Merge pull request 'fix: gültiger WireGuard-Kandidatenname' (#54) from fix/wg-candidate-interface-name-20260905 into main

This commit is contained in:
sascha 2026-09-05 13:04:08 +02:00
commit 6c92c7023a
2 changed files with 14 additions and 3 deletions

4
app.py
View file

@ -12,7 +12,7 @@ from contextlib import asynccontextmanager
from contextvars import ContextVar from contextvars import ContextVar
log = logging.getLogger("butler") log = logging.getLogger("butler")
VERSION = "2.3.8" VERSION = "2.3.9"
API_DIR = os.environ.get("API_KEY_DIR", "/data/api") API_DIR = os.environ.get("API_KEY_DIR", "/data/api")
VAULT_CACHE_DIR = os.environ.get("VAULT_CACHE_DIR", "/data/vault-cache") VAULT_CACHE_DIR = os.environ.get("VAULT_CACHE_DIR", "/data/vault-cache")
@ -2409,7 +2409,7 @@ def _media_tunnel_install_command(role: Literal["vps", "emby"], peer_public_key:
+lines.extend(["", "[Peer]", "PublicKey = {peer_public_key}", "AllowedIPs = {settings['peer']}"]) +lines.extend(["", "[Peer]", "PublicKey = {peer_public_key}", "AllowedIPs = {settings['peer']}"])
+if {settings['endpoint']!r}: lines.append("Endpoint = " + {settings['endpoint']!r}) +if {settings['endpoint']!r}: lines.append("Endpoint = " + {settings['endpoint']!r})
+if {settings['keepalive']!r}: lines.append("PersistentKeepalive = " + str({settings['keepalive']!r})) +if {settings['keepalive']!r}: lines.append("PersistentKeepalive = " + str({settings['keepalive']!r}))
+candidate = root / "wg-media-candidate.conf" +candidate = root / "wgmtest.conf"
+candidate.write_text("\\n".join(lines) + "\\n") +candidate.write_text("\\n".join(lines) + "\\n")
+os.chmod(candidate, 0o600) +os.chmod(candidate, 0o600)
+check = subprocess.run(["wg-quick", "strip", str(candidate)], text=True, capture_output=True) +check = subprocess.run(["wg-quick", "strip", str(candidate)], text=True, capture_output=True)

View file

@ -43,7 +43,7 @@ def test_health_exposes_current_version():
with TestClient(app.app) as client: with TestClient(app.app) as client:
response = client.get("/health") response = client.get("/health")
assert response.status_code == 200 assert response.status_code == 200
assert response.json()["version"] == app.VERSION == "2.3.8" assert response.json()["version"] == app.VERSION == "2.3.9"
def test_media_handoff_proxies_strict_category_contract(monkeypatch): def test_media_handoff_proxies_strict_category_contract(monkeypatch):
@ -1344,3 +1344,14 @@ def test_sascha_media_tunnel_apply_returns_redacted_result(monkeypatch):
assert response.status_code == 200 assert response.status_code == 200
assert response.json()["handshake"] is True assert response.json()["handshake"] is True
assert "private" not in response.text.lower() assert "private" not in response.text.lower()
def test_sascha_media_tunnel_candidate_uses_valid_wireguard_interface_name():
import base64
import re
command = app._media_tunnel_install_command("vps", "A" * 43 + "=")
encoded = re.search(r"b64decode\('([^']+)'\)", command).group(1)
script = base64.b64decode(encoded).decode()
assert 'root / "wgmtest.conf"' in script
assert len("wgmtest") <= 15