summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | tor-proto: improve error messages using `RestrictedMsg`Steven Engler2026-03-032-35/+17
| | | | | |
| * | | | | tor-cell: add `RestrictedMsg` traitSteven Engler2026-03-031-0/+35
| | | | | |
| * | | | | tor-proto: improve error messages during handshakeSteven Engler2026-03-032-5/+7
| | | | | |
| * | | | | tor-basic-utils: clean up `iter_join`Steven Engler2026-03-031-8/+6
| | | | | |
| * | | | | tor-basic-utils: move `iter_join` from arti-relaySteven Engler2026-03-034-33/+37
| | | | | | | | | | | | | | | | | | | | | | | | Will clean this up in the following commit.
* | | | | | Merge branch 'dirclient-empty-successful' into 'main'Clara Engler2026-03-045-6/+39
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-dirclient: Disallow empty successful responses See merge request tpo/core/arti!3650
| * | | | | | tor-dirclient: Add semver.mdClara Engler2026-03-041-0/+1
| | | | | | |
| * | | | | | Rename DirResponse::from_body to from_get_bodyClara Engler2026-03-042-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This reflects that it is expected for an HTTP GET body. It is okay because it is only used in tor-dirmgr, which only performs GET request anyways.
| * | | | | | tor-dirclient: Only fail on empty GET responsesClara Engler2026-03-043-12/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit fixes the previous check to only fail on empty GET responses. For this, it introduces a `method` field into `DirResponse`, which is required to determine the method there. Doing this is reasonable for an HTTP client, as responses have different meanings depending on the request method used.
| * | | | | | tor-dirclient: Disallow empty successful responsesClara Engler2026-03-042-0/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit disallows empty responses with a status code 200. From a pure HTTP level, this is totally valid, but it does not make any sense in the context of the Tor directory protocol, where an empty response only makes sense with a 404. The motivation for this is that a work-in-progress tor_dirclient::send_request wrapper for tor-dirserver passes the response into the parse2 multiple function which returns a Vec<T>. Interfacing code would then always have to check for an empty length and do respective error handling, which should already fail at an earlier level (tor-dirclient) instead.
* | | | | | | deps: use the same `rusqlite` version range for all cratesHydroxideUnlaced2026-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
* | | | | | | Apply 1 suggestion(s) to 1 file(s)HydroxideUnlaced2026-03-041-0/+1
| | | | | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
* | | | | | | deps: relax `libsqlite3-sys` version requirementHydroxideUnlaced2026-03-042-3/+8
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The issue concerns `libsqlite3-sys` linking to a native library. Cargo cannot handle multiple versions/crates linking to the same native library. This affects both the `tor-dirmgr` and `tor-dirserver` crates, which depend on `rusqlite`. Relaxing the version requirement gives downstream projects flexibility so cargo can select an appropriate `libsqlite3-sys` version without a high chance of conflicts caused by pinning a specific version. The proposed supported version range was determined by testing until encountering a version lacking a feature currently in use (breaking unchange?). Regarding testing, the current CI with minimum-version test only validates the maximum and minimum versions, so breaking changes introduced between them can pass unnoticed. Tools like [Cargo-Bounds](https://github.com/vivax3794/cargo_bounds) can help, but this is out of scope for this MR. Also, supported versions of `rusqlite` for `tor-dirmgr` and `tor-dirserver` differ, so running tests for the whole project (same workspace) causes cargo to pick only overlapping versions, which hides parts of each crate’s supported range. Referencing #754, after this MR, increasing the maximum version or decreasing the minimum version of `rusqlite` shouldn't be a breaking change, but increasing the minimum version could be. Resolves: #1740
* | | / / / arti-client: Remove "not as secure as C Tor" text in the README.Nick Mathewson2026-03-041-4/+1
| |_|/ / / |/| | | | | | | | | | | | | | | | | | | I think we currently have the same security features implemented in Arti as C tor has.
* | | | | Bump strum to 0.28Gabriela Moldovan2026-03-0414-14/+14
| | | | |
* | | | | rtcompat: Bump async-native-tls to 0.6.0Gabriela Moldovan2026-03-041-1/+1
| | | | |
* | | | | arti: Bump trycmd to 1.0.0Gabriela Moldovan2026-03-041-1/+1
| | | | |
* | | | | arti-ureq: Bump ureq to ~3.2.0Gabriela Moldovan2026-03-041-1/+1
| | | | |
* | | | | memquota: Bump sysinfo to 0.38.3Gabriela Moldovan2026-03-041-1/+1
| | | | |
* | | | | hashx: Bump dynasmrt to 5.0.0Gabriela Moldovan2026-03-044-10/+10
| | | | | | | | | | | | | | | | | | | | | | | | | Contains a small code change as `bare_relocation()` was replaced with `value_relocation()`.
* | | | | Bump toml to 1.0.3Gabriela Moldovan2026-03-049-9/+9
| | | | |
* | | | | Merge branch 'cargo-update' into 'main'gabi-2502026-03-042-0/+4
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Run cargo update post-release See merge request tpo/core/arti!3740
| * | | | rtmock, chanmgr: Allow use of deprecated try_next() in testsGabriela Moldovan2026-03-032-0/+4
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | futures 0.3.32 has deprecated UnboundedReceiver::try_next() in favor of UnboundedReceiver::try_recv(), but try_recv() was only introduced in 0.3.32, so using it would cause our minimal versions checks to fail (rightfully so, because our code wouldn't build with futures 0.3.x for x < 32).
* | | | tor-proto: during handshake ensure circ id is 0Steven Engler2026-03-032-4/+18
| | | |
* | | | tor-proto: require cells from initiator to be orderedSteven Engler2026-03-031-61/+112
| | | |
* | | | tor-proto: require cells from responder to be orderedSteven Engler2026-03-032-61/+97
| | | |
* | | | tor-proto: make receiving AUTH_CHALLENGE non-optionalSteven Engler2026-03-032-8/+3
| | | |
* | | | tor-proto: remove `is_expecting_auth_challenge()`Steven Engler2026-03-033-14/+1
| | | | | | | | | | | | | | | | The responder always sends an AUTH_CHALLENGE cell.
* | | | tor-proto: send an AUTH_CHALLENGE during testsSteven Engler2026-03-032-0/+7
|/ / / | | | | | | | | | | | | | | | | | | As far as I know, a responder will always send an AUTH_CHALLENGE cell since it doesn't yet know if the initiator is a client or relay. The spec also doesn't have any mention about the AUTH_CHALLENGE being optional. So we should send it in our tests as well.
* | | safelog: Rename MaybeSensitive::hidden/visible()David Goulet2026-03-038-17/+22
| | | | | | | | | | | | | | | | | | Rename them to respectively sensitive() and not_sensitive(). Signed-off-by: David Goulet <[email protected]>
* | | linkspec: Implement a RelayIdsBuilder::from_relay_ids()David Goulet2026-03-032-6/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | This is used when we build an OwnedChanTarget using the builder. Instead of going identities by identities at the callsite, we can use this helper to get us a RelayIds builder and set it in the OwnedChanTargetBuilder. Signed-off-by: David Goulet <[email protected]>
* | | chanmgr: Safely log the peer in the channel builderDavid Goulet2026-03-032-18/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | On I/O error, we safely log the peer address that was used that lead to this error. Closes #2375 Signed-off-by: David Goulet <[email protected]>
* | | proto: Channel handshake minor cleanupDavid Goulet2026-03-033-11/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | To make the code a bit better here. Also, at this commit, the UnverifiedChannel::finish() and VerifiedChannel::finish() are basically the exact same. A refactoring to use a finish() helper would work nicely. Signed-off-by: David Goulet <[email protected]>
* | | proto: Setup the channel PeerInfo in the specialized finish()David Goulet2026-03-036-67/+73
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Every specific types know if the peer is sensitive or not so now the finish() of each of these channel types builds the right PeerInfo with MaybeSensitive. This is passed on the Channel so from that point on, the Channel will never leak peer data in the logs. Signed-off-by: David Goulet <[email protected]>
* | | proto: Make PeerInfo accessors pub(crate)David Goulet2026-03-031-2/+8
| | | | | | | | | | | | | | | | | | | | | | | | And implement Display as well. This is for the upcoming changes to be able to wrap PeerInfo into a MaybeSensitive<> container which can be logged safely hence the Display. Signed-off-by: David Goulet <[email protected]>
* | | safelog: Add MaybeSensitive structDavid Goulet2026-03-031-0/+47
| | | | | | | | | | | | | | | | | | | | | This is meant to be like MaybeRedacted but for the Sensitive<> container. Signed-off-by: David Goulet <[email protected]>
* | | proto: Implement Display for PeerAddrDavid Goulet2026-03-032-1/+11
| | | | | | | | | | | | | | | | | | This required to implement Display for PtTarget. Signed-off-by: David Goulet <[email protected]>
* | | proto: Make channel PeerAddr sensitiveDavid Goulet2026-03-036-26/+39
| | | | | | | | | | | | | | | | | | | | | Only the R2R channel that the PeerAddr becomes unsensitive. The rest, we keep it sensitive as it can be a client or a client's guard/bridge. Signed-off-by: David Goulet <[email protected]>
* | | Merge branch 'slog-clog' into 'main'opara2026-03-032-54/+84
|\ \ \ | | | | | | | | | | | | | | | | tor-proto: rename 'SLOG'/'CLOG' and related code See merge request tpo/core/arti!3732
| * | | tor-proto: rename 'SLOG'/'CLOG' and related codeSteven Engler2026-03-022-54/+84
| | | |
* | | | Remove semver.md files post-releaseGabriela Moldovan2026-03-036-8/+0
| | | |
* | | | Update the release date for today's releaseGabriela Moldovan2026-03-031-1/+1
| | | |
* | | | Merge branch '2.1.0-bumps' into 'main'gabi-2502026-03-0267-700/+704
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Version bumps for 2.1.0 See merge request tpo/core/arti!3733
| * | | | arti: Add placeholder derive-deftly featureGabriela Moldovan2026-03-022-1/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `derive-deftly` used to be an optional dependency in `arti` (with a corresponding `derive-deftly` feature to enable it). In 28081850a5b475e9ae557a926d7f9a08a2ac9c82, we made `derive-deftly` a non-optional dependency, which made the implicit feature disappear. This was detected as a semver breakage by `cargo-semver-checks`, so I am adding a placeholder deprecated feature to make sure this doesn't break anyone's builds.
| * | | | Bump arti crate to 2.1.0Gabriela Moldovan2026-03-023-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Done using: ``` cargo set-version --bump minor -p arti ```
| * | | | Bump all the unstable tor- and arti- crates to 0.40.0.Gabriela Moldovan2026-03-0254-510/+510
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Done using: ``` for crate in $(./maint/list_crates | rg '^(tor|arti-)'); do cargo set-version -p $crate 0.40.0 done
| * | | | Run cargo update for {hashx,equix}/benchGabriela Moldovan2026-03-022-97/+97
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Done using ``` (cd crates/hashx/bench && cargo update) (cd crates/equix/bench && cargo update) ```
| * | | | Bump the versions of the non-{arti-,tor-} cratesGabriela Moldovan2026-03-0245-89/+89
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The non-{arti-,tor-} crates are: ``` ./maint/list-crates | rg -v '^(tor|arti)' oneshot-fused-workaround slotmap-careful test-temp-dir fslock-guard hashx equix caret fs-mistrust safelog retry-error futures-copy ``` Because this release bumps the MSRV, I am bumping the minor version of all of them. MINOR=" oneshot-fused-workaround slotmap-careful test-temp-dir fslock-guard hashx equix caret fs-mistrust safelog retry-error futures-copy " for crate in $MINOR; do cargo set-version --bump minor -p $crate; done ```
* | | | | Merge branch 'release-date' into 'main'gabi-2502026-03-021-1/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Update release date in preparation for today's release See merge request tpo/core/arti!3734
| * | | | | Update release date in preparation for today's releaseGabriela Moldovan2026-03-021-1/+1
| |/ / / /