| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
The script isn't handling the `cfg_attr` on `pub mod restricted_discovery`
very well, so we need to use the `additional_required` escape hatch.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Without it, if the `restricted-discovery` feature is compiled out, the
module gets documented as:
```
Non-restricted-discovery (Available on non-crate feature `restricted-discovery`
only)
```
which is inaccurate.
|
| | |/ / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This makes the script work on `cfg_attr`s applied to `mod` declarations
ending in `;`.
Without this change, the script fails with
```
processing tor-hsservice
res += fn(os.path.join(dir_, file))
^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/builds/nickm/arti/./maint/check_doc_features", line 112, in extract_cfg_attr
end = min(subline.find(pat) for pat in ' (<' if subline.find(pat) !=-1)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ValueError: min() arg is an empty sequence
```
when run on code with `cfg_attr`s applied to `mod` declarations.
Note: this change just improves the UX a bit, but doesn't actually fix
the issue: the script still isn't able to handle `cfg_attr`'d `mod`s: it
assumes all `#[cfg_attr(docsrs, ..)]` statements are applied to
feature-gated `pub use`s, and if there aren't any (such as in the case
of `cfg_attr`d modules, it assumes the feature gating is missing.
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
Don't require TRANSPORT for PT STATUS messages.
See merge request tpo/core/arti!2307
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
See: tpo/core/arti#1488.
|
| | |/ / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This patch changes the PT STATUS handler to not require the presence of
the `TRANSPORT` field in the K/V line. This matches current behaviour of
C Tor and was requested by the Anti-censorship Team at an earlier point
to enable STATUS messages to work for situation where it's not transport
specific messages.
To avoid future issues, we simply ignore any required keys right now
even though TYPE is to be expected.
See: tpo/core/torspec#267
See: tpo/core/torspec!63
See: tpo/core/arti#1488
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
shadow test: Add tests for restricted discovery hidden services
See merge request tpo/core/arti!2272
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This tests that the client configured in the `authorized_clients`
directory of the service is able to connect.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This helped me debug some shadow test failures.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This enables us to test "restricted discovery" mode in shadow.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This will be used with the new `fileserver-onion-arti-auth` test hidden
service.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This adds a new restricted discovery hidden service
(`fpqqmiwzqiv63jczrshh4qcmlxw6gujcai3arobq23wikt7hk7ojadid.onion`)
that has 2 authorized clients:
* `alice`, the client configured in the `restricted_discovery.static`
list in its TOML config
* `default`, the client configured in `authorized_clients/default.auth`
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
rpc-client-core: Always re-encode requests and responses, and preserve unrecognized struct fields.
Closes #1491
See merge request tpo/core/arti!2312
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This enable a `meta` object to have no `updates` field set.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
We want to re-encode responses to avoid possible mismatch between
how arti-rpc-client-core parses messages and how the user application
parses messages. (In theory this shouldn't be necessary so long as
arti-rpc-client-core and arti have the same json implementation,
and arti-rpc-client-core is only used for talking to arti.
But those assumptions might change in the future.)
Closes #1491.
We want to preserve fields so that, if Arti adds any new elements
to response or error in the future, and the client knows about them,
they won't be lost simply because arti-rpc-client-core hasn't heard
of them.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
When writing a request, we want to keep any fields that we don't
recognize, in case the application (and arti) know about some
field that we haven't heard of.
|
| | | |/ / /
| |/| | |
| | | | |
| | | | | |
(They are about to diverge even further.)
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-hsservice: Add service-side config for enabling restricted discovery mode
Closes #1292
See merge request tpo/core/arti!2266
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This also adds a test for it.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This rewrites `RestrictedDiscoveryConfig::read_keys` to give
`static_keys` precedence over the keys from `key_dirs`.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
MAX_RESTRICTED_DISCOVERY_CLIENTS.
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2266#note_3051758
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
descriptor.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
The base64ct dependency is now unused in tor-hsservice, so we should
consider removing it at some point.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
We can just used `build_for_arti()` here.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
`BuilderExt` will soon be used in tor-hsservice too (for configuring the
mistrust settings of the client "restricted mode" authorization keys).
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Needed because such keys will be stored in the `OnionServiceConfig`.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Restricted discovery mode is initially going to be gated behind the
experimental `restricted-discovery` feature.
Part of #1292
|
| |/ / / / / |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
integration-shadow test: fix broken reference to apt-install script
See merge request tpo/core/arti!2309
|
| | |/ / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Relative directory reference here is incorrect since we changed
directories. Move this line to before the directory-change.
Looks like this was broken in c4e1d0c582164e17e0226af754a08692da5efb29,
but only surfaces on a cache miss of the tgen build.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
arti: Add docs for the hsc module.
See merge request tpo/core/arti!2304
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This also makes the `tests/testcases/hsc/hsc.md` test case a symlink to
`doc/hsc.md`.
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This adds a bit more information to `hsc.md`.
Note: `hsc.md` is currently just a test case for the CLI tests. A future
commit promote it to module-level README.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Fix a pair of typos in an ffi comment.
See merge request tpo/core/arti!2310
|
| | |/ / / / |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
ffi: Expose errno from errors that have it.
Closes #1501
See merge request tpo/core/arti!2311
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Closes #1501.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
(This is an errno or a GetLastError.)
|