Opened 2 years ago

Closed 23 months ago

Last modified 20 months ago

#27735 closed defect (implemented)

Tors with cached consensuses can't upgrade to a version that stops supporting a required protocol

Reported by: teor Owned by: nickm
Priority: High Milestone: Tor: 0.4.0.x-final
Component: Core Tor/Tor Version:
Severity: Normal Keywords: 029-unreached-backport-maybe, 033-unreached-backport-maybe, 034-unreached-backport-maybe, 032-unreached-backport-maybe, prop297
Cc: Actual Points: .3
Parent ID: Points:
Reviewer: ahf Sponsor:

Description

When Tor loads the cached consensus, it checks the protocols in that consensus, and then exits if it does not have any required protocols. These checks happen before signatures and expiry are checked. (And before trying to get a new consensus.)

This makes it impossible for a Tor with a cached consensus to stop supporting a protocol required in that consensus.

Child Tickets

Change History (13)

comment:2 Changed 2 years ago by nickm

Parent ID: #27288

Unparenting.

comment:3 Changed 2 years ago by nickm

Owner: set to nickm
Priority: MediumHigh
Status: newaccepted

comment:4 Changed 2 years ago by nickm

Milestone: Tor: 0.3.5.x-finalTor: 0.3.6.x-final

On analysis, I think it's safe to defer this to 0.3.6. This only comes up when we are possibly about to drop support for a protocol, and we aren't planning to drop any more protocols in 0.3.5.

comment:5 Changed 2 years ago by nickm

Milestone: Tor: 0.3.6.x-finalTor: 0.4.0.x-final

Tor 0.3.6.x has been renamed to 0.4.0.x.

comment:6 Changed 2 years ago by teor

Keywords: 032-unreached-backport added

0.3.2 is end of life, so 032-backport is now 032-unreached-backport.

comment:7 Changed 2 years ago by teor

Keywords: 032-unreached-backport-maybe added; 032-backport-maybe removed

Tag 032-backport-maybe with 032-unreached-backport-maybe

comment:8 Changed 2 years ago by teor

Keywords: 032-unreached-backport removed

Remove redundant 032-unreached-backport on 032-unreached-backport-maybe

comment:9 Changed 2 years ago by nickm

Actual Points: .3
Keywords: prop297 added
Status: acceptedneeds_review

See branch prop297, PR at https://github.com/torproject/tor/pull/541 .

This code updates the update_versions script to automatically keep the version dates moving forward with each release. (It also rewrites update_versions in Python, to be less horrible.)

comment:10 Changed 2 years ago by dgoulet

Reviewer: ahf

comment:11 Changed 23 months ago by ahf

Status: needs_reviewmerge_ready

Very nice. Looks good.

comment:12 Changed 23 months ago by nickm

Resolution: implemented
Status: merge_readyclosed

Merged, and updated torspec as 18fcb9ab42cca4ce963202a22cd1f93f68ecd57c

comment:13 Changed 20 months ago by teor

Keywords: 029-unreached-backport-maybe 033-unreached-backport-maybe 034-unreached-backport-maybe added; 029-backport-maybe 033-backport-maybe 034-backport-maybe removed
Note: See TracTickets for help on using tickets.