Documentation
¶
Overview ¶
Package linuxkernel is the kernel dataplane Backend (design.md 6.1, 7a.7, 7a.8 節 Phase 3): kernel WireGuard (linuxkernel/wg), nftables DNAT and admission (linuxkernel/nft), and conntrack convergence (linuxkernel/conntrack), behind the same dataplane.Backend interface the userspace Backend implements. It never imports internal/vpsd or internal/agent (design.md 7a.7 節; internal/dataplane/deps_test.go checks this), so the future agent kernel backend (Phase 7) can reuse its common kernel components: WireGuard, the platform checks, and the nft and conntrack primitives. The table built here (public ports DNATed to an agent's wg address) and the convergence of those DNATed flows are server-specific; the agent needs its own nft and conntrack path (DNAT to the LAN target, MASQUERADE toward the LAN, agent-side convergence), to be added in this package next to the server's.
Backend's Prepare stages nothing: nft.Apply's build-then-Flush is one atomic kernel operation (design.md 7a.2 節), so there is nothing reversible to separate out yet, and Commit alone already gives the "nothing is published on failure" guarantee the Prepared contract asks for. Everything beyond the participant (EnsureWG, Converge, ReadDrops, Dial) is called by the control plane around the Runtime, exactly where the pre-Backend vpsd code called it (design.md 7a.2 節); Phase 4 folds these into the transaction.
Index ¶
- type Backend
- func (b *Backend) Converge(plan planner.Plan) (int, error)
- func (b *Backend) Dial(network, addr string) (net.Conn, error)
- func (b *Backend) EnsureWG(cfg dataplane.WGConfig) ([]string, error)
- func (b *Backend) OtherDeviceWithKey(key wgtypes.Key) (string, bool)
- func (b *Backend) Prepare(d dataplane.Desired) (dataplane.Prepared, error)
- func (b *Backend) ReadDrops() ([]dataplane.Drop, error)
- func (b *Backend) WGStatus() (*wgtypes.Device, error)
- type Options
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Backend ¶
type Backend struct {
// contains filtered or unexported fields
}
Backend is the kernel dataplane: kernel WireGuard, nftables DNAT and admission, and conntrack convergence (design.md 6.1 節). It implements dataplane.Backend.
func (*Backend) Converge ¶
Converge closes conntrack flows the committed Plan no longer admits (design.md 6.1 節). It runs after the Runtime's Commit (the nftables table has already been replaced).
func (*Backend) Dial ¶
Dial connects to addr (an agent's wg address and port). Kernel mode routes it straight over wg0 like any other kernel route, so this is a plain dial with no tunnel to go through (unlike the userspace Backend's Dial, which dials through its netstack).
func (*Backend) OtherDeviceWithKey ¶
OtherDeviceWithKey reports another kernel WireGuard device with the same private key, if any (interface rename detection; not part of dataplane.Backend, vpsd calls it directly).
func (*Backend) Prepare ¶
Prepare stages d without publishing it. nft.Apply's build and Flush happen together as one atomic kernel operation in Commit, so there is nothing to stage here yet (design.md 7a.2 節); moving the build into Prepare is Phase 4's job.
type Options ¶
type Options struct {
// Interface は wg インタフェース名(既定 wgft0)。
Interface string
// AdoptExisting が真のときだけ、鍵の一致しない既存インタフェースを引き継ぐ(design.md 9 節)。
AdoptExisting bool
}
Options configures a Backend. Interface と AdoptExisting は kernel の wg インタフェースだけの 性質なので、宣言(dataplane.WGConfig)ではなく construction 時にここで固定する(dataplane.WGConfig のドキュメントコメントのとおり)。
Directories
¶
| Path | Synopsis |
|---|---|
|
Package conntrack は、外から入って DNAT されたフローを Plan に収束させる(仕様 6.1 節、 設計文書 7a.8 節 Phase 3)。
|
Package conntrack は、外から入って DNAT されたフローを Plan に収束させる(仕様 6.1 節、 設計文書 7a.8 節 Phase 3)。 |
|
Package nft は、Plan から VPS の table inet wgft を組み立てて適用する(仕様 6.1 節、設計文書 7a.2 節)。
|
Package nft は、Plan から VPS の table inet wgft を組み立てて適用する(仕様 6.1 節、設計文書 7a.2 節)。 |
|
Package wg は VPS(および将来の agent の kernel backend、Phase 7)の WireGuard インタフェースを 宣言に収束させる(仕様 4, 9 節、設計文書 7a.7 節)。
|
Package wg は VPS(および将来の agent の kernel backend、Phase 7)の WireGuard インタフェースを 宣言に収束させる(仕様 4, 9 節、設計文書 7a.7 節)。 |