summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | maint/crates-io-utils.sh: Add preserving tmp featureIan Jackson2024-06-241-2/+8
| | | | | | | | | | | | This is useful for debugging.
| * | maint/crates-io-utils.sh: Add exit status control featureIan Jackson2024-06-241-1/+5
| | |
| * | maint/crates-io-utils.sh: Break out from cargo-publishIan Jackson2024-06-242-30/+62
| | |
| * | shellcheck: check *.sh files tooIan Jackson2024-06-241-1/+4
| |/ | | | | | | | | We (will) use `*.sh` for shell include files. We're about to make one of these.
* | Merge branch 'fslock-retry' into 'main'Nick Mathewson2024-06-246-10/+150
|\ \ | |/ |/| | | | | | | | | TorClientBuilder: Add the ability to retry when fslock fails Closes #1464 See merge request tpo/core/arti!2198
| * Add a maximum to local_resource_timeout.Nick Mathewson2024-06-242-8/+33
| |
| * local_resource_timeout: Change wait interval to 50 ms.Nick Mathewson2024-06-241-1/+1
| |
| * Rename fslock_timeout to local_resource_timeoutNick Mathewson2024-06-241-11/+16
| | | | | | | | Name chosen to match the error kind that we're detecting.
| * Clarify documentation about blocking.Nick Mathewson2024-06-241-2/+4
| |
| * arti: wait a short while on startup if lockfiles are unavailable.Nick Mathewson2024-06-241-1/+1
| |
| * TorClientBuilder: Wait for a little while if the lockfiles are held.Nick Mathewson2024-06-243-4/+111
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a parameter to TorClientBuilder that control how long we should retry constructing a TorClient if we get a LocalResourceInUse error. When this parameter is not set, we default to 500 milliseconds for async entry points and 0 milliseconds for sync entry points. (`LocalResourceInUse` usually means that a lockfile is held by somebody else; but when the resource is some other type, we typically want the same behavior anyway.) (I really don't want to introduce delays by default for the create_unbootstrapped case, since it previously had no delay at all.) There is now also an async entry point to create an unbootstrapped TorClient. Closes #1464.
| * TorClientBuilder: take self by reference when buildingNick Mathewson2024-06-242-4/+5
|/ | | | | There is no actual reason to consume this type, and taking it by reference allows us to retry.
* Merge branch 'refactor-hspath' into 'main'gabi-2502024-06-203-153/+301
|\ | | | | | | | | | | | | tor-circmgr: Refactor VanguardHsPathBuilder::pick_path Closes #1459 See merge request tpo/core/arti!2205
| * tor-circmgr: Clarify the update_last_hop_kind documentation.Gabriela Moldovan2024-06-201-2/+10
| |
| * tor-circmgr: Rename VanguardPath to PathBuilder.Gabriela Moldovan2024-06-202-13/+12
| |
| * tor-circmgr: Remove duplicated path building logic from HS pool.Gabriela Moldovan2024-06-201-30/+19
| |
| * tor-circmgr: Fix clippy warning.Gabriela Moldovan2024-06-201-1/+1
| |
| * tor-circmgr: Gate vanguard-specific code behind vanguards feature.Gabriela Moldovan2024-06-201-0/+15
| | | | | | | | | | | | | | This is just code motion: moving the vanguard-specific parts of `maybe_extend_stub_circuit()` behind the `vanguards` feature will enable us to refactor it to use `select_middle_for_vanguard_circuit()`, which is only available if the `vanguards` feature is enabled.
| * tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts (fmt).Gabriela Moldovan2024-06-201-5/+2
| |
| * tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts.Gabriela Moldovan2024-06-202-118/+259
| | | | | | | | | | | | This is a follow up from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2186#note_3035525 Closes #1459
| * tor-circmgr: Remove unnecessary TODO.Gabriela Moldovan2024-06-201-1/+0
|/ | | | There's not much to refactor about this line.
* Merge branch 'test-hspath' into 'main'gabi-2502024-06-207-83/+566
|\ | | | | | | | | tor-circmgr: Write tests for the HsPathBuilder. See merge request tpo/core/arti!2199
| * tor-circmgr: Rename HsCircStubKind::len to HsCircStubKind::num_hops.Gabriela Moldovan2024-06-202-5/+5
| |
| * tor-circmgr: Note which test prevents TROVE-2024-005.Gabriela Moldovan2024-06-201-0/+1
| | | | | | | | | | | | This test is not new (it was added in !2168), but I think it's a good idea to annotate the tests preventing security issues with the TROVE number and/or arti ticket they pertain to.
| * tor-circmgr: Write tests for the HsPathBuilder.Gabriela Moldovan2024-06-203-0/+465
| | | | | | | | | | | | | | These tests should give us *some* assurance that the upcoming `HsVanguardPathBuilder` refactoring doesn't break anything. Part of #1459
| * tor-circmgr: Refactor duplicated circuit stub length calculation.Gabriela Moldovan2024-06-202-27/+26
| | | | | | | | Part of #1459
| * tor-guardmgr: Make some vanguard test helpers public (fmt).Gabriela Moldovan2024-06-201-10/+5
| |
| * tor-guardmgr: Make some vanguard test helpers public.Gabriela Moldovan2024-06-202-51/+69
| | | | | | | | | | | | We will soon need these helpers outside of `tor-guardmgr` too. This commit is mainly code motion.
| * tor-circmgr: Add a TODO about an unused restriction.Gabriela Moldovan2024-06-201-0/+5
|/
* Merge branch 'update-curve25519-dalek' into 'main'gabi-2502024-06-201-9/+2
|\ | | | | | | | | | | | | Update curve25519-dalek to 4.1.3. Closes #1468 See merge request tpo/core/arti!2211
| * Update curve25519-dalek to 4.1.3.Gabriela Moldovan2024-06-201-9/+2
|/ | | | | | | | | This updates our `curve25519-dalek` dependency to 4.1.3, which doesn't have the issues described in RUSTSEC-2024-0344. Closes TROVE-2024-007 and #1468 Fixes the failing cargo-audit job.
* Merge branch 'ticket1432_01' into 'main'David Goulet2024-06-189-0/+68
|\ | | | | | | | | | | | | tls: Support export keying material (RFC 5705) Closes #1432 See merge request tpo/core/arti!2185
| * tls: Support export keying material (RFC 5705)David Goulet2024-06-189-0/+68
| | | | | | | | | | | | | | | | | | | | | | | | | | Add a function to get the keying material as detailed by RFC 5705. Because native-tls doesn't have such support, there is a place holder panic!() for now. This means that for the forseable future, relay would only work with rustls until we figure out a solution for native-tls. Closes #1432 Signed-off-by: David Goulet <[email protected]>
* | Merge branch 'always-amd64' into 'main'David Goulet2024-06-181-24/+67
|\ \ | | | | | | | | | | | | CI: Bail if unexpectedly using a non-amd64 container See merge request tpo/core/arti!2207
| * | CI: Bail if unexpectedly using a non-amd64 containerJim Newsome2024-06-181-0/+20
| | | | | | | | | | | | | | | | | | | | | | | | cf https://gitlab.torproject.org/tpo/tpa/team/-/issues/41621, it's possible to unexpectedly run on a container for a different architecture than the one requested. This can result in subtle and difficult to debug issues, e.g. when unexpectedly running in the i386 variant of a container instead of the expected amd64 variant.
| * | CI: use single-arch docker images where availableJim Newsome2024-06-171-24/+47
| | | | | | | | | | | | | | | | | | | | | | | | Images with multi-arch manifests suffer from subtle caching issues that can result in running an image with a different arch than intended. See https://gitlab.torproject.org/tpo/tpa/team/-/issues/41621. We can avoid this issue by using single-arch manifests where available.
* | | Merge branch 'tolerate_missing_blob' into 'main'Nick Mathewson2024-06-183-24/+165
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | dirmgr::storage: Treat a missing blob file as an absent object. Closes #1466 See merge request tpo/core/arti!2200
| * | sqlite: (style) Use consistent casing on "ExtDocs"Nick Mathewson2024-06-181-2/+2
| | | | | | | | | | | | SQL is case-insensitive, but it is still nice to be consistent.
| * | storage: Remove orphaned files from dir_blobsNick Mathewson2024-06-123-0/+119
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This patch removes files from dir_blobs if they are not referenced from the database, or if their filenames are not valid UTF-8. (If they were not valid UTF-8, we wouldn't have put them in our database.) To ensure that there can't be any race conditions, we only do this when the file is a bit old.
| * | dirmgr: create temporary testing stores with correct paths.Nick Mathewson2024-06-121-3/+3
| | | | | | | | | | | | | | | Previously, we were putting an (optional) db.sql file and our blobs into the same path, which is not what we do outside of our tests.
| * | dirmgr: reformat cargo.tomlNick Mathewson2024-06-121-1/+2
| | |
| * | dirmgr::storage: Enable foreign keys on our sqlite connections.Nick Mathewson2024-06-121-0/+4
| | | | | | | | | | | | | | | | | | Without this, "ON DELETE CASCADE" will do nothing. Part of fixing #1466.
| * | dirmgr::storage: Treat a missing blob file as an absent object.Nick Mathewson2024-06-121-19/+36
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously it was counted as a hard error, which would cause an absolute failure to start if a blob file had been deleted improperly -- for example, by a renegade cache-cleaner that had decided to remove the largest files it could find. Upon encountering a missing blob, we remove it from the database as well: if we did not, then unavailable consensuses could still cause us to try to fetch consensus diffs, because their rows would still be present. Fixes #1466.
* | | Merge branch 'deftly-incompat' into 'main'David Goulet2024-06-1832-44/+51
|\ \ \ | | | | | | | | | | | | | | | | Update to derive-deftly 0.12.1 See merge request tpo/core/arti!2209
| * | | Change deftly syntax to post 0.12.1 versionIan Jackson2024-06-1716-19/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Change `pub` to `export` * Change the `=` in define to `:` * Change `pub_template_semver_check` to `template_export_semver_check` Right now, 0.12.1 supports both syntaxes. I have verified this branch also compiles with https://gitlab.torproject.org/Diziet/rust-derive-deftly/-/merge_requests/402 ee171ffaf56d7dcb7d75584054921153fe19b222
| * | | Update to derive-deftly 0.12.1Ian Jackson2024-06-1722-27/+34
| | |/ | |/| | | | | | | | | | | | | * Bump in Cargo.toml * Deal with `${Xmeta as ...}` incompatible change, by always specifying an `as`, and changing `as tokens`.
* | | Merge branch 'hss-subcommand' into 'main'gabi-2502024-06-183-38/+60
|\ \ \ | |/ / |/| | | | | | | | arti: Move arti hss subcommand implementation to separate module. See merge request tpo/core/arti!2206
| * | arti: Add a TODO about a possible refactoring.Gabriela Moldovan2024-06-171-0/+2
| | | | | | | | | | | | | | | I propose we move each subcommand implementation to a `subcommand` submodule.
| * | arti: Move arti hss subcommand implementation to separate module.Gabriela Moldovan2024-06-173-38/+58
|/ / | | | | | | This addresses a TODO.
* | Merge branch 'mailmap' into 'main'Nick Mathewson2024-06-151-0/+1
|\ \ | | | | | | | | | | | | meta: Use my new name See merge request tpo/core/arti!2204