aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | rpc: State that we're using I-JSONIan Jackson2023-03-241-0/+8
| | | |
| * | | rpc: Forbid troublesome numbers as idsIan Jackson2023-03-241-2/+4
| | | | | | | | | | | | | | | | | | | | This is a bit sad but I think we should have a conservative JSON profile.
| * | | rpc: Be more explicit about ignoring JSON fieldsIan Jackson2023-03-241-1/+4
| | | |
| * | | rpc: Clarify/restate method definition requirementsIan Jackson2023-03-241-9/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | In particular, abolish the notion of a "response type". Since responses don't come with a discriminant, each method may have only one success response format (although of course that format might itself have optional fields or be an enum or something).
| * | | rpc: Use Object for method targets and JSON object for document objectsIan Jackson2023-03-241-29/+31
| | | |
| * | | rpc: Make `params` in a request non-optionalIan Jackson2023-03-241-1/+5
| | | | | | | | | | | | | | | | | | | | | | | | *If* it is optional that would depend on the request, which is a bit complicated to specify precisely. And making it mandatory is more orthogonal.
* | | | Merge branch 'x25519' into 'main'Nick Mathewson2023-04-042-3/+3
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-llcrypto: Pin x25519-dalek version, bump our crate version Closes #807 See merge request tpo/core/arti!1108
| * | | | tor-llcrypto: Pin x25519-dalek version, bump our crate versiontor-llcrypto-v0.4.4Ian Jackson2023-04-042-3/+3
| | | | | | | | | | | | | | | | | | | | Fixes #807
* | | | | Merge branch 'timerange' into 'main'gabi-2502023-04-031-1/+35
|\ \ \ \ \ | |_|_|/ / |/| | | | | | | | | | | | | | Ergonomic improvements to TimerangeBound See merge request tpo/core/arti!1105
| * | | | TimerangeBound: Provide .as_ref() and .as_deref()Ian Jackson2023-04-031-1/+33
| | | | |
| * | | | TimerangeBound: derive Debug and Clone, and Eq/PartialEq in testsIan Jackson2023-04-031-0/+2
| | | | |
* | | | | Merge branch 'debug-hex' into 'main'Nick Mathewson2023-04-034-5/+92
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Debug two types as compact hex strings See merge request tpo/core/arti!1104
| * | | | Debug as hex strings for HsBlindId and HsDirIndexIan Jackson2023-03-313-5/+10
| | | | |
| * | | | tor-basic-utils: Provide impl_debug_hexIan Jackson2023-03-311-0/+82
| | | | |
* | | | | Merge branch 'hserror' into 'main'Ian Jackson2023-03-313-0/+52
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-error: Errors for hidden services See merge request tpo/core/arti!1099
| * | | | | tor-error: Add missing footnoteIan Jackson2023-03-311-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | I C&P this from tor-dirmgr, and missed this part.
| * | | | | Fix duplicated licence in Cargo.tomlgabi-2502023-03-311-1/+0
| | | | | |
| * | | | | tor-error: Add OnionServiceNotRunning errorIan Jackson2023-03-311-0/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We'll want this later. Define it now, though, since we've discussed it here https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1099#note_2892020
| * | | | | tor-error: Put OnionService errors behind a new experimental-api featureIan Jackson2023-03-313-0/+14
| | | | | |
| * | | | | tor-error: Document cargo featureIan Jackson2023-03-311-0/+4
| | | | | |
| * | | | | tor-error: Errors for hidden servicesIan Jackson2023-03-311-0/+18
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | So far these are just the errors that occur during descriptor fetch. There will be more later as we have more code in tor-hsconn. This is very user-facing; use the "onion service" terminology.
* | | | | Merge branch 'netdir' into 'main'Ian Jackson2023-03-312-29/+90
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdir: API changes to support hsconn hsdir fetch See merge request tpo/core/arti!1094
| * | | | | tor-netdir: iter_filter_secondary: Make it less of a messIan Jackson2023-03-301-13/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1094#note_2891857
| * | | | | tor-netdir: Expand on comment for HsRingRings::itergabi-2502023-03-301-1/+1
| | | | | |
| * | | | | tor-netdir: Minor docs fixesgabi-2502023-03-301-2/+3
| | | | | |
| * | | | | tor-netdir: Provide accessor for params field of HsDirParamsIan Jackson2023-03-301-0/+5
| | | | | |
| * | | | | tor-netdir: Implement hs_dirs accessorIan Jackson2023-03-301-2/+16
| | | | | |
| * | | | | tor-netdir: hs_dirs accessor: change semantics, type, and nameIan Jackson2023-03-301-7/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Don't have it take the TP, so that the caller must call it multiple times. Instead, have it return all the relevant relays.
| * | | | | tor-netdir: Provide hs_all_time_periods instead of ..._secondary_...Ian Jackson2023-03-301-5/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I don't think the server-side support will want to explicitly call current and then secondary. Rather, it will want to iterate over all the relevant ones. And fix the name, and add another comment about whether we need this.
| * | | | | tor-netdir: Rename hs_time_periodIan Jackson2023-03-301-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Change its name to hs_* like we do with things at this layer. But, it turns out, that at least for hs client connections to fetch the descriptor, I don't seem to need to call it yet ? Maybe it's not needed.
| * | | | | tor-netdir: Sort out HsDirOpIan Jackson2023-03-301-2/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Change its name to Hs* like we do with things at this layer * Make the Upload variant cfg-conditional
| * | | | | tor-netdir: Reorganise iteration over hsdir ringsIan Jackson2023-03-301-4/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Provide iter_for_op, by changing iter into iter_filter_secondary and having a new entrypoint iter.
| * | | | | tor-netdir: Provide relay_by_rs_idxIan Jackson2023-03-301-0/+16
| | | | | |
* | | | | | Merge branch 'docs-runes' into 'main'Ian Jackson2023-03-311-2/+5
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | CONTRIBUTING.md: Improve wording about docs builds recommendations See merge request tpo/core/arti!1090
| * | | | | CONTRIBUTING.md: Explicitly support --document-private-itemsIan Jackson2023-03-301-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We have many internal doc comments with curated links etc., so we should actually mention that formatting and reading those can be useful.
| * | | | | CONTRIBUTING.md: Recommend --workspace when building docsIan Jackson2023-03-301-2/+3
| | | | | |
* | | | | | Merge branch 'hsdesc-encoder-client-auth' into 'main'gabi-2502023-03-315-157/+310
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Stop requiring the caller to supply `AuthClient`s. See merge request tpo/core/arti!1087
| * | | | | | Generate a new KP_hss_desc_enc keypair for each new descriptor.Gabriela Moldovan2023-03-312-33/+51
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, to build descriptors for hidden services with client auth enabled, in addition to the list of authorized clients, users of `HsDescBuilder` were required to also provide a descriptor encryption keypair and a descriptor cookie. This was potentially dangerous and/or error-prone, because the ephemeral encryption key and the descriptor cookie are expected to be randomly generated and unique for each descriptor. This change makes `ClientAuth` private to the `hsdesc::build` module and updates `HsDescBuilder` to build `ClientAuth`s internally. Users now only need to provide the list of authorized client public keys. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | | | | Remove unnecessary test constant.Gabriela Moldovan2023-03-312-14/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It's not really needed, it can just be generated at (test) runtime. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | | | | Add an encode-decode test for descriptors with client auth.Gabriela Moldovan2023-03-311-23/+96
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a test for an `encode -> decode -> encode` flow for a hidden service descriptor with client authorization enabled. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | | | | Use constants instead of magic numbers.Gabriela Moldovan2023-03-311-6/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | | | | Stop requiring the caller to supply `AuthClient`s.Gabriela Moldovan2023-03-315-102/+166
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `AuthClient`s were originally meant to represent parsed `auth-client` lines. In !1070, this struct was repurposed for representing individual authorized clients in the HS descriptor encoder. However, hidden services will likely use a list of public keys to represent the authorized clients rather than a list of `AuthClient`s, as the information from an `AuthClient` (`client_id`, `iv`, `encrypted_cookie`) likely won't be immediately available to the hidden service. This change updates the HS descriptor encoder to represent authorized clients as a list of `curve25519::PublicKey`s. As such, it is now the responsibility of the encoder to create the `client_id`, `iv`, and `encrypted_cookie` using the available keys, the unencrypted descriptor cookie, and HS subcredential. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | | | | Merge branch 'update_once_more' into 'main'gabi-2502023-03-311-82/+25
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Run cargo-update to move away from yanked versions of "windows" See merge request tpo/core/arti!1103
| * | | | | | Run cargo-update to move away from yanked versions of "windows"Nick Mathewson2023-03-311-82/+25
|/ / / / / / | | | | | | | | | | | | | | | | | | (cargo-audit is complaining about these and breaking CI)
* | | / / / Remove semver.md files.Nick Mathewson2023-03-318-13/+0
| |_|/ / / |/| | | |
* | | | | Remove "publish = false" from tor-hsclient.arti-v1.1.3Nick Mathewson2023-03-311-2/+0
| | | | | | | | | | | | | | | | | | | | It is now a (conditional, experimental) dependency of arti-client.
* | | | | Merge branch 'version_bump' into 'main'gabi-2502023-03-3134-209/+209
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Bump versions for today's release of arti 1.1.3 See merge request tpo/core/arti!1102
| * | | | | Patchlevel bumps for crates whose dependencies just changed.Nick Mathewson2023-03-3119-33/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These crates had no changes until just a moment ago. But since we updated the versions on some of their dependents, they have now changed themselves. Thus they get patchlevel bumps. ``` tor-rtmock tor-protover tor-socksproto tor-consdiff tor-chanmgr tor-dirclient tor-hsservice ```
| * | | | | Bump crate versions that have breaking changesNick Mathewson2023-03-3121-32/+32
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These crates have had breaking changes. They are pre-1.0, so they get a minor bump. ``` tor-basic-utils tor-config ```
| * | | | | Bump patchlevel on crates with non-breaking changesNick Mathewson2023-03-3129-126/+126
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | For these crates, the changes are nontrivial, so we _do_ bump the versions on which their dependent crates depend. Fortunately, since they are all pre-1.0, we don't need to distinguish semver-additions from other changes. (Except for arti, which _is_ post-1.0, but gets a patchlevel bump anyway.) These are unstable crates with breaking changes: ``` tor-hscrypto tor-hsclient ``` These have new or extended APIs: ``` safelog tor-bytes tor-cell tor-linkspec tor-llcrypto tor-proto tor-cert arti-client ``` These have new unstable APIs or features: ``` tor-netdoc tor-circmgr (also broke some unstable APIs) arti (is post-1.0) ``` These have bugfixes only: ``` caret tor-dirmgr ```