# Linux Platform and Kernel Requirements `nx9-wg` is designed for native Linux execution and interacts directly with Linux kernel subsystems via Netlink sockets and direct `/proc` filesystem interfaces. --- ## 1. Kernel Requirements - **Linux Kernel Version**: 5.6 or newer (in-tree WireGuard module support). - **WireGuard Subsystem**: `wireguard.ko` in-tree module (`modprobe wireguard`). - **Generic Netlink (Genl)**: Family `wireguard` for cryptographic interface and peer configuration. - **RTNETLINK**: For network interface lifecycle (RTM_NEWLINK/DELLINK), address assignments (RTM_NEWADDR), and routing table management (RTM_NEWROUTE/DELROUTE). - **Sysctl IP Forwarding**: Direct procfs mutation: - `/proc/sys/net/ipv4/ip_forward` (enabled for IPv4 packet routing) - `/proc/sys/net/ipv6/conf/all/forwarding` (enabled for IPv6 dual-stack routing) --- ## 2. Dynamic Library & Runtime Dependencies When compiled for Linux, `nx9-wg` links dynamically against standard system libraries: | Library | Runtime Function | Installation Package (Debian/Ubuntu) | Installation Package (RHEL/Fedora/Arch) | | :--- | :--- | :--- | :--- | | `libnftables.so.1` | Native nftables ruleset execution | `libnftables1` / `nftables` | `libnftables` / `nftables` | | `libmnl.so.0` | Minimal Netlink library | `libmnl0` | `libmnl` | | `libnftnl.so.11` | Netfilter Netlink object library | `libnftnl11` | `libnftnl` | | `libc.so.6` | Standard C library (glibc / musl) | Base system | Base system | > [!NOTE] > SQLite is statically embedded into the `nx9-wg` binary via `libsqlite3-sys`. No external SQLite installation or database daemon is required. --- ## 3. Security Capabilities & Privilege Boundaries When executed under systemd or non-root service accounts: - `CAP_NET_ADMIN`: Strictly required for RTNETLINK interface lifecycle, IP route mutations, WireGuard Genl socket communication, and nftables Netfilter execution. - `CAP_NET_BIND_SERVICE`: Required if binding the REST API or WireGuard UDP socket to privileged ports (< 1024). --- ## 4. Execution Mode Classification - **Linux Native Mode**: Automatically engaged on Linux systems with `CAP_NET_ADMIN` and kernel WireGuard/Netfilter modules. - **Non-Linux / Simulated Mode**: Automatically engaged on macOS and Windows hosts for development and UI preview. - **Restricted Mode**: Engaged when running on Linux without `CAP_NET_ADMIN`; control-plane REST API, SQLite queries, and diagnostics operate normally, while kernel mutation calls return descriptive permission errors without crashing.