committing changes in /etc made by "apt install torbrowser-launcher"
Packages with configuration changes: +tor 0.4.5.10-1~deb11u1 amd64 +torbrowser-launcher 0.3.5-2 amd64 +torsocks 2.3.0-3 amd64 Package changes: +libdouble-conversion3 3.1.5-6.1 amd64 +libmd4c0 0.4.7-2 amd64 +libpcre2-16-0 10.36-2 amd64 +libqt5core5a 5.15.2+dfsg-9 amd64 +libqt5dbus5 5.15.2+dfsg-9 amd64 +libqt5designer5 5.15.2-5 amd64 +libqt5gui5 5.15.2+dfsg-9 amd64 +libqt5help5 5.15.2-5 amd64 +libqt5network5 5.15.2+dfsg-9 amd64 +libqt5printsupport5 5.15.2+dfsg-9 amd64 +libqt5sql5 5.15.2+dfsg-9 amd64 +libqt5sql5-sqlite 5.15.2+dfsg-9 amd64 +libqt5svg5 5.15.2-3 amd64 +libqt5test5 5.15.2+dfsg-9 amd64 +libqt5widgets5 5.15.2+dfsg-9 amd64 +libqt5xml5 5.15.2+dfsg-9 amd64 +libxcb-icccm4 0.4.1-1.1 amd64 +libxcb-image0 0.4.0-1+b3 amd64 +libxcb-keysyms1 0.4.0-1+b2 amd64 +libxcb-render-util0 0.3.9-1+b1 amd64 +libxcb-xinerama0 1.14-3 amd64 +libxcb-xinput0 1.14-3 amd64 +libxcb-xkb1 1.14-3 amd64 +libxkbcommon-x11-0 1.0.3-2 amd64 +python3-packaging 20.9-2 all +python3-pyparsing 2.4.7-1 all +python3-pyqt5 5.15.2+dfsg-3 amd64 +python3-pyqt5.sip 12.8.1-1+b2 amd64 +python3-socks 1.7.1+dfsg-1 all +qt5-gtk-platformtheme 5.15.2+dfsg-9 amd64 +qttranslations5-l10n 5.15.2-2 all +tor 0.4.5.10-1~deb11u1 amd64 +tor-geoipdb 0.4.5.10-1~deb11u1 all +torbrowser-launcher 0.3.5-2 amd64 +torsocks 2.3.0-3 amd64
This commit is contained in:
+21
@@ -443,6 +443,7 @@ maybe chmod 0644 'apparmor.d/abstractions/smbpass'
|
||||
maybe chmod 0644 'apparmor.d/abstractions/ssl_certs'
|
||||
maybe chmod 0644 'apparmor.d/abstractions/ssl_keys'
|
||||
maybe chmod 0644 'apparmor.d/abstractions/svn-repositories'
|
||||
maybe chmod 0644 'apparmor.d/abstractions/tor'
|
||||
maybe chmod 0644 'apparmor.d/abstractions/ubuntu-bittorrent-clients'
|
||||
maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers'
|
||||
maybe chmod 0755 'apparmor.d/abstractions/ubuntu-browsers.d'
|
||||
@@ -489,6 +490,9 @@ maybe chmod 0755 'apparmor.d/local'
|
||||
maybe chmod 0644 'apparmor.d/local/README'
|
||||
maybe chmod 0644 'apparmor.d/local/lsb_release'
|
||||
maybe chmod 0644 'apparmor.d/local/nvidia_modprobe'
|
||||
maybe chmod 0644 'apparmor.d/local/system_tor'
|
||||
maybe chmod 0644 'apparmor.d/local/torbrowser.Browser.firefox'
|
||||
maybe chmod 0644 'apparmor.d/local/torbrowser.Tor.tor'
|
||||
maybe chmod 0644 'apparmor.d/local/usr.bin.man'
|
||||
maybe chmod 0644 'apparmor.d/local/usr.bin.thunderbird'
|
||||
maybe chmod 0644 'apparmor.d/local/usr.lib.libreoffice.program.oosplash'
|
||||
@@ -500,6 +504,9 @@ maybe chmod 0644 'apparmor.d/local/usr.sbin.cupsd'
|
||||
maybe chmod 0644 'apparmor.d/local/usr.sbin.ntpd'
|
||||
maybe chmod 0644 'apparmor.d/lsb_release'
|
||||
maybe chmod 0644 'apparmor.d/nvidia_modprobe'
|
||||
maybe chmod 0644 'apparmor.d/system_tor'
|
||||
maybe chmod 0644 'apparmor.d/torbrowser.Browser.firefox'
|
||||
maybe chmod 0644 'apparmor.d/torbrowser.Tor.tor'
|
||||
maybe chmod 0755 'apparmor.d/tunables'
|
||||
maybe chmod 0644 'apparmor.d/tunables/alias'
|
||||
maybe chmod 0644 'apparmor.d/tunables/apparmorfs'
|
||||
@@ -519,6 +526,7 @@ maybe chmod 0644 'apparmor.d/tunables/run'
|
||||
maybe chmod 0644 'apparmor.d/tunables/securityfs'
|
||||
maybe chmod 0644 'apparmor.d/tunables/share'
|
||||
maybe chmod 0644 'apparmor.d/tunables/sys'
|
||||
maybe chmod 0644 'apparmor.d/tunables/torbrowser'
|
||||
maybe chmod 0644 'apparmor.d/tunables/xdg-user-dirs'
|
||||
maybe chmod 0755 'apparmor.d/tunables/xdg-user-dirs.d'
|
||||
maybe chmod 0644 'apparmor.d/tunables/xdg-user-dirs.d/site.local'
|
||||
@@ -664,6 +672,7 @@ maybe chmod 0755 'cron.weekly'
|
||||
maybe chmod 0644 'cron.weekly/.placeholder'
|
||||
maybe chmod 0755 'cron.weekly/0anacron'
|
||||
maybe chmod 0755 'cron.weekly/man-db'
|
||||
maybe chmod 0755 'cron.weekly/tor'
|
||||
maybe chmod 0644 'crontab'
|
||||
maybe chmod 0755 'cruft'
|
||||
maybe chmod 0755 'cruft/filters-unex'
|
||||
@@ -731,6 +740,7 @@ maybe chmod 0644 'default/rpcbind'
|
||||
maybe chmod 0644 'default/rsync'
|
||||
maybe chmod 0644 'default/saned'
|
||||
maybe chmod 0644 'default/ssh'
|
||||
maybe chmod 0644 'default/tor'
|
||||
maybe chmod 0644 'default/useradd'
|
||||
maybe chmod 0644 'default/xinetd'
|
||||
maybe chmod 0644 'deluser.conf'
|
||||
@@ -954,6 +964,7 @@ maybe chmod 0755 'init.d/speech-dispatcher'
|
||||
maybe chmod 0755 'init.d/ssh'
|
||||
maybe chmod 0755 'init.d/sudo'
|
||||
maybe chmod 0755 'init.d/systune'
|
||||
maybe chmod 0755 'init.d/tor'
|
||||
maybe chmod 0755 'init.d/udev'
|
||||
maybe chmod 0755 'init.d/unattended-upgrades'
|
||||
maybe chmod 0755 'init.d/uuidd'
|
||||
@@ -1082,6 +1093,7 @@ maybe chmod 0644 'logrotate.d/ppp'
|
||||
maybe chmod 0644 'logrotate.d/rsyslog'
|
||||
maybe chmod 0644 'logrotate.d/sane-utils'
|
||||
maybe chmod 0644 'logrotate.d/speech-dispatcher'
|
||||
maybe chmod 0644 'logrotate.d/tor'
|
||||
maybe chmod 0644 'logrotate.d/unattended-upgrades'
|
||||
maybe chmod 0644 'logrotate.d/wtmp'
|
||||
maybe chmod 0755 'lvm'
|
||||
@@ -1538,6 +1550,12 @@ maybe chmod 0755 'sv/ssh/finish'
|
||||
maybe chmod 0755 'sv/ssh/log'
|
||||
maybe chmod 0755 'sv/ssh/log/run'
|
||||
maybe chmod 0755 'sv/ssh/run'
|
||||
maybe chmod 0755 'sv/tor'
|
||||
maybe chmod 0755 'sv/tor/.meta'
|
||||
maybe chmod 0644 'sv/tor/.meta/installed'
|
||||
maybe chmod 0755 'sv/tor/log'
|
||||
maybe chmod 0755 'sv/tor/log/run'
|
||||
maybe chmod 0755 'sv/tor/run'
|
||||
maybe chmod 0755 'synth-shell'
|
||||
maybe chmod 0755 'synth-shell/examples'
|
||||
maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.blue.config'
|
||||
@@ -1595,6 +1613,9 @@ maybe chmod 0644 'timidity/fluidr3_gs.cfg'
|
||||
maybe chmod 0644 'timidity/timgm6mb.cfg'
|
||||
maybe chmod 0755 'tmpfiles.d'
|
||||
maybe chmod 0644 'tmpfiles.d/screen-cleanup.conf'
|
||||
maybe chmod 0755 'tor'
|
||||
maybe chmod 0644 'tor/torrc'
|
||||
maybe chmod 0644 'tor/torsocks.conf'
|
||||
maybe chmod 0644 'ucf.conf'
|
||||
maybe chmod 0755 'udev'
|
||||
maybe chmod 0755 'udev/hwdb.d'
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
# vim:syntax=apparmor
|
||||
|
||||
#include <abstractions/base>
|
||||
#include <abstractions/nameservice>
|
||||
#include <abstractions/openssl>
|
||||
|
||||
network tcp,
|
||||
network udp,
|
||||
|
||||
capability chown,
|
||||
capability dac_read_search,
|
||||
capability fowner,
|
||||
capability fsetid,
|
||||
capability setgid,
|
||||
capability setuid,
|
||||
|
||||
/usr/bin/tor r,
|
||||
/usr/sbin/tor r,
|
||||
|
||||
# Needed by obfs4proxy
|
||||
/proc/sys/net/core/somaxconn r,
|
||||
|
||||
/proc/sys/kernel/random/uuid r,
|
||||
/sys/devices/system/cpu/ r,
|
||||
/sys/devices/system/cpu/** r,
|
||||
|
||||
/etc/tor/* r,
|
||||
/usr/share/tor/** r,
|
||||
|
||||
/usr/bin/obfsproxy PUx,
|
||||
/usr/bin/obfs4proxy Pix,
|
||||
@@ -0,0 +1,25 @@
|
||||
# vim:syntax=apparmor
|
||||
#include <tunables/global>
|
||||
|
||||
profile system_tor flags=(attach_disconnected) {
|
||||
#include <abstractions/tor>
|
||||
|
||||
owner /var/lib/tor/** rwk,
|
||||
owner /var/lib/tor/ r,
|
||||
owner /var/log/tor/* w,
|
||||
|
||||
# During startup, tor (as root) tries to open various things such as
|
||||
# directories via check_private_dir(). Let it.
|
||||
/var/lib/tor/** r,
|
||||
|
||||
/{,var/}run/tor/ r,
|
||||
/{,var/}run/tor/control w,
|
||||
/{,var/}run/tor/socks w,
|
||||
/{,var/}run/tor/tor.pid w,
|
||||
/{,var/}run/tor/control.authcookie w,
|
||||
/{,var/}run/tor/control.authcookie.tmp rw,
|
||||
/{,var/}run/systemd/notify w,
|
||||
|
||||
# Site-specific additions and overrides. See local/README for details.
|
||||
#include <local/system_tor>
|
||||
}
|
||||
@@ -0,0 +1,173 @@
|
||||
#include <tunables/global>
|
||||
#include <tunables/torbrowser>
|
||||
|
||||
@{torbrowser_firefox_executable} = /home/*/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*/Browser/firefox.real
|
||||
|
||||
profile torbrowser_firefox @{torbrowser_firefox_executable} {
|
||||
#include <abstractions/audio>
|
||||
#include <abstractions/dri-enumerate>
|
||||
#include <abstractions/gnome>
|
||||
#include <abstractions/ibus>
|
||||
#include <abstractions/mesa>
|
||||
#include <abstractions/opencl>
|
||||
#include if exists <abstractions/vulkan>
|
||||
#include if exists <abstractions/dbus-session>
|
||||
#include if exists <abstractions/X>
|
||||
|
||||
# Uncomment the following lines if you want to give the Tor Browser read-write
|
||||
# access to most of your personal files.
|
||||
# #include <abstractions/user-download>
|
||||
# @{HOME}/ r,
|
||||
|
||||
# Audio support
|
||||
/{,usr/}bin/pulseaudio Pixr,
|
||||
|
||||
#dbus,
|
||||
network netlink raw,
|
||||
network tcp,
|
||||
|
||||
ptrace (trace) peer=@{profile_name},
|
||||
signal (receive, send) set=("term") peer=@{profile_name},
|
||||
|
||||
deny /etc/host.conf r,
|
||||
deny /etc/hosts r,
|
||||
deny /etc/nsswitch.conf r,
|
||||
deny /etc/os-release r,
|
||||
deny /etc/resolv.conf r,
|
||||
deny /etc/passwd r,
|
||||
deny /etc/group r,
|
||||
deny /etc/mailcap r,
|
||||
|
||||
/etc/machine-id r,
|
||||
/var/lib/dbus/machine-id r,
|
||||
|
||||
/dev/ r,
|
||||
/dev/shm/ r,
|
||||
|
||||
owner @{PROC}/@{pid}/cgroup r,
|
||||
owner @{PROC}/@{pid}/environ r,
|
||||
owner @{PROC}/@{pid}/fd/ r,
|
||||
owner @{PROC}/@{pid}/mountinfo r,
|
||||
owner @{PROC}/@{pid}/stat r,
|
||||
owner @{PROC}/@{pid}/status r,
|
||||
owner @{PROC}/@{pid}/task/*/stat r,
|
||||
@{PROC}/sys/kernel/random/uuid r,
|
||||
|
||||
owner @{torbrowser_installation_dir}/ r,
|
||||
owner @{torbrowser_installation_dir}/* r,
|
||||
owner @{torbrowser_installation_dir}/.** rwk,
|
||||
owner @{torbrowser_installation_dir}/update.test/ rwk,
|
||||
owner @{torbrowser_home_dir}/.** rwk,
|
||||
owner @{torbrowser_home_dir}/ rw,
|
||||
owner @{torbrowser_home_dir}/** rwk,
|
||||
owner @{torbrowser_home_dir}.bak/ rwk,
|
||||
owner @{torbrowser_home_dir}.bak/** rwk,
|
||||
owner @{torbrowser_home_dir}/*.so mr,
|
||||
owner @{torbrowser_home_dir}/.cache/fontconfig/ rwk,
|
||||
owner @{torbrowser_home_dir}/.cache/fontconfig/** rwkl,
|
||||
owner @{torbrowser_home_dir}/browser/** r,
|
||||
owner @{torbrowser_home_dir}/{,browser/}components/*.so mr,
|
||||
owner @{torbrowser_home_dir}/Downloads/ rwk,
|
||||
owner @{torbrowser_home_dir}/Downloads/** rwk,
|
||||
owner @{torbrowser_home_dir}/firefox rix,
|
||||
owner @{torbrowser_home_dir}/{,TorBrowser/UpdateInfo/}updates/[0-9]*/* rw,
|
||||
owner @{torbrowser_home_dir}/{,TorBrowser/UpdateInfo/}updates/[0-9]*/{,MozUpdater/bgupdate/}updater ix,
|
||||
owner @{torbrowser_home_dir}/updater ix,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/Browser/.parentwritetest rw,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/Browser/profiles.ini r,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/{,**} rwk,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/fontconfig/fonts.conf r,
|
||||
owner @{torbrowser_home_dir}/fonts/* l,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/tor px,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/ r,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so mr,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so.* mr,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/libstdc++/*.so mr,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/libstdc++/*.so.* mr,
|
||||
|
||||
# parent Firefox process when restarting after upgrade, Web Content processes
|
||||
owner @{torbrowser_firefox_executable} pxmr -> torbrowser_firefox,
|
||||
|
||||
/etc/mailcap r,
|
||||
/etc/mime.types r,
|
||||
|
||||
/usr/share/ r,
|
||||
/usr/share/glib-2.0/schemas/gschemas.compiled r,
|
||||
/usr/share/mime/ r,
|
||||
/usr/share/themes/ r,
|
||||
/usr/share/applications/** rk,
|
||||
/usr/share/gnome/applications/ r,
|
||||
/usr/share/gnome/applications/kde4/ r,
|
||||
/usr/share/poppler/cMap/ r,
|
||||
/etc/xdg/mimeapps.list r,
|
||||
|
||||
# Distribution homepage
|
||||
/usr/share/homepage/ r,
|
||||
/usr/share/homepage/** r,
|
||||
|
||||
/sys/bus/pci/devices/ r,
|
||||
@{sys}/devices/pci[0-9]*/**/irq r,
|
||||
/sys/devices/system/cpu/ r,
|
||||
/sys/devices/system/cpu/present r,
|
||||
/sys/devices/system/node/ r,
|
||||
/sys/devices/system/node/node[0-9]*/meminfo r,
|
||||
/sys/fs/cgroup/cpu,cpuacct/{,user.slice/}cpu.cfs_quota_us r,
|
||||
deny /sys/devices/virtual/block/*/uevent r,
|
||||
|
||||
# Should use abstractions/gstreamer instead once merged upstream
|
||||
/etc/udev/udev.conf r,
|
||||
/run/udev/data/+pci:* r,
|
||||
/sys/devices/pci[0-9]*/**/uevent r,
|
||||
owner /{dev,run}/shm/shmfd-* rw,
|
||||
|
||||
# Required for multiprocess Firefox (aka Electrolysis, i.e. e10s)
|
||||
owner /{dev,run}/shm/org.chromium.* rw,
|
||||
owner /dev/shm/org.mozilla.ipc.[0-9]*.[0-9]* rw, # for Chromium IPC
|
||||
|
||||
# Required for Wayland display protocol support
|
||||
owner /dev/shm/wayland.mozilla.ipc.[0-9]* rw,
|
||||
|
||||
# Silence denial logs about permissions we don't need
|
||||
deny @{HOME}/.cache/fontconfig/ rw,
|
||||
deny @{HOME}/.cache/fontconfig/** rw,
|
||||
deny @{HOME}/.config/gtk-2.0/ rw,
|
||||
deny @{HOME}/.config/gtk-2.0/** rw,
|
||||
deny @{PROC}/@{pid}/net/route r,
|
||||
deny /sys/devices/system/cpu/cpufreq/policy[0-9]*/cpuinfo_max_freq r,
|
||||
deny /sys/devices/system/cpu/*/cache/index[0-9]*/size r,
|
||||
deny /run/user/[0-9]*/dconf/user rw,
|
||||
deny /usr/bin/lsb_release x,
|
||||
|
||||
# Silence denial logs about PulseAudio
|
||||
deny /etc/pulse/client.conf r,
|
||||
deny /usr/bin/pulseaudio x,
|
||||
|
||||
# KDE 4
|
||||
owner @{HOME}/.kde/share/config/* r,
|
||||
|
||||
# Xfce4
|
||||
/etc/xfce4/defaults.list r,
|
||||
/usr/share/xfce4/applications/ r,
|
||||
|
||||
# u2f (tested with Yubikey 4)
|
||||
/sys/class/ r,
|
||||
/sys/bus/ r,
|
||||
/sys/class/hidraw/ r,
|
||||
/run/udev/data/c24{5,7,9}:* r,
|
||||
/dev/hidraw* rw,
|
||||
# Yubikey NEO also needs this:
|
||||
/sys/devices/**/hidraw/hidraw*/uevent r,
|
||||
|
||||
# Needed for Firefox sandboxing via unprivileged user namespaces
|
||||
capability sys_admin,
|
||||
capability sys_chroot,
|
||||
owner @{PROC}/@{pid}/{gid,uid}_map w,
|
||||
owner @{PROC}/@{pid}/setgroups w,
|
||||
|
||||
# Remove these rules once we can assume abstractions/vulkan is recent enough
|
||||
# to include them
|
||||
/etc/glvnd/egl_vendor.d/{*,.json} r,
|
||||
/usr/share/glvnd/egl_vendor.d/{,*.json} r,
|
||||
|
||||
#include <local/torbrowser.Browser.firefox>
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
#include <tunables/global>
|
||||
#include <tunables/torbrowser>
|
||||
|
||||
@{torbrowser_tor_executable} = /home/*/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*/Browser/TorBrowser/Tor/tor
|
||||
|
||||
profile torbrowser_tor @{torbrowser_tor_executable} {
|
||||
#include <abstractions/base>
|
||||
|
||||
network netlink raw,
|
||||
network tcp,
|
||||
network udp,
|
||||
|
||||
/etc/host.conf r,
|
||||
/etc/nsswitch.conf r,
|
||||
/etc/passwd r,
|
||||
/etc/resolv.conf r,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/tor mr,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/Tor/ rw,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/Tor/** rw,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Data/Tor/lock rwk,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so mr,
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so.* mr,
|
||||
|
||||
# Support some of the included pluggable transports
|
||||
owner @{torbrowser_home_dir}/TorBrowser/Tor/PluggableTransports/** rix,
|
||||
@{PROC}/sys/net/core/somaxconn r,
|
||||
#include <abstractions/ssl_certs>
|
||||
|
||||
# Silence file_inherit logs
|
||||
deny @{torbrowser_home_dir}/{browser/,}omni.ja r,
|
||||
deny @{torbrowser_home_dir}/{browser/,}features/*.xpi r,
|
||||
deny @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/.parentlock rw,
|
||||
deny @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/extensions/*.xpi r,
|
||||
deny @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/startupCache/* r,
|
||||
# Silence logs from included pluggable transports
|
||||
deny /etc/hosts r,
|
||||
deny /etc/services r,
|
||||
|
||||
@{PROC}/sys/kernel/random/uuid r,
|
||||
/sys/devices/system/cpu/ r,
|
||||
/sys/kernel/mm/transparent_hugepage/hpage_pmd_size r,
|
||||
|
||||
# OnionShare compatibility
|
||||
/tmp/onionshare/** rw,
|
||||
|
||||
#include <local/torbrowser.Tor.tor>
|
||||
}
|
||||
@@ -0,0 +1,2 @@
|
||||
@{torbrowser_installation_dir}=@{HOME}/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*
|
||||
@{torbrowser_home_dir}=@{torbrowser_installation_dir}/Browser
|
||||
Executable
+16
@@ -0,0 +1,16 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -e
|
||||
set -u
|
||||
|
||||
DEFAULTSFILE=/etc/default/tor
|
||||
|
||||
if [ -f $DEFAULTSFILE ] ; then
|
||||
. $DEFAULTSFILE
|
||||
fi
|
||||
|
||||
if [ "${CLEANUP_OLD_COREFILES:-}" = "y" ] ; then
|
||||
if [ -d /var/lib/tor ] ; then
|
||||
find /var/lib/tor -mindepth 1 -maxdepth 1 -type f -mtime +21 -user debian-tor -regex '.*/core\(\.[0-9]+\)?' -exec rm '{}' +
|
||||
fi
|
||||
fi
|
||||
+75
@@ -0,0 +1,75 @@
|
||||
# Defaults for tor initscript
|
||||
# sourced by /etc/init.d/tor
|
||||
# installed at /etc/default/tor by the maintainer scripts
|
||||
#
|
||||
# Note that this file is not being used for controlling Tor-startup
|
||||
# when Tor is launched by systemd.
|
||||
#
|
||||
|
||||
#
|
||||
# This is a bash shell fragment
|
||||
#
|
||||
RUN_DAEMON="yes"
|
||||
|
||||
#
|
||||
# Servers sometimes may need more than the default 1024 file descriptors
|
||||
# if they are very busy and have many clients connected to them. The top
|
||||
# servers as of early 2008 regularly have more than 10000 connected
|
||||
# clients.
|
||||
# (ulimit -n)
|
||||
#
|
||||
# (the default varies as it depends on the number of available system-wide file
|
||||
# descriptors. See the init script in /etc/init.d/tor for details.)
|
||||
#
|
||||
# MAX_FILEDESCRIPTORS=
|
||||
|
||||
#
|
||||
# If tor is seriously hogging your CPU, taking away too much cycles from
|
||||
# other system resources, then you can renice tor. See nice(1) for a
|
||||
# bit more information. Another way to limit the CPU usage of an Onion
|
||||
# Router is to set a lower BandwidthRate, as CPU usage is mostly a function
|
||||
# of the amount of traffic flowing through your node. Consult the torrc(5)
|
||||
# manual page for more information on setting BandwidthRate.
|
||||
#
|
||||
# NICE="--nicelevel 5"
|
||||
|
||||
# Additional arguments to pass on tor's command line.
|
||||
#
|
||||
# ARGS="$ARGS "
|
||||
|
||||
#
|
||||
# Uncomment the ulimit call below, and set "DisableDebuggerAttachment 0"
|
||||
# in /etc/tor/torrc, if you want tor to produce coredumps on segfaults
|
||||
# and assert errors.
|
||||
#
|
||||
# Keeping coredumps around is some sort of security issue since they
|
||||
# may leak session keys, sensitive client data and more, should such
|
||||
# files fall into the wrong hands. Therefore coredumps are not enabled
|
||||
# by default.
|
||||
#
|
||||
# ulimit -c unlimited
|
||||
|
||||
#
|
||||
# Config option for the weekly cron file: Whether or not to remove old
|
||||
# coredumps in /var/lib/tor. Coredumps can hold sensitive data, as such
|
||||
# they probably should not be kept lying around if nobody will ever look
|
||||
# at them. This option makes /etc/cron.weekly/tor clean out files older
|
||||
# then three weeks.
|
||||
#
|
||||
CLEANUP_OLD_COREFILES=y
|
||||
|
||||
#
|
||||
# By default the tor init script will launch Tor using apparmor iff
|
||||
# /usr/sbin/aa-status exists and is executable and calling it with --enabled
|
||||
# returns true, /usr/sbin/aa-exec is executable, there is a
|
||||
# /etc/apparmor.d/system_tor policy, and USE_AA_EXEC is set to 'yes'.
|
||||
#
|
||||
# USE_AA_EXEC="yes" # default
|
||||
# USE_AA_EXEC="no"
|
||||
|
||||
# Let the vidalia package override some of our settings.
|
||||
# People who have vidalia installed might not want to run Tor as a system
|
||||
# service. The vidalia .deb can ask them that and then set run-daemon to no.
|
||||
if [ -e /etc/default/tor.vidalia ] && [ -x /usr/bin/vidalia ]; then
|
||||
. /etc/default/tor.vidalia
|
||||
fi
|
||||
@@ -73,3 +73,4 @@ wheel:x:1003:pi
|
||||
_flatpak:x:129:
|
||||
tss:x:130:
|
||||
docker:x:998:
|
||||
debian-tor:x:131:
|
||||
|
||||
@@ -72,3 +72,4 @@ pi:x:1002:
|
||||
wheel:x:1003:pi
|
||||
_flatpak:x:129:
|
||||
tss:x:130:
|
||||
docker:x:998:
|
||||
|
||||
Executable
+253
@@ -0,0 +1,253 @@
|
||||
#! /bin/bash
|
||||
|
||||
### BEGIN INIT INFO
|
||||
# Provides: tor
|
||||
# Required-Start: $local_fs $remote_fs $network $named $time
|
||||
# Required-Stop: $local_fs $remote_fs $network $named $time
|
||||
# Should-Start: $syslog
|
||||
# Should-Stop: $syslog
|
||||
# Default-Start: 2 3 4 5
|
||||
# Default-Stop: 0 1 6
|
||||
# Short-Description: Starts The Onion Router daemon processes
|
||||
# Description: Start The Onion Router, a TCP overlay
|
||||
# network client that provides anonymous
|
||||
# transport.
|
||||
### END INIT INFO
|
||||
|
||||
# Load the VERBOSE setting and other rcS variables
|
||||
. /lib/init/vars.sh
|
||||
|
||||
# Define LSB log_* functions.
|
||||
. /lib/lsb/init-functions
|
||||
|
||||
PATH=/sbin:/bin:/usr/sbin:/usr/bin
|
||||
DAEMON=/usr/bin/tor
|
||||
NAME=tor
|
||||
DESC="tor daemon"
|
||||
TORLOGDIR=/var/log/tor
|
||||
TORPIDDIR=/run/tor
|
||||
TORPID=$TORPIDDIR/tor.pid
|
||||
DEFAULTSFILE=/etc/default/$NAME
|
||||
WAITFORDAEMON=60
|
||||
DEFAULT_ARGS="--defaults-torrc /usr/share/tor/tor-service-defaults-torrc"
|
||||
VERIFY_ARGS="--verify-config $DEFAULT_ARGS"
|
||||
USE_AA_EXEC="yes"
|
||||
ARGS=""
|
||||
if [ "${VERBOSE:-}" != "yes" ]; then
|
||||
ARGS="$ARGS --hush"
|
||||
fi
|
||||
|
||||
# Let's try to figure our some sane defaults:
|
||||
if [ -r /proc/sys/fs/file-max ]; then
|
||||
system_max=`cat /proc/sys/fs/file-max`
|
||||
if [ "$system_max" -gt "80000" ] ; then
|
||||
MAX_FILEDESCRIPTORS=32768
|
||||
elif [ "$system_max" -gt "40000" ] ; then
|
||||
MAX_FILEDESCRIPTORS=16384
|
||||
elif [ "$system_max" -gt "10000" ] ; then
|
||||
MAX_FILEDESCRIPTORS=8192
|
||||
else
|
||||
MAX_FILEDESCRIPTORS=1024
|
||||
cat << EOF
|
||||
|
||||
Warning: Your system has very few filedescriptors available in total.
|
||||
|
||||
Maybe you should try raising that by adding 'fs.file-max=100000' to your
|
||||
/etc/sysctl.conf file. Feel free to pick any number that you deem appropriate.
|
||||
Then run 'sysctl -p'. See /proc/sys/fs/file-max for the current value, and
|
||||
file-nr in the same directory for how many of those are used at the moment.
|
||||
|
||||
EOF
|
||||
fi
|
||||
else
|
||||
MAX_FILEDESCRIPTORS=8192
|
||||
fi
|
||||
|
||||
NICE=""
|
||||
|
||||
test -x $DAEMON || exit 0
|
||||
|
||||
# Include tor defaults if available
|
||||
if [ -f $DEFAULTSFILE ] ; then
|
||||
. $DEFAULTSFILE
|
||||
fi
|
||||
|
||||
wait_for_deaddaemon () {
|
||||
pid=$1
|
||||
sleep 1
|
||||
if test -n "$pid"
|
||||
then
|
||||
if kill -0 $pid 2>/dev/null
|
||||
then
|
||||
cnt=0
|
||||
while kill -0 $pid 2>/dev/null
|
||||
do
|
||||
cnt=`expr $cnt + 1`
|
||||
if [ $cnt -gt $WAITFORDAEMON ]
|
||||
then
|
||||
log_action_end_msg 1 "still running"
|
||||
exit 1
|
||||
fi
|
||||
sleep 1
|
||||
[ "`expr $cnt % 3`" != 2 ] || log_action_cont_msg ""
|
||||
done
|
||||
fi
|
||||
fi
|
||||
log_action_end_msg 0
|
||||
}
|
||||
|
||||
|
||||
check_torpiddir () {
|
||||
if test ! -d $TORPIDDIR; then
|
||||
mkdir -m 02755 "$TORPIDDIR"
|
||||
chown debian-tor:debian-tor "$TORPIDDIR"
|
||||
! [ -x /sbin/restorecon ] || /sbin/restorecon "$TORPIDDIR"
|
||||
fi
|
||||
|
||||
if test ! -x $TORPIDDIR; then
|
||||
log_action_end_msg 1 "cannot access $TORPIDDIR directory, are you root?"
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
check_torlogdir () {
|
||||
if test ! -d $TORLOGDIR; then
|
||||
mkdir -m 02750 "$TORLOGDIR"
|
||||
chown debian-tor:adm "$TORLOGDIR"
|
||||
! [ -x /sbin/restorecon ] || /sbin/restorecon "$TORPIDDIR"
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
check_config () {
|
||||
if ! $DAEMON $VERIFY_ARGS > /dev/null; then
|
||||
log_failure_msg "Checking if $NAME configuration is valid"
|
||||
$DAEMON $VERIFY_ARGS >&2
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
case "$1" in
|
||||
start)
|
||||
if [ "$RUN_DAEMON" != "yes" ]; then
|
||||
log_action_msg "Not starting $DESC (Disabled in $DEFAULTSFILE)."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if [ -n "$MAX_FILEDESCRIPTORS" ]; then
|
||||
[ "${VERBOSE:-}" != "yes" ] || log_action_begin_msg "Raising maximum number of filedescriptors (ulimit -n) for tor to $MAX_FILEDESCRIPTORS"
|
||||
if ulimit -n "$MAX_FILEDESCRIPTORS" ; then
|
||||
[ "${VERBOSE:-}" != "yes" ] || log_action_end_msg 0
|
||||
else
|
||||
[ "${VERBOSE:-}" != "yes" ] || log_action_end_msg 1
|
||||
fi
|
||||
fi
|
||||
|
||||
check_torpiddir
|
||||
check_torlogdir
|
||||
check_config
|
||||
|
||||
log_action_begin_msg "Starting $DESC"
|
||||
|
||||
if start-stop-daemon --stop --signal 0 --quiet --pidfile $TORPID --exec $DAEMON; then
|
||||
log_action_end_msg 0 "already running"
|
||||
else
|
||||
if [ "$USE_AA_EXEC" = "yes" ] &&
|
||||
command -v aa-status > /dev/null &&
|
||||
command -v aa-exec > /dev/null &&
|
||||
[ -e /etc/apparmor.d/system_tor ] && \
|
||||
aa-status --enabled ; then
|
||||
AA_EXEC_PATH=$(command -v aa-exec)
|
||||
AA_EXEC="--startas $AA_EXEC_PATH"
|
||||
AA_EXEC_ARGS="--profile=system_tor -- $DAEMON"
|
||||
else
|
||||
AA_EXEC=""
|
||||
AA_EXEC_ARGS=""
|
||||
fi
|
||||
if start-stop-daemon --start --quiet \
|
||||
--pidfile $TORPID \
|
||||
$NICE \
|
||||
$AA_EXEC \
|
||||
--exec $DAEMON -- $AA_EXEC_ARGS $DEFAULT_ARGS $ARGS
|
||||
then
|
||||
log_action_end_msg 0
|
||||
else
|
||||
log_action_end_msg 1
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
;;
|
||||
stop)
|
||||
log_action_begin_msg "Stopping $DESC"
|
||||
pid=`cat $TORPID 2>/dev/null` || true
|
||||
|
||||
if test ! -f $TORPID -o -z "$pid"; then
|
||||
log_action_end_msg 0 "not running - there is no $TORPID"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if start-stop-daemon --stop --signal INT --quiet --pidfile $TORPID --exec $DAEMON; then
|
||||
wait_for_deaddaemon $pid
|
||||
elif kill -0 $pid 2>/dev/null; then
|
||||
log_action_end_msg 1 "Is $pid not $NAME? Is $DAEMON a different binary now?"
|
||||
exit 1
|
||||
else
|
||||
log_action_end_msg 1 "$DAEMON died: process $pid not running; or permission denied"
|
||||
exit 1
|
||||
fi
|
||||
;;
|
||||
reload|force-reload)
|
||||
check_config
|
||||
|
||||
log_action_begin_msg "Reloading $DESC configuration"
|
||||
pid=`cat $TORPID 2>/dev/null` || true
|
||||
|
||||
if test ! -f $TORPID -o -z "$pid"; then
|
||||
log_action_end_msg 1 "not running - there is no $TORPID"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if start-stop-daemon --stop --signal 1 --quiet --pidfile $TORPID --exec $DAEMON
|
||||
then
|
||||
log_action_end_msg 0
|
||||
elif kill -0 $pid 2>/dev/null; then
|
||||
log_action_end_msg 1 "Is $pid not $NAME? Is $DAEMON a different binary now?"
|
||||
exit 1
|
||||
else
|
||||
log_action_end_msg 1 "$DAEMON died: process $pid not running; or permission denied"
|
||||
exit 1
|
||||
fi
|
||||
;;
|
||||
restart)
|
||||
check_config
|
||||
|
||||
$0 stop
|
||||
sleep 1
|
||||
$0 start
|
||||
;;
|
||||
status)
|
||||
if test ! -r $(dirname $TORPID); then
|
||||
log_failure_msg "cannot read PID file $TORPID"
|
||||
exit 4
|
||||
fi
|
||||
pid=`cat $TORPID 2>/dev/null` || true
|
||||
if test ! -f $TORPID -o -z "$pid"; then
|
||||
log_failure_msg "$NAME is not running"
|
||||
exit 3
|
||||
fi
|
||||
if start-stop-daemon --pid "$pid" -T ; then
|
||||
log_success_msg "$NAME is running"
|
||||
exit 0
|
||||
else
|
||||
log_failure_msg "$NAME is not running"
|
||||
exit 1
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
log_action_msg "Usage: $0 {start|stop|restart|reload|force-reload|status}" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
exit 0
|
||||
@@ -0,0 +1,15 @@
|
||||
/var/log/tor/*log {
|
||||
daily
|
||||
rotate 5
|
||||
compress
|
||||
delaycompress
|
||||
missingok
|
||||
notifempty
|
||||
create 0640 debian-tor adm
|
||||
sharedscripts
|
||||
postrotate
|
||||
if invoke-rc.d tor status > /dev/null; then
|
||||
invoke-rc.d tor reload > /dev/null
|
||||
fi
|
||||
endscript
|
||||
}
|
||||
@@ -43,3 +43,4 @@ uuidd:x:120:128::/run/uuidd:/usr/sbin/nologin
|
||||
pi:x:1001:1002::/home/pi:/bin/bash
|
||||
_flatpak:x:121:129:Flatpak system-wide installation helper,,,:/nonexistent:/usr/sbin/nologin
|
||||
tss:x:122:130:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
debian-tor:x:123:131::/var/lib/tor:/bin/false
|
||||
|
||||
@@ -42,4 +42,5 @@ statd:x:119:65534::/var/lib/nfs:/usr/sbin/nologin
|
||||
uuidd:x:120:128::/run/uuidd:/usr/sbin/nologin
|
||||
pi:x:1001:1002::/home/pi:/bin/bash
|
||||
_flatpak:x:121:129:Flatpak system-wide installation helper,,,:/nonexistent:/usr/sbin/nologin
|
||||
tss:x:122:130::/var/lib/tpm:/bin/false
|
||||
tss:x:122:130:TPM software stack,,,:/var/lib/tpm:/bin/false
|
||||
debian-tor:x:123:131::/var/lib/tor:/bin/false
|
||||
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../init.d/tor
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
/etc/sv/tor
|
||||
@@ -43,3 +43,4 @@ uuidd:*:19115:0:99999:7:::
|
||||
pi:$y$j9T$OvZKYo/X0taV3uBG47Fxu0$CAvPg3ND5EmSJDmuurGqt1HxmNJ7y392RjYB5934Qs1:19116:0:99999:7:::
|
||||
_flatpak:*:19118:0:99999:7:::
|
||||
tss:*:19118:0:99999:7:::
|
||||
debian-tor:*:19128:0:99999:7:::
|
||||
|
||||
@@ -43,3 +43,4 @@ uuidd:*:19115:0:99999:7:::
|
||||
pi:$y$j9T$OvZKYo/X0taV3uBG47Fxu0$CAvPg3ND5EmSJDmuurGqt1HxmNJ7y392RjYB5934Qs1:19116:0:99999:7:::
|
||||
_flatpak:*:19118:0:99999:7:::
|
||||
tss:*:19118:0:99999:7:::
|
||||
debian-tor:*:19128:0:99999:7:::
|
||||
|
||||
Executable
+4
@@ -0,0 +1,4 @@
|
||||
#!/bin/sh
|
||||
chown _runit-log:adm '/var/log/runit/tor'
|
||||
chmod 750 '/var/log/runit/tor'
|
||||
exec chpst -u _runit-log svlogd -tt '/var/log/runit/tor'
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
/run/runit/supervise/tor.log
|
||||
Executable
+33
@@ -0,0 +1,33 @@
|
||||
#!/usr/bin/env /lib/runit/invoke-run
|
||||
readonly daemon=/usr/bin/tor
|
||||
exec 2>&1
|
||||
|
||||
# This directory is referenced in /usr/share/tor/tor-service-defaults-torrc
|
||||
# and must exist.
|
||||
readonly rundir=/run/tor
|
||||
if ! [ -d "${rundir}" ]; then
|
||||
mkdir -m 02755 "${rundir}"
|
||||
chown debian-tor:debian-tor "${rundir}"
|
||||
! [ -x /sbin/restorecon ] || /sbin/restorecon "${rundir}"
|
||||
fi
|
||||
|
||||
MAX_FILEDESCRIPTORS="${MAX_FILEDESCRIPTORS:-65536}"
|
||||
ulimit -n "${MAX_FILEDESCRIPTORS}"
|
||||
|
||||
# default invocation
|
||||
set -- "${daemon}" \
|
||||
--defaults-torrc /usr/share/tor/tor-service-defaults-torrc \
|
||||
-f /etc/tor/torrc \
|
||||
--Log 'notice stdout' \
|
||||
--RunAsDaemon 0
|
||||
|
||||
if ! "$@" --verify-config ; then
|
||||
echo "persistent error: Tor configuration is not valid"
|
||||
exec sv down tor
|
||||
fi
|
||||
|
||||
if aa-status --enabled ; then
|
||||
set -- /usr/bin/aa-exec --profile=system_tor -- "$@"
|
||||
fi
|
||||
|
||||
exec /usr/bin/env -i "$@"
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
/run/runit/supervise/tor
|
||||
@@ -0,0 +1 @@
|
||||
/lib/systemd/system/tor.service
|
||||
@@ -0,0 +1,192 @@
|
||||
## Configuration file for a typical Tor user
|
||||
## Last updated 9 October 2013 for Tor 0.2.5.2-alpha.
|
||||
## (may or may not work for much older or much newer versions of Tor.)
|
||||
##
|
||||
## Lines that begin with "## " try to explain what's going on. Lines
|
||||
## that begin with just "#" are disabled commands: you can enable them
|
||||
## by removing the "#" symbol.
|
||||
##
|
||||
## See 'man tor', or https://www.torproject.org/docs/tor-manual.html,
|
||||
## for more options you can use in this file.
|
||||
##
|
||||
## Tor will look for this file in various places based on your platform:
|
||||
## https://www.torproject.org/docs/faq#torrc
|
||||
|
||||
## Tor opens a socks proxy on port 9050 by default -- even if you don't
|
||||
## configure one below. Set "SocksPort 0" if you plan to run Tor only
|
||||
## as a relay, and not make any local application connections yourself.
|
||||
#SocksPort 9050 # Default: Bind to localhost:9050 for local connections.
|
||||
#SocksPort 192.168.0.1:9100 # Bind to this address:port too.
|
||||
|
||||
## Entry policies to allow/deny SOCKS requests based on IP address.
|
||||
## First entry that matches wins. If no SocksPolicy is set, we accept
|
||||
## all (and only) requests that reach a SocksPort. Untrusted users who
|
||||
## can access your SocksPort may be able to learn about the connections
|
||||
## you make.
|
||||
#SocksPolicy accept 192.168.0.0/16
|
||||
#SocksPolicy reject *
|
||||
|
||||
## Logs go to stdout at level "notice" unless redirected by something
|
||||
## else, like one of the below lines. You can have as many Log lines as
|
||||
## you want.
|
||||
##
|
||||
## We advise using "notice" in most cases, since anything more verbose
|
||||
## may provide sensitive information to an attacker who obtains the logs.
|
||||
##
|
||||
## Send all messages of level 'notice' or higher to /var/log/tor/notices.log
|
||||
#Log notice file /var/log/tor/notices.log
|
||||
## Send every possible message to /var/log/tor/debug.log
|
||||
#Log debug file /var/log/tor/debug.log
|
||||
## Use the system log instead of Tor's logfiles
|
||||
#Log notice syslog
|
||||
## To send all messages to stderr:
|
||||
#Log debug stderr
|
||||
|
||||
## Uncomment this to start the process in the background... or use
|
||||
## --runasdaemon 1 on the command line. This is ignored on Windows;
|
||||
## see the FAQ entry if you want Tor to run as an NT service.
|
||||
#RunAsDaemon 1
|
||||
|
||||
## The directory for keeping all the keys/etc. By default, we store
|
||||
## things in $HOME/.tor on Unix, and in Application Data\tor on Windows.
|
||||
#DataDirectory /var/lib/tor
|
||||
|
||||
## The port on which Tor will listen for local connections from Tor
|
||||
## controller applications, as documented in control-spec.txt.
|
||||
#ControlPort 9051
|
||||
## If you enable the controlport, be sure to enable one of these
|
||||
## authentication methods, to prevent attackers from accessing it.
|
||||
#HashedControlPassword 16:872860B76453A77D60CA2BB8C1A7042072093276A3D701AD684053EC4C
|
||||
#CookieAuthentication 1
|
||||
|
||||
############### This section is just for location-hidden services ###
|
||||
|
||||
## Once you have configured a hidden service, you can look at the
|
||||
## contents of the file ".../hidden_service/hostname" for the address
|
||||
## to tell people.
|
||||
##
|
||||
## HiddenServicePort x y:z says to redirect requests on port x to the
|
||||
## address y:z.
|
||||
|
||||
#HiddenServiceDir /var/lib/tor/hidden_service/
|
||||
#HiddenServicePort 80 127.0.0.1:80
|
||||
|
||||
#HiddenServiceDir /var/lib/tor/other_hidden_service/
|
||||
#HiddenServicePort 80 127.0.0.1:80
|
||||
#HiddenServicePort 22 127.0.0.1:22
|
||||
|
||||
################ This section is just for relays #####################
|
||||
#
|
||||
## See https://www.torproject.org/docs/tor-doc-relay for details.
|
||||
|
||||
## Required: what port to advertise for incoming Tor connections.
|
||||
#ORPort 9001
|
||||
## If you want to listen on a port other than the one advertised in
|
||||
## ORPort (e.g. to advertise 443 but bind to 9090), you can do it as
|
||||
## follows. You'll need to do ipchains or other port forwarding
|
||||
## yourself to make this work.
|
||||
#ORPort 443 NoListen
|
||||
#ORPort 127.0.0.1:9090 NoAdvertise
|
||||
|
||||
## The IP address or full DNS name for incoming connections to your
|
||||
## relay. Leave commented out and Tor will guess.
|
||||
#Address noname.example.com
|
||||
|
||||
## If you have multiple network interfaces, you can specify one for
|
||||
## outgoing traffic to use.
|
||||
# OutboundBindAddress 10.0.0.5
|
||||
|
||||
## A handle for your relay, so people don't have to refer to it by key.
|
||||
#Nickname ididnteditheconfig
|
||||
|
||||
## Define these to limit how much relayed traffic you will allow. Your
|
||||
## own traffic is still unthrottled. Note that RelayBandwidthRate must
|
||||
## be at least 20 KB.
|
||||
## Note that units for these config options are bytes per second, not bits
|
||||
## per second, and that prefixes are binary prefixes, i.e. 2^10, 2^20, etc.
|
||||
#RelayBandwidthRate 100 KB # Throttle traffic to 100KB/s (800Kbps)
|
||||
#RelayBandwidthBurst 200 KB # But allow bursts up to 200KB/s (1600Kbps)
|
||||
|
||||
## Use these to restrict the maximum traffic per day, week, or month.
|
||||
## Note that this threshold applies separately to sent and received bytes,
|
||||
## not to their sum: setting "4 GB" may allow up to 8 GB total before
|
||||
## hibernating.
|
||||
##
|
||||
## Set a maximum of 4 gigabytes each way per period.
|
||||
#AccountingMax 4 GB
|
||||
## Each period starts daily at midnight (AccountingMax is per day)
|
||||
#AccountingStart day 00:00
|
||||
## Each period starts on the 3rd of the month at 15:00 (AccountingMax
|
||||
## is per month)
|
||||
#AccountingStart month 3 15:00
|
||||
|
||||
## Administrative contact information for this relay or bridge. This line
|
||||
## can be used to contact you if your relay or bridge is misconfigured or
|
||||
## something else goes wrong. Note that we archive and publish all
|
||||
## descriptors containing these lines and that Google indexes them, so
|
||||
## spammers might also collect them. You may want to obscure the fact that
|
||||
## it's an email address and/or generate a new address for this purpose.
|
||||
#ContactInfo Random Person <nobody AT example dot com>
|
||||
## You might also include your PGP or GPG fingerprint if you have one:
|
||||
#ContactInfo 0xFFFFFFFF Random Person <nobody AT example dot com>
|
||||
|
||||
## Uncomment this to mirror directory information for others. Please do
|
||||
## if you have enough bandwidth.
|
||||
#DirPort 9030 # what port to advertise for directory connections
|
||||
## If you want to listen on a port other than the one advertised in
|
||||
## DirPort (e.g. to advertise 80 but bind to 9091), you can do it as
|
||||
## follows. below too. You'll need to do ipchains or other port
|
||||
## forwarding yourself to make this work.
|
||||
#DirPort 80 NoListen
|
||||
#DirPort 127.0.0.1:9091 NoAdvertise
|
||||
## Uncomment to return an arbitrary blob of html on your DirPort. Now you
|
||||
## can explain what Tor is if anybody wonders why your IP address is
|
||||
## contacting them. See contrib/tor-exit-notice.html in Tor's source
|
||||
## distribution for a sample.
|
||||
#DirPortFrontPage /etc/tor/tor-exit-notice.html
|
||||
|
||||
## Uncomment this if you run more than one Tor relay, and add the identity
|
||||
## key fingerprint of each Tor relay you control, even if they're on
|
||||
## different networks. You declare it here so Tor clients can avoid
|
||||
## using more than one of your relays in a single circuit. See
|
||||
## https://www.torproject.org/docs/faq#MultipleRelays
|
||||
## However, you should never include a bridge's fingerprint here, as it would
|
||||
## break its concealability and potentionally reveal its IP/TCP address.
|
||||
#MyFamily $keyid,$keyid,...
|
||||
|
||||
## A comma-separated list of exit policies. They're considered first
|
||||
## to last, and the first match wins. If you want to _replace_
|
||||
## the default exit policy, end this with either a reject *:* or an
|
||||
## accept *:*. Otherwise, you're _augmenting_ (prepending to) the
|
||||
## default exit policy. Leave commented to just use the default, which is
|
||||
## described in the man page or at
|
||||
## https://www.torproject.org/documentation.html
|
||||
##
|
||||
## Look at https://www.torproject.org/faq-abuse.html#TypicalAbuses
|
||||
## for issues you might encounter if you use the default exit policy.
|
||||
##
|
||||
## If certain IPs and ports are blocked externally, e.g. by your firewall,
|
||||
## you should update your exit policy to reflect this -- otherwise Tor
|
||||
## users will be told that those destinations are down.
|
||||
##
|
||||
## For security, by default Tor rejects connections to private (local)
|
||||
## networks, including to your public IP address. See the man page entry
|
||||
## for ExitPolicyRejectPrivate if you want to allow "exit enclaving".
|
||||
##
|
||||
#ExitPolicy accept *:6660-6667,reject *:* # allow irc ports but no more
|
||||
#ExitPolicy accept *:119 # accept nntp as well as default exit policy
|
||||
#ExitPolicy reject *:* # no exits allowed
|
||||
|
||||
## Bridge relays (or "bridges") are Tor relays that aren't listed in the
|
||||
## main directory. Since there is no complete public list of them, even an
|
||||
## ISP that filters connections to all the known Tor relays probably
|
||||
## won't be able to block all the bridges. Also, websites won't treat you
|
||||
## differently because they won't know you're running Tor. If you can
|
||||
## be a real relay, please do; but if not, be a bridge!
|
||||
#BridgeRelay 1
|
||||
## By default, Tor will advertise your bridge to users through various
|
||||
## mechanisms like https://bridges.torproject.org/. If you want to run
|
||||
## a private bridge, for example because you'll give out your bridge
|
||||
## address manually to your friends, uncomment this line:
|
||||
#PublishServerDescriptor 0
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
# This is the configuration for libtorsocks (transparent socks) for use
|
||||
# with tor, which is providing a socks server on port 9050 by default.
|
||||
#
|
||||
# Lines beginning with # and blank lines are ignored
|
||||
# Much more documentation than provided in these comments can be found in
|
||||
#
|
||||
# torsocks.conf(5), torsocks(1) and torsocks(8) manpages.
|
||||
|
||||
# Default Tor address and port. By default, Tor will listen on localhost for
|
||||
# any SOCKS connection and relay the traffic on the Tor network.
|
||||
TorAddress 127.0.0.1
|
||||
TorPort 9050
|
||||
|
||||
# Tor hidden sites do not have real IP addresses. This specifies what range of
|
||||
# IP addresses will be handed to the application as "cookies" for .onion names.
|
||||
# Of course, you should pick a block of addresses which you aren't going to
|
||||
# ever need to actually connect to. This is similar to the MapAddress feature
|
||||
# of the main tor daemon.
|
||||
OnionAddrRange 127.42.42.0/24
|
||||
|
||||
# SOCKS5 Username and Password. This is used to isolate the torsocks connection
|
||||
# circuit from other streams in Tor. Use with option IsolateSOCKSAuth (on by
|
||||
# default) in tor(1). TORSOCKS_USERNAME and TORSOCKS_PASSWORD environment
|
||||
# variable overrides these options.
|
||||
#SOCKS5Username <username>
|
||||
#SOCKS5Password <password>
|
||||
|
||||
# Set Torsocks to accept inbound connections. If set to 1, listen() and
|
||||
# accept() will be allowed to be used with non localhost address. (Default: 0)
|
||||
#AllowInbound 1
|
||||
|
||||
# Set Torsocks to allow outbound connections to the loopback interface.
|
||||
# If set to 1, connect() will be allowed to be used to the loopback interface
|
||||
# bypassing Tor. If set to 2, in addition to TCP connect(), UDP operations to
|
||||
# the loopback interface will also be allowed, bypassing Tor. This option
|
||||
# should not be used by most users. (Default: 0)
|
||||
#AllowOutboundLocalhost 1
|
||||
|
||||
# Set Torsocks to use an automatically generated SOCKS5 username/password based
|
||||
# on the process ID and current time, that makes the connections to Tor use a
|
||||
# different circuit from other existing streams in Tor on a per-process basis.
|
||||
# If set, the SOCKS5Username and SOCKS5Password options must not be set.
|
||||
# (Default: 0)
|
||||
#IsolatePID 1
|
||||
Reference in New Issue
Block a user