1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142 |
- #include "core/or/or.h"
- #include "app/config/config.h"
- #include "core/mainloop/connection.h"
- #include "core/or/channel.h"
- #include "core/or/circuitbuild.h"
- #include "core/or/circuitlist.h"
- #include "core/or/circuitstats.h"
- #include "core/or/circuituse.h"
- #include "core/or/connection_edge.h"
- #include "core/or/policies.h"
- #include "feature/client/addressmap.h"
- #include "feature/client/bridges.h"
- #include "feature/client/circpathbias.h"
- #include "feature/client/entrynodes.h"
- #include "feature/control/control.h"
- #include "feature/dircommon/directory.h"
- #include "feature/hs/hs_circuit.h"
- #include "feature/hs/hs_client.h"
- #include "feature/hs/hs_common.h"
- #include "feature/hs/hs_ident.h"
- #include "feature/hs/hs_stats.h"
- #include "feature/nodelist/describe.h"
- #include "feature/nodelist/networkstatus.h"
- #include "feature/nodelist/nodelist.h"
- #include "feature/nodelist/routerlist.h"
- #include "feature/relay/routermode.h"
- #include "feature/relay/selftest.h"
- #include "feature/rend/rendclient.h"
- #include "feature/rend/rendcommon.h"
- #include "feature/rend/rendservice.h"
- #include "feature/stats/predict_ports.h"
- #include "lib/math/fp.h"
- #include "lib/time/tvdiff.h"
- #include "core/or/cpath_build_state_st.h"
- #include "feature/dircommon/dir_connection_st.h"
- #include "core/or/entry_connection_st.h"
- #include "core/or/extend_info_st.h"
- #include "core/or/or_circuit_st.h"
- #include "core/or/origin_circuit_st.h"
- #include "core/or/socks_request_st.h"
- static void circuit_expire_old_circuits_clientside(void);
- static void circuit_increment_failure_count(void);
- static int
- circuit_matches_with_rend_stream(const edge_connection_t *edge_conn,
- const origin_circuit_t *origin_circ)
- {
-
- if ((edge_conn->rend_data && !origin_circ->rend_data) ||
- (!edge_conn->rend_data && origin_circ->rend_data) ||
- (edge_conn->rend_data && origin_circ->rend_data &&
- rend_cmp_service_ids(rend_data_get_address(edge_conn->rend_data),
- rend_data_get_address(origin_circ->rend_data)))) {
-
- return 0;
- }
-
- if ((edge_conn->hs_ident && !origin_circ->hs_ident) ||
- (!edge_conn->hs_ident && origin_circ->hs_ident) ||
- (edge_conn->hs_ident && origin_circ->hs_ident &&
- !ed25519_pubkey_eq(&edge_conn->hs_ident->identity_pk,
- &origin_circ->hs_ident->identity_pk))) {
-
- return 0;
- }
- return 1;
- }
- static int
- circuit_is_acceptable(const origin_circuit_t *origin_circ,
- const entry_connection_t *conn,
- int must_be_open, uint8_t purpose,
- int need_uptime, int need_internal,
- time_t now)
- {
- const circuit_t *circ = TO_CIRCUIT(origin_circ);
- const node_t *exitnode;
- cpath_build_state_t *build_state;
- tor_assert(circ);
- tor_assert(conn);
- tor_assert(conn->socks_request);
- if (must_be_open && (circ->state != CIRCUIT_STATE_OPEN || !circ->n_chan))
- return 0;
- if (circ->marked_for_close)
- return 0;
-
- if (purpose == CIRCUIT_PURPOSE_C_REND_JOINED && !must_be_open) {
- if (circ->purpose != CIRCUIT_PURPOSE_C_ESTABLISH_REND &&
- circ->purpose != CIRCUIT_PURPOSE_C_REND_READY &&
- circ->purpose != CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED &&
- circ->purpose != CIRCUIT_PURPOSE_C_REND_JOINED)
- return 0;
- } else if (purpose == CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT &&
- !must_be_open) {
- if (circ->purpose != CIRCUIT_PURPOSE_C_INTRODUCING &&
- circ->purpose != CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT)
- return 0;
- } else {
- if (purpose != circ->purpose)
- return 0;
- }
-
- if (origin_circ->hs_circ_has_timed_out) {
- return 0;
- }
- if (purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- purpose == CIRCUIT_PURPOSE_C_HSDIR_GET ||
- purpose == CIRCUIT_PURPOSE_S_HSDIR_POST ||
- purpose == CIRCUIT_PURPOSE_HS_VANGUARDS ||
- purpose == CIRCUIT_PURPOSE_C_REND_JOINED) {
- if (circ->timestamp_dirty &&
- circ->timestamp_dirty+get_options()->MaxCircuitDirtiness <= now)
- return 0;
- }
- if (origin_circ->unusable_for_new_conns)
- return 0;
-
-
- build_state = origin_circ->build_state;
- exitnode = build_state_get_exit_node(build_state);
- if (need_uptime && !build_state->need_uptime)
- return 0;
- if (need_internal != build_state->is_internal)
- return 0;
- if (purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- purpose == CIRCUIT_PURPOSE_S_HSDIR_POST ||
- purpose == CIRCUIT_PURPOSE_C_HSDIR_GET) {
- tor_addr_t addr;
- const int family = tor_addr_parse(&addr, conn->socks_request->address);
- if (!exitnode && !build_state->onehop_tunnel) {
- log_debug(LD_CIRC,"Not considering circuit with unknown router.");
- return 0;
- }
- if (build_state->onehop_tunnel) {
- if (!conn->want_onehop) {
- log_debug(LD_CIRC,"Skipping one-hop circuit.");
- return 0;
- }
- tor_assert(conn->chosen_exit_name);
- if (build_state->chosen_exit) {
- char digest[DIGEST_LEN];
- if (hexdigest_to_digest(conn->chosen_exit_name, digest) < 0)
- return 0;
- if (tor_memneq(digest, build_state->chosen_exit->identity_digest,
- DIGEST_LEN))
- return 0;
- if (tor_digest_is_zero(digest)) {
-
- if (family < 0 ||
- !tor_addr_eq(&build_state->chosen_exit->addr, &addr) ||
- build_state->chosen_exit->port != conn->socks_request->port)
- return 0;
- }
- }
- } else {
- if (conn->want_onehop) {
-
- return 0;
- }
- }
- if (origin_circ->prepend_policy && family != -1) {
- int r = compare_tor_addr_to_addr_policy(&addr,
- conn->socks_request->port,
- origin_circ->prepend_policy);
- if (r == ADDR_POLICY_REJECTED)
- return 0;
- }
- if (exitnode && !connection_ap_can_use_exit(conn, exitnode)) {
-
- return 0;
- }
- } else {
- const edge_connection_t *edge_conn = ENTRY_TO_EDGE_CONN(conn);
- if (!circuit_matches_with_rend_stream(edge_conn, origin_circ)) {
- return 0;
- }
- }
- if (!connection_edge_compatible_with_circuit(conn, origin_circ)) {
-
- return 0;
- }
- return 1;
- }
- static int
- circuit_is_better(const origin_circuit_t *oa, const origin_circuit_t *ob,
- const entry_connection_t *conn)
- {
- const circuit_t *a = TO_CIRCUIT(oa);
- const circuit_t *b = TO_CIRCUIT(ob);
- const uint8_t purpose = ENTRY_TO_CONN(conn)->purpose;
- int a_bits, b_bits;
-
- if (oa->relaxed_timeout && !ob->relaxed_timeout)
- return 0;
- if (!oa->relaxed_timeout && ob->relaxed_timeout)
- return 1;
- switch (purpose) {
- case CIRCUIT_PURPOSE_S_HSDIR_POST:
- case CIRCUIT_PURPOSE_C_HSDIR_GET:
- case CIRCUIT_PURPOSE_C_GENERAL:
-
- if (b->timestamp_dirty) {
- if (a->timestamp_dirty &&
- a->timestamp_dirty > b->timestamp_dirty)
- return 1;
- } else {
- if (a->timestamp_dirty ||
- timercmp(&a->timestamp_began, &b->timestamp_began, OP_GT))
- return 1;
- if (ob->build_state->is_internal)
-
- return 1;
- }
- break;
- case CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT:
-
- if (a->purpose > b->purpose)
- return 1;
- break;
- case CIRCUIT_PURPOSE_C_REND_JOINED:
-
- if (a->purpose > b->purpose)
- return 1;
- break;
- }
-
- a_bits = connection_edge_update_circuit_isolation(conn,
- (origin_circuit_t*)oa, 1);
- b_bits = connection_edge_update_circuit_isolation(conn,
- (origin_circuit_t*)ob, 1);
-
- if (a_bits < 0) {
- return 0;
- } else if (b_bits < 0) {
- return 1;
- }
- a_bits &= ~ oa->isolation_flags_mixed;
- a_bits &= ~ ob->isolation_flags_mixed;
- if (n_bits_set_u8(a_bits) < n_bits_set_u8(b_bits)) {
-
- return 1;
- }
- return 0;
- }
- static origin_circuit_t *
- circuit_get_best(const entry_connection_t *conn,
- int must_be_open, uint8_t purpose,
- int need_uptime, int need_internal)
- {
- origin_circuit_t *best=NULL;
- struct timeval now;
- int intro_going_on_but_too_old = 0;
- tor_assert(conn);
- tor_assert(purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- purpose == CIRCUIT_PURPOSE_HS_VANGUARDS ||
- purpose == CIRCUIT_PURPOSE_C_HSDIR_GET ||
- purpose == CIRCUIT_PURPOSE_S_HSDIR_POST ||
- purpose == CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT ||
- purpose == CIRCUIT_PURPOSE_C_REND_JOINED);
- tor_gettimeofday(&now);
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- origin_circuit_t *origin_circ;
- if (!CIRCUIT_IS_ORIGIN(circ))
- continue;
- origin_circ = TO_ORIGIN_CIRCUIT(circ);
-
- if (purpose == CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT &&
- !must_be_open && origin_circ->hs_circ_has_timed_out &&
- !circ->marked_for_close) {
- intro_going_on_but_too_old = 1;
- continue;
- }
- if (!circuit_is_acceptable(origin_circ,conn,must_be_open,purpose,
- need_uptime,need_internal, (time_t)now.tv_sec))
- continue;
-
- if (!best || circuit_is_better(origin_circ,best,conn))
- best = origin_circ;
- }
- SMARTLIST_FOREACH_END(circ);
- if (!best && intro_going_on_but_too_old)
- log_info(LD_REND|LD_CIRC, "There is an intro circuit being created "
- "right now, but it has already taken quite a while. Starting "
- "one in parallel.");
- return best;
- }
- static int
- count_pending_general_client_circuits(void)
- {
- int count = 0;
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- if (circ->marked_for_close ||
- circ->state == CIRCUIT_STATE_OPEN ||
- !CIRCUIT_PURPOSE_COUNTS_TOWARDS_MAXPENDING(circ->purpose) ||
- !CIRCUIT_IS_ORIGIN(circ))
- continue;
- ++count;
- }
- SMARTLIST_FOREACH_END(circ);
- return count;
- }
- #if 0
- int
- circuit_conforms_to_options(const origin_circuit_t *circ,
- const or_options_t *options)
- {
- const crypt_path_t *cpath, *cpath_next = NULL;
-
- for (cpath = circ->cpath; cpath_next != circ->cpath; cpath = cpath_next) {
- cpath_next = cpath->next;
- if (routerset_contains_extendinfo(options->ExcludeNodes,
- cpath->extend_info))
- return 0;
- }
-
- if (routerset_contains_extendinfo(options->ExcludeExitNodes,
- circ->cpath->prev->extend_info))
- return 0;
- return 1;
- }
- #endif
- void
- circuit_expire_building(void)
- {
-
- struct timeval general_cutoff, begindir_cutoff, fourhop_cutoff,
- close_cutoff, extremely_old_cutoff, hs_extremely_old_cutoff,
- cannibalized_cutoff, c_intro_cutoff, s_intro_cutoff, stream_cutoff;
- const or_options_t *options = get_options();
- struct timeval now;
- cpath_build_state_t *build_state;
- int any_opened_circs = 0;
- tor_gettimeofday(&now);
-
- any_opened_circs = circuit_any_opened_circuits();
- #define SET_CUTOFF(target, msec) do { \
- long ms = tor_lround(msec); \
- struct timeval diff; \
- diff.tv_sec = ms / 1000; \
- diff.tv_usec = (int)((ms % 1000) * 1000); \
- timersub(&now, &diff, &target); \
- } while (0)
-
- SET_CUTOFF(general_cutoff, get_circuit_build_timeout_ms());
- SET_CUTOFF(begindir_cutoff, get_circuit_build_timeout_ms());
-
-
-
-
- SET_CUTOFF(fourhop_cutoff, get_circuit_build_timeout_ms() * (10/6.0) + 1000);
-
- SET_CUTOFF(stream_cutoff, MAX(options->CircuitStreamTimeout,15)*1000 + 1000);
-
- SET_CUTOFF(cannibalized_cutoff,
- MAX(get_circuit_build_close_time_ms()*(4/6.0),
- options->CircuitStreamTimeout * 1000) + 1000);
-
- SET_CUTOFF(c_intro_cutoff, get_circuit_build_timeout_ms() * (14/6.0) + 1000);
-
- SET_CUTOFF(s_intro_cutoff, get_circuit_build_timeout_ms() * (9/6.0) + 1000);
- SET_CUTOFF(close_cutoff, get_circuit_build_close_time_ms());
- SET_CUTOFF(extremely_old_cutoff, get_circuit_build_close_time_ms()*2 + 1000);
- SET_CUTOFF(hs_extremely_old_cutoff,
- MAX(get_circuit_build_close_time_ms()*2 + 1000,
- options->SocksTimeout * 1000));
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *,victim) {
- struct timeval cutoff;
- bool fixed_time = circuit_build_times_disabled(get_options());
- if (!CIRCUIT_IS_ORIGIN(victim) ||
- victim->marked_for_close)
- continue;
-
- if (TO_ORIGIN_CIRCUIT(victim)->cpath->state == CPATH_STATE_CLOSED) {
- continue;
- }
- build_state = TO_ORIGIN_CIRCUIT(victim)->build_state;
- if (build_state && build_state->onehop_tunnel)
- cutoff = begindir_cutoff;
- else if (victim->purpose == CIRCUIT_PURPOSE_C_MEASURE_TIMEOUT)
- cutoff = close_cutoff;
- else if (victim->purpose == CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT)
- cutoff = c_intro_cutoff;
- else if (victim->purpose == CIRCUIT_PURPOSE_S_ESTABLISH_INTRO)
- cutoff = s_intro_cutoff;
- else if (victim->purpose == CIRCUIT_PURPOSE_C_ESTABLISH_REND)
- cutoff = stream_cutoff;
- else if (victim->purpose == CIRCUIT_PURPOSE_PATH_BIAS_TESTING)
- cutoff = close_cutoff;
- else if (TO_ORIGIN_CIRCUIT(victim)->has_opened &&
- victim->state != CIRCUIT_STATE_OPEN)
- cutoff = cannibalized_cutoff;
- else if (build_state && build_state->desired_path_len >= 4)
- cutoff = fourhop_cutoff;
- else
- cutoff = general_cutoff;
- if (TO_ORIGIN_CIRCUIT(victim)->hs_circ_has_timed_out)
- cutoff = hs_extremely_old_cutoff;
- if (timercmp(&victim->timestamp_began, &cutoff, OP_GT))
- continue;
-
- if (!any_opened_circs && victim->state != CIRCUIT_STATE_OPEN) {
-
- if (timercmp(&victim->timestamp_began, &close_cutoff, OP_GT)) {
- if (!TO_ORIGIN_CIRCUIT(victim)->relaxed_timeout) {
- int first_hop_succeeded = TO_ORIGIN_CIRCUIT(victim)->cpath->state
- == CPATH_STATE_OPEN;
- if (!fixed_time) {
- log_info(LD_CIRC,
- "No circuits are opened. Relaxing timeout for circuit %d "
- "(a %s %d-hop circuit in state %s with channel state %s).",
- TO_ORIGIN_CIRCUIT(victim)->global_identifier,
- circuit_purpose_to_string(victim->purpose),
- TO_ORIGIN_CIRCUIT(victim)->build_state ?
- TO_ORIGIN_CIRCUIT(victim)->build_state->desired_path_len :
- -1,
- circuit_state_to_string(victim->state),
- victim->n_chan ?
- channel_state_to_string(victim->n_chan->state) : "none");
- }
-
- circuit_build_times_count_timeout(get_circuit_build_times_mutable(),
- first_hop_succeeded);
- TO_ORIGIN_CIRCUIT(victim)->relaxed_timeout = 1;
- }
- continue;
- } else {
- static ratelim_t relax_timeout_limit = RATELIM_INIT(3600);
- const double build_close_ms = get_circuit_build_close_time_ms();
- if (!fixed_time) {
- log_fn_ratelim(&relax_timeout_limit, LOG_NOTICE, LD_CIRC,
- "No circuits are opened. Relaxed timeout for circuit %d "
- "(a %s %d-hop circuit in state %s with channel state %s) to "
- "%ldms. However, it appears the circuit has timed out "
- "anyway.",
- TO_ORIGIN_CIRCUIT(victim)->global_identifier,
- circuit_purpose_to_string(victim->purpose),
- TO_ORIGIN_CIRCUIT(victim)->build_state ?
- TO_ORIGIN_CIRCUIT(victim)->build_state->desired_path_len :
- -1,
- circuit_state_to_string(victim->state),
- victim->n_chan ?
- channel_state_to_string(victim->n_chan->state) : "none",
- (long)build_close_ms);
- }
- }
- }
- #if 0
-
- if (victim->purpose >= CIRCUIT_PURPOSE_C_INTRODUCING &&
- victim->purpose <= CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED) {
- if (!victim->timestamp_dirty)
- log_fn(LOG_DEBUG,"Considering %sopen purpose %d to %s (circid %d)."
- "(clean).",
- victim->state == CIRCUIT_STATE_OPEN ? "" : "non",
- victim->purpose, victim->build_state->chosen_exit_name,
- victim->n_circ_id);
- else
- log_fn(LOG_DEBUG,"Considering %sopen purpose %d to %s (circid %d). "
- "%d secs since dirty.",
- victim->state == CIRCUIT_STATE_OPEN ? "" : "non",
- victim->purpose, victim->build_state->chosen_exit_name,
- victim->n_circ_id,
- (int)(now - victim->timestamp_dirty));
- }
- #endif
-
- if (victim->state == CIRCUIT_STATE_OPEN) {
- switch (victim->purpose) {
- default:
- continue;
- case CIRCUIT_PURPOSE_S_ESTABLISH_INTRO:
- break;
- case CIRCUIT_PURPOSE_C_REND_READY:
-
-
- if (TO_ORIGIN_CIRCUIT(victim)->rend_data ||
- TO_ORIGIN_CIRCUIT(victim)->hs_ident ||
- victim->timestamp_dirty > cutoff.tv_sec)
- continue;
- break;
- case CIRCUIT_PURPOSE_PATH_BIAS_TESTING:
-
- TO_ORIGIN_CIRCUIT(victim)->path_state = PATH_STATE_USE_FAILED;
- break;
- case CIRCUIT_PURPOSE_C_INTRODUCING:
-
- continue;
- case CIRCUIT_PURPOSE_C_ESTABLISH_REND:
- case CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED:
- case CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT:
-
- if (victim->timestamp_dirty > cutoff.tv_sec)
- continue;
- break;
- }
- } else {
- int first_hop_succeeded = TO_ORIGIN_CIRCUIT(victim)->cpath &&
- TO_ORIGIN_CIRCUIT(victim)->cpath->state == CPATH_STATE_OPEN;
- if (TO_ORIGIN_CIRCUIT(victim)->p_streams != NULL) {
- log_warn(LD_BUG, "Circuit %d (purpose %d, %s) has timed out, "
- "yet has attached streams!",
- TO_ORIGIN_CIRCUIT(victim)->global_identifier,
- victim->purpose,
- circuit_purpose_to_string(victim->purpose));
- tor_fragile_assert();
- continue;
- }
- if (circuit_timeout_want_to_count_circ(TO_ORIGIN_CIRCUIT(victim)) &&
- circuit_build_times_enough_to_compute(get_circuit_build_times())) {
- log_info(LD_CIRC,
- "Deciding to count the timeout for circuit %"PRIu32"\n",
- TO_ORIGIN_CIRCUIT(victim)->global_identifier);
-
- if (victim->purpose != CIRCUIT_PURPOSE_C_MEASURE_TIMEOUT) {
- circuit_build_times_mark_circ_as_measurement_only(TO_ORIGIN_CIRCUIT(
- victim));
- continue;
- }
-
- if (timercmp(&victim->timestamp_began, &extremely_old_cutoff, OP_LT)) {
- log_notice(LD_CIRC,
- "Extremely large value for circuit build timeout: %lds. "
- "Assuming clock jump. Purpose %d (%s)",
- (long)(now.tv_sec - victim->timestamp_began.tv_sec),
- victim->purpose,
- circuit_purpose_to_string(victim->purpose));
- } else if (circuit_build_times_count_close(
- get_circuit_build_times_mutable(),
- first_hop_succeeded,
- (time_t)victim->timestamp_created.tv_sec)) {
- circuit_build_times_set_timeout(get_circuit_build_times_mutable());
- }
- }
- }
-
- if (!(TO_ORIGIN_CIRCUIT(victim)->hs_circ_has_timed_out)) {
- switch (victim->purpose) {
- case CIRCUIT_PURPOSE_C_REND_READY:
-
- if (TO_ORIGIN_CIRCUIT(victim)->build_state &&
- TO_ORIGIN_CIRCUIT(victim)->build_state->pending_final_cpath ==
- NULL)
- break;
-
- case CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT:
- case CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED:
-
- log_info(LD_CIRC,"Marking circ %u (state %d:%s, purpose %d) "
- "as timed-out HS circ",
- (unsigned)victim->n_circ_id,
- victim->state, circuit_state_to_string(victim->state),
- victim->purpose);
- TO_ORIGIN_CIRCUIT(victim)->hs_circ_has_timed_out = 1;
- continue;
- default:
- break;
- }
- }
-
- if (!(TO_ORIGIN_CIRCUIT(victim)->hs_circ_has_timed_out) &&
- victim->purpose == CIRCUIT_PURPOSE_S_CONNECT_REND) {
- log_info(LD_CIRC,"Marking circ %u (state %d:%s, purpose %d) "
- "as timed-out HS circ; relaunching rendezvous attempt.",
- (unsigned)victim->n_circ_id,
- victim->state, circuit_state_to_string(victim->state),
- victim->purpose);
- TO_ORIGIN_CIRCUIT(victim)->hs_circ_has_timed_out = 1;
- hs_circ_retry_service_rendezvous_point(TO_ORIGIN_CIRCUIT(victim));
- continue;
- }
- if (victim->n_chan)
- log_info(LD_CIRC,
- "Abandoning circ %u %s:%u (state %d,%d:%s, purpose %d, "
- "len %d)", TO_ORIGIN_CIRCUIT(victim)->global_identifier,
- channel_get_canonical_remote_descr(victim->n_chan),
- (unsigned)victim->n_circ_id,
- TO_ORIGIN_CIRCUIT(victim)->has_opened,
- victim->state, circuit_state_to_string(victim->state),
- victim->purpose,
- TO_ORIGIN_CIRCUIT(victim)->build_state ?
- TO_ORIGIN_CIRCUIT(victim)->build_state->desired_path_len :
- -1);
- else
- log_info(LD_CIRC,
- "Abandoning circ %u %u (state %d,%d:%s, purpose %d, len %d)",
- TO_ORIGIN_CIRCUIT(victim)->global_identifier,
- (unsigned)victim->n_circ_id,
- TO_ORIGIN_CIRCUIT(victim)->has_opened,
- victim->state,
- circuit_state_to_string(victim->state), victim->purpose,
- TO_ORIGIN_CIRCUIT(victim)->build_state ?
- TO_ORIGIN_CIRCUIT(victim)->build_state->desired_path_len :
- -1);
- circuit_log_path(LOG_INFO,LD_CIRC,TO_ORIGIN_CIRCUIT(victim));
- if (victim->purpose == CIRCUIT_PURPOSE_C_MEASURE_TIMEOUT)
- circuit_mark_for_close(victim, END_CIRC_REASON_MEASUREMENT_EXPIRED);
- else
- circuit_mark_for_close(victim, END_CIRC_REASON_TIMEOUT);
- pathbias_count_timeout(TO_ORIGIN_CIRCUIT(victim));
- } SMARTLIST_FOREACH_END(victim);
- }
- void
- circuit_expire_waiting_for_better_guard(void)
- {
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_origin_circuit_list(),
- origin_circuit_t *, circ) {
- if (TO_CIRCUIT(circ)->marked_for_close)
- continue;
- if (circ->guard_state == NULL)
- continue;
- if (entry_guard_state_should_expire(circ->guard_state))
- circuit_mark_for_close(TO_CIRCUIT(circ), END_CIRC_REASON_NONE);
- } SMARTLIST_FOREACH_END(circ);
- }
- static time_t last_expired_clientside_circuits = 0;
- void
- circuit_log_ancient_one_hop_circuits(int age)
- {
- #define MAX_ANCIENT_ONEHOP_CIRCUITS_TO_LOG 10
- time_t now = time(NULL);
- time_t cutoff = now - age;
- int n_found = 0;
- smartlist_t *log_these = smartlist_new();
- const or_options_t *options = get_options();
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- const origin_circuit_t *ocirc;
- if (! CIRCUIT_IS_ORIGIN(circ))
- continue;
- if (circ->timestamp_created.tv_sec >= cutoff)
- continue;
-
- if (rend_service_allow_non_anonymous_connection(options) &&
- (circ->purpose == CIRCUIT_PURPOSE_S_INTRO ||
- circ->purpose == CIRCUIT_PURPOSE_S_REND_JOINED))
- continue;
- ocirc = CONST_TO_ORIGIN_CIRCUIT(circ);
- if (ocirc->build_state && ocirc->build_state->onehop_tunnel) {
- ++n_found;
- if (smartlist_len(log_these) < MAX_ANCIENT_ONEHOP_CIRCUITS_TO_LOG)
- smartlist_add(log_these, (origin_circuit_t*) ocirc);
- }
- }
- SMARTLIST_FOREACH_END(circ);
- if (n_found == 0)
- goto done;
- log_notice(LD_HEARTBEAT,
- "Diagnostic for issue 8387: Found %d one-hop circuits more "
- "than %d seconds old! Logging %d...",
- n_found, age, smartlist_len(log_these));
- SMARTLIST_FOREACH_BEGIN(log_these, const origin_circuit_t *, ocirc) {
- char created[ISO_TIME_LEN+1];
- int stream_num;
- const edge_connection_t *conn;
- char *dirty = NULL;
- const circuit_t *circ = TO_CIRCUIT(ocirc);
- format_local_iso_time(created,
- (time_t)circ->timestamp_created.tv_sec);
- if (circ->timestamp_dirty) {
- char dirty_since[ISO_TIME_LEN+1];
- format_local_iso_time(dirty_since, circ->timestamp_dirty);
- tor_asprintf(&dirty, "Dirty since %s (%ld seconds vs %ld-second cutoff)",
- dirty_since, (long)(now - circ->timestamp_dirty),
- (long) options->MaxCircuitDirtiness);
- } else {
- dirty = tor_strdup("Not marked dirty");
- }
- log_notice(LD_HEARTBEAT, " #%d created at %s. %s, %s. %s for close. "
- "Package window: %d. "
- "%s for new conns. %s.",
- ocirc_sl_idx,
- created,
- circuit_state_to_string(circ->state),
- circuit_purpose_to_string(circ->purpose),
- circ->marked_for_close ? "Marked" : "Not marked",
- circ->package_window,
- ocirc->unusable_for_new_conns ? "Not usable" : "usable",
- dirty);
- tor_free(dirty);
- stream_num = 0;
- for (conn = ocirc->p_streams; conn; conn = conn->next_stream) {
- const connection_t *c = TO_CONN(conn);
- char stream_created[ISO_TIME_LEN+1];
- if (++stream_num >= 5)
- break;
- format_local_iso_time(stream_created, c->timestamp_created);
- log_notice(LD_HEARTBEAT, " Stream#%d created at %s. "
- "%s conn in state %s. "
- "It is %slinked and %sreading from a linked connection %p. "
- "Package window %d. "
- "%s for close (%s:%d). Hold-open is %sset. "
- "Has %ssent RELAY_END. %s on circuit.",
- stream_num,
- stream_created,
- conn_type_to_string(c->type),
- conn_state_to_string(c->type, c->state),
- c->linked ? "" : "not ",
- c->reading_from_linked_conn ? "": "not",
- c->linked_conn,
- conn->package_window,
- c->marked_for_close ? "Marked" : "Not marked",
- c->marked_for_close_file ? c->marked_for_close_file : "--",
- c->marked_for_close,
- c->hold_open_until_flushed ? "" : "not ",
- conn->edge_has_sent_end ? "" : "not ",
- conn->edge_blocked_on_circ ? "Blocked" : "Not blocked");
- if (! c->linked_conn)
- continue;
- c = c->linked_conn;
- log_notice(LD_HEARTBEAT, " Linked to %s connection in state %s "
- "(Purpose %d). %s for close (%s:%d). Hold-open is %sset. ",
- conn_type_to_string(c->type),
- conn_state_to_string(c->type, c->state),
- c->purpose,
- c->marked_for_close ? "Marked" : "Not marked",
- c->marked_for_close_file ? c->marked_for_close_file : "--",
- c->marked_for_close,
- c->hold_open_until_flushed ? "" : "not ");
- }
- } SMARTLIST_FOREACH_END(ocirc);
- log_notice(LD_HEARTBEAT, "It has been %ld seconds since I last called "
- "circuit_expire_old_circuits_clientside().",
- (long)(now - last_expired_clientside_circuits));
- done:
- smartlist_free(log_these);
- }
- void
- circuit_remove_handled_ports(smartlist_t *needed_ports)
- {
- int i;
- uint16_t *port;
- for (i = 0; i < smartlist_len(needed_ports); ++i) {
- port = smartlist_get(needed_ports, i);
- tor_assert(*port);
- if (circuit_stream_is_being_handled(NULL, *port,
- MIN_CIRCUITS_HANDLING_STREAM)) {
- log_debug(LD_CIRC,"Port %d is already being handled; removing.", *port);
- smartlist_del(needed_ports, i--);
- tor_free(port);
- } else {
- log_debug(LD_CIRC,"Port %d is not handled.", *port);
- }
- }
- }
- int
- circuit_stream_is_being_handled(entry_connection_t *conn,
- uint16_t port, int min)
- {
- const node_t *exitnode;
- int num=0;
- time_t now = time(NULL);
- int need_uptime = smartlist_contains_int_as_string(
- get_options()->LongLivedPorts,
- conn ? conn->socks_request->port : port);
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- if (CIRCUIT_IS_ORIGIN(circ) &&
- !circ->marked_for_close &&
- circ->purpose == CIRCUIT_PURPOSE_C_GENERAL &&
- (!circ->timestamp_dirty ||
- circ->timestamp_dirty + get_options()->MaxCircuitDirtiness > now)) {
- origin_circuit_t *origin_circ = TO_ORIGIN_CIRCUIT(circ);
- cpath_build_state_t *build_state = origin_circ->build_state;
- if (build_state->is_internal || build_state->onehop_tunnel)
- continue;
- if (origin_circ->unusable_for_new_conns)
- continue;
- if (origin_circ->isolation_values_set &&
- (conn == NULL ||
- !connection_edge_compatible_with_circuit(conn, origin_circ)))
- continue;
- exitnode = build_state_get_exit_node(build_state);
- if (exitnode && (!need_uptime || build_state->need_uptime)) {
- int ok;
- if (conn) {
- ok = connection_ap_can_use_exit(conn, exitnode);
- } else {
- addr_policy_result_t r;
- r = compare_tor_addr_to_node_policy(NULL, port, exitnode);
- ok = r != ADDR_POLICY_REJECTED && r != ADDR_POLICY_PROBABLY_REJECTED;
- }
- if (ok) {
- if (++num >= min)
- return 1;
- }
- }
- }
- }
- SMARTLIST_FOREACH_END(circ);
- return 0;
- }
- #define MAX_UNUSED_OPEN_CIRCUITS 14
- STATIC int
- circuit_is_available_for_use(const circuit_t *circ)
- {
- const origin_circuit_t *origin_circ;
- cpath_build_state_t *build_state;
- if (!CIRCUIT_IS_ORIGIN(circ))
- return 0;
- if (circ->marked_for_close)
- return 0;
- if (circ->timestamp_dirty)
- return 0;
- if (circ->purpose != CIRCUIT_PURPOSE_C_GENERAL &&
- circ->purpose != CIRCUIT_PURPOSE_HS_VANGUARDS)
- return 0;
- origin_circ = CONST_TO_ORIGIN_CIRCUIT(circ);
- if (origin_circ->unusable_for_new_conns)
- return 0;
- build_state = origin_circ->build_state;
- if (build_state->onehop_tunnel)
- return 0;
- return 1;
- }
- STATIC int
- needs_exit_circuits(time_t now, int *needs_uptime, int *needs_capacity)
- {
- return (!circuit_all_predicted_ports_handled(now, needs_uptime,
- needs_capacity) &&
- router_have_consensus_path() == CONSENSUS_PATH_EXIT);
- }
- #define SUFFICIENT_UPTIME_INTERNAL_HS_SERVERS 3
- STATIC int
- needs_hs_server_circuits(time_t now, int num_uptime_internal)
- {
- if (!rend_num_services() && !hs_service_get_num_services()) {
-
- goto no_need;
- }
- if (num_uptime_internal >= SUFFICIENT_UPTIME_INTERNAL_HS_SERVERS) {
-
- goto no_need;
- }
- if (router_have_consensus_path() == CONSENSUS_PATH_UNKNOWN) {
-
- goto no_need;
- }
-
- rep_hist_note_used_internal(now, 1, 1);
- return 1;
- no_need:
- return 0;
- }
- #define SUFFICIENT_INTERNAL_HS_CLIENTS 3
- #define SUFFICIENT_UPTIME_INTERNAL_HS_CLIENTS 2
- STATIC int
- needs_hs_client_circuits(time_t now, int *needs_uptime, int *needs_capacity,
- int num_internal, int num_uptime_internal)
- {
- int used_internal_recently = rep_hist_get_predicted_internal(now,
- needs_uptime,
- needs_capacity);
- int requires_uptime = num_uptime_internal <
- SUFFICIENT_UPTIME_INTERNAL_HS_CLIENTS &&
- needs_uptime;
- return (used_internal_recently &&
- (requires_uptime || num_internal < SUFFICIENT_INTERNAL_HS_CLIENTS) &&
- router_have_consensus_path() != CONSENSUS_PATH_UNKNOWN);
- }
- #define DFLT_CBT_UNUSED_OPEN_CIRCS (10)
- #define MIN_CBT_UNUSED_OPEN_CIRCS 0
- #define MAX_CBT_UNUSED_OPEN_CIRCS MAX_UNUSED_OPEN_CIRCUITS
- STATIC int
- needs_circuits_for_build(int num)
- {
- if (router_have_consensus_path() != CONSENSUS_PATH_UNKNOWN) {
- if (num < networkstatus_get_param(NULL, "cbtmaxopencircs",
- DFLT_CBT_UNUSED_OPEN_CIRCS,
- MIN_CBT_UNUSED_OPEN_CIRCS,
- MAX_CBT_UNUSED_OPEN_CIRCS) &&
- !circuit_build_times_disabled(get_options()) &&
- circuit_build_times_needs_circuits_now(get_circuit_build_times())) {
- return 1;
- }
- }
- return 0;
- }
- static void
- circuit_launch_predicted_hs_circ(int flags)
- {
-
- if (circuit_should_use_vanguards(CIRCUIT_PURPOSE_HS_VANGUARDS)) {
- circuit_launch(CIRCUIT_PURPOSE_HS_VANGUARDS, flags);
- } else {
-
- circuit_launch(CIRCUIT_PURPOSE_C_GENERAL, flags);
- }
- }
- static void
- circuit_predict_and_launch_new(void)
- {
- int num=0, num_internal=0, num_uptime_internal=0;
- int hidserv_needs_uptime=0, hidserv_needs_capacity=1;
- int port_needs_uptime=0, port_needs_capacity=1;
- time_t now = time(NULL);
- int flags = 0;
-
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- if (!circuit_is_available_for_use(circ))
- continue;
- num++;
- cpath_build_state_t *build_state = TO_ORIGIN_CIRCUIT(circ)->build_state;
- if (build_state->is_internal)
- num_internal++;
- if (build_state->need_uptime && build_state->is_internal)
- num_uptime_internal++;
- }
- SMARTLIST_FOREACH_END(circ);
-
- if (num >= MAX_UNUSED_OPEN_CIRCUITS)
- return;
- if (needs_exit_circuits(now, &port_needs_uptime, &port_needs_capacity)) {
- if (port_needs_uptime)
- flags |= CIRCLAUNCH_NEED_UPTIME;
- if (port_needs_capacity)
- flags |= CIRCLAUNCH_NEED_CAPACITY;
- log_info(LD_CIRC,
- "Have %d clean circs (%d internal), need another exit circ.",
- num, num_internal);
- circuit_launch(CIRCUIT_PURPOSE_C_GENERAL, flags);
- return;
- }
- if (needs_hs_server_circuits(now, num_uptime_internal)) {
- flags = (CIRCLAUNCH_NEED_CAPACITY | CIRCLAUNCH_NEED_UPTIME |
- CIRCLAUNCH_IS_INTERNAL);
- log_info(LD_CIRC,
- "Have %d clean circs (%d internal), need another internal "
- "circ for my hidden service.",
- num, num_internal);
- circuit_launch_predicted_hs_circ(flags);
- return;
- }
- if (needs_hs_client_circuits(now, &hidserv_needs_uptime,
- &hidserv_needs_capacity,
- num_internal, num_uptime_internal))
- {
- if (hidserv_needs_uptime)
- flags |= CIRCLAUNCH_NEED_UPTIME;
- if (hidserv_needs_capacity)
- flags |= CIRCLAUNCH_NEED_CAPACITY;
- flags |= CIRCLAUNCH_IS_INTERNAL;
- log_info(LD_CIRC,
- "Have %d clean circs (%d uptime-internal, %d internal), need"
- " another hidden service circ.",
- num, num_uptime_internal, num_internal);
- circuit_launch_predicted_hs_circ(flags);
- return;
- }
- if (needs_circuits_for_build(num)) {
- flags = CIRCLAUNCH_NEED_CAPACITY;
-
- if (router_have_consensus_path() == CONSENSUS_PATH_INTERNAL)
- flags |= CIRCLAUNCH_IS_INTERNAL;
- log_info(LD_CIRC,
- "Have %d clean circs need another buildtime test circ.", num);
- circuit_launch(CIRCUIT_PURPOSE_C_GENERAL, flags);
- return;
- }
- }
- #define TESTING_CIRCUIT_INTERVAL 300
- void
- circuit_build_needed_circs(time_t now)
- {
- const or_options_t *options = get_options();
-
- if (router_have_consensus_path() != CONSENSUS_PATH_UNKNOWN)
- connection_ap_rescan_and_attach_pending();
- circuit_expire_old_circs_as_needed(now);
- if (!options->DisablePredictedCircuits)
- circuit_predict_and_launch_new();
- }
- void
- circuit_expire_old_circs_as_needed(time_t now)
- {
- static time_t time_to_expire_and_reset = 0;
- if (time_to_expire_and_reset < now) {
- circuit_reset_failure_count(1);
- time_to_expire_and_reset = now + get_options()->NewCircuitPeriod;
- if (proxy_mode(get_options()))
- addressmap_clean(now);
- circuit_expire_old_circuits_clientside();
- #if 0
-
- circ = circuit_get_youngest_clean_open(CIRCUIT_PURPOSE_C_GENERAL);
- if (get_options()->RunTesting &&
- circ &&
- circ->timestamp_began.tv_sec + TESTING_CIRCUIT_INTERVAL < now) {
- log_fn(LOG_INFO,"Creating a new testing circuit.");
- circuit_launch(CIRCUIT_PURPOSE_C_GENERAL, 0);
- }
- #endif
- }
- }
- void
- circuit_detach_stream(circuit_t *circ, edge_connection_t *conn)
- {
- edge_connection_t *prevconn;
- tor_assert(circ);
- tor_assert(conn);
- if (conn->base_.type == CONN_TYPE_AP) {
- entry_connection_t *entry_conn = EDGE_TO_ENTRY_CONN(conn);
- entry_conn->may_use_optimistic_data = 0;
- }
- conn->cpath_layer = NULL;
- conn->on_circuit = NULL;
- if (CIRCUIT_IS_ORIGIN(circ)) {
- origin_circuit_t *origin_circ = TO_ORIGIN_CIRCUIT(circ);
- int removed = 0;
- if (conn == origin_circ->p_streams) {
- origin_circ->p_streams = conn->next_stream;
- removed = 1;
- } else {
- for (prevconn = origin_circ->p_streams;
- prevconn && prevconn->next_stream && prevconn->next_stream != conn;
- prevconn = prevconn->next_stream)
- ;
- if (prevconn && prevconn->next_stream) {
- prevconn->next_stream = conn->next_stream;
- removed = 1;
- }
- }
- if (removed) {
- log_debug(LD_APP, "Removing stream %d from circ %u",
- conn->stream_id, (unsigned)circ->n_circ_id);
-
- if (circ->purpose == CIRCUIT_PURPOSE_S_REND_JOINED) {
- hs_dec_rdv_stream_counter(origin_circ);
- }
- return;
- }
- } else {
- or_circuit_t *or_circ = TO_OR_CIRCUIT(circ);
- if (conn == or_circ->n_streams) {
- or_circ->n_streams = conn->next_stream;
- return;
- }
- if (conn == or_circ->resolving_streams) {
- or_circ->resolving_streams = conn->next_stream;
- return;
- }
- for (prevconn = or_circ->n_streams;
- prevconn && prevconn->next_stream && prevconn->next_stream != conn;
- prevconn = prevconn->next_stream)
- ;
- if (prevconn && prevconn->next_stream) {
- prevconn->next_stream = conn->next_stream;
- return;
- }
- for (prevconn = or_circ->resolving_streams;
- prevconn && prevconn->next_stream && prevconn->next_stream != conn;
- prevconn = prevconn->next_stream)
- ;
- if (prevconn && prevconn->next_stream) {
- prevconn->next_stream = conn->next_stream;
- return;
- }
- }
- log_warn(LD_BUG,"Edge connection not in circuit's list.");
-
- tor_fragile_assert();
- }
- static void
- circuit_expire_old_circuits_clientside(void)
- {
- struct timeval cutoff, now;
- tor_gettimeofday(&now);
- last_expired_clientside_circuits = now.tv_sec;
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- if (circ->marked_for_close || !CIRCUIT_IS_ORIGIN(circ))
- continue;
- cutoff = now;
- cutoff.tv_sec -= TO_ORIGIN_CIRCUIT(circ)->circuit_idle_timeout;
-
- if (circ->timestamp_dirty &&
- circ->timestamp_dirty + get_options()->MaxCircuitDirtiness <
- now.tv_sec &&
- !TO_ORIGIN_CIRCUIT(circ)->p_streams ) {
- log_debug(LD_CIRC, "Closing n_circ_id %u (dirty %ld sec ago, "
- "purpose %d)",
- (unsigned)circ->n_circ_id,
- (long)(now.tv_sec - circ->timestamp_dirty),
- circ->purpose);
-
- if (circ->purpose != CIRCUIT_PURPOSE_PATH_BIAS_TESTING)
- circuit_mark_for_close(circ, END_CIRC_REASON_FINISHED);
- } else if (!circ->timestamp_dirty && circ->state == CIRCUIT_STATE_OPEN) {
- if (timercmp(&circ->timestamp_began, &cutoff, OP_LT)) {
- if (circ->purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- circ->purpose == CIRCUIT_PURPOSE_C_HSDIR_GET ||
- circ->purpose == CIRCUIT_PURPOSE_S_HSDIR_POST ||
- circ->purpose == CIRCUIT_PURPOSE_HS_VANGUARDS ||
- circ->purpose == CIRCUIT_PURPOSE_C_MEASURE_TIMEOUT ||
- circ->purpose == CIRCUIT_PURPOSE_S_ESTABLISH_INTRO ||
- circ->purpose == CIRCUIT_PURPOSE_TESTING ||
- (circ->purpose >= CIRCUIT_PURPOSE_C_INTRODUCING &&
- circ->purpose <= CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED) ||
- circ->purpose == CIRCUIT_PURPOSE_S_CONNECT_REND) {
- log_info(LD_CIRC,
- "Closing circuit %"PRIu32
- " that has been unused for %ld msec.",
- TO_ORIGIN_CIRCUIT(circ)->global_identifier,
- tv_mdiff(&circ->timestamp_began, &now));
- circuit_mark_for_close(circ, END_CIRC_REASON_FINISHED);
- } else if (!TO_ORIGIN_CIRCUIT(circ)->is_ancient) {
-
- if (circ->purpose != CIRCUIT_PURPOSE_S_REND_JOINED &&
- circ->purpose != CIRCUIT_PURPOSE_S_INTRO) {
- log_notice(LD_CIRC,
- "Ancient non-dirty circuit %d is still around after "
- "%ld milliseconds. Purpose: %d (%s)",
- TO_ORIGIN_CIRCUIT(circ)->global_identifier,
- tv_mdiff(&circ->timestamp_began, &now),
- circ->purpose,
- circuit_purpose_to_string(circ->purpose));
- TO_ORIGIN_CIRCUIT(circ)->is_ancient = 1;
- }
- }
- }
- }
- } SMARTLIST_FOREACH_END(circ);
- }
- #define IDLE_ONE_HOP_CIRC_TIMEOUT 60
- void
- circuit_expire_old_circuits_serverside(time_t now)
- {
- or_circuit_t *or_circ;
- time_t cutoff = now - IDLE_ONE_HOP_CIRC_TIMEOUT;
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- if (circ->marked_for_close || CIRCUIT_IS_ORIGIN(circ))
- continue;
- or_circ = TO_OR_CIRCUIT(circ);
-
- if (or_circ->p_chan && channel_is_client(or_circ->p_chan) &&
- !circ->n_chan &&
- !or_circ->n_streams && !or_circ->resolving_streams &&
- !or_circ->rend_splice &&
- channel_when_last_xmit(or_circ->p_chan) <= cutoff) {
- log_info(LD_CIRC, "Closing circ_id %u (empty %d secs ago)",
- (unsigned)or_circ->p_circ_id,
- (int)(now - channel_when_last_xmit(or_circ->p_chan)));
- circuit_mark_for_close(circ, END_CIRC_REASON_FINISHED);
- }
- }
- SMARTLIST_FOREACH_END(circ);
- }
- #define NUM_PARALLEL_TESTING_CIRCS 4
- static int have_performed_bandwidth_test = 0;
- void
- reset_bandwidth_test(void)
- {
- have_performed_bandwidth_test = 0;
- }
- int
- circuit_enough_testing_circs(void)
- {
- int num = 0;
- if (have_performed_bandwidth_test)
- return 1;
- SMARTLIST_FOREACH_BEGIN(circuit_get_global_list(), circuit_t *, circ) {
- if (!circ->marked_for_close && CIRCUIT_IS_ORIGIN(circ) &&
- circ->purpose == CIRCUIT_PURPOSE_TESTING &&
- circ->state == CIRCUIT_STATE_OPEN)
- num++;
- }
- SMARTLIST_FOREACH_END(circ);
- return num >= NUM_PARALLEL_TESTING_CIRCS;
- }
- static void
- circuit_testing_opened(origin_circuit_t *circ)
- {
- if (have_performed_bandwidth_test ||
- !check_whether_orport_reachable(get_options())) {
-
- circuit_mark_for_close(TO_CIRCUIT(circ), END_CIRC_AT_ORIGIN);
- } else if (circuit_enough_testing_circs()) {
- router_perform_bandwidth_test(NUM_PARALLEL_TESTING_CIRCS, time(NULL));
- have_performed_bandwidth_test = 1;
- } else
- router_do_reachability_checks(1, 0);
- }
- static void
- circuit_testing_failed(origin_circuit_t *circ, int at_last_hop)
- {
- const or_options_t *options = get_options();
- if (server_mode(options) && check_whether_orport_reachable(options))
- return;
- log_info(LD_GENERAL,
- "Our testing circuit (to see if your ORPort is reachable) "
- "has failed. I'll try again later.");
-
- (void)circ;
- (void)at_last_hop;
- }
- void
- circuit_has_opened(origin_circuit_t *circ)
- {
- control_event_circuit_status(circ, CIRC_EVENT_BUILT, 0);
-
- circ->has_opened = 1;
- switch (TO_CIRCUIT(circ)->purpose) {
- case CIRCUIT_PURPOSE_C_ESTABLISH_REND:
- hs_client_circuit_has_opened(circ);
-
- connection_ap_attach_pending(1);
-
- break;
- case CIRCUIT_PURPOSE_C_INTRODUCING:
- hs_client_circuit_has_opened(circ);
- break;
- case CIRCUIT_PURPOSE_C_GENERAL:
- case CIRCUIT_PURPOSE_C_HSDIR_GET:
- case CIRCUIT_PURPOSE_S_HSDIR_POST:
-
- circuit_try_attaching_streams(circ);
- break;
- case CIRCUIT_PURPOSE_S_ESTABLISH_INTRO:
-
- hs_service_circuit_has_opened(circ);
- break;
- case CIRCUIT_PURPOSE_S_CONNECT_REND:
-
- hs_service_circuit_has_opened(circ);
- break;
- case CIRCUIT_PURPOSE_TESTING:
- circuit_testing_opened(circ);
- break;
-
- }
- }
- static int
- circuit_try_clearing_isolation_state(origin_circuit_t *circ)
- {
- if (
- circ->base_.state == CIRCUIT_STATE_OPEN &&
-
- circ->isolation_values_set &&
-
- !circ->isolation_any_streams_attached) {
-
- circuit_clear_isolation(circ);
- return 1;
- } else {
- return 0;
- }
- }
- void
- circuit_try_attaching_streams(origin_circuit_t *circ)
- {
-
- connection_ap_attach_pending(1);
-
- if (circuit_try_clearing_isolation_state(circ)) {
-
- connection_ap_attach_pending(1);
- }
- }
- void
- circuit_build_failed(origin_circuit_t *circ)
- {
- channel_t *n_chan = NULL;
-
- int failed_at_last_hop = 0;
-
- if (circuit_get_cpath_len(circ) < circ->build_state->desired_path_len) {
- static ratelim_t pathfail_limit = RATELIM_INIT(3600);
- log_fn_ratelim(&pathfail_limit, LOG_NOTICE, LD_CIRC,
- "Our circuit %u (id: %" PRIu32 ") died due to an invalid "
- "selected path, purpose %s. This may be a torrc "
- "configuration issue, or a bug.",
- TO_CIRCUIT(circ)->n_circ_id, circ->global_identifier,
- circuit_purpose_to_string(TO_CIRCUIT(circ)->purpose));
-
- if (TO_CIRCUIT(circ)->purpose == CIRCUIT_PURPOSE_S_CONNECT_REND)
- hs_circ_retry_service_rendezvous_point(circ);
-
- return;
- }
-
- if (circ->cpath &&
- circ->cpath->prev->state != CPATH_STATE_OPEN &&
- circ->cpath->prev->prev->state == CPATH_STATE_OPEN) {
- failed_at_last_hop = 1;
- }
-
- if (circ->cpath &&
- circ->cpath->state != CPATH_STATE_OPEN &&
- ! circ->base_.received_destroy) {
-
- const char *n_chan_ident = circ->cpath->extend_info->identity_digest;
- tor_assert(n_chan_ident);
- int already_marked = 0;
- if (circ->base_.n_chan) {
- n_chan = circ->base_.n_chan;
- if (n_chan->is_bad_for_new_circs) {
-
- already_marked = 1;
- }
- log_info(LD_OR,
- "Our circuit %u (id: %" PRIu32 ") failed to get a response "
- "from the first hop (%s). I'm going to try to rotate to a "
- "better connection.",
- TO_CIRCUIT(circ)->n_circ_id, circ->global_identifier,
- channel_get_canonical_remote_descr(n_chan));
- n_chan->is_bad_for_new_circs = 1;
- } else {
- log_info(LD_OR,
- "Our circuit %u (id: %" PRIu32 ") died before the first hop "
- "with no connection",
- TO_CIRCUIT(circ)->n_circ_id, circ->global_identifier);
- }
- if (!already_marked) {
-
- if (circ->guard_state)
- entry_guard_failed(&circ->guard_state);
-
- connection_ap_fail_onehop(n_chan_ident, circ->build_state);
- }
- }
- switch (circ->base_.purpose) {
- case CIRCUIT_PURPOSE_C_HSDIR_GET:
- case CIRCUIT_PURPOSE_S_HSDIR_POST:
- case CIRCUIT_PURPOSE_C_GENERAL:
-
- circuit_increment_failure_count();
- if (failed_at_last_hop) {
-
- circuit_discard_optional_exit_enclaves(circ->cpath->prev->extend_info);
- }
- break;
- case CIRCUIT_PURPOSE_TESTING:
- circuit_testing_failed(circ, failed_at_last_hop);
- break;
- case CIRCUIT_PURPOSE_S_ESTABLISH_INTRO:
-
- if (circ->base_.state != CIRCUIT_STATE_OPEN) {
- circuit_increment_failure_count();
- }
-
- break;
- case CIRCUIT_PURPOSE_C_INTRODUCING:
-
-
-
- break;
- case CIRCUIT_PURPOSE_C_ESTABLISH_REND:
-
- circuit_increment_failure_count();
-
- break;
- case CIRCUIT_PURPOSE_S_CONNECT_REND:
-
-
- log_info(LD_REND,
- "Couldn't connect to the client's chosen rend point %s "
- "(%s hop failed).",
- escaped(build_state_get_exit_nickname(circ->build_state)),
- failed_at_last_hop?"last":"non-last");
- hs_circ_retry_service_rendezvous_point(circ);
- break;
-
- }
- }
- static int n_circuit_failures = 0;
- static int did_circs_fail_last_period = 0;
- #define MAX_CIRCUIT_FAILURES 5
- origin_circuit_t *
- circuit_launch(uint8_t purpose, int flags)
- {
- return circuit_launch_by_extend_info(purpose, NULL, flags);
- }
- static int
- have_enough_path_info(int need_exit)
- {
- if (need_exit)
- return router_have_consensus_path() == CONSENSUS_PATH_EXIT;
- else
- return router_have_consensus_path() != CONSENSUS_PATH_UNKNOWN;
- }
- int
- circuit_purpose_is_hidden_service(uint8_t purpose)
- {
- if (purpose == CIRCUIT_PURPOSE_HS_VANGUARDS) {
- return 1;
- }
-
- if (purpose >= CIRCUIT_PURPOSE_C_HS_MIN_ &&
- purpose <= CIRCUIT_PURPOSE_C_HS_MAX_) {
- return 1;
- }
-
- if (purpose >= CIRCUIT_PURPOSE_S_HS_MIN_ &&
- purpose <= CIRCUIT_PURPOSE_S_HS_MAX_) {
- return 1;
- }
- return 0;
- }
- int
- circuit_should_use_vanguards(uint8_t purpose)
- {
- const or_options_t *options = get_options();
-
- if (!circuit_purpose_is_hidden_service(purpose))
- return 0;
-
- if (options->HSLayer2Nodes || options->HSLayer3Nodes)
- return 1;
- return 0;
- }
- static int
- circuit_should_cannibalize_to_build(uint8_t purpose_to_build,
- int has_extend_info,
- int onehop_tunnel)
- {
-
- if (onehop_tunnel) {
- return 0;
- }
-
- if (purpose_to_build == CIRCUIT_PURPOSE_C_GENERAL && !has_extend_info) {
- return 0;
- }
-
- if (purpose_to_build == CIRCUIT_PURPOSE_TESTING ||
- purpose_to_build == CIRCUIT_PURPOSE_HS_VANGUARDS) {
- return 0;
- }
-
- if (circuit_should_use_vanguards(purpose_to_build) &&
- purpose_to_build == CIRCUIT_PURPOSE_S_ESTABLISH_INTRO) {
- return 0;
- }
- return 1;
- }
- origin_circuit_t *
- circuit_launch_by_extend_info(uint8_t purpose,
- extend_info_t *extend_info,
- int flags)
- {
- origin_circuit_t *circ;
- int onehop_tunnel = (flags & CIRCLAUNCH_ONEHOP_TUNNEL) != 0;
- int have_path = have_enough_path_info(! (flags & CIRCLAUNCH_IS_INTERNAL) );
-
- if (purpose == CIRCUIT_PURPOSE_S_CONNECT_REND) {
- hs_stats_note_service_rendezvous_launch();
- }
- if (!onehop_tunnel && (!router_have_minimum_dir_info() || !have_path)) {
- log_debug(LD_CIRC,"Haven't %s yet; canceling "
- "circuit launch.",
- !router_have_minimum_dir_info() ?
- "fetched enough directory info" :
- "received a consensus with exits");
- return NULL;
- }
-
- if (circuit_should_cannibalize_to_build(purpose,
- extend_info != NULL,
- onehop_tunnel)) {
-
-
- circ = circuit_find_to_cannibalize(purpose, extend_info, flags);
- if (circ) {
- uint8_t old_purpose = circ->base_.purpose;
- struct timeval old_timestamp_began = circ->base_.timestamp_began;
- log_info(LD_CIRC, "Cannibalizing circ %u (id: %" PRIu32 ") for "
- "purpose %d (%s)",
- TO_CIRCUIT(circ)->n_circ_id, circ->global_identifier, purpose,
- circuit_purpose_to_string(purpose));
- if ((purpose == CIRCUIT_PURPOSE_S_CONNECT_REND ||
- purpose == CIRCUIT_PURPOSE_C_INTRODUCING) &&
- circ->path_state == PATH_STATE_BUILD_SUCCEEDED) {
-
-
- pathbias_check_close(circ, END_CIRC_REASON_FINISHED);
- }
- circuit_change_purpose(TO_CIRCUIT(circ), purpose);
-
- tor_gettimeofday(&circ->base_.timestamp_began);
- control_event_circuit_cannibalized(circ, old_purpose,
- &old_timestamp_began);
- switch (purpose) {
- case CIRCUIT_PURPOSE_C_ESTABLISH_REND:
-
- break;
- case CIRCUIT_PURPOSE_C_INTRODUCING:
- case CIRCUIT_PURPOSE_S_CONNECT_REND:
- case CIRCUIT_PURPOSE_C_GENERAL:
- case CIRCUIT_PURPOSE_S_HSDIR_POST:
- case CIRCUIT_PURPOSE_C_HSDIR_GET:
- case CIRCUIT_PURPOSE_S_ESTABLISH_INTRO:
-
- tor_assert(extend_info);
- if (circuit_extend_to_new_exit(circ, extend_info) < 0)
- return NULL;
- break;
- default:
- log_warn(LD_BUG,
- "unexpected purpose %d when cannibalizing a circ.",
- purpose);
- tor_fragile_assert();
- return NULL;
- }
- return circ;
- }
- }
- if (did_circs_fail_last_period &&
- n_circuit_failures > MAX_CIRCUIT_FAILURES) {
-
- return NULL;
- }
-
- return circuit_establish_circuit(purpose, extend_info, flags);
- }
- static void
- circuit_increment_failure_count(void)
- {
- ++n_circuit_failures;
- log_debug(LD_CIRC,"n_circuit_failures now %d.",n_circuit_failures);
- }
- void
- circuit_reset_failure_count(int timeout)
- {
- if (timeout && n_circuit_failures > MAX_CIRCUIT_FAILURES)
- did_circs_fail_last_period = 1;
- else
- did_circs_fail_last_period = 0;
- n_circuit_failures = 0;
- }
- static int
- circuit_get_open_circ_or_launch(entry_connection_t *conn,
- uint8_t desired_circuit_purpose,
- origin_circuit_t **circp)
- {
- origin_circuit_t *circ;
- int check_exit_policy;
- int need_uptime, need_internal;
- int want_onehop;
- const or_options_t *options = get_options();
- tor_assert(conn);
- tor_assert(circp);
- if (ENTRY_TO_CONN(conn)->state != AP_CONN_STATE_CIRCUIT_WAIT) {
- connection_t *c = ENTRY_TO_CONN(conn);
- log_err(LD_BUG, "Connection state mismatch: wanted "
- "AP_CONN_STATE_CIRCUIT_WAIT, but got %d (%s)",
- c->state, conn_state_to_string(c->type, c->state));
- }
- tor_assert(ENTRY_TO_CONN(conn)->state == AP_CONN_STATE_CIRCUIT_WAIT);
-
- check_exit_policy =
- conn->socks_request->command == SOCKS_COMMAND_CONNECT &&
- !conn->use_begindir &&
- !connection_edge_is_rendezvous_stream(ENTRY_TO_EDGE_CONN(conn));
-
- want_onehop = conn->want_onehop;
-
- need_uptime = !conn->want_onehop && !conn->use_begindir &&
- smartlist_contains_int_as_string(options->LongLivedPorts,
- conn->socks_request->port);
-
- if (desired_circuit_purpose != CIRCUIT_PURPOSE_C_GENERAL)
- need_internal = 1;
- else if (conn->use_begindir || conn->want_onehop)
- need_internal = 1;
- else
- need_internal = 0;
-
- circ = circuit_get_best(conn, 1 ,
- desired_circuit_purpose,
- need_uptime, need_internal);
- if (circ) {
-
- *circp = circ;
- return 1;
- }
-
-
- int have_path = have_enough_path_info(!need_internal);
- if (!want_onehop && (!router_have_minimum_dir_info() || !have_path)) {
-
- if (!connection_get_by_type(CONN_TYPE_DIR)) {
- int severity = LOG_NOTICE;
-
-
- if (entry_list_is_constrained(options)) {
-
- int rv = guards_retry_optimistic(options);
- tor_assert_nonfatal_once(rv);
- log_fn(severity, LD_APP|LD_DIR,
- "Application request when we haven't %s. "
- "Optimistically trying known %s again.",
- !router_have_minimum_dir_info() ?
- "used client functionality lately" :
- "received a consensus with exits",
- options->UseBridges ? "bridges" : "entrynodes");
- } else {
-
- tor_assert_nonfatal(!options->UseBridges);
- tor_assert_nonfatal(!options->EntryNodes);
-
- log_fn(severity, LD_APP|LD_DIR,
- "Application request when we haven't %s. "
- "Optimistically trying directory fetches again.",
- !router_have_minimum_dir_info() ?
- "used client functionality lately" :
- "received a consensus with exits");
- routerlist_retry_directory_downloads(time(NULL));
- }
- }
-
- return 0;
- }
-
- if (check_exit_policy) {
- if (!conn->chosen_exit_name) {
- struct in_addr in;
- tor_addr_t addr, *addrp=NULL;
- if (tor_inet_aton(conn->socks_request->address, &in)) {
- tor_addr_from_in(&addr, &in);
- addrp = &addr;
- }
- if (router_exit_policy_all_nodes_reject(addrp,
- conn->socks_request->port,
- need_uptime)) {
- log_notice(LD_APP,
- "No Tor server allows exit to %s:%d. Rejecting.",
- safe_str_client(conn->socks_request->address),
- conn->socks_request->port);
- return -1;
- }
- } else {
-
- const node_t *node = node_get_by_nickname(conn->chosen_exit_name, 0);
- int opt = conn->chosen_exit_optional;
- if (node && !connection_ap_can_use_exit(conn, node)) {
- log_fn(opt ? LOG_INFO : LOG_WARN, LD_APP,
- "Requested exit point '%s' is excluded or "
- "would refuse request. %s.",
- conn->chosen_exit_name, opt ? "Trying others" : "Closing");
- if (opt) {
- conn->chosen_exit_optional = 0;
- tor_free(conn->chosen_exit_name);
-
- return circuit_get_open_circ_or_launch(conn,
- desired_circuit_purpose,
- circp);
- }
- return -1;
- }
- }
- }
-
- circ = circuit_get_best(conn, 0 ,
- desired_circuit_purpose,
- need_uptime, need_internal);
- if (circ)
- log_debug(LD_CIRC, "one on the way!");
- if (!circ) {
-
-
- extend_info_t *extend_info=NULL;
- const int n_pending = count_pending_general_client_circuits();
-
- if (n_pending >= options->MaxClientCircuitsPending) {
- static ratelim_t delay_limit = RATELIM_INIT(10*60);
- char *m;
- if ((m = rate_limit_log(&delay_limit, approx_time()))) {
- log_notice(LD_APP, "We'd like to launch a circuit to handle a "
- "connection, but we already have %d general-purpose client "
- "circuits pending. Waiting until some finish.%s",
- n_pending, m);
- tor_free(m);
- }
- return 0;
- }
-
- if (desired_circuit_purpose == CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT) {
- const edge_connection_t *edge_conn = ENTRY_TO_EDGE_CONN(conn);
-
- extend_info = hs_client_get_random_intro_from_edge(edge_conn);
- if (!extend_info) {
- log_info(LD_REND, "No intro points: re-fetching service descriptor.");
- if (edge_conn->rend_data) {
- rend_client_refetch_v2_renddesc(edge_conn->rend_data);
- } else {
- hs_client_refetch_hsdesc(&edge_conn->hs_ident->identity_pk);
- }
- connection_ap_mark_as_waiting_for_renddesc(conn);
- return 0;
- }
- log_info(LD_REND,"Chose %s as intro point for '%s'.",
- extend_info_describe(extend_info),
- (edge_conn->rend_data) ?
- safe_str_client(rend_data_get_address(edge_conn->rend_data)) :
- "service");
- }
-
- if (desired_circuit_purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- desired_circuit_purpose == CIRCUIT_PURPOSE_S_HSDIR_POST ||
- desired_circuit_purpose == CIRCUIT_PURPOSE_C_HSDIR_GET) {
- if (conn->chosen_exit_name) {
- const node_t *r;
- int opt = conn->chosen_exit_optional;
- r = node_get_by_nickname(conn->chosen_exit_name, 0);
- if (r && node_has_preferred_descriptor(r, conn->want_onehop ? 1 : 0)) {
-
- extend_info = extend_info_from_node(r, conn->want_onehop ? 1 : 0);
- if (!extend_info) {
- log_warn(LD_CIRC,"Could not make a one-hop connection to %s. "
- "Discarding this circuit.", conn->chosen_exit_name);
- return -1;
- }
- } else {
- log_debug(LD_DIR, "considering %d, %s",
- want_onehop, conn->chosen_exit_name);
- if (want_onehop && conn->chosen_exit_name[0] == '$') {
-
-
- char digest[DIGEST_LEN];
- char *hexdigest = conn->chosen_exit_name+1;
- tor_addr_t addr;
- if (strlen(hexdigest) < HEX_DIGEST_LEN ||
- base16_decode(digest,DIGEST_LEN,
- hexdigest,HEX_DIGEST_LEN) != DIGEST_LEN) {
- log_info(LD_DIR, "Broken exit digest on tunnel conn. Closing.");
- return -1;
- }
- if (tor_addr_parse(&addr, conn->socks_request->address) < 0) {
- log_info(LD_DIR, "Broken address %s on tunnel conn. Closing.",
- escaped_safe_str_client(conn->socks_request->address));
- return -1;
- }
-
- extend_info = extend_info_new(conn->chosen_exit_name+1,
- digest,
- NULL,
- NULL, NULL,
- &addr, conn->socks_request->port);
- } else {
-
- log_fn(opt ? LOG_INFO : LOG_WARN, LD_APP,
- "Requested exit point '%s' is not known. %s.",
- conn->chosen_exit_name, opt ? "Trying others" : "Closing");
- if (opt) {
- conn->chosen_exit_optional = 0;
- tor_free(conn->chosen_exit_name);
-
- return circuit_get_open_circ_or_launch(conn,
- desired_circuit_purpose,
- circp);
- }
- return -1;
- }
- }
- }
- }
-
- uint8_t new_circ_purpose;
- if (desired_circuit_purpose == CIRCUIT_PURPOSE_C_REND_JOINED)
- new_circ_purpose = CIRCUIT_PURPOSE_C_ESTABLISH_REND;
- else if (desired_circuit_purpose == CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT)
- new_circ_purpose = CIRCUIT_PURPOSE_C_INTRODUCING;
- else
- new_circ_purpose = desired_circuit_purpose;
-
- {
- int flags = CIRCLAUNCH_NEED_CAPACITY;
- if (want_onehop) flags |= CIRCLAUNCH_ONEHOP_TUNNEL;
- if (need_uptime) flags |= CIRCLAUNCH_NEED_UPTIME;
- if (need_internal) flags |= CIRCLAUNCH_IS_INTERNAL;
-
- if (desired_circuit_purpose == CIRCUIT_PURPOSE_C_REND_JOINED &&
- new_circ_purpose == CIRCUIT_PURPOSE_C_ESTABLISH_REND &&
- ENTRY_TO_EDGE_CONN(conn)->hs_ident) {
- flags |= CIRCLAUNCH_IS_V3_RP;
- log_info(LD_GENERAL, "Getting rendezvous circuit to v3 service!");
- }
- circ = circuit_launch_by_extend_info(new_circ_purpose, extend_info,
- flags);
- }
- extend_info_free(extend_info);
-
- if (desired_circuit_purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- desired_circuit_purpose == CIRCUIT_PURPOSE_C_HSDIR_GET ||
- desired_circuit_purpose == CIRCUIT_PURPOSE_S_HSDIR_POST) {
-
- if (conn->num_circuits_launched < NUM_CIRCUITS_LAUNCHED_THRESHOLD &&
- ++conn->num_circuits_launched == NUM_CIRCUITS_LAUNCHED_THRESHOLD)
- log_info(LD_CIRC, "The application request to %s:%d has launched "
- "%d circuits without finding one it likes.",
- escaped_safe_str_client(conn->socks_request->address),
- conn->socks_request->port,
- conn->num_circuits_launched);
- } else {
-
- rep_hist_note_used_internal(time(NULL), need_uptime, 1);
- if (circ) {
- const edge_connection_t *edge_conn = ENTRY_TO_EDGE_CONN(conn);
- if (edge_conn->rend_data) {
-
- circ->rend_data = rend_data_dup(edge_conn->rend_data);
- } else if (edge_conn->hs_ident) {
- circ->hs_ident =
- hs_ident_circuit_new(&edge_conn->hs_ident->identity_pk,
- HS_IDENT_CIRCUIT_INTRO);
- }
- if (circ->base_.purpose == CIRCUIT_PURPOSE_C_ESTABLISH_REND &&
- circ->base_.state == CIRCUIT_STATE_OPEN)
- circuit_has_opened(circ);
- }
- }
- }
-
- if (circ) {
-
- connection_edge_update_circuit_isolation(conn, circ, 0);
- } else {
- log_info(LD_APP,
- "No safe circuit (purpose %d) ready for edge "
- "connection; delaying.",
- desired_circuit_purpose);
- }
- *circp = circ;
- return 0;
- }
- static int
- cpath_is_on_circuit(origin_circuit_t *circ, crypt_path_t *crypt_path)
- {
- crypt_path_t *cpath, *cpath_next = NULL;
- for (cpath = circ->cpath; cpath_next != circ->cpath; cpath = cpath_next) {
- cpath_next = cpath->next;
- if (crypt_path == cpath)
- return 1;
- }
- return 0;
- }
- static int
- optimistic_data_enabled(void)
- {
- const or_options_t *options = get_options();
- if (options->OptimisticData < 0) {
-
- const int32_t enabled =
- networkstatus_get_param(NULL, "UseOptimisticData", 1, 0, 1);
- return (int)enabled;
- }
- return options->OptimisticData;
- }
- static void
- link_apconn_to_circ(entry_connection_t *apconn, origin_circuit_t *circ,
- crypt_path_t *cpath)
- {
- const node_t *exitnode = NULL;
-
- log_debug(LD_APP|LD_CIRC, "attaching new conn to circ. n_circ_id %u.",
- (unsigned)circ->base_.n_circ_id);
-
- ENTRY_TO_CONN(apconn)->timestamp_last_read_allowed = time(NULL);
- ENTRY_TO_EDGE_CONN(apconn)->next_stream = circ->p_streams;
- ENTRY_TO_EDGE_CONN(apconn)->on_circuit = TO_CIRCUIT(circ);
-
- circ->p_streams = ENTRY_TO_EDGE_CONN(apconn);
- if (connection_edge_is_rendezvous_stream(ENTRY_TO_EDGE_CONN(apconn))) {
-
- hs_client_note_connection_attempt_succeeded(ENTRY_TO_EDGE_CONN(apconn));
- }
- if (cpath) {
- tor_assert(cpath_is_on_circuit(circ, cpath));
- } else {
-
- tor_assert(circ->cpath);
- tor_assert(circ->cpath->prev);
- tor_assert(circ->cpath->prev->state == CPATH_STATE_OPEN);
- cpath = circ->cpath->prev;
- }
- ENTRY_TO_EDGE_CONN(apconn)->cpath_layer = cpath;
- circ->isolation_any_streams_attached = 1;
- connection_edge_update_circuit_isolation(apconn, circ, 0);
-
- if (cpath->extend_info)
- exitnode = node_get_by_id(cpath->extend_info->identity_digest);
-
- if (optimistic_data_enabled() &&
- (circ->base_.purpose == CIRCUIT_PURPOSE_C_GENERAL ||
- circ->base_.purpose == CIRCUIT_PURPOSE_C_HSDIR_GET ||
- circ->base_.purpose == CIRCUIT_PURPOSE_S_HSDIR_POST ||
- circ->base_.purpose == CIRCUIT_PURPOSE_C_REND_JOINED))
- apconn->may_use_optimistic_data = 1;
- else
- apconn->may_use_optimistic_data = 0;
- log_info(LD_APP, "Looks like completed circuit to %s %s allow "
- "optimistic data for connection to %s",
- circ->base_.purpose == CIRCUIT_PURPOSE_C_GENERAL ?
-
- safe_str_client(node_describe(exitnode)) :
- "hidden service",
- apconn->may_use_optimistic_data ? "does" : "doesn't",
- safe_str_client(apconn->socks_request->address));
- }
- int
- hostname_in_track_host_exits(const or_options_t *options, const char *address)
- {
- if (!options->TrackHostExits)
- return 0;
- SMARTLIST_FOREACH_BEGIN(options->TrackHostExits, const char *, cp) {
- if (cp[0] == '.') {
- if (cp[1] == '\0' ||
- !strcasecmpend(address, cp) ||
- !strcasecmp(address, &cp[1]))
- return 1;
- } else if (strcasecmp(cp, address) == 0) {
- return 1;
- }
- } SMARTLIST_FOREACH_END(cp);
- return 0;
- }
- static void
- consider_recording_trackhost(const entry_connection_t *conn,
- const origin_circuit_t *circ)
- {
- const or_options_t *options = get_options();
- char *new_address = NULL;
- char fp[HEX_DIGEST_LEN+1];
-
-
- if (!options->TrackHostExits ||
- addressmap_have_mapping(conn->socks_request->address,
- options->TrackHostExitsExpire))
- return;
- if (!hostname_in_track_host_exits(options, conn->socks_request->address) ||
- !circ->build_state->chosen_exit)
- return;
-
- base16_encode(fp, sizeof(fp),
- circ->build_state->chosen_exit->identity_digest, DIGEST_LEN);
-
- tor_asprintf(&new_address, "%s.%s.exit",
- conn->socks_request->address, fp);
- addressmap_register(conn->socks_request->address, new_address,
- time(NULL) + options->TrackHostExitsExpire,
- ADDRMAPSRC_TRACKEXIT, 0, 0);
- }
- int
- connection_ap_handshake_attach_chosen_circuit(entry_connection_t *conn,
- origin_circuit_t *circ,
- crypt_path_t *cpath)
- {
- connection_t *base_conn = ENTRY_TO_CONN(conn);
- tor_assert(conn);
- tor_assert(base_conn->state == AP_CONN_STATE_CIRCUIT_WAIT ||
- base_conn->state == AP_CONN_STATE_CONTROLLER_WAIT);
- tor_assert(conn->socks_request);
- tor_assert(circ);
- tor_assert(circ->base_.state == CIRCUIT_STATE_OPEN);
- base_conn->state = AP_CONN_STATE_CIRCUIT_WAIT;
- if (!circ->base_.timestamp_dirty ||
- ((conn->entry_cfg.isolation_flags & ISO_SOCKSAUTH) &&
- (conn->entry_cfg.socks_iso_keep_alive) &&
- (conn->socks_request->usernamelen ||
- conn->socks_request->passwordlen))) {
-
- circ->base_.timestamp_dirty = approx_time();
- }
- pathbias_count_use_attempt(circ);
-
- link_apconn_to_circ(conn, circ, cpath);
- tor_assert(conn->socks_request);
- if (conn->socks_request->command == SOCKS_COMMAND_CONNECT) {
- if (!conn->use_begindir)
- consider_recording_trackhost(conn, circ);
- if (connection_ap_handshake_send_begin(conn) < 0)
- return -1;
- } else {
- if (connection_ap_handshake_send_resolve(conn) < 0)
- return -1;
- }
- return 1;
- }
- static int
- connection_ap_get_nonrend_circ_purpose(const entry_connection_t *conn)
- {
- const connection_t *base_conn = ENTRY_TO_CONN(conn);
- tor_assert_nonfatal(!connection_edge_is_rendezvous_stream(
- ENTRY_TO_EDGE_CONN(conn)));
- if (base_conn->linked_conn &&
- base_conn->linked_conn->type == CONN_TYPE_DIR) {
-
- if (base_conn->linked_conn->purpose == DIR_PURPOSE_UPLOAD_RENDDESC_V2 ||
- base_conn->linked_conn->purpose == DIR_PURPOSE_UPLOAD_HSDESC) {
- return CIRCUIT_PURPOSE_S_HSDIR_POST;
- } else if (base_conn->linked_conn->purpose
- == DIR_PURPOSE_FETCH_RENDDESC_V2 ||
- base_conn->linked_conn->purpose
- == DIR_PURPOSE_FETCH_HSDESC) {
- return CIRCUIT_PURPOSE_C_HSDIR_GET;
- }
- }
-
- return CIRCUIT_PURPOSE_C_GENERAL;
- }
- int
- connection_ap_handshake_attach_circuit(entry_connection_t *conn)
- {
- connection_t *base_conn = ENTRY_TO_CONN(conn);
- int retval;
- int conn_age;
- int want_onehop;
- tor_assert(conn);
- tor_assert(base_conn->state == AP_CONN_STATE_CIRCUIT_WAIT);
- tor_assert(conn->socks_request);
- want_onehop = conn->want_onehop;
- conn_age = (int)(time(NULL) - base_conn->timestamp_created);
-
- if (conn_age >= get_options()->SocksTimeout) {
- int severity = (tor_addr_is_null(&base_conn->addr) && !base_conn->port) ?
- LOG_INFO : LOG_NOTICE;
- log_fn(severity, LD_APP,
- "Tried for %d seconds to get a connection to %s:%d. Giving up.",
- conn_age, safe_str_client(conn->socks_request->address),
- conn->socks_request->port);
- return -1;
- }
-
- if (!connection_edge_is_rendezvous_stream(ENTRY_TO_EDGE_CONN(conn))) {
-
- origin_circuit_t *circ=NULL;
-
- if (base_conn->linked_conn &&
- base_conn->linked_conn->type == CONN_TYPE_DIR &&
- base_conn->linked_conn->purpose == DIR_PURPOSE_FETCH_CONSENSUS) {
-
- if (networkstatus_consensus_is_already_downloading(
- TO_DIR_CONN(base_conn->linked_conn)->requested_resource)) {
-
- log_info(LD_DIR, "Closing extra consensus fetch (to %s) since one "
- "is already downloading.", base_conn->linked_conn->address);
- return -1;
- }
- }
-
- if (conn->chosen_exit_name) {
- const node_t *node = node_get_by_nickname(conn->chosen_exit_name, 0);
- int opt = conn->chosen_exit_optional;
- if (!node && !want_onehop) {
-
- log_fn(opt ? LOG_INFO : LOG_WARN, LD_APP,
- "Requested exit point '%s' is not known. %s.",
- conn->chosen_exit_name, opt ? "Trying others" : "Closing");
- if (opt) {
-
- conn->chosen_exit_optional = 0;
- tor_free(conn->chosen_exit_name);
- return 0;
- }
- return -1;
- }
- if (node && !connection_ap_can_use_exit(conn, node)) {
- log_fn(opt ? LOG_INFO : LOG_WARN, LD_APP,
- "Requested exit point '%s' is excluded or "
- "would refuse request. %s.",
- conn->chosen_exit_name, opt ? "Trying others" : "Closing");
- if (opt) {
-
- conn->chosen_exit_optional = 0;
- tor_free(conn->chosen_exit_name);
- return 0;
- }
- return -1;
- }
- }
-
- retval = circuit_get_open_circ_or_launch(conn,
- connection_ap_get_nonrend_circ_purpose(conn),
- &circ);
- if (retval < 1) {
-
- return retval;
- }
- log_debug(LD_APP|LD_CIRC,
- "Attaching apconn to circ %u (stream %d sec old).",
- (unsigned)circ->base_.n_circ_id, conn_age);
-
- circuit_log_path(LOG_INFO,LD_APP|LD_CIRC,circ);
-
- return connection_ap_handshake_attach_chosen_circuit(conn, circ, NULL);
- } else {
- origin_circuit_t *rendcirc=NULL, *introcirc=NULL;
- tor_assert(!ENTRY_TO_EDGE_CONN(conn)->cpath_layer);
-
- retval = circuit_get_open_circ_or_launch(
- conn, CIRCUIT_PURPOSE_C_REND_JOINED, &rendcirc);
- if (retval < 0) return -1;
- if (retval > 0) {
- tor_assert(rendcirc);
-
- log_info(LD_REND,
- "rend joined circ %u (id: %" PRIu32 ") already here. "
- "Attaching. (stream %d sec old)",
- (unsigned) TO_CIRCUIT(rendcirc)->n_circ_id,
- rendcirc->global_identifier, conn_age);
-
- rendcirc->base_.timestamp_dirty = time(NULL);
-
- pathbias_count_use_attempt(rendcirc);
- link_apconn_to_circ(conn, rendcirc, NULL);
- if (connection_ap_handshake_send_begin(conn) < 0)
- return 0;
- return 1;
- }
-
- if (ENTRY_TO_CONN(conn)->state != AP_CONN_STATE_CIRCUIT_WAIT) {
- log_info(LD_REND, "This connection is no longer ready to attach; its "
- "state changed."
- "(We probably have to re-fetch its descriptor.)");
- return 0;
- }
- if (rendcirc && (rendcirc->base_.purpose ==
- CIRCUIT_PURPOSE_C_REND_READY_INTRO_ACKED)) {
- log_info(LD_REND,
- "pending-join circ %u (id: %" PRIu32 ") already here, with "
- "intro ack. Stalling. (stream %d sec old)",
- (unsigned) TO_CIRCUIT(rendcirc)->n_circ_id,
- rendcirc->global_identifier, conn_age);
- return 0;
- }
-
- retval = circuit_get_open_circ_or_launch(
- conn, CIRCUIT_PURPOSE_C_INTRODUCE_ACK_WAIT, &introcirc);
- if (retval < 0) return -1;
- if (retval > 0) {
-
- tor_assert(introcirc);
- log_info(LD_REND, "Intro circ %u (id: %" PRIu32 ") present and "
- "awaiting ACK. Rend circuit %u (id: %" PRIu32 "). "
- "Stalling. (stream %d sec old)",
- (unsigned) TO_CIRCUIT(introcirc)->n_circ_id,
- introcirc->global_identifier,
- rendcirc ? (unsigned) TO_CIRCUIT(rendcirc)->n_circ_id : 0,
- rendcirc ? rendcirc->global_identifier : 0,
- conn_age);
- return 0;
- }
-
- if (rendcirc && introcirc &&
- rendcirc->base_.purpose == CIRCUIT_PURPOSE_C_REND_READY) {
- log_info(LD_REND,
- "ready rend circ %u (id: %" PRIu32 ") already here. No"
- "intro-ack yet on intro %u (id: %" PRIu32 "). "
- "(stream %d sec old)",
- (unsigned) TO_CIRCUIT(rendcirc)->n_circ_id,
- rendcirc->global_identifier,
- (unsigned) TO_CIRCUIT(introcirc)->n_circ_id,
- introcirc->global_identifier, conn_age);
- tor_assert(introcirc->base_.purpose == CIRCUIT_PURPOSE_C_INTRODUCING);
- if (introcirc->base_.state == CIRCUIT_STATE_OPEN) {
- int ret;
- log_info(LD_REND, "Found open intro circ %u (id: %" PRIu32 "). "
- "Rend circuit %u (id: %" PRIu32 "); Sending "
- "introduction. (stream %d sec old)",
- (unsigned) TO_CIRCUIT(introcirc)->n_circ_id,
- introcirc->global_identifier,
- (unsigned) TO_CIRCUIT(rendcirc)->n_circ_id,
- rendcirc->global_identifier, conn_age);
- ret = hs_client_send_introduce1(introcirc, rendcirc);
- switch (ret) {
- case 0:
- rendcirc->base_.timestamp_dirty = time(NULL);
- introcirc->base_.timestamp_dirty = time(NULL);
- pathbias_count_use_attempt(introcirc);
- pathbias_count_use_attempt(rendcirc);
- assert_circuit_ok(TO_CIRCUIT(rendcirc));
- assert_circuit_ok(TO_CIRCUIT(introcirc));
- return 0;
- case -1:
- return 0;
- case -2:
- return -1;
- default:
- tor_fragile_assert();
- return -1;
- }
- }
- }
- log_info(LD_REND, "Intro %u (id: %" PRIu32 ") and rend circuit %u "
- "(id: %" PRIu32 ") circuits are not both ready. "
- "Stalling conn. (%d sec old)",
- introcirc ? (unsigned) TO_CIRCUIT(introcirc)->n_circ_id : 0,
- introcirc ? introcirc->global_identifier : 0,
- rendcirc ? (unsigned) TO_CIRCUIT(rendcirc)->n_circ_id : 0,
- rendcirc ? rendcirc->global_identifier : 0, conn_age);
- return 0;
- }
- }
- void
- circuit_change_purpose(circuit_t *circ, uint8_t new_purpose)
- {
- uint8_t old_purpose;
-
- tor_assert(!!(CIRCUIT_IS_ORIGIN(circ)) ==
- !!(CIRCUIT_PURPOSE_IS_ORIGIN(new_purpose)));
- if (circ->purpose == new_purpose) return;
- if (CIRCUIT_IS_ORIGIN(circ)) {
- char old_purpose_desc[80] = "";
- strncpy(old_purpose_desc, circuit_purpose_to_string(circ->purpose), 80-1);
- old_purpose_desc[80-1] = '\0';
- log_debug(LD_CIRC,
- "changing purpose of origin circ %d "
- "from \"%s\" (%d) to \"%s\" (%d)",
- TO_ORIGIN_CIRCUIT(circ)->global_identifier,
- old_purpose_desc,
- circ->purpose,
- circuit_purpose_to_string(new_purpose),
- new_purpose);
-
- if (circuit_purpose_is_hidden_service(circ->purpose) &&
- !circuit_purpose_is_hidden_service(new_purpose)) {
- hs_circ_cleanup(circ);
- }
- }
- old_purpose = circ->purpose;
- circ->purpose = new_purpose;
- if (CIRCUIT_IS_ORIGIN(circ)) {
- control_event_circuit_purpose_changed(TO_ORIGIN_CIRCUIT(circ),
- old_purpose);
- }
- }
- void
- mark_circuit_unusable_for_new_conns(origin_circuit_t *circ)
- {
- const or_options_t *options = get_options();
- tor_assert(circ);
-
- if (! circ->base_.timestamp_dirty)
- circ->base_.timestamp_dirty = approx_time();
- if (options->MaxCircuitDirtiness >= circ->base_.timestamp_dirty)
- circ->base_.timestamp_dirty = 1;
- else
- circ->base_.timestamp_dirty -= options->MaxCircuitDirtiness;
- circ->unusable_for_new_conns = 1;
- }
- void
- circuit_sent_valid_data(origin_circuit_t *circ, uint16_t relay_body_len)
- {
- if (!circ) return;
- tor_assert_nonfatal(relay_body_len <= RELAY_PAYLOAD_SIZE);
- circ->n_delivered_written_circ_bw =
- tor_add_u32_nowrap(circ->n_delivered_written_circ_bw, relay_body_len);
- circ->n_overhead_written_circ_bw =
- tor_add_u32_nowrap(circ->n_overhead_written_circ_bw,
- RELAY_PAYLOAD_SIZE-relay_body_len);
- }
- void
- circuit_read_valid_data(origin_circuit_t *circ, uint16_t relay_body_len)
- {
- if (!circ) return;
- tor_assert_nonfatal(relay_body_len <= RELAY_PAYLOAD_SIZE);
- circ->n_delivered_read_circ_bw =
- tor_add_u32_nowrap(circ->n_delivered_read_circ_bw, relay_body_len);
- circ->n_overhead_read_circ_bw =
- tor_add_u32_nowrap(circ->n_overhead_read_circ_bw,
- RELAY_PAYLOAD_SIZE-relay_body_len);
- }
|