| Commit message (Collapse) | Author | Age | Files | Lines | ||
|---|---|---|---|---|---|---|
| ... | ||||||
| | * | | rpc: Expose Cookie::load unconditionally. | Nick Mathewson | 2025-01-15 | 1 | -2/+0 | |
| | | | | ||||||
| | * | | arti-rpcserver: require latest tiny-keccak. | Nick Mathewson | 2025-01-15 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | rpc: Clarify auth-repetition rules. | Nick Mathewson | 2025-01-15 | 1 | -2/+5 | |
| | | | | ||||||
| | * | | rpc: Document cookie messages a little more. | Nick Mathewson | 2025-01-15 | 1 | -1/+14 | |
| | | | | ||||||
| | * | | rpc: Use symbolic constants for nonce/mac lengths. | Nick Mathewson | 2025-01-15 | 1 | -7/+14 | |
| | | | | ||||||
| | * | | rpc: Tests for cookie nonce/mac encoding/decoding. | Nick Mathewson | 2025-01-15 | 1 | -2/+46 | |
| | | | | | | | | | | | | | Also fix a bug in decoding, where we accepted too-short strings. | |||||
| | * | | rpc: Refactor Cookie and UnloadedCookie into a single type. | Nick Mathewson | 2025-01-15 | 6 | -28/+45 | |
| | | | | ||||||
| | * | | rpc: Update cbindgen warnings. | Nick Mathewson | 2025-01-15 | 1 | -0/+3 | |
| | | | | ||||||
| | * | | rpc: consolodate naming of "inherent" auth. | Nick Mathewson | 2025-01-15 | 7 | -23/+26 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | We don't want to call this "unix path" anywhere, since it corresponds to _any_ case where the ability to negotiate a successful connection means that the client is authorized. We also don't want to call it "none": The authentication is inherent to the connection, not nonexistent. | |||||
| | * | | rpc: Tweak cookie protocol to bind both nonces. | Nick Mathewson | 2025-01-15 | 4 | -10/+22 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously participants in the cookie protocol only bound the peer nonce in their MACs. With this change, they bind both nonces. This change is _probably_ not necessary for security, but it can't hurt. It follows a general principle that Adam Langley told me a long time ago: you won't regret binding more, but you might regret binding less. | |||||
| | * | | rpc: Keep Cookie in an Arc. | Nick Mathewson | 2025-01-15 | 3 | -5/+11 | |
| | | | | | | | | | | | | | | | | Since this is a secret value, it's probably best not to copy it all over the place. | |||||
| | * | | RPC tests: test that unix sockets still work. | Nick Mathewson | 2025-01-15 | 1 | -0/+14 | |
| | | | | ||||||
| | * | | RPC tests: use cookie authentication as the default. | Nick Mathewson | 2025-01-15 | 2 | -4/+39 | |
| | | | | | | | | | | | | | | | | (Since Windows doesn't have unix sockets, this is the option that will work everywhere.) | |||||
| | * | | rpc_tests: rename connpt_path, since we are about to have a second. | Nick Mathewson | 2025-01-15 | 1 | -5/+6 | |
| | | | | ||||||
| | * | | arti-rpc-client-core: Client side of cookie authentication. | Nick Mathewson | 2025-01-15 | 5 | -9/+106 | |
| | | | | ||||||
| | * | | arti-rpc-client-core: rewrap Cargo.toml | Nick Mathewson | 2025-01-15 | 1 | -1/+9 | |
| | | | | ||||||
| | * | | arti-rpcserver: Server side of cookie auth. | Nick Mathewson | 2025-01-15 | 4 | -10/+214 | |
| | | | | ||||||
| | * | | arti-rpcserver: Tell connections what kind of auth to expect. | Nick Mathewson | 2025-01-15 | 7 | -28/+38 | |
| | | | | ||||||
| | * | | arti-rpcserver: move inherent authentication to its own module. | Nick Mathewson | 2025-01-15 | 2 | -69/+83 | |
| | | | | ||||||
| | * | | arti-rpcserver: remove some dead code. | Nick Mathewson | 2025-01-15 | 1 | -57/+0 | |
| | | | | | | | | | | | | | | | | Now that we have a solid idea of how connections happen, it's clear we won't need to enable this negotiation mechanism. | |||||
| | * | | tor-rpc-connect: Cryptographic support for cookie auth. | Nick Mathewson | 2025-01-15 | 3 | -5/+220 | |
| | | | | | | | | | | | | | Conforms to rpc-cookie-sketch.md. | |||||
| | * | | rpc-cookie-sketch: typo fix. | Nick Mathewson | 2025-01-15 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-rpc-connect: defer loading auth cookies on the client side. | Nick Mathewson | 2025-01-15 | 3 | -6/+37 | |
| | | | | | | | | | | | | | | | | We want to load cookies only after we've connected and gotten a banner. | |||||
| | * | | tor-rpc-connect: move cookie auth support to its own module. | Nick Mathewson | 2025-01-15 | 5 | -171/+172 | |
| | | | | ||||||
| * | | | Merge branch 'p101-2024-q4' into 'main' | Alexander Hansen Færøy | 2025-01-15 | 1 | -0/+26 | |
| |\ \ \ | |_|/ |/| | | | | | | | | Update P101 numbers for Q4-2024 See merge request tpo/core/arti!2711 | |||||
| | * | | Update P101 numbers for Q4-2024. | Alexander Færøy | 2025-01-15 | 1 | -0/+26 | |
| | |/ | ||||||
| * | | Merge branch 'relay-bin-3' into 'main' | opara | 2025-01-15 | 2 | -21/+2 | |
| |\ \ | | | | | | | | | | | | | arti-relay: remove 'override_net_params' config See merge request tpo/core/arti!2709 | |||||
| | * | | arti-relay: remove 'override_net_params' config | Steven Engler | 2025-01-14 | 2 | -21/+2 | |
| | | | | | | | | | | | | | | | | | | | | | | We think that for relays, the 'override_net_params' config option is overly broad and a footgun. We can always re-add this back later if we want to, but for now the focus will be on exposing specific config options for features that are okay to be changed by users. | |||||
| * | | | Merge branch 'kist-socks' into 'main' | gabi-250 | 2025-01-15 | 34 | -46/+431 | |
| |\ \ \ | |_|/ |/| | | | | | | | | | | | | | | tor-proto: Initial KIST support (Linux-only) Closes #1728, #1729, and #1730 See merge request tpo/core/arti!2706 | |||||
| | * | | tor-chanmgr: Update NetParamsExtract docs (fmt). | Gabriela Moldovan | 2025-01-15 | 1 | -1/+2 | |
| | | | | ||||||
| | * | | tor-chanmgr: Update NetParamsExtract docs. | Gabriela Moldovan | 2025-01-15 | 1 | -4/+1 | |
| | | | | | | | | | | | | | | | | This also removes the TODO that was addressed by adding the kist params to this type. | |||||
| | * | | tor-chanmgr: Move KIST and padding params to ChannelParams. | Gabriela Moldovan | 2025-01-15 | 1 | -11/+22 | |
| | | | | ||||||
| | * | | tor-proto: Remove dependency on tor-netdir. | Gabriela Moldovan | 2025-01-15 | 6 | -50/+51 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | This moves the `NetParameters -> KistParams` conversion to `tor-chanmgr`. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2706#note_3147557 | |||||
| | * | | tor-chanmgr: Add a TODO about a possible renaming. | Gabriela Moldovan | 2025-01-15 | 1 | -0/+3 | |
| | | | | ||||||
| | * | | tor-proto: Replace constants with caret_int. | Gabriela Moldovan | 2025-01-15 | 3 | -3/+16 | |
| | | | | ||||||
| | * | | tor-rtcompat: Rename UnsupportedStreamOps to NoOpStreamOpsHandle (fmt). | Gabriela Moldovan | 2025-01-15 | 3 | -5/+5 | |
| | | | | ||||||
| | * | | tor-rtcompat: Rename UnsupportedStreamOps to NoOpStreamOpsHandle. | Gabriela Moldovan | 2025-01-15 | 5 | -9/+9 | |
| | | | | | | | | | | | | | | | | This renames UnsupportedStreamOpsHandle to NoOpStreamOpsHandle for clarity (the old name kind of sounded like the name of an error type). | |||||
| | * | | tor-async-utils: Fix type inference in test. | Gabriela Moldovan | 2025-01-15 | 1 | -1/+2 | |
| | | | | ||||||
| | * | | tor-changmgr: Update the KIST params whenever the consensus/config changes. | Gabriela Moldovan | 2025-01-15 | 1 | -8/+34 | |
| | | | | | | | | | | | | | Closes #1730, #1728 | |||||
| | * | | tor-chanmgr: Add reparameterize_kist to AbstractChannel trait. | Gabriela Moldovan | 2025-01-15 | 5 | -0/+22 | |
| | | | | | | | | | | | | | | | | Needed for the chanmgr to be able to update existing channels with new KIST settings read from the consensus. | |||||
| | * | | tor-proto: Set kist params in channel reactor. | Gabriela Moldovan | 2025-01-15 | 2 | -2/+33 | |
| | | | | ||||||
| | * | | tor-proto: Add Channel::reparameterize_kist() API. | Gabriela Moldovan | 2025-01-15 | 1 | -0/+9 | |
| | | | | | | | | | | | | | | | | This will enable us to update the channel's KIST configuration whenever there is a change in the consensus or config. | |||||
| | * | | tor-proto: Add CtrlMsg for setting kist options (fmt). | Gabriela Moldovan | 2025-01-15 | 1 | -1/+3 | |
| | | | | ||||||
| | * | | tor-proto: Add CtrlMsg for setting kist options. | Gabriela Moldovan | 2025-01-15 | 1 | -1/+8 | |
| | | | | ||||||
| | * | | tor-rtcompat: Fix doc warning. | Gabriela Moldovan | 2025-01-15 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-proto: Pass a StreamOps handle to the channel reactor. | Gabriela Moldovan | 2025-01-15 | 3 | -2/+16 | |
| | | | | ||||||
| | * | | tor-rtcompat: Big invasive change adding StreamOps bound everywhere. | Gabriela Moldovan | 2025-01-15 | 11 | -21/+34 | |
| | | | | | | | | | | | | | | | | | | | This is unfortunately necessary, because after the channel handshake, we need to give the channel reactor a `StreamOps` handle to the underlying stream. | |||||
| | * | | tor-rtcompat: Implement StreamOps for TLS stream types. | Gabriela Moldovan | 2025-01-15 | 2 | -1/+22 | |
| | | | | ||||||
| | * | | tor-rtmock: Implement StreamOps for MockTlsStream (fmt). | Gabriela Moldovan | 2025-01-15 | 1 | -1/+3 | |
| | | | | ||||||
| | * | | tor-rtmock: Implement StreamOps for MockTlsStream. | Gabriela Moldovan | 2025-01-15 | 1 | -1/+14 | |
| | | | | | | | | | | | | | | | | We're about to add a trait bound that forces `MockTlsStream` to impl `StreamOps`. | |||||
