vpn: poke the tunnel with traffic to force a WireGuard handshake (idle interfaces never handshake)
This commit is contained in:
@@ -220,10 +220,27 @@ def down(cfg) -> None:
|
|||||||
_sudo(["rm", "-rf", f"/etc/netns/{ns}"])
|
_sudo(["rm", "-rf", f"/etc/netns/{ns}"])
|
||||||
|
|
||||||
|
|
||||||
|
def _poke(cfg) -> None:
|
||||||
|
"""Send a tiny packet through the tunnel to force a WireGuard handshake."""
|
||||||
|
ns = netns_name(cfg)
|
||||||
|
code = (
|
||||||
|
"import socket;"
|
||||||
|
"s=socket.socket(socket.AF_INET,socket.SOCK_DGRAM);"
|
||||||
|
"s.sendto(b'\\x00'*32, ('10.64.0.1', 53))"
|
||||||
|
)
|
||||||
|
_sudo(["ip", "netns", "exec", ns, "python3", "-c", code], check=False)
|
||||||
|
|
||||||
|
|
||||||
def wait_for_handshake(cfg, timeout: float = 20.0) -> bool:
|
def wait_for_handshake(cfg, timeout: float = 20.0) -> bool:
|
||||||
|
"""Wait for a handshake, actively routing packets to trigger one.
|
||||||
|
|
||||||
|
WireGuard only initiates a handshake once traffic flows through the
|
||||||
|
tunnel, so an idle interface would never handshake on its own.
|
||||||
|
"""
|
||||||
import time
|
import time
|
||||||
deadline = time.monotonic() + timeout
|
deadline = time.monotonic() + timeout
|
||||||
while time.monotonic() < deadline:
|
while time.monotonic() < deadline:
|
||||||
|
_poke(cfg) # force traffic -> handshake
|
||||||
if has_handshake(cfg):
|
if has_handshake(cfg):
|
||||||
return True
|
return True
|
||||||
time.sleep(0.5)
|
time.sleep(0.5)
|
||||||
|
|||||||
Reference in New Issue
Block a user