Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#35832 - [tor] 0.2.3.25-3 Service file should not start Tor as tor user
Attached to Project:
Community Packages
Opened by Jon Gjengset (Jonhoo) - Monday, 17 June 2013, 12:44 GMT
Last edited by Lukas Fleischer (lfleischer) - Friday, 28 June 2013, 12:04 GMT
Opened by Jon Gjengset (Jonhoo) - Monday, 17 June 2013, 12:44 GMT
Last edited by Lukas Fleischer (lfleischer) - Friday, 28 June 2013, 12:04 GMT
|
DetailsDescription:
The Systemd service file shipped with Tor in Arch Linux includes User=tor. This is incorrect as it disallows certain Tor configurations such as starting Tor on port 443 (which requires root). Instead, users should set the User directive in /etc/tor/torrc to "tor" and privileges will be dropped after binding to the port. Also, using the proposed upstream .service file should be considered: https://trac.torproject.org/projects/tor/ticket/8368 Steps to reproduce: 1. Add QRPort 443 in /etc/tor/torrc 2. Run systemctl start tor 3. Observe that Tor fails to start with a Permission denied error upon binding to port 443 4. Remove User=tor in /usr/lib/systemd/system/tor.service 5. Add User tor to /etc/tor/torrc 6. Run systemctl start tor 7. Observe that Tor starts correctly 8. Run ps aux | grep tor and note that the process runs as user tor as expected |
This task depends upon
Closed by Lukas Fleischer (lfleischer)
Friday, 28 June 2013, 12:04 GMT
Reason for closing: Not a bug
Friday, 28 June 2013, 12:04 GMT
Reason for closing: Not a bug
The upstream one hasn't been merged yet, but seems to he well on its way to be.