summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | tor-rtmock: allow-Decorate every use of MockSleepProviderIan Jackson2025-03-068-3/+35
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | MockSleepProvider and MockSleepRuntime have been declared deprecated by the docs for some time. We're about to mark them `#[deprecated]`. This commit has been split out for clarity of review.
* | | | Merge branch 'move-circ' into 'main'gabi-2502025-03-069-1312/+1400
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-proto: Move Circuit to its own module. See merge request tpo/core/arti!2837
| * | | | tor-proto: s/note/warning in function docs about locking stream map mutex.Gabriela Moldovan2025-03-061-1/+1
| | | | |
| * | | | tor-proto: s/has_first_hop/has_hops (fmt).Gabriela Moldovan2025-03-061-5/+1
| | | | |
| * | | | tor-proto: s/has_first_hop/has_hops.Gabriela Moldovan2025-03-063-3/+3
| | | | |
| * | | | tor-proto: Fix up docs post-refactoring (fmt).Gabriela Moldovan2025-03-061-4/+1
| | | | |
| * | | | tor-proto: Fix up docs post-refactoring.Gabriela Moldovan2025-03-061-3/+3
| | | | |
| * | | | tor-proto: Move Circuit to its own module.Gabriela Moldovan2025-03-069-1325/+1393
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is mostly code motion + some visibility adjustments. Moving all of these outside of `reactor` makes it easier to see which parts are internal vs which are accessed by the reactor. It also helps us enforce/audit invariants such as 'there should be no contention on the `CircHop::map` mutex' (the stream map is now private to `reactor::circuit`, and therefore nothing inside `reactor` will be directly accessing it).
| * | | | tor-proto: Avoid accessing CircHop internals from the reactor.Gabriela Moldovan2025-03-063-2/+16
| | | | | | | | | | | | | | | | | | | | This will enable us to move `CircHop` out of `reactor.rs`.
| * | | | tor-proto: Avoid accessing Circuit internals from the reactor.Gabriela Moldovan2025-03-062-3/+16
|/ / / / | | | | | | | | | | | | This will enable us to factor `Circuit` out of `reactor.rs`.
* | | | Merge branch 'fix-nightly' into 'main'Nick Mathewson2025-03-061-1/+0
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-dirmgr: Remove `dbg!` See merge request tpo/core/arti!2838
| * | | | tor-dirmgr: remove `dbg!`Steven Engler2025-03-051-1/+0
|/ / / /
* | | | Merge branch 'extdocs-pruning' into 'main'Nick Mathewson2025-03-053-102/+473
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | dirmgr: When expiring a consensus, remove its blob from disk. Closes #1655 See merge request tpo/core/arti!2504
| * | | | sqlite: Handle vanished blobs during consensus loadingNick Mathewson2025-03-053-16/+40
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Here we move the responsibility for removing ExtDoc entries for vanished blobs into the _caller_ of read_blob(): we want to tidy all such entries in one go. Unlike a (reverted) previous approach, this time we don't need a retry loop.
| * | | | sqlite: add a method to tidy extdocs for vanished blobsNick Mathewson2025-03-051-1/+93
| | | | |
| * | | | sqlite.rs: Let read_blob signal whether it cleaned up.Nick Mathewson2025-03-051-8/+28
| | | | | | | | | | | | | | | | | | | | We'll want to use this information to tell us whether to retry.
| * | | | sqlite: Extract body of latest_consensus into a new methodNick Mathewson2025-03-051-23/+33
| | | | | | | | | | | | | | | | | | | | I'm about to add a retry mechanism.
| * | | | sqlite: Stop ignoring any errors.Nick Mathewson2025-03-051-3/+22
| | | | | | | | | | | | | | | | | | | | | | | | | We've already stopped ignoring any DB errors, so we may as well make sure that any FS errors we encounter are also reported.
| * | | | sqlite: Add a comment about O(n) query.Nick Mathewson2025-03-051-0/+2
| | | | |
| * | | | sqlite.rs: Rustfmt.Nick Mathewson2025-03-051-86/+87
| | | | |
| * | | | sqlite.rs: Put SavedBlobHandle into its own moduleNick Mathewson2025-03-051-13/+30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will help us keep its members private from the rest of sqlite.rs, and ensure that things are kept consistent. (This violates rust formatting for clarity. I'll reindent after.)
| * | | | sqlite.rs: More comments about blob rollback.Nick Mathewson2025-03-051-1/+7
| | | | |
| * | | | sqlite.rs: Give SavedBlobHandle more methods.Nick Mathewson2025-03-051-24/+47
| | | | | | | | | | | | | | | | | | | | | | | | | This is in preparation for making it opaque from the rest of the code, so that we can more easily reason about it.
| * | | | sqlite.rs: add comments about consistencyNick Mathewson2025-03-051-2/+14
| | | | |
| * | | | sqlite.rs: Add a note on blob consistency (or lack thereof)Nick Mathewson2025-03-051-0/+77
| | | | |
| * | | | sqlite.rs: Rename dtype to digest_type to avoid further confusion.Nick Mathewson2025-03-051-6/+6
| | | | |
| * | | | dirmgr: Propagate row-conversion failure from expire_all.Nick Mathewson2025-03-051-5/+4
| | | | | | | | | | | | | | | | | | | | | | | | | This can only happen because of a bug or because of db corruption, and we probably shouldn't ignore it.
| * | | | dirmgr: When expiring a consensus, remove its blob.Nick Mathewson2025-03-051-2/+68
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, we would leave the ExtDocs blob to expire on its own, and it would hang out for up to a week. Closes #1655.
| * | | | dirmgr: Store the correct value in ExtDocs.typeNick Mathewson2025-03-051-2/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also, document that old values will be kicking around for a little while. Fortunately: - Nothing actually looked at these values before. - All elements in this table have an expiration date, so once a new version of Arti has been running for a week or two, the old erroneous values will go away.
* | | | | Merge branch 'test-all-features' into 'main'Alexander Hansen Færøy2025-03-051-0/+16
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | docs: Add perl and C compiler as build dependencies to 'CONTRIBUTING.md' See merge request tpo/core/arti!2836
| * | | | docs: add "C compiler" as a build dependency to 'CONTRIBUTING.md'Steven Engler2025-03-041-0/+2
| | | | |
| * | | | docs: add perl as a build dependency to 'CONTRIBUTING.md'Steven Engler2025-03-041-0/+14
| |/ / /
* | | | Merge branch 'x509-signature-yeet' into 'main'Nick Mathewson2025-03-058-165/+257
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Switch from x509-signature to rustls-webpki when using rustls. Closes #1824 and #1854 See merge request tpo/core/arti!2816
| * | | | Add permissions for aws-lc-* licensesNick Mathewson2025-03-041-0/+7
| | | | |
| * | | | rustls: move provider-installer to its own function.Nick Mathewson2025-03-041-13/+21
| | | | | | | | | | | | | | | | | | | | | | | | | We do this so that we can make sure there's a provider installed when we run the tests.
| * | | | Require rustls 0.23.20Nick Mathewson2025-03-043-2/+141
| | | | | | | | | | | | | | | | | | | | | | | | | This is the version that introduces `root_hint_subjects()`, which we want our ServerCertVerifier to override.
| * | | | Require rustls-pki-types 1.8 for CertificateDer::from_sliceNick Mathewson2025-03-041-1/+1
| | | | |
| * | | | Remove now-unneeded ring 1.6 from downgrade_dependenciesNick Mathewson2025-03-041-1/+0
| | | | |
| * | | | rustls.rs: Replace x509-signature with rustls-webpkiNick Mathewson2025-03-046-146/+83
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The x509-signature crate is archived, and won't see any more releases. Using it is tying us to ring 0.16 internally, which means we depend on two ring versions. Fortunately, rustls-webpki relaxes some of the earlier restrictions from the vanilla webpki crate, which means that its certificate parser now accepts C tor's oddball x509 certificates as valid. With this change, we can delegate to rustls's built-in signature-checking code, and we only have to override its certificate validation. (We still override it with a pile of comments about how we don't validate link certificates much.) I've had to include a few certificates: two are for tests, but one is needed as a placeholder, since we can't construct a rustls certificate validator without a root cert, even if we'll never use it. Closes #1824. Closes #1854.
| * | | | rtcompat: Un-rename CertificateDer type.Nick Mathewson2025-03-041-6/+8
| |/ / / | | | | | | | | | | | | (We had added this rename when rustls renamed it originally.)
* | | | Merge branch 'remove_email_step' into 'main'David Goulet2025-03-051-7/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Release.md: Remove step about emailing the grants manager See merge request tpo/core/arti!2834
| * | | | Release.md: Remove step about emailing the grants managerNick Mathewson2025-03-041-7/+1
| | | | | | | | | | | | | | | | | | | | | | | | | Bekeela says that now that the Zcash grant is done, we don't need to do this any more.
* | | | | Merge branch 'no-block-on-2' into 'main'Ian Jackson2025-03-0546-159/+511
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | Overhaul Runtime APIs for sync<->async interaction Closes #1835 See merge request tpo/core/arti!2810
| * | | | tor-rtcompat: Fix grammar in docIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3168425
| * | | | tor-rtcompat: Rename spawn_thread to spawn_blockingIan Jackson2025-03-047-43/+42
| | | | | | | | | | | | | | | | | | | | Let's use Tokio terminology here.
| * | | | tor-rtcompat: Give a reason in blocking_io for not using for cpu workIan Jackson2025-03-041-1/+4
| | | | | | | | | | | | | | | | | | | | | | | | | As requested https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167979
| * | | | tor-rtcompat: Fix docs typoIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167978
| * | | | tor-rtcompat: Change the title of RuntimeIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167977
| * | | | tor-rtcompat: Clarify reentrancy restrictions on `block_on`Ian Jackson2025-03-041-2/+5
| | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167976
| * | | | tor-rtcompat: Remove the TODO re #1835Ian Jackson2025-03-041-3/+0
| | | | | | | | | | | | | | | | | | | | This is the TODO we are fixing with this MR.