| Commit message (Collapse) | Author | Age | Files | Lines | ||
|---|---|---|---|---|---|---|
| ... | ||||||
| * | | tor-hsservice: Specify the expiry time for the intro_{auth, enc}_key_cert. | Gabriela Moldovan | 2023-09-22 | 2 | -5/+21 | |
| | | | | | | | | | | | The certs are generated internally by `HsDescBuilder`. The publisher just needs to set their expiry. | |||||
| * | | tor-hsservice: Remove unused keys module. | Gabriela Moldovan | 2023-09-22 | 2 | -35/+0 | |
| | | | ||||||
| * | | tor-hsservice: Make the publisher load keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -15/+25 | |
| | | | ||||||
| * | | tor-hsservice: Add a helper for reading service keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+19 | |
| | | | ||||||
| * | | tor-hsservice: Support storing desc signing keys in the keystore. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+8 | |
| | | | ||||||
| * | | tor-hsservice: Support storing HsIdKeys in the keystore. | Gabriela Moldovan | 2023-09-22 | 1 | -3/+6 | |
| | | | ||||||
| * | | tor-hsservice: Add an error variant for key-not-found errors. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 | |
| | | | ||||||
| * | | tor-hsservice: Add key specifier for blinded_id keypairs. | Gabriela Moldovan | 2023-09-22 | 3 | -0/+58 | |
| | | | ||||||
| * | | tor-hsservice: Return a ReactorError from build_sign. | Gabriela Moldovan | 2023-09-22 | 1 | -2/+2 | |
| | | | | | | | | | | | | | `build_sign` will soon be using the `KeyMgr` to look up keys, so we need to be able to propagate `KeystoreError`s (via the `ReactorError::KeyStore` variant). | |||||
| * | | tor-hsservice: Add an error variant for keystore errors. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+5 | |
| | | | ||||||
| * | | tor-hsservice: Give the publisher a reference to the key manager. | Gabriela Moldovan | 2023-09-22 | 3 | -8/+33 | |
| | | | ||||||
| * | | hss: Un-parameterize OnionService. | Nick Mathewson | 2023-09-21 | 1 | -20/+31 | |
| | | | ||||||
| * | | publish: note a possible behavior change on launch(). | Nick Mathewson | 2023-09-21 | 1 | -0/+4 | |
| | | | ||||||
| * | | hss: remove an "#[allow(...)]". | Nick Mathewson | 2023-09-21 | 1 | -2/+0 | |
| | | | ||||||
| * | | hss: adjust members of OnionService type. | Nick Mathewson | 2023-09-21 | 2 | -23/+13 | |
| | | | ||||||
| * | | hss: fix error return from OnionService::launch() | Nick Mathewson | 2023-09-21 | 2 | -1/+13 | |
| | | | ||||||
| * | | hss: start filling in a "launch" function for OnionService. | Nick Mathewson | 2023-09-21 | 2 | -39/+57 | |
| | | | ||||||
| * | | tor-hsservice: Update Publisher::new docs. | Gabriela Moldovan | 2023-09-21 | 1 | -1/+3 | |
| | | | ||||||
| * | | tor-hsservice: Add must_use for Publisher::launch. | Gabriela Moldovan | 2023-09-21 | 1 | -0/+1 | |
| | | | ||||||
| * | | tor-hsservice: Remove outdated TODO. | Gabriela Moldovan | 2023-09-21 | 1 | -1/+0 | |
| | | | ||||||
| * | | tor-hsservice: Give the descriptor publisher a separate launch function. | Gabriela Moldovan | 2023-09-21 | 3 | -28/+54 | |
| | | | | | | | | | | | | | | | | | | | | | | | This also makes `Publisher::new` synchronous. If `Reactor::new` fails, `Publisher::launch` propagates the error to its caller (to achieve this, I had to give `PublisherError` a new `ReactorLaunch` variant and make `ReactorError` and `UploadError` crate-public). Closes #1042 | |||||
| * | | Merge branch 'intro_rend' into 'main' | Nick Mathewson | 2023-09-21 | 6 | -40/+174 | |
| |\ \ | | | | | | | | | | | | | HSS: Route necessary material into RendRequest See merge request tpo/core/arti!1610 | |||||
| | * | | hs_ntor: allow attempting handshake with a set of subcredentials. | Nick Mathewson | 2023-09-20 | 2 | -16/+8 | |
| | | | | | | | | | | | | | | | | | | | | | | Since we are using the same introduction point circuits for multiple time periods, we need the ability to provide a set of subcredentials and see which of them acually works. Fortunately, we "only" have to do digest operations here, which are much faster than public key. | |||||
| | * | | hs_ntor: Take our k_hss_ntor keypair explicitly. | Nick Mathewson | 2023-09-20 | 1 | -2/+1 | |
| | | | | ||||||
| | * | | HSS: Enable RendRequests to be answered. | Nick Mathewson | 2023-09-20 | 5 | -25/+79 | |
| | | | | | | | | | | | | | | | | This requires yet more plumbing—this time, of HsCircPool and NetDirProvider. | |||||
| | * | | hss: Minor hack to avoid parameterizing RendRequestContext on Runtime | Nick Mathewson | 2023-09-20 | 1 | -2/+29 | |
| | | | | | | | | | | | | | | | | We need to pass around an Arc<HsCircPool<R>>, but doing so directly would force us to make RendRequestContext parameterized on R. | |||||
| | * | | HSS: route most necessary key material to RendRequest | Nick Mathewson | 2023-09-20 | 3 | -15/+77 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | When we go to answer a RendRequest, we need to have a few objects present. This commit makes sure that they're available at the right places. We also note a significant problem with the need for a Subcredential here. | |||||
| * | | | tor-hsservice: Fix compile error, make Publisher use Arc<OnionServiceConfig>. | Gabriela Moldovan | 2023-09-20 | 4 | -11/+12 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a compile error introduced as a result of merging a couple of conflicting MRs (!1611 and !1604). This also makes the channel the publisher uses for watching for config changes receive `Arc<OnionServiceConfig>` (rather than `OnionServiceConfig`). | |||||
| * | | | Merge branch 'mgr-watch' into 'main' | gabi-250 | 2023-09-20 | 1 | -6/+25 | |
| |\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Make config a watch receiver Closes #1041 See merge request tpo/core/arti!1611 | |||||
| | * | | | tor-hsservice: Handle config updates correctly | Ian Jackson | 2023-09-20 | 1 | -7/+24 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Make config a watch receiver | Ian Jackson | 2023-09-20 | 1 | -3/+5 | |
| | | | | | | | | | | | | | | | | | We introduce a bug here which the next commit will fix. | |||||
| * | | | | Merge branch 'onionservice_part1' into 'main' | Nick Mathewson | 2023-09-20 | 1 | -79/+91 | |
| |\ \ \ \ | |/ / / |/| | | | | | | | | | | | Start to implement OnionService::new (part 1) See merge request tpo/core/arti!1604 | |||||
| | * | | | hss: Use tor-persist to make a StorageHandle. | Nick Mathewson | 2023-09-20 | 1 | -2/+12 | |
| | | | | | | | | | | | | | | | | | We'll use this to implement intro point persistence. | |||||
| | * | | | OnionService: start to flesh out the new() function. | Nick Mathewson | 2023-09-20 | 1 | -5/+80 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | This has a lot of open questions, and won't work yet, but it starts to show us the current level of interface mismatch between our pieces. | |||||
| | * | | | hss remove duplicated data from OnionService structure. | Nick Mathewson | 2023-09-19 | 1 | -74/+1 | |
| | | | | | | | | | | | | | | | | | This data is all duplicated in other places, or will be. | |||||
| * | | | | tor-hsservice: Make the publisher compile again. | Gabriela Moldovan | 2023-09-20 | 2 | -0/+12 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The compile error happened because there was a conflict between arti!1603 and arti!1599: * the patch from !1603 uses `OnionServiceConfig::encrypt_descriptor` * !1599 removes `encrypt_descriptor` altogether | |||||
| * | | | | Merge branch 'publish-on-state-change' into 'main' | gabi-250 | 2023-09-20 | 2 | -236/+383 | |
| |\ \ \ \ | |_|/ / |/| | | | | | | | | | | | tor-hsservice: Descriptor publisher improvements See merge request tpo/core/arti!1603 | |||||
| | * | | | tor-hsservice: Add TODO regarding DescriptorConfigView. | Gabriela Moldovan | 2023-09-19 | 1 | -0/+4 | |
| | | | | | | | | | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1603#note_2944902 | |||||
| | * | | | tor-hsservice: Do not discard the runtime.spawn() Result (fmt). | Gabriela Moldovan | 2023-09-19 | 1 | -18/+21 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Do not discard the runtime.spawn() Result. | Gabriela Moldovan | 2023-09-19 | 1 | -16/+28 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Add an explicit Idle state for the publisher reactor. | Gabriela Moldovan | 2023-09-19 | 1 | -0/+8 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The previous code was correct too: after uploading the descriptor, the `PublishStatus` is not updated, because the reactor is still in a state where it has enough information to publish descriptors. Note that simply "being" in the `UploadScheduled` state isn't enough to trigger another upload, because `publish_status_rx.next()` (from the `select_biased!` of the main-loop), blocks until something triggers another state transition (`AwaitingIpts` -> `UploadScheduled`, or even `UploadScheduled` -> `UploadScheduled`), so while a third state is not strictly necessary, it does help with readability. | |||||
| | * | | | tor-hsservice: Use Instant instead of Duration for rescheduling uploads. | Gabriela Moldovan | 2023-09-19 | 1 | -6/+31 | |
| | | | | | | | | | | | | | | | | | This also documents how updates are rescheduled. | |||||
| | * | | | tor-hsservice: Remove stray doc comment. | Gabriela Moldovan | 2023-09-19 | 1 | -1/+0 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Make some publisher functions synchronous. | Gabriela Moldovan | 2023-09-19 | 1 | -13/+13 | |
| | | | | | | | | | | | | | | | | | | | | | Now that we've switched to `std::sync::Mutex` many publish functions no longer need to be async. | |||||
| | * | | | tor-hsservice: Use std::sync::Mutex instead of the one from futures (fmt). | Gabriela Moldovan | 2023-09-19 | 1 | -1/+4 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Use std::sync::Mutex instead of the one from futures. | Gabriela Moldovan | 2023-09-19 | 1 | -10/+9 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Run cargo fmt. | Gabriela Moldovan | 2023-09-19 | 1 | -69/+74 | |
| | | | | | ||||||
| | * | | | tor-hsservice: s/handle_new_intro_points/handle_ipt_change | Gabriela Moldovan | 2023-09-19 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | | | | | | | | `handle_ipt_change` no longer handles the new intro points: it now handles the IPT _change_ by updating the publish state of the reactor. | |||||
| | * | | | tor-hsservice: Borrow the IPT set from the IPT manager. | Gabriela Moldovan | 2023-09-19 | 1 | -3/+13 | |
| | | | | | ||||||
| | * | | | tor-hsservice: Discard the task handle and propagate any errors. | Gabriela Moldovan | 2023-09-19 | 1 | -3/+3 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We don't really need to keep the handles around, so let's just discard them. This also updates `upload_all` to propagate any errors coming from `build_sign`. | |||||
