summaryrefslogtreecommitdiff
path: root/crates/arti/src/socks.rs
Commit message (Collapse)AuthorAgeFilesLines
* socks users: copy the correct amount in our drain logic.Nick Mathewson2024-09-241-1/+1
| | | | | | | | When calling copy_within, we want to copy the amount of data that we're keeping; previously, we were copying an extra `action.drain` bytes, which could have led to a panic. Spotted by Opara.
* socks users: detect closed sockets.Nick Mathewson2024-09-241-1/+6
| | | | | | | | | Without this check, our socks code can enter an infinite loop if a socket is closed at the wrong time. Resolves TROVE-2024-011. Fixes #1635.
* Merge branch 'impl-prop-351' into 'main'Nick Mathewson2024-09-241-124/+106
|\ | | | | | | | | socks: Implement proposal 351. See merge request tpo/core/arti!2401
| * socks: Add a comment about interpreting legacy usernames.Nick Mathewson2024-09-241-0/+5
| |
| * socks: cleanups in interpret_socks_authNick Mathewson2024-09-181-12/+22
| | | | | | | | Introduce an enum, and use explicit `format_code @` syntax.
| * prop351: comment Suggestions from @diziet.Nick Mathewson2024-09-181-1/+4
| |
| * Socks: isolate streams from different extended-socks formatsNick Mathewson2024-09-181-3/+16
| | | | | | | | | | | | | | (These streams would already be isolated by accident, since streams with an RPC object are always on a client that's isolated from the main client. But, as discussed on torspec!280, it's best to do this sort of thing explicitly.)
| * socks: Optimistically revise format to match torspec!280Nick Mathewson2024-09-101-43/+53
| |
| * socks: update protocol documentationNick Mathewson2024-09-091-78/+9
| | | | | | | | | | | | | | The current best source here is prop351, and later will be socks-extensions.md. The examples are now correct.
| * socks: Implement proposal 351.Nick Mathewson2024-09-091-40/+50
| | | | | | | | | | | | | | | | See https://spec.torproject.org/proposals/351-socks-auth-extensions.html This proposal changes the interpretation of SOCKS5 usernames/passwords to give a more principled and extensible way of getting RPC IDs and isolation strings.
* | Merge branch 'pessimistic' into 'main'Nick Mathewson2024-09-241-0/+5
|\ \ | | | | | | | | | | | | arti SOCKS proxy: Tear down connections when client sends optimistic data See merge request tpo/core/arti!2443
| * | arti SOCKS proxy: Tear down connections when client sends optimistic dataIan Jackson2024-09-241-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We *do* want to support optimistic data, see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2436#note_3081886 However, right now, Arti risks mis-framing bugs if clients do send optimistic data, which would be quite serious. Mitigates #1627 / TROVE-2024-010 by replacing the misframing bug with connection failure. It doesn't seem so easy to write a test case for this.
* | | rtcompat: Rename TcpProvider to NetStreamProvider.Nick Mathewson2024-09-241-2/+2
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | (And similarly rename TcpListener to NetStreamListener, along with their TcpStream/TcpListener associated types.) These types are about to become generic over addresses, and therefore shouldn't be named after TCP. Renaming was done mostly with Rust Analyzer, except for some macros that needed to be hand-edited. (I'll revise the comments in the next commit; this one is all about renaming.)
* / Fix a typo in WRONG_PROTOCOL_PAYLOAD.Pier Angelo Vendrame2024-09-101-2/+3
|/
* socksproto: Add a const for suggested buffer length.Nick Mathewson2024-09-091-2/+2
| | | | | Ticket #1509 will probably get rid of this constant, but for now we may as well put it in one place.
* rpc: More specificity surrounding SOCKS-rpc integrationNick Mathewson2024-09-091-2/+25
|
* Suggestion about describing non-RPC behavior of SOCKS protocol from @diziet.Nick Mathewson2024-09-091-1/+3
|
* arti: Add a comment explaining how RPC and SOCKS interactNick Mathewson2024-09-091-0/+181
| | | | | | | | | This belongs in a spec, but adding things to a spec is slow and fraught. Instead we'll put it here for now and move it later. There are some XXXXs about "finalizing" the design that we need to resolve before we can merge !2373 and implement stream creation in `arti-rpc-client-core`.
* rpc: Try using postage::watch to initialize ProxyInfo.Nick Mathewson2024-08-281-6/+6
| | | | | (This is a bit trickier than I would like, but it ensures that we never return a "not initialized yet" code.)
* RPC: Add experimental method to list SOCKS proxies.Nick Mathewson2024-08-281-1/+25
| | | | | | | We'll need this for our rpc-library code to meaningfully open SOCKS connections. Closes #1523.
* RPC: Use RPC methods instead of the "ClientConnectionTarget" trait.Nick Mathewson2024-06-111-30/+9
| | | | | | | | | | | | On its own, this might not seem like a huge improvement, but it will later let us implement these RPC methods for types that can't reasonably implement ClientConnectionTarget. It also serves as a proof of concept that special-method invocation can actually work, so that we can build things like this in cases where introducing a trait isn't practical. Closes #1427
* rpc: Make RpcMgr::lookup_object return context along with object.Nick Mathewson2024-06-101-0/+1
| | | | The context will make it possible to invoke rpc methods.
* RPC: Use a slightly less awful workaround in socks.rsNick Mathewson2024-05-141-20/+34
| | | | | | | | | | | | | | | | | The problem was that Rust won't let us say ``` type ConnTarget<R> = Arc<dyn ClientConnectionTarget>; ``` because the R parameter wasn't used. Previously we solved this by using a macro instead of a type definition, which is ugly. I had been thinking previously I would need to declare some kind of additional wrapper type, and had shrunk from the verbosity. But @diziet pointed out that I could just use a 2-tuple unconditionally. It's still not beautiful, but it is less hideous than before.
* Remove excess indentation from last commit.Nick Mathewson2024-05-141-14/+11
| | | | (This is a separate commit to make the branch more readable)
* RPC: Refactor socks interpretation to remove stream id, add isolation.Nick Mathewson2024-05-141-41/+41
|
* RPC: Add a trait that can be the target of SOCKS requestsNick Mathewson2024-05-121-18/+34
| | | | | | | | | | | | (These will later become objects that can receive any application request, once we have HTTP connect.) For now, Session and TorClient implement this trait; but soon there will be a new type to hold on to the created DataStreamCtrl. There are some XXXXs here, marking code that is too ugly to live. I should fix it before I merge this branch.
* handle_socks_conn: update parameter name in doc commentJim Newsome2023-10-251-1/+1
|
* Treat only EAFNOSUPPORT as a warningJani Monoses2023-09-261-4/+6
|
* Handle address already in useJani Monoses2023-09-221-2/+2
|
* arti, tor-config: Allow listening on generic addresses for SOCKS and DNS.Jani Monoses2023-09-221-15/+22
|
* Throughout: Use *_report!() macros for reporting Errors.Nick Mathewson2023-07-071-3/+4
| | | | | | | | | | | | | | | I identified the cases to replace by searching for the string `.report()`. There are a few that I didn't change: * A couple of cases that used anyhow::Error, * One case that reported two Errors. * Two cases in `tor_hsclient::err` that just did `error!("Bug: {}")`. I have also not audited the cases in `tor-hsclient` where we're using `tor_error::Report` manually. Nonetheless, closes #949.
* Remove onion service descriptor-related errorkinds.Nick Mathewson2023-06-221-4/+0
| | | | | | | | These have been subsumed by other errorkinds, mostly OnionServiceProtocolViolation and TorProtocolViolation. In particular please review the change in tor-hsclient closely; I am not sure about the new errorkinds for the error there.
* arti: Resolve TODO HS items related to extended SOCKS5 errorsNick Mathewson2023-06-221-6/+8
| | | | | | | | | This takes an approach discussed in #736: Instead of trying to distinguish INTRO/REND failures perfectly, we instead map our existing ErrorKinds as best we can, in respect to the fact that this distinction is not super important in practice. Closes #736
* New ErrorKind for invalid onion addressesNick Mathewson2023-06-221-0/+2
| | | | Use this to emit HS_BAD_ADDRESS as appropriate.
* Remove ErrorKind::OnionService{Intro,Rend}FailedNick Mathewson2023-06-221-6/+0
| | | | | These errors are orthogonal to our actual error kinds. See discussion on #736.
* Generate correct ErrorKinds for hsdesc decryption failures.Nick Mathewson2023-06-211-2/+2
| | | | Part of #736
* Add and use ErrorKinds for remaining onion service errorsNick Mathewson2023-06-211-6/+12
|
* arti: return prop304 extended socks5 reply codes for onion servicesNick Mathewson2023-06-211-0/+35
| | | | | | | We don't yet return all of them; this commit adds some todo notes about changes we may need to our ErrorKinds. Part of #736
* arti: Abbreviate SocksStatus and ErrorKind imports and refactor.Nick Mathewson2023-06-211-7/+8
|
* RPC: Suppress a warning to do with RPC and SOCKSIan Jackson2023-06-131-0/+1
| | | | Fixes `cargo check`
* arti: Interpret socks request to mean "lookup an RPC session"Nick Mathewson2023-06-051-13/+104
| | | | | | | | | The actual decoding here is just a placeholder. The important part is that we can get either a (SessionId, StreamId) tuple out of the request, or we treat it as part of an isolation token. This commit has a few TODOs for additional things that we'll need in order to build out our design.
* arti: Move SOCKS code for building StreamPrefs and getting a TorClient.Nick Mathewson2023-06-051-12/+25
|
* arti: Add an alias in the SOCKS code for per-conn isolatino info.Nick Mathewson2023-06-051-4/+10
| | | | This enables some small simplifications.
* RPC: tell the `arti` SOCKS code about an RpcMgr object.Nick Mathewson2023-06-051-3/+26
| | | | | It will use this to find which TorClient to use when opening a stream.
* Fix a local-only CPU DoS bug.Nick Mathewson2023-05-231-0/+10
| | | | | | | | | | | | | | | | | | Previously, there was a bug in the way that our code used our SOCKS implementations. If the buffer used for a SOCKS handshake became full without completing the handshake, then rather than expanding the buffer or closing the connection, our code would keep trying to read into the zero-byte slice available in the full buffer forever, in a tight loop. We're classifying this as a LOW-severity issue, since it is only exploitable by pluggable transports (which are trusted) and by local applications with access to the SOCKS port. Closes #861. Fixes TROVE-2023-001. Reported-By: Jakob Lell <jakob AT srlabs DOT de>
* Use ErrorReport/Report for errors in warn! in artiIan Jackson2023-01-301-3/+4
|
* resolve ip through socks by parsing themtrinity-1686a2023-01-031-15/+25
|
* Spelling fixes and normalizations on some high-level cratesNick Mathewson2022-11-071-1/+1
|
* socksproto: Rename SocksHandshake to SocksProxyHandshake.Nick Mathewson2022-09-271-1/+1
| | | | | | | | Retain "SocksHandshake" as a deprecated synonym. Also, make an (on-by-default) feature for SocksProxyHandshake. (There is about to be a SocksClientHandshake as well.)
* arti: Adjust severity on per-socks-request log.Nick Mathewson2022-08-251-4/+6
| | | | | Also, note why we aren't hiding the addrs that we're listening on here.