| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
There is no `Multiple` counterpart in `CircuitAction`, so the `Single`
variant name doesn't make much sense.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
The `LegId` is now added by the caller, when converting the resulting
`CircuitCmd`s to `RunOnceCmdInner`.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
`CircuitCmd`s are a subset of `RunOnceCmdInner`, and don't have a
`LegId`.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
A `CircuitCmd`, unlike `RunOnceCmdInner`, doesn't know anything about
`LegId`s. The user of the `CircuitCmd`s is supposed to know the `LegId`
of the circuit the `CircuitCmd` came from. This is necessary because
circuits don't know (and can't know) their own `LegId`.
The various `Circuit` operations (e.g. `handle_cell`) will soon be
updated to return `CircuitCmd` instead of `RunOnceCmdInner` (because the
`RunOnceCmdInner` variants will soon be updated to also have an
associated `LegId`, and `Circuit`s don't have access to their `LegId`s).
The calling code, which *does* know the `LegId`, will then map
`CircuitCmd`s to `RunOnceCmdInner`.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This tells the reactor which circuit leg the input message originated
from.
Addresses a TODO.
|
| |\ \ \ \ \ \
| |_|/ / / /
|/| | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Use a very cautious Rng for deriving longer-lived keys
Closes #1898
See merge request tpo/core/arti!2874
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
We want to require that whenever we generate a key that's persistent
(stored in KeyMgr), it's going to be made from a stronger-than-usual
Rng. This trait helps us enforce that.
We also add a FakeEntropicRng struct to use for testing.
Note that this turned up a case that we'd missed, which required
an internal change in tor-hsservice.
|
| | | | | | | |
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This Rng combines inputs from several sources,
including OsRng, to minimize the likelihood
of falling to a vulnerability in any particular one.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
rpcserver: Increase coverage in msgs module
See merge request tpo/core/arti!2870
|
| | | | | | | |
|
| |\ \ \ \ \ \
| |_|_|/ / /
|/| | | | |
| | | | | |
| | | | | | |
Update links to the code of conduct
See merge request tpo/core/arti!2882
|
| | | |/ / /
| |/| | |
| | | | |
| | | | | |
The old link seems not to work any more.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
fallbackdir: Update list generated on March 20, 2025
See merge request tpo/core/arti!2875
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Signed-off-by: Tor CI Release <[email protected]>
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
tor-proto: some TODO fixes in `ControlHandler`
See merge request tpo/core/arti!2867
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | |/ / / / |
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Correct terminology for unix-domain sockets
Closes #827
See merge request tpo/core/arti!2841
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
We change `NoUnixAddressSupport` to `NoAfUnixSocketSupport` because it
doesn't make much sense to talk about support for the addresses
separately from support for the sockets.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Change `..UnixAddress...` to `...AfUnixAddress..`.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This variant breaches the new guidelines about AF_UNIX terminology.
And its purpose is unclear and it's not used.
|
| | | | | | |
|
| | | | | | |
|
| |/ / / /
| | | |
| | | |
| | | | |
This marks the anti-examples more clearly.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Fix erratic rust-checks pipeline on non-arti toplevels
Closes #1868
See merge request tpo/core/arti!2864
|
| | | | | | |
|
| |/ / / / |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-netdir: Handle InsufficientNonZero error.
See merge request tpo/core/arti!2877
|
| |/ / / /
| | | |
| | | |
| | | | |
Possible fix for #1902.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
protover: Add support for subprotocol version mnemonics.
Closes #1891
See merge request tpo/core/arti!2854
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
It's error-prone to have to remember e.g. that "Desc=5"
means "family ID support", so in torspec!251 we added mnemonic names
like DESC_FAMILY_IDS.
Here we use those names in tor-protover.
|
| | | | | | |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
rpc-book: Clarify auth="none" vs auth:inherent
Closes #1820
See merge request tpo/core/arti!2872
|
| | | |/ / /
| |/| | |
| | | | |
| | | | | |
Closes #1820.
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
replace state_dir and storage_mistrust with tor_persist::state_dir::StateDirectory
See merge request tpo/core/arti!2863
|
| | | | | |
| | | | |
| | | | |
| | | | | |
tor_persist::state_dir::StateDirectory
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Impose a maximum on our fallback estimated timeout
Closes #1693
See merge request tpo/core/arti!2842
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
The fallback timeout is the one that we use when we have
insufficient data. We reset our observations, and maybe rebuild
our circuits, when we find that too many circuits have failed
recently. When we do so, we double our fallback timeout.
Previously we had no limit, which could lead to overflow (#1693).
In this commit we impose a maximum of 2 hours,
which is ridiculously high.
(C tor uses a maximum of INT32_MAX seconds, which is even more
ridiculously high.)
Closes #1693.
|
| |\ \ \ \ \ \
| |_|/ / / /
|/| | | | |
| | | | | |
| | | | | | |
Port to rand 0.9
See merge request tpo/core/arti!2869
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
The constructor for rand::distr::Uniform is now fallible,
so it makes sense to bubble up its restrictions.
This is a breaking change.
|