Documentation
¶
Overview ¶
Package userspace is the userspace dataplane Backend (design.md 6.3, 7a.7 節). It uses neither kernel WireGuard nor nftables nor conntrack: a wireguard-go + netstack tunnel (utun), the Go admission evaluator (srcpolicy) in place of nftables, and the shared relay (relay) turned around so that it accepts on the host's public ports and dials the agents through the netstack.
Everything the Backend converges to comes from the Plan it is given (design.md 7a.2 節): Transparent ports become relay listeners, Plan.Admission feeds the evaluator and the per-source flow caps. Only process-wide budgets (Resource Guard, design.md 7a.5 節) are fixed at New.
Index ¶
- type Backend
- func (b *Backend) Converge(planner.Plan) (int, error)
- func (b *Backend) Dial(network, addr string) (net.Conn, error)
- func (b *Backend) EnsureWG(cfg dataplane.WGConfig) ([]string, error)
- func (b *Backend) Prepare(d dataplane.Desired) (dataplane.Prepared, error)
- func (b *Backend) ReadDrops() ([]dataplane.Drop, error)
- func (b *Backend) TCPCounter() *flowcap.Counter
- func (b *Backend) WGStatus() (*wgtypes.Device, error)
- type Options
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Backend ¶
type Backend struct {
// contains filtered or unexported fields
}
Backend is the userspace dataplane. It implements dataplane.Backend.
func New ¶
New builds a Backend with no tunnel and no listeners; EnsureWG brings the tunnel up and the first Commit opens the listeners. The per-source caps are off until that first Commit sets them from its Plan, before it opens any listener.
func (*Backend) Converge ¶
Converge closes the relay sessions the committed admission policy no longer allows (in place of conntrack convergence, design.md 6.3 節). It reads the policy Commit installed, so it does not need the Plan again.
func (*Backend) Dial ¶
Dial connects to an agent through the netstack. The relay, the server's Relay frontend and the connectivity check all dial with it.
func (*Backend) Prepare ¶
Prepare stages d. The userspace backend has no reversible stage yet: relay.Manager.Apply binds and starts serving each port in one step, and a port that fails to bind is recorded and retried by the relay rather than failing the whole change. So Prepare only keeps the Plan and cannot fail, and Commit does the work and cannot fail either. This is how the userspace mode applied rules before the Backend existed; Phase 4 (design.md 7a.3, 7a.8 節) moves binding into Prepare.
d.RelayListening is not used: the kernel backend needs it to give Relay ports per-source flow rows (design.md 6.1 節), while in userspace mode the Relay frontend counts per source itself through the shared TCPCounter.
func (*Backend) TCPCounter ¶
TCPCounter is the TCP flow counter the relay uses. The server hands it to its Relay frontend so that both count against one TCP budget, per source included, in userspace mode (design.md 7 節).
type Options ¶
type Options struct {
// Limits gives the process-wide flow budgets and the per-rule isolation derived from them
// (design.md 7 節 and 7a.5 節, Resource Guard). Its per-source caps are not read here: those
// are Admission Policy and come with every Plan (Plan.Admission.PerSourceFlowCaps).
Limits flowcap.Limits
// Logf is where the Backend and its tunnel log. nil means log.Printf.
Logf func(format string, args ...any)
}
Options configures a Backend.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package relay は、エージェントの netstack 上のリスナーと、LAN 内の target への中継を持つ(仕様 7 節)。
|
Package relay は、エージェントの netstack 上のリスナーと、LAN 内の target への中継を持つ(仕様 7 節)。 |
|
Package srcpolicy はユーザースペースモード(nftables を使わない転送)向けに、 接続元制限とレート制限を Go で評価する。
|
Package srcpolicy はユーザースペースモード(nftables を使わない転送)向けに、 接続元制限とレート制限を Go で評価する。 |
|
Package utun は、ユーザー空間モード(仕様 6.3 節)の VPS 側トンネル。
|
Package utun は、ユーザー空間モード(仕様 6.3 節)の VPS 側トンネル。 |