summaryrefslogtreecommitdiff
path: root/crates/tor-hsservice/src/publish
Commit message (Collapse)AuthorAgeFilesLines
* netdoc, hsservice: Respect maximum descriptor sizesNick Mathewson2025-07-102-4/+14
| | | | | It would be better to take a more sophisticated approach; see #2048.
* hs*: Define some HsDesc errors as _suspicious_.Nick Mathewson2025-07-101-2/+32
| | | | | These errors are suspicious as hsdir inflation attacks, in the context of prop360.
* hs*: Include SourceInfo when making HsDesc requests.Nick Mathewson2025-07-101-2/+12
|
* *: suppress cognitive_complexity warnings from nightlyNick Mathewson2025-05-292-0/+4
| | | | | | | | | | | | | Apparently clippy nightly is better (or worse?) about detecting complex functions than before, so I'm suppressing these warnings where they occur. I have mixed feelings about these warnings: On the plus side, they really do help to detect functions that are twistier than they need to be. On the minus side, they get confused by tracing macros, and the "allows" do pile up. But on the plus side, those "allows" do provide a way to find functions that need to be refactored, and they are never uglier than the functions they decorate.
* tor-hsservice: Refactor PoW error handling.Wesley Aptekar-Cassels2025-05-271-1/+8
| | | | | | This adds a error type for internal errors, and in error cases where we previously panicked, returns a Result instead. The publisher then simply doesn't publish the pow_params line and warns the user.
* tor-hsservice: Initial parts of PowManager.Wesley Aptekar-Cassels2025-05-272-4/+34
| | | | | | | This adds PowManager, as described in doc/dev/notes/service-side-pow.md, hooks it into IptManager and Publisher, and adds code to publish and rotate seeds, and to keep a updated list of Verifier instances for currently active seeds.
* Resolve clippy warnings from 1.83Nick Mathewson2025-05-131-2/+1
| | | | | Now that our MSRV is 1.83, clippy is happy to make more recommendations for us.
* Use an EntropicRng trait to enforce key generation rules.Nick Mathewson2025-03-242-2/+6
| | | | | | | | | | | We want to require that whenever we generate a key that's persistent (stored in KeyMgr), it's going to be made from a stronger-than-usual Rng. This trait helps us enforce that. We also add a FakeEntropicRng struct to use for testing. Note that this turned up a case that we'd missed, which required an internal change in tor-hsservice.
* squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-181-1/+1
| | | | - `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
* tor-rt*: Apply deferred formatting churnIan Jackson2025-03-041-1/+1
| | | | rustfmt.
* tor-rtcompat: Rename BlockOn to ToplevelBlockOnIan Jackson2025-03-041-1/+1
| | | | | | | | | | We're going to distinguish top-level runtime entry, from *re*-entry to an existing executor. It is most convenient to rename this trait first. Documentation of the distinction will come later. (We're going to retain the function name `block_on`, but we want the trait to be more obviously a top-level only thing, though, so we give it a name that will hopefully avoid it peroulating throughout the codebase..)
* Move helpers from tor-hsservice to tor-netdir.Wesley Aptekar-Cassels2024-11-251-2/+5
| | | | | These helpers seem potentially broadly useful, and only really discoverable if they're here.
* tor-hsservice: add clippy allowsSteven Engler2024-11-201-0/+4
|
* update `CfgPath::path` to use a `CfgPathResolver`Steven Engler2024-11-181-2/+2
| | | | | | | | | | | | | | | | This is a big change across multiple crates since there isn't a good way to break it up. This changes the signature of `CfgPath::path` to: ``` pub fn path(&self, path_resolver: &CfgPathResolver) -> Result<PathBuf, CfgPathError> { ``` Making this change means that our global `CfgPathResolver` needs to be stored in the 'arti-client' library instead of `tor-config-path`, and must be passed through to anything that calls `path` to expand the variables.
* tor-hsservice: pass through the `CfgPathResolver`Steven Engler2024-11-181-8/+19
|
* tor-config: removed re-export of `CfgPath`Steven Engler2024-11-041-1/+2
| | | | | Also updated other packages to get `CfgPath` directly from `tor-config-path' instead of 'tor-config'.
* Introduce mpsc_channel_no_memquota and use it in the places it's wantedIan Jackson2024-10-151-1/+2
| | | | | These are the call sites where using this fucntion is correct. (Outside tor-rtmock, which we'll do separately.)
* tor-hsservice: Remove the anonymity setting from the config.Gabriela Moldovan2024-09-121-2/+2
| | | | As mentioned in #727, this is not supported yet.
* Merge branch 'bug_1613' into 'main'gabi-2502024-09-121-1/+1
|\ | | | | | | | | | | | | Bug 1613: Add support for inserting externally generated and removing arbitrary service discovery keys Closes #1613 See merge request tpo/core/arti!2396
| * tor-keymgr: add an overwrite flag to KeyMgr::insert()Morgan2024-09-101-1/+1
| |
* | Merge branch 'publisher-svc-status' into 'main'David Goulet2024-09-102-108/+517
|\ \ | |/ |/| | | | | | | | | tor-hsservice: Improve descriptor publisher status reporting Closes #1216 and #1572 See merge request tpo/core/arti!2397
| * tor-hsservice: Add tests for status changes induced by descriptor uploads.Gabriela Moldovan2024-09-091-1/+185
| |
| * tor-hsservice: Include descriptor upload errors in onion service status.Gabriela Moldovan2024-09-091-9/+17
| |
| * tor-hsservice: Change the error type in Problem::DescriptorUpload.Gabriela Moldovan2024-09-091-1/+17
| | | | | | | | | | | | | | | | We will need to return a list of descriptor upload errors. We can't return a `Vec<RetryError<DescUploadError>>` here because `DescUploadError` is a lower-level error type that can't express that e.g. the upload timed out.
| * tor-hsservice: Remove unused UploadError variant (fmt).Gabriela Moldovan2024-09-091-3/+1
| |
| * tor-hsservice: Remove unused UploadError variant.Gabriela Moldovan2024-09-091-6/+1
| | | | | | | | | | We never return `UploadError::Timeout` (timeouts are represented as `BackoffError::Timeout`).
| * tor-hsservice: Rename UploadStatus to UploadResult.Gabriela Moldovan2024-09-091-4/+4
| | | | | | | | This type is a `Result`, renaming for clarity.
| * tor-hsservice: Fill out the missing descriptor publisher docs.Gabriela Moldovan2024-09-091-7/+62
| | | | | | | | Closes #1216
| * tor-hsservice: Return Bug where possible.Gabriela Moldovan2024-09-091-4/+4
| | | | | | | | | | This makes it clearer that some of these functions are essentially infallible.
| * tor-hsservice: Update docs with new status reporting logic.Gabriela Moldovan2024-09-091-12/+32
| |
| * tor-hsservice: Validate the authorized clients before publishing.Gabriela Moldovan2024-09-092-2/+40
| | | | | | | | | | This enables us to report a "broken" service status if restricted discovery is enabled but the authorized_clients list is empty.
| * tor-hsservice: Set the publisher State based on the upload results.Gabriela Moldovan2024-09-091-29/+106
| | | | | | | | Closes #1572
| * tor-hsservice: Store the upload result in TimePeriodContext.Gabriela Moldovan2024-09-091-2/+33
| | | | | | | | | | | | This will allows us determine the ComponentStatus of the publisher (it'll be either `Running` or `Degraded`, depending on whether the upload failed).
| * tor-hsservice: Don't update the onion svc status when publisher goes idle.Gabriela Moldovan2024-09-091-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | After uploading the descriptor, the publisher transitions into the `Idle` state. This transition happens even if the upload was unsuccessful, so it shouldn't cause the onion service status to become `Running` (because `Running` implies the service is fully reachable, and if the publisher failed to upload the descriptor to some or all HsDirs, that won't necessarily be the case). A future commit will set the publisher's onion svc `State` to `Running`/`Recovering`/`Broken` according to the upload status.
| * tor-hsservice: Add a comment noting where the publisher tests live.Gabriela Moldovan2024-09-091-0/+2
| |
| * tor-hsservice: Replace UploadStatus enum with type alias.Gabriela Moldovan2024-09-091-24/+6
| | | | | | | | This resolves a TODO.
| * tor-hsservice: Store the authorized_clients in the mutable state of the reactor.Gabriela Moldovan2024-09-092-17/+18
| | | | | | | | | | | | Previously, these were stored in the immutable state behind a mutex, but since they're not really immutable (we update them if the config changes), it makes more sense to put them in `State`.
| * tor-hsservice: Move a misplaced TODO.Gabriela Moldovan2024-09-091-1/+1
| | | | | | | | | | | | This TODO was added in !2353 and was supposed to be about reporting a broken/degraded onion service status if the restricted discovery config watcher fails.
* | tor_hsservice use get::<HsIdKey> rather than get::<HsIdKeypair>Adam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-091-4/+3
|/ | | | | | | | | | There are three places where we query the KeyMgr for an `HsIdKeypair` but all we really need is the public part. This commit changes those three callsites to instead use `get::<HsIdKey>`. This relies on the previous commit, which makes sure that a request for an `HsIdKey` will always succeed if the keystore has a `HsIdKeypair` with the same service nickname.
* extract tor_async_utils::oneshot into ::oneshot-fused-workaroundJim Newsome2024-08-281-1/+1
| | | | | | | | | | | | | | Having this in the `tor-async-utils` crate prevents us from doing both of the following without introducing a circular dependency: * using it in `tor-rtmock` (which we currently do, particularly in tests). * using `tor-rtmock` to test things in `tor-async-utils`. We don't do this yet, but it is generally sensible to do so. In particular we want to move the `stream_peak` module there, which is currently tested with `tor-rtmock`. Moving this into its own crate avoids this circular dependency.
* tor-hsservice: Recreate the file watcher on every key_dir change event.Gabriela Moldovan2024-08-271-0/+3
| | | | | | | This ensures that if a directory used as a `key_dir` is moved (e.g. renamed), and then moved back to its original location (the one specified in `key_dirs`), our watcher continues watching the `key_dirs` contents.
* tor-config: Rename watch_file to watch_path.Gabriela Moldovan2024-08-271-2/+2
| | | | `FileWatcher::watch_file` can be used with arbitrary paths.
* tor-hsservice: Make sure we always watch the parents of the key_dirs.Gabriela Moldovan2024-08-271-15/+24
| | | | | This ensures that if a `key_dir` is created after we start watching it (or if it's moved), we are still able to detect changes.
* tor-hsservice: Always recreate the file watcher if the config changes.Gabriela Moldovan2024-08-271-59/+6
| | | | | | While this means we will be recreating the watcher slightly more often than necessary, this new approach is less error-prone than what we had before.
* tor-hsservice: Add a TODO about rethinking publish rate-limiting.Gabriela Moldovan2024-08-211-0/+11
|
* tor-hsservice: Add TODO about updating publisher status on error.Gabriela Moldovan2024-08-211-0/+1
| | | | | This is a general issue with the publisher that will need to be addressed soon.
* tor-hsservice: Update the authorized_clients and watcher when the config ↵Gabriela Moldovan2024-08-211-1/+5
| | | | changes.
* tor-hsservice: Store a FileWatcher in the publisher reactor.Gabriela Moldovan2024-08-211-2/+137
| | | | | This `FileWatcher` is watching the `restricted_discovery.key_dirs` directories for changes.
* tor-hsservice: Schedule descriptor republication whenever the key_dirs ↵Gabriela Moldovan2024-08-211-1/+57
| | | | contents change.
* tor-hsservice: Add helper for reading authorized_clients.Gabriela Moldovan2024-08-211-8/+17
| | | | | This will soon be used in the `key_dirs` change handler, which will re-read the authorized_clients list.