mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-22 07:48:26 +00:00
Add TorTransport in src/transport/tor/ supporting three operating modes: Outbound (socks5 mode): - Non-blocking SOCKS5 connect via tokio-socks with per-destination circuit isolation (IsolateSOCKSAuth) - TorAddr enum for .onion and clearnet address types - Connection pool with per-connection receive tasks, reuses TCP stream FMP framing - connect_async()/connection_state_sync()/promote_connection() follow the same non-blocking polling pattern as TCP transport Inbound (directory mode — recommended for production): - Tor manages the onion service via HiddenServiceDir in torrc - FIPS reads .onion address from hostname file at startup - No control port needed — enables Tor Sandbox 1 (seccomp-bpf) - Accept loop mirrors TCP pattern with DirectoryServiceConfig Monitoring (control_port mode and optional in directory mode): - Async control port client supporting TCP and Unix socket connections via Box<dyn AsyncRead/Write> trait objects - AUTHENTICATE with cookie or password auth - 8 GETINFO queries: bootstrap, circuits, traffic, liveness, version, dormant state, SOCKS listeners - Background monitoring task polls every 10s, caches TorMonitoringInfo in Arc<RwLock> for synchronous query access - Bootstrap milestone logging (25/50/75/100%), stall warning (>60s), network liveness transitions, dormant mode entry - Directory mode optionally connects to control port when control_addr is configured (non-fatal on failure) Operator visibility: - show_transports query exposes tor_mode, onion_address, tor_monitoring (bootstrap, circuit_established, traffic, liveness, version, dormant) - fipstop transport detail view: Tor mode, onion address, SOCKS5/control errors, connection stats, Tor daemon status section - fipstop table view: tor(mode) label with truncated onion address hint Security hardening: - Per-destination circuit isolation via IsolateSOCKSAuth - Unix socket default for control port (/run/tor/control) - Reference torrc with HiddenServiceDir, VanguardsLiteEnabled, ConnectionPadding, DoS protections (PoW + intro rate limiting) Config: - TorConfig with socks5, control_port, and directory modes - DirectoryServiceConfig: hostname_file, bind_addr - control_addr, control_auth, cookie_path, connect_timeout, max_inbound_connections Testing: - 69 unit + integration tests with mock SOCKS5 and control servers - Docker tests: socks5-outbound (clearnet via Tor) and directory-mode (HiddenServiceDir onion service) Documentation: - Transport layer design doc: Tor architecture, directory mode - Configuration doc: Tor config tables and examples
47 lines
1.3 KiB
Bash
Executable File
47 lines
1.3 KiB
Bash
Executable File
#!/bin/bash
|
|
# Entrypoint for directory-mode test container.
|
|
# Starts Tor, optionally waits for hostname file, then starts FIPS.
|
|
|
|
set -e
|
|
|
|
echo "Starting dnsmasq..."
|
|
dnsmasq
|
|
|
|
# Check if this node uses directory mode (match the YAML value, not comments)
|
|
IS_DIRECTORY_MODE=false
|
|
if grep -qE '^\s+mode:\s+"directory"' /etc/fips/fips.yaml 2>/dev/null; then
|
|
IS_DIRECTORY_MODE=true
|
|
fi
|
|
|
|
# Pre-create HiddenServiceDir with correct permissions.
|
|
# Tor requires 0700 on the directory.
|
|
HIDDEN_SERVICE_DIR="/var/lib/tor/fips_onion_service"
|
|
if [ "$IS_DIRECTORY_MODE" = true ]; then
|
|
mkdir -p "$HIDDEN_SERVICE_DIR"
|
|
chmod 700 "$HIDDEN_SERVICE_DIR"
|
|
fi
|
|
|
|
echo "Starting Tor daemon..."
|
|
tor -f /etc/tor/torrc &
|
|
|
|
# If this node uses directory mode, wait for Tor to create the hostname file
|
|
if [ "$IS_DIRECTORY_MODE" = true ]; then
|
|
HOSTNAME_FILE="${HIDDEN_SERVICE_DIR}/hostname"
|
|
echo "Waiting for Tor to create ${HOSTNAME_FILE}..."
|
|
for i in $(seq 1 120); do
|
|
if [ -f "$HOSTNAME_FILE" ]; then
|
|
echo "Tor hostname file ready after ${i}s: $(cat "$HOSTNAME_FILE")"
|
|
break
|
|
fi
|
|
sleep 1
|
|
done
|
|
|
|
if [ ! -f "$HOSTNAME_FILE" ]; then
|
|
echo "FATAL: Tor did not create hostname file within 120s"
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
echo "Starting FIPS daemon..."
|
|
exec fips --config /etc/fips/fips.yaml
|