summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | proto: Apply deferred rustfmt.Gabriela Moldovan2025-09-221-3/+1
| | | | | |
| * | | | | proto: Remove duplicate word in comment.Gabriela Moldovan2025-09-221-1/+1
| | | | | |
| * | | | | proto: Add new error type for cells received on non-existent streams.Gabriela Moldovan2025-09-224-11/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3267#note_3261239
| * | | | | proto: Log circuit reactor errors at debug level.Gabriela Moldovan2025-09-221-2/+2
| | | | | |
| * | | | | proto: Use the circuit build timeout instead of the abandon timeout.Gabriela Moldovan2025-09-221-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3267#note_3259820
| * | | | | proto: Reject any messages arriving on expired half-streams.Gabriela Moldovan2025-09-193-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Half-streams are periodically removed from each hop's stream map by the reactor main loop, but we still need to ensure we reject any messages arriving on expired half-streams in between these cleanup cycles.
| * | | | | proto: Add test to ensure half-streams are removed after a while.Gabriela Moldovan2025-09-191-0/+80
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This tests that the half-stream expiry works as expected. Note: it doesn't! This test currently fails, because there's a bug in the way half-streams are expired. Because we don't do it on a timer, and instead garbage-collect the half-streams on each reactor iteration, if the reactor is stuck long enough `.await`ing a message on one of its channels (for example, the `input` one), there is a chance it will accept a cell on a half-stream that should've been expired. A future commit will fix this bug.
| * | | | | proto: Calculate CBT more accurately.Gabriela Moldovan2025-09-192-4/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This should look at length of the circuit up until the hop where the half-stream is (because the half-stream might be on an intermediate hop, and not necessarily on the final one).
| * | | | | proto: Remove half-streams when they expire.Gabriela Moldovan2025-09-164-1/+33
| | | | | | | | | | | | | | | | | | | | | | | | Closes #264
| * | | | | circmgr: Pass the timeout estimator to circuit constructor (fmt).Gabriela Moldovan2025-09-163-11/+22
| | | | | |
| * | | | | circmgr: Pass the timeout estimator to circuit constructor.Gabriela Moldovan2025-09-164-14/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This enables us to read the CBT estimates from the circuit reactor (we need these to compute the half-stream timeouts for #264).
| * | | | | circmgr: Implement TimeoutEstimator for Estimator.Gabriela Moldovan2025-09-161-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will enable us to pass the timeout estimator to the circuit reactor in tor-proto.
| * | | | | proto: Use the CBT to compute half-stream timeouts.Gabriela Moldovan2025-09-166-9/+55
| | | | | |
| * | | | | proto: Give Each EndSentStreamEnt an expiry (fmt).Gabriela Moldovan2025-09-162-2/+8
| | | | | |
| * | | | | proto: Give Each EndSentStreamEnt an expiry.Gabriela Moldovan2025-09-164-8/+44
| | | | | |
| * | | | | proto: Remove unnecessary IEFE.Gabriela Moldovan2025-09-161-6/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The move of `self` into the closure was getting in the way, as I will need to reference `self` again below.
| * | | | | proto: Add an accessor for the max observed circ RTT.Gabriela Moldovan2025-09-161-0/+6
| | | | | | | | | | | | | | | | | | | | | | | | We will need this to calculate the END ack timeout.
| * | | | | proto: Expose RoundtripTimeEstimator more broadly.Gabriela Moldovan2025-09-161-3/+0
| | | | | | | | | | | | | | | | | | | | | | | | We need this to calculate the half-stream timeouts for #264.
* | | | | | Merge branch 'constant-time-eq' into 'main'Nick Mathewson2025-09-247-24/+172
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-llcrypto/tor-hscrypto: constant time PartialEq for tor-hscrypto types Closes #2021 See merge request tpo/core/arti!3268
| * | | | | | tor-hscrypto: derive_deftly is mandatory againhashcatHitman2025-09-232-4/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I don't know why this was breaking rust-recent-async-std-rustls, but oh well. Signed-off-by: hashcatHitman <[email protected]>
| * | | | | | tor-(hs|ll)crypto: export cteq macros correctlyhashcatHitman2025-09-236-76/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The macros to deftly derive `ConstantTimeEq` and `PartialEq` (for `ConstantTimeEq`) are now only defined in `tor-llcrypto` and exported. The macro to deftly derive `ConstantTimeEq` is now struct only and uses `subtle::Choice::from(1)` for improved clarity. Signed-off-by: hashcatHitman <[email protected]>
| * | | | | | tor-llcrypto: unconditionally use derive_deftlyhashcatHitman2025-09-232-5/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I didn't even realize I was still conditionally using it on a feature. That's what I get for always testing with all-features. Signed-off-by: hashcatHitman <[email protected]>
| * | | | | | tor-llcrypto: derive_deftly is mandatoryhashcatHitman2025-09-231-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I forgot to make derive_deftly a required dependency. Oops. Signed-off-by: hashcatHitman <[email protected]>
| * | | | | | tor-(hs|ll)crypto: deftly derive ConstantTimeEqhashcatHitman2025-09-236-297/+213
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is my initial attempt at deriving ConstantTimeEq and PartialEq. This includes the previously missed HsSvcNtorKeypair and HsClientDescEncKeypair types. In tor-llcrypto, a few implementations still had to be done by hand, and some types which previously derived normal PartialEq now derive it with ConstantTimeEq. I could not figure out how to properly set up the macros such that they could be used both in the current crate and in others, so for the moment they are duplicated. Just so I can get feedback. Ideally, this will be replaced with a better solution before merge. Signed-off-by: hashcatHitman <[email protected]>
| * | | | | | tor-hscrypto: constant time PartialEq for keyshashcatHitman2025-09-161-1/+282
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implemented `subtle::ConstantTimeEq` for all of the following types: - `pk::HsIdKey` - `pk::HsIdKeypair` - `pk::HsBlindIdKey` - `pk::HsBlindIdKeypair` - `pk::HsDescSigningKey` - `pk::HsDescSigningKeypair` - `pk::HsIntroPtSessionIdKey` - `pk::HsIntroPtSessionIdKeypair` - `pk::HsSvcNtorKey` - `pk::HsSvcNtorSecretKey` - `pk::hs_client_intro_auth::HsClientIntroAuthKey` - `pk::hs_client_intro_auth::HsClientIntroAuthKeypair` - `pk::HsClientDescEncKey` - `pk::HsClientDescEncSecretKey` - `pk::HsSvcDescEncKey` - `pk::HsSvcDescEncSecretKey` - `pk::HsSvcDescEncKeypair` `PartialEq` has also been implemented for all listed types, using the constant time comparison under the hood. Signed-off-by: hashcatHitman <[email protected]>
| * | | | | | tor-llcrypto: as_bytes on curve25519::StaticSecrethashcatHitman2025-09-161-0/+4
| | |/ / / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Exposed `as_bytes` on `curve25519::StaticSecret`, allowing a shared reference to the secret bytes rather than needing to copy them. Signed-off-by: hashcatHitman <[email protected]>
* | | | | | Merge branch '5225225/2114-nix-flake-for-dev-shell' into 'main'Clara Engler2025-09-242-0/+124
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti: Add flake.nix for a dev environment Closes #2114 See merge request tpo/core/arti!3275
| * | | | | | arti: Add flake.nix for a dev environment52252252025-09-242-0/+124
|/ / / / / /
* | | | | | Merge branch 'bounded_vec_deque' into 'main'gabi-2502025-09-243-18/+79
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | circmgr: Replace BoundedVecDeque with a much smaller wrapper Closes #2174 See merge request tpo/core/arti!3281
| * | | | | | circmgr: Replace BoundedVecDeque with a much smaller wrapperNick Mathewson2025-09-173-18/+79
| |/ / / / / | | | | | | | | | | | | | | | | | | Closes #2174. See that ticket for rationale.
* | | | | | Merge branch 'docs' into 'main'gabi-2502025-09-241-0/+14
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti-client: Add small doc comments to `TorClient::create_onion_service()` See merge request tpo/core/arti!3282
| * | | | | | arti-client: add doc comments to `TorClient::create_onion_service()`Steven Engler2025-09-231-0/+14
|/ / / / / /
* | | | | | Merge branch 'xon-xoff-checker' into 'main'David Goulet2025-09-232-0/+18
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Add some trace logs to XON/XOFF code See merge request tpo/core/arti!3280
| * | | | | | tor-proto: add some trace logs to XON/XOFF codeSteven Engler2025-09-221-0/+9
| | | | | | |
| * | | | | | tor-cell: add `Display` impl for `XonKbpsEwma`Steven Engler2025-09-221-0/+9
|/ / / / / /
* | | | | | Merge branch 'migrate-to-waker-noop' into 'main'Jim Newsome2025-09-224-10/+9
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Migrate to waker noop See merge request tpo/core/arti!3250
| * | | | | | Migrate to waker noopdisha2025-09-224-10/+9
| | | | | | |
* | | | | | | Merge branch 'fix-list-keystore-description' into 'main'gabi-2502025-09-221-1/+1
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-keymgr: Correct `KeyMgr::list_keystores` description See merge request tpo/core/arti!3278
| * | | | | | | tor-keymgr: Fix `KeyMgr::list_keystores` descriptionhjrgrn2025-09-221-1/+1
|/ / / / / / /
* | | | | | | Merge branch 'xon-xoff-checker' into 'main'David Goulet2025-09-187-42/+62
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Small improvements to XON/XOFF code See merge request tpo/core/arti!3273
| * | | | | | | tor-proto: fix a hard-coded `cc_xoff_client`Steven Engler2025-09-182-4/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This should be `cc_xoff_exit` if we're an exit.
| * | | | | | | tor-proto: rename `take_capacity_to_send` to `about_to_send`Steven Engler2025-09-186-27/+21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | XON/XOFF flow control doesn't have the idea of taking "capacity". But it does need to know the messages we're about to send so that it can count the number of stream bytes that we've sent.
| * | | | | | | tor-proto: add checks for receiving XON/XOFF before data sentSteven Engler2025-09-171-0/+14
| | | | | | | |
| * | | | | | | tor-proto: share the `FlowCtrlParameters` across streamsSteven Engler2025-09-173-11/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Streams at the same circuit hop will now share a single `Arc<FlowCtrlParameters>`.
* | | | | | | | Merge branch 'simple_circpad_todos' into 'main'gabi-2502025-09-188-59/+62
|\ \ \ \ \ \ \ \ | |/ / / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | Resolve blocking padding-related TODOs See merge request tpo/core/arti!3271
| * | | | | | | counting_policy: fix a doc link.Nick Mathewson2025-09-171-1/+1
| | | | | | | |
| * | | | | | | proto: Use a VecDeque for padding events; avoid reversing.Nick Mathewson2025-09-171-11/+7
| | | | | | | |
| * | | | | | | proto: Rename PaddingEventVec => PaddingEventQueueNick Mathewson2025-09-171-5/+5
| | | | | | | |
| * | | | | | | proto: Fix a pair of padding setup TODOs.Nick Mathewson2025-09-171-22/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When we install a new padder, we should check whether we have become unblocked, and we should wake up the PaddingEventStream in case the new padder has something to say. This has required us to move a couple of fields around, but not in a very complicated way.
| * | | | | | | proto::util::sink_blocker: Narrow dead_code warning exception.Nick Mathewson2025-09-172-17/+6
| | | | | | | |