2.5 KiB
2.5 KiB
Linux Platform and Kernel Requirements
nx9-wg is designed for native Linux execution and interacts directly with Linux kernel subsystems via Netlink sockets and direct /proc filesystem interfaces.
1. Kernel Requirements
- Linux Kernel Version: 5.6 or newer (in-tree WireGuard module support).
- WireGuard Subsystem:
wireguard.koin-tree module (modprobe wireguard). - Generic Netlink (Genl): Family
wireguardfor cryptographic interface and peer configuration. - RTNETLINK: For network interface lifecycle (RTM_NEWLINK/DELLINK), address assignments (RTM_NEWADDR), and routing table management (RTM_NEWROUTE/DELROUTE).
- Sysctl IP Forwarding: Direct procfs mutation:
/proc/sys/net/ipv4/ip_forward(enabled for IPv4 packet routing)/proc/sys/net/ipv6/conf/all/forwarding(enabled for IPv6 dual-stack routing)
2. Dynamic Library & Runtime Dependencies
When compiled for Linux, nx9-wg links dynamically against standard system libraries:
| Library | Runtime Function | Installation Package (Debian/Ubuntu) | Installation Package (RHEL/Fedora/Arch) |
|---|---|---|---|
libnftables.so.1 |
Native nftables ruleset execution | libnftables1 / nftables |
libnftables / nftables |
libmnl.so.0 |
Minimal Netlink library | libmnl0 |
libmnl |
libnftnl.so.11 |
Netfilter Netlink object library | libnftnl11 |
libnftnl |
libc.so.6 |
Standard C library (glibc / musl) | Base system | Base system |
Note
SQLite is statically embedded into the
nx9-wgbinary vialibsqlite3-sys. No external SQLite installation or database daemon is required.
3. Security Capabilities & Privilege Boundaries
When executed under systemd or non-root service accounts:
CAP_NET_ADMIN: Strictly required for RTNETLINK interface lifecycle, IP route mutations, WireGuard Genl socket communication, and nftables Netfilter execution.CAP_NET_BIND_SERVICE: Required if binding the REST API or WireGuard UDP socket to privileged ports (< 1024).
4. Execution Mode Classification
- Linux Native Mode: Automatically engaged on Linux systems with
CAP_NET_ADMINand kernel WireGuard/Netfilter modules. - Non-Linux / Simulated Mode: Automatically engaged on macOS and Windows hosts for development and UI preview.
- Restricted Mode: Engaged when running on Linux without
CAP_NET_ADMIN; control-plane REST API, SQLite queries, and diagnostics operate normally, while kernel mutation calls return descriptive permission errors without crashing.