summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* Remove Guard::get_relay(); use Guard::guard_id().get_relay().Nick Mathewson2021-10-191-12/+4
| | | | | | | | | The `get_relay` function was confusing, since it would return None if the relay was present, but wasn't actually a guard. We only used it in one place, and in that one place we used it wrong, leading to a panic bug. Fixes #193.
* Remove special-case for ipv6 in is_valid_hostnameNick Mathewson2021-10-181-10/+2
|
* Use a proper RFC5737 address in tests.Nick Mathewson2021-10-181-2/+2
|
* Add the "clock" feature to chrono in netdoc.Nick Mathewson2021-10-181-1/+1
| | | | | | This seems to fix a bug when running cargo check on netdoc individually. Reported by @janimo
* Move hostname enforcement into TorAddr.Nick Mathewson2021-10-182-97/+132
|
* Change how we connect to target addresses.Nick Mathewson2021-10-185-9/+262
| | | | | | | Now we all both address:port, (address, port), and more. We also allow SocketAddr and IpAddr, but only via a trait labeled as "Dangerous".
* Remove "internal" address checking to its own function.Nick Mathewson2021-10-181-38/+45
|
* Merge branch 'reject_bad_hostnames'Nick Mathewson2021-10-186-3/+144
|\
| * Rename is_localhost to allow_local_addrs, and apply it to IPs too.Nick Mathewson2021-10-183-8/+13
| |
| * Formatting fixesNeel Chauhan2021-10-062-5/+9
| |
| * Make is_valid_hostname() globalNeel Chauhan2021-10-061-44/+45
| |
| * Add unit tests for hostnamesNeel Chauhan2021-10-061-4/+34
| |
| * Introduce ClientConfig for is_localhost config parameterNeel Chauhan2021-10-066-7/+57
| |
| * Hostname corrections and add IPv6 hostname validation supportNeel Chauhan2021-10-061-5/+15
| |
| * Reject bad hostnames and internal addresses in ArtiNeel Chauhan2021-10-061-0/+39
| |
* | Do not use downcast_ref, use tor-client error.Jani Monoses2021-10-181-8/+6
| |
* | Remove anyhow usage in tor-client.Jani Monoses2021-10-184-5/+65
| |
* | Remove useless into() conversions caught by clippy.Jani Monoses2021-10-185-28/+30
| |
* | Remove anyhow dependency from tor-dirmgr.Jani Monoses2021-10-184-13/+62
| |
* | Use unwrap in tests.Jani Monoses2021-10-181-9/+15
| | | | | | | | | | | | | | | | | | For now, this avoids having to separately handle AuthorityBuilderError, DirMgrConfigBuilderError, DownloadScheduleConfigBuilderError, NetworkConfigBuilderError and FallbackDirBuilderError when anyhow is not used. Turn off a clippy warning.
* | Use append in place of extend_from_slice in DataReaderImpl::add_data.Nick Mathewson2021-10-171-2/+2
| | | | | | | | Suggested by @cheako.
* | Turn off default-features in chrono where possible.Nick Mathewson2021-10-172-2/+2
| |
* | Add a cast to correct a type error about WSAEMFILENick Mathewson2021-10-151-1/+7
| |
* | arti: On startup, increase the NOFILE resource limit.Nick Mathewson2021-10-143-0/+29
| | | | | | | | | | | | | | | | | | | | | | The default soft limit is typically enough for process usage on most Unixes, but OSX has a pretty low default (256), which you can run into easily under heavy usage. With this patch, we're going to aim for as much as 16384, if we're allowed. Fixes part of #188.
* | proxy: Mark ENFILES and EMFILES as survivable.Nick Mathewson2021-10-142-2/+33
| | | | | | | | | | | | | | | | I don't love this approach, but those errors aren't distinguished by ErrorKind, so we have to use libc or winapi, apparently. At least nothing here is unsafe. Addresses part of #188.
* | Add a few tracing directives to tor-dirmgr.Nick Mathewson2021-10-133-3/+14
| |
* | tor-dirmgr: report bootstrap success on all successful cases.Nick Mathewson2021-10-131-0/+5
| | | | | | | | | | Previously we would sometimes fail to report that we had successfully bootstrapped.
* | Fix a documentation link error.Nick Mathewson2021-10-131-4/+2
| |
* | Report errors in logging configuration a bit more usefullyNick Mathewson2021-10-131-2/+22
| |
* | Document trace_filter example in main.rs too.Nick Mathewson2021-10-131-0/+2
| |
* | Don't report the bootstrap as completed unless it actually succeeds.Nick Mathewson2021-10-132-5/+14
| | | | | | | | | | (Previously we'd report it as successful even if the inner download task was a failure.)
* | Use better reporting for guard status.Nick Mathewson2021-10-135-24/+127
| | | | | | | | | | | | | | | | | | | | | | | | | | The previous code would report all failures to build a circuit as failures of the guard. But of course that's not right: If we fail to extend to the second or third hop, that might or might not be the guard's fault. Now we use the "pending status" feature of the GuardMonitor type so that an early failure is attributed to the guard, but a later failure is attributed as "Indeterminate". Only a complete circuit is called a success. We use a new "GuardStatusHandle" type here so that we can report the status early if there is a timeout.
* | Rename GuardStatusMsg, make it public, add an `Indeterminate` case.Nick Mathewson2021-10-133-26/+43
| |
* | Implement guards for multihop paths.Nick Mathewson2021-10-133-26/+87
| | | | | | | | There are some limitations here, as noted in the comments.
* | Actually select guards for directory circuits.Nick Mathewson2021-10-134-13/+27
| |
* | Pass the guard manager down to the path selection functions.Nick Mathewson2021-10-115-14/+37
| |
* | WIPNick Mathewson2021-10-114-13/+19
| |
* | Make the guard selection function return a more useful type.Nick Mathewson2021-10-113-4/+56
| |
* | Add a function to look up a Relay by ChanTarget.Nick Mathewson2021-10-111-0/+8
| |
* | Integrate GuardUsability and GuardMonitor into CircuitBuilder.Nick Mathewson2021-10-103-11/+73
| | | | | | | | | | | | (When we're building a path with a guard, we need to tell the guard manager whether the path succeeded, and we need to wait to hear whether the guard is usable.)
* | Notify guard manager on network change and state flush.Nick Mathewson2021-10-106-8/+67
| |
* | Add a GuardMgr member to CircuitBuilderNick Mathewson2021-10-105-4/+21
| |
* | Change the GuardMgr APIs to no longer be async.Nick Mathewson2021-10-101-32/+18
| |
* | Use an mpsc::unbounded() channel in GuardMgr.Nick Mathewson2021-10-102-29/+22
| | | | | | | | | | | | | | | | | | | | | | | | The advantage here is that we no longer have to use a futures-aware Mutex, or a blocking send operation, and therefore can simplify a bunch of the GuardMgr APIs to no longer be async. That'll avoid having to propagate the asyncness up the stack. The disadvantage is that unbounded channels are just that: nothing in the channel prevents us from overfilling it. Fortunately, the process that consumes from the channel shouldn't block much, and the channel only gets filled when we're planning a circuit path.
* | Require up-to-date x25519-dalek, async_executors, and argh.Nick Mathewson2021-10-093-3/+3
| | | | | | | | | | | | | | | | I tried using -Z minimal-versions to downgrade all first-level dependencies to their oldest permitted versions, and found that we were apparently depending on newer features of all three crates. I'm kind of surprised there were only three.
* | Lock down some dirmgr config functions.Nick Mathewson2021-10-091-11/+11
| |
* | Re-export configuration types from tor-client.Nick Mathewson2021-10-0910-12/+55
| |
* | enable checked_conversions lint.Nick Mathewson2021-10-0929-22/+74
| |
* | Normalize tor-guardmgr warningsNick Mathewson2021-10-091-6/+6
| |
* | Note a possible heisenbug in a unit test.Nick Mathewson2021-10-081-0/+6
| |