Age | Commit message (Collapse) | Author | |
---|---|---|---|
2020-03-18 | Merge branch 'maint-0.4.1' into maint-0.4.2 | Nick Mathewson | |
2020-03-18 | Merge branch 'maint-0.3.5' into maint-0.4.1 | Nick Mathewson | |
2020-03-18 | Port rsa_private_key_too_long() to work on OpenSSL 1.1.0. | Nick Mathewson | |
2020-03-17 | Merge branch 'maint-0.4.1' into maint-0.4.2 | Nick Mathewson | |
2020-03-17 | Merge branch 'trove_2020_002_041' into maint-0.4.1 | Nick Mathewson | |
2020-03-17 | Merge branch 'trove_2020_002_035' into maint-0.3.5 | Nick Mathewson | |
2020-03-17 | Merge branch 'maint-0.4.1' into maint-0.4.2 | Nick Mathewson | |
2020-03-17 | Merge branch 'maint-0.3.5' into maint-0.4.1 | Nick Mathewson | |
2020-03-17 | Trivial bugfixes found during TROVE investigation. | George Kadianakis | |
2020-03-17 | Merge branch 'trove_2020_002_035' into trove_2020_002_041 | Nick Mathewson | |
2020-03-17 | Use >= consistently with max_bits. | Nick Mathewson | |
2020-03-17 | Extract key length check into a new function, and check more fields. | Nick Mathewson | |
In the openssl that I have, it should be safe to only check the size of n. But if I'm wrong, or if other openssls work differently, we should check whether any of the fields are too large. Issue spotted by Teor. | |||
2020-03-14 | Merge branch 'trove_2020_002_035' into trove_2020_002_041 | Nick Mathewson | |
2020-03-14 | Fix memory leak in crypto_pk_asn1_decode_private. | Nick Mathewson | |
(Deep, deep thanks to Taylor for reminding me to test this!) | |||
2020-03-14 | Revise TROVE-2020-002 fix to work on older OpenSSL versions. | Nick Mathewson | |
Although OpenSSL before 1.1.1 is no longer supported, it's possible that somebody is still using it with 0.3.5, so we probably shouldn't break it with this fix. | |||
2020-03-13 | Merge branch 'maint-0.3.5' into maint-0.4.1 | Nick Mathewson | |
2020-03-13 | Merge branch 'maint-0.4.1' into maint-0.4.2 | Nick Mathewson | |
2020-03-13 | Merge remote-tracking branch 'tor-github/pr/1693/head' into maint-0.3.5 | Nick Mathewson | |
2020-02-05 | Merge branch 'trove_2020_002_035' into trove_2020_002_041 | Nick Mathewson | |
Resolved Conflicts: src/feature/dirparse/parsecommon.c | |||
2020-02-05 | When parsing, reject >1024-bit RSA private keys sooner. | Nick Mathewson | |
Private-key validation is fairly expensive for long keys in openssl, so we need to avoid it sooner. | |||
2020-01-30 | Merge branch 'maint-0.4.1' into maint-0.4.2 | teor | |
2020-01-30 | Merge branch 'maint-0.4.0' into maint-0.4.1 | teor | |
2020-01-30 | Merge branch 'maint-0.3.5' into maint-0.4.0 | teor | |
2020-01-30 | Merge remote-tracking branch 'tor-github/pr/1614' into maint-0.3.5 | teor | |
2020-01-29 | Change BUG() messages in buf_flush_to_tls() to IF_BUG_ONCE() | Nick Mathewson | |
We introduced these BUG() checks in b0ddaac07428a06 to prevent a recurrence of bug 23690. But there's a report of the BUG() message getting triggered and filling up the disk. Let's change it to IF_BUG_ONCE(). Fixes bug 33093; bugfix on 0.3.2.2-alpha. | |||
2020-01-16 | Merge branch 'maint-0.4.0' into maint-0.4.1 | teor | |
2020-01-16 | Merge branch 'maint-0.3.5' into maint-0.4.0 | teor | |
2020-01-16 | Merge remote-tracking branch 'tor-github/pr/1513' into maint-0.3.5 | teor | |
2020-01-06 | Merge remote-tracking branch 'tor-github/pr/1612' into maint-0.4.2 | Nick Mathewson | |
2020-01-06 | Merge branch 'maint-0.4.1' into maint-0.4.2 | Nick Mathewson | |
2020-01-05 | Fix sandbox crash during reload of logging configuration | Peter Gerber | |
Allow calls to dup() which was introduced in commit a22fbab986. From a security perspective, I don't think this should impact the security of the sandbox significantly. As far as I can tell, there is nothing an adversary can do with a duplicated FD that can't be done with the original. | |||
2019-12-17 | Correct how we use libseccomp | Peter Gerber | |
This fixes a startup crash with libseccomp v2.4.0 if Sandbox is set to 1. | |||
2019-12-16 | Fix formatting in tor_assertf() message in struct_check_magic(). | Nick Mathewson | |
Closes 32771; bugfix on 0.4.2.1-alpha. | |||
2019-12-16 | Merge branch 'bug32765_041' into bug32771_042 | Nick Mathewson | |
2019-12-16 | Use CHECK_PRINTF() for printf-like functions in util_bug.h | Nick Mathewson | |
2019-12-05 | Merge branch 'maint-0.4.0' into maint-0.4.1 | teor | |
2019-12-05 | Merge branch 'maint-0.3.5' into maint-0.4.0 | teor | |
2019-12-05 | Merge remote-tracking branch 'tor-github/pr/1424' into maint-0.4.0 | teor | |
2019-12-05 | Merge remote-tracking branch 'tor-github/pr/1277' into maint-0.3.5 | teor | |
2019-11-25 | Merge branch 'maint-0.4.0' into maint-0.4.1 | teor | |
2019-11-25 | Merge branch 'maint-0.3.5' into maint-0.4.0 | teor | |
2019-11-25 | Merge remote-tracking branch 'tor-github/pr/1394' into maint-0.3.5 | teor | |
2019-11-12 | config: Log the option name when skipping an obsolete option | teor | |
This is a basic fix for 0.4.2 only. The fix for 0.4.3 and later is in 32404. Fixes bug 32295; bugfix on 0.4.2.1-alpha. | |||
2019-11-07 | Merge remote-tracking branch 'tor-github/pr/1513' into maint-0.4.2 | teor | |
2019-11-06 | Do not try to shut down the event loop when it is not initialized. | Nick Mathewson | |
Doing so caused us to crash in some unusual circumstances, such as using --verify-config to verify a configuration that failed during the options_act() stage. Fixes bug 32407; bugfix on 0.3.3.1-alpha. | |||
2019-11-06 | Merge branch 'maint-0.4.0' into maint-0.4.1 | teor | |
2019-11-06 | Merge branch 'maint-0.3.5' into maint-0.4.0 | teor | |
2019-10-22 | Merge remote-tracking branch 'tor-github/pr/1303' into maint-0.4.1 | Nick Mathewson | |
2019-10-22 | Merge remote-tracking branch 'tor-github/pr/1302' into maint-0.4.1 | Nick Mathewson | |
2019-10-22 | Merge remote-tracking branch 'tor-github/pr/1346' into maint-0.4.1 | Nick Mathewson | |