| Commit message (Collapse) | Author | Age | Files | Lines | ||
|---|---|---|---|---|---|---|
| ... | ||||||
| | * | tor-hsservice: ipt mgr tests: Narrow a TODO | Ian Jackson | 2024-02-12 | 1 | -1/+1 | |
| | | | | | | | | | We do have some tests, but they're not as comprehensive as we'd like. | |||||
| | * | tor-hsservice: ipt mgr tests: Test that we expire old IPT data | Ian Jackson | 2024-02-12 | 1 | -0/+37 | |
| | | | ||||||
| | * | tor-hsservice: ipt mgr tests: Avoid reusing RNG seed | Ian Jackson | 2024-02-12 | 1 | -4/+4 | |
| | | | | | | | | | | | | | Without this, we can regenerate the same IptLocalIds (etc.) on shutdown/restart (which involves calling startup again within a test case). | |||||
| | * | tor-hsservice: ipt mgr: Expire replay logs for old IPTs | Ian Jackson | 2024-02-12 | 1 | -4/+57 | |
| | | | ||||||
| | * | tor-hsservice: ipt mgr: Expire keys for old IPTs | Ian Jackson | 2024-02-12 | 1 | -3/+84 | |
| | | | ||||||
| | * | tor-hsservice: ipt mgr: Track whether we've deleted any IPT (fmt) | Ian Jackson | 2024-02-12 | 1 | -9/+9 | |
| | | | ||||||
| | * | tor-hsservice: ipt mgr: Track whether we've deleted any IPT | Ian Jackson | 2024-02-12 | 1 | -2/+17 | |
| | | | | | | | | | Indentation left anmolaous briefly for ease of review. | |||||
| | * | tor-hsservice: ipt mgr: Break out REPLAY_LOG_SUFFIX | Ian Jackson | 2024-02-12 | 1 | -1/+4 | |
| | | | | | | | | | | | The expiry code is going to want this too. We should at least make a constant of it. | |||||
| | * | tor-hsservice: ipt mgr: Rotate IPT relays even without good IPTs! (fmt) | Ian Jackson | 2024-02-12 | 1 | -6/+6 | |
| | | | ||||||
| | * | tor-hsservice: ipt mgr: Rotate IPT relays even without good IPTs! | Ian Jackson | 2024-02-12 | 1 | -3/+1 | |
| | | | | | | | | | | | | | | | | | We shouldn't keep the same IPT relays just because they're not working! Firstly, that's just silly, and secondly, for privacy reasons we want to put a limit on teh lifetime anyway. Indentation left anmolaous briefly for ease of review. | |||||
| * | | tor-hsservice: Add a TODO about using HashMap for the reupload_timers. | Gabriela Moldovan | 2024-02-12 | 1 | -0/+4 | |
| | | | ||||||
| * | | tor-hsservice: Fix typo in comment. | Ian Jackson | 2024-02-12 | 1 | -1/+1 | |
| | | | ||||||
| * | | tor-hsservice: Add test for desc publisher reuploads. | Gabriela Moldovan | 2024-02-12 | 1 | -3/+41 | |
| | | | | | | | | | Part of #1241 | |||||
| * | | tor-hsservice: Remove unnecessary locking in test. | Gabriela Moldovan | 2024-02-12 | 1 | -8/+8 | |
| | | | ||||||
| * | | tor-hsservice: Add a publisher TODO about limiting reuploads. | Gabriela Moldovan | 2024-02-12 | 1 | -0/+7 | |
| | | | ||||||
| * | | tor-hsservice: Periodically reupload the descriptor. | Gabriela Moldovan | 2024-02-12 | 2 | -3/+32 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | According to the spec, the publisher needs to periodically reupload the descriptor. ``` Specifically, every time a hidden service publishes its descriptor, it also sets up a timer for a random time between 60 minutes and 120 minutes in the future. When the timer triggers, the hidden service needs to publish its descriptor again to the responsible HSDirs for that time period. [TODO SPEC: Control republish period using a consensus parameter?] ``` After each `upload_for_time_period()`, the publisher now sets a timer as described in the spec, by pushing a `ReuploadTimer` into its `reupload_timers` heap. Closes #1241 | |||||
| * | | tor-hsservice: Set the status to UploadScheduled when it's time to reupload. | Gabriela Moldovan | 2024-02-12 | 1 | -0/+45 | |
| | | | ||||||
| * | | tor-hsservice: Add helper type for scheduling descriptor reuploads. | Gabriela Moldovan | 2024-02-12 | 2 | -0/+113 | |
| | | | ||||||
| * | | tor-hsservice: Add a function for marking descriptors dirty for a specific TP. | Gabriela Moldovan | 2024-02-12 | 1 | -0/+20 | |
| | | | | | | | | | | | | | | | We will soon need the ability to trigger a descriptor reupload for a specific time period. Part of #1241 | |||||
| * | | tor-hsservice: replay log test: Check SIGUSR2 status on entry | Ian Jackson | 2024-02-12 | 1 | -0/+35 | |
| | | | | | | | | | Will make the situation in #1264 clear, I think. | |||||
| * | | tor-hsservice: replay log test: Break out sigemptyset() | Ian Jackson | 2024-02-12 | 1 | -3/+7 | |
| | | | ||||||
| * | | tor-hsservice: replay log test: Plumb output manually | Ian Jackson | 2024-02-12 | 1 | -2/+13 | |
| |/ | | | | | | | | | Something libtest is doing hides the child stderr/stdout from the test log, when --nocapture is not given. With these changes, I see much more output in failing cases or with --nocapture. In the case mentioned in #1264, the message "we survived raise SIGUSR2" is now printed both with and without --nocapture. | |||||
| * | Fix compilation with musl. | Nick Mathewson | 2024-02-06 | 1 | -3/+3 | |
| | | | | | | | | | Don't try to name the type of `RLIMIT_FSIZE` in our tests: its type is either `c_int` or `__rlimit_resource_t` depending on the libc instance. Closes #1264. | |||||
| * | Merge branch 'keymgr-generate' into 'main' | gabi-250 | 2024-02-01 | 6 | -180/+135 | |
| |\ | | | | | | | | | | | | | tor-keymgr: A handful of API fixes Closes #1194 and #1074 See merge request tpo/core/arti!1948 | |||||
| | * | tor-hsservice: Use ErrorKind::KeystoreAccessFailed for KeystoreRace errors. | Gabriela Moldovan | 2024-02-01 | 1 | -1/+1 | |
| | | | ||||||
| | * | tor-hsservice: Use FatalError::KeystoreRace where possible (fmt). | Gabriela Moldovan | 2024-02-01 | 1 | -4/+8 | |
| | | | ||||||
| | * | tor-hsservice: Use FatalError::KeystoreRace where possible. | Gabriela Moldovan | 2024-02-01 | 2 | -6/+7 | |
| | | | ||||||
| | * | tor-hsservice: Add FatalError::KeystoreRace. | Gabriela Moldovan | 2024-02-01 | 1 | -0/+13 | |
| | | | | | | | | | This will be used when a keystore race is detected. | |||||
| | * | tor-hsservice: Fix typo in error message. | Gabriela Moldovan | 2024-02-01 | 1 | -1/+1 | |
| | | | ||||||
| | * | tor-hsservice: Use read_blind_id_keypair instead of duplicating code. | Gabriela Moldovan | 2024-02-01 | 1 | -16/+6 | |
| | | | ||||||
| | * | tor-hsservice: Rewrite blind_id_keypair without get_or_generate_with_derived. | Gabriela Moldovan | 2024-02-01 | 1 | -8/+18 | |
| | | | | | | | | | We are about to remove `KeyMgr::get_or_generate_with_derived`. | |||||
| | * | tor-hsservice: Remove unnecessary loop (fmt). | Gabriela Moldovan | 2024-02-01 | 1 | -12/+12 | |
| | | | ||||||
| | * | tor-hsservice: Remove unnecessary loop. | Gabriela Moldovan | 2024-02-01 | 1 | -4/+0 | |
| | | | | | | | | | | | We don't store public HsId key in the keystore anymore, so this test is not needed anymore. | |||||
| | * | tor-hsservice: Rewrite get_or_gen_key using KeyMgr::generate. | Gabriela Moldovan | 2024-02-01 | 1 | -13/+18 | |
| | | | | | | | | | | | | | | | Now that `KeyMgr::generate` returns the generated key, we can tidy up `get_or_gen_key`. Part of #1074 | |||||
| | * | tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate (fmt). | Gabriela Moldovan | 2024-02-01 | 1 | -45/+41 | |
| | | | ||||||
| | * | tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate. | Gabriela Moldovan | 2024-02-01 | 1 | -108/+42 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon remove the `KeyMgr::*_with_derived()` functions, so we need to rewrite `maybe_generate_hsid` using `KeyMgr::get` and `KeyMgr::generate`. An important point to note is that `maybe_generate_hsid` no longer stores the `KP_hs_id` in the key store. The reason we originally put the `KP_hs_id` in the keystore in the first place was to support offline HsId mode. However, offline HsId mode was never fully implemented (#1194), and the decision to put the public part of the HsId in the keystore is controversial (#1195). We can revisit this decision when we implement #1194, but for now, we don't need a separate `KP_hs_Id` entry in the keystore. | |||||
| | * | tor-hsservice: Read the keypair when deriving the subcredentials. | Gabriela Moldovan | 2024-02-01 | 1 | -5/+8 | |
| | | | | | | | | | | | We're about to stop storing `KP_hs_id` in the keystore, so in preparation, let's update the callsites that attempt to retrieve it. | |||||
| | * | tor-hsservice: Extract the onion name from the keypair. | Gabriela Moldovan | 2024-02-01 | 1 | -3/+6 | |
| | | | | | | | | | We're about to stop storing the public part of the hsid in the keystore. | |||||
| * | | tor-hsservice: Apply deferred cargo fmt. | Gabriela Moldovan | 2024-02-01 | 1 | -8/+5 | |
| | | | ||||||
| * | | tor-hsservice: Remove unnecessary trace! log. | Gabriela Moldovan | 2024-02-01 | 1 | -1/+0 | |
| | | | ||||||
| * | | tor-hsservice: Remove old upload rate-limiting code. | Gabriela Moldovan | 2024-02-01 | 1 | -97/+1 | |
| | | | ||||||
| * | | tor-hsservice: Reimplement upload rate-limiting using TrackingNow. | Gabriela Moldovan | 2024-02-01 | 1 | -2/+16 | |
| | | | | | | | | | | | | | | | | | | | | | | | This simplifies the publisher code in preparation for #1241 This replaces the overly complicated task-based approach to rate-limiting with a simpler one, where the publisher has: * a separate `RateLimited` state that indicates it is rate-limited, and for how long * an additional arm in its `run_once()` `select_biased!`, which checks if the rate-limit has expired | |||||
| * | | tor-hsservice: Update docs with the new RateLimited state. | Gabriela Moldovan | 2024-02-01 | 1 | -10/+10 | |
| | | | ||||||
| * | | tor-hsservice: Add functions for starting/stopping the rate-limiting. | Gabriela Moldovan | 2024-02-01 | 1 | -0/+22 | |
| | | | ||||||
| * | | tor-hsservice: Add a RateLimited publisher status. | Gabriela Moldovan | 2024-02-01 | 1 | -9/+36 | |
| | | | ||||||
| * | | tor-hsservice: Remove an unnecessary TODO. | Gabriela Moldovan | 2024-02-01 | 1 | -4/+0 | |
| | | | | | | | | | | | We _do_ schedule the rate-limited upload at `now + UPLOAD_RATE_LIM_THRESHOLD`, see `schedule_rate_lim_upload()`. | |||||
| * | | tor-hsservice: Downgrade a warn! to debug!. | Gabriela Moldovan | 2024-02-01 | 1 | -2/+2 | |
| |/ | | | | | This shouldn't be a warning (it's logged when the reactor is shutting down, not when it crashes). | |||||
| * | Make the OnionServiceState type crate-private. | Nick Mathewson | 2024-02-01 | 1 | -17/+22 | |
| | | | | | Closes #1261. | |||||
| * | Merge branch 'high-level-docs' into 'main' | Nick Mathewson | 2024-02-01 | 1 | -1/+19 | |
| |\ | | | | | | | | | | | | | Add some higher-level documentation for tor-hsservice. Closes #1228 See merge request tpo/core/arti!1945 | |||||
| | * | Correct description of parameters | Ian Jackson | 2024-02-01 | 1 | -1/+1 | |
| | | | ||||||
