| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |
| |
| |
| |
| |
| |
| |
| |
| | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1115#note_2894238
And move the "This is the converse" comment to somewhere it actually
appears in public docs. The module-level docs only appear with
--document-private-items because the modules themselves are private.
|
| | |
| |
| |
| |
| | |
I wanted one of these for a test stream. Unaccountably neither
the futures crate, nor tokio, seem to have one!
|
| |\ \
| | |
| | |
| | |
| | | |
tor-error: Introduce ErrorKind::TorDirectoryBroken
See merge request tpo/core/arti!1117
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1117#note_2893986
(Not going to squash this as it has a semantic conflict with !1118, so
needs a little special handling there.)
|
| | | |
| | |
| | |
| | |
| | |
| | | |
We will use this for a lack of HS directories. (These aren't chosen
according to any local restrictions, so the problems with EK::NoPath
and EK::NoExit don't arise.)
|
| | | | |
|
| |/ / |
|
| |\ \
| |/
|/|
| |
| | |
tor-netdoc: Expose some test data (and fix feature builds)
See merge request tpo/core/arti!1106
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Fixes
cargo +stable test --locked --offline F -p tor-netdoc
cargo +stable clippy -p tor-netdoc F --all-targets
for values of F including
--all-features
--features=hs-client
--features=hs-common
--features=hs-service
(nothing)
|
| |\ \
| |/
|/|
| |
| | |
tor-dirclient: Provide HsDescDownloadRequest
See merge request tpo/core/arti!1097
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
I couldn't find a test vector in C Tor. This test case was generated
from the code here.
I'm fairly sure it's right since I managed to get my descriptor
downloader to work. (That's not an MR yet, but uses this code.)
|
| | |
| |
| |
| |
| | |
In my tests this seems to do the right thing, but I'm getting 404s.
I'm not sure if actually this URL is wrong.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-llcrypto: Pin x25519-dalek version, bump our crate version
Closes #807
See merge request tpo/core/arti!1108
|
| | | |
| | |
| | |
| | | |
Fixes #807
|
| |\ \ \
| |_|/
|/| |
| | |
| | | |
Ergonomic improvements to TimerangeBound
See merge request tpo/core/arti!1105
|
| | | | |
|
| | | | |
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Debug two types as compact hex strings
See merge request tpo/core/arti!1104
|
| | | | |
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-error: Errors for hidden services
See merge request tpo/core/arti!1099
|
| | | | |
| | | |
| | | |
| | | | |
I C&P this from tor-dirmgr, and missed this part.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
We'll want this later. Define it now, though, since we've discussed
it here
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1099#note_2892020
|
| | | | | |
|
| | | | | |
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | | |
So far these are just the errors that occur during descriptor
fetch. There will be more later as we have more code in tor-hsconn.
This is very user-facing; use the "onion service" terminology.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
tor-netdir: API changes to support hsconn hsdir fetch
See merge request tpo/core/arti!1094
|
| | | |
| | |
| | |
| | |
| | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1094#note_2891857
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Don't have it take the TP, so that the caller must call it multiple
times. Instead, have it return all the relevant relays.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
I don't think the server-side support will want to explicitly call
current and then secondary. Rather, it will want to iterate over all
the relevant ones.
And fix the name, and add another comment about whether we need this.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Change its name to hs_* like we do with things at this layer.
But, it turns out, that at least for hs client connections to fetch
the descriptor, I don't seem to need to call it yet ? Maybe it's not
needed.
|
| | | |
| | |
| | |
| | |
| | | |
* Change its name to Hs* like we do with things at this layer
* Make the Upload variant cfg-conditional
|
| | | |
| | |
| | |
| | |
| | | |
Provide iter_for_op, by changing iter into iter_filter_secondary and
having a new entrypoint iter.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously, to build descriptors for hidden services with client auth
enabled, in addition to the list of authorized clients, users of
`HsDescBuilder` were required to also provide a descriptor encryption
keypair and a descriptor cookie. This was potentially dangerous and/or
error-prone, because the ephemeral encryption key and the descriptor
cookie are expected to be randomly generated and unique for each
descriptor.
This change makes `ClientAuth` private to the `hsdesc::build` module and
updates `HsDescBuilder` to build `ClientAuth`s internally. Users now
only need to provide the list of authorized client public keys.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | | |
It's not really needed, it can just be generated at (test) runtime.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This adds a test for an `encode -> decode -> encode` flow for a hidden
service descriptor with client authorization enabled.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
`AuthClient`s were originally meant to represent parsed `auth-client`
lines. In !1070, this struct was repurposed for representing individual
authorized clients in the HS descriptor encoder. However, hidden
services will likely use a list of public keys to represent the
authorized clients rather than a list of `AuthClient`s, as the
information from an `AuthClient` (`client_id`, `iv`, `encrypted_cookie`)
likely won't be immediately available to the hidden service.
This change updates the HS descriptor encoder to represent authorized
clients as a list of `curve25519::PublicKey`s. As such, it is now the
responsibility of the encoder to create the `client_id`, `iv`, and
`encrypted_cookie` using the available keys, the unencrypted descriptor
cookie, and HS subcredential.
Signed-off-by: Gabriela Moldovan <[email protected]>
|
| | |/
|/| |
|
| | |
| |
| |
| | |
It is now a (conditional, experimental) dependency of arti-client.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
These crates had no changes until just a moment ago. But since
we updated the versions on some of their dependents, they have now
changed themselves. Thus they get patchlevel bumps.
```
tor-rtmock
tor-protover
tor-socksproto
tor-consdiff
tor-chanmgr
tor-dirclient
tor-hsservice
```
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
These crates have had breaking changes. They are pre-1.0, so they get
a minor bump.
```
tor-basic-utils
tor-config
```
|