Decisions
Why lnk vpn works the way it does.
Why is the home exit a plugin of its own?
It's useful with no agent, since anything on a box can use the proxy,
and with no box, since any machine you reach over SSH can have one. So
neither the agent's plugin nor the box's owns it. lnk vpn keeps one
exit per machine and reaches boxes through lnk box forward, because
SSH to boxes stays the box plugin's. Agents on one machine share its
exit by holding it: each holder, you or an agent by its ID, is written
down, off takes one away, and the exit stops with the last. No plugin
counts another's users.
How does the traffic get home?
Over SSH, not WireGuard. ssh -R opens a SOCKS proxy on the machine
that SSH carries back to this computer, where the connections
are made. This computer already reaches every box over SSH, so nothing
new runs, no port opens and no administrator rights are needed. It
carries TCP only, which is what web and API traffic is.
Why does a Mac stay awake while it's an exit?
An exit that sleeps is none, so the connection runs under caffeinate -i on a Mac. Closing a laptop's lid still sleeps it.
How does an agent use the exit?
lnk agent exit home holds its box's exit and routes the agent's proxy
through it. lnk agent move gives the old box's exit back and holds
the new one's.
How does the exit know your network's public address?
Some routers answer their admin page on their public address, from inside, so the exit has to know that address to refuse it. NAT-PMP asks nothing of the internet, and a STUN server works behind any router, so the exit asks both; Cloudflare's STUN server needs no account. It asks again now and then, since a home's address changes with its lease (how). For IPv6 a computer sees only its own /64, not what its network was delegated, so the exit refuses the /48 around it, the most a home is delegated: at worst a few neighbors' addresses with the same provider.
Why is the exit a Unix socket on the machine?
The proxy takes no password, so only where it listens keeps others
out. On a TCP port, an sshd with GatewayPorts yes opens it on every
address, and a check on the host can only close it after it opened,
a second or so after each reconnect. A socket in the user's home
folder has no port for any setting to open, and sshd makes it the
user's alone, so other users of the machine are kept out too. A
password per exit would guard the port rather than remove it, and
change what every program that uses it sends.
Why does an older peer keep the port?
An lnk on a box from before the socket routes its agents to the port
and refuses the socket, so lnk agent exit home asks the box for the
socket and, refused, takes the port for that agent. The exit stays on
the port while anyone holds it there, so an agent already routed to it
keeps working, and it moves to the socket once nobody does. A move
upgrades the box first, so a moved agent always gets the socket.
Why does a host's exit on the port check it rather than ask for a password?
On the port, every program that uses the proxy reaches it by its address alone. A password would change what each sends; a check on the host, run by the exit's own SSH connection, keeps the address as it is and stops the exit wherever the port wouldn't be private.
