summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | dev docs: Add note about C Tor store configuration.Gabriela Moldovan2023-05-161-1/+49
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Move the key passphrases subsection to the Arti store section.Gabriela Moldovan2023-05-161-6/+6
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Create a separate section for the C tor key store discussion.Gabriela Moldovan2023-05-161-5/+17
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Rename {Key, HsClient}Identity.Gabriela Moldovan2023-05-161-45/+45
| |/ / | | | | | | | | | | | | | | | | | | | | | This renames `KeyIdentity` to `KeySpecifier` so it doesn't get confused with the concept of an "identity key". `HsClientIdentity` is also renamed for consistency. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Merge branch 'rpc-objectmap' into 'main'Nick Mathewson2023-05-165-231/+214
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | RPC: revise semantics for weak references and object IDs Closes #848 See merge request tpo/core/arti!1183
| * | rpc: Clarify how authentication works.Nick Mathewson2023-05-161-10/+5
| | |
| * | rpc: Clarify some object ID docs and remove impl details.Nick Mathewson2023-05-161-37/+4
| | |
| * | rpc: Revise example in documentationNick Mathewson2023-05-161-4/+4
| | |
| * | rpc: Split the generational index into two.Nick Mathewson2023-05-161-113/+92
| | | | | | | | | | | | This lets us simplify our logic a bit for strong references.
| * | rpc: Change the formatting of object IDsNick Mathewson2023-05-153-22/+79
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want each ID to have a unique form every time it is given out, so that you can't use ID==ID to check whether Object==Object. (See discussions leading to #848.) We'd also like the form of object IDs to be a little annoying to analyze, to discourage people from writing programs that depends on their particular format. (We are reserving the right to change the format whenever we want.) We _don't_ want to use any cryptography here (yet), lest somebody think that this is an actual security mechanism. (This isn't for security; it's for encouraging developers to treat IDs as opaque.) With that in mind, we now lightly obfuscate our generational indices before returning them.
| * | rpc: rename GenIdx::into/try_from implementationsNick Mathewson2023-05-152-11/+9
| | | | | | | | | | | | | | | These are about to become nondeterministic-ish and probably shouldn't use the Into/TryFrom traits.
| * | rpc: do not deduplicate strong object idsNick Mathewson2023-05-151-52/+39
| | | | | | | | | | | | | | | | | | | | | | | | Per discussion referenced at #848, we want each operation that returns a strong object ID to return a new, distinct strong ID. Note that we no longer need to put strong and weak references in the same arena; we can clean this code up a lot down the road.
| * | rpc: Repair an error in our ObjectId encoding.Nick Mathewson2023-05-151-1/+1
| |/ | | | | | | | | | | Now we generate object IDs that we can parse. This is about to be obsolete once we change how we generate objects and their IDs for #848, but we may as well start from a working state.
* | Merge branch 'run-fixup-features' into 'main'gabi-2502023-05-1643-117/+412
|\ \ | |/ |/| | | | | | | | | Run fixup-features on our Cargo.tomls, and handle its warnings Closes #856 and #795 See merge request tpo/core/arti!1182
| * Revise all XXXXs from fixup-featuresNick Mathewson2023-05-1519-89/+79
| |
| * Run fixup-features _with_ annotations.Nick Mathewson2023-05-1519-0/+70
| | | | | | | | | | This litters our Cargo.toml files with "XXX" entries that we should fix.
| * Reformat Cargo.toml files.Nick Mathewson2023-05-1520-69/+230
| |
| * Run fixup-features --no-annotate for initial Cargo.toml fixes.Nick Mathewson2023-05-1542-44/+118
|/ | | | | | | | | This does the following: - Gives every crate a `full`. - Cause every `full` to depend on `full` from the lower-level crates. - Makes every feature listed _directly_ in `experimental` depend on `__is_experimental`.
* Merge branch 'better-fixup-features' into 'main'Nick Mathewson2023-05-159-146/+416
|\ | | | | | | | | Revise fixup-features to be closer to something we can use See merge request tpo/core/arti!1180
| * fixup-features: minor doc fix.Nick Mathewson2023-05-151-5/+5
| |
| * Mark an initial set of non-additive features.Nick Mathewson2023-05-155-14/+24
| |
| * fixup-features: Do not annotate non-features.Nick Mathewson2023-05-152-3/+7
| |
| * fixup-features: Do not add edges from non-features.Nick Mathewson2023-05-152-2/+7
| |
| * fixup-features: distinguish internal and external edgesNick Mathewson2023-05-152-3/+8
| | | | | | | | An external edge does not cause its target to be created as a feature.
| * fixup-features: Add an option to not annotate.Nick Mathewson2023-05-153-6/+25
| |
| * fixup-features: ability to add annotations for everything.Nick Mathewson2023-05-151-7/+13
| |
| * fixup-features: fix off-by-one in argument reading.Nick Mathewson2023-05-151-1/+1
| |
| * fixup-features: Implement remaining rules.Nick Mathewson2023-05-151-34/+64
| |
| * fixup-features: Enforce __is_experimental tagging rule.Nick Mathewson2023-05-151-0/+19
| |
| * fixup-features: Revise our rule 2 enforcement to use newer APIs.Nick Mathewson2023-05-151-14/+14
| |
| * fixup-features: Refactor "apply a list of changes" code into a new module.Nick Mathewson2023-05-152-25/+88
| |
| * fixup-features: Make a feature graph type in a submoduleNick Mathewson2023-05-153-60/+149
| | | | | | | | | | I tried to use petgraph, but it was optimized for performance over usability, and the usability was beyond me.
| * fixup-features: minor spelling and comment fixes.Nick Mathewson2023-05-151-1/+1
| |
| * fixup-features: Describe the semantics we actually wantNick Mathewson2023-05-151-6/+26
| | | | | | | | | | | | | | | | | | The problem with our old rules is that "reachable from __nonadditive" and "reachable from experimental" were not themselves sensible definitions of nonadditive and experimental. See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1068#note_2887939
* | Merge branch 'x25519-dalek-upgrade' into 'main'gabi-2502023-05-158-28/+72
|\ \ | | | | | | | | | | | | llcrypto: upgrade x25519-dalek. See merge request tpo/core/arti!1181
| * | Use non-deprecated *Secret::random_from_rng.Nick Mathewson2023-05-136-20/+21
| | | | | | | | | | | | The `new` function is deprecated in x25519-dalek 2.0.0-rc.2
| * | llcrypto: upgrade x25519-dalek.Nick Mathewson2023-05-132-8/+51
|/ / | | | | | | | | | | | | | | This upgrades us to 2.0.0-rc.2, which is the latest in the not-quite-done-yet 2.0 series. The only code change that's absolutely needed is opting into the static_secrets feature.
* | Merge branch 'connect-hsdesc-bounds' into 'main'gabi-2502023-05-136-47/+398
|\ \ | | | | | | | | | | | | hsclient: Build cached descriptor TimerangeBounds from descriptor lifetime. See merge request tpo/core/arti!1154
| * | tor-basic-utils: Add unbounded range (..) test.Gabriela Moldovan2023-05-131-0/+31
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-basic-utils: Update combinatorial test to randomly choose an open or ↵Gabriela Moldovan2023-05-131-2/+12
| | | | | | | | | | | | | | | | | | closed bound. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-basic-utils: Add rangebounds test with time ranges.Gabriela Moldovan2023-05-131-0/+35
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-basic-utils: Assert witness is not part of the intersection.Gabriela Moldovan2023-05-131-0/+4
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-basic-utils: Log the ranges/intersection on assertion failure.Gabriela Moldovan2023-05-131-1/+13
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | netdoc: Use the RangeBoundsExt impl of TimerangeBound.Gabriela Moldovan2023-05-133-82/+25
| | | | | | | | | | | | | | | | | | We can now get rid of the standalone `intersect_bounds` function. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-checkable: Implement RangeBounds for TimerangeBound.Gabriela Moldovan2023-05-132-6/+19
| | | | | | | | | | | | | | | | | | | | | | | | By implementing `RangeBounds` for `TimerangeBound`, we get `RangeBoundsExt` for free. This will enable `parse_decrypt_validate` to easily compute the intersection of the `TimerangeBound`s its layers. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-basic-utils: Add a helper function to deduplicate test code.Gabriela Moldovan2023-05-131-19/+29
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | tor-basic-utils: Add RangeBoundsExt trait.Gabriela Moldovan2023-05-132-0/+201
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | hsclient: descriptor_ensure no longer wraps the descriptor in TimerangeBound.Gabriela Moldovan2023-05-131-2/+5
| | | | | | | | | | | | | | | | | | | | | `descriptor_fetch_attempt` now returns a `TimerangeBound<HsDesc>` (and so does `parse_descript_validate`). Signed-off-by: Gabriela Moldovan <[email protected]>
| * | netdoc: Do not consume EncryptedHsDesc when decrypting.Gabriela Moldovan2023-05-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | `parse_decrypt_validate` will need to "peek" inside an encrypted descriptor (before validating it) to extract the `TimerangeBound` of the inner layer. This is needed to compute the intersection of the `TimerangeBound`s of both layers. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | hsclient: Compute HsDesc validity time from the TimerangeBounds of its layers.Gabriela Moldovan2023-05-132-38/+29
| | | | | | | | | | | | | | | | | | | | | This makes `descriptor_ensure` refetch the descriptor if either of its layers (inner or outer) expires. Signed-off-by: Gabriela Moldovan <[email protected]>