From f9bdb8a0da735caf263a72bdd0db847a78b64b53 Mon Sep 17 00:00:00 2001 From: Roger Dingledine Date: Sun, 14 Dec 2003 07:50:45 +0000 Subject: [PATCH] document aborted attempt to merge client dns cache with server dns cache svn:r930 --- src/or/connection_edge.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/or/connection_edge.c b/src/or/connection_edge.c index b7cbe41280..0b279b4d92 100644 --- a/src/or/connection_edge.c +++ b/src/or/connection_edge.c @@ -838,6 +838,11 @@ int connection_ap_can_use_exit(connection_t *conn, routerinfo_t *exit) /* ***** Client DNS code ***** */ /* XXX Perhaps this should get merged with the dns.c code somehow. */ +/* XXX But we can't just merge them, because then nodes that act as + * both OR and OP could be attacked: people could rig the dns cache + * by answering funny things to stream begin requests, and later + * other clients would reuse those funny addr's. Hm. + */ struct client_dns_entry { SPLAY_ENTRY(client_dns_entry) node; char *address;