| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | tor-circmgr: Make client rendezvous circuits EXTENDED instead of SHORT. | Gabriela Moldovan | 2024-06-25 | 1 | -3/+3 |
| | | | | | | | | | This updates the code to match the spec. This fixes TROVE-2024-008. Closes #1474 | ||||
| * | tor-circmgr: Clarify the update_last_hop_kind documentation. | Gabriela Moldovan | 2024-06-20 | 1 | -2/+10 |
| | | |||||
| * | tor-circmgr: Rename VanguardPath to PathBuilder. | Gabriela Moldovan | 2024-06-20 | 2 | -13/+12 |
| | | |||||
| * | tor-circmgr: Remove duplicated path building logic from HS pool. | Gabriela Moldovan | 2024-06-20 | 1 | -30/+19 |
| | | |||||
| * | tor-circmgr: Fix clippy warning. | Gabriela Moldovan | 2024-06-20 | 1 | -1/+1 |
| | | |||||
| * | tor-circmgr: Gate vanguard-specific code behind vanguards feature. | Gabriela Moldovan | 2024-06-20 | 1 | -0/+15 |
| | | | | | | | | This is just code motion: moving the vanguard-specific parts of `maybe_extend_stub_circuit()` behind the `vanguards` feature will enable us to refactor it to use `select_middle_for_vanguard_circuit()`, which is only available if the `vanguards` feature is enabled. | ||||
| * | tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts (fmt). | Gabriela Moldovan | 2024-06-20 | 1 | -5/+2 |
| | | |||||
| * | tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts. | Gabriela Moldovan | 2024-06-20 | 2 | -118/+259 |
| | | | | | | | This is a follow up from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2186#note_3035525 Closes #1459 | ||||
| * | tor-circmgr: Remove unnecessary TODO. | Gabriela Moldovan | 2024-06-20 | 1 | -1/+0 |
| | | | | | There's not much to refactor about this line. | ||||
| * | tor-circmgr: Rename HsCircStubKind::len to HsCircStubKind::num_hops. | Gabriela Moldovan | 2024-06-20 | 2 | -5/+5 |
| | | |||||
| * | tor-circmgr: Note which test prevents TROVE-2024-005. | Gabriela Moldovan | 2024-06-20 | 1 | -0/+1 |
| | | | | | | | This test is not new (it was added in !2168), but I think it's a good idea to annotate the tests preventing security issues with the TROVE number and/or arti ticket they pertain to. | ||||
| * | tor-circmgr: Write tests for the HsPathBuilder. | Gabriela Moldovan | 2024-06-20 | 1 | -0/+463 |
| | | | | | | | | These tests should give us *some* assurance that the upcoming `HsVanguardPathBuilder` refactoring doesn't break anything. Part of #1459 | ||||
| * | tor-circmgr: Refactor duplicated circuit stub length calculation. | Gabriela Moldovan | 2024-06-20 | 2 | -27/+26 |
| | | | | | Part of #1459 | ||||
| * | tor-circmgr: Add a TODO about an unused restriction. | Gabriela Moldovan | 2024-06-20 | 1 | -0/+5 |
| | | |||||
| * | tor-circmgr: Explicitly handle all VanguardMode variants. | Gabriela Moldovan | 2024-06-05 | 1 | -1/+10 |
| | | | | | This is less error-prone than the alternative. | ||||
| * | tor-circmgr: Reference a ticket number in a refactoring TODO. | Gabriela Moldovan | 2024-06-05 | 1 | -1/+1 |
| | | |||||
| * | tor-circmgr: Note that guard_and_target exclusion sometimes doesn't exclude ↵ | Gabriela Moldovan | 2024-06-05 | 1 | -0/+3 |
| | | | | | target. | ||||
| * | tor-circmgr: Exclude the target when extending SHORT stubs. | Gabriela Moldovan | 2024-06-04 | 1 | -4/+18 |
| | | | | | | When extending SHORT circuit stubs, the last hop shouldn't be the same as the circuit target. | ||||
| * | tor-circmgr: Exclude the target relay when building vanguards circuits. | Gabriela Moldovan | 2024-06-04 | 1 | -13/+71 |
| | | | | | | | Otherwise, some of the circuits will fail (because if the target is selected as one of the L2, L3, or M hops, it won't be able to extend the circuit to itself). | ||||
| * | tor-circmgr: Apply deferred fmt. | Gabriela Moldovan | 2024-06-04 | 1 | -1/+3 |
| | | |||||
| * | tor-circmgr: Add TODOs about improving circuit length checks. | Gabriela Moldovan | 2024-06-04 | 1 | -0/+2 |
| | | |||||
| * | tor-circmgr: Remove HsPool::vanguards_enabled() (fmt). | Gabriela Moldovan | 2024-06-04 | 1 | -2/+10 |
| | | |||||
| * | tor-circmgr: Remove HsPool::vanguards_enabled(). | Gabriela Moldovan | 2024-06-04 | 1 | -24/+33 |
| | | | | | | | | | | Previously, the HsCircPool had a bug that caused SHORT lite-vanguards circuits to be incorrectly extended by one hop when being repurposed as EXTENDED circuits (EXTENDED circuits only need to be extended by extra hop if full vanguards are in use). Closes #1456 and #1458 | ||||
| * | tor-circmgr: Validate the circuit stub length before returning it. | Gabriela Moldovan | 2024-06-04 | 1 | -8/+68 |
| | | |||||
| * | Merge branch 'pick-path-fix' into 'main' | gabi-250 | 2024-06-04 | 1 | -12/+49 |
| |\ | | | | | | | | | | | | | tor-circmgr: Exclude the circ target when building paths. Closes #1425 See merge request tpo/core/arti!2179 | ||||
| | * | tor-circmgr: If the path is invalid, display the offending hops in the error. | Gabriela Moldovan | 2024-06-03 | 1 | -4/+5 |
| | | | |||||
| | * | tor-circmgr: Ensure pick_path() builds paths with unique hops (fmt). | Gabriela Moldovan | 2024-06-03 | 1 | -1/+5 |
| | | | |||||
| | * | tor-circmgr: Ensure pick_path() builds paths with unique hops. | Gabriela Moldovan | 2024-06-03 | 1 | -10/+24 |
| | | | | | | | | | | | We now return an internal error if the path we've just built contains the same hop in multiple positions. | ||||
| | * | tor-circmgr: Exclude the circ target when building paths. | Gabriela Moldovan | 2024-06-03 | 1 | -2/+20 |
| | | | | | | | | | Closes #1425 | ||||
| * | | tor-circmgr: Display the offending hop if the circuit is not compatible with ↵ | Gabriela Moldovan | 2024-06-03 | 1 | -4/+5 |
| | | | | | | | | | target. | ||||
| * | | tor-circmgr: Use has_any_relay_id_from to check for relay equality. | Gabriela Moldovan | 2024-06-03 | 1 | -2/+2 |
| | | | | | | | | | | | | | | | When checking for relay equality, we are happy to accept some false positives (which result in building/selecting a different circuit). We want to be less tolerant of false negatives, to avoid accidentally using a circuit that doesn't have the properties we need. | ||||
| * | | tor-circmgr: Ensure circuit stubs are compatible with the target. | Gabriela Moldovan | 2024-06-03 | 1 | -1/+39 |
| |/ | | | | | | This is a follow-up from !2167. It should prevent issues like #1417 from going unnoticed. | ||||
| * | tor-circmgr: Make retire_all_circuits unconditional. | Gabi Moldovan | 2024-06-03 | 2 | -2/+0 |
| | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2168?commit_id=3c67fa55c7c5b0c4f30c1d57e8e67fe541d9c99e#note_3033368 | ||||
| * | tor-circmgr: Log the kind of HS circuit stub we are selecting. | Gabriela Moldovan | 2024-06-03 | 1 | -1/+7 |
| | | |||||
| * | tor-circmgr: Remove VanguardMode from Pool (fmt). | Gabriela Moldovan | 2024-06-03 | 2 | -6/+2 |
| | | |||||
| * | tor-circmgr: Remove VanguardMode from Pool. | Gabriela Moldovan | 2024-06-03 | 3 | -34/+18 |
| | | | | | | | | | | Storing the VanguardMode in multiple places (in the VanguardMgr *and* the HS circ Pool) is dangerous and can lead to split brain situations where different parts of the code think they are running in different VanguardModes. See #1424 | ||||
| * | tor-circmgr: Remove dangerous vanguards_enabled() function. | Gabriela Moldovan | 2024-06-03 | 2 | -9/+9 |
| | | | | | | | | `VanguardMgr` should be the source of truth for obtaining the current `VanguardMode`. Closes #1424 | ||||
| * | tor-circmgr: Add a test to check that the pool uses the right VanguardMode. | Gabriela Moldovan | 2024-06-03 | 1 | -0/+86 |
| | | | | | See arti#1424 | ||||
| * | tor-circmgr: Ensure we don't select an incompatible circuit stub. | Gabriela Moldovan | 2024-06-03 | 1 | -3/+19 |
| | | | | | | | | | | | | Previously, HS stub circuit selection (with vanguards enabled) was buggy: when selecting a circuit stub from the circ pool, we failed to ensure its last hop was different from the circuit target. So in some cases, arti would attempt to extend a stub circuit of the form G -> L2 [-> L3] -> T to T, which can't work, because a relay won't extend a circuit to itself (or to its predecessor, for that matter). Closes #1417 | ||||
| * | tor-circmgr: Move vanguard circuit validation to a separate function. | Gabriela Moldovan | 2024-06-03 | 1 | -1/+20 |
| | | | | | This will soon grow more complex. | ||||
| * | tor-circmgr: Return an error if HS circ has an invalid length. | Gabriela Moldovan | 2024-06-03 | 1 | -4/+15 |
| | | | | | | | | | | | | | Previously, we'd `debug_assert` that the length of the path is valid. However, `debug_` asserts are compiled out for release builds, which means that if we have some code path that triggers the assertion failure, it will go unnoticed unless our tests happen to exercise it. It's safer to return an internal error, because we definitely don't want to proceed if the path is too short (see arti#1400 and arti#1409). Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2154#note_3030820 | ||||
| * | tor-guardmgr: Replace From impl with VanguardConfig::mode accessor. | Gabriela Moldovan | 2024-06-03 | 1 | -1/+1 |
| | | |||||
| * | tor-guardmgr: Use ExplicitOrAuto in the VanguardConfig | Gabriela Moldovan | 2024-06-03 | 1 | -1/+1 |
| | | |||||
| * | tor-guardmgr: Unconditionally define VanguardConfig. | Gabriela Moldovan | 2024-06-03 | 3 | -5/+5 |
| | | | | | | | | | | We want to export the `VanguardConfig` even if the `vanguards` feature is disabled (we will need to unconditionally include it in the arti config). Note that if `vanguards` are disabled, the `VanguardMode` from the `VanguardConfig` can only be `Dsiabled`. | ||||
| * | tor-circmgr: Downgrade a HS-VANGUARDS TODO. | Gabriela Moldovan | 2024-06-03 | 1 | -1/+1 |
| | | |||||
| * | tor-circmgr: Fix a broken doc link. | Gabriela Moldovan | 2024-05-16 | 1 | -1/+1 |
| | | |||||
| * | tor-circmgr: Clarify module-level docs. | Gabriela Moldovan | 2024-05-16 | 1 | -0/+6 |
| | | |||||
| * | tor-circmgr: Replace STUB/STUB+ terminology with SHORT/EXTENDED (fmt). | Gabriela Moldovan | 2024-05-16 | 1 | -1/+3 |
| | | |||||
| * | tor-circmgr: Replace STUB/STUB+ terminology with SHORT/EXTENDED. | Gabriela Moldovan | 2024-05-16 | 3 | -46/+44 |
| | | | | | | | | The previous STUB/STUB+ terminology was confusing, because STUB and STUB+ are both "circuit stubs" (but STUB is shorter than STUB+). Closes #1339 | ||||
| * | tor-circmgr: Rename HsCircStubKind::Stub to HsCircStubKind::Short. | Gabriela Moldovan | 2024-05-16 | 3 | -25/+31 |
| | | | | | Part of #1339 | ||||
