1. 18 Jul, 2017 2 commits
  2. 09 Jul, 2017 6 commits
  3. 08 May, 2017 1 commit
    • vieira's avatar
      Order first by port range and only then by swidth · f9361d70
      vieira authored
      This change makes the subnets with the most specific port ranges come
      before subnets with larger, least specific, port ranges. Before this
      change subnets with smaller swidth would always come first and only for
      subnets with the same width would the size of the port range be
      considered.
      
      Example:
      188.0.0.0/8 -x 0.0.0.0/0:443
      Before: 188.0.0.0/8 would come first meaning that all ports would be
      routed through the VPN for the subnet 188.0.0.0/8
      After: 0.0.0.0/0:443 comes first, meaning that port 443 will be
      excluded for all subnets, including 188.0.0.0/8. All other ports of
      188.0.0.0/8 will be routed.
      f9361d70
  4. 07 May, 2017 1 commit
    • João Vieira's avatar
      Adds support for tunneling specific port ranges (#144) · c4a41ada
      João Vieira authored
      * Adds support for tunneling specific port ranges
      
      This set of changes implements the ability of specifying a port or port
      range for an IP or subnet to only tunnel those ports for that subnet.
      Also supports excluding a port or port range for a given IP or subnet.
      
      When, for a given subnet, there are intercepting ranges being added and
      excluded, the most specific, i.e., smaller range, takes precedence. In
      case of a tie the exclusion wins.
      
      For different subnets, the most specific, i.e., largest swidth, takes
      precedence independent of any eventual port ranges.
      
      Examples:
      Tunnels all traffic to the 188.0.0.0/8 subnet except those to port 443.
      ```
      sshuttle -r <server> 188.0.0.0/8 -x 188.0.0.0/8:443
      ```
      
      Only tunnels traffic to port 80 of the 188.0.0.0/8 subnet.
      ```
      sshuttle -r <server> 188.0.0.0/8:80
      ```
      
      Tunnels traffic to the 188.0.0.0/8 subnet and the port range that goes
      from 80 to 89.
      ```
      sshuttle -r <server> 188.0.0.0/8:80-89 -x 188.0.0.0/8:80-90
      ```
      
      * Allow subnets to be specified with domain names
      
      Simplifies the implementation of address parsing by using
      socket.getaddrinfo(), which can handle domain resolution, IPv4 and IPv6
      addresses. This was proposed and mostly implemented by @DavidBuchanan314
      in #146.
      Signed-off-by: 's avatarDavid Buchanan <DavidBuchanan314@users.noreply.github.com>
      Signed-off-by: 's avatarJoão Vieira <vieira@yubo.be>
      
      * Also use getaddrinfo for parsing listen addr:port
      
      * Fixes tests for tunneling a port range
      
      * Updates documentation to include port/port range
      
      Adds some examples with subnet:port and subnet:port-port.
      Also clarifies the versions of Python supported on the server while
      maintaining the recommendation for Python 2.7, 3.5 or later.
      Mentions support for pfSense.
      
      * In Py2 only named arguments may follow *expression
      
      Fixes issue in Python 2.7 where *expression may only be followed by
      named arguments.
      
      * Use right regex to extract ip4/6, mask and ports
      
      * Tests for parse_subnetport
      c4a41ada
  5. 05 Apr, 2017 1 commit
    • vieira's avatar
      Work around non tabular headers in BSD netstat · ef83a5c5
      vieira authored
      netstat outputs some headers in BSD (that the Linux version does not)
      that are not tabular and were breaking our 'split line into columns
      and get nth column' logic. We now skip such headers.
      
      Should fix #141.
      ef83a5c5
  6. 21 Feb, 2017 1 commit
  7. 11 Feb, 2017 4 commits
  8. 28 Jan, 2017 1 commit
  9. 15 Jan, 2017 1 commit
    • vieira's avatar
      Add support for PfSense · e8ceccc3
      vieira authored
      PfSense is based on FreeBSD and its pf is pretty close to the one
      FreeBSD ships, however some structures have different fields and two
      offsets had to be fixed.
      e8ceccc3
  10. 09 Jan, 2017 1 commit
    • vieira's avatar
      Set started_by_sshuttle False after disabling pf · e39c4afc
      vieira authored
      We set it to true when we enable pf, but do not set it back to False
      after disabling. When using IPv4 and IPv6 we end up trying to disable
      twice which procudes an error while undoing changes in FreeBSD 11.
      e39c4afc
  11. 30 Oct, 2016 2 commits
  12. 29 Oct, 2016 1 commit
    • vieira's avatar
      Move pytest-runner to tests_require · 08fb3be7
      vieira authored
      As it is only required to run the tests move pytest-runner from
      setup_requires to tests_require as suggested by @jonathanunderwood
      on #115.
      08fb3be7
  13. 28 Oct, 2016 1 commit
  14. 24 Oct, 2016 1 commit
    • vieira's avatar
      Support sdnotify for better systemd integration · fbbcc05d
      vieira authored
      These changes introduce support for sdnotify allowing sshuttle to notify
      systemd when it finishes connecting to the server and installing
      firewall rules, and is ready to tunnel requests.
      fbbcc05d
  15. 13 Oct, 2016 1 commit
    • Joao Vieira's avatar
      Fix #117 to allow for no subnets via file (-s) · 15b394da
      Joao Vieira authored
      This should fix an issue introduced in #117 where when no subnets are
      given via file (-s file) the variable is None instead of an empty list
      and the concatenation with the subnets given as positional parameters
      fails.
      15b394da
  16. 04 Oct, 2016 1 commit
    • Felix Dreissig's avatar
      Fix argument splitting for multi-word arguments · 0ed5ef9a
      Felix Dreissig authored
      By just splitting at spaces, multi-word arguments are torn apart even if
      quoted. In case of custom ssh-cmd, this makes it practically impossible
      to set certian options through `ssh -o`.
      shlex splits arguments like a shell and e.g. respects quotes.
      0ed5ef9a
  17. 27 Sep, 2016 1 commit
    • vieira's avatar
      Allow subnets to be given only by file (-s) · c0c3612e
      vieira authored
      This should fix #116. Handling this while still having the positional
      arguments and -s both write to the same list turned out to be more
      complicated than it's worth so each writes to their own variable and we
      merge them at the end.
      c0c3612e
  18. 05 Sep, 2016 2 commits
  19. 01 Sep, 2016 2 commits
  20. 30 Aug, 2016 4 commits
  21. 06 Aug, 2016 2 commits
  22. 29 Jul, 2016 1 commit
  23. 28 Jul, 2016 2 commits