summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* Get rid of unbounded stream sender, and RawCellStreameta2021-11-129-149/+183
| | | | | | | | | | | | | | | | | | | | | Previously, the reactor would use an `UnboundedSender` to send things to the `RawCellStream`, in order that the reactor wouldn't block if you failed to read from the latter. This is bad, though, since it means people can just run us out of memory by sending lots of things. To fix this, we make the new `StreamReader` type (which does the reading parts from `RawCellStream`) keep track of the stream's receive window and issue SENDMEs once *it* has consumed enough data to require it, thus meaning that we shouldn't get sent enough data to fill the channel between reactor and `StreamReader` (and, if we do, that's someone trying to flood us, and we abort the circuit). As hinted to above, the `RawCellStream` was removed and its reading functionalities replaced by `StreamReader`; its writing functionalities are handled by `StreamTarget` anyway, so we just give out one of those for the write end. This now means we don't need any mutexes! note: this commit introduces a known issue, arti#230
* Completely overhaul the tor-proto circuit reactoreta2021-11-1211-1297/+1439
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Rather like e8e9699c3c239d6c30f9ad414f15d3bad6ec03fd ("Get rid of tor-proto's ChannelImpl, and use the reactor more instead"), this admittedly rather large commit refactors the way circuits in `tor-proto` work, centralising all of the logic in one large nonblocking reactor which other things send messages into and out of, instead of having a bunch of `-Impl` types that are protected by mutexes. Congestion control becomes a lot simpler with this refactor, since the reactor can manage both stream- and circuit-level congestion control unilaterally without having to share this information with consumers, meaning we can get rid of some locks. The way streams work also changes, in order to facilitate better handling of backpressure / fairness between streams: each stream now has a set of channels to send and receive messages over, instead of sending relay cells directly onto the channel (now, the reactor pulls messages off each stream in each map, and tries to avoid doing so if it won't be able to forward them yet). Additionally, a lot of "close this circuit / stream" messages aren't required any more, since that state is simply indicated by one end of a channel going away. This should make cleanup a lot less brittle. Getting all of this to work involved writing a fair deal of intricate nonblocking code in Reactor::run_once that tries very hard to be mindful of making backpressure work correctly (and congestion control); the old code could get away with having tasks .await on things, but the new reactor can't really do this (as it'd lock the reactor up), so has to do everything in a nonblocking manner.
* Merge branch 'typos' into 'main'eta2021-11-126-7/+7
|\ | | | | | | | | Fix typos See merge request tpo/core/arti!127
| * Fix typosDimitris Apostolou2021-11-126-7/+7
| |
* | Upgrade to async-native-tls 0.4.0Nick Mathewson2021-11-121-1/+1
|/
* Remove usage of tracing-test 0.1Nick Mathewson2021-11-112-3/+0
| | | | | | | | It requires tracing-subscriber 0.2, which is a lower version than we want, and which causes trouble with our minimal-versions CI test. There is a pending issue to fix this; we can reinstate tracing-test once it is merged: https://github.com/dbrgn/tracing-test/pull/11
* Document that the "experimental-api" feature is not semver-covered.Nick Mathewson2021-11-113-0/+14
|
* Document that the "testing" feature is not semver-covered.Nick Mathewson2021-11-113-0/+8
|
* Tests for tor-dirmgr::bootstrapNick Mathewson2021-11-114-1/+223
|
* Minor tests for DirMgr::query_into_requestsNick Mathewson2021-11-111-0/+39
|
* Merge IpVersionPreferences and the optimistic flag into one type.Nick Mathewson2021-11-104-25/+100
| | | | | It seems like a good time to do this, before we add a zillion other arguments to begin_stream.
* Refactor wait_for_connection a bit.Nick Mathewson2021-11-101-12/+14
| | | | | | | * Make it crate-visible only. * Make it idempotent * Have it be an internal error if it's called at the wrong time. * Simplify the return logic.
* Merge remote-tracking branch 'origin/mr/116'Nick Mathewson2021-11-103-24/+63
|\
| * Implement optimistic streamYuan Lyu2021-11-093-24/+63
| |
* | Require consensus-diff line 2 to start with "hash "Nick Mathewson2021-11-101-1/+1
| | | | | | | | | | | | Previously we didn't check for the space. Closes #225.
* | tor-dirmgr: tests for making and expanding consensus requests.Nick Mathewson2021-11-101-0/+125
| |
* | tor-dirmgr: Tests for high-level loading functions.Nick Mathewson2021-11-101-3/+152
|/
* Merge branch 'S0AndS0/arti-cargo-husky' into HEADeta2021-11-091-3/+2
|
* Add a couple of pieces of missing documentation.Nick Mathewson2021-11-082-4/+6
|
* More tests on tor-dirmgr::stateNick Mathewson2021-11-083-27/+113
| | | | | These test our download schedules, resetting to the original state, and storing downloaded objects.
* In rust-nightly CI, forbid debugging prints.Nick Mathewson2021-11-041-0/+3
| | | | | | | | | | | | | | | | | | | | This patch makes the rust-nightly CI task fail if it detects any dbg!(), println!(), or eprintln!() calls in production code. Because of clippy limitations, it may also gripe about calls to these macros in our tests. The preferred workarounds are to either instead. Both are acceptable. We're doing this check in CI rather than unconditionally with clippy directives, since we often want to have these calls in our code temporarily while we're developing. Some day we might want this test to go into a pre-push hook. This patch also adds #![allow()] directives for println!() and eprintln!() in the arti crate. Since that one isn't a library, it's okay for it to speak to stdout/stderr. Closes #218.
* Remove one more test println!().Nick Mathewson2021-11-041-1/+0
|
* Replace all println/eprintln calls outside of arti CLI with trace.Nick Mathewson2021-11-047-30/+39
|
* Remove all remaining dbg! instances.Nick Mathewson2021-11-044-11/+0
|
* tor-dirmgr: tests for docid module.Nick Mathewson2021-11-041-1/+156
|
* Basic tests for readonly estimators, and estimator migration.Nick Mathewson2021-11-032-2/+92
| | | | | Also add a comment about a possible problem behavior in read-only estimators.
* Change how TestingStateMgr handles locking.Nick Mathewson2021-11-031-43/+80
| | | | | | Previously it was either all-locked or all-not-locked. Now you can simulate having the same shared storage opened by multiple managers, only one of which has the lock.
* tor-proto: Use a dedicated sender for channel cells, make full-duplexeta2021-11-032-47/+105
| | | | | | | | | | | | | | | | @nickm pointed out that refactoring tor_proto::channel's Reactor to do sending as well meant that it could only send or receive, but not both, simultaneously, which was bad! To fix this, rewrite Reactor::run_once to use a handcrafted future (with futures::future::poll_fn) that can handle the logic required to push items onto the sink asynchronously (i.e. checking that it can be written to before trying to do that, and then flushing it). This also means we don't use select_biased! any more, and just handroll that logic ourselves; as a small bonus, we can now process all 3 kinds of message in one run_once() call, instead of having to do only one of them.
* Get rid of tor-proto's ChannelImpl, and use the reactor more insteadeta2021-11-0310-347/+268
| | | | | | | | | | | | | | | | | | | Instead of awkwardly sharing the internals of a `tor-proto` `Channel` between the reactor task and any other tasks, move most of the internals into the reactor and have other tasks communicate with the reactor via message-passing to allocate circuits and send cells. This makes a lot of things simple, and has convenient properties like not needing to wrap the `Channel` in an `Arc` (though some places in the code still do this for now). A lot of test code required tweaking in order to deal with the refactor; in fact, fixing the tests probably took longer than writing the mainline code (!). Importantly, we now use `tokio`'s `tokio::test` annotation instead of `async_test`, so that we can run things in the background (which is required to have reactors running for the circuit tests). This is an instance of #205, and also kind of #217.
* Disable a check in exitpathNick Mathewson2021-11-021-1/+2
| | | | | This check relies on families being enforced correctly, which is not the case when specifying a fixed exit and using guards. (See #183)
* Allow clone-on-copy in tor-circmgr tests to fix a nightly-only clippy warning.Nick Mathewson2021-11-022-0/+2
|
* Merge branch 'bug219'Nick Mathewson2021-11-023-63/+28
|\
| * Refactor tor-guardmgr's inter-task communication.Nick Mathewson2021-11-023-63/+28
| | | | | | | | | | | | | | | | | | This is based on @eta's patches for !118 and !119: Since we already have an unbounded channel, we don't need to use an elaborate mess of one-shot senders. We can just use the unbounded_send() method, which also lets us enqueue a message without having to await. Closes #219.
* | tor-circmgr: test ExitPathBuilder with guards.Nick Mathewson2021-11-024-0/+115
| |
* | tor-circmgr: test DirPathBuilder with GuardMgr.Nick Mathewson2021-11-023-1/+43
| |
* | tor-circmgr: testing for NoUsage and TimeoutTesting usageNick Mathewson2021-11-021-0/+24
| | | | | | | | This doesn't add much to coverage, but it's important.
* | Merge branch 'timestamp'Nick Mathewson2021-11-0211-47/+272
|\ \
| * | Add a comment to explain the computation of net_has_been_down.Nick Mathewson2021-11-021-0/+5
| | |
| * | tor-guardmgr: Add tests for a few functions.Nick Mathewson2021-11-022-0/+57
| | |
| * | Mark primary guards as retriable when we come back online.Nick Mathewson2021-11-024-47/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We define "coming back online" as happening when a guard attempt succeeds, if that attempt that was launched when we seemed to be offline. We define "seeming to be offline" as having all of our primary guards marked unreachable, and having received no incoming network traffic in a while. Closes #216.
| * | Use coarsetime to build an incoming traffic timestamp.Nick Mathewson2021-11-026-0/+146
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need this for the circuit timeout estimator (#57). It needs to know "how recently have we got some incoming traffic", so that it can tell whether a circuit has truly timed out, or whether the entire network is down. I'm implementing this with coarsetime, since we need to update these in response to every single incoming cell, and we need the timestamp operation to be _fast_. (This reinstates an earlier commit, f30b2280, which I reverted because we didn't need it at the time.) Closes #179.
* | | Merge remote-tracking branch 'origin/mr/119'Nick Mathewson2021-11-022-85/+31
|\ \ \ | |_|/ |/| |
| * | Refactor tor_proto::circuit::Reactor to use an UnboundedSendereta2021-11-022-85/+31
| | | | | | | | | | | | | | | | | | | | | | | | Basically the same thing as 371437d3384ed73520e7141e66874be3d85f1df0 ("Refactor tor_proto::channel::Reactor to use an UnboundedSender"), but for tor_proto::circuit's Reactor instead. (part of arti#217)
* | | tor-circmgr: tests for netwoks with no exitsNick Mathewson2021-11-022-25/+76
|/ /
* | Merge remote-tracking branch 'origin/mr/118'Nick Mathewson2021-11-022-78/+32
|\ \
| * | Refactor tor_proto::channel::Reactor to use an UnboundedSendereta2021-11-022-78/+32
| |/ | | | | | | | | | | | | | | | | | | | | There wasn't any good reason for tor-proto's channel reactor to use a shedload of oneshot channels instead of just an mpsc UnboundedSender, and the whole `CtrlResult` thing made even less sense. Straighten this code out by replacing all of that machinery with a simple UnboundedSender, instead. (part of arti#218)
* | Remove some dbg!() calls in real code.Nick Mathewson2021-11-023-4/+1
| |
* | tor-circmgr::usage: Add a few more tests.Nick Mathewson2021-11-021-2/+66
|/
* tor-persist: serde usage now requires derive feature.Nick Mathewson2021-10-291-2/+1
|
* Bump all crate versions to 0.0.1Nick Mathewson2021-10-2926-123/+123
|