summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | hss: Downgrade MissingHsIdKeypair TODONick Mathewson2024-01-241-1/+1
| | | | | | | | | | | | | | | | | | | | This is not typically wrong, but it may become wrong if we do not tidy up MissingHsIdKeypair in the future. The TODO now refers to
| * | | hss: Change ticket about ErrorKind for IntroPointNotListedNick Mathewson2024-01-241-1/+1
| | | | | | | | | | | | | | | | This is now #1255, which is not a MUST.
| * | | hss: Clean up errors while expecting intro_establishedNick Mathewson2024-01-241-11/+25
| | | | | | | | | | | | | | | | Part of #1225, also #1237.
| * | | hss: Correct the Kind for EstablishTimeout.Nick Mathewson2024-01-241-1/+1
| | | |
| * | | hss: Return LocalResourceAlreadyInUse on StateLocked.Nick Mathewson2024-01-231-2/+1
| | | |
| * | | hss: Return summarized errorkind for RendCirc error.Nick Mathewson2024-01-231-2/+3
| | | |
| * | | tor-circmgr: Expose ErrorKind-combining calculation.Nick Mathewson2024-01-232-5/+13
| | | | | | | | | | | | | | | | | | | | We use this for a RetryError in circmgr, but we will also want it in hsservice.
* | | | Merge branch 'fslock-guard-windows-fix' into 'main'Nick Mathewson2024-01-243-6/+30
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | fslock-guard: use winapi to test file-equivalency on windows Closes #1258 See merge request tpo/core/arti!1910
| * | | fslock-guard: Add links to documentation about windows approachNick Mathewson2024-01-241-0/+7
| | | |
| * | | fslock-guard: use winapi to test file-equivalency on windowsNick Mathewson2024-01-233-6/+23
| | | |
* | | | Merge branch 'expire-tp-keys' into 'main'gabi-2502024-01-244-177/+106
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Do TP-based HSS key expiry in publisher reactor. See merge request tpo/core/arti!1909
| * | | | tor-hsservice: Fix typos etc.gabi-2502024-01-241-2/+2
| | | | |
| * | | | tor-hsservice: key expiry: Code motion and reindentingIan Jackson2024-01-241-26/+22
| | | | | | | | | | | | | | | | | | | | | | | | | Now the remove_if_expire closure, which does the actual work, is lexically outside the macro, and the macro is trivial.
| * | | | tor-hsservice: key expiry: Introduce HsTimePeriodKeySpecifier traitIan Jackson2024-01-241-10/+49
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This allows us to have a closure containing runtime-polymorphic code, reducing monomorphisation and moving code out of a macro into a closure.
| * | | | tor-hsservice: key expiry: Rely on limiting publisher key scanIan Jackson2024-01-241-2/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Our pattern is now supposed to ensure that we don't see any irrelevant keys. So if we do, that's a bug. (The code layout is getting increasingly odd. We'll sort that out along with some code motion later.)
| * | | | tor-hsservice: key expiry: Limit publisher key scanIan Jackson2024-01-241-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Only examine keys for this HS. This avoids thinking about every key for every HS for every netdir change. That's quadratic in the number of HS's.
| * | | | tor-hsservice: key expiry: clippy followupIan Jackson2024-01-241-3/+2
| | | | | | | | | | | | | | | | | | | | | | | | | These are now the last uses of these values, so they need the "no clone" form.
| * | | | tor-hsservice: key expiry: Do publisher expiry from reactorIan Jackson2024-01-243-131/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In principle there is a small race with doing this in a separate task: the reactor and the sweeper might process the new netdir at different times. For example, if two netdir updates come in quick succession, and the sweeper is slower, the sweeper might still be running with the previous TPs as the publisher is creating keys in the new TPs. Theoretically, the sweeper might delete keys the reactor has just generated. This is also considerably simpler.
| * | | | tor-hsservice: key expiry: Break out KeystoreSweeper::expire_keysIan Jackson2024-01-242-43/+55
|/ / / / | | | | | | | | | | | | We're going to change where this is called.
* | | | Merge branch 'rev-counter-redux' into 'main'gabi-2502024-01-2411-96/+113
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Generate revision counter using the start of SRV period. Closes #1166 See merge request tpo/core/arti!1904
| * | | | tor-netdir: Make hs_dirs_{upload, download} take separate args instead of tuple.Gabriela Moldovan2024-01-245-5/+10
| | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1904#note_2987777
| * | | | tor-netdir, tor-hscrypto: Add function for computing SRV period offset.Gabriela Moldovan2024-01-246-13/+45
| | | | | | | | | | | | | | | | | | | | Part of #1166
| * | | | tor-hscrypto: Remove TimePeriodOffset, offset_within_period().Gabriela Moldovan2024-01-243-27/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These are now unused. Part of #1166
| * | | | tor-hsservice: Generate revision counter using the start of SRV period (fmt).Gabriela Moldovan2024-01-241-2/+1
| | | | |
| * | | | tor-hsservice: Generate revision counter using the start of SRV period.Gabriela Moldovan2024-01-243-22/+20
| | | | | | | | | | | | | | | | | | | | Closes #1166
| * | | | tor-netdir: Simplify `hs_dirs_upload` by only returning the `Relay`.Gabriela Moldovan2024-01-244-24/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher is the only user of `hs_dirs_upload`. It turns out it never actually uses the first element of the yielded `Item`s, so we can simplify `hs_dir_upload` to only return the HsDir `Relay`s. Part of #1166
| * | | | tor-hsservice: Store HsDirParams in the publisher's TimePeriodContext.Gabriela Moldovan2024-01-241-10/+19
| | | | | | | | | | | | | | | | | | | | Part of #1166
| * | | | tor-netdir: Make hs_all_time_periods return HsDirParams.Gabriela Moldovan2024-01-244-11/+14
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The descriptor publisher uses this function to obtain the list of relevant time periods. It will soon also need to know the `srv_lifespan` associated with each time period, so we change this function to return `HsDirParams`. Part of #1166
* | | | Merge branch 'less_experimental' into 'main'gabi-2502024-01-245-9/+12
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Make lower-level "hs-service" features non-experimental See merge request tpo/core/arti!1908
| * | | | Remove dependency from hsrproxy to tor-proto::experimental-apiNick Mathewson2024-01-231-1/+1
| | | | | | | | | | | | | | | | | | | | It would appear nothing was using this.
| * | | | Mark lower-level hs-service features non-experimentalNick Mathewson2024-01-234-8/+11
| | |_|/ | |/| |
* | | | Merge branch 'fslock-guard' into 'main'Nick Mathewson2024-01-235-0/+341
|\ \ \ \ | |/ / / |/| / / | |/ / | | | fslock-guard: sketch implementation See merge request tpo/core/arti!1900
| * | fslockguard: try to document windows assumptionsNick Mathewson2024-01-231-0/+41
| | | | | | | | | | | | | | | These are necessarily a bit hand-wavey, but I think they summarize what we are assuming.
| * | Remove an XXX: fslock does indeed use O_CLOEXEC.Nick Mathewson2024-01-231-1/+0
| | |
| * | fslockguard: implement a delete_lock_file function.Nick Mathewson2024-01-233-3/+31
| | |
| * | Use fslock-arti-forkNick Mathewson2024-01-233-21/+18
| | |
| * | fslock-guard: Write down the locking protocol on UnixIan Jackson2024-01-231-0/+65
| | | | | | | | | | | | | | | | | | Text from here https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1900#note_2986683 with a few minor fixes.
| * | fslock-guard: Rename os modulesIan Jackson2024-01-231-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These two modules are key to the implementation of the locking protocols. We must define the locking protocol in terms of underlying OS semantics (since Unix and Windows have different fs concepts and different concurrency semantics) and therefore, although we are sharing some code between the implementations, these modules are what defines the two protocols.
| * | Give a formal semantics for the fslock operations.Ian Jackson2024-01-221-0/+15
| | |
| * | fslock-guard: sketch implementationNick Mathewson2024-01-215-0/+196
| | | | | | | | | | | | | | | | | | | | | This is not yet "correct", since it will rely on https://github.com/brunoczim/fslock/pull/15 (Conceivably, it might be better to make the `fslock` crate rm-safe.)
* | | Merge branch 'hsdirparams' into 'main'gabi-2502024-01-234-15/+44
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | Expose SRV lifespan info from netdir Closes #1254 See merge request tpo/core/arti!1903
| * | netdir: Make hs_dirs_upload() yield &HsDirParams.Nick Mathewson2024-01-232-2/+4
| | | | | | | | | | | | Closes #1254.
| * | Expose HsDirParams, and give it accessors.Nick Mathewson2024-01-232-2/+24
| | |
| * | hsservice: Make HsDirParams include the SRV lifespan.Nick Mathewson2024-01-232-11/+16
| | | | | | | | | | | | This is part of #1254.
* | | Merge branch 'fix-1242' into 'main'Nick Mathewson2024-01-234-112/+116
|\ \ \ | |/ / |/| | | | | | | | | | | | | | tor-hsservice: Do not store the subcredentials in RendRequestContext. Closes #1242 See merge request tpo/core/arti!1901
| * | tor-hsservice: Move compute_subcredentials to RendRequestContext.Gabriela Moldovan2024-01-223-103/+100
| | | | | | | | | | | | Part of #1242
| * | tor-hsservice: Do not store the subcredentials in RendRequestContext.Gabriela Moldovan2024-01-223-21/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the subcredentials were computed in `IptEstablisher::launch` and stored in `RendRequestContext`. This caused long-running services to report errors like: ``` WARN tor_hsservice::helpers: Problem while accepting rendezvous request: error: Could not process INTRODUCE request: Introduction handshake was invalid: Circuit-extension handshake authentication failed ``` for clients using newer subcredentials than the ones the service had at the time the IPT was established. Fixes #1242
| * | tor-hsservice: Add an error type for subcredential lookup failures.Gabriela Moldovan2024-01-222-0/+6
|/ / | | | | | | | | | | | | | | The subcredential lookup will be moved to `IntroRequest::decrypt_from_introduce2`. The error returned on failure is going to be `IntroRequestError::Subcredentials`. Part of #1242
* | Merge branch 'shutdown_on_drop' into 'main'gabi-2502024-01-195-14/+27
|\ \ | | | | | | | | | | | | | | | | | | Clarify shutdown behavior when RemoteOnionService is dropped. Closes #1238 and #1236 See merge request tpo/core/arti!1899
| * | Document when (most) spawned tasks will be canceled.Nick Mathewson2024-01-182-0/+6
| | |