feat(image): remote LUKS unlock via a Tor onion service in the initramfs
Encrypted image setups can now bake a Tor onion service into the initramfs so the dropbear unlock shell stays reachable behind NAT or a dynamic IP. When the user opts in, configure_encryption installs tor + busybox, drops the mkinitcpio hooks (ordered `netconf tor dropbear encryptssh`), generates the v3 onion keys offline in the image chroot, and prints the stable .onion address. Unlock with `torsocks ssh root@<onion-address>`. The runtime hook syncs the clock via NTP first (RTC-less boards boot at 1970, which Tor's consensus checks reject) and starts the onion service pointing at dropbear on 127.0.0.1:22. Hardening baked in from an adversarial review of the shipped path: - cmdline.txt boot path (RPi4-class firmware boot) now sets the same ip=::::<host>:eth0:dhcp net.ifnames=0 params as the boot.txt path, so the initramfs actually gets a network and the onion can publish. - the initramfs bakes in libnss_dns.so.2 so the NTP hostname resolves. - the hook extracts DHCP DNS with sed instead of sourcing the lease files, which would run attacker-controlled DHCP option strings as root pre-boot. - NTP is attempted unconditionally (bounded), not gated on DHCP-provided DNS. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -49,6 +49,10 @@ def _choose_and_verify_image(plan: ImagePlan) -> None:
|
||||
if plan.operation_system == "linux":
|
||||
choosers.choose_linux_image(plan)
|
||||
plan.encrypt_system = ui.confirm("Should the system be encrypted?")
|
||||
if plan.encrypt_system:
|
||||
plan.tor_unlock = ui.confirm(
|
||||
"Should the system be remotely unlockable via a Tor onion service?"
|
||||
)
|
||||
ui.info("Generating os-image...")
|
||||
transfer.download_image(plan)
|
||||
else:
|
||||
|
||||
Reference in New Issue
Block a user