summaryrefslogtreecommitdiff
path: root/crates/tor-hsservice/src
Commit message (Collapse)AuthorAgeFilesLines
* tor-hsservice: Fix time_store test.Wesley Aptekar-Cassels2025-10-011-1/+0
| | | | | | | | This behaviour was changed in humantime 2.3.0. Because they made this breaking change on a minor semver bump, if we want to depend on this behaviour, we would need to lock to a specific version. I don't think this is critical, but I am still looking into where exactly this is used.
* Remove "doc_auto_cfg" incantation from all crates.Nick Mathewson2025-09-291-1/+1
| | | | This feature has been removed from nightly, in favor of doc_cfg.
* hsservice: Remove misleading OnionService note.Gabriela Moldovan2025-09-121-1/+1
| | | | | | | | An `OnionService` represents a not-yet-running service. To launch it, you have to call `OnionService::launch()`, which consumes the `OnionService` and returns `RunningOnionService`, so the part of the docs saying that an `OnionService` "may or may not be running" was somewhat misleading.
* hsservice: Say how a RunningOnionService is constructed.Gabriela Moldovan2025-09-121-1/+3
| | | | | | | This adds some extra docs to `RunningOnionService`. This also removes the TODO about #1228, because that ticket was closed in !1945.
* hsservice: Remove an already-addressed TODO.Gabriela Moldovan2025-09-121-1/+0
| | | | In #1247 we decided to stick with the current names.
* arti: keys: Add `keys check-integrity` CLI toolhjrgrn2025-09-042-42/+76
|
* Merge branch 'the-bell-tolls-for-once_cell' into 'main'wesleyac2025-09-031-7/+1
|\ | | | | | | | | various crates: Updated MSRV TODOs for `once_cell` removal See merge request tpo/core/arti!2953
| * tor-hsservice: Modified MSRV TODO for `once_cell` removalhashcatHitman2025-08-201-7/+1
| | | | | | | | | | | | | | | | | | - Shortened the TODO added in cad6f9054a5ff4d16e953fd4617d3893639deeef in the style of [this maintainer request] for consistency. [this maintainer request]: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2953#note_3197719 Signed-off-by: hashcatHitman <[email protected]>
* | proto: Add a circuit module shared between client and relay impls.Gabriela Moldovan2025-08-281-2/+2
| | | | | | | | | | | | | | This is just code motion (I suggest reviewing with `--color-moved`). This also moves the implementation-agnostic parts from `tor_proto::client::circuit` to a new `tor_proto::circuit` module.
* | hsservice: Move derive_more::From out of internal_prelude.Nick Mathewson2025-08-194-1/+4
|/ | | | | | | | | | | | | | This fixes an error from nightly. The trouble is that with nightly, there's a now a [derive macro for From][issue]. That doesn't cause a conflict when we `use derive_more::From`, but it _does_ cause a conflict when we import `derive_more::From` via `use internal_prelude::*`. So as a solution, we just import `derive_more::From` explicitly. Closes #2124 [issue]: https://github.com/rust-lang/rust/pull/144922
* misc: cleanup now that `_report!` macros support fieldsSteven Engler2025-08-181-1/+1
|
* Merge branch 'relay-reactor-placeholder' into 'main'David Goulet2025-08-184-9/+9
|\ | | | | | | | | proto: Add a placeholder for the relay reactor. See merge request tpo/core/arti!3162
| * proto: Move the `stream` module under `client` (breaking).Gabriela Moldovan2025-08-184-9/+9
| | | | | | | | | | | | | | | | | | | | | | | | The `stream` module is client-specific, for the most part, so I am moving it under `client`. Later on, we will factor out the parts that can be shared with the relay implementation. Note: this is a breaking change as the deleted `stream` module was `pub`. We could've kept the module and reexported from it the public types from `tor_proto::client::stream`, but I think it's better to have this `client` namespacing, because it makes the separation between the client and relay parts clearer.
* | Merge branch 'fix-nightly-warn' into 'main'Nick Mathewson2025-08-181-2/+0
|\ \ | | | | | | | | | | | | Fix clippy errors on nightly See merge request tpo/core/arti!3148
| * | clippy: fix `clippy::duplicated_attributes` warningsSteven Engler2025-08-111-2/+0
| |/ | | | | | | | | | | | | | | | | | | ```text warning: duplicated attribute --> crates/tor-hsservice/src/timeout_track.rs:630:14 | 630 | #![allow(clippy::needless_pass_by_value)] // TODO hoist into standard lint block | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ```
* | tor-hsservice: Move check for enable_pow without hs-pow-full feature.Wesley Aptekar-Cassels2025-08-142-11/+9
| | | | | | | | This also make this check a error rather than a warning.
* | tor-hsservice: Add note about check_solve implementation.Wesley Aptekar-Cassels2025-08-131-0/+3
| |
* | tor-hsservice: Fix error message.Wesley Aptekar-Cassels2025-08-131-1/+1
| |
* | tor-hsservice: Change capping of PoW effort.Wesley Aptekar-Cassels2025-08-131-26/+23
| | | | | | | | | | | | | | | | This caps the PoW effort during sorting, rather than at intake. This allows us to record efforts that are capped in our metrics histogram while only recording metrics after the PoW solve has actually been verified.
* | tor-hsservice: Make some PoW warnings more understandable.Wesley Aptekar-Cassels2025-08-131-3/+10
| |
* | tor-hsservice: Improve error conversion code.Wesley Aptekar-Cassels2025-08-131-16/+8
| |
* | tor-hsservice: Use warn_report for PoW errors.Wesley Aptekar-Cassels2025-08-131-9/+15
| |
* | tor-hsservice: Don't set DegradedReachable status in PowManager.Wesley Aptekar-Cassels2025-08-131-2/+2
| | | | | | | | | | | | | | | | | | | | | | Three is a concern that a DegradedReachable status could overwrite a previous Broken status. A nicer solution could be to add a function to StatusSender that only will change the status to a "more or equally severe" status. However, I am a little dubious about using the DegradedReachable status for PoW in general, since it has a better documented meaning for IPTs than it does for PoW.
* | tor-hsservice: Remove outdated comment.Wesley Aptekar-Cassels2025-08-131-5/+0
| | | | | | | | We do in fact need multiple locations to hold the sender.
* | tor-hsservice: Rename InternalPowError to PowError.Wesley Aptekar-Cassels2025-08-132-13/+13
| |
* | tor-hsservice: Make InternalPowError non_exhaustive.Wesley Aptekar-Cassels2025-08-131-0/+1
| | | | | | | | Now that this is public, this is prudent.
* | tor-hsservice: Make OpenReplayLog error transparent.Wesley Aptekar-Cassels2025-08-131-1/+1
| |
* | tor-hsservice: Fix clippy.Wesley Aptekar-Cassels2025-08-131-3/+2
| |
* | tor-hsservice: Add disable_pow_compilation option.Wesley Aptekar-Cassels2025-08-132-15/+39
| | | | | | | | | | | | I'm not 100% on this being here, it seems like it might want to be a option for all onion services, rather than per-service. However, this is good enough for now.
* | tor-hsservice: Warn when enable_pow is set on a non hs-pow-full build.Wesley Aptekar-Cassels2025-08-132-1/+11
| |
* | tor-hsservice: Remove unimplemented config option.Wesley Aptekar-Cassels2025-08-131-10/+0
| | | | | | | | | | This config option doesn't really apply to Prop 362 (which is what's implemented in Arti), as far as I can tell.
* | tor-hsservice: Remove outdated TODO.Wesley Aptekar-Cassels2025-08-131-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I have thought about this and come to the conclusion (which is what I suspected when I wrote it) that the current behaviour is correct. The attack described is completely impractical (the space of nonces is very large), and checking whether a nonce is a replay is cheaper than verifying a PoW solve, so we want to do that first. Splitting this into something like the following: * Check replay log without updating * Check that solve is valid * Update replay log Would require adding a somewhat dangerous API to the ReplayLog, and requires doing more work per request for something that isn't even a practical attack, AFAICT.
* | tor-hsservice: Add note about not persisting per-PoW-period state.Wesley Aptekar-Cassels2025-08-131-1/+7
| |
* | tor-hsservice: Add metrics support to PoW code.Wesley Aptekar-Cassels2025-08-131-2/+56
| |
* | tor-hsservice: Restore PoW verifier state from disk.Wesley Aptekar-Cassels2025-08-131-2/+25
| | | | | | | | | | We restored the seeds, but doing so is counterproductive if we don't also recreate the verifiers needed to check solves for those seeds.
* | tor-hsservice: Add pow_rend_queue_depth config option.Wesley Aptekar-Cassels2025-08-132-35/+111
| |
* | tor-hsservice: Pass Rng into PoW code where possible.Wesley Aptekar-Cassels2025-08-132-10/+11
| |
* | tor-hsservice: Implement enable_pow option.Wesley Aptekar-Cassels2025-08-136-61/+139
| | | | | | | | | | | | This does not currently allow this option to be changed at runtime, although the code is structured so that allowing it to be changed at runtime won't be too hard. This is tracked by #2082.
* | tor-hsservice: Reenable publisher test in hs-pow-full.Wesley Aptekar-Cassels2025-08-132-12/+3
| | | | | | | | MockExecutor now supports the features needed for this test to work.
* | tor-hsservice: Add PowManager to OnionServiceStatus.Wesley Aptekar-Cassels2025-08-137-35/+130
| |
* | tor-hsservice: Change ReplayLog error type.Wesley Aptekar-Cassels2025-08-135-17/+21
|/ | | | | | | | This disentangles the ReplyLog from the IptManager. This will allow us to make the InternalPowError type more public (in order to use it in the OnionServiceStatus code) without also having to make the CreateIptError type more public.
* Fix warnings and errors from edition 2024.Nick Mathewson2025-08-071-3/+2
| | | | | | | | | | The two main causes of errors were: - Since some of the lifetime rules have changed, we no longer need to do as many "bind a variable and immediately return it" patterns, and so clippy now warns about them. - We needed to adjust the explicit captures (`use<...>`) in a couple of our RPIT instances.
* Switch Cargo.toml files to edition 2024.Nick Mathewson2025-08-0719-75/+85
| | | | | | | | | | | | | | First, run ``` git grep -l "^edition =" | xargs perl -i -pe 's/^edition *=.*/edition = "2024"/;' ``` Second, manually verify that all Cargo.toml files have changed, and nothing else has changed. Third, run cargo fmt again.
* Update code for Edition 2024Nick Mathewson2025-08-073-3/+3
| | | | | | | | | | | | | | | | | | 1. Run cargo fix --edition 2. Selectively revert the "if let"->"match" changes. These changes are meant to protect us from the lifetime changes for "if let" bindings in Rust 2024. But we're not actually relying on the old lifetime rules anywhere, and the match syntax here is quite ugly. 3. Automatically revert `$pat:expr_2021` to `$pat:expr`. (We don't actually want to restrict the expression syntax that our macros accept). Done with `git grep -l expr_2021 | xargs perl -i -pe 's/expr_2021/expr/g;'` 4. Run cargo fmt.
* Merge branch 'msrv-fixes' into 'main'Nick Mathewson2025-08-051-0/+8
|\ | | | | | | | | Resolve a few issues that had been waiting for an MSRV update. See merge request tpo/core/arti!3129
| * hsservice: copy our TODO about eventually replacing once_cell.Nick Mathewson2025-08-051-0/+8
| |
* | tor-hsservice: cargo fmt.Wesley Aptekar-Cassels2025-08-051-1/+1
| |
* | tor-hsservice: Fix clippy lints.Wesley Aptekar-Cassels2025-08-051-2/+2
| |
* | tor-hsservice: Use saturating versions of time math functions.Wesley Aptekar-Cassels2025-08-051-1/+3
| |
* | tor-hsservice: Remove redundant check.Wesley Aptekar-Cassels2025-08-051-7/+1
| |