From 8d5c0e58ea19fa1bc662c23e1a7ae77d688400fc Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Wed, 11 Jan 2012 11:06:31 -0500 Subject: [PATCH 1/4] Fix a compilation warning for our bug4822 fix on 64-bit linux --- src/common/tortls.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/common/tortls.c b/src/common/tortls.c index d88a59b9c7..e624183c94 100644 --- a/src/common/tortls.c +++ b/src/common/tortls.c @@ -775,8 +775,8 @@ tor_tls_context_new(crypto_pk_env_t *identity, unsigned int key_lifetime, "might otherwise be vulnerable to CVE-2011-4657 " "(compile-time version %08lx (%s); " "runtime version %08lx (%s))", - OPENSSL_VERSION_NUMBER, OPENSSL_VERSION_TEXT, - SSLeay(), SSLeay_version(SSLEAY_VERSION)); + (unsigned long)OPENSSL_VERSION_NUMBER, OPENSSL_VERSION_TEXT, + (unsigned long)SSLeay(), SSLeay_version(SSLEAY_VERSION)); SSL_CTX_set_options(result->ctx, SSL_OP_NO_SSLv3); } From dd4b1a2ac605ff53c0eda4ebf44ddd84c3b243c0 Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Wed, 18 Jan 2012 10:47:22 -0500 Subject: [PATCH 2/4] Fix SOCKET_OK test on win64. Bugfix on 0.2.2.29-beta; partial fix for 4533; found by wanoskarnet --- changes/bug4533_part2 | 5 +++++ src/common/compat.h | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) create mode 100644 changes/bug4533_part2 diff --git a/changes/bug4533_part2 b/changes/bug4533_part2 new file mode 100644 index 0000000000..7e0f7c313e --- /dev/null +++ b/changes/bug4533_part2 @@ -0,0 +1,5 @@ + o Major bugfixes: + - Fix the SOCKET_OK test that we use to tell when socket + creation fails so that it works on Win64. Fixes part of bug + 4533; bugfix on 0.2.2.29-beta. Bug found by wanoskarnet. + diff --git a/src/common/compat.h b/src/common/compat.h index e0b074cf53..d2f1fd1295 100644 --- a/src/common/compat.h +++ b/src/common/compat.h @@ -396,7 +396,7 @@ typedef int socklen_t; #ifdef MS_WINDOWS #define tor_socket_t intptr_t -#define SOCKET_OK(s) ((unsigned)(s) != INVALID_SOCKET) +#define SOCKET_OK(s) ((SOCKET)(s) != INVALID_SOCKET) #else #define tor_socket_t int #define SOCKET_OK(s) ((s) >= 0) From 676bba8e0c91b7885aa8a9b7f55b008ccccfe282 Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Tue, 17 Jan 2012 15:28:23 -0500 Subject: [PATCH 3/4] Documentation for GiveGuardFlagTo... option --- changes/bug4012_022 | 3 +++ doc/tor.1.txt | 4 ++++ 2 files changed, 7 insertions(+) create mode 100644 changes/bug4012_022 diff --git a/changes/bug4012_022 b/changes/bug4012_022 new file mode 100644 index 0000000000..f101db5535 --- /dev/null +++ b/changes/bug4012_022 @@ -0,0 +1,3 @@ + o Minor bugfixes (documentation): + - Document the GiveGuardFlagTo_CVE_2011_2768_VulnerableRelays + directory authority option (introduced in Tor 0.2.2.34). diff --git a/doc/tor.1.txt b/doc/tor.1.txt index d91f873269..558b31b0fd 100644 --- a/doc/tor.1.txt +++ b/doc/tor.1.txt @@ -1347,6 +1347,10 @@ DIRECTORY AUTHORITY SERVER OPTIONS votes on whether to accept relays as hidden service directories. (Default: 1) +GiveGuardFlagTo_CVE_2011_2768_VulnerableRelays **0**|**1**:: + When this option is set to 0, do not vote to give the Guard flag to any + version of Tor vulnerable to CVE-2011-2769. (Default: 0) + HIDDEN SERVICE OPTIONS ---------------------- From 688903e919a4c0b942893d7b507a851e57e4e452 Mon Sep 17 00:00:00 2001 From: Roger Dingledine Date: Thu, 2 Feb 2012 02:31:28 -0500 Subject: [PATCH 4/4] Update "ClientOnly" man page entry There isn't really any point to messing with it. Resolves ticket 5005. --- changes/bug5005 | 3 +++ doc/tor.1.txt | 11 ++++++----- 2 files changed, 9 insertions(+), 5 deletions(-) create mode 100644 changes/bug5005 diff --git a/changes/bug5005 b/changes/bug5005 new file mode 100644 index 0000000000..04d8dfe6a5 --- /dev/null +++ b/changes/bug5005 @@ -0,0 +1,3 @@ + o Minor bugfixes: + - Update "ClientOnly" man page entry to explain that there isn't + really any point to messing with it. Resolves ticket 5005. diff --git a/doc/tor.1.txt b/doc/tor.1.txt index 558b31b0fd..160feb0281 100644 --- a/doc/tor.1.txt +++ b/doc/tor.1.txt @@ -499,11 +499,12 @@ The following options are useful only for clients (that is, if number like 60. (Default: 0) **ClientOnly** **0**|**1**:: - If set to 1, Tor will under no circumstances run as a server or serve - directory requests. The default is to run as a client unless ORPort is - configured. (Usually, you don't need to set this; Tor is pretty smart at - figuring out whether you are reliable and high-bandwidth enough to be a - useful server.) (Default: 0) + If set to 1, Tor will under no circumstances run as a relay or serve + directory requests. This config option is mostly meaningless: we + added it back when we were considering having Tor clients auto-promote + themselves to being relays if they were stable and fast enough. The + current behavior is simply that Tor is a client unless ORPort or + DirPort are configured. (Default: 0) **ExcludeNodes** __node__,__node__,__...__:: A list of identity fingerprints, nicknames, country codes and address