aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'extra-info-init' into 'main'Nick Mathewson8 days2-0/+245
|\ | | | | | | | | Initialize extra-info module See merge request tpo/core/arti!4284
| * tor-netdoc: Initialize extra-info moduleClara Engler2026-08-052-0/+245
| | | | | | | | | | | | | | | | | | | | | | This commit initializes the doc::extra_info module in tor-netdoc, which is still marked as incomplete and will be extended in the future. Right now, it is very barebones by only supporting the introduction item as well as the bare minimum required for verification. It also adds a simple unit test, which iterates over the available test data, parses and verifies it.
* | Merge branch 'proto-relay-fix' into 'main'gabi-2508 days1-1/+1
|\ \ | | | | | | | | | | | | tor-proto: Fix tests build error when "testing" feature isn't enabled See merge request tpo/core/arti!4319
| * | tor-proto: make 'testing_exports' available to own unit testsSteven Engler9 days1-1/+1
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes: ```text $ cargo test -p tor-proto --features relay error[E0603]: enum import `CtrlMsg` is private --> crates/tor-proto/src/relay/reactor.rs:463:33 | 463 | use crate::channel::CtrlMsg; | ^^^^^^^ private enum import | note: the enum import `CtrlMsg` is defined here... --> crates/tor-proto/src/channel.rs:117:5 | 117 | use testing_exports::*; | ^^^^^^^^^^^^^^^^^^ note: ...and refers to the enum import `CtrlMsg` which is defined here... <snip> ``` There are a few ways we could fix this, but I don't see an advantage of one over another.
* | Merge branch 'destroy-on-drop' into 'main'gabi-2509 days6-71/+208
|\ \ | | | | | | | | | | | | | | | | | | proto: Avoid sending DESTROY if we have received DESTROY Closes #2646 and #2648 See merge request tpo/core/arti!4312
| * | proto: Extend test to check DESTROY is sent to the next hopGabriela Moldovan9 days1-0/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This extends the `destroy_from_client()` test to also check that a DESTROY received from the client (or, more generally speaking, from the "inbound channel") is actually forwarded to the next hop. The reason the `assert_destroy_sent()` assertion is commented out is specified in the TODO that precedes it (tldr: testing the DESTROY behaviour involves both the channel reactor and the circuit reactor, and our test setup is currently quite limited, in that it doesn't actually exercise the right channel reactor code paths for the *inbound* channel). I plan to address this soon.
| * | proto: Move assert_cell_is_destroy macro out of helper functionGabriela Moldovan9 days1-15/+15
| | | | | | | | | | | | I am about to need this in a test.
| * | proto: Add comments explaining why the tests use DestroyDirection::BackwardGabriela Moldovan9 days1-2/+14
| | |
| * | proto: Remove misleading comment and rename misnamed variableGabriela Moldovan9 days1-3/+2
| | | | | | | | | | | | This fixes an old bad copy-paste that I've just noticed.
| * | proto: Clarify what read_{inbound,outbound} are forGabriela Moldovan9 days1-0/+14
| | | | | | | | | | | | This adds an example suggested by opara.
| * | proto: Update the tests to check DESTROY is only sent when neededGabriela Moldovan9 days1-25/+72
| | |
| * | proto: Allocate a real circ id in the circ reactor testsGabriela Moldovan9 days1-13/+47
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need this because the channel reactor now only sends DESTROY for circuits that are still in the circ map (and we are about to test this behaviour, so we need the circuit map to actually have an entry for our test circuit). Initially, these tests were meant to test the circuit reactor in isolation, but they've gradually grown more complex, and now require a semi-working channel reactor. In the long run, I think I'd like to: * change the tests from `tor_proto::relay::reactor` to use a proper relay channel reactor as opposed to a `working_dummy_channel()`, and to initialize a circuit through the normal means, namely by sending a CREATE2 through the channel reactor (naturally, this "proper relay channel reactor" still wouldn't be connected to the network). These will test the integration between the channel and the circuit reactor, as well as the circuit reactor behaviour * add new, implementation-agnostic tests for the generic multi-reactor system. These will use a mock channel reactor
| * | proto: Make Channel::send_control() pub(crate) for testingGabriela Moldovan9 days1-0/+1
| | | | | | | | | | | | | | | | | | The relay circuit reactor tests will soon need the ability to send control messages (for allocating a circuit id for the circuit reactor under test).
| * | proto: Expect a now-unused test function to be dead codeGabriela Moldovan9 days1-0/+1
| | |
| * | proto: Update create handler tests to no longer expect DESTROYGabriela Moldovan9 days1-18/+6
| | | | | | | | | | | | | | | Now that we no longer respond to DESTROY by sending a DESTROY ourselves, these tests need to be updated.
| * | proto: s/client/next hop in test commentGabriela Moldovan9 days1-1/+1
| | | | | | | | | | | | This test simulates the *next hop* sending us a DESTROY.
| * | proto: Avoid sending DESTROY if we have received DESTROYGabriela Moldovan9 days2-0/+25
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | This change prevents the channel reactor from sending DESTROY cells on already-closed (or non-existent) circuits. Upon receiving a DESTROY cell, the channel reactor removes the corresponding circuit entry, if any, from its circmap. It then passes the DESTROY to the circuit reactor for handling. The circuit reactor handles it by shutting down, and calling `Channel::close_circuit()` on drop. Previously, this would unconditionally send a DESTROY cell, which caused #2648 and #2646. This affects both clients and relays, because both circuit reactors call `Channel::close_circuit()` on drop. Closes #2648, #2646
* | Merge branch 'ahf/fix-load-store-path-formatting' into 'main'opara9 days1-1/+2
|\ \ | | | | | | | | | | | | tor-persist: fix display of Target path(s). See merge request tpo/core/arti!4317
| * | tor-persist: fix display of Target path(s).Alexander Hansen Færøy9 days1-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This patch changes how display works on our Target struct. Currently, log messages generated by Arti Relay looks like this: `tor_persist::load_store: storing "/path/to/arti-relay/state"/"circuit_timeouts.json"` With this patch applies it instead looks like this: `tor_persist::load_store: storing "/path/to/arti-relay/state/circuit_timeouts.json"` With this change we ensure that the correct delimiter between the directory and the filename is used (on Unix it's "/", but on Windows it's "\") and we also avoid the added "" around both the directory and filename.
* | | Merge branch 'ci-cleanup' into 'main'Jim Newsome9 days1-3/+14
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | CI: Reduce disk usage after job ends Closes #2669 and #2672 See merge request tpo/core/arti!4316
| * | | ci: clean up build artifacts in 'deb-binary-{amd,arm}64' jobsSteven Engler10 days1-0/+3
| | | |
| * | | ci: `rm -r ./target` in 'after_script'Steven Engler10 days1-3/+7
| | | |
| * | | ci: show disk usage of project directorySteven Engler10 days1-0/+4
| |/ /
* | | Merge branch 'bump-hyper' into 'main'Nick Mathewson9 days1-16/+16
|\ \ \ | |/ / |/| | | | | | | | maint/cargo-audit: Bump h2 to address RUSTSEC-2026-0258 See merge request tpo/core/arti!4318
| * | maint/cargo-audit: Bump h2 to address RUSTSEC-2026-0258Gabriela Moldovan9 days1-16/+16
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Older versions of `h2` have a bug that causes empty HTTP/2 DATA frames to be queued without limit if the streams are not read from quickly enough. According to the [hyper advisory]: > To determine if vulnerable, all these things must be true: > > * You are using HTTP/2, either as a server or a client. > * Your application does not fully drain incoming request > or response bodies (for example, a proxy applying backpressure, > or a client that delays reading the body). > * The direct remote peer is malicious and intentionally > sends large numbers of empty DATA frames. To my knowledge, the only non-example crates that use `hyper` are `arti` and `tor-dirserver`. Both of them run HTTP/1.1 servers, so I don't believe we're affected by the `h2` bug. [hyper advisory]: https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h
* | Merge branch 'all_bind_addr_fail' into 'main'Jim Newsome10 days1-1/+6
|\ \ | | | | | | | | | | | | refactor: fail when all addresses bind fail See merge request tpo/core/arti!4309
| * | bind_dns_resolver: fail when no addresses in a group can bindSteven Masnada10 days1-1/+6
| | |
* | | Merge branch 'config-refactor-v3' into 'main'Nick Mathewson10 days3-130/+176
|\ \ \ | | | | | | | | | | | | | | | | arti: refactor reload_cfg in preparation for RPC work See merge request tpo/core/arti!4310
| * | | Apply 1 suggestion(s) to 1 file(s)Nick Mathewson10 days1-1/+1
| | | | | | | | | | | | Co-authored-by: gabi-250 <[email protected]>
| * | | Reindent impl block.Nick Mathewson14 days1-87/+88
| | | |
| * | | Move reload_configuration method.Nick Mathewson14 days1-40/+37
| | | | | | | | | | | | | | | | Code movement only.
| * | | reload_cfg: Refactor to use a CfgMgr object.Nick Mathewson14 days2-87/+134
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Right now this just helps us keep the parts of the configuration-reloading logic in one place, and clarifies what needs to be owned by the watcher thread and what doesn't. Moving forward, this will help make the configuration something that RPC can inspect and change.
| * | | tor-config: Make FileWatcher must_use.Nick Mathewson14 days1-0/+1
| | | | | | | | | | | | | | | | | | | | (If you drop a FileWatcher, the thread that makes it works will exit.)
* | | | Merge branch 'proto-docs' into 'main'opara10 days2-25/+29
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | Update the relay circuit reactor docs See merge request tpo/core/arti!4313
| * | | README_relay: Check off a couple of circuit reactor itemsGabriela Moldovan10 days1-2/+2
| | | |
| * | | proto: Remove redundant headingGabriela Moldovan10 days1-2/+0
| | | | | | | | | | | | | | | | | | | | | | | | There is no `BackwardReactor` heading, because there isn't that much to say about it (it moves `RELAY` cells in the opposite direction, and rejects RELAY_EARLY and PADDING_NEGOTIATE).
| * | | proto: Update table to mention all the other commands we handleGabriela Moldovan10 days1-2/+8
| | | |
| * | | proto: Be more specific about where the meta messages are handledGabriela Moldovan10 days1-14/+15
| | | |
| * | | proto: Say how forward DESTROY are handledGabriela Moldovan10 days1-1/+2
| | | |
| * | | proto: Clarify that "it" refers to the forward reactorGabriela Moldovan10 days1-1/+2
| | | |
| * | | proto: Update docs to clarify they apply to RELAY_EARLY tooGabriela Moldovan10 days1-3/+2
| | | |
| * | | proto: Update docs to say EXTEND2 is supportedGabriela Moldovan10 days1-5/+2
| | | |
| * | | proto: Update reactor docs to say TRUNCATE is unsupportedGabriela Moldovan10 days1-2/+3
|/ / /
* | | Merge branch 'take_until_with_limit' into 'main'Nick Mathewson14 days2-10/+90
|\ \ \ | | | | | | | | | | | | | | | | Add take_until_with_limit methods for better developer experience, modified error handling, changed take_until to use take_until_with_limit and added tests. See merge request tpo/core/arti!4082
| * | | Add take_until_with_limit methods for better developer experience,pryty262026-07-022-10/+90
| | | | | | | | | | | | | | | | | | | | These methods provide modified error handling, changed take_until to use take_until_with_limit and added tests.
* | | | Merge branch 'refactor-use-task-handler' into 'main'Nick Mathewson14 days2-20/+13
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | refactor(tor-hsclient): use TaskHandle for expiring circuit task See merge request tpo/core/arti!4290
| * | | | refactor: use TaskHandle for expiring circuitiqdecay14 days2-20/+13
| | | | |
* | | | | Merge branch 'unk-circid' into 'main'gabi-25014 days2-40/+49
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | proto: Silently drop DESTROY/RELAY/CREATED cells on unknown circuits Closes #2655 See merge request tpo/core/arti!4301
| * | | | proto: Explicitly drop the cells with unrecognized CircIdsGabriela Moldovan2026-08-121-0/+20
| | | | | | | | | | | | | | | | | | | | And say why it's okay to do so.
| * | | | proto: Update tests now that unrecognized CREATED are droppedGabriela Moldovan2026-08-111-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | These are no longer causing the channel reactor to shut down, so we need to update this test accordingly.