1. 26 Jan, 2011 2 commits
    • Roger's avatar
      new option to disable fullness checking · fdb7c9b9
      Roger authored
      On high latency links, the PING/PONG round trip triggered by fullness
      checking could kill the bandwidth. Disabling it could result in >10x
      bandwidth increase in some setups where the existing latency is already high
      and the available bandwidth is also high.
      fdb7c9b9
    • Avery Pennarun's avatar
      Don't die if iptables doesn't have 'ttl match' support. · 675f19f5
      Avery Pennarun authored
      ttl matching is only needed if your server is the same machine as the
      client, which is kind of useless anyway (other than for testing), so there's
      no reason for it to be fatal if that doesn't work.
      
      Reported by "Alphazo" on the mailing list, who managed to get sshuttle
      working on his Nokia N900 by removing the ttl stuff.
      675f19f5
  2. 23 Jan, 2011 13 commits
  3. 13 Jan, 2011 3 commits
  4. 01 Jan, 2011 13 commits
    • Avery Pennarun's avatar
      973d5a95
    • Avery Pennarun's avatar
      ssyslog.py: use daemon.notice instead of daemon.info · 95ab6e71
      Avery Pennarun authored
      ...MacOS X seems to default (in /etc/syslog.conf) to not logging daemon.info
      anywhere.  That kind of defeats the purpose, I think.
      95ab6e71
    • Avery Pennarun's avatar
      Merge branch 'daemon' · e6d7c44e
      Avery Pennarun authored
      * daemon:
        daemonization: make sure the firewall subproc sends to syslog too.
        Rearrange daemonization/syslog stuff and make it more resilient.
        run in background (daemon) and option
      e6d7c44e
    • Avery Pennarun's avatar
    • Avery Pennarun's avatar
      Rearrange daemonization/syslog stuff and make it more resilient. · 8a5ae1a4
      Avery Pennarun authored
      Rename --background to -D/--daemon, to match other programs (like smbd).
      
      You can now have --syslog even without --daemon.
      
      Avoid using atexit(); try/finally is better.
      
      Don't just close stderr; we'll end up eating error output from ssh!
      Instead, redirect stderr to a 'logger' subprocess that will send to syslog.
      
      Delay redirecting stderr until after we know we're daemonizing, so handy
      error messages can go to stderr instead of syslog.
      
      Make pidfile stuff more resilient: support already-existing files, files
      with strict permissions, outdated files containing an already-dead pid.  Add
      a --pidfile option to let you specify the pidfile path.
      
      chdir("/") while daemonizing, so that the filesystem containing $PWD can
      later be unmounted without killing the daemon.
      
      fw.done() can't wait on the firewall subprocess on exit when daemonized; we
      no longer are the parent of that process.
      8a5ae1a4
    • Avery Pennarun's avatar
      If ssh dies right after starting, we might get ECONNRESET. · 651b6073
      Avery Pennarun authored
      Turn it into a nicer-looking fatal error instead of an exception dump.
      651b6073
    • Avery Pennarun's avatar
      dc9a5e63
    • Avery Pennarun's avatar
      Merge branch 'closing' · 33bc55be
      Avery Pennarun authored
      * closing:
        Correctly close server connection when client disconnects.
        "Too many open files" shouldn't be a fatal condition.
      33bc55be
    • Avery Pennarun's avatar
      Correctly close server connection when client disconnects. · c3204d27
      Avery Pennarun authored
      When the server disconnected, we were forwarding that information to the
      client.  But we weren't forwarding back the other way when the client
      disconnected since there was no callback in place to do that.
      
      Relatedly, when we failed entirely to connect to the server, we didn't notify the
      client right away.  Now we do.
      
      Thanks to 'Roger' on the mailing list for pointing out these bugs.
      c3204d27
    • Avery Pennarun's avatar
      "Too many open files" shouldn't be a fatal condition. · b1edb226
      Avery Pennarun authored
      It can happen if there are too many sockets open.  If that happens, just
      throw away any connections that arrive in the meantime instead of aborting
      completely.
      b1edb226
    • Avery Pennarun's avatar
      Listen on localhost:0 instead of 0.0.0.0:0 by default. · 7fa1c3c4
      Avery Pennarun authored
      This avoids any possible problem caused by other people on your network
      using you as a proxy.  If you want to allow this, you can force it back to
      the old way using the --listen option.
      
      Thanks to 'tass' on github for reporting portscans that revealed this
      potential security problem.
      7fa1c3c4
    • Avery Pennarun's avatar
      Don't allow proxying of connections to the proxy port. · cca69eb4
      Avery Pennarun authored
      Add some cleverness for breaking infinite loops.  Previously we'd only
      detect it successfully if you connected to exactly the same IP as we were
      listening on, but that was unreliable if we're listening on 0.0.0.0 and you
      connected to one of the IP addresses we haven't heard of.
      
      Now, if you try to connect to our listen port on *any* IP, we try binding to
      that IP as a local socket; if it works, that's a local IP, and therefore
      it's our socket, so reject the connection.  If it doesn't work, it's a
      remote IP, so forward it along.
      
      Thanks to 'tass' on github for noticing the problem.
      cca69eb4
    • Avery Pennarun's avatar
      91f65132
  5. 12 Dec, 2010 2 commits
  6. 10 Dec, 2010 5 commits
  7. 20 Nov, 2010 1 commit
    • Christopher Bowns's avatar
      Add support for IPv6 remote hosts. · 95c9b788
      Christopher Bowns authored
      Supported sshuttle commands for IPv6:
      
      ./sshuttle -r "IPv6:addr" 0.0.0.0/0 -vv
      ./sshuttle -r "[IPv6:addr]" 0.0.0.0/0 -vv
      ./sshuttle -r "[IPv6:addr]:22" 0.0.0.0/0 -vv
      
      Technically "invalid" address/port formats, but they can still be parsed because they’re unambiguous, so these also work:
      
      ./sshuttle -r "IPv6:addr]" 0.0.0.0/0 -vv
      ./sshuttle -r "IPv6:addr]:" 0.0.0.0/0 -vv
      ./sshuttle -r "IPv6:addr]:22" 0.0.0.0/0 -vv
      ./sshuttle -r "[IPv6:addr" 0.0.0.0/0 -vv
      
      (If you have a Mac with Back To My Mac, use dns-sd to discover the remote host's IPv6 address:
      dns-sd -G v4v6 <machine name>.<member name>.members.mac.com )
      95c9b788
  8. 09 Nov, 2010 1 commit