| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
We're going to need this for encoding too.
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit implements the RouterDescSignatures type that carries the
signatures for the yet to be derived RouterDescUnverified.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit adds RouterSigEd25519 as a type to misc.rs for use in router
descriptor signatures.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit adds RouterDescSignature to types, which implements
SignatureItemParseable manually in order to also include the Ed25519
signature.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit adds a hash accumulator for router descriptor signature
hashes. We will need this because router descriptors have overlapping
signatures.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Part of #2492 phase 2.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This avoids much repetition (and consequent conflicts as code is
added).
|
| | | | | | |
|
| |\| | | |
| | | | |
| | | | |
| | | | |
| | | | | |
tor-netdoc: Un-cfg much parse2 and encode
See merge request tpo/core/arti!3915
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
plain-consensus
"incomplete" is correct since encoded authcert depends on votes.
"plain-consensus" is going backwards, but stripping "plain-consensus"
gates from everything will be very intrusive.
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Unconditionally enable everything previously gated with parse2 or
encode.
|
| | | | | | |
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | | |
Part of #2492. We're going to make encode unconditional, and remove
all the cfg-gates for it. Code currently gated by encode depends on
rand.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
CI: tune shadow for shared CI environment
See merge request tpo/core/arti!3911
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
shadow's default behavior of spin-looping is bad behavior in a shared
environment.
This is already disabled in integration-shadow.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
In CI, shadow's default behavior of pinning to CPU cores can result in
multiple instances of shadow fighting over the same CPU cores instead of
using idle ones.
|
| |\ \ \ \ \
| |_|_|/ /
|/| | | /
| | |_|/
| |/| | |
Update MACOS_DEPLOYMENT_TARGET to 10.14
See merge request tpo/core/arti!3920
|
| | | | | |
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This gives our reproducible-build tools permission to use APIs
introduced in versions up to 10.14. Previously, we had this set to
10.12, which is the oldest version supported by Rust.
Upgrading to 10.14 will allow us to merge !3817, and to upgrade
security-framework to the latest version (#2387).
OSX 10.14 ("Mojave") was released in September 2018, and hasn't
been officially supported since October 2021. IMO it's a fine "very
old version" for now.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Update the OSX SDK in our reproducible build.
See merge request tpo/core/arti!3901
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This patch puts the osx tools build (which gets cached) into a
directory that includes the SDK version, so that we don't get
confused with older or newer SDK builds.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Changes:
- Update the build target to 10.12, and define it in a single place.
(We had 10.7 before, but Rust only supports 10.12 and higher.
We will probably want to update this to something even more recent
soon.
- Use the default clang c++ library, rather than trying to force
libstdc++, which OSX dropped after the 10.13 SDK.
- Use the same clang++ for compilation and linking.
- Use the 15.5 SDK.
- Use a copy of the SDK with a known source.
Specifically we start with the the pkg file from Apple, as cached
by the TBB team on `build-sources.tbb.tpo`. Using a pkg file means
that we have to run a script from them the tor-browser-build
repository to extract the SDK files, and then run the osxcross
script that repackages that SDK as a tar.xz file.
I believe our script will make sure this gets cached.
- Stop trying to use define an `ar`; nothing needs it.
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-llcrypto: Add RsaIdentity::to_bytes()
See merge request tpo/core/arti!3916
|
| | | |_|/
| |/| |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This commit adds .to_bytes() to RsaIdentity which is similar to
.as_bytes() except that it returns the RsaIdentity as a byte array.
We are going to need this at a few places in tor-dirserver. The naming
was inspired from x25519-dalek which has similar .as_bytes() and
.to_bytes() methods. Besides, copying 20 bytes shall be okay and it
avoids having to write ugly try_into() constructs.
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | |
| | | |
| | | | |
proto: Reject EXTEND2 targeting the previous hop in the circuit
Closes #2415
See merge request tpo/core/arti!3906
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
To avoid copying the same information for every circuit,
as suggested by @opara in
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3906#note_3399497
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This is analogous to `Option::map()`, and can be useful when you need to
map the inner type of a `MaybeSensitive` to another type.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
It doesn't make sense to do so, as pointed out by @opara in
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3906#note_3398956
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
This is used in the relay circuit reactor.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
The new relay circuit reactor test expect the `PeerInfo` to be populated
with the identity keys of the peer, and won't work without this change.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3906#note_3397922
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The relay reactor will now reject any EXTEND2 that tries to extend the
circuit to a hop that shares any identities with our previous hop.
Closes #2415
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This will soon be used for preventing the circuit from being extended to
the previous hop (#2415).
|