summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | rpc: Document cookie messages a little more.Nick Mathewson2025-01-151-1/+14
| | |
| * | rpc: Use symbolic constants for nonce/mac lengths.Nick Mathewson2025-01-151-7/+14
| | |
| * | rpc: Tests for cookie nonce/mac encoding/decoding.Nick Mathewson2025-01-151-2/+46
| | | | | | | | | | | | Also fix a bug in decoding, where we accepted too-short strings.
| * | rpc: Refactor Cookie and UnloadedCookie into a single type.Nick Mathewson2025-01-156-28/+45
| | |
| * | rpc: Update cbindgen warnings.Nick Mathewson2025-01-151-0/+3
| | |
| * | rpc: consolodate naming of "inherent" auth.Nick Mathewson2025-01-157-23/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | We don't want to call this "unix path" anywhere, since it corresponds to _any_ case where the ability to negotiate a successful connection means that the client is authorized. We also don't want to call it "none": The authentication is inherent to the connection, not nonexistent.
| * | rpc: Tweak cookie protocol to bind both nonces.Nick Mathewson2025-01-154-10/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously participants in the cookie protocol only bound the peer nonce in their MACs. With this change, they bind both nonces. This change is _probably_ not necessary for security, but it can't hurt. It follows a general principle that Adam Langley told me a long time ago: you won't regret binding more, but you might regret binding less.
| * | rpc: Keep Cookie in an Arc.Nick Mathewson2025-01-153-5/+11
| | | | | | | | | | | | | | | Since this is a secret value, it's probably best not to copy it all over the place.
| * | RPC tests: test that unix sockets still work.Nick Mathewson2025-01-151-0/+14
| | |
| * | RPC tests: use cookie authentication as the default.Nick Mathewson2025-01-152-4/+39
| | | | | | | | | | | | | | | (Since Windows doesn't have unix sockets, this is the option that will work everywhere.)
| * | rpc_tests: rename connpt_path, since we are about to have a second.Nick Mathewson2025-01-151-5/+6
| | |
| * | arti-rpc-client-core: Client side of cookie authentication.Nick Mathewson2025-01-155-9/+106
| | |
| * | arti-rpc-client-core: rewrap Cargo.tomlNick Mathewson2025-01-151-1/+9
| | |
| * | arti-rpcserver: Server side of cookie auth.Nick Mathewson2025-01-154-10/+214
| | |
| * | arti-rpcserver: Tell connections what kind of auth to expect.Nick Mathewson2025-01-157-28/+38
| | |
| * | arti-rpcserver: move inherent authentication to its own module.Nick Mathewson2025-01-152-69/+83
| | |
| * | arti-rpcserver: remove some dead code.Nick Mathewson2025-01-151-57/+0
| | | | | | | | | | | | | | | Now that we have a solid idea of how connections happen, it's clear we won't need to enable this negotiation mechanism.
| * | tor-rpc-connect: Cryptographic support for cookie auth.Nick Mathewson2025-01-153-5/+220
| | | | | | | | | | | | Conforms to rpc-cookie-sketch.md.
| * | rpc-cookie-sketch: typo fix.Nick Mathewson2025-01-151-1/+1
| | |
| * | tor-rpc-connect: defer loading auth cookies on the client side.Nick Mathewson2025-01-153-6/+37
| | | | | | | | | | | | | | | We want to load cookies only after we've connected and gotten a banner.
| * | tor-rpc-connect: move cookie auth support to its own module.Nick Mathewson2025-01-155-171/+172
| | |
* | | Merge branch 'p101-2024-q4' into 'main'Alexander Hansen Færøy2025-01-151-0/+26
|\ \ \ | |_|/ |/| | | | | | | | Update P101 numbers for Q4-2024 See merge request tpo/core/arti!2711
| * | Update P101 numbers for Q4-2024.Alexander Færøy2025-01-151-0/+26
| |/
* | Merge branch 'relay-bin-3' into 'main'opara2025-01-152-21/+2
|\ \ | | | | | | | | | | | | arti-relay: remove 'override_net_params' config See merge request tpo/core/arti!2709
| * | arti-relay: remove 'override_net_params' configSteven Engler2025-01-142-21/+2
| | | | | | | | | | | | | | | | | | | | | We think that for relays, the 'override_net_params' config option is overly broad and a footgun. We can always re-add this back later if we want to, but for now the focus will be on exposing specific config options for features that are okay to be changed by users.
* | | Merge branch 'kist-socks' into 'main'gabi-2502025-01-1534-46/+431
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | tor-proto: Initial KIST support (Linux-only) Closes #1728, #1729, and #1730 See merge request tpo/core/arti!2706
| * | tor-chanmgr: Update NetParamsExtract docs (fmt).Gabriela Moldovan2025-01-151-1/+2
| | |
| * | tor-chanmgr: Update NetParamsExtract docs.Gabriela Moldovan2025-01-151-4/+1
| | | | | | | | | | | | | | | This also removes the TODO that was addressed by adding the kist params to this type.
| * | tor-chanmgr: Move KIST and padding params to ChannelParams.Gabriela Moldovan2025-01-151-11/+22
| | |
| * | tor-proto: Remove dependency on tor-netdir.Gabriela Moldovan2025-01-156-50/+51
| | | | | | | | | | | | | | | | | | | | | | | | This moves the `NetParameters -> KistParams` conversion to `tor-chanmgr`. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2706#note_3147557
| * | tor-chanmgr: Add a TODO about a possible renaming.Gabriela Moldovan2025-01-151-0/+3
| | |
| * | tor-proto: Replace constants with caret_int.Gabriela Moldovan2025-01-153-3/+16
| | |
| * | tor-rtcompat: Rename UnsupportedStreamOps to NoOpStreamOpsHandle (fmt).Gabriela Moldovan2025-01-153-5/+5
| | |
| * | tor-rtcompat: Rename UnsupportedStreamOps to NoOpStreamOpsHandle.Gabriela Moldovan2025-01-155-9/+9
| | | | | | | | | | | | | | | This renames UnsupportedStreamOpsHandle to NoOpStreamOpsHandle for clarity (the old name kind of sounded like the name of an error type).
| * | tor-async-utils: Fix type inference in test.Gabriela Moldovan2025-01-151-1/+2
| | |
| * | tor-changmgr: Update the KIST params whenever the consensus/config changes.Gabriela Moldovan2025-01-151-8/+34
| | | | | | | | | | | | Closes #1730, #1728
| * | tor-chanmgr: Add reparameterize_kist to AbstractChannel trait.Gabriela Moldovan2025-01-155-0/+22
| | | | | | | | | | | | | | | Needed for the chanmgr to be able to update existing channels with new KIST settings read from the consensus.
| * | tor-proto: Set kist params in channel reactor.Gabriela Moldovan2025-01-152-2/+33
| | |
| * | tor-proto: Add Channel::reparameterize_kist() API.Gabriela Moldovan2025-01-151-0/+9
| | | | | | | | | | | | | | | This will enable us to update the channel's KIST configuration whenever there is a change in the consensus or config.
| * | tor-proto: Add CtrlMsg for setting kist options (fmt).Gabriela Moldovan2025-01-151-1/+3
| | |
| * | tor-proto: Add CtrlMsg for setting kist options.Gabriela Moldovan2025-01-151-1/+8
| | |
| * | tor-rtcompat: Fix doc warning.Gabriela Moldovan2025-01-151-1/+1
| | |
| * | tor-proto: Pass a StreamOps handle to the channel reactor.Gabriela Moldovan2025-01-153-2/+16
| | |
| * | tor-rtcompat: Big invasive change adding StreamOps bound everywhere.Gabriela Moldovan2025-01-1511-21/+34
| | | | | | | | | | | | | | | | | | This is unfortunately necessary, because after the channel handshake, we need to give the channel reactor a `StreamOps` handle to the underlying stream.
| * | tor-rtcompat: Implement StreamOps for TLS stream types.Gabriela Moldovan2025-01-152-1/+22
| | |
| * | tor-rtmock: Implement StreamOps for MockTlsStream (fmt).Gabriela Moldovan2025-01-151-1/+3
| | |
| * | tor-rtmock: Implement StreamOps for MockTlsStream.Gabriela Moldovan2025-01-151-1/+14
| | | | | | | | | | | | | | | We're about to add a trait bound that forces `MockTlsStream` to impl `StreamOps`.
| * | tor-rtcompat: Implement StreamOps for Framed.Gabriela Moldovan2025-01-153-0/+15
| | |
| * | tor-rtcompat: Implement new_handle() using TcpSockFd (fmt).Gabriela Moldovan2025-01-151-1/+3
| | |
| * | tor-rtcompat: Implement new_handle() using TcpSockFd.Gabriela Moldovan2025-01-154-3/+16
| | |