| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |
| | | |
| | | |
| | | |
| | | | |
This is a better name, and will suit us better when we reorganise this
code to allow incremental writing.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Make this a doc comment.
We're going to add an entrypoint that makes this more likely.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-cell: Add missing semver.md entries
See merge request tpo/core/arti!4257
|
| | | | | |
| | | | |
| | | | |
| | | | | |
I forgot to add these during a previous MR.
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
tor-netdoc: testing: Expose some more test utilities
See merge request tpo/core/arti!4250
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Involves code motion. Review with --color-moved.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
I don't understand why this suddenly, but whatever.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Involves lots of code motion. Review with --color-moved.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
This whole module is gated by the very same condition.
|
| | |/ / /
| | | |
| | | |
| | | | |
I discovered this didn't work, when I tried to use it.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
tor-cell,tor-proto: Fix XON conversion from KB/s to B/s
Closes #2650
See merge request tpo/core/arti!4255
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
We previously interpreted the rate in the XON message as being Kbits per
second, but it's really Kbytes per second.
|
| | | | | |
|
| | | | | |
|
| |/ / / |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-proto: Small improvements to circuit handshake tests
See merge request tpo/core/arti!4254
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Now that we read all of the cells from the connection inspector, we can
reuse the existing channel objects.
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
These TODOs are for client issues, not relay isues.
|
| | | | |
| | | |
| | | |
| | | | |
Otherwise the new circuit gets closed immediately by the relay.
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
tor-protover,tor-proto: Add and use a new `subprotocol_restricted_set` macro
See merge request tpo/core/arti!4241
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-dirpublish: Change `Uploader::upload()` to not require `Arc<Self>`
See merge request tpo/core/arti!4243
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
I was a bit confused as to why `Uploader::upload()` required an
`Arc<Self>`, and after looking at the code it appears that this `Arc`
isn't needed anywhere outside of the `PublishReactor`.
Instead `Uploader::upload()` now takes a `&self` instead of `Arc<Self>`.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Important pre-release fixes for RouterDescUnverified::verify()
See merge request tpo/core/arti!4252
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Better do it before the release so we can think about it a bit more.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
We need to obtain the maximum of the lower bound and the minimum of the
upper bound instead of vice versa.
Another example on why we should replace this with a better
implementation.
Likewise, `expiry` in the legacy verification code is also obtained like
that.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This makes it more clear, besides it will sound more "correct" with the
next commit applied.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-netdoc: Fix typo in testdata-live-download and RELAY_* constants
See merge request tpo/core/arti!4249
|
| | | |_|_|/ /
| |/| | | |
| | | | | |
| | | | | |
| | | | | | |
I still had the previously downloaded full consensus locally, so
running testdata-live-download fixed the Rust file.
|
| |\ \ \ \ \ \
| |_|/ / / /
|/| | | | |
| | | | | |
| | | | | | |
tor-proto: Add some unit tests for circuit handshakes
See merge request tpo/core/arti!4248
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
These help to establish connected channel objects to be used for tests.
|
| | | | | | | |
|
| | | | | | | |
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
Add RouterDescUnverified::verify()
See merge request tpo/core/arti!4144
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Otherwise clippy complains.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds a comprehensive test for router descriptor verification
that tests various valid and invalid edge cases.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Required for convert_curve25519_to_ed25519_private().
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This is a bad encode_sign() method for RouterDesc that is testing only
and will be used soon to implement testing for invalid router
descriptors, for which we may need to create invalid ones in the first
place.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit implements verification for router descriptors. 🎉
For this, the following checks are performed:
* RouterDesc::identity_ed25519 is validly signed.
* RouterDesc::master_key_ed25519 is as implied by identity_ed25519.
* RouterDesc::fingerprint is as implied by RouterDesc::signing_key.
* RouterDesc::ntor_onion_key_crosscert is validly signed.
* RouterDesc::signing_key has correct length and exponent.
* All RouterDesc::family_cert elements are valid.
* The inner and outer RouterDescSignatures are valid.
Unfortunately, we now have two implementations for that, as the legacy
parse_internal() also implements its own verification logic for this.
It seems merging these two together however would probably cause more
harm than good, as the legacy verification is closely intertwined with
legacy parsing, making a commonly shared verification logic hard to
achieve. In other words: parse2 parses the descriptor in its entirety
first, followed by verification afterwards, whereas the legacy code
parses and verifies every field before advancing towards the next.
Instead, I suggest to read through RouterDesc::parse_internal() and
ensure that every verification related check present there is also
present here. The notable exception to this is everything TAP related,
which is absent on purpose here.
Right now, this code is untested. I will add unit tests shortly
afterwards.
|
| | |/ / / /
| | | | |
| | | | |
| | | | | |
The underlying type also implements Copy. We will need it later.
|