mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Merge remote-tracking branch 'github/shrink_or_h_more'
This commit is contained in:
@@ -18,7 +18,7 @@
|
||||
* GZIP_METHOD is guaranteed to be supported by the compress/uncompress
|
||||
* functions here. Call tor_compress_supports_method() to check if a given
|
||||
* compression schema is supported by Tor. */
|
||||
typedef enum {
|
||||
typedef enum compress_method_t {
|
||||
NO_METHOD=0, // This method must be first.
|
||||
GZIP_METHOD=1,
|
||||
ZLIB_METHOD=2,
|
||||
@@ -32,7 +32,7 @@ typedef enum {
|
||||
* BEST_COMPRESSION saves the most bandwidth; LOW_COMPRESSION saves the most
|
||||
* memory.
|
||||
**/
|
||||
typedef enum {
|
||||
typedef enum compression_level_t {
|
||||
BEST_COMPRESSION, HIGH_COMPRESSION, MEDIUM_COMPRESSION, LOW_COMPRESSION
|
||||
} compression_level_t;
|
||||
|
||||
|
||||
@@ -8,13 +8,7 @@
|
||||
#include "lib/cc/torint.h"
|
||||
#include "lib/crypt_ops/crypto_digest.h"
|
||||
#include "lib/crypt_ops/crypto_openssl_mgt.h"
|
||||
|
||||
/** Length of a curve25519 public key when encoded. */
|
||||
#define CURVE25519_PUBKEY_LEN 32
|
||||
/** Length of a curve25519 secret key when encoded. */
|
||||
#define CURVE25519_SECKEY_LEN 32
|
||||
/** Length of the result of a curve25519 handshake. */
|
||||
#define CURVE25519_OUTPUT_LEN 32
|
||||
#include "lib/defs/x25519_sizes.h"
|
||||
|
||||
/** Wrapper type for a curve25519 public key.
|
||||
*
|
||||
@@ -75,8 +69,6 @@ STATIC int curve25519_impl(uint8_t *output, const uint8_t *secret,
|
||||
STATIC int curve25519_basepoint_impl(uint8_t *output, const uint8_t *secret);
|
||||
#endif /* defined(CRYPTO_CURVE25519_PRIVATE) */
|
||||
|
||||
#define CURVE25519_BASE64_PADDED_LEN 44
|
||||
|
||||
int curve25519_public_from_base64(curve25519_public_key_t *pkey,
|
||||
const char *input);
|
||||
int curve25519_public_to_base64(char *output,
|
||||
@@ -86,4 +78,3 @@ void curve25519_set_impl_params(int use_ed);
|
||||
void curve25519_init(void);
|
||||
|
||||
#endif /* !defined(TOR_CRYPTO_CURVE25519_H) */
|
||||
|
||||
|
||||
@@ -344,7 +344,7 @@ crypto_dh_generate_public(crypto_dh_t *dh)
|
||||
|
||||
/** Generate g^x as necessary, and write the g^x for the key exchange
|
||||
* as a <b>pubkey_len</b>-byte value into <b>pubkey</b>. Return 0 on
|
||||
* success, -1 on failure. <b>pubkey_len</b> must be \>= DH_BYTES.
|
||||
* success, -1 on failure. <b>pubkey_len</b> must be \>= DH1024_KEY_LEN.
|
||||
*/
|
||||
int
|
||||
crypto_dh_get_public(crypto_dh_t *dh, char *pubkey, size_t pubkey_len)
|
||||
@@ -378,7 +378,7 @@ crypto_dh_get_public(crypto_dh_t *dh, char *pubkey, size_t pubkey_len)
|
||||
tor_assert(bytes >= 0);
|
||||
if (pubkey_len < (size_t)bytes) {
|
||||
log_warn(LD_CRYPTO,
|
||||
"Weird! pubkey_len (%d) was smaller than DH_BYTES (%d)",
|
||||
"Weird! pubkey_len (%d) was smaller than DH1024_KEY_LEN (%d)",
|
||||
(int) pubkey_len, bytes);
|
||||
return -1;
|
||||
}
|
||||
|
||||
@@ -14,9 +14,8 @@
|
||||
#define TOR_CRYPTO_DH_H
|
||||
|
||||
#include "orconfig.h"
|
||||
|
||||
/** Length of our DH keys. */
|
||||
#define DH_BYTES (1024/8)
|
||||
#include "lib/cc/torint.h"
|
||||
#include "lib/defs/dh_sizes.h"
|
||||
|
||||
typedef struct crypto_dh_t crypto_dh_t;
|
||||
|
||||
|
||||
@@ -7,24 +7,20 @@
|
||||
#include "lib/testsupport/testsupport.h"
|
||||
#include "lib/cc/torint.h"
|
||||
#include "lib/crypt_ops/crypto_curve25519.h"
|
||||
|
||||
#define ED25519_PUBKEY_LEN 32
|
||||
#define ED25519_SECKEY_LEN 64
|
||||
#define ED25519_SECKEY_SEED_LEN 32
|
||||
#define ED25519_SIG_LEN 64
|
||||
#include "lib/defs/x25519_sizes.h"
|
||||
|
||||
/** An Ed25519 signature. */
|
||||
typedef struct {
|
||||
typedef struct ed25519_signature_t {
|
||||
uint8_t sig[ED25519_SIG_LEN];
|
||||
} ed25519_signature_t;
|
||||
|
||||
/** An Ed25519 public key */
|
||||
typedef struct {
|
||||
typedef struct ed25519_public_key_t {
|
||||
uint8_t pubkey[ED25519_PUBKEY_LEN];
|
||||
} ed25519_public_key_t;
|
||||
|
||||
/** An Ed25519 secret key */
|
||||
typedef struct {
|
||||
typedef struct ed25519_secret_key_t {
|
||||
/** Note that we store secret keys in an expanded format that doesn't match
|
||||
* the format from standard ed25519. Ed25519 stores a 32-byte value k and
|
||||
* expands it into a 64-byte H(k), using the first 32 bytes for a multiplier
|
||||
@@ -35,7 +31,7 @@ typedef struct {
|
||||
} ed25519_secret_key_t;
|
||||
|
||||
/** An Ed25519 keypair. */
|
||||
typedef struct {
|
||||
typedef struct ed25519_keypair_t {
|
||||
ed25519_public_key_t pubkey;
|
||||
ed25519_secret_key_t seckey;
|
||||
} ed25519_keypair_t;
|
||||
|
||||
@@ -9,7 +9,10 @@
|
||||
|
||||
#include "lib/testsupport/testsupport.h"
|
||||
#include "lib/cc/torint.h"
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
#include "lib/defs/x25519_sizes.h"
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
struct ed25519_signature_t;
|
||||
|
||||
int crypto_write_tagged_contents_to_file(const char *fname,
|
||||
const char *typestring,
|
||||
@@ -23,20 +26,16 @@ ssize_t crypto_read_tagged_contents_from_file(const char *fname,
|
||||
uint8_t *data_out,
|
||||
ssize_t data_out_len);
|
||||
|
||||
#define ED25519_BASE64_LEN 43
|
||||
int ed25519_public_from_base64(ed25519_public_key_t *pkey,
|
||||
int ed25519_public_from_base64(struct ed25519_public_key_t *pkey,
|
||||
const char *input);
|
||||
int ed25519_public_to_base64(char *output,
|
||||
const ed25519_public_key_t *pkey);
|
||||
const char *ed25519_fmt(const ed25519_public_key_t *pkey);
|
||||
const struct ed25519_public_key_t *pkey);
|
||||
const char *ed25519_fmt(const struct ed25519_public_key_t *pkey);
|
||||
|
||||
/* XXXX move these to crypto_format.h */
|
||||
#define ED25519_SIG_BASE64_LEN 86
|
||||
|
||||
int ed25519_signature_from_base64(ed25519_signature_t *sig,
|
||||
int ed25519_signature_from_base64(struct ed25519_signature_t *sig,
|
||||
const char *input);
|
||||
int ed25519_signature_to_base64(char *output,
|
||||
const ed25519_signature_t *sig);
|
||||
const struct ed25519_signature_t *sig);
|
||||
|
||||
int digest_to_base64(char *d64, const char *digest);
|
||||
int digest_from_base64(char *digest, const char *d64);
|
||||
@@ -44,4 +43,3 @@ int digest256_to_base64(char *d64, const char *digest);
|
||||
int digest256_from_base64(char *digest, const char *d64);
|
||||
|
||||
#endif /* !defined(TOR_CRYPTO_FORMAT_H) */
|
||||
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
/* Copyright (c) 2001, Matej Pfajfar.
|
||||
* Copyright (c) 2001-2004, Roger Dingledine.
|
||||
* Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
|
||||
* Copyright (c) 2007-2018, The Tor Project, Inc. */
|
||||
/* See LICENSE for licensing information */
|
||||
|
||||
#ifndef TOR_DH_SIZES_H
|
||||
#define TOR_DH_SIZES_H
|
||||
|
||||
/** Length of our legacy DH keys. */
|
||||
#define DH1024_KEY_LEN (1024/8)
|
||||
|
||||
#endif
|
||||
@@ -1,3 +1,5 @@
|
||||
|
||||
noinst_HEADERS += \
|
||||
src/lib/defs/digest_sizes.h
|
||||
noinst_HEADERS += \
|
||||
src/lib/defs/dh_sizes.h \
|
||||
src/lib/defs/digest_sizes.h \
|
||||
src/lib/defs/x25519_sizes.h
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
/* Copyright (c) 2001, Matej Pfajfar.
|
||||
* Copyright (c) 2001-2004, Roger Dingledine.
|
||||
* Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
|
||||
* Copyright (c) 2007-2018, The Tor Project, Inc. */
|
||||
/* See LICENSE for licensing information */
|
||||
|
||||
#ifndef TOR_X25519_SIZES_H
|
||||
#define TOR_X25519_SIZES_H
|
||||
|
||||
/** Length of a curve25519 public key when encoded. */
|
||||
#define CURVE25519_PUBKEY_LEN 32
|
||||
/** Length of a curve25519 secret key when encoded. */
|
||||
#define CURVE25519_SECKEY_LEN 32
|
||||
/** Length of the result of a curve25519 handshake. */
|
||||
#define CURVE25519_OUTPUT_LEN 32
|
||||
|
||||
#define ED25519_PUBKEY_LEN 32
|
||||
#define ED25519_SECKEY_LEN 64
|
||||
#define ED25519_SECKEY_SEED_LEN 32
|
||||
#define ED25519_SIG_LEN 64
|
||||
|
||||
#define CURVE25519_BASE64_PADDED_LEN 44
|
||||
|
||||
#define ED25519_BASE64_LEN 43
|
||||
#define ED25519_SIG_BASE64_LEN 86
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,46 @@
|
||||
/* Copyright (c) 2001 Matej Pfajfar.
|
||||
* Copyright (c) 2001-2004, Roger Dingledine.
|
||||
* Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
|
||||
* Copyright (c) 2007-2018, The Tor Project, Inc. */
|
||||
/* See LICENSE for licensing information */
|
||||
|
||||
#ifndef TOR_ADDR_POLICY_ST_H
|
||||
#define TOR_ADDR_POLICY_ST_H
|
||||
|
||||
#include "lib/cc/torint.h"
|
||||
#include "lib/net/address.h"
|
||||
|
||||
/** What action type does an address policy indicate: accept or reject? */
|
||||
typedef enum {
|
||||
ADDR_POLICY_ACCEPT=1,
|
||||
ADDR_POLICY_REJECT=2,
|
||||
} addr_policy_action_t;
|
||||
#define addr_policy_action_bitfield_t ENUM_BF(addr_policy_action_t)
|
||||
|
||||
/** A reference-counted address policy rule. */
|
||||
typedef struct addr_policy_t {
|
||||
int refcnt; /**< Reference count */
|
||||
/** What to do when the policy matches.*/
|
||||
addr_policy_action_bitfield_t policy_type:2;
|
||||
unsigned int is_private:1; /**< True iff this is the pseudo-address,
|
||||
* "private". */
|
||||
unsigned int is_canonical:1; /**< True iff this policy is the canonical
|
||||
* copy (stored in a hash table to avoid
|
||||
* duplication of common policies) */
|
||||
maskbits_t maskbits; /**< Accept/reject all addresses <b>a</b> such that the
|
||||
* first <b>maskbits</b> bits of <b>a</b> match
|
||||
* <b>addr</b>. */
|
||||
/** Base address to accept or reject.
|
||||
*
|
||||
* Note that wildcards are treated
|
||||
* differntly depending on address family. An AF_UNSPEC address means
|
||||
* "All addresses, IPv4 or IPv6." An AF_INET address with maskbits==0 means
|
||||
* "All IPv4 addresses" and an AF_INET6 address with maskbits == 0 means
|
||||
* "All IPv6 addresses".
|
||||
**/
|
||||
tor_addr_t addr;
|
||||
uint16_t prt_min; /**< Lowest port number to accept/reject. */
|
||||
uint16_t prt_max; /**< Highest port number to accept/reject. */
|
||||
} addr_policy_t;
|
||||
|
||||
#endif
|
||||
+2
-2
@@ -15,13 +15,14 @@
|
||||
|
||||
#define ADDRESSMAP_PRIVATE
|
||||
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
|
||||
#include "or/or.h"
|
||||
#include "or/addressmap.h"
|
||||
#include "or/circuituse.h"
|
||||
#include "or/config.h"
|
||||
#include "or/connection_edge.h"
|
||||
#include "or/control.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "or/dns.h"
|
||||
#include "or/nodelist.h"
|
||||
#include "or/routerset.h"
|
||||
@@ -1153,4 +1154,3 @@ addressmap_get_mappings(smartlist_t *sl, time_t min_expires,
|
||||
iter = strmap_iter_next(addressmap,iter);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+2
-2
@@ -13,6 +13,7 @@
|
||||
#define TOR_BRIDGES_H
|
||||
|
||||
struct bridge_line_t;
|
||||
struct ed25519_public_key_t;
|
||||
|
||||
/* Opaque handle to a configured bridge */
|
||||
typedef struct bridge_info_t bridge_info_t;
|
||||
@@ -38,7 +39,7 @@ int routerinfo_is_a_configured_bridge(const routerinfo_t *ri);
|
||||
int node_is_a_configured_bridge(const node_t *node);
|
||||
void learned_router_identity(const tor_addr_t *addr, uint16_t port,
|
||||
const char *digest,
|
||||
const ed25519_public_key_t *ed_id);
|
||||
const struct ed25519_public_key_t *ed_id);
|
||||
|
||||
void bridge_add_from_config(struct bridge_line_t *bridge_line);
|
||||
void retry_bridge_descriptor_fetch_directly(const char *digest);
|
||||
@@ -77,4 +78,3 @@ STATIC void bridge_resolve_conflicts(const tor_addr_t *addr,
|
||||
#endif /* defined(TOR_BRIDGES_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_BRIDGES_H) */
|
||||
|
||||
|
||||
@@ -7,6 +7,8 @@
|
||||
#ifndef PACKED_CELL_ST_H
|
||||
#define PACKED_CELL_ST_H
|
||||
|
||||
#include "tor_queue.h"
|
||||
|
||||
/** A cell as packed for writing to the network. */
|
||||
struct packed_cell_t {
|
||||
/** Next cell queued on this circuit. */
|
||||
@@ -25,4 +27,3 @@ struct cell_queue_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
+1
-1
@@ -79,6 +79,7 @@
|
||||
#include "lib/time/compat_time.h"
|
||||
#include "or/networkstatus.h"
|
||||
#include "or/rendservice.h"
|
||||
#include "common/timers.h"
|
||||
|
||||
#include "or/cell_queue_st.h"
|
||||
|
||||
@@ -3477,4 +3478,3 @@ channel_update_bad_for_new_circs(const char *digest, int force)
|
||||
channel_rsa_id_group_set_badness(&(*iter)->channel_list, force);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+149
-9
@@ -11,8 +11,13 @@
|
||||
|
||||
#include "or/or.h"
|
||||
#include "or/circuitmux.h"
|
||||
#include "common/timers.h"
|
||||
#include "common/handles.h"
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
#include "tor_queue.h"
|
||||
|
||||
#define tor_timer_t timeout
|
||||
struct tor_timer_t;
|
||||
|
||||
/* Channel handler function pointer typedefs */
|
||||
typedef void (*channel_listener_fn_ptr)(channel_listener_t *, channel_t *);
|
||||
@@ -30,6 +35,141 @@ typedef enum {
|
||||
CHANNEL_USED_FOR_USER_TRAFFIC,
|
||||
} channel_usage_info_t;
|
||||
|
||||
/** Possible rules for generating circuit IDs on an OR connection. */
|
||||
typedef enum {
|
||||
CIRC_ID_TYPE_LOWER=0, /**< Pick from 0..1<<15-1. */
|
||||
CIRC_ID_TYPE_HIGHER=1, /**< Pick from 1<<15..1<<16-1. */
|
||||
/** The other side of a connection is an OP: never create circuits to it,
|
||||
* and let it use any circuit ID it wants. */
|
||||
CIRC_ID_TYPE_NEITHER=2
|
||||
} circ_id_type_t;
|
||||
#define circ_id_type_bitfield_t ENUM_BF(circ_id_type_t)
|
||||
|
||||
/* channel states for channel_t */
|
||||
|
||||
typedef enum {
|
||||
/*
|
||||
* Closed state - channel is inactive
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_CLOSING
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_STATE_OPENING
|
||||
*/
|
||||
CHANNEL_STATE_CLOSED = 0,
|
||||
/*
|
||||
* Opening state - channel is trying to connect
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_CLOSED
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_STATE_CLOSING
|
||||
* - CHANNEL_STATE_ERROR
|
||||
* - CHANNEL_STATE_OPEN
|
||||
*/
|
||||
CHANNEL_STATE_OPENING,
|
||||
/*
|
||||
* Open state - channel is active and ready for use
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_MAINT
|
||||
* - CHANNEL_STATE_OPENING
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_STATE_CLOSING
|
||||
* - CHANNEL_STATE_ERROR
|
||||
* - CHANNEL_STATE_MAINT
|
||||
*/
|
||||
CHANNEL_STATE_OPEN,
|
||||
/*
|
||||
* Maintenance state - channel is temporarily offline for subclass specific
|
||||
* maintenance activities such as TLS renegotiation.
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_OPEN
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_STATE_CLOSING
|
||||
* - CHANNEL_STATE_ERROR
|
||||
* - CHANNEL_STATE_OPEN
|
||||
*/
|
||||
CHANNEL_STATE_MAINT,
|
||||
/*
|
||||
* Closing state - channel is shutting down
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_MAINT
|
||||
* - CHANNEL_STATE_OPEN
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_STATE_CLOSED,
|
||||
* - CHANNEL_STATE_ERROR
|
||||
*/
|
||||
CHANNEL_STATE_CLOSING,
|
||||
/*
|
||||
* Error state - channel has experienced a permanent error
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_CLOSING
|
||||
* - CHANNEL_STATE_MAINT
|
||||
* - CHANNEL_STATE_OPENING
|
||||
* - CHANNEL_STATE_OPEN
|
||||
* Permitted transitions to:
|
||||
* - None
|
||||
*/
|
||||
CHANNEL_STATE_ERROR,
|
||||
/*
|
||||
* Placeholder for maximum state value
|
||||
*/
|
||||
CHANNEL_STATE_LAST
|
||||
} channel_state_t;
|
||||
|
||||
/* channel listener states for channel_listener_t */
|
||||
|
||||
typedef enum {
|
||||
/*
|
||||
* Closed state - channel listener is inactive
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_LISTENER_STATE_CLOSING
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_LISTENER_STATE_LISTENING
|
||||
*/
|
||||
CHANNEL_LISTENER_STATE_CLOSED = 0,
|
||||
/*
|
||||
* Listening state - channel listener is listening for incoming
|
||||
* connections
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_LISTENER_STATE_CLOSED
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_LISTENER_STATE_CLOSING
|
||||
* - CHANNEL_LISTENER_STATE_ERROR
|
||||
*/
|
||||
CHANNEL_LISTENER_STATE_LISTENING,
|
||||
/*
|
||||
* Closing state - channel listener is shutting down
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_LISTENER_STATE_LISTENING
|
||||
* Permitted transitions to:
|
||||
* - CHANNEL_LISTENER_STATE_CLOSED,
|
||||
* - CHANNEL_LISTENER_STATE_ERROR
|
||||
*/
|
||||
CHANNEL_LISTENER_STATE_CLOSING,
|
||||
/*
|
||||
* Error state - channel listener has experienced a permanent error
|
||||
*
|
||||
* Permitted transitions from:
|
||||
* - CHANNEL_STATE_CLOSING
|
||||
* - CHANNEL_STATE_LISTENING
|
||||
* Permitted transitions to:
|
||||
* - None
|
||||
*/
|
||||
CHANNEL_LISTENER_STATE_ERROR,
|
||||
/*
|
||||
* Placeholder for maximum state value
|
||||
*/
|
||||
CHANNEL_LISTENER_STATE_LAST
|
||||
} channel_listener_state_t;
|
||||
|
||||
/**
|
||||
* Channel struct; see the channel_t typedef in or.h. A channel is an
|
||||
* abstract interface for the OR-to-OR connection, similar to connection_or_t,
|
||||
@@ -92,7 +232,7 @@ struct channel_s {
|
||||
monotime_coarse_t next_padding_time;
|
||||
|
||||
/** The callback pointer for the padding callbacks */
|
||||
tor_timer_t *padding_timer;
|
||||
struct tor_timer_t *padding_timer;
|
||||
/** The handle to this channel (to free on canceled timers) */
|
||||
struct channel_handle_t *timer_handle;
|
||||
|
||||
@@ -251,7 +391,7 @@ struct channel_s {
|
||||
* necessarily its true identity. Don't believe this identity unless
|
||||
* authentication has happened.
|
||||
*/
|
||||
ed25519_public_key_t ed25519_identity;
|
||||
struct ed25519_public_key_t ed25519_identity;
|
||||
|
||||
/**
|
||||
* Linked list of channels with the same RSA identity digest, for use with
|
||||
@@ -470,8 +610,8 @@ void channel_mark_incoming(channel_t *chan);
|
||||
void channel_mark_outgoing(channel_t *chan);
|
||||
void channel_mark_remote(channel_t *chan);
|
||||
void channel_set_identity_digest(channel_t *chan,
|
||||
const char *identity_digest,
|
||||
const ed25519_public_key_t *ed_identity);
|
||||
const char *identity_digest,
|
||||
const struct ed25519_public_key_t *ed_identity);
|
||||
|
||||
void channel_listener_change_state(channel_listener_t *chan_l,
|
||||
channel_listener_state_t to_state);
|
||||
@@ -521,10 +661,10 @@ int channel_send_destroy(circid_t circ_id, channel_t *chan,
|
||||
|
||||
channel_t * channel_connect(const tor_addr_t *addr, uint16_t port,
|
||||
const char *rsa_id_digest,
|
||||
const ed25519_public_key_t *ed_id);
|
||||
const struct ed25519_public_key_t *ed_id);
|
||||
|
||||
channel_t * channel_get_for_extend(const char *rsa_id_digest,
|
||||
const ed25519_public_key_t *ed_id,
|
||||
const struct ed25519_public_key_t *ed_id,
|
||||
const tor_addr_t *target_addr,
|
||||
const char **msg_out,
|
||||
int *launch_out);
|
||||
@@ -537,7 +677,7 @@ int channel_is_better(channel_t *a, channel_t *b);
|
||||
|
||||
channel_t * channel_find_by_global_id(uint64_t global_identifier);
|
||||
channel_t * channel_find_by_remote_identity(const char *rsa_id_digest,
|
||||
const ed25519_public_key_t *ed_id);
|
||||
const struct ed25519_public_key_t *ed_id);
|
||||
|
||||
/** For things returned by channel_find_by_remote_digest(), walk the list.
|
||||
* The RSA key will match for all returned elements; the Ed25519 key might not.
|
||||
@@ -635,6 +775,6 @@ int packed_cell_is_destroy(channel_t *chan,
|
||||
HANDLE_DECL(channel, channel_s,)
|
||||
#define channel_handle_free(h) \
|
||||
FREE_AND_NULL(channel_handle_t, channel_handle_free_, (h))
|
||||
#undef tor_timer_t
|
||||
|
||||
#endif /* !defined(TOR_CHANNEL_H) */
|
||||
|
||||
|
||||
@@ -22,6 +22,7 @@
|
||||
#include "or/router.h"
|
||||
#include "lib/time/compat_time.h"
|
||||
#include "or/rendservice.h"
|
||||
#include "common/timers.h"
|
||||
|
||||
#include "or/cell_st.h"
|
||||
#include "or/or_connection_st.h"
|
||||
@@ -797,4 +798,3 @@ channelpadding_decide_to_pad_channel(channel_t *chan)
|
||||
return CHANNELPADDING_PADLATER;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+2
-1
@@ -69,6 +69,8 @@
|
||||
#include "or/routerinfo_st.h"
|
||||
#include "or/var_cell_st.h"
|
||||
|
||||
#include "lib/tls/tortls.h"
|
||||
|
||||
/** How many CELL_PADDING cells have we received, ever? */
|
||||
uint64_t stats_n_padding_cells_processed = 0;
|
||||
/** How many CELL_VERSIONS cells have we received, ever? */
|
||||
@@ -2454,4 +2456,3 @@ channel_tls_process_authenticate_cell(var_cell_t *cell, channel_tls_t *chan)
|
||||
|
||||
#undef ERR
|
||||
}
|
||||
|
||||
|
||||
+4
-2
@@ -12,6 +12,9 @@
|
||||
#include "or/or.h"
|
||||
#include "or/channel.h"
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
struct curve25519_public_key_t;
|
||||
|
||||
#define BASE_CHAN_TO_TLS(c) (channel_tls_from_base((c)))
|
||||
#define TLS_CHAN_TO_BASE(c) (channel_tls_to_base((c)))
|
||||
|
||||
@@ -30,7 +33,7 @@ struct channel_tls_s {
|
||||
|
||||
channel_t * channel_tls_connect(const tor_addr_t *addr, uint16_t port,
|
||||
const char *id_digest,
|
||||
const ed25519_public_key_t *ed_id);
|
||||
const struct ed25519_public_key_t *ed_id);
|
||||
channel_listener_t * channel_tls_get_listener(void);
|
||||
channel_listener_t * channel_tls_start_listener(void);
|
||||
channel_t * channel_tls_handle_incoming(or_connection_t *orconn);
|
||||
@@ -72,4 +75,3 @@ STATIC void channel_tls_process_authenticate_cell(var_cell_t *cell,
|
||||
#endif /* defined(CHANNELTLS_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CHANNELTLS_H) */
|
||||
|
||||
|
||||
@@ -23,7 +23,6 @@ int pathbias_check_probe_response(circuit_t *circ, const cell_t *cell);
|
||||
void pathbias_count_use_attempt(origin_circuit_t *circ);
|
||||
void pathbias_mark_use_success(origin_circuit_t *circ);
|
||||
void pathbias_mark_use_rollback(origin_circuit_t *circ);
|
||||
const char *pathbias_state_to_string(path_state_t state);
|
||||
const char *pathbias_state_to_string(enum path_state_t state);
|
||||
|
||||
#endif /* !defined(TOR_CIRCPATHBIAS_H) */
|
||||
|
||||
|
||||
+12
-2
@@ -11,6 +11,17 @@
|
||||
|
||||
#include "or/cell_queue_st.h"
|
||||
|
||||
struct hs_token_t;
|
||||
|
||||
/** "magic" value for an origin_circuit_t */
|
||||
#define ORIGIN_CIRCUIT_MAGIC 0x35315243u
|
||||
/** "magic" value for an or_circuit_t */
|
||||
#define OR_CIRCUIT_MAGIC 0x98ABC04Fu
|
||||
/** "magic" value for a circuit that would have been freed by circuit_free,
|
||||
* but which we're keeping around until a cpuworker reply arrives. See
|
||||
* circuit_free() for more documentation. */
|
||||
#define DEAD_CIRCUIT_MAGIC 0xdeadc14c
|
||||
|
||||
/**
|
||||
* A circuit is a path over the onion routing
|
||||
* network. Applications can connect to one end of the circuit, and can
|
||||
@@ -162,11 +173,10 @@ struct circuit_t {
|
||||
|
||||
/** If set, points to an HS token that this circuit might be carrying.
|
||||
* Used by the HS circuitmap. */
|
||||
hs_token_t *hs_token;
|
||||
struct hs_token_t *hs_token;
|
||||
/** Hashtable node: used to look up the circuit by its HS token using the HS
|
||||
circuitmap. */
|
||||
HT_ENTRY(circuit_t) hs_circuitmap_node;
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
@@ -12,6 +12,9 @@
|
||||
#ifndef TOR_CIRCUITBUILD_H
|
||||
#define TOR_CIRCUITBUILD_H
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
struct curve25519_public_key_t;
|
||||
|
||||
int route_len_for_purpose(uint8_t purpose, extend_info_t *exit_ei);
|
||||
char *circuit_list_path(origin_circuit_t *circ, int verbose);
|
||||
char *circuit_list_path_for_controller(origin_circuit_t *circ);
|
||||
@@ -52,9 +55,9 @@ int circuit_extend_to_new_exit(origin_circuit_t *circ, extend_info_t *info);
|
||||
void onion_append_to_cpath(crypt_path_t **head_ptr, crypt_path_t *new_hop);
|
||||
extend_info_t *extend_info_new(const char *nickname,
|
||||
const char *rsa_id_digest,
|
||||
const ed25519_public_key_t *ed_id,
|
||||
const struct ed25519_public_key_t *ed_id,
|
||||
crypto_pk_t *onion_key,
|
||||
const curve25519_public_key_t *ntor_key,
|
||||
const struct curve25519_public_key_t *ntor_key,
|
||||
const tor_addr_t *addr, uint16_t port);
|
||||
extend_info_t *extend_info_from_node(const node_t *r, int for_direct_connect);
|
||||
extend_info_t *extend_info_dup(extend_info_t *info);
|
||||
@@ -91,8 +94,10 @@ onion_pick_cpath_exit(origin_circuit_t *circ, extend_info_t *exit_ei,
|
||||
int is_hs_v3_rp_circuit);
|
||||
|
||||
#if defined(ENABLE_TOR2WEB_MODE) || defined(TOR_UNIT_TESTS)
|
||||
STATIC const node_t *pick_tor2web_rendezvous_node(router_crn_flags_t flags,
|
||||
const or_options_t *options);
|
||||
enum router_crn_flags_t;
|
||||
STATIC const node_t *pick_tor2web_rendezvous_node(
|
||||
enum router_crn_flags_t flags,
|
||||
const or_options_t *options);
|
||||
unsigned int cpath_get_n_hops(crypt_path_t **head_ptr);
|
||||
|
||||
#endif /* defined(ENABLE_TOR2WEB_MODE) || defined(TOR_UNIT_TESTS) */
|
||||
@@ -100,4 +105,3 @@ unsigned int cpath_get_n_hops(crypt_path_t **head_ptr);
|
||||
#endif /* defined(CIRCUITBUILD_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CIRCUITBUILD_H) */
|
||||
|
||||
|
||||
@@ -67,6 +67,7 @@
|
||||
#include "or/control.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "lib/crypt_ops/crypto_dh.h"
|
||||
#include "or/directory.h"
|
||||
#include "or/entrynodes.h"
|
||||
#include "or/main.h"
|
||||
@@ -86,9 +87,11 @@
|
||||
#include "or/routerlist.h"
|
||||
#include "or/routerset.h"
|
||||
#include "or/channelpadding.h"
|
||||
#include "lib/compress/compress.h"
|
||||
#include "lib/compress/compress_lzma.h"
|
||||
#include "lib/compress/compress_zlib.h"
|
||||
#include "lib/compress/compress_zstd.h"
|
||||
#include "lib/container/buffers.h"
|
||||
|
||||
#include "ht.h"
|
||||
|
||||
@@ -2737,4 +2740,3 @@ assert_circuit_ok,(const circuit_t *c))
|
||||
tor_assert(!or_circ || !or_circ->rend_splice);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+141
-1
@@ -15,6 +15,147 @@
|
||||
#include "lib/testsupport/testsupport.h"
|
||||
#include "or/hs_ident.h"
|
||||
|
||||
/** Circuit state: I'm the origin, still haven't done all my handshakes. */
|
||||
#define CIRCUIT_STATE_BUILDING 0
|
||||
/** Circuit state: Waiting to process the onionskin. */
|
||||
#define CIRCUIT_STATE_ONIONSKIN_PENDING 1
|
||||
/** Circuit state: I'd like to deliver a create, but my n_chan is still
|
||||
* connecting. */
|
||||
#define CIRCUIT_STATE_CHAN_WAIT 2
|
||||
/** Circuit state: the circuit is open but we don't want to actually use it
|
||||
* until we find out if a better guard will be available.
|
||||
*/
|
||||
#define CIRCUIT_STATE_GUARD_WAIT 3
|
||||
/** Circuit state: onionskin(s) processed, ready to send/receive cells. */
|
||||
#define CIRCUIT_STATE_OPEN 4
|
||||
|
||||
#define CIRCUIT_PURPOSE_MIN_ 1
|
||||
|
||||
/* these circuits were initiated elsewhere */
|
||||
#define CIRCUIT_PURPOSE_OR_MIN_ 1
|
||||
/** OR-side circuit purpose: normal circuit, at OR. */
|
||||
#define CIRCUIT_PURPOSE_OR 1
|
||||
/** OR-side circuit purpose: At OR, from the service, waiting for intro from
|
||||
* clients. */
|
||||
#define CIRCUIT_PURPOSE_INTRO_POINT 2
|
||||
/** OR-side circuit purpose: At OR, from the client, waiting for the service.
|
||||
*/
|
||||
#define CIRCUIT_PURPOSE_REND_POINT_WAITING 3
|
||||
/** OR-side circuit purpose: At OR, both circuits have this purpose. */
|
||||
#define CIRCUIT_PURPOSE_REND_ESTABLISHED 4
|
||||
#define CIRCUIT_PURPOSE_OR_MAX_ 4
|
||||
|
||||
/* these circuits originate at this node */
|
||||
|
||||
/* here's how circ client-side purposes work:
|
||||
* normal circuits are C_GENERAL.
|
||||
* circuits that are c_introducing are either on their way to
|
||||
* becoming open, or they are open and waiting for a
|
||||
* suitable rendcirc before they send the intro.
|
||||
* circuits that are c_introduce_ack_wait have sent the intro,
|
||||
* but haven't gotten a response yet.
|
||||
* circuits that are c_establish_rend are either on their way
|
||||
* to becoming open, or they are open and have sent the
|
||||
* establish_rendezvous cell but haven't received an ack.
|
||||
* circuits that are c_rend_ready are open and have received a
|
||||
* rend ack, but haven't heard from the service yet. if they have a
|
||||
* buildstate->pending_final_cpath then they're expecting a
|
||||
* cell from the service, else they're not.
|
||||
* circuits that are c_rend_ready_intro_acked are open, and
|
||||
* some intro circ has sent its intro and received an ack.
|
||||
* circuits that are c_rend_joined are open, have heard from
|
||||
* the service, and are talking to it.
|
||||
*/
|
||||
/** Client-side circuit purpose: Normal circuit, with cpath. */
|
||||
#define CIRCUIT_PURPOSE_C_GENERAL 5
|
||||
#define CIRCUIT_PURPOSE_C_HS_MIN_ 6
|
||||
/** Client-side circuit purpose: at the client, connecting to intro point. */
|
||||
#define CIRCUIT_PURPOSE_C_INTRODUCING 6
|
||||
/** Client-side circuit purpose: at the client, sent INTRODUCE1 to intro point,
|
||||
* waiting for ACK/NAK. */
|
||||
#define CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT 7
|
||||
/** Client-side circuit purpose: at the client, introduced and acked, closing.
|
||||
*/
|
||||
#define CIRCUIT_PURPOSE_C_INTRODUCE_ACKED 8
|
||||
/** Client-side circuit purpose: at the client, waiting for ack. */
|
||||
#define CIRCUIT_PURPOSE_C_ESTABLISH_REND 9
|
||||
/** Client-side circuit purpose: at the client, waiting for the service. */
|
||||
#define CIRCUIT_PURPOSE_C_REND_READY 10
|
||||
/** Client-side circuit purpose: at the client, waiting for the service,
|
||||
* INTRODUCE has been acknowledged. */
|
||||
#define CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED 11
|
||||
/** Client-side circuit purpose: at the client, rendezvous established. */
|
||||
#define CIRCUIT_PURPOSE_C_REND_JOINED 12
|
||||
/** This circuit is used for getting hsdirs */
|
||||
#define CIRCUIT_PURPOSE_C_HSDIR_GET 13
|
||||
#define CIRCUIT_PURPOSE_C_HS_MAX_ 13
|
||||
/** This circuit is used for build time measurement only */
|
||||
#define CIRCUIT_PURPOSE_C_MEASURE_TIMEOUT 14
|
||||
#define CIRCUIT_PURPOSE_C_MAX_ 14
|
||||
|
||||
#define CIRCUIT_PURPOSE_S_HS_MIN_ 15
|
||||
/** Hidden-service-side circuit purpose: at the service, waiting for
|
||||
* introductions. */
|
||||
#define CIRCUIT_PURPOSE_S_ESTABLISH_INTRO 15
|
||||
/** Hidden-service-side circuit purpose: at the service, successfully
|
||||
* established intro. */
|
||||
#define CIRCUIT_PURPOSE_S_INTRO 16
|
||||
/** Hidden-service-side circuit purpose: at the service, connecting to rend
|
||||
* point. */
|
||||
#define CIRCUIT_PURPOSE_S_CONNECT_REND 17
|
||||
/** Hidden-service-side circuit purpose: at the service, rendezvous
|
||||
* established. */
|
||||
#define CIRCUIT_PURPOSE_S_REND_JOINED 18
|
||||
/** This circuit is used for uploading hsdirs */
|
||||
#define CIRCUIT_PURPOSE_S_HSDIR_POST 19
|
||||
#define CIRCUIT_PURPOSE_S_HS_MAX_ 19
|
||||
|
||||
/** A testing circuit; not meant to be used for actual traffic. */
|
||||
#define CIRCUIT_PURPOSE_TESTING 20
|
||||
/** A controller made this circuit and Tor should not use it. */
|
||||
#define CIRCUIT_PURPOSE_CONTROLLER 21
|
||||
/** This circuit is used for path bias probing only */
|
||||
#define CIRCUIT_PURPOSE_PATH_BIAS_TESTING 22
|
||||
|
||||
/** This circuit is used for vanguards/restricted paths.
|
||||
*
|
||||
* This type of circuit is *only* created preemptively and never
|
||||
* on-demand. When an HS operation needs to take place (e.g. connect to an
|
||||
* intro point), these circuits are then cannibalized and repurposed to the
|
||||
* actual needed HS purpose. */
|
||||
#define CIRCUIT_PURPOSE_HS_VANGUARDS 23
|
||||
|
||||
#define CIRCUIT_PURPOSE_MAX_ 23
|
||||
/** A catch-all for unrecognized purposes. Currently we don't expect
|
||||
* to make or see any circuits with this purpose. */
|
||||
#define CIRCUIT_PURPOSE_UNKNOWN 255
|
||||
|
||||
/** True iff the circuit purpose <b>p</b> is for a circuit that
|
||||
* originated at this node. */
|
||||
#define CIRCUIT_PURPOSE_IS_ORIGIN(p) ((p)>CIRCUIT_PURPOSE_OR_MAX_)
|
||||
/** True iff the circuit purpose <b>p</b> is for a circuit that originated
|
||||
* here to serve as a client. (Hidden services don't count here.) */
|
||||
#define CIRCUIT_PURPOSE_IS_CLIENT(p) \
|
||||
((p)> CIRCUIT_PURPOSE_OR_MAX_ && \
|
||||
(p)<=CIRCUIT_PURPOSE_C_MAX_)
|
||||
/** True iff the circuit_t <b>c</b> is actually an origin_circuit_t. */
|
||||
#define CIRCUIT_IS_ORIGIN(c) (CIRCUIT_PURPOSE_IS_ORIGIN((c)->purpose))
|
||||
/** True iff the circuit purpose <b>p</b> is for an established rendezvous
|
||||
* circuit. */
|
||||
#define CIRCUIT_PURPOSE_IS_ESTABLISHED_REND(p) \
|
||||
((p) == CIRCUIT_PURPOSE_C_REND_JOINED || \
|
||||
(p) == CIRCUIT_PURPOSE_S_REND_JOINED)
|
||||
/** True iff the circuit_t c is actually an or_circuit_t */
|
||||
#define CIRCUIT_IS_ORCIRC(c) (((circuit_t *)(c))->magic == OR_CIRCUIT_MAGIC)
|
||||
|
||||
/** True iff this circuit purpose should count towards the global
|
||||
* pending rate limit (set by MaxClientCircuitsPending). We count all
|
||||
* general purpose circuits, as well as the first step of client onion
|
||||
* service connections (HSDir gets). */
|
||||
#define CIRCUIT_PURPOSE_COUNTS_TOWARDS_MAXPENDING(p) \
|
||||
((p) == CIRCUIT_PURPOSE_C_GENERAL || \
|
||||
(p) == CIRCUIT_PURPOSE_C_HSDIR_GET)
|
||||
|
||||
/** Convert a circuit_t* to a pointer to the enclosing or_circuit_t. Assert
|
||||
* if the cast is impossible. */
|
||||
or_circuit_t *TO_OR_CIRCUIT(circuit_t *);
|
||||
@@ -104,4 +245,3 @@ STATIC uint32_t circuit_max_queued_item_age(const circuit_t *c, uint32_t now);
|
||||
#endif /* defined(CIRCUITLIST_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CIRCUITLIST_H) */
|
||||
|
||||
|
||||
@@ -39,6 +39,7 @@
|
||||
#include "or/circuitmux_ewma.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "or/networkstatus.h"
|
||||
#include "or/or_options_st.h"
|
||||
|
||||
/*** EWMA parameter #defines ***/
|
||||
|
||||
@@ -826,4 +827,3 @@ circuitmux_ewma_free_all(void)
|
||||
{
|
||||
ewma_ticks_initialized = 0;
|
||||
}
|
||||
|
||||
|
||||
@@ -42,9 +42,11 @@
|
||||
#include "or/circuituse.h"
|
||||
#include "lib/math/fp.h"
|
||||
#include "lib/time/tvdiff.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
#include "or/crypt_path_st.h"
|
||||
#include "or/origin_circuit_st.h"
|
||||
#include "or/or_state_st.h"
|
||||
|
||||
#undef log
|
||||
#include <math.h>
|
||||
|
||||
+86
-1
@@ -21,6 +21,9 @@ int circuit_build_times_disabled(const or_options_t *options);
|
||||
int circuit_build_times_disabled_(const or_options_t *options,
|
||||
int ignore_consensus);
|
||||
|
||||
/** A build_time_t is milliseconds */
|
||||
typedef uint32_t build_time_t;
|
||||
|
||||
int circuit_build_times_enough_to_compute(const circuit_build_times_t *cbt);
|
||||
void circuit_build_times_update_state(const circuit_build_times_t *cbt,
|
||||
or_state_t *state);
|
||||
@@ -47,6 +50,89 @@ double circuit_build_times_close_rate(const circuit_build_times_t *cbt);
|
||||
void circuit_build_times_update_last_circ(circuit_build_times_t *cbt);
|
||||
void circuit_build_times_mark_circ_as_measurement_only(origin_circuit_t *circ);
|
||||
|
||||
/** Total size of the circuit timeout history to accumulate.
|
||||
* 1000 is approx 2.5 days worth of continual-use circuits. */
|
||||
#define CBT_NCIRCUITS_TO_OBSERVE 1000
|
||||
|
||||
/** Width of the histogram bins in milliseconds */
|
||||
#define CBT_BIN_WIDTH ((build_time_t)50)
|
||||
|
||||
/** Number of modes to use in the weighted-avg computation of Xm */
|
||||
#define CBT_DEFAULT_NUM_XM_MODES 3
|
||||
#define CBT_MIN_NUM_XM_MODES 1
|
||||
#define CBT_MAX_NUM_XM_MODES 20
|
||||
|
||||
/**
|
||||
* CBT_BUILD_ABANDONED is our flag value to represent a force-closed
|
||||
* circuit (Aka a 'right-censored' pareto value).
|
||||
*/
|
||||
#define CBT_BUILD_ABANDONED ((build_time_t)(INT32_MAX-1))
|
||||
#define CBT_BUILD_TIME_MAX ((build_time_t)(INT32_MAX))
|
||||
|
||||
/** Save state every 10 circuits */
|
||||
#define CBT_SAVE_STATE_EVERY 10
|
||||
|
||||
/* Circuit build times consensus parameters */
|
||||
|
||||
/**
|
||||
* How long to wait before actually closing circuits that take too long to
|
||||
* build in terms of CDF quantile.
|
||||
*/
|
||||
#define CBT_DEFAULT_CLOSE_QUANTILE 95
|
||||
#define CBT_MIN_CLOSE_QUANTILE CBT_MIN_QUANTILE_CUTOFF
|
||||
#define CBT_MAX_CLOSE_QUANTILE CBT_MAX_QUANTILE_CUTOFF
|
||||
|
||||
/**
|
||||
* How many circuits count as recent when considering if the
|
||||
* connection has gone gimpy or changed.
|
||||
*/
|
||||
#define CBT_DEFAULT_RECENT_CIRCUITS 20
|
||||
#define CBT_MIN_RECENT_CIRCUITS 3
|
||||
#define CBT_MAX_RECENT_CIRCUITS 1000
|
||||
|
||||
/**
|
||||
* Maximum count of timeouts that finish the first hop in the past
|
||||
* RECENT_CIRCUITS before calculating a new timeout.
|
||||
*
|
||||
* This tells us whether to abandon timeout history and set
|
||||
* the timeout back to whatever circuit_build_times_get_initial_timeout()
|
||||
* gives us.
|
||||
*/
|
||||
#define CBT_DEFAULT_MAX_RECENT_TIMEOUT_COUNT (CBT_DEFAULT_RECENT_CIRCUITS*9/10)
|
||||
#define CBT_MIN_MAX_RECENT_TIMEOUT_COUNT 3
|
||||
#define CBT_MAX_MAX_RECENT_TIMEOUT_COUNT 10000
|
||||
|
||||
/** Minimum circuits before estimating a timeout */
|
||||
#define CBT_DEFAULT_MIN_CIRCUITS_TO_OBSERVE 100
|
||||
#define CBT_MIN_MIN_CIRCUITS_TO_OBSERVE 1
|
||||
#define CBT_MAX_MIN_CIRCUITS_TO_OBSERVE 10000
|
||||
|
||||
/** Cutoff percentile on the CDF for our timeout estimation. */
|
||||
#define CBT_DEFAULT_QUANTILE_CUTOFF 80
|
||||
#define CBT_MIN_QUANTILE_CUTOFF 10
|
||||
#define CBT_MAX_QUANTILE_CUTOFF 99
|
||||
double circuit_build_times_quantile_cutoff(void);
|
||||
|
||||
/** How often in seconds should we build a test circuit */
|
||||
#define CBT_DEFAULT_TEST_FREQUENCY 10
|
||||
#define CBT_MIN_TEST_FREQUENCY 1
|
||||
#define CBT_MAX_TEST_FREQUENCY INT32_MAX
|
||||
|
||||
/** Lowest allowable value for CircuitBuildTimeout in milliseconds */
|
||||
#define CBT_DEFAULT_TIMEOUT_MIN_VALUE (1500)
|
||||
#define CBT_MIN_TIMEOUT_MIN_VALUE 500
|
||||
#define CBT_MAX_TIMEOUT_MIN_VALUE INT32_MAX
|
||||
|
||||
/** Initial circuit build timeout in milliseconds */
|
||||
#define CBT_DEFAULT_TIMEOUT_INITIAL_VALUE (60*1000)
|
||||
#define CBT_MIN_TIMEOUT_INITIAL_VALUE CBT_MIN_TIMEOUT_MIN_VALUE
|
||||
#define CBT_MAX_TIMEOUT_INITIAL_VALUE INT32_MAX
|
||||
int32_t circuit_build_times_initial_timeout(void);
|
||||
|
||||
#if CBT_DEFAULT_MAX_RECENT_TIMEOUT_COUNT < CBT_MIN_MAX_RECENT_TIMEOUT_COUNT
|
||||
#error "RECENT_CIRCUITS is set too low."
|
||||
#endif
|
||||
|
||||
#ifdef CIRCUITSTATS_PRIVATE
|
||||
STATIC double circuit_build_times_calculate_timeout(circuit_build_times_t *cbt,
|
||||
double quantile);
|
||||
@@ -125,4 +211,3 @@ struct circuit_build_times_s {
|
||||
#endif /* defined(CIRCUITSTATS_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CIRCUITSTATS_H) */
|
||||
|
||||
|
||||
@@ -71,6 +71,7 @@
|
||||
#include "or/circuitstats.h"
|
||||
#include "lib/compress/compress.h"
|
||||
#include "or/config.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
#include "or/connection.h"
|
||||
#include "or/connection_edge.h"
|
||||
#include "or/connection_or.h"
|
||||
@@ -109,6 +110,15 @@
|
||||
#ifdef _WIN32
|
||||
#include <shlobj.h>
|
||||
#endif
|
||||
#ifdef HAVE_FCNTL_H
|
||||
#include <fcntl.h>
|
||||
#endif
|
||||
#ifdef HAVE_SYS_STAT_H
|
||||
#include <sys/stat.h>
|
||||
#endif
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
|
||||
#include "lib/meminfo/meminfo.h"
|
||||
#include "lib/osinfo/uname.h"
|
||||
@@ -146,6 +156,10 @@ static const char unix_socket_prefix[] = "unix:";
|
||||
* configuration. */
|
||||
static const char unix_q_socket_prefix[] = "unix:\"";
|
||||
|
||||
/* limits for TCP send and recv buffer size used for constrained sockets */
|
||||
#define MIN_CONSTRAINED_TCP_BUFFER 2048
|
||||
#define MAX_CONSTRAINED_TCP_BUFFER 262144 /* 256k */
|
||||
|
||||
/** macro to help with the bulk rename of *DownloadSchedule to
|
||||
* *DowloadInitialDelay . */
|
||||
#define DOWNLOAD_SCHEDULE(name) \
|
||||
|
||||
+15
-5
@@ -12,6 +12,7 @@
|
||||
#ifndef TOR_CONFIG_H
|
||||
#define TOR_CONFIG_H
|
||||
|
||||
#include "or/or_options_st.h"
|
||||
#include "lib/testsupport/testsupport.h"
|
||||
|
||||
#if defined(__FreeBSD__) || defined(__FreeBSD_kernel__) || defined(DARWIN)
|
||||
@@ -42,7 +43,16 @@ void init_protocol_warning_severity_level(void);
|
||||
int get_protocol_warning_severity_level(void);
|
||||
const char *get_version(void);
|
||||
const char *get_short_version(void);
|
||||
setopt_err_t options_trial_assign(config_line_t *list, unsigned flags,
|
||||
|
||||
/** An error from options_trial_assign() or options_init_from_string(). */
|
||||
typedef enum setopt_err_t {
|
||||
SETOPT_OK = 0,
|
||||
SETOPT_ERR_MISC = -1,
|
||||
SETOPT_ERR_PARSE = -2,
|
||||
SETOPT_ERR_TRANSITION = -3,
|
||||
SETOPT_ERR_SETTING = -4,
|
||||
} setopt_err_t;
|
||||
setopt_err_t options_trial_assign(struct config_line_t *list, unsigned flags,
|
||||
char **msg);
|
||||
|
||||
uint32_t get_last_resolved_addr(void);
|
||||
@@ -62,7 +72,7 @@ setopt_err_t options_init_from_string(const char *cf_defaults, const char *cf,
|
||||
int command, const char *command_arg, char **msg);
|
||||
int option_is_recognized(const char *key);
|
||||
const char *option_get_canonical_name(const char *key);
|
||||
config_line_t *option_get_assignment(const or_options_t *options,
|
||||
struct config_line_t *option_get_assignment(const or_options_t *options,
|
||||
const char *key);
|
||||
int options_save_current(void);
|
||||
const char *get_torrc_fname(int defaults_fname);
|
||||
@@ -180,8 +190,8 @@ int init_cookie_authentication(const char *fname, const char *header,
|
||||
or_options_t *options_new(void);
|
||||
|
||||
int config_parse_commandline(int argc, char **argv, int ignore_errors,
|
||||
config_line_t **result,
|
||||
config_line_t **cmdline_result);
|
||||
struct config_line_t **result,
|
||||
struct config_line_t **cmdline_result);
|
||||
|
||||
void config_register_addressmaps(const or_options_t *options);
|
||||
/* XXXX move to connection_edge.h */
|
||||
@@ -260,7 +270,7 @@ STATIC int parse_dir_fallback_line(const char *line, int validate_only);
|
||||
STATIC int have_enough_mem_for_dircache(const or_options_t *options,
|
||||
size_t total_mem, char **msg);
|
||||
STATIC int parse_port_config(smartlist_t *out,
|
||||
const config_line_t *ports,
|
||||
const struct config_line_t *ports,
|
||||
const char *portname,
|
||||
int listener_type,
|
||||
const char *defaultaddr,
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
#include "or/routerset.h"
|
||||
|
||||
#include "lib/container/bitarray.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
static uint64_t config_parse_memunit(const char *s, int *ok);
|
||||
static int config_parse_msec_interval(const char *s, int *ok);
|
||||
|
||||
+5
-6
@@ -65,9 +65,9 @@ typedef union {
|
||||
time_t *ISOTIME;
|
||||
smartlist_t **CSV;
|
||||
int *CSV_INTERVAL;
|
||||
config_line_t **LINELIST;
|
||||
config_line_t **LINELIST_S;
|
||||
config_line_t **LINELIST_V;
|
||||
struct config_line_t **LINELIST;
|
||||
struct config_line_t **LINELIST_S;
|
||||
struct config_line_t **LINELIST_V;
|
||||
routerset_t **ROUTERSET;
|
||||
} confparse_dummy_values_t;
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
@@ -185,7 +185,7 @@ void config_free_(const config_format_t *fmt, void *options);
|
||||
(options) = NULL; \
|
||||
} while (0)
|
||||
|
||||
config_line_t *config_get_assigned_option(const config_format_t *fmt,
|
||||
struct config_line_t *config_get_assigned_option(const config_format_t *fmt,
|
||||
const void *options, const char *key,
|
||||
int escape_val);
|
||||
int config_is_same(const config_format_t *fmt,
|
||||
@@ -197,7 +197,7 @@ char *config_dump(const config_format_t *fmt, const void *default_options,
|
||||
const void *options, int minimal,
|
||||
int comment_defaults);
|
||||
int config_assign(const config_format_t *fmt, void *options,
|
||||
config_line_t *list,
|
||||
struct config_line_t *list,
|
||||
unsigned flags, char **msg);
|
||||
config_var_t *config_find_option_mutable(config_format_t *fmt,
|
||||
const char *key);
|
||||
@@ -219,4 +219,3 @@ void warn_deprecated_option(const char *what, const char *why);
|
||||
#define CFG_EQ_ROUTERSET(a,b,opt) routerset_equal((a)->opt, (b)->opt)
|
||||
|
||||
#endif /* !defined(TOR_CONFPARSE_H) */
|
||||
|
||||
|
||||
@@ -104,11 +104,21 @@
|
||||
#include "or/routerparse.h"
|
||||
#include "lib/sandbox/sandbox.h"
|
||||
#include "lib/net/buffers_net.h"
|
||||
#include "lib/tls/tortls.h"
|
||||
#include "common/compat_libevent.h"
|
||||
#include "lib/compress/compress.h"
|
||||
|
||||
#ifdef HAVE_PWD_H
|
||||
#include <pwd.h>
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
#ifdef HAVE_SYS_STAT_H
|
||||
#include <sys/stat.h>
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_SYS_UN_H
|
||||
#include <sys/socket.h>
|
||||
#include <sys/un.h>
|
||||
|
||||
+85
-4
@@ -14,8 +14,72 @@
|
||||
|
||||
listener_connection_t *TO_LISTENER_CONN(connection_t *);
|
||||
|
||||
/* XXXX For buf_datalen in inline function */
|
||||
#include "lib/container/buffers.h"
|
||||
struct buf_t;
|
||||
|
||||
#define CONN_TYPE_MIN_ 3
|
||||
/** Type for sockets listening for OR connections. */
|
||||
#define CONN_TYPE_OR_LISTENER 3
|
||||
/** A bidirectional TLS connection transmitting a sequence of cells.
|
||||
* May be from an OR to an OR, or from an OP to an OR. */
|
||||
#define CONN_TYPE_OR 4
|
||||
/** A TCP connection from an onion router to a stream's destination. */
|
||||
#define CONN_TYPE_EXIT 5
|
||||
/** Type for sockets listening for SOCKS connections. */
|
||||
#define CONN_TYPE_AP_LISTENER 6
|
||||
/** A SOCKS proxy connection from the user application to the onion
|
||||
* proxy. */
|
||||
#define CONN_TYPE_AP 7
|
||||
/** Type for sockets listening for HTTP connections to the directory server. */
|
||||
#define CONN_TYPE_DIR_LISTENER 8
|
||||
/** Type for HTTP connections to the directory server. */
|
||||
#define CONN_TYPE_DIR 9
|
||||
/* Type 10 is unused. */
|
||||
/** Type for listening for connections from user interface process. */
|
||||
#define CONN_TYPE_CONTROL_LISTENER 11
|
||||
/** Type for connections from user interface process. */
|
||||
#define CONN_TYPE_CONTROL 12
|
||||
/** Type for sockets listening for transparent connections redirected by pf or
|
||||
* netfilter. */
|
||||
#define CONN_TYPE_AP_TRANS_LISTENER 13
|
||||
/** Type for sockets listening for transparent connections redirected by
|
||||
* natd. */
|
||||
#define CONN_TYPE_AP_NATD_LISTENER 14
|
||||
/** Type for sockets listening for DNS requests. */
|
||||
#define CONN_TYPE_AP_DNS_LISTENER 15
|
||||
|
||||
/** Type for connections from the Extended ORPort. */
|
||||
#define CONN_TYPE_EXT_OR 16
|
||||
/** Type for sockets listening for Extended ORPort connections. */
|
||||
#define CONN_TYPE_EXT_OR_LISTENER 17
|
||||
/** Type for sockets listening for HTTP CONNECT tunnel connections. */
|
||||
#define CONN_TYPE_AP_HTTP_CONNECT_LISTENER 18
|
||||
|
||||
#define CONN_TYPE_MAX_ 19
|
||||
/* !!!! If _CONN_TYPE_MAX is ever over 31, we must grow the type field in
|
||||
* connection_t. */
|
||||
|
||||
/* Proxy client handshake states */
|
||||
/* We use a proxy but we haven't even connected to it yet. */
|
||||
#define PROXY_INFANT 1
|
||||
/* We use an HTTP proxy and we've sent the CONNECT command. */
|
||||
#define PROXY_HTTPS_WANT_CONNECT_OK 2
|
||||
/* We use a SOCKS4 proxy and we've sent the CONNECT command. */
|
||||
#define PROXY_SOCKS4_WANT_CONNECT_OK 3
|
||||
/* We use a SOCKS5 proxy and we try to negotiate without
|
||||
any authentication . */
|
||||
#define PROXY_SOCKS5_WANT_AUTH_METHOD_NONE 4
|
||||
/* We use a SOCKS5 proxy and we try to negotiate with
|
||||
Username/Password authentication . */
|
||||
#define PROXY_SOCKS5_WANT_AUTH_METHOD_RFC1929 5
|
||||
/* We use a SOCKS5 proxy and we just sent our credentials. */
|
||||
#define PROXY_SOCKS5_WANT_AUTH_RFC1929_OK 6
|
||||
/* We use a SOCKS5 proxy and we just sent our CONNECT command. */
|
||||
#define PROXY_SOCKS5_WANT_CONNECT_OK 7
|
||||
/* We use a proxy and we CONNECTed successfully!. */
|
||||
#define PROXY_CONNECTED 8
|
||||
|
||||
/** State for any listener connection. */
|
||||
#define LISTENER_STATE_READY 0
|
||||
|
||||
const char *conn_type_to_string(int type);
|
||||
const char *conn_state_to_string(int type, int state);
|
||||
@@ -159,7 +223,7 @@ connection_buf_add(const char *string, size_t len, connection_t *conn)
|
||||
}
|
||||
void connection_buf_add_compress(const char *string, size_t len,
|
||||
dir_connection_t *conn, int done);
|
||||
void connection_buf_add_buf(connection_t *conn, buf_t *buf);
|
||||
void connection_buf_add_buf(connection_t *conn, struct buf_t *buf);
|
||||
|
||||
size_t connection_get_inbuf_len(connection_t *conn);
|
||||
size_t connection_get_outbuf_len(connection_t *conn);
|
||||
@@ -242,6 +306,24 @@ MOCK_DECL(void, clock_skew_warning,
|
||||
int connection_is_moribund(connection_t *conn);
|
||||
void connection_check_oos(int n_socks, int failed);
|
||||
|
||||
/** Execute the statement <b>stmt</b>, which may log events concerning the
|
||||
* connection <b>conn</b>. To prevent infinite loops, disable log messages
|
||||
* being sent to controllers if <b>conn</b> is a control connection.
|
||||
*
|
||||
* Stmt must not contain any return or goto statements.
|
||||
*/
|
||||
#define CONN_LOG_PROTECT(conn, stmt) \
|
||||
STMT_BEGIN \
|
||||
int _log_conn_is_control; \
|
||||
tor_assert(conn); \
|
||||
_log_conn_is_control = (conn->type == CONN_TYPE_CONTROL); \
|
||||
if (_log_conn_is_control) \
|
||||
disable_control_logging(); \
|
||||
STMT_BEGIN stmt; STMT_END; \
|
||||
if (_log_conn_is_control) \
|
||||
enable_control_logging(); \
|
||||
STMT_END
|
||||
|
||||
#ifdef CONNECTION_PRIVATE
|
||||
STATIC void connection_free_minimal(connection_t *conn);
|
||||
|
||||
@@ -259,4 +341,3 @@ MOCK_DECL(STATIC smartlist_t *, pick_oos_victims, (int n));
|
||||
#endif /* defined(CONNECTION_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CONNECTION_H) */
|
||||
|
||||
|
||||
@@ -106,6 +106,7 @@
|
||||
#include "or/or_circuit_st.h"
|
||||
#include "or/origin_circuit_st.h"
|
||||
#include "or/socks_request_st.h"
|
||||
#include "common/compat_libevent.h"
|
||||
|
||||
#ifdef HAVE_LINUX_TYPES_H
|
||||
#include <linux/types.h>
|
||||
@@ -4221,4 +4222,3 @@ connection_edge_free_all(void)
|
||||
pending_entry_connections = NULL;
|
||||
mainloop_event_free(attach_pending_entry_connections_ev);
|
||||
}
|
||||
|
||||
|
||||
@@ -18,6 +18,54 @@ edge_connection_t *TO_EDGE_CONN(connection_t *);
|
||||
entry_connection_t *TO_ENTRY_CONN(connection_t *);
|
||||
entry_connection_t *EDGE_TO_ENTRY_CONN(edge_connection_t *);
|
||||
|
||||
#define EXIT_CONN_STATE_MIN_ 1
|
||||
/** State for an exit connection: waiting for response from DNS farm. */
|
||||
#define EXIT_CONN_STATE_RESOLVING 1
|
||||
/** State for an exit connection: waiting for connect() to finish. */
|
||||
#define EXIT_CONN_STATE_CONNECTING 2
|
||||
/** State for an exit connection: open and ready to transmit data. */
|
||||
#define EXIT_CONN_STATE_OPEN 3
|
||||
/** State for an exit connection: waiting to be removed. */
|
||||
#define EXIT_CONN_STATE_RESOLVEFAILED 4
|
||||
#define EXIT_CONN_STATE_MAX_ 4
|
||||
|
||||
/* The AP state values must be disjoint from the EXIT state values. */
|
||||
#define AP_CONN_STATE_MIN_ 5
|
||||
/** State for a SOCKS connection: waiting for SOCKS request. */
|
||||
#define AP_CONN_STATE_SOCKS_WAIT 5
|
||||
/** State for a SOCKS connection: got a y.onion URL; waiting to receive
|
||||
* rendezvous descriptor. */
|
||||
#define AP_CONN_STATE_RENDDESC_WAIT 6
|
||||
/** The controller will attach this connection to a circuit; it isn't our
|
||||
* job to do so. */
|
||||
#define AP_CONN_STATE_CONTROLLER_WAIT 7
|
||||
/** State for a SOCKS connection: waiting for a completed circuit. */
|
||||
#define AP_CONN_STATE_CIRCUIT_WAIT 8
|
||||
/** State for a SOCKS connection: sent BEGIN, waiting for CONNECTED. */
|
||||
#define AP_CONN_STATE_CONNECT_WAIT 9
|
||||
/** State for a SOCKS connection: sent RESOLVE, waiting for RESOLVED. */
|
||||
#define AP_CONN_STATE_RESOLVE_WAIT 10
|
||||
/** State for a SOCKS connection: ready to send and receive. */
|
||||
#define AP_CONN_STATE_OPEN 11
|
||||
/** State for a transparent natd connection: waiting for original
|
||||
* destination. */
|
||||
#define AP_CONN_STATE_NATD_WAIT 12
|
||||
/** State for an HTTP tunnel: waiting for an HTTP CONNECT command. */
|
||||
#define AP_CONN_STATE_HTTP_CONNECT_WAIT 13
|
||||
#define AP_CONN_STATE_MAX_ 13
|
||||
|
||||
#define EXIT_PURPOSE_MIN_ 1
|
||||
/** This exit stream wants to do an ordinary connect. */
|
||||
#define EXIT_PURPOSE_CONNECT 1
|
||||
/** This exit stream wants to do a resolve (either normal or reverse). */
|
||||
#define EXIT_PURPOSE_RESOLVE 2
|
||||
#define EXIT_PURPOSE_MAX_ 2
|
||||
|
||||
/** True iff the AP_CONN_STATE_* value <b>s</b> means that the corresponding
|
||||
* edge connection is not attached to any circuit. */
|
||||
#define AP_CONN_STATE_IS_UNATTACHED(s) \
|
||||
((s) <= AP_CONN_STATE_CIRCUIT_WAIT || (s) == AP_CONN_STATE_NATD_WAIT)
|
||||
|
||||
#define connection_mark_unattached_ap(conn, endreason) \
|
||||
connection_mark_unattached_ap_((conn), (endreason), __LINE__, SHORT_FILE__)
|
||||
|
||||
@@ -198,4 +246,3 @@ STATIC int connection_ap_process_http_connect(entry_connection_t *conn);
|
||||
#endif /* defined(CONNECTION_EDGE_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CONNECTION_EDGE_H) */
|
||||
|
||||
|
||||
@@ -66,8 +66,12 @@
|
||||
#include "or/or_connection_st.h"
|
||||
#include "or/or_handshake_certs_st.h"
|
||||
#include "or/or_handshake_state_st.h"
|
||||
#include "or/or_state_st.h"
|
||||
#include "or/routerinfo_st.h"
|
||||
#include "or/var_cell_st.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
|
||||
#include "lib/tls/tortls.h"
|
||||
|
||||
static int connection_tls_finish_handshake(or_connection_t *conn);
|
||||
static int connection_or_launch_v3_or_handshake(or_connection_t *conn);
|
||||
@@ -2990,4 +2994,3 @@ connection_or_send_authenticate_cell,(or_connection_t *conn, int authtype))
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
+43
-13
@@ -12,8 +12,38 @@
|
||||
#ifndef TOR_CONNECTION_OR_H
|
||||
#define TOR_CONNECTION_OR_H
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
struct ed25519_keypair_t;
|
||||
|
||||
or_connection_t *TO_OR_CONN(connection_t *);
|
||||
|
||||
#define OR_CONN_STATE_MIN_ 1
|
||||
/** State for a connection to an OR: waiting for connect() to finish. */
|
||||
#define OR_CONN_STATE_CONNECTING 1
|
||||
/** State for a connection to an OR: waiting for proxy handshake to complete */
|
||||
#define OR_CONN_STATE_PROXY_HANDSHAKING 2
|
||||
/** State for an OR connection client: SSL is handshaking, not done
|
||||
* yet. */
|
||||
#define OR_CONN_STATE_TLS_HANDSHAKING 3
|
||||
/** State for a connection to an OR: We're doing a second SSL handshake for
|
||||
* renegotiation purposes. (V2 handshake only.) */
|
||||
#define OR_CONN_STATE_TLS_CLIENT_RENEGOTIATING 4
|
||||
/** State for a connection at an OR: We're waiting for the client to
|
||||
* renegotiate (to indicate a v2 handshake) or send a versions cell (to
|
||||
* indicate a v3 handshake) */
|
||||
#define OR_CONN_STATE_TLS_SERVER_RENEGOTIATING 5
|
||||
/** State for an OR connection: We're done with our SSL handshake, we've done
|
||||
* renegotiation, but we haven't yet negotiated link protocol versions and
|
||||
* sent a netinfo cell. */
|
||||
#define OR_CONN_STATE_OR_HANDSHAKING_V2 6
|
||||
/** State for an OR connection: We're done with our SSL handshake, but we
|
||||
* haven't yet negotiated link protocol versions, done a V3 handshake, and
|
||||
* sent a netinfo cell. */
|
||||
#define OR_CONN_STATE_OR_HANDSHAKING_V3 7
|
||||
/** State for an OR connection: Ready to send/receive cells. */
|
||||
#define OR_CONN_STATE_OPEN 8
|
||||
#define OR_CONN_STATE_MAX_ 8
|
||||
|
||||
void connection_or_clear_identity(or_connection_t *conn);
|
||||
void connection_or_clear_identity_map(void);
|
||||
void clear_broken_connection_map(int disable);
|
||||
@@ -42,7 +72,7 @@ MOCK_DECL(or_connection_t *,
|
||||
connection_or_connect,
|
||||
(const tor_addr_t *addr, uint16_t port,
|
||||
const char *id_digest,
|
||||
const ed25519_public_key_t *ed_id,
|
||||
const struct ed25519_public_key_t *ed_id,
|
||||
channel_tls_t *chan));
|
||||
|
||||
void connection_or_close_normally(or_connection_t *orconn, int flush);
|
||||
@@ -60,14 +90,14 @@ void connection_or_set_canonical(or_connection_t *or_conn,
|
||||
int connection_init_or_handshake_state(or_connection_t *conn,
|
||||
int started_here);
|
||||
void connection_or_init_conn_from_address(or_connection_t *conn,
|
||||
const tor_addr_t *addr,
|
||||
uint16_t port,
|
||||
const char *rsa_id_digest,
|
||||
const ed25519_public_key_t *ed_id,
|
||||
int started_here);
|
||||
const tor_addr_t *addr,
|
||||
uint16_t port,
|
||||
const char *rsa_id_digest,
|
||||
const struct ed25519_public_key_t *ed_id,
|
||||
int started_here);
|
||||
int connection_or_client_learned_peer_id(or_connection_t *conn,
|
||||
const uint8_t *rsa_peer_id,
|
||||
const ed25519_public_key_t *ed_peer_id);
|
||||
const struct ed25519_public_key_t *ed_peer_id);
|
||||
time_t connection_or_client_used(or_connection_t *conn);
|
||||
MOCK_DECL(int, connection_or_get_num_circuits, (or_connection_t *conn));
|
||||
void or_handshake_state_free_(or_handshake_state_t *state);
|
||||
@@ -94,11 +124,12 @@ int connection_or_send_auth_challenge_cell(or_connection_t *conn);
|
||||
int authchallenge_type_is_supported(uint16_t challenge_type);
|
||||
int authchallenge_type_is_better(uint16_t challenge_type_a,
|
||||
uint16_t challenge_type_b);
|
||||
var_cell_t *connection_or_compute_authenticate_cell_body(or_connection_t *conn,
|
||||
const int authtype,
|
||||
crypto_pk_t *signing_key,
|
||||
const ed25519_keypair_t *ed_signing_key,
|
||||
int server);
|
||||
var_cell_t *connection_or_compute_authenticate_cell_body(
|
||||
or_connection_t *conn,
|
||||
const int authtype,
|
||||
crypto_pk_t *signing_key,
|
||||
const struct ed25519_keypair_t *ed_signing_key,
|
||||
int server);
|
||||
MOCK_DECL(int,connection_or_send_authenticate_cell,
|
||||
(or_connection_t *conn, int type));
|
||||
|
||||
@@ -132,4 +163,3 @@ extern int certs_cell_ed25519_disabled_for_testing;
|
||||
#endif
|
||||
|
||||
#endif /* !defined(TOR_CONNECTION_OR_H) */
|
||||
|
||||
|
||||
@@ -9,6 +9,16 @@
|
||||
|
||||
struct buf_t;
|
||||
|
||||
/* Values for connection_t.magic: used to make sure that downcasts (casts from
|
||||
* connection_t to foo_connection_t) are safe. */
|
||||
#define BASE_CONNECTION_MAGIC 0x7C3C304Eu
|
||||
#define OR_CONNECTION_MAGIC 0x7D31FF03u
|
||||
#define EDGE_CONNECTION_MAGIC 0xF0374013u
|
||||
#define ENTRY_CONNECTION_MAGIC 0xbb4a5703
|
||||
#define DIR_CONNECTION_MAGIC 0x9988ffeeu
|
||||
#define CONTROL_CONNECTION_MAGIC 0x8abc765du
|
||||
#define LISTENER_CONNECTION_MAGIC 0x1a1ac741u
|
||||
|
||||
/** Description of a connection to another host or process, and associated
|
||||
* data.
|
||||
*
|
||||
@@ -128,4 +138,12 @@ struct connection_t {
|
||||
uint32_t n_written_conn_bw;
|
||||
};
|
||||
|
||||
/** True iff <b>x</b> is an edge connection. */
|
||||
#define CONN_IS_EDGE(x) \
|
||||
((x)->type == CONN_TYPE_EXIT || (x)->type == CONN_TYPE_AP)
|
||||
|
||||
/** True iff the purpose of <b>conn</b> means that it's a server-side
|
||||
* directory connection. */
|
||||
#define DIR_CONN_IS_SERVER(conn) ((conn)->purpose == DIR_PURPOSE_SERVER)
|
||||
|
||||
#endif
|
||||
|
||||
+1
-1
@@ -7,6 +7,7 @@
|
||||
#include "or/conscache.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "lib/fs/storagedir.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
#define CCE_MAGIC 0x17162253
|
||||
|
||||
@@ -624,4 +625,3 @@ consensus_cache_entry_is_mapped(consensus_cache_entry_t *ent)
|
||||
}
|
||||
}
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
|
||||
|
||||
+4
-5
@@ -27,9 +27,9 @@ void consensus_cache_delete_pending(consensus_cache_t *cache,
|
||||
int force);
|
||||
int consensus_cache_get_n_filenames_available(consensus_cache_t *cache);
|
||||
consensus_cache_entry_t *consensus_cache_add(consensus_cache_t *cache,
|
||||
const config_line_t *labels,
|
||||
const uint8_t *data,
|
||||
size_t datalen);
|
||||
const struct config_line_t *labels,
|
||||
const uint8_t *data,
|
||||
size_t datalen);
|
||||
|
||||
consensus_cache_entry_t *consensus_cache_find_first(
|
||||
consensus_cache_t *cache,
|
||||
@@ -46,7 +46,7 @@ void consensus_cache_filter_list(smartlist_t *lst,
|
||||
|
||||
const char *consensus_cache_entry_get_value(const consensus_cache_entry_t *ent,
|
||||
const char *key);
|
||||
const config_line_t *consensus_cache_entry_get_labels(
|
||||
const struct config_line_t *consensus_cache_entry_get_labels(
|
||||
const consensus_cache_entry_t *ent);
|
||||
|
||||
void consensus_cache_entry_incref(consensus_cache_entry_t *ent);
|
||||
@@ -64,4 +64,3 @@ int consensus_cache_entry_is_mapped(consensus_cache_entry_t *ent);
|
||||
#endif
|
||||
|
||||
#endif /* !defined(TOR_CONSCACHE_H) */
|
||||
|
||||
|
||||
@@ -21,7 +21,10 @@
|
||||
#include "or/cpuworker.h"
|
||||
#include "or/networkstatus.h"
|
||||
#include "or/routerparse.h"
|
||||
#include "common/compat_libevent.h"
|
||||
#include "common/workqueue.h"
|
||||
#include "lib/compress/compress.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
#include "or/networkstatus_st.h"
|
||||
#include "or/networkstatus_voter_info_st.h"
|
||||
@@ -1940,4 +1943,3 @@ consensus_cache_entry_get_valid_after(const consensus_cache_entry_t *ent,
|
||||
else
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
@@ -4,6 +4,8 @@
|
||||
#ifndef TOR_CONSDIFFMGR_H
|
||||
#define TOR_CONSDIFFMGR_H
|
||||
|
||||
enum compress_method_t;
|
||||
|
||||
/**
|
||||
* Possible outcomes from trying to look up a given consensus diff.
|
||||
*/
|
||||
@@ -25,7 +27,7 @@ int consdiffmgr_add_consensus(const char *consensus,
|
||||
consdiff_status_t consdiffmgr_find_consensus(
|
||||
struct consensus_cache_entry_t **entry_out,
|
||||
consensus_flavor_t flavor,
|
||||
compress_method_t method);
|
||||
enum compress_method_t method);
|
||||
|
||||
consdiff_status_t consdiffmgr_find_diff_from(
|
||||
struct consensus_cache_entry_t **entry_out,
|
||||
@@ -33,7 +35,7 @@ consdiff_status_t consdiffmgr_find_diff_from(
|
||||
int digest_type,
|
||||
const uint8_t *digest,
|
||||
size_t digestlen,
|
||||
compress_method_t method);
|
||||
enum compress_method_t method);
|
||||
|
||||
int consensus_cache_entry_get_voter_id_digests(
|
||||
const struct consensus_cache_entry_t *ent,
|
||||
@@ -71,4 +73,3 @@ STATIC int uncompress_or_copy(char **out, size_t *outlen,
|
||||
#endif /* defined(CONSDIFFMGR_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CONSDIFFMGR_H) */
|
||||
|
||||
|
||||
+9
-1
@@ -80,6 +80,7 @@
|
||||
#include "or/routerlist.h"
|
||||
#include "or/routerparse.h"
|
||||
#include "or/shared_random_client.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
#include "or/cached_dir_st.h"
|
||||
#include "or/control_connection_st.h"
|
||||
@@ -99,6 +100,13 @@
|
||||
#include "or/routerlist_st.h"
|
||||
#include "or/socks_request_st.h"
|
||||
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
#ifdef HAVE_SYS_STAT_H
|
||||
#include <sys/stat.h>
|
||||
#endif
|
||||
|
||||
#ifndef _WIN32
|
||||
#include <pwd.h>
|
||||
#include <sys/resource.h>
|
||||
@@ -106,6 +114,7 @@
|
||||
|
||||
#include "lib/crypt_ops/crypto_s2k.h"
|
||||
#include "common/procmon.h"
|
||||
#include "common/compat_libevent.h"
|
||||
|
||||
/** Yield true iff <b>s</b> is the state of a control_connection_t that has
|
||||
* finished authentication and is accepting commands. */
|
||||
@@ -7791,4 +7800,3 @@ control_testing_set_global_event_mask(uint64_t mask)
|
||||
global_event_mask = mask;
|
||||
}
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
|
||||
|
||||
+89
-2
@@ -12,8 +12,93 @@
|
||||
#ifndef TOR_CONTROL_H
|
||||
#define TOR_CONTROL_H
|
||||
|
||||
/** Used to indicate the type of a circuit event passed to the controller.
|
||||
* The various types are defined in control-spec.txt */
|
||||
typedef enum circuit_status_event_t {
|
||||
CIRC_EVENT_LAUNCHED = 0,
|
||||
CIRC_EVENT_BUILT = 1,
|
||||
CIRC_EVENT_EXTENDED = 2,
|
||||
CIRC_EVENT_FAILED = 3,
|
||||
CIRC_EVENT_CLOSED = 4,
|
||||
} circuit_status_event_t;
|
||||
|
||||
/** Used to indicate the type of a CIRC_MINOR event passed to the controller.
|
||||
* The various types are defined in control-spec.txt . */
|
||||
typedef enum circuit_status_minor_event_t {
|
||||
CIRC_MINOR_EVENT_PURPOSE_CHANGED,
|
||||
CIRC_MINOR_EVENT_CANNIBALIZED,
|
||||
} circuit_status_minor_event_t;
|
||||
|
||||
/** Used to indicate the type of a stream event passed to the controller.
|
||||
* The various types are defined in control-spec.txt */
|
||||
typedef enum stream_status_event_t {
|
||||
STREAM_EVENT_SENT_CONNECT = 0,
|
||||
STREAM_EVENT_SENT_RESOLVE = 1,
|
||||
STREAM_EVENT_SUCCEEDED = 2,
|
||||
STREAM_EVENT_FAILED = 3,
|
||||
STREAM_EVENT_CLOSED = 4,
|
||||
STREAM_EVENT_NEW = 5,
|
||||
STREAM_EVENT_NEW_RESOLVE = 6,
|
||||
STREAM_EVENT_FAILED_RETRIABLE = 7,
|
||||
STREAM_EVENT_REMAP = 8
|
||||
} stream_status_event_t;
|
||||
|
||||
/** Used to indicate the type of an OR connection event passed to the
|
||||
* controller. The various types are defined in control-spec.txt */
|
||||
typedef enum or_conn_status_event_t {
|
||||
OR_CONN_EVENT_LAUNCHED = 0,
|
||||
OR_CONN_EVENT_CONNECTED = 1,
|
||||
OR_CONN_EVENT_FAILED = 2,
|
||||
OR_CONN_EVENT_CLOSED = 3,
|
||||
OR_CONN_EVENT_NEW = 4,
|
||||
} or_conn_status_event_t;
|
||||
|
||||
/** Used to indicate the type of a buildtime event */
|
||||
typedef enum buildtimeout_set_event_t {
|
||||
BUILDTIMEOUT_SET_EVENT_COMPUTED = 0,
|
||||
BUILDTIMEOUT_SET_EVENT_RESET = 1,
|
||||
BUILDTIMEOUT_SET_EVENT_SUSPENDED = 2,
|
||||
BUILDTIMEOUT_SET_EVENT_DISCARD = 3,
|
||||
BUILDTIMEOUT_SET_EVENT_RESUME = 4
|
||||
} buildtimeout_set_event_t;
|
||||
|
||||
/** Enum describing various stages of bootstrapping, for use with controller
|
||||
* bootstrap status events. The values range from 0 to 100. */
|
||||
typedef enum {
|
||||
BOOTSTRAP_STATUS_UNDEF=-1,
|
||||
BOOTSTRAP_STATUS_STARTING=0,
|
||||
BOOTSTRAP_STATUS_CONN_DIR=5,
|
||||
BOOTSTRAP_STATUS_HANDSHAKE=-2,
|
||||
BOOTSTRAP_STATUS_HANDSHAKE_DIR=10,
|
||||
BOOTSTRAP_STATUS_ONEHOP_CREATE=15,
|
||||
BOOTSTRAP_STATUS_REQUESTING_STATUS=20,
|
||||
BOOTSTRAP_STATUS_LOADING_STATUS=25,
|
||||
BOOTSTRAP_STATUS_LOADING_KEYS=40,
|
||||
BOOTSTRAP_STATUS_REQUESTING_DESCRIPTORS=45,
|
||||
BOOTSTRAP_STATUS_LOADING_DESCRIPTORS=50,
|
||||
BOOTSTRAP_STATUS_CONN_OR=80,
|
||||
BOOTSTRAP_STATUS_HANDSHAKE_OR=85,
|
||||
BOOTSTRAP_STATUS_CIRCUIT_CREATE=90,
|
||||
BOOTSTRAP_STATUS_DONE=100
|
||||
} bootstrap_status_t;
|
||||
|
||||
control_connection_t *TO_CONTROL_CONN(connection_t *);
|
||||
|
||||
#define CONTROL_CONN_STATE_MIN_ 1
|
||||
/** State for a control connection: Authenticated and accepting v1 commands. */
|
||||
#define CONTROL_CONN_STATE_OPEN 1
|
||||
/** State for a control connection: Waiting for authentication; speaking
|
||||
* protocol v1. */
|
||||
#define CONTROL_CONN_STATE_NEEDAUTH 2
|
||||
#define CONTROL_CONN_STATE_MAX_ 2
|
||||
|
||||
/** Reason for remapping an AP connection's address: we have a cached
|
||||
* answer. */
|
||||
#define REMAP_STREAM_SOURCE_CACHE 1
|
||||
/** Reason for remapping an AP connection's address: the exit node told us an
|
||||
* answer. */
|
||||
#define REMAP_STREAM_SOURCE_EXIT 2
|
||||
|
||||
void control_initialize_event_queue(void);
|
||||
|
||||
void control_update_global_event_mask(void);
|
||||
@@ -99,7 +184,8 @@ int control_event_signal(uintptr_t signal);
|
||||
|
||||
int init_control_cookie_authentication(int enabled);
|
||||
char *get_controller_cookie_file_name(void);
|
||||
smartlist_t *decode_hashed_passwords(config_line_t *passwords);
|
||||
struct config_line_t;
|
||||
smartlist_t *decode_hashed_passwords(struct config_line_t *passwords);
|
||||
void disable_control_logging(void);
|
||||
void enable_control_logging(void);
|
||||
|
||||
@@ -162,6 +248,8 @@ void control_event_hs_descriptor_content(const char *onion_address,
|
||||
void control_free_all(void);
|
||||
|
||||
#ifdef CONTROL_PRIVATE
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
/* Recognized asynchronous event types. It's okay to expand this list
|
||||
* because it is used both as a list of v0 event types, and as indices
|
||||
* into the bitfield to determine which controllers want which events.
|
||||
@@ -325,4 +413,3 @@ STATIC int getinfo_helper_current_time(
|
||||
#endif /* defined(CONTROL_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_CONTROL_H) */
|
||||
|
||||
|
||||
+16
-2
@@ -8,6 +8,21 @@
|
||||
#define CRYPT_PATH_ST_H
|
||||
|
||||
#include "or/relay_crypto_st.h"
|
||||
struct crypto_dh_t;
|
||||
|
||||
#define CRYPT_PATH_MAGIC 0x70127012u
|
||||
|
||||
struct fast_handshake_state_t;
|
||||
struct ntor_handshake_state_t;
|
||||
struct crypto_dh_t;
|
||||
struct onion_handshake_state_t {
|
||||
uint16_t tag;
|
||||
union {
|
||||
struct fast_handshake_state_t *fast;
|
||||
struct crypto_dh_t *tap;
|
||||
struct ntor_handshake_state_t *ntor;
|
||||
} u;
|
||||
};
|
||||
|
||||
/** Holds accounting information for a single step in the layered encryption
|
||||
* performed by a circuit. Used only at the client edge of a circuit. */
|
||||
@@ -23,7 +38,7 @@ struct crypt_path_t {
|
||||
onion_handshake_state_t handshake_state;
|
||||
/** Diffie-hellman handshake state for performing an introduction
|
||||
* operations */
|
||||
crypto_dh_t *rend_dh_handshake_state;
|
||||
struct crypto_dh_t *rend_dh_handshake_state;
|
||||
|
||||
/** Negotiated key material shared with the OR at this step. */
|
||||
char rend_circ_nonce[DIGEST_LEN];/* KH in tor-spec.txt */
|
||||
@@ -53,4 +68,3 @@ struct crypt_path_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
@@ -7,6 +7,12 @@
|
||||
#ifndef DESC_STORE_ST_H
|
||||
#define DESC_STORE_ST_H
|
||||
|
||||
/** Allowable types of desc_store_t. */
|
||||
typedef enum store_type_t {
|
||||
ROUTER_STORE = 0,
|
||||
EXTRAINFO_STORE = 1
|
||||
} store_type_t;
|
||||
|
||||
/** A 'store' is a set of descriptors saved on disk, with accompanying
|
||||
* journal, mmaped as needed, rebuilt as needed. */
|
||||
struct desc_store_t {
|
||||
@@ -31,4 +37,3 @@ struct desc_store_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
@@ -9,6 +9,8 @@
|
||||
|
||||
#include "or/connection_st.h"
|
||||
|
||||
struct tor_compress_state_t;
|
||||
|
||||
/** Subtype of connection_t for an "directory connection" -- that is, an HTTP
|
||||
* connection to retrieve or serve directory material. */
|
||||
struct dir_connection_t {
|
||||
@@ -31,7 +33,7 @@ struct dir_connection_t {
|
||||
* it from back to front. */
|
||||
smartlist_t *spool;
|
||||
/** The compression object doing on-the-fly compression for spooled data. */
|
||||
tor_compress_state_t *compress_state;
|
||||
struct tor_compress_state_t *compress_state;
|
||||
|
||||
/** What rendezvous service are we querying for? */
|
||||
rend_data_t *rend_data;
|
||||
@@ -63,4 +65,3 @@ struct dir_connection_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
@@ -44,6 +44,8 @@
|
||||
#include "or/vote_timing_st.h"
|
||||
|
||||
#include "lib/container/order.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
|
||||
/**
|
||||
* \file dirvote.c
|
||||
|
||||
@@ -21,6 +21,9 @@
|
||||
#include "or/shared_random_client.h"
|
||||
#include "or/dirauth/shared_random_state.h"
|
||||
#include "or/voting_schedule.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
#include "or/or_state_st.h"
|
||||
|
||||
/* Default filename of the shared random state on disk. */
|
||||
static const char default_fname[] = "sr-state";
|
||||
@@ -1321,4 +1324,3 @@ get_sr_state(void)
|
||||
}
|
||||
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
|
||||
|
||||
@@ -85,11 +85,11 @@ typedef struct sr_disk_state_t {
|
||||
/* State valid until? */
|
||||
time_t ValidUntil;
|
||||
/* All commits seen that are valid. */
|
||||
config_line_t *Commit;
|
||||
struct config_line_t *Commit;
|
||||
/* Previous and current shared random value. */
|
||||
config_line_t *SharedRandValues;
|
||||
struct config_line_t *SharedRandValues;
|
||||
/* Extra Lines for configuration we might not know. */
|
||||
config_line_t *ExtraLines;
|
||||
struct config_line_t *ExtraLines;
|
||||
} sr_disk_state_t;
|
||||
|
||||
/* API */
|
||||
@@ -144,4 +144,3 @@ STATIC sr_state_t *get_sr_state(void);
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
|
||||
#endif /* !defined(TOR_SHARED_RANDOM_STATE_H) */
|
||||
|
||||
|
||||
+12
-1
@@ -17,6 +17,7 @@
|
||||
#include "or/consdiff.h"
|
||||
#include "or/consdiffmgr.h"
|
||||
#include "or/control.h"
|
||||
#include "lib/compress/compress.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/directory.h"
|
||||
@@ -42,6 +43,8 @@
|
||||
#include "or/routerlist.h"
|
||||
#include "or/routerparse.h"
|
||||
#include "or/routerset.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
|
||||
#if defined(EXPORTMALLINFO) && defined(HAVE_MALLOC_H) && defined(HAVE_MALLINFO)
|
||||
#if !defined(OpenBSD)
|
||||
@@ -141,6 +144,15 @@ static void connection_dir_close_consensus_fetches(
|
||||
|
||||
/********* START VARIABLES **********/
|
||||
|
||||
/** Maximum size, in bytes, for resized buffers. */
|
||||
#define MAX_BUF_SIZE ((1<<24)-1) /* 16MB-1 */
|
||||
/** Maximum size, in bytes, for any directory object that we've downloaded. */
|
||||
#define MAX_DIR_DL_SIZE MAX_BUF_SIZE
|
||||
|
||||
/** Maximum size, in bytes, for any directory object that we're accepting
|
||||
* as an upload. */
|
||||
#define MAX_DIR_UL_SIZE MAX_BUF_SIZE
|
||||
|
||||
/** How far in the future do we allow a directory server to tell us it is
|
||||
* before deciding that one of us has the wrong time? */
|
||||
#define ALLOW_DIRECTORY_TIME_SKEW (30*60)
|
||||
@@ -5952,4 +5964,3 @@ dir_split_resource_into_spoolable(const char *resource,
|
||||
smartlist_free(fingerprints);
|
||||
return r;
|
||||
}
|
||||
|
||||
|
||||
+82
-6
@@ -13,8 +13,82 @@
|
||||
#define TOR_DIRECTORY_H
|
||||
|
||||
#include "or/hs_ident.h"
|
||||
enum compress_method_t;
|
||||
|
||||
dir_connection_t *TO_DIR_CONN(connection_t *c);
|
||||
|
||||
#define DIR_CONN_STATE_MIN_ 1
|
||||
/** State for connection to directory server: waiting for connect(). */
|
||||
#define DIR_CONN_STATE_CONNECTING 1
|
||||
/** State for connection to directory server: sending HTTP request. */
|
||||
#define DIR_CONN_STATE_CLIENT_SENDING 2
|
||||
/** State for connection to directory server: reading HTTP response. */
|
||||
#define DIR_CONN_STATE_CLIENT_READING 3
|
||||
/** State for connection to directory server: happy and finished. */
|
||||
#define DIR_CONN_STATE_CLIENT_FINISHED 4
|
||||
/** State for connection at directory server: waiting for HTTP request. */
|
||||
#define DIR_CONN_STATE_SERVER_COMMAND_WAIT 5
|
||||
/** State for connection at directory server: sending HTTP response. */
|
||||
#define DIR_CONN_STATE_SERVER_WRITING 6
|
||||
#define DIR_CONN_STATE_MAX_ 6
|
||||
|
||||
#define DIR_PURPOSE_MIN_ 4
|
||||
/** A connection to a directory server: set after a v2 rendezvous
|
||||
* descriptor is downloaded. */
|
||||
#define DIR_PURPOSE_HAS_FETCHED_RENDDESC_V2 4
|
||||
/** A connection to a directory server: download one or more server
|
||||
* descriptors. */
|
||||
#define DIR_PURPOSE_FETCH_SERVERDESC 6
|
||||
/** A connection to a directory server: download one or more extra-info
|
||||
* documents. */
|
||||
#define DIR_PURPOSE_FETCH_EXTRAINFO 7
|
||||
/** A connection to a directory server: upload a server descriptor. */
|
||||
#define DIR_PURPOSE_UPLOAD_DIR 8
|
||||
/** A connection to a directory server: upload a v3 networkstatus vote. */
|
||||
#define DIR_PURPOSE_UPLOAD_VOTE 10
|
||||
/** A connection to a directory server: upload a v3 consensus signature */
|
||||
#define DIR_PURPOSE_UPLOAD_SIGNATURES 11
|
||||
/** A connection to a directory server: download one or more v3 networkstatus
|
||||
* votes. */
|
||||
#define DIR_PURPOSE_FETCH_STATUS_VOTE 12
|
||||
/** A connection to a directory server: download a v3 detached signatures
|
||||
* object for a consensus. */
|
||||
#define DIR_PURPOSE_FETCH_DETACHED_SIGNATURES 13
|
||||
/** A connection to a directory server: download a v3 networkstatus
|
||||
* consensus. */
|
||||
#define DIR_PURPOSE_FETCH_CONSENSUS 14
|
||||
/** A connection to a directory server: download one or more directory
|
||||
* authority certificates. */
|
||||
#define DIR_PURPOSE_FETCH_CERTIFICATE 15
|
||||
|
||||
/** Purpose for connection at a directory server. */
|
||||
#define DIR_PURPOSE_SERVER 16
|
||||
/** A connection to a hidden service directory server: upload a v2 rendezvous
|
||||
* descriptor. */
|
||||
#define DIR_PURPOSE_UPLOAD_RENDDESC_V2 17
|
||||
/** A connection to a hidden service directory server: download a v2 rendezvous
|
||||
* descriptor. */
|
||||
#define DIR_PURPOSE_FETCH_RENDDESC_V2 18
|
||||
/** A connection to a directory server: download a microdescriptor. */
|
||||
#define DIR_PURPOSE_FETCH_MICRODESC 19
|
||||
/** A connection to a hidden service directory: upload a v3 descriptor. */
|
||||
#define DIR_PURPOSE_UPLOAD_HSDESC 20
|
||||
/** A connection to a hidden service directory: fetch a v3 descriptor. */
|
||||
#define DIR_PURPOSE_FETCH_HSDESC 21
|
||||
/** A connection to a directory server: set after a hidden service descriptor
|
||||
* is downloaded. */
|
||||
#define DIR_PURPOSE_HAS_FETCHED_HSDESC 22
|
||||
#define DIR_PURPOSE_MAX_ 22
|
||||
|
||||
/** True iff <b>p</b> is a purpose corresponding to uploading
|
||||
* data to a directory server. */
|
||||
#define DIR_PURPOSE_IS_UPLOAD(p) \
|
||||
((p)==DIR_PURPOSE_UPLOAD_DIR || \
|
||||
(p)==DIR_PURPOSE_UPLOAD_VOTE || \
|
||||
(p)==DIR_PURPOSE_UPLOAD_SIGNATURES || \
|
||||
(p)==DIR_PURPOSE_UPLOAD_RENDDESC_V2 || \
|
||||
(p)==DIR_PURPOSE_UPLOAD_HSDESC)
|
||||
|
||||
int directories_have_accepted_server_descriptor(void);
|
||||
void directory_post_to_dirservers(uint8_t dir_purpose, uint8_t router_purpose,
|
||||
dirinfo_type_t type, const char *payload,
|
||||
@@ -90,7 +164,7 @@ void directory_request_add_header(directory_request_t *req,
|
||||
MOCK_DECL(void, directory_initiate_request, (directory_request_t *request));
|
||||
|
||||
int parse_http_response(const char *headers, int *code, time_t *date,
|
||||
compress_method_t *compression, char **response);
|
||||
enum compress_method_t *compression, char **response);
|
||||
int parse_http_command(const char *headers,
|
||||
char **command_out, char **url_out);
|
||||
char *http_get_header(const char *headers, const char *which);
|
||||
@@ -189,7 +263,7 @@ struct directory_request_t {
|
||||
/** Hidden-service-specific information v2. */
|
||||
const rend_data_t *rend_query;
|
||||
/** Extra headers to append to the request */
|
||||
config_line_t *additional_headers;
|
||||
struct config_line_t *additional_headers;
|
||||
/** Hidden-service-specific information for v3+. */
|
||||
const hs_ident_dir_conn_t *hs_ident;
|
||||
/** Used internally to directory.c: gets informed when the attempt to
|
||||
@@ -203,8 +277,10 @@ STATIC int handle_get_hs_descriptor_v3(dir_connection_t *conn,
|
||||
const struct get_handler_args_t *args);
|
||||
STATIC int directory_handle_command(dir_connection_t *conn);
|
||||
STATIC char *accept_encoding_header(void);
|
||||
STATIC int allowed_anonymous_connection_compression_method(compress_method_t);
|
||||
STATIC void warn_disallowed_anonymous_compression_method(compress_method_t);
|
||||
STATIC int allowed_anonymous_connection_compression_method(
|
||||
enum compress_method_t);
|
||||
STATIC void warn_disallowed_anonymous_compression_method(
|
||||
enum compress_method_t);
|
||||
|
||||
STATIC int handle_response_fetch_hsdesc_v3(dir_connection_t *conn,
|
||||
const response_handler_args_t *args);
|
||||
@@ -239,7 +315,8 @@ STATIC int handle_post_hs_descriptor(const char *url, const char *body);
|
||||
STATIC char* authdir_type_to_string(dirinfo_type_t auth);
|
||||
STATIC const char * dir_conn_purpose_to_string(int purpose);
|
||||
STATIC int should_use_directory_guards(const or_options_t *options);
|
||||
STATIC compression_level_t choose_compression_level(ssize_t n_bytes);
|
||||
enum compression_level_t;
|
||||
STATIC enum compression_level_t choose_compression_level(ssize_t n_bytes);
|
||||
STATIC int find_dl_min_delay(const download_status_t *dls,
|
||||
const or_options_t *options);
|
||||
|
||||
@@ -268,4 +345,3 @@ STATIC unsigned parse_accept_encoding_header(const char *h);
|
||||
#endif /* defined(TOR_UNIT_TESTS) || defined(DIRECTORY_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_DIRECTORY_H) */
|
||||
|
||||
|
||||
@@ -46,7 +46,10 @@
|
||||
#include "or/tor_version_st.h"
|
||||
#include "or/vote_routerstatus_st.h"
|
||||
|
||||
#include "lib/compress/compress.h"
|
||||
#include "lib/container/order.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
/**
|
||||
* \file dirserv.c
|
||||
|
||||
+18
-2
@@ -12,8 +12,25 @@
|
||||
#ifndef TOR_DIRSERV_H
|
||||
#define TOR_DIRSERV_H
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
|
||||
#include "lib/testsupport/testsupport.h"
|
||||
|
||||
/** An enum to describe what format we're generating a routerstatus line in.
|
||||
*/
|
||||
typedef enum {
|
||||
/** For use in a v2 opinion */
|
||||
NS_V2,
|
||||
/** For use in a consensus networkstatus document (ns flavor) */
|
||||
NS_V3_CONSENSUS,
|
||||
/** For use in a vote networkstatus document */
|
||||
NS_V3_VOTE,
|
||||
/** For passing to the controlport in response to a GETINFO request */
|
||||
NS_CONTROL_PORT,
|
||||
/** For use in a consensus networkstatus document (microdesc flavor) */
|
||||
NS_V3_CONSENSUS_MICRODESC
|
||||
} routerstatus_format_type_t;
|
||||
|
||||
/** What fraction (1 over this number) of the relay ID space do we
|
||||
* (as a directory authority) launch connections to at each reachability
|
||||
* test? */
|
||||
@@ -138,7 +155,7 @@ int dirserv_get_routerdescs(smartlist_t *descs_out, const char *key,
|
||||
void dirserv_orconn_tls_done(const tor_addr_t *addr,
|
||||
uint16_t or_port,
|
||||
const char *digest_rcvd,
|
||||
const ed25519_public_key_t *ed_id_rcvd);
|
||||
const struct ed25519_public_key_t *ed_id_rcvd);
|
||||
int dirserv_should_launch_reachability_test(const routerinfo_t *ri,
|
||||
const routerinfo_t *ri_old);
|
||||
void dirserv_single_reachability_test(time_t now, routerinfo_t *router);
|
||||
@@ -220,4 +237,3 @@ void dirserv_spool_sort(dir_connection_t *conn);
|
||||
void dir_conn_clear_spool(dir_connection_t *conn);
|
||||
|
||||
#endif /* !defined(TOR_DIRSERV_H) */
|
||||
|
||||
|
||||
+5
-1
@@ -64,10 +64,15 @@
|
||||
#include "or/router.h"
|
||||
#include "ht.h"
|
||||
#include "lib/sandbox/sandbox.h"
|
||||
#include "common/compat_libevent.h"
|
||||
|
||||
#include "or/edge_connection_st.h"
|
||||
#include "or/or_circuit_st.h"
|
||||
|
||||
#ifdef HAVE_SYS_STAT_H
|
||||
#include <sys/stat.h>
|
||||
#endif
|
||||
|
||||
#include <event2/event.h>
|
||||
#include <event2/dns.h>
|
||||
|
||||
@@ -2136,4 +2141,3 @@ dns_insert_cache_entry(cached_resolve_t *new_entry)
|
||||
{
|
||||
HT_INSERT(cache_map, &cache_root, new_entry);
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -34,6 +34,7 @@
|
||||
#include "or/entry_connection_st.h"
|
||||
#include "or/listener_connection_st.h"
|
||||
#include "or/socks_request_st.h"
|
||||
#include "common/compat_libevent.h"
|
||||
|
||||
#include <event2/dns.h>
|
||||
#include <event2/dns_compat.h>
|
||||
@@ -412,4 +413,3 @@ dnsserv_close_listener(connection_t *conn)
|
||||
listener_conn->dns_server_port = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -11,6 +11,7 @@
|
||||
#include "or/or.h"
|
||||
#include "or/channel.h"
|
||||
#include "or/config.h"
|
||||
#include "or/connection.h"
|
||||
#include "or/connection_or.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "or/geoip.h"
|
||||
@@ -798,4 +799,3 @@ dos_init(void)
|
||||
/* To initialize, we only need to get the parameters. */
|
||||
set_dos_parameters(NULL);
|
||||
}
|
||||
|
||||
|
||||
@@ -139,9 +139,11 @@
|
||||
#include "or/transports.h"
|
||||
#include "or/statefile.h"
|
||||
#include "lib/math/fp.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
|
||||
#include "or/node_st.h"
|
||||
#include "or/origin_circuit_st.h"
|
||||
#include "or/or_state_st.h"
|
||||
|
||||
#include "lib/crypt_ops/digestset.h"
|
||||
|
||||
|
||||
+2
-1
@@ -64,6 +64,8 @@ typedef struct guard_pathbias_t {
|
||||
} guard_pathbias_t;
|
||||
|
||||
#if defined(ENTRYNODES_PRIVATE)
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
/**
|
||||
* @name values for entry_guard_t.is_reachable.
|
||||
*
|
||||
@@ -635,4 +637,3 @@ guard_get_guardfraction_bandwidth(guardfraction_bandwidth_t *guardfraction_bw,
|
||||
uint32_t guardfraction_percentage);
|
||||
|
||||
#endif /* !defined(TOR_ENTRYNODES_H) */
|
||||
|
||||
|
||||
+19
-1
@@ -7,6 +7,25 @@
|
||||
#ifndef EXT_ORPORT_H
|
||||
#define EXT_ORPORT_H
|
||||
|
||||
/** States of the Extended ORPort protocol. Be careful before changing
|
||||
* the numbers: they matter. */
|
||||
#define EXT_OR_CONN_STATE_MIN_ 1
|
||||
/** Extended ORPort authentication is waiting for the authentication
|
||||
* type selected by the client. */
|
||||
#define EXT_OR_CONN_STATE_AUTH_WAIT_AUTH_TYPE 1
|
||||
/** Extended ORPort authentication is waiting for the client nonce. */
|
||||
#define EXT_OR_CONN_STATE_AUTH_WAIT_CLIENT_NONCE 2
|
||||
/** Extended ORPort authentication is waiting for the client hash. */
|
||||
#define EXT_OR_CONN_STATE_AUTH_WAIT_CLIENT_HASH 3
|
||||
#define EXT_OR_CONN_STATE_AUTH_MAX 3
|
||||
/** Authentication finished and the Extended ORPort is now accepting
|
||||
* traffic. */
|
||||
#define EXT_OR_CONN_STATE_OPEN 4
|
||||
/** Extended ORPort is flushing its last messages and preparing to
|
||||
* start accepting OR connections. */
|
||||
#define EXT_OR_CONN_STATE_FLUSHING 5
|
||||
#define EXT_OR_CONN_STATE_MAX_ 5
|
||||
|
||||
int connection_ext_or_start_auth(or_connection_t *or_conn);
|
||||
|
||||
ext_or_cmd_t *ext_or_cmd_new(uint16_t len);
|
||||
@@ -43,4 +62,3 @@ extern int ext_or_auth_cookie_is_set;
|
||||
#endif /* defined(EXT_ORPORT_PRIVATE) */
|
||||
|
||||
#endif /* !defined(EXT_ORPORT_H) */
|
||||
|
||||
|
||||
@@ -7,6 +7,9 @@
|
||||
#ifndef EXTEND_INFO_ST_H
|
||||
#define EXTEND_INFO_ST_H
|
||||
|
||||
#include "lib/crypt_ops/crypto_curve25519.h"
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
/** Information on router used when extending a circuit. We don't need a
|
||||
* full routerinfo_t to extend: we only need addr:port:keyid to build an OR
|
||||
* connection, and onion_key to create the onionskin. Note that for onehop
|
||||
@@ -25,4 +28,3 @@ struct extend_info_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
+58
-1
@@ -15,6 +15,64 @@
|
||||
#include "lib/testsupport/testsupport.h"
|
||||
#include "or/dos.h"
|
||||
|
||||
/** Indicates an action that we might be noting geoip statistics on.
|
||||
* Note that if we're noticing CONNECT, we're a bridge, and if we're noticing
|
||||
* the others, we're not.
|
||||
*/
|
||||
typedef enum {
|
||||
/** We've noticed a connection as a bridge relay or entry guard. */
|
||||
GEOIP_CLIENT_CONNECT = 0,
|
||||
/** We've served a networkstatus consensus as a directory server. */
|
||||
GEOIP_CLIENT_NETWORKSTATUS = 1,
|
||||
} geoip_client_action_t;
|
||||
/** Indicates either a positive reply or a reason for rejectng a network
|
||||
* status request that will be included in geoip statistics. */
|
||||
typedef enum {
|
||||
/** Request is answered successfully. */
|
||||
GEOIP_SUCCESS = 0,
|
||||
/** V3 network status is not signed by a sufficient number of requested
|
||||
* authorities. */
|
||||
GEOIP_REJECT_NOT_ENOUGH_SIGS = 1,
|
||||
/** Requested network status object is unavailable. */
|
||||
GEOIP_REJECT_UNAVAILABLE = 2,
|
||||
/** Requested network status not found. */
|
||||
GEOIP_REJECT_NOT_FOUND = 3,
|
||||
/** Network status has not been modified since If-Modified-Since time. */
|
||||
GEOIP_REJECT_NOT_MODIFIED = 4,
|
||||
/** Directory is busy. */
|
||||
GEOIP_REJECT_BUSY = 5,
|
||||
} geoip_ns_response_t;
|
||||
#define GEOIP_NS_RESPONSE_NUM 6
|
||||
|
||||
/** Directory requests that we are measuring can be either direct or
|
||||
* tunneled. */
|
||||
typedef enum {
|
||||
DIRREQ_DIRECT = 0,
|
||||
DIRREQ_TUNNELED = 1,
|
||||
} dirreq_type_t;
|
||||
|
||||
/** Possible states for either direct or tunneled directory requests that
|
||||
* are relevant for determining network status download times. */
|
||||
typedef enum {
|
||||
/** Found that the client requests a network status; applies to both
|
||||
* direct and tunneled requests; initial state of a request that we are
|
||||
* measuring. */
|
||||
DIRREQ_IS_FOR_NETWORK_STATUS = 0,
|
||||
/** Finished writing a network status to the directory connection;
|
||||
* applies to both direct and tunneled requests; completes a direct
|
||||
* request. */
|
||||
DIRREQ_FLUSHING_DIR_CONN_FINISHED = 1,
|
||||
/** END cell sent to circuit that initiated a tunneled request. */
|
||||
DIRREQ_END_CELL_SENT = 2,
|
||||
/** Flushed last cell from queue of the circuit that initiated a
|
||||
* tunneled request to the outbuf of the OR connection. */
|
||||
DIRREQ_CIRC_QUEUE_FLUSHED = 3,
|
||||
/** Flushed last byte from buffer of the channel belonging to the
|
||||
* circuit that initiated a tunneled request; completes a tunneled
|
||||
* request. */
|
||||
DIRREQ_CHANNEL_BUFFER_FLUSHED = 4
|
||||
} dirreq_state_t;
|
||||
|
||||
#ifdef GEOIP_PRIVATE
|
||||
STATIC int geoip_parse_entry(const char *line, sa_family_t family);
|
||||
STATIC int geoip_get_country_by_ipv4(uint32_t ipaddr);
|
||||
@@ -97,4 +155,3 @@ char *geoip_get_bridge_stats_controller(time_t);
|
||||
char *format_client_stats_heartbeat(time_t now);
|
||||
|
||||
#endif /* !defined(TOR_GEOIP_H) */
|
||||
|
||||
|
||||
+6
-1
@@ -41,8 +41,14 @@ hibernating, phase 2:
|
||||
#include "or/main.h"
|
||||
#include "or/router.h"
|
||||
#include "or/statefile.h"
|
||||
#include "common/compat_libevent.h"
|
||||
|
||||
#include "or/or_connection_st.h"
|
||||
#include "or/or_state_st.h"
|
||||
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
|
||||
/** Are we currently awake, asleep, running out of bandwidth, or shutting
|
||||
* down? */
|
||||
@@ -1227,4 +1233,3 @@ hibernate_set_state_for_testing_(hibernate_state_t newstate)
|
||||
hibernate_state = newstate;
|
||||
}
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
|
||||
|
||||
+1
-1
@@ -11,6 +11,7 @@
|
||||
|
||||
#include "or/or.h"
|
||||
#include "or/config.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/hs_ident.h"
|
||||
#include "or/hs_common.h"
|
||||
@@ -976,4 +977,3 @@ hs_cache_free_all(void)
|
||||
cache_client_intro_state_free_void);
|
||||
hs_cache_client_intro_state = NULL;
|
||||
}
|
||||
|
||||
|
||||
+13
-11
@@ -11,12 +11,13 @@
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
#include "or/hs_common.h"
|
||||
#include "or/hs_descriptor.h"
|
||||
#include "or/rendcommon.h"
|
||||
#include "or/torcert.h"
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
|
||||
/* This is the maximum time an introduction point state object can stay in the
|
||||
* client cache in seconds (2 mins or 120 seconds). */
|
||||
#define HS_CACHE_CLIENT_INTRO_STATE_MAX_AGE (2 * 60)
|
||||
@@ -79,30 +80,32 @@ int hs_cache_lookup_as_dir(uint32_t version, const char *query,
|
||||
const char **desc_out);
|
||||
|
||||
const hs_descriptor_t *
|
||||
hs_cache_lookup_as_client(const ed25519_public_key_t *key);
|
||||
hs_cache_lookup_as_client(const struct ed25519_public_key_t *key);
|
||||
const char *
|
||||
hs_cache_lookup_encoded_as_client(const ed25519_public_key_t *key);
|
||||
hs_cache_lookup_encoded_as_client(const struct ed25519_public_key_t *key);
|
||||
int hs_cache_store_as_client(const char *desc_str,
|
||||
const ed25519_public_key_t *identity_pk);
|
||||
const struct ed25519_public_key_t *identity_pk);
|
||||
void hs_cache_clean_as_client(time_t now);
|
||||
void hs_cache_purge_as_client(void);
|
||||
|
||||
/* Client failure cache. */
|
||||
void hs_cache_client_intro_state_note(const ed25519_public_key_t *service_pk,
|
||||
const ed25519_public_key_t *auth_key,
|
||||
rend_intro_point_failure_t failure);
|
||||
void hs_cache_client_intro_state_note(
|
||||
const struct ed25519_public_key_t *service_pk,
|
||||
const struct ed25519_public_key_t *auth_key,
|
||||
rend_intro_point_failure_t failure);
|
||||
const hs_cache_intro_state_t *hs_cache_client_intro_state_find(
|
||||
const ed25519_public_key_t *service_pk,
|
||||
const ed25519_public_key_t *auth_key);
|
||||
const struct ed25519_public_key_t *service_pk,
|
||||
const struct ed25519_public_key_t *auth_key);
|
||||
void hs_cache_client_intro_state_clean(time_t now);
|
||||
void hs_cache_client_intro_state_purge(void);
|
||||
|
||||
#ifdef HS_CACHE_PRIVATE
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
/** Represents a locally cached HS descriptor on a hidden service client. */
|
||||
typedef struct hs_cache_client_descriptor_t {
|
||||
/* This object is indexed using the service identity public key */
|
||||
ed25519_public_key_t key;
|
||||
struct ed25519_public_key_t key;
|
||||
|
||||
/* When will this entry expire? We expire cached client descriptors in the
|
||||
* start of the next time period, since that's when clients need to start
|
||||
@@ -125,4 +128,3 @@ lookup_v3_desc_as_client(const uint8_t *key);
|
||||
#endif /* defined(HS_CACHE_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_HS_CACHE_H) */
|
||||
|
||||
|
||||
+7
-5
@@ -13,6 +13,7 @@
|
||||
#include "or/circuitlist.h"
|
||||
#include "or/circuituse.h"
|
||||
#include "or/config.h"
|
||||
#include "lib/crypt_ops/crypto_dh.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/nodelist.h"
|
||||
@@ -23,6 +24,7 @@
|
||||
#include "or/router.h"
|
||||
|
||||
#include "or/hs_cell.h"
|
||||
#include "or/hs_circuitmap.h"
|
||||
#include "or/hs_ident.h"
|
||||
#include "or/hs_ntor.h"
|
||||
#include "or/hs_service.h"
|
||||
@@ -102,7 +104,8 @@ create_rend_cpath(const uint8_t *ntor_key_seed, size_t seed_len,
|
||||
/* We are a v2 legacy HS client: Create and return a crypt path for the hidden
|
||||
* service on the other side of the rendezvous circuit <b>circ</b>. Initialize
|
||||
* the crypt path crypto using the body of the RENDEZVOUS1 cell at
|
||||
* <b>rend_cell_body</b> (which must be at least DH_KEY_LEN+DIGEST_LEN bytes).
|
||||
* <b>rend_cell_body</b> (which must be at least DH1024_KEY_LEN+DIGEST_LEN
|
||||
* bytes).
|
||||
*/
|
||||
static crypt_path_t *
|
||||
create_rend_cpath_legacy(origin_circuit_t *circ, const uint8_t *rend_cell_body)
|
||||
@@ -110,7 +113,7 @@ create_rend_cpath_legacy(origin_circuit_t *circ, const uint8_t *rend_cell_body)
|
||||
crypt_path_t *hop = NULL;
|
||||
char keys[DIGEST_LEN+CPATH_KEY_MATERIAL_LEN];
|
||||
|
||||
/* first DH_KEY_LEN bytes are g^y from the service. Finish the dh
|
||||
/* first DH1024_KEY_LEN bytes are g^y from the service. Finish the dh
|
||||
* handshake...*/
|
||||
tor_assert(circ->build_state);
|
||||
tor_assert(circ->build_state->pending_final_cpath);
|
||||
@@ -118,7 +121,7 @@ create_rend_cpath_legacy(origin_circuit_t *circ, const uint8_t *rend_cell_body)
|
||||
|
||||
tor_assert(hop->rend_dh_handshake_state);
|
||||
if (crypto_dh_compute_secret(LOG_PROTOCOL_WARN, hop->rend_dh_handshake_state,
|
||||
(char*)rend_cell_body, DH_KEY_LEN,
|
||||
(char*)rend_cell_body, DH1024_KEY_LEN,
|
||||
keys, DIGEST_LEN+CPATH_KEY_MATERIAL_LEN)<0) {
|
||||
log_warn(LD_GENERAL, "Couldn't complete DH handshake.");
|
||||
goto err;
|
||||
@@ -130,7 +133,7 @@ create_rend_cpath_legacy(origin_circuit_t *circ, const uint8_t *rend_cell_body)
|
||||
goto err;
|
||||
|
||||
/* Check whether the digest is right... */
|
||||
if (tor_memneq(keys, rend_cell_body+DH_KEY_LEN, DIGEST_LEN)) {
|
||||
if (tor_memneq(keys, rend_cell_body+DH1024_KEY_LEN, DIGEST_LEN)) {
|
||||
log_warn(LD_PROTOCOL, "Incorrect digest of key material.");
|
||||
goto err;
|
||||
}
|
||||
@@ -1244,4 +1247,3 @@ hs_circ_cleanup(circuit_t *circ)
|
||||
hs_circuitmap_remove_circuit(circ);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -583,4 +583,3 @@ hs_circuitmap_free_all(void)
|
||||
tor_free(the_hs_circuitmap);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
|
||||
typedef HT_HEAD(hs_circuitmap_ht, circuit_t) hs_circuitmap_ht;
|
||||
|
||||
typedef struct hs_token_s hs_token_t;
|
||||
typedef struct hs_token_t hs_token_t;
|
||||
struct or_circuit_t;
|
||||
struct origin_circuit_t;
|
||||
|
||||
@@ -90,7 +90,7 @@ typedef enum {
|
||||
|
||||
/** Represents a token used in the HS protocol. Each such token maps to a
|
||||
* specific introduction or rendezvous circuit. */
|
||||
struct hs_token_s {
|
||||
struct hs_token_t {
|
||||
/* Type of HS token. */
|
||||
hs_token_type_t type;
|
||||
|
||||
@@ -110,4 +110,3 @@ hs_circuitmap_ht *get_hs_circuitmap(void);
|
||||
#endif /* TOR_UNIT_TESTS */
|
||||
|
||||
#endif /* !defined(TOR_HS_CIRCUITMAP_H) */
|
||||
|
||||
|
||||
+2
-1
@@ -16,12 +16,14 @@
|
||||
#include "or/config.h"
|
||||
#include "or/connection.h"
|
||||
#include "or/connection_edge.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/directory.h"
|
||||
#include "or/hs_cache.h"
|
||||
#include "or/hs_cell.h"
|
||||
#include "or/hs_circuit.h"
|
||||
#include "or/hs_circuitmap.h"
|
||||
#include "or/hs_client.h"
|
||||
#include "or/hs_control.h"
|
||||
#include "or/hs_descriptor.h"
|
||||
@@ -1619,4 +1621,3 @@ hs_client_dir_info_changed(void)
|
||||
* AP_CONN_STATE_RENDDESC_WAIT state in order to fetch the descriptor. */
|
||||
retry_all_socks_conn_waiting_for_desc();
|
||||
}
|
||||
|
||||
|
||||
@@ -1823,4 +1823,3 @@ hs_inc_rdv_stream_counter(origin_circuit_t *circ)
|
||||
tor_assert_nonfatal_unreached();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+19
-15
@@ -10,6 +10,11 @@
|
||||
#define TOR_HS_COMMON_H
|
||||
|
||||
#include "or/or.h"
|
||||
#include "lib/defs/x25519_sizes.h"
|
||||
|
||||
struct curve25519_public_key_t;
|
||||
struct ed25519_public_key_t;
|
||||
struct ed25519_keypair_t;
|
||||
|
||||
/* Trunnel */
|
||||
#include "trunnel/ed25519_cert.h"
|
||||
@@ -122,7 +127,7 @@
|
||||
* bigger than the 84 bytes needed for version 3 so we need to pad up to that
|
||||
* length so it is indistinguishable between versions. */
|
||||
#define HS_LEGACY_RENDEZVOUS_CELL_SIZE \
|
||||
(REND_COOKIE_LEN + DH_KEY_LEN + DIGEST_LEN)
|
||||
(REND_COOKIE_LEN + DH1024_KEY_LEN + DIGEST_LEN)
|
||||
|
||||
/* Type of authentication key used by an introduction point. */
|
||||
typedef enum {
|
||||
@@ -167,20 +172,20 @@ int hs_check_service_private_dir(const char *username, const char *path,
|
||||
int hs_get_service_max_rend_failures(void);
|
||||
|
||||
char *hs_path_from_filename(const char *directory, const char *filename);
|
||||
void hs_build_address(const ed25519_public_key_t *key, uint8_t version,
|
||||
void hs_build_address(const struct ed25519_public_key_t *key, uint8_t version,
|
||||
char *addr_out);
|
||||
int hs_address_is_valid(const char *address);
|
||||
int hs_parse_address(const char *address, ed25519_public_key_t *key_out,
|
||||
int hs_parse_address(const char *address, struct ed25519_public_key_t *key_out,
|
||||
uint8_t *checksum_out, uint8_t *version_out);
|
||||
|
||||
void hs_build_blinded_pubkey(const ed25519_public_key_t *pubkey,
|
||||
void hs_build_blinded_pubkey(const struct ed25519_public_key_t *pubkey,
|
||||
const uint8_t *secret, size_t secret_len,
|
||||
uint64_t time_period_num,
|
||||
ed25519_public_key_t *pubkey_out);
|
||||
void hs_build_blinded_keypair(const ed25519_keypair_t *kp,
|
||||
struct ed25519_public_key_t *pubkey_out);
|
||||
void hs_build_blinded_keypair(const struct ed25519_keypair_t *kp,
|
||||
const uint8_t *secret, size_t secret_len,
|
||||
uint64_t time_period_num,
|
||||
ed25519_keypair_t *kp_out);
|
||||
struct ed25519_keypair_t *kp_out);
|
||||
int hs_service_requires_uptime_circ(const smartlist_t *ports);
|
||||
|
||||
void rend_data_free_(rend_data_t *data);
|
||||
@@ -203,8 +208,8 @@ const uint8_t *rend_data_get_pk_digest(const rend_data_t *rend_data,
|
||||
|
||||
routerstatus_t *pick_hsdir(const char *desc_id, const char *desc_id_base32);
|
||||
|
||||
void hs_get_subcredential(const ed25519_public_key_t *identity_pk,
|
||||
const ed25519_public_key_t *blinded_pk,
|
||||
void hs_get_subcredential(const struct ed25519_public_key_t *identity_pk,
|
||||
const struct ed25519_public_key_t *blinded_pk,
|
||||
uint8_t *subcred_out);
|
||||
|
||||
uint64_t hs_get_previous_time_period_num(time_t now);
|
||||
@@ -222,18 +227,18 @@ uint8_t *hs_get_current_srv(uint64_t time_period_num,
|
||||
uint8_t *hs_get_previous_srv(uint64_t time_period_num,
|
||||
const networkstatus_t *ns);
|
||||
|
||||
void hs_build_hsdir_index(const ed25519_public_key_t *identity_pk,
|
||||
void hs_build_hsdir_index(const struct ed25519_public_key_t *identity_pk,
|
||||
const uint8_t *srv, uint64_t period_num,
|
||||
uint8_t *hsdir_index_out);
|
||||
void hs_build_hs_index(uint64_t replica,
|
||||
const ed25519_public_key_t *blinded_pk,
|
||||
const struct ed25519_public_key_t *blinded_pk,
|
||||
uint64_t period_num, uint8_t *hs_index_out);
|
||||
|
||||
int32_t hs_get_hsdir_n_replicas(void);
|
||||
int32_t hs_get_hsdir_spread_fetch(void);
|
||||
int32_t hs_get_hsdir_spread_store(void);
|
||||
|
||||
void hs_get_responsible_hsdirs(const ed25519_public_key_t *blinded_pk,
|
||||
void hs_get_responsible_hsdirs(const struct ed25519_public_key_t *blinded_pk,
|
||||
uint64_t time_period_num,
|
||||
int use_second_hsdir_index,
|
||||
int for_fetching, smartlist_t *responsible_dirs);
|
||||
@@ -254,8 +259,8 @@ void hs_inc_rdv_stream_counter(origin_circuit_t *circ);
|
||||
void hs_dec_rdv_stream_counter(origin_circuit_t *circ);
|
||||
|
||||
extend_info_t *hs_get_extend_info_from_lspecs(const smartlist_t *lspecs,
|
||||
const curve25519_public_key_t *onion_key,
|
||||
int direct_conn);
|
||||
const struct curve25519_public_key_t *onion_key,
|
||||
int direct_conn);
|
||||
|
||||
#ifdef HS_COMMON_PRIVATE
|
||||
|
||||
@@ -281,4 +286,3 @@ STATIC uint8_t *get_second_cached_disaster_srv(void);
|
||||
#endif /* defined(HS_COMMON_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_HS_COMMON_H) */
|
||||
|
||||
|
||||
+2
-1
@@ -29,6 +29,8 @@
|
||||
#include "or/hs_config.h"
|
||||
#include "or/hs_service.h"
|
||||
#include "or/rendservice.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
#include "or/or_options_st.h"
|
||||
|
||||
/* Using the given list of services, stage them into our global state. Every
|
||||
* service version are handled. This function can remove entries in the given
|
||||
@@ -587,4 +589,3 @@ hs_config_service_all(const or_options_t *options, int validate_only)
|
||||
/* Tor main should call the free all function on error. */
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -8,6 +8,7 @@
|
||||
|
||||
#include "or/or.h"
|
||||
#include "or/control.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/hs_common.h"
|
||||
#include "or/hs_control.h"
|
||||
@@ -258,4 +259,3 @@ hs_control_hspost_command(const char *body, const char *onion_address,
|
||||
smartlist_free(hsdirs);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
@@ -66,6 +66,8 @@
|
||||
#include "or/hs_cache.h"
|
||||
#include "or/hs_config.h"
|
||||
#include "or/torcert.h" /* tor_cert_encode_ed22519() */
|
||||
#include "lib/memarea/memarea.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
|
||||
#include "or/extend_info_st.h"
|
||||
|
||||
@@ -2607,4 +2609,3 @@ hs_desc_lspec_to_trunnel(const hs_desc_link_specifier_t *spec)
|
||||
|
||||
return ls;
|
||||
}
|
||||
|
||||
|
||||
@@ -12,9 +12,6 @@
|
||||
#include <stdint.h>
|
||||
|
||||
#include "or/or.h"
|
||||
#include "lib/net/address.h"
|
||||
#include "lib/crypt_ops/crypto.h"
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
#include "trunnel/ed25519_cert.h" /* needed for trunnel */
|
||||
#include "or/torcert.h"
|
||||
|
||||
@@ -281,4 +278,3 @@ MOCK_DECL(STATIC size_t, decrypt_desc_layer,(const hs_descriptor_t *desc,
|
||||
#endif /* defined(HS_DESCRIPTOR_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_HS_DESCRIPTOR_H) */
|
||||
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
#include "or/relay.h"
|
||||
#include "or/rendmid.h"
|
||||
#include "or/rephist.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
|
||||
/* Trunnel */
|
||||
#include "trunnel/ed25519_cert.h"
|
||||
@@ -611,4 +612,3 @@ hs_intropoint_clear(hs_intropoint_t *ip)
|
||||
smartlist_free(ip->link_specifiers);
|
||||
memset(ip, 0, sizeof(hs_intropoint_t));
|
||||
}
|
||||
|
||||
|
||||
+2
-1
@@ -26,6 +26,8 @@
|
||||
|
||||
#include "or/or.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "lib/crypt_ops/crypto_curve25519.h"
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
#include "or/hs_ntor.h"
|
||||
|
||||
/* String constants used by the ntor HS protocol */
|
||||
@@ -616,4 +618,3 @@ hs_ntor_circuit_key_expansion(const uint8_t *ntor_key_seed, size_t seed_len,
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
+23
-21
@@ -5,6 +5,9 @@
|
||||
#define TOR_HS_NTOR_H
|
||||
|
||||
#include "or/or.h"
|
||||
struct ed25519_public_key_t;
|
||||
struct curve25519_public_key_t;
|
||||
struct curve25519_keypair_t;
|
||||
|
||||
/* Output length of KDF for key expansion */
|
||||
#define HS_NTOR_KEY_EXPANSION_KDF_OUT_LEN \
|
||||
@@ -28,32 +31,32 @@ typedef struct {
|
||||
} hs_ntor_rend_cell_keys_t;
|
||||
|
||||
int hs_ntor_client_get_introduce1_keys(
|
||||
const ed25519_public_key_t *intro_auth_pubkey,
|
||||
const curve25519_public_key_t *intro_enc_pubkey,
|
||||
const curve25519_keypair_t *client_ephemeral_enc_keypair,
|
||||
const uint8_t *subcredential,
|
||||
hs_ntor_intro_cell_keys_t *hs_ntor_intro_cell_keys_out);
|
||||
const struct ed25519_public_key_t *intro_auth_pubkey,
|
||||
const struct curve25519_public_key_t *intro_enc_pubkey,
|
||||
const struct curve25519_keypair_t *client_ephemeral_enc_keypair,
|
||||
const uint8_t *subcredential,
|
||||
hs_ntor_intro_cell_keys_t *hs_ntor_intro_cell_keys_out);
|
||||
|
||||
int hs_ntor_client_get_rendezvous1_keys(
|
||||
const ed25519_public_key_t *intro_auth_pubkey,
|
||||
const curve25519_keypair_t *client_ephemeral_enc_keypair,
|
||||
const curve25519_public_key_t *intro_enc_pubkey,
|
||||
const curve25519_public_key_t *service_ephemeral_rend_pubkey,
|
||||
hs_ntor_rend_cell_keys_t *hs_ntor_rend_cell_keys_out);
|
||||
const struct ed25519_public_key_t *intro_auth_pubkey,
|
||||
const struct curve25519_keypair_t *client_ephemeral_enc_keypair,
|
||||
const struct curve25519_public_key_t *intro_enc_pubkey,
|
||||
const struct curve25519_public_key_t *service_ephemeral_rend_pubkey,
|
||||
hs_ntor_rend_cell_keys_t *hs_ntor_rend_cell_keys_out);
|
||||
|
||||
int hs_ntor_service_get_introduce1_keys(
|
||||
const ed25519_public_key_t *intro_auth_pubkey,
|
||||
const curve25519_keypair_t *intro_enc_keypair,
|
||||
const curve25519_public_key_t *client_ephemeral_enc_pubkey,
|
||||
const uint8_t *subcredential,
|
||||
hs_ntor_intro_cell_keys_t *hs_ntor_intro_cell_keys_out);
|
||||
const struct ed25519_public_key_t *intro_auth_pubkey,
|
||||
const struct curve25519_keypair_t *intro_enc_keypair,
|
||||
const struct curve25519_public_key_t *client_ephemeral_enc_pubkey,
|
||||
const uint8_t *subcredential,
|
||||
hs_ntor_intro_cell_keys_t *hs_ntor_intro_cell_keys_out);
|
||||
|
||||
int hs_ntor_service_get_rendezvous1_keys(
|
||||
const ed25519_public_key_t *intro_auth_pubkey,
|
||||
const curve25519_keypair_t *intro_enc_keypair,
|
||||
const curve25519_keypair_t *service_ephemeral_rend_keypair,
|
||||
const curve25519_public_key_t *client_ephemeral_enc_pubkey,
|
||||
hs_ntor_rend_cell_keys_t *hs_ntor_rend_cell_keys_out);
|
||||
const struct ed25519_public_key_t *intro_auth_pubkey,
|
||||
const struct curve25519_keypair_t *intro_enc_keypair,
|
||||
const struct curve25519_keypair_t *service_ephemeral_rend_keypair,
|
||||
const struct curve25519_public_key_t *client_ephemeral_enc_pubkey,
|
||||
hs_ntor_rend_cell_keys_t *hs_ntor_rend_cell_keys_out);
|
||||
|
||||
int hs_ntor_circuit_key_expansion(const uint8_t *ntor_key_seed,
|
||||
size_t seed_len,
|
||||
@@ -64,4 +67,3 @@ int hs_ntor_client_rendezvous2_mac_is_good(
|
||||
const uint8_t *rcvd_mac);
|
||||
|
||||
#endif /* !defined(TOR_HS_NTOR_H) */
|
||||
|
||||
|
||||
+11
-1
@@ -45,13 +45,24 @@
|
||||
#include "or/networkstatus_st.h"
|
||||
#include "or/node_st.h"
|
||||
#include "or/origin_circuit_st.h"
|
||||
#include "or/or_state_st.h"
|
||||
#include "or/routerstatus_st.h"
|
||||
|
||||
#include "lib/encoding/confline.h"
|
||||
#include "lib/crypt_ops/crypto_format.h"
|
||||
|
||||
/* Trunnel */
|
||||
#include "trunnel/ed25519_cert.h"
|
||||
#include "trunnel/hs/cell_common.h"
|
||||
#include "trunnel/hs/cell_establish_intro.h"
|
||||
|
||||
#ifdef HAVE_SYS_STAT_H
|
||||
#include <sys/stat.h>
|
||||
#endif
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
|
||||
/* Helper macro. Iterate over every service in the global map. The var is the
|
||||
* name of the service pointer. */
|
||||
#define FOR_EACH_SERVICE_BEGIN(var) \
|
||||
@@ -3631,4 +3642,3 @@ get_first_service(void)
|
||||
}
|
||||
|
||||
#endif /* defined(TOR_UNIT_TESTS) */
|
||||
|
||||
|
||||
+4
-1
@@ -75,7 +75,7 @@ LIBTOR_APP_A_SOURCES = \
|
||||
src/or/onion_fast.c \
|
||||
src/or/onion_tap.c \
|
||||
src/or/transports.c \
|
||||
src/or/parsecommon.c \
|
||||
src/or/parsecommon.c \
|
||||
src/or/periodic.c \
|
||||
src/or/protover.c \
|
||||
src/or/protover_rust.c \
|
||||
@@ -180,6 +180,7 @@ endif
|
||||
|
||||
ORHEADERS = \
|
||||
src/or/addressmap.h \
|
||||
src/or/addr_policy_st.h \
|
||||
src/or/authority_cert_st.h \
|
||||
src/or/auth_dirs.inc \
|
||||
src/or/bridges.h \
|
||||
@@ -274,6 +275,8 @@ ORHEADERS = \
|
||||
src/or/or_connection_st.h \
|
||||
src/or/or_handshake_certs_st.h \
|
||||
src/or/or_handshake_state_st.h \
|
||||
src/or/or_options_st.h \
|
||||
src/or/or_state_st.h \
|
||||
src/or/origin_circuit_st.h \
|
||||
src/or/transports.h \
|
||||
src/or/parsecommon.h \
|
||||
|
||||
@@ -116,6 +116,10 @@
|
||||
#include "lib/sandbox/sandbox.h"
|
||||
#include "lib/fs/lockfile.h"
|
||||
#include "lib/net/buffers_net.h"
|
||||
#include "lib/tls/tortls.h"
|
||||
#include "common/compat_libevent.h"
|
||||
#include "lib/encoding/confline.h"
|
||||
#include "common/timers.h"
|
||||
|
||||
#include <event2/event.h>
|
||||
|
||||
@@ -127,10 +131,15 @@
|
||||
#include "or/entry_connection_st.h"
|
||||
#include "or/networkstatus_st.h"
|
||||
#include "or/or_connection_st.h"
|
||||
#include "or/or_state_st.h"
|
||||
#include "or/port_cfg_st.h"
|
||||
#include "or/routerinfo_st.h"
|
||||
#include "or/socks_request_st.h"
|
||||
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_SYSTEMD
|
||||
# if defined(__COVERITY__) && !defined(__INCLUDE_LEVEL__)
|
||||
/* Systemd's use of gcc's __INCLUDE_LEVEL__ extension macro appears to confuse
|
||||
|
||||
+4
-3
@@ -96,10 +96,12 @@ uint64_t get_main_loop_idle_count(void);
|
||||
void periodic_events_on_new_options(const or_options_t *options);
|
||||
void reschedule_per_second_timer(void);
|
||||
|
||||
struct token_bucket_rw_t;
|
||||
|
||||
extern time_t time_of_process_start;
|
||||
extern int quiet_level;
|
||||
extern token_bucket_rw_t global_bucket;
|
||||
extern token_bucket_rw_t global_relayed_bucket;
|
||||
extern struct token_bucket_rw_t global_bucket;
|
||||
extern struct token_bucket_rw_t global_relayed_bucket;
|
||||
|
||||
#ifdef MAIN_PRIVATE
|
||||
STATIC void init_connection_lists(void);
|
||||
@@ -118,4 +120,3 @@ extern periodic_event_item_t periodic_events[];
|
||||
#endif /* defined(MAIN_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_MAIN_H) */
|
||||
|
||||
|
||||
@@ -30,6 +30,13 @@
|
||||
#include "or/node_st.h"
|
||||
#include "or/routerstatus_st.h"
|
||||
|
||||
#ifdef HAVE_FCNTL_H
|
||||
#include <fcntl.h>
|
||||
#endif
|
||||
#ifdef HAVE_SYS_STAT_H
|
||||
#include <sys/stat.h>
|
||||
#endif
|
||||
|
||||
/** A data structure to hold a bunch of cached microdescriptors. There are
|
||||
* two active files in the cache: a "cache file" that we mmap, and a "journal
|
||||
* file" that we append to. Periodically, we rebuild the cache file to hold
|
||||
|
||||
@@ -7,6 +7,10 @@
|
||||
#ifndef MICRODESC_ST_H
|
||||
#define MICRODESC_ST_H
|
||||
|
||||
struct curve25519_public_key_t;
|
||||
struct ed25519_public_key_t;
|
||||
struct short_policy_t;
|
||||
|
||||
/** A microdescriptor is the smallest amount of information needed to build a
|
||||
* circuit through a router. They are generated by the directory authorities,
|
||||
* using information from the uploaded routerinfo documents. They are not
|
||||
@@ -52,9 +56,9 @@ struct microdesc_t {
|
||||
/** As routerinfo_t.onion_pkey */
|
||||
crypto_pk_t *onion_pkey;
|
||||
/** As routerinfo_t.onion_curve25519_pkey */
|
||||
curve25519_public_key_t *onion_curve25519_pkey;
|
||||
struct curve25519_public_key_t *onion_curve25519_pkey;
|
||||
/** Ed25519 identity key, if included. */
|
||||
ed25519_public_key_t *ed25519_identity_pkey;
|
||||
struct ed25519_public_key_t *ed25519_identity_pkey;
|
||||
/** As routerinfo_t.ipv6_addr */
|
||||
tor_addr_t ipv6_addr;
|
||||
/** As routerinfo_t.ipv6_orport */
|
||||
@@ -62,10 +66,9 @@ struct microdesc_t {
|
||||
/** As routerinfo_t.family */
|
||||
smartlist_t *family;
|
||||
/** IPv4 exit policy summary */
|
||||
short_policy_t *exit_policy;
|
||||
struct short_policy_t *exit_policy;
|
||||
/** IPv6 exit policy summary */
|
||||
short_policy_t *ipv6_exit_policy;
|
||||
struct short_policy_t *ipv6_exit_policy;
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
@@ -45,6 +45,7 @@
|
||||
#include "or/circuitstats.h"
|
||||
#include "or/config.h"
|
||||
#include "or/connection.h"
|
||||
#include "or/connection_edge.h"
|
||||
#include "or/connection_or.h"
|
||||
#include "or/consdiffmgr.h"
|
||||
#include "or/control.h"
|
||||
@@ -87,6 +88,10 @@
|
||||
#include "or/vote_microdesc_hash_st.h"
|
||||
#include "or/vote_routerstatus_st.h"
|
||||
|
||||
#ifdef HAVE_UNISTD_H
|
||||
#include <unistd.h>
|
||||
#endif
|
||||
|
||||
/** Most recently received and validated v3 "ns"-flavored consensus network
|
||||
* status. */
|
||||
STATIC networkstatus_t *current_ns_consensus = NULL;
|
||||
@@ -2719,4 +2724,3 @@ networkstatus_free_all(void)
|
||||
tor_free(waiting->body);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -9,6 +9,13 @@
|
||||
|
||||
#include "or/networkstatus_sr_info_st.h"
|
||||
|
||||
/** Enumerates the possible seriousness values of a networkstatus document. */
|
||||
typedef enum networkstatus_type_t {
|
||||
NS_TYPE_VOTE,
|
||||
NS_TYPE_CONSENSUS,
|
||||
NS_TYPE_OPINION,
|
||||
} networkstatus_type_t;
|
||||
|
||||
/** A common structure to hold a v3 network status vote, or a v3 network
|
||||
* status consensus. */
|
||||
struct networkstatus_t {
|
||||
@@ -92,4 +99,3 @@ struct networkstatus_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
+1
-1
@@ -8,6 +8,7 @@
|
||||
#define NODE_ST_H
|
||||
|
||||
#include "or/hsdir_index_st.h"
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
/** A node_t represents a Tor router.
|
||||
*
|
||||
@@ -99,4 +100,3 @@ struct node_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
+9
-6
@@ -12,15 +12,19 @@
|
||||
#ifndef TOR_NODELIST_H
|
||||
#define TOR_NODELIST_H
|
||||
|
||||
struct ed25519_public_key_t;
|
||||
struct curve25519_public_key_t;
|
||||
|
||||
#define node_assert_ok(n) STMT_BEGIN { \
|
||||
tor_assert((n)->ri || (n)->rs); \
|
||||
} STMT_END
|
||||
|
||||
MOCK_DECL(node_t *, node_get_mutable_by_id,(const char *identity_digest));
|
||||
MOCK_DECL(const node_t *, node_get_by_id, (const char *identity_digest));
|
||||
node_t *node_get_mutable_by_ed25519_id(const ed25519_public_key_t *ed_id);
|
||||
node_t *node_get_mutable_by_ed25519_id(
|
||||
const struct ed25519_public_key_t *ed_id);
|
||||
MOCK_DECL(const node_t *, node_get_by_ed25519_id,
|
||||
(const ed25519_public_key_t *ed_id));
|
||||
(const struct ed25519_public_key_t *ed_id));
|
||||
|
||||
#define NNF_NO_WARN_UNNAMED (1u<<0)
|
||||
|
||||
@@ -65,9 +69,9 @@ uint32_t node_get_prim_addr_ipv4h(const node_t *node);
|
||||
void node_get_address_string(const node_t *node, char *cp, size_t len);
|
||||
long node_get_declared_uptime(const node_t *node);
|
||||
const smartlist_t *node_get_declared_family(const node_t *node);
|
||||
const ed25519_public_key_t *node_get_ed25519_id(const node_t *node);
|
||||
const struct ed25519_public_key_t *node_get_ed25519_id(const node_t *node);
|
||||
int node_ed25519_id_matches(const node_t *node,
|
||||
const ed25519_public_key_t *id);
|
||||
const struct ed25519_public_key_t *id);
|
||||
int node_supports_ed25519_link_authentication(const node_t *node,
|
||||
int compatible_with_us);
|
||||
int node_supports_v3_hsdir(const node_t *node);
|
||||
@@ -89,7 +93,7 @@ void node_get_prim_dirport(const node_t *node, tor_addr_port_t *ap_out);
|
||||
void node_get_pref_dirport(const node_t *node, tor_addr_port_t *ap_out);
|
||||
void node_get_pref_ipv6_dirport(const node_t *node, tor_addr_port_t *ap_out);
|
||||
int node_has_curve25519_onion_key(const node_t *node);
|
||||
const curve25519_public_key_t *node_get_curve25519_onion_key(
|
||||
const struct curve25519_public_key_t *node_get_curve25519_onion_key(
|
||||
const node_t *node);
|
||||
|
||||
MOCK_DECL(smartlist_t *, nodelist_get_list, (void));
|
||||
@@ -162,4 +166,3 @@ node_set_hsdir_index(node_t *node, const networkstatus_t *ns);
|
||||
MOCK_DECL(int, get_estimated_address_per_node, (void));
|
||||
|
||||
#endif /* !defined(TOR_NODELIST_H) */
|
||||
|
||||
|
||||
@@ -25,6 +25,7 @@
|
||||
#include "or/ntmain.h"
|
||||
#include "lib/log/win32err.h"
|
||||
#include "lib/fs/winlib.h"
|
||||
#include "common/compat_libevent.h"
|
||||
|
||||
#include <windows.h>
|
||||
#define GENSRV_SERVICENAME "tor"
|
||||
|
||||
+3
-3
@@ -68,6 +68,7 @@
|
||||
#include "or/config.h"
|
||||
#include "or/cpuworker.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "lib/crypt_ops/crypto_dh.h"
|
||||
#include "or/networkstatus.h"
|
||||
#include "or/onion.h"
|
||||
#include "or/onion_fast.h"
|
||||
@@ -558,7 +559,7 @@ onion_skin_server_handshake(int type,
|
||||
(char*)keys_out, keys_out_len)<0)
|
||||
return -1;
|
||||
r = TAP_ONIONSKIN_REPLY_LEN;
|
||||
memcpy(rend_nonce_out, reply_out+DH_KEY_LEN, DIGEST_LEN);
|
||||
memcpy(rend_nonce_out, reply_out+DH1024_KEY_LEN, DIGEST_LEN);
|
||||
break;
|
||||
case ONION_HANDSHAKE_TYPE_FAST:
|
||||
if (onionskin_len != CREATE_FAST_LEN)
|
||||
@@ -635,7 +636,7 @@ onion_skin_client_handshake(int type,
|
||||
msg_out) < 0)
|
||||
return -1;
|
||||
|
||||
memcpy(rend_authenticator_out, reply+DH_KEY_LEN, DIGEST_LEN);
|
||||
memcpy(rend_authenticator_out, reply+DH1024_KEY_LEN, DIGEST_LEN);
|
||||
|
||||
return 0;
|
||||
case ONION_HANDSHAKE_TYPE_FAST:
|
||||
@@ -1343,4 +1344,3 @@ extended_cell_format(uint8_t *command_out, uint16_t *len_out,
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
+7
-4
@@ -13,6 +13,10 @@
|
||||
#define TOR_ONION_H
|
||||
|
||||
struct create_cell_t;
|
||||
struct curve25519_keypair_t;
|
||||
struct curve25519_public_key_t;
|
||||
#include "lib/crypt_ops/crypto_ed25519.h"
|
||||
|
||||
int onion_pending_add(or_circuit_t *circ, struct create_cell_t *onionskin);
|
||||
or_circuit_t *onion_next_task(struct create_cell_t **onionskin_out);
|
||||
int onion_num_pending(uint16_t handshake_type);
|
||||
@@ -23,8 +27,8 @@ typedef struct server_onion_keys_t {
|
||||
uint8_t my_identity[DIGEST_LEN];
|
||||
crypto_pk_t *onion_key;
|
||||
crypto_pk_t *last_onion_key;
|
||||
di_digest256_map_t *curve25519_key_map;
|
||||
curve25519_keypair_t *junk_keypair;
|
||||
struct di_digest256_map_t *curve25519_key_map;
|
||||
struct curve25519_keypair_t *junk_keypair;
|
||||
} server_onion_keys_t;
|
||||
|
||||
#define MAX_ONIONSKIN_CHALLENGE_LEN 255
|
||||
@@ -88,7 +92,7 @@ typedef struct extend_cell_t {
|
||||
/** Identity fingerprint of the node we're conecting to.*/
|
||||
uint8_t node_id[DIGEST_LEN];
|
||||
/** Ed25519 public identity key. Zero if not set. */
|
||||
ed25519_public_key_t ed_pubkey;
|
||||
struct ed25519_public_key_t ed_pubkey;
|
||||
/** The "create cell" embedded in this extend cell. Note that unlike the
|
||||
* create cells we generate ourself, this once can have a handshake type we
|
||||
* don't recognize. */
|
||||
@@ -122,4 +126,3 @@ int extended_cell_format(uint8_t *command_out, uint16_t *len_out,
|
||||
uint8_t *payload_out, const extended_cell_t *cell_in);
|
||||
|
||||
#endif /* !defined(TOR_ONION_H) */
|
||||
|
||||
|
||||
+1
-1
@@ -29,6 +29,7 @@
|
||||
|
||||
#include "or/or.h"
|
||||
#include "or/onion_fast.h"
|
||||
#include "lib/crypt_ops/crypto_hkdf.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
|
||||
@@ -141,4 +142,3 @@ fast_client_handshake(const fast_handshake_state_t *handshake_state,
|
||||
tor_free(out);
|
||||
return r;
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -27,6 +27,7 @@
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/onion_ntor.h"
|
||||
#include "lib/log/torlog.h"
|
||||
#include "lib/ctime/di_ops.h"
|
||||
#include "common/util.h"
|
||||
|
||||
/** Free storage held in an ntor handshake state. */
|
||||
@@ -335,4 +336,3 @@ onion_skin_ntor_client_handshake(
|
||||
|
||||
return bad ? -1 : 0;
|
||||
}
|
||||
|
||||
|
||||
+12
-10
@@ -5,8 +5,10 @@
|
||||
#define TOR_ONION_NTOR_H
|
||||
|
||||
#include "lib/cc/torint.h"
|
||||
#include "lib/crypt_ops/crypto_curve25519.h"
|
||||
#include "lib/ctime/di_ops.h"
|
||||
|
||||
struct di_digest256_map_t;
|
||||
struct curve25519_public_key_t;
|
||||
struct curve25519_keypair_t;
|
||||
|
||||
/** State to be maintained by a client between sending an ntor onionskin
|
||||
* and receiving a reply. */
|
||||
@@ -22,17 +24,17 @@ void ntor_handshake_state_free_(ntor_handshake_state_t *state);
|
||||
FREE_AND_NULL(ntor_handshake_state_t, ntor_handshake_state_free_, (state))
|
||||
|
||||
int onion_skin_ntor_create(const uint8_t *router_id,
|
||||
const curve25519_public_key_t *router_key,
|
||||
const struct curve25519_public_key_t *router_key,
|
||||
ntor_handshake_state_t **handshake_state_out,
|
||||
uint8_t *onion_skin_out);
|
||||
|
||||
int onion_skin_ntor_server_handshake(const uint8_t *onion_skin,
|
||||
const di_digest256_map_t *private_keys,
|
||||
const curve25519_keypair_t *junk_keypair,
|
||||
const uint8_t *my_node_id,
|
||||
uint8_t *handshake_reply_out,
|
||||
uint8_t *key_out,
|
||||
size_t key_out_len);
|
||||
const struct di_digest256_map_t *private_keys,
|
||||
const struct curve25519_keypair_t *junk_keypair,
|
||||
const uint8_t *my_node_id,
|
||||
uint8_t *handshake_reply_out,
|
||||
uint8_t *key_out,
|
||||
size_t key_out_len);
|
||||
|
||||
int onion_skin_ntor_client_handshake(
|
||||
const ntor_handshake_state_t *handshake_state,
|
||||
@@ -42,6 +44,7 @@ int onion_skin_ntor_client_handshake(
|
||||
const char **msg_out);
|
||||
|
||||
#ifdef ONION_NTOR_PRIVATE
|
||||
#include "lib/crypt_ops/crypto_curve25519.h"
|
||||
|
||||
/** Storage held by a client while waiting for an ntor reply from a server. */
|
||||
struct ntor_handshake_state_t {
|
||||
@@ -60,4 +63,3 @@ struct ntor_handshake_state_t {
|
||||
#endif /* defined(ONION_NTOR_PRIVATE) */
|
||||
|
||||
#endif /* !defined(TOR_ONION_NTOR_H) */
|
||||
|
||||
|
||||
+10
-10
@@ -29,6 +29,7 @@
|
||||
|
||||
#include "or/or.h"
|
||||
#include "or/config.h"
|
||||
#include "lib/crypt_ops/crypto_dh.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
#include "lib/crypt_ops/crypto_util.h"
|
||||
#include "or/onion_tap.h"
|
||||
@@ -53,7 +54,7 @@ onion_skin_TAP_create(crypto_pk_t *dest_router_key,
|
||||
crypto_dh_t **handshake_state_out,
|
||||
char *onion_skin_out) /* TAP_ONIONSKIN_CHALLENGE_LEN bytes */
|
||||
{
|
||||
char challenge[DH_KEY_LEN];
|
||||
char challenge[DH1024_KEY_LEN];
|
||||
crypto_dh_t *dh = NULL;
|
||||
int dhbytes, pkbytes;
|
||||
|
||||
@@ -77,7 +78,7 @@ onion_skin_TAP_create(crypto_pk_t *dest_router_key,
|
||||
/* set meeting point, meeting cookie, etc here. Leave zero for now. */
|
||||
if (crypto_pk_obsolete_public_hybrid_encrypt(dest_router_key, onion_skin_out,
|
||||
TAP_ONIONSKIN_CHALLENGE_LEN,
|
||||
challenge, DH_KEY_LEN,
|
||||
challenge, DH1024_KEY_LEN,
|
||||
PK_PKCS1_OAEP_PADDING, 1)<0)
|
||||
goto err;
|
||||
|
||||
@@ -136,7 +137,7 @@ onion_skin_TAP_server_handshake(
|
||||
log_info(LD_PROTOCOL,
|
||||
"Couldn't decrypt onionskin: client may be using old onion key");
|
||||
goto err;
|
||||
} else if (len != DH_KEY_LEN) {
|
||||
} else if (len != DH1024_KEY_LEN) {
|
||||
log_fn(LOG_PROTOCOL_WARN, LD_PROTOCOL,
|
||||
"Unexpected onionskin length after decryption: %ld",
|
||||
(long)len);
|
||||
@@ -152,7 +153,7 @@ onion_skin_TAP_server_handshake(
|
||||
goto err;
|
||||
/* LCOV_EXCL_STOP */
|
||||
}
|
||||
if (crypto_dh_get_public(dh, handshake_reply_out, DH_KEY_LEN)) {
|
||||
if (crypto_dh_get_public(dh, handshake_reply_out, DH1024_KEY_LEN)) {
|
||||
/* LCOV_EXCL_START
|
||||
* This can only fail if the length of the key we just allocated is too
|
||||
* big. That should be impossible. */
|
||||
@@ -164,7 +165,7 @@ onion_skin_TAP_server_handshake(
|
||||
key_material_len = DIGEST_LEN+key_out_len;
|
||||
key_material = tor_malloc(key_material_len);
|
||||
len = crypto_dh_compute_secret(LOG_PROTOCOL_WARN, dh, challenge,
|
||||
DH_KEY_LEN, key_material,
|
||||
DH1024_KEY_LEN, key_material,
|
||||
key_material_len);
|
||||
if (len < 0) {
|
||||
log_info(LD_GENERAL, "crypto_dh_compute_secret failed.");
|
||||
@@ -172,7 +173,7 @@ onion_skin_TAP_server_handshake(
|
||||
}
|
||||
|
||||
/* send back H(K|0) as proof that we learned K. */
|
||||
memcpy(handshake_reply_out+DH_KEY_LEN, key_material, DIGEST_LEN);
|
||||
memcpy(handshake_reply_out+DH1024_KEY_LEN, key_material, DIGEST_LEN);
|
||||
|
||||
/* use the rest of the key material for our shared keys, digests, etc */
|
||||
memcpy(key_out, key_material+DIGEST_LEN, key_out_len);
|
||||
@@ -212,12 +213,12 @@ onion_skin_TAP_client_handshake(crypto_dh_t *handshake_state,
|
||||
ssize_t len;
|
||||
char *key_material=NULL;
|
||||
size_t key_material_len;
|
||||
tor_assert(crypto_dh_get_bytes(handshake_state) == DH_KEY_LEN);
|
||||
tor_assert(crypto_dh_get_bytes(handshake_state) == DH1024_KEY_LEN);
|
||||
|
||||
key_material_len = DIGEST_LEN + key_out_len;
|
||||
key_material = tor_malloc(key_material_len);
|
||||
len = crypto_dh_compute_secret(LOG_PROTOCOL_WARN, handshake_state,
|
||||
handshake_reply, DH_KEY_LEN, key_material,
|
||||
handshake_reply, DH1024_KEY_LEN, key_material,
|
||||
key_material_len);
|
||||
if (len < 0) {
|
||||
if (msg_out)
|
||||
@@ -225,7 +226,7 @@ onion_skin_TAP_client_handshake(crypto_dh_t *handshake_state,
|
||||
goto err;
|
||||
}
|
||||
|
||||
if (tor_memneq(key_material, handshake_reply+DH_KEY_LEN, DIGEST_LEN)) {
|
||||
if (tor_memneq(key_material, handshake_reply+DH1024_KEY_LEN, DIGEST_LEN)) {
|
||||
/* H(K) does *not* match. Something fishy. */
|
||||
if (msg_out)
|
||||
*msg_out = "Digest DOES NOT MATCH on onion handshake. Bug or attack.";
|
||||
@@ -243,4 +244,3 @@ onion_skin_TAP_client_handshake(crypto_dh_t *handshake_state,
|
||||
tor_free(key_material);
|
||||
return -1;
|
||||
}
|
||||
|
||||
|
||||
+10
-8
@@ -14,25 +14,27 @@
|
||||
|
||||
#define TAP_ONIONSKIN_CHALLENGE_LEN (PKCS1_OAEP_PADDING_OVERHEAD+\
|
||||
CIPHER_KEY_LEN+\
|
||||
DH_KEY_LEN)
|
||||
#define TAP_ONIONSKIN_REPLY_LEN (DH_KEY_LEN+DIGEST_LEN)
|
||||
DH1024_KEY_LEN)
|
||||
#define TAP_ONIONSKIN_REPLY_LEN (DH1024_KEY_LEN+DIGEST_LEN)
|
||||
|
||||
int onion_skin_TAP_create(crypto_pk_t *router_key,
|
||||
crypto_dh_t **handshake_state_out,
|
||||
struct crypto_dh_t;
|
||||
struct crypto_pk_t;
|
||||
|
||||
int onion_skin_TAP_create(struct crypto_pk_t *router_key,
|
||||
struct crypto_dh_t **handshake_state_out,
|
||||
char *onion_skin_out);
|
||||
|
||||
int onion_skin_TAP_server_handshake(const char *onion_skin,
|
||||
crypto_pk_t *private_key,
|
||||
crypto_pk_t *prev_private_key,
|
||||
struct crypto_pk_t *private_key,
|
||||
struct crypto_pk_t *prev_private_key,
|
||||
char *handshake_reply_out,
|
||||
char *key_out,
|
||||
size_t key_out_len);
|
||||
|
||||
int onion_skin_TAP_client_handshake(crypto_dh_t *handshake_state,
|
||||
int onion_skin_TAP_client_handshake(struct crypto_dh_t *handshake_state,
|
||||
const char *handshake_reply,
|
||||
char *key_out,
|
||||
size_t key_out_len,
|
||||
const char **msg_out);
|
||||
|
||||
#endif /* !defined(TOR_ONION_TAP_H) */
|
||||
|
||||
|
||||
+20
-2299
File diff suppressed because it is too large
Load Diff
@@ -8,6 +8,9 @@
|
||||
#define OR_CONNECTION_ST_H
|
||||
|
||||
#include "or/connection_st.h"
|
||||
#include "common/token_bucket.h"
|
||||
|
||||
struct tor_tls_t;
|
||||
|
||||
/** Subtype of connection_t for an "OR connection" -- that is, one that speaks
|
||||
* cells over TLS. */
|
||||
@@ -33,7 +36,7 @@ struct or_connection_t {
|
||||
|
||||
char *nickname; /**< Nickname of OR on other side (if any). */
|
||||
|
||||
tor_tls_t *tls; /**< TLS connection state. */
|
||||
struct tor_tls_t *tls; /**< TLS connection state. */
|
||||
int tls_error; /**< Last tor_tls error code. */
|
||||
/** When we last used this conn for any client traffic. If not
|
||||
* recent, we can rate limit it further. */
|
||||
@@ -87,4 +90,3 @@ struct or_connection_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
@@ -7,6 +7,8 @@
|
||||
#ifndef OR_HANDSHAKE_CERTS_ST
|
||||
#define OR_HANDSHAKE_CERTS_ST
|
||||
|
||||
struct tor_x509_cert_t;
|
||||
|
||||
/** Structure to hold all the certificates we've received on an OR connection
|
||||
*/
|
||||
struct or_handshake_certs_t {
|
||||
@@ -14,13 +16,13 @@ struct or_handshake_certs_t {
|
||||
int started_here;
|
||||
/** The cert for the 'auth' RSA key that's supposed to sign the AUTHENTICATE
|
||||
* cell. Signed with the RSA identity key. */
|
||||
tor_x509_cert_t *auth_cert;
|
||||
struct tor_x509_cert_t *auth_cert;
|
||||
/** The cert for the 'link' RSA key that was used to negotiate the TLS
|
||||
* connection. Signed with the RSA identity key. */
|
||||
tor_x509_cert_t *link_cert;
|
||||
struct tor_x509_cert_t *link_cert;
|
||||
/** A self-signed identity certificate: the RSA identity key signed
|
||||
* with itself. */
|
||||
tor_x509_cert_t *id_cert;
|
||||
struct tor_x509_cert_t *id_cert;
|
||||
/** The Ed25519 signing key, signed with the Ed25519 identity key. */
|
||||
struct tor_cert_st *ed_id_sign;
|
||||
/** A digest of the X509 link certificate for the TLS connection, signed
|
||||
@@ -36,4 +38,3 @@ struct or_handshake_certs_t {
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,86 @@
|
||||
/* Copyright (c) 2001 Matej Pfajfar.
|
||||
* Copyright (c) 2001-2004, Roger Dingledine.
|
||||
* Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
|
||||
* Copyright (c) 2007-2018, The Tor Project, Inc. */
|
||||
/* See LICENSE for licensing information */
|
||||
|
||||
#ifndef TOR_OR_STATE_ST_H
|
||||
#define TOR_OR_STATE_ST_H
|
||||
|
||||
#include "lib/cc/torint.h"
|
||||
struct smartlist_t;
|
||||
|
||||
/** Persistent state for an onion router, as saved to disk. */
|
||||
struct or_state_t {
|
||||
uint32_t magic_;
|
||||
/** The time at which we next plan to write the state to the disk. Equal to
|
||||
* TIME_MAX if there are no savable changes, 0 if there are changes that
|
||||
* should be saved right away. */
|
||||
time_t next_write;
|
||||
|
||||
/** When was the state last written to disk? */
|
||||
time_t LastWritten;
|
||||
|
||||
/** Fields for accounting bandwidth use. */
|
||||
time_t AccountingIntervalStart;
|
||||
uint64_t AccountingBytesReadInInterval;
|
||||
uint64_t AccountingBytesWrittenInInterval;
|
||||
int AccountingSecondsActive;
|
||||
int AccountingSecondsToReachSoftLimit;
|
||||
time_t AccountingSoftLimitHitAt;
|
||||
uint64_t AccountingBytesAtSoftLimit;
|
||||
uint64_t AccountingExpectedUsage;
|
||||
|
||||
/** A list of Entry Guard-related configuration lines. (pre-prop271) */
|
||||
struct config_line_t *EntryGuards;
|
||||
|
||||
/** A list of guard-related configuration lines. (post-prop271) */
|
||||
struct config_line_t *Guard;
|
||||
|
||||
struct config_line_t *TransportProxies;
|
||||
|
||||
/** Cached revision counters for active hidden services on this host */
|
||||
struct config_line_t *HidServRevCounter;
|
||||
|
||||
/** These fields hold information on the history of bandwidth usage for
|
||||
* servers. The "Ends" fields hold the time when we last updated the
|
||||
* bandwidth usage. The "Interval" fields hold the granularity, in seconds,
|
||||
* of the entries of Values. The "Values" lists hold decimal string
|
||||
* representations of the number of bytes read or written in each
|
||||
* interval. The "Maxima" list holds decimal strings describing the highest
|
||||
* rate achieved during the interval.
|
||||
*/
|
||||
time_t BWHistoryReadEnds;
|
||||
int BWHistoryReadInterval;
|
||||
struct smartlist_t *BWHistoryReadValues;
|
||||
struct smartlist_t *BWHistoryReadMaxima;
|
||||
time_t BWHistoryWriteEnds;
|
||||
int BWHistoryWriteInterval;
|
||||
struct smartlist_t *BWHistoryWriteValues;
|
||||
struct smartlist_t *BWHistoryWriteMaxima;
|
||||
time_t BWHistoryDirReadEnds;
|
||||
int BWHistoryDirReadInterval;
|
||||
struct smartlist_t *BWHistoryDirReadValues;
|
||||
struct smartlist_t *BWHistoryDirReadMaxima;
|
||||
time_t BWHistoryDirWriteEnds;
|
||||
int BWHistoryDirWriteInterval;
|
||||
struct smartlist_t *BWHistoryDirWriteValues;
|
||||
struct smartlist_t *BWHistoryDirWriteMaxima;
|
||||
|
||||
/** Build time histogram */
|
||||
struct config_line_t * BuildtimeHistogram;
|
||||
int TotalBuildTimes;
|
||||
int CircuitBuildAbandonedCount;
|
||||
|
||||
/** What version of Tor wrote this state file? */
|
||||
char *TorVersion;
|
||||
|
||||
/** Holds any unrecognized values we found in the state file, in the order
|
||||
* in which we found them. */
|
||||
struct config_line_t *ExtraLines;
|
||||
|
||||
/** When did we last rotate our onion key? "0" for 'no idea'. */
|
||||
time_t LastRotatedOnionKey;
|
||||
};
|
||||
|
||||
#endif
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user