change: give each tunnel role its own WireGuard device #212
Loading…
Reference in a new issue
No description provided.
Delete branch "change/wireguard-roles-176"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Stage 2 of #176 (stage 1 was #211).
Problem: wireguard.py is built around one module-level device (
DEV = wg_aqomui) - the concrete reason WireGuard cannot join a double hop: a second leg has no device to exist on.Change:
wg_aqomui/wg_aqomui_h/wg_aqomui_b(newconfig.WG_DEVICES, next toTUN_DEVICES).link_up,link_down,firewall_rules,_setconf,_routes) takes the device it operates on;handshake_agereads the instance's.Behavior is otherwise unchanged - a single WireGuard connect does exactly what it did.
Verification: suite 523 passed; the secondary-refusal, per-role-device, and IFNAMSIZ/disjoint-names invariants are pinned by new tests. Live check before merge is just a normal WireGuard connect/disconnect (a Proton or Mullvad
-WireGuardentry) confirming nothing regressed.Stage 3 next: chain routing for WG legs via the shared hop_routes model, MTU stacking,
TUNNEL_SECONDARYflip, README.Part of #176.
🤖 Generated with Claude Code