I updated the patch to
1) have AS close /proc
2) enable core dump files
One should add
/proc /chroot_tor/proc none noauto,bind 0 0
to /etc/fstab (note the 'noauto').
Then the 'tor' startup script does a
mount /chroot_tor/proc
...start tor
sleep 10
umount /chroot_tor/proc
And it works like a charm. 'tor' starts
up with full AddressSanitizer monitoring
but with no pesky /proc file system
available to potential attackers.
Attached are the patch and the
/etc/rc.d/init.d/tor
startup script.
Attachment:
tor-0.2.4.21-as.patch
Description: Binary data
Attachment:
tor
Description: Binary data
_______________________________________________ tor-relays mailing list tor-relays@xxxxxxxxxxxxxxxxxxxx https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays