| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | hss: implement HasKind for several errors. | Nick Mathewson | 2023-09-27 | 1 | -1/+31 |
| | | |||||
| * | tor-proto: Make allow_stream_requests() not return a Result | Nick Mathewson | 2023-09-27 | 1 | -1/+1 |
| | | | | | | | | The function never yields anything but an `Ok`, so we can simplify its type. (Not a stable feature, so no semver entry needed) | ||||
| * | tor-hsservice: Document that time_periods is empty until Reactor::run is called. | Gabriela Moldovan | 2023-09-27 | 1 | -0/+2 |
| | | |||||
| * | tor-hsservice: Remove unused publisher error module. | Gabriela Moldovan | 2023-09-27 | 2 | -45/+0 |
| | | | | | | The `Publisher` now returns a `StartupError` if it fails so launch, so we don't need `PublisherError` anymore. | ||||
| * | tor-hsservice: Make Publisher::launch return a StartupError. | Gabriela Moldovan | 2023-09-27 | 1 | -4/+6 |
| | | | | | | | This simplifies error handling in `OnionService`. Closes #1052 | ||||
| * | tor-hsservice: Make Publisher::launch non-async. | Gabriela Moldovan | 2023-09-27 | 2 | -11/+6 |
| | | | | | | | Fixes #1052 See also the discussion in !1616 | ||||
| * | tor-hsservice: Initialize netdir in Reactor::run. | Gabriela Moldovan | 2023-09-27 | 1 | -16/+44 |
| | | | | | This will enable us to make `Publisher::launch` non-async. | ||||
| * | tor-hsservice: Specify the expiry for the hs_desc_sign_cert. | Gabriela Moldovan | 2023-09-27 | 1 | -3/+4 |
| | | | | | | | | Like the other certificates, the descriptor signing key certificate should have a lifetime of `HS_DESC_CERT_LIFETIME_SEC` seconds (at least, this is what C-Tor does. See build_desc_signing_key_cert() in feature/hs/hs_service.c). | ||||
| * | tor-hsservice: Make HsSvcKeySpecifier borrow the nickname. | Gabriela Moldovan | 2023-09-27 | 1 | -4/+4 |
| | | | | | This helps avoid cloning the nickname unnecessarily. | ||||
| * | tor-hsservice: Use the nickname from the OnionServiceConfig. | Gabriela Moldovan | 2023-09-27 | 1 | -3/+3 |
| | | | | | | The publisher can just read the nickname of the service from its `OnionServiceConfig`. | ||||
| * | Merge branch 'worst-case-end' into 'main' | Nick Mathewson | 2023-09-27 | 1 | -34/+85 |
| |\ | | | | | | | | | or-hsservice: Set a timeout for desc upload tasks. See merge request tpo/core/arti!1623 | ||||
| | * | tor-hsservice: Set a timeout for the upload task. | Gabriela Moldovan | 2023-09-27 | 1 | -19/+48 |
| | | | | | | | | | | | | | | | The IPT manager needs to know how long the publication attempt will take in the worst case, so we add a timeout for the upload task. Part of #1050 | ||||
| | * | tor-hsservice: Explain how note_publication_attempt is not called in the ↵ | Gabriela Moldovan | 2023-09-27 | 1 | -0/+23 |
| | | | | | | | | | right place. | ||||
| | * | tor-hsservice: Fix descriptor reactor lifetime bugs. | Gabriela Moldovan | 2023-09-27 | 1 | -20/+14 |
| | | | | | | | | | | | The problem was that several variables were borrowed in the spawned async block. | ||||
| | * | tor-hsservice: Describe the lifetime bug from Reactor::upload_all. | Gabriela Moldovan | 2023-09-27 | 1 | -0/+5 |
| | | | |||||
| * | | tor-hsservice: Remove unnecessary TODO. | Gabriela Moldovan | 2023-09-26 | 1 | -8/+3 |
| |/ | | | | | `Ipt` _is_ `IntroPointDesc`, so we don't need `build_intro_point_desc()` at all. | ||||
| * | Merge branch 'pad_intro2' into 'main' | Nick Mathewson | 2023-09-25 | 1 | -3/+4 |
| |\ | | | | | | | | | | | | | Accept and transmit padding in introduce2 plaintexts Closes #1031 See merge request tpo/core/arti!1602 | ||||
| | * | HSS: accept padding at the end of an introduce2 encrypted payload | Nick Mathewson | 2023-09-18 | 1 | -3/+4 |
| | | | | | | | | | | | According to rend-spec, we intentionally accept and discard extra bytes here. | ||||
| * | | tor-hsservice: Add TODO about MissingKeys errors. | Gabriela Moldovan | 2023-09-22 | 2 | -0/+31 |
| | | | |||||
| * | | tor-hsservice: Make keys.rs a top-level module. | Gabriela Moldovan | 2023-09-22 | 3 | -76/+2 |
| | | | |||||
| * | | tor-hsservice: Make the caller of build_sign calculate `now()`. | Gabriela Moldovan | 2023-09-22 | 2 | -6/+7 |
| | | | |||||
| * | | tor-hsservice: Add TODO regarding the KeySpecifier::ctor_path()s of service ↵ | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 |
| | | | | | | | | | keys. | ||||
| * | | tor-hsservice: Use "hs" instead of "service" the ArtiPaths of services. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+1 |
| | | | |||||
| * | | tor-hsservice: Add some derives for HsSvcKeySpecifier. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+1 |
| | | | |||||
| * | | tor-hsservice: Remove unnecessary placeholder struct. | Gabriela Moldovan | 2023-09-22 | 1 | -15/+0 |
| | | | | | | | | | | | | | This cert should've an Ed25519Cert anyway (but the descriptor publisher doesn't need to worry about the `intro_{auth, enc}_key_cert` certs because they will be generated internally by `HsDescBuilder`. | ||||
| * | | tor-hsservice: Specify the expiry time for the intro_{auth, enc}_key_cert. | Gabriela Moldovan | 2023-09-22 | 2 | -5/+21 |
| | | | | | | | | | | | The certs are generated internally by `HsDescBuilder`. The publisher just needs to set their expiry. | ||||
| * | | tor-hsservice: Make the publisher load keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -15/+25 |
| | | | |||||
| * | | tor-hsservice: Add a helper for reading service keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+19 |
| | | | |||||
| * | | tor-hsservice: Support storing desc signing keys in the keystore. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+8 |
| | | | |||||
| * | | tor-hsservice: Support storing HsIdKeys in the keystore. | Gabriela Moldovan | 2023-09-22 | 1 | -3/+6 |
| | | | |||||
| * | | tor-hsservice: Add an error variant for key-not-found errors. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 |
| | | | |||||
| * | | tor-hsservice: Add key specifier for blinded_id keypairs. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+56 |
| | | | |||||
| * | | tor-hsservice: Return a ReactorError from build_sign. | Gabriela Moldovan | 2023-09-22 | 1 | -2/+2 |
| | | | | | | | | | | | | | `build_sign` will soon be using the `KeyMgr` to look up keys, so we need to be able to propagate `KeystoreError`s (via the `ReactorError::KeyStore` variant). | ||||
| * | | tor-hsservice: Add an error variant for keystore errors. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+5 |
| | | | |||||
| * | | tor-hsservice: Give the publisher a reference to the key manager. | Gabriela Moldovan | 2023-09-22 | 2 | -8/+32 |
| | | | |||||
| * | | publish: note a possible behavior change on launch(). | Nick Mathewson | 2023-09-21 | 1 | -0/+4 |
| | | | |||||
| * | | hss: adjust members of OnionService type. | Nick Mathewson | 2023-09-21 | 1 | -2/+2 |
| | | | |||||
| * | | tor-hsservice: Update Publisher::new docs. | Gabriela Moldovan | 2023-09-21 | 1 | -1/+3 |
| | | | |||||
| * | | tor-hsservice: Add must_use for Publisher::launch. | Gabriela Moldovan | 2023-09-21 | 1 | -0/+1 |
| | | | |||||
| * | | tor-hsservice: Remove outdated TODO. | Gabriela Moldovan | 2023-09-21 | 1 | -1/+0 |
| | | | |||||
| * | | tor-hsservice: Give the descriptor publisher a separate launch function. | Gabriela Moldovan | 2023-09-21 | 3 | -28/+54 |
| | | | | | | | | | | | | | | | | | | | | | | | This also makes `Publisher::new` synchronous. If `Reactor::new` fails, `Publisher::launch` propagates the error to its caller (to achieve this, I had to give `PublisherError` a new `ReactorLaunch` variant and make `ReactorError` and `UploadError` crate-public). Closes #1042 | ||||
| * | | Merge branch 'intro_rend' into 'main' | Nick Mathewson | 2023-09-21 | 2 | -13/+82 |
| |\ \ | | | | | | | | | | | | | HSS: Route necessary material into RendRequest See merge request tpo/core/arti!1610 | ||||
| | * | | hs_ntor: allow attempting handshake with a set of subcredentials. | Nick Mathewson | 2023-09-20 | 1 | -3/+8 |
| | | | | | | | | | | | | | | | | | | | | | | Since we are using the same introduction point circuits for multiple time periods, we need the ability to provide a set of subcredentials and see which of them acually works. Fortunately, we "only" have to do digest operations here, which are much faster than public key. | ||||
| | * | | hs_ntor: Take our k_hss_ntor keypair explicitly. | Nick Mathewson | 2023-09-20 | 1 | -2/+1 |
| | | | | |||||
| | * | | HSS: Enable RendRequests to be answered. | Nick Mathewson | 2023-09-20 | 2 | -5/+11 |
| | | | | | | | | | | | | | | | | This requires yet more plumbing—this time, of HsCircPool and NetDirProvider. | ||||
| | * | | hss: Minor hack to avoid parameterizing RendRequestContext on Runtime | Nick Mathewson | 2023-09-20 | 1 | -2/+29 |
| | | | | | | | | | | | | | | | | We need to pass around an Arc<HsCircPool<R>>, but doing so directly would force us to make RendRequestContext parameterized on R. | ||||
| | * | | HSS: route most necessary key material to RendRequest | Nick Mathewson | 2023-09-20 | 1 | -7/+39 |
| | |/ | | | | | | | | | | | | | | | | | When we go to answer a RendRequest, we need to have a few objects present. This commit makes sure that they're available at the right places. We also note a significant problem with the need for a Subcredential here. | ||||
| * | | tor-hsservice: Fix compile error, make Publisher use Arc<OnionServiceConfig>. | Gabriela Moldovan | 2023-09-20 | 3 | -9/+10 |
| | | | | | | | | | | | | | | | | | | | This fixes a compile error introduced as a result of merging a couple of conflicting MRs (!1611 and !1604). This also makes the channel the publisher uses for watching for config changes receive `Arc<OnionServiceConfig>` (rather than `OnionServiceConfig`). | ||||
| * | | tor-hsservice: Make the publisher compile again. | Gabriela Moldovan | 2023-09-20 | 2 | -0/+12 |
| | | | | | | | | | | | | | | | The compile error happened because there was a conflict between arti!1603 and arti!1599: * the patch from !1603 uses `OnionServiceConfig::encrypt_descriptor` * !1599 removes `encrypt_descriptor` altogether | ||||
| * | | tor-hsservice: Add TODO regarding DescriptorConfigView. | Gabriela Moldovan | 2023-09-19 | 1 | -0/+4 |
| | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1603#note_2944902 | ||||
