| Commit message (Collapse) | Author | Age | Files | Lines |
| |\
| |
| |
| |
| | |
CI; Mark check-api-surface as may-fail
See merge request tpo/core/arti!4185
|
| | |
| |
| |
| | |
See #2616.
|
| | | |
|
| |\ \ |
|
| | | | |
|
| | | | |
|
| | | | |
|
| |\ \ \
| |_|/
|/| | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Closes #2617.
We've lucked out this time, and it turns out that every one of our
published crates gets a minor bump. So this was generated with:
```
for cr in $(./maint/list-crates); do
cargo set-version -p $cr --bump minor
done
```
|
| |\ \ \
| |_|/
|/| |
| | |
| | | |
Run "fixup-features" and clean up the result.
See merge request tpo/core/arti!4180
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
It was both in "metrics" and in "experimental"; I think the latter
was intended.
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Update changelog for Arti 2.5.0
See merge request tpo/core/arti!4179
|
| | | |/
| |/| |
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Update release date for 2.5.0
See merge request tpo/core/arti!4183
|
| |/ / |
|
| |/
|
|
|
|
|
|
|
|
| |
Instead of doing an O(n) check every time we add an unrecognized
protocol, we just scan the list of unrecognized protocols
after we sort them.
Closes #2601.
Resolves TROVE-2026-027.
|
| |\
| |
| |
| |
| | |
Add Windows compatibility for maint/add_warning
See merge request tpo/core/arti!4084
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | | |
tor-basic-utils: Don't include '-' in random hostnames
See merge request tpo/core/arti!4178
|
| |/ / |
|
| |\ \
| | |
| | |
| | |
| | | |
deps: Upgrade anyhow in 'Cargo.lock' (RUSTSEC-2026-0190)
See merge request tpo/core/arti!4174
|
| |/ /
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This resolves unsoundness in anyhow (RUSTSEC-2026-0190).
https://rustsec.org/advisories/RUSTSEC-2026-0190.html
> Affected versions of this crate violate borrow rules, resulting in
> undefined behavior, when the user adds context to an error via
> `Error::context` and then later calls `Error::downcast_mut` on the
> returned `Error`.
I don't see us calling `downcast_mut()` on any errors. It's possible
something outside of the arti code base is calling it, but I think it's
unlikely.
|
| |\ \
| | |
| | |
| | |
| | | |
Derive more Eq in tor-cert and tor-netdoc
See merge request tpo/core/arti!4150
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This commit derives PartialEq and Eq on the "core" certificate types in
lib.rs, i.e. the Ed25519 certificates and its adjacent data types.
We will need this for proper PartialEq and Eq handling in tor-netdoc at
one point.
|
| |\ \ \
| |/ /
|/| |
| | |
| | |
| | |
| | | |
arti-relay: Set incoming stream filters via the CREATE handler
Closes #2582 and #2577
See merge request tpo/core/arti!4145
|
| | | |
| | |
| | |
| | |
| | | |
Suggested by opara in
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4145#note_3430815
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Now that relays no longer use `CtrlCmd::AwaitStreamRequests`, some of
these fields are unused. I'm leaving them in for now, but we should
remove them if they're still unused after we finish the circ reactor
impl.
I'm not removing `AwaitStreamRequests`, because it will be needed by
onion services, when we replace the old client circuit reactor with the
new one.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
We don't need it anymore now that `RelayCirc`s always allow incoming
stream requests.
The previous design, where you could build a `RelayCirc` that didn't
allow stream requests, was a leftover from the onion service
`ClientCirc` implementation that this was inspired from (onion services
*do* need the two to be decoupled, because incoming stream requests are
only allowed on the virtual hop, after it's established).
Closes #2582
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This implements what we discussed in
`doc/dev/notes/relay-streams.md` (lines 218-234):
> Currently, to allow incoming stream requests on a circuit,
> you first need to call `RelayCirc::allow_stream_requests()`
> to install a `CmdChecker` and `IncomingStreamRequestFilter`.
> This is not ideal, because `allow_stream_requests()` will need to be
> called unconditionally, on each `RelayCirc`,
> right after it's created in the `CreateHandler` impl
> (which in turn, would mean making `handle_create()` async too,
> because `allow_stream_requests()` is async, which wouldn't be great).
>
> So, the first step here is to rework the `RelayCirc` API to make relay circuits
> be constructable with a list of allowed `RelayCmd`s and `IncomingStreamRequestFilter`
> from the get-go ([#2582]), and to get rid of `allow_stream_requests()`,
> which will enable the `CREATE*` handler to remain non-`async`.
>
> In any case, the `CREATE*` handler will still require some changes,
> because it needs to be initialized with an `IncomingStreamRequestFilter`,
I am not sure using an `IncomingStreamRequestFilter` "factory" is
necessarily the right approach here, but the circuit `Reactor`'s
constructor needs to take an `IncomingStreamRequestFilter`, and
`IncomingStreamRequestFilter` is not `Clone` (and FWIW, I think it's
better if we don't make it `Clone`).
One obvious limitation is that the `IncomingStreamRequestFilter` of the
circuit reactor is fixed for the entire lifetime of the circuit.
In practice, I don't think this is going to be a problem,
because the arti-relay `IncomingStreamRequestFilter` is only going
be used for
* preventing single-hop exit streams
* per-circuit rate-limiting.
Both of these checks will require the filter to have access to a recent
`NetDir`, which is straightforward if the filter has an Arc<dyn
NetDirProvider> (as mentioned in doc/dev/notes/relay-streams.md,
`NetDirProvider` has a handy non-async `timely_netdir()` function we can
use). And since these checks are based on consensus params, we don't
really need to ever update an already-built circuit with a new
`IncomingStreamRequestFilter` (because all `IncomingStreamRequestFilter`
will have the ability to obtain a fresh `NetDir` as needed).
Nevertheless, I left a TODO about this, because I expect this type to
change once we figure out all the other pieces needed for #1448.
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Part of #2582
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Relay circuits always need a filter, so it's best to set it via the
constructor.
Part of #2582
Closes #2577
|
| |/ /
| |
| |
| |
| |
| | |
This is currently just a placeholder that accepts all stream requests.
It will be fleshed out later, as part of #1448
|
| |\ \
| | |
| | |
| | |
| | | |
tor-netdoc: Fix Ed25519NtorCrossCert range
See merge request tpo/core/arti!4173
|
| | | |
| | |
| | |
| | | |
No longer required because it implements Copy.
|
| |/ /
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This commit fixes the range to NOT include SystemTime::UNIX_EPOCH.
This is because TimerangeBound makes a difference between a lower bound
being Some or None.
This was discovered later during test and is crucial to properly detect
a minimum in the yet-to-be-merged .verify() method for router
descriptors.
|
| |\ \
| | |
| | |
| | |
| | | |
removed unnecessary PinBox wrapper
See merge request tpo/core/arti!4172
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-netdoc: ExpandedKeypair for Ed25519NtorCrossCert::new_signed()
See merge request tpo/core/arti!4155
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This commit changes Ed25519NtorCrossCert::new_signed() to accept an
ExpandedKeypair instead of a Keypair, because when converting the ntor
key using convert_curve25519_to_ed25519_public(), only the
ExpandedKeypair is returned, which is a one-way conversion from Keypair.
|
| |\| | |
| | | |
| | | |
| | | |
| | | | |
tor-llcrypto: Implement Ed25519PublicKey for ExpandedKeypair
See merge request tpo/core/arti!4154
|