summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'bump-versions-v115' into 'main'arti-v1.1.5Ian Jackson2023-06-0143-306/+306
|\ | | | | | | | | Bump crate versions in preparation for v1.1.5 release. See merge request tpo/core/arti!1211
| * Bump crate versions in preparation for v1.1.5 release.Nick Mathewson2023-06-0143-306/+306
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Generated with the following commands: ``` cargo set-version --bump minor -p tor-cell cargo set-version --bump minor -p tor-linkspec cargo set-version --bump minor -p tor-proto cargo set-version --bump minor -p tor-netdoc cargo set-version --bump minor -p tor-circmgr cargo set-version --bump patch -p tor-cert cargo set-version --bump patch -p tor-basic-utils cargo set-version --bump patch -p tor-rpcbase cargo set-version --bump patch -p tor-llcrypto cargo set-version --bump patch -p tor-hscrypto cargo set-version --bump patch -p tor-checkable cargo set-version --bump patch -p tor-async-utils cargo set-version --bump patch -p caret cargo set-version --bump patch -p fs-mistrust cargo set-version --bump patch -p safelog cargo set-version --bump patch -p retry-error cargo set-version --bump patch -p tor-error cargo set-version --bump patch -p tor-config cargo set-version --bump patch -p tor-events cargo set-version --bump patch -p tor-units cargo set-version --bump patch -p tor-rtcompat cargo set-version --bump patch -p tor-rtmock cargo set-version --bump patch -p tor-protover cargo set-version --bump patch -p tor-bytes cargo set-version --bump patch -p tor-socksproto cargo set-version --bump patch -p tor-consdiff cargo set-version --bump patch -p tor-netdir cargo set-version --bump patch -p tor-congestion cargo set-version --bump patch -p tor-persist cargo set-version --bump patch -p tor-chanmgr cargo set-version --bump patch -p tor-ptmgr cargo set-version --bump patch -p tor-guardmgr cargo set-version --bump patch -p tor-dirclient cargo set-version --bump patch -p tor-dirmgr cargo set-version --bump patch -p tor-hsclient cargo set-version --bump patch -p tor-hsservice cargo set-version --bump patch -p arti-client cargo set-version --bump patch -p arti-rpcserver cargo set-version --bump patch -p arti-config cargo set-version --bump patch -p arti-hyper cargo set-version --bump patch -p arti cargo set-version --bump patch -p arti-bench cargo set-version --bump patch -p arti-testing ```
* | fallbackdir: Update list generated on June 01, 2023Tor CI Release2023-06-011-892/+896
|/ | | | Signed-off-by: Tor CI Release <[email protected]>
* Run fixup-features script and resolve its complaints.Nick Mathewson2023-05-314-4/+9
|
* Merge branch 'stream_ctrl' into 'main'Nick Mathewson2023-05-244-3/+238
|\ | | | | | | | | | | | | Experimental new stream-ctrl feature Closes #847 See merge request tpo/core/arti!1198
| * Add "TODO RPC" notes around DataStreamCtrl per review.Nick Mathewson2023-05-242-0/+16
| |
| * proto: Add stream-status functionality to DataStreamCtrl.Nick Mathewson2023-05-241-2/+106
| | | | | | | | There are some weaknesses and problems here; see TODO notes.
| * proto: Create a `DataStreamCtrl` type.Nick Mathewson2023-05-223-1/+114
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The idea here is that we want to make DataStream visible to the RPC system without requiring that the RPC session hold the DataStream itself (or the Reader, or the Writer). We could solve this problem by making _all_ the state in the DataStream shared, but that would introduce unnecessary extra locking in our critical path. Instead we're creating the notion of a "control handle" that lets you manage and observe a stream without actually owning the stream. Right now the only supported functionality is asking for the stream's circuit. Part of #847
| * proto: Add a new experimental stream-ctrl feature.Nick Mathewson2023-05-221-1/+2
| | | | | | | | | | (It doesn't do anything yet. It may eventually become always-on. But for now let's make this API optional. Part of #847)
| * tor-proto: Move a comment in Cargo.tomlNick Mathewson2023-05-221-1/+2
| |
* | Merge branch 'virtual_conditional' into 'main'Ian Jackson2023-05-242-0/+3
|\ \ | | | | | | | | | | | | proto: Make PathEntry::Virtual feature-conditional. See merge request tpo/core/arti!1201
| * | proto: Make PathEntry::Virtual feature-conditional.Nick Mathewson2023-05-232-0/+3
| | | | | | | | | | | | | | | This fixes a warning when building tor-proto without the `rpc-common` feature.
* | | Merge branch 'rpc-auth-and-meta' into 'main'Nick Mathewson2023-05-247-111/+333
|\ \ \ | | | | | | | | | | | | | | | | rpc: authentication and basic handle manipulation See merge request tpo/core/arti!1200
| * | | rpc: Remove downgrade_owned for nowNick Mathewson2023-05-244-42/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Rationale: Our weak-vs-strong design is a bit confused at the moment due to concerns about deduplication and capability semantics. It's not clear that a general "change strong to weak" method is compatible with what we want to provide.
| * | | rpc: Disable auth:get_rpc_protocol for now.Nick Mathewson2023-05-241-0/+8
| | | |
| * | | rpc: Implement functionality to remove objects from a sessionNick Mathewson2023-05-245-5/+135
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I've made doing some design choices here: * Reserving "rpc" as a prefix for post-authentication functionality that is not arti-specific. * Declaring these to be methods on the session rather than methods on the objects themselves. There's a problem with defining an API to drop a weak reference; see comment in code.
| * | | rpc: fix documentation for methods in Context.Nick Mathewson2023-05-241-6/+4
| | | |
| * | | rpc: Make the top-level returned object a "session".Nick Mathewson2023-05-244-38/+67
| | | | | | | | | | | | | | | | | | | | | | | | This will make it easier to change the semantics of what exactly we return, whether it has to be/contain a client, whether you can use it to look up all the live objects, &etc.
| * | | rpc: Implement auth:query.Nick Mathewson2023-05-231-1/+39
| | | |
| * | | rpc: Implement the auth:get_rpc_protocol method.Nick Mathewson2023-05-231-0/+49
| | | |
| * | | rpc: move existing auth code to new module.Nick Mathewson2023-05-232-72/+84
| |/ /
* | | Merge branch 'real_generational_arena' into 'main'Nick Mathewson2023-05-242-79/+2
|\ \ \ | | | | | | | | | | | | | | | | rpc: Use the real generational-arena crate See merge request tpo/core/arti!1203
| * | | rpc: Remove fake_generational_arenaNick Mathewson2023-05-232-79/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Now that generation-arena has merged [@diziet's patch] to clarify their license, we no longer need to disable it. [@diziet's patch]: https://github.com/fitzgen/generational-arena/pull/56
* | | | cell: Make EstablishRendezvous contain a RendCookie.Nick Mathewson2023-05-232-6/+3
|/ / /
* | | Merge branch 'socks-read-fix' into 'main'Nick Mathewson2023-05-232-0/+25
|\ \ \ | |/ / |/| | | | | | | | | | | | | | Fix a local-only CPU DoS bug. Closes #861 See merge request tpo/core/arti!1196
| * | Fix a local-only CPU DoS bug.Nick Mathewson2023-05-232-0/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, there was a bug in the way that our code used our SOCKS implementations. If the buffer used for a SOCKS handshake became full without completing the handshake, then rather than expanding the buffer or closing the connection, our code would keep trying to read into the zero-byte slice available in the full buffer forever, in a tight loop. We're classifying this as a LOW-severity issue, since it is only exploitable by pluggable transports (which are trusted) and by local applications with access to the SOCKS port. Closes #861. Fixes TROVE-2023-001. Reported-By: Jakob Lell <jakob AT srlabs DOT de>
* | | tor-hsclient: Mockable: Do concrete calls with UFCSIan Jackson2023-05-231-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Method dispatch rules mean that if the receiver type of the actual function changes, `self.call()` can turn into a purely-recursive call which overflows the stack. Async Rust doesn't have the usual warning for this situation :-(. UFCS is clumsier but doesn't have that problem because it involves much less magical dispatch. Instead of generating a recursive call which overflows the stack, it fails to compile.
* | | tor-hsclient: Fix MockableClientCirc for ClientCirc changesIan Jackson2023-05-231-3/+3
| | | | | | | | | | | | | | | | | | ClientCirc::begin_dir_stream now takes Arc<Self>. Method resolution rules mean that this code would just recurse, leading to a stack overflow.
* | | Fix a docs reference to refer to HsClientIntroAuthKeypairIan Jackson2023-05-221-1/+1
| |/ |/| | | | | | | | | | | | | Fixes warning from cargo -o doc --document-private-items --all-features --workspace This was evidentlhy overlooked during recent replacement of unescorted private keys in the code.
* | Upgrade notify dependency to 6.0Nick Mathewson2023-05-221-1/+1
| |
* | Upgrade async-compression dependency to 0.4.0.Nick Mathewson2023-05-221-1/+1
| |
* | Upgrade memmap2 dependency to 0.6.1.Nick Mathewson2023-05-221-1/+1
| |
* | Upgrade serde_with dependency to 3.0.0Nick Mathewson2023-05-222-2/+2
| |
* | tor-rtcompat: Say default-features with a dash, not an underscore.Nick Mathewson2023-05-221-1/+1
|/ | | | (`cargo-upgrade` warns about this.)
* Merge branch 'clippy-nightly' into 'main'Ian Jackson2023-05-224-5/+6
|\ | | | | | | | | Fix a few warnings from clippy nightly See merge request tpo/core/arti!1193
| * chanmgr: fix a unit-default warning from clippy nightly.Nick Mathewson2023-05-181-1/+1
| | | | | | | | | | | | I could also have stopped using `::default()` to construct this (testing-only) object, but I think it makes more sense to turn it into a non-unit object.
| * guardmgr, netdir: fix some needless-mut warningsNick Mathewson2023-05-182-4/+4
| | | | | | | | Found by clippy nightly
| * guardmgr: suppress a clippy-nightly warning.Nick Mathewson2023-05-181-0/+1
| | | | | | | | | | I don't love this change, but apparently we are trying for "consistency".
* | Merge branch 'escorted_25519_secrets' into 'main'Nick Mathewson2023-05-188-89/+119
|\ \ | | | | | | | | | | | | | | | | | | Refactor code not to use unescorted ed25519 secrets Closes #798 See merge request tpo/core/arti!1192
| * | hscrypto: Remove an incorrect comment.Nick Mathewson2023-05-181-5/+0
| | | | | | | | | | | | | | | (It said that we want to deprecate all unescorted secret keys; in fact, only unescorted EdDSA secrets are bad.)
| * | netdoc, hsclient: Update remaining ed25519::SecretKey usersNick Mathewson2023-05-184-25/+24
| | | | | | | | | | | | | | | | | | Fortunately, these are all in experimental code. Closes #798
| * | hscrypto: Replace ed25519 secret keys with keypairsNick Mathewson2023-05-181-42/+32
| | | | | | | | | | | | Part of #798: We no longer use unescorted ed25519 secret keys.
| * | llcrypto: Don't take or return "unescorted" ed25519 keys.Nick Mathewson2023-05-182-20/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Per #798, we want to make sure that we never pass around an `ed25519::SecretKey`; only an `ed25519::Keypair` (or `ExpandedKeypair`). This is because, when you're computing an ed25519 signature, you have to use the public key as one of your inputs, and if you ever use a mismatched public key you are vulnerable to a nonce reuse attack. (For more info see https://moderncrypto.org/mail-archive/curves/2020/001012.html )
| * | llcrypto: Add an `ed25519::ExpandedKeypair` type.Nick Mathewson2023-05-181-0/+25
| | | | | | | | | | | | | | | | | | | | | | | | This is like an `ed25519::Keypair`, except that instead of a `SecretKey` it contains an `ExpandedSecretKey`. We'll be using this to implement #798, where we impose a rule that there must be no "unescorted" ed25519 secret keys.
* | | Merge branch 'virtual_hop' into 'main'Nick Mathewson2023-05-185-38/+245
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | tor-proto: Add support for extending circuits through virtual hops. Closes #726 See merge request tpo/core/arti!1191
| * | proto: Explain "virtual" hops better.Nick Mathewson2023-05-181-0/+4
| | | | | | | | | | | | Based on text from @diziet
| * | proto: Try to improve the documentation in crypto/cell.rsNick Mathewson2023-05-181-24/+86
| | |
| * | proto: Allow circuit Paths to represent virtual hops.Nick Mathewson2023-05-183-14/+57
| | | | | | | | | | | | | | | Sadly, this adds a few more `TODO HS` entries, but I think we can clean them up later after a bit of discussion.
| * | proto: Implement Circuit::extend_virtual.Nick Mathewson2023-05-182-2/+59
| | | | | | | | | | | | | | | | | | | | | There are a few new TODO hs comments, though, and an XXXX I'll need to fix up in the next commit. Implements #726.
| * | tor-proto: Code to construct crypto layers for virtual hops.Nick Mathewson2023-05-183-1/+42
| | | | | | | | | | | | | | | This is fairly straightforward, thanks to our existing design work on this code.