| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |
|
| |\
| |
| |
| |
| | |
shadow CI tweaks
See merge request tpo/core/arti!2989
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Not expected to solve any immediate issue, but helpful for consistency
with the chutney-shadow CI, and I think in the past we've hit busy-loop
deadlock without it if/when we try increasing the simulation end time.
Similarly, we apply the same tuning of "max_unapplied_cpu_latency" as we
use in the chutney-shadow simulation, which gets back some of the
simulation stability that enabling model-unblocked-syscall-latency
otherwise sometimes sacrifices.
|
| | |
| |
| |
| |
| | |
While useful, it significantly slows down the test. We should probably
just enable it when needed.
|
| |/
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
As per previous discussion there is some known flakiness around hidden
services with TestingTorNetwork enabled:
<https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1399#note_2921505>
Previously, only requiring 5 of 10 transfers to succeed has been enough
to keep this stable, but recently we've gotten unlucky and dipped under
this threshold: <https://gitlab.torproject.org/tpo/core/arti/-/issues/1986>
More investigation is warranted, especially wrt why the problem seems
to mostly be affecting articlient-onion-auth, but for now it's better to
have a low success threshold than to have folks overriding the CI
failure.
|
| |
|
|
|
|
| |
Since this significantly affects the behavior of the simulation, it's
probably worth having it in the yaml. (It can of course still be
overridden from the command-line).
|
| |
|
|
|
|
| |
Since this significantly affects the behavior of the simulation, it's
useful to have it in the yaml for reference or if the simulation is
manually rerun from the yaml.
|
| |
|
|
|
|
|
|
| |
This should make the simulation results generally more stable with
respect to small perturbations, such as adding logging.
It also causes a previous "heisenbug" failure in this test to reliably
reproduce in every run.
|
| | |
|
| |
|
|
|
|
|
|
|
|
| |
The pcaps are only used to check for leaks by reading the packet
source/destination, so we don't need the entire packet. This should make
CI artifacts a bit smaller.
The fixed-size portion of an IP header is 20 bytes for IPv4 and 40 bytes
for IPv6. Shadow doesn't support IPv6, but used the IPv6 header size
anyways.
|
| |
|
|
| |
ntor v3 is now always enabled.
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
Previously shadow would report a platform of "shadowsys" in the uname
syscall, which would cause chutney to disable sandboxing by default.
As of https://github.com/shadow/shadow/pull/3442, shadow now returns
"Linux", which causes the chutney default to enable sandboxing.
When sandboxing is enabled, the tor processes abort with error, since
shadow doesn't support the seccomp syscall.
|
| | |
|
| |
|
|
|
|
| |
We no longer need a path to a checkout of the chutney repository; we
just need the chutney binary itself. We still allow this to be set
explicitly with CHUTNEY_BIN, but fall back to finding it on the PATH.
|
| |
|
|
|
|
|
|
| |
This takes advantage of a feature added in
https://gitlab.torproject.org/tpo/core/chutney/-/merge_requests/31.
This is a step towards not needing to set CHUTNEY_PATH to point to a
chutney repository.
|
| |
|
|
|
|
| |
The `black` formatter did most line wrapping for us, and we accept
its default of 88 characters there, but for comments and docstrings
(which black doesn't wrap) we allow up to 99 characters.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
"Black" is an "opinionated" python formatter, whose opinionatedness
is somewhat in the spirit of rustfmt.
This MR runs black with default settings on all of our python code
in Arti. It was produced by the following commands
```
# Everything in python/
black python/
# Everything with a .py extension
fd '.py$' -X black
# Everything with a python shebang.
git grep -l '#! */usr/bin/env *python' | xargs black
```
|
| |
|
|
| |
This detected the account lifetime bugs fixed in this branch.
|
| | |
|
| | |
|
| |
|
|
|
| |
This is a wrapper script for running `tests/chutney/integration-e2e`
under shadow.
|
| |
|
|
|
|
|
|
|
|
|
| |
Previously `tests/chutney/setup` would locate *or install* chutney and
set `CHUTNEY_PATH` for itself. However that `CHUTNEY_PATH` wasn't
propagated to other steps or "up" to the new `integration-e2e` wrapper
script.
Tracking it in the arti.run along with other dynamic info lets us ensure
we consistently use the same chutney across steps, and in the higher
level `integration-e2e` script.
|
| | |
|
| |
|
|
|
|
| |
It looks like it changed at some point. Rather than hard-coding,
just do the lookup locally and compare the tor-lookup result against
that.
|
| |
|
|
|
|
|
| |
Having this in a script is a step towards being able to run exactly the
same test under shadow without duplicating this high-level logic.
It's also convenient for running the ci test locally.
|
| |
|
|
| |
This tests that #1569 works.
|
| | |
|
| |
|
|
|
|
|
|
| |
Setting it for all arti processes causes a warning to be logged to
stderr, which causes the shadow ci script to fail.
It's enabled by default anyway when the feature is compiled in, so we
don't need to enable it explicitly.
|
| | |
|
| |
|
|
| |
This would have caught #1513 before it was merged.
|
| |
|
|
|
| |
This tests that the client configured in the `authorized_clients`
directory of the service is able to connect.
|
| | |
|
| |
|
|
|
| |
This will be used with the new `fileserver-onion-arti-auth` test hidden
service.
|
| |
|
|
|
|
|
|
|
| |
This adds a new restricted discovery hidden service
(`fpqqmiwzqiv63jczrshh4qcmlxw6gujcai3arobq23wikt7hk7ojadid.onion`)
that has 2 authorized clients:
* `alice`, the client configured in the `restricted_discovery.static`
list in its TOML config
* `default`, the client configured in `authorized_clients/default.auth`
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
| |
We don't need this now that #1417 is fixed.
This reverts commit a9010f6300c25e4602ecf8017ca176c724ecdfa5.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
Without this change, one of the tgen processes doesn't exit as expected:
```
618990:00:06:50.991981 [4717:shadow-worker] 00:30:00.000000000 [ERROR] [torclient-onion-artiserver:11.0.0.19] [process.rs:1525] [shadow_rs::host::process] process 'torclient-onion-artiserver.tgen.1001' exited with status StoppedByShadow; expected end state was exited: 0 but was running
```
This is because of a stub circuit selection bug that only manifests when
the `torclient-onion-artiserver` and
`torclient-onion-artiserver-full-vanguards` tests are run at the same
time.
See #1417 for more details.
|
| |
|
|
|
|
|
| |
This adds an onion service that uses full vanguards, and a client
that connects to it.
Closes #1408
|
| |
|
|
|
| |
Moving them to a separate variable makes the script more readable as we
add more hosts.
|
| |\
| |
| |
| |
| | |
Forbid script suffixes
See merge request tpo/core/arti!2153
|
| | | |
|
| |/ |
|
| |
|
|
|
|
|
|
| |
Some experimental features (i.e. `vanguards`) break the shadow
integration tests. Since the examples enable `experimental`, we need
`rust-latest` to build arti using `-p arti`, rather than from the
workspace level (because cargo does feature unification when building
the packages as a workspace).
|