mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Merge branch 'maint-0.2.1' into release-0.2.1
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
o Major bugfixes
|
||||
- Ignore and warn about "PublishServerDescriptor hidserv" torrc
|
||||
options. The 'hidserv' argument never controlled publication
|
||||
of hidden service descriptors. Bugfix on 0.2.0.1-alpha.
|
||||
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
o Major bugfixes:
|
||||
- If relays set RelayBandwidthBurst but not RelayBandwidthRate,
|
||||
Tor would ignore their RelayBandwidthBurst setting,
|
||||
potentially using more bandwidth than expected. Bugfix on
|
||||
0.2.0.1-alpha. Reported by Paul Wouters. Fixes bug 2470.
|
||||
@@ -0,0 +1,3 @@
|
||||
o Minor features
|
||||
- Adjust our TLS Diffie-Hellman parameters to match those used by
|
||||
Apache's mod_ssl.
|
||||
@@ -0,0 +1,3 @@
|
||||
o Minor features:
|
||||
- Update to the February 1 2011 Maxmind GeoLite Country database.
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
o Major bugfixes (security)
|
||||
- Fix a bounds-checking error that could allow an attacker to
|
||||
remotely crash a directory authority. Found by piebeer.
|
||||
Bugfix on 0.2.1.5-alpha.
|
||||
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
o Minor bugfixes
|
||||
- Check for and reject overly long directory certificates and
|
||||
directory tokens before they have a chance to hit any
|
||||
assertions. Bugfix on 0.2.1.28. Found by doorss.
|
||||
@@ -1,5 +1,9 @@
|
||||
<html>
|
||||
<?xml version="1.0"?>
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
|
||||
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
|
||||
<html xmlns="http://www.w3.org/1999/xhtml">
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html;charset=utf-8" />
|
||||
<title>This is a Tor Exit Router</title>
|
||||
|
||||
<!--
|
||||
@@ -19,36 +23,38 @@ They are marked with FIXME.
|
||||
-->
|
||||
|
||||
</head>
|
||||
<body bgcolor=white text=black>
|
||||
<body>
|
||||
|
||||
<center><h1>This is a Tor Exit Router</h1></center>
|
||||
|
||||
<p>Most likely you are accessing this website because you had some issue with
|
||||
the traffic coming from this IP. This router is part of the <a
|
||||
href="https://www.torproject.org/">Tor Anonymity Network</a>, which is
|
||||
dedicated to <a href="https://www.torproject.org/30seconds.html.en">providing
|
||||
privacy</a> to people who need it most: average computer users. This
|
||||
router IP should be generating no other traffic, unless it has been
|
||||
compromised.
|
||||
<p style="text-align:center; font-size:xx-large; font-weight:bold">This is a
|
||||
Tor Exit Router</p>
|
||||
|
||||
<p>
|
||||
Most likely you are accessing this website because you had some issue with
|
||||
the traffic coming from this IP. This router is part of the <a
|
||||
href="https://www.torproject.org/">Tor Anonymity Network</a>, which is
|
||||
dedicated to <a href="https://www.torproject.org/about/overview">providing
|
||||
privacy</a> to people who need it most: average computer users. This
|
||||
router IP should be generating no other traffic, unless it has been
|
||||
compromised.</p>
|
||||
|
||||
|
||||
<!-- FIXME: you should probably grab your own copy of how_tor_works_thumb.png
|
||||
and serve it locally -->
|
||||
<center><a href="https://www.torproject.org/overview.html">
|
||||
<img src="https://www.torproject.org/images/how_tor_works_thumb.png"></a></center>
|
||||
and serve it locally -->
|
||||
|
||||
<p style="text-align:center">
|
||||
<a href="https://www.torproject.org/about/overview">
|
||||
<img src="https://www.torproject.org/images/how_tor_works_thumb.png" alt="How Tor works" style="border-style:none"/>
|
||||
</a></p>
|
||||
|
||||
<p>
|
||||
|
||||
Tor sees use by <a href="https://www.torproject.org/torusers.html.en">many
|
||||
Tor sees use by <a href="https://www.torproject.org/about/torusers">many
|
||||
important segments of the population</a>, including whistle blowers,
|
||||
journalists, Chinese dissidents skirting the Great Firewall and oppressive
|
||||
censorship, abuse victims, stalker targets, the US military, and law
|
||||
enforcement, just to name a few. While Tor is not designed for malicious
|
||||
computer users, it is true that they can use the network for malicious ends.
|
||||
In reality however, the actual amount of <a
|
||||
href="https://www.torproject.org/faq-abuse.html">abuse</a> is quite low. This
|
||||
href="https://www.torproject.org/docs/faq-abuse">abuse</a> is quite low. This
|
||||
is largely because criminals and hackers have significantly better access to
|
||||
privacy and anonymity than do the regular users whom they prey upon. Criminals
|
||||
can and do <a
|
||||
@@ -59,44 +65,41 @@ powerful networks</a> than Tor on a daily basis. Thus, in the mind of this
|
||||
operator, the social need for easily accessible censorship-resistant private,
|
||||
anonymous communication trumps the risk of unskilled bad actors, who are
|
||||
almost always more easily uncovered by traditional police work than by
|
||||
extensive monitoring and surveillance anyway.
|
||||
extensive monitoring and surveillance anyway.</p>
|
||||
|
||||
<p>
|
||||
|
||||
In terms of applicable law, the best way to understand Tor is to consider it a
|
||||
network of routers operating as common carriers, much like the Internet
|
||||
backbone. However, unlike the Internet backbone routers, Tor routers
|
||||
explicitly do not contain identifiable routing information about the source of
|
||||
a packet, and no single Tor node can determine both the origin and destination
|
||||
of a given transmission.
|
||||
of a given transmission.</p>
|
||||
|
||||
<p>
|
||||
|
||||
As such, there is little the operator of this router can do to help you track
|
||||
the connection further. This router maintains no logs of any of the Tor
|
||||
traffic, so there is little that can be done to trace either legitimate or
|
||||
illegitimate traffic (or to filter one from the other). Attempts to
|
||||
seize this router will accomplish nothing.
|
||||
seize this router will accomplish nothing.</p>
|
||||
|
||||
<!-- FIXME: US-Only section. Remove if you are a non-US operator -->
|
||||
|
||||
<p>
|
||||
|
||||
<!--- FIXME: US-Only section. Remove if you are a non-US operator -->
|
||||
|
||||
Furthermore, this machine also serves as a carrier of email, which means that
|
||||
its contents are further protected under the ECPA. <a
|
||||
href="http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00002707----000-.html">18
|
||||
USC 2707</a> explicitly allows for civil remedies ($1000/account
|
||||
<i><b><u>plus</u></b></i> legal fees)
|
||||
<i><b>plus</b></i> legal fees)
|
||||
in the event of a seizure executed without good faith or probable cause (it
|
||||
should be clear at this point that traffic with an originating IP address of
|
||||
FIXME_DNS_NAME should not constitute probable cause to seize the
|
||||
machine). Similar considerations exist for 1st amendment content on this
|
||||
machine.
|
||||
|
||||
<p>
|
||||
machine.</p>
|
||||
|
||||
<!-- FIXME: May or may not be US-only. Some non-US tor nodes have in
|
||||
fact reported DMCA harassment... -->
|
||||
fact reported DMCA harassment... -->
|
||||
|
||||
<p>
|
||||
If you are a representative of a company who feels that this router is being
|
||||
used to violate the DMCA, please be aware that this machine does not host or
|
||||
contain any illegal content. Also be aware that network infrastructure
|
||||
@@ -105,36 +108,37 @@ equipment, in accordance with <a
|
||||
href="http://www4.law.cornell.edu/uscode/html/uscode17/usc_sec_17_00000512----000-.html">DMCA
|
||||
"safe harbor" provisions</a>. In other words, you will have just as much luck
|
||||
sending a takedown notice to the Internet backbone providers. Please consult
|
||||
<a href="https://www.torproject.org/eff/tor-dmca-response.html">EFF's prepared
|
||||
response</a> for more information on this matter.
|
||||
<a href="https://www.torproject.org/eff/tor-dmca-response">EFF's prepared
|
||||
response</a> for more information on this matter.</p>
|
||||
|
||||
<p>For more information, please consult the following documentation:
|
||||
<p>For more information, please consult the following documentation:</p>
|
||||
|
||||
<ol>
|
||||
<li><a href="https://www.torproject.org/overview.html">Tor Overview</a></li>
|
||||
<li><a href="https://www.torproject.org/faq-abuse.html">Tor Abuse FAQ</a></li>
|
||||
<li><a href="https://www.torproject.org/eff/tor-legal-faq.html">Tor Legal FAQ</a></li>
|
||||
<li><a href="https://www.torproject.org/about/overview">Tor Overview</a></li>
|
||||
<li><a href="https://www.torproject.org/docs/faq-abuse">Tor Abuse FAQ</a></li>
|
||||
<li><a href="https://www.torproject.org/eff/tor-legal-faq">Tor Legal FAQ</a></li>
|
||||
</ol>
|
||||
<p>
|
||||
|
||||
<p>
|
||||
That being said, if you still have a complaint about the router, you may
|
||||
email the <a href="mailto:FIXME_YOUR_EMAIL_ADDRESS">maintainer</a>. If
|
||||
complaints are related to a particular service that is being abused, I will
|
||||
consider removing that service from my exit policy, which would prevent my
|
||||
router from allowing that traffic to exit through it. I can only do this on an
|
||||
IP+destination port basis, however. Common P2P ports are
|
||||
already blocked.
|
||||
already blocked.</p>
|
||||
|
||||
<p>You also have the option of blocking this IP address and others on
|
||||
<p>
|
||||
You also have the option of blocking this IP address and others on
|
||||
the Tor network if you so desire. The Tor project provides a <a
|
||||
href="https://tor-svn.freehaven.net/svn/tor/trunk/contrib/exitlist">python script</a> to
|
||||
extract all IP addresses of Tor exit nodes, and an official <a
|
||||
href="https://www.torproject.org/tordnsel/">DNSRBL</a> is also available to
|
||||
href="https://check.torproject.org/cgi-bin/TorBulkExitList.py">web service</a>
|
||||
to fetch a list of all IP addresses of Tor exit nodes that allow exiting to a
|
||||
specified IP:port combination, and an official <a
|
||||
href="https://www.torproject.org/tordnsel/dist/">DNSRBL</a> is also available to
|
||||
determine if a given IP address is actually a Tor exit server. Please
|
||||
be considerate
|
||||
when using these options. It would be unfortunate to deny all Tor users access
|
||||
to your site indefinitely simply because of a few bad apples.
|
||||
to your site indefinitely simply because of a few bad apples.</p>
|
||||
|
||||
</body>
|
||||
</html>
|
||||
|
||||
|
||||
+1
-1
@@ -907,7 +907,7 @@ This directive can be specified multiple times to bind to multiple
|
||||
addresses/ports.
|
||||
.LP
|
||||
.TP
|
||||
\fBPublishServerDescriptor \fR\fB0\fR|\fB1\fR|\fBv1\fR|\fBv2\fR|\fBv3\fR|\fBbridge\fR|\fBhidserv\fR, ...\fP
|
||||
\fBPublishServerDescriptor \fR\fB0\fR|\fB1\fR|\fBv1\fR|\fBv2\fR|\fBv3\fR|\fBbridge\fR, ...\fP
|
||||
This option is only considered if you have an ORPort defined. You can
|
||||
choose multiple arguments, separated by commas.
|
||||
|
||||
|
||||
+28
-6
@@ -1505,8 +1505,10 @@ crypto_hmac_sha1(char *hmac_out,
|
||||
|
||||
/* DH */
|
||||
|
||||
/** Shared P parameter for our DH key exchanged. */
|
||||
/** Shared P parameter for our circuit-crypto DH key exchanges. */
|
||||
static BIGNUM *dh_param_p = NULL;
|
||||
/** Shared P parameter for our TLS DH key exchanges. */
|
||||
static BIGNUM *dh_param_p_tls = NULL;
|
||||
/** Shared G parameter for our DH key exchanges. */
|
||||
static BIGNUM *dh_param_g = NULL;
|
||||
|
||||
@@ -1515,14 +1517,16 @@ static BIGNUM *dh_param_g = NULL;
|
||||
static void
|
||||
init_dh_param(void)
|
||||
{
|
||||
BIGNUM *p, *g;
|
||||
BIGNUM *p, *p2, *g;
|
||||
int r;
|
||||
if (dh_param_p && dh_param_g)
|
||||
if (dh_param_p && dh_param_g && dh_param_p_tls)
|
||||
return;
|
||||
|
||||
p = BN_new();
|
||||
p2 = BN_new();
|
||||
g = BN_new();
|
||||
tor_assert(p);
|
||||
tor_assert(p2);
|
||||
tor_assert(g);
|
||||
|
||||
/* This is from rfc2409, section 6.2. It's a safe prime, and
|
||||
@@ -1536,10 +1540,20 @@ init_dh_param(void)
|
||||
"A637ED6B0BFF5CB6F406B7EDEE386BFB5A899FA5AE9F24117C4B1FE6"
|
||||
"49286651ECE65381FFFFFFFFFFFFFFFF");
|
||||
tor_assert(r);
|
||||
/* This is the 1024-bit safe prime that Apache uses for its DH stuff; see
|
||||
* modules/ssl/ssl_engine_dh.c */
|
||||
r = BN_hex2bn(&p2,
|
||||
"D67DE440CBBBDC1936D693D34AFD0AD50C84D239A45F520BB88174CB98"
|
||||
"BCE951849F912E639C72FB13B4B4D7177E16D55AC179BA420B2A29FE324A"
|
||||
"467A635E81FF5901377BEDDCFD33168A461AAD3B72DAE8860078045B07A7"
|
||||
"DBCA7874087D1510EA9FCC9DDD330507DD62DB88AEAA747DE0F4D6E2BD68"
|
||||
"B0E7393E0F24218EB3");
|
||||
tor_assert(r);
|
||||
|
||||
r = BN_set_word(g, 2);
|
||||
tor_assert(r);
|
||||
dh_param_p = p;
|
||||
dh_param_p_tls = p2;
|
||||
dh_param_g = g;
|
||||
}
|
||||
|
||||
@@ -1548,18 +1562,26 @@ init_dh_param(void)
|
||||
/** Allocate and return a new DH object for a key exchange.
|
||||
*/
|
||||
crypto_dh_env_t *
|
||||
crypto_dh_new(void)
|
||||
crypto_dh_new(int dh_type)
|
||||
{
|
||||
crypto_dh_env_t *res = tor_malloc_zero(sizeof(crypto_dh_env_t));
|
||||
|
||||
tor_assert(dh_type == DH_TYPE_CIRCUIT || dh_type == DH_TYPE_TLS ||
|
||||
dh_type == DH_TYPE_REND);
|
||||
|
||||
if (!dh_param_p)
|
||||
init_dh_param();
|
||||
|
||||
if (!(res->dh = DH_new()))
|
||||
goto err;
|
||||
|
||||
if (!(res->dh->p = BN_dup(dh_param_p)))
|
||||
goto err;
|
||||
if (dh_type == DH_TYPE_TLS) {
|
||||
if (!(res->dh->p = BN_dup(dh_param_p_tls)))
|
||||
goto err;
|
||||
} else {
|
||||
if (!(res->dh->p = BN_dup(dh_param_p)))
|
||||
goto err;
|
||||
}
|
||||
|
||||
if (!(res->dh->g = BN_dup(dh_param_g)))
|
||||
goto err;
|
||||
|
||||
+4
-1
@@ -159,7 +159,10 @@ void crypto_hmac_sha1(char *hmac_out,
|
||||
const char *msg, size_t msg_len);
|
||||
|
||||
/* Key negotiation */
|
||||
crypto_dh_env_t *crypto_dh_new(void);
|
||||
#define DH_TYPE_CIRCUIT 1
|
||||
#define DH_TYPE_REND 2
|
||||
#define DH_TYPE_TLS 3
|
||||
crypto_dh_env_t *crypto_dh_new(int dh_type);
|
||||
int crypto_dh_get_bytes(crypto_dh_env_t *dh);
|
||||
int crypto_dh_generate_public(crypto_dh_env_t *dh);
|
||||
int crypto_dh_get_public(crypto_dh_env_t *dh, char *pubkey_out,
|
||||
|
||||
+1
-1
@@ -684,7 +684,7 @@ tor_tls_context_new(crypto_pk_env_t *identity, unsigned int key_lifetime)
|
||||
if (!SSL_CTX_check_private_key(result->ctx))
|
||||
goto error;
|
||||
{
|
||||
crypto_dh_env_t *dh = crypto_dh_new();
|
||||
crypto_dh_env_t *dh = crypto_dh_new(DH_TYPE_TLS);
|
||||
SSL_CTX_set_tmp_dh(result->ctx, _crypto_dh_env_get_dh(dh));
|
||||
crypto_dh_free(dh);
|
||||
}
|
||||
|
||||
+3410
-1822
File diff suppressed because it is too large
Load Diff
+8
-4
@@ -2878,7 +2878,9 @@ compute_publishserverdescriptor(or_options_t *options)
|
||||
else if (!strcasecmp(string, "bridge"))
|
||||
*auth |= BRIDGE_AUTHORITY;
|
||||
else if (!strcasecmp(string, "hidserv"))
|
||||
*auth |= HIDSERV_AUTHORITY;
|
||||
log_warn(LD_CONFIG,
|
||||
"PublishServerDescriptor hidserv is invalid. See "
|
||||
"PublishHidServDescriptors.");
|
||||
else if (!strcasecmp(string, "") || !strcmp(string, "0"))
|
||||
/* no authority */;
|
||||
else
|
||||
@@ -3368,6 +3370,11 @@ options_validate(or_options_t *old_options, or_options_t *options,
|
||||
"RelayBandwidthBurst", msg) < 0)
|
||||
return -1;
|
||||
|
||||
if (options->RelayBandwidthRate && !options->RelayBandwidthBurst)
|
||||
options->RelayBandwidthBurst = options->RelayBandwidthRate;
|
||||
if (options->RelayBandwidthBurst && !options->RelayBandwidthRate)
|
||||
options->RelayBandwidthRate = options->RelayBandwidthBurst;
|
||||
|
||||
if (server_mode(options)) {
|
||||
if (options->BandwidthRate < ROUTER_REQUIRED_MIN_BANDWIDTH) {
|
||||
r = tor_snprintf(buf, sizeof(buf),
|
||||
@@ -3399,9 +3406,6 @@ options_validate(or_options_t *old_options, or_options_t *options,
|
||||
}
|
||||
}
|
||||
|
||||
if (options->RelayBandwidthRate && !options->RelayBandwidthBurst)
|
||||
options->RelayBandwidthBurst = options->RelayBandwidthRate;
|
||||
|
||||
if (options->RelayBandwidthRate > options->RelayBandwidthBurst)
|
||||
REJECT("RelayBandwidthBurst must be at least equal "
|
||||
"to RelayBandwidthRate.");
|
||||
|
||||
+2
-2
@@ -173,7 +173,7 @@ onion_skin_create(crypto_pk_env_t *dest_router_key,
|
||||
*handshake_state_out = NULL;
|
||||
memset(onion_skin_out, 0, ONIONSKIN_CHALLENGE_LEN);
|
||||
|
||||
if (!(dh = crypto_dh_new()))
|
||||
if (!(dh = crypto_dh_new(DH_TYPE_CIRCUIT)))
|
||||
goto err;
|
||||
|
||||
dhbytes = crypto_dh_get_bytes(dh);
|
||||
@@ -247,7 +247,7 @@ onion_skin_server_handshake(const char *onion_skin, /*ONIONSKIN_CHALLENGE_LEN*/
|
||||
goto err;
|
||||
}
|
||||
|
||||
dh = crypto_dh_new();
|
||||
dh = crypto_dh_new(DH_TYPE_CIRCUIT);
|
||||
if (crypto_dh_get_public(dh, handshake_reply_out, DH_KEY_LEN)) {
|
||||
log_info(LD_GENERAL, "crypto_dh_get_public failed.");
|
||||
goto err;
|
||||
|
||||
+2
-2
@@ -1209,8 +1209,8 @@ policy_summarize(smartlist_t *policy)
|
||||
accepts_str = smartlist_join_strings(accepts, ",", 0, &accepts_len);
|
||||
rejects_str = smartlist_join_strings(rejects, ",", 0, &rejects_len);
|
||||
|
||||
if (rejects_len > MAX_EXITPOLICY_SUMMARY_LEN &&
|
||||
accepts_len > MAX_EXITPOLICY_SUMMARY_LEN) {
|
||||
if (rejects_len > MAX_EXITPOLICY_SUMMARY_LEN-strlen("reject")-1 &&
|
||||
accepts_len > MAX_EXITPOLICY_SUMMARY_LEN-strlen("accept")-1) {
|
||||
char *c;
|
||||
shorter_str = accepts_str;
|
||||
prefix = "accept";
|
||||
|
||||
+1
-1
@@ -130,7 +130,7 @@ rend_client_send_introduction(origin_circuit_t *introcirc,
|
||||
cpath = rendcirc->build_state->pending_final_cpath =
|
||||
tor_malloc_zero(sizeof(crypt_path_t));
|
||||
cpath->magic = CRYPT_PATH_MAGIC;
|
||||
if (!(cpath->dh_handshake_state = crypto_dh_new())) {
|
||||
if (!(cpath->dh_handshake_state = crypto_dh_new(DH_TYPE_REND))) {
|
||||
log_warn(LD_BUG, "Internal error: couldn't allocate DH.");
|
||||
goto err;
|
||||
}
|
||||
|
||||
@@ -1151,7 +1151,7 @@ rend_service_introduce(origin_circuit_t *circuit, const uint8_t *request,
|
||||
}
|
||||
|
||||
/* Try DH handshake... */
|
||||
dh = crypto_dh_new();
|
||||
dh = crypto_dh_new(DH_TYPE_REND);
|
||||
if (!dh || crypto_dh_generate_public(dh)<0) {
|
||||
log_warn(LD_BUG,"Internal error: couldn't build DH state "
|
||||
"or generate public key.");
|
||||
|
||||
@@ -1583,6 +1583,10 @@ extrainfo_parse_entry_from_string(const char *s, const char *end,
|
||||
authority_cert_t *
|
||||
authority_cert_parse_from_string(const char *s, const char **end_of_string)
|
||||
{
|
||||
/** Reject any certificate at least this big; it is probably an overflow, an
|
||||
* attack, a bug, or some other nonsense. */
|
||||
#define MAX_CERT_SIZE (128*1024)
|
||||
|
||||
authority_cert_t *cert = NULL, *old_cert;
|
||||
smartlist_t *tokens = NULL;
|
||||
char digest[DIGEST_LEN];
|
||||
@@ -1609,6 +1613,12 @@ authority_cert_parse_from_string(const char *s, const char **end_of_string)
|
||||
++eos;
|
||||
len = eos - s;
|
||||
|
||||
if (len > MAX_CERT_SIZE) {
|
||||
log_warn(LD_DIR, "Certificate is far too big (at %lu bytes long); "
|
||||
"rejecting", (unsigned long)len);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
tokens = smartlist_create();
|
||||
area = memarea_new();
|
||||
if (tokenize_string(area,s, eos, tokens, dir_key_certificate_table, 0) < 0) {
|
||||
@@ -3024,6 +3034,9 @@ get_next_token(memarea_t *area,
|
||||
/** Reject any object at least this big; it is probably an overflow, an
|
||||
* attack, a bug, or some other nonsense. */
|
||||
#define MAX_UNPARSED_OBJECT_SIZE (128*1024)
|
||||
/** Reject any line at least this big; it is probably an overflow, an
|
||||
* attack, a bug, or some other nonsense. */
|
||||
#define MAX_LINE_LENGTH (128*1024)
|
||||
|
||||
const char *next, *eol, *obstart;
|
||||
size_t obname_len;
|
||||
@@ -3043,6 +3056,10 @@ get_next_token(memarea_t *area,
|
||||
eol = memchr(*s, '\n', eos-*s);
|
||||
if (!eol)
|
||||
eol = eos;
|
||||
if (eol - *s > MAX_LINE_LENGTH) {
|
||||
RET_ERR("Line far too long");
|
||||
}
|
||||
|
||||
next = find_whitespace_eos(*s, eol);
|
||||
|
||||
if (!strcmp_len(*s, "opt", next-*s)) {
|
||||
|
||||
+2
-2
@@ -404,8 +404,8 @@ test_buffers(void)
|
||||
static void
|
||||
test_crypto_dh(void)
|
||||
{
|
||||
crypto_dh_env_t *dh1 = crypto_dh_new();
|
||||
crypto_dh_env_t *dh2 = crypto_dh_new();
|
||||
crypto_dh_env_t *dh1 = crypto_dh_new(DH_TYPE_CIRCUIT);
|
||||
crypto_dh_env_t *dh2 = crypto_dh_new(DH_TYPE_CIRCUIT);
|
||||
char p1[DH_BYTES];
|
||||
char p2[DH_BYTES];
|
||||
char s1[DH_BYTES];
|
||||
|
||||
Reference in New Issue
Block a user