Tor 0.4.9.0-alpha-dev
|
Header file containing common data for the whole HS subsystem. More...
Go to the source code of this file.
Data Structures | |
struct | hs_port_config_t |
Enumerations | |
enum | hs_auth_key_type_t { HS_AUTH_KEY_TYPE_LEGACY = 1 , HS_AUTH_KEY_TYPE_ED25519 = 2 } |
enum | hs_service_add_ephemeral_status_t { RSAE_BADAUTH = -5 , RSAE_BADVIRTPORT = -4 , RSAE_ADDREXISTS = -3 , RSAE_BADPRIVKEY = -2 , RSAE_INTERNAL = -1 , RSAE_OKAY = 0 } |
Functions | |
void | hs_init (void) |
void | hs_free_all (void) |
void | hs_cleanup_circ (circuit_t *circ) |
int | hs_check_service_private_dir (const char *username, const char *path, unsigned int dir_group_readable, unsigned int create) |
int | hs_get_service_max_rend_failures (void) |
char * | hs_path_from_filename (const char *directory, const char *filename) |
void | hs_build_address (const struct ed25519_public_key_t *key, uint8_t version, char *addr_out) |
int | hs_address_is_valid (const char *address) |
int | hs_parse_address (const char *address, struct ed25519_public_key_t *key_out, uint8_t *checksum_out, uint8_t *version_out) |
int | hs_parse_address_no_log (const char *address, struct ed25519_public_key_t *key_out, uint8_t *checksum_out, uint8_t *version_out, const char **errmsg) |
void | hs_build_blinded_pubkey (const struct ed25519_public_key_t *pubkey, const uint8_t *secret, size_t secret_len, uint64_t time_period_num, struct ed25519_public_key_t *pubkey_out) |
void | hs_build_blinded_keypair (const struct ed25519_keypair_t *kp, const uint8_t *secret, size_t secret_len, uint64_t time_period_num, struct ed25519_keypair_t *kp_out) |
int | hs_service_requires_uptime_circ (const smartlist_t *ports) |
routerstatus_t * | pick_hsdir (const char *desc_id, const char *desc_id_base32) |
void | hs_get_subcredential (const struct ed25519_public_key_t *identity_pk, const struct ed25519_public_key_t *blinded_pk, struct hs_subcredential_t *subcred_out) |
uint64_t | hs_get_previous_time_period_num (time_t now) |
uint64_t | hs_get_time_period_num (time_t now) |
uint64_t | hs_get_next_time_period_num (time_t now) |
time_t | hs_get_start_time_of_next_time_period (time_t now) |
int | hs_in_period_between_tp_and_srv (const networkstatus_t *consensus, time_t now) |
uint8_t * | hs_get_current_srv (uint64_t time_period_num, const networkstatus_t *ns) |
uint8_t * | hs_get_previous_srv (uint64_t time_period_num, const networkstatus_t *ns) |
void | hs_build_hsdir_index (const struct ed25519_public_key_t *identity_pk, const uint8_t *srv, uint64_t period_num, uint8_t *hsdir_index_out) |
void | hs_build_hs_index (uint64_t replica, const struct ed25519_public_key_t *blinded_pk, uint64_t period_num, uint8_t *hs_index_out) |
int32_t | hs_get_hsdir_n_replicas (void) |
int32_t | hs_get_hsdir_spread_fetch (void) |
int32_t | hs_get_hsdir_spread_store (void) |
void | hs_get_responsible_hsdirs (const struct ed25519_public_key_t *blinded_pk, uint64_t time_period_num, int use_second_hsdir_index, int for_fetching, smartlist_t *responsible_dirs) |
routerstatus_t * | hs_pick_hsdir (smartlist_t *responsible_dirs, const char *req_key_str, bool *is_rate_limited_out) |
time_t | hs_hsdir_requery_period (const or_options_t *options) |
time_t | hs_lookup_last_hid_serv_request (routerstatus_t *hs_dir, const char *desc_id_base32, time_t now, int set) |
void | hs_clean_last_hid_serv_requests (time_t now) |
void | hs_purge_hid_serv_from_last_hid_serv_requests (const char *desc_id) |
void | hs_purge_last_hid_serv_requests (void) |
int | hs_set_conn_addr_port (const smartlist_t *ports, edge_connection_t *conn) |
hs_port_config_t * | hs_parse_port_config (const char *string, const char *sep, char **err_msg_out) |
void | hs_port_config_free_ (hs_port_config_t *p) |
void | hs_inc_rdv_stream_counter (origin_circuit_t *circ) |
void | hs_dec_rdv_stream_counter (origin_circuit_t *circ) |
extend_info_t * | hs_get_extend_info_from_lspecs (const smartlist_t *lspecs, const struct curve25519_public_key_t *onion_key, int direct_conn) |
link_specifier_t * | link_specifier_dup (const link_specifier_t *src) |
Header file containing common data for the whole HS subsystem.
Definition in file hs_common.h.
#define ESTABLISH_INTRO_SIG_PREFIX "Tor establish-intro cell v1" |
String prefix for the signature of ESTABLISH_INTRO
Definition at line 50 of file hs_common.h.
#define HS_CREDENTIAL_PREFIX "credential" |
Credential and subcredential prefix value.
Definition at line 101 of file hs_common.h.
#define HS_CREDENTIAL_PREFIX_LEN (sizeof(HS_CREDENTIAL_PREFIX) - 1) |
Definition at line 102 of file hs_common.h.
#define HS_DEFAULT_HSDIR_N_REPLICAS 2 |
Default value of number of hsdir replicas (hsdir_n_replicas).
Definition at line 119 of file hs_common.h.
#define HS_DEFAULT_HSDIR_SPREAD_FETCH 3 |
Default value of hsdir spread fetch (hsdir_spread_fetch).
Definition at line 123 of file hs_common.h.
#define HS_DEFAULT_HSDIR_SPREAD_STORE 4 |
Default value of hsdir spread store (hsdir_spread_store).
Definition at line 121 of file hs_common.h.
#define HS_INDEX_PREFIX "store-at-idx" |
Node hidden service stored at index prefix value.
Definition at line 107 of file hs_common.h.
#define HS_INDEX_PREFIX_LEN (sizeof(HS_INDEX_PREFIX) - 1) |
Definition at line 108 of file hs_common.h.
#define HS_KEYBLIND_NONCE_LEN (HS_KEYBLIND_NONCE_PREFIX_LEN + sizeof(uint64_t) + sizeof(uint64_t)) |
Definition at line 97 of file hs_common.h.
#define HS_KEYBLIND_NONCE_PREFIX "key-blind" |
Keyblinding parameter construction is as follow: "key-blind" || INT_8(period_num) || INT_8(start_period_sec)
Definition at line 95 of file hs_common.h.
#define HS_KEYBLIND_NONCE_PREFIX_LEN (sizeof(HS_KEYBLIND_NONCE_PREFIX) - 1) |
Definition at line 96 of file hs_common.h.
#define HS_LEGACY_RENDEZVOUS_CELL_SIZE (REND_COOKIE_LEN + DH1024_KEY_LEN + DIGEST_LEN) |
The size of a legacy RENDEZVOUS1 cell which adds up to 168 bytes. It is bigger than the 84 bytes needed for version 3 so we need to pad up to that length so it is indistinguishable between versions.
Definition at line 128 of file hs_common.h.
#define hs_port_config_free | ( | p | ) | FREE_AND_NULL(hs_port_config_t, hs_port_config_free_, (p)) |
Definition at line 245 of file hs_common.h.
#define HS_SERVICE_ADDR_CHECKSUM_INPUT_LEN (HS_SERVICE_ADDR_CHECKSUM_PREFIX_LEN + ED25519_PUBKEY_LEN + sizeof(uint8_t)) |
Length of the resulting checksum of the address. The construction of this checksum looks like: CHECKSUM = ".onion checksum" || PUBKEY || VERSION where VERSION is 1 byte. This is pre-hashing.
Definition at line 68 of file hs_common.h.
#define HS_SERVICE_ADDR_CHECKSUM_LEN_USED 2 |
The amount of bytes we use from the address checksum.
Definition at line 71 of file hs_common.h.
#define HS_SERVICE_ADDR_CHECKSUM_PREFIX ".onion checksum" |
Prefix of the onion address checksum.
Definition at line 60 of file hs_common.h.
#define HS_SERVICE_ADDR_CHECKSUM_PREFIX_LEN (sizeof(HS_SERVICE_ADDR_CHECKSUM_PREFIX) - 1) |
Length of the checksum prefix minus the NUL terminated byte.
Definition at line 62 of file hs_common.h.
#define HS_SERVICE_ADDR_LEN (ED25519_PUBKEY_LEN + HS_SERVICE_ADDR_CHECKSUM_LEN_USED + sizeof(uint8_t)) |
Length of the binary encoded service address which is of course before the base32 encoding. Construction is: PUBKEY || CHECKSUM || VERSION with 1 byte VERSION and 2 bytes CHECKSUM. The following is 35 bytes.
Definition at line 76 of file hs_common.h.
#define HS_SERVICE_ADDR_LEN_BASE32 (CEIL_DIV(HS_SERVICE_ADDR_LEN * 8, 5)) |
Length of 'y' portion of 'y.onion' URL. This is base32 encoded and the length ends up to 56 bytes (not counting the terminated NUL byte.)
Definition at line 80 of file hs_common.h.
#define HS_SRV_DISASTER_PREFIX "shared-random-disaster" |
Prefix of the shared random value disaster mode.
Definition at line 115 of file hs_common.h.
#define HS_SRV_DISASTER_PREFIX_LEN (sizeof(HS_SRV_DISASTER_PREFIX) - 1) |
Definition at line 116 of file hs_common.h.
#define HS_SUBCREDENTIAL_PREFIX "subcredential" |
Definition at line 103 of file hs_common.h.
#define HS_SUBCREDENTIAL_PREFIX_LEN (sizeof(HS_SUBCREDENTIAL_PREFIX) - 1) |
Definition at line 104 of file hs_common.h.
#define HS_TIME_PERIOD_LENGTH_DEFAULT 1440 /* 1440 minutes == one day */ |
The default HS time period length
Definition at line 84 of file hs_common.h.
#define HS_TIME_PERIOD_LENGTH_DEFAULT 1440 /* 1440 minutes == one day */ |
The default HS time period length
Definition at line 84 of file hs_common.h.
#define HS_TIME_PERIOD_LENGTH_MAX (60 * 24 * 10) /* 10 days or 14400 minutes */ |
The minimum time period length as seen in prop224 section [TIME-PERIODS]
Definition at line 88 of file hs_common.h.
#define HS_TIME_PERIOD_LENGTH_MAX (60 * 24 * 10) /* 10 days or 14400 minutes */ |
The minimum time period length as seen in prop224 section [TIME-PERIODS]
Definition at line 88 of file hs_common.h.
#define HS_TIME_PERIOD_LENGTH_MIN 30 /* minutes */ |
The minimum time period length as seen in prop224 section [TIME-PERIODS]
Definition at line 86 of file hs_common.h.
#define HS_TIME_PERIOD_LENGTH_MIN 30 /* minutes */ |
The minimum time period length as seen in prop224 section [TIME-PERIODS]
Definition at line 86 of file hs_common.h.
#define HS_TIME_PERIOD_ROTATION_OFFSET (12 * 60) /* minutes */ |
The time period rotation offset as seen in prop224 section [TIME-PERIODS]
Definition at line 91 of file hs_common.h.
#define HS_VERSION_MAX HS_VERSION_THREE |
Latest version we support.
Definition at line 27 of file hs_common.h.
#define HS_VERSION_MIN HS_VERSION_THREE |
Earliest version we support.
Definition at line 25 of file hs_common.h.
#define HS_VERSION_THREE 3 |
Version 3 of the protocol (prop224).
Definition at line 23 of file hs_common.h.
#define HSDIR_INDEX_PREFIX "node-idx" |
Node hidden service directory index prefix value.
Definition at line 111 of file hs_common.h.
#define HSDIR_INDEX_PREFIX_LEN (sizeof(HSDIR_INDEX_PREFIX) - 1) |
Definition at line 112 of file hs_common.h.
#define INTRO_CIRC_RETRY_PERIOD (60*5) |
If we can't build our intro circuits, don't retry for this long.
Definition at line 38 of file hs_common.h.
#define MAX_INTRO_CIRCS_PER_PERIOD 10 |
Don't try to build more than this many circuits before giving up for a while.
Definition at line 41 of file hs_common.h.
#define MAX_REND_FAILURES 1 |
How many times will a hidden service operator attempt to connect to a requested rendezvous point before giving up?
Definition at line 44 of file hs_common.h.
#define MAX_REND_TIMEOUT 30 |
How many seconds should we spend trying to connect to a requested rendezvous point before giving up?
Definition at line 47 of file hs_common.h.
#define NUM_INTRO_POINTS_DEFAULT 3 |
Try to maintain this many intro points per service by default.
Definition at line 30 of file hs_common.h.
#define NUM_INTRO_POINTS_EXTRA 2 |
Number of extra intro points we launch if our set of intro nodes is empty. See proposal 155, section 4.
Definition at line 35 of file hs_common.h.
#define NUM_INTRO_POINTS_MAX 10 |
Maximum number of intro points per generic and version 2 service.
Definition at line 32 of file hs_common.h.
enum hs_auth_key_type_t |
Type of authentication key used by an introduction point.
Definition at line 132 of file hs_common.h.
Return value when adding an ephemeral service through the ADD_ONION control port command.
Definition at line 139 of file hs_common.h.
int hs_address_is_valid | ( | const char * | address | ) |
Validate a given onion address. The length, the base32 decoding, and checksum are validated. Return 1 if valid else 0.
Definition at line 856 of file hs_common.c.
Referenced by connection_control_closed(), handle_control_hspost(), and hs_build_address().
int hs_check_service_private_dir | ( | const char * | username, |
const char * | path, | ||
unsigned int | dir_group_readable, | ||
unsigned int | create | ||
) |
Make sure that the directory for service is private, using the config username.
If create is true:
Definition at line 200 of file hs_common.c.
Referenced by load_service_keys().
void hs_clean_last_hid_serv_requests | ( | time_t | now | ) |
Clean the history of request times to hidden service directories, so that it does not contain requests older than REND_HID_SERV_DIR_REQUERY_PERIOD seconds any more.
Definition at line 1413 of file hs_common.c.
void hs_dec_rdv_stream_counter | ( | origin_circuit_t * | circ | ) |
For the given origin circuit circ, decrement the number of rendezvous stream counter. This handles every hidden service version.
Definition at line 1722 of file hs_common.c.
void hs_free_all | ( | void | ) |
Release and cleanup all memory of the HS subsystem (all version). This is called by tor_free_all().
Definition at line 1710 of file hs_common.c.
uint8_t * hs_get_current_srv | ( | uint64_t | time_period_num, |
const networkstatus_t * | ns | ||
) |
Return a newly allocated buffer containing the current shared random value or if not present, a disaster value is computed using the given time period number. If a consensus is provided in ns, use it to get the SRV value. This function can't fail.
Definition at line 1117 of file hs_common.c.
int32_t hs_get_hsdir_n_replicas | ( | void | ) |
Return the number of replicas defined by a consensus parameter or the default value.
Definition at line 1152 of file hs_common.c.
int32_t hs_get_hsdir_spread_fetch | ( | void | ) |
Return the spread fetch value defined by a consensus parameter or the default value.
Definition at line 1162 of file hs_common.c.
int32_t hs_get_hsdir_spread_store | ( | void | ) |
Return the spread store value defined by a consensus parameter or the default value.
Definition at line 1172 of file hs_common.c.
uint64_t hs_get_next_time_period_num | ( | time_t | now | ) |
Get the number of the upcoming HS time period, given that the current time is now. If now is not set, we try to get the time from a live consensus.
Definition at line 306 of file hs_common.c.
Referenced by build_descriptors_for_new_service(), and hs_get_start_time_of_next_time_period().
uint8_t * hs_get_previous_srv | ( | uint64_t | time_period_num, |
const networkstatus_t * | ns | ||
) |
Return a newly allocated buffer containing the previous shared random value or if not present, a disaster value is computed using the given time period number. This function can't fail.
Definition at line 1135 of file hs_common.c.
uint64_t hs_get_previous_time_period_num | ( | time_t | now | ) |
Get the number of the previous HS time period, given that the current time is now. If now is not set, we try to get the time from a live consensus.
Definition at line 315 of file hs_common.c.
Referenced by build_descriptors_for_new_service().
int hs_get_service_max_rend_failures | ( | void | ) |
How many times will a hidden service operator attempt to connect to a requested rendezvous point before giving up?
Definition at line 233 of file hs_common.c.
Referenced by can_relaunch_service_rendezvous_point().
time_t hs_get_start_time_of_next_time_period | ( | time_t | now | ) |
Return the start time of the upcoming time period based on now. If now is not set, we try to get the time ourselves from a live consensus.
Definition at line 324 of file hs_common.c.
Referenced by hs_in_period_between_tp_and_srv(), and rep_hist_hs_stats_init().
uint64_t hs_get_time_period_num | ( | time_t | now | ) |
Get the HS time period number at time now. If now is not set, we try to get the time ourselves from a live consensus.
Definition at line 269 of file hs_common.c.
Referenced by build_descriptors_for_new_service(), compute_subcredentials(), directory_launch_v3_desc_fetch(), hs_client_decode_descriptor(), hs_get_next_time_period_num(), hs_get_previous_time_period_num(), pick_hsdir_v3(), and purge_hid_serv_request().
time_t hs_hsdir_requery_period | ( | const or_options_t * | options | ) |
Return the period for which a hidden service directory cannot be queried for the same descriptor ID again, taking TestingTorNetwork into account.
Definition at line 1337 of file hs_common.c.
Referenced by hs_clean_last_hid_serv_requests().
int hs_in_period_between_tp_and_srv | ( | const networkstatus_t * | consensus, |
time_t | now | ||
) |
Return true if we are currently in the time segment between a new time period and a new SRV (in the real network that happens between 12:00 and 00:00 UTC). Here is a diagram showing exactly when this returns true:
+---------------------------------------------------------------—+ | | | 00:00 12:00 00:00 12:00 00:00 12:00 | | SRV#1 TP#1 SRV#2 TP#2 SRV#3 TP#3 | | | | $==========|--------—$===========|--------—$===========| | | ^^^^^^^^^^^^ ^^^^^^^^^^^^ | | | +---------------------------------------------------------------—+
Definition at line 987 of file hs_common.c.
Referenced by build_descriptors_for_new_service().
void hs_inc_rdv_stream_counter | ( | origin_circuit_t * | circ | ) |
For the given origin circuit circ, increment the number of rendezvous stream counter. This handles every hidden service version.
Definition at line 1737 of file hs_common.c.
void hs_init | ( | void | ) |
Initialize the entire HS subsystem. This is called in tor_init() before any torrc options are loaded. Only for >= v3.
Definition at line 1700 of file hs_common.c.
Referenced by tor_init().
time_t hs_lookup_last_hid_serv_request | ( | routerstatus_t * | hs_dir, |
const char * | req_key_str, | ||
time_t | now, | ||
int | set | ||
) |
Look up the last request time to hidden service directory hs_dir for descriptor request key req_key_str which is the blinded key for v3. If set is non-zero, assign the current time now and return that. Otherwise, return the most recent request time, or 0 if no such request has been sent before.
Definition at line 1379 of file hs_common.c.
int hs_parse_address | ( | const char * | address, |
ed25519_public_key_t * | key_out, | ||
uint8_t * | checksum_out, | ||
uint8_t * | version_out | ||
) |
Same has hs_parse_address_no_log() but emits a log warning on parsing failure.
Definition at line 840 of file hs_common.c.
Referenced by hs_address_is_valid(), and hs_service_del_ephemeral().
int hs_parse_address_no_log | ( | const char * | address, |
ed25519_public_key_t * | key_out, | ||
uint8_t * | checksum_out, | ||
uint8_t * | version_out, | ||
const char ** | errmsg | ||
) |
Using a base32 representation of a service address, parse its content into the key_out, checksum_out and version_out. Any out variable can be NULL in case the caller would want only one field. checksum_out MUST at least be 2 bytes long.
Return 0 if parsing went well; return -1 in case of error and if errmsg is non NULL, a human readable string message is set.
Definition at line 800 of file hs_common.c.
Referenced by hs_parse_address().
hs_port_config_t * hs_parse_port_config | ( | const char * | string, |
const char * | sep, | ||
char ** | err_msg_out | ||
) |
Parses a virtual-port to real-port/socket mapping separated by the provided separator and returns a new hs_port_config_t, or NULL and an optional error string on failure.
The format is: VirtualPort SEP (IP|RealPort|IP:RealPort|'socket':path)?
IP defaults to 127.0.0.1; RealPort defaults to VirtualPort.
Definition at line 685 of file hs_common.c.
char * hs_path_from_filename | ( | const char * | directory, |
const char * | filename | ||
) |
Allocate and return a string containing the path to filename in directory. This function will never return NULL. The caller must free this path.
Definition at line 178 of file hs_common.c.
Referenced by get_client_auth_creds_filename(), hs_ob_parse_config_file(), load_client_keys(), load_service_keys(), service_add_fnames_to_list(), and service_key_on_disk().
routerstatus_t * hs_pick_hsdir | ( | smartlist_t * | responsible_dirs, |
const char * | req_key_str, | ||
bool * | is_rate_limited_out | ||
) |
Given the list of responsible HSDirs in responsible_dirs, pick the one that we should use to fetch a descriptor right now. Take into account previous failed attempts at fetching this descriptor from HSDirs using the string identifier req_key_str. We return whether we are rate limited into *is_rate_limited_out if it is not NULL.
Steals ownership of responsible_dirs.
Return the routerstatus of the chosen HSDir if successful, otherwise return NULL if no HSDirs are worth trying right now.
Definition at line 1509 of file hs_common.c.
void hs_port_config_free_ | ( | hs_port_config_t * | p | ) |
Release all storage held in a hs_port_config_t.
Definition at line 787 of file hs_common.c.
void hs_purge_hid_serv_from_last_hid_serv_requests | ( | const char * | req_key_str | ) |
Remove all requests related to the descriptor request key string req_key_str from the history of times of requests to hidden service directories.
This is called from purge_hid_serv_request(), which must be idempotent, so any future changes to this function must leave it idempotent too.
Definition at line 1441 of file hs_common.c.
Referenced by purge_hid_serv_request().
void hs_purge_last_hid_serv_requests | ( | void | ) |
Purge the history of request times to hidden service directories, so that future lookups of an HS descriptor will not fail because we accessed all of the HSDir relays responsible for the descriptor recently.
Definition at line 1481 of file hs_common.c.
Referenced by hs_client_free_all().
int hs_service_requires_uptime_circ | ( | const smartlist_t * | ports | ) |
Return 1 if any virtual port in ports needs a circuit with good uptime. Else return 0.
Definition at line 1016 of file hs_common.c.
Referenced by launch_rendezvous_point_circuit().
int hs_set_conn_addr_port | ( | const smartlist_t * | ports, |
edge_connection_t * | conn | ||
) |
From the given list of hidden service ports, find the ones that match the given edge connection conn, pick one at random and use it to set the connection address. Return 0 on success or -1 if none.
Definition at line 606 of file hs_common.c.
link_specifier_t * link_specifier_dup | ( | const link_specifier_t * | src | ) |
Return a newly allocated link specifier object that is a copy of dst.
Definition at line 1751 of file hs_common.c.