[tor-bugs] #4957 [Metrics Data Processor]: Decide how to sanitize pluggable transport lines in bridge descriptors

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Fri Jun 29 10:42:55 UTC 2012


#4957: Decide how to sanitize pluggable transport lines in bridge descriptors
------------------------------------+---------------------------------------
 Reporter:  karsten                 |          Owner:  karsten
     Type:  task                    |         Status:  new    
 Priority:  normal                  |      Milestone:         
Component:  Metrics Data Processor  |        Version:         
 Keywords:                          |         Parent:         
   Points:                          |   Actualpoints:         
------------------------------------+---------------------------------------

Comment(by karsten):

 After talking more to asn on IRC, we came up with a slightly more paranoid
 variant:

  - Sanitize `transport` lines by only keeping the `transport SP
 <methodname>` part.

  - Remove `transport-info` lines entirely.

 Reasons are that it's yet unclear what the `arglist` part will contain in
 future transports.  As a result, we also drop `transport-info` lines
 completely.  asn further had concerns about not sanitizing the `port`
 part, so we left out `<address:port>`.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/4957#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list