summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | tor-rtcompat: Explain Sendness of reenter_block_on futureIan Jackson2025-03-042-0/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167975 Also allow ourselves the option of changing this in the future.
| * | | | tor-rtcompat: Clarify distinction between Runtime and ToplevelIan Jackson2025-03-041-2/+8
| | | | | | | | | | | | | | | | | | | | | | | | | Prompted by and partially taken from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167973
| * | | | tor-rtcompat: Linkify a mention of spawn_threadIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167972
| * | | | tor-rtcompat: Clarify docs (3)Ian Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167970
| * | | | tor-rtcompat: Make a precise example for mpsc::channelIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167969
| * | | | tor-rtcompat: Blocking::spawn_thread semantics correctionIan Jackson2025-03-041-2/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The: table entry for `spawn_thread` was wrong. We use AsyncExecutors' spawn_blocking which uses tokio::task::spawn_blocking. This has implications for the semantics, as per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167967 https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167968
| * | | | tor-rtcompat: Clarify docs (2)Ian Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167966
| * | | | tor-rtcompat: Clarify docsIan Jackson2025-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | As suggested https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2810#note_3167965
| * | | | tor-rtcompat: Add a semver.md for changes to BlockOn etc.Ian Jackson2025-03-041-0/+4
| | | | |
| * | | | tor-rtmocK; Detect wrong-context blocking_io and spawn_threadIan Jackson2025-03-044-2/+21
| | | | |
| * | | | tor-rtmock: Split out spawn_thread_innerIan Jackson2025-03-041-5/+16
| | | | | | | | | | | | | | | | | | | | | | | | | This will let us call _inner from blocking_io, with a different precondition. No functional change.
| * | | | tor-rtmocK; Detect re-entry into MockExecutorIan Jackson2025-03-042-7/+29
| | | | |
| * | | | tor-rtmock: task: Remove Default impl for ThreadDescriptorIan Jackson2025-03-0423-25/+26
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is going to become a hazard. Let's be explicit. This means using educe to derive the Default for Data. We also need to update our educe dependency to 0.4.22, since that's when Default(expression= "...") started working correctly.
| * | | | tor-rtmock: Split out executor_main_loopIan Jackson2025-03-041-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | execute_until_first_stall is now simply a wrapper which does some logging. It will do a bit more in a moment. Giving the inner function a more obvious name is helpful, since the executor main loop is a thing one is often looking for.
| * | | | tor-rt*: Apply deferred formatting churnIan Jackson2025-03-046-10/+11
| | | | | | | | | | | | | | | | | | | | rustfmt.
| * | | | tor-rtcompat: CompoundRuntime: Rename TaskR member from SpawnRIan Jackson2025-03-041-40/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This member is the principal one which implemnets Spawn, Blocking and perhaps ToplevelBlockOn. It doesn't appear that we actually need to split this into multiple members.
| * | | | tor-rtcompat: Remove ToplevelBlockon from RuntimeIan Jackson2025-03-049-23/+36
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Introduce ToplevelRuntime as an alias, and use it in the top-level programs. Now none of the principal protocol implementation code has access to the executor's toplevel entrypoint, and can't call it by mistake.
| * | | | tor-rtcompat: Provide Blocking::blocking_ioIan Jackson2025-03-043-2/+70
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was referenced and explained from the docs, but didn't exist yet. Here it is. Everyone except the Tokio glue, and the CompoundRuntime, just use the default implementation in terms of spawn_thread. spawn_thread has a more relaxed contract, so this is correct.
| * | | | tor-rtcompat: Provide a new function for executor re-entryIan Jackson2025-03-048-5/+92
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Forbid re-entering the executor using ToplevelBlockOn::block_on. This was always forbidden in the case of MockExecutor, but that meant that tests using MockExecutor would malfunction if the code under test needed to re-enter the executor from sync code (since the code under test would have to use block_on, which wrong). See #1835. Provide a function which *can* do this, reenter_block_on. The MockExecutor needs to know the difference, and other runtimes may too. They are conceptually quite different operations. Introduce ToplevelRuntime as a convenience alias.
| * | | | tor-rtcompat: New plan for blocking interaction, Blocking traitIan Jackson2025-03-048-47/+140
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Document the new plan for blocking interaction in the trait-level docs for the Blocking trait (used to be SpawnBlocking). Add cross-references (in some cases to not-yet-existing pieces). * Rename: spawn_blocking to spawn_thread. We're going to distinguish thread-creation (relatively expensive) from brief entry to sync code (relatively cheap, but more restricted). * Rename the SpawnBlocking trait to Blocking, and its ThreadHandle to ThreadHandle. This trait is going to gain more functionality. * Add the missing mention of `Blocking` to the docs for `Runtime`.
| * | | | tor-rtcompat: Rename BlockOn to ToplevelBlockOnIan Jackson2025-03-0416-29/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We're going to distinguish top-level runtime entry, from *re*-entry to an existing executor. It is most convenient to rename this trait first. Documentation of the distinction will come later. (We're going to retain the function name `block_on`, but we want the trait to be more obviously a top-level only thing, though, so we give it a name that will hopefully avoid it peroulating throughout the codebase..)
| * | | | tor-rtmock: Correct a commentIan Jackson2025-03-041-1/+1
|/ / / / | | | | | | | | | | | | The MockExecutor doesn't have a threadpool.
* | | | Merge branch 'dev/cve/hsdir_debug' into 'main'Alexander Hansen Færøy2025-03-041-1/+2
|\ \ \ \ | |/ / / |/| | | | | | | | | | | hsclient: Include rsa_id in debug See merge request tpo/core/arti!2833
| * | | hsclient: Include rsa_id in debugClara Engler2025-03-041-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the RSA ID of a relay into a debug statement, as found in other places in the code. It mostly serves the purpose that the Ed25519 ID in itself is rather inconvenient, as metrics.torproject.org only allows querying from the RSA ID.
* | | | Merge branch 'release-md-update' into 'main'opara2025-03-041-1/+13
|\ \ \ \ | |/ / / |/| | | | | | | | | | | Release.md: Small fixes from past release See merge request tpo/core/arti!2832
| * | | Release.md: Fix a number.Nick Mathewson2025-03-041-1/+1
| | | | | | | | | | | | | | | | (There were two "step fours" in this list.)
| * | | Release.md: Mention reasons _not_ to upgrade deps.Nick Mathewson2025-03-041-0/+8
| | | |
| * | | Release.md: Mention format_md_links in a sensible place.Nick Mathewson2025-03-041-0/+4
|/ / /
* | | Merge branch 'ctrl-cmd-docs' into 'main'David Goulet2025-03-031-6/+5
|\ \ \ | | | | | | | | | | | | | | | | tor-proto: Update CtrlCmd and CtrlMsg docs. See merge request tpo/core/arti!2829
| * | | tor-proto: Update CtrlCmd and CtrlMsg docs.Gabriela Moldovan2025-03-031-6/+5
| | | | | | | | | | | | | | | | | | | | | | | | In aa08ede11fd483cd6dcb4522c431f9e07001717e, the reactor loop was rewritten to unconditionally read from the `CtrlMsg` channel, so we need to adjust the docs.
* | | | Merge branch 'conflux-cmds' into 'main'David Goulet2025-03-033-13/+73
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Add CtrlCmd:ShutdownAndReturnCircuit Closes #1876 See merge request tpo/core/arti!2831
| * | | | tor-proto: Add CtrlCmd::ShutdownAndReturn circuit.Gabriela Moldovan2025-03-031-0/+18
| | | | | | | | | | | | | | | | | | | | Closes #1876
| * | | | tor-proto: Add ConfluxSet method for taking the only leg in the set.Gabriela Moldovan2025-03-032-0/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will be used to implement the new `ShutdownAndReturnCircuit` control command. Part of #1876
| * | | | tor-proto: Use bad_api_usage! instead of internal! where applicable (fmt).Gabriela Moldovan2025-03-031-2/+6
| | | | |
| * | | | tor-proto: Use bad_api_usage! instead of internal! where applicable.Gabriela Moldovan2025-03-031-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | Some of these were supposed to be `bad_api_usage`, because they result from API misuse rather than an internal error (bug).
| * | | | tor-proto: Factor out conflux set length check to new function (fmt).Gabriela Moldovan2025-03-031-6/+6
| | | | |
| * | | | tor-proto: Factor out conflux set length check to new function.Gabriela Moldovan2025-03-031-3/+13
| | | | | | | | | | | | | | | | | | | | | | | | | This will enable us to reuse these checks for implementing other methods that are only supported if the conflux set has a single leg.
| * | | | tor-proto: Use handle_shutdown() when handling CtrlCmd::Shutdown.Gabriela Moldovan2025-03-031-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | For consistency with the `CtrlCmd::Shutdown` handling from `Reactor::wait_for_create` (`handle_shutdown()` also prints a helpful trace log).
* | | | | Merge branch 'rm-tor-congestion' into 'main'Nick Mathewson2025-03-038-35/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-congestion: remove crate See merge request tpo/core/arti!2828
| * | | | | tor-congestion: remove crateSteven Engler2025-03-038-35/+1
| | | | | |
* | | | | | Merge branch 'rm-arc-mutex' into 'main'gabi-2502025-03-032-27/+3
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | tor-proto: Remove `Arc<AsyncMutex<_>>` in `Circuit::input` See merge request tpo/core/arti!2830
| * | | | | tor-proto: remove `Arc<AsyncMutex<_>>` in `Circuit::input`Steven Engler2025-03-032-27/+3
| | |/ / / | |/| | |
* | | | | Merge branch 'ci-dependency-proxy' into 'main'wesleyac2025-03-031-10/+19
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | CI: use Dependency Proxy when available See merge request tpo/core/arti!2797
| * | | | CI: use Dependency Proxy when availableJérôme Charaoui2025-02-191-10/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This sets up CI to allow the use of the GitLab Dependency Proxy which caches images pulled from DockerHub, in order to bypass rate-limiting. The DOCKER_REGISTRY_URL variable is set dynamically by the check_dependency_proxy_access job defined in dependency_proxy.yml such that only pipelines triggered by users with the requisite access will be configured to use the proxy, while all others will continue to pull from DockerHub as before. When DOCKER_REGISTRY_URL is pre-set in a project's CI/CD variable settings, the extra job is skipped and the dependency proxy is used always, unconditionally. To avoid breaking CI pipelines on 3rd-party GitLab instances, we only include the dependency proxy template on gitlab.tpo
* | | | | Merge branch 'conflux-poll-multiple' into 'main'gabi-2502025-03-032-64/+148
|\ \ \ \ \ | |_|/ / / |/| | | | | | | | | | | | | | | | | | | | | | | | tor-proto: Rewrite reactor loop to read from all circuits. Closes #1863 See merge request tpo/core/arti!2817
| * | | | tor-proto: Document that ready_streams_iterator() is cancel-safe.Gabriela Moldovan2025-03-031-0/+2
| | | | |
| * | | | tor-proto: Add cancellation-safety note inside circuit_action().Gabriela Moldovan2025-03-031-0/+3
| | | | |
| * | | | tor-proto: Reduce select_biased! indentation.Gabriela Moldovan2025-02-271-21/+21
| | | | | | | | | | | | | | | | | | | | | | | | | This was left over from the refactoring that moved the inner `select` into the `ConfluxSet` impl.
| * | | | tor-proto: Rename SelectResult to CircuitAction.Gabriela Moldovan2025-02-272-13/+13
| | | | |
| * | | | tor-proto: Rewrite reactor loop to read from all circuits.Gabriela Moldovan2025-02-272-55/+106
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates the `Reactor::run_once()` loop to attempt to read from (and write to) all of its circuit legs as opposed to just the primary one. Note that this slightly changes the behavior of the reactor. Previously, we'd only read from the control channel if the `chan_sender` was ready, whereas now the control channel is unconditionally read from, in the *outer* select. The overall effect is that the control channel can cause unbounded buffering in the `chan_sender` of each circuit (which can happen if the `chan_sender` is not ready to send). This was actually how the reactor worked before the refactoring from !2747, which is reflected in the `chan_sender` docs: ```rust /// Sender object used to actually send cells. /// /// NOTE: Control messages could potentially add unboundedly to this, although that's /// not likely to happen (and isn't triggereable from the network, either). chan_sender: SometimesUnboundedSink<AnyChanCell, ChannelSender>, ``` I don't believe this to be a problem, for the reason mentioned in the `chan_sender` docs, and because the main reason we check for `chan_sender` readiness is to apply backpressure on senders, which is not something we need to worry about when it comes to the control channel. Besides, the control channel is unbounded, so not reading from it won't stop the senders from sending more commands anyway. Closes #1863