| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
There is no `Multiple` counterpart in `CircuitAction`, so the `Single`
variant name doesn't make much sense.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The `LegId` is now added by the caller, when converting the resulting
`CircuitCmd`s to `RunOnceCmdInner`.
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
`CircuitCmd`s are a subset of `RunOnceCmdInner`, and don't have a
`LegId`.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
A `CircuitCmd`, unlike `RunOnceCmdInner`, doesn't know anything about
`LegId`s. The user of the `CircuitCmd`s is supposed to know the `LegId`
of the circuit the `CircuitCmd` came from. This is necessary because
circuits don't know (and can't know) their own `LegId`.
The various `Circuit` operations (e.g. `handle_cell`) will soon be
updated to return `CircuitCmd` instead of `RunOnceCmdInner` (because the
`RunOnceCmdInner` variants will soon be updated to also have an
associated `LegId`, and `Circuit`s don't have access to their `LegId`s).
The calling code, which *does* know the `LegId`, will then map
`CircuitCmd`s to `RunOnceCmdInner`.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This tells the reactor which circuit leg the input message originated
from.
Addresses a TODO.
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
We want to require that whenever we generate a key that's persistent
(stored in KeyMgr), it's going to be made from a stronger-than-usual
Rng. This trait helps us enforce that.
We also add a FakeEntropicRng struct to use for testing.
Note that this turned up a case that we'd missed, which required
an internal change in tor-hsservice.
|
| | | | | | |
|
| | |/ / /
|/| | |
| | | |
| | | |
| | | |
| | | | |
This Rng combines inputs from several sources,
including OsRng, to minimize the likelihood
of falling to a vulnerability in any particular one.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | | |
rpcserver: Increase coverage in msgs module
See merge request tpo/core/arti!2870
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
fallbackdir: Update list generated on March 20, 2025
See merge request tpo/core/arti!2875
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: Tor CI Release <[email protected]>
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
tor-proto: some TODO fixes in `ControlHandler`
See merge request tpo/core/arti!2867
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | | |/ /
| |/| | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
We change `NoUnixAddressSupport` to `NoAfUnixSocketSupport` because it
doesn't make much sense to talk about support for the addresses
separately from support for the sockets.
|
| | | | |
| | | |
| | | |
| | | | |
Change `..UnixAddress...` to `...AfUnixAddress..`.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This variant breaches the new guidelines about AF_UNIX terminology.
And its purpose is unclear and it's not used.
|
| |/ / / |
|
| | | |
| | |
| | |
| | | |
Possible fix for #1902.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
protover: Add support for subprotocol version mnemonics.
Closes #1891
See merge request tpo/core/arti!2854
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
It's error-prone to have to remember e.g. that "Desc=5"
means "family ID support", so in torspec!251 we added mnemonic names
like DESC_FAMILY_IDS.
Here we use those names in tor-protover.
|
| | | | | |
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | | |
replace state_dir and storage_mistrust with tor_persist::state_dir::StateDirectory
See merge request tpo/core/arti!2863
|
| | | | |
| | | |
| | | |
| | | | |
tor_persist::state_dir::StateDirectory
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Impose a maximum on our fallback estimated timeout
Closes #1693
See merge request tpo/core/arti!2842
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The fallback timeout is the one that we use when we have
insufficient data. We reset our observations, and maybe rebuild
our circuits, when we find that too many circuits have failed
recently. When we do so, we double our fallback timeout.
Previously we had no limit, which could lead to overflow (#1693).
In this commit we impose a maximum of 2 hours,
which is ridiculously high.
(C tor uses a maximum of INT32_MAX seconds, which is even more
ridiculously high.)
Closes #1693.
|
| |\ \ \ \ \
| |_|/ / /
|/| | | |
| | | | |
| | | | | |
Port to rand 0.9
See merge request tpo/core/arti!2869
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The constructor for rand::distr::Uniform is now fallible,
so it makes sense to bubble up its restrictions.
This is a breaking change.
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
(This applies to every crate that has an API that takes a
`rand::Rng` or any related trait.)
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- The Rng::gen() functions have been renamed to Rng::random().
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- Several methods have been moved out of SliceRandom.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
- `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
(I missed these cases because they were from prelude::*)
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- `Uniform::new_inclusive` is now fallible.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- The Standard distribution has been renamed to StandardUniform.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- `try_fill_bytes()` is no longer a member of RngCore.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
dalek-cryptography is still on rand 0.8, so we need a compatibility
shim for the Rng.
Fortunately, since we merged interface-abstraction-of-the-daleks
(!2868), we no longer need to propagate this compatibility layer
throughout our codebase.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- `Rng::gen_range()` has been renamed to `Rng::random_range()`
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- The rand::distributions module has been renamed to rand::distr
|
| | | | | |
| | | | |
| | | | |
| | | | | |
- `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
(Per discussion at #1774, we think the changes are acceptable.)
This commit won't compile on its own; subsequent commits will fix it.
|