| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | | | | | |
|
| | | | | | | | | | |
|
| | | | | | | | | | |
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
I find having too many of these nested `else { None }` branches makes
the overall logic harder to follow, so I changed this to use `Option<>`
combinators instead.
|
| | | | | | | | | | |
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
This avoids us replacing our cached hsdesc with one that has a lower
revision counter.
This was not a problem before, because we'd only ever fetch a new
descriptor when our cahced one expired, but now that we refetch the
descriptor on introduction NACK, we need to make sure the new descriptor
is actually more recent than the one we have.
The implementation is a bit convoluted because I had to avoid retaining
a reference to the known-timely cached `desc` so as not to anger borrowck.
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
This will soon need to be called from two places, unfortunately.
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
The `revision` field is no longer dead code.
|
| | | | | | | | | | |
|
| | | | | | | | | | |
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
As suggested in
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3925?commit_id=22ae30205a5f18fee43f424f8c0f9768b95a2ae6#note_3402779
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
Prior to this change, arti clients would retain their cached HS
descriptors until expiry. This is causing us some problems in
[arti#2458], where arti frequently fails to connect to C Tor services
in a chutney test net. One of the problems in #2458 is that all
introduction points are NACK-ing the client's introduction requests,
ultimately causing the connection attempt to fail:
```
2026-04-23T16:25:23Z DEBUG tor_hsclient::state: HS connection failure for ijalr3vpf67zradtlaxze6pex5ypadu5qfsltn42cmhioqory6363tad.onion error=error: Unable to connect to hidden service using any Rendezvous Point / Introduction Point: Tried to make circuit to hidden service 6 times, but all attempts failed
Attempt 1: Introduction point #3 reported error in its INTRODUCE_ACK: NOT_RECOGNIZED
Attempt 2: Introduction point #2 reported error in its INTRODUCE_ACK: NOT_RECOGNIZED
Attempt 3: Introduction point #1 reported error in its INTRODUCE_ACK: NOT_RECOGNIZED
Attempt 4: Introduction point #3 reported error in its INTRODUCE_ACK: NOT_RECOGNIZED
Attempt 5: Introduction point #2 reported error in its INTRODUCE_ACK: NOT_RECOGNIZED
Attempt 6: Introduction point #1 reported error in its INTRODUCE_ACK: NOT_RECOGNIZED
```
I think this is happening because the C Tor service has rotated intro
points and republished its descriptor, before the descriptor's planned
expiry. I believe is something that can (and does) happen, and so arti
should be able to handle it gracefully.
I added some more logs to arti and reran the test, and noticed the
descriptor's lifetime works out to be just over 2 days (54h), which
seems excessive (especially in our test net, where the voting interval
is 20s and the hsdir interval is 8min). In any case, holding on to a
service's descriptor for too long, and not refetching a new one, will
cause the client's introduction requests to be rejected (because the
service might switch intro points).
I think there are at least 2 things we need to do to improve arti's
handling of HS connections:
* In the case of an introduce NACK (with status = `NOT_RECOGNIZED`),
the client should refetch the descriptor and then retry the
introduction. This behavior is not codified in the spec yet (see
torspec#245), but I am told this is what C Tor does
* Rethink the cached descriptor expiry calculation
This commit addresses the first point. The second one seems trickier, so
I have not looked into it yet.
Part of #966
[arti#913]: https://gitlab.torproject.org/tpo/core/arti/-/work_items/913#note_2914448
[arti#2458]: https://gitlab.torproject.org/tpo/core/arti/-/work_items/2458#note_3400768
|
| | | | | | | | | | |
|
| | | | | | | | | | |
|
| | |_|_|_|/ / / /
|/| | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This will soon be used to force a refetch in the case of an
`INTRODUCE_NACK`.
(This commit is intentionally left misindented to make reviewing a bit
easier. A future commit will rustfmt the file).
|
| |\ \ \ \ \ \ \ \
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
fallbackdir: Update list generated on May 07, 2026
See merge request tpo/core/arti!3964
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
Signed-off-by: Tor CI Release <[email protected]>
|
| |\ \ \ \ \ \ \ \ \
| | | | | | | | | |
| | | | | | | | | |
| | | | | | | | | |
| | | | | | | | | | |
rpc-connect: classify newer io errorkinds.
See merge request tpo/core/arti!3945
|
| | | |_|_|_|/ / / /
| |/| | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
In Rust 1.83 and 1.85, io::ErrorKind added a few new variants.
Here we classify them as "Decline" or "Abort" in our connection
point code.
|
| |\ \ \ \ \ \ \ \ \
| |_|_|_|_|_|/ / /
|/| | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
tor-proto: Don't apply window-based flow control to CC half-streams
Closes #2195 and #2505
See merge request tpo/core/arti!3941
|
| | | | | | | | | | |
|
| | | | | | | | | | |
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
This moves the window-based flow control for half-streams out of the
`HalfStream` and into the `HalfStreamWindowFlowCtrl` object.
Now that it's applied only in `HalfStreamWindowFlowCtrl` and not
generally for all half-streams, we no longer apply window-based flow
control to half-streams when they're really using xon/xoff-based flow
control.
|
| | | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
This adds the general structure, and we'll fill it in and use it in a
following commit.
|
| | | |/ / / / / /
| |/| | | | | | |
|
| |\ \ \ \ \ \ \ \
| |/ / / / / / /
|/| | | | | | |
| | | | | | | |
| | | | | | | | |
hsclient: Fix numerous bugs in timeout estimators
See merge request tpo/core/arti!3940
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Gabi correctly points out that since the client uses guarded
circuits for introduction points, whereas the service uses naive
circuits, we shouldn't expect the peer's circuits to be any longer
than ours.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
There's no reason that the next person should have to rediscover
these caveats.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Both C tor and Arti will retry building a circuit if the first
attempt fails. This means that it can be worthwhile waiting longer
than we might otherwise for the HS to build its rendezvous circuit.
We don't need to make this change for _our_ circuits, since
the CircMgr code takes care of those timeouts for us.
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
We don't actually need to use this method on any circuits that have
a virtual hop, so instead of "fixing" this method to ignore virtual
hops, the simpler approach is to change its name and its documented
behavior, and to explain how the documented behavior is appropriate
for our needs.
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Duration::try_from_secs_f64 has existed since Rust 1.66,
so we can use it now.
It seems wrong to treat "infinity" and "negative infinity" as "one
second", so make them actually saturating.
Additionally, document behavior for infinity and negative infinity,
and document that the NaN behavior isn't documented.
(And secretly NaN behavior return a number on the same order of
magnitude as the input.)
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This strategy is safe because (outside of our tests) we never look
at the actual values of timeout_scale, but only at their ratios.
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This time we _do_ need to use the BuildCircuit estimator, since we
have to consider the peer's circuit building.
The peer may be using full vanguards, so we need to use 5 as their
maximum hop estimate.
Additionally, their circuit may be longer than ours, so we ought to
possibly wait a bit longer for them to get our INTRODUCE2.
There are XXXXs here about OneWay timeout estimators, for immediate
followup.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The circmgr handles timeouts on its own, so we can let it do that.
Use the actual circuit length for calculating round-trip timeouts.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The circmgr code handles circuit timeouts, so we don't need to
include that redundantly.
Also, we look at the circuit to find out its number of hops,
so that we estimate the timeout more accurately.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The hspool operations already include their own timeouts, so we
don't need to recalculate them.
For the directory related operations, we now calculate the timeouts
based on actual circuit lengths, and use those timeouts on the
operations themselves.
|
| | |/ / / / / /
| | | | | | |
| | | | | | |
| | | | | | | |
We'll use these for timeout estimations.
|
| | | | | | | | |
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Rust 1.88 added these, so we no longer have to use `any()` for false
and `all()` for true.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
It is no longer needed since we require Rust 1.89. Nobody was using
it.
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | | |
We now know when it was stabilized, so we can say when to use it.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
release: Remove semver.md files.
See merge request tpo/core/arti!3955
|
| | | | | | | | |
|
| | |/ / / / /
|/| | | | | |
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
release: Bump release date for 2.3.0.
See merge request tpo/core/arti!3953
|
| | | | | | | |
|