This is important because I support each release of the distribution for up to 10 years, and have some customers who may need to build it in an air-gapped environment.
[0] https://chiselapp.com/user/rkeene/repository/bash-drop-netwo...
This is important because I support each release of the distribution for up to 10 years, and have some customers who may need to build it in an air-gapped environment.
[0] https://chiselapp.com/user/rkeene/repository/bash-drop-netwo...
Personally, I just run things in network namespaces with "ip netns exec offline|wireguard $COMMAND" to restrict net access.
I thought about using a network namespace, but that would make things more complicated since I would need to re-call my shell script to pick-up where I left off (because it requires creating a new process). I initially tried to implement this using network namespaces, but you cannot "unshare" the current process, you must spawn a new process.
With dropnet I can do
download()
enable -f ./dropnet.so dropnet
configure()
build()
install()
With "unshare" I would need to do more work to get to "configure()" in a new process.