| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
| |
It can be useful to see the outcome of the other tests/analysis.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
tgen aborts a stream and starts the next one when the "stallout" timeout
is reached. In some cases the arti (or tor) client just needs a bit more
time to establish a connection to the hidden service.
A potential downside is that if a single stream "stalls" forever without
an explicit error, tgen will never give up on it, and thus never try any
more streams. We can worry about that if and when we see it though; and
it would indicate a likely bug since the known clients and servers in
this test shouldn't stall indefinitely in this way.
|
| |
|
|
|
|
|
| |
None of the failures currently recorded in
https://gitlab.torproject.org/tpo/core/arti/-/issues/2209 involve the
c-tor client. I think we can safely require all xfers to succeed for the
c-tor client.
|
| |
|
|
|
|
|
|
| |
From 9/10 to 5/10.
This is to mitigate flakiness.
See
https://gitlab.torproject.org/tpo/core/arti/-/issues/2209#note_3295789
|
| |
|
|
| |
Having this all on one line makes it easier to read.
|
| |
|
|
| |
Now that we no longer echo these, this is useful.
|
| |
|
|
| |
Now that we no longer echo this, it's potentially useful to have it.
|
| |
|
|
|
|
| |
I find that the echoing here does not really contribute to my
understanding of what's going on, and it makes the output quite
difficult to parse.
|
| |
|
|
|
|
| |
articlient-onion-auth was included twice on this list. From looking at
9ad23705e4, where the second instance was introduced, it seems that this
was meant to be articlient-onion-artiserver-auth.
|
| |
|
|
|
|
|
|
| |
It looks like the reliability has increased at some point. Let's ratchet
up the required-success threshold to avoid silent regression.
See
<https://gitlab.torproject.org/tpo/core/arti/-/issues/2109#note_3278828>
|
| | |
|
| |
|
|
|
|
|
|
|
|
| |
Workaround for arti#2240, though doesn't hurt to be more explicit in
general.
This bug wasn't triggered in versions of shadow before
<https://github.com/shadow/shadow/issues/3659> was fixed - shadow's
implementation of `statx` and other syscalls incorrectly behaved as if the
`AT_EMPTY_PATH` were set.
|
| | |
|
| |
|
|
|
|
|
|
| |
This partially reverts b223d504f6a033600c61e81a0b0a0eea3e43fd44 from
arti!3047. Increasing the transfer size exacerbates the failure rate of
the onion services too much.
We should increase it again once arti#2109 is resolved.
|
| |
|
|
|
| |
With the increased transfer sizes and simulation run-time,
the previous log levels resulted in excessively large log files.
|
| |
|
|
|
|
|
|
| |
This is the transfer size used in the tor CI chutney tests, to
more-fully exercise SENDMEs / congestion control.
We also increase the simulation run time to allow time for the larger
transfers.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
This is in preparation to switch arti's console logging to use stderr
instead of stdout. The test script currently fails the test if there are
non-empty stderr files, since that's where rust panics end up getting
recorded.
It will also make it easier to see if there is any other non-logging
output.
Also disable trace-level logging for the tor_proto module. It's unclear
exactly when/why this was added, but it's probably overkill other than
when debugging.
|
| |\
| |
| |
| |
| | |
shadow CI tweaks
See merge request tpo/core/arti!2989
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Not expected to solve any immediate issue, but helpful for consistency
with the chutney-shadow CI, and I think in the past we've hit busy-loop
deadlock without it if/when we try increasing the simulation end time.
Similarly, we apply the same tuning of "max_unapplied_cpu_latency" as we
use in the chutney-shadow simulation, which gets back some of the
simulation stability that enabling model-unblocked-syscall-latency
otherwise sometimes sacrifices.
|
| | |
| |
| |
| |
| | |
While useful, it significantly slows down the test. We should probably
just enable it when needed.
|
| |/
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
As per previous discussion there is some known flakiness around hidden
services with TestingTorNetwork enabled:
<https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1399#note_2921505>
Previously, only requiring 5 of 10 transfers to succeed has been enough
to keep this stable, but recently we've gotten unlucky and dipped under
this threshold: <https://gitlab.torproject.org/tpo/core/arti/-/issues/1986>
More investigation is warranted, especially wrt why the problem seems
to mostly be affecting articlient-onion-auth, but for now it's better to
have a low success threshold than to have folks overriding the CI
failure.
|
| |
|
|
|
|
|
|
|
|
| |
The pcaps are only used to check for leaks by reading the packet
source/destination, so we don't need the entire packet. This should make
CI artifacts a bit smaller.
The fixed-size portion of an IP header is 20 bytes for IPv4 and 40 bytes
for IPv6. Shadow doesn't support IPv6, but used the IPv6 header size
anyways.
|
| |
|
|
| |
ntor v3 is now always enabled.
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
This detected the account lifetime bugs fixed in this branch.
|
| | |
|
| | |
|
| |
|
|
| |
This tests that #1569 works.
|
| | |
|
| |
|
|
|
|
|
|
| |
Setting it for all arti processes causes a warning to be logged to
stderr, which causes the shadow ci script to fail.
It's enabled by default anyway when the feature is compiled in, so we
don't need to enable it explicitly.
|
| | |
|
| |
|
|
| |
This would have caught #1513 before it was merged.
|
| |
|
|
|
| |
This tests that the client configured in the `authorized_clients`
directory of the service is able to connect.
|
| | |
|
| |
|
|
|
| |
This will be used with the new `fileserver-onion-arti-auth` test hidden
service.
|
| |
|
|
|
|
|
|
|
| |
This adds a new restricted discovery hidden service
(`fpqqmiwzqiv63jczrshh4qcmlxw6gujcai3arobq23wikt7hk7ojadid.onion`)
that has 2 authorized clients:
* `alice`, the client configured in the `restricted_discovery.static`
list in its TOML config
* `default`, the client configured in `authorized_clients/default.auth`
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
| |
We don't need this now that #1417 is fixed.
This reverts commit a9010f6300c25e4602ecf8017ca176c724ecdfa5.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
Without this change, one of the tgen processes doesn't exit as expected:
```
618990:00:06:50.991981 [4717:shadow-worker] 00:30:00.000000000 [ERROR] [torclient-onion-artiserver:11.0.0.19] [process.rs:1525] [shadow_rs::host::process] process 'torclient-onion-artiserver.tgen.1001' exited with status StoppedByShadow; expected end state was exited: 0 but was running
```
This is because of a stub circuit selection bug that only manifests when
the `torclient-onion-artiserver` and
`torclient-onion-artiserver-full-vanguards` tests are run at the same
time.
See #1417 for more details.
|
| |
|
|
|
|
|
| |
This adds an onion service that uses full vanguards, and a client
that connects to it.
Closes #1408
|
| |
|
|
|
| |
Moving them to a separate variable makes the script more readable as we
add more hosts.
|
| |\
| |
| |
| |
| | |
Forbid script suffixes
See merge request tpo/core/arti!2153
|
| | | |
|