summaryrefslogtreecommitdiff
path: root/crates/tor-hsservice/src/svc
Commit message (Collapse)AuthorAgeFilesLines
* tor-netdoc: Use the new HandshakeType enum to represent CREATE2 HTYPEs.Gabriela Moldovan2023-10-301-1/+2
| | | | | | | | | | | Representing the supported HTYPEs as `HandshakeType`s instead of `u32`s makes it more difficult to pass in wrong/invalid values to `HsDescBuilder::create2_formats`. This also fixes a descriptor publisher bug spotted by @jnewsome, where the advertised CREATE2 HTYPEs included HTYPE `1`, which is actually supposed to be a reserved value. The publisher now only advertises the `NTOR` HTYPE (just like C Tor).
* tor-netdoc: Change return type of create_desc_sign_key_cert.Gabriela Moldovan2023-10-251-2/+5
| | | | | | `Bug` wasn't necessarily the right error type here. Plus, with the new error type adding new errors (i.e. `CertEncodeError` variants), is not a breaking change.
* tor-netdoc: Building a descriptor now only requires the public part of ↵Gabriela Moldovan2023-10-251-1/+1
| | | | blinded_id.
* tor-netdoc: Update HsDesc, HsDescOuter to accept the hs_desc_sign cert as an ↵Gabriela Moldovan2023-10-251-3/+9
| | | | | | | | | | argument. This will enable us to (eventually) the load the descriptor signing key cert from the keystore (as opposed to always recomputing it when building the `HsDesc`). Part of #1048
* hss: remove some more now-moot "allows".Nick Mathewson2023-10-242-4/+0
|
* hss::svc::publish: Remove a no-longer-needed TODO HSS.Nick Mathewson2023-10-241-3/+0
|
* hss::svc::publish: Resolve previously suppressed warnings.Nick Mathewson2023-10-243-13/+8
|
* hss::svc::ipt_establish: Include nickname in messages.Nick Mathewson2023-10-241-2/+4
|
* hss::svc::ipt_establish: Resolve suppressed warnings.Nick Mathewson2023-10-241-6/+6
|
* tor-hsservice: Look up the keypair, not the public key.Gabriela Moldovan2023-10-241-5/+5
| | | | | This particular public key is not stored in the keystore (though maybe it should be).
* tor-hsservice: Make publisher trace! logs less noisy.Gabriela Moldovan2023-10-241-5/+8
| | | | | | We don't need to be logging the entire descriptor for each upload attempt (logging descriptors immediately after they are generated should be sufficient).
* tor-hsservice: Fix misleading trace! log.Gabriela Moldovan2023-10-241-2/+3
| | | | | | The message is supposed to print how many HSDirs the descriptor was uploaded to (previously it was showing the `<success_count>/<failure_count>` which is pretty unintuitive).
* tor-hsservice: Consistently use structured fields to log the nickname/HSDir.Gabriela Moldovan2023-10-241-2/+2
|
* tor-hsservice: Add another debug! for the publisher.Gabriela Moldovan2023-10-241-1/+8
|
* Merge branch 'rustdoc_link_fix' into 'main'Ian Jackson2023-10-231-1/+1
|\ | | | | | | | | Fix rustdoc link warnings/errors. See merge request tpo/core/arti!1690
| * Fix rustdoc link warnings/errors.Nick Mathewson2023-10-201-1/+1
| |
* | tor-hsservice: Handle None IPT update correctly.Gabriela Moldovan2023-10-191-1/+6
| | | | | | | | | | This is not an error, it just means we need to wait until some IPTs are established.
* | tor-hsservice: Generate the blinded keys, if they don't exist.Gabriela Moldovan2023-10-191-12/+32
| |
* | tor-hsservice: Remove unused function.Gabriela Moldovan2023-10-191-36/+2
| | | | | | | | | | | | | | | | | | | | We don't need this helper anymore (we no longer map `None` to `Err(MissingKey)`, because the new get-or-create functions don't return an `Option`). Also, the key lookups are going to look less uniform from now on (because some will be auto-generated with `get_or_generate`, and others with `get_or_generate_with_derived`).
* | tor-hsservice: Auto-generate the keys needed for building the descriptor, if ↵Gabriela Moldovan2023-10-191-9/+33
| | | | | | | | | | | | | | necessary. This auto-generates the blinded identity key and the descriptor signing key (if they are missing).
* | tor-hsservice: Remove outdated TODO.Gabriela Moldovan2023-10-191-2/+0
|/ | | | We're already fetching the descriptor signing key from the keystore.
* tor-hsservice: Print error sources for descriptor upload errorsIan Jackson2023-10-191-1/+3
|
* tor-hsservice: Declare an IPT that fails during Establishing to be FaultyIan Jackson2023-10-191-1/+5
| | | | If we don't do this then the manager won't ever select a replacement.
* tor-hsservice: Do not claim a completely broken IPT wants to retireIan Jackson2023-10-191-1/+6
|
* ipt_establish: Try to make note_open work.Nick Mathewson2023-10-191-6/+28
|
* tor-hsservice: Rename KeyMetadata to KeyDenotator (fmt).Gabriela Moldovan2023-10-191-1/+2
|
* tor-hsservice: Rename KeyMetadata to KeyDenotator.Gabriela Moldovan2023-10-193-14/+14
|
* tor-hsservice: Add some TODOs about error handling.Gabriela Moldovan2023-10-191-0/+5
|
* tor-hsservice: Replace placeholder subcredentials with values from the keystore.Gabriela Moldovan2023-10-191-9/+93
|
* tor-hsservice: Pass the service nickname to IptEstablisher (fmt).Gabriela Moldovan2023-10-191-0/+2
| | | | The nickname is needed for retrieving keys from the keystore.
* tor-hsservice: Give IptManager a KeyMgr.Gabriela Moldovan2023-10-191-0/+2
|
* tor-hsservice: Hoist the key metadata out of HsSvcKeyRole (fmt).Gabriela Moldovan2023-10-193-11/+21
|
* tor-hsservice: Hoist the key metadata out of HsSvcKeyRole.Gabriela Moldovan2023-10-193-23/+50
| | | | | We will need the string rerpresentation (minus the TimePeriod or any other metadata) of `HsSvcKeyRole`s for building `KeyPathPattern`s.
* dirclient: Seal the Requestable trait and hide most of its members.Nick Mathewson2023-10-171-2/+2
| | | | | | | | Since none of these methods were invoked from outside `tor-dirclient` (except for debugging), and since we have had a fair amount of churn on what we actually want them to be, it seems like a good idea to use this trick to hide them. This will let us make other changes to the actual behavior of Requestable in the future.
* tor-hsservice: Narrow some dead code allowsIan Jackson2023-10-163-0/+4
|
* hss: use Arc to avoid copying on k_hss_ntor.Nick Mathewson2023-10-121-4/+4
| | | | (We try to avoid making tons and tons of copies of a secret key.)
* Remove the (fairly bogus) HsNtorServiceInput type.Nick Mathewson2023-10-122-16/+12
| | | | This will let avoid some copying inside our HSS code.
* Merge branch 'bug1051' into 'main'gabi-2502023-10-112-3/+186
|\ | | | | | | | | Implement build_auth_clients() See merge request tpo/core/arti!1642
| * Implement build_auth_clients()Neel Chauhan2023-10-112-3/+186
| |
* | oneshot: Apply deferred rustfmt churnIan Jackson2023-10-111-6/+2
| | | | | | | | cargo fmt, precisely.
* | oneshot: Use veneer in tor-hsserviceIan Jackson2023-10-112-3/+3
|/
* Merge branch 'new-mock-time' into 'main'Nick Mathewson2023-10-051-2/+1
|\ | | | | | | | | Provide and use a SimpleMockTimeProvider See merge request tpo/core/arti!1639
| * tor-rtmock: Abolish deprecated Runtime::advance()Ian Jackson2023-10-031-2/+1
| | | | | | | | | | Now we're making breaking changes anyway, in or mock crate, it is a convenient time to get rid of this.
* | Merge branch 'launch_onion_proxies' into 'main'Nick Mathewson2023-10-051-1/+1
|\ \ | | | | | | | | | | | | arti: Write the minimal code needed to launch onion proxies. See merge request tpo/core/arti!1644
| * | hss: Mark RendCircConnector as Send+SyncNick Mathewson2023-10-041-1/+1
| | | | | | | | | | | | This makes some other futures Send+Sync, which lets us spawn them.
* | | tor-hsservice: Remove unnecessary let binding.Gabriela Moldovan2023-10-041-4/+2
| | |
* | | tor-hsservice: Remove a now-outdated TODO.Gabriela Moldovan2023-10-041-23/+0
| | |
* | | tor-hsservice: Share an IptsPublisherUploadView with each upload task.Gabriela Moldovan2023-10-041-21/+50
|/ / | | | | | | | | | | This enables us to specify a more accurate `worst_case_end` publish time. Closes #1050
* | tor-hsservice: Fix semantic conflict.Gabriela Moldovan2023-10-041-3/+1
| | | | | | | | | | This fixes a compile error that resulted from a semantic conflict between !1634 and !1638.
* | Merge branch 'configure_onion_service' into 'main'Nick Mathewson2023-10-031-1/+1
|\ \ | | | | | | | | | | | | Initial work on top-level onion service configuration See merge request tpo/core/arti!1638