summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
| * | Circuit reactor: don't process streams when we don't have circuit windowJim Newsome2024-08-131-18/+11
| | | | | | | | | | | | | | | | | | | | | When we've exhausted circuit-level SENDME window, iterating over streams is likely to be a waste of CPU. Theoretically we might be able to send some messages that don't count towards windows, but on balance it doesn't seem worth it.
| * | StreamMap: apply stream flow control before making messages availableJim Newsome2024-08-132-17/+83
| | | | | | | | | | | | | | | | | | This prevents us from having to iterate over streams blocked on flow control inside the circuit reactor, and potentially allows further simplification.
| * | tor-proto: Encapsulate flow-controlJim Newsome2024-08-135-59/+132
| | | | | | | | | | | | | | | | | | Encapsulate flow-control into a separate object that partially abstracts away the difference between window-based (legacy) flow control and xon-based (prop324) flow control.
| * | Circuit reactor: remove unnecessary circ window precheckJim Newsome2024-08-131-21/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | Since we no longer have an outbound queue for each hop, and instead return an error here if there is insufficient circuit window to send a message, there's no need to pre-check whether we have sufficient window. If there's insufficient circuit window, we'll still return an error slightly later, after failing to take from the circuit window.
| * | StreamMap: rm stray commentJim Newsome2024-08-131-3/+0
| | |
* | | tor-memquota: mq_queue: tests: Replace eprintln with debugIan Jackson2024-08-151-1/+1
| | | | | | | | | | | | We use `debug!` (tracing logging) everywhere else. Use it here too.
* | | tor-memquota: mq_queue: tests: fill_and_empty: check balanceIan Jackson2024-08-151-0/+3
| | |
* | | tor-memquota: mq_queue: tests: break out check_zero_claimed and fix bugIan Jackson2024-08-151-1/+17
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Each queue has two `Participation`s, not just one. This didn't matter in the `lifecycle` test, because one of the two Participations was never touched since it was cloned, and a fresh clone starts out with a cache of zero. But we're about to reuse this code in a context where both Participations end up with a cache.
* | | tor-memquota: mq_queue: impl Default for MpscUnboundedSpecIan Jackson2024-08-151-1/+1
| | |
* | | tor-memquota: mq_queue: Provide `new` constructors for SpecsIan Jackson2024-08-152-3/+8
| | | | | | | | | | | | | | | Discussed here https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059928
* | | tor-memquota: mq_queue: Fix doc for `MpscSpec`Ian Jackson2024-08-151-2/+2
| | | | | | | | | | | | It's not a unit. It's `MpscUnboundedSpec` that's a unit
* | | tor-memquota: mq_queue: Rename Mpsc to MpscSpecIan Jackson2024-08-151-12/+12
| | | | | | | | | | | | | | | | | | | | | And MpscUnboundedSpec too. As discussed in https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059516
* | | tor-memquota: mq_queue: Add a caveat about faithfulness/accuracyIan Jackson2024-08-151-0/+14
| | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059543
* | | tor-memquota: Rename mby test helper fn to mbytesIan Jackson2024-08-153-18/+18
| | | | | | | | | | | | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059520
* | | tor-memquota: mq_queue: Call mpsc::Receiver::close in our rx DropIan Jackson2024-08-151-0/+27
| | | | | | | | | | | | | | | Fixes the livelock possibility discussed here https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059519
* | | tor-memquota: StreamUnobtrusivePeeker: provide as_raw_inner_pin_mutIan Jackson2024-08-151-0/+11
| | | | | | | | | | | | | | | | | | | | | | | | This will let us call mpsc::Receiver::close. We have it take Pin, even though we don't really want that for our use case, because if you use StreamUnobtrusivePeeker with a non-Unpin stream you'll ant that.
* | | tor-memquota: mq_queue: Add fill_and_empty testIan Jackson2024-08-151-0/+23
| | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059518
* | | tor-memquota: Add blank lines before fns except in testsIan Jackson2024-08-151-0/+6
| | | | | | | | | | | | | | | Requested by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2292#note_3059517
* | | tor-memquota: Fix typosIan Jackson2024-08-152-5/+5
| | |
* | | tor-memquota: Add mq_queue, memory-quota-tracking (MPSC) queue (tests)Ian Jackson2024-08-151-0/+179
| | |
* | | tor-memquota: Add mq_queue, memory-quota-tracking (MPSC) queueIan Jackson2024-08-155-5/+507
| | |
* | | tor-memquota: Add a Sealed traitIan Jackson2024-08-152-0/+7
| | | | | | | | | | | | We'll use this in a moment.
* | | tor-memquota: Provide Participation::new_dangling and WeakAccount::new_danglingIan Jackson2024-08-151-0/+26
| | | | | | | | | | | | | | | We're going to want the one for Participation - it saves us an annoying Option. Let's provide the one for WeakAccount too.
* | | Merge branch 'mandatory-guardmgr' into 'main'gabi-2502024-08-157-510/+369
|\ \ \ | | | | | | | | | | | | | | | | tor-circmg: Make `GuardMgr` mandatory See merge request tpo/core/arti!2339
| * | | tor-circmgr: fix flaky `path::exitpath::test::by_ports` testSteven Engler2024-08-132-7/+23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The `path::exitpath::test::by_ports` test sometimes failed now that the test is using a `GuardMgr` since `select_guard`, when given a chosen exit, only ensures that the guard and chosen exit are not in the same family. It does not ensure that the guard and exit do not share an extended family. This commit relaxes an assertion in the test. ```text thread 'path::exitpath::test::by_ports' panicked at crates/tor-circmgr/src/path/exitpath.rs:295:9: assertion failed: r1.can_share_circuit(r3, subnet_config) ``` This "chosen exit" functionality isn't actually being used anywhere (`ExitPathBuilderInner::ChosenExit` is only ever constructed in tests).
| * | | tor-circmgr: assert in test that exit path begins with guardSteven Engler2024-08-121-2/+4
| | | |
| * | | tor-circmgr: make `GuardMgr` mandatorySteven Engler2024-08-127-316/+146
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Functions that took `Option<&GuardMgr>` now take only `&GuardMgr`. Three unit tests were removed that covered behaviour when no guard manager was set.
| * | | tor-circmg: prepare tests for runtime requirementSteven Engler2024-08-122-218/+229
| | | | | | | | | | | | | | | | | | | | | | | | This wraps some unit tests with `tor_rtcompat::test_with_all_runtimes!`. This is its own commit to get the indentation changes out of the way and declutter the following commit.
* | | | Merge branch 'rpc-use-slotmap' into 'main'gabi-2502024-08-153-35/+38
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | rpcserver: Use slotmap-careful instead of generational-arena. Closes #1282 See merge request tpo/core/arti!2343
| * | | | rpcserver: Use slotmap-careful instead of generational-arena.Nick Mathewson2024-08-143-35/+38
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Unlike generational-arena, slotmap is maintained. Unlike slotmap, slotmap-careful should never be able to reuse the same key for two different objects. Closes #1282.
* | | | | ffi: Rename arti_rpc_status_to_str.Nick Mathewson2024-08-142-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (This function manipulates an ArtiRpcStatus; and we try to have all of the ffi functions in this library begin with "arti_rpc_".)
* | | | | cbindgen: Correctly hide "Utf8CString".Nick Mathewson2024-08-143-9/+10
|/ / / /
* | | | Merge branch 'careful-slotmap' into 'main'Nick Mathewson2024-08-144-0/+1296
|\ \ \ \ | |_|_|/ |/| | | | | | | | | | | New `slotmap-careful` crate to use when we mustn't re-use keys. See merge request tpo/core/arti!2298
| * | | slotmap-careful: Try to make test work with MSRV.Nick Mathewson2024-08-081-8/+4
| | | |
| * | | New `slotmap-careful` crate to use when we mustn't re-use keys.Nick Mathewson2024-08-084-0/+1300
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This crate works as a drop-in replacement for the generational arena types `slotmap::{SlotMap, DenseSlotMap, HopSlotMap}`, and is implemented a set of wrappers around those types. The wrappers guarantee that slot versions numbers can never wrap around by marking as unusable any slot whose version number would otherwise get too high. (We add some leeway between our max allowed version number and the largest possible version number, so that we can detect bugs.) The code relies on the serde encoding of slotmap key versions. For notes on stability and (surprisingly good) performance, see the comments. Test coverage is around 98% for the lib.rs file; it's lower in key_data.rs, since the error cases are unreachable given slotmap's current behavior. Open questions: * What further testing is a good idea? * Will slotmap ever upstream something like this? See "# Limitations" comment for the parts of slotmap that are not implemented; I hope that we don't need them.
* | | | Merge branch 'mistrust-refactor' into 'main'gabi-2502024-08-141-6/+63
|\ \ \ \ | |_|_|/ |/| | | | | | | | | | | fs-mistrust: Avoid opening the file in CheckedDir::metadata(). See merge request tpo/core/arti!2324
| * | | fs-mistrust: Make CheckedDir::metadata() return an error if path is symlink.Gabriela Moldovan2024-08-121-2/+45
| | | |
| * | | fs-mistrust: Avoid opening the file in CheckedDir::metadata().Gabriela Moldovan2024-08-081-5/+19
| | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2291#note_3057232
* | | | Merge branch 'rpc-connection-error' into 'main'Nick Mathewson2024-08-131-16/+66
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | rpcserver: use more sophisticated handling for ConnectionError. Closes #1517 See merge request tpo/core/arti!2335
| * | | | rpcserver: use more sophisticated handling for ConnectionError.Nick Mathewson2024-08-121-16/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In general, we don't want to return a ConnectionError for a simple EOF condition; we only want to report an error when there's an actual failure. Also, it's a good idea to capture the actual error return conditions that we get from aynchronous_codecs, rather than throwing them away as we did before. Closes #1517.
* | | | | Merge branch 'streampollset-no-v' into 'main'David Goulet2024-08-132-24/+21
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | StreamPollSet: remove redundant type parameter V See merge request tpo/core/arti!2334
| * | | | | StreamPollSet: remove redundant type parameter VJim Newsome2024-08-122-24/+21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This was required to be the same type as `S::Item`. We can just use `S::Item` directly.
* | | | | | Merge branch 'ffi_dylib' into 'main'Alexander Færøy2024-08-131-0/+3
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | ffi: Build arti-rpc-client-core as a C dynamic library. See merge request tpo/core/arti!2331
| * | | | | | ffi: Build client-core as a dynamic library.Nick Mathewson2024-08-061-0/+3
| | | | | | |
* | | | | | | Resolve unreachable_patterns warnings from nightly.Nick Mathewson2024-08-133-28/+19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Nightly rust doesn't like it when you have a `match` arm that can never be reached because of an uninhabited type. As such, we can't say stuff like: ``` let x: Option<Void> = ...; match x { Some(_) => unreachable!(), None => ... } ```
* | | | | | | Merge branch 'nightly-doc-failure' into 'main'Nick Mathewson2024-08-131-0/+1
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add a missing incantation to fix doc(cfg=...). See merge request tpo/core/arti!2337
| * | | | | | | Add a missing incantation to fix doc(cfg=...).Nick Mathewson2024-08-131-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Without this, we get a warning when we run `cargo doc`.
* | | | | | | | tor-hsservice: Log whether the service is running in restricted discovery mode.Gabriela Moldovan2024-08-131-0/+12
| | | | | | | |
* | | | | | | | tor-hsservice: Move authorized_clients out of RunningOnionService.Gabriela Moldovan2024-08-133-31/+9
|/ / / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We now create the authorized_clients in the publisher (we don't need the authorized_clients anywhere else, so it makes little sense to keep them in `RunningOnionService`).
* | | | | | | Merge branch 'rpc-describe' into 'main'Nick Mathewson2024-08-139-12/+217
|\ \ \ \ \ \ \ | |_|_|/ / / / |/| | | | | | | | | | | | | | | | | | | | RPC: Method to expose a list of RPC methods. See merge request tpo/core/arti!2332