|  | Commit message (Collapse) | Author | Age | 
|---|
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| | The new set_unencrypted_volume_mode method sets the access mode of the
unencrypted volume on the Nitrokey Storage.  Depending on the requested
access mode, it calls either NK_set_unencrypted_read_only_admin or
NK_set_unencrypted_read_write_admin.
Note that this function requires firmware version 0.51 or later.
(Earlier firmware versions used the user PIN.) | 
| | 
| 
| 
| 
| 
| | The VolumeMode enum will be used when setting the access mode for the
unencrypted volume.  It can also be used when refactoring the
VolumeStatus enum in a future release. | 
| | 
| 
| 
| 
| 
| | The update PIN is only used in the Storage tests, so it is moved from
the common tests/util module to the tests/device module.  This fixes
compiler warnings when compiling the other test modules. | 
| | |  | 
| | |  | 
| | 
| 
| 
| 
| 
| | This patch adds the wink method to the Storage struct that lets the
Nitrokey device blink until reconnected.  We do not test this method as
it does not change the state that we can observe. | 
| | 
| 
| 
| 
| 
| 
| | This patch adds the get_library_version function to the main library
module that queries and returns the libnitrokey version.  As the version
fields are static values, we fetch them all at the same time and do not
provide getters for the individual fields. | 
| | |  | 
| | 
| 
| 
| 
| | Previously the totp_error test case in the otp test suite called hotp
methods.  This patch fixes the test case by calling totp metods instead. | 
| | 
| 
| 
| 
| 
| 
| 
| 
| | The connect_* device tests fail when run in a setup with a Pro and
Storage stick present. The problem is that these tests assume only one
stick to be present, and that the corresponding connect function for the
other stick reports an error.
However, in a two stick setup there is no such guarantee. This patch
removes tests for those assumptions. | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| | Three more error codes are defined in libnitrokey but currently reported
as the CommandError::Unknown variant:
  200: representing a string that exceeds a limit
  202: indicating a string that is not in hexadecimal format when it
       should be
  203: suggesting that the target buffer is smaller than the source
       buffer and, hence, too small
This change introduces the CommandError variants StringTooLong,
InvalidHexString and TargetBufferTooSmall, respectively, representing
those errors. | 
| | |  | 
| | 
| 
| 
| 
| 
| | This patch adds the global connect_model function that can be used to
connect to a Nitrokey device of a given model.  Contrary to Pro::connect
and Storage::connect, the model does not have to be set at compile time. | 
| | 
| 
| 
| | connect_model will be used for a public function with the next patch. | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| | This patch introduces the methods enable_hidden_volume,
disable_hidden_volume and create_hidden_volume for the Storage struct to
support the hidden volumes on the Nitrokey Storage.  The enable and
create methods require that the encrypted storage has been enabled.
Contrary to authentication and password safe access, we do not enforce
this requirement in the API as file system operations could have
unwanted side effects and should not performed implicitly. | 
| | |  | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| | We experienced various problems running the tests and while they may or
may not be caused by local setup issues, it is helpful to have more
information than just an indication that an assertion (true/false) was
violated.
To that end, this change adjusts some of the assert!(<func>().is_ok())
to compare against Ok(()) instead. This way, if the result is not the Ok
variant, the error code will get printed. | 
| | 
| 
| 
| | This change adjusts the PWS tests to use the nitrokey-test crate. | 
| | 
| 
| 
| | This change adjusts the OTP tests to use the nitrokey-test crate. | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| | This change is the first in a series to migrate the existing tests to
using the nitrokey-test crate. The crate provides a couple of benefits
over the existing way testing works:
- test execution is automatically serialized (i.e., no more need for
  --test-threads)
- available devices are detected at runtime (i.e., no more need for
  --features test-pro)
- tests capable of running only on a specific device are automatically
  skipped if this device is not present
In addition to that, the crate also offers selection of particular
groups of tests by virtue of the NITROKEY_TEST_GROUP environment
variable. If set (valid values are "nodev", "pro", and "storage") only
tests of the particular group are run (those tests will fail if a
required precondition is not met, i.e., if a device is present but
"nodev" is set, or if the "pro" group is run but no device or a storage
device is present).
Unfortunately, it has some limitations as well. Most importantly Rust
does not allow us to indicate whether a test has been skipped or not.
While it has #[ignore] support, that strictly is a compile-time feature
and, hence, not usable.
This patch in particular pulls in the nitrokey-test crate and adjusts
the existing device tests to make use of it. | 
| | |  | 
| | 
| 
| 
| 
| 
| | Contrary to my previous beliefs, build_aes_key has to be called even
after a factory reset using the Nitrokey API.  This patch updates the
documentation and the unit tests based on this insight. | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| 
| | This patch adds the enable_firmware_update method to the Storage struct
that uses NK_enable_firmware_update to put the Nitrokey Storage into
update mode.  This method is not tested as external tooling is required
to resume normal operation and as it is hard to bail out if an error
occurs. | 
| | 
| 
| 
| 
| 
| 
| 
| | This patch adds the build_aes_key method to the Device trait that uses
the NK_build_aes_key function to build new AES keys on the device.  This
effectively resets the password safe and the encrypted storage.  It is
unclear whether other data (e. g. the one-time passwords) are affected
too. | 
| | 
| 
| 
| 
| 
| 
| | This patch adds the factory_reset_method to the Device trait that uses
the NK_factory_reset function to perform a factory reset.  The tests
verify that the user and admin PIN are reset and that the OTP storage
and the password safe are deleted. | 
| | 
| 
| 
| 
| 
| | This patch adds the change_update_pin method to the Storage struct that
uses the NK_change_update_password function to set the password required
for firmware updates. | 
| | 
| 
| 
| 
| 
| | After a factory reset, the password safe cannot be accessed as its
secret cannot be decrypted.  This patch improves the documentation for
GetPasswordSafe::get_password_safe to reflect this behavior. | 
| | |  | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| | The CommandError::Unknown variant, which is used whenever a reported
error code is not known, makes it close to impossible to determine the
root cause of, say, a one-off error, because all information explaining
what went wrong is discarded.
With this change we adjust the Unknown variant to include the error
report. In addition, we introduce a new CommandError variant, Undefined,
that is used when no error code is available. | 
| | |  | 
| | 
| 
| 
| 
| 
| | This patch adds a test case that changes the PIN when calling
unlock_user_pin.  The previous test case only unlocked the current user
PIN. | 
| | 
| 
| 
| 
| | We switched to rand::thread_rng() which cannot fail.  Therefore the
CommandError::RngError is no longer needed and removed in this patch. | 
| | 
| 
| 
| 
| 
| 
| 
| | This patch adds the force argument to the set_time method in the
ConfigureOtp trait that allows the user to choose whether jumps to the
past are allowed when updating the time.  It is implemented by using the
NK_totp_set_time_soft function.  Previously, jumps where unconditionally
allowed. | 
| | |  | 
| | |  | 
| | |  | 
| | 
| 
| 
| 
| | The Cargo.toml extract in the README does not provide any real value,
but it adds maintenance effort.  Therefore it is removed in this patch. | 
| | 
| 
| 
| 
| 
| | It seems that with newer firmeware, the model string in the lsblk output
is Nitrokey_Storage instead of Nitrokey Storage.  Therefore this patch
replaces underscores with spaces to account for both versions. | 
| | |  | 
| | 
| 
| 
| 
| 
| | As these three enums are scalar values, this patch derives the Clone and
Copy traits for them.  This should avoid unnecessary allocations and
reduce the memory footprint. | 
| | |  | 
| | 
| 
| 
| 
| | This patch adds the function Device::get_model that returns the model of
the connected Nitrokey stick. | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| 
| | This patch updates the rand dependecy to version 0.6.  It also replaces
the OsRng, which is guaranteed to use OS/hardware entropy, with the
thread_rng, which is likely to use OS/hardware entropy as a seed.  The
choice of RNG and the handling of password should be reviewed at a later
point. | 
| | 
| 
| 
| 
| 
| 
| | Currently, the test-no-device feature is used for tests that expect no
Nitrokey to be connected.  Yet test-no-device is equivalent to not
test-pro and not test-storage.  Therefore, this patch removes the
test-no-device feature. | 
| | |  |