summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * tor-hsservice: Read the keypair when deriving the subcredentials.Gabriela Moldovan2024-02-011-5/+8
| | | | | | | | | | We're about to stop storing `KP_hs_id` in the keystore, so in preparation, let's update the callsites that attempt to retrieve it.
| * tor-hsservice: Extract the onion name from the keypair.Gabriela Moldovan2024-02-011-3/+6
| | | | | | | | We're about to stop storing the public part of the hsid in the keystore.
| * tor-keymgr: Make KeyMgr::generate return the generated key.Gabriela Moldovan2024-02-011-4/+12
| | | | | | | | | | | | | | `KeyMgr::generate` is now quite similar to `KeyMgr::get_or_generate`, so we will soon remove the latter. Part of #1074
| * tor-keymgr: Add error variant for when a key shouldn't exist.Gabriela Moldovan2024-02-012-0/+6
| | | | | | | | | | | | | | This will be returned by `KeyMgr::generate` if the key to be generated already exists and `overwrite` is `false`. Part of #1074
* | Merge branch 'publisher-rate-lim' into 'main'gabi-2502024-02-012-126/+85
|\ \ | |/ |/| | | | | tor-hsservice: Reimplement upload rate-limiting using TrackingNow. See merge request tpo/core/arti!1951
| * tor-hsservice: Apply deferred cargo fmt.Gabriela Moldovan2024-02-011-8/+5
| |
| * tor-hsservice: Remove unnecessary trace! log.Gabriela Moldovan2024-02-011-1/+0
| |
| * tor-hsservice: Remove old upload rate-limiting code.Gabriela Moldovan2024-02-011-97/+1
| |
| * tor-hsservice: Reimplement upload rate-limiting using TrackingNow.Gabriela Moldovan2024-02-011-2/+16
| | | | | | | | | | | | | | | | | | | | | | This simplifies the publisher code in preparation for #1241 This replaces the overly complicated task-based approach to rate-limiting with a simpler one, where the publisher has: * a separate `RateLimited` state that indicates it is rate-limited, and for how long * an additional arm in its `run_once()` `select_biased!`, which checks if the rate-limit has expired
| * tor-hsservice: Update docs with the new RateLimited state.Gabriela Moldovan2024-02-011-10/+10
| |
| * tor-hsservice: Add functions for starting/stopping the rate-limiting.Gabriela Moldovan2024-02-011-0/+22
| |
| * tor-hsservice: Add a RateLimited publisher status.Gabriela Moldovan2024-02-011-9/+36
| |
| * tor-hsservice: Remove an unnecessary TODO.Gabriela Moldovan2024-02-011-4/+0
| | | | | | | | | | We _do_ schedule the rate-limited upload at `now + UPLOAD_RATE_LIM_THRESHOLD`, see `schedule_rate_lim_upload()`.
| * tor-hsservice: Downgrade a warn! to debug!.Gabriela Moldovan2024-02-011-2/+2
|/ | | | | This shouldn't be a warning (it's logged when the reactor is shutting down, not when it crashes).
* Merge branch 'hide_onionservicestate' into 'main'Nick Mathewson2024-02-011-17/+22
|\ | | | | | | | | | | | | Make the OnionServiceState type crate-private. Closes #1228 and #1261 See merge request tpo/core/arti!1946
| * Make the OnionServiceState type crate-private.Nick Mathewson2024-02-011-17/+22
|/ | | | Closes #1261.
* Merge branch 'high-level-docs' into 'main'Nick Mathewson2024-02-012-7/+59
|\ | | | | | | | | | | | | Add some higher-level documentation for tor-hsservice. Closes #1228 See merge request tpo/core/arti!1945
| * Correct description of parametersIan Jackson2024-02-011-1/+1
| |
| * Note that old state is not yet removedIan Jackson2024-02-011-0/+3
| |
| * Add some higher-level documentation for tor-hsservice.Nick Mathewson2024-01-312-7/+56
| | | | | | | | Closes #1228.
* | Merge branch 'rename-hs-dir' into 'main'gabi-2502024-02-014-19/+19
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Rename the service keystore dir to "hss". Closes #1260 See merge request tpo/core/arti!1949
| * | tor-hsservice: Rename the service keystore dir to "hss".Gabriela Moldovan2024-02-014-19/+19
|/ / | | | | | | | | | | | | | | | | | | | | The onion service keys now live in the `hss/<nickname>` subdirectory within the keystore. This layout change is **not** backwards-compatible, so if you want to use your existing hidden service keys, you will need to manually move them to `<keystore_root>/hss`. Closes #1260
* | Merge branch 'state-use' into 'main'Ian Jackson2024-02-0114-201/+196
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Switch to state_dir for non-key state Closes #1183 See merge request tpo/core/arti!1941
| * | tor-hsservice: Use tor_persist::state_dirIan Jackson2024-02-012-2/+4
| | |
| * | tor-hsservice: Remove now-unused importsIan Jackson2024-02-013-8/+4
| | |
| * | tor-hsservice: tests: create_storage_handles: use a real directory (churn)Ian Jackson2024-02-011-1/+1
| | | | | | | | | | | | Mandatory use line shuffling.
| * | tor-hsservice: Abolish StartupError::StateLockedIan Jackson2024-02-011-5/+0
| | | | | | | | | | | | This is now tor_persist::Error containing ErrorSource::AlreadyLocked.
| * | tor-hsservice: Drop now-unused fslock dependencyIan Jackson2024-02-014-4/+0
| | | | | | | | | | | | We're just using fslock-guard now.
| * | tor-hsservice: Use tor_persist::state_dir, etc. (fmt)Ian Jackson2024-02-013-22/+28
| | |
| * | tor-hsservice: Use tor_persist::state_dirIan Jackson2024-02-017-150/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We no longer do replay log locking in IptManager::new. Instead, we rely on the acquire_instance call in OnionService::launch, which ends up with ipt_mgr getting an InstanceHandle (which contains a lock guard). OnionServiceStateMgr is abolished; it existed to deal with the generics in the tor_persist::StateMgr API. state_dir has no generics (other than the T being loaded/stored). Many places (structs and argument lists) now have state_dir types which embody a path (or a CheckeDir) along with a lock, rather than separate path+lock+mistrust. The creation/startup code uses the new calls from state_dir. Other more minor changes: - StartupError::StateDirectoryInaccessible contains tor_persist::Error - test::create_storage_handles_from_state_dir changed and renamed, from _from_state_mgr. - replay::PersistFile's (separate) file lock is now fslock_guard's
| * | tor-hsservice: Introduce StartupError::StateDirectoryInaccessibleIoIan Jackson2024-02-012-5/+26
| | | | | | | | | | | | | | | | | | We're going to change the payload of StateDirectoryInaccessible to tor_persist::Error, since that's what tor_persist::state_dir gives us, but then we can't use it here.
| * | tor-hsservice: tests: create_storage_handles: use a real directory (fmt)Ian Jackson2024-02-011-1/+5
| | |
| * | tor-hsservice: tests: create_storage_handles: use a real directoryIan Jackson2024-02-013-5/+15
| | | | | | | | | | | | | | | | | | | | | state_dir doesn't have the in-memory dummy implementation, so there will have to be a real directory here. Do that now, as prep.
| * | tor-hsservice: ipt_mgr: Move storage handle to stateIan Jackson2024-02-012-9/+11
| | | | | | | | | | | | | | | The new state_dir types require &mut for storing, which is correct, but that means we can't have it in Immutable.
| * | tor-hsservice: impl state_dir::InstanceIdentity for HsNicknameIan Jackson2024-02-011-0/+10
| | |
| * | tor-hsservice: storage: Move Arcs into type aliasesIan Jackson2024-02-014-12/+12
| | | | | | | | | | | | | | | | | | | | | These are here because that's what you get from the tor_persist singleton StageMgr API (for type erasure reasons). We're going to change these to tor_persist::state_dir types and those don't involve Arcs.
| * | tor-hsservice: ipt_set: Make store method take &mut selfIan Jackson2024-02-011-1/+1
| | | | | | | | | | | | | | | Only people who can mutate the state ought to be saving it. Otherwise there might be concurrent overwrites.
| * | tor-hsservice: tests: Add a missing drop callIan Jackson2024-02-011-0/+2
| | | | | | | | | | | | | | | | | | This doesn't actually change the behaviour with current Rust. But it avoids bugs and future changes. Relying on drop order for temporary directory lifetime seems bad.
| * | tor-persist: state_dir: Add some missing Clone and Debug implsIan Jackson2024-02-011-5/+5
| | |
| * | tor-persist: state_dir: Introduce way to get at underlying lock guardIan Jackson2024-02-013-3/+40
| | | | | | | | | | | | | | | | | | And export the type, so callers don't need to depend directly on fslock_guard; many callers will need to own the returned value, not do anything else with it.
| * | tor-persist: state_dir: Make the storage handle Send and SyncIan Jackson2024-02-011-2/+5
|/ /
* | Merge branch 'clippy' into 'main'Nick Mathewson2024-01-318-8/+8
|\ \ | | | | | | | | | | | | Fix nightly clippy warnings See merge request tpo/core/arti!1942
| * | gsoc2023: download-manager: Truncate the output fileIan Jackson2024-01-311-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Without this we might end up with a mixture of new file and previous wreckage. If this were released code I would think about treating this as a security issue. Prompted by clippy.
| * | clippy: Use Result::cloned in several placesIan Jackson2024-01-313-3/+3
| | |
| * | tor-dirmgr: Simplify a clone call (fmt)Ian Jackson2024-01-311-3/+1
| | |
| * | tor-dirmgr: Simplify a clone callIan Jackson2024-01-311-2/+1
| | | | | | | | | | | | Prompted by clippy.
| * | arti-rpcserver: Add an allowIan Jackson2024-01-311-0/+1
| | |
| * | tor-rpcbase: Add an allowIan Jackson2024-01-311-0/+1
| | |
| * | tor-error: Backtrace: Remove a Captured(...) from a DisplayIan Jackson2024-01-311-1/+1
| | | | | | | | | | | | | | | Prompted by clippy complaining that the content wasn't ever read other than by the autogenerated Debug impl.
* | | Merge branch 'ci3' into 'main'Nick Mathewson2024-01-311-0/+2
|\ \ \ | |_|/ |/| | | | | | | | CI: Run coverage test on bigger runners See merge request tpo/core/arti!1944