Skip to main content

tor_keymgr/
lib.rs

1#![cfg_attr(docsrs, feature(doc_cfg))]
2#![doc = include_str!("../README.md")]
3// @@ begin lint list maintained by maint/add_warning @@
4#![allow(renamed_and_removed_lints)] // @@REMOVE_WHEN(ci_arti_stable)
5#![allow(unknown_lints)] // @@REMOVE_WHEN(ci_arti_nightly)
6#![warn(missing_docs)]
7#![warn(noop_method_call)]
8#![warn(unreachable_pub)]
9#![warn(clippy::all)]
10#![deny(clippy::await_holding_lock)]
11#![deny(clippy::cargo_common_metadata)]
12#![deny(clippy::cast_lossless)]
13#![deny(clippy::checked_conversions)]
14#![warn(clippy::cognitive_complexity)]
15#![deny(clippy::debug_assert_with_mut_call)]
16#![deny(clippy::exhaustive_enums)]
17#![deny(clippy::exhaustive_structs)]
18#![deny(clippy::expl_impl_clone_on_copy)]
19#![deny(clippy::fallible_impl_from)]
20#![deny(clippy::implicit_clone)]
21#![deny(clippy::large_stack_arrays)]
22#![warn(clippy::manual_ok_or)]
23#![deny(clippy::missing_docs_in_private_items)]
24#![warn(clippy::needless_borrow)]
25#![warn(clippy::needless_pass_by_value)]
26#![warn(clippy::option_option)]
27#![deny(clippy::print_stderr)]
28#![deny(clippy::print_stdout)]
29#![warn(clippy::rc_buffer)]
30#![deny(clippy::ref_option_ref)]
31#![warn(clippy::semicolon_if_nothing_returned)]
32#![warn(clippy::trait_duplication_in_bounds)]
33#![deny(clippy::unchecked_time_subtraction)]
34#![deny(clippy::unnecessary_wraps)]
35#![warn(clippy::unseparated_literal_suffix)]
36#![deny(clippy::unwrap_used)]
37#![deny(clippy::mod_module_files)]
38#![allow(clippy::let_unit_value)] // This can reasonably be done for explicitness
39#![allow(clippy::uninlined_format_args)]
40#![allow(clippy::significant_drop_in_scrutinee)] // arti/-/merge_requests/588/#note_2812945
41#![allow(clippy::result_large_err)] // temporary workaround for arti#587
42#![allow(clippy::needless_raw_string_hashes)] // complained-about code is fine, often best
43#![allow(clippy::needless_lifetimes)] // See arti#1765
44#![allow(mismatched_lifetime_syntaxes)] // temporary workaround for arti#2060
45#![allow(clippy::collapsible_if)] // See arti#2342
46#![deny(clippy::unused_async)]
47#![deny(clippy::string_slice)] // See arti#2571
48//! <!-- @@ end lint list maintained by maint/add_warning @@ -->
49
50// TODO #1645 (either remove this, or decide to have it everywhere)
51#![cfg_attr(not(all(feature = "full", feature = "experimental")), allow(unused))]
52
53// TODO: write more comprehensive documentation when the API is a bit more
54// stable
55
56mod arti_path;
57pub mod config;
58mod err;
59mod key_specifier;
60pub(crate) mod raw;
61#[cfg(any(test, feature = "testing"))]
62pub mod test_utils;
63
64#[cfg(feature = "keymgr")]
65mod keystore;
66#[cfg(feature = "keymgr")]
67mod mgr;
68
69#[cfg(not(feature = "keymgr"))]
70mod dummy;
71
72pub use arti_path::{ArtiPath, DENOTATOR_GROUP_SEP, DENOTATOR_SEP};
73pub use err::{
74    ArtiPathSyntaxError, Error, KeystoreCorruptionError, KeystoreError, UnknownKeyTypeError,
75    UnrecognizedEntry, UnrecognizedEntryError,
76};
77pub use key_specifier::{
78    ArtiPathError, ArtiPathRange, ArtiPathUnavailableError, CTorKeySpecifier, CTorPath,
79    CTorPathError, InvalidKeyPathComponentValue, KeyCertificateSpecifier, KeyPath, KeyPathError,
80    KeyPathInfo, KeyPathInfoBuilder, KeyPathInfoExtractor, KeyPathPattern, KeySpecifier,
81    KeySpecifierComponent, KeySpecifierComponentViaDisplayFromStr, KeySpecifierPattern,
82};
83#[cfg(feature = "onion-service-cli-extra")]
84pub use raw::RawEntryId;
85
86#[cfg(feature = "experimental-api")]
87pub use key_specifier::CertSpecifierPattern;
88
89#[cfg(feature = "keymgr")]
90pub use {
91    keystore::arti::ArtiNativeKeystore,
92    keystore::{Keystore, KeystoreEntryResult},
93    mgr::{KeyMgr, KeyMgrBuilder, KeyMgrBuilderError, KeystoreEntry},
94    ssh_key,
95};
96
97#[cfg(all(feature = "keymgr", feature = "ephemeral-keystore"))]
98pub use keystore::ephemeral::ArtiEphemeralKeystore;
99
100#[cfg(all(feature = "keymgr", feature = "ctor-keystore"))]
101pub use keystore::ctor::{CTorClientKeystore, CTorServiceKeystore};
102
103#[doc(hidden)]
104pub use key_specifier::derive as key_specifier_derive;
105
106pub use tor_key_forge::{
107    EncodableItem, ErasedKey, KeyType, Keygen, KeygenRng, SshKeyAlgorithm, SshKeyData,
108    ToEncodableKey,
109};
110
111derive_deftly::template_export_semver_check! { "0.12.1" }
112
113#[cfg(not(feature = "keymgr"))]
114pub use dummy::*;
115
116/// A boxed [`Keystore`].
117pub(crate) type BoxedKeystore = Box<dyn Keystore>;
118
119#[doc(hidden)]
120pub use {derive_deftly, inventory};
121
122use derive_more::{AsRef, Display, From};
123use serde::{Deserialize, Serialize};
124use std::str::FromStr;
125
126/// A Result type for this crate.
127pub type Result<T> = std::result::Result<T, Error>;
128
129/// An identifier for a particular [`Keystore`] instance.
130//
131// TODO (#1193): restrict the charset of this ID
132#[derive(
133    Clone, Debug, Eq, PartialEq, Ord, PartialOrd, Hash, Serialize, Deserialize, Display, AsRef,
134)]
135#[serde(transparent)]
136#[non_exhaustive]
137pub struct KeystoreId(String);
138
139impl FromStr for KeystoreId {
140    type Err = Error;
141
142    fn from_str(s: &str) -> Result<Self> {
143        Ok(Self(s.into()))
144    }
145}
146
147/// Specifies which keystores a [`KeyMgr`] operation should apply to.
148#[derive(Copy, Clone, Default, Debug, PartialEq, Eq, Hash, From)]
149#[non_exhaustive]
150pub enum KeystoreSelector<'a> {
151    /// Try to use the keystore with the specified ID.
152    Id(&'a KeystoreId),
153    /// Use the primary key store.
154    #[default]
155    Primary,
156}