summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | Upgrade to latest asynchronous_codec (0.7.0)Nick Mathewson2023-10-175-41/+41
| | | |
| * | | Upgrade to memmap2 0.9.0Nick Mathewson2023-10-172-6/+6
| | | |
* | | | Merge branch 'terminate_pending_stream' into 'main'gabi-2502023-10-184-6/+31
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | proto: Make StreamTarget::close() misuse less likely. See merge request tpo/core/arti!1678
| * | | Add comments about another problem with close_pending().Nick Mathewson2023-10-172-0/+21
| | | | | | | | | | | | | | | | See #1065 for more information here.
| * | | proto: Make StreamTarget::close() misuse less likely.Nick Mathewson2023-10-173-6/+10
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | It turns out that we can make `IncomingStream::reject()` consume self, thus making it impossible to hit the double-close error from outside the `tor-proto` crate. Also, we rename `StreamTarget::close()` to `close_pending()` to better reflect its limited applicability.
* | | Merge branch 'dirclient-api-breaks' into 'main'gabi-2502023-10-185-63/+90
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Seal the dirclient::Requestable trait and hide most of its members. Closes #1062 See merge request tpo/core/arti!1679
| * | | hsclient: add a missing ) to a message.Nick Mathewson2023-10-171-1/+1
| | | |
| * | | dirclient: Seal the Requestable trait and hide most of its members.Nick Mathewson2023-10-174-44/+71
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Since none of these methods were invoked from outside `tor-dirclient` (except for debugging), and since we have had a fair amount of churn on what we actually want them to be, it seems like a good idea to use this trick to hide them. This will let us make other changes to the actual behavior of Requestable in the future.
| * | | dirclient: Rename partial_docs_ok to partial_response_body_okNick Mathewson2023-10-173-24/+24
| | | |
* | | | Merge branch 'dirclient-todos' into 'main'gabi-2502023-10-174-35/+124
|\| | | | |/ / |/| | | | | | | | | | | | | | Privacy: Do not list supported encodings in hsdesc reqs. Closes #1062 See merge request tpo/core/arti!1675
| * | dirclient: Make Requestable::anonymized mandatory.Nick Mathewson2023-10-172-3/+22
| | |
| * | dirclient: Explain why 1024 is a sufficient maximum response length.Nick Mathewson2023-10-161-0/+4
| | |
| * | dirclient: Wrap a somewhat wide comment.Nick Mathewson2023-10-161-5/+3
| | |
| * | Downgrade another TODO HSS and move it to TODO BREAKINGNick Mathewson2023-10-161-2/+3
| | |
| * | Privacy: Do not list supported encodings in hsdesc reqs.Nick Mathewson2023-10-163-28/+87
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Since not everybody has xz and/or zstd, we don't want to admit whether we support them when we are uploading or downloading an onion service descriptor. Similarly, if we aren't advertising support for an encoding, we shouldn't accept it. Finally, while we're doing this, it made sense to have the ability to mark requests based on how anonymized they are, and reject (some) attempts to send those requests over a one-hop circuit. Closes #1062
| * | dirclient: Change a todo to an API todo and make it less blocking.Nick Mathewson2023-10-161-1/+9
| |/
* | Merge branch 'prevent-illegal-escapes' into 'main'Nick Mathewson2023-10-171-1/+8
|\ \ | |/ |/| | | | | tor-ptmgr: Handle unsupported escapes See merge request tpo/core/arti!1584
| * tor-ptmgr: Handle unsupported escapesEmil Engler2023-10-171-1/+8
|/
* Merge branch 'consecutive_dot' into 'main'gabi-2502023-10-161-6/+6
|\ | | | | | | | | ArtiPathComponent: Disallow consecutive . in paths See merge request tpo/core/arti!1661
| * tor-keymgr: Disallow consecutive . in pathsNeel Chauhan2023-10-161-6/+6
|/
* Merge branch 'key-extensions' into 'main'gabi-2502023-10-164-9/+16
|\ | | | | | | | | tor-keymgr: Encode whether the key is public or private in the file extension. See merge request tpo/core/arti!1672
| * dev-doc: Document the service keys currently supported by keymgr.Gabriela Moldovan2023-10-131-4/+9
| |
| * tor-keymgr: Encode whether the key is public or private in the file extension.Gabriela Moldovan2023-10-134-7/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | There are 2 reasons to make this change: * because having the word `private` in the extension will make it more difficult to accidentally misuse or misplace a private key (see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1618#note_2947461) * because `Keystore`s will soon grow a `list()` function returning all `(ArtiPath, KeyType)`s in the keystore, and in order for `ArtiNativeKeystore` to implement this function, it will need to be able to reverse the `KeyType -> file extension` mapping (if two different `KeyType`s are mapped to the same extension, `ArtiNativeKeystore`s won't be able to reverse the mapping)
* | Merge branch 'bug1039_redux' into 'main'Nick Mathewson2023-10-161-16/+25
|\ \ | | | | | | | | | | | | | | | | | | Sort introduction point lists by ntor public key. Closes #1039 See merge request tpo/core/arti!1674
| * | Explain why we are sorting intro points.Nick Mathewson2023-10-161-0/+7
| | |
| * | Sort introduction point lists by ntor public key.Neel Chauhan2023-10-161-16/+18
| | | | | | | | | | | | Closes #1039
* | | Merge branch 'track' into 'main'Nick Mathewson2023-10-162-7/+119
|\ \ \ | |/ / |/| | | | | | | | tor-hsservice: timeout track: More docs See merge request tpo/core/arti!1673
| * | tor-hsservice: timeout track: Worsify formattingIan Jackson2023-10-161-4/+6
| | | | | | | | | | | | | | | | | | | | | | | | Simply running `rustfmt` makes a mess. This new formatting is less nice but repo policy requires that the layout is a fixed point under rustfmt and this is the least bad fixed point I found.
| * | tor-hsservice: timeout track: Add some discussionIan Jackson2023-10-161-4/+36
| | |
| * | tor-hsservice: timeout track: Add an example doctestIan Jackson2023-10-162-0/+74
| | |
| * | tor-hsservice: timeout track: Add a rustdoc allowIan Jackson2023-10-161-0/+4
| | | | | | | | | | | | Suppresses some erroneous warnings.
* | | Merge branch 'generic-listen' into 'main'Nick Mathewson2023-10-164-56/+120
|\ \ \ | |/ / |/| | | | | | | | arti, tor-config: Allow listening on generic addresses for SOCKS and DNS. See merge request tpo/core/arti!1613
| * | Treat only EAFNOSUPPORT as a warningJani Monoses2023-09-262-8/+12
| | |
| * | Test for Listen DisplayJani Monoses2023-09-261-0/+24
| | |
| * | Do not writelns in Display, undo localhost_port_legacy changes.Jani Monoses2023-09-252-5/+4
| | |
| * | Handle address already in useJani Monoses2023-09-222-2/+6
| | |
| * | arti, tor-config: Allow listening on generic addresses for SOCKS and DNS.Jani Monoses2023-09-224-59/+92
| | |
* | | Merge branch 'test' into 'main'Ian Jackson2023-10-1613-68/+399
|\ \ \ | | | | | | | | | | | | | | | | Cleanups , fixes,and tests in IPT manager See merge request tpo/core/arti!1659
| * | | tor-hsservice: timeout_track: Add a TODO re explanationsIan Jackson2023-10-161-0/+3
| | | |
| * | | tor-hsservice: ipt_mgr: Tolerate complexity warning for nowIan Jackson2023-10-161-0/+1
| | | | | | | | | | | | | | | | And add a TODO HSS for improving it.
| * | | tor-hsservice: Apply mandatory code formatting worseningIan Jackson2023-10-162-21/+49
| | | |
| * | | tor-hsservice: timeout_track: tests: Introduce secs() aliasIan Jackson2023-10-161-11/+14
| | | | | | | | | | | | | | | | I wish we could `use Duration::from_secs as secs`.
| * | | tor-hsservice: ipt_mgr: Add a test caseIan Jackson2023-10-163-0/+173
| | | | | | | | | | | | | | | | | | | | This doesn't test all the code paths, but it does test the main path of execution (and detected a couple of bugs).
| * | | tor-hsservice: ipt_mgr: Adjust API for mock RNGIan Jackson2023-10-161-4/+4
| | | | | | | | | | | | | | | | | | | | We're want to be able to return a mutable borrow of a field in the mock state. This means we must make `Rng` a GAT.
| * | | tor-hsservice: Narrow some dead code allowsIan Jackson2023-10-166-2/+7
| | | |
| * | | tor-hsservice: timeout_track: Change semantics to do what's neededIan Jackson2023-10-161-32/+68
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The key point is this: +//! I.e., the timeout tracker tells you when (in the future) +//! any of the comparisons you have made, might produce different answers. +//! So, that can be used to know how long to sleep for when waiting for timeout(s). That's how the code in ipt_mgr.rs uses this. Without this change, things go wrong in the following case: we've got at least one good IPT, but not quite enough, and the others are taking too long. Ie, the timeout for "we should publish" is in the past. We decide to publish (correctly) but this *past* timeout should be disregarded. Disregarding past timeouts is correct if the code which is making the comparisons acts on the timeout when it occurs.
| * | | tor-hsservice: timeout_track: Provided shortest() for all trackersIan Jackson2023-10-161-0/+25
| | | |
| * | | tor-hsservice: timeout_track: Mark some unused variablesIan Jackson2023-10-161-2/+2
| | | |
| * | | tor-hsservice: timeout_track: Add a dead code allowIan Jackson2023-10-161-0/+1
| | | | | | | | | | | | | | | | For the same reason as the allow(unreachable_pub).
| * | | tor-hsservice: ipt_mgr: Improve waiting publish messageIan Jackson2023-10-161-10/+18
| | | | | | | | | | | | | | | | | | | | | | | | This involves plumbing the duration through. Also it involved breaking out the multiplication by two into an addition, since if we were to change the factor we'd want to print the scaled value.