summaryrefslogtreecommitdiff
path: root/crates/tor-proto/src/circuit.rs
Commit message (Collapse)AuthorAgeFilesLines
* Allow clippy::unchecked_duration_subtraction in testsNick Mathewson2023-01-271-0/+1
| | | | | This panics on error, and we're fine with a panic on misbehavior in tests.
* tor-proto: comment fixes and more TODO hsNick Mathewson2023-01-241-0/+12
|
* tor-proto: Draft API to handle incoming BEGIN requests.Nick Mathewson2023-01-171-0/+26
| | | | Onion services (and later, exits and caches) will need this.
* tor-proto: Expose support for doing onion service handshakesNick Mathewson2023-01-171-0/+28
| | | | | | This is a little tricky, but I think that we're not actually exposing too much here. I expect we'll need to tweak this stuff between now and our final version.
* tor-proto: Draft APIs for handling control messagesNick Mathewson2023-01-171-0/+52
| | | | | We will need these for onion services, to send and receive messages of types not handled directly by the tor-proto crate.
* tor-proto: CreateFastWrap::decode_chanmsg: Do not report handshakeIan Jackson2023-01-061-2/+2
| | | | | The debug impl prints the handshake challenge, which we should probably treat as sensitive.
* Merge branch 'test-lints' into 'main'eta2023-01-061-0/+8
|\ | | | | | | | | Add test lint blocks to all "mod test" See merge request tpo/core/arti!937
| * test lint blocks: Add many many automaticallyIan Jackson2022-12-121-0/+8
| | | | | | | | | | This is precisely the result of running the rune in maint/adhoc-add-lint-blocks.
* | msg::{CreateFast/CreatedFast}: Rename accessor to (into_)body()Neel Chauhan2022-12-181-2/+2
|/
* tor-linkspec: Remove the old OwnedFoo::new() functionsNick Mathewson2022-10-061-5/+12
| | | | These are now builders.
* Final (?) API revisions for tor-linkspecNick Mathewson2022-08-101-4/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With this change, each individual identity type becomes optional. The functions that expose them unconditionally are now in a "legacy" trait that only some downstream types are expected to implement. There are new convenience APIs in HasRelayIds: * to return Option<&keytype>, * to see if one identity-set contains another. This commit will break several downstream crates! For the reviewer's convenience, I will put the fixes for those crates into a series of squash! commits on this one. tor-netdir ---------- Revise tor-netdir to accept optional identities. This required some caveats and workarounds about the cases where we have to deal with a key type that the tor-netdir code does not currently recognize at all. If we start to add more identity types in the future, we may well want more internal indices in this code. tor-proto --------- In order to make tor-proto support optional identities, there were fewer changes than I thought. Some "check" functions needed to start looking at "all the ids we want" rather than at "the two known IDs"; they also needed to accommodate that case where we don't have an ID that we demand. This change will also help with bridges, since we want to be able to connect to a bridge without knowing all of its IDs up front. The protocol currently _requires_ the two current ID types in some places. To deal with that, I added a new `MissingId` error. I also removed a couple of unconditional identity accessors for chanmgr; code should use `target().identity(...)` instead. tor-chanmgr ----------- This is an incomplete conversion: it does not at all handle channel targets without Ed25519 identities yet. It still uses those identities to index its internal map from identity to channel; but it gives a new `MissingId` error type if it's given a channel target that doesn't have one. We'll want to revise the map type again down the road when we implement bridges, but I'd rather not step on the channel-padding work in progress right now. tor-guardmgr ------------ This change is mostly a matter of constructing owned identity types more sensibly, rather than unwrapping them directly. There are some places marked with TODOs where we still depend on particular identity types, because of how the directory protocol works. This will need revisiting when we add bridge support here. tor-circmgr ----------- These changes are just relatively simple API changes in the tests.
* tor-linkspec: Refactor out traits to represent a relay's ID set.Nick Mathewson2022-08-021-1/+1
| | | | | | | | | | | | | | We want the set of identities supported by a relay to be extensible in the future with minimal fuss; we'd also like to make working with these ID sets more convenient. To handle that, this commit adds a new trait for "Something that has the same IDs as a relay" and a new object for "an owned representation of a relay's IDs." This commit introduces a similar trait for "Something with a list of SocketAddr, like a relay has." There's no owned equivelent for that, since Vec<SocketAddr> is already a thing. Closes #428.
* Remove some testing-only reimplementations of OwnedChanTarget.Nick Mathewson2022-08-021-35/+8
| | | | These predate OwnedChanTarget, and are no longer needed.
* tor-proto: Split CellErr based on activity.Nick Mathewson2022-06-231-1/+2
| | | | | | Failing to encode is fundamentally different from failing to decode. We now treat those separately, and describe _what_ we failed to encode or decode.
* tor-proto: clean up error names and messagesNick Mathewson2022-06-231-1/+1
| | | | | This avoids adding additional information for now; that will come on the next commits.
* try to differentiate transient from nontransient errortrinity-1686a2022-06-081-7/+4
|
* Merge branch 'sleep' into 'main'Ian Jackson2022-06-081-1/+1
|\ | | | | | | | | Plumb a SleepProvider (now Clone + ....) into Channel See merge request tpo/core/arti!569
| * Plumb a SleepProvider into the channel reactorIan Jackson2022-06-081-1/+1
| | | | | | | | | | The channel reactor is going to want to be able to sleep so that it can do padding, so it needs a SleepProvider.
* | Use testing_rng() in tests throughout our crates.Nick Mathewson2022-06-021-4/+4
|/ | | | | | This only affects uses of thread_rng(), and affects them all more or less indiscriminately. One test does not work with ARTI_TEST_PRNG=deterministic; the next commit will fix it.
* Add a channel accessor to ClientCirc.Nick Mathewson2022-05-111-1/+20
| | | | | I need this so that I can expose the skew time for the directory that a circuit will use, when I only have the circuit.
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-251-1/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* Define accessors for circuit hops.Nick Mathewson2022-03-171-0/+25
| | | | Closes #415
* tor-proto: Remember peer information in circuit and channelNick Mathewson2022-03-171-4/+9
| | | | | | | | | Each channel now remembers an OwnedChanTarget. Each circuit now remembers a vector of OwnedChanTarget to represent the path that it was constructed for. Part of #415.
* ClientCirc: Move n_hops into a new Path type.Nick Mathewson2022-03-171-11/+9
| | | | This will help with #415
* tor-proto: Rename BadHandshake to BadCircHandshakeNick Mathewson2022-02-231-1/+1
| | | | (We'll have a BadChanHandshake soon.)
* Update tor-proto errors to latest API.Nick Mathewson2022-02-151-5/+5
|
* Make tor-proto::Error implement HasKind.Nick Mathewson2022-02-151-9/+11
| | | | | | This took some refactoring, and gave an opportunity to notice a few error variants that weren't being used, or didn't mean what they said on the tin.
* tor-proto: use InternalError for internal errors.Nick Mathewson2022-02-151-3/+4
|
* tor-cell: provide HasKind.Nick Mathewson2022-02-151-3/+3
| | | | | | | | | Additionally, refactor the IoError out of tor_cell::Error: nothing in TorCell created this; it was only used by tor_proto. This required refactoring in tor_proto to use a new error type. Here I decided to use a new CodecError for now, though we may refactor that away soon too.
* Fix typosDimitris Apostolou2022-02-021-1/+1
|
* clippy: Rename a `decode_chanmsg` from `handle_`Ian Jackson2022-01-191-3/+3
| | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/249#note_2771025 It doens't really handle it.
* clippy: Rename a `from_foo` method that doesn't do conversionIan Jackson2022-01-191-3/+3
|
* Change RequireSendmeAuth to an enum.Nick Mathewson2022-01-121-9/+8
| | | | | | | | This is a fine example of why booleans are risky: it's far to easy to pass "animate:bool" into "inanimate:bool" like we did here. This is a followup from our fix to #294.
* ClientCirc: change some methods to take &selfNick Mathewson2022-01-071-11/+6
| | | | | Previously they took Arc<Self>, and then Self, but &self is perfectly fine here.
* tor-circmgr: Remove Arc around ClientCircIan Jackson2022-01-071-8/+25
| | | | | | See the new commentary text on `ClientCirc` for the rationale. Signed-off-by: Ian Jackson <[email protected]>
* Merge remote-tracking branch 'origin/mr/212'Nick Mathewson2022-01-061-2/+2
|\
| * tor-circmgr: Don't clone parameters in create_chantarget()Neel Chauhan2021-12-251-2/+2
| |
* | tor-proto: In begin_stream_impl(), if number of hops is zero, don't continueNeel Chauhan2021-12-251-1/+5
|/
* tor-proto: use const-time eq on sendme tags.Nick Mathewson2021-12-161-3/+12
| | | | | | | There's no known attack here, but it's best practice to always compare digests using a constant-time comparison operator. This resolves an XXXX comment.
* add semicolons if nothing returnedDaniel Eades2021-11-251-12/+12
|
* Try to make the tor_proto::circuit::begindir test more reliable.Nick Mathewson2021-11-231-2/+2
| | | | | | | | | | I traced the problem here to the fact that sometimes "rx" in this test would be dropped before the test was done. When "rx" is dropped, the channel reactor shuts down, which in turn kills off the circuit reactor. This bug may exist in other cases in these tests. This patch may fix one case of #238.
* Make unreliable tor-proto tests more reliable (arti#238).eta2021-11-181-10/+12
| | | | | | | | | | | | | | | | | | | | | The `bad_extend_*` failures were caused by bad test code in `bad_extend_test_impl` that used `futures::join!`; this meant that the reactor could receive the `Extended2` cell before it actually got the `ExtendNtor` request, which caused it to get (quite rightly) confused and close the circuit. Spawning a background thread which has a short delay before sending the `Extended2` cell seems to have alleviated this problem. `new_circ_create_failure` is similar; I think the reactor was getting dropped before it had a chance to flush out its `CreateFast` cell properly, because it had already gotten the result back (since the test code sends it indiscriminately). This was "fixed" in much the same manner as the other test: making it wait a bit before sending the result cell back. There seem to be other tests that use `futures::join!` (like `begindir`?), and use similarly erroneous patterns; I haven't gotten any to fail reliably enough to be able to debug them, though.
* Always use optimistic data for begindir connections.Nick Mathewson2021-11-161-1/+5
| | | | Closes #226.
* tor-proto: Use tor-rtcompat macros for testing, not tokio.Nick Mathewson2021-11-151-254/+298
| | | | Closes #222.
* Replace or remove testing eprintln!()s.Nick Mathewson2021-11-131-3/+4
| | | | | The clippy code for warning about these on nightly CI can't tell the difference between cfg(test) and no cfg(test).
* Resolve a dead-code warning on nightly.Nick Mathewson2021-11-131-0/+2
| | | | The `circid` field in `ClientCirc` is now testing-only.
* Get rid of unbounded stream sender, and RawCellStreameta2021-11-121-18/+47
| | | | | | | | | | | | | | | | | | | | | Previously, the reactor would use an `UnboundedSender` to send things to the `RawCellStream`, in order that the reactor wouldn't block if you failed to read from the latter. This is bad, though, since it means people can just run us out of memory by sending lots of things. To fix this, we make the new `StreamReader` type (which does the reading parts from `RawCellStream`) keep track of the stream's receive window and issue SENDMEs once *it* has consumed enough data to require it, thus meaning that we shouldn't get sent enough data to fill the channel between reactor and `StreamReader` (and, if we do, that's someone trying to flood us, and we abort the circuit). As hinted to above, the `RawCellStream` was removed and its reading functionalities replaced by `StreamReader`; its writing functionalities are handled by `StreamTarget` anyway, so we just give out one of those for the write end. This now means we don't need any mutexes! note: this commit introduces a known issue, arti#230
* Completely overhaul the tor-proto circuit reactoreta2021-11-121-853/+242
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Rather like e8e9699c3c239d6c30f9ad414f15d3bad6ec03fd ("Get rid of tor-proto's ChannelImpl, and use the reactor more instead"), this admittedly rather large commit refactors the way circuits in `tor-proto` work, centralising all of the logic in one large nonblocking reactor which other things send messages into and out of, instead of having a bunch of `-Impl` types that are protected by mutexes. Congestion control becomes a lot simpler with this refactor, since the reactor can manage both stream- and circuit-level congestion control unilaterally without having to share this information with consumers, meaning we can get rid of some locks. The way streams work also changes, in order to facilitate better handling of backpressure / fairness between streams: each stream now has a set of channels to send and receive messages over, instead of sending relay cells directly onto the channel (now, the reactor pulls messages off each stream in each map, and tries to avoid doing so if it won't be able to forward them yet). Additionally, a lot of "close this circuit / stream" messages aren't required any more, since that state is simply indicated by one end of a channel going away. This should make cleanup a lot less brittle. Getting all of this to work involved writing a fair deal of intricate nonblocking code in Reactor::run_once that tries very hard to be mindful of making backpressure work correctly (and congestion control); the old code could get away with having tasks .await on things, but the new reactor can't really do this (as it'd lock the reactor up), so has to do everything in a nonblocking manner.
* Merge IpVersionPreferences and the optimistic flag into one type.Nick Mathewson2021-11-101-7/+6
| | | | | It seems like a good time to do this, before we add a zillion other arguments to begin_stream.
* Implement optimistic streamYuan Lyu2021-11-091-21/+17
|