-
Scott Kuhl authored
The list of subnets to route over VPN and the list of subnets to exclude are parsed in option.py parse_subnetport(). Hostnames or IP addresses are supported. If a hostname was provided, only the first IP address was considered. This could result in some traffic not traversing the VPN that the user might expect should traverse it from the arguments passed to sshuttle. This patch makes the function handle all of the IPs if a hostname is provided. If a user provides a hostname with a CIDR mask, problems can occur and we warn the user about the issue. If the user includes a hostname with both an IPv4 and an IPv6 address, and the underlying method doesn't support IPv6, then this patch will cause sshuttle to fail. I plan to provide a future patch where failure won't occur if the only place IPv6 addresses appear is in the exclude list. In that case it should be safe to ignore the IPv6 address. This patch also changes parse_ipport() which is used by the --to-ns option. If the user provides a hostname here, we just use the first IP from the hostname and warn the user that only one is being used.
036c49e4
| Name |
Last commit
|
Last update |
|---|---|---|
| .github/workflows | ||
| bin | ||
| docs | ||
| sshuttle | ||
| tests | ||
| .gitignore | ||
| .prospector.yml | ||
| CHANGES.rst | ||
| LICENSE | ||
| MANIFEST.in | ||
| README.rst | ||
| bandit.yml | ||
| requirements-tests.txt | ||
| requirements.txt | ||
| run | ||
| setup.cfg | ||
| setup.py | ||
| tox.ini |