Files
tsunagi/docs/wireguard.md
T
tsunagiandClaude Opus 5 38beb762d8 Fix the TUN setup recipe: the overlay address was being flushed
The setup this tool printed did not work, and the agent then correctly
refused to start. A persistent TUN interface has no carrier until a process
attaches to it, and Linux flushes IPv6 addresses from an interface that
loses carrier unless net.ipv6.conf.<dev>.keep_addr_on_down is set, which it
is not by default. So `ip -6 address add` on a freshly created interface
silently lost the address before the agent ever ran.

The recipe now brings the link up first, sets keep_addr_on_down, and adds
the address with `nodad` — without which duplicate address detection can
never finish on an interface with no carrier and the address stays
tentative and unusable.

The agent's own retry loop made this worse: it attached, failed the address
check, dropped the device and toggled the carrier, which flushed the
address again. The check now runs before attaching to an existing
interface, so looking is not destructive.

Failures are self-diagnosing now: the check parses the IFA_F_* flags, tells
tentative and DAD-failed apart from missing, and lists the addresses the
interface actually has.

Four new tests, including one that reads this host's real /proc/net/if_inet6
and one that pins the ordering of the setup commands.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-21 12:36:16 +01:00

8.8 KiB

The WireGuard data plane

WireGuard is the first IP plugin. It carries user traffic between participants while the control plane keeps doing its own job: deciding who is in the network and carrying each participant's opaque announcement.

Module boundaries are in architecture.md, the control protocol in protocol.md, the security consequences in threat-model.md.

Userspace, not the kernel

WireGuard here is boringtun's protocol state machine running in this process. There is no kernel WireGuard module and no wg tool: the same code runs everywhere, and the protocol can be exercised in tests without any privileges at all.

The only privileged step left is creating a packet interface so the operating system can hand us IP packets, and even that is behind a trait (TunFactory) with an in-memory implementation.

needs privileges what it proves
MemoryTunFactory no handshake, encryption, routing, address ownership
SystemTunFactory, attaching none, if the interface was prepared traffic actually reaches the OS
SystemTunFactory, creating CAP_NET_ADMIN the same, at the cost of a capability

SystemTunFactory attaches to an interface that already exists and only creates one when it does not. A persistent interface created by root and owned by the user lets the agent run with no privileges at all; see Running unprivileged in ../README.md.

Where the packets go

The plugin does not know and does not care. It is handed a PacketLink per peer by the agent and runs a WireGuard tunnel over it:

  TUN device (IP packets)                  PacketLink per peer
       |                                          |
       v                                          v
  destination address -> peer  --Tunn.encapsulate-->  ciphertext -> transport
  source address checked       <--Tunn.decapsulate--  ciphertext <- transport

Reachability — hole punching, relay fallback — belongs to the transport, which today is iroh. That is the whole reason the plugin's announcement says who it is and never where it is: there is no address for a peer to advertise, get wrong, or lie about.

Two peers behind NAT work exactly as well as iroh does. iroh hole punches a direct path when it can and falls back to a relay when it cannot; the tunnel rides on whichever it got. There is no separate STUN, no separate hole punching and no second set of NAT problems to solve for WireGuard.

Deterministic overlay addressing

A mesh with no coordinator cannot hand out addresses, so everyone derives their own. The result is an IPv6 unique local address (RFC 4193):

prefix (/64) = 0xfd || SHA-256( LP(domain) || LP("prefix") || LP(network_id) )[0..7]
iid    (64b) =         SHA-256( LP(domain) || LP("interface") || LP(network_id) || LP(wg_public_key) )[0..8]
address      = prefix || iid

with domain = "tsunagi-wireguard-overlay-v1" and LP(x) = u32_be(len(x)) || x, the same unambiguous encoding the rest of the project uses.

Two consequences matter:

  • every member of a network derives the same /64, so the overlay is one subnet that nobody had to allocate;
  • a member's address is bound to its WireGuard public key, so address ownership can be checked locally rather than believed.

Address ownership is enforced, not announced

Kernel WireGuard enforces AllowedIPs. In userspace that is our job, and device does it on both sides:

  • outbound, a packet is routed to the peer that owns its destination address; a destination nobody owns is counted as unroutable and dropped;
  • inbound, a decrypted packet is dropped unless its source is exactly the address derived for the peer whose tunnel decrypted it.

So a participant cannot receive traffic addressed to somebody else and cannot forge traffic that appears to come from somebody else. A participant who knows the network secret can mint many keys and therefore occupy many addresses, but it cannot choose to collide with an existing member without finding a hash preimage.

The announcement also carries the address the peer believes it has. It is never used — only cross-checked — so a version skew produces a clear rejection rather than silent non-connectivity.

MTU

Every packet rides in one transport datagram, and WireGuard adds 32 bytes. A QUIC datagram on a relayed path can be as small as roughly 1160 bytes, so the default interface MTU is 1100, which leaves headroom rather than relying on the best case. Packets that do not fit are dropped and counted (dropped_oversize), never truncated. The observed datagram limit of each link is reported in the status output.

Lifecycle

  • A network is activated → the plugin loads or creates its key for that network, derives the interface name, and creates the packet interface. If that fails — no privileges, for instance — the key and the announcement still work and the interface is retried on the next reconcile.
  • A peer announces its key → recorded.
  • A data link to that peer arrives → recorded.
  • Reconciliation starts a tunnel for every peer that has both, and removes tunnels for peers that lost either.
  • A network is deactivated, or the agent shuts down → the interface and every tunnel go away. The key stays, so coming back keeps the same overlay address.

There is no external configuration file and no command line tool, so unlike a kernel-WireGuard setup there is nothing outside this process for anybody to edit. Reconciliation is purely "do the running tunnels match what is known".

Using it

# On both machines
tsunagi up --network lab --secret "$SECRET" --wireguard

See the two-machine walkthrough in ../README.md.

From the library:

use std::sync::Arc;
use tsunagi::config::{AgentConfig, StoragePaths, TransportPolicy};
use tsunagi::dataplane::IpPlugin;
use tsunagi::dataplane::wireguard::{MemoryTunFactory, WireguardConfig, WireguardPlugin};
use tsunagi::identity::{NetworkName, NetworkSecret};
use tsunagi::{Agent, Result};

#[tokio::main]
async fn main() -> Result<()> {
    let paths = StoragePaths::user_default()?;

    // MemoryTunFactory needs no privileges; swap in SystemTunFactory for a
    // real interface.
    let plugin = WireguardPlugin::open(
        WireguardConfig::new(paths.state_dir.join("wireguard")),
        Arc::new(MemoryTunFactory::new()),
    )
    .await
    .expect("wireguard plugin");

    let agent = Agent::spawn(
        AgentConfig::new(paths)
            .with_transport(TransportPolicy::N0Defaults)
            .with_plugin(plugin.clone() as Arc<dyn IpPlugin>),
    )
    .await?;

    let network = agent
        .join_network(&NetworkName::new("lab")?, &NetworkSecret::generate())
        .await?;

    if let Some(view) = plugin.overview(network) {
        println!("{} on {}", view.interface, view.overlay_address);
    }
    agent.shutdown().await;
    Ok(())
}

Limits and future work

  • Full mesh only. Every member runs a tunnel to every other member. Routing through an intermediate participant is not implemented.
  • IPv6 overlay only. Addressing is IPv6 ULA because it can be derived collision-free. An IPv4 overlay would need an allocator, which needs the agreed state described in sync-model.md.
  • No routes, DNS or firewall rules. The plugin creates its interface and nothing else. Anything beyond the overlay /64 is the operator's business.
  • Membership is session-scoped. A peer leaves the overlay when its control session ends; surviving a long absence is the same future work.
  • Userspace costs CPU. Kernel WireGuard is faster. A kernel backend could return behind the same boundary, but it would give up transport-provided NAT traversal unless paired with a local proxy.
  • A persistent TUN interface needs keep_addr_on_down. Without a process attached it has no carrier, and Linux then flushes its IPv6 addresses. The setup printed by tsunagi tun-setup sets it; the agent checks the address is present and usable — not tentative, not DAD-failed — before attaching, and reports what it actually found.
  • The agent cannot assign the overlay address itself. The tun crate sets addresses through an IPv4-only ioctl, so the IPv6 overlay address must come from ip -6 address add or an equivalent. The agent verifies the address is present, via /proc/net/if_inet6, and refuses with the exact command rather than running an interface that could never receive anything. Doing it in-process would mean speaking netlink, which is not implemented.
  • The system interface path is not exercised by the default suite, because it needs privileges. Everything else about the data plane is.