summaryrefslogtreecommitdiff
path: root/crates/arti
Commit message (Collapse)AuthorAgeFilesLines
* Bump crate versions in preparation for Arti 1.0.0 release.Nick Mathewson2022-09-011-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Because we want to work more on ensuring that our semver stability story is solid, we are _not_ bumping arti-client to 1.0.0 right now. Here are the bumps we _are_ doing. Crates with "minor" bumps have had API breaks; crates with "patch" bumps have had new APIs added. Note that `tor-congestion` is not bumped here: it's a new crate, and hasn't been published before. ``` tor-basic-utils minor fs-mistrust minor tor-config minor tor-rtcompat minor tor-rtmock minor tor-llcrypto patch tor-bytes patch tor-linkspec minor tor-cell minor tor-proto minor tor-netdoc patch tor-netdir minor tor-persist patch tor-chanmgr minor tor-guardmgr minor tor-circmgr minor tor-dirmgr minor arti-client minor arti-hyper minor arti major arti-bench minor arti-testing minor ```
* Add test warning exceptions to arti::cfg::testNick Mathewson2022-08-311-0/+7
|
* Update README.md files with "readmes" tool.Nick Mathewson2022-08-311-1/+12
|
* Mark a few APIs as experimental in docs.Nick Mathewson2022-08-302-0/+2
| | | | | | | | For example, see https://tpo.pages.torproject.net/core/doc/rust/arti/fn.run.html : this isn't labeled as `experimental-api`, but it should be. These APIs were found by poking around in the `arti` crate.
* Fix Tests on Windows in Configuration Subsystem.Alexander Færøy2022-08-301-6/+30
| | | | | | | | | | | | | | | | This patch changes our `default_config()` test in `arti/src/cfg.rs` such that we can define a number of known unrecognized options on different platforms. We mark the two keys "storage.permissions.trust_group" and "storage.permissions.trust_user" as unknown on the Windows platform as such features is not available using the ordinary Unix UID concept. This patch also publicly exposes the `tor_config::load::DisfavouredKey` and `tor_config::load::PathEntry` types and marks them as non-exhaustive. See: tpo/core/arti#450.
* small refactoring to reduce duplicaiton of config reloadingtrinity-1686a2022-08-272-42/+44
|
* connect SIGHUP to watch_cfgtrinity-1686a2022-08-272-62/+90
|
* WIP: listen for sighups and reconfigure?Nick Mathewson2022-08-261-0/+13
|
* Add functionality to listen for SIGHUPs.Nick Mathewson2022-08-262-1/+30
|
* Merge branch 'safelog_more' into 'main'Ian Jackson2022-08-262-5/+9
|\ | | | | | | | | Apply safelog to more of the things that we log See merge request tpo/core/arti!693
| * arti: Adjust severity on per-socks-request log.Nick Mathewson2022-08-252-5/+9
| | | | | | | | | | Also, note why we aren't hiding the addrs that we're listening on here.
* | Bump toml dependencyIan Jackson2022-08-251-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | We need 60b874308e6792a73cc00517a60bbef60a12e3cc Mixed type arrays (#358) for a test case in tor-config. While we're here, drop the dupe entry in tor-config. (In principle we could make this increase only in tor-config's dev-dependencies, but that seems unnecessarily fiddly.)
* | tor-config Listen: Rename localhost_port_legacy (from _deprecated)Ian Jackson2022-08-251-2/+2
| | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/602#note_2830847
* | arti cfg: Provide comprehensive tests for port listeningIan Jackson2022-08-251-1/+116
| |
* | arti: cfg: Rename `*_port` to `*_listen` and change the typeIan Jackson2022-08-254-13/+78
| | | | | | | | | | | | | | This commit largely follows the example for resolve_alternative_specs. The difference is that there are two fields, so we use a macro to avoid recapitulating the field names.
* | tor-config: Support tracking deprecated config keysIan Jackson2022-08-251-5/+11
| |
* | tor-config: Introduce ResolutionResultsIan Jackson2022-08-251-6/+7
| | | | | | | | This will allow us to handle new kinds of warnigns etc.
* | Merge branch 'default_log_severity' into 'main'Nick Mathewson2022-08-253-3/+3
|\ \ | | | | | | | | | | | | arti: Raise the default console log severity to "info" See merge request tpo/core/arti!692
| * | arti: Raise the default console log severity to "info"Nick Mathewson2022-08-253-3/+3
| |/ | | | | | | | | Previously we logged at "debug", but that's not meant to user-facing.
* | tor-config source: just ConfigurationSource, not FoundConfigFileIan Jackson2022-08-251-8/+7
| | | | | | | | | | FoundConfigFile existed to hide something that ConfigurationSource now exposes.
* | config watch: Fix and reduce debounce intervalIan Jackson2022-08-251-3/+3
| | | | | | | | | | | | | | | | The parameter to FileWatcher::new is not a polling time fallback; it is a "debounce time". Events are always delayed by at least this much. 10s is much too long for this. 1s is more appropriate.
* | config sources: Read arti.d as well as arti.tomlIan Jackson2022-08-251-3/+3
| | | | | | | | Fixes #474 aka #271
* | config sources: Supporting reading directoriesIan Jackson2022-08-251-3/+5
| |
* | config sources: Introduce scan() and FoundConfigFilesIan Jackson2022-08-251-11/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | We're going to need to do config file reading in two phases. Right now this isn't actually necessary, because the set of files is fixed since we don't support dynamically scanning directories. But the new API will be needed in a moment. Code motion and API changes, but no overall functional change. Review with `git show -b` may be helpful. The new API also provides for dealing with directories, but right now that doesn't happen.
* | config watch: Provide watch_dirIan Jackson2022-08-251-8/+37
| | | | | | | | | | | | No call site just yet; that will come shortly. This requires a bit of reorganisation first.
* | config watch: Re-establish watcher on each iterationIan Jackson2022-08-251-2/+14
| | | | | | | | This is going to be needed in a moment.
* | config watch: Rescan once on startupIan Jackson2022-08-251-3/+8
| | | | | | | | | | | | | | That way if the config changes after we read it initially, but before we set up the watcher, we will still pick it up. Fixes #544
* | config watch: Break out prepare_watcherIan Jackson2022-08-251-5/+10
| | | | | | | | This is going to become more complicated, and gain another call site.
* | config watch: Make the mpsc channel part of FileWatcherIan Jackson2022-08-251-8/+15
| | | | | | | | | | | | | | | | | | | | The previous approach (inherited from the API of notify) was kind of odd. Soon we are going to want to be able to drop the watcher and replace it. That really wants the same object to contain all the things that ought to be dropped together. (notify's watchers stop generating events and give EOF on the channel, when dropped.)
* | config: Do process hardening on reconfigure even if not watchingIan Jackson2022-08-252-5/+5
|/ | | | | | | These blocks were in the wrong order. Previously, if you tried to turn on process hardening in the config and then reloaded rather than restarting, it wouldn't take effect.
* fix nightly lintstrinity-1686a2022-08-241-0/+1
|
* fix test failing due to missing allow_running_as_roottrinity-1686a2022-08-241-1/+1
|
* enable doc_auto_cfg feature on every crate when documenting for docs.rstrinity-1686a2022-08-242-0/+4
|
* Merge branch 'no_root' into 'main'Nick Mathewson2022-08-245-0/+43
|\ | | | | | | | | arti: Do not allow running as root. See merge request tpo/core/arti!688
| * arti: Do not allow running as root.Nick Mathewson2022-08-245-0/+43
| | | | | | | | | | | | This can be overridden with `application.allow_running_as_root`. Part of #523.
* | arti cfg: Write down future plansIan Jackson2022-08-231-0/+13
| | | | | | | | | | Mostly cribbed from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/684#note_2829937
* | arti cfg: Test parsing of the oldest config file we still supportIan Jackson2022-08-222-8/+310
| |
* | arti cfg: Fix docs about ARTI_EXAMPLE_CONFIGIan Jackson2022-08-221-1/+4
|/ | | | The defaults are now
* channel: Introduce padding configIan Jackson2022-08-161-1/+13
| | | | | Nothing actually reads this yet, and we also want a client-global default for padding.
* Introduce ChannelConfigIan Jackson2022-08-161-0/+4
| | | | | This commit is just the necessary plumbing. The config is currently empty. We'll add something to it, for padding control, later.
* arti: Add support for process hardeningNick Mathewson2022-08-156-3/+75
| | | | | | | | | | | | | This is a compile-time feature with an associated configuration flag, both enabled by default. When it's turned on, hardening prevents the arti process from dumping core or being attached to by low-privileged processes. (This is a defense-in-depth measure, not an absolute way to prevent attacks. For more information, see [`secmem_proc`](https://docs.rs/secmem-proc/0.1.1/secmem_proc/).) Closes #364.
* Add a few dire warnings about main; make main_main experimental.Nick Mathewson2022-08-111-2/+31
|
* Document more explicitly what "voiding a semver warranty" entailsNick Mathewson2022-08-111-1/+5
| | | | Closes #522.
* arti: `main_main` takes command-line arguments does not call exit()Nick Mathewson2022-08-112-3/+19
|
* arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-119-12/+43
| | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
* arti: Add a feature flag for dns-proxy.Nick Mathewson2022-08-112-3/+14
| | | | | | | It remains on-by-default, so users shouldn't notice a difference, but it may help when we want to save a few bytes of binary size. Closes #532
* Now that versions have bumped, remove semver.md files.Nick Mathewson2022-08-011-2/+0
|
* Bump minor version on crates with deps with breaking changes.Nick Mathewson2022-08-011-1/+1
| | | | | | | | | | | | | | | This performs the transitive closure of the last operation: everything that depends on a crate with a breaking change gets the version which it depends on bumped. ``` cargo set-version -p tor-proto --bump minor cargo set-version -p tor-netdoc --bump minor cargo set-version -p arti-hyper --bump minor cargo set-version -p arti-bench --bump minor cargo set-version -p arti-testing --bump minor cargo set-version -p tor-config --bump minor ```
* Bump minor versions on all crates that have had breaking changes.Nick Mathewson2022-08-011-4/+4
| | | | | | | | | | | | | | | | | | | | | | Done with these commands: ``` cargo set-version -p fs-mistrust --bump minor cargo set-version -p tor-bytes --bump minor cargo set-version -p tor-socksproto --bump minor cargo set-version -p tor-cert --bump minor cargo set-version -p tor-linkspec --bump minor cargo set-version -p tor-cell --bump minor cargo set-version -p tor-netdir --bump minor cargo set-version -p tor-persist --bump minor cargo set-version -p tor-chanmgr --bump minor cargo set-version -p tor-guardmgr --bump minor cargo set-version -p tor-circmgr --bump minor cargo set-version -p tor-dirclient --bump minor cargo set-version -p tor-dirmgr --bump minor cargo set-version -p arti-client --bump minor cargo set-version -p arti --bump minor ```
* Rename download_tolerance to directory_toleranceNick Mathewson2022-07-222-2/+6
| | | | Closes #503.