summaryrefslogtreecommitdiff
path: root/crates/arti
Commit message (Collapse)AuthorAgeFilesLines
...
* | config: Do process hardening on reconfigure even if not watchingIan Jackson2022-08-252-5/+5
|/ | | | | | | These blocks were in the wrong order. Previously, if you tried to turn on process hardening in the config and then reloaded rather than restarting, it wouldn't take effect.
* fix nightly lintstrinity-1686a2022-08-241-0/+1
|
* fix test failing due to missing allow_running_as_roottrinity-1686a2022-08-241-1/+1
|
* enable doc_auto_cfg feature on every crate when documenting for docs.rstrinity-1686a2022-08-242-0/+4
|
* Merge branch 'no_root' into 'main'Nick Mathewson2022-08-245-0/+43
|\ | | | | | | | | arti: Do not allow running as root. See merge request tpo/core/arti!688
| * arti: Do not allow running as root.Nick Mathewson2022-08-245-0/+43
| | | | | | | | | | | | This can be overridden with `application.allow_running_as_root`. Part of #523.
* | arti cfg: Write down future plansIan Jackson2022-08-231-0/+13
| | | | | | | | | | Mostly cribbed from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/684#note_2829937
* | arti cfg: Test parsing of the oldest config file we still supportIan Jackson2022-08-222-8/+310
| |
* | arti cfg: Fix docs about ARTI_EXAMPLE_CONFIGIan Jackson2022-08-221-1/+4
|/ | | | The defaults are now
* channel: Introduce padding configIan Jackson2022-08-161-1/+13
| | | | | Nothing actually reads this yet, and we also want a client-global default for padding.
* Introduce ChannelConfigIan Jackson2022-08-161-0/+4
| | | | | This commit is just the necessary plumbing. The config is currently empty. We'll add something to it, for padding control, later.
* arti: Add support for process hardeningNick Mathewson2022-08-156-3/+75
| | | | | | | | | | | | | This is a compile-time feature with an associated configuration flag, both enabled by default. When it's turned on, hardening prevents the arti process from dumping core or being attached to by low-privileged processes. (This is a defense-in-depth measure, not an absolute way to prevent attacks. For more information, see [`secmem_proc`](https://docs.rs/secmem-proc/0.1.1/secmem_proc/).) Closes #364.
* Add a few dire warnings about main; make main_main experimental.Nick Mathewson2022-08-111-2/+31
|
* Document more explicitly what "voiding a semver warranty" entailsNick Mathewson2022-08-111-1/+5
| | | | Closes #522.
* arti: `main_main` takes command-line arguments does not call exit()Nick Mathewson2022-08-112-3/+19
|
* arti: Move most public APIs behind `experimental-api`.Nick Mathewson2022-08-119-12/+43
| | | | | | | | | | | | | | | | | The remaining unconditionally public APIs are those related to our configuration objects, and the main_main() API. The rationale for making main_main() public is to have an actual entry point. The rationale for making the config APIs public is: 1. We really do intend for others to be able to read our configuration files using this API. 2. The structure of our configuration files is already part of our interface. Closes #530.
* arti: Add a feature flag for dns-proxy.Nick Mathewson2022-08-112-3/+14
| | | | | | | It remains on-by-default, so users shouldn't notice a difference, but it may help when we want to save a few bytes of binary size. Closes #532
* Now that versions have bumped, remove semver.md files.Nick Mathewson2022-08-011-2/+0
|
* Bump minor version on crates with deps with breaking changes.Nick Mathewson2022-08-011-1/+1
| | | | | | | | | | | | | | | This performs the transitive closure of the last operation: everything that depends on a crate with a breaking change gets the version which it depends on bumped. ``` cargo set-version -p tor-proto --bump minor cargo set-version -p tor-netdoc --bump minor cargo set-version -p arti-hyper --bump minor cargo set-version -p arti-bench --bump minor cargo set-version -p arti-testing --bump minor cargo set-version -p tor-config --bump minor ```
* Bump minor versions on all crates that have had breaking changes.Nick Mathewson2022-08-011-4/+4
| | | | | | | | | | | | | | | | | | | | | | Done with these commands: ``` cargo set-version -p fs-mistrust --bump minor cargo set-version -p tor-bytes --bump minor cargo set-version -p tor-socksproto --bump minor cargo set-version -p tor-cert --bump minor cargo set-version -p tor-linkspec --bump minor cargo set-version -p tor-cell --bump minor cargo set-version -p tor-netdir --bump minor cargo set-version -p tor-persist --bump minor cargo set-version -p tor-chanmgr --bump minor cargo set-version -p tor-guardmgr --bump minor cargo set-version -p tor-circmgr --bump minor cargo set-version -p tor-dirclient --bump minor cargo set-version -p tor-dirmgr --bump minor cargo set-version -p arti-client --bump minor cargo set-version -p arti --bump minor ```
* Rename download_tolerance to directory_toleranceNick Mathewson2022-07-222-2/+6
| | | | Closes #503.
* disable-fs-permission-checks: remove variable from help messageJim Newsome2022-07-191-1/+0
| | | | | This option doesn't take an argument. This change drops the argument from the `--help` message.
* Merge branch 'mistrust-envvar' into 'main'Nick Mathewson2022-07-192-26/+18
|\ | | | | | | | | | | | | Move environment-variable checking into fs-mistrust Closes #483 See merge request tpo/core/arti!630
| * Arti: Use synthetic argument to implement --disable-fs-permission-checksNick Mathewson2022-07-192-22/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | Now that configuring the environment variables related to fs permissions works properly, we don't need to use the "override" feature any more: we can just add the option to the configuration when appropriate. With this design, `--disable-fs-permission-checks` is now mostly an alias for `--option storage.permissions.dangerously_trust_everyone=true` Enabled by #483.
| * Move responsibility for disable-fs-mistrust envvar.Nick Mathewson2022-07-191-4/+6
| | | | | | | | | | | | | | The variable is now handled when building the configuration, and no longer needs to be special-cased. Closes #483.
* | socksproto: Use fallible writers.Nick Mathewson2022-07-111-10/+20
|/ | | | Also, make private a function that had formerly been `pub`.
* Remove semver.md files now that 0.5.0 is outNick Mathewson2022-06-241-1/+0
|
* Bump crate and dependency versions.Nick Mathewson2022-06-241-7/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These were done with the following commands: ``` cargo set-version -p tor-basic-utils --bump patch cargo set-version -p fs-mistrust --bump minor cargo set-version -p tor-error --bump patch cargo set-version -p tor-config --bump patch cargo set-version -p tor-units --bump patch cargo set-version -p tor-rtcompat --bump minor cargo set-version -p tor-llcrypto --bump patch cargo set-version -p tor-bytes --bump minor cargo set-version -p tor-socksproto --bump minor cargo set-version -p tor-cert --bump minor cargo set-version -p tor-cell --bump minor cargo set-version -p tor-proto --bump minor cargo set-version -p tor-netdoc --bump patch cargo set-version -p tor-netdir --bump minor cargo set-version -p tor-persist --bump patch cargo set-version -p tor-chanmgr --bump minor cargo set-version -p tor-guardmgr --bump minor cargo set-version -p tor-circmgr --bump patch cargo set-version -p tor-dirclient --bump patch cargo set-version -p tor-dirmgr --bump minor cargo set-version -p arti-client --bump patch cargo set-version -p arti --bump minor cargo set-version -p arti-bench --bump minor cargo set-version -p arti-testing --bump minor ```
* Merge branch 'clippy' into 'main'Ian Jackson2022-06-242-0/+6
|\ | | | | | | | | Fix clippy nightly again See merge request tpo/core/arti!603
| * Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-232-0/+6
| | | | | | | | Update all lint blocks
* | Update README.md files from rustdoc.Nick Mathewson2022-06-241-41/+69
|/
* Updated the warning message providing additional information about the type ↵0x4ndy2022-06-211-2/+1
| | | | of the proxy port.
* Merge branch 'reachable_addrs_v2' into 'main'Nick Mathewson2022-06-171-0/+10
|\ | | | | | | | | | | | | Implement support for reachable_addrs Closes #491 and #93 See merge request tpo/core/arti!583
| * Add a configuration option for reachable_addrsNick Mathewson2022-06-171-0/+10
| | | | | | | | (This doesn't do anything yet.)
* | Merge branch 'config-fix2' into 'main'Nick Mathewson2022-06-162-14/+7
|\ \ | | | | | | | | | | | | Use impl_standard_builder more and remove manual Default/builder impls See merge request tpo/core/arti!594
| * | impl_standard_builder: Use for arti::logging::LogfileConfigIan Jackson2022-06-161-7/+2
| | |
| * | arti: logging config: Replace a manual Debug implIan Jackson2022-06-162-7/+5
| | |
* | | Merge branch 'config-fix' into 'main'Ian Jackson2022-06-162-46/+89
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Config handling and logging fixes Closes #480 See merge request tpo/core/arti!589
| * | | arti: cfg: Remove another needless borrowIan Jackson2022-06-161-1/+1
| | | |
| * | | arti cfg tests: Remove a redundant line that shadows an earlier bindingIan Jackson2022-06-161-1/+0
| | | | | | | | | | | | | | | | | | | | Prompted by review https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/589#note_2813596
| * | | Fix grammar erroreta2022-06-161-1/+1
| | | |
| * | | arti: Enable some pre-config loggingIan Jackson2022-06-161-2/+16
| | | |
| * | | arti: Introduce closure which will be used for pre-config loggingIan Jackson2022-06-161-31/+52
| | | | | | | | | | | | | | | | Right now this is an IEFI and therefore a no-op.
| * | | arti cfg tests: Test that example config works as-isIan Jackson2022-06-161-0/+2
| | | | | | | | | | | | | | | | It contains only sections, but we want to detect when that is a problem!
| * | | arti: cfg tests: Refactor to prepare for new testIan Jackson2022-06-161-16/+23
| |/ / | | | | | | | | | We're going to call this new closure another time.
* | | Merge branch 'main' into 'accel-features'Nick Mathewson2022-06-164-3/+8
|\ \ \ | | |/ | |/| | | | # Conflicts: # crates/arti-client/Cargo.toml
| * | Merge branch 'high-level-features' into 'main'Nick Mathewson2022-06-162-41/+67
| |\ \ | | |/ | |/| | | | | | | | | | | | | Add "full" and "experimental" features to arti, arti-client, and below. Closes #499 See merge request tpo/core/arti!584
| | * Remove "rustls" from "full", for license reasons.Nick Mathewson2022-06-152-2/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | Rustls uses ring, which uses code from BoringSSL, which derived from OpenSSL before OpenSSL changed their license. So ring is currently under 3BSD/SSLEay licenses, which aren't GPL-compatible, which may be a problem for some people. See #493.
| * | config: document semver changeIan Jackson2022-06-101-0/+1
| | |
| * | config: Do not strip_option for journald (and in future)Ian Jackson2022-06-101-1/+1
| | | | | | | | | | | | | | | As per point 1 in https://gitlab.torproject.org/tpo/core/arti/-/issues/488