aboutsummaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | proto: Ignore CREATED* with unrecognized CircIdsGabriela Moldovan2026-08-112-9/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we're a relay, we need to tolerate CREATED* with unrecognized CircIds: for example, if we time out[^1] while trying to extend the circuit by another hop, we will send a DESTROY to the extending hop, which can race with the CREATED* response. In other words, a CREATED* cell arriving on a closed circuit shouldn't be treated as a protocol violation. There are, however, a few cases where a CREATED* with an unknown CircId *is* a protocol violation (and probably *should* cause us to close down the channel): * if the CREATED* is moving in the forward direction (towards the exit), or * if we have not previously sent a CREATE* with that particular CircId As before, distinguishing these from the "closed circuit" case above would involve some tricky logic, and the benefits are unclear, while the downsides of closing a channel when we shouldn't have are significant. It seems better to just drop these cells for now. Closes #2655 [^1]: at the time of writing, we don't have timeouts for the circuit extension logic, so what I've described here cannot actually happen today. However, we *do* have a TODO for it, so the time outs I've described here will be implemented at some point
| * | | | proto: Silently drop DESTROY/RELAY cells on unknown circuits (fmt)Gabriela Moldovan2026-08-111-5/+3
| | | | |
| * | | | proto: Silently drop DESTROY/RELAY cells on unknown circuitsGabriela Moldovan2026-08-111-4/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | An unrecognized circuit ID is not always a protocol violation, so we shouldn't close down the channel if it happens. This change makes the channel reactor drop DESTROY and RELAY cells with unknown CircIds without closing down the channel. It affects both clients and relays. Instead of dropping these unconditionally, we could have implemented some more sophisticated checks to distinguish the bogus CircIds from the CircIds of closed circuits, but it's unclear if it's worth the added complexity (see discussion in #2655). This partly addresses #2646 (an unrecognized circuit ID shouldn't cause us to close down the channel if we're a relay). This commit partially undoes the changes from 4f567e4a9432b340c2799e600c8ceb3724ad3082, which was originally intended to mitigate flooding attacks. Part of #2655
* | | | | Merge branch 'clippy-fixes' into 'main'gabi-2502026-08-134-5/+8
|\ \ \ \ \ | |_|_|/ / |/| | | | | | | | | | | | | | tor-proto: Some misc rust/clippy warning fixes See merge request tpo/core/arti!4304
| * | | | tor-proto: 'expect' -> 'allow' in `CircReactorHandle`Steven Engler2026-08-111-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes an `unfulfilled_lint_expectations` warning. tor-proto conditionally sets a global `allow(unused)`, and if you have an `expect(unused)` field within an `allow(unused)` struct, rust seems to warn with 'unfulfilled_lint_expectations'. https://github.com/rust-lang/rust/issues/160942
| * | | | tor-proto: fix a `clippy::unnecessary_filter_map`Steven Engler2026-08-111-0/+2
| | | | |
| * | | | tor-proto: box `CircParameters` in test-only `CtrlCmd::AddFakeHop`Steven Engler2026-08-112-2/+3
| | | | | | | | | | | | | | | | | | | | This fixes a `clippy::large_enum_variant`.
| * | | | tor-proto: fix a 'clippy::useless_conversion'Steven Engler2026-08-111-1/+1
| | | | |
* | | | | Merge branch 'backend-dirserver' into 'main'Clara Engler2026-08-134-4/+139
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Support DirBackendPlugin kludge in tor-dirserver See merge request tpo/core/arti!4306
| * | | | | tor-dirserver: Disallow non GET methodsClara Engler2026-08-121-0/+5
| | | | | |
| * | | | | tor-dirserver: Improve empty body checkClara Engler2026-08-121-1/+10
| | | | | | | | | | | | | | | | | | | | | | | | This commit improves the empty body check by failing if it has happened.
| * | | | | tor-dirserver: Support DirBackendPlugin kludgeClara Engler2026-08-123-2/+124
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds support for the directory backend plugin kludge by adding a new wrapper struct called `DirMirrorWithBackend`. It also moves http-body-util from a development dependency to a real dependency, as this makes working with hyper a lot more comfortable.
| * | | | | tor-dircommon: Sync + Send + 'static for DirBackendPluginClara Engler2026-08-121-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds marker traits as dependencies for implementations of the DirBackendPlugin trait, which will be required for intergration with hyper. Works like a charm, as DirMgr itself implements all three of these already.
| * | | | | tor-dirserver: Remove unused_async lintClara Engler2026-08-121-1/+0
| |/ / / / | | | | | | | | | | | | | | | No longer required.
* | | | | Merge branch 'dns_qdcount_must_be_one' into 'main'Nick Mathewson2026-08-121-68/+71
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | fix: the number of dns queries should be 1 See merge request tpo/core/arti!4281
| * | | | | fix: the number of dns queries should be 1steven2026-08-041-68/+71
| | | | | |
* | | | | | Merge branch 'ntor-v3' into 'main'opara2026-08-128-58/+336
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Handle incoming CREATE2 with ntor-v3 handshakes See merge request tpo/core/arti!4176
| * | | | | | tor-proto: make `CreateRequestHandler` methods asyncSteven Engler2026-08-122-28/+39
| | | | | | |
| * | | | | | tor-proto: use `CgoRelayCrypto`/`Tor1RelayCrypto` aliasesSteven Engler2026-08-121-8/+7
| | | | | | |
| * | | | | | tor-proto: change `TryFrom<_> for HandshakeSubprotocols` to a dedicated ↵Steven Engler2026-08-122-13/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | constructor Replaces `TryFrom<SubprotocolRequest> for HandshakeSubprotocols`.
| * | | | | | tor-proto: check the handshake type in the ntor testSteven Engler2026-08-121-8/+12
| | | | | | |
| * | | | | | tor-proto: implement the ntor-v3 handshakeSteven Engler2026-08-121-9/+199
| | | | | | |
| * | | | | | tor-proto: add `TryFrom<SubprotocolRequest> for HandshakeSubprotocols`Steven Engler2026-08-121-1/+74
| | | | | | |
| * | | | | | tor-cell: derive `Default` for `SubprotocolRequest`Steven Engler2026-08-121-1/+1
| | | | | | |
| * | | | | | tor-protover: fix doc comment for `ProtoKind`Steven Engler2026-08-121-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is both recognized and unrecognized protocol kinds.
| * | | | | | tor-proto: change some instances of `sendme_inc` to u8Steven Engler2026-08-123-9/+7
| | |/ / / / | |/| | | |
* / | | | | tor-netdoc: Fix outdated rustdoc for misc.rsClara Engler2026-08-121-2/+0
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit fixes an outdated rustdoc comment with regard to the misc.rs types and their publicity. Most of these types have been public for a while now and this comment is outdated.
* | | | | Merge branch 'dir-cache-kludge' into 'main'Nick Mathewson2026-08-116-14/+359
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Implement kludge to allow use of DirMgr as a backend for DirServer. See merge request tpo/core/arti!4298
| * | | | | dirmgr: use FixedB64 to parse MD digests in as_plugin.Nick Mathewson2026-08-111-8/+10
| | | | | |
| * | | | | dirmgr: Provide a DirPlugin to temporarily pose as a directory cacheNick Mathewson2026-08-113-1/+296
| | | | | | | | | | | | | | | | | | | | | | | | Part of #2657
| * | | | | dircommon: cargo sort.Nick Mathewson2026-08-101-18/+18
| | | | | |
| * | | | | dircommon: Add trait to use DirMgr as a temporary pluginNick Mathewson2026-08-103-0/+48
| | |/ / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is part of #2657. The goal here is to use DirMgr as a temporary backend for tor-dirserver, so that we can have a sort-of-working directory cache that can be used for testing guards before tor-dirserver is complete.
* | | | | tor-dirserver: Remove getters from database.rsClara Engler2026-08-112-17/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit removes the getters in database.rs. If the overall tor-netdoc refactoring has taught us something, then that the use of getters can be quite annoying. Therefore, this commit removes the getters and marks the respective fields as pub. Given that these data types are pub(crate) only right now, it does not matter a lot anyways.
* | | | | Merge branch 'ticket_2653' into 'main'Jim Newsome2026-08-101-1/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti: Fix compilation of http-connect without rpc Closes #2653 See merge request tpo/core/arti!4296
| * | | | | arti: Fix compilation of http-connect without rpcNick Mathewson2026-08-101-1/+1
| |/ / / / | | | | | | | | | | | | | | | Closes #2653.
* / / / / add TODO about Arti#2634pryty262026-08-101-0/+4
|/ / / /
* | | | tor-netdoc: Derive PartialEq and Eq for LifetimeClara Engler2026-08-102-1/+2
| | | | | | | | | | | | | | | | Needed for tor-dirserver testing.
* | | | Merge branch 'upgrades' into 'main'wesleyac2026-08-061-1/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ci,maint: Update container image versions Closes #2618 See merge request tpo/core/arti!4280
| * | | | tor-persist: remove hidden backspace characterSteven Engler2026-08-041-1/+1
| |/ / /
* | | | tor-dirserver: fix tests on OpenBSDAndrew Kloet2026-08-052-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | Use an IPv6 loopback address instead of the unspecified address when creating test servers. The address returned by binding to [::]:0 is not valid as a connection target on OpenBSD.
* | | | Merge branch 'rust-upgrades' into 'main'opara2026-08-051-1/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-proto: Upgrade statrs dev-dependency and remove default features See merge request tpo/core/arti!4283
| * | | | tor-proto: remove all default features from statrsSteven Engler2026-08-051-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | This doesn't appear to be needed, and removes an nalgebra dev-dependency which should help build times.
| * | | | tor-proto: upgrade statrsSteven Engler2026-08-041-1/+1
| |/ / / | | | | | | | | | | | | | | | | | | | | ```bash cargo upgrade --incompatible allow -p statrs ```
* | | | Merge branch 'test-dirclient-bad-utf8' into 'main'Nick Mathewson2026-08-051-1/+18
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | test(dirclient): invalid utf-8 bytes in response body See merge request tpo/core/arti!4277
| * | | | test: invalid utf-8 bytes in response bodyiqdecay2026-08-041-1/+18
| | | | |
* | | | | Merge branch 'fix-incomplete' into 'main'Nick Mathewson2026-08-051-2/+0
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: Fix left-over incompletes See merge request tpo/core/arti!4273
| * | | | | tor-netdoc: Fix left-over incompletesClara Engler2026-08-041-2/+0
| |/ / / / | | | | | | | | | | | | | | | | | | | | This removes two left over incomplete feature flags. Follow-up to c20df8c5f879806f7044c6e26d9e69404c88cfa3.
* | | | | Merge branch 'rd-comment-outdated' into 'main'gabi-2502026-08-051-5/+0
|\ \ \ \ \ | |_|_|_|/ |/| | | | | | | | | | | | | | tor-netdoc: Remove outdated top-level RouterDesc comment See merge request tpo/core/arti!4274
| * | | | tor-netdoc: Remove outdated top-level RouterDesc commentClara Engler2026-08-041-5/+0
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | This feature is no longer present and we now always compile with router descriptors enabled, deferring the optimization to the Rust compiler and linker respectively. Follow-up to arti!3972
* | / / Revert "Merge branch 'da-microdesc-calc' into 'main'"Clara Engler2026-08-047-603/+11
| |/ / |/| | | | | This reverts merge request !4264