summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | circmgr:Resolve a warning when building without ntor-v3Nick Mathewson2023-12-131-2/+3
| |/ / / /
* | | | | Merge branch 'shadow-onion-svc' into 'main'gabi-2502023-12-1312-8/+151
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | shadow ci: test arti hs server functionality See merge request tpo/core/arti!1827
| * | | | | shadow test: add tor client connecting to arti hsJim Newsome2023-12-134-1/+16
| | | | | |
| * | | | | editorconfig: exclude arti HS keys in shadow testJim Newsome2023-12-131-1/+1
| | | | | |
| * | | | | shadow test: add client for arti hsJim Newsome2023-12-135-1/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This also adds a workaround - the arti service doesn't appear to register itself (set up intro points) unless first used as a client.
| * | | | | shadow test: add hidden service keystore to templateJim Newsome2023-12-132-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | This is to ensure a stable HS address.
| * | | | | shadow test: add fileserver-onion-artiJim Newsome2023-12-132-0/+24
| | | | | |
| * | | | | shadow ci: use proxy.sock_listen instead of socks_portJim Newsome2023-12-131-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | socks_port is deprecated
| * | | | | shadow ci: reformat arti argument lists (no-op)Jim Newsome2023-12-131-5/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Put one argument per line and use a yaml list instead of string (shadow accepts either here).
| * | | | | arti-extra build: enable onion-service-serviceJim Newsome2023-12-131-1/+1
| | | | | |
| * | | | | arti-extra build: no-op reformatJim Newsome2023-12-131-1/+5
|/ / / / /
* | | | | Merge branch 'publisher-do-not-retry-fatal' into 'main'gabi-2502023-12-131-16/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: If the error is fatal, do not retry the desc upload. See merge request tpo/core/arti!1821
| * | | | | tor-hsservice: If the error is fatal, do not retry the desc upload.Gabriela Moldovan2023-12-131-16/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The errors returned by `upload_all` are now all fatal, so we there is no point in retrying `upload_all` on failure. Note this will exacerbate #1155, as it will cause the seemingly transient time skew issues to become fatal (the corresponding error type is `Bug`, so in principle they ought to be fatal)
* | | | | | Merge branch 'replay' into 'main'Ian Jackson2023-12-1317-59/+310
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | Make IPT logs persistent See merge request tpo/core/arti!1824
| * | | | | arti-client: TorClient.storage_mistrust: Correct doc commentIan Jackson2023-12-131-1/+6
| | | | | |
| * | | | | tor-hsservice: Add more explanation of replay_log lockingIan Jackson2023-12-131-0/+5
| | | | | |
| * | | | | tor-hsservice: Add more explanation of replay_log lockingIan Jackson2023-12-131-0/+6
| | | | | |
| * | | | | tor-hsservice: Cargo.toml: sortIan Jackson2023-12-131-1/+1
| | | | | |
| * | | | | tor-hsservice: replay: Note a bugIan Jackson2023-12-131-0/+4
| | | | | |
| * | | | | tor-hsservice: Make IPT logs be persistent (fmt)Ian Jackson2023-12-131-1/+3
| | | | | |
| * | | | | tor-hsservice: Make IPT logs be persistentIan Jackson2023-12-133-7/+88
| | | | | |
| * | | | | tor-hsservice ipt_mgr: Rename STORAGE_RETRY from KEYSTORE_RETRYIan Jackson2023-12-131-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | We're going to reuse this for other kinds of storage error.
| * | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgr (fmt)Ian Jackson2023-12-131-5/+2
| | | | | |
| * | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgrIan Jackson2023-12-134-4/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed for the replay logs. It's a shame that CheckedDir is (i) a bit unergonomic (ii) has an extra bool in it, or we could pass one of those instead of these two arguments. Since HS's might be created after startup, TorClient must have these fields.
| * | | | | arti-client: Centralise state_dir variable (fmt)Ian Jackson2023-12-131-5/+2
| | | | | |
| * | | | | arti-client: Centralise state_dir variableIan Jackson2023-12-131-3/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Call expand_state_dir only once. We'll reuse this value, another time, too.
| * | | | | tor-hsservice tests: replay: Pass nick to ↵Ian Jackson2023-12-131-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | create_storage_handles_from_state_mgr (fmt)
| * | | | | tor-hsservice tests: replay: Pass nick to create_storage_handles_from_state_mgrIan Jackson2023-12-132-3/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will allow us to more faithfully model the actual Arti state directory layout.
| * | | | | tor-hsservice tests: replay: Provide for a filesystem lockfileIan Jackson2023-12-133-2/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is to prevent current use of the same directory of replay logs by different instances.
| * | | | | tor-hsservice tests: replay: Break out create_loggedIan Jackson2023-12-131-13/+25
| | | | | |
| * | | | | tor-hsservice: Move ReplayLog construction to ipt_mgrIan Jackson2023-12-132-9/+19
| | | | | |
| * | | | | tor-hsservice: Note some TODOs relating to IPT teardownIan Jackson2023-12-131-0/+9
| | | | | |
| * | | | | tor-hsservice: ReplayLog: Fix file magicIan Jackson2023-12-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This ought to have the hash algorithm name in it or we'll have trouble if we want to change the hash algorithm in the future. (Strictly, we could just choose a different magic but the string was rather short.) Add a newline, which is often convenient in file headers. And "onion" to mean "onion swervice" is improper.
| * | | | | tor-hsservice: ReplayLog: Slight tidying upIan Jackson2023-12-131-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | Make `#[cfg(target_family = "unix")]` appear only once.
| * | | | | tor-persist: Provide FsMistrustErrorExt, and use itIan Jackson2023-12-138-12/+70
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This code needs fs_mistrust::Error and tor_error::ErrorKind. I think we probably don't want fs_mistrust to depend on tor_error or vice versa. tor_persist is approximately the place where these two threads of thought come together, and it's currently the lowest place where this is needed. Use it in tor-dirmgr too, which is currently the other place that embodies this knowledge about fs_mistrust::Error.
| * | | | | fs-mistrust: Explain where a Verifier comes fromIan Jackson2023-12-131-0/+2
|/ / / / /
* | | | | Merge branch 'wallclock-time' into 'main'gabi-2502023-12-131-1/+3
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP. Closes #1155 See merge request tpo/core/arti!1828
| * | | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP.Gabriela Moldovan2023-12-131-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | #1155 was happening because we couldn't compute the offset of the current time from the start of the _next_ TP (`TimePeriod::offset_within_period` expected `when` to come after the start of the TP). `TimePeriod::offset_within_period` now returns an offset of 0 for timestamps that come before the start of the TP, to support computing revision counters for the descriptors uploaded to the HsDirs from the ring associated with the next TP. Fixes #1155
* | | | | | Merge branch 'publisher-errors' into 'main'gabi-2502023-12-137-227/+209
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Replace ReactorError with FatalError See merge request tpo/core/arti!1812
| * | | | | | tor-hsservice: Add TODO about removing the shutdown handling from the publisher.Gabriela Moldovan2023-12-131-0/+5
| | | | | | |
| * | | | | | tor-hsservice: Add TODO about changing a return type in ipt_set.Gabriela Moldovan2023-12-131-0/+5
| | | | | | |
| * | | | | | tor-hsservice: Add TODO about possibly making UploadStatus a type alias.Gabriela Moldovan2023-12-131-0/+2
| | | | | | |
| * | | | | | tor-hsservice: Add TODO about possibly retrying failed uploads.Gabriela Moldovan2023-12-131-0/+6
| | | | | | |
| * | | | | | tor-hsservice: Remove unused ReactorError type.Gabriela Moldovan2023-12-131-84/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher now returns `FatalError`s, so we don't need `ReactorError` anymore. Addresses a TODO HSS in publish/reactor.rs Part of #1129
| * | | | | | tor-hsservice: Replace ReactorError with FatalError (fmt).Gabriela Moldovan2023-12-132-9/+6
| | | | | | |
| * | | | | | tor-hsservice: Replace ReactorError with FatalError.Gabriela Moldovan2023-12-132-30/+29
| | | | | | |
| * | | | | | tor-hsservice: Add a NetdirProviderShutdown FatalError variant.Gabriela Moldovan2023-12-131-1/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is another type of fatal error.
| * | | | | | tor-hsservice: Add a FatalError::from_spawn.Gabriela Moldovan2023-12-131-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | We're about to use this (in the publisher reactor).
| * | | | | | tor-hsservice: Replace ReactorError::ShuttingDown with ShutdownStatus.Gabriela Moldovan2023-12-131-13/+33
| | | | | | |
| * | | | | | tor-hsservice: Make descriptor publisher wait for shutdown signal.Gabriela Moldovan2023-12-133-3/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher logs a nice `info!` message when it receives the shutdown signal. The publisher can infer that the service is shutting down from the errors received on its various receiver channels (i.e. from the errors that suggest the sender was dropped), but listening for the shutdown signal is nicer.