summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | memory-limit: Fix heading depth for cache discussionsIan Jackson2024-09-101-4/+4
| | | |
| * | | memory-limit.md: Remove obsolete overview docsIan Jackson2024-09-101-31/+0
| | | | | | | | | | | | | | | | All of this is now documented in the lib.rs.
| * | | tor-memquota: Move some information into the proper docsIan Jackson2024-09-102-2/+8
| | | | | | | | | | | | | | | | | | | | This sentence is very important piece of overall explanation, but didn't make it into the crate level docs.
| * | | memory-limit.md: Remove obsolete docs of implemented channel facilityIan Jackson2024-09-101-121/+0
| | | | | | | | | | | | | | | | All of this is now implemented. Delete the obsolete sketch.
* | | | Merge branch 'ephemeral-keystore-docs' into 'main'gabi-2502024-09-171-0/+6
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-keymgr: add disk-related docs to `ArtiEphemeralKeystore` See merge request tpo/core/arti!2424
| * | | | tor-keymgr: add disk-related docs to `ArtiEphemeralKeystore`Steven Engler2024-09-171-0/+6
| | | | |
* | | | | Merge branch 'msrv-1.75' into 'main'Nick Mathewson2024-09-1762-62/+62
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Bump MSRV from 1.70 to 1.75. See merge request tpo/core/arti!2421
| * | | | Bump MSRV from 1.70 to 1.75.Wesley Aptekar-Cassels2024-09-1662-62/+62
| | | | |
* | | | | Merge branch 'hss-generate-hsid' into 'main'gabi-2502024-09-176-73/+220
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti: Add subcommand for generating service identity keys Closes #1621 See merge request tpo/core/arti!2419
| * | | | | arti: Remove hss get-key from the tests.Gabriela Moldovan2024-09-172-24/+2
| | | | | | | | | | | | | | | | | | | | | | | | The `hss get-key` functionality was folded into `hss onion-name`.
| * | | | | arti: Remove get-key subcommand in favor of onion-name.Gabriela Moldovan2024-09-171-28/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The `hss get-key` subcommand is now folded into `onion-name`, which takes a `--generate` argument which specifies whether to generate the key if missing. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2419#note_3078068
| * | | | | tor-hsservice: Remove unused import from internal prelude.Gabriela Moldovan2024-09-171-1/+1
| | | | | |
| * | | | | arti: Add a test and some docs for the hss get-key subcommand.Gabriela Moldovan2024-09-171-0/+30
| | | | | |
| * | | | | arti: Add CLI for generating an onion service hsid.Gabriela Moldovan2024-09-172-3/+85
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new `hss get-key` subcommand for retrieving and generating service identity keys. The existing `hss onion-name` is now a convenience alias for `hss get-key --generate=no --key-type=onion-name`. Note: I am calling this new subcommand `get-key` for consistency with its client counterpart (`hsc get-key`). Closes #1621
| * | | | | arti: Add an enum for the hss subcommand.Gabriela Moldovan2024-09-173-40/+48
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed because we'll soon add an `hss get-key` subcommand for getting and/or generating a service identity key alongside `hss onion-name` (`hss onion-name` will become a convenience around `hss get-key --key-type=onion-name`).
| * | | | | arti: Refactor hss::onion_name() implementation.Gabriela Moldovan2024-09-171-11/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This splits `onion_name` into multiple functions (which will be repurposed for the future `hss get-key` implementation).
| * | | | | arti: Move hss onion-name implementation to a separate function.Gabriela Moldovan2024-09-171-29/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `hss` will soon sprout another subcommand, so I am preemptively refactoring the `hss onion-name` implementation out of `hss::run()`.
| * | | | | arti: Remove a completed TODO.Gabriela Moldovan2024-09-171-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | The tests were added in !2275
| * | | | | tor-hsservice: Add API for generating the hsid for a service.Gabriela Moldovan2024-09-171-2/+30
| | | | | | | | | | | | | | | | | | | | | | | | This also reexports `HsId` from the `tor-hsservice` crate.
| * | | | | tor-hsservice: Make maybe_generate_hsid take a selector (fmt).Gabriela Moldovan2024-09-171-3/+14
| | | | | |
| * | | | | tor-hsservice: Make maybe_generate_hsid take a selector.Gabriela Moldovan2024-09-171-6/+8
| | |_|/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon add a new `OnionService` function for generating an HsId for the service without launching it (#1621). This new API will be implemented using `maybe_generate_hsid`, which will need to take the user-provided keystore selector as an argument. (the selector exists for future-proofing reasons; we're not yet exposing it in the CLI, but it will be part of the new `OnionService` API)
* | | | | Merge branch 's101-2024-q2' into 'main'Alexander Hansen Færøy2024-09-171-0/+26
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Update s101 numbers for Q2 2024 See merge request tpo/core/arti!2245
| * | | | Update s101 numbers for Q2 2024Alexander Færøy2024-07-081-0/+26
| | | | |
* | | | | Merge branch 'bug_1612v2' into 'main'gabi-2502024-09-171-1/+45
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bug 1612: Allow programmatic launching of onion-service with user-provided HsIdKeypair Closes #1612 See merge request tpo/core/arti!2402
| * | | | | arti-client: add experimental launch_onion_service_with_hsid() method which ↵Morgan2024-09-151-1/+45
| | | | | | | | | | | | | | | | | | | | | | | | HsIdKeypair
* | | | | | Merge branch 'defer-hsid-generation' into 'main'gabi-2502024-09-174-48/+29
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | tor-hsservice: Do not generate the HsId until the service is launched. See merge request tpo/core/arti!2417
| * | | | | arti: Test hss onion-name behavior when the hsid is missing.Gabriela Moldovan2024-09-172-0/+17
| | | | | |
| * | | | | tor-hsservice: Do not generate the HsId until the service is launched.Gabriela Moldovan2024-09-171-8/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This defers generating an HsId until `OnionService::launch`, enabling us to use APIs like `OnionService::onion_name` to e.g. check for the existence of an HsId (previously, you couldn't do that because creating an `OnionService` would auto-generate the `HsId`).
| * | | | | tor-hsservice: Remove outdated TODO.Gabriela Moldovan2024-09-171-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per #1247, we decided to stick with the current name. As for the docs, they were added in !1946
| * | | | | tor-hsservice: Remove deprecated constructor.Gabriela Moldovan2024-09-172-36/+2
|/ / / / / | | | | | | | | | | | | | | | This has been deprecated since 1.2.6, so let's remove it.
* | | | | Merge branch 'take_all_but' into 'main'Nick Mathewson2024-09-162-8/+75
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement and user Reader::take_all_but() Closes #1620 See merge request tpo/core/arti!2415
| * | | | | tor-proto: Use Reader::take_all_but().Nick Mathewson2024-09-162-21/+15
| | | | | |
| * | | | | tor-bytes: Add a new take_all_but method.Nick Mathewson2024-09-161-0/+73
| | | | | |
* | | | | | Merge branch 'ticket_1591' into 'main'Nick Mathewson2024-09-163-97/+108
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | rpc: Simplify handling of fatal Json read errors. Closes #1591 See merge request tpo/core/arti!2400
| * | | | | | rpcserver: Split a few long lines.Nick Mathewson2024-09-161-5/+10
| | | | | | |
| * | | | | | rpcserver: move is_connection_close detection into run_loop.Nick Mathewson2024-09-161-6/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I've used an `async{ expr }.await` pattern, to make sure that _every_ error returned by the `loop{select!{}}` construct is actually transformed.
| * | | | | | rpcserver: Add an extra level of braces.Nick Mathewson2024-09-161-50/+52
| | | | | | | | | | | | | | | | | | | | | | | | | | | | (This will make the next commit easier to read.)
| * | | | | | rpcserver: Apply documentation suggestion.Nick Mathewson2024-09-161-0/+2
| | | | | | |
| * | | | | | rpcserver: Use a struct to enforce explicit ContinueNick Mathewson2024-09-161-2/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Per suggestion from @diziet.
| * | | | | | rpc: Simplify simplified close logic even furtherNick Mathewson2024-09-162-35/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Instead of classifying errors and complicating our behavior _early_ in our loop, instead we just decide whether an error indicates an EOF immediately before we return it.
| * | | | | | rpc: Simplify close logic even further.Nick Mathewson2024-09-161-6/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Make it more clear than the previous match statement that once we get an Err() from request_stream.next(), we aren't going to continue the loop.
| * | | | | | rpc: Simplify handling of fatal Json read errors.Nick Mathewson2024-09-163-44/+33
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, after determining that an error on an RPC connection was fatal, we would: 1. Determine whether it was a "clean" close or one that needed to be logged. 2. In exactly one case (specifically, when the inbound Json stream contained a Value that was not an Object) , we would send back a message to the client. 3. Exit the connection with Ok() or Err(e). We no longer do step "2" above. Additionally, we document: - Why it's important to exit immediately on syntax errors. - A better way to tolerate non-Object Json Values, if we decide someday to do so. Closes #1591.
* | | | | | Merge branch 'circmgr-remove-abstractspec' into 'main'Nick Mathewson2024-09-164-260/+328
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | tor-circmgr: Remove AbstractSpec and FakeSpec. See merge request tpo/core/arti!2412
| * | | | | Add test for CircList::find_open.Wesley Aptekar-Cassels2024-09-161-1/+55
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This tests that when requesting preemptive circuits, they are not given out when a insufficient number of circuits are in the CircList, but that they are given out once the required number of circuits has been reached.
| * | | | | tor-circmgr: Remove AbstractSpec and FakeSpec.Wesley Aptekar-Cassels2024-09-164-260/+274
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | AbstractSpec and FakeSpec actually make testing more difficult, since they prevent using FakeBuilder in code that relies on the concrete TargetCircUsage and SupportedCircUsage types. Removing them means FakeBuilder can be used in more places, and also means that the test code is closer to the real code, since TargetCircUsage and SupportedCircUsage are now exercised directly in more tests. This did require making one change to a test, which I think was previously testing behaviour that was true for FakeSpec but not for the real code: The mgr::test::isolated test previously asserted that, in the case where three circuits were requested, two with isolation and one without, the non-isolated circuit would be shared with one of the isolated circuits. This was allowed by the FakeSpec::supports function. However, in the actual code, the path is as follows: * AbstractCircMgr::get_or_launch * AbstractCircMgr::prepare_action * CircList::find_open * AbstractSpec::find_supported * abstract_spec_find_supported * OpenEntry::supports * SupportedCircUsage::supports * StreamIsolation::compatible_same_type StreamIsolation::compatible_same_type checks owner_type, which is always zero for non-isolated streams and always non-zero for isolated streams, meaning that a isolated stream will never be compatible with a non-isolated stream. The seems like desirable behaviour, so I simply modified the test to make four connections, two isolated and two not, and checked that the isolated streams never share any circuits, and that the two non-isolated streams use the same circuit. As far as I can tell, this is the intended behaviour in the existing code.
* | | | | Merge branch 'proxy-subcmd' into 'main'Nick Mathewson2024-09-163-188/+224
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | arti: Move proxy subcommand to a separate module. See merge request tpo/core/arti!2416
| * | | | arti: Move proxy subcommand to a separate module.Gabriela Moldovan2024-09-122-41/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | No functional changes, this is just code motion. This helps organize the code in `arti/src/lib.rs` a bit. It now only contains the argument parsing and various other setup, and all the subcommands are contained in separate modules.
| * | | | arti: Move arti::run to subcommands::proxy.Gabriela Moldovan2024-09-122-156/+172
| | | | | | | | | | | | | | | | | | | | No functional changes, this is just code motion.
| * | | | arti: Add a new module for the proxy subcommand.Gabriela Moldovan2024-09-122-0/+19
|/ / / / | | | | | | | | | | | | | | | | The implementation for `arti proxy` will soon be relocated to this new module.
* | | | Merge branch 'orport' into 'main'David Goulet2024-09-127-30/+170
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-chanmgr: add experimental `ChanMgr::handle_incoming` See merge request tpo/core/arti!2389