aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-guardmgr/src/vanguards.rs
Commit message (Collapse)AuthorAgeFilesLines
* maint: Run maint/add_warning to deny string slicesClara Engler2026-06-091-0/+1
| | | | | | | | | | | | This commit executes maint/add_warning with the just added change to deny string slices except in tests. I recommend auditing this by checking out the previous commit followed by running the script yourself and then verifying that the diff is identical to this commit. This commit makes cargo clippy fail. We will add exceptions in the next commit.
* Upgrade rand crates to 0.10.Wesley Aptekar-Cassels2026-05-121-2/+1
| | | | | | | | | | | When the circ-padding feature is enabled, we use maybenot, which does not yet support rand 0.10. In the meantime, enabling this feature pulls in rand 0.9. This is not ideal, but should be okay as a temporary situation. This also replaces the use of ReseedingRng (which was removed in 0.10) with the reseeding_rng crate. This is somewhat less performant, but it should be okay.
* opentelemetry: Instrument a bunch of functions.Wesley Aptekar-Cassels2025-11-241-1/+2
| | | | | These are all aimed at figuring out in more detail what's going on in #2079 and related issues.
* Fix name of clippy lint to unchecked_time_subtraction (2)Ian Jackson2025-11-061-1/+1
| | | | Run maint/add_warning
* all: run cargo fmtSteven Engler2025-11-041-1/+1
|
* all: replace all uses of `futures::task::SpawnExt` with `tor_rtcompat::SpawnExt`Steven Engler2025-11-041-1/+1
|
* Switch Cargo.toml files to edition 2024.Nick Mathewson2025-08-071-9/+13
| | | | | | | | | | | | | | First, run ``` git grep -l "^edition =" | xargs perl -i -pe 's/^edition *=.*/edition = "2024"/;' ``` Second, manually verify that all Cargo.toml files have changed, and nothing else has changed. Third, run cargo fmt again.
* Typo fixes (automatic and hand-verified)Nick Mathewson2025-07-091-1/+1
| | | | Made with https://crates.io/crates/typos-cli
* guardmgr, circmgr: Make vanguard selection take a RelaySelector.Nick Mathewson2025-05-201-18/+24
| | | | | | This is the preferred type for choosing a relay, since unlike a RelayExclusion, it lets us add multiple restrictions, and a relay usage.
* Upgrade to derive_more version 1.0.0Nick Mathewson2024-09-251-2/+2
| | | | | | The `derive_more` crate broke backward compatibility with this version, so this change involved quite a few manual fixups. With luck, they'll keep compatibility for some while in the future.
* tor-netdir: Allow access to the `ConsensusBuilder` when building test netdirs.Gabriela Moldovan2024-09-091-3/+3
| | | | | This allows us to set SRVs for example (needed because by default, the test `NetDir` is built from a consensus that doesn't contain any SRVs).
* Fix typosDimitris Apostolou2024-09-031-1/+1
|
* tor-guardmgr: Make some vanguard test helpers public (fmt).Gabriela Moldovan2024-06-201-10/+5
|
* tor-guardmgr: Make some vanguard test helpers public.Gabriela Moldovan2024-06-201-50/+67
| | | | | | We will soon need these helpers outside of `tor-guardmgr` too. This commit is mainly code motion.
* tor-guardmgr: Add test for vanguards state file deserialization.Gabriela Moldovan2024-06-031-2/+104
| | | | This checks that we can read `vanguards.json` state files.
* tor-guardmgr: Replace From impl with VanguardConfig::mode accessor.Gabriela Moldovan2024-06-031-3/+2
|
* tor-guardmgr: Use ExplicitOrAuto in the VanguardConfig (fmt).Gabriela Moldovan2024-06-031-2/+8
|
* tor-guardmgr: Use ExplicitOrAuto in the VanguardConfigGabriela Moldovan2024-06-031-5/+7
|
* tor-guardmgr: Unconditionally define VanguardConfig.Gabriela Moldovan2024-06-031-1/+2
| | | | | | | | | We want to export the `VanguardConfig` even if the `vanguards` feature is disabled (we will need to unconditionally include it in the arti config). Note that if `vanguards` are disabled, the `VanguardMode` from the `VanguardConfig` can only be `Dsiabled`.
* tor-guardmgr: Add an error variant for when the vanguard mode is unsuitable.Gabriela Moldovan2024-05-091-7/+14
|
* tor-guardmgr: Return a BootstrapRequired error if all the sets are empty (fmt).Gabriela Moldovan2024-05-091-1/+6
|
* tor-guardmgr: Return a BootstrapRequired error if all the sets are empty.Gabriela Moldovan2024-05-091-14/+22
| | | | | | | | | Previously, `select_vanguard` returned a `NoSuitableRelay` error if it was unable to select a relay to use as a vanguard. We now distunguish the "there are no suitable relays in the vanguard sets" (`NoSuitableRelays`) error case from the "our vanguard sets are empty" (`BootstrapRequired`) one.
* tor-guardmgr: Fix typo in documentation.Gabriela Moldovan2024-05-091-1/+1
|
* tor-guardmgr: Move VanguardMgrError to a separate module.Gabriela Moldovan2024-05-091-40/+4
| | | | | This is about to grow another variant, so I'm moving it to a dedicated `err` module.
* tor-guardmgr: Remove a nonsensical TODO.Gabriela Moldovan2024-05-091-1/+0
| | | | | | The `match` below it is fine, there's no need to rewrite it. (I think this TODO is actually dupe of the the TODO above it).
* tor-guardmgr: Remove unnecessary clippy allow.Gabriela Moldovan2024-05-091-1/+0
|
* tor-guardmgr: Make remove_expired return the number of expired vanguards.Gabriela Moldovan2024-04-301-3/+2
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2109#note_3024672
* tor-guardmgr: Prevent misleading logs when not rotating vanguards.Gabriela Moldovan2024-04-291-2/+5
| | | | | `rotate_expired()` now only logs that it is rotating the vanguards if some existing vanguards have actually expired.
* tor-guardmgr: Make a vanguard log message more accurate.Gabriela Moldovan2024-04-291-1/+1
| | | | | We flush every time the vanguards may have changed, but we don't know for sure if they did.
* tor-guardmgr: Make the VanguardMgr tests pass again.Gabriela Moldovan2024-04-291-14/+29
| | | | | The tests need to be updated now that the `VanguardMode` is read from the config rather than the consensus.
* tor-guardmgr: Temporarily reintroduce VanguardConfig.Gabriela Moldovan2024-04-291-35/+66
| | | | | | | | | | | | | | As discussed on #tor-dev, I'm reintroducing `VanguardConfig` for now. The `VanguardConfig` specifies what mode (full/lite/disabled) the `VanguardMgr` should run in. We currently don't have a separate modes for HS clients and HS services. We shouldn't actually *need* a `VanguardConfig` at all, so this is just a (hopefully!) short- or medium-term fix until we sort out #1382 (which might involve making breaking changes to our `reconfigure()` APIs). Closes #1272
* tor-guardmgr: Remove unnecessary clippy allows.Gabriela Moldovan2024-04-291-4/+0
| | | | None of these should be unused anymore.
* tor-guardmgr: Remove unnecessary VanguardSetsTrackedMut contraption (fmt).Gabriela Moldovan2024-04-221-1/+2
|
* tor-guardmgr: Remove unnecessary VanguardSetsTrackedMut contraption.Gabriela Moldovan2024-04-221-14/+9
| | | | | | | | The VanguardMgr now unconditionally flushes the vanguard sets to disk each time there's a consensus change, and every time a vanguard expires. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2090#note_3021013
* tor-guardmgr: Remove pick_{l2,l3}_relay, add l2(), l3() accessors (fmt).Gabriela Moldovan2024-04-221-20/+19
|
* tor-guardmgr: Remove pick_{l2,l3}_relay, add l2(), l3() accessors.Gabriela Moldovan2024-04-221-2/+4
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2090#note_3021016
* tor-guardmgr: Make vanguard logs begin with an uppercase letter for consistency.Gabriela Moldovan2024-04-221-3/+3
| | | | | Our log messages begin with an uppercase letter in the rest of the code base.
* tor-guardmgr: Add logging around vanguard rotation.Gabriela Moldovan2024-04-221-0/+2
|
* tor-guardmgr: Add a TODO about rethinking vanguard flushing.Gabriela Moldovan2024-04-221-0/+14
|
* tor-guardmgr: Rename VanguardMgr::handle_netdir_update for clarity (fmt).Gabriela Moldovan2024-04-221-2/+1
|
* tor-guardmgr: Rename VanguardMgr::handle_netdir_update for clarity.Gabriela Moldovan2024-04-221-9/+6
|
* tor-guardmgr: Test that vanguards are written to persistent storage.Gabriela Moldovan2024-04-221-1/+137
|
* tor-guardmgr: Fix vanguard doc links.Gabriela Moldovan2024-04-221-4/+4
| | | | The referenced types are no longer available in `vanguards.rs`.
* tor-guardmgr: Select an L3 vanguard in a vanguard test.Gabriela Moldovan2024-04-221-4/+3
|
* tor-guardmgr: Allow running VanguardMgr in "service mode" in the tests.Gabriela Moldovan2024-04-221-7/+7
| | | | We will soon use this to test full vanguards.
* tor-guardmgr: Load the vanguards from disk on startup.Gabriela Moldovan2024-04-221-7/+26
| | | | | | The `VanguardMgr` reads the vanguards from the vanguards state file, whether full vanguards are enabled or not. It only persists the vanguard sets to storage if full vanguards are in use.
* tor-guardmgr: Flush the vanguard changes to disk (fmt).Gabriela Moldovan2024-04-221-1/+2
|
* tor-guardmgr: Flush the vanguard changes to disk.Gabriela Moldovan2024-04-221-3/+8
|
* tor-guardmgr: Implement VanguardMgr::flush_to_storage.Gabriela Moldovan2024-04-221-10/+15
|
* tor-guardmgr: Fix vanguard expiration test.Gabriela Moldovan2024-04-221-1/+18
| | | | | | | | | | | | | | | | Since `rotate_expired()` (previously `remove_expired()`) now also replenishes the vanguard sets, we can't use `advance_until_stalled()` anymore, because `run_once()` is never be stalled in the tests (`next_to_expire` is never `None`, so `sleep_fut` is never `future::pending()`: ``` warning: MockRuntime advance_* looped >1000 (next sleep: 877560507ms) ``` Previously, `next_to_expire` was computed *before* replenishing the vanguard sets, which is why the tests could use `advance_until_stalled()`.