aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-cell/src
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-cell: Stop using write_infallibleNick Mathewson2022-07-113-37/+69
| | | | | | | | | | | | Also, stop using "expect" and "assert!" to check for errors.
| * | tor-cell: Make encoding method signatures fallible.Nick Mathewson2022-07-116-50/+89
| | |
| * | Convert each write_onto_infallible implementation into write_onto.Nick Mathewson2022-07-113-10/+16
| | |
| * | Rename "write" methods on tor-bytes to "write_infallible".Nick Mathewson2022-07-113-21/+21
| |/ | | | | | | | | | | | | | | | | | | | | | | | | | | | | This comprises four renames: ``` write_onto -> write_onto_infallible write_into -> write_into_infallible write -> write_infallible writer_and_consume -> write_and_consume_infallible. ``` The rest of this branch will be concerned with replacing these `_infallible` methods with ones that return a `Result`. This is part of #513.
* / tor-cell: Derive Eq for NtorV3ExtensionIan Jackson2022-07-181-1/+1
|/ | | | Apropos clippy complaint.
* Implement a higher-level API for the ntor v3 handshakeeta2022-07-082-0/+116
| | | | | | | | | | | | | | | | | | | This implements a higher-level API for the ntor v3 handshake, in line with that exposed by the ntor handshake. It does not, however, use the existing `ClientHandshake` trait, due to fundamental differences in the handshakes (namely, that the v3 handshake can include some additional extra extension data). Currently, the higher-level API assumes circuit extension, and copies the (undocumented!) magic verification string from c-tor that indicates this usage. A rudimentary set of functions for serializing and deserializing extensions to be sent with the handshake is also included, implementing the protocol in proposal 332 § A.2. Currently, it only implements the congestion control extensions specified in proposal 324 § 10.3. part of arti#88
* Merge branch 'clippy' into 'main'Ian Jackson2022-06-241-0/+3
|\ | | | | | | | | Fix clippy nightly again See merge request tpo/core/arti!603
| * Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-231-0/+3
| | | | | | | | Update all lint blocks
* | Fix a couple of typos in rustdoc comments.Nick Mathewson2022-06-241-1/+1
|/
* tor-cell: convert BytesErr to a struct variantNick Mathewson2022-06-223-7/+21
|
* tor-cell: error usefulness and style fixesNick Mathewson2022-06-225-17/+25
|
* Do not include error source() in display() format.Nick Mathewson2022-06-211-3/+3
| | | | | | | | | According to doc/Errors.md, and in keeping with current best practices, we should not include display an error's `source()` as part of that error's display method. Instead, we should let the caller decide to call source() and display that error in turn. Part of #323.
* tor-bytes: read_nested_*: Take a closureIan Jackson2022-06-101-15/+11
| | | | | | | | | | This eliminates the possibility of writing the bug of failing to call `should_be_exhausted`. As per this discussion https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/572#note_2811464 Fixes #498
* tor-cell: udp: Remove manual length calculationsIan Jackson2022-06-091-20/+8
| | | | | This does away entirely with `wire_addr_len`, which recapitulates the length calculation.
* Merge branch 'less-servfail' into 'main'Ian Jackson2022-06-091-1/+2
|\ | | | | | | | | return nodata instead of servfail in some instances See merge request tpo/core/arti!564
| * try to differentiate transient from nontransient errortrinity-1686a2022-06-081-1/+2
| |
* | Fix a second docs linkIan Jackson2022-06-081-1/+1
| |
* | Fix a doc linkIan Jackson2022-06-081-1/+1
|/
* udp: New AddressPort used in cellsDavid Goulet2022-06-071-28/+59
| | | | Signed-off-by: David Goulet <[email protected]>
* udp: Allow empty hostname and no nul byteIan Jackson2022-06-071-11/+9
| | | | | | | | | | | | | | | After changes to the prop339, the domain name in an Address can only be 255 bytes max and can NOT contain nul byte(s). Unit tests had to be modified to accept this change: - Centralise msg_ip_address - Add currently-passing tests for address length - Test counted address length longer than type wants Related to #463 Signed-off-by: David Goulet <[email protected]>
* cell: Don't use NUL terminated string in CONNECT_UDPDavid Goulet2022-06-071-16/+16
| | | | Signed-off-by: David Goulet <[email protected]>
* cell: Move UDP to its own module and feature gate itDavid Goulet2022-06-073-304/+34
| | | | | | Related to #463 Signed-off-by: David Goulet <[email protected]>
* cell: Implement DATAGRAM cell from prop339David Goulet2022-06-072-4/+67
| | | | | | | | Decoding and encoding of the DATAGRAM cell from proposal 339. Related to #463. Signed-off-by: David Goulet <[email protected]>
* cell: Implement CONNECTED_UDP cell from prop339David Goulet2022-06-071-5/+61
| | | | | | Decoding and encoding implemented according to proposal 339. Related to #463
* cell: Implement CONNECT_UDP cell from prop339David Goulet2022-06-073-3/+503
| | | | | | | | | Decoding and encoding is implemented according to proposal 339 specifications. Related to #463 Signed-off-by: David Goulet <[email protected]>
* lints: Add let_unit_value allow to all cratesIan Jackson2022-05-311-0/+1
| | | | | From running add_warning, with manual picking of the right hunks/lines.
* lints: Add lint block delimiters to every crateIan Jackson2022-05-311-0/+2
| | | | | | This was the result of: maint/add_warning crates/*/src/{lib,main}.rs and then manually curating the results.
* clippy: Use write! rather than push_str, formatIan Jackson2022-05-111-2/+3
| | | | | This does involve unwrap, but of course that can't fail unless the formats fail, which would already panic (that's implied by format!).
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-252-2/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* tor-proto: add a backend to detect reported clock skew.Nick Mathewson2022-03-231-2/+14
| | | | | | | | | | | | | | | | NETINFO cells, which are sent in every handshake, may contain timestamps. This patch adds an accessor for the timestamp in the Netinfo messages, and teaches the tor-proto code how to compute the minimum clock skew in the code. The computation isn't terribly precise, but it doesn't need to be: Tor should work fine if your clock is accurate to within a few hours. This patch also notes a Y2038 problem in the protocol: see torspec#80. Part of #405.
* Merge branch 'educe-traits' into 'main'Ian Jackson2022-03-042-12/+9
|\ | | | | | | | | Replace many manual trait impls with use of educe See merge request tpo/core/arti!375
| * Move skip_fmt into tor-basic-utilsIan Jackson2022-03-041-1/+2
| | | | | | | | | | | | | | Code motion and the minimal mechanical changes. As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/375#note_2783078
| * Replace manual Default impl with educe in tor-cellIan Jackson2022-03-021-6/+4
| |
| * Replace manual Debug impl with educe in tor-cellIan Jackson2022-03-021-7/+5
| |
* | Replace manual Default impl with std derive in tor-cellIan Jackson2022-03-021-6/+1
|/
* Merge branch 'clippy-allow-arc-clone' into 'main'Nick Mathewson2022-03-011-1/+0
|\ | | | | | | | | Disable clippy::clone_on_ref_ptr See merge request tpo/core/arti!352
| * Disable clippy::clone_on_ref_ptrIan Jackson2022-02-241-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This lint is IMO inherently ill-conceived. I have looked for the reasons why this might be thought to be a good idea and there were basically two (and they are sort of contradictory): I. "Calling ‘.clone()` on an Rc, Arc, or Weak can obscure the fact that only the pointer is being cloned, not the underlying data." This is the wording from https://rust-lang.github.io/rust-clippy/v0.0.212/#clone_on_ref_ptr It is a bit terse; we are left to infer why it is a bad idea to obscure this fact. It seems to me that if it is bad to obscure some fact, that must be because the fact is a hazard. But why would it be a hazard to not copy the underlying data ? In other languages, faliing to copy the underlying data is a serious correctness hazard. There is a whose class of bugs where things were not copied, and then mutated and/or reused in multiple places in ways that were not what the programmer intended. In my experience, this is a very common bug when writing Python and Javascript. I'm told it's common in golang too. But in Rust this bug is much much harder to write. The data inside an Arc is immutable. To have this bug you'd have use interior mutability - ie mess around with Mutex or RefCell. That provides a good barrier to these kind of accidents. II. "The reason for writing Rc::clone and Arc::clone [is] to make it clear that only the pointer is being cloned, as opposed to the underlying data. The former is always fast, while the latter can be very expensive depending on what is being cloned." This is the reasoning found here https://github.com/rust-lang/rust-clippy/issues/2048 This is saying that *not* using Arc::clone is hazardous. Specifically, that a deep clone is a performance hazard. But for this argument, the lint is precisely backwards. It's linting the "good" case and asking for it to be written in a more explicit way; while the supposedly bad case can be written conveniently. Also, many objects (in our codebase, and in all the libraries we use) that are Clone are in fact simply handles. They contain Arc(s) (or similar) and are cheap to clone. Indeed, that is the usual case. It does not make sense to distinguish in the syntax we use to clone such a handle, whether the handle is a transparent Arc, or an opaque struct containing one or more other handles. Forcing Arc::clone to be written as such makes for code churn when a type is changed from Arc<Something> to Something: Clone, or vice versa.
* | Give specific error kinds to different END reasonsNick Mathewson2022-02-231-0/+21
|/ | | | Closes #360.
* Remove clippy::needless_borrow exception in CI.Nick Mathewson2022-02-201-1/+0
| | | | | This exception is no longer necessary now that the underlying CI bug is fixed.
* Merge branch 'clippy-followup' into 'main'Nick Mathewson2022-02-171-3/+3
|\ | | | | | | | | Remove some needless refs and slicing See merge request tpo/core/arti!327
| * Remove some needless refs and slicingIan Jackson2022-02-171-3/+3
| | | | | | | | | | Prompted by nightly's clippy (which has some false positives, so is currently disabled).
* | Merge branch 'ptr_arg_fix' into 'main'Ian Jackson2022-02-171-1/+0
|\| | | | | | | | | Re-enable clippy::ptr_arg where it had been disabled. See merge request tpo/core/arti!323
| * Re-enable clippy::ptr_arg where it had been disabled.Nick Mathewson2022-02-161-1/+0
| | | | | | | | | | | | | | | | | | | | In one of the two places, nightly no longer warns. In the other place, it's fine for nightly to warn: I just fixed the code to take a slice instead. Partial revert of 856aca879151c622512bc4b15c6307808fc83e82. Resolves part of #310.
* | Update tor-cell errors to latest APINick Mathewson2022-02-151-4/+4
| |
* | tor-cell: provide HasKind.Nick Mathewson2022-02-153-13/+22
|/ | | | | | | | | Additionally, refactor the IoError out of tor_cell::Error: nothing in TorCell created this; it was only used by tor_proto. This required refactoring in tor_proto to use a new error type. Here I decided to use a new CodecError for now, though we may refactor that away soon too.
* Change deny(clippy::all) to warn(clippy::all).Nick Mathewson2022-02-141-1/+1
| | | | Closes #338.
* Temporarily disable some clippy lints on nightlyIan Jackson2022-02-022-0/+2
|
* extend lints to include 'clippy::all'Daniel Eades2021-12-281-0/+1
|
* tor-cell: replace an XXXX with a TODO.Nick Mathewson2021-12-161-1/+6
| | | | | The original comment was a gnomic question about what to box; the real issue is that we want to avoid copying data in our critical path.
* Extend trace messages for destroy/truncated reasons.Nick Mathewson2021-12-152-18/+43
| | | | | | | | | | | | It makes sense to put the method for human-readable strings onto the type itself, so that we can format these whenever they occur. I'm choosing the "human_str" method name here, since caret-generated types already have a to_str. I was thinking about using Display, but caret types already implement that. I've also moved the message from "warn!" to "debug!", since these aren't necessarily a problem condition.