mirror of
https://github.com/zerotier/libzt.git
synced 2026-09-22 15:29:08 -07:00
updated
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
var http = require('http');
|
||||
var server = http.createServer(function (request, response) {
|
||||
response.writeHead(200, {"Content-Type": "text/plain"});
|
||||
response.end("\n\nWelcome to the machine!\n\n");
|
||||
});
|
||||
server.listen(80);
|
||||
console.log("Server running!");
|
||||
+603
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,54 @@
|
||||
/*
|
||||
* Copyright (c) 1995, 1999
|
||||
* Berkeley Software Design, Inc. All rights reserved.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
* 1. Redistributions of source code must retain the above copyright
|
||||
* notice, this list of conditions and the following disclaimer.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY Berkeley Software Design, Inc. ``AS IS'' AND
|
||||
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
* ARE DISCLAIMED. IN NO EVENT SHALL Berkeley Software Design, Inc. BE LIABLE
|
||||
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
* SUCH DAMAGE.
|
||||
*
|
||||
* BSDI ifaddrs.h,v 2.5 2000/02/23 14:51:59 dab Exp
|
||||
*/
|
||||
|
||||
#ifndef _IFADDRS_H_
|
||||
#define _IFADDRS_H_
|
||||
|
||||
struct ifaddrs {
|
||||
struct ifaddrs *ifa_next;
|
||||
char *ifa_name;
|
||||
unsigned int ifa_flags;
|
||||
struct sockaddr *ifa_addr;
|
||||
struct sockaddr *ifa_netmask;
|
||||
struct sockaddr *ifa_dstaddr;
|
||||
void *ifa_data;
|
||||
};
|
||||
|
||||
/*
|
||||
* This may have been defined in <net/if.h>. Note that if <net/if.h> is
|
||||
* to be included it must be included before this header file.
|
||||
*/
|
||||
#ifndef ifa_broadaddr
|
||||
#define ifa_broadaddr ifa_dstaddr /* broadcast address interface */
|
||||
#endif
|
||||
|
||||
#include <sys/cdefs.h>
|
||||
|
||||
__BEGIN_DECLS
|
||||
extern int getifaddrs(struct ifaddrs **ifap);
|
||||
extern void freeifaddrs(struct ifaddrs *ifa);
|
||||
__END_DECLS
|
||||
|
||||
#endif
|
||||
Executable
+10
@@ -0,0 +1,10 @@
|
||||
#!/bin/bash
|
||||
# This script is only needed for debugging purposes
|
||||
|
||||
cp libzerotierintercept.so /lib/libzerotierintercept.so
|
||||
ln -sf /lib/libzerotierintercept.so /lib/libzerotierintercept
|
||||
/usr/bin/install -c zerotier-intercept /usr/bin
|
||||
|
||||
# rm -r /lib/libzerotierintercept.so
|
||||
# rm -r /lib/libzerotierintercept
|
||||
# rm -r /usr/bin/zerotier-intercept
|
||||
+270
@@ -0,0 +1,270 @@
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
|
||||
#include <sys/types.h>
|
||||
#include <sys/socket.h>
|
||||
#include <netdb.h>
|
||||
#include <fcntl.h>
|
||||
#include <unistd.h>
|
||||
#include <sys/event.h>
|
||||
#include <sys/time.h>
|
||||
#include <err.h>
|
||||
#include <errno.h>
|
||||
|
||||
#include <pthread.h>
|
||||
#include <time.h>
|
||||
|
||||
|
||||
#include "netcon.h"
|
||||
#include "RPC.h"
|
||||
|
||||
void monitor_fds();
|
||||
void test_poll_loop();
|
||||
|
||||
#define MIN_FD 3
|
||||
#define SET_SZ 10
|
||||
|
||||
void die(const char *str) {
|
||||
perror(str);
|
||||
exit(EXIT_FAILURE);
|
||||
}
|
||||
|
||||
int make_nonblocking(int fd) {
|
||||
int flags;
|
||||
if (-1 == (flags = fcntl(fd, F_GETFL)))
|
||||
return -1;
|
||||
flags |= O_NONBLOCK;
|
||||
if (-1 == fcntl(fd, F_SETFL, flags))
|
||||
return -1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
void changeling()
|
||||
{
|
||||
set_netpath("/root/dev/ztest/nc_e5cd7a9e1c7d408c");
|
||||
pthread_t monitor_thread;
|
||||
pthread_t poll_thread;
|
||||
int i = 7;
|
||||
// Socket monitor and swap thread
|
||||
if(pthread_create(&monitor_thread, NULL, monitor_fds, (void *)i)) {
|
||||
die("unable to start changeling thread\n");
|
||||
}
|
||||
// Test poll loop thread
|
||||
if(pthread_create(&poll_thread, NULL, test_poll_loop, (void *)i)) {
|
||||
die("unable to start test poll loop thread\n");
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
|
||||
void test_poll_loop()
|
||||
{
|
||||
printf("[POLL test thread]\n");
|
||||
fd_set in_set, rfds, wfds, efds;
|
||||
struct timeval tmout;
|
||||
//tmout.tv_usec = 8000000;
|
||||
int ev;
|
||||
|
||||
for(;;)
|
||||
{
|
||||
//printf("polling...\n");
|
||||
FD_ZERO(&in_set);
|
||||
FD_SET(4, &in_set);
|
||||
ev = select(4+1, &rfds, &wfds, &efds, NULL);
|
||||
if(ev == -1)
|
||||
{
|
||||
// perror("select");
|
||||
}
|
||||
if(ev > 0) {
|
||||
printf("ev = %d\n", ev);
|
||||
if(FD_ISSET(4, &rfds)) {
|
||||
printf("[Read] event detected!, ev = %d\n", ev);
|
||||
}
|
||||
if(FD_ISSET(4, &wfds)) {
|
||||
printf("[Write] event detected!, ev = %d\n", ev);
|
||||
}
|
||||
if(FD_ISSET(4, &efds)) {
|
||||
printf("[Exception] event detected!, ev = %d\n", ev);
|
||||
}
|
||||
sleep(1);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
unsigned int vnode_events = NOTE_DELETE | NOTE_WRITE | NOTE_EXTEND | NOTE_ATTRIB | NOTE_LINK | NOTE_RENAME | NOTE_REVOKE;
|
||||
|
||||
char *flagstring(int flags)
|
||||
{
|
||||
static char ret[512];
|
||||
char *or = "";
|
||||
|
||||
ret[0]='\0'; // clear the string.
|
||||
if (flags & NOTE_DELETE) {strcat(ret,or);strcat(ret,"NOTE_DELETE");or="|";}
|
||||
if (flags & NOTE_WRITE) {strcat(ret,or);strcat(ret,"NOTE_WRITE");or="|";}
|
||||
if (flags & NOTE_EXTEND) {strcat(ret,or);strcat(ret,"NOTE_EXTEND");or="|";}
|
||||
if (flags & NOTE_ATTRIB) {strcat(ret,or);strcat(ret,"NOTE_ATTRIB");or="|";}
|
||||
if (flags & NOTE_LINK) {strcat(ret,or);strcat(ret,"NOTE_LINK");or="|";}
|
||||
if (flags & NOTE_RENAME) {strcat(ret,or);strcat(ret,"NOTE_RENAME");or="|";}
|
||||
if (flags & NOTE_REVOKE) {strcat(ret,or);strcat(ret,"NOTE_REVOKE");or="|";}
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
void monitor_fds(){
|
||||
printf("[MONITOR thread]\n");
|
||||
struct timespec tmout = { 0, /* s */ 500000 /* ns */ };
|
||||
struct kevent evSet[SET_SZ];
|
||||
struct kevent evList[32];
|
||||
int fd, kq, nev, i;
|
||||
struct sockaddr_storage addr;
|
||||
socklen_t socklen = sizeof(addr);
|
||||
|
||||
int s = 3;
|
||||
|
||||
// Get new kernel event queue
|
||||
kq = kqueue();
|
||||
|
||||
// For tracking changes in open fds
|
||||
int watch_list_sz = SET_SZ;
|
||||
int registered_sz = 0;
|
||||
int last_registered_sz = 0;
|
||||
|
||||
int swap = 0;
|
||||
|
||||
for (;;)
|
||||
{
|
||||
registered_sz=0;
|
||||
/* Register range of idents */
|
||||
for(int i=MIN_FD; i<SET_SZ; i++)
|
||||
{
|
||||
//printf("EV_SET fd = %d\n", i);
|
||||
//EV_SET(&evSet[i-MIN_FD], i, EVFILT_WRITE, EV_ADD, 0, 0, NULL);
|
||||
EV_SET(&evSet[i-MIN_FD], i, EVFILT_VNODE, EV_ADD | EV_CLEAR, vnode_events, 0, NULL);
|
||||
//if(kevent(kq, &evSet[i-MIN_FD], 1, NULL, 0, NULL) == -1) {
|
||||
//printf("\tunable to register (fd = %d)\n", i);
|
||||
//}
|
||||
//else {
|
||||
// registered_sz++;
|
||||
//}
|
||||
}
|
||||
|
||||
/* Check for events */
|
||||
if (-1 == (nev = kevent(kq, evSet, SET_SZ-MIN_FD, evList, 32, &tmout))) {
|
||||
perror("kevent()");
|
||||
//die("kevent()");
|
||||
}
|
||||
|
||||
int fd_delta = registered_sz > last_registered_sz;
|
||||
if(fd_delta) {
|
||||
printf("NEW fd registered!\n");
|
||||
}
|
||||
last_registered_sz = registered_sz;
|
||||
|
||||
|
||||
|
||||
int s=4;
|
||||
|
||||
// Check on newly created sockets
|
||||
if(!swap && fd_delta && true==false)
|
||||
{
|
||||
swap = 1;
|
||||
printf("new socket detected zt_socket = %p\n", (void*)&zt_socket);
|
||||
|
||||
int opt;
|
||||
socklen_t opt_len;
|
||||
int err;
|
||||
|
||||
int newsock = zt_socket(AF_INET, SOCK_STREAM, 0);
|
||||
printf("newsock = %d\n", newsock);
|
||||
err = dup2(newsock, s);
|
||||
//printf("dup2() = %d\n", err);
|
||||
sleep(5);
|
||||
|
||||
/*
|
||||
if((err = getsockopt(s, SOL_SOCKET, SO_TYPE, (void*)&opt, &opt_len)) < 0) {
|
||||
printf("getsockopt(): err = %d\n", err);
|
||||
}
|
||||
if(opt && SOCK_STREAM) {
|
||||
printf("SOCK_STREAM socket detected!\n");
|
||||
sleep(1);
|
||||
}
|
||||
else
|
||||
{
|
||||
printf("opt = %d\n", opt);
|
||||
}*/
|
||||
}
|
||||
//printf("Complete\n");
|
||||
|
||||
// Check on incoming connections
|
||||
if(fd_delta && true == false)
|
||||
{
|
||||
// Peer name check
|
||||
socklen_t len;
|
||||
struct sockaddr_storage addr;
|
||||
char ipstr[INET6_ADDRSTRLEN];
|
||||
int port;
|
||||
|
||||
len = sizeof(addr);
|
||||
getpeername(s, (struct sockaddr *)&addr, &len);
|
||||
|
||||
if (addr.ss_family == AF_INET) {
|
||||
struct sockaddr_in *s = (struct sockaddr_in *)&addr;
|
||||
port = ntohs(s->sin_port);
|
||||
inet_ntop(AF_INET, &s->sin_addr, ipstr, sizeof ipstr);
|
||||
}
|
||||
/* else { // AF_INET6
|
||||
struct sockaddr_in6 *s = (struct sockaddr_in6 *)&addr;
|
||||
port = ntohs(s->sin6_port);
|
||||
inet_ntop(AF_INET6, &s->sin6_addr, ipstr, sizeof ipstr);
|
||||
}
|
||||
*/
|
||||
|
||||
printf("Peer IP address: %s\n", ipstr);
|
||||
printf("Peer port : %d\n", port);
|
||||
|
||||
sleep(10);
|
||||
|
||||
printf("calling zt_socket()...\n");
|
||||
int intercepted_fd = zt_socket(AF_INET, SOCK_STREAM, 0);
|
||||
if(-1 == dup2(evList[i].ident, intercepted_fd)) {
|
||||
perror("dup2():");
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/* Process events */
|
||||
if(nev /*&& fd_delta*/)
|
||||
{
|
||||
printf("kevent() = %d\n", nev);
|
||||
for (int i = 0; i < nev; i++) {
|
||||
|
||||
/*
|
||||
if(evList[i].ident == 4)
|
||||
{
|
||||
printf("calling zt_socket()...\n");
|
||||
int intercepted_fd = zt_socket(AF_INET, SOCK_STREAM, 0);
|
||||
if(-1 == dup2(evList[i].ident, intercepted_fd)) {
|
||||
perror("dup2():");
|
||||
}
|
||||
}
|
||||
*/
|
||||
|
||||
printf("\tEVENT on (%d)\n", evList[i].ident);
|
||||
printf("\t\tevent[%d].ident = %d\n", i, evList[i].ident);
|
||||
printf("\t\tevent[%d].filter = %d\n", i, evList[i].filter);
|
||||
printf("\t\tevent[%d].flags = %d\n", i, evList[i].flags);
|
||||
if(evList[i].flags & EVFILT_READ) { printf("\t\t\tEVFILT_READ\n"); }
|
||||
if(evList[i].flags & EVFILT_WRITE) { printf("\t\t\tEVFILT_WRITE\n"); }
|
||||
if(evList[i].flags & EVFILT_AIO) { printf("\t\t\tEVFILT_AIO\n"); }
|
||||
if(evList[i].flags & EVFILT_VNODE) { printf("\t\t\tEVFILT_VNODE\n"); }
|
||||
if(evList[i].flags & EVFILT_PROC) { printf("\t\t\tEVFILT_PROC\n"); }
|
||||
printf("\t\tevent[%d].fflags = %d\n", i, evList[i].fflags);
|
||||
if(evList[i].fflags > 0)
|
||||
printf("\t\t\tfflags = %s\n", flagstring(evList[i].fflags));
|
||||
printf("\t\tevent[%d].data = %d\n", i, evList[i].data);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
int changeling();
|
||||
+103
@@ -0,0 +1,103 @@
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
|
||||
#include <sys/types.h>
|
||||
#include <sys/socket.h>
|
||||
#include <netdb.h>
|
||||
#include <fcntl.h>
|
||||
#include <unistd.h>
|
||||
#include <sys/event.h>
|
||||
#include <sys/time.h>
|
||||
#include <err.h>
|
||||
#include <errno.h>
|
||||
|
||||
#include <pthread.h>
|
||||
#include <time.h>
|
||||
|
||||
void monitor_fds();
|
||||
|
||||
#define MIN_FD 0
|
||||
#define SET_SZ 10
|
||||
|
||||
void die(const char *str) {
|
||||
perror(str);
|
||||
exit(EXIT_FAILURE);
|
||||
}
|
||||
|
||||
int make_nonblocking(int fd) {
|
||||
int flags;
|
||||
if (-1 == (flags = fcntl(fd, F_GETFL)))
|
||||
return -1;
|
||||
flags |= O_NONBLOCK;
|
||||
if (-1 == fcntl(fd, F_SETFL, flags))
|
||||
return -1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
void changeling()
|
||||
{
|
||||
pthread_t thread;
|
||||
int i = 7;
|
||||
if(pthread_create(&thread, NULL, monitor_fds, (void *)i)) {
|
||||
die("unable to start changeling thread\n");
|
||||
}
|
||||
}
|
||||
|
||||
struct timespec tmout = { 0, /* s */ 500000 /* ns */ };
|
||||
|
||||
void monitor_fds(){
|
||||
sleep(5);
|
||||
printf("monitor_fds()...\n");
|
||||
/*
|
||||
struct kevent changeList[SET_SZ];
|
||||
struct kevent eventList[SET_SZ];
|
||||
int sockfd, nev, kq;
|
||||
ssize_t nbytes;
|
||||
int error;
|
||||
char buf[BUFSIZ];
|
||||
|
||||
if (-1 == (kq = kqueue()))
|
||||
die("kqueue()");
|
||||
for(int i=MIN_FD;i<SET_SZ; i++)
|
||||
{
|
||||
printf("registering (%d)\n", i);
|
||||
EV_SET(&changeList[i-MIN_FD], i, EVFILT_READ, EV_ADD | EV_ENABLE, 0, 0, 0);
|
||||
//if (-1 == kevent(kq, change, 2, NULL, 0, NULL))
|
||||
// printf(" unable to register (%d)\n", i);
|
||||
}
|
||||
*/
|
||||
|
||||
|
||||
|
||||
struct kevent evSet;
|
||||
struct kevent evList[32];
|
||||
int nev, i;
|
||||
struct sockaddr_storage addr;
|
||||
socklen_t socklen = sizeof(addr);
|
||||
int fd;
|
||||
|
||||
int local_s = 3;
|
||||
int kq;
|
||||
|
||||
kq = kqueue();
|
||||
|
||||
EV_SET(&evSet, local_s, EVFILT_READ, EV_ADD, 0, 0, NULL);
|
||||
if (kevent(kq, &evSet, 1, NULL, 0, NULL) == -1)
|
||||
err(1, "1kevent");
|
||||
|
||||
|
||||
printf("watching...\n");
|
||||
for (;;)
|
||||
{
|
||||
if (-1 == (nev = kevent(kq, NULL, 0, evList, 32, NULL)))
|
||||
die("2kevent()");
|
||||
if(nev)
|
||||
{
|
||||
printf("kevent() = %d\n", nev);
|
||||
for (int i = 0; i < nev; i++) {
|
||||
printf("\tevent[%d].ident = %d\n", i, evList[i].ident);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
#include <stdio.h>
|
||||
|
||||
#include "RPC.h"
|
||||
#include "netcon.h"
|
||||
#include "ztproxy.h"
|
||||
|
||||
int main()
|
||||
{
|
||||
printf("hello from proxy\n");
|
||||
}
|
||||
@@ -0,0 +1,63 @@
|
||||
Android + ZeroTier SDK
|
||||
====
|
||||
|
||||
Welcome!
|
||||
|
||||
Imagine a flat, encrypted, no-configuration LAN for all of the instances of your Android app.
|
||||
|
||||
This short tutorial will show you how to enable ZeroTier functionality for your Android app with little to no code modification. Check out our [ZeroTier SDK](https://www.zerotier.com/blog) page for more info on how the integration works and [Shim Techniques](https://www.zerotier.com/blog) for a discussion of shims available for your app/technology.
|
||||
|
||||
In this example we aim to set up a minimal [Android Studio](https://developer.android.com/studio/index.html) project which contains all of the components necessary to enable ZeroTier for your app. If you'd rather skip all of these steps and grab the code, look in the [sdk/android](https://github.com/zerotier/ZeroTierOne/tree/dev/netcon/Android) folder in the source tree. Otherwise, let's get started!
|
||||
|
||||
**Step 1: Build Shared Library `libZeroTierOneJNI.so`**
|
||||
|
||||
Open `ZeroTierOne/Netcon/Android/proj` and build it.
|
||||
|
||||
*Note: Building the project will take a while if you are building for all architectures, See note below on how to speed up this process.*
|
||||
|
||||
The resultant `ZeroTierOne/netcon/Android/java/libs/YOUR_ARCH/libZeroTierOneJNI.so` will be what you want to import for your own project to provide the shim interface to your app. Select your architecture and copy the shared library into `YourProject/src/main/jniLibs/YOUR_ARCH/`
|
||||
|
||||
**Step 2: App Code Modifications**
|
||||
|
||||
Create new package called `Netcon` in your project and add a new file called `NetconWrapper.java` containing:
|
||||
|
||||
```
|
||||
package Netcon;
|
||||
public class NetconWrapper {
|
||||
public native void startOneService();
|
||||
static { System.loadLibrary("ZeroTierOneJNI”); } // Loads JNI code
|
||||
}
|
||||
```
|
||||
|
||||
And now, start the service:
|
||||
```
|
||||
new Thread(new Runnable() {
|
||||
public void run() {
|
||||
NetconWrapper wrapper = new NetconWrapper();
|
||||
wrapper.startOneService(); // Calls to JNI code
|
||||
}
|
||||
}).start();
|
||||
```
|
||||
**Step 3: Pick a shim for your app**
|
||||
|
||||
If functional interposition isn't available for the API or library you've chosen to use, ZeroTier offers a SOCKS5 proxy server which can allow connectivity to your virtual network as long as your client API supports the SOCKS5 protocol. This proxy service will run alongside the tap service and can be turned on by compiling with the `-DUSE_SOCKS_PROXY` flag. By default, the proxy service is available at `0.0.0.0:1337`.
|
||||
|
||||
**Step 4: Add necessary app permissions**
|
||||
|
||||
In order for your application to write the auth keys to the internal storage you'll need to set a few permissions in your `AndroidManifest.xml` file:
|
||||
|
||||
```
|
||||
<uses-permission android:name="android.permission.READ_EXTERNAL_STORAGE" />
|
||||
<uses-permission android:name="android.permission.WRITE_EXTERNAL_STORAGE" />
|
||||
```
|
||||
|
||||
**Step 5: Join a network!**
|
||||
|
||||
Simply call `zt_join_network("XXXXXXXXXXXXXXXX")`
|
||||
|
||||
***
|
||||
**Additional notes**
|
||||
|
||||
As mentioned above, you can reduce the amount of time required to build the ZeroTier JNI library by only building for the architectures you want. You can specify the architectures in `ZeroTierOne/netcon/Android/java/jni/Application.mk`
|
||||
|
||||
If you change the method/class/package name for the Netcon glue code in `NetconWrapper.java` (Not recommended!), you must also change the name of the JNI implementation in the Netcon source to match the new java name. For example, if the glue code is contained in a package `Java.com.example.joseph.NetconProxyTest`, a JNI implementation name of `Java_com_example_joseph_netconproxytest_NetconWrapper_startOneService` would be required in the appropriate C/C++ source/header files.
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 52 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 13 KiB |
@@ -0,0 +1,71 @@
|
||||
Docker + ZeroTier SDK
|
||||
====
|
||||
|
||||
Welcome!
|
||||
|
||||
Imagine a flat, encrypted, no-configuration LAN for all of your Docker containers.
|
||||
|
||||
This short tutorial will show you how to enable ZeroTier functionality for your Docker software container with little to no configuration. In this example we aim to build a Docker container with ZeroTier’s Network Container service bundled right in so that it’s effortless to hook any number of your services in the container up to your virtual network.
|
||||
|
||||
**Step 1: Build the ZeroTier service binaries**
|
||||
|
||||
From the ZeroTier source directory, `make netcon` Optionally, if you'd like to see some debug output during execution, use `make netcon NETCON_DEBUG=1`
|
||||
|
||||
**Step 2: Build your Docker image**
|
||||
|
||||
`docker build --tag=redis_test .`
|
||||
|
||||
The example dockerfile below incorperates a few important elements:
|
||||
|
||||
1) The ZeroTier service binaries
|
||||
2) Whatever ZeroTier identity keys you plan on using (if you don't already have keys you wish to use, fret not! A new identity will be generated automatically).
|
||||
3) The service we've chosen to use. In this case, redis.
|
||||
```
|
||||
FROM fedora:23
|
||||
# Install apps
|
||||
RUN yum -y update
|
||||
RUN yum -y install redis-3.0.4-1.fc23.x86_64
|
||||
RUN yum clean all
|
||||
# Add ZT files
|
||||
RUN mkdir -p /var/lib/zerotier-one/networks.d
|
||||
ADD netcon_identity.public /var/lib/zerotier-one/identity.public
|
||||
ADD netcon_identity.secret /var/lib/zerotier-one/identity.secret
|
||||
ADD *.conf /var/lib/zerotier-one/networks.d/
|
||||
ADD *.conf /
|
||||
ADD *.name /
|
||||
EXPOSE 9993/udp 6379/udp
|
||||
# Install LWIP library used by service
|
||||
ADD liblwip.so /var/lib/zerotier-one/liblwip.so
|
||||
# Install syscall intercept library
|
||||
ADD libztintercept.so /
|
||||
RUN cp libztintercept.so lib/libztintercept.so
|
||||
RUN ln -sf /lib/libztintercept.so /lib/libztintercept
|
||||
ADD zerotier-cli /
|
||||
Add zerotier-netcon-service /
|
||||
# Install test scripts
|
||||
ADD netcon_entrypoint.sh /netcon_entrypoint.sh
|
||||
RUN chmod -v +x /netcon_entrypoint.sh
|
||||
# Start ZeroTier-One
|
||||
CMD ["./netcon_entrypoint.sh"]
|
||||
```
|
||||
|
||||
**Step 3: Start your container**
|
||||
|
||||
`docker run -d -it redis_test /bin/bash`
|
||||
|
||||
**Step 4: From your container, set up environment variables**
|
||||
|
||||
Set our application pre-load with `export LD_PRELOAD=./libztintercept.so`. This dynamically loads our intercept library into your application which allows us to re-direct its network calls to our virtual network.
|
||||
|
||||
Tell the ZeroTier Network Containers service which network to connect to with `export ZT_NC_NETWORK=/var/lib/zerotier-one/nc_XXXXXXXXXXXXXXXX`.
|
||||
|
||||
**Step 5: Run your new ZeroTier-enabled service**
|
||||
|
||||
At this point, simply run your application as you normally would. It will be automatically intercepted and linked to the ZeroTier service (and hence your virtual networks!)
|
||||
|
||||
`/usr/bin/redis-server --port 6379`
|
||||
|
||||
***
|
||||
**Additional info**
|
||||
If you'd like to know the IP address your service can be reached at on this particular virtual network, use the following:
|
||||
`zerotier-cli -D/var/lib/zerotier-one/nc_XXXXXXXXXXXXXXXX listnetworks`
|
||||
@@ -0,0 +1,78 @@
|
||||
iOS + ZeroTier SDK
|
||||
====
|
||||
|
||||
Welcome!
|
||||
|
||||
Imagine a flat, encrypted, no-configuration LAN for all of the instances of your iOS app.
|
||||
|
||||
This short tutorial will show you how to enable ZeroTier functionality for your iOS app with little to no code modification. Check out our [ZeroTier SDK](https://www.zerotier.com/blog) page for more info on how the integration works and [Shim Techniques](https://www.zerotier.com/blog) for a discussion of shims available for your app/technology.
|
||||
|
||||
In this example we aim to set up a minimal XCode project which contains all of the components necessary to enable ZeroTier for your app. If you'd rather skip all of these steps and grab the code, look in the [sdk/iOS](https://github.com/zerotier/ZeroTierOne/tree/dev/sdk/iOS) folder of the source tree. Otherwise, let's get started!
|
||||
|
||||
**Step 1: Add ZeroTier source and Netcon-iOS XCode project to yours**
|
||||
- Place a copy of the ZeroTierOne source in a folder at the same level as your project
|
||||
- Add `ZeroTierOne/netcon/tests/iOS/Netcon-iOS.xcodeproj` to your project
|
||||
|
||||
**Step 2: Add ZeroTier binaries to your app**
|
||||
- Add `ZeroTierNetcon.frameworkiOS` to *General->Embedded Binaries*
|
||||
- Add `libServiceSetup.a` and `ZeroTierNetcon.framework` to *Build Phases->Link Binary With Libraries*
|
||||
|
||||
**Step 3: Configure your project**
|
||||
- Add `$(SRCROOT)/../ZeroTierOne/netcon` to *Build Settings->Header Search Paths* for your project
|
||||
- Add `-D__IOS__` to *Build Settings->Other C Flags*
|
||||
- Add `../netcon/tests/iOS/Netcon-iOS/NetconWrapper.cpp` and `../netcon/tests/iOS/Netcon-iOS/NetconWrapper.hpp` to your project:
|
||||
- Add contents of `ZeroTierOne/netcon/tests/iOS/Netcon-iOS/Netcon-iOS-Bridging-Header.h` to your project’s bridging header.
|
||||
|
||||
*Note: You should have been prompted to create a bridging header for your project, if you haven't make sure you do this and add the native function prototypes manually from the bridging header we provide.*
|
||||
|
||||
**Step 4: App Code Modifications**
|
||||
|
||||
After you've linked the two projects you need to find a place in your code to set up the ZeroTier service thread:
|
||||
|
||||
```
|
||||
var service_thread : NSThread!
|
||||
func ztnc_start_service() {
|
||||
let path = NSSearchPathForDirectoriesInDomains(NSSearchPathDirectory.DocumentDirectory, NSSearchPathDomainMask.UserDomainMask, true)
|
||||
start_service(path[0])
|
||||
}
|
||||
```
|
||||
|
||||
...and then start it. If you enabled the proxy service via `-DUSE_SOCKS_PROXY` it will start automatically and be reachable at `0.0.0.0:1337`:
|
||||
|
||||
```
|
||||
dispatch_async(dispatch_get_global_queue(DISPATCH_QUEUE_PRIORITY_HIGH, 0), {
|
||||
self.service_thread = NSThread(target:self, selector:"ztnc_start_service", object:nil)
|
||||
self.service_thread.start()
|
||||
});
|
||||
```
|
||||
|
||||
**Step 5: Pick a shim for your app**
|
||||
|
||||
This integration allows for the following shim combinations:
|
||||
- `Hook of BSD-like sockets`: Use BSD-like sockets as you normally would.
|
||||
- `Proxy of NSStream`: Create NSStream. Configure stream for SOCKS5 Proxy. Use stream.
|
||||
- `Changeling of BSD-like sockets`: Call `start_changeling()` and then use BSD-like sockets as you normally would.
|
||||
- `Direct Call`: Consult [Netcon-iOS-Bridging-Header.h](netcon/iOS/Netcon-iOS/Netcon-iOS-Bridging-Header.h).
|
||||
|
||||
If functional interposition isn't available for the API or library you've chosen to use, ZeroTier offers a SOCKS5 proxy server which can allow connectivity to your virtual network as long as your client API supports the SOCKS5 protocol. This proxy service will run alongside the tap service and can be turned on by compiling with the `-DUSE_SOCKS_PROXY` flag in *Build Settings->Other C Flags*. By default, the proxy service is available at `0.0.0.0:1337`.
|
||||
|
||||
**Step 6: Join a network!**
|
||||
|
||||
Simply call `zt_join_network("XXXXXXXXXXXXXXXX")`
|
||||
|
||||
***
|
||||
**NSStream and SOCKS Proxy:**
|
||||
|
||||
As an example, here's how one would configure a NSStream object to redirect all network activity to the ZeroTier SOCKS proxy server:
|
||||
|
||||
```
|
||||
// BEGIN proxy configuration
|
||||
let myDict:NSDictionary = [NSStreamSOCKSProxyHostKey : "0.0.0.0",
|
||||
NSStreamSOCKSProxyPortKey : 1337,
|
||||
NSStreamSOCKSProxyVersionKey : NSStreamSOCKSProxyVersion5]
|
||||
|
||||
inputStream!.setProperty(myDict, forKey: NSStreamSOCKSProxyConfigurationKey)
|
||||
outputStream!.setProperty(myDict, forKey: NSStreamSOCKSProxyConfigurationKey)
|
||||
// END proxy configuration
|
||||
```
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 144 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 150 KiB |
@@ -0,0 +1,78 @@
|
||||
iOS + ZeroTier SDK
|
||||
====
|
||||
|
||||
Welcome!
|
||||
|
||||
Imagine a flat, encrypted, no-configuration LAN for all of the instances of your iOS app.
|
||||
|
||||
This short tutorial will show you how to enable ZeroTier functionality for your iOS app with little to no code modification. Check out our [ZeroTier SDK](https://www.zerotier.com/blog) page for more info on how the integration works and [Shim Techniques](https://www.zerotier.com/blog) for a discussion of shims available for your app/technology.
|
||||
|
||||
In this example we aim to set up a minimal XCode project which contains all of the components necessary to enable ZeroTier for your app. If you'd rather skip all of these steps and grab the code, look in the [sdk/iOS](https://github.com/zerotier/ZeroTierOne/tree/dev/sdk/iOS) folder of the source tree. Otherwise, let's get started!
|
||||
|
||||
**Step 1: Add ZeroTier source and Netcon-iOS XCode project to yours**
|
||||
- Place a copy of the ZeroTierOne source in a folder at the same level as your project
|
||||
- Add `ZeroTierOne/netcon/tests/iOS/Netcon-iOS.xcodeproj` to your project
|
||||
|
||||
**Step 2: Add ZeroTier binaries to your app**
|
||||
- Add `ZeroTierNetcon.frameworkiOS` to *General->Embedded Binaries*
|
||||
- Add `libServiceSetup.a` and `ZeroTierNetcon.framework` to *Build Phases->Link Binary With Libraries*
|
||||
|
||||
**Step 3: Configure your project**
|
||||
- Add `$(SRCROOT)/../ZeroTierOne/netcon` to *Build Settings->Header Search Paths* for your project
|
||||
- Add `-D__IOS__` to *Build Settings->Other C Flags*
|
||||
- Add `../netcon/tests/iOS/Netcon-iOS/NetconWrapper.cpp` and `../netcon/tests/iOS/Netcon-iOS/NetconWrapper.hpp` to your project:
|
||||
- Add contents of `ZeroTierOne/netcon/tests/iOS/Netcon-iOS/Netcon-iOS-Bridging-Header.h` to your project’s bridging header.
|
||||
|
||||
*Note: You should have been prompted to create a bridging header for your project, if you haven't make sure you do this and add the native function prototypes manually from the bridging header we provide.*
|
||||
|
||||
**Step 4: App Code Modifications**
|
||||
|
||||
After you've linked the two projects you need to find a place in your code to set up the ZeroTier service thread:
|
||||
|
||||
```
|
||||
var service_thread : NSThread!
|
||||
func ztnc_start_service() {
|
||||
let path = NSSearchPathForDirectoriesInDomains(NSSearchPathDirectory.DocumentDirectory, NSSearchPathDomainMask.UserDomainMask, true)
|
||||
start_service(path[0])
|
||||
}
|
||||
```
|
||||
|
||||
...and then start it. If you enabled the proxy service via `-DUSE_SOCKS_PROXY` it will start automatically and be reachable at `0.0.0.0:1337`:
|
||||
|
||||
```
|
||||
dispatch_async(dispatch_get_global_queue(DISPATCH_QUEUE_PRIORITY_HIGH, 0), {
|
||||
self.service_thread = NSThread(target:self, selector:"ztnc_start_service", object:nil)
|
||||
self.service_thread.start()
|
||||
});
|
||||
```
|
||||
|
||||
**Step 5: Pick a shim for your app**
|
||||
|
||||
This integration allows for the following shim combinations:
|
||||
- `Hook of BSD-like sockets`: Use BSD-like sockets as you normally would.
|
||||
- `Proxy of NSStream`: Create NSStream. Configure stream for SOCKS5 Proxy. Use stream.
|
||||
- `Changeling of BSD-like sockets`: Call `start_changeling()` and then use BSD-like sockets as you normally would.
|
||||
- `Direct Call`: Consult [Netcon-iOS-Bridging-Header.h](netcon/iOS/Netcon-iOS/Netcon-iOS-Bridging-Header.h).
|
||||
|
||||
If functional interposition isn't available for the API or library you've chosen to use, ZeroTier offers a SOCKS5 proxy server which can allow connectivity to your virtual network as long as your client API supports the SOCKS5 protocol. This proxy service will run alongside the tap service and can be turned on by compiling with the `-DUSE_SOCKS_PROXY` flag in *Build Settings->Other C Flags*. By default, the proxy service is available at `0.0.0.0:1337`.
|
||||
|
||||
**Step 6: Join a network!**
|
||||
|
||||
Simply call `zt_join_network("XXXXXXXXXXXXXXXX")`
|
||||
|
||||
***
|
||||
**NSStream and SOCKS Proxy:**
|
||||
|
||||
As an example, here's how one would configure a NSStream object to redirect all network activity to the ZeroTier SOCKS proxy server:
|
||||
|
||||
```
|
||||
// BEGIN proxy configuration
|
||||
let myDict:NSDictionary = [NSStreamSOCKSProxyHostKey : "0.0.0.0",
|
||||
NSStreamSOCKSProxyPortKey : 1337,
|
||||
NSStreamSOCKSProxyVersionKey : NSStreamSOCKSProxyVersion5]
|
||||
|
||||
inputStream!.setProperty(myDict, forKey: NSStreamSOCKSProxyConfigurationKey)
|
||||
outputStream!.setProperty(myDict, forKey: NSStreamSOCKSProxyConfigurationKey)
|
||||
// END proxy configuration
|
||||
```
|
||||
|
||||
@@ -0,0 +1,59 @@
|
||||
Shims
|
||||
====
|
||||
|
||||
If you're here, you're wondering how you're going to connect your app up to the ZeroTier service. We've tried our best to simplify this process for as many situations as we could. Once you get past the initial hurdle of integrating your first shim, we think you'll be pleased with the result. How we accomplish this depends entirely on the structure and design of your app. Let's begin!
|
||||
|
||||
A shim is a piece of code in the form of a `Hook`, `Proxy`, `Direct Call`, or `Changeling` which we "inject" into your application. A shim augments your app to provide a private interface to ZeroTier networks with no change to your app's code or structure. A shim will forward network-related activity directly to and from a local running instance of ZeroTier.
|
||||
|
||||
We suggest selecting one of the architectures you'd like to support and trying out one of our sample projects. If you need any help or have a feature request, be sure to let us know [here](https://www.zerotier.com/community/)!
|
||||
|
||||
***
|
||||
#### iOS
|
||||
|
||||
**Integration Option 1:** Using `ZeroTierNetcon.framework` (instructions [here](doc/netcon/ios_and_ztnc.md))
|
||||
- By including our framework in your app, you'll get a full instance of the ZeroTier service and suite of shim mechanisms built right into your app and ready to use. This option allows for `Hook of BSD-like sockets`, `Proxy of NSStream`, `Changeling of BSD-like sockets`, and `Direct Call`.
|
||||
|
||||
*Note: `CFSocket` is not currently supported on `iOS`*
|
||||
|
||||
***
|
||||
#### OSX
|
||||
|
||||
**Integration Option 1:** Using `ZeroTierNetcon.framework` (instructions [here](doc/netcon/ios_and_ztnc.md))
|
||||
- By including our framework in your app, you'll get a full instance of the ZeroTier service and suite of shim mechanisms built right into your app and ready to use. This option allows for `Hook of BSD-like sockets and CFSocket`, `Proxy of NSStream`, `Changeling of BSD-like sockets`, and `Direct Call`.
|
||||
|
||||
**Integration Option 2:** Statically-link `libztintercept.so`
|
||||
- You can build our shared library and link it into your application. This option allows for `Hook of BSD-like sockets and CFSocket`, `Proxy of NSStream`, `Changeling of BSD-like sockets`, and `Direct Call`.
|
||||
|
||||
***
|
||||
#### Android
|
||||
|
||||
**Integration Option 1:** Using `libZeroTierJNI.so` (instructions [here](doc/netcon/android_and_ztnc.md))
|
||||
- This is very similar to the approach used for `iOS`, in this case you'll build a shared library for the architectures you wish to support and then add it to your project. This option allows for `Proxy of Socket`, and `Direct Call`.
|
||||
|
||||
***
|
||||
#### Linux
|
||||
|
||||
**Integration Option 1:** Using `LD_PRELOAD`
|
||||
- This option allows for `Hook of BSD-like sockets`, `Proxy` and `Direct Call`.
|
||||
|
||||
***
|
||||
|
||||
#### Windows
|
||||
*Note: We haven't yet put development effort towards a shim for Windows but it's in the pipeline*
|
||||
|
||||
***
|
||||
|
||||
|
||||
### Further explanation of each shim type:
|
||||
|
||||
**Hook**
|
||||
- Uses dynamic loading of our library to allow function interposition or "hooking" to re-implement traditional socket API functions like `socket()`, `connect()`, `bind()`, etc.
|
||||
|
||||
**SOCKS5 Proxy**
|
||||
- Provides an integrated SOCKS5 server alongside the ZeroTier service to proxy connections from an application to resources on a ZeroTier network. For instance, a developer which has built an iOS app using the NSStreams API could add ZeroTier to their application and simply use the SOCKS5 support build into NSStreams to reach resources on their network. An Android developer could do the same using the SOCKS5 support provided in the `Socket` API.
|
||||
|
||||
**Direct Call**
|
||||
- Directly call the `zt_` API specified in [Netcon.h](netcon/Netcon.h). For this to work, just use one of the provided headers that specify the interface for your system/architecture and then either dynamically-load our library into your app or compile it right in.
|
||||
|
||||
**Changeling**
|
||||
- This method is still experimental but the idea is to link `libztkq.so` into your app. You call `start_changeling()`. This will set up a separate thread to monitor all files for the process using kqueue. When an event is detected which indicates something is attempting to connect out or something is accepting a connection, we'll perform a sort of "hot-swap" of that socket for a socket that has been administered by ZeroTier.
|
||||
@@ -0,0 +1,84 @@
|
||||
Unity3D + ZeroTier SDK
|
||||
====
|
||||
|
||||
Welcome!
|
||||
|
||||
We want your Unity apps to talk *directly* over a flat, secure, no-config virtual network without sending everything into the "cloud". Thus, we introduce the ZeroTier-Unity3D integration!
|
||||
|
||||
Our implementation currently intends to be the bare minimum required to get your Unity application to talk over ZeroTier virtual networks. As a result, we've created an API that is very similar to the built-in Unity LLAPI. It's possible that higher-level functionality could be added in the future.
|
||||
|
||||
***
|
||||
## Adding ZeroTier to your Unity app
|
||||
|
||||
**Step 1: Create virtual ZeroTier [virtual network](https://my.zerotier.com/)**
|
||||
|
||||
**Step 2: Add plugin**
|
||||
- Create a folder called `Plugins` in `Assets`
|
||||
- Place `ZeroTierUnity.bundle` in that folder
|
||||
|
||||
**Step 3: Add script to some `GameObject`**
|
||||
- Drag our `ZeroTier.cs` native plugin wrapper onto any `GameObject`
|
||||
|
||||
|
||||
***
|
||||
## Examples
|
||||
|
||||
Calling `ZeroTier.Init()` will start the network service in a separate thread. You can check if the service is running by checking `ZeroTier.IsRunning()`. Then, connecting and sending data to another endpoint would look something like the following:
|
||||
|
||||
```
|
||||
public void zt_sample_network_test_thread()
|
||||
{
|
||||
// Prepare sample data buffer
|
||||
byte[] buffer = new byte[1024];
|
||||
Stream stream = new MemoryStream(buffer);
|
||||
BinaryFormatter f = new BinaryFormatter();
|
||||
f.Serialize ( stream , "Welcome to the machine! (from Unity3D)" );
|
||||
|
||||
// Connect and send
|
||||
int error;
|
||||
Connect (0, "192.168.0.6", 8887, out error);
|
||||
Send(connfd,buffer,0, out error);
|
||||
}
|
||||
```
|
||||
|
||||
Finally, when you're done running the service you can call `ZeroTier.Terminate()`
|
||||
|
||||
***
|
||||
## API
|
||||
|
||||
The API is designed to resemble the Unity LLAPI, so you'll see a few familiar functions but with a slight twist.
|
||||
|
||||
- `Join(nwid)`: Joins a ZeroTier virtual network
|
||||
- `Leave(nwid)`: Leaves a ZeroTier virtual network
|
||||
- `AddHost(port)`: Creates a socket, and binds to that socket on the address and port given
|
||||
- `Connect(fd, ip_address, port, out error)`: Connects to an endpoint associated with the given `fd`
|
||||
- `Send(fd, buf, pos, out error)`: Sends data to the endpoint associated with the given `fd`
|
||||
- `Recv(fd, buf, out error)`: Receives data from an endpoint associated with the given `fd`
|
||||
- `Disconnect(fd)`: Closes a connection with an endpoint
|
||||
|
||||
***
|
||||
## Design and structure of the ZeroTier Unity OSX Bundle
|
||||
|
||||
XCode:
|
||||
New XCode project
|
||||
Select Cocoa bundle as target
|
||||
Add C linkages to external functions
|
||||
Build as 64bit (not universal)
|
||||
|
||||
Unity:
|
||||
Select x86_64 build target in `Build Settings`
|
||||
In new C# script asset:
|
||||
|
||||
```
|
||||
[DllImport ("ZeroTierUnity")]
|
||||
private static extern int unity_start_service ();
|
||||
```
|
||||
|
||||
Add asset to GameObject
|
||||
Start ZT service
|
||||
|
||||
***
|
||||
## Future Roadmap
|
||||
With the ZeroTier sockets API in place, higher-level functionality such as lobbies, chat, and object synchronization could easily be built on top.
|
||||
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 97 KiB |
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user