Files
nx9-wg/docs/LINUX_REQUIREMENTS.md

48 lines
2.5 KiB
Markdown

# Linux Platform and Kernel Requirements
`nx9-wg` is designed for native Linux execution and interacts directly with Linux kernel subsystems via Netlink sockets and direct `/proc` filesystem interfaces.
---
## 1. Kernel Requirements
- **Linux Kernel Version**: 5.6 or newer (in-tree WireGuard module support).
- **WireGuard Subsystem**: `wireguard.ko` in-tree module (`modprobe wireguard`).
- **Generic Netlink (Genl)**: Family `wireguard` for cryptographic interface and peer configuration.
- **RTNETLINK**: For network interface lifecycle (RTM_NEWLINK/DELLINK), address assignments (RTM_NEWADDR), and routing table management (RTM_NEWROUTE/DELROUTE).
- **Sysctl IP Forwarding**: Direct procfs mutation:
- `/proc/sys/net/ipv4/ip_forward` (enabled for IPv4 packet routing)
- `/proc/sys/net/ipv6/conf/all/forwarding` (enabled for IPv6 dual-stack routing)
---
## 2. Dynamic Library & Runtime Dependencies
When compiled for Linux, `nx9-wg` links dynamically against standard system libraries:
| Library | Runtime Function | Installation Package (Debian/Ubuntu) | Installation Package (RHEL/Fedora/Arch) |
| :--- | :--- | :--- | :--- |
| `libnftables.so.1` | Native nftables ruleset execution | `libnftables1` / `nftables` | `libnftables` / `nftables` |
| `libmnl.so.0` | Minimal Netlink library | `libmnl0` | `libmnl` |
| `libnftnl.so.11` | Netfilter Netlink object library | `libnftnl11` | `libnftnl` |
| `libc.so.6` | Standard C library (glibc / musl) | Base system | Base system |
> [!NOTE]
> SQLite is statically embedded into the `nx9-wg` binary via `libsqlite3-sys`. No external SQLite installation or database daemon is required.
---
## 3. Security Capabilities & Privilege Boundaries
When executed under systemd or non-root service accounts:
- `CAP_NET_ADMIN`: Strictly required for RTNETLINK interface lifecycle, IP route mutations, WireGuard Genl socket communication, and nftables Netfilter execution.
- `CAP_NET_BIND_SERVICE`: Required if binding the REST API or WireGuard UDP socket to privileged ports (< 1024).
---
## 4. Execution Mode Classification
- **Linux Native Mode**: Automatically engaged on Linux systems with `CAP_NET_ADMIN` and kernel WireGuard/Netfilter modules.
- **Non-Linux / Simulated Mode**: Automatically engaged on macOS and Windows hosts for development and UI preview.
- **Restricted Mode**: Engaged when running on Linux without `CAP_NET_ADMIN`; control-plane REST API, SQLite queries, and diagnostics operate normally, while kernel mutation calls return descriptive permission errors without crashing.