feat(gateway): connect to relay control plane

The gateway binary now has a real relay-facing configuration and QUIC control
handshake. It accepts a relay socket address, expected TLS server name, pinned
DER relay certificate, room code, LAN interface name, and advertised datagram
budget, then connects as role = gateway and waits for a welcome response.

The ALPN token moved into lanparty-ctrl so relay and gateway share the same
protocol identifier instead of carrying duplicate private constants. The gateway
still stops after the control-plane connection; AF_PACKET capture and injection
remain a later slice.

The connector test spins up a local Quinn server with a self-signed certificate,
trusts that certificate explicitly, verifies the outgoing gateway hello, and
checks the received welcome metadata.

Test Plan:
- cargo fmt --check
- cargo test --workspace
- cargo clippy --workspace --all-targets -- -D warnings

Refs: PLAN.md Linux gateway outbound relay connection
This commit is contained in:
2026-05-21 18:06:22 +02:00
parent 956650ea8a
commit 763a55bfba
7 changed files with 449 additions and 5 deletions
+1
View File
@@ -16,6 +16,7 @@ pub use lanparty_obs::TunnelStats;
use lanparty_proto::{MIN_USEFUL_TAP_MTU, MacAddr, MtuError, recommended_tap_mtu};
use thiserror::Error;
pub const RELAY_ALPN: &[u8] = b"lanparty-l2/1";
pub const CONTROL_PROTOCOL_VERSION: u16 = 1;
pub const MIN_ROOM_CODE_LEN: usize = 1;
pub const MAX_ROOM_CODE_LEN: usize = 64;