Add isolated WireGuard module with guarded access modes and server setup

This commit is contained in:
Mikei386
2026-09-28 14:50:02 +02:00
parent b7b2506272
commit e86e540ae4
21 changed files with 1278 additions and 8 deletions
+28
View File
@@ -0,0 +1,28 @@
"""Bounded JSON RPC over a private Unix socket; no shell commands exposed."""
import json
import socket
import sys
SOCKET = '/run/deck/control.sock'
def request(data):
with socket.socket(socket.AF_UNIX) as sock:
sock.settimeout(25)
sock.connect(SOCKET)
sock.sendall(json.dumps(data).encode()+b'\n')
with sock.makefile('rb') as stream:
raw = stream.readline(65537)
if len(raw)>65536:
raise ValueError('Ungültige Helper-Antwort.')
result = json.loads(raw)
if 'error' in result and 'installed' not in result:
raise ValueError(result['error'])
return result
if __name__ == '__main__':
try:
data = json.loads(sys.stdin.buffer.readline(32769))
print(json.dumps(request(data)))
except Exception:
print(json.dumps({'error':'Netzwerkaktion fehlgeschlagen. Konfiguration und Verbindung prüfen.'}))
sys.exit(1)