| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
| |
This detected the account lifetime bugs fixed in this branch.
|
| | |
|
| | |
|
| |
|
|
| |
This tests that #1569 works.
|
| | |
|
| |
|
|
|
|
|
|
| |
Setting it for all arti processes causes a warning to be logged to
stderr, which causes the shadow ci script to fail.
It's enabled by default anyway when the feature is compiled in, so we
don't need to enable it explicitly.
|
| | |
|
| |
|
|
| |
This would have caught #1513 before it was merged.
|
| |
|
|
|
| |
This tests that the client configured in the `authorized_clients`
directory of the service is able to connect.
|
| | |
|
| |
|
|
|
| |
This will be used with the new `fileserver-onion-arti-auth` test hidden
service.
|
| |
|
|
|
|
|
|
|
| |
This adds a new restricted discovery hidden service
(`fpqqmiwzqiv63jczrshh4qcmlxw6gujcai3arobq23wikt7hk7ojadid.onion`)
that has 2 authorized clients:
* `alice`, the client configured in the `restricted_discovery.static`
list in its TOML config
* `default`, the client configured in `authorized_clients/default.auth`
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
| |
We don't need this now that #1417 is fixed.
This reverts commit a9010f6300c25e4602ecf8017ca176c724ecdfa5.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
Without this change, one of the tgen processes doesn't exit as expected:
```
618990:00:06:50.991981 [4717:shadow-worker] 00:30:00.000000000 [ERROR] [torclient-onion-artiserver:11.0.0.19] [process.rs:1525] [shadow_rs::host::process] process 'torclient-onion-artiserver.tgen.1001' exited with status StoppedByShadow; expected end state was exited: 0 but was running
```
This is because of a stub circuit selection bug that only manifests when
the `torclient-onion-artiserver` and
`torclient-onion-artiserver-full-vanguards` tests are run at the same
time.
See #1417 for more details.
|
| |
|
|
|
|
|
| |
This adds an onion service that uses full vanguards, and a client
that connects to it.
Closes #1408
|
| |
|
|
|
| |
Moving them to a separate variable makes the script more readable as we
add more hosts.
|
| |\
| |
| |
| |
| | |
Forbid script suffixes
See merge request tpo/core/arti!2153
|
| | | |
|
| |/ |
|
| |
|
|
|
|
|
|
| |
Some experimental features (i.e. `vanguards`) break the shadow
integration tests. Since the examples enable `experimental`, we need
`rust-latest` to build arti using `-p arti`, rather than from the
workspace level (because cargo does feature unification when building
the packages as a workspace).
|
| |
|
|
| |
Closes #1283
|
| |
|
|
| |
Closes #1202
|
| |
|
|
|
|
|
|
|
|
|
| |
The onion service keys now live in the `hss/<nickname>` subdirectory
within the keystore.
This layout change is **not** backwards-compatible, so if you want to
use your existing hidden service keys, you will need to manually move
them to `<keystore_root>/hss`.
Closes #1260
|
| |
|
|
|
|
|
| |
The role is a slug, and slugs are not allowed to contain uppercase
characters.
Closes #1195
|
| |
|
|
|
|
| |
We are about to replace `ArtiPathComponent` with `Slug`, but `Slug`s
don't support `.`, so let's strip the `.onion` suffix before encoding it
in the `ArtiPath`.
|
| | |
|
| |
|
|
|
| |
The algorithm name for x25519 keys has changed, so the test keys need to
be updated.
|
| |
|
|
|
| |
The algorithm name for expanded ed25519 keys has changed, so the test
keys need to be updated.
|
| |
|
|
|
|
|
| |
Disabling the shadow option --model-unblocked-syscall-latency causes
this bug not to surface. Better to remove this workaround for now
so that we can revisit again if/when it does rather than continue to
mask it.
|
| |
|
|
|
|
|
|
|
| |
This option is mostly a workaround for busy loops and other subtle race
conditions. While having it enabled can let us ignore some benign busy
loops and timing edge cases, it can also hide real problems; e.g.
burning extra CPU in a busy-loop.
https://shadow.github.io/docs/guide/limitations.html#busy-loops
|
| | |
|
| |
|
|
|
| |
This also adds a workaround - the arti service doesn't appear to
register itself (set up intro points) unless first used as a client.
|
| |
|
|
| |
This is to ensure a stable HS address.
|
| | |
|
| |
|
|
| |
socks_port is deprecated
|
| |
|
|
|
| |
Put one argument per line and use a yaml list instead of string (shadow
accepts either here).
|
| |
|
|
|
|
|
|
|
|
|
| |
The arti-extra binary has several experimental features enabled.
Currently it is used to test experimental onion service features, but it
would be useful also do a test of the arti-extra binary in the same
configuration and workload as the arti binary (which has the default
featureset).
In a follow-up commit, we'll enable the experimental ntor-v3 handshake
implementation in the arti-extra binary.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
There are 2 reasons to make this change:
* because having the word `private` in the extension will make it more
difficult to accidentally misuse or misplace a private key (see
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1618#note_2947461)
* because `Keystore`s will soon grow a `list()` function returning all
`(ArtiPath, KeyType)`s in the keystore, and in order for
`ArtiNativeKeystore` to implement this function, it will need to be
able to reverse the `KeyType -> file extension` mapping (if two
different `KeyType`s are mapped to the same extension,
`ArtiNativeKeystore`s won't be able to reverse the mapping)
|
| |
|
|
| |
The secret keys are prefixed with `KS`, not `KP`.
|
| |
|
|
| |
The privateness of the keys is encoded in their name.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Previously, the Arti key store would store x25519 secret keys as ed25519
OpenSSH keys, which it would convert to x25519 upon loading (using the
conversion function added in !1297 (merged)). This approach isn't good
enough though: most people will probably want to bring their existing
x25519 keys, and in order to store those in OpenSSH format, we'd need
convert them to ed25519, which is impossible (because the secret part of
an x25519 key contains a SHA512'd secret, whereas the corresponding,
"un-expanded", ed25519 secret key contains the secret itself rather than
the SHA).
Now that `ssh-key` has support for ssh keys with [custom algorithm
names], we can store x25519 in OpenSSH format directly. This commit
changes the storage format used by the keymgr for x25519 client auth
keys (from ed25519-ssh to our own custom key type with an algorithm name
of `"[email protected]"`).
Closes #936
[custom algorithm names]: https://github.com/RustCrypto/SSH/pull/136
|
| | |
|
| |
|
|
| |
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1399#note_2921505
|
| | |
|
| | |
|
| | |
|