summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | | | Merge branch 'untune-shadow-ci' into 'main'Jim Newsome2026-04-091-5/+17
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | integration-shadow: remove torrc parameter tuning See merge request tpo/core/arti!3871
| * | | | | | integration-shadow: remove torrc parameter tuningJim Newsome2026-04-081-5/+17
| |/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These were originally blindly copied over from shadow's own integration test. The relatively low BandwidthRate and BandwidthBurst rates in particular could cause overload in heavily-used relays given the amount of traffic we're trying to push through the network simultaneously from different clients. I'm not aware of a specific problem the other parameters might cause, but it seems better not to have them without some concrete reason. Motivated while debugging arti#2399; we hypothesize that the bandwidth limits + bad luck of many circuits trying to use one relay at once could be a contributing factor.
* | | | | | Merge branch 'create-fast' into 'main'gabi-2502026-04-092-56/+71
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Move CREATE_FAST handling to a helper See merge request tpo/core/arti!3869
| * | | | | | tor-proto: take `CreateRequest` message by referenceSteven Engler2026-04-082-6/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Clippy has started warning about this since we moved the CREATE_FAST handling to a helper, so this resolves that.
| * | | | | | tor-proto: move a TODOSteven Engler2026-04-081-2/+1
| | | | | | |
| * | | | | | tor-proto: remove old TODOSteven Engler2026-04-081-4/+1
| | | | | | |
| * | | | | | tor-proto: rustfmtSteven Engler2026-04-081-6/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix formatting from previous code movement.
| * | | | | | tor-proto: move CREATE_FAST handlingSteven Engler2026-04-081-45/+43
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This moves the code, changes the indentation, and wraps the result in an `Ok()`.
| * | | | | | tor-proto: prepare to move CREATE_FAST handling to a helperSteven Engler2026-04-081-8/+34
| | | | | | |
| * | | | | | tor-proto: remove old TODOSteven Engler2026-04-081-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This had already been resolved.
* | | | | | | Merge branch 'fix-test-advance-by' into 'main'David Goulet2026-04-091-6/+2
|\ \ \ \ \ \ \ | |_|/ / / / / |/| | | | | | | | | | | | | | | | | | | | arti-relay: Fix test MockRuntime::advance_by() usage See merge request tpo/core/arti!3873
| * | | | | | arti-relay: Fix test MockRuntime::advance_by() usageGabriela Moldovan2026-04-091-6/+2
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was previously advancing time by more than intended (I think the intention here was to use something like `MockRuntime::jump_wallclock()`, but that function has no effect on sleeping futures, so I think we should continue using `advance_by()`).
* | | | | | Merge branch 'rustls-defaults' into 'main'Nick Mathewson2026-04-0811-44/+113
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Allow compile-time selection of rustls CryptoProvider; use aws-lc-rs by default. Closes #2448 See merge request tpo/core/arti!3857
| * | | | | | arti-relay: Change CryptoProvider to aws-lc-rs.Nick Mathewson2026-04-082-3/+4
| | | | | | |
| * | | | | | rtcompat: document choice of aws_lc_rs providerNick Mathewson2026-04-081-9/+11
| | | | | | |
| * | | | | | check-licenses: Remove aws-lc-rs exception.Nick Mathewson2026-04-081-7/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | They have finally updated their license to remove the old OpenSSL/4-clause BSD text. (See https://github.com/aws/aws-lc/pull/3091 .)
| * | | | | | arti: Allow choice of CryptoProvider; use aws-lc-rs by default.Nick Mathewson2026-04-084-18/+41
| | | | | | |
| * | | | | | rtcompat: Stop installing backup CryptoProvider.Nick Mathewson2026-04-024-7/+56
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When using rustls, previously we'd check to see whether the application had installed a CryptoProvider (as it is required to do). If not, we'd log a warning and install a Ring provider. But now, we want to enable other kinds of providers, so this behavior isn't practical any more. (See #2448 for discussion.) Closes #2448.
* | | | | | | Merge branch 'feat/protocol-warnings' into 'main'Nick Mathewson2026-04-084-3/+220
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-error/arti: add logging.protocol_warnings for TorProtocolViolation See merge request tpo/core/arti!3805
| * | | | | | | arti: set_protocol_warning_mode to Warn or Off in setup_loggingmoumenalaoui2026-04-082-14/+26
| | | | | | | |
| * | | | | | | arti: add protocol_warnings config and wire setup_loggingmoumenalaoui2026-03-273-0/+24
| | | | | | | |
| * | | | | | | tor-error: add runtime ProtocolWarningMode and promote TorProtocolViolation ↵moumenalaoui2026-03-271-1/+182
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | in event_report!
* | | | | | | | Merge branch 'ticket2441_01' into 'main'David Goulet2026-04-087-30/+63
|\ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | proto: Add ClogDigest and SlogDigest types Closes #2441 See merge request tpo/core/arti!3844
| * | | | | | | | proto: Bring back AuthLogDigest and explicitly convert to SLOG/CLOGDavid Goulet2026-04-084-36/+27
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | From opara's comment: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3844#note_3388789 Keep the low level AuthLogDigest type alias and return it. The callsite is the one deciding if the returned digest is a Clog or a Slog. Related to #2441 Signed-off-by: David Goulet <[email protected]>
| * | | | | | | | proto: Add ClogDigest and SlogDigest typesDavid Goulet2026-04-087-38/+80
|/ / / / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Introduce those types in order to avoid mixing them up as the previous AuthLogDigest was just a type alias over [u8; 32] Fixes #2441 Signed-off-by: David Goulet <[email protected]>
* | | | | | | | Merge branch 'netdoc-test-fix' into 'main'Clara Engler2026-04-0850-2668/+2826
|\ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix the testdata2 situation See merge request tpo/core/arti!3861
| * | | | | | | | tor-netdoc: Add manual happy families microdesc testClara Engler2026-04-081-0/+35
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a manual test case for happy families in microdesc with parse2. Manual in the sense that we hardcode a microdescriptor taken from the wild here, as testdata2 does not contain them at the current moment, which is unfortunate but reported.
| * | | | | | | | tor-netdoc: Adjust family values for microdesc testClara Engler2026-04-081-12/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adjust the family value for the microdesc test to the one actually found in testdata2/.
| * | | | | | | | tor-netdoc: Update microdesc test EC keysClara Engler2026-04-081-9/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the microdesc test EC keys with the new ones from testdata2/ while also changing the encoding from a byte array to the base64 value found in the microdesc itself.
| * | | | | | | | tor-netdoc: Update microdesc test onion keyClara Engler2026-04-081-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the microdesc onion key with the new one from testdata2.
| * | | | | | | | tor-netdoc: "Remove" assert_eq for mds[6]Clara Engler2026-04-081-40/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit removes the assert_eq for mds[6]. The reason for this was to have a test case with happy families set. However, these values were manually hacked into the respective file which is not the correct way. Instead, we will test this in a separate test that will be added later, as the current testdata2/ is not capable of this. This is an already reported chutney issue.
| * | | | | | | | tor-netdoc: No longer ignore microdesc parse2 testClara Engler2026-04-081-2/+0
| | | | | | | | |
| * | | | | | | | tor-netdoc: Remove dead authcert test codeClara Engler2026-04-081-29/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This removes unused imports as well as the read_b64 and to_der helper functions which are all no longer used.
| * | | | | | | | tor-netdoc: Update dir_auth_cross_cert() test caseClara Engler2026-04-081-1/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the dir_auth_cross_cert() test case with the new constants, replacing the longclaw ones. The replacement also involves a slight refactoring on the way how we obtain the encoded and decoded variable, namely because we have the data in a PEM encoded string now and no longer in separate file, making the use of read_b64 impossible.
| * | | | | | | | tor-netdoc: Update invalid outer signature test caseClara Engler2026-04-081-10/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the invalid outer signature test case by copying the outer signature of the alternative certificate into our test object, which should obviously render this to a failure. It also updates the test vectors to the constant ones because it moves away from longclaw.
| * | | | | | | | tor-netdoc: Update the invalid cross-cert test caseClara Engler2026-04-081-10/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the invalid cross-cert test case by copying the cross-cert from the alternative cert into our test object, resulting in a failure. Of course this also updates the other test vectors to use the constants declared above, as this moves away from longclaw.
| * | | | | | | | tor-netdoc: Update inconsistent fingerprint test caseClara Engler2026-04-081-7/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the inconsistent fingerprint test case that tests whether the fingerprint matches with the identity RSA key. For this, we load the alternative authority cert and move its identity key into the identity key of the canonical cert. Of course, this also replaces the other test vectors that are now required for this change because it moves away from longclaw.
| * | | | | | | | tor-netdoc: Constify ALTERNATIVE_AUTHCERT_RAWClara Engler2026-04-081-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a new constant to the parse2 authcert unit tests, ALTERNATIVE_AUTHCERT_RAW, with the idea being to be different than AUTHCERT_RAW, which we will utilize in order to mix up cross-cert objects from one authcert with the one of another one in order to see it fail.
| * | | | | | | | tor-netdoc: Update "trivial" test cases in dir_auth_signature()Clara Engler2026-04-081-50/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the "trivial" test cases in the dir_auth_signature unit tests, namely the ones concerning the outer signature as well as the timestamp tolerance. A follow-up commit will also update the more tricky ones, such as the ones testing inconsistent cross-certificates, etc.
| * | | | | | | | tor-netdoc: Constify VALID_SYSTEM_TIMEClara Engler2026-04-081-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit constifies VALID_SYSTEM_TIME, a timestamp indicating a point in time at which the certificate is valid. We will need this to test timestamp validation.
| * | | | | | | | tor-netdoc: Update test vectors in dir_auth_certClara Engler2026-04-081-15/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces the longclaw test vectors in dir_auth_cert with the ones we constified previously and represent the ones found in testdata2/. It may look a bit odd that we replaced the file includes for the public keys but this is because those files should have never existed in testdata2/ in the first place and were only added by accident, meaning that the current approach is the correct one.
| * | | | | | | | tor-netdoc: Remove outdated longclaw comment in testClara Engler2026-04-081-2/+0
| | | | | | | | |
| * | | | | | | | tor-netdoc: Replace a File::open with include_strClara Engler2026-04-081-7/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces a File::open with the AUTHCERT_RAW constant in the dir_auth_cert test because that is obviously less error prone.
| * | | | | | | | tor-netdoc: Constify the raw authcert test vectorClara Engler2026-04-081-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds `const AUTHCERT_RAW` which `include_str`'s the actual raw authcert we will use for parsing test purposes. The reason for that being that a single include_str! of the same file is obviously better than multiple ones.
| * | | | | | | | tor-netdoc: Constify the authcert test vectorsClara Engler2026-04-081-0/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit constifies the authcert test vectors by extracting them from testdata2/keys/authority_certificate.
| * | | | | | | | tor-netdoc: Add to_rsa_id() helper functionClara Engler2026-04-081-0/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a to_rsa_id() helper function to the authcert tests in order to convert a hex-encoded RSA identity to an RsaIdentity. It will be required later on for converting the test vector values to the inner representations and this function is helpful here because it avoids us to do repetitive unwrapping and RsaIdentity::from_hex calls, which overall increase the length/readability.
| * | | | | | | | tor-netdoc: Add pem_to_rsa_pk helper functionClara Engler2026-04-081-0/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the pem_to_rsa_pk helper function to the authcert tests in order to convert a PEM encoded RSA public key to the internal data structure. It will be required later on in order to convert the test vector strings to internal representations.
| * | | | | | | | tor-netdoc: Add to_system_time helper functionClara Engler2026-04-081-0/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a to_system_time helper function accepting an &str in the Iso8601TimeSp format and converting it to a SystemTime to the authcert test cases. It will be required later on in order to conveniently convert human readable timestamps to the test vectors expected from parsed data.
| * | | | | | | | tor-netdoc: Fix broken poc testsClara Engler2026-04-081-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These tests got broken due to the replacement of the testdata. The changes required to make them work again were trivial, namely to increase a timestamp by two hours in a consensus, as the new consensus has a `valid-after 2000-01-01 00:02:20` followed by a fingerprint replacement for a directory authority because the authority identity keys were obviously also rotated.
| * | | | | | | | testdata2: Update with job 1468137Clara Engler2026-04-0745-2468/+2610
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This updates the testdata2 directory with job 1468137 using the following command: ./testdata2-download \ "https://gitlab.torproject.org/tpo/core/arti/-/jobs/1468137/artifacts/download" The artifact will expire at one point, so you may not be able to reproduce it anymore.