NetVM: CDP via userspace relay (REDIRECT to loopback did not establish)
This commit is contained in:
+12
-7
@@ -58,13 +58,18 @@ nsexec ip link set "$WG" up
|
||||
nsexec ip route replace default dev "$WG"
|
||||
nsexec ip -6 route replace default dev "$WG" 2>/dev/null || true
|
||||
|
||||
# CDP bridge: chromium binds DevTools to loopback only; redirect the veth
|
||||
# IP:CDP_PORT there so the host (and SSH-forwarded operators) can reach it.
|
||||
# (netns iptables is namespaced; rules vanish with the netns on down.)
|
||||
nsexec sysctl -qw net.ipv4.conf.all.route_localnet=1
|
||||
nsexec sysctl -qw "net.ipv4.conf.${VPEER}.route_localnet=1"
|
||||
nsexec iptables -t nat -C PREROUTING -d "$PEER_IP" -p tcp --dport "$CDP_PORT" -j REDIRECT --to-port "$CDP_PORT" 2>/dev/null || \
|
||||
nsexec iptables -t nat -A PREROUTING -d "$PEER_IP" -p tcp --dport "$CDP_PORT" -j REDIRECT --to-port "$CDP_PORT"
|
||||
# CDP bridge: chromium binds DevTools to loopback only. A tiny TCP relay
|
||||
# listens on the veth IP and forwards to loopback (empirically reliable;
|
||||
# iptables REDIRECT to 127.0.0.1 did not establish). Supervised via pidfile.
|
||||
PIDFILE="/run/netvm-${NODE}-cdp-relay.pid"
|
||||
if [ -f "$PIDFILE" ] && kill -0 "$(cat "$PIDFILE")" 2>/dev/null; then
|
||||
echo "cdp relay already running"
|
||||
else
|
||||
nsexec python3 "$SCRIPT_DIR/netvm-cdp-relay.py" "$PEER_IP" "$CDP_PORT" 127.0.0.1 "$CDP_PORT" \
|
||||
>/dev/null 2>&1 &
|
||||
echo $! > "$PIDFILE"
|
||||
echo "cdp relay started ($PEER_IP:$CDP_PORT -> 127.0.0.1:$CDP_PORT)"
|
||||
fi
|
||||
|
||||
# wait for handshake (first one can take ~10s)
|
||||
HS=""
|
||||
|
||||
Reference in New Issue
Block a user