aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-proto/src
Commit message (Collapse)AuthorAgeFilesLines
...
| * relay: Pass our TLS cert to the responder verify processDavid Goulet2026-02-123-6/+20
| | | | | | | | | | | | | | | | | | | | For the responder to build the authentication data, it needs its own certificate of the TLS handshake that it is responding to (as a TLS server). This resolves an important TODO(relay) in the code. Signed-off-by: David Goulet <[email protected]>
* | Merge branch 'early-relay' into 'main'gabi-2502026-02-127-132/+154
|\ \ | |/ |/| | | | | | | | | proto: Pass *all* cells to handle_forward_cell() Closes #2339 See merge request tpo/core/arti!3674
| * Revert "proto: Add a new ToRelayMsg util"Gabriela Moldovan2026-02-126-56/+2
| | | | | | | | | | | | | | | | | | | | This reverts commit 04ab3cd848d7977baf58dd64ebfcad6aa54ecb17. Reverted because we no longer need to "peek" into the opaque `CircChanMsg` of a circuit reactor: now the implementation-dependent part of the reactor is in charge of handling the channel messages, and extracting `Relay` objects out of RELAY/RELAY_EARLY cells, which then get processed in the base reactor.
| * proto: Remove unused function in relay FWD reactorGabriela Moldovan2026-02-121-7/+1
| |
| * proto: Move decode_relay_cell() out of ForwardHandlerGabriela Moldovan2026-02-122-43/+36
| | | | | | | | | | | | | | | | This doesn't need to be part of the `ForwardHandler` trait anymore, because the base reactor no longer calls it directly (instead implementations are supposed to handle it internally). No functional changes here, just code motion.
| * proto: Forbid EXTEND2 from RELAY cellsGabriela Moldovan2026-02-122-2/+11
| | | | | | | | Closes #2339
| * proto: Pass the early flag to handle_relay_msg() (fmt)Gabriela Moldovan2026-02-121-1/+3
| |
| * proto: Pass the early flag to handle_relay_msg()Gabriela Moldovan2026-02-121-3/+5
| | | | | | | | | | Needed because some messages are handled differently depending on the cell type they originated from (RELAY vs RELAY_EARLY).
| * proto: Return a protocol error if we get too many RELAY_EARLYGabriela Moldovan2026-02-121-1/+20
| |
| * proto: Overhaul forward cell handlingGabriela Moldovan2026-02-122-21/+74
| | | | | | | | | | | | | | | | | | | | | | This pushes the RELAY/REALY_EARLY handling inside `handle_forward_cell()`, which now decodes the relay cells and * handles them internally, if they are unrecognized (`handle_unrecognized_cell()`), or * returns them back to the base reactor if they are recognized (RELAY and RELAY_EARLY cells are handled the same way by the base reactor)
| * proto: Give handle_forward_cell() a handle to the hopmgrGabriela Moldovan2026-02-122-4/+11
| | | | | | | | | | Soon this function will be in charge of decoding the cell too, so it will need a handle to the `HopMgr` (see `decode_relay_cell()`)
| * proto: Pass *all* cells to handle_forward_cell()Gabriela Moldovan2026-02-121-6/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the implementation-dependent `handle_forward_cell()` handled all forward cells *except* for RELAY cells, which were handled in the generic base reactor. This changes the implementation to pass *all* cells, including RELAY cells, to `handle_forward_cell()` too. This is needed because both RELAY and RELAY_EARLY cells need to be handled very similarly: both can be either recognized or unrecognized, with unrecognized cells being handled by the implementation-dependent code, and the recognized ones being sent to the base reactor for handling. A future commit will update `handle_forward_cell()` to extract `Relay` object out of RELAY/RELAY_EARLY cells, and return it back to the base reactor for handling.
* | Merge branch 'channel-canonical' into 'main'David Goulet2026-02-128-47/+173
|\ \ | |/ |/| | | | | Implement channel canonicity See merge request tpo/core/arti!3668
| * proto: Client channel need to consider PT for the targetDavid Goulet2026-02-121-6/+21
| | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * chan: Use Canonicity when choosing a channelDavid Goulet2026-02-121-3/+10
| | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * proto: Enforce that channel method as unique SocketAddrDavid Goulet2026-02-123-28/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | During the channel handshake, we require the peer IP address for the canonicity check which requires the exact peer IP we are connected to. This commit adds a function that enforces this requirement on a ChannelMethod so anything else results in an error. It is to basically have stronger guarantee on the channel method we use in the handshake. Signed-off-by: David Goulet <[email protected]>
| * proto: Channel finish() now handles canonicityDavid Goulet2026-02-128-32/+99
| | | | | | | | | | | | | | | | | | | | | | | | | | | | All handshake pass the NETINFO cell, the advertised addresses (if any) and the peer address in order to build the Canonicity and build the channel with it. In order to pull this off, the "my_addrs" were added to several object along the NETINFO cell. We also pass the channel method when connecting (initiator) to a relay as we need this for this canonicity build. Signed-off-by: David Goulet <[email protected]>
| * proto: Implement a Canonicity structDavid Goulet2026-02-121-1/+51
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This struct will be put in a Channel and derived from the received NETINFO cell. This follows the C-tor implementation for which we have two indicator of canonicity: 1. Peer is canonical: the address they advertise in the NETINFO cell matches the one we see on the TCP connection. 2. Canonical to peer: the peer sees us as canonical. Those flag will get used to select "the best" channel. Signed-off-by: David Goulet <[email protected]>
* | proto: Return internal error on TRUNCATEGabriela Moldovan2026-02-121-1/+1
|/ | | | | | | | This is not yet implemented, so we should just return an error for now (`todo!()` will cause a panic, shutting down the thread the reactor is running on. We don't want this happening when we start manually testing our WIP impl, because depending on which thread it happens on, it can make the entire relay process unusable).
* proto: Add big TODO about flushingGabriela Moldovan2026-02-111-0/+13
|
* proto: Implement validate_backward_cell() for relaysGabriela Moldovan2026-02-111-3/+34
| | | | Closes #2345
* proto: Start forwarding cells in the backward reactorGabriela Moldovan2026-02-111-4/+11
|
* proto: Extend BWD handler with a backward cell handling functionGabriela Moldovan2026-02-112-1/+26
| | | | This will tell the base `BackwardReactor` how to handle the cell.
* proto: Relay responder channel allow to be non_exhaustiveDavid Goulet2026-02-091-1/+1
| | | | Signed-off-by: David Goulet <[email protected]>
* proto: Publicly re-export MaybeVerifiableRelayResponderChannelDavid Goulet2026-02-093-0/+5
| | | | | This type is needed in the tor-chanmgr crate in order to decide to verify or not the underlying relay channel.
* relay: Add a TLS acceptor in the ChanBuilderDavid Goulet2026-02-091-2/+10
| | | | | | | | | | | | | | | This requires the `TlsKeyAndCert` so be passed on the TLS acceptor settings. We assume that `RelayIdentities` has this information. The ChanBuilder::new() was getting a bit too convoluted and feature gated to instead we introduce new_client() and new_relay() and remove the need for `with_identities()`. Because of this, the ChanMgr::new() now returns a `Result<>`. Related to #1597 Signed-off-by: David Goulet <[email protected]>
* proto: Say why it's okay not to have timeouts in a couple of placesGabriela Moldovan2026-02-091-0/+6
|
* proto: Remove the EXTEND2 timeout for nowGabriela Moldovan2026-02-091-26/+11
| | | | | See discussion at https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3648#note_3339863
* proto: Reject EXTEND2 cells even if we already have an extension in progressGabriela Moldovan2026-02-091-1/+12
|
* proto: Ensure DESTROY gets sent on circuit dropGabriela Moldovan2026-02-052-3/+20
| | | | | | | | | | Implements this part of the spec: ``` To tear down a circuit completely, a relay or client sends a DESTROY cell to the adjacent nodes on that circuit, using the appropriate direction’s circID. ```
* proto: Make handle_extend2() synchronousGabriela Moldovan2026-02-051-3/+2
| | | | | This doesn't need to be async, as it delegates the handling to a background task.
* proto: Implement EXTEND2 handlingGabriela Moldovan2026-02-052-152/+262
| | | | | | | | To handle EXTEND2, the relay `ForwardHandler` impl spawns a background task, which reports back the result via the `CircEvent` MPSC stream. This stream is polled from the `ForwardReactor` main loop, and each `CircEvent` is passed back to `ForwardHandler::handle_event()` for handling.
* proto: Move CREATE helpers to a shared moduleGabriela Moldovan2026-02-053-6/+6
| | | | These will be used by the relay code too (for circuit extension).
* proto: Reword an error message for clarityGabriela Moldovan2026-02-051-1/+1
| | | | Users reading the log won't necessarily know what a "forward channel" is.
* proto: Add BWD command for receiving newly launched outbound channelsGabriela Moldovan2026-02-051-0/+36
|
* proto: Give handle_meta_msg() a handle to the runtimeGabriela Moldovan2026-02-053-3/+10
|
* proto: Add an implementation-dependent reactor event streamGabriela Moldovan2026-02-054-1/+54
| | | | | This will enable us to obtain implementation-dependent asynchronous events (such as the outcome of an extend handshake).
* proto: Add new LinkspecDecodeErr kindGabriela Moldovan2026-02-051-0/+15
| | | | | | This will be needed by relays, for wrapping tor_linkspec decode errors (which can happen if the link specifiers in the EXTEND2 cell can't be converted to a channel target).
* proto: Make chan_provider an ArcGabriela Moldovan2026-02-052-3/+4
| | | | To match the `ChannelProvider::get_or_launch()` function signature.
* proto: Pass the unique id to Forward handlerGabriela Moldovan2026-02-052-1/+6
| | | | | | We need the unique_id here, because the Forward handler will soon start using the `ChannelProvider::get_or_launch()` to launch outbound channels, which takes the reactor unique_id as an argument.
* proto: Move channel provider out of the generic reactorGabriela Moldovan2026-02-054-72/+18
| | | | | | The channel provider is relay-specific, so I am moving it to the relay `ForwardHandler` implementation. This enables us to get rid of some of the feature gating from the generic reactor.
* proto: Add Channel function for launching outbound relay circuitsGabriela Moldovan2026-02-051-0/+47
| | | | This is currently very similar to its client counterpart.
* proto: Make inner part of OutboundChanSender pub(crate)Gabriela Moldovan2026-02-051-1/+1
| | | | We will need the ability to build one from within tor-proto.
* proto: Fix misleading SendRelayMsg docsGabriela Moldovan2026-02-051-1/+1
| | | | This was leftover from back when this command was only for Sendmes.
* proto: Make ChannelProvider::get_or_launch() synchronousGabriela Moldovan2026-02-051-1/+1
| | | | This just removes an unnecessary `async`.
* proto: Add missing clock_skew() to unverified channelsDavid Goulet2026-02-043-8/+15
| | | | Signed-off-by: David Goulet <[email protected]>
* proto: Remove unused traits after type refactoringDavid Goulet2026-02-041-73/+0
| | | | Signed-off-by: David Goulet <[email protected]>
* proto: Make channel client to use a specific typeDavid Goulet2026-02-041-38/+43
| | | | | | Remove the use of traits, the caller will handle the specific type. Signed-off-by: David Goulet <[email protected]>
* proto: Relay channel code cleanupDavid Goulet2026-02-041-323/+4
| | | | | | No need for these types, we've replaced them with more specific types. Signed-off-by: David Goulet <[email protected]>
* proto: Introduce new relay responder channel typesDavid Goulet2026-02-043-20/+211
| | | | | | | | | | Add the unverified, verified, non verifiable flavor types of a responder channel. This follow on the previous commit to use the type system for stronger guarantees. Signed-off-by: David Goulet <[email protected]>