aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-netdir
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'clippy-allow-arc-clone' into 'main'Nick Mathewson2022-03-011-1/+0
|\ | | | | | | | | Disable clippy::clone_on_ref_ptr See merge request tpo/core/arti!352
| * Disable clippy::clone_on_ref_ptrIan Jackson2022-02-241-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This lint is IMO inherently ill-conceived. I have looked for the reasons why this might be thought to be a good idea and there were basically two (and they are sort of contradictory): I. "Calling ‘.clone()` on an Rc, Arc, or Weak can obscure the fact that only the pointer is being cloned, not the underlying data." This is the wording from https://rust-lang.github.io/rust-clippy/v0.0.212/#clone_on_ref_ptr It is a bit terse; we are left to infer why it is a bad idea to obscure this fact. It seems to me that if it is bad to obscure some fact, that must be because the fact is a hazard. But why would it be a hazard to not copy the underlying data ? In other languages, faliing to copy the underlying data is a serious correctness hazard. There is a whose class of bugs where things were not copied, and then mutated and/or reused in multiple places in ways that were not what the programmer intended. In my experience, this is a very common bug when writing Python and Javascript. I'm told it's common in golang too. But in Rust this bug is much much harder to write. The data inside an Arc is immutable. To have this bug you'd have use interior mutability - ie mess around with Mutex or RefCell. That provides a good barrier to these kind of accidents. II. "The reason for writing Rc::clone and Arc::clone [is] to make it clear that only the pointer is being cloned, as opposed to the underlying data. The former is always fast, while the latter can be very expensive depending on what is being cloned." This is the reasoning found here https://github.com/rust-lang/rust-clippy/issues/2048 This is saying that *not* using Arc::clone is hazardous. Specifically, that a deep clone is a performance hazard. But for this argument, the lint is precisely backwards. It's linting the "good" case and asking for it to be written in a more explicit way; while the supposedly bad case can be written conveniently. Also, many objects (in our codebase, and in all the libraries we use) that are Clone are in fact simply handles. They contain Arc(s) (or similar) and are cheap to clone. Indeed, that is the usual case. It does not make sense to distinguish in the syntax we use to clone such a handle, whether the handle is a transparent Arc, or an opaque struct containing one or more other handles. Forcing Arc::clone to be written as such makes for code churn when a type is changed from Arc<Something> to Something: Clone, or vice versa.
* | Bump all crates to 0.1.0arti-v0.1.0Nick Mathewson2022-03-011-9/+9
|/
* tor-netdir: Split testnet errors into a new typeNick Mathewson2022-02-152-13/+9
| | | | | There's no reason to have the test-network-construction code share an error enum with the main netdir code.
* tor-netdir: remove unused error variantsNick Mathewson2022-02-151-19/+0
| | | | | This turns out to have been most of them, which simplifies matters a lot.
* Merge branch 'doc-errors' into 'main'Nick Mathewson2022-02-151-0/+4
|\ | | | | | | | | Refactor errors in tor-netdoc See merge request tpo/core/arti!314
| * netdoc: Make doc-build errors a separate typeNick Mathewson2022-02-141-0/+4
| | | | | | | | | | Every other case of tor_netdoc::Error means a parse failure. This one, though, means a failure to construct a document.
* | Change deny(clippy::all) to warn(clippy::all).Nick Mathewson2022-02-141-1/+1
|/ | | | Closes #338.
* Bump tor-netdir and tor-guardmgr versionsarti-v0.0.4Nick Mathewson2022-01-311-1/+1
| | | | | | | | tor-netdir needs to bump because tor-netdoc bumped, even though there were no other changes in tor-netdir. Whoops. tor-guardmgr needs to bump because it already published, with the older tor-netdir.
* Bump the patch version of every crate that changed since 0.0.3Nick Mathewson2022-01-311-3/+3
|
* Bump all crate versions to 0.0.3.Nick Mathewson2022-01-111-9/+9
|
* Minimize the required version for each dependency.Nick Mathewson2022-01-071-13/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I found these versions empirically, by using the following process: First, I used `cargo tree --depth 1 --kind all` to get a list of every immediate dependency we had. Then, I used `cargo upgrade --workspace package@version` to change each dependency to the earliest version with which (in theory) the current version is semver-compatible. IOW, if the current version was 3.2.3, I picked "3". If the current version was 0.12.8, I picked "0.12". Then, I used `cargo +nightly upgrade -Z minimal-versions` to downgrade Cargo.lock to the minimal listed version for each dependency. (I had to override a few packages; see .gitlab-ci.yml for details). Finally, I repeatedly increased the version of each of our dependencies until our code compiled and the tests passed. Here's what I found that we need: anyhow >= 1.0.5: Earlier versions break our hyper example. async-broadcast >= 0.3.2: Earlier versions fail our tests. async-compression 0.3.5: Earlier versions handled futures and tokio differently. async-trait >= 0.1.2: Earlier versions are too buggy to compile our code. clap 2.33.0: For Arg::default_value_os(). coarsetime >= 0.1.20: exposed as_ticks() function. curve25519-dalek >= 3.2: For is_identity(). generic-array 0.14.3: Earlier versions don't implement From<&[T; 32]> httparse >= 1.2: Earlier versions didn't implement Error. itertools at 0.10.1: For at_most_once. rusqlite >= 0.26.3: for backward compatibility with older rustc. serde 1.0.103: Older versions break our code. serde_json >= 1.0.50: Since we need its Value type to implement Eq. shellexpand >= 2.1: To avoid a broken dirs crate version. tokio >= 1.4: For Handle::block_on(). tracing >= 0.1.18: Previously, tracing_core and tracing had separate LevelFilter types. typenum >= 1.12: Compatibility with rust-crypto crates x25519-dalek >= 1.2.0: For was_contributory(). Closes #275.
* extend lints to include 'clippy::all'Daniel Eades2021-12-281-0/+1
|
* Merge branch 'reconfigure' into 'main'eta2021-12-131-0/+18
|\ | | | | | | | | Make most arti-client fields reconfigurable. See merge request tpo/core/arti!181
| * Make override_net_params take effect sooner.Nick Mathewson2021-12-071-0/+18
| | | | | | | | | | This is still not as soon as I'd like: a real change here will require refactoring DirMgr::notify().
* | tor-netdir: Resolve an XXXX about type uglinessNick Mathewson2021-12-082-5/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We had no function to infallibly convert BoundedInt32<{0 or 1},H> into a u32, even though we could have. Because of that, we were treating weight_scale as an i32 when logically it's a u32 or a NonZeroU32. Moreover, it turns out we were using an incorrect minimum for the bwweightscale param, which would in theory have allowed the authorities to make us divide by zero. This patch introduces the necessary From<> implementation and uses it. It corrects the binimum bwweightscale, and prevents a division-by-zero issue in case weight_scale is zero.
* | Remove a couple of spec-related XXXXs in tor-netdir.Nick Mathewson2021-12-081-2/+0
| | | | | | | | | | I've opened torspec!54 to fill in the missing parts of the spec about these issues.
* | Upgrade to digest v0.10.0Nick Mathewson2021-12-071-1/+1
|/ | | | | We generally try to track the latest rust-crypto traits when we can: fortunately, this upgrade didn't break much, considering.
* Merge branch 'bug183a_redux' into 'main'eta2021-12-071-0/+60
|\ | | | | | | | | | | | | Squash, refactor, and test !139 (Don't use same family as exit when picking a guard) Closes #183 See merge request tpo/core/arti!173
| * Tests for new family-related functions.Nick Mathewson2021-12-061-0/+35
| |
| * Move the "real families" code into tor-netdir.Nick Mathewson2021-12-061-6/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Just as `in_same_family` is a member of Relay, so the function for getting all the real family members of a relay should belong in the same crate. This change also removes the `family()` accessor: it gives the _claimed_ family rather than the _acknlowedged_ family, and is therefore a bit dangerous. There's still a hole in this logic; I've noted it in the Limitations section. If we get a microdescriptor for a relay in between creating and using the guard restriction, it might be omitted from the family list.
| * Implement guard family restriction codeNeel Chauhan2021-12-061-0/+6
| |
* | tor-netdir: Use reproducible RNG in tests.Nick Mathewson2021-12-062-5/+3
|/ | | | | | The rand crate's documentation says it's not okay to rely on StdRng having reproducible output. So instead, let's switch to ChaCha12Rng instead (which is what StrRng currently uses).
* tor-netdir: Use bitflags for WeightKindNeel Chauhan2021-11-302-34/+50
|
* Merge remote-tracking branch 'origin/mr/151'Nick Mathewson2021-11-301-12/+0
|\
| * Remove unused tap_onion_key and tap_keyNeel Chauhan2021-11-281-12/+0
| |
* | Bump every crate by one patch version.Nick Mathewson2021-11-291-9/+9
| |
* | add semicolons if nothing returnedDaniel Eades2021-11-253-2/+3
| |
* | deglob some enums, use concise iteration syntaxDaniel Eades2021-11-251-2/+2
|/
* More typo fixes that I forgot to save :(Nick Mathewson2021-11-242-3/+3
|
* Fix a few typos.Nick Mathewson2021-11-241-1/+1
| | | | Also fix some commonwealth spellings that had slipped in.
* Make every Config type implement Eq.Nick Mathewson2021-11-211-1/+1
| | | | | Doing this is necessary for reconfiguration support, and will help a lot with testing, too.
* Document (and allow) behavior for weird values of subnet masks.Nick Mathewson2021-11-181-2/+10
| | | | Chutney needs this, to avoid putting every relay in the same family.
* Use named fields for the elements of ConfigBuildErrorNick Mathewson2021-11-181-4/+4
|
* Flatten enforce_distance into path_rules.Nick Mathewson2021-11-181-5/+13
| | | | Also use the path_rules name consistently throughout the code.
* Move top-level configuration downwards from `arti` to `arti-config`.Nick Mathewson2021-11-182-3/+8
| | | | | | | | To do this at all neatly, I had to split out `tor-config` from `arti-config` again, and putting the lower level stuff (paths, builder errors) into tor-config. I also changed our use of derive_builder to always use a common error type, to avoid error type proliferation.
* Fix typosDimitris Apostolou2021-11-121-1/+1
|
* Document that the "experimental-api" feature is not semver-covered.Nick Mathewson2021-11-111-0/+5
|
* Document that the "testing" feature is not semver-covered.Nick Mathewson2021-11-111-0/+3
|
* Bump all crate versions to 0.0.1Nick Mathewson2021-10-291-8/+8
|
* Run "cargo fix --edition-idioms=2018".Nick Mathewson2021-10-221-1/+1
|
* Replace references to arti-client in the documentation.Nick Mathewson2021-10-211-1/+1
|
* Allow type of timeout estimator to change at runtime.Nick Mathewson2021-10-201-0/+9
| | | | | | This is a big change, but it does simplify the type of Builder a little, and isolates locking across different (potential) timeout estimator types.
* Fix a documentation link error.Nick Mathewson2021-10-131-4/+2
|
* Add a function to look up a Relay by ChanTarget.Nick Mathewson2021-10-111-0/+8
|
* Re-export configuration types from tor-client.Nick Mathewson2021-10-091-0/+5
|
* enable checked_conversions lint.Nick Mathewson2021-10-091-0/+1
|
* Initial backend implementation for guard node manager.Nick Mathewson2021-10-072-11/+30
| | | | | | | There are some missing parts here (like persistence and tests) and some incorrect parts (I am 90% sure that the "exploratory circuit" flag is bogus). Also it is not integrated with the circuit manager code.
* Update total_weight to use UncheckedRelay.Nick Mathewson2021-10-071-3/+7
|
* Make UncheckedRelay public in tor-netdir.Nick Mathewson2021-10-071-4/+4
| | | | This will let us provide a couple of better APIs for use in tor-guardmgr