Public Access
VPN: a WireGuard tunnel (#8)
The device joins a WireGuard network over whatever Wi-Fi it is on: one peer, IPv4. A client's .conf is imported from the card (/vpn/wg0.conf) and kept in the device's settings, private key included, never shown; Settings offers to delete the file. A switch brings the tunnel up until the next restart, "Start with Wi-Fi" every time; it waits for the clock, which a handshake needs. VPN shows in the Status Bar. The protocol is esphome/wireguard 0.4.8. It calls lwIP without lwIP's lock, which this framework checks: every call into it is made with the lock held. What goes through the tunnel is everything (AllowedIPs 0.0.0.0/0) or the one subnet the device's tunnel address is in: lwIP routes by an interface's subnet or by default, nothing finer. The import says how many ranges it can't reach. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -52,6 +52,14 @@ void WifiService::ipSettingChanged(const std::string& ssid) {
|
||||
controller_.retryNow(millis());
|
||||
}
|
||||
|
||||
void WifiService::holdDns(bool held) {
|
||||
if (dnsHeld_ == held) return;
|
||||
dnsHeld_ = held;
|
||||
// Whoever held them puts back what it found (DHCP's servers can't be asked for again without
|
||||
// a new lease, which would drop every connection); ours are checked right away.
|
||||
if (!held) applyServers(Why::Check);
|
||||
}
|
||||
|
||||
// DNS and NTP as decided in Q108 and Q110. Run when connected, when a setting changes, and now
|
||||
// and then: a DHCP renewal puts DHCP's DNS back and clears the NTP slots it didn't fill.
|
||||
void WifiService::applyServers(Why why) {
|
||||
@@ -61,7 +69,9 @@ void WifiService::applyServers(Why why) {
|
||||
|
||||
bool wasFromSettings = dnsFromSettings_;
|
||||
dnsFromSettings_ = fixed_ || settings_.getBool(Setting::DnsAlways);
|
||||
if (dnsFromSettings_) {
|
||||
if (dnsHeld_) {
|
||||
// a tunnel's servers are in: see holdDns()
|
||||
} else if (dnsFromSettings_) {
|
||||
IPAddress dns1 = toIp(settings_.getString(Setting::Dns1)), dns2 = toIp(settings_.getString(Setting::Dns2));
|
||||
if (WiFi.dnsIP(0) != dns1 || WiFi.dnsIP(1) != dns2) WiFi.setDNS(dns1, dns2);
|
||||
} else if (why == Why::SettingsChanged && wasFromSettings) {
|
||||
|
||||
Reference in New Issue
Block a user