commit21d708eb027a1bdeb5be4b5365d029625a67f9bf
Allow root to connect to Tor's SOCKSPort (refs: #17278)
This fixes an issue which occurs when partial APT lists are present in /var/lib/apt/lists/partial which are owned by root instead of the _apt user, which causes APT to run as root rather than _apt, therefore failing to connect when it's not allowed to connect to the SOCKS port.
@@ -36,6 +36,7 @@ domain ip {
mod owner uid-owner _apt ACCEPT;
mod owner uid-owner proxy ACCEPT;
mod owner uid-owner nobody ACCEPT;
+ mod owner uid-owner root ACCEPT;
daddr proto tcp syn mod multiport destination-ports (9050 9062 9150) {
mod owner uid-owner $amnesia_uid ACCEPT;