aboutsummaryrefslogtreecommitdiff
path: root/changes
Commit message (Collapse)AuthorAge
...
| * | | Use strlcpy in create_unix_sockaddr()Nick Mathewson2011-07-01
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Using strncpy meant that if listenaddress were ever >= sizeof(sockaddr_un.sun_path), we would fail to nul-terminate sun_path. This isn't a big deal: we never read sun_path, and the kernel is smart enough to reject the sockaddr_un if it isn't nul-terminated. Nonetheless, it's a dumb failure mode. Instead, we should reject addresses that don't fit in sockaddr_un.sun_path. Coverity found this; it's CID 428. Bugfix on 0.2.0.3-alpha.
* | | Tweak bug2355_revert at suggestion from RogerNick Mathewson2011-06-19
| | |
* | | Add changes file for bug2355 revertNick Mathewson2011-06-17
| | |
* | | Merge remote-tracking branch 'origin/maint-0.2.1' into maint-0.2.2Nick Mathewson2011-06-17
|\| |
| * | Abandon rendezvous circuits on SIGNAL NEWNYMRobert Ransom2011-06-17
| | |
* | | Merge branch 'bug3407' into maint-0.2.2Nick Mathewson2011-06-17
|\ \ \
| * | | Make send_control_event_impl's behaviour saneRobert Ransom2011-06-17
| | | |
| * | | Make connection_printf_to_buf's behaviour saneRobert Ransom2011-06-17
| | | |
* | | | Merge remote-tracking branch 'public/bug3369' into maint-0.2.2Nick Mathewson2011-06-14
|\ \ \ \
| * | | | changelog entry for bug3369Nick Mathewson2011-06-13
| | | | |
* | | | | Add changes file for bug3393Nick Mathewson2011-06-14
|/ / / /
* | | | Fix a rare memleak during stats writingSebastian Hahn2011-06-08
| | | | | | | | | | | | | | | | | | | | If rep_hist_buffer_stats_write() was called unitinitalized, we'd leak memory.
* | | | Don't use signed 1-bit bitfieldsSebastian Hahn2011-06-08
| | | | | | | | | | | | | | | | | | | | This was harmless, we never compared it to anything but itself or 0. But Coverity complained, and it had a point.
* | | | Remove a few dead assignments during router parsingSebastian Hahn2011-06-08
| | | |
* | | | Check some more return values in unit testsSebastian Hahn2011-06-08
| | | |
* | | | remove some dead code, found by coveritySebastian Hahn2011-06-08
| | | |
* | | | Merge branch 'bug3306_nm_squashed' into maint-0.2.2Nick Mathewson2011-06-06
|\ \ \ \
| * | | | Detect insanely large circuit build state; don't give its length to rand_intNick Mathewson2011-06-06
| | | | |
| * | | | Check maximum properly in crypto_rand_int()Nick Mathewson2011-06-06
| | |_|/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | George Kadianakis notes that if you give crypto_rand_int() a value above INT_MAX, it can return a negative number, which is not what the documentation would imply. The simple solution is to assert that the input is in [1,INT_MAX+1]. If in the future we need a random-value function that can return values up to UINT_MAX, we can add one. Fixes bug 3306; bugfix on 0.2.2pre14.
* | | | Merge branch 'maint-0.2.1' into maint-0.2.2Roger Dingledine2011-06-05
|\ \ \ \ | |/ / / |/| | / | | |/ | |/|
| * | move to the june 1 2011 maxmind geoip dbRoger Dingledine2011-06-05
| | |
* | | Merge branch 'bug3318c' into maint-0.2.2Nick Mathewson2011-06-03
|\ \ \
| * | | Reject 128-byte keys that are not 1024-bitNick Mathewson2011-06-03
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When we added the check for key size, we required that the keys be 128 bytes. But RSA_size (which defers to BN_num_bytes) will return 128 for keys of length 1017..1024. This patch adds a new crypto_pk_num_bits() that returns the actual number of significant bits in the modulus, and uses that to enforce key sizes. Also, credit the original bug3318 in the changes file.
* | | | Merge remote-tracking branch 'rransom/bug2748-v2' into maint-0.2.2Nick Mathewson2011-06-03
|\ \ \ \
| * | | | Log malformed HS descriptor requests at the proper levelRobert Ransom2011-03-14
| | | | | | | | | | | | | | | | | | | | This log message should be a 'protocol warning', not a 'warning'.
| * | | | Remove dead code from rend_cache_lookup_v2_desc_as_dirRobert Ransom2011-03-14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | hid_serv_responsible_for_desc_id's return value is never negative, and there is no need to search through the consensus to find out whether we are responsible for a descriptor ID before we look in our cache for a descriptor.
* | | | | Changes file for bug2355.Nick Mathewson2011-06-02
| | | | |
* | | | | Merge remote-tracking branch 'rransom-tor/bug3309' into maint-0.2.2Nick Mathewson2011-06-02
|\ \ \ \ \
| * | | | | Add info-level log messages during HS-client-state purgeRobert Ransom2011-06-02
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I hope these will never be useful, but having them and not needing them is better than needing them and not having them.
| * | | | | Clear last_hid_serv_requests on SIGNAL NEWNYMRobert Ransom2011-06-02
| | |/ / / | |/| | | | | | | | | | | | | Fixes bug #3309.
* | | | | Merge remote-tracking branch 'arma/bug3321' into maint-0.2.2Nick Mathewson2011-06-02
|\ \ \ \ \ | |/ / / / |/| | | |
| * | | | fix a bridge edge case similar to 2511Roger Dingledine2011-05-31
| | | | | | | | | | | | | | | | | | | | | | | | | If you had configured a bridge but then switched to a different bridge via the controller, you would still be willing to use the old one.
* | | | | Report wrong key sizes correctlyNick Mathewson2011-06-01
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | When we introduced NEED_KEY_1024 in routerparse.c back in 0.2.0.1-alpha, I forgot to add a *8 when logging the length of a bad-length key. Bugfix for 3318 on 0.2.0.1-alpha.
* | | | Merge branch 'bug3216_v2' into maint-0.2.2Nick Mathewson2011-05-30
|\ \ \ \
| * | | | Don't build descriptors if ORPort auto is set and we have no OR listenerNick Mathewson2011-05-24
| | |_|/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This situation can happen easily if you set 'ORPort auto' and 'AccountingMax'. Doing so means that when you have no ORPort, you won't be able to set an ORPort in a descriptor, so instead you would just generate lots of invalid descriptors, freaking out all the time. Possible fix for 3216; fix on 0.2.2.26-beta.
* | | | Warn when two hs use the same directorySebastian Hahn2011-05-30
| | | | | | | | | | | | | | | | | | | | This simple implementation has a few issues, but it should do for 0.2.2.x. We will want to revisit this later and make it smarter.
* | | | Merge branch 'bug3045' into maint-0.2.2Nick Mathewson2011-05-30
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Conflicts: src/or/circuitbuild.c
| * | | | changes file for bug3045Nick Mathewson2011-05-15
| | | | |
* | | | | Merge remote-tracking branch 'public/bug3270' into maint-0.2.2Nick Mathewson2011-05-30
|\ \ \ \ \
| * | | | | Use a 64-bit type to hold sockets on win64.Nick Mathewson2011-05-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | On win64, sockets are of type UINT_PTR; on win32 they're u_int; elsewhere they're int. The correct windows way to check a socket for being set is to compare it with INVALID_SOCKET; elsewhere you see if it is negative. On Libevent 2, all callbacks take sockets as evutil_socket_t; we've been passing them int. This patch should fix compilation and correctness when built for 64-bit windows. Fixes bug 3270.
* | | | | | Reinit keys at the start of options_act().Nick Mathewson2011-05-30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously we did this nearer to the end (in the old_options && transition_affects_workers() block). But other stuff cares about keys being consistent with options... particularly anything which tries to access a key, which can die in assert_identity_keys_ok(). Fixes bug 3228; bugfix on 0.2.2.18-alpha.
* | | | | | Use the normal four-hop CBT for client intro circuitsRobert Ransom2011-05-30
| | | | | | | | | | | | | | | | | | | | | | | | Fixes another part of bug 1297.
* | | | | | Set timestamp_dirty on HS circuits as circuit_expire_building requiresRobert Ransom2011-05-30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes part of #1297; bugfix on 48e0228f1e031a709c1deb149c7dfd187c3609cf, when circuit_expire_building was changed to assume that timestamp_dirty was set when a circuit changed purpose to _C_REND_READY. (It wasn't.)
* | | | | | Merge remote-tracking branch 'origin/maint-0.2.1' into maint-0.2.2Nick Mathewson2011-05-28
|\ \ \ \ \ \ | | |_|_|_|/ | |/| | | |
| * | | | | Fix typo in changes/bug2574. Thanks, rransomNick Mathewson2011-05-28
| | | | | |
* | | | | | Merge remote-tracking branch 'origin/maint-0.2.1' into maint-0.2.2Nick Mathewson2011-05-28
|\| | | | |
| * | | | | Merge branch 'bug2574' into maint-0.2.1Nick Mathewson2011-05-28
| |\ \ \ \ \
| | * | | | | Work correctly if your nameserver is ::1Nick Mathewson2011-05-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We had all the code in place to handle this right... except that we were unconditionally opening a PF_INET socket instead of looking at sa_family. Ow. Fixes bug 2574; not a bugfix on any particular version, since this never worked before.
* | | | | | | Fix GCC 4.6's new -Wunused-but-set-variable warnings.Nick Mathewson2011-05-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Most instances were dead code; for those, I removed the assignments. Some were pieces of info we don't currently plan to use, but which we might in the future. For those, I added an explicit cast-to-void to indicate that we know that the thing's unused. Finally, one was a case where we were testing the wrong variable in a unit test. That one I fixed. This resolves bug 3208.
* | | | | | | Remove the -F option from tor-resolve.Nick Mathewson2011-05-23
| |_|_|_|/ / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It used to mean "Force": it would tell tor-resolve to ask tor to resolve an address even if it ended with .onion. But when AutomapHostsOnResolve was added, automatically refusing to resolve .onion hosts stopped making sense. So in 0.2.1.16-rc (commit 298dc95dfd8), we made tor-resolve happy to resolve anything. The -F option stayed in, though, even though it didn't do anything. Oddly, it never got documented. Found while fixing GCC 4.6 "set, unused variable" warnings.