aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-hsservice
Commit message (Collapse)AuthorAgeFilesLines
...
* | tor-hsservice: Add a TODO about using HashMap for the reupload_timers.Gabriela Moldovan2024-02-121-0/+4
| |
* | tor-hsservice: Fix typo in comment.Ian Jackson2024-02-121-1/+1
| |
* | tor-hsservice: Add test for desc publisher reuploads.Gabriela Moldovan2024-02-121-3/+41
| | | | | | | | Part of #1241
* | tor-hsservice: Remove unnecessary locking in test.Gabriela Moldovan2024-02-121-8/+8
| |
* | tor-hsservice: Add a publisher TODO about limiting reuploads.Gabriela Moldovan2024-02-121-0/+7
| |
* | tor-hsservice: Periodically reupload the descriptor.Gabriela Moldovan2024-02-122-3/+32
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | According to the spec, the publisher needs to periodically reupload the descriptor. ``` Specifically, every time a hidden service publishes its descriptor, it also sets up a timer for a random time between 60 minutes and 120 minutes in the future. When the timer triggers, the hidden service needs to publish its descriptor again to the responsible HSDirs for that time period. [TODO SPEC: Control republish period using a consensus parameter?] ``` After each `upload_for_time_period()`, the publisher now sets a timer as described in the spec, by pushing a `ReuploadTimer` into its `reupload_timers` heap. Closes #1241
* | tor-hsservice: Set the status to UploadScheduled when it's time to reupload.Gabriela Moldovan2024-02-121-0/+45
| |
* | tor-hsservice: Add helper type for scheduling descriptor reuploads.Gabriela Moldovan2024-02-122-0/+113
| |
* | tor-hsservice: Add a function for marking descriptors dirty for a specific TP.Gabriela Moldovan2024-02-121-0/+20
| | | | | | | | | | | | | | We will soon need the ability to trigger a descriptor reupload for a specific time period. Part of #1241
* | tor-hsservice: replay log test: Check SIGUSR2 status on entryIan Jackson2024-02-121-0/+35
| | | | | | | | Will make the situation in #1264 clear, I think.
* | tor-hsservice: replay log test: Break out sigemptyset()Ian Jackson2024-02-121-3/+7
| |
* | tor-hsservice: replay log test: Plumb output manuallyIan Jackson2024-02-121-2/+13
|/ | | | | | | | | Something libtest is doing hides the child stderr/stdout from the test log, when --nocapture is not given. With these changes, I see much more output in failing cases or with --nocapture. In the case mentioned in #1264, the message "we survived raise SIGUSR2" is now printed both with and without --nocapture.
* Fix compilation with musl.Nick Mathewson2024-02-061-3/+3
| | | | | | | | Don't try to name the type of `RLIMIT_FSIZE` in our tests: its type is either `c_int` or `__rlimit_resource_t` depending on the libc instance. Closes #1264.
* Merge branch 'delete-semvers' into 'main'Ian Jackson2024-02-051-6/+0
|\ | | | | | | | | Remove all semver.md files to start a fresh release round See merge request tpo/core/arti!1957
| * Remove all semver.md files to start a fresh release roundIan Jackson2024-02-051-6/+0
| |
* | Bump patch versions *with* dependency updateIan Jackson2024-02-051-1/+1
| | | | | | | | | | | | | | This crate has had new features added. It's 0.x. So bump in-tree dependencies' references: fs-mistrust
* | Bump minor versionsIan Jackson2024-02-051-23/+23
|/ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bump the minor version of these crates, and update the in-tree dependencies. Recently published as fresh crates, let's just assume there are breaking changes: fslock-guard test-temp-dir Breaking API change affecting many many downstream crates: tor-rtcompat Downstream crates which we're (conservatively) assuming have tor-rtcompat types in their APIs: tor-rtmock tor-log-ratelim tor-rpcbase tor-llcrypto tor-protover tor-bytes tor-hscrypto tor-hspow tor-socksproto tor-checkable tor-cert tor-linkspec tor-cell tor-proto tor-netdoc tor-consdiff tor-netdir tor-congestion tor-persist tor-chanmgr tor-ptmgr tor-guardmgr tor-circmgr tor-dirclient tor-dirmgr tor-keymgr tor-hsclient tor-hsservice tor-hsrproxy arti-client arti-rpcserver arti-config arti-hyper arti-bench arti-testing
* Run maint/fixup-featuresIan Jackson2024-02-051-1/+1
| | | | Discard hunks in examples/
* Merge branch 'keymgr-generate' into 'main'gabi-2502024-02-017-180/+136
|\ | | | | | | | | | | | | tor-keymgr: A handful of API fixes Closes #1194 and #1074 See merge request tpo/core/arti!1948
| * tor-hsservice: Use ErrorKind::KeystoreAccessFailed for KeystoreRace errors.Gabriela Moldovan2024-02-011-1/+1
| |
| * tor-hsservice: Use FatalError::KeystoreRace where possible (fmt).Gabriela Moldovan2024-02-011-4/+8
| |
| * tor-hsservice: Use FatalError::KeystoreRace where possible.Gabriela Moldovan2024-02-012-6/+7
| |
| * tor-hsservice: Add FatalError::KeystoreRace.Gabriela Moldovan2024-02-012-0/+14
| | | | | | | | This will be used when a keystore race is detected.
| * tor-hsservice: Fix typo in error message.Gabriela Moldovan2024-02-011-1/+1
| |
| * tor-hsservice: Use read_blind_id_keypair instead of duplicating code.Gabriela Moldovan2024-02-011-16/+6
| |
| * tor-hsservice: Rewrite blind_id_keypair without get_or_generate_with_derived.Gabriela Moldovan2024-02-011-8/+18
| | | | | | | | We are about to remove `KeyMgr::get_or_generate_with_derived`.
| * tor-hsservice: Remove unnecessary loop (fmt).Gabriela Moldovan2024-02-011-12/+12
| |
| * tor-hsservice: Remove unnecessary loop.Gabriela Moldovan2024-02-011-4/+0
| | | | | | | | | | We don't store public HsId key in the keystore anymore, so this test is not needed anymore.
| * tor-hsservice: Rewrite get_or_gen_key using KeyMgr::generate.Gabriela Moldovan2024-02-011-13/+18
| | | | | | | | | | | | | | Now that `KeyMgr::generate` returns the generated key, we can tidy up `get_or_gen_key`. Part of #1074
| * tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate (fmt).Gabriela Moldovan2024-02-011-45/+41
| |
| * tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate.Gabriela Moldovan2024-02-011-108/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon remove the `KeyMgr::*_with_derived()` functions, so we need to rewrite `maybe_generate_hsid` using `KeyMgr::get` and `KeyMgr::generate`. An important point to note is that `maybe_generate_hsid` no longer stores the `KP_hs_id` in the key store. The reason we originally put the `KP_hs_id` in the keystore in the first place was to support offline HsId mode. However, offline HsId mode was never fully implemented (#1194), and the decision to put the public part of the HsId in the keystore is controversial (#1195). We can revisit this decision when we implement #1194, but for now, we don't need a separate `KP_hs_Id` entry in the keystore.
| * tor-hsservice: Read the keypair when deriving the subcredentials.Gabriela Moldovan2024-02-011-5/+8
| | | | | | | | | | We're about to stop storing `KP_hs_id` in the keystore, so in preparation, let's update the callsites that attempt to retrieve it.
| * tor-hsservice: Extract the onion name from the keypair.Gabriela Moldovan2024-02-011-3/+6
| | | | | | | | We're about to stop storing the public part of the hsid in the keystore.
* | tor-hsservice: Apply deferred cargo fmt.Gabriela Moldovan2024-02-011-8/+5
| |
* | tor-hsservice: Remove unnecessary trace! log.Gabriela Moldovan2024-02-011-1/+0
| |
* | tor-hsservice: Remove old upload rate-limiting code.Gabriela Moldovan2024-02-011-97/+1
| |
* | tor-hsservice: Reimplement upload rate-limiting using TrackingNow.Gabriela Moldovan2024-02-011-2/+16
| | | | | | | | | | | | | | | | | | | | | | This simplifies the publisher code in preparation for #1241 This replaces the overly complicated task-based approach to rate-limiting with a simpler one, where the publisher has: * a separate `RateLimited` state that indicates it is rate-limited, and for how long * an additional arm in its `run_once()` `select_biased!`, which checks if the rate-limit has expired
* | tor-hsservice: Update docs with the new RateLimited state.Gabriela Moldovan2024-02-011-10/+10
| |
* | tor-hsservice: Add functions for starting/stopping the rate-limiting.Gabriela Moldovan2024-02-011-0/+22
| |
* | tor-hsservice: Add a RateLimited publisher status.Gabriela Moldovan2024-02-011-9/+36
| |
* | tor-hsservice: Remove an unnecessary TODO.Gabriela Moldovan2024-02-011-4/+0
| | | | | | | | | | We _do_ schedule the rate-limited upload at `now + UPLOAD_RATE_LIM_THRESHOLD`, see `schedule_rate_lim_upload()`.
* | tor-hsservice: Downgrade a warn! to debug!.Gabriela Moldovan2024-02-011-2/+2
|/ | | | | This shouldn't be a warning (it's logged when the reactor is shutting down, not when it crashes).
* Make the OnionServiceState type crate-private.Nick Mathewson2024-02-011-17/+22
| | | | Closes #1261.
* Merge branch 'high-level-docs' into 'main'Nick Mathewson2024-02-012-7/+59
|\ | | | | | | | | | | | | Add some higher-level documentation for tor-hsservice. Closes #1228 See merge request tpo/core/arti!1945
| * Correct description of parametersIan Jackson2024-02-011-1/+1
| |
| * Note that old state is not yet removedIan Jackson2024-02-011-0/+3
| |
| * Add some higher-level documentation for tor-hsservice.Nick Mathewson2024-01-312-7/+56
| | | | | | | | Closes #1228.
* | tor-hsservice: Rename the service keystore dir to "hss".Gabriela Moldovan2024-02-011-14/+14
| | | | | | | | | | | | | | | | | | | | | | The onion service keys now live in the `hss/<nickname>` subdirectory within the keystore. This layout change is **not** backwards-compatible, so if you want to use your existing hidden service keys, you will need to manually move them to `<keystore_root>/hss`. Closes #1260
* | tor-hsservice: Remove now-unused importsIan Jackson2024-02-013-8/+4
| |
* | tor-hsservice: tests: create_storage_handles: use a real directory (churn)Ian Jackson2024-02-011-1/+1
| | | | | | | | Mandatory use line shuffling.