summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | Merge branch 'virtual_conditional' into 'main'Ian Jackson2023-05-242-0/+3
|\ \ | | | | | | | | | | | | proto: Make PathEntry::Virtual feature-conditional. See merge request tpo/core/arti!1201
| * | proto: Make PathEntry::Virtual feature-conditional.Nick Mathewson2023-05-232-0/+3
| | | | | | | | | | | | | | | This fixes a warning when building tor-proto without the `rpc-common` feature.
* | | Merge branch 'rpc-auth-and-meta' into 'main'Nick Mathewson2023-05-248-114/+340
|\ \ \ | | | | | | | | | | | | | | | | rpc: authentication and basic handle manipulation See merge request tpo/core/arti!1200
| * | | rpc: Remove downgrade_owned for nowNick Mathewson2023-05-244-42/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Rationale: Our weak-vs-strong design is a bit confused at the moment due to concerns about deduplication and capability semantics. It's not clear that a general "change strong to weak" method is compatible with what we want to provide.
| * | | rpc: Disable auth:get_rpc_protocol for now.Nick Mathewson2023-05-241-0/+8
| | | |
| * | | rpc: Implement functionality to remove objects from a sessionNick Mathewson2023-05-245-5/+135
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I've made doing some design choices here: * Reserving "rpc" as a prefix for post-authentication functionality that is not arti-specific. * Declaring these to be methods on the session rather than methods on the objects themselves. There's a problem with defining an API to drop a weak reference; see comment in code.
| * | | rpc: fix documentation for methods in Context.Nick Mathewson2023-05-241-6/+4
| | | |
| * | | rpc: update rpc-meta-draft with new behavior.Nick Mathewson2023-05-241-3/+7
| | | |
| * | | rpc: Make the top-level returned object a "session".Nick Mathewson2023-05-244-38/+67
| | | | | | | | | | | | | | | | | | | | | | | | This will make it easier to change the semantics of what exactly we return, whether it has to be/contain a client, whether you can use it to look up all the live objects, &etc.
| * | | rpc: Implement auth:query.Nick Mathewson2023-05-231-1/+39
| | | |
| * | | rpc: Implement the auth:get_rpc_protocol method.Nick Mathewson2023-05-231-0/+49
| | | |
| * | | rpc: move existing auth code to new module.Nick Mathewson2023-05-232-72/+84
| | | |
* | | | Merge branch 'real_generational_arena' into 'main'Nick Mathewson2023-05-244-80/+34
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | rpc: Use the real generational-arena crate See merge request tpo/core/arti!1203
| * | | | rpc: Remove fake_generational_arenaNick Mathewson2023-05-233-79/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now that generation-arena has merged [@diziet's patch] to clarify their license, we no longer need to disable it. [@diziet's patch]: https://github.com/fitzgen/generational-arena/pull/56
| * | | | maint/check_license: Make MPL-2.0 into an allow-listNick Mathewson2023-05-231-1/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously we allowed this license unconditionally. But because of its non-self-enacting nature, we need the actual notice from its "exhibit A" to appear somewhere that says that it applies to all the relevant code. Therefore, we shouldn't take new MPL-2.0 dependencies without hand-checking them. (I am tentatively allowing option-ext, though, since we already have an indirect dependency on that crate via `directories`.) For more info, see https://gitlab.torproject.org/tpo/core/arti/-/issues/845
* | | | | Merge branch 'cookie_in_est_intro' into 'main'Ian Jackson2023-05-242-6/+3
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | cell: Make EstablishRendezvous contain a RendCookie. See merge request tpo/core/arti!1202
| * | | | cell: Make EstablishRendezvous contain a RendCookie.Nick Mathewson2023-05-232-6/+3
|/ / / /
* | | | Merge branch 'socks-read-fix' into 'main'Nick Mathewson2023-05-232-0/+25
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | Fix a local-only CPU DoS bug. Closes #861 See merge request tpo/core/arti!1196
| * | | Fix a local-only CPU DoS bug.Nick Mathewson2023-05-232-0/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, there was a bug in the way that our code used our SOCKS implementations. If the buffer used for a SOCKS handshake became full without completing the handshake, then rather than expanding the buffer or closing the connection, our code would keep trying to read into the zero-byte slice available in the full buffer forever, in a tight loop. We're classifying this as a LOW-severity issue, since it is only exploitable by pluggable transports (which are trusted) and by local applications with access to the SOCKS port. Closes #861. Fixes TROVE-2023-001. Reported-By: Jakob Lell <jakob AT srlabs DOT de>
* | | | Merge branch 'shadow-v3' into 'main'Nick Mathewson2023-05-234-21/+42
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | shadow tests: bump to shadow 3.0 See merge request tpo/core/arti!1199
| * | | | shadow-ci: check for successful transfers on bridge-client as wellJim Newsome2023-05-221-7/+9
| | | | |
| * | | | shadow ci: bump tgenJim Newsome2023-05-221-1/+1
| | | | |
| * | | | shadow ci: bump shadowJim Newsome2023-05-224-14/+33
| | |_|/ | |/| |
* | | | Merge branch 'thanks_trailer' into 'main'Ian Jackson2023-05-231-4/+28
|\ \ \ \ | |_|_|/ |/| | | | | | | | | | | maint/thanks: Include some git trailers in acknowledgments See merge request tpo/core/arti!1194
| * | | thanks: Also acknowledge Suggested-ByNick Mathewson2023-05-221-0/+2
| | | |
| * | | maint/thanks: Split up some long pipelinesNick Mathewson2023-05-181-2/+9
| | | |
| * | | maint/thanks: Remove email addresses from git trailersNick Mathewson2023-05-181-1/+1
| | | | | | | | | | | | | | | | | | | | Okay, technically we're removing everything between the first `<` and the `>` at the end of the line.
| * | | maint/thanks: Include some git trailers in acknowledgmentsNick Mathewson2023-05-181-3/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When building our list of acknowledgments, previously we would only include author and committer names. Now we also include anybody listed in the "Reported-by", "Co-authored-by", and "Thanks" trailers.
* | | | Merge branch 'misc' into 'main'Ian Jackson2023-05-232-6/+6
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | Fix misc regressions in nascent HS client code See merge request tpo/core/arti!1197
| * | | tor-hsclient: Mockable: Do concrete calls with UFCSIan Jackson2023-05-231-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Method dispatch rules mean that if the receiver type of the actual function changes, `self.call()` can turn into a purely-recursive call which overflows the stack. Async Rust doesn't have the usual warning for this situation :-(. UFCS is clumsier but doesn't have that problem because it involves much less magical dispatch. Instead of generating a recursive call which overflows the stack, it fails to compile.
| * | | tor-hsclient: Fix MockableClientCirc for ClientCirc changesIan Jackson2023-05-231-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | ClientCirc::begin_dir_stream now takes Arc<Self>. Method resolution rules mean that this code would just recurse, leading to a stack overflow.
| * | | Fix a docs reference to refer to HsClientIntroAuthKeypairIan Jackson2023-05-221-1/+1
|/ / / | | | | | | | | | | | | | | | | | | | | | Fixes warning from cargo -o doc --document-private-items --all-features --workspace This was evidentlhy overlooked during recent replacement of unescorted private keys in the code.
* | | Merge branch 'misc_upgrades' into 'main'Ian Jackson2023-05-227-332/+225
|\ \ \ | |_|/ |/| | | | | | | | Upgrade miscellaneous dependencies See merge request tpo/core/arti!1195
| * | Upgrade notify dependency to 6.0Nick Mathewson2023-05-222-3/+3
| | |
| * | Upgrade async-compression dependency to 0.4.0.Nick Mathewson2023-05-222-7/+7
| | |
| * | Upgrade memmap2 dependency to 0.6.1.Nick Mathewson2023-05-222-3/+3
| | |
| * | Upgrade serde_with dependency to 3.0.0Nick Mathewson2023-05-223-8/+14
| | |
| * | tor-rtcompat: Say default-features with a dash, not an underscore.Nick Mathewson2023-05-221-1/+1
| | | | | | | | | | | | (`cargo-upgrade` warns about this.)
| * | Run "cargo update".Nick Mathewson2023-05-221-312/+199
|/ /
* | Merge branch 'clippy-nightly' into 'main'Ian Jackson2023-05-224-5/+6
|\ \ | | | | | | | | | | | | Fix a few warnings from clippy nightly See merge request tpo/core/arti!1193
| * | chanmgr: fix a unit-default warning from clippy nightly.Nick Mathewson2023-05-181-1/+1
| | | | | | | | | | | | | | | | | | I could also have stopped using `::default()` to construct this (testing-only) object, but I think it makes more sense to turn it into a non-unit object.
| * | guardmgr, netdir: fix some needless-mut warningsNick Mathewson2023-05-182-4/+4
| | | | | | | | | | | | Found by clippy nightly
| * | guardmgr: suppress a clippy-nightly warning.Nick Mathewson2023-05-181-0/+1
| |/ | | | | | | | | I don't love this change, but apparently we are trying for "consistency".
* | Merge branch 'escorted_25519_secrets' into 'main'Nick Mathewson2023-05-189-89/+120
|\ \ | | | | | | | | | | | | | | | | | | Refactor code not to use unescorted ed25519 secrets Closes #798 See merge request tpo/core/arti!1192
| * | hscrypto: Remove an incorrect comment.Nick Mathewson2023-05-181-5/+0
| | | | | | | | | | | | | | | (It said that we want to deprecate all unescorted secret keys; in fact, only unescorted EdDSA secrets are bad.)
| * | key-management.md: Add a note deprecating unescorted ed secretsNick Mathewson2023-05-181-0/+1
| | |
| * | netdoc, hsclient: Update remaining ed25519::SecretKey usersNick Mathewson2023-05-184-25/+24
| | | | | | | | | | | | | | | | | | Fortunately, these are all in experimental code. Closes #798
| * | hscrypto: Replace ed25519 secret keys with keypairsNick Mathewson2023-05-181-42/+32
| | | | | | | | | | | | Part of #798: We no longer use unescorted ed25519 secret keys.
| * | llcrypto: Don't take or return "unescorted" ed25519 keys.Nick Mathewson2023-05-182-20/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Per #798, we want to make sure that we never pass around an `ed25519::SecretKey`; only an `ed25519::Keypair` (or `ExpandedKeypair`). This is because, when you're computing an ed25519 signature, you have to use the public key as one of your inputs, and if you ever use a mismatched public key you are vulnerable to a nonce reuse attack. (For more info see https://moderncrypto.org/mail-archive/curves/2020/001012.html )
| * | llcrypto: Add an `ed25519::ExpandedKeypair` type.Nick Mathewson2023-05-181-0/+25
| | | | | | | | | | | | | | | | | | | | | | | | This is like an `ed25519::Keypair`, except that instead of a `SecretKey` it contains an `ExpandedSecretKey`. We'll be using this to implement #798, where we impose a rule that there must be no "unescorted" ed25519 secret keys.