| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
arti: Put supported request headers in Tor-Capabilties
Closes #2259
See merge request tpo/core/arti!3473
|
| | |/ /
| | |
| | |
| | |
| | |
| | | |
This is for spec conformance; it is a missing piece of prop365.
Closes #2259.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Fix some errors in and around making directories for logfiles.
Closes #2240, #2265, and #2266
See merge request tpo/core/arti!3491
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This will improve the error message for problems similar to
arti#2240, if they recur.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This should fix the main part of arti#2240.
This is an instance of arti#2267 ("Path::parent has funny behavior")
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
arti: Add rate_limit_at_intro to the example config
See merge request tpo/core/arti!3493
|
| | | | | | |
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | | |
This is mostly c&p from the `rate_limit_at_intro` docs, I just added an
extra paragraph to clarify the meaning of the tuple elements (i.e.
`(rate, burst)`).
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
hsservice: Clarify what max_concurrent_streams_per_circuit does
See merge request tpo/core/arti!3492
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
At first glance, this might seem equivalent to C Tor's
`HiddenServiceMaxStreams` option, but it's actually
`HiddenServiceMaxStreamsCloseCircuit` (Arti doesn't implement the
former).
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
http-connect: use end reason for http status if possible
See merge request tpo/core/arti!3481
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The spec includes a direct conversion from END reason fields to HTTP
status codes, so we should follow it if we have an END reason.
|
| | |/ / /
|/| | |
| | | |
| | | |
| | | | |
These are all aimed at figuring out in more detail what's going on
in #2079 and related issues.
|
| |/ / / |
|
| | | | |
|
| | | | |
|
| |/ /
| |
| |
| |
| |
| |
| | |
It makes more sense to have the conversion here, so it can use an
exhaustive match over ErrorKind.
This isn't the final API; I'm just moving the code from `arti`.
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
arti: Warning when opentelemetry config is set but not build with feature
Closes #2247
See merge request tpo/core/arti!3458
|
| | | |
| | |
| | |
| | | |
It seems this config is for tokio-console and not the RPC.
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Validate Host header for non-CONNECT requests to HTTP CONNECT port
See merge request tpo/core/arti!3429
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This validation makes it harder for an adversarial webpage to probe
for the version of arti and its capabilities.
See torspec!437.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
Implement a usage-based timeout for strongly isolated circuits (prop368)
Closes #2237
See merge request tpo/core/arti!3430
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
Part of prop368.
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | |
| | | |
| | | | |
arti/arti-client/tor-hsservice: Support disabling onion services in the config
Closes #2133
See merge request tpo/core/arti!3253
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
There is no longer a hard error anywhere for trying to launch a service
which is disabled in the config. Instead, it always means returning
`Ok(None)`.
The axum and hyper examples were updated again as a consequence.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The "enabled" config option is back to using a regular `bool`. When
unset, it defaults to true, and the service runs as if it had been set.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
I didn't realize we had tests that made use of the example config. The
pre-commit and pre-push hooks I had didn't trigger them, so my
modification to the example config silently got through and caused
`cfg::test::onion_services` to fail in CI.
The issue was that I had put my example for
`onion_services."allium-cepa".enabled` with a default of `true`. The
correct default is actually `"auto"`, so I switched it and improved the
description of the options.
I've fixed my hooks. Which, to be fair, are just the hooks provided in
`./maint/hooks/`. Maybe those should be improved?
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The "enabled" config option now uses `tor_config::BoolOrAuto`. When
unset (which defaults to "Auto"), the service will run with a warning.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
When a service is disabled in the config, `arti::onion_proxy::Proxy`
handles it gracefully, and
`arti_client::client::TorClient::launch_onion_service_with_hsid` and
`arti_client::client::TorClient::launch_onion_service` both hard error.
The axum and hyper examples were updated again as a consequence.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Hidden services disabled in the config are now handled more gracefully
by arti/arti-client, before the hard error occurs.
The axum and hyper examples were updated as a consequence.
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | | |
Signed-off-by: hashcatHitman <[email protected]>
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is the pattern we used elsewhere with the "rpc" option.
IMO, this kind of thing is another argument in favor if
arti#1704 (redoing config types using derive-deftly.)
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is controlled by a new option, `logging.tokio_console.enabled`.
It requires building with `--cfg tokio_unstable`. See documentation
and comments for more information.
|
| | | | |
| | | |
| | | |
| | | | |
Run maint/add_warning
|
| | |_|/
|/| | |
|
| | |/
|/|
| |
| |
| |
| |
| |
| | |
This change lets us avoid spawning extra tasks (due to one-direction
nature of copy_interactive), and avoid some lock contention (due to
use of AsyncReadExt::split).
Addresses part of #786.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
arti: Revise strings that implied that we were a SOCKS-only proxy.
Closes #2225
See merge request tpo/core/arti!3398
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Closes #2225
|
| | | | |
|
| |/ /
| |
| |
| |
| |
| |
| | |
Apparently the http_connect refactoring made these no longer
trigger.
Closes #2226
|
| | |
| |
| |
| |
| |
| | |
We can't remove them all, since X-Tor-Stream-Isolation is recognized
by C-Tor. I've added a non-deprecated Tor-Stream-Isolation
that works indepenently.
|