Skip to content

Landlock causes HTTPs permission issues - #213

Merged
windtf merged 1 commit into
windtf:masterfrom
OwenCochell:landlock-fix
Jul 16, 2026
Merged

Landlock causes HTTPs permission issues#213
windtf merged 1 commit into
windtf:masterfrom
OwenCochell:landlock-fix

Conversation

@OwenCochell

Copy link
Copy Markdown
Contributor

Hello,

When building a docker image from the latest main branch, a permission error occurs when providing the main HTTPs certificate and private key via the config file. This is due to the fact that on linux machines, landlock rules are applied before the HTTP server loads the necessary files, which are not included in the rule list. This can be reporduced by creating a linux docker image, enabiling the HTTP proxy, and providing CertFile and KeyFile via the config file.

This fix adds the files to the rulelist, allowing the HTTP server to correctly load them. An alternative approach would be to load the files into the HTTP server before preforming the lock, but I wanted to keep the current order in case there is something I am missing.

This fix enables the correct behavior on my end. Please let me know if there any any issues, I would be happy to fix them.

Thanks!

@windtf
windtf merged commit 31a9a34 into windtf:master Jul 16, 2026
10 of 11 checks passed
CatDonIO pushed a commit to CatDonIO/wireproxy-awg that referenced this pull request Aug 14, 2026
Brings in everything from the base project up to v1.1.3:

- SNI (transparent TLS) proxy section (windtf#210)
- bare WGConfig filenames are resolved relative to the parent config dir (windtf#204)
- landlock: TCPClientTunnel BindAddress is now BindTCP, not ConnectTCP (windtf#219)
- landlock: TLS cert/key files are added to the allowed read paths (windtf#213)
- dependency bumps (x/net 0.55.0, x/crypto 0.52.0, x/sys 0.45.0)

Conflicts resolved in favour of the fork:

- go.mod/go.sum keep amneziawg-go and drop the direct golang.zx2c4.com/wireguard
  dependency; every shared dependency takes the newer of the two versions
- cmd/wireproxy/main.go keeps the wireproxyawg import alias and takes the
  upstream landlock fix
- README keeps the fork feature list and install path, and adds the SNI section

The upstream sponsor blocks (IPCook affiliate banner, DigitalOcean credits) and
assets/ipcook.png are not carried into the fork - they point at the base
project's referral code and sponsorship, which do not apply here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants