summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-dirmgr/state.rs: take an object to get a netdir, not a netdireta2022-05-102-12/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | - Taking a previous netdir directly and keeping it around before we need it is a bit of a waste of memory, and also doesn't mesh well with how SharedMutArc works. - To remedy this, introduce a new trait `PreviousNetDir` and have the state machines take that instead. (I was a bit tempted to just pass in the SharedMutArc directly. Maybe I should've done that.)
| * | tor-dirmgr/state.rs: remove GetConsensusState::bodge_neweta2022-05-102-43/+36
| | | | | | | | | | | | - (Also fixes up some dirfilter stuff, whoops.)
| * | tor-dirmgr/state.rs: remove WriteNetDir, use filters directlyeta2022-05-101-97/+79
| | | | | | | | | | | | | | | - The only purpose of WriteNetDir was to provide a filter, which isn't necessary any more. Refactor to provide the filter directly.
| * | tor-dirmgr/state.rs: use the NetDirChange API instead of WriteNetDireta2022-05-103-260/+179
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - GetMicrodescsState now uses the NetDirChange API to propagate netdir changes, instead of modifying the netdir directly. - PendingNetDir was refactored in order to support this use case. - As a result, the netdir-related methods in WriteNetDir can be removed, leaving only the DirFilter for now. - add_from_cache() no longer takes a store, because nothing uses it. - (bodge: apply_netdir_changes() was put in a few places missed previously)
| * | tor-dirmgr/state.rs: add new NetDirChange API, consume iteta2022-05-102-3/+97
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - The new DirState::get_netdir_change() API lets the state machine export a NetDirChange: a request to either replace the current netdir, or add microdescs to it. - bootstrap.rs now consumes this new API, even though nothing implements it yet. - This will let us implement GetMicrodescsState without having to directly mutate the netdir. The calling code also handles checking the netdir against the circmgr for sufficiency, and updating the consensus metadata in the store, meaning the revised GetMicrodescsState will not have to perform these tasks.
| * | tor-dirmgr/state.rs: feed through additional parameters, use themeta2022-05-103-242/+223
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - The additional parameters passed to GetConsensusState are now passed through all the states, and used as well. - WriteNetDir doesn't have a now() or config() method any more, since the states now get this from the runtime or the config parameters. - This required modifying the tests to make a mocked runtime and custom config directly, instead of using DirRcv for this purpose. - Additionally, because we don't have to upgrade a weak reference for DirState::dl_config(), that function no longer wraps its return value in Result. - (A bunch of the FIXMEs from the previous commit that introduced the additional parameters have now been rectified as a result.)
| * | tor-rtcompat: make CompoundRuntime handle SleepProviders properlyeta2022-05-101-0/+11
| | | | | | | | | | | | | | | | | | Previously, CompoundRuntime would use the default implementations of SleepProvider::now() and ::wallclock(), instead of using its wrapped SleepProvider. This mildly embarrassing omission has been rectified.
| * | tor-dirmgr/state.rs: refactor GetConsensusState::neweta2022-05-103-220/+285
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - GetConsensusState::new now takes a set of parameters matching what it actually needs, instead of just taking a writedir. (It still *does* take a writedir, and indeed still uses it for basically everything, but that will eventually go away.) - Its call sites were updated. - Some tests now need to take a runtime, and got indented a lot as a result. - Resetting was made non-functional, because we need to thread through the parameters passed to GetConsensusState to all of the other states, too. This will happen in a later commit.
| * | tor-dirmgr: move DirState to state.rseta2022-05-103-78/+80
| | | | | | | | | | | | | | | | | | - Given that this is effectively an implementation detail, it doesn't really make sense to have it be in the crate root... - (also, we're going to change it a bunch now)
| * | tor-dirmgr/bootstrap.rs: refactor fetch_singleeta2022-05-101-31/+34
| | | | | | | | | | | | | | | | | | | | | - fetch_single now takes what it needs, instead of an Arc<DirMgr<R>>. - This required refactoring the CANNED_RESPONSE mechanism, given the test would otherwise fail due to not having a CircMgr to pass to fetch_single.
| * | tor-dirmgr: make note_request_* functions standaloneeta2022-05-102-72/+80
| | | | | | | | | | | | | | | - DirMgr::note_request_outcome and friends are now just standalone functions, taking a CircMgr.
| * | tor-dirmgr/bootstrap.rs: refactor query_into_requests, make it usedeta2022-05-102-60/+56
| | | | | | | | | | | | | | | | | | | | | - query_into_requests is now called make_requests_for_documents, and does the &[DocId] -> DocQuery conversion internally instead. - DirMgr::make_consensus_request and DirMgr::query_into_requests are now gone. The tests use the new functions, as does fetch_multiple.
| * | tor-dirmgr: move query_into_requests into bootstrap.rseta2022-05-102-44/+71
| | | | | | | | | | | | | | | | | | | | | - There's no good reason these functions needed to be part of the dirmgr, apart from needing a runtime and a store. - However, we can just add those as arguments and copy them over. This commit does that.
| * | tor-dirmgr/bootstrap.rs: refactor load_all -> load_documents_from_storeeta2022-05-103-15/+29
| | | | | | | | | | | | | | | | | | | | | | | | - Function renamed & docs tidied up a bit - Function signature now takes what it needs (immutable &dyn Store instead of mutex, slice instead of Vec) and nothing more - DocQuery::load_documents_into was also renamed DocQuery::load_from_store_into and given similar treatment
| * | tor-dirmgr/storage.rs: impl Store for Box<dyn Store>eta2022-05-101-0/+87
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Annoyingly, Rust doesn't automatically generate this sort of `impl` for you, and I'd like to reduce the usage of Mutex<DynStore> everywhere else in favour of either &dyn Store or &mut dyn Store. (This is for two reasons: firstly, we might have a Store implementation that doesn't use a mutex as above, or similar refactors; secondly, passing the raw trait object reference lets us encode mutability into the function signature, which I believe is quite valuable.)
| * | tor-dirmgr/lib.rs: move DirMgr::load_documents_into to DocQueryeta2022-05-103-56/+59
| | | | | | | | | | | | | | | Move the function out of DirMgr, giving it a new &Mutex<DynStore> argument instead.
* | | Remove cargo-husky, and replace with manual instructionseta2022-05-101-8/+0
|/ / | | | | | | | | | | | | | | A build script reaching into your .git/hooks/ and modifying them nonconsensually was a bit of a horrifying concept, and also made it hard to build arti with the feature disabled. Remove this crate, and replace it with manual instructions on how to install the hooks in CONTRIBUTING.md.
* | netdoc: add a new type for NicknamesNick Mathewson2022-05-096-11/+96
| | | | | | | | | | | | | | | | | | | | Relay nicknames are always between 1 and 19 characters long, and they're always ASCII: That means that storing them in a [u8;19] will always be possible, and always use less resources than storing them in a String. Fortunately, the tinystr crate already helps us with this kind of thing.
* | Merge branch 'use-fs-mistrust'Nick Mathewson2022-05-0920-154/+492
|\ \
| * | Loosen checking for readable files within target directories.Nick Mathewson2022-05-092-14/+30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If the target directory itself is unreadable by untrusted users, then its contents can't be read[*] by them regardless of their permissions. If the target directory _is_ readable, then _it_ will be rejected if we are forbidding readable objects. (And if we aren't we don't care if the contents are readable.) A similar argument would apply to writable objects within an unreadable target directory. We're not making that argument, since such contents are likelier to be a mistake. [*] Unless they're hard-linked; see comments in "Limitations" section.
| * | Add a CLI option to disable FS permission checks.Nick Mathewson2022-05-091-1/+10
| | |
| * | Remove "Mistrust" from the public API of arti-client.Nick Mathewson2022-05-093-15/+35
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I'm doing this per discussion, so that we can have it be part of the TorConfig later on, and not break stuff as we change the Mistrust API to have a builder. This change, unfortunately, results in a little more internal complexity and duplicated code in arti and arti-client. I've marked those points with TODOs.
| * | arti: use fs-mistrust to validate configuration file locations.Nick Mathewson2022-05-094-13/+29
| | |
| * | arti-client: Configure and use fs-mistrust.Nick Mathewson2022-05-094-8/+63
| | | | | | | | | | | | | | | | | | This is derived from the environment, not the configuration file: We might not want to trust the configuration file until we've decided whether we like its permissions.
| * | Update tor-dirmgr to use fs-mistrust.Nick Mathewson2022-05-096-86/+115
| | |
| * | tor-persist: Use fs-mistrust to verify state file permissions.Nick Mathewson2022-05-093-35/+51
| | |
| * | Add new FsPermissions ErrorKind.Nick Mathewson2022-05-091-0/+9
| | |
| * | fs-mistrust: add various methods.Nick Mathewson2022-05-092-7/+174
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This includes: * a CachedDir::join method. * functions to read and write from provided filenames in a CachedDir. * a method to tell whether a fs-mistrust error is about bad file permissions, or failure to inspect file permissions or some other kind of IO problem.
| * | Derive Clone and Debug for CheckedDir.Nick Mathewson2022-05-051-0/+1
| | |
* | | NetParams: Document its role as a validated config parameterIan Jackson2022-05-092-3/+3
| | |
* | | Bump the version of every* crate to 0.3.0Nick Mathewson2022-05-0633-184/+184
| | | | | | | | | | | | * Except for safelog and fs-mistrust, which are new.
* | | Change safelog version to 0.1.0.Nick Mathewson2022-05-064-4/+4
| | | | | | | | | | | | | | | (This is okay because we haven't published it yet, or any crate that uses it.)
* | | Update README.md files (automated).Nick Mathewson2022-05-0610-16/+307
| | |
* | | Merge branch 'derive-builder-fork' into 'main'Nick Mathewson2022-05-068-8/+8
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Switch to derive_builder_arti_fork Closes #446 See merge request tpo/core/arti!490
| * | | Switch to derive_builder_arti_forkIan Jackson2022-05-068-8/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | For reference, the git source for this crate (and the others in its workspace) currently lives in my personal github account (ijackson). If this fork turns out to be long-lived and gains features and/or users, it would be good to move it to a gitlab somewhere. I have granted Nick crate ownership on the crates.io system.
* | | | Punctuation fix.eta2022-05-061-1/+1
| | | |
* | | | Disable safe-logging when logging to console.Nick Mathewson2022-05-061-1/+30
| | | |
* | | | arti: add support for safe-logging configurationNick Mathewson2022-05-062-3/+35
| | | | | | | | | | | | | | | | | | | | | | | | Here we add a config option to disable safe logging, and ensure that safe logging is disabled when we are formatting an error message on exit (since we assume it's safe to write sensitive info to stderr.)
* | | | Apply `sensitive` in some info-level log messages.Nick Mathewson2022-05-065-3/+8
| | | | | | | | | | | | | | | | | | | | This specifically applies the `sensitive` wrapper in the places where we're logging target addresses at level "info" or higher.
* | | | Implement a safe-logging facility.Nick Mathewson2022-05-065-0/+656
|/ / / | | | | | | | | | | | | | | | This is a rough first-cut of an API that I think might help us with keeping limited categories of sensitive information out of our logs. I'll refine it based on experiences with using it.
* | | Merge branch 'typos-20220504' into 'main'eta2022-05-054-6/+6
|\ \ \ | |/ / |/| | | | | | | | Fix typos (using the typos-cli tool). See merge request tpo/core/arti!486
| * | Fix typos (using the typos-cli tool).Nick Mathewson2022-05-044-6/+6
| | |
* | | config derive attrs: Make builders serde, and validated structs notIan Jackson2022-05-0511-98/+56
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Builders additionally derive: Debug, Serialize, Deserialize. * Validated structs no longer derive: Serialize, Deserialize and all related attributes deleted. * As a consequence, all the `#[serde(deny_unknown_fields)]` are gone. That means that right now unknown fields are totally ignored. This is good for compatibility but poor for useability. Doing something better here is arti#417, in progress. * As a consequence, delete tor_dirmgr::retry::default_parallelism. (The default value was already duplicated into a builder attr.)
* | | serde attributes: A tiny bit of reorderingIan Jackson2022-05-052-3/+3
| | | | | | | | | | | | Having a consistent order will make the nest commit easier to read.
* | | Make LogRotation SerializeIan Jackson2022-05-051-1/+1
|/ / | | | | | | We want to be able to serialise as well as deserialise configurations.
* | Merge branch 'socket-addr-list-builder' into 'main'Ian Jackson2022-05-049-52/+132
|\ \ | | | | | | | | | | | | FallbackDir: orports: Introduce and use VecBuilder See merge request tpo/core/arti!474
| * | list_builder: Add some xrefs about macro_rules limitationsIan Jackson2022-05-041-0/+8
| | | | | | | | | | | | | | | Apropos https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/474#note_2800481
| * | Fix typoNick Mathewson2022-05-041-1/+1
| | |
| * | FallbackDir: Use VecBuilder for orportsIan Jackson2022-05-046-37/+46
| | | | | | | | | | | | | | | | | | | | | And drop the ad-hoc orport() method. This brings FallbackDir's orports field in line with our list builder API. The general semver note in "configuation" seems to cover most of this.
| * | FallbackDir: Do orport validation after autogenerated buildIan Jackson2022-05-041-5/+11
| | | | | | | | | | | | This avoids it having to recapitulate defaulting logic.