| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |
|
|
|
|
|
|
|
|
| |
This is no longer needed now that `KeyMgr::describe()` works on
`CTorPath`s.
Removing this special handling has the added bonus that the keymgr CLI
output is now uniform for all keystores (before this change, `keys list`
used a slightly different output format for displaying C Tor entries).
The corresponding tests will be updated in a future commit.
|
| | |
|
| |
|
|
|
|
| |
This was a little funny, since the other storage elements are
declared in tor-client. Fortunately, our stacked configuration
logic handles this fine.
|
| | |
|
| |
|
|
|
| |
This allows applications to find out where arti is listening when
arti has been configured to listen with the port "auto".
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
Previously, the proxy and dns modules only had "be a proxy"
functions that ran forever. Now they have functions that bind to
listeners and return a separate "be a proxy" future that runs
forever.
This lets us simplify some kludges in subcommands::proxy. More
importantly, it will let us return the bound-to ports so that
subcommands::proxy can write them to disk.
This is a break in experimental-apis, which does not require a
semver change.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
| |
Fixes part of #2193.
(Edits from nickm: I selected the cases here that I could verify
were correct from immediate context.)
Edited-by: Nick Mathewson <[email protected]>
|
| |\
| |
| |
| |
| | |
Add `KeyMgr` accessor to `TorClient`
See merge request tpo/core/arti!3442
|
| | |
| |
| |
| |
| |
| | |
`run_check_integrity`
This change simplifies the signature of `run_check_integrity`.
|
| |\ \
| | |
| | |
| | |
| | | |
tor-config: Refactor `Listen` to make usable for arti-relay
See merge request tpo/core/arti!3469
|
| | | |
| | |
| | |
| | | |
Assumes that 0.37.0 will be the next version number.
|
| | | | |
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
arti: Put supported request headers in Tor-Capabilties
Closes #2259
See merge request tpo/core/arti!3473
|
| | |/ /
| | |
| | |
| | |
| | |
| | | |
This is for spec conformance; it is a missing piece of prop365.
Closes #2259.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Fix some errors in and around making directories for logfiles.
Closes #2240, #2265, and #2266
See merge request tpo/core/arti!3491
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This will improve the error message for problems similar to
arti#2240, if they recur.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This should fix the main part of arti#2240.
This is an instance of arti#2267 ("Path::parent has funny behavior")
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
arti: Add rate_limit_at_intro to the example config
See merge request tpo/core/arti!3493
|
| | | | | | |
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | | |
This is mostly c&p from the `rate_limit_at_intro` docs, I just added an
extra paragraph to clarify the meaning of the tuple elements (i.e.
`(rate, burst)`).
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
hsservice: Clarify what max_concurrent_streams_per_circuit does
See merge request tpo/core/arti!3492
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
At first glance, this might seem equivalent to C Tor's
`HiddenServiceMaxStreams` option, but it's actually
`HiddenServiceMaxStreamsCloseCircuit` (Arti doesn't implement the
former).
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
http-connect: use end reason for http status if possible
See merge request tpo/core/arti!3481
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The spec includes a direct conversion from END reason fields to HTTP
status codes, so we should follow it if we have an END reason.
|
| | |/ / /
|/| | |
| | | |
| | | |
| | | | |
These are all aimed at figuring out in more detail what's going on
in #2079 and related issues.
|
| |/ / / |
|
| | | | |
|
| | | | |
|
| |/ /
| |
| |
| |
| |
| |
| | |
It makes more sense to have the conversion here, so it can use an
exhaustive match over ErrorKind.
This isn't the final API; I'm just moving the code from `arti`.
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
arti: Warning when opentelemetry config is set but not build with feature
Closes #2247
See merge request tpo/core/arti!3458
|
| | | |
| | |
| | |
| | | |
It seems this config is for tokio-console and not the RPC.
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Validate Host header for non-CONNECT requests to HTTP CONNECT port
See merge request tpo/core/arti!3429
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This validation makes it harder for an adversarial webpage to probe
for the version of arti and its capabilities.
See torspec!437.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
Implement a usage-based timeout for strongly isolated circuits (prop368)
Closes #2237
See merge request tpo/core/arti!3430
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
Part of prop368.
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | |
| | | |
| | | | |
arti/arti-client/tor-hsservice: Support disabling onion services in the config
Closes #2133
See merge request tpo/core/arti!3253
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
There is no longer a hard error anywhere for trying to launch a service
which is disabled in the config. Instead, it always means returning
`Ok(None)`.
The axum and hyper examples were updated again as a consequence.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The "enabled" config option is back to using a regular `bool`. When
unset, it defaults to true, and the service runs as if it had been set.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
I didn't realize we had tests that made use of the example config. The
pre-commit and pre-push hooks I had didn't trigger them, so my
modification to the example config silently got through and caused
`cfg::test::onion_services` to fail in CI.
The issue was that I had put my example for
`onion_services."allium-cepa".enabled` with a default of `true`. The
correct default is actually `"auto"`, so I switched it and improved the
description of the options.
I've fixed my hooks. Which, to be fair, are just the hooks provided in
`./maint/hooks/`. Maybe those should be improved?
Signed-off-by: hashcatHitman <[email protected]>
|