| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This is mostly code motion + some visibility adjustments.
Moving all of these outside of `reactor` makes it easier to see which
parts are internal vs which are accessed by the reactor. It also helps
us enforce/audit invariants such as 'there should be no contention on
the `CircHop::map` mutex' (the stream map is now private to
`reactor::circuit`, and therefore nothing inside `reactor` will be
directly accessing it).
|
| | |
| |
| |
| | |
This will enable us to move `CircHop` out of `reactor.rs`.
|
| | |
| |
| |
| | |
This will enable us to factor `Circuit` out of `reactor.rs`.
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| | |
Here we move the responsibility for removing ExtDoc entries for
vanished blobs into the _caller_ of read_blob(): we want to tidy all
such entries in one go.
Unlike a (reverted) previous approach, this time we don't need a
retry loop.
|
| | | |
|
| | |
| |
| |
| | |
We'll want to use this information to tell us whether to retry.
|
| | |
| |
| |
| | |
I'm about to add a retry mechanism.
|
| | |
| |
| |
| |
| | |
We've already stopped ignoring any DB errors, so we may as well make
sure that any FS errors we encounter are also reported.
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| | |
This will help us keep its members private from the rest
of sqlite.rs, and ensure that things are kept consistent.
(This violates rust formatting for clarity. I'll reindent after.)
|
| | | |
|
| | |
| |
| |
| |
| | |
This is in preparation for making it opaque from the rest
of the code, so that we can more easily reason about it.
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
This can only happen because of a bug or because of db corruption,
and we probably shouldn't ignore it.
|
| | |
| |
| |
| |
| |
| |
| | |
Previously, we would leave the ExtDocs blob to expire on its own,
and it would hang out for up to a week.
Closes #1655.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Also, document that old values will be kicking around
for a little while.
Fortunately:
- Nothing actually looked at these values before.
- All elements in this table have an expiration date, so once a new
version of Arti has been running for a week or two, the old
erroneous values will go away.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
Switch from x509-signature to rustls-webpki when using rustls.
Closes #1824 and #1854
See merge request tpo/core/arti!2816
|
| | | |
| | |
| | |
| | |
| | | |
We do this so that we can make sure there's a provider installed
when we run the tests.
|
| | | |
| | |
| | |
| | |
| | | |
This is the version that introduces `root_hint_subjects()`,
which we want our ServerCertVerifier to override.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The x509-signature crate is archived, and won't see any more
releases. Using it is tying us to ring 0.16 internally,
which means we depend on two ring versions.
Fortunately, rustls-webpki relaxes some of the earlier restrictions
from the vanilla webpki crate, which means that its certificate parser
now accepts C tor's oddball x509 certificates as valid.
With this change, we can delegate to rustls's built-in
signature-checking code, and we only have to override its
certificate validation. (We still override it with a pile of
comments about how we don't validate link certificates much.)
I've had to include a few certificates: two are for tests,
but one is needed as a placeholder, since we can't construct
a rustls certificate validator without a root cert,
even if we'll never use it.
Closes #1824.
Closes #1854.
|
| | | |
| | |
| | |
| | | |
(We had added this rename when rustls renamed it originally.)
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3168425
|
| | | |
| | |
| | |
| | | |
Let's use Tokio terminology here.
|
| | | |
| | |
| | |
| | |
| | | |
As requested
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167979
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167978
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167977
|
| | | |
| | |
| | |
| | |
| | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167976
|
| | | |
| | |
| | |
| | | |
This is the TODO we are fixing with this MR.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167975
Also allow ourselves the option of changing this in the future.
|
| | | |
| | |
| | |
| | |
| | | |
Prompted by and partially taken from
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167973
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167972
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167970
|
| | | |
| | |
| | |
| | |
| | | |
See
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167969
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The: table entry for `spawn_thread` was wrong. We use AsyncExecutors'
spawn_blocking which uses tokio::task::spawn_blocking.
This has implications for the semantics, as per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167967
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167968
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167966
|
| | | |
| | |
| | |
| | |
| | | |
As suggested
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167965
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
This will let us call _inner from blocking_io, with a different
precondition. No functional change.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This is going to become a hazard. Let's be explicit.
This means using educe to derive the Default for Data.
We also need to update our educe dependency to 0.4.22, since that's
when Default(expression= "...") started working correctly.
|