| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |
|
|
| |
Part of #1242
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Previously, the subcredentials were computed in `IptEstablisher::launch`
and stored in `RendRequestContext`. This caused long-running services to
report errors like:
```
WARN tor_hsservice::helpers: Problem while accepting rendezvous request: error: Could not process INTRODUCE request: Introduction handshake was invalid: Circuit-extension handshake authentication failed
```
for clients using newer subcredentials than the ones the service had at
the time the IPT was established.
Fixes #1242
|
| |
|
|
|
|
|
|
| |
The subcredential lookup will be moved to
`IntroRequest::decrypt_from_introduce2`. The error returned on failure
is going to be `IntroRequestError::Subcredentials`.
Part of #1242
|
| |\
| |
| |
| |
| |
| |
| | |
Clarify shutdown behavior when RemoteOnionService is dropped.
Closes #1238 and #1236
See merge request tpo/core/arti!1899
|
| | | |
|
| | |
| |
| |
| |
| | |
We don't need to implement this for our first release of onion
services, but we shouldn't ship a function that calls todo!().
|
| | | |
|
| | |
| |
| |
| |
| |
| | |
There was no actual bug here; just some missing comments.
Closes #1236.
|
| |\|
| |
| |
| |
| |
| |
| | |
Do not reject INTRO_ESTABLISHED messages with extensions
Closes #1238
See merge request tpo/core/arti!1898
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The spec says that we should ignore unrecognized extensions.
Per discussion at torspec#249, this is still correct.
Additionally, this commit moves responsibility for checking
INTRO_ESTABLISHED messages into IptMsgHandler::handle_msg, to make
sure that the circuit is torn down as soon as possible on a bad
reply. (There's nothing to check yet, but there will be once we
start sending extensions that expect a reply.)
Closes #1238.
|
| |/
|
|
| |
Followup from !1895.
|
| |\
| |
| |
| |
| | |
tor-hsservice: The publisher should exit when the IPT manager says so.
See merge request tpo/core/arti!1895
|
| | |
| |
| |
| |
| |
| | |
The publisher needs to shut down when
`IptPublisherView::sawait_update()` returns `None`, not pause the
uploads.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-hsservice: Reference #1226 instead of #1219 in a TODO.
Closes #1219
See merge request tpo/core/arti!1896
|
| | |/
| |
| |
| |
| |
| |
| |
| | |
`note_publication_attempt` can only fail:
* due to an internal error, in which case there is no point in
retrying
* if `PublishIptSet::save` fails, i.e. if we fail to write to persistent
storage (this is #1226)
|
| | |
| |
| |
| |
| |
| | |
This introduces an internal `OnionServiceStateMgr` trait, which enables
us to store the `StateMgr` inside the `OnionServiceState` (without
having to parameterize `OnionServiceState` on `S: StateMgr`).
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
Both `OnionService` and `RunningOnionService` have an `onion_name()`
function. To reduce code duplication, we can move `onion_name()` to a
new `OnionServiceState` struct (which will grow more state management
functions int he future), and make both `*OnionService` structs deref to
it.
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| | |
The `StateMgr` is currently only needed in `launch()`, so we don't
really need to store it.
This allows us to unparameterize OnionService.
|
| | | |
|
| | |
| |
| |
| |
| | |
The functionality previously provided by the so-called `StateMgr` is now
part of `OnionService`, so we can remove state.rs altogether.
|
| | |
| |
| |
| |
| |
| |
| | |
This a modified version of `tor_hsservice::state::StateMgr::onion_name`.
`tor_hsservice::state::StateMgr` will soon be abolished.
Part of #1220, #1227
|
| | |
| |
| |
| |
| |
| |
| |
| | |
This will enable us to construct non-launched (but configured)
`OnionService`s. We need this, for example, for implementing
the `arti hss` CLI command.
Part of #1227
|
| |/
|
|
| |
Part of #1227
|
| |\
| |
| |
| |
| |
| |
| | |
Implement is_ipt_failure better.
Closes #1234
See merge request tpo/core/arti!1889
|
| | | |
|
| | |
| |
| |
| |
| | |
Additionally, explain its behavior better, since we cannot always
identify an Ipt failure with certainty.
|
| | |
| |
| |
| |
| | |
Closes #1224, by making it more clear that we aren't keeping a
circuit alive indefinitely.
|
| |/
|
|
|
|
| |
All appropriate checks here should be in `is_hs_intro_point()`.
Closes #1211.
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
| |
k_sid was not redundant with RequestContext: the latter only held
the public key, but the reactor here needed the entire keypair.
|
| |
|
|
|
| |
(I've expanded #1209 to give us the option to either _implement_ these
transitions, or _forbid_ them. We shouldn't just ignore them, though.)
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
(We can revert this later if it turns out to be needed.)
|
| |
|
|
| |
This is a MUST.
|
| |
|
|
|
| |
Mostly, this is just adding documentation, but it is also removing
a couple of no-longer-relevant TODOs.
|
| | |
|
| |
|
|
| |
This misunderstands the way that introduce rate-limiting works.
|
| | |
|