aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | Merge branch 'ci-cleanup' into 'main'Jim Newsome8 days1-3/+14
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | CI: Reduce disk usage after job ends Closes #2669 and #2672 See merge request tpo/core/arti!4316
| * | | | ci: clean up build artifacts in 'deb-binary-{amd,arm}64' jobsSteven Engler9 days1-0/+3
| | | | |
| * | | | ci: `rm -r ./target` in 'after_script'Steven Engler9 days1-3/+7
| | | | |
| * | | | ci: show disk usage of project directorySteven Engler9 days1-0/+4
| |/ / /
* | | | Merge branch 'bump-hyper' into 'main'Nick Mathewson8 days1-16/+16
|\ \ \ \ | |/ / / |/| | | | | | | | | | | maint/cargo-audit: Bump h2 to address RUSTSEC-2026-0258 See merge request tpo/core/arti!4318
| * | | maint/cargo-audit: Bump h2 to address RUSTSEC-2026-0258Gabriela Moldovan8 days1-16/+16
|/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Older versions of `h2` have a bug that causes empty HTTP/2 DATA frames to be queued without limit if the streams are not read from quickly enough. According to the [hyper advisory]: > To determine if vulnerable, all these things must be true: > > * You are using HTTP/2, either as a server or a client. > * Your application does not fully drain incoming request > or response bodies (for example, a proxy applying backpressure, > or a client that delays reading the body). > * The direct remote peer is malicious and intentionally > sends large numbers of empty DATA frames. To my knowledge, the only non-example crates that use `hyper` are `arti` and `tor-dirserver`. Both of them run HTTP/1.1 servers, so I don't believe we're affected by the `h2` bug. [hyper advisory]: https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h
* | | Merge branch 'all_bind_addr_fail' into 'main'Jim Newsome9 days1-1/+6
|\ \ \ | | | | | | | | | | | | | | | | refactor: fail when all addresses bind fail See merge request tpo/core/arti!4309
| * | | bind_dns_resolver: fail when no addresses in a group can bindSteven Masnada9 days1-1/+6
| | | |
* | | | Merge branch 'config-refactor-v3' into 'main'Nick Mathewson9 days3-130/+176
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti: refactor reload_cfg in preparation for RPC work See merge request tpo/core/arti!4310
| * | | | Apply 1 suggestion(s) to 1 file(s)Nick Mathewson9 days1-1/+1
| | | | | | | | | | | | | | | Co-authored-by: gabi-250 <[email protected]>
| * | | | Reindent impl block.Nick Mathewson13 days1-87/+88
| | | | |
| * | | | Move reload_configuration method.Nick Mathewson13 days1-40/+37
| | | | | | | | | | | | | | | | | | | | Code movement only.
| * | | | reload_cfg: Refactor to use a CfgMgr object.Nick Mathewson13 days2-87/+134
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Right now this just helps us keep the parts of the configuration-reloading logic in one place, and clarifies what needs to be owned by the watcher thread and what doesn't. Moving forward, this will help make the configuration something that RPC can inspect and change.
| * | | | tor-config: Make FileWatcher must_use.Nick Mathewson13 days1-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | (If you drop a FileWatcher, the thread that makes it works will exit.)
* | | | | Merge branch 'proto-docs' into 'main'opara9 days2-25/+29
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | Update the relay circuit reactor docs See merge request tpo/core/arti!4313
| * | | | README_relay: Check off a couple of circuit reactor itemsGabriela Moldovan9 days1-2/+2
| | | | |
| * | | | proto: Remove redundant headingGabriela Moldovan9 days1-2/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There is no `BackwardReactor` heading, because there isn't that much to say about it (it moves `RELAY` cells in the opposite direction, and rejects RELAY_EARLY and PADDING_NEGOTIATE).
| * | | | proto: Update table to mention all the other commands we handleGabriela Moldovan9 days1-2/+8
| | | | |
| * | | | proto: Be more specific about where the meta messages are handledGabriela Moldovan9 days1-14/+15
| | | | |
| * | | | proto: Say how forward DESTROY are handledGabriela Moldovan9 days1-1/+2
| | | | |
| * | | | proto: Clarify that "it" refers to the forward reactorGabriela Moldovan9 days1-1/+2
| | | | |
| * | | | proto: Update docs to clarify they apply to RELAY_EARLY tooGabriela Moldovan9 days1-3/+2
| | | | |
| * | | | proto: Update docs to say EXTEND2 is supportedGabriela Moldovan9 days1-5/+2
| | | | |
| * | | | proto: Update reactor docs to say TRUNCATE is unsupportedGabriela Moldovan9 days1-2/+3
|/ / / /
* | | | Merge branch 'take_until_with_limit' into 'main'Nick Mathewson13 days2-10/+90
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Add take_until_with_limit methods for better developer experience, modified error handling, changed take_until to use take_until_with_limit and added tests. See merge request tpo/core/arti!4082
| * | | | Add take_until_with_limit methods for better developer experience,pryty262026-07-022-10/+90
| | | | | | | | | | | | | | | | | | | | | | | | | These methods provide modified error handling, changed take_until to use take_until_with_limit and added tests.
* | | | | Merge branch 'refactor-use-task-handler' into 'main'Nick Mathewson13 days2-20/+13
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | refactor(tor-hsclient): use TaskHandle for expiring circuit task See merge request tpo/core/arti!4290
| * | | | | refactor: use TaskHandle for expiring circuitiqdecay13 days2-20/+13
| | | | | |
* | | | | | Merge branch 'unk-circid' into 'main'gabi-25013 days2-40/+49
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | proto: Silently drop DESTROY/RELAY/CREATED cells on unknown circuits Closes #2655 See merge request tpo/core/arti!4301
| * | | | | proto: Explicitly drop the cells with unrecognized CircIdsGabriela Moldovan2026-08-121-0/+20
| | | | | | | | | | | | | | | | | | | | | | | | And say why it's okay to do so.
| * | | | | proto: Update tests now that unrecognized CREATED are droppedGabriela Moldovan2026-08-111-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These are no longer causing the channel reactor to shut down, so we need to update this test accordingly.
| * | | | | proto: Update tests now that we tolerate unrecognized CircIdsGabriela Moldovan2026-08-111-24/+8
| | | | | |
| * | | | | proto: s/channel/circuit in test commentGabriela Moldovan2026-08-111-1/+1
| | | | | |
| * | | | | proto: Ignore CREATED* with unrecognized CircIdsGabriela Moldovan2026-08-112-9/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we're a relay, we need to tolerate CREATED* with unrecognized CircIds: for example, if we time out[^1] while trying to extend the circuit by another hop, we will send a DESTROY to the extending hop, which can race with the CREATED* response. In other words, a CREATED* cell arriving on a closed circuit shouldn't be treated as a protocol violation. There are, however, a few cases where a CREATED* with an unknown CircId *is* a protocol violation (and probably *should* cause us to close down the channel): * if the CREATED* is moving in the forward direction (towards the exit), or * if we have not previously sent a CREATE* with that particular CircId As before, distinguishing these from the "closed circuit" case above would involve some tricky logic, and the benefits are unclear, while the downsides of closing a channel when we shouldn't have are significant. It seems better to just drop these cells for now. Closes #2655 [^1]: at the time of writing, we don't have timeouts for the circuit extension logic, so what I've described here cannot actually happen today. However, we *do* have a TODO for it, so the time outs I've described here will be implemented at some point
| * | | | | proto: Silently drop DESTROY/RELAY cells on unknown circuits (fmt)Gabriela Moldovan2026-08-111-5/+3
| | | | | |
| * | | | | proto: Silently drop DESTROY/RELAY cells on unknown circuitsGabriela Moldovan2026-08-111-4/+6
| | |_|_|/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | An unrecognized circuit ID is not always a protocol violation, so we shouldn't close down the channel if it happens. This change makes the channel reactor drop DESTROY and RELAY cells with unknown CircIds without closing down the channel. It affects both clients and relays. Instead of dropping these unconditionally, we could have implemented some more sophisticated checks to distinguish the bogus CircIds from the CircIds of closed circuits, but it's unclear if it's worth the added complexity (see discussion in #2655). This partly addresses #2646 (an unrecognized circuit ID shouldn't cause us to close down the channel if we're a relay). This commit partially undoes the changes from 4f567e4a9432b340c2799e600c8ceb3724ad3082, which was originally intended to mitigate flooding attacks. Part of #2655
* | | | | Merge branch 'clippy-fixes' into 'main'gabi-25013 days4-5/+8
|\ \ \ \ \ | |_|_|/ / |/| | | | | | | | | | | | | | tor-proto: Some misc rust/clippy warning fixes See merge request tpo/core/arti!4304
| * | | | tor-proto: 'expect' -> 'allow' in `CircReactorHandle`Steven Engler2026-08-111-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes an `unfulfilled_lint_expectations` warning. tor-proto conditionally sets a global `allow(unused)`, and if you have an `expect(unused)` field within an `allow(unused)` struct, rust seems to warn with 'unfulfilled_lint_expectations'. https://github.com/rust-lang/rust/issues/160942
| * | | | tor-proto: fix a `clippy::unnecessary_filter_map`Steven Engler2026-08-111-0/+2
| | | | |
| * | | | tor-proto: box `CircParameters` in test-only `CtrlCmd::AddFakeHop`Steven Engler2026-08-112-2/+3
| | | | | | | | | | | | | | | | | | | | This fixes a `clippy::large_enum_variant`.
| * | | | tor-proto: fix a 'clippy::useless_conversion'Steven Engler2026-08-111-1/+1
| | | | |
* | | | | Merge branch 'backend-dirserver' into 'main'Clara Engler13 days4-4/+139
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Support DirBackendPlugin kludge in tor-dirserver See merge request tpo/core/arti!4306
| * | | | | tor-dirserver: Disallow non GET methodsClara Engler2026-08-121-0/+5
| | | | | |
| * | | | | tor-dirserver: Improve empty body checkClara Engler2026-08-121-1/+10
| | | | | | | | | | | | | | | | | | | | | | | | This commit improves the empty body check by failing if it has happened.
| * | | | | tor-dirserver: Support DirBackendPlugin kludgeClara Engler2026-08-123-2/+124
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds support for the directory backend plugin kludge by adding a new wrapper struct called `DirMirrorWithBackend`. It also moves http-body-util from a development dependency to a real dependency, as this makes working with hyper a lot more comfortable.
| * | | | | tor-dircommon: Sync + Send + 'static for DirBackendPluginClara Engler2026-08-121-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds marker traits as dependencies for implementations of the DirBackendPlugin trait, which will be required for intergration with hyper. Works like a charm, as DirMgr itself implements all three of these already.
| * | | | | tor-dirserver: Remove unused_async lintClara Engler2026-08-121-1/+0
| |/ / / / | | | | | | | | | | | | | | | No longer required.
* | | | | Merge branch 'dns_qdcount_must_be_one' into 'main'Nick Mathewson2026-08-121-68/+71
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | fix: the number of dns queries should be 1 See merge request tpo/core/arti!4281
| * | | | | fix: the number of dns queries should be 1steven2026-08-041-68/+71
| | | | | |
* | | | | | Merge branch 'ntor-v3' into 'main'opara2026-08-128-58/+336
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Handle incoming CREATE2 with ntor-v3 handshakes See merge request tpo/core/arti!4176