tonarino/innernet
66.4
Adequate · 30 September 2026
10.3k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Innernet is a secure, decentralized virtual private network (VPN) system built on WireGuard that manages peer identities, network topology, and interface configuration. It provides a server for coordinating network state and peer invites, alongside a client library and CLI for establishing and maintaining encrypted tunnels across Linux, Windows, macOS, and OpenBSD. The system handles critical networking tasks such as public IP resolution, NAT traversal, and cross-platform hosts file management to ensure reliable connectivity.
Features
Add RPM build infrastructure with Docker-based packaging
Users can now build RPM packages for the client and server components using a new Docker-based build system. The addition of rpm/Dockerfile and rpm/build-package.sh enables building for specific distributions (e.g., Fedora, AlmaLinux) and architectures (x86\_64, aarch64). The build process installs necessary dependencies like gcc and libselinux-devel, compiles the Rust code with SELinux features enabled, and handles architecture validation to ensure host and target architectures match.
rpm · high confidence
Add shell completion scripts and man pages for innernet-server and innernet
The documentation directory now includes generated man pages (innernet-server.8, innernet.8) and shell completion scripts for Bash, Zsh, Fish, Elvish, and PowerShell for both the server and client binaries. These files provide tab-completion for commands and options, improving the command-line experience for users of innernet-server and innernet.
doc · high confidence
Added device enumeration example for Linux, OpenBSD, and Userspace backends
A new example file (enumerate.rs) demonstrates how to list WireGuard devices using the appropriate backend for the target operating system. On Linux, it uses the Kernel backend; on OpenBSD, it uses the OpenBSD backend; and on other platforms, it falls back to the Userspace backend. This provides users with a concrete reference for integrating device enumeration into their own applications across supported platforms.
wireguard-control/examples · high confidence
Introduce innernet-client-core library
The \innernet-client-core\ library is introduced, providing a reusable API for controlling innernet interfaces. This includes a \RestClient\ for communicating with the server, a \DataStore\ for persisting peer and CIDR data, and functions for redeeming invites, fetching network state, setting listen ports, and creating peers. Example scripts are also added to demonstrate usage for adding CIDRs, adding peers, and setting listen ports.
client-core · high confidence
Introduce netlink-request crate for Linux netlink communication
A new \netlink-request\ library has been added for Linux to handle Netlink socket communication. It provides functions to send generic Netlink (\netlink\_request\_genl\) and routing Netlink (\netlink\_request\_rtnl\) messages, automatically resolving generic family IDs when necessary. The implementation includes a length check to ensure serialized packets do not exceed the maximum buffer size (calculated based on page size or 8KB), and it filters out Done and Ack messages from the returned response list to provide cleaner results to callers.
netlink-request/src · high confidence
New public IP resolution library and CLI tool
A new standalone \publicip\ crate has been introduced to handle public IP address detection for the innernet project. This library resolves both IPv4 and IPv6 addresses by querying the Quad9 DNS resolver (9.9.9.9 and 2620:fe::fe) using raw UDP packets, eliminating external dependencies. It exposes functions to retrieve both addresses or a single address based on user preference, and includes a CLI binary that prints the detected IPv4 and IPv6 addresses (or '?' if unavailable) to standard output.
publicip · high confidence
Removals
Removal of Linux-specific WireGuard system bindings
The \wgctrl-sys\ crate no longer provides the low-level C bindings and build scripts required to interface with the Linux WireGuard kernel module. Specifically, the \build.rs\ script that used \bindgen\ and \cc\ to compile \c/wireguard.c\ and generate Rust bindings, along with the C source files (\wireguard.c\, \wireguard.h\) and the Rust \lib.rs\ that included the generated bindings, have been deleted. This change removes the ability to control WireGuard devices on Linux from this crate.
wgctrl-sys · high confidence
Removal of kernel backend implementation
The kernel backend implementation file (kernel.rs) has been removed from the wgctrl-rs backends directory. This change eliminates the direct Rust code responsible for parsing and encoding WireGuard device and peer information via the kernel interface, likely shifting this responsibility to other backend implementations or the underlying sys crate.
wgctrl-rs/src/backends · high confidence
Removal of public WireGuard configuration and device API modules
The public API for configuring WireGuard interfaces and reading device status has been removed from the \wgctrl-rs\ crate. The \config.rs\ module, which provided the \DeviceConfigBuilder\ for applying settings, and the \device.rs\ module, which defined data structures like \DeviceInfo\, \PeerConfig\, and \PeerInfo\ for querying interface state, are no longer exported. Consequently, users can no longer programmatically build or apply WireGuard configurations or retrieve device information using this library.
wgctrl-rs/src · high confidence
Removed obsolete Debian packaging and installation scripts
The legacy \deb/install.sh\ and \deb/package.sh\ scripts have been removed from the project. These scripts previously handled the manual installation of WireGuard configuration files and the building of Debian packages via \cargo-deb\. Their removal indicates a shift away from this specific manual packaging and deployment workflow.
deb · high confidence
macOS manual installation script removed
The manual macOS installation script (install.sh) has been removed, eliminating the previous method of building the innernet binary via Cargo and installing it to /usr/local/bin along with a LaunchDaemon for the background service. Users can no longer rely on this script for on-device installation and should instead use the newly added Homebrew package for macOS distribution.
macos · high confidence
Architecture
Client logic moved to innernet-client-core library
The client's core logic, including the data store, peer management, and REST client interactions, has been extracted into the new \innernet-client-core\ library. The \client/src\ directory now primarily contains the CLI interface and utility functions, importing the core functionality from the new crate. This refactoring separates the business logic from the command-line interface, making the client code more modular and reusable.
client/src · high confidence
Behavioural changes
Arch Linux packaging moved out of repository
The PKGBUILD and associated .gitignore files for the Arch Linux package have been removed from the repository. This change reflects the migration of the package maintenance to the Arch User Repository (AUR), meaning users can no longer build the package directly from this source tree and must instead fetch it from AUR.
arch · high confidence
Cross-platform hosts file management with safe atomic writes
The hostsfile library now supports writing to the hosts file on Windows (in addition to Unix), automatically detecting the correct path via the WinDir environment variable. It implements a safer write strategy by creating a timestamped temporary file and writing to it, rather than directly overwriting the target, which helps preserve file attributes and prevents data loss. The internal data structure for hostname mappings has been switched from HashMap to BTreeMap to ensure deterministic ordering, and the write methods now return a boolean indicating whether the file was actually modified.
hostsfile/src · high confidence
Enhanced NAT traversal and new server capabilities endpoint
The server now supports more robust NAT hole punching by allowing peers to configure override endpoints with unspecified IP addresses, which the server resolves using the most recent WireGuard endpoint. It also reports these resolved endpoints as connection candidates to peers. Additionally, a new /user/capabilities endpoint has been added to expose server-side feature flags, such as support for unspecified IPs in override endpoints.
server/src/api · high confidence
Improved systemd service restart reliability and lifecycle management
The client's systemd unit configuration has been updated to ensure more robust service management. A new 'innernet.target' has been introduced to allow coordinated restarting and stopping of all innernet components. The client daemon service now explicitly depends on this target via 'PartOf', ensuring it is stopped when the target is deactivated. Additionally, a 'RestartSec=10' delay has been added to prevent rapid restart loops that could trigger systemd's 'StartLimitBurst' protection, ensuring the service remains available even after unexpected exits.
client · high confidence
Linux networking backend migrates to netlink and wireguard-control
On Linux, the shared networking layer now uses the \netlink\ and \netlink-packet-route\ crates to manage WireGuard interfaces, replacing the previous \wgctrl\-based approach. This change introduces a new \netlink.rs\ module that handles interface setup, address assignment, and route management via netlink sockets, while \wireguard-control\ is used explicitly for backend operations. The migration also includes switching the IP address handling library from \ipnetwork\ to \ipnet\ and replacing \lazy\_static\ with \once\_cell\ for static initialization across the shared module.
shared · high confidence
Peer invites expire and associations are validated
The server now enforces expiration on peer invites, rejecting redemption attempts once the specified time has passed, and adds validation to the associations endpoint to prevent duplicate or invalid CIDR pairings. Additionally, the database schema has been updated to support these features, including new columns for invite expiration times and endpoint candidates, with automatic migration handled for existing databases.
server/src/db · high confidence
Release process modernized and CLI renamed to innernet
The release workflow has been overhauled: the old \generate\_manpage.sh\ and \release.toml\ are removed in favor of a new \release.sh\ script that integrates with \cargo-release\, automatically generates shell completions for multiple shells, and produces manpages using \help2man\. Additionally, the command-line interface binary has been renamed from \inn\ to \innernet\, requiring users to update their scripts and documentation to use the new command name (e.g., \sudo innernet install\ instead of \sudo inn install\).
(repo-wide) · high confidence
Server API backend migrated from Warp to Hyper
The server's HTTP handling has been refactored from the Warp framework to the lower-level Hyper library. This change replaces the previous filter-based routing and \warp::Reply\ return types with explicit \hyper::Request\ and \hyper::Response\ handling, introducing a new \util\ module for JSON serialization and status code mapping. The \endpoints.rs\ module, which previously managed WireGuard peer endpoint discovery via a background thread, has been removed in favor of an in-memory \RwLock\ map, and the \AdminSession\ wrapper has been consolidated into the standard \Session\ struct.
server/src · high confidence
Server service restart delay adjusted
The systemd unit for the innernet server now waits 1 second before restarting after a crash, replacing the default 100ms delay. This prevents rapid restart loops and ensures the system has time to stabilize between restart attempts.
server · high confidence
WireGuard control backend migration and OpenBSD support
The wireguard-control library has migrated its Linux backend from the \wireguard-control-sys\ crate to the \netlink\ ecosystem, implementing kernel interface management via netlink messages. Additionally, a new OpenBSD backend has been added, which configures WireGuard interfaces by invoking the system \ifconfig\ command. The userspace backend has also been updated to use the new \InterfaceName\ type and \Device\ model, ensuring consistent API usage across all supported platforms.
wireguard-control/src/backends · high confidence
WireGuard control library restructured with new configuration API and key generation
The \wireguard-control\ crate has been reorganized into a new modular structure (\config.rs\, \device.rs\, \key.rs\) providing a builder-based API for managing WireGuard peers and interfaces. Users can now construct peer configurations using \PeerConfigBuilder\ to set endpoints, allowed IPs, and preshared keys, and apply them via \DeviceUpdate\. The \Key\ type has been reimplemented to support direct generation of private and preshared keys, as well as deriving public keys from private ones using \x25519\_dalek\, replacing the previous backend-specific implementations. The library also introduces \InterfaceName\ for safe interface name handling and exposes \Backend\ variants for Linux, OpenBSD, and userspace backends.
wireguard-control/src · high confidence
Test coverage
Add RPM build specification for innernet-server; Added RPM packaging specification for the client; Initial integration test suite for innernet.
Dependencies
Innernet 2.0: New core library, renamed packages, and dependency upgrades
This release introduces the \innernet-client-core\ library for managing network interfaces and a new \innernet-publicip\ crate for public IP resolution, while renaming the client binary to \innernet\ and the server to \innernet-server\. The project migrates from \structopt\ to \clap 4\, replaces \ipnetwork\ with \ipnet\, and updates the WireGuard control backend to use \netlink\ crates instead of the removed \wgctrl-sys\. Additionally, \rusqlite\ is upgraded to 0.29 with musl static linking support, and the Rust edition is updated to 2021 across all components.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 66 → 66 (-0.1)
- Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 95 → 95 (+0.0)
- Architecture 100 → 93 (-6.5)
- Maturity 55 → 55 (+0.1)
- Readiness 59 → 58 (-0.6)
- Security 88 → 90 (+2.4)
- Performance 100 (new)
Resolved (5)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Hotspot: client-core/src/interface.rs (client-core/src/interface.rs)
- Hotspot: shared/src/types.rs (shared/src/types.rs)
- Off-boarding risk: anonymized user #1
New (20)
- Ambiguous intent: open vs open_or_create. It is unclear if open fails if the store does not exist, or if it creates it. Having both names suggests open might be read-only or strict, while open_or_create is explicit, but the distinction is not immediately obvious from signatures alone and invites misuse.
- Duplicate path construction logic. get_path returns a PathBuf directly, while build_config_file_path returns a Result. It is unclear why one would fail and the other wouldn't, or if they produce different results. This suggests inconsistent error handling for the same logical operation.
- Low cohesion: DeviceUpdate (LCOM4 7) (wireguard-control/src/device.rs)
- Off the main sequence: hostsfile
- Off the main sequence: wireguard-control
- Off-boarding risk: anonymized user #1
- Outdated: anyhow
- Outdated: bytes
- Outdated: clap
- Outdated: clap_complete
- Outdated: ipnet
- Outdated: libc
- Outdated: log
- Outdated: regex
- Outdated: serde
- Outdated: serde_json
- Outdated: thiserror
- Outdated: tokio
- Public API exposes a private/internal method _get_local_addrs alongside a public get_local_addrs. The underscore prefix usually denotes private, but it is in the public type list, suggesting it might be accidentally exposed or intended for internal use only but leaked.
- Redundant save operations with different signatures. save_new takes a specific path and mode, while save takes a config dir and interface name to derive the path. This splits the 'save' responsibility between explicit path control and implicit path derivation without a clear naming convention (e.g., save_to vs save).
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tonarino/innernet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1ba6154b6ebacd68dfe79c3a4f6273fd3e8dea35 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-505904ce13c1.