| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | |
|
| |/ / / |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tor-circmgr: Remove HsPool::vanguards_enabled().
Closes #1456 and #1458
See merge request tpo/core/arti!2183
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Previously, the HsCircPool had a bug that caused SHORT lite-vanguards
circuits to be incorrectly extended by one hop when being repurposed as
EXTENDED circuits (EXTENDED circuits only need to be extended by extra
hop if full vanguards are in use).
Closes #1456 and #1458
|
| |/ / / |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tor-circmgr: Exclude the circ target when building paths.
Closes #1425
See merge request tpo/core/arti!2179
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
We now return an internal error if the path we've just built contains
the same hop in multiple positions.
|
| | | | |
| | | |
| | | |
| | | | |
Closes #1425
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
tor-circmgr: Ensure circuit stubs are compatible with the target.
See merge request tpo/core/arti!2181
|
| | | | |
| | | |
| | | |
| | | | |
target.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
When checking for relay equality, we are happy to accept some false
positives (which result in building/selecting a different circuit). We
want to be less tolerant of false negatives, to avoid accidentally using
a circuit that doesn't have the properties we need.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is a follow-up from !2167.
It should prevent issues like #1417 from going unnoticed.
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
tor-config: Move macro above ExplicitOrAuto definition.
See merge request tpo/core/arti!2180
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | | |
The macro needs to be defined before `ExplicitOrAuto`, otherwise we
can't reference it in its docs.
Fixes the broken doc links.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tor-circmgr: Fix vanguard configuration error
Closes #1424
See merge request tpo/core/arti!2168
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
If the circmgr retires all of its circuits, so should the HS circ pool.
The circuits can be retired for various reasons (for example, if the
configured vanguard mode changes).
|
| | | | |
| | | |
| | | |
| | | | |
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2168?commit_id=3c67fa55c7c5b0c4f30c1d57e8e67fe541d9c99e#note_3033368
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Storing the VanguardMode in multiple places (in the VanguardMgr *and*
the HS circ Pool) is dangerous and can lead to split brain situations
where different parts of the code think they are running in different
VanguardModes.
See #1424
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
`VanguardMgr` should be the source of truth for obtaining the current
`VanguardMode`.
Closes #1424
|
| |/ / /
| | |
| | |
| | | |
See arti#1424
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Upgrade and update packages for upcoming release
See merge request tpo/core/arti!2177
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | |
| | | |
| | | | |
tor-guardmgr: Add more tests for vanguards
Closes #1417 and #1408
See merge request tpo/core/arti!2167
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
We don't need this now that #1417 is fixed.
This reverts commit a9010f6300c25e4602ecf8017ca176c724ecdfa5.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Previously, HS stub circuit selection (with vanguards enabled) was
buggy: when selecting a circuit stub from the circ pool, we failed to
ensure its last hop was different from the circuit target. So in some
cases, arti would attempt to extend a stub circuit of the form G -> L2
[-> L3] -> T to T, which can't work, because a relay won't extend a
circuit to itself (or to its predecessor, for that matter).
Closes #1417
|
| | | | |
| | | |
| | | |
| | | | |
This will soon grow more complex.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Without this change, one of the tgen processes doesn't exit as expected:
```
618990:00:06:50.991981 [4717:shadow-worker] 00:30:00.000000000 [ERROR] [torclient-onion-artiserver:11.0.0.19] [process.rs:1525] [shadow_rs::host::process] process 'torclient-onion-artiserver.tgen.1001' exited with status StoppedByShadow; expected end state was exited: 0 but was running
```
This is because of a stub circuit selection bug that only manifests when
the `torclient-onion-artiserver` and
`torclient-onion-artiserver-full-vanguards` tests are run at the same
time.
See #1417 for more details.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This adds an onion service that uses full vanguards, and a client
that connects to it.
Closes #1408
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
Moving them to a separate variable makes the script more readable as we
add more hosts.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Previously, we'd `debug_assert` that the length of the path is valid.
However, `debug_` asserts are compiled out for release builds, which
means that if we have some code path that triggers the assertion
failure, it will go unnoticed unless our tests happen to exercise it.
It's safer to return an internal error, because we definitely don't want
to proceed if the path is too short (see arti#1400 and arti#1409).
Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2154#note_3030820
|
| |/ / /
| | |
| | |
| | | |
This checks that we can read `vanguards.json` state files.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
arti: Add vanguards settings to example config.
See merge request tpo/core/arti!2146
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
We are about to need this in other crates (for generating the tests for
the `NotAutoValue` implementations).
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is a safeguard to prevent users from using ExplicitOrAuto with
types that serialize to the same value as ExplicitOrAuto::Auto.
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2146#note_3030692
|
| | | | | |
|
| | | | | |
|