wgengine, all: remove LazyWG, use wireguard-go callback API for on-demand peers
Replace the UAPI text protocol-based wireguard configuration with wireguard-go's new direct callback API (SetPeerLookupFunc, SetPeerByIPPacketFunc, RemoveMatchingPeers, SetPrivateKey). Instead of computing a trimmed wireguard config ahead of time upon control plane updates and pushing it via UAPI, install callbacks so wireguard-go creates peers on demand when packets arrive. This removes all the LazyWG trimming machinery: idle peer tracking, activity maps, noteRecvActivity callbacks, the KeepFullWGConfig control knob, and the ts_omit_lazywg build tag. For incoming packets, PeerLookupFunc answers wireguard-go's questions about unknown public keys by looking up the peer in the full config. For outgoing packets, PeerByIPPacketFunc (installed from LocalBackend.lookupPeerByIP) maps destination IPs to node public keys using the existing nodeByAddr index. Updates tailscale/corp#12345 Change-Id: I4cba80979ac49a1231d00a01fdba5f0c2af95dd8 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
This commit is contained in:
committed by
Brad Fitzpatrick
parent
b313bffbe7
commit
f343b496c3
@@ -65,6 +65,11 @@ func NewNode() NodePrivate {
|
||||
// Raw32 returns k as 32 raw bytes.
|
||||
func (k NodePrivate) Raw32() [32]byte { return k.k }
|
||||
|
||||
// NodePrivateAs returns a NodePrivate as a named fixed-size array of bytes.
|
||||
// It's intended for interoperability with wireguard-go's
|
||||
// device.NoisePrivateKey type.
|
||||
func NodePrivateAs[T ~[32]byte](k NodePrivate) T { return k.k }
|
||||
|
||||
// NodePrivateFromRaw32 parses a 32-byte raw value as a NodePrivate.
|
||||
//
|
||||
// Deprecated: only needed to cast from legacy node private key types,
|
||||
|
||||
Reference in New Issue
Block a user