linuxkernel

package
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 19, 2026 License: MIT Imports: 10 Imported by: 0

Documentation

Overview

Package linuxkernel is the kernel dataplane Backend (design.md 6.1, 7a.7, 7a.8 節 Phase 3): kernel WireGuard (linuxkernel/wg), nftables DNAT and admission (linuxkernel/nft), and conntrack convergence (linuxkernel/conntrack), behind the same dataplane.Backend interface the userspace Backend implements. It never imports internal/vpsd or internal/agent (design.md 7a.7 節; internal/dataplane/deps_test.go checks this), so the future agent kernel backend (Phase 7) can reuse its common kernel components: WireGuard, the platform checks, and the nft and conntrack primitives. The table built here (public ports DNATed to an agent's wg address) and the convergence of those DNATed flows are server-specific; the agent needs its own nft and conntrack path (DNAT to the LAN target, MASQUERADE toward the LAN, agent-side convergence), to be added in this package next to the server's.

Backend's Prepare stages nothing: nft.Apply's build-then-Flush is one atomic kernel operation (design.md 7a.2 節), so there is nothing reversible to separate out yet, and Commit alone already gives the "nothing is published on failure" guarantee the Prepared contract asks for. Everything beyond the participant (EnsureWG, Converge, ReadDrops, Dial) is called by the control plane around the Runtime, exactly where the pre-Backend vpsd code called it (design.md 7a.2 節); Phase 4 folds these into the transaction.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Backend

type Backend struct {
	// contains filtered or unexported fields
}

Backend is the kernel dataplane: kernel WireGuard, nftables DNAT and admission, and conntrack convergence (design.md 6.1 節). It implements dataplane.Backend.

func New

func New(opts Options) *Backend

New builds a Backend that converges opts.Interface.

func (*Backend) Converge

func (b *Backend) Converge(plan planner.Plan) (int, error)

Converge closes conntrack flows the committed Plan no longer admits (design.md 6.1 節). It runs after the Runtime's Commit (the nftables table has already been replaced).

func (*Backend) Dial

func (b *Backend) Dial(network, addr string) (net.Conn, error)

Dial connects to addr (an agent's wg address and port). Kernel mode routes it straight over wg0 like any other kernel route, so this is a plain dial with no tunnel to go through (unlike the userspace Backend's Dial, which dials through its netstack).

func (*Backend) EnsureWG

func (b *Backend) EnsureWG(cfg dataplane.WGConfig) ([]string, error)

EnsureWG converges the kernel wg interface to cfg (design.md 4, 9 節).

func (*Backend) OtherDeviceWithKey

func (b *Backend) OtherDeviceWithKey(key wgtypes.Key) (string, bool)

OtherDeviceWithKey reports another kernel WireGuard device with the same private key, if any (interface rename detection; not part of dataplane.Backend, vpsd calls it directly).

func (*Backend) Prepare

func (b *Backend) Prepare(d dataplane.Desired) (dataplane.Prepared, error)

Prepare stages d without publishing it. nft.Apply's build and Flush happen together as one atomic kernel operation in Commit, so there is nothing to stage here yet (design.md 7a.2 節); moving the build into Prepare is Phase 4's job.

func (*Backend) ReadDrops

func (b *Backend) ReadDrops() ([]dataplane.Drop, error)

ReadDrops reads table inet wgft's per-rule drop counters. They are reset by the next successful table replacement (nft.Apply, called from Commit); if that replacement fails, the next ReadDrops returns the same counts again (design.md 6.1 節).

func (*Backend) WGStatus

func (b *Backend) WGStatus() (*wgtypes.Device, error)

WGStatus reports the kernel wg interface's current peers.

type Options

type Options struct {
	// Interface は wg インタフェース名(既定 wgft0)。
	Interface string
	// AdoptExisting が真のときだけ、鍵の一致しない既存インタフェースを引き継ぐ(design.md 9 節)。
	AdoptExisting bool
}

Options configures a Backend. Interface と AdoptExisting は kernel の wg インタフェースだけの 性質なので、宣言(dataplane.WGConfig)ではなく construction 時にここで固定する(dataplane.WGConfig のドキュメントコメントのとおり)。

Directories

Path Synopsis
Package conntrack は、外から入って DNAT されたフローを Plan に収束させる(仕様 6.1 節、 設計文書 7a.8 節 Phase 3)。
Package conntrack は、外から入って DNAT されたフローを Plan に収束させる(仕様 6.1 節、 設計文書 7a.8 節 Phase 3)。
Package nft は、Plan から VPS の table inet wgft を組み立てて適用する(仕様 6.1 節、設計文書 7a.2 節)。
Package nft は、Plan から VPS の table inet wgft を組み立てて適用する(仕様 6.1 節、設計文書 7a.2 節)。
Package wg は VPS(および将来の agent の kernel backend、Phase 7)の WireGuard インタフェースを 宣言に収束させる(仕様 4, 9 節、設計文書 7a.7 節)。
Package wg は VPS(および将来の agent の kernel backend、Phase 7)の WireGuard インタフェースを 宣言に収束させる(仕様 4, 9 節、設計文書 7a.7 節)。

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL