mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Add TorTransport in src/transport/tor/ supporting three operating modes: Outbound (socks5 mode): - Non-blocking SOCKS5 connect via tokio-socks with per-destination circuit isolation (IsolateSOCKSAuth) - TorAddr enum for .onion and clearnet address types - Connection pool with per-connection receive tasks, reuses TCP stream FMP framing - connect_async()/connection_state_sync()/promote_connection() follow the same non-blocking polling pattern as TCP transport Inbound (directory mode — recommended for production): - Tor manages the onion service via HiddenServiceDir in torrc - FIPS reads .onion address from hostname file at startup - No control port needed — enables Tor Sandbox 1 (seccomp-bpf) - Accept loop mirrors TCP pattern with DirectoryServiceConfig Monitoring (control_port mode and optional in directory mode): - Async control port client supporting TCP and Unix socket connections via Box<dyn AsyncRead/Write> trait objects - AUTHENTICATE with cookie or password auth - 8 GETINFO queries: bootstrap, circuits, traffic, liveness, version, dormant state, SOCKS listeners - Background monitoring task polls every 10s, caches TorMonitoringInfo in Arc<RwLock> for synchronous query access - Bootstrap milestone logging (25/50/75/100%), stall warning (>60s), network liveness transitions, dormant mode entry - Directory mode optionally connects to control port when control_addr is configured (non-fatal on failure) Operator visibility: - show_transports query exposes tor_mode, onion_address, tor_monitoring (bootstrap, circuit_established, traffic, liveness, version, dormant) - fipstop transport detail view: Tor mode, onion address, SOCKS5/control errors, connection stats, Tor daemon status section - fipstop table view: tor(mode) label with truncated onion address hint Security hardening: - Per-destination circuit isolation via IsolateSOCKSAuth - Unix socket default for control port (/run/tor/control) - Reference torrc with HiddenServiceDir, VanguardsLiteEnabled, ConnectionPadding, DoS protections (PoW + intro rate limiting) Config: - TorConfig with socks5, control_port, and directory modes - DirectoryServiceConfig: hostname_file, bind_addr - control_addr, control_auth, cookie_path, connect_timeout, max_inbound_connections Testing: - 69 unit + integration tests with mock SOCKS5 and control servers - Docker tests: socks5-outbound (clearnet via Tor) and directory-mode (HiddenServiceDir onion service) Documentation: - Transport layer design doc: Tor architecture, directory mode - Configuration doc: Tor config tables and examples
67 lines
1.6 KiB
YAML
67 lines
1.6 KiB
YAML
# Tor transport integration test — socks5-outbound
|
|
#
|
|
# Topology:
|
|
# [fips-a] --tor/socks5--> vps-chi (217.77.8.91:443) <--tor/socks5-- [fips-b]
|
|
#
|
|
# Both FIPS nodes connect outbound through a local Tor daemon's SOCKS5
|
|
# proxy to vps-chi's TCP listener. vps-chi routes between them.
|
|
# Ping between fips-a and fips-b validates the full Tor transport path.
|
|
|
|
networks:
|
|
tor-test:
|
|
driver: bridge
|
|
|
|
services:
|
|
tor-daemon:
|
|
image: osminogin/tor-simple:latest
|
|
container_name: tor-daemon
|
|
restart: "no"
|
|
volumes:
|
|
- ../common/torrc:/etc/tor/torrc:ro
|
|
networks:
|
|
tor-test:
|
|
|
|
fips-a:
|
|
build:
|
|
context: ../common
|
|
cap_add:
|
|
- NET_ADMIN
|
|
devices:
|
|
- /dev/net/tun:/dev/net/tun
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
restart: "no"
|
|
container_name: fips-tor-a
|
|
hostname: fips-tor-a
|
|
depends_on:
|
|
- tor-daemon
|
|
volumes:
|
|
- ../common/resolv.conf:/etc/resolv.conf:ro
|
|
- ./configs/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
environment:
|
|
- RUST_LOG=info,fips::transport::tor=debug
|
|
networks:
|
|
tor-test:
|
|
|
|
fips-b:
|
|
build:
|
|
context: ../common
|
|
cap_add:
|
|
- NET_ADMIN
|
|
devices:
|
|
- /dev/net/tun:/dev/net/tun
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
restart: "no"
|
|
container_name: fips-tor-b
|
|
hostname: fips-tor-b
|
|
depends_on:
|
|
- tor-daemon
|
|
volumes:
|
|
- ../common/resolv.conf:/etc/resolv.conf:ro
|
|
- ./configs/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
environment:
|
|
- RUST_LOG=info,fips::transport::tor=debug
|
|
networks:
|
|
tor-test:
|