| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | |
| | |
| | |
| | | |
This seems a minimal API for such a thing.
|
| | | |
| | |
| | |
| | | |
This repetition was getting repetitive.
|
| |/ /
| |
| |
| |
| | |
The config parsing wants this. Also there are some anomalies in the
types here that ought to be tidied up.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Enforce SafeLogging on the console.
Closes #553
See merge request tpo/core/arti!742
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously we always assumed that the console was ephemeral, and so
we disabled safe logging. But the console can be piped to journald.
And even if we enforce isatty there's no guarantee that the user
isn't using some kind of terminal that logs to disk or something.
Best just to enable SafeLogging unconditionally. I've added a note
about where and how we might re-enable this.
Closes #553.
|
| |\ \ \
| |/ /
|/| |
| | |
| | |
| | |
| | | |
Remaining bridge-and-pt APIs
Closes #543
See merge request tpo/core/arti!741
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Their omission was an oversight.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
This covers only the most basic notions of working with bridges:
that we need a separate set of guards, and that they have to
come from the list of known bridges.
|
| |/ /
| |
| |
| |
| |
| |
| | |
This type goes in tor-guardmgr, since that's where decisions about
circuits' first hops are made.
There are a lot of "todo"s here for us to resolve.
|
| |\ \
| | |
| | |
| | |
| | | |
Implement Introduce2 tor cell
See merge request tpo/core/arti!736
|
| | | |
| | |
| | |
| | |
| | | |
Reuse the same Introduce inner body implementation
of Introduce1.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Add sketched-out pluggable transport APIs (part 1)
See merge request tpo/core/arti!740
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This clarifies that the types apply to pluggable transports only,
and not (typically) to the default plain-old-TCP transport.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
When complete, this crate will handle launching and using pluggable
transports on demand.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
We'll need to sort these out as we implement pluggable transports.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
I've tried to name and structure these for consistency, and
comment reasonably well. We'll still probably want to make changes.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
As with `TransportId`, this type only gets complicated when
`pt-client` is enabled: it's meant to stay simple for relays and
non-PT-using clients.
|
| |/ / / |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Fix nightly clippy
See merge request tpo/core/arti!729
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
Improve docs for ChannelUsage
See merge request tpo/core/arti!737
|
| | | |/ /
| |/| |
| | | |
| | | |
| | | |
| | | |
| | | | |
Try to clarify more that the ChannelUsage is for describing the
usage for one particular channel request, not for the channel as a
whole. This is a potentially confusing point, so we should spell it
out completely.
|
| |\ \ \ \
| |_|_|/
|/| | |
| | | |
| | | | |
CircMgr: Add an accessor for the CircuitBuilder.
See merge request tpo/core/arti!738
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | | |
Without this, actually building circuits manually is a pain.
This API is behind the `experimental-api` feature, and so it does
not require a semver.md entry.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Add a new constant-time is_zero() check for RsaIdentity
See merge request tpo/core/arti!735
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
As a matter of good crypto practice, we shouldn't use
short-circuiting checks to compare keys or key-like objects, since
the amount of time taken by those checks can leak information about
their inputs.
I don't think it's actually _necessary_ to use a constant-time
operation in this case, but let's establish the precedent.
This is a follow-up to !724.
|
| |/ /
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
There are some places in the protocol where we have an all-zero RSA
identity that does not truly represent a key, but rather represents
an absent or unknown key. For these, it's better to use
`RsaIdentity::is_zero` instead of manually checking for a set of
zero bytes: it expresses the intent better, and ensures that the
operation is constant-time.
I am deliberately not introducing a more general IsZero trait here,
or implementing is_zero for anything else: This is the only one we
seem to need right now. We can generalize it later if we have to.
|
| |\ \
| | |
| | |
| | |
| | | |
Implement onion service Introduce1
See merge request tpo/core/arti!724
|
| | | | |
|
| |\ \ \
| |_|/
|/| |
| | |
| | |
| | |
| | | |
enumerate platform with getresuid support
Closes #582
See merge request tpo/core/arti!728
|
| |/ / |
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
force no inlining on internal_macro_test
Closes #570
See merge request tpo/core/arti!727
|
| |/ /
| |
| |
| | |
it may fix this test when running in release, where the function gets inlined, so its name does not appear in the backtrace
|
| |\ \
| | |
| | |
| | |
| | | |
Add a dbg!() to diagnose #570.
See merge request tpo/core/arti!726
|
| |/ /
| |
| |
| |
| | |
This won't fix anything, but it will let us see what the backtrace
looks like when it fails.
|
| |\ \
| | |
| | |
| | |
| | | |
fix compilation error with async-std
See merge request tpo/core/arti!723
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
`TaskSchedule`: give error on `sleep*()` if last handle is dropped
Closes #572
See merge request tpo/core/arti!725
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This fixes an busy-loop.
When the last `TaskHandle` on a `TaskSchedule` is dropped, the
schedule is permanently canceled: whatever operation it was
scheduling should no longer be performed. But our code was broken:
the `sleep()` and `sleep_until_wallclock()` functions don't verify
whether the handles are dropped or not.
This breakage caused an CPU-eating busy-loop in
`sleep_until_wallclock`.
With this patch, we now return a `Result<(), SleepError>` from these
functions.
Fixes #572.
|
| | | | |
|
| | |/
|/| |
|
| |\ \
| |/
|/|
| |
| | |
CI: build-repro: Bump image to 1.63, and other improvements
See merge request tpo/core/arti!716
|