aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-guardmgr/src
Commit message (Collapse)AuthorAgeFilesLines
...
* Remove the use of Mutex in channel unused_since timestampYuan Lyu2022-02-081-5/+10
|
* Make SpawnError wrappers contain a 'spawning' stringNick Mathewson2022-02-041-11/+25
| | | | | (By our convention, these errors should say what we were trying to spawn when the error occurred.)
* errors: impl HasKind for GuardMgrErrorIan Jackson2022-02-041-0/+12
|
* spawn errors: tor-guardmgr: Use formulaic patternIan Jackson2022-02-041-2/+2
| | | | This makes this like all the others, and is marginally shorter
* tor_persist::Error: impl HasKind and adjust commentsIan Jackson2022-02-041-1/+2
| | | | | And change the comments to slightly reinterpret these errors, to relate to the circumstances rather than error generation site.
* Temporarily disable some clippy lints on nightlyIan Jackson2022-02-021-0/+1
|
* Merge branch 'ticket_176_v2' into 'main'Nick Mathewson2022-01-112-63/+144
|\ | | | | | | | | | | | | guardmgr: Use a better persistent data format Closes #176 See merge request tpo/core/arti!233
| * Remove now-unused GuardSet::new().Nick Mathewson2022-01-111-14/+8
| |
| * guardmgr: Use a better persistent data formatNick Mathewson2022-01-112-50/+137
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously we stored only one guard sample, in a state file called "default_guards". That's not future-proof, since we want to have multiple samples in the future. (`guard-spec.txt` specifies separate samples for highly restrictive filters, and for bridge usage.) This patch changes our behavior so that we can store multiple samples in a new "guards" file. I had thought about automatically migrating from the previous file format and location, but I don't think that's necessary given our current (lack of) stability guarantees. Closes #176.
* | guardmgr::..::sample_test: Fix intermittent failure.Nick Mathewson2022-01-111-3/+37
|/ | | | | | | | | | | | | | This test should only fail very rarely (around 1/2.4e8) when guards are chosen from a list of 20 with uniform probability. But that wasn't what we were doing on the mock test network: we were choosing from a list of 10 viable guards, with nonuniform probability. As a fix, we change the test network probabilities so that the guards _are_ chosen with a uniform probability for this test, and we use a modified version of the test network where there are indeed 20 Guard-flagged relays with the required DirCache=2 protocol. Closes #276.
* Tests for new guardmgr functionality.Nick Mathewson2022-01-062-0/+83
|
* Add API to check if primary MDs are missing.Nick Mathewson2022-01-063-2/+34
| | | | | | | We need this information to know if it's okay to migrate to a new NetDir, or if we need to download more information first. Part of #178.
* guardmgr: Don't use no-md guards for data circs.Nick Mathewson2022-01-061-5/+31
| | | | | | | If we don't know a current microdescriptor for a guard, we can't use it for multihop circuits, since we don't know its onion keys. This is part of a fix for #178.
* extend lints to include 'clippy::all'Daniel Eades2021-12-281-0/+1
|
* Remove unused started_at PendingRequestNeel Chauhan2021-12-142-12/+2
|
* Make TlsConnector wrap TCP connections, not create its owneta2021-12-071-1/+1
| | | | | | | | | | | | | | | | | | | | `tor-rtcompat`'s `TlsConnector` trait previously included a method to create a TLS-over-TCP connection, which implied creating a TCP stream inside that method. This commit changes that, and makes the function wrap a TCP stream, as returned from the runtime's `TcpProvider` trait implementation, instead. This means you can actually override `TcpProvider` and have it apply to *all* connections Arti makes, which is useful for issues like arti#235 and other cases where you want to have a custom TCP stream implementation. This required updating the mock TCP/TLS types in `tor-rtmock` slightly; due to the change in API, we now store whether a `LocalStream` should actually be a TLS stream inside the stream itself, and check this property on reads/writes in order to detect misuse. The fake TLS wrapper checks this property and removes it in order to "wrap" the stream, making reads and writes work again.
* Merge branch 'bug183a_redux' into 'main'eta2021-12-072-15/+49
|\ | | | | | | | | | | | | Squash, refactor, and test !139 (Don't use same family as exit when picking a guard) Closes #183 See merge request tpo/core/arti!173
| * Tests for new family-related functions.Nick Mathewson2021-12-061-0/+23
| |
| * Use hashset _inside_ GuardRestriction.Nick Mathewson2021-12-062-1/+4
| | | | | | | | This approach saves us from a linear search when picking guards.
| * Change GuardUsage to have Vec of restrictions.Nick Mathewson2021-12-062-32/+26
| | | | | | | | | | | | | | | | There's not much reason to use a HashSet here, since we're just going over the whole list. This reverts commit 16e8489abbea1581b8e2 and does a little more refactoring.
| * Implement guard family restriction codeNeel Chauhan2021-12-062-9/+23
| |
* | Resolve roughly half of the XXXXs.Nick Mathewson2021-12-061-1/+3
|/ | | | | | | | We want to only use TODO in the codebase for non-blockers, and open tickets for anything that is a bigger blocker than a TODO. These XXXXs seem like definite non-blockers to me. Part of arti#231.
* add semicolons if nothing returnedDaniel Eades2021-11-252-4/+5
|
* deglob some enums, use concise iteration syntaxDaniel Eades2021-11-251-6/+6
|
* More typo fixes that I forgot to save :(Nick Mathewson2021-11-241-3/+3
|
* Fix a clippy issue on nightlyNick Mathewson2021-11-241-0/+1
|
* Fix a few typos.Nick Mathewson2021-11-242-5/+5
| | | | Also fix some commonwealth spellings that had slipped in.
* Avoid a warning about retain_mut() in nightly.Nick Mathewson2021-11-231-2/+2
| | | | | | | Rust nightly claims that Vec might get its own retain_mut method, which would potentially conflict with the extension method we've grabbed from the retain_mut crate. To solve this, we're calling the method explicitly.
* Merge remote-tracking branch 'origin/mr/140'Nick Mathewson2021-11-231-1/+13
|\
| * Use guard-extreme-restriction-percentNeel Chauhan2021-11-231-3/+8
| |
| * In guard filtering code, warn if the filter is too small according to guard ↵Neel Chauhan2021-11-221-1/+8
| | | | | | | | params
* | Fix typo in tor-guardmgr comment related to suspicious guardsNeel Chauhan2021-11-221-1/+1
|/
* Move top-level configuration downwards from `arti` to `arti-config`.Nick Mathewson2021-11-181-0/+1
| | | | | | | | To do this at all neatly, I had to split out `tor-config` from `arti-config` again, and putting the lower level stuff (paths, builder errors) into tor-config. I also changed our use of derive_builder to always use a common error type, to avoid error type proliferation.
* Fix typosDimitris Apostolou2021-11-121-1/+1
|
* Remove all remaining dbg! instances.Nick Mathewson2021-11-041-2/+0
|
* Merge branch 'bug219'Nick Mathewson2021-11-023-63/+28
|\
| * Refactor tor-guardmgr's inter-task communication.Nick Mathewson2021-11-023-63/+28
| | | | | | | | | | | | | | | | | | This is based on @eta's patches for !118 and !119: Since we already have an unbounded channel, we don't need to use an elaborate mess of one-shot senders. We can just use the unbounded_send() method, which also lets us enqueue a message without having to await. Closes #219.
* | tor-circmgr: test ExitPathBuilder with guards.Nick Mathewson2021-11-021-0/+7
| |
* | tor-circmgr: test DirPathBuilder with GuardMgr.Nick Mathewson2021-11-021-1/+2
| |
* | Add a comment to explain the computation of net_has_been_down.Nick Mathewson2021-11-021-0/+5
| |
* | tor-guardmgr: Add tests for a few functions.Nick Mathewson2021-11-022-0/+57
| |
* | Mark primary guards as retriable when we come back online.Nick Mathewson2021-11-023-47/+63
|/ | | | | | | | | | | | We define "coming back online" as happening when a guard attempt succeeds, if that attempt that was launched when we seemed to be offline. We define "seeming to be offline" as having all of our primary guards marked unreachable, and having received no incoming network traffic in a while. Closes #216.
* Improve some documentation linksNick Mathewson2021-10-292-6/+6
| | | | | | | | | Instead of putting a fully qualified name in the text, in most cases we should just use the short name of the type or function we're referring to. In other words, instead of saying [`crate::module::Foo`], we should typically say [`Foo`](crate::module::Foo).
* Update our disclaimers and limitations sections.Nick Mathewson2021-10-271-0/+1
|
* Add Futureproof<T> wrapper type, use for GuardDisabled enumeta2021-10-271-6/+4
| | | | | | | | | | | The Futureproof<T> type lets you serialize and deserialize types whose representations might change (most useful for enums that might grow additional variants). It uses #[serde(untagged)] to accomplish this. This gets used in order to make the `disabled` field of `Guard` more robust against future guard disablement reasons being added. A test was also added to verify correct behaviour of the new type.
* Add #[serde(flatten)] HashMap fields to serializable objectseta2021-10-272-4/+20
| | | | | | | | | | As per arti#175, we'd like to be able to handle newer Arti versions storing additional state in the persisted state files, without dropping this data on the floor when we write out changes to these files. Use the #[serde(flatten)] mechanism to achieve this, by adding catch-all HashMap<String, JsonValue> fields to all structs that are at risk of this happening to them.
* Avoid a strange borrow syntax in tor_guardmgr::sampleNick Mathewson2021-10-261-3/+3
| | | | I'm not sure what I was thinking here.
* Do not blame a guard for failures on non-random circuits.Nick Mathewson2021-10-261-3/+30
| | | | | | | | | We must not apply our new path-bias behavior (where we blame a guard if it gives us too many indeterminate circuit failures) if the path was not chosen at random. If too many random paths fail, we know that's suspicious, since the other relays are a random sample. But if a bunch of user-provided paths fail, that could simply be because the user's chosen exit is down.
* Implement a "lightweight" form of pathbias detection.Nick Mathewson2021-10-263-5/+193
| | | | | | | | | | | | | | | | | | | | | | | | | | | We now track, for every guard: the total number of successful circuits we've built through it, along with the total number of "indeterminate" circuits. Recall that a circuit's status is "indeterminate" if it has failed for a reason that _might_ be the guard's fault, or might not be the guard's fault. For example, if extending to the second hop of the circuit fails, we have no way to know whether the guard deliberately refused to connect there, or whether the second hop is just offline. But we don't want to forgive all indeterminate circuit failures: if we did, then a malicious guard could simply reject any second hops that it didn't like, thereby filtering the client into a chosen set of circuits. As a stopgap solution, this patch now makes guards become permanently disabled if the fraction of their circuit failures becomes too high. See also general-purpose path bias selection (arti#65), and Mike's idea for changing the guard reachability definition (torspec#67). This patch doesn't do either of those. Closes #185.
* guardmgr: Don't use guards that are marked as unlisted.Nick Mathewson2021-10-252-7/+22
| | | | Closes #202.