|  | Commit message (Collapse) | Author | Age | 
|---|
| | 
| 
| 
| 
| 
| 
| | rand_core does not have a stable release yet, and it is unlikely that
there will be one soon.  To be able to stabilize nitrokey without
waiting for a stable rand_core version, we remove the rand_core::Error
type from the public API and replace it with a Box<dyn error::Error>. | 
| | 
| 
| 
| 
| | The reuse linter verifies that nitrokey-rs complies with the REUSE
specification 2.0. | 
| | 
| 
| 
| 
| 
| | While we want to test the code on multiple platforms and with different
configurations, it is sufficient to execute the linting once.  Therefore
we move the formatting checks into a new lint build. | 
| | 
| 
| 
| 
| 
| 
| | This patch adds license and copyright information to all files to make
nitrokey-rs compliant with the REUSE practices [0].
[0] https://reuse.software/practices/2.0/ | 
| | |  | 
| | 
| 
| 
| 
| 
| | Not all users of the authenticate methods want to use the device after
an error, so implementing From<(T: Device, Error)> for Error makes it
easier for them to discard the device. | 
| | 
| 
| 
| 
| 
| 
| | Previously, we used lossy UTF-8 conversion.  Yet the user should be
notified if we have a problem instead of silently changing the data.
Therefore, we now return an error if we enocunter an invalid UTF-8
string.  This leads to a change in `get_library_version`’s signature. | 
| | 
| 
| 
| 
| | Previously, we just ignored UTF-8 errors.  This patch prepares the
Utf8Error variant so that we are able to return UTF-8 errors. | 
| | |  | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| | This includes:
- using idiomatic Rust
- limiting the scope of unsafe blocks
- simplifying code | 
| | 
| 
| 
| 
| 
| | To reduce the number of casts, we introduce the temp_password_ptr method
that casts the pointer received from the Vec<u8> to a c_char pointer
that can be handled by libnitrokey. | 
| | 
| 
| 
| 
| 
| | Numeric casting might truncate an integer, while into() is only
implemented for numeric types if the cast is possible without
truncation. | 
| | 
| 
| 
| 
| 
| | The Pro and Storage structs may only be created using the connect
functions.  This patch adds a private PhantomData field to the structs
to ensure that the compiler does not allow direct instantiation. | 
| | |  | 
| |\  
| | 
| | 
| | | RFC: https://lists.sr.ht/~ireas/nitrokey-rs-dev/%3C20190117000856.slgb6jwkwd3qu6ey%40localhost%3E | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | | If possible, check specific error codes instead of `is_err()`.  This
makes the code more readable and catches bugs resulting in the wrong
error code.  Also, using the assert_*_err and assert_ok macros yields
error messages containing the expected and the actual value.
To be able to use these macros with the `get_password_safe` method, we
also have to implement `Debug` for `PasswordSafe` and `Device`. | 
| | | 
| | 
| | 
| | 
| | 
| | | The CommandError::Undefined variant has been refactored into
Error::UnexpectedError and CommunicationError::NotConnected and is
therefore no longer needed. | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | | Previously, we returned a CommandError::Undefined if a connect function
failed.  A CommunicationError::NotConnected is a more specific and
better fitting choice.
Once the Try trait has been stabilized, we should return an Option<_>
instead of a Result<_, Error> from the connect functions. | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | | The UnexpectedError variant is used when a libnitrokey function returns
a value that violates the function’s contract, for example if a function
returns a null pointer although it guarantees to never return null.
Previously, we returned a CommandError::Unspecified in these cases. | 
| | | 
| | 
| | 
| | | For example, the WrongSlot error may also be returned for a PWS slot. | 
| | | 
| | 
| | 
| | 
| | | AsStr is automatically implementeded if Display is implemented, so
having a manual as_str() method is not necessary. | 
| | | 
| | 
| | 
| | 
| | 
| | | Communication errors returned by libnitrokey were previously not mapped
to an error type in the nitrokey crate.  We introduce the
CommunicationError enum to represent these errors. | 
| | | 
| | 
| | 
| | 
| | 
| | | Previously, library errors were part of the CommandError enum.  As
command errors and library errors are two different error types, they
should be split into two enums. | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | | An error code can not only indiciate a command error, but also a library
or device communication error.  Therefore, the variant for an unknown
error code should be placed in the top-level Error enum instead of the
CommandError enum. | 
| | | 
| | 
| | 
| | 
| | | We reserve CommandError for errors returned by the Nitrokey device.
Errors during random number generation should have their own type. | 
| | | 
| | 
| | 
| | 
| | 
| | | With the std feature enabled, rand_core::Error implements
std::error::Error, which we require for the error types wrapped in the
Error enum. | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | | These macros allow easier comparisions using the new error type.  This
patch fixes all tests and updates nitrokey-test to 0.2.0 so that it
integrates with the new error structure.
Some tests may still fail until CommunicationError::NotConnected is
actually returned. | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | | This patch changes all public functions to return the Error enum instead
of the CommandError enum.  This breaks the tests which will be fixed
with the next patch.
This patch also adds a placeholder variant Error::CommandError and a
placeholder enum CommandError to make the transition to a new
nitrokey-test version easier. | 
| | | 
| | 
| | 
| | 
| | | The Error enum is a wrapper for the possible error types (currently only
CommandError).  Result<T> is defined as Result<T, Error>. | 
| | | |  | 
| |/  
|   
|   
| | This prepares the refactoring of util::CommandError into multiple enums. | 
| |\ |  | 
| | | |  | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | | The random number generator used for the temporary password produces a
Vec<u8>.  The libnitrokey functions using the temporary password require
a pointer to a c_char.  Previously, we cast the u8 pointer to the
Vec<u8> to a i8 pointer (unsigned to signed).  This leads to a type
mismatch if the char type is not signed.  Therefore we now cast to
c_char instead of i8. | 
| | | 
| | 
| | 
| | | The constants can be used for tests or after a factory reset. | 
| | | |  | 
| | | 
| | 
| | 
| | 
| | 
| | | The FirmwareVersion struct stores the major and minor firmware version
of a Nitrokey device.  We refactor the StorageProductionInfo and
StorageStatus structs to use this new struct. | 
| | | 
| | 
| | 
| | 
| | 
| | | NK_is_AES_supported is not needed for newer firmware versions of the Pro
and Storage, see this discussion for more information:
	https://github.com/Nitrokey/libnitrokey/issues/142 | 
| |/  
|   
|   
|   
|   
|   
| | Since commit 65bff57e6139cc126191d4faabbcf74118932dd2, we use the
nitrokey-test crate to select test cases.  Previously, we used the
features test-pro and test-storage to select test suites.  These
features are now obsolete. | 
| | |  | 
| | 
| 
| 
| 
| | The archlinux build compiles libnitrokey from source.  Now we also
verify that we can use the system libnitrokey version. | 
| | 
| 
| 
| 
| | If libnitrokey has not been built from a clone of the Git repository,
the Git version string may be empty. | 
| | 
| 
| 
| 
| 
| 
| 
| | There seems to be a bug in libnitrokey or the Nitrokey Storage firmware
that causes problems when chaining factory reset and build_AES_keys
without delay (upstream issue [0]).
[0] https://github.com/Nitrokey/nitrokey-storage-firmware/issues/80 | 
| | 
| 
| 
| 
| 
| | The device::clear_new_sd_card_warning used to perform a factory reset
without building an AES key.  This led to errors in tests that assume
that an AES key is present. | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| | The device::factory_reset test used to first change the PINs and then
access the PWS and the OTP data.  If for example the PWS access failed
due to an problem with the AES key, the PINs were not reset.
Now we perform the PWS and OTP access with the old PINs – which is okay
as we do not want to test the PIN change but the factory reset.  If
these preparations fail, the tests is cancelled before the PINs are
changed. | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| | Until the last commit, all empty strings returned by the library were
interepreted as errors.  As the PWS functions return empty strings for
unprogrammed slots, the methods to access the PWS data returned an error
when querying a slot that is not programmed.  Since the last commit,
they return an empty string instead.
This patch restores the old behavior by returning an error instead of an
empty string.  Yet we change the error variant: SlotNotProgrammed
instead of Undefined. | 
| | 
| 
| 
| 
| 
| 
| 
| 
| 
| 
| | An empty string returned from a libnitrokey function can either indicate
an error or be a valid return value.  Previously, we assumed that it
indicates an error.  But instead, we should check the last command
status and use it to decide whether to return the empty string or an
error code.
This breaks the unit tests that assume that empty strings cause errors.
These will be fixed in the next patches. | 
| | |  | 
| | |  |