summaryrefslogtreecommitdiff
path: root/crates/tor-proto/src/circuit
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'sometimes-unbounded' into 'main'Nick Mathewson2024-06-111-50/+13
|\ | | | | | | | | RFC: Provide and use SometimesUnboundedSender in circuit reactor See merge request tpo/core/arti!2172
| * Use SometimesUnboundedSink for the circuit reactor's bag-on-the-sideIan Jackson2024-05-291-50/+13
| |
* | Merge branch 'poll-ready-unpin-bool' into 'main'Nick Mathewson2024-05-291-3/+4
|\| | | | | | | | | Tidy up the ChannelSender::poll_ready inherent method See merge request tpo/core/arti!2171
| * ChannelSender::poll_ready_unpin_bool: move to utilIan Jackson2024-05-291-1/+1
| | | | | | | | This is where it belongs.
| * ChannelSender::poll_ready_unpin_bool: extension traitIan Jackson2024-05-291-0/+1
| | | | | | | | | | | | | | This makes this available for any Sink + Unpin. Which we want because we're about to wrap our ChannelSender in a Sink wrapper. It's in the wrong place now; we'll move it in a moment.
| * ChannelSender::poll_ready_unpin_bool: rename from poll_readyIan Jackson2024-05-291-3/+3
| | | | | | | | | | | | | | | | | | | | This would otherwise shadow the poll_ready method, which is confusing. Also this paves the way for making it available for any Sink + Unpin. Improve the docs somewhat to explain what this thing actually is.
* | proto: Make DataWriter::close actually do something.Nick Mathewson2024-05-291-2/+6
|/ | | | | | | | | | | | | | | | | | | Previously we had a bug where `<DataWriter as AsyncWrite>::close` (or `shutdown` in tokio-land) would not actually have any effect. It _would_ drop the `StreamTarget` held by the `DataWriter`, but since the `DataReader` also held a `StreamTarget`, the MPSC channel would not get closed, and the circuit reactor would not realize that the stream wanted to shut down. Now we use `mpsc::Sender::close_channel` to make our closes effectual. Closes #1368. Additionally, we fix a bug where `poll_close()` never actually did anything if the buffer had nothing in it when it was called. Previously, `poll_flush_impl()` would exit immediately if it had no data to flush. That isn't what we want when we are closing!
* proto: Make Channel explicitly Arc<.>Nick Mathewson2024-05-161-2/+2
| | | | | | | | | | | | | | | | Previously, Channel was a type that you could Clone that implicitly its state. Now, Channel always appears as an Arc<Channel>. This change has several benefits: * It makes the relationship between Channel struct and the underlying channel more clear. * It enables Channel to participate in the RPC system, where everything has to be an Arc<.> * It enables us to have a Weak<Channel>, if we ever want to. * It will let us move various members out of ChannelDetails. We did this change a while ago with ClientCirc.
* proto: Move Channel send functionality into a separate type.Nick Mathewson2024-05-161-9/+14
| | | | | | | | | | | | This serves three purposes: * It removes the 'send a cell' method from the channel's public API. Nothing outside of tor-proto should have to use this. * It paves the way for giving each circuit a separate handle onto the channel's send functionality. This will eventually let the channel multiplex among circuits more intelligently. * It prepares for the next commit, which will make Channel itself universally Arc<.>ed.
* proto: Explicitly enforce maxima on SENDME windows.Nick Mathewson2024-05-142-4/+15
| | | | | | | | | | | | | | No actual bug here, just technical debt: For `SendWindow`s, our tag system already ensured that we rejected any SENDME that didn't correspond to an appropriate drain. Still, it doesn't hurt to check. For `RecvWindow`s, it would have been a protocol violation if we ever did this, but it makes sense to make it an internal error if we try. Part of #1383.
* Circuit reactor: use refutable let to unnest some codeJim Newsome2024-05-061-34/+35
|
* Circuit reactor: rename 'hop to 'hop_outboundJim Newsome2024-05-061-3/+3
| | | | | It was a bit misleading since it doesn't cover all processing for the hop.
* Circuit reactor run_once: remove a level of nestingJim Newsome2024-05-061-27/+27
| | | | | | | Get rid of an `if` block by changing the guarded loop to check its conditions at the beginning of the loop instead of the end. This is a slight behavior change, since previously channel readiness wasn't checked before the first iteration of the loop.
* circuit reactor run_once: remove a level of nestingJim Newsome2024-05-061-90/+87
| | | | | | This should be a pure refactor. We remove a large if block and modify the first loop inside it to check whether the channel is ready before each attempt to send a message instead of after.
* Circuit reactor: document some requirements and assumptionsJim Newsome2024-04-251-10/+42
| | | | | | | | There are some tricky bits here that implicitly assume particular behavior in other bits for correctness. Document these requirements and assumptions. Fixes arti#1373
* Add temporary allows for some dead code warningsIan Jackson2024-04-251-0/+1
|
* counted_map: Use educe(Default).Nick Mathewson2024-04-021-12/+4
|
* counted_map: Use PhantomData<fn(P)->P>Nick Mathewson2024-04-021-4/+4
| | | | This is always Send+Sync, and invariant with P.
* counted_map: Add some notes about correctness; downgrade unsafesNick Mathewson2024-04-022-13/+21
| | | | | (We're letting the "unchecked" suffix of this function be enough to indicate that it's risky to use.)
* streammap: Use an internal counted_hashmap to simplify invariant checkingNick Mathewson2024-03-282-43/+566
| | | | | | | | | | Instead of making `streammap.rs` responsible for keeping track of a count field, this lowers that functionality into a lower-level CountedHashMap type. Said type has a little more functionality than we need, to sketch out how we'd want to develop it moving forward if we find that it's useful elsewhere. Closes #1344.
* Make filter conditional, to fix build with hs-service disabled.Nick Mathewson2024-03-261-2/+3
|
* Refactor and simplify ClientCircSyncViewNick Mathewson2024-03-262-34/+24
| | | | | | | | With this patch, it holds only a reference to `&reactor.hops`, which greatly simplifies the reactor code's fight with the borrow checker. I've left some TODO comments about future directions here.
* Rename the old IncomingStreamRequestContext to StreamReqInfo.Nick Mathewson2024-03-261-4/+4
| | | | (Doing this to prevent us having two structs with the same name.)
* Add an IncomingStreamRequestFilter to check early propertiesNick Mathewson2024-03-262-9/+62
| | | | | | | Based on designs in #1124. Note that there is a TODO here about a hack I had to do to appease the borrow checker.
* Define a type for a synchronous (blocking) view of a circuit state.Nick Mathewson2024-03-263-0/+40
| | | | | We'll use this as an argument for the callback that checks stream requests to make sure they're permitted.
* proto: Make StreamMap keep a count of open streams.Nick Mathewson2024-03-261-0/+34
|
* proto: Prevent general state-transitions on StreamEntNick Mathewson2024-03-262-38/+60
| | | | | | We want to keep an accurate count of the number of open streams, so we have to stop exposing `&mut StreamEnt` outside of the streammap module.
* proto: Refactor circuit::streammap::StreamEntNick Mathewson2024-03-262-40/+51
| | | | | | | This is the first part of a refactoring that will let us keep code from the outside of `streammap` from changing a stream from one state to another. And we need to do _that_ so that StreamMap can count how many open streams it has.
* Push HandshakeRole down one level.Nick Mathewson2024-03-261-5/+4
|
* Provide spec links for relay crypto formats.Nick Mathewson2024-03-261-2/+10
|
* Clean up match statement a little.Nick Mathewson2024-03-261-7/+7
|
* We now need circuit::handshake to exist unconditionally.Nick Mathewson2024-03-261-2/+11
|
* Refactor the logic for constructing crypt layers.Nick Mathewson2024-03-262-64/+91
| | | | | | | | | | | The key insights here are: - That relay cell format and crypto protocols aren't orthogonal: Once we have GCO, it will require V1. - That we only need the actual functions for layer construction to be generic; we don't need to proliferate generic parameters everywhere. - That the circuit::handshake module already does most of what we want.
* Add and use RelayCellFormatTraitJim Newsome2024-03-202-27/+40
| | | | | | This lets us paramaterize types and functions by a particular relay cell format. We use this e.g. to statically parameterize the cell crypto functions, thereby removing some run-time branching in the hot path.
* Propagate RelayCellFormat selection up to where format decisions will be madeJim Newsome2024-03-202-17/+50
|
* Paramaterize layer crypto objects by cell formatJim Newsome2024-03-202-3/+11
|
* Run maint/add_warning.Nick Mathewson2024-03-134-0/+4
|
* relay-cell: Update relay cell decoding API for prop340Jim Newsome2024-03-123-19/+77
| | | | | | | | | | | Prop 340: https://spec.torproject.org/proposals/340-packed-and-fragmented.html This updates the decoding API to support multiple versions of the relay cell encoding, including the new encoding proposed in prop340 that supports relay message packing and fragmentation. This commit doesn't actually add support for that new encoding yet.
* Rename UnparsedRelayCell -> UnparsedRelayMsgJim Newsome2024-03-125-24/+24
| | | | | For consistency with the terminology proposed in https://gitlab.torproject.org/tpo/core/torspec/-/issues/253
* tor-circmgr: Add a helper for displaying optional UniqIds.Gabriela Moldovan2024-02-271-1/+17
| | | | | | | | Some of the `tor_circmgr::Error` variants will include the `UniqId` of the corresponding circuit, so we'll need to be able to display it without the `Circ ` prefix. Part of #1297
* proto: Use log_ratelim to report problems delivering BEGIN messges.Nick Mathewson2024-01-171-3/+7
|
* Give an error on duplicate call to allow_stream_requests.Nick Mathewson2024-01-171-2/+2
| | | | Closes #1190
* proto: Close circuit _intentionally_ when Request Sink is dropped.Nick Mathewson2024-01-171-6/+27
| | | | | | | | | | | | | | | | | | | | | In theory, it might be better to just un-register the IncomingStreamRequestHandler when the Receiver for the stream requests is dropped. However, there are two reasons not to do so: 1. It's tricky. We never actually poll on the corresponding Sink, so there isn't a place where the Reactor would expect to get a prompt notification of closure. We only find out that the Receiver has been dropped when an attempt to send on the Sink returns an `is_disconnected` error. 2. It's unnecessary. In the Tor protocols, once we have decided to accept incoming stream requests on a circuit, we want to continue to do so until one of the parties closes the circuit. I've documented this in several comments, in case whe want to get fancier in the future. Closes #1188.
* proto: Send END when buffer of IncomingRequests is fullNick Mathewson2024-01-171-11/+14
| | | | Closes #1189.
* Convert a TODO HSS about excessive BEGINs to #1189.Nick Mathewson2024-01-101-1/+1
|
* proto: Downgrade TODO HSS about HopNum in IncomingStreamRequestCommentNick Mathewson2024-01-101-5/+4
| | | | | | | These comments are about internal representations and future extensions. Also, add a fail-safe check to make sure that hop_num consistency is enforced.
* proto: Downgrade TODO HSS comments about hop lookupNick Mathewson2024-01-101-2/+2
|
* proto: Change some TODO HSS comments to refer to #1188Nick Mathewson2024-01-101-3/+3
|
* clippy nightly: For now, locally allow blocks_in_conditionsIan Jackson2024-01-021-0/+1
| | | | | | Filed https://gitlab.torproject.org/tpo/core/arti/-/issues/1176 proposing a final fix.
* clippy: Replace many calls to .get(0) with .first()Ian Jackson2024-01-021-1/+1
| | | | | FTR I don't think agree with clippy on this question, but then I often don't.