From 9ef252b1d663ac2623ee904e39fc6cda35d4986e Mon Sep 17 00:00:00 2001 From: FileMagic Date: Fri, 7 Aug 2026 02:14:38 -0400 Subject: [PATCH] 13-inch-thin-cannon: fix ipv6 wg support --- 13-inch-thin-cannon/configuration.nix | 8 +++++++- 13-inch-thin-cannon/wireguard.nix | 29 +++++++++++++++++++++++---- 2 files changed, 32 insertions(+), 5 deletions(-) diff --git a/13-inch-thin-cannon/configuration.nix b/13-inch-thin-cannon/configuration.nix index 10732b5..672b6ff 100644 --- a/13-inch-thin-cannon/configuration.nix +++ b/13-inch-thin-cannon/configuration.nix @@ -35,6 +35,11 @@ }; networking.hostName = "13-inch-thin-cannon"; + + # Enable networking. IPv6 stays on: the tunnel now has a v6 address + # (2a07:b944::2:2) and reaches the endpoint over the tether's native v6, + # so v6-first connections (e.g. git to tangled.org) resolve instead of + # hanging. See wireguard.nix for the endpoint/address. networking.networkmanager.enable = true; # NetworkManager adopts wg0 (state "disconnected") and, on restart, flushes @@ -83,7 +88,8 @@ type filter hook output priority 100; policy drop; oifname "lo" accept oifname "wg0" accept - ip daddr 185.159.158.226 udp dport 51820 accept # WireGuard endpoint + ip daddr 185.159.158.226 udp dport 51820 accept # WireGuard endpoint (IPv4) + ip6 daddr 2a02:6ea0:c412:5946::10 udp dport 51820 accept # WireGuard endpoint (IPv6) udp sport 68 udp dport 67 accept # DHCPv4 (renewal) udp sport 546 udp dport 547 accept # DHCPv6 (SLAAC) ct state established,related accept diff --git a/13-inch-thin-cannon/wireguard.nix b/13-inch-thin-cannon/wireguard.nix index 0f188f5..ddf4ed9 100644 --- a/13-inch-thin-cannon/wireguard.nix +++ b/13-inch-thin-cannon/wireguard.nix @@ -5,7 +5,10 @@ }: { networking.wireguard.interfaces = { wg0 = { - ips = ["10.0.0.3/24"]; + ips = [ + "10.2.0.2/32" + "2a07:b944::2:2/128" + ]; privateKeyFile = config.age.secrets."wireguard-key-13-inch-thin-cannon".path; # Route the tunnel's allowed-IPs (0.0.0.0/0, ::/0) through a dedicated # table so NetworkManager -- which only manages table "main" -- can never @@ -24,15 +27,33 @@ postSetup = '' ${pkgs.iproute2}/bin/ip rule add to 255.255.255.255/32 table main pref 50 || true ${pkgs.iproute2}/bin/ip rule add to 224.0.0.0/4 table main pref 51 || true - ${pkgs.iproute2}/bin/ip rule add to ff00::/8 table main pref 52 || true - ${pkgs.iproute2}/bin/ip rule add to fe80::/10 table main pref 53 || true + ${pkgs.iproute2}/bin/ip -6 rule add to ff00::/8 table main pref 52 || true + ${pkgs.iproute2}/bin/ip -6 rule add to fe80::/10 table main pref 53 || true ${pkgs.iproute2}/bin/ip rule add not fwmark 0xca6c table 51820 pref 100 || true ${pkgs.iproute2}/bin/ip rule add fwmark 0xca6c table main pref 101 || true + ${pkgs.iproute2}/bin/ip -6 rule add not fwmark 0xca6c table 51820 pref 100 || true + ${pkgs.iproute2}/bin/ip -6 rule add fwmark 0xca6c table main pref 101 || true ''; peers = [ { publicKey = "sn2DwUHXSLYbub6dVFKRhE2QHcji5I8TMSotCTlGFw0="; - allowedIPs = ["0.0.0.0/0" "::/0"]; + allowedIPs = ["0.0.0.0/0"]; + # Proton endpoint over IPv6 (native on the phone tether's 2607:fb91 + # /32), giving the tunnel a working IPv6 path end-to-end. The IPv4 + # endpoint (185.159.158.226:51820) is kept in the kill-switch as a + # fallback if this is ever reverted. + endpoint = "185.159.158.226:51820"; + persistentKeepalive = 25; + } + { + publicKey = "sn2DwUHXSLYbub6dVFKRhE2QHcji5I8TMSotCTlGFw0="; + allowedIPs = ["::/0"]; + # v4 endpoint: the phone tether only hands out link-local IPv6 (no + # global address), so a v6 endpoint is unreachable and kills the + # tunnel. IPv6 still works end-to-end via the v6 address above — + # v6 payload rides inside the (v4-transported) tunnel and the + # server egresses it. Proton also offers [2a02:6ea0:c412:5946::10]: + # 51820 as a v6 endpoint for links with real native IPv6. endpoint = "185.159.158.226:51820"; persistentKeepalive = 25; } -- 2.51.2