Opened 9 months ago

Closed 6 months ago

Last modified 3 months ago

#27735 closed defect (implemented)

Tors with cached consensuses can't upgrade to a version that stops supporting a required protocol

Reported by: teor Owned by: nickm
Priority: High Milestone: Tor: 0.4.0.x-final
Component: Core Tor/Tor Version:
Severity: Normal Keywords: 029-unreached-backport-maybe, 033-unreached-backport-maybe, 034-unreached-backport-maybe, 032-unreached-backport-maybe, prop297
Cc: Actual Points: .3
Parent ID: Points:
Reviewer: ahf Sponsor:

Description

When Tor loads the cached consensus, it checks the protocols in that consensus, and then exits if it does not have any required protocols. These checks happen before signatures and expiry are checked. (And before trying to get a new consensus.)

This makes it impossible for a Tor with a cached consensus to stop supporting a protocol required in that consensus.

Child Tickets

Change History (13)

comment:2 Changed 9 months ago by nickm

Parent ID: #27288

Unparenting.

comment:3 Changed 9 months ago by nickm

Owner: set to nickm
Priority: MediumHigh
Status: newaccepted

comment:4 Changed 9 months ago by nickm

Milestone: Tor: 0.3.5.x-finalTor: 0.3.6.x-final

On analysis, I think it's safe to defer this to 0.3.6. This only comes up when we are possibly about to drop support for a protocol, and we aren't planning to drop any more protocols in 0.3.5.

comment:5 Changed 7 months ago by nickm

Milestone: Tor: 0.3.6.x-finalTor: 0.4.0.x-final

Tor 0.3.6.x has been renamed to 0.4.0.x.

comment:6 Changed 7 months ago by teor

Keywords: 032-unreached-backport added

0.3.2 is end of life, so 032-backport is now 032-unreached-backport.

comment:7 Changed 7 months ago by teor

Keywords: 032-unreached-backport-maybe added; 032-backport-maybe removed

Tag 032-backport-maybe with 032-unreached-backport-maybe

comment:8 Changed 7 months ago by teor

Keywords: 032-unreached-backport removed

Remove redundant 032-unreached-backport on 032-unreached-backport-maybe

comment:9 Changed 7 months ago by nickm

Actual Points: .3
Keywords: prop297 added
Status: acceptedneeds_review

See branch prop297, PR at https://github.com/torproject/tor/pull/541 .

This code updates the update_versions script to automatically keep the version dates moving forward with each release. (It also rewrites update_versions in Python, to be less horrible.)

comment:10 Changed 7 months ago by dgoulet

Reviewer: ahf

comment:11 Changed 6 months ago by ahf

Status: needs_reviewmerge_ready

Very nice. Looks good.

comment:12 Changed 6 months ago by nickm

Resolution: implemented
Status: merge_readyclosed

Merged, and updated torspec as 18fcb9ab42cca4ce963202a22cd1f93f68ecd57c

comment:13 Changed 3 months ago by teor

Keywords: 029-unreached-backport-maybe 033-unreached-backport-maybe 034-unreached-backport-maybe added; 029-backport-maybe 033-backport-maybe 034-backport-maybe removed
Note: See TracTickets for help on using tickets.