vpn: poke the tunnel with traffic to force a WireGuard handshake (idle interfaces never handshake)
This commit is contained in:
@@ -220,10 +220,27 @@ def down(cfg) -> None:
|
||||
_sudo(["rm", "-rf", f"/etc/netns/{ns}"])
|
||||
|
||||
|
||||
def _poke(cfg) -> None:
|
||||
"""Send a tiny packet through the tunnel to force a WireGuard handshake."""
|
||||
ns = netns_name(cfg)
|
||||
code = (
|
||||
"import socket;"
|
||||
"s=socket.socket(socket.AF_INET,socket.SOCK_DGRAM);"
|
||||
"s.sendto(b'\\x00'*32, ('10.64.0.1', 53))"
|
||||
)
|
||||
_sudo(["ip", "netns", "exec", ns, "python3", "-c", code], check=False)
|
||||
|
||||
|
||||
def wait_for_handshake(cfg, timeout: float = 20.0) -> bool:
|
||||
"""Wait for a handshake, actively routing packets to trigger one.
|
||||
|
||||
WireGuard only initiates a handshake once traffic flows through the
|
||||
tunnel, so an idle interface would never handshake on its own.
|
||||
"""
|
||||
import time
|
||||
deadline = time.monotonic() + timeout
|
||||
while time.monotonic() < deadline:
|
||||
_poke(cfg) # force traffic -> handshake
|
||||
if has_handshake(cfg):
|
||||
return True
|
||||
time.sleep(0.5)
|
||||
|
||||
Reference in New Issue
Block a user