summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | tor-proto: s/CircuitAction::Single/CircuitAction::RunCmd.Gabriela Moldovan2025-03-243-8/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There is no `Multiple` counterpart in `CircuitAction`, so the `Single` variant name doesn't make much sense.
| * | | | | tor-proto: Remove now-unused leg_id argument.Gabriela Moldovan2025-03-242-7/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The `LegId` is now added by the caller, when converting the resulting `CircuitCmd`s to `RunOnceCmdInner`.
| * | | | | tor-proto: Add docs to SendRelayCell.Gabriela Moldovan2025-03-241-3/+3
| | | | | |
| * | | | | tor-proto: Replace RunOnceCmdInner with CircuitCmd where appropriate.Gabriela Moldovan2025-03-243-47/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `CircuitCmd`s are a subset of `RunOnceCmdInner`, and don't have a `LegId`.
| * | | | | tor-proto: Add CircuitCmd enum.Gabriela Moldovan2025-03-242-1/+63
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | A `CircuitCmd`, unlike `RunOnceCmdInner`, doesn't know anything about `LegId`s. The user of the `CircuitCmd`s is supposed to know the `LegId` of the circuit the `CircuitCmd` came from. This is necessary because circuits don't know (and can't know) their own `LegId`. The various `Circuit` operations (e.g. `handle_cell`) will soon be updated to return `CircuitCmd` instead of `RunOnceCmdInner` (because the `RunOnceCmdInner` variants will soon be updated to also have an associated `LegId`, and `Circuit`s don't have access to their `LegId`s). The calling code, which *does* know the `LegId`, will then map `CircuitCmd`s to `RunOnceCmdInner`.
| * | | | | tor-proto: Put the leg id of the circuit in CircuitAction::HandleCell.Gabriela Moldovan2025-03-232-7/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This tells the reactor which circuit leg the input message originated from. Addresses a TODO.
* | | | | | Merge branch 'cautious_rng' into 'main'Nick Mathewson2025-03-2418-25/+291
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Use a very cautious Rng for deriving longer-lived keys Closes #1898 See merge request tpo/core/arti!2874
| * | | | | llcrypto: Document some design choices from CautiousRng.Nick Mathewson2025-03-241-1/+12
| | | | | |
| * | | | | Use an EntropicRng trait to enforce key generation rules.Nick Mathewson2025-03-2410-20/+82
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want to require that whenever we generate a key that's persistent (stored in KeyMgr), it's going to be made from a stronger-than-usual Rng. This trait helps us enforce that. We also add a FakeEntropicRng struct to use for testing. Note that this turned up a case that we'd missed, which required an internal change in tor-hsservice.
| * | | | | Use CautiousRng for keys going into the KeyMgr.Nick Mathewson2025-03-247-6/+23
| | | | | |
| * | | | | llcrypto: new CautiousRng for constructing long-lived keysNick Mathewson2025-03-244-0/+176
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | This Rng combines inputs from several sources, including OsRng, to minimize the likelihood of falling to a vulnerability in any particular one.
* | | | | Merge branch 'tests-rpcserver-msgs' into 'main'Nick Mathewson2025-03-241-6/+25
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | rpcserver: Increase coverage in msgs module See merge request tpo/core/arti!2870
| * | | | | rpcserver: Increase coverage in msgs modulevcrn2025-03-241-6/+25
| | | | | |
* | | | | | Merge branch 'coc_link' into 'main'David Goulet2025-03-243-3/+3
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | Update links to the code of conduct See merge request tpo/core/arti!2882
| * | | | | Update links to the code of conductNick Mathewson2025-03-243-3/+3
| | |/ / / | |/| | | | | | | | | | | | | The old link seems not to work any more.
* | | | | Merge branch 'fallbackdirs-03-2025' into 'main'opara2025-03-241-920/+897
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | fallbackdir: Update list generated on March 20, 2025 See merge request tpo/core/arti!2875
| * | | | | fallbackdir: Update list generated on March 20, 2025Tor CI Release2025-03-241-920/+897
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Tor CI Release <[email protected]>
* | | | | | Merge branch 'return-errors-through-channel' into 'main'opara2025-03-243-50/+74
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | tor-proto: some TODO fixes in `ControlHandler` See merge request tpo/core/arti!2867
| * | | | | tor-proto: send errors to oneshot channel in more placesSteven Engler2025-03-241-16/+38
| | | | | |
| * | | | | tor-proto: made `StreamTarget::send_sendme` async and fixed a TODOSteven Engler2025-03-243-10/+28
| | | | | |
| * | | | | tor-proto: remove previously completed TODOsSteven Engler2025-03-241-21/+7
| | | | | |
| * | | | | tor-proto: fix small TODOSteven Engler2025-03-241-3/+1
| |/ / / /
* | | | | Merge branch 'af-unix' into 'main'Ian Jackson2025-03-2423-70/+142
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | Correct terminology for unix-domain sockets Closes #827 See merge request tpo/core/arti!2841
| * | | | Style.md: Be more nuanced about identifiers with `Unix` inIan Jackson2025-03-241-3/+7
| | | | |
| * | | | RPC: Explain in more detail about Windows "named pipe"sIan Jackson2025-03-241-2/+5
| | | | |
| * | | | AF_UNIX terminology: Rename two error structsIan Jackson2025-03-2410-21/+43
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We change `NoUnixAddressSupport` to `NoAfUnixSocketSupport` because it doesn't make much sense to talk about support for the addresses separately from support for the sockets.
| * | | | AF_UNIX terminology: Rename two error variantsIan Jackson2025-03-247-13/+32
| | | | | | | | | | | | | | | | | | | | Change `..UnixAddress...` to `...AfUnixAddress..`.
| * | | | RPC: Abolish an unused and misnamed error variantIan Jackson2025-03-243-5/+4
| | | | | | | | | | | | | | | | | | | | | | | | | This variant breaches the new guidelines about AF_UNIX terminology. And its purpose is unclear and it's not used.
| * | | | Fix AF_UNIX terminology in docs, comments, and error messagesIan Jackson2025-03-2412-26/+26
| | | | |
| * | | | Style.md: Discuss how to refer to AF_UNIX socketsIan Jackson2025-03-241-0/+25
| | | | |
| * | | | Style.md: (ab)use linguists' *-convention to decorate deprected usagesIan Jackson2025-03-241-3/+3
|/ / / / | | | | | | | | | | | | This marks the anti-examples more clearly.
* | | | Merge branch 'maint-cargo-sort' into 'main'Jim Newsome2025-03-211-2/+21
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix erratic rust-checks pipeline on non-arti toplevels Closes #1868 See merge request tpo/core/arti!2864
| * | | | maint: docs and formatting for cargo_sortmatt0222025-03-211-2/+10
| | | | |
| * | | | cargo_sort: better checking scriptmatt0222025-03-211-2/+13
|/ / / /
* | | | Merge branch 'rand-select-more' into 'main'Nick Mathewson2025-03-201-0/+8
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-netdir: Handle InsufficientNonZero error. See merge request tpo/core/arti!2877
| * | | | tor-netdir: Handle InsufficientNonZero error.Nick Mathewson2025-03-201-0/+8
|/ / / / | | | | | | | | | | | | Possible fix for #1902.
* | | | Merge branch 'named_protovers' into 'main'David Goulet2025-03-207-12/+177
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | protover: Add support for subprotocol version mnemonics. Closes #1891 See merge request tpo/core/arti!2854
| * | | | Use named subprotocol versions throughout arti.Nick Mathewson2025-03-123-11/+12
| | | | |
| * | | | protover: Add support for subprotocol version mnemonics.Nick Mathewson2025-03-124-0/+162
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It's error-prone to have to remember e.g. that "Desc=5" means "family ID support", so in torspec!251 we added mnemonic names like DESC_FAMILY_IDS. Here we use those names in tor-protover.
| * | | | protover: Add Conflux protocol group.Nick Mathewson2025-03-121-1/+3
| | | | |
* | | | | Merge branch 'inherent=none' into 'main'Nick Mathewson2025-03-201-2/+3
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | rpc-book: Clarify auth="none" vs auth:inherent Closes #1820 See merge request tpo/core/arti!2872
| * | | | | rpc-book: Clarify auth="none" vs auth:inherentNick Mathewson2025-03-191-2/+3
| | |/ / / | |/| | | | | | | | | | | | | Closes #1820.
* | | | | Merge branch 'client-arti' into 'main'opara2025-03-201-16/+12
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | replace state_dir and storage_mistrust with tor_persist::state_dir::StateDirectory See merge request tpo/core/arti!2863
| * | | | replace state_dir and storage_mistrust with ↵abdul28012025-03-201-16/+12
| | | | | | | | | | | | | | | | | | | | tor_persist::state_dir::StateDirectory
* | | | | Merge branch 'timeout_est_overflow' into 'main'Nick Mathewson2025-03-191-3/+11
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Impose a maximum on our fallback estimated timeout Closes #1693 See merge request tpo/core/arti!2842
| * | | | | Impose a maximum on our fallback estimated timeoutNick Mathewson2025-03-061-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The fallback timeout is the one that we use when we have insufficient data. We reset our observations, and maybe rebuild our circuits, when we find that too many circuits have failed recently. When we do so, we double our fallback timeout. Previously we had no limit, which could lead to overflow (#1693). In this commit we impose a maximum of 2 hours, which is ridiculously high. (C tor uses a maximum of INT32_MAX seconds, which is even more ridiculously high.) Closes #1693.
* | | | | | Merge branch 'rand-0.9' into 'main'Nick Mathewson2025-03-19121-524/+721
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | Port to rand 0.9 See merge request tpo/core/arti!2869
| * | | | | proto: make padding::Parameters construction fallible.Nick Mathewson2025-03-184-23/+106
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The constructor for rand::distr::Uniform is now fallible, so it makes sense to bubble up its restrictions. This is a breaking change.
| * | | | | Update Cargo.lock in bench directories.Nick Mathewson2025-03-182-218/+256
| | | | | |
| * | | | | Add a semver note about rand 0.9Nick Mathewson2025-03-181-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (This applies to every crate that has an API that takes a `rand::Rng` or any related trait.)