summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | fslock-guard: Write down the locking protocol on UnixIan Jackson2024-01-231-0/+65
| | | | | | | | | | | | | | | | | | Text from here https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1900#note_2986683 with a few minor fixes.
| * | fslock-guard: Rename os modulesIan Jackson2024-01-231-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These two modules are key to the implementation of the locking protocols. We must define the locking protocol in terms of underlying OS semantics (since Unix and Windows have different fs concepts and different concurrency semantics) and therefore, although we are sharing some code between the implementations, these modules are what defines the two protocols.
| * | Give a formal semantics for the fslock operations.Ian Jackson2024-01-221-0/+15
| | |
| * | fslock-guard: sketch implementationNick Mathewson2024-01-213-0/+188
| | | | | | | | | | | | | | | | | | | | | This is not yet "correct", since it will rely on https://github.com/brunoczim/fslock/pull/15 (Conceivably, it might be better to make the `fslock` crate rm-safe.)
* | | Merge branch 'hsdirparams' into 'main'gabi-2502024-01-234-15/+44
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | Expose SRV lifespan info from netdir Closes #1254 See merge request tpo/core/arti!1903
| * | netdir: Make hs_dirs_upload() yield &HsDirParams.Nick Mathewson2024-01-232-2/+4
| | | | | | | | | | | | Closes #1254.
| * | Expose HsDirParams, and give it accessors.Nick Mathewson2024-01-232-2/+24
| | |
| * | hsservice: Make HsDirParams include the SRV lifespan.Nick Mathewson2024-01-232-11/+16
| | | | | | | | | | | | This is part of #1254.
* | | tor-hsservice: Move compute_subcredentials to RendRequestContext.Gabriela Moldovan2024-01-223-103/+100
| | | | | | | | | | | | Part of #1242
* | | tor-hsservice: Do not store the subcredentials in RendRequestContext.Gabriela Moldovan2024-01-223-21/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the subcredentials were computed in `IptEstablisher::launch` and stored in `RendRequestContext`. This caused long-running services to report errors like: ``` WARN tor_hsservice::helpers: Problem while accepting rendezvous request: error: Could not process INTRODUCE request: Introduction handshake was invalid: Circuit-extension handshake authentication failed ``` for clients using newer subcredentials than the ones the service had at the time the IPT was established. Fixes #1242
* | | tor-hsservice: Add an error type for subcredential lookup failures.Gabriela Moldovan2024-01-222-0/+6
|/ / | | | | | | | | | | | | | | The subcredential lookup will be moved to `IntroRequest::decrypt_from_introduce2`. The error returned on failure is going to be `IntroRequestError::Subcredentials`. Part of #1242
* | Merge branch 'shutdown_on_drop' into 'main'gabi-2502024-01-195-14/+27
|\ \ | | | | | | | | | | | | | | | | | | Clarify shutdown behavior when RemoteOnionService is dropped. Closes #1238 and #1236 See merge request tpo/core/arti!1899
| * | Document when (most) spawned tasks will be canceled.Nick Mathewson2024-01-182-0/+6
| | |
| * | hsservice: Temporarily remove .pause() (formerly stop()).Nick Mathewson2024-01-182-0/+3
| | | | | | | | | | | | | | | We don't need to implement this for our first release of onion services, but we shouldn't ship a function that calls todo!().
| * | Clarify usage and behavior of shutdown_tx.Nick Mathewson2024-01-181-6/+7
| | |
| * | Clarify IptEstablisher shutdown rulesNick Mathewson2024-01-181-8/+11
| | | | | | | | | | | | | | | | | | There was no actual bug here; just some missing comments. Closes #1236.
* | | Merge branch 'tolerant_intro_established' into 'main'gabi-2502024-01-191-17/+12
|\| | | |/ |/| | | | | | | | | Do not reject INTRO_ESTABLISHED messages with extensions Closes #1238 See merge request tpo/core/arti!1898
| * Do not reject INTRO_ESTABLISHED messages with extensionsNick Mathewson2024-01-181-17/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | The spec says that we should ignore unrecognized extensions. Per discussion at torspec#249, this is still correct. Additionally, this commit moves responsibility for checking INTRO_ESTABLISHED messages into IptMsgHandler::handle_msg, to make sure that the circuit is torn down as soon as possible on a bad reply. (There's nothing to check yet, but there will be once we start sending extensions that expect a reply.) Closes #1238.
* | Mark ShutdownStatus as must_useNick Mathewson2024-01-181-0/+1
|/ | | | Followup from !1895.
* Merge branch 'publisher-shut-down' into 'main'Nick Mathewson2024-01-182-7/+13
|\ | | | | | | | | tor-hsservice: The publisher should exit when the IPT manager says so. See merge request tpo/core/arti!1895
| * tor-hsservice: The publisher should exit when the IPT manager says so.Gabriela Moldovan2024-01-182-7/+13
| | | | | | | | | | | | The publisher needs to shut down when `IptPublisherView::sawait_update()` returns `None`, not pause the uploads.
* | Merge branch 'downgrade-todo' into 'main'Nick Mathewson2024-01-181-1/+1
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Reference #1226 instead of #1219 in a TODO. Closes #1219 See merge request tpo/core/arti!1896
| * | tor-hsservice: Reference #1226 instead of #1219 in a TODO.Gabriela Moldovan2024-01-181-1/+1
| |/ | | | | | | | | | | | | | | `note_publication_attempt` can only fail: * due to an internal error, in which case there is no point in retrying * if `PublishIptSet::save` fails, i.e. if we fail to write to persistent storage (this is #1226)
* | tor-hsservice: Store the StateMgr inside OnionServiceState.Gabriela Moldovan2024-01-183-25/+61
| | | | | | | | | | | | This introduces an internal `OnionServiceStateMgr` trait, which enables us to store the `StateMgr` inside the `OnionServiceState` (without having to parameterize `OnionServiceState` on `S: StateMgr`).
* | tor-hsservice: Add TODO about testing arti hss.Gabriela Moldovan2024-01-181-0/+1
| |
* | tor-hsservice: Add a test for OnionService::onion_name.Gabriela Moldovan2024-01-181-0/+31
| |
* | arti-client: Move state_dir and mistrust handling to separate function.Gabriela Moldovan2024-01-181-11/+19
| | | | | | | | This reduces code duplication.
* | arti-client: Move keymgr creation to TorClient::create_keymgr.Gabriela Moldovan2024-01-181-49/+34
| | | | | | | | | | This code was duplicated by `create_inner()` and `create_onion_service()`.
* | tor-hsservice: Move onion_name() to OnionServiceState.Gabriela Moldovan2024-01-182-56/+61
| | | | | | | | | | | | | | | | Both `OnionService` and `RunningOnionService` have an `onion_name()` function. To reduce code duplication, we can move `onion_name()` to a new `OnionServiceState` struct (which will grow more state management functions int he future), and make both `*OnionService` structs deref to it.
* | tor-hsservice: Add RunningOnionService::onion_name.Gabriela Moldovan2024-01-181-7/+42
| |
* | tor-hsservice: Add a couple of TODOs for #1247.Gabriela Moldovan2024-01-181-0/+2
| |
* | tor-hsservice: Do not store the StateMgr in OnionService.Gabriela Moldovan2024-01-182-20/+10
| | | | | | | | | | | | | | The `StateMgr` is currently only needed in `launch()`, so we don't really need to store it. This allows us to unparameterize OnionService.
* | tor-hsservice: Remove a couple of resolved TODOs.Gabriela Moldovan2024-01-181-3/+0
| |
* | tor-hsservice: Remove unused state module.Gabriela Moldovan2024-01-182-50/+0
| | | | | | | | | | The functionality previously provided by the so-called `StateMgr` is now part of `OnionService`, so we can remove state.rs altogether.
* | arti: Use OnionService to get the onion_name().Gabriela Moldovan2024-01-181-7/+19
| |
* | arti: Make OnionServiceProxyConfig pub(crate).Gabriela Moldovan2024-01-181-2/+2
| | | | | | | | | | We are about to need the `svc_cfg` (for calling `TorClient::create_onion_service`).
* | arti-client: Add a function for creating OnionServices.Gabriela Moldovan2024-01-181-0/+58
| | | | | | | | | | This will be used from `arti` to create an `OnionService`, to implement the `arti hss` command.
* | tor-hsservice: Move onion_name() to OnionService.Gabriela Moldovan2024-01-181-0/+12
| | | | | | | | | | | | | | This a modified version of `tor_hsservice::state::StateMgr::onion_name`. `tor_hsservice::state::StateMgr` will soon be abolished. Part of #1220, #1227
* | tor-hsservice: Create a separate RunningOnionService type.Gabriela Moldovan2024-01-185-32/+85
| | | | | | | | | | | | | | | | This will enable us to construct non-launched (but configured) `OnionService`s. We need this, for example, for implementing the `arti hss` CLI command. Part of #1227
* | tor-hsservice: Rename stop() to pause().Gabriela Moldovan2024-01-181-1/+1
|/ | | | Part of #1227
* Merge branch 'is_ipt_failure' into 'main'Nick Mathewson2024-01-171-3/+39
|\ | | | | | | | | | | | | Implement is_ipt_failure better. Closes #1234 See merge request tpo/core/arti!1889
| * Add a note about torspec#249.Nick Mathewson2024-01-171-1/+4
| |
| * Implement is_ipt_failure better.Nick Mathewson2024-01-171-2/+35
| | | | | | | | | | Additionally, explain its behavior better, since we cannot always identify an Ipt failure with certainty.
* | Merge branch 'enc_key_cert_signbit' into 'main'Nick Mathewson2024-01-172-6/+14
|\ \ | | | | | | | | | | | | | | | | | | hsdesc: Document why enc_key_cert signbit is always zero. Closes #1221 See merge request tpo/core/arti!1888
| * | hsdesc: Document why enc_key_cert signbit is always zero.Nick Mathewson2024-01-162-6/+14
| |/ | | | | | | | | | | Closes #1221. See torspec!240 for a corresponding spec change.
* | Merge branch 'send_incoming_request_failures' into 'main'gabi-2502024-01-173-30/+58
|\ \ | | | | | | | | | | | | | | | | | | Several clean-ups around failures in incoming stream request handlers. Closes #1190, #1189, and #1188 See merge request tpo/core/arti!1892
| * | proto: Use log_ratelim to report problems delivering BEGIN messges.Nick Mathewson2024-01-172-3/+8
| | |
| * | Give an error on duplicate call to allow_stream_requests.Nick Mathewson2024-01-172-8/+2
| | | | | | | | | | | | Closes #1190
| * | proto: Close circuit _intentionally_ when Request Sink is dropped.Nick Mathewson2024-01-172-8/+36
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In theory, it might be better to just un-register the IncomingStreamRequestHandler when the Receiver for the stream requests is dropped. However, there are two reasons not to do so: 1. It's tricky. We never actually poll on the corresponding Sink, so there isn't a place where the Reactor would expect to get a prompt notification of closure. We only find out that the Receiver has been dropped when an attempt to send on the Sink returns an `is_disconnected` error. 2. It's unnecessary. In the Tor protocols, once we have decided to accept incoming stream requests on a circuit, we want to continue to do so until one of the parties closes the circuit. I've documented this in several comments, in case whe want to get fancier in the future. Closes #1188.
| * | proto: Send END when buffer of IncomingRequests is fullNick Mathewson2024-01-172-13/+14
| | | | | | | | | | | | Closes #1189.