1. 04 May, 2010 1 commit
  2. 03 May, 2010 7 commits
    • Avery Pennarun's avatar
      README: update to use real markdown-style headings. · 33a73056
      Avery Pennarun authored
      Oops, got those mixed up with some random other markup format.
      33a73056
    • Avery Pennarun's avatar
      ssh.py: support finding sshuttle in "$HOME/.../sshuttle" · 4a462258
      Avery Pennarun authored
      If you ran sshuttle from /home/apenwarr/sshuttle/sshuttle, we would
      automatically add /home/apenwarr/sshuttle to the PATH before trying to
      execute sshuttle on the remote machine.  That way, if you install it in the
      same place on two computers, the client would still be able to start the
      server.
      
      Someone reported, though, that if they installed the client in
      /home/apenwarr/sshuttle/shuttle, and the server in /root/sshuttle/sshuttle,
      then used "-r root@servername", it wasn't able to find the program.
      
      Similar problems would happen if you're apenwarr at home and averyp at work.
      
      So what we now do is add *two* directories to the PATH:
      /home/apenwarr/sshuttle and $HOME/sshuttle, where $HOME is the value of
      $HOME on the *server*, not the client.  So it'll find it in either place.
      4a462258
    • Avery Pennarun's avatar
      iptables: if client dies before sending GO, just quit. · a5fc93c8
      Avery Pennarun authored
      If the server was having trouble starting, we would print a lot of
      unnecessary stuff from iptables.  We shouldn't even have bothered *starting*
      iptables if the server was dead anyway.
      a5fc93c8
    • Avery Pennarun's avatar
      iptables: die quietly if parent process dies. · ea6bb5c2
      Avery Pennarun authored
      If we can't communicate with the parent process, he's probably died
      unexpectedly; just shut down and don't bother people about it.
      ea6bb5c2
    • Avery Pennarun's avatar
      iptables: try launching with sudo, then su, then directly. · 2c2bea80
      Avery Pennarun authored
      Previous versions depended on having 'sudo' in your PATH.  Now that we can
      feel safe that --iptables will clean up properly when you exit, and it
      doesn't need to authenticate twice, the advantages of sudo aren't strictly
      needed.  Good old 'su' is a reasonable fallback - and everybody has it,
      which is nice.
      
      Unfortunately su doesn't let you redirect stdin, so I had to play a stupid
      fd trick to make it work.
      2c2bea80
    • Avery Pennarun's avatar
      ssnet: throw a nicer-looking Fatal when the mux connection dies. · 7d674e9e
      Avery Pennarun authored
      When it happens, it's probably because the client died and the server hasn't
      noticed yet.
      7d674e9e
    • Avery Pennarun's avatar
      iptables: more resilient startup/cleanup. · a21e8c7a
      Avery Pennarun authored
      Now the sudo iptables subprocess persists for the entire life of sshuttle.
      The benefits of this are:
      
      - no need to authenticate again at shutdown (failure of which could cause us
        to not clean up iptables)
      
      - if the main process dies unexpectedly, iptables still gets cleaned up
      
      - the password prompt can happen *before* starting the ssh/server process,
        which means it'll stand out and the password prompt won't be overwritten.
      a21e8c7a
  3. 02 May, 2010 26 commits