28 Commits
Author SHA1 Message Date
bj 5a2ac0c3dc Attempt to fix broken PySocks Debian package dependency 2020-10-20 13:27:09 +02:00
bj 26d4444137 Revised README.md files to take Rudefox repo into account 2020-10-20 12:26:26 +02:00
bj 59ddc37cfd Incremented version number to 0.0.5 2020-10-20 12:25:35 +02:00
bj fe94fcc204 BUGFIX: onion urls were broken 2020-10-20 12:16:19 +02:00
bj a8b1029ad2 Can provision from the online Rudefox Debian repo 2020-10-20 10:49:38 +02:00
bj 32ee0ffe55 fixed up build-deb.sh 2020-10-20 10:25:31 +02:00
bj f31e9e62d7 fixed build by correcting typo in setup.cfg 2020-10-20 00:42:05 +02:00
bj 05c9ae8d6e Upgraded build system to setup.cfg 2020-10-20 00:27:38 +02:00
bj 64b9698010 Fixed PySocks (lack of) dependency and formatting 2020-10-20 00:20:33 +02:00
bj d9e68d50fe Upgraded setuptools version 2020-10-20 00:08:33 +02:00
bj 1c6da7a091 Added .gitignore for .idea 2020-10-20 00:08:17 +02:00
bj 609ccfbf27 Fixed bash script warnings 2020-10-20 00:07:57 +02:00
bj a78cddfdb1 Fixed broken comment 2020-10-20 00:07:36 +02:00
bj a38b6ee751 Fixed typo 2020-10-20 00:07:24 +02:00
bj f3677ad45e Incremented version to 0.0.4 2020-10-09 12:11:59 +02:00
bj ceb80569cb Debian dependency fixed (albeit in a hacky way for now...) Finally works through tor on RPi image 2020-10-09 11:59:31 +02:00
bj 72c6af328e Attempt 3 at solving dependency issue on pi 2020-10-09 01:42:36 +02:00
bj 54b1fe79a9 2nd attempt at fixing Debian packaging issue with paho-mqtt version for RPi 2020-10-09 01:16:14 +02:00
bj 19df7d2d35 Updated example Debian package 2020-10-09 00:17:54 +02:00
bj 1a4fceb89e Increment version to 0.0.3 2020-10-09 00:01:59 +02:00
bj fa3ad27146 BUGFIX: Require Python paho-mqtt package version >= 1.5.1 2020-10-09 00:01:38 +02:00
bj 21d8dbe1d1 Added updated example .deb package 2020-10-08 19:58:45 +02:00
bj 4a54459eab BUGFIX: Changelog changed to build package 2020-10-08 19:55:00 +02:00
bj 21665f976c Updated version to 0.0.2 2020-10-08 19:48:16 +02:00
bj a891f9bf51 Revomed redundant version number constant 2020-10-08 19:45:01 +02:00
bj fa24e56662 Deleted unnecessary file 2020-10-08 19:41:39 +02:00
bj c94962e2f1 Updated README.md 2020-10-08 15:25:08 +02:00
bj a9aca4da54 Moved build over to Python setuptools and Debian dh_python 2020-10-08 15:20:42 +02:00
17 changed files with 154 additions and 144 deletions
+1
View File
@@ -6,3 +6,4 @@ venv
/*.egg-info
*.pyc
__pycache__
.idea
+16 -8
View File
@@ -13,7 +13,19 @@ A TORch solution consists of 3 processes:
* MQTT broker - Any MQTT broker, reachable via IPv4 or Tor, through TLS or insecure communications
* `torch-subscriber` - Listens for and handles onion hostname publications
## Build Debian Package
## Installation
### Install Package from Rudefox Debian Repo
1. Add the [Rudefox Repo](https://rudefox.io/repo/) as an `apt` source
2. Install the `torch-agent` package
```bash
sudo apt install torch-agent
```
### Build Debian Package from Source
If you don't already have a GPG key, generate one:
@@ -21,11 +33,11 @@ If you don't already have a GPG key, generate one:
gpg --full-generate-key
```
Using the e-mail address you provided during GPG key generation, run `make-pkg.sh` to build a Debian package and install it
Using the e-mail address you provided during GPG key generation, run `build-deb.sh` to build a Debian package and install it
```bash
./make-pkg.sh [email protected]
apt update && apt install build/torch-agent_0.0.1-1_all.deb
./build-deb.sh [email protected]
apt update && apt install build/torch-agent_0.0.5-1_all.deb
```
This will:
@@ -45,7 +57,3 @@ The configuation directory can be specified by
A fully configured example can be found [here](example)
See the sample [`torch.conf`](torch.conf) file for additional configuration options and details
## Roadmap
[ ] Utilize [dh_python3](https://www.debian.org/doc/manuals/debmake-doc/ch08.en.html#setup-py) in Debian package build
+18 -17
View File
@@ -1,33 +1,34 @@
#!/bin/bash
TORCH_VERSION=$(git describe --tags --abbrev=0)
PROJECT=torch-agent-$TORCH_VERSION
if [[ -z "${DEBEMAIL}" ]]; then
DEBEMAIL="$1"
if [[ -z "${DEB_EMAIL}" ]]; then
DEB_EMAIL="$1"
fi
if [[ -z "${DEBEMAIL}" ]]; then
if [[ -z "${DEB_EMAIL}" ]]; then
echo "E-mail address required for packaging signing with gpg key!"
echo "Usage: ./build-deb.sh EMAIL"
exit 1
fi
TORCH_VERSION=$(git describe --tags --abbrev=0)
PROJECT=torch-agent-$TORCH_VERSION
BUILD_DIR=dist
DEB_DIR=$BUILD_DIR/$PROJECT
rm -rf $BUILD_DIR/*
rm -rf "${BUILD_DIR:?}"
mkdir -p "$DEB_DIR/src/etc/torch"
cp -r debian "$DEB_DIR/"
cp torch.conf "$DEB_DIR/src/etc/torch/"
pip3 install -r requirements.txt
python3 setup.py sdist
mkdir -p $DEB_DIR/src/etc/torch
cp -r debian $DEB_DIR/
cp torch.conf $DEB_DIR/src/etc/torch/
cd $BUILD_DIR || exit
tar -xzmf "$PROJECT.tar.gz"
cd $BUILD_DIR
tar -xzmf $PROJECT.tar.gz
cd $PROJECT
export USER=`whoami`
dh_make --createorig -e $DEBEMAIL -s -y
dpkg-buildpackage -k$DEBEMAIL
cd "$PROJECT" || exit
export USER
USER=$(whoami)
dh_make --createorig -e "$DEB_EMAIL" -s -y
dpkg-buildpackage -k"$DEB_EMAIL"
+3 -3
View File
@@ -1,5 +1,5 @@
torch-agent (0.0.1-1) unstable; urgency=medium
torch-agent (0.0.5-1) stable; urgency=medium
* Initial release
* Update
-- Benjamin Dweck <[email protected]> Tue, 06 Oct 2020 15:53:02 +0200
-- Benjamin Dweck <[email protected]> Tue, 08 Oct 2020 19:46:22 +0200
-2
View File
@@ -1,2 +0,0 @@
torch-agent_0.0.1-1_all.deb net optional
torch-agent_0.0.1-1_amd64.buildinfo net optional
+5 -3
View File
@@ -53,10 +53,12 @@ case "$1" in
useradd -r -g $GROUP $USER
fi
chown $USER /etc/torch
chown $USER /etc/torch/torch.conf
sudo -H pip3 install 'paho-mqtt>=1.5.1'
configure_tor_controller
chown $USER /etc/torch
chown $USER /etc/torch/torch.conf
configure_tor_controller
;;
abort-upgrade|abort-remove|abort-deconfigure)
+1
View File
@@ -0,0 +1 @@
OthermoduleName python-othermodule; PEP386
+1 -10
View File
@@ -35,19 +35,10 @@ In a separate terminal window, run the subscriber:
#### Run TORch Agent in Vagrant
[Build](..) the latest source into a Debian package and copy it to `example/`
```bash
cd ..
./make-pkg.sh [email protected]
cp -f build/torch-agent_0.0.1-1_all.deb example/
cd example
```
Run the Vagrant box in a third terminal window:
```bash
vagrant up
```
You should see that the broker received a connection from the Vagrant box at boot up and the subscriber received the onion hostname. You can use a local `tor` proxy to connect to the vagrant box using SSH and the onion hostname.
You should see that the broker received a connection from the Vagrant box at boot up and the subscriber received the onion hostname. You can use a local `tor` proxy to connect to the vagrant box using SSH and the onion hostname.
+9 -7
View File
@@ -64,17 +64,19 @@ Vagrant.configure("2") do |config|
# Ansible, Chef, Docker, Puppet and Salt are also available. Please see the
# documentation for more information about their specific syntax and use.
config.vm.provision "file", source: "torch-agent_0.0.1-1_all.deb", destination: "~/"
config.vm.provision "file", source: "agent-config", destination: "~/torch-conf"
config.vm.provision "shell", inline: <<-SHELL
sudo -- sh -c "echo '10.0.2.2 mqtt.example.com' >> /etc/hosts"
sudo -- sh -c "echo '10.0.2.2 mqtt.example.com' >> /etc/hosts"
sudo apt update
sudo apt install -y ./torch-agent_0.0.1-1_all.deb
sudo cp -f torch-conf/* /etc/torch/
wget -qO - https://rudefox.io/repo/gpg | sudo apt-key add
sudo add-apt-repository "deb https://repo.rudefox.io/repository/apt-release focal main"
sudo apt update
sudo apt install -y torch-agent
sudo cp -f torch-conf/* /etc/torch/
sudo chown -R torch /etc/torch
sudo systemctl enable torch-agent
Binary file not shown.
+3
View File
@@ -0,0 +1,3 @@
[build-system]
requires = ["setuptools", "wheel"]
build-backend = "setuptools.build_meta"
+5 -4
View File
@@ -1,5 +1,6 @@
wheel>=0.35.1
setuptools>=44.0.0
pip~=20.2.4
setuptools~=50.3.2
stdeb3~=0.9.0.post2
paho-mqtt~=1.5.1
stem>=1.8.0
paho-mqtt>=1.5.1
PySocks>=1.7.1
PySocks
+25
View File
@@ -0,0 +1,25 @@
[metadata]
name = torch-agent
version = attr: torch_agent.__version__
author = Benjamin Dweck
author_email = [email protected]
description = TORch: Illuminate the Way to your Node
url = https://git.rudefox.io/bj/torch-agent
classifiers =
Programming Language :: Python :: 3
License :: OSI Approved :: MIT License
[options]
packages = find:
install_requires =
paho-mqtt~=1.5.1
setuptools~=50.3.1
pip~=20.2.3
stem
PySocks
[options.entry_points]
console_scripts = torch-agent=torch_agent.torch_agent:main
[options.packages.find]
exclude=test
+1 -28
View File
@@ -1,31 +1,4 @@
#!/usr/bin/env python3
import setuptools
with open("README.md", "r") as fh:
long_description = fh.read()
setuptools.setup(
name="torch-agent",
version="0.0.1",
author="B.J. Dweck",
author_email="[email protected]",
description="TORch: Iluminate the Way to your Node",
long_description=long_description,
long_description_content_type="text/markdown",
url="https://git.rudefox.io/bj/torch-agent",
packages=setuptools.find_packages(),
install_requires=[
'stem',
'paho-mqtt',
'PySocks',
],
entry_points = {
'console_scripts': ['torch-agent=torch_agent.torch_agent:main'],
},
classifiers=[
"Programming Language :: Python :: 3",
"License :: OSI Approved :: MIT License",
],
python_requires='>=3.6',
)
setuptools.setup()
+4 -1
View File
@@ -6,7 +6,10 @@ ControllerPort = 9051
Port = 22
[mqtt]
BrokerHost = mqtt.example.com # OR example1i3uyrbfoi3fi.onion
BrokerHost = mqtt.example.com
#BrokerHost = example1i3uyrbfoi3fi.onion
BrokerPort = 1883
ClientID = my-client
Topic = example/topic
+1 -1
View File
@@ -1 +1 @@
__version__ = "0.0.1"
__version__ = "0.0.5"
+61 -60
View File
@@ -1,8 +1,8 @@
from stem.control import Controller
import stem.connection
import paho.mqtt.client as mqtt
import ssl
import socks
import ssl
import socket
import json
import configparser
@@ -10,88 +10,89 @@ import argparse
from datetime import datetime
from os import environ
def main():
parser = argparse.ArgumentParser(description='Broadcast SSH hidden service hostname via MQTT')
parser = argparse.ArgumentParser(description='Broadcast SSH hidden service hostname via MQTT')
parser.add_argument('--config-dir', nargs='?', dest='configPath', default='/etc/torch',
help='configuration directory (default: /etc/torch)')
parser.add_argument('--config-dir', nargs='?', dest='configPath', default='/etc/torch',
help='configuration directory (default: /etc/torch)')
args = parser.parse_args()
args = parser.parse_args()
configPath = args.configPath
config_path = args.configPath
if "TORCH_CONFIG_DIR" in environ:
configPath = environ.get("TORCH_CONFIG_DIR")
if "TORCH_CONFIG_DIR" in environ:
config_path = environ.get("TORCH_CONFIG_DIR")
if not configPath.endswith("/"):
configPath = configPath + "/"
if not config_path.endswith("/"):
config_path = config_path + "/"
print("Using torch configuration path: " + configPath)
print("Using torch configuration path: " + config_path)
config = configparser.ConfigParser()
config.read(configPath + "torch.conf")
config = configparser.ConfigParser()
config.read(config_path + "torch.conf")
torProxyPort = config['tor'].getint('ProxyPort', fallback = 9050)
torControllerPort = config['tor'].getint('ControllerPort', fallback = 9051)
tor_proxy_port = config['tor'].getint('ProxyPort', fallback=9050)
tor_controller_port = config['tor'].getint('ControllerPort', fallback=9051)
sshPort = config['ssh'].getint('Port', fallback = 22)
ssh_port = config['ssh'].getint('Port', fallback=22)
mqttConfig = config['mqtt']
mqttBrokerHost = mqttConfig.get('BrokerHost', fallback = "localhost")
mqttBrokerPort = mqttConfig.getint('BrokerPort', fallback = 1883)
clientID = mqttConfig.get('ClientID', fallback = socket.gethostname())
mqttTopic = mqttConfig.get('Topic', fallback = "torch/%s/onion_url" % (clientID))
mqtt_config = config['mqtt']
mqtt_broker_host = mqtt_config.get('BrokerHost', fallback="localhost")
mqtt_broker_port = mqtt_config.getint('BrokerPort', fallback=1883)
client_id = mqtt_config.get('ClientID', fallback=socket.gethostname())
mqtt_topic = mqtt_config.get('Topic', fallback="torch/%s/onion_url" % client_id)
mqttRequireCertificate = mqttConfig.getboolean(
'RequireCertificate',
fallback = False)
mqtt_require_certificate = mqtt_config.getboolean(
'RequireCertificate',
fallback=False)
mqttCaFile = configPath + mqttConfig.get('CaFile')
mqttCertFile = configPath + mqttConfig.get('CertFile')
mqttKeyFile = configPath + mqttConfig.get('KeyFile')
mqtt_ca_file = config_path + mqtt_config.get('CaFile')
mqtt_cert_file = config_path + mqtt_config.get('CertFile')
mqtt_key_file = config_path + mqtt_config.get('KeyFile')
with Controller.from_port(port = torControllerPort) as controller:
protocolInfo = stem.connection.get_protocolinfo(controller)
with Controller.from_port(port=tor_controller_port) as controller:
stem.connection.authenticate_safecookie(
controller,
protocolInfo.cookie_path)
print("Connected to Tor on port %s" % (torControllerPort))
protocol_info = stem.connection.get_protocolinfo(controller)
service = controller.create_ephemeral_hidden_service(sshPort, detached = True)
stem.connection.authenticate_safecookie(
controller,
protocol_info.cookie_path)
onionAddress = "%s.onion" % (service.service_id)
print("Connected to Tor on port %s" % tor_controller_port)
print("Created Tor Hidden Service for local port %s at %s" % (sshPort, onionAddress))
service = controller.create_ephemeral_hidden_service(ssh_port, detached=True)
payload = {
'clientId': clientID,
'timestamp': datetime.now().strftime("%d-%b-%Y (%H:%M:%S.%f)"),
'onionAddress': onionAddress,
'sshPort': sshPort
onion_address = "%s.onion" % service.service_id
print("Created Tor Hidden Service for local port %s at %s" % (ssh_port, onion_address))
payload = {
'clientId': client_id,
'timestamp': datetime.now().strftime("%d-%b-%Y (%H:%M:%S.%f)"),
'onionAddress': onion_address,
'sshPort': ssh_port
}
client = mqtt.Client()
protocol = "mqtt"
client = mqtt.Client()
protocol = "mqtt"
if mqttRequireCertificate:
client.tls_set(
ca_certs = mqttCaFile,
certfile = mqttCertFile,
keyfile = mqttKeyFile,
if mqtt_require_certificate:
client.tls_set(
ca_certs=mqtt_ca_file,
certfile=mqtt_cert_file,
keyfile=mqtt_key_file,
cert_reqs=ssl.CERT_REQUIRED)
protocol = "mqtts"
protocol = "mqtts"
if mqttBrokerHost.endswith(".onion"):
client.proxy_set(proxy_type=socks.SOCKS5, proxy_addr="localhost", proxy_port=torProxyPort)
client.tls_insecure_set(True)
if mqtt_broker_host.endswith(".onion"):
client.proxy_set(proxy_type=socks.SOCKS5, proxy_addr="localhost", proxy_port=tor_proxy_port)
client.tls_insecure_set(True)
client.connect(mqttBrokerHost, mqttBrokerPort, 60)
client.publish(mqttTopic, json.dumps(payload))
print("Connected to MQTT Broker at %s://%s:%s/%s" % (protocol, mqttBrokerHost, mqttBrokerPort, mqttTopic))
print("Published payload: " + json.dumps(payload))
client.connect(mqtt_broker_host, mqtt_broker_port, 60)
client.publish(mqtt_topic, json.dumps(payload))
print("Connected to MQTT Broker at %s://%s:%s/%s" % (protocol, mqtt_broker_host, mqtt_broker_port, mqtt_topic))
print("Published payload: " + json.dumps(payload))
client.disconnect()
print("Disconnected from MQTT Broker")
client.disconnect()
print("Disconnected from MQTT Broker")