networks

package
v2.3.0-beta.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 26 Imported by: 0

Documentation

Index

Constants

View Source
const (
	SocketVMNet       = "socket_vmnet"
	LimaPrivilegedNet = "lima-privileged-net"
)
View Source
const (
	SlirpNICName = "eth0"
	// CIDR is intentionally hardcoded to 192.168.5.0/24, as each of QEMU has its own independent slirp network.
	SlirpNetwork   = "192.168.5.0/24"
	SlirpGateway   = "192.168.5.2"
	SlirpIPAddress = "192.168.5.15"
)
View Source
const (
	ModeUserV2  = "user-v2"
	ModeHost    = "host"
	ModeShared  = "shared"
	ModeBridged = "bridged"
)

Variables

Functions

func ConfigFile

func ConfigFile() (string, error)

func IsManagedBridge

func IsManagedBridge(name string) bool

IsManagedBridge reports whether the interface is a bridge created by lima-privileged-net.

func IsTapName

func IsTapName(name string) bool

IsTapName reports whether the interface name could have been generated by TapName, i.e. whether the interface belongs to Lima.

func IsUsernet

func IsUsernet(name string) bool

IsUsernet returns true if the given network name is a usernet network. It return false if the cache cannot be loaded or the network is not defined.

func RequiredDaemons

func RequiredDaemons() []string

RequiredDaemons returns the privileged helpers needed by the non-usernet networks on this host: socket_vmnet on macOS, lima-privileged-net on Linux. Everything else in this package is generic over the daemon name.

func Sock

func Sock(name string) (string, error)

Sock returns a socket_vmnet socket.

func TapName

func TapName(instName, netName string) string

TapName returns the name of the tap device connecting an instance to a network. A hash keeps the name within the maxIfNameLen limit and within the fixed shape that TapNamePattern pins down in the sudoers file. The uid is part of the hash because the bridges are shared between all users of the sudoers group, and a tap device may only ever be used by its owner.

func TapNamePattern

func TapNamePattern() string

TapNamePattern is the sudoers wildcard matching exactly the names generated by TapName. Character classes are used instead of "*" because "*" would also match whitespace, which would allow smuggling extra arguments into the command.

Types

type Config

type Config struct {
	Paths    Paths              `yaml:"paths" json:"paths"`
	Group    string             `yaml:"group,omitempty" json:"group,omitempty"` // default: "admin"
	Networks map[string]Network `yaml:"networks" json:"networks"`
}

func DefaultConfig

func DefaultConfig() (Config, error)

func LoadConfig

func LoadConfig() (Config, error)

LoadConfig returns the network cfg from the _config/networks.yaml file.

func (*Config) BridgeName

func (c *Config) BridgeName(name string) string

BridgeName returns the bridge that the instances of a network are attached to: the pre-existing bridge named by `interface` for "bridged" networks, and the Lima-managed "lima-<name>" bridge otherwise.

func (*Config) Check

func (c *Config) Check(name string) error

func (*Config) DaemonPath

func (c *Config) DaemonPath(daemon string) (string, error)

DaemonPath returns the daemon path.

func (*Config) DigestSpec

func (c *Config) DigestSpec(daemon string) (string, error)

DigestSpec returns the sudoers `Digest_Spec` pinning the contents of the daemon binary. sudo (>= 1.8.7) hashes the file immediately before executing it and refuses to run it when the digest no longer matches, so an attacker who manages to replace the helper cannot get the replacement executed as root. Unlike the ownership checks in validate.go, this is enforced inside sudo itself and is therefore not subject to a time-of-check/time-of-use race with limactl.

func (*Config) IsDaemonInstalled

func (c *Config) IsDaemonInstalled(daemon string) (bool, error)

IsDaemonInstalled checks whether the daemon is installed.

func (*Config) LogFile

func (c *Config) LogFile(name, daemon, stream string) string

func (*Config) MkdirCmd

func (c *Config) MkdirCmd() string

func (*Config) PIDFile

func (c *Config) PIDFile(name, daemon string) string

func (*Config) Sock

func (c *Config) Sock(name string) string

Sock returns a socket_vmnet socket.

func (*Config) StartCmd

func (c *Config) StartCmd(name, daemon string) string

func (*Config) StopCmd

func (c *Config) StopCmd(name, daemon string) string

func (Config) Sudoers

func (c Config) Sudoers() (string, error)

func (*Config) TapCmd

func (c *Config) TapCmd(name, tap string) string

TapCmd returns the command creating the tap device that connects an instance to the bridge of a network. Passing TapNamePattern renders the sudoers entry.

func (*Config) User

func (c *Config) User(daemon string) (osutil.User, error)

func (*Config) Usernet

func (c *Config) Usernet(name string) (bool, error)

Usernet returns true if the mode of given network is ModeUserV2.

func (*Config) Validate

func (c *Config) Validate() error

func (*Config) VerifySudoAccess

func (c *Config) VerifySudoAccess(ctx context.Context, sudoersFile string) error

type Network

type Network struct {
	Mode      string `yaml:"mode" json:"mode"`                               // "user-v2", "host", "shared", or "bridged"
	Interface string `yaml:"interface,omitempty" json:"interface,omitempty"` // only used by "bridged" networks
	Gateway   net.IP `yaml:"gateway,omitempty" json:"gateway,omitempty"`     // only used by "user-v2", "host" and "shared" networks
	DHCPEnd   net.IP `yaml:"dhcpEnd,omitempty" json:"dhcpEnd,omitempty"`     // default: same as Gateway, last byte is 254
	NetMask   net.IP `yaml:"netmask,omitempty" json:"netmask,omitempty"`     // default: 255.255.255.0
}

type Paths

type Paths struct {
	SocketVMNet string `yaml:"socketVMNet" json:"socketVMNet"`
	VarRun      string `yaml:"varRun" json:"varRun"`
	Sudoers     string `yaml:"sudoers,omitempty" json:"sudoers,omitempty"`
}

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL