aboutsummaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | tor-netdoc: Add test only rd_encode_sign() methodClara Engler2026-07-301-0/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a bad encode_sign() method for RouterDesc that is testing only and will be used soon to implement testing for invalid router descriptors, for which we may need to create invalid ones in the first place.
| * | | | | tor-netdoc: Call .verify() in test_parse2_simpleClara Engler2026-07-301-1/+8
| | | | | |
| * | | | | tor-netdoc: Add RouterDescUnverified::verify()Clara Engler2026-07-301-5/+118
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit implements verification for router descriptors. 🎉 For this, the following checks are performed: * RouterDesc::identity_ed25519 is validly signed. * RouterDesc::master_key_ed25519 is as implied by identity_ed25519. * RouterDesc::fingerprint is as implied by RouterDesc::signing_key. * RouterDesc::ntor_onion_key_crosscert is validly signed. * RouterDesc::signing_key has correct length and exponent. * All RouterDesc::family_cert elements are valid. * The inner and outer RouterDescSignatures are valid. Unfortunately, we now have two implementations for that, as the legacy parse_internal() also implements its own verification logic for this. It seems merging these two together however would probably cause more harm than good, as the legacy verification is closely intertwined with legacy parsing, making a commonly shared verification logic hard to achieve. In other words: parse2 parses the descriptor in its entirety first, followed by verification afterwards, whereas the legacy code parses and verifies every field before advancing towards the next. Instead, I suggest to read through RouterDesc::parse_internal() and ensure that every verification related check present there is also present here. The notable exception to this is everything TAP related, which is absent on purpose here. Right now, this code is untested. I will add unit tests shortly afterwards.
| * | | | | tor-netdoc: Derive Copy for Ed25519PublicClara Engler2026-07-292-1/+2
| |/ / / / | | | | | | | | | | | | | | | The underlying type also implements Copy. We will need it later.
* | | | | tor-proto: fix tests when `feature = relay`Steven Engler2026-07-291-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ```text $ cargo test -p tor-proto --features relay [...] error[E0405]: cannot find trait `IncomingStreamRequestFilter` in this scope --> crates/tor-proto/src/circuit/reactor.rs:631:10 | 631 | impl IncomingStreamRequestFilter for AllowAllStreamsFilter { | ^^^^^^^^^^^^^^^^^^^^^^^^^^^ not found in this scope ```
* | | | | proto: Use PeerInfo to log responder channel addrDavid Goulet2026-07-291-2/+2
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Inbound channel (as responder) don't have a ChannelMethod as they are not initiating the type of transport to use (PT vs Direct). It would result in a log line when receiving a channel request: DEBUG tor_proto::channel::handshake: Completed handshake without authentication to [? ] stream_id=Chan 2 This commit uses the `PeerInfo` which is wrapped in a `MaybeSensitive` and thus safe to log. Signed-off-by: David Goulet <[email protected]>
* | | | Merge branch 'no-tap' into 'main'Ian Jackson2026-07-291-49/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-netdoc: routerdesc: Abolish onion-key (obsolete TAP) field See merge request tpo/core/arti!4244
| * | | | tor-netdoc: routerdesc: Abolish onion-key & -crosscert handling in old parserIan Jackson2026-07-291-38/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `onion_key_crosscert` was already absent from `RouterDesc`, even though its item `onion-key-crosscert` was processed by the old parser. Delete it all.
| * | | | tor-netdoc: routerdesc: Abolish onion-key (obsolete TAP) fieldIan Jackson2026-07-291-11/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | See prop350 https://spec.torproject.org/proposals/350-remove-tap.html This is part of "Phase 3, Item 2: Remove vestigial TAP code in Arti". Technically we are not at phase 3 yet, because we haven't yet sunsetted C Tor 0.4.8 and made the dirauth changes in Phase 2. However, this field is not used in Arti right now. RouterDescs are used by client code for handling bridges (but we never use TAP keys), and the RouterDesc type will be used for generation and mirroring by by Arti Relay/Dirauth. In prop350 we have decided that we won't be deploying Arti Relay until this as been done.
* | | | | relay: Keep desc publisher idle until encoding is implementedDavid Goulet2026-07-281-1/+2
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Make build_descriptor() return Arc<str>David Goulet2026-07-281-9/+2
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Add needeed changes to dirmirror todo commentDavid Goulet2026-07-281-1/+2
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Get rid of our custom relay desc uploaderDavid Goulet2026-07-281-51/+20
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Use mpsc_channel_no_memquota for tasks' queueDavid Goulet2026-07-282-4/+5
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Move authorities ownership to TorRelayDavid Goulet2026-07-282-20/+12
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Adjust the try_send() error messageDavid Goulet2026-07-282-3/+6
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Use warn_report on crypto task command failureDavid Goulet2026-07-281-1/+2
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Use DirectHttpUploader for the desc taskDavid Goulet2026-07-281-31/+12
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Return bug error if dir authority has no address(es)David Goulet2026-07-281-3/+4
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Make compute_targets() not return an OptionDavid Goulet2026-07-281-10/+10
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Remove runtime from desc task structDavid Goulet2026-07-282-13/+6
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Add crypto task command channelDavid Goulet2026-07-284-12/+97
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Give a tx to the descriptor task so it can request the keys when building a new descriptor. Implement the crypto task handling of that command channel. Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Pass the desc task TX to the crypto taskDavid Goulet2026-07-284-6/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The crypto task can now signal the descriptor task that the keys have changed related to the relay descriptor (signing key and ntor keys) so a new descriptor can be built and uploaded. Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Implement descriptor upload in desc taskDavid Goulet2026-07-282-10/+31
| | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Pass the dirauth list to the desc taskDavid Goulet2026-07-283-11/+53
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Config reload is not fully supported just yet but when that comes, we'll need to make a task command for new targets. Signed-off-by: David Goulet <[email protected]>
* | | | | relay: Initial skeleton of the descriptor upload taskDavid Goulet2026-07-284-0/+280
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the basics, with many TODO(relay), for a relay descriptor upload task which uses tor-dirpublish::Publisher. Future commits will implement the several todo!(). Signed-off-by: David Goulet <[email protected]>
* | | | Merge branch 'destroyreason' into 'main'gabi-2502026-07-282-3/+3
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | align DestroyReason with torspec!490 Part of #2578 See merge request tpo/core/arti!4202
| * | | | align DestroyReason with torspec!490ramdoys2026-07-282-3/+3
| |/ / /
* | | | tor-proto: build crypt state after building hop settingsSteven Engler2026-07-271-10/+10
| | | | | | | | | | | | | | | | | | | | | | | | `HopSettings::from_handshake_params()` checks that the parameters are correct, so if there are invalid parameters we should fail early before we initialize the `CryptStatePair`.
* | | | tor-proto: move where we split 'crypt' in CREATE_FAST handshakeSteven Engler2026-07-271-2/+2
| | | | | | | | | | | | | | | | This is just to make ntor and CREATE_FAST handshakes consistent.
* | | | tor-proto: add some log messages after circuit handshakeSteven Engler2026-07-271-0/+5
|/ / /
* | | Merge branch 'clippy' into 'main'opara2026-07-275-16/+11
|\ \ \ | |/ / |/| | | | | | | | Fix some recently-appearing clippy lints See merge request tpo/core/arti!4240
| * | tor-proto: Remove a redundant explicit link targetIan Jackson2026-07-271-1/+1
| | | | | | | | | | | | Found by rustdoc.
| * | tor-hsservice: Remove a useless formatIan Jackson2026-07-271-4/+4
| | | | | | | | | | | | Placates clippy.
| * | tor-netdoc: Replace two open-coded slice::fillIan Jackson2026-07-272-6/+2
| | | | | | | | | | | | Placates recent clippy.
| * | tor-hscrypto: Replace .chunks_exact with .as_chunks (fmt)Ian Jackson2026-07-271-4/+4
| | |
| * | tor-hscrypto: Replace .chunks_exact with .as_chunksIan Jackson2026-07-271-3/+2
| | | | | | | | | | | | | | | | | | Placates recent clippy. I find the API of both of these functions unsatisfactory and would prefer a chunks_exact that promises to panic, but I didn't find one in std or Itertools.
* | | Merge branch 'intern' into 'main'Ian Jackson2026-07-278-25/+25
|\ \ \ | | | | | | | | | | | | | | | | Tidy some uses of Intern See merge request tpo/core/arti!4233
| * | | tor-netdoc: Make RouterStatus.port_policy use Intern, not ArcIan Jackson2026-07-272-2/+1
| | | | | | | | | | | | | | | | We intern these in Microdesc, and should be consistent.
| * | | tor-netdoc: Make the str in a SoftwareVersion be Intern (fmt)Ian Jackson2026-07-271-3/+1
| | | |
| * | | tor-netdoc: Make the str in a SoftwareVersion be InternIan Jackson2026-07-272-3/+4
| | | | | | | | | | | | | | | | Rather than converting it to an Arc. This is the new idiom for Intern.
| * | | tor-protover: Use GloballyInternableIan Jackson2026-07-272-12/+10
| | | | | | | | | | | | | | | | We don't need to open-code this any more.
| * | | tor-protover: Replace Arc with InternIan Jackson2026-07-271-7/+7
| | | | | | | | | | | | | | | | This makes the interning more natural.
| * | | tor-basic-utils: Intern is always CloneIan Jackson2026-07-273-1/+5
| |/ / | | | | | | | | | Use educe so that we don't derive T: Clone bound.
* | | Merge branch 'create-fast' into 'main'opara2026-07-275-79/+159
|\ \ \ | | | | | | | | | | | | | | | | tor-proto: Add `HopSettings::from_handshake_params()` for incoming circuit requests See merge request tpo/core/arti!4171
| * | | tor-proto: add a TODO for crypt protocol and cc alg logicSteven Engler2026-07-271-0/+4
| | | |
| * | | tor-proto: add `HandshakeSubprotocols`Steven Engler2026-07-272-9/+49
| | | | | | | | | | | | | | | | | | | | | | | | The advantage of this over using a `SubprotocolRequest` is that we can use the type system to ensure it only has subprotocols that are allowed during a handshake.
| * | | tor-proto: remove `CircNetParameters::extend_by_ed25519_id`Steven Engler2026-07-274-10/+1
| | | | | | | | | | | | | | | | | | | | We never used this, it was just needed because we used to convert to a `CircParameters` which required this.
| * | | tor-proto: add `HopSettings::from_handshake_params()`Steven Engler2026-07-272-71/+115
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ... and also remove `CircNetParameters::as_circ_parameters()`. We used to call `HopSettings::from_params_and_caps()` when handling incoming circuit requests, but this didn't really make sense because we already know exactly what settings we want. The new `HopSettings::from_handshake_params()` takes the exact settings we want, which means we can also skip constructing a `CircParameters` and use the raw consensus `CircNetParameters`. Most of the code in `CircNetParameters::as_circ_parameters()` has been migrated in some form to `HopSettings::from_handshake_params()`.
| * | | tor-proto: require feat 'counter-galois-onion' for 'relay'Steven Engler2026-07-271-0/+1
| |/ /