summaryrefslogtreecommitdiff
path: root/crates/tor-guardmgr
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'readme_fixes'Nick Mathewson2021-11-301-1/+1
|\
| * run ./maint/readmes.shdagon2021-11-291-1/+1
| |
* | Bump every crate by one patch version.Nick Mathewson2021-11-291-13/+13
| |
* | add semicolons if nothing returnedDaniel Eades2021-11-252-4/+5
| |
* | deglob some enums, use concise iteration syntaxDaniel Eades2021-11-251-6/+6
|/
* More typo fixes that I forgot to save :(Nick Mathewson2021-11-241-3/+3
|
* Fix a clippy issue on nightlyNick Mathewson2021-11-241-0/+1
|
* Fix a few typos.Nick Mathewson2021-11-242-5/+5
| | | | Also fix some commonwealth spellings that had slipped in.
* Avoid a warning about retain_mut() in nightly.Nick Mathewson2021-11-231-2/+2
| | | | | | | Rust nightly claims that Vec might get its own retain_mut method, which would potentially conflict with the extension method we've grabbed from the retain_mut crate. To solve this, we're calling the method explicitly.
* Merge remote-tracking branch 'origin/mr/140'Nick Mathewson2021-11-231-1/+13
|\
| * Use guard-extreme-restriction-percentNeel Chauhan2021-11-231-3/+8
| |
| * In guard filtering code, warn if the filter is too small according to guard ↵Neel Chauhan2021-11-221-1/+8
| | | | | | | | params
* | Fix typo in tor-guardmgr comment related to suspicious guardsNeel Chauhan2021-11-221-1/+1
|/
* Move top-level configuration downwards from `arti` to `arti-config`.Nick Mathewson2021-11-182-0/+2
| | | | | | | | To do this at all neatly, I had to split out `tor-config` from `arti-config` again, and putting the lower level stuff (paths, builder errors) into tor-config. I also changed our use of derive_builder to always use a common error type, to avoid error type proliferation.
* Fix typosDimitris Apostolou2021-11-121-1/+1
|
* Document that the "testing" feature is not semver-covered.Nick Mathewson2021-11-111-0/+3
|
* Remove all remaining dbg! instances.Nick Mathewson2021-11-041-2/+0
|
* Merge branch 'bug219'Nick Mathewson2021-11-023-63/+28
|\
| * Refactor tor-guardmgr's inter-task communication.Nick Mathewson2021-11-023-63/+28
| | | | | | | | | | | | | | | | | | This is based on @eta's patches for !118 and !119: Since we already have an unbounded channel, we don't need to use an elaborate mess of one-shot senders. We can just use the unbounded_send() method, which also lets us enqueue a message without having to await. Closes #219.
* | tor-circmgr: test ExitPathBuilder with guards.Nick Mathewson2021-11-022-0/+11
| |
* | tor-circmgr: test DirPathBuilder with GuardMgr.Nick Mathewson2021-11-021-1/+2
| |
* | Add a comment to explain the computation of net_has_been_down.Nick Mathewson2021-11-021-0/+5
| |
* | tor-guardmgr: Add tests for a few functions.Nick Mathewson2021-11-022-0/+57
| |
* | Mark primary guards as retriable when we come back online.Nick Mathewson2021-11-024-47/+64
|/ | | | | | | | | | | | We define "coming back online" as happening when a guard attempt succeeds, if that attempt that was launched when we seemed to be offline. We define "seeming to be offline" as having all of our primary guards marked unreachable, and having received no incoming network traffic in a while. Closes #216.
* Bump all crate versions to 0.0.1Nick Mathewson2021-10-291-11/+11
|
* Improve some documentation linksNick Mathewson2021-10-292-6/+6
| | | | | | | | | Instead of putting a fully qualified name in the text, in most cases we should just use the short name of the type or function we're referring to. In other words, instead of saying [`crate::module::Foo`], we should typically say [`Foo`](crate::module::Foo).
* Update our disclaimers and limitations sections.Nick Mathewson2021-10-272-0/+2
|
* Add Futureproof<T> wrapper type, use for GuardDisabled enumeta2021-10-271-6/+4
| | | | | | | | | | | The Futureproof<T> type lets you serialize and deserialize types whose representations might change (most useful for enums that might grow additional variants). It uses #[serde(untagged)] to accomplish this. This gets used in order to make the `disabled` field of `Guard` more robust against future guard disablement reasons being added. A test was also added to verify correct behaviour of the new type.
* Add #[serde(flatten)] HashMap fields to serializable objectseta2021-10-272-4/+20
| | | | | | | | | | As per arti#175, we'd like to be able to handle newer Arti versions storing additional state in the persisted state files, without dropping this data on the floor when we write out changes to these files. Use the #[serde(flatten)] mechanism to achieve this, by adding catch-all HashMap<String, JsonValue> fields to all structs that are at risk of this happening to them.
* Avoid a strange borrow syntax in tor_guardmgr::sampleNick Mathewson2021-10-261-3/+3
| | | | I'm not sure what I was thinking here.
* Do not blame a guard for failures on non-random circuits.Nick Mathewson2021-10-261-3/+30
| | | | | | | | | We must not apply our new path-bias behavior (where we blame a guard if it gives us too many indeterminate circuit failures) if the path was not chosen at random. If too many random paths fail, we know that's suspicious, since the other relays are a random sample. But if a bunch of user-provided paths fail, that could simply be because the user's chosen exit is down.
* Implement a "lightweight" form of pathbias detection.Nick Mathewson2021-10-263-5/+193
| | | | | | | | | | | | | | | | | | | | | | | | | | | We now track, for every guard: the total number of successful circuits we've built through it, along with the total number of "indeterminate" circuits. Recall that a circuit's status is "indeterminate" if it has failed for a reason that _might_ be the guard's fault, or might not be the guard's fault. For example, if extending to the second hop of the circuit fails, we have no way to know whether the guard deliberately refused to connect there, or whether the second hop is just offline. But we don't want to forgive all indeterminate circuit failures: if we did, then a malicious guard could simply reject any second hops that it didn't like, thereby filtering the client into a chosen set of circuits. As a stopgap solution, this patch now makes guards become permanently disabled if the fraction of their circuit failures becomes too high. See also general-purpose path bias selection (arti#65), and Mike's idea for changing the guard reachability definition (torspec#67). This patch doesn't do either of those. Closes #185.
* guardmgr: Don't use guards that are marked as unlisted.Nick Mathewson2021-10-252-7/+22
| | | | Closes #202.
* Merge branch 'share_state'Nick Mathewson2021-10-213-11/+62
|\
| * Implement the guard side of shared state directories.Nick Mathewson2021-10-213-2/+41
| |
| * Finish the timeout-inference side of shared state.Nick Mathewson2021-10-201-2/+19
| |
| * Replace the return type of StorageMgr::try_lock with a tristateNick Mathewson2021-10-201-1/+1
| | | | | | | | | | It's useful to know now only if we now have the lock, but also if we just got it for the first time.
| * Initial work on periodically reloading state.Nick Mathewson2021-10-191-11/+6
| | | | | | | | | | We can use this in the case where we don't get the lock on the state file, because another process is running.
* | Fix most warnings from nightly.Nick Mathewson2021-10-192-0/+2
|/ | | | (One represents code that I forgot to write.)
* Remove Guard::get_relay(); use Guard::guard_id().get_relay().Nick Mathewson2021-10-191-12/+4
| | | | | | | | | The `get_relay` function was confusing, since it would return None if the relay was present, but wasn't actually a guard. We only used it in one place, and in that one place we used it wrong, leading to a panic bug. Fixes #193.
* Use better reporting for guard status.Nick Mathewson2021-10-132-2/+8
| | | | | | | | | | | | | The previous code would report all failures to build a circuit as failures of the guard. But of course that's not right: If we fail to extend to the second or third hop, that might or might not be the guard's fault. Now we use the "pending status" feature of the GuardMonitor type so that an early failure is attributed to the guard, but a later failure is attributed as "Indeterminate". Only a complete circuit is called a success. We use a new "GuardStatusHandle" type here so that we can report the status early if there is a timeout.
* Rename GuardStatusMsg, make it public, add an `Indeterminate` case.Nick Mathewson2021-10-133-26/+43
|
* Actually select guards for directory circuits.Nick Mathewson2021-10-131-1/+2
|
* Make the guard selection function return a more useful type.Nick Mathewson2021-10-113-4/+56
|
* Change the GuardMgr APIs to no longer be async.Nick Mathewson2021-10-101-32/+18
|
* Use an mpsc::unbounded() channel in GuardMgr.Nick Mathewson2021-10-102-29/+22
| | | | | | | | | | | | The advantage here is that we no longer have to use a futures-aware Mutex, or a blocking send operation, and therefore can simplify a bunch of the GuardMgr APIs to no longer be async. That'll avoid having to propagate the asyncness up the stack. The disadvantage is that unbounded channels are just that: nothing in the channel prevents us from overfilling it. Fortunately, the process that consumes from the channel shouldn't block much, and the channel only gets filled when we're planning a circuit path.
* enable checked_conversions lint.Nick Mathewson2021-10-091-0/+1
|
* Normalize tor-guardmgr warningsNick Mathewson2021-10-091-6/+6
|
* Note a possible heisenbug in a unit test.Nick Mathewson2021-10-081-0/+6
|
* Add a few tracing calls to tor-guardmgr.Nick Mathewson2021-10-083-17/+74
|