Public Access
VPN: a WireGuard tunnel (#8)
The device joins a WireGuard network over whatever Wi-Fi it is on: one peer, IPv4. A client's .conf is imported from the card (/vpn/wg0.conf) and kept in the device's settings, private key included, never shown; Settings offers to delete the file. A switch brings the tunnel up until the next restart, "Start with Wi-Fi" every time; it waits for the clock, which a handshake needs. VPN shows in the Status Bar. The protocol is esphome/wireguard 0.4.8. It calls lwIP without lwIP's lock, which this framework checks: every call into it is made with the lock held. What goes through the tunnel is everything (AllowedIPs 0.0.0.0/0) or the one subnet the device's tunnel address is in: lwIP routes by an interface's subnet or by default, nothing finer. The import says how many ranges it can't reach. Checked against a test peer in both directions and against a real server, with a configuration uploaded from a phone (docs/milestones/N1.md). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -56,6 +56,8 @@ class WifiService : public Service {
|
||||
void ipSettingChanged(const std::string& ssid);
|
||||
// The DNS or NTP settings changed: use them now.
|
||||
void serversChanged() { applyServers(Why::SettingsChanged); }
|
||||
// While a tunnel has put its own DNS servers in (issue #8), ours are not put back over them.
|
||||
void holdDns(bool held);
|
||||
// The noise self-test switches the radio off for a few seconds. Not saved anywhere: a restart
|
||||
// during the test brings Wi-Fi back, which a changed setting wouldn't.
|
||||
void debugPause(bool paused) { paused_ = paused; }
|
||||
@@ -89,6 +91,7 @@ class WifiService : public Service {
|
||||
bool paused_ = false; // Debug Builds: off for a moment, whatever the setting says
|
||||
bool fixed_ = false; // the network in use has a Fixed address
|
||||
bool dnsFromSettings_ = false;
|
||||
bool dnsHeld_ = false;
|
||||
std::string ntpNames_[2]; // lwIP keeps the pointers, so the names live here
|
||||
uint32_t serversCheckedMs_ = 0;
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user