HydraIssues

GL.iNet neck follow-ups: SSH WireGuard toggle and iPad check
open improvement Project: hydraneck Reporter: cederik 20 Aug 2026 09:06

Description

Goal

Finish the GL.iNet work that remains after the backend shipped and the Slate 7 Pro went live. Carried out of #516, which is closed as implemented. The Omada decommission is a separate ticket: #535. Background: #516 (backend + rollout), #517 (device API verification), #522 (mesh tunnel bring-up), hydraneck/docs/runbooks/glinet.md (the full device picture).

Current state

  • hydraneck v0.12.1 scans the Slate 7 Pro live at venue sint-niklaas-tourism-office (mesh address 10.10.5.1, "4.8.4 (GL.iNet GL-BE10000)").
  • The hydraguard tunnel on the device runs via netifd wgclient1 plus /usr/bin/hydra-wg-up.sh, and survives reboots.
  • hydraneck wg setup (config CRUD over the JSON-RPC API) works. hydraneck wg on|off is broken on firmware 4.8+ and wg status reports the tunnel as down even when it is up.

Track 1: SSH-based WireGuard toggle for glinet

Firmware 4.8+ removed wg-client start, stop, and get_status from the JSON-RPC API. The replacement vpn-client module is the global-proxy engine and cannot do subnet-selective routing; it must not be used. The reliable control surface is SSH (dropbear, port 22, root + admin password, the documented fallback).

  • Add an SSH transport to pkg/glinet (golang.org/x/crypto/ssh; password auth with the same secret the JSON-RPC client uses).
  • EnableWireGuard: ifup wgclient1 (the on-device hydra-wg-up.sh logic re-adds address and routes). DisableWireGuard: ifdown wgclient1.
  • WireGuardUp: parse wg show wgclient1 (handshake present = up). Fixes the false "down" from the missing service entry in system get_status.
  • Keep the JSON-RPC path as a fallback for firmware that still has the wg-client control methods; probe once and remember.
  • Consider making hydraneck own /usr/bin/hydra-wg-up.sh: install and update it over SSH so the tunnel bootstrap is reproducible on the next device, not hand-installed (#522 installed it manually).
  • Keep every mutating path behind access: write.
  • Tests: fake SSH server or a command-runner seam; keep the 4.8.4 JSON-RPC fixture green.
  • Update docs/runbooks/glinet.md and CLAUDE.md: remove the "broken on 4.8+" caveats once wg on|off work.

Track 2: iPad coexistence check (carried from #522 step 4c)

  • With the router tunnel up, confirm one iPad head on the Slate 7 Pro Wi-Fi still works (its own WireGuard handshakes, head app connects). Expected fine: the WAN-IP check in #522 passed. Needs someone with an iPad at the device.

Deferred (only if a need appears)

  • Live debug streams (SSE) for glinet, generalizing the MikroTik-shaped debug plumbing. Omada skipped this too.
  • Renumber the Slate 7 Pro LAN from 192.168.8.0/24 to 10.0.5.0/24 if the venue LAN ever needs hub-side routing to individual clients.