[tor-reports] Georg's May 2014

Georg Koppen gk at torproject.org
Mon Jun 2 09:57:38 UTC 2014


this month I seriously started working on hardened TBBs[1] and as a
result I published a build based on GCC 4.8.2[2] which gives us ASan
(Address Sanitizer[3]). Work is ongoing to get additional hardening
features included that we get by using GCC >= 4.9.x.
With respect to the hardening work I wrote a small patch for Mozilla
which will get included into Firefox 31 allowing to build Firefox with
ASan and other hardening feature using GCC.[4]

Apart from that I worked on a bunch of Gitian related things. I:

-finally fixed the descriptor refactoring allowing us to keep already
built build utilities[5]
-added the missing txsocksx dependency of obfsproxy[6]
-worked on issues we had with our nightly builds[7][8]
-added missing geoip6 files in our descriptors[9]
-merged patches for missing PT docs in Windows and Mac bundles[10][11]
-fixed a regression in my refactoring of Windows descriptors[12]
-implemented a workaround obfsproxy shebang issues on Mac OS X[13]
-investigated why RELRO hardening is sort of broken since 3.5.3[14]
-merged a fix for the TBB start script on Linux[15]

On the non-Gitian side I:

-worked on getting down to the cause for the non-deterministic behavior
of HTTPS-Everywhere's rules.sqlite database[16]
-prepared Torbutton patches done by a cypherpunk[17][18]
-triaged some tickets[19][20][21][22]
-looked at the information leak due to JavaScript date methods[23]
-helped David with his HTTP host header patch for Mozilla[24]


[1] https://bugs.torproject.org/10599
[2] https://lists.torproject.org/pipermail/tor-qa/2014-May/000414.html
[3] https://code.google.com/p/address-sanitizer/
[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1013341
[5] https://bugs.torproject.org/10120
[6] https://bugs.torproject.org/11535
[7] https://bugs.torproject.org/11615
[8] https://bugs.torproject.org/11249
[9] https://bugs.torproject.org/10425
[10] https://bugs.torproject.org/11834
[11] https://bugs.torproject.org/11835
[12] https://bugs.torproject.org/11919
[13] https://bugs.torproject.org/11190
[14] https://bugs.torproject.org/12103
[15] https://bugs.torproject.org/12161
[16] https://bugs.torproject.org/11630
[17] https://bugs.torproject.org/11763
[18] https://bugs.torproject.org/11783
[19] https://bugs.torproject.org/11935
[20] https://bugs.torproject.org/11949
[21] https://bugs.torproject.org/12154
[22] https://bugs.torproject.org/12158
[23] https://bugs.torproject.org/5926
[24] https://bugzilla.mozilla.org/show_bug.cgi?id=1017769

