summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | netdoc parse2: Fix keyword parsing to hate nul, not digit zero (!)Ian Jackson2025-09-291-1/+1
| | | | | |
| * | | | | netdoc parse2: Use $P::Result throughoutIan Jackson2025-09-292-5/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed when using these macros in a namespace with a local redefinition of `Result`.
| * | | | | netdoc parse2: Fix a compile_error! invocationIan Jackson2025-09-291-1/+1
|/ / / / / | | | | | | | | | | | | | | | I triggered this error and it didn't work right.
* | | | | Merge branch 'sysinfo-no-default' into 'main'opara2025-09-281-1/+1
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | remove default feature off sysinfo See merge request tpo/core/arti!3290
| * | | | | remove default feature off sysinfotrinity-1686a2025-09-281-1/+1
|/ / / / /
* | | | | Merge branch 'padding_edits' into 'main'Nick Mathewson2025-09-251-75/+249
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Clarifications and changes to padding doc See merge request tpo/core/arti!3276
| * | | | | Note replace difficultiesMike Perry2025-09-251-1/+3
| | | | | |
| * | | | | Note about framework consolidationMike Perry2025-09-251-0/+9
| | | | | |
| * | | | | Relocate framework section after intended usageMike Perry2025-09-251-8/+8
| | | | | |
| * | | | | Note about current replace flag implementationMike Perry2025-09-241-0/+8
| | | | | |
| * | | | | Clarify congestion control interactionsMike Perry2025-09-241-2/+13
| | | | | |
| * | | | | Clarify where latency defenses belongMike Perry2025-09-241-4/+8
| | | | | |
| * | | | | NN noteMike Perry2025-09-241-0/+3
| | | | | |
| * | | | | Add note about threat model scopeMike Perry2025-09-241-0/+11
| | | | | |
| * | | | | repeat that this document is current as of sept 2025Mike Perry2025-09-221-2/+2
| | | | | |
| * | | | | Clarifications and changes to padding docMike Perry2025-09-181-75/+201
| | | | | |
* | | | | | Merge branch 'poll-all-once' into 'main'gabi-2502025-09-258-198/+437
|\ \ \ \ \ \ | |_|/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | proto: Rewrite ConfluxSet::next_circ_action() using PollAll. Closes #2179 and #2180 See merge request tpo/core/arti!3279
| * | | | | proto: Replace magic value with constant (fmt).Gabriela Moldovan2025-09-251-1/+2
| | | | | |
| * | | | | proto: Replace magic value with constant.Gabriela Moldovan2025-09-251-4/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also derives `CIRC_ACTION_COUNT` from the two other constants instead of hard-coding the value.
| * | | | | proto: Use MAX_CONFLUX_LEGS instead of magic number.Gabriela Moldovan2025-09-251-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Besides, it's better if we use the same number for the expected number of legs as we do in the conflux set impl.
| * | | | | proto: Make padding and timeout actions take priority.Gabriela Moldovan2025-09-251-34/+69
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This rewrites `next_circ_action()` yet again, using two layers of `PollAll`: * the inner layer drives an individual circuit leg. Each circuit has a `PollAll` that drives its futures * the outer layer drives the inner `PollAll`s belonging to the circuits that form the tunnel
| * | | | | proto: Add comment emphasizing that the PollAll ordering matters.Gabriela Moldovan2025-09-251-0/+7
| | | | | |
| * | | | | proto: Add comment explaining why we need the chan_sender readiness check.Gabriela Moldovan2025-09-251-0/+3
| | | | | |
| * | | | | proto: Document exactly how PollAll polls its futures.Gabriela Moldovan2025-09-251-1/+11
| | | | | |
| * | | | | proto: Resolve a couple of clippy warnings in the tests.Gabriela Moldovan2025-09-251-2/+2
| | | | | |
| * | | | | proto: Rewrite should_skip_join_point to return bool.Gabriela Moldovan2025-09-251-11/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We don't really need to return a `HopNum` anymore (because we work out the join point `HopNum` unconditionally in `next_circ_action`).
| * | | | | proto: Avoid polling join point streams more than once.Gabriela Moldovan2025-09-251-6/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we poll the ready streams on the join point more than once per reactor loop, we risk sending more than one DATA cell (which is not good, because cc might block after the first cell is sent).
| * | | | | proto: Remove now-unused function.Gabriela Moldovan2025-09-251-21/+2
| | | | | |
| * | | | | proto: Rewrite ConfluxSet::next_circ_action() using PollAll.Gabriela Moldovan2025-09-254-132/+109
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This removes our usage of `FuturesUnordered` in `ConfluxSet::next_circ_action()` to address two issues: * a fairness issue, where the futures driven by `FuturesUnordered` could be starved under some circumstances (#2180) * a logic error, where we'd explicitly avoid reading from the input channel if the outgoing `chan_sender` channel was blocked (#2179) Note that the fixing the latter will cause the reactor to buffer more into the unbounded `chan_sender` sink, but that *should* be okay, because no input message should be able cause us to queue cells excessively. Closes #2179, #2180
| * | | | | proto: Expose CircHopList in ConfluxSet.Gabriela Moldovan2025-09-251-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will soon need to access this directly (rather than via a method on `Circuit`) to work around borrow checker limitations.
| * | | | | proto: Return multiple actions from next_circ_action (fmt).Gabriela Moldovan2025-09-251-47/+47
| | | | | |
| * | | | | proto: Return multiple actions from next_circ_action.Gabriela Moldovan2025-09-252-4/+17
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Part of #2180 Note: the code is intentionaly left misindented to make reviewing a bit easier. A future commit will fix the indentation.
| * | | | | proto: Add PollAll helper for driving futures in lockstep.Gabriela Moldovan2025-09-252-0/+196
| | | | | |
| * | | | | proto: Push conflux state checks inside handshake_timeout() (fmt).Gabriela Moldovan2025-09-251-6/+6
| | | | | |
| * | | | | proto: Push conflux state checks inside handshake_timeout().Gabriela Moldovan2025-09-254-10/+16
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | This simplifies the calling code, which will, in turn, make it easier for us to simplify the logic in ConfluxSet::next_circ_action() and abolish the questionable use of FuturesUnordered.
* | | | | Merge branch 'expire-halfstream-cbt' into 'main'gabi-2502025-09-2415-47/+321
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | proto: Remove half-streams when they expire. Closes #264 See merge request tpo/core/arti!3267
| * | | | | proto: Temporarily ignore large_enum_variant clippy warning.Gabriela Moldovan2025-09-231-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | I want to tackle this separately, as part of #2003
| * | | | | proto: Apply deferred rustfmt.Gabriela Moldovan2025-09-221-3/+1
| | | | | |
| * | | | | proto: Remove duplicate word in comment.Gabriela Moldovan2025-09-221-1/+1
| | | | | |
| * | | | | proto: Add new error type for cells received on non-existent streams.Gabriela Moldovan2025-09-224-11/+41
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3267#note_3261239
| * | | | | proto: Log circuit reactor errors at debug level.Gabriela Moldovan2025-09-221-2/+2
| | | | | |
| * | | | | proto: Use the circuit build timeout instead of the abandon timeout.Gabriela Moldovan2025-09-221-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3267#note_3259820
| * | | | | proto: Reject any messages arriving on expired half-streams.Gabriela Moldovan2025-09-193-3/+11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Half-streams are periodically removed from each hop's stream map by the reactor main loop, but we still need to ensure we reject any messages arriving on expired half-streams in between these cleanup cycles.
| * | | | | proto: Add test to ensure half-streams are removed after a while.Gabriela Moldovan2025-09-191-0/+80
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This tests that the half-stream expiry works as expected. Note: it doesn't! This test currently fails, because there's a bug in the way half-streams are expired. Because we don't do it on a timer, and instead garbage-collect the half-streams on each reactor iteration, if the reactor is stuck long enough `.await`ing a message on one of its channels (for example, the `input` one), there is a chance it will accept a cell on a half-stream that should've been expired. A future commit will fix this bug.
| * | | | | proto: Calculate CBT more accurately.Gabriela Moldovan2025-09-192-4/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This should look at length of the circuit up until the hop where the half-stream is (because the half-stream might be on an intermediate hop, and not necessarily on the final one).
| * | | | | proto: Remove half-streams when they expire.Gabriela Moldovan2025-09-164-1/+33
| | | | | | | | | | | | | | | | | | | | | | | | Closes #264
| * | | | | circmgr: Pass the timeout estimator to circuit constructor (fmt).Gabriela Moldovan2025-09-163-11/+22
| | | | | |
| * | | | | circmgr: Pass the timeout estimator to circuit constructor.Gabriela Moldovan2025-09-164-14/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This enables us to read the CBT estimates from the circuit reactor (we need these to compute the half-stream timeouts for #264).
| * | | | | circmgr: Implement TimeoutEstimator for Estimator.Gabriela Moldovan2025-09-161-0/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will enable us to pass the timeout estimator to the circuit reactor in tor-proto.
| * | | | | proto: Use the CBT to compute half-stream timeouts.Gabriela Moldovan2025-09-166-9/+55
| | | | | |