summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | arti: Make Rpc argument unconditional when constructing socks proxyNick Mathewson2025-01-236-33/+43
| | | | | | | | | | | | | | | | | | Formerly this was a conditional method argument, which is a huge antipattern. Now it is unconditionally present, as `Option<T>` for a type that is uninhabited when RPC isn't supported.
| * | arti::socks: Re-wrap a section.Nick Mathewson2025-01-231-2/+3
| | | | | | | | | | | | | | | rust-analyzer keeps re-wrapping this piece for me, even though rustfmt doesn't complain.
| * | arti: remove an obsolete rpc todo.Nick Mathewson2025-01-231-1/+0
| | | | | | | | | | | | Information _is_ passed to the RpcMgr, via the argument to new_connection.
| * | arti: remove an obsolete rpc todo.Nick Mathewson2025-01-231-1/+0
| | | | | | | | | | | | | | | The RpcMgr does indirectly hold a reference to the client, via its make_session argument.
| * | arti: remove an obsolete rpc todo.Nick Mathewson2025-01-231-1/+0
| | | | | | | | | | | | We _do_ have error detection from this function, and have for ages.
| * | arti: Remove old workaround for runtime selection under RPC.Nick Mathewson2025-01-231-6/+1
|/ / | | | | | | | | This was necessary before we had support for implementing RPC methods on generic types.
* | Merge branch 'dev/cve/mistrust-doc' into 'main'Nick Mathewson2025-01-231-0/+12
|\ \ | | | | | | | | | | | | tor-config: Improve mistrust documentation See merge request tpo/core/arti!2727
| * | tor-config: Improve mistrust documentationClara Engler2025-01-231-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | This commit improves the documentation for `ConfigurationSources::set_mistrust`, by explaining that this option is unrelated to the paths defined within the configuration file itself, referring to the `storage.permissions.dangerously_trust_everyone` option.
* | | Merge branch 'fix-rpc-client-core' into 'main'Nick Mathewson2025-01-231-2/+2
|\ \ \ | | | | | | | | | | | | | | | | arti-rpc-client-core: Use EmptyReply instead of EmptyResponse. See merge request tpo/core/arti!2732
| * | | arti-rpc-client-core: Use EmptyReply instead of EmptyResponse.Gabriela Moldovan2025-01-231-2/+2
|/ / / | | | | | | | | | | | | | | | It looks like !2729 and !2722 raced with each other, because we're still using the old name for `EmptyReply` (and so `arti-rpc-client-core` doesn't currently compile on `main`).
* | | Merge branch 'rpc-cancel-2' into 'main'Nick Mathewson2025-01-2316-51/+503
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | rpc: Implement request cancellation Closes #818 See merge request tpo/core/arti!2722
| * | Document more that cancel is uncancellable.Nick Mathewson2025-01-222-0/+7
| | |
| * | rpc: Correct RPC error code for "RequestNotFound".Nick Mathewson2025-01-222-2/+5
| | |
| * | rpc-meta-draft: Make rpc:cancel more permissive on ID collision.Nick Mathewson2025-01-221-1/+2
| | |
| * | cancel: Distinguish the internal-error case for double-cancel.Nick Mathewson2025-01-221-2/+23
| | |
| * | cancel: Document deadlock/panic issue and how to avoid it.Nick Mathewson2025-01-221-2/+19
| | |
| * | rpc: Make cancel requests uncancellable.Nick Mathewson2025-01-224-28/+94
| | | | | | | | | | | | | | | | | | | | | | | | | | | The current cancel code is prone to deadlock, so the easiest way to solve it appears to be making cancel requests themselves uncancellable. I've included a test to verify the behavior; previously, this test caused a deadlock.
| * | cancel: Add a TODO about moving the Future inside the lock.Nick Mathewson2025-01-221-0/+5
| | |
| * | Cancel: Drop lock before calling waker.Nick Mathewson2025-01-221-0/+1
| | |
| * | cancel: Remove FusedFuture implementation.Nick Mathewson2025-01-221-12/+1
| | | | | | | | | | | | | | | | | | | | | Nothing used it, and it has some semantic complexity. (see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2722#note_3149591 )
| * | cancel: Use Waker::clone_from to avoid needless clones.Nick Mathewson2025-01-221-1/+9
| | | | | | | | | | | | | | | | | | The Waker::clone_from implementation uses Waker::will_wake to avoid unnecessarily cloning a Waker that it already has a copy of.
| * | rpc: Python Integration tests for cancelling requests.Nick Mathewson2025-01-222-0/+34
| | |
| * | python rpc: Add support for cancelling requests.Nick Mathewson2025-01-222-2/+30
| | |
| * | arti-rpc-client-core: Document that dropping a request does not cancel it.Nick Mathewson2025-01-223-6/+8
| | | | | | | | | | | | | | | | | | | | | I hope that this limitation is acceptable; the alternative involves some significant refactoring to give Request a Weak reference to RpcConn -- but RpcConn isn't currently kept in an Arc<> at all, and so we'd need some fairly heavy hacking.
| * | arti-rpc-client-core: Implement and expose cancellation.Nick Mathewson2025-01-224-3/+65
| | |
| * | python rpc: Document with_meta arguments.Nick Mathewson2025-01-221-0/+3
| | |
| * | python rpc: Expose an ArtiRpcObject for the "connection" object.Nick Mathewson2025-01-222-0/+12
| | |
| * | rpc: Implement the rpc:cancel command.Nick Mathewson2025-01-162-1/+79
| | |
| * | rpc: Document how cancel interacts with RequestId collision.Nick Mathewson2025-01-161-0/+6
| | |
| * | rpc: Better RpcErrorKind for for RequestCancelled.Nick Mathewson2025-01-161-4/+7
| | |
| * | rpc: Strengthen guarantees from Cancel.Nick Mathewson2025-01-163-20/+126
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Cancellation is now fallable, which allows us to detect attempts to cancel which cannot work. We now guarantee that when you try to cancel a `Cancel<F>` future, either the cancel operation will succeed, or the future will return (or will have already returned) Ok(), but not both, and not neither. Closes #818.
* | | Merge branch 'rpc-request-response-naming' into 'main'Nick Mathewson2025-01-214-29/+28
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | rpclib: Rename params/reply structs for consistency. Closes #1586 See merge request tpo/core/arti!2729
| * | rpclib: Rename params/reply structs for consistency.Nick Mathewson2025-01-214-29/+28
|/ / | | | | | | | | | | | | | | Our now convention here in rpclib is that a struct holding a request's parameters is called `FooParams`, and a struct holding that request's reply is called `FooReply`. Closes #1586
* | Merge branch 'mpl-insteructions' into 'main'Nick Mathewson2025-01-201-2/+13
|\ \ | | | | | | | | | | | | Better instructions for handling new MPL dependencies See merge request tpo/core/arti!2726
| * | maint/check_licenses: Acknowledge that we don't handle ORIan Jackson2025-01-201-1/+1
| | |
| * | maint/check_licenses: Instructions for what to do about MPLIan Jackson2025-01-201-1/+12
|/ /
* | Merge branch 'update-pow-manager-draft' into 'main'wesleyac2025-01-161-28/+54
|\ \ | | | | | | | | | | | | Update `service-side-pow.md` See merge request tpo/core/arti!2701
| * | tor-hsservice: Add more notes about publisher_update_tx.Wesley Aptekar-Cassels2025-01-161-1/+3
| | |
| * | tor-hsservice: Clarify PowManager publisher_update_tx.Wesley Aptekar-Cassels2025-01-161-0/+2
| | |
| * | tor-hsservice: Remove impl Clone for PowManager.Wesley Aptekar-Cassels2025-01-161-2/+0
| | | | | | | | | | | | Now that it's not in a Arc internally it shouldn't have this.
| * | tor-hsservice: Update PowManager persistence plan.Wesley Aptekar-Cassels2025-01-161-7/+19
| | |
| * | tor-hsservice: Make PowManager not use internal Arc.Wesley Aptekar-Cassels2025-01-161-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Per review feedback: > We have discovered that as a general rule of thumb, it is a good idea > to expose the `Arc`. This has a number of advantages; for example, if a > caller wants a `Weak` for any reason, that's right there. The typical > pattern is for the constructor to return `Arc<Self>` and methods to take > `self: &Arc<Self>`.
| * | tor-hsservice: Make PoW seed expiration be per-TP.Wesley Aptekar-Cassels2025-01-161-7/+6
| | | | | | | | | | | | | | | | | | This is something we wanted to do in general for security reasons, and ad I was implementing I discovered that it actually makes the code simpler, rather than more complicated.
| * | tor-hsservice: Update notes about PowManager persistence.Wesley Aptekar-Cassels2025-01-161-1/+1
| | |
| * | tor-hsservice: Add KeyMgr and HsNickname to PowManager.Wesley Aptekar-Cassels2025-01-161-0/+6
| | | | | | | | | | | | | | | These are needed to allow the PowManager to get the blinded ID needed to construct a PoW verifier.
| * | tor-hsservice: Give PowManager its own update loop.Wesley Aptekar-Cassels2025-01-161-14/+19
| | |
| * | tor-hsservice: Make PowManager use Arc internally.Wesley Aptekar-Cassels2025-01-161-1/+3
|/ / | | | | | | It is cleaner to not force callers to wrap it.
* | Merge branch 'test-sleep' into 'main'David Goulet2025-01-161-15/+5
|\ \ | | | | | | | | | | | | tor-proto: Replace sleep() in test with advance_until_stalled(). See merge request tpo/core/arti!2721
| * | tor-proto: Replace sleep() in test with advance_until_stalled().Gabriela Moldovan2025-01-161-15/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This test spuriously failed on my !2720 branch (https://gitlab.torproject.org/gabi-250/arti/-/jobs/811495): ``` failures: ---- circuit::test::invalid_circ_sendme stdout ---- E tor_proto::channel::reactor: UniqId(71): Running reactor E tor_proto::circuit::reactor: Circ 23.17: Running circuit reactor E tor_proto::circuit::reactor: Circ 23.17: reactor received AddFakeHop { relay_cell_format: V0, fwd_lasthop: false, rev_lasthop: false, params: CircParameters { extend_by_ed25519_id: true, ccontrol: CongestionControlParams { alg: FixedWindow(FixedWindowParams { circ_window_start: 1000, circ_window_min: 100, circ_window_max: 1000 }), cwnd_params: CongestionWindowParams { cwnd_init: 124, cwnd_inc_pct_ss: Percentage { value: 100 }, cwnd_inc: 1, cwnd_inc_rate: 31, cwnd_min: 124, cwnd_max: 4294967295, sendme_inc: 31 }, rtt_params: RoundTripEstimatorParams { ewma_cwnd_pct: Percentage { value: 50 }, ewma_max: 10, ewma_ss_max: 2, rtt_reset_pct: Percentage { value: 100 } } } }, done: Sender { complete: false } } E tor_proto::circuit::reactor: Circ 23.17: reactor received AddFakeHop { relay_cell_format: V0, fwd_lasthop: true, rev_lasthop: true, params: CircParameters { extend_by_ed25519_id: true, ccontrol: CongestionControlParams { alg: FixedWindow(FixedWindowParams { circ_window_start: 1000, circ_window_min: 100, circ_window_max: 1000 }), cwnd_params: CongestionWindowParams { cwnd_init: 124, cwnd_inc_pct_ss: Percentage { value: 100 }, cwnd_inc: 1, cwnd_inc_rate: 31, cwnd_min: 124, cwnd_max: 4294967295, sendme_inc: 31 }, rtt_params: RoundTripEstimatorParams { ewma_cwnd_pct: Percentage { value: 50 }, ewma_max: 10, ewma_ss_max: 2, rtt_reset_pct: Percentage { value: 100 } } } }, done: Sender { complete: false } } E tor_proto::circuit::reactor: Circ 23.17: reactor received BeginStream { hop_num: HopNum(2), message: Begin(Begin { addr: [119, 119, 119, 46, 101, 120, 97, 109, 112, 108, 101, 46, 99, 111, 109], port: 443, flags: BeginFlags(IPV6_OKAY) }), sender: Sender { tx: Sender { closed: false }, mq: TypedParticipation(Participation(Noop)) }, rx: Receiver { inner: ReceiverInner { state: Mutex { data: Ok(ReceiverState { rx: StreamUnobtrusivePeeker { buffered: None, poll_waker: None, inner: Some(Receiver { closed: false }) }, mq: TypedParticipation(Participation(Noop)), collapse_callbacks: 0 }), poisoned: false, .. } } }, done: Sender { complete: false }, cmd_checker: DataCmdChecker { expecting_connected: true } } Using RNG seed ARTI_TEST_PRNG=62d085c0fb1213c4f41d1a0a5c3f92dd10223a27c42bfda3caedfe60e011e95d E tor_proto::circuit::reactor: Circ 23.17: handling cell: Relay(Relay { body: .. }) Using RNG seed ARTI_TEST_PRNG=fd2f2f045a7340f1189972b13645346943efa2c42f43afd2161420c692bb4ff0 E tor_proto::circuit::reactor: Circ 23.17: handling cell: Relay(Relay { body: .. }) E tor_proto::circuit::reactor: Circ 23.17: Circuit reactor stopped: Err(CircProto("Mismatched tag on circuit SENDME")) E tor_proto::channel::reactor: UniqId(71): reactor received CloseCircuit(CircId(128)) E tor_proto::channel::reactor: UniqId(71): Circuit 128 is gone; sending DESTROY thread 'circuit::test::invalid_circ_sendme' panicked at crates/tor-proto/src/circuit.rs:2262:21: reactor continued running after invalid sendme failures: circuit::test::invalid_circ_sendme test result: FAILED. 142 passed; 1 failed; 1 ignored; 0 measured; 0 filtered out; finished in 4.93s ``` This is probably because of the `sleep()`-based check. This branch changes the test to use `MockRuntime`, replacing the `sleep()` with `advance_until_stalled()`.
* | | Merge branch 'refactor-poll_fn' into 'main'gabi-2502025-01-161-71/+82
|\ \ \ | |_|/ |/| | | | | | | | tor-proto: Light run_once() refactoring See merge request tpo/core/arti!2720