From 94e1e94062a0235c6d53f30b1667d6ab0f64a70f Mon Sep 17 00:00:00 2001 From: Antigravity Agent Date: Sat, 3 Oct 2026 09:40:48 -0400 Subject: [PATCH] fast-path node-up when tunnel already passes traffic --- bin/netvm-node-up.sh | 30 +++++++++++++++++++----------- 1 file changed, 19 insertions(+), 11 deletions(-) diff --git a/bin/netvm-node-up.sh b/bin/netvm-node-up.sh index 421dbd9..4c7d419 100755 --- a/bin/netvm-node-up.sh +++ b/bin/netvm-node-up.sh @@ -73,17 +73,25 @@ else echo "cdp relay started ($PEER_IP:$CDP_PORT -> 127.0.0.1:$CDP_PORT)" fi -# wait for handshake (first one can take ~10s) -HS="" -for i in $(seq 1 10); do - HS=$(nsexec wg show "$WG" latest-handshakes 2>/dev/null | awk '{print $2}') - if [ -n "$HS" ] && [ "$HS" != "0" ]; then break; fi - sleep 2 -done -if [ -z "$HS" ] || [ "$HS" = "0" ]; then - echo "no handshake yet (endpoint=$ENDPOINT)" +# fast path: if the tunnel already passes traffic, skip the handshake wait. +# (WireGuard handshakes go stale without traffic; waiting 20s every launch +# is the main reason chrome-box feels slow to start.) +EGRESS=$(nsexec curl -sk --max-time 5 'https://1.1.1.1/cdn-cgi/trace' 2>/dev/null | grep -oP '^ip=\K.*' || true) +if [ -n "$EGRESS" ]; then + echo "tunnel already up (egress=$EGRESS), skipping handshake wait" else - echo "handshake ok" + # wait for handshake (first one can take ~10s) + HS="" + for i in $(seq 1 10); do + HS=$(nsexec wg show "$WG" latest-handshakes 2>/dev/null | awk '{print $2}') + if [ -n "$HS" ] && [ "$HS" != "0" ]; then break; fi + sleep 2 + done + if [ -z "$HS" ] || [ "$HS" = "0" ]; then + echo "no handshake yet (endpoint=$ENDPOINT)" + else + echo "handshake ok" + fi + EGRESS=$(nsexec curl -sk --max-time 15 'https://1.1.1.1/cdn-cgi/trace' 2>/dev/null | grep -oP '^ip=\K.*' || true) fi -EGRESS=$(nsexec curl -sk --max-time 15 'https://1.1.1.1/cdn-cgi/trace' 2>/dev/null | grep -oP '^ip=\K.*' || true) echo "node=$NODE netns=$NETNS ifaces=$WG/$VETH egress=${EGRESS:-unknown}"