| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |
|
| |
|
|
|
|
|
| |
MockSleepProvider and MockSleepRuntime have been declared deprecated
by the docs for some time. We're about to mark them `#[deprecated]`.
This commit has been split out for clarity of review.
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
This is mostly code motion + some visibility adjustments.
Moving all of these outside of `reactor` makes it easier to see which
parts are internal vs which are accessed by the reactor. It also helps
us enforce/audit invariants such as 'there should be no contention on
the `CircHop::map` mutex' (the stream map is now private to
`reactor::circuit`, and therefore nothing inside `reactor` will be
directly accessing it).
|
| |
|
|
| |
This will enable us to move `CircHop` out of `reactor.rs`.
|
| |
|
|
| |
This will enable us to factor `Circuit` out of `reactor.rs`.
|
| |\
| |
| |
| |
| | |
tor-proto: Update CtrlCmd and CtrlMsg docs.
See merge request tpo/core/arti!2829
|
| | |
| |
| |
| |
| |
| | |
In aa08ede11fd483cd6dcb4522c431f9e07001717e, the reactor loop was
rewritten to unconditionally read from the `CtrlMsg` channel, so we need
to adjust the docs.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-proto: Add CtrlCmd:ShutdownAndReturnCircuit
Closes #1876
See merge request tpo/core/arti!2831
|
| | | |
| | |
| | |
| | | |
Closes #1876
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This will be used to implement the new `ShutdownAndReturnCircuit`
control command.
Part of #1876
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
Some of these were supposed to be `bad_api_usage`, because they result
from API misuse rather than an internal error (bug).
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
This will enable us to reuse these checks for implementing other methods
that are only supported if the conflux set has a single leg.
|
| | |/
| |
| |
| |
| |
| | |
For consistency with the `CtrlCmd::Shutdown` handling from
`Reactor::wait_for_create` (`handle_shutdown()` also prints a helpful
trace log).
|
| |/ |
|
| |\
| |
| |
| |
| |
| |
| | |
tor-proto: Rewrite reactor loop to read from all circuits.
Closes #1863
See merge request tpo/core/arti!2817
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| | |
This was left over from the refactoring that moved the inner `select`
into the `ConfluxSet` impl.
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This commit updates the `Reactor::run_once()` loop to attempt to read
from (and write to) all of its circuit legs as opposed to just the
primary one.
Note that this slightly changes the behavior of the reactor. Previously,
we'd only read from the control channel if the `chan_sender` was ready,
whereas now the control channel is unconditionally read from, in the
*outer* select. The overall effect is that the control channel can cause
unbounded buffering in the `chan_sender` of each circuit (which can
happen if the `chan_sender` is not ready to send). This was actually how
the reactor worked before the refactoring from !2747, which is
reflected in the `chan_sender` docs:
```rust
/// Sender object used to actually send cells.
///
/// NOTE: Control messages could potentially add unboundedly to this, although that's
/// not likely to happen (and isn't triggereable from the network, either).
chan_sender: SometimesUnboundedSink<AnyChanCell, ChannelSender>,
```
I don't believe this to be a problem, for the reason mentioned in the
`chan_sender` docs, and because the main reason we check for
`chan_sender` readiness is to apply backpressure on senders, which is
not something we need to worry about when it comes to the control
channel. Besides, the control channel is unbounded, so not reading
from it won't stop the senders from sending more commands anyway.
Closes #1863
|
| | |
| |
| |
| |
| | |
This tells the reactor to remove a given circuit from the conflux set,
and will be used to remove the circuits that have been shut down.
|
| | | |
|
| | | |
|
| |/
|
|
|
| |
`futures::future::poll_fn` returns a future, so the `async` block isn't
actually necessary.
|
| |\
| |
| |
| |
| |
| |
| | |
Make DataStream, and its members, implement Sync.
Closes #1859
See merge request tpo/core/arti!2808
|
| | |
| |
| | |
Co-authored-by: Ian Jackson <[email protected]>
|
| | |
| |
| |
| |
| |
| |
| | |
Also, use static_assertions to enforce that that they
_stay_ Send+Sync.
Closes #1859.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
As suggested by opara in https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2804#note_3165059
|
| | |
| |
| |
| |
| | |
It used to be a Reactor, but the `reactor` variable name no longer makes
sense.
|
| | |
| |
| |
| |
| |
| | |
This helps us get rid of some unnecessary error handling.
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2804#note_3165058
|
| | | |
|
| | |
| |
| |
| | |
We definitely don't want to ever allow this.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Previously, sending two `CtrlMsg::Create` to the reactor would cause it
to panic. This makes it so that the double `Create` just leads to the
caller receiving an error response via the completion channel.
Note: this was not triggerable via the network, only via the tor-proto
API. Moreover, the panic was unreachable from the public client API,
because the `PendingClientCirc`/`ClientCirc` typestate makes it
impossible to send a second `Create` (the `PendingClientCirc` becomes
`ClientCirc` after the `Create` completes, and `PendingClientCirc`
doesn't have an API for sending `Create` control messages to the
reactor).
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This is the first step toward supporting traffic splitting in the
circuit reactor.
While the logic has changed slightly to support handling circuits
instead of just one, the reactor still only supports `ConfluxSet`s of
size 1, so this should effectively be a no-op. In the future, this code
will be extended to support the conflux-specific cells and to implement
the conflux proto.
The code uses `ConfluxSet::primary_leg()` and `ConfluxSet::single_leg()`
somewhat interchangeably. This is not *currently* a problem
because`primary_leg()` is the same as `single_leg()` for single path
tunnels, but we will need to adjust some of these call sites when we add
support for multipath tunnels (I have left a `TODO(conflux)` for every
dubious call site).
This commit also makes `CtrlMsg::FirstHopClockSkew` fallible: if the
reactor is multipath, it will return `Err(Bug(..))` to the caller (this
error is returned to the caller over the `answer` channel; it does *not*
shut down the reactor)
|
| | | |
|