summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | tor-hsservice: Add TODO about rethinking the HSS StateMgr API.Gabriela Moldovan2023-12-141-0/+3
| | | |
| * | | arti: Print out the onion address retrieved from StateMgr.Gabriela Moldovan2023-12-141-1/+15
| | | |
| * | | tor-hsservice: Add an hss state mgmt APIGabriela Moldovan2023-12-142-0/+47
| | | |
| * | | arti-client: Add an accessor for the keystore config.Gabriela Moldovan2023-12-142-0/+6
| | | |
| * | | arti: Add an hss subcommand.Gabriela Moldovan2023-12-141-2/+46
| | |/ | |/| | | | | | | Part of #1071
* | | ChannelState::ready_to_expire: return true when rem time is zeroJim Newsome2023-12-131-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a race condition that would normally be fairly benign - it would result in scheduling to check for expired channels again immediately, and assuming non-zero time passes would then remove the channel. In Shadow's default time model though, zero time passes in this case, so we just keep scheduling to check again immediately forever; i.e. deadlock.
* | | ChannelState::ready_to_expire: refactor using let-elseJim Newsome2023-12-131-18/+14
| | |
* | | continually_expire_channels: don't round off expiration delayJim Newsome2023-12-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | Without this change, if the delay is less than one second, the code will effectively busy-loop until the delay has elapsed. This potentially leads to deadlock in shadow simulations, and wastes CPU in real usage. https://shadow.github.io/docs/guide/limitations.html?highlight=busy#busy-loops
* | | continually_expire_channels: refactor using let-elseJim Newsome2023-12-131-3/+2
|/ /
* | Merge branch 'todos-hss' into 'main'Nick Mathewson2023-12-133-25/+29
|\ \ | | | | | | | | | | | | Clear away some misc todos in tor-hsservice. See merge request tpo/core/arti!1819
| * | hss: Explain why wait_for_netdir_to_list does not need more complexity.Nick Mathewson2023-12-131-6/+11
| | |
| * | hss::svc::netdir: Explain why it is okay to suppress errors.Nick Mathewson2023-12-121-1/+3
| | |
| * | hss::config: Downgrade or remove some TODO HSS comments.Nick Mathewson2023-12-121-16/+15
| | |
| * | hss: remove TODO about making DangerouslyNonAnonymous conditional.Nick Mathewson2023-12-121-2/+0
| | |
* | | Merge branch 'log_hsid_unconditionally' into 'main'Nick Mathewson2023-12-131-14/+20
|\ \ \ | | | | | | | | | | | | | | | | hsservice: Log hsid whether we just generated it or not. See merge request tpo/core/arti!1830
| * | | tor-hsservice: Retrieve the public hsid for logging purposes.gabi-2502023-12-131-3/+3
| | | |
| * | | hsservice: Log hsid whether we just generated it or not.Nick Mathewson2023-12-131-14/+20
| | | | | | | | | | | | | | | | | | | | | | | | With this change you can find your hsid in your logs (if safe logging is off) even if you forgot to notice it the first time around.
* | | | Merge branch 'keymgr_enabled_default' into 'main'Nick Mathewson2023-12-132-24/+14
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | arti_client: Cleanup around keymgr feature and config See merge request tpo/core/arti!1832
| * | | | arti_config: remove experimental-api as way to enable keymgr.Nick Mathewson2023-12-131-7/+4
| | | | | | | | | | | | | | | | | | | | | | | | | keymgr is always on when it is needed, so experimental-api isn't needed here.
| * | | | arti-client: use sub_builder for ArtiNativeKeystoreConfigNick Mathewson2023-12-132-10/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The sub_builder pattern changes `StorageConfigBuilder` so that instead of holding an `Option<ArtiNativeKeystoreConfig>`, it holds an `ArtiNativeKeystoreConfigBuilder`. This makes it a little more ergonomic to use from Rust, and lets us use defaults for the builder fields so that we can make them optional in our configuration.
| * | | | arti_client: enable keymgr when keymgr feature is configuredNick Mathewson2023-12-131-11/+9
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | This change causes arti_client to have a configurable keymgr when the onion-service-service feature is present, so that you no longer need to configure "experimental" or "experimental-api" as well in order to get a working onion service.
* | | | Merge branch 'circmgr_warning' into 'main'Nick Mathewson2023-12-131-2/+3
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | circmgr:Resolve a warning when building without ntor-v3 See merge request tpo/core/arti!1831
| * | | | circmgr:Resolve a warning when building without ntor-v3Nick Mathewson2023-12-131-2/+3
| |/ / /
* | | | Merge branch 'publisher-do-not-retry-fatal' into 'main'gabi-2502023-12-131-16/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-hsservice: If the error is fatal, do not retry the desc upload. See merge request tpo/core/arti!1821
| * | | | tor-hsservice: If the error is fatal, do not retry the desc upload.Gabriela Moldovan2023-12-131-16/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The errors returned by `upload_all` are now all fatal, so we there is no point in retrying `upload_all` on failure. Note this will exacerbate #1155, as it will cause the seemingly transient time skew issues to become fatal (the corresponding error type is `Bug`, so in principle they ought to be fatal)
* | | | | arti-client: TorClient.storage_mistrust: Correct doc commentIan Jackson2023-12-131-1/+6
| | | | |
* | | | | tor-hsservice: Add more explanation of replay_log lockingIan Jackson2023-12-131-0/+5
| | | | |
* | | | | tor-hsservice: Add more explanation of replay_log lockingIan Jackson2023-12-131-0/+6
| | | | |
* | | | | tor-hsservice: Cargo.toml: sortIan Jackson2023-12-131-1/+1
| | | | |
* | | | | tor-hsservice: replay: Note a bugIan Jackson2023-12-131-0/+4
| | | | |
* | | | | tor-hsservice: Make IPT logs be persistent (fmt)Ian Jackson2023-12-131-1/+3
| | | | |
* | | | | tor-hsservice: Make IPT logs be persistentIan Jackson2023-12-133-7/+88
| | | | |
* | | | | tor-hsservice ipt_mgr: Rename STORAGE_RETRY from KEYSTORE_RETRYIan Jackson2023-12-131-2/+2
| | | | | | | | | | | | | | | | | | | | We're going to reuse this for other kinds of storage error.
* | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgr (fmt)Ian Jackson2023-12-131-5/+2
| | | | |
* | | | | tor-hsservice: Plumb state dir and its mistrust into ipt_mgrIan Jackson2023-12-134-4/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed for the replay logs. It's a shame that CheckedDir is (i) a bit unergonomic (ii) has an extra bool in it, or we could pass one of those instead of these two arguments. Since HS's might be created after startup, TorClient must have these fields.
* | | | | arti-client: Centralise state_dir variable (fmt)Ian Jackson2023-12-131-5/+2
| | | | |
* | | | | arti-client: Centralise state_dir variableIan Jackson2023-12-131-3/+4
| | | | | | | | | | | | | | | | | | | | | | | | | Call expand_state_dir only once. We'll reuse this value, another time, too.
* | | | | tor-hsservice tests: replay: Pass nick to ↵Ian Jackson2023-12-131-1/+2
| | | | | | | | | | | | | | | | | | | | create_storage_handles_from_state_mgr (fmt)
* | | | | tor-hsservice tests: replay: Pass nick to create_storage_handles_from_state_mgrIan Jackson2023-12-132-3/+6
| | | | | | | | | | | | | | | | | | | | | | | | | This will allow us to more faithfully model the actual Arti state directory layout.
* | | | | tor-hsservice tests: replay: Provide for a filesystem lockfileIan Jackson2023-12-132-2/+23
| | | | | | | | | | | | | | | | | | | | | | | | | This is to prevent current use of the same directory of replay logs by different instances.
* | | | | tor-hsservice tests: replay: Break out create_loggedIan Jackson2023-12-131-13/+25
| | | | |
* | | | | tor-hsservice: Move ReplayLog construction to ipt_mgrIan Jackson2023-12-132-9/+19
| | | | |
* | | | | tor-hsservice: Note some TODOs relating to IPT teardownIan Jackson2023-12-131-0/+9
| | | | |
* | | | | tor-hsservice: ReplayLog: Fix file magicIan Jackson2023-12-131-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This ought to have the hash algorithm name in it or we'll have trouble if we want to change the hash algorithm in the future. (Strictly, we could just choose a different magic but the string was rather short.) Add a newline, which is often convenient in file headers. And "onion" to mean "onion swervice" is improper.
* | | | | tor-hsservice: ReplayLog: Slight tidying upIan Jackson2023-12-131-3/+5
| | | | | | | | | | | | | | | | | | | | Make `#[cfg(target_family = "unix")]` appear only once.
* | | | | tor-persist: Provide FsMistrustErrorExt, and use itIan Jackson2023-12-137-12/+68
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This code needs fs_mistrust::Error and tor_error::ErrorKind. I think we probably don't want fs_mistrust to depend on tor_error or vice versa. tor_persist is approximately the place where these two threads of thought come together, and it's currently the lowest place where this is needed. Use it in tor-dirmgr too, which is currently the other place that embodies this knowledge about fs_mistrust::Error.
* | | | | fs-mistrust: Explain where a Verifier comes fromIan Jackson2023-12-131-0/+2
|/ / / /
* | | | Merge branch 'wallclock-time' into 'main'gabi-2502023-12-131-1/+3
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP. Closes #1155 See merge request tpo/core/arti!1828
| * | | | tor-hscrypto: Return 0 if the timestamp is before the start of the TP.Gabriela Moldovan2023-12-131-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | #1155 was happening because we couldn't compute the offset of the current time from the start of the _next_ TP (`TimePeriod::offset_within_period` expected `when` to come after the start of the TP). `TimePeriod::offset_within_period` now returns an offset of 0 for timestamps that come before the start of the TP, to support computing revision counters for the descriptors uploaded to the HsDirs from the ring associated with the next TP. Fixes #1155
* | | | | Merge branch 'publisher-errors' into 'main'gabi-2502023-12-137-227/+209
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Replace ReactorError with FatalError See merge request tpo/core/arti!1812