mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-22 07:48:26 +00:00
Add TorTransport in src/transport/tor/ supporting three operating modes: Outbound (socks5 mode): - Non-blocking SOCKS5 connect via tokio-socks with per-destination circuit isolation (IsolateSOCKSAuth) - TorAddr enum for .onion and clearnet address types - Connection pool with per-connection receive tasks, reuses TCP stream FMP framing - connect_async()/connection_state_sync()/promote_connection() follow the same non-blocking polling pattern as TCP transport Inbound (directory mode — recommended for production): - Tor manages the onion service via HiddenServiceDir in torrc - FIPS reads .onion address from hostname file at startup - No control port needed — enables Tor Sandbox 1 (seccomp-bpf) - Accept loop mirrors TCP pattern with DirectoryServiceConfig Monitoring (control_port mode and optional in directory mode): - Async control port client supporting TCP and Unix socket connections via Box<dyn AsyncRead/Write> trait objects - AUTHENTICATE with cookie or password auth - 8 GETINFO queries: bootstrap, circuits, traffic, liveness, version, dormant state, SOCKS listeners - Background monitoring task polls every 10s, caches TorMonitoringInfo in Arc<RwLock> for synchronous query access - Bootstrap milestone logging (25/50/75/100%), stall warning (>60s), network liveness transitions, dormant mode entry - Directory mode optionally connects to control port when control_addr is configured (non-fatal on failure) Operator visibility: - show_transports query exposes tor_mode, onion_address, tor_monitoring (bootstrap, circuit_established, traffic, liveness, version, dormant) - fipstop transport detail view: Tor mode, onion address, SOCKS5/control errors, connection stats, Tor daemon status section - fipstop table view: tor(mode) label with truncated onion address hint Security hardening: - Per-destination circuit isolation via IsolateSOCKSAuth - Unix socket default for control port (/run/tor/control) - Reference torrc with HiddenServiceDir, VanguardsLiteEnabled, ConnectionPadding, DoS protections (PoW + intro rate limiting) Config: - TorConfig with socks5, control_port, and directory modes - DirectoryServiceConfig: hostname_file, bind_addr - control_addr, control_auth, cookie_path, connect_timeout, max_inbound_connections Testing: - 69 unit + integration tests with mock SOCKS5 and control servers - Docker tests: socks5-outbound (clearnet via Tor) and directory-mode (HiddenServiceDir onion service) Documentation: - Transport layer design doc: Tor architecture, directory mode - Configuration doc: Tor config tables and examples
57 lines
1.4 KiB
YAML
57 lines
1.4 KiB
YAML
# Tor transport integration test — directory mode
|
|
#
|
|
# Topology:
|
|
# [fips-a] — Tor + FIPS co-located, HiddenServiceDir onion service
|
|
# [fips-b] — Tor + FIPS co-located, socks5-only, connects to fips-a's .onion
|
|
#
|
|
# Both nodes run Tor and FIPS in the same container. Node A's Tor manages
|
|
# the onion service via HiddenServiceDir with Sandbox 1. Node B connects
|
|
# outbound through its local Tor's SOCKS5 proxy.
|
|
|
|
networks:
|
|
dir-test:
|
|
driver: bridge
|
|
|
|
services:
|
|
fips-a:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile.colocated
|
|
cap_add:
|
|
- NET_ADMIN
|
|
devices:
|
|
- /dev/net/tun:/dev/net/tun
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
restart: "no"
|
|
container_name: fips-dir-a
|
|
hostname: fips-dir-a
|
|
volumes:
|
|
- ./configs/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
environment:
|
|
- RUST_LOG=info,fips::transport::tor=debug
|
|
networks:
|
|
dir-test:
|
|
|
|
fips-b:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile.colocated
|
|
args:
|
|
TORRC: torrc.socks5
|
|
cap_add:
|
|
- NET_ADMIN
|
|
devices:
|
|
- /dev/net/tun:/dev/net/tun
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
restart: "no"
|
|
container_name: fips-dir-b
|
|
hostname: fips-dir-b
|
|
volumes:
|
|
- ./configs/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
environment:
|
|
- RUST_LOG=info,fips::transport::tor=debug
|
|
networks:
|
|
dir-test:
|