | | | | | | | | | | | | | | | Disable use-statements which are only needed for unix.
* | | | | arti-rpc-client-core: Fix windows buildTobias Stoeckmann2026-03-151-1/+1
| |/ / / |/| | | | | | | | | | | Fix a typo in use-statement for windows.
* | | | proto: Move criterion-cycles-per-byte to dev-dependenciesNick Mathewson2026-03-131-1/+1
|/ / / | | | | | | | | | | | | | | | | | | | | | This may help fix our CI cross compilation tests on platforms without a C compiler install. In any case, it may speed up non-test builds by a tiny bit. Possible solution for #2366.
* | | Merge branch 'relay-log-idents' into 'main'opara2026-03-122-0/+33
|\ \ \ | | | | | | | | | | | | | | | | arti-relay: Log relay identities See merge request tpo/core/arti!3773
| * | | arti-relay: Log relay identitiesSteven Engler2026-03-122-0/+33
| | | |
* | | | keymgr: Add test retrieving an expired certGabriela Moldovan2026-03-121-1/+77
| | | | | | | | | | | | | | | | | | | | This tests that the `KeyMgr` returns an error if you try to retrieve an invalid cert.
* | | | keymgr: Introduce a new TestCert typeGabriela Moldovan2026-03-121-4/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a bit of a hack, but we need it to make the tests pass. The issue is that our test keystore stores `TestItem`s, and all our other test used `TestItem` as their key types. Now that we have certs, we have this concept of a `ToEncodableCert::ParsedCert`, which is what the keymgr downcasts the retrieved certs to before validating them and returning the final cert result (which is usually going to be of a different type than `ParsedCert`). This wrapper ensures that the keystore returns the expected `ParsedCert` type, so that validation doesn't fail. Before this change, we were hackily returning `TestItem` in the tests, even for certificates, but that doesn't work anymore, because the `ItemType` impl of `TestItem` returns `KeyType::Ed25519Keypair`, which is obviously not a `CertType`. Using it resulted in an error because there is a mismatch between the cert `ItemType` (`Ed25519Keypair`) and the `ItemType` of the `KeystoreItem::Cert` entry (`Ed25519TorCert`). Normally this wouldn't happen, but the whole test keystore implementation is funky and inconsistent.
* | | | keymgr: Add tests for the new get_cert() APIGabriela Moldovan2026-03-121-1/+89
| | | |
* | | | keymgr: Generate test cert specifiers using d-dGabriela Moldovan2026-03-122-24/+26
| | | | | | | | | | | | | | | | | | | | | | | | This will enable us to test against other keymgr APIs (e.g. `list_matching()`), which require some extra trait impls that get generated for free by our new `CertSpecifier` macro.
* | | | keymgr: Reexport the d-d helpersGabriela Moldovan2026-03-121-0/+5
| | | |
* | | | keymgr: Make make_certificate() a top-level functionGabriela Moldovan2026-03-121-31/+32
| | | | | | | | | | | | | | | | This will soon be used by other tests too.
* | | | keymgr: Add test for the auto-generated cert patternsGabriela Moldovan2026-03-121-0/+34
| | | |
* | | | relay-crypto: Add test for cert specifier patternsGabriela Moldovan2026-03-121-1/+8
| | | | | | | | | | | | | | | | | | | | | | | | For relays these are pretty basic (they have no globbing components), because relay certs don't have specifiers (their `ArtiPath`s are identical to the `ArtiPath` of the subject key).
* | | | keymgr: Add new KeyMgr::get_cert_entry() APIGabriela Moldovan2026-03-121-1/+70
| | | | | | | | | | | | | | | | | | | | | | | | This will enable us to retrieve a cert given its `KeystoreEntry`. This is useful for retrieving certificates listed with `KeyMgr::list_matching()`.
* | | | keymgr: Remove old has_certificate() optionGabriela Moldovan2026-03-122-52/+1
| | | | | | | | | | | | | | | | This was replaced by the new `CertSpecifier` d-d macro.
* | | | relay-crypto: Use the new CertSpecifier macroGabriela Moldovan2026-03-122-5/+13
| | | | | | | | | | | | | | | | | | | | This enables the `experimental-api` feature in `tor-keymgr` because `CertSpecifier` is experimental.
* | | | keymgr: Add a new experimental CertSpecifier macroGabriela Moldovan2026-03-121-0/+303
| | | | | | | | | | | | | | | | | | | | This will replace the `has_certificate()` attr from the `KeySpecifier` d-d macro.
* | | | keymgr: Move extract() out of parse_arti_path()Gabriela Moldovan2026-03-121-41/+41
| | | | | | | | | | | | | | | | This will soon be used for parsing the denotators of cert paths too.
* | | | keymgr: Abolish KeyCertificateSpecifier::signing_key_specifier() (fmt)Gabriela Moldovan2026-03-121-3/+1
| | | |
* | | | keymgr: Abolish KeyCertificateSpecifier::signing_key_specifier()Gabriela Moldovan2026-03-125-61/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | We need to be able to parse KeyPaths into KeyCertificateSpecifier, and we can't do that if the signing key is part of the cert specifier (because the signing key doesn't get encoded in the key path, unlike the subject key, which does)
* | | | keymgr: Add a new trait for cert specifier patternsGabriela Moldovan2026-03-122-0/+31
|/ / / | | | | | | | | | | | | These are significantly different from `KeySpecifierPattern`s, so it's best to have a separate trait.
* | | Merge branch 'flags-url' into 'main'Clara Engler2026-03-121-0/+3
|\ \ \ | | | | | | | | | | | | | | | | tor-netdir: Add spec link to flag descriptions See merge request tpo/core/arti!3768
| * | | tor-netdir: Add spec link to flag descriptionsIan Jackson2026-03-111-0/+3
| |/ /
* | | cert-x509: Generate TLS certs with RSA2048 subject keysNick Mathewson2026-03-111-4/+20
| | | | | | | | | | | | | | | | | | | | | We'd rather use p256, but unfortunately C tor has a bug when TLS cert subject keys are not RSA: see tor#41226. Closes #2403.
* | | Merge branch 'anon-request' into 'main'Ian Jackson2026-03-111-3/+44
|\ \ \ | | | | | | | | | | | | | | | | tor-dirclient: Attempt to explain AnonymizedRequest See merge request tpo/core/arti!3767
| * | | tor-dirclient: Use US spellingIan Jackson2026-03-111-6/+6
| | | |
| * | | tor-dirclient: Attempt to explain AnonymizedRequestIan Jackson2026-03-111-3/+44
| |/ /
* | | Merge branch 'cert-denotators2' into 'main'Ian Jackson2026-03-114-30/+143
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | keymgr: Update cert ArtiPath building to use denotator sets Closes #2377 See merge request tpo/core/arti!3754
| * | | keymgr: Do not elide leading empty denotator groupsGabriela Moldovan2026-03-051-2/+5
| | | | | | | | | | | | | | | | Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3754#note_3361904
| * | | keymgr: Replace literal value with constantGabriela Moldovan2026-03-051-1/+1
| | | |
| * | | keymgr: Add test for paths with empty denotator groups (fmt)Gabriela Moldovan2026-03-051-1/+4
| | | |