| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This is a bad encode_sign() method for RouterDesc that is testing only
and will be used soon to implement testing for invalid router
descriptors, for which we may need to create invalid ones in the first
place.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit implements verification for router descriptors. 🎉
For this, the following checks are performed:
* RouterDesc::identity_ed25519 is validly signed.
* RouterDesc::master_key_ed25519 is as implied by identity_ed25519.
* RouterDesc::fingerprint is as implied by RouterDesc::signing_key.
* RouterDesc::ntor_onion_key_crosscert is validly signed.
* RouterDesc::signing_key has correct length and exponent.
* All RouterDesc::family_cert elements are valid.
* The inner and outer RouterDescSignatures are valid.
Unfortunately, we now have two implementations for that, as the legacy
parse_internal() also implements its own verification logic for this.
It seems merging these two together however would probably cause more
harm than good, as the legacy verification is closely intertwined with
legacy parsing, making a commonly shared verification logic hard to
achieve. In other words: parse2 parses the descriptor in its entirety
first, followed by verification afterwards, whereas the legacy code
parses and verifies every field before advancing towards the next.
Instead, I suggest to read through RouterDesc::parse_internal() and
ensure that every verification related check present there is also
present here. The notable exception to this is everything TAP related,
which is absent on purpose here.
Right now, this code is untested. I will add unit tests shortly
afterwards.
|
| | |/ / / /
| | | | |
| | | | |
| | | | | |
The underlying type also implements Copy. We will need it later.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
```text
$ cargo test -p tor-proto --features relay
[...]
error[E0405]: cannot find trait `IncomingStreamRequestFilter` in this scope
--> crates/tor-proto/src/circuit/reactor.rs:631:10
|
631 | impl IncomingStreamRequestFilter for AllowAllStreamsFilter {
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^ not found in this scope
```
|
| |/ / / /
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Inbound channel (as responder) don't have a ChannelMethod as they are
not initiating the type of transport to use (PT vs Direct). It would
result in a log line when receiving a channel request:
DEBUG tor_proto::channel::handshake: Completed handshake without authentication to [? ] stream_id=Chan 2
This commit uses the `PeerInfo` which is wrapped in a `MaybeSensitive`
and thus safe to log.
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-netdoc: routerdesc: Abolish onion-key (obsolete TAP) field
See merge request tpo/core/arti!4244
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
`onion_key_crosscert` was already absent from `RouterDesc`, even
though its item `onion-key-crosscert` was processed by the old parser.
Delete it all.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
See prop350
https://spec.torproject.org/proposals/350-remove-tap.html
This is part of "Phase 3, Item 2: Remove vestigial TAP code in Arti".
Technically we are not at phase 3 yet, because we haven't yet
sunsetted C Tor 0.4.8 and made the dirauth changes in Phase 2.
However, this field is not used in Arti right now. RouterDescs are
used by client code for handling bridges (but we never use TAP keys),
and the RouterDesc type will be used for generation and mirroring by
by Arti Relay/Dirauth.
In prop350 we have decided that we won't be deploying Arti Relay until
this as been done.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Give a tx to the descriptor task so it can request the keys when
building a new descriptor.
Implement the crypto task handling of that command channel.
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
The crypto task can now signal the descriptor task that the keys have
changed related to the relay descriptor (signing key and ntor keys) so
a new descriptor can be built and uploaded.
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Config reload is not fully supported just yet but when that comes, we'll
need to make a task command for new targets.
Signed-off-by: David Goulet <[email protected]>
|
| |/ / / /
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is the basics, with many TODO(relay), for a relay descriptor upload
task which uses tor-dirpublish::Publisher.
Future commits will implement the several todo!().
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
align DestroyReason with torspec!490
Part of #2578
See merge request tpo/core/arti!4202
|
| | |/ / / |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
`HopSettings::from_handshake_params()` checks that the parameters are
correct, so if there are invalid parameters we should fail early before
we initialize the `CryptStatePair`.
|
| | | | |
| | | |
| | | |
| | | | |
This is just to make ntor and CREATE_FAST handshakes consistent.
|
| |/ / / |
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Fix some recently-appearing clippy lints
See merge request tpo/core/arti!4240
|
| | | |
| | |
| | |
| | | |
Found by rustdoc.
|
| | | |
| | |
| | |
| | | |
Placates clippy.
|
| | | |
| | |
| | |
| | | |
Placates recent clippy.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
Placates recent clippy. I find the API of both of these functions
unsatisfactory and would prefer a chunks_exact that promises to panic,
but I didn't find one in std or Itertools.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Tidy some uses of Intern
See merge request tpo/core/arti!4233
|
| | | | |
| | | |
| | | |
| | | | |
We intern these in Microdesc, and should be consistent.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
Rather than converting it to an Arc. This is the new idiom for Intern.
|
| | | | |
| | | |
| | | |
| | | | |
We don't need to open-code this any more.
|
| | | | |
| | | |
| | | |
| | | | |
This makes the interning more natural.
|
| | |/ /
| | |
| | |
| | | |
Use educe so that we don't derive T: Clone bound.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-proto: Add `HopSettings::from_handshake_params()` for incoming circuit requests
See merge request tpo/core/arti!4171
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The advantage of this over using a `SubprotocolRequest` is that we can
use the type system to ensure it only has subprotocols that are allowed
during a handshake.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
We never used this, it was just needed because we used to convert to a
`CircParameters` which required this.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
... and also remove `CircNetParameters::as_circ_parameters()`.
We used to call `HopSettings::from_params_and_caps()` when handling
incoming circuit requests, but this didn't really make sense because we
already know exactly what settings we want.
The new `HopSettings::from_handshake_params()` takes the exact settings
we want, which means we can also skip constructing a `CircParameters`
and use the raw consensus `CircNetParameters`.
Most of the code in `CircNetParameters::as_circ_parameters()` has been
migrated in some form to `HopSettings::from_handshake_params()`.
|
| | |/ / |
|