mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Bringing the TUN device and the .fips DNS responder up and taking them down is host-side work, but the bodies sat inline in the node's supervisor arms, and their handles were eight loose fields on the supervisor. Move the bodies to ipv6tun::lifecycle and gather the handles into one Handles struct there, held by the supervisor. The supervisor arms, their order and the child-exit reporting are unchanged; each arm now calls into ipv6tun. The TUN start is two calls so the node can refresh its MSS ceiling between them, exactly where it did before: open_tun creates and logs the device, then spawn_tun creates the macOS/FreeBSD shutdown pipe and starts the writer and reader threads. A failure to create the device still continues without a TUN, and a pipe or writer failure still fails the node's start. stop_tun and stop_dns carry the teardown unchanged, including the shutdown-pipe write that wakes the reader on macOS and FreeBSD. The TUN device name moves into Handles as well, so the teardown up-set can ask ipv6tun whether each child is up. A TUN counts as up when it has a device name, not when it has a sender, so an app-owned TUN still produces no TUN teardown; DNS counts as up while its task handle exists. Node::tun_name, tun_tx, dns_local_addr and enable_app_owned_tun keep their behaviour and now read or write the handles. Node::mesh_ifindex had no caller left outside a test and is replaced by the same method on Handles. Tests install a TUN sender through a test-only Node::install_tun. The moved log lines now log under fips::ipv6tun::lifecycle instead of fips::node::lifecycle. Add that target to the NAT harness and its trace overlay, and to the harnesses that relied on fips::node=debug, and note the rename in the changelog.
21 lines
602 B
Rust
21 lines
602 B
Rust
//! IPv6 Upper Layer Adaptation
|
|
//!
|
|
//! This module groups the components that bridge between the FIPS routing
|
|
//! layer and IPv6 applications: the TUN interface (packet I/O), DNS
|
|
//! responder (.fips domain resolution), and ICMPv6 handling (error
|
|
//! signaling and neighbor discovery).
|
|
|
|
pub mod config;
|
|
pub mod dns;
|
|
pub mod icmp;
|
|
pub mod icmp_rate_limit;
|
|
pub mod ipv6_shim;
|
|
pub(crate) mod lifecycle;
|
|
pub(crate) mod outbound;
|
|
pub mod tcp_mss;
|
|
pub mod tun;
|
|
|
|
// The hosts file moved to `crate::hosts`; re-exported so `crate::upper::hosts`
|
|
// and `fips::upper::hosts` still resolve.
|
|
pub use crate::hosts;
|