uzbek-plus/logs/b15/B15-AUDIT.md

35 lines
2.9 KiB
Markdown

# B15 audit — WireGuard over FOCSQ/CSQTT (2026-10-05) — **STOPPED: kernel prerequisites missing**
## Source (canonical = user's private repo, no upstream merge)
- `git.bebrik.xyz/Dan4ick/Uzbek-vpn` (private), branch main, HEAD `5a9ff1d` (2026-10-04: "Deliver flow frames that arrive after the
reassembler stops waiting", "Stop dropping downlink packets that arrive in a flow frame"). Cloned to the private dir
`b15/private/focsq-src` on 480s (token used only as an HTTP header, not stored). Project = CSQTT fork (csqtt-dion), PolyForm-Noncommercial.
- Release `v2.1.9-dion.6` (2026-10-02, **older than HEAD**): `csqtt-client-linux-aarch64` 9.5 MB, sha256 4ce37e50… (matches SHA256SUMS-linux.txt).
## Headless component (no Flutter/GUI needed)
- `rust-client` = one binary `csqtt-client` (Rust 2024, rust-version 1.97.1, tokio, aws-lc-rs, rustls). Same binary:
- tunnel: `--provider dion|vk --rooms … -peer … -password … -n WORKERS -turn-transport udp|tcp -obfs audio|video -device-id …
--tun-dev csqtt0 --tun-up <script> --status-file /run/csqtt/status.json --idle-keepalive 0`
- `csqtt-client stick`: DoH/DoT DNS forwarder (127.0.0.1:5053), RU split list, web panel :8088 (default password 12345) — not needed here.
- TUN: opens `/dev/net/tun` itself, interface **csqtt0**, /32 address + DNS + MTU (1300) from server TUNCONF, handed to the `--tun-up` script
(`CSQTT_TUN/IP/DNS/MTU`); `down` on SIGTERM.
- Routing (stick/csqtt-tun-up.sh): **policy routing** (`ip rule from LAN lookup 66`, default dev csqtt0 in table 66), iptables MASQUERADE + TCPMSS
clamp; the client's own TURN sockets stay on the main (LTE) table → no loop. Needs rewriting for nft + Aurora (wwan0 has no default route
except the aurora-router one).
- Credentials: `/etc/csqtt/client.env` (CSQTT_PROVIDER/ROOMS/PEER/PASSWORD/WORKERS/TURN_TRANSPORT/OBFS/DEVICE_ID, chmod 600) — **not provided yet**.
- systemd: Type=notify + watchdog (sd_notify is a no-op without NOTIFY_SOCKET), exit 75 on uplink change → needs an OpenRC supervisor that
restarts it (supervise-daemon respawn). No resolved dependency.
- Release binary is **glibc** (interpreter /lib/ld-linux-aarch64.so.1; libc/libm/libpthread/libdl, GLIBC_2.28) — not musl. On Alpine either
bundle a glibc loader+libs (run via the loader, like the earlier musl bundles) or build from HEAD (no Rust toolchain on 480s/host yet).
## Kernel (running 7.2.7-aurora-b12)
| needed | state |
|---|---|
| CONFIG_TUN | y |
| CONFIG_NF_TABLES (+NAT, CT, FIB) | y |
| **CONFIG_WIREGUARD** | **not set** |
| **CONFIG_IP_ADVANCED_ROUTER / IP_MULTIPLE_TABLES** (ip rule, fwmark tables) | **not set** — no policy routing at all |
| CONFIG_NFT_RT (`tcp option maxseg size set rt mtu`) | not set (MSS clamp would need a fixed value) |
Per the B15 brief: kernel WireGuard missing → STOP and report. Policy routing is also required both by the stick design and by the
B15 routing architecture (separate tables for FOCSQ endpoints / WG endpoint / Wi-Fi LAN).