summaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-socksproto: Handle 0-byte reads (EOF) correctlyIan Jackson2024-10-011-1/+1
| | | | | | | | | | | | | | | | | | | | | This restores the functionality of socks users: detect closed sockets. 0c595818f713916d94b7b0e4062f953fad7c9799 which we reverted as part of rebasing this branch onto main.
| * | arti SOCKS proxy: Defer splitting the socks streamIan Jackson2024-10-011-13/+13
| | | | | | | | | | | | This is neater, I think.
| * | arti SOCKS proxy: Reject pipelined client dataIan Jackson2024-10-011-1/+1
| | | | | | | | | | | | Fixes #1627 / TROVE-2024-010
| * | arti SOCKS proxy: Use new tor-socksproto APIIan Jackson2024-10-011-40/+17
| | | | | | | | | | | | No functional change.
| * | tor-socksproto: Move `handshake` to be a trait methodIan Jackson2024-10-011-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This deduplicates some docs and eliminates the two wrapper functiosn for `run_handshake`, which is now just `handshake`. We're going to make other API breaks too, and this isn't going to be the primary API, so we might as well do this. Proper description of the semver breakage will come at the end when it's all done.
| * | Revert "socks users: detect closed sockets."Ian Jackson2024-10-011-6/+1
| | | | | | | | | | | | This reverts commit 0c595818f713916d94b7b0e4062f953fad7c9799.
| * | Revert "socks users: copy the correct amount in our drain logic."Ian Jackson2024-10-011-1/+1
| | | | | | | | | | | | This reverts commit dceeb82f7d1154894ab9c7c607d68f8335bb9615.
| * | Revert "arti SOCKS proxy: Tear down connections when client sends optimistic ↵Ian Jackson2024-10-011-5/+0
| |/ | | | | | | | | | | data" This reverts commit 87e0109832559dec41a485b268579d58be0de278.
* | Merge branch 'warn_on_nonlocal' into 'main'Nick Mathewson2024-10-013-2/+21
|\ \ | |/ |/| | | | | Warn on nonlocal addresses in configuration, PT results See merge request tpo/core/arti!2454
| * Mark resolve_listen_port as deprecated.Nick Mathewson2024-09-301-2/+9
| |
| * arti: Warn when listening on non-loopback addresses.Nick Mathewson2024-09-252-0/+8
| |
| * arti::cfg: Add a note to avoid new uses of a macro.Nick Mathewson2024-09-251-0/+4
| |
* | Merge branch 'silence-warning' into 'main'gabi-2502024-09-301-0/+1
|\ \ | | | | | | | | | | | | arti: Silence unused_mut warning. See merge request tpo/core/arti!2431
| * | arti: Silence unused_mut warning.Gabriela Moldovan2024-09-181-0/+1
| | | | | | | | | | | | The `config` is only mutated if `onion-service-service` is enabled.
* | | Merge branch 'reject_example' into 'main'Jim Newsome2024-09-262-0/+6
|\ \ \ | | | | | | | | | | | | | | | | arti: add an example for onion service "reject" option See merge request tpo/core/arti!2458
| * | | arti: add an example for onion service "reject" optionNick Mathewson2024-09-262-0/+6
| | | | | | | | | | | | | | | | There was previously no example here.
* | | | Merge branch 'arti-relay-bin' into 'main'David Goulet2024-09-263-9/+34
|\ \ \ \ | |/ / / |/| | | | | | | | | | | arti: move 'relay' subcommand to 'subcommands::relay' module See merge request tpo/core/arti!2455
| * | | arti: move 'relay' subcommand to 'subcommands::relay' moduleSteven Engler2024-09-253-9/+34
| | | |
* | | | Merge branch 'upgrades-20240925' into 'main'Nick Mathewson2024-09-261-5/+3
|\ \ \ \ | |_|_|/ |/| | | | | | | | | | | Upgrade dependencies in preparation for next week's releases. See merge request tpo/core/arti!2450
| * | | Upgrade to derive_more version 1.0.0Nick Mathewson2024-09-251-5/+3
| |/ / | | | | | | | | | | | | | | | The `derive_more` crate broke backward compatibility with this version, so this change involved quite a few manual fixups. With luck, they'll keep compatibility for some while in the future.
* | | socks users: copy the correct amount in our drain logic.Nick Mathewson2024-09-241-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | When calling copy_within, we want to copy the amount of data that we're keeping; previously, we were copying an extra `action.drain` bytes, which could have led to a panic. Spotted by Opara.
* | | socks users: detect closed sockets.Nick Mathewson2024-09-241-1/+6
|/ / | | | | | | | | | | | | | | | | Without this check, our socks code can enter an infinite loop if a socket is closed at the wrong time. Resolves TROVE-2024-011. Fixes #1635.
* | Merge branch 'impl-prop-351' into 'main'Nick Mathewson2024-09-241-124/+106
|\ \ | | | | | | | | | | | | socks: Implement proposal 351. See merge request tpo/core/arti!2401
| * | socks: Add a comment about interpreting legacy usernames.Nick Mathewson2024-09-241-0/+5
| | |
| * | socks: cleanups in interpret_socks_authNick Mathewson2024-09-181-12/+22
| | | | | | | | | | | | Introduce an enum, and use explicit `format_code @` syntax.
| * | prop351: comment Suggestions from @diziet.Nick Mathewson2024-09-181-1/+4
| | |
| * | Socks: isolate streams from different extended-socks formatsNick Mathewson2024-09-181-3/+16
| | | | | | | | | | | | | | | | | | | | | (These streams would already be isolated by accident, since streams with an RPC object are always on a client that's isolated from the main client. But, as discussed on torspec!280, it's best to do this sort of thing explicitly.)
| * | socks: Optimistically revise format to match torspec!280Nick Mathewson2024-09-101-43/+53
| | |
| * | socks: update protocol documentationNick Mathewson2024-09-091-78/+9
| | | | | | | | | | | | | | | | | | | | | The current best source here is prop351, and later will be socks-extensions.md. The examples are now correct.
| * | socks: Implement proposal 351.Nick Mathewson2024-09-091-40/+50
| | | | | | | | | | | | | | | | | | | | | | | | See https://spec.torproject.org/proposals/351-socks-auth-extensions.html This proposal changes the interpretation of SOCKS5 usernames/passwords to give a more principled and extensible way of getting RPC IDs and isolation strings.
* | | Merge branch 'pessimistic' into 'main'Nick Mathewson2024-09-241-0/+5
|\ \ \ | | | | | | | | | | | | | | | | arti SOCKS proxy: Tear down connections when client sends optimistic data See merge request tpo/core/arti!2443
| * | | arti SOCKS proxy: Tear down connections when client sends optimistic dataIan Jackson2024-09-241-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We *do* want to support optimistic data, see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2436#note_3081886 However, right now, Arti risks mis-framing bugs if clients do send optimistic data, which would be quite serious. Mitigates #1627 / TROVE-2024-010 by replacing the misframing bug with connection failure. It doesn't seem so easy to write a test case for this.
* | | | rpc: add mandatory delegate-type attribute to Object templateNick Mathewson2024-09-241-1/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | When specifying a delegation, the template user must also say what type they're delegating to. We're going to use this to document and expose delegations.
* | | | Merge branch 'abstract-socket-v2' into 'main'Nick Mathewson2024-09-241-2/+2
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | rtcompat: Second attempt at AF_UNIX support Closes #1152 See merge request tpo/core/arti!2437
| * | | | rtcompat: Rename TcpProvider to NetStreamProvider.Nick Mathewson2024-09-241-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (And similarly rename TcpListener to NetStreamListener, along with their TcpStream/TcpListener associated types.) These types are about to become generic over addresses, and therefore shouldn't be named after TCP. Renaming was done mostly with Rust Analyzer, except for some macros that needed to be hand-edited. (I'll revise the comments in the next commit; this one is all about renaming.)
* | | | | arti: Update example config with new keystore configuration.Gabriela Moldovan2024-09-231-10/+8
| | | | |
* | | | | tor-keymgr: Move keystore config under keystore.primary.Gabriela Moldovan2024-09-231-1/+2
|/ / / / | | | | | | | | | | | | | | | | The keystore settings only configure the *primary* keystore, so they should be under `keystore.primary`.
* | | | tor-keymgr: Rename the primary keystore for clarity.Gabriela Moldovan2024-09-231-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, arti's primary keystore was referred to as its "default" keystore. However, "default" is inaccurate here: there is no way to meaningfully override this "default" (the "default" store acts as the main keystore). Throughout the codebase, we query all keystores for keys (including the secondary ones), but only ever write to the default/primary keystore. This is OK for now, because it enables us to have one mutable keystore, and multiple secondary, read-only stores.
* | | | tor-keymgr: added support for specifying keystore kind to ArtiKeystoreConfigMorgan2024-09-201-1/+19
|/ / /
* | | arti: Tolerate lowercase "no" in confirmation prompt.Gabriela Moldovan2024-09-191-3/+7
| | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2435#note_3080452
* | | arti: Fix typo in display_service_discovery_key function name.Gabriela Moldovan2024-09-191-3/+3
| | |
* | | arti: Gate the arti hsc subcommand behind a new "hsc" feature (fmt).Gabriela Moldovan2024-09-191-4/+1
| | |
* | | arti: Gate the arti hsc subcommand behind a new "hsc" feature.Gabriela Moldovan2024-09-192-12/+4
| | | | | | | | | | | | This new feature is experimental.
* | | arti: Add a subcommand for removing a client discovery key.Gabriela Moldovan2024-09-191-0/+35
| | | | | | | | | | | | Closes #1475
* | | arti: Add an hsc subcommand for rotating client keys.Gabriela Moldovan2024-09-191-0/+65
| | | | | | | | | | | | Part of #1475
* | | arti: Move public key output logic to a separate function.Gabriela Moldovan2024-09-191-4/+13
| | | | | | | | | | | | | | | This will be reused for `arti hsc key rotate`, which also outputs the public key.
* | | arti: Satisfy clippy.Gabriela Moldovan2024-09-181-4/+4
| | |
* | | arti: Add hsc key subcommand, deprecate hsc get-key.Gabriela Moldovan2024-09-181-3/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I am deprecating the old `hsc get-key` subcommand in favor of the new `hsc key get` subcommand. This is because I plan to implement the rest of the key management functionality (key deletion, rotation, etc.) as subcommands of the `hsc key` command. The alternative would be to add a new distinct top-level `hsc rotate-key`, `hsc remove-key`, etc. subcommand alongside the existing `hsc get-key` command (which IMO is less nice than the alternative I'm proposing).
* | | arti: Move the keygen-related args to a separate struct.Gabriela Moldovan2024-09-181-9/+17
| | | | | | | | | | | | These will be reused by a future `key rotate` subcommand.
* | | arti: Make sure we check the KeyType before running the command.Gabriela Moldovan2024-09-181-1/+5
| | | | | | | | | | | | | | | Otherwise, if/when we add support for other `KeyType`s we risk forgetting to update the rest of the implementation.