[tor-bugs] #31011 [Core Tor/Tor]: Make the bridge authority reject private PT addresses when DirAllowPrivateAddresses is 0

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Dec 18 01:07:32 UTC 2019

#31011: Make the bridge authority reject private PT addresses when
DirAllowPrivateAddresses is 0
 Reporter:  teor                               |          Owner:  (none)
     Type:  defect                             |         Status:  new
 Priority:  Medium                             |      Milestone:  Tor:
                                               |  unspecified
Component:  Core Tor/Tor                       |        Version:
 Severity:  Normal                             |     Resolution:
 Keywords:  anti-censorship-roadmap-september  |  Actual Points:
Parent ID:  #31009                             |         Points:  1
 Reviewer:                                     |        Sponsor:
                                               |  Sponsor28-can

Comment (by teor):

 Replying to [comment:9 phw]:
 > I prefer having the bridge authority reject descriptors with private
 addresses. In my opinion, a private address has no business being in the
 descriptor and we should reject such descriptors rather than guessing what
 the bridge operators meant to do.

 Thanks, that seems like a sensible decision.

 We can add bridge authority code that rejects extra-info descriptors with
 a private address in any `transport` line.

 We should probably also add a config error on the bridge side, if
 ServerTransportListenAddress is an internal address,
 compute_publishserverdescriptor() is bridge, and the bridge is using the
 default bridge authority.

 Here's how the `transport` line is created on the bridge side:

 Here's where we reject extra-info descriptors in dirserv_add_extrainfo():

 See dirserv_router_has_valid_address() for some example code. This code
 rejects relay descriptors with private IPv4 or IPv6 addresses, when
 DirAllowPrivateAddresses is 0:

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31011#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online

More information about the tor-bugs mailing list