summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | tor-netdoc: rs: Use species macrology for DocDigestIan Jackson2025-08-182-18/+18
| | | | | | | | | | | | | | | | | | | | | | | | Part of making these two files largely identical.
| * | | | | tor-netdoc: rs: Use species macrology for ConsensusRouterStatusIan Jackson2025-08-184-25/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In the species-specific files ns.rs and md.rs, use the unqualified name; re-export it with the new macro. We are working towards making these two files largely identical.
| * | | | | tor-netdoc: Introduce new "species" macrologyIan Jackson2025-08-186-0/+231
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will let us deduplicate a fair amount of code, and also will let us support votes as well as ns and md consensuses.
| * | | | | tor-netdoc: Change all in-tree references to ns-consensus from ns_consensusIan Jackson2025-08-186-15/+15
| | | | | |
| * | | | | tor-netdoc: Change feature name to `ns-consensus` with a hyphenIan Jackson2025-08-182-1/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Our features are generally kebab-case, and this is the way it's documented. Retain the old name for compatibility.
| * | | | | tor-netdoc: Remove two false commentsIan Jackson2025-08-182-2/+0
|/ / / / / | | | | | | | | | | | | | | | Cut-and-paste error, I think.
* | | | | Merge branch 'pow-manager-onion-service-status-etc' into 'main'wesleyac2025-08-1820-236/+596
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | More PoW miscellania See merge request tpo/core/arti!3132
| * | | | docs: Add notes about hs-pow-full using LGPL deps.Wesley Aptekar-Cassels2025-08-142-1/+3
| | | | |
| * | | | tor-hsservice: Move check for enable_pow without hs-pow-full feature.Wesley Aptekar-Cassels2025-08-142-11/+9
| | | | | | | | | | | | | | | | | | | | This also make this check a error rather than a warning.
| * | | | tor-hsservice: Add note about check_solve implementation.Wesley Aptekar-Cassels2025-08-131-0/+3
| | | | |
| * | | | tor-hsservice: Fix error message.Wesley Aptekar-Cassels2025-08-131-1/+1
| | | | |
| * | | | tor-hsservice: Change capping of PoW effort.Wesley Aptekar-Cassels2025-08-133-36/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This caps the PoW effort during sorting, rather than at intake. This allows us to record efforts that are capped in our metrics histogram while only recording metrics after the PoW solve has actually been verified.
| * | | | tor-hsservice: Make some PoW warnings more understandable.Wesley Aptekar-Cassels2025-08-131-3/+10
| | | | |
| * | | | arti: Add more explanation of pow_rend_queue_depth to example config.Wesley Aptekar-Cassels2025-08-131-1/+3
| | | | |
| * | | | tor-hsservice: Improve error conversion code.Wesley Aptekar-Cassels2025-08-131-16/+8
| | | | |
| * | | | tor-hsservice: Use warn_report for PoW errors.Wesley Aptekar-Cassels2025-08-131-9/+15
| | | | |
| * | | | tor-hsservice: Don't set DegradedReachable status in PowManager.Wesley Aptekar-Cassels2025-08-131-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Three is a concern that a DegradedReachable status could overwrite a previous Broken status. A nicer solution could be to add a function to StatusSender that only will change the status to a "more or equally severe" status. However, I am a little dubious about using the DegradedReachable status for PoW in general, since it has a better documented meaning for IPTs than it does for PoW.
| * | | | tor-hsservice: Remove outdated comment.Wesley Aptekar-Cassels2025-08-131-5/+0
| | | | | | | | | | | | | | | | | | | | We do in fact need multiple locations to hold the sender.
| * | | | tor-hsservice: Rename InternalPowError to PowError.Wesley Aptekar-Cassels2025-08-132-13/+13
| | | | |
| * | | | tor-hsservice: Make InternalPowError non_exhaustive.Wesley Aptekar-Cassels2025-08-131-0/+1
| | | | | | | | | | | | | | | | | | | | Now that this is public, this is prudent.
| * | | | tor-hsservice: Make OpenReplayLog error transparent.Wesley Aptekar-Cassels2025-08-131-1/+1
| | | | |
| * | | | tor-hsservice: Fix clippy.Wesley Aptekar-Cassels2025-08-131-3/+2
| | | | |
| * | | | tor-hsservice: Add disable_pow_compilation option.Wesley Aptekar-Cassels2025-08-135-15/+47
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I'm not 100% on this being here, it seems like it might want to be a option for all onion services, rather than per-service. However, this is good enough for now.
| * | | | tor-hsservice: Warn when enable_pow is set on a non hs-pow-full build.Wesley Aptekar-Cassels2025-08-132-1/+11
| | | | |
| * | | | tor-hsservice: Remove unimplemented config option.Wesley Aptekar-Cassels2025-08-131-10/+0
| | | | | | | | | | | | | | | | | | | | | | | | | This config option doesn't really apply to Prop 362 (which is what's implemented in Arti), as far as I can tell.
| * | | | tor-hsservice: Remove outdated TODO.Wesley Aptekar-Cassels2025-08-131-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I have thought about this and come to the conclusion (which is what I suspected when I wrote it) that the current behaviour is correct. The attack described is completely impractical (the space of nonces is very large), and checking whether a nonce is a replay is cheaper than verifying a PoW solve, so we want to do that first. Splitting this into something like the following: * Check replay log without updating * Check that solve is valid * Update replay log Would require adding a somewhat dangerous API to the ReplayLog, and requires doing more work per request for something that isn't even a practical attack, AFAICT.
| * | | | tor-hsservice: Add note about not persisting per-PoW-period state.Wesley Aptekar-Cassels2025-08-131-1/+7
| | | | |
| * | | | tor-hsservice: Add metrics support to PoW code.Wesley Aptekar-Cassels2025-08-134-3/+61
| | | | |
| * | | | tor-hsservice: Restore PoW verifier state from disk.Wesley Aptekar-Cassels2025-08-131-2/+25
| | | | | | | | | | | | | | | | | | | | | | | | | We restored the seeds, but doing so is counterproductive if we don't also recreate the verifiers needed to check solves for those seeds.
| * | | | tor-hsservice: Add pow_rend_queue_depth config option.Wesley Aptekar-Cassels2025-08-133-35/+118
| | | | |
| * | | | tor-hsservice: Pass Rng into PoW code where possible.Wesley Aptekar-Cassels2025-08-132-10/+11
| | | | |
| * | | | tor-hsservice: Implement enable_pow option.Wesley Aptekar-Cassels2025-08-136-61/+139
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This does not currently allow this option to be changed at runtime, although the code is structured so that allowing it to be changed at runtime won't be too hard. This is tracked by #2082.
| * | | | tor-hsservice: Reenable publisher test in hs-pow-full.Wesley Aptekar-Cassels2025-08-132-12/+3
| | | | | | | | | | | | | | | | | | | | MockExecutor now supports the features needed for this test to work.
| * | | | tor-hsservice: Add PowManager to OnionServiceStatus.Wesley Aptekar-Cassels2025-08-137-35/+130
| | | | |
| * | | | tor-hsservice: Change ReplayLog error type.Wesley Aptekar-Cassels2025-08-135-17/+21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This disentangles the ReplyLog from the IptManager. This will allow us to make the InternalPowError type more public (in order to use it in the OnionServiceStatus code) without also having to make the CreateIptError type more public.
* | | | | Merge branch 'netdoc2' into 'main'Ian Jackson2025-08-1466-258/+6794
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | New netdoc parser, with derive macro See merge request tpo/core/arti!3135
| * | | | | tor-netdoc: Rerun cargo fmt after rebaseIan Jackson2025-08-142-3/+3
| | | | | |
| * | | | | tor-netdoc: parse2: Fix typo in "Naming conventions" docIan Jackson2025-08-141-1/+1
| | | | | |
| * | | | | tgr-netdoc: Tests of parse2Ian Jackson2025-08-142-0/+93
| | | | | | | | | | | | | | | | | | | | | | | | We parse and verify some network documents from testdata2.
| * | | | | tor-netdoc: Proof-of-concept demo of new parserIan Jackson2025-08-146-0/+861
| | | | | | | | | | | | | | | | | | | | | | | | This can parse and validate the signatures on a consensus.
| * | | | | tor-netdoc: Introduce parse2, new parserIan Jackson2025-08-1414-0/+2304
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This isn't used anywhere yet. We're going to demonstrate it, and test the demo, in a moment.
| * | | | | tor-netdoc: Add dependencies: derive-deftly, paste, strum, testresultIan Jackson2025-08-142-0/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | testresult is a new dependency for arti.git. (It's being added as a test-dependenchy here.) It is has a very useful Result type for use in test cases.
| * | | | | tor-netdoc: Always expose NicknameIan Jackson2025-08-143-8/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a fine API. The representation may change, but that wouldn't be breaking.
| * | | | | tor-netdoc: Improve and expose Fingerprint parsing adaptersIan Jackson2025-08-142-4/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We won't want them ever to be anything other than a wrapper around `RsaIdentity`, so we can make them transparent. Derive various useful traits, including Deref. Expose them publicly, since there's no reason not to do so. (The new parser will want to reuse them. It's in-crate, but out-of-crate users may want to use these too for other netdoc types.)
| * | | | | tor-llcrypto: implement Hash for RsaPublicKeyIan Jackson2025-08-140-0/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Revert "tor-llcrypto: implement Hash for RsaPublicKey" This reverts commit 5df5ed8c4be5376a7288f1332541d9bff29a08f5.
| * | | | | tor-netdoc: Expose base64_decode_multiline to crateIan Jackson2025-08-141-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | The new parser is going to reuse this.
| * | | | | tor-netdoc: sort the experimental cargo featuresIan Jackson2025-08-141-2/+2
| | | | | |
| * | | | | netdoc test data: Switch two tests to new consensus dataIan Jackson2025-08-143-243/+3
| | | | | |
| * | | | | netdoc test data: refresh (for first time) by running scriptIan Jackson2025-08-1435-0/+3393
| | | | | |
| * | | | | netdoc test data: Provide script for downloading from CIIan Jackson2025-08-143-0/+97
| |/ / / / | | | | | | | | | | | | | | | Plan to gradually move over to this semiautomatically-maintained data.