Darry
18f5a3338e
Require BOOTP chaddr match for host→VM DHCP responses ( #192 )
...
* Require BOOTP chaddr match for host→VM DHCP responses
Mirror #191 request-path identity checks: admit/forward DHCP
BootReplies only when chaddr matches the VM MAC, so foreign
client replies are not written into the guest fd.
Co-authored-by: Cursor <cursoragent@cursor.com>
* $ cargo fmt
---------
Co-authored-by: genforAI <genforAI@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Nikolay Edigaryev <edi@openai.com>
2026-08-14 13:41:41 +01:00
Yibo Zhuang
0c4327dd71
Exit Softnet when its VM socket disconnects ( #193 )
...
Check the VM socket on poll timeouts because macOS kqueue does not
report Unix datagram peer disconnects. This prevents orphaned
Softnet processes from blocking VM cleanup.
2026-08-14 13:36:32 +01:00
edi-oai
28bb29df4a
Validate DHCP client identity and source address ( #191 )
...
* Validate DHCP client identity and source address
* Use CFBoolean instead of CFNumber for dhcp_ignore_client_identifier
* Serialize bootpd preference updates
2026-08-10 22:10:20 -04:00
edi-oai
cdc2a508aa
Introduce stateful "in TARGET" and "out TARGET" rules ( #188 )
2026-08-03 11:33:22 -04:00
edi-oai
54b419fd18
dhcp_snooper: accept DHCP replies destined to broadcast addresses ( #186 )
2026-07-30 18:27:12 +01:00
dependabot[bot]
c709387d71
Bump the all-updates group across 1 directory with 11 updates ( #183 )
...
* Bump the all-updates group across 1 directory with 11 updates
Bumps the all-updates group with 11 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [libc](https://github.com/rust-lang/libc ) | `0.2.186` | `0.2.188` |
| [dhcproto](https://github.com/bluecatengineering/dhcproto ) | ``eece41c`` | ``60719e5`` |
| [clap](https://github.com/clap-rs/clap ) | `4.6.1` | `4.6.3` |
| [anyhow](https://github.com/dtolnay/anyhow ) | `1.0.102` | `1.0.104` |
| [sentry](https://github.com/getsentry/sentry-rust ) | `0.48.1` | `0.48.5` |
| [sentry-anyhow](https://github.com/getsentry/sentry-rust ) | `0.48.1` | `0.48.5` |
| [nix](https://github.com/nix-rust/nix ) | `0.31.2` | `0.31.3` |
| [prefix-trie](https://github.com/tiborschneider/prefix-trie ) | `0.8.3` | `0.9.2` |
| [log](https://github.com/rust-lang/log ) | `0.4.29` | `0.4.33` |
| [serial_test](https://github.com/palfrey/serial_test ) | `3.4.0` | `3.5.0` |
| [serde](https://github.com/serde-rs/serde ) | `1.0.228` | `1.0.229` |
Updates `libc` from 0.2.186 to 0.2.188
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.188/CHANGELOG.md )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.186...0.2.188 )
Updates `dhcproto` from `eece41c` to `60719e5`
- [Release notes](https://github.com/bluecatengineering/dhcproto/releases )
- [Commits](eece41c9a1...60719e5df1 )
Updates `clap` from 4.6.1 to 4.6.3
- [Release notes](https://github.com/clap-rs/clap/releases )
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md )
- [Commits](https://github.com/clap-rs/clap/compare/clap_complete-v4.6.1...clap_complete-v4.6.3 )
Updates `anyhow` from 1.0.102 to 1.0.104
- [Release notes](https://github.com/dtolnay/anyhow/releases )
- [Commits](https://github.com/dtolnay/anyhow/compare/1.0.102...1.0.104 )
Updates `sentry` from 0.48.1 to 0.48.5
- [Release notes](https://github.com/getsentry/sentry-rust/releases )
- [Changelog](https://github.com/getsentry/sentry-rust/blob/master/CHANGELOG.md )
- [Commits](https://github.com/getsentry/sentry-rust/compare/0.48.1...0.48.5 )
Updates `sentry-anyhow` from 0.48.1 to 0.48.5
- [Release notes](https://github.com/getsentry/sentry-rust/releases )
- [Changelog](https://github.com/getsentry/sentry-rust/blob/master/CHANGELOG.md )
- [Commits](https://github.com/getsentry/sentry-rust/compare/0.48.1...0.48.5 )
Updates `nix` from 0.31.2 to 0.31.3
- [Changelog](https://github.com/nix-rust/nix/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nix-rust/nix/compare/v0.31.2...v0.31.3 )
Updates `prefix-trie` from 0.8.3 to 0.9.2
- [Release notes](https://github.com/tiborschneider/prefix-trie/releases )
- [Commits](https://github.com/tiborschneider/prefix-trie/commits )
Updates `log` from 0.4.29 to 0.4.33
- [Release notes](https://github.com/rust-lang/log/releases )
- [Changelog](https://github.com/rust-lang/log/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rust-lang/log/compare/0.4.29...0.4.33 )
Updates `serial_test` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/palfrey/serial_test/releases )
- [Commits](https://github.com/palfrey/serial_test/compare/v3.4.0...v3.5.0 )
Updates `serde` from 1.0.228 to 1.0.229
- [Release notes](https://github.com/serde-rs/serde/releases )
- [Commits](https://github.com/serde-rs/serde/compare/v1.0.228...v1.0.229 )
---
updated-dependencies:
- dependency-name: libc
dependency-version: 0.2.188
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: dhcproto
dependency-version: 60719e5df11359b12bf74e743b3c7e0831351c2d
dependency-type: direct:production
dependency-group: all-updates
- dependency-name: clap
dependency-version: 4.6.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: anyhow
dependency-version: 1.0.104
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: sentry
dependency-version: 0.48.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: sentry-anyhow
dependency-version: 0.48.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: nix
dependency-version: 0.31.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: prefix-trie
dependency-version: 0.9.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: all-updates
- dependency-name: log
dependency-version: 0.4.33
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
- dependency-name: serial_test
dependency-version: 3.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: all-updates
- dependency-name: serde
dependency-version: 1.0.229
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: all-updates
...
Signed-off-by: dependabot[bot] <support@github.com>
* prefix_trie: Ipv4Net::zero() → Ipv4Net::default()
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nikolay Edigaryev <edi@openai.com>
2026-07-21 21:44:44 +01:00
Fedor Kororkov
08200b7a09
Add dynamic Softnet policy control ( #181 )
...
* Add dynamic Softnet policy control
* Simplify Softnet policy RPC methods
* Use jsonrpsee types for Softnet policy RPC
* Reject superseded Softnet policy revisions
* Apply Softnet policy updates only after enqueue
* Flush final Softnet response after input EOF
* Signal EOF when disabling Softnet control
* Normalize Softnet default-route isolation
* Keep policy rules on Proxy (#182 )
* Simplify Softnet policy protocol
* Bound pipelined Softnet policy responses
* Keep Softnet port forwarding active on control wakes
---------
Co-authored-by: edi-oai <edi@openai.com>
2026-07-21 21:30:06 +01:00
Minh Vu
5d6b4b9d0c
Validate VM file descriptors before ownership transfer ( #177 )
...
* Validate VM file descriptors before ownership transfer
* Handle unnamed macOS Unix sockets
2026-07-16 10:47:53 -04:00
Minh Vu
2d351db2df
Validate VM ARP packets before reading addresses ( #175 )
2026-07-08 09:45:25 +01:00
Minh Vu
4461df5b7b
Tighten DHCP port matching ( #174 )
2026-07-08 00:17:45 +01:00
Nikolay Edigaryev
df84a30016
--allow: support "@host" syntax ( #160 )
...
* --allow: support "@host" syntax
To make communication with the guest VM possible
when using --block=0.0.0.0/0.
* Use "@-alias" wording instead of "@host"
2026-05-15 16:06:03 +02:00
Nikolay Edigaryev
173f7832b3
DHCP snooper: use coarse time to avoid clock_gettime() overhead ( #137 )
...
* DHCP snooper: use coarse time to avoid clock_gettime() overhead
* Introduce uncertainty duration and subtract it from total lease time
* Update coarse time after we've performed the waiting
* Use coarsetime::Updater to update time even when deep inside event loop
* No need for manual coarsetime::Instant::update() anymore
* Ensure that coarsetime::Updater is stopped on Proxy::shutdown()
* Revert "Ensure that coarsetime::Updater is stopped on Proxy::shutdown()"
This reverts commit de255f4240 .
* Revert "Use coarsetime::Updater to update time even when deep inside event loop"
This reverts commit 6a95272dcf .
* Revert "No need for manual coarsetime::Instant::update() anymore"
This reverts commit 9ffa829add .
* Update coarse time for the DHCP snooper after reading packet(s)
2026-01-14 21:16:19 +01:00
Nikolay Edigaryev
7dc5992b55
Perform batched reads from host to improve efficiency ( #128 )
...
* Perform batched reads from host to improve efficiency
* CI: don't test on macOS Sonoma
2025-10-28 16:48:05 +04:00
Nikolay Edigaryev
431ae9bbc9
Introduce --block in addition to --allow ( #126 )
2025-10-21 17:14:28 +04:00
Nikolay Edigaryev
4fa4fb1bda
Avoid using one-shot triggered events ( #102 )
2025-04-21 18:16:09 +04:00
Peter A.
570f02e8d5
PartialEq for ExposedPort ( #90 )
2025-03-05 15:13:07 +04:00
Nikolay Edigaryev
8519fa2f86
Support TCP port exposure via "--expose" command-line argument ( #70 )
2025-01-09 16:50:39 +04:00
dependabot[bot]
762868a8eb
Bump smoltcp from 0.11.0 to 0.12.0 ( #62 )
...
* Bump smoltcp from 0.11.0 to 0.12.0
Bumps [smoltcp](https://github.com/smoltcp-rs/smoltcp ) from 0.11.0 to 0.12.0.
- [Release notes](https://github.com/smoltcp-rs/smoltcp/releases )
- [Changelog](https://github.com/smoltcp-rs/smoltcp/blob/main/CHANGELOG.md )
- [Commits](https://github.com/smoltcp-rs/smoltcp/compare/v0.11.0...v0.12.0 )
---
updated-dependencies:
- dependency-name: smoltcp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
* smoltcp moved to core::net types for IP addresses
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2024-12-05 00:15:21 +04:00
Nikolay Edigaryev
147c051b0e
Disable isolation when `--allow=0.0.0.0/0` is specified ( #39 )
...
* Disable isolation when --allow=0.0.0.0/0 is specified
* Upgrade & upgrade the dependencies
2024-07-02 15:36:07 +04:00
Nikolay Edigaryev
867679446e
Ignore socketpair(2) errors when sending ( #36 )
2024-03-25 12:37:53 -04:00
Nikolay Edigaryev
4a13c5922b
Prevent multiple --allow flags ( #35 )
...
* Prevent multiple --allow flags
* --allow: better value name instead of just <ALLOW>
2024-03-11 23:02:59 +04:00
Nikolay Edigaryev
a92f4e0c99
Introduce --allow command-line argument to allow traffic to CIDRs ( #34 )
2024-03-11 22:07:39 +04:00
Sergei Parshev
0a92c290be
Added a way to enable host-only networking through tart using --net-host ( #32 )
...
* Added a way to enable host-only networking through tart using SOFTNET_NET_TYPE=host
* Removed env variable and moved to Enum instead of str
* Fixed defaults & restricted publicity of host
* Fixed usage of NetType
2024-03-01 11:25:19 -05:00
Nikolay Edigaryev
d7699e95a9
Support graceful termination via SIGINT ( #23 )
...
* Support graceful termination via SIGINT
* $ cargo fmt
* Explain why we need to ignore the SIGINT
2023-03-16 18:38:03 +04:00
Nikolay Edigaryev
d635751948
Capture ENOBUFS message into Sentry only once ( #19 )
2022-12-24 11:36:42 +04:00
Nikolay Edigaryev
59cd9098e0
Ignore ENOBUFS when writing to VM's socket ( #18 )
...
* Ignore ENOBUFS when writing to VM's socket
* Hint the into() target type to the compiler to fix the build error
* Fix Clippy warnings
2022-12-15 00:15:19 +04:00
Nikolay Edigaryev
11910d8540
Sentry integration ( #13 )
...
* Sentry integration
* Introduce a more generic CIRRUS_SENTRY_TAGS
* Revert switching to nightly toolchain
2022-12-12 21:33:45 +04:00
Nikolay Edigaryev
22c92688e5
Don't panic in Drop ( #12 )
2022-11-19 20:53:30 +04:00
Nikolay Edigaryev
e2403f0ea9
Only perform DHCP snooping for frames destined to the VM ( #10 )
2022-11-10 20:31:18 +04:00
Nikolay Edigaryev
ce129ba5cb
Allow host communication ( #7 )
...
* Allow communication with host
* Clarify missing root privileges message
2022-08-12 17:50:10 +03:00
Nikolay Edigaryev
226a7e6c86
Initial revision of Softnet, a software networking for Tart
2022-06-10 16:53:03 +03:00