| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
If we're a relay, we need to tolerate CREATED* with unrecognized
CircIds: for example, if we time out[^1] while trying to extend the circuit
by another hop, we will send a DESTROY to the extending hop, which can
race with the CREATED* response. In other words, a CREATED* cell
arriving on a closed circuit shouldn't be treated as a protocol
violation.
There are, however, a few cases where a CREATED* with an unknown CircId
*is* a protocol violation (and probably *should* cause us to close down
the channel):
* if the CREATED* is moving in the forward direction (towards the
exit), or
* if we have not previously sent a CREATE* with that particular CircId
As before, distinguishing these from the "closed circuit" case above
would involve some tricky logic, and the benefits are unclear, while the
downsides of closing a channel when we shouldn't have are significant.
It seems better to just drop these cells for now.
Closes #2655
[^1]: at the time of writing, we don't have timeouts for the circuit
extension logic, so what I've described here cannot actually happen
today. However, we *do* have a TODO for it, so the time outs I've
described here will be implemented at some point
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
An unrecognized circuit ID is not always a protocol violation, so we
shouldn't close down the channel if it happens.
This change makes the channel reactor drop DESTROY and RELAY cells with
unknown CircIds without closing down the channel. It affects both
clients and relays.
Instead of dropping these unconditionally, we could have implemented
some more sophisticated checks to distinguish the bogus CircIds from the
CircIds of closed circuits, but it's unclear if it's worth the added
complexity (see discussion in #2655).
This partly addresses #2646 (an unrecognized circuit ID shouldn't cause
us to close down the channel if we're a relay).
This commit partially undoes the changes from
4f567e4a9432b340c2799e600c8ceb3724ad3082,
which was originally intended to mitigate flooding attacks.
Part of #2655
|
| |\ \ \ \ \
| |_|_|/ /
|/| | | |
| | | | |
| | | | | |
tor-proto: Some misc rust/clippy warning fixes
See merge request tpo/core/arti!4304
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This fixes an `unfulfilled_lint_expectations` warning.
tor-proto conditionally sets a global `allow(unused)`, and if you have
an `expect(unused)` field within an `allow(unused)` struct, rust seems
to warn with 'unfulfilled_lint_expectations'.
https://github.com/rust-lang/rust/issues/160942
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
This fixes a `clippy::large_enum_variant`.
|
| | | | | | |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Support DirBackendPlugin kludge in tor-dirserver
See merge request tpo/core/arti!4306
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit improves the empty body check by failing if it has happened.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds support for the directory backend plugin kludge by
adding a new wrapper struct called `DirMirrorWithBackend`.
It also moves http-body-util from a development dependency to a real
dependency, as this makes working with hyper a lot more comfortable.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds marker traits as dependencies for implementations of
the DirBackendPlugin trait, which will be required for intergration
with hyper.
Works like a charm, as DirMgr itself implements all three of these
already.
|
| | |/ / / /
| | | | |
| | | | |
| | | | | |
No longer required.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
fix: the number of dns queries should be 1
See merge request tpo/core/arti!4281
|
| | | | | | | |
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-proto: Handle incoming CREATE2 with ntor-v3 handshakes
See merge request tpo/core/arti!4176
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
constructor
Replaces `TryFrom<SubprotocolRequest> for HandshakeSubprotocols`.
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is both recognized and unrecognized protocol kinds.
|
| | | |/ / / /
| |/| | | | |
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit fixes an outdated rustdoc comment with regard to the misc.rs
types and their publicity.
Most of these types have been public for a while now and this comment is
outdated.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Implement kludge to allow use of DirMgr as a backend for DirServer.
See merge request tpo/core/arti!4298
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
Part of #2657
|
| | | | | | | |
|
| | | |/ / /
| |/| | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This is part of #2657. The goal here is to use DirMgr as a
temporary backend for tor-dirserver, so that we can have a
sort-of-working directory cache that can be used for testing guards
before tor-dirserver is complete.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit removes the getters in database.rs. If the overall
tor-netdoc refactoring has taught us something, then that the use of
getters can be quite annoying.
Therefore, this commit removes the getters and marks the respective
fields as pub. Given that these data types are pub(crate) only right
now, it does not matter a lot anyways.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
arti: Fix compilation of http-connect without rpc
Closes #2653
See merge request tpo/core/arti!4296
|
| | |/ / / /
| | | | |
| | | | |
| | | | | |
Closes #2653.
|
| |/ / / / |
|
| | | | |
| | | |
| | | |
| | | | |
Needed for tor-dirserver testing.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
ci,maint: Update container image versions
Closes #2618
See merge request tpo/core/arti!4280
|
| | |/ / / |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Use an IPv6 loopback address instead of the unspecified address when
creating test servers. The address returned by binding to [::]:0 is not
valid as a connection target on OpenBSD.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
tor-proto: Upgrade statrs dev-dependency and remove default features
See merge request tpo/core/arti!4283
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This doesn't appear to be needed, and removes an nalgebra dev-dependency
which should help build times.
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | | |
```bash
cargo upgrade --incompatible allow -p statrs
```
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | | |
test(dirclient): invalid utf-8 bytes in response body
See merge request tpo/core/arti!4277
|
| | | | | | |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-netdoc: Fix left-over incompletes
See merge request tpo/core/arti!4273
|
| | |/ / / /
| | | | |
| | | | |
| | | | |
| | | | | |
This removes two left over incomplete feature flags.
Follow-up to c20df8c5f879806f7044c6e26d9e69404c88cfa3.
|
| |\ \ \ \ \
| |_|_|_|/
|/| | | |
| | | | |
| | | | | |
tor-netdoc: Remove outdated top-level RouterDesc comment
See merge request tpo/core/arti!4274
|
| | |/ / /
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This feature is no longer present and we now always compile with
router descriptors enabled, deferring the optimization to the
Rust compiler and linker respectively.
Follow-up to arti!3972
|
| | |/ /
|/| |
| | | |
This reverts merge request !4264
|