| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\
| |
| |
| |
| | |
rpclib: Use i64 rather than u64 for request IDs.
See merge request tpo/core/arti!2279
|
| | |
| |
| |
| | |
This makes it conform to the spec and match arti-rpcserver.
|
| |\ \
| | |
| | |
| | |
| | | |
rpcbase: Fix most TODO RPC comments.
See merge request tpo/core/arti!2284
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Per discussion, this field isn't really specified in a way that lets
us fill it sensibly at the moment. So for now, we're going to just
omit it.
Additionally, we said that we'd Report on our errors; this branch
changes the implementation of RpcError to do that.
Question: Will the blanket implementation for Into<RpcError> make
it harder to re-add a Data field later on if we want to do so?
|
| | | |
| | |
| | |
| | |
| | | |
It is no longer necessary to say, for every RPC method,
that its error type is RpcError.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
These methods were defined on DispatchTable, and then replaced by
top-level functions in the crate. (The reason for using top-level
functions instead is so that we get the locking on the dispatch
table correct.)
|
| | | |
| | |
| | |
| | |
| | | |
The duplication is only a few lines. I've looked into a couple of
ways for removing it, but they make the code flow even less clear.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
We have decided not to remove the "anybody can define methods"
property. This commit documents the consequences, and warns
extenders away from some really bad ideas.
|
| | | |
| | |
| | |
| | |
| | | |
These functions are called rarely enough that it is probably okay
for the ergonomics to be a bit verbose.
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
We've wanted separate error codes for "no such method exists" and
"this method exists, but this object doesn't have it."
|
| | | |
| | |
| | |
| | | |
This change would take some serde magic that is probably not worth it.
|
| | | | |
|
| | | |
| | |
| | |
| | | |
(There is no longer such a thing as a "pseudomethod.")
|
| | | |
| | |
| | |
| | |
| | | |
See
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2280#note_3051134
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2280#note_3051270
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2280#note_3051268
|
| | | | |
|
| |/ /
| |
| |
| |
| |
| | |
I'm not particularly pleased with this name. We need names for both
the type, and the trait we'll almost certainly want to introduce in
the future.
|
| | | |
|
| | |
| |
| |
| |
| |
| | |
The "complex" test here is fairly involved, since it tries to detect
deadlocks and race conditions by using multiple threads and
answering requests out of order.
|
| | | |
|
| | |
| |
| |
| | |
This turns out not to be necessary.
|
| | | |
|
| | |
| |
| |
| |
| |
| | |
I hadn't been sure that we wanted to do this, since arti is
forgiving about its inputs, but IIRC Diziet was in favor of this,
and it _does_ make it easier to write tests.
|
| |\ \
| | |
| | |
| | |
| | | |
tor-memquota: HasMemoryCost trait, and type-safe methods
See merge request tpo/core/arti!2282
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Trying to write comprehensive tests for the errors showed that these
impls were missing.
|
| | | |
| | |
| | |
| | | |
This will make testing easier.
|
| | | |
| | |
| | |
| | |
| | | |
Bug found in review:
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2282#note_3051101
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Our stream wrapper is going to want this. It's fiddly enough that
doing it as a standalone facility seems sensible.
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Now the constructor is able to return other data to the caller,
passing it through the mtracker machinery.
|
| | | |
| | |
| | |
| | |
| | | |
I just want this for a test right now, bui it seems like it would be
good to expose it publicly.
|
| | | |
| | |
| | |
| | |
| | | |
We're going to want this as the return value from an accessor
function, which cannot fail for any other reason.
|
| | | |
| | |
| | |
| | |
| | | |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2281#note_3051105
|
| | | |
| | |
| | |
| | | |
The stream wrapper is going to want this.
|
| | | |
| | |
| | |
| | |
| | | |
There is no `p_used` here; what we meant was the very same
`ClaimedQty.`
|
| |/ / |
|
| |/ |
|
| |\
| |
| |
| |
| |
| |
| | |
tor-netdoc: Dangerously expose annotation fields
Closes #1469
See merge request tpo/core/arti!2213
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This commit exposes the fields of `routerdesc::AnnotatedRouterDesc` and
`routerdesc::RouterAnnotation` with the enabled feature
`dangerous-expose-struct-fields`.
On one side, it achieves a greater consistency among the other
structures found within this module; On the other side it makes the
already public API (assuming the feature above is enabled) useable.
Fixes #1469
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This fixes a bug in `ArtiNativeKeystore`'s `Keystore::contains()`
implementation: previously, it called Path::exists() on the relative
path (built by concatenating the key specifier and the extension), so
unless your current directory happened to be the root of the keystore,
`contains()` would always return `false`.
`KeyMgr::generate` uses `Keystore::contains()` under the hood, so it
was affected by this bug too: if called `overwrite = false`, it would
misbehave and overwrite any existing keys.
Internally, we call `KeyMgr::generate` in a couple of places:
* `tor-hsservice/src/lib.rs`, to generate the `hsid` if it doesn't
already exist. This callsite is not affected by the bug, because
`KeyMgr::generate` is only called if `KeyMgr::get` returns `None`
* `tor-hsservice/src/ipt_mgr.rs`, to generate `KS_hss_ntor` and
`KS_hs_ipt_sid` keys for intro point establishment. This callsite is
also not affected (because it too calls `get()` before attempting to
`generate()`)
The bug affects any downstream users that use `KeyMgr::generate`
with a key manager backed by `ArtiNativeKeystore`.
------
`KeyMgr::get_or_generate` is not affected, even though it calls
`Keymgr::generate` (it performs a separate extra check before calling
`generate()`). (Both suffer from a known TOCTOU race, but that's a
separate matter.) As an aside, I'd like to somehow unify
`KeyMgr::get_or_generate` and `KeyMgr::get` (I've had some attempts in
the past but ended up abandoning them because the result was more
unergonomic than the existing APIs).
Part of #1492
|