aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | tor-dirclient: Only fail on empty GET responsesClara Engler2026-03-043-12/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit fixes the previous check to only fail on empty GET responses. For this, it introduces a `method` field into `DirResponse`, which is required to determine the method there. Doing this is reasonable for an HTTP client, as responses have different meanings depending on the request method used.
| * | | | | | tor-dirclient: Disallow empty successful responsesClara Engler2026-03-042-0/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit disallows empty responses with a status code 200. From a pure HTTP level, this is totally valid, but it does not make any sense in the context of the Tor directory protocol, where an empty response only makes sense with a 404. The motivation for this is that a work-in-progress tor_dirclient::send_request wrapper for tor-dirserver passes the response into the parse2 multiple function which returns a Vec<T>. Interfacing code would then always have to check for an empty length and do respective error handling, which should already fail at an earlier level (tor-dirclient) instead.
* | | | | | | Merge branch 'deps/relax-libsqlite3-sys' into 'main'Ian Jackson2026-03-042-3/+9
|\ \ \ \ \ \ \ | |/ / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | deps: relax `rusqlite` version requirement Closes #1740 See merge request tpo/core/arti!3706
| * | | | | | deps: use the same `rusqlite` version range for all cratesHydroxideUnlaced2026-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
| * | | | | | Apply 1 suggestion(s) to 1 file(s)HydroxideUnlaced2026-03-041-0/+1
| | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
| * | | | | | deps: relax `libsqlite3-sys` version requirementHydroxideUnlaced2026-03-042-3/+8
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The issue concerns `libsqlite3-sys` linking to a native library. Cargo cannot handle multiple versions/crates linking to the same native library. This affects both the `tor-dirmgr` and `tor-dirserver` crates, which depend on `rusqlite`. Relaxing the version requirement gives downstream projects flexibility so cargo can select an appropriate `libsqlite3-sys` version without a high chance of conflicts caused by pinning a specific version. The proposed supported version range was determined by testing until encountering a version lacking a feature currently in use (breaking unchange?). Regarding testing, the current CI with minimum-version test only validates the maximum and minimum versions, so breaking changes introduced between them can pass unnoticed. Tools like [Cargo-Bounds](https://github.com/vivax3794/cargo_bounds) can help, but this is out of scope for this MR. Also, supported versions of `rusqlite` for `tor-dirmgr` and `tor-dirserver` differ, so running tests for the whole project (same workspace) causes cargo to pick only overlapping versions, which hides parts of each crate’s supported range. Referencing #754, after this MR, increasing the maximum version or decreasing the minimum version of `rusqlite` shouldn't be a breaking change, but increasing the minimum version could be. Resolves: #1740
* | | | | | Merge branch 'readme-cleaning' into 'main'gabi-2502026-03-042-60/+1
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Remove some outdated README text Closes #2000 and #2063 See merge request tpo/core/arti!3748
| * | | | | README.md: Remove Roadmap sectionNick Mathewson2026-03-041-56/+0
| | | | | | | | | | | | | | | | | | | | | | | | It had grown quite old and outdated.
| * | | | | arti-client: Remove "not as secure as C Tor" text in the README.Nick Mathewson2026-03-041-4/+1
|/ / / / / | | | | | | | | | | | | | | | | | | | | I think we currently have the same security features implemented in Arti as C tor has.
* | | | | Merge branch 'version-bumps' into 'main'Alexander Hansen Færøy2026-03-0428-206/+147
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bump the deps that have breaking changes Closes #2383 See merge request tpo/core/arti!3746
| * | | | | Bump strum to 0.28Gabriela Moldovan2026-03-0415-42/+63
| | | | | |
| * | | | | rtcompat: Bump async-native-tls to 0.6.0Gabriela Moldovan2026-03-042-8/+8
| | | | | |
| * | | | | arti: Bump trycmd to 1.0.0Gabriela Moldovan2026-03-042-16/+16
| | | | | |
| * | | | | Downgrade security-frameworkGabriela Moldovan2026-03-041-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | See #2387
| * | | | | arti-ureq: Bump ureq to ~3.2.0Gabriela Moldovan2026-03-042-16/+16
| | | | | |
| * | | | | memquota: Bump sysinfo to 0.38.3Gabriela Moldovan2026-03-042-122/+33
| | | | | |
| * | | | | hashx: Bump dynasmrt to 5.0.0Gabriela Moldovan2026-03-045-15/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Contains a small code change as `bare_relocation()` was replaced with `value_relocation()`.
| * | | | | Bump toml_edit to 0.25.3Gabriela Moldovan2026-03-042-5/+5
| | | | | |
| * | | | | Bump toml to 1.0.3Gabriela Moldovan2026-03-0410-22/+31
|/ / / / /
* | | | | Merge branch 'cargo-update' into 'main'gabi-2502026-03-043-278/+288
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Run cargo update post-release See merge request tpo/core/arti!3740
| * | | | | Downgrade security-framework to 3.6.0Gabriela Moldovan2026-03-031-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | Version 3.7.0 doesn't seem to build in CI.
| * | | | | rtmock, chanmgr: Allow use of deprecated try_next() in testsGabriela Moldovan2026-03-032-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | futures 0.3.32 has deprecated UnboundedReceiver::try_next() in favor of UnboundedReceiver::try_recv(), but try_recv() was only introduced in 0.3.32, so using it would cause our minimal versions checks to fail (rightfully so, because our code wouldn't build with futures 0.3.x for x < 32).
| * | | | | Run cargo update post-releaseGabriela Moldovan2026-03-031-280/+286
| | |/ / / | |/| | |
* | | | | Merge branch 'workaround-mypy' into 'main'Jim Newsome2026-03-031-4/+17
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | python-lints: work around mypy import bug 20962 See merge request tpo/core/arti!3744
| * | | | python-lints: work around mypy import bug 20962Jim Newsome2026-03-031-4/+17
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When analyzing a script, mypy *should* look in the script's directory for imports, but appears not to do so when the script doesn't have a .py extension: https://github.com/python/mypy/issues/20962 We can work around that by adding the script's directory to MYPYPATH. With that workaround, we no longer need to add OTHER_PYTHON files to every invocation when analyzing scripts. That also worked around the problem in some cases, but experimentally not when the script is more than one subdirectory deep (?!)
* | | | Merge branch 'cell-order' into 'main'opara2026-03-035-144/+234
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-proto: Require specific cell order during handshake See merge request tpo/core/arti!3736
| * | | tor-proto: during handshake ensure circ id is 0Steven Engler2026-03-032-4/+18
| | | |
| * | | tor-proto: require cells from initiator to be orderedSteven Engler2026-03-031-61/+112
| | | |
| * | | tor-proto: require cells from responder to be orderedSteven Engler2026-03-032-61/+97
| | | |
| * | | tor-proto: make receiving AUTH_CHALLENGE non-optionalSteven Engler2026-03-032-8/+3
| | | |
| * | | tor-proto: remove `is_expecting_auth_challenge()`Steven Engler2026-03-033-14/+1
| | | | | | | | | | | | | | | | The responder always sends an AUTH_CHALLENGE cell.
| * | | tor-proto: send an AUTH_CHALLENGE during testsSteven Engler2026-03-032-0/+7
|/ / / | | | | | | | | | | | | | | | | | | As far as I know, a responder will always send an AUTH_CHALLENGE cell since it doesn't yet know if the initiator is a client or relay. The spec also doesn't have any mention about the AUTH_CHALLENGE being optional. So we should send it in our tests as well.
* | | Merge branch 'oxford-commaify' into 'main'gabi-2502026-03-031-1/+1
|\ \ \ | | | | | | | | | | | | | | | | ChangelogTemplate: Use oxford comma in sponsor name See merge request tpo/core/arti!3741
| * | | ChangelogTemplate: Use oxford comma in sponsor nameGabriela Moldovan2026-03-031-1/+1
| | | | | | | | | | | | | | | | @jnewsome tells me the official spelling uses an oxford comma.
* | | | Merge branch 'ticket2375_01' into 'main'David Goulet2026-03-0314-107/+215
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Protect PeerAddr in the channel handshake up to the Channel Closes #2375 See merge request tpo/core/arti!3722
| * | | | safelog: Rename MaybeSensitive::hidden/visible()David Goulet2026-03-038-17/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Rename them to respectively sensitive() and not_sensitive(). Signed-off-by: David Goulet <[email protected]>
| * | | | linkspec: Implement a RelayIdsBuilder::from_relay_ids()David Goulet2026-03-032-6/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is used when we build an OwnedChanTarget using the builder. Instead of going identities by identities at the callsite, we can use this helper to get us a RelayIds builder and set it in the OwnedChanTargetBuilder. Signed-off-by: David Goulet <[email protected]>
| * | | | chanmgr: Safely log the peer in the channel builderDavid Goulet2026-03-032-18/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | On I/O error, we safely log the peer address that was used that lead to this error. Closes #2375 Signed-off-by: David Goulet <[email protected]>
| * | | | proto: Channel handshake minor cleanupDavid Goulet2026-03-033-11/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | To make the code a bit better here. Also, at this commit, the UnverifiedChannel::finish() and VerifiedChannel::finish() are basically the exact same. A refactoring to use a finish() helper would work nicely. Signed-off-by: David Goulet <[email protected]>
| * | | | proto: Setup the channel PeerInfo in the specialized finish()David Goulet2026-03-036-67/+73
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Every specific types know if the peer is sensitive or not so now the finish() of each of these channel types builds the right PeerInfo with MaybeSensitive. This is passed on the Channel so from that point on, the Channel will never leak peer data in the logs. Signed-off-by: David Goulet <[email protected]>
| * | | | proto: Make PeerInfo accessors pub(crate)David Goulet2026-03-031-2/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | And implement Display as well. This is for the upcoming changes to be able to wrap PeerInfo into a MaybeSensitive<> container which can be logged safely hence the Display. Signed-off-by: David Goulet <[email protected]>
| * | | | safelog: Add MaybeSensitive structDavid Goulet2026-03-031-0/+47
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is meant to be like MaybeRedacted but for the Sensitive<> container. Signed-off-by: David Goulet <[email protected]>
| * | | | proto: Implement Display for PeerAddrDavid Goulet2026-03-032-1/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This required to implement Display for PtTarget. Signed-off-by: David Goulet <[email protected]>
| * | | | proto: Make channel PeerAddr sensitiveDavid Goulet2026-03-036-26/+39
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | Only the R2R channel that the PeerAddr becomes unsensitive. The rest, we keep it sensitive as it can be a client or a client's guard/bridge. Signed-off-by: David Goulet <[email protected]>
* | | | Merge branch 'slog-clog' into 'main'opara2026-03-032-54/+84
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-proto: rename 'SLOG'/'CLOG' and related code See merge request tpo/core/arti!3732
| * | | | tor-proto: rename 'SLOG'/'CLOG' and related codeSteven Engler2026-03-022-54/+84
| | | | |
* | | | | Merge branch 'rm-semvermd' into 'main'Alexander Hansen Færøy2026-03-036-8/+0
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | Remove semver.md files post-release See merge request tpo/core/arti!3739
| * | | | Remove semver.md files post-releaseGabriela Moldovan2026-03-036-8/+0
|/ / / /
* | | | Merge branch 'changelog-fix' into 'main'arti-v2.1.0gabi-2502026-03-031-2/+0
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Remove old breaking changes from CHANGELOG See merge request tpo/core/arti!3738
| * | | | Remove old breaking changes from CHANGELOGGabriela Moldovan2026-03-031-2/+0
|/ / / / | | | | | | | | | | | | | | | | | | | | I accidentally added these to the changelog, but they're from an old release (I had some old semver.md files left in my local checkout, for some reason).