summaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'keymgr-config' into 'main'gabi-2502023-06-291-0/+22
|\ | | | | | | | | arti-client: Add keystore_dir to StorageConfig. See merge request tpo/core/arti!1312
| * arti cfg tests: Add declare_exceptions for storage.keystore_dir.Gabriela Moldovan2023-06-291-1/+22
| | | | | | | | | | This moves `storage.keystore_dir` to a separate `declare_exceptions` block and explains why we have this exception.
| * example-config: Temporarily remove keystore_dir example.Gabriela Moldovan2023-06-292-17/+1
| | | | | | | | | | | | Let's remove this until we figure out how the config should behave when the `keymgr` feature is disabled (should it accept or reject `keystore_dir = true`?)
| * arti-client: Add keystore_dir to StorageConfig.Gabriela Moldovan2023-06-292-0/+17
| |
* | Turn off HS client connections by defaultIan Jackson2023-06-291-1/+10
|/ | | | As per IRC discussion, re lack of Vanguards.
* arti cfg tests: Suppress an undesriable clippy lintIan Jackson2023-06-281-0/+1
|
* arti cfg tests: declare_exceptions: Annotate the types for clarity (fmt)Ian Jackson2023-06-281-6/+4
|
* arti cfg tests: declare_exceptions: Annotate the types for clarityIan Jackson2023-06-281-1/+6
|
* arti cfg tests: Point the reader to the types used in declarationsIan Jackson2023-06-281-0/+12
|
* arti cfg tests: Move InCode into declare_config_exampleIan Jackson2023-06-281-19/+19
| | | | It's used for declarations only, and they should all be here.
* arti cfg tests: Make declare_exception take distinguished old/new typesIan Jackson2023-06-281-15/+27
| | | | | | As per discussion in https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1320#note_2916689 and IRC followup.
* HS configuration: Add retry parameters to configurationIan Jackson2023-06-282-0/+8
| | | | | | | I think these should go in `[circuit_timing]`. That section already has some retry parameters, so is not strictly *timing*. This is not honoured yet.
* HS configuration: Add and honour `allow_onion_addrs` in configurationIan Jackson2023-06-282-0/+14
| | | | | | | We put this in `[address_filter]`. The interaction with the corresponding stream preference is a bit complicated. We must turn the stream pref into a `BoolOrAuto`.
* art cfg tests: Fix garbled doc wordinggabi-2502023-06-281-2/+2
|
* arti cfg tests: Fix doc commentgabi-2502023-06-281-1/+1
|
* arti cfg tests: Overhaul exception handling (fmt)Ian Jackson2023-06-281-36/+32
|
* arti cfg tests: Overhaul exception handlingIan Jackson2023-06-281-92/+324
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was super confusing and fragile. Amongst the problems: * Information about exceptional config keys was spread across a number of places, manipulated in ad-hoc ways (conditional Vec appends, etc). * As a consequence, each exceptional table has confusing and unclear semantics. * It doesn't deal well with the way that cargo sometimes enables features for dependency crates even if arti itself wouldn't demand them; this can lead to sub-crates supporting config keys when the tests in arti don't expect them to, causing spurious test failures. Fix this: * Introduce a new, systematic, way of writing information about configuration keys that need some kind of special handling. * Use this new approach in *both* sets of "thorough" config tests. * Be more relaxed about deprecated keys. We don't want to tightly couple this to absence in the supported file, I think. * Understand more clearly the concept of keys of which we don't know, in the current build config, whether the code is expected to accept them. I have tested this locally with: for p in '-p arti' '--workspace'; do for f in '--no-default-features --features=tokio,native-tls' '--all-features' ''; do nailing-cargo test $p $f; done; done
* arti cfg tests: Remove a comment relating to work already doneIan Jackson2023-06-281-4/+0
| | | | | | We *do* have a thing that works like this. It's fragile and confusing and that's what I'm about to fix.
* arti cfg tests: Code motionIan Jackson2023-06-281-206/+214
| | | | | Bring the exciting tests together, and move some more normal tests out of the middle.
* Mark a builder as non-exhaustiveIan Jackson2023-06-281-0/+1
| | | | | | | If all the fields vanish, this generates a warning with cargo clippy --locked --offline --workspace --all-targets Fix that.
* Corrected the order of imports in order to make the 'rust-checks' job ↵Andy2023-06-231-1/+1
| | | | complete successfully.
* Provided a fix for #831 - 'Unused import' warnings on WindowsAndy2023-06-232-6/+8
|
* Remove onion service descriptor-related errorkinds.Nick Mathewson2023-06-221-4/+0
| | | | | | | | These have been subsumed by other errorkinds, mostly OnionServiceProtocolViolation and TorProtocolViolation. In particular please review the change in tor-hsclient closely; I am not sure about the new errorkinds for the error there.
* Merge branch 'socks_errorkinds' into 'main'Nick Mathewson2023-06-221-12/+10
|\ | | | | | | | | | | | | Generate correct-ish socks5 errors for onion service errors. Closes #736 See merge request tpo/core/arti!1279
| * arti: Resolve TODO HS items related to extended SOCKS5 errorsNick Mathewson2023-06-221-6/+8
| | | | | | | | | | | | | | | | | | This takes an approach discussed in #736: Instead of trying to distinguish INTRO/REND failures perfectly, we instead map our existing ErrorKinds as best we can, in respect to the fact that this distinction is not super important in practice. Closes #736
| * New ErrorKind for invalid onion addressesNick Mathewson2023-06-221-0/+2
| | | | | | | | Use this to emit HS_BAD_ADDRESS as appropriate.
| * Remove ErrorKind::OnionService{Intro,Rend}FailedNick Mathewson2023-06-221-6/+0
| | | | | | | | | | These errors are orthogonal to our actual error kinds. See discussion on #736.
| * Generate correct ErrorKinds for hsdesc decryption failures.Nick Mathewson2023-06-211-2/+2
| | | | | | | | Part of #736
* | Merge branch 'stderr' into 'main'Alexander Færøy2023-06-212-0/+4
|\ \ | |/ |/| | | | | lints: Promote clippy::print_stderr and clippy::print_stdout See merge request tpo/core/arti!1271
| * lints: Run maint/add_warning to actually apply new lintsIan Jackson2023-06-212-0/+4
| |
* | Add and use ErrorKinds for remaining onion service errorsNick Mathewson2023-06-211-6/+12
| |
* | arti: return prop304 extended socks5 reply codes for onion servicesNick Mathewson2023-06-211-0/+35
| | | | | | | | | | | | | | We don't yet return all of them; this commit adds some todo notes about changes we may need to our ErrorKinds. Part of #736
* | arti: Abbreviate SocksStatus and ErrorKind imports and refactor.Nick Mathewson2023-06-211-7/+8
|/
* rpc: Give the session-creation function an argument.Nick Mathewson2023-06-151-1/+1
| | | | | | This will later let us tell the session-creation function how the authentication occurred, which will let it decide what privileges to provide.
* rpc: revise session initialization a lot.Nick Mathewson2023-06-151-7/+8
| | | | | | | | | | | | | | Formerly, every time we wanted to launch a new connection, we had to give the RpcMgr a TorClient. The connection would hold that TorClient until a session was authenticated, and then would wrap it in a Session and put it in the object map. Now, the RpcMgr holds a Box<dyn Fn()...> that knows how to create Sessions. When a connection is authenticated, it asks the Mgr to make it a new session. This lets us make it clearer that the TorClient simply can't be given out until the connection is authenticated. Later, it will let us create more types of Session objects under more complicated rules.
* RPC: rename new_session to new_connectionNick Mathewson2023-06-151-1/+1
|
* rpc: revise the relationship between Mgr and ConnectionNick Mathewson2023-06-141-1/+1
| | | | | | | | This adds a Weak reference from Connection to Mgr, makes DispatchTable mutable, and makes a few other changes as discussed between me and Diziet the other week. I bet we are not done tweaking this, but I hope it's a setp forwards.
* RPC: Suppress a warning to do with RPC and SOCKSIan Jackson2023-06-131-0/+1
| | | | Fixes `cargo check`
* arti: Interpret socks request to mean "lookup an RPC session"Nick Mathewson2023-06-051-13/+104
| | | | | | | | | The actual decoding here is just a placeholder. The important part is that we can get either a (SessionId, StreamId) tuple out of the request, or we treat it as part of an isolation token. This commit has a few TODOs for additional things that we'll need in order to build out our design.
* arti: Move SOCKS code for building StreamPrefs and getting a TorClient.Nick Mathewson2023-06-051-12/+25
|
* arti: Add an alias in the SOCKS code for per-conn isolatino info.Nick Mathewson2023-06-051-4/+10
| | | | This enables some small simplifications.
* RPC: tell the `arti` SOCKS code about an RpcMgr object.Nick Mathewson2023-06-053-23/+78
| | | | | It will use this to find which TorClient to use when opening a stream.
* rpc: Move Arc::new() to RpcMgr code.Nick Mathewson2023-06-051-2/+2
|
* Fix a local-only CPU DoS bug.Nick Mathewson2023-05-231-0/+10
| | | | | | | | | | | | | | | | | | Previously, there was a bug in the way that our code used our SOCKS implementations. If the buffer used for a SOCKS handshake became full without completing the handshake, then rather than expanding the buffer or closing the connection, our code would keep trying to read into the zero-byte slice available in the full buffer forever, in a tight loop. We're classifying this as a LOW-severity issue, since it is only exploitable by pluggable transports (which are trusted) and by local applications with access to the SOCKS port. Closes #861. Fixes TROVE-2023-001. Reported-By: Jakob Lell <jakob AT srlabs DOT de>
* print both static sqlite/tls when 'static' feature is usedtrinity-1686a2023-05-081-2/+2
|
* RPC: Start on plumbing TorClient into our RPC codeNick Mathewson2023-05-042-4/+9
| | | | | Because of #837, we won't be able to work with _every_ TorClient<R>, so I'm only going to be using TorClient<PreferredRuntime> for now.
* RPC: Move the "listen" part of the RPC listener code to `arti`.Nick Mathewson2023-05-043-21/+129
| | | | | | | | | Now there's a module in `arti` that runs the loop for an RPC listener. The part of the old `listener` module that made the framed connections is now part of the `Session` object. There is now yet another a temporary location for the pipe; we should pick something better. At least now it's configurable.
* rpc: Make an RpcMgr type to own the DispatchTable.Nick Mathewson2023-05-041-1/+3
| | | | | | | | | In the future, this will probably hold more data as well, like a TorClient and some configuration info. The TorClient will present an issue; I've made comments about that. Closes #820
* Update our secmem_proc dependency to 0.3.0Nick Mathewson2023-04-131-1/+1
| | | | | | (This wasn't possible before we updated our MSRV to 1.65.) Closes #664.
* rpc: Add a demonstration feature to "arti"Nick Mathewson2023-04-121-0/+28
| | | | | | | | It's experimental, and tokio-only. To enable it, build with the "rpc" feature turned on, and connect to `~/.arti-rpc-TESTING/PIPE`. (`nc -U` worked for me) I'll add some instructions.