Commit Graph
3199 Commits
Author SHA1 Message Date
orignal 4e2a13bb8e drop public keys if FromBuffer failed 2026-09-17 21:14:41 -04:00
orignal a6ebaeda0c don't crash if unknown signing key type for new private keys 2026-09-17 18:38:12 -04:00
orignal c786d3ab84 updated reseed 2026-09-17 17:46:43 -04:00
orignal 43a8f0981a exlclude duplicated trackers with same host and b32 address 2026-09-16 17:26:00 -04:00
orignal 87340e65db Merge pull request #2557 from jpk68/add-checks
fix: missing checks and limits
2026-09-16 09:00:11 -04:00
jpk68 5e93f74e19 fix: missing checks and limits 2026-09-16 08:47:15 -04:00
orignal daf3b5c58d check encryption key len for known key types 2026-09-16 08:31:21 -04:00
orignal 8769d0615a Revert "LeaseSet2: check declared key length before creating an encryptor" 2026-09-16 07:27:26 -04:00
PobreGatoandClaude Opus 5 466e865e91 LeaseSet2: check declared key length before creating an encryptor
A key section in a standard LeaseSet2 carries both a key type and a key
length. The length is checked against the buffer, but the encryptor reads
a length fixed by the type instead: 256 bytes for ElGamal, 64 for ECIES
P256, 32 for X25519. A section that declares ElGamal with a length of zero
passes the check and then makes CreateEncryptor read 256 bytes past the end
of the message.

Key sections are parsed before the signature is verified, so no key material
is needed to trigger it.

GetCryptoPublicKeyLen returned 32 for ECIES P256, while the key is x and y,
32 bytes each; without fixing that too, the new check would still let a 32
byte P256 section through.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Awv7FvZTpGFsKFNeNyJaTE
2026-09-14 21:43:53 -04:00
acetone e86eac8ee7 require a full range pair in SSU2 ack block 2026-09-14 14:45:39 -04:00
acetone a5d4896a5c check outer plaintext length in encrypted LeaseSet2 2026-09-14 14:45:39 -04:00
acetone 82047ccbc4 check clove length before reading delivery status and tunnel test 2026-09-14 14:45:13 -04:00
orignal ade824808c don't try to parse meta LeaseSet 2026-09-10 20:07:06 -04:00
PobreGato 5da917f576 treat reseed connect timeout as a failure instead of a connection 2026-09-09 20:35:08 -04:00
orignal e5621949d5 chech ratchets payload size and key 2026-09-09 09:23:18 -04:00
orignal 4966e30938 support C++20 with older boost 2026-09-07 22:55:21 -04:00
orignal a592d51a31 don't add session if server is not ready 2026-09-07 20:23:57 -04:00
orignal 6118fa31d9 don't connect to remote peer if sevver was not started or already stopped 2026-09-07 18:47:11 -04:00
orignal 109a1b1625 don't connect or accept sessions during start/stop 2026-09-07 09:17:13 -04:00
PobreGato 789fb8b9c1 check datagram sessions for empty under the lock 2026-09-03 01:58:09 +03:00
PobreGato dc1a0ebe94 don't send packets from a terminated stream 2026-09-02 01:37:06 +03:00
orignal 8800014043 use correct ident hash for datagram2 signature verification 2026-08-31 19:57:45 -04:00
orignal 59c756822d fixed possible overflow 2026-08-31 18:08:55 -04:00
orignal b46554de65 correct incorrect block size for padding block 2026-08-31 16:12:40 -04:00
orignal b7d5d712e7 Merge pull request #2539 from pobregat0/tunnel-short-message
Drop a tunnel message shorter than an I2NP header
2026-08-30 21:40:16 -04:00
PobreGato 4fdb8c7c83 drop a tunnel message shorter than an I2NP header 2026-08-31 04:28:37 +03:00
orignal 61a9a6b1ac Merge pull request #2538 from pobregat0/http-chunk-truncated
Handle malformed HTTP input instead of throwing or returning garbage
2026-08-30 20:23:16 -04:00
PobreGato 039d3feea7 return false instead of throwing on a url with nothing after the schema 2026-08-31 03:12:39 +03:00
PobreGato 954e98eb4d fail on a truncated chunk instead of returning uninitialized bytes 2026-08-31 03:00:47 +03:00
PobreGato 7beb115d1e stop searching for a zip data descriptor on a broken stream 2026-08-31 02:52:36 +03:00
PobreGato 9ef68e2d93 stop parsing a truncated zip in reseed instead of looping forever 2026-08-31 02:33:05 +03:00
orignal f58f9e2838 correct signature for datagram2 2026-08-30 13:24:40 -04:00
orignal 3d14e95567 correct signature for Datagram2 2026-08-25 20:00:48 -04:00
orignal 4177076df9 postpone sending ack if immediate ack requested until all packets get processed 2026-08-25 08:53:24 -04:00
orignal 558c50ca24 http.javascript config param 2026-08-24 18:16:50 -04:00
orignal 393da480da Merge pull request #2504 from pobregat0/stop-from-any-thread
stop a destination on its own thread whoever calls it
2026-08-24 16:55:17 -04:00
orignal 47363b84c6 Merge pull request #2512 from jpk68/http-thread-safety
http, i2pcontrol: use thread-safe snapshots for session/tunnel lists
2026-08-24 13:07:51 -04:00
jpk68 1124b6259f http, i2pcontrol: use thread-safe snapshots for session/tunnel lists 2026-08-24 10:20:04 -04:00
orignal d0d6b8837a erase used element from m_SavedPackets in one shot 2026-08-23 16:03:38 -04:00
orignal d801e971fb removed CreatePath 2026-08-23 14:58:28 -04:00
jpk68 bf594a742e libi2pd: fix parsing crashes 2026-08-23 13:27:13 -04:00
orignal 41cb59c7a7 use std::list for receive queue 2026-08-22 22:53:48 -04:00
PobreGato 2352ebffab stop a destination on its own thread whoever calls it 2026-08-23 02:04:04 +03:00
orignal b6be65d774 min size in AsyncRequest 2026-08-22 14:47:14 -04:00
orignal 4f2d7d7828 common GetRngSeed to initialize std::mt19937 2026-08-21 12:51:05 -04:00
orignal cac6c53ccb common GetRngSeed to initialize std::mt19937 2026-08-21 10:51:44 -04:00
orignal 726c1b9ec0 use std::mt19937 instead RAND_bytes 2026-08-20 21:42:05 -04:00
orignal c42051f6b3 Merge pull request #2499 from jpk68/checks-2
libi2pd: add missing checks and limits
2026-08-19 21:33:57 -04:00
jpk68 a57d375bf1 libi2pd: add missing checks and limits 2026-08-19 21:29:25 -04:00
PobreGato 85b6104080 stop runnable destination in its own thread 2026-08-19 19:12:20 +03:00