Skip to content
CAI
Software that uses CAICheck a score

tonarino/innernet

66.4

Adequate · 30 September 2026

10.3k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Innernet is a secure, decentralized virtual private network (VPN) system built on WireGuard that manages peer identities, network topology, and interface configuration. It provides a server for coordinating network state and peer invites, alongside a client library and CLI for establishing and maintaining encrypted tunnels across Linux, Windows, macOS, and OpenBSD. The system handles critical networking tasks such as public IP resolution, NAT traversal, and cross-platform hosts file management to ensure reliable connectivity.

Features

Add RPM build infrastructure with Docker-based packaging

Users can now build RPM packages for the client and server components using a new Docker-based build system. The addition of rpm/Dockerfile and rpm/build-package.sh enables building for specific distributions (e.g., Fedora, AlmaLinux) and architectures (x86\_64, aarch64). The build process installs necessary dependencies like gcc and libselinux-devel, compiles the Rust code with SELinux features enabled, and handles architecture validation to ensure host and target architectures match.

rpm · high confidence

Add shell completion scripts and man pages for innernet-server and innernet

The documentation directory now includes generated man pages (innernet-server.8, innernet.8) and shell completion scripts for Bash, Zsh, Fish, Elvish, and PowerShell for both the server and client binaries. These files provide tab-completion for commands and options, improving the command-line experience for users of innernet-server and innernet.

doc · high confidence

Added device enumeration example for Linux, OpenBSD, and Userspace backends

A new example file (enumerate.rs) demonstrates how to list WireGuard devices using the appropriate backend for the target operating system. On Linux, it uses the Kernel backend; on OpenBSD, it uses the OpenBSD backend; and on other platforms, it falls back to the Userspace backend. This provides users with a concrete reference for integrating device enumeration into their own applications across supported platforms.

wireguard-control/examples · high confidence

Introduce innernet-client-core library

The \innernet-client-core\ library is introduced, providing a reusable API for controlling innernet interfaces. This includes a \RestClient\ for communicating with the server, a \DataStore\ for persisting peer and CIDR data, and functions for redeeming invites, fetching network state, setting listen ports, and creating peers. Example scripts are also added to demonstrate usage for adding CIDRs, adding peers, and setting listen ports.

client-core · high confidence

A new \netlink-request\ library has been added for Linux to handle Netlink socket communication. It provides functions to send generic Netlink (\netlink\_request\_genl\) and routing Netlink (\netlink\_request\_rtnl\) messages, automatically resolving generic family IDs when necessary. The implementation includes a length check to ensure serialized packets do not exceed the maximum buffer size (calculated based on page size or 8KB), and it filters out Done and Ack messages from the returned response list to provide cleaner results to callers.

netlink-request/src · high confidence

New public IP resolution library and CLI tool

A new standalone \publicip\ crate has been introduced to handle public IP address detection for the innernet project. This library resolves both IPv4 and IPv6 addresses by querying the Quad9 DNS resolver (9.9.9.9 and 2620:fe::fe) using raw UDP packets, eliminating external dependencies. It exposes functions to retrieve both addresses or a single address based on user preference, and includes a CLI binary that prints the detected IPv4 and IPv6 addresses (or '?' if unavailable) to standard output.

publicip · high confidence

Removals

Removal of Linux-specific WireGuard system bindings

The \wgctrl-sys\ crate no longer provides the low-level C bindings and build scripts required to interface with the Linux WireGuard kernel module. Specifically, the \build.rs\ script that used \bindgen\ and \cc\ to compile \c/wireguard.c\ and generate Rust bindings, along with the C source files (\wireguard.c\, \wireguard.h\) and the Rust \lib.rs\ that included the generated bindings, have been deleted. This change removes the ability to control WireGuard devices on Linux from this crate.

wgctrl-sys · high confidence

Removal of kernel backend implementation

The kernel backend implementation file (kernel.rs) has been removed from the wgctrl-rs backends directory. This change eliminates the direct Rust code responsible for parsing and encoding WireGuard device and peer information via the kernel interface, likely shifting this responsibility to other backend implementations or the underlying sys crate.

wgctrl-rs/src/backends · high confidence

Removal of public WireGuard configuration and device API modules

The public API for configuring WireGuard interfaces and reading device status has been removed from the \wgctrl-rs\ crate. The \config.rs\ module, which provided the \DeviceConfigBuilder\ for applying settings, and the \device.rs\ module, which defined data structures like \DeviceInfo\, \PeerConfig\, and \PeerInfo\ for querying interface state, are no longer exported. Consequently, users can no longer programmatically build or apply WireGuard configurations or retrieve device information using this library.

wgctrl-rs/src · high confidence

Removed obsolete Debian packaging and installation scripts

The legacy \deb/install.sh\ and \deb/package.sh\ scripts have been removed from the project. These scripts previously handled the manual installation of WireGuard configuration files and the building of Debian packages via \cargo-deb\. Their removal indicates a shift away from this specific manual packaging and deployment workflow.

deb · high confidence

macOS manual installation script removed

The manual macOS installation script (install.sh) has been removed, eliminating the previous method of building the innernet binary via Cargo and installing it to /usr/local/bin along with a LaunchDaemon for the background service. Users can no longer rely on this script for on-device installation and should instead use the newly added Homebrew package for macOS distribution.

macos · high confidence

Architecture

Client logic moved to innernet-client-core library

The client's core logic, including the data store, peer management, and REST client interactions, has been extracted into the new \innernet-client-core\ library. The \client/src\ directory now primarily contains the CLI interface and utility functions, importing the core functionality from the new crate. This refactoring separates the business logic from the command-line interface, making the client code more modular and reusable.

client/src · high confidence

Behavioural changes

Arch Linux packaging moved out of repository

The PKGBUILD and associated .gitignore files for the Arch Linux package have been removed from the repository. This change reflects the migration of the package maintenance to the Arch User Repository (AUR), meaning users can no longer build the package directly from this source tree and must instead fetch it from AUR.

arch · high confidence

Cross-platform hosts file management with safe atomic writes

The hostsfile library now supports writing to the hosts file on Windows (in addition to Unix), automatically detecting the correct path via the WinDir environment variable. It implements a safer write strategy by creating a timestamped temporary file and writing to it, rather than directly overwriting the target, which helps preserve file attributes and prevents data loss. The internal data structure for hostname mappings has been switched from HashMap to BTreeMap to ensure deterministic ordering, and the write methods now return a boolean indicating whether the file was actually modified.

hostsfile/src · high confidence

Enhanced NAT traversal and new server capabilities endpoint

The server now supports more robust NAT hole punching by allowing peers to configure override endpoints with unspecified IP addresses, which the server resolves using the most recent WireGuard endpoint. It also reports these resolved endpoints as connection candidates to peers. Additionally, a new /user/capabilities endpoint has been added to expose server-side feature flags, such as support for unspecified IPs in override endpoints.

server/src/api · high confidence

Improved systemd service restart reliability and lifecycle management

The client's systemd unit configuration has been updated to ensure more robust service management. A new 'innernet.target' has been introduced to allow coordinated restarting and stopping of all innernet components. The client daemon service now explicitly depends on this target via 'PartOf', ensuring it is stopped when the target is deactivated. Additionally, a 'RestartSec=10' delay has been added to prevent rapid restart loops that could trigger systemd's 'StartLimitBurst' protection, ensuring the service remains available even after unexpected exits.

client · high confidence

On Linux, the shared networking layer now uses the \netlink\ and \netlink-packet-route\ crates to manage WireGuard interfaces, replacing the previous \wgctrl\-based approach. This change introduces a new \netlink.rs\ module that handles interface setup, address assignment, and route management via netlink sockets, while \wireguard-control\ is used explicitly for backend operations. The migration also includes switching the IP address handling library from \ipnetwork\ to \ipnet\ and replacing \lazy\_static\ with \once\_cell\ for static initialization across the shared module.

shared · high confidence

Peer invites expire and associations are validated

The server now enforces expiration on peer invites, rejecting redemption attempts once the specified time has passed, and adds validation to the associations endpoint to prevent duplicate or invalid CIDR pairings. Additionally, the database schema has been updated to support these features, including new columns for invite expiration times and endpoint candidates, with automatic migration handled for existing databases.

server/src/db · high confidence

Release process modernized and CLI renamed to innernet

The release workflow has been overhauled: the old \generate\_manpage.sh\ and \release.toml\ are removed in favor of a new \release.sh\ script that integrates with \cargo-release\, automatically generates shell completions for multiple shells, and produces manpages using \help2man\. Additionally, the command-line interface binary has been renamed from \inn\ to \innernet\, requiring users to update their scripts and documentation to use the new command name (e.g., \sudo innernet install\ instead of \sudo inn install\).

(repo-wide) · high confidence

Server API backend migrated from Warp to Hyper

The server's HTTP handling has been refactored from the Warp framework to the lower-level Hyper library. This change replaces the previous filter-based routing and \warp::Reply\ return types with explicit \hyper::Request\ and \hyper::Response\ handling, introducing a new \util\ module for JSON serialization and status code mapping. The \endpoints.rs\ module, which previously managed WireGuard peer endpoint discovery via a background thread, has been removed in favor of an in-memory \RwLock\ map, and the \AdminSession\ wrapper has been consolidated into the standard \Session\ struct.

server/src · high confidence

Server service restart delay adjusted

The systemd unit for the innernet server now waits 1 second before restarting after a crash, replacing the default 100ms delay. This prevents rapid restart loops and ensures the system has time to stabilize between restart attempts.

server · high confidence

WireGuard control backend migration and OpenBSD support

The wireguard-control library has migrated its Linux backend from the \wireguard-control-sys\ crate to the \netlink\ ecosystem, implementing kernel interface management via netlink messages. Additionally, a new OpenBSD backend has been added, which configures WireGuard interfaces by invoking the system \ifconfig\ command. The userspace backend has also been updated to use the new \InterfaceName\ type and \Device\ model, ensuring consistent API usage across all supported platforms.

wireguard-control/src/backends · high confidence

WireGuard control library restructured with new configuration API and key generation

The \wireguard-control\ crate has been reorganized into a new modular structure (\config.rs\, \device.rs\, \key.rs\) providing a builder-based API for managing WireGuard peers and interfaces. Users can now construct peer configurations using \PeerConfigBuilder\ to set endpoints, allowed IPs, and preshared keys, and apply them via \DeviceUpdate\. The \Key\ type has been reimplemented to support direct generation of private and preshared keys, as well as deriving public keys from private ones using \x25519\_dalek\, replacing the previous backend-specific implementations. The library also introduces \InterfaceName\ for safe interface name handling and exposes \Backend\ variants for Linux, OpenBSD, and userspace backends.

wireguard-control/src · high confidence

Test coverage

Add RPM build specification for innernet-server; Added RPM packaging specification for the client; Initial integration test suite for innernet.

Dependencies

Innernet 2.0: New core library, renamed packages, and dependency upgrades

This release introduces the \innernet-client-core\ library for managing network interfaces and a new \innernet-publicip\ crate for public IP resolution, while renaming the client binary to \innernet\ and the server to \innernet-server\. The project migrates from \structopt\ to \clap 4\, replaces \ipnetwork\ with \ipnet\, and updates the WireGuard control backend to use \netlink\ crates instead of the removed \wgctrl-sys\. Additionally, \rusqlite\ is upgraded to 0.29 with musl static linking support, and the Rust edition is updated to 2021 across all components.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 66 → 66 (-0.1)
  • Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 95 → 95 (+0.0)
  • Architecture 100 → 93 (-6.5)
  • Maturity 55 → 55 (+0.1)
  • Readiness 59 → 58 (-0.6)
  • Security 88 → 90 (+2.4)
  • Performance 100 (new)

Resolved (5)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Hotspot: client-core/src/interface.rs (client-core/src/interface.rs)
  • Hotspot: shared/src/types.rs (shared/src/types.rs)
  • Off-boarding risk: anonymized user #1

New (20)

  • Ambiguous intent: open vs open_or_create. It is unclear if open fails if the store does not exist, or if it creates it. Having both names suggests open might be read-only or strict, while open_or_create is explicit, but the distinction is not immediately obvious from signatures alone and invites misuse.
  • Duplicate path construction logic. get_path returns a PathBuf directly, while build_config_file_path returns a Result. It is unclear why one would fail and the other wouldn't, or if they produce different results. This suggests inconsistent error handling for the same logical operation.
  • Low cohesion: DeviceUpdate (LCOM4 7) (wireguard-control/src/device.rs)
  • Off the main sequence: hostsfile
  • Off the main sequence: wireguard-control
  • Off-boarding risk: anonymized user #1
  • Outdated: anyhow
  • Outdated: bytes
  • Outdated: clap
  • Outdated: clap_complete
  • Outdated: ipnet
  • Outdated: libc
  • Outdated: log
  • Outdated: regex
  • Outdated: serde
  • Outdated: serde_json
  • Outdated: thiserror
  • Outdated: tokio
  • Public API exposes a private/internal method _get_local_addrs alongside a public get_local_addrs. The underscore prefix usually denotes private, but it is in the public type list, suggesting it might be accidentally exposed or intended for internal use only but leaked.
  • Redundant save operations with different signatures. save_new takes a specific path and mode, while save takes a config dir and interface name to derive the path. This splits the 'save' responsibility between explicit path control and implicit path derivation without a clear naming convention (e.g., save_to vs save).

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tonarino/innernet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1ba6154b6ebacd68dfe79c3a4f6273fd3e8dea35 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-505904ce13c1.