mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Add a new family-specific syntax for tor_addr_parse_mask_ports
By default, "*" means "All IPv4 addresses" with tor_addr_parse_mask_ports, so I won't break anything. But if the new EXTENDED_STAR flag is provided, then * means "any address", *4 means "any IPv4 address" (that is, 0.0.0.0/0), and "*6" means "any IPv6 address" (that is, [::]/0). This is going to let us have a syntax for specifying exit policies in torrc that won't drive people mad. Also, add a bunch of unit tests for tor_addr_parse_mask_ports to test these new features, and to increase coverage.
This commit is contained in:
@@ -276,6 +276,7 @@ static config_var_t option_vars_[] = {
|
||||
V(HTTPProxyAuthenticator, STRING, NULL),
|
||||
V(HTTPSProxy, STRING, NULL),
|
||||
V(HTTPSProxyAuthenticator, STRING, NULL),
|
||||
// V(IPv6EXit, BOOL, "0"),
|
||||
VAR("ServerTransportPlugin", LINELIST, ServerTransportPlugin, NULL),
|
||||
V(Socks4Proxy, STRING, NULL),
|
||||
V(Socks5Proxy, STRING, NULL),
|
||||
|
||||
+4
-3
@@ -87,7 +87,8 @@ policy_expand_private(smartlist_t **policy)
|
||||
memcpy(&newpolicy, p, sizeof(addr_policy_t));
|
||||
newpolicy.is_private = 0;
|
||||
newpolicy.is_canonical = 0;
|
||||
if (tor_addr_parse_mask_ports(private_nets[i], &newpolicy.addr,
|
||||
if (tor_addr_parse_mask_ports(private_nets[i], 0,
|
||||
&newpolicy.addr,
|
||||
&newpolicy.maskbits, &port_min, &port_max)<0) {
|
||||
tor_assert(0);
|
||||
}
|
||||
@@ -1192,8 +1193,8 @@ policy_summary_add_item(smartlist_t *summary, addr_policy_t *p)
|
||||
for (i = 0; private_nets[i]; ++i) {
|
||||
tor_addr_t addr;
|
||||
maskbits_t maskbits;
|
||||
if (tor_addr_parse_mask_ports(private_nets[i], &addr,
|
||||
&maskbits, NULL, NULL)<0) {
|
||||
if (tor_addr_parse_mask_ports(private_nets[i], 0, &addr,
|
||||
&maskbits, NULL, NULL)<0) {
|
||||
tor_assert(0);
|
||||
}
|
||||
if (tor_addr_compare(&p->addr, &addr, CMP_EXACT) == 0 &&
|
||||
|
||||
@@ -1280,7 +1280,8 @@ find_single_ipv6_orport(const smartlist_t *list,
|
||||
uint16_t port_min, port_max;
|
||||
tor_assert(t->n_args >= 1);
|
||||
/* XXXX Prop186 the full spec allows much more than this. */
|
||||
if (tor_addr_parse_mask_ports(t->args[0], &a, &bits, &port_min,
|
||||
if (tor_addr_parse_mask_ports(t->args[0], 0,
|
||||
&a, &bits, &port_min,
|
||||
&port_max) == AF_INET6 &&
|
||||
bits == 128 &&
|
||||
port_min == port_max) {
|
||||
@@ -3737,7 +3738,7 @@ router_parse_addr_policy(directory_token_t *tok)
|
||||
else
|
||||
newe.policy_type = ADDR_POLICY_ACCEPT;
|
||||
|
||||
if (tor_addr_parse_mask_ports(arg, &newe.addr, &newe.maskbits,
|
||||
if (tor_addr_parse_mask_ports(arg, 0, &newe.addr, &newe.maskbits,
|
||||
&newe.prt_min, &newe.prt_max) < 0) {
|
||||
log_warn(LD_DIR,"Couldn't parse line %s. Dropping", escaped(arg));
|
||||
return NULL;
|
||||
|
||||
Reference in New Issue
Block a user