diff options
author | teor <teor@torproject.org> | 2019-11-25 12:37:07 +1000 |
---|---|---|
committer | teor <teor@torproject.org> | 2019-11-25 12:37:07 +1000 |
commit | 26071aa3be8f26d7e81384f1d40bb1d5fe94cca0 (patch) | |
tree | 17caa24248899bdbf3cd2261d43b3487578a3aef /src/feature/hs | |
parent | 29eb7b07ef5d5af0c54bbc36804363a0bfdd3252 (diff) | |
parent | 055f5d4d1b2c8ea5a85691f7110e82a9c468b6dd (diff) | |
download | tor-26071aa3be8f26d7e81384f1d40bb1d5fe94cca0.tar.gz tor-26071aa3be8f26d7e81384f1d40bb1d5fe94cca0.zip |
Merge branch 'maint-0.4.0' into maint-0.4.1
Diffstat (limited to 'src/feature/hs')
-rw-r--r-- | src/feature/hs/hs_client.c | 8 | ||||
-rw-r--r-- | src/feature/hs/hs_service.c | 9 |
2 files changed, 15 insertions, 2 deletions
diff --git a/src/feature/hs/hs_client.c b/src/feature/hs/hs_client.c index f8d47f0114..492e77faff 100644 --- a/src/feature/hs/hs_client.c +++ b/src/feature/hs/hs_client.c @@ -682,8 +682,12 @@ setup_intro_circ_auth_key(origin_circuit_t *circ) tor_assert(circ); desc = hs_cache_lookup_as_client(&circ->hs_ident->identity_pk); - if (BUG(desc == NULL)) { - /* Opening intro circuit without the descriptor is no good... */ + if (desc == NULL) { + /* There is a very small race window between the opening of this circuit + * and the client descriptor cache that gets purged (NEWNYM) or the + * cleaned up because it expired. Mark the circuit for close so a new + * descriptor fetch can occur. */ + circuit_mark_for_close(TO_CIRCUIT(circ), END_CIRC_REASON_INTERNAL); goto end; } diff --git a/src/feature/hs/hs_service.c b/src/feature/hs/hs_service.c index 2835912742..d1ca33b12e 100644 --- a/src/feature/hs/hs_service.c +++ b/src/feature/hs/hs_service.c @@ -1652,6 +1652,15 @@ build_desc_intro_points(const hs_service_t *service, DIGEST256MAP_FOREACH(desc->intro_points.map, key, const hs_service_intro_point_t *, ip) { + if (!ip->circuit_established) { + /* Ignore un-established intro points. They can linger in that list + * because their circuit has not opened and they haven't been removed + * yet even though we have enough intro circuits. + * + * Due to #31561, it can stay in that list until rotation so this check + * prevents to publish an intro point without a circuit. */ + continue; + } hs_desc_intro_point_t *desc_ip = hs_desc_intro_point_new(); if (setup_desc_intro_point(&desc->signing_kp, ip, now, desc_ip) < 0) { hs_desc_intro_point_free(desc_ip); |