| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |
|
| | |
|
| | |
|
| |
|
|
| |
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/717#note_2834307
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
| |
For example, see
https://tpo.pages.torproject.net/core/doc/rust/arti/fn.run.html :
this isn't labeled as `experimental-api`, but it should be.
These APIs were found by poking around in the `arti` crate.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This patch changes our `default_config()` test in `arti/src/cfg.rs` such
that we can define a number of known unrecognized options on different
platforms.
We mark the two keys "storage.permissions.trust_group" and
"storage.permissions.trust_user" as unknown on the Windows platform as
such features is not available using the ordinary Unix UID concept.
This patch also publicly exposes the `tor_config::load::DisfavouredKey`
and `tor_config::load::PathEntry` types and marks them as
non-exhaustive.
See: tpo/core/arti#450.
|
| | |
|
| | |
|
| | |
|
| | |
|
| |\
| |
| |
| |
| | |
Apply safelog to more of the things that we log
See merge request tpo/core/arti!693
|
| | |
| |
| |
| |
| | |
Also, note why we aren't hiding the addrs that we're listening on
here.
|
| | |
| |
| |
| |
| | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/602#note_2830847
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| | |
This commit largely follows the example for resolve_alternative_specs.
The difference is that there are two fields, so we use a macro to
avoid recapitulating the field names.
|
| | | |
|
| | |
| |
| |
| | |
This will allow us to handle new kinds of warnigns etc.
|
| |\ \
| | |
| | |
| | |
| | | |
arti: Raise the default console log severity to "info"
See merge request tpo/core/arti!692
|
| | |/
| |
| |
| |
| | |
Previously we logged at "debug", but that's not meant to
user-facing.
|
| | |
| |
| |
| |
| | |
FoundConfigFile existed to hide something that ConfigurationSource now
exposes.
|
| | |
| |
| |
| |
| |
| |
| |
| | |
The parameter to FileWatcher::new is not a polling time fallback; it
is a "debounce time". Events are always delayed by at least this
much.
10s is much too long for this. 1s is more appropriate.
|
| | |
| |
| |
| | |
Fixes #474 aka #271
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
We're going to need to do config file reading in two phases.
Right now this isn't actually necessary, because the set of files
is fixed since we don't support dynamically scanning directories.
But the new API will be needed in a moment.
Code motion and API changes, but no overall functional change.
Review with `git show -b` may be helpful.
The new API also provides for dealing with directories, but right now
that doesn't happen.
|
| | |
| |
| |
| |
| |
| | |
No call site just yet; that will come shortly.
This requires a bit of reorganisation first.
|
| | |
| |
| |
| | |
This is going to be needed in a moment.
|
| | |
| |
| |
| |
| |
| |
| | |
That way if the config changes after we read it initially, but before
we set up the watcher, we will still pick it up.
Fixes #544
|
| | |
| |
| |
| | |
This is going to become more complicated, and gain another call site.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The previous approach (inherited from the API of notify) was kind of
odd.
Soon we are going to want to be able to drop the watcher and replace
it. That really wants the same object to contain all the things that
ought to be dropped together. (notify's watchers stop generating
events and give EOF on the channel, when dropped.)
|
| |/
|
|
|
|
|
| |
These blocks were in the wrong order.
Previously, if you tried to turn on process hardening in the config
and then reloaded rather than restarting, it wouldn't take effect.
|
| | |
|
| | |
|
| | |
|
| |\
| |
| |
| |
| | |
arti: Do not allow running as root.
See merge request tpo/core/arti!688
|
| | |
| |
| |
| |
| |
| | |
This can be overridden with `application.allow_running_as_root`.
Part of #523.
|
| | |
| |
| |
| |
| | |
Mostly cribbed from
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/684#note_2829937
|
| | | |
|
| |/
|
|
| |
The defaults are now
|
| |
|
|
|
| |
Nothing actually reads this yet, and we also want a client-global
default for padding.
|
| |
|
|
|
| |
This commit is just the necessary plumbing. The config is currently
empty. We'll add something to it, for padding control, later.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
This is a compile-time feature with an associated configuration
flag, both enabled by default.
When it's turned on, hardening prevents the arti process from
dumping core or being attached to by low-privileged processes.
(This is a defense-in-depth measure, not an absolute way to prevent
attacks. For more information, see
[`secmem_proc`](https://docs.rs/secmem-proc/0.1.1/secmem_proc/).)
Closes #364.
|
| | |
|
| |
|
|
| |
Closes #522.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
The remaining unconditionally public APIs are those related to our
configuration objects, and the main_main() API.
The rationale for making main_main() public is to have an actual
entry point.
The rationale for making the config APIs public is:
1. We really do intend for others to be able to read our
configuration files using this API.
2. The structure of our configuration files is already part of our
interface.
Closes #530.
|
| |
|
|
|
|
|
| |
It remains on-by-default, so users shouldn't notice a difference,
but it may help when we want to save a few bytes of binary size.
Closes #532
|
| |
|
|
| |
Closes #503.
|