feat: validate onion3 addresses
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- rust
- 領域
- networking
調査の方向性
Onion3Addr::from と既存の data-encoding 依存関係から始め、現在のアドレス処理をリンク先の Tor v3 形式と比較します。チェックサム、バージョン、公開鍵の検証をこのライブラリに含めるべきか判断し、選択したルールに対するテストと失敗し得る変換を追加します。無効な onion3 アドレスが Tor に到達する前に拒否されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
You can currently create invalid onion3 addresses:
let mut b = [0u8; 35];
OsRng.fill_bytes(&mut b);
let addr = multiaddr::Onion3Addr::from((b, 12345u16));
let invalid = multiaddr!(Onion3(addr));
Resulting in these error logs in tor
Jun 5 10:10:44 thor Tor[692]: Service address "pd6sf3mqkkkfrn4rk5odgcr2j5sn7m523a4tm7pzpuotk2b7rpuhaeym" invalid checksum.
Jun 5 10:10:44 thor Tor[692]: Invalid onion hostname pd6sf3mqkkkfrn4rk5odgcr2j5sn7m523a4tm7pzpuotk2b7rpuhaeym.onion; rejecting
Question: Should we be validating the checksum and/or the public key in this library? Defined as follows:
onion_address = base32(PUBKEY | CHECKSUM | VERSION) + ".onion"
CHECKSUM = H(".onion checksum" | PUBKEY | VERSION)[:2]
where:
- PUBKEY is the 32 bytes ed25519 master pubkey of the hidden service.
- VERSION is a one byte version field (default value '\x03')
- ".onion checksum" is a constant string
- CHECKSUM is truncated to two bytes before inserting it in onion_address
source: https://github.com/torproject/torspec/blob/main/rend-spec-v3.txt#LL2258C6-L2258C6
This would introduce a number of dependencies: (edit: not required due to existing base32data-encoding dep), sha3 and an ed25519 library if we decided to validate the PUBKEY.
In many cases the user can leave it to tor, but you may not want to e.g. include the address in a database if it is invalid.
I wanted thoughts on if this is in scope for this library or if this validation should be left up to the user.
I'd be happy to work on a PR for this if this is in scope. Changes should be fairly minor: Fallible TryFrom impl, decoding the address and verifying the checksum, version and possibly the ed25519 key, and adding some new tests.
- 主要言語
- Rust
- スター
- 101
- フォーク
- 56
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
multiformats/rust-multiaddr のほかの issue
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
multiformats/rust-multiaddr#134 · コメント 1 件 ·
-
difficulty:easy help wanted
難易度 2/5 1〜3時間 初心者へのやさしさ 47/100
multiformats/rust-multiaddr#100 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 45/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 25/100
multiformats/rust-multiaddr#90 · コメント 2 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
multiformats/rust-multiaddr の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
aws-samples/sample-pacer#76 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
axodotdev/cargo-dist#2523 ·
メンテナーはふだん 2 日以内に返信