]> git.ipfire.org Git - thirdparty/tor.git/log
thirdparty/tor.git
2 years agoReplace socket_failed_from_resource_exhaustion() by socket_failed_from_fd_exhaustion()
qontinuum [Tue, 29 Nov 2022 20:43:14 +0000 (21:43 +0100)] 
Replace socket_failed_from_resource_exhaustion() by socket_failed_from_fd_exhaustion()

2 years agoIsolate warn_about_resource_exhaution()
qontinuum [Tue, 29 Nov 2022 20:34:06 +0000 (21:34 +0100)] 
Isolate warn_about_resource_exhaution()

2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Tue, 6 Dec 2022 16:14:32 +0000 (11:14 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agoversion: Bump version to 0.4.7.12-dev
Tor CI Release [Tue, 6 Dec 2022 15:34:07 +0000 (15:34 +0000)] 
version: Bump version to 0.4.7.12-dev

2 years agoversion: Bump version to 0.4.5.15-dev
Tor CI Release [Tue, 6 Dec 2022 15:34:07 +0000 (15:34 +0000)] 
version: Bump version to 0.4.5.15-dev

2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Tue, 6 Dec 2022 15:22:48 +0000 (10:22 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agoversion: Bump version to 0.4.7.12
Tor CI Release [Tue, 6 Dec 2022 15:05:30 +0000 (15:05 +0000)] 
version: Bump version to 0.4.7.12

2 years agoversion: Bump version to 0.4.5.15
Tor CI Release [Tue, 6 Dec 2022 15:05:24 +0000 (15:05 +0000)] 
version: Bump version to 0.4.5.15

2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Tue, 6 Dec 2022 15:10:41 +0000 (10:10 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agofallbackdir: Update list generated on December 06, 2022
Tor CI Release [Tue, 6 Dec 2022 15:03:57 +0000 (15:03 +0000)] 
fallbackdir: Update list generated on December 06, 2022

2 years agoUpdate geoip files to match ipfire location db, 2022/12/06.
Tor CI Release [Tue, 6 Dec 2022 14:56:15 +0000 (14:56 +0000)] 
Update geoip files to match ipfire location db, 2022/12/06.

2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Tue, 6 Dec 2022 15:00:01 +0000 (10:00 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agofallbackdir: Update files from latest 047 release
David Goulet [Tue, 6 Dec 2022 14:59:27 +0000 (09:59 -0500)] 
fallbackdir: Update files from latest 047 release

We need the fallbackdir file to be the same so our release CI can
generate a new list and apply it uniformly on all series.

(Same as geoip)

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Tue, 6 Dec 2022 14:49:29 +0000 (09:49 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agogeoip: Update files from latest 047 release
David Goulet [Tue, 6 Dec 2022 14:47:55 +0000 (09:47 -0500)] 
geoip: Update files from latest 047 release

We need all geoip files to be the same so our release CI can generate a
new list and apply it uniformly on all series.

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Tue, 6 Dec 2022 13:56:04 +0000 (08:56 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agoTicket 40724: Add metrics for CC circuit counts
Mike Perry [Fri, 2 Dec 2022 21:50:59 +0000 (21:50 +0000)] 
Ticket 40724: Add metrics for CC circuit counts

2 years agoTicket 40724: Changes file
Mike Perry [Thu, 1 Dec 2022 22:22:45 +0000 (22:22 +0000)] 
Ticket 40724: Changes file

2 years agoTicket 40724: Additional congestion control metrics
Mike Perry [Thu, 1 Dec 2022 22:18:02 +0000 (22:18 +0000)] 
Ticket 40724: Additional congestion control metrics

2 years agodirauth: rotate moria1 keys and ports
Roger Dingledine [Wed, 30 Nov 2022 01:33:58 +0000 (20:33 -0500)] 
dirauth: rotate moria1 keys and ports

Rotate the relay identity key and v3 identity key for moria1. They
have been online for more than a decade, there was a known potential
compromise, and anyway refreshing keys periodically is good practice.

Advertise new ports too, to avoid confusion.

Closes ticket 40722.

2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Mon, 28 Nov 2022 15:27:13 +0000 (10:27 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agochanges: Add file for ticket 40674
David Goulet [Mon, 28 Nov 2022 15:25:48 +0000 (10:25 -0500)] 
changes: Add file for ticket 40674

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agodns: Make TTLs fuzzy at exit relays
Rasmus Dahlberg [Wed, 12 Oct 2022 18:29:11 +0000 (20:29 +0200)] 
dns: Make TTLs fuzzy at exit relays

This change mitigates DNS-based website oracles by making the time that
a domain name is cached uncertain (+- 4 minutes of what's measurable).

Resolves TROVE-2021-009.

Fixes #40674

2 years agoClip DNS TTL values once in event callback
Rasmus Dahlberg [Wed, 12 Oct 2022 18:29:11 +0000 (20:29 +0200)] 
Clip DNS TTL values once in event callback

This change ensures that other parts of the code base always operate on
the same clipped TTL values, notably without being aware of clipping.

2 years agorelay: Use the configured number of threads for worker work calculation
David Goulet [Wed, 23 Nov 2022 18:47:59 +0000 (13:47 -0500)] 
relay: Use the configured number of threads for worker work calculation

We cap our number of CPU worker threads to at least 2 even if we have a
single core. But also, before we used to always add one extra thread
regardless of the number of core.

This meant that we were off when re-using the get_num_cpus() function
when calculating our onionskin work overhead because we were always off
by one.

This commit makes it that we always use the number of thread our actual
thread pool was configured with.

Fixes #40719

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agoversion: Bump version to 0.4.7.11-dev
Tor CI Release [Thu, 10 Nov 2022 14:58:26 +0000 (14:58 +0000)] 
version: Bump version to 0.4.7.11-dev

2 years agoversion: Bump version to 0.4.7.11
Tor CI Release [Thu, 10 Nov 2022 14:41:43 +0000 (14:41 +0000)] 
version: Bump version to 0.4.7.11

2 years agofallbackdir: Update list generated on November 10, 2022
Tor CI Release [Thu, 10 Nov 2022 14:40:50 +0000 (14:40 +0000)] 
fallbackdir: Update list generated on November 10, 2022

2 years agoUpdate geoip files to match ipfire location db, 2022/11/10.
Tor CI Release [Thu, 10 Nov 2022 14:39:17 +0000 (14:39 +0000)] 
Update geoip files to match ipfire location db, 2022/11/10.

2 years agometrics: Split cc with counters and gauges
David Goulet [Thu, 10 Nov 2022 13:57:39 +0000 (08:57 -0500)] 
metrics: Split cc with counters and gauges

Part of #40712

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Split connections with a counter and gauge
David Goulet [Thu, 10 Nov 2022 12:29:18 +0000 (07:29 -0500)] 
metrics: Split connections with a counter and gauge

Created and Rejected connections are ever going up counters. While
Opened connections are gauges going up and down.

Fixes #40712

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agochanges: Add file for ticket 40674
David Goulet [Wed, 9 Nov 2022 20:35:51 +0000 (15:35 -0500)] 
changes: Add file for ticket 40674

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agoMerge branch 'ticket40674_047_01' into maint-0.4.7
David Goulet [Wed, 9 Nov 2022 20:32:18 +0000 (15:32 -0500)] 
Merge branch 'ticket40674_047_01' into maint-0.4.7

2 years agodns: Make TTLs fuzzy at exit relays
Rasmus Dahlberg [Wed, 12 Oct 2022 18:29:11 +0000 (20:29 +0200)] 
dns: Make TTLs fuzzy at exit relays

This change mitigates DNS-based website oracles by making the time that
a domain name is cached uncertain (+- 4 minutes of what's measurable).

Resolves TROVE-2021-009.

Fixes #40674

2 years agorelay: Cache onion queue parameters on consensus change
David Goulet [Wed, 9 Nov 2022 20:10:19 +0000 (15:10 -0500)] 
relay: Cache onion queue parameters on consensus change

This is part of the fast path so we need to cache consensus parameters
instead of querying it everytime we need to learn a value.

Part of #40704

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agorelay: Make the max pending tasks per CPU a consensus parameter
David Goulet [Wed, 9 Nov 2022 17:49:23 +0000 (12:49 -0500)] 
relay: Make the max pending tasks per CPU a consensus parameter

Until now, there was this magic number (64) used as the maximum number
of tasks a CPU worker can take at once.

This commit makes it a consensus parameter so our future selves can
think of a better value depending on network conditions.

Part of #40704

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agorelay: Add the onion_queue_wait_cutoff consensus param
David Goulet [Wed, 9 Nov 2022 15:29:47 +0000 (10:29 -0500)] 
relay: Add the onion_queue_wait_cutoff consensus param

Transform the hardcoded value ONIONQUEUE_WAIT_CUTOFF into a consensus
parameter so we can control it network wide.

Closes #40704

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agorelay: Make MaxOnionQueueDelay into a consensus param
David Goulet [Wed, 9 Nov 2022 15:25:30 +0000 (10:25 -0500)] 
relay: Make MaxOnionQueueDelay into a consensus param

Part of #40704

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agoMerge branch 'tor-gitlab/mr/654' into maint-0.4.7
David Goulet [Wed, 9 Nov 2022 16:51:46 +0000 (11:51 -0500)] 
Merge branch 'tor-gitlab/mr/654' into maint-0.4.7

2 years agometrics: Reorganize state labels so rate() can be applied
Mike Perry [Tue, 8 Nov 2022 20:59:36 +0000 (20:59 +0000)] 
metrics: Reorganize state labels so rate() can be applied

Part of #40708.

2 years agometrics: Use N_EWMA for moving avg, with N=100.
Mike Perry [Tue, 8 Nov 2022 19:02:57 +0000 (19:02 +0000)] 
metrics: Use N_EWMA for moving avg, with N=100.

Part of #40708.

2 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Wed, 9 Nov 2022 16:47:06 +0000 (11:47 -0500)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

2 years agobuild: fix -Wstrict-prototypes (Clang 16)
Sam James [Tue, 8 Nov 2022 06:42:59 +0000 (06:42 +0000)] 
build: fix -Wstrict-prototypes (Clang 16)

Clang 16 warns on -Wstrict-prototypes in preparation for C23 which can
among other things, lead to some configure tests silently failing/returning the wrong result.

Fixes this error:
```
-ignoreme: warning: a function declaration without a prototype is deprecated in all versions of C [-Wstrict-prototypes]
+ignoreme: error: a function declaration without a prototype is deprecated in all versions of C [-Werror,-Wstrict-prototypes]
 main ()
```

For more information, see LWN.net [0] or LLVM's Discourse [1], gentoo-dev@ [2],
or the (new) c-std-porting mailing list [3].

[0] https://lwn.net/Articles/913505/
[1] https://discourse.llvm.org/t/configure-script-breakage-with-the-new-werror-implicit-function-declaration/65213
[2] https://archives.gentoo.org/gentoo-dev/message/dd9f2d3082b8b6f8dfbccb0639e6e240
[3] hosted at lists.linux.dev.

Bug: https://bugs.gentoo.org/879747
Signed-off-by: Sam James <sam@gentoo.org>
---

2 years agoMerge branch 'tor-gitlab/mr/651' into maint-0.4.7
David Goulet [Tue, 8 Nov 2022 20:25:08 +0000 (15:25 -0500)] 
Merge branch 'tor-gitlab/mr/651' into maint-0.4.7

2 years agometrics: Record percentage of blocked channels
Mike Perry [Tue, 8 Nov 2022 18:25:07 +0000 (18:25 +0000)] 
metrics: Record percentage of blocked channels

Part of #40708.

2 years agometrics: Report amount of cwnd drop from delta and gamma
Mike Perry [Tue, 8 Nov 2022 17:39:34 +0000 (17:39 +0000)] 
metrics: Report amount of cwnd drop from delta and gamma

Part of #40708.

2 years agoMerge branch 'tor-gitlab/mr/650' into maint-0.4.7
David Goulet [Tue, 8 Nov 2022 17:36:19 +0000 (12:36 -0500)] 
Merge branch 'tor-gitlab/mr/650' into maint-0.4.7

2 years agorelay: Remove unused conn->ext_or_conn_id
David Goulet [Tue, 26 Jul 2022 15:18:15 +0000 (11:18 -0400)] 
relay: Remove unused conn->ext_or_conn_id

This also incidently removes a use of uninitialized stack data from the
connection_or_set_ext_or_identifier() function.

Fixes #40648

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agomath: Replace naughty macro by an inline function
David Goulet [Mon, 7 Nov 2022 15:01:47 +0000 (10:01 -0500)] 
math: Replace naughty macro by an inline function

Part of #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Add flow control metrics.
Mike Perry [Thu, 3 Nov 2022 21:27:08 +0000 (21:27 +0000)] 
metrics: Add flow control metrics.

Part of #40708.

2 years agometrics: Add stats when the clock stalls.
Mike Perry [Thu, 3 Nov 2022 20:08:01 +0000 (20:08 +0000)] 
metrics: Add stats when the clock stalls.

Part of #40708.

2 years agometrics: Add running average of CC cwnd in slow start when closing circuit
Mike Perry [Thu, 3 Nov 2022 19:48:16 +0000 (19:48 +0000)] 
metrics: Add running average of CC cwnd in slow start when closing circuit

Count slow start separately.

Part of #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agochanges: Add file for ticket 40708
David Goulet [Thu, 3 Nov 2022 17:14:04 +0000 (13:14 -0400)] 
changes: Add file for ticket 40708

Closes #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Add stats when reaching vegas delta or ss_cwnd_max
David Goulet [Thu, 3 Nov 2022 17:12:47 +0000 (13:12 -0400)] 
metrics: Add stats when reaching vegas delta or ss_cwnd_max

Part of #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Add running average of CC cwnd when closing circuit
David Goulet [Thu, 3 Nov 2022 16:41:21 +0000 (12:41 -0400)] 
metrics: Add running average of CC cwnd when closing circuit

Part of #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Add running average of CC cwnd when exiting slow start
David Goulet [Thu, 3 Nov 2022 14:43:37 +0000 (10:43 -0400)] 
metrics: Add running average of CC cwnd when exiting slow start

Part of #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Add connection socket family to metrics
David Goulet [Thu, 3 Nov 2022 17:05:21 +0000 (13:05 -0400)] 
metrics: Add connection socket family to metrics

Adds either ipv4 or ipv6 to the "tor_relay_connections_total" stats.

Closes #40710

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agometrics: Add stats for num circ reaching max cell outq
David Goulet [Thu, 3 Nov 2022 13:37:38 +0000 (09:37 -0400)] 
metrics: Add stats for num circ reaching max cell outq

Part of #40708

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agoClip DNS TTL values once in event callback
Rasmus Dahlberg [Wed, 12 Oct 2022 18:29:11 +0000 (20:29 +0200)] 
Clip DNS TTL values once in event callback

This change ensures that other parts of the code base always operate on
the same clipped TTL values, notably without being aware of clipping.

2 years agosandbox: Add my-consensus-<flavor-name> to sandbox for dirauth
David Goulet [Mon, 31 Oct 2022 15:37:43 +0000 (11:37 -0400)] 
sandbox: Add my-consensus-<flavor-name> to sandbox for dirauth

Fixese #40663

Signed-off-by: David Goulet <dgoulet@torproject.org>
2 years agothread: Bump max detectable CPU from 16 to 128
David Goulet [Fri, 28 Oct 2022 15:13:46 +0000 (11:13 -0400)] 
thread: Bump max detectable CPU from 16 to 128

Lets take advantage of those beefy machines ;).

Closes #40703

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoMerge branch 'tor-gitlab/mr/645' into maint-0.4.7
David Goulet [Thu, 27 Oct 2022 15:42:07 +0000 (11:42 -0400)] 
Merge branch 'tor-gitlab/mr/645' into maint-0.4.7

3 years agoMerge branch 'tor-gitlab/mr/644' into maint-0.4.7
David Goulet [Thu, 27 Oct 2022 15:41:43 +0000 (11:41 -0400)] 
Merge branch 'tor-gitlab/mr/644' into maint-0.4.7

3 years agometrics: Treat relay connections as gauge, not counter
David Goulet [Thu, 27 Oct 2022 15:35:27 +0000 (11:35 -0400)] 
metrics: Treat relay connections as gauge, not counter

Fixes #40699

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoChanges file for 40683
Mike Perry [Thu, 27 Oct 2022 15:36:53 +0000 (15:36 +0000)] 
Changes file for 40683

3 years agoStrip "__.SYMDEF*" before re-archiving in combine_libs on macOS and iOS.
Alexander Færøy [Fri, 14 Oct 2022 10:12:46 +0000 (12:12 +0200)] 
Strip "__.SYMDEF*" before re-archiving in combine_libs on macOS and iOS.

This patch changes how combine_libs works on Darwin like platforms to
make sure we don't include any `__.SYMDEF` and `__.SYMDEF SORTED`
symbols on the archive before we repack and run ${RANLIB} on the
archive.

See: tpo/core/tor#40683.

3 years agochanges: Update changes for ticket 40194
David Goulet [Thu, 27 Oct 2022 14:35:10 +0000 (10:35 -0400)] 
changes: Update changes for ticket 40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agometrics: Add number of opened circuits to MetricsPort
David Goulet [Thu, 27 Oct 2022 14:39:55 +0000 (10:39 -0400)] 
metrics: Add number of opened circuits to MetricsPort

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorelay: Add our consensus relay flag to MetricsPort
David Goulet [Thu, 27 Oct 2022 14:33:25 +0000 (10:33 -0400)] 
relay: Add our consensus relay flag to MetricsPort

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agometrics: Add traffic related stats to MetricsPort
David Goulet [Thu, 27 Oct 2022 14:00:50 +0000 (10:00 -0400)] 
metrics: Add traffic related stats to MetricsPort

At this commit, bytes read and written are exported.

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorelay: Add DoS subsystem stats to MetricsPort
David Goulet [Thu, 27 Oct 2022 13:54:54 +0000 (09:54 -0400)] 
relay: Add DoS subsystem stats to MetricsPort

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agometrics: Fix naming and documentation
David Goulet [Thu, 27 Oct 2022 14:45:08 +0000 (10:45 -0400)] 
metrics: Fix naming and documentation

After nickm's review, minor changes to names and comments.

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorelay: Change the connection metrics name
David Goulet [Thu, 13 Oct 2022 15:09:40 +0000 (11:09 -0400)] 
relay: Change the connection metrics name

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorelay: Add CC RTT reset stats to MetricsPort
David Goulet [Thu, 13 Oct 2022 14:50:18 +0000 (10:50 -0400)] 
relay: Add CC RTT reset stats to MetricsPort

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorelay: Add total number of streams seen on MetricsPort
David Goulet [Thu, 13 Oct 2022 14:41:21 +0000 (10:41 -0400)] 
relay: Add total number of streams seen on MetricsPort

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorephist: Track number of streams seen per type
David Goulet [Thu, 13 Oct 2022 14:32:16 +0000 (10:32 -0400)] 
rephist: Track number of streams seen per type

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agochanges: Ticket 40694
David Goulet [Mon, 24 Oct 2022 15:14:50 +0000 (11:14 -0400)] 
changes: Ticket 40694

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agohs: Retry service rendezvous on circuit close
David Goulet [Wed, 19 Oct 2022 19:27:22 +0000 (15:27 -0400)] 
hs: Retry service rendezvous on circuit close

Move the retry from circuit_expire_building() to when the offending
circuit is being closed.

Fixes #40695

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agocirc: Get rid of hs_circ_has_timed_out
David Goulet [Wed, 19 Oct 2022 19:11:11 +0000 (15:11 -0400)] 
circ: Get rid of hs_circ_has_timed_out

Logic is too convoluted and we can't efficiently apply a specific
timeout depending on the purpose.

Remove it and instead rely on the right circuit cutoff instead of
keeping this flagged circuit open forever.

Part of #40694

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agocirc: Set proper timeout cutoff for HS circuits
David Goulet [Wed, 19 Oct 2022 18:50:00 +0000 (14:50 -0400)] 
circ: Set proper timeout cutoff for HS circuits

Explicitly set the S_CONNECT_REND purpose to a 4-hop cutoff.

As for the established rendezvous circuit waiting on the RENDEZVOUS2,
set one that is very long considering the possible waiting time for the
service to get the request and join our rendezvous.

Part of #40694

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agohs: Retry rdv circuit if repurposed
David Goulet [Mon, 24 Oct 2022 15:03:38 +0000 (11:03 -0400)] 
hs: Retry rdv circuit if repurposed

This can happen if our measurement subsystem decides to snatch it.

Fixes #40696

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoMerge branch 'tor-gitlab/mr/635' into maint-0.4.7
David Goulet [Wed, 26 Oct 2022 19:01:40 +0000 (15:01 -0400)] 
Merge branch 'tor-gitlab/mr/635' into maint-0.4.7

3 years agohs: Change the error for a collapsing client circuit
David Goulet [Wed, 19 Oct 2022 18:41:48 +0000 (14:41 -0400)] 
hs: Change the error for a collapsing client circuit

Change it to an "unreachable" error so the intro point can be retried
and not flagged as a failure and never retried again.

Closes #40692

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Wed, 26 Oct 2022 18:21:41 +0000 (14:21 -0400)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

3 years agoMerge branch 'tor-gitlab/mr/631' into maint-0.4.5
David Goulet [Wed, 26 Oct 2022 18:21:35 +0000 (14:21 -0400)] 
Merge branch 'tor-gitlab/mr/631' into maint-0.4.5

3 years agodirauth: Remove Faravahar
David Goulet [Tue, 18 Oct 2022 14:45:17 +0000 (10:45 -0400)] 
dirauth: Remove Faravahar

Closes #40688

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Wed, 26 Oct 2022 18:12:51 +0000 (14:12 -0400)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

3 years agoMerge branch 'tor-gitlab/mr/629' into maint-0.4.7
David Goulet [Wed, 26 Oct 2022 18:06:33 +0000 (14:06 -0400)] 
Merge branch 'tor-gitlab/mr/629' into maint-0.4.7

3 years agorelay: Reduce the minimum circuit cell in queue limit
David Goulet [Tue, 18 Oct 2022 16:19:40 +0000 (12:19 -0400)] 
relay: Reduce the minimum circuit cell in queue limit

With congestion control, the flow control window is much lower than the
initial 1000.

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agodos: Apply circuit creation defenses if circ max queue cell reached
David Goulet [Mon, 17 Oct 2022 15:34:57 +0000 (11:34 -0400)] 
dos: Apply circuit creation defenses if circ max queue cell reached

This adds two consensus parameters to control the outbound max circuit
queue cell size limit and how many times it is allowed to reach that
limit for a single client IP.

Closes #40680

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agodir auths now omit Measured= if rs->is_authority
Roger Dingledine [Fri, 21 Oct 2022 00:56:33 +0000 (20:56 -0400)] 
dir auths now omit Measured= if rs->is_authority

Directory authorities stop voting a consensus "Measured" weight
for relays with the Authority flag. Now these relays will be
considered unmeasured, which should reserve their bandwidth
for their dir auth role and minimize distractions from other roles.

In place of the "Measured" weight, they now include a
"MeasuredButAuthority" weight (not used by anything) so the bandwidth
authority's opinion on this relay can be recorded for posterity.

Resolves ticket 40698.

3 years agoback out most of commit b7992d4f
Roger Dingledine [Mon, 24 Oct 2022 08:30:23 +0000 (04:30 -0400)] 
back out most of commit b7992d4f

The AuthDirDontVoteOnDirAuthBandwidth torrc option never worked, and it
was implemented in a way that could have produced consensus conflicts
if it had.

Resolves bug 40700.

3 years agofix typo in #40673's changes file
Roger Dingledine [Thu, 20 Oct 2022 23:46:27 +0000 (19:46 -0400)] 
fix typo in #40673's changes file

3 years agodirauth: Change dizum IP address
David Goulet [Tue, 18 Oct 2022 14:35:45 +0000 (10:35 -0400)] 
dirauth: Change dizum IP address

Closes #40687

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoMerge branch 'maint-0.4.5' into maint-0.4.7
David Goulet [Fri, 14 Oct 2022 13:12:23 +0000 (09:12 -0400)] 
Merge branch 'maint-0.4.5' into maint-0.4.7

3 years agoFix a completely wrong calculation in mach monotime_init_internal()
Nick Mathewson [Thu, 13 Oct 2022 17:40:10 +0000 (13:40 -0400)] 
Fix a completely wrong calculation in mach monotime_init_internal()

Bug 1: We were purporting to calculate milliseconds per tick, when we
*should* have been computing ticks per millisecond.

Bug 2: Instead of computing either one of those, we were _actually_
computing femtoseconds per tick.

These two bugs covered for one another on x86 hardware, where 1 tick
== 1 nanosecond.  But on M1 OSX, 1 tick is about 41 nanoseconds,
causing surprising results.

Fixes bug 40684; bugfix on 0.3.3.1-alpha.

3 years agorelay: Add number of rejected connections to MetricsPort
David Goulet [Wed, 12 Oct 2022 13:25:01 +0000 (09:25 -0400)] 
relay: Add number of rejected connections to MetricsPort

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agorelay: Add connection stats to MetricsPort
David Goulet [Tue, 11 Oct 2022 18:03:38 +0000 (14:03 -0400)] 
relay: Add connection stats to MetricsPort

This adds the number of created and opened connections to the
MetricsPort for a relay for each connection type and direction.

Output looks like:

  # HELP tor_relay_connections Connections metrics of this relay
  # TYPE tor_relay_connections counter
  tor_relay_connections{type="OR listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="OR listener",direction="received",state="created"} 0
  tor_relay_connections{type="OR listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="OR listener",direction="received",state="opened"} 0
  tor_relay_connections{type="OR",direction="initiated",state="created"} 5
  tor_relay_connections{type="OR",direction="received",state="created"} 0
  tor_relay_connections{type="OR",direction="initiated",state="opened"} 5
  tor_relay_connections{type="OR",direction="received",state="opened"} 0
  tor_relay_connections{type="Exit",direction="initiated",state="created"} 0
  tor_relay_connections{type="Exit",direction="received",state="created"} 0
  tor_relay_connections{type="Exit",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Exit",direction="received",state="opened"} 0
  tor_relay_connections{type="Socks listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Socks listener",direction="received",state="created"} 0
  tor_relay_connections{type="Socks listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Socks listener",direction="received",state="opened"} 0
  tor_relay_connections{type="Socks",direction="initiated",state="created"} 0
  tor_relay_connections{type="Socks",direction="received",state="created"} 0
  tor_relay_connections{type="Socks",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Socks",direction="received",state="opened"} 0
  tor_relay_connections{type="Directory listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Directory listener",direction="received",state="created"} 0
  tor_relay_connections{type="Directory listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Directory listener",direction="received",state="opened"} 0
  tor_relay_connections{type="Directory",direction="initiated",state="created"} 0
  tor_relay_connections{type="Directory",direction="received",state="created"} 0
  tor_relay_connections{type="Directory",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Directory",direction="received",state="opened"} 0
  tor_relay_connections{type="Control listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Control listener",direction="received",state="created"} 0
  tor_relay_connections{type="Control listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Control listener",direction="received",state="opened"} 0
  tor_relay_connections{type="Control",direction="initiated",state="created"} 0
  tor_relay_connections{type="Control",direction="received",state="created"} 0
  tor_relay_connections{type="Control",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Control",direction="received",state="opened"} 0
  tor_relay_connections{type="Transparent pf/netfilter listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Transparent pf/netfilter listener",direction="received",state="created"} 0
  tor_relay_connections{type="Transparent pf/netfilter listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Transparent pf/netfilter listener",direction="received",state="opened"} 0
  tor_relay_connections{type="Transparent natd listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Transparent natd listener",direction="received",state="created"} 0
  tor_relay_connections{type="Transparent natd listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Transparent natd listener",direction="received",state="opened"} 0
  tor_relay_connections{type="DNS listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="DNS listener",direction="received",state="created"} 0
  tor_relay_connections{type="DNS listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="DNS listener",direction="received",state="opened"} 0
  tor_relay_connections{type="Extended OR",direction="initiated",state="created"} 0
  tor_relay_connections{type="Extended OR",direction="received",state="created"} 0
  tor_relay_connections{type="Extended OR",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Extended OR",direction="received",state="opened"} 0
  tor_relay_connections{type="Extended OR listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Extended OR listener",direction="received",state="created"} 0
  tor_relay_connections{type="Extended OR listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Extended OR listener",direction="received",state="opened"} 0
  tor_relay_connections{type="HTTP tunnel listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="HTTP tunnel listener",direction="received",state="created"} 0
  tor_relay_connections{type="HTTP tunnel listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="HTTP tunnel listener",direction="received",state="opened"} 0
  tor_relay_connections{type="Metrics listener",direction="initiated",state="created"} 0
  tor_relay_connections{type="Metrics listener",direction="received",state="created"} 1
  tor_relay_connections{type="Metrics listener",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Metrics listener",direction="received",state="opened"} 1
  tor_relay_connections{type="Metrics",direction="initiated",state="created"} 0
  tor_relay_connections{type="Metrics",direction="received",state="created"} 0
  tor_relay_connections{type="Metrics",direction="initiated",state="opened"} 0
  tor_relay_connections{type="Metrics",direction="received",state="opened"} 0

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoconn: Keep stats of opened and closed connections
David Goulet [Tue, 11 Oct 2022 17:17:35 +0000 (13:17 -0400)] 
conn: Keep stats of opened and closed connections

Related to #40194

Signed-off-by: David Goulet <dgoulet@torproject.org>
3 years agoProperly compute cell-drop overload fraction
Andy [Thu, 6 Oct 2022 04:30:18 +0000 (04:30 +0000)] 
Properly compute cell-drop overload fraction

Patch to address #40673. An additional check has been added to
onion_pending_add() in order to ensure that we avoid counting create
cells from clients.

In the cpuworker.c assign_onionskin_to_cpuworker
method if total_pending_tasks >= max_pending_tasks
and channel_is_client(circ->p_chan) returns false then
rep_hist_note_circuit_handshake_dropped() will be called and
rep_hist_note_circuit_handshake_assigned() will not be called. This
causes relays to run into errors due to the fact that the number of
dropped packets exceeds the total number of assigned packets.

To avoid this situation a check has been added to
onion_pending_add() to ensure that these erroneous calls to
rep_hist_note_circuit_handshake_dropped() are not made.

See the #40673 ticket for the conversation with armadev about this issue.