summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | | llcrypto: Document some design choices from CautiousRng.Nick Mathewson2025-03-241-1/+12
| | | | |
* | | | | Use an EntropicRng trait to enforce key generation rules.Nick Mathewson2025-03-2410-20/+82
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want to require that whenever we generate a key that's persistent (stored in KeyMgr), it's going to be made from a stronger-than-usual Rng. This trait helps us enforce that. We also add a FakeEntropicRng struct to use for testing. Note that this turned up a case that we'd missed, which required an internal change in tor-hsservice.
* | | | | Use CautiousRng for keys going into the KeyMgr.Nick Mathewson2025-03-246-6/+22
| | | | |
* | | | | llcrypto: new CautiousRng for constructing long-lived keysNick Mathewson2025-03-243-0/+152
| |/ / / |/| | | | | | | | | | | | | | | | | | | This Rng combines inputs from several sources, including OsRng, to minimize the likelihood of falling to a vulnerability in any particular one.
* | | | Merge branch 'tests-rpcserver-msgs' into 'main'Nick Mathewson2025-03-241-6/+25
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | rpcserver: Increase coverage in msgs module See merge request tpo/core/arti!2870
| * | | rpcserver: Increase coverage in msgs modulevcrn2025-03-241-6/+25
| | | |
* | | | Merge branch 'fallbackdirs-03-2025' into 'main'opara2025-03-241-920/+897
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | fallbackdir: Update list generated on March 20, 2025 See merge request tpo/core/arti!2875
| * | | | fallbackdir: Update list generated on March 20, 2025Tor CI Release2025-03-241-920/+897
| | | | | | | | | | | | | | | | | | | | Signed-off-by: Tor CI Release <[email protected]>
* | | | | Merge branch 'return-errors-through-channel' into 'main'opara2025-03-243-50/+74
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | tor-proto: some TODO fixes in `ControlHandler` See merge request tpo/core/arti!2867
| * | | | tor-proto: send errors to oneshot channel in more placesSteven Engler2025-03-241-16/+38
| | | | |
| * | | | tor-proto: made `StreamTarget::send_sendme` async and fixed a TODOSteven Engler2025-03-243-10/+28
| | | | |
| * | | | tor-proto: remove previously completed TODOsSteven Engler2025-03-241-21/+7
| | | | |
| * | | | tor-proto: fix small TODOSteven Engler2025-03-241-3/+1
| | |/ / | |/| |
* | | | RPC: Explain in more detail about Windows "named pipe"sIan Jackson2025-03-241-2/+5
| | | |
* | | | AF_UNIX terminology: Rename two error structsIan Jackson2025-03-2410-21/+43
| | | | | | | | | | | | | | | | | | | | | | | | We change `NoUnixAddressSupport` to `NoAfUnixSocketSupport` because it doesn't make much sense to talk about support for the addresses separately from support for the sockets.
* | | | AF_UNIX terminology: Rename two error variantsIan Jackson2025-03-247-13/+32
| | | | | | | | | | | | | | | | Change `..UnixAddress...` to `...AfUnixAddress..`.
* | | | RPC: Abolish an unused and misnamed error variantIan Jackson2025-03-243-5/+4
| | | | | | | | | | | | | | | | | | | | This variant breaches the new guidelines about AF_UNIX terminology. And its purpose is unclear and it's not used.
* | | | Fix AF_UNIX terminology in docs, comments, and error messagesIan Jackson2025-03-248-22/+22
|/ / /
* | | tor-netdir: Handle InsufficientNonZero error.Nick Mathewson2025-03-201-0/+8
| | | | | | | | | | | | Possible fix for #1902.
* | | Merge branch 'named_protovers' into 'main'David Goulet2025-03-206-12/+176
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | protover: Add support for subprotocol version mnemonics. Closes #1891 See merge request tpo/core/arti!2854
| * | | Use named subprotocol versions throughout arti.Nick Mathewson2025-03-123-11/+12
| | | |
| * | | protover: Add support for subprotocol version mnemonics.Nick Mathewson2025-03-123-0/+161
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It's error-prone to have to remember e.g. that "Desc=5" means "family ID support", so in torspec!251 we added mnemonic names like DESC_FAMILY_IDS. Here we use those names in tor-protover.
| * | | protover: Add Conflux protocol group.Nick Mathewson2025-03-121-1/+3
| | | |
* | | | Merge branch 'client-arti' into 'main'opara2025-03-201-16/+12
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | replace state_dir and storage_mistrust with tor_persist::state_dir::StateDirectory See merge request tpo/core/arti!2863
| * | | replace state_dir and storage_mistrust with ↵abdul28012025-03-201-16/+12
| | | | | | | | | | | | | | | | tor_persist::state_dir::StateDirectory
* | | | Merge branch 'timeout_est_overflow' into 'main'Nick Mathewson2025-03-191-3/+11
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Impose a maximum on our fallback estimated timeout Closes #1693 See merge request tpo/core/arti!2842
| * | | | Impose a maximum on our fallback estimated timeoutNick Mathewson2025-03-061-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The fallback timeout is the one that we use when we have insufficient data. We reset our observations, and maybe rebuild our circuits, when we find that too many circuits have failed recently. When we do so, we double our fallback timeout. Previously we had no limit, which could lead to overflow (#1693). In this commit we impose a maximum of 2 hours, which is ridiculously high. (C tor uses a maximum of INT32_MAX seconds, which is even more ridiculously high.) Closes #1693.
* | | | | Merge branch 'rand-0.9' into 'main'Nick Mathewson2025-03-19117-462/+606
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | Port to rand 0.9 See merge request tpo/core/arti!2869
| * | | | proto: make padding::Parameters construction fallible.Nick Mathewson2025-03-184-23/+106
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The constructor for rand::distr::Uniform is now fallible, so it makes sense to bubble up its restrictions. This is a breaking change.
| * | | | Update Cargo.lock in bench directories.Nick Mathewson2025-03-182-218/+256
| | | | |
| * | | | Add a semver note about rand 0.9Nick Mathewson2025-03-181-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | (This applies to every crate that has an API that takes a `rand::Rng` or any related trait.)
| * | | | Run cargo fmtNick Mathewson2025-03-181-11/+3
| | | | |
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-1823-45/+45
| | | | | | | | | | | | | | | | | | | | - The Rng::gen() functions have been renamed to Rng::random().
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-184-4/+4
| | | | | | | | | | | | | | | | | | | | - Several methods have been moved out of SliceRandom.
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-181-3/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - `rand::thread_rng()` has been deprecated and renamed to `rand::rng()` (I missed these cases because they were from prelude::*)
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-181-1/+2
| | | | | | | | | | | | | | | | | | | | - `Uniform::new_inclusive` is now fallible.
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-183-4/+7
| | | | | | | | | | | | | | | | | | | | - The Standard distribution has been renamed to StandardUniform.
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-184-21/+1
| | | | | | | | | | | | | | | | | | | | - `try_fill_bytes()` is no longer a member of RngCore.
| * | | | llcrypto: add an rng compatibility shim for dalek-cryptoNick Mathewson2025-03-185-5/+57
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | dalek-cryptography is still on rand 0.8, so we need a compatibility shim for the Rng. Fortunately, since we merged interface-abstraction-of-the-daleks (!2868), we no longer need to propagate this compatibility layer throughout our codebase.
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-181-1/+5
| | | | | | | | | | | | | | | | | | | | - `Rng::gen_range()` has been renamed to `Rng::random_range()`
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-187-15/+15
| | | | | | | | | | | | | | | | | | | | - The rand::distributions module has been renamed to rand::distr
| * | | | squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-1856-79/+76
| | | | | | | | | | | | | | | | | | | | - `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
| * | | | Upgrade rand dependency to 0.9.Nick Mathewson2025-03-1830-37/+37
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (Per discussion at #1774, we think the changes are acceptable.) This commit won't compile on its own; subsequent commits will fix it.
| * | | | key-forge: Use CryptoRng from rand.Nick Mathewson2025-03-181-2/+1
| | | | | | | | | | | | | | | | | | | | | | | | | Previously we used the version signature::rand_core for some reason, but that's now incompatible.
| * | | | Always use full path to rand::thread_rng().Nick Mathewson2025-03-184-10/+5
| | | | | | | | | | | | | | | | | | | | | | | | | This is partly for consistency, and partly to facilitate a global search-and-replace.
* | | | | Merge branch '1630-scrub-address-from-output' into 'main'gabi-2502025-03-192-24/+30
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | hsc: remove onion-address flag in favour of stdin Closes #1630 See merge request tpo/core/arti!2861
| * | | | test: Fix get-key-error testcase for hschjrgrn2025-03-192-3/+3
| | | | |
| * | | | test: Fix get-key-error testcase for hschjrgrn2025-03-182-2/+3
| | | | |
| * | | | hsc: Improve get_onion_address functionhjrgrn2025-03-181-2/+3
| | | | |
| * | | | hsc: Add --quite CLI flaghjrgrn2025-03-171-10/+15
| | | | | | | | | | | | | | | | | | | | | | | | | * Add `quite` to the common arguments * Substitute dialoguer in favor of `read_line` in `get_onion_address`