Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add opt-in configuration for incoming Related connections through 'gateway_allow_incoming_related_state' #3

Merged
merged 1 commit into from
May 15, 2023

Conversation

IainKay
Copy link
Contributor

@IainKay IainKay commented May 8, 2023

When running a freshly installed Whonix-Gateway (confirmed that at least 16.0.9.8 and 16.0.9.0 are affected) on a KVM host (note: with Kicksecure installed on the host), Tor gets stuck at 30% when attempting to bootstrap.

(Appears to be the same issue as here: https://forums.whonix.org/t/tor-is-not-yet-fully-bootstrapped-30-done/8792/2)

When I enable the new configuration option "GATEWAY_ALLOW_INCOMING_RELATED_STATE" in file "/usr/local/etc/whonix_firewall.d/50_user.conf", this allows the connection to complete successfully every time.

When I disable the "GATEWAY_ALLOW_INCOMING_RELATED_STATE" option I observe that the issue returns.

I saw a suggestion on the Whonix forums (I believe from Patrick Schleizer) that this could be made into a configuration option. Rather than wasting time replying saying: "yes please I would love this", I've gone ahead and made the necessary changes myself.

Tested on my end and confirmed that this is working as expected.

…teway_allow_incoming_related_state'

When running a freshly installed Whonix-Gateway (confirmed that at least 16.0.9.8 and 16.0.9.0 are affected) on a KVM host (note: with Kicksecure installed on the host), Tor gets stuck at 30% when attempting to bootstrap.

When I enable the new configuration option "GATEWAY_ALLOW_INCOMING_RELATED_STATE" in file "/usr/local/etc/whonix_firewall.d/50_user.conf", this allows the connection to complete successfully every time.

When I disable the "GATEWAY_ALLOW_INCOMING_RELATED_STATE" option I observe that the issue returns.

I saw a suggestion on the Whonix forums (I believe from Patrick Schleizer) that this could be made into a configuration option. Rather than wasting time replying saying: "yes please I would love this", I've gone ahead and made the necessary changes myself.

Tested on my end and confirmed that this is working as expected.
@IainKay
Copy link
Contributor Author

IainKay commented May 8, 2023

Hello,

I put this together to fix an issue that I have been experiencing.

I saw that some other users on the forums may also have experienced this issue and hope that my contribution may be helpful!

@adrelanos adrelanos merged commit 810b740 into Whonix:master May 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants