| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-dirclient: Attempt to explain AnonymizedRequest
See merge request tpo/core/arti!3767
|
| | | | | | | | |
|
| | |/ / / / / |
|
| |\ \ \ \ \ \
| |_|_|/ / /
|/| | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
keymgr: Update cert ArtiPath building to use denotator sets
Closes #2377
See merge request tpo/core/arti!3754
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3754#note_3361904
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit is intentionally misindented to make reviewing the diff a
bit easier.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
In a certificate's `ArtiPath`, the `ArtiPath` of the subject key is now
separated from the certificate denotators by `@`. This will enable us to
derive the subject key `ArtiPath` from the `ArtiPath` of its
certificate.
In practice, this change is a no-op for the relay implementation,
because none of our certificates have certificate denotators. For
instance, the `ArtiPath` of the for the `KP_relaysign_ed` certificate
(`KP_relaysign_ed` signed with `KS_relayid_ed`) is of the form
`relay/relaysign_ed+<valid_until>` (the only denotators here are the
denotators of the subject key).
It's important to note that the certifying key is not encoded in the
`ArtiPath` of the certificate. The implication is that if we'll ever
need to have multiple certs for the same subject key, signed with
different with different certifying keys, those certificates will be
distinguished by their certificate denotator group. So if we ever need a
second certificate for `KP_relaysign_ed`, certified with something other
than `KP_relaysign_ed`, it will need to be of the form
`relay/relaysign_ed+<valid_until>@<CERT_DENOS>`, where `<CERT_DENOS>`
is a list of `+`-separated certificate denotators.
Closes #2377
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This will enable us to parse certificate paths that consist of the
`ArtiPath` of the subject key, followed by the denotator group of the
certificate.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This introduces the concept of a "denotator group", and new syntax for
separating denotator groups within an ArtiPath.
The implementation will follow in a separate commit.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
`KeyCertificateSpecifiers` have an `ArtiPath`, so it's only natural to
retrieve it via this new `KeySpecifier` implementation.
This replaces the old, ad-hoc `ArtiPath` building from the `KeyMgr`
implementation: IMO, the `KeyMgr` impl is the wrong place to build these
`ArtiPath`s (ideally they should remain opaque to the `KeyMgr`).
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-netdir: Add is_flagged_exit() to RelayDetails
See merge request tpo/core/arti!3752
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
No need to over-engineer this, let's keep it simple.
|
| | |/ / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds a method called `is_flagged_exit` to `RelayDetails` in
order to check whether the node is considered to be usable as an exit or
not.
In the Tor VPN app, we need this feature for generating a list of exit
relays (per country). Right now, we do this in an incorrect way by only
checking on whether port 443 is in the exit policy, which is not a
sufficient criteria.
|
| |\ \ \ \ \ \
| |_|/ / / /
|/| | | | |
| | | | | |
| | | | | | |
rpc: Fix a bug related to stop_writing
See merge request tpo/core/arti!3762
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Without this, the poll() method wouldn't actually perform as
advertised.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
chutney test setup: fix override for arti-bench-bin
See merge request tpo/core/arti!3758
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This helps avoid subtle mismatches of the sort fixed in the previous
commit.
|
| | | |_|/ / /
| |/| | | |
| | | | | |
| | | | | |
| | | | | | |
We were accidentally using the arti-bin command-line arg to also
override arti-bench-bin.
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
keymgr: Test helper cleanup
See merge request tpo/core/arti!3761
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Resolves a clippy warning.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Resolves a clippy warning.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
As suggested by clippy
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This doesn't really need to be macro-generated, because these impls only
differ in the `KeystoreId`.
The code is intentionally misindented to make reviewing the diff a bit
easier. A future commit will reformat it all.
|
| | | | | | | |
|
| | | |/ / /
| |/| | |
| | | | |
| | | | |
| | | | | |
I am about to remove this macro altogether and simplify the keystore
impls, so I am preemptively moving this into a separate function.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
chutney test: finish converting to python
See merge request tpo/core/arti!3756
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Everything now uses the json version, instead.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
No particular need to separate them, and the merged version is easier to
follow.
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This organizes the code a bit better and gives nicer output. It also
separates individual test cases and subcases, continuing to try to
complete other tests when one fails instead of exiting.
|
| |\ \ \ \ \
| |_|/ / /
|/| | | |
| | | | |
| | | | | |
tor-dirserver: FSM Migration
See merge request tpo/core/arti!3664
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit changes the functionality of the AuthCerts state to only
report a success when at least a single certificate was included in the
response.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Adds a small TODO with regard to a potentially broken retry logic in the
proof-of-concept.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit documents why and how we use the `unsigned_` fields in the
`consensus_router_descriptor_member` table alongside SQL limitations.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit moves dirserver POC code to an own module to semantically
indicate it is not production ready.
|