"Fossies" - the Fresh Open Source Software Archive

Member "tor-0.4.1.6/src/feature/relay/selftest.c" (10 Jun 2019, 11136 Bytes) of package /linux/misc/tor-0.4.1.6.tar.gz:


As a special service "Fossies" has tried to format the requested source page into HTML format using (guessed) C and C++ source code syntax highlighting (style: standard) with prefixed line numbers and code folding option. Alternatively you can here view or download the uninterpreted source code file. For more information about "selftest.c" see the Fossies "Dox" file reference documentation and the last Fossies "Diffs" side-by-side code changes report: 0.4.0.5_vs_0.4.1.5.

    1 /* Copyright (c) 2001 Matej Pfajfar.
    2  * Copyright (c) 2001-2004, Roger Dingledine.
    3  * Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
    4  * Copyright (c) 2007-2019, The Tor Project, Inc. */
    5 /* See LICENSE for licensing information */
    6 
    7 /**
    8  * \file selftest.c
    9  * \brief Relay self-testing
   10  *
   11  * Relays need to make sure that their own ports are reasonable, and estimate
   12  * their own bandwidth, before publishing.
   13  */
   14 
   15 #define SELFTEST_PRIVATE
   16 
   17 #include "core/or/or.h"
   18 
   19 #include "app/config/config.h"
   20 #include "core/mainloop/connection.h"
   21 #include "core/mainloop/mainloop.h"
   22 #include "core/mainloop/netstatus.h"
   23 #include "core/or/circuitbuild.h"
   24 #include "core/or/circuitlist.h"
   25 #include "core/or/circuituse.h"
   26 #include "core/or/crypt_path_st.h"
   27 #include "core/or/origin_circuit_st.h"
   28 #include "core/or/relay.h"
   29 #include "feature/control/control_events.h"
   30 #include "feature/dirclient/dirclient.h"
   31 #include "feature/dircommon/directory.h"
   32 #include "feature/nodelist/authority_cert_st.h"
   33 #include "feature/nodelist/routerinfo.h"
   34 #include "feature/nodelist/routerinfo_st.h"
   35 #include "feature/nodelist/routerlist.h" // but...
   36 #include "feature/nodelist/routerset.h"
   37 #include "feature/nodelist/torcert.h"
   38 #include "feature/relay/relay_periodic.h"
   39 #include "feature/relay/router.h"
   40 #include "feature/relay/selftest.h"
   41 
   42 /** Whether we can reach our ORPort from the outside. */
   43 static int can_reach_or_port = 0;
   44 /** Whether we can reach our DirPort from the outside. */
   45 static int can_reach_dir_port = 0;
   46 
   47 /** Forget what we have learned about our reachability status. */
   48 void
   49 router_reset_reachability(void)
   50 {
   51   can_reach_or_port = can_reach_dir_port = 0;
   52 }
   53 
   54 /** Return 1 if we won't do reachability checks, because:
   55  *   - AssumeReachable is set, or
   56  *   - the network is disabled.
   57  * Otherwise, return 0.
   58  */
   59 static int
   60 router_reachability_checks_disabled(const or_options_t *options)
   61 {
   62   return options->AssumeReachable ||
   63          net_is_disabled();
   64 }
   65 
   66 /** Return 0 if we need to do an ORPort reachability check, because:
   67  *   - no reachability check has been done yet, or
   68  *   - we've initiated reachability checks, but none have succeeded.
   69  *  Return 1 if we don't need to do an ORPort reachability check, because:
   70  *   - we've seen a successful reachability check, or
   71  *   - AssumeReachable is set, or
   72  *   - the network is disabled.
   73  */
   74 int
   75 check_whether_orport_reachable(const or_options_t *options)
   76 {
   77   int reach_checks_disabled = router_reachability_checks_disabled(options);
   78   return reach_checks_disabled ||
   79          can_reach_or_port;
   80 }
   81 
   82 /** Return 0 if we need to do a DirPort reachability check, because:
   83  *   - no reachability check has been done yet, or
   84  *   - we've initiated reachability checks, but none have succeeded.
   85  *  Return 1 if we don't need to do a DirPort reachability check, because:
   86  *   - we've seen a successful reachability check, or
   87  *   - there is no DirPort set, or
   88  *   - AssumeReachable is set, or
   89  *   - the network is disabled.
   90  */
   91 int
   92 check_whether_dirport_reachable(const or_options_t *options)
   93 {
   94   int reach_checks_disabled = router_reachability_checks_disabled(options) ||
   95                               !options->DirPort_set;
   96   return reach_checks_disabled ||
   97          can_reach_dir_port;
   98 }
   99 
  100 /** See if we currently believe our ORPort or DirPort to be
  101  * unreachable. If so, return 1 else return 0.
  102  */
  103 static int
  104 router_should_check_reachability(int test_or, int test_dir)
  105 {
  106   const routerinfo_t *me = router_get_my_routerinfo();
  107   const or_options_t *options = get_options();
  108 
  109   if (!me)
  110     return 0;
  111 
  112   if (routerset_contains_router(options->ExcludeNodes, me, -1) &&
  113       options->StrictNodes) {
  114     /* If we've excluded ourself, and StrictNodes is set, we can't test
  115      * ourself. */
  116     if (test_or || test_dir) {
  117 #define SELF_EXCLUDED_WARN_INTERVAL 3600
  118       static ratelim_t warning_limit=RATELIM_INIT(SELF_EXCLUDED_WARN_INTERVAL);
  119       log_fn_ratelim(&warning_limit, LOG_WARN, LD_CIRC,
  120                  "Can't peform self-tests for this relay: we have "
  121                  "listed ourself in ExcludeNodes, and StrictNodes is set. "
  122                  "We cannot learn whether we are usable, and will not "
  123                  "be able to advertise ourself.");
  124     }
  125     return 0;
  126   }
  127   return 1;
  128 }
  129 
  130 /** Allocate and return a new extend_info_t that can be used to build
  131  * a circuit to or through the router <b>r</b>. Uses the primary
  132  * address of the router, so should only be called on a server. */
  133 static extend_info_t *
  134 extend_info_from_router(const routerinfo_t *r)
  135 {
  136   crypto_pk_t *rsa_pubkey;
  137   extend_info_t *info;
  138   tor_addr_port_t ap;
  139   tor_assert(r);
  140 
  141   /* Make sure we don't need to check address reachability */
  142   tor_assert_nonfatal(router_skip_or_reachability(get_options(), 0));
  143 
  144   const ed25519_public_key_t *ed_id_key;
  145   if (r->cache_info.signing_key_cert)
  146     ed_id_key = &r->cache_info.signing_key_cert->signing_key;
  147   else
  148     ed_id_key = NULL;
  149 
  150   router_get_prim_orport(r, &ap);
  151   rsa_pubkey = router_get_rsa_onion_pkey(r->onion_pkey, r->onion_pkey_len);
  152   info = extend_info_new(r->nickname, r->cache_info.identity_digest,
  153                          ed_id_key,
  154                          rsa_pubkey, r->onion_curve25519_pkey,
  155                          &ap.addr, ap.port);
  156   crypto_pk_free(rsa_pubkey);
  157   return info;
  158 }
  159 
  160 /** Some time has passed, or we just got new directory information.
  161  * See if we currently believe our ORPort or DirPort to be
  162  * unreachable. If so, launch a new test for it.
  163  *
  164  * For ORPort, we simply try making a circuit that ends at ourselves.
  165  * Success is noticed in onionskin_answer().
  166  *
  167  * For DirPort, we make a connection via Tor to our DirPort and ask
  168  * for our own server descriptor.
  169  * Success is noticed in connection_dir_client_reached_eof().
  170  */
  171 void
  172 router_do_reachability_checks(int test_or, int test_dir)
  173 {
  174   const routerinfo_t *me = router_get_my_routerinfo();
  175   const or_options_t *options = get_options();
  176   int orport_reachable = check_whether_orport_reachable(options);
  177   tor_addr_t addr;
  178 
  179   if (router_should_check_reachability(test_or, test_dir)) {
  180     if (test_or && (!orport_reachable || !circuit_enough_testing_circs())) {
  181       extend_info_t *ei = extend_info_from_router(me);
  182       /* XXX IPv6 self testing */
  183       log_info(LD_CIRC, "Testing %s of my ORPort: %s:%d.",
  184                !orport_reachable ? "reachability" : "bandwidth",
  185                fmt_addr32(me->addr), me->or_port);
  186       circuit_launch_by_extend_info(CIRCUIT_PURPOSE_TESTING, ei,
  187                               CIRCLAUNCH_NEED_CAPACITY|CIRCLAUNCH_IS_INTERNAL);
  188       extend_info_free(ei);
  189     }
  190 
  191     /* XXX IPv6 self testing */
  192     tor_addr_from_ipv4h(&addr, me->addr);
  193     if (test_dir && !check_whether_dirport_reachable(options) &&
  194         !connection_get_by_type_addr_port_purpose(
  195                   CONN_TYPE_DIR, &addr, me->dir_port,
  196                   DIR_PURPOSE_FETCH_SERVERDESC)) {
  197       tor_addr_port_t my_orport, my_dirport;
  198       memcpy(&my_orport.addr, &addr, sizeof(addr));
  199       memcpy(&my_dirport.addr, &addr, sizeof(addr));
  200       my_orport.port = me->or_port;
  201       my_dirport.port = me->dir_port;
  202       /* ask myself, via tor, for my server descriptor. */
  203       directory_request_t *req =
  204         directory_request_new(DIR_PURPOSE_FETCH_SERVERDESC);
  205       directory_request_set_or_addr_port(req, &my_orport);
  206       directory_request_set_dir_addr_port(req, &my_dirport);
  207       directory_request_set_directory_id_digest(req,
  208                                               me->cache_info.identity_digest);
  209       // ask via an anon circuit, connecting to our dirport.
  210       directory_request_set_indirection(req, DIRIND_ANON_DIRPORT);
  211       directory_request_set_resource(req, "authority.z");
  212       directory_initiate_request(req);
  213       directory_request_free(req);
  214     }
  215   }
  216 }
  217 
  218 /** Annotate that we found our ORPort reachable. */
  219 void
  220 router_orport_found_reachable(void)
  221 {
  222   const routerinfo_t *me = router_get_my_routerinfo();
  223   const or_options_t *options = get_options();
  224   if (!can_reach_or_port && me) {
  225     char *address = tor_dup_ip(me->addr);
  226     log_notice(LD_OR,"Self-testing indicates your ORPort is reachable from "
  227                "the outside. Excellent.%s",
  228                options->PublishServerDescriptor_ != NO_DIRINFO
  229                && check_whether_dirport_reachable(options) ?
  230                  " Publishing server descriptor." : "");
  231     can_reach_or_port = 1;
  232     mark_my_descriptor_dirty("ORPort found reachable");
  233     /* This is a significant enough change to upload immediately,
  234      * at least in a test network */
  235     if (options->TestingTorNetwork == 1) {
  236       reschedule_descriptor_update_check();
  237     }
  238     control_event_server_status(LOG_NOTICE,
  239                                 "REACHABILITY_SUCCEEDED ORADDRESS=%s:%d",
  240                                 address, me->or_port);
  241     tor_free(address);
  242   }
  243 }
  244 
  245 /** Annotate that we found our DirPort reachable. */
  246 void
  247 router_dirport_found_reachable(void)
  248 {
  249   const routerinfo_t *me = router_get_my_routerinfo();
  250   const or_options_t *options = get_options();
  251   if (!can_reach_dir_port && me) {
  252     char *address = tor_dup_ip(me->addr);
  253     log_notice(LD_DIRSERV,"Self-testing indicates your DirPort is reachable "
  254                "from the outside. Excellent.%s",
  255                options->PublishServerDescriptor_ != NO_DIRINFO
  256                && check_whether_orport_reachable(options) ?
  257                " Publishing server descriptor." : "");
  258     can_reach_dir_port = 1;
  259     if (router_should_advertise_dirport(options, me->dir_port)) {
  260       mark_my_descriptor_dirty("DirPort found reachable");
  261       /* This is a significant enough change to upload immediately,
  262        * at least in a test network */
  263       if (options->TestingTorNetwork == 1) {
  264         reschedule_descriptor_update_check();
  265       }
  266     }
  267     control_event_server_status(LOG_NOTICE,
  268                                 "REACHABILITY_SUCCEEDED DIRADDRESS=%s:%d",
  269                                 address, me->dir_port);
  270     tor_free(address);
  271   }
  272 }
  273 
  274 /** We have enough testing circuits open. Send a bunch of "drop"
  275  * cells down each of them, to exercise our bandwidth. */
  276 void
  277 router_perform_bandwidth_test(int num_circs, time_t now)
  278 {
  279   int num_cells = (int)(get_options()->BandwidthRate * 10 /
  280                         CELL_MAX_NETWORK_SIZE);
  281   int max_cells = num_cells < CIRCWINDOW_START ?
  282                     num_cells : CIRCWINDOW_START;
  283   int cells_per_circuit = max_cells / num_circs;
  284   origin_circuit_t *circ = NULL;
  285 
  286   log_notice(LD_OR,"Performing bandwidth self-test...done.");
  287   while ((circ = circuit_get_next_by_pk_and_purpose(circ, NULL,
  288                                               CIRCUIT_PURPOSE_TESTING))) {
  289     /* dump cells_per_circuit drop cells onto this circ */
  290     int i = cells_per_circuit;
  291     if (circ->base_.state != CIRCUIT_STATE_OPEN)
  292       continue;
  293     circ->base_.timestamp_dirty = now;
  294     while (i-- > 0) {
  295       if (relay_send_command_from_edge(0, TO_CIRCUIT(circ),
  296                                        RELAY_COMMAND_DROP,
  297                                        NULL, 0, circ->cpath->prev)<0) {
  298         return; /* stop if error */
  299       }
  300     }
  301   }
  302 }