summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | tor-hsservice: ipt mgr: Move/rename to StateExpiryErrorIan Jackson2024-02-132-39/+41
| | | | | | | | | | | | | | | | | | | | The private ExpiryError type is now err::StateExpiryError. We'll fix up the local alias in the HasKind impl in a moment.
| * | | tor-hsservice: replay: Move replay filename knowledge into replay.rs (fmt)Ian Jackson2024-02-131-10/+5
| | | |
| * | | tor-hsservice: replay: Move replay filename knowledge into replay.rsIan Jackson2024-02-132-41/+58
| | | |
| * | | tor-hsservice: tests: Greak out mk_state_instance helperIan Jackson2024-02-131-3/+12
| | | |
| * | | tor-hsservice: Expose HsNickname::newIan Jackson2024-02-131-1/+1
| |/ / | | | | | | | | | | | | The non-visibility of this method seems like it must have been an oversight.
* / / tor-hsservice: The publisher should process all upload results.Gabriela Moldovan2024-02-141-1/+2
|/ / | | | | | | | | | | If one of the upload results is for an HsDir that went away, the publisher should continue processing the remaining ones, not disregard them entirely.
* | Merge branch 'empty_data' into 'main'Nick Mathewson2024-02-134-15/+43
|\ \ | | | | | | | | | | | | | | | | | | tor_cell: Reject empty DATA messages Closes #1269 See merge request tpo/core/arti!1981
| * | tor_cell: never construct empty DATA messages.Nick Mathewson2024-02-134-15/+40
| | | | | | | | | | | | | | | | | | | | | We never actually constructed these before, but now we enforce it at the API level. Part of #1269.
| * | tor_cell: Reject empty DATA messagesNick Mathewson2024-02-131-0/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we don't reject these, they are a way to inject an undetected traffic signal. (This is LOW severity, since we only accept DATA when a stream is open, since DATA messages are rate-limited, and since using length==1 is nearly as effective.) Closes #1269. This is TROVE-2024-001.
* | | Merge branch 'expire-ipts' into 'main'Ian Jackson2024-02-132-22/+260
|\ \ \ | |/ / |/| | | | | | | | tor-hsservice: Expire old on-disk IPT state See merge request tpo/core/arti!1977
| * | tor-hsservice: ipt mgr: Temporarily suppress a lintIan Jackson2024-02-131-0/+1
| | |
| * | tor-hsservice: ipt mgr: Check that file expiry happens precisely when wantedIan Jackson2024-02-131-4/+20
| | | | | | | | | | | | | | | This test detects the bug mentioned here https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2995265
| * | tor-hsservice: ipt mgr: Add a test hook for expiryIan Jackson2024-02-131-0/+24
| | |
| * | tor-hsservice: ipt mgr: Do old IPT file cleanup on startup tooIan Jackson2024-02-131-0/+4
| | | | | | | | | | | | This isn't strictly necessary, but it's better.
| * | tor-hsservice: ipt mgr: Explain about the ipt_set invariantIan Jackson2024-02-131-0/+6
| | | | | | | | | | | | This seemed to warrant some discussion and a cross-reference.
| * | tor-hsservice: ipt mgr: Rewrite state expiry doc commentIan Jackson2024-02-131-3/+7
| | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2994999 https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2995000
| * | tor-hsservice: ipt mgr: Abolish a foolish intermediate variableIan Jackson2024-02-131-14/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1977#note_2994998 Removing the intermediate variable removes the possibility that the information in it could fail to be transferred to the main mutable state, so we don't need the IEFE any more.
| * | tor-hsservice: ipt mgr tests: Narrow a TODOIan Jackson2024-02-121-1/+1
| | | | | | | | | | | | We do have some tests, but they're not as comprehensive as we'd like.
| * | tor-hsservice: ipt mgr tests: Test that we expire old IPT dataIan Jackson2024-02-122-0/+38
| | |
| * | tor-hsservice: ipt mgr tests: Avoid reusing RNG seedIan Jackson2024-02-121-4/+4
| | | | | | | | | | | | | | | | | | Without this, we can regenerate the same IptLocalIds (etc.) on shutdown/restart (which involves calling startup again within a test case).
| * | tor-hsservice: ipt mgr: Expire replay logs for old IPTsIan Jackson2024-02-121-4/+57
| | |
| * | tor-hsservice: ipt mgr: Expire keys for old IPTsIan Jackson2024-02-121-3/+84
| | |
| * | tor-hsservice: ipt mgr: Track whether we've deleted any IPT (fmt)Ian Jackson2024-02-121-9/+9
| | |
| * | tor-hsservice: ipt mgr: Track whether we've deleted any IPTIan Jackson2024-02-121-2/+17
| | | | | | | | | | | | Indentation left anmolaous briefly for ease of review.
| * | tor-hsservice: ipt mgr: Break out REPLAY_LOG_SUFFIXIan Jackson2024-02-121-1/+4
| | | | | | | | | | | | | | | The expiry code is going to want this too. We should at least make a constant of it.
| * | tor-hsservice: ipt mgr: Rotate IPT relays even without good IPTs! (fmt)Ian Jackson2024-02-121-6/+6
| | |
| * | tor-hsservice: ipt mgr: Rotate IPT relays even without good IPTs!Ian Jackson2024-02-121-3/+1
| |/ | | | | | | | | | | | | | | We shouldn't keep the same IPT relays just because they're not working! Firstly, that's just silly, and secondly, for privacy reasons we want to put a limit on teh lifetime anyway. Indentation left anmolaous briefly for ease of review.
* | tor-guardmgr: Fix README typo.Gabriela Moldovan2024-02-121-1/+1
| |
* | tor-guardmgr: Fix spec link in README.Gabriela Moldovan2024-02-121-1/+1
| | | | | | | | The old link now 404s, so let's link to spec.torproject.org instead.
* | tor-hsservice: Add a TODO about using HashMap for the reupload_timers.Gabriela Moldovan2024-02-121-0/+4
| |
* | tor-hsservice: Fix typo in comment.Ian Jackson2024-02-121-1/+1
| |
* | tor-hsservice: Add test for desc publisher reuploads.Gabriela Moldovan2024-02-121-3/+41
| | | | | | | | Part of #1241
* | tor-hsservice: Remove unnecessary locking in test.Gabriela Moldovan2024-02-121-8/+8
| |
* | tor-hsservice: Add a publisher TODO about limiting reuploads.Gabriela Moldovan2024-02-121-0/+7
| |
* | tor-hsservice: Periodically reupload the descriptor.Gabriela Moldovan2024-02-122-3/+32
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | According to the spec, the publisher needs to periodically reupload the descriptor. ``` Specifically, every time a hidden service publishes its descriptor, it also sets up a timer for a random time between 60 minutes and 120 minutes in the future. When the timer triggers, the hidden service needs to publish its descriptor again to the responsible HSDirs for that time period. [TODO SPEC: Control republish period using a consensus parameter?] ``` After each `upload_for_time_period()`, the publisher now sets a timer as described in the spec, by pushing a `ReuploadTimer` into its `reupload_timers` heap. Closes #1241
* | tor-hsservice: Set the status to UploadScheduled when it's time to reupload.Gabriela Moldovan2024-02-121-0/+45
| |
* | tor-hsservice: Add helper type for scheduling descriptor reuploads.Gabriela Moldovan2024-02-122-0/+113
| |
* | tor-hsservice: Add a function for marking descriptors dirty for a specific TP.Gabriela Moldovan2024-02-121-0/+20
| | | | | | | | | | | | | | We will soon need the ability to trigger a descriptor reupload for a specific time period. Part of #1241
* | tor-hsservice: replay log test: Check SIGUSR2 status on entryIan Jackson2024-02-121-0/+35
| | | | | | | | Will make the situation in #1264 clear, I think.
* | tor-hsservice: replay log test: Break out sigemptyset()Ian Jackson2024-02-121-3/+7
| |
* | tor-hsservice: replay log test: Plumb output manuallyIan Jackson2024-02-121-2/+13
|/ | | | | | | | | Something libtest is doing hides the child stderr/stdout from the test log, when --nocapture is not given. With these changes, I see much more output in failing cases or with --nocapture. In the case mentioned in #1264, the message "we survived raise SIGUSR2" is now printed both with and without --nocapture.
* educe: Use std's default for two structsIan Jackson2024-02-122-5/+2
| | | | | | Reviewing uses of `#[educe(default)]`, I came across these two places where it was applied to a non-generic struct without any special attributes on fields. std's derive will do just as well here.
* educe: Use std's default for enums where default variant is unitIan Jackson2024-02-1212-62/+36
| | | | | | | | | | | | | Since Rust 1.66, std's default works properly for enums, provided that the default variant is a unit. Review all uses of `#[educe(default)]` on enums and replace them with std where possible, which is most of them. In 1.66 and later, std's `#[derive(Default)]` doesn't infer any generic bounds on the derived impl, where it's an enum - since the unit variant can always be constructed. So this change doesn't add any generic bounds and is not API-visible.
* Merge branch 'hsrproxy_errs' into 'main'Alexander Færøy2024-02-081-22/+34
|\ | | | | | | | | hsproxy: Improve error messages. See merge request tpo/core/arti!1973
| * hsproxy: Improve error messages.Nick Mathewson2024-02-081-22/+34
| | | | | | | | | | | | | | | | When giving an error message about an hsrproxy configuration: 1) mention that this is for an onion service. 2) mention what the invalid text was. Part of #1266
* | tor-persist: state_dir: Use DOT_LOCK in the final locationIan Jackson2024-02-081-1/+1
| | | | | | | | | | Actually, we want to test handling of the string with whatever the extension would be, if it changed.
* | tor-persist: state_dir: Introduce DOT_LOCKIan Jackson2024-02-081-2/+7
| | | | | | | | | | | | | | And replace ".lock" with it. Now the only place that the "lock" extension this is still present as a literal is in a test.
* | tor-persist: state_dir: Introduce LOCK_EXTNIan Jackson2024-02-081-4/+6
| | | | | | | | | | | | And replace "lock" with it. This is the first half of not open-coding this; the sites where the literal string is ".lock" are in the next commit, to help avoid the slip of using the wrong constant.
* | tor-persist: state_dir: Add a note about the instance modification timeIan Jackson2024-02-081-0/+3
| |
* | tor-persist: state_dir: Test that junk is ignoredIan Jackson2024-02-081-0/+27
| |