aboutsummaryrefslogtreecommitdiff
path: root/crates/arti/src
Commit message (Collapse)AuthorAgeFilesLines
...
* | | Merge branch 'ticket_2259' into 'main'Nick Mathewson2025-11-251-1/+26
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | arti: Put supported request headers in Tor-Capabilties Closes #2259 See merge request tpo/core/arti!3473
| * | | arti: Put supported request headers in Tor-CapabiltiesNick Mathewson2025-11-181-1/+26
| |/ / | | | | | | | | | | | | | | | This is for spec conformance; it is a missing piece of prop365. Closes #2259.
* | | Merge branch 'mistrust-and-the-empty-string' into 'main'Nick Mathewson2025-11-251-2/+18
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Fix some errors in and around making directories for logfiles. Closes #2240, #2265, and #2266 See merge request tpo/core/arti!3491
| * | | arti: Make logging parent check work with our MSRV.Nick Mathewson2025-11-251-1/+1
| | | |
| * | | arti: use anyhow::Context on a make_directory failure.Nick Mathewson2025-11-241-1/+6
| | | | | | | | | | | | | | | | | | | | This will improve the error message for problems similar to arti#2240, if they recur.
| * | | arti: Allow a logfile with no directory prefix.Nick Mathewson2025-11-241-1/+12
| | | | | | | | | | | | | | | | | | | | | | | | This should fix the main part of arti#2240. This is an instance of arti#2267 ("Path::parent has funny behavior")
* | | | Merge branch 'intro-dos' into 'main'gabi-2502025-11-251-0/+21
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti: Add rate_limit_at_intro to the example config See merge request tpo/core/arti!3493
| * | | | arti: Clarify that the "burst" is not per second.Gabriela Moldovan2025-11-251-1/+1
| | | | |
| * | | | arti: Add rate_limit_at_intro to the example configGabriela Moldovan2025-11-251-0/+21
| |/ / / | | | | | | | | | | | | | | | | | | | | This is mostly c&p from the `rate_limit_at_intro` docs, I just added an extra paragraph to clarify the meaning of the tuple elements (i.e. `(rate, burst)`).
* | | | Merge branch 'max-concurrent-streams' into 'main'Nick Mathewson2025-11-251-0/+5
|\ \ \ \ | |/ / / |/| | | | | | | | | | | hsservice: Clarify what max_concurrent_streams_per_circuit does See merge request tpo/core/arti!3492
| * | | hsservice: Clarify what max_concurrent_streams_per_circuit doesGabriela Moldovan2025-11-251-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | At first glance, this might seem equivalent to C Tor's `HiddenServiceMaxStreams` option, but it's actually `HiddenServiceMaxStreamsCloseCircuit` (Arti doesn't implement the former).
* | | | Merge branch 'end_reason_handling' into 'main'Nick Mathewson2025-11-241-1/+38
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | http-connect: use end reason for http status if possible See merge request tpo/core/arti!3481
| * | | | http-connect: use end reason for http status if possibleNick Mathewson2025-11-241-1/+38
| | | | | | | | | | | | | | | | | | | | | | | | | The spec includes a direct conversion from END reason fields to HTTP status codes, so we should follow it if we have an END reason.
* | | | | opentelemetry: Instrument a bunch of functions.Wesley Aptekar-Cassels2025-11-241-1/+7
| |/ / / |/| | | | | | | | | | | | | | | These are all aimed at figuring out in more detail what's going on in #2079 and related issues.
* | | | Add `hsc key ctor-migrate` subcommandhjrgrn2025-11-241-0/+119
|/ / /
* | | http_connect: Report end reasons for HTTP CONNECT failures.Nick Mathewson2025-11-191-6/+27
| | |
* | | tor-error: Provide a more reasonable API for http status codes.Nick Mathewson2025-11-181-2/+2
| | |
* | | tor-error: Add support for ErrorKind->HTTP status conversionNick Mathewson2025-11-181-78/+2
|/ / | | | | | | | | | | | | It makes more sense to have the conversion here, so it can use an exhaustive match over ErrorKind. This isn't the final API; I'm just moving the code from `arti`.
* | http_connect: Add AsyncReadExt to fix compilation.Nick Mathewson2025-11-131-2/+2
| |
* | Merge branch 'opentelemetry-options-without-feature-warning' into 'main'Nick Mathewson2025-11-131-1/+17
|\ \ | | | | | | | | | | | | | | | | | | arti: Warning when opentelemetry config is set but not build with feature Closes #2247 See merge request tpo/core/arti!3458
| * | arti: Boyscout fixnield2025-11-131-1/+1
| | | | | | | | | | | | It seems this config is for tokio-console and not the RPC.
| * | arti: Warning when opentelemetry config is set but not build with featurenield2025-11-131-0/+16
| | |
* | | Merge branch 'http_xsprobe' into 'main'Nick Mathewson2025-11-131-1/+142
|\ \ \ | | | | | | | | | | | | | | | | Validate Host header for non-CONNECT requests to HTTP CONNECT port See merge request tpo/core/arti!3429
| * | | http_connect: prevent tests from colliding on directoriesNick Mathewson2025-11-131-5/+16
| | | |
| * | | http_connect: fix to conform to MSRVNick Mathewson2025-11-131-1/+1
| | | |
| * | | http_connect: add a test for Host validation.Nick Mathewson2025-11-131-0/+73
| | | |
| * | | Validate Host header for non-CONNECT requests to HTTP CONNECT portNick Mathewson2025-11-031-1/+58
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This validation makes it harder for an adversarial webpage to probe for the version of arti and its capabilities. See torspec!437.
* | | | Merge branch 'prop368-v4' into 'main'Nick Mathewson2025-11-135-3/+50
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | | | | | | | | | Implement a usage-based timeout for strongly isolated circuits (prop368) Closes #2237 See merge request tpo/core/arti!3430
| * | | Fix compilation without all-features.Nick Mathewson2025-11-121-1/+2
| | | |
| * | | circmgr: Add a timeout setting for long-lived circuits.Nick Mathewson2025-11-122-2/+10
| | | |
| * | | Add a notion of isolation strong enough to enable long-lived circuits.Nick Mathewson2025-11-123-0/+38
| | | | | | | | | | | | | | | | Part of prop368.
* | | | Merge branch 'disable-hidden-service' into 'main'wesleyac2025-11-122-5/+36
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | arti/arti-client/tor-hsservice: Support disabling onion services in the config Closes #2133 See merge request tpo/core/arti!3253
| * | | arti(-client)/tor-hsservice: return None for disabled servicehashcatHitman2025-10-161-9/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There is no longer a hard error anywhere for trying to launch a service which is disabled in the config. Instead, it always means returning `Ok(None)`. The axum and hyper examples were updated again as a consequence. Signed-off-by: hashcatHitman <[email protected]>
| * | | arti/tor-hsservice: don't warn on autostarthashcatHitman2025-10-162-9/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | The "enabled" config option is back to using a regular `bool`. When unset, it defaults to true, and the service runs as if it had been set. Signed-off-by: hashcatHitman <[email protected]>
| * | | arti: fix hs "enabled" in example confighashcatHitman2025-10-161-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I didn't realize we had tests that made use of the example config. The pre-commit and pre-push hooks I had didn't trigger them, so my modification to the example config silently got through and caused `cfg::test::onion_services` to fail in CI. The issue was that I had put my example for `onion_services."allium-cepa".enabled` with a default of `true`. The correct default is actually `"auto"`, so I switched it and improved the description of the options. I've fixed my hooks. Which, to be fair, are just the hooks provided in `./maint/hooks/`. Maybe those should be improved? Signed-off-by: hashcatHitman <[email protected]>
| * | | arti/tor-hsservice: warn on service autostarthashcatHitman2025-10-162-2/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | The "enabled" config option now uses `tor_config::BoolOrAuto`. When unset (which defaults to "Auto"), the service will run with a warning. Signed-off-by: hashcatHitman <[email protected]>
| * | | arti(-client): graceful service disable in arti onlyhashcatHitman2025-10-161-5/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When a service is disabled in the config, `arti::onion_proxy::Proxy` handles it gracefully, and `arti_client::client::TorClient::launch_onion_service_with_hsid` and `arti_client::client::TorClient::launch_onion_service` both hard error. The axum and hyper examples were updated again as a consequence. Signed-off-by: hashcatHitman <[email protected]>
| * | | arti/arti-client: add graceful service disablehashcatHitman2025-10-161-5/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Hidden services disabled in the config are now handled more gracefully by arti/arti-client, before the hard error occurs. The axum and hyper examples were updated as a consequence. Signed-off-by: hashcatHitman <[email protected]>
| * | | arti: add "enabled" config to the example confighashcatHitman2025-10-161-0/+4
| | | | | | | | | | | | | | | | Signed-off-by: hashcatHitman <[email protected]>
* | | | arti: better error when tokio-console in cfg but feature is absent.Nick Mathewson2025-11-061-3/+27
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the pattern we used elsewhere with the "rpc" option. IMO, this kind of thing is another argument in favor if arti#1704 (redoing config types using derive-deftly.)
* | | | arti: Experimental support for tokio-consoleNick Mathewson2025-11-063-0/+60
| | | | | | | | | | | | | | | | | | | | | | | | This is controlled by a new option, `logging.tokio_console.enabled`. It requires building with `--cfg tokio_unstable`. See documentation and comments for more information.
* | | | Fix name of clippy lint to unchecked_time_subtraction (2)Ian Jackson2025-11-0610-10/+10
| | | | | | | | | | | | | | | | Run maint/add_warning
* | | | all: replace all uses of `futures::task::SpawnExt` with `tor_rtcompat::SpawnExt`Steven Engler2025-11-047-9/+9
| |_|/ |/| |
* | | Replace copy_interactive with futures-copy.Nick Mathewson2025-10-303-115/+34
| |/ |/| | | | | | | | | | | | | This change lets us avoid spawning extra tasks (due to one-direction nature of copy_interactive), and avoid some lock contention (due to use of AsyncReadExt::split). Addresses part of #786.
* | Merge branch 'remove_socks' into 'main'Nick Mathewson2025-10-284-10/+30
|\ \ | | | | | | | | | | | | | | | | | | arti: Revise strings that implied that we were a SOCKS-only proxy. Closes #2225 See merge request tpo/core/arti!3398
| * | arti: explain APP_STREAM_BUF_LEN is what it is.Nick Mathewson2025-10-281-0/+6
| | |
| * | arti: Revise strings that implied that we were a SOCKS-only proxy.Nick Mathewson2025-10-284-7/+14
| | | | | | | | | | | | Closes #2225
| * | arti: Stop using SOCKS_BUF_LEN for non-SOCKS proxies.Nick Mathewson2025-10-281-3/+10
| | |
* | | arti: Remove now-needless cognitive_complexity exceptionsNick Mathewson2025-10-282-2/+0
|/ / | | | | | | | | | | | | Apparently the http_connect refactoring made these no longer trigger. Closes #2226
* | http_connect: Remove (most) X- prefixes.Nick Mathewson2025-10-282-32/+44
| | | | | | | | | | | | We can't remove them all, since X-Tor-Stream-Isolation is recognized by C-Tor. I've added a non-deprecated Tor-Stream-Isolation that works indepenently.