mirror of
https://github.com/SagerNet/sing-box.git
synced 2026-04-14 04:38:28 +10:00
Compare commits
255 Commits
v1.13.0-be
...
cloudflare
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1f1ba549fd | ||
|
|
813b634d08 | ||
|
|
d9b435fb62 | ||
|
|
354b4b040e | ||
|
|
7ffdc48b49 | ||
|
|
e15bdf11eb | ||
|
|
e3bcb06c3e | ||
|
|
84d2280960 | ||
|
|
4fd2532b0a | ||
|
|
02ccde6c71 | ||
|
|
e98b4ad449 | ||
|
|
d09182614c | ||
|
|
6381de7bab | ||
|
|
b0c6762bc1 | ||
|
|
7425100bac | ||
|
|
d454aa0fdf | ||
|
|
a3623eb41a | ||
|
|
72bc4c1f87 | ||
|
|
9ac1e2ff32 | ||
|
|
0045103d14 | ||
|
|
d2a933784c | ||
|
|
3f05a37f65 | ||
|
|
b8e5a71450 | ||
|
|
c13faa8e3c | ||
|
|
7623bcd19e | ||
|
|
795d1c2892 | ||
|
|
6913b11e0a | ||
|
|
1e57c06295 | ||
|
|
ea464cef8d | ||
|
|
a8e3cd3256 | ||
|
|
686cf1f304 | ||
|
|
9fbfb87723 | ||
|
|
d2fa21d07b | ||
|
|
d3768cca36 | ||
|
|
0889ddd001 | ||
|
|
f46fbf188a | ||
|
|
f2d15139f5 | ||
|
|
041646b728 | ||
|
|
b990de2e12 | ||
|
|
fe585157d2 | ||
|
|
eed6a36e5d | ||
|
|
eb0f38544c | ||
|
|
54468a1a2a | ||
|
|
8289bbd846 | ||
|
|
49c450d942 | ||
|
|
a7ee943216 | ||
|
|
8bb4c4dd32 | ||
|
|
67621ee6ba | ||
|
|
a09ffe6a0f | ||
|
|
e0be8743f6 | ||
|
|
0b04528803 | ||
|
|
65875e6dac | ||
|
|
4d6fb1d38d | ||
|
|
305b930d90 | ||
|
|
bc3884ca91 | ||
|
|
df0bf927e4 | ||
|
|
efe20ea51c | ||
|
|
e21a72fcd1 | ||
|
|
e1477bd065 | ||
|
|
aa495fce38 | ||
|
|
9cd60c28c0 | ||
|
|
2ba896c5ac | ||
|
|
1d388547ee | ||
|
|
e343cec4d5 | ||
|
|
d58efc5d01 | ||
|
|
4b26ab16fb | ||
|
|
0e27312eda | ||
|
|
4e0a953b98 | ||
|
|
27c5b0b1af | ||
|
|
84019b06d9 | ||
|
|
7fd21f8bf4 | ||
|
|
88695b0d1f | ||
|
|
fb269c9032 | ||
|
|
e62dc7bfa2 | ||
|
|
f295e195b5 | ||
|
|
ab76062a41 | ||
|
|
d14417d392 | ||
|
|
96c5c27610 | ||
|
|
91f92bee49 | ||
|
|
1803471e02 | ||
|
|
3de56d344e | ||
|
|
c71abbdfb8 | ||
|
|
ed15121e95 | ||
|
|
46c6945da5 | ||
|
|
1beb4cb002 | ||
|
|
4c65fea1ac | ||
|
|
8ae93a98e5 | ||
|
|
6da7e538e1 | ||
|
|
13e6ba4cb2 | ||
|
|
93b7328c3f | ||
|
|
11dc5bcbe1 | ||
|
|
fa3ab87b11 | ||
|
|
9bd9e9a58b | ||
|
|
9d6dee7451 | ||
|
|
9c2cdc7203 | ||
|
|
65150f5cc3 | ||
|
|
21a1512e6c | ||
|
|
cf4791f1ad | ||
|
|
0bc66e5a56 | ||
|
|
d48236da94 | ||
|
|
4c05d7b888 | ||
|
|
94ed42caf1 | ||
|
|
e0c18cc3d4 | ||
|
|
0817c25f4c | ||
|
|
7745a97cca | ||
|
|
9bcd715d31 | ||
|
|
6a95c66bc7 | ||
|
|
b5800847ae | ||
|
|
aa85cbb86e | ||
|
|
c59991420e | ||
|
|
c0304b8362 | ||
|
|
d1f1271a02 | ||
|
|
de4fdbe553 | ||
|
|
804606042f | ||
|
|
53f2db3f97 | ||
|
|
1f2fdec89d | ||
|
|
8714c157c9 | ||
|
|
657fba4ca5 | ||
|
|
0a69621207 | ||
|
|
58ccf82e0b | ||
|
|
ceab244329 | ||
|
|
58fcdceca2 | ||
|
|
98af3c0ad6 | ||
|
|
172a9d5e4e | ||
|
|
aba8346bd6 | ||
|
|
d8e269e0ac | ||
|
|
c45ea8dfac | ||
|
|
a2d313c59b | ||
|
|
15722b06dd | ||
|
|
d230dae0a5 | ||
|
|
e11dbf3a8e | ||
|
|
baa9f29f0d | ||
|
|
55b6e7dbfe | ||
|
|
a05e05a47c | ||
|
|
c1dc6cb0fb | ||
|
|
432fe1b3c9 | ||
|
|
8dd8897fd8 | ||
|
|
ff58edb1c1 | ||
|
|
79bab39502 | ||
|
|
a4d5d59901 | ||
|
|
1af14a0237 | ||
|
|
944a9986d9 | ||
|
|
60a1e4c866 | ||
|
|
5d67c131fa | ||
|
|
b9cc87d35a | ||
|
|
490d501257 | ||
|
|
725e4adc46 | ||
|
|
4a14d39cad | ||
|
|
8ec58c96f5 | ||
|
|
e8450b2e61 | ||
|
|
30c3855e4b | ||
|
|
ccf90aee8a | ||
|
|
e6c03fd448 | ||
|
|
e0f1cdf464 | ||
|
|
8d88c6532f | ||
|
|
3890bd2be7 | ||
|
|
6cd1eb9b94 | ||
|
|
f196b7a583 | ||
|
|
bd9935eebb | ||
|
|
0e0e838ff5 | ||
|
|
0caebd3171 | ||
|
|
7d2944eba9 | ||
|
|
a5db2feb5e | ||
|
|
708ceb3d29 | ||
|
|
157e33f2a4 | ||
|
|
1d4fb83313 | ||
|
|
85f5f6cebb | ||
|
|
6a750f4522 | ||
|
|
46c2cc37c3 | ||
|
|
aa8dd6e44f | ||
|
|
4e94a64dcc | ||
|
|
494990f914 | ||
|
|
95ccb837d3 | ||
|
|
24b33a43fc | ||
|
|
8ae16aa452 | ||
|
|
bf4a9edc89 | ||
|
|
78b4eac974 | ||
|
|
a34868468f | ||
|
|
e392c70b6f | ||
|
|
511d1bb3fa | ||
|
|
4273ffa77e | ||
|
|
f5ccf746ea | ||
|
|
b2d90b7d86 | ||
|
|
e0a78fde07 | ||
|
|
203f4134b0 | ||
|
|
c2b697a778 | ||
|
|
ddec2ab282 | ||
|
|
35ff7d1fb4 | ||
|
|
cba18635c8 | ||
|
|
0d8c7a9c5d | ||
|
|
faff3174a3 | ||
|
|
2fc1b672cc | ||
|
|
143983b585 | ||
|
|
4afdf4153a | ||
|
|
750dc9c3e0 | ||
|
|
48b7adde7d | ||
|
|
0585f6d065 | ||
|
|
8101a7b0bd | ||
|
|
e8620587dd | ||
|
|
a89680fa2d | ||
|
|
b919039c43 | ||
|
|
9b0960bb5a | ||
|
|
ad7b982242 | ||
|
|
7e68013b05 | ||
|
|
ac427b98f4 | ||
|
|
a5fb467db2 | ||
|
|
a930356b04 | ||
|
|
5bc0dfa9dd | ||
|
|
743b460e51 | ||
|
|
8d8ca282a1 | ||
|
|
cd56eaaba2 | ||
|
|
e92938364d | ||
|
|
1c4614318e | ||
|
|
0f5cda4169 | ||
|
|
d87c9fd242 | ||
|
|
fce21607bd | ||
|
|
3dc285be8c | ||
|
|
79bbce3db3 | ||
|
|
dfd95b2615 | ||
|
|
ab0869c972 | ||
|
|
9ac0539ffd | ||
|
|
cb4deb0c20 | ||
|
|
6b90b61358 | ||
|
|
ed1ee4c3a4 | ||
|
|
7f3ea8dbd8 | ||
|
|
12b055989b | ||
|
|
49056b5060 | ||
|
|
c530995832 | ||
|
|
60d81a73d9 | ||
|
|
e9c46cc359 | ||
|
|
9110851af3 | ||
|
|
107f92381b | ||
|
|
f84129ca79 | ||
|
|
44fafcef73 | ||
|
|
a5e09fcd43 | ||
|
|
387b42c9c2 | ||
|
|
044eb728cb | ||
|
|
2be8a45f14 | ||
|
|
1336987756 | ||
|
|
e3473d3de0 | ||
|
|
bba92146b1 | ||
|
|
48f84b31d6 | ||
|
|
1c846df903 | ||
|
|
0bd98a300f | ||
|
|
87eaf3ce6e | ||
|
|
239e6ec701 | ||
|
|
5be1887f92 | ||
|
|
65264afdf9 | ||
|
|
fecdbf20de | ||
|
|
1f03080540 | ||
|
|
737162e75a | ||
|
|
51ce402dbb | ||
|
|
8b404b5a4c | ||
|
|
3ce94d50dd | ||
|
|
29d56fca9c |
23
.fpm_pacman
Normal file
23
.fpm_pacman
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
-s dir
|
||||||
|
--name sing-box
|
||||||
|
--category net
|
||||||
|
--license GPL-3.0-or-later
|
||||||
|
--description "The universal proxy platform."
|
||||||
|
--url "https://sing-box.sagernet.org/"
|
||||||
|
--maintainer "nekohasekai <contact-git@sekai.icu>"
|
||||||
|
--config-files etc/sing-box/config.json
|
||||||
|
--after-install release/config/sing-box.postinst
|
||||||
|
|
||||||
|
release/config/config.json=/etc/sing-box/config.json
|
||||||
|
|
||||||
|
release/config/sing-box.service=/usr/lib/systemd/system/sing-box.service
|
||||||
|
release/config/sing-box@.service=/usr/lib/systemd/system/sing-box@.service
|
||||||
|
release/config/sing-box.sysusers=/usr/lib/sysusers.d/sing-box.conf
|
||||||
|
release/config/sing-box.rules=usr/share/polkit-1/rules.d/sing-box.rules
|
||||||
|
release/config/sing-box-split-dns.xml=/usr/share/dbus-1/system.d/sing-box-split-dns.conf
|
||||||
|
|
||||||
|
release/completions/sing-box.bash=/usr/share/bash-completion/completions/sing-box.bash
|
||||||
|
release/completions/sing-box.fish=/usr/share/fish/vendor_completions.d/sing-box.fish
|
||||||
|
release/completions/sing-box.zsh=/usr/share/zsh/site-functions/_sing-box
|
||||||
|
|
||||||
|
LICENSE=/usr/share/licenses/sing-box/LICENSE
|
||||||
@@ -4,6 +4,7 @@
|
|||||||
--license GPL-3.0-or-later
|
--license GPL-3.0-or-later
|
||||||
--description "The universal proxy platform."
|
--description "The universal proxy platform."
|
||||||
--url "https://sing-box.sagernet.org/"
|
--url "https://sing-box.sagernet.org/"
|
||||||
|
--vendor SagerNet
|
||||||
--maintainer "nekohasekai <contact-git@sekai.icu>"
|
--maintainer "nekohasekai <contact-git@sekai.icu>"
|
||||||
--deb-field "Bug: https://github.com/SagerNet/sing-box/issues"
|
--deb-field "Bug: https://github.com/SagerNet/sing-box/issues"
|
||||||
--no-deb-generate-changes
|
--no-deb-generate-changes
|
||||||
|
|||||||
2
.github/CRONET_GO_VERSION
vendored
2
.github/CRONET_GO_VERSION
vendored
@@ -1 +1 @@
|
|||||||
92d4602aba0ab6084673af0fe4887dccbc1049a5
|
2fef65f9dba90ddb89a87d00a6eb6165487c10c1
|
||||||
|
|||||||
81
.github/build_alpine_apk.sh
vendored
Executable file
81
.github/build_alpine_apk.sh
vendored
Executable file
@@ -0,0 +1,81 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -e -o pipefail
|
||||||
|
|
||||||
|
ARCHITECTURE="$1"
|
||||||
|
VERSION="$2"
|
||||||
|
BINARY_PATH="$3"
|
||||||
|
OUTPUT_PATH="$4"
|
||||||
|
|
||||||
|
if [ -z "$ARCHITECTURE" ] || [ -z "$VERSION" ] || [ -z "$BINARY_PATH" ] || [ -z "$OUTPUT_PATH" ]; then
|
||||||
|
echo "Usage: $0 <architecture> <version> <binary_path> <output_path>"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
PROJECT=$(cd "$(dirname "$0")/.."; pwd)
|
||||||
|
|
||||||
|
# Convert version to APK format:
|
||||||
|
# 1.13.0-beta.8 -> 1.13.0_beta8-r0
|
||||||
|
# 1.13.0-rc.3 -> 1.13.0_rc3-r0
|
||||||
|
# 1.13.0 -> 1.13.0-r0
|
||||||
|
APK_VERSION=$(echo "$VERSION" | sed -E 's/-([a-z]+)\.([0-9]+)/_\1\2/')
|
||||||
|
APK_VERSION="${APK_VERSION}-r0"
|
||||||
|
|
||||||
|
ROOT_DIR=$(mktemp -d)
|
||||||
|
trap 'rm -rf "$ROOT_DIR"' EXIT
|
||||||
|
|
||||||
|
# Binary
|
||||||
|
install -Dm755 "$BINARY_PATH" "$ROOT_DIR/usr/bin/sing-box"
|
||||||
|
|
||||||
|
# Config files
|
||||||
|
install -Dm644 "$PROJECT/release/config/config.json" "$ROOT_DIR/etc/sing-box/config.json"
|
||||||
|
install -Dm755 "$PROJECT/release/config/sing-box.initd" "$ROOT_DIR/etc/init.d/sing-box"
|
||||||
|
install -Dm644 "$PROJECT/release/config/sing-box.confd" "$ROOT_DIR/etc/conf.d/sing-box"
|
||||||
|
|
||||||
|
# Service files
|
||||||
|
install -Dm644 "$PROJECT/release/config/sing-box.service" "$ROOT_DIR/usr/lib/systemd/system/sing-box.service"
|
||||||
|
install -Dm644 "$PROJECT/release/config/sing-box@.service" "$ROOT_DIR/usr/lib/systemd/system/sing-box@.service"
|
||||||
|
|
||||||
|
# Completions
|
||||||
|
install -Dm644 "$PROJECT/release/completions/sing-box.bash" "$ROOT_DIR/usr/share/bash-completion/completions/sing-box.bash"
|
||||||
|
install -Dm644 "$PROJECT/release/completions/sing-box.fish" "$ROOT_DIR/usr/share/fish/vendor_completions.d/sing-box.fish"
|
||||||
|
install -Dm644 "$PROJECT/release/completions/sing-box.zsh" "$ROOT_DIR/usr/share/zsh/site-functions/_sing-box"
|
||||||
|
|
||||||
|
# License
|
||||||
|
install -Dm644 "$PROJECT/LICENSE" "$ROOT_DIR/usr/share/licenses/sing-box/LICENSE"
|
||||||
|
|
||||||
|
# APK metadata
|
||||||
|
PACKAGES_DIR="$ROOT_DIR/lib/apk/packages"
|
||||||
|
mkdir -p "$PACKAGES_DIR"
|
||||||
|
|
||||||
|
# .conffiles
|
||||||
|
cat > "$PACKAGES_DIR/.conffiles" <<'EOF'
|
||||||
|
/etc/conf.d/sing-box
|
||||||
|
/etc/init.d/sing-box
|
||||||
|
/etc/sing-box/config.json
|
||||||
|
EOF
|
||||||
|
|
||||||
|
# .conffiles_static (sha256 checksums)
|
||||||
|
while IFS= read -r conffile; do
|
||||||
|
sha256=$(sha256sum "$ROOT_DIR$conffile" | cut -d' ' -f1)
|
||||||
|
echo "$conffile $sha256"
|
||||||
|
done < "$PACKAGES_DIR/.conffiles" > "$PACKAGES_DIR/.conffiles_static"
|
||||||
|
|
||||||
|
# .list (all files, excluding lib/apk/packages/ metadata)
|
||||||
|
(cd "$ROOT_DIR" && find . -type f -o -type l) \
|
||||||
|
| sed 's|^\./|/|' \
|
||||||
|
| grep -v '^/lib/apk/packages/' \
|
||||||
|
| sort > "$PACKAGES_DIR/.list"
|
||||||
|
|
||||||
|
# Build APK
|
||||||
|
apk mkpkg \
|
||||||
|
--info "name:sing-box" \
|
||||||
|
--info "version:${APK_VERSION}" \
|
||||||
|
--info "description:The universal proxy platform." \
|
||||||
|
--info "arch:${ARCHITECTURE}" \
|
||||||
|
--info "license:GPL-3.0-or-later with name use or association addition" \
|
||||||
|
--info "origin:sing-box" \
|
||||||
|
--info "url:https://sing-box.sagernet.org/" \
|
||||||
|
--info "maintainer:nekohasekai <contact-git@sekai.icu>" \
|
||||||
|
--files "$ROOT_DIR" \
|
||||||
|
--output "$OUTPUT_PATH"
|
||||||
80
.github/build_openwrt_apk.sh
vendored
Executable file
80
.github/build_openwrt_apk.sh
vendored
Executable file
@@ -0,0 +1,80 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -e -o pipefail
|
||||||
|
|
||||||
|
ARCHITECTURE="$1"
|
||||||
|
VERSION="$2"
|
||||||
|
BINARY_PATH="$3"
|
||||||
|
OUTPUT_PATH="$4"
|
||||||
|
|
||||||
|
if [ -z "$ARCHITECTURE" ] || [ -z "$VERSION" ] || [ -z "$BINARY_PATH" ] || [ -z "$OUTPUT_PATH" ]; then
|
||||||
|
echo "Usage: $0 <architecture> <version> <binary_path> <output_path>"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
PROJECT=$(cd "$(dirname "$0")/.."; pwd)
|
||||||
|
|
||||||
|
# Convert version to APK format:
|
||||||
|
# 1.13.0-beta.8 -> 1.13.0_beta8-r0
|
||||||
|
# 1.13.0-rc.3 -> 1.13.0_rc3-r0
|
||||||
|
# 1.13.0 -> 1.13.0-r0
|
||||||
|
APK_VERSION=$(echo "$VERSION" | sed -E 's/-([a-z]+)\.([0-9]+)/_\1\2/')
|
||||||
|
APK_VERSION="${APK_VERSION}-r0"
|
||||||
|
|
||||||
|
ROOT_DIR=$(mktemp -d)
|
||||||
|
trap 'rm -rf "$ROOT_DIR"' EXIT
|
||||||
|
|
||||||
|
# Binary
|
||||||
|
install -Dm755 "$BINARY_PATH" "$ROOT_DIR/usr/bin/sing-box"
|
||||||
|
|
||||||
|
# Config files
|
||||||
|
install -Dm644 "$PROJECT/release/config/config.json" "$ROOT_DIR/etc/sing-box/config.json"
|
||||||
|
install -Dm644 "$PROJECT/release/config/openwrt.conf" "$ROOT_DIR/etc/config/sing-box"
|
||||||
|
install -Dm755 "$PROJECT/release/config/openwrt.init" "$ROOT_DIR/etc/init.d/sing-box"
|
||||||
|
install -Dm644 "$PROJECT/release/config/openwrt.keep" "$ROOT_DIR/lib/upgrade/keep.d/sing-box"
|
||||||
|
|
||||||
|
# Completions
|
||||||
|
install -Dm644 "$PROJECT/release/completions/sing-box.bash" "$ROOT_DIR/usr/share/bash-completion/completions/sing-box.bash"
|
||||||
|
install -Dm644 "$PROJECT/release/completions/sing-box.fish" "$ROOT_DIR/usr/share/fish/vendor_completions.d/sing-box.fish"
|
||||||
|
install -Dm644 "$PROJECT/release/completions/sing-box.zsh" "$ROOT_DIR/usr/share/zsh/site-functions/_sing-box"
|
||||||
|
|
||||||
|
# License
|
||||||
|
install -Dm644 "$PROJECT/LICENSE" "$ROOT_DIR/usr/share/licenses/sing-box/LICENSE"
|
||||||
|
|
||||||
|
# APK metadata
|
||||||
|
PACKAGES_DIR="$ROOT_DIR/lib/apk/packages"
|
||||||
|
mkdir -p "$PACKAGES_DIR"
|
||||||
|
|
||||||
|
# .conffiles
|
||||||
|
cat > "$PACKAGES_DIR/.conffiles" <<'EOF'
|
||||||
|
/etc/config/sing-box
|
||||||
|
/etc/sing-box/config.json
|
||||||
|
EOF
|
||||||
|
|
||||||
|
# .conffiles_static (sha256 checksums)
|
||||||
|
while IFS= read -r conffile; do
|
||||||
|
sha256=$(sha256sum "$ROOT_DIR$conffile" | cut -d' ' -f1)
|
||||||
|
echo "$conffile $sha256"
|
||||||
|
done < "$PACKAGES_DIR/.conffiles" > "$PACKAGES_DIR/.conffiles_static"
|
||||||
|
|
||||||
|
# .list (all files, excluding lib/apk/packages/ metadata)
|
||||||
|
(cd "$ROOT_DIR" && find . -type f -o -type l) \
|
||||||
|
| sed 's|^\./|/|' \
|
||||||
|
| grep -v '^/lib/apk/packages/' \
|
||||||
|
| sort > "$PACKAGES_DIR/.list"
|
||||||
|
|
||||||
|
# Build APK
|
||||||
|
apk mkpkg \
|
||||||
|
--info "name:sing-box" \
|
||||||
|
--info "version:${APK_VERSION}" \
|
||||||
|
--info "description:The universal proxy platform." \
|
||||||
|
--info "arch:${ARCHITECTURE}" \
|
||||||
|
--info "license:GPL-3.0-or-later" \
|
||||||
|
--info "origin:sing-box" \
|
||||||
|
--info "url:https://sing-box.sagernet.org/" \
|
||||||
|
--info "maintainer:nekohasekai <contact-git@sekai.icu>" \
|
||||||
|
--info "depends:ca-bundle kmod-inet-diag kmod-tun firewall4 kmod-nft-queue" \
|
||||||
|
--info "provider-priority:100" \
|
||||||
|
--script "pre-deinstall:${PROJECT}/release/config/openwrt.prerm" \
|
||||||
|
--files "$ROOT_DIR" \
|
||||||
|
--output "$OUTPUT_PATH"
|
||||||
33
.github/detect_track.sh
vendored
Executable file
33
.github/detect_track.sh
vendored
Executable file
@@ -0,0 +1,33 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
branches=$(git branch -r --contains HEAD)
|
||||||
|
if echo "$branches" | grep -q 'origin/stable'; then
|
||||||
|
track=stable
|
||||||
|
elif echo "$branches" | grep -q 'origin/testing'; then
|
||||||
|
track=testing
|
||||||
|
elif echo "$branches" | grep -q 'origin/oldstable'; then
|
||||||
|
track=oldstable
|
||||||
|
else
|
||||||
|
echo "ERROR: HEAD is not on any known release branch (stable/testing/oldstable)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$track" == "stable" ]]; then
|
||||||
|
tag=$(git describe --tags --exact-match HEAD 2>/dev/null || true)
|
||||||
|
if [[ -n "$tag" && "$tag" == *"-"* ]]; then
|
||||||
|
track=beta
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
case "$track" in
|
||||||
|
stable) name=sing-box; docker_tag=latest ;;
|
||||||
|
beta) name=sing-box-beta; docker_tag=latest-beta ;;
|
||||||
|
testing) name=sing-box-testing; docker_tag=latest-testing ;;
|
||||||
|
oldstable) name=sing-box-oldstable; docker_tag=latest-oldstable ;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
echo "track=${track} name=${name} docker_tag=${docker_tag}" >&2
|
||||||
|
echo "TRACK=${track}" >> "$GITHUB_ENV"
|
||||||
|
echo "NAME=${name}" >> "$GITHUB_ENV"
|
||||||
|
echo "DOCKER_TAG=${docker_tag}" >> "$GITHUB_ENV"
|
||||||
2
.github/renovate.json
vendored
2
.github/renovate.json
vendored
@@ -6,7 +6,7 @@
|
|||||||
":disableRateLimiting"
|
":disableRateLimiting"
|
||||||
],
|
],
|
||||||
"baseBranches": [
|
"baseBranches": [
|
||||||
"dev-next"
|
"unstable"
|
||||||
],
|
],
|
||||||
"golang": {
|
"golang": {
|
||||||
"enabled": false
|
"enabled": false
|
||||||
|
|||||||
45
.github/setup_go_for_macos1013.sh
vendored
Executable file
45
.github/setup_go_for_macos1013.sh
vendored
Executable file
@@ -0,0 +1,45 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
VERSION="1.25.8"
|
||||||
|
PATCH_COMMITS=(
|
||||||
|
"afe69d3cec1c6dcf0f1797b20546795730850070"
|
||||||
|
"1ed289b0cf87dc5aae9c6fe1aa5f200a83412938"
|
||||||
|
)
|
||||||
|
CURL_ARGS=(
|
||||||
|
-fL
|
||||||
|
--silent
|
||||||
|
--show-error
|
||||||
|
)
|
||||||
|
|
||||||
|
if [[ -n "${GITHUB_TOKEN:-}" ]]; then
|
||||||
|
CURL_ARGS+=(-H "Authorization: Bearer ${GITHUB_TOKEN}")
|
||||||
|
fi
|
||||||
|
|
||||||
|
mkdir -p "$HOME/go"
|
||||||
|
cd "$HOME/go"
|
||||||
|
wget "https://dl.google.com/go/go${VERSION}.darwin-arm64.tar.gz"
|
||||||
|
tar -xzf "go${VERSION}.darwin-arm64.tar.gz"
|
||||||
|
#cp -a go go_bootstrap
|
||||||
|
mv go go_osx
|
||||||
|
cd go_osx
|
||||||
|
|
||||||
|
# these patch URLs only work on golang1.25.x
|
||||||
|
# that means after golang1.26 release it must be changed
|
||||||
|
# see: https://github.com/SagerNet/go/commits/release-branch.go1.25/
|
||||||
|
# revert:
|
||||||
|
# 33d3f603c1: "cmd/link/internal/ld: use 12.0.0 OS/SDK versions for macOS linking"
|
||||||
|
# 937368f84e: "crypto/x509: change how we retrieve chains on darwin"
|
||||||
|
|
||||||
|
for patch_commit in "${PATCH_COMMITS[@]}"; do
|
||||||
|
curl "${CURL_ARGS[@]}" "https://github.com/SagerNet/go/commit/${patch_commit}.diff" | patch --verbose -p 1
|
||||||
|
done
|
||||||
|
|
||||||
|
# Rebuild is not needed: we build with CGO_ENABLED=1, so Apple's external
|
||||||
|
# linker handles LC_BUILD_VERSION via MACOSX_DEPLOYMENT_TARGET, and the
|
||||||
|
# stdlib (crypto/x509) is compiled from patched src automatically.
|
||||||
|
#cd src
|
||||||
|
#GOROOT_BOOTSTRAP="$HOME/go/go_bootstrap" ./make.bash
|
||||||
|
#cd ../..
|
||||||
|
#rm -rf go_bootstrap "go${VERSION}.darwin-arm64.tar.gz"
|
||||||
39
.github/setup_go_for_windows7.sh
vendored
39
.github/setup_go_for_windows7.sh
vendored
@@ -1,16 +1,35 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
VERSION="1.25.5"
|
set -euo pipefail
|
||||||
|
|
||||||
mkdir -p $HOME/go
|
VERSION="1.25.8"
|
||||||
cd $HOME/go
|
PATCH_COMMITS=(
|
||||||
|
"466f6c7a29bc098b0d4c987b803c779222894a11"
|
||||||
|
"1bdabae205052afe1dadb2ad6f1ba612cdbc532a"
|
||||||
|
"a90777dcf692dd2168577853ba743b4338721b06"
|
||||||
|
"f6bddda4e8ff58a957462a1a09562924d5f3d05c"
|
||||||
|
"bed309eff415bcb3c77dd4bc3277b682b89a388d"
|
||||||
|
"34b899c2fb39b092db4fa67c4417e41dc046be4b"
|
||||||
|
)
|
||||||
|
CURL_ARGS=(
|
||||||
|
-fL
|
||||||
|
--silent
|
||||||
|
--show-error
|
||||||
|
)
|
||||||
|
|
||||||
|
if [[ -n "${GITHUB_TOKEN:-}" ]]; then
|
||||||
|
CURL_ARGS+=(-H "Authorization: Bearer ${GITHUB_TOKEN}")
|
||||||
|
fi
|
||||||
|
|
||||||
|
mkdir -p "$HOME/go"
|
||||||
|
cd "$HOME/go"
|
||||||
wget "https://dl.google.com/go/go${VERSION}.linux-amd64.tar.gz"
|
wget "https://dl.google.com/go/go${VERSION}.linux-amd64.tar.gz"
|
||||||
tar -xzf "go${VERSION}.linux-amd64.tar.gz"
|
tar -xzf "go${VERSION}.linux-amd64.tar.gz"
|
||||||
mv go go_win7
|
mv go go_win7
|
||||||
cd go_win7
|
cd go_win7
|
||||||
|
|
||||||
# modify from https://github.com/restic/restic/issues/4636#issuecomment-1896455557
|
# modify from https://github.com/restic/restic/issues/4636#issuecomment-1896455557
|
||||||
# this patch file only works on golang1.25.x
|
# these patch URLs only work on golang1.25.x
|
||||||
# that means after golang1.26 release it must be changed
|
# that means after golang1.26 release it must be changed
|
||||||
# see: https://github.com/MetaCubeX/go/commits/release-branch.go1.25/
|
# see: https://github.com/MetaCubeX/go/commits/release-branch.go1.25/
|
||||||
# revert:
|
# revert:
|
||||||
@@ -18,10 +37,10 @@ cd go_win7
|
|||||||
# 7c1157f9544922e96945196b47b95664b1e39108: "net: remove sysSocket fallback for Windows 7"
|
# 7c1157f9544922e96945196b47b95664b1e39108: "net: remove sysSocket fallback for Windows 7"
|
||||||
# 48042aa09c2f878c4faa576948b07fe625c4707a: "syscall: remove Windows 7 console handle workaround"
|
# 48042aa09c2f878c4faa576948b07fe625c4707a: "syscall: remove Windows 7 console handle workaround"
|
||||||
# a17d959debdb04cd550016a3501dd09d50cd62e7: "runtime: always use LoadLibraryEx to load system libraries"
|
# a17d959debdb04cd550016a3501dd09d50cd62e7: "runtime: always use LoadLibraryEx to load system libraries"
|
||||||
|
# fixes:
|
||||||
|
# bed309eff415bcb3c77dd4bc3277b682b89a388d: "Fix os.RemoveAll not working on Windows7"
|
||||||
|
# 34b899c2fb39b092db4fa67c4417e41dc046be4b: "Revert \"os: remove 5ms sleep on Windows in (*Process).Wait\""
|
||||||
|
|
||||||
alias curl='curl -H "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}"'
|
for patch_commit in "${PATCH_COMMITS[@]}"; do
|
||||||
|
curl "${CURL_ARGS[@]}" "https://github.com/MetaCubeX/go/commit/${patch_commit}.diff" | patch --verbose -p 1
|
||||||
curl https://github.com/MetaCubeX/go/commit/8cb5472d94c34b88733a81091bd328e70ee565a4.diff | patch --verbose -p 1
|
done
|
||||||
curl https://github.com/MetaCubeX/go/commit/6788c4c6f9fafb56729bad6b660f7ee2272d699f.diff | patch --verbose -p 1
|
|
||||||
curl https://github.com/MetaCubeX/go/commit/a5b2168bb836ed9d6601c626f95e56c07923f906.diff | patch --verbose -p 1
|
|
||||||
curl https://github.com/MetaCubeX/go/commit/f56f1e23507e646c85243a71bde7b9629b2f970c.diff | patch --verbose -p 1
|
|
||||||
|
|||||||
2
.github/update_cronet.sh
vendored
2
.github/update_cronet.sh
vendored
@@ -10,4 +10,4 @@ git -C $PROJECTS/cronet-go fetch origin go
|
|||||||
go get -x github.com/sagernet/cronet-go/all@$(git -C $PROJECTS/cronet-go rev-parse origin/go)
|
go get -x github.com/sagernet/cronet-go/all@$(git -C $PROJECTS/cronet-go rev-parse origin/go)
|
||||||
go get -x github.com/sagernet/cronet-go@$(git -C $PROJECTS/cronet-go rev-parse origin/go)
|
go get -x github.com/sagernet/cronet-go@$(git -C $PROJECTS/cronet-go rev-parse origin/go)
|
||||||
go mod tidy
|
go mod tidy
|
||||||
git -C $PROJECTS/cronet-go rev-parse origin/HEAD > "$SCRIPT_DIR/CRONET_GO_VERSION"
|
git -C $PROJECTS/cronet-go rev-parse origin/go > "$SCRIPT_DIR/CRONET_GO_VERSION"
|
||||||
|
|||||||
13
.github/update_cronet_dev.sh
vendored
Executable file
13
.github/update_cronet_dev.sh
vendored
Executable file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -e -o pipefail
|
||||||
|
|
||||||
|
SCRIPT_DIR=$(dirname "$0")
|
||||||
|
PROJECTS=$SCRIPT_DIR/../..
|
||||||
|
|
||||||
|
git -C $PROJECTS/cronet-go fetch origin dev
|
||||||
|
git -C $PROJECTS/cronet-go fetch origin go_dev
|
||||||
|
go get -x github.com/sagernet/cronet-go/all@$(git -C $PROJECTS/cronet-go rev-parse origin/go_dev)
|
||||||
|
go get -x github.com/sagernet/cronet-go@$(git -C $PROJECTS/cronet-go rev-parse origin/go_dev)
|
||||||
|
go mod tidy
|
||||||
|
git -C $PROJECTS/cronet-go rev-parse origin/dev > "$SCRIPT_DIR/CRONET_GO_VERSION"
|
||||||
182
.github/workflows/build.yml
vendored
182
.github/workflows/build.yml
vendored
@@ -25,8 +25,9 @@ on:
|
|||||||
- publish-android
|
- publish-android
|
||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- main-next
|
- stable
|
||||||
- dev-next
|
- testing
|
||||||
|
- unstable
|
||||||
|
|
||||||
concurrency:
|
concurrency:
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}-${{ inputs.build }}
|
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}-${{ inputs.build }}
|
||||||
@@ -46,7 +47,7 @@ jobs:
|
|||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Check input version
|
- name: Check input version
|
||||||
if: github.event_name == 'workflow_dispatch'
|
if: github.event_name == 'workflow_dispatch'
|
||||||
run: |-
|
run: |-
|
||||||
@@ -71,33 +72,41 @@ jobs:
|
|||||||
include:
|
include:
|
||||||
- { os: linux, arch: amd64, variant: purego, naive: true }
|
- { os: linux, arch: amd64, variant: purego, naive: true }
|
||||||
- { os: linux, arch: amd64, variant: glibc, naive: true }
|
- { os: linux, arch: amd64, variant: glibc, naive: true }
|
||||||
- { os: linux, arch: amd64, variant: musl, naive: true, debian: amd64, rpm: x86_64, pacman: x86_64, openwrt: "x86_64" }
|
- { os: linux, arch: amd64, variant: musl, naive: true, debian: amd64, rpm: x86_64, pacman: x86_64, alpine: x86_64, openwrt: "x86_64" }
|
||||||
|
|
||||||
- { os: linux, arch: arm64, variant: purego, naive: true }
|
- { os: linux, arch: arm64, variant: purego, naive: true }
|
||||||
- { os: linux, arch: arm64, variant: glibc, naive: true }
|
- { os: linux, arch: arm64, variant: glibc, naive: true }
|
||||||
- { os: linux, arch: arm64, variant: musl, naive: true, debian: arm64, rpm: aarch64, pacman: aarch64, openwrt: "aarch64_cortex-a53 aarch64_cortex-a72 aarch64_cortex-a76 aarch64_generic" }
|
- { os: linux, arch: arm64, variant: musl, naive: true, debian: arm64, rpm: aarch64, pacman: aarch64, alpine: aarch64, openwrt: "aarch64_cortex-a53 aarch64_cortex-a72 aarch64_cortex-a76 aarch64_generic" }
|
||||||
|
|
||||||
- { os: linux, arch: "386", go386: sse2 }
|
- { os: linux, arch: "386", go386: sse2 }
|
||||||
- { os: linux, arch: "386", variant: glibc, naive: true, go386: sse2 }
|
- { os: linux, arch: "386", variant: glibc, naive: true, go386: sse2 }
|
||||||
- { os: linux, arch: "386", variant: musl, naive: true, go386: sse2, debian: i386, rpm: i386, openwrt: "i386_pentium4" }
|
- { os: linux, arch: "386", variant: musl, naive: true, go386: sse2, debian: i386, rpm: i386, alpine: x86, openwrt: "i386_pentium4" }
|
||||||
|
|
||||||
- { os: linux, arch: arm, goarm: "7" }
|
- { os: linux, arch: arm, goarm: "7" }
|
||||||
- { os: linux, arch: arm, variant: glibc, naive: true, goarm: "7" }
|
- { os: linux, arch: arm, variant: glibc, naive: true, goarm: "7" }
|
||||||
- { os: linux, arch: arm, variant: musl, naive: true, goarm: "7", debian: armhf, rpm: armv7hl, pacman: armv7hl, openwrt: "arm_cortex-a5_vfpv4 arm_cortex-a7_neon-vfpv4 arm_cortex-a7_vfpv4 arm_cortex-a8_vfpv3 arm_cortex-a9_neon arm_cortex-a9_vfpv3-d16 arm_cortex-a15_neon-vfpv4" }
|
- { os: linux, arch: arm, variant: musl, naive: true, goarm: "7", debian: armhf, rpm: armv7hl, pacman: armv7hl, alpine: armv7, openwrt: "arm_cortex-a5_vfpv4 arm_cortex-a7_neon-vfpv4 arm_cortex-a7_vfpv4 arm_cortex-a8_vfpv3 arm_cortex-a9_neon arm_cortex-a9_vfpv3-d16 arm_cortex-a15_neon-vfpv4" }
|
||||||
|
|
||||||
|
- { os: linux, arch: mipsle, gomips: hardfloat, naive: true, variant: glibc }
|
||||||
|
- { os: linux, arch: mipsle, gomips: softfloat, naive: true, variant: musl, debian: mipsel, rpm: mipsel, openwrt: "mipsel_24kc mipsel_74kc mipsel_mips32" }
|
||||||
|
- { os: linux, arch: mips64le, gomips: hardfloat, naive: true, variant: glibc, debian: mips64el, rpm: mips64el }
|
||||||
|
- { os: linux, arch: riscv64, naive: true, variant: glibc }
|
||||||
|
- { os: linux, arch: riscv64, naive: true, variant: musl, debian: riscv64, rpm: riscv64, alpine: riscv64, openwrt: "riscv64_generic" }
|
||||||
|
- { os: linux, arch: loong64, naive: true, variant: glibc }
|
||||||
|
- { os: linux, arch: loong64, naive: true, variant: musl, debian: loongarch64, rpm: loongarch64, alpine: loongarch64, openwrt: "loongarch64_generic" }
|
||||||
|
|
||||||
- { os: linux, arch: "386", go386: softfloat, openwrt: "i386_pentium-mmx" }
|
- { os: linux, arch: "386", go386: softfloat, openwrt: "i386_pentium-mmx" }
|
||||||
- { os: linux, arch: arm, goarm: "5", openwrt: "arm_arm926ej-s arm_cortex-a7 arm_cortex-a9 arm_fa526 arm_xscale" }
|
- { os: linux, arch: arm, goarm: "5", openwrt: "arm_arm926ej-s arm_cortex-a7 arm_cortex-a9 arm_fa526 arm_xscale" }
|
||||||
- { os: linux, arch: arm, goarm: "6", debian: armel, rpm: armv6hl, openwrt: "arm_arm1176jzf-s_vfp" }
|
- { os: linux, arch: arm, goarm: "6", debian: armel, rpm: armv6hl, openwrt: "arm_arm1176jzf-s_vfp" }
|
||||||
- { os: linux, arch: mips, gomips: softfloat, openwrt: "mips_24kc mips_4kec mips_mips32" }
|
- { os: linux, arch: mips, gomips: softfloat, openwrt: "mips_24kc mips_4kec mips_mips32" }
|
||||||
- { os: linux, arch: mipsle, gomips: hardfloat, debian: mipsel, rpm: mipsel, openwrt: "mipsel_24kc_24kf" }
|
- { os: linux, arch: mipsle, gomips: hardfloat, openwrt: "mipsel_24kc_24kf" }
|
||||||
- { os: linux, arch: mipsle, gomips: softfloat, openwrt: "mipsel_24kc mipsel_74kc mipsel_mips32" }
|
- { os: linux, arch: mipsle, gomips: softfloat }
|
||||||
- { os: linux, arch: mips64, gomips: softfloat, openwrt: "mips64_mips64r2 mips64_octeonplus" }
|
- { os: linux, arch: mips64, gomips: softfloat, openwrt: "mips64_mips64r2 mips64_octeonplus" }
|
||||||
- { os: linux, arch: mips64le, gomips: hardfloat, debian: mips64el, rpm: mips64el }
|
- { os: linux, arch: mips64le, gomips: hardfloat }
|
||||||
- { os: linux, arch: mips64le, gomips: softfloat, openwrt: "mips64el_mips64r2" }
|
- { os: linux, arch: mips64le, gomips: softfloat, openwrt: "mips64el_mips64r2" }
|
||||||
- { os: linux, arch: s390x, debian: s390x, rpm: s390x }
|
- { os: linux, arch: s390x, debian: s390x, rpm: s390x }
|
||||||
- { os: linux, arch: ppc64le, debian: ppc64el, rpm: ppc64le }
|
- { os: linux, arch: ppc64le, debian: ppc64el, rpm: ppc64le }
|
||||||
- { os: linux, arch: riscv64, debian: riscv64, rpm: riscv64, openwrt: "riscv64_generic" }
|
- { os: linux, arch: riscv64 }
|
||||||
- { os: linux, arch: loong64, debian: loongarch64, rpm: loongarch64, openwrt: "loongarch64_generic" }
|
- { os: linux, arch: loong64 }
|
||||||
|
|
||||||
- { os: windows, arch: amd64, legacy_win7: true, legacy_name: "windows-7" }
|
- { os: windows, arch: amd64, legacy_win7: true, legacy_name: "windows-7" }
|
||||||
- { os: windows, arch: "386", legacy_win7: true, legacy_name: "windows-7" }
|
- { os: windows, arch: "386", legacy_win7: true, legacy_name: "windows-7" }
|
||||||
@@ -112,15 +121,10 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
if: ${{ ! (matrix.legacy_win7 || matrix.legacy_go124) }}
|
if: ${{ ! matrix.legacy_win7 }}
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Setup Go 1.24
|
|
||||||
if: matrix.legacy_go124
|
|
||||||
uses: actions/setup-go@v5
|
|
||||||
with:
|
|
||||||
go-version: ~1.24.10
|
|
||||||
- name: Cache Go for Windows 7
|
- name: Cache Go for Windows 7
|
||||||
if: matrix.legacy_win7
|
if: matrix.legacy_win7
|
||||||
id: cache-go-for-windows7
|
id: cache-go-for-windows7
|
||||||
@@ -128,9 +132,11 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
~/go/go_win7
|
~/go/go_win7
|
||||||
key: go_win7_1255
|
key: go_win7_1258
|
||||||
- name: Setup Go for Windows 7
|
- name: Setup Go for Windows 7
|
||||||
if: matrix.legacy_win7 && steps.cache-go-for-windows7.outputs.cache-hit != 'true'
|
if: matrix.legacy_win7 && steps.cache-go-for-windows7.outputs.cache-hit != 'true'
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ github.token }}
|
||||||
run: |-
|
run: |-
|
||||||
.github/setup_go_for_windows7.sh
|
.github/setup_go_for_windows7.sh
|
||||||
- name: Setup Go for Windows 7
|
- name: Setup Go for Windows 7
|
||||||
@@ -154,14 +160,23 @@ jobs:
|
|||||||
git -C ~/cronet-go fetch --depth=1 origin "$CRONET_GO_VERSION"
|
git -C ~/cronet-go fetch --depth=1 origin "$CRONET_GO_VERSION"
|
||||||
git -C ~/cronet-go checkout FETCH_HEAD
|
git -C ~/cronet-go checkout FETCH_HEAD
|
||||||
git -C ~/cronet-go submodule update --init --recursive --depth=1
|
git -C ~/cronet-go submodule update --init --recursive --depth=1
|
||||||
|
- name: Regenerate Debian keyring
|
||||||
|
if: matrix.naive
|
||||||
|
run: |
|
||||||
|
set -xeuo pipefail
|
||||||
|
rm -f ~/cronet-go/naiveproxy/src/build/linux/sysroot_scripts/keyring.gpg
|
||||||
|
cd ~/cronet-go
|
||||||
|
GPG_TTY=/dev/null ./naiveproxy/src/build/linux/sysroot_scripts/generate_keyring.sh
|
||||||
- name: Cache Chromium toolchain
|
- name: Cache Chromium toolchain
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
id: cache-chromium-toolchain
|
id: cache-chromium-toolchain
|
||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
~/cronet-go/naiveproxy/src/third_party/llvm-build/Release+Asserts
|
~/cronet-go/naiveproxy/src/third_party/llvm-build/
|
||||||
~/cronet-go/naiveproxy/src/out/sysroot-build
|
~/cronet-go/naiveproxy/src/gn/out/
|
||||||
|
~/cronet-go/naiveproxy/src/chrome/build/pgo_profiles/
|
||||||
|
~/cronet-go/naiveproxy/src/out/sysroot-build/
|
||||||
key: chromium-toolchain-${{ matrix.arch }}-${{ matrix.variant }}-${{ hashFiles('.github/CRONET_GO_VERSION') }}
|
key: chromium-toolchain-${{ matrix.arch }}-${{ matrix.variant }}-${{ hashFiles('.github/CRONET_GO_VERSION') }}
|
||||||
- name: Download Chromium toolchain
|
- name: Download Chromium toolchain
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
@@ -190,9 +205,10 @@ jobs:
|
|||||||
- name: Set build tags
|
- name: Set build tags
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
TAGS='with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0'
|
|
||||||
if [[ "${{ matrix.naive }}" == "true" ]]; then
|
if [[ "${{ matrix.naive }}" == "true" ]]; then
|
||||||
TAGS="${TAGS},with_naive_outbound"
|
TAGS=$(cat release/DEFAULT_BUILD_TAGS)
|
||||||
|
else
|
||||||
|
TAGS=$(cat release/DEFAULT_BUILD_TAGS_OTHERS)
|
||||||
fi
|
fi
|
||||||
if [[ "${{ matrix.variant }}" == "purego" ]]; then
|
if [[ "${{ matrix.variant }}" == "purego" ]]; then
|
||||||
TAGS="${TAGS},with_purego"
|
TAGS="${TAGS},with_purego"
|
||||||
@@ -200,13 +216,16 @@ jobs:
|
|||||||
TAGS="${TAGS},with_musl"
|
TAGS="${TAGS},with_musl"
|
||||||
fi
|
fi
|
||||||
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
||||||
|
- name: Set shared ldflags
|
||||||
|
run: |
|
||||||
|
echo "LDFLAGS_SHARED=$(cat release/LDFLAGS)" >> "${GITHUB_ENV}"
|
||||||
- name: Build (purego)
|
- name: Build (purego)
|
||||||
if: matrix.variant == 'purego'
|
if: matrix.variant == 'purego'
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "0"
|
CGO_ENABLED: "0"
|
||||||
@@ -228,7 +247,7 @@ jobs:
|
|||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "1"
|
CGO_ENABLED: "1"
|
||||||
@@ -236,6 +255,8 @@ jobs:
|
|||||||
GOARCH: ${{ matrix.arch }}
|
GOARCH: ${{ matrix.arch }}
|
||||||
GO386: ${{ matrix.go386 }}
|
GO386: ${{ matrix.go386 }}
|
||||||
GOARM: ${{ matrix.goarm }}
|
GOARM: ${{ matrix.goarm }}
|
||||||
|
GOMIPS: ${{ matrix.gomips }}
|
||||||
|
GOMIPS64: ${{ matrix.gomips }}
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
- name: Build (musl)
|
- name: Build (musl)
|
||||||
if: matrix.variant == 'musl'
|
if: matrix.variant == 'musl'
|
||||||
@@ -243,7 +264,7 @@ jobs:
|
|||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "1"
|
CGO_ENABLED: "1"
|
||||||
@@ -251,6 +272,8 @@ jobs:
|
|||||||
GOARCH: ${{ matrix.arch }}
|
GOARCH: ${{ matrix.arch }}
|
||||||
GO386: ${{ matrix.go386 }}
|
GO386: ${{ matrix.go386 }}
|
||||||
GOARM: ${{ matrix.goarm }}
|
GOARM: ${{ matrix.goarm }}
|
||||||
|
GOMIPS: ${{ matrix.gomips }}
|
||||||
|
GOMIPS64: ${{ matrix.gomips }}
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
- name: Build (non-variant)
|
- name: Build (non-variant)
|
||||||
if: matrix.os != 'android' && matrix.variant == ''
|
if: matrix.os != 'android' && matrix.variant == ''
|
||||||
@@ -258,7 +281,7 @@ jobs:
|
|||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "0"
|
CGO_ENABLED: "0"
|
||||||
@@ -278,7 +301,7 @@ jobs:
|
|||||||
export CXX="${CC}++"
|
export CXX="${CC}++"
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
GOOS=$BUILD_GOOS GOARCH=$BUILD_GOARCH build go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
GOOS=$BUILD_GOOS GOARCH=$BUILD_GOARCH build go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "1"
|
CGO_ENABLED: "1"
|
||||||
@@ -352,7 +375,7 @@ jobs:
|
|||||||
sudo gem install fpm
|
sudo gem install fpm
|
||||||
sudo apt-get update
|
sudo apt-get update
|
||||||
sudo apt-get install -y libarchive-tools
|
sudo apt-get install -y libarchive-tools
|
||||||
cp .fpm_systemd .fpm
|
cp .fpm_pacman .fpm
|
||||||
fpm -t pacman \
|
fpm -t pacman \
|
||||||
-v "$PKG_VERSION" \
|
-v "$PKG_VERSION" \
|
||||||
-p "dist/sing-box_${{ needs.calculate_version.outputs.version }}_${{ matrix.os }}_${{ matrix.pacman }}.pkg.tar.zst" \
|
-p "dist/sing-box_${{ needs.calculate_version.outputs.version }}_${{ matrix.os }}_${{ matrix.pacman }}.pkg.tar.zst" \
|
||||||
@@ -373,6 +396,30 @@ jobs:
|
|||||||
.github/deb2ipk.sh "$architecture" "dist/openwrt.deb" "dist/sing-box_${{ needs.calculate_version.outputs.version }}_openwrt_${architecture}.ipk"
|
.github/deb2ipk.sh "$architecture" "dist/openwrt.deb" "dist/sing-box_${{ needs.calculate_version.outputs.version }}_openwrt_${architecture}.ipk"
|
||||||
done
|
done
|
||||||
rm "dist/openwrt.deb"
|
rm "dist/openwrt.deb"
|
||||||
|
- name: Install apk-tools
|
||||||
|
if: matrix.openwrt != '' || matrix.alpine != ''
|
||||||
|
run: |-
|
||||||
|
docker run --rm -v /usr/local/bin:/mnt alpine:edge sh -c "apk add --no-cache apk-tools-static && cp /sbin/apk.static /mnt/apk && chmod +x /mnt/apk"
|
||||||
|
- name: Package OpenWrt APK
|
||||||
|
if: matrix.openwrt != ''
|
||||||
|
run: |-
|
||||||
|
set -xeuo pipefail
|
||||||
|
for architecture in ${{ matrix.openwrt }}; do
|
||||||
|
.github/build_openwrt_apk.sh \
|
||||||
|
"$architecture" \
|
||||||
|
"${{ needs.calculate_version.outputs.version }}" \
|
||||||
|
"dist/sing-box" \
|
||||||
|
"dist/sing-box_${{ needs.calculate_version.outputs.version }}_openwrt_${architecture}.apk"
|
||||||
|
done
|
||||||
|
- name: Package Alpine APK
|
||||||
|
if: matrix.alpine != ''
|
||||||
|
run: |-
|
||||||
|
set -xeuo pipefail
|
||||||
|
.github/build_alpine_apk.sh \
|
||||||
|
"${{ matrix.alpine }}" \
|
||||||
|
"${{ needs.calculate_version.outputs.version }}" \
|
||||||
|
"dist/sing-box" \
|
||||||
|
"dist/sing-box_${{ needs.calculate_version.outputs.version }}_linux_${{ matrix.alpine }}.apk"
|
||||||
- name: Archive
|
- name: Archive
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
@@ -408,22 +455,36 @@ jobs:
|
|||||||
include:
|
include:
|
||||||
- { arch: amd64 }
|
- { arch: amd64 }
|
||||||
- { arch: arm64 }
|
- { arch: arm64 }
|
||||||
- { arch: amd64, legacy_go124: true, legacy_name: "macos-11" }
|
- { arch: amd64, legacy_osx: true, legacy_name: "macos-10.13" }
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
if: ${{ ! matrix.legacy_go124 }}
|
if: ${{ ! matrix.legacy_osx }}
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.3
|
go-version: ^1.25.3
|
||||||
- name: Setup Go 1.24
|
- name: Cache Go for macOS 10.13
|
||||||
if: matrix.legacy_go124
|
if: matrix.legacy_osx
|
||||||
uses: actions/setup-go@v5
|
id: cache-go-for-macos1013
|
||||||
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
go-version: ~1.24.6
|
path: |
|
||||||
|
~/go/go_osx
|
||||||
|
key: go_osx_1258
|
||||||
|
- name: Setup Go for macOS 10.13
|
||||||
|
if: matrix.legacy_osx && steps.cache-go-for-macos1013.outputs.cache-hit != 'true'
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ github.token }}
|
||||||
|
run: |-
|
||||||
|
.github/setup_go_for_macos1013.sh
|
||||||
|
- name: Setup Go for macOS 10.13
|
||||||
|
if: matrix.legacy_osx
|
||||||
|
run: |-
|
||||||
|
echo "PATH=$HOME/go/go_osx/bin:$PATH" >> $GITHUB_ENV
|
||||||
|
echo "GOROOT=$HOME/go/go_osx" >> $GITHUB_ENV
|
||||||
- name: Set tag
|
- name: Set tag
|
||||||
run: |-
|
run: |-
|
||||||
git ls-remote --exit-code --tags origin v${{ needs.calculate_version.outputs.version }} || echo "PUBLISHED=false" >> "$GITHUB_ENV"
|
git ls-remote --exit-code --tags origin v${{ needs.calculate_version.outputs.version }} || echo "PUBLISHED=false" >> "$GITHUB_ENV"
|
||||||
@@ -431,22 +492,27 @@ jobs:
|
|||||||
- name: Set build tags
|
- name: Set build tags
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
TAGS='with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0'
|
if [[ "${{ matrix.legacy_osx }}" != "true" ]]; then
|
||||||
if [[ "${{ matrix.legacy_go124 }}" != "true" ]]; then
|
TAGS=$(cat release/DEFAULT_BUILD_TAGS)
|
||||||
TAGS="${TAGS},with_naive_outbound"
|
else
|
||||||
|
TAGS=$(cat release/DEFAULT_BUILD_TAGS_OTHERS)
|
||||||
fi
|
fi
|
||||||
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
||||||
|
- name: Set shared ldflags
|
||||||
|
run: |
|
||||||
|
echo "LDFLAGS_SHARED=$(cat release/LDFLAGS)" >> "${GITHUB_ENV}"
|
||||||
- name: Build
|
- name: Build
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "1"
|
CGO_ENABLED: "1"
|
||||||
GOOS: darwin
|
GOOS: darwin
|
||||||
GOARCH: ${{ matrix.arch }}
|
GOARCH: ${{ matrix.arch }}
|
||||||
|
MACOSX_DEPLOYMENT_TARGET: ${{ matrix.legacy_osx && '10.13' || '' }}
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
- name: Set name
|
- name: Set name
|
||||||
run: |-
|
run: |-
|
||||||
@@ -499,9 +565,11 @@ jobs:
|
|||||||
- name: Build
|
- name: Build
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
run: |
|
run: |
|
||||||
|
$TAGS = Get-Content release/DEFAULT_BUILD_TAGS_WINDOWS
|
||||||
|
$LDFLAGS_SHARED = Get-Content release/LDFLAGS
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box.exe -tags "with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,with_naive_outbound,with_purego,badlinkname,tfogo_checklinkname0" `
|
go build -v -trimpath -o dist/sing-box.exe -tags "$TAGS" `
|
||||||
-ldflags "-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0" `
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' $LDFLAGS_SHARED -s -w -buildid=" `
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "0"
|
CGO_ENABLED: "0"
|
||||||
@@ -511,9 +579,11 @@ jobs:
|
|||||||
- name: Build
|
- name: Build
|
||||||
if: ${{ !matrix.naive }}
|
if: ${{ !matrix.naive }}
|
||||||
run: |
|
run: |
|
||||||
|
$TAGS = Get-Content release/DEFAULT_BUILD_TAGS_OTHERS
|
||||||
|
$LDFLAGS_SHARED = Get-Content release/LDFLAGS
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box.exe -tags "with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0" `
|
go build -v -trimpath -o dist/sing-box.exe -tags "$TAGS" `
|
||||||
-ldflags "-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0" `
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' $LDFLAGS_SHARED -s -w -buildid=" `
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "0"
|
CGO_ENABLED: "0"
|
||||||
@@ -558,7 +628,7 @@ jobs:
|
|||||||
path: "dist"
|
path: "dist"
|
||||||
build_android:
|
build_android:
|
||||||
name: Build Android
|
name: Build Android
|
||||||
if: github.event_name != 'workflow_dispatch' || inputs.build == 'All' || inputs.build == 'Android'
|
if: (github.event_name != 'workflow_dispatch' || inputs.build == 'All' || inputs.build == 'Android') && github.ref != 'refs/heads/oldstable'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
needs:
|
needs:
|
||||||
- calculate_version
|
- calculate_version
|
||||||
@@ -571,7 +641,7 @@ jobs:
|
|||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Setup Android NDK
|
- name: Setup Android NDK
|
||||||
id: setup-ndk
|
id: setup-ndk
|
||||||
uses: nttld/setup-ndk@v1
|
uses: nttld/setup-ndk@v1
|
||||||
@@ -594,12 +664,12 @@ jobs:
|
|||||||
JAVA_HOME: /usr/lib/jvm/java-17-openjdk-amd64
|
JAVA_HOME: /usr/lib/jvm/java-17-openjdk-amd64
|
||||||
ANDROID_NDK_HOME: ${{ steps.setup-ndk.outputs.ndk-path }}
|
ANDROID_NDK_HOME: ${{ steps.setup-ndk.outputs.ndk-path }}
|
||||||
- name: Checkout main branch
|
- name: Checkout main branch
|
||||||
if: github.ref == 'refs/heads/main-next' && github.event_name != 'workflow_dispatch'
|
if: github.ref == 'refs/heads/stable' && github.event_name != 'workflow_dispatch'
|
||||||
run: |-
|
run: |-
|
||||||
cd clients/android
|
cd clients/android
|
||||||
git checkout main
|
git checkout main
|
||||||
- name: Checkout dev branch
|
- name: Checkout dev branch
|
||||||
if: github.ref == 'refs/heads/dev-next'
|
if: github.ref == 'refs/heads/testing'
|
||||||
run: |-
|
run: |-
|
||||||
cd clients/android
|
cd clients/android
|
||||||
git checkout dev
|
git checkout dev
|
||||||
@@ -648,7 +718,7 @@ jobs:
|
|||||||
path: 'dist'
|
path: 'dist'
|
||||||
publish_android:
|
publish_android:
|
||||||
name: Publish Android
|
name: Publish Android
|
||||||
if: github.event_name == 'workflow_dispatch' && inputs.build == 'publish-android'
|
if: github.event_name == 'workflow_dispatch' && inputs.build == 'publish-android' && github.ref != 'refs/heads/oldstable'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
needs:
|
needs:
|
||||||
- calculate_version
|
- calculate_version
|
||||||
@@ -661,7 +731,7 @@ jobs:
|
|||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Setup Android NDK
|
- name: Setup Android NDK
|
||||||
id: setup-ndk
|
id: setup-ndk
|
||||||
uses: nttld/setup-ndk@v1
|
uses: nttld/setup-ndk@v1
|
||||||
@@ -684,12 +754,12 @@ jobs:
|
|||||||
JAVA_HOME: /usr/lib/jvm/java-17-openjdk-amd64
|
JAVA_HOME: /usr/lib/jvm/java-17-openjdk-amd64
|
||||||
ANDROID_NDK_HOME: ${{ steps.setup-ndk.outputs.ndk-path }}
|
ANDROID_NDK_HOME: ${{ steps.setup-ndk.outputs.ndk-path }}
|
||||||
- name: Checkout main branch
|
- name: Checkout main branch
|
||||||
if: github.ref == 'refs/heads/main-next' && github.event_name != 'workflow_dispatch'
|
if: github.ref == 'refs/heads/stable' && github.event_name != 'workflow_dispatch'
|
||||||
run: |-
|
run: |-
|
||||||
cd clients/android
|
cd clients/android
|
||||||
git checkout main
|
git checkout main
|
||||||
- name: Checkout dev branch
|
- name: Checkout dev branch
|
||||||
if: github.ref == 'refs/heads/dev-next'
|
if: github.ref == 'refs/heads/testing'
|
||||||
run: |-
|
run: |-
|
||||||
cd clients/android
|
cd clients/android
|
||||||
git checkout dev
|
git checkout dev
|
||||||
@@ -760,7 +830,7 @@ jobs:
|
|||||||
if: matrix.if
|
if: matrix.if
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Set tag
|
- name: Set tag
|
||||||
if: matrix.if
|
if: matrix.if
|
||||||
run: |-
|
run: |-
|
||||||
@@ -768,12 +838,12 @@ jobs:
|
|||||||
git tag v${{ needs.calculate_version.outputs.version }} -f
|
git tag v${{ needs.calculate_version.outputs.version }} -f
|
||||||
echo "VERSION=${{ needs.calculate_version.outputs.version }}" >> "$GITHUB_ENV"
|
echo "VERSION=${{ needs.calculate_version.outputs.version }}" >> "$GITHUB_ENV"
|
||||||
- name: Checkout main branch
|
- name: Checkout main branch
|
||||||
if: matrix.if && github.ref == 'refs/heads/main-next' && github.event_name != 'workflow_dispatch'
|
if: matrix.if && github.ref == 'refs/heads/stable' && github.event_name != 'workflow_dispatch'
|
||||||
run: |-
|
run: |-
|
||||||
cd clients/apple
|
cd clients/apple
|
||||||
git checkout main
|
git checkout main
|
||||||
- name: Checkout dev branch
|
- name: Checkout dev branch
|
||||||
if: matrix.if && github.ref == 'refs/heads/dev-next'
|
if: matrix.if && github.ref == 'refs/heads/testing'
|
||||||
run: |-
|
run: |-
|
||||||
cd clients/apple
|
cd clients/apple
|
||||||
git checkout dev
|
git checkout dev
|
||||||
@@ -859,7 +929,7 @@ jobs:
|
|||||||
-authenticationKeyID $ASC_KEY_ID \
|
-authenticationKeyID $ASC_KEY_ID \
|
||||||
-authenticationKeyIssuerID $ASC_KEY_ISSUER_ID
|
-authenticationKeyIssuerID $ASC_KEY_ISSUER_ID
|
||||||
- name: Publish to TestFlight
|
- name: Publish to TestFlight
|
||||||
if: matrix.if && matrix.name != 'macOS-standalone' && github.event_name == 'workflow_dispatch' && github.ref =='refs/heads/dev-next'
|
if: matrix.if && matrix.name != 'macOS-standalone' && github.event_name == 'workflow_dispatch' && github.ref =='refs/heads/testing'
|
||||||
run: |-
|
run: |-
|
||||||
go run -v ./cmd/internal/app_store_connect publish_testflight ${{ matrix.platform }}
|
go run -v ./cmd/internal/app_store_connect publish_testflight ${{ matrix.platform }}
|
||||||
- name: Build image
|
- name: Build image
|
||||||
|
|||||||
77
.github/workflows/docker.yml
vendored
77
.github/workflows/docker.yml
vendored
@@ -3,8 +3,8 @@ name: Publish Docker Images
|
|||||||
on:
|
on:
|
||||||
#push:
|
#push:
|
||||||
# branches:
|
# branches:
|
||||||
# - main-next
|
# - stable
|
||||||
# - dev-next
|
# - testing
|
||||||
release:
|
release:
|
||||||
types:
|
types:
|
||||||
- published
|
- published
|
||||||
@@ -29,10 +29,12 @@ jobs:
|
|||||||
- { arch: arm64, naive: true, docker_platform: "linux/arm64" }
|
- { arch: arm64, naive: true, docker_platform: "linux/arm64" }
|
||||||
- { arch: "386", naive: true, docker_platform: "linux/386" }
|
- { arch: "386", naive: true, docker_platform: "linux/386" }
|
||||||
- { arch: arm, goarm: "7", naive: true, docker_platform: "linux/arm/v7" }
|
- { arch: arm, goarm: "7", naive: true, docker_platform: "linux/arm/v7" }
|
||||||
|
- { arch: mipsle, gomips: softfloat, naive: true, docker_platform: "linux/mipsle" }
|
||||||
|
- { arch: riscv64, naive: true, docker_platform: "linux/riscv64" }
|
||||||
|
- { arch: loong64, naive: true, docker_platform: "linux/loong64" }
|
||||||
# Non-naive builds
|
# Non-naive builds
|
||||||
- { arch: arm, goarm: "6", docker_platform: "linux/arm/v6" }
|
- { arch: arm, goarm: "6", docker_platform: "linux/arm/v6" }
|
||||||
- { arch: ppc64le, docker_platform: "linux/ppc64le" }
|
- { arch: ppc64le, docker_platform: "linux/ppc64le" }
|
||||||
- { arch: riscv64, docker_platform: "linux/riscv64" }
|
|
||||||
- { arch: s390x, docker_platform: "linux/s390x" }
|
- { arch: s390x, docker_platform: "linux/s390x" }
|
||||||
steps:
|
steps:
|
||||||
- name: Get commit to build
|
- name: Get commit to build
|
||||||
@@ -53,7 +55,7 @@ jobs:
|
|||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.4
|
go-version: ~1.25.8
|
||||||
- name: Clone cronet-go
|
- name: Clone cronet-go
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
run: |
|
run: |
|
||||||
@@ -64,14 +66,23 @@ jobs:
|
|||||||
git -C ~/cronet-go fetch --depth=1 origin "$CRONET_GO_VERSION"
|
git -C ~/cronet-go fetch --depth=1 origin "$CRONET_GO_VERSION"
|
||||||
git -C ~/cronet-go checkout FETCH_HEAD
|
git -C ~/cronet-go checkout FETCH_HEAD
|
||||||
git -C ~/cronet-go submodule update --init --recursive --depth=1
|
git -C ~/cronet-go submodule update --init --recursive --depth=1
|
||||||
|
- name: Regenerate Debian keyring
|
||||||
|
if: matrix.naive
|
||||||
|
run: |
|
||||||
|
set -xeuo pipefail
|
||||||
|
rm -f ~/cronet-go/naiveproxy/src/build/linux/sysroot_scripts/keyring.gpg
|
||||||
|
cd ~/cronet-go
|
||||||
|
GPG_TTY=/dev/null ./naiveproxy/src/build/linux/sysroot_scripts/generate_keyring.sh
|
||||||
- name: Cache Chromium toolchain
|
- name: Cache Chromium toolchain
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
id: cache-chromium-toolchain
|
id: cache-chromium-toolchain
|
||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
~/cronet-go/naiveproxy/src/third_party/llvm-build/Release+Asserts
|
~/cronet-go/naiveproxy/src/third_party/llvm-build/
|
||||||
~/cronet-go/naiveproxy/src/out/sysroot-build
|
~/cronet-go/naiveproxy/src/gn/out/
|
||||||
|
~/cronet-go/naiveproxy/src/chrome/build/pgo_profiles/
|
||||||
|
~/cronet-go/naiveproxy/src/out/sysroot-build/
|
||||||
key: chromium-toolchain-${{ matrix.arch }}-musl-${{ hashFiles('.github/CRONET_GO_VERSION') }}
|
key: chromium-toolchain-${{ matrix.arch }}-musl-${{ hashFiles('.github/CRONET_GO_VERSION') }}
|
||||||
- name: Download Chromium toolchain
|
- name: Download Chromium toolchain
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
@@ -93,29 +104,34 @@ jobs:
|
|||||||
- name: Set build tags
|
- name: Set build tags
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
TAGS='with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0'
|
|
||||||
if [[ "${{ matrix.naive }}" == "true" ]]; then
|
if [[ "${{ matrix.naive }}" == "true" ]]; then
|
||||||
TAGS="${TAGS},with_naive_outbound,with_musl"
|
TAGS="$(cat release/DEFAULT_BUILD_TAGS),with_musl"
|
||||||
|
else
|
||||||
|
TAGS=$(cat release/DEFAULT_BUILD_TAGS_OTHERS)
|
||||||
fi
|
fi
|
||||||
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
||||||
|
- name: Set shared ldflags
|
||||||
|
run: |
|
||||||
|
echo "LDFLAGS_SHARED=$(cat release/LDFLAGS)" >> "${GITHUB_ENV}"
|
||||||
- name: Build (naive)
|
- name: Build (naive)
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
go build -v -trimpath -o sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags "-X \"github.com/sagernet/sing-box/constant.Version=${VERSION}\" -X 'internal/godebug.defaultGODEBUG=multipathtcp=0' -s -w -buildid= -checklinkname=0" \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${VERSION}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "1"
|
CGO_ENABLED: "1"
|
||||||
GOOS: linux
|
GOOS: linux
|
||||||
GOARCH: ${{ matrix.arch }}
|
GOARCH: ${{ matrix.arch }}
|
||||||
GOARM: ${{ matrix.goarm }}
|
GOARM: ${{ matrix.goarm }}
|
||||||
|
GOMIPS: ${{ matrix.gomips }}
|
||||||
- name: Build (non-naive)
|
- name: Build (non-naive)
|
||||||
if: ${{ ! matrix.naive }}
|
if: ${{ ! matrix.naive }}
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
go build -v -trimpath -o sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags "-X \"github.com/sagernet/sing-box/constant.Version=${VERSION}\" -X 'internal/godebug.defaultGODEBUG=multipathtcp=0' -s -w -buildid= -checklinkname=0" \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${VERSION}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "0"
|
CGO_ENABLED: "0"
|
||||||
@@ -148,15 +164,17 @@ jobs:
|
|||||||
strategy:
|
strategy:
|
||||||
fail-fast: true
|
fail-fast: true
|
||||||
matrix:
|
matrix:
|
||||||
platform:
|
include:
|
||||||
- linux/amd64
|
- { platform: "linux/amd64" }
|
||||||
- linux/arm/v6
|
- { platform: "linux/arm/v6" }
|
||||||
- linux/arm/v7
|
- { platform: "linux/arm/v7" }
|
||||||
- linux/arm64
|
- { platform: "linux/arm64" }
|
||||||
- linux/386
|
- { platform: "linux/386" }
|
||||||
- linux/ppc64le
|
# mipsle: no base Docker image available for this platform
|
||||||
- linux/riscv64
|
- { platform: "linux/ppc64le" }
|
||||||
- linux/s390x
|
- { platform: "linux/riscv64" }
|
||||||
|
- { platform: "linux/s390x" }
|
||||||
|
- { platform: "linux/loong64", base_image: "ghcr.io/loong64/alpine:edge" }
|
||||||
steps:
|
steps:
|
||||||
- name: Get commit to build
|
- name: Get commit to build
|
||||||
id: ref
|
id: ref
|
||||||
@@ -209,6 +227,8 @@ jobs:
|
|||||||
platforms: ${{ matrix.platform }}
|
platforms: ${{ matrix.platform }}
|
||||||
context: .
|
context: .
|
||||||
file: Dockerfile.binary
|
file: Dockerfile.binary
|
||||||
|
build-args: |
|
||||||
|
BASE_IMAGE=${{ matrix.base_image || 'alpine' }}
|
||||||
labels: ${{ steps.meta.outputs.labels }}
|
labels: ${{ steps.meta.outputs.labels }}
|
||||||
outputs: type=image,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=true
|
outputs: type=image,name=${{ env.REGISTRY_IMAGE }},push-by-digest=true,name-canonical=true,push=true
|
||||||
- name: Export digest
|
- name: Export digest
|
||||||
@@ -224,6 +244,7 @@ jobs:
|
|||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
retention-days: 1
|
retention-days: 1
|
||||||
merge:
|
merge:
|
||||||
|
if: github.event_name != 'push'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
needs:
|
needs:
|
||||||
- build_docker
|
- build_docker
|
||||||
@@ -238,13 +259,13 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
echo "ref=$ref"
|
echo "ref=$ref"
|
||||||
echo "ref=$ref" >> $GITHUB_OUTPUT
|
echo "ref=$ref" >> $GITHUB_OUTPUT
|
||||||
if [[ $ref == *"-"* ]]; then
|
- name: Checkout
|
||||||
latest=latest-beta
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
|
||||||
else
|
with:
|
||||||
latest=latest
|
ref: ${{ steps.ref.outputs.ref }}
|
||||||
fi
|
fetch-depth: 0
|
||||||
echo "latest=$latest"
|
- name: Detect track
|
||||||
echo "latest=$latest" >> $GITHUB_OUTPUT
|
run: bash .github/detect_track.sh
|
||||||
- name: Download digests
|
- name: Download digests
|
||||||
uses: actions/download-artifact@v5
|
uses: actions/download-artifact@v5
|
||||||
with:
|
with:
|
||||||
@@ -264,11 +285,11 @@ jobs:
|
|||||||
working-directory: /tmp/digests
|
working-directory: /tmp/digests
|
||||||
run: |
|
run: |
|
||||||
docker buildx imagetools create \
|
docker buildx imagetools create \
|
||||||
-t "${{ env.REGISTRY_IMAGE }}:${{ steps.ref.outputs.latest }}" \
|
-t "${{ env.REGISTRY_IMAGE }}:${{ env.DOCKER_TAG }}" \
|
||||||
-t "${{ env.REGISTRY_IMAGE }}:${{ steps.ref.outputs.ref }}" \
|
-t "${{ env.REGISTRY_IMAGE }}:${{ steps.ref.outputs.ref }}" \
|
||||||
$(printf '${{ env.REGISTRY_IMAGE }}@sha256:%s ' *)
|
$(printf '${{ env.REGISTRY_IMAGE }}@sha256:%s ' *)
|
||||||
- name: Inspect image
|
- name: Inspect image
|
||||||
if: github.event_name != 'push'
|
if: github.event_name != 'push'
|
||||||
run: |
|
run: |
|
||||||
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.ref.outputs.latest }}
|
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ env.DOCKER_TAG }}
|
||||||
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.ref.outputs.ref }}
|
docker buildx imagetools inspect ${{ env.REGISTRY_IMAGE }}:${{ steps.ref.outputs.ref }}
|
||||||
|
|||||||
14
.github/workflows/lint.yml
vendored
14
.github/workflows/lint.yml
vendored
@@ -3,18 +3,20 @@ name: Lint
|
|||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- stable-next
|
- oldstable
|
||||||
- main-next
|
- stable
|
||||||
- dev-next
|
- testing
|
||||||
|
- unstable
|
||||||
paths-ignore:
|
paths-ignore:
|
||||||
- '**.md'
|
- '**.md'
|
||||||
- '.github/**'
|
- '.github/**'
|
||||||
- '!.github/workflows/lint.yml'
|
- '!.github/workflows/lint.yml'
|
||||||
pull_request:
|
pull_request:
|
||||||
branches:
|
branches:
|
||||||
- stable-next
|
- oldstable
|
||||||
- main-next
|
- stable
|
||||||
- dev-next
|
- testing
|
||||||
|
- unstable
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
|
|||||||
56
.github/workflows/linux.yml
vendored
56
.github/workflows/linux.yml
vendored
@@ -3,19 +3,14 @@ name: Build Linux Packages
|
|||||||
on:
|
on:
|
||||||
#push:
|
#push:
|
||||||
# branches:
|
# branches:
|
||||||
# - main-next
|
# - stable
|
||||||
# - dev-next
|
# - testing
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
version:
|
version:
|
||||||
description: "Version name"
|
description: "Version name"
|
||||||
required: true
|
required: true
|
||||||
type: string
|
type: string
|
||||||
forceBeta:
|
|
||||||
description: "Force beta"
|
|
||||||
required: false
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
release:
|
release:
|
||||||
types:
|
types:
|
||||||
- published
|
- published
|
||||||
@@ -34,7 +29,7 @@ jobs:
|
|||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Check input version
|
- name: Check input version
|
||||||
if: github.event_name == 'workflow_dispatch'
|
if: github.event_name == 'workflow_dispatch'
|
||||||
run: |-
|
run: |-
|
||||||
@@ -61,14 +56,14 @@ jobs:
|
|||||||
- { os: linux, arch: arm64, naive: true, debian: arm64, rpm: aarch64, pacman: aarch64 }
|
- { os: linux, arch: arm64, naive: true, debian: arm64, rpm: aarch64, pacman: aarch64 }
|
||||||
- { os: linux, arch: "386", naive: true, debian: i386, rpm: i386 }
|
- { os: linux, arch: "386", naive: true, debian: i386, rpm: i386 }
|
||||||
- { os: linux, arch: arm, goarm: "7", naive: true, debian: armhf, rpm: armv7hl, pacman: armv7hl }
|
- { os: linux, arch: arm, goarm: "7", naive: true, debian: armhf, rpm: armv7hl, pacman: armv7hl }
|
||||||
|
- { os: linux, arch: mipsle, gomips: softfloat, naive: true, debian: mipsel, rpm: mipsel }
|
||||||
|
- { os: linux, arch: riscv64, naive: true, debian: riscv64, rpm: riscv64 }
|
||||||
|
- { os: linux, arch: loong64, naive: true, debian: loongarch64, rpm: loongarch64 }
|
||||||
# Non-naive builds (unsupported architectures)
|
# Non-naive builds (unsupported architectures)
|
||||||
- { os: linux, arch: arm, goarm: "6", debian: armel, rpm: armv6hl }
|
- { os: linux, arch: arm, goarm: "6", debian: armel, rpm: armv6hl }
|
||||||
- { os: linux, arch: mips64le, debian: mips64el, rpm: mips64el }
|
- { os: linux, arch: mips64le, debian: mips64el, rpm: mips64el }
|
||||||
- { os: linux, arch: mipsle, debian: mipsel, rpm: mipsel }
|
|
||||||
- { os: linux, arch: s390x, debian: s390x, rpm: s390x }
|
- { os: linux, arch: s390x, debian: s390x, rpm: s390x }
|
||||||
- { os: linux, arch: ppc64le, debian: ppc64el, rpm: ppc64le }
|
- { os: linux, arch: ppc64le, debian: ppc64el, rpm: ppc64le }
|
||||||
- { os: linux, arch: riscv64, debian: riscv64, rpm: riscv64 }
|
|
||||||
- { os: linux, arch: loong64, debian: loongarch64, rpm: loongarch64 }
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
|
||||||
@@ -77,7 +72,7 @@ jobs:
|
|||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.25.5
|
go-version: ~1.25.8
|
||||||
- name: Clone cronet-go
|
- name: Clone cronet-go
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
run: |
|
run: |
|
||||||
@@ -88,14 +83,23 @@ jobs:
|
|||||||
git -C ~/cronet-go fetch --depth=1 origin "$CRONET_GO_VERSION"
|
git -C ~/cronet-go fetch --depth=1 origin "$CRONET_GO_VERSION"
|
||||||
git -C ~/cronet-go checkout FETCH_HEAD
|
git -C ~/cronet-go checkout FETCH_HEAD
|
||||||
git -C ~/cronet-go submodule update --init --recursive --depth=1
|
git -C ~/cronet-go submodule update --init --recursive --depth=1
|
||||||
|
- name: Regenerate Debian keyring
|
||||||
|
if: matrix.naive
|
||||||
|
run: |
|
||||||
|
set -xeuo pipefail
|
||||||
|
rm -f ~/cronet-go/naiveproxy/src/build/linux/sysroot_scripts/keyring.gpg
|
||||||
|
cd ~/cronet-go
|
||||||
|
GPG_TTY=/dev/null ./naiveproxy/src/build/linux/sysroot_scripts/generate_keyring.sh
|
||||||
- name: Cache Chromium toolchain
|
- name: Cache Chromium toolchain
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
id: cache-chromium-toolchain
|
id: cache-chromium-toolchain
|
||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
~/cronet-go/naiveproxy/src/third_party/llvm-build/Release+Asserts
|
~/cronet-go/naiveproxy/src/third_party/llvm-build/
|
||||||
~/cronet-go/naiveproxy/src/out/sysroot-build
|
~/cronet-go/naiveproxy/src/gn/out/
|
||||||
|
~/cronet-go/naiveproxy/src/chrome/build/pgo_profiles/
|
||||||
|
~/cronet-go/naiveproxy/src/out/sysroot-build/
|
||||||
key: chromium-toolchain-${{ matrix.arch }}-musl-${{ hashFiles('.github/CRONET_GO_VERSION') }}
|
key: chromium-toolchain-${{ matrix.arch }}-musl-${{ hashFiles('.github/CRONET_GO_VERSION') }}
|
||||||
- name: Download Chromium toolchain
|
- name: Download Chromium toolchain
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
@@ -116,24 +120,30 @@ jobs:
|
|||||||
- name: Set build tags
|
- name: Set build tags
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
TAGS='with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0'
|
|
||||||
if [[ "${{ matrix.naive }}" == "true" ]]; then
|
if [[ "${{ matrix.naive }}" == "true" ]]; then
|
||||||
TAGS="${TAGS},with_naive_outbound,with_musl"
|
TAGS="$(cat release/DEFAULT_BUILD_TAGS),with_musl"
|
||||||
|
else
|
||||||
|
TAGS=$(cat release/DEFAULT_BUILD_TAGS_OTHERS)
|
||||||
fi
|
fi
|
||||||
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
echo "BUILD_TAGS=${TAGS}" >> "${GITHUB_ENV}"
|
||||||
|
- name: Set shared ldflags
|
||||||
|
run: |
|
||||||
|
echo "LDFLAGS_SHARED=$(cat release/LDFLAGS)" >> "${GITHUB_ENV}"
|
||||||
- name: Build (naive)
|
- name: Build (naive)
|
||||||
if: matrix.naive
|
if: matrix.naive
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "1"
|
CGO_ENABLED: "1"
|
||||||
GOOS: linux
|
GOOS: linux
|
||||||
GOARCH: ${{ matrix.arch }}
|
GOARCH: ${{ matrix.arch }}
|
||||||
GOARM: ${{ matrix.goarm }}
|
GOARM: ${{ matrix.goarm }}
|
||||||
|
GOMIPS: ${{ matrix.gomips }}
|
||||||
|
GOMIPS64: ${{ matrix.gomips }}
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
- name: Build (non-naive)
|
- name: Build (non-naive)
|
||||||
if: ${{ ! matrix.naive }}
|
if: ${{ ! matrix.naive }}
|
||||||
@@ -141,7 +151,7 @@ jobs:
|
|||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
mkdir -p dist
|
mkdir -p dist
|
||||||
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
go build -v -trimpath -o dist/sing-box -tags "${BUILD_TAGS}" \
|
||||||
-ldflags '-s -buildid= -X github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }} -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0' \
|
-ldflags "-X 'github.com/sagernet/sing-box/constant.Version=${{ needs.calculate_version.outputs.version }}' ${LDFLAGS_SHARED} -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
env:
|
env:
|
||||||
CGO_ENABLED: "0"
|
CGO_ENABLED: "0"
|
||||||
@@ -152,14 +162,8 @@ jobs:
|
|||||||
- name: Set mtime
|
- name: Set mtime
|
||||||
run: |-
|
run: |-
|
||||||
TZ=UTC touch -t '197001010000' dist/sing-box
|
TZ=UTC touch -t '197001010000' dist/sing-box
|
||||||
- name: Set name
|
- name: Detect track
|
||||||
if: (! contains(needs.calculate_version.outputs.version, '-')) && !inputs.forceBeta
|
run: bash .github/detect_track.sh
|
||||||
run: |-
|
|
||||||
echo "NAME=sing-box" >> "$GITHUB_ENV"
|
|
||||||
- name: Set beta name
|
|
||||||
if: contains(needs.calculate_version.outputs.version, '-') || inputs.forceBeta
|
|
||||||
run: |-
|
|
||||||
echo "NAME=sing-box-beta" >> "$GITHUB_ENV"
|
|
||||||
- name: Set version
|
- name: Set version
|
||||||
run: |-
|
run: |-
|
||||||
PKG_VERSION="${{ needs.calculate_version.outputs.version }}"
|
PKG_VERSION="${{ needs.calculate_version.outputs.version }}"
|
||||||
|
|||||||
3
.gitignore
vendored
3
.gitignore
vendored
@@ -12,6 +12,9 @@
|
|||||||
/*.jar
|
/*.jar
|
||||||
/*.aar
|
/*.aar
|
||||||
/*.xcframework/
|
/*.xcframework/
|
||||||
|
/experimental/libbox/*.aar
|
||||||
|
/experimental/libbox/*.xcframework/
|
||||||
|
/experimental/libbox/*.nupkg
|
||||||
.DS_Store
|
.DS_Store
|
||||||
/config.d/
|
/config.d/
|
||||||
/venv/
|
/venv/
|
||||||
|
|||||||
@@ -9,6 +9,11 @@ run:
|
|||||||
- with_utls
|
- with_utls
|
||||||
- with_acme
|
- with_acme
|
||||||
- with_clash_api
|
- with_clash_api
|
||||||
|
- with_tailscale
|
||||||
|
- with_ccm
|
||||||
|
- with_ocm
|
||||||
|
- badlinkname
|
||||||
|
- tfogo_checklinkname0
|
||||||
linters:
|
linters:
|
||||||
default: none
|
default: none
|
||||||
enable:
|
enable:
|
||||||
|
|||||||
@@ -12,10 +12,11 @@ RUN set -ex \
|
|||||||
&& apk add git build-base \
|
&& apk add git build-base \
|
||||||
&& export COMMIT=$(git rev-parse --short HEAD) \
|
&& export COMMIT=$(git rev-parse --short HEAD) \
|
||||||
&& export VERSION=$(go run ./cmd/internal/read_tag) \
|
&& export VERSION=$(go run ./cmd/internal/read_tag) \
|
||||||
&& go build -v -trimpath -tags \
|
&& export TAGS=$(cat release/DEFAULT_BUILD_TAGS_OTHERS) \
|
||||||
"with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0" \
|
&& export LDFLAGS_SHARED=$(cat release/LDFLAGS) \
|
||||||
|
&& go build -v -trimpath -tags "$TAGS" \
|
||||||
-o /go/bin/sing-box \
|
-o /go/bin/sing-box \
|
||||||
-ldflags "-X \"github.com/sagernet/sing-box/constant.Version=$VERSION\" -X 'internal/godebug.defaultGODEBUG=multipathtcp=0' -s -w -buildid= -checklinkname=0" \
|
-ldflags "-X \"github.com/sagernet/sing-box/constant.Version=$VERSION\" $LDFLAGS_SHARED -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
FROM --platform=$TARGETPLATFORM alpine AS dist
|
FROM --platform=$TARGETPLATFORM alpine AS dist
|
||||||
LABEL maintainer="nekohasekai <contact-git@sekai.icu>"
|
LABEL maintainer="nekohasekai <contact-git@sekai.icu>"
|
||||||
|
|||||||
@@ -1,8 +1,14 @@
|
|||||||
FROM alpine
|
ARG BASE_IMAGE=alpine
|
||||||
|
FROM ${BASE_IMAGE}
|
||||||
ARG TARGETARCH
|
ARG TARGETARCH
|
||||||
ARG TARGETVARIANT
|
ARG TARGETVARIANT
|
||||||
LABEL maintainer="nekohasekai <contact-git@sekai.icu>"
|
LABEL maintainer="nekohasekai <contact-git@sekai.icu>"
|
||||||
RUN set -ex \
|
RUN set -ex \
|
||||||
&& apk add --no-cache --upgrade bash tzdata ca-certificates nftables
|
&& if command -v apk > /dev/null; then \
|
||||||
|
apk add --no-cache --upgrade bash tzdata ca-certificates nftables; \
|
||||||
|
else \
|
||||||
|
apt-get update && apt-get install -y --no-install-recommends bash tzdata ca-certificates nftables \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*; \
|
||||||
|
fi
|
||||||
COPY sing-box-${TARGETARCH}${TARGETVARIANT} /usr/local/bin/sing-box
|
COPY sing-box-${TARGETARCH}${TARGETVARIANT} /usr/local/bin/sing-box
|
||||||
ENTRYPOINT ["sing-box"]
|
ENTRYPOINT ["sing-box"]
|
||||||
|
|||||||
38
Makefile
38
Makefile
@@ -1,15 +1,18 @@
|
|||||||
NAME = sing-box
|
NAME = sing-box
|
||||||
COMMIT = $(shell git rev-parse --short HEAD)
|
COMMIT = $(shell git rev-parse --short HEAD)
|
||||||
TAGS ?= with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale,with_ccm,with_ocm,badlinkname,tfogo_checklinkname0
|
TAGS ?= $(shell cat release/DEFAULT_BUILD_TAGS_OTHERS)
|
||||||
|
|
||||||
GOHOSTOS = $(shell go env GOHOSTOS)
|
GOHOSTOS = $(shell go env GOHOSTOS)
|
||||||
GOHOSTARCH = $(shell go env GOHOSTARCH)
|
GOHOSTARCH = $(shell go env GOHOSTARCH)
|
||||||
VERSION=$(shell CGO_ENABLED=0 GOOS=$(GOHOSTOS) GOARCH=$(GOHOSTARCH) go run github.com/sagernet/sing-box/cmd/internal/read_tag@latest)
|
VERSION=$(shell CGO_ENABLED=0 GOOS=$(GOHOSTOS) GOARCH=$(GOHOSTARCH) go run github.com/sagernet/sing-box/cmd/internal/read_tag@latest)
|
||||||
|
|
||||||
PARAMS = -v -trimpath -ldflags "-X 'github.com/sagernet/sing-box/constant.Version=$(VERSION)' -X 'internal/godebug.defaultGODEBUG=multipathtcp=0' -s -w -buildid= -checklinkname=0"
|
LDFLAGS_SHARED = $(shell cat release/LDFLAGS)
|
||||||
|
PARAMS = -v -trimpath -ldflags "-X 'github.com/sagernet/sing-box/constant.Version=$(VERSION)' $(LDFLAGS_SHARED) -s -w -buildid="
|
||||||
MAIN_PARAMS = $(PARAMS) -tags "$(TAGS)"
|
MAIN_PARAMS = $(PARAMS) -tags "$(TAGS)"
|
||||||
MAIN = ./cmd/sing-box
|
MAIN = ./cmd/sing-box
|
||||||
PREFIX ?= $(shell go env GOPATH)
|
PREFIX ?= $(shell go env GOPATH)
|
||||||
|
SING_FFI ?= sing-ffi
|
||||||
|
LIBBOX_FFI_CONFIG ?= ./experimental/libbox/ffi.json
|
||||||
|
|
||||||
.PHONY: test release docs build
|
.PHONY: test release docs build
|
||||||
|
|
||||||
@@ -89,12 +92,12 @@ update_android_version:
|
|||||||
go run ./cmd/internal/update_android_version
|
go run ./cmd/internal/update_android_version
|
||||||
|
|
||||||
build_android:
|
build_android:
|
||||||
cd ../sing-box-for-android && ./gradlew :app:clean :app:assemblePlayRelease :app:assembleOtherRelease && ./gradlew --stop
|
cd ../sing-box-for-android && ./gradlew :app:clean :app:assembleOtherRelease :app:assembleOtherLegacyRelease && ./gradlew --stop
|
||||||
|
|
||||||
upload_android:
|
upload_android:
|
||||||
mkdir -p dist/release_android
|
mkdir -p dist/release_android
|
||||||
cp ../sing-box-for-android/app/build/outputs/apk/play/release/*.apk dist/release_android
|
cp ../sing-box-for-android/app/build/outputs/apk/other/release/*.apk dist/release_android
|
||||||
cp ../sing-box-for-android/app/build/outputs/apk/other/release/*-universal.apk dist/release_android
|
cp ../sing-box-for-android/app/build/outputs/apk/otherLegacy/release/*.apk dist/release_android
|
||||||
ghr --replace --draft --prerelease -p 5 "v${VERSION}" dist/release_android
|
ghr --replace --draft --prerelease -p 5 "v${VERSION}" dist/release_android
|
||||||
rm -rf dist/release_android
|
rm -rf dist/release_android
|
||||||
|
|
||||||
@@ -206,7 +209,7 @@ update_apple_version:
|
|||||||
update_macos_version:
|
update_macos_version:
|
||||||
MACOS_PROJECT_VERSION=$(shell go run -v ./cmd/internal/app_store_connect next_macos_project_version) go run ./cmd/internal/update_apple_version
|
MACOS_PROJECT_VERSION=$(shell go run -v ./cmd/internal/app_store_connect next_macos_project_version) go run ./cmd/internal/update_apple_version
|
||||||
|
|
||||||
release_apple: lib_ios update_apple_version release_ios release_macos release_tvos release_macos_standalone
|
release_apple: lib_apple update_apple_version release_ios release_macos release_tvos release_macos_standalone
|
||||||
|
|
||||||
release_apple_beta: update_apple_version release_ios release_macos release_tvos
|
release_apple_beta: update_apple_version release_ios release_macos release_tvos
|
||||||
|
|
||||||
@@ -234,22 +237,21 @@ test_stdio:
|
|||||||
lib_android:
|
lib_android:
|
||||||
go run ./cmd/internal/build_libbox -target android
|
go run ./cmd/internal/build_libbox -target android
|
||||||
|
|
||||||
lib_android_debug:
|
|
||||||
go run ./cmd/internal/build_libbox -target android -debug
|
|
||||||
|
|
||||||
lib_apple:
|
lib_apple:
|
||||||
go run ./cmd/internal/build_libbox -target apple
|
go run ./cmd/internal/build_libbox -target apple
|
||||||
|
|
||||||
lib_ios:
|
lib_windows:
|
||||||
go run ./cmd/internal/build_libbox -target apple -platform ios -debug
|
$(SING_FFI) generate --config $(LIBBOX_FFI_CONFIG) --platform-type csharp
|
||||||
|
|
||||||
lib:
|
lib_android_new:
|
||||||
go run ./cmd/internal/build_libbox -target android
|
$(SING_FFI) generate --config $(LIBBOX_FFI_CONFIG) --platform-type android
|
||||||
go run ./cmd/internal/build_libbox -target ios
|
|
||||||
|
lib_apple_new:
|
||||||
|
$(SING_FFI) generate --config $(LIBBOX_FFI_CONFIG) --platform-type apple
|
||||||
|
|
||||||
lib_install:
|
lib_install:
|
||||||
go install -v github.com/sagernet/gomobile/cmd/gomobile@v0.1.11
|
go install -v github.com/sagernet/gomobile/cmd/gomobile@v0.1.12
|
||||||
go install -v github.com/sagernet/gomobile/cmd/gobind@v0.1.11
|
go install -v github.com/sagernet/gomobile/cmd/gobind@v0.1.12
|
||||||
|
|
||||||
docs:
|
docs:
|
||||||
venv/bin/mkdocs serve
|
venv/bin/mkdocs serve
|
||||||
@@ -258,8 +260,8 @@ publish_docs:
|
|||||||
venv/bin/mkdocs gh-deploy -m "Update" --force --ignore-version --no-history
|
venv/bin/mkdocs gh-deploy -m "Update" --force --ignore-version --no-history
|
||||||
|
|
||||||
docs_install:
|
docs_install:
|
||||||
python -m venv venv
|
python3 -m venv venv
|
||||||
source ./venv/bin/activate && pip install --force-reinstall mkdocs-material=="9.*" mkdocs-static-i18n=="1.2.*"
|
source ./venv/bin/activate && pip install --force-reinstall mkdocs-material=="9.7.2" mkdocs-static-i18n=="1.2.*"
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -rf bin dist sing-box
|
rm -rf bin dist sing-box
|
||||||
|
|||||||
@@ -9,6 +9,10 @@ import (
|
|||||||
|
|
||||||
type ConnectionManager interface {
|
type ConnectionManager interface {
|
||||||
Lifecycle
|
Lifecycle
|
||||||
|
Count() int
|
||||||
|
CloseAll()
|
||||||
|
TrackConn(conn net.Conn) net.Conn
|
||||||
|
TrackPacketConn(conn net.PacketConn) net.PacketConn
|
||||||
NewConnection(ctx context.Context, this N.Dialer, conn net.Conn, metadata InboundContext, onClose N.CloseHandlerFunc)
|
NewConnection(ctx context.Context, this N.Dialer, conn net.Conn, metadata InboundContext, onClose N.CloseHandlerFunc)
|
||||||
NewPacketConnection(ctx context.Context, this N.Dialer, conn N.PacketConn, metadata InboundContext, onClose N.CloseHandlerFunc)
|
NewPacketConnection(ctx context.Context, this N.Dialer, conn N.PacketConn, metadata InboundContext, onClose N.CloseHandlerFunc)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ import (
|
|||||||
"bytes"
|
"bytes"
|
||||||
"context"
|
"context"
|
||||||
"encoding/binary"
|
"encoding/binary"
|
||||||
|
"io"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/observable"
|
"github.com/sagernet/sing/common/observable"
|
||||||
@@ -68,7 +69,11 @@ func (s *SavedBinary) MarshalBinary() ([]byte, error) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
err = varbin.Write(&buffer, binary.BigEndian, s.Content)
|
_, err = varbin.WriteUvarint(&buffer, uint64(len(s.Content)))
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
_, err = buffer.Write(s.Content)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -76,7 +81,11 @@ func (s *SavedBinary) MarshalBinary() ([]byte, error) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
err = varbin.Write(&buffer, binary.BigEndian, s.LastEtag)
|
_, err = varbin.WriteUvarint(&buffer, uint64(len(s.LastEtag)))
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
_, err = buffer.WriteString(s.LastEtag)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -90,7 +99,12 @@ func (s *SavedBinary) UnmarshalBinary(data []byte) error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
err = varbin.Read(reader, binary.BigEndian, &s.Content)
|
contentLength, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
s.Content = make([]byte, contentLength)
|
||||||
|
_, err = io.ReadFull(reader, s.Content)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -100,10 +114,16 @@ func (s *SavedBinary) UnmarshalBinary(data []byte) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
s.LastUpdated = time.Unix(lastUpdated, 0)
|
s.LastUpdated = time.Unix(lastUpdated, 0)
|
||||||
err = varbin.Read(reader, binary.BigEndian, &s.LastEtag)
|
etagLength, err := binary.ReadUvarint(reader)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
etagBytes := make([]byte, etagLength)
|
||||||
|
_, err = io.ReadFull(reader, etagBytes)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
s.LastEtag = string(etagBytes)
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -62,13 +62,10 @@ type InboundContext struct {
|
|||||||
// cache
|
// cache
|
||||||
|
|
||||||
// Deprecated: implement in rule action
|
// Deprecated: implement in rule action
|
||||||
InboundDetour string
|
InboundDetour string
|
||||||
LastInbound string
|
LastInbound string
|
||||||
OriginDestination M.Socksaddr
|
OriginDestination M.Socksaddr
|
||||||
RouteOriginalDestination M.Socksaddr
|
RouteOriginalDestination M.Socksaddr
|
||||||
// Deprecated: to be removed
|
|
||||||
//nolint:staticcheck
|
|
||||||
InboundOptions option.InboundOptions
|
|
||||||
UDPDisableDomainUnmapping bool
|
UDPDisableDomainUnmapping bool
|
||||||
UDPConnect bool
|
UDPConnect bool
|
||||||
UDPTimeout time.Duration
|
UDPTimeout time.Duration
|
||||||
@@ -104,6 +101,10 @@ type InboundContext struct {
|
|||||||
func (c *InboundContext) ResetRuleCache() {
|
func (c *InboundContext) ResetRuleCache() {
|
||||||
c.IPCIDRMatchSource = false
|
c.IPCIDRMatchSource = false
|
||||||
c.IPCIDRAcceptEmpty = false
|
c.IPCIDRAcceptEmpty = false
|
||||||
|
c.ResetRuleMatchCache()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *InboundContext) ResetRuleMatchCache() {
|
||||||
c.SourceAddressMatch = false
|
c.SourceAddressMatch = false
|
||||||
c.SourcePortMatch = false
|
c.SourcePortMatch = false
|
||||||
c.DestinationAddressMatch = false
|
c.DestinationAddressMatch = false
|
||||||
|
|||||||
@@ -47,11 +47,11 @@ type FindConnectionOwnerRequest struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type ConnectionOwner struct {
|
type ConnectionOwner struct {
|
||||||
ProcessID uint32
|
ProcessID uint32
|
||||||
UserId int32
|
UserId int32
|
||||||
UserName string
|
UserName string
|
||||||
ProcessPath string
|
ProcessPath string
|
||||||
AndroidPackageName string
|
AndroidPackageNames []string
|
||||||
}
|
}
|
||||||
|
|
||||||
type Notification struct {
|
type Notification struct {
|
||||||
|
|||||||
5
box.go
5
box.go
@@ -125,7 +125,10 @@ func New(options Options) (*Box, error) {
|
|||||||
|
|
||||||
ctx = pause.WithDefaultManager(ctx)
|
ctx = pause.WithDefaultManager(ctx)
|
||||||
experimentalOptions := common.PtrValueOrDefault(options.Experimental)
|
experimentalOptions := common.PtrValueOrDefault(options.Experimental)
|
||||||
applyDebugOptions(common.PtrValueOrDefault(experimentalOptions.Debug))
|
err := applyDebugOptions(common.PtrValueOrDefault(experimentalOptions.Debug))
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
var needCacheFile bool
|
var needCacheFile bool
|
||||||
var needClashAPI bool
|
var needClashAPI bool
|
||||||
var needV2RayAPI bool
|
var needV2RayAPI bool
|
||||||
|
|||||||
Submodule clients/android updated: 8b3433e9ba...4f0826b94d
Submodule clients/apple updated: 532c140f05...ffbf405b52
@@ -148,6 +148,7 @@ func publishTestflight(ctx context.Context) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
build := builds.Data[0]
|
build := builds.Data[0]
|
||||||
|
log.Info(string(platform), " ", tag, " found build: ", build.ID, " (", *build.Attributes.Version, ")")
|
||||||
if !waitingForProcess && (common.Contains(buildIDs, build.ID) || time.Since(build.Attributes.UploadedDate.Time) > 30*time.Minute) {
|
if !waitingForProcess && (common.Contains(buildIDs, build.ID) || time.Since(build.Attributes.UploadedDate.Time) > 30*time.Minute) {
|
||||||
log.Info(string(platform), " ", tag, " waiting for process")
|
log.Info(string(platform), " ", tag, " waiting for process")
|
||||||
time.Sleep(15 * time.Second)
|
time.Sleep(15 * time.Second)
|
||||||
|
|||||||
@@ -17,17 +17,17 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
var (
|
var (
|
||||||
debugEnabled bool
|
debugEnabled bool
|
||||||
target string
|
target string
|
||||||
platform string
|
platform string
|
||||||
withTailscale bool
|
// withTailscale bool
|
||||||
)
|
)
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
flag.BoolVar(&debugEnabled, "debug", false, "enable debug")
|
flag.BoolVar(&debugEnabled, "debug", false, "enable debug")
|
||||||
flag.StringVar(&target, "target", "android", "target platform")
|
flag.StringVar(&target, "target", "android", "target platform")
|
||||||
flag.StringVar(&platform, "platform", "", "specify platform")
|
flag.StringVar(&platform, "platform", "", "specify platform")
|
||||||
flag.BoolVar(&withTailscale, "with-tailscale", false, "build tailscale for iOS and tvOS")
|
// flag.BoolVar(&withTailscale, "with-tailscale", false, "build tailscale for iOS and tvOS")
|
||||||
}
|
}
|
||||||
|
|
||||||
func main() {
|
func main() {
|
||||||
@@ -48,7 +48,7 @@ var (
|
|||||||
debugFlags []string
|
debugFlags []string
|
||||||
sharedTags []string
|
sharedTags []string
|
||||||
darwinTags []string
|
darwinTags []string
|
||||||
memcTags []string
|
// memcTags []string
|
||||||
notMemcTags []string
|
notMemcTags []string
|
||||||
debugTags []string
|
debugTags []string
|
||||||
)
|
)
|
||||||
@@ -63,9 +63,10 @@ func init() {
|
|||||||
sharedFlags = append(sharedFlags, "-ldflags", "-X github.com/sagernet/sing-box/constant.Version="+currentTag+" -X internal/godebug.defaultGODEBUG=multipathtcp=0 -s -w -buildid= -checklinkname=0")
|
sharedFlags = append(sharedFlags, "-ldflags", "-X github.com/sagernet/sing-box/constant.Version="+currentTag+" -X internal/godebug.defaultGODEBUG=multipathtcp=0 -s -w -buildid= -checklinkname=0")
|
||||||
debugFlags = append(debugFlags, "-ldflags", "-X github.com/sagernet/sing-box/constant.Version="+currentTag+" -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0")
|
debugFlags = append(debugFlags, "-ldflags", "-X github.com/sagernet/sing-box/constant.Version="+currentTag+" -X internal/godebug.defaultGODEBUG=multipathtcp=0 -checklinkname=0")
|
||||||
|
|
||||||
sharedTags = append(sharedTags, "with_gvisor", "with_quic", "with_wireguard", "with_utls", "with_naive_outbound", "with_clash_api", "with_conntrack", "badlinkname", "tfogo_checklinkname0")
|
sharedTags = append(sharedTags, "with_gvisor", "with_quic", "with_wireguard", "with_utls", "with_naive_outbound", "with_clash_api", "badlinkname", "tfogo_checklinkname0")
|
||||||
darwinTags = append(darwinTags, "with_dhcp")
|
darwinTags = append(darwinTags, "with_dhcp", "grpcnotrace")
|
||||||
memcTags = append(memcTags, "with_tailscale")
|
// memcTags = append(memcTags, "with_tailscale")
|
||||||
|
sharedTags = append(sharedTags, "with_tailscale", "ts_omit_logtail", "ts_omit_ssh", "ts_omit_drive", "ts_omit_taildrop", "ts_omit_webclient", "ts_omit_doctor", "ts_omit_capture", "ts_omit_kube", "ts_omit_aws", "ts_omit_synology", "ts_omit_bird")
|
||||||
notMemcTags = append(notMemcTags, "with_low_memory")
|
notMemcTags = append(notMemcTags, "with_low_memory")
|
||||||
debugTags = append(debugTags, "debug")
|
debugTags = append(debugTags, "debug")
|
||||||
}
|
}
|
||||||
@@ -164,7 +165,7 @@ func buildAndroid() {
|
|||||||
|
|
||||||
// Build main variant (SDK 23)
|
// Build main variant (SDK 23)
|
||||||
mainTags := append([]string{}, sharedTags...)
|
mainTags := append([]string{}, sharedTags...)
|
||||||
mainTags = append(mainTags, memcTags...)
|
// mainTags = append(mainTags, memcTags...)
|
||||||
if debugEnabled {
|
if debugEnabled {
|
||||||
mainTags = append(mainTags, debugTags...)
|
mainTags = append(mainTags, debugTags...)
|
||||||
}
|
}
|
||||||
@@ -176,7 +177,7 @@ func buildAndroid() {
|
|||||||
|
|
||||||
// Build legacy variant (SDK 21, no naive outbound)
|
// Build legacy variant (SDK 21, no naive outbound)
|
||||||
legacyTags := filterTags(sharedTags, "with_naive_outbound")
|
legacyTags := filterTags(sharedTags, "with_naive_outbound")
|
||||||
legacyTags = append(legacyTags, memcTags...)
|
// legacyTags = append(legacyTags, memcTags...)
|
||||||
if debugEnabled {
|
if debugEnabled {
|
||||||
legacyTags = append(legacyTags, debugTags...)
|
legacyTags = append(legacyTags, debugTags...)
|
||||||
}
|
}
|
||||||
@@ -204,9 +205,9 @@ func buildApple() {
|
|||||||
"-libname=box",
|
"-libname=box",
|
||||||
"-tags-not-macos=with_low_memory",
|
"-tags-not-macos=with_low_memory",
|
||||||
}
|
}
|
||||||
if !withTailscale {
|
//if !withTailscale {
|
||||||
args = append(args, "-tags-macos="+strings.Join(memcTags, ","))
|
// args = append(args, "-tags-macos="+strings.Join(memcTags, ","))
|
||||||
}
|
//}
|
||||||
|
|
||||||
if !debugEnabled {
|
if !debugEnabled {
|
||||||
args = append(args, sharedFlags...)
|
args = append(args, sharedFlags...)
|
||||||
@@ -215,9 +216,9 @@ func buildApple() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
tags := append(sharedTags, darwinTags...)
|
tags := append(sharedTags, darwinTags...)
|
||||||
if withTailscale {
|
//if withTailscale {
|
||||||
tags = append(tags, memcTags...)
|
// tags = append(tags, memcTags...)
|
||||||
}
|
//}
|
||||||
if debugEnabled {
|
if debugEnabled {
|
||||||
tags = append(tags, debugTags...)
|
tags = append(tags, debugTags...)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -71,12 +71,12 @@ func findAndReplace(objectsMap map[string]any, projectContent string, bundleIDLi
|
|||||||
indexEnd := indexStart + strings.Index(projectContent[indexStart:], "}")
|
indexEnd := indexStart + strings.Index(projectContent[indexStart:], "}")
|
||||||
versionStart := indexStart + strings.Index(projectContent[indexStart:indexEnd], "MARKETING_VERSION = ") + 20
|
versionStart := indexStart + strings.Index(projectContent[indexStart:indexEnd], "MARKETING_VERSION = ") + 20
|
||||||
versionEnd := versionStart + strings.Index(projectContent[versionStart:indexEnd], ";")
|
versionEnd := versionStart + strings.Index(projectContent[versionStart:indexEnd], ";")
|
||||||
version := projectContent[versionStart:versionEnd]
|
version := strings.Trim(projectContent[versionStart:versionEnd], "\"")
|
||||||
if version == newVersion {
|
if version == newVersion {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
updated = true
|
updated = true
|
||||||
projectContent = projectContent[:versionStart] + newVersion + projectContent[versionEnd:]
|
projectContent = projectContent[:versionStart] + "\"" + newVersion + "\"" + projectContent[versionEnd:]
|
||||||
}
|
}
|
||||||
return projectContent, updated
|
return projectContent, updated
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,54 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
"net"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
type Conn struct {
|
|
||||||
net.Conn
|
|
||||||
element *list.Element[io.Closer]
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewConn(conn net.Conn) (net.Conn, error) {
|
|
||||||
connAccess.Lock()
|
|
||||||
element := openConnection.PushBack(conn)
|
|
||||||
connAccess.Unlock()
|
|
||||||
if KillerEnabled {
|
|
||||||
err := KillerCheck()
|
|
||||||
if err != nil {
|
|
||||||
conn.Close()
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return &Conn{
|
|
||||||
Conn: conn,
|
|
||||||
element: element,
|
|
||||||
}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) Close() error {
|
|
||||||
if c.element.Value != nil {
|
|
||||||
connAccess.Lock()
|
|
||||||
if c.element.Value != nil {
|
|
||||||
openConnection.Remove(c.element)
|
|
||||||
c.element.Value = nil
|
|
||||||
}
|
|
||||||
connAccess.Unlock()
|
|
||||||
}
|
|
||||||
return c.Conn.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) Upstream() any {
|
|
||||||
return c.Conn
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) ReaderReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) WriterReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
runtimeDebug "runtime/debug"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
"github.com/sagernet/sing/common/memory"
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
KillerEnabled bool
|
|
||||||
MemoryLimit uint64
|
|
||||||
killerLastCheck time.Time
|
|
||||||
)
|
|
||||||
|
|
||||||
func KillerCheck() error {
|
|
||||||
if !KillerEnabled {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
nowTime := time.Now()
|
|
||||||
if nowTime.Sub(killerLastCheck) < 3*time.Second {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
killerLastCheck = nowTime
|
|
||||||
if memory.Total() > MemoryLimit {
|
|
||||||
Close()
|
|
||||||
go func() {
|
|
||||||
time.Sleep(time.Second)
|
|
||||||
runtimeDebug.FreeOSMemory()
|
|
||||||
}()
|
|
||||||
return E.New("out of memory")
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
"net"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/bufio"
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
type PacketConn struct {
|
|
||||||
net.PacketConn
|
|
||||||
element *list.Element[io.Closer]
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewPacketConn(conn net.PacketConn) (net.PacketConn, error) {
|
|
||||||
connAccess.Lock()
|
|
||||||
element := openConnection.PushBack(conn)
|
|
||||||
connAccess.Unlock()
|
|
||||||
if KillerEnabled {
|
|
||||||
err := KillerCheck()
|
|
||||||
if err != nil {
|
|
||||||
conn.Close()
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return &PacketConn{
|
|
||||||
PacketConn: conn,
|
|
||||||
element: element,
|
|
||||||
}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) Close() error {
|
|
||||||
if c.element.Value != nil {
|
|
||||||
connAccess.Lock()
|
|
||||||
if c.element.Value != nil {
|
|
||||||
openConnection.Remove(c.element)
|
|
||||||
c.element.Value = nil
|
|
||||||
}
|
|
||||||
connAccess.Unlock()
|
|
||||||
}
|
|
||||||
return c.PacketConn.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) Upstream() any {
|
|
||||||
return bufio.NewPacketConn(c.PacketConn)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) ReaderReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) WriterReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
"sync"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
connAccess sync.RWMutex
|
|
||||||
openConnection list.List[io.Closer]
|
|
||||||
)
|
|
||||||
|
|
||||||
func Count() int {
|
|
||||||
if !Enabled {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
return openConnection.Len()
|
|
||||||
}
|
|
||||||
|
|
||||||
func List() []io.Closer {
|
|
||||||
if !Enabled {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
connAccess.RLock()
|
|
||||||
defer connAccess.RUnlock()
|
|
||||||
connList := make([]io.Closer, 0, openConnection.Len())
|
|
||||||
for element := openConnection.Front(); element != nil; element = element.Next() {
|
|
||||||
connList = append(connList, element.Value)
|
|
||||||
}
|
|
||||||
return connList
|
|
||||||
}
|
|
||||||
|
|
||||||
func Close() {
|
|
||||||
if !Enabled {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
connAccess.Lock()
|
|
||||||
defer connAccess.Unlock()
|
|
||||||
for element := openConnection.Front(); element != nil; element = element.Next() {
|
|
||||||
common.Close(element.Value)
|
|
||||||
element.Value = nil
|
|
||||||
}
|
|
||||||
openConnection.Init()
|
|
||||||
}
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
//go:build !with_conntrack
|
|
||||||
|
|
||||||
package conntrack
|
|
||||||
|
|
||||||
const Enabled = false
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
//go:build with_conntrack
|
|
||||||
|
|
||||||
package conntrack
|
|
||||||
|
|
||||||
const Enabled = true
|
|
||||||
@@ -9,7 +9,6 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/common/conntrack"
|
|
||||||
"github.com/sagernet/sing-box/common/listener"
|
"github.com/sagernet/sing-box/common/listener"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
@@ -37,6 +36,7 @@ type DefaultDialer struct {
|
|||||||
udpAddr4 string
|
udpAddr4 string
|
||||||
udpAddr6 string
|
udpAddr6 string
|
||||||
netns string
|
netns string
|
||||||
|
connectionManager adapter.ConnectionManager
|
||||||
networkManager adapter.NetworkManager
|
networkManager adapter.NetworkManager
|
||||||
networkStrategy *C.NetworkStrategy
|
networkStrategy *C.NetworkStrategy
|
||||||
defaultNetworkStrategy bool
|
defaultNetworkStrategy bool
|
||||||
@@ -47,6 +47,7 @@ type DefaultDialer struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func NewDefault(ctx context.Context, options option.DialerOptions) (*DefaultDialer, error) {
|
func NewDefault(ctx context.Context, options option.DialerOptions) (*DefaultDialer, error) {
|
||||||
|
connectionManager := service.FromContext[adapter.ConnectionManager](ctx)
|
||||||
networkManager := service.FromContext[adapter.NetworkManager](ctx)
|
networkManager := service.FromContext[adapter.NetworkManager](ctx)
|
||||||
platformInterface := service.FromContext[adapter.PlatformInterface](ctx)
|
platformInterface := service.FromContext[adapter.PlatformInterface](ctx)
|
||||||
|
|
||||||
@@ -89,7 +90,7 @@ func NewDefault(ctx context.Context, options option.DialerOptions) (*DefaultDial
|
|||||||
|
|
||||||
if networkManager != nil {
|
if networkManager != nil {
|
||||||
defaultOptions := networkManager.DefaultOptions()
|
defaultOptions := networkManager.DefaultOptions()
|
||||||
if defaultOptions.BindInterface != "" {
|
if defaultOptions.BindInterface != "" && !disableDefaultBind {
|
||||||
bindFunc := control.BindToInterface(networkManager.InterfaceFinder(), defaultOptions.BindInterface, -1)
|
bindFunc := control.BindToInterface(networkManager.InterfaceFinder(), defaultOptions.BindInterface, -1)
|
||||||
dialer.Control = control.Append(dialer.Control, bindFunc)
|
dialer.Control = control.Append(dialer.Control, bindFunc)
|
||||||
listener.Control = control.Append(listener.Control, bindFunc)
|
listener.Control = control.Append(listener.Control, bindFunc)
|
||||||
@@ -157,8 +158,11 @@ func NewDefault(ctx context.Context, options option.DialerOptions) (*DefaultDial
|
|||||||
if keepInterval == 0 {
|
if keepInterval == 0 {
|
||||||
keepInterval = C.TCPKeepAliveInterval
|
keepInterval = C.TCPKeepAliveInterval
|
||||||
}
|
}
|
||||||
dialer.KeepAlive = keepIdle
|
dialer.KeepAliveConfig = net.KeepAliveConfig{
|
||||||
dialer.Control = control.Append(dialer.Control, control.SetKeepAlivePeriod(keepIdle, keepInterval))
|
Enable: true,
|
||||||
|
Idle: keepIdle,
|
||||||
|
Interval: keepInterval,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
var udpFragment bool
|
var udpFragment bool
|
||||||
if options.UDPFragment != nil {
|
if options.UDPFragment != nil {
|
||||||
@@ -206,6 +210,7 @@ func NewDefault(ctx context.Context, options option.DialerOptions) (*DefaultDial
|
|||||||
udpAddr4: udpAddr4,
|
udpAddr4: udpAddr4,
|
||||||
udpAddr6: udpAddr6,
|
udpAddr6: udpAddr6,
|
||||||
netns: options.NetNs,
|
netns: options.NetNs,
|
||||||
|
connectionManager: connectionManager,
|
||||||
networkManager: networkManager,
|
networkManager: networkManager,
|
||||||
networkStrategy: networkStrategy,
|
networkStrategy: networkStrategy,
|
||||||
defaultNetworkStrategy: defaultNetworkStrategy,
|
defaultNetworkStrategy: defaultNetworkStrategy,
|
||||||
@@ -234,11 +239,11 @@ func setMarkWrapper(networkManager adapter.NetworkManager, mark uint32, isDefaul
|
|||||||
func (d *DefaultDialer) DialContext(ctx context.Context, network string, address M.Socksaddr) (net.Conn, error) {
|
func (d *DefaultDialer) DialContext(ctx context.Context, network string, address M.Socksaddr) (net.Conn, error) {
|
||||||
if !address.IsValid() {
|
if !address.IsValid() {
|
||||||
return nil, E.New("invalid address")
|
return nil, E.New("invalid address")
|
||||||
} else if address.IsFqdn() {
|
} else if address.IsDomain() {
|
||||||
return nil, E.New("domain not resolved")
|
return nil, E.New("domain not resolved")
|
||||||
}
|
}
|
||||||
if d.networkStrategy == nil {
|
if d.networkStrategy == nil {
|
||||||
return trackConn(listener.ListenNetworkNamespace[net.Conn](d.netns, func() (net.Conn, error) {
|
return d.trackConn(listener.ListenNetworkNamespace[net.Conn](d.netns, func() (net.Conn, error) {
|
||||||
switch N.NetworkName(network) {
|
switch N.NetworkName(network) {
|
||||||
case N.NetworkUDP:
|
case N.NetworkUDP:
|
||||||
if !address.IsIPv6() {
|
if !address.IsIPv6() {
|
||||||
@@ -303,12 +308,12 @@ func (d *DefaultDialer) DialParallelInterface(ctx context.Context, network strin
|
|||||||
if !fastFallback && !isPrimary {
|
if !fastFallback && !isPrimary {
|
||||||
d.networkLastFallback.Store(time.Now())
|
d.networkLastFallback.Store(time.Now())
|
||||||
}
|
}
|
||||||
return trackConn(conn, nil)
|
return d.trackConn(conn, nil)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *DefaultDialer) ListenPacket(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
|
func (d *DefaultDialer) ListenPacket(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
|
||||||
if d.networkStrategy == nil {
|
if d.networkStrategy == nil {
|
||||||
return trackPacketConn(listener.ListenNetworkNamespace[net.PacketConn](d.netns, func() (net.PacketConn, error) {
|
return d.trackPacketConn(listener.ListenNetworkNamespace[net.PacketConn](d.netns, func() (net.PacketConn, error) {
|
||||||
if destination.IsIPv6() {
|
if destination.IsIPv6() {
|
||||||
return d.udpListener.ListenPacket(ctx, N.NetworkUDP, d.udpAddr6)
|
return d.udpListener.ListenPacket(ctx, N.NetworkUDP, d.udpAddr6)
|
||||||
} else if destination.IsIPv4() && !destination.Addr.IsUnspecified() {
|
} else if destination.IsIPv4() && !destination.Addr.IsUnspecified() {
|
||||||
@@ -324,9 +329,9 @@ func (d *DefaultDialer) ListenPacket(ctx context.Context, destination M.Socksadd
|
|||||||
|
|
||||||
func (d *DefaultDialer) DialerForICMPDestination(destination netip.Addr) net.Dialer {
|
func (d *DefaultDialer) DialerForICMPDestination(destination netip.Addr) net.Dialer {
|
||||||
if !destination.Is6() {
|
if !destination.Is6() {
|
||||||
return d.dialer6.Dialer
|
|
||||||
} else {
|
|
||||||
return d.dialer4.Dialer
|
return d.dialer4.Dialer
|
||||||
|
} else {
|
||||||
|
return d.dialer6.Dialer
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -360,23 +365,23 @@ func (d *DefaultDialer) ListenSerialInterfacePacket(ctx context.Context, destina
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return trackPacketConn(packetConn, nil)
|
return d.trackPacketConn(packetConn, nil)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *DefaultDialer) WireGuardControl() control.Func {
|
func (d *DefaultDialer) WireGuardControl() control.Func {
|
||||||
return d.udpListener.Control
|
return d.udpListener.Control
|
||||||
}
|
}
|
||||||
|
|
||||||
func trackConn(conn net.Conn, err error) (net.Conn, error) {
|
func (d *DefaultDialer) trackConn(conn net.Conn, err error) (net.Conn, error) {
|
||||||
if !conntrack.Enabled || err != nil {
|
if d.connectionManager == nil || err != nil {
|
||||||
return conn, err
|
return conn, err
|
||||||
}
|
}
|
||||||
return conntrack.NewConn(conn)
|
return d.connectionManager.TrackConn(conn), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func trackPacketConn(conn net.PacketConn, err error) (net.PacketConn, error) {
|
func (d *DefaultDialer) trackPacketConn(conn net.PacketConn, err error) (net.PacketConn, error) {
|
||||||
if !conntrack.Enabled || err != nil {
|
if d.connectionManager == nil || err != nil {
|
||||||
return conn, err
|
return conn, err
|
||||||
}
|
}
|
||||||
return conntrack.NewPacketConn(conn)
|
return d.connectionManager.TrackPacketConn(conn), nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -145,3 +145,7 @@ type ParallelNetworkDialer interface {
|
|||||||
DialParallelNetwork(ctx context.Context, network string, destination M.Socksaddr, destinationAddresses []netip.Addr, strategy *C.NetworkStrategy, interfaceType []C.InterfaceType, fallbackInterfaceType []C.InterfaceType, fallbackDelay time.Duration) (net.Conn, error)
|
DialParallelNetwork(ctx context.Context, network string, destination M.Socksaddr, destinationAddresses []netip.Addr, strategy *C.NetworkStrategy, interfaceType []C.InterfaceType, fallbackInterfaceType []C.InterfaceType, fallbackDelay time.Duration) (net.Conn, error)
|
||||||
ListenSerialNetworkPacket(ctx context.Context, destination M.Socksaddr, destinationAddresses []netip.Addr, strategy *C.NetworkStrategy, interfaceType []C.InterfaceType, fallbackInterfaceType []C.InterfaceType, fallbackDelay time.Duration) (net.PacketConn, netip.Addr, error)
|
ListenSerialNetworkPacket(ctx context.Context, destination M.Socksaddr, destinationAddresses []netip.Addr, strategy *C.NetworkStrategy, interfaceType []C.InterfaceType, fallbackInterfaceType []C.InterfaceType, fallbackDelay time.Duration) (net.PacketConn, netip.Addr, error)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type PacketDialerWithDestination interface {
|
||||||
|
ListenPacketWithDestination(ctx context.Context, destination M.Socksaddr) (net.PacketConn, netip.Addr, error)
|
||||||
|
}
|
||||||
|
|||||||
@@ -96,7 +96,7 @@ func (d *resolveDialer) DialContext(ctx context.Context, network string, destina
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if !destination.IsFqdn() {
|
if !destination.IsDomain() {
|
||||||
return d.dialer.DialContext(ctx, network, destination)
|
return d.dialer.DialContext(ctx, network, destination)
|
||||||
}
|
}
|
||||||
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
||||||
@@ -116,7 +116,7 @@ func (d *resolveDialer) ListenPacket(ctx context.Context, destination M.Socksadd
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if !destination.IsFqdn() {
|
if !destination.IsDomain() {
|
||||||
return d.dialer.ListenPacket(ctx, destination)
|
return d.dialer.ListenPacket(ctx, destination)
|
||||||
}
|
}
|
||||||
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
||||||
@@ -144,7 +144,7 @@ func (d *resolveParallelNetworkDialer) DialParallelInterface(ctx context.Context
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if !destination.IsFqdn() {
|
if !destination.IsDomain() {
|
||||||
return d.dialer.DialContext(ctx, network, destination)
|
return d.dialer.DialContext(ctx, network, destination)
|
||||||
}
|
}
|
||||||
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
||||||
@@ -167,7 +167,7 @@ func (d *resolveParallelNetworkDialer) ListenSerialInterfacePacket(ctx context.C
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if !destination.IsFqdn() {
|
if !destination.IsDomain() {
|
||||||
return d.dialer.ListenPacket(ctx, destination)
|
return d.dialer.ListenPacket(ctx, destination)
|
||||||
}
|
}
|
||||||
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
ctx = log.ContextWithOverrideLevel(ctx, log.LevelDebug)
|
||||||
|
|||||||
234
common/geosite/compat_test.go
Normal file
234
common/geosite/compat_test.go
Normal file
@@ -0,0 +1,234 @@
|
|||||||
|
package geosite
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"bytes"
|
||||||
|
"encoding/binary"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/sagernet/sing/common/varbin"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Old implementation using varbin reflection-based serialization
|
||||||
|
|
||||||
|
func oldWriteString(writer varbin.Writer, value string) error {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.Write(writer, binary.BigEndian, value)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldWriteItem(writer varbin.Writer, item Item) error {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.Write(writer, binary.BigEndian, item)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldReadString(reader varbin.Reader) (string, error) {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.ReadValue[string](reader, binary.BigEndian)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldReadItem(reader varbin.Reader) (Item, error) {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.ReadValue[Item](reader, binary.BigEndian)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStringCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input string
|
||||||
|
}{
|
||||||
|
{"empty", ""},
|
||||||
|
{"single_char", "a"},
|
||||||
|
{"ascii", "example.com"},
|
||||||
|
{"utf8", "测试域名.中国"},
|
||||||
|
{"special_chars", "\x00\xff\n\t"},
|
||||||
|
{"127_bytes", strings.Repeat("x", 127)},
|
||||||
|
{"128_bytes", strings.Repeat("x", 128)},
|
||||||
|
{"16383_bytes", strings.Repeat("x", 16383)},
|
||||||
|
{"16384_bytes", strings.Repeat("x", 16384)},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Old write
|
||||||
|
var oldBuf bytes.Buffer
|
||||||
|
err := oldWriteString(&oldBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err = writeString(&newBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Bytes must match
|
||||||
|
require.Equal(t, oldBuf.Bytes(), newBuf.Bytes(),
|
||||||
|
"mismatch for %q\nold: %x\nnew: %x", tc.name, oldBuf.Bytes(), newBuf.Bytes())
|
||||||
|
|
||||||
|
// New write -> old read
|
||||||
|
readBack, err := oldReadString(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// Old write -> new read
|
||||||
|
readBack2, err := readString(bufio.NewReader(bytes.NewReader(oldBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, tc.input, readBack2)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestItemCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Note: varbin.Write has a bug where struct values (not pointers) don't write their fields
|
||||||
|
// because field.CanSet() returns false for non-addressable values.
|
||||||
|
// The old geosite code passed Item values to varbin.Write, which silently wrote nothing.
|
||||||
|
// The new code correctly writes Type + Value using manual serialization.
|
||||||
|
// This test verifies the new serialization format and round-trip correctness.
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input Item
|
||||||
|
}{
|
||||||
|
{"domain_empty", Item{Type: RuleTypeDomain, Value: ""}},
|
||||||
|
{"domain_normal", Item{Type: RuleTypeDomain, Value: "example.com"}},
|
||||||
|
{"domain_suffix", Item{Type: RuleTypeDomainSuffix, Value: ".example.com"}},
|
||||||
|
{"domain_keyword", Item{Type: RuleTypeDomainKeyword, Value: "google"}},
|
||||||
|
{"domain_regex", Item{Type: RuleTypeDomainRegex, Value: `^.*\.example\.com$`}},
|
||||||
|
{"utf8_domain", Item{Type: RuleTypeDomain, Value: "测试.com"}},
|
||||||
|
{"long_domain", Item{Type: RuleTypeDomainSuffix, Value: strings.Repeat("a", 200) + ".com"}},
|
||||||
|
{"128_bytes_value", Item{Type: RuleTypeDomain, Value: strings.Repeat("x", 128)}},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err := newBuf.WriteByte(byte(tc.input.Type))
|
||||||
|
require.NoError(t, err)
|
||||||
|
err = writeString(&newBuf, tc.input.Value)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Verify format: Type (1 byte) + Value (uvarint len + bytes)
|
||||||
|
require.True(t, len(newBuf.Bytes()) >= 1, "output too short")
|
||||||
|
require.Equal(t, byte(tc.input.Type), newBuf.Bytes()[0], "type byte mismatch")
|
||||||
|
|
||||||
|
// New write -> old read (varbin can read correctly when given addressable target)
|
||||||
|
readBack, err := oldReadItem(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// New write -> new read
|
||||||
|
reader := bufio.NewReader(bytes.NewReader(newBuf.Bytes()))
|
||||||
|
typeByte, err := reader.ReadByte()
|
||||||
|
require.NoError(t, err)
|
||||||
|
value, err := readString(reader)
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, tc.input, Item{Type: ItemType(typeByte), Value: value})
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestGeositeWriteReadCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input map[string][]Item
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
"empty_map",
|
||||||
|
map[string][]Item{},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"single_code_empty_items",
|
||||||
|
map[string][]Item{"test": {}},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"single_code_single_item",
|
||||||
|
map[string][]Item{"test": {{Type: RuleTypeDomain, Value: "a.com"}}},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"single_code_multi_items",
|
||||||
|
map[string][]Item{
|
||||||
|
"test": {
|
||||||
|
{Type: RuleTypeDomain, Value: "a.com"},
|
||||||
|
{Type: RuleTypeDomainSuffix, Value: ".b.com"},
|
||||||
|
{Type: RuleTypeDomainKeyword, Value: "keyword"},
|
||||||
|
{Type: RuleTypeDomainRegex, Value: `^.*$`},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"multi_code",
|
||||||
|
map[string][]Item{
|
||||||
|
"cn": {{Type: RuleTypeDomain, Value: "baidu.com"}, {Type: RuleTypeDomainSuffix, Value: ".cn"}},
|
||||||
|
"us": {{Type: RuleTypeDomain, Value: "google.com"}},
|
||||||
|
"jp": {{Type: RuleTypeDomainSuffix, Value: ".jp"}},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"utf8_values",
|
||||||
|
map[string][]Item{
|
||||||
|
"test": {
|
||||||
|
{Type: RuleTypeDomain, Value: "测试.中国"},
|
||||||
|
{Type: RuleTypeDomainSuffix, Value: ".テスト"},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"large_items",
|
||||||
|
generateLargeItems(1000),
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Write using new implementation
|
||||||
|
var buf bytes.Buffer
|
||||||
|
err := Write(&buf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Read back and verify
|
||||||
|
reader, codes, err := NewReader(bytes.NewReader(buf.Bytes()))
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Verify all codes exist
|
||||||
|
codeSet := make(map[string]bool)
|
||||||
|
for _, code := range codes {
|
||||||
|
codeSet[code] = true
|
||||||
|
}
|
||||||
|
for code := range tc.input {
|
||||||
|
require.True(t, codeSet[code], "missing code: %s", code)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Verify items match
|
||||||
|
for code, expectedItems := range tc.input {
|
||||||
|
items, err := reader.Read(code)
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, expectedItems, items, "items mismatch for code: %s", code)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func generateLargeItems(count int) map[string][]Item {
|
||||||
|
items := make([]Item, count)
|
||||||
|
for i := 0; i < count; i++ {
|
||||||
|
items[i] = Item{
|
||||||
|
Type: ItemType(i % 4),
|
||||||
|
Value: strings.Repeat("x", i%200) + ".com",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return map[string][]Item{"large": items}
|
||||||
|
}
|
||||||
@@ -9,7 +9,6 @@ import (
|
|||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
"github.com/sagernet/sing/common/varbin"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type Reader struct {
|
type Reader struct {
|
||||||
@@ -78,7 +77,7 @@ func (r *Reader) readMetadata() error {
|
|||||||
codeIndex uint64
|
codeIndex uint64
|
||||||
codeLength uint64
|
codeLength uint64
|
||||||
)
|
)
|
||||||
code, err = varbin.ReadValue[string](reader, binary.BigEndian)
|
code, err = readString(reader)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -112,9 +111,16 @@ func (r *Reader) Read(code string) ([]Item, error) {
|
|||||||
}
|
}
|
||||||
r.bufferedReader.Reset(r.reader)
|
r.bufferedReader.Reset(r.reader)
|
||||||
itemList := make([]Item, r.domainLength[code])
|
itemList := make([]Item, r.domainLength[code])
|
||||||
err = varbin.Read(r.bufferedReader, binary.BigEndian, &itemList)
|
for i := range itemList {
|
||||||
if err != nil {
|
typeByte, err := r.bufferedReader.ReadByte()
|
||||||
return nil, err
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
itemList[i].Type = ItemType(typeByte)
|
||||||
|
itemList[i].Value, err = readString(r.bufferedReader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
return itemList, nil
|
return itemList, nil
|
||||||
}
|
}
|
||||||
@@ -135,3 +141,18 @@ func (r *readCounter) Read(p []byte) (n int, err error) {
|
|||||||
}
|
}
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func readString(reader io.ByteReader) (string, error) {
|
||||||
|
length, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
bytes := make([]byte, length)
|
||||||
|
for i := range bytes {
|
||||||
|
bytes[i], err = reader.ReadByte()
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return string(bytes), nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -2,7 +2,6 @@ package geosite
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
"encoding/binary"
|
|
||||||
"sort"
|
"sort"
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/varbin"
|
"github.com/sagernet/sing/common/varbin"
|
||||||
@@ -20,7 +19,11 @@ func Write(writer varbin.Writer, domains map[string][]Item) error {
|
|||||||
for _, code := range keys {
|
for _, code := range keys {
|
||||||
index[code] = content.Len()
|
index[code] = content.Len()
|
||||||
for _, item := range domains[code] {
|
for _, item := range domains[code] {
|
||||||
err := varbin.Write(content, binary.BigEndian, item)
|
err := content.WriteByte(byte(item.Type))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
err = writeString(content, item.Value)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -38,7 +41,7 @@ func Write(writer varbin.Writer, domains map[string][]Item) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
for _, code := range keys {
|
for _, code := range keys {
|
||||||
err = varbin.Write(writer, binary.BigEndian, code)
|
err = writeString(writer, code)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -59,3 +62,12 @@ func Write(writer varbin.Writer, domains map[string][]Item) error {
|
|||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func writeString(writer varbin.Writer, value string) error {
|
||||||
|
_, err := varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write([]byte(value))
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net"
|
"net"
|
||||||
|
"unsafe"
|
||||||
)
|
)
|
||||||
|
|
||||||
func (c *Conn) Read(b []byte) (int, error) {
|
func (c *Conn) Read(b []byte) (int, error) {
|
||||||
@@ -229,7 +230,7 @@ func (c *Conn) readRawRecord() (typ uint8, data []byte, err error) {
|
|||||||
record := c.rawConn.RawInput.Next(recordHeaderLen + n)
|
record := c.rawConn.RawInput.Next(recordHeaderLen + n)
|
||||||
data, typ, err = c.rawConn.In.Decrypt(record)
|
data, typ, err = c.rawConn.In.Decrypt(record)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
err = c.rawConn.In.SetErrorLocked(c.sendAlert(uint8(err.(tls.AlertError))))
|
err = c.rawConn.In.SetErrorLocked(c.sendAlert(*(*uint8)((*[2]unsafe.Pointer)(unsafe.Pointer(&err))[1])))
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
return
|
return
|
||||||
|
|||||||
@@ -151,6 +151,7 @@ func ListenNetworkNamespace[T any](nameOrPath string, block func() (T, error)) (
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return common.DefaultValue[T](), E.Cause(err, "get current netns")
|
return common.DefaultValue[T](), E.Cause(err, "get current netns")
|
||||||
}
|
}
|
||||||
|
defer currentNs.Close()
|
||||||
defer netns.Set(currentNs)
|
defer netns.Set(currentNs)
|
||||||
var targetNs netns.NsHandle
|
var targetNs netns.NsHandle
|
||||||
if strings.HasPrefix(nameOrPath, "/") {
|
if strings.HasPrefix(nameOrPath, "/") {
|
||||||
|
|||||||
@@ -99,8 +99,6 @@ func (l *Listener) loopTCPIn() {
|
|||||||
}
|
}
|
||||||
//nolint:staticcheck
|
//nolint:staticcheck
|
||||||
metadata.InboundDetour = l.listenOptions.Detour
|
metadata.InboundDetour = l.listenOptions.Detour
|
||||||
//nolint:staticcheck
|
|
||||||
metadata.InboundOptions = l.listenOptions.InboundOptions
|
|
||||||
metadata.Source = M.SocksaddrFromNet(conn.RemoteAddr()).Unwrap()
|
metadata.Source = M.SocksaddrFromNet(conn.RemoteAddr()).Unwrap()
|
||||||
metadata.OriginDestination = M.SocksaddrFromNet(conn.LocalAddr()).Unwrap()
|
metadata.OriginDestination = M.SocksaddrFromNet(conn.LocalAddr()).Unwrap()
|
||||||
ctx := log.ContextWithNewID(l.ctx)
|
ctx := log.ContextWithNewID(l.ctx)
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import (
|
|||||||
|
|
||||||
type Searcher interface {
|
type Searcher interface {
|
||||||
FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error)
|
FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error)
|
||||||
|
Close() error
|
||||||
}
|
}
|
||||||
|
|
||||||
var ErrNotFound = E.New("process not found")
|
var ErrNotFound = E.New("process not found")
|
||||||
@@ -28,7 +29,7 @@ func FindProcessInfo(searcher Searcher, ctx context.Context, network string, sou
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if info.UserId != -1 {
|
if info.UserId != -1 && info.UserName == "" {
|
||||||
osUser, _ := user.LookupId(F.ToString(info.UserId))
|
osUser, _ := user.LookupId(F.ToString(info.UserId))
|
||||||
if osUser != nil {
|
if osUser != nil {
|
||||||
info.UserName = osUser.Username
|
info.UserName = osUser.Username
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import (
|
|||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-tun"
|
"github.com/sagernet/sing-tun"
|
||||||
|
"github.com/sagernet/sing/common"
|
||||||
)
|
)
|
||||||
|
|
||||||
var _ Searcher = (*androidSearcher)(nil)
|
var _ Searcher = (*androidSearcher)(nil)
|
||||||
@@ -18,22 +19,30 @@ func NewSearcher(config Config) (Searcher, error) {
|
|||||||
return &androidSearcher{config.PackageManager}, nil
|
return &androidSearcher{config.PackageManager}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (s *androidSearcher) Close() error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (s *androidSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
func (s *androidSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
||||||
_, uid, err := resolveSocketByNetlink(network, source, destination)
|
family, protocol, err := socketDiagSettings(network, source)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if sharedPackage, loaded := s.packageManager.SharedPackageByID(uid % 100000); loaded {
|
_, uid, err := querySocketDiagOnce(family, protocol, source)
|
||||||
return &adapter.ConnectionOwner{
|
if err != nil {
|
||||||
UserId: int32(uid),
|
return nil, err
|
||||||
AndroidPackageName: sharedPackage,
|
|
||||||
}, nil
|
|
||||||
}
|
}
|
||||||
if packageName, loaded := s.packageManager.PackageByID(uid % 100000); loaded {
|
appID := uid % 100000
|
||||||
return &adapter.ConnectionOwner{
|
var packageNames []string
|
||||||
UserId: int32(uid),
|
if sharedPackage, loaded := s.packageManager.SharedPackageByID(appID); loaded {
|
||||||
AndroidPackageName: packageName,
|
packageNames = append(packageNames, sharedPackage)
|
||||||
}, nil
|
|
||||||
}
|
}
|
||||||
return &adapter.ConnectionOwner{UserId: int32(uid)}, nil
|
if packages, loaded := s.packageManager.PackagesByID(appID); loaded {
|
||||||
|
packageNames = append(packageNames, packages...)
|
||||||
|
}
|
||||||
|
packageNames = common.Uniq(packageNames)
|
||||||
|
return &adapter.ConnectionOwner{
|
||||||
|
UserId: int32(uid),
|
||||||
|
AndroidPackageNames: packageNames,
|
||||||
|
}, nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,19 +1,15 @@
|
|||||||
|
//go:build darwin
|
||||||
|
|
||||||
package process
|
package process
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"encoding/binary"
|
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
"syscall"
|
"syscall"
|
||||||
"unsafe"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
N "github.com/sagernet/sing/common/network"
|
|
||||||
|
|
||||||
"golang.org/x/sys/unix"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
var _ Searcher = (*darwinSearcher)(nil)
|
var _ Searcher = (*darwinSearcher)(nil)
|
||||||
@@ -24,12 +20,12 @@ func NewSearcher(_ Config) (Searcher, error) {
|
|||||||
return &darwinSearcher{}, nil
|
return &darwinSearcher{}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (d *darwinSearcher) Close() error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (d *darwinSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
func (d *darwinSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
||||||
processName, err := findProcessName(network, source.Addr(), int(source.Port()))
|
return FindDarwinConnectionOwner(network, source, destination)
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return &adapter.ConnectionOwner{ProcessPath: processName, UserId: -1}, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
var structSize = func() int {
|
var structSize = func() int {
|
||||||
@@ -47,107 +43,3 @@ var structSize = func() int {
|
|||||||
return 384
|
return 384
|
||||||
}
|
}
|
||||||
}()
|
}()
|
||||||
|
|
||||||
func findProcessName(network string, ip netip.Addr, port int) (string, error) {
|
|
||||||
var spath string
|
|
||||||
switch network {
|
|
||||||
case N.NetworkTCP:
|
|
||||||
spath = "net.inet.tcp.pcblist_n"
|
|
||||||
case N.NetworkUDP:
|
|
||||||
spath = "net.inet.udp.pcblist_n"
|
|
||||||
default:
|
|
||||||
return "", os.ErrInvalid
|
|
||||||
}
|
|
||||||
|
|
||||||
isIPv4 := ip.Is4()
|
|
||||||
|
|
||||||
value, err := unix.SysctlRaw(spath)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
buf := value
|
|
||||||
|
|
||||||
// from darwin-xnu/bsd/netinet/in_pcblist.c:get_pcblist_n
|
|
||||||
// size/offset are round up (aligned) to 8 bytes in darwin
|
|
||||||
// rup8(sizeof(xinpcb_n)) + rup8(sizeof(xsocket_n)) +
|
|
||||||
// 2 * rup8(sizeof(xsockbuf_n)) + rup8(sizeof(xsockstat_n))
|
|
||||||
itemSize := structSize
|
|
||||||
if network == N.NetworkTCP {
|
|
||||||
// rup8(sizeof(xtcpcb_n))
|
|
||||||
itemSize += 208
|
|
||||||
}
|
|
||||||
|
|
||||||
var fallbackUDPProcess string
|
|
||||||
// skip the first xinpgen(24 bytes) block
|
|
||||||
for i := 24; i+itemSize <= len(buf); i += itemSize {
|
|
||||||
// offset of xinpcb_n and xsocket_n
|
|
||||||
inp, so := i, i+104
|
|
||||||
|
|
||||||
srcPort := binary.BigEndian.Uint16(buf[inp+18 : inp+20])
|
|
||||||
if uint16(port) != srcPort {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
// xinpcb_n.inp_vflag
|
|
||||||
flag := buf[inp+44]
|
|
||||||
|
|
||||||
var srcIP netip.Addr
|
|
||||||
srcIsIPv4 := false
|
|
||||||
switch {
|
|
||||||
case flag&0x1 > 0 && isIPv4:
|
|
||||||
// ipv4
|
|
||||||
srcIP = netip.AddrFrom4([4]byte(buf[inp+76 : inp+80]))
|
|
||||||
srcIsIPv4 = true
|
|
||||||
case flag&0x2 > 0 && !isIPv4:
|
|
||||||
// ipv6
|
|
||||||
srcIP = netip.AddrFrom16([16]byte(buf[inp+64 : inp+80]))
|
|
||||||
default:
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
if ip == srcIP {
|
|
||||||
// xsocket_n.so_last_pid
|
|
||||||
pid := readNativeUint32(buf[so+68 : so+72])
|
|
||||||
return getExecPathFromPID(pid)
|
|
||||||
}
|
|
||||||
|
|
||||||
// udp packet connection may be not equal with srcIP
|
|
||||||
if network == N.NetworkUDP && srcIP.IsUnspecified() && isIPv4 == srcIsIPv4 {
|
|
||||||
pid := readNativeUint32(buf[so+68 : so+72])
|
|
||||||
fallbackUDPProcess, _ = getExecPathFromPID(pid)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if network == N.NetworkUDP && len(fallbackUDPProcess) > 0 {
|
|
||||||
return fallbackUDPProcess, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
return "", ErrNotFound
|
|
||||||
}
|
|
||||||
|
|
||||||
func getExecPathFromPID(pid uint32) (string, error) {
|
|
||||||
const (
|
|
||||||
procpidpathinfo = 0xb
|
|
||||||
procpidpathinfosize = 1024
|
|
||||||
proccallnumpidinfo = 0x2
|
|
||||||
)
|
|
||||||
buf := make([]byte, procpidpathinfosize)
|
|
||||||
_, _, errno := syscall.Syscall6(
|
|
||||||
syscall.SYS_PROC_INFO,
|
|
||||||
proccallnumpidinfo,
|
|
||||||
uintptr(pid),
|
|
||||||
procpidpathinfo,
|
|
||||||
0,
|
|
||||||
uintptr(unsafe.Pointer(&buf[0])),
|
|
||||||
procpidpathinfosize)
|
|
||||||
if errno != 0 {
|
|
||||||
return "", errno
|
|
||||||
}
|
|
||||||
|
|
||||||
return unix.ByteSliceToString(buf), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func readNativeUint32(b []byte) uint32 {
|
|
||||||
return *(*uint32)(unsafe.Pointer(&b[0]))
|
|
||||||
}
|
|
||||||
|
|||||||
269
common/process/searcher_darwin_shared.go
Normal file
269
common/process/searcher_darwin_shared.go
Normal file
@@ -0,0 +1,269 @@
|
|||||||
|
//go:build darwin
|
||||||
|
|
||||||
|
package process
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/binary"
|
||||||
|
"net/netip"
|
||||||
|
"os"
|
||||||
|
"sync"
|
||||||
|
"syscall"
|
||||||
|
"time"
|
||||||
|
"unsafe"
|
||||||
|
|
||||||
|
"github.com/sagernet/sing-box/adapter"
|
||||||
|
N "github.com/sagernet/sing/common/network"
|
||||||
|
|
||||||
|
"golang.org/x/sys/unix"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
darwinSnapshotTTL = 200 * time.Millisecond
|
||||||
|
|
||||||
|
darwinXinpgenSize = 24
|
||||||
|
darwinXsocketOffset = 104
|
||||||
|
darwinXinpcbForeignPort = 16
|
||||||
|
darwinXinpcbLocalPort = 18
|
||||||
|
darwinXinpcbVFlag = 44
|
||||||
|
darwinXinpcbForeignAddr = 48
|
||||||
|
darwinXinpcbLocalAddr = 64
|
||||||
|
darwinXinpcbIPv4Addr = 12
|
||||||
|
darwinXsocketUID = 64
|
||||||
|
darwinXsocketLastPID = 68
|
||||||
|
darwinTCPExtraStructSize = 208
|
||||||
|
)
|
||||||
|
|
||||||
|
type darwinConnectionEntry struct {
|
||||||
|
localAddr netip.Addr
|
||||||
|
remoteAddr netip.Addr
|
||||||
|
localPort uint16
|
||||||
|
remotePort uint16
|
||||||
|
pid uint32
|
||||||
|
uid int32
|
||||||
|
}
|
||||||
|
|
||||||
|
type darwinConnectionMatchKind uint8
|
||||||
|
|
||||||
|
const (
|
||||||
|
darwinConnectionMatchExact darwinConnectionMatchKind = iota
|
||||||
|
darwinConnectionMatchLocalFallback
|
||||||
|
darwinConnectionMatchWildcardFallback
|
||||||
|
)
|
||||||
|
|
||||||
|
type darwinSnapshot struct {
|
||||||
|
createdAt time.Time
|
||||||
|
entries []darwinConnectionEntry
|
||||||
|
}
|
||||||
|
|
||||||
|
type darwinConnectionFinder struct {
|
||||||
|
access sync.Mutex
|
||||||
|
ttl time.Duration
|
||||||
|
snapshots map[string]darwinSnapshot
|
||||||
|
builder func(string) (darwinSnapshot, error)
|
||||||
|
}
|
||||||
|
|
||||||
|
var sharedDarwinConnectionFinder = newDarwinConnectionFinder(darwinSnapshotTTL)
|
||||||
|
|
||||||
|
func newDarwinConnectionFinder(ttl time.Duration) *darwinConnectionFinder {
|
||||||
|
return &darwinConnectionFinder{
|
||||||
|
ttl: ttl,
|
||||||
|
snapshots: make(map[string]darwinSnapshot),
|
||||||
|
builder: buildDarwinSnapshot,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func FindDarwinConnectionOwner(network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
||||||
|
return sharedDarwinConnectionFinder.find(network, source, destination)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (f *darwinConnectionFinder) find(network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
||||||
|
networkName := N.NetworkName(network)
|
||||||
|
source = normalizeDarwinAddrPort(source)
|
||||||
|
destination = normalizeDarwinAddrPort(destination)
|
||||||
|
var lastOwner *adapter.ConnectionOwner
|
||||||
|
for attempt := 0; attempt < 2; attempt++ {
|
||||||
|
snapshot, fromCache, err := f.loadSnapshot(networkName, attempt > 0)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
entry, matchKind, err := matchDarwinConnectionEntry(snapshot.entries, networkName, source, destination)
|
||||||
|
if err != nil {
|
||||||
|
if err == ErrNotFound && fromCache {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if fromCache && matchKind != darwinConnectionMatchExact {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
owner := &adapter.ConnectionOwner{
|
||||||
|
UserId: entry.uid,
|
||||||
|
}
|
||||||
|
lastOwner = owner
|
||||||
|
if entry.pid == 0 {
|
||||||
|
return owner, nil
|
||||||
|
}
|
||||||
|
processPath, err := getExecPathFromPID(entry.pid)
|
||||||
|
if err == nil {
|
||||||
|
owner.ProcessPath = processPath
|
||||||
|
return owner, nil
|
||||||
|
}
|
||||||
|
if fromCache {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
return owner, nil
|
||||||
|
}
|
||||||
|
if lastOwner != nil {
|
||||||
|
return lastOwner, nil
|
||||||
|
}
|
||||||
|
return nil, ErrNotFound
|
||||||
|
}
|
||||||
|
|
||||||
|
func (f *darwinConnectionFinder) loadSnapshot(network string, forceRefresh bool) (darwinSnapshot, bool, error) {
|
||||||
|
f.access.Lock()
|
||||||
|
defer f.access.Unlock()
|
||||||
|
if !forceRefresh {
|
||||||
|
if snapshot, loaded := f.snapshots[network]; loaded && time.Since(snapshot.createdAt) < f.ttl {
|
||||||
|
return snapshot, true, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
snapshot, err := f.builder(network)
|
||||||
|
if err != nil {
|
||||||
|
return darwinSnapshot{}, false, err
|
||||||
|
}
|
||||||
|
f.snapshots[network] = snapshot
|
||||||
|
return snapshot, false, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildDarwinSnapshot(network string) (darwinSnapshot, error) {
|
||||||
|
spath, itemSize, err := darwinSnapshotSettings(network)
|
||||||
|
if err != nil {
|
||||||
|
return darwinSnapshot{}, err
|
||||||
|
}
|
||||||
|
value, err := unix.SysctlRaw(spath)
|
||||||
|
if err != nil {
|
||||||
|
return darwinSnapshot{}, err
|
||||||
|
}
|
||||||
|
return darwinSnapshot{
|
||||||
|
createdAt: time.Now(),
|
||||||
|
entries: parseDarwinSnapshot(value, itemSize),
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func darwinSnapshotSettings(network string) (string, int, error) {
|
||||||
|
itemSize := structSize
|
||||||
|
switch network {
|
||||||
|
case N.NetworkTCP:
|
||||||
|
return "net.inet.tcp.pcblist_n", itemSize + darwinTCPExtraStructSize, nil
|
||||||
|
case N.NetworkUDP:
|
||||||
|
return "net.inet.udp.pcblist_n", itemSize, nil
|
||||||
|
default:
|
||||||
|
return "", 0, os.ErrInvalid
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseDarwinSnapshot(buf []byte, itemSize int) []darwinConnectionEntry {
|
||||||
|
entries := make([]darwinConnectionEntry, 0, (len(buf)-darwinXinpgenSize)/itemSize)
|
||||||
|
for i := darwinXinpgenSize; i+itemSize <= len(buf); i += itemSize {
|
||||||
|
inp := i
|
||||||
|
so := i + darwinXsocketOffset
|
||||||
|
entry, ok := parseDarwinConnectionEntry(buf[inp:so], buf[so:so+structSize-darwinXsocketOffset])
|
||||||
|
if ok {
|
||||||
|
entries = append(entries, entry)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return entries
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseDarwinConnectionEntry(inp []byte, so []byte) (darwinConnectionEntry, bool) {
|
||||||
|
if len(inp) < darwinXsocketOffset || len(so) < structSize-darwinXsocketOffset {
|
||||||
|
return darwinConnectionEntry{}, false
|
||||||
|
}
|
||||||
|
entry := darwinConnectionEntry{
|
||||||
|
remotePort: binary.BigEndian.Uint16(inp[darwinXinpcbForeignPort : darwinXinpcbForeignPort+2]),
|
||||||
|
localPort: binary.BigEndian.Uint16(inp[darwinXinpcbLocalPort : darwinXinpcbLocalPort+2]),
|
||||||
|
pid: binary.NativeEndian.Uint32(so[darwinXsocketLastPID : darwinXsocketLastPID+4]),
|
||||||
|
uid: int32(binary.NativeEndian.Uint32(so[darwinXsocketUID : darwinXsocketUID+4])),
|
||||||
|
}
|
||||||
|
flag := inp[darwinXinpcbVFlag]
|
||||||
|
switch {
|
||||||
|
case flag&0x1 != 0:
|
||||||
|
entry.remoteAddr = netip.AddrFrom4([4]byte(inp[darwinXinpcbForeignAddr+darwinXinpcbIPv4Addr : darwinXinpcbForeignAddr+darwinXinpcbIPv4Addr+4]))
|
||||||
|
entry.localAddr = netip.AddrFrom4([4]byte(inp[darwinXinpcbLocalAddr+darwinXinpcbIPv4Addr : darwinXinpcbLocalAddr+darwinXinpcbIPv4Addr+4]))
|
||||||
|
return entry, true
|
||||||
|
case flag&0x2 != 0:
|
||||||
|
entry.remoteAddr = netip.AddrFrom16([16]byte(inp[darwinXinpcbForeignAddr : darwinXinpcbForeignAddr+16]))
|
||||||
|
entry.localAddr = netip.AddrFrom16([16]byte(inp[darwinXinpcbLocalAddr : darwinXinpcbLocalAddr+16]))
|
||||||
|
return entry, true
|
||||||
|
default:
|
||||||
|
return darwinConnectionEntry{}, false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func matchDarwinConnectionEntry(entries []darwinConnectionEntry, network string, source netip.AddrPort, destination netip.AddrPort) (darwinConnectionEntry, darwinConnectionMatchKind, error) {
|
||||||
|
sourceAddr := source.Addr()
|
||||||
|
if !sourceAddr.IsValid() {
|
||||||
|
return darwinConnectionEntry{}, darwinConnectionMatchExact, os.ErrInvalid
|
||||||
|
}
|
||||||
|
var localFallback darwinConnectionEntry
|
||||||
|
var hasLocalFallback bool
|
||||||
|
var wildcardFallback darwinConnectionEntry
|
||||||
|
var hasWildcardFallback bool
|
||||||
|
for _, entry := range entries {
|
||||||
|
if entry.localPort != source.Port() || sourceAddr.BitLen() != entry.localAddr.BitLen() {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if entry.localAddr == sourceAddr && destination.IsValid() && entry.remotePort == destination.Port() && entry.remoteAddr == destination.Addr() {
|
||||||
|
return entry, darwinConnectionMatchExact, nil
|
||||||
|
}
|
||||||
|
if !destination.IsValid() && entry.localAddr == sourceAddr {
|
||||||
|
return entry, darwinConnectionMatchExact, nil
|
||||||
|
}
|
||||||
|
if network != N.NetworkUDP {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if !hasLocalFallback && entry.localAddr == sourceAddr {
|
||||||
|
hasLocalFallback = true
|
||||||
|
localFallback = entry
|
||||||
|
}
|
||||||
|
if !hasWildcardFallback && entry.localAddr.IsUnspecified() {
|
||||||
|
hasWildcardFallback = true
|
||||||
|
wildcardFallback = entry
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if hasLocalFallback {
|
||||||
|
return localFallback, darwinConnectionMatchLocalFallback, nil
|
||||||
|
}
|
||||||
|
if hasWildcardFallback {
|
||||||
|
return wildcardFallback, darwinConnectionMatchWildcardFallback, nil
|
||||||
|
}
|
||||||
|
return darwinConnectionEntry{}, darwinConnectionMatchExact, ErrNotFound
|
||||||
|
}
|
||||||
|
|
||||||
|
func normalizeDarwinAddrPort(addrPort netip.AddrPort) netip.AddrPort {
|
||||||
|
if !addrPort.IsValid() {
|
||||||
|
return addrPort
|
||||||
|
}
|
||||||
|
return netip.AddrPortFrom(addrPort.Addr().Unmap(), addrPort.Port())
|
||||||
|
}
|
||||||
|
|
||||||
|
func getExecPathFromPID(pid uint32) (string, error) {
|
||||||
|
const (
|
||||||
|
procpidpathinfo = 0xb
|
||||||
|
procpidpathinfosize = 1024
|
||||||
|
proccallnumpidinfo = 0x2
|
||||||
|
)
|
||||||
|
buf := make([]byte, procpidpathinfosize)
|
||||||
|
_, _, errno := syscall.Syscall6(
|
||||||
|
syscall.SYS_PROC_INFO,
|
||||||
|
proccallnumpidinfo,
|
||||||
|
uintptr(pid),
|
||||||
|
procpidpathinfo,
|
||||||
|
0,
|
||||||
|
uintptr(unsafe.Pointer(&buf[0])),
|
||||||
|
procpidpathinfosize)
|
||||||
|
if errno != 0 {
|
||||||
|
return "", errno
|
||||||
|
}
|
||||||
|
return unix.ByteSliceToString(buf), nil
|
||||||
|
}
|
||||||
@@ -4,33 +4,82 @@ package process
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"errors"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
"syscall"
|
||||||
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/log"
|
"github.com/sagernet/sing-box/log"
|
||||||
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
)
|
)
|
||||||
|
|
||||||
var _ Searcher = (*linuxSearcher)(nil)
|
var _ Searcher = (*linuxSearcher)(nil)
|
||||||
|
|
||||||
type linuxSearcher struct {
|
type linuxSearcher struct {
|
||||||
logger log.ContextLogger
|
logger log.ContextLogger
|
||||||
|
diagConns [4]*socketDiagConn
|
||||||
|
processPathCache *uidProcessPathCache
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewSearcher(config Config) (Searcher, error) {
|
func NewSearcher(config Config) (Searcher, error) {
|
||||||
return &linuxSearcher{config.Logger}, nil
|
searcher := &linuxSearcher{
|
||||||
|
logger: config.Logger,
|
||||||
|
processPathCache: newUIDProcessPathCache(time.Second),
|
||||||
|
}
|
||||||
|
for _, family := range []uint8{syscall.AF_INET, syscall.AF_INET6} {
|
||||||
|
for _, protocol := range []uint8{syscall.IPPROTO_TCP, syscall.IPPROTO_UDP} {
|
||||||
|
searcher.diagConns[socketDiagConnIndex(family, protocol)] = newSocketDiagConn(family, protocol)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return searcher, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *linuxSearcher) Close() error {
|
||||||
|
var errs []error
|
||||||
|
for _, conn := range s.diagConns {
|
||||||
|
if conn == nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
errs = append(errs, conn.Close())
|
||||||
|
}
|
||||||
|
return E.Errors(errs...)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *linuxSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
func (s *linuxSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
||||||
inode, uid, err := resolveSocketByNetlink(network, source, destination)
|
inode, uid, err := s.resolveSocketByNetlink(network, source, destination)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
processPath, err := resolveProcessNameByProcSearch(inode, uid)
|
processInfo := &adapter.ConnectionOwner{
|
||||||
|
UserId: int32(uid),
|
||||||
|
}
|
||||||
|
processPath, err := s.processPathCache.findProcessPath(inode, uid)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
s.logger.DebugContext(ctx, "find process path: ", err)
|
s.logger.DebugContext(ctx, "find process path: ", err)
|
||||||
|
} else {
|
||||||
|
processInfo.ProcessPath = processPath
|
||||||
}
|
}
|
||||||
return &adapter.ConnectionOwner{
|
return processInfo, nil
|
||||||
UserId: int32(uid),
|
}
|
||||||
ProcessPath: processPath,
|
|
||||||
}, nil
|
func (s *linuxSearcher) resolveSocketByNetlink(network string, source netip.AddrPort, destination netip.AddrPort) (inode, uid uint32, err error) {
|
||||||
|
family, protocol, err := socketDiagSettings(network, source)
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, err
|
||||||
|
}
|
||||||
|
conn := s.diagConns[socketDiagConnIndex(family, protocol)]
|
||||||
|
if conn == nil {
|
||||||
|
return 0, 0, E.New("missing socket diag connection for family=", family, " protocol=", protocol)
|
||||||
|
}
|
||||||
|
if destination.IsValid() && source.Addr().BitLen() == destination.Addr().BitLen() {
|
||||||
|
inode, uid, err = conn.query(source, destination)
|
||||||
|
if err == nil {
|
||||||
|
return inode, uid, nil
|
||||||
|
}
|
||||||
|
if !errors.Is(err, ErrNotFound) {
|
||||||
|
return 0, 0, err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return querySocketDiagOnce(family, protocol, source)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,43 +3,67 @@
|
|||||||
package process
|
package process
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"encoding/binary"
|
"encoding/binary"
|
||||||
"fmt"
|
"errors"
|
||||||
"net"
|
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
"path"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
|
"sync"
|
||||||
"syscall"
|
"syscall"
|
||||||
|
"time"
|
||||||
"unicode"
|
"unicode"
|
||||||
"unsafe"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/buf"
|
"github.com/sagernet/sing/common"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
N "github.com/sagernet/sing/common/network"
|
N "github.com/sagernet/sing/common/network"
|
||||||
|
"github.com/sagernet/sing/contrab/freelru"
|
||||||
|
"github.com/sagernet/sing/contrab/maphash"
|
||||||
)
|
)
|
||||||
|
|
||||||
// from https://github.com/vishvananda/netlink/blob/bca67dfc8220b44ef582c9da4e9172bf1c9ec973/nl/nl_linux.go#L52-L62
|
|
||||||
var nativeEndian = func() binary.ByteOrder {
|
|
||||||
var x uint32 = 0x01020304
|
|
||||||
if *(*byte)(unsafe.Pointer(&x)) == 0x01 {
|
|
||||||
return binary.BigEndian
|
|
||||||
}
|
|
||||||
|
|
||||||
return binary.LittleEndian
|
|
||||||
}()
|
|
||||||
|
|
||||||
const (
|
const (
|
||||||
sizeOfSocketDiagRequest = syscall.SizeofNlMsghdr + 8 + 48
|
sizeOfSocketDiagRequestData = 56
|
||||||
socketDiagByFamily = 20
|
sizeOfSocketDiagRequest = syscall.SizeofNlMsghdr + sizeOfSocketDiagRequestData
|
||||||
pathProc = "/proc"
|
socketDiagResponseMinSize = 72
|
||||||
|
socketDiagByFamily = 20
|
||||||
|
pathProc = "/proc"
|
||||||
)
|
)
|
||||||
|
|
||||||
func resolveSocketByNetlink(network string, source netip.AddrPort, destination netip.AddrPort) (inode, uid uint32, err error) {
|
type socketDiagConn struct {
|
||||||
var family uint8
|
access sync.Mutex
|
||||||
var protocol uint8
|
family uint8
|
||||||
|
protocol uint8
|
||||||
|
fd int
|
||||||
|
}
|
||||||
|
|
||||||
|
type uidProcessPathCache struct {
|
||||||
|
cache freelru.Cache[uint32, *uidProcessPaths]
|
||||||
|
}
|
||||||
|
|
||||||
|
type uidProcessPaths struct {
|
||||||
|
entries map[uint32]string
|
||||||
|
}
|
||||||
|
|
||||||
|
func newSocketDiagConn(family, protocol uint8) *socketDiagConn {
|
||||||
|
return &socketDiagConn{
|
||||||
|
family: family,
|
||||||
|
protocol: protocol,
|
||||||
|
fd: -1,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func socketDiagConnIndex(family, protocol uint8) int {
|
||||||
|
index := 0
|
||||||
|
if protocol == syscall.IPPROTO_UDP {
|
||||||
|
index += 2
|
||||||
|
}
|
||||||
|
if family == syscall.AF_INET6 {
|
||||||
|
index++
|
||||||
|
}
|
||||||
|
return index
|
||||||
|
}
|
||||||
|
|
||||||
|
func socketDiagSettings(network string, source netip.AddrPort) (family, protocol uint8, err error) {
|
||||||
switch network {
|
switch network {
|
||||||
case N.NetworkTCP:
|
case N.NetworkTCP:
|
||||||
protocol = syscall.IPPROTO_TCP
|
protocol = syscall.IPPROTO_TCP
|
||||||
@@ -48,151 +72,308 @@ func resolveSocketByNetlink(network string, source netip.AddrPort, destination n
|
|||||||
default:
|
default:
|
||||||
return 0, 0, os.ErrInvalid
|
return 0, 0, os.ErrInvalid
|
||||||
}
|
}
|
||||||
|
switch {
|
||||||
if source.Addr().Is4() {
|
case source.Addr().Is4():
|
||||||
family = syscall.AF_INET
|
family = syscall.AF_INET
|
||||||
} else {
|
case source.Addr().Is6():
|
||||||
family = syscall.AF_INET6
|
family = syscall.AF_INET6
|
||||||
|
default:
|
||||||
|
return 0, 0, os.ErrInvalid
|
||||||
}
|
}
|
||||||
|
return family, protocol, nil
|
||||||
req := packSocketDiagRequest(family, protocol, source)
|
|
||||||
|
|
||||||
socket, err := syscall.Socket(syscall.AF_NETLINK, syscall.SOCK_DGRAM, syscall.NETLINK_INET_DIAG)
|
|
||||||
if err != nil {
|
|
||||||
return 0, 0, E.Cause(err, "dial netlink")
|
|
||||||
}
|
|
||||||
defer syscall.Close(socket)
|
|
||||||
|
|
||||||
syscall.SetsockoptTimeval(socket, syscall.SOL_SOCKET, syscall.SO_SNDTIMEO, &syscall.Timeval{Usec: 100})
|
|
||||||
syscall.SetsockoptTimeval(socket, syscall.SOL_SOCKET, syscall.SO_RCVTIMEO, &syscall.Timeval{Usec: 100})
|
|
||||||
|
|
||||||
err = syscall.Connect(socket, &syscall.SockaddrNetlink{
|
|
||||||
Family: syscall.AF_NETLINK,
|
|
||||||
Pad: 0,
|
|
||||||
Pid: 0,
|
|
||||||
Groups: 0,
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
_, err = syscall.Write(socket, req)
|
|
||||||
if err != nil {
|
|
||||||
return 0, 0, E.Cause(err, "write netlink request")
|
|
||||||
}
|
|
||||||
|
|
||||||
buffer := buf.New()
|
|
||||||
defer buffer.Release()
|
|
||||||
|
|
||||||
n, err := syscall.Read(socket, buffer.FreeBytes())
|
|
||||||
if err != nil {
|
|
||||||
return 0, 0, E.Cause(err, "read netlink response")
|
|
||||||
}
|
|
||||||
|
|
||||||
buffer.Truncate(n)
|
|
||||||
|
|
||||||
messages, err := syscall.ParseNetlinkMessage(buffer.Bytes())
|
|
||||||
if err != nil {
|
|
||||||
return 0, 0, E.Cause(err, "parse netlink message")
|
|
||||||
} else if len(messages) == 0 {
|
|
||||||
return 0, 0, E.New("unexcepted netlink response")
|
|
||||||
}
|
|
||||||
|
|
||||||
message := messages[0]
|
|
||||||
if message.Header.Type&syscall.NLMSG_ERROR != 0 {
|
|
||||||
return 0, 0, E.New("netlink message: NLMSG_ERROR")
|
|
||||||
}
|
|
||||||
|
|
||||||
inode, uid = unpackSocketDiagResponse(&messages[0])
|
|
||||||
return
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func packSocketDiagRequest(family, protocol byte, source netip.AddrPort) []byte {
|
func newUIDProcessPathCache(ttl time.Duration) *uidProcessPathCache {
|
||||||
s := make([]byte, 16)
|
cache := common.Must1(freelru.NewSharded[uint32, *uidProcessPaths](64, maphash.NewHasher[uint32]().Hash32))
|
||||||
copy(s, source.Addr().AsSlice())
|
cache.SetLifetime(ttl)
|
||||||
|
return &uidProcessPathCache{cache: cache}
|
||||||
buf := make([]byte, sizeOfSocketDiagRequest)
|
|
||||||
|
|
||||||
nativeEndian.PutUint32(buf[0:4], sizeOfSocketDiagRequest)
|
|
||||||
nativeEndian.PutUint16(buf[4:6], socketDiagByFamily)
|
|
||||||
nativeEndian.PutUint16(buf[6:8], syscall.NLM_F_REQUEST|syscall.NLM_F_DUMP)
|
|
||||||
nativeEndian.PutUint32(buf[8:12], 0)
|
|
||||||
nativeEndian.PutUint32(buf[12:16], 0)
|
|
||||||
|
|
||||||
buf[16] = family
|
|
||||||
buf[17] = protocol
|
|
||||||
buf[18] = 0
|
|
||||||
buf[19] = 0
|
|
||||||
nativeEndian.PutUint32(buf[20:24], 0xFFFFFFFF)
|
|
||||||
|
|
||||||
binary.BigEndian.PutUint16(buf[24:26], source.Port())
|
|
||||||
binary.BigEndian.PutUint16(buf[26:28], 0)
|
|
||||||
|
|
||||||
copy(buf[28:44], s)
|
|
||||||
copy(buf[44:60], net.IPv6zero)
|
|
||||||
|
|
||||||
nativeEndian.PutUint32(buf[60:64], 0)
|
|
||||||
nativeEndian.PutUint64(buf[64:72], 0xFFFFFFFFFFFFFFFF)
|
|
||||||
|
|
||||||
return buf
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func unpackSocketDiagResponse(msg *syscall.NetlinkMessage) (inode, uid uint32) {
|
func (c *uidProcessPathCache) findProcessPath(targetInode, uid uint32) (string, error) {
|
||||||
if len(msg.Data) < 72 {
|
if cached, ok := c.cache.Get(uid); ok {
|
||||||
return 0, 0
|
if processPath, found := cached.entries[targetInode]; found {
|
||||||
|
return processPath, nil
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
processPaths, err := buildProcessPathByUIDCache(uid)
|
||||||
data := msg.Data
|
|
||||||
|
|
||||||
uid = nativeEndian.Uint32(data[64:68])
|
|
||||||
inode = nativeEndian.Uint32(data[68:72])
|
|
||||||
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
func resolveProcessNameByProcSearch(inode, uid uint32) (string, error) {
|
|
||||||
files, err := os.ReadDir(pathProc)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
}
|
}
|
||||||
|
c.cache.Add(uid, &uidProcessPaths{entries: processPaths})
|
||||||
|
processPath, found := processPaths[targetInode]
|
||||||
|
if !found {
|
||||||
|
return "", E.New("process of uid(", uid, "), inode(", targetInode, ") not found")
|
||||||
|
}
|
||||||
|
return processPath, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *socketDiagConn) Close() error {
|
||||||
|
c.access.Lock()
|
||||||
|
defer c.access.Unlock()
|
||||||
|
return c.closeLocked()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *socketDiagConn) query(source netip.AddrPort, destination netip.AddrPort) (inode, uid uint32, err error) {
|
||||||
|
c.access.Lock()
|
||||||
|
defer c.access.Unlock()
|
||||||
|
request := packSocketDiagRequest(c.family, c.protocol, source, destination, false)
|
||||||
|
for attempt := 0; attempt < 2; attempt++ {
|
||||||
|
err = c.ensureOpenLocked()
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, E.Cause(err, "dial netlink")
|
||||||
|
}
|
||||||
|
inode, uid, err = querySocketDiag(c.fd, request)
|
||||||
|
if err == nil || errors.Is(err, ErrNotFound) {
|
||||||
|
return inode, uid, err
|
||||||
|
}
|
||||||
|
if !shouldRetrySocketDiag(err) {
|
||||||
|
return 0, 0, err
|
||||||
|
}
|
||||||
|
_ = c.closeLocked()
|
||||||
|
}
|
||||||
|
return 0, 0, err
|
||||||
|
}
|
||||||
|
|
||||||
|
func querySocketDiagOnce(family, protocol uint8, source netip.AddrPort) (inode, uid uint32, err error) {
|
||||||
|
fd, err := openSocketDiag()
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, E.Cause(err, "dial netlink")
|
||||||
|
}
|
||||||
|
defer syscall.Close(fd)
|
||||||
|
return querySocketDiag(fd, packSocketDiagRequest(family, protocol, source, netip.AddrPort{}, true))
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *socketDiagConn) ensureOpenLocked() error {
|
||||||
|
if c.fd != -1 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
fd, err := openSocketDiag()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
c.fd = fd
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func openSocketDiag() (int, error) {
|
||||||
|
fd, err := syscall.Socket(syscall.AF_NETLINK, syscall.SOCK_DGRAM|syscall.SOCK_CLOEXEC, syscall.NETLINK_INET_DIAG)
|
||||||
|
if err != nil {
|
||||||
|
return -1, err
|
||||||
|
}
|
||||||
|
timeout := &syscall.Timeval{Usec: 100}
|
||||||
|
if err = syscall.SetsockoptTimeval(fd, syscall.SOL_SOCKET, syscall.SO_SNDTIMEO, timeout); err != nil {
|
||||||
|
syscall.Close(fd)
|
||||||
|
return -1, err
|
||||||
|
}
|
||||||
|
if err = syscall.SetsockoptTimeval(fd, syscall.SOL_SOCKET, syscall.SO_RCVTIMEO, timeout); err != nil {
|
||||||
|
syscall.Close(fd)
|
||||||
|
return -1, err
|
||||||
|
}
|
||||||
|
if err = syscall.Connect(fd, &syscall.SockaddrNetlink{
|
||||||
|
Family: syscall.AF_NETLINK,
|
||||||
|
Pid: 0,
|
||||||
|
Groups: 0,
|
||||||
|
}); err != nil {
|
||||||
|
syscall.Close(fd)
|
||||||
|
return -1, err
|
||||||
|
}
|
||||||
|
return fd, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *socketDiagConn) closeLocked() error {
|
||||||
|
if c.fd == -1 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
err := syscall.Close(c.fd)
|
||||||
|
c.fd = -1
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
func packSocketDiagRequest(family, protocol byte, source netip.AddrPort, destination netip.AddrPort, dump bool) []byte {
|
||||||
|
request := make([]byte, sizeOfSocketDiagRequest)
|
||||||
|
|
||||||
|
binary.NativeEndian.PutUint32(request[0:4], sizeOfSocketDiagRequest)
|
||||||
|
binary.NativeEndian.PutUint16(request[4:6], socketDiagByFamily)
|
||||||
|
flags := uint16(syscall.NLM_F_REQUEST)
|
||||||
|
if dump {
|
||||||
|
flags |= syscall.NLM_F_DUMP
|
||||||
|
}
|
||||||
|
binary.NativeEndian.PutUint16(request[6:8], flags)
|
||||||
|
binary.NativeEndian.PutUint32(request[8:12], 0)
|
||||||
|
binary.NativeEndian.PutUint32(request[12:16], 0)
|
||||||
|
|
||||||
|
request[16] = family
|
||||||
|
request[17] = protocol
|
||||||
|
request[18] = 0
|
||||||
|
request[19] = 0
|
||||||
|
if dump {
|
||||||
|
binary.NativeEndian.PutUint32(request[20:24], 0xFFFFFFFF)
|
||||||
|
}
|
||||||
|
requestSource := source
|
||||||
|
requestDestination := destination
|
||||||
|
if protocol == syscall.IPPROTO_UDP && !dump && destination.IsValid() {
|
||||||
|
// udp_dump_one expects the exact-match endpoints reversed for historical reasons.
|
||||||
|
requestSource, requestDestination = destination, source
|
||||||
|
}
|
||||||
|
binary.BigEndian.PutUint16(request[24:26], requestSource.Port())
|
||||||
|
binary.BigEndian.PutUint16(request[26:28], requestDestination.Port())
|
||||||
|
if family == syscall.AF_INET6 {
|
||||||
|
copy(request[28:44], requestSource.Addr().AsSlice())
|
||||||
|
if requestDestination.IsValid() {
|
||||||
|
copy(request[44:60], requestDestination.Addr().AsSlice())
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
copy(request[28:32], requestSource.Addr().AsSlice())
|
||||||
|
if requestDestination.IsValid() {
|
||||||
|
copy(request[44:48], requestDestination.Addr().AsSlice())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
binary.NativeEndian.PutUint32(request[60:64], 0)
|
||||||
|
binary.NativeEndian.PutUint64(request[64:72], 0xFFFFFFFFFFFFFFFF)
|
||||||
|
return request
|
||||||
|
}
|
||||||
|
|
||||||
|
func querySocketDiag(fd int, request []byte) (inode, uid uint32, err error) {
|
||||||
|
_, err = syscall.Write(fd, request)
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, E.Cause(err, "write netlink request")
|
||||||
|
}
|
||||||
|
buffer := make([]byte, 64<<10)
|
||||||
|
n, err := syscall.Read(fd, buffer)
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, E.Cause(err, "read netlink response")
|
||||||
|
}
|
||||||
|
messages, err := syscall.ParseNetlinkMessage(buffer[:n])
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, E.Cause(err, "parse netlink message")
|
||||||
|
}
|
||||||
|
return unpackSocketDiagMessages(messages)
|
||||||
|
}
|
||||||
|
|
||||||
|
func unpackSocketDiagMessages(messages []syscall.NetlinkMessage) (inode, uid uint32, err error) {
|
||||||
|
for _, message := range messages {
|
||||||
|
switch message.Header.Type {
|
||||||
|
case syscall.NLMSG_DONE:
|
||||||
|
continue
|
||||||
|
case syscall.NLMSG_ERROR:
|
||||||
|
err = unpackSocketDiagError(&message)
|
||||||
|
if err != nil {
|
||||||
|
return 0, 0, err
|
||||||
|
}
|
||||||
|
case socketDiagByFamily:
|
||||||
|
inode, uid = unpackSocketDiagResponse(&message)
|
||||||
|
if inode != 0 || uid != 0 {
|
||||||
|
return inode, uid, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return 0, 0, ErrNotFound
|
||||||
|
}
|
||||||
|
|
||||||
|
func unpackSocketDiagResponse(msg *syscall.NetlinkMessage) (inode, uid uint32) {
|
||||||
|
if len(msg.Data) < socketDiagResponseMinSize {
|
||||||
|
return 0, 0
|
||||||
|
}
|
||||||
|
uid = binary.NativeEndian.Uint32(msg.Data[64:68])
|
||||||
|
inode = binary.NativeEndian.Uint32(msg.Data[68:72])
|
||||||
|
return inode, uid
|
||||||
|
}
|
||||||
|
|
||||||
|
func unpackSocketDiagError(msg *syscall.NetlinkMessage) error {
|
||||||
|
if len(msg.Data) < 4 {
|
||||||
|
return E.New("netlink message: NLMSG_ERROR")
|
||||||
|
}
|
||||||
|
errno := int32(binary.NativeEndian.Uint32(msg.Data[:4]))
|
||||||
|
if errno == 0 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
if errno < 0 {
|
||||||
|
errno = -errno
|
||||||
|
}
|
||||||
|
sysErr := syscall.Errno(errno)
|
||||||
|
switch sysErr {
|
||||||
|
case syscall.ENOENT, syscall.ESRCH:
|
||||||
|
return ErrNotFound
|
||||||
|
default:
|
||||||
|
return E.New("netlink message: ", sysErr)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func shouldRetrySocketDiag(err error) bool {
|
||||||
|
return err != nil && !errors.Is(err, ErrNotFound)
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildProcessPathByUIDCache(uid uint32) (map[uint32]string, error) {
|
||||||
|
files, err := os.ReadDir(pathProc)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
buffer := make([]byte, syscall.PathMax)
|
buffer := make([]byte, syscall.PathMax)
|
||||||
socket := []byte(fmt.Sprintf("socket:[%d]", inode))
|
processPaths := make(map[uint32]string)
|
||||||
|
for _, file := range files {
|
||||||
for _, f := range files {
|
if !file.IsDir() || !isPid(file.Name()) {
|
||||||
if !f.IsDir() || !isPid(f.Name()) {
|
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
info, err := file.Info()
|
||||||
info, err := f.Info()
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", err
|
if isIgnorableProcError(err) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
return nil, err
|
||||||
}
|
}
|
||||||
if info.Sys().(*syscall.Stat_t).Uid != uid {
|
if info.Sys().(*syscall.Stat_t).Uid != uid {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
processPath := filepath.Join(pathProc, file.Name())
|
||||||
processPath := path.Join(pathProc, f.Name())
|
fdPath := filepath.Join(processPath, "fd")
|
||||||
fdPath := path.Join(processPath, "fd")
|
exePath, err := os.Readlink(filepath.Join(processPath, "exe"))
|
||||||
|
if err != nil {
|
||||||
|
if isIgnorableProcError(err) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
fds, err := os.ReadDir(fdPath)
|
fds, err := os.ReadDir(fdPath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, fd := range fds {
|
for _, fd := range fds {
|
||||||
n, err := syscall.Readlink(path.Join(fdPath, fd.Name()), buffer)
|
n, err := syscall.Readlink(filepath.Join(fdPath, fd.Name()), buffer)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
inode, ok := parseSocketInode(buffer[:n])
|
||||||
if bytes.Equal(buffer[:n], socket) {
|
if !ok {
|
||||||
return os.Readlink(path.Join(processPath, "exe"))
|
continue
|
||||||
|
}
|
||||||
|
if _, loaded := processPaths[inode]; !loaded {
|
||||||
|
processPaths[inode] = exePath
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
return processPaths, nil
|
||||||
|
}
|
||||||
|
|
||||||
return "", fmt.Errorf("process of uid(%d),inode(%d) not found", uid, inode)
|
func isIgnorableProcError(err error) bool {
|
||||||
|
return os.IsNotExist(err) || os.IsPermission(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseSocketInode(link []byte) (uint32, bool) {
|
||||||
|
const socketPrefix = "socket:["
|
||||||
|
if len(link) <= len(socketPrefix) || string(link[:len(socketPrefix)]) != socketPrefix || link[len(link)-1] != ']' {
|
||||||
|
return 0, false
|
||||||
|
}
|
||||||
|
var inode uint64
|
||||||
|
for _, char := range link[len(socketPrefix) : len(link)-1] {
|
||||||
|
if char < '0' || char > '9' {
|
||||||
|
return 0, false
|
||||||
|
}
|
||||||
|
inode = inode*10 + uint64(char-'0')
|
||||||
|
if inode > uint64(^uint32(0)) {
|
||||||
|
return 0, false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return uint32(inode), true
|
||||||
}
|
}
|
||||||
|
|
||||||
func isPid(s string) bool {
|
func isPid(s string) bool {
|
||||||
|
|||||||
60
common/process/searcher_linux_shared_test.go
Normal file
60
common/process/searcher_linux_shared_test.go
Normal file
@@ -0,0 +1,60 @@
|
|||||||
|
//go:build linux
|
||||||
|
|
||||||
|
package process
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net"
|
||||||
|
"net/netip"
|
||||||
|
"os"
|
||||||
|
"syscall"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestQuerySocketDiagUDPExact(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
server, err := net.ListenUDP("udp4", &net.UDPAddr{IP: net.IPv4(127, 0, 0, 1), Port: 0})
|
||||||
|
require.NoError(t, err)
|
||||||
|
defer server.Close()
|
||||||
|
|
||||||
|
client, err := net.DialUDP("udp4", nil, server.LocalAddr().(*net.UDPAddr))
|
||||||
|
require.NoError(t, err)
|
||||||
|
defer client.Close()
|
||||||
|
|
||||||
|
err = client.SetDeadline(time.Now().Add(time.Second))
|
||||||
|
require.NoError(t, err)
|
||||||
|
_, err = client.Write([]byte{0})
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
err = server.SetReadDeadline(time.Now().Add(time.Second))
|
||||||
|
require.NoError(t, err)
|
||||||
|
buffer := make([]byte, 1)
|
||||||
|
_, _, err = server.ReadFromUDP(buffer)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
source := addrPortFromUDPAddr(t, client.LocalAddr())
|
||||||
|
destination := addrPortFromUDPAddr(t, client.RemoteAddr())
|
||||||
|
|
||||||
|
fd, err := openSocketDiag()
|
||||||
|
require.NoError(t, err)
|
||||||
|
defer syscall.Close(fd)
|
||||||
|
|
||||||
|
inode, uid, err := querySocketDiag(fd, packSocketDiagRequest(syscall.AF_INET, syscall.IPPROTO_UDP, source, destination, false))
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.NotZero(t, inode)
|
||||||
|
require.EqualValues(t, os.Getuid(), uid)
|
||||||
|
}
|
||||||
|
|
||||||
|
func addrPortFromUDPAddr(t *testing.T, addr net.Addr) netip.AddrPort {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
udpAddr, ok := addr.(*net.UDPAddr)
|
||||||
|
require.True(t, ok)
|
||||||
|
|
||||||
|
ip, ok := netip.AddrFromSlice(udpAddr.IP)
|
||||||
|
require.True(t, ok)
|
||||||
|
|
||||||
|
return netip.AddrPortFrom(ip.Unmap(), uint16(udpAddr.Port))
|
||||||
|
}
|
||||||
@@ -28,6 +28,10 @@ func initWin32API() error {
|
|||||||
return winiphlpapi.LoadExtendedTable()
|
return winiphlpapi.LoadExtendedTable()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (s *windowsSearcher) Close() error {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func (s *windowsSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
func (s *windowsSearcher) FindProcessInfo(ctx context.Context, network string, source netip.AddrPort, destination netip.AddrPort) (*adapter.ConnectionOwner, error) {
|
||||||
pid, err := winiphlpapi.FindPid(network, source)
|
pid, err := winiphlpapi.FindPid(network, source)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import (
|
|||||||
"encoding/binary"
|
"encoding/binary"
|
||||||
"io"
|
"io"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
"unsafe"
|
||||||
|
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
@@ -505,7 +506,24 @@ func writeDefaultRule(writer varbin.Writer, rule option.DefaultHeadlessRule, gen
|
|||||||
}
|
}
|
||||||
|
|
||||||
func readRuleItemString(reader varbin.Reader) ([]string, error) {
|
func readRuleItemString(reader varbin.Reader) ([]string, error) {
|
||||||
return varbin.ReadValue[[]string](reader, binary.BigEndian)
|
length, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
result := make([]string, length)
|
||||||
|
for i := range result {
|
||||||
|
strLen, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
buf := make([]byte, strLen)
|
||||||
|
_, err = io.ReadFull(reader, buf)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
result[i] = string(buf)
|
||||||
|
}
|
||||||
|
return result, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func writeRuleItemString(writer varbin.Writer, itemType uint8, value []string) error {
|
func writeRuleItemString(writer varbin.Writer, itemType uint8, value []string) error {
|
||||||
@@ -513,11 +531,34 @@ func writeRuleItemString(writer varbin.Writer, itemType uint8, value []string) e
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return varbin.Write(writer, binary.BigEndian, value)
|
_, err = varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
for _, s := range value {
|
||||||
|
_, err = varbin.WriteUvarint(writer, uint64(len(s)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write([]byte(s))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func readRuleItemUint8[E ~uint8](reader varbin.Reader) ([]E, error) {
|
func readRuleItemUint8[E ~uint8](reader varbin.Reader) ([]E, error) {
|
||||||
return varbin.ReadValue[[]E](reader, binary.BigEndian)
|
length, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
result := make([]E, length)
|
||||||
|
_, err = io.ReadFull(reader, *(*[]byte)(unsafe.Pointer(&result)))
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return result, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func writeRuleItemUint8[E ~uint8](writer varbin.Writer, itemType uint8, value []E) error {
|
func writeRuleItemUint8[E ~uint8](writer varbin.Writer, itemType uint8, value []E) error {
|
||||||
@@ -525,11 +566,25 @@ func writeRuleItemUint8[E ~uint8](writer varbin.Writer, itemType uint8, value []
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return varbin.Write(writer, binary.BigEndian, value)
|
_, err = varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write(*(*[]byte)(unsafe.Pointer(&value)))
|
||||||
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
func readRuleItemUint16(reader varbin.Reader) ([]uint16, error) {
|
func readRuleItemUint16(reader varbin.Reader) ([]uint16, error) {
|
||||||
return varbin.ReadValue[[]uint16](reader, binary.BigEndian)
|
length, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
result := make([]uint16, length)
|
||||||
|
err = binary.Read(reader, binary.BigEndian, result)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return result, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func writeRuleItemUint16(writer varbin.Writer, itemType uint8, value []uint16) error {
|
func writeRuleItemUint16(writer varbin.Writer, itemType uint8, value []uint16) error {
|
||||||
@@ -537,7 +592,11 @@ func writeRuleItemUint16(writer varbin.Writer, itemType uint8, value []uint16) e
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return varbin.Write(writer, binary.BigEndian, value)
|
_, err = varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return binary.Write(writer, binary.BigEndian, value)
|
||||||
}
|
}
|
||||||
|
|
||||||
func writeRuleItemCIDR(writer varbin.Writer, itemType uint8, value []string) error {
|
func writeRuleItemCIDR(writer varbin.Writer, itemType uint8, value []string) error {
|
||||||
|
|||||||
494
common/srs/compat_test.go
Normal file
494
common/srs/compat_test.go
Normal file
@@ -0,0 +1,494 @@
|
|||||||
|
package srs
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"bytes"
|
||||||
|
"encoding/binary"
|
||||||
|
"net/netip"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"unsafe"
|
||||||
|
|
||||||
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
|
"github.com/sagernet/sing/common/varbin"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
"go4.org/netipx"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Old implementations using varbin reflection-based serialization
|
||||||
|
|
||||||
|
func oldWriteStringSlice(writer varbin.Writer, value []string) error {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.Write(writer, binary.BigEndian, value)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldReadStringSlice(reader varbin.Reader) ([]string, error) {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.ReadValue[[]string](reader, binary.BigEndian)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldWriteUint8Slice[E ~uint8](writer varbin.Writer, value []E) error {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.Write(writer, binary.BigEndian, value)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldReadUint8Slice[E ~uint8](reader varbin.Reader) ([]E, error) {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.ReadValue[[]E](reader, binary.BigEndian)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldWriteUint16Slice(writer varbin.Writer, value []uint16) error {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.Write(writer, binary.BigEndian, value)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldReadUint16Slice(reader varbin.Reader) ([]uint16, error) {
|
||||||
|
//nolint:staticcheck
|
||||||
|
return varbin.ReadValue[[]uint16](reader, binary.BigEndian)
|
||||||
|
}
|
||||||
|
|
||||||
|
func oldWritePrefix(writer varbin.Writer, prefix netip.Prefix) error {
|
||||||
|
//nolint:staticcheck
|
||||||
|
err := varbin.Write(writer, binary.BigEndian, prefix.Addr().AsSlice())
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return binary.Write(writer, binary.BigEndian, uint8(prefix.Bits()))
|
||||||
|
}
|
||||||
|
|
||||||
|
type oldIPRangeData struct {
|
||||||
|
From []byte
|
||||||
|
To []byte
|
||||||
|
}
|
||||||
|
|
||||||
|
// Note: The old writeIPSet had a bug where varbin.Write(writer, binary.BigEndian, data)
|
||||||
|
// with a struct VALUE (not pointer) silently wrote nothing because field.CanSet() returned false.
|
||||||
|
// This caused IP range data to be missing from the output.
|
||||||
|
// The new implementation correctly writes all range data.
|
||||||
|
//
|
||||||
|
// The old readIPSet used varbin.Read with a pre-allocated slice, which worked because
|
||||||
|
// slice elements are addressable and CanSet() returns true for them.
|
||||||
|
//
|
||||||
|
// For compatibility testing, we verify:
|
||||||
|
// 1. New write produces correct output with range data
|
||||||
|
// 2. New read can parse the new format correctly
|
||||||
|
// 3. Round-trip works correctly
|
||||||
|
|
||||||
|
func oldReadIPSet(reader varbin.Reader) (*netipx.IPSet, error) {
|
||||||
|
version, err := reader.ReadByte()
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if version != 1 {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
var length uint64
|
||||||
|
err = binary.Read(reader, binary.BigEndian, &length)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
ranges := make([]oldIPRangeData, length)
|
||||||
|
//nolint:staticcheck
|
||||||
|
err = varbin.Read(reader, binary.BigEndian, &ranges)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
mySet := &myIPSet{
|
||||||
|
rr: make([]myIPRange, len(ranges)),
|
||||||
|
}
|
||||||
|
for i, rangeData := range ranges {
|
||||||
|
mySet.rr[i].from = M.AddrFromIP(rangeData.From)
|
||||||
|
mySet.rr[i].to = M.AddrFromIP(rangeData.To)
|
||||||
|
}
|
||||||
|
return (*netipx.IPSet)(unsafe.Pointer(mySet)), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// New write functions (without itemType prefix for testing)
|
||||||
|
|
||||||
|
func newWriteStringSlice(writer varbin.Writer, value []string) error {
|
||||||
|
_, err := varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
for _, s := range value {
|
||||||
|
_, err = varbin.WriteUvarint(writer, uint64(len(s)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write([]byte(s))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func newWriteUint8Slice[E ~uint8](writer varbin.Writer, value []E) error {
|
||||||
|
_, err := varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write(*(*[]byte)(unsafe.Pointer(&value)))
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
func newWriteUint16Slice(writer varbin.Writer, value []uint16) error {
|
||||||
|
_, err := varbin.WriteUvarint(writer, uint64(len(value)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return binary.Write(writer, binary.BigEndian, value)
|
||||||
|
}
|
||||||
|
|
||||||
|
func newWritePrefix(writer varbin.Writer, prefix netip.Prefix) error {
|
||||||
|
addrSlice := prefix.Addr().AsSlice()
|
||||||
|
_, err := varbin.WriteUvarint(writer, uint64(len(addrSlice)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write(addrSlice)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return writer.WriteByte(uint8(prefix.Bits()))
|
||||||
|
}
|
||||||
|
|
||||||
|
// Tests
|
||||||
|
|
||||||
|
func TestStringSliceCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input []string
|
||||||
|
}{
|
||||||
|
{"nil", nil},
|
||||||
|
{"empty", []string{}},
|
||||||
|
{"single_empty", []string{""}},
|
||||||
|
{"single", []string{"test"}},
|
||||||
|
{"multi", []string{"a", "b", "c"}},
|
||||||
|
{"with_empty", []string{"a", "", "c"}},
|
||||||
|
{"utf8", []string{"测试", "テスト", "тест"}},
|
||||||
|
{"long_string", []string{strings.Repeat("x", 128)}},
|
||||||
|
{"many_elements", generateStrings(128)},
|
||||||
|
{"many_elements_256", generateStrings(256)},
|
||||||
|
{"127_byte_string", []string{strings.Repeat("x", 127)}},
|
||||||
|
{"128_byte_string", []string{strings.Repeat("x", 128)}},
|
||||||
|
{"mixed_lengths", []string{"a", strings.Repeat("b", 100), "", strings.Repeat("c", 200)}},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Old write
|
||||||
|
var oldBuf bytes.Buffer
|
||||||
|
err := oldWriteStringSlice(&oldBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err = newWriteStringSlice(&newBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Bytes must match
|
||||||
|
require.Equal(t, oldBuf.Bytes(), newBuf.Bytes(),
|
||||||
|
"mismatch for %q\nold: %x\nnew: %x", tc.name, oldBuf.Bytes(), newBuf.Bytes())
|
||||||
|
|
||||||
|
// New write -> old read
|
||||||
|
readBack, err := oldReadStringSlice(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireStringSliceEqual(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// Old write -> new read
|
||||||
|
readBack2, err := readRuleItemString(bufio.NewReader(bytes.NewReader(oldBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireStringSliceEqual(t, tc.input, readBack2)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestUint8SliceCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input []uint8
|
||||||
|
}{
|
||||||
|
{"nil", nil},
|
||||||
|
{"empty", []uint8{}},
|
||||||
|
{"single_zero", []uint8{0}},
|
||||||
|
{"single_max", []uint8{255}},
|
||||||
|
{"multi", []uint8{0, 1, 127, 128, 255}},
|
||||||
|
{"boundary", []uint8{0x00, 0x7f, 0x80, 0xff}},
|
||||||
|
{"sequential", generateUint8Slice(256)},
|
||||||
|
{"127_elements", generateUint8Slice(127)},
|
||||||
|
{"128_elements", generateUint8Slice(128)},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Old write
|
||||||
|
var oldBuf bytes.Buffer
|
||||||
|
err := oldWriteUint8Slice(&oldBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err = newWriteUint8Slice(&newBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Bytes must match
|
||||||
|
require.Equal(t, oldBuf.Bytes(), newBuf.Bytes(),
|
||||||
|
"mismatch for %q\nold: %x\nnew: %x", tc.name, oldBuf.Bytes(), newBuf.Bytes())
|
||||||
|
|
||||||
|
// New write -> old read
|
||||||
|
readBack, err := oldReadUint8Slice[uint8](bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireUint8SliceEqual(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// Old write -> new read
|
||||||
|
readBack2, err := readRuleItemUint8[uint8](bufio.NewReader(bytes.NewReader(oldBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireUint8SliceEqual(t, tc.input, readBack2)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestUint16SliceCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input []uint16
|
||||||
|
}{
|
||||||
|
{"nil", nil},
|
||||||
|
{"empty", []uint16{}},
|
||||||
|
{"single_zero", []uint16{0}},
|
||||||
|
{"single_max", []uint16{65535}},
|
||||||
|
{"multi", []uint16{0, 255, 256, 32767, 32768, 65535}},
|
||||||
|
{"ports", []uint16{80, 443, 8080, 8443}},
|
||||||
|
{"127_elements", generateUint16Slice(127)},
|
||||||
|
{"128_elements", generateUint16Slice(128)},
|
||||||
|
{"256_elements", generateUint16Slice(256)},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Old write
|
||||||
|
var oldBuf bytes.Buffer
|
||||||
|
err := oldWriteUint16Slice(&oldBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err = newWriteUint16Slice(&newBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Bytes must match
|
||||||
|
require.Equal(t, oldBuf.Bytes(), newBuf.Bytes(),
|
||||||
|
"mismatch for %q\nold: %x\nnew: %x", tc.name, oldBuf.Bytes(), newBuf.Bytes())
|
||||||
|
|
||||||
|
// New write -> old read
|
||||||
|
readBack, err := oldReadUint16Slice(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireUint16SliceEqual(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// Old write -> new read
|
||||||
|
readBack2, err := readRuleItemUint16(bufio.NewReader(bytes.NewReader(oldBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireUint16SliceEqual(t, tc.input, readBack2)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPrefixCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input netip.Prefix
|
||||||
|
}{
|
||||||
|
{"ipv4_0", netip.MustParsePrefix("0.0.0.0/0")},
|
||||||
|
{"ipv4_8", netip.MustParsePrefix("10.0.0.0/8")},
|
||||||
|
{"ipv4_16", netip.MustParsePrefix("192.168.0.0/16")},
|
||||||
|
{"ipv4_24", netip.MustParsePrefix("192.168.1.0/24")},
|
||||||
|
{"ipv4_32", netip.MustParsePrefix("1.2.3.4/32")},
|
||||||
|
{"ipv6_0", netip.MustParsePrefix("::/0")},
|
||||||
|
{"ipv6_64", netip.MustParsePrefix("2001:db8::/64")},
|
||||||
|
{"ipv6_128", netip.MustParsePrefix("::1/128")},
|
||||||
|
{"ipv6_full", netip.MustParsePrefix("2001:0db8:85a3:0000:0000:8a2e:0370:7334/128")},
|
||||||
|
{"ipv4_private", netip.MustParsePrefix("172.16.0.0/12")},
|
||||||
|
{"ipv6_link_local", netip.MustParsePrefix("fe80::/10")},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Old write
|
||||||
|
var oldBuf bytes.Buffer
|
||||||
|
err := oldWritePrefix(&oldBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err = newWritePrefix(&newBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Bytes must match
|
||||||
|
require.Equal(t, oldBuf.Bytes(), newBuf.Bytes(),
|
||||||
|
"mismatch for %q\nold: %x\nnew: %x", tc.name, oldBuf.Bytes(), newBuf.Bytes())
|
||||||
|
|
||||||
|
// New write -> new read (no old read for prefix)
|
||||||
|
readBack, err := readPrefix(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// Old write -> new read
|
||||||
|
readBack2, err := readPrefix(bufio.NewReader(bytes.NewReader(oldBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, tc.input, readBack2)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestIPSetCompat(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// Note: The old writeIPSet was buggy (varbin.Write with struct values wrote nothing).
|
||||||
|
// This test verifies the new implementation writes correct data and round-trips correctly.
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
input *netipx.IPSet
|
||||||
|
}{
|
||||||
|
{"single_ipv4", buildIPSet("1.2.3.4")},
|
||||||
|
{"ipv4_range", buildIPSet("192.168.0.0/16")},
|
||||||
|
{"multi_ipv4", buildIPSet("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16")},
|
||||||
|
{"single_ipv6", buildIPSet("::1")},
|
||||||
|
{"ipv6_range", buildIPSet("2001:db8::/32")},
|
||||||
|
{"mixed", buildIPSet("10.0.0.0/8", "::1", "2001:db8::/32")},
|
||||||
|
{"large", buildLargeIPSet(100)},
|
||||||
|
{"adjacent_ranges", buildIPSet("192.168.0.0/24", "192.168.1.0/24", "192.168.2.0/24")},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// New write
|
||||||
|
var newBuf bytes.Buffer
|
||||||
|
err := writeIPSet(&newBuf, tc.input)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
// Verify format starts with version byte (1) + uint64 count
|
||||||
|
require.True(t, len(newBuf.Bytes()) >= 9, "output too short")
|
||||||
|
require.Equal(t, byte(1), newBuf.Bytes()[0], "version byte mismatch")
|
||||||
|
|
||||||
|
// New write -> old read (varbin.Read with pre-allocated slice works correctly)
|
||||||
|
readBack, err := oldReadIPSet(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireIPSetEqual(t, tc.input, readBack)
|
||||||
|
|
||||||
|
// New write -> new read
|
||||||
|
readBack2, err := readIPSet(bufio.NewReader(bytes.NewReader(newBuf.Bytes())))
|
||||||
|
require.NoError(t, err)
|
||||||
|
requireIPSetEqual(t, tc.input, readBack2)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Helper functions
|
||||||
|
|
||||||
|
func generateStrings(count int) []string {
|
||||||
|
result := make([]string, count)
|
||||||
|
for i := range result {
|
||||||
|
result[i] = strings.Repeat("x", i%50)
|
||||||
|
}
|
||||||
|
return result
|
||||||
|
}
|
||||||
|
|
||||||
|
func generateUint8Slice(count int) []uint8 {
|
||||||
|
result := make([]uint8, count)
|
||||||
|
for i := range result {
|
||||||
|
result[i] = uint8(i % 256)
|
||||||
|
}
|
||||||
|
return result
|
||||||
|
}
|
||||||
|
|
||||||
|
func generateUint16Slice(count int) []uint16 {
|
||||||
|
result := make([]uint16, count)
|
||||||
|
for i := range result {
|
||||||
|
result[i] = uint16(i * 257)
|
||||||
|
}
|
||||||
|
return result
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildIPSet(cidrs ...string) *netipx.IPSet {
|
||||||
|
var builder netipx.IPSetBuilder
|
||||||
|
for _, cidr := range cidrs {
|
||||||
|
prefix, err := netip.ParsePrefix(cidr)
|
||||||
|
if err != nil {
|
||||||
|
addr, err := netip.ParseAddr(cidr)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
builder.Add(addr)
|
||||||
|
} else {
|
||||||
|
builder.AddPrefix(prefix)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
set, _ := builder.IPSet()
|
||||||
|
return set
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildLargeIPSet(count int) *netipx.IPSet {
|
||||||
|
var builder netipx.IPSetBuilder
|
||||||
|
for i := 0; i < count; i++ {
|
||||||
|
prefix := netip.PrefixFrom(netip.AddrFrom4([4]byte{10, byte(i / 256), byte(i % 256), 0}), 24)
|
||||||
|
builder.AddPrefix(prefix)
|
||||||
|
}
|
||||||
|
set, _ := builder.IPSet()
|
||||||
|
return set
|
||||||
|
}
|
||||||
|
|
||||||
|
func requireStringSliceEqual(t *testing.T, expected, actual []string) {
|
||||||
|
t.Helper()
|
||||||
|
if len(expected) == 0 && len(actual) == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
require.Equal(t, expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
func requireUint8SliceEqual(t *testing.T, expected, actual []uint8) {
|
||||||
|
t.Helper()
|
||||||
|
if len(expected) == 0 && len(actual) == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
require.Equal(t, expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
func requireUint16SliceEqual(t *testing.T, expected, actual []uint16) {
|
||||||
|
t.Helper()
|
||||||
|
if len(expected) == 0 && len(actual) == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
require.Equal(t, expected, actual)
|
||||||
|
}
|
||||||
|
|
||||||
|
func requireIPSetEqual(t *testing.T, expected, actual *netipx.IPSet) {
|
||||||
|
t.Helper()
|
||||||
|
expectedRanges := expected.Ranges()
|
||||||
|
actualRanges := actual.Ranges()
|
||||||
|
require.Equal(t, len(expectedRanges), len(actualRanges), "range count mismatch")
|
||||||
|
for i := range expectedRanges {
|
||||||
|
require.Equal(t, expectedRanges[i].From(), actualRanges[i].From(), "range[%d].from mismatch", i)
|
||||||
|
require.Equal(t, expectedRanges[i].To(), actualRanges[i].To(), "range[%d].to mismatch", i)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@ package srs
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/binary"
|
"encoding/binary"
|
||||||
|
"io"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
|
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
@@ -9,11 +10,16 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func readPrefix(reader varbin.Reader) (netip.Prefix, error) {
|
func readPrefix(reader varbin.Reader) (netip.Prefix, error) {
|
||||||
addrSlice, err := varbin.ReadValue[[]byte](reader, binary.BigEndian)
|
addrLen, err := binary.ReadUvarint(reader)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return netip.Prefix{}, err
|
return netip.Prefix{}, err
|
||||||
}
|
}
|
||||||
prefixBits, err := varbin.ReadValue[uint8](reader, binary.BigEndian)
|
addrSlice := make([]byte, addrLen)
|
||||||
|
_, err = io.ReadFull(reader, addrSlice)
|
||||||
|
if err != nil {
|
||||||
|
return netip.Prefix{}, err
|
||||||
|
}
|
||||||
|
prefixBits, err := reader.ReadByte()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return netip.Prefix{}, err
|
return netip.Prefix{}, err
|
||||||
}
|
}
|
||||||
@@ -21,11 +27,16 @@ func readPrefix(reader varbin.Reader) (netip.Prefix, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func writePrefix(writer varbin.Writer, prefix netip.Prefix) error {
|
func writePrefix(writer varbin.Writer, prefix netip.Prefix) error {
|
||||||
err := varbin.Write(writer, binary.BigEndian, prefix.Addr().AsSlice())
|
addrSlice := prefix.Addr().AsSlice()
|
||||||
|
_, err := varbin.WriteUvarint(writer, uint64(len(addrSlice)))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
err = binary.Write(writer, binary.BigEndian, uint8(prefix.Bits()))
|
_, err = writer.Write(addrSlice)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
err = writer.WriteByte(uint8(prefix.Bits()))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,11 +2,11 @@ package srs
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/binary"
|
"encoding/binary"
|
||||||
|
"io"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
"unsafe"
|
"unsafe"
|
||||||
|
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
"github.com/sagernet/sing/common/varbin"
|
"github.com/sagernet/sing/common/varbin"
|
||||||
|
|
||||||
@@ -22,11 +22,6 @@ type myIPRange struct {
|
|||||||
to netip.Addr
|
to netip.Addr
|
||||||
}
|
}
|
||||||
|
|
||||||
type myIPRangeData struct {
|
|
||||||
From []byte
|
|
||||||
To []byte
|
|
||||||
}
|
|
||||||
|
|
||||||
func readIPSet(reader varbin.Reader) (*netipx.IPSet, error) {
|
func readIPSet(reader varbin.Reader) (*netipx.IPSet, error) {
|
||||||
version, err := reader.ReadByte()
|
version, err := reader.ReadByte()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -41,17 +36,30 @@ func readIPSet(reader varbin.Reader) (*netipx.IPSet, error) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
ranges := make([]myIPRangeData, length)
|
|
||||||
err = varbin.Read(reader, binary.BigEndian, &ranges)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
mySet := &myIPSet{
|
mySet := &myIPSet{
|
||||||
rr: make([]myIPRange, len(ranges)),
|
rr: make([]myIPRange, length),
|
||||||
}
|
}
|
||||||
for i, rangeData := range ranges {
|
for i := range mySet.rr {
|
||||||
mySet.rr[i].from = M.AddrFromIP(rangeData.From)
|
fromLen, err := binary.ReadUvarint(reader)
|
||||||
mySet.rr[i].to = M.AddrFromIP(rangeData.To)
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
fromBytes := make([]byte, fromLen)
|
||||||
|
_, err = io.ReadFull(reader, fromBytes)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
toLen, err := binary.ReadUvarint(reader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
toBytes := make([]byte, toLen)
|
||||||
|
_, err = io.ReadFull(reader, toBytes)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
mySet.rr[i].from = M.AddrFromIP(fromBytes)
|
||||||
|
mySet.rr[i].to = M.AddrFromIP(toBytes)
|
||||||
}
|
}
|
||||||
return (*netipx.IPSet)(unsafe.Pointer(mySet)), nil
|
return (*netipx.IPSet)(unsafe.Pointer(mySet)), nil
|
||||||
}
|
}
|
||||||
@@ -61,18 +69,27 @@ func writeIPSet(writer varbin.Writer, set *netipx.IPSet) error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
dataList := common.Map((*myIPSet)(unsafe.Pointer(set)).rr, func(rr myIPRange) myIPRangeData {
|
mySet := (*myIPSet)(unsafe.Pointer(set))
|
||||||
return myIPRangeData{
|
err = binary.Write(writer, binary.BigEndian, uint64(len(mySet.rr)))
|
||||||
From: rr.from.AsSlice(),
|
|
||||||
To: rr.to.AsSlice(),
|
|
||||||
}
|
|
||||||
})
|
|
||||||
err = binary.Write(writer, binary.BigEndian, uint64(len(dataList)))
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
for _, data := range dataList {
|
for _, rr := range mySet.rr {
|
||||||
err = varbin.Write(writer, binary.BigEndian, data)
|
fromBytes := rr.from.AsSlice()
|
||||||
|
_, err = varbin.WriteUvarint(writer, uint64(len(fromBytes)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write(fromBytes)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
toBytes := rr.to.AsSlice()
|
||||||
|
_, err = varbin.WriteUvarint(writer, uint64(len(toBytes)))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = writer.Write(toBytes)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import (
|
|||||||
"github.com/sagernet/sing/common/logger"
|
"github.com/sagernet/sing/common/logger"
|
||||||
|
|
||||||
"github.com/caddyserver/certmagic"
|
"github.com/caddyserver/certmagic"
|
||||||
|
"github.com/libdns/acmedns"
|
||||||
"github.com/libdns/alidns"
|
"github.com/libdns/alidns"
|
||||||
"github.com/libdns/cloudflare"
|
"github.com/libdns/cloudflare"
|
||||||
"github.com/mholt/acmez/v3/acme"
|
"github.com/mholt/acmez/v3/acme"
|
||||||
@@ -126,6 +127,13 @@ func startACME(ctx context.Context, logger logger.Logger, options option.Inbound
|
|||||||
APIToken: dnsOptions.CloudflareOptions.APIToken,
|
APIToken: dnsOptions.CloudflareOptions.APIToken,
|
||||||
ZoneToken: dnsOptions.CloudflareOptions.ZoneToken,
|
ZoneToken: dnsOptions.CloudflareOptions.ZoneToken,
|
||||||
}
|
}
|
||||||
|
case C.DNSProviderACMEDNS:
|
||||||
|
solver.DNSProvider = &acmedns.Provider{
|
||||||
|
Username: dnsOptions.ACMEDNSOptions.Username,
|
||||||
|
Password: dnsOptions.ACMEDNSOptions.Password,
|
||||||
|
Subdomain: dnsOptions.ACMEDNSOptions.Subdomain,
|
||||||
|
ServerURL: dnsOptions.ACMEDNSOptions.ServerURL,
|
||||||
|
}
|
||||||
default:
|
default:
|
||||||
return nil, nil, E.New("unsupported ACME DNS01 provider type: " + dnsOptions.Provider)
|
return nil, nil, E.New("unsupported ACME DNS01 provider type: " + dnsOptions.Provider)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -15,7 +15,6 @@ import (
|
|||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/dns"
|
"github.com/sagernet/sing-box/dns"
|
||||||
"github.com/sagernet/sing-box/experimental/deprecated"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
aTLS "github.com/sagernet/sing/common/tls"
|
aTLS "github.com/sagernet/sing/common/tls"
|
||||||
@@ -38,7 +37,7 @@ func parseECHClientConfig(ctx context.Context, clientConfig ECHCapableConfig, op
|
|||||||
}
|
}
|
||||||
//nolint:staticcheck
|
//nolint:staticcheck
|
||||||
if options.ECH.PQSignatureSchemesEnabled || options.ECH.DynamicRecordSizingDisabled {
|
if options.ECH.PQSignatureSchemesEnabled || options.ECH.DynamicRecordSizingDisabled {
|
||||||
deprecated.Report(ctx, deprecated.OptionLegacyECHOptions)
|
return nil, E.New("legacy ECH options are deprecated in sing-box 1.12.0 and removed in sing-box 1.13.0")
|
||||||
}
|
}
|
||||||
if len(echConfig) > 0 {
|
if len(echConfig) > 0 {
|
||||||
block, rest := pem.Decode(echConfig)
|
block, rest := pem.Decode(echConfig)
|
||||||
@@ -77,7 +76,7 @@ func parseECHServerConfig(ctx context.Context, options option.InboundTLSOptions,
|
|||||||
tlsConfig.EncryptedClientHelloKeys = echKeys
|
tlsConfig.EncryptedClientHelloKeys = echKeys
|
||||||
//nolint:staticcheck
|
//nolint:staticcheck
|
||||||
if options.ECH.PQSignatureSchemesEnabled || options.ECH.DynamicRecordSizingDisabled {
|
if options.ECH.PQSignatureSchemesEnabled || options.ECH.DynamicRecordSizingDisabled {
|
||||||
deprecated.Report(ctx, deprecated.OptionLegacyECHOptions)
|
return E.New("legacy ECH options are deprecated in sing-box 1.12.0 and removed in sing-box 1.13.0")
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -33,4 +33,5 @@ const (
|
|||||||
const (
|
const (
|
||||||
DNSProviderAliDNS = "alidns"
|
DNSProviderAliDNS = "alidns"
|
||||||
DNSProviderCloudflare = "cloudflare"
|
DNSProviderCloudflare = "cloudflare"
|
||||||
|
DNSProviderACMEDNS = "acmedns"
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -25,11 +25,13 @@ const (
|
|||||||
TypeTUIC = "tuic"
|
TypeTUIC = "tuic"
|
||||||
TypeHysteria2 = "hysteria2"
|
TypeHysteria2 = "hysteria2"
|
||||||
TypeTailscale = "tailscale"
|
TypeTailscale = "tailscale"
|
||||||
|
TypeCloudflared = "cloudflared"
|
||||||
TypeDERP = "derp"
|
TypeDERP = "derp"
|
||||||
TypeResolved = "resolved"
|
TypeResolved = "resolved"
|
||||||
TypeSSMAPI = "ssm-api"
|
TypeSSMAPI = "ssm-api"
|
||||||
TypeCCM = "ccm"
|
TypeCCM = "ccm"
|
||||||
TypeOCM = "ocm"
|
TypeOCM = "ocm"
|
||||||
|
TypeOOMKiller = "oom-killer"
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
@@ -85,6 +87,10 @@ func ProxyDisplayName(proxyType string) string {
|
|||||||
return "Hysteria2"
|
return "Hysteria2"
|
||||||
case TypeAnyTLS:
|
case TypeAnyTLS:
|
||||||
return "AnyTLS"
|
return "AnyTLS"
|
||||||
|
case TypeTailscale:
|
||||||
|
return "Tailscale"
|
||||||
|
case TypeCloudflared:
|
||||||
|
return "Cloudflared"
|
||||||
case TypeSelector:
|
case TypeSelector:
|
||||||
return "Selector"
|
return "Selector"
|
||||||
case TypeURLTest:
|
case TypeURLTest:
|
||||||
|
|||||||
@@ -7,9 +7,12 @@ import (
|
|||||||
"github.com/sagernet/sing-box"
|
"github.com/sagernet/sing-box"
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/common/urltest"
|
"github.com/sagernet/sing-box/common/urltest"
|
||||||
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing-box/experimental/deprecated"
|
"github.com/sagernet/sing-box/experimental/deprecated"
|
||||||
"github.com/sagernet/sing-box/include"
|
"github.com/sagernet/sing-box/include"
|
||||||
|
"github.com/sagernet/sing-box/log"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
|
"github.com/sagernet/sing/common"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
"github.com/sagernet/sing/common/json"
|
"github.com/sagernet/sing/common/json"
|
||||||
"github.com/sagernet/sing/service"
|
"github.com/sagernet/sing/service"
|
||||||
@@ -20,6 +23,7 @@ type Instance struct {
|
|||||||
ctx context.Context
|
ctx context.Context
|
||||||
cancel context.CancelFunc
|
cancel context.CancelFunc
|
||||||
instance *box.Box
|
instance *box.Box
|
||||||
|
connectionManager adapter.ConnectionManager
|
||||||
clashServer adapter.ClashServer
|
clashServer adapter.ClashServer
|
||||||
cacheFile adapter.CacheFile
|
cacheFile adapter.CacheFile
|
||||||
pauseManager pause.Manager
|
pauseManager pause.Manager
|
||||||
@@ -83,6 +87,15 @@ func (s *StartedService) newInstance(profileContent string, overrideOptions *Ove
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if s.oomKiller && C.IsIos {
|
||||||
|
if !common.Any(options.Services, func(it option.Service) bool {
|
||||||
|
return it.Type == C.TypeOOMKiller
|
||||||
|
}) {
|
||||||
|
options.Services = append(options.Services, option.Service{
|
||||||
|
Type: C.TypeOOMKiller,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
urlTestHistoryStorage := urltest.NewHistoryStorage()
|
urlTestHistoryStorage := urltest.NewHistoryStorage()
|
||||||
ctx = service.ContextWithPtr(ctx, urlTestHistoryStorage)
|
ctx = service.ContextWithPtr(ctx, urlTestHistoryStorage)
|
||||||
i := &Instance{
|
i := &Instance{
|
||||||
@@ -100,9 +113,11 @@ func (s *StartedService) newInstance(profileContent string, overrideOptions *Ove
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
i.instance = boxInstance
|
i.instance = boxInstance
|
||||||
|
i.connectionManager = service.FromContext[adapter.ConnectionManager](ctx)
|
||||||
i.clashServer = service.FromContext[adapter.ClashServer](ctx)
|
i.clashServer = service.FromContext[adapter.ClashServer](ctx)
|
||||||
i.pauseManager = service.FromContext[pause.Manager](ctx)
|
i.pauseManager = service.FromContext[pause.Manager](ctx)
|
||||||
i.cacheFile = service.FromContext[adapter.CacheFile](ctx)
|
i.cacheFile = service.FromContext[adapter.CacheFile](ctx)
|
||||||
|
log.SetStdLogger(boxInstance.LogFactory().Logger())
|
||||||
return i, nil
|
return i, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/common/conntrack"
|
|
||||||
"github.com/sagernet/sing-box/common/urltest"
|
"github.com/sagernet/sing-box/common/urltest"
|
||||||
"github.com/sagernet/sing-box/experimental/clashapi"
|
"github.com/sagernet/sing-box/experimental/clashapi"
|
||||||
"github.com/sagernet/sing-box/experimental/clashapi/trafficontrol"
|
"github.com/sagernet/sing-box/experimental/clashapi/trafficontrol"
|
||||||
@@ -36,6 +35,7 @@ type StartedService struct {
|
|||||||
handler PlatformHandler
|
handler PlatformHandler
|
||||||
debug bool
|
debug bool
|
||||||
logMaxLines int
|
logMaxLines int
|
||||||
|
oomKiller bool
|
||||||
// workingDirectory string
|
// workingDirectory string
|
||||||
// tempDirectory string
|
// tempDirectory string
|
||||||
// userID int
|
// userID int
|
||||||
@@ -56,6 +56,9 @@ type StartedService struct {
|
|||||||
urlTestHistoryStorage *urltest.HistoryStorage
|
urlTestHistoryStorage *urltest.HistoryStorage
|
||||||
clashModeSubscriber *observable.Subscriber[struct{}]
|
clashModeSubscriber *observable.Subscriber[struct{}]
|
||||||
clashModeObserver *observable.Observer[struct{}]
|
clashModeObserver *observable.Observer[struct{}]
|
||||||
|
|
||||||
|
connectionEventSubscriber *observable.Subscriber[trafficontrol.ConnectionEvent]
|
||||||
|
connectionEventObserver *observable.Observer[trafficontrol.ConnectionEvent]
|
||||||
}
|
}
|
||||||
|
|
||||||
type ServiceOptions struct {
|
type ServiceOptions struct {
|
||||||
@@ -64,6 +67,7 @@ type ServiceOptions struct {
|
|||||||
Handler PlatformHandler
|
Handler PlatformHandler
|
||||||
Debug bool
|
Debug bool
|
||||||
LogMaxLines int
|
LogMaxLines int
|
||||||
|
OOMKiller bool
|
||||||
// WorkingDirectory string
|
// WorkingDirectory string
|
||||||
// TempDirectory string
|
// TempDirectory string
|
||||||
// UserID int
|
// UserID int
|
||||||
@@ -78,22 +82,25 @@ func NewStartedService(options ServiceOptions) *StartedService {
|
|||||||
handler: options.Handler,
|
handler: options.Handler,
|
||||||
debug: options.Debug,
|
debug: options.Debug,
|
||||||
logMaxLines: options.LogMaxLines,
|
logMaxLines: options.LogMaxLines,
|
||||||
|
oomKiller: options.OOMKiller,
|
||||||
// workingDirectory: options.WorkingDirectory,
|
// workingDirectory: options.WorkingDirectory,
|
||||||
// tempDirectory: options.TempDirectory,
|
// tempDirectory: options.TempDirectory,
|
||||||
// userID: options.UserID,
|
// userID: options.UserID,
|
||||||
// groupID: options.GroupID,
|
// groupID: options.GroupID,
|
||||||
// systemProxyEnabled: options.SystemProxyEnabled,
|
// systemProxyEnabled: options.SystemProxyEnabled,
|
||||||
serviceStatus: &ServiceStatus{Status: ServiceStatus_IDLE},
|
serviceStatus: &ServiceStatus{Status: ServiceStatus_IDLE},
|
||||||
serviceStatusSubscriber: observable.NewSubscriber[*ServiceStatus](4),
|
serviceStatusSubscriber: observable.NewSubscriber[*ServiceStatus](4),
|
||||||
logSubscriber: observable.NewSubscriber[*log.Entry](128),
|
logSubscriber: observable.NewSubscriber[*log.Entry](128),
|
||||||
urlTestSubscriber: observable.NewSubscriber[struct{}](1),
|
urlTestSubscriber: observable.NewSubscriber[struct{}](1),
|
||||||
urlTestHistoryStorage: urltest.NewHistoryStorage(),
|
urlTestHistoryStorage: urltest.NewHistoryStorage(),
|
||||||
clashModeSubscriber: observable.NewSubscriber[struct{}](1),
|
clashModeSubscriber: observable.NewSubscriber[struct{}](1),
|
||||||
|
connectionEventSubscriber: observable.NewSubscriber[trafficontrol.ConnectionEvent](256),
|
||||||
}
|
}
|
||||||
s.serviceStatusObserver = observable.NewObserver(s.serviceStatusSubscriber, 2)
|
s.serviceStatusObserver = observable.NewObserver(s.serviceStatusSubscriber, 2)
|
||||||
s.logObserver = observable.NewObserver(s.logSubscriber, 64)
|
s.logObserver = observable.NewObserver(s.logSubscriber, 64)
|
||||||
s.urlTestObserver = observable.NewObserver(s.urlTestSubscriber, 1)
|
s.urlTestObserver = observable.NewObserver(s.urlTestSubscriber, 1)
|
||||||
s.clashModeObserver = observable.NewObserver(s.clashModeSubscriber, 1)
|
s.clashModeObserver = observable.NewObserver(s.clashModeSubscriber, 1)
|
||||||
|
s.connectionEventObserver = observable.NewObserver(s.connectionEventSubscriber, 64)
|
||||||
return s
|
return s
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -161,7 +168,7 @@ func (s *StartedService) waitForStarted(ctx context.Context) error {
|
|||||||
func (s *StartedService) StartOrReloadService(profileContent string, options *OverrideOptions) error {
|
func (s *StartedService) StartOrReloadService(profileContent string, options *OverrideOptions) error {
|
||||||
s.serviceAccess.Lock()
|
s.serviceAccess.Lock()
|
||||||
switch s.serviceStatus.Status {
|
switch s.serviceStatus.Status {
|
||||||
case ServiceStatus_IDLE, ServiceStatus_STARTED, ServiceStatus_STARTING:
|
case ServiceStatus_IDLE, ServiceStatus_STARTED, ServiceStatus_STARTING, ServiceStatus_FATAL:
|
||||||
default:
|
default:
|
||||||
s.serviceAccess.Unlock()
|
s.serviceAccess.Unlock()
|
||||||
return os.ErrInvalid
|
return os.ErrInvalid
|
||||||
@@ -183,6 +190,7 @@ func (s *StartedService) StartOrReloadService(profileContent string, options *Ov
|
|||||||
instance.urlTestHistoryStorage.SetHook(s.urlTestSubscriber)
|
instance.urlTestHistoryStorage.SetHook(s.urlTestSubscriber)
|
||||||
if instance.clashServer != nil {
|
if instance.clashServer != nil {
|
||||||
instance.clashServer.SetModeUpdateHook(s.clashModeSubscriber)
|
instance.clashServer.SetModeUpdateHook(s.clashModeSubscriber)
|
||||||
|
instance.clashServer.(*clashapi.Server).TrafficManager().SetEventHook(s.connectionEventSubscriber)
|
||||||
}
|
}
|
||||||
s.serviceAccess.Unlock()
|
s.serviceAccess.Unlock()
|
||||||
err = instance.Start()
|
err = instance.Start()
|
||||||
@@ -201,6 +209,14 @@ func (s *StartedService) StartOrReloadService(profileContent string, options *Ov
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (s *StartedService) Close() {
|
||||||
|
s.serviceStatusSubscriber.Close()
|
||||||
|
s.logSubscriber.Close()
|
||||||
|
s.urlTestSubscriber.Close()
|
||||||
|
s.clashModeSubscriber.Close()
|
||||||
|
s.connectionEventSubscriber.Close()
|
||||||
|
}
|
||||||
|
|
||||||
func (s *StartedService) CloseService() error {
|
func (s *StartedService) CloseService() error {
|
||||||
s.serviceAccess.Lock()
|
s.serviceAccess.Lock()
|
||||||
switch s.serviceStatus.Status {
|
switch s.serviceStatus.Status {
|
||||||
@@ -210,13 +226,14 @@ func (s *StartedService) CloseService() error {
|
|||||||
return os.ErrInvalid
|
return os.ErrInvalid
|
||||||
}
|
}
|
||||||
s.updateStatus(ServiceStatus_STOPPING)
|
s.updateStatus(ServiceStatus_STOPPING)
|
||||||
if s.instance != nil {
|
instance := s.instance
|
||||||
err := s.instance.Close()
|
s.instance = nil
|
||||||
|
if instance != nil {
|
||||||
|
err := instance.Close()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return s.updateStatusError(err)
|
return s.updateStatusError(err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
s.instance = nil
|
|
||||||
s.startedAt = time.Time{}
|
s.startedAt = time.Time{}
|
||||||
s.updateStatus(ServiceStatus_IDLE)
|
s.updateStatus(ServiceStatus_IDLE)
|
||||||
s.serviceAccess.Unlock()
|
s.serviceAccess.Unlock()
|
||||||
@@ -393,12 +410,14 @@ func (s *StartedService) SubscribeStatus(request *SubscribeStatusRequest, server
|
|||||||
|
|
||||||
func (s *StartedService) readStatus() *Status {
|
func (s *StartedService) readStatus() *Status {
|
||||||
var status Status
|
var status Status
|
||||||
status.Memory = memory.Inuse()
|
status.Memory = memory.Total()
|
||||||
status.Goroutines = int32(runtime.NumGoroutine())
|
status.Goroutines = int32(runtime.NumGoroutine())
|
||||||
status.ConnectionsOut = int32(conntrack.Count())
|
|
||||||
s.serviceAccess.RLock()
|
s.serviceAccess.RLock()
|
||||||
nowService := s.instance
|
nowService := s.instance
|
||||||
s.serviceAccess.RUnlock()
|
s.serviceAccess.RUnlock()
|
||||||
|
if nowService != nil && nowService.connectionManager != nil {
|
||||||
|
status.ConnectionsOut = int32(nowService.connectionManager.Count())
|
||||||
|
}
|
||||||
if nowService != nil {
|
if nowService != nil {
|
||||||
if clashServer := nowService.clashServer; clashServer != nil {
|
if clashServer := nowService.clashServer; clashServer != nil {
|
||||||
status.TrafficAvailable = true
|
status.TrafficAvailable = true
|
||||||
@@ -666,7 +685,7 @@ func (s *StartedService) SetSystemProxyEnabled(ctx context.Context, request *Set
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *StartedService) SubscribeConnections(request *SubscribeConnectionsRequest, server grpc.ServerStreamingServer[Connections]) error {
|
func (s *StartedService) SubscribeConnections(request *SubscribeConnectionsRequest, server grpc.ServerStreamingServer[ConnectionEvents]) error {
|
||||||
err := s.waitForStarted(server.Context())
|
err := s.waitForStarted(server.Context())
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
@@ -674,80 +693,271 @@ func (s *StartedService) SubscribeConnections(request *SubscribeConnectionsReque
|
|||||||
s.serviceAccess.RLock()
|
s.serviceAccess.RLock()
|
||||||
boxService := s.instance
|
boxService := s.instance
|
||||||
s.serviceAccess.RUnlock()
|
s.serviceAccess.RUnlock()
|
||||||
ticker := time.NewTicker(time.Duration(request.Interval))
|
|
||||||
defer ticker.Stop()
|
if boxService.clashServer == nil {
|
||||||
|
return E.New("clash server not available")
|
||||||
|
}
|
||||||
|
|
||||||
trafficManager := boxService.clashServer.(*clashapi.Server).TrafficManager()
|
trafficManager := boxService.clashServer.(*clashapi.Server).TrafficManager()
|
||||||
var (
|
|
||||||
connections = make(map[uuid.UUID]*Connection)
|
subscription, done, err := s.connectionEventObserver.Subscribe()
|
||||||
outConnections []*Connection
|
if err != nil {
|
||||||
)
|
return err
|
||||||
|
}
|
||||||
|
defer s.connectionEventObserver.UnSubscribe(subscription)
|
||||||
|
|
||||||
|
connectionSnapshots := make(map[uuid.UUID]connectionSnapshot)
|
||||||
|
initialEvents := s.buildInitialConnectionState(trafficManager, connectionSnapshots)
|
||||||
|
err = server.Send(&ConnectionEvents{
|
||||||
|
Events: initialEvents,
|
||||||
|
Reset_: true,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
interval := time.Duration(request.Interval)
|
||||||
|
if interval <= 0 {
|
||||||
|
interval = time.Second
|
||||||
|
}
|
||||||
|
ticker := time.NewTicker(interval)
|
||||||
|
defer ticker.Stop()
|
||||||
|
|
||||||
for {
|
for {
|
||||||
outConnections = outConnections[:0]
|
|
||||||
for _, connection := range trafficManager.Connections() {
|
|
||||||
outConnections = append(outConnections, newConnection(connections, connection, false))
|
|
||||||
}
|
|
||||||
for _, connection := range trafficManager.ClosedConnections() {
|
|
||||||
outConnections = append(outConnections, newConnection(connections, connection, true))
|
|
||||||
}
|
|
||||||
err := server.Send(&Connections{Connections: outConnections})
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
select {
|
select {
|
||||||
case <-s.ctx.Done():
|
case <-s.ctx.Done():
|
||||||
return s.ctx.Err()
|
return s.ctx.Err()
|
||||||
case <-server.Context().Done():
|
case <-server.Context().Done():
|
||||||
return server.Context().Err()
|
return server.Context().Err()
|
||||||
|
case <-done:
|
||||||
|
return nil
|
||||||
|
|
||||||
|
case event := <-subscription:
|
||||||
|
var pendingEvents []*ConnectionEvent
|
||||||
|
if protoEvent := s.applyConnectionEvent(event, connectionSnapshots); protoEvent != nil {
|
||||||
|
pendingEvents = append(pendingEvents, protoEvent)
|
||||||
|
}
|
||||||
|
drain:
|
||||||
|
for {
|
||||||
|
select {
|
||||||
|
case event = <-subscription:
|
||||||
|
if protoEvent := s.applyConnectionEvent(event, connectionSnapshots); protoEvent != nil {
|
||||||
|
pendingEvents = append(pendingEvents, protoEvent)
|
||||||
|
}
|
||||||
|
default:
|
||||||
|
break drain
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(pendingEvents) > 0 {
|
||||||
|
err = server.Send(&ConnectionEvents{Events: pendingEvents})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
case <-ticker.C:
|
case <-ticker.C:
|
||||||
|
protoEvents := s.buildTrafficUpdates(trafficManager, connectionSnapshots)
|
||||||
|
if len(protoEvents) == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
err = server.Send(&ConnectionEvents{Events: protoEvents})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func newConnection(connections map[uuid.UUID]*Connection, metadata trafficontrol.TrackerMetadata, isClosed bool) *Connection {
|
type connectionSnapshot struct {
|
||||||
if oldConnection, loaded := connections[metadata.ID]; loaded {
|
uplink int64
|
||||||
if isClosed {
|
downlink int64
|
||||||
if oldConnection.ClosedAt == 0 {
|
hadTraffic bool
|
||||||
oldConnection.Uplink = 0
|
}
|
||||||
oldConnection.Downlink = 0
|
|
||||||
oldConnection.ClosedAt = metadata.ClosedAt.UnixMilli()
|
func (s *StartedService) buildInitialConnectionState(manager *trafficontrol.Manager, snapshots map[uuid.UUID]connectionSnapshot) []*ConnectionEvent {
|
||||||
}
|
var events []*ConnectionEvent
|
||||||
return oldConnection
|
|
||||||
|
for _, metadata := range manager.Connections() {
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_NEW,
|
||||||
|
Id: metadata.ID.String(),
|
||||||
|
Connection: buildConnectionProto(metadata),
|
||||||
|
})
|
||||||
|
snapshots[metadata.ID] = connectionSnapshot{
|
||||||
|
uplink: metadata.Upload.Load(),
|
||||||
|
downlink: metadata.Download.Load(),
|
||||||
}
|
}
|
||||||
lastUplink := oldConnection.UplinkTotal
|
|
||||||
lastDownlink := oldConnection.DownlinkTotal
|
|
||||||
uplinkTotal := metadata.Upload.Load()
|
|
||||||
downlinkTotal := metadata.Download.Load()
|
|
||||||
oldConnection.Uplink = uplinkTotal - lastUplink
|
|
||||||
oldConnection.Downlink = downlinkTotal - lastDownlink
|
|
||||||
oldConnection.UplinkTotal = uplinkTotal
|
|
||||||
oldConnection.DownlinkTotal = downlinkTotal
|
|
||||||
return oldConnection
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
for _, metadata := range manager.ClosedConnections() {
|
||||||
|
conn := buildConnectionProto(metadata)
|
||||||
|
conn.ClosedAt = metadata.ClosedAt.UnixMilli()
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_NEW,
|
||||||
|
Id: metadata.ID.String(),
|
||||||
|
Connection: conn,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
return events
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *StartedService) applyConnectionEvent(event trafficontrol.ConnectionEvent, snapshots map[uuid.UUID]connectionSnapshot) *ConnectionEvent {
|
||||||
|
switch event.Type {
|
||||||
|
case trafficontrol.ConnectionEventNew:
|
||||||
|
if _, exists := snapshots[event.ID]; exists {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
snapshots[event.ID] = connectionSnapshot{
|
||||||
|
uplink: event.Metadata.Upload.Load(),
|
||||||
|
downlink: event.Metadata.Download.Load(),
|
||||||
|
}
|
||||||
|
return &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_NEW,
|
||||||
|
Id: event.ID.String(),
|
||||||
|
Connection: buildConnectionProto(event.Metadata),
|
||||||
|
}
|
||||||
|
case trafficontrol.ConnectionEventClosed:
|
||||||
|
delete(snapshots, event.ID)
|
||||||
|
protoEvent := &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_CLOSED,
|
||||||
|
Id: event.ID.String(),
|
||||||
|
}
|
||||||
|
closedAt := event.ClosedAt
|
||||||
|
if closedAt.IsZero() && !event.Metadata.ClosedAt.IsZero() {
|
||||||
|
closedAt = event.Metadata.ClosedAt
|
||||||
|
}
|
||||||
|
if closedAt.IsZero() {
|
||||||
|
closedAt = time.Now()
|
||||||
|
}
|
||||||
|
protoEvent.ClosedAt = closedAt.UnixMilli()
|
||||||
|
if event.Metadata.ID != uuid.Nil {
|
||||||
|
conn := buildConnectionProto(event.Metadata)
|
||||||
|
conn.ClosedAt = protoEvent.ClosedAt
|
||||||
|
protoEvent.Connection = conn
|
||||||
|
}
|
||||||
|
return protoEvent
|
||||||
|
default:
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *StartedService) buildTrafficUpdates(manager *trafficontrol.Manager, snapshots map[uuid.UUID]connectionSnapshot) []*ConnectionEvent {
|
||||||
|
activeConnections := manager.Connections()
|
||||||
|
activeIndex := make(map[uuid.UUID]*trafficontrol.TrackerMetadata, len(activeConnections))
|
||||||
|
var events []*ConnectionEvent
|
||||||
|
|
||||||
|
for _, metadata := range activeConnections {
|
||||||
|
activeIndex[metadata.ID] = metadata
|
||||||
|
currentUpload := metadata.Upload.Load()
|
||||||
|
currentDownload := metadata.Download.Load()
|
||||||
|
snapshot, exists := snapshots[metadata.ID]
|
||||||
|
if !exists {
|
||||||
|
snapshots[metadata.ID] = connectionSnapshot{
|
||||||
|
uplink: currentUpload,
|
||||||
|
downlink: currentDownload,
|
||||||
|
}
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_NEW,
|
||||||
|
Id: metadata.ID.String(),
|
||||||
|
Connection: buildConnectionProto(metadata),
|
||||||
|
})
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
uplinkDelta := currentUpload - snapshot.uplink
|
||||||
|
downlinkDelta := currentDownload - snapshot.downlink
|
||||||
|
if uplinkDelta < 0 || downlinkDelta < 0 {
|
||||||
|
if snapshot.hadTraffic {
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_UPDATE,
|
||||||
|
Id: metadata.ID.String(),
|
||||||
|
UplinkDelta: 0,
|
||||||
|
DownlinkDelta: 0,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
snapshot.uplink = currentUpload
|
||||||
|
snapshot.downlink = currentDownload
|
||||||
|
snapshot.hadTraffic = false
|
||||||
|
snapshots[metadata.ID] = snapshot
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if uplinkDelta > 0 || downlinkDelta > 0 {
|
||||||
|
snapshot.uplink = currentUpload
|
||||||
|
snapshot.downlink = currentDownload
|
||||||
|
snapshot.hadTraffic = true
|
||||||
|
snapshots[metadata.ID] = snapshot
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_UPDATE,
|
||||||
|
Id: metadata.ID.String(),
|
||||||
|
UplinkDelta: uplinkDelta,
|
||||||
|
DownlinkDelta: downlinkDelta,
|
||||||
|
})
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if snapshot.hadTraffic {
|
||||||
|
snapshot.uplink = currentUpload
|
||||||
|
snapshot.downlink = currentDownload
|
||||||
|
snapshot.hadTraffic = false
|
||||||
|
snapshots[metadata.ID] = snapshot
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_UPDATE,
|
||||||
|
Id: metadata.ID.String(),
|
||||||
|
UplinkDelta: 0,
|
||||||
|
DownlinkDelta: 0,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
var closedIndex map[uuid.UUID]*trafficontrol.TrackerMetadata
|
||||||
|
for id := range snapshots {
|
||||||
|
if _, exists := activeIndex[id]; exists {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if closedIndex == nil {
|
||||||
|
closedIndex = make(map[uuid.UUID]*trafficontrol.TrackerMetadata)
|
||||||
|
for _, metadata := range manager.ClosedConnections() {
|
||||||
|
closedIndex[metadata.ID] = metadata
|
||||||
|
}
|
||||||
|
}
|
||||||
|
closedAt := time.Now()
|
||||||
|
var conn *Connection
|
||||||
|
if metadata, ok := closedIndex[id]; ok {
|
||||||
|
if !metadata.ClosedAt.IsZero() {
|
||||||
|
closedAt = metadata.ClosedAt
|
||||||
|
}
|
||||||
|
conn = buildConnectionProto(metadata)
|
||||||
|
conn.ClosedAt = closedAt.UnixMilli()
|
||||||
|
}
|
||||||
|
events = append(events, &ConnectionEvent{
|
||||||
|
Type: ConnectionEventType_CONNECTION_EVENT_CLOSED,
|
||||||
|
Id: id.String(),
|
||||||
|
ClosedAt: closedAt.UnixMilli(),
|
||||||
|
Connection: conn,
|
||||||
|
})
|
||||||
|
delete(snapshots, id)
|
||||||
|
}
|
||||||
|
|
||||||
|
return events
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildConnectionProto(metadata *trafficontrol.TrackerMetadata) *Connection {
|
||||||
var rule string
|
var rule string
|
||||||
if metadata.Rule != nil {
|
if metadata.Rule != nil {
|
||||||
rule = metadata.Rule.String()
|
rule = metadata.Rule.String()
|
||||||
}
|
}
|
||||||
uplinkTotal := metadata.Upload.Load()
|
uplinkTotal := metadata.Upload.Load()
|
||||||
downlinkTotal := metadata.Download.Load()
|
downlinkTotal := metadata.Download.Load()
|
||||||
uplink := uplinkTotal
|
|
||||||
downlink := downlinkTotal
|
|
||||||
var closedAt int64
|
|
||||||
if !metadata.ClosedAt.IsZero() {
|
|
||||||
closedAt = metadata.ClosedAt.UnixMilli()
|
|
||||||
uplink = 0
|
|
||||||
downlink = 0
|
|
||||||
}
|
|
||||||
var processInfo *ProcessInfo
|
var processInfo *ProcessInfo
|
||||||
if metadata.Metadata.ProcessInfo != nil {
|
if metadata.Metadata.ProcessInfo != nil {
|
||||||
processInfo = &ProcessInfo{
|
processInfo = &ProcessInfo{
|
||||||
ProcessId: metadata.Metadata.ProcessInfo.ProcessID,
|
ProcessId: metadata.Metadata.ProcessInfo.ProcessID,
|
||||||
UserId: metadata.Metadata.ProcessInfo.UserId,
|
UserId: metadata.Metadata.ProcessInfo.UserId,
|
||||||
UserName: metadata.Metadata.ProcessInfo.UserName,
|
UserName: metadata.Metadata.ProcessInfo.UserName,
|
||||||
ProcessPath: metadata.Metadata.ProcessInfo.ProcessPath,
|
ProcessPath: metadata.Metadata.ProcessInfo.ProcessPath,
|
||||||
PackageName: metadata.Metadata.ProcessInfo.AndroidPackageName,
|
PackageNames: metadata.Metadata.ProcessInfo.AndroidPackageNames,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
connection := &Connection{
|
return &Connection{
|
||||||
Id: metadata.ID.String(),
|
Id: metadata.ID.String(),
|
||||||
Inbound: metadata.Metadata.Inbound,
|
Inbound: metadata.Metadata.Inbound,
|
||||||
InboundType: metadata.Metadata.InboundType,
|
InboundType: metadata.Metadata.InboundType,
|
||||||
@@ -760,9 +970,6 @@ func newConnection(connections map[uuid.UUID]*Connection, metadata trafficontrol
|
|||||||
User: metadata.Metadata.User,
|
User: metadata.Metadata.User,
|
||||||
FromOutbound: metadata.Metadata.Outbound,
|
FromOutbound: metadata.Metadata.Outbound,
|
||||||
CreatedAt: metadata.CreatedAt.UnixMilli(),
|
CreatedAt: metadata.CreatedAt.UnixMilli(),
|
||||||
ClosedAt: closedAt,
|
|
||||||
Uplink: uplink,
|
|
||||||
Downlink: downlink,
|
|
||||||
UplinkTotal: uplinkTotal,
|
UplinkTotal: uplinkTotal,
|
||||||
DownlinkTotal: downlinkTotal,
|
DownlinkTotal: downlinkTotal,
|
||||||
Rule: rule,
|
Rule: rule,
|
||||||
@@ -771,8 +978,6 @@ func newConnection(connections map[uuid.UUID]*Connection, metadata trafficontrol
|
|||||||
ChainList: metadata.Chain,
|
ChainList: metadata.Chain,
|
||||||
ProcessInfo: processInfo,
|
ProcessInfo: processInfo,
|
||||||
}
|
}
|
||||||
connections[metadata.ID] = connection
|
|
||||||
return connection
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *StartedService) CloseConnection(ctx context.Context, request *CloseConnectionRequest) (*emptypb.Empty, error) {
|
func (s *StartedService) CloseConnection(ctx context.Context, request *CloseConnectionRequest) (*emptypb.Empty, error) {
|
||||||
@@ -793,7 +998,12 @@ func (s *StartedService) CloseConnection(ctx context.Context, request *CloseConn
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (s *StartedService) CloseAllConnections(ctx context.Context, empty *emptypb.Empty) (*emptypb.Empty, error) {
|
func (s *StartedService) CloseAllConnections(ctx context.Context, empty *emptypb.Empty) (*emptypb.Empty, error) {
|
||||||
conntrack.Close()
|
s.serviceAccess.RLock()
|
||||||
|
nowService := s.instance
|
||||||
|
s.serviceAccess.RUnlock()
|
||||||
|
if nowService != nil && nowService.connectionManager != nil {
|
||||||
|
nowService.connectionManager.CloseAll()
|
||||||
|
}
|
||||||
return &emptypb.Empty{}, nil
|
return &emptypb.Empty{}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -78,104 +78,55 @@ func (LogLevel) EnumDescriptor() ([]byte, []int) {
|
|||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{0}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{0}
|
||||||
}
|
}
|
||||||
|
|
||||||
type ConnectionFilter int32
|
type ConnectionEventType int32
|
||||||
|
|
||||||
const (
|
const (
|
||||||
ConnectionFilter_ALL ConnectionFilter = 0
|
ConnectionEventType_CONNECTION_EVENT_NEW ConnectionEventType = 0
|
||||||
ConnectionFilter_ACTIVE ConnectionFilter = 1
|
ConnectionEventType_CONNECTION_EVENT_UPDATE ConnectionEventType = 1
|
||||||
ConnectionFilter_CLOSED ConnectionFilter = 2
|
ConnectionEventType_CONNECTION_EVENT_CLOSED ConnectionEventType = 2
|
||||||
)
|
)
|
||||||
|
|
||||||
// Enum value maps for ConnectionFilter.
|
// Enum value maps for ConnectionEventType.
|
||||||
var (
|
var (
|
||||||
ConnectionFilter_name = map[int32]string{
|
ConnectionEventType_name = map[int32]string{
|
||||||
0: "ALL",
|
0: "CONNECTION_EVENT_NEW",
|
||||||
1: "ACTIVE",
|
1: "CONNECTION_EVENT_UPDATE",
|
||||||
2: "CLOSED",
|
2: "CONNECTION_EVENT_CLOSED",
|
||||||
}
|
}
|
||||||
ConnectionFilter_value = map[string]int32{
|
ConnectionEventType_value = map[string]int32{
|
||||||
"ALL": 0,
|
"CONNECTION_EVENT_NEW": 0,
|
||||||
"ACTIVE": 1,
|
"CONNECTION_EVENT_UPDATE": 1,
|
||||||
"CLOSED": 2,
|
"CONNECTION_EVENT_CLOSED": 2,
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
func (x ConnectionFilter) Enum() *ConnectionFilter {
|
func (x ConnectionEventType) Enum() *ConnectionEventType {
|
||||||
p := new(ConnectionFilter)
|
p := new(ConnectionEventType)
|
||||||
*p = x
|
*p = x
|
||||||
return p
|
return p
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x ConnectionFilter) String() string {
|
func (x ConnectionEventType) String() string {
|
||||||
return protoimpl.X.EnumStringOf(x.Descriptor(), protoreflect.EnumNumber(x))
|
return protoimpl.X.EnumStringOf(x.Descriptor(), protoreflect.EnumNumber(x))
|
||||||
}
|
}
|
||||||
|
|
||||||
func (ConnectionFilter) Descriptor() protoreflect.EnumDescriptor {
|
func (ConnectionEventType) Descriptor() protoreflect.EnumDescriptor {
|
||||||
return file_daemon_started_service_proto_enumTypes[1].Descriptor()
|
return file_daemon_started_service_proto_enumTypes[1].Descriptor()
|
||||||
}
|
}
|
||||||
|
|
||||||
func (ConnectionFilter) Type() protoreflect.EnumType {
|
func (ConnectionEventType) Type() protoreflect.EnumType {
|
||||||
return &file_daemon_started_service_proto_enumTypes[1]
|
return &file_daemon_started_service_proto_enumTypes[1]
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x ConnectionFilter) Number() protoreflect.EnumNumber {
|
func (x ConnectionEventType) Number() protoreflect.EnumNumber {
|
||||||
return protoreflect.EnumNumber(x)
|
return protoreflect.EnumNumber(x)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Deprecated: Use ConnectionFilter.Descriptor instead.
|
// Deprecated: Use ConnectionEventType.Descriptor instead.
|
||||||
func (ConnectionFilter) EnumDescriptor() ([]byte, []int) {
|
func (ConnectionEventType) EnumDescriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{1}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{1}
|
||||||
}
|
}
|
||||||
|
|
||||||
type ConnectionSortBy int32
|
|
||||||
|
|
||||||
const (
|
|
||||||
ConnectionSortBy_DATE ConnectionSortBy = 0
|
|
||||||
ConnectionSortBy_TRAFFIC ConnectionSortBy = 1
|
|
||||||
ConnectionSortBy_TOTAL_TRAFFIC ConnectionSortBy = 2
|
|
||||||
)
|
|
||||||
|
|
||||||
// Enum value maps for ConnectionSortBy.
|
|
||||||
var (
|
|
||||||
ConnectionSortBy_name = map[int32]string{
|
|
||||||
0: "DATE",
|
|
||||||
1: "TRAFFIC",
|
|
||||||
2: "TOTAL_TRAFFIC",
|
|
||||||
}
|
|
||||||
ConnectionSortBy_value = map[string]int32{
|
|
||||||
"DATE": 0,
|
|
||||||
"TRAFFIC": 1,
|
|
||||||
"TOTAL_TRAFFIC": 2,
|
|
||||||
}
|
|
||||||
)
|
|
||||||
|
|
||||||
func (x ConnectionSortBy) Enum() *ConnectionSortBy {
|
|
||||||
p := new(ConnectionSortBy)
|
|
||||||
*p = x
|
|
||||||
return p
|
|
||||||
}
|
|
||||||
|
|
||||||
func (x ConnectionSortBy) String() string {
|
|
||||||
return protoimpl.X.EnumStringOf(x.Descriptor(), protoreflect.EnumNumber(x))
|
|
||||||
}
|
|
||||||
|
|
||||||
func (ConnectionSortBy) Descriptor() protoreflect.EnumDescriptor {
|
|
||||||
return file_daemon_started_service_proto_enumTypes[2].Descriptor()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (ConnectionSortBy) Type() protoreflect.EnumType {
|
|
||||||
return &file_daemon_started_service_proto_enumTypes[2]
|
|
||||||
}
|
|
||||||
|
|
||||||
func (x ConnectionSortBy) Number() protoreflect.EnumNumber {
|
|
||||||
return protoreflect.EnumNumber(x)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Deprecated: Use ConnectionSortBy.Descriptor instead.
|
|
||||||
func (ConnectionSortBy) EnumDescriptor() ([]byte, []int) {
|
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{2}
|
|
||||||
}
|
|
||||||
|
|
||||||
type ServiceStatus_Type int32
|
type ServiceStatus_Type int32
|
||||||
|
|
||||||
const (
|
const (
|
||||||
@@ -215,11 +166,11 @@ func (x ServiceStatus_Type) String() string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (ServiceStatus_Type) Descriptor() protoreflect.EnumDescriptor {
|
func (ServiceStatus_Type) Descriptor() protoreflect.EnumDescriptor {
|
||||||
return file_daemon_started_service_proto_enumTypes[3].Descriptor()
|
return file_daemon_started_service_proto_enumTypes[2].Descriptor()
|
||||||
}
|
}
|
||||||
|
|
||||||
func (ServiceStatus_Type) Type() protoreflect.EnumType {
|
func (ServiceStatus_Type) Type() protoreflect.EnumType {
|
||||||
return &file_daemon_started_service_proto_enumTypes[3]
|
return &file_daemon_started_service_proto_enumTypes[2]
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x ServiceStatus_Type) Number() protoreflect.EnumNumber {
|
func (x ServiceStatus_Type) Number() protoreflect.EnumNumber {
|
||||||
@@ -1114,8 +1065,6 @@ func (x *SetSystemProxyEnabledRequest) GetEnabled() bool {
|
|||||||
type SubscribeConnectionsRequest struct {
|
type SubscribeConnectionsRequest struct {
|
||||||
state protoimpl.MessageState `protogen:"open.v1"`
|
state protoimpl.MessageState `protogen:"open.v1"`
|
||||||
Interval int64 `protobuf:"varint,1,opt,name=interval,proto3" json:"interval,omitempty"`
|
Interval int64 `protobuf:"varint,1,opt,name=interval,proto3" json:"interval,omitempty"`
|
||||||
Filter ConnectionFilter `protobuf:"varint,2,opt,name=filter,proto3,enum=daemon.ConnectionFilter" json:"filter,omitempty"`
|
|
||||||
SortBy ConnectionSortBy `protobuf:"varint,3,opt,name=sortBy,proto3,enum=daemon.ConnectionSortBy" json:"sortBy,omitempty"`
|
|
||||||
unknownFields protoimpl.UnknownFields
|
unknownFields protoimpl.UnknownFields
|
||||||
sizeCache protoimpl.SizeCache
|
sizeCache protoimpl.SizeCache
|
||||||
}
|
}
|
||||||
@@ -1157,41 +1106,32 @@ func (x *SubscribeConnectionsRequest) GetInterval() int64 {
|
|||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *SubscribeConnectionsRequest) GetFilter() ConnectionFilter {
|
type ConnectionEvent struct {
|
||||||
if x != nil {
|
|
||||||
return x.Filter
|
|
||||||
}
|
|
||||||
return ConnectionFilter_ALL
|
|
||||||
}
|
|
||||||
|
|
||||||
func (x *SubscribeConnectionsRequest) GetSortBy() ConnectionSortBy {
|
|
||||||
if x != nil {
|
|
||||||
return x.SortBy
|
|
||||||
}
|
|
||||||
return ConnectionSortBy_DATE
|
|
||||||
}
|
|
||||||
|
|
||||||
type Connections struct {
|
|
||||||
state protoimpl.MessageState `protogen:"open.v1"`
|
state protoimpl.MessageState `protogen:"open.v1"`
|
||||||
Connections []*Connection `protobuf:"bytes,1,rep,name=connections,proto3" json:"connections,omitempty"`
|
Type ConnectionEventType `protobuf:"varint,1,opt,name=type,proto3,enum=daemon.ConnectionEventType" json:"type,omitempty"`
|
||||||
|
Id string `protobuf:"bytes,2,opt,name=id,proto3" json:"id,omitempty"`
|
||||||
|
Connection *Connection `protobuf:"bytes,3,opt,name=connection,proto3" json:"connection,omitempty"`
|
||||||
|
UplinkDelta int64 `protobuf:"varint,4,opt,name=uplinkDelta,proto3" json:"uplinkDelta,omitempty"`
|
||||||
|
DownlinkDelta int64 `protobuf:"varint,5,opt,name=downlinkDelta,proto3" json:"downlinkDelta,omitempty"`
|
||||||
|
ClosedAt int64 `protobuf:"varint,6,opt,name=closedAt,proto3" json:"closedAt,omitempty"`
|
||||||
unknownFields protoimpl.UnknownFields
|
unknownFields protoimpl.UnknownFields
|
||||||
sizeCache protoimpl.SizeCache
|
sizeCache protoimpl.SizeCache
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *Connections) Reset() {
|
func (x *ConnectionEvent) Reset() {
|
||||||
*x = Connections{}
|
*x = ConnectionEvent{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[17]
|
mi := &file_daemon_started_service_proto_msgTypes[17]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *Connections) String() string {
|
func (x *ConnectionEvent) String() string {
|
||||||
return protoimpl.X.MessageStringOf(x)
|
return protoimpl.X.MessageStringOf(x)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (*Connections) ProtoMessage() {}
|
func (*ConnectionEvent) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *Connections) ProtoReflect() protoreflect.Message {
|
func (x *ConnectionEvent) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[17]
|
mi := &file_daemon_started_service_proto_msgTypes[17]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
@@ -1203,18 +1143,105 @@ func (x *Connections) ProtoReflect() protoreflect.Message {
|
|||||||
return mi.MessageOf(x)
|
return mi.MessageOf(x)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Deprecated: Use Connections.ProtoReflect.Descriptor instead.
|
// Deprecated: Use ConnectionEvent.ProtoReflect.Descriptor instead.
|
||||||
func (*Connections) Descriptor() ([]byte, []int) {
|
func (*ConnectionEvent) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{17}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{17}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *Connections) GetConnections() []*Connection {
|
func (x *ConnectionEvent) GetType() ConnectionEventType {
|
||||||
if x != nil {
|
if x != nil {
|
||||||
return x.Connections
|
return x.Type
|
||||||
|
}
|
||||||
|
return ConnectionEventType_CONNECTION_EVENT_NEW
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvent) GetId() string {
|
||||||
|
if x != nil {
|
||||||
|
return x.Id
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvent) GetConnection() *Connection {
|
||||||
|
if x != nil {
|
||||||
|
return x.Connection
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvent) GetUplinkDelta() int64 {
|
||||||
|
if x != nil {
|
||||||
|
return x.UplinkDelta
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvent) GetDownlinkDelta() int64 {
|
||||||
|
if x != nil {
|
||||||
|
return x.DownlinkDelta
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvent) GetClosedAt() int64 {
|
||||||
|
if x != nil {
|
||||||
|
return x.ClosedAt
|
||||||
|
}
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
type ConnectionEvents struct {
|
||||||
|
state protoimpl.MessageState `protogen:"open.v1"`
|
||||||
|
Events []*ConnectionEvent `protobuf:"bytes,1,rep,name=events,proto3" json:"events,omitempty"`
|
||||||
|
Reset_ bool `protobuf:"varint,2,opt,name=reset,proto3" json:"reset,omitempty"`
|
||||||
|
unknownFields protoimpl.UnknownFields
|
||||||
|
sizeCache protoimpl.SizeCache
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvents) Reset() {
|
||||||
|
*x = ConnectionEvents{}
|
||||||
|
mi := &file_daemon_started_service_proto_msgTypes[18]
|
||||||
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
|
ms.StoreMessageInfo(mi)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvents) String() string {
|
||||||
|
return protoimpl.X.MessageStringOf(x)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (*ConnectionEvents) ProtoMessage() {}
|
||||||
|
|
||||||
|
func (x *ConnectionEvents) ProtoReflect() protoreflect.Message {
|
||||||
|
mi := &file_daemon_started_service_proto_msgTypes[18]
|
||||||
|
if x != nil {
|
||||||
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
|
if ms.LoadMessageInfo() == nil {
|
||||||
|
ms.StoreMessageInfo(mi)
|
||||||
|
}
|
||||||
|
return ms
|
||||||
|
}
|
||||||
|
return mi.MessageOf(x)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Deprecated: Use ConnectionEvents.ProtoReflect.Descriptor instead.
|
||||||
|
func (*ConnectionEvents) Descriptor() ([]byte, []int) {
|
||||||
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{18}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvents) GetEvents() []*ConnectionEvent {
|
||||||
|
if x != nil {
|
||||||
|
return x.Events
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (x *ConnectionEvents) GetReset_() bool {
|
||||||
|
if x != nil {
|
||||||
|
return x.Reset_
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
type Connection struct {
|
type Connection struct {
|
||||||
state protoimpl.MessageState `protogen:"open.v1"`
|
state protoimpl.MessageState `protogen:"open.v1"`
|
||||||
Id string `protobuf:"bytes,1,opt,name=id,proto3" json:"id,omitempty"`
|
Id string `protobuf:"bytes,1,opt,name=id,proto3" json:"id,omitempty"`
|
||||||
@@ -1245,7 +1272,7 @@ type Connection struct {
|
|||||||
|
|
||||||
func (x *Connection) Reset() {
|
func (x *Connection) Reset() {
|
||||||
*x = Connection{}
|
*x = Connection{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[18]
|
mi := &file_daemon_started_service_proto_msgTypes[19]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1257,7 +1284,7 @@ func (x *Connection) String() string {
|
|||||||
func (*Connection) ProtoMessage() {}
|
func (*Connection) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *Connection) ProtoReflect() protoreflect.Message {
|
func (x *Connection) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[18]
|
mi := &file_daemon_started_service_proto_msgTypes[19]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1270,7 +1297,7 @@ func (x *Connection) ProtoReflect() protoreflect.Message {
|
|||||||
|
|
||||||
// Deprecated: Use Connection.ProtoReflect.Descriptor instead.
|
// Deprecated: Use Connection.ProtoReflect.Descriptor instead.
|
||||||
func (*Connection) Descriptor() ([]byte, []int) {
|
func (*Connection) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{18}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{19}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *Connection) GetId() string {
|
func (x *Connection) GetId() string {
|
||||||
@@ -1433,14 +1460,14 @@ type ProcessInfo struct {
|
|||||||
UserId int32 `protobuf:"varint,2,opt,name=userId,proto3" json:"userId,omitempty"`
|
UserId int32 `protobuf:"varint,2,opt,name=userId,proto3" json:"userId,omitempty"`
|
||||||
UserName string `protobuf:"bytes,3,opt,name=userName,proto3" json:"userName,omitempty"`
|
UserName string `protobuf:"bytes,3,opt,name=userName,proto3" json:"userName,omitempty"`
|
||||||
ProcessPath string `protobuf:"bytes,4,opt,name=processPath,proto3" json:"processPath,omitempty"`
|
ProcessPath string `protobuf:"bytes,4,opt,name=processPath,proto3" json:"processPath,omitempty"`
|
||||||
PackageName string `protobuf:"bytes,5,opt,name=packageName,proto3" json:"packageName,omitempty"`
|
PackageNames []string `protobuf:"bytes,5,rep,name=packageNames,proto3" json:"packageNames,omitempty"`
|
||||||
unknownFields protoimpl.UnknownFields
|
unknownFields protoimpl.UnknownFields
|
||||||
sizeCache protoimpl.SizeCache
|
sizeCache protoimpl.SizeCache
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *ProcessInfo) Reset() {
|
func (x *ProcessInfo) Reset() {
|
||||||
*x = ProcessInfo{}
|
*x = ProcessInfo{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[19]
|
mi := &file_daemon_started_service_proto_msgTypes[20]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1452,7 +1479,7 @@ func (x *ProcessInfo) String() string {
|
|||||||
func (*ProcessInfo) ProtoMessage() {}
|
func (*ProcessInfo) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *ProcessInfo) ProtoReflect() protoreflect.Message {
|
func (x *ProcessInfo) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[19]
|
mi := &file_daemon_started_service_proto_msgTypes[20]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1465,7 +1492,7 @@ func (x *ProcessInfo) ProtoReflect() protoreflect.Message {
|
|||||||
|
|
||||||
// Deprecated: Use ProcessInfo.ProtoReflect.Descriptor instead.
|
// Deprecated: Use ProcessInfo.ProtoReflect.Descriptor instead.
|
||||||
func (*ProcessInfo) Descriptor() ([]byte, []int) {
|
func (*ProcessInfo) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{19}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{20}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *ProcessInfo) GetProcessId() uint32 {
|
func (x *ProcessInfo) GetProcessId() uint32 {
|
||||||
@@ -1496,11 +1523,11 @@ func (x *ProcessInfo) GetProcessPath() string {
|
|||||||
return ""
|
return ""
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *ProcessInfo) GetPackageName() string {
|
func (x *ProcessInfo) GetPackageNames() []string {
|
||||||
if x != nil {
|
if x != nil {
|
||||||
return x.PackageName
|
return x.PackageNames
|
||||||
}
|
}
|
||||||
return ""
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
type CloseConnectionRequest struct {
|
type CloseConnectionRequest struct {
|
||||||
@@ -1512,7 +1539,7 @@ type CloseConnectionRequest struct {
|
|||||||
|
|
||||||
func (x *CloseConnectionRequest) Reset() {
|
func (x *CloseConnectionRequest) Reset() {
|
||||||
*x = CloseConnectionRequest{}
|
*x = CloseConnectionRequest{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[20]
|
mi := &file_daemon_started_service_proto_msgTypes[21]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1524,7 +1551,7 @@ func (x *CloseConnectionRequest) String() string {
|
|||||||
func (*CloseConnectionRequest) ProtoMessage() {}
|
func (*CloseConnectionRequest) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *CloseConnectionRequest) ProtoReflect() protoreflect.Message {
|
func (x *CloseConnectionRequest) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[20]
|
mi := &file_daemon_started_service_proto_msgTypes[21]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1537,7 +1564,7 @@ func (x *CloseConnectionRequest) ProtoReflect() protoreflect.Message {
|
|||||||
|
|
||||||
// Deprecated: Use CloseConnectionRequest.ProtoReflect.Descriptor instead.
|
// Deprecated: Use CloseConnectionRequest.ProtoReflect.Descriptor instead.
|
||||||
func (*CloseConnectionRequest) Descriptor() ([]byte, []int) {
|
func (*CloseConnectionRequest) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{20}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{21}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *CloseConnectionRequest) GetId() string {
|
func (x *CloseConnectionRequest) GetId() string {
|
||||||
@@ -1556,7 +1583,7 @@ type DeprecatedWarnings struct {
|
|||||||
|
|
||||||
func (x *DeprecatedWarnings) Reset() {
|
func (x *DeprecatedWarnings) Reset() {
|
||||||
*x = DeprecatedWarnings{}
|
*x = DeprecatedWarnings{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[21]
|
mi := &file_daemon_started_service_proto_msgTypes[22]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1568,7 +1595,7 @@ func (x *DeprecatedWarnings) String() string {
|
|||||||
func (*DeprecatedWarnings) ProtoMessage() {}
|
func (*DeprecatedWarnings) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *DeprecatedWarnings) ProtoReflect() protoreflect.Message {
|
func (x *DeprecatedWarnings) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[21]
|
mi := &file_daemon_started_service_proto_msgTypes[22]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1581,7 +1608,7 @@ func (x *DeprecatedWarnings) ProtoReflect() protoreflect.Message {
|
|||||||
|
|
||||||
// Deprecated: Use DeprecatedWarnings.ProtoReflect.Descriptor instead.
|
// Deprecated: Use DeprecatedWarnings.ProtoReflect.Descriptor instead.
|
||||||
func (*DeprecatedWarnings) Descriptor() ([]byte, []int) {
|
func (*DeprecatedWarnings) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{21}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{22}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *DeprecatedWarnings) GetWarnings() []*DeprecatedWarning {
|
func (x *DeprecatedWarnings) GetWarnings() []*DeprecatedWarning {
|
||||||
@@ -1602,7 +1629,7 @@ type DeprecatedWarning struct {
|
|||||||
|
|
||||||
func (x *DeprecatedWarning) Reset() {
|
func (x *DeprecatedWarning) Reset() {
|
||||||
*x = DeprecatedWarning{}
|
*x = DeprecatedWarning{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[22]
|
mi := &file_daemon_started_service_proto_msgTypes[23]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1614,7 +1641,7 @@ func (x *DeprecatedWarning) String() string {
|
|||||||
func (*DeprecatedWarning) ProtoMessage() {}
|
func (*DeprecatedWarning) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *DeprecatedWarning) ProtoReflect() protoreflect.Message {
|
func (x *DeprecatedWarning) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[22]
|
mi := &file_daemon_started_service_proto_msgTypes[23]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1627,7 +1654,7 @@ func (x *DeprecatedWarning) ProtoReflect() protoreflect.Message {
|
|||||||
|
|
||||||
// Deprecated: Use DeprecatedWarning.ProtoReflect.Descriptor instead.
|
// Deprecated: Use DeprecatedWarning.ProtoReflect.Descriptor instead.
|
||||||
func (*DeprecatedWarning) Descriptor() ([]byte, []int) {
|
func (*DeprecatedWarning) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{22}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{23}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *DeprecatedWarning) GetMessage() string {
|
func (x *DeprecatedWarning) GetMessage() string {
|
||||||
@@ -1660,7 +1687,7 @@ type StartedAt struct {
|
|||||||
|
|
||||||
func (x *StartedAt) Reset() {
|
func (x *StartedAt) Reset() {
|
||||||
*x = StartedAt{}
|
*x = StartedAt{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[23]
|
mi := &file_daemon_started_service_proto_msgTypes[24]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1672,7 +1699,7 @@ func (x *StartedAt) String() string {
|
|||||||
func (*StartedAt) ProtoMessage() {}
|
func (*StartedAt) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *StartedAt) ProtoReflect() protoreflect.Message {
|
func (x *StartedAt) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[23]
|
mi := &file_daemon_started_service_proto_msgTypes[24]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1685,7 +1712,7 @@ func (x *StartedAt) ProtoReflect() protoreflect.Message {
|
|||||||
|
|
||||||
// Deprecated: Use StartedAt.ProtoReflect.Descriptor instead.
|
// Deprecated: Use StartedAt.ProtoReflect.Descriptor instead.
|
||||||
func (*StartedAt) Descriptor() ([]byte, []int) {
|
func (*StartedAt) Descriptor() ([]byte, []int) {
|
||||||
return file_daemon_started_service_proto_rawDescGZIP(), []int{23}
|
return file_daemon_started_service_proto_rawDescGZIP(), []int{24}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (x *StartedAt) GetStartedAt() int64 {
|
func (x *StartedAt) GetStartedAt() int64 {
|
||||||
@@ -1705,7 +1732,7 @@ type Log_Message struct {
|
|||||||
|
|
||||||
func (x *Log_Message) Reset() {
|
func (x *Log_Message) Reset() {
|
||||||
*x = Log_Message{}
|
*x = Log_Message{}
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[24]
|
mi := &file_daemon_started_service_proto_msgTypes[25]
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
ms.StoreMessageInfo(mi)
|
ms.StoreMessageInfo(mi)
|
||||||
}
|
}
|
||||||
@@ -1717,7 +1744,7 @@ func (x *Log_Message) String() string {
|
|||||||
func (*Log_Message) ProtoMessage() {}
|
func (*Log_Message) ProtoMessage() {}
|
||||||
|
|
||||||
func (x *Log_Message) ProtoReflect() protoreflect.Message {
|
func (x *Log_Message) ProtoReflect() protoreflect.Message {
|
||||||
mi := &file_daemon_started_service_proto_msgTypes[24]
|
mi := &file_daemon_started_service_proto_msgTypes[25]
|
||||||
if x != nil {
|
if x != nil {
|
||||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||||
if ms.LoadMessageInfo() == nil {
|
if ms.LoadMessageInfo() == nil {
|
||||||
@@ -1818,13 +1845,21 @@ const file_daemon_started_service_proto_rawDesc = "" +
|
|||||||
"\tavailable\x18\x01 \x01(\bR\tavailable\x12\x18\n" +
|
"\tavailable\x18\x01 \x01(\bR\tavailable\x12\x18\n" +
|
||||||
"\aenabled\x18\x02 \x01(\bR\aenabled\"8\n" +
|
"\aenabled\x18\x02 \x01(\bR\aenabled\"8\n" +
|
||||||
"\x1cSetSystemProxyEnabledRequest\x12\x18\n" +
|
"\x1cSetSystemProxyEnabledRequest\x12\x18\n" +
|
||||||
"\aenabled\x18\x01 \x01(\bR\aenabled\"\x9d\x01\n" +
|
"\aenabled\x18\x01 \x01(\bR\aenabled\"9\n" +
|
||||||
"\x1bSubscribeConnectionsRequest\x12\x1a\n" +
|
"\x1bSubscribeConnectionsRequest\x12\x1a\n" +
|
||||||
"\binterval\x18\x01 \x01(\x03R\binterval\x120\n" +
|
"\binterval\x18\x01 \x01(\x03R\binterval\"\xea\x01\n" +
|
||||||
"\x06filter\x18\x02 \x01(\x0e2\x18.daemon.ConnectionFilterR\x06filter\x120\n" +
|
"\x0fConnectionEvent\x12/\n" +
|
||||||
"\x06sortBy\x18\x03 \x01(\x0e2\x18.daemon.ConnectionSortByR\x06sortBy\"C\n" +
|
"\x04type\x18\x01 \x01(\x0e2\x1b.daemon.ConnectionEventTypeR\x04type\x12\x0e\n" +
|
||||||
"\vConnections\x124\n" +
|
"\x02id\x18\x02 \x01(\tR\x02id\x122\n" +
|
||||||
"\vconnections\x18\x01 \x03(\v2\x12.daemon.ConnectionR\vconnections\"\x95\x05\n" +
|
"\n" +
|
||||||
|
"connection\x18\x03 \x01(\v2\x12.daemon.ConnectionR\n" +
|
||||||
|
"connection\x12 \n" +
|
||||||
|
"\vuplinkDelta\x18\x04 \x01(\x03R\vuplinkDelta\x12$\n" +
|
||||||
|
"\rdownlinkDelta\x18\x05 \x01(\x03R\rdownlinkDelta\x12\x1a\n" +
|
||||||
|
"\bclosedAt\x18\x06 \x01(\x03R\bclosedAt\"Y\n" +
|
||||||
|
"\x10ConnectionEvents\x12/\n" +
|
||||||
|
"\x06events\x18\x01 \x03(\v2\x17.daemon.ConnectionEventR\x06events\x12\x14\n" +
|
||||||
|
"\x05reset\x18\x02 \x01(\bR\x05reset\"\x95\x05\n" +
|
||||||
"\n" +
|
"\n" +
|
||||||
"Connection\x12\x0e\n" +
|
"Connection\x12\x0e\n" +
|
||||||
"\x02id\x18\x01 \x01(\tR\x02id\x12\x18\n" +
|
"\x02id\x18\x01 \x01(\tR\x02id\x12\x18\n" +
|
||||||
@@ -1849,13 +1884,13 @@ const file_daemon_started_service_proto_rawDesc = "" +
|
|||||||
"\boutbound\x18\x13 \x01(\tR\boutbound\x12\"\n" +
|
"\boutbound\x18\x13 \x01(\tR\boutbound\x12\"\n" +
|
||||||
"\foutboundType\x18\x14 \x01(\tR\foutboundType\x12\x1c\n" +
|
"\foutboundType\x18\x14 \x01(\tR\foutboundType\x12\x1c\n" +
|
||||||
"\tchainList\x18\x15 \x03(\tR\tchainList\x125\n" +
|
"\tchainList\x18\x15 \x03(\tR\tchainList\x125\n" +
|
||||||
"\vprocessInfo\x18\x16 \x01(\v2\x13.daemon.ProcessInfoR\vprocessInfo\"\xa3\x01\n" +
|
"\vprocessInfo\x18\x16 \x01(\v2\x13.daemon.ProcessInfoR\vprocessInfo\"\xa5\x01\n" +
|
||||||
"\vProcessInfo\x12\x1c\n" +
|
"\vProcessInfo\x12\x1c\n" +
|
||||||
"\tprocessId\x18\x01 \x01(\rR\tprocessId\x12\x16\n" +
|
"\tprocessId\x18\x01 \x01(\rR\tprocessId\x12\x16\n" +
|
||||||
"\x06userId\x18\x02 \x01(\x05R\x06userId\x12\x1a\n" +
|
"\x06userId\x18\x02 \x01(\x05R\x06userId\x12\x1a\n" +
|
||||||
"\buserName\x18\x03 \x01(\tR\buserName\x12 \n" +
|
"\buserName\x18\x03 \x01(\tR\buserName\x12 \n" +
|
||||||
"\vprocessPath\x18\x04 \x01(\tR\vprocessPath\x12 \n" +
|
"\vprocessPath\x18\x04 \x01(\tR\vprocessPath\x12\"\n" +
|
||||||
"\vpackageName\x18\x05 \x01(\tR\vpackageName\"(\n" +
|
"\fpackageNames\x18\x05 \x03(\tR\fpackageNames\"(\n" +
|
||||||
"\x16CloseConnectionRequest\x12\x0e\n" +
|
"\x16CloseConnectionRequest\x12\x0e\n" +
|
||||||
"\x02id\x18\x01 \x01(\tR\x02id\"K\n" +
|
"\x02id\x18\x01 \x01(\tR\x02id\"K\n" +
|
||||||
"\x12DeprecatedWarnings\x125\n" +
|
"\x12DeprecatedWarnings\x125\n" +
|
||||||
@@ -1873,17 +1908,11 @@ const file_daemon_started_service_proto_rawDesc = "" +
|
|||||||
"\x04WARN\x10\x03\x12\b\n" +
|
"\x04WARN\x10\x03\x12\b\n" +
|
||||||
"\x04INFO\x10\x04\x12\t\n" +
|
"\x04INFO\x10\x04\x12\t\n" +
|
||||||
"\x05DEBUG\x10\x05\x12\t\n" +
|
"\x05DEBUG\x10\x05\x12\t\n" +
|
||||||
"\x05TRACE\x10\x06*3\n" +
|
"\x05TRACE\x10\x06*i\n" +
|
||||||
"\x10ConnectionFilter\x12\a\n" +
|
"\x13ConnectionEventType\x12\x18\n" +
|
||||||
"\x03ALL\x10\x00\x12\n" +
|
"\x14CONNECTION_EVENT_NEW\x10\x00\x12\x1b\n" +
|
||||||
"\n" +
|
"\x17CONNECTION_EVENT_UPDATE\x10\x01\x12\x1b\n" +
|
||||||
"\x06ACTIVE\x10\x01\x12\n" +
|
"\x17CONNECTION_EVENT_CLOSED\x10\x022\xe5\v\n" +
|
||||||
"\n" +
|
|
||||||
"\x06CLOSED\x10\x02*<\n" +
|
|
||||||
"\x10ConnectionSortBy\x12\b\n" +
|
|
||||||
"\x04DATE\x10\x00\x12\v\n" +
|
|
||||||
"\aTRAFFIC\x10\x01\x12\x11\n" +
|
|
||||||
"\rTOTAL_TRAFFIC\x10\x022\xe0\v\n" +
|
|
||||||
"\x0eStartedService\x12=\n" +
|
"\x0eStartedService\x12=\n" +
|
||||||
"\vStopService\x12\x16.google.protobuf.Empty\x1a\x16.google.protobuf.Empty\x12?\n" +
|
"\vStopService\x12\x16.google.protobuf.Empty\x1a\x16.google.protobuf.Empty\x12?\n" +
|
||||||
"\rReloadService\x12\x16.google.protobuf.Empty\x1a\x16.google.protobuf.Empty\x12K\n" +
|
"\rReloadService\x12\x16.google.protobuf.Empty\x1a\x16.google.protobuf.Empty\x12K\n" +
|
||||||
@@ -1900,8 +1929,8 @@ const file_daemon_started_service_proto_rawDesc = "" +
|
|||||||
"\x0eSelectOutbound\x12\x1d.daemon.SelectOutboundRequest\x1a\x16.google.protobuf.Empty\"\x00\x12I\n" +
|
"\x0eSelectOutbound\x12\x1d.daemon.SelectOutboundRequest\x1a\x16.google.protobuf.Empty\"\x00\x12I\n" +
|
||||||
"\x0eSetGroupExpand\x12\x1d.daemon.SetGroupExpandRequest\x1a\x16.google.protobuf.Empty\"\x00\x12K\n" +
|
"\x0eSetGroupExpand\x12\x1d.daemon.SetGroupExpandRequest\x1a\x16.google.protobuf.Empty\"\x00\x12K\n" +
|
||||||
"\x14GetSystemProxyStatus\x12\x16.google.protobuf.Empty\x1a\x19.daemon.SystemProxyStatus\"\x00\x12W\n" +
|
"\x14GetSystemProxyStatus\x12\x16.google.protobuf.Empty\x1a\x19.daemon.SystemProxyStatus\"\x00\x12W\n" +
|
||||||
"\x15SetSystemProxyEnabled\x12$.daemon.SetSystemProxyEnabledRequest\x1a\x16.google.protobuf.Empty\"\x00\x12T\n" +
|
"\x15SetSystemProxyEnabled\x12$.daemon.SetSystemProxyEnabledRequest\x1a\x16.google.protobuf.Empty\"\x00\x12Y\n" +
|
||||||
"\x14SubscribeConnections\x12#.daemon.SubscribeConnectionsRequest\x1a\x13.daemon.Connections\"\x000\x01\x12K\n" +
|
"\x14SubscribeConnections\x12#.daemon.SubscribeConnectionsRequest\x1a\x18.daemon.ConnectionEvents\"\x000\x01\x12K\n" +
|
||||||
"\x0fCloseConnection\x12\x1e.daemon.CloseConnectionRequest\x1a\x16.google.protobuf.Empty\"\x00\x12G\n" +
|
"\x0fCloseConnection\x12\x1e.daemon.CloseConnectionRequest\x1a\x16.google.protobuf.Empty\"\x00\x12G\n" +
|
||||||
"\x13CloseAllConnections\x12\x16.google.protobuf.Empty\x1a\x16.google.protobuf.Empty\"\x00\x12M\n" +
|
"\x13CloseAllConnections\x12\x16.google.protobuf.Empty\x1a\x16.google.protobuf.Empty\"\x00\x12M\n" +
|
||||||
"\x15GetDeprecatedWarnings\x12\x16.google.protobuf.Empty\x1a\x1a.daemon.DeprecatedWarnings\"\x00\x12;\n" +
|
"\x15GetDeprecatedWarnings\x12\x16.google.protobuf.Empty\x1a\x1a.daemon.DeprecatedWarnings\"\x00\x12;\n" +
|
||||||
@@ -1920,31 +1949,31 @@ func file_daemon_started_service_proto_rawDescGZIP() []byte {
|
|||||||
}
|
}
|
||||||
|
|
||||||
var (
|
var (
|
||||||
file_daemon_started_service_proto_enumTypes = make([]protoimpl.EnumInfo, 4)
|
file_daemon_started_service_proto_enumTypes = make([]protoimpl.EnumInfo, 3)
|
||||||
file_daemon_started_service_proto_msgTypes = make([]protoimpl.MessageInfo, 25)
|
file_daemon_started_service_proto_msgTypes = make([]protoimpl.MessageInfo, 26)
|
||||||
file_daemon_started_service_proto_goTypes = []any{
|
file_daemon_started_service_proto_goTypes = []any{
|
||||||
(LogLevel)(0), // 0: daemon.LogLevel
|
(LogLevel)(0), // 0: daemon.LogLevel
|
||||||
(ConnectionFilter)(0), // 1: daemon.ConnectionFilter
|
(ConnectionEventType)(0), // 1: daemon.ConnectionEventType
|
||||||
(ConnectionSortBy)(0), // 2: daemon.ConnectionSortBy
|
(ServiceStatus_Type)(0), // 2: daemon.ServiceStatus.Type
|
||||||
(ServiceStatus_Type)(0), // 3: daemon.ServiceStatus.Type
|
(*ServiceStatus)(nil), // 3: daemon.ServiceStatus
|
||||||
(*ServiceStatus)(nil), // 4: daemon.ServiceStatus
|
(*ReloadServiceRequest)(nil), // 4: daemon.ReloadServiceRequest
|
||||||
(*ReloadServiceRequest)(nil), // 5: daemon.ReloadServiceRequest
|
(*SubscribeStatusRequest)(nil), // 5: daemon.SubscribeStatusRequest
|
||||||
(*SubscribeStatusRequest)(nil), // 6: daemon.SubscribeStatusRequest
|
(*Log)(nil), // 6: daemon.Log
|
||||||
(*Log)(nil), // 7: daemon.Log
|
(*DefaultLogLevel)(nil), // 7: daemon.DefaultLogLevel
|
||||||
(*DefaultLogLevel)(nil), // 8: daemon.DefaultLogLevel
|
(*Status)(nil), // 8: daemon.Status
|
||||||
(*Status)(nil), // 9: daemon.Status
|
(*Groups)(nil), // 9: daemon.Groups
|
||||||
(*Groups)(nil), // 10: daemon.Groups
|
(*Group)(nil), // 10: daemon.Group
|
||||||
(*Group)(nil), // 11: daemon.Group
|
(*GroupItem)(nil), // 11: daemon.GroupItem
|
||||||
(*GroupItem)(nil), // 12: daemon.GroupItem
|
(*URLTestRequest)(nil), // 12: daemon.URLTestRequest
|
||||||
(*URLTestRequest)(nil), // 13: daemon.URLTestRequest
|
(*SelectOutboundRequest)(nil), // 13: daemon.SelectOutboundRequest
|
||||||
(*SelectOutboundRequest)(nil), // 14: daemon.SelectOutboundRequest
|
(*SetGroupExpandRequest)(nil), // 14: daemon.SetGroupExpandRequest
|
||||||
(*SetGroupExpandRequest)(nil), // 15: daemon.SetGroupExpandRequest
|
(*ClashMode)(nil), // 15: daemon.ClashMode
|
||||||
(*ClashMode)(nil), // 16: daemon.ClashMode
|
(*ClashModeStatus)(nil), // 16: daemon.ClashModeStatus
|
||||||
(*ClashModeStatus)(nil), // 17: daemon.ClashModeStatus
|
(*SystemProxyStatus)(nil), // 17: daemon.SystemProxyStatus
|
||||||
(*SystemProxyStatus)(nil), // 18: daemon.SystemProxyStatus
|
(*SetSystemProxyEnabledRequest)(nil), // 18: daemon.SetSystemProxyEnabledRequest
|
||||||
(*SetSystemProxyEnabledRequest)(nil), // 19: daemon.SetSystemProxyEnabledRequest
|
(*SubscribeConnectionsRequest)(nil), // 19: daemon.SubscribeConnectionsRequest
|
||||||
(*SubscribeConnectionsRequest)(nil), // 20: daemon.SubscribeConnectionsRequest
|
(*ConnectionEvent)(nil), // 20: daemon.ConnectionEvent
|
||||||
(*Connections)(nil), // 21: daemon.Connections
|
(*ConnectionEvents)(nil), // 21: daemon.ConnectionEvents
|
||||||
(*Connection)(nil), // 22: daemon.Connection
|
(*Connection)(nil), // 22: daemon.Connection
|
||||||
(*ProcessInfo)(nil), // 23: daemon.ProcessInfo
|
(*ProcessInfo)(nil), // 23: daemon.ProcessInfo
|
||||||
(*CloseConnectionRequest)(nil), // 24: daemon.CloseConnectionRequest
|
(*CloseConnectionRequest)(nil), // 24: daemon.CloseConnectionRequest
|
||||||
@@ -1957,14 +1986,14 @@ var (
|
|||||||
)
|
)
|
||||||
|
|
||||||
var file_daemon_started_service_proto_depIdxs = []int32{
|
var file_daemon_started_service_proto_depIdxs = []int32{
|
||||||
3, // 0: daemon.ServiceStatus.status:type_name -> daemon.ServiceStatus.Type
|
2, // 0: daemon.ServiceStatus.status:type_name -> daemon.ServiceStatus.Type
|
||||||
28, // 1: daemon.Log.messages:type_name -> daemon.Log.Message
|
28, // 1: daemon.Log.messages:type_name -> daemon.Log.Message
|
||||||
0, // 2: daemon.DefaultLogLevel.level:type_name -> daemon.LogLevel
|
0, // 2: daemon.DefaultLogLevel.level:type_name -> daemon.LogLevel
|
||||||
11, // 3: daemon.Groups.group:type_name -> daemon.Group
|
10, // 3: daemon.Groups.group:type_name -> daemon.Group
|
||||||
12, // 4: daemon.Group.items:type_name -> daemon.GroupItem
|
11, // 4: daemon.Group.items:type_name -> daemon.GroupItem
|
||||||
1, // 5: daemon.SubscribeConnectionsRequest.filter:type_name -> daemon.ConnectionFilter
|
1, // 5: daemon.ConnectionEvent.type:type_name -> daemon.ConnectionEventType
|
||||||
2, // 6: daemon.SubscribeConnectionsRequest.sortBy:type_name -> daemon.ConnectionSortBy
|
22, // 6: daemon.ConnectionEvent.connection:type_name -> daemon.Connection
|
||||||
22, // 7: daemon.Connections.connections:type_name -> daemon.Connection
|
20, // 7: daemon.ConnectionEvents.events:type_name -> daemon.ConnectionEvent
|
||||||
23, // 8: daemon.Connection.processInfo:type_name -> daemon.ProcessInfo
|
23, // 8: daemon.Connection.processInfo:type_name -> daemon.ProcessInfo
|
||||||
26, // 9: daemon.DeprecatedWarnings.warnings:type_name -> daemon.DeprecatedWarning
|
26, // 9: daemon.DeprecatedWarnings.warnings:type_name -> daemon.DeprecatedWarning
|
||||||
0, // 10: daemon.Log.Message.level:type_name -> daemon.LogLevel
|
0, // 10: daemon.Log.Message.level:type_name -> daemon.LogLevel
|
||||||
@@ -1974,38 +2003,38 @@ var file_daemon_started_service_proto_depIdxs = []int32{
|
|||||||
29, // 14: daemon.StartedService.SubscribeLog:input_type -> google.protobuf.Empty
|
29, // 14: daemon.StartedService.SubscribeLog:input_type -> google.protobuf.Empty
|
||||||
29, // 15: daemon.StartedService.GetDefaultLogLevel:input_type -> google.protobuf.Empty
|
29, // 15: daemon.StartedService.GetDefaultLogLevel:input_type -> google.protobuf.Empty
|
||||||
29, // 16: daemon.StartedService.ClearLogs:input_type -> google.protobuf.Empty
|
29, // 16: daemon.StartedService.ClearLogs:input_type -> google.protobuf.Empty
|
||||||
6, // 17: daemon.StartedService.SubscribeStatus:input_type -> daemon.SubscribeStatusRequest
|
5, // 17: daemon.StartedService.SubscribeStatus:input_type -> daemon.SubscribeStatusRequest
|
||||||
29, // 18: daemon.StartedService.SubscribeGroups:input_type -> google.protobuf.Empty
|
29, // 18: daemon.StartedService.SubscribeGroups:input_type -> google.protobuf.Empty
|
||||||
29, // 19: daemon.StartedService.GetClashModeStatus:input_type -> google.protobuf.Empty
|
29, // 19: daemon.StartedService.GetClashModeStatus:input_type -> google.protobuf.Empty
|
||||||
29, // 20: daemon.StartedService.SubscribeClashMode:input_type -> google.protobuf.Empty
|
29, // 20: daemon.StartedService.SubscribeClashMode:input_type -> google.protobuf.Empty
|
||||||
16, // 21: daemon.StartedService.SetClashMode:input_type -> daemon.ClashMode
|
15, // 21: daemon.StartedService.SetClashMode:input_type -> daemon.ClashMode
|
||||||
13, // 22: daemon.StartedService.URLTest:input_type -> daemon.URLTestRequest
|
12, // 22: daemon.StartedService.URLTest:input_type -> daemon.URLTestRequest
|
||||||
14, // 23: daemon.StartedService.SelectOutbound:input_type -> daemon.SelectOutboundRequest
|
13, // 23: daemon.StartedService.SelectOutbound:input_type -> daemon.SelectOutboundRequest
|
||||||
15, // 24: daemon.StartedService.SetGroupExpand:input_type -> daemon.SetGroupExpandRequest
|
14, // 24: daemon.StartedService.SetGroupExpand:input_type -> daemon.SetGroupExpandRequest
|
||||||
29, // 25: daemon.StartedService.GetSystemProxyStatus:input_type -> google.protobuf.Empty
|
29, // 25: daemon.StartedService.GetSystemProxyStatus:input_type -> google.protobuf.Empty
|
||||||
19, // 26: daemon.StartedService.SetSystemProxyEnabled:input_type -> daemon.SetSystemProxyEnabledRequest
|
18, // 26: daemon.StartedService.SetSystemProxyEnabled:input_type -> daemon.SetSystemProxyEnabledRequest
|
||||||
20, // 27: daemon.StartedService.SubscribeConnections:input_type -> daemon.SubscribeConnectionsRequest
|
19, // 27: daemon.StartedService.SubscribeConnections:input_type -> daemon.SubscribeConnectionsRequest
|
||||||
24, // 28: daemon.StartedService.CloseConnection:input_type -> daemon.CloseConnectionRequest
|
24, // 28: daemon.StartedService.CloseConnection:input_type -> daemon.CloseConnectionRequest
|
||||||
29, // 29: daemon.StartedService.CloseAllConnections:input_type -> google.protobuf.Empty
|
29, // 29: daemon.StartedService.CloseAllConnections:input_type -> google.protobuf.Empty
|
||||||
29, // 30: daemon.StartedService.GetDeprecatedWarnings:input_type -> google.protobuf.Empty
|
29, // 30: daemon.StartedService.GetDeprecatedWarnings:input_type -> google.protobuf.Empty
|
||||||
29, // 31: daemon.StartedService.GetStartedAt:input_type -> google.protobuf.Empty
|
29, // 31: daemon.StartedService.GetStartedAt:input_type -> google.protobuf.Empty
|
||||||
29, // 32: daemon.StartedService.StopService:output_type -> google.protobuf.Empty
|
29, // 32: daemon.StartedService.StopService:output_type -> google.protobuf.Empty
|
||||||
29, // 33: daemon.StartedService.ReloadService:output_type -> google.protobuf.Empty
|
29, // 33: daemon.StartedService.ReloadService:output_type -> google.protobuf.Empty
|
||||||
4, // 34: daemon.StartedService.SubscribeServiceStatus:output_type -> daemon.ServiceStatus
|
3, // 34: daemon.StartedService.SubscribeServiceStatus:output_type -> daemon.ServiceStatus
|
||||||
7, // 35: daemon.StartedService.SubscribeLog:output_type -> daemon.Log
|
6, // 35: daemon.StartedService.SubscribeLog:output_type -> daemon.Log
|
||||||
8, // 36: daemon.StartedService.GetDefaultLogLevel:output_type -> daemon.DefaultLogLevel
|
7, // 36: daemon.StartedService.GetDefaultLogLevel:output_type -> daemon.DefaultLogLevel
|
||||||
29, // 37: daemon.StartedService.ClearLogs:output_type -> google.protobuf.Empty
|
29, // 37: daemon.StartedService.ClearLogs:output_type -> google.protobuf.Empty
|
||||||
9, // 38: daemon.StartedService.SubscribeStatus:output_type -> daemon.Status
|
8, // 38: daemon.StartedService.SubscribeStatus:output_type -> daemon.Status
|
||||||
10, // 39: daemon.StartedService.SubscribeGroups:output_type -> daemon.Groups
|
9, // 39: daemon.StartedService.SubscribeGroups:output_type -> daemon.Groups
|
||||||
17, // 40: daemon.StartedService.GetClashModeStatus:output_type -> daemon.ClashModeStatus
|
16, // 40: daemon.StartedService.GetClashModeStatus:output_type -> daemon.ClashModeStatus
|
||||||
16, // 41: daemon.StartedService.SubscribeClashMode:output_type -> daemon.ClashMode
|
15, // 41: daemon.StartedService.SubscribeClashMode:output_type -> daemon.ClashMode
|
||||||
29, // 42: daemon.StartedService.SetClashMode:output_type -> google.protobuf.Empty
|
29, // 42: daemon.StartedService.SetClashMode:output_type -> google.protobuf.Empty
|
||||||
29, // 43: daemon.StartedService.URLTest:output_type -> google.protobuf.Empty
|
29, // 43: daemon.StartedService.URLTest:output_type -> google.protobuf.Empty
|
||||||
29, // 44: daemon.StartedService.SelectOutbound:output_type -> google.protobuf.Empty
|
29, // 44: daemon.StartedService.SelectOutbound:output_type -> google.protobuf.Empty
|
||||||
29, // 45: daemon.StartedService.SetGroupExpand:output_type -> google.protobuf.Empty
|
29, // 45: daemon.StartedService.SetGroupExpand:output_type -> google.protobuf.Empty
|
||||||
18, // 46: daemon.StartedService.GetSystemProxyStatus:output_type -> daemon.SystemProxyStatus
|
17, // 46: daemon.StartedService.GetSystemProxyStatus:output_type -> daemon.SystemProxyStatus
|
||||||
29, // 47: daemon.StartedService.SetSystemProxyEnabled:output_type -> google.protobuf.Empty
|
29, // 47: daemon.StartedService.SetSystemProxyEnabled:output_type -> google.protobuf.Empty
|
||||||
21, // 48: daemon.StartedService.SubscribeConnections:output_type -> daemon.Connections
|
21, // 48: daemon.StartedService.SubscribeConnections:output_type -> daemon.ConnectionEvents
|
||||||
29, // 49: daemon.StartedService.CloseConnection:output_type -> google.protobuf.Empty
|
29, // 49: daemon.StartedService.CloseConnection:output_type -> google.protobuf.Empty
|
||||||
29, // 50: daemon.StartedService.CloseAllConnections:output_type -> google.protobuf.Empty
|
29, // 50: daemon.StartedService.CloseAllConnections:output_type -> google.protobuf.Empty
|
||||||
25, // 51: daemon.StartedService.GetDeprecatedWarnings:output_type -> daemon.DeprecatedWarnings
|
25, // 51: daemon.StartedService.GetDeprecatedWarnings:output_type -> daemon.DeprecatedWarnings
|
||||||
@@ -2027,8 +2056,8 @@ func file_daemon_started_service_proto_init() {
|
|||||||
File: protoimpl.DescBuilder{
|
File: protoimpl.DescBuilder{
|
||||||
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
||||||
RawDescriptor: unsafe.Slice(unsafe.StringData(file_daemon_started_service_proto_rawDesc), len(file_daemon_started_service_proto_rawDesc)),
|
RawDescriptor: unsafe.Slice(unsafe.StringData(file_daemon_started_service_proto_rawDesc), len(file_daemon_started_service_proto_rawDesc)),
|
||||||
NumEnums: 4,
|
NumEnums: 3,
|
||||||
NumMessages: 25,
|
NumMessages: 26,
|
||||||
NumExtensions: 0,
|
NumExtensions: 0,
|
||||||
NumServices: 1,
|
NumServices: 1,
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ service StartedService {
|
|||||||
rpc GetSystemProxyStatus(google.protobuf.Empty) returns(SystemProxyStatus) {}
|
rpc GetSystemProxyStatus(google.protobuf.Empty) returns(SystemProxyStatus) {}
|
||||||
rpc SetSystemProxyEnabled(SetSystemProxyEnabledRequest) returns(google.protobuf.Empty) {}
|
rpc SetSystemProxyEnabled(SetSystemProxyEnabledRequest) returns(google.protobuf.Empty) {}
|
||||||
|
|
||||||
rpc SubscribeConnections(SubscribeConnectionsRequest) returns(stream Connections) {}
|
rpc SubscribeConnections(SubscribeConnectionsRequest) returns(stream ConnectionEvents) {}
|
||||||
rpc CloseConnection(CloseConnectionRequest) returns(google.protobuf.Empty) {}
|
rpc CloseConnection(CloseConnectionRequest) returns(google.protobuf.Empty) {}
|
||||||
rpc CloseAllConnections(google.protobuf.Empty) returns(google.protobuf.Empty) {}
|
rpc CloseAllConnections(google.protobuf.Empty) returns(google.protobuf.Empty) {}
|
||||||
rpc GetDeprecatedWarnings(google.protobuf.Empty) returns(DeprecatedWarnings) {}
|
rpc GetDeprecatedWarnings(google.protobuf.Empty) returns(DeprecatedWarnings) {}
|
||||||
@@ -143,24 +143,26 @@ message SetSystemProxyEnabledRequest {
|
|||||||
|
|
||||||
message SubscribeConnectionsRequest {
|
message SubscribeConnectionsRequest {
|
||||||
int64 interval = 1;
|
int64 interval = 1;
|
||||||
ConnectionFilter filter = 2;
|
|
||||||
ConnectionSortBy sortBy = 3;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
enum ConnectionFilter {
|
enum ConnectionEventType {
|
||||||
ALL = 0;
|
CONNECTION_EVENT_NEW = 0;
|
||||||
ACTIVE = 1;
|
CONNECTION_EVENT_UPDATE = 1;
|
||||||
CLOSED = 2;
|
CONNECTION_EVENT_CLOSED = 2;
|
||||||
}
|
}
|
||||||
|
|
||||||
enum ConnectionSortBy {
|
message ConnectionEvent {
|
||||||
DATE = 0;
|
ConnectionEventType type = 1;
|
||||||
TRAFFIC = 1;
|
string id = 2;
|
||||||
TOTAL_TRAFFIC = 2;
|
Connection connection = 3;
|
||||||
|
int64 uplinkDelta = 4;
|
||||||
|
int64 downlinkDelta = 5;
|
||||||
|
int64 closedAt = 6;
|
||||||
}
|
}
|
||||||
|
|
||||||
message Connections {
|
message ConnectionEvents {
|
||||||
repeated Connection connections = 1;
|
repeated ConnectionEvent events = 1;
|
||||||
|
bool reset = 2;
|
||||||
}
|
}
|
||||||
|
|
||||||
message Connection {
|
message Connection {
|
||||||
@@ -193,7 +195,7 @@ message ProcessInfo {
|
|||||||
int32 userId = 2;
|
int32 userId = 2;
|
||||||
string userName = 3;
|
string userName = 3;
|
||||||
string processPath = 4;
|
string processPath = 4;
|
||||||
string packageName = 5;
|
repeated string packageNames = 5;
|
||||||
}
|
}
|
||||||
|
|
||||||
message CloseConnectionRequest {
|
message CloseConnectionRequest {
|
||||||
|
|||||||
@@ -58,7 +58,7 @@ type StartedServiceClient interface {
|
|||||||
SetGroupExpand(ctx context.Context, in *SetGroupExpandRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
SetGroupExpand(ctx context.Context, in *SetGroupExpandRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||||
GetSystemProxyStatus(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*SystemProxyStatus, error)
|
GetSystemProxyStatus(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*SystemProxyStatus, error)
|
||||||
SetSystemProxyEnabled(ctx context.Context, in *SetSystemProxyEnabledRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
SetSystemProxyEnabled(ctx context.Context, in *SetSystemProxyEnabledRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||||
SubscribeConnections(ctx context.Context, in *SubscribeConnectionsRequest, opts ...grpc.CallOption) (grpc.ServerStreamingClient[Connections], error)
|
SubscribeConnections(ctx context.Context, in *SubscribeConnectionsRequest, opts ...grpc.CallOption) (grpc.ServerStreamingClient[ConnectionEvents], error)
|
||||||
CloseConnection(ctx context.Context, in *CloseConnectionRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
CloseConnection(ctx context.Context, in *CloseConnectionRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||||
CloseAllConnections(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
CloseAllConnections(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||||
GetDeprecatedWarnings(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*DeprecatedWarnings, error)
|
GetDeprecatedWarnings(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*DeprecatedWarnings, error)
|
||||||
@@ -278,13 +278,13 @@ func (c *startedServiceClient) SetSystemProxyEnabled(ctx context.Context, in *Se
|
|||||||
return out, nil
|
return out, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *startedServiceClient) SubscribeConnections(ctx context.Context, in *SubscribeConnectionsRequest, opts ...grpc.CallOption) (grpc.ServerStreamingClient[Connections], error) {
|
func (c *startedServiceClient) SubscribeConnections(ctx context.Context, in *SubscribeConnectionsRequest, opts ...grpc.CallOption) (grpc.ServerStreamingClient[ConnectionEvents], error) {
|
||||||
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
||||||
stream, err := c.cc.NewStream(ctx, &StartedService_ServiceDesc.Streams[5], StartedService_SubscribeConnections_FullMethodName, cOpts...)
|
stream, err := c.cc.NewStream(ctx, &StartedService_ServiceDesc.Streams[5], StartedService_SubscribeConnections_FullMethodName, cOpts...)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
x := &grpc.GenericClientStream[SubscribeConnectionsRequest, Connections]{ClientStream: stream}
|
x := &grpc.GenericClientStream[SubscribeConnectionsRequest, ConnectionEvents]{ClientStream: stream}
|
||||||
if err := x.ClientStream.SendMsg(in); err != nil {
|
if err := x.ClientStream.SendMsg(in); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -295,7 +295,7 @@ func (c *startedServiceClient) SubscribeConnections(ctx context.Context, in *Sub
|
|||||||
}
|
}
|
||||||
|
|
||||||
// This type alias is provided for backwards compatibility with existing code that references the prior non-generic stream type by name.
|
// This type alias is provided for backwards compatibility with existing code that references the prior non-generic stream type by name.
|
||||||
type StartedService_SubscribeConnectionsClient = grpc.ServerStreamingClient[Connections]
|
type StartedService_SubscribeConnectionsClient = grpc.ServerStreamingClient[ConnectionEvents]
|
||||||
|
|
||||||
func (c *startedServiceClient) CloseConnection(ctx context.Context, in *CloseConnectionRequest, opts ...grpc.CallOption) (*emptypb.Empty, error) {
|
func (c *startedServiceClient) CloseConnection(ctx context.Context, in *CloseConnectionRequest, opts ...grpc.CallOption) (*emptypb.Empty, error) {
|
||||||
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
||||||
@@ -357,7 +357,7 @@ type StartedServiceServer interface {
|
|||||||
SetGroupExpand(context.Context, *SetGroupExpandRequest) (*emptypb.Empty, error)
|
SetGroupExpand(context.Context, *SetGroupExpandRequest) (*emptypb.Empty, error)
|
||||||
GetSystemProxyStatus(context.Context, *emptypb.Empty) (*SystemProxyStatus, error)
|
GetSystemProxyStatus(context.Context, *emptypb.Empty) (*SystemProxyStatus, error)
|
||||||
SetSystemProxyEnabled(context.Context, *SetSystemProxyEnabledRequest) (*emptypb.Empty, error)
|
SetSystemProxyEnabled(context.Context, *SetSystemProxyEnabledRequest) (*emptypb.Empty, error)
|
||||||
SubscribeConnections(*SubscribeConnectionsRequest, grpc.ServerStreamingServer[Connections]) error
|
SubscribeConnections(*SubscribeConnectionsRequest, grpc.ServerStreamingServer[ConnectionEvents]) error
|
||||||
CloseConnection(context.Context, *CloseConnectionRequest) (*emptypb.Empty, error)
|
CloseConnection(context.Context, *CloseConnectionRequest) (*emptypb.Empty, error)
|
||||||
CloseAllConnections(context.Context, *emptypb.Empty) (*emptypb.Empty, error)
|
CloseAllConnections(context.Context, *emptypb.Empty) (*emptypb.Empty, error)
|
||||||
GetDeprecatedWarnings(context.Context, *emptypb.Empty) (*DeprecatedWarnings, error)
|
GetDeprecatedWarnings(context.Context, *emptypb.Empty) (*DeprecatedWarnings, error)
|
||||||
@@ -373,87 +373,87 @@ type StartedServiceServer interface {
|
|||||||
type UnimplementedStartedServiceServer struct{}
|
type UnimplementedStartedServiceServer struct{}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) StopService(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) StopService(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method StopService not implemented")
|
return nil, status.Error(codes.Unimplemented, "method StopService not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) ReloadService(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) ReloadService(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method ReloadService not implemented")
|
return nil, status.Error(codes.Unimplemented, "method ReloadService not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SubscribeServiceStatus(*emptypb.Empty, grpc.ServerStreamingServer[ServiceStatus]) error {
|
func (UnimplementedStartedServiceServer) SubscribeServiceStatus(*emptypb.Empty, grpc.ServerStreamingServer[ServiceStatus]) error {
|
||||||
return status.Errorf(codes.Unimplemented, "method SubscribeServiceStatus not implemented")
|
return status.Error(codes.Unimplemented, "method SubscribeServiceStatus not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SubscribeLog(*emptypb.Empty, grpc.ServerStreamingServer[Log]) error {
|
func (UnimplementedStartedServiceServer) SubscribeLog(*emptypb.Empty, grpc.ServerStreamingServer[Log]) error {
|
||||||
return status.Errorf(codes.Unimplemented, "method SubscribeLog not implemented")
|
return status.Error(codes.Unimplemented, "method SubscribeLog not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) GetDefaultLogLevel(context.Context, *emptypb.Empty) (*DefaultLogLevel, error) {
|
func (UnimplementedStartedServiceServer) GetDefaultLogLevel(context.Context, *emptypb.Empty) (*DefaultLogLevel, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method GetDefaultLogLevel not implemented")
|
return nil, status.Error(codes.Unimplemented, "method GetDefaultLogLevel not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) ClearLogs(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) ClearLogs(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method ClearLogs not implemented")
|
return nil, status.Error(codes.Unimplemented, "method ClearLogs not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SubscribeStatus(*SubscribeStatusRequest, grpc.ServerStreamingServer[Status]) error {
|
func (UnimplementedStartedServiceServer) SubscribeStatus(*SubscribeStatusRequest, grpc.ServerStreamingServer[Status]) error {
|
||||||
return status.Errorf(codes.Unimplemented, "method SubscribeStatus not implemented")
|
return status.Error(codes.Unimplemented, "method SubscribeStatus not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SubscribeGroups(*emptypb.Empty, grpc.ServerStreamingServer[Groups]) error {
|
func (UnimplementedStartedServiceServer) SubscribeGroups(*emptypb.Empty, grpc.ServerStreamingServer[Groups]) error {
|
||||||
return status.Errorf(codes.Unimplemented, "method SubscribeGroups not implemented")
|
return status.Error(codes.Unimplemented, "method SubscribeGroups not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) GetClashModeStatus(context.Context, *emptypb.Empty) (*ClashModeStatus, error) {
|
func (UnimplementedStartedServiceServer) GetClashModeStatus(context.Context, *emptypb.Empty) (*ClashModeStatus, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method GetClashModeStatus not implemented")
|
return nil, status.Error(codes.Unimplemented, "method GetClashModeStatus not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SubscribeClashMode(*emptypb.Empty, grpc.ServerStreamingServer[ClashMode]) error {
|
func (UnimplementedStartedServiceServer) SubscribeClashMode(*emptypb.Empty, grpc.ServerStreamingServer[ClashMode]) error {
|
||||||
return status.Errorf(codes.Unimplemented, "method SubscribeClashMode not implemented")
|
return status.Error(codes.Unimplemented, "method SubscribeClashMode not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SetClashMode(context.Context, *ClashMode) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) SetClashMode(context.Context, *ClashMode) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method SetClashMode not implemented")
|
return nil, status.Error(codes.Unimplemented, "method SetClashMode not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) URLTest(context.Context, *URLTestRequest) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) URLTest(context.Context, *URLTestRequest) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method URLTest not implemented")
|
return nil, status.Error(codes.Unimplemented, "method URLTest not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SelectOutbound(context.Context, *SelectOutboundRequest) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) SelectOutbound(context.Context, *SelectOutboundRequest) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method SelectOutbound not implemented")
|
return nil, status.Error(codes.Unimplemented, "method SelectOutbound not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SetGroupExpand(context.Context, *SetGroupExpandRequest) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) SetGroupExpand(context.Context, *SetGroupExpandRequest) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method SetGroupExpand not implemented")
|
return nil, status.Error(codes.Unimplemented, "method SetGroupExpand not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) GetSystemProxyStatus(context.Context, *emptypb.Empty) (*SystemProxyStatus, error) {
|
func (UnimplementedStartedServiceServer) GetSystemProxyStatus(context.Context, *emptypb.Empty) (*SystemProxyStatus, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method GetSystemProxyStatus not implemented")
|
return nil, status.Error(codes.Unimplemented, "method GetSystemProxyStatus not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SetSystemProxyEnabled(context.Context, *SetSystemProxyEnabledRequest) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) SetSystemProxyEnabled(context.Context, *SetSystemProxyEnabledRequest) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method SetSystemProxyEnabled not implemented")
|
return nil, status.Error(codes.Unimplemented, "method SetSystemProxyEnabled not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) SubscribeConnections(*SubscribeConnectionsRequest, grpc.ServerStreamingServer[Connections]) error {
|
func (UnimplementedStartedServiceServer) SubscribeConnections(*SubscribeConnectionsRequest, grpc.ServerStreamingServer[ConnectionEvents]) error {
|
||||||
return status.Errorf(codes.Unimplemented, "method SubscribeConnections not implemented")
|
return status.Error(codes.Unimplemented, "method SubscribeConnections not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) CloseConnection(context.Context, *CloseConnectionRequest) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) CloseConnection(context.Context, *CloseConnectionRequest) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method CloseConnection not implemented")
|
return nil, status.Error(codes.Unimplemented, "method CloseConnection not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) CloseAllConnections(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
func (UnimplementedStartedServiceServer) CloseAllConnections(context.Context, *emptypb.Empty) (*emptypb.Empty, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method CloseAllConnections not implemented")
|
return nil, status.Error(codes.Unimplemented, "method CloseAllConnections not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) GetDeprecatedWarnings(context.Context, *emptypb.Empty) (*DeprecatedWarnings, error) {
|
func (UnimplementedStartedServiceServer) GetDeprecatedWarnings(context.Context, *emptypb.Empty) (*DeprecatedWarnings, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method GetDeprecatedWarnings not implemented")
|
return nil, status.Error(codes.Unimplemented, "method GetDeprecatedWarnings not implemented")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (UnimplementedStartedServiceServer) GetStartedAt(context.Context, *emptypb.Empty) (*StartedAt, error) {
|
func (UnimplementedStartedServiceServer) GetStartedAt(context.Context, *emptypb.Empty) (*StartedAt, error) {
|
||||||
return nil, status.Errorf(codes.Unimplemented, "method GetStartedAt not implemented")
|
return nil, status.Error(codes.Unimplemented, "method GetStartedAt not implemented")
|
||||||
}
|
}
|
||||||
func (UnimplementedStartedServiceServer) mustEmbedUnimplementedStartedServiceServer() {}
|
func (UnimplementedStartedServiceServer) mustEmbedUnimplementedStartedServiceServer() {}
|
||||||
func (UnimplementedStartedServiceServer) testEmbeddedByValue() {}
|
func (UnimplementedStartedServiceServer) testEmbeddedByValue() {}
|
||||||
@@ -466,7 +466,7 @@ type UnsafeStartedServiceServer interface {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func RegisterStartedServiceServer(s grpc.ServiceRegistrar, srv StartedServiceServer) {
|
func RegisterStartedServiceServer(s grpc.ServiceRegistrar, srv StartedServiceServer) {
|
||||||
// If the following call pancis, it indicates UnimplementedStartedServiceServer was
|
// If the following call panics, it indicates UnimplementedStartedServiceServer was
|
||||||
// embedded by pointer and is nil. This will cause panics if an
|
// embedded by pointer and is nil. This will cause panics if an
|
||||||
// unimplemented method is ever invoked, so we test this at initialization
|
// unimplemented method is ever invoked, so we test this at initialization
|
||||||
// time to prevent it from happening at runtime later due to I/O.
|
// time to prevent it from happening at runtime later due to I/O.
|
||||||
@@ -734,11 +734,11 @@ func _StartedService_SubscribeConnections_Handler(srv interface{}, stream grpc.S
|
|||||||
if err := stream.RecvMsg(m); err != nil {
|
if err := stream.RecvMsg(m); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return srv.(StartedServiceServer).SubscribeConnections(m, &grpc.GenericServerStream[SubscribeConnectionsRequest, Connections]{ServerStream: stream})
|
return srv.(StartedServiceServer).SubscribeConnections(m, &grpc.GenericServerStream[SubscribeConnectionsRequest, ConnectionEvents]{ServerStream: stream})
|
||||||
}
|
}
|
||||||
|
|
||||||
// This type alias is provided for backwards compatibility with existing code that references the prior non-generic stream type by name.
|
// This type alias is provided for backwards compatibility with existing code that references the prior non-generic stream type by name.
|
||||||
type StartedService_SubscribeConnectionsServer = grpc.ServerStreamingServer[Connections]
|
type StartedService_SubscribeConnectionsServer = grpc.ServerStreamingServer[ConnectionEvents]
|
||||||
|
|
||||||
func _StartedService_CloseConnection_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
|
func _StartedService_CloseConnection_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
|
||||||
in := new(CloseConnectionRequest)
|
in := new(CloseConnectionRequest)
|
||||||
|
|||||||
8
debug.go
8
debug.go
@@ -3,11 +3,11 @@ package box
|
|||||||
import (
|
import (
|
||||||
"runtime/debug"
|
"runtime/debug"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/common/conntrack"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
)
|
)
|
||||||
|
|
||||||
func applyDebugOptions(options option.DebugOptions) {
|
func applyDebugOptions(options option.DebugOptions) error {
|
||||||
applyDebugListenOption(options)
|
applyDebugListenOption(options)
|
||||||
if options.GCPercent != nil {
|
if options.GCPercent != nil {
|
||||||
debug.SetGCPercent(*options.GCPercent)
|
debug.SetGCPercent(*options.GCPercent)
|
||||||
@@ -26,9 +26,9 @@ func applyDebugOptions(options option.DebugOptions) {
|
|||||||
}
|
}
|
||||||
if options.MemoryLimit.Value() != 0 {
|
if options.MemoryLimit.Value() != 0 {
|
||||||
debug.SetMemoryLimit(int64(float64(options.MemoryLimit.Value()) / 1.5))
|
debug.SetMemoryLimit(int64(float64(options.MemoryLimit.Value()) / 1.5))
|
||||||
conntrack.MemoryLimit = options.MemoryLimit.Value()
|
|
||||||
}
|
}
|
||||||
if options.OOMKiller != nil {
|
if options.OOMKiller != nil {
|
||||||
conntrack.KillerEnabled = *options.OOMKiller
|
return E.New("legacy oom_killer in debug options is removed, use oom-killer service instead")
|
||||||
}
|
}
|
||||||
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -144,7 +144,11 @@ func (c *Client) Exchange(ctx context.Context, transport adapter.DNSTransport, m
|
|||||||
if c.cache != nil {
|
if c.cache != nil {
|
||||||
cond, loaded := c.cacheLock.LoadOrStore(question, make(chan struct{}))
|
cond, loaded := c.cacheLock.LoadOrStore(question, make(chan struct{}))
|
||||||
if loaded {
|
if loaded {
|
||||||
<-cond
|
select {
|
||||||
|
case <-cond:
|
||||||
|
case <-ctx.Done():
|
||||||
|
return nil, ctx.Err()
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
defer func() {
|
defer func() {
|
||||||
c.cacheLock.Delete(question)
|
c.cacheLock.Delete(question)
|
||||||
@@ -154,7 +158,11 @@ func (c *Client) Exchange(ctx context.Context, transport adapter.DNSTransport, m
|
|||||||
} else if c.transportCache != nil {
|
} else if c.transportCache != nil {
|
||||||
cond, loaded := c.transportCacheLock.LoadOrStore(question, make(chan struct{}))
|
cond, loaded := c.transportCacheLock.LoadOrStore(question, make(chan struct{}))
|
||||||
if loaded {
|
if loaded {
|
||||||
<-cond
|
select {
|
||||||
|
case <-cond:
|
||||||
|
case <-ctx.Done():
|
||||||
|
return nil, ctx.Err()
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
defer func() {
|
defer func() {
|
||||||
c.transportCacheLock.Delete(question)
|
c.transportCacheLock.Delete(question)
|
||||||
@@ -232,8 +240,10 @@ func (c *Client) Exchange(ctx context.Context, transport adapter.DNSTransport, m
|
|||||||
if responseChecker != nil {
|
if responseChecker != nil {
|
||||||
var rejected bool
|
var rejected bool
|
||||||
// TODO: add accept_any rule and support to check response instead of addresses
|
// TODO: add accept_any rule and support to check response instead of addresses
|
||||||
if response.Rcode != dns.RcodeSuccess || len(response.Answer) == 0 {
|
if response.Rcode != dns.RcodeSuccess && response.Rcode != dns.RcodeNameError {
|
||||||
rejected = true
|
rejected = true
|
||||||
|
} else if len(response.Answer) == 0 {
|
||||||
|
rejected = !responseChecker(nil)
|
||||||
} else {
|
} else {
|
||||||
rejected = !responseChecker(MessageToAddresses(response))
|
rejected = !responseChecker(MessageToAddresses(response))
|
||||||
}
|
}
|
||||||
@@ -314,16 +324,20 @@ func (c *Client) Lookup(ctx context.Context, transport adapter.DNSTransport, dom
|
|||||||
} else {
|
} else {
|
||||||
strategy = options.Strategy
|
strategy = options.Strategy
|
||||||
}
|
}
|
||||||
|
lookupOptions := options
|
||||||
|
if options.LookupStrategy != C.DomainStrategyAsIS {
|
||||||
|
lookupOptions.Strategy = strategy
|
||||||
|
}
|
||||||
if strategy == C.DomainStrategyIPv4Only {
|
if strategy == C.DomainStrategyIPv4Only {
|
||||||
return c.lookupToExchange(ctx, transport, dnsName, dns.TypeA, options, responseChecker)
|
return c.lookupToExchange(ctx, transport, dnsName, dns.TypeA, lookupOptions, responseChecker)
|
||||||
} else if strategy == C.DomainStrategyIPv6Only {
|
} else if strategy == C.DomainStrategyIPv6Only {
|
||||||
return c.lookupToExchange(ctx, transport, dnsName, dns.TypeAAAA, options, responseChecker)
|
return c.lookupToExchange(ctx, transport, dnsName, dns.TypeAAAA, lookupOptions, responseChecker)
|
||||||
}
|
}
|
||||||
var response4 []netip.Addr
|
var response4 []netip.Addr
|
||||||
var response6 []netip.Addr
|
var response6 []netip.Addr
|
||||||
var group task.Group
|
var group task.Group
|
||||||
group.Append("exchange4", func(ctx context.Context) error {
|
group.Append("exchange4", func(ctx context.Context) error {
|
||||||
response, err := c.lookupToExchange(ctx, transport, dnsName, dns.TypeA, options, responseChecker)
|
response, err := c.lookupToExchange(ctx, transport, dnsName, dns.TypeA, lookupOptions, responseChecker)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -331,7 +345,7 @@ func (c *Client) Lookup(ctx context.Context, transport adapter.DNSTransport, dom
|
|||||||
return nil
|
return nil
|
||||||
})
|
})
|
||||||
group.Append("exchange6", func(ctx context.Context) error {
|
group.Append("exchange6", func(ctx context.Context) error {
|
||||||
response, err := c.lookupToExchange(ctx, transport, dnsName, dns.TypeAAAA, options, responseChecker)
|
response, err := c.lookupToExchange(ctx, transport, dnsName, dns.TypeAAAA, lookupOptions, responseChecker)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -195,7 +195,16 @@ func (r *Router) matchDNS(ctx context.Context, allowFakeIP bool, ruleIndex int,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return r.transport.Default(), nil, -1
|
transport := r.transport.Default()
|
||||||
|
if legacyTransport, isLegacy := transport.(adapter.LegacyDNSTransport); isLegacy {
|
||||||
|
if options.Strategy == C.DomainStrategyAsIS {
|
||||||
|
options.Strategy = legacyTransport.LegacyStrategy()
|
||||||
|
}
|
||||||
|
if !options.ClientSubnet.IsValid() {
|
||||||
|
options.ClientSubnet = legacyTransport.LegacyClientSubnet()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return transport, nil, -1
|
||||||
}
|
}
|
||||||
|
|
||||||
func (r *Router) Exchange(ctx context.Context, message *mDNS.Msg, options adapter.DNSQueryOptions) (*mDNS.Msg, error) {
|
func (r *Router) Exchange(ctx context.Context, message *mDNS.Msg, options adapter.DNSQueryOptions) (*mDNS.Msg, error) {
|
||||||
@@ -272,13 +281,7 @@ func (r *Router) Exchange(ctx context.Context, message *mDNS.Msg, options adapte
|
|||||||
return action.Response(message), nil
|
return action.Response(message), nil
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
var responseCheck func(responseAddrs []netip.Addr) bool
|
responseCheck := addressLimitResponseCheck(rule, metadata)
|
||||||
if rule != nil && rule.WithAddressLimit() {
|
|
||||||
responseCheck = func(responseAddrs []netip.Addr) bool {
|
|
||||||
metadata.DestinationAddresses = responseAddrs
|
|
||||||
return rule.MatchAddressLimit(metadata)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if dnsOptions.Strategy == C.DomainStrategyAsIS {
|
if dnsOptions.Strategy == C.DomainStrategyAsIS {
|
||||||
dnsOptions.Strategy = r.defaultDomainStrategy
|
dnsOptions.Strategy = r.defaultDomainStrategy
|
||||||
}
|
}
|
||||||
@@ -351,7 +354,7 @@ func (r *Router) Lookup(ctx context.Context, domain string, options adapter.DNSQ
|
|||||||
transport := options.Transport
|
transport := options.Transport
|
||||||
if legacyTransport, isLegacy := transport.(adapter.LegacyDNSTransport); isLegacy {
|
if legacyTransport, isLegacy := transport.(adapter.LegacyDNSTransport); isLegacy {
|
||||||
if options.Strategy == C.DomainStrategyAsIS {
|
if options.Strategy == C.DomainStrategyAsIS {
|
||||||
options.Strategy = r.defaultDomainStrategy
|
options.Strategy = legacyTransport.LegacyStrategy()
|
||||||
}
|
}
|
||||||
if !options.ClientSubnet.IsValid() {
|
if !options.ClientSubnet.IsValid() {
|
||||||
options.ClientSubnet = legacyTransport.LegacyClientSubnet()
|
options.ClientSubnet = legacyTransport.LegacyClientSubnet()
|
||||||
@@ -377,9 +380,11 @@ func (r *Router) Lookup(ctx context.Context, domain string, options adapter.DNSQ
|
|||||||
case *R.RuleActionReject:
|
case *R.RuleActionReject:
|
||||||
return nil, &R.RejectedError{Cause: action.Error(ctx)}
|
return nil, &R.RejectedError{Cause: action.Error(ctx)}
|
||||||
case *R.RuleActionPredefined:
|
case *R.RuleActionPredefined:
|
||||||
|
responseAddrs = nil
|
||||||
if action.Rcode != mDNS.RcodeSuccess {
|
if action.Rcode != mDNS.RcodeSuccess {
|
||||||
err = RcodeError(action.Rcode)
|
err = RcodeError(action.Rcode)
|
||||||
} else {
|
} else {
|
||||||
|
err = nil
|
||||||
for _, answer := range action.Answer {
|
for _, answer := range action.Answer {
|
||||||
switch record := answer.(type) {
|
switch record := answer.(type) {
|
||||||
case *mDNS.A:
|
case *mDNS.A:
|
||||||
@@ -392,13 +397,7 @@ func (r *Router) Lookup(ctx context.Context, domain string, options adapter.DNSQ
|
|||||||
goto response
|
goto response
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
var responseCheck func(responseAddrs []netip.Addr) bool
|
responseCheck := addressLimitResponseCheck(rule, metadata)
|
||||||
if rule != nil && rule.WithAddressLimit() {
|
|
||||||
responseCheck = func(responseAddrs []netip.Addr) bool {
|
|
||||||
metadata.DestinationAddresses = responseAddrs
|
|
||||||
return rule.MatchAddressLimit(metadata)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if dnsOptions.Strategy == C.DomainStrategyAsIS {
|
if dnsOptions.Strategy == C.DomainStrategyAsIS {
|
||||||
dnsOptions.Strategy = r.defaultDomainStrategy
|
dnsOptions.Strategy = r.defaultDomainStrategy
|
||||||
}
|
}
|
||||||
@@ -426,6 +425,18 @@ func isAddressQuery(message *mDNS.Msg) bool {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func addressLimitResponseCheck(rule adapter.DNSRule, metadata *adapter.InboundContext) func(responseAddrs []netip.Addr) bool {
|
||||||
|
if rule == nil || !rule.WithAddressLimit() {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
responseMetadata := *metadata
|
||||||
|
return func(responseAddrs []netip.Addr) bool {
|
||||||
|
checkMetadata := responseMetadata
|
||||||
|
checkMetadata.DestinationAddresses = responseAddrs
|
||||||
|
return rule.MatchAddressLimit(&checkMetadata)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (r *Router) ClearCache() {
|
func (r *Router) ClearCache() {
|
||||||
r.client.ClearCache()
|
r.client.ClearCache()
|
||||||
if r.platformInterface != nil {
|
if r.platformInterface != nil {
|
||||||
|
|||||||
@@ -4,6 +4,9 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"net"
|
"net"
|
||||||
"sync"
|
"sync"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
)
|
)
|
||||||
|
|
||||||
type ConnectorCallbacks[T any] struct {
|
type ConnectorCallbacks[T any] struct {
|
||||||
@@ -16,10 +19,11 @@ type Connector[T any] struct {
|
|||||||
dial func(ctx context.Context) (T, error)
|
dial func(ctx context.Context) (T, error)
|
||||||
callbacks ConnectorCallbacks[T]
|
callbacks ConnectorCallbacks[T]
|
||||||
|
|
||||||
access sync.Mutex
|
access sync.Mutex
|
||||||
connection T
|
connection T
|
||||||
hasConnection bool
|
hasConnection bool
|
||||||
connecting chan struct{}
|
connectionCancel context.CancelFunc
|
||||||
|
connecting chan struct{}
|
||||||
|
|
||||||
closeCtx context.Context
|
closeCtx context.Context
|
||||||
closed bool
|
closed bool
|
||||||
@@ -47,6 +51,16 @@ func NewSingleflightConnector(closeCtx context.Context, dial func(context.Contex
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type contextKeyConnecting struct{}
|
||||||
|
|
||||||
|
var errRecursiveConnectorDial = E.New("recursive connector dial")
|
||||||
|
|
||||||
|
type connectorDialResult[T any] struct {
|
||||||
|
connection T
|
||||||
|
cancel context.CancelFunc
|
||||||
|
err error
|
||||||
|
}
|
||||||
|
|
||||||
func (c *Connector[T]) Get(ctx context.Context) (T, error) {
|
func (c *Connector[T]) Get(ctx context.Context) (T, error) {
|
||||||
var zero T
|
var zero T
|
||||||
for {
|
for {
|
||||||
@@ -64,6 +78,14 @@ func (c *Connector[T]) Get(ctx context.Context) (T, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
c.hasConnection = false
|
c.hasConnection = false
|
||||||
|
if c.connectionCancel != nil {
|
||||||
|
c.connectionCancel()
|
||||||
|
c.connectionCancel = nil
|
||||||
|
}
|
||||||
|
if isRecursiveConnectorDial(ctx, c) {
|
||||||
|
c.access.Unlock()
|
||||||
|
return zero, errRecursiveConnectorDial
|
||||||
|
}
|
||||||
|
|
||||||
if c.connecting != nil {
|
if c.connecting != nil {
|
||||||
connecting := c.connecting
|
connecting := c.connecting
|
||||||
@@ -79,48 +101,134 @@ func (c *Connector[T]) Get(ctx context.Context) (T, error) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
c.connecting = make(chan struct{})
|
if err := ctx.Err(); err != nil {
|
||||||
c.access.Unlock()
|
|
||||||
|
|
||||||
connection, err := c.dialWithCancellation(ctx)
|
|
||||||
|
|
||||||
c.access.Lock()
|
|
||||||
close(c.connecting)
|
|
||||||
c.connecting = nil
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
c.access.Unlock()
|
c.access.Unlock()
|
||||||
return zero, err
|
return zero, err
|
||||||
}
|
}
|
||||||
|
|
||||||
if c.closed {
|
connecting := make(chan struct{})
|
||||||
c.callbacks.Close(connection)
|
c.connecting = connecting
|
||||||
c.access.Unlock()
|
dialContext := context.WithValue(ctx, contextKeyConnecting{}, c)
|
||||||
return zero, ErrTransportClosed
|
dialResult := make(chan connectorDialResult[T], 1)
|
||||||
}
|
|
||||||
|
|
||||||
c.connection = connection
|
|
||||||
c.hasConnection = true
|
|
||||||
result := c.connection
|
|
||||||
c.access.Unlock()
|
c.access.Unlock()
|
||||||
|
|
||||||
return result, nil
|
go func() {
|
||||||
|
connection, cancel, err := c.dialWithCancellation(dialContext)
|
||||||
|
dialResult <- connectorDialResult[T]{
|
||||||
|
connection: connection,
|
||||||
|
cancel: cancel,
|
||||||
|
err: err,
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
|
||||||
|
select {
|
||||||
|
case result := <-dialResult:
|
||||||
|
return c.completeDial(ctx, connecting, result)
|
||||||
|
case <-ctx.Done():
|
||||||
|
go func() {
|
||||||
|
result := <-dialResult
|
||||||
|
_, _ = c.completeDial(ctx, connecting, result)
|
||||||
|
}()
|
||||||
|
return zero, ctx.Err()
|
||||||
|
case <-c.closeCtx.Done():
|
||||||
|
go func() {
|
||||||
|
result := <-dialResult
|
||||||
|
_, _ = c.completeDial(ctx, connecting, result)
|
||||||
|
}()
|
||||||
|
return zero, ErrTransportClosed
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *Connector[T]) dialWithCancellation(ctx context.Context) (T, error) {
|
func isRecursiveConnectorDial[T any](ctx context.Context, connector *Connector[T]) bool {
|
||||||
dialCtx, cancel := context.WithCancel(ctx)
|
dialConnector, loaded := ctx.Value(contextKeyConnecting{}).(*Connector[T])
|
||||||
defer cancel()
|
return loaded && dialConnector == connector
|
||||||
|
}
|
||||||
|
|
||||||
go func() {
|
func (c *Connector[T]) completeDial(ctx context.Context, connecting chan struct{}, result connectorDialResult[T]) (T, error) {
|
||||||
select {
|
var zero T
|
||||||
case <-c.closeCtx.Done():
|
|
||||||
cancel()
|
c.access.Lock()
|
||||||
case <-dialCtx.Done():
|
defer c.access.Unlock()
|
||||||
|
defer func() {
|
||||||
|
if c.connecting == connecting {
|
||||||
|
c.connecting = nil
|
||||||
}
|
}
|
||||||
|
close(connecting)
|
||||||
}()
|
}()
|
||||||
|
|
||||||
return c.dial(dialCtx)
|
if result.err != nil {
|
||||||
|
return zero, result.err
|
||||||
|
}
|
||||||
|
if c.closed || c.closeCtx.Err() != nil {
|
||||||
|
result.cancel()
|
||||||
|
c.callbacks.Close(result.connection)
|
||||||
|
return zero, ErrTransportClosed
|
||||||
|
}
|
||||||
|
if err := ctx.Err(); err != nil {
|
||||||
|
result.cancel()
|
||||||
|
c.callbacks.Close(result.connection)
|
||||||
|
return zero, err
|
||||||
|
}
|
||||||
|
|
||||||
|
c.connection = result.connection
|
||||||
|
c.hasConnection = true
|
||||||
|
c.connectionCancel = result.cancel
|
||||||
|
return c.connection, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *Connector[T]) dialWithCancellation(ctx context.Context) (T, context.CancelFunc, error) {
|
||||||
|
var zero T
|
||||||
|
if err := ctx.Err(); err != nil {
|
||||||
|
return zero, nil, err
|
||||||
|
}
|
||||||
|
connCtx, cancel := context.WithCancel(c.closeCtx)
|
||||||
|
|
||||||
|
var (
|
||||||
|
stateAccess sync.Mutex
|
||||||
|
dialComplete bool
|
||||||
|
)
|
||||||
|
stopCancel := context.AfterFunc(ctx, func() {
|
||||||
|
stateAccess.Lock()
|
||||||
|
if !dialComplete {
|
||||||
|
cancel()
|
||||||
|
}
|
||||||
|
stateAccess.Unlock()
|
||||||
|
})
|
||||||
|
select {
|
||||||
|
case <-ctx.Done():
|
||||||
|
stateAccess.Lock()
|
||||||
|
dialComplete = true
|
||||||
|
stateAccess.Unlock()
|
||||||
|
stopCancel()
|
||||||
|
cancel()
|
||||||
|
return zero, nil, ctx.Err()
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
|
||||||
|
connection, err := c.dial(valueContext{connCtx, ctx})
|
||||||
|
stateAccess.Lock()
|
||||||
|
dialComplete = true
|
||||||
|
stateAccess.Unlock()
|
||||||
|
stopCancel()
|
||||||
|
if err != nil {
|
||||||
|
cancel()
|
||||||
|
return zero, nil, err
|
||||||
|
}
|
||||||
|
return connection, cancel, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
type valueContext struct {
|
||||||
|
context.Context
|
||||||
|
parent context.Context
|
||||||
|
}
|
||||||
|
|
||||||
|
func (v valueContext) Value(key any) any {
|
||||||
|
return v.parent.Value(key)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (v valueContext) Deadline() (time.Time, bool) {
|
||||||
|
return v.parent.Deadline()
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *Connector[T]) Close() error {
|
func (c *Connector[T]) Close() error {
|
||||||
@@ -132,6 +240,10 @@ func (c *Connector[T]) Close() error {
|
|||||||
}
|
}
|
||||||
c.closed = true
|
c.closed = true
|
||||||
|
|
||||||
|
if c.connectionCancel != nil {
|
||||||
|
c.connectionCancel()
|
||||||
|
c.connectionCancel = nil
|
||||||
|
}
|
||||||
if c.hasConnection {
|
if c.hasConnection {
|
||||||
c.callbacks.Close(c.connection)
|
c.callbacks.Close(c.connection)
|
||||||
c.hasConnection = false
|
c.hasConnection = false
|
||||||
@@ -144,6 +256,10 @@ func (c *Connector[T]) Reset() {
|
|||||||
c.access.Lock()
|
c.access.Lock()
|
||||||
defer c.access.Unlock()
|
defer c.access.Unlock()
|
||||||
|
|
||||||
|
if c.connectionCancel != nil {
|
||||||
|
c.connectionCancel()
|
||||||
|
c.connectionCancel = nil
|
||||||
|
}
|
||||||
if c.hasConnection {
|
if c.hasConnection {
|
||||||
c.callbacks.Reset(c.connection)
|
c.callbacks.Reset(c.connection)
|
||||||
c.hasConnection = false
|
c.hasConnection = false
|
||||||
|
|||||||
407
dns/transport/connector_test.go
Normal file
407
dns/transport/connector_test.go
Normal file
@@ -0,0 +1,407 @@
|
|||||||
|
package transport
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"sync/atomic"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
)
|
||||||
|
|
||||||
|
type testConnectorConnection struct{}
|
||||||
|
|
||||||
|
func TestConnectorRecursiveGetFailsFast(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var (
|
||||||
|
dialCount atomic.Int32
|
||||||
|
closeCount atomic.Int32
|
||||||
|
connector *Connector[*testConnectorConnection]
|
||||||
|
)
|
||||||
|
|
||||||
|
dial := func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialCount.Add(1)
|
||||||
|
_, err := connector.Get(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
connector = NewConnector(context.Background(), dial, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {
|
||||||
|
closeCount.Add(1)
|
||||||
|
},
|
||||||
|
Reset: func(connection *testConnectorConnection) {
|
||||||
|
closeCount.Add(1)
|
||||||
|
},
|
||||||
|
})
|
||||||
|
|
||||||
|
_, err := connector.Get(context.Background())
|
||||||
|
require.ErrorIs(t, err, errRecursiveConnectorDial)
|
||||||
|
require.EqualValues(t, 1, dialCount.Load())
|
||||||
|
require.EqualValues(t, 0, closeCount.Load())
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorRecursiveGetAcrossConnectorsAllowed(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var (
|
||||||
|
outerDialCount atomic.Int32
|
||||||
|
innerDialCount atomic.Int32
|
||||||
|
outerConnector *Connector[*testConnectorConnection]
|
||||||
|
innerConnector *Connector[*testConnectorConnection]
|
||||||
|
)
|
||||||
|
|
||||||
|
innerConnector = NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
innerDialCount.Add(1)
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
outerConnector = NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
outerDialCount.Add(1)
|
||||||
|
_, err := innerConnector.Get(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
_, err := outerConnector.Get(context.Background())
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.EqualValues(t, 1, outerDialCount.Load())
|
||||||
|
require.EqualValues(t, 1, innerDialCount.Load())
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorDialContextPreservesValueAndDeadline(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
type contextKey struct{}
|
||||||
|
|
||||||
|
var (
|
||||||
|
dialValue any
|
||||||
|
dialDeadline time.Time
|
||||||
|
dialHasDeadline bool
|
||||||
|
)
|
||||||
|
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialValue = ctx.Value(contextKey{})
|
||||||
|
dialDeadline, dialHasDeadline = ctx.Deadline()
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
deadline := time.Now().Add(time.Minute)
|
||||||
|
requestContext, cancel := context.WithDeadline(context.WithValue(context.Background(), contextKey{}, "test-value"), deadline)
|
||||||
|
defer cancel()
|
||||||
|
|
||||||
|
_, err := connector.Get(requestContext)
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.Equal(t, "test-value", dialValue)
|
||||||
|
require.True(t, dialHasDeadline)
|
||||||
|
require.WithinDuration(t, deadline, dialDeadline, time.Second)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorDialSkipsCanceledRequest(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var dialCount atomic.Int32
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialCount.Add(1)
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
requestContext, cancel := context.WithCancel(context.Background())
|
||||||
|
cancel()
|
||||||
|
|
||||||
|
_, err := connector.Get(requestContext)
|
||||||
|
require.ErrorIs(t, err, context.Canceled)
|
||||||
|
require.EqualValues(t, 0, dialCount.Load())
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorCanceledRequestDoesNotCacheConnection(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var (
|
||||||
|
dialCount atomic.Int32
|
||||||
|
closeCount atomic.Int32
|
||||||
|
)
|
||||||
|
dialStarted := make(chan struct{}, 1)
|
||||||
|
releaseDial := make(chan struct{})
|
||||||
|
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialCount.Add(1)
|
||||||
|
select {
|
||||||
|
case dialStarted <- struct{}{}:
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
<-releaseDial
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {
|
||||||
|
closeCount.Add(1)
|
||||||
|
},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
requestContext, cancel := context.WithCancel(context.Background())
|
||||||
|
result := make(chan error, 1)
|
||||||
|
go func() {
|
||||||
|
_, err := connector.Get(requestContext)
|
||||||
|
result <- err
|
||||||
|
}()
|
||||||
|
|
||||||
|
<-dialStarted
|
||||||
|
cancel()
|
||||||
|
close(releaseDial)
|
||||||
|
|
||||||
|
err := <-result
|
||||||
|
require.ErrorIs(t, err, context.Canceled)
|
||||||
|
require.EqualValues(t, 1, dialCount.Load())
|
||||||
|
require.Eventually(t, func() bool {
|
||||||
|
return closeCount.Load() == 1
|
||||||
|
}, time.Second, 10*time.Millisecond)
|
||||||
|
|
||||||
|
_, err = connector.Get(context.Background())
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.EqualValues(t, 2, dialCount.Load())
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorCanceledRequestReturnsBeforeIgnoredDialCompletes(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var (
|
||||||
|
dialCount atomic.Int32
|
||||||
|
closeCount atomic.Int32
|
||||||
|
)
|
||||||
|
dialStarted := make(chan struct{}, 1)
|
||||||
|
releaseDial := make(chan struct{})
|
||||||
|
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialCount.Add(1)
|
||||||
|
select {
|
||||||
|
case dialStarted <- struct{}{}:
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
<-releaseDial
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {
|
||||||
|
closeCount.Add(1)
|
||||||
|
},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
requestContext, cancel := context.WithCancel(context.Background())
|
||||||
|
result := make(chan error, 1)
|
||||||
|
go func() {
|
||||||
|
_, err := connector.Get(requestContext)
|
||||||
|
result <- err
|
||||||
|
}()
|
||||||
|
|
||||||
|
<-dialStarted
|
||||||
|
cancel()
|
||||||
|
|
||||||
|
select {
|
||||||
|
case err := <-result:
|
||||||
|
require.ErrorIs(t, err, context.Canceled)
|
||||||
|
case <-time.After(time.Second):
|
||||||
|
t.Fatal("Get did not return after request cancel")
|
||||||
|
}
|
||||||
|
|
||||||
|
require.EqualValues(t, 1, dialCount.Load())
|
||||||
|
require.EqualValues(t, 0, closeCount.Load())
|
||||||
|
|
||||||
|
close(releaseDial)
|
||||||
|
|
||||||
|
require.Eventually(t, func() bool {
|
||||||
|
return closeCount.Load() == 1
|
||||||
|
}, time.Second, 10*time.Millisecond)
|
||||||
|
|
||||||
|
_, err := connector.Get(context.Background())
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.EqualValues(t, 2, dialCount.Load())
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorWaiterDoesNotStartNewDialBeforeCanceledDialCompletes(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var (
|
||||||
|
dialCount atomic.Int32
|
||||||
|
closeCount atomic.Int32
|
||||||
|
)
|
||||||
|
firstDialStarted := make(chan struct{}, 1)
|
||||||
|
secondDialStarted := make(chan struct{}, 1)
|
||||||
|
releaseFirstDial := make(chan struct{})
|
||||||
|
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
attempt := dialCount.Add(1)
|
||||||
|
switch attempt {
|
||||||
|
case 1:
|
||||||
|
select {
|
||||||
|
case firstDialStarted <- struct{}{}:
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
<-releaseFirstDial
|
||||||
|
case 2:
|
||||||
|
select {
|
||||||
|
case secondDialStarted <- struct{}{}:
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {
|
||||||
|
closeCount.Add(1)
|
||||||
|
},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
requestContext, cancel := context.WithCancel(context.Background())
|
||||||
|
firstResult := make(chan error, 1)
|
||||||
|
go func() {
|
||||||
|
_, err := connector.Get(requestContext)
|
||||||
|
firstResult <- err
|
||||||
|
}()
|
||||||
|
|
||||||
|
<-firstDialStarted
|
||||||
|
cancel()
|
||||||
|
|
||||||
|
secondResult := make(chan error, 1)
|
||||||
|
go func() {
|
||||||
|
_, err := connector.Get(context.Background())
|
||||||
|
secondResult <- err
|
||||||
|
}()
|
||||||
|
|
||||||
|
select {
|
||||||
|
case <-secondDialStarted:
|
||||||
|
t.Fatal("second dial started before first dial completed")
|
||||||
|
case <-time.After(100 * time.Millisecond):
|
||||||
|
}
|
||||||
|
|
||||||
|
select {
|
||||||
|
case err := <-firstResult:
|
||||||
|
require.ErrorIs(t, err, context.Canceled)
|
||||||
|
case <-time.After(time.Second):
|
||||||
|
t.Fatal("first Get did not return after request cancel")
|
||||||
|
}
|
||||||
|
|
||||||
|
close(releaseFirstDial)
|
||||||
|
|
||||||
|
require.Eventually(t, func() bool {
|
||||||
|
return closeCount.Load() == 1
|
||||||
|
}, time.Second, 10*time.Millisecond)
|
||||||
|
|
||||||
|
select {
|
||||||
|
case <-secondDialStarted:
|
||||||
|
case <-time.After(time.Second):
|
||||||
|
t.Fatal("second dial did not start after first dial completed")
|
||||||
|
}
|
||||||
|
|
||||||
|
err := <-secondResult
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.EqualValues(t, 2, dialCount.Load())
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorDialContextNotCanceledByRequestContextAfterDial(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var dialContext context.Context
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialContext = ctx
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
requestContext, cancel := context.WithCancel(context.Background())
|
||||||
|
_, err := connector.Get(requestContext)
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.NotNil(t, dialContext)
|
||||||
|
|
||||||
|
cancel()
|
||||||
|
|
||||||
|
select {
|
||||||
|
case <-dialContext.Done():
|
||||||
|
t.Fatal("dial context canceled by request context after successful dial")
|
||||||
|
case <-time.After(100 * time.Millisecond):
|
||||||
|
}
|
||||||
|
|
||||||
|
err = connector.Close()
|
||||||
|
require.NoError(t, err)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConnectorDialContextCanceledOnClose(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
var dialContext context.Context
|
||||||
|
connector := NewConnector(context.Background(), func(ctx context.Context) (*testConnectorConnection, error) {
|
||||||
|
dialContext = ctx
|
||||||
|
return &testConnectorConnection{}, nil
|
||||||
|
}, ConnectorCallbacks[*testConnectorConnection]{
|
||||||
|
IsClosed: func(connection *testConnectorConnection) bool {
|
||||||
|
return false
|
||||||
|
},
|
||||||
|
Close: func(connection *testConnectorConnection) {},
|
||||||
|
Reset: func(connection *testConnectorConnection) {},
|
||||||
|
})
|
||||||
|
|
||||||
|
_, err := connector.Get(context.Background())
|
||||||
|
require.NoError(t, err)
|
||||||
|
require.NotNil(t, dialContext)
|
||||||
|
|
||||||
|
select {
|
||||||
|
case <-dialContext.Done():
|
||||||
|
t.Fatal("dial context canceled before connector close")
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
|
||||||
|
err = connector.Close()
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
select {
|
||||||
|
case <-dialContext.Done():
|
||||||
|
case <-time.After(time.Second):
|
||||||
|
t.Fatal("dial context not canceled after connector close")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -7,7 +7,6 @@ import (
|
|||||||
"strings"
|
"strings"
|
||||||
"syscall"
|
"syscall"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/dns"
|
|
||||||
"github.com/sagernet/sing-box/dns/transport"
|
"github.com/sagernet/sing-box/dns/transport"
|
||||||
"github.com/sagernet/sing/common/buf"
|
"github.com/sagernet/sing/common/buf"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
@@ -40,13 +39,6 @@ func (t *Transport) exchangeParallel(ctx context.Context, servers []M.Socksaddr,
|
|||||||
results := make(chan queryResult)
|
results := make(chan queryResult)
|
||||||
startRacer := func(ctx context.Context, fqdn string) {
|
startRacer := func(ctx context.Context, fqdn string) {
|
||||||
response, err := t.tryOneName(ctx, servers, fqdn, message)
|
response, err := t.tryOneName(ctx, servers, fqdn, message)
|
||||||
if err == nil {
|
|
||||||
if response.Rcode != mDNS.RcodeSuccess {
|
|
||||||
err = dns.RcodeError(response.Rcode)
|
|
||||||
} else if len(dns.MessageToAddresses(response)) == 0 {
|
|
||||||
err = dns.RcodeSuccess
|
|
||||||
}
|
|
||||||
}
|
|
||||||
select {
|
select {
|
||||||
case results <- queryResult{response, err}:
|
case results <- queryResult{response, err}:
|
||||||
case <-returned:
|
case <-returned:
|
||||||
|
|||||||
@@ -18,6 +18,8 @@ type Store struct {
|
|||||||
logger logger.Logger
|
logger logger.Logger
|
||||||
inet4Range netip.Prefix
|
inet4Range netip.Prefix
|
||||||
inet6Range netip.Prefix
|
inet6Range netip.Prefix
|
||||||
|
inet4Last netip.Addr
|
||||||
|
inet6Last netip.Addr
|
||||||
storage adapter.FakeIPStorage
|
storage adapter.FakeIPStorage
|
||||||
|
|
||||||
addressAccess sync.Mutex
|
addressAccess sync.Mutex
|
||||||
@@ -26,12 +28,35 @@ type Store struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func NewStore(ctx context.Context, logger logger.Logger, inet4Range netip.Prefix, inet6Range netip.Prefix) *Store {
|
func NewStore(ctx context.Context, logger logger.Logger, inet4Range netip.Prefix, inet6Range netip.Prefix) *Store {
|
||||||
return &Store{
|
store := &Store{
|
||||||
ctx: ctx,
|
ctx: ctx,
|
||||||
logger: logger,
|
logger: logger,
|
||||||
inet4Range: inet4Range,
|
inet4Range: inet4Range,
|
||||||
inet6Range: inet6Range,
|
inet6Range: inet6Range,
|
||||||
}
|
}
|
||||||
|
if inet4Range.IsValid() {
|
||||||
|
store.inet4Last = broadcastAddress(inet4Range)
|
||||||
|
}
|
||||||
|
if inet6Range.IsValid() {
|
||||||
|
store.inet6Last = broadcastAddress(inet6Range)
|
||||||
|
}
|
||||||
|
return store
|
||||||
|
}
|
||||||
|
|
||||||
|
func broadcastAddress(prefix netip.Prefix) netip.Addr {
|
||||||
|
addr := prefix.Addr()
|
||||||
|
raw := addr.As16()
|
||||||
|
bits := prefix.Bits()
|
||||||
|
if addr.Is4() {
|
||||||
|
bits += 96
|
||||||
|
}
|
||||||
|
for i := bits; i < 128; i++ {
|
||||||
|
raw[i/8] |= 1 << (7 - i%8)
|
||||||
|
}
|
||||||
|
if addr.Is4() {
|
||||||
|
return netip.AddrFrom4([4]byte(raw[12:]))
|
||||||
|
}
|
||||||
|
return netip.AddrFrom16(raw)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *Store) Start() error {
|
func (s *Store) Start() error {
|
||||||
@@ -49,10 +74,10 @@ func (s *Store) Start() error {
|
|||||||
s.inet6Current = metadata.Inet6Current
|
s.inet6Current = metadata.Inet6Current
|
||||||
} else {
|
} else {
|
||||||
if s.inet4Range.IsValid() {
|
if s.inet4Range.IsValid() {
|
||||||
s.inet4Current = s.inet4Range.Addr().Next().Next()
|
s.inet4Current = s.inet4Range.Addr().Next()
|
||||||
}
|
}
|
||||||
if s.inet6Range.IsValid() {
|
if s.inet6Range.IsValid() {
|
||||||
s.inet6Current = s.inet6Range.Addr().Next().Next()
|
s.inet6Current = s.inet6Range.Addr().Next()
|
||||||
}
|
}
|
||||||
_ = storage.FakeIPReset()
|
_ = storage.FakeIPReset()
|
||||||
}
|
}
|
||||||
@@ -98,7 +123,7 @@ func (s *Store) Create(domain string, isIPv6 bool) (netip.Addr, error) {
|
|||||||
return netip.Addr{}, E.New("missing IPv4 fakeip address range")
|
return netip.Addr{}, E.New("missing IPv4 fakeip address range")
|
||||||
}
|
}
|
||||||
nextAddress := s.inet4Current.Next()
|
nextAddress := s.inet4Current.Next()
|
||||||
if !s.inet4Range.Contains(nextAddress) {
|
if nextAddress == s.inet4Last || !s.inet4Range.Contains(nextAddress) {
|
||||||
nextAddress = s.inet4Range.Addr().Next().Next()
|
nextAddress = s.inet4Range.Addr().Next().Next()
|
||||||
}
|
}
|
||||||
s.inet4Current = nextAddress
|
s.inet4Current = nextAddress
|
||||||
@@ -108,7 +133,7 @@ func (s *Store) Create(domain string, isIPv6 bool) (netip.Addr, error) {
|
|||||||
return netip.Addr{}, E.New("missing IPv6 fakeip address range")
|
return netip.Addr{}, E.New("missing IPv6 fakeip address range")
|
||||||
}
|
}
|
||||||
nextAddress := s.inet6Current.Next()
|
nextAddress := s.inet6Current.Next()
|
||||||
if !s.inet6Range.Contains(nextAddress) {
|
if nextAddress == s.inet6Last || !s.inet6Range.Contains(nextAddress) {
|
||||||
nextAddress = s.inet6Range.Addr().Next().Next()
|
nextAddress = s.inet6Range.Addr().Next().Next()
|
||||||
}
|
}
|
||||||
s.inet6Current = nextAddress
|
s.inet6Current = nextAddress
|
||||||
|
|||||||
@@ -81,10 +81,7 @@ func (t *Transport) Reset() {
|
|||||||
|
|
||||||
func (t *Transport) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
|
func (t *Transport) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
|
||||||
if t.resolved != nil {
|
if t.resolved != nil {
|
||||||
resolverObject := t.resolved.Object()
|
return t.resolved.Exchange(ctx, message)
|
||||||
if resolverObject != nil {
|
|
||||||
return t.resolved.Exchange(resolverObject, ctx, message)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
question := message.Question[0]
|
question := message.Question[0]
|
||||||
if question.Qtype == mDNS.TypeA || question.Qtype == mDNS.TypeAAAA {
|
if question.Qtype == mDNS.TypeA || question.Qtype == mDNS.TypeAAAA {
|
||||||
|
|||||||
@@ -9,6 +9,5 @@ import (
|
|||||||
type ResolvedResolver interface {
|
type ResolvedResolver interface {
|
||||||
Start() error
|
Start() error
|
||||||
Close() error
|
Close() error
|
||||||
Object() any
|
Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error)
|
||||||
Exchange(object any, ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error)
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,19 +4,26 @@ import (
|
|||||||
"bufio"
|
"bufio"
|
||||||
"context"
|
"context"
|
||||||
"errors"
|
"errors"
|
||||||
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
"strings"
|
"strings"
|
||||||
"sync"
|
"sync"
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
|
"github.com/sagernet/sing-box/common/dialer"
|
||||||
|
"github.com/sagernet/sing-box/common/tls"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
|
"github.com/sagernet/sing-box/dns"
|
||||||
|
dnsTransport "github.com/sagernet/sing-box/dns/transport"
|
||||||
|
"github.com/sagernet/sing-box/option"
|
||||||
"github.com/sagernet/sing-box/service/resolved"
|
"github.com/sagernet/sing-box/service/resolved"
|
||||||
"github.com/sagernet/sing-tun"
|
"github.com/sagernet/sing-tun"
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
"github.com/sagernet/sing/common/control"
|
"github.com/sagernet/sing/common/control"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
"github.com/sagernet/sing/common/logger"
|
"github.com/sagernet/sing/common/logger"
|
||||||
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
|
N "github.com/sagernet/sing/common/network"
|
||||||
"github.com/sagernet/sing/common/x/list"
|
"github.com/sagernet/sing/common/x/list"
|
||||||
"github.com/sagernet/sing/service"
|
"github.com/sagernet/sing/service"
|
||||||
|
|
||||||
@@ -49,13 +56,23 @@ type DBusResolvedResolver struct {
|
|||||||
interfaceMonitor tun.DefaultInterfaceMonitor
|
interfaceMonitor tun.DefaultInterfaceMonitor
|
||||||
interfaceCallback *list.Element[tun.DefaultInterfaceUpdateCallback]
|
interfaceCallback *list.Element[tun.DefaultInterfaceUpdateCallback]
|
||||||
systemBus *dbus.Conn
|
systemBus *dbus.Conn
|
||||||
resoledObject atomic.Pointer[ResolvedObject]
|
savedServerSet atomic.Pointer[resolvedServerSet]
|
||||||
closeOnce sync.Once
|
closeOnce sync.Once
|
||||||
}
|
}
|
||||||
|
|
||||||
type ResolvedObject struct {
|
type resolvedServerSet struct {
|
||||||
dbus.BusObject
|
servers []resolvedServer
|
||||||
InterfaceIndex int32
|
}
|
||||||
|
|
||||||
|
type resolvedServer struct {
|
||||||
|
primaryTransport adapter.DNSTransport
|
||||||
|
fallbackTransport adapter.DNSTransport
|
||||||
|
}
|
||||||
|
|
||||||
|
type resolvedServerSpecification struct {
|
||||||
|
address netip.Addr
|
||||||
|
port uint16
|
||||||
|
serverName string
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewResolvedResolver(ctx context.Context, logger logger.ContextLogger) (ResolvedResolver, error) {
|
func NewResolvedResolver(ctx context.Context, logger logger.ContextLogger) (ResolvedResolver, error) {
|
||||||
@@ -82,17 +99,31 @@ func (t *DBusResolvedResolver) Start() error {
|
|||||||
"org.freedesktop.DBus",
|
"org.freedesktop.DBus",
|
||||||
"NameOwnerChanged",
|
"NameOwnerChanged",
|
||||||
dbus.WithMatchSender("org.freedesktop.DBus"),
|
dbus.WithMatchSender("org.freedesktop.DBus"),
|
||||||
dbus.WithMatchArg(0, "org.freedesktop.resolve1.Manager"),
|
dbus.WithMatchArg(0, "org.freedesktop.resolve1"),
|
||||||
).Err
|
).Err
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return E.Cause(err, "configure resolved restart listener")
|
return E.Cause(err, "configure resolved restart listener")
|
||||||
}
|
}
|
||||||
|
err = t.systemBus.BusObject().AddMatchSignal(
|
||||||
|
"org.freedesktop.DBus.Properties",
|
||||||
|
"PropertiesChanged",
|
||||||
|
dbus.WithMatchSender("org.freedesktop.resolve1"),
|
||||||
|
dbus.WithMatchArg(0, "org.freedesktop.resolve1.Manager"),
|
||||||
|
).Err
|
||||||
|
if err != nil {
|
||||||
|
return E.Cause(err, "configure resolved properties listener")
|
||||||
|
}
|
||||||
go t.loopUpdateStatus()
|
go t.loopUpdateStatus()
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *DBusResolvedResolver) Close() error {
|
func (t *DBusResolvedResolver) Close() error {
|
||||||
|
var closeErr error
|
||||||
t.closeOnce.Do(func() {
|
t.closeOnce.Do(func() {
|
||||||
|
serverSet := t.savedServerSet.Swap(nil)
|
||||||
|
if serverSet != nil {
|
||||||
|
closeErr = serverSet.Close()
|
||||||
|
}
|
||||||
if t.interfaceCallback != nil {
|
if t.interfaceCallback != nil {
|
||||||
t.interfaceMonitor.UnregisterCallback(t.interfaceCallback)
|
t.interfaceMonitor.UnregisterCallback(t.interfaceCallback)
|
||||||
}
|
}
|
||||||
@@ -100,99 +131,97 @@ func (t *DBusResolvedResolver) Close() error {
|
|||||||
_ = t.systemBus.Close()
|
_ = t.systemBus.Close()
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
return nil
|
return closeErr
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *DBusResolvedResolver) Object() any {
|
func (t *DBusResolvedResolver) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
|
||||||
return common.PtrOrNil(t.resoledObject.Load())
|
serverSet := t.savedServerSet.Load()
|
||||||
}
|
if serverSet == nil {
|
||||||
|
var err error
|
||||||
func (t *DBusResolvedResolver) Exchange(object any, ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
|
serverSet, err = t.checkResolved(context.Background())
|
||||||
question := message.Question[0]
|
if err != nil {
|
||||||
resolvedObject := object.(*ResolvedObject)
|
return nil, err
|
||||||
call := resolvedObject.CallWithContext(
|
}
|
||||||
ctx,
|
previousServerSet := t.savedServerSet.Swap(serverSet)
|
||||||
"org.freedesktop.resolve1.Manager.ResolveRecord",
|
if previousServerSet != nil {
|
||||||
0,
|
_ = previousServerSet.Close()
|
||||||
resolvedObject.InterfaceIndex,
|
|
||||||
question.Name,
|
|
||||||
question.Qclass,
|
|
||||||
question.Qtype,
|
|
||||||
uint64(0),
|
|
||||||
)
|
|
||||||
if call.Err != nil {
|
|
||||||
var dbusError dbus.Error
|
|
||||||
if errors.As(call.Err, &dbusError) && dbusError.Name == "org.freedesktop.resolve1.NoNameServers" {
|
|
||||||
t.updateStatus()
|
|
||||||
}
|
}
|
||||||
return nil, E.Cause(call.Err, " resolve record via resolved")
|
|
||||||
}
|
}
|
||||||
var (
|
response, err := t.exchangeServerSet(ctx, message, serverSet)
|
||||||
records []resolved.ResourceRecord
|
if err == nil {
|
||||||
outflags uint64
|
return response, nil
|
||||||
)
|
}
|
||||||
err := call.Store(&records, &outflags)
|
t.updateStatus()
|
||||||
if err != nil {
|
refreshedServerSet := t.savedServerSet.Load()
|
||||||
|
if refreshedServerSet == nil || refreshedServerSet == serverSet {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
response := &mDNS.Msg{
|
return t.exchangeServerSet(ctx, message, refreshedServerSet)
|
||||||
MsgHdr: mDNS.MsgHdr{
|
|
||||||
Id: message.Id,
|
|
||||||
Response: true,
|
|
||||||
Authoritative: true,
|
|
||||||
RecursionDesired: true,
|
|
||||||
RecursionAvailable: true,
|
|
||||||
Rcode: mDNS.RcodeSuccess,
|
|
||||||
},
|
|
||||||
Question: []mDNS.Question{question},
|
|
||||||
}
|
|
||||||
for _, record := range records {
|
|
||||||
var rr mDNS.RR
|
|
||||||
rr, _, err = mDNS.UnpackRR(record.Data, 0)
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "unpack resource record")
|
|
||||||
}
|
|
||||||
response.Answer = append(response.Answer, rr)
|
|
||||||
}
|
|
||||||
return response, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *DBusResolvedResolver) loopUpdateStatus() {
|
func (t *DBusResolvedResolver) loopUpdateStatus() {
|
||||||
signalChan := make(chan *dbus.Signal, 1)
|
signalChan := make(chan *dbus.Signal, 1)
|
||||||
t.systemBus.Signal(signalChan)
|
t.systemBus.Signal(signalChan)
|
||||||
for signal := range signalChan {
|
for signal := range signalChan {
|
||||||
var restarted bool
|
switch signal.Name {
|
||||||
if signal.Name == "org.freedesktop.DBus.NameOwnerChanged" {
|
case "org.freedesktop.DBus.NameOwnerChanged":
|
||||||
if len(signal.Body) != 3 || signal.Body[2].(string) == "" {
|
if len(signal.Body) != 3 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
newOwner, loaded := signal.Body[2].(string)
|
||||||
|
if !loaded || newOwner == "" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
t.updateStatus()
|
||||||
|
case "org.freedesktop.DBus.Properties.PropertiesChanged":
|
||||||
|
if !shouldUpdateResolvedServerSet(signal) {
|
||||||
continue
|
continue
|
||||||
} else {
|
|
||||||
restarted = true
|
|
||||||
}
|
}
|
||||||
}
|
|
||||||
if restarted {
|
|
||||||
t.updateStatus()
|
t.updateStatus()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *DBusResolvedResolver) updateStatus() {
|
func (t *DBusResolvedResolver) updateStatus() {
|
||||||
dbusObject, err := t.checkResolved(context.Background())
|
serverSet, err := t.checkResolved(context.Background())
|
||||||
oldValue := t.resoledObject.Swap(dbusObject)
|
oldServerSet := t.savedServerSet.Swap(serverSet)
|
||||||
|
if oldServerSet != nil {
|
||||||
|
_ = oldServerSet.Close()
|
||||||
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
var dbusErr dbus.Error
|
var dbusErr dbus.Error
|
||||||
if !errors.As(err, &dbusErr) || dbusErr.Name != "org.freedesktop.DBus.Error.NameHasNoOwnerCould" {
|
if !errors.As(err, &dbusErr) || dbusErr.Name != "org.freedesktop.DBus.Error.NameHasNoOwner" {
|
||||||
t.logger.Debug(E.Cause(err, "systemd-resolved service unavailable"))
|
t.logger.Debug(E.Cause(err, "systemd-resolved service unavailable"))
|
||||||
}
|
}
|
||||||
if oldValue != nil {
|
if oldServerSet != nil {
|
||||||
t.logger.Debug("systemd-resolved service is gone")
|
t.logger.Debug("systemd-resolved service is gone")
|
||||||
}
|
}
|
||||||
return
|
return
|
||||||
} else if oldValue == nil {
|
} else if oldServerSet == nil {
|
||||||
t.logger.Debug("using systemd-resolved service as resolver")
|
t.logger.Debug("using systemd-resolved service as resolver")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *DBusResolvedResolver) checkResolved(ctx context.Context) (*ResolvedObject, error) {
|
func (t *DBusResolvedResolver) exchangeServerSet(ctx context.Context, message *mDNS.Msg, serverSet *resolvedServerSet) (*mDNS.Msg, error) {
|
||||||
|
if serverSet == nil || len(serverSet.servers) == 0 {
|
||||||
|
return nil, E.New("link has no DNS servers configured")
|
||||||
|
}
|
||||||
|
var lastError error
|
||||||
|
for _, server := range serverSet.servers {
|
||||||
|
response, err := server.primaryTransport.Exchange(ctx, message)
|
||||||
|
if err != nil && server.fallbackTransport != nil {
|
||||||
|
response, err = server.fallbackTransport.Exchange(ctx, message)
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
lastError = err
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
return response, nil
|
||||||
|
}
|
||||||
|
return nil, lastError
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *DBusResolvedResolver) checkResolved(ctx context.Context) (*resolvedServerSet, error) {
|
||||||
dbusObject := t.systemBus.Object("org.freedesktop.resolve1", "/org/freedesktop/resolve1")
|
dbusObject := t.systemBus.Object("org.freedesktop.resolve1", "/org/freedesktop/resolve1")
|
||||||
err := dbusObject.Call("org.freedesktop.DBus.Peer.Ping", 0).Err
|
err := dbusObject.Call("org.freedesktop.DBus.Peer.Ping", 0).Err
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -220,16 +249,19 @@ func (t *DBusResolvedResolver) checkResolved(ctx context.Context) (*ResolvedObje
|
|||||||
if linkObject == nil {
|
if linkObject == nil {
|
||||||
return nil, E.New("missing link object for default interface")
|
return nil, E.New("missing link object for default interface")
|
||||||
}
|
}
|
||||||
dnsProp, err := linkObject.GetProperty("org.freedesktop.resolve1.Link.DNS")
|
dnsOverTLSMode, err := loadResolvedLinkDNSOverTLS(linkObject)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
var linkDNS []resolved.LinkDNS
|
linkDNSEx, err := loadResolvedLinkDNSEx(linkObject)
|
||||||
err = dnsProp.Store(&linkDNS)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if len(linkDNS) == 0 {
|
linkDNS, err := loadResolvedLinkDNS(linkObject)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if len(linkDNSEx) == 0 && len(linkDNS) == 0 {
|
||||||
for _, inbound := range service.FromContext[adapter.InboundManager](t.ctx).Inbounds() {
|
for _, inbound := range service.FromContext[adapter.InboundManager](t.ctx).Inbounds() {
|
||||||
if inbound.Type() == C.TypeTun {
|
if inbound.Type() == C.TypeTun {
|
||||||
return nil, E.New("No appropriate name servers or networks for name found")
|
return nil, E.New("No appropriate name servers or networks for name found")
|
||||||
@@ -237,12 +269,233 @@ func (t *DBusResolvedResolver) checkResolved(ctx context.Context) (*ResolvedObje
|
|||||||
}
|
}
|
||||||
return nil, E.New("link has no DNS servers configured")
|
return nil, E.New("link has no DNS servers configured")
|
||||||
}
|
}
|
||||||
return &ResolvedObject{
|
serverDialer, err := dialer.NewDefault(t.ctx, option.DialerOptions{
|
||||||
BusObject: dbusObject,
|
BindInterface: defaultInterface.Name,
|
||||||
InterfaceIndex: int32(defaultInterface.Index),
|
UDPFragmentDefault: true,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
var serverSpecifications []resolvedServerSpecification
|
||||||
|
if len(linkDNSEx) > 0 {
|
||||||
|
for _, entry := range linkDNSEx {
|
||||||
|
serverSpecification, loaded := buildResolvedServerSpecification(defaultInterface.Name, entry.Address, entry.Port, entry.Name)
|
||||||
|
if !loaded {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
serverSpecifications = append(serverSpecifications, serverSpecification)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
for _, entry := range linkDNS {
|
||||||
|
serverSpecification, loaded := buildResolvedServerSpecification(defaultInterface.Name, entry.Address, 0, "")
|
||||||
|
if !loaded {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
serverSpecifications = append(serverSpecifications, serverSpecification)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(serverSpecifications) == 0 {
|
||||||
|
return nil, E.New("no valid DNS servers on link")
|
||||||
|
}
|
||||||
|
serverSet := &resolvedServerSet{
|
||||||
|
servers: make([]resolvedServer, 0, len(serverSpecifications)),
|
||||||
|
}
|
||||||
|
for _, serverSpecification := range serverSpecifications {
|
||||||
|
server, createErr := t.createResolvedServer(serverDialer, dnsOverTLSMode, serverSpecification)
|
||||||
|
if createErr != nil {
|
||||||
|
_ = serverSet.Close()
|
||||||
|
return nil, createErr
|
||||||
|
}
|
||||||
|
serverSet.servers = append(serverSet.servers, server)
|
||||||
|
}
|
||||||
|
return serverSet, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *DBusResolvedResolver) createResolvedServer(serverDialer N.Dialer, dnsOverTLSMode string, serverSpecification resolvedServerSpecification) (resolvedServer, error) {
|
||||||
|
if dnsOverTLSMode == "yes" {
|
||||||
|
primaryTransport, err := t.createResolvedTransport(serverDialer, serverSpecification, true)
|
||||||
|
if err != nil {
|
||||||
|
return resolvedServer{}, err
|
||||||
|
}
|
||||||
|
return resolvedServer{
|
||||||
|
primaryTransport: primaryTransport,
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
if dnsOverTLSMode == "opportunistic" {
|
||||||
|
primaryTransport, err := t.createResolvedTransport(serverDialer, serverSpecification, true)
|
||||||
|
if err != nil {
|
||||||
|
return resolvedServer{}, err
|
||||||
|
}
|
||||||
|
fallbackTransport, err := t.createResolvedTransport(serverDialer, serverSpecification, false)
|
||||||
|
if err != nil {
|
||||||
|
_ = primaryTransport.Close()
|
||||||
|
return resolvedServer{}, err
|
||||||
|
}
|
||||||
|
return resolvedServer{
|
||||||
|
primaryTransport: primaryTransport,
|
||||||
|
fallbackTransport: fallbackTransport,
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
primaryTransport, err := t.createResolvedTransport(serverDialer, serverSpecification, false)
|
||||||
|
if err != nil {
|
||||||
|
return resolvedServer{}, err
|
||||||
|
}
|
||||||
|
return resolvedServer{
|
||||||
|
primaryTransport: primaryTransport,
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (t *DBusResolvedResolver) createResolvedTransport(serverDialer N.Dialer, serverSpecification resolvedServerSpecification, useTLS bool) (adapter.DNSTransport, error) {
|
||||||
|
serverAddress := M.SocksaddrFrom(serverSpecification.address, resolvedServerPort(serverSpecification.port, useTLS))
|
||||||
|
if useTLS {
|
||||||
|
tlsAddress := serverSpecification.address
|
||||||
|
if tlsAddress.Zone() != "" {
|
||||||
|
tlsAddress = tlsAddress.WithZone("")
|
||||||
|
}
|
||||||
|
serverName := serverSpecification.serverName
|
||||||
|
if serverName == "" {
|
||||||
|
serverName = tlsAddress.String()
|
||||||
|
}
|
||||||
|
tlsConfig, err := tls.NewClient(t.ctx, t.logger, tlsAddress.String(), option.OutboundTLSOptions{
|
||||||
|
Enabled: true,
|
||||||
|
ServerName: serverName,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
serverTransport := dnsTransport.NewTLSRaw(t.logger, dns.NewTransportAdapter(C.DNSTypeTLS, "", nil), serverDialer, serverAddress, tlsConfig)
|
||||||
|
err = serverTransport.Start(adapter.StartStateStart)
|
||||||
|
if err != nil {
|
||||||
|
_ = serverTransport.Close()
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return serverTransport, nil
|
||||||
|
}
|
||||||
|
serverTransport := dnsTransport.NewUDPRaw(t.logger, dns.NewTransportAdapter(C.DNSTypeUDP, "", nil), serverDialer, serverAddress)
|
||||||
|
err := serverTransport.Start(adapter.StartStateStart)
|
||||||
|
if err != nil {
|
||||||
|
_ = serverTransport.Close()
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return serverTransport, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *resolvedServerSet) Close() error {
|
||||||
|
var errors []error
|
||||||
|
for _, server := range s.servers {
|
||||||
|
errors = append(errors, server.primaryTransport.Close())
|
||||||
|
if server.fallbackTransport != nil {
|
||||||
|
errors = append(errors, server.fallbackTransport.Close())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return E.Errors(errors...)
|
||||||
|
}
|
||||||
|
|
||||||
|
func buildResolvedServerSpecification(interfaceName string, rawAddress []byte, port uint16, serverName string) (resolvedServerSpecification, bool) {
|
||||||
|
address, loaded := netip.AddrFromSlice(rawAddress)
|
||||||
|
if !loaded {
|
||||||
|
return resolvedServerSpecification{}, false
|
||||||
|
}
|
||||||
|
if address.Is6() && address.IsLinkLocalUnicast() && address.Zone() == "" {
|
||||||
|
address = address.WithZone(interfaceName)
|
||||||
|
}
|
||||||
|
return resolvedServerSpecification{
|
||||||
|
address: address,
|
||||||
|
port: port,
|
||||||
|
serverName: serverName,
|
||||||
|
}, true
|
||||||
|
}
|
||||||
|
|
||||||
|
func resolvedServerPort(port uint16, useTLS bool) uint16 {
|
||||||
|
if port > 0 {
|
||||||
|
return port
|
||||||
|
}
|
||||||
|
if useTLS {
|
||||||
|
return 853
|
||||||
|
}
|
||||||
|
return 53
|
||||||
|
}
|
||||||
|
|
||||||
|
func loadResolvedLinkDNS(linkObject dbus.BusObject) ([]resolved.LinkDNS, error) {
|
||||||
|
dnsProperty, err := linkObject.GetProperty("org.freedesktop.resolve1.Link.DNS")
|
||||||
|
if err != nil {
|
||||||
|
if isResolvedUnknownPropertyError(err) {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
var linkDNS []resolved.LinkDNS
|
||||||
|
err = dnsProperty.Store(&linkDNS)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return linkDNS, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func loadResolvedLinkDNSEx(linkObject dbus.BusObject) ([]resolved.LinkDNSEx, error) {
|
||||||
|
dnsProperty, err := linkObject.GetProperty("org.freedesktop.resolve1.Link.DNSEx")
|
||||||
|
if err != nil {
|
||||||
|
if isResolvedUnknownPropertyError(err) {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
var linkDNSEx []resolved.LinkDNSEx
|
||||||
|
err = dnsProperty.Store(&linkDNSEx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return linkDNSEx, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func loadResolvedLinkDNSOverTLS(linkObject dbus.BusObject) (string, error) {
|
||||||
|
dnsOverTLSProperty, err := linkObject.GetProperty("org.freedesktop.resolve1.Link.DNSOverTLS")
|
||||||
|
if err != nil {
|
||||||
|
if isResolvedUnknownPropertyError(err) {
|
||||||
|
return "", nil
|
||||||
|
}
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
var dnsOverTLSMode string
|
||||||
|
err = dnsOverTLSProperty.Store(&dnsOverTLSMode)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
return dnsOverTLSMode, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func isResolvedUnknownPropertyError(err error) bool {
|
||||||
|
var dbusError dbus.Error
|
||||||
|
return errors.As(err, &dbusError) && dbusError.Name == "org.freedesktop.DBus.Error.UnknownProperty"
|
||||||
|
}
|
||||||
|
|
||||||
|
func shouldUpdateResolvedServerSet(signal *dbus.Signal) bool {
|
||||||
|
if len(signal.Body) != 3 {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
changedProperties, loaded := signal.Body[1].(map[string]dbus.Variant)
|
||||||
|
if !loaded {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
for propertyName := range changedProperties {
|
||||||
|
switch propertyName {
|
||||||
|
case "DNS", "DNSEx", "DNSOverTLS":
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
invalidatedProperties, loaded := signal.Body[2].([]string)
|
||||||
|
if !loaded {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
for _, propertyName := range invalidatedProperties {
|
||||||
|
switch propertyName {
|
||||||
|
case "DNS", "DNSEx", "DNSOverTLS":
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
func (t *DBusResolvedResolver) updateDefaultInterface(defaultInterface *control.Interface, flags int) {
|
func (t *DBusResolvedResolver) updateDefaultInterface(defaultInterface *control.Interface, flags int) {
|
||||||
t.updateStatus()
|
t.updateStatus()
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import (
|
|||||||
"syscall"
|
"syscall"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/dns"
|
|
||||||
"github.com/sagernet/sing-box/dns/transport"
|
"github.com/sagernet/sing-box/dns/transport"
|
||||||
"github.com/sagernet/sing/common/buf"
|
"github.com/sagernet/sing/common/buf"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
@@ -49,13 +48,6 @@ func (t *Transport) exchangeParallel(ctx context.Context, systemConfig *dnsConfi
|
|||||||
results := make(chan queryResult)
|
results := make(chan queryResult)
|
||||||
startRacer := func(ctx context.Context, fqdn string) {
|
startRacer := func(ctx context.Context, fqdn string) {
|
||||||
response, err := t.tryOneName(ctx, systemConfig, fqdn, message)
|
response, err := t.tryOneName(ctx, systemConfig, fqdn, message)
|
||||||
if err == nil {
|
|
||||||
if response.Rcode != mDNS.RcodeSuccess {
|
|
||||||
err = dns.RcodeError(response.Rcode)
|
|
||||||
} else if len(dns.MessageToAddresses(response)) == 0 {
|
|
||||||
err = E.New(fqdn, ": empty result")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
select {
|
select {
|
||||||
case results <- queryResult{response, err}:
|
case results <- queryResult{response, err}:
|
||||||
case <-returned:
|
case <-returned:
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import (
|
|||||||
"net"
|
"net"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
|
"strconv"
|
||||||
"syscall"
|
"syscall"
|
||||||
"time"
|
"time"
|
||||||
"unsafe"
|
"unsafe"
|
||||||
@@ -63,6 +64,9 @@ func dnsReadConfig(ctx context.Context, _ string) *dnsConfig {
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
dnsServerAddr = netip.AddrFrom16(sockaddr.Addr)
|
dnsServerAddr = netip.AddrFrom16(sockaddr.Addr)
|
||||||
|
if sockaddr.ZoneId != 0 {
|
||||||
|
dnsServerAddr = dnsServerAddr.WithZone(strconv.FormatInt(int64(sockaddr.ZoneId), 10))
|
||||||
|
}
|
||||||
default:
|
default:
|
||||||
// Unexpected type.
|
// Unexpected type.
|
||||||
continue
|
continue
|
||||||
|
|||||||
@@ -2,6 +2,306 @@
|
|||||||
icon: material/alert-decagram
|
icon: material/alert-decagram
|
||||||
---
|
---
|
||||||
|
|
||||||
|
#### 1.13.6
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.5
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.4
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.3
|
||||||
|
|
||||||
|
* Add OpenWrt and Alpine APK packages to release **1**
|
||||||
|
* Backport to macOS 10.13 High Sierra **2**
|
||||||
|
* OCM service: Add WebSocket support for Responses API **3**
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
**1**:
|
||||||
|
|
||||||
|
Alpine APK files use `linux` in the filename to distinguish from OpenWrt APKs which use the `openwrt` prefix:
|
||||||
|
|
||||||
|
- OpenWrt: `sing-box_{version}_openwrt_{architecture}.apk`
|
||||||
|
- Alpine: `sing-box_{version}_linux_{architecture}.apk`
|
||||||
|
|
||||||
|
**2**:
|
||||||
|
|
||||||
|
Legacy macOS binaries (with `-legacy-macos-10.13` suffix) now support
|
||||||
|
macOS 10.13 High Sierra, built using Go 1.25 with patches
|
||||||
|
from [SagerNet/go](https://github.com/SagerNet/go).
|
||||||
|
|
||||||
|
**3**:
|
||||||
|
|
||||||
|
See [OCM](/configuration/service/ocm).
|
||||||
|
|
||||||
|
#### 1.13.2
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.1
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.12.14
|
||||||
|
|
||||||
|
* Backport fixes
|
||||||
|
|
||||||
|
#### 1.13.0
|
||||||
|
|
||||||
|
Important changes since 1.12:
|
||||||
|
|
||||||
|
* Add NaiveProxy outbound **1**
|
||||||
|
* Add pre-match support for `auto_redirect` **2**
|
||||||
|
* Improve `auto_redirect` **3**
|
||||||
|
* Add Chrome Root Store certificate option **4**
|
||||||
|
* Add new options for ACME DNS-01 challenge providers **5**
|
||||||
|
* Add Wi-Fi state support for Linux and Windows **6**
|
||||||
|
* Add curve preferences, pinned public key SHA256, mTLS and ECH `query_server_name` for TLS options **7**
|
||||||
|
* Add kTLS support **8**
|
||||||
|
* Add ICMP echo (ping) proxy support **9**
|
||||||
|
* Add `interface_address`, `network_interface_address` and `default_interface_address` rule items **10**
|
||||||
|
* Add `preferred_by` route rule item **11**
|
||||||
|
* Improve `local` DNS server **12**
|
||||||
|
* Add `disable_tcp_keep_alive`, `tcp_keep_alive` and `tcp_keep_alive_interval` options for listen and dial fields **13**
|
||||||
|
* Add `bind_address_no_port` option for dial fields **14**
|
||||||
|
* Add system interface, relay server and advertise tags options for Tailscale endpoint **15**
|
||||||
|
* Add Claude Code Multiplexer service **16**
|
||||||
|
* Add OpenAI Codex Multiplexer service **17**
|
||||||
|
* Apple/Android: Refactor GUI
|
||||||
|
* Apple/Android: Add support for sharing configurations via [QRS](https://github.com/qifi-dev/qrs)
|
||||||
|
* Android: Add support for resisting VPN detection via Xposed
|
||||||
|
* Drop support for go1.23 **18**
|
||||||
|
* Drop support for Android 5.0 **19**
|
||||||
|
* Update uTLS to v1.8.2 **20**
|
||||||
|
* Update quic-go to v0.59.0
|
||||||
|
* Update gVisor to v20250811
|
||||||
|
* Update Tailscale to v1.92.4
|
||||||
|
|
||||||
|
**1**:
|
||||||
|
|
||||||
|
NaiveProxy outbound now supports QUIC, ECH, UDP over TCP, and configurable QUIC congestion control.
|
||||||
|
|
||||||
|
Only available on Apple platforms, Android, Windows and some Linux architectures.
|
||||||
|
Each Windows release includes `libcronet.dll` —
|
||||||
|
ensure this file is in the same directory as `sing-box.exe` or in a directory listed in `PATH`.
|
||||||
|
|
||||||
|
See [NaiveProxy outbound](/configuration/outbound/naive/).
|
||||||
|
|
||||||
|
**2**:
|
||||||
|
|
||||||
|
`auto_redirect` now allows you to bypass sing-box for connections based on routing rules.
|
||||||
|
|
||||||
|
A new rule action `bypass` is introduced to support this feature. When matched during pre-match, the connection will bypass sing-box and connect directly.
|
||||||
|
|
||||||
|
This feature requires Linux with `auto_redirect` enabled.
|
||||||
|
|
||||||
|
See [Pre-match](/configuration/shared/pre-match/) and [Rule Action](/configuration/route/rule_action/#bypass).
|
||||||
|
|
||||||
|
**3**:
|
||||||
|
|
||||||
|
`auto_redirect` now rejects MPTCP connections by default to fix compatibility issues.
|
||||||
|
You can change it to bypass sing-box via the new `exclude_mptcp` option.
|
||||||
|
|
||||||
|
Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default),
|
||||||
|
ensuring traffic is routed to the sing-box table when no route is found in system tables.
|
||||||
|
The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768).
|
||||||
|
|
||||||
|
See [TUN](/configuration/inbound/tun/#exclude_mptcp).
|
||||||
|
|
||||||
|
**4**:
|
||||||
|
|
||||||
|
Adds `chrome` as a new certificate store option alongside `mozilla`.
|
||||||
|
Both stores filter out China-based CA certificates.
|
||||||
|
|
||||||
|
See [Certificate](/configuration/certificate/#store).
|
||||||
|
|
||||||
|
**5**:
|
||||||
|
|
||||||
|
See [DNS-01 Challenge](/configuration/shared/dns01_challenge/).
|
||||||
|
|
||||||
|
**6**:
|
||||||
|
|
||||||
|
sing-box can now monitor Wi-Fi state on Linux and Windows to enable routing rules based on `wifi_ssid` and `wifi_bssid`.
|
||||||
|
|
||||||
|
See [Wi-Fi State](/configuration/shared/wifi-state/).
|
||||||
|
|
||||||
|
**7**:
|
||||||
|
|
||||||
|
See [TLS](/configuration/shared/tls/).
|
||||||
|
|
||||||
|
**8**:
|
||||||
|
|
||||||
|
Adds `kernel_tx` and `kernel_rx` options for TLS inbound.
|
||||||
|
Enables kernel-level TLS offloading via `splice(2)` on Linux 5.1+ with TLS 1.3.
|
||||||
|
|
||||||
|
See [TLS](/configuration/shared/tls/).
|
||||||
|
|
||||||
|
**9**:
|
||||||
|
|
||||||
|
sing-box can now proxy ICMP echo (ping) requests.
|
||||||
|
A new `icmp` network type is available for route rules.
|
||||||
|
Supported from TUN, WireGuard and Tailscale inbounds to Direct, WireGuard and Tailscale outbounds.
|
||||||
|
The `reject` action can also reply to ICMP echo requests.
|
||||||
|
|
||||||
|
**10**:
|
||||||
|
|
||||||
|
New rule items for matching based on interface IP addresses, available in route rules, DNS rules and rule-sets.
|
||||||
|
|
||||||
|
**11**:
|
||||||
|
|
||||||
|
Matches outbounds' preferred routes.
|
||||||
|
For Tailscale: MagicDNS domains and peers' allowed IPs. For WireGuard: peers' allowed IPs.
|
||||||
|
|
||||||
|
**12**:
|
||||||
|
|
||||||
|
The `local` DNS server now uses platform-native resolution:
|
||||||
|
`getaddrinfo`/libresolv on Apple platforms, systemd-resolved DBus on Linux.
|
||||||
|
A new `prefer_go` option is available to opt out.
|
||||||
|
|
||||||
|
See [Local DNS](/configuration/dns/server/local/).
|
||||||
|
|
||||||
|
**13**:
|
||||||
|
|
||||||
|
The default TCP keep-alive initial period has been updated from 10 minutes to 5 minutes.
|
||||||
|
|
||||||
|
See [Dial Fields](/configuration/shared/dial/#tcp_keep_alive).
|
||||||
|
|
||||||
|
**14**:
|
||||||
|
|
||||||
|
Adds the Linux socket option `IP_BIND_ADDRESS_NO_PORT` support when explicitly binding to a source address.
|
||||||
|
|
||||||
|
This allows reusing the same source port for multiple connections, improving scalability for high-concurrency proxy scenarios.
|
||||||
|
|
||||||
|
See [Dial Fields](/configuration/shared/dial/#bind_address_no_port).
|
||||||
|
|
||||||
|
**15**:
|
||||||
|
|
||||||
|
Tailscale endpoint can now create a system TUN interface to handle traffic directly.
|
||||||
|
New `relay_server_port` and `relay_server_static_endpoints` options for incoming relay connections.
|
||||||
|
New `advertise_tags` option for ACL tag advertisement.
|
||||||
|
|
||||||
|
See [Tailscale endpoint](/configuration/endpoint/tailscale/).
|
||||||
|
|
||||||
|
**16**:
|
||||||
|
|
||||||
|
CCM (Claude Code Multiplexer) service allows you to access your local Claude Code subscription remotely through custom tokens, eliminating the need for OAuth authentication on remote clients.
|
||||||
|
|
||||||
|
See [CCM](/configuration/service/ccm).
|
||||||
|
|
||||||
|
**17**:
|
||||||
|
|
||||||
|
See [OCM](/configuration/service/ocm).
|
||||||
|
|
||||||
|
**18**:
|
||||||
|
|
||||||
|
Due to maintenance difficulties, sing-box 1.13.0 requires at least Go 1.24 to compile.
|
||||||
|
|
||||||
|
**19**:
|
||||||
|
|
||||||
|
Due to maintenance difficulties, sing-box 1.13.0 will be the last version to support Android 5.0,
|
||||||
|
and only through a separate legacy build (with `-legacy-android-5` suffix).
|
||||||
|
|
||||||
|
For standalone binaries, the minimum Android version has been raised to Android 6.0,
|
||||||
|
since Termux requires Android 7.0 or later.
|
||||||
|
|
||||||
|
**20**:
|
||||||
|
|
||||||
|
This update fixes missing padding extension for Chrome 120+ fingerprints.
|
||||||
|
|
||||||
|
Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities.
|
||||||
|
uTLS is not recommended for censorship circumvention due to fundamental architectural limitations;
|
||||||
|
use NaiveProxy instead for TLS fingerprint resistance.
|
||||||
|
|
||||||
|
#### 1.12.23
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.0-rc.5
|
||||||
|
|
||||||
|
* Add `mipsle`, `mips64le`, `riscv64` and `loong64` support for NaiveProxy outbound
|
||||||
|
|
||||||
|
#### 1.12.22
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.0-rc.3
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.12.21
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.0-rc.2
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.12.20
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.0-rc.1
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.12.19
|
||||||
|
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
#### 1.13.0-beta.8
|
||||||
|
|
||||||
|
* Add fallback routing rule for `auto_redirect` **1**
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
**1**:
|
||||||
|
|
||||||
|
Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default),
|
||||||
|
ensuring traffic is routed to the sing-box table when no route is found in system tables.
|
||||||
|
|
||||||
|
The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768).
|
||||||
|
|
||||||
|
#### 1.12.18
|
||||||
|
|
||||||
|
* Add fallback routing rule for `auto_redirect` **1**
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
**1**:
|
||||||
|
|
||||||
|
Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default),
|
||||||
|
ensuring traffic is routed to the sing-box table when no route is found in system tables.
|
||||||
|
|
||||||
|
The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768).
|
||||||
|
|
||||||
|
#### 1.13.0-beta.6
|
||||||
|
|
||||||
|
* Update uTLS to v1.8.2 **1**
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
**1**:
|
||||||
|
|
||||||
|
This update fixes missing padding extension for Chrome 120+ fingerprints.
|
||||||
|
|
||||||
|
Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities.
|
||||||
|
uTLS is not recommended for censorship circumvention due to fundamental architectural limitations;
|
||||||
|
use NaiveProxy instead for TLS fingerprint resistance.
|
||||||
|
|
||||||
|
#### 1.12.17
|
||||||
|
|
||||||
|
* Update uTLS to v1.8.2 **1**
|
||||||
|
* Fixes and improvements
|
||||||
|
|
||||||
|
**1**:
|
||||||
|
|
||||||
|
This update fixes missing padding extension for Chrome 120+ fingerprints.
|
||||||
|
|
||||||
|
Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities.
|
||||||
|
uTLS is not recommended for censorship circumvention due to fundamental architectural limitations;
|
||||||
|
use NaiveProxy instead for TLS fingerprint resistance.
|
||||||
|
|
||||||
#### 1.13.0-beta.5
|
#### 1.13.0-beta.5
|
||||||
|
|
||||||
* Fixes and improvements
|
* Fixes and improvements
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ icon: material/delete-clock
|
|||||||
|
|
||||||
!!! failure "已在 sing-box 1.12.0 废弃"
|
!!! failure "已在 sing-box 1.12.0 废弃"
|
||||||
|
|
||||||
旧的 fake-ip 配置已废弃且将在 sing-box 1.14.0 中被移除,参阅 [迁移指南](/migration/#migrate-to-new-dns-servers)。
|
旧的 fake-ip 配置已废弃且将在 sing-box 1.14.0 中被移除,参阅 [迁移指南](/zh/migration/#迁移到新的-dns-服务器格式)。
|
||||||
|
|
||||||
### 结构
|
### 结构
|
||||||
|
|
||||||
|
|||||||
@@ -209,7 +209,7 @@ icon: material/alert-decagram
|
|||||||
(`source_port` || `source_port_range`) &&
|
(`source_port` || `source_port_range`) &&
|
||||||
`other fields`
|
`other fields`
|
||||||
|
|
||||||
Additionally, included rule-sets can be considered merged rather than as a single rule sub-item.
|
Additionally, each branch inside an included rule-set can be considered merged into the outer rule, while different branches keep OR semantics.
|
||||||
|
|
||||||
#### inbound
|
#### inbound
|
||||||
|
|
||||||
|
|||||||
@@ -208,7 +208,7 @@ icon: material/alert-decagram
|
|||||||
(`source_port` || `source_port_range`) &&
|
(`source_port` || `source_port_range`) &&
|
||||||
`other fields`
|
`other fields`
|
||||||
|
|
||||||
另外,引用的规则集可视为被合并,而不是作为一个单独的规则子项。
|
另外,引用规则集中的每个分支都可视为与外层规则合并,不同分支之间仍保持 OR 语义。
|
||||||
|
|
||||||
#### inbound
|
#### inbound
|
||||||
|
|
||||||
@@ -256,7 +256,7 @@ DNS 查询类型。值可以为整数或者类型名称字符串。
|
|||||||
|
|
||||||
!!! failure "已在 sing-box 1.12.0 中被移除"
|
!!! failure "已在 sing-box 1.12.0 中被移除"
|
||||||
|
|
||||||
GeoSite 已在 sing-box 1.8.0 废弃且在 sing-box 1.12.0 中被移除,参阅 [迁移指南](/zh/migration/#geosite)。
|
GeoSite 已在 sing-box 1.8.0 废弃且在 sing-box 1.12.0 中被移除,参阅 [迁移指南](/zh/migration/#迁移-geosite-到规则集)。
|
||||||
|
|
||||||
匹配 Geosite。
|
匹配 Geosite。
|
||||||
|
|
||||||
@@ -264,7 +264,7 @@ DNS 查询类型。值可以为整数或者类型名称字符串。
|
|||||||
|
|
||||||
!!! failure "已在 sing-box 1.12.0 中被移除"
|
!!! failure "已在 sing-box 1.12.0 中被移除"
|
||||||
|
|
||||||
GeoIP 已在 sing-box 1.8.0 废弃且在 sing-box 1.12.0 中被移除,参阅 [迁移指南](/zh/migration/#geoip)。
|
GeoIP 已在 sing-box 1.8.0 废弃且在 sing-box 1.12.0 中被移除,参阅 [迁移指南](/zh/migration/#迁移-geoip-到规则集)。
|
||||||
|
|
||||||
匹配源 GeoIP。
|
匹配源 GeoIP。
|
||||||
|
|
||||||
@@ -453,7 +453,7 @@ Available values: `wifi`, `cellular`, `ethernet` and `other`.
|
|||||||
|
|
||||||
!!! failure "已在 sing-box 1.12.0 废弃"
|
!!! failure "已在 sing-box 1.12.0 废弃"
|
||||||
|
|
||||||
`outbound` 规则项已废弃且将在 sing-box 1.14.0 中被移除,参阅 [迁移指南](/migration/#migrate-outbound-dns-rule-items-to-domain-resolver)。
|
`outbound` 规则项已废弃且将在 sing-box 1.14.0 中被移除,参阅 [迁移指南](/zh/migration/#迁移-outbound-dns-规则项到域解析选项)。
|
||||||
|
|
||||||
匹配出站。
|
匹配出站。
|
||||||
|
|
||||||
@@ -505,7 +505,7 @@ Available values: `wifi`, `cellular`, `ethernet` and `other`.
|
|||||||
|
|
||||||
!!! failure "已在 sing-box 1.12.0 中被移除"
|
!!! failure "已在 sing-box 1.12.0 中被移除"
|
||||||
|
|
||||||
GeoIP 已在 sing-box 1.8.0 废弃且在 sing-box 1.12.0 中被移除,参阅 [迁移指南](/zh/migration/#geoip)。
|
GeoIP 已在 sing-box 1.8.0 废弃且在 sing-box 1.12.0 中被移除,参阅 [迁移指南](/zh/migration/#迁移-geoip-到规则集)。
|
||||||
|
|
||||||
|
|
||||||
与查询响应匹配 GeoIP。
|
与查询响应匹配 GeoIP。
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ DNS 服务器的路径。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#outbound)。
|
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#出站)。
|
||||||
|
|
||||||
### 拨号字段
|
### 拨号字段
|
||||||
|
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ DNS 服务器的路径。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#outbound)。
|
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#出站)。
|
||||||
|
|
||||||
### 拨号字段
|
### 拨号字段
|
||||||
|
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ icon: material/delete-clock
|
|||||||
|
|
||||||
!!! failure "Deprecated in sing-box 1.12.0"
|
!!! failure "Deprecated in sing-box 1.12.0"
|
||||||
|
|
||||||
旧的 DNS 服务器配置已废弃且将在 sing-box 1.14.0 中被移除,参阅 [迁移指南](/migration/#migrate-to-new-dns-servers)。
|
旧的 DNS 服务器配置已废弃且将在 sing-box 1.14.0 中被移除,参阅 [迁移指南](/zh/migration/#迁移到新的-dns-服务器格式)。
|
||||||
|
|
||||||
!!! quote "sing-box 1.9.0 中的更改"
|
!!! quote "sing-box 1.9.0 中的更改"
|
||||||
|
|
||||||
|
|||||||
@@ -51,7 +51,7 @@ DNS 服务器的端口。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#outbound)。
|
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#出站)。
|
||||||
|
|
||||||
### 拨号字段
|
### 拨号字段
|
||||||
|
|
||||||
|
|||||||
@@ -51,7 +51,7 @@ DNS 服务器的端口。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#outbound)。
|
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#出站)。
|
||||||
|
|
||||||
### 拨号字段
|
### 拨号字段
|
||||||
|
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ icon: material/new-box
|
|||||||
:material-plus: [system_interface](#system_interface)
|
:material-plus: [system_interface](#system_interface)
|
||||||
:material-plus: [system_interface_name](#system_interface_name)
|
:material-plus: [system_interface_name](#system_interface_name)
|
||||||
:material-plus: [system_interface_mtu](#system_interface_mtu)
|
:material-plus: [system_interface_mtu](#system_interface_mtu)
|
||||||
|
:material-plus: [advertise_tags](#advertise_tags)
|
||||||
|
|
||||||
!!! question "Since sing-box 1.12.0"
|
!!! question "Since sing-box 1.12.0"
|
||||||
|
|
||||||
@@ -28,6 +29,7 @@ icon: material/new-box
|
|||||||
"exit_node_allow_lan_access": false,
|
"exit_node_allow_lan_access": false,
|
||||||
"advertise_routes": [],
|
"advertise_routes": [],
|
||||||
"advertise_exit_node": false,
|
"advertise_exit_node": false,
|
||||||
|
"advertise_tags": [],
|
||||||
"relay_server_port": 0,
|
"relay_server_port": 0,
|
||||||
"relay_server_static_endpoints": [],
|
"relay_server_static_endpoints": [],
|
||||||
"system_interface": false,
|
"system_interface": false,
|
||||||
@@ -102,6 +104,14 @@ Example: `["192.168.1.1/24"]`
|
|||||||
|
|
||||||
Indicates whether the node should advertise itself as an exit node.
|
Indicates whether the node should advertise itself as an exit node.
|
||||||
|
|
||||||
|
#### advertise_tags
|
||||||
|
|
||||||
|
!!! question "Since sing-box 1.13.0"
|
||||||
|
|
||||||
|
Tags to advertise for this node, for ACL enforcement purposes.
|
||||||
|
|
||||||
|
Example: `["tag:server"]`
|
||||||
|
|
||||||
#### relay_server_port
|
#### relay_server_port
|
||||||
|
|
||||||
!!! question "Since sing-box 1.13.0"
|
!!! question "Since sing-box 1.13.0"
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ icon: material/new-box
|
|||||||
:material-plus: [system_interface](#system_interface)
|
:material-plus: [system_interface](#system_interface)
|
||||||
:material-plus: [system_interface_name](#system_interface_name)
|
:material-plus: [system_interface_name](#system_interface_name)
|
||||||
:material-plus: [system_interface_mtu](#system_interface_mtu)
|
:material-plus: [system_interface_mtu](#system_interface_mtu)
|
||||||
|
:material-plus: [advertise_tags](#advertise_tags)
|
||||||
|
|
||||||
!!! question "自 sing-box 1.12.0 起"
|
!!! question "自 sing-box 1.12.0 起"
|
||||||
|
|
||||||
@@ -28,6 +29,7 @@ icon: material/new-box
|
|||||||
"exit_node_allow_lan_access": false,
|
"exit_node_allow_lan_access": false,
|
||||||
"advertise_routes": [],
|
"advertise_routes": [],
|
||||||
"advertise_exit_node": false,
|
"advertise_exit_node": false,
|
||||||
|
"advertise_tags": [],
|
||||||
"relay_server_port": 0,
|
"relay_server_port": 0,
|
||||||
"relay_server_static_endpoints": [],
|
"relay_server_static_endpoints": [],
|
||||||
"system_interface": false,
|
"system_interface": false,
|
||||||
@@ -101,6 +103,14 @@ icon: material/new-box
|
|||||||
|
|
||||||
指示节点是否应将自己通告为出口节点。
|
指示节点是否应将自己通告为出口节点。
|
||||||
|
|
||||||
|
#### advertise_tags
|
||||||
|
|
||||||
|
!!! question "自 sing-box 1.13.0 起"
|
||||||
|
|
||||||
|
为此节点通告的标签,用于 ACL 执行。
|
||||||
|
|
||||||
|
示例:`["tag:server"]`
|
||||||
|
|
||||||
#### relay_server_port
|
#### relay_server_port
|
||||||
|
|
||||||
!!! question "自 sing-box 1.13.0 起"
|
!!! question "自 sing-box 1.13.0 起"
|
||||||
|
|||||||
@@ -42,7 +42,7 @@
|
|||||||
|
|
||||||
将拒绝的 DNS 响应缓存存储在缓存文件中。
|
将拒绝的 DNS 响应缓存存储在缓存文件中。
|
||||||
|
|
||||||
[地址筛选 DNS 规则项](/zh/configuration/dns/rule/#_3) 的检查结果将被缓存至过期。
|
[地址筛选 DNS 规则项](/zh/configuration/dns/rule/#地址筛选字段) 的检查结果将被缓存至过期。
|
||||||
|
|
||||||
#### rdrc_timeout
|
#### rdrc_timeout
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
!!! quote ""
|
!!! quote ""
|
||||||
|
|
||||||
默认安装不包含 V2Ray API,参阅 [安装](/zh/installation/build-from-source/#_5)。
|
默认安装不包含 V2Ray API,参阅 [安装](/zh/installation/build-from-source/#构建标记)。
|
||||||
|
|
||||||
### 结构
|
### 结构
|
||||||
|
|
||||||
|
|||||||
@@ -58,4 +58,4 @@ AnyTLS 填充方案行数组。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
|
|||||||
@@ -26,7 +26,7 @@
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
|
|
||||||
#### users
|
#### users
|
||||||
|
|
||||||
|
|||||||
@@ -104,4 +104,4 @@ base64 编码的认证密码。
|
|||||||
|
|
||||||
==必填==
|
==必填==
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
@@ -38,7 +38,7 @@ icon: material/alert-decagram
|
|||||||
!!! warning "与官方 Hysteria2 的区别"
|
!!! warning "与官方 Hysteria2 的区别"
|
||||||
|
|
||||||
官方程序支持一种名为 **userpass** 的验证方式,
|
官方程序支持一种名为 **userpass** 的验证方式,
|
||||||
本质上上是将用户名与密码的组合 `<username>:<password>` 作为实际上的密码,而 sing-box 不提供此别名。
|
本质上是将用户名与密码的组合 `<username>:<password>` 作为实际上的密码,而 sing-box 不提供此别名。
|
||||||
要将 sing-box 与官方程序一起使用, 您需要填写该组合作为实际密码。
|
要将 sing-box 与官方程序一起使用, 您需要填写该组合作为实际密码。
|
||||||
|
|
||||||
### 监听字段
|
### 监听字段
|
||||||
@@ -85,7 +85,7 @@ Hysteria 用户
|
|||||||
|
|
||||||
==必填==
|
==必填==
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
|
|
||||||
#### masquerade
|
#### masquerade
|
||||||
|
|
||||||
|
|||||||
@@ -60,4 +60,4 @@ QUIC 拥塞控制算法。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
@@ -93,4 +93,4 @@
|
|||||||
|
|
||||||
#### multiplex
|
#### multiplex
|
||||||
|
|
||||||
参阅 [多路复用](/zh/configuration/shared/multiplex#inbound)。
|
参阅 [多路复用](/zh/configuration/shared/multiplex#入站)。
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ Trojan 用户。
|
|||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
|
|
||||||
#### fallback
|
#### fallback
|
||||||
|
|
||||||
@@ -61,7 +61,7 @@ TLS 配置,参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
|||||||
|
|
||||||
#### multiplex
|
#### multiplex
|
||||||
|
|
||||||
参阅 [多路复用](/zh/configuration/shared/multiplex#inbound)。
|
参阅 [多路复用](/zh/configuration/shared/multiplex#入站)。
|
||||||
|
|
||||||
#### transport
|
#### transport
|
||||||
|
|
||||||
|
|||||||
@@ -75,4 +75,4 @@ QUIC 拥塞控制算法
|
|||||||
|
|
||||||
==必填==
|
==必填==
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#入站)。
|
||||||
@@ -2,11 +2,21 @@
|
|||||||
icon: material/new-box
|
icon: material/new-box
|
||||||
---
|
---
|
||||||
|
|
||||||
|
!!! quote "Changes in sing-box 1.14.0"
|
||||||
|
|
||||||
|
:material-plus: [include_mac_address](#include_mac_address)
|
||||||
|
:material-plus: [exclude_mac_address](#exclude_mac_address)
|
||||||
|
|
||||||
|
!!! quote "Changes in sing-box 1.13.3"
|
||||||
|
|
||||||
|
:material-alert: [strict_route](#strict_route)
|
||||||
|
|
||||||
!!! quote "Changes in sing-box 1.13.0"
|
!!! quote "Changes in sing-box 1.13.0"
|
||||||
|
|
||||||
:material-plus: [auto_redirect_reset_mark](#auto_redirect_reset_mark)
|
:material-plus: [auto_redirect_reset_mark](#auto_redirect_reset_mark)
|
||||||
:material-plus: [auto_redirect_nfqueue](#auto_redirect_nfqueue)
|
:material-plus: [auto_redirect_nfqueue](#auto_redirect_nfqueue)
|
||||||
:material-plus: [exclude_mptcp](#exclude_mptcp)
|
:material-plus: [exclude_mptcp](#exclude_mptcp)
|
||||||
|
:material-plus: [auto_redirect_iproute2_fallback_rule_index](#auto_redirect_iproute2_fallback_rule_index)
|
||||||
|
|
||||||
!!! quote "Changes in sing-box 1.12.0"
|
!!! quote "Changes in sing-box 1.12.0"
|
||||||
|
|
||||||
@@ -71,6 +81,7 @@ icon: material/new-box
|
|||||||
"auto_redirect_output_mark": "0x2024",
|
"auto_redirect_output_mark": "0x2024",
|
||||||
"auto_redirect_reset_mark": "0x2025",
|
"auto_redirect_reset_mark": "0x2025",
|
||||||
"auto_redirect_nfqueue": 100,
|
"auto_redirect_nfqueue": 100,
|
||||||
|
"auto_redirect_iproute2_fallback_rule_index": 32768,
|
||||||
"exclude_mptcp": false,
|
"exclude_mptcp": false,
|
||||||
"loopback_address": [
|
"loopback_address": [
|
||||||
"10.7.0.1"
|
"10.7.0.1"
|
||||||
@@ -303,6 +314,17 @@ NFQueue number used by `auto_redirect` pre-matching.
|
|||||||
|
|
||||||
`100` is used by default.
|
`100` is used by default.
|
||||||
|
|
||||||
|
#### auto_redirect_iproute2_fallback_rule_index
|
||||||
|
|
||||||
|
!!! question "Since sing-box 1.12.18"
|
||||||
|
|
||||||
|
Linux iproute2 fallback rule index generated by `auto_redirect`.
|
||||||
|
|
||||||
|
This rule is checked after system default rules (32766: main, 32767: default),
|
||||||
|
routing traffic to the sing-box table only when no route is found in system tables.
|
||||||
|
|
||||||
|
`32768` is used by default.
|
||||||
|
|
||||||
#### exclude_mptcp
|
#### exclude_mptcp
|
||||||
|
|
||||||
!!! question "Since sing-box 1.13.0"
|
!!! question "Since sing-box 1.13.0"
|
||||||
@@ -335,6 +357,9 @@ Enforce strict routing rules when `auto_route` is enabled:
|
|||||||
|
|
||||||
* Let unsupported network unreachable
|
* Let unsupported network unreachable
|
||||||
* For legacy reasons, when neither `strict_route` nor `auto_redirect` are enabled, all ICMP traffic will not go through TUN.
|
* For legacy reasons, when neither `strict_route` nor `auto_redirect` are enabled, all ICMP traffic will not go through TUN.
|
||||||
|
* When `auto_redirect` is enabled, `strict_route` also affects `SO_BINDTODEVICE` traffic:
|
||||||
|
* Enabled: `SO_BINDTODEVICE` traffic is redirected through sing-box.
|
||||||
|
* Disabled: `SO_BINDTODEVICE` traffic bypasses sing-box.
|
||||||
|
|
||||||
*In Windows*:
|
*In Windows*:
|
||||||
|
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user