fix(wg+fw): Peer-Sync-Bug via sudo-Symlink + Site-to-Site-Masquerade

- WireGuard-Peer-Änderungen landeten nicht im laufenden Interface:
  /etc/wireguard/ ist root:root 700, os.Readlink schlug fehl →
  ensureWGQuickSymlink fiel immer in den Error-Pfad. Fix: Symlink
  via sudo /bin/ln -sf (sudoers-Entry in postinst ergänzt).

- Site-to-Site-Masquerade: Roadwarrior-Clients (z. B. 192.168.99.3)
  konnten LANs hinter anderen Peers nicht erreichen, weil das remote
  Gateway die VPN-Client-IP nicht als Tunnel-Route kannte. Fix: auto
  masquerade in nftables postrouting_nat pro WireGuard-Server-Interface
  (oifname "wg7" ip saddr 192.168.99.0/24 masquerade).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Debian
2026-05-21 16:31:54 +02:00
parent bc5d81d966
commit 6445e162a6
6 changed files with 56 additions and 26 deletions

View File

@@ -33,3 +33,16 @@ func stopWGQuick(iface string) error {
_ = cmd.Run()
return nil
}
// symlinkWGQuickConf creates (or atomically replaces) the symlink
// /etc/wireguard/<iface>.conf → target via sudo. /etc/wireguard/ is
// owned root:root 700 so the edgeguard user cannot write to it directly;
// the sudoers entry in postinst whitelists exactly this ln command.
func symlinkWGQuickConf(iface, target string) error {
link := "/etc/wireguard/" + iface + ".conf"
cmd := exec.Command("sudo", "-n", "/bin/ln", "-sf", target, link)
if out, err := cmd.CombinedOutput(); err != nil {
return fmt.Errorf("ln -sf %s %s: %w: %s", target, link, err, string(out))
}
return nil
}