feat: complete nx9-wg v0.8.0 platform

This commit is contained in:
thakares committed 2026-08-17 14:25:45 +05:30
1 parent c75e5c4e71
commit c8a9b7cde6
52 files changed
+7751 -725

No files matched your search

+28 -15
View File
@@ -1,34 +1,47 @@
# Linux Platform and Kernel Requirements
`nx9-wg` is built for modern Linux systems and relies directly on kernel networking features.
`nx9-wg` is designed for native Linux execution and interacts directly with Linux kernel subsystems via Netlink sockets and direct `/proc` filesystem interfaces.
---
## 1. Kernel Requirements
- **Linux Kernel Version**: 5.6 or newer (WireGuard module is included in mainline kernel 5.6+).
- **Kernel Module**: `wireguard.ko` (`modprobe wireguard`).
- **Sysctl IP Forwarding**:
- `/proc/sys/net/ipv4/ip_forward` (must be `1` for VPN client internet routing).
- `/proc/sys/net/ipv6/conf/all/forwarding` (optional, for IPv6 dual-stack).
- **Linux Kernel Version**: 5.6 or newer (in-tree WireGuard module support).
- **WireGuard Subsystem**: `wireguard.ko` in-tree module (`modprobe wireguard`).
- **Generic Netlink (Genl)**: Family `wireguard` for cryptographic interface and peer configuration.
- **RTNETLINK**: For network interface lifecycle (RTM_NEWLINK/DELLINK), address assignments (RTM_NEWADDR), and routing table management (RTM_NEWROUTE/DELROUTE).
- **Sysctl IP Forwarding**: Direct procfs mutation:
- `/proc/sys/net/ipv4/ip_forward` (enabled for IPv4 packet routing)
- `/proc/sys/net/ipv6/conf/all/forwarding` (enabled for IPv6 dual-stack routing)
---
## 2. Firewall and Packet Filtering
## 2. Dynamic Library & Runtime Dependencies
- **`nftables`**: `nx9-wg` requires `nftables` in the kernel.
- **Isolated Table**: All rules are scoped inside `table inet nx9_wg`. `nx9-wg` does not alter or flush tables created by Docker, Kubernetes, or other firewall utilities.
When compiled for Linux, `nx9-wg` links dynamically against standard system libraries:
| Library | Runtime Function | Installation Package (Debian/Ubuntu) | Installation Package (RHEL/Fedora/Arch) |
| :--- | :--- | :--- | :--- |
| `libnftables.so.1` | Native nftables ruleset execution | `libnftables1` / `nftables` | `libnftables` / `nftables` |
| `libmnl.so.0` | Minimal Netlink library | `libmnl0` | `libmnl` |
| `libnftnl.so.11` | Netfilter Netlink object library | `libnftnl11` | `libnftnl` |
| `libc.so.6` | Standard C library (glibc / musl) | Base system | Base system |
> [!NOTE]
> SQLite is statically embedded into the `nx9-wg` binary via `libsqlite3-sys`. No external SQLite installation or database daemon is required.
---
## 3. Capability Requirements
## 3. Security Capabilities & Privilege Boundaries
When running without full root privileges, the process requires:
- `CAP_NET_ADMIN`: For configuring network links, routes, and packet filter tables.
- `CAP_NET_BIND_SERVICE`: If binding to low UDP ports (< 1024).
When executed under systemd or non-root service accounts:
- `CAP_NET_ADMIN`: Strictly required for RTNETLINK interface lifecycle, IP route mutations, WireGuard Genl socket communication, and nftables Netfilter execution.
- `CAP_NET_BIND_SERVICE`: Required if binding the REST API or WireGuard UDP socket to privileged ports (< 1024).
---
## 4. Unsupported Environments
## 4. Execution Mode Classification
- macOS and Windows do not support the Linux in-tree WireGuard kernel module. For local testing on non-Linux platforms, `nx9-wg` automatically engages the built-in `SimulatedWireGuardEngine` and `SimulatedNetworkEngine`.
- **Linux Native Mode**: Automatically engaged on Linux systems with `CAP_NET_ADMIN` and kernel WireGuard/Netfilter modules.
- **Non-Linux / Simulated Mode**: Automatically engaged on macOS and Windows hosts for development and UI preview.
- **Restricted Mode**: Engaged when running on Linux without `CAP_NET_ADMIN`; control-plane REST API, SQLite queries, and diagnostics operate normally, while kernel mutation calls return descriptive permission errors without crashing.