aboutsummaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
...
* | | socks users: detect closed sockets.Nick Mathewson2024-09-241-1/+6
|/ / | | | | | | | | | | | | | | | | Without this check, our socks code can enter an infinite loop if a socket is closed at the wrong time. Resolves TROVE-2024-011. Fixes #1635.
* | Merge branch 'impl-prop-351' into 'main'Nick Mathewson2024-09-241-124/+106
|\ \ | | | | | | | | | | | | socks: Implement proposal 351. See merge request tpo/core/arti!2401
| * | socks: Add a comment about interpreting legacy usernames.Nick Mathewson2024-09-241-0/+5
| | |
| * | socks: cleanups in interpret_socks_authNick Mathewson2024-09-181-12/+22
| | | | | | | | | | | | Introduce an enum, and use explicit `format_code @` syntax.
| * | prop351: comment Suggestions from @diziet.Nick Mathewson2024-09-181-1/+4
| | |
| * | Socks: isolate streams from different extended-socks formatsNick Mathewson2024-09-181-3/+16
| | | | | | | | | | | | | | | | | | | | | (These streams would already be isolated by accident, since streams with an RPC object are always on a client that's isolated from the main client. But, as discussed on torspec!280, it's best to do this sort of thing explicitly.)
| * | socks: Optimistically revise format to match torspec!280Nick Mathewson2024-09-101-43/+53
| | |
| * | socks: update protocol documentationNick Mathewson2024-09-091-78/+9
| | | | | | | | | | | | | | | | | | | | | The current best source here is prop351, and later will be socks-extensions.md. The examples are now correct.
| * | socks: Implement proposal 351.Nick Mathewson2024-09-091-40/+50
| | | | | | | | | | | | | | | | | | | | | | | | See https://spec.torproject.org/proposals/351-socks-auth-extensions.html This proposal changes the interpretation of SOCKS5 usernames/passwords to give a more principled and extensible way of getting RPC IDs and isolation strings.
* | | Merge branch 'pessimistic' into 'main'Nick Mathewson2024-09-241-0/+5
|\ \ \ | | | | | | | | | | | | | | | | arti SOCKS proxy: Tear down connections when client sends optimistic data See merge request tpo/core/arti!2443
| * | | arti SOCKS proxy: Tear down connections when client sends optimistic dataIan Jackson2024-09-241-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We *do* want to support optimistic data, see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2436#note_3081886 However, right now, Arti risks mis-framing bugs if clients do send optimistic data, which would be quite serious. Mitigates #1627 / TROVE-2024-010 by replacing the misframing bug with connection failure. It doesn't seem so easy to write a test case for this.
* | | | rpc: add mandatory delegate-type attribute to Object templateNick Mathewson2024-09-241-1/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | When specifying a delegation, the template user must also say what type they're delegating to. We're going to use this to document and expose delegations.
* | | | Merge branch 'abstract-socket-v2' into 'main'Nick Mathewson2024-09-241-2/+2
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | rtcompat: Second attempt at AF_UNIX support Closes #1152 See merge request tpo/core/arti!2437
| * | | | rtcompat: Rename TcpProvider to NetStreamProvider.Nick Mathewson2024-09-241-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (And similarly rename TcpListener to NetStreamListener, along with their TcpStream/TcpListener associated types.) These types are about to become generic over addresses, and therefore shouldn't be named after TCP. Renaming was done mostly with Rust Analyzer, except for some macros that needed to be hand-edited. (I'll revise the comments in the next commit; this one is all about renaming.)
* | | | | arti: Update example config with new keystore configuration.Gabriela Moldovan2024-09-231-10/+8
| | | | |
* | | | | tor-keymgr: Move keystore config under keystore.primary.Gabriela Moldovan2024-09-231-1/+2
|/ / / / | | | | | | | | | | | | | | | | The keystore settings only configure the *primary* keystore, so they should be under `keystore.primary`.
* | | | tor-keymgr: Rename the primary keystore for clarity.Gabriela Moldovan2024-09-231-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, arti's primary keystore was referred to as its "default" keystore. However, "default" is inaccurate here: there is no way to meaningfully override this "default" (the "default" store acts as the main keystore). Throughout the codebase, we query all keystores for keys (including the secondary ones), but only ever write to the default/primary keystore. This is OK for now, because it enables us to have one mutable keystore, and multiple secondary, read-only stores.
* | | | tor-keymgr: added support for specifying keystore kind to ArtiKeystoreConfigMorgan2024-09-201-1/+19
|/ / /
* | | arti: Tolerate lowercase "no" in confirmation prompt.Gabriela Moldovan2024-09-191-3/+7
| | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2435#note_3080452
* | | arti: Fix typo in display_service_discovery_key function name.Gabriela Moldovan2024-09-191-3/+3
| | |
* | | arti: Gate the arti hsc subcommand behind a new "hsc" feature (fmt).Gabriela Moldovan2024-09-191-4/+1
| | |
* | | arti: Gate the arti hsc subcommand behind a new "hsc" feature.Gabriela Moldovan2024-09-192-12/+4
| | | | | | | | | | | | This new feature is experimental.
* | | arti: Add a subcommand for removing a client discovery key.Gabriela Moldovan2024-09-191-0/+35
| | | | | | | | | | | | Closes #1475
* | | arti: Add an hsc subcommand for rotating client keys.Gabriela Moldovan2024-09-191-0/+65
| | | | | | | | | | | | Part of #1475
* | | arti: Move public key output logic to a separate function.Gabriela Moldovan2024-09-191-4/+13
| | | | | | | | | | | | | | | This will be reused for `arti hsc key rotate`, which also outputs the public key.
* | | arti: Satisfy clippy.Gabriela Moldovan2024-09-181-4/+4
| | |
* | | arti: Add hsc key subcommand, deprecate hsc get-key.Gabriela Moldovan2024-09-181-3/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I am deprecating the old `hsc get-key` subcommand in favor of the new `hsc key get` subcommand. This is because I plan to implement the rest of the key management functionality (key deletion, rotation, etc.) as subcommands of the `hsc key` command. The alternative would be to add a new distinct top-level `hsc rotate-key`, `hsc remove-key`, etc. subcommand alongside the existing `hsc get-key` command (which IMO is less nice than the alternative I'm proposing).
* | | arti: Move the keygen-related args to a separate struct.Gabriela Moldovan2024-09-181-9/+17
| | | | | | | | | | | | These will be reused by a future `key rotate` subcommand.
* | | arti: Make sure we check the KeyType before running the command.Gabriela Moldovan2024-09-181-1/+5
| | | | | | | | | | | | | | | Otherwise, if/when we add support for other `KeyType`s we risk forgetting to update the rest of the implementation.
* | | arti: Move the shared arti hsc args to CommonArgs (fmt).Gabriela Moldovan2024-09-181-2/+4
| | |
* | | arti: Move the shared arti hsc args to CommonArgs.Gabriela Moldovan2024-09-181-16/+22
| | |
* | | arti: Move TorClient creation to the top-level (fmt).Gabriela Moldovan2024-09-181-4/+1
| | |
* | | arti: Move TorClient creation to the top-level.Gabriela Moldovan2024-09-181-8/+7
| |/ |/| | | | | | | The client will be used by future subcommands too, not just `prepare_service_discovery_key`.
* | Merge branch 'svc-no-proxy-port' into 'main'David Goulet2024-09-172-14/+36
|\ \ | | | | | | | | | | | | | | | | | | arti: Allow running hidden services with SOCKS/DNS proxying disabled. Closes #1569 See merge request tpo/core/arti!2423
| * | arti: Don't log that we are in SOCKS mode unless socks_listen is set.Gabriela Moldovan2024-09-171-6/+13
| | | | | | | | | | | | If `socks_listen` is disabled, we're not actually running in SOCKS mode.
| * | arti: Allow running hidden services with SOCKS/DNS ports disabled.Gabriela Moldovan2024-09-172-8/+23
| | | | | | | | | | | | Closes #1569
* | | arti: Remove get-key subcommand in favor of onion-name.Gabriela Moldovan2024-09-171-28/+7
| | | | | | | | | | | | | | | | | | | | | | | | The `hss get-key` subcommand is now folded into `onion-name`, which takes a `--generate` argument which specifies whether to generate the key if missing. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2419#note_3078068
* | | arti: Add CLI for generating an onion service hsid.Gabriela Moldovan2024-09-171-2/+83
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new `hss get-key` subcommand for retrieving and generating service identity keys. The existing `hss onion-name` is now a convenience alias for `hss get-key --generate=no --key-type=onion-name`. Note: I am calling this new subcommand `get-key` for consistency with its client counterpart (`hsc get-key`). Closes #1621
* | | arti: Add an enum for the hss subcommand.Gabriela Moldovan2024-09-172-39/+47
| | | | | | | | | | | | | | | | | | | | | This is needed because we'll soon add an `hss get-key` subcommand for getting and/or generating a service identity key alongside `hss onion-name` (`hss onion-name` will become a convenience around `hss get-key --key-type=onion-name`).
* | | arti: Refactor hss::onion_name() implementation.Gabriela Moldovan2024-09-171-11/+29
| | | | | | | | | | | | | | | This splits `onion_name` into multiple functions (which will be repurposed for the future `hss get-key` implementation).
* | | arti: Move hss onion-name implementation to a separate function.Gabriela Moldovan2024-09-171-29/+41
| | | | | | | | | | | | | | | `hss` will soon sprout another subcommand, so I am preemptively refactoring the `hss onion-name` implementation out of `hss::run()`.
* | | arti: Remove a completed TODO.Gabriela Moldovan2024-09-171-1/+0
|/ / | | | | | | The tests were added in !2275
* | arti: Move proxy subcommand to a separate module.Gabriela Moldovan2024-09-122-41/+42
| | | | | | | | | | | | | | | | No functional changes, this is just code motion. This helps organize the code in `arti/src/lib.rs` a bit. It now only contains the argument parsing and various other setup, and all the subcommands are contained in separate modules.
* | arti: Move arti::run to subcommands::proxy.Gabriela Moldovan2024-09-122-156/+172
| | | | | | | | No functional changes, this is just code motion.
* | arti: Add a new module for the proxy subcommand.Gabriela Moldovan2024-09-122-0/+19
| | | | | | | | | | The implementation for `arti proxy` will soon be relocated to this new module.
* | Merge branch 'rpc_proxy_info_fix' into 'main'Ian Jackson2024-09-121-1/+1
|\ \ | | | | | | | | | | | | rpc: Fix argument type for rpc_session_get_rpc_proxy_info See merge request tpo/core/arti!2409
| * | rpc: Fix argument type for rpc_session_get_rpc_proxy_infoNick Mathewson2024-09-111-1/+1
| | | | | | | | | | | | | | | | | | | | | Without this, we get a panic on startup when running with RPC! (This stresses the need for an integration test for RPC; I will start writing that after the Python wrapper lands.)
* | | arti: Remove onion service anonymity setting.Gabriela Moldovan2024-09-121-7/+0
|/ / | | | | | | We don't support this yet, see #727.
* | Merge branch 'publisher-svc-status' into 'main'David Goulet2024-09-101-1/+15
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Improve descriptor publisher status reporting Closes #1216 and #1572 See merge request tpo/core/arti!2397
| * | tor-hsservice: Log the onion svc status.Gabriela Moldovan2024-09-091-1/+15
| |/ | | | | | | We now log the onion service status on change.