aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-proto/src/circuit.rs
Commit message (Collapse)AuthorAgeFilesLines
* tor-proto: Rename BadHandshake to BadCircHandshakeNick Mathewson2022-02-231-1/+1
| | | | (We'll have a BadChanHandshake soon.)
* Update tor-proto errors to latest API.Nick Mathewson2022-02-151-5/+5
|
* Make tor-proto::Error implement HasKind.Nick Mathewson2022-02-151-9/+11
| | | | | | This took some refactoring, and gave an opportunity to notice a few error variants that weren't being used, or didn't mean what they said on the tin.
* tor-proto: use InternalError for internal errors.Nick Mathewson2022-02-151-3/+4
|
* tor-cell: provide HasKind.Nick Mathewson2022-02-151-3/+3
| | | | | | | | | Additionally, refactor the IoError out of tor_cell::Error: nothing in TorCell created this; it was only used by tor_proto. This required refactoring in tor_proto to use a new error type. Here I decided to use a new CodecError for now, though we may refactor that away soon too.
* Fix typosDimitris Apostolou2022-02-021-1/+1
|
* clippy: Rename a `decode_chanmsg` from `handle_`Ian Jackson2022-01-191-3/+3
| | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/249#note_2771025 It doens't really handle it.
* clippy: Rename a `from_foo` method that doesn't do conversionIan Jackson2022-01-191-3/+3
|
* Change RequireSendmeAuth to an enum.Nick Mathewson2022-01-121-9/+8
| | | | | | | | This is a fine example of why booleans are risky: it's far to easy to pass "animate:bool" into "inanimate:bool" like we did here. This is a followup from our fix to #294.
* ClientCirc: change some methods to take &selfNick Mathewson2022-01-071-11/+6
| | | | | Previously they took Arc<Self>, and then Self, but &self is perfectly fine here.
* tor-circmgr: Remove Arc around ClientCircIan Jackson2022-01-071-8/+25
| | | | | | See the new commentary text on `ClientCirc` for the rationale. Signed-off-by: Ian Jackson <[email protected]>
* Merge remote-tracking branch 'origin/mr/212'Nick Mathewson2022-01-061-2/+2
|\
| * tor-circmgr: Don't clone parameters in create_chantarget()Neel Chauhan2021-12-251-2/+2
| |
* | tor-proto: In begin_stream_impl(), if number of hops is zero, don't continueNeel Chauhan2021-12-251-1/+5
|/
* tor-proto: use const-time eq on sendme tags.Nick Mathewson2021-12-161-3/+12
| | | | | | | There's no known attack here, but it's best practice to always compare digests using a constant-time comparison operator. This resolves an XXXX comment.
* add semicolons if nothing returnedDaniel Eades2021-11-251-12/+12
|
* Try to make the tor_proto::circuit::begindir test more reliable.Nick Mathewson2021-11-231-2/+2
| | | | | | | | | | I traced the problem here to the fact that sometimes "rx" in this test would be dropped before the test was done. When "rx" is dropped, the channel reactor shuts down, which in turn kills off the circuit reactor. This bug may exist in other cases in these tests. This patch may fix one case of #238.
* Make unreliable tor-proto tests more reliable (arti#238).eta2021-11-181-10/+12
| | | | | | | | | | | | | | | | | | | | | The `bad_extend_*` failures were caused by bad test code in `bad_extend_test_impl` that used `futures::join!`; this meant that the reactor could receive the `Extended2` cell before it actually got the `ExtendNtor` request, which caused it to get (quite rightly) confused and close the circuit. Spawning a background thread which has a short delay before sending the `Extended2` cell seems to have alleviated this problem. `new_circ_create_failure` is similar; I think the reactor was getting dropped before it had a chance to flush out its `CreateFast` cell properly, because it had already gotten the result back (since the test code sends it indiscriminately). This was "fixed" in much the same manner as the other test: making it wait a bit before sending the result cell back. There seem to be other tests that use `futures::join!` (like `begindir`?), and use similarly erroneous patterns; I haven't gotten any to fail reliably enough to be able to debug them, though.
* Always use optimistic data for begindir connections.Nick Mathewson2021-11-161-1/+5
| | | | Closes #226.
* tor-proto: Use tor-rtcompat macros for testing, not tokio.Nick Mathewson2021-11-151-254/+298
| | | | Closes #222.
* Replace or remove testing eprintln!()s.Nick Mathewson2021-11-131-3/+4
| | | | | The clippy code for warning about these on nightly CI can't tell the difference between cfg(test) and no cfg(test).
* Resolve a dead-code warning on nightly.Nick Mathewson2021-11-131-0/+2
| | | | The `circid` field in `ClientCirc` is now testing-only.
* Get rid of unbounded stream sender, and RawCellStreameta2021-11-121-18/+47
| | | | | | | | | | | | | | | | | | | | | Previously, the reactor would use an `UnboundedSender` to send things to the `RawCellStream`, in order that the reactor wouldn't block if you failed to read from the latter. This is bad, though, since it means people can just run us out of memory by sending lots of things. To fix this, we make the new `StreamReader` type (which does the reading parts from `RawCellStream`) keep track of the stream's receive window and issue SENDMEs once *it* has consumed enough data to require it, thus meaning that we shouldn't get sent enough data to fill the channel between reactor and `StreamReader` (and, if we do, that's someone trying to flood us, and we abort the circuit). As hinted to above, the `RawCellStream` was removed and its reading functionalities replaced by `StreamReader`; its writing functionalities are handled by `StreamTarget` anyway, so we just give out one of those for the write end. This now means we don't need any mutexes! note: this commit introduces a known issue, arti#230
* Completely overhaul the tor-proto circuit reactoreta2021-11-121-853/+242
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Rather like e8e9699c3c239d6c30f9ad414f15d3bad6ec03fd ("Get rid of tor-proto's ChannelImpl, and use the reactor more instead"), this admittedly rather large commit refactors the way circuits in `tor-proto` work, centralising all of the logic in one large nonblocking reactor which other things send messages into and out of, instead of having a bunch of `-Impl` types that are protected by mutexes. Congestion control becomes a lot simpler with this refactor, since the reactor can manage both stream- and circuit-level congestion control unilaterally without having to share this information with consumers, meaning we can get rid of some locks. The way streams work also changes, in order to facilitate better handling of backpressure / fairness between streams: each stream now has a set of channels to send and receive messages over, instead of sending relay cells directly onto the channel (now, the reactor pulls messages off each stream in each map, and tries to avoid doing so if it won't be able to forward them yet). Additionally, a lot of "close this circuit / stream" messages aren't required any more, since that state is simply indicated by one end of a channel going away. This should make cleanup a lot less brittle. Getting all of this to work involved writing a fair deal of intricate nonblocking code in Reactor::run_once that tries very hard to be mindful of making backpressure work correctly (and congestion control); the old code could get away with having tasks .await on things, but the new reactor can't really do this (as it'd lock the reactor up), so has to do everything in a nonblocking manner.
* Merge IpVersionPreferences and the optimistic flag into one type.Nick Mathewson2021-11-101-7/+6
| | | | | It seems like a good time to do this, before we add a zillion other arguments to begin_stream.
* Implement optimistic streamYuan Lyu2021-11-091-21/+17
|
* Replace all println/eprintln calls outside of arti CLI with trace.Nick Mathewson2021-11-041-3/+3
|
* Get rid of tor-proto's ChannelImpl, and use the reactor more insteadeta2021-11-031-24/+42
| | | | | | | | | | | | | | | | | | | Instead of awkwardly sharing the internals of a `tor-proto` `Channel` between the reactor task and any other tasks, move most of the internals into the reactor and have other tasks communicate with the reactor via message-passing to allocate circuits and send cells. This makes a lot of things simple, and has convenient properties like not needing to wrap the `Channel` in an `Arc` (though some places in the code still do this for now). A lot of test code required tweaking in order to deal with the refactor; in fact, fixing the tests probably took longer than writing the mainline code (!). Importantly, we now use `tokio`'s `tokio::test` annotation instead of `async_test`, so that we can run things in the background (which is required to have reactors running for the circuit tests). This is an instance of #205, and also kind of #217.
* Refactor tor_proto::circuit::Reactor to use an UnboundedSendereta2021-11-021-47/+26
| | | | | | | | Basically the same thing as 371437d3384ed73520e7141e66874be3d85f1df0 ("Refactor tor_proto::channel::Reactor to use an UnboundedSender"), but for tor_proto::circuit's Reactor instead. (part of arti#217)
* fix/silence clippy lints in test modulesDaniel Eades2021-09-081-0/+2
|
* Move all crates into a `crates` subdirectory.Nick Mathewson2021-08-271-0/+1890
This will cause some pain for now, but now is really the best time to do this kind of thing.