Replace WireGuard prototype with native host service and scoped access
This commit is contained in:
1 parent
37b5394df1
commit
11f16ef4a3
16 files changed
+667
-136
No files matched your search
+8
-5
@@ -7,7 +7,7 @@ class ConfigError(ValueError):
|
||||
pass
|
||||
|
||||
|
||||
def parse_config(text):
|
||||
def parse_config(text, native=False):
|
||||
if not isinstance(text, str) or len(text.encode('utf-8')) > 16384:
|
||||
raise ConfigError('Die Konfiguration darf höchstens 16 KiB groß sein.')
|
||||
sections = {}
|
||||
@@ -25,6 +25,9 @@ def parse_config(text):
|
||||
raise ConfigError('Ungültiges WireGuard-Dateiformat.')
|
||||
name, value = (part.strip() for part in line.split('=', 1))
|
||||
allowed = {'PrivateKey', 'Address', 'DNS', 'MTU', 'ListenPort'} if current is sections.get('[Interface]') else {'PublicKey', 'PresharedKey', 'AllowedIPs', 'Endpoint', 'PersistentKeepalive'}
|
||||
if native and name == 'DNS' and name in current:
|
||||
current[name] += ', ' + value
|
||||
continue
|
||||
if name not in allowed or name in current:
|
||||
raise ConfigError('Unbekannte oder doppelte Direktive. Hooks, Table und SaveConfig sind nicht erlaubt.')
|
||||
if not value or any(ord(c) < 32 for c in value):
|
||||
@@ -44,9 +47,9 @@ def parse_config(text):
|
||||
try:
|
||||
addresses = [ipaddress.ip_interface(v.strip()) for v in interface['Address'].split(',')]
|
||||
networks = [ipaddress.ip_network(v.strip(), strict=False) for v in peer['AllowedIPs'].split(',')]
|
||||
if len(addresses) != 1 or addresses[0].version != 4 or any(n.version != 4 for n in networks):
|
||||
if (not native and (len(addresses) != 1 or addresses[0].version != 4 or any(n.version != 4 for n in networks))) or (native and (not 1 <= len(addresses) <= 2 or len({a.version for a in addresses}) != len(addresses) or addresses[0].version != 4)):
|
||||
raise ConfigError('Diese Version unterstützt eine IPv4-Tunneladresse und IPv4-AllowedIPs.')
|
||||
if addresses[0].ip.is_loopback or addresses[0].ip.is_unspecified or addresses[0].ip.is_multicast:
|
||||
if any(a.ip.is_loopback or a.ip.is_unspecified or a.ip.is_multicast for a in addresses):
|
||||
raise ValueError()
|
||||
if len(networks) > 32:
|
||||
raise ValueError()
|
||||
@@ -64,8 +67,8 @@ def parse_config(text):
|
||||
if isinstance(exc, ConfigError):
|
||||
raise
|
||||
raise ConfigError('Ungültige Adresse, Endpoint, Port, MTU oder Keepalive.') from None
|
||||
warnings = ['DNS wird nicht übernommen; die Container-DNS-Auflösung bleibt bestehen.'] if 'DNS' in interface else []
|
||||
return dict(interface=interface, peer=peer, address=str(addresses[0].ip), allowed_ips=[str(n) for n in networks], mtu=mtu, keepalive=keepalive, listen=listen, warnings=warnings)
|
||||
warnings = ['DNS wird nicht übernommen; die bestehende System-DNS-Auflösung bleibt erhalten.'] if 'DNS' in interface else []
|
||||
return dict(addresses=[str(a) for a in addresses], interface=interface, peer=peer, address=str(addresses[0].ip), allowed_ips=[str(n) for n in networks], mtu=mtu, keepalive=keepalive, listen=listen, warnings=warnings)
|
||||
|
||||
|
||||
def wireguard_text(config):
|
||||
|
||||
Reference in new issue
Block a user