uzbek-plus/logs/b15/B15-AUDIT.md

2.9 KiB

B15 audit — WireGuard over FOCSQ/CSQTT (2026-10-05) — STOPPED: kernel prerequisites missing

Source (canonical = user's private repo, no upstream merge)

  • git.bebrik.xyz/Dan4ick/Uzbek-vpn (private), branch main, HEAD 5a9ff1d (2026-10-04: "Deliver flow frames that arrive after the reassembler stops waiting", "Stop dropping downlink packets that arrive in a flow frame"). Cloned to the private dir b15/private/focsq-src on 480s (token used only as an HTTP header, not stored). Project = CSQTT fork (csqtt-dion), PolyForm-Noncommercial.
  • Release v2.1.9-dion.6 (2026-10-02, older than HEAD): csqtt-client-linux-aarch64 9.5 MB, sha256 4ce37e50… (matches SHA256SUMS-linux.txt).

Headless component (no Flutter/GUI needed)

  • rust-client = one binary csqtt-client (Rust 2024, rust-version 1.97.1, tokio, aws-lc-rs, rustls). Same binary:
    • tunnel: --provider dion|vk --rooms … -peer … -password … -n WORKERS -turn-transport udp|tcp -obfs audio|video -device-id … --tun-dev csqtt0 --tun-up <script> --status-file /run/csqtt/status.json --idle-keepalive 0
    • csqtt-client stick: DoH/DoT DNS forwarder (127.0.0.1:5053), RU split list, web panel :8088 (default password 12345) — not needed here.
  • TUN: opens /dev/net/tun itself, interface csqtt0, /32 address + DNS + MTU (1300) from server TUNCONF, handed to the --tun-up script (CSQTT_TUN/IP/DNS/MTU); down on SIGTERM.
  • Routing (stick/csqtt-tun-up.sh): policy routing (ip rule from LAN lookup 66, default dev csqtt0 in table 66), iptables MASQUERADE + TCPMSS clamp; the client's own TURN sockets stay on the main (LTE) table → no loop. Needs rewriting for nft + Aurora (wwan0 has no default route except the aurora-router one).
  • Credentials: /etc/csqtt/client.env (CSQTT_PROVIDER/ROOMS/PEER/PASSWORD/WORKERS/TURN_TRANSPORT/OBFS/DEVICE_ID, chmod 600) — not provided yet.
  • systemd: Type=notify + watchdog (sd_notify is a no-op without NOTIFY_SOCKET), exit 75 on uplink change → needs an OpenRC supervisor that restarts it (supervise-daemon respawn). No resolved dependency.
  • Release binary is glibc (interpreter /lib/ld-linux-aarch64.so.1; libc/libm/libpthread/libdl, GLIBC_2.28) — not musl. On Alpine either bundle a glibc loader+libs (run via the loader, like the earlier musl bundles) or build from HEAD (no Rust toolchain on 480s/host yet).

Kernel (running 7.2.7-aurora-b12)

needed state
CONFIG_TUN y
CONFIG_NF_TABLES (+NAT, CT, FIB) y
CONFIG_WIREGUARD not set
CONFIG_IP_ADVANCED_ROUTER / IP_MULTIPLE_TABLES (ip rule, fwmark tables) not set — no policy routing at all
CONFIG_NFT_RT (tcp option maxseg size set rt mtu) not set (MSS clamp would need a fixed value)

Per the B15 brief: kernel WireGuard missing → STOP and report. Policy routing is also required both by the stick design and by the B15 routing architecture (separate tables for FOCSQ endpoints / WG endpoint / Wi-Fi LAN).