2021-04-19 12:56:18 +00:00
|
|
|
#!/usr/bin/env bash
|
|
|
|
set -e
|
2021-05-21 05:22:43 +00:00
|
|
|
shopt -s nocasematch
|
2021-04-19 12:56:18 +00:00
|
|
|
|
|
|
|
SELF_DIR="$(dirname "$0")"
|
|
|
|
cd "$SELF_DIR/.."
|
|
|
|
|
2021-05-21 05:22:43 +00:00
|
|
|
if [[ $# -eq 1 ]]; then
|
|
|
|
case "$1" in
|
|
|
|
kernel)
|
|
|
|
INNERNET_ARGS=""
|
|
|
|
;;
|
|
|
|
userspace)
|
|
|
|
INNERNET_ARGS="--backend userspace"
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
echo "invalid backend (must be kernel or userspace)"
|
|
|
|
exit 1
|
|
|
|
esac
|
|
|
|
else
|
|
|
|
cat >&2 <<-_EOF
|
|
|
|
Usage: "${0##*/}" <BACKEND>
|
|
|
|
|
|
|
|
BACKEND: "kernel" or "userspace"
|
|
|
|
_EOF
|
|
|
|
exit
|
|
|
|
fi
|
|
|
|
|
2021-04-19 12:56:18 +00:00
|
|
|
cmd() {
|
|
|
|
echo "[#] $*" >&2
|
|
|
|
"$@"
|
|
|
|
}
|
|
|
|
|
|
|
|
info() {
|
2021-05-20 02:43:52 +00:00
|
|
|
echo -e "\033[0;34m- $@\033[0m" 1>&2
|
2021-04-19 12:56:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
tmp_dir=$(mktemp -d -t innernet-tests-XXXXXXXXXX)
|
|
|
|
cleanup() {
|
|
|
|
info "Cleaning up."
|
|
|
|
rm -rf "$tmp_dir"
|
|
|
|
cmd docker stop $(docker ps -q) || true
|
|
|
|
cmd docker network remove innernet
|
|
|
|
}
|
|
|
|
trap cleanup EXIT
|
|
|
|
|
|
|
|
info "Creating network."
|
|
|
|
NETWORK=$(cmd docker network create -d bridge --subnet=172.18.0.0/16 innernet)
|
|
|
|
|
|
|
|
info "Starting server."
|
2021-05-19 18:16:28 +00:00
|
|
|
SERVER_CONTAINER=$(cmd docker create -it --rm \
|
2021-04-19 12:56:18 +00:00
|
|
|
--network "$NETWORK" \
|
|
|
|
--ip 172.18.1.1 \
|
2021-05-19 18:16:28 +00:00
|
|
|
--volume /dev/net/tun:/dev/net/tun \
|
|
|
|
--env RUST_LOG=debug \
|
2021-05-21 05:22:43 +00:00
|
|
|
--env INNERNET_ARGS="$INNERNET_ARGS" \
|
2021-04-19 12:56:18 +00:00
|
|
|
--cap-add NET_ADMIN \
|
2021-09-15 13:57:48 +00:00
|
|
|
innernet)
|
2021-05-19 18:16:28 +00:00
|
|
|
cmd docker start -a "$SERVER_CONTAINER" &
|
2021-04-19 12:56:18 +00:00
|
|
|
|
2021-05-08 15:32:51 +00:00
|
|
|
info "server started as $SERVER_CONTAINER"
|
2021-04-19 12:56:18 +00:00
|
|
|
info "Waiting for server to initialize."
|
2021-09-18 07:15:29 +00:00
|
|
|
cmd sleep 5
|
2021-04-19 12:56:18 +00:00
|
|
|
|
|
|
|
info "Starting first peer."
|
|
|
|
cmd docker cp "$SERVER_CONTAINER:/app/peer1.toml" "$tmp_dir"
|
|
|
|
PEER1_CONTAINER=$(cmd docker create --rm -it \
|
|
|
|
--network "$NETWORK" \
|
|
|
|
--ip 172.18.1.2 \
|
2021-05-19 18:16:28 +00:00
|
|
|
--volume /dev/net/tun:/dev/net/tun \
|
2021-04-19 12:56:18 +00:00
|
|
|
--env INTERFACE=evilcorp \
|
2021-05-21 05:22:43 +00:00
|
|
|
--env INNERNET_ARGS="$INNERNET_ARGS" \
|
2021-04-19 12:56:18 +00:00
|
|
|
--cap-add NET_ADMIN \
|
2021-09-15 13:57:48 +00:00
|
|
|
innernet /app/start-client.sh)
|
2021-05-08 15:32:51 +00:00
|
|
|
info "peer1 started as $PEER1_CONTAINER"
|
2021-04-19 12:56:18 +00:00
|
|
|
cmd docker cp "$tmp_dir/peer1.toml" "$PEER1_CONTAINER:/app/invite.toml"
|
|
|
|
cmd docker start "$PEER1_CONTAINER"
|
2021-05-19 18:16:28 +00:00
|
|
|
sleep 10
|
2021-04-19 12:56:18 +00:00
|
|
|
|
|
|
|
info "Creating a new CIDR from first peer."
|
|
|
|
cmd docker exec "$PEER1_CONTAINER" innernet \
|
|
|
|
add-cidr evilcorp \
|
|
|
|
--name "robots" \
|
|
|
|
--cidr "10.66.2.0/24" \
|
|
|
|
--parent "evilcorp" \
|
|
|
|
--yes
|
|
|
|
|
|
|
|
info "Creating association between CIDRs."
|
|
|
|
cmd docker exec "$PEER1_CONTAINER" innernet \
|
|
|
|
add-association evilcorp \
|
|
|
|
humans \
|
|
|
|
robots
|
|
|
|
|
|
|
|
info "Creating invitation for second peer from first peer."
|
|
|
|
cmd docker exec "$PEER1_CONTAINER" innernet \
|
|
|
|
add-peer evilcorp \
|
|
|
|
--name "peer2" \
|
|
|
|
--cidr "robots" \
|
|
|
|
--admin false \
|
|
|
|
--auto-ip \
|
|
|
|
--save-config "/app/peer2.toml" \
|
2021-05-08 18:07:32 +00:00
|
|
|
--invite-expires "30s" \
|
2021-04-19 12:56:18 +00:00
|
|
|
--yes
|
|
|
|
cmd docker cp "$PEER1_CONTAINER:/app/peer2.toml" "$tmp_dir"
|
|
|
|
|
|
|
|
info "Starting second peer."
|
|
|
|
PEER2_CONTAINER=$(docker create --rm -it \
|
|
|
|
--network "$NETWORK" \
|
|
|
|
--ip 172.18.1.3 \
|
2021-05-19 18:16:28 +00:00
|
|
|
--volume /dev/net/tun:/dev/net/tun \
|
2021-04-19 12:56:18 +00:00
|
|
|
--cap-add NET_ADMIN \
|
|
|
|
--env INTERFACE=evilcorp \
|
2021-05-21 05:22:43 +00:00
|
|
|
--env INNERNET_ARGS="$INNERNET_ARGS" \
|
2021-09-15 13:57:48 +00:00
|
|
|
innernet /app/start-client.sh)
|
2021-05-08 15:32:51 +00:00
|
|
|
info "peer2 started as $PEER2_CONTAINER"
|
2021-04-19 12:56:18 +00:00
|
|
|
cmd docker cp "$tmp_dir/peer2.toml" "$PEER2_CONTAINER:/app/invite.toml"
|
|
|
|
cmd docker start "$PEER2_CONTAINER"
|
|
|
|
sleep 10
|
|
|
|
|
2021-05-08 18:07:32 +00:00
|
|
|
info "Creating short-lived invitation for third peer."
|
|
|
|
cmd docker exec "$PEER1_CONTAINER" innernet \
|
|
|
|
add-peer evilcorp \
|
|
|
|
--name "peer3" \
|
|
|
|
--cidr "robots" \
|
|
|
|
--admin false \
|
|
|
|
--ip "10.66.2.100" \
|
|
|
|
--save-config "/app/peer3.toml" \
|
2021-09-18 07:15:29 +00:00
|
|
|
--invite-expires "1s" \
|
2021-05-08 18:07:32 +00:00
|
|
|
--yes
|
|
|
|
|
|
|
|
info "waiting 15 seconds to see if the server clears out the IP address."
|
2021-09-18 07:15:29 +00:00
|
|
|
sleep 11
|
2021-05-08 18:07:32 +00:00
|
|
|
|
|
|
|
info "Re-requesting invite after expiration with the same parameters."
|
|
|
|
cmd docker exec "$PEER1_CONTAINER" innernet \
|
|
|
|
add-peer evilcorp \
|
|
|
|
--name "peer3" \
|
|
|
|
--cidr "robots" \
|
|
|
|
--admin false \
|
|
|
|
--ip "10.66.2.100" \
|
|
|
|
--save-config "/app/peer3_2.toml" \
|
|
|
|
--invite-expires "30m" \
|
|
|
|
--yes
|
|
|
|
|
|
|
|
info "peer2 started as $PEER2_CONTAINER"
|
|
|
|
cmd docker cp "$tmp_dir/peer2.toml" "$PEER2_CONTAINER:/app/invite.toml"
|
|
|
|
cmd docker start "$PEER2_CONTAINER"
|
|
|
|
sleep 10
|
2021-04-19 12:56:18 +00:00
|
|
|
|
|
|
|
info "Checking connectivity betweeen peers."
|
|
|
|
cmd docker exec "$PEER2_CONTAINER" ping -c3 10.66.0.1
|
|
|
|
cmd docker exec "$PEER2_CONTAINER" ping -c3 10.66.1.1
|