update tor from 0.4.9.12-r0 to 0.4.9.13-r0
security release (TROVE-2026-051, TROVE-2026-058), relevant changes:
- onion service: relaunch failed service-side rendezvous circuits exactly
once instead of twice (exponential circuit builds per INTRODUCE2 on
repeated failures)
- onion service: rotate intro point if INTRODUCE2 replay cache is full
- fix use-after-free when TCP connection succeeds immediately but TLS
handshake fails
- fix memory corruption / double-free / null pointer dereference with
some reverse DNS virtual address configurations
- stop blaming guards for circuit, stream & directory-request failures
- HSDirs: rate limit "invalid signature length" log messages
- controller: no longer seg fault on SETCIRCUITPURPOSE without arguments
https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ReleaseNotes
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>