| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |
| | | |
| | | |
| | | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | | |
| | | |
| | | |
| | | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | | |
| | | |
| | | |
| | | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This renames `KeyIdentity` to `KeySpecifier` so it doesn't get confused
with the concept of an "identity key". `HsClientIdentity` is also
renamed for consistency.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| |\ \ \
| |_|/
|/| |
| | |
| | |
| | |
| | | |
RPC: revise semantics for weak references and object IDs
Closes #848
See merge request tpo/core/arti!1183
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
This lets us simplify our logic a bit for strong references.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
We want each ID to have a unique form every time it is given out,
so that you can't use ID==ID to check whether Object==Object. (See
discussions leading to #848.)
We'd also like the form of object IDs to be a little annoying to
analyze, to discourage people from writing programs that depends on
their particular format. (We are reserving the right to change the
format whenever we want.)
We _don't_ want to use any cryptography here (yet), lest somebody
think that this is an actual security mechanism. (This isn't for
security; it's for encouraging developers to treat IDs as opaque.)
With that in mind, we now lightly obfuscate our generational indices
before returning them.
|
| | | |
| | |
| | |
| | |
| | | |
These are about to become nondeterministic-ish and probably shouldn't
use the Into/TryFrom traits.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Per discussion referenced at #848, we want each operation that
returns a strong object ID to return a new, distinct strong ID.
Note that we no longer need to put strong and weak references in the
same arena; we can clean this code up a lot down the road.
|
| | |/
| |
| |
| |
| |
| | |
Now we generate object IDs that we can parse. This is about to be
obsolete once we change how we generate objects and their IDs for #848,
but we may as well start from a working state.
|
| |\ \
| |/
|/|
| |
| |
| |
| | |
Run fixup-features on our Cargo.tomls, and handle its warnings
Closes #856 and #795
See merge request tpo/core/arti!1182
|
| | | |
|
| | |
| |
| |
| |
| | |
This litters our Cargo.toml files with "XXX" entries that we should
fix.
|
| | | |
|
| |/
|
|
|
|
|
|
|
| |
This does the following:
- Gives every crate a `full`.
- Cause every `full` to depend on `full` from the lower-level
crates.
- Makes every feature listed _directly_ in `experimental` depend
on `__is_experimental`.
|
| |\
| |
| |
| |
| | |
Revise fixup-features to be closer to something we can use
See merge request tpo/core/arti!1180
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
An external edge does not cause its target to be created as a feature.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
I tried to use petgraph, but it was optimized for performance over
usability, and the usability was beyond me.
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| | |
The problem with our old rules is that "reachable from __nonadditive"
and "reachable from experimental" were not themselves sensible
definitions of nonadditive and experimental.
See
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1068#note_2887939
|
| |\ \
| | |
| | |
| | |
| | | |
llcrypto: upgrade x25519-dalek.
See merge request tpo/core/arti!1181
|
| | | |
| | |
| | |
| | | |
The `new` function is deprecated in x25519-dalek 2.0.0-rc.2
|
| |/ /
| |
| |
| |
| |
| |
| |
| | |
This upgrades us to 2.0.0-rc.2, which is the latest in the
not-quite-done-yet 2.0 series.
The only code change that's absolutely needed is opting into the
static_secrets feature.
|
| |\ \
| | |
| | |
| | |
| | | |
hsclient: Build cached descriptor TimerangeBounds from descriptor lifetime.
See merge request tpo/core/arti!1154
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | | |
closed bound.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | | |
We can now get rid of the standalone `intersect_bounds` function.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
By implementing `RangeBounds` for `TimerangeBound`, we get
`RangeBoundsExt` for free. This will enable `parse_decrypt_validate` to
easily compute the intersection of the `TimerangeBound`s its layers.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
`descriptor_fetch_attempt` now returns a `TimerangeBound<HsDesc>` (and
so does `parse_descript_validate`).
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
`parse_decrypt_validate` will need to "peek" inside an encrypted
descriptor (before validating it) to extract the `TimerangeBound` of the
inner layer. This is needed to compute the intersection of the
`TimerangeBound`s of both layers.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This makes `descriptor_ensure` refetch the descriptor if either of its
layers (inner or outer) expires.
Signed-off-by: Gabriela Moldovan <[email protected]>
|