Opened 3 years ago

Closed 2 years ago

#22030 closed defect (fixed)

Onionoo shows old IPv6 Exit ports

Reported by: teor Owned by: metrics-team
Priority: Medium Milestone: Onionoo-1.4.0
Component: Metrics/Onionoo Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:


I have an exit policy that looks like this on a relay running tor-

ExitPolicy reject *:*
ExitPolicy reject (IPv4 Blocks):*
ExitPolicy reject (IPv6 Blocks):*
ExitPolicy accept *:(Ports)
ExitPolicy reject *:*
ExitRelay 1
IPv6Exit 1

Even though the policy starts with 'reject *:*', atlas reports that the accepted ports are allowed over IPv6. All ports are rejected over IPv4.

This was a big surprise to me.

Child Tickets

Change History (7)

comment:1 Changed 3 years ago by teor

Component: Core Tor/TorMetrics/Onionoo
Keywords: ipv6 tor-exit removed
Milestone: Tor: 0.3.2.x-final
Owner: set to metrics-team
Points: 1
Summary: Exit Policy reject * does not reject IPv6 portsOnionoo shows old IPv6 ports
Version: Tor:

Turns out this is a bug in Onionoo.

The relay descriptor says:

reject *:*

But onionoo says:

"exit_policy":["reject *:*"],

This is the old policy from when the relay used to be an exit.

comment:2 Changed 2 years ago by teor

Summary: Onionoo shows old IPv6 portsOnionoo shows old IPv6 Exit ports

comment:3 Changed 2 years ago by karsten

Status: newneeds_review

Indeed, looks like a bug in Onionoo. Here's a potential fix that is yet untested.

comment:4 Changed 2 years ago by iwakeh

Milestone: Onionoo-1.3.0

comment:5 Changed 2 years ago by iwakeh

Milestone: Onionoo-1.3.0Onionoo-1.4.0

comment:6 Changed 2 years ago by iwakeh

Status: needs_reviewmerge_ready

Looks like the correct solution (cf. spec); checks and tests pass. Merge ready.

I rebased your branch on the current master and added a junit test, that would fail without the fix. Please review this branch.

comment:7 Changed 2 years ago by karsten

Resolution: fixed
Status: merge_readyclosed

Thanks for the review and the test! Merged with a fix to the change log. Closing.

Note: See TracTickets for help on using tickets.