net: canonicalize Tor/I2P hosts during deserialization
What changed, and why it matters
This change makes Monero's network address handling for Tor and I2P more consistent by converting hostnames to lowercase when they are read from stored or received data. Before this fix, an address like 'EXAMPLE.onion' written in capital letters would be treated differently from 'example.onion', which could cause mismatches, failed connections, or possibly bypass security checks that rely on exact string comparison. The patch adds a normalization step during deserialization and includes tests to confirm it works.
Treat as a hardening fix with possible security relevance. Review whether any other address comparison or peer-list logic depends on exact host string matching and ensure canonicalization is applied consistently across all Tor/I2P input paths. No immediate emergency response is indicated from the diff alone.
Security signals we found
Input normalization added to deserialization path for anonymizing network addresses
Potential case-sensitivity bypass in host validation/lookup mitigated
Tests added for uppercase Tor v3 and I2P b32 host acceptance
Evidence from the diff
The commit modifies i2p_address::_load and tor_address::_load to call net::canonicalize_host on the deserialized host string before validating it with host_check. Previously, validation accepted only already-canonical forms; uppercase variants would fail host_check and fall back to the unknown host. The change ensures that any case variation in serialized Tor/I2P hostnames is normalized to lowercase, improving consistency in address comparison and lookup. Unit tests verify that uppercase v3 onion and b32 i2p addresses are accepted and canonicalized.
Changed components
src/net/i2p_address.cppsrc/net/tor_address.cpptests/unit_tests/net.cppInspect captured patch +45 / −9
diff --git a/src/net/i2p_address.cpp b/src/net/i2p_address.cpp
index 5864320..2454bb7 100644
--- a/src/net/i2p_address.cpp
+++ b/src/net/i2p_address.cpp
@@ -117,11 +117,15 @@ namespace net
bool i2p_address::_load(epee::serialization::portable_storage& src, epee::serialization::section* hparent)
{
i2p_serialized in{};
- if (in._load(src, hparent) && in.host.size() < sizeof(host_) && (in.host == unknown_host || !host_check(in.host).has_error()))
+ if (in._load(src, hparent) && in.host.size() < sizeof(host_))
{
- std::memcpy(host_, in.host.data(), in.host.size());
- std::memset(host_ + in.host.size(), 0, sizeof(host_) - in.host.size());
- return true;
+ net::canonicalize_host(in.host);
+ if (in.host == unknown_host || !host_check(in.host).has_error())
+ {
+ std::memcpy(host_, in.host.data(), in.host.size());
+ std::memset(host_ + in.host.size(), 0, sizeof(host_) - in.host.size());
+ return true;
+ }
}
static_assert(sizeof(unknown_host) <= sizeof(host_), "bad buffer size");
std::memcpy(host_, unknown_host, sizeof(unknown_host)); // include null terminator
diff --git a/src/net/tor_address.cpp b/src/net/tor_address.cpp
index 7e81995..42389a3 100644
--- a/src/net/tor_address.cpp
+++ b/src/net/tor_address.cpp
@@ -149,12 +149,16 @@ namespace net
bool tor_address::_load(epee::serialization::portable_storage& src, epee::serialization::section* hparent)
{
tor_serialized in{};
- if (in._load(src, hparent) && in.host.size() < sizeof(host_) && (in.host == unknown_host || !host_check(in.host).has_error()))
+ if (in._load(src, hparent) && in.host.size() < sizeof(host_))
{
- std::memcpy(host_, in.host.data(), in.host.size());
- std::memset(host_ + in.host.size(), 0, sizeof(host_) - in.host.size());
- port_ = in.port;
- return true;
+ net::canonicalize_host(in.host);
+ if (in.host == unknown_host || !host_check(in.host).has_error())
+ {
+ std::memcpy(host_, in.host.data(), in.host.size());
+ std::memset(host_ + in.host.size(), 0, sizeof(host_) - in.host.size());
+ port_ = in.port;
+ return true;
+ }
}
static_assert(sizeof(unknown_host) <= sizeof(host_), "bad buffer size");
std::memcpy(host_, unknown_host, sizeof(unknown_host)); // include null terminator
diff --git a/tests/unit_tests/net.cpp b/tests/unit_tests/net.cpp
index 6caaf3c..64748e7 100644
--- a/tests/unit_tests/net.cpp
+++ b/tests/unit_tests/net.cpp
@@ -300,6 +300,20 @@ TEST(tor_address, epee_serializev_v3)
EXPECT_STREQ(v3_onion, command.tor.host_str());
EXPECT_EQ(10u, command.tor.port());
+ // make sure tor_address::_load canonicalizes incoming hosts
+ {
+ epee::serialization::portable_storage stg{};
+ stg.load_from_binary(epee::to_span(buffer));
+
+ EXPECT_TRUE(stg.set_value("host", std::string{v3_onion_upper}, stg.open_section("tor", nullptr, false)));
+ EXPECT_TRUE(command.load(stg));
+ }
+
+ EXPECT_FALSE(command.tor.is_unknown());
+ EXPECT_NE(net::tor_address{}, command.tor);
+ EXPECT_STREQ(v3_onion, command.tor.host_str());
+ EXPECT_EQ(10u, command.tor.port());
+
// make sure that exceeding max buffer doesn't destroy tor_address::_load
{
epee::serialization::portable_storage stg{};
@@ -676,6 +690,20 @@ TEST(i2p_address, epee_serializev_b32)
EXPECT_STREQ(b32_i2p, command.i2p.host_str());
EXPECT_EQ(1u, command.i2p.port());
+ // make sure i2p_address::_load canonicalizes incoming hosts
+ {
+ epee::serialization::portable_storage stg{};
+ stg.load_from_binary(epee::to_span(buffer));
+
+ EXPECT_TRUE(stg.set_value("host", std::string{b32_i2p_upper}, stg.open_section("i2p", nullptr, false)));
+ EXPECT_TRUE(command.load(stg));
+ }
+
+ EXPECT_FALSE(command.i2p.is_unknown());
+ EXPECT_NE(net::i2p_address{}, command.i2p);
+ EXPECT_STREQ(b32_i2p, command.i2p.host_str());
+ EXPECT_EQ(1u, command.i2p.port());
+
// make sure that exceeding max buffer doesn't destroy i2p_address::_load
{
epee::serialization::portable_storage stg{};
Why this scored 48/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.