| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | | | |
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | | |
This will be needed for ntor handshakes.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
arti-relay: Generate and rotate ntor keys
Closes #2451
See merge request tpo/core/arti!3874
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Usually, there will only be two of these.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This also updates the key rotation task to call the setter whenever the
ntor keys get updated.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will need to be updated each time the ntor keys change.
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
I am about to add another one of these, so I tried to deduplicate the
impls a bit.
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
There is still some outstanding work here to read the lifetime and grace
period from the consensus, but that will require some bigger changes to
the rotation task.
Closes #2451
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
The logic for removing and generating ntor keys is going to be slightly
different here.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will enable us to plug in the ntor key rotation logic.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is just a wrapper over `bool` right now. It will helps us
distinguish changes to the channel auth material from changes affecting
the ntor circuit extension keys.
|
| | | | | | | | |
|
| |/ / / / / / |
|
| |\ \ \ \ \ \
| |_|/ / / /
|/| | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
chanmgr: Validate the ChanTarget for both client and relay
Closes #2404 and #2440
See merge request tpo/core/arti!3843
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Also set a better error message when validating channel target.
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This trickles down to the tor-proto channel handshake code. But, the
real need is in the channel builder in order to validate the outbound
channel target.
Fixes #2440
Signed-off-by: David Goulet <[email protected]>
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
It used to be only with the feature = relay but since client can have
that feature enabled, we now validate based on channel outbound type
instead.
Related to #2440
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
Log IDs
See merge request tpo/core/arti!3872
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
integration-shadow: remove torrc parameter tuning
See merge request tpo/core/arti!3871
|
| | |/ / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
These were originally blindly copied over from shadow's own integration
test.
The relatively low BandwidthRate and BandwidthBurst rates in particular
could cause overload in heavily-used relays given the amount of traffic
we're trying to push through the network simultaneously from different
clients.
I'm not aware of a specific problem the other parameters might cause,
but it seems better not to have them without some concrete reason.
Motivated while debugging arti#2399; we hypothesize that the bandwidth
limits + bad luck of many circuits trying to use one relay at once could
be a contributing factor.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-proto: Move CREATE_FAST handling to a helper
See merge request tpo/core/arti!3869
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Clippy has started warning about this since we moved the CREATE_FAST
handling to a helper, so this resolves that.
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Fix formatting from previous code movement.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This moves the code, changes the indentation, and wraps the result in an
`Ok()`.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This had already been resolved.
|
| |\ \ \ \ \ \ \
| |_|/ / / / /
|/| | | | | |
| | | | | | |
| | | | | | | |
arti-relay: Fix test MockRuntime::advance_by() usage
See merge request tpo/core/arti!3873
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This was previously advancing time by more than intended (I think the
intention here was to use something like
`MockRuntime::jump_wallclock()`, but that function has no effect on
sleeping futures, so I think we should continue using `advance_by()`).
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Allow compile-time selection of rustls CryptoProvider; use aws-lc-rs by default.
Closes #2448
See merge request tpo/core/arti!3857
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
They have finally updated their license to remove the old OpenSSL/4-clause
BSD text. (See https://github.com/aws/aws-lc/pull/3091 .)
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
When using rustls, previously we'd check to see whether the
application had installed a CryptoProvider (as it is required to
do). If not, we'd log a warning and install a Ring provider.
But now, we want to enable other kinds of providers,
so this behavior isn't practical any more.
(See #2448 for discussion.)
Closes #2448.
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
tor-error/arti: add logging.protocol_warnings for TorProtocolViolation
See merge request tpo/core/arti!3805
|
| | | | | | | | | |
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
in event_report!
|