summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * tor-hsservice: Rewrite get_or_gen_key using KeyMgr::generate.Gabriela Moldovan2024-02-011-13/+18
| | | | | | | | | | | | | | Now that `KeyMgr::generate` returns the generated key, we can tidy up `get_or_gen_key`. Part of #1074
| * tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate (fmt).Gabriela Moldovan2024-02-011-45/+41
| |
| * tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate.Gabriela Moldovan2024-02-011-108/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon remove the `KeyMgr::*_with_derived()` functions, so we need to rewrite `maybe_generate_hsid` using `KeyMgr::get` and `KeyMgr::generate`. An important point to note is that `maybe_generate_hsid` no longer stores the `KP_hs_id` in the key store. The reason we originally put the `KP_hs_id` in the keystore in the first place was to support offline HsId mode. However, offline HsId mode was never fully implemented (#1194), and the decision to put the public part of the HsId in the keystore is controversial (#1195). We can revisit this decision when we implement #1194, but for now, we don't need a separate `KP_hs_Id` entry in the keystore.
| * tor-hsservice: Read the keypair when deriving the subcredentials.Gabriela Moldovan2024-02-011-5/+8
| | | | | | | | | | We're about to stop storing `KP_hs_id` in the keystore, so in preparation, let's update the callsites that attempt to retrieve it.
| * tor-hsservice: Extract the onion name from the keypair.Gabriela Moldovan2024-02-011-3/+6
| | | | | | | | We're about to stop storing the public part of the hsid in the keystore.
| * tor-keymgr: Make KeyMgr::generate return the generated key.Gabriela Moldovan2024-02-011-4/+12
| | | | | | | | | | | | | | `KeyMgr::generate` is now quite similar to `KeyMgr::get_or_generate`, so we will soon remove the latter. Part of #1074
| * tor-keymgr: Add error variant for when a key shouldn't exist.Gabriela Moldovan2024-02-012-0/+6
| | | | | | | | | | | | | | This will be returned by `KeyMgr::generate` if the key to be generated already exists and `overwrite` is `false`. Part of #1074
* | tor-hsservice: Apply deferred cargo fmt.Gabriela Moldovan2024-02-011-8/+5
| |
* | tor-hsservice: Remove unnecessary trace! log.Gabriela Moldovan2024-02-011-1/+0
| |
* | tor-hsservice: Remove old upload rate-limiting code.Gabriela Moldovan2024-02-011-97/+1
| |
* | tor-hsservice: Reimplement upload rate-limiting using TrackingNow.Gabriela Moldovan2024-02-011-2/+16
| | | | | | | | | | | | | | | | | | | | | | This simplifies the publisher code in preparation for #1241 This replaces the overly complicated task-based approach to rate-limiting with a simpler one, where the publisher has: * a separate `RateLimited` state that indicates it is rate-limited, and for how long * an additional arm in its `run_once()` `select_biased!`, which checks if the rate-limit has expired
* | tor-hsservice: Update docs with the new RateLimited state.Gabriela Moldovan2024-02-011-10/+10
| |
* | tor-hsservice: Add functions for starting/stopping the rate-limiting.Gabriela Moldovan2024-02-011-0/+22
| |
* | tor-hsservice: Add a RateLimited publisher status.Gabriela Moldovan2024-02-011-9/+36
| |
* | tor-hsservice: Remove an unnecessary TODO.Gabriela Moldovan2024-02-011-4/+0
| | | | | | | | | | We _do_ schedule the rate-limited upload at `now + UPLOAD_RATE_LIM_THRESHOLD`, see `schedule_rate_lim_upload()`.
* | tor-hsservice: Downgrade a warn! to debug!.Gabriela Moldovan2024-02-011-2/+2
|/ | | | | This shouldn't be a warning (it's logged when the reactor is shutting down, not when it crashes).
* Make the OnionServiceState type crate-private.Nick Mathewson2024-02-011-17/+22
| | | | Closes #1261.
* Merge branch 'high-level-docs' into 'main'Nick Mathewson2024-02-012-7/+59
|\ | | | | | | | | | | | | Add some higher-level documentation for tor-hsservice. Closes #1228 See merge request tpo/core/arti!1945
| * Correct description of parametersIan Jackson2024-02-011-1/+1
| |
| * Note that old state is not yet removedIan Jackson2024-02-011-0/+3
| |
| * Add some higher-level documentation for tor-hsservice.Nick Mathewson2024-01-312-7/+56
| | | | | | | | Closes #1228.
* | tor-hsservice: Rename the service keystore dir to "hss".Gabriela Moldovan2024-02-011-14/+14
| | | | | | | | | | | | | | | | | | | | | | The onion service keys now live in the `hss/<nickname>` subdirectory within the keystore. This layout change is **not** backwards-compatible, so if you want to use your existing hidden service keys, you will need to manually move them to `<keystore_root>/hss`. Closes #1260
* | tor-hsservice: Use tor_persist::state_dirIan Jackson2024-02-012-2/+4
| |
* | tor-hsservice: Remove now-unused importsIan Jackson2024-02-013-8/+4
| |
* | tor-hsservice: tests: create_storage_handles: use a real directory (churn)Ian Jackson2024-02-011-1/+1
| | | | | | | | Mandatory use line shuffling.
* | tor-hsservice: Abolish StartupError::StateLockedIan Jackson2024-02-011-5/+0
| | | | | | | | This is now tor_persist::Error containing ErrorSource::AlreadyLocked.
* | tor-hsservice: Drop now-unused fslock dependencyIan Jackson2024-02-013-3/+0
| | | | | | | | We're just using fslock-guard now.
* | tor-hsservice: Use tor_persist::state_dir, etc. (fmt)Ian Jackson2024-02-013-22/+28
| |
* | tor-hsservice: Use tor_persist::state_dirIan Jackson2024-02-017-150/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We no longer do replay log locking in IptManager::new. Instead, we rely on the acquire_instance call in OnionService::launch, which ends up with ipt_mgr getting an InstanceHandle (which contains a lock guard). OnionServiceStateMgr is abolished; it existed to deal with the generics in the tor_persist::StateMgr API. state_dir has no generics (other than the T being loaded/stored). Many places (structs and argument lists) now have state_dir types which embody a path (or a CheckeDir) along with a lock, rather than separate path+lock+mistrust. The creation/startup code uses the new calls from state_dir. Other more minor changes: - StartupError::StateDirectoryInaccessible contains tor_persist::Error - test::create_storage_handles_from_state_dir changed and renamed, from _from_state_mgr. - replay::PersistFile's (separate) file lock is now fslock_guard's
* | tor-hsservice: Introduce StartupError::StateDirectoryInaccessibleIoIan Jackson2024-02-012-5/+26
| | | | | | | | | | | | We're going to change the payload of StateDirectoryInaccessible to tor_persist::Error, since that's what tor_persist::state_dir gives us, but then we can't use it here.
* | tor-hsservice: tests: create_storage_handles: use a real directory (fmt)Ian Jackson2024-02-011-1/+5
| |
* | tor-hsservice: tests: create_storage_handles: use a real directoryIan Jackson2024-02-013-5/+15
| | | | | | | | | | | | | | state_dir doesn't have the in-memory dummy implementation, so there will have to be a real directory here. Do that now, as prep.
* | tor-hsservice: ipt_mgr: Move storage handle to stateIan Jackson2024-02-012-9/+11
| | | | | | | | | | The new state_dir types require &mut for storing, which is correct, but that means we can't have it in Immutable.
* | tor-hsservice: impl state_dir::InstanceIdentity for HsNicknameIan Jackson2024-02-011-0/+10
| |
* | tor-hsservice: storage: Move Arcs into type aliasesIan Jackson2024-02-014-12/+12
| | | | | | | | | | | | | | These are here because that's what you get from the tor_persist singleton StageMgr API (for type erasure reasons). We're going to change these to tor_persist::state_dir types and those don't involve Arcs.
* | tor-hsservice: ipt_set: Make store method take &mut selfIan Jackson2024-02-011-1/+1
| | | | | | | | | | Only people who can mutate the state ought to be saving it. Otherwise there might be concurrent overwrites.
* | tor-hsservice: tests: Add a missing drop callIan Jackson2024-02-011-0/+2
| | | | | | | | | | | | This doesn't actually change the behaviour with current Rust. But it avoids bugs and future changes. Relying on drop order for temporary directory lifetime seems bad.
* | tor-persist: state_dir: Add some missing Clone and Debug implsIan Jackson2024-02-011-5/+5
| |
* | tor-persist: state_dir: Introduce way to get at underlying lock guardIan Jackson2024-02-012-3/+39
| | | | | | | | | | | | And export the type, so callers don't need to depend directly on fslock_guard; many callers will need to own the returned value, not do anything else with it.
* | tor-persist: state_dir: Make the storage handle Send and SyncIan Jackson2024-02-011-2/+5
| |
* | Merge branch 'clippy' into 'main'Nick Mathewson2024-01-317-8/+7
|\ \ | |/ |/| | | | | Fix nightly clippy warnings See merge request tpo/core/arti!1942
| * clippy: Use Result::cloned in several placesIan Jackson2024-01-313-3/+3
| |
| * tor-dirmgr: Simplify a clone call (fmt)Ian Jackson2024-01-311-3/+1
| |
| * tor-dirmgr: Simplify a clone callIan Jackson2024-01-311-2/+1
| | | | | | | | Prompted by clippy.
| * arti-rpcserver: Add an allowIan Jackson2024-01-311-0/+1
| |
| * tor-rpcbase: Add an allowIan Jackson2024-01-311-0/+1
| |
| * tor-error: Backtrace: Remove a Captured(...) from a DisplayIan Jackson2024-01-311-1/+1
| | | | | | | | | | Prompted by clippy complaining that the content wasn't ever read other than by the autogenerated Debug impl.
* | Merge branch 'ipt_parameters' into 'main'Nick Mathewson2024-01-317-42/+62
|\ \ | | | | | | | | | | | | | | | | | | Clean up, tune, and correct various parameters related to introduction points. Closes #1210 See merge request tpo/core/arti!1924
| * | Rename parameters for intro-point lifetime to match the spec.Nick Mathewson2024-01-312-6/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (Also, correct the comments that describe them.) We may as well match the spec names when they aren't completely bogus. We are already renaming these parameters for this release, so it isn't an additional breaking change.
| * | hss: clean up comments on ipt establish time tuningNick Mathewson2024-01-251-3/+7
| | | | | | | | | | | | See #1210 "question 4".