summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-netdir: Reorganise iteration over hsdir ringsIan Jackson2023-03-301-4/+24
| | | | | | | | | | | | | | | Provide iter_for_op, by changing iter into iter_filter_secondary and having a new entrypoint iter.
| * | tor-netdir: Provide relay_by_rs_idxIan Jackson2023-03-301-0/+16
| | |
* | | Generate a new KP_hss_desc_enc keypair for each new descriptor.Gabriela Moldovan2023-03-312-33/+51
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, to build descriptors for hidden services with client auth enabled, in addition to the list of authorized clients, users of `HsDescBuilder` were required to also provide a descriptor encryption keypair and a descriptor cookie. This was potentially dangerous and/or error-prone, because the ephemeral encryption key and the descriptor cookie are expected to be randomly generated and unique for each descriptor. This change makes `ClientAuth` private to the `hsdesc::build` module and updates `HsDescBuilder` to build `ClientAuth`s internally. Users now only need to provide the list of authorized client public keys. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Remove unnecessary test constant.Gabriela Moldovan2023-03-312-14/+8
| | | | | | | | | | | | | | | | | | It's not really needed, it can just be generated at (test) runtime. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Add an encode-decode test for descriptors with client auth.Gabriela Moldovan2023-03-311-23/+96
| | | | | | | | | | | | | | | | | | | | | This adds a test for an `encode -> decode -> encode` flow for a hidden service descriptor with client authorization enabled. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Use constants instead of magic numbers.Gabriela Moldovan2023-03-311-6/+10
| | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Stop requiring the caller to supply `AuthClient`s.Gabriela Moldovan2023-03-315-102/+166
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `AuthClient`s were originally meant to represent parsed `auth-client` lines. In !1070, this struct was repurposed for representing individual authorized clients in the HS descriptor encoder. However, hidden services will likely use a list of public keys to represent the authorized clients rather than a list of `AuthClient`s, as the information from an `AuthClient` (`client_id`, `iv`, `encrypted_cookie`) likely won't be immediately available to the hidden service. This change updates the HS descriptor encoder to represent authorized clients as a list of `curve25519::PublicKey`s. As such, it is now the responsibility of the encoder to create the `client_id`, `iv`, and `encrypted_cookie` using the available keys, the unencrypted descriptor cookie, and HS subcredential. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Remove semver.md files.Nick Mathewson2023-03-318-13/+0
| |/ |/|
* | Remove "publish = false" from tor-hsclient.arti-v1.1.3Nick Mathewson2023-03-311-2/+0
| | | | | | | | It is now a (conditional, experimental) dependency of arti-client.
* | Patchlevel bumps for crates whose dependencies just changed.Nick Mathewson2023-03-3118-26/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These crates had no changes until just a moment ago. But since we updated the versions on some of their dependents, they have now changed themselves. Thus they get patchlevel bumps. ``` tor-rtmock tor-protover tor-socksproto tor-consdiff tor-chanmgr tor-dirclient tor-hsservice ```
* | Bump crate versions that have breaking changesNick Mathewson2023-03-3120-30/+30
| | | | | | | | | | | | | | | | | | | | These crates have had breaking changes. They are pre-1.0, so they get a minor bump. ``` tor-basic-utils tor-config ```
* | Bump patchlevel on crates with non-breaking changesNick Mathewson2023-03-3128-111/+111
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | For these crates, the changes are nontrivial, so we _do_ bump the versions on which their dependent crates depend. Fortunately, since they are all pre-1.0, we don't need to distinguish semver-additions from other changes. (Except for arti, which _is_ post-1.0, but gets a patchlevel bump anyway.) These are unstable crates with breaking changes: ``` tor-hscrypto tor-hsclient ``` These have new or extended APIs: ``` safelog tor-bytes tor-cell tor-linkspec tor-llcrypto tor-proto tor-cert arti-client ``` These have new unstable APIs or features: ``` tor-netdoc tor-circmgr (also broke some unstable APIs) arti (is post-1.0) ``` These have bugfixes only: ``` caret tor-dirmgr ```
* | Bump patchlevel on crates with semver-irrelevant changes.Nick Mathewson2023-03-319-9/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Their dependents are _not_ updated to a more recent version. These bumped the version of a dependency that they don't expose ``` tor-rtcompat fs-mistrust ``` This one had internal refactoring: ``` tor-netdir ``` These had trivial changes only: ``` tor-checkable tor-ptmgr tor-guardmgr arti-hyper arti-bench arti-testing ```
* | tor-hsclient: Fix a doc link.Nick Mathewson2023-03-301-1/+1
| |
* | Merge branch 'fix-broken-doc-links' into 'main'Nick Mathewson2023-03-302-5/+5
|\ \ | | | | | | | | | | | | Fix broken doc link. See merge request tpo/core/arti!1082
| * | Fix broken doc link.Gabriela Moldovan2023-03-272-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a broken doc link I introduced in !1070: ``` error: unresolved link to `crate::doc::hsdesc::build::inner::HsDescInnerBuilder` --> crates/tor-netdoc/src/doc/hsdesc/build/middle.rs:34:11 | 34 | /// [`crate::doc::hsdesc::build::inner::HsDescInnerBuilder`] as described in sections | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `HsDescInnerBuilder` in module `inner` | = note: `-D rustdoc::broken-intra-doc-links` implied by `-D warnings` error: could not document `tor-netdoc` ``` Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Merge branch 'plumb' into 'main'Alexander Færøy2023-03-306-49/+69
|\ \ \ | | | | | | | | | | | | | | | | More plumbing for hs connections See merge request tpo/core/arti!1098
| * | | Run rustfmtIan Jackson2023-03-302-21/+18
| | | | | | | | | | | | | | | | Apply this churn, which I deferred for ease of review.
| * | | arti-client: Call HsCircPool::launch_background_tasksIan Jackson2023-03-301-4/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I found that I had the bug where I forgot to call this function, and reached bad_api_usage!("The circuit launcher wasn't initialized") The possibility of such a bug is a hazard of this API pattern.
| * | | tor-hsconn: Rename ConnError (from HsClientConnError)Ian Jackson2023-03-305-21/+21
| | | | | | | | | | | | | | | | | | | | The old name was unwieldy and other crates can just as well name it by the crate scope.
| * | | arti-client: When making hs conn, wait for bootstrapIan Jackson2023-03-301-0/+3
| | | | | | | | | | | | | | | | | | | | Not doing this was a bug. The bug was possible because of some code duplication between the exit and hs paths. Add a comment about that.
| * | | tor-client: Pass a netdir for each requestIan Jackson2023-03-304-16/+27
| | |/ | |/| | | | | | | | | | This will be more convenient inside tor-hsclient. In arti-client, this mirrors the way TorClient::get_or_launch_exit_circ works.
* | | Merge branch 'send' into 'main'Alexander Færøy2023-03-301-2/+1
|\ \ \ | | | | | | | | | | | | | | | | tor-circmgr: Make take_or_launch_stub_circuit future Send See merge request tpo/core/arti!1096
| * | | tor-circmgr: Make take_or_launch_stub_circuit future SendIan Jackson2023-03-301-2/+1
| |/ / | | | | | | | | | | | | thread_rng() isn't Send. We can fix this by not holding it over an await point.
* | | Merge branch 'ring' into 'main'gabi-2502023-03-301-7/+17
|\ \ \ | | | | | | | | | | | | | | | | tor-netdir: Implement `HsDirRing::find_pos` See merge request tpo/core/arti!1095
| * | | tor-netdir: Implmeent HsDirRing::find_posIan Jackson2023-03-301-2/+3
| | | |
| * | | tor-netdir: Make the hsdir ring be a TiVecIan Jackson2023-03-301-5/+14
| |/ / | | | | | | | | | This eliminates an untyped `usize` index.
* | | Upgrade dependency to latest rusqlite.Nick Mathewson2023-03-301-1/+1
| | |
* | | Upgrade dependency to latest async-native-tls.Nick Mathewson2023-03-301-1/+1
| | |
* | | Move functionality from tor_basic_utils to tor_async_utilsNick Mathewson2023-03-2911-205/+231
| | | | | | | | | | | | | | | This commit is mostly code movement; I'd recommend reviewing it with git's `--color-moved` option.
* | | Make a new empty tor-async-utils crate.Nick Mathewson2023-03-293-0/+71
|/ /
* | Merge branch 'blind' into 'main'Ian Jackson2023-03-292-29/+34
|\ \ | | | | | | | | | | | | key blinding: Use consistent terminology See merge request tpo/core/arti!1085
| * | tor-hscrypto: key blinding: Use consistent terminologyIan Jackson2023-03-281-10/+12
| | | | | | | | | | | | | | | | | | | | | | | | * Don't ever use the words "parameter" or "param". These doesn't appear in the spec anywhere. * Use `h` as the variable name for the unclamped blinding factor, and `blinding_factor` in function names.
| * | tor-llcrypto: key blinding: Use consistent terminologyIan Jackson2023-03-281-19/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Unhelpfully, the spec uses the variable name `h` and the phrase "blinding factor" for both the unclamped and clamped value. The clamped value is internal to the algorithm. In our code: * Don't ever use the word "parameter" or variable name `param`. This doesn't appear in the spec anywhere. * Use `h` for the unclamped blinding factor, and `blinding_factor` for the clamped blinding factor. * Rename `blinding_factor` function to `clamp_blinding_factor`, since in the spec's terminology it takes an (unclamped) "blinding factor" and returns a (clamped) "blinding factor". * State explicitly what thing in the spec the `h` parameters are.
* | | Merge branch 'hspre' into 'main'Ian Jackson2023-03-298-14/+34
|\ \ \ | | | | | | | | | | | | | | | | Miscellanious tidying up (pursuant to HS client work) See merge request tpo/core/arti!1086
| * | | Tidy up an unused import warningIan Jackson2023-03-281-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | Now cargo +stable clippy --locked --offline --workspace --all-targets is clean.
| * | | Pass HS identity to hsclient connection functionIan Jackson2023-03-282-2/+10
| | | | | | | | | | | | | | | | Obviously it will need this!
| * | | Pass HsCircPool to hsclient connect function, not CircMgr (fmt)Ian Jackson2023-03-281-5/+5
| | | |
| * | | Pass HsCircPool to hsclient connect function, not CircMgrIan Jackson2023-03-283-7/+11
| | | | | | | | | | | | | | | | | | | | We separated this out in the circmgr API. This is what the HS client needs. It doesn't want to participate in the general circuit pool.
| * | | Add some missing importsIan Jackson2023-03-283-3/+9
| |/ / | | | | | | | | | | | | | | | | | | | | | Now nailing-cargo +stable clippy -p tor-hsclient --all-features --all-targets actually works. squash! Add some missing imports
* | | arti-client: add accessors for `Blockage`eta2023-03-281-1/+13
| | | | | | | | | | | | Fixes #800.
* | | Remove hard-coded test certs.Gabriela Moldovan2023-03-274-98/+86
| | | | | | | | | | | | | | | | | | We can use a deterministic rng to generate predictable keypairs instead. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Make the HS encoder randomness source injectable.Gabriela Moldovan2023-03-275-50/+46
| | | | | | | | | | | | | | | | | | | | | This makes it possible to plug in a deterministic randomness source for testing. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | tor-netdir: Use `pos` not `idx` in test network constructorsIan Jackson2023-03-271-14/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | There are too many things called "index" here. `idx` could be read to mean the table index `RouterStatusIdx`, the hsdir hash `HsDirIndex`, or an entry in some other one of these tables. Here's, it's just the sequence number of the index in the test netdir. Use `pos` for that. (`seq` would have been another possibility.)
* | | tor-netdir: Use `hsdir_index` for hidden service directory hashval (fmt)Ian Jackson2023-03-271-1/+4
| | |
* | | tor-netdir: Use `hsdir_index` for hidden service directory hashvalIan Jackson2023-03-271-11/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The hidden services directory hashring is a ring of hsdir relays, sorted by a hash that the spec calls the "index". That's `HsDirIndex`. This was a bad idea because the word "index" is seriously overused, but in Arti we must use the same terminology. At least, qualify it everywhere. Now one of these hsdir sort position hashes is always, in our code, an `hsdir_index`. I think this is necessary even inside modules called `hsdir_*`, because those can deal with other kind of "index" too.
* | | tor-netdir: eliminate ref to abolished MdEntryIan Jackson2023-03-271-2/+2
| | | | | | | | | | | | | | | This was removed in c3e74973b4201f71275d8cf4c0c954cfb8d0eba5 netdir: Use an even smaller rep for list of microdescs
* | | tor-netdir: Use `rsidx` consistent for `RouterStatusIdx`Ian Jackson2023-03-272-42/+42
|/ / | | | | | | | | | | | | | | | | This is an `IndexVec` key type. Some places used `idx`, some `rsi`, some `rs_idx`. Use `rsidx` for it everywhere, including in locals, function names, and fields. `rsidx` is a compromise. `rsi` might be a bit opaque, but we want a one-"word" name since it appears inside other names.
* / Use the type system to enforce use of blinded keys.Gabriela Moldovan2023-03-275-29/+79
|/ | | | | | | | | | | | | | | Hidden services use blinded singing keys derived from the identity key to sign descriptor signing keys. Before this patch, the hidden descriptor builder represented its blinded signing keys (`blinded_id`) as plain `ed25519::Keypair`s. This was not ideal, as there was nothing preventing the caller from accidentally initializing `blinded_id` with an unblinded keypair. This introduces a new `HsBlindKeypair` type to represent blinded keypairs. Signed-off-by: Gabriela Moldovan <[email protected]>
* tor_client: Add some example code for BridgeConfig.Nick Mathewson2023-03-241-0/+49
| | | | Closes #791