feat(amneziawg): add embedded amneziawg-go device package (Phase 1)

New internal/amneziawgnet package: builds a real amneziawg-go Device over a
gVisor netstack from an existing amneziawg.Instance, with a TCP/UDP
forwarder that recovers each tunnel connection's real destination and a
peer-identity index keyed by AllowedIPs. This is the foundation for
migrating AmneziaWG off the kernel-module+TPROXY path (see the AmneziaWG-go
vs kernel-module decision) -- nothing wires into live traffic yet, that's
Phase 2 (relay into Xray's own SOCKS5 inbound).

Covered by three real end-to-end tests: a genuine handshake + TCP forwarder
+ identity resolution, the same for UDP (including a reply routed back
through the tunnel), and the manager's reconfigure-in-place vs. rebuild
lifecycle.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Kuzz007
2026-08-02 13:48:13 +03:00
parent 59dc94a288
commit 58671533bb
11 changed files with 1165 additions and 1 deletions
+3 -1
View File
@@ -35,6 +35,8 @@ require (
pgregory.net/rapid v1.3.0
)
require github.com/amnezia-vpn/amneziawg-go/v3 v3.0.3
require (
github.com/Azure/go-ntlmssp v0.1.1 // indirect
github.com/andybalholm/brotli v1.2.2 // indirect
@@ -110,6 +112,6 @@ require (
golang.zx2c4.com/wireguard/windows v1.0.1 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20260729162451-8efbd57d26e0 // indirect
google.golang.org/protobuf v1.36.11
gvisor.dev/gvisor v0.0.0-20260122175437-89a5d21be8f0 // indirect
gvisor.dev/gvisor v0.0.0-20260122175437-89a5d21be8f0
lukechampine.com/blake3 v1.4.1 // indirect
)