summaryrefslogtreecommitdiff
path: root/crates/tor-circmgr/src
Commit message (Collapse)AuthorAgeFilesLines
* Upgrade to derive_more version 1.0.0Nick Mathewson2024-09-251-2/+2
| | | | | | The `derive_more` crate broke backward compatibility with this version, so this change involved quite a few manual fixups. With luck, they'll keep compatibility for some while in the future.
* CircMgr: Make CircMgr and HsCircPool generic over builder type.Wesley Aptekar-Cassels2024-09-246-446/+852
| | | | | | | | | | This will allow for testing, as the CircuitBuilder can be replaced with a mocked version. This did require moving some of what was in the CircuitBuilder impl into the AbstractCircuitBuilder type, since Drop implementations can't be specialized, but that's fine, as we'll probably be doing more of that in the future anyways.
* Add test for CircList::find_open.Wesley Aptekar-Cassels2024-09-161-1/+55
| | | | | | | This tests that when requesting preemptive circuits, they are not given out when a insufficient number of circuits are in the CircList, but that they are given out once the required number of circuits has been reached.
* tor-circmgr: Remove AbstractSpec and FakeSpec.Wesley Aptekar-Cassels2024-09-163-260/+221
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | AbstractSpec and FakeSpec actually make testing more difficult, since they prevent using FakeBuilder in code that relies on the concrete TargetCircUsage and SupportedCircUsage types. Removing them means FakeBuilder can be used in more places, and also means that the test code is closer to the real code, since TargetCircUsage and SupportedCircUsage are now exercised directly in more tests. This did require making one change to a test, which I think was previously testing behaviour that was true for FakeSpec but not for the real code: The mgr::test::isolated test previously asserted that, in the case where three circuits were requested, two with isolation and one without, the non-isolated circuit would be shared with one of the isolated circuits. This was allowed by the FakeSpec::supports function. However, in the actual code, the path is as follows: * AbstractCircMgr::get_or_launch * AbstractCircMgr::prepare_action * CircList::find_open * AbstractSpec::find_supported * abstract_spec_find_supported * OpenEntry::supports * SupportedCircUsage::supports * StreamIsolation::compatible_same_type StreamIsolation::compatible_same_type checks owner_type, which is always zero for non-isolated streams and always non-zero for isolated streams, meaning that a isolated stream will never be compatible with a non-isolated stream. The seems like desirable behaviour, so I simply modified the test to make four connections, two isolated and two not, and checked that the isolated streams never share any circuits, and that the two non-isolated streams use the same circuit. As far as I can tell, this is the intended behaviour in the existing code.
* tor-netdir: Allow access to the `ConsensusBuilder` when building test netdirs.Gabriela Moldovan2024-09-093-4/+4
| | | | | This allows us to set SRVs for example (needed because by default, the test `NetDir` is built from a consensus that doesn't contain any SRVs).
* Fix typosDimitris Apostolou2024-09-031-1/+1
|
* extract tor_async_utils::oneshot into ::oneshot-fused-workaroundJim Newsome2024-08-283-3/+3
| | | | | | | | | | | | | | Having this in the `tor-async-utils` crate prevents us from doing both of the following without introducing a circular dependency: * using it in `tor-rtmock` (which we currently do, particularly in tests). * using `tor-rtmock` to test things in `tor-async-utils`. We don't do this yet, but it is generally sensible to do so. In particular we want to move the `stream_peak` module there, which is currently tested with `tor-rtmock`. Moving this into its own crate avoids this circular dependency.
* tor-circmgr: removed unused 'skip_guard_subnet_check' workaround in testsSteven Engler2024-08-151-18/+5
|
* tor-circmgr: removed unused "chosen exit" functionalitySteven Engler2024-08-153-159/+18
|
* tor-circmgr: fix flaky `path::exitpath::test::by_ports` testSteven Engler2024-08-132-7/+23
| | | | | | | | | | | | | | | | The `path::exitpath::test::by_ports` test sometimes failed now that the test is using a `GuardMgr` since `select_guard`, when given a chosen exit, only ensures that the guard and chosen exit are not in the same family. It does not ensure that the guard and exit do not share an extended family. This commit relaxes an assertion in the test. ```text thread 'path::exitpath::test::by_ports' panicked at crates/tor-circmgr/src/path/exitpath.rs:295:9: assertion failed: r1.can_share_circuit(r3, subnet_config) ``` This "chosen exit" functionality isn't actually being used anywhere (`ExitPathBuilderInner::ChosenExit` is only ever constructed in tests).
* tor-circmgr: assert in test that exit path begins with guardSteven Engler2024-08-121-2/+4
|
* tor-circmgr: make `GuardMgr` mandatorySteven Engler2024-08-127-316/+146
| | | | | | | Functions that took `Option<&GuardMgr>` now take only `&GuardMgr`. Three unit tests were removed that covered behaviour when no guard manager was set.
* tor-circmg: prepare tests for runtime requirementSteven Engler2024-08-122-218/+229
| | | | | | This wraps some unit tests with `tor_rtcompat::test_with_all_runtimes!`. This is its own commit to get the indentation changes out of the way and declutter the following commit.
* tor-circmgr: Make client rendezvous circuits EXTENDED instead of SHORT.Gabriela Moldovan2024-06-251-3/+3
| | | | | | | | This updates the code to match the spec. This fixes TROVE-2024-008. Closes #1474
* tor-circmgr: Clarify the update_last_hop_kind documentation.Gabriela Moldovan2024-06-201-2/+10
|
* tor-circmgr: Rename VanguardPath to PathBuilder.Gabriela Moldovan2024-06-202-13/+12
|
* tor-circmgr: Remove duplicated path building logic from HS pool.Gabriela Moldovan2024-06-201-30/+19
|
* tor-circmgr: Fix clippy warning.Gabriela Moldovan2024-06-201-1/+1
|
* tor-circmgr: Gate vanguard-specific code behind vanguards feature.Gabriela Moldovan2024-06-201-0/+15
| | | | | | | This is just code motion: moving the vanguard-specific parts of `maybe_extend_stub_circuit()` behind the `vanguards` feature will enable us to refactor it to use `select_middle_for_vanguard_circuit()`, which is only available if the `vanguards` feature is enabled.
* tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts (fmt).Gabriela Moldovan2024-06-201-5/+2
|
* tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts.Gabriela Moldovan2024-06-202-118/+259
| | | | | | This is a follow up from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2186#note_3035525 Closes #1459
* tor-circmgr: Remove unnecessary TODO.Gabriela Moldovan2024-06-201-1/+0
| | | | There's not much to refactor about this line.
* tor-circmgr: Rename HsCircStubKind::len to HsCircStubKind::num_hops.Gabriela Moldovan2024-06-202-5/+5
|
* tor-circmgr: Note which test prevents TROVE-2024-005.Gabriela Moldovan2024-06-201-0/+1
| | | | | | This test is not new (it was added in !2168), but I think it's a good idea to annotate the tests preventing security issues with the TROVE number and/or arti ticket they pertain to.
* tor-circmgr: Write tests for the HsPathBuilder.Gabriela Moldovan2024-06-201-0/+463
| | | | | | | These tests should give us *some* assurance that the upcoming `HsVanguardPathBuilder` refactoring doesn't break anything. Part of #1459
* tor-circmgr: Refactor duplicated circuit stub length calculation.Gabriela Moldovan2024-06-202-27/+26
| | | | Part of #1459
* tor-circmgr: Add a TODO about an unused restriction.Gabriela Moldovan2024-06-201-0/+5
|
* tor-circmgr: Explicitly handle all VanguardMode variants.Gabriela Moldovan2024-06-051-1/+10
| | | | This is less error-prone than the alternative.
* tor-circmgr: Reference a ticket number in a refactoring TODO.Gabriela Moldovan2024-06-051-1/+1
|
* tor-circmgr: Note that guard_and_target exclusion sometimes doesn't exclude ↵Gabriela Moldovan2024-06-051-0/+3
| | | | target.
* tor-circmgr: Exclude the target when extending SHORT stubs.Gabriela Moldovan2024-06-041-4/+18
| | | | | When extending SHORT circuit stubs, the last hop shouldn't be the same as the circuit target.
* tor-circmgr: Exclude the target relay when building vanguards circuits.Gabriela Moldovan2024-06-041-13/+71
| | | | | | Otherwise, some of the circuits will fail (because if the target is selected as one of the L2, L3, or M hops, it won't be able to extend the circuit to itself).
* tor-circmgr: Apply deferred fmt.Gabriela Moldovan2024-06-041-1/+3
|
* tor-circmgr: Add TODOs about improving circuit length checks.Gabriela Moldovan2024-06-041-0/+2
|
* tor-circmgr: Remove HsPool::vanguards_enabled() (fmt).Gabriela Moldovan2024-06-041-2/+10
|
* tor-circmgr: Remove HsPool::vanguards_enabled().Gabriela Moldovan2024-06-041-24/+33
| | | | | | | | | Previously, the HsCircPool had a bug that caused SHORT lite-vanguards circuits to be incorrectly extended by one hop when being repurposed as EXTENDED circuits (EXTENDED circuits only need to be extended by extra hop if full vanguards are in use). Closes #1456 and #1458
* tor-circmgr: Validate the circuit stub length before returning it.Gabriela Moldovan2024-06-041-8/+68
|
* Merge branch 'pick-path-fix' into 'main'gabi-2502024-06-041-12/+49
|\ | | | | | | | | | | | | tor-circmgr: Exclude the circ target when building paths. Closes #1425 See merge request tpo/core/arti!2179
| * tor-circmgr: If the path is invalid, display the offending hops in the error.Gabriela Moldovan2024-06-031-4/+5
| |
| * tor-circmgr: Ensure pick_path() builds paths with unique hops (fmt).Gabriela Moldovan2024-06-031-1/+5
| |
| * tor-circmgr: Ensure pick_path() builds paths with unique hops.Gabriela Moldovan2024-06-031-10/+24
| | | | | | | | | | We now return an internal error if the path we've just built contains the same hop in multiple positions.
| * tor-circmgr: Exclude the circ target when building paths.Gabriela Moldovan2024-06-031-2/+20
| | | | | | | | Closes #1425
* | tor-circmgr: Display the offending hop if the circuit is not compatible with ↵Gabriela Moldovan2024-06-031-4/+5
| | | | | | | | target.
* | tor-circmgr: Use has_any_relay_id_from to check for relay equality.Gabriela Moldovan2024-06-031-2/+2
| | | | | | | | | | | | | | When checking for relay equality, we are happy to accept some false positives (which result in building/selecting a different circuit). We want to be less tolerant of false negatives, to avoid accidentally using a circuit that doesn't have the properties we need.
* | tor-circmgr: Ensure circuit stubs are compatible with the target.Gabriela Moldovan2024-06-031-1/+39
|/ | | | | | This is a follow-up from !2167. It should prevent issues like #1417 from going unnoticed.
* tor-circmgr: Make retire_all_circuits unconditional.Gabi Moldovan2024-06-032-2/+0
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2168?commit_id=3c67fa55c7c5b0c4f30c1d57e8e67fe541d9c99e#note_3033368
* tor-circmgr: Log the kind of HS circuit stub we are selecting.Gabriela Moldovan2024-06-031-1/+7
|
* tor-circmgr: Remove VanguardMode from Pool (fmt).Gabriela Moldovan2024-06-032-6/+2
|
* tor-circmgr: Remove VanguardMode from Pool.Gabriela Moldovan2024-06-033-34/+18
| | | | | | | | | Storing the VanguardMode in multiple places (in the VanguardMgr *and* the HS circ Pool) is dangerous and can lead to split brain situations where different parts of the code think they are running in different VanguardModes. See #1424
* tor-circmgr: Remove dangerous vanguards_enabled() function.Gabriela Moldovan2024-06-032-9/+9
| | | | | | | `VanguardMgr` should be the source of truth for obtaining the current `VanguardMode`. Closes #1424