summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | Mark request_retried test as ignoredNick Mathewson2021-10-281-0/+1
| | | |
* | | | move integration tests to scriptsTrinity Pointard2021-10-285-8/+49
|/ / /
* | | Small FAQ update.Nick Mathewson2021-10-271-1/+1
| | |
* | | Add missing entries to Architecture.mdNick Mathewson2021-10-271-0/+5
| | |
* | | Upgrade to fslock version 0.2Nick Mathewson2021-10-275-7/+6
| | | | | | | | | | | | | | | This version makes all locks per-handle rather than per-process, by moving from lockf() to flock() on unix.
* | | Improve and future-proof the `arti` CLIeta2021-10-278-171/+224
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This switches out `arti`'s argument-parsing library with `clap`, which is a lot more featureful (and very widely used within the Rust ecosystem). We also now use a lot of `clap`'s features to improve the CLI experience: - The CLI now expects a subcommand (currently, either "help", or "proxy" for the existing SOCKS proxy behaviour). This should let us add additional non-SOCKS-proxy features to arti in future. - `clap` supports default values determined at runtime, so the way the default config file is loaded was changed: now, we determine the OS-specific path for said file before invoking `clap`, so the help command can show it properly. - The behaviour of `tor_config` was also changed; now, one simply specifies a list of configuration files to load, together with whether they're required. - That function also way overused generics; this has been fixed. - Instead of using the ARTI_LOG environment variable to configure logging, one now uses the `-l, --log-level` CLI option. (The intent is for this option to be more discoverable by users.) - The `proxy` subcommand allows the user to override the SOCKS port used on the CLI without editing the config file.
* | | Update our disclaimers and limitations sections.Nick Mathewson2021-10-2713-92/+38
| | |
* | | Add Futureproof<T> wrapper type, use for GuardDisabled enumeta2021-10-273-7/+77
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The Futureproof<T> type lets you serialize and deserialize types whose representations might change (most useful for enums that might grow additional variants). It uses #[serde(untagged)] to accomplish this. This gets used in order to make the `disabled` field of `Guard` more robust against future guard disablement reasons being added. A test was also added to verify correct behaviour of the new type.
* | | Add #[serde(flatten)] HashMap fields to serializable objectseta2021-10-274-6/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per arti#175, we'd like to be able to handle newer Arti versions storing additional state in the persisted state files, without dropping this data on the floor when we write out changes to these files. Use the #[serde(flatten)] mechanism to achieve this, by adding catch-all HashMap<String, JsonValue> fields to all structs that are at risk of this happening to them.
* | | Fix some clippy-nightly warnings.Nick Mathewson2021-10-264-12/+18
| | | | | | | | | | | | These are my fault; I merged the wrong version of !102. :p
* | | Clarify that new SleepProvider methods are testing-only.Nick Mathewson2021-10-261-0/+9
| | |
* | | circmgr: Split request_timeout test into two.Nick Mathewson2021-10-261-0/+7
| | | | | | | | | | | | | | | | | | | | | There seems to be some issue here with the new WaitFor code, where using the same MockSleepProvider with both of these wait_for() calls gives questionable behavior under some circumstances (like when running under Tarpaulin with the wrong set of flags).
* | | Merge remote-tracking branch 'origin/mr/102'Nick Mathewson2021-10-266-55/+350
|\ \ \
| * | | Overhaul the way WaitFor and the MockSleepProvider worketa2021-10-266-55/+350
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Instead of racily advancing time forward, this commit attempts to rework how WaitFor works, such that it makes advances when all sleeper futures that have been created have been polled (by handing the MockSleepRuntime a Waker with which to wake up the WaitFor). The above described mechanics work well enough for the double timeout test, but fail in the presence of code that spawns asynchronous / background tasks that must make progress before time is advanced for the test to work properly. In order to deal with these cases, a set of APIs are introduced in order to block time from being advanced until some code has run, and a carveout added in order to permit small advances in time where required. (In some cases, code needed to be hacked up a bit in order to be made properly testable using these APIs; the `MockablePlan` trait included in here is somewhat unfortunate.) This should fix arti#149.
* | | | Merge branch 'pb_lite_squashed'Nick Mathewson2021-10-265-11/+236
|\ \ \ \
| * | | | Avoid a strange borrow syntax in tor_guardmgr::sampleNick Mathewson2021-10-261-3/+3
| | | | | | | | | | | | | | | | | | | | I'm not sure what I was thinking here.
| * | | | Do not blame a guard for failures on non-random circuits.Nick Mathewson2021-10-262-4/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We must not apply our new path-bias behavior (where we blame a guard if it gives us too many indeterminate circuit failures) if the path was not chosen at random. If too many random paths fail, we know that's suspicious, since the other relays are a random sample. But if a bunch of user-provided paths fail, that could simply be because the user's chosen exit is down.
| * | | | Implement a "lightweight" form of pathbias detection.Nick Mathewson2021-10-263-5/+193
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We now track, for every guard: the total number of successful circuits we've built through it, along with the total number of "indeterminate" circuits. Recall that a circuit's status is "indeterminate" if it has failed for a reason that _might_ be the guard's fault, or might not be the guard's fault. For example, if extending to the second hop of the circuit fails, we have no way to know whether the guard deliberately refused to connect there, or whether the second hop is just offline. But we don't want to forgive all indeterminate circuit failures: if we did, then a malicious guard could simply reject any second hops that it didn't like, thereby filtering the client into a chosen set of circuits. As a stopgap solution, this patch now makes guards become permanently disabled if the fraction of their circuit failures becomes too high. See also general-purpose path bias selection (arti#65), and Mike's idea for changing the guard reachability definition (torspec#67). This patch doesn't do either of those. Closes #185.
* | | | | Tests and refactoring for IsolationMap.Nick Mathewson2021-10-261-13/+50
| | | | |
* | | | | TorClient::resolve_ptr should take an IpAddr.Nick Mathewson2021-10-263-10/+14
| | | | |
* | | | | More tests for arti_client::addressNick Mathewson2021-10-261-15/+106
| | | | |
* | | | | Merge branch 'isolate_clients'Nick Mathewson2021-10-263-55/+134
|\ \ \ \ \
| * | | | | Turn StreamIsolation into a separate type.Nick Mathewson2021-10-253-43/+103
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now that we have two kinds of isolation tokens (those set on a stream, and those set by the stream's associated TorClient), we need a more sophisticated kind of isolation. This fixes the bug introduced with the previous commit, where per-stream tokens would override per-TorClient tokens.
| * | | | | Add an isolate_client() function to create an isolated TorClient.Nick Mathewson2021-10-251-15/+34
| |/ / / / | | | | | | | | | | | | | | | | | | | | When two TorClients are isolated, their streams shouldn't share circuits, even though they share internal circuit and guard state.
* | | | | Upgrade curve25519-dalek requirement to 3.2.0Nick Mathewson2021-10-251-1/+1
| | | | | | | | | | | | | | | | | | | | We need this now that we check for contributory behavior.
* | | | | Fix typos and cleanupDimitris Apostolou2021-10-255-9/+9
|/ / / /
* | | | guardmgr: Don't use guards that are marked as unlisted.Nick Mathewson2021-10-252-7/+22
| | | | | | | | | | | | | | | | Closes #202.
* | | | s/arti-arti-client/arti-client/ and regenerate readme filesNick Mathewson2021-10-255-6/+6
| | | |
* | | | Fix a typo in a comment.Nick Mathewson2021-10-251-1/+1
| | | |
* | | | Remove chrono exception from cargo_audit.shNick Mathewson2021-10-241-13/+17
| | | |
* | | | Migrate tor-dirmgr from chrono to time 0.3Nick Mathewson2021-10-244-64/+44
| | | | | | | | | | | | | | | | | | | | (This appears to be the emerging consensus of how to handle RUSTSEC-2020-0159.)
* | | | Migrate tor-netdoc from chrono to time 0.3Nick Mathewson2021-10-243-6/+9
| | | | | | | | | | | | | | | | | | | | (This appears to be the emerging consensus of how to handle RUSTSEC-2020-0159.)
* | | | Upgrade to latest tracing-{subscriber,journald}Nick Mathewson2021-10-233-23/+9
| | | |
* | | | Upgrade to new version of simple_asn1.Nick Mathewson2021-10-222-5/+32
| | | |
* | | | Run "cargo fix --edition-idioms=2018".Nick Mathewson2021-10-224-5/+5
| |_|/ |/| |
* | | Replace references to arti-client in the documentation.Nick Mathewson2021-10-218-11/+11
| | |
* | | Rename tor_client/arti_tor_client to arti_client.Nick Mathewson2021-10-2116-36/+28
| | | | | | | | | | | | | | | | | | Solves a name conflict with the existing tor_client create. Closes #130.
* | | Remove #![allow(clippy::unnecessary_wraps)] in tor-proto.Nick Mathewson2021-10-211-1/+0
| | |
* | | Remove #![allow(unreachable_pub)] in shared_ref.rsNick Mathewson2021-10-211-7/+5
| | |
* | | Remove #![allow(clippy::unwrap_used)] in cmdline.rsNick Mathewson2021-10-211-1/+0
| | |
* | | Remove #![allow_unused] in tor_chanmgr::mgrNick Mathewson2021-10-212-1/+4
| | |
* | | Remove #![allow(dead_code)] in timeouts.rsNick Mathewson2021-10-212-2/+3
| | |
* | | Merge branch 'share_state'Nick Mathewson2021-10-2120-330/+718
|\ \ \
| * | | Implement the guard side of shared state directories.Nick Mathewson2021-10-214-3/+51
| | | |
| * | | Mark consensus as "not-pending" even if its microdescs come from cache.Nick Mathewson2021-10-203-8/+48
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously our code would clear the 'pending' flag on a consensus only when a _downloaded_ md made it become usable. Closes #199.
| * | | Move tor-dirmgr to use a sync::Mutex.Nick Mathewson2021-10-203-45/+36
| | | | | | | | | | | | | | | | | | | | The futures::lock::Mutex was unnecessary, since we never held it when we were suspending.
| * | | Finish the timeout-inference side of shared state.Nick Mathewson2021-10-204-32/+113
| | | |
| * | | Add a timeout estimator to take estimates from another process.Nick Mathewson2021-10-204-42/+93
| | | |
| * | | Allow type of timeout estimator to change at runtime.Nick Mathewson2021-10-205-201/+298
| | | | | | | | | | | | | | | | | | | | | | | | This is a big change, but it does simplify the type of Builder a little, and isolates locking across different (potential) timeout estimator types.
| * | | Remove try_lock from StorageHandle.Nick Mathewson2021-10-202-8/+2
| | | |