summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* Merge branch 'less_arti_surface' into 'main'Nick Mathewson2022-08-1111-20/+116
|\ | | | | | | | | | | | | Reduce the arti crate's API surface; improve semver documentation. Closes #522, #530, and #532 See merge request tpo/core/arti!664
| * Add a few dire warnings about main; make main_main experimental.Nick Mathewson2022-08-111-2/+31
| |
| * Document more explicitly what "voiding a semver warranty" entailsNick Mathewson2022-08-112-2/+10
| | | | | | | | Closes #522.
| * arti: `main_main` takes command-line arguments does not call exit()Nick Mathewson2022-08-112-3/+19
| |
| * arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-1110-12/+44
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
| * arti: Add a feature flag for dns-proxy.Nick Mathewson2022-08-112-3/+14
| | | | | | | | | | | | | | It remains on-by-default, so users shouldn't notice a difference, but it may help when we want to save a few bytes of binary size. Closes #532
* | Merge branch 'rtt-estimation-wip' into 'main'eta2022-08-118-0/+530
|\ \ | | | | | | | | | | | | tor-congestion: WIP implementation of RTT estimation See merge request tpo/core/arti!525
| * | tor-congestion: implement the RTT estimation algorithm from prop#324eta2022-08-118-0/+530
|/ / | | | | | | | | | | | | | | | | | | | | This commit implements the round-trip-time estimation algorithm from Tor proposal 324, validating the implementation against the test vectors found in C tor. (Note that at the time of writing, the new test vectors may not be committed to C tor yet, but they will be soon.) This also adds the necessary consensus parameters to `NetParameters`. Some of them have been renamed in order to (hopefully) make them more understandable.
* | Merge branch 'proto-layer-doc' into 'main'Ian Jackson2022-08-111-4/+20
|\ \ | | | | | | | | | | | | | | | | | | tor-proto: Add a comment about the tor-proto layer. Closes #531 See merge request tpo/core/arti!665
| * | tor-proto: Add a comment about the tor-proto layer.Nick Mathewson2022-08-101-0/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | We want to clarify that the tor-proto crate should only know _how_ its objects behave, not _why they behave that way_. (In other words, we can have a "padding strategy" setting on a channel, but not a "general usage" setting.) Closes #531.
| * | Clarify that tor-proto _does_ create timers.Nick Mathewson2022-08-101-4/+2
|/ /
* | Merge branch 'linkspec_refactor_v3' into 'main'Nick Mathewson2022-08-1038-482/+1254
|\ \ | | | | | | | | | | | | | | | | | | Refactor tor-linkspec once more. Closes #428 See merge request tpo/core/arti!662
| * \ Merge branch 'main' into 'linkspec_refactor_v3'Nick Mathewson2022-08-1037-136/+532
| |\ \ | |/ / |/| | | | | # Conflicts: # crates/tor-netdir/semver.md
* | | Merge branch 'storage_timeout_settings' into 'main'Ian Jackson2022-08-091-6/+29
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Decrease the lifetimes for storing descriptors. Closes #527 See merge request tpo/core/arti!669
| * | | Decrease the lifetimes for storing descriptors.Nick Mathewson2022-08-091-6/+29
|/ / / | | | | | | | | | | | | | | | | | | These values were chosen experimentally, based on those from Tor, to save disk space without wasting much bandwidth. Closes #527.
* | | Merge branch 'fix-nightly-ci' into 'main'Nick Mathewson2022-08-091-1/+1
|\ \ \ | | | | | | | | | | | | | | | | fix nighly ci See merge request tpo/core/arti!668
| * | | fix nighly citrinity-1686a2022-08-081-1/+1
| | |/ | |/|
* | | Merge branch 'fix-android-runtime' into 'main'eta2022-08-093-12/+45
|\ \ \ | | | | | | | | | | | | | | | | fix fs-misstrust on android See merge request tpo/core/arti!667
| * | | fix fs-misstrust on androidtrinity-1686a2022-08-083-12/+45
| |/ / | | | | | | | | | | | | | | | it would fail to link at runtime due to missing getgrnam_r in bionic and then it would fail again because some directory is group writeable
* | | Merge branch 'shellexpand' into 'main'eta2022-08-092-27/+6
|\ \ \ | |/ / |/| | | | | | | | Update shellexpand, and switch to non-fork See merge request tpo/core/arti!661
| * | Update shellexpand, and switch to non-forkIan Jackson2022-08-052-27/+6
|/ / | | | | | | | | | | | | | | Now we have bus>1 ownership of the crate name `shellexpand`. I have made a release, and retired `shellexpand-fork`. The new shellexpand release switches to a (quite similarly) unforked version of `dirs`.
* | Merge branch 'establish-rendezvous' into 'main'Ian Jackson2022-08-053-1/+80
|\ \ | | | | | | | | | | | | Implement establish rendezvous cell See merge request tpo/core/arti!651
| * | Implement establish rendezvous cellYuan Lyu2022-08-053-1/+80
|/ /
* | Merge branch 'zeroize' into 'main'Nick Mathewson2022-08-0418-84/+306
|\ \ | | | | | | | | | | | | | | | | | | Revise our handling of the zeroize trait Closes #254 See merge request tpo/core/arti!655
| * | ZeroizeStrategy.md: Clarify which list we're referring to.Nick Mathewson2022-08-041-4/+4
| | |
| * | tor-proto: Use correct SecretBuf in handshakes.Nick Mathewson2022-08-014-17/+27
| | | | | | | | | | | | | | | | | | | | | | | | Everything that is a secret encryption key, or an input that is used to produce a secret encryption key, has to get zeroized. And that's all! Closes #254.
| * | tor-proto: Replace SecretBytes with SecretBuf.Nick Mathewson2022-08-018-63/+65
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This does not yet make sure that `SecretBuf` is used where it _should_ be, but at least it ensures that most uses of `SecretBytes` will indeed act as intended, and make sure that whatever they contain is zeroized. It requires some corresponding changes to method calls for correctness and type conformance.
| * | New SecretBuf type in tor-bytesNick Mathewson2022-08-015-0/+129
| | | | | | | | | | | | | | | | | | | | | | | | | | | This Writer is a simple wrapper around `Vec<u8>` that makes sure that its contents are cleared whenever they are dropped _or reallocated_. The reallocation is the important part here: without that, we risk not zeroizing the first allocation of the buffer.
| * | Add TODO comments about unwanted copies.Nick Mathewson2022-08-011-0/+2
| | |
| * | tor-llcrypto: make AES key objects ZeroizeOnDrop when using opensslNick Mathewson2022-08-011-0/+3
| | | | | | | | | | | | Part of #254.
| * | Stop deriving Zeroize for RsaIdentity.Nick Mathewson2022-08-011-2/+1
| | | | | | | | | | | | These are not secret.
| * | Use the `zeroize` feature in several cratesNick Mathewson2022-08-013-4/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Using `zeroize` here tells these crates that they should make various structures zeroize-on-drop. (This is not yet implemented in `aes` 0.8.1, but support has been merged in the repository for `aes`, so it should go out in the next release.) No corresponding feature flag is needed to enable zeroize-on-drop for `rsa` and `*25519-dalek` private keys.
| * | Initial document describing our plans for zeroizeNick Mathewson2022-08-011-0/+76
| | |
* | | Merge branch 'delete-unused-import' into 'main'Nick Mathewson2022-08-041-2/+1
|\ \ \ | | | | | | | | | | | | | | | | Delete unused Enum and fileinput in maint file See merge request tpo/core/arti!660
| * | | Delete unused Enum and fileinput in maint fileFAMASoon2022-08-041-2/+1
| | | |
* | | | Merge branch 'provide_params_too' into 'main'Nick Mathewson2022-08-045-0/+61
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | Add params() method to NetDirProvider Closes #528 See merge request tpo/core/arti!658
| * | | Finish implementation of params() for DirMgr.Nick Mathewson2022-08-023-0/+59
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Now it maintains an up-to-date set of default parameters to be handed out if there is no directory. Closes #528.
| * | | Add params() method to NetDirProvider, and partial implementationNick Mathewson2022-08-022-0/+2
| |/ / | | | | | | | | | | | | | | | | | | | | | This method will let users get the latest `NetParameters`, with user-configured overrides, even if there is no current directory at all. Part of #528
* | | Merge branch 'inc-rename' into 'main'Ian Jackson2022-08-024-2/+2
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Rename `.inc` and other included files to end in `.rs` Closes #381 See merge request tpo/core/arti!645
| * | | Rename `.inc` and other included files to end in `.rs`eta2022-07-264-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In order to mitigate syntax highlighting issues and a rust-analyzer bug (https://github.com/rust-analyzer/rust-analyzer/issues/10178), rename files that are included with the `include!` macro to have a `.rs` extension. Make sure the included files are outside `src/`, in order to not confuse humans and automated editing tools that might mistake them for valid Rust modules. fixes arti#381
* | | | Merge branch 's-micros-millis' into 'main'Ian Jackson2022-08-021-1/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-rtcompat: s/micros/millis inside a flaky test Closes #515 See merge request tpo/core/arti!644
| * | | | tor-rtcompat: s/micros/millis inside a flaky testeta2022-07-261-1/+1
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The other tests wait for 100 milliseconds; this one waits for 100 *microseconds* for some reason, which meant it was understandably flaky if run on anything less than perfect conditions (arti#515). This is probably a typo, so just change it. fixes arti#515
| | | * tor-proto: Unify the check_match code in channel and handshakeNick Mathewson2022-08-104-46/+49
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This had to become a new internal function, since at the point that the handshake needs this code, it does not yet have a Channel to use. This change made the error messages in the handshake code more informative: and now they require a regex to check. Later, we might want to defer formatting these strings, but I don't think we need to do it now.
| | | * tor-netdir: Add a static assertion about RelayIdType::COUNTNick Mathewson2022-08-104-3/+23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Doing this will make sure that we fix a correctness issue in netdir that will be caused if we add more IDs. (Also add RelayIdType::COUNT in tor-linkspec.)
| | | * Implement `Into<RelayIdRef>` for `&RelayId`.Nick Mathewson2022-08-101-0/+6
| | | | | | | | | | | | | | | | | | | | This will let us use `&RelayId` in all the places that take `Into<RelayIdRef>`.
| | | * Make sure all HasRelayIds constaints allow ?Sized.Nick Mathewson2022-08-102-16/+25
| | | |
| | | * netdir: remove long-unused missing_descriptor_for codeNick Mathewson2022-08-102-23/+2
| | | |
| | | * tor-netdir: Remove or hide some no-longer-used accessors.Nick Mathewson2022-08-101-29/+13
| | | | | | | | | | | | | | | | | | | | The hidden ones are only used to implement higher-level accessors; the others are not used at all.
| | | * tor-netdir: Collapse by_id and by_relay_id into a single fn.Nick Mathewson2022-08-105-58/+71
| | | | | | | | | | | | | | | | | | | | | | | | There are some downstream changes required for this to work, but they are all just unit tests that could no longer infer the type of an Ed25519 key.
| | | * Final (?) API revisions for tor-linkspecNick Mathewson2022-08-1022-223/+335
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With this change, each individual identity type becomes optional. The functions that expose them unconditionally are now in a "legacy" trait that only some downstream types are expected to implement. There are new convenience APIs in HasRelayIds: * to return Option<&keytype>, * to see if one identity-set contains another. This commit will break several downstream crates! For the reviewer's convenience, I will put the fixes for those crates into a series of squash! commits on this one. tor-netdir ---------- Revise tor-netdir to accept optional identities. This required some caveats and workarounds about the cases where we have to deal with a key type that the tor-netdir code does not currently recognize at all. If we start to add more identity types in the future, we may well want more internal indices in this code. tor-proto --------- In order to make tor-proto support optional identities, there were fewer changes than I thought. Some "check" functions needed to start looking at "all the ids we want" rather than at "the two known IDs"; they also needed to accommodate that case where we don't have an ID that we demand. This change will also help with bridges, since we want to be able to connect to a bridge without knowing all of its IDs up front. The protocol currently _requires_ the two current ID types in some places. To deal with that, I added a new `MissingId` error. I also removed a couple of unconditional identity accessors for chanmgr; code should use `target().identity(...)` instead. tor-chanmgr ----------- This is an incomplete conversion: it does not at all handle channel targets without Ed25519 identities yet. It still uses those identities to index its internal map from identity to channel; but it gives a new `MissingId` error type if it's given a channel target that doesn't have one. We'll want to revise the map type again down the road when we implement bridges, but I'd rather not step on the channel-padding work in progress right now. tor-guardmgr ------------ This change is mostly a matter of constructing owned identity types more sensibly, rather than unwrapping them directly. There are some places marked with TODOs where we still depend on particular identity types, because of how the directory protocol works. This will need revisiting when we add bridge support here. tor-circmgr ----------- These changes are just relatively simple API changes in the tests.