summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | rpcbase: Remove a TODO RPC about duplicationNick Mathewson2024-07-251-1/+0
| | | | | | | | | | | | | | | | | | | | The duplication is only a few lines. I've looked into a couple of ways for removing it, but they make the code flow even less clear.
| * | | rpcbase: Replace a TODO with a set of notes and caveatsNick Mathewson2024-07-252-7/+45
| | | | | | | | | | | | | | | | | | | | | | | | We have decided not to remove the "anybody can define methods" property. This commit documents the consequences, and warns extenders away from some really bad ideas.
| * | | rpc: remove TODO about adding an extension traitNick Mathewson2024-07-251-4/+0
| | | | | | | | | | | | | | | | | | | | These functions are called rarely enough that it is probably okay for the ergonomics to be a bit verbose.
| * | | rpc: Remove TODO about moving @special to a different macro.Nick Mathewson2024-07-251-4/+0
| | | |
| * | | rpc: Do not hide InvokeError::Bug when converting to RpcErrorNick Mathewson2024-07-251-18/+35
| | | |
| * | | rpc: split "method not found"Nick Mathewson2024-07-254-12/+17
| | | | | | | | | | | | | | | | | | | | We've wanted separate error codes for "no such method exists" and "this method exists, but this object doesn't have it."
| * | | rpcbase: remove "Nil" TODO.Nick Mathewson2024-07-251-3/+0
| | | | | | | | | | | | | | | | This change would take some serde magic that is probably not worth it.
| * | | rpcbase: Use newer "tgens" deftly syntaxNick Mathewson2024-07-251-3/+1
| | | |
| * | | rpcbase: remove a TODO about expose_outside_of_sessionNick Mathewson2024-07-251-4/+0
| | | | | | | | | | | | | | | | (There is no longer such a thing as a "pseudomethod.")
* | | | Merge branch 'stream-peek' into 'main'Ian Jackson2024-07-246-2/+540
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-memquota: Provide StreamUnobtrusivePeeker See merge request tpo/core/arti!2280
| * | | tor-memquota: discuss StreamUnobtrusivePeeker nameIan Jackson2024-07-241-7/+8
| | | | | | | | | | | | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2280#note_3051134
| * | | tor-memquota: Elide a lifetimeIan Jackson2024-07-241-1/+1
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2280#note_3051270
| * | | tor-memquota: Fix a wrong commentIan Jackson2024-07-241-3/+1
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2280#note_3051268
| * | | tor-memquota: Provide StreamUnobtrusivePeeker (tests)Ian Jackson2024-07-241-0/+163
| | | |
| * | | tor-memquota: Provide StreamUnobtrusivePeekerIan Jackson2024-07-246-2/+378
|/ / / | | | | | | | | | | | | | | | I'm not particularly pleased with this name. We need names for both the type, and the trait we'll almost certainly want to introduce in the future.
* | | Merge branch 'rpc-testing' into 'main'Nick Mathewson2024-07-247-11/+517
|\ \ \ | | | | | | | | | | | | | | | | rpclib: Add initial unit tests See merge request tpo/core/arti!2277
| * | | rpclib: Add tests for errors that terminate an RpcConn.Nick Mathewson2024-07-241-1/+101
| | | |
| * | | rpclib: Initial tests for RpcConnNick Mathewson2024-07-246-4/+243
| | | | | | | | | | | | | | | | | | | | | | | | The "complex" test here is fairly involved, since it tries to detect deadlocks and race conditions by using multiple threads and answering requests out of order.
| * | | rpclib: Test low-level reader/writer.Nick Mathewson2024-07-243-1/+166
| | | |
| * | | rpc: Relax 'static requirement on execute_with_updates closure.Nick Mathewson2024-07-241-1/+1
| | | | | | | | | | | | | | | | This turns out not to be necessary.
| * | | rpclib: do not include `"meta":null` when serializing.Nick Mathewson2024-07-241-0/+1
| | | |
| * | | rpclib: re-encode outgoing requests.Nick Mathewson2024-07-241-5/+6
|/ / / | | | | | | | | | | | | | | | I hadn't been sure that we wanted to do this, since arti is forgiving about its inputs, but IIRC Diziet was in favor of this, and it _does_ make it easier to write tests.
* | | Merge branch 'memquota-typed' into 'main'Ian Jackson2024-07-246-38/+469
|\ \ \ | | | | | | | | | | | | | | | | tor-memquota: HasMemoryCost trait, and type-safe methods See merge request tpo/core/arti!2282
| * | | tor-memquota: Test Debug, Display and HasKind impls for errorsIan Jackson2024-07-241-0/+72
| | | |
| * | | tor-memquota: impl HasKind for StartupError and ReclaimCrashedIan Jackson2024-07-241-0/+19
| | | | | | | | | | | | | | | | | | | | Trying to write comprehensive tests for the errors showed that these impls were missing.
| * | | tor-memquota: impl HasKind for ReclaimedErrorInnerIan Jackson2024-07-241-1/+7
| | | | | | | | | | | | | | | | This will make testing easier.
| * | | tor-memquota: Fix Display impl for Error::TrackerCorruptedIan Jackson2024-07-241-1/+1
| | | | | | | | | | | | | | | | | | | | Bug found in review: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2282#note_3051101
| * | | tor-memquota: memory_cost: Introduce try_claim (tests)Ian Jackson2024-07-241-0/+31
| | | |
| * | | tor-memquota: memory_cost: Introduce try_claimIan Jackson2024-07-241-0/+38
| | | | | | | | | | | | | | | | | | | | Our stream wrapper is going to want this. It's fiddly enough that doing it as a standalone facility seems sensible.
| * | | tor-memquota: memory_cost: New trait and typed wrappers (tests)Ian Jackson2024-07-241-0/+69
| | | |
| * | | tor-memquota: memory_cost: New trait and typed wrappersIan Jackson2024-07-243-0/+158
| | | |
| * | | tor-memquota: Expose some test utilities for the rest of the crateIan Jackson2024-07-242-5/+8
| | | |
| * | | tor-memquota: Improve register_participant_with (fmt)Ian Jackson2024-07-241-18/+24
| | | |
| * | | tor-memquota: Improve register_participant_withIan Jackson2024-07-242-13/+16
| | | | | | | | | | | | | | | | | | | | Now the constructor is able to return other data to the caller, passing it through the mtracker machinery.
| * | | tor-memquota: Add get_used_approx accessorIan Jackson2024-07-242-1/+15
| | | | | | | | | | | | | | | | | | | | I just want this for a test right now, bui it seems like it would be good to expose it publicly.
| * | | tor-memquota: Expose TrackerCorruptedIan Jackson2024-07-241-4/+16
| | | | | | | | | | | | | | | | | | | | We're going to want this as the return value from an accessor function, which cannot fail for any other reason.
* | | | Merge branch 'memquota-destroy-participant' into 'main'Ian Jackson2024-07-245-3/+73
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-memquota: Provide destroy_participant See merge request tpo/core/arti!2281
| * | | tor-memquota: destroy_participant: Clarify "no longer useable"Ian Jackson2024-07-241-1/+2
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2281#note_3051105
| * | | tor-memquota: Provide Participant::destroy_participantIan Jackson2024-07-243-0/+70
| | | | | | | | | | | | | | | | The stream wrapper is going to want this.
| * | | tor-memquota: Correct a wrong commentIan Jackson2024-07-241-2/+1
| | | | | | | | | | | | | | | | | | | | There is no `p_used` here; what we meant was the very same `ClaimedQty.`
| * | | tor-memquota: Tidy up a minor formatting glitch in a doc commentIan Jackson2024-07-241-1/+1
|/ / /
* | | Merge branch 'explain-wfs' into 'main'Nick Mathewson2024-07-231-1/+7
|\ \ \ | |/ / |/| | | | | | | | Tweak documentation for wait_for_stop slightly. See merge request tpo/core/arti!2278
| * | Tweak documentation for wait_for_stop slightly.Nick Mathewson2024-07-231-1/+7
|/ /
* | Merge branch 'expose-annotated' into 'main'Nick Mathewson2024-07-221-0/+15
|\ \ | | | | | | | | | | | | | | | | | | tor-netdoc: Dangerously expose annotation fields Closes #1469 See merge request tpo/core/arti!2213
| * | tor-netdoc: Dangerously expose annotation fieldsClara Engler2024-06-211-0/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit exposes the fields of `routerdesc::AnnotatedRouterDesc` and `routerdesc::RouterAnnotation` with the enabled feature `dangerous-expose-struct-fields`. On one side, it achieves a greater consistency among the other structures found within this module; On the other side it makes the already public API (assuming the feature above is enabled) useable. Fixes #1469
* | | Merge branch 'openssl-bump' into 'main'Nick Mathewson2024-07-221-4/+4
|\ \ \ | | | | | | | | | | | | | | | | Bump openssl to 0.10.66 to satisfy cargo-audit. See merge request tpo/core/arti!2276
| * | | Bump openssl to 0.10.66 to satisfy cargo-audit.Gabriela Moldovan2024-07-221-4/+4
|/ / / | | | | | | | | | See RUSTSEC-2024-0357.
* | | Merge branch 'fix-keystore-contains' into 'main'gabi-2502024-07-221-16/+27
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-keymgr: Fix bug in ArtiNativeKeystore::contains Closes #1492 See merge request tpo/core/arti!2274
| * | | tor-keymgr: Fix ArtiNativeKeystore::contains() bug.Gabriela Moldovan2024-07-171-1/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a bug in `ArtiNativeKeystore`'s `Keystore::contains()` implementation: previously, it called Path::exists() on the relative path (built by concatenating the key specifier and the extension), so unless your current directory happened to be the root of the keystore, `contains()` would always return `false`. `KeyMgr::generate` uses `Keystore::contains()` under the hood, so it was affected by this bug too: if called `overwrite = false`, it would misbehave and overwrite any existing keys. Internally, we call `KeyMgr::generate` in a couple of places: * `tor-hsservice/src/lib.rs`, to generate the `hsid` if it doesn't already exist. This callsite is not affected by the bug, because `KeyMgr::generate` is only called if `KeyMgr::get` returns `None` * `tor-hsservice/src/ipt_mgr.rs`, to generate `KS_hss_ntor` and `KS_hs_ipt_sid` keys for intro point establishment. This callsite is also not affected (because it too calls `get()` before attempting to `generate()`) The bug affects any downstream users that use `KeyMgr::generate` with a key manager backed by `ArtiNativeKeystore`. ------ `KeyMgr::get_or_generate` is not affected, even though it calls `Keymgr::generate` (it performs a separate extra check before calling `generate()`). (Both suffer from a known TOCTOU race, but that's a separate matter.) As an aside, I'd like to somehow unify `KeyMgr::get_or_generate` and `KeyMgr::get` (I've had some attempts in the past but ended up abandoning them because the result was more unergonomic than the existing APIs). Part of #1492
| * | | tor-keymgr: Rename function to clarify it returns a relative path (fmt).Gabriela Moldovan2024-07-171-1/+2
| | | |