summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * Force use of standard hasher with weak_tables.Nick Mathewson2026-03-245-5/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | Closes #2418. Fixes TROVE-2026-005, where we would use a less cryptographically secure (and probably less DoS resistant) hash function for these tables if: - We are built alongside another crate that uses `weak-table` - That crate enables the `weak-table/ahash` feature. - We are running on a system without hardware AES. Severity: Low
* | Merge branch 'relay-log' into 'main'David Goulet2026-03-241-2/+2
|\ \ | | | | | | | | | | | | arti-relay: Change a 'debug' log to 'info' See merge request tpo/core/arti!3803
| * | arti-relay: change a 'debug' log to 'info'Steven Engler2026-03-241-2/+2
|/ / | | | | | | | | I had intended for this to be 'info' in f287ec7910, but must have accidentally wrote 'debug'.
* | Merge branch 'codespell' into 'main'opara2026-03-2456-91/+93
|\ \ | |/ |/| | | | | Fix typos See merge request tpo/core/arti!3792
| * Fix typosTobias Stoeckmann2026-03-2456-91/+93
|/ | | | Typos found with codespell
* Merge branch 'rpc-nonblocking-ffi' into 'main'Nick Mathewson2026-03-2310-19/+1252
|\ | | | | | | | | RPC: C/Python wrappers and integration tests for nonblocking and polling IO See merge request tpo/core/arti!3771
| * rpc: re-run cbindben.Nick Mathewson2026-03-231-3/+3
| |
| * typo fixes from @jnewsomeNick Mathewson2026-03-232-5/+5
| |
| * rpc: Python wrappers (and tests) for pollable FFI.Nick Mathewson2026-03-234-1/+297
| | | | | | | | | | This provides an API and tests for create_polling(), poll(), and related APIs.
| * rpc: Add pythonic wrappers nonblocking requests.Nick Mathewson2026-03-233-1/+195
| | | | | | | | | | | | | | These wrappers present a "pythonic" API to the C functions for submit and wait. Tests included.
| * rpc: Add python ctypes wrappers for new FFI functions.Nick Mathewson2026-03-231-11/+82
| | | | | | | | | | These are low-level wrappers that let us call the relevant C code, but are not suitable for general use.
| * Run cbindgen to regenerate header file.Nick Mathewson2026-03-232-1/+230
| |
| * rpc: add ffi wrappers for nonblocking and event-loop functions.Nick Mathewson2026-03-232-6/+313
| | | | | | | | | | This commit adds FFI wrappers for the "poll" API, which lets the user integrate with a poll(2)-style event loop.
| * rpc: define FFI wrappers for nonblocking request APIsNick Mathewson2026-03-231-1/+137
|/ | | | | | This commit adds wrappers for the "submit/wait" methods on RpcConn (which are used to submit tagged requests, and then wait for responses to all tagged requests at once).
* Merge branch 'half-stream-expiry3' into 'main'gabi-2502026-03-233-53/+55
|\ | | | | | | | | | | | | proto: Replace TimeoutEstimator with opaque handler Closes #2410 See merge request tpo/core/arti!3794
| * proto: Remove now-unused TimeoutEstimator argumentGabriela Moldovan2026-03-191-2/+0
| |
| * proto: Replace TimeoutEstimator with opaque handlerGabriela Moldovan2026-03-193-50/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This replaces the client-specific half-stream expiry calculation from the stream reactor (which is meant to be implementation agnostic) with a call to the new `StreamHandler::halfstream_expiry()`, which abstracts away the implementation-specific half-stream expiry calculation (for example, on the client-side, the calculation takes into account the CBT, which we don't have on the relay side). Note that there is currently no `StreamHandler` implementation on the client-side (because we haven't ported the client circuit reactor to the new reactor yet). Closes #2410
| * proto: Implement StreamHandler for relaysGabriela Moldovan2026-03-191-1/+29
| |
| * proto: Add a trait for customizing StreamReactor behaviorGabriela Moldovan2026-03-191-0/+13
| | | | | | | | | | This will enable us to handle half-stream expiry differently on the client side vs the exit side.
* | Merge branch 'bump-rustls-webpki' into 'main'Nick Mathewson2026-03-231-3/+3
|\ \ | | | | | | | | | | | | Bump to latest webpki (0.103.10) to resolve RUSTSEC-2026-0049 See merge request tpo/core/arti!3798
| * | Bump to latest webpki (0.103.10) to resolve RUSTSEC-2026-0049Nick Mathewson2026-03-231-3/+3
| | | | | | | | | | | | | | | | | | | | | Advisory at https://rustsec.org/advisories/RUSTSEC-2026-0049 This issue doesn't affect Arti itself, since Arti doesn't actually _use_ regular X.509 CAs or CRLs.
* | | Merge branch 'build_certs_refactor' into 'main'Nick Mathewson2026-03-237-23/+59
|\ \ \ | |/ / |/| | | | | | | | cell, proto, cert: Simplify CERTS cell building. See merge request tpo/core/arti!3795
| * | cell: Feature-gate API using the possibly absent EncodedCert type.Nick Mathewson2026-03-233-1/+6
| | |
| * | cell, proto, cert: Simplify CERTS cell building.Nick Mathewson2026-03-195-22/+53
| | | | | | | | | | | | | | | | | | | | | | | | Formerly we required the caller for push_cert_body to specify the type of the cert that they were pushing. But in nearly every case, the certificate object that the caller is holding knows what its own type is! This makes the tor_proto build_certs_cell function a bit less error-prone, since we don't have to worry about mismatch.
* | | Merge branch 'gating-cleanup' into 'main'Ian Jackson2026-03-232-5/+1
|\ \ \ | | | | | | | | | | | | | | | | proto: Remove unnecessary test-gating See merge request tpo/core/arti!3796
| * | | proto: Remove unnecessary feature-gatingGabriela Moldovan2026-03-191-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | `test_utils` is not exposed outside of `tor-proto`, so the feature gating here isn't needed (we typically use the `testing` feature for exposing testing utilities outside the current crate, but that's not the case here).
| * | | proto: Remove unnecessary test-gatingGabriela Moldovan2026-03-191-4/+0
| | |/ | |/| | | | | | | | | | The `test_util` modules is already gated behind `#[cfg(any(test, feature = "testing"))]`.
* | | Merge branch 'retry_error_dedup' into 'main'gabi-2502026-03-231-23/+62
|\ \ \ | | | | | | | | | | | | | | | | retry-error: Allow dedup_by to merge ranges See merge request tpo/core/arti!3784
| * | | retry-error: Remove unused variableTobias Stoeckmann2026-03-191-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | Spotted during review by gabi-250 in another test. Signed-off-by: Tobias Stoeckmann <[email protected]>
| * | | retry-error: Simplify extend_from_retry_errorTobias Stoeckmann2026-03-191-16/+7
| | | | | | | | | | | | | | | | | | | | With the newly introduced count function, extend_from_retry_error can be simplified by spliting n_errors calculation from new_attempt creation.
| * | | retry-error: Allow dedup_by to merge rangesTobias Stoeckmann2026-03-191-5/+54
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The dedup_by function grows the "last_attempt" always by one, even if a range is encountered. A mergeable range can be encountered if the RetryError has been extended by another RetryError already containing a range. Take this special case into account by using the actual amount of failures of the attempt when growing. Signed-off-by: Tobias Stoeckmann <[email protected]>
| * | | retry-error: Fix typo in dedup_by descriptionTobias Stoeckmann2026-03-171-1/+1
| | | | | | | | | | | | | | | | The function argument is named same_err, not dedup.
* | | | Merge branch 'ticket2388_02' into 'main'David Goulet2026-03-1910-375/+693
|\ \ \ \ | |_|_|/ |/| | | | | | | | | | | | | | | | | | | proto: Fix channel responder expecting a peer certificate Closes #2388 See merge request tpo/core/arti!3791
| * | | proto: Compare AUTHENTICATE expected body in constant-timeDavid Goulet2026-03-191-1/+3
| | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | proto: The relay signing key signs the auth certDavid Goulet2026-03-192-9/+6
| | | | | | | | | | | | | | | | | | | | | | | | In other words kp_relaysign_ed. Signed-off-by: David Goulet <[email protected]>
| * | | proto: Check the AUTHENTICATE auth type that we support itDavid Goulet2026-03-194-1/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As a responder, we should check the AUTHENTICATE auth type and make sure we support it. We were not doing that, we were simply putting in our max version. Signed-off-by: David Goulet <[email protected]>
| * | | chanmgr: Don't build relay channel if method is not DirectDavid Goulet2026-03-191-0/+6
| | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | chanmgr: Clarify the use of no identity ChanTargetDavid Goulet2026-03-192-9/+14
| | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | cell: Use Error::MissingData if Authenticate fields length is wrongDavid Goulet2026-03-191-26/+16
| | | | | | | | | | | | | | | | | | | | | | | | Proper error to use and better code to use checked_sub(). Signed-off-by: David Goulet <[email protected]>
| * | | tor-proto: fix the relay responder's CLOG/SLOG digestsSteven Engler2026-03-192-20/+37
| | | |
| * | | tor-proto: fix the relay initiator's SLOG digestSteven Engler2026-03-194-13/+47
| | | |
| * | | tor-proto: get SLOG/CLOG outside of `ChannelAuthenticationData`Steven Engler2026-03-193-10/+24
| | | |
| * | | tor-proto: improve chan send/recv-log error messagesSteven Engler2026-03-191-2/+6
| | | |
| * | | tor-proto: build AUTHENTICATE after sending CERTSSteven Engler2026-03-191-15/+22
| | | | | | | | | | | | | | | | | | | | | | | | The AUTHENTICATE cell contents depends on all bytes sent on the channel before the AUTHENTICATE cell itself is sent (the CLOG). So we can only build a correct AUTHENTICATE cell after the CERTS cell has been sent.
| * | | cell: Simplify the Authenticate APIDavid Goulet2026-03-192-21/+34
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Remove the is_equal_no_sig() and instead add a getter that returns a reference to the body without the random part so it can be used to verify the signature. The caller now checks the equality with what it is expected. Signed-off-by: David Goulet <[email protected]>
| * | | proto: Fix AUTHENTICATE equality check and signature checkDavid Goulet2026-03-192-2/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes two things. 1. The "is_equal_no_sig()", if true, was going into the error path. 2. The signature verification is done against the body of the AUTHENTICATE cell that is all fields except the signature. Next commit will change the is_equal_no_sig() to make more sense with the "body" semantic. Signed-off-by: David Goulet <[email protected]>
| * | | proto: Set the link protocol outside the recv VERSIONS helperDavid Goulet2026-03-193-17/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It used to work for an initiator to set the link protocol once a VERSIONS is received because initiator send their VERSIONS before. This failed with responders because a responder channel sends their VERSIONS after receiving one from the initiator. This reverse logic means that the channel cell handler was transitionned to the Handshake state before a responder was able to send a VERSIONS cell leading to a failure because VERSIONS cell aren't allowed at the Handshake state. To fix this, the send/recv or recv/send is now explicit per channel type and once this is done and successful, the link protocol is set. A `set_link_protocol()` is added to the ChannelBaseHandshake trait so it can be used to set the cell handler. Signed-off-by: David Goulet <[email protected]>
| * | | proto: Fix unit testsDavid Goulet2026-03-191-7/+17
| | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | proto: Improve logging in channel handshakeDavid Goulet2026-03-191-2/+2
| | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | chanmgr: Don't get the peer cert as a responder channelDavid Goulet2026-03-191-9/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | No initiator present a TLS certificate and so don't try to get one. Fixes #2388 Signed-off-by: David Goulet <[email protected]>