WireGuard conf knowledge consolidates into the wireguard module #187

Closed
opened 2026-08-28 01:19:50 -04:00 by mysticalsoap · 1 comment
Owner

WireGuard conf-format knowledge is currently spread over four files:

  • providers/custom.py mini-parses Endpoint = during import to build the server list
  • providers/mullvad.py generates the template conf by hand
  • tunnel.py completes it with conf.insert(8/9, ...) line-index surgery (currently lands past the list end and appends — correct by accident)
  • aqomui/wireguard.py (#186) parses the result at bring-up and teardown

Decision (from the #152 design discussion): the wireguard module owns the format end to end, as module-level codec functions — parse_conf (exists) plus a generate_conf(fields) that builds [Interface]/[Peer] sections from data. Module functions, not protocol-class methods: providers need the codec at import time with no tunnel in existence. The protocol class (planned after #186) owns lifecycle only and calls the same codec.

Explicitly ruled out: config.py — it is the app-settings leaf that imports nothing and knows no protocols; .ovpn handling never lived there either. The conf format itself stays the wg(8)-plus-wg-quick-extensions interchange format every provider exports; aqomui treats it as data describing a tunnel, never as instructions (Table and the PreUp/PostUp hook keys stay stripped and inert — #186 closed the root-execution hazard of passing imported confs to wg-quick).

Work items:

  1. wireguard.generate_conf(fields); Mullvad path builds its conf through it (index surgery retired)
  2. custom.py endpoint extraction calls wireguard.parse_conf instead of its own regex
  3. Native Proton WG generation (#152 step 4) targets the same generator

Rides on the protocol-seam branch rather than standing alone — the class extraction touches the same call sites.

🤖 Generated with Claude Code

WireGuard conf-format knowledge is currently spread over four files: - `providers/custom.py` mini-parses `Endpoint =` during import to build the server list - `providers/mullvad.py` generates the template conf by hand - `tunnel.py` completes it with `conf.insert(8/9, ...)` line-index surgery (currently lands past the list end and appends — correct by accident) - `aqomui/wireguard.py` (#186) parses the result at bring-up and teardown Decision (from the #152 design discussion): the **wireguard module** owns the format end to end, as module-level codec functions — `parse_conf` (exists) plus a `generate_conf(fields)` that builds `[Interface]`/`[Peer]` sections from data. Module functions, not protocol-class methods: providers need the codec at import time with no tunnel in existence. The protocol class (planned after #186) owns lifecycle only and calls the same codec. Explicitly ruled out: `config.py` — it is the app-settings leaf that imports nothing and knows no protocols; `.ovpn` handling never lived there either. The conf format itself stays the wg(8)-plus-wg-quick-extensions interchange format every provider exports; aqomui treats it as data describing a tunnel, never as instructions (Table and the PreUp/PostUp hook keys stay stripped and inert — #186 closed the root-execution hazard of passing imported confs to wg-quick). Work items: 1. `wireguard.generate_conf(fields)`; Mullvad path builds its conf through it (index surgery retired) 2. `custom.py` endpoint extraction calls `wireguard.parse_conf` instead of its own regex 3. Native Proton WG generation (#152 step 4) targets the same generator Rides on the protocol-seam branch rather than standing alone — the class extraction touches the same call sites. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Author
Owner

Implemented in PR #189 (second commit) alongside the protocol seam: parse_conf/generate_conf as inverses, setconf input always generated, Mullvad completion anchored to the [Peer] section, custom.py endpoint split through the codec helper. Close when #189 merges.

Implemented in PR #189 (second commit) alongside the protocol seam: parse_conf/generate_conf as inverses, setconf input always generated, Mullvad completion anchored to the [Peer] section, custom.py endpoint split through the codec helper. Close when #189 merges.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/aqomui#187
No description provided.