summaryrefslogtreecommitdiff
path: root/crates/tor-rpc-connect/src
Commit message (Collapse)AuthorAgeFilesLines
* rpc: Fix test builds on Windows.Alexander Hansen Færøy2025-01-301-1/+4
|
* rpc-connect: Remove remaining TODO RPCsNick Mathewson2025-01-271-4/+1
| | | | I have checked the relevant code, and it seems okay.
* rpc-connect: Make Connect::validate more straightforwardNick Mathewson2025-01-271-11/+12
|
* rpc-connect: check that all paths inside a connpt are absolute.Nick Mathewson2025-01-271-13/+49
|
* rpc-connect: remove todo; confirm that we do want to mkdir.Nick Mathewson2025-01-271-1/+1
|
* rpc-connect: Detect and decline connpts with invalid "auth" feieldsNick Mathewson2025-01-273-20/+18
|
* rpc-connect: Abort on misformed cookie file, and explain why.Nick Mathewson2025-01-271-6/+3
|
* rpc-connect: Use file_access() API, and permit symlinks.Nick Mathewson2025-01-272-17/+20
|
* Merge branch 'rpc-connect-clarify' into 'main'Nick Mathewson2025-01-161-0/+9
|\ | | | | | | | | | | | | rpc: Clarify and fix some issues surrounding relative paths. Closes #1748 and #1749 See merge request tpo/core/arti!2712
| * rpc: Reject relative unix paths.Nick Mathewson2025-01-151-0/+9
| |
* | rpc: Document windows USER_DEFAULT connect point.Nick Mathewson2025-01-151-1/+0
| |
* | rpc: Expose Cookie::load unconditionally.Nick Mathewson2025-01-151-2/+0
| |
* | rpc: Use symbolic constants for nonce/mac lengths.Nick Mathewson2025-01-151-7/+14
| |
* | rpc: Tests for cookie nonce/mac encoding/decoding.Nick Mathewson2025-01-151-2/+46
| | | | | | | | Also fix a bug in decoding, where we accepted too-short strings.
* | rpc: Refactor Cookie and UnloadedCookie into a single type.Nick Mathewson2025-01-153-18/+33
| |
* | rpc: consolodate naming of "inherent" auth.Nick Mathewson2025-01-153-4/+5
| | | | | | | | | | | | | | | | | | We don't want to call this "unix path" anywhere, since it corresponds to _any_ case where the ability to negotiate a successful connection means that the client is authorized. We also don't want to call it "none": The authentication is inherent to the connection, not nonexistent.
* | rpc: Tweak cookie protocol to bind both nonces.Nick Mathewson2025-01-151-2/+8
| | | | | | | | | | | | | | | | | | | | Previously participants in the cookie protocol only bound the peer nonce in their MACs. With this change, they bind both nonces. This change is _probably_ not necessary for security, but it can't hurt. It follows a general principle that Adam Langley told me a long time ago: you won't regret binding more, but you might regret binding less.
* | rpc: Keep Cookie in an Arc.Nick Mathewson2025-01-152-3/+9
| | | | | | | | | | Since this is a secret value, it's probably best not to copy it all over the place.
* | arti-rpcserver: Server side of cookie auth.Nick Mathewson2025-01-151-2/+25
| |
* | tor-rpc-connect: Cryptographic support for cookie auth.Nick Mathewson2025-01-151-2/+208
| | | | | | | | Conforms to rpc-cookie-sketch.md.
* | tor-rpc-connect: defer loading auth cookies on the client side.Nick Mathewson2025-01-153-6/+37
| | | | | | | | | | We want to load cookies only after we've connected and gotten a banner.
* | tor-rpc-connect: move cookie auth support to its own module.Nick Mathewson2025-01-155-171/+172
|/
* Merge branch 'mod-module-files' into 'main'Nick Mathewson2025-01-071-0/+1
|\ | | | | | | | | clippy: deny `mod_module_files` See merge request tpo/core/arti!2689
| * clippy: deny `mod_module_files`Steven Engler2025-01-061-0/+1
| | | | | | | | | | | | Denies 'mod.rs' files for consistency. https://rust-lang.github.io/rust-clippy/master/index.html#mod_module_files
* | fix: fix typosDimitris Apostolou2025-01-061-1/+1
| |
* | Merge branch 'bug1776' into 'main'Nick Mathewson2025-01-061-1/+0
|\ \ | |/ |/| | | | | | | | | rpc-connect: Remove cfg(unix) of SYSTEM_DEFAULT_CONNECT_POINT Closes #1776 See merge request tpo/core/arti!2667
| * rpc-connect: Remove cfg(unix) of SYSTEM_DEFAULT_CONNECT_POINTNick Mathewson2024-12-111-1/+0
| | | | | | | | | | | | | | When we switched this definition to use `cfg_if`, we overlooked the `#[cfg(unix)]`. Fixes #1776.
* | Rename Guard=>ListenerGuard.Nick Mathewson2024-12-191-4/+4
| |
* | rpc-connect: Explain locking rationale better.Nick Mathewson2024-12-191-3/+12
| |
* | rpc-connect: Use try_lock when acquiring fslockNick Mathewson2024-12-192-1/+9
| | | | | | | | | | This lets us bail when another process has bound to our connect point, rather than blocking indefinitely.
* | connpt: Make unix socket handling more robust.Nick Mathewson2024-12-193-20/+68
| | | | | | | | | | | | | | | | | | | | Grab an associated lock file... - ... then delete the socket file (if it's present) ... - ... then bind to it. On exit: - remove the socket - then drop the lock.
* | rpc-connect: Make LoadOptions buildable.Nick Mathewson2024-12-191-1/+2
| |
* | rpc-connect: fix another very typoed lineNick Mathewson2024-12-191-1/+1
|/
* connpt: note an opportunity to save some fds.Nick Mathewson2024-12-091-0/+3
|
* connpt: use cfg-if to declare connect point defaults.Nick Mathewson2024-12-091-20/+27
|
* connpts: duplicate socket before returning.Nick Mathewson2024-12-091-15/+24
| | | | | (We want a separate read and write socket before we return, and once we've done the type-erasure, we can't do try_clone().)
* connpts: Add default connect points as constants.Nick Mathewson2024-12-091-0/+60
|
* add_warnings, *: Allow clippy::needless_lifetimesNick Mathewson2024-12-031-0/+1
| | | | | | | | In 1.83, this warning triggers on many of our crates. We're thinking of fixing them all, but for now, we're going to disable the warning. This is part of #1765.
* connect point: Use new CfgPathResolver api.Nick Mathewson2024-11-191-12/+22
|
* connect point: handle unrecognized auth variants.Nick Mathewson2024-11-193-6/+39
|
* Connect point: Improve robustness against new SocketAddr variantsNick Mathewson2024-11-191-2/+10
|
* connect point: add a test for ConflictingMembers.Nick Mathewson2024-11-191-0/+13
|
* connect-point: Rename Reps to Addresses.Nick Mathewson2024-11-191-7/+7
|
* connect point: Add server support.Nick Mathewson2024-11-192-0/+71
| | | | | ("Server support" here means binding to a socket and reading a cookie file.)
* connect point: Add client support.Nick Mathewson2024-11-193-0/+182
| | | | | ("Client support" here means connecting to a socket and reading a cookie file.)
* connect point: Treat unrecognized auth types as Decline.Nick Mathewson2024-11-191-0/+9
|
* connect points: Validate more correctness propertiesNick Mathewson2024-11-191-4/+23
| | | | | In particular, we only allow binding/connecting to localhost, and we only support None auth for Unix connections.
* connect points: Remember original string addressesNick Mathewson2024-11-191-6/+57
| | | | The cookie authentication protocol will need these.
* rpc-connect: Types for cookie authentication.Nick Mathewson2024-11-192-0/+186
| | | | (Cookie authentication is described in rpc-cookie-sketch.md)
* rpc-connect: Move tempdir() helper to a new moduleNick Mathewson2024-11-193-17/+36
|