- 23 Oct, 2020 1 commit
-
-
Scott Kuhl authored
Update docs to indicate that IPv6 is supported with the nft method. - Adds nft into the requirements.rst file. - Update description of what happens when a hostname is used in a subnet. - Add ipfw to list of methods. - Indicate that --auto-nets does not work with IPv6. Previously this was only mentioned in tproxy.rst - Clarify that we try to use "python3" on the server before trying "python".
-
- 22 Oct, 2020 2 commits
-
-
Scott Kuhl authored
This works for me but needs testing by others. Remember to specify a ::0/0 subnet or similar to route IPv6 through sshuttle. I'm adding this to nft before nat since it is not sshuttle's default method on Linux. Documentation updates may be required too. This patch uses the ipaddress module, but that appears to be included since Python 3.3.
-
Brian May authored
Make nat and nft rules consistent; improve rule ordering.
-
- 21 Oct, 2020 6 commits
-
-
Scott Kuhl authored
First, check if TTL indicates we should ignore packet (instead of checking in multiple rules later). Also, nft method didn't do this at all. Now, nft matches the behavior of nat. Second, forward DNS traffic (we may need to intercept traffic to localhost if a DNS server is running on localhost). Third, ignore any local traffic packets. (Previously, we ignored local traffic except DNS and then had the DNS rules). The nft method didn't do this previously at all. It now matches the behavior of nat. Lastly, list the subnets to redirect and/or exclude. This step is left unchanged. Excluding the local port that we are listening on is redundant with the third step, but should cause no harm. In summary, this ordering simplifies the rules in nat and eliminates differences that previously existed between nat and nft.
-
Brian May authored
Allow no remote to work.
-
Brian May authored
Make prefixes in verbose output more consistent.
-
Scott Kuhl authored
-
Scott Kuhl authored
-
Scott Kuhl authored
Use 'c' prefix for client, 's' prefix for server, and 'fw' prefix for firewall messages. The 'c' and 's' prefixes were used sometimes but not consistently. The firewall printed messages prefixed with "firewall manager:" or "firewall:" or ">>" previously. This patch also fixes a couple of print() calls that should have been debug1()---a bug introduced in a recent commit.
-
- 20 Oct, 2020 2 commits
- 19 Oct, 2020 7 commits
-
-
Nicolas Stalder authored
-
Brian May authored
Only write /etc/hosts when necessary.
-
Scott Kuhl authored
Without this patch, sshuttle 'restores' /etc/hosts even if it didn't make any modifications to it. This can be confirmed by running without --auto-hosts and confirming that the modification time of /etc/hosts is unchanged while sshuttle is running, but is updated when sshuttle exits (and a debug2() message is printed indicating the file is written). I'm not aware of the previous behavior causing problems. However, writing an important file unnecessarily as root should be avoided.
-
Scott Kuhl authored
Pull request #502 made -r/--remote required. However, the documentation still indicates that using no remote is a valid way to test sshuttle (see Examples section of man page). I think this mode might be useful for testing performance local without ssh, local with ssh, and remote with ssh. This patch adds a warning when -r/--remote is missing but restores the previous behavior.
-
Brian May authored
sdnotify.py documentation
-
Scott Kuhl authored
-
Scott Kuhl authored
Additional comments, checks, warning messages, and diagnostic information is printed out when the client starts. We assume IPv4 is always present and enabled. We assume IPv6 is not supported when it is disabled at the command line or when it is not supported by the firewall method. Warn if IPv6 is disabled but the user specified IPv6 subnets, IPv6 DNS servers, or IPv6 excludes that are effectively ignored. Instead of indicating which features are on/off, we also indicate if features are available in the verbose output. We also more clearly print the subnets that we forward, excludes, and any redirected DNS servers to the terminal output. These changes should help handling bug reports and make it clearer to users what is happening. It should also make it more graceful when a user specifies a subnet/exclude with hostname that resolves to both IPv4 and IPv6 (but IPv6 is disabled in sshuttle).
-
- 18 Oct, 2020 4 commits
-
-
Scott Kuhl authored
-
Scott Kuhl authored
-
Scott Kuhl authored
-
Scott Kuhl authored
-
- 17 Oct, 2020 1 commit
-
-
Scott Kuhl authored
The list of subnets to route over VPN and the list of subnets to exclude are parsed in option.py parse_subnetport(). Hostnames or IP addresses are supported. If a hostname was provided, only the first IP address was considered. This could result in some traffic not traversing the VPN that the user might expect should traverse it from the arguments passed to sshuttle. This patch makes the function handle all of the IPs if a hostname is provided. If a user provides a hostname with a CIDR mask, problems can occur and we warn the user about the issue. If the user includes a hostname with both an IPv4 and an IPv6 address, and the underlying method doesn't support IPv6, then this patch will cause sshuttle to fail. I plan to provide a future patch where failure won't occur if the only place IPv6 addresses appear is in the exclude list. In that case it should be safe to ignore the IPv6 address. This patch also changes parse_ipport() which is used by the --to-ns option. If the user provides a hostname here, we just use the first IP from the hostname and warn the user that only one is being used.
-
- 10 Oct, 2020 1 commit
-
-
Brian May authored
Include sshuttle version in verbose output.
-
- 09 Oct, 2020 1 commit
-
-
Scott Kuhl authored
Some bug reports include verbose sshuttle output but lack the version that is being used. Including the sshuttle version in the output may make it easier to handle future bug reports.
-
- 08 Oct, 2020 2 commits
- 06 Oct, 2020 2 commits
- 05 Oct, 2020 2 commits
-
-
dependabot-preview[bot] authored
Bumps [flake8](https://gitlab.com/pycqa/flake8) from 3.8.3 to 3.8.4. - [Release notes](https://gitlab.com/pycqa/flake8/tags) - [Commits](https://gitlab.com/pycqa/flake8/compare/3.8.3...3.8.4) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
dependabot-preview[bot] authored
Bumps [pytest](https://github.com/pytest-dev/pytest) from 6.1.0 to 6.1.1. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/6.1.0...6.1.1) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
- 29 Sep, 2020 1 commit
-
-
Brian May authored
Bump pytest from 6.0.2 to 6.1.0
-
- 28 Sep, 2020 1 commit
-
-
dependabot-preview[bot] authored
Bumps [pytest](https://github.com/pytest-dev/pytest) from 6.0.2 to 6.1.0. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/6.0.2...6.1.0) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
- 15 Sep, 2020 1 commit
-
-
Brian May authored
Bump pytest from 6.0.1 to 6.0.2
-
- 14 Sep, 2020 1 commit
-
-
dependabot-preview[bot] authored
Bumps [pytest](https://github.com/pytest-dev/pytest) from 6.0.1 to 6.0.2. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/6.0.1...6.0.2) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
- 09 Sep, 2020 1 commit
-
-
Brian May authored
Fix #494 sshuttle caught in infinite select() loop.
-
- 08 Sep, 2020 4 commits
-
-
Brian May authored
Bump attrs from 20.1.0 to 20.2.0
-
Scott Kuhl authored
-
Scott Kuhl authored
-
Scott Kuhl authored
Improve detection of when the ssh process exits in both daemon and foreground modes. Previously, sshuttle could infinite loop with 100% cpu usage if the ssh process died. On machines that use suspend, the ssh connection might not resume after wakeup. Now, this situation is detected and sshuttle exits. The fix involves changing the return value we check for when we call poll() and using a psutil function to detect when the process exits if we are running sshuttle as a daemon.
-