| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | | | | |
|
| |\ \ \ \ \ \ \ \
| |_|_|/ / / / /
|/| | | | | | |
| | | | | | | |
| | | | | | | | |
proto: Allow AUTHORIZE and VPADDING before VERSIONS
See merge request tpo/core/arti!3174
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The AUTHORIZE cell command is simply reserved but not defined. The tor
specification, at this point in time, is allowing such cell before the
handshake starts but it is very unclear on what ordering is allowed nor
how many can are allowed.
C-tor silents drop them like VPADDING and so clearly unused. Instead of
dealing with it, simply remove its support but keeping its reserved
number.
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
When starting a handshake, we were only expecting a VERSIONS which is
not what the protocol say. An AUTHORIZE and VPADDING can arrive before a
VERSIONS.
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
First of all, VPADDING has been added in link protocol version 3 so it
was missing from v4.
Second, after closely looking at C-tor and the spec, it appears that we
allow VPADDING at any point on a channel which should simply be silently
dropped. Any number in any order.
Third, couple sets were missing the PADDING cell which is only allowed
on an open channel.
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \ \ \ \ \
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
hsservice: Move derive_more::From out of internal_prelude.
Closes #2124
See merge request tpo/core/arti!3169
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
This fixes an error from nightly. The trouble is that with nightly,
there's a now a [derive macro for From][issue]. That doesn't cause
a conflict when we `use derive_more::From`, but it _does_
cause a conflict when we import `derive_more::From` via
`use internal_prelude::*`.
So as a solution, we just import `derive_more::From` explicitly.
Closes #2124
[issue]: https://github.com/rust-lang/rust/pull/144922
|
| |\ \ \ \ \ \ \ \ \
| |_|/ / / / / / /
|/| | | | | | | |
| | | | | | | | |
| | | | | | | | | |
ci: drop dependency proxy experiment
See merge request tpo/core/arti!3175
|
| |/ / / / / / / /
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
the dependency proxy didn't work as well as we hoped
(tpo/tpa/team#42089) and it also fix all rate-limiting issues from
dockerhub since a lot of contributors were bypassing the proxy because
of insufficient credentials
from now on pulls from "docker.io" will go through a new pull-though
cache deployed by tpa, similar to what osuosl folks are using
successfully with their own ci runners
|
| |\ \ \ \ \ \ \ \
| |_|_|_|_|_|/ /
|/| | | | | | |
| | | | | | | |
| | | | | | | | |
smol: Implement smol in tor-rtcompat
See merge request tpo/core/arti!2986
|
| | | | | | | | | |
|
| |\ \ \ \ \ \ \ \
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
tor-proto: Simplify some match statements
See merge request tpo/core/arti!3173
|
| |/ / / / / / / / |
|
| |\ \ \ \ \ \ \ \
| |_|_|/ / / / /
|/| | | | | | |
| | | | | | | |
| | | | | | | | |
Refactor channel cell handling for channel authentication (v2)
See merge request tpo/core/arti!3158
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Use the specification terminology which is also the same for
ChannelType.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Use the ChannelFrame<> for the entirety of the outbound client handshake
that is the ClientInitiator channel type.
With this change, the codec.rs code is not needed anymore along its
CodecError as well which has been normalized onto the crate::Error
instead in order to simplify error handling and avoid duplication of
error types.
Unit tests have been modified to reflect this change of what can be done
with a channel frame. Also renamed to focus on client behavior.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This type and functions will be used in the handshake process in future
commits.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The handler.rs file contains a generic "ChannelCellHandler" which is
split into three different handler depending of the channel state (new,
handshaking or open).
These handlers implement Encoder/Decoder so we can give a
ChannelCellHandler to a asynchronous_codec::Framed along a TLS stream.
That cell handler is also in charge of tracking the CLOG/SLOG (see
tor-spec), running digest of cells seen, which is used to authenticate a
channel for the Relay <-> Relay case.
This ChannelCellHandler auto transitions as the setters function are
used. The handshake code will use this to advance the handler. Each
handler uses a MessageFilter from msg.rs in order to allow or not to
return the message.
A keen eye will notice that we can avoid encoding a message if we don't
need but we will decode all possible messages and only then allow it or
not.
The channel cell handler is not used at this commit.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This adds the code in msg.rs to be able to filter an inbound or outbound
message on a channel.
Each link protocol version implement a "is_allowed()" which is quite
verbose and tests each possibilities for human readability.
Then, we have several small struct/enum that are used to describe how a
message is filtered.
It is still unused at this commit.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
To be able to return a crate::Error from the Decoded/Encoder trait, it
needs to implement this conversion.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Add is_known_cmd() to the restricted_msg!() macro which can be used to
learn if a specific ChanCmd is part of the restricted set or not.
Then add a simple function to get the link protocol version from a
channel codec.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Add the msg.rs file containing all the allowed message sets based on the
channel type and direction. They are also namespaced by link protocol
version.
Unused at this commit. They will be used by the channel reactor along
the channel type and link protocol version in order to know if the
message is allowed or not. See is_allowed() helper function in this
commit.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The ChannelType indicates the type of channel in order to dictate which
message is allowed on it. The value use the Initiator and Responder
terminology from tor-spec documents.
At this commit, we only have client channel meaning the
"ClientInitiator" type.
In future commits, the channel type will be used by the channel reactor
to restrict which message is allowed or not.
Part of #1597
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| |/ / / / / / /
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is so a relay can build authenticated channels. Several keys/cert
are required for this that are within the key manager.
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
A few python CI fixes
See merge request tpo/core/arti!3168
|
| | | | | | | | | |
|
| | | |/ / / / /
| |/| | | | | |
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Document why we are using ring with rustls
See merge request tpo/core/arti!3170
|
| |/ / / / / / /
| | | | | | |
| | | | | | |
| | | | | | | |
See #1977, #2122.
|
| |\ \ \ \ \ \ \
| |/ / / / / /
|/| | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Add a few unit tests for create_unbootstrapped_async.
Closes #2121
See merge request tpo/core/arti!3167
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Closes #2121
Co-Authored-by: thesw4rm
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Use "plain" rather than "ns" for a full (unflavoured) consensus
See merge request tpo/core/arti!3164
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
ns-consensus doesn't seem to have ever been released.
This is part of abolishing the use of "ns" to mean "plain".
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is part of abolishing the use of "ns" to mean "plain".
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is part of abolishing the use of "ns" to mean "plain".
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is part of abolishing the use of "ns" to mean "plain".
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is part of abolishing the use of "ns" to mean "plain".
And edit a few docs lines.
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
tor-proto: Add comments about buffer sizes to `CC_XOFF_CLIENT`
See merge request tpo/core/arti!3156
|
| |/ / / / / / /
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This tries to explain that the amount of incoming data we choose to
buffer on an arti stream doesn't really matter for arti's socks proxy,
since the amount of data buffered by the kernel is significantly higher.
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
tor-error,arti: Support tracing fields in the `_report!` macros
Closes #2096 and #2116
See merge request tpo/core/arti!3142
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This is useful when you create an `internal!` error and then immediately
report it. If the `_report!` macro also requires a message, then you
need to provide two messages for the error, which doesn't always make
sense.
This is already possible anyways with `warn_report!(e,)`.
Now you don't need the comma.
|