| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
(I also ran them a couple billion iterations, and didn't hit
any bugs.)
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The old code parsed and encoded a signature and a mac... but there
was no way to actually set them properly. Now EstablishIntro is
built around an EstablishIntroBody, and has the ability to check
signatures and macs.
Because there is no way to handle one of these messages if we can't
check the signature, we no longer accept unrecognized `auth_key` types
in this message.
I've added a test to make sure that we can validate a message from the
C tor implementation, and a test to make sure we can validate our
own cells. I also had to modify the previous tests so that their
keys were well-formed.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Expose ED25519 signature length; make ValidatableEd25519Signature
implement Debug and Clone.
|
| | | |
| | |
| | |
| | |
| | | |
We'll use this to implement signature and MAC checking for
EstablishIntro cells.
|
| |\| |
| |/
|/|
| |
| | |
Implement most remaining HS cell types
See merge request tpo/core/arti!1038
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
These are fairly simple, since the bulk of them is just an extension
list with no supported extensions.
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Specifically, RendCookie, Subcredential, HsId, and HsBlindId.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Use humantime in tor-checkable and tor-guardmgr
Closes #663
See merge request tpo/core/arti!1037
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
The four values of times taken in a particular test were changed to both
be human readable and have comments explaining their significance (they
are all important moments after the Unix Epoch for freedom)
|
| | |/
|/|
| |
| |
| | |
https://gitlab.torproject.org/tpo/core/arti/-/issues/715
has been fixed, so there is no need to display such a warning
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
These crates didn't have any changes until now, when I bumped
the versions of some other crates they depend on:
tor-consdiff
arti-hyper
arti-bench
arti-testing
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
These crates have had small code changes, but no API additions:
tor-config
tor-socksproto
tor-cert
tor-chanmgr
tor-ptmgr
tor-guardmgr
tor-circmgr
tor-dirclient
tor-dirmgr
arti
tor-hsservice
tor-congestion
These crates have had API extensions:
fs-mistrust
tor-llcrypto
tor-bytes
tor-checkable
tor-linkspec
tor-netdoc
tor-persist
arti-client
|
| | |
| |
| |
| |
| |
| |
| |
| | |
(The breaking change was removing `as_days()` from IntegerMinutes.)
We are _not_ calling this a downstream-api breaking change, per
discussion at
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1012?commit_id=bb2ab7c2a3e0994bb438188511688b5b039cae29#note_2876819
|
| | |
| |
| |
| |
| |
| | |
These are API breaks, but the crates themselves are currently
100% experimental, so there's no need to bump the minor versions
according to our semver rules.
|
| | |
| |
| |
| | |
This includes tor-cell, tor-proto, and tor-netdir.
|
| | | |
|
| | |
| |
| |
| | |
Fixes #756
|
| |\ \
| |/
|/|
| |
| |
| |
| | |
tor-proto: Introduce CmdChecker, and use it to enforce correctness for our streams.
Closes #774 and #769
See merge request tpo/core/arti!1026
|
| | | |
|
| | |
| |
| |
| | |
It can now indicate _any_ cell that means we can forget about a stream.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This change makes sure that open streams and half-closed streams
have the same stream-type-dependent state machines with respect to
which cells are acceptable.
Fixes #774.
Fixes #769.
|
| | |
| |
| |
| |
| |
| |
| |
| | |
The role of CmdChecker is to verify that messages are arriving at
the appropriate sequence on a stream, with respect to the other
messages that have been received. Once the stream becomes
half-closed, the CmdChecker is also in charge of consuming incoming
messages on the stream and making sure that they are well-formed.
|
| | | |
|
| | |
| |
| |
| |
| | |
docsrs wants to find its `cfg_attr(docsrs...)` line after the
`cfg()` line.
|
| |\ \
| | |
| | |
| | |
| | | |
HsDesc: Use a new UnparsedLinkSpecifier to avoid leaking which linkspec types we know
See merge request tpo/core/arti!1029
|
| | | | |
|
| | |/
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Unlike linkspec, this doesn't validate the actual contents of the
specifiers. We'll use this so we can handle the linkspec list for an
introduction point in an HsDesc, and just pass it on when
constructing our circuits.
I haven't added any accessor or constructor functions, because I
don't expect to need them.
|
| |\ \
| | |
| | |
| | |
| | | |
netdoc: Remove a TODO hs comment.
See merge request tpo/core/arti!1028
|
| | |/
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
It said to check whether C enforces an absence of extraneous bytes
at the end of the link specifiers. It does, in
`hs_desc.c:decode_link_specifiers()`, where it says:
```
if (link_specifier_list_parse(&specs, decoded,
(size_t) decoded_len) < decoded_len) {
goto err;
}
```
The comparison with "decoded_len" checks whether all the bytes were
decoded.
|
| |/
|
|
|
|
|
| |
Some code in our tests that worked fine with time 0.3.17 no
longer works with 0.3.19, despite the semver.
See https://github.com/time-rs/time/issues/552 for the upstream bug.
|
| |\
| |
| |
| |
| |
| |
| | |
tor-netdoc: Abolish PauseAt in favour of using itertools
Closes #760
See merge request tpo/core/arti!1021
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Nothing uses these now; the NetDocReader is simply an iterator, itself.
|
| | | |
|
| | |
| |
| |
| | |
This simplifies the return type!
|
| | |
| |
| |
| | |
This will simplify things at many call sites.
|
| | |
| |
| |
| | |
We're going to want this a bit more widely.
|