36 KiB
NX9 WireGuard (nx9-wg) — Full Technical Architecture & Stack Report
"Software people can own, understand, and control." — NX9 Systems (https://nx9.in)
📑 Table of Contents
- Executive Summary
- The NX9 Philosophy in Implementation
- The Architectural Paradigm Shift
- Six-Crate Workspace Architecture
- Complete Capability Inventory
- Native Linux Execution Planes
- Closed-Loop Reconciliation & Convergence
- Embedded Single Page Application (SPA) & WebSockets
- REST API & WebSocket Protocol Reference
- Native CLI Command System
- Security Model & Capability Isolation
- Disaster Recovery, Backups & Upgrades
- Release Engineering & Deployment Lifecycle
- Quality Assurance & Verification Evidence
- Ecosystem & License Summary
1. Executive Summary
nx9-wg is a sovereign, self-hosted, Linux-native VPN and network control plane built directly around the Linux kernel's in-tree WireGuard implementation (wireguard.ko).
Rather than functioning as a fragile user interface wrapper that shells out to external command-line utilities (wg, ip, nft, sysctl), nx9-wg establishes an integrated, single-binary architecture. It combines authoritative SQLite desired-state persistence, direct kernel Netlink execution (RTNETLINK and WireGuard Generic Netlink), in-process Netfilter firewall/NAT compilation (libnftables.so.1), continuous closed-loop reconciliation, a multi-format native CLI, and an embedded zero-dependency Single Page Application (SPA) Web UI.
2. The NX9 Philosophy in Implementation
Every design and architectural choice in nx9-wg directly reflects the core philosophy of the NX9 Ecosystem (https://nx9.in):
| NX9 Principle | Core Intent | nx9-wg Implementation |
|---|---|---|
| 🔑 Operator Ownership | Full control over binaries, configurations, databases, keys, and backups with zero dependency on cloud-hosted control planes. | 100% local operation. Private keys, configuration data, and encryption parameters never leave the operator's host. |
| 🖥️ Self-Hosting First | Built to be deployed and operated effortlessly by a single administrator without requiring Kubernetes or external infrastructure. | Self-contained single executable. Bootstrapped with a single command (nx9-wg init), running seamlessly under standard systemd. |
| ⚡ Simplicity Over Complexity | One binary, one configuration file, one SQLite database, one administrator. | No multi-daemon orchestration, no external message queues, no Node.js runtime, no Python scripts, and zero shell wrappers. |
| 🛡️ Privacy by Default | Zero analytics, zero telemetry collection, zero third-party tracking, and zero assumptions of external cloud connectivity. | No phone-home telemetry. Completely air-gapped capable with all static assets, fonts, and scripts embedded in the binary. |
| 🔒 Security by Design | Modern cryptography, strict invariants, and append-only audit logging embedded from day one. | Argon2id password hashing, SHA-256 token digests, X25519 key generation, single-admin database constraint (CHECK (id=1)), and strict secret redaction. |
| 🔧 Operational Excellence | Diagnostics, backup/restore, migration tools, CLI management, and comprehensive documentation built-in. | Multi-subsystem automated health inspections, atomic online SQLite VACUUM INTO snapshots with SHA-256 manifests, and 100% CLI parity. |
| ⏳ Long-Term Stability | Avoid dependency churn. Build software that remains understandable and maintainable years into the future. | Built in stable native Rust (Edition 2024), standard SQLite 3 storage, standard TOML configuration, and POSIX-compliant systemd integration. |
| 🌐 Open Source First | 100% free and open-source software under permissive licensing. | Dual-licensed under MIT OR Apache-2.0. Complete freedom to inspect, audit, build, and extend. |
| ♾️ Zero Vendor Lock-In | Standard data formats, open protocols, and zero proprietary cloud lock-in. | Standard SQLite database, standard WireGuard .conf files, standard RFC-compliant JSON/YAML/CSV output formats, and open Netlink sockets. |
3. The Architectural Paradigm Shift
Typical WireGuard Management Wrappers
┌──────────┐ ┌──────────────────────┐ ┌────────────────────────────┐ ┌──────────────┐
│ Web UI │ ──► │ Text Config Files │ ──► │ wg / ip / nft / sysctl │ ──► │ Linux Kernel │
│ (Node/Py)│ │(/etc/wireguard/*.conf│ │ (Subprocess Spawning) │ │ (wireguard.ko│
└──────────┘ └──────────────────────┘ └────────────────────────────┘ └──────────────┘
Disadvantages: Fragile process spawning, race conditions, lack of atomic state, broken host routing, vulnerability to configuration drift, and heavy runtime dependency footprints.
Whereas nx9-wg is a Native Control & Execution Plane:
┌───────────────────────────────────┐
│ nx9-wg │
└─────────────────┬─────────────────┘
│
┌────────────────────────────────┴────────────────────────────────┐
│ │
┌─────────▼─────────┐ ┌─────────▼─────────┐
│ Desired State │ │ Live State │
│ (Authoritative) │ │ (Kernel Cache) │
└─────────┬─────────┘ └─────────▲─────────┘
│ │
┌─────────▼─────────┐ ┌─────────┴─────────┐
│ SQLite 3 (WAL) │ │ Linux Kernel │
└─────────┬─────────┘ └─────────▲─────────┘
│ │
│ Live Netlink Telemetry
▼ │
┌───────────────────┐ │
│ Reconciliation │ ◄─────────────────────────────────────────────────────┘
│ Engine │
└─────────┬─────────┘
│
├── 🔐 WireGuard Generic Netlink (family "wireguard")
├── 🌐 RTNETLINK (Links, IPv4/IPv6 Addresses, Routes)
├── 🔥 Netfilter / libnftables FFI (table inet nx9_wg)
└── ↔️ Direct Procfs IP Forwarding (/proc/sys/net)
│
▼
┌───────────────────┐
│ Linux Networking │
└───────────────────┘
4. Six-Crate Workspace Architecture
nx9-wg is architected as a modular six-crate Cargo workspace ensuring clean separation of concerns, zero circular dependencies, and isolated testability:
nx9-wg (Root Executable & Unified Entrypoint)
├── 📦 crates/nx9-wg-core — Domain models, RFC validation, cryptography, configuration
├── 📦 crates/nx9-wg-db — SQLite storage engine, migration framework, repositories
├── 📦 crates/nx9-wireguard — WireGuard Generic Netlink, RTNETLINK link engine, config & QR
├── 📦 crates/nx9-wg-network — RTNETLINK routes/addresses, libnftables Netfilter, procfs
├── 📦 crates/nx9-wg-api — Axum REST router, WebSockets, auth, reconciliation, IP allocator
└── 📦 crates/nx9-wg-ui — Design tokens, CSS compiler, view models, SPA integration
5. Complete Capability Inventory
nx9-wg delivers a comprehensive suite of 20 core infrastructure capabilities:
| Icon | Capability | Architectural Description |
|---|---|---|
| 🔐 | WireGuard Interface Lifecycle | In-process RTNETLINK link creation (RTM_NEWLINK), state toggling (IFF_UP/IFF_DOWN), and WireGuard Generic Netlink cryptokey configuration (WG_CMD_SET_DEVICE). |
| 👥 | Cryptographic Peer Enrollment | Dynamic Curve25519 public key management, preshared keys, CIDR allowed IPs, persistent keepalive intervals, and atomic ReplacePeers synchronization. |
| 🌐 | IPv4 & IPv6 Address Management | Native Netlink address assignment (RTM_NEWADDR / RTM_DELADDR) across WireGuard interfaces without invoking ip addr. |
| 🛣️ | Kernel Route Management | Routing table synchronization (RTM_NEWROUTE / RTM_DELROUTE) with strict default gateway protection and multi-tenant non-interference invariants. |
| 🔥 | nftables Netfilter Firewall | In-process rule compilation and transactional application via libnftables.so.1 confined strictly to table inet nx9_wg. |
| 🛡️ | Scoped NAT & Masquerading | Outbound NAT masquerade dynamically calculated and applied strictly to managed WireGuard client subnets, preventing host network disruption. |
| ↔️ | Direct Procfs IP Forwarding | Direct atomic mutation of /proc/sys/net/ipv4/ip_forward and /proc/sys/net/ipv6/conf/all/forwarding without invoking sysctl. |
| 📡 | Live Kernel Telemetry | Real-time extraction of handshake timestamps, rx/tx byte counters, and roaming remote socket endpoints directly from kernel sockets. |
| 🔄 | Desired-State Reconciliation | Continuous closed-loop control cycle bringing the Linux kernel execution plane into alignment with authoritative SQLite storage. |
| 🧭 | 5-Subsystem Drift Detection | Deterministic, read-only calculation of state divergence across interfaces, peers, routes, firewall rules, and IP forwarding. |
| ♻️ | Cold-Boot Restart Recovery | Autonomous reconstruction of kernel network topology, routes, and firewall rules upon daemon startup or host reboot. |
| 🧪 | Cross-Platform Simulation Engine | In-memory simulated execution planes enabling full UI and CLI development on macOS and Windows without requiring Linux Netlink. |
| 🖥️ | Multi-Format Native CLI | 100% native CLI coverage across all 17 subcommands supporting table, json, yaml, and csv output with script-friendly exit codes. |
| 🌐 | Axum REST API & WebSockets | High-performance asynchronous HTTP server with session/bearer authentication and a real-time WebSocket event broadcaster (/api/v1/ws). |
| 💻 | Embedded Zero-Dependency SPA | Modern HTML5/CSS3/Vanilla ES6+ Single Page Application compiled into the binary with Light/Dark theme support and 15 interactive views. |
| 📊 | Automated Health Diagnostics | Built-in inspection across 9 subsystems with structured status reporting, root-cause diagnostics, and actionable remediation hints. |
| 💾 | Atomic Disaster Recovery Backups | Online non-blocking SQLite VACUUM INTO snapshots with SHA-256 manifest verification and automatic pre-restore safety checkpoints. |
| 🔑 | Single-Administrator Security | Database-enforced single identity (CHECK (id=1)), Argon2id password hashing, SHA-256 API token storage, and brute-force login rate limiting. |
| 📱 | Client Profiles & QR Engine | Provider/device MTU profiles (1280 vs 1360 vs 1420), collision-resistant IP allocation, and pure Rust vector SVG, PNG, and ASCII QR generation. |
| 📦 | Production Release Packaging | Standalone distribution archive generator (scripts/package-release.sh), automated installer/uninstaller, and hardened systemd service unit. |
6. Native Linux Execution Planes
nx9-wg enforces a Zero Subprocess Guarantee across the entire production codebase:
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ Rust Production Binary │
├────────────────────────────┬────────────────────────────┬──────────────────────────────┤
│ NativeLinuxWireGuardEngine │ NativeLinuxNetworkEngine │ NativeLinuxNftablesEngine │
├────────────────────────────┼────────────────────────────┼──────────────────────────────┤
│ • AF_NETLINK │ • NETLINK_ROUTE │ • In-process libnftables FFI │
│ • NETLINK_GENERIC (wg) │ • RTM_NEWLINK / DELLINK │ • nft_ctx_new() │
│ • WG_CMD_SET_DEVICE │ • RTM_NEWADDR / DELADDR │ • Atomic Netfilter batch │
│ • WG_CMD_GET_DEVICE │ • RTM_NEWROUTE / DELROUTE │ • Scoped: table inet nx9_wg │
│ • WGDEVICE_F_REPLACE_PEERS │ • Direct /proc/sys writes │ • Zero host table flushes │
└─────────────┬──────────────┴─────────────┬──────────────┴──────────────┬───────────────┘
▼ ▼ ▼
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ Linux Kernel │
│ (wireguard.ko • RTNETLINK • Netfilter • /proc/sys/net) │
└────────────────────────────────────────────────────────────────────────────────────────┘
7. Closed-Loop Reconciliation & Convergence
Reconciliation is the foundational control loop that bridges authoritative SQLite state with the Linux kernel:
┌──────────────────────────────────────────────────────────────────┐
│ 1. SQLite Desired State (Authoritative Persistent Source of Truth│
└────────────────────────────────┬─────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────────────┐
│ 2. Live Kernel Query (WireGuard Genl, RTNL routes, table nx9_wg) │
└────────────────────────────────┬─────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────────────┐
│ 3. Drift Detection (Read-Only Deterministic Multi-Subsystem Diff)│
└────────────────────────────────┬─────────────────────────────────┘
│
┌───────────────┴───────────────┐
│ has_drift == false? │
├───────────────────────┬───────┤
│ YES │ NO │
▼ ▼ │
┌─────────────┐ ┌──────────────▼────────────────┐
│ Converged │ │ 4. Acquire Async Mutex Lock │
│ (In Sync) │ └──────────────┬────────────────┘
└─────────────┘ │
▼
┌───────────────────────────────┐
│ 5. Execute Native Mutations │
│ (Genl SET_DEVICE, RTNL) │
└──────────────┬────────────────┘
│
▼
┌───────────────────────────────┐
│ 6. Post-Apply Verification │
└──────────────┬────────────────┘
│
┌───────────────┴───────────────┐
▼ ▼
┌─────────────┐ ┌─────────────┐
│ Converged │ │ Partial │
│ (100% Sync)│ │ Failure │
└─────────────┘ └─────────────┘
The Six Reconciliation Lifecycle States
Plan: Read-only calculation of drift between SQLite and kernel.Applying: In-progress dispatch of native mutations across execution planes.Verifying: Querying live kernel state to confirm applied changes took effect.Converged: 100% synchronization achieved with zero remaining drift.PartialFailure: One or more execution planes failed during apply (e.g. permission error).DriftRemains: Apply completed without fatal error, but post-verification detected unapplied state.
8. Embedded Single Page Application (SPA) & WebSockets
The nx9-wg frontend is a zero-dependency HTML5/CSS/JavaScript SPA embedded directly into the Rust binary:
- Zero External Toolchains: No Node.js, npm, Webpack, Vite, React, or external CDN dependencies.
- Embedded In-Memory Delivery: Bundled at compile-time via
include_str!()and served from memory. - Design Tokens: Custom CSS token system (
crates/nx9-wg-ui/src/css.rs) supporting Light and Dark modes. - Real-Time WebSocket Stream: Subscribes to
ws://<host>/api/v1/wsfor live handshakes and drift alerts without polling. - 15 Interactive Views:
#dashboard— System overview, uptime, interface/peer counts, health cards.#interfaces— WireGuard interface CRUD, listen port, MTU, state toggles.#peers— Enrolled peer table, real-time handshakes, profile resolution,.confexport, SVG QR modal.#networks— Subnet network ranges, CIDR masks, available IP inspector.#routes— Kernel route definitions, gateway assignments, interface scoping.#firewall— nftables packet filtering rules intable inet nx9_wg, priority sorting.#nat— Managed subnet NAT masquerade status and instant toggle.#forwarding— Kernel IPv4/IPv6 packet forwarding status and toggle.#reconciliation— Real-time kernel drift overview, action plan table, interactive Apply button.#diagnostics— Automated multi-subsystem health checks with remediation hints.#live-state— Raw Linux Netlink telemetry, active kernel interfaces, live routing table.#settings— Key-value appliance parameters and danger zone reset controls.#backups— Online SQLite backup snapshots list, instant backup creation,.dbdownload.#audit— Append-only security and administrative audit trail.#administrator— Admin account verification, password rotation, and one-time API token generation.
9. REST API & WebSocket Protocol Reference
Authentication Mechanisms
- Session Cookie:
nx9_session=<UUID>returned viaPOST /api/v1/auth/login. - Bearer Token:
Authorization: Bearer nx9_<UUID>_<SECRET>passed in HTTP headers.
Complete REST Route Inventory
POST /api/v1/auth/login - Authenticate administrator & create session
POST /api/v1/auth/logout - Invalidate active session
GET /api/v1/auth/session - Query authenticated session info
POST /api/v1/auth/password - Rotate admin password (invalidates all sessions)
GET /api/v1/auth/tokens - List active API token metadata
POST /api/v1/auth/tokens - Generate new API token (one-time raw secret return)
DELETE /api/v1/auth/tokens/{id} - Revoke an API token
GET /api/v1/system - System operational overview and object counts
GET /api/v1/system/health - Public health check endpoint
GET /api/v1/system/version - Version, build edition, and architecture
GET /api/v1/system/settings - List all appliance key-value settings
PUT /api/v1/system/settings - Upsert appliance setting
GET /api/v1/interfaces - List all WireGuard interfaces
POST /api/v1/interfaces - Create WireGuard interface
GET /api/v1/interfaces/{id} - Get interface details
PUT /api/v1/interfaces/{id} - Update interface configuration
DELETE /api/v1/interfaces/{id} - Delete interface (cascades to peers)
POST /api/v1/interfaces/{id}/enable - Set interface IFF_UP
POST /api/v1/interfaces/{id}/disable - Set interface IFF_DOWN
GET /api/v1/interfaces/{id}/status - Query live kernel netlink telemetry
GET /api/v1/interfaces/{id}/peers - List peers attached to interface
POST /api/v1/interfaces/{id}/peers - Enroll new peer on interface
GET /api/v1/peers/{id} - Get peer details
PUT /api/v1/peers/{id} - Update peer parameters
DELETE /api/v1/peers/{id} - Delete peer
POST /api/v1/peers/{id}/enable - Enable peer
POST /api/v1/peers/{id}/disable - Disable peer
GET /api/v1/peers/{id}/config - Download client .conf file
GET /api/v1/peers/{id}/qr - Render QR code (SVG / PNG / ASCII)
GET /api/v1/networks - List subnet networks
POST /api/v1/networks - Create subnet network
GET /api/v1/networks/{id} - Get network details
DELETE /api/v1/networks/{id} - Delete network
GET /api/v1/networks/{id}/available - List available unallocated IP addresses
GET /api/v1/routes - List kernel routing entries
POST /api/v1/routes - Create routing entry
DELETE /api/v1/routes/{id} - Delete routing entry
GET /api/v1/firewall/rules - List nftables firewall rules
POST /api/v1/firewall/rules - Create firewall rule
DELETE /api/v1/firewall/rules/{id} - Delete firewall rule
POST /api/v1/firewall/rules/{id}/enable - Enable firewall rule
POST /api/v1/firewall/rules/{id}/disable - Disable firewall rule
GET /api/v1/reconcile/plan - Read-only drift calculation plan
POST /api/v1/reconcile/apply - Serialized kernel apply and convergence check
GET /api/v1/diagnostics/all - Run full diagnostics across all 9 subsystems
GET /api/v1/diagnostics/{subsystem} - Run diagnostics for single subsystem
GET /api/v1/backups - List backup records
POST /api/v1/backups/create - Trigger atomic online VACUUM INTO snapshot
GET /api/v1/backups/{id}/download - Download raw SQLite database snapshot
POST /api/v1/backups/{id}/restore - Restore database with automatic safety backup
DELETE /api/v1/backups/{id} - Delete backup snapshot file and metadata
GET /api/v1/audit - Query append-only audit trail
10. Native CLI Command System
nx9-wg provides 100% native CLI coverage across all 17 subcommands:
# Global output formats: --format table | json | yaml | csv
nx9-wg version
nx9-wg serve --bind 127.0.0.1:8080
nx9-wg init --generate-password --write-password-file /var/lib/nx9-wg/admin-password
# Administration & Authentication
nx9-wg admin info
nx9-wg admin password
nx9-wg admin token create "ci-pipeline" --expires-in-days 90 --write-token-file /tmp/token
nx9-wg admin token list
nx9-wg admin token revoke <TOKEN_UUID>
# Interface & Peer Management
nx9-wg interface list
nx9-wg interface create wg0 --address-v4 10.100.0.1/24 --port 51820 --mtu 1420
nx9-wg peer create --interface wg0 --name alice --profile full_tunnel --mtu 1280
nx9-wg peer qr <PEER_UUID>
nx9-wg peer config <PEER_UUID>
# Networking, Firewall & NAT
nx9-wg route add --destination 192.168.50.0/24 --gateway 10.100.0.2 --interface-name wg0
nx9-wg firewall add --name "allow-dns" --protocol udp --port 53 --action accept --priority 10
nx9-wg nat enable
nx9-wg forwarding enable
# State Reconciliation & Diagnostics
nx9-wg reconcile plan
nx9-wg reconcile apply
nx9-wg diagnostics all
# Disaster Recovery
nx9-wg backup create --description "Pre-upgrade snapshot"
nx9-wg backup verify /var/lib/nx9-wg/backups/nx9-backup-...db
nx9-wg backup restore <BACKUP_UUID>
11. Security Model & Capability Isolation
A. Single Administrator Identity
- Database-level integrity constraint:
CHECK (id = 1)inadminstable. - Eliminates multi-tenant privilege escalation and role-confusion attack surfaces.
B. Credential Protection
- Passwords: Hashed with Argon2id using unique cryptographic salts.
- API Tokens: Stored exclusively as SHA-256 digests in SQLite; raw tokens are displayed once upon creation.
- Secret Redaction: Private keys, preshared keys, and password hashes implement custom
std::fmt::Debugimplementations returning[REDACTED].
C. Hardened systemd Sandbox (nx9-wg.service)
[Unit]
Description=NX9 WireGuard Native VPN Platform
After=network.target network-online.target
[Service]
Type=simple
ExecStart=/usr/local/bin/nx9-wg serve
Restart=always
RestartSec=5s
# Minimal Linux Capabilities
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
# Sandboxing Directives
ProtectSystem=strict
ProtectHome=true
PrivateTmp=true
ProtectControlGroups=true
RestrictSUIDSGID=true
LockPersonality=true
NoNewPrivileges=true
# Allowed Network Address Families
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
# Explicit Read-Write Paths (for state and direct procfs forwarding)
ReadWritePaths=/var/lib/nx9-wg /etc/nx9-wg /var/log/nx9-wg /proc/sys/net
ProtectKernelTunables=false
# Systemd Directory Management
StateDirectory=nx9-wg
ConfigurationDirectory=nx9-wg
LogsDirectory=nx9-wg
12. Disaster Recovery, Backups & Upgrades
Atomic Online Backups
- Uses SQLite
VACUUM INTOto produce non-blocking, consistent binary database snapshots while the daemon is actively serving traffic. - Generates SHA-256 manifest records for each snapshot.
Safe Rollback Workflow
┌────────────────────────────────────────────────────────┐
│ 1. Operator Initiates Restore (nx9-wg backup restore) │
└───────────────────────────┬────────────────────────────┘
│
┌───────────────────────────▼────────────────────────────┐
│ 2. Verify Backup File Size, Magic Header & SHA-256 │
└───────────────────────────┬────────────────────────────┘
│
┌───────────────────────────▼────────────────────────────┐
│ 3. Create Pre-Restore Safety Snapshot (Automatic Fallback│
└───────────────────────────┬────────────────────────────┘
│
┌───────────────────────────▼────────────────────────────┐
│ 4. Close Connection Pools, Replace .db, Clean WAL/SHM │
└───────────────────────────┬────────────────────────────┘
│
┌───────────────────────────▼────────────────────────────┐
│ 5. Reopen Database & Execute Reconciliation Engine │
│ (Kernel state converged to restored desired state) │
└────────────────────────────────────────────────────────┘
13. Release Engineering & Deployment Lifecycle
Automated Packaging Pipeline (scripts/package-release.sh)
Generates self-contained, reproducible distribution archives in target/dist/:
nx9-wg-v1.0.0-linux-x86_64.tar.gz(7.8 MB)nx9-wg-v1.0.0-linux-x86_64.tar.xz(5.0 MB)nx9-wg-v1.0.0-linux-x86_64.sha256(Cryptographic checksum manifest)
Production Filesystem Layout & Permissions
/usr/local/bin/nx9-wg 0755 root:root - Native Executable Binary
/etc/nx9-wg/ 0750 root:root - Configuration Directory
└── config.toml 0640 root:root - Production Configuration
/var/lib/nx9-wg/ 0700 root:root - State & SQLite Directory
├── nx9-wg.db 0600 root:root - Authoritative SQLite Database
├── nx9-wg.db-wal 0600 root:root - WAL Journal
├── admin-password 0600 root:root - Initial Bootstrap Password
└── backups/ 0700 root:root - Backup Snapshots Directory
/var/log/nx9-wg/ 0750 root:root - Operational Logs
/etc/systemd/system/nx9-wg.service 0644 root:root - Hardened Service Unit
14. Quality Assurance & Verification Evidence
All quality gates have been executed and verified clean:
| Quality Gate | Verification Command | Result |
|---|---|---|
| Code Formatting | cargo fmt --all -- --check |
PASS (Zero diffs) |
| Workspace Compilation | cargo check --workspace |
PASS (Zero errors) |
| Workspace Unit Tests | cargo test --workspace |
PASS (162 / 162 passed, 100%) |
| Clippy Linter Check | cargo clippy --workspace --all-targets --all-features -- -D warnings |
PASS (Zero warnings) |
| Comprehensive CLI Suite | LIVE=0 bash scripts/test-cli-comprehensive.sh |
PASS (203 passed / 7 skipped) |
| Native Integration Suite | LIVE=0 bash scripts/test-native-integration.sh |
PASS (19 passed / 1 skipped) |
| Dedicated Live Kernel Suite | LIVE=0 bash scripts/test-live-kernel.sh |
PASS (23 passed / 1 skipped) |
| Subprocess Safety Audit | Automated source scan for Command::new |
PASS (Zero subprocesses) |
| Secret Leakage Audit | Automated audit for plaintext credentials | PASS (Zero secrets leaked) |
| Standalone Package Verification | Fresh directory extraction & independent run | PASS (Standalone execution) |
| Git Diff Whitespace Audit | git diff --check |
PASS (Zero whitespace issues) |
15. Ecosystem & License Summary
nx9-wg is part of the NX9 Ecosystem (https://nx9.in) created by Sunil Thakare.
Dual-licensed under either:
- MIT License (
LICENSE-MIT) - Apache License, Version 2.0 (
LICENSE-APACHE)
at your option.
NX9 WireGuard — Sovereign, Self-Hosted, Linux-Native Network Infrastructure.