summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | rpclib: Avoid overuse of execute_internal_ok.Nick Mathewson2025-01-234-24/+60
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The execute_internal_ok method converts every error response into an internal error; as such, it's only appropriate when there is no way for a well-behaved Arti instance to give an error response. But we had been using it in a few places where errors were possible under other circumstances. This commit fixes that behavior, and adds documentation to help avoid it.
* | | Merge branch 'rpc-todos-1' into 'main'Nick Mathewson2025-01-232-20/+3
|\ \ \ | | | | | | | | | | | | | | | | rpc: Resolve a couple of dead code TODOs See merge request tpo/core/arti!2731
| * | | rpcserver: remove dead code exception in objmap.rsNick Mathewson2025-01-221-3/+1
| | | |
| * | | rpcserver: remove dead code in codecs.rsNick Mathewson2025-01-221-17/+2
| | | |
* | | | Merge branch 'rpc-todos-2' into 'main'Nick Mathewson2025-01-236-44/+47
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | Fix several 'TODO RPC' notes in the arti crate. See merge request tpo/core/arti!2737
| * | | arti: Make Rpc argument unconditional when constructing socks proxyNick Mathewson2025-01-236-33/+43
| | | | | | | | | | | | | | | | | | | | | | | | Formerly this was a conditional method argument, which is a huge antipattern. Now it is unconditionally present, as `Option<T>` for a type that is uninhabited when RPC isn't supported.
| * | | arti::socks: Re-wrap a section.Nick Mathewson2025-01-231-2/+3
| | | | | | | | | | | | | | | | | | | | rust-analyzer keeps re-wrapping this piece for me, even though rustfmt doesn't complain.
| * | | arti: remove an obsolete rpc todo.Nick Mathewson2025-01-231-1/+0
| | | | | | | | | | | | | | | | Information _is_ passed to the RpcMgr, via the argument to new_connection.
| * | | arti: remove an obsolete rpc todo.Nick Mathewson2025-01-231-1/+0
| | | | | | | | | | | | | | | | | | | | The RpcMgr does indirectly hold a reference to the client, via its make_session argument.
| * | | arti: remove an obsolete rpc todo.Nick Mathewson2025-01-231-1/+0
| | | | | | | | | | | | | | | | We _do_ have error detection from this function, and have for ages.
| * | | arti: Remove old workaround for runtime selection under RPC.Nick Mathewson2025-01-231-6/+1
|/ / / | | | | | | | | | | | | This was necessary before we had support for implementing RPC methods on generic types.
* | | Merge branch 'dev/cve/mistrust-doc' into 'main'Nick Mathewson2025-01-231-0/+12
|\ \ \ | | | | | | | | | | | | | | | | tor-config: Improve mistrust documentation See merge request tpo/core/arti!2727
| * | | tor-config: Improve mistrust documentationClara Engler2025-01-231-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit improves the documentation for `ConfigurationSources::set_mistrust`, by explaining that this option is unrelated to the paths defined within the configuration file itself, referring to the `storage.permissions.dangerously_trust_everyone` option.
* | | | Merge branch 'fix-rpc-client-core' into 'main'Nick Mathewson2025-01-231-2/+2
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti-rpc-client-core: Use EmptyReply instead of EmptyResponse. See merge request tpo/core/arti!2732
| * | | | arti-rpc-client-core: Use EmptyReply instead of EmptyResponse.Gabriela Moldovan2025-01-231-2/+2
|/ / / / | | | | | | | | | | | | | | | | | | | | It looks like !2729 and !2722 raced with each other, because we're still using the old name for `EmptyReply` (and so `arti-rpc-client-core` doesn't currently compile on `main`).
* | | | Merge branch 'rpc-cancel-2' into 'main'Nick Mathewson2025-01-2316-51/+503
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | rpc: Implement request cancellation Closes #818 See merge request tpo/core/arti!2722
| * | | Document more that cancel is uncancellable.Nick Mathewson2025-01-222-0/+7
| | | |
| * | | rpc: Correct RPC error code for "RequestNotFound".Nick Mathewson2025-01-222-2/+5
| | | |
| * | | rpc-meta-draft: Make rpc:cancel more permissive on ID collision.Nick Mathewson2025-01-221-1/+2
| | | |
| * | | cancel: Distinguish the internal-error case for double-cancel.Nick Mathewson2025-01-221-2/+23
| | | |
| * | | cancel: Document deadlock/panic issue and how to avoid it.Nick Mathewson2025-01-221-2/+19
| | | |
| * | | rpc: Make cancel requests uncancellable.Nick Mathewson2025-01-224-28/+94
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The current cancel code is prone to deadlock, so the easiest way to solve it appears to be making cancel requests themselves uncancellable. I've included a test to verify the behavior; previously, this test caused a deadlock.
| * | | cancel: Add a TODO about moving the Future inside the lock.Nick Mathewson2025-01-221-0/+5
| | | |
| * | | Cancel: Drop lock before calling waker.Nick Mathewson2025-01-221-0/+1
| | | |
| * | | cancel: Remove FusedFuture implementation.Nick Mathewson2025-01-221-12/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Nothing used it, and it has some semantic complexity. (see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2722#note_3149591 )
| * | | cancel: Use Waker::clone_from to avoid needless clones.Nick Mathewson2025-01-221-1/+9
| | | | | | | | | | | | | | | | | | | | | | | | The Waker::clone_from implementation uses Waker::will_wake to avoid unnecessarily cloning a Waker that it already has a copy of.
| * | | rpc: Python Integration tests for cancelling requests.Nick Mathewson2025-01-222-0/+34
| | | |
| * | | python rpc: Add support for cancelling requests.Nick Mathewson2025-01-222-2/+30
| | | |
| * | | arti-rpc-client-core: Document that dropping a request does not cancel it.Nick Mathewson2025-01-223-6/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | I hope that this limitation is acceptable; the alternative involves some significant refactoring to give Request a Weak reference to RpcConn -- but RpcConn isn't currently kept in an Arc<> at all, and so we'd need some fairly heavy hacking.
| * | | arti-rpc-client-core: Implement and expose cancellation.Nick Mathewson2025-01-224-3/+65
| | | |
| * | | python rpc: Document with_meta arguments.Nick Mathewson2025-01-221-0/+3
| | | |
| * | | python rpc: Expose an ArtiRpcObject for the "connection" object.Nick Mathewson2025-01-222-0/+12
| | | |
| * | | rpc: Implement the rpc:cancel command.Nick Mathewson2025-01-162-1/+79
| | | |
| * | | rpc: Document how cancel interacts with RequestId collision.Nick Mathewson2025-01-161-0/+6
| | | |
| * | | rpc: Better RpcErrorKind for for RequestCancelled.Nick Mathewson2025-01-161-4/+7
| | | |
| * | | rpc: Strengthen guarantees from Cancel.Nick Mathewson2025-01-163-20/+126
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Cancellation is now fallable, which allows us to detect attempts to cancel which cannot work. We now guarantee that when you try to cancel a `Cancel<F>` future, either the cancel operation will succeed, or the future will return (or will have already returned) Ok(), but not both, and not neither. Closes #818.
* | | | Merge branch 'rpc-request-response-naming' into 'main'Nick Mathewson2025-01-214-29/+28
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | rpclib: Rename params/reply structs for consistency. Closes #1586 See merge request tpo/core/arti!2729
| * | | rpclib: Rename params/reply structs for consistency.Nick Mathewson2025-01-214-29/+28
|/ / / | | | | | | | | | | | | | | | | | | | | | Our now convention here in rpclib is that a struct holding a request's parameters is called `FooParams`, and a struct holding that request's reply is called `FooReply`. Closes #1586
* | | Merge branch 'mpl-insteructions' into 'main'Nick Mathewson2025-01-201-2/+13
|\ \ \ | | | | | | | | | | | | | | | | Better instructions for handling new MPL dependencies See merge request tpo/core/arti!2726
| * | | maint/check_licenses: Acknowledge that we don't handle ORIan Jackson2025-01-201-1/+1
| | | |
| * | | maint/check_licenses: Instructions for what to do about MPLIan Jackson2025-01-201-1/+12
|/ / /
* | | Merge branch 'update-pow-manager-draft' into 'main'wesleyac2025-01-161-28/+54
|\ \ \ | | | | | | | | | | | | | | | | Update `service-side-pow.md` See merge request tpo/core/arti!2701
| * | | tor-hsservice: Add more notes about publisher_update_tx.Wesley Aptekar-Cassels2025-01-161-1/+3
| | | |
| * | | tor-hsservice: Clarify PowManager publisher_update_tx.Wesley Aptekar-Cassels2025-01-161-0/+2
| | | |
| * | | tor-hsservice: Remove impl Clone for PowManager.Wesley Aptekar-Cassels2025-01-161-2/+0
| | | | | | | | | | | | | | | | Now that it's not in a Arc internally it shouldn't have this.
| * | | tor-hsservice: Update PowManager persistence plan.Wesley Aptekar-Cassels2025-01-161-7/+19
| | | |
| * | | tor-hsservice: Make PowManager not use internal Arc.Wesley Aptekar-Cassels2025-01-161-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Per review feedback: > We have discovered that as a general rule of thumb, it is a good idea > to expose the `Arc`. This has a number of advantages; for example, if a > caller wants a `Weak` for any reason, that's right there. The typical > pattern is for the constructor to return `Arc<Self>` and methods to take > `self: &Arc<Self>`.
| * | | tor-hsservice: Make PoW seed expiration be per-TP.Wesley Aptekar-Cassels2025-01-161-7/+6
| | | | | | | | | | | | | | | | | | | | | | | | This is something we wanted to do in general for security reasons, and ad I was implementing I discovered that it actually makes the code simpler, rather than more complicated.
| * | | tor-hsservice: Update notes about PowManager persistence.Wesley Aptekar-Cassels2025-01-161-1/+1
| | | |
| * | | tor-hsservice: Add KeyMgr and HsNickname to PowManager.Wesley Aptekar-Cassels2025-01-161-0/+6
| | | | | | | | | | | | | | | | | | | | These are needed to allow the PowManager to get the blinded ID needed to construct a PoW verifier.