summaryrefslogtreecommitdiff
path: root/Cargo.lock
Commit message (Collapse)AuthorAgeFilesLines
...
* | Merge branch 'safelog_more' into 'main'Ian Jackson2022-08-261-0/+1
|\ \ | |/ |/| | | | | Apply safelog to more of the things that we log See merge request tpo/core/arti!693
| * tor-chanmgr: don't log addresses so much.Nick Mathewson2022-08-251-0/+1
| | | | | | | | | | We now log connection attempts at debug!, and mark relay target addresses as sensitive.
* | arti: cfg: Rename `*_port` to `*_listen` and change the typeIan Jackson2022-08-251-0/+1
| | | | | | | | | | | | | | This commit largely follows the example for resolve_alternative_specs. The difference is that there are two fields, so we use a macro to avoid recapitulating the field names.
* | tor-config: Provide misc::ListenIan Jackson2022-08-251-0/+1
| |
* | tor-basic-utils: Provide IoErrorExt is_not_a_directory()Ian Jackson2022-08-251-0/+1
|/ | | | | We're going to want this functionality, which isn't in the stable stdlib.
* arti_client: Refuse to build a client if we are setuid.Nick Mathewson2022-08-241-0/+1
| | | | | | Arti is not designed to be a setuid-safe program. Part of #523.
* tor-cell: PaddingNegotiate::start: take IntegerMillisecondsIan Jackson2022-08-171-0/+1
|
* channel padding: Test through most of the layersIan Jackson2022-08-171-0/+1
|
* channel padding: Send negotiation cellsIan Jackson2022-08-161-0/+1
|
* Introduce ChannelConfigIan Jackson2022-08-161-0/+3
| | | | | This commit is just the necessary plumbing. The config is currently empty. We'll add something to it, for padding control, later.
* tor-config: Introduce PaddingLevelIan Jackson2022-08-161-0/+1
| | | | This will be used for controlling channel padding, for now.
* tor-proto: padding::Parameters: use impl_standard_builderIan Jackson2022-08-161-0/+1
| | | | | | | This is more standard. It also provides the ::build() method. This isn't a config type, and build failures ought not to happen, so we use Bug for the error.
* arti: Add support for process hardeningNick Mathewson2022-08-151-0/+13
| | | | | | | | | | | | | This is a compile-time feature with an associated configuration flag, both enabled by default. When it's turned on, hardening prevents the arti process from dumping core or being attached to by low-privileged processes. (This is a defense-in-depth measure, not an absolute way to prevent attacks. For more information, see [`secmem_proc`](https://docs.rs/secmem-proc/0.1.1/secmem_proc/).) Closes #364.
* Merge branch 'less_arti_surface' into 'main'Nick Mathewson2022-08-111-0/+1
|\ | | | | | | | | | | | | Reduce the arti crate's API surface; improve semver documentation. Closes #522, #530, and #532 See merge request tpo/core/arti!664
| * arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-111-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
* | tor-congestion: implement the RTT estimation algorithm from prop#324eta2022-08-111-0/+10
| | | | | | | | | | | | | | | | | | | | | | This commit implements the round-trip-time estimation algorithm from Tor proposal 324, validating the implementation against the test vectors found in C tor. (Note that at the time of writing, the new test vectors may not be committed to C tor yet, but they will be soon.) This also adds the necessary consensus parameters to `NetParameters`. Some of them have been renamed in order to (hopefully) make them more understandable.
* | Merge branch 'main' into 'linkspec_refactor_v3'Nick Mathewson2022-08-101-26/+7
|\ \ | | | | | | | | | # Conflicts: # crates/tor-netdir/semver.md
| * | Update shellexpand, and switch to non-forkIan Jackson2022-08-051-26/+5
| |/ | | | | | | | | | | | | | | Now we have bus>1 ownership of the crate name `shellexpand`. I have made a release, and retired `shellexpand-fork`. The new shellexpand release switches to a (quite similarly) unforked version of `dirs`.
| * New SecretBuf type in tor-bytesNick Mathewson2022-08-011-0/+1
| | | | | | | | | | | | | | | | | | This Writer is a simple wrapper around `Vec<u8>` that makes sure that its contents are cleared whenever they are dropped _or reallocated_. The reallocation is the important part here: without that, we risk not zeroizing the first allocation of the buffer.
| * Use the `zeroize` feature in several cratesNick Mathewson2022-08-011-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | Using `zeroize` here tells these crates that they should make various structures zeroize-on-drop. (This is not yet implemented in `aes` 0.8.1, but support has been merged in the repository for `aes`, so it should go out in the next release.) No corresponding feature flag is needed to enable zeroize-on-drop for `rsa` and `*25519-dalek` private keys.
* | tor-proto: Unify the check_match code in channel and handshakeNick Mathewson2022-08-101-0/+1
| | | | | | | | | | | | | | | | | | | | This had to become a new internal function, since at the point that the handshake needs this code, it does not yet have a Channel to use. This change made the error messages in the handshake code more informative: and now they require a regex to check. Later, we might want to defer formatting these strings, but I don't think we need to do it now.
* | tor-netdir: Add a static assertion about RelayIdType::COUNTNick Mathewson2022-08-101-0/+1
| | | | | | | | | | | | | | Doing this will make sure that we fix a correctness issue in netdir that will be caused if we add more IDs. (Also add RelayIdType::COUNT in tor-linkspec.)
* | Parsing, encoding, and serde for RelayId.Nick Mathewson2022-08-101-0/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The formats used here are backward-compatible with those used by C tor and those used elsewhere in our code. We need a way to encode _both_ current kinds of identities as a string that tells you what kind of ID they are. Traditionally we have used hexadecimal, sometimes with a $, for RSA ids, and we have used base64 for Ed25519 IDs. We also introduce a new forward-compatible format for new identity keys in the future. (The new format is the key identity type, a colon, and the id encoded as base64.) We will use this new format _only_ when we need to encode identities in a way where it would be otherwise unclear what kind of key we are dealing with.
* | Add a set of Identity-related types and accessors.Nick Mathewson2022-08-101-0/+2
| | | | | | | | | | | | | | I wonder if these types are correct. I think it makes sense to have a Ref type like this, rather than just using `&RelayId`, but it doesn't seems that I can make `RelayId` and `RelayIdRef` implement Borrow and ToOwned for one another, so maybe I've messed up.
* | Implement serde traits on RelayIds.Nick Mathewson2022-08-021-0/+1
|/ | | | | This will allow RelayIds to replace IdPair in tor-guardmgr. (The fields are named accordingly with `serde(rename)`.)
* Update Cargo.lock based on version bumps.Nick Mathewson2022-08-011-24/+24
|
* Run "cargo update" in preparation for next week's release.Nick Mathewson2022-07-271-90/+58
|
* Update arti-client to new NetDirProvider API.Nick Mathewson2022-07-261-0/+2
| | | | | | This allows us to give better errors in the case where bootstrapping succeeds at first, but fails thereafter for long enough to make our directory expire.
* Also downgrade serde_with: Version 2.0 requires Rust 1.60Nick Mathewson2022-07-201-40/+44
|
* Downgrade phf back to 0.10Nick Mathewson2022-07-201-8/+16
| | | | | It turns out that phf 0.11 depends on Rust 1.60, which is above our MSRV.
* Run "cargo update" in preparation for next week's releases.Nick Mathewson2022-07-201-44/+48
|
* Upgrade to latest phf, serde_with, serial_test.Nick Mathewson2022-07-191-64/+53
|
* Bump to rusqlite 0.28.Nick Mathewson2022-07-191-9/+8
|
* Provide maybe_send on postage::watch::Sender, via extension traitIan Jackson2022-07-181-0/+2
| | | | | | | | | | | | We need to replace the AtomicBool for dormant mode with something that can wake up tasks. postage::watch is the right shape. But we want to be able to update it but suppress no-op updates. (There is going to be a call site where no-op updates can occur.) In the absence of a suitable upstream method as requested here https://github.com/austinjones/postage-rs/issues/56 we introduce this facility via an extension trait.
* Bump tor-dirmgr to version 0.5.1.tor-dirmgr-v0.5.1Nick Mathewson2022-07-141-1/+1
| | | | | This does not require a change in any other crate, since the change here does not affect tor-dirmgr's APIs.
* Merge branch 'generate_cert' into 'main'Nick Mathewson2022-07-081-0/+2
|\ | | | | | | | | | | | | Implement functionality to construct signed Ed25519 certs. Closes #511 See merge request tpo/core/arti!611
| * Implement functionality to construct signed Ed25519 certs.Nick Mathewson2022-07-061-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is behind a feature flag, since it isn't needed for pure clients: only onion services and relays need this. I've named the object that constructs these certs `Ed25519CertConstructor` because it doesn't follow the builder pattern exactly: mainly because you can't get an Ed25519Cert out of it. _That_ part is necessary because we require that an Ed25519Cert should only exist if the certificate was found to be well-signed with the right public key. Closes #511.
* | Merge branch 'persist-error-cleanup' into 'main'eta2022-07-061-0/+1
|\ \ | | | | | | | | | | | | tor-persist: Big refactoring on Error type. See merge request tpo/core/arti!614
| * | tor-persist: Big refactoring on Error type.Nick Mathewson2022-07-061-0/+1
| |/ | | | | | | | | | | | | | | | | | | | | Every error now has an action (what we were trying to do), a resource (what we were trying to do it to), and a source (what problem we encountered). Initially I tried to add "action" and "resource" fields to error variants individually, but that led to a combinatorial explosion. Part of #323.
* | Merge branch 'update-rsa-v2' into 'main'Ian Jackson2022-07-061-50/+39
|\ \ | | | | | | | | | | | | | | | | | | Update `rsa` dependency (and use `x25519-dalek` prerelease) Closes #448 See merge request tpo/core/arti!612
| * | Update `rsa` dependency (and use `x25519-dalek` prerelease)eta2022-07-061-50/+39
| |/ | | | | | | | | | | | | | | | | | | | | | | | | | | - arti#448 and arti!607 highlight an issue with upgrading `rsa`: namely, the `x25519-dalek` version previously used has a hard dependency on `zeroize` 1.3, which creates a dependency conflict. - However, `x25519-dalek` version `2.0.0-pre.1` relaxes this dependency. Reviewing the changelogs, it doesn't look like that version is substantially different from the current one at all, so it should be safe to use despite the "prerelease" tag. - The new `x25519-dalek` version also bumps `rand_core`, which means we don't have to use the RNG compat wrapper in `tor-llcrypto` as much. closes arti#448
* / tor-netdoc: b64 tests: add exhaustive roundtrip testIan Jackson2022-07-061-0/+1
|/
* cargo updateIan Jackson2022-07-051-36/+36
| | | | | | This fixes a complaint from cargo audit about https://rustsec.org/advisories/RUSTSEC-2022-0032 in openssl.
* Bump `base64ct` crate `1.5.0` -> `1.5.1`Arturo Marquez2022-06-271-2/+2
| | | | | | This new release checks for invalid symbols in non-padded inputs for decoding. Therefore, we can get rid of the logic implemented in `https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/600`
* Bump crate and dependency versions.Nick Mathewson2022-06-241-24/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These were done with the following commands: ``` cargo set-version -p tor-basic-utils --bump patch cargo set-version -p fs-mistrust --bump minor cargo set-version -p tor-error --bump patch cargo set-version -p tor-config --bump patch cargo set-version -p tor-units --bump patch cargo set-version -p tor-rtcompat --bump minor cargo set-version -p tor-llcrypto --bump patch cargo set-version -p tor-bytes --bump minor cargo set-version -p tor-socksproto --bump minor cargo set-version -p tor-cert --bump minor cargo set-version -p tor-cell --bump minor cargo set-version -p tor-proto --bump minor cargo set-version -p tor-netdoc --bump patch cargo set-version -p tor-netdir --bump minor cargo set-version -p tor-persist --bump patch cargo set-version -p tor-chanmgr --bump minor cargo set-version -p tor-guardmgr --bump minor cargo set-version -p tor-circmgr --bump patch cargo set-version -p tor-dirclient --bump patch cargo set-version -p tor-dirmgr --bump minor cargo set-version -p arti-client --bump patch cargo set-version -p arti --bump minor cargo set-version -p arti-bench --bump minor cargo set-version -p arti-testing --bump minor ```
* Increment versions of crates with trivial changes only.Nick Mathewson2022-06-241-11/+11
| | | | | | "Trivial" here includes stuff like cargo reformatting, comment edits, error message string changes, and clippy warning changes. Crates that depend on these do not need to increment.
* Merge branch 'error_cleanup_2' into 'main'eta2022-06-241-0/+1
|\ | | | | | | | | Error refactoring: bytes, cert, proto. See merge request tpo/core/arti!604
| * tor-proto: split and elaborate tor_bytes::Error instancesNick Mathewson2022-06-231-0/+1
| | | | | | | | | | | | | | | | | | Some of these were for decoding particular objects (we now say what kind of objects), and some were unrelated tor_cert errors that for some reason we had shoved into a tor_bytes::Error. There is now a separate tor_cert::CertError type, independent from tor_cert's use of `tor_bytes::Error` for parsing errors.
* | Run cargo upgrade in preparation for release.Nick Mathewson2022-06-241-10/+10
| |
* | Merge branch 'tor-netdoc/use-base64ct' into 'main'Ian Jackson2022-06-231-5/+5
|\ \ | |/ |/| | | | | Replace `base64` crate with `base64ct` crate in `tor-netdoc` See merge request tpo/core/arti!600