mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-22 07:48:26 +00:00
Add TorTransport in src/transport/tor/ supporting three operating modes: Outbound (socks5 mode): - Non-blocking SOCKS5 connect via tokio-socks with per-destination circuit isolation (IsolateSOCKSAuth) - TorAddr enum for .onion and clearnet address types - Connection pool with per-connection receive tasks, reuses TCP stream FMP framing - connect_async()/connection_state_sync()/promote_connection() follow the same non-blocking polling pattern as TCP transport Inbound (directory mode — recommended for production): - Tor manages the onion service via HiddenServiceDir in torrc - FIPS reads .onion address from hostname file at startup - No control port needed — enables Tor Sandbox 1 (seccomp-bpf) - Accept loop mirrors TCP pattern with DirectoryServiceConfig Monitoring (control_port mode and optional in directory mode): - Async control port client supporting TCP and Unix socket connections via Box<dyn AsyncRead/Write> trait objects - AUTHENTICATE with cookie or password auth - 8 GETINFO queries: bootstrap, circuits, traffic, liveness, version, dormant state, SOCKS listeners - Background monitoring task polls every 10s, caches TorMonitoringInfo in Arc<RwLock> for synchronous query access - Bootstrap milestone logging (25/50/75/100%), stall warning (>60s), network liveness transitions, dormant mode entry - Directory mode optionally connects to control port when control_addr is configured (non-fatal on failure) Operator visibility: - show_transports query exposes tor_mode, onion_address, tor_monitoring (bootstrap, circuit_established, traffic, liveness, version, dormant) - fipstop transport detail view: Tor mode, onion address, SOCKS5/control errors, connection stats, Tor daemon status section - fipstop table view: tor(mode) label with truncated onion address hint Security hardening: - Per-destination circuit isolation via IsolateSOCKSAuth - Unix socket default for control port (/run/tor/control) - Reference torrc with HiddenServiceDir, VanguardsLiteEnabled, ConnectionPadding, DoS protections (PoW + intro rate limiting) Config: - TorConfig with socks5, control_port, and directory modes - DirectoryServiceConfig: hostname_file, bind_addr - control_addr, control_auth, cookie_path, connect_timeout, max_inbound_connections Testing: - 69 unit + integration tests with mock SOCKS5 and control servers - Docker tests: socks5-outbound (clearnet via Tor) and directory-mode (HiddenServiceDir onion service) Documentation: - Transport layer design doc: Tor architecture, directory mode - Configuration doc: Tor config tables and examples
38 lines
1.1 KiB
Docker
38 lines
1.1 KiB
Docker
# Dockerfile for directory-mode test: Tor + FIPS co-located in one container.
|
|
#
|
|
# Tor manages the onion service via HiddenServiceDir. FIPS reads the
|
|
# .onion hostname from /var/lib/tor/fips_onion_service/hostname at startup.
|
|
# This requires Tor to bootstrap and create the hostname file before FIPS
|
|
# starts, so the entrypoint script waits for it.
|
|
|
|
FROM debian:bookworm-slim
|
|
|
|
ARG TORRC=torrc
|
|
|
|
RUN apt-get update && \
|
|
apt-get install -y --no-install-recommends \
|
|
tor iproute2 iputils-ping dnsutils \
|
|
dnsmasq python3 && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
# dnsmasq: forward .fips to FIPS daemon, everything else to Docker DNS
|
|
RUN printf '%s\n' \
|
|
'port=53' \
|
|
'listen-address=127.0.0.1' \
|
|
'bind-interfaces' \
|
|
'server=/fips/127.0.0.1#5354' \
|
|
'server=127.0.0.11' \
|
|
'no-resolv' \
|
|
>> /etc/dnsmasq.conf
|
|
|
|
COPY fips fipsctl /usr/local/bin/
|
|
RUN chmod +x /usr/local/bin/fips /usr/local/bin/fipsctl
|
|
|
|
COPY ${TORRC} /etc/tor/torrc
|
|
COPY entrypoint.sh /entrypoint.sh
|
|
RUN chmod +x /entrypoint.sh
|
|
|
|
COPY resolv.conf /etc/resolv.conf
|
|
|
|
ENTRYPOINT ["/entrypoint.sh"]
|