aboutsummaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | hs_ntor: several documentation cleanups.Nick Mathewson2023-05-171-6/+14
| | |
| * | hs_ntor: make encrypt_and_mac take a typed public keyNick Mathewson2023-05-171-10/+6
| | | | | | | | | | | | This is still not the most beautiful interface, but it'll do for now.
| * | hs_ntor: remove the last lingering AsRef<[u8]>Nick Mathewson2023-05-171-7/+7
| | |
| * | hs_ntor: Add a test vector case extracted from C tor.Nick Mathewson2023-05-171-0/+104
| | |
| * | hs_ntor: Calculate MAC on introduce1 message correctly.Nick Mathewson2023-05-171-3/+12
| | | | | | | | | | | | | | | | | | There were two bugs here that made the behavior unlike that of C tor: we had swapped the MAC inputs, and we had forgotten to include the public key X in the input.
| * | hs_ntor: Make internal no-rng variants of the handshake functions.Nick Mathewson2023-05-171-2/+25
| | | | | | | | | | | | We'll want these so we can implement some test vectors.
| * | hs_ntor: Move extra data outside of the "input" fields.Nick Mathewson2023-05-171-59/+33
| | | | | | | | | | | | | | | | | | | | | I think that these Input structs had been defined so that we could use hs_ntor interchangeably with other handshakes. The trouble is, though, that it doesn't really work like any other handshakes we have.
| * | hs_ntor: Use MAC implementation from tor-hscryptoNick Mathewson2023-05-171-35/+16
| | | | | | | | | | | | | | | | | | Note that some of the invocations for this function seem to put the key and the message in a questionable order. But that's a thing to figure out later, while debugging.
| * | hs_ntor: Use correct PK types from tor_hscrypto.Nick Mathewson2023-05-171-20/+24
| | |
| * | hs_ntor: Use Subcredential type from tor-hscryptoNick Mathewson2023-05-172-5/+5
| |/
* | cell: Make Introduce2::new testing-only.Nick Mathewson2023-05-171-1/+6
| | | | | | | | | | | | We never want to create one of these from its parts except when we are testing it; we only want to forward an Introduce1 message with a new command on it.
* | cell: Record the text of an INTRODUCE2 headerNick Mathewson2023-05-171-9/+39
| | | | | | | | | | We'll need to store this so that it can later on be used to complete the hs_ntor handshake.
* | cell: extract introduce headers into a new type.Nick Mathewson2023-05-171-20/+42
|/ | | | | | | | We'll want this because our hs_ntor handshake requires access to an encoded version of the header independent from the actual encrypted message. part of #866.
* Merge branch 'info-to-warn' into 'main'gabi-2502023-05-171-5/+8
|\ | | | | | | | | | | | | Change log levels of messages from INFO to others Closes #854 See merge request tpo/core/arti!1172
| * Change log level to debug and warn for certain appropriate situationsSaksham Mittal2023-05-171-5/+8
| | | | | | | | | | | | This commit changes certain log messages to debug for recoverable errors and a warn if all such attempts fail, in order to not clutter up the info messages that end users get to see.
* | Merge branch 'arc_circ' into 'main'gabi-2502023-05-1714-74/+83
|\ \ | | | | | | | | | | | | | | | | | | Refactor ClientCirc APIs to use Arc<ClientCirc>. Closes #846 See merge request tpo/core/arti!1187
| * | Refactor ClientCirc APIs to use Arc<ClientCirc>.Nick Mathewson2023-05-1614-74/+83
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now ClientCirc is no longer `Clone`, and the things that need it to be `Clone` instead return and use an Arc<ClientCirc> We're doing this so that ClientCirc can participate in the RPC system, and so that its semantics are more obvious. Closes #846. Thanks to the type system, this was a much simpler refactoring than I had feared it would be.
* | | Merge branch 'ticket_759' into 'main'Nick Mathewson2023-05-169-17/+66
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-cert: Replace the KeyUnknownCert::check_key API Closes #759 See merge request tpo/core/arti!1184
| * | | Deprecate check_key, and refactor its logic into the new functions.Nick Mathewson2023-05-161-16/+33
| | | | | | | | | | | | | | | | Closes #759
| * | | Replace usage of KeyUnknownCert::check_key.Nick Mathewson2023-05-167-11/+11
| | | |
| * | | tor-cert: Add new functions to replace KeyUnknownCert::check_key.Nick Mathewson2023-05-162-0/+32
| | |/ | |/| | | | | | | | | | | | | | | | These should have a cleaner API than check_key, and be easier to understand. Part of #759
* | | Merge branch 'resolve_relay' into 'main'Nick Mathewson2023-05-161-0/+142
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | netdir: New function to check consistency of a HasRelayIds Closes #855 See merge request tpo/core/arti!1186
| * | | netdir: New function to check consistency of a HasRelayIdsNick Mathewson2023-05-161-0/+142
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This function will be used to look up a relay by a set of LinkSpecs given from an incoming HsDesc or INTRODUCE2 message. It differs from other "lookup relay by IDs" functions in that it needs to be able to return "here's a relay", "couldn't found a relay", or "learned that this relay is impossible." Closes #855: This is the only new API needed for ChanTarget validation, I think.
* | | Merge branch 'rpc-objectmap' into 'main'Nick Mathewson2023-05-163-180/+197
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | RPC: revise semantics for weak references and object IDs Closes #848 See merge request tpo/core/arti!1183
| * | rpc: Split the generational index into two.Nick Mathewson2023-05-161-113/+92
| | | | | | | | | | | | This lets us simplify our logic a bit for strong references.
| * | rpc: Change the formatting of object IDsNick Mathewson2023-05-152-22/+75
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want each ID to have a unique form every time it is given out, so that you can't use ID==ID to check whether Object==Object. (See discussions leading to #848.) We'd also like the form of object IDs to be a little annoying to analyze, to discourage people from writing programs that depends on their particular format. (We are reserving the right to change the format whenever we want.) We _don't_ want to use any cryptography here (yet), lest somebody think that this is an actual security mechanism. (This isn't for security; it's for encouraging developers to treat IDs as opaque.) With that in mind, we now lightly obfuscate our generational indices before returning them.
| * | rpc: rename GenIdx::into/try_from implementationsNick Mathewson2023-05-152-11/+9
| | | | | | | | | | | | | | | These are about to become nondeterministic-ish and probably shouldn't use the Into/TryFrom traits.
| * | rpc: do not deduplicate strong object idsNick Mathewson2023-05-151-52/+39
| | | | | | | | | | | | | | | | | | | | | | | | Per discussion referenced at #848, we want each operation that returns a strong object ID to return a new, distinct strong ID. Note that we no longer need to put strong and weak references in the same arena; we can clean this code up a lot down the road.
| * | rpc: Repair an error in our ObjectId encoding.Nick Mathewson2023-05-151-1/+1
| |/ | | | | | | | | | | Now we generate object IDs that we can parse. This is about to be obsolete once we change how we generate objects and their IDs for #848, but we may as well start from a working state.
* | Revise all XXXXs from fixup-featuresNick Mathewson2023-05-1519-89/+79
| |
* | Run fixup-features _with_ annotations.Nick Mathewson2023-05-1519-0/+70
| | | | | | | | | | This litters our Cargo.toml files with "XXX" entries that we should fix.
* | Reformat Cargo.toml files.Nick Mathewson2023-05-1520-69/+230
| |
* | Run fixup-features --no-annotate for initial Cargo.toml fixes.Nick Mathewson2023-05-1542-44/+118
|/ | | | | | | | | This does the following: - Gives every crate a `full`. - Cause every `full` to depend on `full` from the lower-level crates. - Makes every feature listed _directly_ in `experimental` depend on `__is_experimental`.
* Merge branch 'better-fixup-features' into 'main'Nick Mathewson2023-05-155-14/+24
|\ | | | | | | | | Revise fixup-features to be closer to something we can use See merge request tpo/core/arti!1180
| * Mark an initial set of non-additive features.Nick Mathewson2023-05-155-14/+24
| |
* | Use non-deprecated *Secret::random_from_rng.Nick Mathewson2023-05-136-20/+21
| | | | | | | | The `new` function is deprecated in x25519-dalek 2.0.0-rc.2
* | llcrypto: upgrade x25519-dalek.Nick Mathewson2023-05-131-1/+1
| | | | | | | | | | | | | | | | This upgrades us to 2.0.0-rc.2, which is the latest in the not-quite-done-yet 2.0 series. The only code change that's absolutely needed is opting into the static_secrets feature.
* | tor-basic-utils: Add unbounded range (..) test.Gabriela Moldovan2023-05-131-0/+31
| | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-basic-utils: Update combinatorial test to randomly choose an open or ↵Gabriela Moldovan2023-05-131-2/+12
| | | | | | | | | | | | closed bound. Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-basic-utils: Add rangebounds test with time ranges.Gabriela Moldovan2023-05-131-0/+35
| | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-basic-utils: Assert witness is not part of the intersection.Gabriela Moldovan2023-05-131-0/+4
| | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-basic-utils: Log the ranges/intersection on assertion failure.Gabriela Moldovan2023-05-131-1/+13
| | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | netdoc: Use the RangeBoundsExt impl of TimerangeBound.Gabriela Moldovan2023-05-133-82/+25
| | | | | | | | | | | | We can now get rid of the standalone `intersect_bounds` function. Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-checkable: Implement RangeBounds for TimerangeBound.Gabriela Moldovan2023-05-132-6/+19
| | | | | | | | | | | | | | | | By implementing `RangeBounds` for `TimerangeBound`, we get `RangeBoundsExt` for free. This will enable `parse_decrypt_validate` to easily compute the intersection of the `TimerangeBound`s its layers. Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-basic-utils: Add a helper function to deduplicate test code.Gabriela Moldovan2023-05-131-19/+29
| | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-basic-utils: Add RangeBoundsExt trait.Gabriela Moldovan2023-05-132-0/+201
| | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
* | hsclient: descriptor_ensure no longer wraps the descriptor in TimerangeBound.Gabriela Moldovan2023-05-131-2/+5
| | | | | | | | | | | | | | `descriptor_fetch_attempt` now returns a `TimerangeBound<HsDesc>` (and so does `parse_descript_validate`). Signed-off-by: Gabriela Moldovan <[email protected]>
* | netdoc: Do not consume EncryptedHsDesc when decrypting.Gabriela Moldovan2023-05-131-1/+1
| | | | | | | | | | | | | | | | | | `parse_decrypt_validate` will need to "peek" inside an encrypted descriptor (before validating it) to extract the `TimerangeBound` of the inner layer. This is needed to compute the intersection of the `TimerangeBound`s of both layers. Signed-off-by: Gabriela Moldovan <[email protected]>
* | hsclient: Compute HsDesc validity time from the TimerangeBounds of its layers.Gabriela Moldovan2023-05-132-38/+29
| | | | | | | | | | | | | | This makes `descriptor_ensure` refetch the descriptor if either of its layers (inner or outer) expires. Signed-off-by: Gabriela Moldovan <[email protected]>
* | tor-checkable: Add a way to compute the intersection of 2 RangeBounds.Gabriela Moldovan2023-05-131-0/+71
| | | | | | | | | | | | | | This will be used for computing the final `TimerangeBound` of a `HsDesc` from the `TimerangeBound`s of its inner and outer layers. Signed-off-by: Gabriela Moldovan <[email protected]>