| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
CI: Reduce disk usage after job ends
Closes #2669 and #2672
See merge request tpo/core/arti!4316
|
| | | | | | |
|
| | | | | | |
|
| | |/ / / |
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
maint/cargo-audit: Bump h2 to address RUSTSEC-2026-0258
See merge request tpo/core/arti!4318
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Older versions of `h2` have a bug that causes empty HTTP/2 DATA frames
to be queued without limit if the streams are not read from quickly
enough.
According to the [hyper advisory]:
> To determine if vulnerable, all these things must be true:
>
> * You are using HTTP/2, either as a server or a client.
> * Your application does not fully drain incoming request
> or response bodies (for example, a proxy applying backpressure,
> or a client that delays reading the body).
> * The direct remote peer is malicious and intentionally
> sends large numbers of empty DATA frames.
To my knowledge, the only non-example crates that use `hyper` are `arti`
and `tor-dirserver`. Both of them run HTTP/1.1 servers, so I don't
believe we're affected by the `h2` bug.
[hyper advisory]: https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
refactor: fail when all addresses bind fail
See merge request tpo/core/arti!4309
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
arti: refactor reload_cfg in preparation for RPC work
See merge request tpo/core/arti!4310
|
| | | | | |
| | | | |
| | | | | |
Co-authored-by: gabi-250 <[email protected]>
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Code movement only.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Right now this just helps us keep the parts of the
configuration-reloading logic in one place, and clarifies what needs
to be owned by the watcher thread and what doesn't.
Moving forward, this will help make the configuration something
that RPC can inspect and change.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
(If you drop a FileWatcher, the thread that makes it works will
exit.)
|
| |\ \ \ \ \
| |_|/ / /
|/| | | |
| | | | |
| | | | | |
Update the relay circuit reactor docs
See merge request tpo/core/arti!4313
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
There is no `BackwardReactor` heading, because there isn't that much to
say about it (it moves `RELAY` cells in the opposite direction, and
rejects RELAY_EARLY and PADDING_NEGOTIATE).
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| |/ / / / |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
Add take_until_with_limit methods for better developer experience, modified error handling, changed take_until to use take_until_with_limit and added tests.
See merge request tpo/core/arti!4082
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
These methods provide modified error handling,
changed take_until to use take_until_with_limit and added tests.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
refactor(tor-hsclient): use TaskHandle for expiring circuit task
See merge request tpo/core/arti!4290
|
| | | | | | | |
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
proto: Silently drop DESTROY/RELAY/CREATED cells on unknown circuits
Closes #2655
See merge request tpo/core/arti!4301
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
And say why it's okay to do so.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
These are no longer causing the channel reactor to shut down, so we need
to update this test accordingly.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
If we're a relay, we need to tolerate CREATED* with unrecognized
CircIds: for example, if we time out[^1] while trying to extend the circuit
by another hop, we will send a DESTROY to the extending hop, which can
race with the CREATED* response. In other words, a CREATED* cell
arriving on a closed circuit shouldn't be treated as a protocol
violation.
There are, however, a few cases where a CREATED* with an unknown CircId
*is* a protocol violation (and probably *should* cause us to close down
the channel):
* if the CREATED* is moving in the forward direction (towards the
exit), or
* if we have not previously sent a CREATE* with that particular CircId
As before, distinguishing these from the "closed circuit" case above
would involve some tricky logic, and the benefits are unclear, while the
downsides of closing a channel when we shouldn't have are significant.
It seems better to just drop these cells for now.
Closes #2655
[^1]: at the time of writing, we don't have timeouts for the circuit
extension logic, so what I've described here cannot actually happen
today. However, we *do* have a TODO for it, so the time outs I've
described here will be implemented at some point
|
| | | | | | | |
|
| | | |_|_|/
| |/| | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
An unrecognized circuit ID is not always a protocol violation, so we
shouldn't close down the channel if it happens.
This change makes the channel reactor drop DESTROY and RELAY cells with
unknown CircIds without closing down the channel. It affects both
clients and relays.
Instead of dropping these unconditionally, we could have implemented
some more sophisticated checks to distinguish the bogus CircIds from the
CircIds of closed circuits, but it's unclear if it's worth the added
complexity (see discussion in #2655).
This partly addresses #2646 (an unrecognized circuit ID shouldn't cause
us to close down the channel if we're a relay).
This commit partially undoes the changes from
4f567e4a9432b340c2799e600c8ceb3724ad3082,
which was originally intended to mitigate flooding attacks.
Part of #2655
|
| |\ \ \ \ \
| |_|_|/ /
|/| | | |
| | | | |
| | | | | |
tor-proto: Some misc rust/clippy warning fixes
See merge request tpo/core/arti!4304
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This fixes an `unfulfilled_lint_expectations` warning.
tor-proto conditionally sets a global `allow(unused)`, and if you have
an `expect(unused)` field within an `allow(unused)` struct, rust seems
to warn with 'unfulfilled_lint_expectations'.
https://github.com/rust-lang/rust/issues/160942
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
This fixes a `clippy::large_enum_variant`.
|
| | | | | | |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Support DirBackendPlugin kludge in tor-dirserver
See merge request tpo/core/arti!4306
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit improves the empty body check by failing if it has happened.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds support for the directory backend plugin kludge by
adding a new wrapper struct called `DirMirrorWithBackend`.
It also moves http-body-util from a development dependency to a real
dependency, as this makes working with hyper a lot more comfortable.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds marker traits as dependencies for implementations of
the DirBackendPlugin trait, which will be required for intergration
with hyper.
Works like a charm, as DirMgr itself implements all three of these
already.
|
| | |/ / / /
| | | | |
| | | | |
| | | | | |
No longer required.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
fix: the number of dns queries should be 1
See merge request tpo/core/arti!4281
|
| | | | | | | |
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-proto: Handle incoming CREATE2 with ntor-v3 handshakes
See merge request tpo/core/arti!4176
|