VPN: a WireGuard tunnel (#8) #87
Merged
twisla
merged 2 commits from 2026-10-07 23:52:09 +00:00
vpn-wireguard into main
No Reviewers
Labels
Clear labels
area/apps
area/audio
area/build
area/cluster
area/gemini
area/gitea
area/gnss
area/ir
area/irc
area/lora
area/ota-debug
area/power
area/scripting
area/ssh
area/storage
area/ui
area/vpn
area/website
area/wifi
concern/memory
concern/security
Launcher and the apps in src/apps
Microphone, speaker, the codec, recording and playback
PlatformIO, Docker, scripts, partitions, sdkconfig
AtomS3 co-processors on Grove and the link protocol
GeminiService, the Gemini App, Saved Pages
The Gitea client: issues, releases, its TLS and its token
GnssService, the GNSS App, Tracks
The infrared LED and the IR Remote
IrcService and the IRC App
The Cap LoRa-1262 radio and the mesh
Updates, Probation, Safe Mode, Debug Console, crash reports
Battery, PowerService, sleep
Lua Apps from the SD card and their API
The SSH client and its terminal
StorageService, the SD card, Storage page
Canvas, widgets, dialogs, Toasts, fonts, keyboard
The WireGuard tunnel
The project website and its docs
WifiService, Wi-Fi Settings, Wi-Fi Tools
May push the heap towards its floors; measure on the device
TLS, signing, the debug token, trust on first use
kind
bug
Something that doesn't work as it should
kind
chore
Refactors, tooling, CI, scripts
kind
docs
README, CONTEXT, milestones, ADRs
kind
feature
Something new the device can do
priority
high
Next up
priority
low
Some day
priority
medium
Soon
status
blocked
Waiting on something else
status
needs-design
Needs a question round (Qnn) before code
status
ready
Designed; can be started
No labels
Milestone
No items
No Milestone
Assignees
twisla (Clément Martin)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: twisla/roro9stack#87
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
For #8: a WireGuard client. One tunnel to one peer, IPv4, over whatever Wi-Fi the device is on.
Using it
.confto the card as/vpn/wg0.conf, then Settings > VPN > Import (orvpn import). The configuration, private key included, is kept in the device and never shown or printed. Settings offers to delete the file.VPNin the Status Bar, bright once the server has answered. Toasts when it comes up and when the server stops answering.vpn status | up [seconds] | down | import [path] | forget | auto on|off.Two things differ from the design round
0.0.0.0/0), or the one subnet the device's tunnel address is in. lwIP routes by an interface's subnet or by default and has no table for more. A home LAN behind the server needs the full tunnel; the import says how many ranges it can't reach.How
esphome/wireguard0.4.8, pinned. It calls lwIP without lwIP's lock, which this build checks (the device stopped on the first try): every call into it is made with the lock held, on our side.lib/net/src/wg_config.h: the.confreader and the routing decision, host-tested.src/services/vpn_service: when the tunnel is up, the allowed ranges, the default route, DNS in and out.Checked
vpn up 100, start with Wi-Fi after a restart, a silenced peer and its return,vpn forget.Not checked
Costs 63 KB of flash, 1.2 KB of static RAM, 1.8 KB of heap while up.
Design, measurements and what went wrong: docs/milestones/N1.md.
🤖 Generated with Claude Code
https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
454e879e60toe00fff670f