Skip to content

v1.9.0

Latest

Choose a tag to compare

@github-actions github-actions released this 12 Aug 06:29

Fixed

  • A browser can now be launched on a tor-pool exit. The lease's proxy URL carries the session key as its SOCKS5 username, and no browser can send one — Chrome rejects --proxy-server outright when the URL has userinfo — so every challenged host held on a pool endpoint failed the solve it needed, and render() raised on the first call. Dropping the credential would have been worse: the pool keys an unnamed caller by client address, so the browser would leave by a different instance than the requests replaying its clearance, and a clearance from an address that did not earn it reads as the site refusing you. The address now comes from ExitPool.browser_proxy, which asks the pool for the credential-free port its session's instance is on — tor-pool's SESSION_PORT_BASE, which needs the pool's authentication off. A pool without those listeners, or one that has not pinned the session yet, makes the browser tier TierUnavailable rather than launching it somewhere the clearance cannot be replayed from.