summaryrefslogtreecommitdiff
path: root/crates/tor-circmgr
Commit message (Collapse)AuthorAgeFilesLines
* Update versions of 0.x tor-* and arti-* cratesIan Jackson2024-06-271-22/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | nailing-cargo -uE set-version -p arti-client 0.20.0 nailing-cargo -uE set-version -p arti-relay 0.20.0 nailing-cargo -uE set-version -p arti-rpcserver 0.20.0 nailing-cargo -uE set-version -p tor-async-utils 0.20.0 nailing-cargo -uE set-version -p tor-basic-utils 0.20.0 nailing-cargo -uE set-version -p tor-bytes 0.20.0 nailing-cargo -uE set-version -p tor-cell 0.20.0 nailing-cargo -uE set-version -p tor-cert 0.20.0 nailing-cargo -uE set-version -p tor-chanmgr 0.20.0 nailing-cargo -uE set-version -p tor-checkable 0.20.0 nailing-cargo -uE set-version -p tor-circmgr 0.20.0 nailing-cargo -uE set-version -p tor-config 0.20.0 nailing-cargo -uE set-version -p tor-consdiff 0.20.0 nailing-cargo -uE set-version -p tor-dirclient 0.20.0 nailing-cargo -uE set-version -p tor-dirmgr 0.20.0 nailing-cargo -uE set-version -p tor-error 0.20.0 nailing-cargo -uE set-version -p tor-geoip 0.20.0 nailing-cargo -uE set-version -p tor-guardmgr 0.20.0 nailing-cargo -uE set-version -p tor-hsclient 0.20.0 nailing-cargo -uE set-version -p tor-hscrypto 0.20.0 nailing-cargo -uE set-version -p tor-hsrproxy 0.20.0 nailing-cargo -uE set-version -p tor-hsservice 0.20.0 nailing-cargo -uE set-version -p tor-keymgr 0.20.0 nailing-cargo -uE set-version -p tor-linkspec 0.20.0 nailing-cargo -uE set-version -p tor-llcrypto 0.20.0 nailing-cargo -uE set-version -p tor-log-ratelim 0.20.0 nailing-cargo -uE set-version -p tor-memquota 0.20.0 nailing-cargo -uE set-version -p tor-netdir 0.20.0 nailing-cargo -uE set-version -p tor-netdoc 0.20.0 nailing-cargo -uE set-version -p tor-persist 0.20.0 nailing-cargo -uE set-version -p tor-proto 0.20.0 nailing-cargo -uE set-version -p tor-protover 0.20.0 nailing-cargo -uE set-version -p tor-ptmgr 0.20.0 nailing-cargo -uE set-version -p tor-relay-selection 0.20.0 nailing-cargo -uE set-version -p tor-rpcbase 0.20.0 nailing-cargo -uE set-version -p tor-rtcompat 0.20.0 nailing-cargo -uE set-version -p tor-rtmock 0.20.0 nailing-cargo -uE set-version -p tor-socksproto 0.20.0 nailing-cargo -uE set-version -p tor-units 0.20.0 Each of which runs a rune like cargo set-version --offline -p tor-units 0.20.0
* tor-circmgr: Make client rendezvous circuits EXTENDED instead of SHORT.Gabriela Moldovan2024-06-251-3/+3
| | | | | | | | This updates the code to match the spec. This fixes TROVE-2024-008. Closes #1474
* Update to itertools 0.13.0Ian Jackson2024-06-251-1/+1
| | | | | | | No code changes needed. Precisely nailing-cargo -Eu upgrade --incompatible -p itertools
* tor-circmgr: Clarify the update_last_hop_kind documentation.Gabriela Moldovan2024-06-201-2/+10
|
* tor-circmgr: Rename VanguardPath to PathBuilder.Gabriela Moldovan2024-06-202-13/+12
|
* tor-circmgr: Remove duplicated path building logic from HS pool.Gabriela Moldovan2024-06-201-30/+19
|
* tor-circmgr: Fix clippy warning.Gabriela Moldovan2024-06-201-1/+1
|
* tor-circmgr: Gate vanguard-specific code behind vanguards feature.Gabriela Moldovan2024-06-201-0/+15
| | | | | | | This is just code motion: moving the vanguard-specific parts of `maybe_extend_stub_circuit()` behind the `vanguards` feature will enable us to refactor it to use `select_middle_for_vanguard_circuit()`, which is only available if the `vanguards` feature is enabled.
* tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts (fmt).Gabriela Moldovan2024-06-201-5/+2
|
* tor-circmgr: Break VanguardHsPathBuilder::pick_path into smaller parts.Gabriela Moldovan2024-06-202-118/+259
| | | | | | This is a follow up from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2186#note_3035525 Closes #1459
* tor-circmgr: Remove unnecessary TODO.Gabriela Moldovan2024-06-201-1/+0
| | | | There's not much to refactor about this line.
* tor-circmgr: Rename HsCircStubKind::len to HsCircStubKind::num_hops.Gabriela Moldovan2024-06-202-5/+5
|
* tor-circmgr: Note which test prevents TROVE-2024-005.Gabriela Moldovan2024-06-201-0/+1
| | | | | | This test is not new (it was added in !2168), but I think it's a good idea to annotate the tests preventing security issues with the TROVE number and/or arti ticket they pertain to.
* tor-circmgr: Write tests for the HsPathBuilder.Gabriela Moldovan2024-06-202-0/+464
| | | | | | | These tests should give us *some* assurance that the upcoming `HsVanguardPathBuilder` refactoring doesn't break anything. Part of #1459
* tor-circmgr: Refactor duplicated circuit stub length calculation.Gabriela Moldovan2024-06-202-27/+26
| | | | Part of #1459
* tor-circmgr: Add a TODO about an unused restriction.Gabriela Moldovan2024-06-201-0/+5
|
* Remove semver.md files.Gabriela Moldovan2024-06-051-2/+0
| | | | The 1.2.4 release is out, so we won't be needing these anymore.
* Bump all the unstable tor- and arti- crates to 0.19.Gabriela Moldovan2024-06-051-22/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The unstable crates are: - tor-error - tor-config - tor-units - tor-geoip - tor-rtcompat - tor-rtmock - tor-log-ratelim - tor-rpcbase - tor-memquota - tor-llcrypto - tor-protover - tor-bytes - tor-hscrypto - tor-socksproto - tor-checkable - tor-cert - tor-linkspec - tor-cell - tor-proto - tor-netdoc - tor-consdiff - tor-netdir - tor-relay-selection - tor-persist - tor-chanmgr - tor-ptmgr - tor-guardmgr - tor-circmgr - tor-dirclient - tor-dirmgr - tor-keymgr - tor-hsclient - tor-hsservice - tor-hsrproxy - arti-client - arti-rpcserver - arti-hyper - tor-basic-utils - tor-async-utils Done using ``` for p in "${unstable[@]}"; do cargo set-version -p $p 0.19; done ``` where `unstable` contains the list above
* tor-circmgr: Explicitly handle all VanguardMode variants.Gabriela Moldovan2024-06-051-1/+10
| | | | This is less error-prone than the alternative.
* tor-circmgr: Reference a ticket number in a refactoring TODO.Gabriela Moldovan2024-06-051-1/+1
|
* tor-circmgr: Note that guard_and_target exclusion sometimes doesn't exclude ↵Gabriela Moldovan2024-06-051-0/+3
| | | | target.
* tor-circmgr: Exclude the target when extending SHORT stubs.Gabriela Moldovan2024-06-041-4/+18
| | | | | When extending SHORT circuit stubs, the last hop shouldn't be the same as the circuit target.
* tor-circmgr: Exclude the target relay when building vanguards circuits.Gabriela Moldovan2024-06-041-13/+71
| | | | | | Otherwise, some of the circuits will fail (because if the target is selected as one of the L2, L3, or M hops, it won't be able to extend the circuit to itself).
* tor-circmgr: Apply deferred fmt.Gabriela Moldovan2024-06-041-1/+3
|
* tor-circmgr: Add TODOs about improving circuit length checks.Gabriela Moldovan2024-06-041-0/+2
|
* tor-circmgr: Remove HsPool::vanguards_enabled() (fmt).Gabriela Moldovan2024-06-041-2/+10
|
* tor-circmgr: Remove HsPool::vanguards_enabled().Gabriela Moldovan2024-06-041-24/+33
| | | | | | | | | Previously, the HsCircPool had a bug that caused SHORT lite-vanguards circuits to be incorrectly extended by one hop when being repurposed as EXTENDED circuits (EXTENDED circuits only need to be extended by extra hop if full vanguards are in use). Closes #1456 and #1458
* tor-circmgr: Validate the circuit stub length before returning it.Gabriela Moldovan2024-06-041-8/+68
|
* Merge branch 'pick-path-fix' into 'main'gabi-2502024-06-041-12/+49
|\ | | | | | | | | | | | | tor-circmgr: Exclude the circ target when building paths. Closes #1425 See merge request tpo/core/arti!2179
| * tor-circmgr: If the path is invalid, display the offending hops in the error.Gabriela Moldovan2024-06-031-4/+5
| |
| * tor-circmgr: Ensure pick_path() builds paths with unique hops (fmt).Gabriela Moldovan2024-06-031-1/+5
| |
| * tor-circmgr: Ensure pick_path() builds paths with unique hops.Gabriela Moldovan2024-06-031-10/+24
| | | | | | | | | | We now return an internal error if the path we've just built contains the same hop in multiple positions.
| * tor-circmgr: Exclude the circ target when building paths.Gabriela Moldovan2024-06-031-2/+20
| | | | | | | | Closes #1425
* | tor-circmgr: Display the offending hop if the circuit is not compatible with ↵Gabriela Moldovan2024-06-031-4/+5
| | | | | | | | target.
* | tor-circmgr: Use has_any_relay_id_from to check for relay equality.Gabriela Moldovan2024-06-031-2/+2
| | | | | | | | | | | | | | When checking for relay equality, we are happy to accept some false positives (which result in building/selecting a different circuit). We want to be less tolerant of false negatives, to avoid accidentally using a circuit that doesn't have the properties we need.
* | tor-circmgr: Ensure circuit stubs are compatible with the target.Gabriela Moldovan2024-06-031-1/+39
|/ | | | | | This is a follow-up from !2167. It should prevent issues like #1417 from going unnoticed.
* tor-circmgr: Make retire_all_circuits unconditional.Gabi Moldovan2024-06-032-2/+0
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2168?commit_id=3c67fa55c7c5b0c4f30c1d57e8e67fe541d9c99e#note_3033368
* tor-circmgr: Log the kind of HS circuit stub we are selecting.Gabriela Moldovan2024-06-031-1/+7
|
* tor-circmgr: Remove VanguardMode from Pool (fmt).Gabriela Moldovan2024-06-032-6/+2
|
* tor-circmgr: Remove VanguardMode from Pool.Gabriela Moldovan2024-06-034-34/+20
| | | | | | | | | Storing the VanguardMode in multiple places (in the VanguardMgr *and* the HS circ Pool) is dangerous and can lead to split brain situations where different parts of the code think they are running in different VanguardModes. See #1424
* tor-circmgr: Remove dangerous vanguards_enabled() function.Gabriela Moldovan2024-06-032-9/+9
| | | | | | | `VanguardMgr` should be the source of truth for obtaining the current `VanguardMode`. Closes #1424
* tor-circmgr: Add a test to check that the pool uses the right VanguardMode.Gabriela Moldovan2024-06-031-0/+86
| | | | See arti#1424
* tor-circmgr: Ensure we don't select an incompatible circuit stub.Gabriela Moldovan2024-06-031-3/+19
| | | | | | | | | | | Previously, HS stub circuit selection (with vanguards enabled) was buggy: when selecting a circuit stub from the circ pool, we failed to ensure its last hop was different from the circuit target. So in some cases, arti would attempt to extend a stub circuit of the form G -> L2 [-> L3] -> T to T, which can't work, because a relay won't extend a circuit to itself (or to its predecessor, for that matter). Closes #1417
* tor-circmgr: Move vanguard circuit validation to a separate function.Gabriela Moldovan2024-06-031-1/+20
| | | | This will soon grow more complex.
* tor-circmgr: Return an error if HS circ has an invalid length.Gabriela Moldovan2024-06-031-4/+15
| | | | | | | | | | | | Previously, we'd `debug_assert` that the length of the path is valid. However, `debug_` asserts are compiled out for release builds, which means that if we have some code path that triggers the assertion failure, it will go unnoticed unless our tests happen to exercise it. It's safer to return an internal error, because we definitely don't want to proceed if the path is too short (see arti#1400 and arti#1409). Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2154#note_3030820
* tor-guardmgr: Replace From impl with VanguardConfig::mode accessor.Gabriela Moldovan2024-06-031-1/+1
|
* tor-guardmgr: Use ExplicitOrAuto in the VanguardConfigGabriela Moldovan2024-06-031-1/+1
|
* tor-guardmgr: Unconditionally define VanguardConfig.Gabriela Moldovan2024-06-033-5/+5
| | | | | | | | | We want to export the `VanguardConfig` even if the `vanguards` feature is disabled (we will need to unconditionally include it in the arti config). Note that if `vanguards` are disabled, the `VanguardMode` from the `VanguardConfig` can only be `Dsiabled`.
* tor-circmgr: Downgrade a HS-VANGUARDS TODO.Gabriela Moldovan2024-06-031-1/+1
|
* tor-circmgr: Fix a broken doc link.Gabriela Moldovan2024-05-161-1/+1
|