Files
nx9-wg/docs/linux_requirements.md
T

2.5 KiB

Linux Platform and Kernel Requirements

nx9-wg is designed for native Linux execution and interacts directly with Linux kernel subsystems via Netlink sockets and direct /proc filesystem interfaces.


1. Kernel Requirements

  • Linux Kernel Version: 5.6 or newer (in-tree WireGuard module support).
  • WireGuard Subsystem: wireguard.ko in-tree module (modprobe wireguard).
  • Generic Netlink (Genl): Family wireguard for cryptographic interface and peer configuration.
  • RTNETLINK: For network interface lifecycle (RTM_NEWLINK/DELLINK), address assignments (RTM_NEWADDR), and routing table management (RTM_NEWROUTE/DELROUTE).
  • Sysctl IP Forwarding: Direct procfs mutation:
    • /proc/sys/net/ipv4/ip_forward (enabled for IPv4 packet routing)
    • /proc/sys/net/ipv6/conf/all/forwarding (enabled for IPv6 dual-stack routing)

2. Dynamic Library & Runtime Dependencies

When compiled for Linux, nx9-wg links dynamically against standard system libraries:

Library Runtime Function Installation Package (Debian/Ubuntu) Installation Package (RHEL/Fedora/Arch)
libnftables.so.1 Native nftables ruleset execution libnftables1 / nftables libnftables / nftables
libmnl.so.0 Minimal Netlink library libmnl0 libmnl
libnftnl.so.11 Netfilter Netlink object library libnftnl11 libnftnl
libc.so.6 Standard C library (glibc / musl) Base system Base system

Note

SQLite is statically embedded into the nx9-wg binary via libsqlite3-sys. No external SQLite installation or database daemon is required.


3. Security Capabilities & Privilege Boundaries

When executed under systemd or non-root service accounts:

  • CAP_NET_ADMIN: Strictly required for RTNETLINK interface lifecycle, IP route mutations, WireGuard Genl socket communication, and nftables Netfilter execution.
  • CAP_NET_BIND_SERVICE: Required if binding the REST API or WireGuard UDP socket to privileged ports (< 1024).

4. Execution Mode Classification

  • Linux Native Mode: Automatically engaged on Linux systems with CAP_NET_ADMIN and kernel WireGuard/Netfilter modules.
  • Non-Linux / Simulated Mode: Automatically engaged on macOS and Windows hosts for development and UI preview.
  • Restricted Mode: Engaged when running on Linux without CAP_NET_ADMIN; control-plane REST API, SQLite queries, and diagnostics operate normally, while kernel mutation calls return descriptive permission errors without crashing.