Files
OpenFlux/network
p1neappleXpressandClaude Opus 5.5 b81b52d8c6 logging: three debug levels, -d / -dd / -ddd
0          off: status lines only
    1  -d      packet movement, one line per IPv4 packet:
               -> 52 bytes - UDP 10.10.10.2:53000 -> 8.8.8.8:53 len=42 ttl=64
    2  -dd     plus operational logs (sessions, carriers, crypto, control)
    3  -ddd    plus hexdumps of packets and ciphertext

--debug=N sets the level directly; a bare --debug means -d. Only a run of
d's counts as the counted flag, so -direct-listen=... and other
single-dash long flags starting with d are no longer turned into
--debug. -d=N is accepted too. --sensetive is accepted as --sensitive,
as the previous commit message promised.

utils:
- Packetf logs at level 1, Debugf at level 2, IsVerbose() means level 3;
- the logger is created once and SetOutput swaps its writer, so the
  mobile bridges can flip the level and the output while goroutines of
  the previous connection are logging (from OpenFlux-Android 80fc99d);
- SetLogSink mirrors debug and packet lines to an embedding app, as the
  Android bridge expects; EnableDebug/SetDebug(true) mean level 2, what
  debug meant before levels;
- the unused Redact, Sensitivef and Verbosef are gone.

network.LogPacket is the one place that prints a packet line and, at
level 3, its hexdump. Every packet is logged once per side: the [NIC]
lines duplicated [TUNNEL] and are gone, and the iOS L3 path and
PacketTunnel, which logged nothing, now log too. On both sides "->"
points towards the internet and "<-" back towards the device: the L4
exit used to print them the other way round from L3 and the client, so
one flow now reads the same in both logs.

--sensitive now covers what can reveal a secret:
- key material, as before;
- hexdumps of plaintext frames (crypto plaintext, batch records, control
  messages): control messages carry cookie jars, including an account
  login, so -ddd alone never dumps them. Packet and ciphertext hexdumps
  need only -ddd.
The [KEY] line and the [KEYDUMP] digest no longer print a SHA-256 of the
secret without --sensitive: it let anyone with the log test guesses
without paying for scrypt. The digest keeps the context and derived-key
prefixes, which is enough to compare peers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 19:20:51 +03:00
..
2026-06-18 04:01:27 +03:00