summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | tor-hsservice: Remove outdated TODO.Wesley Aptekar-Cassels2025-08-131-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I have thought about this and come to the conclusion (which is what I suspected when I wrote it) that the current behaviour is correct. The attack described is completely impractical (the space of nonces is very large), and checking whether a nonce is a replay is cheaper than verifying a PoW solve, so we want to do that first. Splitting this into something like the following: * Check replay log without updating * Check that solve is valid * Update replay log Would require adding a somewhat dangerous API to the ReplayLog, and requires doing more work per request for something that isn't even a practical attack, AFAICT.
| * | | | | tor-hsservice: Add note about not persisting per-PoW-period state.Wesley Aptekar-Cassels2025-08-131-1/+7
| | | | | |
| * | | | | tor-hsservice: Add metrics support to PoW code.Wesley Aptekar-Cassels2025-08-134-3/+61
| | | | | |
| * | | | | tor-hsservice: Restore PoW verifier state from disk.Wesley Aptekar-Cassels2025-08-131-2/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We restored the seeds, but doing so is counterproductive if we don't also recreate the verifiers needed to check solves for those seeds.
| * | | | | tor-hsservice: Add pow_rend_queue_depth config option.Wesley Aptekar-Cassels2025-08-133-35/+118
| | | | | |
| * | | | | tor-hsservice: Pass Rng into PoW code where possible.Wesley Aptekar-Cassels2025-08-132-10/+11
| | | | | |
| * | | | | tor-hsservice: Implement enable_pow option.Wesley Aptekar-Cassels2025-08-136-61/+139
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This does not currently allow this option to be changed at runtime, although the code is structured so that allowing it to be changed at runtime won't be too hard. This is tracked by #2082.
| * | | | | tor-hsservice: Reenable publisher test in hs-pow-full.Wesley Aptekar-Cassels2025-08-132-12/+3
| | | | | | | | | | | | | | | | | | | | | | | | MockExecutor now supports the features needed for this test to work.
| * | | | | tor-hsservice: Add PowManager to OnionServiceStatus.Wesley Aptekar-Cassels2025-08-137-35/+130
| | | | | |
| * | | | | tor-hsservice: Change ReplayLog error type.Wesley Aptekar-Cassels2025-08-135-17/+21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This disentangles the ReplyLog from the IptManager. This will allow us to make the InternalPowError type more public (in order to use it in the OnionServiceStatus code) without also having to make the CreateIptError type more public.
* | | | | | Merge branch 'netdoc2' into 'main'Ian Jackson2025-08-1466-258/+6794
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | New netdoc parser, with derive macro See merge request tpo/core/arti!3135
| * | | | | | tor-netdoc: Rerun cargo fmt after rebaseIan Jackson2025-08-142-3/+3
| | | | | | |
| * | | | | | tor-netdoc: parse2: Fix typo in "Naming conventions" docIan Jackson2025-08-141-1/+1
| | | | | | |
| * | | | | | tgr-netdoc: Tests of parse2Ian Jackson2025-08-142-0/+93
| | | | | | | | | | | | | | | | | | | | | | | | | | | | We parse and verify some network documents from testdata2.
| * | | | | | tor-netdoc: Proof-of-concept demo of new parserIan Jackson2025-08-146-0/+861
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This can parse and validate the signatures on a consensus.
| * | | | | | tor-netdoc: Introduce parse2, new parserIan Jackson2025-08-1414-0/+2304
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This isn't used anywhere yet. We're going to demonstrate it, and test the demo, in a moment.
| * | | | | | tor-netdoc: Add dependencies: derive-deftly, paste, strum, testresultIan Jackson2025-08-142-0/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | testresult is a new dependency for arti.git. (It's being added as a test-dependenchy here.) It is has a very useful Result type for use in test cases.
| * | | | | | tor-netdoc: Always expose NicknameIan Jackson2025-08-143-8/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a fine API. The representation may change, but that wouldn't be breaking.
| * | | | | | tor-netdoc: Improve and expose Fingerprint parsing adaptersIan Jackson2025-08-142-4/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We won't want them ever to be anything other than a wrapper around `RsaIdentity`, so we can make them transparent. Derive various useful traits, including Deref. Expose them publicly, since there's no reason not to do so. (The new parser will want to reuse them. It's in-crate, but out-of-crate users may want to use these too for other netdoc types.)
| * | | | | | tor-llcrypto: implement Hash for RsaPublicKeyIan Jackson2025-08-140-0/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Revert "tor-llcrypto: implement Hash for RsaPublicKey" This reverts commit 5df5ed8c4be5376a7288f1332541d9bff29a08f5.
| * | | | | | tor-netdoc: Expose base64_decode_multiline to crateIan Jackson2025-08-141-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | The new parser is going to reuse this.
| * | | | | | tor-netdoc: sort the experimental cargo featuresIan Jackson2025-08-141-2/+2
| | | | | | |
| * | | | | | netdoc test data: Switch two tests to new consensus dataIan Jackson2025-08-143-243/+3
| | | | | | |
| * | | | | | netdoc test data: refresh (for first time) by running scriptIan Jackson2025-08-1435-0/+3393
| | | | | | |
| * | | | | | netdoc test data: Provide script for downloading from CIIan Jackson2025-08-143-0/+97
| |/ / / / / | | | | | | | | | | | | | | | | | | Plan to gradually move over to this semiautomatically-maintained data.
* | | | | | Merge branch 'release-checklist' into 'main'Ian Jackson2025-08-142-39/+142
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | Make a checklist out of Release.md See merge request tpo/core/arti!3125
| * | | | | maint/release-prep-ticket-template: Explain single-line behaviourIan Jackson2025-08-141-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3125#note_3235240
| * | | | | maint/release-prep-ticket-template: never print partial outputIan Jackson2025-08-141-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | This might avoid some comedy.
| * | | | | maint/release-prep-ticket-template: trip on tickybox with too many spacesIan Jackson2025-08-141-1/+1
| | | | | |
| * | | | | Release.md: fix a tickyboxIan Jackson2025-08-141-2/+3
| | | | | |
| * | | | | Release.md: Say that the final CI pass should be on `main`Ian Jackson2025-08-141-1/+1
| | | | | |
| * | | | | Release.md: Say to improve the processesIan Jackson2025-08-141-0/+5
| | | | | |
| * | | | | Release.md: Renumber the "do release" sectionIan Jackson2025-08-141-5/+5
| | | | | |
| * | | | | Release.md: Move reopening the tree into Post-ReleaseIan Jackson2025-08-141-2/+2
| | | | | |
| * | | | | Release.md: Move final pre-release checks into the "do release" sectionIan Jackson2025-08-141-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | This will perhaps avoid them being accidentally skipped.
| * | | | | Release.md: say to tee the output of cargo-semver-checksIan Jackson2025-08-141-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | It's longer than the scrollback in my terminals!
| * | | | | Release.md: Say to do non-breaking update firstIan Jackson2025-08-141-12/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | IME this tends make the breaking change updates easier to understand. by having them producing less noise in Cargo.lock.
| * | | | | Release.md: Say to recheck blockers before releasing!Ian Jackson2025-08-141-0/+2
| | | | | |
| * | | | | Release.md: Add tickyboxesIan Jackson2025-08-141-27/+34
| | | | | |
| * | | | | maint/release-prep-ticket-template: script for making checklistIan Jackson2025-08-142-0/+84
|/ / / / /
* | | | | Merge branch 'send-unbounded' into 'main'gabi-2502025-08-131-2/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | proto: Consolidate all send_unbounded() calls in send_msg(). See merge request tpo/core/arti!3154
| * | | | | proto: Consolidate all send_unbounded() calls in send_msg().Gabriela Moldovan2025-08-131-2/+1
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This replaces a `send_unbounded()` call with `send_msg()`. Now `send_msg()` is the only place where we call `send_unbounded()` in the tunnel reactor, which makes it a bit easier to see which callsites have the potential to cause buffering in the channel sink. Prompted by #2112
* | | | | Merge branch 'mock-time-core-tidy' into 'main'Ian Jackson2025-08-131-6/+7
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-rtmock: Slightly clean up CrateGetters macro See merge request tpo/core/arti!3150
| * | | | | tor-rtmock: MockTimeCore: fix docsIan Jackson2025-08-121-2/+2
| | | | | |
| * | | | | tor-rtmock: Slightly clean up CrateGetters macroIan Jackson2025-08-121-4/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I want to use this as an example in a talk. Add a blank line that makes it more readable, and generate only one impl block with many methods.
* | | | | | Merge branch 'remove-comment' into 'main'David Goulet2025-08-121-1/+3
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-cell: Fix comment in `ChannelCodec::encode` See merge request tpo/core/arti!3155
| * | | | | | tor-cell: fix comment in `ChannelCodec::encode`Steven Engler2025-08-121-1/+3
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This comment isn't correct if the encode() was given a non-empty buffer (for example if two cells were written to the same buffer, the second encode() would be given a non-empty buffer, so `pos != 5`).
* | | | / / Merge branch 'slab' into 'main'Ian Jackson2025-08-121-2/+2
|\| | | | | | |_|_|/ / |/| | | | | | | | | | | | | | Update slab dependency to fix cargo audit See merge request tpo/core/arti!3151
| * | | | Update slab dependency to fix cargo auditIan Jackson2025-08-121-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Avoids https://rustsec.org/advisories/RUSTSEC-2025-0047 I have considered whether this needs a TROVE. I think not. We don't call the unsound method at all directly within arti.git. As for our dependencies: I (with some flailing) managed to patch the whole build to use a modified version of slab with the unsound method sabotaged. This was successful. So I think nothing in our whole tree uses it. (I also verified that my sabotage arrangements were effective: applying `#![cfg(any())]` at the top of slab's lib.rs did break the build of hs.)
* | | | | Merge branch 'chutney-multi-phase' into 'main'Jim Newsome2025-08-124-13/+31
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | CI: tweaks to make chutney network bootstrap less noisy See merge request tpo/core/arti!3149