mirror of
https://github.com/cirruslabs/softnet.git
synced 2026-10-01 12:32:05 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8359992a08 | ||
|
|
147c051b0e | ||
|
|
6456ed7228 | ||
|
|
56808c591f | ||
|
|
eba21ed33e |
Generated
+876
-548
File diff suppressed because it is too large
Load Diff
+18
-18
@@ -12,21 +12,21 @@ inherits = "release"
|
||||
debug = true
|
||||
|
||||
[dependencies]
|
||||
smoltcp = "0.8.1"
|
||||
libc = "0.2.126"
|
||||
polling = { git = "https://github.com/smol-rs/polling.git" }
|
||||
dhcproto = "0.7.0"
|
||||
vmnet = "0.1.1"
|
||||
clap = { version = "4.5.2", features = ["derive"] }
|
||||
mac_address = "1.1.3"
|
||||
privdrop = "0.5.2"
|
||||
anyhow = { version = "1.0.66", features = ["backtrace"] }
|
||||
ip_network = "0.4.1"
|
||||
uzers = "0.11.3"
|
||||
system-configuration = "0.5.0"
|
||||
num_enum = "0.5.7"
|
||||
sentry = { version = "0.29.1", features = ["debug-images"] }
|
||||
sentry-anyhow = { version = "0.29.1", features = ["backtrace"] }
|
||||
nix = "0.26.2"
|
||||
prefix-trie = "0.3.0"
|
||||
ipnet = "2.9.0"
|
||||
smoltcp = "0"
|
||||
libc = "0"
|
||||
polling = "3"
|
||||
dhcproto = "0"
|
||||
vmnet = "0"
|
||||
clap = { version = "4", features = ["derive"] }
|
||||
mac_address = "1"
|
||||
privdrop = "0"
|
||||
anyhow = { version = "1", features = ["backtrace"] }
|
||||
ip_network = "0"
|
||||
uzers = "0"
|
||||
system-configuration = "0"
|
||||
num_enum = "0"
|
||||
sentry = { version = "0", features = ["debug-images"] }
|
||||
sentry-anyhow = { version = "0", features = ["backtrace"] }
|
||||
nix = { version = "0", features = ["signal"] }
|
||||
prefix-trie = "0"
|
||||
ipnet = "2"
|
||||
|
||||
@@ -8,9 +8,9 @@ Please check out [this blog post](https://cirrus-ci.org/blog/2022/07/07/isolatin
|
||||
Softnet solves two problems:
|
||||
|
||||
1. VM network isolation
|
||||
* [`VZNATNetworkDeviceAttachment`](https://developer.apple.com/documentation/virtualization/vznatnetworkdeviceattachment) (the default networking in Tart) enables [vmnet's bridge isolation](https://developer.apple.com/documentation/vmnet/vmnet_enable_isolation_key) by default and prevents cross-VM traffic, however it's still possible for any VM to spoof the host's ARP-table and capture other VMs traffic
|
||||
* [`VZNATNetworkDeviceAttachment`](https://developer.apple.com/documentation/virtualization/vznatnetworkdeviceattachment) (the default networking in Tart) enables [vmnet's bridge isolation](https://developer.apple.com/documentation/vmnet/vmnet_enable_isolation_key) by default and prevents cross-VM traffic, however it's still possible for any VM to spoof the host's ARP-table and capture other VMs traffic by using tools that enable conducting the [ARP spoofing attacks](https://en.wikipedia.org/wiki/ARP_spoofing) (e.g. [arpspoof](https://www.monkey.org/~dugsong/dsniff/), [arpoison](http://www.arpoison.net/) and so on)
|
||||
2. DHCP exhaustion
|
||||
* macOS built-in DHCP-server allocates a `/24` subnet with 86400 seconds lease time by default, which only allows for ~253 VMs a day (or 1 VM every ~6 minutes) to be spawned without causing a denial-of-service, which is pretty limiting for CI services like Cirrus CI
|
||||
* macOS built-in DHCP-server allocates a `/24` subnet with 86400 seconds lease time by default, which only allows for ~253 VMs a day (or 1 VM every ~6 minutes) to be spawned without causing a denial-of-service, which is pretty limiting for CI services like Cirrus CI
|
||||
|
||||
And assumes that:
|
||||
|
||||
|
||||
+2
-2
@@ -31,7 +31,7 @@ pub struct Host {
|
||||
}
|
||||
|
||||
impl Host {
|
||||
pub fn new(vm_net_type: NetType) -> Result<Host> {
|
||||
pub fn new(vm_net_type: NetType, enable_isolation: bool) -> Result<Host> {
|
||||
// Initialize a vmnet.framework NAT or Host interface with isolation enabled
|
||||
let mut interface = vmnet::Interface::new(
|
||||
match vm_net_type {
|
||||
@@ -39,7 +39,7 @@ impl Host {
|
||||
NetType::Host => Mode::Host(Default::default()),
|
||||
},
|
||||
Options {
|
||||
enable_isolation: Some(true),
|
||||
enable_isolation: Some(enable_isolation),
|
||||
..Default::default()
|
||||
},
|
||||
)
|
||||
|
||||
+18
-16
@@ -2,14 +2,15 @@ use anyhow::Result;
|
||||
use num_enum::IntoPrimitive;
|
||||
use polling::os::kqueue::PollerKqueueExt;
|
||||
use polling::PollMode;
|
||||
use std::os::fd::{AsRawFd, BorrowedFd};
|
||||
use std::os::unix::io::RawFd;
|
||||
use std::time::Duration;
|
||||
|
||||
pub struct Poller {
|
||||
pub struct Poller<'poller> {
|
||||
poller: polling::Poller,
|
||||
events: Vec<polling::Event>,
|
||||
vm_fd: RawFd,
|
||||
host_fd: RawFd,
|
||||
events: polling::Events,
|
||||
vm_fd: BorrowedFd<'poller>,
|
||||
host_fd: BorrowedFd<'poller>,
|
||||
}
|
||||
|
||||
#[derive(IntoPrimitive)]
|
||||
@@ -20,22 +21,25 @@ enum EventKey {
|
||||
Interrupt,
|
||||
}
|
||||
|
||||
impl Poller {
|
||||
pub fn new(vm_fd: RawFd, host_fd: RawFd) -> Result<Poller> {
|
||||
impl Poller<'_> {
|
||||
pub fn new<'poller>(vm_fd: RawFd, host_fd: RawFd) -> Result<Poller<'poller>> {
|
||||
let poller = polling::Poller::new()?;
|
||||
|
||||
Ok(Poller {
|
||||
poller,
|
||||
events: Vec::new(),
|
||||
vm_fd,
|
||||
host_fd,
|
||||
events: polling::Events::new(),
|
||||
vm_fd: unsafe { BorrowedFd::borrow_raw(vm_fd) },
|
||||
host_fd: unsafe { BorrowedFd::borrow_raw(host_fd) },
|
||||
})
|
||||
}
|
||||
|
||||
pub fn arm(&self) -> Result<()> {
|
||||
self.poller.add(self.vm_fd as RawFd, self.vm_interest())?;
|
||||
self.poller
|
||||
.add(self.host_fd as RawFd, self.host_interest())?;
|
||||
unsafe {
|
||||
self.poller
|
||||
.add(self.vm_fd.as_raw_fd(), self.vm_interest())?;
|
||||
self.poller
|
||||
.add(self.host_fd.as_raw_fd(), self.host_interest())?;
|
||||
}
|
||||
|
||||
let interrupt_signal = polling::os::kqueue::Signal(libc::SIGINT);
|
||||
self.poller
|
||||
@@ -52,10 +56,8 @@ impl Poller {
|
||||
pub fn rearm(&mut self) -> Result<()> {
|
||||
self.events.clear();
|
||||
|
||||
self.poller
|
||||
.modify(self.vm_fd as RawFd, self.vm_interest())?;
|
||||
self.poller
|
||||
.modify(self.host_fd as RawFd, self.host_interest())?;
|
||||
self.poller.modify(self.vm_fd, self.vm_interest())?;
|
||||
self.poller.modify(self.host_fd, self.host_interest())?;
|
||||
|
||||
let interrupt_signal = polling::os::kqueue::Signal(libc::SIGINT);
|
||||
self.poller.modify_filter(
|
||||
|
||||
+2
-2
@@ -3,7 +3,7 @@ use crate::proxy::Proxy;
|
||||
use anyhow::{Context, Result};
|
||||
use smoltcp::wire::{EthernetFrame, EthernetProtocol, Ipv4Packet, UdpPacket};
|
||||
|
||||
impl Proxy {
|
||||
impl Proxy<'_> {
|
||||
pub(crate) fn process_frame_from_host(&mut self, frame: &EthernetFrame<&[u8]>) -> Result<()> {
|
||||
if self.allowed_from_host(frame).is_none() {
|
||||
// Block packet by not forwarding it to the VM
|
||||
@@ -58,7 +58,7 @@ impl Proxy {
|
||||
return;
|
||||
}
|
||||
|
||||
if ipv4_pkt.protocol() != smoltcp::wire::IpProtocol::Udp {
|
||||
if ipv4_pkt.next_header() != smoltcp::wire::IpProtocol::Udp {
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
+7
-7
@@ -10,30 +10,30 @@ use crate::vm::VM;
|
||||
use anyhow::Result;
|
||||
use ipnet::Ipv4Net;
|
||||
use mac_address::MacAddress;
|
||||
use prefix_trie::PrefixSet;
|
||||
use prefix_trie::{Prefix, PrefixSet};
|
||||
use smoltcp::wire::EthernetFrame;
|
||||
use std::io::ErrorKind;
|
||||
use std::os::unix::io::{AsRawFd, RawFd};
|
||||
|
||||
pub struct Proxy {
|
||||
pub struct Proxy<'proxy> {
|
||||
vm: VM,
|
||||
host: Host,
|
||||
poller: Poller,
|
||||
poller: Poller<'proxy>,
|
||||
vm_mac_address: smoltcp::wire::EthernetAddress,
|
||||
dhcp_snooper: DhcpSnooper,
|
||||
allow: PrefixSet<Ipv4Net>,
|
||||
enobufs_encountered: bool,
|
||||
}
|
||||
|
||||
impl Proxy {
|
||||
pub fn new(
|
||||
impl Proxy<'_> {
|
||||
pub fn new<'proxy>(
|
||||
vm_fd: RawFd,
|
||||
vm_mac_address: MacAddress,
|
||||
vm_net_type: NetType,
|
||||
allow: PrefixSet<Ipv4Net>,
|
||||
) -> Result<Proxy> {
|
||||
) -> Result<Proxy<'proxy>> {
|
||||
let vm = VM::new(vm_fd)?;
|
||||
let host = Host::new(vm_net_type)?;
|
||||
let host = Host::new(vm_net_type, !allow.contains(&Ipv4Net::zero()))?;
|
||||
let poller = Poller::new(vm.as_raw_fd(), host.as_raw_fd())?;
|
||||
|
||||
Ok(Proxy {
|
||||
|
||||
+7
-3
@@ -8,7 +8,7 @@ use smoltcp::wire::{
|
||||
};
|
||||
use std::net::Ipv4Addr;
|
||||
|
||||
impl Proxy {
|
||||
impl Proxy<'_> {
|
||||
pub(crate) fn process_frame_from_vm(&mut self, frame: EthernetFrame<&[u8]>) -> Result<()> {
|
||||
if self.allowed_from_vm(&frame).is_none() {
|
||||
// Block packet by not forwarding it to the host
|
||||
@@ -72,7 +72,11 @@ impl Proxy {
|
||||
// Also allow all traffic to the user-specified CIDRs
|
||||
let dst_net = Ipv4Net::from(dst_addr);
|
||||
|
||||
if self.allow.get_spm(&dst_net).is_some() {
|
||||
// Use get_lpm() instead of get_spm() to work around prefix-trie
|
||||
// not handling prefixes like 0.0.0.0/0 correctly[1]
|
||||
//
|
||||
// [1]: https://github.com/tiborschneider/prefix-trie/issues/8
|
||||
if self.allow.get_lpm(&dst_net).is_some() {
|
||||
return Some(());
|
||||
}
|
||||
}
|
||||
@@ -82,7 +86,7 @@ impl Proxy {
|
||||
return Some(());
|
||||
}
|
||||
|
||||
if ipv4_pkt.protocol() == IpProtocol::Udp {
|
||||
if ipv4_pkt.next_header() == IpProtocol::Udp {
|
||||
let udp_pkt = UdpPacket::new_checked(ipv4_pkt.payload()).ok()?;
|
||||
|
||||
// Allow DNS communication with the DNS-servers provided by DHCP
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
nightly
|
||||
@@ -0,0 +1,2 @@
|
||||
[toolchain]
|
||||
channel = "nightly"
|
||||
Reference in New Issue
Block a user