1. 01 Oct, 2010 2 commits
  2. 22 Sep, 2010 2 commits
    • Avery Pennarun's avatar
      latest options.py from bup, now with tty-width guessing. · 2ef1c6a4
      Avery Pennarun authored
      as of bup commit bup-0.19-2-gce2ace5.
      2ef1c6a4
    • Frederik Deweerdt's avatar
      hostwatch: add missing errno import · b35cfbd0
      Frederik Deweerdt authored
      If the ~/.sshuttle.hosts file does not exist, it triggers the following
      error:
      
             Traceback (most recent call last):
               File "./sshuttle", line 80, in <module>
                 sys.exit(hostwatch.hw_main(extra))
               File "/home/def/p/sshuttle/hostwatch.py", line 246, in hw_main
                 read_host_cache()
               File "/home/def/p/sshuttle/hostwatch.py", line 41, in read_host_cache
                 if e.errno == errno.ENOENT:
             NameError: global name 'errno' is not defined
      
      (This only happened if you run 'sshuttle --hostwatch' from the command line
      directly, without passing it through assembler.py.)
      b35cfbd0
  3. 05 Sep, 2010 1 commit
  4. 04 Sep, 2010 2 commits
  5. 25 Jul, 2010 1 commit
  6. 16 Jul, 2010 1 commit
  7. 17 May, 2010 1 commit
    • Avery Pennarun's avatar
      log(): don't abort if we fail to write to stderr. · 3a25f709
      Avery Pennarun authored
      Failing to write to the log sucks, but not as much as failing to clean up
      just because stderr disappeared.  So let's catch any IOError exception from
      log() and just ignore it.
      
      This should fix a problem reported by Camille Moncelier, which is that
      sshuttle firewall entries stick around if your tty dies strangely (eg. your
      X server aborts for some reason).
      3a25f709
  8. 13 May, 2010 1 commit
  9. 12 May, 2010 2 commits
  10. 11 May, 2010 1 commit
  11. 09 May, 2010 3 commits
  12. 08 May, 2010 5 commits
    • Avery Pennarun's avatar
      Added new --auto-hosts and --seed-hosts options to the client. · 33efa5ac
      Avery Pennarun authored
      Now if you use --auto-hosts (-H), the client will ask the server to spawn a
      hostwatcher to add names.  That, in turn, will send names back to the
      server, which sends them back to the client, which sends them to the
      firewall subprocess, which will write them to /etc/hosts.  Whew!
      
      Only the firewall process can write to /etc/hosts, of course, because only
      he's running as root.
      
      Since the name discovery process is kind of slow, we cache the names in
      ~/.sshuttle.hosts on the remote server.
      
      Right now, most of the names are discovered using nmblookup and smbclient,
      as well as by reading the existing entries in /etc/hosts.  What would really
      be nice would be to query active directory or mdns somehow... but I don't
      really know how those work, so this is what you get for now :)  It's pretty
      neat, at least.
      33efa5ac
    • Avery Pennarun's avatar
      Add 'sshuttle --hostwatch' subcommand. · a2ea5ab4
      Avery Pennarun authored
      This tries to discover local hostnames and prints them to stdout.  Will be
      used by the server for auto-hostname tracking.
      a2ea5ab4
    • Avery Pennarun's avatar
      BSD: "ipfw add %d accept ip from any to any established" · 680941cb
      Avery Pennarun authored
      With this rule, we don't interfere with already-established (or incoming)
      connections to routes that we're about to take over.  This is what
      happens by default in Linux/iptables.
      680941cb
    • Avery Pennarun's avatar
      Add -N (--auto-nets) option for auto-discovering subnets. · 70431950
      Avery Pennarun authored
      Now if you do
      
      	./sshuttle -Nr username@myservername
      
      It'll automatically route the "local" subnets (ie., stuff in the routing
      table) from myservername.  This is (hopefully a reasonable default setting
      for most people.
      70431950
    • Avery Pennarun's avatar
      ssnet: EHOSTUNREACH and ENETUNREACH are non-fatal errors. · 77935bd1
      Avery Pennarun authored
      Reported by Wayne Scott.
      77935bd1
  13. 05 May, 2010 5 commits
    • Avery Pennarun's avatar
      Don't require the remote server to have sshuttle installed. · 8fe3592b
      Avery Pennarun authored
      Instead, grab our source code, send it over the link, and have python eval
      it and then start the server.py main() function.
      
      Strangely, there's now *less* horrible stuff in ssh.py, because we no longer
      have to munge around with the PATH environment variable.  And this
      significantly reduces the setup required to get sshuttle going.
      
      Based on a suggestion from Wayne Scott.
      8fe3592b
    • Avery Pennarun's avatar
      Rename iptables->firewall. · ba19d9c7
      Avery Pennarun authored
      Since we "almost" support ipfw on MacOS (which I guess might mean FreeBSD
      too), the name should be a bit more generic.
      ba19d9c7
    • Avery Pennarun's avatar
      Client "almost" works on MacOS and maybe FreeBSD. · 096bbcc5
      Avery Pennarun authored
      Basic forwarding now works on MacOS, assuming you set up ipfw correctly
      (ha ha).  I wasted a few hours today trying to figure this out, and I'm *so
      very close*, but unfortunately it just didn't work.  Think you can figure it
      out?
      
      Related changes:
      - don't die if iptables is unavailable
      - BSD uses getsockname() instead of SO_ORIGINAL_DST
      - non-blocking connect() returns EISCONN once it's connected
      - you can't setsockopt IP_TTL more than once
      096bbcc5
    • Avery Pennarun's avatar
      7bd0efd5
    • Avery Pennarun's avatar
      ssh.py: allow hostnames of the form hostname:port · 8173925b
      Avery Pennarun authored
      Feature requested by Wayne Scott and Ed Maste.
      8173925b
  14. 04 May, 2010 3 commits
  15. 03 May, 2010 7 commits
    • Avery Pennarun's avatar
      README: update to use real markdown-style headings. · 33a73056
      Avery Pennarun authored
      Oops, got those mixed up with some random other markup format.
      33a73056
    • Avery Pennarun's avatar
      ssh.py: support finding sshuttle in "$HOME/.../sshuttle" · 4a462258
      Avery Pennarun authored
      If you ran sshuttle from /home/apenwarr/sshuttle/sshuttle, we would
      automatically add /home/apenwarr/sshuttle to the PATH before trying to
      execute sshuttle on the remote machine.  That way, if you install it in the
      same place on two computers, the client would still be able to start the
      server.
      
      Someone reported, though, that if they installed the client in
      /home/apenwarr/sshuttle/shuttle, and the server in /root/sshuttle/sshuttle,
      then used "-r root@servername", it wasn't able to find the program.
      
      Similar problems would happen if you're apenwarr at home and averyp at work.
      
      So what we now do is add *two* directories to the PATH:
      /home/apenwarr/sshuttle and $HOME/sshuttle, where $HOME is the value of
      $HOME on the *server*, not the client.  So it'll find it in either place.
      4a462258
    • Avery Pennarun's avatar
      iptables: if client dies before sending GO, just quit. · a5fc93c8
      Avery Pennarun authored
      If the server was having trouble starting, we would print a lot of
      unnecessary stuff from iptables.  We shouldn't even have bothered *starting*
      iptables if the server was dead anyway.
      a5fc93c8
    • Avery Pennarun's avatar
      iptables: die quietly if parent process dies. · ea6bb5c2
      Avery Pennarun authored
      If we can't communicate with the parent process, he's probably died
      unexpectedly; just shut down and don't bother people about it.
      ea6bb5c2
    • Avery Pennarun's avatar
      iptables: try launching with sudo, then su, then directly. · 2c2bea80
      Avery Pennarun authored
      Previous versions depended on having 'sudo' in your PATH.  Now that we can
      feel safe that --iptables will clean up properly when you exit, and it
      doesn't need to authenticate twice, the advantages of sudo aren't strictly
      needed.  Good old 'su' is a reasonable fallback - and everybody has it,
      which is nice.
      
      Unfortunately su doesn't let you redirect stdin, so I had to play a stupid
      fd trick to make it work.
      2c2bea80
    • Avery Pennarun's avatar
      ssnet: throw a nicer-looking Fatal when the mux connection dies. · 7d674e9e
      Avery Pennarun authored
      When it happens, it's probably because the client died and the server hasn't
      noticed yet.
      7d674e9e
    • Avery Pennarun's avatar
      iptables: more resilient startup/cleanup. · a21e8c7a
      Avery Pennarun authored
      Now the sudo iptables subprocess persists for the entire life of sshuttle.
      The benefits of this are:
      
      - no need to authenticate again at shutdown (failure of which could cause us
        to not clean up iptables)
      
      - if the main process dies unexpectedly, iptables still gets cleaned up
      
      - the password prompt can happen *before* starting the ssh/server process,
        which means it'll stand out and the password prompt won't be overwritten.
      a21e8c7a
  16. 02 May, 2010 3 commits