mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
cmux: Don't pick a marked for close circuit as active
Fixes #25312 Signed-off-by: David Goulet <dgoulet@torproject.org>
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
o Minor bugfixes (circuit):
|
||||
- Fix a tiny window where a circuit can be chosen as active but is marked
|
||||
for close. Fixes bug 25312; bugfix on 0.2.4.4-alpha.
|
||||
@@ -35,6 +35,7 @@
|
||||
#include <math.h>
|
||||
|
||||
#include "core/or/or.h"
|
||||
#include "core/or/circuit_st.h"
|
||||
#include "core/or/circuitmux.h"
|
||||
#include "core/or/circuitmux_ewma.h"
|
||||
#include "lib/crypt_ops/crypto_rand.h"
|
||||
@@ -382,10 +383,17 @@ ewma_pick_active_circuit(circuitmux_t *cmux,
|
||||
|
||||
pol = TO_EWMA_POL_DATA(pol_data);
|
||||
|
||||
if (smartlist_len(pol->active_circuit_pqueue) > 0) {
|
||||
for (int i = 0; i < smartlist_len(pol->active_circuit_pqueue); i++) {
|
||||
/* Get the head of the queue */
|
||||
cell_ewma = smartlist_get(pol->active_circuit_pqueue, 0);
|
||||
cell_ewma = smartlist_get(pol->active_circuit_pqueue, i);
|
||||
circ = cell_ewma_to_circuit(cell_ewma);
|
||||
/* Don't send back closed circuit. This is possible because the circuit
|
||||
* is detached from the cmux before the circuit gets freed and not when
|
||||
* marked for close. Because of that, there is a window where a closed
|
||||
* circuit can be picked here. See #25312. */
|
||||
if (circ->marked_for_close) {
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
return circ;
|
||||
|
||||
Reference in New Issue
Block a user