mirror of
https://github.com/cirruslabs/softnet.git
synced 2026-09-30 20:11:16 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
22c92688e5 | ||
|
|
e2403f0ea9 | ||
|
|
717e6b0f89 | ||
|
|
71465f8bff | ||
|
|
ce129ba5cb |
@@ -20,12 +20,12 @@ And assumes that:
|
||||
|
||||
## Installing
|
||||
|
||||
For proper functioning Softnet binary requires two things:
|
||||
For proper functioning, Softnet binary requires two things:
|
||||
|
||||
* a [SUID-bit](https://en.wikipedia.org/wiki/Setuid#SUID) is set on the binary or [passwordless sudo](https://serverfault.com/questions/160581/how-to-setup-passwordless-sudo-on-linux) is enabled, which effectively gives the binary `root` privileges
|
||||
* this is needed in order to create [`vmnet.framework`](https://developer.apple.com/documentation/vmnet) interface and perform DHCP-related tweaks
|
||||
* a [SUID-bit](https://en.wikipedia.org/wiki/Setuid#SUID) to be set on the binary or a [passwordless sudo](https://serverfault.com/questions/160581/how-to-setup-passwordless-sudo-on-linux) to be configured, which effectively gives the binary `root` privileges
|
||||
* these privileges are needed to create [`vmnet.framework`](https://developer.apple.com/documentation/vmnet) interface and perform DHCP-related system tweaks
|
||||
* the privileges will be dropped automatically to that of the calling user (or those represented by the `--user` and `--group` command-line arguments) once all of the initialization is completed
|
||||
* the binary is available in `PATH`
|
||||
* the binary to be available in `PATH`
|
||||
* so that the Tart will be able to find it
|
||||
|
||||
## Running
|
||||
|
||||
+1
-1
@@ -107,7 +107,7 @@ impl Host {
|
||||
.map_err(|err| Error::VmnetFailed { source: err })?;
|
||||
|
||||
// Now let the callback finish
|
||||
self.callback_can_continue_tx.send(()).unwrap();
|
||||
let _ = self.callback_can_continue_tx.send(());
|
||||
|
||||
self.interface
|
||||
.finalize()
|
||||
|
||||
+3
-1
@@ -12,7 +12,9 @@ impl Proxy {
|
||||
|
||||
// Snoop bootpd(8) replies from the host to
|
||||
// figure out the IP assigned to the VM
|
||||
self.snoop(frame);
|
||||
if frame.dst_addr() == self.vm_mac_address {
|
||||
self.snoop(frame);
|
||||
}
|
||||
|
||||
self.vm
|
||||
.write(frame.as_ref())
|
||||
|
||||
+7
-5
@@ -68,6 +68,11 @@ impl Proxy {
|
||||
}
|
||||
}
|
||||
|
||||
// Allow communication with host
|
||||
if ipv4_pkt.dst_addr() == self.host.gateway_ip {
|
||||
return Some(());
|
||||
}
|
||||
|
||||
if ipv4_pkt.protocol() == IpProtocol::Udp {
|
||||
let udp_pkt = UdpPacket::new_checked(ipv4_pkt.payload()).ok()?;
|
||||
|
||||
@@ -77,11 +82,8 @@ impl Proxy {
|
||||
return Some(());
|
||||
}
|
||||
|
||||
// Allow DHCP communication with the bootpd(8) on host
|
||||
let allowed_dhcp_target =
|
||||
ipv4_pkt.dst_addr().is_broadcast() || ipv4_pkt.dst_addr() == self.host.gateway_ip;
|
||||
|
||||
if udp_pkt.is_dhcp_request() && allowed_dhcp_target {
|
||||
// Allow DHCP communication with the bootpd(8) on host via broadcast address
|
||||
if udp_pkt.is_dhcp_request() && ipv4_pkt.dst_addr().is_broadcast() {
|
||||
return Some(());
|
||||
}
|
||||
}
|
||||
|
||||
+2
-2
@@ -27,7 +27,7 @@ struct Args {
|
||||
#[clap(
|
||||
long,
|
||||
help = "set bootpd(8) lease time to this value (in seconds) before starting the VM",
|
||||
default_value_t = 60
|
||||
default_value_t = 600
|
||||
)]
|
||||
bootpd_lease_time: u32,
|
||||
|
||||
@@ -92,7 +92,7 @@ fn try_main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
.exec();
|
||||
}
|
||||
|
||||
return Err("root privileges are required to run".into());
|
||||
return Err("root privileges are required to run and passwordless sudo was not available".into());
|
||||
}
|
||||
|
||||
// Set bootpd(8) min/max lease time while still having the root privileges
|
||||
|
||||
Reference in New Issue
Block a user