committing changes in /etc made by "apt install torbrowser-launcher"

Packages with configuration changes:
+tor 0.4.5.10-1~deb11u1 amd64
+torbrowser-launcher 0.3.5-2 amd64
+torsocks 2.3.0-3 amd64

Package changes:
+libdouble-conversion3 3.1.5-6.1 amd64
+libmd4c0 0.4.7-2 amd64
+libpcre2-16-0 10.36-2 amd64
+libqt5core5a 5.15.2+dfsg-9 amd64
+libqt5dbus5 5.15.2+dfsg-9 amd64
+libqt5designer5 5.15.2-5 amd64
+libqt5gui5 5.15.2+dfsg-9 amd64
+libqt5help5 5.15.2-5 amd64
+libqt5network5 5.15.2+dfsg-9 amd64
+libqt5printsupport5 5.15.2+dfsg-9 amd64
+libqt5sql5 5.15.2+dfsg-9 amd64
+libqt5sql5-sqlite 5.15.2+dfsg-9 amd64
+libqt5svg5 5.15.2-3 amd64
+libqt5test5 5.15.2+dfsg-9 amd64
+libqt5widgets5 5.15.2+dfsg-9 amd64
+libqt5xml5 5.15.2+dfsg-9 amd64
+libxcb-icccm4 0.4.1-1.1 amd64
+libxcb-image0 0.4.0-1+b3 amd64
+libxcb-keysyms1 0.4.0-1+b2 amd64
+libxcb-render-util0 0.3.9-1+b1 amd64
+libxcb-xinerama0 1.14-3 amd64
+libxcb-xinput0 1.14-3 amd64
+libxcb-xkb1 1.14-3 amd64
+libxkbcommon-x11-0 1.0.3-2 amd64
+python3-packaging 20.9-2 all
+python3-pyparsing 2.4.7-1 all
+python3-pyqt5 5.15.2+dfsg-3 amd64
+python3-pyqt5.sip 12.8.1-1+b2 amd64
+python3-socks 1.7.1+dfsg-1 all
+qt5-gtk-platformtheme 5.15.2+dfsg-9 amd64
+qttranslations5-l10n 5.15.2-2 all
+tor 0.4.5.10-1~deb11u1 amd64
+tor-geoipdb 0.4.5.10-1~deb11u1 all
+torbrowser-launcher 0.3.5-2 amd64
+torsocks 2.3.0-3 amd64
This commit is contained in:
root
2022-05-16 14:38:36 +02:00
parent 6f266b32e6
commit 8d303d2bbe
37 changed files with 951 additions and 1 deletions
+21
View File
@@ -443,6 +443,7 @@ maybe chmod 0644 'apparmor.d/abstractions/smbpass'
maybe chmod 0644 'apparmor.d/abstractions/ssl_certs'
maybe chmod 0644 'apparmor.d/abstractions/ssl_keys'
maybe chmod 0644 'apparmor.d/abstractions/svn-repositories'
maybe chmod 0644 'apparmor.d/abstractions/tor'
maybe chmod 0644 'apparmor.d/abstractions/ubuntu-bittorrent-clients'
maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers'
maybe chmod 0755 'apparmor.d/abstractions/ubuntu-browsers.d'
@@ -489,6 +490,9 @@ maybe chmod 0755 'apparmor.d/local'
maybe chmod 0644 'apparmor.d/local/README'
maybe chmod 0644 'apparmor.d/local/lsb_release'
maybe chmod 0644 'apparmor.d/local/nvidia_modprobe'
maybe chmod 0644 'apparmor.d/local/system_tor'
maybe chmod 0644 'apparmor.d/local/torbrowser.Browser.firefox'
maybe chmod 0644 'apparmor.d/local/torbrowser.Tor.tor'
maybe chmod 0644 'apparmor.d/local/usr.bin.man'
maybe chmod 0644 'apparmor.d/local/usr.bin.thunderbird'
maybe chmod 0644 'apparmor.d/local/usr.lib.libreoffice.program.oosplash'
@@ -500,6 +504,9 @@ maybe chmod 0644 'apparmor.d/local/usr.sbin.cupsd'
maybe chmod 0644 'apparmor.d/local/usr.sbin.ntpd'
maybe chmod 0644 'apparmor.d/lsb_release'
maybe chmod 0644 'apparmor.d/nvidia_modprobe'
maybe chmod 0644 'apparmor.d/system_tor'
maybe chmod 0644 'apparmor.d/torbrowser.Browser.firefox'
maybe chmod 0644 'apparmor.d/torbrowser.Tor.tor'
maybe chmod 0755 'apparmor.d/tunables'
maybe chmod 0644 'apparmor.d/tunables/alias'
maybe chmod 0644 'apparmor.d/tunables/apparmorfs'
@@ -519,6 +526,7 @@ maybe chmod 0644 'apparmor.d/tunables/run'
maybe chmod 0644 'apparmor.d/tunables/securityfs'
maybe chmod 0644 'apparmor.d/tunables/share'
maybe chmod 0644 'apparmor.d/tunables/sys'
maybe chmod 0644 'apparmor.d/tunables/torbrowser'
maybe chmod 0644 'apparmor.d/tunables/xdg-user-dirs'
maybe chmod 0755 'apparmor.d/tunables/xdg-user-dirs.d'
maybe chmod 0644 'apparmor.d/tunables/xdg-user-dirs.d/site.local'
@@ -664,6 +672,7 @@ maybe chmod 0755 'cron.weekly'
maybe chmod 0644 'cron.weekly/.placeholder'
maybe chmod 0755 'cron.weekly/0anacron'
maybe chmod 0755 'cron.weekly/man-db'
maybe chmod 0755 'cron.weekly/tor'
maybe chmod 0644 'crontab'
maybe chmod 0755 'cruft'
maybe chmod 0755 'cruft/filters-unex'
@@ -731,6 +740,7 @@ maybe chmod 0644 'default/rpcbind'
maybe chmod 0644 'default/rsync'
maybe chmod 0644 'default/saned'
maybe chmod 0644 'default/ssh'
maybe chmod 0644 'default/tor'
maybe chmod 0644 'default/useradd'
maybe chmod 0644 'default/xinetd'
maybe chmod 0644 'deluser.conf'
@@ -954,6 +964,7 @@ maybe chmod 0755 'init.d/speech-dispatcher'
maybe chmod 0755 'init.d/ssh'
maybe chmod 0755 'init.d/sudo'
maybe chmod 0755 'init.d/systune'
maybe chmod 0755 'init.d/tor'
maybe chmod 0755 'init.d/udev'
maybe chmod 0755 'init.d/unattended-upgrades'
maybe chmod 0755 'init.d/uuidd'
@@ -1082,6 +1093,7 @@ maybe chmod 0644 'logrotate.d/ppp'
maybe chmod 0644 'logrotate.d/rsyslog'
maybe chmod 0644 'logrotate.d/sane-utils'
maybe chmod 0644 'logrotate.d/speech-dispatcher'
maybe chmod 0644 'logrotate.d/tor'
maybe chmod 0644 'logrotate.d/unattended-upgrades'
maybe chmod 0644 'logrotate.d/wtmp'
maybe chmod 0755 'lvm'
@@ -1538,6 +1550,12 @@ maybe chmod 0755 'sv/ssh/finish'
maybe chmod 0755 'sv/ssh/log'
maybe chmod 0755 'sv/ssh/log/run'
maybe chmod 0755 'sv/ssh/run'
maybe chmod 0755 'sv/tor'
maybe chmod 0755 'sv/tor/.meta'
maybe chmod 0644 'sv/tor/.meta/installed'
maybe chmod 0755 'sv/tor/log'
maybe chmod 0755 'sv/tor/log/run'
maybe chmod 0755 'sv/tor/run'
maybe chmod 0755 'synth-shell'
maybe chmod 0755 'synth-shell/examples'
maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.blue.config'
@@ -1595,6 +1613,9 @@ maybe chmod 0644 'timidity/fluidr3_gs.cfg'
maybe chmod 0644 'timidity/timgm6mb.cfg'
maybe chmod 0755 'tmpfiles.d'
maybe chmod 0644 'tmpfiles.d/screen-cleanup.conf'
maybe chmod 0755 'tor'
maybe chmod 0644 'tor/torrc'
maybe chmod 0644 'tor/torsocks.conf'
maybe chmod 0644 'ucf.conf'
maybe chmod 0755 'udev'
maybe chmod 0755 'udev/hwdb.d'
+31
View File
@@ -0,0 +1,31 @@
# vim:syntax=apparmor
#include <abstractions/base>
#include <abstractions/nameservice>
#include <abstractions/openssl>
network tcp,
network udp,
capability chown,
capability dac_read_search,
capability fowner,
capability fsetid,
capability setgid,
capability setuid,
/usr/bin/tor r,
/usr/sbin/tor r,
# Needed by obfs4proxy
/proc/sys/net/core/somaxconn r,
/proc/sys/kernel/random/uuid r,
/sys/devices/system/cpu/ r,
/sys/devices/system/cpu/** r,
/etc/tor/* r,
/usr/share/tor/** r,
/usr/bin/obfsproxy PUx,
/usr/bin/obfs4proxy Pix,
View File
View File
+25
View File
@@ -0,0 +1,25 @@
# vim:syntax=apparmor
#include <tunables/global>
profile system_tor flags=(attach_disconnected) {
#include <abstractions/tor>
owner /var/lib/tor/** rwk,
owner /var/lib/tor/ r,
owner /var/log/tor/* w,
# During startup, tor (as root) tries to open various things such as
# directories via check_private_dir(). Let it.
/var/lib/tor/** r,
/{,var/}run/tor/ r,
/{,var/}run/tor/control w,
/{,var/}run/tor/socks w,
/{,var/}run/tor/tor.pid w,
/{,var/}run/tor/control.authcookie w,
/{,var/}run/tor/control.authcookie.tmp rw,
/{,var/}run/systemd/notify w,
# Site-specific additions and overrides. See local/README for details.
#include <local/system_tor>
}
+173
View File
@@ -0,0 +1,173 @@
#include <tunables/global>
#include <tunables/torbrowser>
@{torbrowser_firefox_executable} = /home/*/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*/Browser/firefox.real
profile torbrowser_firefox @{torbrowser_firefox_executable} {
#include <abstractions/audio>
#include <abstractions/dri-enumerate>
#include <abstractions/gnome>
#include <abstractions/ibus>
#include <abstractions/mesa>
#include <abstractions/opencl>
#include if exists <abstractions/vulkan>
#include if exists <abstractions/dbus-session>
#include if exists <abstractions/X>
# Uncomment the following lines if you want to give the Tor Browser read-write
# access to most of your personal files.
# #include <abstractions/user-download>
# @{HOME}/ r,
# Audio support
/{,usr/}bin/pulseaudio Pixr,
#dbus,
network netlink raw,
network tcp,
ptrace (trace) peer=@{profile_name},
signal (receive, send) set=("term") peer=@{profile_name},
deny /etc/host.conf r,
deny /etc/hosts r,
deny /etc/nsswitch.conf r,
deny /etc/os-release r,
deny /etc/resolv.conf r,
deny /etc/passwd r,
deny /etc/group r,
deny /etc/mailcap r,
/etc/machine-id r,
/var/lib/dbus/machine-id r,
/dev/ r,
/dev/shm/ r,
owner @{PROC}/@{pid}/cgroup r,
owner @{PROC}/@{pid}/environ r,
owner @{PROC}/@{pid}/fd/ r,
owner @{PROC}/@{pid}/mountinfo r,
owner @{PROC}/@{pid}/stat r,
owner @{PROC}/@{pid}/status r,
owner @{PROC}/@{pid}/task/*/stat r,
@{PROC}/sys/kernel/random/uuid r,
owner @{torbrowser_installation_dir}/ r,
owner @{torbrowser_installation_dir}/* r,
owner @{torbrowser_installation_dir}/.** rwk,
owner @{torbrowser_installation_dir}/update.test/ rwk,
owner @{torbrowser_home_dir}/.** rwk,
owner @{torbrowser_home_dir}/ rw,
owner @{torbrowser_home_dir}/** rwk,
owner @{torbrowser_home_dir}.bak/ rwk,
owner @{torbrowser_home_dir}.bak/** rwk,
owner @{torbrowser_home_dir}/*.so mr,
owner @{torbrowser_home_dir}/.cache/fontconfig/ rwk,
owner @{torbrowser_home_dir}/.cache/fontconfig/** rwkl,
owner @{torbrowser_home_dir}/browser/** r,
owner @{torbrowser_home_dir}/{,browser/}components/*.so mr,
owner @{torbrowser_home_dir}/Downloads/ rwk,
owner @{torbrowser_home_dir}/Downloads/** rwk,
owner @{torbrowser_home_dir}/firefox rix,
owner @{torbrowser_home_dir}/{,TorBrowser/UpdateInfo/}updates/[0-9]*/* rw,
owner @{torbrowser_home_dir}/{,TorBrowser/UpdateInfo/}updates/[0-9]*/{,MozUpdater/bgupdate/}updater ix,
owner @{torbrowser_home_dir}/updater ix,
owner @{torbrowser_home_dir}/TorBrowser/Data/Browser/.parentwritetest rw,
owner @{torbrowser_home_dir}/TorBrowser/Data/Browser/profiles.ini r,
owner @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/{,**} rwk,
owner @{torbrowser_home_dir}/TorBrowser/Data/fontconfig/fonts.conf r,
owner @{torbrowser_home_dir}/fonts/* l,
owner @{torbrowser_home_dir}/TorBrowser/Tor/tor px,
owner @{torbrowser_home_dir}/TorBrowser/Tor/ r,
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so mr,
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so.* mr,
owner @{torbrowser_home_dir}/TorBrowser/Tor/libstdc++/*.so mr,
owner @{torbrowser_home_dir}/TorBrowser/Tor/libstdc++/*.so.* mr,
# parent Firefox process when restarting after upgrade, Web Content processes
owner @{torbrowser_firefox_executable} pxmr -> torbrowser_firefox,
/etc/mailcap r,
/etc/mime.types r,
/usr/share/ r,
/usr/share/glib-2.0/schemas/gschemas.compiled r,
/usr/share/mime/ r,
/usr/share/themes/ r,
/usr/share/applications/** rk,
/usr/share/gnome/applications/ r,
/usr/share/gnome/applications/kde4/ r,
/usr/share/poppler/cMap/ r,
/etc/xdg/mimeapps.list r,
# Distribution homepage
/usr/share/homepage/ r,
/usr/share/homepage/** r,
/sys/bus/pci/devices/ r,
@{sys}/devices/pci[0-9]*/**/irq r,
/sys/devices/system/cpu/ r,
/sys/devices/system/cpu/present r,
/sys/devices/system/node/ r,
/sys/devices/system/node/node[0-9]*/meminfo r,
/sys/fs/cgroup/cpu,cpuacct/{,user.slice/}cpu.cfs_quota_us r,
deny /sys/devices/virtual/block/*/uevent r,
# Should use abstractions/gstreamer instead once merged upstream
/etc/udev/udev.conf r,
/run/udev/data/+pci:* r,
/sys/devices/pci[0-9]*/**/uevent r,
owner /{dev,run}/shm/shmfd-* rw,
# Required for multiprocess Firefox (aka Electrolysis, i.e. e10s)
owner /{dev,run}/shm/org.chromium.* rw,
owner /dev/shm/org.mozilla.ipc.[0-9]*.[0-9]* rw, # for Chromium IPC
# Required for Wayland display protocol support
owner /dev/shm/wayland.mozilla.ipc.[0-9]* rw,
# Silence denial logs about permissions we don't need
deny @{HOME}/.cache/fontconfig/ rw,
deny @{HOME}/.cache/fontconfig/** rw,
deny @{HOME}/.config/gtk-2.0/ rw,
deny @{HOME}/.config/gtk-2.0/** rw,
deny @{PROC}/@{pid}/net/route r,
deny /sys/devices/system/cpu/cpufreq/policy[0-9]*/cpuinfo_max_freq r,
deny /sys/devices/system/cpu/*/cache/index[0-9]*/size r,
deny /run/user/[0-9]*/dconf/user rw,
deny /usr/bin/lsb_release x,
# Silence denial logs about PulseAudio
deny /etc/pulse/client.conf r,
deny /usr/bin/pulseaudio x,
# KDE 4
owner @{HOME}/.kde/share/config/* r,
# Xfce4
/etc/xfce4/defaults.list r,
/usr/share/xfce4/applications/ r,
# u2f (tested with Yubikey 4)
/sys/class/ r,
/sys/bus/ r,
/sys/class/hidraw/ r,
/run/udev/data/c24{5,7,9}:* r,
/dev/hidraw* rw,
# Yubikey NEO also needs this:
/sys/devices/**/hidraw/hidraw*/uevent r,
# Needed for Firefox sandboxing via unprivileged user namespaces
capability sys_admin,
capability sys_chroot,
owner @{PROC}/@{pid}/{gid,uid}_map w,
owner @{PROC}/@{pid}/setgroups w,
# Remove these rules once we can assume abstractions/vulkan is recent enough
# to include them
/etc/glvnd/egl_vendor.d/{*,.json} r,
/usr/share/glvnd/egl_vendor.d/{,*.json} r,
#include <local/torbrowser.Browser.firefox>
}
+47
View File
@@ -0,0 +1,47 @@
#include <tunables/global>
#include <tunables/torbrowser>
@{torbrowser_tor_executable} = /home/*/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*/Browser/TorBrowser/Tor/tor
profile torbrowser_tor @{torbrowser_tor_executable} {
#include <abstractions/base>
network netlink raw,
network tcp,
network udp,
/etc/host.conf r,
/etc/nsswitch.conf r,
/etc/passwd r,
/etc/resolv.conf r,
owner @{torbrowser_home_dir}/TorBrowser/Tor/tor mr,
owner @{torbrowser_home_dir}/TorBrowser/Data/Tor/ rw,
owner @{torbrowser_home_dir}/TorBrowser/Data/Tor/** rw,
owner @{torbrowser_home_dir}/TorBrowser/Data/Tor/lock rwk,
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so mr,
owner @{torbrowser_home_dir}/TorBrowser/Tor/*.so.* mr,
# Support some of the included pluggable transports
owner @{torbrowser_home_dir}/TorBrowser/Tor/PluggableTransports/** rix,
@{PROC}/sys/net/core/somaxconn r,
#include <abstractions/ssl_certs>
# Silence file_inherit logs
deny @{torbrowser_home_dir}/{browser/,}omni.ja r,
deny @{torbrowser_home_dir}/{browser/,}features/*.xpi r,
deny @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/.parentlock rw,
deny @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/extensions/*.xpi r,
deny @{torbrowser_home_dir}/TorBrowser/Data/Browser/profile.default/startupCache/* r,
# Silence logs from included pluggable transports
deny /etc/hosts r,
deny /etc/services r,
@{PROC}/sys/kernel/random/uuid r,
/sys/devices/system/cpu/ r,
/sys/kernel/mm/transparent_hugepage/hpage_pmd_size r,
# OnionShare compatibility
/tmp/onionshare/** rw,
#include <local/torbrowser.Tor.tor>
}
+2
View File
@@ -0,0 +1,2 @@
@{torbrowser_installation_dir}=@{HOME}/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*
@{torbrowser_home_dir}=@{torbrowser_installation_dir}/Browser
+16
View File
@@ -0,0 +1,16 @@
#!/bin/sh
set -e
set -u
DEFAULTSFILE=/etc/default/tor
if [ -f $DEFAULTSFILE ] ; then
. $DEFAULTSFILE
fi
if [ "${CLEANUP_OLD_COREFILES:-}" = "y" ] ; then
if [ -d /var/lib/tor ] ; then
find /var/lib/tor -mindepth 1 -maxdepth 1 -type f -mtime +21 -user debian-tor -regex '.*/core\(\.[0-9]+\)?' -exec rm '{}' +
fi
fi
+75
View File
@@ -0,0 +1,75 @@
# Defaults for tor initscript
# sourced by /etc/init.d/tor
# installed at /etc/default/tor by the maintainer scripts
#
# Note that this file is not being used for controlling Tor-startup
# when Tor is launched by systemd.
#
#
# This is a bash shell fragment
#
RUN_DAEMON="yes"
#
# Servers sometimes may need more than the default 1024 file descriptors
# if they are very busy and have many clients connected to them. The top
# servers as of early 2008 regularly have more than 10000 connected
# clients.
# (ulimit -n)
#
# (the default varies as it depends on the number of available system-wide file
# descriptors. See the init script in /etc/init.d/tor for details.)
#
# MAX_FILEDESCRIPTORS=
#
# If tor is seriously hogging your CPU, taking away too much cycles from
# other system resources, then you can renice tor. See nice(1) for a
# bit more information. Another way to limit the CPU usage of an Onion
# Router is to set a lower BandwidthRate, as CPU usage is mostly a function
# of the amount of traffic flowing through your node. Consult the torrc(5)
# manual page for more information on setting BandwidthRate.
#
# NICE="--nicelevel 5"
# Additional arguments to pass on tor's command line.
#
# ARGS="$ARGS "
#
# Uncomment the ulimit call below, and set "DisableDebuggerAttachment 0"
# in /etc/tor/torrc, if you want tor to produce coredumps on segfaults
# and assert errors.
#
# Keeping coredumps around is some sort of security issue since they
# may leak session keys, sensitive client data and more, should such
# files fall into the wrong hands. Therefore coredumps are not enabled
# by default.
#
# ulimit -c unlimited
#
# Config option for the weekly cron file: Whether or not to remove old
# coredumps in /var/lib/tor. Coredumps can hold sensitive data, as such
# they probably should not be kept lying around if nobody will ever look
# at them. This option makes /etc/cron.weekly/tor clean out files older
# then three weeks.
#
CLEANUP_OLD_COREFILES=y
#
# By default the tor init script will launch Tor using apparmor iff
# /usr/sbin/aa-status exists and is executable and calling it with --enabled
# returns true, /usr/sbin/aa-exec is executable, there is a
# /etc/apparmor.d/system_tor policy, and USE_AA_EXEC is set to 'yes'.
#
# USE_AA_EXEC="yes" # default
# USE_AA_EXEC="no"
# Let the vidalia package override some of our settings.
# People who have vidalia installed might not want to run Tor as a system
# service. The vidalia .deb can ask them that and then set run-daemon to no.
if [ -e /etc/default/tor.vidalia ] && [ -x /usr/bin/vidalia ]; then
. /etc/default/tor.vidalia
fi
+1
View File
@@ -73,3 +73,4 @@ wheel:x:1003:pi
_flatpak:x:129:
tss:x:130:
docker:x:998:
debian-tor:x:131:
+1
View File
@@ -72,3 +72,4 @@ pi:x:1002:
wheel:x:1003:pi
_flatpak:x:129:
tss:x:130:
docker:x:998:
+1
View File
@@ -73,3 +73,4 @@ wheel:!::pi
_flatpak:!::
tss:!::
docker:!::
debian-tor:!::
+1
View File
@@ -72,3 +72,4 @@ pi:!::
wheel:!::pi
_flatpak:!::
tss:!::
docker:!::
Executable
+253
View File
@@ -0,0 +1,253 @@
#! /bin/bash
### BEGIN INIT INFO
# Provides: tor
# Required-Start: $local_fs $remote_fs $network $named $time
# Required-Stop: $local_fs $remote_fs $network $named $time
# Should-Start: $syslog
# Should-Stop: $syslog
# Default-Start: 2 3 4 5
# Default-Stop: 0 1 6
# Short-Description: Starts The Onion Router daemon processes
# Description: Start The Onion Router, a TCP overlay
# network client that provides anonymous
# transport.
### END INIT INFO
# Load the VERBOSE setting and other rcS variables
. /lib/init/vars.sh
# Define LSB log_* functions.
. /lib/lsb/init-functions
PATH=/sbin:/bin:/usr/sbin:/usr/bin
DAEMON=/usr/bin/tor
NAME=tor
DESC="tor daemon"
TORLOGDIR=/var/log/tor
TORPIDDIR=/run/tor
TORPID=$TORPIDDIR/tor.pid
DEFAULTSFILE=/etc/default/$NAME
WAITFORDAEMON=60
DEFAULT_ARGS="--defaults-torrc /usr/share/tor/tor-service-defaults-torrc"
VERIFY_ARGS="--verify-config $DEFAULT_ARGS"
USE_AA_EXEC="yes"
ARGS=""
if [ "${VERBOSE:-}" != "yes" ]; then
ARGS="$ARGS --hush"
fi
# Let's try to figure our some sane defaults:
if [ -r /proc/sys/fs/file-max ]; then
system_max=`cat /proc/sys/fs/file-max`
if [ "$system_max" -gt "80000" ] ; then
MAX_FILEDESCRIPTORS=32768
elif [ "$system_max" -gt "40000" ] ; then
MAX_FILEDESCRIPTORS=16384
elif [ "$system_max" -gt "10000" ] ; then
MAX_FILEDESCRIPTORS=8192
else
MAX_FILEDESCRIPTORS=1024
cat << EOF
Warning: Your system has very few filedescriptors available in total.
Maybe you should try raising that by adding 'fs.file-max=100000' to your
/etc/sysctl.conf file. Feel free to pick any number that you deem appropriate.
Then run 'sysctl -p'. See /proc/sys/fs/file-max for the current value, and
file-nr in the same directory for how many of those are used at the moment.
EOF
fi
else
MAX_FILEDESCRIPTORS=8192
fi
NICE=""
test -x $DAEMON || exit 0
# Include tor defaults if available
if [ -f $DEFAULTSFILE ] ; then
. $DEFAULTSFILE
fi
wait_for_deaddaemon () {
pid=$1
sleep 1
if test -n "$pid"
then
if kill -0 $pid 2>/dev/null
then
cnt=0
while kill -0 $pid 2>/dev/null
do
cnt=`expr $cnt + 1`
if [ $cnt -gt $WAITFORDAEMON ]
then
log_action_end_msg 1 "still running"
exit 1
fi
sleep 1
[ "`expr $cnt % 3`" != 2 ] || log_action_cont_msg ""
done
fi
fi
log_action_end_msg 0
}
check_torpiddir () {
if test ! -d $TORPIDDIR; then
mkdir -m 02755 "$TORPIDDIR"
chown debian-tor:debian-tor "$TORPIDDIR"
! [ -x /sbin/restorecon ] || /sbin/restorecon "$TORPIDDIR"
fi
if test ! -x $TORPIDDIR; then
log_action_end_msg 1 "cannot access $TORPIDDIR directory, are you root?"
exit 1
fi
}
check_torlogdir () {
if test ! -d $TORLOGDIR; then
mkdir -m 02750 "$TORLOGDIR"
chown debian-tor:adm "$TORLOGDIR"
! [ -x /sbin/restorecon ] || /sbin/restorecon "$TORPIDDIR"
fi
}
check_config () {
if ! $DAEMON $VERIFY_ARGS > /dev/null; then
log_failure_msg "Checking if $NAME configuration is valid"
$DAEMON $VERIFY_ARGS >&2
exit 1
fi
}
case "$1" in
start)
if [ "$RUN_DAEMON" != "yes" ]; then
log_action_msg "Not starting $DESC (Disabled in $DEFAULTSFILE)."
exit 0
fi
if [ -n "$MAX_FILEDESCRIPTORS" ]; then
[ "${VERBOSE:-}" != "yes" ] || log_action_begin_msg "Raising maximum number of filedescriptors (ulimit -n) for tor to $MAX_FILEDESCRIPTORS"
if ulimit -n "$MAX_FILEDESCRIPTORS" ; then
[ "${VERBOSE:-}" != "yes" ] || log_action_end_msg 0
else
[ "${VERBOSE:-}" != "yes" ] || log_action_end_msg 1
fi
fi
check_torpiddir
check_torlogdir
check_config
log_action_begin_msg "Starting $DESC"
if start-stop-daemon --stop --signal 0 --quiet --pidfile $TORPID --exec $DAEMON; then
log_action_end_msg 0 "already running"
else
if [ "$USE_AA_EXEC" = "yes" ] &&
command -v aa-status > /dev/null &&
command -v aa-exec > /dev/null &&
[ -e /etc/apparmor.d/system_tor ] && \
aa-status --enabled ; then
AA_EXEC_PATH=$(command -v aa-exec)
AA_EXEC="--startas $AA_EXEC_PATH"
AA_EXEC_ARGS="--profile=system_tor -- $DAEMON"
else
AA_EXEC=""
AA_EXEC_ARGS=""
fi
if start-stop-daemon --start --quiet \
--pidfile $TORPID \
$NICE \
$AA_EXEC \
--exec $DAEMON -- $AA_EXEC_ARGS $DEFAULT_ARGS $ARGS
then
log_action_end_msg 0
else
log_action_end_msg 1
exit 1
fi
fi
;;
stop)
log_action_begin_msg "Stopping $DESC"
pid=`cat $TORPID 2>/dev/null` || true
if test ! -f $TORPID -o -z "$pid"; then
log_action_end_msg 0 "not running - there is no $TORPID"
exit 0
fi
if start-stop-daemon --stop --signal INT --quiet --pidfile $TORPID --exec $DAEMON; then
wait_for_deaddaemon $pid
elif kill -0 $pid 2>/dev/null; then
log_action_end_msg 1 "Is $pid not $NAME? Is $DAEMON a different binary now?"
exit 1
else
log_action_end_msg 1 "$DAEMON died: process $pid not running; or permission denied"
exit 1
fi
;;
reload|force-reload)
check_config
log_action_begin_msg "Reloading $DESC configuration"
pid=`cat $TORPID 2>/dev/null` || true
if test ! -f $TORPID -o -z "$pid"; then
log_action_end_msg 1 "not running - there is no $TORPID"
exit 1
fi
if start-stop-daemon --stop --signal 1 --quiet --pidfile $TORPID --exec $DAEMON
then
log_action_end_msg 0
elif kill -0 $pid 2>/dev/null; then
log_action_end_msg 1 "Is $pid not $NAME? Is $DAEMON a different binary now?"
exit 1
else
log_action_end_msg 1 "$DAEMON died: process $pid not running; or permission denied"
exit 1
fi
;;
restart)
check_config
$0 stop
sleep 1
$0 start
;;
status)
if test ! -r $(dirname $TORPID); then
log_failure_msg "cannot read PID file $TORPID"
exit 4
fi
pid=`cat $TORPID 2>/dev/null` || true
if test ! -f $TORPID -o -z "$pid"; then
log_failure_msg "$NAME is not running"
exit 3
fi
if start-stop-daemon --pid "$pid" -T ; then
log_success_msg "$NAME is running"
exit 0
else
log_failure_msg "$NAME is not running"
exit 1
fi
;;
*)
log_action_msg "Usage: $0 {start|stop|restart|reload|force-reload|status}" >&2
exit 1
;;
esac
exit 0
+15
View File
@@ -0,0 +1,15 @@
/var/log/tor/*log {
daily
rotate 5
compress
delaycompress
missingok
notifempty
create 0640 debian-tor adm
sharedscripts
postrotate
if invoke-rc.d tor status > /dev/null; then
invoke-rc.d tor reload > /dev/null
fi
endscript
}
+1
View File
@@ -43,3 +43,4 @@ uuidd:x:120:128::/run/uuidd:/usr/sbin/nologin
pi:x:1001:1002::/home/pi:/bin/bash
_flatpak:x:121:129:Flatpak system-wide installation helper,,,:/nonexistent:/usr/sbin/nologin
tss:x:122:130:TPM software stack,,,:/var/lib/tpm:/bin/false
debian-tor:x:123:131::/var/lib/tor:/bin/false
+2 -1
View File
@@ -42,4 +42,5 @@ statd:x:119:65534::/var/lib/nfs:/usr/sbin/nologin
uuidd:x:120:128::/run/uuidd:/usr/sbin/nologin
pi:x:1001:1002::/home/pi:/bin/bash
_flatpak:x:121:129:Flatpak system-wide installation helper,,,:/nonexistent:/usr/sbin/nologin
tss:x:122:130::/var/lib/tpm:/bin/false
tss:x:122:130:TPM software stack,,,:/var/lib/tpm:/bin/false
debian-tor:x:123:131::/var/lib/tor:/bin/false
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
../init.d/tor
+1
View File
@@ -0,0 +1 @@
/etc/sv/tor
+1
View File
@@ -43,3 +43,4 @@ uuidd:*:19115:0:99999:7:::
pi:$y$j9T$OvZKYo/X0taV3uBG47Fxu0$CAvPg3ND5EmSJDmuurGqt1HxmNJ7y392RjYB5934Qs1:19116:0:99999:7:::
_flatpak:*:19118:0:99999:7:::
tss:*:19118:0:99999:7:::
debian-tor:*:19128:0:99999:7:::
+1
View File
@@ -43,3 +43,4 @@ uuidd:*:19115:0:99999:7:::
pi:$y$j9T$OvZKYo/X0taV3uBG47Fxu0$CAvPg3ND5EmSJDmuurGqt1HxmNJ7y392RjYB5934Qs1:19116:0:99999:7:::
_flatpak:*:19118:0:99999:7:::
tss:*:19118:0:99999:7:::
debian-tor:*:19128:0:99999:7:::
View File
Executable
+4
View File
@@ -0,0 +1,4 @@
#!/bin/sh
chown _runit-log:adm '/var/log/runit/tor'
chmod 750 '/var/log/runit/tor'
exec chpst -u _runit-log svlogd -tt '/var/log/runit/tor'
+1
View File
@@ -0,0 +1 @@
/run/runit/supervise/tor.log
Executable
+33
View File
@@ -0,0 +1,33 @@
#!/usr/bin/env /lib/runit/invoke-run
readonly daemon=/usr/bin/tor
exec 2>&1
# This directory is referenced in /usr/share/tor/tor-service-defaults-torrc
# and must exist.
readonly rundir=/run/tor
if ! [ -d "${rundir}" ]; then
mkdir -m 02755 "${rundir}"
chown debian-tor:debian-tor "${rundir}"
! [ -x /sbin/restorecon ] || /sbin/restorecon "${rundir}"
fi
MAX_FILEDESCRIPTORS="${MAX_FILEDESCRIPTORS:-65536}"
ulimit -n "${MAX_FILEDESCRIPTORS}"
# default invocation
set -- "${daemon}" \
--defaults-torrc /usr/share/tor/tor-service-defaults-torrc \
-f /etc/tor/torrc \
--Log 'notice stdout' \
--RunAsDaemon 0
if ! "$@" --verify-config ; then
echo "persistent error: Tor configuration is not valid"
exec sv down tor
fi
if aa-status --enabled ; then
set -- /usr/bin/aa-exec --profile=system_tor -- "$@"
fi
exec /usr/bin/env -i "$@"
+1
View File
@@ -0,0 +1 @@
/run/runit/supervise/tor
+1
View File
@@ -0,0 +1 @@
/lib/systemd/system/tor.service
+192
View File
@@ -0,0 +1,192 @@
## Configuration file for a typical Tor user
## Last updated 9 October 2013 for Tor 0.2.5.2-alpha.
## (may or may not work for much older or much newer versions of Tor.)
##
## Lines that begin with "## " try to explain what's going on. Lines
## that begin with just "#" are disabled commands: you can enable them
## by removing the "#" symbol.
##
## See 'man tor', or https://www.torproject.org/docs/tor-manual.html,
## for more options you can use in this file.
##
## Tor will look for this file in various places based on your platform:
## https://www.torproject.org/docs/faq#torrc
## Tor opens a socks proxy on port 9050 by default -- even if you don't
## configure one below. Set "SocksPort 0" if you plan to run Tor only
## as a relay, and not make any local application connections yourself.
#SocksPort 9050 # Default: Bind to localhost:9050 for local connections.
#SocksPort 192.168.0.1:9100 # Bind to this address:port too.
## Entry policies to allow/deny SOCKS requests based on IP address.
## First entry that matches wins. If no SocksPolicy is set, we accept
## all (and only) requests that reach a SocksPort. Untrusted users who
## can access your SocksPort may be able to learn about the connections
## you make.
#SocksPolicy accept 192.168.0.0/16
#SocksPolicy reject *
## Logs go to stdout at level "notice" unless redirected by something
## else, like one of the below lines. You can have as many Log lines as
## you want.
##
## We advise using "notice" in most cases, since anything more verbose
## may provide sensitive information to an attacker who obtains the logs.
##
## Send all messages of level 'notice' or higher to /var/log/tor/notices.log
#Log notice file /var/log/tor/notices.log
## Send every possible message to /var/log/tor/debug.log
#Log debug file /var/log/tor/debug.log
## Use the system log instead of Tor's logfiles
#Log notice syslog
## To send all messages to stderr:
#Log debug stderr
## Uncomment this to start the process in the background... or use
## --runasdaemon 1 on the command line. This is ignored on Windows;
## see the FAQ entry if you want Tor to run as an NT service.
#RunAsDaemon 1
## The directory for keeping all the keys/etc. By default, we store
## things in $HOME/.tor on Unix, and in Application Data\tor on Windows.
#DataDirectory /var/lib/tor
## The port on which Tor will listen for local connections from Tor
## controller applications, as documented in control-spec.txt.
#ControlPort 9051
## If you enable the controlport, be sure to enable one of these
## authentication methods, to prevent attackers from accessing it.
#HashedControlPassword 16:872860B76453A77D60CA2BB8C1A7042072093276A3D701AD684053EC4C
#CookieAuthentication 1
############### This section is just for location-hidden services ###
## Once you have configured a hidden service, you can look at the
## contents of the file ".../hidden_service/hostname" for the address
## to tell people.
##
## HiddenServicePort x y:z says to redirect requests on port x to the
## address y:z.
#HiddenServiceDir /var/lib/tor/hidden_service/
#HiddenServicePort 80 127.0.0.1:80
#HiddenServiceDir /var/lib/tor/other_hidden_service/
#HiddenServicePort 80 127.0.0.1:80
#HiddenServicePort 22 127.0.0.1:22
################ This section is just for relays #####################
#
## See https://www.torproject.org/docs/tor-doc-relay for details.
## Required: what port to advertise for incoming Tor connections.
#ORPort 9001
## If you want to listen on a port other than the one advertised in
## ORPort (e.g. to advertise 443 but bind to 9090), you can do it as
## follows. You'll need to do ipchains or other port forwarding
## yourself to make this work.
#ORPort 443 NoListen
#ORPort 127.0.0.1:9090 NoAdvertise
## The IP address or full DNS name for incoming connections to your
## relay. Leave commented out and Tor will guess.
#Address noname.example.com
## If you have multiple network interfaces, you can specify one for
## outgoing traffic to use.
# OutboundBindAddress 10.0.0.5
## A handle for your relay, so people don't have to refer to it by key.
#Nickname ididnteditheconfig
## Define these to limit how much relayed traffic you will allow. Your
## own traffic is still unthrottled. Note that RelayBandwidthRate must
## be at least 20 KB.
## Note that units for these config options are bytes per second, not bits
## per second, and that prefixes are binary prefixes, i.e. 2^10, 2^20, etc.
#RelayBandwidthRate 100 KB # Throttle traffic to 100KB/s (800Kbps)
#RelayBandwidthBurst 200 KB # But allow bursts up to 200KB/s (1600Kbps)
## Use these to restrict the maximum traffic per day, week, or month.
## Note that this threshold applies separately to sent and received bytes,
## not to their sum: setting "4 GB" may allow up to 8 GB total before
## hibernating.
##
## Set a maximum of 4 gigabytes each way per period.
#AccountingMax 4 GB
## Each period starts daily at midnight (AccountingMax is per day)
#AccountingStart day 00:00
## Each period starts on the 3rd of the month at 15:00 (AccountingMax
## is per month)
#AccountingStart month 3 15:00
## Administrative contact information for this relay or bridge. This line
## can be used to contact you if your relay or bridge is misconfigured or
## something else goes wrong. Note that we archive and publish all
## descriptors containing these lines and that Google indexes them, so
## spammers might also collect them. You may want to obscure the fact that
## it's an email address and/or generate a new address for this purpose.
#ContactInfo Random Person <nobody AT example dot com>
## You might also include your PGP or GPG fingerprint if you have one:
#ContactInfo 0xFFFFFFFF Random Person <nobody AT example dot com>
## Uncomment this to mirror directory information for others. Please do
## if you have enough bandwidth.
#DirPort 9030 # what port to advertise for directory connections
## If you want to listen on a port other than the one advertised in
## DirPort (e.g. to advertise 80 but bind to 9091), you can do it as
## follows. below too. You'll need to do ipchains or other port
## forwarding yourself to make this work.
#DirPort 80 NoListen
#DirPort 127.0.0.1:9091 NoAdvertise
## Uncomment to return an arbitrary blob of html on your DirPort. Now you
## can explain what Tor is if anybody wonders why your IP address is
## contacting them. See contrib/tor-exit-notice.html in Tor's source
## distribution for a sample.
#DirPortFrontPage /etc/tor/tor-exit-notice.html
## Uncomment this if you run more than one Tor relay, and add the identity
## key fingerprint of each Tor relay you control, even if they're on
## different networks. You declare it here so Tor clients can avoid
## using more than one of your relays in a single circuit. See
## https://www.torproject.org/docs/faq#MultipleRelays
## However, you should never include a bridge's fingerprint here, as it would
## break its concealability and potentionally reveal its IP/TCP address.
#MyFamily $keyid,$keyid,...
## A comma-separated list of exit policies. They're considered first
## to last, and the first match wins. If you want to _replace_
## the default exit policy, end this with either a reject *:* or an
## accept *:*. Otherwise, you're _augmenting_ (prepending to) the
## default exit policy. Leave commented to just use the default, which is
## described in the man page or at
## https://www.torproject.org/documentation.html
##
## Look at https://www.torproject.org/faq-abuse.html#TypicalAbuses
## for issues you might encounter if you use the default exit policy.
##
## If certain IPs and ports are blocked externally, e.g. by your firewall,
## you should update your exit policy to reflect this -- otherwise Tor
## users will be told that those destinations are down.
##
## For security, by default Tor rejects connections to private (local)
## networks, including to your public IP address. See the man page entry
## for ExitPolicyRejectPrivate if you want to allow "exit enclaving".
##
#ExitPolicy accept *:6660-6667,reject *:* # allow irc ports but no more
#ExitPolicy accept *:119 # accept nntp as well as default exit policy
#ExitPolicy reject *:* # no exits allowed
## Bridge relays (or "bridges") are Tor relays that aren't listed in the
## main directory. Since there is no complete public list of them, even an
## ISP that filters connections to all the known Tor relays probably
## won't be able to block all the bridges. Also, websites won't treat you
## differently because they won't know you're running Tor. If you can
## be a real relay, please do; but if not, be a bridge!
#BridgeRelay 1
## By default, Tor will advertise your bridge to users through various
## mechanisms like https://bridges.torproject.org/. If you want to run
## a private bridge, for example because you'll give out your bridge
## address manually to your friends, uncomment this line:
#PublishServerDescriptor 0
+44
View File
@@ -0,0 +1,44 @@
# This is the configuration for libtorsocks (transparent socks) for use
# with tor, which is providing a socks server on port 9050 by default.
#
# Lines beginning with # and blank lines are ignored
# Much more documentation than provided in these comments can be found in
#
# torsocks.conf(5), torsocks(1) and torsocks(8) manpages.
# Default Tor address and port. By default, Tor will listen on localhost for
# any SOCKS connection and relay the traffic on the Tor network.
TorAddress 127.0.0.1
TorPort 9050
# Tor hidden sites do not have real IP addresses. This specifies what range of
# IP addresses will be handed to the application as "cookies" for .onion names.
# Of course, you should pick a block of addresses which you aren't going to
# ever need to actually connect to. This is similar to the MapAddress feature
# of the main tor daemon.
OnionAddrRange 127.42.42.0/24
# SOCKS5 Username and Password. This is used to isolate the torsocks connection
# circuit from other streams in Tor. Use with option IsolateSOCKSAuth (on by
# default) in tor(1). TORSOCKS_USERNAME and TORSOCKS_PASSWORD environment
# variable overrides these options.
#SOCKS5Username <username>
#SOCKS5Password <password>
# Set Torsocks to accept inbound connections. If set to 1, listen() and
# accept() will be allowed to be used with non localhost address. (Default: 0)
#AllowInbound 1
# Set Torsocks to allow outbound connections to the loopback interface.
# If set to 1, connect() will be allowed to be used to the loopback interface
# bypassing Tor. If set to 2, in addition to TCP connect(), UDP operations to
# the loopback interface will also be allowed, bypassing Tor. This option
# should not be used by most users. (Default: 0)
#AllowOutboundLocalhost 1
# Set Torsocks to use an automatically generated SOCKS5 username/password based
# on the process ID and current time, that makes the connections to Tor use a
# different circuit from other existing streams in Tor on a per-process basis.
# If set, the SOCKS5Username and SOCKS5Password options must not be set.
# (Default: 0)
#IsolatePID 1