summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | arti: rethink a TODO HSS about nicknamesNick Mathewson2023-12-121-1/+9
| | | | | | | | | | | | | | | | | | The TODO HSS in question is about our inability to serialize every possible builder. The right answer here might be to use something else instead of a ListBuilder.
| * | arti: Enforce onion service nickname distinctnessNick Mathewson2023-12-122-18/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The most logical way to do this was to change the "List" type to a HashMap, and add a build function to the ListBuilder. This change additionally renames: OnionServiceProxyConfig{List=>Map} NamedProxyMap => ProxyBuilderMap (We now have two kinds of map, and this name change will clarify the distinction.)
| * | arti: Downgrade a TODO HSS about testing onion-service config.Nick Mathewson2023-12-121-1/+2
| | | | | | | | | | | | | | | | | | | | | IIUC, there will never be a Some(InNew) entry here, since we will never have an onion service be configured by default. Instead we test this kind of configuration by having commented-out options that we uncomment as needed.
| * | arti: Generalize a TODO HSS about reconfiguration.Nick Mathewson2023-12-122-1/+10
| | | | | | | | | | | | | | | | | | It's correct that we'd like someday for the `arti` crate APIs to allow all the different modes supported by `Reconfigure` enum; this is #1156, and it does not block an HSS release.
| * | arti: conditionally expose onion_proxy module when experimental-api is enabledNick Mathewson2023-12-121-4/+4
| | |
| * | Remove TODOs obsoleted by onion service reconfiguration.Nick Mathewson2023-12-122-2/+0
| | | | | | | | | | | | (This was solved with !1798)
* | | Merge branch 'hss-cli' into 'main'gabi-2502023-12-145-2/+116
|\ \ \ | | | | | | | | | | | | | | | | arti: Add an hss subcommand. See merge request tpo/core/arti!1837
| * | | tor-hsservice: Add TODO about rethinking the HSS StateMgr API.Gabriela Moldovan2023-12-141-0/+3
| | | |
| * | | arti: Print out the onion address retrieved from StateMgr.Gabriela Moldovan2023-12-141-1/+15
| | | |
| * | | tor-hsservice: Add an hss state mgmt APIGabriela Moldovan2023-12-142-0/+47
| | | |
| * | | arti-client: Add an accessor for the keystore config.Gabriela Moldovan2023-12-142-0/+6
| | | |
| * | | arti: Add an hss subcommand.Gabriela Moldovan2023-12-141-2/+46
| | |/ | |/| | | | | | | Part of #1071
* | | Merge branch 'changmgr-timing' into 'main'Nick Mathewson2023-12-144-31/+21
|\ \ \ | | | | | | | | | | | | | | | | Fix continually_expire_channels timing issues See merge request tpo/core/arti!1834
| * | | shadow test: remove workaround for #1170Jim Newsome2023-12-131-9/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Disabling the shadow option --model-unblocked-syscall-latency causes this bug not to surface. Better to remove this workaround for now so that we can revisit again if/when it does rather than continue to mask it.
| * | | shadow test: disable --model-unblocked-syscall-latencyJim Newsome2023-12-131-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This option is mostly a workaround for busy loops and other subtle race conditions. While having it enabled can let us ignore some benign busy loops and timing edge cases, it can also hide real problems; e.g. burning extra CPU in a busy-loop. https://shadow.github.io/docs/guide/limitations.html#busy-loops
| * | | ChannelState::ready_to_expire: return true when rem time is zeroJim Newsome2023-12-131-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a race condition that would normally be fairly benign - it would result in scheduling to check for expired channels again immediately, and assuming non-zero time passes would then remove the channel. In Shadow's default time model though, zero time passes in this case, so we just keep scheduling to check again immediately forever; i.e. deadlock.
| * | | ChannelState::ready_to_expire: refactor using let-elseJim Newsome2023-12-131-18/+14
| | | |
| * | | continually_expire_channels: don't round off expiration delayJim Newsome2023-12-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Without this change, if the delay is less than one second, the code will effectively busy-loop until the delay has elapsed. This potentially leads to deadlock in shadow simulations, and wastes CPU in real usage. https://shadow.github.io/docs/guide/limitations.html?highlight=busy#busy-loops
| * | | continually_expire_channels: refactor using let-elseJim Newsome2023-12-131-3/+2
| |/ /
* | | Merge branch 'security-audit-of-the-daleks' into 'main'gabi-2502023-12-141-8/+34
|\ \ \ | |/ / |/| | | | | | | | Remove our cargo-audit exception for ed25519-dalek See merge request tpo/core/arti!1783
| * | Restore deleted entries to OBSOLETE_IGNORENick Mathewson2023-12-111-0/+23
| | | | | | | | | | | | | | | We should have added these to our record of previous rustsec ignores, but we accidentally removed them instead.
| * | Remove our cargo-audit exception for ed25519-dalekNick Mathewson2023-12-111-8/+11
| | | | | | | | | | | | It's no longer necessary now that we have upgraded.
* | | Merge branch 'todos-hss' into 'main'Nick Mathewson2023-12-133-25/+29
|\ \ \ | | | | | | | | | | | | | | | | Clear away some misc todos in tor-hsservice. See merge request tpo/core/arti!1819
| * | | hss: Explain why wait_for_netdir_to_list does not need more complexity.Nick Mathewson2023-12-131-6/+11
| | | |
| * | | hss::svc::netdir: Explain why it is okay to suppress errors.Nick Mathewson2023-12-121-1/+3
| | | |
| * | | hss::config: Downgrade or remove some TODO HSS comments.Nick Mathewson2023-12-121-16/+15
| | | |
| * | | hss: remove TODO about making DangerouslyNonAnonymous conditional.Nick Mathewson2023-12-121-2/+0
| | | |
* | | | Merge branch 'log_hsid_unconditionally' into 'main'Nick Mathewson2023-12-132-21/+23
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | hsservice: Log hsid whether we just generated it or not. See merge request tpo/core/arti!1830
| * | | | tor-hsservice: Retrieve the public hsid for logging purposes.gabi-2502023-12-131-3/+3
| | | | |
| * | | | hsservice: Log hsid whether we just generated it or not.Nick Mathewson2023-12-132-21/+23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With this change you can find your hsid in your logs (if safe logging is off) even if you forgot to notice it the first time around.
* | | | | Merge branch 'keymgr_enabled_default' into 'main'Nick Mathewson2023-12-133-33/+16
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | arti_client: Cleanup around keymgr feature and config See merge request tpo/core/arti!1832
| * | | | | arti_config: remove experimental-api as way to enable keymgr.Nick Mathewson2023-12-131-7/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | keymgr is always on when it is needed, so experimental-api isn't needed here.
| * | | | | arti-client: use sub_builder for ArtiNativeKeystoreConfigNick Mathewson2023-12-133-13/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The sub_builder pattern changes `StorageConfigBuilder` so that instead of holding an `Option<ArtiNativeKeystoreConfig>`, it holds an `ArtiNativeKeystoreConfigBuilder`. This makes it a little more ergonomic to use from Rust, and lets us use defaults for the builder fields so that we can make them optional in our configuration.
| * | | | | arti_client: enable keymgr when keymgr feature is configuredNick Mathewson2023-12-132-17/+10
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This change causes arti_client to have a configurable keymgr when the onion-service-service feature is present, so that you no longer need to configure "experimental" or "experimental-api" as well in order to get a working onion service.
* | | | | Merge branch 'circmgr_warning' into 'main'Nick Mathewson2023-12-131-2/+3
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | circmgr:Resolve a warning when building without ntor-v3 See merge request tpo/core/arti!1831
| * | | | | circmgr:Resolve a warning when building without ntor-v3Nick Mathewson2023-12-131-2/+3
| |/ / / /
* | | | | Merge branch 'shadow-onion-svc' into 'main'gabi-2502023-12-1312-8/+151
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | shadow ci: test arti hs server functionality See merge request tpo/core/arti!1827
| * | | | | shadow test: add tor client connecting to arti hsJim Newsome2023-12-134-1/+16
| | | | | |
| * | | | | editorconfig: exclude arti HS keys in shadow testJim Newsome2023-12-131-1/+1
| | | | | |
| * | | | | shadow test: add client for arti hsJim Newsome2023-12-135-1/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This also adds a workaround - the arti service doesn't appear to register itself (set up intro points) unless first used as a client.
| * | | | | shadow test: add hidden service keystore to templateJim Newsome2023-12-132-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | This is to ensure a stable HS address.
| * | | | | shadow test: add fileserver-onion-artiJim Newsome2023-12-132-0/+24
| | | | | |
| * | | | | shadow ci: use proxy.sock_listen instead of socks_portJim Newsome2023-12-131-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | socks_port is deprecated
| * | | | | shadow ci: reformat arti argument lists (no-op)Jim Newsome2023-12-131-5/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Put one argument per line and use a yaml list instead of string (shadow accepts either here).
| * | | | | arti-extra build: enable onion-service-serviceJim Newsome2023-12-131-1/+1
| | | | | |
| * | | | | arti-extra build: no-op reformatJim Newsome2023-12-131-1/+5
|/ / / / /
* | | | | Merge branch 'publisher-do-not-retry-fatal' into 'main'gabi-2502023-12-131-16/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: If the error is fatal, do not retry the desc upload. See merge request tpo/core/arti!1821
| * | | | | tor-hsservice: If the error is fatal, do not retry the desc upload.Gabriela Moldovan2023-12-131-16/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The errors returned by `upload_all` are now all fatal, so we there is no point in retrying `upload_all` on failure. Note this will exacerbate #1155, as it will cause the seemingly transient time skew issues to become fatal (the corresponding error type is `Bug`, so in principle they ought to be fatal)
* | | | | | Merge branch 'replay' into 'main'Ian Jackson2023-12-1317-59/+310
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | Make IPT logs persistent See merge request tpo/core/arti!1824
| * | | | | arti-client: TorClient.storage_mistrust: Correct doc commentIan Jackson2023-12-131-1/+6
| | | | | |