# \[tor-relays\] Quick bugfix sharing regarding obfs4 malfunctioning

**URL:** https://forum.torproject.org/t/tor-relays-quick-bugfix-sharing-regarding-obfs4-malfunctioning/9116
**Category:** tor-relays
**Created:** [September 7, 2023, 12:12pm UTC](https://forum.torproject.org/t/tor-relays-quick-bugfix-sharing-regarding-obfs4-malfunctioning/9116 "2023-09-07T12:12:36Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![telekobold](https://forum.torproject.org/letter_avatar_proxy/v4/letter/t/c2a13f/32.png) [@telekobold](https://forum.torproject.org/u/telekobold)
#### Post date: [September 7, 2023, 12:12pm UTC](https://forum.torproject.org/t/tor-relays-quick-bugfix-sharing-regarding-obfs4-malfunctioning/9116/1 "2023-09-07T12:12:36Z")

</div>

Hi,

I just want to share some quick bugfix with you (sorry if this is obvious to you or has been written somewhere else).

Suddenly, I got the following error messages on my two bridges running on Debian 11 appearing in the logs (in /var/log/tor/notices.log and in the nyx output) every second until a restart:

\<timestamp\> [warn] Managed proxy "/usr/bin/obfs4proxy" process terminated with status code 65280  
\<timestamp\> [warn] Server managed proxy encountered a method error. (obfs4 listen tcp 0.0.0.0:443: bind: permission denied)  
\<timestamp\> [warn] Managed proxy '/usr/bin/obfs4proxy' was spawned successfully, but it didn't launch any pluggable transport listeners!

When restarting the corresponding bridge, in the startup process the second and the third of the above warning messages again appeared in the logs. So obfs4 was suddenly not usable any more. Port 443 is not blocked in the bridge's firewalls.

A bit research reveled that apparently, an automatic update set the systemd setting "NoNewPrivileges=no" in /lib/systemd/system/tor@default.service and tor@.service [1] back to yes, which caused the above issue. After setting it back and restarting, everything works fine now and instead of the warning messages mentioned above, the following message appears in the log again:

\<timestamp\> [notice] Registered server transport 'obfs4' at '[::]:443'

(Several places recommend to set the obfs4 port to 443 to get around restrictive firewalls, so I didn't want to set it to something else).

Kind regards  
telekobold

[1] [http://xmrhfasfg5suueegrnc4gsgyi2tyclcy5oz7f5drnrodmdtob6t2ioyd.onion/relay/setup/bridge/debian-ubuntu/](http://xmrhfasfg5suueegrnc4gsgyi2tyclcy5oz7f5drnrodmdtob6t2ioyd.onion/relay/setup/bridge/debian-ubuntu/)

> **···**
>
> \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
> tor-relays mailing list  
> tor-relays@lists.torproject.org  
> [https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays](https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays)

---

<div class="post-metadata">

### Author: ![toralf](https://forum.torproject.org/user_avatar/forum.torproject.org/toralf/32/57_2.png) [@toralf](https://forum.torproject.org/u/toralf)
#### Post date: [September 7, 2023, 12:39pm UTC](https://forum.torproject.org/t/tor-relays-quick-bugfix-sharing-regarding-obfs4-malfunctioning/9116/2 "2023-09-07T12:39:15Z")

</div>

You probably need another entry too (grabed from [1]):

[Service]  
NoNewPrivileges=no  
AmbientCapabilities=CAP\_NET\_BIND\_SERVICE

[1] [https://github.com/toralf/tor-relays/blob/main/playbooks/roles/setup-tor/files/override\_tor\_service.conf](https://github.com/toralf/tor-relays/blob/main/playbooks/roles/setup-tor/files/override_tor_service.conf)

> **···**
>
> On 9/7/23 14:12, telekobold wrote:
> 
> > A bit research reveled that apparently, an automatic update set the systemd setting "NoNewPrivileges=no" in /lib/systemd/system/tor@default.service and tor@.service [1] back to yes,
> 
> --  
> Toralf

---

<div class="post-metadata">

### Author: ![dcf](https://forum.torproject.org/letter_avatar_proxy/v4/letter/d/c6cbf5/32.png) [@dcf](https://forum.torproject.org/u/dcf)
#### Post date: [September 7, 2023, 4:54pm UTC](https://forum.torproject.org/t/tor-relays-quick-bugfix-sharing-regarding-obfs4-malfunctioning/9116/3 "2023-09-07T16:54:29Z")

</div>

There's a better way to set `NoNewPrivileges=no` that will not get  
overwritten in an upgrade. Use a systemd override:

> **[obfs4proxy cannot bind to \<1024 port with systemd hardened service unit...](https://gitlab.torproject.org/tpo/core/tor/-/issues/18356)**
>
> Hi, I was running an obfs4proxy Debian Wheezy bridge with such configuration in torrc:

```auto
systemctl edit tor@.service tor@default.service

```

Enter this text in both editors that appear:

```auto
[Service]
NoNewPrivileges=no

```

Then run

```auto
service tor restart

```

This will create files /etc/systemd/system/tor@.service.d/override.conf  
and /etc/systemd/system/tor@default.service.d/override.conf that will  
not be overwritten in an upgrade.

> **···**
>
> On Thu, Sep 07, 2023 at 02:12:36PM +0200, telekobold wrote:
> 
> > I just want to share some quick bugfix with you (sorry if this is obvious to  
> > you or has been written somewhere else).
> > 
> > Suddenly, I got the following error messages on my two bridges running on  
> > Debian 11 appearing in the logs (in /var/log/tor/notices.log and in the nyx  
> > output) every second until a restart:
> > 
> > \<timestamp\> [warn] Managed proxy "/usr/bin/obfs4proxy" process terminated  
> > with status code 65280  
> > \<timestamp\> [warn] Server managed proxy encountered a method error. (obfs4  
> > listen tcp 0.0.0.0:443: bind: permission denied)  
> > \<timestamp\> [warn] Managed proxy '/usr/bin/obfs4proxy' was spawned  
> > successfully, but it didn't launch any pluggable transport listeners!
> > 
> > When restarting the corresponding bridge, in the startup process the second  
> > and the third of the above warning messages again appeared in the logs. So  
> > obfs4 was suddenly not usable any more. Port 443 is not blocked in the  
> > bridge's firewalls.
> > 
> > A bit research reveled that apparently, an automatic update set the systemd  
> > setting "NoNewPrivileges=no" in /lib/systemd/system/tor@default.service and  
> > tor@.service [1] back to yes, which caused the above issue. After setting it  
> > back and restarting, everything works fine now and instead of the warning  
> > messages mentioned above, the following message appears in the log again:
> > 
> > \<timestamp\> [notice] Registered server transport 'obfs4' at '[::]:443'
> 
> \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
> tor-relays mailing list  
> tor-relays@lists.torproject.org  
> [https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays](https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays)
