This is an example of a DNS proxy provider network extension, written in rust, and managed by another rust program.
You need rust and make. Running make will compile the rust programs, assemble them into a
systemextension bundle inside an app bundle, and self-sign them.
In order to run the network extension without involving Apple, you will need to break the shackles on your system. Here's what worked for me, and I'll only recommend doing this in a VM:
Disable System Integrity Protection
- Boot into recovery mode.
tart run --recovery <vm>
- Go to Utilities -> Terminal
- Disable SIP, by running
csrutil disable - You may also need to run one of these commands:
- Either
-
nvram boot-args="amfi_get_out_of_my_way=0x1" - ...or
-
bputil --disable-boot-args-restriction-nvram 40A0DDD2-77F8-4392-B4A3-1E7304206516:boot-args='amfi=0x80'
- Either
-
reboot- Run
csrutil status, verify that SIP is disabled.
Enable system extension developer mode
systemextensionsctl developer on
Some useful links to various pieces of documentation.