summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | rpclib: Refactor request canonicalizationNick Mathewson2024-08-074-28/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This lets us make a couple of types module-private, and prepares the way for using the serde_json::Value trick on requests too.
| * | | | | | rpclib: Ensure that re-encoded responses end with NLNick Mathewson2024-08-071-1/+4
| | | | | | |
| * | | | | | rpclib: Use JsonValue to re-encode responsesNick Mathewson2024-08-072-38/+127
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This approach keeps the property that we still preserve any unrecognized fields, but takes a different approach. Instead of using our own `structs` to round-trip the json, we use a `serde_json::Value`, to ensure that we cannot forget to add the `unexpected_fields` element to a struct.
* | | | | | Merge branch 'ffi_obj_id' into 'main'Nick Mathewson2024-08-074-15/+132
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | FFI: Expose the objectID for the session object See merge request tpo/core/arti!2318
| * | | | | | FFI: Expose the object ID for the session.Nick Mathewson2024-08-062-0/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | (Without this, it isn't actually possible to use the RPC subsystem.)
| * | | | | | rpc: Make ObjectId hold a Utf8CString internally.Nick Mathewson2024-08-063-15/+95
| | |_|/ / / | |/| | | | | | | | | | | | | | | | This will enable us to return it to FFI callers as a nul-terminated string.
* | | | | | Merge branch 'b1513' into 'main'Nick Mathewson2024-08-075-6/+30
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: fix streammap panic Closes #1513 See merge request tpo/core/arti!2319
| * | | | | | shadow ci: don't explicitly set storage.keystore.enabledJim Newsome2024-08-061-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Setting it for all arti processes causes a warning to be logged to stderr, which causes the shadow ci script to fail. It's enabled by default anyway when the feature is compiled in, so we don't need to enable it explicitly.
| * | | | | | shadow CI: fail on arti logged errorsJim Newsome2024-08-061-0/+9
| | | | | | |
| * | | | | | shadow ci: fail on nonempty stderr fileJim Newsome2024-08-061-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This would have caught #1513 before it was merged.
| * | | | | | tor-proto streammap: Drop receiver for outgoing messages after ENDJim Newsome2024-08-061-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes #1513
| * | | | | | tor-proto: add Debug impls and improve panic messageJim Newsome2024-08-063-2/+8
| |/ / / / / | | | | | | | | | | | | | | | | | | For debugging #1513
* | | | | | Merge branch 'fix-doc-features' into 'main'Nick Mathewson2024-08-072-2/+9
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | maint/check_doc_features: Fixes for use with "pub mod restricted discovery" See merge request tpo/core/arti!2316
| * | | | | | tor-hsservice: Remove unnecessary docsrs cfg_attr.Gabriela Moldovan2024-08-072-2/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The module is correctly documented as "only available on crate feature restricted-discovery" without it.
| * | | | | | tor-hsservice: Add comments about the cfg_attrs around restricted_discovery.Gabriela Moldovan2024-08-071-0/+3
| | | | | | |
| * | | | | | maint/check_doc_features: Add restricted_discovery to additional_required.Gabriela Moldovan2024-08-061-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The script isn't handling the `cfg_attr` on `pub mod restricted_discovery` very well, so we need to use the `additional_required` escape hatch.
| * | | | | | tor-hsservice: Add missing docsrs cfg to restricted_discovery module.Gabriela Moldovan2024-08-061-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Without it, if the `restricted-discovery` feature is compiled out, the module gets documented as: ``` Non-restricted-discovery (Available on non-crate feature `restricted-discovery` only) ``` which is inaccurate.
| * | | | | | maint/check_doc_features: Include ; in end of item pattern.Gabriela Moldovan2024-08-061-1/+1
| |/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes the script work on `cfg_attr`s applied to `mod` declarations ending in `;`. Without this change, the script fails with ``` processing tor-hsservice res += fn(os.path.join(dir_, file)) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/builds/nickm/arti/./maint/check_doc_features", line 112, in extract_cfg_attr end = min(subline.find(pat) for pat in ' (<' if subline.find(pat) !=-1) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ValueError: min() arg is an empty sequence ``` when run on code with `cfg_attr`s applied to `mod` declarations. Note: this change just improves the UX a bit, but doesn't actually fix the issue: the script still isn't able to handle `cfg_attr`'d `mod`s: it assumes all `#[cfg_attr(docsrs, ..)]` statements are applied to feature-gated `pub use`s, and if there aren't any (such as in the case of `cfg_attr`d modules, it assumes the feature gating is missing.
* | | | | | Merge branch 'ahf/pt-status-ignore-transport' into 'main'Nick Mathewson2024-08-061-17/+13
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | Don't require TRANSPORT for PT STATUS messages. See merge request tpo/core/arti!2307
| * | | | | Add test for PtStatus containing TRANSPORT field.Alexander Færøy2024-08-011-0/+10
| | | | | | | | | | | | | | | | | | | | | | | | See: tpo/core/arti#1488.
| * | | | | Don't require TRANSPORT for PT STATUS messages.Alexander Færøy2024-08-011-18/+4
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This patch changes the PT STATUS handler to not require the presence of the `TRANSPORT` field in the K/V line. This matches current behaviour of C Tor and was requested by the Anti-censorship Team at an earlier point to enable STATUS messages to work for situation where it's not transport specific messages. To avoid future issues, we simply ignore any required keys right now even though TYPE is to be expected. See: tpo/core/torspec#267 See: tpo/core/torspec!63 See: tpo/core/arti#1488
* | | | | Merge branch 'arti-client-auth-tests' into 'main'gabi-2502024-08-0517-1/+190
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | shadow test: Add tests for restricted discovery hidden services See merge request tpo/core/arti!2272
| * | | | | shadow test: Add another client for the restricted discovery service.Gabriela Moldovan2024-08-056-0/+75
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This tests that the client configured in the `authorized_clients` directory of the service is able to connect.
| * | | | | tor-hsservice: Add an extra log in the descriptor publisher.Gabriela Moldovan2024-08-051-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | This helped me debug some shadow test failures.
| * | | | | CI: Enable restricted-discovery for arti-extra.Gabriela Moldovan2024-08-051-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | This enables us to test "restricted discovery" mode in shadow.
| * | | | | shadow test: Set the right permissions for authorized_clients.Gabriela Moldovan2024-08-051-0/+1
| | | | | |
| * | | | | shadow test: Add a new arti client for connecting to filserver-onion-arti-auth.Gabriela Moldovan2024-08-056-0/+63
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will be used with the new `fileserver-onion-arti-auth` test hidden service.
| * | | | | shadow test: Add fileserver-onion-arti-authGabriela Moldovan2024-08-057-0/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new restricted discovery hidden service (`fpqqmiwzqiv63jczrshh4qcmlxw6gujcai3arobq23wikt7hk7ojadid.onion`) that has 2 authorized clients: * `alice`, the client configured in the `restricted_discovery.static` list in its TOML config * `default`, the client configured in `authorized_clients/default.auth`
* | | | | | Merge branch 'rpc-reencoding' into 'main'Nick Mathewson2024-08-055-93/+187
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | rpc-client-core: Always re-encode requests and responses, and preserve unrecognized struct fields. Closes #1491 See merge request tpo/core/arti!2312
| * | | | | rpclib: Apply serde(default) to RpcMeta::updates.Nick Mathewson2024-08-051-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | This enable a `meta` object to have no `updates` field set.
| * | | | | rpclib: re-encode responses from arti, and preserve fields.Nick Mathewson2024-08-041-60/+87
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want to re-encode responses to avoid possible mismatch between how arti-rpc-client-core parses messages and how the user application parses messages. (In theory this shouldn't be necessary so long as arti-rpc-client-core and arti have the same json implementation, and arti-rpc-client-core is only used for talking to arti. But those assumptions might change in the future.) Closes #1491. We want to preserve fields so that, if Arti adds any new elements to response or error in the future, and the client knows about them, they won't be lost simply because arti-rpc-client-core hasn't heard of them.
| * | | | | rpclib: preserve unrecognized request fieldsNick Mathewson2024-08-042-6/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When writing a request, we want to keep any fields that we don't recognize, in case the application (and arti) know about some field that we haven't heard of.
| * | | | | rpclib: Split ParsedRequest and Request types.Nick Mathewson2024-08-043-27/+58
| | |/ / / | |/| | | | | | | | | | | | | (They are about to diverge even further.)
* | | | | Merge branch 'onion-svc-auth' into 'main'gabi-2502024-08-0523-140/+1179
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Add service-side config for enabling restricted discovery mode Closes #1292 See merge request tpo/core/arti!2266
| * | | | | arti: Add the restricted_discovery configuration to the example config.Gabriela Moldovan2024-08-052-9/+94
| | | | | | | | | | | | | | | | | | | | | | | | This also adds a test for it.
| * | | | | tor-hsservice: Fix broken doc links in RestrictedDiscoveryConfig.Gabriela Moldovan2024-08-051-6/+4
| | | | | |
| * | | | | tor-hsservice: Rewrite read_keys impl to be more functional.Gabriela Moldovan2024-08-051-21/+11
| | | | | |
| * | | | | tor-hsservice: Use DirEntry::file_name to simplify key file reading logic.Gabriela Moldovan2024-08-051-19/+14
| | | | | |
| * | | | | tor-hsservice: Reduce code duplication in restricted mode tests.Gabriela Moldovan2024-08-051-6/+3
| | | | | |
| * | | | | tor-hsservice: Give static_keys precedence over key_dirs (fmt).Gabriela Moldovan2024-08-053-16/+8
| | | | | |
| * | | | | tor-hsservice: Give static_keys precedence over key_dirs.Gabriela Moldovan2024-08-052-32/+100
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This rewrites `RestrictedDiscoveryConfig::read_keys` to give `static_keys` precedence over the keys from `key_dirs`.
| * | | | | tor-hsservice: Do not error if there are more than ↵Gabriela Moldovan2024-08-053-93/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | MAX_RESTRICTED_DISCOVERY_CLIENTS. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2266#note_3051758
| * | | | | tor-hsservice: Add a note about live updates.Gabriela Moldovan2024-08-051-0/+7
| | | | | |
| * | | | | tor-hsservice: Use the configured authorized clients when encrypting the ↵Gabriela Moldovan2024-08-055-8/+49
| | | | | | | | | | | | | | | | | | | | | | | | descriptor.
| * | | | | tor-hsservice: Remove unused import from internal prelude.Gabriela Moldovan2024-08-051-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The base64ct dependency is now unused in tor-hsservice, so we should consider removing it at some point.
| * | | | | tor-hsservice: Remove unused config types.Gabriela Moldovan2024-08-052-79/+1
| | | | | |
| * | | | | tor-hsservice: Store the client keys in RunningOnionService.Gabriela Moldovan2024-08-052-0/+41
| | | | | |
| * | | | | tor-hsservice: Use restricted config option in OnionServiceConfig.Gabriela Moldovan2024-08-051-13/+30
| | | | | |
| * | | | | tor-hsservice: Add restricted discovery configuration.Gabriela Moldovan2024-08-057-3/+921
| | | | | |
| * | | | | arti: Avoid using the now-deprecated arti_client constant.Gabriela Moldovan2024-08-051-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | We can just used `build_for_arti()` here.