summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | tor-hsservice: IptLocalId: bespoke serde implIan Jackson2023-11-273-2/+31
| | | | | | | | | | | | | | | | | | | | This avoids writing "[42,\n 43,\n ...]" into the storage json, which is (a) wasteful (b) hard to read by hand.
| * | | tor-hsservice: IptLocalId: impl DisplayIan Jackson2023-11-271-0/+11
| | | | | | | | | | | | | | | | This will help us construct ArtiPaths
| * | | tor-hsservice: IptLocalId: provide dummy (test) constructorIan Jackson2023-11-271-0/+10
| | |/ | |/|
* | | Merge branch 'persist-prefix' into 'main'Ian Jackson2023-11-287-171/+285
|\ \ \ | | | | | | | | | | | | | | | | HSS IPT persistence - preparatory work See merge request tpo/core/arti!1755
| * | | tor-hsservice: ipt_set: Fix broken doc linksIan Jackson2023-11-271-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | "tor-hsservice: Make note_publication_attempt a method on PublishIptSet" broke several of these. (Rebasing to insert this at the appropriate point causes conflicts, so I'm leaving it here at the tip.)
| * | | tor-hsservice: import_new_expiry_times: Add another xrefIan Jackson2023-11-271-0/+5
| | | |
| * | | tor-hsservice: ipt_mgr: Split out start_establisherIan Jackson2023-11-271-13/+46
| | | | | | | | | | | | | | | | We're going to need to call this on startup to reestablish existing IPTs.
| * | | tor-hsservice: Make import_new_expiry_times not take &mut IptManager (fmt)Ian Jackson2023-11-271-3/+1
| | | |
| * | | tor-hsservice: Make import_new_expiry_times not take &mut IptManagerIan Jackson2023-11-271-5/+3
| | | | | | | | | | | | | | | | | | | | We are going to want to call this during startup, when we don't have an IptManager yet.
| * | | tor-hsservice: Soup up plumbing for ipt_relay_rotation_timeIan Jackson2023-11-272-10/+11
| | | | | | | | | | | | | | | | | | | | This will mean if we refer to it in more places, we'll still only have one place to change it.
| * | | tor-hsservice: ipt_mgr: Move nascent state records into mod persistIan Jackson2023-11-272-27/+35
| | | | | | | | | | | | | | | | | | | | Let's avoid cluttering the core algorithm file with this, which is going to expand.
| * | | tor-hsservice: Use Instant for planned_retirementIan Jackson2023-11-271-6/+4
| | | | | | | | | | | | | | | | We're going to use time_store, which works nicely with Instants.
| * | | tor-hsservice: Mockable: Don't pass an explicit keymgr any more (fmt)Ian Jackson2023-11-271-5/+1
| | | |
| * | | tor-hsservice: Mockable: Don't pass an explicit keymgr any moreIan Jackson2023-11-271-7/+2
| | | | | | | | | | | | | | | | There's a keymgr in imm now, so just use that.
| * | | tor-hsservice: ipt_mgr: Move KeyMgr to ImmutableIan Jackson2023-11-271-7/+6
| | | | | | | | | | | | | | | | As per the TODO.
| * | | tor-hsservice: Remove a done TODOIan Jackson2023-11-271-2/+0
| | | | | | | | | | | | | | | | This is now in fact plumbed through.
| * | | tor-hsservice: ipt_set: Change last_descriptor_expiry_including_slop (fmt)Ian Jackson2023-11-272-5/+9
| | | | | | | | | | | | | | | | Mandatory format degradation.
| * | | tor-hsservice: ipt_set: Change last_descriptor_expiry_including_slopIan Jackson2023-11-273-52/+125
| | | | | | | | | | | | | | | | Prepare for persistence.
| * | | tor-hsservice: ipt_set: Make note_publication_attempt a method on PublishIptSetIan Jackson2023-11-272-7/+9
| | | | | | | | | | | | | | | | | | | | We're going to move the last_descriptor_expiry_including_slop data out of IptSet.
| * | | tor-hsservice: ipt_set: Make PublishIptSet a structIan Jackson2023-11-274-30/+35
| | | | | | | | | | | | | | | | | | | | We're going to add another field here. No functional change, just much churn.
| * | | tor-hsservice: ipt_set: Make initial state in the constructorIan Jackson2023-11-274-5/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This struct is going to be responsible for loading and storing some persistent state, so it makes sense for it to handle initialisation. This also reduces duplication.
* | | | Merge branch 'keymgr-errors' into 'main'gabi-2502023-11-278-165/+159
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | tor-keymgr: Add a top-level Error enum Closes #1113 See merge request tpo/core/arti!1751
| * | | tor-keymgr: Return InvalidSshKeyData if the ssh key data is invalid (fmt).Gabriela Moldovan2023-11-211-2/+5
| | | |
| * | | tor-keymgr: Return InvalidSshKeyData if the ssh key data is invalid.Gabriela Moldovan2023-11-211-27/+20
| | | | | | | | | | | | | | | | | | | | We were previously returning `internal!`, which is incorrect: this is a type of Arti keystore corruption error, not an internal error.
| * | | tor-keymgr: Add an Arti keystore error type for keys with invalid key data.Gabriela Moldovan2023-11-211-0/+5
| | | |
| * | | tor-keymgr: Remove a TODO that is no longer relevant.Gabriela Moldovan2023-11-211-3/+0
| | | | | | | | | | | | | | | | | | | | | | | | `KeystoreCorruptionError` is now part of `tor_keymgr::Error` and no longer implements `KeystoreError` (the `KeystoreError` trait is now only for keystore-specific errors).
| * | | tor-keymgr: Remove unnecessary trait function.Gabriela Moldovan2023-11-211-7/+0
| | | | | | | | | | | | | | | | We don't use this anymore.
| * | | tor-keymgr: Add a top-level error type (fmt).Gabriela Moldovan2023-11-211-1/+4
| | | |
| * | | tor-keymgr: Add a top-level error type.Gabriela Moldovan2023-11-216-37/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the `tor_keymgr::Error` type was `Box<dyn KeystoreError>`. This forced us to impl `KeystoreError` for any error returned by the keymgr (including those that were not coming from a `Keystore` impl). Now, `tor_keymgr::Error` is an non-exhaustive enum and the `Box<dyn KeystoreError>` opaque error type is only returned from `Keystore` impls The reason we're keeping the `dyn KeystoreError` error type is because it enables `Keystore` implementors to use their own error types. Without it, they would have to choose from our (closed) set of error variants, which may not be suitable for their keystore. See #901.
| * | | tor-keymgr: Add some derives for the dummy KeyType.Gabriela Moldovan2023-11-211-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We are about to add a top-level `tor_keymgr::Error` enum that has a variant that contains a `KeyType`. The error enum needs to be `Clone`, so we need `KeyType` (both the dummy version and the "real" one, because the `err` module is not cfg'd behind the `keymgr` feature) to be `Clone`.
| * | | tor-keymgr: Move ArtiPathError, KeystoreCorruptionError to err.rs.Gabriela Moldovan2023-11-213-54/+53
| | | | | | | | | | | | | | | | | | | | | | | | KeystoreCorruptionError is about to become a variant of the top-level keymgr Error enum (which doesn't exist yet but will be introduced in a future commit).
| * | | tor-keymgr: Inline SshKeyError variants into ArtiNativeKeystoreError.Gabriela Moldovan2023-11-202-43/+34
| | | | | | | | | | | | | | | | An `SshKeyError` *is* an Arti keystore error, so let's unify the two.
* | | | Merge branch 'conditional-content-length' into 'main'Nick Mathewson2023-11-272-19/+16
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Only send Content-Length when needed. See merge request tpo/core/arti!1761
| * | | | Only send Content-Length when needed.Nick Mathewson2023-11-272-19/+16
| | |/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | According to RFC 9110: A user agent SHOULD send Content-Length in a request when the method defines a meaning for enclosed content and it is not sending Transfer-Encoding. For example, a user agent normally sends Content-Length in a POST request even when the value is 0 (indicating empty content). A user agent SHOULD NOT send a Content-Length header field when the request message does not contain content and the method semantics do not anticipate such data. Part of #1024
* | | | Merge branch 'checkeddir_list_and_remove' into 'main'Nick Mathewson2023-11-272-0/+143
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fs-mistrust: Add read_directory and remove_file to CheckedDir. Closes #1117 See merge request tpo/core/arti!1759
| * | | | fs-mistrust: Add read_directory and remove_file to CheckedDir.Nick Mathewson2023-11-272-0/+143
| |/ / / | | | | | | | | | | | | Closes #1117.
* | | | Merge branch 'enable-ntorv3-v2' into 'main'Nick Mathewson2023-11-277-165/+509
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-proto: Add and expose ntorv3 support See merge request tpo/core/arti!1739
| * | | Fix 'target' in doc comment for create_firsthop_ntorJim Newsome2023-11-271-1/+1
| | | |
| * | | Test extend_ntor_v3Jim Newsome2023-11-271-10/+33
| | | |
| * | | Parameterize circuit-extension test by handshake typeJim Newsome2023-11-271-55/+68
| | | |
| * | | Add `ClientCirc::extend_ntor_v3`Jim Newsome2023-11-273-0/+79
| | | |
| * | | tor-proto::circuit::reactor: handle server auxiliary handshake dataJim Newsome2023-11-271-10/+81
| | | |
| * | | Circuit reactor: test ntor-v3 "create"Jim Newsome2023-11-271-43/+101
| | | |
| * | | Add NtorV3SecretKey::generate_for_test and NtorV3SecretKey::newJim Newsome2023-11-271-39/+36
| | | |
| * | | Add PendingClientCirc::create_firsthop_ntor_v3Jim Newsome2023-11-272-0/+44
| | | |
| * | | Add Reactor::create_firsthop_ntor_v3Jim Newsome2023-11-271-0/+50
| | | |
| * | | NtorV3PublicKey: make fields pub(crate), as for NtorPublicKeyJim Newsome2023-11-271-2/+2
| | | |
| * | | Use HandshakeType in Extend2 and CircuitExtender::beginJim Newsome2023-11-274-10/+19
|/ / /
* | | Merge branch 'persist-prefix-keys' into 'main'Nick Mathewson2023-11-247-20/+57
|\ \ \ | |_|/ |/| | | | | | | | Key handling improvements (prompted by HSS IPT persistence) See merge request tpo/core/arti!1756
| * | tor-hscrypto: Add a TODO re re-implementation of x25519 keypair genIan Jackson2023-11-231-0/+5
| | | | | | | | | | | | | | | | | | IMO it is quite undesirable to have multiple copies of "gen a secret key and make a keypair out of it". Add a TODO HSS and and a ref to arti#1137 which is related.