summaryrefslogtreecommitdiff
path: root/crates/arti-rpcserver/src
Commit message (Collapse)AuthorAgeFilesLines
* lints: Run maint/add_warning to actually apply new lintsIan Jackson2023-06-211-0/+2
|
* Merge branch 'rpcdoc' into 'main'Ian Jackson2023-06-203-7/+51
|\ | | | | | | | | rpc: Minor docs improvements See merge request tpo/core/arti!1260
| * rpc: Fix docs typoNick Mathewson2023-06-201-1/+1
| |
| * rpc: Expand and clarify and cross-reference lock hierarchyIan Jackson2023-06-162-6/+34
| |
| * rpc: Document relationship between `Connection` and `RpcSession`Ian Jackson2023-06-162-1/+17
| |
* | Fix compilation afver last suggestion.Nick Mathewson2023-06-161-1/+2
| |
* | Apply 1 suggestion(s) to 1 file(s)Ian Jackson2023-06-161-0/+1
|/
* rpc: Document and apply lock hierarchy for Mgr/ConnectionNick Mathewson2023-06-151-4/+13
|
* rpc: Give the session-creation function an argument.Nick Mathewson2023-06-154-10/+18
| | | | | | This will later let us tell the session-creation function how the authentication occurred, which will let it decide what privileges to provide.
* rpc: revise session initialization a lot.Nick Mathewson2023-06-154-37/+52
| | | | | | | | | | | | | | Formerly, every time we wanted to launch a new connection, we had to give the RpcMgr a TorClient. The connection would hold that TorClient until a session was authenticated, and then would wrap it in a Session and put it in the object map. Now, the RpcMgr holds a Box<dyn Fn()...> that knows how to create Sessions. When a connection is authenticated, it asks the Mgr to make it a new session. This lets us make it clearer that the TorClient simply can't be given out until the connection is authenticated. Later, it will let us create more types of Session objects under more complicated rules.
* rpc: Rename Session=>RpcSessionNick Mathewson2023-06-153-9/+9
|
* rpc: Expose Session object.Nick Mathewson2023-06-152-3/+13
| | | | | We'll want to move the responsibility for creating Sessions outside the rpcmgr crate.
* RPC: rename new_session to new_connectionNick Mathewson2023-06-151-1/+1
|
* rpc: switch GlobalId mac to KMAC.Nick Mathewson2023-06-141-14/+4
|
* rpc: connection_id _is_ used: remove a comment to the contraryNick Mathewson2023-06-141-3/+0
|
* rpc: revise the relationship between Mgr and ConnectionNick Mathewson2023-06-142-26/+40
| | | | | | | | This adds a Weak reference from Connection to Mgr, makes DispatchTable mutable, and makes a few other changes as discussed between me and Diziet the other week. I bet we are not done tweaking this, but I hope it's a setp forwards.
* RPC: Functionality to downcast dyn Object to a dyn Trait.Nick Mathewson2023-06-121-8/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a rather tricky piece of functionality. It works as follows. We introduce a `CastTable` type. Each `CastTable` tells us how to downcast `dyn Object` for objects of a single concrete type. The `Object` type now has a `get_casttable` method that returns an empty `CastTable` by default. `CastTable` is, internally, a map from the `TypeId` of the target dyn Trait reference type to a function `fn(&dyn Object) -> &dyn Trait`. These functions are stored as `Box<dyn Any + ...>`. (They are Boxed because they may refer to generic functions, which you can't get a static reference to, and they're Any because the functions have different types.) The `decl_object!` macro now implements `get_casttable` as appropriate. (The syntax is a bit janky, but that's what we get for not using derive_adhoc.) For non-generic types, `get_casttable` uses a Lazy<CastTable>`. to initialize a CastTable exactly once. For generic types, it use a `Lazy<RwLock<HashMap<..>>` to build one CastTable per instantiation of the generic type. This could probably be optimized a bit more, the yaks could be shaved in a more scintillating hairstyle, and the syntax for generic `decl_object` could definitely be improved.
* rpc: make decl_object! responsible for writing impl Object {} blocks.Nick Mathewson2023-06-073-4/+1
|
* RPC: Note a possible API change in RpcMgr::new.Nick Mathewson2023-06-051-0/+4
|
* RPC: Make Session objects get a GlobalId.Nick Mathewson2023-06-051-1/+7
|
* RPC: Give out and accept GlobalIds for appropriate objects.Nick Mathewson2023-06-053-11/+86
|
* RPC: Implement a "global identifier" for non-session-bound IDsNick Mathewson2023-06-054-7/+288
| | | | | | | These identifiers are actually only "global" with respect to a given `RpcMgr`, but they should not be forgeable or reusable across RpcMgr objects. We're going to use them so that we have a kind of identifier for `TorClient`s that we can expose to SOCKS.
* rpc: Slightly refactor GenIdx encoding.Nick Mathewson2023-06-053-17/+27
|
* rpc: Give RpcMgr a registry of connections.Nick Mathewson2023-06-052-5/+66
| | | | | We're going to use this to implement arti#863, which requires that some RPC objects be globally nameable.
* rpc: Move Arc::new() to RpcMgr code.Nick Mathewson2023-06-051-2/+2
|
* Merge branch 'rpc-auth-and-meta' into 'main'Nick Mathewson2023-05-245-105/+308
|\ | | | | | | | | rpc: authentication and basic handle manipulation See merge request tpo/core/arti!1200
| * rpc: Remove downgrade_owned for nowNick Mathewson2023-05-242-27/+0
| | | | | | | | | | | | | | Rationale: Our weak-vs-strong design is a bit confused at the moment due to concerns about deduplication and capability semantics. It's not clear that a general "change strong to weak" method is compatible with what we want to provide.
| * rpc: Disable auth:get_rpc_protocol for now.Nick Mathewson2023-05-241-0/+8
| |
| * rpc: Implement functionality to remove objects from a sessionNick Mathewson2023-05-243-5/+99
| | | | | | | | | | | | | | | | | | | | | | I've made doing some design choices here: * Reserving "rpc" as a prefix for post-authentication functionality that is not arti-specific. * Declaring these to be methods on the session rather than methods on the objects themselves. There's a problem with defining an API to drop a weak reference; see comment in code.
| * rpc: Make the top-level returned object a "session".Nick Mathewson2023-05-244-38/+67
| | | | | | | | | | | | This will make it easier to change the semantics of what exactly we return, whether it has to be/contain a client, whether you can use it to look up all the live objects, &etc.
| * rpc: Implement auth:query.Nick Mathewson2023-05-231-1/+39
| |
| * rpc: Implement the auth:get_rpc_protocol method.Nick Mathewson2023-05-231-0/+49
| |
| * rpc: move existing auth code to new module.Nick Mathewson2023-05-232-72/+84
| |
* | rpc: Remove fake_generational_arenaNick Mathewson2023-05-231-76/+1
|/ | | | | | | Now that generation-arena has merged [@diziet's patch] to clarify their license, we no longer need to disable it. [@diziet's patch]: https://github.com/fitzgen/generational-arena/pull/56
* rpc: Split the generational index into two.Nick Mathewson2023-05-161-113/+92
| | | | This lets us simplify our logic a bit for strong references.
* rpc: Change the formatting of object IDsNick Mathewson2023-05-151-22/+71
| | | | | | | | | | | | | | | | | | We want each ID to have a unique form every time it is given out, so that you can't use ID==ID to check whether Object==Object. (See discussions leading to #848.) We'd also like the form of object IDs to be a little annoying to analyze, to discourage people from writing programs that depends on their particular format. (We are reserving the right to change the format whenever we want.) We _don't_ want to use any cryptography here (yet), lest somebody think that this is an actual security mechanism. (This isn't for security; it's for encouraging developers to treat IDs as opaque.) With that in mind, we now lightly obfuscate our generational indices before returning them.
* rpc: rename GenIdx::into/try_from implementationsNick Mathewson2023-05-152-11/+9
| | | | | These are about to become nondeterministic-ish and probably shouldn't use the Into/TryFrom traits.
* rpc: do not deduplicate strong object idsNick Mathewson2023-05-151-52/+39
| | | | | | | | Per discussion referenced at #848, we want each operation that returns a strong object ID to return a new, distinct strong ID. Note that we no longer need to put strong and weak references in the same arena; we can clean this code up a lot down the road.
* rpc: Repair an error in our ObjectId encoding.Nick Mathewson2023-05-151-1/+1
| | | | | | Now we generate object IDs that we can parse. This is about to be obsolete once we change how we generate objects and their IDs for #848, but we may as well start from a working state.
* objmap: move types to top of file.Nick Mathewson2023-05-041-74/+74
|
* Note/clean more TODOs in objmap.Nick Mathewson2023-05-041-1/+4
|
* RPC: Make the "client" return optional.Nick Mathewson2023-05-041-2/+2
|
* RPC: Make "Weak" and "Strong" entries separate.Nick Mathewson2023-05-041-43/+41
| | | | | | | | | Now there can be one of each, since we want references and handles to be conceptually separate. (The alternative would be to say that an operation either "returns a handle" or "returns a reference (which may become a handle) unless a handle already exists.")
* Temporarily replace generational-arena with a fake version.Nick Mathewson2023-05-041-1/+77
| | | | | This fake version is completely silly, but it will do the job until we figure out our MPL2 concerns.
* RPC: Rename session.rs to connection.rsNick Mathewson2023-05-044-4/+4
|
* RPC: rename Session to Connection.Nick Mathewson2023-05-043-45/+48
| | | | | | | To me, "Session" suggests that we're authenticated, when we are not necessarily authenticated. Also, we may eventually want to have some kind of persistent session object; if we do, then we'll want Connections to be separate.
* RPC: Make authentication return a TorClient.Nick Mathewson2023-05-042-58/+66
| | | | | | (This is the correct capabilities-based behavior. For now it will only work if the TorClient uses a PreferredRuntime, but with luck we will find a solution for #837 soon.)
* Add a generational arena for object mapping for RPC.Nick Mathewson2023-05-042-0/+664
| | | | | | See the comments on `TypedAddr` for some explanations about why this is so tricky. Thanks to @diziet for helping me figure this out.
* RPC: Add "register" methods to RequestContext.Nick Mathewson2023-05-041-0/+8
|
* RPC: Start on plumbing TorClient into our RPC codeNick Mathewson2023-05-041-3/+8
| | | | | Because of #837, we won't be able to work with _every_ TorClient<R>, so I'm only going to be using TorClient<PreferredRuntime> for now.