| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | |
| | | | |
| | | | |
| | | | | |
The descriptor publisher docs live in the `publisher` module.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Closes #1216
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This makes it clearer that some of these functions are essentially
infallible.
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This enables us to report a "broken" service status if restricted
discovery is enabled but the authorized_clients list is empty.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Closes #1572
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Currently, the `DegradedReachable` status is only reported by the the IPT
manager and `DegradedUnreachable` is unused.
Soon we'll the publisher reporting `DegradedReachable` or
`DegradedUnreachable` or `Running`, depending on how the descriptor
uploads went.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This will allows us determine the ComponentStatus of the publisher
(it'll be either `Running` or `Degraded`, depending on whether the
upload failed).
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
After uploading the descriptor, the publisher transitions into the
`Idle` state. This transition happens even if the upload was
unsuccessful, so it shouldn't cause the onion service status to become
`Running` (because `Running` implies the service is fully reachable, and
if the publisher failed to upload the descriptor to some or all HsDirs,
that won't necessarily be the case).
A future commit will set the publisher's onion svc `State` to
`Running`/`Recovering`/`Broken` according to the upload status.
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
This resolves a TODO.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Previously, these were stored in the immutable state behind a mutex, but
since they're not really immutable (we update them if the config
changes), it makes more sense to put them in `State`.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
These TODOs were addressed a while ago (when we introduced
`IptManager::ipt_errors`).
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
These aren't dead code anymore, with the exception of
`PublisherStatusSender::send_recovering`, which isn't used.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
We now log the onion service status on change.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
This is already implemented.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This TODO was added in !2353 and was supposed to be about reporting a
broken/degraded onion service status if the restricted discovery config
watcher fails.
|
| |\ \ \ \ \
| |_|_|_|/
|/| | | |
| | | | |
| | | | | |
Fix a typo in WRONG_PROTOCOL_PAYLOAD.
See merge request tpo/core/arti!2403
|
| |/ / / / |
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
Add a deficit field to tor_bytes::Error::Truncated
Closes #1592
See merge request tpo/core/arti!2390
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Suggested in
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2390#note_3072975
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
This will allow us to fix #1592, but it doesn't do so yet.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is going to want to do something more complicated (as described
in the docs).
In this commit we change all the tests that are expecting Truncated
errors. That reduces noise in the next commit.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This refers to the `deficit` field in Error::Truncated, which is going
to appear in a later commit. It seems kinder to my reviewer to add
this doc now early in the branch.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Error::Truncated is going to become more complicated, and anyway it
would be nice to print the values if the test fails.
Error is PartialEq now. (Maybe it wasn't when this was written?)
|
| |/ / /
| | |
| | |
| | |
| | | |
This removes one construction site of Error::Truncated. We are about
to make constructing one of those more fiddly.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
arti-relay: add and use `Error`/`ErrorDetail`
See merge request tpo/core/arti!2392
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Most of this is copied from `arti_client::err`, but with a lot of stuff
removed to simplify the error types (for example no `error_detail`
feature handling). I tried to keep things generally consistent with
arti-client so that error handling will be similar in both crates.
`TorRelayBuilder::create()` will likely need to be fallible in the
future (for example if spawning a task for the OR port listener fails),
so it now returns a `Result<TorRelay, crate::err::Error>` instead of
just a `TorRelay`.
|
| | | | | |
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
eliminate all but one use of `KeyMgr::get::<HsIdKeypair>()`
Closes #1194
See merge request tpo/core/arti!2393
|
| | | | |
| | | |
| | | |
| | | | |
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2393#note_3073480
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
There are three places where we query the KeyMgr for an `HsIdKeypair` but all
we really need is the public part. This commit changes those three callsites
to instead use `get::<HsIdKey>`.
This relies on the previous commit, which makes sure that a request for an
`HsIdKey` will always succeed if the keystore has a `HsIdKeypair` with the
same service nickname.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
keypair
Now that:
- KeySpecifier::get_keypair_specifier() can be used to convert the
KeySpecifier for a public key into the KeySpecifier for its secret key
- ToEncodableKey<Key=PublicKey> has a "type level pointer" to
ToEncodableKey<Key=KeyPair>
We can use these two features together to automatically satisfy any request to
get a public key using the corresponding secret key (if available).
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This comment adds a second associated type `KeyPair` to ToEncodableKey. For a
`ToEncodableKey` which represents a (secret) KeyPair, this type is Self. For
a `ToEncodableKey` which represents a public key, this is the `ToEncodableKey`
whose `Key` is the pair of which this is the public part.
This is essentially a "type level pointer" from the ToEncodableKey for a
public key to the ToEncodableKey for its secret key.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This commit adds a new method `get_keypair_specifier()` to `KeySpecifier`.
This method is used to indicate when one KeySpecifier (e.g. `KP_hs_id`) is the
public part of another keypair (e.g. `KS_hs_id`). It will return the
containing keypair in this case, and `None` otherwise.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
FooKeypairSpecifier` instances
This adds the following trivial `From` instances:
- tor_hsservice: impl From<&HsIdPublicKeySpecifier> for HsIdKeypairSpecifier
- tor_hsservice: impl From<&BlindIdPublicKeySpecifier> for BlindIdKeypairSpecifier
- tor_hscrypto::pk: impl From<HsBlindIdKeypair> for HsBlindIdKey
- tor_llcrypto::pk::ed25519: impl From<ExpandedKeypair> for PublicKey
- tor_keymgr::mgr: impl From<TestKey> for TestPublicKey
- tor::hscrypto::pk: impl From<HsIdKeypair> for HsIdKey
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | |
| | | |
| | | | |
rpclib: Support opening a data stream.
Closes #1524
See merge request tpo/core/arti!2373
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Ticket #1509 will probably get rid of this constant,
but for now we may as well put it in one place.
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Here we make sure that we can actually skip over other proxy formats
in the future.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Renamed address to tcp_address, and made it optional, so that later
we can have a unix_path, etc.
On deser side, add support for unrecognized listener types.
|
| | | | | |
|