Files
fips/testing/tor/directory-mode/entrypoint.sh
Johnathan Corgan 6c90cf6c02 Implement Tor transport with operator visibility
Add TorTransport in src/transport/tor/ supporting three operating modes:

Outbound (socks5 mode):
- Non-blocking SOCKS5 connect via tokio-socks with per-destination
  circuit isolation (IsolateSOCKSAuth)
- TorAddr enum for .onion and clearnet address types
- Connection pool with per-connection receive tasks, reuses TCP
  stream FMP framing
- connect_async()/connection_state_sync()/promote_connection() follow
  the same non-blocking polling pattern as TCP transport

Inbound (directory mode — recommended for production):
- Tor manages the onion service via HiddenServiceDir in torrc
- FIPS reads .onion address from hostname file at startup
- No control port needed — enables Tor Sandbox 1 (seccomp-bpf)
- Accept loop mirrors TCP pattern with DirectoryServiceConfig

Monitoring (control_port mode and optional in directory mode):
- Async control port client supporting TCP and Unix socket connections
  via Box<dyn AsyncRead/Write> trait objects
- AUTHENTICATE with cookie or password auth
- 8 GETINFO queries: bootstrap, circuits, traffic, liveness, version,
  dormant state, SOCKS listeners
- Background monitoring task polls every 10s, caches TorMonitoringInfo
  in Arc<RwLock> for synchronous query access
- Bootstrap milestone logging (25/50/75/100%), stall warning (>60s),
  network liveness transitions, dormant mode entry
- Directory mode optionally connects to control port when control_addr
  is configured (non-fatal on failure)

Operator visibility:
- show_transports query exposes tor_mode, onion_address, tor_monitoring
  (bootstrap, circuit_established, traffic, liveness, version, dormant)
- fipstop transport detail view: Tor mode, onion address, SOCKS5/control
  errors, connection stats, Tor daemon status section
- fipstop table view: tor(mode) label with truncated onion address hint

Security hardening:
- Per-destination circuit isolation via IsolateSOCKSAuth
- Unix socket default for control port (/run/tor/control)
- Reference torrc with HiddenServiceDir, VanguardsLiteEnabled,
  ConnectionPadding, DoS protections (PoW + intro rate limiting)

Config:
- TorConfig with socks5, control_port, and directory modes
- DirectoryServiceConfig: hostname_file, bind_addr
- control_addr, control_auth, cookie_path, connect_timeout,
  max_inbound_connections

Testing:
- 69 unit + integration tests with mock SOCKS5 and control servers
- Docker tests: socks5-outbound (clearnet via Tor) and directory-mode
  (HiddenServiceDir onion service)

Documentation:
- Transport layer design doc: Tor architecture, directory mode
- Configuration doc: Tor config tables and examples
2026-03-15 16:19:54 +00:00

47 lines
1.3 KiB
Bash
Executable File

#!/bin/bash
# Entrypoint for directory-mode test container.
# Starts Tor, optionally waits for hostname file, then starts FIPS.
set -e
echo "Starting dnsmasq..."
dnsmasq
# Check if this node uses directory mode (match the YAML value, not comments)
IS_DIRECTORY_MODE=false
if grep -qE '^\s+mode:\s+"directory"' /etc/fips/fips.yaml 2>/dev/null; then
IS_DIRECTORY_MODE=true
fi
# Pre-create HiddenServiceDir with correct permissions.
# Tor requires 0700 on the directory.
HIDDEN_SERVICE_DIR="/var/lib/tor/fips_onion_service"
if [ "$IS_DIRECTORY_MODE" = true ]; then
mkdir -p "$HIDDEN_SERVICE_DIR"
chmod 700 "$HIDDEN_SERVICE_DIR"
fi
echo "Starting Tor daemon..."
tor -f /etc/tor/torrc &
# If this node uses directory mode, wait for Tor to create the hostname file
if [ "$IS_DIRECTORY_MODE" = true ]; then
HOSTNAME_FILE="${HIDDEN_SERVICE_DIR}/hostname"
echo "Waiting for Tor to create ${HOSTNAME_FILE}..."
for i in $(seq 1 120); do
if [ -f "$HOSTNAME_FILE" ]; then
echo "Tor hostname file ready after ${i}s: $(cat "$HOSTNAME_FILE")"
break
fi
sleep 1
done
if [ ! -f "$HOSTNAME_FILE" ]; then
echo "FATAL: Tor did not create hostname file within 120s"
exit 1
fi
fi
echo "Starting FIPS daemon..."
exec fips --config /etc/fips/fips.yaml