summaryrefslogtreecommitdiff
path: root/crates/arti/src/socks.rs
Commit message (Collapse)AuthorAgeFilesLines
* rpc: Try using postage::watch to initialize ProxyInfo.Nick Mathewson2024-08-281-6/+6
| | | | | (This is a bit trickier than I would like, but it ensures that we never return a "not initialized yet" code.)
* RPC: Add experimental method to list SOCKS proxies.Nick Mathewson2024-08-281-1/+25
| | | | | | | We'll need this for our rpc-library code to meaningfully open SOCKS connections. Closes #1523.
* RPC: Use RPC methods instead of the "ClientConnectionTarget" trait.Nick Mathewson2024-06-111-30/+9
| | | | | | | | | | | | On its own, this might not seem like a huge improvement, but it will later let us implement these RPC methods for types that can't reasonably implement ClientConnectionTarget. It also serves as a proof of concept that special-method invocation can actually work, so that we can build things like this in cases where introducing a trait isn't practical. Closes #1427
* rpc: Make RpcMgr::lookup_object return context along with object.Nick Mathewson2024-06-101-0/+1
| | | | The context will make it possible to invoke rpc methods.
* RPC: Use a slightly less awful workaround in socks.rsNick Mathewson2024-05-141-20/+34
| | | | | | | | | | | | | | | | | The problem was that Rust won't let us say ``` type ConnTarget<R> = Arc<dyn ClientConnectionTarget>; ``` because the R parameter wasn't used. Previously we solved this by using a macro instead of a type definition, which is ugly. I had been thinking previously I would need to declare some kind of additional wrapper type, and had shrunk from the verbosity. But @diziet pointed out that I could just use a 2-tuple unconditionally. It's still not beautiful, but it is less hideous than before.
* Remove excess indentation from last commit.Nick Mathewson2024-05-141-14/+11
| | | | (This is a separate commit to make the branch more readable)
* RPC: Refactor socks interpretation to remove stream id, add isolation.Nick Mathewson2024-05-141-41/+41
|
* RPC: Add a trait that can be the target of SOCKS requestsNick Mathewson2024-05-121-18/+34
| | | | | | | | | | | | (These will later become objects that can receive any application request, once we have HTTP connect.) For now, Session and TorClient implement this trait; but soon there will be a new type to hold on to the created DataStreamCtrl. There are some XXXXs here, marking code that is too ugly to live. I should fix it before I merge this branch.
* handle_socks_conn: update parameter name in doc commentJim Newsome2023-10-251-1/+1
|
* Treat only EAFNOSUPPORT as a warningJani Monoses2023-09-261-4/+6
|
* Handle address already in useJani Monoses2023-09-221-2/+2
|
* arti, tor-config: Allow listening on generic addresses for SOCKS and DNS.Jani Monoses2023-09-221-15/+22
|
* Throughout: Use *_report!() macros for reporting Errors.Nick Mathewson2023-07-071-3/+4
| | | | | | | | | | | | | | | I identified the cases to replace by searching for the string `.report()`. There are a few that I didn't change: * A couple of cases that used anyhow::Error, * One case that reported two Errors. * Two cases in `tor_hsclient::err` that just did `error!("Bug: {}")`. I have also not audited the cases in `tor-hsclient` where we're using `tor_error::Report` manually. Nonetheless, closes #949.
* Remove onion service descriptor-related errorkinds.Nick Mathewson2023-06-221-4/+0
| | | | | | | | These have been subsumed by other errorkinds, mostly OnionServiceProtocolViolation and TorProtocolViolation. In particular please review the change in tor-hsclient closely; I am not sure about the new errorkinds for the error there.
* arti: Resolve TODO HS items related to extended SOCKS5 errorsNick Mathewson2023-06-221-6/+8
| | | | | | | | | This takes an approach discussed in #736: Instead of trying to distinguish INTRO/REND failures perfectly, we instead map our existing ErrorKinds as best we can, in respect to the fact that this distinction is not super important in practice. Closes #736
* New ErrorKind for invalid onion addressesNick Mathewson2023-06-221-0/+2
| | | | Use this to emit HS_BAD_ADDRESS as appropriate.
* Remove ErrorKind::OnionService{Intro,Rend}FailedNick Mathewson2023-06-221-6/+0
| | | | | These errors are orthogonal to our actual error kinds. See discussion on #736.
* Generate correct ErrorKinds for hsdesc decryption failures.Nick Mathewson2023-06-211-2/+2
| | | | Part of #736
* Add and use ErrorKinds for remaining onion service errorsNick Mathewson2023-06-211-6/+12
|
* arti: return prop304 extended socks5 reply codes for onion servicesNick Mathewson2023-06-211-0/+35
| | | | | | | We don't yet return all of them; this commit adds some todo notes about changes we may need to our ErrorKinds. Part of #736
* arti: Abbreviate SocksStatus and ErrorKind imports and refactor.Nick Mathewson2023-06-211-7/+8
|
* RPC: Suppress a warning to do with RPC and SOCKSIan Jackson2023-06-131-0/+1
| | | | Fixes `cargo check`
* arti: Interpret socks request to mean "lookup an RPC session"Nick Mathewson2023-06-051-13/+104
| | | | | | | | | The actual decoding here is just a placeholder. The important part is that we can get either a (SessionId, StreamId) tuple out of the request, or we treat it as part of an isolation token. This commit has a few TODOs for additional things that we'll need in order to build out our design.
* arti: Move SOCKS code for building StreamPrefs and getting a TorClient.Nick Mathewson2023-06-051-12/+25
|
* arti: Add an alias in the SOCKS code for per-conn isolatino info.Nick Mathewson2023-06-051-4/+10
| | | | This enables some small simplifications.
* RPC: tell the `arti` SOCKS code about an RpcMgr object.Nick Mathewson2023-06-051-3/+26
| | | | | It will use this to find which TorClient to use when opening a stream.
* Fix a local-only CPU DoS bug.Nick Mathewson2023-05-231-0/+10
| | | | | | | | | | | | | | | | | | Previously, there was a bug in the way that our code used our SOCKS implementations. If the buffer used for a SOCKS handshake became full without completing the handshake, then rather than expanding the buffer or closing the connection, our code would keep trying to read into the zero-byte slice available in the full buffer forever, in a tight loop. We're classifying this as a LOW-severity issue, since it is only exploitable by pluggable transports (which are trusted) and by local applications with access to the SOCKS port. Closes #861. Fixes TROVE-2023-001. Reported-By: Jakob Lell <jakob AT srlabs DOT de>
* Use ErrorReport/Report for errors in warn! in artiIan Jackson2023-01-301-3/+4
|
* resolve ip through socks by parsing themtrinity-1686a2023-01-031-15/+25
|
* Spelling fixes and normalizations on some high-level cratesNick Mathewson2022-11-071-1/+1
|
* socksproto: Rename SocksHandshake to SocksProxyHandshake.Nick Mathewson2022-09-271-1/+1
| | | | | | | | Retain "SocksHandshake" as a deprecated synonym. Also, make an (on-by-default) feature for SocksProxyHandshake. (There is about to be a SocksClientHandshake as well.)
* arti: Adjust severity on per-socks-request log.Nick Mathewson2022-08-251-4/+6
| | | | | Also, note why we aren't hiding the addrs that we're listening on here.
* arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-111-2/+4
| | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
* socksproto: Use fallible writers.Nick Mathewson2022-07-111-10/+20
| | | | Also, make private a function that had formerly been `pub`.
* reply socks error on more codepathtrinity-1686a2022-05-251-48/+67
|
* Apply `sensitive` in some info-level log messages.Nick Mathewson2022-05-061-2/+3
| | | | | This specifically applies the `sensitive` wrapper in the places where we're logging target addresses at level "info" or higher.
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-251-1/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* rename *_isolation_group to *_isolationtrinity-1686a2022-03-241-1/+1
|
* Alternative API for set_isolation_group().Nick Mathewson2022-03-171-1/+1
| | | | | | | | | | | | Instead of requiring a `Box<dyn Isolation>`, it now takes either a `Box<dyn Isolation>`, or an arbitrary `T` that implements `Isolation`. This API still allows the user to pass in a `Box<dyn Isolation>` if that's what they have, but it doesn't require them to Box the isolation on their own. Part of #414.
* add isolation to dns requeststrinity-1686a2022-03-161-3/+3
|
* accept boxed isolation in StreamPref::set_isolation_grouptrinity-1686a2022-03-161-1/+1
|
* replace IsolationMap with new Isolation traittrinity-1686a2022-03-161-102/+14
|
* add skeleton for DNS handlingtrinity-1686a2022-03-141-2/+2
|
* add udp to runtimetrinity-1686a2022-03-141-0/+537