| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Storing the VanguardMode in multiple places (in the VanguardMgr *and*
the HS circ Pool) is dangerous and can lead to split brain situations
where different parts of the code think they are running in different
VanguardModes.
See #1424
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
`VanguardMgr` should be the source of truth for obtaining the current
`VanguardMode`.
Closes #1424
|
| |/ /
| |
| |
| | |
See arti#1424
|
| |\ \
| | |
| | |
| | |
| | | |
Upgrade and update packages for upcoming release
See merge request tpo/core/arti!2177
|
| | | | |
|
| | | | |
|
| | | | |
|
| |\ \ \
| |_|/
|/| |
| | |
| | |
| | |
| | | |
tor-guardmgr: Add more tests for vanguards
Closes #1417 and #1408
See merge request tpo/core/arti!2167
|
| | | |
| | |
| | |
| | |
| | |
| | | |
We don't need this now that #1417 is fixed.
This reverts commit a9010f6300c25e4602ecf8017ca176c724ecdfa5.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously, HS stub circuit selection (with vanguards enabled) was
buggy: when selecting a circuit stub from the circ pool, we failed to
ensure its last hop was different from the circuit target. So in some
cases, arti would attempt to extend a stub circuit of the form G -> L2
[-> L3] -> T to T, which can't work, because a relay won't extend a
circuit to itself (or to its predecessor, for that matter).
Closes #1417
|
| | | |
| | |
| | |
| | | |
This will soon grow more complex.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Without this change, one of the tgen processes doesn't exit as expected:
```
618990:00:06:50.991981 [4717:shadow-worker] 00:30:00.000000000 [ERROR] [torclient-onion-artiserver:11.0.0.19] [process.rs:1525] [shadow_rs::host::process] process 'torclient-onion-artiserver.tgen.1001' exited with status StoppedByShadow; expected end state was exited: 0 but was running
```
This is because of a stub circuit selection bug that only manifests when
the `torclient-onion-artiserver` and
`torclient-onion-artiserver-full-vanguards` tests are run at the same
time.
See #1417 for more details.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This adds an onion service that uses full vanguards, and a client
that connects to it.
Closes #1408
|
| | | |
| | |
| | |
| | |
| | | |
Moving them to a separate variable makes the script more readable as we
add more hosts.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously, we'd `debug_assert` that the length of the path is valid.
However, `debug_` asserts are compiled out for release builds, which
means that if we have some code path that triggers the assertion
failure, it will go unnoticed unless our tests happen to exercise it.
It's safer to return an internal error, because we definitely don't want
to proceed if the path is too short (see arti#1400 and arti#1409).
Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2154#note_3030820
|
| |/ /
| |
| |
| | |
This checks that we can read `vanguards.json` state files.
|
| |\ \
| | |
| | |
| | |
| | | |
arti: Add vanguards settings to example config.
See merge request tpo/core/arti!2146
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
We are about to need this in other crates (for generating the tests for
the `NotAutoValue` implementations).
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This is a safeguard to prevent users from using ExplicitOrAuto with
types that serialize to the same value as ExplicitOrAuto::Auto.
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2146#note_3030692
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This will be used for the `vanguard.mode` config option. The
`VanguardMode` corresponding to the `"auto"` variant will depend
on whether the `vanguards` feature is enabled: if the feature is
enabled, it is mapped to `VanguardMode::Lite`, and
`VanguardMode::Disabled` otherwise.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
We want to export the `VanguardConfig` even if the `vanguards` feature
is disabled (we will need to unconditionally include it in the arti
config).
Note that if `vanguards` are disabled, the `VanguardMode` from the
`VanguardConfig` can only be `Dsiabled`.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This is already exported via the `pub mod vanguards` module, so there is
no need to export it from the top-level too. This *is* a breaking change,
but the downstream fix is trivial (and the type should never have been
exported directly from `arti_client::config` in the first place).
|
| |/ / |
|
| |\ \
| | |
| | |
| | |
| | | |
tor-keymgr: Add script for generating test key files.
See merge request tpo/core/arti!2121
|
| | | |
| | |
| | |
| | |
| | | |
The keys generated in this commit are reproducible using the
`maint/keygen-openssh-test/generate` script.
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
The README now applies to the generate.sh script too, so it had to be
updated.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This commit contains a new set of `tor-keymgr/testdata` keys,
generated using ./maint/keygen-openssh-test/generate.sh`.
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2121#note_3025369
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
`tor-keymgr/testdata` contains a bunch of OpenSSH keys used for testing.
I meant to share the script I generated them with, but somehow never got
around to it.
Note: the OpenSSH keys generated by this script are going to look
slightly different than the ones that are checked into the repo. This is
because some of those original key files were generated ad-hoc (I
manually modified them a while ago, but I forgot exactly how
|