Commit Graph

2304 Commits

Author SHA1 Message Date
世界
63d9af04ac dns: use refcounted snapshot to narrow rule lock scope
Exchange and Lookup held rulesAccess.RLock across all DNS network I/O,
blocking rebuildRules from swapping in new rules until every in-flight
query finished. Replace the RWMutex with an atomic pointer to a
refcounted rulesSnapshot so queries only hold a snapshot reference
during execution, allowing concurrent rule rebuilds.
2026-04-07 00:54:44 +08:00
世界
663b70d860 dns: serialize rebuilds and keep last good rules on failure 2026-04-07 00:54:44 +08:00
世界
9127a29164 docs: fix grammar errors and typos 2026-04-07 00:54:43 +08:00
世界
d710461ba0 Suppress SA1019 lint warnings for intentional deprecated field usage 2026-04-07 00:54:43 +08:00
世界
18af3d61fb docs: add evaluate action, response matching fields, and deprecation notices 2026-04-07 00:54:42 +08:00
世界
f5b58215fc Use typed SVCB hint structs instead of string parsing 2026-04-07 00:54:42 +08:00
世界
6821d44f8b option: reject nested rule actions 2026-04-07 00:54:42 +08:00
世界
1495f24e60 dns: make rule strategy legacy-only 2026-04-07 00:54:42 +08:00
世界
8d44f52233 Make DNS match_response fail as a normal condition 2026-04-07 00:54:42 +08:00
世界
7ae1eaa403 Fix DNS rule-set ref handling 2026-04-07 00:54:42 +08:00
世界
7257fa590e Fix legacy DNS rule_set accept_empty matching 2026-04-07 00:54:42 +08:00
世界
c52ae06a4a dns: restore lookup reject semantics 2026-04-07 00:54:41 +08:00
世界
7f64980ea3 Fix DNS record parser file inclusion and rule match log index
Remove SetIncludeAllowed(true) from the DNS record zone parser.
The $INCLUDE directive allows opening arbitrary files via os.Open,
which is unnecessary and dangerous when parsing a single record string
from configuration (especially remote profiles).

Fix displayRuleIndex arithmetic in dns/router.go that computed
2*index+1 instead of the correct 0-based index. This was a
reintroduction of a bug previously fixed in be8ee370a. Both
matchDNS and logRuleMatch now use the index directly, matching
the pattern in route/route.go.
2026-04-07 00:54:41 +08:00
世界
4ea33a00b1 Fix DNS record parsing and shutdown race 2026-04-07 00:54:41 +08:00
世界
db7655e7d3 dns: restore init validation and fix rule-set query type 2026-04-07 00:54:41 +08:00
世界
60c9f02fb4 dns: make rule path selection rule-set aware 2026-04-07 00:54:41 +08:00
世界
58f9933f14 dns: complete lookup rule execution in new mode 2026-04-07 00:54:41 +08:00
世界
3803c0f8de Fix legacy DNS negation expansion 2026-04-07 00:54:41 +08:00
世界
a5c3201140 dns: isolate legacy pre-match semantics 2026-04-07 00:54:40 +08:00
世界
0893488073 dns: preserve legacy address-filter pre-match semantics
Legacy DNS address-filter mode still accepts destination-side IP
predicates with a deprecation warning, but the recent evaluate/
match_response refactor started evaluating those predicates during
pre-response Match(). That broke rules whose transport selection must
be deferred until MatchAddressLimit() can inspect the upstream reply.

Restore the old defer behavior by reintroducing an internal
IgnoreDestinationIPCIDRMatch flag on InboundContext and using it only
for legacy pre-response DNS matching. Default and logical DNS rules now
carry the legacy mode bit, set the ignore flag on metadata copies while
performing pre-response Match(), and explicitly clear it again for
match_response and MatchAddressLimit() so response-phase matching still
checks the returned addresses.

Add regression coverage for direct legacy destination-IP rules,
rule_set-backed CIDR rules, logical wrappers, and the legacy Lookup
router path, including fallback after a rejected response. This keeps
legacy configs working without changing new-mode evaluate semantics.

Tests: go test ./route/rule ./dns
Tests: make
2026-04-07 00:54:40 +08:00
世界
01079a2483 Remove legacy DNS server formats 2026-04-07 00:54:40 +08:00
世界
618dcc5aac dns: document non-response rule_set address-filter semantics 2026-04-07 00:54:40 +08:00
世界
de73486d21 Fix DNS pre-match CIDR fail-closed semantics 2026-04-07 00:54:40 +08:00
世界
312221eaf0 Fix DNS evaluate regressions 2026-04-07 00:54:40 +08:00
世界
097e75cc02 dns: use response-only address matching 2026-04-07 00:54:40 +08:00
世界
ae65281254 Fix DNS match_response response address handling 2026-04-07 00:54:39 +08:00
世界
81a06dd324 Fix DNS record parsing and matching regressions 2026-04-07 00:54:39 +08:00
世界
801366059c Fix DNS evaluate routing regressions 2026-04-07 00:54:39 +08:00
世界
8cedfdbad7 Reorder DNS rule item fields: match_response above address filter and response items, deprecated fields at bottom 2026-04-07 00:54:39 +08:00
世界
2d08d34e0b Add evaluate DNS rule action and related rule items 2026-04-07 00:54:39 +08:00
世界
00ec31142f Bump version v1.14.0-alpha.9 2026-04-06 23:39:52 +08:00
世界
83a0b44659 platform: Add OOM Report & Crash Rerport 2026-04-06 23:36:06 +08:00
世界
95fd74a9f9 Add BBR profile and hop interval randomization for Hysteria2 2026-04-06 23:36:06 +08:00
nekohasekai
d98ab6f1b8 Refactor ACME support to certificate provider 2026-04-06 23:36:05 +08:00
世界
b1379a23a5 cronet-go: Update chromium to 145.0.7632.159 2026-04-06 23:36:05 +08:00
世界
c79a3a81e7 documentation: Update descriptions for neighbor rules 2026-04-06 23:36:05 +08:00
世界
18e64323ef Add macOS support for MAC and hostname rule items 2026-04-06 23:36:05 +08:00
世界
594932a226 Add Android support for MAC and hostname rule items 2026-04-06 23:36:05 +08:00
世界
793ad6ffc5 Add MAC and hostname rule items 2026-04-06 23:36:05 +08:00
世界
813b634d08 Bump version v1.13.6 2026-04-06 23:09:11 +08:00
hdrover
d9b435fb62 Fix naive inbound padding bytes 2026-04-06 22:33:11 +08:00
世界
354b4b040e sing: Fix vectorised readv iovec length calculation
This does not seem to affect any actual paths in the sing-box.
2026-04-01 16:16:58 +08:00
世界
7ffdc48b49 Bump version v1.13.5 2026-03-30 23:03:43 +08:00
世界
e15bdf11eb sing: Minor fixes 2026-03-30 22:58:11 +08:00
世界
e3bcb06c3e platform: Add HTTPResponse.WriteToWithProgress 2026-03-30 22:42:36 +08:00
世界
84d2280960 quic: Fix protocol client close & Sync hysteria bbr fix 2026-03-30 22:42:36 +08:00
世界
4fd2532b0a Fix naive quic error message 2026-03-30 22:42:36 +08:00
Zhengchao Ding
02ccde6c71 fix(rpm): add vendor field to fpm config to avoid (none) vendor
Co-authored-by: Hyper <hypar@disroot.org>
2026-03-30 22:09:54 +08:00
世界
e98b4ad449 Fix WireGuard shutdown race crashing
Stop peer goroutines before closing the TUN device to prevent
RoutineSequentialReceiver from calling Write on a nil dispatcher.
2026-03-26 16:33:21 +08:00
世界
d09182614c Bump version v1.13.4 2026-03-26 13:28:33 +08:00