Created by: ston1th 2019-05-29 18:17:19
Updated by: ston1th 2022-05-12 22:44:22
Visibility: Public

OpenBSD Tor Relay

Installation

#!/bin/sh

if [ $(id -u) -ne 0 ]; then
  echo "error: script must be run as root" >&2
  exit 2
fi

USR="_tor"
CHR="/var/tor"
VERSION="0.4.7.7"
TORGZ="tor-${VERSION}.tar.gz"
TORSUM="${TORGZ}.sha256sum"
TORASC="${TORSUM}.asc"
DOWNLOAD="https://dist.torproject.org"

ADDR="<tor server address>"
NICK="<tor server nickname>"
MAX_BAND="<max bandwidth>"
MAX_BURST_BAND="<max burst bandwidth>"

# Create login class
cat <<EOF>> /etc/login.conf

${USR}:\\
        :openfiles-max=13500:\\
        :openfiles-cur=13500:\\
        :tc=daemon:
EOF
cap_mkdb /etc/login.conf

# Create chroot
mkdir -p ${CHR}/{bin,dev,etc/tor,data}
groupadd ${USR}
useradd -L ${USR} -g ${USR} -d /var/empty -s /sbin/nologin ${USR}
cd ${CHR}/dev
sh /dev/MAKEDEV std random
rm ${CHR}/dev/{console,klog,kmem,ksyms,mem,tty,xf86}

# Create etc config
cp /etc/{resolv.conf,hosts,localtime} ${CHR}/etc/
chmod 0644 ${CHR}/etc/{resolv.conf,hosts,localtime}

# Create tor config
cat <<EOF> ${CHR}/etc/tor/torrc
RunAsDaemon 1
Log notice file /data/tor.log
DataDirectory /data
ORPort 9001
DirPort 9030
Address ${ADDR}
Nickname ${NICK}
RelayBandwidthRate ${MAX_BAND}
RelayBandwidthBurst ${MAX_BURST_BAND}
MaxMemInQueues 2500MB
NumCPUs 2
ExitPolicy reject *:*
EOF

# Add packages
pkg_info | grep "^gmake"
[ ${?} -ne 0 ] && pkg_add gmake
pkg_info | grep "^gnupg"
[ ${?} -ne 0 ] && pkg_add -I -z gnupg-1
pkg_info | grep "^libevent"
[ ${?} -ne 0 ] && pkg_add libevent

# Building
# https://support.torproject.org/little-t-tor/verify-little-t-tor/
#gpg --auto-key-locate nodefault,wkd --locate-keys ahf@torproject.org
#gpg --auto-key-locate nodefault,wkd --locate-keys dgoulet@torproject.org
#gpg --auto-key-locate nodefault,wkd --locate-keys nickm@torproject.org
gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys \
  0x1C1BC007A9F607AA8152C040BEA7B180B1491921 \
  0xB74417EDDF22AC9F9E90F49142E86A2A11F48D36 \
  0x7A02B3521DC75C542BA015456AFEE6D49E92B601

cd /tmp
ftp -o ${TORGZ} ${DOWNLOAD}/${TORGZ}
ftp -o ${TORSUM} ${DOWNLOAD}/${TORSUM}
ftp -o ${TORASC} ${DOWNLOAD}/${TORASC}
gpg --verify ${TORASC}
if [ ${?} -ne 0 ]; then
  echo "error: gpg verify failed" >&2
  exit 2
fi
sha256 -C ${TORSUM} ${TORGZ}
if [ ${?} -ne 0 ]; then
  echo "error: sha256 verify failed" >&2
  exit 2
fi
tar xfz ${TORGZ}
cd tor-${VERSION}
env CFLAGS=-static ./configure --prefix=/ --disable-asciidoc --disable-manpage --disable-html-manual --disable-unittests
gmake noinst_PROGRAMS= EXTRA_DIST= DIST_SOURCES= SOURCES= TESTS= DESTDIR=${CHR} install

# Set permissions
chmod 0755 ${CHR}/{bin,dev,etc,data}
chmod 0750 ${CHR}
chown -R root:wheel ${CHR}
chown root:${USR} ${CHR}
chown -R ${USR}:${USR} ${CHR}/data

# Init script
cat <<EOF> /etc/rc.d/tor
#!/bin/sh

daemon="/usr/bin/env -i /usr/sbin/chroot -u ${USR} -g ${USR} ${CHR}"

. /etc/rc.d/rc.subr

pexp="\${daemon_flags}"

rc_cmd \$1
EOF

cat <<EOF> /etc/sysctl.conf
kern.maxfiles=16384

#net.inet.tcp.recvspace=65535
#net.inet.tcp.sendspace=65535
net.inet.ip.maxqueue=2048
kern.somaxconn=2048
net.bpf.bufsize=2097152
net.bpf.maxbufsize=4194304

#net.inet.ip.portfirst=32768
#net.inet.ip.portlast=49151
#net.inet.ip.porthifirst=49152
#net.inet.ip.porthilast=65535

kern.seminfo.semmni=1024
kern.seminfo.semmns=4096
kern.shminfo.shmmax=67018864
kern.shminfo.shmall=32768
EOF

# Apply sysctl
grep "^[^#]" /etc/sysctl.conf | xargs sysctl

chmod 0555 /etc/rc.d/tor

rcctl enable tor
rcctl set tor flags "/bin/tor"
rcctl start tor

Rebuild

#!/bin/sh

if [ $(id -u) -ne 0 ]; then
  echo "error: script must be run as root" >&2
  exit 2
fi

CHR="/var/tor"
VERSION="0.4.7.7"
TORGZ="tor-${VERSION}.tar.gz"
TORSUM="${TORGZ}.sha256sum"
TORASC="${TORSUM}.asc"
DOWNLOAD="https://dist.torproject.org"

rcctl stop tor

cd /tmp
ftp -o ${TORGZ} ${DOWNLOAD}/${TORGZ}
ftp -o ${TORSUM} ${DOWNLOAD}/${TORSUM}
ftp -o ${TORASC} ${DOWNLOAD}/${TORASC}
gpg --verify ${TORASC}
if [ ${?} -ne 0 ]; then
  echo "error: gpg verify failed" >&2
  exit 2
fi
sha256 -C ${TORSUM} ${TORGZ}
if [ ${?} -ne 0 ]; then
  echo "error: sha256 verify failed" >&2
  exit 2
fi
tar xfz ${TORGZ}
cd tor-${VERSION}
env CFLAGS=-static ./configure --prefix=/ --disable-asciidoc --disable-manpage --disable-html-manual --disable-unittests
gmake noinst_PROGRAMS= EXTRA_DIST= DIST_SOURCES= SOURCES= TESTS= DESTDIR=${CHR} install

rcctl start tor

Uninstall

#!/bin/sh

if [ $(id -u) -ne 0 ]; then
  echo "error: script must be run as root" >&2
  exit 2
fi

rcctl stop tor
rcctl disable tor

userdel _tor
groupdel _tor

# TODO remove tor from login.conf

rm -rf /var/tor /etc/rc.d/tor