summaryrefslogtreecommitdiff
path: root/crates/tor-guardmgr
Commit message (Collapse)AuthorAgeFilesLines
...
* fallback list: Move default list into tor-guardmgrIan Jackson2022-04-223-0/+1729
| | | | | | | | | | This is where the FallbackList type is. We are going to want to provide a builder too, which ought to impl Default. This means that the default value for the type must be next to the type. In any case, it was anomalous that it wasn't. This commit is pure code motion.
* arti-client: Report clock skew when it is noteworthyNick Mathewson2022-04-121-0/+5
| | | | | (Also, blame clock skew when it is an explanation of why we cannot finish a connection.)
* circmgr: re-export clock skew estimates.Nick Mathewson2022-04-122-0/+4
|
* GuardMgr: publish skew estimates.Nick Mathewson2022-04-123-9/+86
| | | | | | Instead of just having a function that recalculates the latest clock skew, instead recalculate the clock skew when it may have changed, and notify other processes via a postage::watch.
* guardmgr: fix a unit test panic.Nick Mathewson2022-04-111-1/+5
| | | | | | | Apparently on OSX you are not allowed to construct an Instant that is a long time before the time when the test is running. Also, fix the length of a year in this test.
* Fold FallbackStatus into Entry.Nick Mathewson2022-04-111-44/+31
| | | | This simplifies the code a lot.
* Add a couple of TODO items to clock-skew estimator.Nick Mathewson2022-04-111-0/+7
|
* Implement a better clock skew estimator.Nick Mathewson2022-04-112-16/+308
| | | | | | | | This time, our estimator discards outliers, takes the mean of what's left, and uses the standard deviation to try to figure out how seriously to take our report of skew/not-skew. These estimates are still not actually used.
* Initial functions to determine and expose a clock skew estimate.Nick Mathewson2022-04-076-1/+111
| | | | | (This is just a placeholder; I'm going to make the functions smarter in the next commit.)
* Reformat tor-guardmgr/Cargo.tomlNick Mathewson2022-04-071-12/+12
|
* GuardMgr: record clock skew information.Nick Mathewson2022-04-076-22/+106
| | | | (It is not yet actually used.)
* Create and use API to report guard/fallback skew.Nick Mathewson2022-04-072-3/+17
| | | | (The information is not yet recorded.)
* Merge branch 'main' into 'separate_dir_status'Nick Mathewson2022-04-061-0/+24
|\ | | | | | | # Conflicts: # doc/semver_status.md
| * guardmgr: implement HasRetryTime.Nick Mathewson2022-04-041-0/+24
| |
* | Fix a rustdoc linkNick Mathewson2022-04-051-5/+5
| |
* | GuardMgr: Tests for copy_status_from.Nick Mathewson2022-04-052-0/+65
| |
* | GuardMgr: Tests for note_external_{success,failure}.Nick Mathewson2022-04-051-0/+57
| |
* | Rewrite and fix Guard::copy_status_from.Nick Mathewson2022-04-053-21/+45
| | | | | | | | | | | | | | | | | | | | | | | | | | | | The old version of this function was error-prone, and in fact had errors: it was too easy to forget to add non-persistent fields, and that's exactly what we forgot in a few cases (`microdescriptor_missing`, `circ_history`, and `suspicious_behavior_warned`). The new version of this function consumes both of the incoming Guards, and constructs every field explicitly so that we can't forget to list any. Closes #429.
* | GuardMgr: Track directory status and circuit status separately.Nick Mathewson2022-04-054-69/+235
| | | | | | | | | | | | | | | | | | | | | | | | | | Previously, we treated successfully building a circuit to a guard as a "success", and any failure, including a directory cache failure, as a failure. With this change, guards now have separate success/failure and retry status for circuit usage and directory usage. This change is needed for guard-as-directory retry to have reasonable behavior. Otherwise, when a guard succeeds at building a circuit, that clears the directory-is-failing status and makes us retry the guards to quickly.
* | Allow DirStatus objects to have different timeout floorsNick Mathewson2022-04-042-21/+24
| | | | | | | | This will help when we give Guards a DirStatus as well.
* | Rename fallback::status::Status to DirStatus.Nick Mathewson2022-04-044-13/+13
|/ | | | It's about to be shared between fallbacks and guards.
* Bump all arti*, tor* crates to 0.2.0Nick Mathewson2022-04-011-16/+16
| | | | | | | | Not all of these strictly need to be bumped to 0.2.0; many could go to 0.1.1 instead. But since everything at the tor-rtcompat and higher layers has had breaking API changes, it seems not so useful to distinguish. (It seems unlikely that anybody at this stage is depending on e.g. tor-protover but not arti-client.)
* Use derive_more to derive AsRef.Nick Mathewson2022-03-302-12/+4
|
* Reformat tor-guardmgr/Cargo.toml.Nick Mathewson2022-03-301-18/+18
|
* Fix some Rustdoc links.Nick Mathewson2022-03-304-5/+5
|
* Refactor FirstHopId into type-differentiated formNick Mathewson2022-03-307-169/+322
| | | | | | | | | | | The FirstHopId type now records an enum that stores whether the hop is a guard or a fallback. This change addresses concerns about remembering to check the type or source of an Id before passing it down to the FallbackState or GuardSet. Making this change required an API change, so that dirmgr can report success/failure status without actually knowing whether it's using a fallback or a guard.
* Rename Guard=>FirstHop, GuardId=>FirstHopIdNick Mathewson2022-03-306-70/+84
| | | | | This is preparation for having separate GuardId and FirstHopId types that distinguish which back-end they index.
* FallbackState: Use itertools::merge_join_by.Nick Mathewson2022-03-301-100/+8
| | | | | This replaces a hand-coded replacement that was probably a little less efficient.
* Fold fallback::Status::reset() into its (only) caller.Nick Mathewson2022-03-301-7/+2
|
* Rename FallbackState::lookup_mut => get_mut.Nick Mathewson2022-03-301-12/+12
|
* Rename FallbackSet => FallbackState.Nick Mathewson2022-03-303-15/+15
|
* Refactor select_guard_with_expand to use match and log errors.Nick Mathewson2022-03-301-10/+13
|
* ListKind: Use an exhaustive match to future-proof.Nick Mathewson2022-03-301-1/+4
|
* Clarify documentation about GuardUsable constructorsNick Mathewson2022-03-301-4/+10
|
* Add a TODO about an unslightly type.Nick Mathewson2022-03-301-0/+2
|
* Clean up a rustdoc linkIan Jackson2022-03-301-1/+1
|
* guardmgr::fallback::set: basic unit tests.Nick Mathewson2022-03-301-10/+190
|
* Rename ExternalFailure => ExternalActivity.Nick Mathewson2022-03-302-11/+10
|
* Replace the fallback directories when they change in the config.Nick Mathewson2022-03-302-0/+122
| | | | | | The code here uses a new iterator type, since I couldn't find one of these on crates.io. I tried writing the code without it, but it was harder to follow and test.
* Add status tracking to FallbackDir.Nick Mathewson2022-03-305-24/+260
| | | | | | | | | | | We do this by creating a new FallbackSet type that includes status information, and updating the GuardMgr APIs to record success and failure about it when appropriate. We can use this to mark FallbackDirs retriable (or not). With this change, FallbackDir is now stored internally as a Guard in the GuardMgr crate. That's fine: the FallbackDir type really only matters for configuration.
* GuardMgr: Return fallback directories when appropriate.Nick Mathewson2022-03-301-26/+67
| | | | | | | | | | | We only do this when we fail to get a regular guard (e.g., because they're all down), and when we have been asked for a guard for a one-hop directory. Most of the change in this commit is plumbing to make all of the types match up. As before, compilation may still be broken.
* Fix typos in guardmgr/lib.rsNick Mathewson2022-03-301-2/+2
|
* GuardMgr: some prep work for returning fallbacks as guards.Nick Mathewson2022-03-303-4/+40
| | | | | | | | | We need to extend our notion of "the origin of a guard" to include "somewhere outside the guard list"; we need the ability to return a FallbackDir as a Guard; and we need to remember a few more pieces of information in each pending request. As before, this commit may break compilation; it will be restored soon.
* Turn FallbackList into a real type, and store one in GuardMgr.Nick Mathewson2022-03-304-5/+85
| | | | | | | | | | | | | | The guard manager is responsible for handing out the first hops of tor circuits, keeping track of their successes and failures, and remembering their states. Given that, it makes sense to store this information here. It is not yet used; I'll be fixing that in upcoming commits. Arguably, this information no longer belongs in the directory manager: I've added a todo about moving it. This commit will break compilation on its own in a couple of places; subsequent commits will fix it up.
* guardmgr: move error types into new err.rs module.Nick Mathewson2022-03-303-73/+79
| | | | This is more in keeping with the rest of our code.
* Move fallback.rs into guardmgr.Nick Mathewson2022-03-302-0/+87
| | | | | | | This is the logical place for it, I think: the GuardMgr's job is to pick the first hop for a circuit depending on remembered status for possible first hops. Making this change will let us streamline the code that interacts with these objects.
* Remove allow(clippy::disallowed_methods) lint.Nick Mathewson2022-03-303-18/+0
|
* Merge branch 'no-system-time' into 'main'eta2022-03-303-6/+28
|\ | | | | | | | | | | | | Don't use SystemTime::now() Closes #306 See merge request tpo/core/arti!365
| * use wallclock where possible in teststrinity-1686a2022-02-263-6/+28
| |
* | GuardMgr:: generalize GuardId::from_relay.Nick Mathewson2022-03-213-6/+10
| |