aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | | | | | | Merge branch 'flowctrl-tests' into 'main'opara2026-06-163-15/+435
|\ \ \ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Add unit test for `XonXoffReader` See merge request tpo/core/arti!4093
| * | | | | | | | | tor-proto: add a unit test for `XonXoffReader`Steven Engler2026-06-162-1/+399
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The 'futures' version bump is needed so that our test can use `UnboundedSender::try_recv()` in the minimal-versions CI test.
| * | | | | | | | | tor-proto: add `DrainRateNotifier` trait for `XonXoffReader`Steven Engler2026-06-101-13/+35
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will allow us to add a unit test for `XonXoffReader`.
| * | | | | | | | | tor-cell: impl `PartialEq + Eq` on `XonKbpsEwma`Steven Engler2026-06-101-1/+1
| | | | | | | | | |
* | | | | | | | | | Merge branch 'bump-chutney-2026-06' into 'main'Jim Newsome2026-06-162-5/+11
|\ \ \ \ \ \ \ \ \ \ | |_|_|/ / / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bump chutney and add additional middle nodes to chutney test net Closes #2463 See merge request tpo/core/arti!4111
| * | | | | | | | | chutney test network: add 4 suitable middle/guard/vg relaysJim Newsome2026-06-151-3/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With the chutney bump in the previous commit alone, we hit arti#2463 consistently. According to the spec, a hidden service using vanguards-lite needs 2 guards and 4 vanguards <https://spec.torproject.org/vanguards-spec/index.html>. All 6 of those relays need to be Fast and Stable. At least the 2 guards also need to be Measured. (Probably the 4 vanguards too, but I haven't verified). authority relays are never considered Measured. Prior to the chutney bump, none of the relays were, but since chutney!142, we create a bandwidth file to ensure the non-authorities *are* Measured, and will get the Fast flag. (IIUC, tor doesn't apply the bandwidth measurements to authorities). Maybe the presence of *some* measured relays gets us out of some fallback path that was getting used before to allow unmeasured relays? Adding the additional relays seems to fix the issue.
| * | | | | | | | | Bump chutney to get Stable flag fixJim Newsome2026-06-151-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is primarily to get chutney!149. This should fix arti#2463, but I haven't been able to repro locally to verify. I suspect it'll mitigate some of the other difficult-to-repro cases of arti#2209 as well.
* | | | | | | | | | Merge branch 'fix-authcert' into 'main'Clara Engler2026-06-161-1/+2
|\ \ \ \ \ \ \ \ \ \ | |/ / / / / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: fix EncodedAuthCert parsing See merge request tpo/core/arti!4104
| * | | | | | | | | tor-netdoc: fix EncodedAuthCert parsingIan Jackson2026-06-151-1/+2
| | |_|/ / / / / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It would swallow the whole rest of the document, leading to bizarre output on re-encoding. There is no test case for this in-tree (which is why this is cfg "incomplete"), but I have a full roundtrip test of a vote (which contains an authcert) in a wip branch, which detected this problem.
* | | | | | | | | Merge branch 'string-slice-types' into 'main'Ian Jackson2026-06-153-36/+21
|\ \ \ \ \ \ \ \ \ | |_|_|_|/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | Avoid string slices in netdoc types See merge request tpo/core/arti!4103
| * | | | | | | | tor-netdoc: Replace string slice in LongIdentClara Engler2026-06-151-7/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces the use of string slices in LongIdent by using .strip_prefix() and .split_once() instead.
| * | | | | | | | tor-netdoc: Use .rsplit_once() in AddrPortPatternClara Engler2026-06-151-4/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Replaces the use of a string slice in conjuction with .rfind() with a call to .rsplit_once().
| * | | | | | | | tor-netdoc: Replace string slice in address parse helperClara Engler2026-06-151-5/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces the use of a string slice in an address parse helper by replacing calls to `.starts_with` / `.ends_with` to calls with `.strip_prefix` / `.strip_suffix` and using the respective `.is_some()` for the boolean like value, making the result functionally equivalent.
| * | | | | | | | tor-netdoc: Use .split_once() in IpPatternClara Engler2026-06-151-3/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces the use of string slices in IpPattern with a call to split_once(). Either review as it is or with --word-diff=color.
| * | | | | | | | tor-netdoc: Use .split_once() in PortRangeClara Engler2026-06-151-17/+10
| |/ / / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces a string slice use in PortRange with a call to .split_string(). Either review the change as an entire rewrite, as the function in itself is pretty small or use --color-moved --color-moved-ws=ignore-all-space if you want to verify that the lines regarding a port range without a hyphen is still using the same logic.
* | | | | | | | Merge branch 'rs-stats' into 'main'Ian Jackson2026-06-155-3/+11
|\ \ \ \ \ \ \ \ | |/ / / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: routerstatus entries: Add `stats` item (votes only) See merge request tpo/core/arti!4097
| * | | | | | | tor-netdoc: rs.rs: tidy importsIan Jackson2026-06-151-2/+3
| | | | | | | |
| * | | | | | | tor-netdoc: routerstatus entries: Add `stats` item (votes only)Ian Jackson2026-06-155-2/+9
|/ / / / / / /
* | | | | | | Merge branch 'rename-auth-auth-auth' into 'main'Clara Engler2026-06-152-11/+9
|\ \ \ \ \ \ \ | |_|_|_|_|_|/ |/| | | | | | | | | | | | | | | | | | | | tor-netdoc: Rename variants in VerifyGeneralTrustedAuthorities See merge request tpo/core/arti!4099
| * | | | | | tor-netdoc: Rename variants in VerifyGeneralTrustedAuthorities (fmt)Ian Jackson2026-06-111-3/+1
| | | | | | |
| * | | | | | tor-netdoc: Rename variants in VerifyGeneralTrustedAuthoritiesIan Jackson2026-06-112-9/+9
| | |/ / / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In a wip branch I added a variant, and clippy complained. In this case, I agree with clippy. warning: all variants have the same postfix: `Authorities` --> crates/tor-netdoc/src/doc/netstatus.rs:2335:1 | 2335 | / pub(crate) enum VerifyGeneralTrustedAuthorities<'r> { 2336 | | /// Trust these authorities. 2337 | | TrustTheseAuthorities { 2338 | | /// The HKP_auth_id_rsa ... | 2357 | | }, 2358 | | } | |_^ | = help: remove the postfixes and use full paths to the variants instead of glob imports = help: for further information visit https://rust-lang.github.io/rust-clippy/beta/index.html#enum_variant_names note: the lint level is defined here --> crates/tor-netdoc/src/lib.rs:9:9 | 9 | #![warn(clippy::all)] | ^^^^^^^^^^^ = note: `#[warn(clippy::enum_variant_names)]` implied by `#[warn(clippy::all)]`
* | | | | | Merge branch 'destroy' into 'main'opara2026-06-123-29/+12
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Always use destroy reason NONE in circuit handshake code Closes #2466 See merge request tpo/core/arti!4088
| * | | | | tor-proto: circ handshake now always uses NONE destroy reasonSteven Engler2026-06-122-29/+5
| | | | | |
| * | | | | tor-cell: document that destroy reason should be NONESteven Engler2026-06-121-0/+7
| | |_|/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | The spec was recently updated in [1], so we should make this clearer in our code comments. [1]: https://gitlab.torproject.org/tpo/core/torspec/-/merge_requests/490
* | | | | Merge branch 'verify-general' into 'main'Ian Jackson2026-06-114-100/+245
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: overhaul consensus verification, in preparation for parse2 ns verification See merge request tpo/core/arti!4065
| * | | | | tor-netdoc: verify_general: explain an exhaustive patternIan Jackson2026-06-111-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4065#note_3423331
| * | | | | tor-netdoc: consensuses: Add a TODO about validate's signatureIan Jackson2026-06-111-0/+2
| | | | | |
| * | | | | tor-netdoc: consensuses: Introduce VerifyGeneralTrustedAuthorities (fmt)Ian Jackson2026-06-112-10/+9
| | | | | |
| * | | | | tor-netdoc: consensuses: Introduce VerifyGeneralTrustedAuthoritiesIan Jackson2026-06-113-11/+43
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This avoids passing the threshold around as a bare usize, separated out from the list of trusted authorities. Roughly as discussed in https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4065#note_3423775 But, VGTA::HazardouslyAssumeAllAuthCertsAreRealAuthorities contains n_authorities, not the thtreshold. That's what its user has, and that allows us to centralise the threshold calculation somewhat. The situation with votes in poc is a bit odd now: we pass one cert and then there's one authority so the threshold of 1 is calculated rather than literal. That's OK, but also we perhaps aren't going to use verify_general for votes in the production.
| * | | | | tor-netdoc: certs: Use .contains() in one placeIan Jackson2026-06-111-1/+1
| | | | | |
| * | | | | tor-netdoc: Apply deferred rustfmt import churnIan Jackson2026-06-112-3/+2
| | | | | |
| * | | | | tor-netdoc: ns verification: Allow "dry run" to just get missing certs infoIan Jackson2026-06-112-10/+25
| | | | | | | | | | | | | | | | | | | | | | | | No functional change with the existing caller.
| * | | | | tor-netdoc: ns verification: Collect missing certs/sigs informationIan Jackson2026-06-111-2/+68
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Introduce ConsensusVerifiabilityError. No functional change with the existing callere, which discards the error value.
| * | | | | tor-netdoc: ns verification: verify_general, return Result, tidy callerIan Jackson2026-06-111-5/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now the caller can use .map_err rather than if .ok(). No functional change.
| * | | | | tor-netdoc: ns verification: verify_general, return ResultIan Jackson2026-06-113-5/+10
| | | | | | | | | | | | | | | | | | | | | | | | No functional change.
| * | | | | tor-netdoc: ns verification: abolish SigCheckResultIan Jackson2026-06-111-27/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Move the body of check_signature into verify_general. check_signature was the only thing that returned SigCheckResult. No functional change.
| * | | | | tor-netdoc: ns verification: Introduce ConsensusSignatureToVerifyIan Jackson2026-06-111-9/+53
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | And split check_signature into signature_to_verify which obtains a ConsensusSignatureToVerify, and then a call to .verify(). The return values are still a bit janky. No functional change.
| * | | | | tor-netdoc: poc: Abolish core of separate verification logicIan Jackson2026-06-111-50/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In an attempt to check that the new verification code makes sense, we compare it with the freshly rewritten one in poc. To review this, compare the code being deleted with the body of verify_general (doc/netstatus.rs, line 2164 et seq). You'll also want to refer to the body of find_cert and check_signature (lines 2068-2086).
| * | | | | tor-netdoc: poc: Skip duplicate signatures earlier.Ian Jackson2026-06-111-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Like verify_general does. (This wasn't a bug before, because we could the length of ok, so all that would happen is we'd do some extra work.)
| * | | | | tor-netdoc: poc: Reorder slightlyIan Jackson2026-06-111-4/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Obtain the hash first, like verify_general does. No significant functional change, and this is poc code anyway.
| * | | | | tor-netdoc: poc: Use let else continue (fmt)Ian Jackson2026-06-111-18/+18
| | | | | |
| * | | | | tor-netdoc: poc: Use let else continueIan Jackson2026-06-111-2/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes the code more like that in verify_general. No functional change, and this is poc code anyway.
| * | | | | tor-netdoc: ns verification: verify_general, remove an otiose typecheckIan Jackson2026-06-111-2/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously this was arguably needed for clarity. With the new hash finding arrangements, much less so. No functional change.
| * | | | | tor-netdoc: ns verification: verify_general, disassemble SignatureIan Jackson2026-06-111-2/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Use an exhaustive pattern. This allows us to spot any fields which we omit to look at, which would be an indication of a possible bug. No functional change.
| * | | | | tor-netdoc: ns verification: verify_general, add trusted_auth's argumentIan Jackson2026-06-111-0/+15
| | | | | | | | | | | | | | | | | | | | | | | | No functional change with the current caller.
| * | | | | tor-netdoc: ns verification: Use the proper hash fieldIan Jackson2026-06-111-9/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This does not fix the bug with the old parser. The old parser always uses the `sha1` field in `hashes` even when `sha1_unnamed` would be right. But it also always sets `sha1`. Or to put it another way, because the old parser parses an unspecified algorithm as if it were explicitly `sha1`, it then both sets the digest_algo to DigestAlgoInSignature(Some(...)), and writes the hash to the `sha1` field. So this does not have an overall functional change with the old parser, and nothing else calls this. I'm fixing this here, now, so that the new parser doesn't inherit the bug. The new parser will set `digest_algo` correctly, and correctly write the hash to `sha1` or `sha1_unnamed`. What a terrible protocol this is.
| * | | | | tor-netdoc: ns verification: Use let else to avoid an unwrapIan Jackson2026-06-111-5/+3
| | | | | | | | | | | | | | | | | | | | | | | | No functional change.
| * | | | | tor-netdoc: ns verification: Break out SignatureGroup::verify_generalIan Jackson2026-06-111-1/+23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is going to be the entrypoint for sharing verification code with parse2. For now it must be pub(crate) since we're going to call it from poc. No functional change.
* | | | | | Merge branch 'rd-ntor-crosscert' into 'main'Clara Engler2026-06-112-1/+102
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add NtorOnionKeyCrossCert See merge request tpo/core/arti!4023
| * | | | | | tor-netdoc: Test NtorOnionKeyCrossCert typeClara Engler2026-06-111-1/+71
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a unit test for NtorOnionKeyCrossCert that tests whether it can be successfully decoded and verified if enough fields are given. The test itself is performed on keys with a negative as well as keys with a positive sign as the argument.