aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-proto
Commit message (Collapse)AuthorAgeFilesLines
...
* tor-proto: only use congestion control if "flowctl-cc" feature is enabledSteven Engler2025-04-234-19/+45
| | | | | | | Congestion control is not completely working correctly, and is not fully implemented (XON/XOFF). This commit adds a new experimental "flowctl-cc" feature to enable the congestion control extension during the ntor-v3 handshake.
* tor-proto: expand docs for `CongestionWindowParams::set_sendme_inc`Steven Engler2025-04-231-1/+5
|
* tor-proto: rename `stream_sendme_required` to `uses_stream_sendme`Steven Engler2025-04-234-9/+9
|
* tor-proto: rename `allow_stream_sendme` to `uses_stream_sendme`Steven Engler2025-04-234-10/+10
| | | | | We use this method to decide whether to allow receiving stream SENDMEs, and also whether we should send stream SENDMEs.
* tor-proto: remove redundant `allow_stream_sendme` checkSteven Engler2025-04-231-15/+3
| | | | | | | `OpenStreamEnt::put_for_incoming_sendme()` calls `StreamSendFlowControl::put_for_incoming_sendme()`, which returns an error if the `StreamSendFlowControl` is in XON/XOFF mode. So we don't need this extra check.
* tor-proto: initialize `StreamSendFlowControl` based on CCSteven Engler2025-04-231-2/+6
| | | | | Congestion control tells us whether we should use stream or XON/XOFF flow control.
* tor-proto: new stream entries now take `StreamSendFlowControl`Steven Engler2025-04-232-15/+19
| | | | | | | | Previously new stream entries required a `StreamSendWindow`, but to support other flow control algorithms, we want new stream entries to take a `StreamSendFlowControl` instead. This also deduplicates the `StreamSendWindow` creation code.
* tor-proto: add no-op XON/XOFF flow control variantSteven Engler2025-04-231-8/+29
| | | | | | | This doesn't do anything yet, so is effectively like not having stream flow control. This should be implemented as part of arti#534.
* tests: Add CC ntorv3 negotiation unit testDavid Goulet2025-04-233-10/+86
| | | | | | | | Also add one for the sendme_inc validity function. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* circ: Don't allow stream level SENDME with CCDavid Goulet2025-04-231-2/+16
| | | | | | | | | | | | | If we ever receive a stream-level SENDME from the Exit while the circuit is under congestion control (Vegas), it is a protocol violation so close the circuit. This is important in order to avoid yet another side channel with cells that would be essentially ignored silently. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* circ: Don't send stream level SENDME with CCDavid Goulet2025-04-235-7/+44
| | | | | | | | | | | | | This adds a new function to the CongestionControl object that returns true or false on if stream level SENDMEs are allowed by the underlying algorithm. Congestion control Vegas doesn't allow them as in it retires them and so we avoid sending them for that algorithm. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* tor-proto: added `stream_sendme_required` methodsSteven Engler2025-04-233-0/+23
| | | | | These pass through congestion control state to the reactor, and aren't actually hooked up to the congestion control code yet.
* tor-proto: added accessors for circuit legs/hopsSteven Engler2025-04-232-1/+11
|
* circ: Request congestion control with ntorv3 extensionDavid Goulet2025-04-232-5/+12
| | | | | | | | | This puts in, based on the circuit parameters, the CC extension request in the CREATE and EXTEND requests. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* circ: Apply possible subprotocol changes to circ paramsDavid Goulet2025-04-231-1/+5
| | | | | | | | | | | | | Congestion control can change the circuit parameters if the relay we are negotiating with doesn't support FlowCtrl=2. This commit adds a function in the circuit builder that will apply any changes to the circuit parameters of the hop based on the hop protocol values. For now, only congestion control applies. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* circ: Remove CircParameters reference in call stackDavid Goulet2025-04-232-14/+13
| | | | | | | | | | | This avoids cloning the object and instead allows us to have a CircParameters per hop on the circuit path. This will come handy with congestion control where each hop might have different congestion control parameters. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* congestion: Setup a fallback algorithm in the paramsDavid Goulet2025-04-232-1/+9
| | | | | | | | | | | | | | | | CircParameters is built before path selection and thus once we start building the hops, we can't access the consensus values that were used to build it in the first place. For congestion control, we require a fallback algorithm in case the hop doesn't support FlowCtrl=2. This commit adds a "fallback_alg" to the CC parameters which will be used for this exact case. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* circ: Set the negotiated CC sendme_inc from handshakeDavid Goulet2025-04-232-7/+70
| | | | | | | | | | | When receiving the congestion control response extension, evaluate our state and set the sendme_inc if valid in our circuit parameters. For this, a series of helper functions is needed. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* circ: Make CircParameters mutable in the call stackDavid Goulet2025-04-233-12/+15
| | | | | | | | | | | | This is required because circuit ntor v3 handshake can negotiate circuit level parameters and thus able to change any values. Needed for congestion control ntorv3 handshake extension for which the sendme increment is negotiated. Part of #1817 Signed-off-by: David Goulet <[email protected]>
* protover, *: Add documentation about what "supported" means.Nick Mathewson2025-04-161-1/+2
|
* Add warnings about removing supported protocols.Nick Mathewson2025-04-161-0/+2
|
* New functions to report supported subprotocolsNick Mathewson2025-04-162-0/+43
| | | | | | | | | | | | | | | Part of #1849. Note that these functions are distributed across crates, so that if (in the future) we stop doing API breaks with every release, we will get the right outputs. Note also that these functions build the list of protocols out of specific symbolic features, rather than numbers: this makes it easier to avoid errors about "which feature was Relay=4 again", and easier to avoid accidentally referring to a protocol that doesn't exist, like "Consensus" (should be "Cons") or "HsDir" (case is wrong).
* proto: Create StreamTargets with the right RelayCellFormat.Nick Mathewson2025-04-164-8/+27
|
* cell, proto: Use correct Data sizes for v1 relay cellsNick Mathewson2025-04-163-16/+42
| | | | | | | | | | | | Since v1 cells have a longer tag, they can fit less data into a single cell. Ah well, that's the cost of improved security. The code in data.rs is a little wonky, in that it currently requires its buffer to be exactly the maximum size for a data cell. We have a TODO about fixing that in the future, but for now I've moved it to use a boxed slice rather than a boxed array. Part of #1944.
* proto: Use selected format when encoding messagesNick Mathewson2025-04-161-6/+11
|
* Add a RelayCellFormat argument to encode().Nick Mathewson2025-04-165-11/+20
| | | | | | | | | This will let us actually _send_ messages in the right format. This approach is not ideal for packed/fragmented messages; they will need a separate RelayCellEncoder. part of #1944.
* Note some places where we need updates for #1944.Nick Mathewson2025-04-164-2/+8
| | | | (Also note a couple of other CGO-related issues)
* proto: Avoid panic on non-existent hop numberNick Mathewson2025-04-111-1/+1
| | | | | | | | | | | | | In `send_relay_cell()` in `tunnel/reactor/circuit.rs`, replace an unconditional array access (which would cause a panic if `hop_num` were out-of-range) with a checked `get_mut()` call. It's not totally clear whether this can happen in practice, but in either case, an error is probably better than a panic. All of our other lookups in this vector are either checked, or more obviously infallible. Closes #1950.
* Allow StreamOps import to be unusedNick Mathewson2025-04-091-2/+8
| | | | | This comes up on OSX; I hadn't seen it before, so I assume it is new with Rust 1.86.
* tor-proto: Add TODO about using Itertools instead of open-coded impl.Gabriela Moldovan2025-04-081-0/+2
| | | | | This won't involve an extra dep, because we already use `itertools` throughout the codebase.
* tor-proto: Remove outdated TODO.Gabriela Moldovan2025-04-081-4/+0
| | | | | For service introduction circuits, we have `IptMsgHandler`, so we've already worked something out :)
* tor-proto: clean up after "ntor_v3" feature flag removalSteven Engler2025-04-011-2/+1
|
* tor-proto: removed "ntor_v3" feature flagSteven Engler2025-04-017-25/+1
| | | | ntor v3 is now always enabled.
* Remove semver.md files post-release.Gabriela Moldovan2025-04-012-2/+0
|
* Bump all the unstable tor- and arti- crates to 0.29.0.Gabriela Moldovan2025-03-311-18/+18
| | | | | | | | | | Done using: ``` for crate in $(./maint/list_crates | rg '^(tor|arti-)'); do cargo set-version -p $crate 0.29.0 done ```
* Bump the versions of the non-{arti-,tor-} crates.Gabriela Moldovan2025-03-311-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The non-{arti-,tor-} crates are: ``` ./maint/list_crates | rg -v '^(tor|arti)' oneshot-fused-workaround slotmap-careful test-temp-dir fslock-guard hashx equix caret fs-mistrust safelog retry-error ``` We split them in the following categories: * crates with no changes (no version bumps): ``` maint/changed_crates -v "arti-v$LAST_VERSION" 2>&1 >/dev/null | grep -i "no change" | grep -v '\(tor\|arti\)-' oneshot-fused-workaround: No change. slotmap-careful: No change. fslock-guard: No change. caret: No change. retry-error: No change. ``` * crates that only have non-functional changes (bump the patch version): - test-temp-dir - equix - fs-mistrust - safelog * crates where APIs were broken (bump minor): - hashx (`RngCore` impl for `SipRand`) The bumps from this commit were created using this script: ``` PATCH=" test-temp-dir equix fs-mistrust safelog " for crate in $PATCH; do cargo set-version --bump patch -p $crate; done MINOR=" hashx " for crate in $MINOR; do cargo set-version --bump minor -p $crate; done ```
* tor-proto: remove unnecessary `Option` from `circuit_action`Steven Engler2025-03-262-10/+9
|
* tor-proto: fix possible bug when there are no ready streamsSteven Engler2025-03-261-13/+21
|
* Merge branch 'circuit-action' into 'main'opara2025-03-252-16/+17
|\ | | | | | | | | tor-proto: simplify `ConfluxSet::circuit_action` See merge request tpo/core/arti!2884
| * tor-basic-utils: move `flatten` from tor-protoSteven Engler2025-03-251-10/+1
| | | | | | | | I also added an additional non-doc TODO comment.
| * tor-proto: simplify tunnel `run_once`Steven Engler2025-03-241-7/+1
| | | | | | | | As far as I can tell, the extra drop handling code isn't needed anymore.
| * tor-proto: remove `CircuitActionResult` aliasSteven Engler2025-03-241-4/+1
| | | | | | | | | | I think the return type is simplified enough now that we don't need this.
| * tor-proto: change `ConfluxSet::next_circ_action` to return a `Future`Steven Engler2025-03-242-6/+25
| | | | | | | | | | | | Now returns only the first item of the stream rather than the stream itself. We use this in `Reactor::run_once`, which means we only ever use the first item anyways.
| * tor-proto: rename `ConfluxSet::circuit_action` to `next_circ_action`Steven Engler2025-03-242-6/+6
| |
* | Merge branch 'circuit-cmd' into 'main'gabi-2502025-03-253-66/+155
|\ \ | |/ |/| | | | | tor-proto: Replace RunOnceCmdInner with CircuitCmd in Circuit impl See merge request tpo/core/arti!2881
| * tor-proto: Add a TODO about supporting incoming streams with conflux.Gabriela Moldovan2025-03-241-0/+1
| |
| * tor-proto: Clarify the semantics of various CircuitCmds.Gabriela Moldovan2025-03-241-3/+3
| | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2881#note_3178624
| * tor-proto: Add a TODO about the unnecessary Vec allocations.Gabriela Moldovan2025-03-242-2/+11
| |
| * tor-proto: Add TODO about rethinking the circuit *Cmd enums.Gabriela Moldovan2025-03-241-0/+6
| |
| * tor-proto: s/CircuitAction::Single/CircuitAction::RunCmd.Gabriela Moldovan2025-03-243-8/+6
| | | | | | | | | | There is no `Multiple` counterpart in `CircuitAction`, so the `Single` variant name doesn't make much sense.