Skip to main content

AddrPolicy

Struct AddrPolicy 

Source
pub struct AddrPolicy {
    rules: Vec<AddrPolicyRule>,
}
Expand description

Sequence of accept and reject rules

https://spec.torproject.org/dir-spec/server-descriptor-format.html#item:accept

Encodable in netdocs, and parseable as NetdocParseableFields.

A specific address:port is tested against them in order; first match wins. Each rule is of the form “accept PATTERN” or “reject PATTERN”, where every pattern describes a set of addresses and ports. Address sets are given as a prefix of 0-128 bits that the address must have; port sets are given as a low-bound and high-bound that the target port might lie between.

Relays use this type for defining their own policies, and for publishing their IPv4 policies. Clients instead use super::portpolicy::PortPolicy objects to view a summary of the relays’ declared policies.

An example IPv4 policy might be:

ⓘ
 reject *:25
 reject 127.0.0.0/8:*
 reject 192.168.0.0/16:*
 accept *:80
 accept *:443
 accept *:9000-65535
 reject *:*

Default is the all-reject policy, also constructible with AddrPolicy::new.

Fields§

§rules: Vec<AddrPolicyRule>

A list of rules to apply to find out whether an address is contained by this policy.

The rules apply in order; the first one to match determines whether the address is accepted or rejected.

Implementations§

Source§

impl AddrPolicy

Source

pub fn allows(&self, addr: &IpAddr, port: u16) -> Option<RuleKind>

Apply this policy to an address:port combination

We do this by applying each rule in sequence, until one matches.

Returns None if no rule matches.

Source

pub fn allows_sockaddr(&self, addr: &SocketAddr) -> Option<RuleKind>

As allows, but accept a SocketAddr.

Source

pub fn new() -> Self

Create a new AddrPolicy that matches nothing.

Source

pub fn push(&mut self, kind: RuleKind, pattern: AddrPortPattern)

Add a new rule to this policy.

The newly added rule is applied after all previous rules. It matches all addresses and ports covered by AddrPortPattern.

If accept is true, the rule is to accept addresses that match; if accept is false, the rule rejects such addresses.

Source

pub fn rules( &self, ) -> impl DoubleEndedIterator<Item = (RuleKind, AddrPortPattern)> + '_

List the rules in this pattern

Source§

impl AddrPolicy

Source

pub fn summarise_precise( &self, thresholds: &PortSummaryThresholds, private_ranges: impl IntoIterator<Item = IpNet>, ) -> PortPolicies

Calculate port policy summaries using a precise but unhardened algorithm

Returns two Exit Policy Summaries, one for for each of IPv4 and IPv6. https://spec.torproject.org/dir-spec/computing-consensus.html#exit-summary

Not generally suitable for use on untrusted input because there is no effort to limit the computational complexity.

Useful for a router, when calculating ipv6-policy in its router descriptor, from its own (locally configured) accept/reject policy.

The result is calculated according to this rule:

A port should be summarised as accepted iff the full exit policy permits “most” “public” addresses on that port.

summarise_precise implements the rule precisely as specified there; not the hardened approximate algorithm used by dirauths for IPv4 summaries.

private_ranges is the ranges considered not “public”. Rejections of addresses in these ranges are disregarded when considering whether a port is open.

This algorithm does not handle “IPv4-mapped Addresses” (ie, IPv6-mapped IPv4 addresses) specially. They should normally be rejected, and be in private_ranges.

thresholds should normally be &PortSummaryThresholds::DEFAULT.

Trait Implementations§

Source§

impl Clone for AddrPolicy

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AddrPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for AddrPolicy

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Eq for AddrPolicy

Source§

impl NetdocEncodableFields for AddrPolicy

Source§

fn encode_fields(&self, out: &mut NetdocEncoder) -> Result<(), Bug>

Append the document onto out
Source§

impl NetdocParseableFields for AddrPolicy

Source§

type Accumulator = AddrPolicy

The partially-parsed set of items.
Source§

fn is_item_keyword(kw: KeywordRef<'_>) -> bool

Is this one of the keywords in this struct
Source§

fn accumulate_item( acc: &mut Self::Accumulator, item: UnparsedItem<'_>, ) -> Result<(), EP>

Accumulate an item in this struct Read more
Source§

fn finish(acc: Self::Accumulator, _: &ItemStream<'_>) -> Result<Self, EP>

Finish Read more
Source§

impl PartialEq for AddrPolicy

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for AddrPolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Downcast for T
where T: Any,

Source§

fn into_any(self: Box<T>) -> Box<dyn Any>

Converts Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>

Converts Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further downcast into Rc<ConcreteType> where ConcreteType implements Trait.
Source§

fn as_any(&self) -> &(dyn Any + 'static)

Converts &Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &Any’s vtable from &Trait’s.
Source§

fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)

Converts &mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &mut Any’s vtable from &mut Trait’s.
Source§

impl<T> DowncastSend for T
where T: Any + Send,

Source§

fn into_any_send(self: Box<T>) -> Box<dyn Any + Send>

Converts Box<Trait> (where Trait: DowncastSend) to Box<dyn Any + Send>, which can then be downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

impl<T> DowncastSync for T
where T: Any + Send + Sync,

Source§

fn into_any_sync(self: Box<T>) -> Box<dyn Any + Send + Sync>

Converts Box<Trait> (where Trait: DowncastSync) to Box<dyn Any + Send + Sync>, which can then be downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_arc(self: Arc<T>) -> Arc<dyn Any + Send + Sync> ⓘ

Converts Arc<Trait> (where Trait: DowncastSync) to Arc<Any>, which can then be downcast into Arc<ConcreteType> where ConcreteType implements Trait.
Source§

impl<T> DynClone for T
where T: Clone,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PossiblyOption<T> for T

Source§

fn to_option(self) -> Option<T>

Convert this object into an Option<T>
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more