I am kindof curious if Tinc could leverage Wireguard for the encryption. Everything else is in user-space so I think it should just be wg vs tun and a config option and do all the dynamic mesh routing on top of wg, but it would be nice if the maintainer could chime in.
I (not a tinc maintainer, but a tinc contributor) have replied to this in the past [0]. Summary: it's not really possible without giving up some flexibility.
Makes sense. Not sure how I missed your comment in the past as I've always been curious if it could be done. Thankyou for answering that. I'm fine with Tinc's performance for my use cases.
Tailscale gets pretty good performance using Wireguard in userspace, with some very clever use of the tun/tap device like supporting TCP segmentation offload. Does (or could) tinc use the same tricks?
The draw of wireguard, for me, is that I can build it into my kernel. No weird issues starting it at boot, no missing libraries, etc.
And you can use wg interface as another standard network interface.
This is true of tinc interfaces too, in the appropriate mode.