-
Notifications
You must be signed in to change notification settings - Fork 91
Peers behind a firewall #5241
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Peers behind a firewall #5241
Changes from 2 commits
5d2e86d
c2e3eec
a12338a
405b005
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,17 @@ | ||
| <!-- | ||
| A new scriv changelog fragment. | ||
| Uncomment the section that is right (remove the HTML comment wrapper). | ||
| For top level release notes, leave all the headers commented out. | ||
| --> | ||
|
|
||
| ### Breaking | ||
|
|
||
| - Modified `establishPeerConnection` in `Test.Cardano.Network.PeerSelection.MockEnvironment`: | ||
| - Now only creates a new connection if no inbound connection is found and `ConnectionMode` allows it. | ||
| - Added tracing for newly created connections. | ||
|
|
||
| ### Non-Breaking | ||
|
|
||
| - Added a new tracer: `TraceEnvNewConnCreated`. | ||
| - Added a property test to verify that the node never connects to peers behind a firewall. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -30,5 +30,6 @@ isValidTrustedPeerConfiguration | |
| IsTrustable -> not | ||
| . null | ||
| . rootAccessPoints | ||
| . rootConfig | ||
| $ localRoots | ||
| ) lprgs | ||
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,22 @@ | ||
| <!-- | ||
| A new scriv changelog fragment. | ||
|
|
||
| Uncomment the section that is right (remove the HTML comment wrapper). | ||
| For top level release notes, leave all the headers commented out. | ||
| --> | ||
|
|
||
| ### Breaking | ||
|
|
||
| - Changed the type of `localRoots` to `LocalRoots`. | ||
| - Modified `AcquireOutboundConnection` to include an additional parameter: `ConnectionMode`. | ||
| - `acquireOutboundConnectionImpl` only creates a new connection if the `ConnectionMode` function permits it. | ||
| - `jobPromoteColdPeer` only creates a new connection if no inbound connection is found and the peer is not behind a firewall. | ||
|
|
||
| ### Non-Breaking | ||
|
|
||
| - Added `LocalRoots` type in `Ouroboros.Network.PeerSelection.State.LocalRootPeers` with the following fields: | ||
| - `rootConfig` of type `RootConfig` | ||
| - `behindFirewall` of type `Bool` | ||
| - Added `localRootBehindFirewall` field to `LocalRootConfig`. | ||
| - Added a new sum type: `ConnectionMode`. | ||
| - Added a new constructor `InboundConnectionNotFound` for `ConnectionManagerError`. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1338,8 +1338,9 @@ with args@Arguments { | |
| -> ConnectionHandlerFn handlerTrace socket peerAddr handle handleError version versionData m | ||
| -> DiffusionMode | ||
| -> peerAddr | ||
| -> ConnectionMode | ||
| -> m (Connected peerAddr handle handleError) | ||
| acquireOutboundConnectionImpl stateVar stdGenVar handler diffusionMode peerAddr = do | ||
| acquireOutboundConnectionImpl stateVar stdGenVar handler diffusionMode peerAddr connectionMode = do | ||
| let provenance = Outbound | ||
| traceWith tracer (TrIncludeConnection provenance peerAddr) | ||
| (trace, mutableConnState@MutableConnState { connVar, connStateId } | ||
|
|
@@ -1486,6 +1487,10 @@ with args@Arguments { | |
|
|
||
| -- connection manager does not have a connection with @peerAddr@. | ||
| Right Nowhere -> do | ||
| -- Only proceed if creating a new connection is allowed | ||
| when (inboundRequired connectionMode) $ | ||
| throwIO (withCallStack $ InboundConnectionNotFound peerAddr) | ||
|
|
||
|
||
| (reader, writer) <- newEmptyPromiseIO | ||
|
|
||
| (connId, connThread) <- | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -114,6 +114,8 @@ module Ouroboros.Network.ConnectionManager.Types | |
| , resultInState | ||
| , DemotedToColdRemoteTr (..) | ||
| , AcquireOutboundConnection | ||
| , ConnectionMode (..) | ||
| , inboundRequired | ||
| , IncludeInboundConnection | ||
| -- *** Outbound side | ||
| , acquireOutboundConnection | ||
|
|
@@ -497,9 +499,23 @@ data Connected peerAddr handle handleError = | |
| -- | ||
| | Disconnected !(ConnectionId peerAddr) !(DisconnectionException handleError) | ||
|
|
||
| -- | Describes the behavior for handling connections when no inbound connection | ||
| -- is found. | ||
| -- - 'CreateNewIfNoInbound': If no inbound connection exists, create a new | ||
| -- conection. | ||
| -- - 'RequireInbound': Strictly require an inbound connection; fail if none | ||
| -- exists. | ||
| data ConnectionMode | ||
| = CreateNewIfNoInbound | ||
| | RequireInbound | ||
|
|
||
| inboundRequired :: ConnectionMode -> Bool | ||
| inboundRequired RequireInbound = True | ||
| inboundRequired _other = False | ||
|
Comment on lines
508
to
515
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I don't think we need a new data type. We can use |
||
|
|
||
| type AcquireOutboundConnection peerAddr handle handleError m | ||
| = DiffusionMode -> peerAddr -> m (Connected peerAddr handle handleError) | ||
| = DiffusionMode -> peerAddr -> ConnectionMode -> m (Connected peerAddr handle handleError) | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. s/ConnectionMode/Provenance/ |
||
|
|
||
| type IncludeInboundConnection socket peerAddr handle handleError m | ||
| = Word32 | ||
| -- ^ inbound connections hard limit. | ||
|
|
@@ -723,6 +739,11 @@ data ConnectionManagerError peerAddr | |
| -- | ||
| | ForbiddenConnection !(ConnectionId peerAddr) !CallStack | ||
|
|
||
| -- | No matching inbound connection found and creating new connection is | ||
| -- not allowed. | ||
| -- | ||
| | InboundConnectionNotFound !peerAddr !CallStack | ||
|
||
|
|
||
| -- | Connections that would be forbidden by the kernel (@TCP@ semantics). | ||
| -- | ||
| | ImpossibleConnection !(ConnectionId peerAddr) !CallStack | ||
|
|
@@ -774,6 +795,12 @@ instance ( Show peerAddr | |
| , "\n" | ||
| , prettyCallStack cs | ||
| ] | ||
| displayException (InboundConnectionNotFound peerAddr cs) = | ||
| concat [ "No matching inbound connection found and creating new connection is not allowed with peer " | ||
| , show peerAddr | ||
| , "\n" | ||
| , prettyCallStack cs | ||
| ] | ||
| displayException (ConnectionTerminating connId cs) = | ||
| concat [ "Connection terminating " | ||
| , show connId | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think it's needed - see my other comments.