]> git.ipfire.org Git - thirdparty/tor.git/commitdiff
hs: Silence a spurious warning in rend_client_send_introduction()
authorteor <teor@torproject.org>
Wed, 5 Sep 2018 11:07:58 +0000 (21:07 +1000)
committerteor <teor@torproject.org>
Fri, 7 Sep 2018 02:40:11 +0000 (12:40 +1000)
gcc 8 warns that extend_info_t.nickname might be truncated by strncpy().

But it doesn't know that nickname can either contain a hex id, or a
nicknames. hex ids are only used for general and HSDir circuits.

Fixes bug 27463; bugfix on 0.1.1.2-alpha.

changes/bug27463 [new file with mode: 0644]
src/or/rendclient.c

diff --git a/changes/bug27463 b/changes/bug27463
new file mode 100644 (file)
index 0000000..073acdd
--- /dev/null
@@ -0,0 +1,3 @@
+  o Minor bugfixes (onion services):
+    - Silence a spurious compiler warning in rend_client_send_introduction().
+      Fixes bug 27463; bugfix on 0.1.1.2-alpha.
index a93bc94a9cf15e2d05fb00b2fced0fc892616b61..f0144b076f0072c1db5752408c9b3d7bf7fc3cd4 100644 (file)
@@ -269,6 +269,15 @@ rend_client_send_introduction(origin_circuit_t *introcirc,
     dh_offset = v3_shift+7+DIGEST_LEN+2+klen+REND_COOKIE_LEN;
   } else {
     /* Version 0. */
+
+    /* Some compilers are smart enough to work out that nickname can be more
+     * than 19 characters, when it's a hexdigest. They warn that strncpy()
+     * will truncate hexdigests without NUL-terminating them. But we only put
+     * hexdigests in HSDir and general circuit exits. */
+    if (BUG(strlen(rendcirc->build_state->chosen_exit->nickname)
+            > MAX_NICKNAME_LEN)) {
+      goto perm_err;
+    }
     strncpy(tmp, rendcirc->build_state->chosen_exit->nickname,
             (MAX_NICKNAME_LEN+1)); /* nul pads */
     memcpy(tmp+MAX_NICKNAME_LEN+1, rendcirc->rend_data->rend_cookie,