Decisions

Why lnk vpn works the way it does.

Why is the home exit a plugin of its own?

It's useful with no agent, since anything on a box can use the proxy, and with no box, since any machine you reach over SSH can have one. So neither the agent's plugin nor the box's owns it. lnk vpn keeps one exit per machine and reaches boxes through lnk box forward, because SSH to boxes stays the box plugin's. Agents on one machine share its exit by holding it: each holder, you or an agent by its ID, is written down, off takes one away, and the exit stops with the last. No plugin counts another's users.

How does the traffic get home?

Over SSH, not WireGuard. ssh -R opens a SOCKS proxy on the machine that SSH carries back to this computer, where the connections are made. This computer already reaches every box over SSH, so nothing new runs, no port opens and no administrator rights are needed. It carries TCP only, which is what web and API traffic is.

Why does a Mac stay awake while it's an exit?

An exit that sleeps is none, so the connection runs under caffeinate -i on a Mac. Closing a laptop's lid still sleeps it.

How does an agent use the exit?

lnk agent exit home holds its box's exit and routes the agent's proxy through it. lnk agent move gives the old box's exit back and holds the new one's.

How does the exit know your network's public address?

Some routers answer their admin page on their public address, from inside, so the exit has to know that address to refuse it. NAT-PMP asks nothing of the internet, and a STUN server works behind any router, so the exit asks both; Cloudflare's STUN server needs no account. It asks again now and then, since a home's address changes with its lease (how). For IPv6 a computer sees only its own /64, not what its network was delegated, so the exit refuses the /48 around it, the most a home is delegated: at worst a few neighbors' addresses with the same provider.

Why is the exit a Unix socket on the machine?

The proxy takes no password, so only where it listens keeps others out. On a TCP port, an sshd with GatewayPorts yes opens it on every address, and a check on the host can only close it after it opened, a second or so after each reconnect. A socket in the user's home folder has no port for any setting to open, and sshd makes it the user's alone, so other users of the machine are kept out too. A password per exit would guard the port rather than remove it, and change what every program that uses it sends.

Why does an older peer keep the port?

An lnk on a box from before the socket routes its agents to the port and refuses the socket, so lnk agent exit home asks the box for the socket and, refused, takes the port for that agent. The exit stays on the port while anyone holds it there, so an agent already routed to it keeps working, and it moves to the socket once nobody does. A move upgrades the box first, so a moved agent always gets the socket.

Why does a host's exit on the port check it rather than ask for a password?

On the port, every program that uses the proxy reaches it by its address alone. A password would change what each sends; a check on the host, run by the exit's own SSH connection, keeps the address as it is and stops the exit wherever the port wouldn't be private.