aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | proto: Upgrade to latest polyval.Nick Mathewson2026-03-043-26/+74
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will improve performance for CGO. Closes #2390.
* | | | | | Merge branch 'signature-rework-rename-signed' into 'main'Clara Engler2026-03-0514-156/+101
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | tor-netdoc parse2: Rename *Signed to *Unverified See merge request tpo/core/arti!3742
| * | | | | tor-netdoc: Fix typo in docsIan Jackson2026-03-041-1/+1
| | | | | |
| * | | | | tor-netdoc: Apply rustfmt churnIan Jackson2026-03-033-11/+5
| | | | | |
| * | | | | tor-netdoc: parse2: Lengthen a doc comment slightlyIan Jackson2026-03-031-1/+1
| | | | | |
| * | | | | tor-netdoc: parse2: Use eprint for dtraceIan Jackson2026-03-032-5/+8
| | | | | |
| * | | | | tor-netdoc: Rename *Signed to *UnverifiedIan Jackson2026-03-0313-60/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was a weird name, and while working in this area it all seemed to make the docs strange. Rename it. This is quite invasive! In theory we could have the macros generate compatibility aliases, but that seems quite complex.
| * | | | | tor-netdoc: Move NetdocSigned to signatures.rsIan Jackson2026-03-034-34/+36
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I keep not finding it because all the other signatures stuff is in signatures.rs.
| * | | | | tor-netdoc: Drop dir_auth_key_cert_signatures test caseIan Jackson2026-03-031-56/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This test case constructs a "netdoc" which consists of one dir-key-certification item, and parses it using `AuthCertSignatures as NetdocParseable`. But we're going to split out the parsing trait for signatures sections, so that's not going to work any more. This test tests only corner cases of the derived SignatureItemParseable implementation; but that's unit tested in the parse2 tests. (Once upon a time there was perhaps manual parsing code which needed a specific test.) Remove it.
* | | | | | Merge branch 'cell-order' into 'main'opara2026-03-047-80/+89
|\ \ \ \ \ \ | |_|_|_|/ / |/| | | | | | | | | | | | | | | | | Improve error messages during channel handshake See merge request tpo/core/arti!3745
| * | | | | tor-cell: rename `RestrictedMsg::restricted_cmds()` to `cmds_for_logging()`Steven Engler2026-03-043-4/+4
| | | | | |
| * | | | | tor-proto: small code cleanupSteven Engler2026-03-032-18/+6
| | | | | |
| * | | | | tor-proto: improve error messages using `RestrictedMsg`Steven Engler2026-03-032-35/+17
| | | | | |
| * | | | | tor-cell: add `RestrictedMsg` traitSteven Engler2026-03-031-0/+35
| | | | | |
| * | | | | tor-proto: improve error messages during handshakeSteven Engler2026-03-032-5/+7
| | | | | |
| * | | | | tor-basic-utils: clean up `iter_join`Steven Engler2026-03-031-8/+6
| | | | | |
| * | | | | tor-basic-utils: move `iter_join` from arti-relaySteven Engler2026-03-034-33/+37
| | | | | | | | | | | | | | | | | | | | | | | | Will clean this up in the following commit.
* | | | | | Merge branch 'dirclient-empty-successful' into 'main'Clara Engler2026-03-045-6/+39
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-dirclient: Disallow empty successful responses See merge request tpo/core/arti!3650
| * | | | | | tor-dirclient: Add semver.mdClara Engler2026-03-041-0/+1
| | | | | | |
| * | | | | | Rename DirResponse::from_body to from_get_bodyClara Engler2026-03-042-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This reflects that it is expected for an HTTP GET body. It is okay because it is only used in tor-dirmgr, which only performs GET request anyways.
| * | | | | | tor-dirclient: Only fail on empty GET responsesClara Engler2026-03-043-12/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit fixes the previous check to only fail on empty GET responses. For this, it introduces a `method` field into `DirResponse`, which is required to determine the method there. Doing this is reasonable for an HTTP client, as responses have different meanings depending on the request method used.
| * | | | | | tor-dirclient: Disallow empty successful responsesClara Engler2026-03-042-0/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit disallows empty responses with a status code 200. From a pure HTTP level, this is totally valid, but it does not make any sense in the context of the Tor directory protocol, where an empty response only makes sense with a 404. The motivation for this is that a work-in-progress tor_dirclient::send_request wrapper for tor-dirserver passes the response into the parse2 multiple function which returns a Vec<T>. Interfacing code would then always have to check for an empty length and do respective error handling, which should already fail at an earlier level (tor-dirclient) instead.
* | | | | | | Merge branch 'deps/relax-libsqlite3-sys' into 'main'Ian Jackson2026-03-042-3/+9
|\ \ \ \ \ \ \ | |/ / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | deps: relax `rusqlite` version requirement Closes #1740 See merge request tpo/core/arti!3706
| * | | | | | deps: use the same `rusqlite` version range for all cratesHydroxideUnlaced2026-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
| * | | | | | Apply 1 suggestion(s) to 1 file(s)HydroxideUnlaced2026-03-041-0/+1
| | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
| * | | | | | deps: relax `libsqlite3-sys` version requirementHydroxideUnlaced2026-03-042-3/+8
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The issue concerns `libsqlite3-sys` linking to a native library. Cargo cannot handle multiple versions/crates linking to the same native library. This affects both the `tor-dirmgr` and `tor-dirserver` crates, which depend on `rusqlite`. Relaxing the version requirement gives downstream projects flexibility so cargo can select an appropriate `libsqlite3-sys` version without a high chance of conflicts caused by pinning a specific version. The proposed supported version range was determined by testing until encountering a version lacking a feature currently in use (breaking unchange?). Regarding testing, the current CI with minimum-version test only validates the maximum and minimum versions, so breaking changes introduced between them can pass unnoticed. Tools like [Cargo-Bounds](https://github.com/vivax3794/cargo_bounds) can help, but this is out of scope for this MR. Also, supported versions of `rusqlite` for `tor-dirmgr` and `tor-dirserver` differ, so running tests for the whole project (same workspace) causes cargo to pick only overlapping versions, which hides parts of each crate’s supported range. Referencing #754, after this MR, increasing the maximum version or decreasing the minimum version of `rusqlite` shouldn't be a breaking change, but increasing the minimum version could be. Resolves: #1740
* | | | | | Merge branch 'readme-cleaning' into 'main'gabi-2502026-03-042-60/+1
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Remove some outdated README text Closes #2000 and #2063 See merge request tpo/core/arti!3748
| * | | | | README.md: Remove Roadmap sectionNick Mathewson2026-03-041-56/+0
| | | | | | | | | | | | | | | | | | | | | | | | It had grown quite old and outdated.
| * | | | | arti-client: Remove "not as secure as C Tor" text in the README.Nick Mathewson2026-03-041-4/+1
|/ / / / / | | | | | | | | | | | | | | | | | | | | I think we currently have the same security features implemented in Arti as C tor has.
* | | | | Merge branch 'version-bumps' into 'main'Alexander Hansen Færøy2026-03-0428-206/+147
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bump the deps that have breaking changes Closes #2383 See merge request tpo/core/arti!3746
| * | | | | Bump strum to 0.28Gabriela Moldovan2026-03-0415-42/+63
| | | | | |
| * | | | | rtcompat: Bump async-native-tls to 0.6.0Gabriela Moldovan2026-03-042-8/+8
| | | | | |
| * | | | | arti: Bump trycmd to 1.0.0Gabriela Moldovan2026-03-042-16/+16
| | | | | |
| * | | | | Downgrade security-frameworkGabriela Moldovan2026-03-041-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | See #2387
| * | | | | arti-ureq: Bump ureq to ~3.2.0Gabriela Moldovan2026-03-042-16/+16
| | | | | |
| * | | | | memquota: Bump sysinfo to 0.38.3Gabriela Moldovan2026-03-042-122/+33
| | | | | |
| * | | | | hashx: Bump dynasmrt to 5.0.0Gabriela Moldovan2026-03-045-15/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Contains a small code change as `bare_relocation()` was replaced with `value_relocation()`.
| * | | | | Bump toml_edit to 0.25.3Gabriela Moldovan2026-03-042-5/+5
| | | | | |
| * | | | | Bump toml to 1.0.3Gabriela Moldovan2026-03-0410-22/+31
|/ / / / /
* | | | | Merge branch 'cargo-update' into 'main'gabi-2502026-03-043-278/+288
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Run cargo update post-release See merge request tpo/core/arti!3740
| * | | | | Downgrade security-framework to 3.6.0Gabriela Moldovan2026-03-031-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | Version 3.7.0 doesn't seem to build in CI.
| * | | | | rtmock, chanmgr: Allow use of deprecated try_next() in testsGabriela Moldovan2026-03-032-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | futures 0.3.32 has deprecated UnboundedReceiver::try_next() in favor of UnboundedReceiver::try_recv(), but try_recv() was only introduced in 0.3.32, so using it would cause our minimal versions checks to fail (rightfully so, because our code wouldn't build with futures 0.3.x for x < 32).
| * | | | | Run cargo update post-releaseGabriela Moldovan2026-03-031-280/+286
| | |/ / / | |/| | |
* | | | | Merge branch 'workaround-mypy' into 'main'Jim Newsome2026-03-031-4/+17
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | python-lints: work around mypy import bug 20962 See merge request tpo/core/arti!3744
| * | | | python-lints: work around mypy import bug 20962Jim Newsome2026-03-031-4/+17
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When analyzing a script, mypy *should* look in the script's directory for imports, but appears not to do so when the script doesn't have a .py extension: https://github.com/python/mypy/issues/20962 We can work around that by adding the script's directory to MYPYPATH. With that workaround, we no longer need to add OTHER_PYTHON files to every invocation when analyzing scripts. That also worked around the problem in some cases, but experimentally not when the script is more than one subdirectory deep (?!)
* | | | Merge branch 'cell-order' into 'main'opara2026-03-035-144/+234
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-proto: Require specific cell order during handshake See merge request tpo/core/arti!3736
| * | | tor-proto: during handshake ensure circ id is 0Steven Engler2026-03-032-4/+18
| | | |
| * | | tor-proto: require cells from initiator to be orderedSteven Engler2026-03-031-61/+112
| | | |
| * | | tor-proto: require cells from responder to be orderedSteven Engler2026-03-032-61/+97
| | | |
| * | | tor-proto: make receiving AUTH_CHALLENGE non-optionalSteven Engler2026-03-032-8/+3
| | | |