summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-proto: fix XON conversion from KB/s to B/sSteven Engler2026-07-301-4/+4
| | | | | | | | | | | | | | | We previously interpreted the rate in the XON message as being Kbits per second, but it's really Kbytes per second.
| * | tor-cell: update docs and variable names for `Xon`Steven Engler2026-07-303-13/+16
| | |
| * | tor-cell: update docs and variable names for `XonKBpsEwma`Steven Engler2026-07-301-9/+9
| | |
| * | tor-cell: rename `XonKbpsEwma` to `XonKBpsEwma`Steven Engler2026-07-3013-44/+44
|/ /
* | Merge branch 'mock-net' into 'main'David Goulet2026-07-302-31/+69
|\ \ | | | | | | | | | | | | tor-proto: Small improvements to circuit handshake tests See merge request tpo/core/arti!4254
| * | tor-proto: reuse existing channels in ntor testSteven Engler2026-07-301-8/+5
| | | | | | | | | | | | | | | Now that we read all of the cells from the connection inspector, we can reuse the existing channel objects.
| * | tor-proto: extend circ handshake tests to close the circuitSteven Engler2026-07-302-2/+38
| | |
| * | tor-proto: rename some methods on test `ConnInspector`Steven Engler2026-07-302-10/+10
| | |
| * | tor-proto: reword some TODOsSteven Engler2026-07-301-2/+2
| | | | | | | | | | | | These TODOs are for client issues, not relay isues.
| * | tor-proto: don't drop stream rx in testsSteven Engler2026-07-302-10/+15
| | | | | | | | | | | | Otherwise the new circuit gets closed immediately by the relay.
* | | Merge branch 'create-fast' into 'main'opara2026-07-305-37/+160
|\ \ \ | |/ / |/| | | | | | | | tor-protover,tor-proto: Add and use a new `subprotocol_restricted_set` macro See merge request tpo/core/arti!4241
| * | tor-protover: set field visibility in `subprotocol_restricted_set`Steven Engler2026-07-301-5/+5
| | |
| * | tor-proto: use `subprotocol_restricted_set` macroSteven Engler2026-07-303-37/+19
| | |
| * | tor-protover: add a `subprotocol_restricted_set` macroSteven Engler2026-07-302-0/+135
| | |
| * | tor-protover: add `From<NamedSubver> for Protocols`Steven Engler2026-07-271-0/+6
| | |
* | | Merge branch 'uploader-arc' into 'main'opara2026-07-304-18/+21
|\ \ \ | | | | | | | | | | | | | | | | tor-dirpublish: Change `Uploader::upload()` to not require `Arc<Self>` See merge request tpo/core/arti!4243
| * | | tor-dirpublish: change `Uploader::upload()` to not require `Arc`Steven Engler2026-07-304-18/+21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I was a bit confused as to why `Uploader::upload()` required an `Arc<Self>`, and after looking at the code it appears that this `Arc` isn't needed anywhere outside of the `PublishReactor`. Instead `Uploader::upload()` now takes a `&self` instead of `Arc<Self>`.
* | | | Merge branch 'verify-fix' into 'main'Clara Engler2026-07-301-7/+12
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Important pre-release fixes for RouterDescUnverified::verify() See merge request tpo/core/arti!4252
| * | | | tor-netdoc: Mark RouterDescUnverified::verify() incompleteClara Engler2026-07-301-0/+3
| | | | | | | | | | | | | | | | | | | | Better do it before the release so we can think about it a bit more.
| * | | | tor-netdoc: Properly obtain min/max for start and end timeClara Engler2026-07-301-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need to obtain the maximum of the lower bound and the minimum of the upper bound instead of vice versa. Another example on why we should replace this with a better implementation. Likewise, `expiry` in the legacy verification code is also obtained like that.
| * | | | tor-netdoc: Rename min/max to start and end timeClara Engler2026-07-301-5/+7
| | | | | | | | | | | | | | | | | | | | | | | | | This makes it more clear, besides it will sound more "correct" with the next commit applied.
* | | | | Merge branch 'testdata-typo' into 'main'Ian Jackson2026-07-302-3/+3
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: Fix typo in testdata-live-download and RELAY_* constants See merge request tpo/core/arti!4249
| * | | | | tor-netdoc: Fix typo in testdata-live-download and RELAY_* constantsIan Jackson2026-07-302-3/+3
| | |_|_|/ | |/| | | | | | | | | | | | | | | | | | I still had the previously downloaded full consensus locally, so running testdata-live-download fixed the Rust file.
* | | | | Merge branch 'mock-net' into 'main'David Goulet2026-07-305-0/+476
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | tor-proto: Add some unit tests for circuit handshakes See merge request tpo/core/arti!4248
| * | | | tor-proto: add unit tests for some circuit handshakesSteven Engler2026-07-291-0/+130
| | | | |
| * | | | tor-proto: add 'test_utils' mod for channel testsSteven Engler2026-07-292-0/+308
| | | | | | | | | | | | | | | | | | | | These help to establish connected channel objects to be used for tests.
| * | | | tor-proto: add test-only `NoOpChannelProvider`Steven Engler2026-07-291-0/+22
| | | | |
| * | | | tor-proto: add test-only `NoOpRequestFilter`Steven Engler2026-07-291-0/+16
| | | | |
* | | | | Merge branch 'rd-verify' into 'main'Clara Engler2026-07-304-8/+359
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Add RouterDescUnverified::verify() See merge request tpo/core/arti!4144
| * | | | tor-netdoc: Add various TODO follow-upsClara Engler2026-07-302-3/+8
| | | | |
| * | | | tor-netdoc: Make RouterDescUnverified::verify() publicClara Engler2026-07-302-2/+2
| | | | |
| * | | | tor-netdoc: Run cargo-fmtClara Engler2026-07-301-3/+13
| | | | |
| * | | | tor-netdoc: Allow dead_code for RouterDesc::verifyClara Engler2026-07-301-0/+1
| | | | | | | | | | | | | | | | | | | | Otherwise clippy complains.
| * | | | tor-netdoc: Add large RouterDesc verification testClara Engler2026-07-301-1/+169
| | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a comprehensive test for router descriptor verification that tests various valid and invalid edge cases.
| * | | | tor-netdoc: Enable cvt-x25519 for llcryptoClara Engler2026-07-301-1/+1
| | | | | | | | | | | | | | | | | | | | Required for convert_curve25519_to_ed25519_private().
| * | | | tor-netdoc: Add test only rd_encode_sign() methodClara Engler2026-07-301-0/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a bad encode_sign() method for RouterDesc that is testing only and will be used soon to implement testing for invalid router descriptors, for which we may need to create invalid ones in the first place.
| * | | | tor-netdoc: Call .verify() in test_parse2_simpleClara Engler2026-07-301-1/+8
| | | | |
| * | | | tor-netdoc: Add RouterDescUnverified::verify()Clara Engler2026-07-301-5/+118
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit implements verification for router descriptors. 🎉 For this, the following checks are performed: * RouterDesc::identity_ed25519 is validly signed. * RouterDesc::master_key_ed25519 is as implied by identity_ed25519. * RouterDesc::fingerprint is as implied by RouterDesc::signing_key. * RouterDesc::ntor_onion_key_crosscert is validly signed. * RouterDesc::signing_key has correct length and exponent. * All RouterDesc::family_cert elements are valid. * The inner and outer RouterDescSignatures are valid. Unfortunately, we now have two implementations for that, as the legacy parse_internal() also implements its own verification logic for this. It seems merging these two together however would probably cause more harm than good, as the legacy verification is closely intertwined with legacy parsing, making a commonly shared verification logic hard to achieve. In other words: parse2 parses the descriptor in its entirety first, followed by verification afterwards, whereas the legacy code parses and verifies every field before advancing towards the next. Instead, I suggest to read through RouterDesc::parse_internal() and ensure that every verification related check present there is also present here. The notable exception to this is everything TAP related, which is absent on purpose here. Right now, this code is untested. I will add unit tests shortly afterwards.
| * | | | tor-netdoc: Derive Copy for Ed25519PublicClara Engler2026-07-292-1/+2
| |/ / / | | | | | | | | | | | | The underlying type also implements Copy. We will need it later.
* | | | Merge branch 'relay-fix' into 'main'David Goulet2026-07-291-1/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-proto: Small build fix for tests with "relay" feature enabled See merge request tpo/core/arti!4247
| * | | | tor-proto: fix tests when `feature = relay`Steven Engler2026-07-291-1/+1
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ```text $ cargo test -p tor-proto --features relay [...] error[E0405]: cannot find trait `IncomingStreamRequestFilter` in this scope --> crates/tor-proto/src/circuit/reactor.rs:631:10 | 631 | impl IncomingStreamRequestFilter for AllowAllStreamsFilter { | ^^^^^^^^^^^^^^^^^^^^^^^^^^^ not found in this scope ```
* | | | Merge branch 'proto-relay-chan-log' into 'main'opara2026-07-291-2/+2
|\ \ \ \ | |/ / / |/| | | | | | | | | | | proto: Use PeerInfo to log responder channel addr See merge request tpo/core/arti!4245
| * | | proto: Use PeerInfo to log responder channel addrDavid Goulet2026-07-291-2/+2
|/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Inbound channel (as responder) don't have a ChannelMethod as they are not initiating the type of transport to use (PT vs Direct). It would result in a log line when receiving a channel request: DEBUG tor_proto::channel::handshake: Completed handshake without authentication to [? ] stream_id=Chan 2 This commit uses the `PeerInfo` which is wrapped in a `MaybeSensitive` and thus safe to log. Signed-off-by: David Goulet <[email protected]>
* | | Merge branch 'no-tap' into 'main'Ian Jackson2026-07-291-49/+1
|\ \ \ | | | | | | | | | | | | | | | | tor-netdoc: routerdesc: Abolish onion-key (obsolete TAP) field See merge request tpo/core/arti!4244
| * | | tor-netdoc: routerdesc: Abolish onion-key & -crosscert handling in old parserIan Jackson2026-07-291-38/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | `onion_key_crosscert` was already absent from `RouterDesc`, even though its item `onion-key-crosscert` was processed by the old parser. Delete it all.
| * | | tor-netdoc: routerdesc: Abolish onion-key (obsolete TAP) fieldIan Jackson2026-07-291-11/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | See prop350 https://spec.torproject.org/proposals/350-remove-tap.html This is part of "Phase 3, Item 2: Remove vestigial TAP code in Arti". Technically we are not at phase 3 yet, because we haven't yet sunsetted C Tor 0.4.8 and made the dirauth changes in Phase 2. However, this field is not used in Arti right now. RouterDescs are used by client code for handling bridges (but we never use TAP keys), and the RouterDesc type will be used for generation and mirroring by by Arti Relay/Dirauth. In prop350 we have decided that we won't be deploying Arti Relay until this as been done.
* | | | Merge branch 'todo-newcomer' into 'main'Ian Jackson2026-07-291-21/+23
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | CONTRIBUTING: Suggest the ticket tracker rather than TODO-hunting See merge request tpo/core/arti!4226
| * | | | CONTRIBUTING: Remove a stray backslashIan Jackson2026-07-281-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | This wasn't necessary, and when formatted with pandoc it appears in the output.
| * | | | CONTRIBUTING: Encourage asking on irc some moreIan Jackson2026-07-281-8/+10
| | | | |
| * | | | CONTRIBUTING: Improve best next stepsIan Jackson2026-07-281-2/+2
| | | | |