1. 25 Oct, 2020 1 commit
  2. 23 Oct, 2020 1 commit
    • Scott Kuhl's avatar
      nft IPv6 documentation (and other minor doc updates) · c02b93e7
      Scott Kuhl authored
      Update docs to indicate that IPv6 is supported with the nft method.
      
      - Adds nft into the requirements.rst file.
      
      - Update description of what happens when a hostname is used in a
        subnet.
      
      - Add ipfw to list of methods.
      
      - Indicate that --auto-nets does not work with IPv6. Previously this
        was only mentioned in tproxy.rst
      
      - Clarify that we try to use "python3" on the server before trying
        "python".
      c02b93e7
  3. 22 Oct, 2020 2 commits
    • Scott Kuhl's avatar
      IPv6 support in nft method. · 6d86e44f
      Scott Kuhl authored
      This works for me but needs testing by others. Remember to specify a
      ::0/0 subnet or similar to route IPv6 through sshuttle.
      
      I'm adding this to nft before nat since it is not sshuttle's default
      method on Linux. Documentation updates may be required too.
      
      This patch uses the ipaddress module, but that appears to be included
      since Python 3.3.
      6d86e44f
    • Brian May's avatar
      Merge pull request #549 from skuhl/nft-nat-update · ebf87d8f
      Brian May authored
      Make nat and nft rules consistent; improve rule ordering.
      ebf87d8f
  4. 21 Oct, 2020 6 commits
    • Scott Kuhl's avatar
      Make nat and nft rules consistent; improve rule ordering. · bc24ed35
      Scott Kuhl authored
      First, check if TTL indicates we should ignore packet (instead of
      checking in multiple rules later). Also, nft method didn't do this at
      all. Now, nft matches the behavior of nat.
      
      Second, forward DNS traffic (we may need to intercept traffic to
      localhost if a DNS server is running on localhost).
      
      Third, ignore any local traffic packets. (Previously, we ignored local
      traffic except DNS and then had the DNS rules). The nft method didn't
      do this previously at all. It now matches the behavior of nat.
      
      Lastly, list the subnets to redirect and/or exclude. This step is left
      unchanged. Excluding the local port that we are listening on is
      redundant with the third step, but should cause no harm.
      
      In summary, this ordering simplifies the rules in nat and eliminates
      differences that previously existed between nat and nft.
      bc24ed35
    • Brian May's avatar
      Merge pull request #544 from skuhl/fix-no-remote · ac3ccb76
      Brian May authored
      Allow no remote to work.
      ac3ccb76
    • Brian May's avatar
      Merge pull request #548 from skuhl/stdout-cleanup · 1f3c74a1
      Brian May authored
      Make prefixes in verbose output more consistent.
      1f3c74a1
    • Scott Kuhl's avatar
      Add missing space in client ssh error message · 512a3a8d
      Scott Kuhl authored
      512a3a8d
    • Scott Kuhl's avatar
      whitespace cleanup · 4deee45b
      Scott Kuhl authored
      4deee45b
    • Scott Kuhl's avatar
      Make prefixes in verbose output more consistent. · 7cb30b78
      Scott Kuhl authored
      Use 'c' prefix for client, 's' prefix for server, and 'fw' prefix for
      firewall messages. The 'c' and 's' prefixes were used sometimes but
      not consistently. The firewall printed messages prefixed with
      "firewall manager:" or "firewall:" or ">>" previously.
      
      This patch also fixes a couple of print() calls that should have been
      debug1()---a bug introduced in a recent commit.
      7cb30b78
  5. 20 Oct, 2020 2 commits
  6. 19 Oct, 2020 7 commits
    • Nicolas Stalder's avatar
      Document -s/--subnets option in man page · 9d704b35
      Nicolas Stalder authored
      9d704b35
    • Brian May's avatar
      Merge pull request #545 from skuhl/avoid-touching-etc-hosts · a266e7a8
      Brian May authored
      Only write /etc/hosts when necessary.
      a266e7a8
    • Scott Kuhl's avatar
      Only write /etc/hosts when necessary. · e1106a33
      Scott Kuhl authored
      Without this patch, sshuttle 'restores' /etc/hosts even if it didn't
      make any modifications to it. This can be confirmed by running without
      --auto-hosts and confirming that the modification time of /etc/hosts
      is unchanged while sshuttle is running, but is updated when sshuttle
      exits (and a debug2() message is printed indicating the file is
      written).
      
      I'm not aware of the previous behavior causing problems. However,
      writing an important file unnecessarily as root should be avoided.
      e1106a33
    • Scott Kuhl's avatar
      Allow no remote to work. · 574ed8e5
      Scott Kuhl authored
      Pull request #502 made -r/--remote required. However, the
      documentation still indicates that using no remote is a valid way to
      test sshuttle (see Examples section of man page). I think this mode
      might be useful for testing performance local without ssh, local with
      ssh, and remote with ssh.
      
      This patch adds a warning when -r/--remote is missing but restores the
      previous behavior.
      574ed8e5
    • Brian May's avatar
      Merge pull request #543 from skuhl/sdnotify-doc · 1dbf2163
      Brian May authored
      sdnotify.py documentation
      1dbf2163
    • Scott Kuhl's avatar
      sdnotify.py documentation · 52558174
      Scott Kuhl authored
      52558174
    • Scott Kuhl's avatar
      Update/document client's handling of IPv4 and IPv6. · b7a29aca
      Scott Kuhl authored
      Additional comments, checks, warning messages, and diagnostic
      information is printed out when the client starts.
      
      We assume IPv4 is always present and enabled. We assume IPv6 is not
      supported when it is disabled at the command line or when it is not
      supported by the firewall method. Warn if IPv6 is disabled but the
      user specified IPv6 subnets, IPv6 DNS servers, or IPv6 excludes that
      are effectively ignored.
      
      Instead of indicating which features are on/off, we also indicate if
      features are available in the verbose output.
      
      We also more clearly print the subnets that we forward, excludes, and
      any redirected DNS servers to the terminal output.
      
      These changes should help handling bug reports and make it clearer to
      users what is happening. It should also make it more graceful when a
      user specifies a subnet/exclude with hostname that resolves to both
      IPv4 and IPv6 (but IPv6 is disabled in sshuttle).
      b7a29aca
  7. 18 Oct, 2020 4 commits
  8. 17 Oct, 2020 1 commit
    • Scott Kuhl's avatar
      When subnets and excludes are specified with hostnames, use all IPs. · 036c49e4
      Scott Kuhl authored
      The list of subnets to route over VPN and the list of subnets to
      exclude are parsed in option.py parse_subnetport(). Hostnames or IP
      addresses are supported. If a hostname was provided, only the first IP
      address was considered. This could result in some traffic not
      traversing the VPN that the user might expect should traverse it from
      the arguments passed to sshuttle.
      
      This patch makes the function handle all of the IPs if a hostname is
      provided. If a user provides a hostname with a CIDR mask, problems can
      occur and we warn the user about the issue.
      
      If the user includes a hostname with both an IPv4 and an IPv6 address,
      and the underlying method doesn't support IPv6, then this patch will
      cause sshuttle to fail. I plan to provide a future patch where failure
      won't occur if the only place IPv6 addresses appear is in the exclude
      list. In that case it should be safe to ignore the IPv6 address.
      
      This patch also changes parse_ipport() which is used by the --to-ns
      option. If the user provides a hostname here, we just use the first IP
      from the hostname and warn the user that only one is being used.
      036c49e4
  9. 10 Oct, 2020 1 commit
  10. 09 Oct, 2020 1 commit
    • Scott Kuhl's avatar
      Include sshuttle version in verbose output. · 84e43d31
      Scott Kuhl authored
      Some bug reports include verbose sshuttle output but lack the version
      that is being used. Including the sshuttle version in the output may
      make it easier to handle future bug reports.
      84e43d31
  11. 08 Oct, 2020 2 commits
  12. 06 Oct, 2020 2 commits
  13. 05 Oct, 2020 2 commits
  14. 29 Sep, 2020 1 commit
  15. 28 Sep, 2020 1 commit
  16. 15 Sep, 2020 1 commit
  17. 14 Sep, 2020 1 commit
  18. 09 Sep, 2020 1 commit
  19. 08 Sep, 2020 3 commits