| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
I have thought about this and come to the conclusion (which is what I
suspected when I wrote it) that the current behaviour is correct.
The attack described is completely impractical (the space of nonces is
very large), and checking whether a nonce is a replay is cheaper than
verifying a PoW solve, so we want to do that first.
Splitting this into something like the following:
* Check replay log without updating
* Check that solve is valid
* Update replay log
Would require adding a somewhat dangerous API to the ReplayLog, and
requires doing more work per request for something that isn't even a
practical attack, AFAICT.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
We restored the seeds, but doing so is counterproductive if we don't
also recreate the verifiers needed to check solves for those seeds.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This does not currently allow this option to be changed at runtime,
although the code is structured so that allowing it to be changed at
runtime won't be too hard. This is tracked by #2082.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
MockExecutor now supports the features needed for this test to work.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This disentangles the ReplyLog from the IptManager.
This will allow us to make the InternalPowError type more public (in
order to use it in the OnionServiceStatus code) without also having to
make the CreateIptError type more public.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
New netdoc parser, with derive macro
See merge request tpo/core/arti!3135
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
We parse and verify some network documents from testdata2.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This can parse and validate the signatures on a consensus.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This isn't used anywhere yet. We're going to demonstrate it, and test
the demo, in a moment.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
testresult is a new dependency for arti.git. (It's being added as a
test-dependenchy here.) It is has a very useful Result type for use
in test cases.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is a fine API. The representation may change, but that wouldn't
be breaking.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
We won't want them ever to be anything other than a wrapper around
`RsaIdentity`, so we can make them transparent.
Derive various useful traits, including Deref.
Expose them publicly, since there's no reason not to do so. (The new
parser will want to reuse them. It's in-crate, but out-of-crate users
may want to use these too for other netdoc types.)
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Revert "tor-llcrypto: implement Hash for RsaPublicKey"
This reverts commit 5df5ed8c4be5376a7288f1332541d9bff29a08f5.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
The new parser is going to reuse this.
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | | |
|
| | |/ / / / /
| | | | | |
| | | | | |
| | | | | | |
Plan to gradually move over to this semiautomatically-maintained data.
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
Make a checklist out of Release.md
See merge request tpo/core/arti!3125
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3125#note_3235240
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This might avoid some comedy.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This will perhaps avoid them being accidentally skipped.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
It's longer than the scrollback in my terminals!
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
IME this tends make the breaking change updates easier to understand.
by having them producing less noise in Cargo.lock.
|
| | | | | | | |
|
| | | | | | | |
|
| |/ / / / / |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
proto: Consolidate all send_unbounded() calls in send_msg().
See merge request tpo/core/arti!3154
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This replaces a `send_unbounded()` call with `send_msg()`. Now
`send_msg()` is the only place where we call `send_unbounded()` in the
tunnel reactor, which makes it a bit easier to see which callsites have
the potential to cause buffering in the channel sink.
Prompted by #2112
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-rtmock: Slightly clean up CrateGetters macro
See merge request tpo/core/arti!3150
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
I want to use this as an example in a talk.
Add a blank line that makes it more readable, and generate only one
impl block with many methods.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-cell: Fix comment in `ChannelCodec::encode`
See merge request tpo/core/arti!3155
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This comment isn't correct if the encode() was given a non-empty buffer
(for example if two cells were written to the same buffer, the second
encode() would be given a non-empty buffer, so `pos != 5`).
|
| |\| | | | |
| |_|_|/ /
|/| | | |
| | | | |
| | | | | |
Update slab dependency to fix cargo audit
See merge request tpo/core/arti!3151
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Avoids
https://rustsec.org/advisories/RUSTSEC-2025-0047
I have considered whether this needs a TROVE. I think not.
We don't call the unsound method at all directly within arti.git.
As for our dependencies: I (with some flailing) managed to patch the
whole build to use a modified version of slab with the unsound method
sabotaged. This was successful. So I think nothing in our whole tree
uses it.
(I also verified that my sabotage arrangements were effective:
applying `#![cfg(any())]` at the top of slab's lib.rs did break the
build of hs.)
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
CI: tweaks to make chutney network bootstrap less noisy
See merge request tpo/core/arti!3149
|