Compare commits

...
5 Commits
Author SHA1 Message Date
Nikolay Edigaryev 22c92688e5 Don't panic in Drop (#12) 2022-11-19 20:53:30 +04:00
Nikolay Edigaryev e2403f0ea9 Only perform DHCP snooping for frames destined to the VM (#10) 2022-11-10 20:31:18 +04:00
Nikolay Edigaryev 717e6b0f89 Increase the default bootpd(8) lease time from 1 to 10 minutes (#8) 2022-10-21 19:09:18 +04:00
Nikolay Edigaryev 71465f8bff README.md: clarify installation instructions a bit 2022-10-13 18:30:30 +04:00
Nikolay Edigaryev ce129ba5cb Allow host communication (#7)
* Allow communication with host

* Clarify missing root privileges message
2022-08-12 17:50:10 +03:00
5 changed files with 17 additions and 13 deletions
+4 -4
View File
@@ -20,12 +20,12 @@ And assumes that:
## Installing
For proper functioning Softnet binary requires two things:
For proper functioning, Softnet binary requires two things:
* a [SUID-bit](https://en.wikipedia.org/wiki/Setuid#SUID) is set on the binary or [passwordless sudo](https://serverfault.com/questions/160581/how-to-setup-passwordless-sudo-on-linux) is enabled, which effectively gives the binary `root` privileges
* this is needed in order to create [`vmnet.framework`](https://developer.apple.com/documentation/vmnet) interface and perform DHCP-related tweaks
* a [SUID-bit](https://en.wikipedia.org/wiki/Setuid#SUID) to be set on the binary or a [passwordless sudo](https://serverfault.com/questions/160581/how-to-setup-passwordless-sudo-on-linux) to be configured, which effectively gives the binary `root` privileges
* these privileges are needed to create [`vmnet.framework`](https://developer.apple.com/documentation/vmnet) interface and perform DHCP-related system tweaks
* the privileges will be dropped automatically to that of the calling user (or those represented by the `--user` and `--group` command-line arguments) once all of the initialization is completed
* the binary is available in `PATH`
* the binary to be available in `PATH`
* so that the Tart will be able to find it
## Running
+1 -1
View File
@@ -107,7 +107,7 @@ impl Host {
.map_err(|err| Error::VmnetFailed { source: err })?;
// Now let the callback finish
self.callback_can_continue_tx.send(()).unwrap();
let _ = self.callback_can_continue_tx.send(());
self.interface
.finalize()
+3 -1
View File
@@ -12,7 +12,9 @@ impl Proxy {
// Snoop bootpd(8) replies from the host to
// figure out the IP assigned to the VM
self.snoop(frame);
if frame.dst_addr() == self.vm_mac_address {
self.snoop(frame);
}
self.vm
.write(frame.as_ref())
+7 -5
View File
@@ -68,6 +68,11 @@ impl Proxy {
}
}
// Allow communication with host
if ipv4_pkt.dst_addr() == self.host.gateway_ip {
return Some(());
}
if ipv4_pkt.protocol() == IpProtocol::Udp {
let udp_pkt = UdpPacket::new_checked(ipv4_pkt.payload()).ok()?;
@@ -77,11 +82,8 @@ impl Proxy {
return Some(());
}
// Allow DHCP communication with the bootpd(8) on host
let allowed_dhcp_target =
ipv4_pkt.dst_addr().is_broadcast() || ipv4_pkt.dst_addr() == self.host.gateway_ip;
if udp_pkt.is_dhcp_request() && allowed_dhcp_target {
// Allow DHCP communication with the bootpd(8) on host via broadcast address
if udp_pkt.is_dhcp_request() && ipv4_pkt.dst_addr().is_broadcast() {
return Some(());
}
}
+2 -2
View File
@@ -27,7 +27,7 @@ struct Args {
#[clap(
long,
help = "set bootpd(8) lease time to this value (in seconds) before starting the VM",
default_value_t = 60
default_value_t = 600
)]
bootpd_lease_time: u32,
@@ -92,7 +92,7 @@ fn try_main() -> Result<(), Box<dyn std::error::Error>> {
.exec();
}
return Err("root privileges are required to run".into());
return Err("root privileges are required to run and passwordless sudo was not available".into());
}
// Set bootpd(8) min/max lease time while still having the root privileges