summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | | | maint: Allow CDLA-Permissive-2.0 license.Wesley Aptekar-Cassels2025-04-291-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This seems to be compatible with our licenses, and is used by the webpki crates.
| * | | | | | | | Run cargo update.Wesley Aptekar-Cassels2025-04-2926-278/+188
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I updated everything except rand, because the new version of rand interacts with #1903, thus requiring more care.
| * | | | | | | | Upgrade dependencies.Wesley Aptekar-Cassels2025-04-292-5/+5
|/ / / / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Updates: * hashlink 0.9.1 -> 0.10.0 * Updates hashbrown * metrics-exporter-prometheus 0.16.2 -> 0.17.0 * Bumps deps * Minor API change Not updated: * rusqlite, due to MSRV incompatibility * educe (#1257) * hickroy-proto (https://github.com/hickory-dns/hickory-dns/issues/2956)
* | | | | | | | Merge branch 'cgo-crypto-v1' into 'main'Nick Mathewson2025-04-2915-416/+2823
|\ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement CGO cryptography backends. Closes #1943 See merge request tpo/core/arti!2942
| * | | | | | | | tor-proto: use RelayCellFormat rather than u8 in tests.Nick Mathewson2025-04-291-14/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (The u8 code was written before RelayCellFormat::V1 was introduced.)
| * | | | | | | | Rename feature cgo => counter-galois-onion.Nick Mathewson2025-04-292-5/+5
| | | | | | | | |
| * | | | | | | | CGO: Fix authenticated-sendme tag handling.Nick Mathewson2025-04-291-5/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | See discussion at torspec#328: it's important that our SENDME authentication tag always be taken based on the _encrypted_ cell.
| * | | | | | | | CGO: Note another possible performance improvement.Nick Mathewson2025-04-291-0/+3
| | | | | | | | |
| * | | | | | | | proto: Implement and test CGO cryptography.Nick Mathewson2025-04-294-13/+763
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This provides all the operations from proposal 359, along with the necessary integration and unit tests to make sure that they are behaving properly. Closes #1943
| * | | | | | | | proto: Implement UIV+, the wide-block RPRP used for CGO.Nick Mathewson2025-04-292-1/+456
| | | | | | | | |
| * | | | | | | | proto: Implement CGO functions ET and PRFNick Mathewson2025-04-295-4/+846
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These are a tweakable block cipher, and a pseudorandom byte stream. This commit includes test vectors, which were generated from the Python reference implementation and confirmed with a less optimized Rust implementation.
| * | | | | | | | New empty CGO module.Nick Mathewson2025-04-292-1/+26
| | | | | | | | |
| * | | | | | | | proto: Unified integration tests for relay crypto.Nick Mathewson2025-04-291-3/+210
| | | | | | | | |
| * | | | | | | | proto: Make relay-side cell crypto traits return tags.Nick Mathewson2025-04-292-15/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (We'll need these tags both to implement authenticated SENDMES at the relay side, and also to make sure that cgo is generating them correctly.)
| * | | | | | | | proto: Make crypt layers take a ChanCmd argumentNick Mathewson2025-04-295-49/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | CGO will need this argument so that it can authenticate the command as part of its crypto operations. (Trying to meddle with RELAY vs RELAY_EARLY will no longer work!)
| * | | | | | | | proto: refactor RelayCrypt trait into separate traitsNick Mathewson2025-04-295-21/+80
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It seems very likely that, as with client crypto, we'll want relay crypto to separable into "forward" and "reverse" objects, so that the two can be used more or less independently.
| * | | | | | | | proto: Tweak semantics of RelayCrypt::originate.Nick Mathewson2025-04-293-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes the behavior of "originate" match the behavior of OutboundClientLayer::originate_for, which creates the message _and_ encrypts it. This will be necessary for CGO, where "originate" and "encrypt" are not easily separated operations. (Nothing uses this trait yet, since relay circuits aren't yet a thing, so it's a good time to get it right.)
| * | | | | | | | proto: move tor1 testvector test into tor1 module.Nick Mathewson2025-04-292-54/+79
| | | | | | | | |
| * | | | | | | | proto: Clean up imports in tor1.rs.Nick Mathewson2025-04-292-6/+8
| | | | | | | | |
| * | | | | | | | proto: Move tor1 relay crypto to a separate file.Nick Mathewson2025-04-292-312/+312
|/ / / / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Since we're about to have a second kind of relay cell crypto, it makes sense to move this module. This change is pure code movement.
* | | | | | | | Merge branch 'log_conventions' into 'main'Nick Mathewson2025-04-287-8/+97
|\ \ \ \ \ \ \ \ | |_|_|/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Log conventions Closes #1906 See merge request tpo/core/arti!2966
| * | | | | | | Include "bug" in all bug error messagesNick Mathewson2025-04-286-8/+11
| | | | | | | |
| * | | | | | | New developer document about log conventions.Nick Mathewson2025-04-281-0/+86
| | |/ / / / / | |/| | | | |
* | | | | | | Merge branch 'fix-rustsec-2024-0384' into 'main'Jim Newsome2025-04-283-187/+31
|\ \ \ \ \ \ \ | |_|_|_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Replace signal-hook-async-std with async-signal to fix RUSTSEC-2024-0384 Closes #1867 See merge request tpo/core/arti!2960
| * | | | | | Replace signal-hook-async-std with async-signal to fix RUSTSEC-2024-0384Vijaya Bhaskar2025-04-263-187/+31
| |/ / / / /
* | | | | | Merge branch 'optimize-for-performance' into 'main'Nick Mathewson2025-04-284-7/+25
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Change "release" to optimize for peformance. Closes #1954 See merge request tpo/core/arti!2959
| * | | | | correct references claiming that --release optimized for sizeNick Mathewson2025-04-282-2/+6
| | | | | |
| * | | | | Correct description of lto.Nick Mathewson2025-04-281-1/+1
| | | | | |
| * | | | | Change "release" to optimize for peformance.Nick Mathewson2025-04-242-5/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (Previously, it was optimized for size, leading to problems like \#1336.) For any purposes that need the old optimize-for-size behavior, I've added a new "release-small" target. I've also moved the "strip=debuginfo" behavior from maint/binary_size to this new target, since cargo started supporting "strip" in 1.59. Closes #1954.
* | | | | | Merge branch 'upgrade-shadow' into 'main'opara2025-04-241-3/+2
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | ci: Upgrade shadow version to get TCP FIN fix See merge request tpo/core/arti!2958
| * | | | | ci: upgrade shadow version to get TCP FIN fixSteven Engler2025-04-241-3/+2
|/ / / / /
* | | | | Merge branch 'fix-cc-handshake' into 'main'opara2025-04-241-2/+27
|\ \ \ \ \ | |_|_|/ / |/| | | | | | | | | | | | | | tor-proto: Prevent congestion control extension during ntor-v3 extend See merge request tpo/core/arti!2957
| * | | | tor-proto: prevent cc extension during ntor-v3 extendSteven Engler2025-04-241-2/+27
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was missed in commits ccb65961 and eeda643f. While `params.ccontrol.is_enabled()` should always be false because of those earlier commits which ensure we don't enable congestion control, we were missing the defense-in-depth conditions here that would alert us if we accidentally did enable congestion control.
* | | | Merge branch 'ticket1817_02' into 'main'David Goulet2025-04-2422-127/+468
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | Implement congestion control handshake negotiation Closes #1817 See merge request tpo/core/arti!2932
| * | | tor-circmgr: put vegas cc in `CircParameters` behind `if false`Steven Engler2025-04-232-22/+55
| | | | | | | | | | | | | | | | | | | | This means that even with the "flowctl-cc" feature enabled, we shouldn't try to negotiate congestion control.
| * | | tor-circmgr: only use congestion control if "flowctl-cc" feature is enabledSteven Engler2025-04-232-3/+7
| | | |
| * | | tor-proto: only use congestion control if "flowctl-cc" feature is enabledSteven Engler2025-04-235-19/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Congestion control is not completely working correctly, and is not fully implemented (XON/XOFF). This commit adds a new experimental "flowctl-cc" feature to enable the congestion control extension during the ntor-v3 handshake.
| * | | tor-proto: expand docs for `CongestionWindowParams::set_sendme_inc`Steven Engler2025-04-231-1/+5
| | | |
| * | | tor-circmgr: switch from `supports_{known,named}_subver()`Steven Engler2025-04-231-3/+3
| | | |
| * | | tor-proto: rename `stream_sendme_required` to `uses_stream_sendme`Steven Engler2025-04-234-9/+9
| | | |
| * | | tor-proto: rename `allow_stream_sendme` to `uses_stream_sendme`Steven Engler2025-04-234-10/+10
| | | | | | | | | | | | | | | | | | | | We use this method to decide whether to allow receiving stream SENDMEs, and also whether we should send stream SENDMEs.
| * | | tor-proto: remove redundant `allow_stream_sendme` checkSteven Engler2025-04-231-15/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | `OpenStreamEnt::put_for_incoming_sendme()` calls `StreamSendFlowControl::put_for_incoming_sendme()`, which returns an error if the `StreamSendFlowControl` is in XON/XOFF mode. So we don't need this extra check.
| * | | tor-proto: initialize `StreamSendFlowControl` based on CCSteven Engler2025-04-231-2/+6
| | | | | | | | | | | | | | | | | | | | Congestion control tells us whether we should use stream or XON/XOFF flow control.
| * | | tor-proto: new stream entries now take `StreamSendFlowControl`Steven Engler2025-04-232-15/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously new stream entries required a `StreamSendWindow`, but to support other flow control algorithms, we want new stream entries to take a `StreamSendFlowControl` instead. This also deduplicates the `StreamSendWindow` creation code.
| * | | tor-proto: add no-op XON/XOFF flow control variantSteven Engler2025-04-231-8/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This doesn't do anything yet, so is effectively like not having stream flow control. This should be implemented as part of arti#534.
| * | | tests: Add CC ntorv3 negotiation unit testDavid Goulet2025-04-233-10/+86
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also add one for the sendme_inc validity function. Part of #1817 Signed-off-by: David Goulet <[email protected]>
| * | | circ: Don't pin CC algorithm to FixedWindow anymoreDavid Goulet2025-04-231-4/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Circuit handshake negotiation for congestion control has been added in previous commit so stop pinning the algorithm. This commit marks the start of congestion control usage by arti client. Closes #1817 Signed-off-by: David Goulet <[email protected]>
| * | | circ: Don't allow stream level SENDME with CCDavid Goulet2025-04-231-2/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we ever receive a stream-level SENDME from the Exit while the circuit is under congestion control (Vegas), it is a protocol violation so close the circuit. This is important in order to avoid yet another side channel with cells that would be essentially ignored silently. Part of #1817 Signed-off-by: David Goulet <[email protected]>
| * | | circ: Don't send stream level SENDME with CCDavid Goulet2025-04-235-7/+44
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new function to the CongestionControl object that returns true or false on if stream level SENDMEs are allowed by the underlying algorithm. Congestion control Vegas doesn't allow them as in it retires them and so we avoid sending them for that algorithm. Part of #1817 Signed-off-by: David Goulet <[email protected]>
| * | | tor-proto: added `stream_sendme_required` methodsSteven Engler2025-04-233-0/+23
| | | | | | | | | | | | | | | | | | | | These pass through congestion control state to the reactor, and aren't actually hooked up to the congestion control code yet.