summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | Merge branch 'x509-signature-yeet' into 'main'Nick Mathewson2025-03-055-120/+104
|\ \ | | | | | | | | | | | | | | | | | | Switch from x509-signature to rustls-webpki when using rustls. Closes #1824 and #1854 See merge request tpo/core/arti!2816
| * | rustls: move provider-installer to its own function.Nick Mathewson2025-03-041-13/+21
| | | | | | | | | | | | | | | We do this so that we can make sure there's a provider installed when we run the tests.
| * | Require rustls 0.23.20Nick Mathewson2025-03-041-1/+2
| | | | | | | | | | | | | | | This is the version that introduces `root_hint_subjects()`, which we want our ServerCertVerifier to override.
| * | Require rustls-pki-types 1.8 for CertificateDer::from_sliceNick Mathewson2025-03-041-1/+1
| | |
| * | rustls.rs: Replace x509-signature with rustls-webpkiNick Mathewson2025-03-045-103/+76
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The x509-signature crate is archived, and won't see any more releases. Using it is tying us to ring 0.16 internally, which means we depend on two ring versions. Fortunately, rustls-webpki relaxes some of the earlier restrictions from the vanilla webpki crate, which means that its certificate parser now accepts C tor's oddball x509 certificates as valid. With this change, we can delegate to rustls's built-in signature-checking code, and we only have to override its certificate validation. (We still override it with a pile of comments about how we don't validate link certificates much.) I've had to include a few certificates: two are for tests, but one is needed as a placeholder, since we can't construct a rustls certificate validator without a root cert, even if we'll never use it. Closes #1824. Closes #1854.
| * | rtcompat: Un-rename CertificateDer type.Nick Mathewson2025-03-041-6/+8
| | | | | | | | | | | | (We had added this rename when rustls renamed it originally.)
* | | tor-rtcompat: Fix grammar in docIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3168425
* | | tor-rtcompat: Rename spawn_thread to spawn_blockingIan Jackson2025-03-047-43/+42
| | | | | | | | | | | | Let's use Tokio terminology here.
* | | tor-rtcompat: Give a reason in blocking_io for not using for cpu workIan Jackson2025-03-041-1/+4
| | | | | | | | | | | | | | | As requested https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167979
* | | tor-rtcompat: Fix docs typoIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167978
* | | tor-rtcompat: Change the title of RuntimeIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167977
* | | tor-rtcompat: Clarify reentrancy restrictions on `block_on`Ian Jackson2025-03-041-2/+5
| | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167976
* | | tor-rtcompat: Remove the TODO re #1835Ian Jackson2025-03-041-3/+0
| | | | | | | | | | | | This is the TODO we are fixing with this MR.
* | | tor-rtcompat: Explain Sendness of reenter_block_on futureIan Jackson2025-03-042-0/+7
| | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167975 Also allow ourselves the option of changing this in the future.
* | | tor-rtcompat: Clarify distinction between Runtime and ToplevelIan Jackson2025-03-041-2/+8
| | | | | | | | | | | | | | | Prompted by and partially taken from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167973
* | | tor-rtcompat: Linkify a mention of spawn_threadIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167972
* | | tor-rtcompat: Clarify docs (3)Ian Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167970
* | | tor-rtcompat: Make a precise example for mpsc::channelIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167969
* | | tor-rtcompat: Blocking::spawn_thread semantics correctionIan Jackson2025-03-041-2/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | The: table entry for `spawn_thread` was wrong. We use AsyncExecutors' spawn_blocking which uses tokio::task::spawn_blocking. This has implications for the semantics, as per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167967 https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167968
* | | tor-rtcompat: Clarify docs (2)Ian Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167966
* | | tor-rtcompat: Clarify docsIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | As suggested https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167965
* | | tor-rtcompat: Add a semver.md for changes to BlockOn etc.Ian Jackson2025-03-041-0/+4
| | |
* | | tor-rtmocK; Detect wrong-context blocking_io and spawn_threadIan Jackson2025-03-043-2/+20
| | |
* | | tor-rtmock: Split out spawn_thread_innerIan Jackson2025-03-041-5/+16
| | | | | | | | | | | | | | | This will let us call _inner from blocking_io, with a different precondition. No functional change.
* | | tor-rtmocK; Detect re-entry into MockExecutorIan Jackson2025-03-042-7/+29
| | |
* | | tor-rtmock: task: Remove Default impl for ThreadDescriptorIan Jackson2025-03-0423-25/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | This is going to become a hazard. Let's be explicit. This means using educe to derive the Default for Data. We also need to update our educe dependency to 0.4.22, since that's when Default(expression= "...") started working correctly.
* | | tor-rtmock: Split out executor_main_loopIan Jackson2025-03-041-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | execute_until_first_stall is now simply a wrapper which does some logging. It will do a bit more in a moment. Giving the inner function a more obvious name is helpful, since the executor main loop is a thing one is often looking for.
* | | tor-rt*: Apply deferred formatting churnIan Jackson2025-03-046-10/+11
| | | | | | | | | | | | rustfmt.
* | | tor-rtcompat: CompoundRuntime: Rename TaskR member from SpawnRIan Jackson2025-03-041-40/+39
| | | | | | | | | | | | | | | | | | This member is the principal one which implemnets Spawn, Blocking and perhaps ToplevelBlockOn. It doesn't appear that we actually need to split this into multiple members.
* | | tor-rtcompat: Remove ToplevelBlockon from RuntimeIan Jackson2025-03-049-23/+36
| | | | | | | | | | | | | | | | | | | | | | | | Introduce ToplevelRuntime as an alias, and use it in the top-level programs. Now none of the principal protocol implementation code has access to the executor's toplevel entrypoint, and can't call it by mistake.
* | | tor-rtcompat: Provide Blocking::blocking_ioIan Jackson2025-03-043-2/+70
| | | | | | | | | | | | | | | | | | | | | | | | | | | This was referenced and explained from the docs, but didn't exist yet. Here it is. Everyone except the Tokio glue, and the CompoundRuntime, just use the default implementation in terms of spawn_thread. spawn_thread has a more relaxed contract, so this is correct.
* | | tor-rtcompat: Provide a new function for executor re-entryIan Jackson2025-03-048-5/+92
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Forbid re-entering the executor using ToplevelBlockOn::block_on. This was always forbidden in the case of MockExecutor, but that meant that tests using MockExecutor would malfunction if the code under test needed to re-enter the executor from sync code (since the code under test would have to use block_on, which wrong). See #1835. Provide a function which *can* do this, reenter_block_on. The MockExecutor needs to know the difference, and other runtimes may too. They are conceptually quite different operations. Introduce ToplevelRuntime as a convenience alias.
* | | tor-rtcompat: New plan for blocking interaction, Blocking traitIan Jackson2025-03-048-47/+140
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Document the new plan for blocking interaction in the trait-level docs for the Blocking trait (used to be SpawnBlocking). Add cross-references (in some cases to not-yet-existing pieces). * Rename: spawn_blocking to spawn_thread. We're going to distinguish thread-creation (relatively expensive) from brief entry to sync code (relatively cheap, but more restricted). * Rename the SpawnBlocking trait to Blocking, and its ThreadHandle to ThreadHandle. This trait is going to gain more functionality. * Add the missing mention of `Blocking` to the docs for `Runtime`.
* | | tor-rtcompat: Rename BlockOn to ToplevelBlockOnIan Jackson2025-03-0416-29/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We're going to distinguish top-level runtime entry, from *re*-entry to an existing executor. It is most convenient to rename this trait first. Documentation of the distinction will come later. (We're going to retain the function name `block_on`, but we want the trait to be more obviously a top-level only thing, though, so we give it a name that will hopefully avoid it peroulating throughout the codebase..)
* | | tor-rtmock: Correct a commentIan Jackson2025-03-041-1/+1
|/ / | | | | | | The MockExecutor doesn't have a threadpool.
* | hsclient: Include rsa_id in debugClara Engler2025-03-041-1/+2
| | | | | | | | | | | | | | This commit adds the RSA ID of a relay into a debug statement, as found in other places in the code. It mostly serves the purpose that the Ed25519 ID in itself is rather inconvenient, as metrics.torproject.org only allows querying from the RSA ID.
* | Merge branch 'ctrl-cmd-docs' into 'main'David Goulet2025-03-031-6/+5
|\ \ | | | | | | | | | | | | tor-proto: Update CtrlCmd and CtrlMsg docs. See merge request tpo/core/arti!2829
| * | tor-proto: Update CtrlCmd and CtrlMsg docs.Gabriela Moldovan2025-03-031-6/+5
| | | | | | | | | | | | | | | | | | In aa08ede11fd483cd6dcb4522c431f9e07001717e, the reactor loop was rewritten to unconditionally read from the `CtrlMsg` channel, so we need to adjust the docs.
* | | Merge branch 'conflux-cmds' into 'main'David Goulet2025-03-033-13/+73
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Add CtrlCmd:ShutdownAndReturnCircuit Closes #1876 See merge request tpo/core/arti!2831
| * | | tor-proto: Add CtrlCmd::ShutdownAndReturn circuit.Gabriela Moldovan2025-03-031-0/+18
| | | | | | | | | | | | | | | | Closes #1876
| * | | tor-proto: Add ConfluxSet method for taking the only leg in the set.Gabriela Moldovan2025-03-032-0/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This will be used to implement the new `ShutdownAndReturnCircuit` control command. Part of #1876
| * | | tor-proto: Use bad_api_usage! instead of internal! where applicable (fmt).Gabriela Moldovan2025-03-031-2/+6
| | | |
| * | | tor-proto: Use bad_api_usage! instead of internal! where applicable.Gabriela Moldovan2025-03-031-3/+3
| | | | | | | | | | | | | | | | | | | | Some of these were supposed to be `bad_api_usage`, because they result from API misuse rather than an internal error (bug).
| * | | tor-proto: Factor out conflux set length check to new function (fmt).Gabriela Moldovan2025-03-031-6/+6
| | | |
| * | | tor-proto: Factor out conflux set length check to new function.Gabriela Moldovan2025-03-031-3/+13
| | | | | | | | | | | | | | | | | | | | This will enable us to reuse these checks for implementing other methods that are only supported if the conflux set has a single leg.
| * | | tor-proto: Use handle_shutdown() when handling CtrlCmd::Shutdown.Gabriela Moldovan2025-03-031-1/+1
| |/ / | | | | | | | | | | | | | | | For consistency with the `CtrlCmd::Shutdown` handling from `Reactor::wait_for_create` (`handle_shutdown()` also prints a helpful trace log).
* | | Merge branch 'rm-tor-congestion' into 'main'Nick Mathewson2025-03-034-28/+0
|\ \ \ | | | | | | | | | | | | | | | | tor-congestion: remove crate See merge request tpo/core/arti!2828
| * | | tor-congestion: remove crateSteven Engler2025-03-034-28/+0
| | | |
* | | | tor-proto: remove `Arc<AsyncMutex<_>>` in `Circuit::input`Steven Engler2025-03-032-27/+3
| |/ / |/| |
* | | Merge branch 'conflux-poll-multiple' into 'main'gabi-2502025-03-032-64/+148
|\ \ \ | |/ / |/| | | | | | | | | | | | | | tor-proto: Rewrite reactor loop to read from all circuits. Closes #1863 See merge request tpo/core/arti!2817