| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit replaces the use of lines with byte offsets for cutting of
the signatures.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit adds a compile time assertion that a u32 can always be
safely casted into a usize.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit adds a check that prevents gen_cons_diff from computing a
diff with a single dot line.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit refactors gen_ed_diff to have less code duplication by not
matching upon the hunk type once but by splitting it into two different
matches for the header and the body.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Mark a failed apply from a consensus diff we generate as a bug as this
should not happen. We must obviously always accept the consensus diffs
we produce.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit replaces repeated `result += &format!(...)` cruft with
`write!` calls and multi-line strings.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit moves "directory-signature" and "directory-signature " into
semantically meaningful constants.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit replaces the names crate with a simple hardcoded wordlist of
length 20, obtained from my systems wordlist.
Reason for that being that names triggers a cargo-audit failure.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit implements support for the consensus diff generation.
Unlike CTor, it does not use its own custom algorithm but rather uses an
implementation of Myers' algorithm from the `imara-diff` crate, which is
pretty performant and comparable to size and run time to CTor, while
being much simpler in the interfacing code.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This commit lno_for_error in ItemStream to lno because its value may not
always be used for error handling, such as in tor-consdiff.
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds the ParseError::new() method, which allows external
APIs to construct a ParseError, which is currently not possible due to
non-exhaustiveness, despite the member fields being public.
It is required for external applications using lower-level but public
parse2 APIs, such as ItemStream's.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
docs: Fix config file path on windows
Closes #2422
See merge request tpo/core/arti!3808
|
| | | |/ / / /
| |/| | | | |
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
hsservice: Remove obsolete "Limitations" section
See merge request tpo/core/arti!3812
|
| | | |/ / / /
| |/| | | |
| | | | | |
| | | | | | |
These have been implemented for a while now.
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
tor-chanmgr: Don't `warn_report!` for failed connections
See merge request tpo/core/arti!3807
|
| | |/ / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
`warn_report!` is useful when there's an error that we need to ignore
and can't propagate up the call stack. But here we're using
`warn_report!` while also returning the error in a
`Error::ChannelBuild`.
This is not great because:
1. The caller should warn if it wants to, since it will have the error
message and the proper context.
2. This code is doing something like happy eyeballs, which means we only
care that one connection succeeds, not if any fail.
One instance where this is problematic is when running Arti on a machine
without IPv6 support. If connecting to a relay with both an IPv4 and
IPv6 address, the IPv6 attempt will always fail. We don't want to warn
about every outgoing IPv6 connection failure when the IPv4 connection
succeeds.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-guardmgr: Fix some duration string formatting
See merge request tpo/core/arti!3804
|
| | |/ / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Old text would say something like:
> Retrying in FormattedDuration(29.999861026s).
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
tor-proto: Small miscellaneous changes on relay circuit reactor
See merge request tpo/core/arti!3809
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
An `Arc<T>` is only `Send` if `T` is `Send + Sync`,
which is needed by the runtime.
|
| |/ / / /
| | | |
| | | |
| | | |
| | | | |
I plan to call this from
`crates/tor-proto/src/channel/reactor.rs`.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Force use of standard hasher with weak_tables.
Closes #2418
See merge request tpo/core/arti!3801
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Closes #2418.
Fixes TROVE-2026-005, where we would use a less cryptographically
secure (and probably less DoS resistant) hash function for these
tables if:
- We are built alongside another crate that uses `weak-table`
- That crate enables the `weak-table/ahash` feature.
- We are running on a system without hardware AES.
Severity: Low
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
arti-relay: Change a 'debug' log to 'info'
See merge request tpo/core/arti!3803
|
| |/ / / /
| | | |
| | | |
| | | |
| | | | |
I had intended for this to be 'info' in f287ec7910, but must have
accidentally wrote 'debug'.
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
Fix typos
See merge request tpo/core/arti!3792
|
| |/ / /
| | |
| | |
| | | |
Typos found with codespell
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
RPC: C/Python wrappers and integration tests for nonblocking and polling IO
See merge request tpo/core/arti!3771
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This provides an API and tests for create_polling(), poll(), and
related APIs.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
These wrappers present a "pythonic" API to the C functions for
submit and wait.
Tests included.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
These are low-level wrappers that let us call the relevant C code,
but are not suitable for general use.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This commit adds FFI wrappers for the "poll" API, which lets the
user integrate with a poll(2)-style event loop.
|
| |/ / /
| | |
| | |
| | |
| | |
| | | |
This commit adds wrappers for the "submit/wait" methods on RpcConn
(which are used to submit tagged requests,
and then wait for responses to all tagged requests at once).
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
proto: Replace TimeoutEstimator with opaque handler
Closes #2410
See merge request tpo/core/arti!3794
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This replaces the client-specific half-stream expiry calculation from
the stream reactor (which is meant to be implementation agnostic) with a
call to the new `StreamHandler::halfstream_expiry()`, which abstracts
away the implementation-specific half-stream expiry calculation (for
example, on the client-side, the calculation takes into account the CBT,
which we don't have on the relay side).
Note that there is currently no `StreamHandler` implementation on the
client-side (because we haven't ported the client circuit reactor to the
new reactor yet).
Closes #2410
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This will enable us to handle half-stream expiry differently on the
client side vs the exit side.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
Bump to latest webpki (0.103.10) to resolve RUSTSEC-2026-0049
See merge request tpo/core/arti!3798
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Advisory at https://rustsec.org/advisories/RUSTSEC-2026-0049
This issue doesn't affect Arti itself, since Arti doesn't actually
_use_ regular X.509 CAs or CRLs.
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
cell, proto, cert: Simplify CERTS cell building.
See merge request tpo/core/arti!3795
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Formerly we required the caller for push_cert_body to specify the
type of the cert that they were pushing. But in nearly every case,
the certificate object that the caller is holding knows what its
own type is! This makes the tor_proto build_certs_cell function
a bit less error-prone, since we don't have to worry about mismatch.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
proto: Remove unnecessary test-gating
See merge request tpo/core/arti!3796
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
`test_utils` is not exposed outside of `tor-proto`, so the feature
gating here isn't needed (we typically use the `testing` feature for
exposing testing utilities outside the current crate, but that's not the
case here).
|