summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-dirmgr: Don't try to mark consensus usable in a read-only store.Nick Mathewson2023-03-081-4/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Doing this means that any attempt to use a read-only store would crash as soon as it found that the consensus was usable. It seems that this bug was introduced at some point doing all the dirmgr refactors we did over the past year. Perhaps there should be a test for running with a read-only store. Fixes #779
* | | Merge branch 'fuzzing_tor_bytes' into 'main'Ian Jackson2023-03-082-1/+39
|\ \ \ | |/ / |/| | | | | | | | tor-bytes: defend against misuse of extract_n(). See merge request tpo/core/arti!1053
| * | tor-bytes: Add take_rest and read_nested_* to fuzzer.Nick Mathewson2023-03-061-0/+25
| | |
| * | tor-bytes: defend against misuse of extract_n().Nick Mathewson2023-03-061-1/+14
| |/ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, if somebody wrote this code, an attacker could easily use it to cause an OOM panic: ``` let n = r.take_u64(); let items: Vec<Foo> = r.extract_n(n as usize)?; ``` The first line of defense here is not to write protocols like that: we don't actually _have_ any 32-bit counters in our protocol AFAICT. The second line of defense is to pre-check `n` for reasonableness before calling `extract_n`. Here we add a third line of defense: whereas previously we would do `Vec::with_capacity(n)` in `extract_n`, we now allocate an initial capacity of `min(n, r.remaining())`. This ensures that the size of the allocation can't exceed the remaining length of the message, which (for our cell types at least) should prevent it from overflowing or running OOM.
* | Merge branch 'hsonion' into 'main'Ian Jackson2023-03-073-5/+187
|\ \ | | | | | | | | | | | | Impl FromStr and Display for HsId, etc. See merge request tpo/core/arti!1054
| * | Impl Redactable for HsIdIan Jackson2023-03-073-1/+27
| | |
| * | Debug HsId as the .onion; retain the hex printing as {:x}Ian Jackson2023-03-071-3/+10
| | |
| * | impl Display for HsIdIan Jackson2023-03-073-1/+150
| |/
* | Merge branch 'typos' into 'main'Ian Jackson2023-03-072-4/+4
|\ \ | |/ |/| | | | | Fix typos See merge request tpo/core/arti!1050
| * Fix typosDimitris Apostolou2023-03-032-4/+4
|/
* Merge branch 'hs_cert_inner_validation' into 'main'Ian Jackson2023-03-023-85/+200
|\ | | | | | | | | | | | | tor-netdoc: Validate inner certs in HsDesc Closes #744 See merge request tpo/core/arti!1044
| * tor-netdoc: Clarify that we must indeed check cert expiration.Nick Mathewson2023-03-011-3/+1
| |
| * tor-netdoc: Validate inner certs in HsDescNick Mathewson2023-03-013-82/+199
| | | | | | | | | | | | | | | | | | | | | | | | This makes our implementation behave the same as the C tor implementation, by validating all of the expiration and signatures on the certificates in the inner document. (It is still not semantically necessary to check these certs: the document in which they appear is already signed by the key with which they are allegedly signed.) Closes #744
* | Merge branch 'hstidy' into 'main'Nick Mathewson2023-03-013-106/+8
|\ \ | | | | | | | | | | | | Abolish knowledge of HS circuits in circmgr, and tidying See merge request tpo/core/arti!1047
| * | hsclient: Discuss HsClientConnector multiplicity/reuseIan Jackson2023-03-011-3/+7
| | | | | | | | | | | | And delete the associated TODO.
| * | hsclient: Remove TODOs about circular referencesIan Jackson2023-03-011-10/+0
| | | | | | | | | | | | | | | | | | | | | | | | These Arcs are all "downward", referencing items from layers lower in the stack. So they don't cause cycles. There was going to be a cycle involving the `OnionConnector` upcall trait, but we have just abolished that.
| * | hsclient: Abolish knowledge of HS circuits in circmgrIan Jackson2023-03-013-93/+1
|/ / | | | | | | | | | | | | | | | | | | | | Abolish CircMgr::get_or_launch_onion_client and everything to support it. We have decided that `.onion` diversion ccan't/shouldn't occur in tor-circmgr. Probably, it should occur much higher up - arti-client maybe - since it will sometimes need ambient authority (KS_hsc_*). Now all knowledge of HS connections is in tor-hsclient. This gets rid of a layering inversion and the trait needed for tor-circmgr to do the upcall to tor-hsclient.
* | Merge branch 'rename_rend_message' into 'main'Nick Mathewson2023-03-011-15/+18
|\ \ | | | | | | | | | | | | tor-cell: Rename Rendezvous*::message to handshake_info. See merge request tpo/core/arti!1045
| * | tor-cell: Rename Rendezvous*::message to handshake_info.Nick Mathewson2023-03-011-15/+18
| | | | | | | | | | | | Follow-up from !1038
* | | Merge branch 'hsconn' into 'main'Ian Jackson2023-03-0113-97/+1457
|\ \ \ | | | | | | | | | | | | | | | | Implement HS state management See merge request tpo/core/arti!1034
| * | | hsclient isol_map: Use 1:1 notation in diagram to show correspondenceIan Jackson2023-03-011-1/+1
| | | |
| * | | hsclient isol_map: Document invariant, fix comment, terminologyIan Jackson2023-03-011-9/+15
| | | | | | | | | | | | | | | | Use the occupied/vacant terminology that the slotmap docs use.
| * | | hsclient state: Rename rechecks (from attempts) and add clarifying docsIan Jackson2023-03-012-9/+25
| | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2882079
| * | | hsclient keys: Be more explicit about HsClientSecretKeys nullableIan Jackson2023-03-011-5/+9
| | | | | | | | | | | | | | | | | | | | It can contain no keys; state this more prominently, and explain what it represents. Also fix a few typos etc.
| * | | hsclient state: Implement and test MultikeyIsolatedMap::retainIan Jackson2023-03-012-3/+109
| | | |
| * | | hsclient state: Split off MultikeyIsolatedMapIan Jackson2023-03-015-82/+191
| | | |
| * | | hsclient state: Move all the data fields into the tableIan Jackson2023-03-011-28/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2881576 This is a singificant simplification, in fact.
| * | | tor-llcrypto: Add a TODO re impl Redactable for HsIdIan Jackson2023-03-011-0/+1
| | | |
| * | | hsclient: Clarify period task handle TODOIan Jackson2023-03-011-1/+1
| | | |
| * | | hsclient: Document sharing rulesIan Jackson2023-03-012-0/+15
| | | | | | | | | | | | | | | | | | | | Text largely from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2881638
| * | | hsclient state: rustfmtIan Jackson2023-03-011-241/+244
| | | | | | | | | | | | | | | | | | | | | | | | Autogenerated with rustfmt; no code changes. This tidies up the bizarre formatting.
| * | | hsclient state: Lots more doc comments about barriers, structure, etc.Ian Jackson2023-03-011-2/+74
| | | |
| * | | hsclient state: Break `obtain` out into a fnIan Jackson2023-03-011-61/+82
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is getting rather confusing; simply reformtting it won't do, I think. Also there would be much rightward drift. So move the meat out into the new function. (And introduce a convenience alias for its captures.) Docs and reformatting will follow in a moment.
| * | | hsclient state: Demonstrate that our future is now SendIan Jackson2023-03-011-3/+9
| | | |
| * | | hsclient state: Restructure using a scope to drop the mutex guardIan Jackson2023-03-013-20/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Explicit drops don't work. Instead, introduce a scope. We need two scopes, actually: one where we do the initial table wrangling, and one for the retries after relock. So we must put the meat in a closure so we can reuse it. And we must return the flow control as an enum. Bah, etc. Avoid reformatting this for the moment. This makes the delta legible...
| * | | hsclient state: Break out ServiceState::blankIan Jackson2023-03-011-5/+12
| | | | | | | | | | | | | | | | | | | | We're going to have another function which will want this. Leave a convenience closure to capture the runtime.
| * | | hsclient state: Move error inspection before guard re-lock.Ian Jackson2023-03-011-4/+5
| | | | | | | | | | | | | | | | | | | | | | | | This is still correct from a lock hierarchy pov. It moves the guard relock to the end, which is going to be necessary since it is going to have to move right outside the loop.
| * | | hsclient keys: Add a todo to remove spurious OptionIan Jackson2023-03-011-0/+3
| | | |
| * | | hsclient keys: Compare all empty sets of keys as equalIan Jackson2023-03-011-1/+5
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2881575
| * | | hsclient keys: Fix non-equal keys test to provide a (dummy) key (fmt)Ian Jackson2023-03-011-1/+4
| | | |
| * | | hsclient keys: Fix non-equal keys test to provide a (dummy) keyIan Jackson2023-03-011-4/+10
| | | | | | | | | | | | | | | | | | | | We're about to fix the comparison to treat all empty key sets as equal.
| * | | hsclient keys: Provide :none() and Default and .is_empty()Ian Jackson2023-03-011-1/+22
| | | |
| * | | hsclient keys: Fix a missing full stopIan Jackson2023-03-011-1/+1
| | | |
| * | | hsclient state: Test most important code pathsIan Jackson2023-03-014-18/+151
| | | |
| * | | hsclient: Provide some missing debug impls and trace messagesIan Jackson2023-03-012-2/+25
| | | |
| * | | tor-hscrypto: Provide manual Debug impl for HsIdIan Jackson2023-03-011-1/+16
| | | | | | | | | | | | | | | | | | | | This is still not great, but it at least makes the output plausible to read by eye.
| * | | Apply rustfmtIan Jackson2023-03-013-48/+81
| | | |
| * | | hsclient state: Provide one testIan Jackson2023-03-013-0/+109
| | | |
| * | | hsclient: Use a generic to provide a mock for connect()Ian Jackson2023-03-015-21/+78
| | | | | | | | | | | | | | | | This will allow us to test state.rs.
| * | | tor-circmgr: Provide testing feature and TestConfigIan Jackson2023-03-014-0/+52
| | | | | | | | | | | | | | | | Like the similar thing in tor-guardmgr.