summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | | | | tor-netdoc: Fix handling of netdoc(skip) in NetdocParseableFieldsIan Jackson2026-04-071-1/+6
| | |/ / / / / / / | |/| | | | | | |
* | | | | | | | | Merge branch 'cert-retrieval' into 'main'David Goulet2026-04-085-57/+63
|\ \ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti-relay: Retrieve the signing key cert from the keystore See merge request tpo/core/arti!3863
| * | | | | | | | | keymgr: Fix ephemeral keystore cert encoding bug (fmt)Gabriela Moldovan2026-04-081-6/+3
| | | | | | | | | |
| * | | | | | | | | keymgr: Fix ephemeral keystore cert encoding bugGabriela Moldovan2026-04-084-28/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a bug that was causing the ephemeral keystore to retrieve certs in a format that couldn't be handled by the `KeyMgr`. This caused all certificate retrievals from `EphemeralKeystore` done via the `KeyMgr` to fail with an internal error. For context, the only supported cert type is `TorEd25519Cert`, which is a pre-encoded certificate (i.e. a type wrapper over a `Vec<u8>`). These certificates are stored as-is by the Arti native keystore (the bytes are written to a file on disk). When retrieving a `TorEd25519Cert`, the Arti keystore uses `parse_certificate_erased()` to parse the cert into a `ParsedEd25519Cert` before returning it as a type-erased `ErasedKey`. This works as intended with the `KeyMgr` retrieval and downcasting logic, which expects the certificate to be returned in the `ParsedCert` format specified in the `ToEncodableCert` implementation. Before this change, the ephemeral keystore, on the other hand, did not play well with the `KeyMgr` when it came to cert retrieval: it would incorrectly store the `KeystoreItem` as-is, and retrieve it as an `ErasedKey` using the `ErasedKey::into_erased()` implementation. This would then cause the `KeyMgr` to fail to downcast the `ErasedKey` to the correct type (because the returned erased item was of a different type than `ParsedCert`). This commit also removes `KeystoreItem::into_erased()`, which was a footgun (because certificates are not actually supposed to be retrieved in the format returned by `CertData::into_erased()`).
| * | | | | | | | | arti-relay: Retrieve the signing key cert from the keystoreGabriela Moldovan2026-04-081-8/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The API for retrieving certs exists now, so we don't need to regenerate the cert each time. This addresses a TODO.
| * | | | | | | | | arti-relay: Reuse cert_expiry calculationGabriela Moldovan2026-04-081-2/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | For readability.
| * | | | | | | | | arti-relay: Move comment closer to the durations it refers toGabriela Moldovan2026-04-081-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We forgot to move this comment when we replaced the hard-coded durations with top-level constants.
| * | | | | | | | | arti-relay: Use more descriptive names for the key lifetimesGabriela Moldovan2026-04-081-20/+20
|/ / / / / / / / /
* | | | | | | | | Merge branch 'memquota-add-parent' into 'main'gabi-2502026-04-084-48/+165
|\ \ \ \ \ \ \ \ \ | |_|_|_|_|_|_|/ / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | memquota: Add new add_parent() API Closes #2427 See merge request tpo/core/arti!3829
| * | | | | | | | memquota: Say what kind of errors add_parent() returnsGabriela Moldovan2026-04-071-2/+2
| | | | | | | | |
| * | | | | | | | memquota: Add dedicated variant for duplicate child errorGabriela Moldovan2026-04-073-2/+12
| | | | | | | | |
| * | | | | | | | memquota: Expand on the prepare_parent_aid() docsGabriela Moldovan2026-04-071-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Applies the suggestion from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3829#note_3388033
| * | | | | | | | memquota: Adjust Account::add_parent() docsGabriela Moldovan2026-04-071-3/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As suggested by @Diziet
| * | | | | | | | proto: Link the memquota circ acc with the outbound chan accGabriela Moldovan2026-03-301-6/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Closes #2427
| * | | | | | | | memquota: Make prepare_parent_aid() error message more genericGabriela Moldovan2026-03-301-2/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is now used by `Account::add_parent()` too.
| * | | | | | | | memquota: Add new Account::add_parent() APIGabriela Moldovan2026-03-302-0/+100
| | | | | | | | |
| * | | | | | | | memquota: Move parent AId checks to separate function (fmt)Gabriela Moldovan2026-03-301-8/+3
| | | | | | | | |
| * | | | | | | | memquota: Move parent AId checks to separate functionGabriela Moldovan2026-03-301-40/+50
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I am moving this to another function because we'll soon need to run these same checks in the new `Account::add_parent()` API I'm planning on adding for #2427.
* | | | | | | | | Merge branch 'closed-stream-err' into 'main'opara2026-04-072-9/+17
|\ \ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Change an error from `CircuitClosed` to `NotConnected` Closes #2421 See merge request tpo/core/arti!3825
| * | | | | | | | | arti: fix clippy warnings in `report_proxy_error()`Steven Engler2026-03-301-3/+5
| | | | | | | | | |
| * | | | | | | | | arti: use report macros in `report_proxy_error()`Steven Engler2026-03-301-5/+6
| | | | | | | | | |
| * | | | | | | | | arti: don't warn for `NotConnected` errorsSteven Engler2026-03-301-0/+1
| | | | | | | | | |
| * | | | | | | | | tor-proto: change an error to `NotConnected`Steven Engler2026-03-291-3/+7
| | |_|_|_|/ / / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Returning `CircuitClosed` isn't right here since the circuit may not have closed.
* | | | | | | | | Merge branch 'deftly-quoted' into 'main'Ian Jackson2026-04-0710-44/+44
|\ \ \ \ \ \ \ \ \ | |_|_|_|_|/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: Use new unquoted meta syntax for deftly attributes See merge request tpo/core/arti!3856
| * | | | | | | | tor-netdoc: parse2/encode derive: Use unquoted attributes at call sitesIan Jackson2026-04-076-18/+18
| | | | | | | | |
| * | | | | | | | tor-netdoc: parse2/encode derive: Show unquoted attributes in the docsIan Jackson2026-04-073-11/+11
| | | | | | | | |
| * | | | | | | | tor-netdoc: parse2/encode derive: Use meta_quoted rigorousIan Jackson2026-04-073-11/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The `doctype_for_error` attribute needs immediate adjustment, because a string expression value is expected. With `quoted retain`, that would be re-interpreted, silently. This kind of thing is why `quoted rigorous` exists. So change its docs and the one use site. The macros' docs, and the other calls ites, we'll deal with shortly.
| * | | | | | | | tor-netdoc: Constructor derive: Use meta_quoted rigorousIan Jackson2026-04-072-4/+4
|/ / / / / / / /
* | | | | | | | Merge branch 'chutney-enable-hs' into 'main'David Goulet2026-04-076-8/+45
|\ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | chutney CI: add hidden services See merge request tpo/core/arti!3858
| * | | | | | | | chutney CI: add hidden servicesJim Newsome2026-04-022-1/+23
| | | | | | | | |
| * | | | | | | | CI: bump chutneyJim Newsome2026-04-021-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Primarily to get recent improvements to bootstrap checking and reporting.
| * | | | | | | | NetDir::pick_relay: add a little more info to error reportsJim Newsome2026-04-021-1/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In particular to help debug arti#1907
| * | | | | | | | NetDir::pick_relay: add some trace loggingJim Newsome2026-04-021-1/+6
| | | | | | | | |
| * | | | | | | | hsdir_params: add debug log when we fall back to disaster paramsJim Newsome2026-04-021-2/+4
| | | | | | | | |
| * | | | | | | | tor-hsclient: include period metadata in trace log messageJim Newsome2026-04-021-1/+2
| | | | | | | | |
| * | | | | | | | chutney test: enable loggingJim Newsome2026-04-021-0/+2
| | | | | | | | |
* | | | | | | | | Merge branch 'circ-leg-warn' into 'main'gabi-2502026-04-071-1/+1
|\ \ \ \ \ \ \ \ \ | |_|_|_|/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Lower log level of "removing circuit leg" See merge request tpo/core/arti!3859
| * | | | | | | | tor-proto: lower log level of "removing circuit leg"Steven Engler2026-04-061-1/+1
|/ / / / / / / / | | | | | | | | | | | | | | | | | | | | | | | | This appears often in the arti logs, but is a normal thing to happen.
* | | | | | | | Merge branch 'stream-close' into 'main'opara2026-04-021-6/+12
|\ \ \ \ \ \ \ \ | |/ / / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Allow sending DATA cells on closed streams Closes #2434 See merge request tpo/core/arti!3824
| * | | | | | | tor-proto: allow sending DATA cells on closed streamsSteven Engler2026-03-291-6/+12
| |/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously we would close the circuit, which isn't great because there can be other streams in use on the circuit.
* | | | | | | Merge branch 'microdescs2' into 'main'Ian Jackson2026-04-0214-182/+729
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Microdescriptor parsing using parse2 See merge request tpo/core/arti!3797
| * | | | | | | tor-netdoc: Add TODO to test ignoringClara Engler2026-04-021-0/+1
| | | | | | | |
| * | | | | | | tor-netdoc: Disable broken test for nowClara Engler2026-04-021-0/+1
| | | | | | | |
| * | | | | | | tor-netdoc: Note on hardcoded test vectorsClara Engler2026-04-022-0/+10
| | | | | | | |
| * | | | | | | tor-netdoc: Fix typo in commentClara Engler2026-04-021-1/+1
| | | | | | | |
| * | | | | | | tor-netdoc: Some comment improvementsClara Engler2026-04-021-2/+4
| | | | | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson
| * | | | | | | tor-netdoc: Replace if by exhaustive matchClara Engler2026-04-021-2/+4
| | | | | | | |
| * | | | | | | tor-netdoc: Rename Wrapper to RawPortPolicyClara Engler2026-04-021-2/+2
| | | | | | | |
| * | | | | | | tor-netdoc: Use PortRanges::from_str in PortPolicy::from_strClara Engler2026-04-021-4/+1
| | | | | | | |
| * | | | | | | tor-netdoc: Document that an overflow is impossibleClara Engler2026-04-021-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit documents that a u16 overflow in a certain branch is impossible due to the properties of a BTreeSet over which an iteration takes place.