| Commit message (Collapse) | Author | Age | Files | Lines |
| |\
| |
| |
| |
| | |
tor-cell: Assert data length in Data cells
See merge request tpo/core/arti!800
|
| | |
| |
| |
| |
| |
| | |
This commit adds a `debug_assert!` macro into the `new_unchecked()`
function of the Data cell. Beside this, it also fixes a misleading
comment regarding that limit.
|
| |\ \
| | |
| | |
| | |
| | | |
tor-cell: Consistent and secure conversion to u16
See merge request tpo/core/arti!803
|
| | |/
| |
| |
| |
| |
| |
| | |
This commit improves the overflow protection of one call to
Vec::write_u16(), by replacing the cast conversion from self.sig.len()
with a call to u16::try_from(), like it is already done in the rest of
the accompanying function.
|
| |\ \
| | |
| | |
| | |
| | | |
tor-cell: Fix typos in msg.rs
See merge request tpo/core/arti!802
|
| | |/ |
|
| |/
|
|
|
| |
This commit adds a comment explaining composition of the magic number
"11" found in the assignment of the Data::MAXLEN constant.
|
| |\
| |
| |
| |
| | |
Implement Introduce2 tor cell
See merge request tpo/core/arti!736
|
| | |
| |
| |
| |
| | |
Reuse the same Introduce inner body implementation
of Introduce1.
|
| |/
|
|
|
|
|
|
|
|
|
|
| |
As a matter of good crypto practice, we shouldn't use
short-circuiting checks to compare keys or key-like objects, since
the amount of time taken by those checks can leak information about
their inputs.
I don't think it's actually _necessary_ to use a constant-time
operation in this case, but let's establish the precedent.
This is a follow-up to !724.
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
It was based on the old `Writeable` API.
|
| |\
| |
| |
| |
| | |
Implement ESTABLISH_INTRO relay cell
See merge request tpo/core/arti!626
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Revise tor_bytes::Writer::write to return a Result.
Closes #513
See merge request tpo/core/arti!623
|
| | | |
| | |
| | |
| | | |
Also, stop using "expect" and "assert!" to check for errors.
|
| | | | |
|
| | | | |
|
| | |/
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This comprises four renames:
```
write_onto -> write_onto_infallible
write_into -> write_into_infallible
write -> write_infallible
writer_and_consume -> write_and_consume_infallible.
```
The rest of this branch will be concerned with replacing these
`_infallible` methods with ones that return a `Result`. This is
part of #513.
|
| |/
|
|
| |
Apropos clippy complaint.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This implements a higher-level API for the ntor v3 handshake, in line
with that exposed by the ntor handshake. It does not, however, use the
existing `ClientHandshake` trait, due to fundamental differences in the
handshakes (namely, that the v3 handshake can include some additional
extra extension data).
Currently, the higher-level API assumes circuit extension, and copies
the (undocumented!) magic verification string from c-tor that indicates
this usage.
A rudimentary set of functions for serializing and deserializing
extensions to be sent with the handshake is also included, implementing
the protocol in proposal 332 § A.2. Currently, it only implements the
congestion control extensions specified in proposal 324 § 10.3.
part of arti#88
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
| |
This eliminates the possibility of writing the bug of failing to call
`should_be_exhausted`.
As per this discussion
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/572#note_2811464
Fixes #498
|
| |
|
|
|
| |
This does away entirely with `wire_addr_len`, which recapitulates the
length calculation.
|
| |\
| |
| |
| |
| | |
return nodata instead of servfail in some instances
See merge request tpo/core/arti!564
|
| | | |
|
| | | |
|
| |/ |
|
| |
|
|
| |
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
After changes to the prop339, the domain name in an Address can only be
255 bytes max and can NOT contain nul byte(s).
Unit tests had to be modified to accept this change:
- Centralise msg_ip_address
- Add currently-passing tests for address length
- Test counted address length longer than type wants
Related to #463
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
| |
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
|
|
| |
Related to #463
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
|
|
|
|
| |
Decoding and encoding of the DATAGRAM cell from proposal 339.
Related to #463.
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
|
|
| |
Decoding and encoding implemented according to proposal 339.
Related to #463
|
| |
|
|
|
|
|
|
|
| |
Decoding and encoding is implemented according to proposal 339
specifications.
Related to #463
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
|
| |
This does involve unwrap, but of course that can't fail unless the
formats fail, which would already panic (that's implied by format!).
|
| |
|
|
|
| |
Remove all `use` statements for `TryFrom` and `TryInto`. These are
now redundant in Rust 2021.
|
| | |
|
| |
|
|
| |
Closes #360.
|
| |
|
|
|
|
|
|
|
|
| |
In one of the two places, nightly no longer warns. In the other
place, it's fine for nightly to warn: I just fixed the code to take
a slice instead.
Partial revert of 856aca879151c622512bc4b15c6307808fc83e82.
Resolves part of #310.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
| |
It makes sense to put the method for human-readable strings onto the
type itself, so that we can format these whenever they occur.
I'm choosing the "human_str" method name here, since caret-generated
types already have a to_str. I was thinking about using Display,
but caret types already implement that.
I've also moved the message from "warn!" to "debug!", since these
aren't necessarily a problem condition.
|
| | |
|
| | |
|
| |
|
|
|
|
| |
We should never get one of these unless we have opted in to get it.
(This behavior is the same as C tor.)
|