summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * tor-keymgr: Add cert parse error variant.Gabriela Moldovan2025-01-135-2/+22
| | | | | | | | | | | | | | This will soon be used, when we modify the `ArtiNativeKeystore` cert lookup code to actually parse certificates before returning them. Part of #1768
| * tor-key-forge: Add ItemType impl for KeyUnknownCert.Gabriela Moldovan2025-01-131-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `KeyUnknownCert` will soon be used as the `ToEncodableCert::ParsedCert` type for Tor ed25519 certs. For example, the `ToEncodableCert` impl for `RelaySigningKeyCert` will look like this: ```rust pub struct RelaySigningKeyCert(EncodedEd25519Cert); impl ToEncodableCert<RelaySigningKeypair> for RelaySigningKeyCert { type ParsedCert = KeyUnknownCert; type EncodableCert = EncodedEd25519Cert; type SigningKey = RelayIdentityKeypair; fn validate( cert: Self::ParsedCert, subject: &RelaySigningKeypair, signed_with: &Self::SigningKey, ) -> Result<Self, InvalidCertError> { // TODO: validate `KeyUnknownCert` // and convert it to an EncodedEd25519Cert // (we don't yet an easy way to perform this conversion) } fn to_encodable_cert(self) -> Self::EncodableCert { self.0 } } ```
| * tor-key-forge: Split out ItemType as a separate trait.Gabriela Moldovan2025-01-137-28/+57
| | | | | | | | | | | | | | | | This is necessary because `ParsedCert`s will not be `EncodableItem`s. This is because we cannot (and don't want to) write certificates that have not yet been validated to the keystore. They do need to be retrievable from the keystore though, so we also change `ErasedKey` to be `Box<dyn ItemType>` instead.
| * tor-key-forge: Distinguish between parsed certs and encodable certs.Gabriela Moldovan2025-01-132-12/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need two different types to represent * certs that have been parsed, but not yet validated (`KeyUnknownCert`) * newly generated encodable certs (`EncodedEd25519Cert`) Currently, we don't use `KeyUnknownCert` anywhere, and instead use `EncodedEd25519Cert` to represent "parsed" but not-yet-validated certs. This approach is wrong and relies on a broken (no-op) `EncodedEd25519Cert::from_bytes` implementation. A future commit will address this problem by replacing `EncodedEd25519Cert::from_bytes` with `Ed25519Cert::decode` to actually parse the cert upon retrieving it from the keystore.
| * tor-keymgr: Replace from_encodable_cert with validation function.Gabriela Moldovan2025-01-132-22/+7
| | | | | | | | | | | | | | | | In practice, we won't be able to obtain an `ToEncodableCert` type from an `EncodableItem` cert without validating it first, so we need to collapse `validate` into `from_encodable_cert`. Part of #1768
| * tor-key-forge: Export some additional tor-cert types.Gabriela Moldovan2025-01-131-3/+3
|/ | | | This will soon be used.
* Merge branch 'relay-bin-3' into 'main'opara2025-01-137-149/+465
|\ | | | | | | | | arti-relay: improve cli and add config loading See merge request tpo/core/arti!2699
| * arti-relay: don't use environment var in `Mistrust`Steven Engler2025-01-132-26/+4
| |
| * arti-relay: remove `TorRelayConfigBuilder::from_directories`Steven Engler2025-01-131-27/+0
| | | | | | | | | | I don't think we'll ever need this. Users will set the directories through the config file.
| * arti-relay: add basic placeholder loggerSteven Engler2025-01-131-4/+61
| | | | | | | | | | This is probably not what the final logger would look like, but it's a fine placeholder for now.
| * arti-relay: add config loadingSteven Engler2025-01-132-13/+47
| |
| * arti-relay: make `main` a wrapper around a `main_main`Steven Engler2025-01-133-1/+16
| | | | | | | | This makes it more similar to arti.
| * arti-relay: add `LoggingConfig`Steven Engler2025-01-133-0/+42
| |
| * arti-relay: rework default config file path handlingSteven Engler2025-01-131-15/+91
| |
| * arti-relay: add constant `ARTI_FS_DISABLE_PERMISSION_CHECKS`Steven Engler2025-01-131-0/+24
| | | | | | | | We don't actually use it yet, but we do show it in the '--help' text.
| * arti-relay: `TorRelay` takes a `CfgPathResolver`Steven Engler2025-01-132-8/+20
| |
| * arti-relay: remove relay builderSteven Engler2025-01-133-71/+8
| | | | | | | | | | | | | | This is a bunch of boilerplate code that we don't currently need, and may not need in the future since we don't need to provide a lot of library-API-level customization for `TorRelay` like we do with `TorClient`.
| * arti-relay: default config paths now use path resolverSteven Engler2025-01-133-12/+21
| |
| * arti-relay: added a base `CfgPathResolver`Steven Engler2025-01-133-5/+126
| |
| * arti-relay: impl `TopLevel` for `TorRelayConfig`Steven Engler2025-01-131-0/+4
| |
| * arti-relay: added `From<LogLevel> for tracing::metadata::Level`Steven Engler2025-01-131-1/+13
| |
| * arti-relay: make cli `log_level` an `Option`Steven Engler2025-01-131-4/+3
| | | | | | | | This is an override option, which we want to default to "unset".
| * arti-relay: test that global cli options have "global" setSteven Engler2025-01-131-1/+16
| |
| * arti-relay: moved global cli options to common structSteven Engler2025-01-131-16/+24
|/
* Merge branch 'recent_rust_ver_1.83' into 'main'Nick Mathewson2025-01-131-1/+1
|\ | | | | | | | | CI: Update RECENT_RUST_IMAGE to 1.83. See merge request tpo/core/arti!2694
| * CI: Update RECENT_RUST_IMAGE to 1.83.Nick Mathewson2025-01-071-1/+1
| |
* | Merge branch 'rpc-banner' into 'main'Nick Mathewson2025-01-097-9/+81
|\ \ | | | | | | | | | | | | | | | | | | RPC spec: specify banner format. Closes #1753 See merge request tpo/core/arti!2700
| * | Implement banner for RPC protocol.Nick Mathewson2025-01-095-8/+53
| | | | | | | | | | | | Closes #1753
| * | RPC spec: specify banner format.Nick Mathewson2025-01-092-1/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | See #1753. This banner message will give the client a clear signal that the server is ready, so that the client will know that it can read files (such as a cookie file) written by the server. (We can't use "is the port bound" as a way to signal that the server is ready, since the server needs to bind the port in order to determine that there isn't another server running... which it needs to do before it can write an rpc cookie file.)
* | | Merge branch 'fix-endless-reload-config' into 'main'gabi-2502025-01-091-6/+38
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-config: Make the `FileWatcher` ignore non-mutating file events. Closes #1794 See merge request tpo/core/arti!2696
| * | | tor-config: Test that uninteresting events get ignored.Gabriela Moldovan2025-01-091-3/+21
| | | |
| * | | tor-config: Rewrite match for readability.Gabriela Moldovan2025-01-091-3/+5
| | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2696#note_3145971
| * | | tor-config: Avoid using EventKind::Any in the tests.Gabriela Moldovan2025-01-091-3/+4
| | | | | | | | | | | | | | | | Events of type `Any` now get discarded by the event handler.
| * | | tor-config: Handle rescan events before filtering.Gabriela Moldovan2025-01-091-3/+2
| | | | | | | | | | | | | | | | | | | | This enables us to catch "rescan" events, regardless of their underlying `EventKind`.
| * | | tor-config: Make the `FileWatcher` ignore non-mutating file events.Gabriela Moldovan2025-01-091-1/+13
|/ / / | | | | | | | | | | | | | | | | | | | | | Without this, setting `watch_configuration = true` results in endless config reloading due to arti accessing the config (which triggers an access event, which in turn, triggers a config reload, and so on). Closes #1794
* | | Merge branch 'chanmgr-dos' into 'main'opara2025-01-092-23/+80
|\ \ \ | | | | | | | | | | | | | | | | tor-proto: Make `Channel::wait_for_close` non-experimental See merge request tpo/core/arti!2666
| * | | tor-proto: fix bad indentationSteven Engler2025-01-091-3/+3
| | | |
| * | | tor-proto: test `Channel::wait_for_close`Steven Engler2025-01-091-5/+35
| | | |
| * | | tor-proto: make `Channel::wait_for_close` non-experimentalSteven Engler2025-01-091-1/+0
| | | |
| * | | tor-proto: `Channel::wait_for_close` return success statusSteven Engler2025-01-092-14/+42
| |/ / | | | | | | | | | | | | | | | This had a TODO about returning a "status indication instead of just ()" so this commit adds some status indication that we can expand later if needed.
* | | Merge branch 'audit_less' into 'main'Ian Jackson2025-01-091-9/+10
|\ \ \ | |/ / |/| | | | | | | | | | | | | | Un-ignore RUSTSEC-2024-0421 Closes #1773 See merge request tpo/core/arti!2693
| * | Un-ignore RUSTSEC-2024-0421Nick Mathewson2025-01-071-9/+10
| |/ | | | | | | We no longer require a version of hickory that requires an affected idns.
* | Merge branch 'trace-circuit-timeout' into 'main'opara2025-01-081-0/+2
|\ \ | | | | | | | | | | | | tor-circmgr: Add trace log on circuit build timeout. See merge request tpo/core/arti!2698
| * | tor-circmgr: Add trace log on circuit build timeout.Wesley Aptekar-Cassels2025-01-081-0/+2
|/ / | | | | | | This may help debugging #1792.
* | Merge branch 'tor-rtcompat-spawn-blocking' into 'main'wesleyac2025-01-079-5/+143
|\ \ | | | | | | | | | | | | tor-rtcompat: Add spawn_blocking to Runtime trait. See merge request tpo/core/arti!2678
| * | tor-rtcompat: Note that SpawnBlocking isn't for CPU-bound tasks.Wesley Aptekar-Cassels2025-01-071-1/+1
| | |
| * | tor-rtcompat: Use GAT instead of RPIT in SpawnBlocking trait.Wesley Aptekar-Cassels2025-01-077-9/+25
| | | | | | | | | | | | Due to the limitations on RPIT, it's better to use a GAT for now.
| * | tor-rtcompat: Add note about what to use spawn_blocking for.Wesley Aptekar-Cassels2025-01-071-1/+5
| | |
| * | tor-rtcompat: Note SpawnBlocking semver break.Wesley Aptekar-Cassels2025-01-071-0/+1
| | |
| * | tor-rtmock: Add task names for spawn_obj and spawn_blocking.Wesley Aptekar-Cassels2025-01-071-2/+2
| | |