mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Merge branch 'maint-0.2.1' into release-0.2.1
This commit is contained in:
+1
-1
@@ -898,7 +898,7 @@ tor_tls_new(int sock, int isServer)
|
||||
|
||||
#ifdef SSL_set_tlsext_host_name
|
||||
/* Browsers use the TLS hostname extension, so we should too. */
|
||||
{
|
||||
if (!isServer) {
|
||||
char *fake_hostname = crypto_random_hostname(4,25, "www.",".com");
|
||||
SSL_set_tlsext_host_name(result->ssl, fake_hostname);
|
||||
tor_free(fake_hostname);
|
||||
|
||||
+68673
-28198
File diff suppressed because it is too large
Load Diff
+6
-3
@@ -251,6 +251,7 @@ buf_shrink_freelists(int free_all)
|
||||
{
|
||||
#ifdef ENABLE_BUF_FREELISTS
|
||||
int i;
|
||||
disable_control_logging();
|
||||
for (i = 0; freelists[i].alloc_size; ++i) {
|
||||
int slack = freelists[i].slack;
|
||||
assert_freelist_ok(&freelists[i]);
|
||||
@@ -259,12 +260,10 @@ buf_shrink_freelists(int free_all)
|
||||
(freelists[i].lowest_length - slack);
|
||||
int n_to_skip = freelists[i].cur_length - n_to_free;
|
||||
int orig_n_to_free = n_to_free, n_freed=0;
|
||||
int orig_n_to_skip = n_to_skip;
|
||||
int new_length = n_to_skip;
|
||||
chunk_t **chp = &freelists[i].head;
|
||||
chunk_t *chunk;
|
||||
log_info(LD_MM, "Cleaning freelist for %d-byte chunks: keeping %d, "
|
||||
"dropping %d.",
|
||||
(int)freelists[i].alloc_size, n_to_skip, n_to_free);
|
||||
while (n_to_skip) {
|
||||
tor_assert((*chp)->next);
|
||||
chp = &(*chp)->next;
|
||||
@@ -291,10 +290,14 @@ buf_shrink_freelists(int free_all)
|
||||
}
|
||||
// tor_assert(!n_to_free);
|
||||
freelists[i].cur_length = new_length;
|
||||
log_info(LD_MM, "Cleaned freelist for %d-byte chunks: kept %d, "
|
||||
"dropped %d.",
|
||||
(int)freelists[i].alloc_size, orig_n_to_skip, orig_n_to_free);
|
||||
}
|
||||
freelists[i].lowest_length = freelists[i].cur_length;
|
||||
assert_freelist_ok(&freelists[i]);
|
||||
}
|
||||
enable_control_logging();
|
||||
#else
|
||||
(void) free_all;
|
||||
#endif
|
||||
|
||||
@@ -3162,6 +3162,10 @@ learned_bridge_descriptor(routerinfo_t *ri, int from_cache)
|
||||
add_an_entry_guard(ri, 1);
|
||||
log_notice(LD_DIR, "new bridge descriptor '%s' (%s)", ri->nickname,
|
||||
from_cache ? "cached" : "fresh");
|
||||
/* set entry->made_contact so if it goes down we don't drop it from
|
||||
* our entry node list */
|
||||
entry_guard_register_connect_status(ri->cache_info.identity_digest,
|
||||
1, 0, now);
|
||||
if (first)
|
||||
routerlist_retry_directory_downloads(now);
|
||||
}
|
||||
@@ -3227,7 +3231,8 @@ bridges_retry_helper(int act)
|
||||
}
|
||||
}
|
||||
});
|
||||
log_debug(LD_DIR, "any_known %d, any_running %d", any_known, any_running);
|
||||
log_debug(LD_DIR, "%d: any_known %d, any_running %d",
|
||||
act, any_known, any_running);
|
||||
return any_known && !any_running;
|
||||
}
|
||||
|
||||
|
||||
+4
-2
@@ -922,6 +922,9 @@ add_default_trusted_dir_authorities(authority_type_t type)
|
||||
"193.23.244.244:80 7BE6 83E6 5D48 1413 21C5 ED92 F075 C553 64AC 7123",
|
||||
"urras orport=80 no-v2 v3ident=80550987E1D626E3EBA5E5E75A458DE0626D088C "
|
||||
"208.83.223.34:443 0AD3 FA88 4D18 F89E EA2D 89C0 1937 9E0E 7FD9 4417",
|
||||
"maatuska orport=80 no-v2 "
|
||||
"v3ident=49015F787433103580E3B66A1707A00E60F2D15B "
|
||||
"213.115.239.118:443 BD6A 8292 55CB 08E6 6FBE 7D37 4836 3586 E46B 3810",
|
||||
NULL
|
||||
};
|
||||
for (i=0; dirservers[i]; i++) {
|
||||
@@ -2425,8 +2428,7 @@ resolve_my_address(int warn_severity, or_options_t *options,
|
||||
}
|
||||
|
||||
tor_inet_ntoa(&in,tmpbuf,sizeof(tmpbuf));
|
||||
if (is_internal_IP(ntohl(in.s_addr), 0) &&
|
||||
options->_PublishServerDescriptor) {
|
||||
if (is_internal_IP(ntohl(in.s_addr), 0)) {
|
||||
/* make sure we're ok with publishing an internal IP */
|
||||
if (!options->DirServers && !options->AlternateDirAuthority) {
|
||||
/* if they are using the default dirservers, disallow internal IPs
|
||||
|
||||
+7
-6
@@ -735,12 +735,13 @@ run_connection_housekeeping(int i, time_t now)
|
||||
"Tor gave up on the connection");
|
||||
connection_mark_for_close(conn);
|
||||
conn->hold_open_until_flushed = 1;
|
||||
} else if (past_keepalive && !connection_state_is_open(conn)) {
|
||||
/* We never managed to actually get this connection open and happy. */
|
||||
log_info(LD_OR,"Expiring non-open OR connection to fd %d (%s:%d).",
|
||||
conn->s,conn->address, conn->port);
|
||||
connection_mark_for_close(conn);
|
||||
conn->hold_open_until_flushed = 1;
|
||||
} else if (!connection_state_is_open(conn)) {
|
||||
if (past_keepalive) {
|
||||
/* We never managed to actually get this connection open and happy. */
|
||||
log_info(LD_OR,"Expiring non-open OR connection to fd %d (%s:%d).",
|
||||
conn->s,conn->address, conn->port);
|
||||
connection_mark_for_close(conn);
|
||||
}
|
||||
} else if (we_are_hibernating() && !or_conn->n_circuits &&
|
||||
!buf_datalen(conn->outbuf)) {
|
||||
/* We're hibernating, there's no circuits, and nothing to flush.*/
|
||||
|
||||
+13
-4
@@ -1132,11 +1132,21 @@ update_consensus_networkstatus_fetch_time(time_t now)
|
||||
if (c) {
|
||||
long dl_interval;
|
||||
long interval = c->fresh_until - c->valid_after;
|
||||
long min_sec_before_caching = CONSENSUS_MIN_SECONDS_BEFORE_CACHING;
|
||||
time_t start;
|
||||
|
||||
if (min_sec_before_caching > interval/16) {
|
||||
/* Usually we allow 2-minutes slop factor in case clocks get
|
||||
desynchronized a little. If we're on a private network with
|
||||
a crazy-fast voting interval, though, 2 minutes may be too
|
||||
much. */
|
||||
min_sec_before_caching = interval/16;
|
||||
}
|
||||
|
||||
if (directory_fetches_dir_info_early(options)) {
|
||||
/* We want to cache the next one at some point after this one
|
||||
* is no longer fresh... */
|
||||
start = c->fresh_until + CONSENSUS_MIN_SECONDS_BEFORE_CACHING;
|
||||
start = c->fresh_until + min_sec_before_caching;
|
||||
/* But only in the first half-interval after that. */
|
||||
dl_interval = interval/2;
|
||||
} else {
|
||||
@@ -1150,10 +1160,9 @@ update_consensus_networkstatus_fetch_time(time_t now)
|
||||
* to choose the rest of the interval *after* them. */
|
||||
if (directory_fetches_dir_info_later(options)) {
|
||||
/* Give all the *clients* enough time to download the consensus. */
|
||||
start = start + dl_interval + CONSENSUS_MIN_SECONDS_BEFORE_CACHING;
|
||||
start = start + dl_interval + min_sec_before_caching;
|
||||
/* But try to get it before ours actually expires. */
|
||||
dl_interval = (c->valid_until - start) -
|
||||
CONSENSUS_MIN_SECONDS_BEFORE_CACHING;
|
||||
dl_interval = (c->valid_until - start) - min_sec_before_caching;
|
||||
}
|
||||
}
|
||||
if (dl_interval < 1)
|
||||
|
||||
+1
-1
@@ -544,7 +544,7 @@ typedef enum {
|
||||
#define END_STREAM_REASON_DESTROY 5
|
||||
#define END_STREAM_REASON_DONE 6
|
||||
#define END_STREAM_REASON_TIMEOUT 7
|
||||
/* 8 is unallocated for historical reasons. */
|
||||
#define END_STREAM_REASON_NOROUTE 8
|
||||
#define END_STREAM_REASON_HIBERNATING 9
|
||||
#define END_STREAM_REASON_INTERNAL 10
|
||||
#define END_STREAM_REASON_RESOURCELIMIT 11
|
||||
|
||||
@@ -26,6 +26,7 @@ stream_end_reason_to_control_string(int reason)
|
||||
case END_STREAM_REASON_DESTROY: return "DESTROY";
|
||||
case END_STREAM_REASON_DONE: return "DONE";
|
||||
case END_STREAM_REASON_TIMEOUT: return "TIMEOUT";
|
||||
case END_STREAM_REASON_NOROUTE: return "NOROUTE";
|
||||
case END_STREAM_REASON_HIBERNATING: return "HIBERNATING";
|
||||
case END_STREAM_REASON_INTERNAL: return "INTERNAL";
|
||||
case END_STREAM_REASON_RESOURCELIMIT: return "RESOURCELIMIT";
|
||||
@@ -60,6 +61,7 @@ stream_end_reason_to_string(int reason)
|
||||
case END_STREAM_REASON_DESTROY: return "destroyed";
|
||||
case END_STREAM_REASON_DONE: return "closed normally";
|
||||
case END_STREAM_REASON_TIMEOUT: return "gave up (timeout)";
|
||||
case END_STREAM_REASON_NOROUTE: return "no route to host";
|
||||
case END_STREAM_REASON_HIBERNATING: return "server is hibernating";
|
||||
case END_STREAM_REASON_INTERNAL: return "internal error at server";
|
||||
case END_STREAM_REASON_RESOURCELIMIT: return "server out of resources";
|
||||
@@ -102,6 +104,8 @@ stream_end_reason_to_socks5_response(int reason)
|
||||
return SOCKS5_SUCCEEDED;
|
||||
case END_STREAM_REASON_TIMEOUT:
|
||||
return SOCKS5_TTL_EXPIRED;
|
||||
case END_STREAM_REASON_NOROUTE:
|
||||
return SOCKS5_HOST_UNREACHABLE;
|
||||
case END_STREAM_REASON_RESOURCELIMIT:
|
||||
return SOCKS5_GENERAL_ERROR;
|
||||
case END_STREAM_REASON_HIBERNATING:
|
||||
@@ -162,6 +166,14 @@ errno_to_stream_end_reason(int e)
|
||||
S_CASE(ENOTCONN):
|
||||
S_CASE(ENETUNREACH):
|
||||
return END_STREAM_REASON_INTERNAL;
|
||||
E_CASE(EHOSTUNREACH):
|
||||
/* XXXX022
|
||||
* The correct behavior is END_STREAM_REASON_NOROUTE, but older
|
||||
* clients don't recognize it. So we're going to continue sending
|
||||
* "MISC" until 0.2.1.27 or later is "well established".
|
||||
*/
|
||||
/* return END_STREAM_REASON_NOROUTE; */
|
||||
return END_STREAM_REASON_MISC;
|
||||
S_CASE(ECONNREFUSED):
|
||||
return END_STREAM_REASON_CONNECTREFUSED;
|
||||
S_CASE(ECONNRESET):
|
||||
|
||||
+3
-1
@@ -648,7 +648,8 @@ edge_reason_is_retriable(int reason)
|
||||
reason == END_STREAM_REASON_RESOURCELIMIT ||
|
||||
reason == END_STREAM_REASON_EXITPOLICY ||
|
||||
reason == END_STREAM_REASON_RESOLVEFAILED ||
|
||||
reason == END_STREAM_REASON_MISC;
|
||||
reason == END_STREAM_REASON_MISC ||
|
||||
reason == END_STREAM_REASON_NOROUTE;
|
||||
}
|
||||
|
||||
/** Called when we receive an END cell on a stream that isn't open yet,
|
||||
@@ -743,6 +744,7 @@ connection_ap_process_end_not_open(
|
||||
case END_STREAM_REASON_RESOLVEFAILED:
|
||||
case END_STREAM_REASON_TIMEOUT:
|
||||
case END_STREAM_REASON_MISC:
|
||||
case END_STREAM_REASON_NOROUTE:
|
||||
if (client_dns_incr_failures(conn->socks_request->address)
|
||||
< MAX_RESOLVE_FAILURES) {
|
||||
/* We haven't retried too many times; reattach the connection. */
|
||||
|
||||
+13
-4
@@ -1177,10 +1177,16 @@ router_parse_entry_from_string(const char *s, const char *end,
|
||||
s = cp+1;
|
||||
}
|
||||
|
||||
if (allow_annotations && start_of_annotations != s) {
|
||||
if (tokenize_string(area,start_of_annotations,s,tokens,
|
||||
routerdesc_token_table,TS_NOCHECK)) {
|
||||
log_warn(LD_DIR, "Error tokenizing router descriptor (annotations).");
|
||||
if (start_of_annotations != s) { /* We have annotations */
|
||||
if (allow_annotations) {
|
||||
if (tokenize_string(area,start_of_annotations,s,tokens,
|
||||
routerdesc_token_table,TS_NOCHECK)) {
|
||||
log_warn(LD_DIR, "Error tokenizing router descriptor (annotations).");
|
||||
goto err;
|
||||
}
|
||||
} else {
|
||||
log_warn(LD_DIR, "Found unexpected annotations on router descriptor not "
|
||||
"loaded from disk. Dropping it.");
|
||||
goto err;
|
||||
}
|
||||
}
|
||||
@@ -3175,6 +3181,9 @@ tokenize_string(memarea_t *area,
|
||||
end = start+strlen(start);
|
||||
for (i = 0; i < _NIL; ++i)
|
||||
counts[i] = 0;
|
||||
|
||||
SMARTLIST_FOREACH(out, const directory_token_t *, t, ++counts[t->tp]);
|
||||
|
||||
while (*s < end && (!tok || tok->tp != _EOF)) {
|
||||
tok = get_next_token(area, s, end, table);
|
||||
if (tok->tp == _ERR) {
|
||||
|
||||
Reference in New Issue
Block a user