| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
And clarify docs for the *current* ipt functions.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
"current" has a special meaning here: it means an IPT that we haven't
replaced with another at the same relay due to number of requests.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
On Windows filenames are WTF-16, not bytes, so a weird filename fails
to be UTF-16 rather than failing to be UTF-8.
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
The private ExpiryError type is now err::StateExpiryError.
We'll fix up the local alias in the HasKind impl in a moment.
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | |/ /
| | |
| | |
| | |
| | | |
The non-visibility of this method seems like it must have been an
oversight.
|
| |/ /
| |
| |
| |
| |
| | |
If one of the upload results is for an HsDir that went away, the
publisher should continue processing the remaining ones, not disregard
them entirely.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor_cell: Reject empty DATA messages
Closes #1269
See merge request tpo/core/arti!1981
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
We never actually constructed these before, but now we enforce it at
the API level.
Part of #1269.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
If we don't reject these, they are a way to inject an undetected
traffic signal. (This is LOW severity, since we only accept DATA
when a stream is open, since DATA messages are rate-limited,
and since using length==1 is nearly as effective.)
Closes #1269.
This is TROVE-2024-001.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
tor-hsservice: Expire old on-disk IPT state
See merge request tpo/core/arti!1977
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
This test detects the bug mentioned here
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2995265
|
| | | | |
|
| | | |
| | |
| | |
| | | |
This isn't strictly necessary, but it's better.
|
| | | |
| | |
| | |
| | | |
This seemed to warrant some discussion and a cross-reference.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2994999
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2995000
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2994998
Removing the intermediate variable removes the possibility that the
information in it could fail to be transferred to the main mutable
state, so we don't need the IEFE any more.
|
| | | |
| | |
| | |
| | | |
We do have some tests, but they're not as comprehensive as we'd like.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
Without this, we can regenerate the same IptLocalIds (etc.) on
shutdown/restart (which involves calling startup again within a test
case).
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
Indentation left anmolaous briefly for ease of review.
|
| | | |
| | |
| | |
| | |
| | | |
The expiry code is going to want this too. We should at least make a
constant of it.
|
| | | | |
|
| | |/
| |
| |
| |
| |
| |
| |
| | |
We shouldn't keep the same IPT relays just because they're not
working! Firstly, that's just silly, and secondly, for privacy
reasons we want to put a limit on teh lifetime anyway.
Indentation left anmolaous briefly for ease of review.
|
| | | |
|
| | |
| |
| |
| | |
The old link now 404s, so let's link to spec.torproject.org instead.
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Part of #1241
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
According to the spec, the publisher needs to periodically reupload the
descriptor.
```
Specifically, every time a hidden service publishes its descriptor, it also sets up a timer for a random time
between 60 minutes and 120 minutes in the future. When the timer triggers, the hidden service needs to
publish its descriptor again to the responsible HSDirs for that time period. [TODO SPEC: Control republish period
using a consensus parameter?]
```
After each `upload_for_time_period()`, the publisher now sets a timer as
described in the spec, by pushing a `ReuploadTimer` into its
`reupload_timers` heap.
Closes #1241
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| | |
We will soon need the ability to trigger a descriptor reupload for a
specific time period.
Part of #1241
|
| | |
| |
| |
| | |
Will make the situation in #1264 clear, I think.
|
| | | |
|
| |/
|
|
|
|
|
|
|
| |
Something libtest is doing hides the child stderr/stdout from the test
log, when --nocapture is not given.
With these changes, I see much more output in failing cases or with
--nocapture. In the case mentioned in #1264, the message
"we survived raise SIGUSR2" is now printed both with and without --nocapture.
|
| |
|
|
|
|
| |
Reviewing uses of `#[educe(default)]`, I came across these two places
where it was applied to a non-generic struct without any special
attributes on fields. std's derive will do just as well here.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
Since Rust 1.66, std's default works properly for enums, provided that
the default variant is a unit.
Review all uses of `#[educe(default)]` on enums and replace them with
std where possible, which is most of them.
In 1.66 and later, std's `#[derive(Default)]` doesn't infer any
generic bounds on the derived impl, where it's an enum - since the
unit variant can always be constructed. So this change doesn't add
any generic bounds and is not API-visible.
|
| |\
| |
| |
| |
| | |
hsproxy: Improve error messages.
See merge request tpo/core/arti!1973
|