summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | maint/thanks: Include some git trailers in acknowledgmentsNick Mathewson2023-05-181-3/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When building our list of acknowledgments, previously we would only include author and committer names. Now we also include anybody listed in the "Reported-by", "Co-authored-by", and "Thanks" trailers.
* | | | Merge branch 'misc' into 'main'Ian Jackson2023-05-232-6/+6
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | Fix misc regressions in nascent HS client code See merge request tpo/core/arti!1197
| * | | tor-hsclient: Mockable: Do concrete calls with UFCSIan Jackson2023-05-231-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Method dispatch rules mean that if the receiver type of the actual function changes, `self.call()` can turn into a purely-recursive call which overflows the stack. Async Rust doesn't have the usual warning for this situation :-(. UFCS is clumsier but doesn't have that problem because it involves much less magical dispatch. Instead of generating a recursive call which overflows the stack, it fails to compile.
| * | | tor-hsclient: Fix MockableClientCirc for ClientCirc changesIan Jackson2023-05-231-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | ClientCirc::begin_dir_stream now takes Arc<Self>. Method resolution rules mean that this code would just recurse, leading to a stack overflow.
| * | | Fix a docs reference to refer to HsClientIntroAuthKeypairIan Jackson2023-05-221-1/+1
|/ / / | | | | | | | | | | | | | | | | | | | | | Fixes warning from cargo -o doc --document-private-items --all-features --workspace This was evidentlhy overlooked during recent replacement of unescorted private keys in the code.
* | | Merge branch 'misc_upgrades' into 'main'Ian Jackson2023-05-227-332/+225
|\ \ \ | |_|/ |/| | | | | | | | Upgrade miscellaneous dependencies See merge request tpo/core/arti!1195
| * | Upgrade notify dependency to 6.0Nick Mathewson2023-05-222-3/+3
| | |
| * | Upgrade async-compression dependency to 0.4.0.Nick Mathewson2023-05-222-7/+7
| | |
| * | Upgrade memmap2 dependency to 0.6.1.Nick Mathewson2023-05-222-3/+3
| | |
| * | Upgrade serde_with dependency to 3.0.0Nick Mathewson2023-05-223-8/+14
| | |
| * | tor-rtcompat: Say default-features with a dash, not an underscore.Nick Mathewson2023-05-221-1/+1
| | | | | | | | | | | | (`cargo-upgrade` warns about this.)
| * | Run "cargo update".Nick Mathewson2023-05-221-312/+199
|/ /
* | Merge branch 'clippy-nightly' into 'main'Ian Jackson2023-05-224-5/+6
|\ \ | | | | | | | | | | | | Fix a few warnings from clippy nightly See merge request tpo/core/arti!1193
| * | chanmgr: fix a unit-default warning from clippy nightly.Nick Mathewson2023-05-181-1/+1
| | | | | | | | | | | | | | | | | | I could also have stopped using `::default()` to construct this (testing-only) object, but I think it makes more sense to turn it into a non-unit object.
| * | guardmgr, netdir: fix some needless-mut warningsNick Mathewson2023-05-182-4/+4
| | | | | | | | | | | | Found by clippy nightly
| * | guardmgr: suppress a clippy-nightly warning.Nick Mathewson2023-05-181-0/+1
| |/ | | | | | | | | I don't love this change, but apparently we are trying for "consistency".
* | Merge branch 'escorted_25519_secrets' into 'main'Nick Mathewson2023-05-189-89/+120
|\ \ | | | | | | | | | | | | | | | | | | Refactor code not to use unescorted ed25519 secrets Closes #798 See merge request tpo/core/arti!1192
| * | hscrypto: Remove an incorrect comment.Nick Mathewson2023-05-181-5/+0
| | | | | | | | | | | | | | | (It said that we want to deprecate all unescorted secret keys; in fact, only unescorted EdDSA secrets are bad.)
| * | key-management.md: Add a note deprecating unescorted ed secretsNick Mathewson2023-05-181-0/+1
| | |
| * | netdoc, hsclient: Update remaining ed25519::SecretKey usersNick Mathewson2023-05-184-25/+24
| | | | | | | | | | | | | | | | | | Fortunately, these are all in experimental code. Closes #798
| * | hscrypto: Replace ed25519 secret keys with keypairsNick Mathewson2023-05-181-42/+32
| | | | | | | | | | | | Part of #798: We no longer use unescorted ed25519 secret keys.
| * | llcrypto: Don't take or return "unescorted" ed25519 keys.Nick Mathewson2023-05-182-20/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Per #798, we want to make sure that we never pass around an `ed25519::SecretKey`; only an `ed25519::Keypair` (or `ExpandedKeypair`). This is because, when you're computing an ed25519 signature, you have to use the public key as one of your inputs, and if you ever use a mismatched public key you are vulnerable to a nonce reuse attack. (For more info see https://moderncrypto.org/mail-archive/curves/2020/001012.html )
| * | llcrypto: Add an `ed25519::ExpandedKeypair` type.Nick Mathewson2023-05-181-0/+25
| | | | | | | | | | | | | | | | | | | | | | | | This is like an `ed25519::Keypair`, except that instead of a `SecretKey` it contains an `ExpandedSecretKey`. We'll be using this to implement #798, where we impose a rule that there must be no "unescorted" ed25519 secret keys.
* | | Merge branch 'virtual_hop' into 'main'Nick Mathewson2023-05-185-38/+245
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | tor-proto: Add support for extending circuits through virtual hops. Closes #726 See merge request tpo/core/arti!1191
| * | proto: Explain "virtual" hops better.Nick Mathewson2023-05-181-0/+4
| | | | | | | | | | | | Based on text from @diziet
| * | proto: Try to improve the documentation in crypto/cell.rsNick Mathewson2023-05-181-24/+86
| | |
| * | proto: Allow circuit Paths to represent virtual hops.Nick Mathewson2023-05-183-14/+57
| | | | | | | | | | | | | | | Sadly, this adds a few more `TODO HS` entries, but I think we can clean them up later after a bit of discussion.
| * | proto: Implement Circuit::extend_virtual.Nick Mathewson2023-05-182-2/+59
| | | | | | | | | | | | | | | | | | | | | There are a few new TODO hs comments, though, and an XXXX I'll need to fix up in the next commit. Implements #726.
| * | tor-proto: Code to construct crypto layers for virtual hops.Nick Mathewson2023-05-183-1/+42
| | | | | | | | | | | | | | | This is fairly straightforward, thanks to our existing design work on this code.
* | | Merge branch 'logging-tweaks' into 'main'Nick Mathewson2023-05-182-4/+4
|\ \ \ | |_|/ |/| | | | | | | | tor-guardmgr, tor-proto: minor logging tweaks See merge request tpo/core/arti!1190
| * | tor-guardmgr, tor-proto: minor logging tweakseta2023-05-182-4/+4
|/ / | | | | | | | | | | | | | | - We make the tor-guardmgr "We have found that {} is usable" line include the word "guard", otherwise it doesn't appear very useful to a user in safe logging mode, since the guard gets replaced with [scrubbed]. - The "Actually got an end cell..." message is downgraded to DEBUG.
* | Merge branch 'hs_handshake' into 'main'Nick Mathewson2023-05-183-130/+230
|\ \ | | | | | | | | | | | | | | | | | | Clean up hs_ntor.rs, add test vectors generated by C tor, and fix some bugs Closes #865 See merge request tpo/core/arti!1189
| * | hs_ntor: several documentation cleanups.Nick Mathewson2023-05-171-6/+14
| | |
| * | hs_ntor: make encrypt_and_mac take a typed public keyNick Mathewson2023-05-171-10/+6
| | | | | | | | | | | | This is still not the most beautiful interface, but it'll do for now.
| * | hs_ntor: remove the last lingering AsRef<[u8]>Nick Mathewson2023-05-171-7/+7
| | |
| * | hs_ntor: Add a test vector case extracted from C tor.Nick Mathewson2023-05-171-0/+104
| | |
| * | hs_ntor: Calculate MAC on introduce1 message correctly.Nick Mathewson2023-05-171-3/+12
| | | | | | | | | | | | | | | | | | There were two bugs here that made the behavior unlike that of C tor: we had swapped the MAC inputs, and we had forgotten to include the public key X in the input.
| * | hs_ntor: Make internal no-rng variants of the handshake functions.Nick Mathewson2023-05-171-2/+25
| | | | | | | | | | | | We'll want these so we can implement some test vectors.
| * | hs_ntor: Move extra data outside of the "input" fields.Nick Mathewson2023-05-171-59/+33
| | | | | | | | | | | | | | | | | | | | | I think that these Input structs had been defined so that we could use hs_ntor interchangeably with other handshakes. The trouble is, though, that it doesn't really work like any other handshakes we have.
| * | hs_ntor: Use MAC implementation from tor-hscryptoNick Mathewson2023-05-171-35/+16
| | | | | | | | | | | | | | | | | | Note that some of the invocations for this function seem to put the key and the message in a questionable order. But that's a thing to figure out later, while debugging.
| * | hs_ntor: Use correct PK types from tor_hscrypto.Nick Mathewson2023-05-171-20/+24
| | |
| * | hs_ntor: Use Subcredential type from tor-hscryptoNick Mathewson2023-05-173-5/+6
| |/
* | Merge branch 'hs-intro-msg-refactor-again' into 'main'Nick Mathewson2023-05-171-26/+83
|\ \ | |/ |/| | | | | | | | | Refactor Introduce messages to support looking at encoded headers Closes #866 See merge request tpo/core/arti!1188
| * cell: Make Introduce2::new testing-only.Nick Mathewson2023-05-171-1/+6
| | | | | | | | | | | | We never want to create one of these from its parts except when we are testing it; we only want to forward an Introduce1 message with a new command on it.
| * cell: Record the text of an INTRODUCE2 headerNick Mathewson2023-05-171-9/+39
| | | | | | | | | | We'll need to store this so that it can later on be used to complete the hs_ntor handshake.
| * cell: extract introduce headers into a new type.Nick Mathewson2023-05-171-20/+42
|/ | | | | | | | We'll want this because our hs_ntor handshake requires access to an encoded version of the header independent from the actual encrypted message. part of #866.
* Merge branch 'info-to-warn' into 'main'gabi-2502023-05-171-5/+8
|\ | | | | | | | | | | | | Change log levels of messages from INFO to others Closes #854 See merge request tpo/core/arti!1172
| * Change log level to debug and warn for certain appropriate situationsSaksham Mittal2023-05-171-5/+8
| | | | | | | | | | | | This commit changes certain log messages to debug for recoverable errors and a warn if all such attempts fail, in order to not clutter up the info messages that end users get to see.
* | Merge branch 'arc_circ' into 'main'gabi-2502023-05-1714-74/+83
|\ \ | | | | | | | | | | | | | | | | | | Refactor ClientCirc APIs to use Arc<ClientCirc>. Closes #846 See merge request tpo/core/arti!1187
| * | Refactor ClientCirc APIs to use Arc<ClientCirc>.Nick Mathewson2023-05-1614-74/+83
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now ClientCirc is no longer `Clone`, and the things that need it to be `Clone` instead return and use an Arc<ClientCirc> We're doing this so that ClientCirc can participate in the RPC system, and so that its semantics are more obvious. Closes #846. Thanks to the type system, this was a much simpler refactoring than I had feared it would be.