| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
Here we test the (arguably inconsistent behavior) where can we
return fewer items than requested if no item had zero weight.
(If this ever becomes an error, we need to modify the calling code.)
|
| | | |
| | |
| | |
| | |
| | |
| | | |
WeightedError::InsufficientNonzero is expected under some
circumstances, but the other instances would mean that we have a
bug.
|
| | | |
| | |
| | |
| | |
| | | |
We want to make sure that behavior for 0-weighted elements is
consistent for choose_multiple_weighted and choose_weighted.
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-proto: Replace RunOnceCmdInner with CircuitCmd in Circuit impl
See merge request tpo/core/arti!2881
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2881#note_3178624
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
There is no `Multiple` counterpart in `CircuitAction`, so the `Single`
variant name doesn't make much sense.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
The `LegId` is now added by the caller, when converting the resulting
`CircuitCmd`s to `RunOnceCmdInner`.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
`CircuitCmd`s are a subset of `RunOnceCmdInner`, and don't have a
`LegId`.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
A `CircuitCmd`, unlike `RunOnceCmdInner`, doesn't know anything about
`LegId`s. The user of the `CircuitCmd`s is supposed to know the `LegId`
of the circuit the `CircuitCmd` came from. This is necessary because
circuits don't know (and can't know) their own `LegId`.
The various `Circuit` operations (e.g. `handle_cell`) will soon be
updated to return `CircuitCmd` instead of `RunOnceCmdInner` (because the
`RunOnceCmdInner` variants will soon be updated to also have an
associated `LegId`, and `Circuit`s don't have access to their `LegId`s).
The calling code, which *does* know the `LegId`, will then map
`CircuitCmd`s to `RunOnceCmdInner`.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This tells the reactor which circuit leg the input message originated
from.
Addresses a TODO.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
We want to require that whenever we generate a key that's persistent
(stored in KeyMgr), it's going to be made from a stronger-than-usual
Rng. This trait helps us enforce that.
We also add a FakeEntropicRng struct to use for testing.
Note that this turned up a case that we'd missed, which required
an internal change in tor-hsservice.
|
| | | | | |
|
| | |/ /
|/| |
| | |
| | |
| | |
| | | |
This Rng combines inputs from several sources,
including OsRng, to minimize the likelihood
of falling to a vulnerability in any particular one.
|
| |\ \ \
| |_|/
|/| |
| | |
| | | |
rpcserver: Increase coverage in msgs module
See merge request tpo/core/arti!2870
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
fallbackdir: Update list generated on March 20, 2025
See merge request tpo/core/arti!2875
|
| | | | |
| | | |
| | | |
| | | | |
Signed-off-by: Tor CI Release <[email protected]>
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
tor-proto: some TODO fixes in `ControlHandler`
See merge request tpo/core/arti!2867
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | |/
| |/| |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
We change `NoUnixAddressSupport` to `NoAfUnixSocketSupport` because it
doesn't make much sense to talk about support for the addresses
separately from support for the sockets.
|
| | | |
| | |
| | |
| | | |
Change `..UnixAddress...` to `...AfUnixAddress..`.
|
| | | |
| | |
| | |
| | |
| | | |
This variant breaches the new guidelines about AF_UNIX terminology.
And its purpose is unclear and it's not used.
|
| |/ / |
|
| | |
| |
| |
| | |
Possible fix for #1902.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
protover: Add support for subprotocol version mnemonics.
Closes #1891
See merge request tpo/core/arti!2854
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
It's error-prone to have to remember e.g. that "Desc=5"
means "family ID support", so in torspec!251 we added mnemonic names
like DESC_FAMILY_IDS.
Here we use those names in tor-protover.
|
| | | | |
|
| |\ \ \
| |_|/
|/| |
| | |
| | | |
replace state_dir and storage_mistrust with tor_persist::state_dir::StateDirectory
See merge request tpo/core/arti!2863
|
| | | |
| | |
| | |
| | | |
tor_persist::state_dir::StateDirectory
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Impose a maximum on our fallback estimated timeout
Closes #1693
See merge request tpo/core/arti!2842
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The fallback timeout is the one that we use when we have
insufficient data. We reset our observations, and maybe rebuild
our circuits, when we find that too many circuits have failed
recently. When we do so, we double our fallback timeout.
Previously we had no limit, which could lead to overflow (#1693).
In this commit we impose a maximum of 2 hours,
which is ridiculously high.
(C tor uses a maximum of INT32_MAX seconds, which is even more
ridiculously high.)
Closes #1693.
|
| |\ \ \ \
| |_|/ /
|/| | |
| | | |
| | | | |
Port to rand 0.9
See merge request tpo/core/arti!2869
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
The constructor for rand::distr::Uniform is now fallible,
so it makes sense to bubble up its restrictions.
This is a breaking change.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
(This applies to every crate that has an API that takes a
`rand::Rng` or any related trait.)
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
- The Rng::gen() functions have been renamed to Rng::random().
|
| | | | |
| | | |
| | | |
| | | | |
- Several methods have been moved out of SliceRandom.
|