Alexander 6e5d27497e feat(torad): validate WireGuard config at parse time
The parser stored every value as a raw String and only ever rejected a
missing key. Those values are about to be handed to `ip addr add`, route
setup, and the wireguard-go UAPI socket in Wave 3, none of which give a
diagnostic worth reading: a mistyped address comes back as a bare EINVAL
or a UAPI errno with no hint of which config line caused it.

Parse into typed values instead — Key, IpCidr, Endpoint — and report
failures with a line number and the offending value.

Key validation was not in the original scope, but the fixture in this
file's own tests was a 41-character "private key" that parsed clean:
long enough to look right, short enough to fail at the UAPI socket three
waves later. Decoding here also yields the hex encoding that UAPI
expects, so it replaces work rather than adding it. Errors on the
private key deliberately describe only the shape of the problem, never
the input, and there is a test that fails if the value leaks.

Address and DNS become lists because wg-quick allows comma-separated
values and dual-stack providers emit them; parsing only the first would
have silently dropped the IPv6 address.

Also reject what used to be accepted in silence: a second [Peer] or
[Interface] section, a repeated key within a section, an unknown
section, and a key appearing before any section header.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:33:41 +02:00
2026-07-03 19:10:26 +02:00
2026-07-03 19:10:26 +02:00
2026-07-03 19:10:26 +02:00
2026-07-02 17:02:49 +02:00
2026-07-03 22:21:18 +02:00
2026-07-25 12:44:20 +02:00
2026-07-03 22:21:18 +02:00
2026-07-03 19:10:26 +02:00
S
Description
No description provided
542 KiB
Languages
Rust 99.1%
Nix 0.9%