summaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
...
* | Fix typosDimitris Apostolou2024-09-032-2/+2
|/
* arti: Implement the hsc subcommand using an inert tor client.Gabriela Moldovan2024-08-281-1/+1
| | | | | | | | | This allows us to reenable the `arti hsc` tests, which were previously disabled due to flakiness (see #1496). The `help` test bit rotted a bit, so I had to tweak its expected output. Closes #1496
* Merge branch 'expose-proxy-setting' into 'main'Nick Mathewson2024-08-285-11/+298
|\ | | | | | | | | | | | | RPC: Add experimental method to list SOCKS proxy addresses. Closes #1523 See merge request tpo/core/arti!2359
| * rpc: Use MockRuntime for set_proxy_info test.Nick Mathewson2024-08-281-2/+2
| |
| * rpc: Add a test for setting proxy info.Nick Mathewson2024-08-282-0/+43
| |
| * rpc: Rename E::SenderDroppedNick Mathewson2024-08-281-5/+6
| |
| * rpc: Try another incantation for watching for ProxyInfo.Nick Mathewson2024-08-281-13/+7
| |
| * rpc: Add another layer of indirection on proxyinfoNick Mathewson2024-08-282-3/+12
| |
| * rpc: Try using postage::watch to initialize ProxyInfo.Nick Mathewson2024-08-285-35/+80
| | | | | | | | | | (This is a bit trickier than I would like, but it ensures that we never return a "not initialized yet" code.)
| * RPC: Add experimental method to list SOCKS proxies.Nick Mathewson2024-08-285-16/+135
| | | | | | | | | | | | | | We'll need this for our rpc-library code to meaningfully open SOCKS connections. Closes #1523.
| * arti: Define a new ArtiRpcSession type.Nick Mathewson2024-08-283-3/+79
| | | | | | | | | | | | | | This type exists in the `arti` crate. It wraps and delegates to `arti_rpcserver::RpcSession`. Subsequent commits will use it to expose information from the `arti` crate to the RPC system; right now it does nothing.
* | tor-config: Rename watch_file to watch_path.Gabriela Moldovan2024-08-271-1/+1
|/ | | | `FileWatcher::watch_file` can be used with arbitrary paths.
* Merge branch 'ci' into 'main'Ian Jackson2024-08-271-1/+2
|\ | | | | | | | | Run tests of every crate, with all features disabled See merge request tpo/core/arti!2350
| * arti: Fix an unused Result in tests if pts disabledIan Jackson2024-08-191-1/+2
| | | | | | | | | | Fixes compilation with cargo test --no-default-features -p arti --features=tokio,rustls
* | arti: Temporarily disable a flaky test.Gabriela Moldovan2024-08-221-0/+1
| | | | | | | | Disabling until #1549 is fixed to unblock CI.
* | arti: Use a postage::watch channel in the tests.Gabriela Moldovan2024-08-221-15/+22
| | | | | | | | | | | | | | | | The watch channel should help prevent flakiness in the tests (`TestModule` uses `maybe_send` to only send the received config if it's different from the previously received value. This is supposed to prevent the tests from failing when duplicate update events are received).
* | arti: Add test for config reloading.Gabriela Moldovan2024-08-211-0/+174
| |
* | arti: Wrap long lines not handled by rustfmt.Gabriela Moldovan2024-08-211-2/+14
| |
* | tor-hsservice: Pass watch_configuration down to restricted discovery config.Gabriela Moldovan2024-08-211-7/+23
| | | | | | | | | | | | We need to know if `watch_configuration` is set in the descriptor publisher reactor to know whether we should be watching the `restricted_discovery.key_dirs` directories.
* | tor-config: Support watching dirs for files with a given extension.Gabriela Moldovan2024-08-211-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This also fixes a couple of issues with the previous implementation: * it enables you to watch for more than just one file/extension per directory (each directory now has a list of filters. If any of the filters apply to the path contained in the notify::Event, the `FilterWatcher` notifies the listeners * it removes the list watched files from `FileWatcher`. This makes things a lot simpler to grok: essentially, the file watcher only ever watches directories, notifying if an "interesting" file was changed (in our case, the interesting files are files that have a relevant extension, such as `.auth`, or specific configuration files, as specified by `ConfigurationSources`).
* | tor-config: Make FileWatcher use an opaque channel type.Gabriela Moldovan2024-08-211-89/+106
| | | | | | | | The `FileWatcher` now uses a `postage::watch` channel under the hood.
* | tor-config: Give FileWatcherBuilder a handle to the runtime.Gabriela Moldovan2024-08-211-5/+6
| | | | | | | | | | The event handler will soon be made async, so we need a handle to the runtime.
* | tor-config: Move FileWatcher to tor-config.Gabriela Moldovan2024-08-211-185/+22
| | | | | | | | | | | | | | | | | | For the most part, this is just code motion. The only change here is that `prepare` is no longer a method on `FileWatcher`. This decouples `FileWatcher` from `ConfigurationSources`, enabling us to use it to watch files and directories that aren't configuration.
* | arti: Update outdated FileWatcher docs.Gabriela Moldovan2024-08-211-5/+1
|/ | | | | The `FileWatcher` doesn't contain the channel for receiving events anymore, and `FileWatcher::event_matched` was removed at some point.
* Merge branch '1144-std-backtrace' into 'main'David Goulet2024-08-121-5/+3
|\ | | | | | | | | | | | | Use std::backtrace instead of backtrace crate Closes #1144 See merge request tpo/core/arti!2301
| * Match previous backtrace formattingRobin Leander Schröder2024-08-081-2/+2
| | | | | | | | | | std::backtrace::Backtrace's Display looks the same as backtrace_rs::Backtrace's Debug
| * Use std::backtrace instead of backtrace crateRobin Leander Schröder2024-08-011-3/+1
| | | | | | | | | | Removes resolve_backtraces from rtmock since it is no longer needed as stdlib's backtraces automatically lazily resolve without needing a &mut.
* | arti: Add the restricted_discovery configuration to the example config.Gabriela Moldovan2024-08-052-9/+94
| | | | | | | | This also adds a test for it.
* | tor-hsservice: Add restricted discovery configuration.Gabriela Moldovan2024-08-051-1/+1
| |
* | arti: Avoid using the now-deprecated arti_client constant.Gabriela Moldovan2024-08-051-2/+2
| | | | | | | | We can just used `build_for_arti()` here.
* | Have `arti hss onion-name` error if it doesn't print the onion nameKunal Mehta2024-08-011-3/+5
|/ | | | | | | There are two error cases where the onion name isn't printed, but previously returned `Ok(())`. It now returns an error to exit with a non-zero status code.
* arti: Use Path::try_exists() instead of Path::exists().Gabriela Moldovan2024-07-301-1/+1
|
* arti: Gate the hsc subcommand behind the keymgr feature (fmt).Gabriela Moldovan2024-07-102-2/+10
|
* arti: Gate the hsc subcommand behind the keymgr feature.Gabriela Moldovan2024-07-102-4/+4
| | | | | | | | | | | The `arti hsc` subcommand can't run without keymgr support. Previously, it relied on `tor-keymgr/keymgr` being enabled indirectly by its dependencies, via the `experimental` feature. We need to be able to enable this feature in `arti` without relying on `experimental` (because `arti hsc` will eventually be made non-experimental). Part of #1487
* tor-hscrypto: Remove unnecessary Display wrapper.Gabriela Moldovan2024-07-081-1/+1
| | | | | | | | | | | I don't think we need a separate wrapper type for displaying `HsClientDescEncKey` keys in the "C Tor format" (`<auth-type>:<key-type>:<base32-encoded-public-key>`). I think this should be the canonical string representation of `HsClientDescEncKey`, so I'm removing the `display_authorized_client` function and corresponding `DisplayAuthorizedHsClientDescEncKey` wrapper type.
* Merge branch 'warnings' into 'main'Ian Jackson2024-07-081-1/+1
|\ | | | | | | | | Fix or allow warnings that show up in beta See merge request tpo/core/arti!2244
| * Work around clippy::doc_lazy_continuation false positivesIan Jackson2024-07-081-1/+1
| | | | | | | | | | | | | | See https://github.com/rust-lang/rust-clippy/issues/13001 I think it's OK to change this in our tree, nevertheless.
* | Fix markdown quoting.Ian Jackson2024-07-081-1/+1
|/ | | | | | | | | | | | Fixes: warning: unclosed HTML tag `FILE` --> crates/arti/src/subcommands/hsc.rs:56:33 | 56 | /// Write the public key to <FILE>. Use - to write to stdout | ^^^^^^ | = note: `#[warn(rustdoc::invalid_html_tags)]` on by default
* arti: Rewrite the hsc prepare-service-discovery-key command (fmt).Gabriela Moldovan2024-06-271-11/+6
|
* arti: Rewrite the hsc prepare-service-discovery-key command.Gabriela Moldovan2024-06-271-10/+30
| | | | | | | The `arti hsc prepare-service-discovery-key` command is now `arti hsc get-key [--key-type=service-discovery]`. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2212#note_3042903
* arti: Add an arti hsc subcommand.Gabriela Moldovan2024-06-273-0/+168
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds an experimental `arti hsc` subcommand for managing client state and keys. Currently, it only supports the `prepare-service-discovery-keys` operation described in #1281 and `doc/dev/notes/client-auth.md`. A note on terminology: I am referring to services that encrypt the second layer of their descriptor as running in "restricted discovery" mode (because they can only be discovered, i.e. have their IPT points found out, by a set of authorized clients). The corresponding client "auth" keys, being the keys that enable the client to find out the list of intro points, pow-params etc. of the service, are referred to as service "discovery keys". Alternative names I considered: * extra descriptor encryption: accurate, but overly technical. IMO, the CLI should be accessible to users who aren't familiar with the nitty-gritty of the protocol * shielded mode: good, but slightly misleading. Calling it "shielded mode" makes it sound like a universally desirable "extra protection" that should almost always be enabled (which is not the case). Seeing `shielded_mode = off` in the config might be worry operators that don't fully understand what "extra descriptor encryption" or "shielded mode" means * restricted mode: slightly inaccurate. It implies this mechanism is a good substitute for conventional service-side authentication, which it isn't (because client authorization isn't instantaneous) Closes #1281
* arti: wait a short while on startup if lockfiles are unavailable.Nick Mathewson2024-06-241-1/+1
|
* arti: Add a TODO about a possible refactoring.Gabriela Moldovan2024-06-171-0/+2
| | | | | I propose we move each subcommand implementation to a `subcommand` submodule.
* arti: Move arti hss subcommand implementation to separate module.Gabriela Moldovan2024-06-173-38/+58
| | | | This addresses a TODO.
* Merge branch 'arti-relay-flag' into 'main'Nick Mathewson2024-06-121-39/+63
|\ | | | | | | | | relay: Add relay cargo feature flag and subcommand See merge request tpo/core/arti!2182
| * relay: Add relay cargo feature flag and subcommandDavid Goulet2024-06-111-39/+63
| | | | | | | | | | | | | | | | | | | | Add the optional non default feature flag "relay" that will be used to enable relay support of arti. This commit also adds the "relay" subcommand to arti binary conditionnal on the feature flag in order to have a place holder starting point. Signed-off-by: David Goulet <[email protected]>
* | RPC: Use RPC methods instead of the "ClientConnectionTarget" trait.Nick Mathewson2024-06-113-30/+116
|/ | | | | | | | | | | | On its own, this might not seem like a huge improvement, but it will later let us implement these RPC methods for types that can't reasonably implement ClientConnectionTarget. It also serves as a proof of concept that special-method invocation can actually work, so that we can build things like this in cases where introducing a trait isn't practical. Closes #1427
* rpc: Make RpcMgr::lookup_object return context along with object.Nick Mathewson2024-06-101-0/+1
| | | | The context will make it possible to invoke rpc methods.
* arti: Note that auto is the same as disabled if vanguards are disabled.Gabriela Moldovan2024-06-031-0/+3
|
* arti: Add vanguards settings to example config.Gabriela Moldovan2024-06-032-1/+14
|