From 1539c589a1182459f1b421b3cebd912bcd64427d Mon Sep 17 00:00:00 2001 From: sysops Date: Wed, 29 Jul 2026 14:30:53 +0200 Subject: [PATCH] Normalize AllocatedIPs/ExtraAllowedIPs to network address before ip route replace A client CIDR with nonzero host bits (e.g. 10.66.120.1/30 instead of the network 10.66.120.0/30) is tolerated by wg's own AllowedIPs/setconf, which just warns, but plain iproute2 rejects it with "Invalid prefix for given prefix length" and aborts the whole PostUp chain, taking the interface down on start. Added a routeNet template func that clears host bits via net.ParseCIDR before generating each PostUp route line. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01ATVUwTa4Pqwq26orW5BcDW --- DEVLOG.md | 216 ++++++++++++++++++++++++++++++++++++++++++++++ templates/wg.conf | 2 +- util/util.go | 21 ++++- 3 files changed, 237 insertions(+), 2 deletions(-) diff --git a/DEVLOG.md b/DEVLOG.md index 0d314ca..6132f82 100644 --- a/DEVLOG.md +++ b/DEVLOG.md @@ -3597,3 +3597,219 @@ Keine Commits in dieser Session. - wireguard/service.go | 24 +++ --- +## 2026-07-29 13:37 – 13:38 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +- 3e57de1 Make Start/Stop enable/disable the wg-quick unit, not just start/stop it + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:41 – 13:42 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:43 – 13:44 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:46 – 13:48 (2m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:49 – 13:50 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:51 – 13:51 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:51 – 13:52 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 13:53 – 13:54 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:01 – 14:02 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:04 – 14:04 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:10 – 14:10 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:11 – 14:11 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:12 – 14:12 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:15 – 14:18 (2m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:18 – 14:20 (2m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:21 – 14:21 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:22 – 14:23 (0m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- +## 2026-07-29 14:25 – 14:28 (2m) +**Beschreibung:** Claude Code Session +**Projekt:** wireguard-ui-multi + +### Commits +Keine Commits in dieser Session. + +### Geänderte Dateien +- DEVLOG.md | 136 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +- wireguard/service.go | 23 ++++++++++++----- + +--- diff --git a/templates/wg.conf b/templates/wg.conf index f0b573e..5abf913 100644 --- a/templates/wg.conf +++ b/templates/wg.conf @@ -17,7 +17,7 @@ PreUp = {{ .serverConfig.Interface.PreUp }} # "RTNETLINK: File exists" the moment two servers claim the same route, # which used to take down every server started after the first. `replace` # is idempotent and never fails on a pre-existing route. -PostUp = {{ .serverConfig.Interface.PostUp }}{{range .clientDataList}}{{if eq .Client.Enabled true}}{{range .Client.AllocatedIPs}}ip route replace {{.}} dev %i; {{end}}{{range .Client.ExtraAllowedIPs}}ip route replace {{.}} dev %i; {{end}}{{end}}{{end}} +PostUp = {{ .serverConfig.Interface.PostUp }}{{range .clientDataList}}{{if eq .Client.Enabled true}}{{range .Client.AllocatedIPs}}ip route replace {{routeNet .}} dev %i; {{end}}{{range .Client.ExtraAllowedIPs}}ip route replace {{routeNet .}} dev %i; {{end}}{{end}}{{end}} PreDown = {{ .serverConfig.Interface.PreDown }} PostDown = {{ .serverConfig.Interface.PostDown }} Table = off diff --git a/util/util.go b/util/util.go index 37a3d65..10c0b6a 100644 --- a/util/util.go +++ b/util/util.go @@ -566,6 +566,23 @@ func GetSubnetRangesString() string { return strings.TrimSpace(strB.String()) } +// routeNetworkCIDR normalizes a CIDR string to its network address (host +// bits cleared) for use in `ip route replace dev %i` PostUp lines. +// wg's own AllowedIPs/setconf tolerates a CIDR with nonzero host bits (e.g. +// a peer address like 10.66.120.1/30 instead of the network 10.66.120.0/30) +// and just warns, but plain `ip route replace` rejects it outright with +// "Invalid prefix for given prefix length" and aborts the whole wg-quick +// up - taking down the interface over what should be a harmless data-entry +// quirk. Malformed input is passed through unchanged so the resulting +// PostUp line still fails loudly instead of silently mangling an address. +func routeNetworkCIDR(cidr string) string { + _, ipnet, err := net.ParseCIDR(cidr) + if err != nil { + return cidr + } + return ipnet.String() +} + // WriteWireGuardServerConfig to write Wireguard server config. e.g. wg0.conf func WriteWireGuardServerConfig(tmplDir fs.FS, serverConfig model.Server, clientDataList []model.ClientData, usersList []model.User, globalSettings model.GlobalSetting) error { var tmplWireguardConf string @@ -596,7 +613,9 @@ func WriteWireGuardServerConfig(tmplDir fs.FS, serverConfig model.Server, client } // parse the template - t, err := template.New("wg_config").Parse(tmplWireguardConf) + t, err := template.New("wg_config").Funcs(template.FuncMap{ + "routeNet": routeNetworkCIDR, + }).Parse(tmplWireguardConf) if err != nil { return err }