| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\ \
| | |
| | |
| | |
| | | |
Run fixup-features script and resolve its complaints.
See merge request tpo/core/arti!1205
|
| |/ / |
|
| |\ \
| |/
|/|
| |
| | |
Run "cargo update" in preparation for Thursday release.
See merge request tpo/core/arti!1204
|
| |/ |
|
| |\
| |
| |
| |
| |
| |
| | |
Experimental new stream-ctrl feature
Closes #847
See merge request tpo/core/arti!1198
|
| | | |
|
| | |
| |
| |
| | |
There are some weaknesses and problems here; see TODO notes.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The idea here is that we want to make DataStream visible to the
RPC system without requiring that the RPC session hold the
DataStream itself (or the Reader, or the Writer). We could solve
this problem by making _all_ the state in the DataStream shared,
but that would introduce unnecessary extra locking in our critical
path.
Instead we're creating the notion of a "control handle" that lets
you manage and observe a stream without actually owning the stream.
Right now the only supported functionality is asking for the
stream's circuit.
Part of #847
|
| | |
| |
| |
| |
| | |
(It doesn't do anything yet. It may eventually become always-on.
But for now let's make this API optional. Part of #847)
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | | |
proto: Make PathEntry::Virtual feature-conditional.
See merge request tpo/core/arti!1201
|
| | | |
| | |
| | |
| | |
| | | |
This fixes a warning when building tor-proto without the
`rpc-common` feature.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
rpc: authentication and basic handle manipulation
See merge request tpo/core/arti!1200
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Rationale: Our weak-vs-strong design is a bit confused at the moment
due to concerns about deduplication and capability semantics. It's
not clear that a general "change strong to weak" method is
compatible with what we want to provide.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
I've made doing some design choices here:
* Reserving "rpc" as a prefix for post-authentication
functionality that is not arti-specific.
* Declaring these to be methods on the session rather than methods
on the objects themselves.
There's a problem with defining an API to drop a weak reference; see
comment in code.
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This will make it easier to change the semantics of what exactly we
return, whether it has to be/contain a client, whether you can use
it to look up all the live objects, &etc.
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
rpc: Use the real generational-arena crate
See merge request tpo/core/arti!1203
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Now that generation-arena has merged [@diziet's patch] to clarify
their license, we no longer need to disable it.
[@diziet's patch]: https://github.com/fitzgen/generational-arena/pull/56
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Previously we allowed this license unconditionally. But because of its
non-self-enacting nature, we need the actual notice from its "exhibit A"
to appear somewhere that says that it applies to all the relevant code.
Therefore, we shouldn't take new MPL-2.0 dependencies without
hand-checking them. (I am tentatively allowing option-ext, though,
since we already have an indirect dependency on that crate via
`directories`.)
For more info, see https://gitlab.torproject.org/tpo/core/arti/-/issues/845
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
cell: Make EstablishRendezvous contain a RendCookie.
See merge request tpo/core/arti!1202
|
| |/ / / / |
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
Fix a local-only CPU DoS bug.
Closes #861
See merge request tpo/core/arti!1196
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Previously, there was a bug in the way that our code used our SOCKS
implementations. If the buffer used for a SOCKS handshake became full
without completing the handshake, then rather than expanding the buffer
or closing the connection, our code would keep trying to read into the
zero-byte slice available in the full buffer forever, in a tight loop.
We're classifying this as a LOW-severity issue, since it is only
exploitable by pluggable transports (which are trusted) and by
local applications with access to the SOCKS port.
Closes #861.
Fixes TROVE-2023-001.
Reported-By: Jakob Lell <jakob AT srlabs DOT de>
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
shadow tests: bump to shadow 3.0
See merge request tpo/core/arti!1199
|
| | | | | | |
|
| | | | | | |
|
| | | |_|/
| |/| | |
|
| |\ \ \ \
| |_|_|/
|/| | |
| | | |
| | | | |
maint/thanks: Include some git trailers in acknowledgments
See merge request tpo/core/arti!1194
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Okay, technically we're removing everything between the first `<` and
the `>` at the end of the line.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
When building our list of acknowledgments, previously we would only
include author and committer names.
Now we also include anybody listed in the "Reported-by",
"Co-authored-by", and "Thanks" trailers.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | | |
Fix misc regressions in nascent HS client code
See merge request tpo/core/arti!1197
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Method dispatch rules mean that if the receiver type of the actual
function changes, `self.call()` can turn into a purely-recursive call
which overflows the stack.
Async Rust doesn't have the usual warning for this situation :-(.
UFCS is clumsier but doesn't have that problem because it involves
much less magical dispatch. Instead of generating a recursive call
which overflows the stack, it fails to compile.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
ClientCirc::begin_dir_stream now takes Arc<Self>. Method resolution
rules mean that this code would just recurse, leading to a stack
overflow.
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Fixes warning from
cargo -o doc --document-private-items --all-features --workspace
This was evidentlhy overlooked during recent replacement of unescorted
private keys in the code.
|
| |\ \ \
| |_|/
|/| |
| | |
| | | |
Upgrade miscellaneous dependencies
See merge request tpo/core/arti!1195
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
(`cargo-upgrade` warns about this.)
|
| |/ / |
|
| |\ \
| | |
| | |
| | |
| | | |
Fix a few warnings from clippy nightly
See merge request tpo/core/arti!1193
|