summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgrIan Jackson2023-12-134-4/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed for the replay logs. It's a shame that CheckedDir is (i) a bit unergonomic (ii) has an extra bool in it, or we could pass one of those instead of these two arguments. Since HS's might be created after startup, TorClient must have these fields.
| * | | | | arti-client: Centralise state_dir variable (fmt)Ian Jackson2023-12-131-5/+2
| | | | | |
| * | | | | arti-client: Centralise state_dir variableIan Jackson2023-12-131-3/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Call expand_state_dir only once. We'll reuse this value, another time, too.
| * | | | | tor-hsservice tests: replay: Pass nick to ↵Ian Jackson2023-12-131-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | create_storage_handles_from_state_mgr (fmt)
| * | | | | tor-hsservice tests: replay: Pass nick to create_storage_handles_from_state_mgrIan Jackson2023-12-132-3/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will allow us to more faithfully model the actual Arti state directory layout.
| * | | | | tor-hsservice tests: replay: Provide for a filesystem lockfileIan Jackson2023-12-133-2/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is to prevent current use of the same directory of replay logs by different instances.
| * | | | | tor-hsservice tests: replay: Break out create_loggedIan Jackson2023-12-131-13/+25
| | | | | |
| * | | | | tor-hsservice: Move ReplayLog construction to ipt_mgrIan Jackson2023-12-132-9/+19
| | | | | |
| * | | | | tor-hsservice: Note some TODOs relating to IPT teardownIan Jackson2023-12-131-0/+9
| | | | | |
| * | | | | tor-hsservice: ReplayLog: Fix file magicIan Jackson2023-12-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This ought to have the hash algorithm name in it or we'll have trouble if we want to change the hash algorithm in the future. (Strictly, we could just choose a different magic but the string was rather short.) Add a newline, which is often convenient in file headers. And "onion" to mean "onion swervice" is improper.
| * | | | | tor-hsservice: ReplayLog: Slight tidying upIan Jackson2023-12-131-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | Make `#[cfg(target_family = "unix")]` appear only once.
| * | | | | tor-persist: Provide FsMistrustErrorExt, and use itIan Jackson2023-12-138-12/+70
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This code needs fs_mistrust::Error and tor_error::ErrorKind. I think we probably don't want fs_mistrust to depend on tor_error or vice versa. tor_persist is approximately the place where these two threads of thought come together, and it's currently the lowest place where this is needed. Use it in tor-dirmgr too, which is currently the other place that embodies this knowledge about fs_mistrust::Error.
| * | | | | fs-mistrust: Explain where a Verifier comes fromIan Jackson2023-12-131-0/+2
|/ / / / /
* | | | | Merge branch 'wallclock-time' into 'main'gabi-2502023-12-131-1/+3
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP. Closes #1155 See merge request tpo/core/arti!1828
| * | | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP.Gabriela Moldovan2023-12-131-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | #1155 was happening because we couldn't compute the offset of the current time from the start of the _next_ TP (`TimePeriod::offset_within_period` expected `when` to come after the start of the TP). `TimePeriod::offset_within_period` now returns an offset of 0 for timestamps that come before the start of the TP, to support computing revision counters for the descriptors uploaded to the HsDirs from the ring associated with the next TP. Fixes #1155
* | | | | | Merge branch 'publisher-errors' into 'main'gabi-2502023-12-137-227/+209
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Replace ReactorError with FatalError See merge request tpo/core/arti!1812
| * | | | | | tor-hsservice: Add TODO about removing the shutdown handling from the publisher.Gabriela Moldovan2023-12-131-0/+5
| | | | | | |
| * | | | | | tor-hsservice: Add TODO about changing a return type in ipt_set.Gabriela Moldovan2023-12-131-0/+5
| | | | | | |
| * | | | | | tor-hsservice: Add TODO about possibly making UploadStatus a type alias.Gabriela Moldovan2023-12-131-0/+2
| | | | | | |
| * | | | | | tor-hsservice: Add TODO about possibly retrying failed uploads.Gabriela Moldovan2023-12-131-0/+6
| | | | | | |
| * | | | | | tor-hsservice: Remove unused ReactorError type.Gabriela Moldovan2023-12-131-84/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher now returns `FatalError`s, so we don't need `ReactorError` anymore. Addresses a TODO HSS in publish/reactor.rs Part of #1129
| * | | | | | tor-hsservice: Replace ReactorError with FatalError (fmt).Gabriela Moldovan2023-12-132-9/+6
| | | | | | |
| * | | | | | tor-hsservice: Replace ReactorError with FatalError.Gabriela Moldovan2023-12-132-30/+29
| | | | | | |
| * | | | | | tor-hsservice: Add a NetdirProviderShutdown FatalError variant.Gabriela Moldovan2023-12-131-1/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is another type of fatal error.
| * | | | | | tor-hsservice: Add a FatalError::from_spawn.Gabriela Moldovan2023-12-131-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | We're about to use this (in the publisher reactor).
| * | | | | | tor-hsservice: Replace ReactorError::ShuttingDown with ShutdownStatus.Gabriela Moldovan2023-12-131-13/+33
| | | | | | |
| * | | | | | tor-hsservice: Make descriptor publisher wait for shutdown signal.Gabriela Moldovan2023-12-133-3/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher logs a nice `info!` message when it receives the shutdown signal. The publisher can infer that the service is shutting down from the errors received on its various receiver channels (i.e. from the errors that suggest the sender was dropped), but listening for the shutdown signal is nicer.
| * | | | | | tor-hsservice: Move ShutdownStatus to svc.Gabriela Moldovan2023-12-132-16/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will be used by the descriptor publisher soon (we want to abolish its `ReactorError` altogether, and to do that, we need to get rid of `ReactorError::ShuttingDown`. `ShuttingDown::Terminate` happens to be a suitable replacement).
| * | | | | | tor-hsservice: Remove unused ReactorError variant.Gabriela Moldovan2023-12-131-5/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This moves us one step closer to removing ReactorError in favour of FatalError (see the TODO HSS above ReactorError for more details).
| * | | | | | tor-hsservice: Refactor upload_descriptor_with_retries to not return an error.Gabriela Moldovan2023-12-131-67/+60
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, this would return `ReactorError::PublishFailure` if the upload failed. However, that error wasn't used for anything other than logging. Instead of returning the error, we now log it inside `upload_descriptor_with_retries` and return an `UploadStatus` describing the upload outcome. This will enable us to abolish `ReactorError::PublishFailure` (and eventually replace `ReactorError` with `FatalError`).
| * | | | | | tor-hsservice: Abolish ReactorError::HsDescBuild.Gabriela Moldovan2023-12-132-7/+3
| | |/ / / / | |/| | | | | | | | | | | | | | | | | | | | | | The failure to build a descriptor out of seemingly valid parts is an internal (irrecoverable) error.
* | | | | | Merge branch 'todo-hscrypto' into 'main'Alexander Færøy2023-12-131-4/+0
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | hscrypto: Remove a "TODO HSS" about a no-longer-unused type. See merge request tpo/core/arti!1817
| * | | | | hscrypto: Remove a "TODO HSS" about a no-longer-unused type.Nick Mathewson2023-12-121-4/+0
| | |/ / / | |/| | |
* | | | | Merge branch 'warn_on_dubious_hsproxy_config' into 'main'Nick Mathewson2023-12-122-9/+52
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | hsproxy: warn on some dubious configurations Closes #1154 See merge request tpo/core/arti!1822
| * | | | | Add NOTEs about similar code for address types.Nick Mathewson2023-12-122-1/+10
| | | | | |
| * | | | | hsproxy: warn on some dubious configurationsNick Mathewson2023-12-121-8/+42
| | |_|_|/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | Specifically, warn about non-private target addresses and onion services with no forwarding rules at all. Removes some TODO HSS comments and closes #1154.
* | | | | Merge branch 'hss-docs' into 'main'Nick Mathewson2023-12-121-1/+68
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | doc/OnionService: more caveats and warnings See merge request tpo/core/arti!1826
| * | | | | doc/OnionService: strengthen the warningsIan Jackson2023-12-121-0/+13
| | | | | |
| * | | | | doc/OnionService: warn about persistent stateIan Jackson2023-12-121-0/+20
| | | | | |
| * | | | | doc/OnionService: warn about future incompatIan Jackson2023-12-121-0/+12
| | | | | |
| * | | | | doc/OnionService: warn about stack backtracesIan Jackson2023-12-121-0/+1
| | | | | |
| * | | | | doc/OnionService: mention two security risksIan Jackson2023-12-121-1/+12
| | | | | |
| * | | | | doc/OnionService: mention Rust API instabilityIan Jackson2023-12-121-0/+10
| | | | | | | | | | | | | | | | | | | | | | | | This is implied by our other docs but it ought to be repeated here I guess.
* | | | | | Merge branch 'warn_report_onion_proxy' into 'main'Ian Jackson2023-12-121-4/+1
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | arti: Use warn_report on anyhow::Error in onion_proxy See merge request tpo/core/arti!1820
| * | | | | arti: Use warn_report on anyhow::Error in onion_proxyNick Mathewson2023-12-121-4/+1
| |/ / / / | | | | | | | | | | | | | | | This was made possible by !1818.
* | | | | Merge branch 'onion-service-doc' into 'main'Nick Mathewson2023-12-121-0/+139
|\ \ \ \ \ | |_|_|/ / |/| | | | | | | | | | | | | | Initial onion service howto See merge request tpo/core/arti!1825
| * | | | Tweaks from reviewNick Mathewson2023-12-121-0/+6
| | | | |
| * | | | Initial onion service howtoNick Mathewson2023-12-121-0/+133
| |/ / /
* | | | Merge branch 'tor_cell_todo' into 'main'Ian Jackson2023-12-121-1/+0
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-cell: Remove a now-unneeded allow(unused). See merge request tpo/core/arti!1816
| * | | tor-cell: Remove a now-unneeded allow(unused).Nick Mathewson2023-12-121-1/+0
| |/ /