fix: HiddenServiceDir must be chmod 700 for Tor

Tor requires HiddenServiceDir to be 700. Root can still read hostname
files inside 700 dirs, so the background onion-writer works fine.
This commit is contained in:
NW
2026-06-24 12:16:59 +01:00
parent 3bbda97bb9
commit b99f70f344

View File

@@ -32,8 +32,7 @@ fi
mkdir -p /var/lib/tor/ssh /var/lib/tor/admin
chown -R tor:nogroup /var/lib/tor
chmod 700 /var/lib/tor
chmod 755 /var/lib/tor/ssh /var/lib/tor/admin
chmod 700 /var/lib/tor /var/lib/tor/ssh /var/lib/tor/admin
cat > /etc/tor/torrc <<EOF
# Generated by entrypoint.sh at container start