aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-hsservice/src
Commit message (Collapse)AuthorAgeFilesLines
...
* | tor-hsservice: Warn when enable_pow is set on a non hs-pow-full build.Wesley Aptekar-Cassels2025-08-132-1/+11
| |
* | tor-hsservice: Remove unimplemented config option.Wesley Aptekar-Cassels2025-08-131-10/+0
| | | | | | | | | | This config option doesn't really apply to Prop 362 (which is what's implemented in Arti), as far as I can tell.
* | tor-hsservice: Remove outdated TODO.Wesley Aptekar-Cassels2025-08-131-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I have thought about this and come to the conclusion (which is what I suspected when I wrote it) that the current behaviour is correct. The attack described is completely impractical (the space of nonces is very large), and checking whether a nonce is a replay is cheaper than verifying a PoW solve, so we want to do that first. Splitting this into something like the following: * Check replay log without updating * Check that solve is valid * Update replay log Would require adding a somewhat dangerous API to the ReplayLog, and requires doing more work per request for something that isn't even a practical attack, AFAICT.
* | tor-hsservice: Add note about not persisting per-PoW-period state.Wesley Aptekar-Cassels2025-08-131-1/+7
| |
* | tor-hsservice: Add metrics support to PoW code.Wesley Aptekar-Cassels2025-08-131-2/+56
| |
* | tor-hsservice: Restore PoW verifier state from disk.Wesley Aptekar-Cassels2025-08-131-2/+25
| | | | | | | | | | We restored the seeds, but doing so is counterproductive if we don't also recreate the verifiers needed to check solves for those seeds.
* | tor-hsservice: Add pow_rend_queue_depth config option.Wesley Aptekar-Cassels2025-08-132-35/+111
| |
* | tor-hsservice: Pass Rng into PoW code where possible.Wesley Aptekar-Cassels2025-08-132-10/+11
| |
* | tor-hsservice: Implement enable_pow option.Wesley Aptekar-Cassels2025-08-136-61/+139
| | | | | | | | | | | | This does not currently allow this option to be changed at runtime, although the code is structured so that allowing it to be changed at runtime won't be too hard. This is tracked by #2082.
* | tor-hsservice: Reenable publisher test in hs-pow-full.Wesley Aptekar-Cassels2025-08-132-12/+3
| | | | | | | | MockExecutor now supports the features needed for this test to work.
* | tor-hsservice: Add PowManager to OnionServiceStatus.Wesley Aptekar-Cassels2025-08-137-35/+130
| |
* | tor-hsservice: Change ReplayLog error type.Wesley Aptekar-Cassels2025-08-135-17/+21
|/ | | | | | | | This disentangles the ReplyLog from the IptManager. This will allow us to make the InternalPowError type more public (in order to use it in the OnionServiceStatus code) without also having to make the CreateIptError type more public.
* Fix warnings and errors from edition 2024.Nick Mathewson2025-08-071-3/+2
| | | | | | | | | | The two main causes of errors were: - Since some of the lifetime rules have changed, we no longer need to do as many "bind a variable and immediately return it" patterns, and so clippy now warns about them. - We needed to adjust the explicit captures (`use<...>`) in a couple of our RPIT instances.
* Switch Cargo.toml files to edition 2024.Nick Mathewson2025-08-0719-75/+85
| | | | | | | | | | | | | | First, run ``` git grep -l "^edition =" | xargs perl -i -pe 's/^edition *=.*/edition = "2024"/;' ``` Second, manually verify that all Cargo.toml files have changed, and nothing else has changed. Third, run cargo fmt again.
* Update code for Edition 2024Nick Mathewson2025-08-073-3/+3
| | | | | | | | | | | | | | | | | | 1. Run cargo fix --edition 2. Selectively revert the "if let"->"match" changes. These changes are meant to protect us from the lifetime changes for "if let" bindings in Rust 2024. But we're not actually relying on the old lifetime rules anywhere, and the match syntax here is quite ugly. 3. Automatically revert `$pat:expr_2021` to `$pat:expr`. (We don't actually want to restrict the expression syntax that our macros accept). Done with `git grep -l expr_2021 | xargs perl -i -pe 's/expr_2021/expr/g;'` 4. Run cargo fmt.
* Merge branch 'msrv-fixes' into 'main'Nick Mathewson2025-08-051-0/+8
|\ | | | | | | | | Resolve a few issues that had been waiting for an MSRV update. See merge request tpo/core/arti!3129
| * hsservice: copy our TODO about eventually replacing once_cell.Nick Mathewson2025-08-051-0/+8
| |
* | tor-hsservice: cargo fmt.Wesley Aptekar-Cassels2025-08-051-1/+1
| |
* | tor-hsservice: Fix clippy lints.Wesley Aptekar-Cassels2025-08-051-2/+2
| |
* | tor-hsservice: Use saturating versions of time math functions.Wesley Aptekar-Cassels2025-08-051-1/+3
| |
* | tor-hsservice: Remove redundant check.Wesley Aptekar-Cassels2025-08-051-7/+1
| |
* | tor-hsservice: Don't panic on PoW main loop error.Wesley Aptekar-Cassels2025-08-051-5/+8
| |
* | tor-hsservice: Change detection of empty queue in tests.Wesley Aptekar-Cassels2025-08-051-3/+3
| |
* | tor-hsservice: Clean up use of MockRuntime functions.Wesley Aptekar-Cassels2025-08-051-10/+2
| |
* | tor-hsservice: Refactor PoW test helper functions.Wesley Aptekar-Cassels2025-08-051-57/+56
| |
* | tor-hsservice: Make PoW timeout logic smarter.Wesley Aptekar-Cassels2025-08-051-5/+11
| |
* | tor-hsservice: Make several PoW loop functions return Result.Wesley Aptekar-Cassels2025-08-051-6/+12
| | | | | | | | | | These now `warn!` and cleanly exit their respective threads on error, instead of panicking.
* | tor-hsservice: Add explanation of REND_REQUEST_QUEUE_MAX_DEPTH default.Wesley Aptekar-Cassels2025-08-051-0/+6
| |
* | tor-hsservice: Clean up try_from syntax.Wesley Aptekar-Cassels2025-08-051-4/+6
| |
* | tor-cell: Add ProofOfWorkV1::cap_effort function.Wesley Aptekar-Cassels2025-08-051-6/+1
| |
* | tor-hsservice: Make main_loop_task return Result.Wesley Aptekar-Cassels2025-08-051-5/+11
| | | | | | | | | | | | This just pushes around where the panic is for now, but enables better handling of this error, and it makes it clearer that this panic will only stop this thread.
* | tor-hsservice: Time out RendRequests in PoW queue.Wesley Aptekar-Cassels2025-08-051-13/+94
| |
* | tor-hsservice: Increase rend request queue depth.Wesley Aptekar-Cassels2025-08-051-2/+3
| | | | | | | | | | | | | | | | The "a few KB" measurement was done by using the get_size crate to measure the size of the RendRequest object, but due to limitations in that crate (and in my willingness to go implement ways of checking the size of external types), it might be somewhat off. The ~32MB value is based on the idea that each RendRequest is 4KB.
* | tor-hsservice: Persist suggested_effort.Wesley Aptekar-Cassels2025-08-051-6/+14
| |
* | tor-hsservice: Add consensus params for Prop 362.Wesley Aptekar-Cassels2025-08-054-26/+102
|/ | | | | | | | | | | This adds the three new parameters specified in Prop 362 [0]. Two of these replace hardcoded defaults in the code. The third, HiddenServiceProofOfWorkV1ServiceIntroTimeoutSeconds, is not implemented yet, but will be in a future commit. [0]: https://spec.torproject.org/proposals/362-update-pow-control-loop.html
* hsservice: Do not send the REND1 to the virtual hop.Gabriela Moldovan2025-08-051-2/+5
| | | | | The service is supposed to send the RENDEZVOUS1 to the rendezvous point itself, not the virtual hop.
* tunnel: Implement start_conversation() for all tunnel typesDavid Goulet2025-08-052-2/+2
| | | | | | | | | | The BaseTunnel now has a start_conversation() which takes a TargetHop meaning it can be used with a multi path tunnel. The Conversation object has been moved into the tunnel namespace out of the circuit one. Signed-off-by: David Goulet <[email protected]>
* hs: Use the new Tunnel interface for onion serviceDavid Goulet2025-08-056-78/+69
|
* Use new DisplayRedacted/DebugRedacted code for HsId.Nick Mathewson2025-07-312-3/+3
| | | | Closes #2012.
* tor-hsservice: Fix doccomment link.Wesley Aptekar-Cassels2025-07-231-1/+1
|
* tor-hsservice: Add monotonic request id to RendRequestOrdByEffort.Wesley Aptekar-Cassels2025-07-231-4/+23
| | | | | This ensures that even in situations where multiple requests are received at the exact same time, we will not drop any requests.
* tor-hsservice: Add note about SUGGESTED_EFFORT_DEADZONE.Wesley Aptekar-Cassels2025-07-231-0/+4
|
* tor-hsservice: Fix typo.Wesley Aptekar-Cassels2025-07-231-4/+4
|
* tor-hsservice: Remove remaining `as` casts from suggested effort update.Wesley Aptekar-Cassels2025-07-231-12/+23
| | | | | This basically converts everything to use the num_traits conversion function, and explicitly panics on errors.
* tor-hsservice: Remove another use of `as`.Wesley Aptekar-Cassels2025-07-231-3/+6
| | | | | | This pulls in num_traits (which is already a dependency for PoW) to allow f64 casts that for reasons I do not understand are not implemented via TryFrom in the standard library.
* tor-hsservice: Convert as into checked conversion.Wesley Aptekar-Cassels2025-07-231-1/+1
| | | | | This should never happen, as the queue size is limited to well below u32. However, it's still nicer not to use `as`.
* tor-hsservice: Make num_dequeued u32 instead of usize.Wesley Aptekar-Cassels2025-07-231-2/+2
| | | | | | | | | | | | We need to divide a Duration by this, and Duration only supports division by u32. This is, in a sense, just pushing around where the overflow would happen, (from the conversion in the suggested update to the increment when a item is dequeued). However, this overflow is so unlikely to happen (it would require more that 14 million requests per second) that it does not seem worth slowing down the increment operation to try to handle it.
* tor-hsservice: Fix typos.Wesley Aptekar-Cassels2025-07-231-6/+6
|
* tor-hsservice: Use Mutex for suggested_effort.Wesley Aptekar-Cassels2025-07-231-16/+16
| | | | | | | | This has fewer weird edge cases than RwLock does. It might also be reasonable to make this a AtomicU32 (or AtomicEffort which wraps AtomicU32), but that's slightly more complex, so I've opted for a mutex for now.
* tor-hsservice: Add tests for PowManager control loop.Wesley Aptekar-Cassels2025-07-231-21/+244
| | | | | | This modifies the code to be more testable (making it generic over RendRequest, getting the time from the runtime rather than Instant::now(), etc) and adds some tests for the PoW control loop.