summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * Rename DirSkewTolerance to DirToleranceNick Mathewson2022-07-226-11/+19
| | | | | | | | | | | | This name is more accurate because we aren't only dealing with clock skew here: we're also trying to tolerate the case where the authorities fail to reach consensus for a while.
* | use Ed25519 identity instead of PublicKey in tor-cert::rsatrinity-1686a2022-07-251-2/+2
| |
* | fix nighly clippytrinity-1686a2022-07-235-14/+9
| |
* | change usage of PublicKey to Ed25519 in tor-certtrinity-1686a2022-07-239-43/+43
| | | | | | | | and propagate to other affected crates
* | change check_key to take a Option<&_> instead of &Option<_>trinity-1686a2022-07-238-12/+13
| |
* | Fix compilation of EstablishInto encoding.Nick Mathewson2022-07-221-2/+3
| | | | | | | | It was based on the old `Writeable` API.
* | Merge branch 'hs-cells' into 'main'eta2022-07-224-1/+89
|\ \ | |/ |/| | | | | Implement ESTABLISH_INTRO relay cell See merge request tpo/core/arti!626
| * Implement ESTABLISH_INTRO relay cellYuan Lyu2022-07-184-1/+89
| |
* | arti-client: Split "Persist" into setup and access variants.Nick Mathewson2022-07-212-5/+16
| |
* | arti_client: turn "Proto" error into StreamFailed.Nick Mathewson2022-07-212-6/+22
| |
* | arti_client: Split DirMgr error into useful types.Nick Mathewson2022-07-213-6/+15
| |
* | arti-client: minor edits in error messages and commentsNick Mathewson2022-07-211-17/+20
| |
* | Also downgrade serde_with: Version 2.0 requires Rust 1.60Nick Mathewson2022-07-201-1/+1
| |
* | Downgrade phf back to 0.10Nick Mathewson2022-07-201-1/+1
| | | | | | | | | | It turns out that phf 0.11 depends on Rust 1.60, which is above our MSRV.
* | disable-fs-permission-checks: remove variable from help messageJim Newsome2022-07-191-1/+0
| | | | | | | | | | This option doesn't take an argument. This change drops the argument from the `--help` message.
* | Upgrade to latest phf, serde_with, serial_test.Nick Mathewson2022-07-192-3/+3
| |
* | Bump to rusqlite 0.28.Nick Mathewson2022-07-191-1/+1
| |
* | Merge branch 'mistrust-envvar' into 'main'Nick Mathewson2022-07-1910-106/+257
|\ \ | | | | | | | | | | | | | | | | | | Move environment-variable checking into fs-mistrust Closes #483 See merge request tpo/core/arti!630
| * | fs-mistrust: accept "n" as "no".Nick Mathewson2022-07-191-2/+2
| | |
| * | Semver tweaks from review.Ian Jackson2022-07-192-2/+2
| | | | | | | | | | | | These aren't user facing comments, but getting them right will help us write better changelogs.
| * | arti-client: Remove code related to overriding fs-mistrust.Nick Mathewson2022-07-193-45/+8
| | | | | | | | | | | | | | | | | | | | | | | | This logic can now be adjusted via the config object so that it does its own overriding by looking at the environment as appropriate. Removing these methods helps simplify the code a bit. Enabled by #483.
| * | Arti: Use synthetic argument to implement --disable-fs-permission-checksNick Mathewson2022-07-192-22/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now that configuring the environment variables related to fs permissions works properly, we don't need to use the "override" feature any more: we can just add the option to the configuration when appropriate. With this design, `--disable-fs-permission-checks` is now mostly an alias for `--option storage.permissions.dangerously_trust_everyone=true` Enabled by #483.
| * | Move responsibility for disable-fs-mistrust envvar.Nick Mathewson2022-07-194-37/+22
| | | | | | | | | | | | | | | | | | | | | The variable is now handled when building the configuration, and no longer needs to be special-cased. Closes #483.
| * | fs-mistrust: API to disable based on environmentNick Mathewson2022-07-194-5/+218
| | | | | | | | | | | | | | | | | | | | | By default we look at `$FS_MISTRUST_DISABLE_PERMISSIONS_CHECKS`. Optionally, the user can provide another variable as well, or disable looking at the environment entirely.
* | | Merge branch 'fallible_writers_v2' into 'main'Nick Mathewson2022-07-1930-346/+551
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Revise tor_bytes::Writer::write to return a Result. Closes #513 See merge request tpo/core/arti!623
| * | | Apply 1 suggestion(s) to 1 file(s)eta2022-07-191-1/+1
| | | |
| * | | Remove the last vestiges of write_infallible.Nick Mathewson2022-07-113-41/+7
| | | | | | | | | | | | | | | | | | | | Now that everything has been converted to fallible writers, we get to finally remove write_infallible() from tor_bytes.
| * | | tor-proto: Stop using write_infallible in handshake code.Nick Mathewson2022-07-115-138/+196
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This change was a bit annoying, since most of this code _can't_ fail, and so the only reasonable response is to wrap the input in an internal error... except for one case where we're actually encoding a caller-provided message, so we _do_ want to wrap the EncodeError from tor_bytes.
| * | | tor-cell: Stop using write_infallibleNick Mathewson2022-07-113-37/+69
| | | | | | | | | | | | | | | | Also, stop using "expect" and "assert!" to check for errors.
| * | | tor-cell: Make encoding method signatures fallible.Nick Mathewson2022-07-1111-56/+106
| | | |
| * | | tor-linkspec: Stop using infallible writers.Nick Mathewson2022-07-112-7/+11
| | | |
| * | | tor-cert: Remove all usage of infallible writers.Nick Mathewson2022-07-111-1/+1
| | | |
| * | | tor-cert: Encoding now uses Writeable trait.Nick Mathewson2022-07-113-25/+26
| | | | | | | | | | | | | | | | This lets us remove a few TODOs.
| * | | tor-bytes::impls: Remove usage of infallible writers.Nick Mathewson2022-07-111-2/+2
| | | |
| * | | socksproto: Use fallible writers.Nick Mathewson2022-07-113-26/+39
| | | | | | | | | | | | | | | | Also, make private a function that had formerly been `pub`.
| * | | Remove "write_and_consume_infallible".Nick Mathewson2022-07-112-16/+15
| | | | | | | | | | | | | | | | | | | | | | | | There were only a few of these. Removing it required porting everything to use `write_and_consume` instead, and handling its (potential) errors.
| * | | Convert each write_onto_infallible implementation into write_onto.Nick Mathewson2022-07-117-29/+51
| | | |
| * | | Convert each write_into_infallible implementation into write_into.Nick Mathewson2022-07-111-1/+2
| | | | | | | | | | | | | | | | (There was only one.)
| * | | Define new write_into and write_onto methods with correct APIs.Nick Mathewson2022-07-112-6/+56
| | | |
| * | | Rename "write" methods on tor-bytes to "write_infallible".Nick Mathewson2022-07-1112-178/+178
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This comprises four renames: ``` write_onto -> write_onto_infallible write_into -> write_into_infallible write -> write_infallible writer_and_consume -> write_and_consume_infallible. ``` The rest of this branch will be concerned with replacing these `_infallible` methods with ones that return a `Result`. This is part of #513.
| * | | Add a Bug variant to tor-bytes::EncodeError.Nick Mathewson2022-07-112-2/+11
| | | | | | | | | | | | | | | | This will help down the line as we make more writers fallible.
* | | | Merge branch 'eq' into 'main'eta2022-07-191-1/+1
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | tor-cell: Derive Eq for NtorV3Extension See merge request tpo/core/arti!631
| * | | tor-cell: Derive Eq for NtorV3ExtensionIan Jackson2022-07-181-1/+1
| | | | | | | | | | | | | | | | Apropos clippy complaint.
* | | | Merge branch 'dormant' into 'main'Ian Jackson2022-07-194-24/+207
|\ \ \ \ | |_|_|/ |/| | | | | | | | | | | Make dormant be a postage::watch See merge request tpo/core/arti!632
| * | | tor-basic-utils: Add a test for DropNotifyWatchSenderIan Jackson2022-07-191-0/+17
| | | |
| * | | tor-basic-utils: Add ref to upstream issue re dropIan Jackson2022-07-191-0/+3
| | | |
| * | | tor-basic-utils: Add comment about lack of raceIan Jackson2022-07-191-0/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | In answer to https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/632#note_2822107 I think this is subtle enough that it deserves a comment.
| * | | arti-client: Do periodic task dormancy in a management taskIan Jackson2022-07-181-37/+28
| | | | | | | | | | | | | | | | | | | | This means that it is no longer possible to write code which updates the dormant mode but forgets to notify the periodic tasks.
| * | | arti-client: Make dormant_mode be an Option, None on dropIan Jackson2022-07-181-13/+27
| | | | | | | | | | | | | | | | | | | | This will allow receivers (which we are about to introduce) to terminate when the last client is dropped.
| * | | arti-client: Provide DropNotifyWatchSenderIan Jackson2022-07-181-0/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There are going to be some tasks (well, right away, one task) which will want to go away when the sender is dropped. The docs in postage are silent, but postage::watch::Sender does not have a Drop impl so I don't think we can rely on the Receivers getting None from their Stream impl. So we're going to have the watch send Options, which are None only when the sender is dropped.