| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-hsservice: If the error is fatal, do not retry the desc upload.
See merge request tpo/core/arti!1821
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The errors returned by `upload_all` are now all fatal, so we there is no
point in retrying `upload_all` on failure.
Note this will exacerbate #1155, as it will cause the seemingly
transient time skew issues to become fatal (the corresponding error type
is `Bug`, so in principle they ought to be fatal)
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
We're going to reuse this for other kinds of storage error.
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This is needed for the replay logs.
It's a shame that CheckedDir is (i) a bit unergonomic (ii) has an
extra bool in it, or we could pass one of those instead of these two
arguments.
Since HS's might be created after startup, TorClient must have these
fields.
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Call expand_state_dir only once. We'll reuse this value, another
time, too.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
create_storage_handles_from_state_mgr (fmt)
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This will allow us to more faithfully model the actual Arti state
directory layout.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This is to prevent current use of the same directory of replay logs by
different instances.
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This ought to have the hash algorithm name in it or we'll have trouble
if we want to change the hash algorithm in the future. (Strictly, we
could just choose a different magic but the string was rather short.)
Add a newline, which is often convenient in file headers.
And "onion" to mean "onion swervice" is improper.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Make `#[cfg(target_family = "unix")]` appear only once.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This code needs fs_mistrust::Error and tor_error::ErrorKind. I think
we probably don't want fs_mistrust to depend on tor_error or vice
versa.
tor_persist is approximately the place where these two threads of
thought come together, and it's currently the lowest place where this
is needed.
Use it in tor-dirmgr too, which is currently the other place that
embodies this knowledge about fs_mistrust::Error.
|
| |/ / / / |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
tor-hscrypto: Return 0 if the timestamp is before the start of the TP.
Closes #1155
See merge request tpo/core/arti!1828
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
#1155 was happening because we couldn't compute the offset of the
current time from the start of the _next_ TP
(`TimePeriod::offset_within_period` expected `when` to come after the
start of the TP). `TimePeriod::offset_within_period` now returns an
offset of 0 for timestamps that come before the start of the TP, to
support computing revision counters for the descriptors uploaded to
the HsDirs from the ring associated with the next TP.
Fixes #1155
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-hsservice: Replace ReactorError with FatalError
See merge request tpo/core/arti!1812
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
The publisher now returns `FatalError`s, so we don't need `ReactorError`
anymore. Addresses a TODO HSS in publish/reactor.rs
Part of #1129
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This is another type of fatal error.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
We're about to use this (in the publisher reactor).
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
The publisher logs a nice `info!` message when it receives the shutdown
signal. The publisher can infer that the service is shutting down from
the errors received on its various receiver channels (i.e. from the
errors that suggest the sender was dropped), but listening for the
shutdown signal is nicer.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This will be used by the descriptor publisher soon (we want to abolish
its `ReactorError` altogether, and to do that, we need to get rid of
`ReactorError::ShuttingDown`. `ShuttingDown::Terminate` happens to be a
suitable replacement).
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This moves us one step closer to removing ReactorError in favour of
FatalError (see the TODO HSS above ReactorError for more details).
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Previously, this would return `ReactorError::PublishFailure` if the
upload failed. However, that error wasn't used for anything other than
logging.
Instead of returning the error, we now log it inside
`upload_descriptor_with_retries` and return an `UploadStatus` describing
the upload outcome. This will enable us to abolish
`ReactorError::PublishFailure` (and eventually replace `ReactorError`
with `FatalError`).
|
| | | |/ / /
| |/| | |
| | | | |
| | | | |
| | | | | |
The failure to build a descriptor out of seemingly valid parts is an
internal (irrecoverable) error.
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
hscrypto: Remove a "TODO HSS" about a no-longer-unused type.
See merge request tpo/core/arti!1817
|
| | | |/ /
| |/| | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
hsproxy: warn on some dubious configurations
Closes #1154
See merge request tpo/core/arti!1822
|
| | | | | | |
|
| | | |_|/
| |/| |
| | | |
| | | |
| | | |
| | | |
| | | | |
Specifically, warn about non-private target addresses
and onion services with no forwarding rules at all.
Removes some TODO HSS comments and closes #1154.
|
| |\ \ \ \
| |_|_|/
|/| | |
| | | |
| | | | |
arti: Use warn_report on anyhow::Error in onion_proxy
See merge request tpo/core/arti!1820
|
| | |/ /
| | |
| | |
| | | |
This was made possible by !1818.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
tor-cell: Remove a now-unneeded allow(unused).
See merge request tpo/core/arti!1816
|