Public Access
VPN: a WireGuard tunnel (#8)
The device joins a WireGuard network over whatever Wi-Fi it is on: one peer, IPv4. A client's .conf is imported from the card (/vpn/wg0.conf) and kept in the device's settings, private key included, never shown; Settings offers to delete the file. A switch brings the tunnel up until the next restart, "Start with Wi-Fi" every time; it waits for the clock, which a handshake needs. VPN shows in the Status Bar. The protocol is esphome/wireguard 0.4.8. It calls lwIP without lwIP's lock, which this framework checks: every call into it is made with the lock held. What goes through the tunnel is everything (AllowedIPs 0.0.0.0/0) or the one subnet the device's tunnel address is in: lwIP routes by an interface's subnet or by default, nothing finer. The import says how many ranges it can't reach. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -35,6 +35,9 @@ bool SettingsApp::onKey(const KeyEvent& e) {
|
||||
case Page::Firmware:
|
||||
if (!firmwarePage_.onKey(e)) page_ = Page::Menu;
|
||||
return true;
|
||||
case Page::Vpn:
|
||||
if (!vpnPage_.onKey(e)) page_ = Page::Menu;
|
||||
return true;
|
||||
case Page::Debug:
|
||||
if (!debugPage_.onKey(e)) page_ = Page::Menu;
|
||||
return true;
|
||||
@@ -79,6 +82,10 @@ bool SettingsApp::onMenuKey(const KeyEvent& e) {
|
||||
page_ = Page::Firmware;
|
||||
firmwarePage_.enter();
|
||||
break;
|
||||
case Row::Vpn:
|
||||
page_ = Page::Vpn;
|
||||
vpnPage_.enter();
|
||||
break;
|
||||
case Row::DebugConsole:
|
||||
page_ = Page::Debug;
|
||||
debugPage_.enter();
|
||||
@@ -139,6 +146,7 @@ void SettingsApp::help(std::vector<KeyHelp>& out) const {
|
||||
case Page::Wifi: wifiPage_.help(out); break;
|
||||
case Page::Firmware: firmwarePage_.help(out); break;
|
||||
case Page::Debug: debugPage_.help(out); break;
|
||||
case Page::Vpn: vpnPage_.help(out); break;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -147,6 +155,7 @@ const char* SettingsApp::helpTitle() const {
|
||||
case Page::Wifi: return wifiPage_.helpTitle();
|
||||
case Page::Firmware: return firmwarePage_.helpTitle();
|
||||
case Page::Debug: return debugPage_.helpTitle();
|
||||
case Page::Vpn: return "VPN";
|
||||
case Page::About: return "About";
|
||||
default: return nullptr;
|
||||
}
|
||||
@@ -154,7 +163,7 @@ const char* SettingsApp::helpTitle() const {
|
||||
|
||||
void SettingsApp::update(uint32_t nowMs) {
|
||||
// Live values on About and Firmware.
|
||||
bool live = page_ == Page::About || page_ == Page::Firmware || page_ == Page::Debug ||
|
||||
bool live = page_ == Page::About || page_ == Page::Firmware || page_ == Page::Debug || page_ == Page::Vpn ||
|
||||
(page_ == Page::Wifi && wifiPage_.live());
|
||||
if (live && nowMs - lastRefreshMs_ >= 500) {
|
||||
lastRefreshMs_ = nowMs;
|
||||
@@ -213,6 +222,7 @@ void SettingsApp::draw(Canvas& c) {
|
||||
case Page::Wifi: wifiPage_.draw(c); break;
|
||||
case Page::Firmware: firmwarePage_.draw(c); break;
|
||||
case Page::Debug: debugPage_.draw(c); break;
|
||||
case Page::Vpn: vpnPage_.draw(c); break;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -14,6 +14,7 @@
|
||||
#include "services/clock_service.h"
|
||||
#include "services/storage_service.h"
|
||||
#include "apps/debug_console_page.h"
|
||||
#include "apps/vpn_page.h"
|
||||
#include "apps/firmware_page.h"
|
||||
#include "apps/wifi_settings_page.h"
|
||||
#include "settings_menu.h"
|
||||
@@ -31,6 +32,7 @@ struct SettingsAppDeps {
|
||||
WifiService& wifi;
|
||||
SavedNetworks& savedNetworks;
|
||||
UpdateService& update;
|
||||
VpnService& vpn;
|
||||
};
|
||||
|
||||
// Settings: every user-facing setting, plus the Wi-Fi, Firmware, Debug Console and About pages.
|
||||
@@ -41,7 +43,8 @@ class SettingsApp : public App {
|
||||
menu_(deps.settings),
|
||||
wifiPage_(deps.settings, deps.savedNetworks, deps.wifi, deps.bus),
|
||||
firmwarePage_(deps.update, deps.wifi, deps.storage),
|
||||
debugPage_(deps.settings, deps.wifi) {}
|
||||
debugPage_(deps.settings, deps.wifi),
|
||||
vpnPage_(deps.settings, deps.vpn, deps.storage, deps.clock) {}
|
||||
void onEnter() override;
|
||||
bool onKey(const KeyEvent& e) override;
|
||||
void update(uint32_t nowMs) override;
|
||||
@@ -55,7 +58,7 @@ class SettingsApp : public App {
|
||||
bool showsSecret() const override { return page_ == Page::Debug; } // the Debug Console's token
|
||||
|
||||
private:
|
||||
enum class Page { Menu, Text, Choice, About, Wifi, Firmware, Debug };
|
||||
enum class Page { Menu, Text, Choice, About, Wifi, Firmware, Debug, Vpn };
|
||||
|
||||
bool onMenuKey(const KeyEvent& e);
|
||||
bool onTextKey(const KeyEvent& e);
|
||||
@@ -69,6 +72,7 @@ class SettingsApp : public App {
|
||||
WifiSettingsPage wifiPage_;
|
||||
FirmwarePage firmwarePage_;
|
||||
DebugConsolePage debugPage_;
|
||||
VpnPage vpnPage_;
|
||||
Page page_ = Page::Menu;
|
||||
ListModel list_{theme::kContent.h / theme::kLineHeight};
|
||||
ListModel choices_{theme::kContent.h / theme::kLineHeight};
|
||||
|
||||
@@ -0,0 +1,133 @@
|
||||
#include "apps/vpn_page.h"
|
||||
|
||||
#include <SD.h>
|
||||
|
||||
#include "app_keys.h"
|
||||
#include "ipv4.h"
|
||||
#include "ui/fonts.h"
|
||||
#include "ui/theme.h"
|
||||
#include "ui/widgets.h"
|
||||
|
||||
namespace roro {
|
||||
|
||||
void VpnPage::enter() {
|
||||
list_.setCount(kRows);
|
||||
confirm_.reset();
|
||||
message_.clear();
|
||||
}
|
||||
|
||||
bool VpnPage::onKey(const KeyEvent& e) {
|
||||
if (confirm_) {
|
||||
confirm_->onKey(e);
|
||||
int result = confirm_->result();
|
||||
if (result == DialogModel::kPending) return true;
|
||||
Ask asked = ask_;
|
||||
ask_ = Ask::None;
|
||||
confirm_.reset();
|
||||
if (result == 1 && asked == Ask::DeleteFile) {
|
||||
storage_.runJob([]() { SD.remove(kConfPath); });
|
||||
message_ = "Imported, and the file is deleted";
|
||||
} else if (result == 1 && asked == Ask::Forget) {
|
||||
vpn_.forget();
|
||||
message_ = "Forgotten";
|
||||
}
|
||||
return true;
|
||||
}
|
||||
switch (e.key) {
|
||||
case Key::Up: list_.up(); break;
|
||||
case Key::Down: list_.down(); break;
|
||||
case Key::Back: return false;
|
||||
case Key::Left:
|
||||
case Key::Right:
|
||||
case Key::Select:
|
||||
if (e.key != Key::Select && list_.selected() > kAuto) break;
|
||||
message_.clear();
|
||||
switch (list_.selected()) {
|
||||
case kSwitch:
|
||||
if (!vpn_.configured()) message_ = "Import a .conf first";
|
||||
else vpn_.want(!vpn_.wanted());
|
||||
break;
|
||||
case kAuto:
|
||||
if (!vpn_.configured()) message_ = "Import a .conf first";
|
||||
else settings_.setBool(Setting::VpnAuto, !settings_.getBool(Setting::VpnAuto));
|
||||
break;
|
||||
case kImport: {
|
||||
std::string why = vpn_.importFile(storage_, kConfPath);
|
||||
if (!why.empty()) {
|
||||
message_ = why;
|
||||
break;
|
||||
}
|
||||
message_ = "Imported";
|
||||
ask_ = Ask::DeleteFile; // the card can be taken out, and the key is in that file
|
||||
confirm_.reset(new DialogModel({"Keep it", "Delete it"}));
|
||||
break;
|
||||
}
|
||||
case kForget:
|
||||
if (!vpn_.configured()) break;
|
||||
ask_ = Ask::Forget;
|
||||
confirm_.reset(new DialogModel({"Cancel", "Forget"}));
|
||||
break;
|
||||
default: break;
|
||||
}
|
||||
break;
|
||||
default: break;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
void VpnPage::help(std::vector<KeyHelp>& out) const {
|
||||
if (confirm_) return keys::add(out, keys::kDialog);
|
||||
keys::add(out, keys::kVpn);
|
||||
}
|
||||
|
||||
void VpnPage::draw(Canvas& c) {
|
||||
const auto& area = theme::kContent;
|
||||
c.setTextDatum(top_left);
|
||||
bool set = vpn_.configured();
|
||||
widgets::list(
|
||||
c, list_, {area.x, area.y, area.w, kRows * theme::kLineHeight},
|
||||
[](int i) -> std::string {
|
||||
switch (i) {
|
||||
case kSwitch: return "VPN";
|
||||
case kAuto: return "Start with Wi-Fi";
|
||||
case kImport: return "Import /vpn/wg0.conf";
|
||||
default: return "Forget it";
|
||||
}
|
||||
},
|
||||
[&](int i) -> std::string {
|
||||
switch (i) {
|
||||
case kSwitch: return !set ? "Not set" : vpn_.wanted() ? "On" : "Off";
|
||||
case kAuto: return settings_.getBool(Setting::VpnAuto) ? "On" : "Off";
|
||||
default: return "";
|
||||
}
|
||||
});
|
||||
|
||||
int y = area.y + kRows * theme::kLineHeight + 4;
|
||||
c.setFont(&fonts::small);
|
||||
auto line = [&](const std::string& text, uint16_t colour) {
|
||||
c.setTextColor(colour);
|
||||
c.drawString(text.c_str(), 4, y);
|
||||
y += 10;
|
||||
};
|
||||
if (set) {
|
||||
const net::WgConfig& k = vpn_.config();
|
||||
std::string state = std::string("It is ") + vpn_.stateText();
|
||||
int64_t now = clock_.utcNow(), last = vpn_.lastHandshake();
|
||||
if (vpn_.state() == VpnService::State::Up && now >= 0 && last > 0 && now >= last) state += ", heard " + std::to_string(now - last) + " s ago";
|
||||
line(state, vpn_.state() == VpnService::State::Up ? theme::kAccent : theme::kText);
|
||||
line("Server " + k.endpointHost + ":" + std::to_string(k.endpointPort), theme::kMuted);
|
||||
line("This device " + net::formatIpv4(k.address) + ", through it " + net::describeWgRouting(k), theme::kMuted);
|
||||
} else {
|
||||
line("Copy a WireGuard .conf to the card as", theme::kMuted);
|
||||
line(std::string(kConfPath) + ", then import it.", theme::kMuted);
|
||||
}
|
||||
if (!message_.empty()) line(message_, theme::kWarning);
|
||||
else if (!vpn_.lastError().empty()) line(vpn_.lastError(), theme::kWarning);
|
||||
|
||||
if (confirm_ && ask_ == Ask::DeleteFile)
|
||||
widgets::dialog(c, "Delete the file?", "It is stored in the device now. The file on the card still holds the private key.", *confirm_);
|
||||
else if (confirm_)
|
||||
widgets::dialog(c, "Forget the VPN?", "The tunnel stops and its keys are erased from the device.", *confirm_);
|
||||
}
|
||||
|
||||
} // namespace roro
|
||||
@@ -0,0 +1,47 @@
|
||||
#pragma once
|
||||
|
||||
#include <memory>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
#include "dialog_model.h"
|
||||
#include "key_event.h"
|
||||
#include "key_help.h"
|
||||
#include "list_model.h"
|
||||
#include "services/clock_service.h"
|
||||
#include "services/storage_service.h"
|
||||
#include "services/vpn_service.h"
|
||||
#include "settings.h"
|
||||
#include "ui/canvas.h"
|
||||
|
||||
namespace roro {
|
||||
|
||||
// Settings > VPN (issue #8): the switch, "Start with Wi-Fi", importing a `.conf` from the card
|
||||
// and forgetting it, and what the tunnel is doing. No key is ever on this page.
|
||||
class VpnPage {
|
||||
public:
|
||||
static constexpr const char* kConfPath = "/vpn/wg0.conf";
|
||||
|
||||
VpnPage(Settings& settings, VpnService& vpn, StorageService& storage, ClockService& clock)
|
||||
: settings_(settings), vpn_(vpn), storage_(storage), clock_(clock) {}
|
||||
|
||||
void enter();
|
||||
bool onKey(const KeyEvent& e); // false: leave the page
|
||||
void draw(Canvas& c);
|
||||
void help(std::vector<KeyHelp>& out) const;
|
||||
|
||||
private:
|
||||
enum Row { kSwitch, kAuto, kImport, kForget, kRows };
|
||||
enum class Ask { None, DeleteFile, Forget };
|
||||
|
||||
Settings& settings_;
|
||||
VpnService& vpn_;
|
||||
StorageService& storage_;
|
||||
ClockService& clock_;
|
||||
ListModel list_{kRows};
|
||||
std::unique_ptr<DialogModel> confirm_;
|
||||
Ask ask_ = Ask::None;
|
||||
std::string message_;
|
||||
};
|
||||
|
||||
} // namespace roro
|
||||
Reference in New Issue
Block a user