summaryrefslogtreecommitdiff
path: root/crates/tor-guardmgr/src/guard.rs
Commit message (Collapse)AuthorAgeFilesLines
* Fix some Rustdoc links.Nick Mathewson2022-03-301-1/+1
|
* Refactor FirstHopId into type-differentiated formNick Mathewson2022-03-301-35/+29
| | | | | | | | | | | The FirstHopId type now records an enum that stores whether the hop is a guard or a fallback. This change addresses concerns about remembering to check the type or source of an Id before passing it down to the FallbackState or GuardSet. Making this change required an API change, so that dirmgr can report success/failure status without actually knowing whether it's using a fallback or a guard.
* Rename Guard=>FirstHop, GuardId=>FirstHopIdNick Mathewson2022-03-301-13/+21
| | | | | This is preparation for having separate GuardId and FirstHopId types that distinguish which back-end they index.
* Remove allow(clippy::disallowed_methods) lint.Nick Mathewson2022-03-301-6/+0
|
* Merge branch 'no-system-time' into 'main'eta2022-03-301-2/+9
|\ | | | | | | | | | | | | Don't use SystemTime::now() Closes #306 See merge request tpo/core/arti!365
| * use wallclock where possible in teststrinity-1686a2022-02-261-2/+9
| |
* | GuardMgr:: generalize GuardId::from_relay.Nick Mathewson2022-03-211-1/+5
| |
* | GuardMgr: revise handling of "all guards are down".Nick Mathewson2022-03-211-0/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When all guards are down, we would previously mark them all as up, and retry aggressively. But that's far too aggressive: if there's something wrong with our ability to connect to guards, it makes us hammer the network over and over, ignoring all the guard retry timeouts in practice. Instead, * We now allow the `pick_guard()` function to fail without automatically retrying. * We give different errors in the cases when all our guards are down, and when all of the guards selected by our active usage are down. * Our "guards are down" error includes the time at which a guard will next be retriable. This is part of #407.
* | GuardMgr: use decorrelated-jitter backoff for retrying guards.Nick Mathewson2022-03-211-80/+34
| | | | | | | | | | | | | | | | | | | | | | | | C tor used one schedule, and guard-spec specified another. But in reality we should probably use a randomized schedule to retry guards, for the reasons explained in the documentation for RetrySchedule. I've chosen the minima to be not too far from our previous minima for primary and non-primary guards. This is part of #407.
* | Replace manual Default impls with educe in tor-guardmgrIan Jackson2022-03-021-7/+4
|/
* Tests for new guardmgr functionality.Nick Mathewson2022-01-061-0/+51
|
* Add API to check if primary MDs are missing.Nick Mathewson2022-01-061-1/+11
| | | | | | | We need this information to know if it's okay to migrate to a new NetDir, or if we need to download more information first. Part of #178.
* guardmgr: Don't use no-md guards for data circs.Nick Mathewson2022-01-061-5/+31
| | | | | | | If we don't know a current microdescriptor for a guard, we can't use it for multihop circuits, since we don't know its onion keys. This is part of a fix for #178.
* Tests for new family-related functions.Nick Mathewson2021-12-061-0/+23
|
* Use hashset _inside_ GuardRestriction.Nick Mathewson2021-12-061-0/+1
| | | | This approach saves us from a linear search when picking guards.
* Change GuardUsage to have Vec of restrictions.Nick Mathewson2021-12-061-25/+13
| | | | | | | | There's not much reason to use a HashSet here, since we're just going over the whole list. This reverts commit 16e8489abbea1581b8e2 and does a little more refactoring.
* Implement guard family restriction codeNeel Chauhan2021-12-061-6/+20
|
* Fix a clippy issue on nightlyNick Mathewson2021-11-241-0/+1
|
* Fix a few typos.Nick Mathewson2021-11-241-3/+3
| | | | Also fix some commonwealth spellings that had slipped in.
* Fix typo in tor-guardmgr comment related to suspicious guardsNeel Chauhan2021-11-221-1/+1
|
* Remove all remaining dbg! instances.Nick Mathewson2021-11-041-2/+0
|
* tor-guardmgr: Add tests for a few functions.Nick Mathewson2021-11-021-0/+18
|
* Add Futureproof<T> wrapper type, use for GuardDisabled enumeta2021-10-271-6/+4
| | | | | | | | | | | The Futureproof<T> type lets you serialize and deserialize types whose representations might change (most useful for enums that might grow additional variants). It uses #[serde(untagged)] to accomplish this. This gets used in order to make the `disabled` field of `Guard` more robust against future guard disablement reasons being added. A test was also added to verify correct behaviour of the new type.
* Add #[serde(flatten)] HashMap fields to serializable objectseta2021-10-271-2/+8
| | | | | | | | | | As per arti#175, we'd like to be able to handle newer Arti versions storing additional state in the persisted state files, without dropping this data on the floor when we write out changes to these files. Use the #[serde(flatten)] mechanism to achieve this, by adding catch-all HashMap<String, JsonValue> fields to all structs that are at risk of this happening to them.
* Implement a "lightweight" form of pathbias detection.Nick Mathewson2021-10-261-4/+178
| | | | | | | | | | | | | | | | | | | | | | | | | | | We now track, for every guard: the total number of successful circuits we've built through it, along with the total number of "indeterminate" circuits. Recall that a circuit's status is "indeterminate" if it has failed for a reason that _might_ be the guard's fault, or might not be the guard's fault. For example, if extending to the second hop of the circuit fails, we have no way to know whether the guard deliberately refused to connect there, or whether the second hop is just offline. But we don't want to forgive all indeterminate circuit failures: if we did, then a malicious guard could simply reject any second hops that it didn't like, thereby filtering the client into a chosen set of circuits. As a stopgap solution, this patch now makes guards become permanently disabled if the fraction of their circuit failures becomes too high. See also general-purpose path bias selection (arti#65), and Mike's idea for changing the guard reachability definition (torspec#67). This patch doesn't do either of those. Closes #185.
* guardmgr: Don't use guards that are marked as unlisted.Nick Mathewson2021-10-251-0/+5
| | | | Closes #202.
* Implement the guard side of shared state directories.Nick Mathewson2021-10-211-0/+14
|
* Remove Guard::get_relay(); use Guard::guard_id().get_relay().Nick Mathewson2021-10-191-12/+4
| | | | | | | | | The `get_relay` function was confusing, since it would return None if the relay was present, but wasn't actually a guard. We only used it in one place, and in that one place we used it wrong, leading to a panic bug. Fixes #193.
* Make the guard selection function return a more useful type.Nick Mathewson2021-10-111-0/+8
|
* Add a few tracing calls to tor-guardmgr.Nick Mathewson2021-10-081-5/+26
|
* Resolve small issues and XXXX/TODO comments in GuardMgr.Nick Mathewson2021-10-071-1/+1
| | | | | By the time I merge this, most of the comments should have tickets to go with them.
* Initial tests for tor_guardmgr::guardNick Mathewson2021-10-071-0/+295
|
* Initial backend implementation for guard node manager.Nick Mathewson2021-10-071-0/+481
There are some missing parts here (like persistence and tests) and some incorrect parts (I am 90% sure that the "exploratory circuit" flag is bogus). Also it is not integrated with the circuit manager code.