pub struct C2Config {
pub api_listen: SocketAddr,
pub control_endpoint: String,
pub nodes: Vec<C2NodeConfig>,
pub node_listen: Option<SocketAddr>,
pub timings: C2Timings,
/* private fields */
}Fields§
§api_listen: SocketAddr§control_endpoint: String§nodes: Vec<C2NodeConfig>§node_listen: Option<SocketAddr>Where nodes that cannot be dialled come to announce themselves.
None unless at least one node is configured accept.
timings: C2TimingsImplementations§
Source§impl C2Config
impl C2Config
pub fn new( api_listen: SocketAddr, api_token: impl Into<String>, nodes: Vec<C2NodeConfig>, ) -> Result<Self, C2ConfigError>
Sourcepub fn with_node_listen(
self,
node_listen: SocketAddr,
) -> Result<Self, C2ConfigError>
pub fn with_node_listen( self, node_listen: SocketAddr, ) -> Result<Self, C2ConfigError>
Binds the address nodes call in on.
Loopback only, deliberately, and for the same reason every other listener in this stack is: the node wire authenticates both ends with a mutual challenge-response but encrypts nothing, so its frames – terminal contents, keystrokes, file bytes – are plaintext JSON. Accepting node connections from off-box would put all of that on the network. Direction and distance are separate problems and this change only solves direction.
Sourcepub fn validate_call_home(&self) -> Result<(), C2ConfigError>
pub fn validate_call_home(&self) -> Result<(), C2ConfigError>
Every node that waits to be called needs somewhere to call, so a config that asks for one without the other is refused rather than started into a relay that can never reach that node. Checked at startup, not at connect time, because the failure is total and permanent – there is nothing to retry.