summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | Add basic DirProvider trait, use it in clientChristian Grigis2022-02-232-6/+80
| | |
* | | Merge branch 'clippy-allow-arc-clone' into 'main'Nick Mathewson2022-03-0130-30/+0
|\ \ \ | | | | | | | | | | | | | | | | Disable clippy::clone_on_ref_ptr See merge request tpo/core/arti!352
| * | | Disable clippy::clone_on_ref_ptrIan Jackson2022-02-2430-30/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This lint is IMO inherently ill-conceived. I have looked for the reasons why this might be thought to be a good idea and there were basically two (and they are sort of contradictory): I. "Calling ‘.clone()` on an Rc, Arc, or Weak can obscure the fact that only the pointer is being cloned, not the underlying data." This is the wording from https://rust-lang.github.io/rust-clippy/v0.0.212/#clone_on_ref_ptr It is a bit terse; we are left to infer why it is a bad idea to obscure this fact. It seems to me that if it is bad to obscure some fact, that must be because the fact is a hazard. But why would it be a hazard to not copy the underlying data ? In other languages, faliing to copy the underlying data is a serious correctness hazard. There is a whose class of bugs where things were not copied, and then mutated and/or reused in multiple places in ways that were not what the programmer intended. In my experience, this is a very common bug when writing Python and Javascript. I'm told it's common in golang too. But in Rust this bug is much much harder to write. The data inside an Arc is immutable. To have this bug you'd have use interior mutability - ie mess around with Mutex or RefCell. That provides a good barrier to these kind of accidents. II. "The reason for writing Rc::clone and Arc::clone [is] to make it clear that only the pointer is being cloned, as opposed to the underlying data. The former is always fast, while the latter can be very expensive depending on what is being cloned." This is the reasoning found here https://github.com/rust-lang/rust-clippy/issues/2048 This is saying that *not* using Arc::clone is hazardous. Specifically, that a deep clone is a performance hazard. But for this argument, the lint is precisely backwards. It's linting the "good" case and asking for it to be written in a more explicit way; while the supposedly bad case can be written conveniently. Also, many objects (in our codebase, and in all the libraries we use) that are Clone are in fact simply handles. They contain Arc(s) (or similar) and are cheap to clone. Indeed, that is the usual case. It does not make sense to distinguish in the syntax we use to clone such a handle, whether the handle is a transparent Arc, or an opaque struct containing one or more other handles. Forcing Arc::clone to be written as such makes for code churn when a type is changed from Arc<Something> to Something: Clone, or vice versa.
* | | | Bump all crates to 0.1.0arti-v0.1.0Nick Mathewson2022-03-0131-160/+160
| | | |
* | | | Update README.md files from rustdoc.Nick Mathewson2022-03-017-112/+173
| | | |
* | | | Fix rustdoc errors.Nick Mathewson2022-03-013-10/+11
| | | |
* | | | Run rustfmt.Nick Mathewson2022-03-011-1/+0
| | | |
* | | | Merge remote-tracking branch 'origin/mr/371'Nick Mathewson2022-03-012-2/+31
|\ \ \ \
| * | | | arti-hyper: Upgrade from an example to an "adaptation layer"Ian Jackson2022-03-011-0/+8
| | | | |
| * | | | arti-hyper: Expand docsIan Jackson2022-03-011-1/+15
| | | | |
| * | | | arti-hyper: Drop obsolete comment about not doing TLSIan Jackson2022-03-011-2/+0
| | | | |
| * | | | arti-client: Add stability warning to config moduleIan Jackson2022-03-011-0/+9
| | | | |
| * | | | Merge branch 'main' into hyper-docsIan Jackson2022-03-016-83/+183
| |\ \ \ \
* | | | | | Merge branch '010_docs'Nick Mathewson2022-03-014-7/+36
|\| | | | |
| * | | | | Update our stability warning on arti-client.Nick Mathewson2022-02-281-5/+12
| | | | | |
| * | | | | Add warnings about configuration stability.Nick Mathewson2022-02-283-2/+24
| | | | | |
* | | | | | Merge branch 'main' into 364Ian Jackson2022-03-017-84/+183
|\ \ \ \ \ \ | | |/ / / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: crates/arti-hyper/examples/hyper.rs Trivially resolved. Hyper example still works.
| * | | | | Merge branch 'tls' into 'main'Nick Mathewson2022-02-285-38/+133
| |\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement TLS in arti-hyper See merge request tpo/core/arti!355
| | * | | | | Fix typo in messageNick Mathewson2022-02-281-1/+1
| | | | | | |
| | * | | | | arti-hyper: Add vacuous doc comments as required by clippyIan Jackson2022-02-281-0/+3
| | | | | | |
| | * | | | | EK::RemoteProtocolFailed replaces OtherRemoteIan Jackson2022-02-282-7/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/355#note_2781816
| | * | | | | Fix rustfmtIan Jackson2022-02-281-9/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | I disagree with all these. Whatever.
| | * | | | | arti-hyper: Abolish a bool in favour of a custom private enumIan Jackson2022-02-281-12/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/355#note_2781820
| | * | | | | arti-hyper: Box the http variant (bare DataStream)Ian Jackson2022-02-281-7/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/355#note_2781819
| | * | | | | arti-hyper: Fix duplicative doc comment not to be wrongIan Jackson2022-02-281-1/+1
| | | | | | |
| | * | | | | arti-hyper: Drop description of nonexistent error-detail featureIan Jackson2022-02-281-3/+0
| | | | | | |
| | * | | | | arti-hyper: Clarify what the TLS features do.Ian Jackson2022-02-281-1/+2
| | | | | | |
| | * | | | | arti-hyper: Actually support TLSIan Jackson2022-02-283-19/+39
| | | | | | |
| | * | | | | arti-hyper: Provide TLS connector and make space for TLS streamIan Jackson2022-02-283-19/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add tls_conn field to ArtiHttpConnector (and argument to constructor). Introduce MaybeHttpsStream and use it in ArtiHttpConnection. Have the example program pass the native TLS connector. Currently the TLS connector and the HTTPS variant are not used, but this commit is very noisy and fomrulaic, so I have split out the code to use them into a separate commit for easier preparation and review.
| | * | | | | Manually implement Clone for ArtiHttpConnectorIan Jackson2022-02-281-1/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will be needed in a moment and doing it now makes the next patch smaller and hence easier to read.
| | * | | | | Introduce ErrorKind::OtherRemoteIan Jackson2022-02-281-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti-hyper wants to be able to have a kind for TLS failure. Given that arti-hyper is above arti-client, this shows that callers above arti-client might need to invent kinds for their own errors. Possibly this means we need other Other errors for other locations. If we have pluggable components we might even want OtherTorError.
| | * | | | | arti-hyper: Disable clippy::clone_on_ref_ptrIan Jackson2022-02-281-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/355#note_2781816 disable this here for now, pending a decision on !352
| * | | | | | Merge branch 'retry-err-circmgr' into 'main'Nick Mathewson2022-02-281-45/+50
| |\ \ \ \ \ \ | | |_|/ / / / | |/| | | | | | | | | | | | | | | | | | | add some error to retry_error instead of dropping it See merge request tpo/core/arti!368
| | * | | | | resolve commenttrinity-1686a2022-02-281-1/+6
| | | | | | |
| | * | | | | add some error to retry_error instead of dropping ittrinity-1686a2022-02-281-45/+45
| | | | | | |
| * | | | | | remove usage of dbg!(..)trinity-1686a2022-02-281-1/+0
| |/ / / / / | | | | | | | | | | | | | | | | | | it's making rust-nightly job fail
* | | | | | Merge branch 'main'Ian Jackson2022-03-0112-24/+80
|\| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixed conflict in crates/arti-client/src/lib.rs as per tree from https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/364/#note_2782166 ie 13e55b8d7c22c26e55ba75823409b477f1bce66b
| * | | | | Merge branch 'teardown' into 'main'Nick Mathewson2022-02-281-1/+12
| |\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-circmgr: take_action: Handle Cancelled from the oneshot Closes #365 See merge request tpo/core/arti!363
| | * | | | | Add a debug! log message for source cancellationIan Jackson2022-02-281-0/+4
| | | | | | |
| | * | | | | Fix rustfmtIan Jackson2022-02-281-1/+1
| | | | | | |
| | * | | | | tor-circmgr: take_action: Handle Cancelled from the oneshotIan Jackson2022-02-251-1/+8
| | | |_|_|/ | | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes #365 Inspection of the code and logs shows that: * One of the plan futures' oneshots must be returning Cancelled * This means that the corresponding sender must have been dropped * The sender is owned by the task spawned by spawn_launch Presumably that entire task gets dropped as part of executor shutdown, or something. The correct response in this situation is to declare that we are shutting down, and stop trying to do stuff. Unfortunately, despite trying quite hard by putting sleeps in various strategic places, I have not been able to reproduce the problem. So I can't be 100% sure that the new behaviour is correct. But I am reasonably confident that this ought not to be able to occur unless either 1. the task from spawn_launch is dropped, or 2. that task somehow panics despite its attempts to trap panics and report them as errors through the oneshot. So this "burn it all down" action ought only to occur in actually serious situations. I observe that 3ff9b187ea26aaec4875067fcdbf485ecc9f597d Handle panics from circuit construction. changed the EK for PendingCanceled to EK::ReactorShuttingDown, and there's From impl. I think, therefore, that it is right to reuse this Error variant. I don't quite understand why when take_action gets an actual error it doesn't push it, but just logs it. But I am not changing that for now. Arguably the two instances of retry_error.push are a sign of an inferior flow control pattern - maybe the loop body including the code I am adding ought to be an IEFE returning `Result<Option<circ>, crate::Error>`.
| * | | | | Merge branch 'split-static' into 'main'eta2022-02-284-7/+41
| |\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Split "static" into sqlite and native-tls features. Closes #302 See merge request tpo/core/arti!362
| | * | | | | Split "static" into sqlite and native-tls features.Nick Mathewson2022-02-254-7/+41
| | |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Otherwise, it's impossible to get a static sqlite linkage without also getting native-tls, even if you wanted rustls. Closes #302.
| * | | | | Merge branch 'always-coarsetime' into 'main'eta2022-02-284-13/+3
| |\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Make coarsetime dependency and traffic-timestamping non-optional. See merge request tpo/core/arti!358
| | * | | | | Make coarsetime dependency and traffic-timestamping non-optional.Nick Mathewson2022-02-254-13/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously coarsetime and the traffic-timestamp feature were enabled, since they were only required for a small corner of the guardmgr algorithm. But in 1.0 and beyond we'll be adding a bunch of other features (eg, netflow padding, DoS prevention) that will need coarsetime all over the place. And since we're going to be doing coarsetime all over the place, the previous justification for making traffic-timestamping optional (the tiny performance hit) is no longer relevant.
| * | | | | | Merge branch 'fix/210' into 'main'Nick Mathewson2022-02-281-1/+1
| |\ \ \ \ \ \ | | |_|_|/ / / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | don't return already errored pending circuit when searching new circuit matching spec Closes #210 See merge request tpo/core/arti!366
| | * | | | | don't return already errored pending circuit when searching new circuit ↵trinity-1686a2022-02-271-1/+1
| | | |/ / / | | |/| | | | | | | | | | | | | | | matching spec
| * | | | | Fix two typosNick Mathewson2022-02-282-2/+2
| | | | | |
| * | | | | impl Debug for various internal typesIan Jackson2022-02-254-4/+36
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I wanted this while debugging something. The ad-hoc impl Debug with f.debug_struct is getting repetitive and I've already perpetrated one copy-paste mistake. We should consider using something like the `educe` crate's Clone.
* | | | | arti-client: use PreferredRuntime by default, doc cleanupseta2022-02-289-139/+156
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes using the `PreferredRuntime` the first-class option inside `arti-client`, freeing users who don't want to think about runtimes from having to do so. `TorClient::create_unbootstrapped` and `builder` now automatically use this runtime, leaving only `builder_custom` for users who wish to manually specify a runtime. This lets us clean up the docs a lot: mentions of using custom runtimes are now relegated to nearer the end of the crate-level documentation, and we mostly just link to `tor_rtcompat`'s docs to explain more there. Instead, we take some more time to explain how you use the builder API to create clients synchronously. Other doc cleanups included getting rid of the explanation of `TorAddr` in the main crate-level doc; this is already well-documented elsewhere, and is something users should discover organically later. fixes arti#326