| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Introduce and use ends_with_ignore_ascii_case
See merge request tpo/core/arti!1058
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1056#note_2884428
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-cell: Add code for the payload of an hs-ntor handshake.
See merge request tpo/core/arti!1052
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
(This is the encrypted information inside the INTRODUCE2 cell; it's
used by the client to tell the service where to find its rendezvous
point.)
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
arti-client: Do not send resolve requests for IP addrs to exits
See merge request tpo/core/arti!1057
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
When I was trying to add HS support to these layers, I found I could
add a new variant to the `Host` enum but everything would still
compile even though I hadn't written the necessary implementation!
This method is a liability: when using it, one inevitably writes such
latent bugs.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Doing so doesn't seem like a good idea. It might even be some kind of
leak?
Found because I added a variant to `address::Host` for hidden
services, and noticed that the resolve code still compiled.
|
| | | | | | |
|
| |\ \ \ \ \
| |/ / / /
|/| | / /
| | |/ /
| |/| | |
Introduce and use strip_sufrfix_ignore_ascii_case
See merge request tpo/core/arti!1056
|
| | | | |
| | | |
| | | |
| | | | |
Use new strip_suffix_ignore_ascii_case
|
| | | | | |
|
| | | | | |
|
| |/ / /
| | |
| | |
| | | |
We're going to want this for cheaply stripping ".onion" from things.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tor-dirmgr: Don't try to mark consensus usable in a read-only store.
Closes #779
See merge request tpo/core/arti!1055
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Doing this means that any attempt to use a read-only store would
crash as soon as it found that the consensus was usable.
It seems that this bug was introduced at some point doing all the
dirmgr refactors we did over the past year. Perhaps there should be
a test for running with a read-only store.
Fixes #779
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
tor-bytes: defend against misuse of extract_n().
See merge request tpo/core/arti!1053
|
| | | | | |
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously, if somebody wrote this code, an attacker could easily
use it to cause an OOM panic:
```
let n = r.take_u64();
let items: Vec<Foo> = r.extract_n(n as usize)?;
```
The first line of defense here is not to write protocols like that:
we don't actually _have_ any 32-bit counters in our protocol
AFAICT.
The second line of defense is to pre-check `n` for reasonableness
before calling `extract_n`.
Here we add a third line of defense: whereas previously we would do
`Vec::with_capacity(n)` in `extract_n`, we now allocate an initial
capacity of `min(n, r.remaining())`. This ensures that the size of
the allocation can't exceed the remaining length of the message,
which (for our cell types at least) should prevent it from
overflowing or running OOM.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Impl FromStr and Display for HsId, etc.
See merge request tpo/core/arti!1054
|
| | | | | |
|
| | | | | |
|
| | |/ / |
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Fix typos
See merge request tpo/core/arti!1050
|
| |/ / |
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-netdoc: Validate inner certs in HsDesc
Closes #744
See merge request tpo/core/arti!1044
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This makes our implementation behave the same as the C tor
implementation, by validating all of the expiration and signatures
on the certificates in the inner document.
(It is still not semantically necessary to check these certs: the
document in which they appear is already signed by the key with
which they are allegedly signed.)
Closes #744
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Abolish knowledge of HS circuits in circmgr, and tidying
See merge request tpo/core/arti!1047
|
| | | | |
| | | |
| | | |
| | | | |
And delete the associated TODO.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
These Arcs are all "downward", referencing items from layers lower in
the stack. So they don't cause cycles.
There was going to be a cycle involving the `OnionConnector` upcall
trait, but we have just abolished that.
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Abolish CircMgr::get_or_launch_onion_client and everything to support
it. We have decided that `.onion` diversion ccan't/shouldn't occur in
tor-circmgr. Probably, it should occur much higher up - arti-client
maybe - since it will sometimes need ambient authority (KS_hsc_*).
Now all knowledge of HS connections is in tor-hsclient. This
gets rid of a layering inversion and the trait needed for tor-circmgr
to do the upcall to tor-hsclient.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-cell: Rename Rendezvous*::message to handshake_info.
See merge request tpo/core/arti!1045
|
| | | | |
| | | |
| | | |
| | | | |
Follow-up from !1038
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
Implement HS state management
See merge request tpo/core/arti!1034
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Use the occupied/vacant terminology that the slotmap docs use.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2882079
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
It can contain no keys; state this more prominently, and explain what
it represents. Also fix a few typos etc.
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2881576
This is a singificant simplification, in fact.
|
| | | | | | |
|
| | | | | | |
|