aboutsummaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | keymgr: Add test for paths with empty denotator groupsGabriela Moldovan2026-03-051-0/+12
| | | |
| * | | keymgr: Add more tests for cert ArtiPath construction (fmt)Gabriela Moldovan2026-03-052-9/+9
| | | |
| * | | keymgr: Add more tests for cert ArtiPath constructionGabriela Moldovan2026-03-051-2/+17
| | | | | | | | | | | | | | | | | | | | This commit is intentionally misindented to make reviewing the diff a bit easier.
| * | | keymgr: Update cert ArtiPath building to use denotator groupsGabriela Moldovan2026-03-051-7/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In a certificate's `ArtiPath`, the `ArtiPath` of the subject key is now separated from the certificate denotators by `@`. This will enable us to derive the subject key `ArtiPath` from the `ArtiPath` of its certificate. In practice, this change is a no-op for the relay implementation, because none of our certificates have certificate denotators. For instance, the `ArtiPath` of the for the `KP_relaysign_ed` certificate (`KP_relaysign_ed` signed with `KS_relayid_ed`) is of the form `relay/relaysign_ed+<valid_until>` (the only denotators here are the denotators of the subject key). It's important to note that the certifying key is not encoded in the `ArtiPath` of the certificate. The implication is that if we'll ever need to have multiple certs for the same subject key, signed with different with different certifying keys, those certificates will be distinguished by their certificate denotator group. So if we ever need a second certificate for `KP_relaysign_ed`, certified with something other than `KP_relaysign_ed`, it will need to be of the form `relay/relaysign_ed+<valid_until>@<CERT_DENOS>`, where `<CERT_DENOS>` is a list of `+`-separated certificate denotators. Closes #2377
| * | | keymgr: Support having multiple denotator groups within an ArtiPathGabriela Moldovan2026-03-052-4/+14
| | | | | | | | | | | | | | | | | | | | | | | | This will enable us to parse certificate paths that consist of the `ArtiPath` of the subject key, followed by the denotator group of the certificate.
| * | | keymgr: Move denotator group validation to a separate functionGabriela Moldovan2026-03-051-3/+10
| | | |
| * | | keymgr: Update ArtiPath docs with the new denotator rulesGabriela Moldovan2026-03-051-3/+21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This introduces the concept of a "denotator group", and new syntax for separating denotator groups within an ArtiPath. The implementation will follow in a separate commit.
| * | | keymgr: Implement KeySpecifier for KeyCertificateSpecifiersGabriela Moldovan2026-03-052-5/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `KeyCertificateSpecifiers` have an `ArtiPath`, so it's only natural to retrieve it via this new `KeySpecifier` implementation. This replaces the old, ad-hoc `ArtiPath` building from the `KeyMgr` implementation: IMO, the `KeyMgr` impl is the wrong place to build these `ArtiPath`s (ideally they should remain opaque to the `KeyMgr`).
* | | | Merge branch 'netdir-exit-flag' into 'main'Ian Jackson2026-03-111-0/+4
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-netdir: Add is_flagged_exit() to RelayDetails See merge request tpo/core/arti!3752
| * | | | tor-netdir: Simply exit documentationClara Engler2026-03-091-7/+0
| | | | | | | | | | | | | | | | | | | | No need to over-engineer this, let's keep it simple.
| * | | | tor-netdir: Add is_flagged_exit() to RelayDetailsClara Engler2026-03-051-0/+11
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a method called `is_flagged_exit` to `RelayDetails` in order to check whether the node is considered to be usable as an exit or not. In the Tor VPN app, we need this feature for generating a list of exit relays (per country). Right now, we do this in an incorrect way by only checking on whether port 443 is in the exit policy, which is not a sufficient criteria.
* | | | Merge branch 'rpc_stop_writing' into 'main'Ian Jackson2026-03-111-0/+4
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | rpc: Fix a bug related to stop_writing See merge request tpo/core/arti!3762
| * | | rpc: Actually call the stop_writing method when data is all written!Nick Mathewson2026-03-101-0/+4
| | | | | | | | | | | | | | | | | | | | Without this, the poll() method wouldn't actually perform as advertised.
* | | | Merge branch 'keymgr-test-cleanup' into 'main'David Goulet2026-03-101-212/+182
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | keymgr: Test helper cleanup See merge request tpo/core/arti!3761
| * | | | keymgr: Remove unnecessary TestItem building (fmt)Gabriela Moldovan2026-03-101-1/+4
| | | | |
| * | | | keymgr: Remove unnecessary TestItem buildingGabriela Moldovan2026-03-101-4/+1
| | | | |
| * | | | keymgr: Remove unnecessary parenthesesGabriela Moldovan2026-03-101-1/+1
| | | | | | | | | | | | | | | | | | | | Resolves a clippy warning.
| * | | | keymgr: Replace .find(...).is_some() with .any() (fmt)Gabriela Moldovan2026-03-101-9/+4
| | | | |
| * | | | keymgr: Replace .find(...).is_some() with .any()Gabriela Moldovan2026-03-101-3/+2
| | | | | | | | | | | | | | | | | | | | Resolves a clippy warning.
| * | | | keymgr: Replace Result<> with type alias (fmt)Gabriela Moldovan2026-03-101-5/+5
| | | | |
| * | | | keymgr: Replace match with if letGabriela Moldovan2026-03-101-4/+1
| | | | | | | | | | | | | | | | | | | | As suggested by clippy
| * | | | keymgr: Replace Result<> with type alias (fmt)Gabriela Moldovan2026-03-101-3/+5
| | | | |
| * | | | keymgr: Replace Result<> with type aliasGabriela Moldovan2026-03-101-1/+1
| | | | |
| * | | | keymgr: Remove unnecessary type annotationGabriela Moldovan2026-03-101-4/+1
| | | | |
| * | | | keymgr: Replace macro-generated Keystore impls with a single Keystore type (fmt)Gabriela Moldovan2026-03-101-162/+156
| | | | |
| * | | | keymgr: Replace macro-generated Keystore impls with a single Keystore typeGabriela Moldovan2026-03-101-33/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This doesn't really need to be macro-generated, because these impls only differ in the `KeystoreId`. The code is intentionally misindented to make reviewing the diff a bit easier. A future commit will reformat it all.
| * | | | keymgr: Move unrecognized entry building logic out of macro (fmt)Gabriela Moldovan2026-03-101-22/+14
| | | | |
| * | | | keymgr: Move unrecognized entry building logic out of macroGabriela Moldovan2026-03-101-29/+34
| | |/ / | |/| | | | | | | | | | | | | | I am about to remove this macro altogether and simplify the keystore impls, so I am preemptively moving this into a separate function.
* | | | tor-dirserver: Require AuthCerts to make progressClara Engler2026-03-091-37/+54
| | | | | | | | | | | | | | | | | | | | | | | | This commit changes the functionality of the AuthCerts state to only report a success when at least a single certificate was included in the response.
* | | | tor-dirserver: Add retry logic POC TODOClara Engler2026-03-091-0/+4
| | | | | | | | | | | | | | | | | | | | Adds a small TODO with regard to a potentially broken retry logic in the proof-of-concept.
* | | | tor-dirserver: SQL comment for unsigned hashesClara Engler2026-03-091-0/+11
| | | | | | | | | | | | | | | | | | | | This commit documents why and how we use the `unsigned_` fields in the `consensus_router_descriptor_member` table alongside SQL limitations.
* | | | tor-dirserver: Move POC to own moduleClara Engler2026-03-092-73/+91
| | | | | | | | | | | | | | | | | | | | This commit moves dirserver POC code to an own module to semantically indicate it is not production ready.
* | | | tor-dirserver: Document stream dropClara Engler2026-03-091-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | This commit documents why we drop the HTTP TCP stream and why this is fine, namely because this is compliant HTTP/1.0 behavior where there is no connection reuse.
* | | | tor-dirserver: Link to discussion regarding TODOClara Engler2026-03-091-0/+3
| | | | | | | | | | | | | | | | | | | | This commit links the discussion for the TODO for the dirmirror's handling of forward compatibility with netdocs.
* | | | parse2: Add TODO for netstatus traitClara Engler2026-03-091-0/+5
| | | | | | | | | | | | | | | | | | | | This commit adds a TODO to implement a trait combining the common fields in a network status documents.
* | | | tor-dirserver: Use collect instead of mutable forClara Engler2026-03-091-18/+9
| | | |
* | | | tor-dirserver: Remove fiddly SQL CHECKClara Engler2026-03-091-5/+1
| | | |
* | | | tor-dirserver: Use tor-llcrypto for digestsClara Engler2026-03-092-7/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces the uses of sha1, sha2, and sha3 with their respective pedants from tor-llcrypto for better consistency. Internally, they still use the same logic and underlying crates but let's use this encapsulation nonetheless.
* | | | tor-dirserver: Improve hash wrapper macro docsClara Engler2026-03-091-0/+19
| | | |
* | | | tor-dirserver: Move schema to own fileClara Engler2026-03-092-170/+167
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit moves the database schema into schema_v1.sql and uses include_str to include it. For now, the schema lives in the `src/` directory. If this becomes a problem because we get more schemas and schema upgrades, we can move it into another sub directory, but let's not overengineer the hierarchy there.
* | | | tor-dirserver: PoC for FSM main loopClara Engler2026-03-091-2/+73
| | | | | | | | | | | | | | | | | | | | This commit implements a PoC serving as the main loop for the FSM, demonstrating how invocation and error handling works.
* | | | tor-dirserver: TODO a torspec DoS issueClara Engler2026-03-091-0/+9
| | | | | | | | | | | | | | | | Discussed with nickm on IRC, there will be a torspec issue soon.
* | | | tor-dirserver: Implement `State::AuthCerts`Clara Engler2026-03-093-7/+986
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit implements the logic required for retrieving, validating, and storing authority certificates. The implementation determines the missing certificates by looking at the signatories of the unvalidated consensus and checking them in the db. Afterwards, they will be queried and individually filtered and verified before being inserted into the database. A return of this implementation notably DOES NOT imply all missing certificates have been downloaded. This was chosen for a simplified retry logic.
* | | | tor-dirserver: Add `StaticEngine::send_request()`Clara Engler2026-03-092-47/+104
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a new method to static engine that serves as a convenience wrapper around `tor_dirclient::send_request`. The reason for that is, that fetch_consensus is not the only method that requires performing download requests, so it makes sense to generalize it. Besides, it also adds support for parsing multiple netdocs alongside storing their raw variant, which is required for inserting them into the database at one point eventually.
* | | | tor-dirserver: Add IsFatal traitClara Engler2026-03-092-19/+24
| | | | | | | | | | | | | | | | | | | | This commit adds the IsFatal trait to the err module for having a generic signature for the fatality of certain error variants.
* | | | tor-dirservert: Implement FetchConsensus stateClara Engler2026-03-092-2/+167
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit implements the `FetchConsensus` state by adding a method to `StaticEngine` called `fetch_consensus`, which retrieves the consensus from an upstream directory authority. Likewise, it also implements a new error type called `AuthorityRequestError`. The retry logic is handled externally which will be done in later commits.
* | | | tor-dirserver: Derive PartialEq and Eq for StateClara Engler2026-03-091-2/+2
| | | | | | | | | | | | | | | | Required to test state transitions properly.
* | | | tor-dirserver: PreferredRuntime in StaticEngineClara Engler2026-03-091-2/+9
| | | | | | | | | | | | | | | | This is required for compatibility with other crates in arti.
* | | | tor-dirserver: Remove unused error variantsClara Engler2026-03-091-62/+0
| | | |
* | | | tor-dirserver: Remove download moduleClara Engler2026-03-092-367/+0
| | | | | | | | | | | | | | | | | | | | This commit removes the download manager module because it does not fit well into the mental model of our current finite state machine anymore.