Commit Graph
1507 Commits
Author SHA1 Message Date
Roger Dingledine 109ba37d54 fold in latest changes entries 2011-05-14 00:21:12 -04:00
Roger Dingledine 2bd2c10fcb fold in changes file 2011-05-10 23:05:37 -04:00
Roger Dingledine b36a837f08 fold in changes files for 0.2.1.31 2011-05-10 22:36:29 -04:00
Roger Dingledine 1855b4ebfd a blurb for 0.2.1.30 2011-02-23 03:24:32 -05:00
Roger Dingledine feabf2eb6c fold in last two changes files 2011-02-22 22:56:57 -05:00
Roger Dingledine 6168d2e975 fold in more changes files 2011-02-22 15:00:07 -05:00
Roger Dingledine 026204088a fold in changes files so far 2011-02-11 01:15:21 -05:00
Roger Dingledine 2cb9ed2cd3 final changelog cleanup. it'll do. 2011-01-15 19:43:34 -05:00
Roger Dingledine 9be473b82f amend changelog for fixing --enable-openbsd-malloc 2011-01-15 18:23:30 -05:00
Roger Dingledine f90fcaff64 clean up changelog more, add blurb 2011-01-15 17:29:42 -05:00
Roger Dingledine bcd788f33f start cleaning up 0.2.1.29 changelog 2011-01-15 16:25:52 -05:00
Roger Dingledine 3936267fd9 add blurb, change release date 2010-12-16 19:22:47 -05:00
Roger Dingledine 4170a11398 fold in changelog entry 2010-12-16 17:02:21 -05:00
Roger Dingledine df16e99718 merge changes files 2010-12-16 16:31:52 -05:00
Roger Dingledine 924f7bf9a5 integrate the changelog entry 2010-11-23 22:26:48 -05:00
Roger Dingledine d05323c802 fold in changelog 2010-11-23 00:06:43 -05:00
Roger Dingledine 05319e4d59 fold in geoip changes commit 2010-11-22 22:36:35 -05:00
Roger Dingledine a55b44dc00 add blurbs to recent releases 2010-11-22 00:04:14 -05:00
Roger Dingledine 32ca2bd0f5 fold in the pending changes 2010-11-21 17:47:03 -05:00
Roger Dingledine 77f30fb55b bump to 0.2.1.26, and pick a release date 2010-04-30 13:40:00 -04:00
Roger Dingledine ba97ab4eb2 fold in the changelog entries 2010-04-30 13:36:13 -04:00
Roger Dingledine 6b7e5eb5f1 give us a blurb; add stanza to the releasenotes 2010-03-16 00:44:30 -04:00
Roger Dingledine 94dccce3fa bump to 0.2.1.25
it's perfect, let's ship it
2010-03-15 18:08:29 -04:00
Roger Dingledine 841351e612 clean up the 0.2.1.25 changelog 2010-03-06 22:39:34 -05:00
Nick Mathewson 3ff092391b Apply Roger's bug 1269 fix.
From http://archives.seul.org/tor/relays/Mar-2010/msg00006.html :

   As I understand it, the bug should show up on relays that don't set
   Address to an IP address (so they need to resolve their Address
   line or their hostname to guess their IP address), and their
   hostname or Address line fails to resolve -- at that point they'll
   pick a random 4 bytes out of memory and call that their address. At
   the same time, relays that *do* successfully resolve their address
   will ignore the result, and only come up with a useful address if
   their interface address happens to be a public IP address.
2010-03-04 18:37:40 -05:00
Sebastian Hahn b67657bd95 Properly handle non-terminated strings
Treat strings returned from signed_descriptor_get_body_impl() as not
NUL-terminated. Since the length of the strings is available, this is
not a big problem.

Discovered by rieo.
2010-02-27 02:13:22 +01:00
Sebastian Hahn 86828e2004 Proper NULL checking in circuit_list_path_impl()
Another dereference-then-NULL-check sequence. No reports of this bug
triggered in the wild. Fixes bugreport 1256.

Thanks to ekir for discovering and reporting this bug.
2010-02-26 05:53:26 +01:00
Sebastian Hahn f36c36f4a8 Proper NULL checking for hsdesc publication
Fix a dereference-then-NULL-check sequence. This bug wasn't triggered
in the wild, but we should fix it anyways in case it ever happens.
Also make sure users get a note about this being a bug when they
see it in their log.

Thanks to ekir for discovering and reporting this bug.
2010-02-26 05:49:34 +01:00
Sebastian Hahn a9802d3322 Zero a cipher completely before freeing it
We used to only zero the first ptrsize bytes of the cipher. Since
cipher is large enough, we didn't zero too many bytes. Discovered
and fixed by ekir. Fixes bug 1254.
2010-02-26 05:47:25 +01:00
Roger Dingledine b9696b96da bump to 0.2.1.24 2010-02-21 17:27:12 -05:00
Nick Mathewson 428c07ea0d Add changelog for latest openssl fix 2010-02-18 11:54:26 -05:00
Roger Dingledine c9a3781580 give it a blurb, update the date 2010-02-13 14:10:57 -05:00
Roger Dingledine 3e6a37e61e new dannenberg address; make moria2's demise official. 2010-02-12 14:31:08 -05:00
Roger Dingledine 33f8dcae6a prepare for 0.2.1.23 2010-02-12 12:35:40 -05:00
Sebastian Hahn a168cd2a54 Don't use gethostbyname() in resolve_my_address()
Tor has tor_lookup_hostname(), which prefers ipv4 addresses automatically.
Bug 1244 occured because gethostbyname() returned an ipv6 address, which
Tor cannot handle currently. Fixes bug 1244; bugfix on 0.0.2pre25.
Reported by Mike Mestnik.
2010-02-08 15:49:54 +01:00
Sebastian Hahn dfee173289 lookup_last_hid_serv_request() could overflow and leak memory
The problem was that we didn't allocate enough memory on 32-bit
platforms with 64-bit time_t. The memory leak occured every time
we fetched a hidden service descriptor we've fetched before.
2010-02-07 06:37:35 +01:00
Nick Mathewson 1744e447a1 Decide whether to use SSL flags based on runtime OpenSSL version.
We need to do this because Apple doesn't update its dev-tools headers
when it updates its libraries in a security patch.  On the bright
side, this might get us out of shipping a statically linked OpenSSL on
OSX.

May fix bug 1225.

[backported]
2010-01-29 17:17:47 -05:00
Roger Dingledine 1fc94bfd0e spread guard rotation out throughout the month 2010-01-19 17:52:52 -05:00
Roger Dingledine 0642ab2428 weight guard choice by bandwidth; discard old guards 2010-01-19 17:30:52 -05:00
Roger Dingledine f43f87db5b bump to 0.2.1.22, and give it a changelog 2010-01-19 14:43:05 -05:00
Roger Dingledine adae600715 rotate keys for moria1 and gabelmoo 2010-01-19 14:12:39 -05:00
Roger Dingledine 79eaeef1cd stop bridge authorities from leaking their bridge list 2010-01-17 19:41:22 -05:00
Roger Dingledine 5201e05fc5 bump to 0.2.1.21 so we can release 2009-12-21 03:22:49 -05:00
Nick Mathewson 1c87a27574 Fix bug 1173: remove an assert(unsigned >= 0). 2009-12-15 15:51:59 -05:00
Roger Dingledine a89f51c936 fix race condition that can cause crashes at client or exit relay
Avoid crashing if the client is trying to upload many bytes and the
circuit gets torn down at the same time, or if the flip side
happens on the exit relay. Bugfix on 0.2.0.1-alpha; fixes bug 1150.
2009-11-23 10:13:50 -05:00
Roger Dingledine 0656c12b07 add the 0.2.1.20 changelog blurb, plus update the releasenotes 2009-11-17 15:35:14 -05:00
Nick Mathewson ce0a89e262 Make Tor work with OpenSSL 0.9.8l
To fix a major security problem related to incorrect use of
SSL/TLS renegotiation, OpenSSL has turned off renegotiation by
default.  We are not affected by this security problem, however,
since we do renegotiation right.  (Specifically, we never treat a
renegotiated credential as authenticating previous communication.)
Nevertheless, OpenSSL's new behavior requires us to explicitly
turn renegotiation back on in order to get our protocol working
again.

Amusingly, this is not so simple as "set the flag when you create
the SSL object" , since calling connect or accept seems to clear
the flags.

For belt-and-suspenders purposes, we clear the flag once the Tor
handshake is done.  There's no way to exploit a second handshake
either, but we might as well not allow it.
2009-11-05 18:13:08 -05:00
Nick Mathewson e50e739556 Add changelog to describe coverity fixes for 0.2.1.21 2009-10-26 22:39:42 -04:00
Nick Mathewson 56048637a5 Only send the if_modified_since header for a v3 consensus.
Spotted by xmux; bugfix on 0.2.0.10-alpha.
(Bug introduced by 20b10859)
2009-10-26 20:14:11 -04:00
Roger Dingledine 16dc543851 bump to 0.2.1.20 2009-10-15 12:14:18 -04:00