aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'exit-flowctl' into 'main'HEADmainopara6 days8-27/+87
|\ | | | | | | | | | | | | tor-proto: Disable flow control sidechannel mitigations for relays Closes #2579 See merge request tpo/core/arti!4324
| * tor-proto: disable flowctrl sidechannel mitigations for relaysSteven Engler7 days4-14/+43
| | | | | | | | | | | | | | | | The end result should be: 1. outgoing streams - enable sidechannel mitigations 2. incoming hs streams - enable sidechannel mitigations 3. incoming exit streams - disable sidechannel mitigations
| * tor-proto: add `StreamHandler::flowctrl_sidechannel_mitigations()`Steven Engler7 days2-0/+10
| |
| * tor-proto: add `WithSidechannelMitigations` for flow ctrlSteven Engler7 days4-14/+35
| |
* | Merge branch 'otel-out-of-arti' into 'main'wesleyac7 days17-135/+377
|\ \ | | | | | | | | | | | | | | | | | | Split OTLP exporter into separate crate. Closes #2611 See merge request tpo/core/arti!4297
| * | Fix tests.Wesley Aptekar-Cassels9 days2-1/+4
| | |
| * | Stub out opentelemetry config when feature is disabled.Wesley Aptekar-Cassels9 days4-5/+17
| | |
| * | Fix many review comments.Wesley Aptekar-Cassels9 days10-28/+18
| | | | | | | | | | | | Mostly relating to typos and dependencies.
| * | Fix config tests.Wesley Aptekar-Cassels13 days2-1/+3
| | |
| * | Fix clippy lints.Wesley Aptekar-Cassels2026-08-111-2/+0
| | |
| * | tor-config-shared: Add README.Wesley Aptekar-Cassels2026-08-102-0/+14
| | |
| * | Fix cargo-sort.Wesley Aptekar-Cassels2026-08-102-5/+4
| | |
| * | Fix maint/add_warning.Wesley Aptekar-Cassels2026-08-102-0/+94
| | |
| * | Fix cyclic dependency issues.Wesley Aptekar-Cassels2026-08-105-6/+9
| | |
| * | Revert "tor-config: Allow use of Option<Duration>."Wesley Aptekar-Cassels2026-08-101-0/+7
| | | | | | | | | | | | This reverts commit 95db661dc6be2ad6ed87f34094542660b9e0e155.
| * | tor-config-shared: Stop using Option<Duration>.Wesley Aptekar-Cassels2026-08-105-25/+21
| | |
| * | Add new tor-conig-shared crate.Wesley Aptekar-Cassels2026-08-1013-20/+100
| | | | | | | | | | | | | | | This contains configuration types that are shared between arti and arti-rely.
| * | arti: Move OpentelemetryConfig to tor-config.Wesley Aptekar-Cassels2026-08-106-118/+121
| | | | | | | | | | | | | | | | | | This will allow this code to be shared between arti and arti-relay. See: #2470
| * | tor-config: Allow use of Option<Duration>.Wesley Aptekar-Cassels2026-08-101-7/+0
| | | | | | | | | | | | | | | | | | | | | | | | While it's true that TOML doesn't allow explicitly setting None values, None is also used to represent a key not being in a table, which is a valid thing to want in the case of a duration. Fixes: #2611
| * | Split OTLP exporter into separate crate.Wesley Aptekar-Cassels2026-08-107-4/+52
| | | | | | | | | | | | | | | This will allow this code to be shared between arti and arti-relay, and will also likely be useful for others in the ecosystem.
* | | Merge branch 'dont-preserve-doc' into 'main'opara7 days1-7/+12
|\ \ \ | | | | | | | | | | | | | | | | CI: Stop using `./maint/preserve` for `target/doc/` See merge request tpo/core/arti!4315
| * | | ci: stop preserving 'target/doc/' between jobsSteven Engler9 days1-7/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I think the original intent was to save the rustdoc build as an artifact. But by using `./maint/preserve`, we preserve the docs between jobs, which is not what we want. Instead, we just save the rustdoc build as an artifact.
* | | | Merge branch 'rpc-config-prep1' into 'main'Nick Mathewson7 days5-52/+197
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti: Preparation for RPC configuration management, part 1 See merge request tpo/core/arti!4322
| * | | | arti: Move cfg_mgr preservation techniqueNick Mathewson7 days1-2/+4
| | | | |
| * | | | arti: In RPC mode, remember normalized configuration dataNick Mathewson7 days1-9/+43
| | | | | | | | | | | | | | | | | | | | This will be the basis for configuration _inspection_.
| * | | | arti: Give an Arc<CfgMgr> to RPC superuser sessions.Nick Mathewson7 days4-5/+26
| | | | |
| * | | | arti: Construct CfgMgr object earlier.Nick Mathewson7 days1-10/+11
| | | | |
| * | | | reload_cfg: add comments about some tricky points.Nick Mathewson7 days1-0/+9
| | | | |
| * | | | reload_cfg: Allow modules to be set after CfgMgr is createdNick Mathewson7 days1-10/+35
| | | | | | | | | | | | | | | | | | | | (But before the watcher task is launched.)
| * | | | code movement to tidy previous commitNick Mathewson7 days1-44/+41
| | | | |
| * | | | reload_cfg: Separate creation of CfgMgr and launch of taskNick Mathewson7 days2-7/+63
| | |_|/ | |/| | | | | | | | | | | | | | | | | | We want to be able to create the CfgMgr early so that we can give it to the RPC code, then add a bunch of reconfigurable modules to it, and only then launch the file-watcher task.
* | | | Merge branch 'extra-info-init' into 'main'Nick Mathewson7 days2-0/+245
|\ \ \ \ | |/ / / |/| | | | | | | | | | | Initialize extra-info module See merge request tpo/core/arti!4284
| * | | tor-netdoc: Initialize extra-info moduleClara Engler2026-08-052-0/+245
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit initializes the doc::extra_info module in tor-netdoc, which is still marked as incomplete and will be extended in the future. Right now, it is very barebones by only supporting the introduction item as well as the bare minimum required for verification. It also adds a simple unit test, which iterates over the available test data, parses and verifies it.
* | | | Merge branch 'proto-relay-fix' into 'main'gabi-2508 days1-1/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-proto: Fix tests build error when "testing" feature isn't enabled See merge request tpo/core/arti!4319
| * | | | tor-proto: make 'testing_exports' available to own unit testsSteven Engler8 days1-1/+1
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes: ```text $ cargo test -p tor-proto --features relay error[E0603]: enum import `CtrlMsg` is private --> crates/tor-proto/src/relay/reactor.rs:463:33 | 463 | use crate::channel::CtrlMsg; | ^^^^^^^ private enum import | note: the enum import `CtrlMsg` is defined here... --> crates/tor-proto/src/channel.rs:117:5 | 117 | use testing_exports::*; | ^^^^^^^^^^^^^^^^^^ note: ...and refers to the enum import `CtrlMsg` which is defined here... <snip> ``` There are a few ways we could fix this, but I don't see an advantage of one over another.
* | | | Merge branch 'destroy-on-drop' into 'main'gabi-2508 days6-71/+208
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | proto: Avoid sending DESTROY if we have received DESTROY Closes #2646 and #2648 See merge request tpo/core/arti!4312
| * | | | proto: Extend test to check DESTROY is sent to the next hopGabriela Moldovan8 days1-0/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This extends the `destroy_from_client()` test to also check that a DESTROY received from the client (or, more generally speaking, from the "inbound channel") is actually forwarded to the next hop. The reason the `assert_destroy_sent()` assertion is commented out is specified in the TODO that precedes it (tldr: testing the DESTROY behaviour involves both the channel reactor and the circuit reactor, and our test setup is currently quite limited, in that it doesn't actually exercise the right channel reactor code paths for the *inbound* channel). I plan to address this soon.
| * | | | proto: Move assert_cell_is_destroy macro out of helper functionGabriela Moldovan8 days1-15/+15
| | | | | | | | | | | | | | | | | | | | I am about to need this in a test.
| * | | | proto: Add comments explaining why the tests use DestroyDirection::BackwardGabriela Moldovan8 days1-2/+14
| | | | |
| * | | | proto: Remove misleading comment and rename misnamed variableGabriela Moldovan8 days1-3/+2
| | | | | | | | | | | | | | | | | | | | This fixes an old bad copy-paste that I've just noticed.
| * | | | proto: Clarify what read_{inbound,outbound} are forGabriela Moldovan8 days1-0/+14
| | | | | | | | | | | | | | | | | | | | This adds an example suggested by opara.
| * | | | proto: Update the tests to check DESTROY is only sent when neededGabriela Moldovan8 days1-25/+72
| | | | |
| * | | | proto: Allocate a real circ id in the circ reactor testsGabriela Moldovan8 days1-13/+47
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need this because the channel reactor now only sends DESTROY for circuits that are still in the circ map (and we are about to test this behaviour, so we need the circuit map to actually have an entry for our test circuit). Initially, these tests were meant to test the circuit reactor in isolation, but they've gradually grown more complex, and now require a semi-working channel reactor. In the long run, I think I'd like to: * change the tests from `tor_proto::relay::reactor` to use a proper relay channel reactor as opposed to a `working_dummy_channel()`, and to initialize a circuit through the normal means, namely by sending a CREATE2 through the channel reactor (naturally, this "proper relay channel reactor" still wouldn't be connected to the network). These will test the integration between the channel and the circuit reactor, as well as the circuit reactor behaviour * add new, implementation-agnostic tests for the generic multi-reactor system. These will use a mock channel reactor
| * | | | proto: Make Channel::send_control() pub(crate) for testingGabriela Moldovan8 days1-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The relay circuit reactor tests will soon need the ability to send control messages (for allocating a circuit id for the circuit reactor under test).
| * | | | proto: Expect a now-unused test function to be dead codeGabriela Moldovan8 days1-0/+1
| | | | |
| * | | | proto: Update create handler tests to no longer expect DESTROYGabriela Moldovan8 days1-18/+6
| | | | | | | | | | | | | | | | | | | | | | | | | Now that we no longer respond to DESTROY by sending a DESTROY ourselves, these tests need to be updated.
| * | | | proto: s/client/next hop in test commentGabriela Moldovan8 days1-1/+1
| | | | | | | | | | | | | | | | | | | | This test simulates the *next hop* sending us a DESTROY.
| * | | | proto: Avoid sending DESTROY if we have received DESTROYGabriela Moldovan8 days2-0/+25
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This change prevents the channel reactor from sending DESTROY cells on already-closed (or non-existent) circuits. Upon receiving a DESTROY cell, the channel reactor removes the corresponding circuit entry, if any, from its circmap. It then passes the DESTROY to the circuit reactor for handling. The circuit reactor handles it by shutting down, and calling `Channel::close_circuit()` on drop. Previously, this would unconditionally send a DESTROY cell, which caused #2648 and #2646. This affects both clients and relays, because both circuit reactors call `Channel::close_circuit()` on drop. Closes #2648, #2646
* | | | Merge branch 'ahf/fix-load-store-path-formatting' into 'main'opara8 days1-1/+2
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-persist: fix display of Target path(s). See merge request tpo/core/arti!4317
| * | | | tor-persist: fix display of Target path(s).Alexander Hansen Færøy8 days1-1/+2
| | |/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This patch changes how display works on our Target struct. Currently, log messages generated by Arti Relay looks like this: `tor_persist::load_store: storing "/path/to/arti-relay/state"/"circuit_timeouts.json"` With this patch applies it instead looks like this: `tor_persist::load_store: storing "/path/to/arti-relay/state/circuit_timeouts.json"` With this change we ensure that the correct delimiter between the directory and the filename is used (on Unix it's "/", but on Windows it's "\") and we also avoid the added "" around both the directory and filename.