ExtOsdep.cpp 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628
  1. /*
  2. * Copyright (c)2019 ZeroTier, Inc.
  3. *
  4. * Use of this software is governed by the Business Source License included
  5. * in the LICENSE.TXT file in the project's root directory.
  6. *
  7. * Change Date: 2026-01-01
  8. *
  9. * On the date above, in accordance with the Business Source License, use
  10. * of this software will be governed by version 2.0 of the Apache License.
  11. */
  12. /****/
  13. #include "ExtOsdep.hpp"
  14. #include "../node/AtomicCounter.hpp"
  15. #include <fcntl.h>
  16. #include <iostream>
  17. #include <list>
  18. #include <sys/times.h>
  19. #include <unistd.h>
  20. #define ZT_TAP_BUF_SIZE 16384
  21. namespace ZeroTier {
  22. static int eodFd = -1;
  23. static Mutex eodMutex;
  24. static int eodMgmtFd = -1;
  25. struct EodRoute {
  26. InetAddress target;
  27. InetAddress via;
  28. InetAddress src;
  29. std::string ifname;
  30. };
  31. static std::list<EodRoute> allRoutes;
  32. template <typename T> static void __eodSend(const T& t)
  33. {
  34. write(eodFd, &t, sizeof(t));
  35. }
  36. static void strncpyx(char* dest, const char* src, size_t n)
  37. {
  38. strncpy(dest, src, n);
  39. if (n > 1) {
  40. dest[n - 1] = 0;
  41. }
  42. }
  43. static int __eodWait(unsigned char msg, unsigned char* d, unsigned l, unsigned maxl = 0, int* recvfd = nullptr)
  44. {
  45. if (! maxl) {
  46. maxl = l;
  47. }
  48. auto start = times(NULL);
  49. while (1) {
  50. msghdr mh;
  51. iovec iov;
  52. struct {
  53. size_t cmsg_len;
  54. int cmsg_level;
  55. int cmsg_type;
  56. int fd;
  57. } __attribute__((packed)) cmsg;
  58. memset(&mh, 0, sizeof(mh));
  59. mh.msg_iov = &iov;
  60. mh.msg_iovlen = 1;
  61. if (recvfd) {
  62. mh.msg_control = &cmsg;
  63. mh.msg_controllen = sizeof(cmsg);
  64. }
  65. iov.iov_base = d;
  66. iov.iov_len = maxl;
  67. int r = recvmsg(eodFd, &mh, MSG_TRUNC | MSG_CMSG_CLOEXEC);
  68. if (r > 0) {
  69. if (recvfd && mh.msg_controllen >= sizeof(cmsg) && cmsg.cmsg_len == sizeof(cmsg) && cmsg.cmsg_level == SOL_SOCKET && cmsg.cmsg_type == SCM_RIGHTS) {
  70. *recvfd = cmsg.fd;
  71. fprintf(stderr, "eodWait: received fd %d\n", *recvfd);
  72. }
  73. if (d[0] != msg) {
  74. fprintf(stderr, "eodWait: wrong msg, expected %u got %u\n", msg, d[0]);
  75. return -1;
  76. }
  77. if ((unsigned)r < l || (unsigned)r > maxl) {
  78. fprintf(stderr, "eodWait: wrong len, expected %u got %d\n", l, r);
  79. return -1;
  80. }
  81. return r;
  82. }
  83. if (times(NULL) - start > 500) {
  84. fprintf(stderr, "eodWait: timeout\n");
  85. return -1;
  86. }
  87. usleep(100000);
  88. }
  89. }
  90. template <typename T> static bool __eodWait(unsigned msg, T& t)
  91. {
  92. return __eodWait(msg, (unsigned char*)&t, sizeof(T)) == (int)sizeof(T);
  93. }
  94. template <typename M, typename R> static bool __eodXchg(const M& m, unsigned rm, R& r)
  95. {
  96. __eodSend(m);
  97. return __eodWait(rm, r);
  98. }
  99. template <typename M, typename R> static bool eodXchg(const M& m, unsigned rm, R& r)
  100. {
  101. Mutex::Lock l(eodMutex);
  102. return __eodXchg(m, rm, r);
  103. }
  104. void ExtOsdep::init(int fd1, int fd2)
  105. {
  106. eodFd = fd1;
  107. eodMgmtFd = fd2;
  108. fcntl(eodMgmtFd, F_SETFL, O_NONBLOCK);
  109. }
  110. void ExtOsdep::started(int* f, void** cp)
  111. {
  112. *f = eodMgmtFd;
  113. *cp = (void*)eodMgmtFd;
  114. unsigned char msg = ZT_EOD_MSG_STARTED;
  115. Mutex::Lock l(eodMutex);
  116. __eodSend(msg);
  117. }
  118. static std::string mgmtrd;
  119. static std::string mgmtwr;
  120. bool ExtOsdep::mgmtWritable(void* cookie)
  121. {
  122. if (cookie != (void*)eodMgmtFd) {
  123. return false;
  124. }
  125. if (mgmtwr.size() == 0) {
  126. return true;
  127. }
  128. auto sz = write(eodMgmtFd, mgmtwr.data(), mgmtwr.size());
  129. if (sz <= 0) {
  130. return false;
  131. }
  132. mgmtwr.erase(mgmtwr.begin(), mgmtwr.begin() + sz);
  133. return mgmtwr.empty();
  134. }
  135. bool ExtOsdep::mgmtRecv(void* cookie, void* data, unsigned long len, std::function<unsigned(unsigned, const std::string&, const std::string&, std::string&)> cb)
  136. {
  137. if (cookie != (void*)eodMgmtFd) {
  138. return false;
  139. }
  140. mgmtrd.append((char*)data, len);
  141. while (1) {
  142. auto req = (zt_eod_mgmt_req*)mgmtrd.data();
  143. if (mgmtrd.size() < sizeof(*req)) {
  144. break;
  145. }
  146. unsigned reqsz = sizeof(*req) + req->pathlen + req->datalen;
  147. if (mgmtrd.size() < reqsz) {
  148. break;
  149. }
  150. std::string resp;
  151. char* p = (char*)req->data;
  152. zt_eod_mgmt_reply rep;
  153. rep.scode = cb(req->method, std::string(p, p + req->pathlen), std::string(p + req->pathlen, p + req->pathlen + req->datalen), resp);
  154. rep.datalen = resp.size();
  155. mgmtrd.erase(mgmtrd.begin(), mgmtrd.begin() + reqsz);
  156. mgmtwr.append((char*)&rep, sizeof(rep));
  157. mgmtwr.append(resp);
  158. auto sz = write(eodMgmtFd, mgmtwr.data(), mgmtwr.size());
  159. if (sz > 0) {
  160. mgmtwr.erase(mgmtwr.begin(), mgmtwr.begin() + sz);
  161. }
  162. }
  163. return ! mgmtwr.empty();
  164. }
  165. void ExtOsdep::routeAddDel(bool add, const InetAddress& target, const InetAddress& via, const InetAddress& src, const char* ifname)
  166. {
  167. Mutex::Lock l(eodMutex);
  168. std::string ifn;
  169. if (ifname) {
  170. ifn = ifname;
  171. }
  172. if (add) {
  173. for (auto x = allRoutes.begin(); x != allRoutes.end(); ++x) {
  174. if (x->target == target && x->via == via && x->src == src && x->ifname == ifn) {
  175. return;
  176. }
  177. }
  178. allRoutes.push_back({ target, via, src, ifn });
  179. }
  180. else {
  181. bool found = false;
  182. for (auto x = allRoutes.begin(); x != allRoutes.end(); ++x) {
  183. if (x->target == target && x->via == via && x->src == src && x->ifname == ifn) {
  184. allRoutes.erase(x);
  185. found = true;
  186. break;
  187. }
  188. }
  189. if (! found) {
  190. return;
  191. }
  192. }
  193. zt_eod_msg_route req;
  194. memset(&req, 0, sizeof(req));
  195. req.cmd = add ? ZT_EOD_MSG_ADDROUTE : ZT_EOD_MSG_DELROUTE;
  196. req.afi = target.isV4() ? 1 : 2;
  197. req.dstlen = target.netmaskBits();
  198. memcpy(req.dst, target.rawIpData(), target.isV4() ? 4 : 16);
  199. if (ifname) {
  200. strncpyx(req.dev, ifname, sizeof(req.dev));
  201. }
  202. if (via) {
  203. memcpy(req.gw, via.rawIpData(), target.isV4() ? 4 : 16);
  204. }
  205. if (src) {
  206. memcpy(req.src, src.rawIpData(), target.isV4() ? 4 : 16);
  207. }
  208. unsigned char resp;
  209. __eodXchg(req, add ? ZT_EOD_MSG_ADDROUTERESP : ZT_EOD_MSG_DELROUTERESP, resp);
  210. }
  211. bool ExtOsdep::getBindAddrs(std::map<InetAddress, std::string>& ret)
  212. {
  213. Mutex::Lock l(eodMutex);
  214. unsigned char req = ZT_EOD_MSG_GETBINDADDRS;
  215. __eodSend(req);
  216. zt_eod_msg_getbindaddrsresp* resp;
  217. unsigned char buf[ZT_EOD_MAXMSGSIZE];
  218. int r = __eodWait(ZT_EOD_MSG_GETBINDADDRSRESP, (unsigned char*)buf, sizeof(*resp), sizeof(buf));
  219. if (r < (int)sizeof(*resp)) {
  220. return false;
  221. }
  222. int c = (r - (int)sizeof(*resp)) / sizeof(resp->addrs[0]);
  223. resp = (zt_eod_msg_getbindaddrsresp*)buf;
  224. for (int i = 0; i < c; ++i) {
  225. ret[InetAddress(resp->addrs[i].data, resp->addrs[i].afi == 1 ? 4 : 16, resp->addrs[i].len)] = resp->addrs[i].ifname;
  226. }
  227. return resp->result;
  228. }
  229. ExtOsdepTap::ExtOsdepTap(
  230. const char* homePath,
  231. const MAC& mac,
  232. unsigned int mtu,
  233. unsigned int metric,
  234. uint64_t nwid,
  235. const char* friendlyName,
  236. void (*handler)(void*, void*, uint64_t, const MAC&, const MAC&, unsigned int, unsigned int, const void*, unsigned int),
  237. void* arg)
  238. : _handler(handler)
  239. , _arg(arg)
  240. , _nwid(nwid)
  241. , _mac(mac)
  242. , _homePath(homePath)
  243. , _mtu(mtu)
  244. , _fd(0)
  245. , _enabled(true)
  246. , _run(true)
  247. {
  248. zt_eod_msg_addtap req;
  249. req.cmd = ZT_EOD_MSG_ADDTAP;
  250. req.nwid = nwid;
  251. req.mtu = mtu;
  252. req.metric = metric;
  253. strncpyx(req.fname, friendlyName, sizeof(req.fname));
  254. mac.copyTo(req.mac, 6);
  255. zt_eod_msg_addtapresp resp;
  256. Mutex::Lock l(eodMutex);
  257. __eodSend(req);
  258. _fd = -1;
  259. if (__eodWait(ZT_EOD_MSG_ADDTAPRESP, (unsigned char*)&resp, sizeof(resp), sizeof(resp), &_fd) != sizeof(resp)) {
  260. throw std::runtime_error(std::string("could not create TAP"));
  261. }
  262. _dev = resp.name;
  263. if (_dev.empty() || _fd < 0) {
  264. throw std::runtime_error(std::string("could not create TAP"));
  265. }
  266. fcntl(_fd, F_SETFL, O_NONBLOCK);
  267. (void)::pipe(_shutdownSignalPipe);
  268. for (unsigned int t = 0; t < 2; ++t) {
  269. _tapReaderThread[t] = std::thread([this, t] {
  270. fd_set readfds, nullfds;
  271. int n, nfds, r;
  272. void* buf = nullptr;
  273. std::vector<void*> buffers;
  274. if (! _run) {
  275. return;
  276. }
  277. FD_ZERO(&readfds);
  278. FD_ZERO(&nullfds);
  279. nfds = (int)std::max(_shutdownSignalPipe[0], _fd) + 1;
  280. r = 0;
  281. for (;;) {
  282. FD_SET(_shutdownSignalPipe[0], &readfds);
  283. FD_SET(_fd, &readfds);
  284. select(nfds, &readfds, &nullfds, &nullfds, (struct timeval*)0);
  285. if (FD_ISSET(_shutdownSignalPipe[0], &readfds)) { // writes to shutdown pipe terminate thread
  286. break;
  287. }
  288. if (FD_ISSET(_fd, &readfds)) {
  289. for (;;) { // read until there are no more packets, then return to outer select() loop
  290. if (! buf) {
  291. // To reduce use of the mutex, we keep a local buffer vector and
  292. // swap (which is a pointer swap) with the global one when it's
  293. // empty. This retrieves a batch of buffers to use.
  294. if (buffers.empty()) {
  295. std::lock_guard<std::mutex> l(_buffers_l);
  296. buffers.swap(_buffers);
  297. }
  298. if (buffers.empty()) {
  299. buf = malloc(ZT_TAP_BUF_SIZE);
  300. if (! buf) {
  301. break;
  302. }
  303. }
  304. else {
  305. buf = buffers.back();
  306. buffers.pop_back();
  307. }
  308. }
  309. n = (int)::read(_fd, reinterpret_cast<uint8_t*>(buf) + r, ZT_TAP_BUF_SIZE - r);
  310. if (n > 0) {
  311. // Some tap drivers like to send the ethernet frame and the
  312. // payload in two chunks, so handle that by accumulating
  313. // data until we have at least a frame.
  314. r += n;
  315. if (r > 14) {
  316. if (r > ((int)_mtu + 14)) { // sanity check for weird TAP behavior on some platforms
  317. r = _mtu + 14;
  318. }
  319. if (_enabled && _tapqsize.load() < 1000) {
  320. ++_tapqsize;
  321. _tapq.post(std::pair<void*, int>(buf, r));
  322. buf = nullptr;
  323. }
  324. r = 0;
  325. }
  326. }
  327. else {
  328. r = 0;
  329. break;
  330. }
  331. }
  332. }
  333. }
  334. });
  335. }
  336. _tapProcessorThread = std::thread([this] {
  337. MAC to, from;
  338. std::pair<void*, int> qi;
  339. while (_tapq.get(qi)) {
  340. --_tapqsize;
  341. uint8_t* const b = reinterpret_cast<uint8_t*>(qi.first);
  342. if (b) {
  343. to.setTo(b, 6);
  344. from.setTo(b + 6, 6);
  345. unsigned int etherType = Utils::ntoh(((const uint16_t*)b)[6]);
  346. _handler(_arg, nullptr, _nwid, from, to, etherType, 0, (const void*)(b + 14), (unsigned int)(qi.second - 14));
  347. {
  348. std::lock_guard<std::mutex> l(_buffers_l);
  349. if (_buffers.size() < 128) {
  350. _buffers.push_back(qi.first);
  351. }
  352. else {
  353. free(qi.first);
  354. }
  355. }
  356. }
  357. else {
  358. break;
  359. }
  360. }
  361. });
  362. }
  363. ExtOsdepTap::~ExtOsdepTap()
  364. {
  365. _run = false;
  366. (void)::write(_shutdownSignalPipe[1], "\0", 1); // causes reader thread(s) to exit
  367. _tapq.post(std::pair<void*, int>(nullptr, 0)); // causes processor thread to exit
  368. _tapReaderThread[0].join();
  369. _tapReaderThread[1].join();
  370. _tapProcessorThread.join();
  371. ::close(_fd);
  372. ::close(_shutdownSignalPipe[0]);
  373. ::close(_shutdownSignalPipe[1]);
  374. for (std::vector<void*>::iterator i(_buffers.begin()); i != _buffers.end(); ++i) {
  375. free(*i);
  376. }
  377. std::vector<std::pair<void*, int> > dv(_tapq.drain());
  378. for (std::vector<std::pair<void*, int> >::iterator i(dv.begin()); i != dv.end(); ++i) {
  379. if (i->first) {
  380. free(i->first);
  381. }
  382. }
  383. zt_eod_msg_deltap req;
  384. req.cmd = ZT_EOD_MSG_DELTAP;
  385. strcpy(req.name, _dev.c_str());
  386. unsigned char resp;
  387. eodXchg(req, ZT_EOD_MSG_DELTAPRESP, resp);
  388. }
  389. void ExtOsdepTap::setEnabled(bool en)
  390. {
  391. _enabled = en;
  392. }
  393. bool ExtOsdepTap::enabled() const
  394. {
  395. return _enabled;
  396. }
  397. void ExtOsdepTap::doRemoveIp(const InetAddress& ip)
  398. {
  399. zt_eod_msg_ip req;
  400. req.cmd = ZT_EOD_MSG_DELIP;
  401. strcpy(req.name, _dev.c_str());
  402. req.afi = ip.isV4() ? 1 : 2;
  403. req.len = ip.netmaskBits();
  404. memcpy(req.data, ip.rawIpData(), ip.isV4() ? 4 : 16);
  405. unsigned char resp;
  406. __eodXchg(req, ZT_EOD_MSG_DELIPRESP, resp);
  407. }
  408. bool ExtOsdepTap::addIp(const InetAddress& ip)
  409. {
  410. Mutex::Lock l(eodMutex);
  411. for (auto i = allIps.begin(); i != allIps.end(); ++i) {
  412. if (*i == ip) {
  413. return true;
  414. }
  415. if (i->ipsEqual(ip)) {
  416. doRemoveIp(*i);
  417. }
  418. }
  419. zt_eod_msg_ip req;
  420. req.cmd = ZT_EOD_MSG_ADDIP;
  421. strcpy(req.name, _dev.c_str());
  422. req.afi = ip.isV4() ? 1 : 2;
  423. req.len = ip.netmaskBits();
  424. memcpy(req.data, ip.rawIpData(), ip.isV4() ? 4 : 16);
  425. unsigned char resp;
  426. __eodXchg(req, ZT_EOD_MSG_ADDIPRESP, resp);
  427. allIps.push_back(ip);
  428. return true;
  429. }
  430. bool ExtOsdepTap::addIps(std::vector<InetAddress> ips)
  431. {
  432. return false;
  433. }
  434. bool ExtOsdepTap::removeIp(const InetAddress& ip)
  435. {
  436. Mutex::Lock l(eodMutex);
  437. for (auto i = allIps.begin(); i != allIps.end(); ++i) {
  438. if (*i == ip) {
  439. doRemoveIp(*i);
  440. return true;
  441. }
  442. }
  443. return false;
  444. }
  445. std::vector<InetAddress> ExtOsdepTap::ips() const
  446. {
  447. std::vector<InetAddress> ret;
  448. Mutex::Lock l(eodMutex);
  449. zt_eod_msg_getips req;
  450. req.cmd = ZT_EOD_MSG_GETIPS;
  451. strcpy(req.name, _dev.c_str());
  452. __eodSend(req);
  453. zt_eod_msg_getipsresp* resp;
  454. unsigned char buf[ZT_EOD_MAXMSGSIZE];
  455. int r = __eodWait(ZT_EOD_MSG_GETIPSRESP, (unsigned char*)buf, sizeof(*resp), sizeof(buf));
  456. if (r < (int)sizeof(*resp)) {
  457. return ret;
  458. }
  459. int c = (r - (int)sizeof(*resp)) / sizeof(resp->addrs[0]);
  460. resp = (zt_eod_msg_getipsresp*)buf;
  461. for (int i = 0; i < c; ++i) {
  462. ret.push_back(InetAddress(resp->addrs[i].data, resp->addrs[i].afi == 1 ? 4 : 16, resp->addrs[i].len));
  463. }
  464. return ret;
  465. }
  466. void ExtOsdepTap::put(const MAC& from, const MAC& to, unsigned int etherType, const void* data, unsigned int len)
  467. {
  468. char putBuf[ZT_MAX_MTU + 64];
  469. if ((_fd > 0) && (len <= _mtu) && (_enabled)) {
  470. to.copyTo(putBuf, 6);
  471. from.copyTo(putBuf + 6, 6);
  472. *((uint16_t*)(putBuf + 12)) = htons((uint16_t)etherType);
  473. memcpy(putBuf + 14, data, len);
  474. len += 14;
  475. (void)::write(_fd, putBuf, len);
  476. }
  477. }
  478. std::string ExtOsdepTap::deviceName() const
  479. {
  480. return _dev;
  481. }
  482. void ExtOsdepTap::setFriendlyName(const char* friendlyName)
  483. {
  484. }
  485. void ExtOsdepTap::scanMulticastGroups(std::vector<MulticastGroup>& added, std::vector<MulticastGroup>& removed)
  486. {
  487. char *ptr, *ptr2;
  488. unsigned char mac[6];
  489. std::vector<MulticastGroup> newGroups;
  490. int fd = ::open("/proc/net/dev_mcast", O_RDONLY);
  491. if (fd > 0) {
  492. char buf[131072];
  493. int n = (int)::read(fd, buf, sizeof(buf));
  494. if ((n > 0) && (n < (int)sizeof(buf))) {
  495. buf[n] = (char)0;
  496. for (char* l = strtok_r(buf, "\r\n", &ptr); (l); l = strtok_r((char*)0, "\r\n", &ptr)) {
  497. int fno = 0;
  498. char* devname = (char*)0;
  499. char* mcastmac = (char*)0;
  500. for (char* f = strtok_r(l, " \t", &ptr2); (f); f = strtok_r((char*)0, " \t", &ptr2)) {
  501. if (fno == 1) {
  502. devname = f;
  503. }
  504. else if (fno == 4) {
  505. mcastmac = f;
  506. }
  507. ++fno;
  508. }
  509. if ((devname) && (! strcmp(devname, _dev.c_str())) && (mcastmac) && (Utils::unhex(mcastmac, mac, 6) == 6)) {
  510. newGroups.push_back(MulticastGroup(MAC(mac, 6), 0));
  511. }
  512. }
  513. }
  514. ::close(fd);
  515. }
  516. std::vector<InetAddress> allIps(ips());
  517. for (std::vector<InetAddress>::iterator ip(allIps.begin()); ip != allIps.end(); ++ip) {
  518. newGroups.push_back(MulticastGroup::deriveMulticastGroupForAddressResolution(*ip));
  519. }
  520. std::sort(newGroups.begin(), newGroups.end());
  521. newGroups.erase(std::unique(newGroups.begin(), newGroups.end()), newGroups.end());
  522. for (std::vector<MulticastGroup>::iterator m(newGroups.begin()); m != newGroups.end(); ++m) {
  523. if (! std::binary_search(_multicastGroups.begin(), _multicastGroups.end(), *m)) {
  524. added.push_back(*m);
  525. }
  526. }
  527. for (std::vector<MulticastGroup>::iterator m(_multicastGroups.begin()); m != _multicastGroups.end(); ++m) {
  528. if (! std::binary_search(newGroups.begin(), newGroups.end(), *m)) {
  529. removed.push_back(*m);
  530. }
  531. }
  532. _multicastGroups.swap(newGroups);
  533. }
  534. void ExtOsdepTap::setMtu(unsigned int mtu)
  535. {
  536. if (mtu == _mtu) {
  537. return;
  538. }
  539. _mtu = mtu;
  540. zt_eod_msg_setmtu req;
  541. req.cmd = ZT_EOD_MSG_SETMTU;
  542. strcpy(req.name, _dev.c_str());
  543. req.mtu = mtu;
  544. unsigned char resp;
  545. eodXchg(req, ZT_EOD_MSG_SETMTURESP, resp);
  546. }
  547. } // namespace ZeroTier