[tor-bugs] #24826 [Core Tor/Tor]: LZMA- and Zstandard compressed consensus diffs stall Tor Browser launch for at least 20s or break it entirely if compiled with --enable-expensive-hardening

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jan 16 15:10:12 UTC 2018


#24826: LZMA- and Zstandard compressed consensus diffs stall Tor Browser launch for
at least 20s or break it entirely if compiled with --enable-expensive-
hardening
--------------------------+------------------------------------
 Reporter:  gk            |          Owner:  (none)
     Type:  defect        |         Status:  new
 Priority:  Medium        |      Milestone:  Tor: 0.3.3.x-final
Component:  Core Tor/Tor  |        Version:
 Severity:  Normal        |     Resolution:
 Keywords:                |  Actual Points:
Parent ID:  #22341        |         Points:
 Reviewer:                |        Sponsor:
--------------------------+------------------------------------

Comment (by nickm):

 Okay, the plot grows thicker: It seems that we already are compiling the
 sha3 module without the hardening flags. So maybe the problem here isn't
 the hardening in sha3, but somewhere else instead.

 It could be either in consensus_split_lines, or in consdiff_get_digests.
 I'll try them both out.  I suspect it might be split_lines, though.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/24826#comment:21>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list