summaryrefslogtreecommitdiff
path: root/crates/tor-netdir/src
Commit message (Collapse)AuthorAgeFilesLines
* Fix a rustdoc link in tor-netdir.Nick Mathewson2022-07-261-1/+1
|
* tor-netdir: Remove latest_netdir method.Nick Mathewson2022-07-261-10/+0
|
* Add new APIs to NetDirProvider to better support timeliness.Nick Mathewson2022-07-262-3/+78
| | | | | | | | | | | | | | | | | Over the years we've found that most callers who want a netdir want what C Tor calls a "reasonably live" network directory: One that is not expired by too much, or too far in the future. But a few want a _strictly_ live directory: one that says it is valid now, with no tolerances. And a few want _any_ directory, no matter how expired it is. This commit adds net methods to NetDirProvider to provide these directories. I think that most use cases will want to explicitly think about what kind of directory they want, so I've made `netdir` the simplest method. I might remove `timely_netdir` by the end of this branch; see TODO comments. Part of #518.
* netdir: Make pick() functions take FnMut closures.Nick Mathewson2022-07-121-2/+2
| | | | | | There's no reason to enforce their being Fn closures, and allowing them to be FnMut allows us to count which filters make us rejected given relays.
* Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-231-0/+3
| | | | Update all lint blocks
* channel padding: Use IntegerMilliseconds in netdirIan Jackson2022-06-211-8/+8
|
* tor-netdir: Make CHANNEL_PADDING_TIMEOUT_UPPER_BOUND pubIan Jackson2022-06-211-1/+1
| | | | We need this because it is a type parameter for the types of nf_ito_*.
* channel padding: Change timeout to match C TorIan Jackson2022-06-211-1/+6
| | | | Pending an official value from the spec.
* channel padding: Add the parameters from the spec to NetDirIan Jackson2022-06-211-0/+28
|
* Remove some outdated comments.Nick Mathewson2022-06-171-1/+1
| | | | | These all say, in one form or another, "there is no guard filtering; there is only one selection". That's now false.
* tor-netdir: testnet: Make construct_netdir infallibleIan Jackson2022-06-132-5/+5
| | | | | This is a *lot* of unwraps. The function takes no parameters and is used only for testing. It ought to be infallible.
* Merge branch 'use-testing-rng'Nick Mathewson2022-06-073-75/+37
|\
| * Rewrite tests in tor-netdir to use testing_rng()Nick Mathewson2022-06-022-76/+35
| | | | | | | | | | | | | | | | | | | | | | The randomized tests in this crate take a lot of iterations to converge, so they default to using a deterministic PRNG seed with few iterations and higher tolerance, and they only randomize the tests (with more iterations and tighter tolerances) when you explicitly opt in to randomization. (If you specify a seed explicitly, you're doing that to reproduce a randomized case, so we use the same behavior.)
| * Use testing_rng() in tests throughout our crates.Nick Mathewson2022-06-022-1/+4
| | | | | | | | | | | | This only affects uses of thread_rng(), and affects them all more or less indiscriminately. One test does not work with ARTI_TEST_PRNG=deterministic; the next commit will fix it.
* | Make NetDirProvider require Send and Sync.Nick Mathewson2022-06-071-1/+1
| | | | | | | | | | | | | | | | Our own code is the only stuff that consumes NetDirProvider, and all the code that consumes it wants it to be Send and Sync. Making this change avoids our having to define a new function to upcast Arc<dyn Foo> to Arc<dyn NetDirProvider + Send + Sync>.
* | Add an upcast_arc function to NetDirProvider.Nick Mathewson2022-06-021-1/+27
| | | | | | | | | | | | | | | | This uses some apparently-standard trickery to implement a function that lets us upcast from Arc<dyn Subtrait> to Arc<dyn Supertrait>. I considered as alternatives `as_dyn_trait` and `cast_dyn_object`. Both were nice, but generated a far larger interface than this.
* | lints: Add let_unit_value allow to all cratesIan Jackson2022-05-311-0/+1
| | | | | | | | | | From running add_warning, with manual picking of the right hunks/lines.
* | lints: Add lint block delimiters to every crateIan Jackson2022-05-311-0/+2
|/ | | | | | This was the result of: maint/add_warning crates/*/src/{lib,main}.rs and then manually curating the results.
* Resolve the new `derive_partial_eq_without_eq` lint.Nick Mathewson2022-05-231-1/+1
| | | | It's a little overzealous sometimes, but it's mostly to the good.
* Fix grammar and typosSamanta Navarro2022-04-271-1/+1
|
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-251-2/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* Move fallback.rs into guardmgr.Nick Mathewson2022-03-302-87/+0
| | | | | | | This is the logical place for it, I think: the GuardMgr's job is to pick the first hop for a circuit depending on remembered status for possible first hops. Making this change will let us streamline the code that interacts with these objects.
* Merge branch 'disallowed_lint' into 'main'eta2022-03-302-2/+0
|\ | | | | | | | | Remove allow(clippy::disallowed_methods) lint flag. See merge request tpo/core/arti!437
| * Remove allow(clippy::disallowed_methods) lint.Nick Mathewson2022-03-302-2/+0
| |
* | Make daemon tasks self-contained; introduce NetDirProvidereta2022-03-301-0/+50
|/ | | | | | | | | | | | | | | The various background daemon tasks that `arti-client` used to spawn are now handled inside their respective crates instead, with functions provided to spawn them that return `TaskHandle`s. This required introducing a new trait, `NetDirProvider`, which steals some functionality from the `DirProvider` trait to enable `tor-circmgr` to depend on it (`tor-circmgr` is a dependency of `tor-dirmgr`, so it can't depend on `DirProvider` directly). While we're at it, we also make some of the tasks wait for events from the `NetDirProvider` instead of sleeping, slightly increasing efficiency.
* Merge branch 'no-system-time' into 'main'eta2022-03-302-0/+2
|\ | | | | | | | | | | | | Don't use SystemTime::now() Closes #306 See merge request tpo/core/arti!365
| * use wallclock where possible in teststrinity-1686a2022-02-262-0/+2
| |
* | netdir: Use an even smaller rep for list of microdescsNick Mathewson2022-03-161-55/+29
| | | | | | | | | | | | | | Every time we want a microdescriptor, we know the index of that microdesc's corresponding routerstatus within the consensus. Therefore, we can use that index to store `Arc<Microdesc>`s in a dense array, and not have to use a HashSet here at all.
* | tor-dirmgr: Remove redundant hashtable.Nick Mathewson2022-03-161-0/+8
| | | | | | | | | | | | | | | | | | We were using a hashtable to keep track of missing microdescriptor digests. But this information is redundant with the NetDir state, and there's now no longer any performance benefit to keeping a separate copy. Part of #386.
* | NetDir: Use less space in hash tablesNick Mathewson2022-03-161-61/+35
| | | | | | | | | | | | | | | | | | | | | | | | | | We previously kept missing-MD entries and present-MD entries all in the same HashSet, which resulted in using more slack space than we need. Now we use separate tables, so we can drop missing-MD entries as we move forward. Also, when constructing a NetDir, set its hash tables to their final capacities. This also lets us simplify some of our missing-md-listing code a lot.
* | Derive Deserialize for derive-builder-generated config buildersIan Jackson2022-03-071-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | I used git-grep -P '\#\[serde\((?!default|deny_unknown)' to find places where I needed to add additional attributes on the builder method fields. This is currently a bit duplicative, but when #371 is completely done, the validated (non-builder) configs won't need to be Deserialize any more. This is part of #371 and #372.
* | Disable clippy::clone_on_ref_ptrIan Jackson2022-02-241-1/+0
|/ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This lint is IMO inherently ill-conceived. I have looked for the reasons why this might be thought to be a good idea and there were basically two (and they are sort of contradictory): I. "Calling ‘.clone()` on an Rc, Arc, or Weak can obscure the fact that only the pointer is being cloned, not the underlying data." This is the wording from https://rust-lang.github.io/rust-clippy/v0.0.212/#clone_on_ref_ptr It is a bit terse; we are left to infer why it is a bad idea to obscure this fact. It seems to me that if it is bad to obscure some fact, that must be because the fact is a hazard. But why would it be a hazard to not copy the underlying data ? In other languages, faliing to copy the underlying data is a serious correctness hazard. There is a whose class of bugs where things were not copied, and then mutated and/or reused in multiple places in ways that were not what the programmer intended. In my experience, this is a very common bug when writing Python and Javascript. I'm told it's common in golang too. But in Rust this bug is much much harder to write. The data inside an Arc is immutable. To have this bug you'd have use interior mutability - ie mess around with Mutex or RefCell. That provides a good barrier to these kind of accidents. II. "The reason for writing Rc::clone and Arc::clone [is] to make it clear that only the pointer is being cloned, as opposed to the underlying data. The former is always fast, while the latter can be very expensive depending on what is being cloned." This is the reasoning found here https://github.com/rust-lang/rust-clippy/issues/2048 This is saying that *not* using Arc::clone is hazardous. Specifically, that a deep clone is a performance hazard. But for this argument, the lint is precisely backwards. It's linting the "good" case and asking for it to be written in a more explicit way; while the supposedly bad case can be written conveniently. Also, many objects (in our codebase, and in all the libraries we use) that are Clone are in fact simply handles. They contain Arc(s) (or similar) and are cheap to clone. Indeed, that is the usual case. It does not make sense to distinguish in the syntax we use to clone such a handle, whether the handle is a transparent Arc, or an opaque struct containing one or more other handles. Forcing Arc::clone to be written as such makes for code churn when a type is changed from Arc<Something> to Something: Clone, or vice versa.
* tor-netdir: Split testnet errors into a new typeNick Mathewson2022-02-152-13/+9
| | | | | There's no reason to have the test-network-construction code share an error enum with the main netdir code.
* tor-netdir: remove unused error variantsNick Mathewson2022-02-151-19/+0
| | | | | This turns out to have been most of them, which simplifies matters a lot.
* Merge branch 'doc-errors' into 'main'Nick Mathewson2022-02-151-0/+4
|\ | | | | | | | | Refactor errors in tor-netdoc See merge request tpo/core/arti!314
| * netdoc: Make doc-build errors a separate typeNick Mathewson2022-02-141-0/+4
| | | | | | | | | | Every other case of tor_netdoc::Error means a parse failure. This one, though, means a failure to construct a document.
* | Change deny(clippy::all) to warn(clippy::all).Nick Mathewson2022-02-141-1/+1
|/ | | | Closes #338.
* extend lints to include 'clippy::all'Daniel Eades2021-12-281-0/+1
|
* Merge branch 'reconfigure' into 'main'eta2021-12-131-0/+18
|\ | | | | | | | | Make most arti-client fields reconfigurable. See merge request tpo/core/arti!181
| * Make override_net_params take effect sooner.Nick Mathewson2021-12-071-0/+18
| | | | | | | | | | This is still not as soon as I'd like: a real change here will require refactoring DirMgr::notify().
* | tor-netdir: Resolve an XXXX about type uglinessNick Mathewson2021-12-082-5/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We had no function to infallibly convert BoundedInt32<{0 or 1},H> into a u32, even though we could have. Because of that, we were treating weight_scale as an i32 when logically it's a u32 or a NonZeroU32. Moreover, it turns out we were using an incorrect minimum for the bwweightscale param, which would in theory have allowed the authorities to make us divide by zero. This patch introduces the necessary From<> implementation and uses it. It corrects the binimum bwweightscale, and prevents a division-by-zero issue in case weight_scale is zero.
* | Remove a couple of spec-related XXXXs in tor-netdir.Nick Mathewson2021-12-081-2/+0
|/ | | | | I've opened torspec!54 to fill in the missing parts of the spec about these issues.
* Merge branch 'bug183a_redux' into 'main'eta2021-12-071-0/+60
|\ | | | | | | | | | | | | Squash, refactor, and test !139 (Don't use same family as exit when picking a guard) Closes #183 See merge request tpo/core/arti!173
| * Tests for new family-related functions.Nick Mathewson2021-12-061-0/+35
| |
| * Move the "real families" code into tor-netdir.Nick Mathewson2021-12-061-6/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Just as `in_same_family` is a member of Relay, so the function for getting all the real family members of a relay should belong in the same crate. This change also removes the `family()` accessor: it gives the _claimed_ family rather than the _acknlowedged_ family, and is therefore a bit dangerous. There's still a hole in this logic; I've noted it in the Limitations section. If we get a microdescriptor for a relay in between creating and using the guard restriction, it might be omitted from the family list.
| * Implement guard family restriction codeNeel Chauhan2021-12-061-0/+6
| |
* | tor-netdir: Use reproducible RNG in tests.Nick Mathewson2021-12-061-5/+2
|/ | | | | | The rand crate's documentation says it's not okay to rely on StdRng having reproducible output. So instead, let's switch to ChaCha12Rng instead (which is what StrRng currently uses).
* tor-netdir: Use bitflags for WeightKindNeel Chauhan2021-11-301-34/+49
|
* Merge remote-tracking branch 'origin/mr/151'Nick Mathewson2021-11-301-12/+0
|\
| * Remove unused tap_onion_key and tap_keyNeel Chauhan2021-11-281-12/+0
| |