@RN
@ReturningNovice
@StormyCloud
@T3s|4
@T3s|4_
@orignal
@postman
@zzz
%acetone
%mareki2p
%snex
+Atticfire
+FreefallHeavens
+Onn4l7h
+Onn4|7h
+Over
+fa
+marek22k
+onon_
+poriori
+profetikla
+qend-irc2p
+r00tobo
+sexy
+uberius
+uop23ip
Arch
Danny
Irc2PGuest21708
Irc2PGuest28384
Irc2PGuest66257
Irc2PGuest75631
Irc2PGuest99986
RTP_
U1F642
Watson
ahiru
anontor
cims
i2potus
interesting
justaperson
lokzz
luvme
mahlay
makoto
n2_
nilbog
not_bob_afk
pinotto
r00tobo[2]
rednode
user_ygg2__
dr|z3d
about as painless as it gets. 'ant updateWrapper'
nyaa2pguy
drop.i2p/f/0b28b973-c3ba-408d-a181-3bd3276f459f yay kinda working transit tunnels
orignal
nyaa2pguy why did you start with i2cp?
nyaa2pguy
i haven't actually looked at that code yet, it's mostly left from original github.com/PeterZander/i2p-cs/tree/github-master/I2CP/I2CP
nyaa2pguy
probably doesn't work
onon_
Well, i2pd has been updated, now you can safely remove the java-router and switch to i2pd.
onon_
Now the excuses that i2pd does not know how to change b32 are not accepted. Now i2pd can do this.
uop23ip
hope they fixed the reseed stuff github.com/PurpleI2P/i2pd/issues/2373
orignal
not yet
orignal
this issue came before the release
orignal
will do it few days
orignal
nyaa2pguy I2CP is not the best protocol
orignal
if you want to implement a fast i2p
onon_
I2CP is really bad
orignal
it's utdated
orignal
was good for dial-up days
nyaa2pguy
i was thinking using something else for letting my other c# use the router
nyaa2pguy
my other c# apps*
onon_
Are there any other excuses not to change the router to i2pd?
uop23ip
thanks. can't tell in general for this issue ofc, but it happened with a fresh install.
orignal
it shouldn't
orignal
that issue is about no network right after startup
waffles
orignal:
waffles
i had to switch to i2pd i2p+ keeps dcing
orignal
what?
waffles
u winned
onon_
Yeah
orignal
me?
orignal
I don't suggest to switch to i2pd
uop23ip
lol
onon_
I won
onon_
This is my victory
onon_
Who else wants to make me happy today?
onon_
You just need to install i2pd, it's not as difficult as it seems.
onon_
And I will be satisfied.
dr|z3d
You might be satisified, the jury's out on whether the victim will be.
orignal
jury?
nyaa2pguy
i run at least 8 i2pds on my pc :) github.com/samueldaaaarling/i2p-cs-renewed/blob/github-master/src/I2PCore.NTests/IntegrationTests/Infrastructure/ScaledNetworkFixture.cs
nyaa2pguy
9*
onon_
*** in ecstasy with happiness ***
uop23ip
zzz ,on canon java 2.12 as transit router got following errors (with changing ip). anything serious or just some old/bad peers? router runs fine.
uop23ip
ERROR [ handler 1/1] er.transport.udp.PacketHandler: Internal error handling 912 byte pkt with xxx.xxx.xxx.xxx:xxxxx priority=100 sinceEnqueued=6 sinceReceived=5
uop23ip
java.lang.IllegalArgumentException: low order input RFC 7748
uop23ip
at com.southernstorm.noise.crypto.x25519.Curve25519.eval(Curve25519.java:533)...
uop23ip
ERROR [ handler 1/1] er.transport.udp.PacketHandler: Internal error handling 912 byte pkt with xxx.xxx.xxx.xxx:xxxxx priority=100 sinceEnqueued=1 sinceReceived=0
uop23ip
java.lang.IllegalStateException: Handshake state FAILED does not allow reading messages
uop23ip
at com.southernstorm.noise.protocol.HandshakeState.readMessage(HandshakeState.java:962)...
zzz
uop23ip, can I have the full stack trace from the first one?
zzz
I assume the 2nd one was right after the first?
zzz
thanks. this is super interesting
zzz
this check was added very recently on recommendation of a security report
zzz
I assumed it wouldn't or couldn't actually happen
zzz
please PM me the offender's IP so I can take a look at his RI
zzz
I also need to catch the error better so it doesn't puke out like that
uop23ip
you only need one ip. there are more. exactly 3 today
zzz
I'll take them all
dr|z3d
speaking of checks, are you watching the fairly high number of handshake timeouts, zzz? those and handshakes where no data is being sent? maybe probing attacks?
uop23ip
you only need one ip? ofc
zzz
haven't seen that drz. inbound? NTCP or SSU?
dr|z3d
both, I think, I'd have to remind myself, but I've got some tracking happening.. > 3 offenses in 15m == ban, so I've got some ips.
dr|z3d
all within a few seconds, as a sample:
dr|z3d
WARN [...PReader 3/6] ...ndEstablishState: [NTCP] Establishment handshake message #3 (part 2) failure -> Signature error
dr|z3d
* For: InboundEstablishState -> Inbound: 193.5.237.114:38481 [Unknown] -> Not established (IB_NTCP2_GOT_RI)
dr|z3d
WARN [NTCP Pumper] ...tboundNTCP2State: OutboundEstablishState -> Outbound: 86.49.236.88:38512 [9Key9P] -> Not established (CORRUPT)
dr|z3d
* Reason: Establishment timeout (>15s)
dr|z3d
WARN [...Handler 2/6] ...blishmentManager: [SSU] PROBING ATTACK or corrupt SessionConfirmed from InboundEstablishState 62.148.157.34:2222
dr|z3d
WARN [...20 (scaled)] ...eStoreMessageJob: Dropping unsolicited NetDbStore of banned LU Router [5BFOv4]
dr|z3d
WARN [NTCP Pumper] ...tboundNTCP2State: OutboundEstablishState -> Outbound: 138.75.200.121:40021 [Q78Dtu] -> Not established (CORRUPT)
dr|z3d
* Reason: Establishment timeout (>15s)
dr|z3d
WARN [NTCP Pumper] ...tboundNTCP2State: OutboundEstablishState -> Outbound: 192.227.222.81:22908 [GwNeBF] -> Not established (CORRUPT)
dr|z3d
* Reason: Establishment timeout (>15s)
dr|z3d
WARN [NTCP Pumper] ...tboundNTCP2State: OutboundEstablishState -> Outbound: 154.20.227.103:24056 [DD-Z7M] -> Not established (CORRUPT)
dr|z3d
* EOF on Inbound connection -> No data received
dr|z3d
WARN [NTCP Pumper] ...ntcp.EventPumper: [NTCP] Failed outbound connection to Router [dusIf2]
dr|z3d
WARN [NTCP Pumper] ...tboundNTCP2State: OutboundEstablishState -> Outbound: 172.90.58.68:17018 [dusIf2] -> Not established (CORRUPT)
dr|z3d
* Connect failed: No route to host
dr|z3d
WARN [NTCP Pumper] ...tboundNTCP2State: OutboundEstablishState -> Outbound: 37.99.200.197:17699 [yQiBPn] -> Not established (CORRUPT)
dr|z3d
* EOF on Inbound connection -> No data received
zzz
hmm. not buying your logging, those all look like outbound
zzz
unless the EOF is from a separate place
dr|z3d
hmm, might need to tighten up my logging.
zzz
timeout for OB is normal ofc
zzz
unless it's on waiting for msg 2
dr|z3d
I bumped the timeout up to 15s, I think you have it at 10, just to make sure we weren't be overly hostile to slow peers.
zzz
then which is it, a probing attack or slow peers? ))
dr|z3d
:)
dr|z3d
this one's likely a probing attack: [SSU] PROBING ATTACK or corrupt SessionConfirmed from InboundEstablishState 62.148.157.34:2222
dr|z3d
the others, well, there's slow and there's problematic. 15s to complete a handshake is potentially abusive.
zzz
a "probing attack" would be specifically with session request, not session confirmed, so it would help to disambiguate those two
dr|z3d
ok. so this, then, potentially:
dr|z3d
WARN [...Handler 2/6] ...blishmentManager: [SSU] Received CORRUPT Session or Token Request after retry -> Router: InboundEstablishState 146.70.200.6:14264
dr|z3d
* General Security Exception: Token mismatch -> Expected: 8995989051980513751 Received: 2013805240410452155
zzz
now you're just throwing out random logs )) try to narrow things down
dr|z3d
ok, let me get to you :)
dr|z3d
*back
dr|z3d
changing the subject, did my message about wrapper building come through yesterday?
dr|z3d
I've got updating the wrapper files down to a single ant command which downloads the deltapack, downloads the source, builds a win64 binary, and removes obsolete files.
dr|z3d
version control with a single version.txt file.
zzz
fancy ))
dr|z3d
haha
dr|z3d
it's in the + repo, if you want to try it. ant updateWrapper is the target.
dr|z3d
you should only need the mingw-w64 package to build for windows.
nyaa2pguy
i wonder if anyone has tried to measure the popularity of b32s by monitoring/counting netdb lookups using multiple routers
dr|z3d
as of now, it's on 3.6.5 which is the latest release version.
zzz
still have my list of all your other build stuff you were promoting, unlikely to take much if any of it, at least not soon
dr|z3d
I don't recall what I was promoting, but help yourself if it makes your life easier.
zzz
shorthand, all the same
zzz
nothing wrong with promotion
dr|z3d
jbigi and the wrapper are probably the most impactful build updates, given the amount of time they take to do manually.
zzz
uop23ip, I couldn't find any routers for those IPs, I'll keep an eye out. I just checked in some fixes so the error doesn't cascade
uop23ip
sent you the ip of latest zzz
zzz
ok, found that one, looks like i2pd but maybe could be emissary
nyaa2pguy
would say it might be me but i've only been testing my router under 1 ip address
orignal
where?