Commit Graph
3214 Commits
Author SHA1 Message Date
orignal 793431aed3 use std::stoi for conversion from hex string 2026-10-03 11:04:54 -04:00
orignal 2de93be1a3 check is host end with .i2p using ends_with 2026-10-01 22:21:16 -04:00
PobreGato 2c1d3612e0 check datetime block size in NTCP2 data frame 2026-10-01 21:17:20 -04:00
orignal 1078c347f1 fixed typo in log message 2026-09-27 18:13:37 -04:00
orignal c9cc1c80be check if received timestamp is too high 2026-09-27 09:52:09 -04:00
acetone 5b3e4db7f1 create key files readable by owner only 2026-09-23 10:48:32 -04:00
orignal 1e98572c32 use std::span instead naked poinnted for transient private key 2026-09-22 08:26:13 -04:00
acetone 4d9cba2df5 b33 offline keys for an encrypted LeaseSet 2026-09-21 14:33:24 -04:00
acetone 55fa7cd72d don't verify Layer 2 of an encrypted LeaseSet with the outer transient 2026-09-21 13:19:02 -04:00
orignal b8a8bcc7e0 constexpr Base64EncodingBufferSize for C++23 2026-09-20 10:03:32 -04:00
orignal 1a1884c4eb changed minimal compressed size to 20 bytes 2026-09-19 22:28:51 -04:00
orignal f70e74f316 don't try to copy private key if not set 2026-09-19 21:43:23 -04:00
orignal 328860f0bb Merge pull request #2565 from pobregat0/pool-cleanup-order
detach memory pool list before freeing it
2026-09-18 22:27:03 -04:00
PobreGato 68a4f90fa9 call SendClose and Terminate through the service in Close 2026-09-18 22:17:59 -04:00
PobreGato 1c408f6086 detach memory pool list before freeing it 2026-09-18 19:57:20 -04:00
orignal 4e2a13bb8e drop public keys if FromBuffer failed 2026-09-17 21:14:41 -04:00
orignal a6ebaeda0c don't crash if unknown signing key type for new private keys 2026-09-17 18:38:12 -04:00
orignal c786d3ab84 updated reseed 2026-09-17 17:46:43 -04:00
orignal 43a8f0981a exlclude duplicated trackers with same host and b32 address 2026-09-16 17:26:00 -04:00
orignal 87340e65db Merge pull request #2557 from jpk68/add-checks
fix: missing checks and limits
2026-09-16 09:00:11 -04:00
jpk68 5e93f74e19 fix: missing checks and limits 2026-09-16 08:47:15 -04:00
orignal daf3b5c58d check encryption key len for known key types 2026-09-16 08:31:21 -04:00
orignal 8769d0615a Revert "LeaseSet2: check declared key length before creating an encryptor" 2026-09-16 07:27:26 -04:00
PobreGatoandClaude Opus 5 466e865e91 LeaseSet2: check declared key length before creating an encryptor
A key section in a standard LeaseSet2 carries both a key type and a key
length. The length is checked against the buffer, but the encryptor reads
a length fixed by the type instead: 256 bytes for ElGamal, 64 for ECIES
P256, 32 for X25519. A section that declares ElGamal with a length of zero
passes the check and then makes CreateEncryptor read 256 bytes past the end
of the message.

Key sections are parsed before the signature is verified, so no key material
is needed to trigger it.

GetCryptoPublicKeyLen returned 32 for ECIES P256, while the key is x and y,
32 bytes each; without fixing that too, the new check would still let a 32
byte P256 section through.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Awv7FvZTpGFsKFNeNyJaTE
2026-09-14 21:43:53 -04:00
acetone e86eac8ee7 require a full range pair in SSU2 ack block 2026-09-14 14:45:39 -04:00
acetone a5d4896a5c check outer plaintext length in encrypted LeaseSet2 2026-09-14 14:45:39 -04:00
acetone 82047ccbc4 check clove length before reading delivery status and tunnel test 2026-09-14 14:45:13 -04:00
orignal ade824808c don't try to parse meta LeaseSet 2026-09-10 20:07:06 -04:00
PobreGato 5da917f576 treat reseed connect timeout as a failure instead of a connection 2026-09-09 20:35:08 -04:00
orignal e5621949d5 chech ratchets payload size and key 2026-09-09 09:23:18 -04:00
orignal 4966e30938 support C++20 with older boost 2026-09-07 22:55:21 -04:00
orignal a592d51a31 don't add session if server is not ready 2026-09-07 20:23:57 -04:00
orignal 6118fa31d9 don't connect to remote peer if sevver was not started or already stopped 2026-09-07 18:47:11 -04:00
orignal 109a1b1625 don't connect or accept sessions during start/stop 2026-09-07 09:17:13 -04:00
PobreGato 789fb8b9c1 check datagram sessions for empty under the lock 2026-09-03 01:58:09 +03:00
PobreGato dc1a0ebe94 don't send packets from a terminated stream 2026-09-02 01:37:06 +03:00
orignal 8800014043 use correct ident hash for datagram2 signature verification 2026-08-31 19:57:45 -04:00
orignal 59c756822d fixed possible overflow 2026-08-31 18:08:55 -04:00
orignal b46554de65 correct incorrect block size for padding block 2026-08-31 16:12:40 -04:00
orignal b7d5d712e7 Merge pull request #2539 from pobregat0/tunnel-short-message
Drop a tunnel message shorter than an I2NP header
2026-08-30 21:40:16 -04:00
PobreGato 4fdb8c7c83 drop a tunnel message shorter than an I2NP header 2026-08-31 04:28:37 +03:00
orignal 61a9a6b1ac Merge pull request #2538 from pobregat0/http-chunk-truncated
Handle malformed HTTP input instead of throwing or returning garbage
2026-08-30 20:23:16 -04:00
PobreGato 039d3feea7 return false instead of throwing on a url with nothing after the schema 2026-08-31 03:12:39 +03:00
PobreGato 954e98eb4d fail on a truncated chunk instead of returning uninitialized bytes 2026-08-31 03:00:47 +03:00
PobreGato 7beb115d1e stop searching for a zip data descriptor on a broken stream 2026-08-31 02:52:36 +03:00
PobreGato 9ef68e2d93 stop parsing a truncated zip in reseed instead of looping forever 2026-08-31 02:33:05 +03:00
orignal f58f9e2838 correct signature for datagram2 2026-08-30 13:24:40 -04:00
orignal 3d14e95567 correct signature for Datagram2 2026-08-25 20:00:48 -04:00
orignal 4177076df9 postpone sending ack if immediate ack requested until all packets get processed 2026-08-25 08:53:24 -04:00
orignal 558c50ca24 http.javascript config param 2026-08-24 18:16:50 -04:00