[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #31088 [Core Tor/Tor]: Check IPv4 and IPv6 private addresses in descriptors, first hops, and extends



#31088: Check IPv4 and IPv6 private addresses in descriptors, first hops, and
extends
-------------------------------------------------+-------------------------
 Reporter:  teor                                 |          Owner:  neel
     Type:  defect                               |         Status:
                                                 |  needs_review
 Priority:  Medium                               |      Milestone:  Tor:
                                                 |  unspecified
Component:  Core Tor/Tor                         |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  ipv6, tor-relay, tor-client, tor-    |  Actual Points:
  dirauth                                        |
Parent ID:  #24403                               |         Points:
 Reviewer:  nickm                                |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by teor):

 Replying to [comment:7 neel]:
 > I don't believe a null address will count as internal, but I removed the
 check because in `tor_addr_is_internal_()` at the end of the function on a
 null family (or any non-IPv4/IPv6):
 >
 > {{{
 >   /* unknown address family... assume it's not safe for external use */
 >   /* rather than tor_assert(0) */
 >   log_warn(LD_BUG, "tor_addr_is_internal() called from %s:%d with a "
 >            "non-IP address of type %d", filename, lineno,
 (int)v_family);
 >   tor_fragile_assert();
 >   return 1;
 > }}}
 >
 > So (I guess) it would report as internal anyways.

 We don't want to execute a tor_fragile_assert().

 So the null address checks are required, and we should treat a null
 address as a missing address:
 * if one address is null, use the result for the other address
 * if both addresses are null, reject, because the request can never
 succeed

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31088#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs