From cbf28e3cfeeb78d33e45db0b600a39d8f52d24a2 Mon Sep 17 00:00:00 2001 From: Konstantin Passig PC <2002erdi@gmail.com> Date: Tue, 25 Aug 2026 18:10:25 +0200 Subject: [PATCH] vpn: poke the tunnel with traffic to force a WireGuard handshake (idle interfaces never handshake) --- yt_downloader/vpn.py | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/yt_downloader/vpn.py b/yt_downloader/vpn.py index 23265f9..626ae77 100644 --- a/yt_downloader/vpn.py +++ b/yt_downloader/vpn.py @@ -220,10 +220,27 @@ def down(cfg) -> None: _sudo(["rm", "-rf", f"/etc/netns/{ns}"]) +def _poke(cfg) -> None: + """Send a tiny packet through the tunnel to force a WireGuard handshake.""" + ns = netns_name(cfg) + code = ( + "import socket;" + "s=socket.socket(socket.AF_INET,socket.SOCK_DGRAM);" + "s.sendto(b'\\x00'*32, ('10.64.0.1', 53))" + ) + _sudo(["ip", "netns", "exec", ns, "python3", "-c", code], check=False) + + def wait_for_handshake(cfg, timeout: float = 20.0) -> bool: + """Wait for a handshake, actively routing packets to trigger one. + + WireGuard only initiates a handshake once traffic flows through the + tunnel, so an idle interface would never handshake on its own. + """ import time deadline = time.monotonic() + timeout while time.monotonic() < deadline: + _poke(cfg) # force traffic -> handshake if has_handshake(cfg): return True time.sleep(0.5)