summaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
...
* Introduce ChannelConfigIan Jackson2022-08-161-0/+4
| | | | | This commit is just the necessary plumbing. The config is currently empty. We'll add something to it, for padding control, later.
* arti: Add support for process hardeningNick Mathewson2022-08-155-1/+71
| | | | | | | | | | | | | This is a compile-time feature with an associated configuration flag, both enabled by default. When it's turned on, hardening prevents the arti process from dumping core or being attached to by low-privileged processes. (This is a defense-in-depth measure, not an absolute way to prevent attacks. For more information, see [`secmem_proc`](https://docs.rs/secmem-proc/0.1.1/secmem_proc/).) Closes #364.
* Add a few dire warnings about main; make main_main experimental.Nick Mathewson2022-08-111-2/+31
|
* Document more explicitly what "voiding a semver warranty" entailsNick Mathewson2022-08-111-1/+5
| | | | Closes #522.
* arti: `main_main` takes command-line arguments does not call exit()Nick Mathewson2022-08-111-3/+18
|
* arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-117-11/+37
| | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
* arti: Add a feature flag for dns-proxy.Nick Mathewson2022-08-111-0/+10
| | | | | | | It remains on-by-default, so users shouldn't notice a difference, but it may help when we want to save a few bytes of binary size. Closes #532
* Rename download_tolerance to directory_toleranceNick Mathewson2022-07-221-2/+5
| | | | Closes #503.
* disable-fs-permission-checks: remove variable from help messageJim Newsome2022-07-191-1/+0
| | | | | This option doesn't take an argument. This change drops the argument from the `--help` message.
* Merge branch 'mistrust-envvar' into 'main'Nick Mathewson2022-07-191-26/+17
|\ | | | | | | | | | | | | Move environment-variable checking into fs-mistrust Closes #483 See merge request tpo/core/arti!630
| * Arti: Use synthetic argument to implement --disable-fs-permission-checksNick Mathewson2022-07-191-22/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | Now that configuring the environment variables related to fs permissions works properly, we don't need to use the "override" feature any more: we can just add the option to the configuration when appropriate. With this design, `--disable-fs-permission-checks` is now mostly an alias for `--option storage.permissions.dangerously_trust_everyone=true` Enabled by #483.
| * Move responsibility for disable-fs-mistrust envvar.Nick Mathewson2022-07-191-4/+6
| | | | | | | | | | | | | | The variable is now handled when building the configuration, and no longer needs to be special-cased. Closes #483.
* | socksproto: Use fallible writers.Nick Mathewson2022-07-111-10/+20
|/ | | | Also, make private a function that had formerly been `pub`.
* Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-232-0/+6
| | | | Update all lint blocks
* Updated the warning message providing additional information about the type ↵0x4ndy2022-06-211-2/+1
| | | | of the proxy port.
* Merge branch 'reachable_addrs_v2' into 'main'Nick Mathewson2022-06-171-0/+10
|\ | | | | | | | | | | | | Implement support for reachable_addrs Closes #491 and #93 See merge request tpo/core/arti!583
| * Add a configuration option for reachable_addrsNick Mathewson2022-06-171-0/+10
| | | | | | | | (This doesn't do anything yet.)
* | Merge branch 'config-fix2' into 'main'Nick Mathewson2022-06-161-14/+6
|\ \ | | | | | | | | | | | | Use impl_standard_builder more and remove manual Default/builder impls See merge request tpo/core/arti!594
| * | impl_standard_builder: Use for arti::logging::LogfileConfigIan Jackson2022-06-161-7/+2
| | |
| * | arti: logging config: Replace a manual Debug implIan Jackson2022-06-161-7/+4
| | |
* | | Merge branch 'config-fix' into 'main'Ian Jackson2022-06-162-46/+89
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Config handling and logging fixes Closes #480 See merge request tpo/core/arti!589
| * | | arti: cfg: Remove another needless borrowIan Jackson2022-06-161-1/+1
| | | |
| * | | arti cfg tests: Remove a redundant line that shadows an earlier bindingIan Jackson2022-06-161-1/+0
| | | | | | | | | | | | | | | | | | | | Prompted by review https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/589#note_2813596
| * | | Fix grammar erroreta2022-06-161-1/+1
| | | |
| * | | arti: Enable some pre-config loggingIan Jackson2022-06-161-2/+16
| | | |
| * | | arti: Introduce closure which will be used for pre-config loggingIan Jackson2022-06-161-31/+52
| | | | | | | | | | | | | | | | Right now this is an IEFI and therefore a no-op.
| * | | arti cfg tests: Test that example config works as-isIan Jackson2022-06-161-0/+2
| | | | | | | | | | | | | | | | It contains only sections, but we want to detect when that is a problem!
| * | | arti: cfg tests: Refactor to prepare for new testIan Jackson2022-06-161-16/+23
| |/ / | | | | | | | | | We're going to call this new closure another time.
* | | Merge branch 'main' into 'accel-features'Nick Mathewson2022-06-162-2/+6
|\ \ \ | | |/ | |/| | | | # Conflicts: # crates/arti-client/Cargo.toml
| * | Merge branch 'high-level-features' into 'main'Nick Mathewson2022-06-161-41/+60
| |\ \ | | |/ | |/| | | | | | | | | | | | | Add "full" and "experimental" features to arti, arti-client, and below. Closes #499 See merge request tpo/core/arti!584
| | * Remove "rustls" from "full", for license reasons.Nick Mathewson2022-06-151-1/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | Rustls uses ring, which uses code from BoringSSL, which derived from OpenSSL before OpenSSL changed their license. So ring is currently under 3BSD/SSLEay licenses, which aren't GPL-compatible, which may be a problem for some people. See #493.
| * | config: Do not strip_option for journald (and in future)Ian Jackson2022-06-101-1/+1
| | | | | | | | | | | | | | | As per point 1 in https://gitlab.torproject.org/tpo/core/arti/-/issues/488
* | | Add "accel-*" features to arti-client and arti.Nick Mathewson2022-06-131-0/+9
| |/ |/| | | | | | | | | | | | | | | | | These need to be optional: they improve performance by shifting to asm implementations, which may not be everybody's idea of good practice. These are not 'pure' features, since they select one implementation but disable another. Therefore they don't go in `full`. Closes #441.
* | Document "full", "experimental" in toplevel crate documentation.Nick Mathewson2022-06-131-41/+56
|/ | | | | Also, unify the features documentation format for those two crates, and document previously undocumented features there.
* try to differentiate transient from nontransient errortrinity-1686a2022-06-081-2/+0
|
* return nodata instead of servfail in some instancestrinity-1686a2022-06-081-3/+13
|
* Merge branch 'lint' into 'main'Ian Jackson2022-05-312-6/+10
|\ | | | | | | | | | | | | lints: Make lint blocks consistent and ensure they stay that way Closes #469 See merge request tpo/core/arti!557
| * lints: Make lint blocks consistentIan Jackson2022-05-312-4/+0
| | | | | | | | The remaining consequences of running add_warning
| * lints: Add let_unit_value allow to all cratesIan Jackson2022-05-312-0/+2
| | | | | | | | | | From running add_warning, with manual picking of the right hunks/lines.
| * lints: arti: Move some allows outside the auto blockIan Jackson2022-05-311-2/+4
| | | | | | | | These need to survive.
| * lints: Add lint block delimiters to every crateIan Jackson2022-05-312-0/+4
| | | | | | | | | | | | This was the result of: maint/add_warning crates/*/src/{lib,main}.rs and then manually curating the results.
* | arti config: Check that example config is exhaustiveIan Jackson2022-05-301-0/+114
| | | | | | | | This is the final piece of #457.
* | mistrust: Canonicalise prefix from Some("") to NoneIan Jackson2022-05-301-0/+1
| | | | | | | | | | This allows us to add the proper default example to the arti example config file.
* | arti: config: Canonicalise ports, and provide example dns_portIan Jackson2022-05-302-8/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | Now the validated configuration will never be `Some(0)`, even if that is what was written in the config file. The arti CLI parser can still produce this, so we don't touch the code that actually uses this. (Without the canonicalisation the default builder produces `None` for the `dns_port`, but the example would produce `Some(0)`, which is semantically identical but fails the test.) See https://gitlab.torproject.org/tpo/core/arti/-/issues/488 for some background.
* | config: Provide tor_config::resolve_option and resolve journaldIan Jackson2022-05-302-3/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Canonicalise the `logging.journald` setting in the validated configuration. Now it will never be `Some("")`, even if that is what was written in the config file. This allows us to write `journald = ""` in the example configuration. (Without the canonicalisation the default builder produces `None` and the example would produce `Some("")`, which are semantically identical but fail the test.) See https://gitlab.torproject.org/tpo/core/arti/-/issues/488 for some background.
* | arti: config example: Add entries for tor_network fieldsIan Jackson2022-05-301-0/+9
| | | | | | | | | | These weren't previously discussed. It's not practical or useful to show the actual default values here.
* | arti: config example: Add some missing defaultsIan Jackson2022-05-301-3/+17
| | | | | | | | Found by my forthcoming test.
* | arti: example config: Arrange to uncomment logfilesIan Jackson2022-05-301-2/+2
| | | | | | | | | | This makes the config default parser see just "[ ]", an empty list, which is indeed the default.
* | arti: Make ProxyConfig no longer DeserializeIan Jackson2022-05-301-4/+1
| | | | | | | | That this remained was an oversight.
* | arti: cfg: Actually uncomment *all* the things in the exampleIan Jackson2022-05-301-1/+1
|/