summaryrefslogtreecommitdiff
path: root/tests/shadow
Commit message (Collapse)AuthorAgeFilesLines
* shadow CI: disable stallouts for onion clientsJim Newsome2025-12-087-0/+21
| | | | | | | | | | | | tgen aborts a stream and starts the next one when the "stallout" timeout is reached. In some cases the arti (or tor) client just needs a bit more time to establish a connection to the hidden service. A potential downside is that if a single stream "stalls" forever without an explicit error, tgen will never give up on it, and thus never try any more streams. We can worry about that if and when we see it though; and it would indicate a likely bug since the known clients and servers in this test shouldn't stall indefinitely in this way.
* shadow CI: *increase* required success rate for c-tor clientJim Newsome2025-12-021-5/+5
| | | | | | | None of the failures currently recorded in https://gitlab.torproject.org/tpo/core/arti/-/issues/2209 involve the c-tor client. I think we can safely require all xfers to succeed for the c-tor client.
* shadow CI: reduce arti client HS required successesJim Newsome2025-12-021-7/+7
| | | | | | | | From 9/10 to 5/10. This is to mitigate flakiness. See https://gitlab.torproject.org/tpo/core/arti/-/issues/2209#note_3295789
* ci: Improve formatting of shadow results.Wesley Aptekar-Cassels2025-11-251-3/+3
| | | | Having this all on one line makes it easier to read.
* ci: Print host names in shadow run script.Wesley Aptekar-Cassels2025-11-251-1/+1
| | | | Now that we no longer echo these, this is useful.
* ci: Print seed in shadow run script.Wesley Aptekar-Cassels2025-11-251-0/+2
| | | | Now that we no longer echo this, it's potentially useful to have it.
* ci: Disable echoing in shadow test script.Wesley Aptekar-Cassels2025-11-251-1/+1
| | | | | | I find that the echoing here does not really contribute to my understanding of what's going on, and it makes the output quite difficult to parse.
* tests: Fix error in shadow checking script.Wesley Aptekar-Cassels2025-11-241-1/+1
| | | | | | articlient-onion-auth was included twice on this list. From looking at 9ad23705e4, where the second instance was introduced, it seems that this was meant to be articlient-onion-artiserver-auth.
* shadow CI: increase success threshold for onion svc xfersJim Newsome2025-11-041-13/+13
| | | | | | | | It looks like the reliability has increased at some point. Let's ratchet up the required-success threshold to avoid silent regression. See <https://gitlab.torproject.org/tpo/core/arti/-/issues/2109#note_3278828>
* shadow CI: add check_host_xfers helper function and improve outputJim Newsome2025-11-041-36/+30
|
* shadow CI: Use ./ prefix for logging pathJim Newsome2025-11-031-1/+1
| | | | | | | | | | Workaround for arti#2240, though doesn't hurt to be more explicit in general. This bug wasn't triggered in versions of shadow before <https://github.com/shadow/shadow/issues/3659> was fixed - shadow's implementation of `statx` and other syscalls incorrectly behaved as if the `AT_EMPTY_PATH` were set.
* shadow: Update shadow syntax for prop330Clara Engler2025-09-161-3/+1
|
* shadow CI: decrease onion service xfer sizesJim Newsome2025-09-037-14/+21
| | | | | | | | This partially reverts b223d504f6a033600c61e81a0b0a0eea3e43fd44 from arti!3047. Increasing the transfer size exacerbates the failure rate of the onion services too much. We should increase it again once arti#2109 is resolved.
* shadow CI: less-verbose loggingJim Newsome2025-08-271-1/+1
| | | | | With the increased transfer sizes and simulation run-time, the previous log levels resulted in excessively large log files.
* CI shadow test: increase transfer sizes to 5 MBJim Newsome2025-08-2710-19/+19
| | | | | | | | This is the transfer size used in the tor CI chutney tests, to more-fully exercise SENDMEs / congestion control. We also increase the simulation run time to allow time for the larger transfers.
* shadow.yaml: move arti build dir to a yaml anchorJim Newsome2025-08-261-15/+22
|
* Integration testing: use quicktest buildJim Newsome2025-08-262-27/+30
|
* shadow CI: have arti processes log to file instead of consoleJim Newsome2025-06-173-17/+54
| | | | | | | | | | | | | | This is in preparation to switch arti's console logging to use stderr instead of stdout. The test script currently fails the test if there are non-empty stderr files, since that's where rust panics end up getting recorded. It will also make it easier to see if there is any other non-logging output. Also disable trace-level logging for the tor_proto module. It's unclear exactly when/why this was added, but it's probably overkill other than when debugging.
* Merge branch 'debug-ci' into 'main'gabi-2502025-05-062-1/+20
|\ | | | | | | | | shadow CI tweaks See merge request tpo/core/arti!2989
| * shadow CI: enable model-unblocked-syscall-latencyJim Newsome2025-05-051-0/+20
| | | | | | | | | | | | | | | | | | | | | | Not expected to solve any immediate issue, but helpful for consistency with the chutney-shadow CI, and I think in the past we've hit busy-loop deadlock without it if/when we try increasing the simulation end time. Similarly, we apply the same tuning of "max_unapplied_cpu_latency" as we use in the chutney-shadow simulation, which gets back some of the simulation stability that enabling model-unblocked-syscall-latency otherwise sometimes sacrifices.
| * shadow CI: disable strace loggingJim Newsome2025-05-051-1/+0
| | | | | | | | | | While useful, it significantly slows down the test. We should probably just enable it when needed.
* | shadow CI test: only require 1 successful HS transferJim Newsome2025-05-051-5/+5
|/ | | | | | | | | | | | | | | As per previous discussion there is some known flakiness around hidden services with TestingTorNetwork enabled: <https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1399#note_2921505> Previously, only requiring 5 of 10 transfers to succeed has been enough to keep this stable, but recently we've gotten unlucky and dipped under this threshold: <https://gitlab.torproject.org/tpo/core/arti/-/issues/1986> More investigation is warranted, especially wrt why the problem seems to mostly be affecting articlient-onion-auth, but for now it's better to have a low success threshold than to have folks overriding the CI failure.
* shadow: capture only 40 bytes of packetsSteven Engler2025-04-011-0/+4
| | | | | | | | | | The pcaps are only used to check for leaks by reading the packet source/destination, so we don't need the entire packet. This should make CI artifacts a bit smaller. The fixed-size portion of an IP header is 20 bytes for IPv4 and 40 bytes for IPv6. Shadow doesn't support IPv6, but used the IPv6 header size anyways.
* tor-circmgr: removed "ntor_v3" feature flagSteven Engler2025-04-011-1/+1
| | | | ntor v3 is now always enabled.
* shadow ci README: add notes about reproducibilityJim Newsome2025-03-311-0/+22
|
* shadow ci: add CLI option to run with specified seedJim Newsome2025-03-311-0/+31
|
* shadow test README: update with latest feature setJim Newsome2025-03-311-1/+1
|
* shadow tests: Enable and turn on memquotaIan Jackson2024-10-211-0/+5
| | | | This detected the account lifetime bugs fixed in this branch.
* shadow tests: Provide an arti.extra.toml to arti-extra binaryIan Jackson2024-10-2117-0/+26
|
* shadow CI: Add arti hidden service test using a C Tor keystore.Gabriela Moldovan2024-10-0812-0/+101
|
* shadow CI: Disable SOCKS/DNS proxying for the arti onion services.Gabriela Moldovan2024-09-171-0/+6
| | | | This tests that #1569 works.
* shadow: add obfs4 arti client + tor bridgeopara2024-08-2116-1/+82
|
* shadow ci: don't explicitly set storage.keystore.enabledJim Newsome2024-08-061-4/+0
| | | | | | | | Setting it for all arti processes causes a warning to be logged to stderr, which causes the shadow ci script to fail. It's enabled by default anyway when the feature is compiled in, so we don't need to enable it explicitly.
* shadow CI: fail on arti logged errorsJim Newsome2024-08-061-0/+9
|
* shadow ci: fail on nonempty stderr fileJim Newsome2024-08-061-0/+9
| | | | This would have caught #1513 before it was merged.
* shadow test: Add another client for the restricted discovery service.Gabriela Moldovan2024-08-056-0/+75
| | | | | This tests that the client configured in the `authorized_clients` directory of the service is able to connect.
* shadow test: Set the right permissions for authorized_clients.Gabriela Moldovan2024-08-051-0/+1
|
* shadow test: Add a new arti client for connecting to filserver-onion-arti-auth.Gabriela Moldovan2024-08-056-0/+63
| | | | | This will be used with the new `fileserver-onion-arti-auth` test hidden service.
* shadow test: Add fileserver-onion-arti-authGabriela Moldovan2024-08-057-0/+46
| | | | | | | | | This adds a new restricted discovery hidden service (`fpqqmiwzqiv63jczrshh4qcmlxw6gujcai3arobq23wikt7hk7ojadid.onion`) that has 2 authorized clients: * `alice`, the client configured in the `restricted_discovery.static` list in its TOML config * `default`, the client configured in `authorized_clients/default.auth`
* ci: Fix variable not expanding.Gabriela Moldovan2024-06-051-3/+4
|
* ci: Fix shellcheck warnings.Gabriela Moldovan2024-06-051-2/+2
|
* ci: If there are internal errors, log where they were found.Gabriela Moldovan2024-06-051-2/+3
|
* ci: Make the shadow simulation fail if an internal error is logged.Gabriela Moldovan2024-06-041-0/+24
|
* Revert "shadow ci: Increase start_time of the new test."Gabriela Moldovan2024-06-031-2/+2
| | | | | | We don't need this now that #1417 is fixed. This reverts commit a9010f6300c25e4602ecf8017ca176c724ecdfa5.
* shadow ci: Increase start_time of the new test.Gabriela Moldovan2024-06-031-2/+2
| | | | | | | | | | | | | | Without this change, one of the tgen processes doesn't exit as expected: ``` 618990:00:06:50.991981 [4717:shadow-worker] 00:30:00.000000000 [ERROR] [torclient-onion-artiserver:11.0.0.19] [process.rs:1525] [shadow_rs::host::process] process 'torclient-onion-artiserver.tgen.1001' exited with status StoppedByShadow; expected end state was exited: 0 but was running ``` This is because of a stub circuit selection bug that only manifests when the `torclient-onion-artiserver` and `torclient-onion-artiserver-full-vanguards` tests are run at the same time. See #1417 for more details.
* shadow test: Add test for onion svc using full vanguards.Gabriela Moldovan2024-06-039-0/+106
| | | | | | | This adds an onion service that uses full vanguards, and a client that connects to it. Closes #1408
* shadow ci: Put the test hosts in a HOSTS variable.Gabriela Moldovan2024-06-031-2/+9
| | | | | Moving them to a separate variable makes the script more readable as we add more hosts.
* Merge branch 'script-suffixes' into 'main'Ian Jackson2024-05-162-1/+1
|\ | | | | | | | | Forbid script suffixes See merge request tpo/core/arti!2153
| * Rename tests/shadow/run.sh to runIan Jackson2024-05-162-1/+1
| |
* | doc: Use locked buildpinkforest2024-05-161-1/+1
|/