summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRoger Dingledine <arma@torproject.org>2010-01-17 19:41:22 -0500
committerRoger Dingledine <arma@torproject.org>2010-01-17 19:41:22 -0500
commit79eaeef1cdef7503e5e4368161fc169f1317eef6 (patch)
tree39daa9af33da548e6e8bb5faf2c362333dad09f1
parent5201e05fc55d479d95a8b908f6c33d2b88eee26c (diff)
downloadtor-79eaeef1cdef7503e5e4368161fc169f1317eef6.tar.gz
tor-79eaeef1cdef7503e5e4368161fc169f1317eef6.zip
stop bridge authorities from leaking their bridge list
-rw-r--r--ChangeLog7
-rw-r--r--src/or/directory.c3
2 files changed, 9 insertions, 1 deletions
diff --git a/ChangeLog b/ChangeLog
index cf6afcf500..0732265192 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,10 @@
+Changes in version 0.2.1.22 - 2010-??-??
+ o Major bugfixes:
+ - Stop bridge directory authorities from answering dbg-stability.txt
+ directory queries, which would let people fetch a list of all
+ bridge identities they track. Bugfix on 0.2.1.6-alpha.
+
+
Changes in version 0.2.1.21 - 2009-12-21
Tor 0.2.1.21 fixes an incompatibility with the most recent OpenSSL
library. If you use Tor on Linux / Unix and you're getting SSL
diff --git a/src/or/directory.c b/src/or/directory.c
index 8099e3376d..42341f1040 100644
--- a/src/or/directory.c
+++ b/src/or/directory.c
@@ -2956,7 +2956,8 @@ directory_handle_command_get(dir_connection_t *conn, const char *headers,
if (!strcmp(url,"/tor/dbg-stability.txt")) {
const char *stability;
size_t len;
- if (! authdir_mode_tests_reachability(options) ||
+ if (options->BridgeAuthoritativeDir ||
+ ! authdir_mode_tests_reachability(options) ||
! (stability = rep_hist_get_router_stability_doc(time(NULL)))) {
write_http_status_line(conn, 404, "Not found.");
goto done;