summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | hs_ntor: Calculate MAC on introduce1 message correctly.Nick Mathewson2023-05-171-3/+12
| | | | | | | | | | | | | | | | | | There were two bugs here that made the behavior unlike that of C tor: we had swapped the MAC inputs, and we had forgotten to include the public key X in the input.
| * | hs_ntor: Make internal no-rng variants of the handshake functions.Nick Mathewson2023-05-171-2/+25
| | | | | | | | | | | | We'll want these so we can implement some test vectors.
| * | hs_ntor: Move extra data outside of the "input" fields.Nick Mathewson2023-05-171-59/+33
| | | | | | | | | | | | | | | | | | | | | I think that these Input structs had been defined so that we could use hs_ntor interchangeably with other handshakes. The trouble is, though, that it doesn't really work like any other handshakes we have.
| * | hs_ntor: Use MAC implementation from tor-hscryptoNick Mathewson2023-05-171-35/+16
| | | | | | | | | | | | | | | | | | Note that some of the invocations for this function seem to put the key and the message in a questionable order. But that's a thing to figure out later, while debugging.
| * | hs_ntor: Use correct PK types from tor_hscrypto.Nick Mathewson2023-05-171-20/+24
| | |
| * | hs_ntor: Use Subcredential type from tor-hscryptoNick Mathewson2023-05-173-5/+6
| |/
* | Merge branch 'hs-intro-msg-refactor-again' into 'main'Nick Mathewson2023-05-171-26/+83
|\ \ | |/ |/| | | | | | | | | Refactor Introduce messages to support looking at encoded headers Closes #866 See merge request tpo/core/arti!1188
| * cell: Make Introduce2::new testing-only.Nick Mathewson2023-05-171-1/+6
| | | | | | | | | | | | We never want to create one of these from its parts except when we are testing it; we only want to forward an Introduce1 message with a new command on it.
| * cell: Record the text of an INTRODUCE2 headerNick Mathewson2023-05-171-9/+39
| | | | | | | | | | We'll need to store this so that it can later on be used to complete the hs_ntor handshake.
| * cell: extract introduce headers into a new type.Nick Mathewson2023-05-171-20/+42
|/ | | | | | | | We'll want this because our hs_ntor handshake requires access to an encoded version of the header independent from the actual encrypted message. part of #866.
* Merge branch 'info-to-warn' into 'main'gabi-2502023-05-171-5/+8
|\ | | | | | | | | | | | | Change log levels of messages from INFO to others Closes #854 See merge request tpo/core/arti!1172
| * Change log level to debug and warn for certain appropriate situationsSaksham Mittal2023-05-171-5/+8
| | | | | | | | | | | | This commit changes certain log messages to debug for recoverable errors and a warn if all such attempts fail, in order to not clutter up the info messages that end users get to see.
* | Merge branch 'arc_circ' into 'main'gabi-2502023-05-1714-74/+83
|\ \ | | | | | | | | | | | | | | | | | | Refactor ClientCirc APIs to use Arc<ClientCirc>. Closes #846 See merge request tpo/core/arti!1187
| * | Refactor ClientCirc APIs to use Arc<ClientCirc>.Nick Mathewson2023-05-1614-74/+83
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now ClientCirc is no longer `Clone`, and the things that need it to be `Clone` instead return and use an Arc<ClientCirc> We're doing this so that ClientCirc can participate in the RPC system, and so that its semantics are more obvious. Closes #846. Thanks to the type system, this was a much simpler refactoring than I had feared it would be.
* | | Merge branch 'ticket_759' into 'main'Nick Mathewson2023-05-169-17/+66
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-cert: Replace the KeyUnknownCert::check_key API Closes #759 See merge request tpo/core/arti!1184
| * | | Deprecate check_key, and refactor its logic into the new functions.Nick Mathewson2023-05-161-16/+33
| | | | | | | | | | | | | | | | Closes #759
| * | | Replace usage of KeyUnknownCert::check_key.Nick Mathewson2023-05-167-11/+11
| | | |
| * | | tor-cert: Add new functions to replace KeyUnknownCert::check_key.Nick Mathewson2023-05-162-0/+32
| | |/ | |/| | | | | | | | | | | | | | | | These should have a cleaner API than check_key, and be easier to understand. Part of #759
* | | Merge branch 'resolve_relay' into 'main'Nick Mathewson2023-05-161-0/+142
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | netdir: New function to check consistency of a HasRelayIds Closes #855 See merge request tpo/core/arti!1186
| * | | netdir: New function to check consistency of a HasRelayIdsNick Mathewson2023-05-161-0/+142
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This function will be used to look up a relay by a set of LinkSpecs given from an incoming HsDesc or INTRODUCE2 message. It differs from other "lookup relay by IDs" functions in that it needs to be able to return "here's a relay", "couldn't found a relay", or "learned that this relay is impossible." Closes #855: This is the only new API needed for ChanTarget validation, I think.
* | | Merge branch 'key-mgmt-api-updates-v2' into 'main'gabi-2502023-05-161-81/+208
|\ \ \ | | | | | | | | | | | | | | | | dev docs: key-management.md updates and clarifications See merge request tpo/core/arti!1185
| * | | dev docs: The key store version file should specify a minimum supported version.Gabriela Moldovan2023-05-161-2/+10
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Remove unused arguments.Gabriela Moldovan2023-05-161-12/+9
| | | | | | | | | | | | | | | | | | | | | | | | There are several places where he `KeyType` isn't needed anymore. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Clarify how C Tor key store loads keys from multiple different key ↵Gabriela Moldovan2023-05-161-26/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | dirs. This also moves the `extension` function out of `KeyType` because for the C Tor key store, a key's file extension depends on the role/user of the key, which isn't known by `KeyType` (`KeyType` is a tor-agnostic key type such as `Ed25519Private`). Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Distinguish between arti_extension and ctor_extension.Gabriela Moldovan2023-05-161-2/+7
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Clarify that ArtiPath/CTorPath are relative to the key store root.Gabriela Moldovan2023-05-161-1/+9
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Add note about key store versioning.Gabriela Moldovan2023-05-161-0/+9
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Add note about C Tor store configuration.Gabriela Moldovan2023-05-161-1/+49
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Move the key passphrases subsection to the Arti store section.Gabriela Moldovan2023-05-161-6/+6
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Create a separate section for the C tor key store discussion.Gabriela Moldovan2023-05-161-5/+17
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Rename {Key, HsClient}Identity.Gabriela Moldovan2023-05-161-45/+45
| |/ / | | | | | | | | | | | | | | | | | | | | | This renames `KeyIdentity` to `KeySpecifier` so it doesn't get confused with the concept of an "identity key". `HsClientIdentity` is also renamed for consistency. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Merge branch 'rpc-objectmap' into 'main'Nick Mathewson2023-05-165-231/+214
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | RPC: revise semantics for weak references and object IDs Closes #848 See merge request tpo/core/arti!1183
| * | rpc: Clarify how authentication works.Nick Mathewson2023-05-161-10/+5
| | |
| * | rpc: Clarify some object ID docs and remove impl details.Nick Mathewson2023-05-161-37/+4
| | |
| * | rpc: Revise example in documentationNick Mathewson2023-05-161-4/+4
| | |
| * | rpc: Split the generational index into two.Nick Mathewson2023-05-161-113/+92
| | | | | | | | | | | | This lets us simplify our logic a bit for strong references.
| * | rpc: Change the formatting of object IDsNick Mathewson2023-05-153-22/+79
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want each ID to have a unique form every time it is given out, so that you can't use ID==ID to check whether Object==Object. (See discussions leading to #848.) We'd also like the form of object IDs to be a little annoying to analyze, to discourage people from writing programs that depends on their particular format. (We are reserving the right to change the format whenever we want.) We _don't_ want to use any cryptography here (yet), lest somebody think that this is an actual security mechanism. (This isn't for security; it's for encouraging developers to treat IDs as opaque.) With that in mind, we now lightly obfuscate our generational indices before returning them.
| * | rpc: rename GenIdx::into/try_from implementationsNick Mathewson2023-05-152-11/+9
| | | | | | | | | | | | | | | These are about to become nondeterministic-ish and probably shouldn't use the Into/TryFrom traits.
| * | rpc: do not deduplicate strong object idsNick Mathewson2023-05-151-52/+39
| | | | | | | | | | | | | | | | | | | | | | | | Per discussion referenced at #848, we want each operation that returns a strong object ID to return a new, distinct strong ID. Note that we no longer need to put strong and weak references in the same arena; we can clean this code up a lot down the road.
| * | rpc: Repair an error in our ObjectId encoding.Nick Mathewson2023-05-151-1/+1
| |/ | | | | | | | | | | Now we generate object IDs that we can parse. This is about to be obsolete once we change how we generate objects and their IDs for #848, but we may as well start from a working state.
* | Merge branch 'run-fixup-features' into 'main'gabi-2502023-05-1643-117/+412
|\ \ | |/ |/| | | | | | | | | Run fixup-features on our Cargo.tomls, and handle its warnings Closes #856 and #795 See merge request tpo/core/arti!1182
| * Revise all XXXXs from fixup-featuresNick Mathewson2023-05-1519-89/+79
| |
| * Run fixup-features _with_ annotations.Nick Mathewson2023-05-1519-0/+70
| | | | | | | | | | This litters our Cargo.toml files with "XXX" entries that we should fix.
| * Reformat Cargo.toml files.Nick Mathewson2023-05-1520-69/+230
| |
| * Run fixup-features --no-annotate for initial Cargo.toml fixes.Nick Mathewson2023-05-1542-44/+118
|/ | | | | | | | | This does the following: - Gives every crate a `full`. - Cause every `full` to depend on `full` from the lower-level crates. - Makes every feature listed _directly_ in `experimental` depend on `__is_experimental`.
* Merge branch 'better-fixup-features' into 'main'Nick Mathewson2023-05-159-146/+416
|\ | | | | | | | | Revise fixup-features to be closer to something we can use See merge request tpo/core/arti!1180
| * fixup-features: minor doc fix.Nick Mathewson2023-05-151-5/+5
| |
| * Mark an initial set of non-additive features.Nick Mathewson2023-05-155-14/+24
| |
| * fixup-features: Do not annotate non-features.Nick Mathewson2023-05-152-3/+7
| |
| * fixup-features: Do not add edges from non-features.Nick Mathewson2023-05-152-2/+7
| |