summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | tor-hsservice: Remove duplicate trace! log.Gabriela Moldovan2023-12-111-5/+0
| | | | | | | | | | | | | | | | | | | | We already log the outcome of the HsDir upload in the function that calls this code.
| * | | tor-hsservice: Use debug! instead of trace! to log upload outcome.Gabriela Moldovan2023-12-111-1/+1
| | | | | | | | | | | | | | | | This also wraps the line.
| * | | tor-hsservice: Remove some TODOs that have been addressed.Gabriela Moldovan2023-12-111-11/+0
| | | |
| * | | tor-hsservice: Publish the IptPublishSet we called note_publication_attempt on.Gabriela Moldovan2023-12-111-50/+50
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, it was possible for the `IptPublishSet` used to generate the descriptor and the `IptPublishSet` `note_publication_attempt` to differ. Now, the publisher generates the descriptor using the same `IptPublishSet` it calls `note_publication_attempt` on. Note that as a consequence, the publisher generates a new descriptor just before _each_ HsDir upload. This means each HsDir could, in theory, receive a different descriptor (not just in terms of revision-counters, but also with a different set of IPTs). It may seem like this could lead to some HsDirs being left with an outdated descriptor, but that's not the case: after the upload completes, the publisher will be notified by the ipt_watcher of the IPT change event (if there was one to begin with), which will trigger another upload job. Previously, the publisher would only generate a single descriptor for each time period (all HsDirs in a given time period would receive the same descriptor). Closes #1097
| * | | tor-hsservice: Move revision_counter to HsDirUploadResult.Gabriela Moldovan2023-12-111-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | This was previously in `TimePeriodUploadResult`. We will soon have different revision_counter for each `HsDirUploadResult`, so let's preemptively move the field there.
| * | | tor-hsservice: Make build_sign also return the revision counter used.Gabriela Moldovan2023-12-112-10/+11
| | | |
| * | | tor-hsservice: Derive Clone for VersionedDescriptor.Gabriela Moldovan2023-12-111-0/+1
| | | | | | | | | | | | | | | | We're going to need to clone it soon.
| * | | tor-hsservice: Move generate_revision_counter to Immutable.Gabriela Moldovan2023-12-111-74/+75
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `generate_revision_counter` and `create_ope_key` don't use anything from `self` other than `imm`, so they might as well be methods on `Immutable`. This change is needed because we're soon going to need to use `generate_revision_counter` from an associated `Reactor` function (where we don't have `self`).
* | | | Merge branch 'hsrproxy-config-test' into 'main'Ian Jackson2023-12-111-1/+34
|\ \ \ \ | |/ / / |/| | | | | | | | | | | hsrproxy: Add a test for the contents of a parsed configuration. See merge request tpo/core/arti!1810
| * | | hsrproxy: Add a test for the contents of a parsed configuration.Nick Mathewson2023-12-111-1/+34
|/ / /
* | | Merge branch 'local-resource-error' into 'main'Ian Jackson2023-12-111-0/+22
|\ \ \ | | | | | | | | | | | | | | | | tor-error: Introduce ErrorKind::LocalResourceAlreadyInUse See merge request tpo/core/arti!1775
| * | | tor-error: Introduce ErrorKind::LocalResourceAlreadyInUseIan Jackson2023-12-111-0/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Our HSS code isn't going to work if you run more than one copy. Soon we'll detect this (via our use of tor_persist). There may be other places this ought to be used. Eg if we get EADDRINUSE from trying to set up a proxy, maybe ...
* | | | Merge branch 'publisher-todos' into 'main'Ian Jackson2023-12-111-19/+25
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | tor-hsservice: Remove a publisher TODO that has been addressed. Closes #1131 See merge request tpo/core/arti!1807
| * | | tor-hsservice: Reformat a long log line.Gabriela Moldovan2023-12-081-1/+5
| | | |
| * | | tor-hsservice: Add more context to the publisher logs.Gabriela Moldovan2023-12-081-10/+20
| | | |
| * | | tor-hsservice: Remove a publisher TODO that has been addressed.Gabriela Moldovan2023-12-081-8/+0
| | |/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher doesn't reupload unless explicitly asked to do so by the `IptManager` (via `await_update()`). Also, when the consensus changes, we always trigger a reupload, but only to those HsDirs that don't already have the descriptor (the HsDirs marked as "clean" stay "clean", and any new HsDirs are marked "dirty" until they get a copy of the descriptor. See !1806). Similarly, a config change only triggers a reupload if the change means we need to generate a new descriptor (e.g. if the `anonymity` of the service changes). Note, however, that this logic is currently commented out (it depends on #1028). Closes #1131
* | | Merge branch 'onion-reconfigure' into 'main'Nick Mathewson2023-12-113-52/+210
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | arti: Reconfigure onion services as needed Closes #1089 See merge request tpo/core/arti!1798
| * | | Add a TODO HSS comment about Reconfigure.Ian Jackson2023-12-111-0/+1
| | | |
| * | | Reconfigure onion services when their configuration changes.Nick Mathewson2023-12-052-28/+20
| | | | | | | | | | | | | | | | Closes #1089.
| * | | arti: Make reconfiguration slightly more abstractNick Mathewson2023-12-052-24/+94
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now instead of having a hardwired list of of things to reconfigure, the watch_cfg module now has a vector of ReconfigurableModule. As noted in the documentation, I don't intend that this should be our final API here: It is deliberately not exposed. When we revisit the structure of `arti` more, we should probably do this differently.
| * | | arti: Backend support for reconfiguring onion proxies.Nick Mathewson2023-12-051-6/+101
| | | |
* | | | Merge branch 'svc-status' into 'main'Nick Mathewson2023-12-111-9/+42
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | tor-hsservice: Derive service state from the state of its components. See merge request tpo/core/arti!1808
| * | | tor-hsservice: Add functions to update the IPT mgr/publisher states.Gabriela Moldovan2023-12-111-7/+21
| | | | | | | | | | | | | | | | Part of #1083
| * | | tor-hsservice: Derive service state from the state of its components.Gabriela Moldovan2023-12-111-1/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need to know the status of each component to be able to report the overall status of the service. Without this change, the service (and its components) have no way of knowing if a given transition is valid: if the state of a component (say, the IPT manager) is `Bootstrapping`, `Recovering` or `Broken`, a transition out of the current state is only valid if it is initiated by the same component that caused the current state (for example, if the publisher sets the state to `Recovering`, the IPT manager should not be allowed to trigger an overall state transition to `Running`). Part of #1083
| * | | tor-hsservice: Trim trailing whitespace.Gabriela Moldovan2023-12-111-1/+1
|/ / /
* | | Merge branch 'publisher-recompute-hsdir' into 'main'gabi-2502023-12-071-25/+30
|\ \ \ | | | | | | | | | | | | | | | | tor-hsservice: Fix publisher bug causing unnecessary uploads. See merge request tpo/core/arti!1806
| * | | tor-hsservice: Remove unused lifetime.Gabriela Moldovan2023-12-071-1/+1
| | | | | | | | | | | | | | | | Fixes a clippy lint.
| * | | tor-hsservice: Remove unused function.Gabriela Moldovan2023-12-071-16/+0
| | | |
| * | | tor-hsservice: Fix publisher bug causing unnecessary uploads.Gabriela Moldovan2023-12-071-27/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a bug where the publisher wasn't preserving the `DescriptorStatus` of its `HsDirs` when handling consensus changes. The bug is described in more detailed in the TODO removed by this commit.
| * | | tor-hsservice: Add a TODO about a publlisher bugGabriela Moldovan2023-12-071-0/+17
| | | |
| * | | tor-hsservice: Rename period to ctx for clarity.Gabriela Moldovan2023-12-071-2/+2
| | | | | | | | | | | | | | | | This is actually a `TimePeriodContext`.
* | | | Merge branch 'ntor-v3-circmgr' into 'main'Nick Mathewson2023-12-0710-31/+96
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti: add ntor-v3 handshake experimental feature Closes #1084 See merge request tpo/core/arti!1766
| * | | | Enable ntor_v3 in the arti-extra buildJim Newsome2023-12-071-1/+1
| | | | | | | | | | | | | | | | | | | | This tests ntor_v3 in the shadow integration test.
| * | | | ClientCir: use ntor_v3 handshake when target supports itJim Newsome2023-12-073-18/+52
| | | | |
| * | | | tor-circmgr: add experimental feature "ntor_v3"Jim Newsome2023-12-071-1/+2
| | | | |
| * | | | shadow ci: add host articlient-extraJim Newsome2023-12-073-1/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The arti-extra binary has several experimental features enabled. Currently it is used to test experimental onion service features, but it would be useful also do a test of the arti-extra binary in the same configuration and workload as the arti binary (which has the default featureset). In a follow-up commit, we'll enable the experimental ntor-v3 handshake implementation in the arti-extra binary.
| * | | | NtorV3Extension set encoding/decoding: include n_extensionsJim Newsome2023-12-073-10/+21
| | |_|/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | An encoded set of extensions in the ntorv3 handshake includes a header with the number of extensions. This change adds that header. It also changes `write_many_onto` to take a slice instead of an iterator, since we need to know the number of extensions up-front. In principle we could take a clonable iterator instead and use Iterator::count, but it's probably not worth the extra complexity.
* | | | Merge branch 'hsclient_parallelism_notes' into 'main'Alexander Færøy2023-12-071-7/+8
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | hsclient: Clean up some TODOs about parallelism. See merge request tpo/core/arti!1795
| * | | hsclient: Clean up some TODOs about parallelism.Nick Mathewson2023-12-051-7/+8
| | |/ | |/| | | | | | | | | | | | | | | | | | | * Be a little more specific about what is being parallelized. * Remove TODOs about specs, in favor of torspec#244. * Note some other issues surrounding some of the cases. (See discussions of points 3-6 at #913)
* | | Merge branch 'persist-macro' into 'main'Ian Jackson2023-12-0714-431/+705
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | Improve KeySpecifier, errors, IptKeySpecifier impl, etc. Closes #1116 and #1148 See merge request tpo/core/arti!1796
| * | tor-hsservice: keys: Remove unused imports (and a blocking todo)Ian Jackson2023-12-071-2/+0
| | |
| * | tor-keymgr: ArtiPath[Component]: Manually reformat derive listsIan Jackson2023-12-071-32/+8
| | |
| * | tor-keymgr: ArtiPath: impl serdeIan Jackson2023-12-071-0/+3
| | |
| * | tor-keymgr: ArtiPathComponent: Use unqualified namesIan Jackson2023-12-071-3/+3
| | | | | | | | | | | | This makes this like the list for ArtiPath.
| * | tor-keymgr: ArtiPath[Component]: Don't DerefMutIan Jackson2023-12-071-3/+1
| | | | | | | | | | | | That would allow construction of invalid paths.
| * | tor-keymgr: ArtiPath[Component]: Add some more test aspectsIan Jackson2023-12-071-1/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | Test that the FromStr and TryFrom impls give the same answers as new(). These tests dodn't even compile before Properly validate in FromStr because the derive-more generated version has a wrong error type.
| * | tor-keymgr: ArtiPath[Component]: Properly validate in FromStrIan Jackson2023-12-071-2/+11
| | | | | | | | | | | | | | | | | | | | | As pointed out in https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1796#note_2974513 derive-more just parses like the inner type, so an unvalidated String. That is wrong.
| * | tor-keymgr: ArtiPath[Component]: Use d-a to generate various methodsIan Jackson2023-12-071-30/+36
| | | | | | | | | | | | Now ArtiPath too is TryFrom<String> and AsRef<str>.
| * | tor-keymgr: ArtiPath: Introduce validate_strIan Jackson2023-12-071-3/+8
| | | | | | | | | | | | This makes it more like ArtiPathComponent and will allow more unification
| * | tor-keymgr: ArtiPath tests: Add a test for a multi-component pathIan Jackson2023-12-071-2/+6
| | |