chore: rebrand backone names, add lint gate + agent docs
- CI: build/validate use backone selftest + binary names, add lint.yml - make-*.mk: emit/install backone binaries, drop zerotier-one paths - doc/debian/ext.installfiles: backone manpages, service, init, te - rule-compiler: npm test runs test.js; attic world planet files - AGENTS.md repository guidelines, tools/lint.sh changed-lines gate - gitignore: /backone-selftest, *.gcno, *.gcda
This commit is contained in:
1 parent
104d781614
commit
c550fe0684
37 files changed
+864
-548
No files matched your search
@@ -31,14 +31,14 @@ jobs:
|
|||||||
- name: selftest
|
- name: selftest
|
||||||
run: |
|
run: |
|
||||||
make selftest
|
make selftest
|
||||||
./zerotier-selftest
|
./backone-selftest
|
||||||
- name: 'Tar files' # keeps permissions (execute)
|
- name: 'Tar files' # keeps permissions (execute)
|
||||||
run: tar -cvf zerotier-one.tar zerotier-one
|
run: tar -cvf backone.tar backone
|
||||||
- name: Archive production artifacts
|
- name: Archive production artifacts
|
||||||
uses: actions/upload-artifact@v4
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: zerotier-one-ubuntu-x64
|
name: backone-ubuntu-x64
|
||||||
path: zerotier-one.tar
|
path: backone.tar
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
|
|
||||||
build_macos:
|
build_macos:
|
||||||
@@ -75,14 +75,14 @@ jobs:
|
|||||||
- name: selftest
|
- name: selftest
|
||||||
run: |
|
run: |
|
||||||
make selftest
|
make selftest
|
||||||
./zerotier-selftest
|
./backone-selftest
|
||||||
- name: 'Tar files' # keeps permissions (execute)
|
- name: 'Tar files' # keeps permissions (execute)
|
||||||
run: tar -cvf zerotier-one.tar zerotier-one
|
run: tar -cvf backone.tar backone
|
||||||
- name: Archive production artifacts
|
- name: Archive production artifacts
|
||||||
uses: actions/upload-artifact@v4
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: zerotier-one-mac
|
name: backone-mac
|
||||||
path: zerotier-one.tar
|
path: backone.tar
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
|
|
||||||
|
|
||||||
@@ -118,6 +118,6 @@ jobs:
|
|||||||
- name: Archive production artifacts
|
- name: Archive production artifacts
|
||||||
uses: actions/upload-artifact@v4
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: zerotier-one-windows
|
name: backone-windows
|
||||||
path: windows/Build
|
path: windows/Build
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
name: Lint
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
clang-format:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
# Pin: format results differ across clang-format versions.
|
||||||
|
- run: pip install --user clang-format==23.1.1 && echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
||||||
|
- name: Check changed lines
|
||||||
|
run: |
|
||||||
|
if [ "${{ github.event_name }}" = "pull_request" ]; then
|
||||||
|
BASE="${{ github.event.pull_request.base.sha }}"
|
||||||
|
elif [ "${{ github.event.before }}" != "" ] && [ "${{ github.event.before }}" != "0000000000000000000000000000000000000000" ]; then
|
||||||
|
BASE="${{ github.event.before }}"
|
||||||
|
else
|
||||||
|
BASE="$(git merge-base HEAD "origin/${{ github.event.repository.default_branch }}" || echo HEAD~1)"
|
||||||
|
fi
|
||||||
|
./tools/lint.sh "$BASE"
|
||||||
@@ -38,9 +38,9 @@ test() {
|
|||||||
export NS1="ip netns exec ns1"
|
export NS1="ip netns exec ns1"
|
||||||
export NS2="ip netns exec ns2"
|
export NS2="ip netns exec ns2"
|
||||||
|
|
||||||
export ZT1="$NS1 ./zerotier-cli -p9996 -D$(pwd)/node1"
|
export ZT1="$NS1 ./backone-cli -p9996 -D$(pwd)/node1"
|
||||||
# Specify custom port on one node to ensure that feature works
|
# Specify custom port on one node to ensure that feature works
|
||||||
export ZT2="$NS2 ./zerotier-cli -p9997 -D$(pwd)/node2"
|
export ZT2="$NS2 ./backone-cli -p9997 -D$(pwd)/node2"
|
||||||
|
|
||||||
echo -e "\nSetting up network namespaces..."
|
echo -e "\nSetting up network namespaces..."
|
||||||
echo "Setting up ns1"
|
echo "Setting up ns1"
|
||||||
@@ -102,13 +102,13 @@ test() {
|
|||||||
--xml=yes \
|
--xml=yes \
|
||||||
--xml-file=$FILENAME_MEMORY_LOG \
|
--xml-file=$FILENAME_MEMORY_LOG \
|
||||||
--leak-check=full \
|
--leak-check=full \
|
||||||
./zerotier-one node1 -p$ZT_PORT_NODE_1 -U >>node_1.log 2>&1 &
|
./backone node1 -p$ZT_PORT_NODE_1 -U >>node_1.log 2>&1 &
|
||||||
|
|
||||||
# Second instance, not run in memory profiler
|
# Second instance, not run in memory profiler
|
||||||
# Don't set up internet access until _after_ zerotier is running
|
# Don't set up internet access until _after_ zerotier is running
|
||||||
# This has been a source of stuckness in the past.
|
# This has been a source of stuckness in the past.
|
||||||
$NS2 ip addr del 192.168.1.2/24 dev veth3
|
$NS2 ip addr del 192.168.1.2/24 dev veth3
|
||||||
$NS2 sudo ./zerotier-one node2 -U -p$ZT_PORT_NODE_2 >>node_2.log 2>&1 &
|
$NS2 sudo ./backone node2 -U -p$ZT_PORT_NODE_2 >>node_2.log 2>&1 &
|
||||||
|
|
||||||
sleep 10; # New HTTP control plane is a bit sluggish, so we delay here
|
sleep 10; # New HTTP control plane is a bit sluggish, so we delay here
|
||||||
|
|
||||||
@@ -170,9 +170,9 @@ test() {
|
|||||||
|
|
||||||
echo -e "\n\nRunning ZeroTier processes:"
|
echo -e "\n\nRunning ZeroTier processes:"
|
||||||
echo -e "\nNode 1:\n"
|
echo -e "\nNode 1:\n"
|
||||||
$NS1 ps aux | grep zerotier-one
|
$NS1 ps aux | grep backone
|
||||||
echo -e "\nNode 2:\n"
|
echo -e "\nNode 2:\n"
|
||||||
$NS2 ps aux | grep zerotier-one
|
$NS2 ps aux | grep backone
|
||||||
|
|
||||||
echo -e "\n\nStatus of each instance:"
|
echo -e "\n\nStatus of each instance:"
|
||||||
|
|
||||||
@@ -319,10 +319,10 @@ exit_test_and_generate_report() {
|
|||||||
node2_id=$($ZT2 -j status | jq -r .address)
|
node2_id=$($ZT2 -j status | jq -r .address)
|
||||||
|
|
||||||
$ZT1 dump
|
$ZT1 dump
|
||||||
mv zerotier_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node1_id.txt"
|
mv backone_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node1_id.txt"
|
||||||
|
|
||||||
$ZT2 dump
|
$ZT2 dump
|
||||||
mv zerotier_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node2_id.txt"
|
mv backone_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node2_id.txt"
|
||||||
|
|
||||||
# Copy ZeroTier stdout/stderr logs
|
# Copy ZeroTier stdout/stderr logs
|
||||||
|
|
||||||
@@ -386,7 +386,7 @@ exit_test_and_generate_report() {
|
|||||||
"commit":"$ZTO_COMMIT",
|
"commit":"$ZTO_COMMIT",
|
||||||
"arch_m":"$(uname -m)",
|
"arch_m":"$(uname -m)",
|
||||||
"arch_a":"$(uname -a)",
|
"arch_a":"$(uname -a)",
|
||||||
"binary_size":"$(stat -c %s zerotier-one)",
|
"binary_size":"$(stat -c %s backone)",
|
||||||
"time_length_test":$time_length_test,
|
"time_length_test":$time_length_test,
|
||||||
"time_to_both_nodes_online":$time_to_both_nodes_online,
|
"time_to_both_nodes_online":$time_to_both_nodes_online,
|
||||||
"num_possible_bytes_lost": $POSSIBLY_LOST,
|
"num_possible_bytes_lost": $POSSIBLY_LOST,
|
||||||
@@ -448,7 +448,7 @@ spam_cli() {
|
|||||||
check_exit_on_invalid_identity() {
|
check_exit_on_invalid_identity() {
|
||||||
echo "Checking ZeroTier exits on invalid identity..."
|
echo "Checking ZeroTier exits on invalid identity..."
|
||||||
mkdir -p $(pwd)/exit_test
|
mkdir -p $(pwd)/exit_test
|
||||||
ZT1="sudo ./zerotier-one -p9999 $(pwd)/exit_test"
|
ZT1="sudo ./backone -p9999 $(pwd)/exit_test"
|
||||||
echo "asdfasdfasdfasdf" > $(pwd)/exit_test/identity.secret
|
echo "asdfasdfasdfasdf" > $(pwd)/exit_test/identity.secret
|
||||||
echo "asdfasdfasdfasdf" > $(pwd)/exit_test/authtoken.secret
|
echo "asdfasdfasdfasdf" > $(pwd)/exit_test/authtoken.secret
|
||||||
|
|
||||||
@@ -473,20 +473,20 @@ check_exit_on_invalid_identity() {
|
|||||||
check_bind_to_correct_ports() {
|
check_bind_to_correct_ports() {
|
||||||
PORT_NUMBER=$1
|
PORT_NUMBER=$1
|
||||||
echo "Checking bound ports:"
|
echo "Checking bound ports:"
|
||||||
sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier"
|
sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone"
|
||||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier" | grep "tcp") ]];
|
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone" | grep "tcp") ]];
|
||||||
then
|
then
|
||||||
:
|
:
|
||||||
else
|
else
|
||||||
exit_test_and_generate_report $TEST_FAIL "ZeroTier did not bind to tcp/$1"
|
exit_test_and_generate_report $TEST_FAIL "ZeroTier did not bind to tcp/$1"
|
||||||
fi
|
fi
|
||||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier" | grep "tcp6") ]];
|
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone" | grep "tcp6") ]];
|
||||||
then
|
then
|
||||||
:
|
:
|
||||||
else
|
else
|
||||||
exit_test_and_generate_report $TEST_FAIL "ZeroTier did not bind to tcp6/$1"
|
exit_test_and_generate_report $TEST_FAIL "ZeroTier did not bind to tcp6/$1"
|
||||||
fi
|
fi
|
||||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier" | grep "udp") ]];
|
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone" | grep "udp") ]];
|
||||||
then
|
then
|
||||||
:
|
:
|
||||||
else
|
else
|
||||||
|
|||||||
@@ -154,3 +154,7 @@ rustybits/
|
|||||||
backone
|
backone
|
||||||
backone-cli
|
backone-cli
|
||||||
backone-idtool
|
backone-idtool
|
||||||
|
|
||||||
|
/backone-selftest
|
||||||
|
*.gcno
|
||||||
|
*.gcda
|
||||||
@@ -0,0 +1,117 @@
|
|||||||
|
# Repository Guidelines
|
||||||
|
|
||||||
|
## Project Overview
|
||||||
|
|
||||||
|
BackOne — fork of ZeroTier 1.14.1: peer-to-peer SDN daemon. Builds virtual Ethernet (TUN/TAP), tunnels L2 frames over encrypted UDP mesh, issues membership certs from an embedded controller. One fat binary `backone` doubles as CLI (`backone-cli`) and identity tool (`backone-idtool`) via `argv[0]` dispatch (`one.cpp:2140-2142`). Local JSON API on `127.0.0.1:9993`.
|
||||||
|
|
||||||
|
## Architecture & Data Flow
|
||||||
|
|
||||||
|
Four layers, top → bottom:
|
||||||
|
|
||||||
|
1. **Entry** — `one.cpp`: `main()` → `cli()` / `idtool()` / daemon → `OneService::newInstance()` + `run()`.
|
||||||
|
2. **Service** — `service/OneService.cpp` (`OneServiceImpl`, line 776): owns sockets (`Phy<>`), httplib control plane, TAP devices, `Node`, `EmbeddedNetworkController`, main loop.
|
||||||
|
3. **Core** — `node/`: OS-independent switch. Reached only through the C API (`ZT_Node_*` in `include/ZeroTierOne.h`, implemented at bottom of `node/Node.cpp`).
|
||||||
|
4. **OS glue** — `osdep/`: `Phy` (select()-based reactor, the only event loop), `EthernetTap` (per-OS TUN/TAP), `OSUtils`, `ManagedRoute`, `Thread`, `BlockingQueue`.
|
||||||
|
|
||||||
|
**Core pattern = inversion of control.** `OneServiceImpl` fills `struct ZT_Node_Callbacks` (`service/OneService.cpp:1045-1054`) with `Snode*` static functions; `node/` never touches OS code, it calls back. Shared context is `RuntimeEnvironment` passed as `const RuntimeEnvironment *RR` to every `node/` function (`node/RuntimeEnvironment.hpp`).
|
||||||
|
|
||||||
|
Flows:
|
||||||
|
|
||||||
|
- **Wire → app:** `Phy::poll` → `phyOnDatagram` (`service/OneService.cpp:2940`) → `Node::processWirePacket` (`node/Node.cpp:206`) → `Switch::onRemotePacket` → verb dispatch `switch` (`node/IncomingPacket.cpp:94-151`) → peer/network/crypto. Heavy work offloaded to `PacketMultiplexer` worker threads.
|
||||||
|
- **App → wire:** TAP handler → `tapFrameHandler` (`service/OneService.cpp:3776`) → `Node::processVirtualNetworkFrame` → `Switch::onLocalEthernet` → `Peer`/`Path` → `_phy.udpSend`.
|
||||||
|
- **Controller:** `IncomingPacket::_doNETWORK_CONFIG_REQUEST` → `EmbeddedNetworkController::request` posts `_RQEntry*` to `BlockingQueue` → `hardware_concurrency()` workers → `DBMirrorSet`/`DB` → signed cert back via `NetworkController::Sender`.
|
||||||
|
- **Main loop** (`OneServiceImpl::run`, `service/OneService.cpp:~1150-1310`): single-threaded, time-sliced; refresh binds → `processBackgroundTasks` when due → `_phy.poll(delay)`. `Phy::whack()` (self-pipe) is the only cross-thread-safe Phy call.
|
||||||
|
|
||||||
|
## Key Directories
|
||||||
|
|
||||||
|
| Path | Purpose |
|
||||||
|
|---|---|
|
||||||
|
| `one.cpp` | Daemon/CLI/idtool entry; privilege drop, daemonize, signals |
|
||||||
|
| `node/` | Overlay engine: `Switch`, `Topology`, `Peer`, `IncomingPacket`, `Identity`, `Bond`, `Metrics` — OS-independent by rule |
|
||||||
|
| `service/` | `OneService` (whole runtime), `SoftwareUpdater` |
|
||||||
|
| `controller/` | `EmbeddedNetworkController` + `DB` backends (FileDB default, LFDB, PostgreSQL, Redis) |
|
||||||
|
| `osdep/` | All OS-dependent code: `Phy`, `EthernetTap*`, `Binder`, `ManagedRoute`, netlink/DNS helpers |
|
||||||
|
| `include/` | Public C API (`ZeroTierOne.h`, 57KB) — changes ripple to Java/libzt/SDK |
|
||||||
|
| `ext/` | Vendored: nlohmann/json, cpp-httplib, prometheus-cpp-lite, libpqxx, redis++, miniupnpc, ASM crypto |
|
||||||
|
| `rustybits/` | Cargo workspace: `zeroidc` (SSO FFI), `smeeclient` (PostgreSQL workflow client) |
|
||||||
|
| `java/` | JNI wrapper (`java/jni/…Node.cpp`, ant build) |
|
||||||
|
| `tcp-proxy/` | Standalone TCP fallback relay; own Makefile (C++11) |
|
||||||
|
| `rule-compiler/` | JS network-rules compiler (`node cli.js <rules>`), npm |
|
||||||
|
| `pkg/`, `debian/`, `windows/` | Packaging (snap/QNAP/Synology/ASUSTOR/WD, RPM `backone.spec`, MSVC sln) |
|
||||||
|
|
||||||
|
## Development Commands
|
||||||
|
|
||||||
|
```sh
|
||||||
|
make # = make one → ./backone + backone-cli/backone-idtool symlinks
|
||||||
|
make -j$(nproc) one
|
||||||
|
make core # libbackonecore.a
|
||||||
|
make selftest && ./backone-selftest
|
||||||
|
make debug # ZT_DEBUG=1 (adds -g, forces ZT_TRACE=1)
|
||||||
|
make ZT_SANITIZE=1 one # ASan
|
||||||
|
make central-controller # ZT_CONTROLLER=1 (needs ext/ libpqxx + hiredis + redis++)
|
||||||
|
make install DESTDIR=/tmp/root
|
||||||
|
make debian | make redhat # debuild / rpmbuild
|
||||||
|
make manpages # cd doc && ./build.sh (needs ronn or node marked-man)
|
||||||
|
cd rustybits && cargo build # zeroidc/smeeclient (also auto via `make zeroidc`)
|
||||||
|
cd java && ant build_java | build_android | build_jar
|
||||||
|
cd tcp-proxy && make
|
||||||
|
```
|
||||||
|
|
||||||
|
`Makefile` is a uname dispatcher → `make-linux.mk` / `make-mac.mk` / `make-bsd.mk` / `make-netbsd.mk`. Windows: `MSBuild windows/ZeroTierOne.sln /property:Configuration=Release`. Top-level `CMakeLists.txt` is a 323B stub — never `cmake .` as product build.
|
||||||
|
|
||||||
|
Env knobs (make vars): `ZT_DEBUG`, `ZT_TRACE`, `ZT_SANITIZE`, `ZT_STATIC`, `ZT_OFFICIAL`, `ZT_CONTROLLER`, `ZT_SSO_SUPPORTED` (0 on Linux default → no cargo needed), `ZT_VAULT_SUPPORT`, `ZT_IA32`.
|
||||||
|
|
||||||
|
## Code Conventions & Common Patterns
|
||||||
|
|
||||||
|
- **Standard: C++17** (`-std=c++17` in all makefiles; `tcp-proxy` is C++11). Ignore stale comments claiming otherwise (`node/README.md` "No C++11", `osdep/BlockingQueue.hpp:30`).
|
||||||
|
- **Formatting**: `.clang-format` — LLVM base, **tabs always**, indent 4, Stroustrup braces, `BinPackArguments: false`, `PointerAlignment: Left`. Gate: `make lint` → `tools/lint.sh` (clang-format on lines changed vs base commit; `--all` checks whole files — whole repo has format debt, don't reformat untouched lines). No clang-tidy, no `-Werror`.
|
||||||
|
- **Namespace**: everything in `namespace ZeroTier { … }`, close with `} // namespace ZeroTier`. File-local helpers in anonymous namespace or `static`.
|
||||||
|
- **Naming**: classes `PascalCase`; methods `camelCase`; private members `_camelCase`; static C callbacks `S` + class (`SnodeWirePacketSendFunction`); macros/enums `ZT_UPPER_SNAKE`; include guards `ZT_<NAME>_HPP` (no `#pragma once`).
|
||||||
|
- **Includes**: quoted relative (`"../node/Constants.hpp"` from subdirs, `"node/Constants.hpp"` from root). Third-party via angle brackets resolved by `-isystem ext`. `node/Constants.hpp` FIRST in `node/` files — canonicalizes `__LINUX__`/`__APPLE__`/`__UNIX_LIKE__`/`__WINDOWS__`; never test raw `__linux__`/`_WIN32`.
|
||||||
|
- **Error handling**: three regimes — (1) C API boundary returns `ZT_ResultCode`, fatal = 100–999, checked via `ZT_ResultCode_isFatal`; (2) `node/` throws bare ints (`ZT_EXCEPTION_OUT_OF_BOUNDS`, `node/Constants.hpp:757+`), caught as `catch (int e)` in `OneServiceImpl::run`; (3) service/controller use `std::exception`/`catch (...)` at thread boundaries. **No exceptions across the C API.**
|
||||||
|
- **Threading**: no global lock; per-object `ZeroTier::Mutex` scoped guard (`Mutex::Lock _l(_m);`) or `std::mutex` + `lock_guard`/`shared_lock` in controller. Cross-thread wake only via `Phy::whack()`; producer/consumer via `BlockingQueue<T>`. Threads: `std::thread`.
|
||||||
|
- **Async**: single-threaded reactor (`Phy::poll` callbacks), not futures; no `std::async`/`future` in C++ paths (tokio only inside `rustybits/smeeclient`).
|
||||||
|
- **Memory**: raw `new`/`delete` in service/controller; intrusive `SharedPtr<T>` (`node/SharedPtr.hpp` — class needs `friend class SharedPtr<X>` + `AtomicCounter __refCount`) for `Peer`/`Network`/`Path`; `std::shared_ptr` for `DB` backends. Zero secrets with `Utils::burn`.
|
||||||
|
- **DI/state**: no framework. Two seams only: `ZT_Node_Callbacks` function-pointer struct (core ↔ OS) and `const RuntimeEnvironment *RR` as first param. Controller injected via `Node::setNetconfMaster`.
|
||||||
|
- **JSON**: `nlohmann::json` + typed accessors `OSUtils::jsonString/jsonInt/jsonBool` (defaults); API is type-sensitive.
|
||||||
|
- **Metrics**: `node/Metrics.hpp` namespace, increment inline (`Metrics::udp_recv += len;`).
|
||||||
|
- **License header**: every new `.cpp/.hpp/.h` gets the 11-line BSL block verbatim (copy `node/Mutex.hpp:1-12`).
|
||||||
|
- **Placement rule**: sockets/files/interfaces → `osdep/`; orchestration → `service/`; persistence → `controller/`; `node/` stays OS-independent. New compiled file must be added to `objects.mk` (`CORE_OBJS` or `ONE_OBJS`) or it won't link.
|
||||||
|
|
||||||
|
## Important Files
|
||||||
|
|
||||||
|
Read before editing:
|
||||||
|
|
||||||
|
1. `include/ZeroTierOne.h` — public contract (`ZT_Node_Callbacks:1733`, `ZT_ResultCode:375`); ripples to Java/SDK.
|
||||||
|
2. `node/Constants.hpp` — platform macros, exception ints, constants; include first.
|
||||||
|
3. `node/RuntimeEnvironment.hpp` — object graph every `node/` fn navigates.
|
||||||
|
4. `service/OneService.cpp` lines 690–1100 (callback table) and 1150–1400 (`run()` loop) — the integration seam.
|
||||||
|
5. `osdep/Phy.hpp` lines 55–160 — handler contract for any socket behavior.
|
||||||
|
6. `objects.mk` + `make-linux.mk:12,62-73,370-457` — what compiles with which flags.
|
||||||
|
7. Per-dir READMEs: `service/README.md` (local.conf schema + JSON API — primary ops doc), `controller/README.md`, `node/README.md`.
|
||||||
|
|
||||||
|
Module-specific: wire protocol → `node/IncomingPacket.cpp:94-151` + `node/Packet.hpp`; routing → `node/Switch.cpp`; DB backend → `controller/DB.hpp` + `EmbeddedNetworkController.cpp:465-580`; TAP → `osdep/EthernetTap.cpp`.
|
||||||
|
|
||||||
|
## Runtime/Tooling Preferences
|
||||||
|
|
||||||
|
- **Build**: GNU make (g++ or clang auto-detected, `make-linux.mk:3-10`); MSVC on Windows; ant + NDK for Java; cargo for `rustybits/`; npm for `rule-compiler/`.
|
||||||
|
- **No package manager for C++** — deps vendored in `ext/` (do not add new ones casually).
|
||||||
|
- **Daemon paths (Linux)**: home `/var/lib/backone` (macOS: `/Library/Application Support/BackOne`); port 9993; key files `identity.secret`, `authtoken.secret`, `networks.d/`, `local.conf`, `controller.db`. Unprivileged CLI: `cp authtoken.secret ~/.backOneOneAuthToken` (source: `one.cpp:283`).
|
||||||
|
- **CLI**: `backone-cli info|listpeers|listnetworks|join <nwid>|leave <nwid>` (`-j` JSON, `-p<port>`, `-D<dir>`); `backone-idtool generate|validate|getpublic|sign|verify|mkcom`.
|
||||||
|
- **Dangerous scripts**: `update_controllers.sh`, `cycle_controllers.sh` are live ZeroTier-Central kubectl ops — never run locally.
|
||||||
|
- **Rebrand is partial**: build outputs, CI (`build.yml`, `validate-linux.sh`), `Dockerfile.ci`, `make-bsd.mk`/`make-netbsd.mk`, and debian units now use `backone*`. Still upstream-named: `pkg/snap/snapcraft.yaml` (builds `github.com/zerotier/zerotierone.git` → broken) and cosmetic strings (`/etc/zerotier-version` in `Dockerfile.ci`, `windows/zerotier-cli.bat`, `pkg/` vendor paths). Expect occasional `zerotier-*` names in docs/scripts.
|
||||||
|
|
||||||
|
## Testing & QA
|
||||||
|
|
||||||
|
No C++ unit framework. Practical loop:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
make selftest && ./backone-selftest # crypto KATs, identity, certs, packet codec, Phy loopback; non-zero exit on failure
|
||||||
|
make debug # ZT_DEBUG=1 build of one + selftest
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Sections** in `selftest.cpp`: `testCrypto`, `testIdentity`, `testCertificate`, `testPacket`, `testOther`, `testPhy` (binds 127.0.0.1 UDP/TCP loopback; no root needed).
|
||||||
|
- **CI** (`.github/workflows/`): `build.yml` = build smoke (`make`, `make selftest`); `validate.yml` = `make one ZT_COVERAGE=1 ZT_TRACE=1` then `.github/workflows/validate-linux.sh` (two-node netns + ping + iperf3 + valgrind) and `validate-report.sh` (fails on any definite leak or non-zero test exit — the only hard gate). `ZT_COVERAGE=1` adds `--coverage` flags (`make-linux.mk:322-326`); coverage recorded via gcovr, never thresholded.
|
||||||
|
- **Lint/format**: `make lint` → `tools/lint.sh` (clang-format on changed lines vs base; CI: `.github/workflows/lint.yml`, clang-format pinned 23.1.1). No clang-tidy, no `-Werror`. Do not reformat untouched lines.
|
||||||
|
- **Gaps**: no Rust tests, no Java tests (orphaned `java/test/` deleted), no `make test`/`check` target. Prefer extending `selftest.cpp` for regression coverage; `rule-compiler` has `npm test` (real, `rule-compiler/test.js`).
|
||||||
|
- **Windows smoke** (`windows/README.md`): run exe `-p9994 -C <tmpdir>` then `zerotier-cli.bat -p9994 -D<tmpdir> info|join`.
|
||||||
+6
-5
@@ -6,16 +6,17 @@ RUN apt-get update -qq && apt-get -qq install make clang
|
|||||||
COPY . .
|
COPY . .
|
||||||
RUN /usr/bin/make
|
RUN /usr/bin/make
|
||||||
RUN echo $PWD
|
RUN echo $PWD
|
||||||
RUN cp zerotier-one /usr/sbin
|
RUN cp backone /usr/sbin
|
||||||
|
|
||||||
FROM ubuntu:21.04
|
FROM ubuntu:21.04
|
||||||
|
|
||||||
COPY --from=stage /zerotier-one /usr/sbin
|
COPY --from=stage /backone /usr/sbin
|
||||||
RUN ln -sf /usr/sbin/zerotier-one /usr/sbin/zerotier-idtool
|
RUN ln -sf /usr/sbin/backone /usr/sbin/backone-idtool
|
||||||
RUN ln -sf /usr/sbin/zerotier-one /usr/sbin/zerotier-cli
|
RUN ln -sf /usr/sbin/backone /usr/sbin/backone-cli
|
||||||
|
|
||||||
RUN echo "${VERSION}" > /etc/zerotier-version
|
RUN echo "${VERSION}" > /etc/zerotier-version
|
||||||
RUN rm -rf /var/lib/zerotier-one
|
RUN rm -rf /var/lib/backone
|
||||||
|
ENV ZEROTIER_HOME=/var/lib/backone ZT_PID_FILE=backone.pid ZT_PORT_FILE=backone.port ZT_DAEMON=/usr/sbin/backone ZT_CLI=backone-cli
|
||||||
|
|
||||||
|
|
||||||
RUN apt-get -qq update
|
RUN apt-get -qq update
|
||||||
|
|||||||
@@ -27,6 +27,9 @@ ifeq ($(OSTYPE),NetBSD)
|
|||||||
include make-netbsd.mk
|
include make-netbsd.mk
|
||||||
endif
|
endif
|
||||||
|
|
||||||
|
lint:
|
||||||
|
@./tools/lint.sh
|
||||||
|
|
||||||
drone:
|
drone:
|
||||||
@echo "rendering .drone.yaml from .drone.jsonnet"
|
@echo "rendering .drone.yaml from .drone.jsonnet"
|
||||||
drone jsonnet --format --stream
|
drone jsonnet --format --stream
|
||||||
|
|||||||
+29
-23
@@ -82,35 +82,41 @@ int main(int argc,char **argv)
|
|||||||
|
|
||||||
const uint64_t id = ZT_WORLD_ID_EARTH;
|
const uint64_t id = ZT_WORLD_ID_EARTH;
|
||||||
const uint64_t ts = 1567191349589ULL; // August 30th, 2019
|
const uint64_t ts = 1567191349589ULL; // August 30th, 2019
|
||||||
|
//const uint64_t ts = 1778645159589ULL; // May 13th, 2026
|
||||||
|
|
||||||
// Los Angeles
|
// MVNET server1.saltis.id
|
||||||
roots.push_back(World::Root());
|
roots.push_back(World::Root());
|
||||||
roots.back().identity = Identity("3a46f1bf30:0:76e66fab33e28549a62ee2064d1843273c2c300ba45c3f20bef02dbad225723bb59a9bb4b13535730961aeecf5a163ace477cceb0727025b99ac14a5166a09a3");
|
roots.back().identity = Identity("41cff2b17b:0:1f62d405a755ed8522e903edee7e2166fa357658a6cac8e6739b9e463898107538f09419e5cf5c2d139468c04ad1e0a08b59680ee2f07b2e50e670f81fd1dc3d");
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("185.180.13.82/9993"));
|
roots.back().stableEndpoints.push_back(InetAddress("103.80.237.27/9993"));
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("2a02:6ea0:c815::/9993"));
|
|
||||||
|
|
||||||
// Miami
|
// MVNET server2.saltis.id
|
||||||
roots.push_back(World::Root());
|
roots.push_back(World::Root());
|
||||||
roots.back().identity = Identity("de8950a8b2:0:1b3ada8251b91b6b6fa6535b8c7e2460918f4f729abdec97d3c7f3796868fb02f0de0b0ee554b2d59fc3524743eebfcf5315e790ed6d92db5bd10c28c09b40ef");
|
roots.back().identity = Identity("e4bfc89a12:0:93f764c53030b11c4b9f824cdade6fb731d26b5150f326ca484dbb3acb33a065d5431524fe7ce517512b13c21c4ab5edb04a2e145cefa33ffdf39a855b966c21");
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("207.246.73.245/443"));
|
roots.back().stableEndpoints.push_back(InetAddress("103.80.237.163/9993"));
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("2001:19f0:9002:5cb:ec4:7aff:fe8f:69d9/443"));
|
|
||||||
|
|
||||||
// Tokyo
|
// IDC server1a.saltis.id
|
||||||
roots.push_back(World::Root());
|
|
||||||
roots.back().identity = Identity("34e0a5e174:0:93efb50934788f856d5cfb9ca5be88e85b40965586b75befac900df77352c145a1ba7007569d37c77bfe52c0999f3bdc67a47a4a6000b720a883ce47aa2fb7f8");
|
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("147.75.92.2/443"));
|
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("2604:1380:3000:7100::1/443"));
|
|
||||||
|
|
||||||
// Amsterdam
|
|
||||||
roots.push_back(World::Root());
|
|
||||||
roots.back().identity = Identity("992fcf1db7:0:206ed59350b31916f749a1f85dffb3a8787dcbf83b8c6e9448d4e3ea0e3369301be716c3609344a9d1533850fb4460c50af43322bcfc8e13d3301a1f1003ceb6");
|
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("195.181.173.159/443"));
|
|
||||||
roots.back().stableEndpoints.push_back(InetAddress("2a02:6ea0:c024::/443"));
|
|
||||||
|
|
||||||
// Alice
|
|
||||||
//roots.push_back(World::Root());
|
//roots.push_back(World::Root());
|
||||||
//roots.back().identity = Identity("9d219039f3:0:01f0922a98e3b34ebcbff333269dc265d7a020aab69d72be4d4acc9c8c9294785771256cd1d942a90d1bd1d2dca3ea84ef7d85afe6611fb43ff0b74126d90a6e");
|
//roots.back().identity = Identity("e620faa6a2:0:f450e2de69d0a70fa3183af50e881a96daac6a736fbb6004492cf97da774de0e003b060ec19e4c9b4288a60a99b4a60464b475ec2d1efb1b0c4a9b924b8f4bf1");
|
||||||
//roots.back().stableEndpoints.push_back(InetAddress("188.166.94.177/9993")); // Amsterdam
|
//roots.back().stableEndpoints.push_back(InetAddress("103.185.47.53/9993"));
|
||||||
|
|
||||||
|
// IDC server2a.saltis.id
|
||||||
|
roots.push_back(World::Root());
|
||||||
|
roots.back().identity = Identity("35b7a18f36:0:e7d0dc4f655c0a2adb72aa9529e97d0fdf1e72bf12a6e753c6b366d88b388b645702edbd8dfeda21c3654f2d73c28fecc7c4713b335ffa61b09e322a7b93c18a");
|
||||||
|
roots.back().stableEndpoints.push_back(InetAddress("103.185.47.52/9993"));
|
||||||
|
|
||||||
|
// GW-Bridge Metro Link
|
||||||
|
//roots.push_back(World::Root());
|
||||||
|
//roots.back().identity = Identity("117cd947d5:0:8b15bfe3798aa1529abf6def4d4d8eb3ff5cbd50c04ddaf7747adc00a55aef5b6666953ee30a2b6c3c852db7426c42760b7d26c63acdc6489fd11bb36690d966");
|
||||||
|
//roots.back().stableEndpoints.push_back(InetAddress("103.87.149.147/9993")); // Amsterdam
|
||||||
|
//roots.back().stableEndpoints.push_back(InetAddress("203.30.255.130/9993")); // Amsterdam
|
||||||
|
//roots.back().stableEndpoints.push_back(InetAddress("192.168.80.5/9993")); // Amsterdam
|
||||||
|
|
||||||
|
// GW-Bridge Metro Link
|
||||||
|
roots.push_back(World::Root());
|
||||||
|
roots.back().identity = Identity("82ff7e0148:0:01a99aac0d7084a59c03831517cdcd9ced2af58bc61de92ab45e0ea2ea86e2692935c84e9923dafce9675f3cc5dd46846d52b5f31e0e6726cb94884b9b6c5518");
|
||||||
|
roots.back().stableEndpoints.push_back(InetAddress("103.87.149.150/9993")); // Amsterdam
|
||||||
|
roots.back().stableEndpoints.push_back(InetAddress("192.168.80.5/9993")); // Amsterdam
|
||||||
|
|
||||||
//roots.back().stableEndpoints.push_back(InetAddress("2a03:b0c0:2:d0::7d:1/9993")); // Amsterdam
|
//roots.back().stableEndpoints.push_back(InetAddress("2a03:b0c0:2:d0::7d:1/9993")); // Amsterdam
|
||||||
//roots.back().stableEndpoints.push_back(InetAddress("154.66.197.33/9993")); // Johannesburg
|
//roots.back().stableEndpoints.push_back(InetAddress("154.66.197.33/9993")); // Johannesburg
|
||||||
//roots.back().stableEndpoints.push_back(InetAddress("2c0f:f850:154:197::33/9993")); // Johannesburg
|
//roots.back().stableEndpoints.push_back(InetAddress("2c0f:f850:154:197::33/9993")); // Johannesburg
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+13
-2
@@ -380,12 +380,23 @@ bool LFDB::save(nlohmann::json &record,bool notifyListeners)
|
|||||||
|
|
||||||
void LFDB::eraseNetwork(const uint64_t networkId)
|
void LFDB::eraseNetwork(const uint64_t networkId)
|
||||||
{
|
{
|
||||||
// TODO
|
nlohmann::json network, nullJson;
|
||||||
|
get(networkId, network);
|
||||||
|
_networkChanged(network, nullJson, true);
|
||||||
|
std::lock_guard<std::mutex> l(_state_l);
|
||||||
|
_state.erase(networkId);
|
||||||
}
|
}
|
||||||
|
|
||||||
void LFDB::eraseMember(const uint64_t networkId,const uint64_t memberId)
|
void LFDB::eraseMember(const uint64_t networkId,const uint64_t memberId)
|
||||||
{
|
{
|
||||||
// TODO
|
nlohmann::json network, member, nullJson;
|
||||||
|
get(networkId, network, memberId, member);
|
||||||
|
_memberChanged(member, nullJson, true);
|
||||||
|
std::lock_guard<std::mutex> l(_state_l);
|
||||||
|
auto nw = _state.find(networkId);
|
||||||
|
if (nw != _state.end()) {
|
||||||
|
nw->second.members.erase(memberId);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
void LFDB::nodeIsOnline(const uint64_t networkId,const uint64_t memberId,const InetAddress &physicalAddress)
|
void LFDB::nodeIsOnline(const uint64_t networkId,const uint64_t memberId,const InetAddress &physicalAddress)
|
||||||
|
|||||||
@@ -199,9 +199,14 @@ PostgreSQL::PostgreSQL(const Identity &myId, const char *path, int listenPort, R
|
|||||||
}
|
}
|
||||||
const char *redisMemberStatus = getenv("ZT_REDIS_MEMBER_STATUS");
|
const char *redisMemberStatus = getenv("ZT_REDIS_MEMBER_STATUS");
|
||||||
if (redisMemberStatus && (strcmp(redisMemberStatus, "true") == 0)) {
|
if (redisMemberStatus && (strcmp(redisMemberStatus, "true") == 0)) {
|
||||||
|
if (_rc != NULL) {
|
||||||
_redisMemberStatus = true;
|
_redisMemberStatus = true;
|
||||||
fprintf(stderr, "Using redis for member status\n");
|
fprintf(stderr, "Using redis for member status\n");
|
||||||
}
|
}
|
||||||
|
else {
|
||||||
|
fprintf(stderr, "ZT_REDIS_MEMBER_STATUS=true ignored: no settings.redis config\n");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
auto c = _pool->borrow();
|
auto c = _pool->borrow();
|
||||||
pqxx::work txn{*c->c};
|
pqxx::work txn{*c->c};
|
||||||
@@ -222,7 +227,7 @@ PostgreSQL::PostgreSQL(const Identity &myId, const char *path, int listenPort, R
|
|||||||
opts.host = _rc->hostname;
|
opts.host = _rc->hostname;
|
||||||
opts.port = _rc->port;
|
opts.port = _rc->port;
|
||||||
opts.password = _rc->password;
|
opts.password = _rc->password;
|
||||||
opts.db = 0;
|
opts.db = _rc->clusterMode ? 0 : _rc->db;
|
||||||
opts.keep_alive = true;
|
opts.keep_alive = true;
|
||||||
opts.connect_timeout = std::chrono::seconds(3);
|
opts.connect_timeout = std::chrono::seconds(3);
|
||||||
poolOpts.size = 25;
|
poolOpts.size = 25;
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ struct RedisConfig {
|
|||||||
int port;
|
int port;
|
||||||
std::string password;
|
std::string password;
|
||||||
bool clusterMode;
|
bool clusterMode;
|
||||||
|
int db;
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Vendored
+12
@@ -0,0 +1,12 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=BackOne
|
||||||
|
After=network-online.target network.target
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/usr/sbin/backone
|
||||||
|
Restart=always
|
||||||
|
KillMode=process
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -1,58 +1,63 @@
|
|||||||
.TH "ZEROTIER\-CLI" "1" "December 2016" "" ""
|
.TH "BACKONE\-CLI" "1" "September 2026"
|
||||||
.SH "NAME"
|
.SH "NAME"
|
||||||
\fBzerotier-cli\fR \- control local ZeroTier virtual network service
|
\fBbackone-cli\fR \- control local BackOne virtual network service
|
||||||
.SH SYNOPSIS
|
.SH SYNOPSIS
|
||||||
.P
|
.P
|
||||||
\fBzerotier\-cli\fP [\-switches] <command> [arguments]
|
\fBbackone\-cli\fP [\-switches] <command> [arguments]
|
||||||
.SH DESCRIPTION
|
.SH DESCRIPTION
|
||||||
.P
|
.P
|
||||||
\fBzerotier\-cli\fR provides a simple command line interface to the local JSON API of the ZeroTier virtual network endpoint service zerotier\-one(8)\.
|
\fBbackone\-cli\fR provides a simple command line interface to the local JSON API of the BackOne virtual network endpoint service backone(8)\.
|
||||||
.P
|
|
||||||
By default \fBzerotier\-cli\fR must be run as root or with \fBsudo\fP\|\. If you want to allow an unprivileged user to use \fBzerotier\-cli\fR to control the system ZeroTier service, you can create a local copy of the ZeroTier service authorization token in the user's home directory:
|
|
||||||
.P
|
.P
|
||||||
|
By default \fBbackone\-cli\fR must be run as root or with \fBsudo\fP\|\. If you want to allow an unprivileged user to use \fBbackone\-cli\fR to control the system BackOne service, you can create a local copy of the BackOne service authorization token in the user's home directory:
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
sudo cp /var/lib/zerotier\-one/authtoken\.secret /home/user/\.zeroTierOneAuthToken
|
sudo cp /var/lib/backone/authtoken\.secret /home/user/\.backOneOneAuthToken
|
||||||
chown user /home/user/\.zeroTierOneAuthToken
|
chown user /home/user/\.backOneOneAuthToken
|
||||||
chmod 0600 /home/user/\.zeroTierOneAuthToken
|
chmod 0600 /home/user/\.backOneOneAuthToken
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
(The location of ZeroTier's service home may differ by platform\. See zerotier\-one(8)\.)
|
(The location of BackOne's service home may differ by platform\. See backone(8)\.)
|
||||||
.P
|
.P
|
||||||
Note that this gives the user the power to connect or disconnect the system to or from any virtual network, which is a significant permission\.
|
Note that this gives the user the power to connect or disconnect the system to or from any virtual network, which is a significant permission\.
|
||||||
.P
|
.P
|
||||||
\fBzerotier\-cli\fR has several command line arguments that are visible in \fBhelp\fP output\. The two most commonly used are \fB\-j\fP for raw JSON output and \fB\-D<path>\fP to specify an alternative ZeroTier service working directory\. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output\. The \fB\-D<path>\fP option specifies where the service's zerotier\-one\.port and authtoken\.secret files are located if the service is not running at the default location for your system\.
|
\fBbackone\-cli\fR has several command line arguments that are visible in \fBhelp\fP output\. The two most commonly used are \fB\-j\fP for raw JSON output and \fB\-D<path>\fP to specify an alternative BackOne service working directory\. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output\. The \fB\-D<path>\fP option specifies where the service's backone\.port and authtoken\.secret files are located if the service is not running at the default location for your system\.
|
||||||
.SH COMMANDS
|
.SH COMMANDS
|
||||||
.RS 0
|
|
||||||
|
.RS 1
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBhelp\fP:
|
\fBhelp\fP:
|
||||||
Displays \fBzerotier\-cli\fR help\.
|
.br
|
||||||
|
Displays \fBbackone\-cli\fR help\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBinfo\fP:
|
\fBinfo\fP:
|
||||||
|
.br
|
||||||
Shows information about this device including its 10\-digit ZeroTier address and apparent connection status\. Use \fB\-j\fP for more verbose output\.
|
Shows information about this device including its 10\-digit ZeroTier address and apparent connection status\. Use \fB\-j\fP for more verbose output\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBlistpeers\fP:
|
\fBlistpeers\fP:
|
||||||
|
.br
|
||||||
This command lists the ZeroTier VL1 (virtual layer 1, the peer to peer network) peers this service knows about and has recently (within the past 30 minutes or so) communicated with\. These are not necessarily all the devices on your virtual network(s), and may also include a few devices not on any virtual network you've joined\. These are typically either root servers or network controllers\.
|
This command lists the ZeroTier VL1 (virtual layer 1, the peer to peer network) peers this service knows about and has recently (within the past 30 minutes or so) communicated with\. These are not necessarily all the devices on your virtual network(s), and may also include a few devices not on any virtual network you've joined\. These are typically either root servers or network controllers\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBlistnetworks\fP:
|
\fBlistnetworks\fP:
|
||||||
|
.br
|
||||||
This lists the networks your system belongs to and some information about them, such as any ZeroTier\-managed IP addresses you have been assigned\. (IP addresses assigned manually to ZeroTier interfaces will not be listed here\. Use the standard network interface commands to see these\.)
|
This lists the networks your system belongs to and some information about them, such as any ZeroTier\-managed IP addresses you have been assigned\. (IP addresses assigned manually to ZeroTier interfaces will not be listed here\. Use the standard network interface commands to see these\.)
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBjoin\fP:
|
\fBjoin\fP:
|
||||||
|
.br
|
||||||
To join a network just use \fBjoin\fP and its 16\-digit hex network ID\. That's it\. Then use \fBlistnetworks\fP to see the status\. You'll either get a reply from the network controller with a certificate and other info such as IP assignments, or you'll get "access denied\." In this case you'll need the administrator of this network to authorize your device by its 10\-digit device ID (visible with \fBinfo\fP) on the network's controller\.
|
To join a network just use \fBjoin\fP and its 16\-digit hex network ID\. That's it\. Then use \fBlistnetworks\fP to see the status\. You'll either get a reply from the network controller with a certificate and other info such as IP assignments, or you'll get "access denied\." In this case you'll need the administrator of this network to authorize your device by its 10\-digit device ID (visible with \fBinfo\fP) on the network's controller\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBleave\fP:
|
\fBleave\fP:
|
||||||
|
.br
|
||||||
Leaving a network is as easy as joining it\. This disconnects from the network and deletes its interface from the system\. Note that peers on the network may hang around in \fBlistpeers\fP for up to 30 minutes until they time out due to lack of traffic\. But if they no longer share a network with you, they can't actually communicate with you in any meaningful way\.
|
Leaving a network is as easy as joining it\. This disconnects from the network and deletes its interface from the system\. Note that peers on the network may hang around in \fBlistpeers\fP for up to 30 minutes until they time out due to lack of traffic\. But if they no longer share a network with you, they can't actually communicate with you in any meaningful way\.
|
||||||
|
|
||||||
.RE
|
.RE
|
||||||
.SH EXAMPLES
|
.SH EXAMPLES
|
||||||
.P
|
.P
|
||||||
Join "Earth," ZeroTier's big public party line network:
|
Join "Earth," ZeroTier's big public party line network:
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ sudo zerotier\-cli join 8056c2e21c000001
|
$ sudo backone\-cli join 8056c2e21c000001
|
||||||
$ sudo zerotier\-cli listnetworks
|
$ sudo backone\-cli listnetworks
|
||||||
( wait until you get an Earth IP )
|
( wait until you get an Earth IP )
|
||||||
$ ping earth\.zerotier\.net
|
$ ping earth\.zerotier\.net
|
||||||
( you should now be able to ping our Earth test IP )
|
( you should now be able to ping our Earth test IP )
|
||||||
@@ -60,24 +65,22 @@ $ ping earth\.zerotier\.net
|
|||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
Leave "Earth":
|
Leave "Earth":
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ sudo zerotier\-cli leave 8056c2e21c000001
|
$ sudo backone\-cli leave 8056c2e21c000001
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
List VL1 peers:
|
List VL1 peers:
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ sudo zerotier\-cli listpeers
|
$ sudo backone\-cli listpeers
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.SH COPYRIGHT
|
.SH COPYRIGHT
|
||||||
.P
|
.P
|
||||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www\.zerotier\.com/ \-\- https://github\.com/zerotier
|
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www.zerotier.com/ \-\- https://github.com/zerotier
|
||||||
.SH SEE ALSO
|
.SH SEE ALSO
|
||||||
.P
|
.P
|
||||||
zerotier\-one(8), zerotier\-idtool(1)
|
backone(8), backone\-idtool(1)
|
||||||
|
|
||||||
@@ -1,30 +1,30 @@
|
|||||||
zerotier-cli(1) -- control local ZeroTier virtual network service
|
backone-cli(1) -- control local BackOne virtual network service
|
||||||
=================================================================
|
===============================================================
|
||||||
|
|
||||||
## SYNOPSIS
|
## SYNOPSIS
|
||||||
|
|
||||||
`zerotier-cli` [-switches] <command> [arguments]
|
`backone-cli` [-switches] <command> [arguments]
|
||||||
|
|
||||||
## DESCRIPTION
|
## DESCRIPTION
|
||||||
|
|
||||||
**zerotier-cli** provides a simple command line interface to the local JSON API of the ZeroTier virtual network endpoint service zerotier-one(8).
|
**backone-cli** provides a simple command line interface to the local JSON API of the BackOne virtual network endpoint service backone(8).
|
||||||
|
|
||||||
By default **zerotier-cli** must be run as root or with `sudo`. If you want to allow an unprivileged user to use **zerotier-cli** to control the system ZeroTier service, you can create a local copy of the ZeroTier service authorization token in the user's home directory:
|
By default **backone-cli** must be run as root or with `sudo`. If you want to allow an unprivileged user to use **backone-cli** to control the system BackOne service, you can create a local copy of the BackOne service authorization token in the user's home directory:
|
||||||
|
|
||||||
sudo cp /var/lib/zerotier-one/authtoken.secret /home/user/.zeroTierOneAuthToken
|
sudo cp /var/lib/backone/authtoken.secret /home/user/.backOneOneAuthToken
|
||||||
chown user /home/user/.zeroTierOneAuthToken
|
chown user /home/user/.backOneOneAuthToken
|
||||||
chmod 0600 /home/user/.zeroTierOneAuthToken
|
chmod 0600 /home/user/.backOneOneAuthToken
|
||||||
|
|
||||||
(The location of ZeroTier's service home may differ by platform. See zerotier-one(8).)
|
(The location of BackOne's service home may differ by platform. See backone(8).)
|
||||||
|
|
||||||
Note that this gives the user the power to connect or disconnect the system to or from any virtual network, which is a significant permission.
|
Note that this gives the user the power to connect or disconnect the system to or from any virtual network, which is a significant permission.
|
||||||
|
|
||||||
**zerotier-cli** has several command line arguments that are visible in `help` output. The two most commonly used are `-j` for raw JSON output and `-D<path>` to specify an alternative ZeroTier service working directory. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output. The `-D<path>` option specifies where the service's zerotier-one.port and authtoken.secret files are located if the service is not running at the default location for your system.
|
**backone-cli** has several command line arguments that are visible in `help` output. The two most commonly used are `-j` for raw JSON output and `-D<path>` to specify an alternative BackOne service working directory. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output. The `-D<path>` option specifies where the service's backone.port and authtoken.secret files are located if the service is not running at the default location for your system.
|
||||||
|
|
||||||
## COMMANDS
|
## COMMANDS
|
||||||
|
|
||||||
* `help`:
|
* `help`:
|
||||||
Displays **zerotier-cli** help.
|
Displays **backone-cli** help.
|
||||||
|
|
||||||
* `info`:
|
* `info`:
|
||||||
Shows information about this device including its 10-digit ZeroTier address and apparent connection status. Use `-j` for more verbose output.
|
Shows information about this device including its 10-digit ZeroTier address and apparent connection status. Use `-j` for more verbose output.
|
||||||
@@ -45,19 +45,19 @@ Note that this gives the user the power to connect or disconnect the system to o
|
|||||||
|
|
||||||
Join "Earth," ZeroTier's big public party line network:
|
Join "Earth," ZeroTier's big public party line network:
|
||||||
|
|
||||||
$ sudo zerotier-cli join 8056c2e21c000001
|
$ sudo backone-cli join 8056c2e21c000001
|
||||||
$ sudo zerotier-cli listnetworks
|
$ sudo backone-cli listnetworks
|
||||||
( wait until you get an Earth IP )
|
( wait until you get an Earth IP )
|
||||||
$ ping earth.zerotier.net
|
$ ping earth.zerotier.net
|
||||||
( you should now be able to ping our Earth test IP )
|
( you should now be able to ping our Earth test IP )
|
||||||
|
|
||||||
Leave "Earth":
|
Leave "Earth":
|
||||||
|
|
||||||
$ sudo zerotier-cli leave 8056c2e21c000001
|
$ sudo backone-cli leave 8056c2e21c000001
|
||||||
|
|
||||||
List VL1 peers:
|
List VL1 peers:
|
||||||
|
|
||||||
$ sudo zerotier-cli listpeers
|
$ sudo backone-cli listpeers
|
||||||
|
|
||||||
## COPYRIGHT
|
## COPYRIGHT
|
||||||
|
|
||||||
@@ -65,4 +65,4 @@ List VL1 peers:
|
|||||||
|
|
||||||
## SEE ALSO
|
## SEE ALSO
|
||||||
|
|
||||||
zerotier-one(8), zerotier-idtool(1)
|
backone(8), backone-idtool(1)
|
||||||
@@ -1,84 +1,87 @@
|
|||||||
.TH "ZEROTIER\-IDTOOL" "1" "December 2016" "" ""
|
.TH "BACKONE\-IDTOOL" "1" "September 2026"
|
||||||
.SH "NAME"
|
.SH "NAME"
|
||||||
\fBzerotier-idtool\fR \- tool for creating and manipulating ZeroTier identities
|
\fBbackone-idtool\fR \- tool for creating and manipulating ZeroTier identities
|
||||||
.SH SYNOPSIS
|
.SH SYNOPSIS
|
||||||
.P
|
.P
|
||||||
\fBzerotier\-idtool\fP <command> [args]
|
\fBbackone\-idtool\fP <command> [args]
|
||||||
.SH DESCRIPTION
|
.SH DESCRIPTION
|
||||||
.P
|
.P
|
||||||
\fBzerotier\-idtool\fR is a command line utility for doing things with ZeroTier identities\. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity\.public) and a 10\-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function\.
|
\fBbackone\-idtool\fR is a command line utility for doing things with ZeroTier identities\. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity\.public) and a 10\-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function\.
|
||||||
.SH COMMANDS
|
.SH COMMANDS
|
||||||
.P
|
.P
|
||||||
When command arguments call for a public or secret (full) identity, the identity can be specified as a path to a file or directly on the command line\.
|
When command arguments call for a public or secret (full) identity, the identity can be specified as a path to a file or directly on the command line\.
|
||||||
.RS 0
|
|
||||||
|
.RS 1
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBhelp\fP:
|
\fBhelp\fP:
|
||||||
|
.br
|
||||||
Display help\. (Also running with no command does this\.)
|
Display help\. (Also running with no command does this\.)
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBgenerate\fP [secret file] [public file] [vanity]:
|
\fBgenerate\fP [secret file] [public file] [vanity]:
|
||||||
|
.br
|
||||||
Generate a new ZeroTier identity\. If a secret file is specified, the full identity including the private key will be written to this file\. If the public file is specified, the public portion will be written there\. If no file paths are specified the full secret identity is output to STDOUT\. The vanity prefix is a series of hexadecimal digits that the generated identity's address should start with\. Typically this isn't used, and if it's specified generation can take a very long time due to the intrinsic cost of generating identities with their proof of work function\. Generating an identity with a known 16\-bit (4 digit) prefix on a 2\.8ghz Core i5 (using one core) takes an average of two hours\.
|
Generate a new ZeroTier identity\. If a secret file is specified, the full identity including the private key will be written to this file\. If the public file is specified, the public portion will be written there\. If no file paths are specified the full secret identity is output to STDOUT\. The vanity prefix is a series of hexadecimal digits that the generated identity's address should start with\. Typically this isn't used, and if it's specified generation can take a very long time due to the intrinsic cost of generating identities with their proof of work function\. Generating an identity with a known 16\-bit (4 digit) prefix on a 2\.8ghz Core i5 (using one core) takes an average of two hours\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBvalidate\fP <identity, only public part required>:
|
\fBvalidate\fP <identity, only public part required>:
|
||||||
|
.br
|
||||||
Locally validate an identity's key and proof of work function correspondence\.
|
Locally validate an identity's key and proof of work function correspondence\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBgetpublic\fP <full identity with secret>:
|
\fBgetpublic\fP <full identity with secret>:
|
||||||
|
.br
|
||||||
Extract the public portion of an identity\.secret and print to STDOUT\.
|
Extract the public portion of an identity\.secret and print to STDOUT\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBsign\fP <full identity with secret> <file to sign>:
|
\fBsign\fP <full identity with secret> <file to sign>:
|
||||||
|
.br
|
||||||
Sign a file's contents with SHA512+ECC\-256 (ed25519)\. The signature is output in hex to STDOUT\.
|
Sign a file's contents with SHA512+ECC\-256 (ed25519)\. The signature is output in hex to STDOUT\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBverify\fP <identity, only public part required> <file to check> <signature in hex>:
|
\fBverify\fP <identity, only public part required> <file to check> <signature in hex>:
|
||||||
|
.br
|
||||||
Verify a signature created with \fBsign\fP\|\.
|
Verify a signature created with \fBsign\fP\|\.
|
||||||
.IP \(bu 2
|
.IP \(bu 2
|
||||||
\fBmkcom\fP <full identity with secret> [id,value,maxdelta] [\|\.\.\.]:
|
\fBmkcom\fP <full identity with secret> [id,value,maxdelta] [\.\.\.]:
|
||||||
|
.br
|
||||||
Create and sign a network membership certificate\. This is not generally useful since network controllers do this automatically and is included mostly for testing purposes\.
|
Create and sign a network membership certificate\. This is not generally useful since network controllers do this automatically and is included mostly for testing purposes\.
|
||||||
|
|
||||||
.RE
|
.RE
|
||||||
.SH EXAMPLES
|
.SH EXAMPLES
|
||||||
.P
|
.P
|
||||||
Generate and dump a new identity:
|
Generate and dump a new identity:
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ zerotier\-idtool generate
|
$ backone\-idtool generate
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
Generate and write a new identity, both secret and public parts:
|
Generate and write a new identity, both secret and public parts:
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ zerotier\-idtool generate identity\.secret identity\.public
|
$ backone\-idtool generate identity\.secret identity\.public
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
Generate a vanity address that begins with the hex digits "beef" (this will take a while!):
|
Generate a vanity address that begins with the hex digits "beef" (this will take a while!):
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ zerotier\-idtool generate beef\.secret beef\.public beef
|
$ backone\-idtool generate beef\.secret beef\.public beef
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
Sign a file with an identity's secret key:
|
Sign a file with an identity's secret key:
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ zerotier\-idtool sign identity\.secret last_will_and_testament\.txt
|
$ backone\-idtool sign identity\.secret last_will_and_testament\.txt
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.P
|
.P
|
||||||
Verify a file's signature with a public key:
|
Verify a file's signature with a public key:
|
||||||
.P
|
|
||||||
.RS 2
|
.RS 2
|
||||||
.nf
|
.nf
|
||||||
$ zerotier\-idtool verify identity\.public last_will_and_testament\.txt
|
$ backone\-idtool verify identity\.public last_will_and_testament\.txt
|
||||||
.fi
|
.fi
|
||||||
.RE
|
.RE
|
||||||
.SH COPYRIGHT
|
.SH COPYRIGHT
|
||||||
.P
|
.P
|
||||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www\.zerotier\.com/ \-\- https://github\.com/zerotier
|
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www.zerotier.com/ \-\- https://github.com/zerotier
|
||||||
.SH SEE ALSO
|
.SH SEE ALSO
|
||||||
.P
|
.P
|
||||||
zerotier\-one(8), zerotier\-cli(1)
|
backone(8), backone\-cli(1)
|
||||||
|
|
||||||
@@ -1,13 +1,13 @@
|
|||||||
zerotier-idtool(1) -- tool for creating and manipulating ZeroTier identities
|
backone-idtool(1) -- tool for creating and manipulating ZeroTier identities
|
||||||
============================================================================
|
===========================================================================
|
||||||
|
|
||||||
## SYNOPSIS
|
## SYNOPSIS
|
||||||
|
|
||||||
`zerotier-idtool` <command> [args]
|
`backone-idtool` <command> [args]
|
||||||
|
|
||||||
## DESCRIPTION
|
## DESCRIPTION
|
||||||
|
|
||||||
**zerotier-idtool** is a command line utility for doing things with ZeroTier identities. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity.public) and a 10-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function.
|
**backone-idtool** is a command line utility for doing things with ZeroTier identities. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity.public) and a 10-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function.
|
||||||
|
|
||||||
## COMMANDS
|
## COMMANDS
|
||||||
|
|
||||||
@@ -38,23 +38,23 @@ When command arguments call for a public or secret (full) identity, the identity
|
|||||||
|
|
||||||
Generate and dump a new identity:
|
Generate and dump a new identity:
|
||||||
|
|
||||||
$ zerotier-idtool generate
|
$ backone-idtool generate
|
||||||
|
|
||||||
Generate and write a new identity, both secret and public parts:
|
Generate and write a new identity, both secret and public parts:
|
||||||
|
|
||||||
$ zerotier-idtool generate identity.secret identity.public
|
$ backone-idtool generate identity.secret identity.public
|
||||||
|
|
||||||
Generate a vanity address that begins with the hex digits "beef" (this will take a while!):
|
Generate a vanity address that begins with the hex digits "beef" (this will take a while!):
|
||||||
|
|
||||||
$ zerotier-idtool generate beef.secret beef.public beef
|
$ backone-idtool generate beef.secret beef.public beef
|
||||||
|
|
||||||
Sign a file with an identity's secret key:
|
Sign a file with an identity's secret key:
|
||||||
|
|
||||||
$ zerotier-idtool sign identity.secret last_will_and_testament.txt
|
$ backone-idtool sign identity.secret last_will_and_testament.txt
|
||||||
|
|
||||||
Verify a file's signature with a public key:
|
Verify a file's signature with a public key:
|
||||||
|
|
||||||
$ zerotier-idtool verify identity.public last_will_and_testament.txt
|
$ backone-idtool verify identity.public last_will_and_testament.txt
|
||||||
|
|
||||||
## COPYRIGHT
|
## COPYRIGHT
|
||||||
|
|
||||||
@@ -62,4 +62,4 @@ Verify a file's signature with a public key:
|
|||||||
|
|
||||||
## SEE ALSO
|
## SEE ALSO
|
||||||
|
|
||||||
zerotier-one(8), zerotier-cli(1)
|
backone(8), backone-cli(1)
|
||||||
+121
@@ -0,0 +1,121 @@
|
|||||||
|
.TH "BACKONE" "8" "September 2026"
|
||||||
|
.SH "NAME"
|
||||||
|
\fBbackone\fR \- BackOne virtual network endpoint service
|
||||||
|
.SH SYNOPSIS
|
||||||
|
.P
|
||||||
|
\fBbackone\fP [\-switches] [working directory]
|
||||||
|
.SH DESCRIPTION
|
||||||
|
.P
|
||||||
|
\fBbackone\fR is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports\. You can think of it as a peer to peer VPN client\.
|
||||||
|
.P
|
||||||
|
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the \fB\-U\fP switch and don't plan on actually joining networks (e\.g\. to run a network controller microservice only)\.
|
||||||
|
.P
|
||||||
|
The \fBbackone\fR service keeps its state and other files in a working directory\. If this directory is not specified at launch it defaults to "/var/lib/backone" on Linux, "/Library/Application Support/BackOne" on Mac, and "/var/db/backone" on FreeBSD and other similar BSDs\. The working directory should persist\. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location\. Loss of its identity\.secret file results in loss of this system's unique 10\-digit ZeroTier address and key\.
|
||||||
|
.P
|
||||||
|
Multiple instances of \fBbackone\fR can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory\. But since a single service can join any number of networks, typically there's no point in doing this\.
|
||||||
|
.P
|
||||||
|
The \fBbackone\fR service is controlled via a JSON API available at 127\.0\.0\.1:<primary port> with the default primary port being 9993\. Access to this API requires an authorization token normally found in the authtoken\.secret file in the service's working directory\. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default)\.
|
||||||
|
.P
|
||||||
|
The first time the service is started in a fresh working directory, it generates a ZeroTier identity\. On slow systems this process can take ten seconds or more due to an anti\-DDOS/anti\-counterfeit proof of work function used by ZeroTier in address generation\. This only happens once, and once generated the result is saved in identity\.secret in the working directory\. This file represents and defines/claims your ZeroTier address and associated ECC\-256 key pair\.
|
||||||
|
.SH SWITCHES
|
||||||
|
|
||||||
|
.RS 1
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-h\fP:
|
||||||
|
.br
|
||||||
|
Display help\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-v\fP:
|
||||||
|
.br
|
||||||
|
Display BackOne version\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-U\fP:
|
||||||
|
.br
|
||||||
|
Skip privilege check and allow to be run by non\-privileged user\. This is typically used when \fBbackone\fR is built with the network controller option included\. In this case the BackOne service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-p<port>\fP:
|
||||||
|
.br
|
||||||
|
Specify a different primary port\. If this is not given the default is 9993\. If zero is given a random port is chosen each time\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-d\fP:
|
||||||
|
.br
|
||||||
|
Fork and run as a daemon\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-i\fP:
|
||||||
|
.br
|
||||||
|
Invoke the \fBbackone\-idtool\fR personality, in which case the binary behaves like backone\-idtool(1)\. This happens automatically if the name of the binary (or a symlink to it) is backone\-idtool\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fB\-q\fP:
|
||||||
|
.br
|
||||||
|
Invoke the \fBbackone\-cli\fR personality, in which case the binary behaves like backone\-cli(1)\. This happens automatically if the name of the binary (or a symlink to it) is backone\-cli\.
|
||||||
|
|
||||||
|
.RE
|
||||||
|
.SH EXAMPLES
|
||||||
|
.P
|
||||||
|
Run as daemon with OS default working directory and default port:
|
||||||
|
.RS 2
|
||||||
|
.nf
|
||||||
|
$ sudo backone \-d
|
||||||
|
.fi
|
||||||
|
.RE
|
||||||
|
.P
|
||||||
|
Run as daemon with a different working directory and port:
|
||||||
|
.RS 2
|
||||||
|
.nf
|
||||||
|
$ sudo backone \-d \-p12345 /tmp/backone\-working\-directory\-test
|
||||||
|
.fi
|
||||||
|
.RE
|
||||||
|
.SH FILES
|
||||||
|
.P
|
||||||
|
These are found in the service's working directory\.
|
||||||
|
|
||||||
|
.RS 1
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBidentity\.public\fP:
|
||||||
|
.br
|
||||||
|
The public portion of your ZeroTier identity, which is your 10\-digit hex address and the associated public key\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBidentity\.secret\fP:
|
||||||
|
.br
|
||||||
|
Your full ZeroTier identity including its private key\. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address\. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic\. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBauthtoken\.secret\fP:
|
||||||
|
.br
|
||||||
|
The secret token used to authenticate requests to the service's local JSON API\. If it does not exist it is generated from a secure random source on service start\. To use, send it in the "X\-ZT1\-Auth" header with HTTP requests to 127\.0\.0\.1:<primary port>\|\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBdevicemap\fP:
|
||||||
|
.br
|
||||||
|
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts\. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBbackone\.pid\fP:
|
||||||
|
.br
|
||||||
|
BackOne's PID\. This file is deleted on normal shutdown\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBbackone\.port\fP:
|
||||||
|
.br
|
||||||
|
BackOne's primary port, which is also where its JSON API is found at 127\.0\.0\.1:<this port>\|\. This file is created on startup and is read by backone\-cli(1) to determine where it should find the control API\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBcontroller\.db\fP:
|
||||||
|
.br
|
||||||
|
If the BackOne service is built with the network controller enabled, this file contains the controller's SQLite3 database\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBcontroller\.db\.backup\fP:
|
||||||
|
.br
|
||||||
|
If the BackOne service is built with the network controller enabled, it periodically backs up its controller\.db database in this file (currently every 5 minutes if there have been changes)\. Since this file is not a currently in use SQLite3 database it's safer to back up without corruption\. On new backups the file is rotated out rather than being rewritten in place\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBiddb\.d/\fP (directory):
|
||||||
|
.br
|
||||||
|
Caches the public identity of every peer BackOne has spoken with in the last 60 days\. This directory and its contents can be deleted, but this may result in slower connection initiations since it will require that we go out and re\-fetch full identities for peers we're speaking to\.
|
||||||
|
.IP \(bu 2
|
||||||
|
\fBnetworks\.d\fP (directory):
|
||||||
|
.br
|
||||||
|
This caches network configurations and certificate information for networks you belong to\. BackOne scans this directory for <network ID>\|\.conf files on startup to recall its networks, so "touch"ing an empty <network ID>\|\.conf file in this directory is a way of pre\-configuring BackOne to join a specific network on startup without using the API\. If the config file is empty BackOne will just fetch it from the network's controller\.
|
||||||
|
|
||||||
|
.RE
|
||||||
|
.SH COPYRIGHT
|
||||||
|
.P
|
||||||
|
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www.zerotier.com/ \-\- https://github.com/zerotier
|
||||||
|
.SH SEE ALSO
|
||||||
|
.P
|
||||||
|
backone\-cli(1), backone\-idtool(1)
|
||||||
|
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
backone(8) -- BackOne virtual network endpoint service
|
||||||
|
======================================================
|
||||||
|
|
||||||
|
## SYNOPSIS
|
||||||
|
|
||||||
|
`backone` [-switches] [working directory]
|
||||||
|
|
||||||
|
## DESCRIPTION
|
||||||
|
|
||||||
|
**backone** is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports. You can think of it as a peer to peer VPN client.
|
||||||
|
|
||||||
|
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the `-U` switch and don't plan on actually joining networks (e.g. to run a network controller microservice only).
|
||||||
|
|
||||||
|
The **backone** service keeps its state and other files in a working directory. If this directory is not specified at launch it defaults to "/var/lib/backone" on Linux, "/Library/Application Support/BackOne" on Mac, and "/var/db/backone" on FreeBSD and other similar BSDs. The working directory should persist. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location. Loss of its identity.secret file results in loss of this system's unique 10-digit ZeroTier address and key.
|
||||||
|
|
||||||
|
Multiple instances of **backone** can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory. But since a single service can join any number of networks, typically there's no point in doing this.
|
||||||
|
|
||||||
|
The **backone** service is controlled via a JSON API available at 127.0.0.1:<primary port> with the default primary port being 9993. Access to this API requires an authorization token normally found in the authtoken.secret file in the service's working directory. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default).
|
||||||
|
|
||||||
|
The first time the service is started in a fresh working directory, it generates a ZeroTier identity. On slow systems this process can take ten seconds or more due to an anti-DDOS/anti-counterfeit proof of work function used by ZeroTier in address generation. This only happens once, and once generated the result is saved in identity.secret in the working directory. This file represents and defines/claims your ZeroTier address and associated ECC-256 key pair.
|
||||||
|
|
||||||
|
## SWITCHES
|
||||||
|
|
||||||
|
* `-h`:
|
||||||
|
Display help.
|
||||||
|
|
||||||
|
* `-v`:
|
||||||
|
Display BackOne version.
|
||||||
|
|
||||||
|
* `-U`:
|
||||||
|
Skip privilege check and allow to be run by non-privileged user. This is typically used when **backone** is built with the network controller option included. In this case the BackOne service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions.
|
||||||
|
|
||||||
|
* `-p<port>`:
|
||||||
|
Specify a different primary port. If this is not given the default is 9993. If zero is given a random port is chosen each time.
|
||||||
|
|
||||||
|
* `-d`:
|
||||||
|
Fork and run as a daemon.
|
||||||
|
|
||||||
|
* `-i`:
|
||||||
|
Invoke the **backone-idtool** personality, in which case the binary behaves like backone-idtool(1). This happens automatically if the name of the binary (or a symlink to it) is backone-idtool.
|
||||||
|
|
||||||
|
* `-q`:
|
||||||
|
Invoke the **backone-cli** personality, in which case the binary behaves like backone-cli(1). This happens automatically if the name of the binary (or a symlink to it) is backone-cli.
|
||||||
|
|
||||||
|
## EXAMPLES
|
||||||
|
|
||||||
|
Run as daemon with OS default working directory and default port:
|
||||||
|
|
||||||
|
$ sudo backone -d
|
||||||
|
|
||||||
|
Run as daemon with a different working directory and port:
|
||||||
|
|
||||||
|
$ sudo backone -d -p12345 /tmp/backone-working-directory-test
|
||||||
|
|
||||||
|
## FILES
|
||||||
|
|
||||||
|
These are found in the service's working directory.
|
||||||
|
|
||||||
|
* `identity.public`:
|
||||||
|
The public portion of your ZeroTier identity, which is your 10-digit hex address and the associated public key.
|
||||||
|
|
||||||
|
* `identity.secret`:
|
||||||
|
Your full ZeroTier identity including its private key. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks.
|
||||||
|
|
||||||
|
* `authtoken.secret`:
|
||||||
|
The secret token used to authenticate requests to the service's local JSON API. If it does not exist it is generated from a secure random source on service start. To use, send it in the "X-ZT1-Auth" header with HTTP requests to 127.0.0.1:<primary port>.
|
||||||
|
|
||||||
|
* `devicemap`:
|
||||||
|
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present.
|
||||||
|
|
||||||
|
* `backone.pid`:
|
||||||
|
BackOne's PID. This file is deleted on normal shutdown.
|
||||||
|
|
||||||
|
* `backone.port`:
|
||||||
|
BackOne's primary port, which is also where its JSON API is found at 127.0.0.1:<this port>. This file is created on startup and is read by backone-cli(1) to determine where it should find the control API.
|
||||||
|
|
||||||
|
* `controller.db`:
|
||||||
|
If the BackOne service is built with the network controller enabled, this file contains the controller's SQLite3 database.
|
||||||
|
|
||||||
|
* `controller.db.backup`:
|
||||||
|
If the BackOne service is built with the network controller enabled, it periodically backs up its controller.db database in this file (currently every 5 minutes if there have been changes). Since this file is not a currently in use SQLite3 database it's safer to back up without corruption. On new backups the file is rotated out rather than being rewritten in place.
|
||||||
|
|
||||||
|
* `iddb.d/` (directory):
|
||||||
|
Caches the public identity of every peer BackOne has spoken with in the last 60 days. This directory and its contents can be deleted, but this may result in slower connection initiations since it will require that we go out and re-fetch full identities for peers we're speaking to.
|
||||||
|
|
||||||
|
* `networks.d` (directory):
|
||||||
|
This caches network configurations and certificate information for networks you belong to. BackOne scans this directory for <network ID>.conf files on startup to recall its networks, so "touch"ing an empty <network ID>.conf file in this directory is a way of pre-configuring BackOne to join a specific network on startup without using the API. If the config file is empty BackOne will just fetch it from the network's controller.
|
||||||
|
|
||||||
|
## COPYRIGHT
|
||||||
|
|
||||||
|
(c)2011-2016 ZeroTier, Inc. -- https://www.zerotier.com/ -- https://github.com/zerotier
|
||||||
|
|
||||||
|
## SEE ALSO
|
||||||
|
|
||||||
|
backone-cli(1), backone-idtool(1)
|
||||||
+12
-21
@@ -1,42 +1,33 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
export PATH=/bin:/usr/bin:/usr/local/bin:/sbin:/usr/sbin:/usr/local/sbin
|
if [ ! -f backone.8.md ]; then
|
||||||
|
echo 'This script must be run from the doc/ subfolder of the BackOne tree.'
|
||||||
if [ ! -f zerotier-cli.1.md ]; then
|
exit 1
|
||||||
echo 'This script must be run from the doc/ subfolder of the ZeroTier tree.'
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
rm -f *.1 *.2 *.8
|
rm -f *.1 *.2 *.8
|
||||||
|
|
||||||
if [ -e /usr/bin/ronn -o -e /usr/local/bin/ronn ]; then
|
if [ -e /usr/bin/ronn -o -e /usr/local/bin/ronn ]; then
|
||||||
# Use 'ronn' which is available as a package on many distros including Debian
|
# Use 'ronn' which is available as a package on many distros including Debian
|
||||||
ronn -r zerotier-cli.1.md
|
ronn -r backone-cli.1.md
|
||||||
ronn -r zerotier-idtool.1.md
|
ronn -r backone-idtool.1.md
|
||||||
ronn -r zerotier-one.8.md
|
ronn -r backone.8.md
|
||||||
else
|
else
|
||||||
# Use 'marked-man' from npm
|
# Use 'marked-man' from npm
|
||||||
NODE=/usr/bin/node
|
NODE=$(command -v node || command -v nodejs)
|
||||||
if [ ! -e $NODE ]; then
|
if [ -z "$NODE" ]; then
|
||||||
if [ -e /usr/bin/nodejs ]; then
|
|
||||||
NODE=/usr/bin/nodejs
|
|
||||||
elif [ -e /usr/local/bin/node ]; then
|
|
||||||
NODE=/usr/local/bin/node
|
|
||||||
elif [ -e /usr/local/bin/nodejs ]; then
|
|
||||||
NODE=/usr/local/bin/nodejs
|
|
||||||
else
|
|
||||||
echo 'Unable to find ronn or node/npm -- cannot build man pages!'
|
echo 'Unable to find ronn or node/npm -- cannot build man pages!'
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
if [ ! -f node_modules/marked-man/bin/marked-man ]; then
|
if ! npx --no-install marked-man --version >/dev/null 2>&1; then
|
||||||
echo 'Installing npm package "marked-man" -- MarkDown to ROFF converter...'
|
echo 'Installing npm package "marked-man" -- MarkDown to ROFF converter...'
|
||||||
npm install marked-man
|
npm install marked-man
|
||||||
fi
|
fi
|
||||||
|
|
||||||
$NODE node_modules/marked-man/bin/marked-man zerotier-cli.1.md >zerotier-cli.1
|
npx --no-install marked-man backone-cli.1.md >backone-cli.1
|
||||||
$NODE node_modules/marked-man/bin/marked-man zerotier-idtool.1.md >zerotier-idtool.1
|
npx --no-install marked-man backone-idtool.1.md >backone-idtool.1
|
||||||
$NODE node_modules/marked-man/bin/marked-man zerotier-one.8.md >zerotier-one.8
|
npx --no-install marked-man backone.8.md >backone.8
|
||||||
fi
|
fi
|
||||||
|
|
||||||
exit 0
|
exit 0
|
||||||
@@ -1,104 +0,0 @@
|
|||||||
.TH "ZEROTIER\-ONE" "8" "December 2016" "" ""
|
|
||||||
.SH "NAME"
|
|
||||||
\fBzerotier-one\fR \- ZeroTier virtual network endpoint service
|
|
||||||
.SH SYNOPSIS
|
|
||||||
.P
|
|
||||||
\fBzerotier\-one\fP [\-switches] [working directory]
|
|
||||||
.SH DESCRIPTION
|
|
||||||
.P
|
|
||||||
\fBzerotier\-one\fR is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports\. You can think of it as a peer to peer VPN client\.
|
|
||||||
.P
|
|
||||||
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the \fB\-U\fP switch and don't plan on actually joining networks (e\.g\. to run a network controller microservice only)\.
|
|
||||||
.P
|
|
||||||
The \fBzerotier\-one\fR service keeps its state and other files in a working directory\. If this directory is not specified at launch it defaults to "/var/lib/zerotier\-one" on Linux, "/Library/Application Support/ZeroTier/One" on Mac, and "/var/db/zerotier\-one" on FreeBSD and other similar BSDs\. The working directory should persist\. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location\. Loss of its identity\.secret file results in loss of this system's unique 10\-digit ZeroTier address and key\.
|
|
||||||
.P
|
|
||||||
Multiple instances of \fBzerotier\-one\fR can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory\. But since a single service can join any number of networks, typically there's no point in doing this\.
|
|
||||||
.P
|
|
||||||
The \fBzerotier\-one\fR service is controlled via a JSON API available at 127\.0\.0\.1:<primary port> with the default primary port being 9993\. Access to this API requires an authorization token normally found in the authtoken\.secret file in the service's working directory\. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default)\.
|
|
||||||
.P
|
|
||||||
The first time the service is started in a fresh working directory, it generates a ZeroTier identity\. On slow systems this process can take ten seconds or more due to an anti\-DDOS/anti\-counterfeit proof of work function used by ZeroTier in address generation\. This only happens once, and once generated the result is saved in identity\.secret in the working directory\. This file represents and defines/claims your ZeroTier address and associated ECC\-256 key pair\.
|
|
||||||
.SH SWITCHES
|
|
||||||
.RS 0
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-h\fP:
|
|
||||||
Display help\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-v\fP:
|
|
||||||
Display ZeroTier One version\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-U\fP:
|
|
||||||
Skip privilege check and allow to be run by non\-privileged user\. This is typically used when \fBzerotier\-one\fR is built with the network controller option included\. In this case the ZeroTier service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-p<port>\fP:
|
|
||||||
Specify a different primary port\. If this is not given the default is 9993\. If zero is given a random port is chosen each time\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-d\fP:
|
|
||||||
Fork and run as a daemon\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-i\fP:
|
|
||||||
Invoke the \fBzerotier\-idtool\fR personality, in which case the binary behaves like zerotier\-idtool(1)\. This happens automatically if the name of the binary (or a symlink to it) is zerotier\-idtool\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fB\-q\fP:
|
|
||||||
Invoke the \fBzerotier\-cli\fR personality, in which case the binary behaves like zerotier\-cli(1)\. This happens automatically if the name of the binary (or a symlink to it) is zerotier\-cli\.
|
|
||||||
|
|
||||||
.RE
|
|
||||||
.SH EXAMPLES
|
|
||||||
.P
|
|
||||||
Run as daemon with OS default working directory and default port:
|
|
||||||
.P
|
|
||||||
.RS 2
|
|
||||||
.nf
|
|
||||||
$ sudo zerotier\-one \-d
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
.P
|
|
||||||
Run as daemon with a different working directory and port:
|
|
||||||
.P
|
|
||||||
.RS 2
|
|
||||||
.nf
|
|
||||||
$ sudo zerotier\-one \-d \-p12345 /tmp/zerotier\-working\-directory\-test
|
|
||||||
.fi
|
|
||||||
.RE
|
|
||||||
.SH FILES
|
|
||||||
.P
|
|
||||||
These are found in the service's working directory\.
|
|
||||||
.RS 0
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBidentity\.public\fP:
|
|
||||||
The public portion of your ZeroTier identity, which is your 10\-digit hex address and the associated public key\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBidentity\.secret\fP:
|
|
||||||
Your full ZeroTier identity including its private key\. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address\. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic\. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBauthtoken\.secret\fP:
|
|
||||||
The secret token used to authenticate requests to the service's local JSON API\. If it does not exist it is generated from a secure random source on service start\. To use, send it in the "X\-ZT1\-Auth" header with HTTP requests to 127\.0\.0\.1:<primary port>\|\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBdevicemap\fP:
|
|
||||||
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts\. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBzerotier\-one\.pid\fP:
|
|
||||||
ZeroTier's PID\. This file is deleted on normal shutdown\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBzerotier\-one\.port\fP:
|
|
||||||
ZeroTier's primary port, which is also where its JSON API is found at 127\.0\.0\.1:<this port>\|\. This file is created on startup and is read by zerotier\-cli(1) to determine where it should find the control API\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBcontroller\.db\fP:
|
|
||||||
If the ZeroTier One service is built with the network controller enabled, this file contains the controller's SQLite3 database\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBcontroller\.db\.backup\fP:
|
|
||||||
If the ZeroTier One service is built with the network controller enabled, it periodically backs up its controller\.db database in this file (currently every 5 minutes if there have been changes)\. Since this file is not a currently in use SQLite3 database it's safer to back up without corruption\. On new backups the file is rotated out rather than being rewritten in place\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBiddb\.d/\fP (directory):
|
|
||||||
Caches the public identity of every peer ZeroTier has spoken with in the last 60 days\. This directory and its contents can be deleted, but this may result in slower connection initations since it will require that we go out and re\-fetch full identities for peers we're speaking to\.
|
|
||||||
.IP \(bu 2
|
|
||||||
\fBnetworks\.d\fP (directory):
|
|
||||||
This caches network configurations and certificate information for networks you belong to\. ZeroTier scans this directory for <network ID>\|\.conf files on startup to recall its networks, so "touch"ing an empty <network ID>\|\.conf file in this directory is a way of pre\-configuring ZeroTier to join a specific network on startup without using the API\. If the config file is empty ZeroTIer will just fetch it from the network's controller\.
|
|
||||||
|
|
||||||
.RE
|
|
||||||
.SH COPYRIGHT
|
|
||||||
.P
|
|
||||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www\.zerotier\.com/ \-\- https://github\.com/zerotier
|
|
||||||
.SH SEE ALSO
|
|
||||||
.P
|
|
||||||
zerotier\-cli(1), zerotier\-idtool(1)
|
|
||||||
|
|
||||||
@@ -1,95 +0,0 @@
|
|||||||
zerotier-one(8) -- ZeroTier virtual network endpoint service
|
|
||||||
============================================================
|
|
||||||
|
|
||||||
## SYNOPSIS
|
|
||||||
|
|
||||||
`zerotier-one` [-switches] [working directory]
|
|
||||||
|
|
||||||
## DESCRIPTION
|
|
||||||
|
|
||||||
**zerotier-one** is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports. You can think of it as a peer to peer VPN client.
|
|
||||||
|
|
||||||
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the `-U` switch and don't plan on actually joining networks (e.g. to run a network controller microservice only).
|
|
||||||
|
|
||||||
The **zerotier-one** service keeps its state and other files in a working directory. If this directory is not specified at launch it defaults to "/var/lib/zerotier-one" on Linux, "/Library/Application Support/ZeroTier/One" on Mac, and "/var/db/zerotier-one" on FreeBSD and other similar BSDs. The working directory should persist. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location. Loss of its identity.secret file results in loss of this system's unique 10-digit ZeroTier address and key.
|
|
||||||
|
|
||||||
Multiple instances of **zerotier-one** can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory. But since a single service can join any number of networks, typically there's no point in doing this.
|
|
||||||
|
|
||||||
The **zerotier-one** service is controlled via a JSON API available at 127.0.0.1:<primary port> with the default primary port being 9993. Access to this API requires an authorization token normally found in the authtoken.secret file in the service's working directory. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default).
|
|
||||||
|
|
||||||
The first time the service is started in a fresh working directory, it generates a ZeroTier identity. On slow systems this process can take ten seconds or more due to an anti-DDOS/anti-counterfeit proof of work function used by ZeroTier in address generation. This only happens once, and once generated the result is saved in identity.secret in the working directory. This file represents and defines/claims your ZeroTier address and associated ECC-256 key pair.
|
|
||||||
|
|
||||||
## SWITCHES
|
|
||||||
|
|
||||||
* `-h`:
|
|
||||||
Display help.
|
|
||||||
|
|
||||||
* `-v`:
|
|
||||||
Display ZeroTier One version.
|
|
||||||
|
|
||||||
* `-U`:
|
|
||||||
Skip privilege check and allow to be run by non-privileged user. This is typically used when **zerotier-one** is built with the network controller option included. In this case the ZeroTier service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions.
|
|
||||||
|
|
||||||
* `-p<port>`:
|
|
||||||
Specify a different primary port. If this is not given the default is 9993. If zero is given a random port is chosen each time.
|
|
||||||
|
|
||||||
* `-d`:
|
|
||||||
Fork and run as a daemon.
|
|
||||||
|
|
||||||
* `-i`:
|
|
||||||
Invoke the **zerotier-idtool** personality, in which case the binary behaves like zerotier-idtool(1). This happens automatically if the name of the binary (or a symlink to it) is zerotier-idtool.
|
|
||||||
|
|
||||||
* `-q`:
|
|
||||||
Invoke the **zerotier-cli** personality, in which case the binary behaves like zerotier-cli(1). This happens automatically if the name of the binary (or a symlink to it) is zerotier-cli.
|
|
||||||
|
|
||||||
## EXAMPLES
|
|
||||||
|
|
||||||
Run as daemon with OS default working directory and default port:
|
|
||||||
|
|
||||||
$ sudo zerotier-one -d
|
|
||||||
|
|
||||||
Run as daemon with a different working directory and port:
|
|
||||||
|
|
||||||
$ sudo zerotier-one -d -p12345 /tmp/zerotier-working-directory-test
|
|
||||||
|
|
||||||
## FILES
|
|
||||||
|
|
||||||
These are found in the service's working directory.
|
|
||||||
|
|
||||||
* `identity.public`:
|
|
||||||
The public portion of your ZeroTier identity, which is your 10-digit hex address and the associated public key.
|
|
||||||
|
|
||||||
* `identity.secret`:
|
|
||||||
Your full ZeroTier identity including its private key. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks.
|
|
||||||
|
|
||||||
* `authtoken.secret`:
|
|
||||||
The secret token used to authenticate requests to the service's local JSON API. If it does not exist it is generated from a secure random source on service start. To use, send it in the "X-ZT1-Auth" header with HTTP requests to 127.0.0.1:<primary port>.
|
|
||||||
|
|
||||||
* `devicemap`:
|
|
||||||
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present.
|
|
||||||
|
|
||||||
* `zerotier-one.pid`:
|
|
||||||
ZeroTier's PID. This file is deleted on normal shutdown.
|
|
||||||
|
|
||||||
* `zerotier-one.port`:
|
|
||||||
ZeroTier's primary port, which is also where its JSON API is found at 127.0.0.1:<this port>. This file is created on startup and is read by zerotier-cli(1) to determine where it should find the control API.
|
|
||||||
|
|
||||||
* `controller.db`:
|
|
||||||
If the ZeroTier One service is built with the network controller enabled, this file contains the controller's SQLite3 database.
|
|
||||||
|
|
||||||
* `controller.db.backup`:
|
|
||||||
If the ZeroTier One service is built with the network controller enabled, it periodically backs up its controller.db database in this file (currently every 5 minutes if there have been changes). Since this file is not a currently in use SQLite3 database it's safer to back up without corruption. On new backups the file is rotated out rather than being rewritten in place.
|
|
||||||
|
|
||||||
* `iddb.d/` (directory):
|
|
||||||
Caches the public identity of every peer ZeroTier has spoken with in the last 60 days. This directory and its contents can be deleted, but this may result in slower connection initiations since it will require that we go out and re-fetch full identities for peers we're speaking to.
|
|
||||||
|
|
||||||
* `networks.d` (directory):
|
|
||||||
This caches network configurations and certificate information for networks you belong to. ZeroTier scans this directory for <network ID>.conf files on startup to recall its networks, so "touch"ing an empty <network ID>.conf file in this directory is a way of pre-configuring ZeroTier to join a specific network on startup without using the API. If the config file is empty ZeroTIer will just fetch it from the network's controller.
|
|
||||||
|
|
||||||
## COPYRIGHT
|
|
||||||
|
|
||||||
(c)2011-2016 ZeroTier, Inc. -- https://www.zerotier.com/ -- https://github.com/zerotier
|
|
||||||
|
|
||||||
## SEE ALSO
|
|
||||||
|
|
||||||
zerotier-cli(1), zerotier-idtool(1)
|
|
||||||
+12
-12
@@ -1,7 +1,7 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
grepzt() {
|
grepzt() {
|
||||||
[ -f /var/lib/zerotier-one/zerotier-one.pid -a -n "$(cat /var/lib/zerotier-one/zerotier-one.pid 2>/dev/null)" -a -d "/proc/$(cat /var/lib/zerotier-one/zerotier-one.pid 2>/dev/null)" ]
|
[ -f "$ZEROTIER_HOME/$ZT_PID_FILE" -a -n "$(cat "$ZEROTIER_HOME/$ZT_PID_FILE" 2>/dev/null)" -a -d "/proc/$(cat "$ZEROTIER_HOME/$ZT_PID_FILE" 2>/dev/null)" ]
|
||||||
return $?
|
return $?
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -10,9 +10,9 @@ mkztfile() {
|
|||||||
mode=$2
|
mode=$2
|
||||||
content=$3
|
content=$3
|
||||||
|
|
||||||
mkdir -p /var/lib/zerotier-one
|
mkdir -p "$ZEROTIER_HOME"
|
||||||
echo "$content" > "/var/lib/zerotier-one/$file"
|
echo "$content" > "$ZEROTIER_HOME/$file"
|
||||||
chmod "$mode" "/var/lib/zerotier-one/$file"
|
chmod "$mode" "$ZEROTIER_HOME/$file"
|
||||||
}
|
}
|
||||||
|
|
||||||
if [ "x$ZEROTIER_API_SECRET" != "x" ]
|
if [ "x$ZEROTIER_API_SECRET" != "x" ]
|
||||||
@@ -30,11 +30,11 @@ then
|
|||||||
mkztfile identity.secret 0600 "$ZEROTIER_IDENTITY_SECRET"
|
mkztfile identity.secret 0600 "$ZEROTIER_IDENTITY_SECRET"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
mkztfile zerotier-one.port 0600 "9993"
|
mkztfile "$ZT_PORT_FILE" 0600 "9993"
|
||||||
|
|
||||||
killzerotier() {
|
killzerotier() {
|
||||||
log "Killing zerotier"
|
log "Killing zerotier"
|
||||||
kill $(cat /var/lib/zerotier-one/zerotier-one.pid 2>/dev/null)
|
kill $(cat "$ZEROTIER_HOME/$ZT_PID_FILE" 2>/dev/null)
|
||||||
exit 0
|
exit 0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -69,13 +69,13 @@ log_detail_params() {
|
|||||||
trap killzerotier INT TERM
|
trap killzerotier INT TERM
|
||||||
|
|
||||||
log "Configuring networks to join"
|
log "Configuring networks to join"
|
||||||
mkdir -p /var/lib/zerotier-one/networks.d
|
mkdir -p "$ZEROTIER_HOME/networks.d"
|
||||||
|
|
||||||
log_params "Joining networks from command line:" $@
|
log_params "Joining networks from command line:" $@
|
||||||
for i in "$@"
|
for i in "$@"
|
||||||
do
|
do
|
||||||
log_detail_params "Configuring join:" "$i"
|
log_detail_params "Configuring join:" "$i"
|
||||||
touch "/var/lib/zerotier-one/networks.d/${i}.conf"
|
touch "$ZEROTIER_HOME/networks.d/${i}.conf"
|
||||||
done
|
done
|
||||||
|
|
||||||
if [ "x$ZEROTIER_JOIN_NETWORKS" != "x" ]
|
if [ "x$ZEROTIER_JOIN_NETWORKS" != "x" ]
|
||||||
@@ -84,12 +84,12 @@ then
|
|||||||
for i in $ZEROTIER_JOIN_NETWORKS
|
for i in $ZEROTIER_JOIN_NETWORKS
|
||||||
do
|
do
|
||||||
log_detail_params "Configuring join:" "$i"
|
log_detail_params "Configuring join:" "$i"
|
||||||
touch "/var/lib/zerotier-one/networks.d/${i}.conf"
|
touch "$ZEROTIER_HOME/networks.d/${i}.conf"
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
|
|
||||||
log "Starting ZeroTier"
|
log "Starting ZeroTier"
|
||||||
nohup /usr/sbin/zerotier-one &
|
nohup "$ZT_DAEMON" &
|
||||||
|
|
||||||
while ! grepzt
|
while ! grepzt
|
||||||
do
|
do
|
||||||
@@ -109,13 +109,13 @@ cat >/healthcheck.sh <<EOF
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
for i in $@ $ZEROTIER_JOIN_NETWORKS
|
for i in $@ $ZEROTIER_JOIN_NETWORKS
|
||||||
do
|
do
|
||||||
[ "\$(zerotier-cli get \$i status)" = "OK" ] || exit 1
|
[ "\$($ZT_CLI get \$i status)" = "OK" ] || exit 1
|
||||||
done
|
done
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
chmod +x /healthcheck.sh
|
chmod +x /healthcheck.sh
|
||||||
|
|
||||||
log_params "zerotier-cli info:" "$(zerotier-cli info)"
|
log_params "$ZT_CLI info:" "$($ZT_CLI info)"
|
||||||
|
|
||||||
log "Sleeping infinitely"
|
log "Sleeping infinitely"
|
||||||
while true
|
while true
|
||||||
|
|||||||
Executable
+138
@@ -0,0 +1,138 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
#
|
||||||
|
# backone Start the BackOne network virtualization service
|
||||||
|
#
|
||||||
|
# chkconfig: 2345 55 25
|
||||||
|
# description: BackOne allows systems to join and participate in \
|
||||||
|
# ZeroTier virtual networks. See https://www.zerotier.com/
|
||||||
|
#
|
||||||
|
# processname: backone
|
||||||
|
# config: /var/lib/backone/identity.public
|
||||||
|
# config: /var/lib/backone/identity.secret
|
||||||
|
# config: /var/lib/backone/local.conf
|
||||||
|
# config: /var/lib/backone/authtoken.secret
|
||||||
|
# pidfile: /var/lib/backone/backone.pid
|
||||||
|
|
||||||
|
### BEGIN INIT INFO
|
||||||
|
# Provides: backone
|
||||||
|
# Required-Start: $local_fs $network $syslog
|
||||||
|
# Required-Stop: $local_fs $syslog
|
||||||
|
# Should-Start: $syslog
|
||||||
|
# Should-Stop: $network $syslog
|
||||||
|
# Default-Start: 2 3 4 5
|
||||||
|
# Default-Stop: 0 1 6
|
||||||
|
# Short-Description: Start the BackOne network virtualization service
|
||||||
|
# Description: BackOne allows systems to join and participate in
|
||||||
|
# ZeroTier virtual networks. See https://www.zerotier.com/
|
||||||
|
### END INIT INFO
|
||||||
|
|
||||||
|
# source function library
|
||||||
|
. /etc/rc.d/init.d/functions
|
||||||
|
|
||||||
|
# pull in sysconfig settings
|
||||||
|
[ -f /etc/sysconfig/backone ] && . /etc/sysconfig/backone
|
||||||
|
|
||||||
|
RETVAL=0
|
||||||
|
prog="backone"
|
||||||
|
lockfile=/var/lock/subsys/$prog
|
||||||
|
ZT="/usr/sbin/backone"
|
||||||
|
PID_FILE=/var/lib/backone/backone.pid
|
||||||
|
|
||||||
|
runlevel=$(set -- $(runlevel); eval "echo \$$#" )
|
||||||
|
|
||||||
|
start()
|
||||||
|
{
|
||||||
|
[ -x $ZT ] || exit 5
|
||||||
|
echo -n $"Starting $prog: "
|
||||||
|
$ZT $ZT_OPTIONS -d && success || failure
|
||||||
|
RETVAL=$?
|
||||||
|
[ $RETVAL -eq 0 ] && touch $lockfile
|
||||||
|
echo
|
||||||
|
return $RETVAL
|
||||||
|
}
|
||||||
|
|
||||||
|
stop()
|
||||||
|
{
|
||||||
|
echo -n $"Stopping $prog: "
|
||||||
|
killproc -p $PID_FILE $ZT
|
||||||
|
RETVAL=$?
|
||||||
|
if [ "x$runlevel" = x0 -o "x$runlevel" = x6 ] ; then
|
||||||
|
trap '' TERM
|
||||||
|
killall $prog 2>/dev/null
|
||||||
|
trap TERM
|
||||||
|
fi
|
||||||
|
[ $RETVAL -eq 0 ] && rm -f $lockfile
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
reload()
|
||||||
|
{
|
||||||
|
stop
|
||||||
|
start
|
||||||
|
}
|
||||||
|
|
||||||
|
restart() {
|
||||||
|
stop
|
||||||
|
start
|
||||||
|
}
|
||||||
|
|
||||||
|
force_reload() {
|
||||||
|
restart
|
||||||
|
}
|
||||||
|
|
||||||
|
rh_status() {
|
||||||
|
status -p $PID_FILE backone
|
||||||
|
}
|
||||||
|
|
||||||
|
rh_status_q() {
|
||||||
|
rh_status >/dev/null 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
start)
|
||||||
|
rh_status_q && exit 0
|
||||||
|
start
|
||||||
|
;;
|
||||||
|
stop)
|
||||||
|
if ! rh_status_q; then
|
||||||
|
rm -f $lockfile
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
stop
|
||||||
|
;;
|
||||||
|
restart)
|
||||||
|
restart
|
||||||
|
;;
|
||||||
|
reload)
|
||||||
|
rh_status_q || exit 7
|
||||||
|
reload
|
||||||
|
;;
|
||||||
|
force-reload)
|
||||||
|
force_reload
|
||||||
|
;;
|
||||||
|
condrestart|try-restart)
|
||||||
|
rh_status_q || exit 0
|
||||||
|
if [ -f $lockfile ] ; then
|
||||||
|
do_restart_sanity_check
|
||||||
|
if [ $RETVAL -eq 0 ] ; then
|
||||||
|
stop
|
||||||
|
# avoid race
|
||||||
|
sleep 3
|
||||||
|
start
|
||||||
|
else
|
||||||
|
RETVAL=6
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
status)
|
||||||
|
rh_status
|
||||||
|
RETVAL=$?
|
||||||
|
if [ $RETVAL -eq 3 -a -f $lockfile ] ; then
|
||||||
|
RETVAL=2
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo $"Usage: $0 {start|stop|restart|reload|force-reload|condrestart|try-restart|status}"
|
||||||
|
RETVAL=2
|
||||||
|
esac
|
||||||
|
exit $RETVAL
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
|
|
||||||
module zerotier-one 1.0;
|
module backone 1.0;
|
||||||
|
|
||||||
require {
|
require {
|
||||||
type unconfined_t;
|
type unconfined_t;
|
||||||
@@ -1,138 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
#
|
|
||||||
# zerotier-one Start the ZeroTier One network virtualization service
|
|
||||||
#
|
|
||||||
# chkconfig: 2345 55 25
|
|
||||||
# description: ZeroTier One allows systems to join and participate in \
|
|
||||||
# ZeroTier virtual networks. See https://www.zerotier.com/
|
|
||||||
#
|
|
||||||
# processname: zerotier-one
|
|
||||||
# config: /var/lib/zerotier-one/identity.public
|
|
||||||
# config: /var/lib/zerotier-one/identity.secret
|
|
||||||
# config: /var/lib/zerotier-one/local.conf
|
|
||||||
# config: /var/lib/zerotier-one/authtoken.secret
|
|
||||||
# pidfile: /var/lib/zerotier-one/zerotier-one.pid
|
|
||||||
|
|
||||||
### BEGIN INIT INFO
|
|
||||||
# Provides: zerotier-one
|
|
||||||
# Required-Start: $local_fs $network $syslog
|
|
||||||
# Required-Stop: $local_fs $syslog
|
|
||||||
# Should-Start: $syslog
|
|
||||||
# Should-Stop: $network $syslog
|
|
||||||
# Default-Start: 2 3 4 5
|
|
||||||
# Default-Stop: 0 1 6
|
|
||||||
# Short-Description: Start the ZeroTier One network virtualization service
|
|
||||||
# Description: ZeroTier One allows systems to join and participate in
|
|
||||||
# ZeroTier virtual networks. See https://www.zerotier.com/
|
|
||||||
### END INIT INFO
|
|
||||||
|
|
||||||
# source function library
|
|
||||||
. /etc/rc.d/init.d/functions
|
|
||||||
|
|
||||||
# pull in sysconfig settings
|
|
||||||
[ -f /etc/sysconfig/zerotier-one ] && . /etc/sysconfig/zerotier-one
|
|
||||||
|
|
||||||
RETVAL=0
|
|
||||||
prog="zerotier-one"
|
|
||||||
lockfile=/var/lock/subsys/$prog
|
|
||||||
ZT="/usr/sbin/zerotier-one"
|
|
||||||
PID_FILE=/var/lib/zerotier-one/zerotier-one.pid
|
|
||||||
|
|
||||||
runlevel=$(set -- $(runlevel); eval "echo \$$#" )
|
|
||||||
|
|
||||||
start()
|
|
||||||
{
|
|
||||||
[ -x $ZT ] || exit 5
|
|
||||||
echo -n $"Starting $prog: "
|
|
||||||
$ZT $ZT_OPTIONS -d && success || failure
|
|
||||||
RETVAL=$?
|
|
||||||
[ $RETVAL -eq 0 ] && touch $lockfile
|
|
||||||
echo
|
|
||||||
return $RETVAL
|
|
||||||
}
|
|
||||||
|
|
||||||
stop()
|
|
||||||
{
|
|
||||||
echo -n $"Stopping $prog: "
|
|
||||||
killproc -p $PID_FILE $ZT
|
|
||||||
RETVAL=$?
|
|
||||||
if [ "x$runlevel" = x0 -o "x$runlevel" = x6 ] ; then
|
|
||||||
trap '' TERM
|
|
||||||
killall $prog 2>/dev/null
|
|
||||||
trap TERM
|
|
||||||
fi
|
|
||||||
[ $RETVAL -eq 0 ] && rm -f $lockfile
|
|
||||||
echo
|
|
||||||
}
|
|
||||||
|
|
||||||
reload()
|
|
||||||
{
|
|
||||||
stop
|
|
||||||
start
|
|
||||||
}
|
|
||||||
|
|
||||||
restart() {
|
|
||||||
stop
|
|
||||||
start
|
|
||||||
}
|
|
||||||
|
|
||||||
force_reload() {
|
|
||||||
restart
|
|
||||||
}
|
|
||||||
|
|
||||||
rh_status() {
|
|
||||||
status -p $PID_FILE zerotier-one
|
|
||||||
}
|
|
||||||
|
|
||||||
rh_status_q() {
|
|
||||||
rh_status >/dev/null 2>&1
|
|
||||||
}
|
|
||||||
|
|
||||||
case "$1" in
|
|
||||||
start)
|
|
||||||
rh_status_q && exit 0
|
|
||||||
start
|
|
||||||
;;
|
|
||||||
stop)
|
|
||||||
if ! rh_status_q; then
|
|
||||||
rm -f $lockfile
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
stop
|
|
||||||
;;
|
|
||||||
restart)
|
|
||||||
restart
|
|
||||||
;;
|
|
||||||
reload)
|
|
||||||
rh_status_q || exit 7
|
|
||||||
reload
|
|
||||||
;;
|
|
||||||
force-reload)
|
|
||||||
force_reload
|
|
||||||
;;
|
|
||||||
condrestart|try-restart)
|
|
||||||
rh_status_q || exit 0
|
|
||||||
if [ -f $lockfile ] ; then
|
|
||||||
do_restart_sanity_check
|
|
||||||
if [ $RETVAL -eq 0 ] ; then
|
|
||||||
stop
|
|
||||||
# avoid race
|
|
||||||
sleep 3
|
|
||||||
start
|
|
||||||
else
|
|
||||||
RETVAL=6
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
status)
|
|
||||||
rh_status
|
|
||||||
RETVAL=$?
|
|
||||||
if [ $RETVAL -eq 3 -a -f $lockfile ] ; then
|
|
||||||
RETVAL=2
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
echo $"Usage: $0 {start|stop|restart|reload|force-reload|condrestart|try-restart|status}"
|
|
||||||
RETVAL=2
|
|
||||||
esac
|
|
||||||
exit $RETVAL
|
|
||||||
+20
-20
@@ -157,42 +157,42 @@ CXXFLAGS+=$(CFLAGS) -std=c++17 #-D_GLIBCXX_USE_C99 -D_GLIBCXX_USE_C99_MATH -D_GL
|
|||||||
all: one
|
all: one
|
||||||
|
|
||||||
one: $(CORE_OBJS) $(ONE_OBJS) one.o
|
one: $(CORE_OBJS) $(ONE_OBJS) one.o
|
||||||
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o zerotier-one $(CORE_OBJS) $(ONE_OBJS) one.o $(LIBS)
|
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o backone $(CORE_OBJS) $(ONE_OBJS) one.o $(LIBS)
|
||||||
$(STRIP) zerotier-one
|
$(STRIP) backone
|
||||||
ln -sf zerotier-one zerotier-idtool
|
ln -sf backone backone-idtool
|
||||||
ln -sf zerotier-one zerotier-cli
|
ln -sf backone backone-cli
|
||||||
|
|
||||||
zerotier-one: one
|
backone: one
|
||||||
|
|
||||||
zerotier-idtool: one
|
backone-idtool: one
|
||||||
|
|
||||||
zerotier-cli: one
|
backone-cli: one
|
||||||
|
|
||||||
libzerotiercore.a: $(CORE_OBJS)
|
libbackonecore.a: $(CORE_OBJS)
|
||||||
ar rcs libzerotiercore.a $(CORE_OBJS)
|
ar rcs libbackonecore.a $(CORE_OBJS)
|
||||||
ranlib libzerotiercore.a
|
ranlib libbackonecore.a
|
||||||
|
|
||||||
core: libzerotiercore.a
|
core: libbackonecore.a
|
||||||
|
|
||||||
selftest: $(CORE_OBJS) $(ONE_OBJS) selftest.o
|
selftest: $(CORE_OBJS) $(ONE_OBJS) selftest.o
|
||||||
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o zerotier-selftest selftest.o $(CORE_OBJS) $(ONE_OBJS) $(LIBS)
|
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o backone-selftest selftest.o $(CORE_OBJS) $(ONE_OBJS) $(LIBS)
|
||||||
$(STRIP) zerotier-selftest
|
$(STRIP) backone-selftest
|
||||||
|
|
||||||
zerotier-selftest: selftest
|
backone-selftest: selftest
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -rf *.a *.o node/*.o controller/*.o osdep/*.o service/*.o ext/http-parser/*.o build-* zerotier-one zerotier-idtool zerotier-selftest zerotier-cli $(ONE_OBJS) $(CORE_OBJS)
|
rm -rf *.a *.o node/*.o controller/*.o osdep/*.o service/*.o ext/http-parser/*.o build-* backone backone-idtool backone-selftest backone-cli $(ONE_OBJS) $(CORE_OBJS)
|
||||||
|
|
||||||
debug: FORCE
|
debug: FORCE
|
||||||
$(MAKE) -j ZT_DEBUG=1
|
$(MAKE) -j ZT_DEBUG=1
|
||||||
|
|
||||||
install: one
|
install: one
|
||||||
rm -f /usr/local/sbin/zerotier-one
|
rm -f /usr/local/sbin/backone
|
||||||
cp zerotier-one /usr/local/sbin
|
cp backone /usr/local/sbin
|
||||||
ln -sf /usr/local/sbin/zerotier-one /usr/local/sbin/zerotier-cli
|
ln -sf /usr/local/sbin/backone /usr/local/sbin/backone-cli
|
||||||
ln -sf /usr/local/sbin/zerotier-one /usr/local/bin/zerotier-idtool
|
ln -sf /usr/local/sbin/backone /usr/local/bin/backone-idtool
|
||||||
|
|
||||||
uninstall: FORCE
|
uninstall: FORCE
|
||||||
rm -rf /usr/local/sbin/zerotier-one /usr/local/sbin/zerotier-cli /usr/local/bin/zerotier-idtool /var/db/zerotier-one/zerotier-one.port /var/db/zerotier-one/zerotier-one.pid /var/db/zerotier-one/iddb.d
|
rm -rf /usr/local/sbin/backone /usr/local/sbin/backone-cli /usr/local/bin/backone-idtool /var/db/backone/backone.port /var/db/backone/backone.pid /var/db/backone/iddb.d
|
||||||
|
|
||||||
FORCE:
|
FORCE:
|
||||||
+17
-1
@@ -9,7 +9,7 @@ ifeq ($(origin CXX),default)
|
|||||||
CXX:=$(shell if [ -e /opt/rh/devtoolset-8/root/usr/bin/g++ ]; then echo /opt/rh/devtoolset-8/root/usr/bin/g++; else echo $(CXX); fi)
|
CXX:=$(shell if [ -e /opt/rh/devtoolset-8/root/usr/bin/g++ ]; then echo /opt/rh/devtoolset-8/root/usr/bin/g++; else echo $(CXX); fi)
|
||||||
endif
|
endif
|
||||||
|
|
||||||
INCLUDES?=-Irustybits/target -isystem ext -Iext/prometheus-cpp-lite-1.0/core/include -Iext-prometheus-cpp-lite-1.0/3rdparty/http-client-lite/include -Iext/prometheus-cpp-lite-1.0/simpleapi/include
|
INCLUDES?=-Irustybits/target -isystem ext -isystem ext/liboqs/include -Iext/prometheus-cpp-lite-1.0/core/include -Iext-prometheus-cpp-lite-1.0/3rdparty/http-client-lite/include -Iext/prometheus-cpp-lite-1.0/simpleapi/include
|
||||||
DEFS?=
|
DEFS?=
|
||||||
LDLIBS?=
|
LDLIBS?=
|
||||||
DESTDIR?=
|
DESTDIR?=
|
||||||
@@ -46,6 +46,15 @@ endif
|
|||||||
# Trying to use dynamically linked libhttp-parser causes tons of compatibility problems.
|
# Trying to use dynamically linked libhttp-parser causes tons of compatibility problems.
|
||||||
ONE_OBJS+=ext/http-parser/http_parser.o
|
ONE_OBJS+=ext/http-parser/http_parser.o
|
||||||
|
|
||||||
|
# ext/liboqs 0.16.0 vendored: PQ objects (list in objects.mk), isolated flags
|
||||||
|
override CORE_OBJS+=$(OQS_OBJS)
|
||||||
|
OQS_CFLAGS=-isystem ext/liboqs/include -isystem ext/liboqs/src -isystem ext/liboqs/src/common/pqclean_shims \
|
||||||
|
-Iext/liboqs/src/kem/ml_kem/mlkem-native_ml-kem-768_ref \
|
||||||
|
-Iext/liboqs/src/sig/ml_dsa/mldsa-native_ml-dsa-65_ref \
|
||||||
|
-Iext/liboqs/src/common/sha3/xkcp_low/KeccakP-1600/plain-64bits \
|
||||||
|
-DMLK_CONFIG_PARAMETER_SET=768 -DMLK_CONFIG_FILE=\"../../integration/liboqs/config_c.h\" \
|
||||||
|
-DMLD_CONFIG_PARAMETER_SET=65 -DMLD_CONFIG_FILE=\"../../integration/liboqs/config_c.h\"
|
||||||
|
|
||||||
ifeq ($(ZT_RULES_ENGINE_DEBUGGING),1)
|
ifeq ($(ZT_RULES_ENGINE_DEBUGGING),1)
|
||||||
override DEFS+=-DZT_RULES_ENGINE_DEBUGGING
|
override DEFS+=-DZT_RULES_ENGINE_DEBUGGING
|
||||||
endif
|
endif
|
||||||
@@ -319,6 +328,11 @@ ifeq ($(ZT_OFFICIAL),1)
|
|||||||
CORE_OBJS+=ext/misc/linux-old-glibc-compat.o
|
CORE_OBJS+=ext/misc/linux-old-glibc-compat.o
|
||||||
override LDFLAGS+=-Wl,--wrap=memcpy -static-libstdc++
|
override LDFLAGS+=-Wl,--wrap=memcpy -static-libstdc++
|
||||||
endif
|
endif
|
||||||
|
ifeq ($(ZT_COVERAGE),1)
|
||||||
|
override CFLAGS+=--coverage
|
||||||
|
override CXXFLAGS+=--coverage
|
||||||
|
override LDFLAGS+=--coverage
|
||||||
|
endif
|
||||||
|
|
||||||
ifeq ($(ZT_CONTROLLER),1)
|
ifeq ($(ZT_CONTROLLER),1)
|
||||||
override CXXFLAGS+=-Wall -Wno-deprecated -std=c++17 -pthread $(INCLUDES) -DNDEBUG $(DEFS)
|
override CXXFLAGS+=-Wall -Wno-deprecated -std=c++17 -pthread $(INCLUDES) -DNDEBUG $(DEFS)
|
||||||
@@ -365,6 +379,8 @@ override CXXFLAGS+=-fPIC -fPIE
|
|||||||
|
|
||||||
# Non-executable stack
|
# Non-executable stack
|
||||||
override LDFLAGS+=-Wl,-z,noexecstack
|
override LDFLAGS+=-Wl,-z,noexecstack
|
||||||
|
ext/liboqs/src/%.o: ext/liboqs/src/%.c
|
||||||
|
$(CC) $(CFLAGS) $(OQS_CFLAGS) -c -o $@ $<
|
||||||
|
|
||||||
.PHONY: all
|
.PHONY: all
|
||||||
all: one
|
all: one
|
||||||
|
|||||||
+7
-7
@@ -39,21 +39,21 @@ CXXFLAGS+=$(CFLAGS) -fno-rtti -fpermissive
|
|||||||
all: one
|
all: one
|
||||||
|
|
||||||
one: $(OBJS) service/OneService.o one.o
|
one: $(OBJS) service/OneService.o one.o
|
||||||
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o zerotier-one $(OBJS) service/OneService.o one.o $(LIBS)
|
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o backone $(OBJS) service/OneService.o one.o $(LIBS)
|
||||||
$(STRIP) zerotier-one
|
$(STRIP) backone
|
||||||
ln -sf zerotier-one zerotier-idtool
|
ln -sf backone backone-idtool
|
||||||
ln -sf zerotier-one zerotier-cli
|
ln -sf backone backone-cli
|
||||||
|
|
||||||
selftest: $(OBJS) selftest.o
|
selftest: $(OBJS) selftest.o
|
||||||
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o zerotier-selftest selftest.o $(OBJS) $(LIBS)
|
$(CXX) $(CXXFLAGS) $(LDFLAGS) -o backone-selftest selftest.o $(OBJS) $(LIBS)
|
||||||
$(STRIP) zerotier-selftest
|
$(STRIP) backone-selftest
|
||||||
|
|
||||||
# No installer on FreeBSD yet
|
# No installer on FreeBSD yet
|
||||||
#installer: one FORCE
|
#installer: one FORCE
|
||||||
# ./buildinstaller.sh
|
# ./buildinstaller.sh
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -rf *.o node/*.o controller/*.o osdep/*.o service/*.o ext/http-parser/*.o ext/lz4/*.o ext/json-parser/*.o build-* zerotier-one zerotier-idtool zerotier-selftest zerotier-cli ZeroTierOneInstaller-*
|
rm -rf *.o node/*.o controller/*.o osdep/*.o service/*.o ext/http-parser/*.o ext/lz4/*.o ext/json-parser/*.o build-* backone backone-idtool backone-selftest backone-cli ZeroTierOneInstaller-*
|
||||||
|
|
||||||
debug: FORCE
|
debug: FORCE
|
||||||
make -j 4 ZT_DEBUG=1
|
make -j 4 ZT_DEBUG=1
|
||||||
|
|||||||
+23
-27
@@ -1,13 +1,13 @@
|
|||||||
name: zerotier
|
name: backone
|
||||||
summary: Securely connect any device, anywhere.
|
summary: Securely connect any device, anywhere.
|
||||||
description: |
|
description: |
|
||||||
|
|
||||||
ZeroTier is a software-based managed Ethernet switch for planet Earth. Use it to connect your
|
BackOne is a fork of ZeroTier, a software-based managed Ethernet switch for planet Earth. Use it
|
||||||
desktop clients, servers, phones, NAS, or even individual applications (using our SDK).
|
to connect your desktop clients, servers, phones, NAS, or even individual applications (using
|
||||||
|
our SDK).
|
||||||
|
|
||||||
This snap contains ZeroTier One, a service that provides ZeroTier network connectivity and
|
This snap contains the BackOne daemon, a service that provides ZeroTier network connectivity
|
||||||
makes joining virtual networks as easy as joining IRC or Slack channels. Apps for Android
|
and makes joining virtual networks as easy as joining IRC or Slack channels.
|
||||||
and iOS are available for free in the Google Play and Apple app stores.
|
|
||||||
|
|
||||||
ZeroTier eliminates the LAN/WAN distinction and makes VPNs, tunnels, proxies, and other kludges
|
ZeroTier eliminates the LAN/WAN distinction and makes VPNs, tunnels, proxies, and other kludges
|
||||||
arising from the inflexible nature of physical networks obsolete. Everything is encrypted
|
arising from the inflexible nature of physical networks obsolete. Everything is encrypted
|
||||||
@@ -15,14 +15,12 @@ description: |
|
|||||||
|
|
||||||
Install (be sure to use sudo)
|
Install (be sure to use sudo)
|
||||||
|
|
||||||
sudo snap install zerotier
|
sudo snap install backone
|
||||||
|
|
||||||
Join your network
|
Join your network
|
||||||
|
|
||||||
sudo zerotier join <nwid>
|
sudo backone join <nwid>
|
||||||
sudo zerotier status
|
sudo backone status
|
||||||
|
|
||||||
Approve your new node in ZeroTier Central (https://my.zerotier.com)! Welcome online!
|
|
||||||
|
|
||||||
adopt-info: one
|
adopt-info: one
|
||||||
confinement: strict
|
confinement: strict
|
||||||
@@ -32,41 +30,39 @@ base: core18
|
|||||||
apps:
|
apps:
|
||||||
one:
|
one:
|
||||||
# Add -U to prevent attempting to drop privileges since snaps have their
|
# Add -U to prevent attempting to drop privileges since snaps have their
|
||||||
# own containment mechanism. Otherwise, if a user named "zerotier-one"
|
# own containment mechanism. Otherwise, if a user named "backone"
|
||||||
# exists on the system, the setgid or related calls will fail.
|
# exists on the system, the setgid or related calls will fail.
|
||||||
command: usr/sbin/zerotier-one -U
|
command: usr/sbin/backone -U
|
||||||
daemon: simple
|
daemon: simple
|
||||||
plugs:
|
plugs:
|
||||||
- network
|
- network
|
||||||
- network-bind
|
- network-bind
|
||||||
- network-control
|
- network-control
|
||||||
|
|
||||||
# For backwards compatibility with old package (e.g. zerotier.cli)
|
|
||||||
# Should be removed someday
|
|
||||||
cli:
|
cli:
|
||||||
command: usr/sbin/zerotier-cli
|
command: usr/sbin/backone-cli
|
||||||
plugs:
|
plugs:
|
||||||
- network
|
- network
|
||||||
|
|
||||||
zerotier:
|
backone:
|
||||||
command: usr/sbin/zerotier-cli
|
command: usr/sbin/backone-cli
|
||||||
plugs:
|
plugs:
|
||||||
- network
|
- network
|
||||||
|
|
||||||
idtool:
|
idtool:
|
||||||
command: usr/sbin/zerotier-idtool
|
command: usr/sbin/backone-idtool
|
||||||
plugs:
|
plugs:
|
||||||
- network
|
- network
|
||||||
|
|
||||||
layout:
|
layout:
|
||||||
/var/lib/zerotier-one:
|
/var/lib/backone:
|
||||||
bind: $SNAP_COMMON
|
bind: $SNAP_COMMON
|
||||||
|
|
||||||
parts:
|
parts:
|
||||||
one:
|
one:
|
||||||
plugin: make
|
plugin: make
|
||||||
source: https://github.com/zerotier/zerotierone.git
|
source: https://git.proit.id/dsutanto/BackOne.git
|
||||||
source-branch: "master"
|
source-branch: "main"
|
||||||
build-packages:
|
build-packages:
|
||||||
- build-essential
|
- build-essential
|
||||||
- libc++-dev
|
- libc++-dev
|
||||||
@@ -74,17 +70,17 @@ parts:
|
|||||||
- ZT_SSO_SUPPORTED=0
|
- ZT_SSO_SUPPORTED=0
|
||||||
filesets:
|
filesets:
|
||||||
binaries:
|
binaries:
|
||||||
- usr/sbin/zerotier-one
|
- usr/sbin/backone
|
||||||
- usr/sbin/zerotier-cli
|
- usr/sbin/backone-cli
|
||||||
- usr/sbin/zerotier-idtool
|
- usr/sbin/backone-idtool
|
||||||
prime:
|
prime:
|
||||||
- $binaries
|
- $binaries
|
||||||
override-build: |
|
override-build: |
|
||||||
snapcraftctl build
|
snapcraftctl build
|
||||||
# Grab the version string from the newly-compiled binary.
|
# Grab the version string from the newly-compiled binary.
|
||||||
snapcraftctl set-version "$(./zerotier-one -v)"
|
snapcraftctl set-version "$(./backone -v)"
|
||||||
slots:
|
slots:
|
||||||
zerotier-control:
|
backone-control:
|
||||||
interface: content
|
interface: content
|
||||||
read:
|
read:
|
||||||
- $SNAP_COMMON
|
- $SNAP_COMMON
|
||||||
@@ -4,7 +4,7 @@
|
|||||||
"description": "ZeroTier Rule Script Compiler",
|
"description": "ZeroTier Rule Script Compiler",
|
||||||
"main": "cli.js",
|
"main": "cli.js",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"test": "echo \"Error: no test specified\" && exit 1"
|
"test": "node test.js"
|
||||||
},
|
},
|
||||||
"repository": {
|
"repository": {
|
||||||
"type": "git",
|
"type": "git",
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
const assert = require('assert');
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const RuleCompiler = require('./rule-compiler.js');
|
||||||
|
|
||||||
|
// 1. Bundled example ruleset compiles and produces expected cap/tag metadata.
|
||||||
|
const rules = [];
|
||||||
|
const caps = {};
|
||||||
|
const tags = {};
|
||||||
|
let err = RuleCompiler.compile(
|
||||||
|
fs.readFileSync(path.join(__dirname, 'examples', 'capabilities-and-tags.ztrules')).toString(),
|
||||||
|
rules, caps, tags);
|
||||||
|
assert.strictEqual(err, null, 'example ruleset must compile, got: ' + JSON.stringify(err));
|
||||||
|
assert.ok(Array.isArray(rules) && rules.length > 0, 'document-level rules emitted');
|
||||||
|
assert.strictEqual(caps.ssh.id, 1000, 'cap ssh id');
|
||||||
|
assert.strictEqual(caps.ssh.default, false, 'cap ssh not default');
|
||||||
|
assert.ok(caps.ssh.rules.length > 0, 'cap ssh body rendered');
|
||||||
|
assert.strictEqual(tags.department.id, 1000, 'tag department id');
|
||||||
|
assert.strictEqual(tags.department.enums.engineering, 400, 'tag department enum');
|
||||||
|
assert.ok(rules.some(r => r.type === 'ACTION_ACCEPT'), 'example contains an accept rule');
|
||||||
|
|
||||||
|
// 2. Syntax/semantic errors return [line, col, message], not a throw.
|
||||||
|
err = RuleCompiler.compile('tag broken\n;\n', [], {}, {});
|
||||||
|
assert.ok(Array.isArray(err) && err.length === 3, 'error tuple returned');
|
||||||
|
assert.ok(err[0] >= 1, 'error carries line number');
|
||||||
|
assert.strictEqual(typeof err[2], 'string');
|
||||||
|
assert.ok(err[2].length > 0, 'error carries message');
|
||||||
|
|
||||||
|
// 3. Undefined tag reference rejected with error tuple.
|
||||||
|
err = RuleCompiler.compile('accept tdiff nosuchtag 1;\n', [], {}, {});
|
||||||
|
assert.ok(Array.isArray(err) && err.length === 3, 'undefined tag rejected');
|
||||||
|
|
||||||
|
// 4. Non-string src rejected without throwing.
|
||||||
|
err = RuleCompiler.compile(42, [], {}, {});
|
||||||
|
assert.ok(Array.isArray(err), 'non-string src rejected');
|
||||||
|
|
||||||
|
console.log('rule-compiler: all tests passed');
|
||||||
+8
-1
@@ -41,7 +41,14 @@ Settings available in `local.conf` (this is not valid JSON, and JSON does not al
|
|||||||
"allowManagementFrom": [ "NETWORK/bits", ...] |null, /* If non-NULL, allow JSON/HTTP management from this IP network. Default is 127.0.0.1 only. */
|
"allowManagementFrom": [ "NETWORK/bits", ...] |null, /* If non-NULL, allow JSON/HTTP management from this IP network. Default is 127.0.0.1 only. */
|
||||||
"bind": [ "ip",... ], /* If present and non-null, bind to these IPs instead of to each interface (wildcard IP allowed) */
|
"bind": [ "ip",... ], /* If present and non-null, bind to these IPs instead of to each interface (wildcard IP allowed) */
|
||||||
"allowTcpFallbackRelay": true|false, /* Allow or disallow establishment of TCP relay connections (true by default) */
|
"allowTcpFallbackRelay": true|false, /* Allow or disallow establishment of TCP relay connections (true by default) */
|
||||||
"multipathMode": 0|1|2 /* multipath mode: none (0), random (1), proportional (2) */
|
"multipathMode": 0|1|2, /* multipath mode: none (0), random (1), proportional (2) */
|
||||||
|
"redis": { /* Optional, requires controllerDbPath starting with "postgres:" */
|
||||||
|
"hostname": "str", /* Redis server host */
|
||||||
|
"port": 1-65535, /* Redis server port */
|
||||||
|
"password": "str", /* Auth password, "" for none */
|
||||||
|
"clusterMode": true|false, /* Connect via RedisCluster instead of standalone */
|
||||||
|
"db": 0-15 /* Database index, standalone mode only (cluster mode forces 0) */
|
||||||
|
},
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|||||||
Executable
+59
@@ -0,0 +1,59 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# clang-format gate. Whole repo has format debt (139/141 first-party files fail),
|
||||||
|
# so default mode checks only lines CHANGED vs base. --all checks whole files.
|
||||||
|
# Usage: tools/lint.sh [base-commit] | tools/lint.sh --all
|
||||||
|
set -euo pipefail
|
||||||
|
cd "$(dirname "$0")/.."
|
||||||
|
|
||||||
|
CF="${CLANG_FORMAT:-$(command -v clang-format || true)}"
|
||||||
|
if [ -z "$CF" ]; then
|
||||||
|
echo "lint: clang-format not found (pip install clang-format)" >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
|
PATHSPEC=(
|
||||||
|
'*.cpp' '*.hpp' '*.h'
|
||||||
|
':(exclude)ext/*' ':(exclude)java/*' ':(exclude)rustybits/*'
|
||||||
|
':(exclude)windows/*' ':(exclude)attic/*'
|
||||||
|
)
|
||||||
|
|
||||||
|
fail=0
|
||||||
|
|
||||||
|
check() { # $1=file, rest=--lines args; empty args = whole file
|
||||||
|
local f=$1
|
||||||
|
shift
|
||||||
|
if ! "$CF" --dry-run --Werror "$@" "$f"; then
|
||||||
|
fail=1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
if [ "${1:-}" = "--all" ]; then
|
||||||
|
while IFS= read -r f; do check "$f"; done < <(git ls-files "${PATHSPEC[@]}")
|
||||||
|
else
|
||||||
|
base=${1:-}
|
||||||
|
if [ -z "$base" ]; then
|
||||||
|
base=$(git merge-base HEAD '@{upstream}' 2>/dev/null || echo HEAD~1)
|
||||||
|
fi
|
||||||
|
# tracked changed files: only changed line ranges (MR = modified/renamed content)
|
||||||
|
while IFS= read -r f; do
|
||||||
|
args=()
|
||||||
|
while IFS= read -r hunk; do
|
||||||
|
# new-side header is "+start,count" (git diff format), not "+start,end"
|
||||||
|
[[ $hunk =~ \+([0-9]+)(,([0-9]+))? ]] || continue
|
||||||
|
start=${BASH_REMATCH[1]}
|
||||||
|
count=${BASH_REMATCH[3]:-1}
|
||||||
|
end=$((start + count - 1))
|
||||||
|
if [ "$count" -eq 0 ]; then # deletion-only: nearest surviving line
|
||||||
|
start=$((start > 1 ? start - 1 : 1))
|
||||||
|
end=$start
|
||||||
|
fi
|
||||||
|
args+=(--lines="$start:$end")
|
||||||
|
done < <(git diff -U0 --no-color "$base" --diff-filter=ACMR -- "$f" | grep '^@@' || true)
|
||||||
|
[ ${#args[@]} -eq 0 ] && continue
|
||||||
|
check "$f" "${args[@]}"
|
||||||
|
done < <(git diff --name-only --diff-filter=ACMR "$base" -- "${PATHSPEC[@]}")
|
||||||
|
# untracked new files: whole file (no debt possible yet)
|
||||||
|
while IFS= read -r f; do check "$f"; done < <(git ls-files --others --exclude-standard "${PATHSPEC[@]}")
|
||||||
|
fi
|
||||||
|
|
||||||
|
exit $fail
|
||||||
Reference in new issue
Block a user