Public Access
The device joins a WireGuard network over whatever Wi-Fi it is on: one peer, IPv4. A client's .conf is imported from the card (/vpn/wg0.conf) and kept in the device's settings, private key included, never shown; Settings offers to delete the file. A switch brings the tunnel up until the next restart, "Start with Wi-Fi" every time; it waits for the clock, which a handshake needs. VPN shows in the Status Bar. The protocol is esphome/wireguard 0.4.8. It calls lwIP without lwIP's lock, which this framework checks: every call into it is made with the lock held. What goes through the tunnel is everything (AllowedIPs 0.0.0.0/0) or the one subnet the device's tunnel address is in: lwIP routes by an interface's subnet or by default, nothing finer. The import says how many ranges it can't reach. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
53 lines
1.7 KiB
INI
53 lines
1.7 KiB
INI
; roro9stack — firmware for M5Stack Cardputer ADV + Cap LoRa-1262
|
|
; Build/test/flash through scripts/ci.sh and scripts/flash.sh (Docker), see README.
|
|
|
|
[platformio]
|
|
default_envs = cardputer-adv
|
|
|
|
[env]
|
|
extra_scripts = pre:scripts/version.py
|
|
test_framework = unity
|
|
|
|
[env:cardputer-adv]
|
|
platform = https://github.com/pioarduino/platform-espressif32/releases/download/55.03.312/platform-espressif32.zip
|
|
board = m5stack-stamps3
|
|
framework = arduino
|
|
board_build.partitions = default_8MB.csv
|
|
monitor_speed = 115200
|
|
build_flags =
|
|
-DARDUINO_USB_CDC_ON_BOOT=1
|
|
-DARDUINO_USB_MODE=1
|
|
-DCONFIG_WIREGUARD_MAX_SRC_IPS=4
|
|
lib_deps =
|
|
m5stack/M5Cardputer @ 1.1.1
|
|
jgromes/RadioLib @ 7.8.1
|
|
esphome/wireguard @ 0.4.8
|
|
test_ignore = *
|
|
; Smaller TLS buffers (M2): the framework is rebuilt with these settings (pioarduino "hybrid
|
|
; compile"). Receive stays 16 KB (servers send full TLS records); send drops to 4 KB (IRC lines are
|
|
; short); buffers are allocated as needed and handshake-only data is freed once connected.
|
|
custom_sdkconfig =
|
|
CONFIG_MBEDTLS_ASYMMETRIC_CONTENT_LEN=y
|
|
CONFIG_MBEDTLS_SSL_IN_CONTENT_LEN=16384
|
|
CONFIG_MBEDTLS_SSL_OUT_CONTENT_LEN=4096
|
|
CONFIG_MBEDTLS_DYNAMIC_BUFFER=y
|
|
CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA=y
|
|
CONFIG_MBEDTLS_DYNAMIC_FREE_CA_CERT=y
|
|
|
|
; Host-side unit tests for pure logic (no hardware).
|
|
[env:native]
|
|
platform = native
|
|
lib_ldf_mode = deep+
|
|
build_flags = -std=gnu++17
|
|
|
|
; The same tests, built to count which lines of lib/ they run (scripts/coverage.sh).
|
|
[env:native-coverage]
|
|
extends = env:native
|
|
build_flags =
|
|
${env:native.build_flags}
|
|
--coverage
|
|
-O0
|
|
extra_scripts =
|
|
${env.extra_scripts}
|
|
pre:scripts/coverage_link.py
|