summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | Merge branch 'publisher-svc-status' into 'main'David Goulet2024-09-1019-176/+667
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Improve descriptor publisher status reporting Closes #1216 and #1572 See merge request tpo/core/arti!2397
| * | | | tor-hsservice: Add tests for status changes induced by descriptor uploads.Gabriela Moldovan2024-09-091-1/+185
| | | | |
| * | | | tor-netdir: Allow access to the `ConsensusBuilder` when building test ↵Gabriela Moldovan2024-09-091-1/+6
| | | | | | | | | | | | | | | | | | | | netdirs (fmt).
| * | | | tor-netdir: Allow access to the `ConsensusBuilder` when building test netdirs.Gabriela Moldovan2024-09-0911-31/+32
| | | | | | | | | | | | | | | | | | | | | | | | | This allows us to set SRVs for example (needed because by default, the test `NetDir` is built from a consensus that doesn't contain any SRVs).
| * | | | tor-hsservice: Include descriptor upload errors in onion service status.Gabriela Moldovan2024-09-091-9/+17
| | | | |
| * | | | tor-hsservice: Change the error type in Problem::DescriptorUpload.Gabriela Moldovan2024-09-093-3/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will need to return a list of descriptor upload errors. We can't return a `Vec<RetryError<DescUploadError>>` here because `DescUploadError` is a lower-level error type that can't express that e.g. the upload timed out.
| * | | | tor-hsservice: Remove unused UploadError variant (fmt).Gabriela Moldovan2024-09-091-3/+1
| | | | |
| * | | | tor-hsservice: Remove unused UploadError variant.Gabriela Moldovan2024-09-092-6/+2
| | | | | | | | | | | | | | | | | | | | | | | | | We never return `UploadError::Timeout` (timeouts are represented as `BackoffError::Timeout`).
| * | | | tor-hsservice: Rename UploadStatus to UploadResult.Gabriela Moldovan2024-09-091-4/+4
| | | | | | | | | | | | | | | | | | | | This type is a `Result`, renaming for clarity.
| * | | | tor-hsservice: Remove outdated comment about publisher.Gabriela Moldovan2024-09-091-17/+0
| | | | | | | | | | | | | | | | | | | | The descriptor publisher docs live in the `publisher` module.
| * | | | tor-hsservice: Fill out the missing descriptor publisher docs.Gabriela Moldovan2024-09-092-8/+66
| | | | | | | | | | | | | | | | | | | | Closes #1216
| * | | | tor-hsservice: Return Bug where possible.Gabriela Moldovan2024-09-091-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | This makes it clearer that some of these functions are essentially infallible.
| * | | | tor-hsservice: Update docs with new status reporting logic.Gabriela Moldovan2024-09-091-12/+32
| | | | |
| * | | | tor-hsservice: Add basic tests for publisher status reporting.Gabriela Moldovan2024-09-092-4/+52
| | | | |
| * | | | tor-hsservice: Validate the authorized clients before publishing.Gabriela Moldovan2024-09-092-2/+40
| | | | | | | | | | | | | | | | | | | | | | | | | This enables us to report a "broken" service status if restricted discovery is enabled but the authorized_clients list is empty.
| * | | | tor-hsservice: Set the publisher State based on the upload results.Gabriela Moldovan2024-09-091-29/+106
| | | | | | | | | | | | | | | | | | | | Closes #1572
| * | | | tor-hsservice: Add Degraded{Unr,R}eachable onion svc states.Gabriela Moldovan2024-09-093-3/+17
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Currently, the `DegradedReachable` status is only reported by the the IPT manager and `DegradedUnreachable` is unused. Soon we'll the publisher reporting `DegradedReachable` or `DegradedUnreachable` or `Running`, depending on how the descriptor uploads went.
| * | | | tor-hsservice: Store the upload result in TimePeriodContext.Gabriela Moldovan2024-09-091-2/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will allows us determine the ComponentStatus of the publisher (it'll be either `Running` or `Degraded`, depending on whether the upload failed).
| * | | | tor-hsservice: Don't update the onion svc status when publisher goes idle.Gabriela Moldovan2024-09-091-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | After uploading the descriptor, the publisher transitions into the `Idle` state. This transition happens even if the upload was unsuccessful, so it shouldn't cause the onion service status to become `Running` (because `Running` implies the service is fully reachable, and if the publisher failed to upload the descriptor to some or all HsDirs, that won't necessarily be the case). A future commit will set the publisher's onion svc `State` to `Running`/`Recovering`/`Broken` according to the upload status.
| * | | | tor-hsservice: Add a comment noting where the publisher tests live.Gabriela Moldovan2024-09-091-0/+2
| | | | |
| * | | | tor-hsservice: Replace UploadStatus enum with type alias.Gabriela Moldovan2024-09-091-24/+6
| | | | | | | | | | | | | | | | | | | | This resolves a TODO.
| * | | | tor-hsservice: Store the authorized_clients in the mutable state of the reactor.Gabriela Moldovan2024-09-092-17/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, these were stored in the immutable state behind a mutex, but since they're not really immutable (we update them if the config changes), it makes more sense to put them in `State`.
| * | | | tor-hsservice: Remove outdated IPT manager TODOs.Gabriela Moldovan2024-09-091-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | These TODOs were addressed a while ago (when we introduced `IptManager::ipt_errors`).
| * | | | tor-hsservice: Remove dead_code allows.Gabriela Moldovan2024-09-091-4/+1
| | | | | | | | | | | | | | | | | | | | | | | | | These aren't dead code anymore, with the exception of `PublisherStatusSender::send_recovering`, which isn't used.
| * | | | tor-hsservice: Log the onion svc status.Gabriela Moldovan2024-09-091-1/+15
| | | | | | | | | | | | | | | | | | | | We now log the onion service status on change.
| * | | | tor-hsservice: Remove an outdated TODO.Gabriela Moldovan2024-09-091-2/+0
| | | | | | | | | | | | | | | | | | | | This is already implemented.
| * | | | tor-hsservice: Move a misplaced TODO.Gabriela Moldovan2024-09-091-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This TODO was added in !2353 and was supposed to be about reporting a broken/degraded onion service status if the restricted discovery config watcher fails.
* | | | | Merge branch 'socks-typo' into 'main'Nick Mathewson2024-09-101-2/+3
|\ \ \ \ \ | |_|_|_|/ |/| | | | | | | | | | | | | | Fix a typo in WRONG_PROTOCOL_PAYLOAD. See merge request tpo/core/arti!2403
| * | | | Fix a typo in WRONG_PROTOCOL_PAYLOAD.Pier Angelo Vendrame2024-09-101-2/+3
|/ / / /
* | | | Merge branch 'bytes-deficit' into 'main'Ian Jackson2024-09-1014-36/+104
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | Add a deficit field to tor_bytes::Error::Truncated Closes #1592 See merge request tpo/core/arti!2390
| * | | tor-bytes: Error::Truncated: mark the deficit as Sensitive (fmt)Ian Jackson2024-09-101-2/+4
| | | |
| * | | tor-bytes: Error::Truncated: mark the deficit as SensitiveIan Jackson2024-09-103-1/+8
| | | | | | | | | | | | | | | | | | | | Suggested in https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2390#note_3072975
| * | | tor-bytes: Add a deficit field to Error::Truncated (fmt)Ian Jackson2024-09-102-2/+6
| | | |
| * | | tor-bytes: Add a deficit field to Error::TruncatedIan Jackson2024-09-109-14/+23
| | | | | | | | | | | | | | | | This will allow us to fix #1592, but it doesn't do so yet.
| * | | Introduce and use tor_bytes::Error::new_truncated_for_test (fmt)Ian Jackson2024-09-101-1/+5
| | | |
| * | | Introduce and use tor_bytes::Error::new_truncated_for_testIan Jackson2024-09-104-21/+36
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is going to want to do something more complicated (as described in the docs). In this commit we change all the tests that are expecting Truncated errors. That reduces noise in the next commit.
| * | | tor-bytes: Document Readable::take_from correctness propertiesIan Jackson2024-09-101-0/+29
| | | | | | | | | | | | | | | | | | | | | | | | This refers to the `deficit` field in Error::Truncated, which is going to appear in a later commit. It seems kinder to my reviewer to add this doc now early in the branch.
| * | | tor-linkspec: reading tests: Use assert_eqIan Jackson2024-09-101-6/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Error::Truncated is going to become more complicated, and anyway it would be nice to print the values if the test fails. Error is PartialEq now. (Maybe it wasn't when this was written?)
| * | | tor-bytes: advance: Call peek for the error checkIan Jackson2024-09-101-3/+1
|/ / / | | | | | | | | | | | | This removes one construction site of Error::Truncated. We are about to make constructing one of those more fiddly.
* | | Merge branch 'relay-err' into 'main'David Goulet2024-09-096-5/+127
|\ \ \ | | | | | | | | | | | | | | | | arti-relay: add and use `Error`/`ErrorDetail` See merge request tpo/core/arti!2392
| * | | arti-relay: add and use `Error`/`ErrorDetail`Steven Engler2024-09-055-4/+126
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Most of this is copied from `arti_client::err`, but with a lot of stuff removed to simplify the error types (for example no `error_detail` feature handling). I tried to keep things generally consistent with arti-client so that error handling will be similar in both crates. `TorRelayBuilder::create()` will likely need to be fallible in the future (for example if spawning a task for the OR port listener fails), so it now returns a `Result<TorRelay, crate::err::Error>` instead of just a `TorRelay`.
| * | | arti-client: minor documentation grammar fixSteven Engler2024-09-051-1/+1
| | | |
* | | | Merge branch 'pr/arti/keymgr/use-keypairs-if-available' into 'main'gabi-2502024-09-0914-24/+129
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | eliminate all but one use of `KeyMgr::get::<HsIdKeypair>()` Closes #1194 See merge request tpo/core/arti!2393
| * | | rename get_keypair_specifier() to keypair_specifier()Adam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-094-8/+8
| | | | | | | | | | | | | | | | https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2393#note_3073480
| * | | tor_hsservice use get::<HsIdKey> rather than get::<HsIdKeypair>Adam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-094-22/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There are three places where we query the KeyMgr for an `HsIdKeypair` but all we really need is the public part. This commit changes those three callsites to instead use `get::<HsIdKey>`. This relies on the previous commit, which makes sure that a request for an `HsIdKey` will always succeed if the keystore has a `HsIdKeypair` with the same service nickname.
| * | | tor_keymgr: teach the KeyStore how to satisfy public key requests using a ↵Adam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-091-1/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | keypair Now that: - KeySpecifier::get_keypair_specifier() can be used to convert the KeySpecifier for a public key into the KeySpecifier for its secret key - ToEncodableKey<Key=PublicKey> has a "type level pointer" to ToEncodableKey<Key=KeyPair> We can use these two features together to automatically satisfy any request to get a public key using the corresponding secret key (if available).
| * | | tor_key_forge::traits::ToEncodableKey: add KeyPair associated typeAdam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-093-1/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This comment adds a second associated type `KeyPair` to ToEncodableKey. For a `ToEncodableKey` which represents a (secret) KeyPair, this type is Self. For a `ToEncodableKey` which represents a public key, this is the `ToEncodableKey` whose `Key` is the pair of which this is the public part. This is essentially a "type level pointer" from the ToEncodableKey for a public key to the ToEncodableKey for its secret key.
| * | | tor_keymgr: add get_keypair_specifier() to KeySpecifier, and derive itAdam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-096-0/+35
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a new method `get_keypair_specifier()` to `KeySpecifier`. This method is used to indicate when one KeySpecifier (e.g. `KP_hs_id`) is the public part of another keypair (e.g. `KS_hs_id`). It will return the containing keypair in this case, and `None` otherwise.
| * | | tor_hsservice: add `impl From<&FooPublicKeySpecifier> for ↵Adam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-094-0/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | FooKeypairSpecifier` instances This adds the following trivial `From` instances: - tor_hsservice: impl From<&HsIdPublicKeySpecifier> for HsIdKeypairSpecifier - tor_hsservice: impl From<&BlindIdPublicKeySpecifier> for BlindIdKeypairSpecifier - tor_hscrypto::pk: impl From<HsBlindIdKeypair> for HsBlindIdKey - tor_llcrypto::pk::ed25519: impl From<ExpandedKeypair> for PublicKey - tor_keymgr::mgr: impl From<TestKey> for TestPublicKey - tor::hscrypto::pk: impl From<HsIdKeypair> for HsIdKey
* | | | Merge branch 'rpc-connect' into 'main'Nick Mathewson2024-09-0920-22/+1097
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | rpclib: Support opening a data stream. Closes #1524 See merge request tpo/core/arti!2373