Documentation
¶
Index ¶
- Constants
- Variables
- func ConfigFile() (string, error)
- func IsManagedBridge(name string) bool
- func IsTapName(name string) bool
- func IsUsernet(name string) bool
- func RequiredDaemons() []string
- func Sock(name string) (string, error)
- func TapName(instName, netName string) string
- func TapNamePattern() string
- type Config
- func (c *Config) BridgeName(name string) string
- func (c *Config) Check(name string) error
- func (c *Config) DaemonPath(daemon string) (string, error)
- func (c *Config) DigestSpec(daemon string) (string, error)
- func (c *Config) IsDaemonInstalled(daemon string) (bool, error)
- func (c *Config) LogFile(name, daemon, stream string) string
- func (c *Config) MkdirCmd() string
- func (c *Config) PIDFile(name, daemon string) string
- func (c *Config) Sock(name string) string
- func (c *Config) StartCmd(name, daemon string) string
- func (c *Config) StopCmd(name, daemon string) string
- func (c Config) Sudoers() (string, error)
- func (c *Config) TapCmd(name, tap string) string
- func (c *Config) User(daemon string) (osutil.User, error)
- func (c *Config) Usernet(name string) (bool, error)
- func (c *Config) Validate() error
- func (c *Config) VerifySudoAccess(ctx context.Context, sudoersFile string) error
- type Network
- type Paths
Constants ¶
const ( SocketVMNet = "socket_vmnet" LimaPrivilegedNet = "lima-privileged-net" )
const ( SlirpNICName = "eth0" // CIDR is intentionally hardcoded to 192.168.5.0/24, as each of QEMU has its own independent slirp network. SlirpNetwork = "192.168.5.0/24" SlirpGateway = "192.168.5.2" SlirpIPAddress = "192.168.5.15" )
const ( ModeUserV2 = "user-v2" ModeHost = "host" ModeBridged = "bridged" )
Variables ¶
var Modes = []string{ ModeUserV2, ModeHost, ModeShared, ModeBridged, }
Functions ¶
func ConfigFile ¶
func IsManagedBridge ¶
IsManagedBridge reports whether the interface is a bridge created by lima-privileged-net.
func IsTapName ¶
IsTapName reports whether the interface name could have been generated by TapName, i.e. whether the interface belongs to Lima.
func IsUsernet ¶
IsUsernet returns true if the given network name is a usernet network. It return false if the cache cannot be loaded or the network is not defined.
func RequiredDaemons ¶
func RequiredDaemons() []string
RequiredDaemons returns the privileged helpers needed by the non-usernet networks on this host: socket_vmnet on macOS, lima-privileged-net on Linux. Everything else in this package is generic over the daemon name.
func TapName ¶
TapName returns the name of the tap device connecting an instance to a network. A hash keeps the name within the maxIfNameLen limit and within the fixed shape that TapNamePattern pins down in the sudoers file. The uid is part of the hash because the bridges are shared between all users of the sudoers group, and a tap device may only ever be used by its owner.
func TapNamePattern ¶
func TapNamePattern() string
TapNamePattern is the sudoers wildcard matching exactly the names generated by TapName. Character classes are used instead of "*" because "*" would also match whitespace, which would allow smuggling extra arguments into the command.
Types ¶
type Config ¶
type Config struct {
Paths Paths `yaml:"paths" json:"paths"`
Group string `yaml:"group,omitempty" json:"group,omitempty"` // default: "admin"
Networks map[string]Network `yaml:"networks" json:"networks"`
}
func DefaultConfig ¶
func LoadConfig ¶
LoadConfig returns the network cfg from the _config/networks.yaml file.
func (*Config) BridgeName ¶
BridgeName returns the bridge that the instances of a network are attached to: the pre-existing bridge named by `interface` for "bridged" networks, and the Lima-managed "lima-<name>" bridge otherwise.
func (*Config) DaemonPath ¶
DaemonPath returns the daemon path.
func (*Config) DigestSpec ¶
DigestSpec returns the sudoers `Digest_Spec` pinning the contents of the daemon binary. sudo (>= 1.8.7) hashes the file immediately before executing it and refuses to run it when the digest no longer matches, so an attacker who manages to replace the helper cannot get the replacement executed as root. Unlike the ownership checks in validate.go, this is enforced inside sudo itself and is therefore not subject to a time-of-check/time-of-use race with limactl.
func (*Config) IsDaemonInstalled ¶
IsDaemonInstalled checks whether the daemon is installed.
func (*Config) TapCmd ¶
TapCmd returns the command creating the tap device that connects an instance to the bridge of a network. Passing TapNamePattern renders the sudoers entry.
type Network ¶
type Network struct {
Mode string `yaml:"mode" json:"mode"` // "user-v2", "host", "shared", or "bridged"
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"` // only used by "bridged" networks
Gateway net.IP `yaml:"gateway,omitempty" json:"gateway,omitempty"` // only used by "user-v2", "host" and "shared" networks
DHCPEnd net.IP `yaml:"dhcpEnd,omitempty" json:"dhcpEnd,omitempty"` // default: same as Gateway, last byte is 254
NetMask net.IP `yaml:"netmask,omitempty" json:"netmask,omitempty"` // default: 255.255.255.0
}