2014-10-25 16:49:49 +00:00
|
|
|
#!/bin/bash
|
2014-10-14 16:02:12 +00:00
|
|
|
|
|
|
|
if [ -x /usr/sbin/xenstore-read ]; then
|
|
|
|
XENSTORE_READ="/usr/sbin/xenstore-read"
|
|
|
|
else
|
|
|
|
XENSTORE_READ="/usr/bin/xenstore-read"
|
|
|
|
fi
|
2014-10-25 16:49:49 +00:00
|
|
|
|
|
|
|
INTERFACE="eth1"
|
2014-10-28 08:09:55 +00:00
|
|
|
ip=$(${XENSTORE_READ} qubes-netvm-gateway 2> /dev/null)
|
2014-10-14 16:02:12 +00:00
|
|
|
|
|
|
|
# Create a dummy eth1 interface so tor can bind to it if there
|
|
|
|
# are no DOMU virtual machines connected at the moment
|
2014-10-25 16:49:49 +00:00
|
|
|
ip link show ${INTERFACE} >> /dev/null || {
|
|
|
|
/sbin/ip link add ${INTERFACE} type dummy
|
|
|
|
|
|
|
|
# Now, assign it the netvm-gateway IP address
|
|
|
|
if [ x${ip} != x ]; then
|
|
|
|
netmask=$(${XENSTORE_READ} qubes-netvm-netmask)
|
|
|
|
gateway=$(${XENSTORE_READ} qubes-netvm-gateway)
|
|
|
|
/sbin/ifconfig ${INTERFACE} ${ip} netmask 255.255.255.255
|
|
|
|
/sbin/ifconfig ${INTERFACE} up
|
|
|
|
/sbin/ethtool -K ${INTERFACE} sg off
|
|
|
|
/sbin/ethtool -K ${INTERFACE} tx off
|
|
|
|
fi
|
2014-10-29 16:53:35 +00:00
|
|
|
|
|
|
|
ip link set ${INTERFACE} up
|
2014-10-25 16:49:49 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
# Files that will have the immutable bit set
|
|
|
|
# since we don't want them modified by other programs
|
|
|
|
IMMUTABLE_FILES=(
|
|
|
|
'/etc/resolv.conf'
|
|
|
|
'/etc/hostname'
|
|
|
|
'/etc/hosts'
|
|
|
|
)
|
|
|
|
|
|
|
|
immutableFilesEnable() {
|
|
|
|
files="${1}"
|
|
|
|
suffix="${2}"
|
|
|
|
|
|
|
|
for file in "${files[@]}"; do
|
|
|
|
if [ -f "${file}" ] && ! [ -L "${file}" ]; then
|
|
|
|
chattr +i "${file}${suffix}"
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
}
|
|
|
|
|
|
|
|
immutableFilesDisable() {
|
|
|
|
files="${1}"
|
|
|
|
suffix="${2}"
|
|
|
|
|
|
|
|
for file in "${files[@]}"; do
|
|
|
|
if [ -f "${file}" ] && ! [ -L "${file}" ]; then
|
|
|
|
chattr -i "${file}${suffix}"
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
}
|
|
|
|
|
|
|
|
copyAnondist() {
|
|
|
|
file="${1}"
|
|
|
|
suffix="${2-.anondist}"
|
|
|
|
|
|
|
|
# Remove any softlinks first
|
|
|
|
if [ -L "${file}" ]; then
|
|
|
|
rm -f "${file}"
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ -f "${file}" ] && [ -n "$(diff ${file} ${file}${suffix})" ]; then
|
|
|
|
chattr -i "${file}"
|
|
|
|
rm -f "${file}"
|
|
|
|
cp -p "${file}${suffix}" "${file}"
|
|
|
|
chattr +i "${file}"
|
|
|
|
elif ! [ -f "${file}" ]; then
|
|
|
|
cp -p "${file}${suffix}" "${file}"
|
|
|
|
chattr +i "${file}"
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
# Make sure all .anondist files in list are immutable
|
|
|
|
immutableFilesEnable "${IMMUTABLE_FILES}"
|
|
|
|
immutableFilesEnable "${IMMUTABLE_FILES}" ".anondist"
|
|
|
|
|
|
|
|
# Make sure we are using a copy of the annondist file and if not
|
|
|
|
# copy the annondist file and set it immutable
|
|
|
|
copyAnondist "/etc/resolv.conf"
|
|
|
|
copyAnondist "/etc/hosts"
|
|
|
|
copyAnondist "/etc/hostname"
|
2014-10-14 16:02:12 +00:00
|
|
|
|
|
|
|
# Replace IP addresses in known configuration files / scripts to
|
|
|
|
# currently discovered one
|
|
|
|
/usr/lib/whonix/replace-ips
|
|
|
|
|
|
|
|
# Make sure hostname is correct
|
2014-10-29 16:53:35 +00:00
|
|
|
/bin/hostname host
|
2014-10-14 16:02:12 +00:00
|
|
|
|
|
|
|
# Start Whonix Firewall
|
|
|
|
export INT_IF="vif+"
|
|
|
|
export INT_TIF="vif+"
|
|
|
|
/usr/bin/whonix_firewall
|
2014-10-25 16:49:49 +00:00
|
|
|
|
|
|
|
# Route any traffic FROM netvm TO netvm BACK-TO localhost
|
|
|
|
# Allows localhost access to tor network
|
|
|
|
iptables -t nat -A OUTPUT -s ${ip} -d ${ip} -j DNAT --to-destination 127.0.0.1
|
2014-10-28 08:09:55 +00:00
|
|
|
|
2014-10-29 16:53:35 +00:00
|
|
|
# Will only enable / disable if service is not already in that state
|
|
|
|
enable_sysv() {
|
2014-10-28 08:09:55 +00:00
|
|
|
servicename=${1}
|
2014-10-29 16:53:35 +00:00
|
|
|
disable=${2-0}
|
|
|
|
|
|
|
|
# Check to see if the service is already enabled and if not, enable it
|
|
|
|
string="/etc/rc$(runlevel | awk '{ print $2 }').d/S[0-9][0-9]${servicename}"
|
|
|
|
|
|
|
|
if [ $(find $string 2>/dev/null | wc -l) -eq ${disable} ] ; then
|
|
|
|
case ${disable} in
|
|
|
|
0)
|
|
|
|
echo "${1} is currently disabled; enabling it"
|
|
|
|
systemctl --quiet enable ${servicename}
|
|
|
|
;;
|
|
|
|
1)
|
|
|
|
echo "${1} is currently enabled; disabling it"
|
|
|
|
systemctl --quiet disable ${servicename}
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
fi
|
2014-10-28 08:09:55 +00:00
|
|
|
}
|
|
|
|
|
2014-10-29 16:53:35 +00:00
|
|
|
disable_sysv() {
|
|
|
|
enable_sysv ${1} 1
|
|
|
|
}
|
2014-10-28 08:09:55 +00:00
|
|
|
|
2014-10-29 16:53:35 +00:00
|
|
|
# This would be a really good place to apply any hacks required and remove them
|
|
|
|
# from template build script
|
|
|
|
grep "^DisableNetwork 0$" /etc/tor/torrc && {
|
|
|
|
#enable_sysv tor
|
|
|
|
#enable_sysv whonixcheck
|
|
|
|
#enable_sysv sdwdate
|
|
|
|
:
|
|
|
|
} || {
|
|
|
|
:
|
|
|
|
}
|