summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | relay: Try to generate long-term identity keyDavid Goulet2024-09-182-5/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When creating the KeyMgr, attempt to create the long-term identity key if none are found in the KeyMgr. Until the KeyMgr has certificate support, we can't create the certificate. Add a TODO comment item about future work needed there. Related to #1604 Signed-off-by: David Goulet <[email protected]>
| * | relay: Add KeyMgr to TorRelayDavid Goulet2024-09-184-2/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the first step before creating relay key definition and storing them into a keystore. The KeyMgr should be passed on the ChanMgr in later commit so the ChanMgr can use it for the authenticated channel handshake. Part of #1604 Signed-off-by: David Goulet <[email protected]>
| * | relay-crypto: Initial import of new tor-relay-crypto crateDavid Goulet2024-09-185-0/+175
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new crate called tor-relay-crypto which is responsible for declaring the relay keys and certificate that will be used by a relay and stored in a KeyMgr. This is in its own crate and considered pretty low level so other crates can use it to access the relay keys, like tor-proto, for cryptographic actions like channel authentication or descriptor signing. The lower level cryptographic keys are wrapped in a higher level object in this crate, using tor-key-forge crate, so we can have proper semantic and strong type check on those keys so they are not misused or confused with other keys. At this point, the key declaration might change once the KeyMgr supports attaching a certificate to a key. We are likely going to see more code related to certificate creation in this crate in the future. Part of #1604 Signed-off-by: David Goulet <[email protected]>
| * | key-forge: Add helper function and implement traitsDavid Goulet2024-09-183-12/+48
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement the signature::Signer and Ed25519PublicKey trait so the ed25519 keypair wrapper can be easily used for certificate creation. This also adds a to_ed25519_id() so we can get a Ed25519Identity which is an object used around. Finally, add a prelude module as the list of imports started to grow a bit out of control. Part of #1604 Signed-off-by: David Goulet <[email protected]>
* | | tor-keymgr: Enable the keymgr feature by default.Gabriela Moldovan2024-09-181-1/+1
|/ / | | | | | | `tor-keymgr` users now get the real keymgr implementation by default.
* | tor-keymgr: put ephemeral keystore behind experimental featureSteven Engler2024-09-173-2/+11
| | | | | | | | Feature is named "ephemeral-keystore".
* | Merge branch 'svc-no-proxy-port' into 'main'David Goulet2024-09-172-14/+36
|\ \ | | | | | | | | | | | | | | | | | | arti: Allow running hidden services with SOCKS/DNS proxying disabled. Closes #1569 See merge request tpo/core/arti!2423
| * | arti: Don't log that we are in SOCKS mode unless socks_listen is set.Gabriela Moldovan2024-09-171-6/+13
| | | | | | | | | | | | If `socks_listen` is disabled, we're not actually running in SOCKS mode.
| * | arti: Allow running hidden services with SOCKS/DNS ports disabled.Gabriela Moldovan2024-09-172-8/+23
| | | | | | | | | | | | Closes #1569
* | | Merge branch 'mq-tidy' into 'main'David Goulet2024-09-177-5/+80
|\ \ \ | | | | | | | | | | | | | | | | memquota: be more firm about avoiding panics, and tidy up docs See merge request tpo/core/arti!2404
| * | | tor-memquota: queue plan: Add a cross-referenceIan Jackson2024-09-101-0/+3
| | | |
| * | | tor-memquota: queue plan: Clean up intent and make into a doc commentIan Jackson2024-09-101-32/+24
| | | | | | | | | | | | | | | | Remove extraneous text, wrap it, and change to a more declarative style.
| * | | tor-memquota: queue plan: Copy from !1997 discussionIan Jackson2024-09-101-0/+32
| | | |
| * | | tor-memquota: Worsify formatting to stop rustfmt making it even worseIan Jackson2024-09-101-1/+3
| | | |
| * | | tor-memquota: Use clippy::arithmetic_side_effects, against panicsIan Jackson2024-09-104-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | This detect possibly-panicking operations. Empirically this lint seems rather better now.
| * | | tor-memquota: Document that we're panic-freeIan Jackson2024-09-101-0/+10
| | | |
| * | | tor-memquota: Avoid a perhaps-impossible division-by-zero (fmt)Ian Jackson2024-09-101-1/+5
| | | |
| * | | tor-memquota: Avoid a perhaps-impossible division-by-zeroIan Jackson2024-09-101-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | It is not locally obvious that n_particips can't be zero, here. Certainly if it *is* that would be state corruption, but I don't think I can quite rule it out in the presence of a bug somewhere else.
| * | | tor-memquota: Use a const to hoist a panic to compile-timeIan Jackson2024-09-101-1/+3
| | | |
| * | | tor-memquota: Use checked_sub .. expect in two places (fmt)Ian Jackson2024-09-101-2/+6
| | | |
| * | | tor-memquota: Use checked_sub .. expect in two placesIan Jackson2024-09-101-2/+6
| | | | | | | | | | | | | | | | | | | | In these two places, underflow is statically impossible, but demonstrating that to the compiler is probably too onerous.
| * | | tor-memquota: Move some information into the proper docsIan Jackson2024-09-101-0/+8
| | | | | | | | | | | | | | | | | | | | This sentence is very important piece of overall explanation, but didn't make it into the crate level docs.
* | | | Merge branch 'ephemeral-keystore-docs' into 'main'gabi-2502024-09-171-0/+6
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-keymgr: add disk-related docs to `ArtiEphemeralKeystore` See merge request tpo/core/arti!2424
| * | | | tor-keymgr: add disk-related docs to `ArtiEphemeralKeystore`Steven Engler2024-09-171-0/+6
| | | | |
* | | | | Merge branch 'msrv-1.75' into 'main'Nick Mathewson2024-09-1758-58/+58
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Bump MSRV from 1.70 to 1.75. See merge request tpo/core/arti!2421
| * | | | Bump MSRV from 1.70 to 1.75.Wesley Aptekar-Cassels2024-09-1658-58/+58
| | | | |
* | | | | arti: Remove hss get-key from the tests.Gabriela Moldovan2024-09-172-24/+2
| | | | | | | | | | | | | | | | | | | | The `hss get-key` functionality was folded into `hss onion-name`.
* | | | | arti: Remove get-key subcommand in favor of onion-name.Gabriela Moldovan2024-09-171-28/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The `hss get-key` subcommand is now folded into `onion-name`, which takes a `--generate` argument which specifies whether to generate the key if missing. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2419#note_3078068
* | | | | tor-hsservice: Remove unused import from internal prelude.Gabriela Moldovan2024-09-171-1/+1
| | | | |
* | | | | arti: Add a test and some docs for the hss get-key subcommand.Gabriela Moldovan2024-09-171-0/+30
| | | | |
* | | | | arti: Add CLI for generating an onion service hsid.Gabriela Moldovan2024-09-172-3/+85
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new `hss get-key` subcommand for retrieving and generating service identity keys. The existing `hss onion-name` is now a convenience alias for `hss get-key --generate=no --key-type=onion-name`. Note: I am calling this new subcommand `get-key` for consistency with its client counterpart (`hsc get-key`). Closes #1621
* | | | | arti: Add an enum for the hss subcommand.Gabriela Moldovan2024-09-173-40/+48
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed because we'll soon add an `hss get-key` subcommand for getting and/or generating a service identity key alongside `hss onion-name` (`hss onion-name` will become a convenience around `hss get-key --key-type=onion-name`).
* | | | | arti: Refactor hss::onion_name() implementation.Gabriela Moldovan2024-09-171-11/+29
| | | | | | | | | | | | | | | | | | | | | | | | | This splits `onion_name` into multiple functions (which will be repurposed for the future `hss get-key` implementation).
* | | | | arti: Move hss onion-name implementation to a separate function.Gabriela Moldovan2024-09-171-29/+41
| | | | | | | | | | | | | | | | | | | | | | | | | `hss` will soon sprout another subcommand, so I am preemptively refactoring the `hss onion-name` implementation out of `hss::run()`.
* | | | | arti: Remove a completed TODO.Gabriela Moldovan2024-09-171-1/+0
| | | | | | | | | | | | | | | | | | | | The tests were added in !2275
* | | | | tor-hsservice: Add API for generating the hsid for a service.Gabriela Moldovan2024-09-171-2/+30
| | | | | | | | | | | | | | | | | | | | This also reexports `HsId` from the `tor-hsservice` crate.
* | | | | tor-hsservice: Make maybe_generate_hsid take a selector (fmt).Gabriela Moldovan2024-09-171-3/+14
| | | | |
* | | | | tor-hsservice: Make maybe_generate_hsid take a selector.Gabriela Moldovan2024-09-171-6/+8
| |_|/ / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon add a new `OnionService` function for generating an HsId for the service without launching it (#1621). This new API will be implemented using `maybe_generate_hsid`, which will need to take the user-provided keystore selector as an argument. (the selector exists for future-proofing reasons; we're not yet exposing it in the CLI, but it will be part of the new `OnionService` API)
* | | | Merge branch 'bug_1612v2' into 'main'gabi-2502024-09-171-1/+45
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bug 1612: Allow programmatic launching of onion-service with user-provided HsIdKeypair Closes #1612 See merge request tpo/core/arti!2402
| * | | | arti-client: add experimental launch_onion_service_with_hsid() method which ↵Morgan2024-09-151-1/+45
| | | | | | | | | | | | | | | | | | | | HsIdKeypair
* | | | | arti: Test hss onion-name behavior when the hsid is missing.Gabriela Moldovan2024-09-172-0/+17
| | | | |
* | | | | tor-hsservice: Do not generate the HsId until the service is launched.Gabriela Moldovan2024-09-171-8/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This defers generating an HsId until `OnionService::launch`, enabling us to use APIs like `OnionService::onion_name` to e.g. check for the existence of an HsId (previously, you couldn't do that because creating an `OnionService` would auto-generate the `HsId`).
* | | | | tor-hsservice: Remove outdated TODO.Gabriela Moldovan2024-09-171-4/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per #1247, we decided to stick with the current name. As for the docs, they were added in !1946
* | | | | tor-hsservice: Remove deprecated constructor.Gabriela Moldovan2024-09-172-36/+2
| |/ / / |/| | | | | | | | | | | This has been deprecated since 1.2.6, so let's remove it.
* | | | Merge branch 'take_all_but' into 'main'Nick Mathewson2024-09-162-8/+75
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement and user Reader::take_all_but() Closes #1620 See merge request tpo/core/arti!2415
| * | | | tor-proto: Use Reader::take_all_but().Nick Mathewson2024-09-162-21/+15
| | | | |
| * | | | tor-bytes: Add a new take_all_but method.Nick Mathewson2024-09-161-0/+73
| | | | |
* | | | | rpcserver: Split a few long lines.Nick Mathewson2024-09-161-5/+10
| | | | |
* | | | | rpcserver: move is_connection_close detection into run_loop.Nick Mathewson2024-09-161-6/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I've used an `async{ expr }.await` pattern, to make sure that _every_ error returned by the `loop{select!{}}` construct is actually transformed.
* | | | | rpcserver: Add an extra level of braces.Nick Mathewson2024-09-161-50/+52
| | | | | | | | | | | | | | | | | | | | (This will make the next commit easier to read.)