summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * tor-keymgr: Abolish get_or_generate_with_derived.Gabriela Moldovan2024-02-011-58/+1
| |
| * tor-keymgr: Rewrite get_or_generate() using of get() and generate().Gabriela Moldovan2024-02-011-6/+15
| | | | | | | | | | We are about to remove `KeyMgr::get_or_generate_with_derived`, so this rewrites `KeyMgr::get_or_generate` without using it.
| * tor-hsservice: Use read_blind_id_keypair instead of duplicating code.Gabriela Moldovan2024-02-011-16/+6
| |
| * tor-hsservice: Rewrite blind_id_keypair without get_or_generate_with_derived.Gabriela Moldovan2024-02-011-8/+18
| | | | | | | | We are about to remove `KeyMgr::get_or_generate_with_derived`.
| * tor-keymgr: Abolish KeyMgr::generate_with_derived.Gabriela Moldovan2024-02-011-155/+24
| |
| * tor-hsservice: Remove unnecessary loop (fmt).Gabriela Moldovan2024-02-011-12/+12
| |
| * tor-hsservice: Remove unnecessary loop.Gabriela Moldovan2024-02-011-4/+0
| | | | | | | | | | We don't store public HsId key in the keystore anymore, so this test is not needed anymore.
| * tor-hsservice: Rewrite get_or_gen_key using KeyMgr::generate.Gabriela Moldovan2024-02-011-13/+18
| | | | | | | | | | | | | | Now that `KeyMgr::generate` returns the generated key, we can tidy up `get_or_gen_key`. Part of #1074
| * tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate (fmt).Gabriela Moldovan2024-02-011-45/+41
| |
| * tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate.Gabriela Moldovan2024-02-012-109/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon remove the `KeyMgr::*_with_derived()` functions, so we need to rewrite `maybe_generate_hsid` using `KeyMgr::get` and `KeyMgr::generate`. An important point to note is that `maybe_generate_hsid` no longer stores the `KP_hs_id` in the key store. The reason we originally put the `KP_hs_id` in the keystore in the first place was to support offline HsId mode. However, offline HsId mode was never fully implemented (#1194), and the decision to put the public part of the HsId in the keystore is controversial (#1195). We can revisit this decision when we implement #1194, but for now, we don't need a separate `KP_hs_Id` entry in the keystore.
| * tor-hsservice: Read the keypair when deriving the subcredentials.Gabriela Moldovan2024-02-011-5/+8
| | | | | | | | | | We're about to stop storing `KP_hs_id` in the keystore, so in preparation, let's update the callsites that attempt to retrieve it.
| * tor-hsservice: Extract the onion name from the keypair.Gabriela Moldovan2024-02-011-3/+6
| | | | | | | | We're about to stop storing the public part of the hsid in the keystore.
| * tor-keymgr: Make KeyMgr::generate return the generated key.Gabriela Moldovan2024-02-011-4/+12
| | | | | | | | | | | | | | `KeyMgr::generate` is now quite similar to `KeyMgr::get_or_generate`, so we will soon remove the latter. Part of #1074
| * tor-keymgr: Add error variant for when a key shouldn't exist.Gabriela Moldovan2024-02-012-0/+6
| | | | | | | | | | | | | | This will be returned by `KeyMgr::generate` if the key to be generated already exists and `overwrite` is `false`. Part of #1074
* | Merge branch 'publisher-rate-lim' into 'main'gabi-2502024-02-012-126/+85
|\ \ | |/ |/| | | | | tor-hsservice: Reimplement upload rate-limiting using TrackingNow. See merge request tpo/core/arti!1951
| * tor-hsservice: Apply deferred cargo fmt.Gabriela Moldovan2024-02-011-8/+5
| |
| * tor-hsservice: Remove unnecessary trace! log.Gabriela Moldovan2024-02-011-1/+0
| |
| * tor-hsservice: Remove old upload rate-limiting code.Gabriela Moldovan2024-02-011-97/+1
| |
| * tor-hsservice: Reimplement upload rate-limiting using TrackingNow.Gabriela Moldovan2024-02-011-2/+16
| | | | | | | | | | | | | | | | | | | | | | This simplifies the publisher code in preparation for #1241 This replaces the overly complicated task-based approach to rate-limiting with a simpler one, where the publisher has: * a separate `RateLimited` state that indicates it is rate-limited, and for how long * an additional arm in its `run_once()` `select_biased!`, which checks if the rate-limit has expired
| * tor-hsservice: Update docs with the new RateLimited state.Gabriela Moldovan2024-02-011-10/+10
| |
| * tor-hsservice: Add functions for starting/stopping the rate-limiting.Gabriela Moldovan2024-02-011-0/+22
| |
| * tor-hsservice: Add a RateLimited publisher status.Gabriela Moldovan2024-02-011-9/+36
| |
| * tor-hsservice: Remove an unnecessary TODO.Gabriela Moldovan2024-02-011-4/+0
| | | | | | | | | | We _do_ schedule the rate-limited upload at `now + UPLOAD_RATE_LIM_THRESHOLD`, see `schedule_rate_lim_upload()`.
| * tor-hsservice: Downgrade a warn! to debug!.Gabriela Moldovan2024-02-011-2/+2
|/ | | | | This shouldn't be a warning (it's logged when the reactor is shutting down, not when it crashes).
* Merge branch 'hide_onionservicestate' into 'main'Nick Mathewson2024-02-011-17/+22
|\ | | | | | | | | | | | | Make the OnionServiceState type crate-private. Closes #1228 and #1261 See merge request tpo/core/arti!1946
| * Make the OnionServiceState type crate-private.Nick Mathewson2024-02-011-17/+22
|/ | | | Closes #1261.
* Merge branch 'high-level-docs' into 'main'Nick Mathewson2024-02-012-7/+59
|\ | | | | | | | | | | | | Add some higher-level documentation for tor-hsservice. Closes #1228 See merge request tpo/core/arti!1945
| * Correct description of parametersIan Jackson2024-02-011-1/+1
| |
| * Note that old state is not yet removedIan Jackson2024-02-011-0/+3
| |
| * Add some higher-level documentation for tor-hsservice.Nick Mathewson2024-01-312-7/+56
| | | | | | | | Closes #1228.
* | Merge branch 'rename-hs-dir' into 'main'gabi-2502024-02-014-19/+19
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Rename the service keystore dir to "hss". Closes #1260 See merge request tpo/core/arti!1949
| * | tor-hsservice: Rename the service keystore dir to "hss".Gabriela Moldovan2024-02-014-19/+19
|/ / | | | | | | | | | | | | | | | | | | | | The onion service keys now live in the `hss/<nickname>` subdirectory within the keystore. This layout change is **not** backwards-compatible, so if you want to use your existing hidden service keys, you will need to manually move them to `<keystore_root>/hss`. Closes #1260
* | Merge branch 'state-use' into 'main'Ian Jackson2024-02-0114-201/+196
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Switch to state_dir for non-key state Closes #1183 See merge request tpo/core/arti!1941
| * | tor-hsservice: Use tor_persist::state_dirIan Jackson2024-02-012-2/+4
| | |
| * | tor-hsservice: Remove now-unused importsIan Jackson2024-02-013-8/+4
| | |
| * | tor-hsservice: tests: create_storage_handles: use a real directory (churn)Ian Jackson2024-02-011-1/+1
| | | | | | | | | | | | Mandatory use line shuffling.
| * | tor-hsservice: Abolish StartupError::StateLockedIan Jackson2024-02-011-5/+0
| | | | | | | | | | | | This is now tor_persist::Error containing ErrorSource::AlreadyLocked.
| * | tor-hsservice: Drop now-unused fslock dependencyIan Jackson2024-02-014-4/+0
| | | | | | | | | | | | We're just using fslock-guard now.
| * | tor-hsservice: Use tor_persist::state_dir, etc. (fmt)Ian Jackson2024-02-013-22/+28
| | |
| * | tor-hsservice: Use tor_persist::state_dirIan Jackson2024-02-017-150/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We no longer do replay log locking in IptManager::new. Instead, we rely on the acquire_instance call in OnionService::launch, which ends up with ipt_mgr getting an InstanceHandle (which contains a lock guard). OnionServiceStateMgr is abolished; it existed to deal with the generics in the tor_persist::StateMgr API. state_dir has no generics (other than the T being loaded/stored). Many places (structs and argument lists) now have state_dir types which embody a path (or a CheckeDir) along with a lock, rather than separate path+lock+mistrust. The creation/startup code uses the new calls from state_dir. Other more minor changes: - StartupError::StateDirectoryInaccessible contains tor_persist::Error - test::create_storage_handles_from_state_dir changed and renamed, from _from_state_mgr. - replay::PersistFile's (separate) file lock is now fslock_guard's
| * | tor-hsservice: Introduce StartupError::StateDirectoryInaccessibleIoIan Jackson2024-02-012-5/+26
| | | | | | | | | | | | | | | | | | We're going to change the payload of StateDirectoryInaccessible to tor_persist::Error, since that's what tor_persist::state_dir gives us, but then we can't use it here.
| * | tor-hsservice: tests: create_storage_handles: use a real directory (fmt)Ian Jackson2024-02-011-1/+5
| | |
| * | tor-hsservice: tests: create_storage_handles: use a real directoryIan Jackson2024-02-013-5/+15
| | | | | | | | | | | | | | | | | | | | | state_dir doesn't have the in-memory dummy implementation, so there will have to be a real directory here. Do that now, as prep.
| * | tor-hsservice: ipt_mgr: Move storage handle to stateIan Jackson2024-02-012-9/+11
| | | | | | | | | | | | | | | The new state_dir types require &mut for storing, which is correct, but that means we can't have it in Immutable.
| * | tor-hsservice: impl state_dir::InstanceIdentity for HsNicknameIan Jackson2024-02-011-0/+10
| | |
| * | tor-hsservice: storage: Move Arcs into type aliasesIan Jackson2024-02-014-12/+12
| | | | | | | | | | | | | | | | | | | | | These are here because that's what you get from the tor_persist singleton StageMgr API (for type erasure reasons). We're going to change these to tor_persist::state_dir types and those don't involve Arcs.
| * | tor-hsservice: ipt_set: Make store method take &mut selfIan Jackson2024-02-011-1/+1
| | | | | | | | | | | | | | | Only people who can mutate the state ought to be saving it. Otherwise there might be concurrent overwrites.
| * | tor-hsservice: tests: Add a missing drop callIan Jackson2024-02-011-0/+2
| | | | | | | | | | | | | | | | | | This doesn't actually change the behaviour with current Rust. But it avoids bugs and future changes. Relying on drop order for temporary directory lifetime seems bad.
| * | tor-persist: state_dir: Add some missing Clone and Debug implsIan Jackson2024-02-011-5/+5
| | |
| * | tor-persist: state_dir: Introduce way to get at underlying lock guardIan Jackson2024-02-013-3/+40
| | | | | | | | | | | | | | | | | | And export the type, so callers don't need to depend directly on fslock_guard; many callers will need to own the returned value, not do anything else with it.