| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |/ /
| |
| |
| |
| |
| |
| |
| | |
Previously we were using backtrace 0.3.39, which has a [bug] that causes
it to segault in some circumstances. I experienced this bug while trying
to fix the minimal-versions build in !1508.
[bug]: https://github.com/rust-lang/backtrace-rs/issues/267
|
| |\ \
| | |
| | |
| | |
| | | |
cargo_audit: Add an exception for RUSTSEC-2022-0093.
See merge request tpo/core/arti!1506
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This is the API deficiency in ed25519-dalek v1 that allows you to
mismatch public and private keys, leading to a (fatal)
double-signing attack. We have worked around this in our current
design, so it's appropriate to suppress this warning for now.
|
| |\ \ \
| |/ /
|/| |
| | |
| | |
| | |
| | | |
Implement circuit binding and start on intro-point establisher logic
Closes #953 and #993
See merge request tpo/core/arti!1472
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This should be enough now to establish real introduction points,
though there is still a lot of work to do. Part of #976.
This has been rebased and edited to incorporate discussions from
!1465.
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Closes #993
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
These values are computed as part of the circuit extension
handshake, and are used as MAC keys to bind `ESTABLISH_INTRO`
messages to a particular circuit so that they can't be replayed.
Part of #993.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This allows us to allow passing in opaque HsMacKey objects,
rather than untyped byte slices.
Additionally, we now check both MAC and signature unconditionally,
to avoid the large timing side-channel. The small timing
side-channel of combining booleans with `&` is considered safe.
Part of #993.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This will be useful in preference to the regular Mac trait for the
places where we need to pass a Mac key around, but we don't need to
support incremental operation.
Part of arti#993, where we want to expose a MAC object without
exposing sensitive data.
|
| |/ / |
|
| |\ \
| |/
|/|
| |
| | |
README: Note more details about upcoming milestones
See merge request tpo/core/arti!1471
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | | |
CI: Remove unneeded install of git in maint-checks
See merge request tpo/core/arti!1492
|
| |/ /
| |
| |
| |
| |
| |
| | |
This was added in 9357a8fd6b22 "ci: add shebang to the GitLab CI" as
part of !990 to the `maint-checks` job; but the actual additional
check was added to the `doc-features` job (by mistake, fixed in
!1490); and, that shebang check script doesn't need git anyway.
|
| |\ \
| | |
| | |
| | |
| | | |
ci: move shebang check into proper CI test
See merge request tpo/core/arti!1490
|
| |/ /
| |
| |
| |
| |
| |
| | |
Currently, the shebang check CI is not executed, as it would need to
fail then.
See !1489
|
| |\ \
| | |
| | |
| | |
| | | |
maint: use relative shebang in `maint/bump_nodep`
See merge request tpo/core/arti!1489
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Disable chutney test again
Closes #810
See merge request tpo/core/arti!1488
|
| | | | | |
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | | |
tor-proto: Implement IncomingStream::discard()
See merge request tpo/core/arti!1484
|
| | | | |
| | | |
| | | |
| | | | |
These functions only ever return `Bug` errors.
|
| | | | | |
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This commit introduces an `IncomingStreamState` enum, which indicates
whether the stream was accepted, discarded, or rejected, or if it is
still pending. The `is_rejected`/`is_accepted` boolean flags are no
longer needed.
Without this change, we'd need to introduce yet another boolean flag
when we implement `discard()` (for the "discarded" state).
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
key-management.md: Use scenarios
See merge request tpo/core/arti!1445
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
Add a missing blank line.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-error: Remove KeystoreFsPermissions variant.
See merge request tpo/core/arti!1487
|
| | | |/ /
| |/| |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
According to the `ErrorKind` lumping guidelines, `KeystoreFsPermissions`
should be lumped with `FsPermissions`: they represent the same type
of error, and their "location" is the same ("Host").
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1315#note_2916455
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
maint: provide no list of grcov formats
See merge request tpo/core/arti!1482
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This commit removes a list we provide for the supported grcov formats.
In my opinion, this is a practice of bad software engineering, as we would then
have to maintain this list by ourselves.
Therefore, this commit removes this list from the `maint/with_coverage` script
and replaces it with a references to the accompanying grcov command.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
arti-client config: Fix bridge handling and test it
Closes #1000
See merge request tpo/core/arti!1481
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
As demanded by rustfmt
|
| | | | | |
| | | | |
| | | | |
| | | | | |
This complements the new `check_bridge_pt` test.
|
| | |/ / /
| | | |
| | | |
| | | | |
This is a bugfix. Perhaps it is a security fix?
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
maint: list the HTML dependencies in coverage
See merge request tpo/core/arti!1485
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
The `maint/coverage` script has a useless option `c`.
This commit removes it.
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Currently, the `maint/coverage` script does not inform about the
dependencies required for generating the HTML output, those are, the
Python packages `bs4` and `lxml`.
This commit fixes that, by updating the help section accordingly.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-proto: Replace IncomingStreamMsg with IncomingStreamRequest.
See merge request tpo/core/arti!1477
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The two enums essentially serve the same purpose, so we don't
need both of them.
This also addresses the TODO that says we should return an error if
`accept_data` is called for a RESOLVE stream.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-proto: Implement `Drop` for `IncomingStream`.
See merge request tpo/core/arti!1476
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
blocking.
Instead of having 2 version of `StreamTarget::close` (a blocking one and
a nonblocking one), we can just return the `oneshot::Receiver` for
receiving the reactor's response and let the caller of
`StreamTarget::close` decide whether to block.
This allows us to reduce some code duplication in the `IncomingStream`
implementation.
|