feat(image): distro-agnostic remote unlock via initramfs backends + Debian support
Split the mkinitcpio-only remote-LUKS-unlock path into an InitramfsBackend ABC with a get_backend() dispatch, and add the initramfs-tools backend for Debian / Raspberry Pi OS. - base.py: six-step backend contract; encryption.py becomes a thin, distro-neutral sequencer (get_backend by distribution). - initramfs_tools.py: crypttab `none luks,initramfs`, cmdline rewritten to root=/dev/mapper + ip=::::host:eth0:dhcp, dropbear-initramfs authorized_keys, update-initramfs -k all (no build-host uname leak). - shipped hooks (configuration/initramfs-tools/*): single-hop non-anonymous onion, libnss DNS baking, sed-not-source DHCP, kill-tor-before-pivot. - shared offline onion keygen in keygen.py; tor.py removed (logic moved to mkinitcpio.py). - raspios added to the apt distro family (session.py, raspberry.py). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
51
lim/configuration/initramfs-tools/tor_premount
Normal file
51
lim/configuration/initramfs-tools/tor_premount
Normal file
@@ -0,0 +1,51 @@
|
||||
#!/bin/sh
|
||||
# initramfs-tools runtime hook: bring up networking, sync the clock and start
|
||||
# the Tor onion service so the dropbear unlock shell is reachable while
|
||||
# cryptsetup waits. Installed to /etc/initramfs-tools/scripts/init-premount/tor.
|
||||
PREREQ=""
|
||||
prereqs() { echo "$PREREQ"; }
|
||||
case "$1" in
|
||||
prereqs) prereqs; exit 0 ;;
|
||||
esac
|
||||
|
||||
. /scripts/functions
|
||||
|
||||
log_begin_msg "tor: bringing up networking and starting the onion service"
|
||||
|
||||
# init-premount runs BEFORE the cryptroot/dropbear networking, so Tor would
|
||||
# start with no network and never publish the onion. Bring the interface up
|
||||
# ourselves from the ip= cmdline (idempotent; the later dropbear setup reuses
|
||||
# the lease in /run/net-*.conf).
|
||||
configure_networking
|
||||
|
||||
# initramfs-tools does not export arbitrary cmdline params as shell vars.
|
||||
tor_ntp=$(sed -n 's/.*\btor_ntp=\([^ ]*\).*/\1/p' /proc/cmdline)
|
||||
|
||||
# Best-effort DNS from the DHCP lease; extract ONLY the DNS fields with sed,
|
||||
# never source the files (attacker-controllable DHCP option strings would run
|
||||
# as root pre-boot).
|
||||
if [ ! -s /etc/resolv.conf ]; then
|
||||
for conf in /run/net-*.conf /tmp/net-*.conf; do
|
||||
[ -f "$conf" ] || continue
|
||||
for dns in $(sed -n 's/^IPV4DNS[01]=//p' "$conf"); do
|
||||
[ -n "$dns" ] && [ "$dns" != "0.0.0.0" ] \
|
||||
&& echo "nameserver $dns" >> /etc/resolv.conf
|
||||
done
|
||||
done
|
||||
fi
|
||||
|
||||
# RTC-less boards boot at 1970; Tor rejects the consensus otherwise. Bounded so
|
||||
# a failed sync never blocks boot.
|
||||
if [ -x /usr/local/bin/busybox ]; then
|
||||
/usr/local/bin/busybox timeout 30 \
|
||||
/usr/local/bin/busybox ntpd -n -q -p "${tor_ntp:-pool.ntp.org}" \
|
||||
|| log_warning_msg "tor: NTP sync failed, keeping current clock"
|
||||
fi
|
||||
|
||||
mkdir -p /var/lib/tor
|
||||
chmod 0700 /var/lib/tor /etc/tor/onion
|
||||
chmod 0600 /etc/tor/onion/hs_ed25519_secret_key
|
||||
tor -f /etc/tor/torrc --RunAsDaemon 1 --Log "notice file /run/tor.log" \
|
||||
|| log_warning_msg "tor: failed to start, unlock stays reachable via direct IP"
|
||||
|
||||
log_end_msg
|
||||
Reference in New Issue
Block a user