summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | Merge branch 'reachable_addrs_v2' into 'main'Nick Mathewson2022-06-1715-154/+543
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement support for reachable_addrs Closes #491 and #93 See merge request tpo/core/arti!583
| * | | | Rename guardset-selection function.Nick Mathewson2022-06-171-2/+7
| | | | | | | | | | | | | | | | | | | | Also, improve its documentation.
| * | | | Rename pick_guard, pick_guard_ext.Nick Mathewson2022-06-172-17/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now the primary exposed function is `pick_guard` again. This commit is just function renaming.
| * | | | Refactor and document issues with modify_hop.Nick Mathewson2022-06-173-14/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | At the site of modify_hop, we now have a comment explaining the internal-error issue. To make the internal error less likely, we lower the modify_hop call in lib.rs into GuardSet, where it can make sure it's looking at the same filter as was used to select the guard. The function name "pick_guard_ext" is not permanent; I'm going to rename it in the next commit.
| * | | | API-fix for extend_sample_as_needed.Nick Mathewson2022-06-172-19/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the API said "you need to call this in a loop till it returns false". We did that in one place, but not another. With the introduction of filters, forgetting to loop here becomes a bug: so instead, change the behavior of extend_sample_as_needed so it handles looping itself.
| * | | | Remove some outdated comments.Nick Mathewson2022-06-174-19/+1
| | | | | | | | | | | | | | | | | | | | | | | | | These all say, in one form or another, "there is no guard filtering; there is only one selection". That's now false.
| * | | | Tweak parameters in guardmgr tests to improve testnet behavior.Nick Mathewson2022-06-171-9/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The fake network we construct for these tests is small in ways that can sometimes cause weird behavior with guard filters. We fix this by adjusting the parameters of the guard selection algorithm accordingly in the tests. With these new parameters, #491 no longer occurs. This commit also adds comments to explain why the parameters are set as they are. Closes #491.
| * | | | CircMgr: Enable reachable_addrs filter.Nick Mathewson2022-06-172-1/+21
| | | | |
| * | | | Add a configuration option for reachable_addrsNick Mathewson2022-06-173-0/+46
| | | | | | | | | | | | | | | | | | | | (This doesn't do anything yet.)
| * | | | NetDoc: Make AddrPortPattern implement serde traitsNick Mathewson2022-06-174-6/+96
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I'm using serde_with here to just re-use the Display and FromStr implementations, since those are what has proven easier to type in the past.
| * | | | GuardMgr: Support for multiple guard setsNick Mathewson2022-06-172-33/+98
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | guard-spec.txt specifies that we have multiple separate samples of guards that we can use depending on whether the filter is restrictive or not. Here we implement the rules for switching between samples.
| * | | | Move set_filter into GuardMgrInner.Nick Mathewson2022-06-173-41/+34
| | | | | | | | | | | | | | | | | | | | | | | | | Convert its argument type to Option<&NetDir> to better match the rest of the API.
| * | | | GuardMgr: Function to tell how permissive a filter is.Nick Mathewson2022-06-171-0/+50
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When we're filtering guards, we have to check whether the filter is "restrictive": if it forbids most of the guards (by bandwidth), we keep its guards separated from the main set. If it is super-restrictive, we also warn. This functionality is specified in guard-spec.txt.
| * | | | Make AddrPortPattern and friends implement Eq and PartialEqNick Mathewson2022-06-172-2/+3
| | | | |
| * | | | GuardMgr: Also apply filters to fallback directories.Nick Mathewson2022-06-172-7/+12
| | | | |
| * | | | GuardMgr: remove disallowed addresses from returned FirstHops.Nick Mathewson2022-06-174-2/+54
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Since a guard can have a bunch of addresses, and the guard is permitted if any one of those addresses is permitted, then we might decide to use a guard with some non-permitted addresses. Thus, we need to filter those addresses before returning the view of the guard as a FirstHop.
| * | | | GuardMgr: Remove old testing filter variant.Nick Mathewson2022-06-172-21/+9
| | | | | | | | | | | | | | | | | | | | | | | | | We don't need to restrict based on bits in the key id any longer, since we have a real filter.
| * | | | GuardMgr: Add a new filter type based on reachable addresses.Nick Mathewson2022-06-172-8/+24
| | | | |
| * | | | Guardmgr: Change the GuardFilter API.Nick Mathewson2022-06-173-19/+46
| | | | | | | | | | | | | | | | | | | | | | | | | The guard filter is now a set of restrictions that can be placed on allowable guards.
* | | | | Merge branch 'config-fix2' into 'main'Nick Mathewson2022-06-169-104/+77
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Use impl_standard_builder more and remove manual Default/builder impls See merge request tpo/core/arti!594
| * | | | | tor-proto: channel: Tell clippy it's ok to print in testsIan Jackson2022-06-161-0/+1
| | | | | |
| * | | | | impl_standard_builder: Use for tor_dirmgr::AuthorityIan Jackson2022-06-161-10/+2
| | | | | |
| * | | | | impl_standard_builder: Use for tor_guardmgr::FallbackDirIan Jackson2022-06-161-6/+3
| | | | | |
| * | | | | impl_standard_builder: Use for tor_dirmgr::DownloadScheduleIan Jackson2022-06-161-14/+3
| | | | | |
| * | | | | impl_standard_builder: Use for arti::logging::LogfileConfigIan Jackson2022-06-161-7/+2
| | | | | |
| * | | | | impl_standard_builder: Allow for !DefaultIan Jackson2022-06-161-13/+54
| | | | | |
| * | | | | arti: logging config: Replace a manual Debug implIan Jackson2022-06-163-7/+6
| | | | | |
| * | | | | impl_standard_builder: Use for tor_dirmgr::DownloadScheduleConfigIan Jackson2022-06-161-14/+1
| | | | | |
| * | | | | impl_standard_builder: Use for tor_dirmgr::NetworkConfigIan Jackson2022-06-161-19/+2
| | | | | |
| * | | | | impl_standard_builder: Use for tor_dirmgr::DirSkewToleranceIan Jackson2022-06-161-13/+2
| | | | | |
| * | | | | tor-config: impl_standard_builder: handle contexts with local ResultIan Jackson2022-06-161-1/+1
| | | | | |
* | | | | | Merge branch 'upgrade_float_eq' into 'main'Ian Jackson2022-06-162-11/+5
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Upgrade to float_eq 1.0.0 See merge request tpo/core/arti!591
| * | | | | | Upgrade to float_eq 1.0.0Nick Mathewson2022-06-162-11/+5
| | |_|/ / / | |/| | | |
* | | | | | Merge branch 'config-fix' into 'main'Ian Jackson2022-06-164-49/+92
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Config handling and logging fixes Closes #480 See merge request tpo/core/arti!589
| * | | | | | arti: cfg: Remove another needless borrowIan Jackson2022-06-161-1/+1
| | | | | | |
| * | | | | | arti cfg tests: Remove a redundant line that shadows an earlier bindingIan Jackson2022-06-161-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by review https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/589#note_2813596
| * | | | | | Fix grammar erroreta2022-06-161-1/+1
| | | | | | |
| * | | | | | arti: Enable some pre-config loggingIan Jackson2022-06-161-2/+16
| | | | | | |
| * | | | | | arti: Introduce closure which will be used for pre-config loggingIan Jackson2022-06-161-31/+52
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Right now this is an IEFI and therefore a no-op.
| * | | | | | arti cfg tests: Test that example config works as-isIan Jackson2022-06-161-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | It contains only sections, but we want to detect when that is a problem!
| * | | | | | arti: cfg tests: Refactor to prepare for new testIan Jackson2022-06-161-16/+23
| | |/ / / / | |/| | | | | | | | | | | | | | | | We're going to call this new closure another time.
| * | | | | Add some missing `serde(default)` to uses of humantime_serde::optionIan Jackson2022-06-162-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Without this, if the substructure is provided, these fields are mandatory within it.
* | | | | | Merge branch 'accel-features' into 'main'Nick Mathewson2022-06-167-42/+98
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Top-level (arti and arti-client) features to enable crypto acceleration Closes #441 See merge request tpo/core/arti!590
| * | | | | Merge branch 'main' into 'accel-features'Nick Mathewson2022-06-1630-158/+272
| |\ \ \ \ \ | | | |/ / / | | |/| | | | | | | | | # Conflicts: # crates/arti-client/Cargo.toml
| * | | | | Add "accel-*" features to arti-client and arti.Nick Mathewson2022-06-135-2/+47
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These need to be optional: they improve performance by shifting to asm implementations, which may not be everybody's idea of good practice. These are not 'pure' features, since they select one implementation but disable another. Therefore they don't go in `full`. Closes #441.
| * | | | | Add a feature to tor-llcrypto to enable sha-1/asm.Nick Mathewson2022-06-133-41/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | SHA1 is a reasonably large part of our CPU usage (sigh), and this implementation is 20-50% faster, depending on arch.
* | | | | | gitlab-ci: Use lowercase tpa tag.Nick Mathewson2022-06-161-1/+1
| |/ / / / |/| | | | | | | | | | | | | | Our gitlab admins are standardizing on this variant.
* | | | | Merge branch 'high-level-features' into 'main'Nick Mathewson2022-06-1613-86/+168
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add "full" and "experimental" features to arti, arti-client, and below. Closes #499 See merge request tpo/core/arti!584
| * | | | | Remove "rustls" from "full", for license reasons.Nick Mathewson2022-06-154-5/+13
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Rustls uses ring, which uses code from BoringSSL, which derived from OpenSSL before OpenSSL changed their license. So ring is currently under 3BSD/SSLEay licenses, which aren't GPL-compatible, which may be a problem for some people. See #493.
| * | | | Document "full", "experimental" in toplevel crate documentation.Nick Mathewson2022-06-132-82/+121
| | | | | | | | | | | | | | | | | | | | | | | | | Also, unify the features documentation format for those two crates, and document previously undocumented features there.