| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | |
|
| | |
| |
| |
| |
| | |
We are about to remove `KeyMgr::get_or_generate_with_derived`,
so this rewrites `KeyMgr::get_or_generate` without using it.
|
| | | |
|
| | |
| |
| |
| | |
We are about to remove `KeyMgr::get_or_generate_with_derived`.
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
We don't store public HsId key in the keystore anymore, so this test is
not needed anymore.
|
| | |
| |
| |
| |
| |
| |
| | |
Now that `KeyMgr::generate` returns the generated key, we can tidy up
`get_or_gen_key`.
Part of #1074
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
We will soon remove the `KeyMgr::*_with_derived()` functions, so we need
to rewrite `maybe_generate_hsid` using `KeyMgr::get` and
`KeyMgr::generate`.
An important point to note is that `maybe_generate_hsid` no longer
stores the `KP_hs_id` in the key store. The reason we originally put the
`KP_hs_id` in the keystore in the first place was to support offline
HsId mode. However, offline HsId mode was never fully implemented
(#1194), and the decision to put the public part of the HsId in the
keystore is controversial (#1195). We can revisit this decision when we
implement #1194, but for now, we don't need a separate `KP_hs_Id` entry
in the keystore.
|
| | |
| |
| |
| |
| | |
We're about to stop storing `KP_hs_id` in the keystore, so in
preparation, let's update the callsites that attempt to retrieve it.
|
| | |
| |
| |
| | |
We're about to stop storing the public part of the hsid in the keystore.
|
| | |
| |
| |
| |
| |
| |
| | |
`KeyMgr::generate` is now quite similar to `KeyMgr::get_or_generate`, so
we will soon remove the latter.
Part of #1074
|
| | |
| |
| |
| |
| |
| |
| | |
This will be returned by `KeyMgr::generate` if the key to be generated
already exists and `overwrite` is `false`.
Part of #1074
|
| |\ \
| |/
|/|
| |
| | |
tor-hsservice: Reimplement upload rate-limiting using TrackingNow.
See merge request tpo/core/arti!1951
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This simplifies the publisher code in preparation for #1241
This replaces the overly complicated task-based approach to
rate-limiting with a simpler one, where the publisher has:
* a separate `RateLimited` state that indicates it is rate-limited,
and for how long
* an additional arm in its `run_once()` `select_biased!`, which
checks if the rate-limit has expired
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
We _do_ schedule the rate-limited upload at `now +
UPLOAD_RATE_LIM_THRESHOLD`, see `schedule_rate_lim_upload()`.
|
| |/
|
|
|
| |
This shouldn't be a warning (it's logged when the reactor is shutting
down, not when it crashes).
|
| |\
| |
| |
| |
| |
| |
| | |
Make the OnionServiceState type crate-private.
Closes #1228 and #1261
See merge request tpo/core/arti!1946
|
| |/
|
|
| |
Closes #1261.
|
| |\
| |
| |
| |
| |
| |
| | |
Add some higher-level documentation for tor-hsservice.
Closes #1228
See merge request tpo/core/arti!1945
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Closes #1228.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-hsservice: Rename the service keystore dir to "hss".
Closes #1260
See merge request tpo/core/arti!1949
|
| |/ /
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The onion service keys now live in the `hss/<nickname>` subdirectory
within the keystore.
This layout change is **not** backwards-compatible, so if you want to
use your existing hidden service keys, you will need to manually move
them to `<keystore_root>/hss`.
Closes #1260
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-hsservice: Switch to state_dir for non-key state
Closes #1183
See merge request tpo/core/arti!1941
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Mandatory use line shuffling.
|
| | | |
| | |
| | |
| | | |
This is now tor_persist::Error containing ErrorSource::AlreadyLocked.
|
| | | |
| | |
| | |
| | | |
We're just using fslock-guard now.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
We no longer do replay log locking in IptManager::new. Instead, we
rely on the acquire_instance call in OnionService::launch, which ends
up with ipt_mgr getting an InstanceHandle (which contains a lock
guard).
OnionServiceStateMgr is abolished; it existed to deal with the
generics in the tor_persist::StateMgr API. state_dir has no
generics (other than the T being loaded/stored).
Many places (structs and argument lists) now have state_dir types
which embody a path (or a CheckeDir) along with a lock, rather than
separate path+lock+mistrust.
The creation/startup code uses the new calls from state_dir.
Other more minor changes:
- StartupError::StateDirectoryInaccessible contains tor_persist::Error
- test::create_storage_handles_from_state_dir changed and renamed,
from _from_state_mgr.
- replay::PersistFile's (separate) file lock is now fslock_guard's
|
| | | |
| | |
| | |
| | |
| | |
| | | |
We're going to change the payload of StateDirectoryInaccessible to
tor_persist::Error, since that's what tor_persist::state_dir gives us,
but then we can't use it here.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
state_dir doesn't have the in-memory dummy implementation,
so there will have to be a real directory here.
Do that now, as prep.
|
| | | |
| | |
| | |
| | |
| | | |
The new state_dir types require &mut for storing, which is correct,
but that means we can't have it in Immutable.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
These are here because that's what you get from the tor_persist
singleton StageMgr API (for type erasure reasons). We're going to
change these to tor_persist::state_dir types and those don't involve
Arcs.
|
| | | |
| | |
| | |
| | |
| | | |
Only people who can mutate the state ought to be saving it. Otherwise
there might be concurrent overwrites.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
This doesn't actually change the behaviour with current Rust. But it
avoids bugs and future changes. Relying on drop order for temporary
directory lifetime seems bad.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
And export the type, so callers don't need to depend directly on
fslock_guard; many callers will need to own the returned value, not do
anything else with it.
|