1. 04 Feb, 2020 3 commits
  2. 13 Dec, 2019 2 commits
    • Nathan Aclander's avatar
      Link Directly to TCP Over TCP Explanation · ad31ac4e
      Nathan Aclander authored
      See Below was confusing because it linked to the entire documentation section.
      This provides a direct link to the section explaining why TCP over TCP is a bad idea.
      ad31ac4e
    • William Mantly's avatar
      Auto sudoers file (#269) · 69d3f7dc
      William Mantly authored
      * added sudoers options to command line arguments
      
      * added sudoers options to command line arguments
      
      * template for sudoers file
      
      * Added option for GUI sudo
      
      * added support for GUI sudo
      
      * script for auto adding sudo file
      
      * sudoers auto add works and validates
      
      * small change
      
      * Clean up for CI
      
      * removed code that belongs in another PR
      
      * added path for package bins
      
      * added sudoers bin
      
      * added sudoers-add to setup file
      
      * fixed issue with sudoers bash script
      
      * auto sudoers now works
      
      * added --sudoers-no-modify option
      
      * bin now works with ./run
      
      * removed debug print
      
      * Updated sudoers-add script
      
      * Fixed error passing sudoers config to script
      
      * more dynamic building of sudoers file
      
      * added option to specify sudoers.d file name
      
      * fixed indent issue
      
      * fixed indent issue
      
      * indent issue
      
      * clean up
      
      * formating
      
      * docs
      
      * fix for flags
      
      * Update usage.rst
      
      * removed shell=true
      
      * cleared CI errors
      
      * cleared CI errors
      
      * removed random
      
      * cleared linter issue
      
      * cleared linter issue
      
      * cleared linter issue
      
      * updated sudoers-add script
      
      * safer temp file
      
      * moved bin directory
      
      * moved bin directory
      
      * removed print
      
      * fixed spacing issue
      
      * sudoers commands must only containe upper case latters
      69d3f7dc
  3. 09 Nov, 2019 1 commit
    • Ben Wiederhake's avatar
      Make hostwatch locale-independent (#379) · 6ad4473c
      Ben Wiederhake authored
      * Make hostwatch locale-independent
      
      See #377: hostwatch used to call netstat and parse the result,
      without setting the locale.
      The problem is converting the binary output to a unicode string,
      as the locale may be utf-8, latin-1, or literally anything.
      Setting the locale to C avoids this issue, as netstat's source
      strings to not use non-ASCII characters.
      
      * Break line, check all other invocations
      6ad4473c
  4. 08 Nov, 2019 1 commit
    • Joseph Barker's avatar
      Add option for latency control buffer size · 23516ebd
      Joseph Barker authored
      This commit resolves #297, allowing the buffers used in the latency control to be changed with a command line option ‘--latency-buffer-size’.
      
      We do this by changing a module variable in ssnet.py (similar to the MAX_CHANNEL variable) which seems to be the simplest code change without extensive hacking.
      
      Documentation is also updated.
      23516ebd
  5. 27 Oct, 2019 1 commit
    • Joseph Barker's avatar
      Fix broken string substitution from a765aa32 · c69b9d6f
      Joseph Barker authored
      The changes in a765aa32 removed a more complex pieced of code for parsing which sudo command to use. The %(eb)s no longer refers to any variable and is directly printed to the command line.
      
      %(eb)s is now replaced with ‘sudo’.
      c69b9d6f
  6. 24 Oct, 2019 1 commit
  7. 13 Oct, 2019 1 commit
  8. 03 Oct, 2019 2 commits
  9. 22 Sep, 2019 5 commits
  10. 25 Jul, 2019 1 commit
  11. 21 Jun, 2019 1 commit
  12. 08 Jun, 2019 2 commits
  13. 04 Apr, 2019 1 commit
  14. 14 Feb, 2019 2 commits
  15. 11 Feb, 2019 1 commit
    • Bastian Venthur's avatar
      Fix/pep8 (#277) · 3bfb975e
      Bastian Venthur authored
      * re-organized imports according to pep8
      * fixed all remaining pep8 issues
      * moved common config into setup.cfg, additionally test `tests`
      * removed --select=X -- the errors selected where by default not in
        flake8's --ignore list so effectively had no effect
      * update .travis.yml to reflect changes in tox.ini
      * make travis just use tox in order to avoid code duplaction
      * replace py.test with pytest
      * fixed .travis.yml
      * try different pypy toxenv
      * hopefully fixed testenv for pypy
      * added pypy basepython, removed unused python2.6
      * install dev package before testing (fixes missing coverage)
      * fixed empty exception pass blocks with noqa
      * Added dummy log message on empty try-except-pass blocks to make dodacy happy :(
      * Replaced Exception with BaseException
      3bfb975e
  16. 28 Jan, 2019 3 commits
  17. 23 Jan, 2019 2 commits
  18. 29 Dec, 2018 1 commit
    • André Draszik's avatar
      docs: document --ns-hosts --to-ns and update --dns · 531a17c1
      André Draszik authored
      --ns-hosts is available since commit d2ee34d7
      ("dns: Added --ns-hosts to tunnel only some requests")
      (released as v0.72), but was never documented.
      
      --to-ns is available since commit be559fc7
      ("Fix case where there is no --dns.") after several
      bugfixes, released as v0.78.4, but was never
      documented.
      531a17c1
  19. 09 Dec, 2018 1 commit
    • Alex Tomlins's avatar
      Fix deadlock with iptables with large ruleset · d43db80d
      Alex Tomlins authored
      When running sshuttle with a large list of routes it's failing to clean
      them up at exit. It returns the following:
      
      $ sshuttle -r user@host.example.com -s /tmp/aws-cidrs.txt
      user@host.example.com's password:
      client: Connected.
      ^CAnother app is currently holding the xtables lock; still -9s 0us time ahead to have a chance to grab the lock...
      Another app is currently holding the xtables lock; still -19s 0us time ahead to have a chance to grab the lock...
      Another app is currently holding the xtables lock; still -29s 0us time ahead to have a chance to grab the lock...
      
      This continues indefinitely. Looking in ps reveals that there are 2
      iptables processes running. Killing -9 the first one, allows sshuttle to
      continue and clean up successfully.
      
      The problem lies with the use of Popen here. The function currently
      returns as soon as it finds a match without consuming everything from
      stdout. This means that if there's more output from iptables than will
      fit in the buffer it doesn't exit, and therefore doesn't release the
      kernel xtables lock.
      d43db80d
  20. 03 Dec, 2018 1 commit
  21. 29 Nov, 2018 1 commit
  22. 03 Nov, 2018 1 commit
    • João Vieira's avatar
      Changes pf exclusion rules precedence · ca41026c
      João Vieira authored
      Before this change, in pf, exclusions used a pass out quick which gave
      them higher precedence than any other rule independent of subnet width.
      As reported in #265 this causes exclusion from one instance of sshuttle
      to also take effect on other instances because quick aborts the
      evaluation of rules across all anchors.
      
      This commit changes the precedence of rules so quick can now be
      dropped. The new order is defined by the following rule, from
      subnet_weight:
      
      "We need to go from smaller, more specific, port ranges, to larger,
      less-specific, port ranges. At each level, we order by subnet
      width, from most-specific subnets (largest swidth) to
      least-specific. On ties, excludes come first."
      ca41026c
  23. 01 Nov, 2018 1 commit
  24. 23 Oct, 2018 1 commit
    • João Vieira's avatar
      Fixes support for OpenBSD (6.1+) (#282) · 7a54d12f
      João Vieira authored
      * Fixes support for OpenBSD (6.1+)
      
      As reported in #219, new versions of OpenBSD ship with a different
      pfioc_rule struct. This commit adjusts the offset to match the new struct.
      
      * Fixes tests for OpenBSD 6.1+
      7a54d12f
  25. 17 Oct, 2018 3 commits