aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | tor-netdoc testdata-live: Run a downloadIan Jackson2026-07-2328-356/+367
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This updates everything, but really I'm just running it to create the new selected_relays.rs file. The meaning of this file will become clear shortly.
| * | | | tor-netdoc testdata-live: Write out a selected_relays.rs fileIan Jackson2026-07-231-0/+17
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We could use build.rs for this, but since we have a script already, this seems better. The meaning of this file will become clear shortly.
* | | | | Merge branch 'promote-supported-consensus' into 'main'gabi-2502026-07-276-17/+37
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Move supported consensus methods iteration to tor-dirauth from arti-dirauth See merge request tpo/core/arti!4234
| * | | | | Move supported consensus methods iteration to tor-dirauth from arti-dirauthIan Jackson2026-07-236-17/+37
| | |/ / / | |/| | | | | | | | | | | | | Now we provide SupportedConsensusMethod::iter_all().
* | | | | Merge branch 'use-chutney-shadow' into 'main'Jim Newsome2026-07-237-47/+104
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | integration-e2e-shadow: initialize network outside of shadow This is progress towards generating multi-host simulations; we want to use the generated network specification when generating the shadow config, so the former has to happen before we start shadow. Progress on #1683 See merge request tpo/core/arti!4211
| * | | | | .gitignore: ignore default integration-e2e-shadow output dirJim Newsome2026-07-231-0/+2
| | | | | |
| * | | | | integration-e2e-shadow: change default data-dir to TOPLEVEL/chutney-netJim Newsome2026-07-232-3/+5
| | | | | |
| * | | | | integration-e2e-shadow: move artifacts into nodes dirJim Newsome2026-07-233-18/+23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This keeps everything together and avoids clobbering previous artifacts, since chutney already creates a unique nodes dir in every run.
| * | | | | integration-e2e-shadow: config and init outside of shadowJim Newsome2026-07-231-10/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes the chutney network configuration available *before* we generate the shadow config file, which we need in order to generate multi-host networks.
| * | | | | chutney test: split network init from network bootstrapJim Newsome2026-07-233-10/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is in preparation to move the init step outside of the shadow simulation in integration-e2e-shadow (while leaving the bootstrap step inside the shadow simulation).
| * | | | | integration-e2e-shadow: inline integration-e2eJim Newsome2026-07-231-2/+30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is in preparation to diverge somewhat. In particular, we want to do some of the configuration and setup from *outside* of shadow, so that we can generate shadow configs that take the chutney network configuration into account.
| * | | | | integration-e2e-shadow: add support for subcommandsJim Newsome2026-07-231-1/+3
| | | | | |
| * | | | | integration-e2e-shadow: split out helper _configure_and_run_shadowJim Newsome2026-07-231-10/+13
|/ / / / /
* | | | | Merge branch 'limit_warn' into 'main'Jim Newsome2026-07-232-3/+47
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | arti: Ratelimit proxy error reports See merge request tpo/core/arti!4158
| * | | | | arti: Ratelimit proxy error reportssyphyr2026-07-232-3/+47
|/ / / / / | | | | | | | | | | | | | | | Implement log_ratelim! in report_proxy_error
* | | | | Merge branch 'circhop-handlemsg' into 'main'gabi-2502026-07-233-9/+9
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | proto: Remove feature-gating from CircHop::handle_msg() See merge request tpo/core/arti!4230
| * | | | proto: Include the actual cell command in an error messageGabriela Moldovan2026-07-231-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This can happen if we get an unexpected BEGIN_DIR/RESOLVE too, so we can't hard-code "BEGIN" in the error message. Context: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4230#note_3439258,
| * | | | proto: Remove feature-gating from CircHop::handle_msg()Gabriela Moldovan2026-07-233-6/+4
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This feature-gating has been a source of confusion, and it unnecessarily complicates the stream message handling flow. I've previously argued in favour of keeping it, in the spirit of a belt and braces approach to message validation, but I've been convinced that in this particular case, the feature-gate is more trouble than it's worth. What makes things worse is that the `CircHop::handle_msg()` function was designed poorly (by yours truly). I plan on refactoring it at some point, hopefully soon. There is a TODO about this below its doc comment.
* | | | Merge branch 'arti-authority-plugin-1' into 'main'Ian Jackson2026-07-237-0/+236
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti-dirauth: Build an arti consensus method plugin binary, and implement list-methods See merge request tpo/core/arti!4225
| * | | | arti-dirauth: Correct URL for authority-plugin.mdIan Jackson2026-07-231-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will appear when the MR is merged. As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4225#note_3439197
| * | | | arti-dirauth: FilenameOrStdio: Add doc and comments about permissionsIan Jackson2026-07-231-0/+3
| | | | |
| * | | | arti-dirauth: FilenameOrStdio: Discussion of leftover .tmp filesIan Jackson2026-07-231-0/+11
| | | | |
| * | | | arti-dirauth: FilenameOrStdio: Clarify a TODOIan Jackson2026-07-231-1/+2
| | | | |
| * | | | arti-dirauth: Provide a command to dump the specIan Jackson2026-07-231-0/+21
| | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4225#note_3438787
| * | | | arti-dirauth: Move plugin spec to crate subdirIan Jackson2026-07-231-0/+0
| | | | |
| * | | | arti-dirauth: Add a divider commentIan Jackson2026-07-231-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4225#note_3438786
| * | | | arti authority plugin: Implement list-methodsIan Jackson2026-07-212-4/+27
| | | | |
| * | | | arti authority plugin: FilenameOrStdio utilityIan Jackson2026-07-212-0/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Although we have other places in-tree where we do this very standard thing, we don't seem to have an affordance for it. I doubt we want to add a dependency just for this, so roll our own.
| * | | | arti authority plugin: Command line parsing skeletonIan Jackson2026-07-213-1/+82
| | | | |
| * | | | arti-dirauth: Build an arti consensus method plugin binaryIan Jackson2026-07-214-0/+28
| | |/ / | |/| | | | | | | | | | This just panics, right now.
* | | | Merge branch 'refactor-tor-dirmgr-0' into 'main'Jim Newsome2026-07-231-102/+180
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-dirmgr: Refactor function download See merge request tpo/core/arti!4204
| * | | | tor-dirmgr: Refactor bootstrap::downloadhjrgrn2026-07-231-102/+180
| | |/ / | |/| | | | | | | | | | | | | | | | | | | | | | - Add helper functions: perform_download, advance_state, apply_state, and update_state - Add enum used in said helper functions: DownloadOutcome and AdvanceStateError - Add minor improvements on the readability of the entire sub-module
* | | | Merge branch 'dynasm' into 'main'opara2026-07-234-37/+37
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | hashx: Update dynasmrt to 5.1.0 Closes #2637 See merge request tpo/core/arti!4232
| * | | | hashx,equix: update bench Cargo.lockSteven Engler2026-07-232-24/+24
| | | | | | | | | | | | | | | | | | | | This was forgotten in the previous commit.
| * | | | hashx: update dynasmrt to 5.1.0Steven Engler2026-07-232-13/+13
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | This fixes a rust future-incompatibilities warning, which was caused by the proc-macro-error2 crate. The dynasmrt crate switched to a fork proc-macro-error3 to fix this.
* | | | Merge branch 'rsa-1024' into 'main'David Goulet2026-07-231-1/+21
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-cert-x509: Fix RSA key size check Closes #2626 See merge request tpo/core/arti!4231
| * | | | tor-cert-x509: fix size check in `create_legacy_rsa_id_cert`Steven Engler2026-07-231-3/+5
| | | | |
| * | | | tor-cert-x509: add unit test demonstrating bugSteven Engler2026-07-231-0/+18
| |/ / /
* | | | Merge branch 'timebound-overhaul' into 'main'Ian Jackson2026-07-2334-204/+524
|\ \ \ \ | |/ / / |/| | | | | | | | | | | Overhaul tor_checkable's TimeBound See merge request tpo/core/arti!4223
| * | | tor-netdoc: HsDesc parse_decrypt_validate: Fix docs re time boundsIan Jackson2026-07-231-1/+2
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4223#note_3438348
| * | | tor-checkable: Fix a wrong ref in semver.mdIan Jackson2026-07-231-1/+1
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4223#note_3438344
| * | | tor-checkable: Improve/fix a commentIan Jackson2026-07-231-1/+2
| | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4223#note_3438341
| * | | tor-checkable: Fix punctuation in commentIan Jackson2026-07-231-1/+1
| | | |
| * | | tor-checkable: Fix a doc comment copypastaIan Jackson2026-07-231-1/+1
| | | |
| * | | tor-checkable: Fix two doc comments start/endIan Jackson2026-07-231-2/+2
| | | |
| * | | tor-hsclient: connect.rs: Remove a redundant map_errIan Jackson2026-07-231-2/+1
| | | |
| * | | HsDesc::parse_decrypt_validate: Don't check validity time (style followup)Ian Jackson2026-07-231-5/+3
| | | |
| * | | HsDesc::parse_decrypt_validate: Don't check validity timeIan Jackson2026-07-234-9/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This function returns a `TimeRangeBound`. That implies a responsibility on the caller to check the time. It doesn't make sense for this function to do the check as well. But, it turns out that in tor-hsclient, the `TimeRangeBound<HsDesc>` is sometimes processed with `.dangerously` on the assumption that it was checked earlier. I considered changing this, and storing plain `HsDesc` and a separate `TimeRange` - but that's not right, because there are places where the `TimeRangeBound<HsDesc>` is used well after it was verified. Instead, in this commit, I (effectively) move the `.check_valid_at` call from `parse_decrypt_validate` to its principal call site. This involves a change to the error representation. Previously, validity time errors ended up as `DescriptorErrorDetail::Descriptor` containing an `HsDescError::OuterValidation` HsDescError:: InnerValidation`, which in turn contains a `tor_netdoc::Error`. (`tor_netdoc::Error` is a rather awkward type.) Now we have our own error variant. The overall behaviour is unchanged.
| * | | tor-netdoc: hsdesc: Use new TimeRangeBound::build_intersect (fmt)Ian Jackson2026-07-231-5/+4
| | | |
| * | | tor-netdoc: hsdesc: Use new TimeRangeBound::build_intersectIan Jackson2026-07-231-27/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Replace open-coding of various is_valid_at and various dangerously and intersect. In more detail: * Do most of the processing inside `TimeRangeBound::build_intersect` * Replace uses of dangerously_peek etc. with `TimeBound::unwrap_with` * The timebound machinery now takes care of doing the intersection * Remove the individual `.is_valid_at` calls and replace them with one at the end, on the intersection. This preserves the current behaviour except that sometimes time validity errors will now be reported as having occurred the wrong level. We'll deal with this in a moment (by deleting these checks from here entirely). * There is no need to handle a `None` from `intersect` any more. TimeBound handles conflicting time ranges differently: it allows ranges which are empty due to being ill-formed.