1. 17 Oct, 2010 1 commit
    • Avery Pennarun's avatar
      firewall.py: don't die if a given sysctl doesn't exist. · fe742c92
      Avery Pennarun authored
      Instead, get a list of known sysctls in the interesting prefix (net.inet.ip)
      and check if there's an entry in the list for each sysctl we want to change.
      If there isn't, then don't try to change it.
      
      This fixes a problem with FreeBSD, which doesn't have
      net.inet.ip.scopedroute but also doesn't need it.  Probably also fixes MacOS
      10.5, which probably didn't have that either, but I don't know for sure.
      
      Reported by Ed Maste.
      fe742c92
  2. 06 Oct, 2010 1 commit
    • Avery Pennarun's avatar
      ipfw: use 'delete' instead of 'del' to avoid a warning on freebsd. · 10ce1ee5
      Avery Pennarun authored
      'del' is an abbreviation that happened to work because of substring matching
      in earlier versions of ipfw, but apparently they're planning to remove the
      substring matching eventually.  In any case, 'delete' has always worked, so
      there's no downside to using that.
      
      Reported by Ed Maste.
      10ce1ee5
  3. 04 Oct, 2010 1 commit
    • Avery Pennarun's avatar
      server.py: don't send partial hostwatch lists. · a32305a2
      Avery Pennarun authored
      If hostwatch has a lot of stuff to say all at once, it would come in more
      than one recv() packet, and server.py would send each packet individually as
      a CMD_HOST_LIST message.  Unfortunately, client.py (rightly) expects each
      CMD_HOST_LIST message to be complete, ie. a correct sequence of rows.
      
      So now server.py makes sure of this.  If there's a leftover bit (ie. an
      unterminated line), it saves it for later.
      
      Bug reported by user "Duke" on the mailing list.
      a32305a2
  4. 03 Oct, 2010 3 commits
  5. 02 Oct, 2010 10 commits
  6. 01 Oct, 2010 5 commits
    • Avery Pennarun's avatar
    • Avery Pennarun's avatar
      BSD: sysctl net.inet.ip.forwarding=1 is not necessary. · f950a380
      Avery Pennarun authored
      If your machine is a firewall/router, it affects whether people behind the
      router can use your sshuttle connection - in the same way that it affects
      whether they can route *anything* through you.  And thus, it should be set
      by the admin, not by sshuttle.
      
      sshuttle works fine for the local user either way.
      
      (This also affects MacOS since it's a BSD variant.)
      f950a380
    • Avery Pennarun's avatar
      BSD ipfw: switch from 'established' to 'keep-state/check-state'. · 8b4466b8
      Avery Pennarun authored
      It turns out 'established' doesn't work the way I expected it to from
      iptables; it's not stateful.  It just checks the TCP flags to see if the
      connection *thinks* it's already established, and follows the rule if so.
      That caused the first packet of each new connection to set sent to our
      transproxy, but not the subsequent ones, so weird stuff happened.
      
      With this change, any (matching) connection created *after* starting sshuttle
      will get forwarded, but pre-existing ones - most importantly, sshuttle's own
      ssh connection - will not.
      
      And with this (plus the previous commit), sshuttle works on MacOS, including
      10.6!
      8b4466b8
    • Avery Pennarun's avatar
      ssnet: recover slightly more gracefully from an infinite forwarding loop. · 4bf4f70c
      Avery Pennarun authored
      If you 'telnet localhost 12300' weird things happen; someday we should
      probably auto-detect and avoid that altogether.  But meanwhile, catch EPIPE
      if it happens (it's irrelevant) and don't barf with a %d data type for a
      value that can apparently sometimes be None.
      4bf4f70c
    • Avery Pennarun's avatar
      Magic incantation to mostly fix MacOS 10.6. · 410b9d42
      Avery Pennarun authored
      It comes down to this:
         sysctl_set('net.inet.ip.scopedroute', 0)
      
      I say "mostly" because actually it doesn't fix it; sshuttle doesn't know
      what to do with the received connection, so there must be a minor bug
      remaining somewhere.  I'll fix that next.
      
      Thanks to dkf <dfortunato@gmail.com> on the sshuttle mailing list for
      suggesting the magic fix.  He points at this post in particular:
        http://discussions.apple.com/thread.jspa?messageID=11558355&#11558355
      that gave him the necessary clue.
      410b9d42
  7. 22 Sep, 2010 2 commits
    • Avery Pennarun's avatar
      latest options.py from bup, now with tty-width guessing. · 2ef1c6a4
      Avery Pennarun authored
      as of bup commit bup-0.19-2-gce2ace5.
      2ef1c6a4
    • Frederik Deweerdt's avatar
      hostwatch: add missing errno import · b35cfbd0
      Frederik Deweerdt authored
      If the ~/.sshuttle.hosts file does not exist, it triggers the following
      error:
      
             Traceback (most recent call last):
               File "./sshuttle", line 80, in <module>
                 sys.exit(hostwatch.hw_main(extra))
               File "/home/def/p/sshuttle/hostwatch.py", line 246, in hw_main
                 read_host_cache()
               File "/home/def/p/sshuttle/hostwatch.py", line 41, in read_host_cache
                 if e.errno == errno.ENOENT:
             NameError: global name 'errno' is not defined
      
      (This only happened if you run 'sshuttle --hostwatch' from the command line
      directly, without passing it through assembler.py.)
      b35cfbd0
  8. 05 Sep, 2010 1 commit
  9. 04 Sep, 2010 2 commits
  10. 25 Jul, 2010 1 commit
  11. 16 Jul, 2010 1 commit
  12. 17 May, 2010 1 commit
    • Avery Pennarun's avatar
      log(): don't abort if we fail to write to stderr. · 3a25f709
      Avery Pennarun authored
      Failing to write to the log sucks, but not as much as failing to clean up
      just because stderr disappeared.  So let's catch any IOError exception from
      log() and just ignore it.
      
      This should fix a problem reported by Camille Moncelier, which is that
      sshuttle firewall entries stick around if your tty dies strangely (eg. your
      X server aborts for some reason).
      3a25f709
  13. 13 May, 2010 1 commit
  14. 12 May, 2010 2 commits
  15. 11 May, 2010 1 commit
  16. 09 May, 2010 3 commits
  17. 08 May, 2010 4 commits
    • Avery Pennarun's avatar
      Added new --auto-hosts and --seed-hosts options to the client. · 33efa5ac
      Avery Pennarun authored
      Now if you use --auto-hosts (-H), the client will ask the server to spawn a
      hostwatcher to add names.  That, in turn, will send names back to the
      server, which sends them back to the client, which sends them to the
      firewall subprocess, which will write them to /etc/hosts.  Whew!
      
      Only the firewall process can write to /etc/hosts, of course, because only
      he's running as root.
      
      Since the name discovery process is kind of slow, we cache the names in
      ~/.sshuttle.hosts on the remote server.
      
      Right now, most of the names are discovered using nmblookup and smbclient,
      as well as by reading the existing entries in /etc/hosts.  What would really
      be nice would be to query active directory or mdns somehow... but I don't
      really know how those work, so this is what you get for now :)  It's pretty
      neat, at least.
      33efa5ac
    • Avery Pennarun's avatar
      Add 'sshuttle --hostwatch' subcommand. · a2ea5ab4
      Avery Pennarun authored
      This tries to discover local hostnames and prints them to stdout.  Will be
      used by the server for auto-hostname tracking.
      a2ea5ab4
    • Avery Pennarun's avatar
      BSD: "ipfw add %d accept ip from any to any established" · 680941cb
      Avery Pennarun authored
      With this rule, we don't interfere with already-established (or incoming)
      connections to routes that we're about to take over.  This is what
      happens by default in Linux/iptables.
      680941cb
    • Avery Pennarun's avatar
      Add -N (--auto-nets) option for auto-discovering subnets. · 70431950
      Avery Pennarun authored
      Now if you do
      
      	./sshuttle -Nr username@myservername
      
      It'll automatically route the "local" subnets (ie., stuff in the routing
      table) from myservername.  This is (hopefully a reasonable default setting
      for most people.
      70431950