summaryrefslogtreecommitdiff
path: root/crates/tor-guardmgr/src/lib.rs
Commit message (Collapse)AuthorAgeFilesLines
* Update our disclaimers and limitations sections.Nick Mathewson2021-10-271-0/+1
|
* Implement a "lightweight" form of pathbias detection.Nick Mathewson2021-10-261-1/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | We now track, for every guard: the total number of successful circuits we've built through it, along with the total number of "indeterminate" circuits. Recall that a circuit's status is "indeterminate" if it has failed for a reason that _might_ be the guard's fault, or might not be the guard's fault. For example, if extending to the second hop of the circuit fails, we have no way to know whether the guard deliberately refused to connect there, or whether the second hop is just offline. But we don't want to forgive all indeterminate circuit failures: if we did, then a malicious guard could simply reject any second hops that it didn't like, thereby filtering the client into a chosen set of circuits. As a stopgap solution, this patch now makes guards become permanently disabled if the fraction of their circuit failures becomes too high. See also general-purpose path bias selection (arti#65), and Mike's idea for changing the guard reachability definition (torspec#67). This patch doesn't do either of those. Closes #185.
* Merge branch 'share_state'Nick Mathewson2021-10-211-11/+39
|\
| * Implement the guard side of shared state directories.Nick Mathewson2021-10-211-2/+18
| |
| * Finish the timeout-inference side of shared state.Nick Mathewson2021-10-201-2/+19
| |
| * Replace the return type of StorageMgr::try_lock with a tristateNick Mathewson2021-10-201-1/+1
| | | | | | | | | | It's useful to know now only if we now have the lock, but also if we just got it for the first time.
| * Initial work on periodically reloading state.Nick Mathewson2021-10-191-11/+6
| | | | | | | | | | We can use this in the case where we don't get the lock on the state file, because another process is running.
* | Fix most warnings from nightly.Nick Mathewson2021-10-191-0/+1
|/ | | | (One represents code that I forgot to write.)
* Use better reporting for guard status.Nick Mathewson2021-10-131-2/+2
| | | | | | | | | | | | | The previous code would report all failures to build a circuit as failures of the guard. But of course that's not right: If we fail to extend to the second or third hop, that might or might not be the guard's fault. Now we use the "pending status" feature of the GuardMonitor type so that an early failure is attributed to the guard, but a later failure is attributed as "Indeterminate". Only a complete circuit is called a success. We use a new "GuardStatusHandle" type here so that we can report the status early if there is a timeout.
* Rename GuardStatusMsg, make it public, add an `Indeterminate` case.Nick Mathewson2021-10-131-5/+5
|
* Actually select guards for directory circuits.Nick Mathewson2021-10-131-1/+2
|
* Make the guard selection function return a more useful type.Nick Mathewson2021-10-111-4/+43
|
* Change the GuardMgr APIs to no longer be async.Nick Mathewson2021-10-101-32/+18
|
* Use an mpsc::unbounded() channel in GuardMgr.Nick Mathewson2021-10-101-24/+18
| | | | | | | | | | | | The advantage here is that we no longer have to use a futures-aware Mutex, or a blocking send operation, and therefore can simplify a bunch of the GuardMgr APIs to no longer be async. That'll avoid having to propagate the asyncness up the stack. The disadvantage is that unbounded channels are just that: nothing in the channel prevents us from overfilling it. Fortunately, the process that consumes from the channel shouldn't block much, and the channel only gets filled when we're planning a circuit path.
* enable checked_conversions lint.Nick Mathewson2021-10-091-0/+1
|
* Normalize tor-guardmgr warningsNick Mathewson2021-10-091-6/+6
|
* Note a possible heisenbug in a unit test.Nick Mathewson2021-10-081-0/+6
|
* Add a few tracing calls to tor-guardmgr.Nick Mathewson2021-10-081-5/+28
|
* Resolve small issues and XXXX/TODO comments in GuardMgr.Nick Mathewson2021-10-071-29/+39
| | | | | By the time I merge this, most of the comments should have tickets to go with them.
* Tests for top-level GuardMgr.Nick Mathewson2021-10-071-4/+144
| | | | | | | Also, refactor our message handling to be more like the tor_proto reactors. The previous code had a bug where, once the stream of events was exhausted, we wouldn't actually get any more notifications.
* Implement persistent state for guard mgrNick Mathewson2021-10-071-9/+25
|
* Initial backend implementation for guard node manager.Nick Mathewson2021-10-071-0/+800
There are some missing parts here (like persistence and tests) and some incorrect parts (I am 90% sure that the "exploratory circuit" flag is bogus). Also it is not integrated with the circuit manager code.