summaryrefslogtreecommitdiff
path: root/crates/tor-proto/src/circuit
Commit message (Collapse)AuthorAgeFilesLines
* Allow clippy::unchecked_duration_subtraction in testsNick Mathewson2023-01-274-0/+4
| | | | | This panics on error, and we're fine with a panic on misbehavior in tests.
* Merge branch 'sensitive' into 'main'eta2023-01-261-3/+4
|\ | | | | | | | | tor-proto: Mark stream ids in errors as sensitive See merge request tpo/core/arti!986
| * tor-proto: Mark stream ids in errors as sensitiveIan Jackson2023-01-241-3/+4
| | | | | | | | Pursuant to #556
* | tor-proto: comment fixes and more TODO hsNick Mathewson2023-01-241-2/+6
| |
* | tor-proto: Expose support for doing onion service handshakesNick Mathewson2023-01-171-0/+33
|/ | | | | | This is a little tricky, but I think that we're not actually exposing too much here. I expect we'll need to tweak this stuff between now and our final version.
* tor-proto: impl Display for CreateResponseIan Jackson2023-01-061-0/+12
| | | | Don't print the handshake value, but do print the display reason.
* test lint blocks: Add many many automaticallyIan Jackson2022-12-124-0/+32
| | | | | This is precisely the result of running the rune in maint/adhoc-add-lint-blocks.
* tor-linkspec: Remove the old OwnedFoo::new() functionsNick Mathewson2022-10-061-2/+11
| | | | These are now builders.
* add feature annotation not added by doc_auto_cfgtrinity-1686a2022-08-241-0/+1
|
* tor-proto: Make "testing" feature that exports some thingsIan Jackson2022-08-161-2/+5
| | | | | We are going to want this for through-the-layers padding control testing.
* Final (?) API revisions for tor-linkspecNick Mathewson2022-08-101-16/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With this change, each individual identity type becomes optional. The functions that expose them unconditionally are now in a "legacy" trait that only some downstream types are expected to implement. There are new convenience APIs in HasRelayIds: * to return Option<&keytype>, * to see if one identity-set contains another. This commit will break several downstream crates! For the reviewer's convenience, I will put the fixes for those crates into a series of squash! commits on this one. tor-netdir ---------- Revise tor-netdir to accept optional identities. This required some caveats and workarounds about the cases where we have to deal with a key type that the tor-netdir code does not currently recognize at all. If we start to add more identity types in the future, we may well want more internal indices in this code. tor-proto --------- In order to make tor-proto support optional identities, there were fewer changes than I thought. Some "check" functions needed to start looking at "all the ids we want" rather than at "the two known IDs"; they also needed to accommodate that case where we don't have an ID that we demand. This change will also help with bridges, since we want to be able to connect to a bridge without knowing all of its IDs up front. The protocol currently _requires_ the two current ID types in some places. To deal with that, I added a new `MissingId` error. I also removed a couple of unconditional identity accessors for chanmgr; code should use `target().identity(...)` instead. tor-chanmgr ----------- This is an incomplete conversion: it does not at all handle channel targets without Ed25519 identities yet. It still uses those identities to index its internal map from identity to channel; but it gives a new `MissingId` error type if it's given a channel target that doesn't have one. We'll want to revise the map type again down the road when we implement bridges, but I'd rather not step on the channel-padding work in progress right now. tor-guardmgr ------------ This change is mostly a matter of constructing owned identity types more sensibly, rather than unwrapping them directly. There are some places marked with TODOs where we still depend on particular identity types, because of how the directory protocol works. This will need revisiting when we add bridge support here. tor-circmgr ----------- These changes are just relatively simple API changes in the tests.
* tor-proto: split and elaborate tor_bytes::Error instancesNick Mathewson2022-06-231-1/+2
| | | | | | | | | Some of these were for decoding particular objects (we now say what kind of objects), and some were unrelated tor_cert errors that for some reason we had shoved into a tor_bytes::Error. There is now a separate tor_cert::CertError type, independent from tor_cert's use of `tor_bytes::Error` for parsing errors.
* tor-proto: Split CellErr based on activity.Nick Mathewson2022-06-231-1/+4
| | | | | | Failing to encode is fundamentally different from failing to decode. We now treat those separately, and describe _what_ we failed to encode or decode.
* tor-proto: clean up error names and messagesNick Mathewson2022-06-231-4/+4
| | | | | This avoids adding additional information for now; that will come on the next commits.
* tor-proto: err: Provide ChannelClosed as a separate unit errorIan Jackson2022-06-211-3/+3
|
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-252-4/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* Define accessors for circuit hops.Nick Mathewson2022-03-171-0/+14
| | | | Closes #415
* tor-proto: Remember peer information in circuit and channelNick Mathewson2022-03-172-12/+33
| | | | | | | | | Each channel now remembers an OwnedChanTarget. Each circuit now remembers a vector of OwnedChanTarget to represent the path that it was constructed for. Part of #415.
* ClientCirc: Move n_hops into a new Path type.Nick Mathewson2022-03-172-3/+27
| | | | This will help with #415
* impl Debug for DataStream (and its components)Ian Jackson2022-02-241-2/+2
| | | | | | | | | My proximate motivation is that tls-api wants its inner streams to be Debug. But in general, I agree with the Rust API Guidelines notion that almost everything should be Debug. I have gone for the "dump all the things" approach. A more nuanced approach would be possible too.
* Update tor-proto errors to latest API.Nick Mathewson2022-02-154-11/+13
|
* tor-proto: use InternalError for internal errors.Nick Mathewson2022-02-154-15/+32
|
* Merge branch 'eta/reactor-2.5' into 'main'eta2022-02-031-33/+60
|\ | | | | | | | | Fix severe reactor ordering problems See merge request tpo/core/arti!282
| * Fix severe reactor ordering problemseta2022-02-031-33/+60
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | A number of severe problems with the circuit reactor were fixed which could cause reordering of cells (which causes relays to terminate the circuit with a protocol violation, as they become unable to decrypt them). These mostly revolve around improper usage of queues: - The code assumed that a failure to place cells onto the channel would persist for the duration of a reactor cycle run. However, under high contention, this wouldn't always be the case. - This leads to some cells getting enqueued while others go straight through, before the enqueued cells. - To fix this, we block sending cells out of the channel while there are still some enqueued. - The hop-specific queues queued after encryption, not before. This was very brittle, and led to frequent mis-ordering. - This was fixed by making them not do that. This is arti!264 / 5bce9db5628126be2b736f228211174fe4132918 without the refactor part.
* | Merge branch 'typos' into 'main'eta2022-02-031-1/+1
|\ \ | | | | | | | | | | | | Fix typos See merge request tpo/core/arti!285
| * | Fix typosDimitris Apostolou2022-02-021-1/+1
| |/
* / Remove many needless borrows and slicesIan Jackson2022-02-021-1/+1
|/ | | | | | | Found via clippy::needless_borrow. In some cases I removed needless `[..]` too. See also: needless_borrow suggestion doesn't go far enough https://github.com/rust-lang/rust-clippy/issues/8389
* clippy: Rename a `decode_chanmsg` from `handle_`Ian Jackson2022-01-191-1/+1
| | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/249#note_2771025 It doens't really handle it.
* clippy: Rename a `from_foo` method that doesn't do conversionIan Jackson2022-01-191-1/+1
|
* Describe when we will need SendmeAcceptMinVersionNick Mathewson2022-01-121-0/+8
| | | | | | (spoiler: not until we have a relay implementation) Closes #53.
* Change RequireSendmeAuth to an enum.Nick Mathewson2022-01-121-24/+61
| | | | | | | | This is a fine example of why booleans are risky: it's far to easy to pass "animate:bool" into "inanimate:bool" like we did here. This is a followup from our fix to #294.
* Fix a boolean inversion in auth_sendme_optional.Nick Mathewson2022-01-121-1/+2
| | | | | | | | | | | | | Previously we were requiring authenticated sendme cells exactly when we should be permitting the old format, and vice versa. This bug was caused by using a boolean to represent one property, but with giving that boolean two different senses without inverting at the right time. The next commit will prevent a recurrence. Closes #294
* Document SendmeEmitMinVersion statusNick Mathewson2022-01-121-0/+4
| | | | | (We don't need to look at SendmeEmitMinVersion since higher values are not yet defined.)
* tor-proto: Allow one meta-cell handler at a time.Nick Mathewson2021-12-161-10/+18
| | | | | Previously the code would let us try to install a meta-cell handler before the old one was done, leading to possible confusion.
* Merge branch 'ct_sendme_tags' into 'main'eta2021-12-161-10/+36
|\ | | | | | | | | tor-proto: use const-time eq on sendme tags. See merge request tpo/core/arti!201
| * tor-proto: use const-time eq on sendme tags.Nick Mathewson2021-12-161-10/+36
| | | | | | | | | | | | | | There's no known attack here, but it's best practice to always compare digests using a constant-time comparison operator. This resolves an XXXX comment.
* | tor-proto: set HalfStream::connected_ok right.Nick Mathewson2021-12-162-2/+15
| | | | | | | | | | | | | | | | Previously we'd always set it to true, allowing one CONNECTED per half-closed stream even if the stream had already received a CONNECTED cell. This resolves an XXXX.
* | tor-proto: replace a streammap XXXX with a ticket.Nick Mathewson2021-12-161-3/+4
|/
* Extend trace messages for destroy/truncated reasons.Nick Mathewson2021-12-151-2/+17
| | | | | | | | | | | | It makes sense to put the method for human-readable strings onto the type itself, so that we can format these whenever they occur. I'm choosing the "human_str" method name here, since caret-generated types already have a to_str. I was thinking about using Display, but caret types already implement that. I've also moved the message from "warn!" to "debug!", since these aren't necessarily a problem condition.
* Merge remote-tracking branch 'origin/mr/191'Nick Mathewson2021-12-151-23/+24
|\
| * In reactor, use enums on whether to destroy circuitsNeel Chauhan2021-12-141-11/+20
| |
| * Methodize the destroy circuit reasonNeel Chauhan2021-12-141-19/+2
| |
| * Handle TRUNCATED cellsNeel Chauhan2021-12-131-12/+9
| |
| * Log on TRUNCATED cellNeel Chauhan2021-12-131-9/+21
| |
* | Merge branch 'check_put_return' into 'main'eta2021-12-153-25/+27
|\ \ | | | | | | | | | | | | | | | | | | Always check whether stream-level SENDMEs are expected. Closes #261 See merge request tpo/core/arti!192
| * | Always check whether stream-level SENDMEs are expected.Nick Mathewson2021-12-143-25/+27
| |/ | | | | | | | | | | | | | | | | | | (It's a protocol violation to get a SENDME when our send window is already full.) This patch makes SendWindow::put return a Result, so that it's easier to do the right thing with it. Closes #261.
* / Actually decrement the stream-level SENDME windoweta2021-12-142-0/+31
|/ | | | | | | | | | | | | arti!126 overhauled the `tor-proto` circuit reactor, but left out one very important thing: actually decrementing the SENDME window for streams (not circuits) when we send cells along them. Since the circuit-level SENDME window would often prevent us from running into a problem, this wasn't caught until my benchmarking efforts noticed it (in the form of Tor nodes aborting the circuit for a protocol violation). fixes arti#260
* Beautify some Vec->array code in tor-proto.Nick Mathewson2021-12-081-6/+7
| | | | | | | [T;N] supports TryFrom<Vec<T>>, and has since Rust 1.48: we can just use that. This resolves an XXXX comment.
* Resolve roughly half of the XXXXs.Nick Mathewson2021-12-062-8/+9
| | | | | | | | We want to only use TODO in the codebase for non-blockers, and open tickets for anything that is a bigger blocker than a TODO. These XXXXs seem like definite non-blockers to me. Part of arti#231.
* More typo fixes that I forgot to save :(Nick Mathewson2021-11-241-1/+1
|