summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | | tor-proto: small comment improvementSteven Engler2026-04-091-1/+2
| | | | |
* | | | | tor-proto: replace a tuple with a dedicated structSteven Engler2026-04-092-18/+29
| | | | |
* | | | | tor-proto: give our ed ident to the channel reactorSteven Engler2026-04-096-5/+48
| | | | | | | | | | | | | | | | | | | | This will be needed for ntor handshakes.
* | | | | proto: Apply deferred rustfmtGabriela Moldovan2026-04-091-1/+1
| | | | |
* | | | | arti-relay: Use a SmallVec for the ntor keysGabriela Moldovan2026-04-092-2/+5
| | | | | | | | | | | | | | | | | | | | Usually, there will only be two of these.
* | | | | proto: Add method for installing ntor keys in the create handlerGabriela Moldovan2026-04-092-3/+28
| | | | | | | | | | | | | | | | | | | | | | | | | This also updates the key rotation task to call the setter whenever the ntor keys get updated.
* | | | | arti-relays: Pass a CreateRequestHandler to the crypto task (fmt)Gabriela Moldovan2026-04-091-3/+8
| | | | |
* | | | | arti-relays: Pass a CreateRequestHandler to the crypto taskGabriela Moldovan2026-04-093-1/+5
| | | | | | | | | | | | | | | | | | | | This will need to be updated each time the ntor keys change.
* | | | | arti-relay: Add tests for the ntor key rotationGabriela Moldovan2026-04-091-0/+53
| | | | |
* | | | | arti-relay: Test that 1 ntor key gets generated on first runGabriela Moldovan2026-04-091-0/+7
| | | | |
* | | | | arti-relay: Dedupe test helperGabriela Moldovan2026-04-091-16/+10
| | | | | | | | | | | | | | | | | | | | | | | | | I am about to add another one of these, so I tried to deduplicate the impls a bit.
* | | | | arti-relays: Extend existing tests to check ntor key rotation (fmt)Gabriela Moldovan2026-04-091-1/+4
| | | | |
* | | | | arti-relays: Extend existing tests to check ntor key rotationGabriela Moldovan2026-04-091-2/+6
| | | | |
* | | | | arti-relay: Generate and rotate ntor keysGabriela Moldovan2026-04-091-10/+162
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There is still some outstanding work here to read the lifetime and grace period from the consensus, but that will require some bigger changes to the rotation task. Closes #2451
* | | | | arti-relay: Add callbacks for deciding whether to expire and generateGabriela Moldovan2026-04-091-11/+26
| | | | | | | | | | | | | | | | | | | | | | | | | The logic for removing and generating ntor keys is going to be slightly different here.
* | | | | arti-relay: Replace have_rotated bools with KeyChange (fmt)Gabriela Moldovan2026-04-091-8/+14
| | | | |
* | | | | arti-relay: Replace have_rotated bools with KeyChangeGabriela Moldovan2026-04-091-15/+23
| | | | | | | | | | | | | | | | | | | | This will enable us to plug in the ntor key rotation logic.
* | | | | arti-relay: Add a struct describing a key change eventGabriela Moldovan2026-04-091-0/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is just a wrapper over `bool` right now. It will helps us distinguish changes to the channel auth material from changes affecting the ntor circuit extension keys.
* | | | | arti-relay: s/have_rotated/have_removed for clarityGabriela Moldovan2026-04-091-2/+2
| | | | |
* | | | | relay-crypto: Add new RelayNtor key wrapperGabriela Moldovan2026-04-091-1/+6
| | | | |
* | | | | Merge branch 'ticket2440_01' into 'main'David Goulet2026-04-097-66/+91
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | chanmgr: Validate the ChanTarget for both client and relay Closes #2404 and #2440 See merge request tpo/core/arti!3843
| * | | | linkspec: Rename all_addrs_allowed_for_extend()David Goulet2026-04-092-4/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also set a better error message when validating channel target. Signed-off-by: David Goulet <[email protected]>
| * | | | relay: Pass advertise SocketAddr to channel builder instead of IpAddrDavid Goulet2026-04-096-22/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This trickles down to the tor-proto channel handshake code. But, the real need is in the channel builder in order to validate the outbound channel target. Fixes #2440 Signed-off-by: David Goulet <[email protected]>
| * | | | chanmgr: Validate the ChanTarget for both client and relayDavid Goulet2026-04-091-41/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It used to be only with the feature = relay but since client can have that feature enabled, we now validate based on channel outbound type instead. Related to #2440 Signed-off-by: David Goulet <[email protected]>
* | | | | Merge branch 'log-ids' into 'main'Jim Newsome2026-04-093-5/+13
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | Log IDs See merge request tpo/core/arti!3872
| * | | | Log socks isolationJim Newsome2026-04-081-0/+1
| | | | |
| * | | | Log tunnel and circuit IDsJim Newsome2026-04-082-5/+12
| | | | |
| * | | | Fix log typo PreeemptiveJim Newsome2026-04-081-1/+1
| | | | |
* | | | | Merge branch 'create-fast' into 'main'gabi-2502026-04-092-56/+71
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Move CREATE_FAST handling to a helper See merge request tpo/core/arti!3869
| * | | | | tor-proto: take `CreateRequest` message by referenceSteven Engler2026-04-082-6/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Clippy has started warning about this since we moved the CREATE_FAST handling to a helper, so this resolves that.
| * | | | | tor-proto: move a TODOSteven Engler2026-04-081-2/+1
| | | | | |
| * | | | | tor-proto: remove old TODOSteven Engler2026-04-081-4/+1
| | | | | |
| * | | | | tor-proto: rustfmtSteven Engler2026-04-081-6/+3
| | | | | | | | | | | | | | | | | | | | | | | | Fix formatting from previous code movement.
| * | | | | tor-proto: move CREATE_FAST handlingSteven Engler2026-04-081-45/+43
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This moves the code, changes the indentation, and wraps the result in an `Ok()`.
| * | | | | tor-proto: prepare to move CREATE_FAST handling to a helperSteven Engler2026-04-081-8/+34
| | | | | |
| * | | | | tor-proto: remove old TODOSteven Engler2026-04-081-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | This had already been resolved.
* | | | | | arti-relay: Fix test MockRuntime::advance_by() usageGabriela Moldovan2026-04-091-6/+2
| |/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was previously advancing time by more than intended (I think the intention here was to use something like `MockRuntime::jump_wallclock()`, but that function has no effect on sleeping futures, so I think we should continue using `advance_by()`).
* | | | | Merge branch 'rustls-defaults' into 'main'Nick Mathewson2026-04-089-37/+72
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Allow compile-time selection of rustls CryptoProvider; use aws-lc-rs by default. Closes #2448 See merge request tpo/core/arti!3857
| * | | | | arti-relay: Change CryptoProvider to aws-lc-rs.Nick Mathewson2026-04-082-3/+4
| | | | | |
| * | | | | rtcompat: document choice of aws_lc_rs providerNick Mathewson2026-04-081-9/+11
| | | | | |
| * | | | | arti: Allow choice of CryptoProvider; use aws-lc-rs by default.Nick Mathewson2026-04-084-18/+41
| | | | | |
| * | | | | rtcompat: Stop installing backup CryptoProvider.Nick Mathewson2026-04-023-7/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When using rustls, previously we'd check to see whether the application had installed a CryptoProvider (as it is required to do). If not, we'd log a warning and install a Ring provider. But now, we want to enable other kinds of providers, so this behavior isn't practical any more. (See #2448 for discussion.) Closes #2448.
* | | | | | Merge branch 'feat/protocol-warnings' into 'main'Nick Mathewson2026-04-084-3/+220
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-error/arti: add logging.protocol_warnings for TorProtocolViolation See merge request tpo/core/arti!3805
| * | | | | | arti: set_protocol_warning_mode to Warn or Off in setup_loggingmoumenalaoui2026-04-082-14/+26
| | | | | | |
| * | | | | | arti: add protocol_warnings config and wire setup_loggingmoumenalaoui2026-03-273-0/+24
| | | | | | |
| * | | | | | tor-error: add runtime ProtocolWarningMode and promote TorProtocolViolation ↵moumenalaoui2026-03-271-1/+182
| | | | | | | | | | | | | | | | | | | | | | | | | | | | in event_report!
* | | | | | | proto: Bring back AuthLogDigest and explicitly convert to SLOG/CLOGDavid Goulet2026-04-084-36/+27
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | From opara's comment: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3844#note_3388789 Keep the low level AuthLogDigest type alias and return it. The callsite is the one deciding if the returned digest is a Clog or a Slog. Related to #2441 Signed-off-by: David Goulet <[email protected]>
* | | | | | | proto: Add ClogDigest and SlogDigest typesDavid Goulet2026-04-087-38/+80
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Introduce those types in order to avoid mixing them up as the previous AuthLogDigest was just a type alias over [u8; 32] Fixes #2441 Signed-off-by: David Goulet <[email protected]>
* | | | | | | Merge branch 'netdoc-test-fix' into 'main'Clara Engler2026-04-0849-2668/+2825
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix the testdata2 situation See merge request tpo/core/arti!3861
| * | | | | | | tor-netdoc: Add manual happy families microdesc testClara Engler2026-04-081-0/+35
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a manual test case for happy families in microdesc with parse2. Manual in the sense that we hardcode a microdescriptor taken from the wild here, as testdata2 does not contain them at the current moment, which is unfortunate but reported.