| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
|
| |
I don't think the previous comment is correct. The main flow control
checks are about receiving SENDME/XON/XOFFs, and ensuring that we don't
receive too many of them. This all happens in the reactor.
In theory the stream should be checking that we don't receive too many
DATA messages for how many stream SENDMEs we've sent. But this is broken
due to arti#2100. We do check this in the halfstream code though.
|
| |
|
|
|
|
|
| |
We no longer want to _ever_ block non-DATA cells, per discussion
in circuit-padding.md.
Closes #2190.
|
| | |
|
| |
|
|
|
|
|
|
| |
This sort makes it so that that blocking and unblocking are always
ordered in a sensible way with respect to sending data. This might
help simplify padding machines a bit.
Prerequisite for #2190
|
| | |
|
| |
|
|
|
| |
Also derives `CIRC_ACTION_COUNT` from the two other constants instead of
hard-coding the value.
|
| |
|
|
|
| |
Besides, it's better if we use the same number for the expected number
of legs as we do in the conflux set impl.
|
| |
|
|
|
|
|
|
|
|
| |
This rewrites `next_circ_action()` yet again, using two layers of
`PollAll`:
* the inner layer drives an individual circuit leg. Each circuit
has a `PollAll` that drives its futures
* the outer layer drives the inner `PollAll`s belonging to the
circuits that form the tunnel
|
| | |
|
| | |
|
| |
|
|
|
| |
We don't really need to return a `HopNum` anymore (because we work out
the join point `HopNum` unconditionally in `next_circ_action`).
|
| |
|
|
|
|
| |
If we poll the ready streams on the join point more than once per
reactor loop, we risk sending more than one DATA cell (which is not
good, because cc might block after the first cell is sent).
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This removes our usage of `FuturesUnordered` in
`ConfluxSet::next_circ_action()` to address two issues:
* a fairness issue, where the futures driven by `FuturesUnordered`
could be starved under some circumstances (#2180)
* a logic error, where we'd explicitly avoid reading from the input
channel if the outgoing `chan_sender` channel was blocked (#2179)
Note that the fixing the latter will cause the reactor to buffer more
into the unbounded `chan_sender` sink, but that *should* be okay,
because no input message should be able cause us to queue cells
excessively.
Closes #2179, #2180
|
| |
|
|
|
| |
We will soon need to access this directly (rather than via a method on
`Circuit`) to work around borrow checker limitations.
|
| | |
|
| |
|
|
|
|
|
| |
Part of #2180
Note: the code is intentionaly left misindented to make reviewing a
bit easier. A future commit will fix the indentation.
|
| | |
|
| |
|
|
|
|
| |
This simplifies the calling code, which will, in turn, make it easier
for us to simplify the logic in ConfluxSet::next_circ_action() and
abolish the questionable use of FuturesUnordered.
|
| |\
| |
| |
| |
| |
| |
| | |
proto: Remove half-streams when they expire.
Closes #264
See merge request tpo/core/arti!3267
|
| | |
| |
| |
| | |
I want to tackle this separately, as part of #2003
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3267#note_3261239
|
| | | |
|
| | |
| |
| |
| |
| |
| | |
Half-streams are periodically removed from each hop's stream map by the
reactor main loop, but we still need to ensure we reject any messages
arriving on expired half-streams in between these cleanup cycles.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This tests that the half-stream expiry works as expected.
Note: it doesn't! This test currently fails, because there's a bug in
the way half-streams are expired. Because we don't do it on a timer, and
instead garbage-collect the half-streams on each reactor iteration, if
the reactor is stuck long enough `.await`ing a message on one of its
channels (for example, the `input` one), there is a chance it will
accept a cell on a half-stream that should've been expired.
A future commit will fix this bug.
|
| | |
| |
| |
| |
| |
| | |
This should look at length of the circuit up until the hop where the
half-stream is (because the half-stream might be on an intermediate hop,
and not necessarily on the final one).
|
| | |
| |
| |
| | |
Closes #264
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
The move of `self` into the closure was getting in the way, as I will
need to reference `self` again below.
|
| | | |
|
| |\ \
| | |
| | |
| | |
| | | |
tor-proto: Small improvements to XON/XOFF code
See merge request tpo/core/arti!3273
|
| | | |
| | |
| | |
| | | |
This should be `cc_xoff_exit` if we're an exit.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
XON/XOFF flow control doesn't have the idea of taking "capacity". But it
does need to know the messages we're about to send so that it can count
the number of stream bytes that we've sent.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Streams at the same circuit hop will now share a single
`Arc<FlowCtrlParameters>`.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
Resolve blocking padding-related TODOs
See merge request tpo/core/arti!3271
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
When we install a new padder, we should check whether we have become
unblocked, and we should wake up the PaddingEventStream in case
the new padder has something to say.
This has required us to move a couple of fields around, but not in a
very complicated way.
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tor-proto: Add dropmark sidechannel mitigations for XON/XOFF flow control
Closes #2129
See merge request tpo/core/arti!3266
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | | |
|