| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |
|
| |
|
|
|
|
|
|
| |
For calculating `ipv6-policy` in routerdescs.
Also implement for v4 for the benefit of future tests of approximate
port policy summaries, for possible future protocol change, and for
completeness.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Fixes cargo-audit failure, due to spin 0.9.8 being yanked:
The changelog entry for 0.9.9 says:
> ### Fixed
>
> - Unsoundness in `Once::force_into_inner`, `Once::try_into_inner`, and
> `Once::into_inner_unchecked`. \[...]
In our stack, spin <- lazy_static 1.5.0 (only). lazy_static
1.5.0 (git tag) has no hits for `into_inner`. So I think we don't
have any calls to the previously-unsound methods.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
RUSTSEC-2026-0204 doesn't affect Arti, so this won't need a TROVE.
I checked using the procedure documented under "Checking whether we are
affected by a RUSTSEC" in `doc/dev/SecurityResponse.md`. I applied the
following patch to my local `crossbeam-epoch` to remove the affected
impls, and confirmed that Arti still builds successfully with it:
```diff
diff --git a/crossbeam-epoch/src/atomic.rs b/crossbeam-epoch/src/atomic.rs
index 41b4cd91..8b9b3a01 100644
--- a/crossbeam-epoch/src/atomic.rs
+++ b/crossbeam-epoch/src/atomic.rs
@@ -939,14 +939,6 @@ impl<T: ?Sized + Pointable> fmt::Debug for Atomic<T> {
}
}
-impl<T: ?Sized + Pointable> fmt::Pointer for Atomic<T> {
- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
- let data = self.data.load(Ordering::SeqCst);
- let (raw, _) = decompose_tag::<T>(data);
- fmt::Pointer::fmt(&(unsafe { T::deref(raw) as *const _ }), f)
- }
-}
-
impl<T: ?Sized + Pointable> Clone for Atomic<T> {
/// Returns a copy of the atomic value.
///
@@ -1660,12 +1652,6 @@ impl<T: ?Sized + Pointable> fmt::Debug for Shared<'_, T> {
}
}
-impl<T: ?Sized + Pointable> fmt::Pointer for Shared<'_, T> {
- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
- fmt::Pointer::fmt(&(unsafe { self.deref() as *const _ }), f)
- }
-}
-
impl<T: ?Sized + Pointable> Default for Shared<'_, T> {
fn default() -> Self {
Shared::null()
```
Note: the reason the `fmt::Pointer` impls I removed above look slightly
different from the ones in the [crossbeam-rs MR] from the RUSTSEC page
is because my patched `crossbeam-epoch` is based on the
`crossbeam-epoch-0.9.18` tag rather than `main`.
[crossbeam-rs MR]: https://github.com/crossbeam-rs/crossbeam/pull/1273/files
|
| |\
| |
| |
| |
| | |
Upgrade cipher, aes, and ctr.
See merge request tpo/core/arti!4195
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Negotiate flowcontrol-cc and CGO on onion services
Closes #2473 and #1948
See merge request tpo/core/arti!4135
|
| | | | |
|
| |/ /
| |
| |
| | |
This will be used for exit port summary calculations.
|
| |\ \
| |/
|/|
| |
| | |
Upgrade itertools to 0.15.0
See merge request tpo/core/arti!4192
|
| | |
| |
| |
| |
| |
| | |
Additionally, fix itertools usage in maybenot_padding.rs
The definition of `Position` changed in 0.15.0.
|
| |\ \
| |/
|/|
| |
| | |
Upgrade rdrand dependency to 0.9
See merge request tpo/core/arti!4194
|
| | | |
|
| |/ |
|
| |\
| |
| |
| |
| | |
Run cargo-update and fix deprecation warnings
See merge request tpo/core/arti!4187
|
| | | |
|
| |/
|
|
|
|
|
|
|
|
|
| |
This enables us to make these configurable: any relays that are not
configured to be an exit will exclude BEGIN and RESOLVE from their list
of allowed commands, causing exit and DNS streams to be rejected as soon
as the BEGIN/RESOLVE cell is received in the circuit reactor.
Context: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/4145#note_3430345
Part of #2606
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
Closes #2617.
We've lucked out this time, and it turns out that every one of our
published crates gets a minor bump. So this was generated with:
```
for cr in $(./maint/list-crates); do
cargo set-version -p $cr --bump minor
done
```
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This resolves unsoundness in anyhow (RUSTSEC-2026-0190).
https://rustsec.org/advisories/RUSTSEC-2026-0190.html
> Affected versions of this crate violate borrow rules, resulting in
> undefined behavior, when the user adds context to an error via
> `Error::context` and then later calls `Error::downcast_mut` on the
> returned `Error`.
I don't see us calling `downcast_mut()` on any errors. It's possible
something outside of the arti code base is calling it, but I think it's
unlikely.
|
| |
|
|
| |
We will make use of it in the next commit.
|
| |\
| |
| |
| |
| |
| |
| | |
tor-netdoc: addr policy: Overhaul and fix /0 bug
Closes #2589
See merge request tpo/core/arti!4128
|
| | |
| |
| |
| |
| | |
ipnet is a very widely used crate which is already in our dependency
stack.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| | |
This commit upgrades memmap2 to 0.9.11 in order to fix an unchecked
pointer offset in the memmap2 crate.
We are not directly affected by this, as `tor-dirmgr`, the only crate
making use of this dependency, does not call the affected functions
listed on rustsec.org.
|
| |\ \
| | |
| | |
| | |
| | | |
Create dirauth crates (empty)
See merge request tpo/core/arti!4122
|
| | | |
| | |
| | |
| | | |
Let's start this now.
|
| | |/ |
|
| |/ |
|
| |
|
|
|
| |
We're going to need this for fudges in round trip tests of consensuses
etc.
|
| |
|
|
|
|
| |
And wrap it up nicely in an assert_eq_or_diff macro.
I've tested the output by sabotaging one of the test2 tests.
|
| |
|
|
|
|
| |
This commit replaces a call to .duration_since(...).expect() with
.saturating_duration_since() for defensive programming. We will change
code related to it in the next commit.
|
| |
|
|
| |
New beta semver policy means we should pin the patchlevel.
|
| |
|
|
| |
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
| |
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
| |
Closes #2562
|
| | |
|
| |
|
|
| |
Part of #2559
|
| |\
| |
| |
| |
| | |
Run routine cargo update
See merge request tpo/core/arti!4045
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Without this, the shadow integration tests fail because
`touch_instance_dir()` isn't able to set the mtime on the state dir:
```
Err(Error { source: IoError(Os { code: 14, kind: Uncategorized, message: "Bad address" }), action: Initializing, resource: Directory { dir: "./hss/tgen_hs" } })
```
I suspect switching to the stblib implementation of these functions in
https://github.com/alexcrichton/filetime/pull/121 is what broke things
for us.
The new implementation calls into rust's `set_times()` impl, which calls
the `utimensat64` libc function under the hood. I suspect the underlying
syscall used by this function is not supported by shadow.
|
| | |
| |
| |
| | |
Part of #2599
|
| |/
|
|
|
|
| |
This adds a structure to initialize metrics when the `ChanMgr` is
created, and adds a counter for the total number of channels built,
broken down by success and failure.
|
| | |
|
| |
|
|
|
|
|
|
|
|
| |
Done using:
```
for crate in $(./maint/list-crates | rg '^(tor|arti-)'); do
cargo set-version -p $crate 0.43.0
done
```
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
The non-{arti-,tor-} crates are:
```
./maint/list-crates | rg -v '^(tor|arti)'
oneshot-fused-workaround
web-time-compat
slotmap-careful
test-temp-dir
fslock-guard
hashx
equix
caret
fs-mistrust
safelog
retry-error
futures-copy
```
We split them in the following categories:
* crates with no changes (no version bumps):
```
oneshot-fused-workaround: No change.
web-time-compat: No change.
slotmap-careful: No change.
test-temp-dir: No change.
caret: No change.
safelog: No change.
retry-error: No change.
futures-copy: No change.
```
Obtained with:
```
maint/changed-crates -v "arti-v$LAST_VERSION" 2>&1 >/dev/null | grep -i "no change" | grep -v '\(tor\|arti\)-'
```
* crates that only have non-functional changes (bump the patch version,
but not the dependend-on version):
- equix
* crates where functional changes were made, but no APIs were broken
(bump patch):
- fs-mistrust
* crates where APIs were broken (bump minor):
- hashx
- fslock-guard
The bumps from this commit were created using this script:
```
PATCH_NF=(
equix
)
PATCH="
fs-mistrust
"
MINOR="
hashx
fslock-guard
"
./maint/bump-nodep "${PATCH_NF[@]}"
for crate in $PATCH; do
cargo set-version --bump patch -p $crate;
done
for crate in $MINOR; do
cargo set-version --bump minor -p $crate;
done
```
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
We need these because `File::lock()` and `File::try_lock()`
claim not to work on Android, and have to be emulated with flock.
For more information, see
<https://github.com/rust-lang/rust/issues/148325>.
Closes #2544.
Based on code by @syphyr.
Co-Authored-By: syphyr <[email protected]>
|
| |\
| |
| |
| |
| | |
fslock-guard: Use windows-sys and GetFileInformationByHandleEx.
See merge request tpo/core/arti!3974
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Unlike winapi, windows-sys is maintained (by microsoft),
and supports more APIs. We use it elsewhere in our tree,
but this was our largest usae of winapi.
The GetFileInformationByHandleEx variant includes an
explicit buffer size to make errors harder,
and enables us to get a 128-bit file identifier,
which is (supposedly) even more unique than the 64-bit
identifiers we were looking at before.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This new method modifies a builder by replacing any unset values
that have a default with that default. We're using this method
so that we can re-serialize a builder into a `ConfigurationTree`
with all of its default values included.
In all cases, `b.apply_defaults()?; b.build()` should produce
the same output as `b.build()`.
The interesting parts of this commit are in tor_config::load
and tor_config::derive. The rest of this commit just adds
`apply_defaults` to other builders that _aren't_ made with
`derive_deftly(TorConfig)`.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| | |
This currently does not actually export any metrics, but puts the
infrastructure in place to do so.
This adds the `experimental`, `__is_experimental`, etc features to
arti-relay. I presume we want to do that in the long term, but I'm not
100% sure on that.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Set socket buffer sizes (`SO_SNDBUF` and `SO_RCVBUF`) for proxy sockets
Closes #2500
See merge request tpo/core/arti!3957
|
| | | |
| | |
| | |
| | |
| | | |
For now this just sets up the structure. We'll add options for TCP
later.
|