| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |
|
|
|
|
|
|
|
| |
Previously IPT creation could only fail due to key generation failures
or other kinds of internal error, which were very unlikely and treated
as fatal.
But with key persistence, IPT creation will be able to fail due to eg
disk full.
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
| |
Store the IPT manager's data structure to the provided storage
manager.
Keys are not persistent yet! And we must save the publication IPT set
since it can have the only record of IPT publication times.
|
| |
|
|
|
|
|
|
| |
Actually, a SleepProvider.
We will need this for timestamp conversion during loading and saving.
channel() needs it to load. note_publication_attempt needs it for
saving, as does borrow_for_update.
|
| |
|
|
| |
Whitespace changes that make the next commit less noisy.
|
| |
|
|
|
|
|
| |
We're about to make borrow_for_update() take a runtime parameter,
which will be a bit annoying. borrow_for_read() doesn't need one.
Call sites will come on a moment.
|
| | |
|
| |
|
|
| |
We're going to want to reuse this.
|
| |
|
|
|
|
|
| |
And therefore, break out the IPT manager startup, into a
MockedIptManager::start.
We can have it borrow the TempDir, legitimising the _untracked call.
|
| |
|
|
|
|
| |
IPT persistence tests will need to actually save things.
We'll fix up the `.into_untracked()` wrinkle shortly.
|
| |
|
|
|
| |
We're about to need to arrange to have the same runtime earlier, so
run_test needs to accept one from the caller.
|
| | |
|
| |
|
|
| |
This is going to load the state from disk.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Introduce type aliases for the Arc<dyn >. Add Send and Sync bounds.
* Pass the storage manager to ipt_mgr and the per-key handle to ipt_set.
* Store the handles in ipt_mgr::Immutable and IptPublishSet.
* Change the ipt mgr storage key to "hs_ipts_{nickname}". This avoids use
of "_" as a non-separator, and allows the possibility of other
submodules using other storage keys too - and, here, we introduce one.
* Provide a dummy struct for the IPT set state, which is needed to
define the type alias etc. We'll populate that struct later.
|
| | |
|
| |
|
|
|
|
|
|
|
|
| |
If we can't store IPT details, we mustn't publish the corresponding
IPT. But that's not fatal; maybe we can store later. So introduce a
new IptStoreError type, and change the return value from some
functions that are going to be able to fail that way.
This introduces a new TODO HSS: we need the publisher to be able to
retry after such a failure.
|
| |\
| |
| |
| |
| |
| |
| | |
tor-hsservice: Measure last_uploaded from when the upload was initiated.
Closes #1142, #1130, and #1132
See merge request tpo/core/arti!1787
|
| | | |
|
| | |
| |
| |
| | |
Fixes #1132
|
| | |
| |
| |
| | |
This promotes some logs to `debug!` and adds some new trace-level logs.
|
| | |
| |
| |
| |
| |
| |
| | |
I don't think we need to do this (rate-limiting/debouncing the uploads
in upload_all should be sufficient).
Closes #1130
|
| | |
| |
| |
| |
| | |
We're about to use this for retrying failed uploads too (so let's give
it a more generic name).
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
This also fixes an incorrect duration calculation (it should be
`now.duration_since(last_uploaded)` rather than
`last_uploaded.duration_since(now)`).
Fixes #1142
|
| | |
| |
| |
| |
| | |
The existing callers all use create_dir_all but new callers shouldn't
ahve to, eg if they just want a single file.
|
| |/ |
|
| |\
| |
| |
| |
| | |
hssvc-ipt-algorithms.md: Move and fix up some text
See merge request tpo/core/arti!1777
|
| | |
| |
| |
| |
| |
| | |
This rune
RUSTDOCFLAGS="-Dwarnings --cfg docsrs" nailing-cargo +nightly doc --all-features --document-private-items --no-deps
is clean now.
|
| | |
| |
| |
| |
| | |
Fixes a rustdoc warning. This was already wrong in the .md file but
nothing checked it there.
|
| | |
| |
| |
| |
| | |
This is describing the detailed algorithm in
compute_iptsetstatus_publish. Move it there (and add an xref).
|
| | |
| |
| |
| |
| | |
This is describing the detailed algorithm in
idempotently_progress_things_now. Move it there (and add an xref).
|
| | |
| |
| |
| |
| |
| |
| |
| | |
This is describing our data structures and IPT states. But we have
this documented elsewhere, largely.
There are a few sentences here that can usefully be replaced with a
bit of extra text in the data structure docs.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Convert to the latest versions of dalek-cryptography
Closes #808
See merge request tpo/core/arti!1767
|
| | | |
| | |
| | |
| | |
| | | |
With this change, we no longer expose the ExpandedSecretKey
unescorted, which makes it harder to misuse the API.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This code was needed with the old version of dalek-cryptography,
which wasn't compatible with up-to-date versions of the `rand`
crate(s). But now that we've upgraded, we can drop this.
(We could have left it around and deprecated it, but we are already
making a breaking change to tor-llcrypto by upgrading
dalek-cryptography.)
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The main changes that we have to adjust for are as follows:
* In x25519-dalek:
* `StaticSecret` is now behind a feature.
* `StaticSecret::new` is deprecated in favor of
`StaticSecret::random_from_rng`.
* StaticSecret no longer does its own clamping.
* In ed25519-dalek:
* `SecretKey` has (in effect) been renamed to `SigningKey`. The name
`SecretKey` is now an alias for `[u8; 32]`.
* `SigningKey` is effectively a keypair, since it contains a
public key as well.
* `PublicKey` has been renamed to `VerifyingKey`.
* The functions to extract a signing key and verifying key have
been renamed as you might expect.
* `ExpandedSecretKey` has been moved to `hasmat` and no longer
implements `sign`.
* `ExpanededSecretKey` now has as its elements a scalar and a hash
prefix.
* Various functions that took `&[u8]` now take `&[u8; N]`.
* We no longer need a wrapper for older versions of rand.
There is a single test in tor-keymgr that does not pass. I've
marked it as ignore for now, in hopes that @gabi-250 can help me
figure it out.
This closes #808. There are several changes I want to make before
we merge, however. They are marked with TODO DALEK.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
tor-hsservice tests: Introduce new test_temp_dir helper module
See merge request tpo/core/arti!1762
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
from obtain_in.
As per irc discussion.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
from UsingTempDir.
As per irc discussion.
|
| | | |
| | |
| | |
| | | |
Mandatory whitespace degradation.
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|