summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | tor-netdoc: EncodedAuthCert: unit testsIan Jackson2026-01-151-0/+197
| | | | |
| * | | | tor-netdoc: EncodedAuthCert: implementIan Jackson2026-01-153-0/+214
| | | | | | | | | | | | | | | | | | | | As per doc/dev/notes/authcert-in-consensus.md.
| * | | | tor-netdoc: Expose whole input string (rustfmt)Ian Jackson2026-01-151-2/+1
| | | | |
| * | | | tor-netdoc: Expose whole input stringIan Jackson2026-01-152-8/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The string so far is exposed already via whole_for_signatures. It is unusual for a doc parser to need this, but embedded documents can use this plus byte_position to get the original input text for their part of the outer document.
| * | | | tor-netdoc: parse2: Provide NetdocParseable::is_structural_keyword (rustfmt)Ian Jackson2026-01-152-5/+3
| | | | |
| * | | | tor-netdoc: parse2: Provide NetdocParseable::is_structural_keywordIan Jackson2026-01-156-2/+87
| | | | | | | | | | | | | | | | | | | | Roughly as per the proposal in `doc/dev/notes/authcert-in-consensus.md`.
| * | | | tor-netdoc: Abolish poc's AuthCert (rustfmt)Ian Jackson2026-01-152-8/+3
| | | | |
| * | | | tor-netdoc: Abolish poc's AuthCertIan Jackson2026-01-154-109/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We can use the real AuthCert now that it implements the parse2 traits. The verification function is still used by poc's netstatus code and by a test case. We must change the field names in a few places, because the real AuthCert's struct field names are the keywords, whereas the poc's are the key names. (A shame that they're different!)
| * | | | tor-netdoc: Prepare poc's DirAuthKeyCertSigned::verify_selfcertIan Jackson2026-01-151-7/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Use accessors for the body. (Eventually this function will replace, be replaced by, or merge with, the existing signature code outside poc.)
| * | | | tor-netdoc: Add an error variant we'll need for parsing embedded docsIan Jackson2026-01-151-0/+3
| | | | |
| * | | | tor-netdoc: Improve Keyword API slightlyIan Jackson2026-01-152-1/+13
| | | | |
* | | | | Merge branch 'dirmirror-authcert' into 'main'Clara Engler2026-01-1513-65/+945
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Implement authority certificate management See merge request tpo/core/arti!3561
| * | | | | tor-dirserver: Small pre-merge fixesClara Engler2026-01-152-3/+2
| | | | | |
| * | | | | tor-dirserver: Add TODO wrt hex::encode_upperClara Engler2026-01-151-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Adding a comment suggesting to implement this as part of abstracting `Sha256` behind a more generic identifier.
| * | | | | tor-dirserver: Fix clippy warningClara Engler2026-01-151-1/+1
| | | | | |
| * | | | | tor-dirserver: Use `INSERT OR REPLACE`Clara Engler2026-01-151-2/+43
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit rpelaces the use of `INSERT` with `INSERT OR REPLACE` for handling insertion conflicts in `store_insert`. Because everything is content-addressed anyways, it does not matter to do this, because if we get a conflict on a SHA256, it means the data is equal.[1] [1]: Excluding SHA-2 collisions which are impractical as of 2026.
| * | | | | tor-dirserver: Change store_insert logicClara Engler2026-01-152-49/+53
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit modifies the database::store_insert logic to accept an iterator of the encodings to store the document in, instead of encoding it with all encodings we support.
| * | | | | tor-netdoc: Change error variantsClara Engler2026-01-153-18/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit changes `ErrorProblem::Other` to `ErrorProblem::OtherBadDocument` while adding two new variants: * `ErrorProblem::Internal` * `ErrorProblem::BadApiUsage`
| * | | | | tor-dirserver: Remove algorithm CHECK constraintClara Engler2026-01-151-2/+1
| | | | | |
| * | | | | tor-dirserver: Add TODO for hash agnostic type alias nameClara Engler2026-01-151-0/+1
| | | | | |
| * | | | | tor-dirmirror: Handle unparsable certificatesClara Engler2026-01-151-8/+69
| | | | | | | | | | | | | | | | | | | | | | | | Instead of failing, add them to missing and query them again.
| * | | | | tor-dirserver: Improve note on query performanceClara Engler2026-01-151-6/+8
| | | | | |
| * | | | | tor-dirserver: Fix formulationClara Engler2026-01-151-1/+1
| | | | | |
| * | | | | tor-dirserver: Implement authcert retrieval logicClara Engler2026-01-153-4/+280
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit implements the logic necessary to retrieve the (missing) directory authority certificates from an upstream directory authority. In order to do so, this commit implements three new functions: 1. `download_authority_certificates()` 2. `parse_authority_certificates()` 3. `verify_authority_certificates()` 4. `insert_authority_certificates()`
| * | | | | parse2: OOB check for parse_netdoc_multiple_with_offsetsClara Engler2026-01-151-5/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds an out-of-bounds memory check to parse2::parse_netdoc_multiple_with_offsets while adding the guarantee that interfacing applications do not need to validate the returned usize values to be in-range.
| * | | | | tor-dirserver: Ensure algorithm with CHECKClara Engler2026-01-151-2/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a CHECK constraint to the compressed_document table in order to ensure that `algorithm` may only take up a limited set of values.
| * | | | | tor-dirserver: Move ContentEncoding to databaseClara Engler2026-01-152-20/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit moves the ContentEncoding enum from the http module to the database module, primarily because the content encoding is more of a matter to the database, as this is where the data actually resides.
| * | | | | tor-dirserver: Support for inserting into storeClara Engler2026-01-154-10/+227
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit implements support for adding arbitrary documents into the store table. It is non-trivial because the relevant data has to be compressed into various formats, so it can be retrieved without delays.
| * | | | | tor-dirserver: Test authcert queryingClara Engler2026-01-154-0/+139
| | | | | |
| * | | | | tor-dirserver: Operation test refactoringClara Engler2026-01-151-9/+7
| | | | | |
| * | | | | tor-dirserver: Add get_recent_authority_certificatesClara Engler2026-01-152-3/+111
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the `get_recent_authority_certificates()` function to the operation of a directory mirror, which is responsible for looking up the certificates in the database, returning the parsed found ones as well as the missing ones.
| * | | | | tor-dirserver: `From<Timestamp> for SystemTime`Clara Engler2026-01-151-0/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The reverse direction already exists and it will be required when we act with functions outside the crate that only accept a `SystemTime` in situations where we just have a `Timestamp`.
| * | | | | tor-dirserver: Add `dir_key_published` to schemaClara Engler2026-01-151-1/+4
| | | | | |
| * | | | | tor-llcrypto: Add `RsaIdentity::as_hex_upper`Clara Engler2026-01-152-0/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the method `as_hex_upper(&self) -> String` to `RsaIdentity`, which returns the `RsaIdentity` as a hexadecimal string in uppercase. Although this type already implements `ToString`, this result is unsuitable for working with consensuses because they neither contain a `$` prefix, nor are encoded in lowercase.
| * | | | | tor-netdoc: Make ConsensusFlavor exhaustiveClara Engler2026-01-151-1/+5
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit marks the ConsensusFlavor struct exhaustive because handling it in a non-exhaustive fashion would cause lots of redundant error handling in tor-dirserver. Besides, a change in the list of consensus flavors should indeed be breaking for applications making use of this struct, as it is quite a heavy change, from a netdoc point of view.
* | | | | Merge branch 'version-expose' into 'main'Alexander Hansen Færøy2026-01-154-9/+9
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: Rename Version and expose it as netstatus::SoftwareVersion See merge request tpo/core/arti!3594
| * | | | | tor-netdoc: Rename Version and expose it as netstatus::SoftwareVersionIan Jackson2026-01-154-9/+9
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This struct is still a bit odd, and there's a todo saying we may change it again, but at least now it's now available. While we're here, rename the variant Tor to CTor.
* | | | | Merge branch 'install-runtime' into 'main'Ian Jackson2026-01-156-2/+39
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Use and document `tor_log_ratelim::install_runtime()` See merge request tpo/core/arti!3593
| * | | | arti-client: document the need for `tor_log_ratelim::install_runtime()`Steven Engler2026-01-141-0/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This function can only be called once within a program, so we can't call it ourselves from a `TorClient`. The user must call it themselves, so we should document this.
| * | | | arti-relay: call `tor_log_ratelim::install_runtime`Steven Engler2026-01-143-0/+6
| | | | |
| * | | | arti: call `tor_log_ratelim::install_runtime`Steven Engler2026-01-143-2/+8
|/ / / /
* | | | Merge branch 'authcert-constructor-non-exhaustive' into 'main'Clara Engler2026-01-146-13/+51
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-netdoc: Use manual non exhaustive in constructors See merge request tpo/core/arti!3571
| * | | | tor-netdoc: Fix typoIan Jackson2026-01-141-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3571#note_3325449
| * | | | tor-netdoc: constructors: Use manual non exhaustiveIan Jackson2026-01-143-3/+14
| | | | | | | | | | | | | | | | | | | | With `#[non_exhaustive]`, you're not allowed to write even `Thing { ..base }`.
| * | | | tor-netdoc: derives: New `skip` document field optionIan Jackson2026-01-144-10/+37
| | | | | | | | | | | | | | | | | | | | | | | | | This lets us having document items that are "manually non exhaustive" which is necessary for struct literal constructors.
* | | | | Merge branch 'download-test-speed' into 'main'Clara Engler2026-01-142-36/+7
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Speedup in tor-dirserver tests See merge request tpo/core/arti!3591
| * | | | | tor-dirserver: Speedup tests using tokio's test-utilClara Engler2026-01-142-9/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit speeds up the tests in `tor-dirserver` by using functionality from Tokio's `test-util`. Most notably, it runs the time intensive test in paused mode, which means that the clock gets advanced either explicitly or implicitly using auto-advance in case the runtime has nothing to do. In our case, the last one, auto-advancing, is used, leading to our sleep calls returning immediately. This is good enough for testing in this module. It is not the responsibility of tor-dirserver to ensure whether `RetryDelay` returns proper values, as this is the responsibility of `tor-basic-utils`. Still, it is a bit unfortunate that Tokio offers no way to manually disbale the auto-advancing. In the future, it might be useful to migrate more parts of this to crate to `tor-rtcompat`, but for now, this change is a good enough performance fix.
| * | | | | tor-dirserver: Remove slow ineffective testClara Engler2026-01-141-27/+0
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit removes `mirror::download::test::request_fail_timeout` which takes more than five seconds (due to a timeout) and is generally ineffective in what it does, because testing whether a task is still sleeping after a certain time is not super trivial with the tools Tokio offers. All this test offers is testing that we enter a timeout at all.
* | | | | Merge branch 'rpc-auto-spec' into 'main'Nick Mathewson2026-01-141-11/+54
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | rpc: Document the intended behavior of inet-auto connpts See merge request tpo/core/arti!3587
| * | | | | rpc: Rename socket_stored_in_file => socket_address_fileNick Mathewson2026-01-141-2/+2
| | | | | |