VPN: a WireGuard tunnel (#8)

The device joins a WireGuard network over whatever Wi-Fi it is on: one
peer, IPv4. A client's .conf is imported from the card (/vpn/wg0.conf) and
kept in the device's settings, private key included, never shown; Settings
offers to delete the file. A switch brings the tunnel up until the next
restart, "Start with Wi-Fi" every time; it waits for the clock, which a
handshake needs. VPN shows in the Status Bar.

The protocol is esphome/wireguard 0.4.8. It calls lwIP without lwIP's lock,
which this framework checks: every call into it is made with the lock held.

What goes through the tunnel is everything (AllowedIPs 0.0.0.0/0) or the
one subnet the device's tunnel address is in: lwIP routes by an
interface's subnet or by default, nothing finer. The import says how many
ranges it can't reach.

Checked against a test peer in both directions and against a real server,
with a configuration uploaded from a phone (docs/milestones/N1.md).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-08 01:49:47 +02:00
co-authored by Claude Opus 5.5
parent f0306dd880
commit 4404dd9380
31 changed files with 1309 additions and 12 deletions
+6 -2
View File
@@ -14,6 +14,7 @@
#include "services/clock_service.h"
#include "services/storage_service.h"
#include "apps/debug_console_page.h"
#include "apps/vpn_page.h"
#include "apps/firmware_page.h"
#include "apps/wifi_settings_page.h"
#include "settings_menu.h"
@@ -31,6 +32,7 @@ struct SettingsAppDeps {
WifiService& wifi;
SavedNetworks& savedNetworks;
UpdateService& update;
VpnService& vpn;
};
// Settings: every user-facing setting, plus the Wi-Fi, Firmware, Debug Console and About pages.
@@ -41,7 +43,8 @@ class SettingsApp : public App {
menu_(deps.settings),
wifiPage_(deps.settings, deps.savedNetworks, deps.wifi, deps.bus),
firmwarePage_(deps.update, deps.wifi, deps.storage),
debugPage_(deps.settings, deps.wifi) {}
debugPage_(deps.settings, deps.wifi),
vpnPage_(deps.settings, deps.vpn, deps.storage, deps.clock) {}
void onEnter() override;
bool onKey(const KeyEvent& e) override;
void update(uint32_t nowMs) override;
@@ -55,7 +58,7 @@ class SettingsApp : public App {
bool showsSecret() const override { return page_ == Page::Debug; } // the Debug Console's token
private:
enum class Page { Menu, Text, Choice, About, Wifi, Firmware, Debug };
enum class Page { Menu, Text, Choice, About, Wifi, Firmware, Debug, Vpn };
bool onMenuKey(const KeyEvent& e);
bool onTextKey(const KeyEvent& e);
@@ -69,6 +72,7 @@ class SettingsApp : public App {
WifiSettingsPage wifiPage_;
FirmwarePage firmwarePage_;
DebugConsolePage debugPage_;
VpnPage vpnPage_;
Page page_ = Page::Menu;
ListModel list_{theme::kContent.h / theme::kLineHeight};
ListModel choices_{theme::kContent.h / theme::kLineHeight};