summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | hss: remove TODO about making DangerouslyNonAnonymous conditional.Nick Mathewson2023-12-121-2/+0
| | |
* | | Merge branch 'log_hsid_unconditionally' into 'main'Nick Mathewson2023-12-131-14/+20
|\ \ \ | | | | | | | | | | | | | | | | hsservice: Log hsid whether we just generated it or not. See merge request tpo/core/arti!1830
| * | | tor-hsservice: Retrieve the public hsid for logging purposes.gabi-2502023-12-131-3/+3
| | | |
| * | | hsservice: Log hsid whether we just generated it or not.Nick Mathewson2023-12-131-14/+20
| | | | | | | | | | | | | | | | | | | | | | | | With this change you can find your hsid in your logs (if safe logging is off) even if you forgot to notice it the first time around.
* | | | Merge branch 'keymgr_enabled_default' into 'main'Nick Mathewson2023-12-132-24/+14
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti_client: Cleanup around keymgr feature and config See merge request tpo/core/arti!1832
| * | | | arti_config: remove experimental-api as way to enable keymgr.Nick Mathewson2023-12-131-7/+4
| | | | | | | | | | | | | | | | | | | | | | | | | keymgr is always on when it is needed, so experimental-api isn't needed here.
| * | | | arti-client: use sub_builder for ArtiNativeKeystoreConfigNick Mathewson2023-12-132-10/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The sub_builder pattern changes `StorageConfigBuilder` so that instead of holding an `Option<ArtiNativeKeystoreConfig>`, it holds an `ArtiNativeKeystoreConfigBuilder`. This makes it a little more ergonomic to use from Rust, and lets us use defaults for the builder fields so that we can make them optional in our configuration.
| * | | | arti_client: enable keymgr when keymgr feature is configuredNick Mathewson2023-12-131-11/+9
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | This change causes arti_client to have a configurable keymgr when the onion-service-service feature is present, so that you no longer need to configure "experimental" or "experimental-api" as well in order to get a working onion service.
* | | | Merge branch 'circmgr_warning' into 'main'Nick Mathewson2023-12-131-2/+3
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | circmgr:Resolve a warning when building without ntor-v3 See merge request tpo/core/arti!1831
| * | | | circmgr:Resolve a warning when building without ntor-v3Nick Mathewson2023-12-131-2/+3
| |/ / /
* | | | Merge branch 'publisher-do-not-retry-fatal' into 'main'gabi-2502023-12-131-16/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-hsservice: If the error is fatal, do not retry the desc upload. See merge request tpo/core/arti!1821
| * | | | tor-hsservice: If the error is fatal, do not retry the desc upload.Gabriela Moldovan2023-12-131-16/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The errors returned by `upload_all` are now all fatal, so we there is no point in retrying `upload_all` on failure. Note this will exacerbate #1155, as it will cause the seemingly transient time skew issues to become fatal (the corresponding error type is `Bug`, so in principle they ought to be fatal)
* | | | | arti-client: TorClient.storage_mistrust: Correct doc commentIan Jackson2023-12-131-1/+6
| | | | |
* | | | | tor-hsservice: Add more explanation of replay_log lockingIan Jackson2023-12-131-0/+5
| | | | |
* | | | | tor-hsservice: Add more explanation of replay_log lockingIan Jackson2023-12-131-0/+6
| | | | |
* | | | | tor-hsservice: Cargo.toml: sortIan Jackson2023-12-131-1/+1
| | | | |
* | | | | tor-hsservice: replay: Note a bugIan Jackson2023-12-131-0/+4
| | | | |
* | | | | tor-hsservice: Make IPT logs be persistent (fmt)Ian Jackson2023-12-131-1/+3
| | | | |
* | | | | tor-hsservice: Make IPT logs be persistentIan Jackson2023-12-133-7/+88
| | | | |
* | | | | tor-hsservice ipt_mgr: Rename STORAGE_RETRY from KEYSTORE_RETRYIan Jackson2023-12-131-2/+2
| | | | | | | | | | | | | | | | | | | | We're going to reuse this for other kinds of storage error.
* | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgr (fmt)Ian Jackson2023-12-131-5/+2
| | | | |
* | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgrIan Jackson2023-12-134-4/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed for the replay logs. It's a shame that CheckedDir is (i) a bit unergonomic (ii) has an extra bool in it, or we could pass one of those instead of these two arguments. Since HS's might be created after startup, TorClient must have these fields.
* | | | | arti-client: Centralise state_dir variable (fmt)Ian Jackson2023-12-131-5/+2
| | | | |
* | | | | arti-client: Centralise state_dir variableIan Jackson2023-12-131-3/+4
| | | | | | | | | | | | | | | | | | | | | | | | | Call expand_state_dir only once. We'll reuse this value, another time, too.
* | | | | tor-hsservice tests: replay: Pass nick to ↵Ian Jackson2023-12-131-1/+2
| | | | | | | | | | | | | | | | | | | | create_storage_handles_from_state_mgr (fmt)
* | | | | tor-hsservice tests: replay: Pass nick to create_storage_handles_from_state_mgrIan Jackson2023-12-132-3/+6
| | | | | | | | | | | | | | | | | | | | | | | | | This will allow us to more faithfully model the actual Arti state directory layout.
* | | | | tor-hsservice tests: replay: Provide for a filesystem lockfileIan Jackson2023-12-132-2/+23
| | | | | | | | | | | | | | | | | | | | | | | | | This is to prevent current use of the same directory of replay logs by different instances.
* | | | | tor-hsservice tests: replay: Break out create_loggedIan Jackson2023-12-131-13/+25
| | | | |
* | | | | tor-hsservice: Move ReplayLog construction to ipt_mgrIan Jackson2023-12-132-9/+19
| | | | |
* | | | | tor-hsservice: Note some TODOs relating to IPT teardownIan Jackson2023-12-131-0/+9
| | | | |
* | | | | tor-hsservice: ReplayLog: Fix file magicIan Jackson2023-12-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This ought to have the hash algorithm name in it or we'll have trouble if we want to change the hash algorithm in the future. (Strictly, we could just choose a different magic but the string was rather short.) Add a newline, which is often convenient in file headers. And "onion" to mean "onion swervice" is improper.
* | | | | tor-hsservice: ReplayLog: Slight tidying upIan Jackson2023-12-131-3/+5
| | | | | | | | | | | | | | | | | | | | Make `#[cfg(target_family = "unix")]` appear only once.
* | | | | tor-persist: Provide FsMistrustErrorExt, and use itIan Jackson2023-12-137-12/+68
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This code needs fs_mistrust::Error and tor_error::ErrorKind. I think we probably don't want fs_mistrust to depend on tor_error or vice versa. tor_persist is approximately the place where these two threads of thought come together, and it's currently the lowest place where this is needed. Use it in tor-dirmgr too, which is currently the other place that embodies this knowledge about fs_mistrust::Error.
* | | | | fs-mistrust: Explain where a Verifier comes fromIan Jackson2023-12-131-0/+2
|/ / / /
* | | | Merge branch 'wallclock-time' into 'main'gabi-2502023-12-131-1/+3
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP. Closes #1155 See merge request tpo/core/arti!1828
| * | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP.Gabriela Moldovan2023-12-131-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | #1155 was happening because we couldn't compute the offset of the current time from the start of the _next_ TP (`TimePeriod::offset_within_period` expected `when` to come after the start of the TP). `TimePeriod::offset_within_period` now returns an offset of 0 for timestamps that come before the start of the TP, to support computing revision counters for the descriptors uploaded to the HsDirs from the ring associated with the next TP. Fixes #1155
* | | | | Merge branch 'publisher-errors' into 'main'gabi-2502023-12-137-227/+209
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Replace ReactorError with FatalError See merge request tpo/core/arti!1812
| * | | | | tor-hsservice: Add TODO about removing the shutdown handling from the publisher.Gabriela Moldovan2023-12-131-0/+5
| | | | | |
| * | | | | tor-hsservice: Add TODO about changing a return type in ipt_set.Gabriela Moldovan2023-12-131-0/+5
| | | | | |
| * | | | | tor-hsservice: Add TODO about possibly making UploadStatus a type alias.Gabriela Moldovan2023-12-131-0/+2
| | | | | |
| * | | | | tor-hsservice: Add TODO about possibly retrying failed uploads.Gabriela Moldovan2023-12-131-0/+6
| | | | | |
| * | | | | tor-hsservice: Remove unused ReactorError type.Gabriela Moldovan2023-12-131-84/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher now returns `FatalError`s, so we don't need `ReactorError` anymore. Addresses a TODO HSS in publish/reactor.rs Part of #1129
| * | | | | tor-hsservice: Replace ReactorError with FatalError (fmt).Gabriela Moldovan2023-12-132-9/+6
| | | | | |
| * | | | | tor-hsservice: Replace ReactorError with FatalError.Gabriela Moldovan2023-12-132-30/+29
| | | | | |
| * | | | | tor-hsservice: Add a NetdirProviderShutdown FatalError variant.Gabriela Moldovan2023-12-131-1/+7
| | | | | | | | | | | | | | | | | | | | | | | | This is another type of fatal error.
| * | | | | tor-hsservice: Add a FatalError::from_spawn.Gabriela Moldovan2023-12-131-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | We're about to use this (in the publisher reactor).
| * | | | | tor-hsservice: Replace ReactorError::ShuttingDown with ShutdownStatus.Gabriela Moldovan2023-12-131-13/+33
| | | | | |
| * | | | | tor-hsservice: Make descriptor publisher wait for shutdown signal.Gabriela Moldovan2023-12-133-3/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The publisher logs a nice `info!` message when it receives the shutdown signal. The publisher can infer that the service is shutting down from the errors received on its various receiver channels (i.e. from the errors that suggest the sender was dropped), but listening for the shutdown signal is nicer.
| * | | | | tor-hsservice: Move ShutdownStatus to svc.Gabriela Moldovan2023-12-132-16/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will be used by the descriptor publisher soon (we want to abolish its `ReactorError` altogether, and to do that, we need to get rid of `ReactorError::ShuttingDown`. `ShuttingDown::Terminate` happens to be a suitable replacement).
| * | | | | tor-hsservice: Remove unused ReactorError variant.Gabriela Moldovan2023-12-131-5/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This moves us one step closer to removing ReactorError in favour of FatalError (see the TODO HSS above ReactorError for more details).