summaryrefslogtreecommitdiff
path: root/crates/tor-hsservice/src/svc
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'hss-notes' into 'main'Ian Jackson2023-11-301-0/+12
|\ | | | | | | | | hssvc-ipt-algorithms.md: Move and fix up some text See merge request tpo/core/arti!1777
| * tor-hsclient: ipt_establisher: Fix a broken rustdoc linkIan Jackson2023-11-301-1/+1
| | | | | | | | | | | | This rune RUSTDOCFLAGS="-Dwarnings --cfg docsrs" nailing-cargo +nightly doc --all-features --document-private-items --no-deps is clean now.
| * hssvc-ipt-algorithms.md: Move some text to ipt_mgrIan Jackson2023-11-291-0/+4
| | | | | | | | | | This is describing the detailed algorithm in idempotently_progress_things_now. Move it there (and add an xref).
| * hssvc-ipt-algorithms.md: Delete rendundant textIan Jackson2023-11-291-0/+8
| | | | | | | | | | | | | | | | This is describing our data structures and IPT states. But we have this documented elsewhere, largely. There are a few sentences here that can usefully be replaced with a bit of extra text in the data structure docs.
* | Remove RngCompatExt.Nick Mathewson2023-11-292-5/+3
| | | | | | | | | | | | | | | | | | | | This code was needed with the old version of dalek-cryptography, which wasn't compatible with up-to-date versions of the `rand` crate(s). But now that we've upgraded, we can drop this. (We could have left it around and deprecated it, but we are already making a breaking change to tor-llcrypto by upgrading dalek-cryptography.)
* | Convert to the latest versions of dalek-cryptographyNick Mathewson2023-11-294-11/+10
|/ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The main changes that we have to adjust for are as follows: * In x25519-dalek: * `StaticSecret` is now behind a feature. * `StaticSecret::new` is deprecated in favor of `StaticSecret::random_from_rng`. * StaticSecret no longer does its own clamping. * In ed25519-dalek: * `SecretKey` has (in effect) been renamed to `SigningKey`. The name `SecretKey` is now an alias for `[u8; 32]`. * `SigningKey` is effectively a keypair, since it contains a public key as well. * `PublicKey` has been renamed to `VerifyingKey`. * The functions to extract a signing key and verifying key have been renamed as you might expect. * `ExpandedSecretKey` has been moved to `hasmat` and no longer implements `sign`. * `ExpanededSecretKey` now has as its elements a scalar and a hash prefix. * Various functions that took `&[u8]` now take `&[u8; N]`. * We no longer need a wrapper for older versions of rand. There is a single test in tor-keymgr that does not pass. I've marked it as ignore for now, in hopes that @gabi-250 can help me figure it out. This closes #808. There are several changes I want to make before we merge, however. They are marked with TODO DALEK.
* Merge branch 'keymgr-derive-builder' into 'main'gabi-2502023-11-281-2/+5
|\ | | | | | | | | | | | | tor-keymgr: Derive Builder for KeyMgr. Closes #1114 See merge request tpo/core/arti!1760
| * tor-keymgr: Derive Builder for KeyMgr (fmt).Gabriela Moldovan2023-11-271-1/+4
| |
| * tor-keymgr: Derive Builder for KeyMgr.Gabriela Moldovan2023-11-271-2/+2
| | | | | | | | | | | | | | `KeyMgr` is soon going to have more fields, so now is a good time to derive `Builder` for it. Closes #1114
* | Merge branch 'hss-debug-serde' into 'main'Ian Jackson2023-11-281-0/+6
|\ \ | | | | | | | | | | | | tor-hsservice: improve Debug and serde See merge request tpo/core/arti!1765
| * | tor-hsservice: derive Debug for IptParametersIan Jackson2023-11-271-0/+6
| |/
* | Merge branch 'persist-prefix' into 'main'Ian Jackson2023-11-282-7/+5
|\ \ | | | | | | | | | | | | HSS IPT persistence - preparatory work See merge request tpo/core/arti!1755
| * | tor-hsservice: ipt_set: Change last_descriptor_expiry_including_slopIan Jackson2023-11-271-1/+0
| | | | | | | | | | | | Prepare for persistence.
| * | tor-hsservice: ipt_set: Make note_publication_attempt a method on PublishIptSetIan Jackson2023-11-271-1/+1
| | | | | | | | | | | | | | | We're going to move the last_descriptor_expiry_including_slop data out of IptSet.
| * | tor-hsservice: ipt_set: Make PublishIptSet a structIan Jackson2023-11-272-5/+4
| | | | | | | | | | | | | | | We're going to add another field here. No functional change, just much churn.
| * | tor-hsservice: ipt_set: Make initial state in the constructorIan Jackson2023-11-271-1/+1
| |/ | | | | | | | | | | | | | | This struct is going to be responsible for loading and storing some persistent state, so it makes sense for it to handle initialisation. This also reduces duplication.
* | Merge branch 'keymgr-errors' into 'main'gabi-2502023-11-271-2/+2
|\ \ | |/ |/| | | | | | | | | tor-keymgr: Add a top-level Error enum Closes #1113 See merge request tpo/core/arti!1751
| * tor-keymgr: Add a top-level error type.Gabriela Moldovan2023-11-211-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the `tor_keymgr::Error` type was `Box<dyn KeystoreError>`. This forced us to impl `KeystoreError` for any error returned by the keymgr (including those that were not coming from a `Keystore` impl). Now, `tor_keymgr::Error` is an non-exhaustive enum and the `Box<dyn KeystoreError>` opaque error type is only returned from `Keystore` impls The reason we're keeping the `dyn KeystoreError` error type is because it enables `Keystore` implementors to use their own error types. Without it, they would have to choose from our (closed) set of error variants, which may not be suitable for their keystore. See #901.
* | HSS publisher error: lack of netdir: clarify messagegabi-2502023-11-201-1/+1
| |
* | HSS publisher: do not crash reactor if netdir unavailableIan Jackson2023-11-201-7/+19
| | | | | | | | | | | | | | It might come back. This introduces a new bug relating to logging, but it does abolish one of the variants of ReactorError.
* | HSS errors: expose and sort out NetdirProviderShutdown error type (fmt)Ian Jackson2023-11-201-1/+1
| | | | | | | | IHNI why rustfmt wants to do this *now*
* | HSS errors: expose and sort out NetdirProviderShutdown error typeIan Jackson2023-11-202-2/+14
| | | | | | | | | | | | We're going have it in an variant in FatalError. Also make it impl HasKind and have IptError delegate to that.
* | HSS publisher errors: Declare that we want to abolish ReactorErrorIan Jackson2023-11-201-2/+23
| | | | | | | | And explain why this isn't just a question of merging it with FatalError.
* | HSS publisher: Remove a redundant debug messageIan Jackson2023-11-201-2/+0
|/ | | | The call to reactor.run() in publish.rs, launch(), calls warn_report.
* Merge branch 'send_dos_params' into 'main'Nick Mathewson2023-11-201-9/+29
|\ | | | | | | | | | | | | HSS: Send DosParams extension to introduction points. Closes #723 See merge request tpo/core/arti!1740
| * Send DosParams conditionally on HsIntro support.Nick Mathewson2023-11-201-4/+11
| | | | | | | | It's available when the HsIntro=5 subprotocol version is present.
| * hss: Take intro_dos extension from configuration and send it.Nick Mathewson2023-11-201-4/+5
| | | | | | | | Closes #723.
| * hss: pipe config watchers into ipt_establish.Nick Mathewson2023-11-201-1/+13
| | | | | | | | | | | | We want the configuration, at least, so that we can see our DoS settings. I expect we'll also want the watcher so that we can see _changes_ in the DoS settings.
* | tor-hsservice: Update MissingHsIdKey docs, remove outdated TODO HSS.Gabriela Moldovan2023-11-201-26/+1
| |
* | tor-hsservice: Rename MissingKey to MissingHsIdKeypair.Gabriela Moldovan2023-11-203-6/+7
|/ | | | | | | | | We only return this error if the identity key is missing from the keystore. This change will also help us abolish the `.role()` method on `KeySpecifier`s (it was only needed for populating the string of a `MissingKey` error).
* Merge branch 'publisher-todo' into 'main'Ian Jackson2023-11-203-5/+3
|\ | | | | | | | | tor-hsservice: Remove and downgrade several TODO HSS See merge request tpo/core/arti!1742
| * tor-hsservice: Downgrade a couple of TODO HSS to TODO.Gabriela Moldovan2023-11-162-2/+2
| | | | | | | | These are definitely blockers.
| * tor-hsservice: Remove TODO HSS that does not make sense.Gabriela Moldovan2023-11-151-2/+0
| | | | | | | | I don't understand what this TODO is about, so let's remove it.
| * tor-hsservice: Downgrade TODO HSS to TODO.Gabriela Moldovan2023-11-151-1/+1
| |
* | tor-keymgr: Remove unnecessary borrow.Gabriela Moldovan2023-11-161-2/+2
| |
* | tor-hsservice: Reuse read_blind_id_keypair when building descriptors.Gabriela Moldovan2023-11-161-14/+6
| | | | | | | | This code was identical to that from `read_blind_id_keypair`.
* | tor-hsservice: Extract read_blind_id_keypair out of Reactor (fmt).Gabriela Moldovan2023-11-161-36/+34
| |
* | tor-hsservice: Extract read_blind_id_keypair out of Reactor.Gabriela Moldovan2023-11-161-12/+10
| | | | | | | | This will soon be used in `publish/descriptor.rs` too.
* | tor-hsservice: Pass the current time as an argument to ↵Gabriela Moldovan2023-11-161-3/+4
| | | | | | | | generate_revision_counter.
* | tor-hsservice: Add note about computing ope_key once per TP.Gabriela Moldovan2023-11-161-0/+2
| |
* | tor-hsservice: Link the the spec instead of referencing section number.Gabriela Moldovan2023-11-161-2/+3
| |
* | tor-hsservice: Remove dead code.Gabriela Moldovan2023-11-161-21/+0
| | | | | | | | | | | | This code is no longer needed: we're now using `generate_revision_counter()` to generate revision counters using the OPE scheme from appendix F.2 rend-spec-v3.
* | tor-hsservice: Generate revision counters using an OPE scheme.Gabriela Moldovan2023-11-161-6/+3
| | | | | | | | | | | | | | The publisher now generates revision counters according to the "encrypted time in period" scheme described in appendix F.2 rend-spec-v3. Part of #1053
* | tor-hsservice: Add function for generating revision counters using OPE scheme.Gabriela Moldovan2023-11-161-2/+106
| | | | | | | | Part of #1053
* | tor-hsservice: Rename period to period_ctx for clarity.Gabriela Moldovan2023-11-161-5/+4
|/ | | | `period` is actually a `TimePeriodContext`, not a `TimePeriod.
* Merge branch 'keymgr-docs2' into 'main'gabi-2502023-11-151-9/+3
|\ | | | | | | | | | | | | tor-keymgr: Minor doc improvements Closes #1066 See merge request tpo/core/arti!1731
| * tor-keymgr: Add missing backticks (fmt).Gabriela Moldovan2023-11-131-1/+1
| |
| * tor-keymgr: Abolish KeyPathPatternSet.Gabriela Moldovan2023-11-131-9/+3
| | | | | | | | | | | | We don't really need it. Closes #1066
* | tor-hsservice: Downgrade TODO HSS to TODO.Gabriela Moldovan2023-11-131-1/+1
| |
* | tor-hsservice: Remove some `allow`s we don't need anymore.Gabriela Moldovan2023-11-131-4/+0
|/