vpn: poke the tunnel with traffic to force a WireGuard handshake (idle interfaces never handshake)

This commit is contained in:
Konstantin Passig PC
2026-08-25 18:10:25 +02:00
parent 567e20027a
commit cbf28e3cfe
+17
View File
@@ -220,10 +220,27 @@ def down(cfg) -> None:
_sudo(["rm", "-rf", f"/etc/netns/{ns}"]) _sudo(["rm", "-rf", f"/etc/netns/{ns}"])
def _poke(cfg) -> None:
"""Send a tiny packet through the tunnel to force a WireGuard handshake."""
ns = netns_name(cfg)
code = (
"import socket;"
"s=socket.socket(socket.AF_INET,socket.SOCK_DGRAM);"
"s.sendto(b'\\x00'*32, ('10.64.0.1', 53))"
)
_sudo(["ip", "netns", "exec", ns, "python3", "-c", code], check=False)
def wait_for_handshake(cfg, timeout: float = 20.0) -> bool: def wait_for_handshake(cfg, timeout: float = 20.0) -> bool:
"""Wait for a handshake, actively routing packets to trigger one.
WireGuard only initiates a handshake once traffic flows through the
tunnel, so an idle interface would never handshake on its own.
"""
import time import time
deadline = time.monotonic() + timeout deadline = time.monotonic() + timeout
while time.monotonic() < deadline: while time.monotonic() < deadline:
_poke(cfg) # force traffic -> handshake
if has_handshake(cfg): if has_handshake(cfg):
return True return True
time.sleep(0.5) time.sleep(0.5)