| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
ffi: Expose errno from errors that have it.
Closes #1501
See merge request tpo/core/arti!2311
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Closes #1501.
|
| | | | | |
| | | | |
| | | | |
| | | | | |
(This is an errno or a GetLastError.)
|
| | |/ / /
| | | |
| | | |
| | | |
| | | | |
This will make error outputs more usable, and will make it possible
to expose OS error codes.
|
| |/ / /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The help output of the `-c ` option includes some local paths, which can
be quite long on some platforms, spanning over multiple lines. This
causes the CLI tests to fail, because they expect each of the paths from
the `-c` help to fit on a single line.
To fix this, we can use `trycmd`'s `...` to match as many lines as
needed.
Closes #1509
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Have `arti hss onion-name` error if it doesn't print the onion name
See merge request tpo/core/arti!2305
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
There are two error cases where the onion name isn't printed, but
previously returned `Ok(())`.
It now returns an error to exit with a non-zero status code.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | | |
tor-proto::circuit::StreamMap: Use StreamPollSet
See merge request tpo/core/arti!2285
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
We no longer need this. StreamMap now supports handling only one
outgoing message at a time while ensuring no streams starve, so we no
longer ever pull messages out of the map when we're not actually ready
to send them.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
* Refactors `StreamMap` to use `StreamPollSet` to manage its receivers
for mpsc streams.
* Extends `StreamMap` to support iterating only over streams that have a
pending outgoing message, and in round-robin order.
* Updates `circuit::reactor::Reactor` to use this functionality. It now
iterates only over streams that have a ready outgoing message, and
only actually "pops" a message that is ready to be sent.
This mildly simplifies the circuit reactor, but more importantly clears
the way to:
* Remove the "outbound queue" of messages that were pulled from stream
channels but that we couldn't send yet due to congestion control.
* Support opportunistic packing when preparing to send a relay message.
(proposal 340).
* Refactor the circuit reactor's `run_once` into futures that we can
`select!` over.
|
| | | | | |
|
| | |/ / |
|
| |/ / |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
Done with
```
cargo set-version --bump patch -p arti
```
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This is the result of:
```
for crate in $( ./maint/list_crates |grep '^\(tor\|arti-\)' ); do
cargo set-version -p $crate 0.21.0
done
```
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
No updates on their dependents, because:
fslock-guard (only tests have changed)
equix (only change is removal of a private constant)
fs-mistrust (documentation, formatting, and use of Path::try_exists in tests)
|
| |/ |
|
| |
|
|
|
| |
Rust 1.70 (our MSRV) will not allow us to use a trait from a private
module in this way, unfortunately.
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
Except for *error_out, they are always set to NULL on error.
|
| | |
|
| | |
|
| |
|
|
|
|
|
| |
Additionally, inline the related conversion functions.
This should reduce the total amount of unsafe code that somebody
would need to look at.
|
| | |
|
| | |
|
| |
|
|
| |
(Documentation movement still needed.)
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
| |
I got this by reading over all the relevant Rust stdlib safety
documentation (now linked to in the macro definitions),
and making sure that the C no-UB text is sufficient to guarantee
that those requirements are met.
|
| |
|
|
|
|
|
|
|
| |
Previously, some of our conversion macros tried to exit early with
`?`. This is undesirable, since the OutPtr conversion has the side
effect of writing NULL to a pointer (if it is present).
Now, every conversion runs, and _then_ we exit with an error if
any of them fails.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
These macros do the only part of our FFI functions that needs to be
`unsafe`: converting input pointers into types that can be used in
safe rust. I've added documentation about what requirements each of
these conversions puts onto out inputs: both informally, and via a
reference to the relevant parts of the Rust library documentation.
While doing this I found a safety bug in `OutPtr::from_opt_ptr`:
it should have been using `MaybeUninit`.
These macros should allow us to build a "proof sketch" for the
safety of our FFI code. We need to show, for each input parameter:
- That the documented requirements for its conversion method
are also documented requirements for that kind of input, in our
header file.
- That the documented requirements for how it can be used
after conversion are in fact followed in the code.
|
| |
|
|
| |
(and to what extent)
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
In brief: Everything now starts with ARTI_RPC, arti_rpc, or ArtiRpc.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
These documents are no longer called "safety". They are now mostly
collected as a big list of "correctness requirements" at the start
of the cbindgen header. Because of these requirements, most
functions no longer need their own "safety" sections.
I am explicitly using `#[allow(clippy::missing_safety_doc)]` on each
function, rather than adding a blanket exception:
- There are other unsafe functions in this code, to which we
wouldn't want an exception to apply.
- Documenting the safety^W correctness requirements of a function
is important enough to make sure that we aren't skipping out on
it unintentionally.
|
| | |
|
| |
|
|
|
|
|
|
| |
Per discussion, we'd rather have an optional output parameter for error
objects rather than mess with thread-local variables.
This is possibly less convenient for direct usage from C,
but likely more convenient for wrapper functions in other languages.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
In this API, borrowed strings are `const char *`, and owned strings
are `ArtiRpcStr *`. You can get the former from the latter with
`arti_rpc_str_get()`, which returns a `const char *` in hopes that
you will neither modify nor free() that `const char *`
(Note that there are no places where string ownership needs to be
passed into this library; and at present, there is only one case
where it is passed out. I do not anticipate that we will need to do
intake of owned strings. We will probably need to return these in a
few more cases as we add more API surface.)
|
| | |
|
| | |
|
| | |
|