summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* Revise TODO and README; declare "milestone 2" done.Nick Mathewson2020-10-132-24/+24
| | | | | | Part of this "declaring milestone 2 done" business is a matter of putting additional tests and documentation into milestone 3 where they logically belong.
* Revise DropMark defense to use a better type and match Tor's behavior.Nick Mathewson2020-10-136-14/+99
|
* Document all private members in tor-protoNick Mathewson2020-10-1315-10/+133
|
* Make sure that protocol errors terminate the circuit responsible.Nick Mathewson2020-10-133-23/+59
|
* Improve handling of circuit closure or failure on reactor shutdown.Nick Mathewson2020-10-133-6/+37
| | | | | | | | | | We already handled the case okay when we were reading on streams, since the reactor's going away would drop the sender side of their mpsc channels. But if the reactor went away, nothing would tell _writing_ streams that they needed to close. Now we handle that case, as well as anybody who is waiting on a meta-cell to get back to them.
* Another tweak to handling closing streamsNick Mathewson2020-10-133-14/+40
| | | | | | When a stream is closed and we haven't adjusted its state in the stream map yet, remember how many cells we've dropped so we can decrement them from the window later on.
* Try giving distinct handling to streams where END has been sentNick Mathewson2020-10-126-54/+118
| | | | | | This is the first step along the line to handling Tor issue tor#27557. We want to remember streams that we've ended and treat them as distinct from streams that have never existed
* Tweak terminate hand handle_close() functions.Nick Mathewson2020-10-112-13/+20
| | | | | These need to become functions about terminating and noticing a termination request.
* Rename StreamMap::Closing to EndReceivedNick Mathewson2020-10-111-4/+4
| | | | This is in preparation for adding a different EndSent stream state.
* Test the pick_weighted function in tor-netdirNick Mathewson2020-10-101-0/+128
|
* Document remaining private members of tor-netdoc.Nick Mathewson2020-10-106-9/+259
|
* Document most private items in tor-netdoc.Nick Mathewson2020-10-0911-9/+115
|
* Document all the private items in tor-cellNick Mathewson2020-10-096-7/+97
| | | | | Also, change the type of the authentication challenge to be an array; it isn't in fact variable-length.
* Remove a couple of allow(unused) notationsNick Mathewson2020-10-092-2/+0
|
* mark off a TODO item.Nick Mathewson2020-10-091-1/+1
|
* Fix a pair of bugs in SENDME handling.Nick Mathewson2020-10-091-13/+10
| | | | | | | | | The problem is that we would count begin and end cells towards towards window totals when we are only supposed to count DATA cells, *and* that we would we send our sendmes one cell too early (or maybe late?). Closes #1.
* Move counts_towards_windows() code into circuit moduleNick Mathewson2020-10-096-19/+19
|
* client-main: Add an option to run a test more than onceNick Mathewson2020-10-092-6/+12
|
* add point estimates to TODONick Mathewson2020-10-091-37/+45
|
* check off the deadlock in the todo.Nick Mathewson2020-10-091-1/+1
|
* Split information about circuit hops into inbound and outbound.Nick Mathewson2020-10-092-61/+172
| | | | | | | | | | | | | | | | | | Previously the circuit object owned not only the outbound crypto, but also the inbound crypto and the stream maps. That's not so great, since the reactor needs to use the inbound crypto and the stream maps all the time, whereas the circuit doesn't need them much (or at all). Moving these objects to the reactor-owned structure should let us fix the deadlock case in stream sendme handling, since the circuit reactor no longer needs to lock the circuit in order to do crypto and demultiplexing. It should also speed up the code a bit, since it doesn't need to grab the circuit lock nearly so often as before. This change forced me to add a couple of new reactor CtrlMsg values, since the circuit can no longer add streams and layers directly. I think it will still be a performance win, though.
* Split client relay crypto into separate directionsNick Mathewson2020-10-093-77/+179
| | | | | I think we should have the reactor task own the reverse crypto and the circuit own the forward crypto.
* client-demo:Be louder on reactor failure.Nick Mathewson2020-10-091-1/+4
|
* Fix counting rules for circuit-level sendmes.Nick Mathewson2020-10-091-4/+4
|
* Logic error: negate test for sendme cells in counts_towards_windowsNick Mathewson2020-10-091-1/+1
|
* Expose --flood and --dl switches on client-demoNick Mathewson2020-10-091-4/+22
| | | | These are for testing sendmes.
* Add routerdesc examplesNick Mathewson2020-10-077-0/+343
|
* netdoc: more tests for routerdesc parsingNick Mathewson2020-10-072-5/+107
|
* A few more tests in tor-netdocNick Mathewson2020-10-072-3/+90
|
* netdoc: test for signature/key checking funcNick Mathewson2020-10-071-0/+11
|
* mdconsensus: add tests for a few accessorsNick Mathewson2020-10-061-3/+26
|
* tests for some failing cases in mdconsensusNick Mathewson2020-10-0612-7/+781
|
* Tokenize: report accurate positions for more parsing errorsNick Mathewson2020-10-021-2/+18
|
* microdesc parsing: tests for bad microdescsNick Mathewson2020-10-023-0/+66
|
* tests and fixes for md content parsingNick Mathewson2020-10-022-11/+46
|
* Make rsa::PublicKey derive Debug.Nick Mathewson2020-10-021-1/+1
|
* Remove an unwrap() from tor-cert.Nick Mathewson2020-10-021-6/+6
|
* Use batch verification in client<->relay handshake.Nick Mathewson2020-10-022-7/+20
|
* Enable batch ed25519 verification.Nick Mathewson2020-10-024-3/+62
|
* netdoc: remove some outdated/unused stuff.Nick Mathewson2020-10-022-12/+6
|
* authcert: test error recovery.Nick Mathewson2020-10-021-10/+36
|
* Netdoc: use a more bulletproof pattern to prevent infinite loopsNick Mathewson2020-10-025-15/+84
| | | | | | | | | | | | | | | | Previously our "read a bunch of this kind of document" functions had a common problem, where they could get into an infinite loop if the underlying "read this kind of document" function failed without consuming any tokens. I _think_ that this error case was unreachable (or else fuzzing would have found it, right?), but proving that it was unreachable was a bit fiddly, and I couldn't follow my own arguments about it. Instead, we just store the position of the reader before we start reading, and make sure that it has consumed at least some data. If it hasn't, then we consume and drop a token before advancing to the next document.
* authcert: add tests for several ways certs can fail.Nick Mathewson2020-10-026-1/+263
|
* authcert: fix an error, and detect mismatched fingerprintsNick Mathewson2020-10-021-4/+14
|
* netdoc: rename BadVersion to BadTorVersion for clarityNick Mathewson2020-10-012-7/+7
|
* improve errors in authcert.rsNick Mathewson2020-10-012-12/+30
|
* Remove redundant signature check in authcert parsing.Nick Mathewson2020-09-301-4/+0
|
* More tests on parsing, plus remove dead code.Nick Mathewson2020-09-302-20/+56
|
* Start on some parser backend testsNick Mathewson2020-09-301-0/+77
|
* tokenize: accept base64 with funny linewraps.Nick Mathewson2020-09-301-3/+3
|