| Commit message (Collapse) | Author | Age | Files | Lines |
| | |
|
| |
|
|
|
|
| |
This simplifies our implementation logic in a few places,
and simplifies our invocation syntax greatly. There are a few
infelicities, noted in `TODO RPC` comments.
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
If vanguards are enabled, we will need to be able to reconfigure the HS
circ pool in `TorClient::reconfigure_inner` (to handle the switch from
vanguards-full to vanguards-lite etc.). The reconfiguration needs to
happen even if only one of `onion-service-client` and
`onion-service-service` is enabled.
Without this change, in the `onion-service-client`-enabled /
`onion-service-service`-disabled case, we'd need to reach into
`HsClientConnector::hs_circ_pool` to reconfigure the client
`HsCircPool`. By making `hs_circ_pool` part of `TorClient` in both
cases, we only need to call `HsCircPool::reconfigure` from one place (in
`TorClient::reconfigure_inner`).
|
| | |
|
| |
|
|
| |
Closes #1277
|
| | |
|
| |
|
|
| |
Closes #1283
|
| |
|
|
| |
Closes #1202
|
| |
|
|
|
|
| |
Reviewing uses of `#[educe(default)]`, I came across these two places
where it was applied to a non-generic struct without any special
attributes on fields. std's derive will do just as well here.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
Since Rust 1.66, std's default works properly for enums, provided that
the default variant is a unit.
Review all uses of `#[educe(default)]` on enums and replace them with
std where possible, which is most of them.
In 1.66 and later, std's `#[derive(Default)]` doesn't infer any
generic bounds on the derived impl, where it's an enum - since the
unit variant can always be constructed. So this change doesn't add
any generic bounds and is not API-visible.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
We no longer do replay log locking in IptManager::new. Instead, we
rely on the acquire_instance call in OnionService::launch, which ends
up with ipt_mgr getting an InstanceHandle (which contains a lock
guard).
OnionServiceStateMgr is abolished; it existed to deal with the
generics in the tor_persist::StateMgr API. state_dir has no
generics (other than the T being loaded/stored).
Many places (structs and argument lists) now have state_dir types
which embody a path (or a CheckeDir) along with a lock, rather than
separate path+lock+mistrust.
The creation/startup code uses the new calls from state_dir.
Other more minor changes:
- StartupError::StateDirectoryInaccessible contains tor_persist::Error
- test::create_storage_handles_from_state_dir changed and renamed,
from _from_state_mgr.
- replay::PersistFile's (separate) file lock is now fslock_guard's
|
| | |
|
| |
|
|
|
| |
Service nicknames are represented by `HsNickname`, so let's
rename `HsClientSpecifier` to `HsClientNickname`.
|
| |
|
|
|
|
| |
This introduces an internal `OnionServiceStateMgr` trait, which enables
us to store the `StateMgr` inside the `OnionServiceState` (without
having to parameterize `OnionServiceState` on `S: StateMgr`).
|
| |
|
|
| |
This reduces code duplication.
|
| |
|
|
|
| |
This code was duplicated by `create_inner()` and
`create_onion_service()`.
|
| |
|
|
|
|
|
| |
The `StateMgr` is currently only needed in `launch()`, so we don't
really need to store it.
This allows us to unparameterize OnionService.
|
| |
|
|
|
| |
This will be used from `arti` to create an `OnionService`, to implement
the `arti hss` command.
|
| |
|
|
|
|
|
|
| |
This will enable us to construct non-launched (but configured)
`OnionService`s. We need this, for example, for implementing
the `arti hss` CLI command.
Part of #1227
|
| | |
|
| |
|
|
|
| |
This addresses a `TODO HSS` about not using `internal!` for an error
caused by misconfiguration.
|
| | |
|
| | |
|
| |\
| |
| |
| |
| | |
tor-keymgr: Abolish ArtiNativeKeystoreConfig::expand_keystore_dir.
See merge request tpo/core/arti!1867
|
| | |
| |
| |
| |
| |
| | |
This resolves a `TODO HSS` in arti-client.
Part of #1187
|
| | | |
|
| |/
|
|
|
|
|
|
| |
This addresses a `TODO HSS` about deriving the `KeySpecifier`
implementation for client key specifiers.
Note that we no longer have a key specifier type for intro auth keys
(which are not supported anyway, see #1037).
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
This is needed for the replay logs.
It's a shame that CheckedDir is (i) a bit unergonomic (ii) has an
extra bool in it, or we could pass one of those instead of these two
arguments.
Since HS's might be created after startup, TorClient must have these
fields.
|
| | |
|
| |
|
|
|
| |
Call expand_state_dir only once. We'll reuse this value, another
time, too.
|
| |
|
|
| |
We don't use this now that we have a `KeyMgrBuilder`.
|
| |
|
|
| |
Closes #1037
|
| |
|
|
|
|
|
|
|
| |
While looking for differences, we found that C tor always
omits the flags and the hostname from a BEGIN message sent on an
onion service circuit. In torspec!179, we specified that behavior.
This patch brings arti into conformance.
Closes #1077.
|
| |
|
|
| |
Closes #1078.
|
| | |
|
| |
|
|
| |
Return a stream of requests, and document what to do with them.
|
| | |
|
| | |
|
| |
|
|
|
| |
This doesn't need to be an async_trait now that `Publisher::launch` is
no longer async.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
StaticSecret.
Previously, when retrieving `KS_hsc_desc_enc` keys (or any other x25519
keys) from the keystore, the keymgr would discard the public part of the
key (SSH private keys contain the public part of the key too). Instead
of discarding the public key and returning just the `StaticSecret`, the
keymgr now returns a `StaticKeypair`. This makes the x25519
`EncodableKey`/`ToEncodableKey` implementation consistent with the
ed25519 one (which retrieves key pairs rather than "unescorted"
secrets).
|