summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-proto: Give circ Reactor a constructor, and make its fields private.Nick Mathewson2023-03-082-30/+48
| | |
* | | Merge branch 'suffix' into 'main'Nick Mathewson2023-03-082-2/+7
|\ \ \ | |/ / |/| | | | | | | | Introduce and use ends_with_ignore_ascii_case See merge request tpo/core/arti!1058
| * | Introduce and use ends_with_ignore_ascii_caseIan Jackson2023-03-082-2/+7
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1056#note_2884428
* | | Merge branch 'introduce2_encrypted_portion' into 'main'Nick Mathewson2023-03-086-0/+235
|\ \ \ | | | | | | | | | | | | | | | | tor-cell: Add code for the payload of an hs-ntor handshake. See merge request tpo/core/arti!1052
| * | | intro_payload: various doc fixes and TODOs from review.Nick Mathewson2023-03-081-4/+16
| | | |
| * | | tor-cell: Be a little more pedantic about INTRODUCE cell types.Nick Mathewson2023-03-081-3/+3
| | | |
| * | | tor-cell: Better describe the parts of intro payload.Nick Mathewson2023-03-081-3/+23
| | | |
| * | | tor-cell: Add code for the payload of an hs-ntor handshake.Nick Mathewson2023-03-064-0/+192
| | | | | | | | | | | | | | | | | | | | | | | | (This is the encrypted information inside the INTRODUCE2 cell; it's used by the client to tell the service where to find its rendezvous point.)
| * | | tor-linkspec: Add a constructor for UnparsedLinkSpecNick Mathewson2023-03-062-0/+11
| | | |
* | | | Merge branch 'host2' into 'main'Ian Jackson2023-03-082-47/+140
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti-client: Do not send resolve requests for IP addrs to exits See merge request tpo/core/arti!1057
| * | | | arti-client: Host: Be more explicit about what is allowed in HostnameIan Jackson2023-03-081-1/+11
| | | | |
| * | | | RustfmtIan Jackson2023-03-082-4/+16
| | | | |
| * | | | Abolish Host::into_string_and_portIan Jackson2023-03-081-23/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When I was trying to add HS support to these layers, I found I could add a new variant to the `Host` enum but everything would still compile even though I hadn't written the necessary implementation! This method is a liability: when using it, one inevitably writes such latent bugs.
| * | | | arti-client: Do not send resolve requests for IP addrs to exitsIan Jackson2023-03-082-13/+58
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Doing so doesn't seem like a good idea. It might even be some kind of leak? Found because I added a variant to `address::Host` for hidden services, and noticed that the resolve code still compiled.
| * | | | arti-client addr handling: Introduce StreamInstructionsIan Jackson2023-03-082-22/+71
| | | | |
* | | | | Merge branch 'suffix' into 'main'Ian Jackson2023-03-084-4/+52
|\ \ \ \ \ | |/ / / / |/| | / / | | |/ / | |/| | Introduce and use strip_sufrfix_ignore_ascii_case See merge request tpo/core/arti!1056
| * | | arti-client: Reject .onion, when we should, without allocatingIan Jackson2023-03-081-1/+2
| | | | | | | | | | | | | | | | Use new strip_suffix_ignore_ascii_case
| * | | Use strip_suffix_ignore_ascii_case to quickly reject non-.onion HsId (fmt)Ian Jackson2023-03-081-1/+3
| | | |
| * | | Use strip_suffix_ignore_ascii_case to quickly reject non-.onion HsIdIan Jackson2023-03-082-3/+4
| | | |
| * | | tor-basic-utils: Provide str.strip_suffix_ignore_ascii_caseIan Jackson2023-03-081-0/+44
|/ / / | | | | | | | | | We're going to want this for cheaply stripping ".onion" from things.
* | | Merge branch 'bug779' into 'main'Ian Jackson2023-03-081-4/+6
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-dirmgr: Don't try to mark consensus usable in a read-only store. Closes #779 See merge request tpo/core/arti!1055
| * | | tor-dirmgr: Don't try to mark consensus usable in a read-only store.Nick Mathewson2023-03-081-4/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Doing this means that any attempt to use a read-only store would crash as soon as it found that the consensus was usable. It seems that this bug was introduced at some point doing all the dirmgr refactors we did over the past year. Perhaps there should be a test for running with a read-only store. Fixes #779
* | | | Merge branch 'fuzzing_tor_bytes' into 'main'Ian Jackson2023-03-082-1/+39
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-bytes: defend against misuse of extract_n(). See merge request tpo/core/arti!1053
| * | | tor-bytes: Add take_rest and read_nested_* to fuzzer.Nick Mathewson2023-03-061-0/+25
| | | |
| * | | tor-bytes: defend against misuse of extract_n().Nick Mathewson2023-03-061-1/+14
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, if somebody wrote this code, an attacker could easily use it to cause an OOM panic: ``` let n = r.take_u64(); let items: Vec<Foo> = r.extract_n(n as usize)?; ``` The first line of defense here is not to write protocols like that: we don't actually _have_ any 32-bit counters in our protocol AFAICT. The second line of defense is to pre-check `n` for reasonableness before calling `extract_n`. Here we add a third line of defense: whereas previously we would do `Vec::with_capacity(n)` in `extract_n`, we now allocate an initial capacity of `min(n, r.remaining())`. This ensures that the size of the allocation can't exceed the remaining length of the message, which (for our cell types at least) should prevent it from overflowing or running OOM.
* | | Merge branch 'hsonion' into 'main'Ian Jackson2023-03-073-5/+187
|\ \ \ | | | | | | | | | | | | | | | | Impl FromStr and Display for HsId, etc. See merge request tpo/core/arti!1054
| * | | Impl Redactable for HsIdIan Jackson2023-03-073-1/+27
| | | |
| * | | Debug HsId as the .onion; retain the hex printing as {:x}Ian Jackson2023-03-071-3/+10
| | | |
| * | | impl Display for HsIdIan Jackson2023-03-073-1/+150
| |/ /
* | | Merge branch 'typos' into 'main'Ian Jackson2023-03-072-4/+4
|\ \ \ | |/ / |/| | | | | | | | Fix typos See merge request tpo/core/arti!1050
| * | Fix typosDimitris Apostolou2023-03-032-4/+4
|/ /
* | Merge branch 'hs_cert_inner_validation' into 'main'Ian Jackson2023-03-023-85/+200
|\ \ | | | | | | | | | | | | | | | | | | tor-netdoc: Validate inner certs in HsDesc Closes #744 See merge request tpo/core/arti!1044
| * | tor-netdoc: Clarify that we must indeed check cert expiration.Nick Mathewson2023-03-011-3/+1
| | |
| * | tor-netdoc: Validate inner certs in HsDescNick Mathewson2023-03-013-82/+199
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes our implementation behave the same as the C tor implementation, by validating all of the expiration and signatures on the certificates in the inner document. (It is still not semantically necessary to check these certs: the document in which they appear is already signed by the key with which they are allegedly signed.) Closes #744
* | | Merge branch 'hstidy' into 'main'Nick Mathewson2023-03-013-106/+8
|\ \ \ | | | | | | | | | | | | | | | | Abolish knowledge of HS circuits in circmgr, and tidying See merge request tpo/core/arti!1047
| * | | hsclient: Discuss HsClientConnector multiplicity/reuseIan Jackson2023-03-011-3/+7
| | | | | | | | | | | | | | | | And delete the associated TODO.
| * | | hsclient: Remove TODOs about circular referencesIan Jackson2023-03-011-10/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These Arcs are all "downward", referencing items from layers lower in the stack. So they don't cause cycles. There was going to be a cycle involving the `OnionConnector` upcall trait, but we have just abolished that.
| * | | hsclient: Abolish knowledge of HS circuits in circmgrIan Jackson2023-03-013-93/+1
|/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Abolish CircMgr::get_or_launch_onion_client and everything to support it. We have decided that `.onion` diversion ccan't/shouldn't occur in tor-circmgr. Probably, it should occur much higher up - arti-client maybe - since it will sometimes need ambient authority (KS_hsc_*). Now all knowledge of HS connections is in tor-hsclient. This gets rid of a layering inversion and the trait needed for tor-circmgr to do the upcall to tor-hsclient.
* | | Merge branch 'rename_rend_message' into 'main'Nick Mathewson2023-03-011-15/+18
|\ \ \ | | | | | | | | | | | | | | | | tor-cell: Rename Rendezvous*::message to handshake_info. See merge request tpo/core/arti!1045
| * | | tor-cell: Rename Rendezvous*::message to handshake_info.Nick Mathewson2023-03-011-15/+18
| | | | | | | | | | | | | | | | Follow-up from !1038
* | | | Merge branch 'hsconn' into 'main'Ian Jackson2023-03-0113-97/+1457
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Implement HS state management See merge request tpo/core/arti!1034
| * | | | hsclient isol_map: Use 1:1 notation in diagram to show correspondenceIan Jackson2023-03-011-1/+1
| | | | |
| * | | | hsclient isol_map: Document invariant, fix comment, terminologyIan Jackson2023-03-011-9/+15
| | | | | | | | | | | | | | | | | | | | Use the occupied/vacant terminology that the slotmap docs use.
| * | | | hsclient state: Rename rechecks (from attempts) and add clarifying docsIan Jackson2023-03-012-9/+25
| | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2882079
| * | | | hsclient keys: Be more explicit about HsClientSecretKeys nullableIan Jackson2023-03-011-5/+9
| | | | | | | | | | | | | | | | | | | | | | | | | It can contain no keys; state this more prominently, and explain what it represents. Also fix a few typos etc.
| * | | | hsclient state: Implement and test MultikeyIsolatedMap::retainIan Jackson2023-03-012-3/+109
| | | | |
| * | | | hsclient state: Split off MultikeyIsolatedMapIan Jackson2023-03-015-82/+191
| | | | |
| * | | | hsclient state: Move all the data fields into the tableIan Jackson2023-03-011-28/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1034#note_2881576 This is a singificant simplification, in fact.
| * | | | tor-llcrypto: Add a TODO re impl Redactable for HsIdIan Jackson2023-03-011-0/+1
| | | | |
| * | | | hsclient: Clarify period task handle TODOIan Jackson2023-03-011-1/+1
| | | | |