summaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
...
| * | arti: Raise the default console log severity to "info"Nick Mathewson2022-08-253-3/+3
| |/ | | | | | | | | Previously we logged at "debug", but that's not meant to user-facing.
* | tor-config source: just ConfigurationSource, not FoundConfigFileIan Jackson2022-08-251-8/+7
| | | | | | | | | | FoundConfigFile existed to hide something that ConfigurationSource now exposes.
* | config watch: Fix and reduce debounce intervalIan Jackson2022-08-251-3/+3
| | | | | | | | | | | | | | | | The parameter to FileWatcher::new is not a polling time fallback; it is a "debounce time". Events are always delayed by at least this much. 10s is much too long for this. 1s is more appropriate.
* | config sources: Read arti.d as well as arti.tomlIan Jackson2022-08-251-3/+3
| | | | | | | | Fixes #474 aka #271
* | config sources: Supporting reading directoriesIan Jackson2022-08-251-3/+5
| |
* | config sources: Introduce scan() and FoundConfigFilesIan Jackson2022-08-251-11/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | We're going to need to do config file reading in two phases. Right now this isn't actually necessary, because the set of files is fixed since we don't support dynamically scanning directories. But the new API will be needed in a moment. Code motion and API changes, but no overall functional change. Review with `git show -b` may be helpful. The new API also provides for dealing with directories, but right now that doesn't happen.
* | config watch: Provide watch_dirIan Jackson2022-08-251-8/+37
| | | | | | | | | | | | No call site just yet; that will come shortly. This requires a bit of reorganisation first.
* | config watch: Re-establish watcher on each iterationIan Jackson2022-08-251-2/+14
| | | | | | | | This is going to be needed in a moment.
* | config watch: Rescan once on startupIan Jackson2022-08-251-3/+8
| | | | | | | | | | | | | | That way if the config changes after we read it initially, but before we set up the watcher, we will still pick it up. Fixes #544
* | config watch: Break out prepare_watcherIan Jackson2022-08-251-5/+10
| | | | | | | | This is going to become more complicated, and gain another call site.
* | config watch: Make the mpsc channel part of FileWatcherIan Jackson2022-08-251-8/+15
| | | | | | | | | | | | | | | | | | | | The previous approach (inherited from the API of notify) was kind of odd. Soon we are going to want to be able to drop the watcher and replace it. That really wants the same object to contain all the things that ought to be dropped together. (notify's watchers stop generating events and give EOF on the channel, when dropped.)
* | config: Do process hardening on reconfigure even if not watchingIan Jackson2022-08-251-4/+4
|/ | | | | | | These blocks were in the wrong order. Previously, if you tried to turn on process hardening in the config and then reloaded rather than restarting, it wouldn't take effect.
* fix nightly lintstrinity-1686a2022-08-241-0/+1
|
* fix test failing due to missing allow_running_as_roottrinity-1686a2022-08-241-1/+1
|
* enable doc_auto_cfg feature on every crate when documenting for docs.rstrinity-1686a2022-08-241-0/+1
|
* Merge branch 'no_root' into 'main'Nick Mathewson2022-08-244-0/+42
|\ | | | | | | | | arti: Do not allow running as root. See merge request tpo/core/arti!688
| * arti: Do not allow running as root.Nick Mathewson2022-08-244-0/+42
| | | | | | | | | | | | This can be overridden with `application.allow_running_as_root`. Part of #523.
* | arti cfg: Write down future plansIan Jackson2022-08-231-0/+13
| | | | | | | | | | Mostly cribbed from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/684#note_2829937
* | arti cfg: Test parsing of the oldest config file we still supportIan Jackson2022-08-222-8/+310
| |
* | arti cfg: Fix docs about ARTI_EXAMPLE_CONFIGIan Jackson2022-08-221-1/+4
|/ | | | The defaults are now
* channel: Introduce padding configIan Jackson2022-08-161-1/+13
| | | | | Nothing actually reads this yet, and we also want a client-global default for padding.
* Introduce ChannelConfigIan Jackson2022-08-161-0/+4
| | | | | This commit is just the necessary plumbing. The config is currently empty. We'll add something to it, for padding control, later.
* arti: Add support for process hardeningNick Mathewson2022-08-155-1/+71
| | | | | | | | | | | | | This is a compile-time feature with an associated configuration flag, both enabled by default. When it's turned on, hardening prevents the arti process from dumping core or being attached to by low-privileged processes. (This is a defense-in-depth measure, not an absolute way to prevent attacks. For more information, see [`secmem_proc`](https://docs.rs/secmem-proc/0.1.1/secmem_proc/).) Closes #364.
* Add a few dire warnings about main; make main_main experimental.Nick Mathewson2022-08-111-2/+31
|
* Document more explicitly what "voiding a semver warranty" entailsNick Mathewson2022-08-111-1/+5
| | | | Closes #522.
* arti: `main_main` takes command-line arguments does not call exit()Nick Mathewson2022-08-111-3/+18
|
* arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-117-11/+37
| | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
* arti: Add a feature flag for dns-proxy.Nick Mathewson2022-08-111-0/+10
| | | | | | | It remains on-by-default, so users shouldn't notice a difference, but it may help when we want to save a few bytes of binary size. Closes #532
* Rename download_tolerance to directory_toleranceNick Mathewson2022-07-221-2/+5
| | | | Closes #503.
* disable-fs-permission-checks: remove variable from help messageJim Newsome2022-07-191-1/+0
| | | | | This option doesn't take an argument. This change drops the argument from the `--help` message.
* Merge branch 'mistrust-envvar' into 'main'Nick Mathewson2022-07-191-26/+17
|\ | | | | | | | | | | | | Move environment-variable checking into fs-mistrust Closes #483 See merge request tpo/core/arti!630
| * Arti: Use synthetic argument to implement --disable-fs-permission-checksNick Mathewson2022-07-191-22/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | Now that configuring the environment variables related to fs permissions works properly, we don't need to use the "override" feature any more: we can just add the option to the configuration when appropriate. With this design, `--disable-fs-permission-checks` is now mostly an alias for `--option storage.permissions.dangerously_trust_everyone=true` Enabled by #483.
| * Move responsibility for disable-fs-mistrust envvar.Nick Mathewson2022-07-191-4/+6
| | | | | | | | | | | | | | The variable is now handled when building the configuration, and no longer needs to be special-cased. Closes #483.
* | socksproto: Use fallible writers.Nick Mathewson2022-07-111-10/+20
|/ | | | Also, make private a function that had formerly been `pub`.
* Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-232-0/+6
| | | | Update all lint blocks
* Updated the warning message providing additional information about the type ↵0x4ndy2022-06-211-2/+1
| | | | of the proxy port.
* Merge branch 'reachable_addrs_v2' into 'main'Nick Mathewson2022-06-171-0/+10
|\ | | | | | | | | | | | | Implement support for reachable_addrs Closes #491 and #93 See merge request tpo/core/arti!583
| * Add a configuration option for reachable_addrsNick Mathewson2022-06-171-0/+10
| | | | | | | | (This doesn't do anything yet.)
* | Merge branch 'config-fix2' into 'main'Nick Mathewson2022-06-161-14/+6
|\ \ | | | | | | | | | | | | Use impl_standard_builder more and remove manual Default/builder impls See merge request tpo/core/arti!594
| * | impl_standard_builder: Use for arti::logging::LogfileConfigIan Jackson2022-06-161-7/+2
| | |
| * | arti: logging config: Replace a manual Debug implIan Jackson2022-06-161-7/+4
| | |
* | | Merge branch 'config-fix' into 'main'Ian Jackson2022-06-162-46/+89
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Config handling and logging fixes Closes #480 See merge request tpo/core/arti!589
| * | | arti: cfg: Remove another needless borrowIan Jackson2022-06-161-1/+1
| | | |
| * | | arti cfg tests: Remove a redundant line that shadows an earlier bindingIan Jackson2022-06-161-1/+0
| | | | | | | | | | | | | | | | | | | | Prompted by review https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/589#note_2813596
| * | | Fix grammar erroreta2022-06-161-1/+1
| | | |
| * | | arti: Enable some pre-config loggingIan Jackson2022-06-161-2/+16
| | | |
| * | | arti: Introduce closure which will be used for pre-config loggingIan Jackson2022-06-161-31/+52
| | | | | | | | | | | | | | | | Right now this is an IEFI and therefore a no-op.
| * | | arti cfg tests: Test that example config works as-isIan Jackson2022-06-161-0/+2
| | | | | | | | | | | | | | | | It contains only sections, but we want to detect when that is a problem!
| * | | arti: cfg tests: Refactor to prepare for new testIan Jackson2022-06-161-16/+23
| |/ / | | | | | | | | | We're going to call this new closure another time.
* | | Merge branch 'main' into 'accel-features'Nick Mathewson2022-06-162-2/+6
|\ \ \ | | |/ | |/| | | | # Conflicts: # crates/arti-client/Cargo.toml