Compare commits
25 Commits
v1.2-beta6
...
v1.1.7
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
60d3ba3b18 | ||
|
|
4f4a815654 | ||
|
|
77e3f2d465 | ||
|
|
d012a9091d | ||
|
|
c986a48001 | ||
|
|
8550495789 | ||
|
|
06bc57d85a | ||
|
|
b54c1b1aa7 | ||
|
|
cc90156b96 | ||
|
|
593fc97c65 | ||
|
|
ef73c6f2a9 | ||
|
|
5f78036977 | ||
|
|
f846cf918e | ||
|
|
c3cab4cad1 | ||
|
|
0b22c7e314 | ||
|
|
a3b1656995 | ||
|
|
f5f3468f65 | ||
|
|
b6cd48944a | ||
|
|
8fbbb4f8dd | ||
|
|
94e0ebd3c8 | ||
|
|
32ad5710ba | ||
|
|
39fb23775c | ||
|
|
3ad4fc728f | ||
|
|
f6cb32b76e | ||
|
|
a8fcadab25 |
28
.github/renovate.json
vendored
28
.github/renovate.json
vendored
@@ -1,28 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
||||||
"commitMessagePrefix": "[dependencies]",
|
|
||||||
"extends": [
|
|
||||||
"config:base",
|
|
||||||
":disableRateLimiting"
|
|
||||||
],
|
|
||||||
"baseBranches": [
|
|
||||||
"dev-next"
|
|
||||||
],
|
|
||||||
"golang": {
|
|
||||||
"enabled": false
|
|
||||||
},
|
|
||||||
"packageRules": [
|
|
||||||
{
|
|
||||||
"matchManagers": [
|
|
||||||
"github-actions"
|
|
||||||
],
|
|
||||||
"groupName": "github-actions"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchManagers": [
|
|
||||||
"dockerfile"
|
|
||||||
],
|
|
||||||
"groupName": "Dockerfile"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
6
.github/workflows/mkdocs.yml
vendored
6
.github/workflows/mkdocs.yml
vendored
@@ -14,7 +14,5 @@ jobs:
|
|||||||
- uses: actions/setup-python@v4
|
- uses: actions/setup-python@v4
|
||||||
with:
|
with:
|
||||||
python-version: 3.x
|
python-version: 3.x
|
||||||
- run: |
|
- run: pip install mkdocs-material mkdocs-static-i18n
|
||||||
pip install mkdocs-material=="9.*" mkdocs-static-i18n=="0.53"
|
- run: mkdocs gh-deploy -m "{sha}" --force --ignore-version --no-history
|
||||||
- run: |
|
|
||||||
mkdocs gh-deploy -m "{sha}" --force --ignore-version --no-history
|
|
||||||
@@ -12,8 +12,6 @@ run:
|
|||||||
- transport/simple-obfs
|
- transport/simple-obfs
|
||||||
- transport/clashssr
|
- transport/clashssr
|
||||||
- transport/cloudflaretls
|
- transport/cloudflaretls
|
||||||
- transport/shadowtls/tls
|
|
||||||
- transport/shadowtls/tls_go119
|
|
||||||
|
|
||||||
linters-settings:
|
linters-settings:
|
||||||
gci:
|
gci:
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ builds:
|
|||||||
gcflags:
|
gcflags:
|
||||||
- all=-trimpath={{.Env.GOPATH}}
|
- all=-trimpath={{.Env.GOPATH}}
|
||||||
ldflags:
|
ldflags:
|
||||||
- -s -w -buildid=
|
- -X "github.com/sagernet/sing-box/constant.Version={{ .Version }}" -s -w -buildid=
|
||||||
tags:
|
tags:
|
||||||
- with_gvisor
|
- with_gvisor
|
||||||
- with_quic
|
- with_quic
|
||||||
|
|||||||
@@ -8,9 +8,10 @@ ENV CGO_ENABLED=0
|
|||||||
RUN set -ex \
|
RUN set -ex \
|
||||||
&& apk add git build-base \
|
&& apk add git build-base \
|
||||||
&& export COMMIT=$(git rev-parse --short HEAD) \
|
&& export COMMIT=$(git rev-parse --short HEAD) \
|
||||||
|
&& export VERSION=$(go run ./cmd/internal/read_tag) \
|
||||||
&& go build -v -trimpath -tags with_quic,with_wireguard,with_acme \
|
&& go build -v -trimpath -tags with_quic,with_wireguard,with_acme \
|
||||||
-o /go/bin/sing-box \
|
-o /go/bin/sing-box \
|
||||||
-ldflags "-s -w -buildid=" \
|
-ldflags "-X \"github.com/sagernet/sing-box/constant.Version=$VERSION\" -s -w -buildid=" \
|
||||||
./cmd/sing-box
|
./cmd/sing-box
|
||||||
FROM alpine AS dist
|
FROM alpine AS dist
|
||||||
LABEL maintainer="nekohasekai <contact-git@sekai.icu>"
|
LABEL maintainer="nekohasekai <contact-git@sekai.icu>"
|
||||||
|
|||||||
11
Makefile
11
Makefile
@@ -2,7 +2,8 @@ NAME = sing-box
|
|||||||
COMMIT = $(shell git rev-parse --short HEAD)
|
COMMIT = $(shell git rev-parse --short HEAD)
|
||||||
TAGS ?= with_gvisor,with_quic,with_wireguard,with_utls,with_reality_server,with_clash_api
|
TAGS ?= with_gvisor,with_quic,with_wireguard,with_utls,with_reality_server,with_clash_api
|
||||||
TAGS_TEST ?= with_gvisor,with_quic,with_wireguard,with_grpc,with_ech,with_utls,with_reality_server,with_shadowsocksr
|
TAGS_TEST ?= with_gvisor,with_quic,with_wireguard,with_grpc,with_ech,with_utls,with_reality_server,with_shadowsocksr
|
||||||
PARAMS = -v -trimpath -tags "$(TAGS)" -ldflags "-s -w -buildid="
|
VERSION=$(shell go run ./cmd/internal/read_tag)
|
||||||
|
PARAMS = -v -trimpath -tags "$(TAGS)" -ldflags "-X \"github.com/sagernet/sing-box/constant.Version=$(VERSION)\" -s -w -buildid="
|
||||||
MAIN = ./cmd/sing-box
|
MAIN = ./cmd/sing-box
|
||||||
|
|
||||||
.PHONY: test release
|
.PHONY: test release
|
||||||
@@ -71,14 +72,6 @@ test_stdio:
|
|||||||
go mod tidy && \
|
go mod tidy && \
|
||||||
go test -v -tags "$(TAGS_TEST),force_stdio" .
|
go test -v -tags "$(TAGS_TEST),force_stdio" .
|
||||||
|
|
||||||
lib:
|
|
||||||
go run ./cmd/internal/build_libbox
|
|
||||||
|
|
||||||
lib_install:
|
|
||||||
go get -v -d
|
|
||||||
go install -v github.com/sagernet/gomobile/cmd/gomobile@v0.0.0-20221130124640-349ebaa752ca
|
|
||||||
go install -v github.com/sagernet/gomobile/cmd/gobind@v0.0.0-20221130124640-349ebaa752ca
|
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -rf bin dist sing-box
|
rm -rf bin dist sing-box
|
||||||
rm -f $(shell go env GOPATH)/sing-box
|
rm -f $(shell go env GOPATH)/sing-box
|
||||||
|
|||||||
@@ -45,6 +45,6 @@ type V2RayServer interface {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type V2RayStatsService interface {
|
type V2RayStatsService interface {
|
||||||
RoutedConnection(inbound string, outbound string, user string, conn net.Conn) net.Conn
|
RoutedConnection(inbound string, outbound string, conn net.Conn) net.Conn
|
||||||
RoutedPacketConnection(inbound string, outbound string, user string, conn N.PacketConn) N.PacketConn
|
RoutedPacketConnection(inbound string, outbound string, conn N.PacketConn) N.PacketConn
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -46,10 +46,6 @@ type InboundContext struct {
|
|||||||
SourceGeoIPCode string
|
SourceGeoIPCode string
|
||||||
GeoIPCode string
|
GeoIPCode string
|
||||||
ProcessInfo *process.Info
|
ProcessInfo *process.Info
|
||||||
|
|
||||||
// dns cache
|
|
||||||
|
|
||||||
QueryType uint16
|
|
||||||
}
|
}
|
||||||
|
|
||||||
type inboundContextKey struct{}
|
type inboundContextKey struct{}
|
||||||
|
|||||||
@@ -34,15 +34,12 @@ type Router interface {
|
|||||||
InterfaceFinder() control.InterfaceFinder
|
InterfaceFinder() control.InterfaceFinder
|
||||||
DefaultInterface() string
|
DefaultInterface() string
|
||||||
AutoDetectInterface() bool
|
AutoDetectInterface() bool
|
||||||
AutoDetectInterfaceFunc() control.Func
|
|
||||||
DefaultMark() int
|
DefaultMark() int
|
||||||
NetworkMonitor() tun.NetworkUpdateMonitor
|
NetworkMonitor() tun.NetworkUpdateMonitor
|
||||||
InterfaceMonitor() tun.DefaultInterfaceMonitor
|
InterfaceMonitor() tun.DefaultInterfaceMonitor
|
||||||
PackageManager() tun.PackageManager
|
PackageManager() tun.PackageManager
|
||||||
Rules() []Rule
|
Rules() []Rule
|
||||||
|
|
||||||
TimeService
|
|
||||||
|
|
||||||
ClashServer() ClashServer
|
ClashServer() ClashServer
|
||||||
SetClashServer(server ClashServer)
|
SetClashServer(server ClashServer)
|
||||||
|
|
||||||
@@ -50,20 +47,6 @@ type Router interface {
|
|||||||
SetV2RayServer(server V2RayServer)
|
SetV2RayServer(server V2RayServer)
|
||||||
}
|
}
|
||||||
|
|
||||||
type routerContextKey struct{}
|
|
||||||
|
|
||||||
func ContextWithRouter(ctx context.Context, router Router) context.Context {
|
|
||||||
return context.WithValue(ctx, (*routerContextKey)(nil), router)
|
|
||||||
}
|
|
||||||
|
|
||||||
func RouterFromContext(ctx context.Context) Router {
|
|
||||||
metadata := ctx.Value((*routerContextKey)(nil))
|
|
||||||
if metadata == nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
return metadata.(Router)
|
|
||||||
}
|
|
||||||
|
|
||||||
type Rule interface {
|
type Rule interface {
|
||||||
Service
|
Service
|
||||||
Type() string
|
Type() string
|
||||||
|
|||||||
@@ -1,8 +0,0 @@
|
|||||||
package adapter
|
|
||||||
|
|
||||||
import "time"
|
|
||||||
|
|
||||||
type TimeService interface {
|
|
||||||
Service
|
|
||||||
TimeFunc() func() time.Time
|
|
||||||
}
|
|
||||||
@@ -3,10 +3,6 @@ package adapter
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"net"
|
"net"
|
||||||
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
|
||||||
N "github.com/sagernet/sing/common/network"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type V2RayServerTransport interface {
|
type V2RayServerTransport interface {
|
||||||
@@ -16,12 +12,6 @@ type V2RayServerTransport interface {
|
|||||||
Close() error
|
Close() error
|
||||||
}
|
}
|
||||||
|
|
||||||
type V2RayServerTransportHandler interface {
|
|
||||||
N.TCPConnectionHandler
|
|
||||||
E.Handler
|
|
||||||
FallbackConnection(ctx context.Context, conn net.Conn, metadata M.Metadata) error
|
|
||||||
}
|
|
||||||
|
|
||||||
type V2RayClientTransport interface {
|
type V2RayClientTransport interface {
|
||||||
DialContext(ctx context.Context) (net.Conn, error)
|
DialContext(ctx context.Context) (net.Conn, error)
|
||||||
}
|
}
|
||||||
|
|||||||
94
box.go
94
box.go
@@ -9,9 +9,7 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
|
||||||
"github.com/sagernet/sing-box/experimental"
|
"github.com/sagernet/sing-box/experimental"
|
||||||
"github.com/sagernet/sing-box/experimental/libbox/platform"
|
|
||||||
"github.com/sagernet/sing-box/inbound"
|
"github.com/sagernet/sing-box/inbound"
|
||||||
"github.com/sagernet/sing-box/log"
|
"github.com/sagernet/sing-box/log"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
@@ -37,7 +35,7 @@ type Box struct {
|
|||||||
done chan struct{}
|
done chan struct{}
|
||||||
}
|
}
|
||||||
|
|
||||||
func New(ctx context.Context, options option.Options, platformInterface platform.Interface) (*Box, error) {
|
func New(ctx context.Context, options option.Options) (*Box, error) {
|
||||||
createdAt := time.Now()
|
createdAt := time.Now()
|
||||||
logOptions := common.PtrValueOrDefault(options.Log)
|
logOptions := common.PtrValueOrDefault(options.Log)
|
||||||
|
|
||||||
@@ -55,25 +53,19 @@ func New(ctx context.Context, options option.Options, platformInterface platform
|
|||||||
var logFactory log.Factory
|
var logFactory log.Factory
|
||||||
var observableLogFactory log.ObservableFactory
|
var observableLogFactory log.ObservableFactory
|
||||||
var logFile *os.File
|
var logFile *os.File
|
||||||
var logWriter io.Writer
|
|
||||||
if logOptions.Disabled {
|
if logOptions.Disabled {
|
||||||
observableLogFactory = log.NewNOPFactory()
|
observableLogFactory = log.NewNOPFactory()
|
||||||
logFactory = observableLogFactory
|
logFactory = observableLogFactory
|
||||||
} else {
|
} else {
|
||||||
|
var logWriter io.Writer
|
||||||
switch logOptions.Output {
|
switch logOptions.Output {
|
||||||
case "":
|
case "", "stderr":
|
||||||
if platformInterface != nil {
|
|
||||||
logWriter = io.Discard
|
|
||||||
} else {
|
|
||||||
logWriter = os.Stdout
|
|
||||||
}
|
|
||||||
case "stderr":
|
|
||||||
logWriter = os.Stderr
|
logWriter = os.Stderr
|
||||||
case "stdout":
|
case "stdout":
|
||||||
logWriter = os.Stdout
|
logWriter = os.Stdout
|
||||||
default:
|
default:
|
||||||
var err error
|
var err error
|
||||||
logFile, err = os.OpenFile(C.BasePath(logOptions.Output), os.O_APPEND|os.O_CREATE|os.O_WRONLY, 0o644)
|
logFile, err = os.OpenFile(logOptions.Output, os.O_APPEND|os.O_CREATE|os.O_WRONLY, 0o644)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -87,10 +79,10 @@ func New(ctx context.Context, options option.Options, platformInterface platform
|
|||||||
TimestampFormat: "-0700 2006-01-02 15:04:05",
|
TimestampFormat: "-0700 2006-01-02 15:04:05",
|
||||||
}
|
}
|
||||||
if needClashAPI {
|
if needClashAPI {
|
||||||
observableLogFactory = log.NewObservableFactory(logFormatter, logWriter, platformInterface)
|
observableLogFactory = log.NewObservableFactory(logFormatter, logWriter)
|
||||||
logFactory = observableLogFactory
|
logFactory = observableLogFactory
|
||||||
} else {
|
} else {
|
||||||
logFactory = log.NewFactory(logFormatter, logWriter, platformInterface)
|
logFactory = log.NewFactory(logFormatter, logWriter)
|
||||||
}
|
}
|
||||||
if logOptions.Level != "" {
|
if logOptions.Level != "" {
|
||||||
logLevel, err := log.ParseLevel(logOptions.Level)
|
logLevel, err := log.ParseLevel(logOptions.Level)
|
||||||
@@ -108,9 +100,7 @@ func New(ctx context.Context, options option.Options, platformInterface platform
|
|||||||
logFactory,
|
logFactory,
|
||||||
common.PtrValueOrDefault(options.Route),
|
common.PtrValueOrDefault(options.Route),
|
||||||
common.PtrValueOrDefault(options.DNS),
|
common.PtrValueOrDefault(options.DNS),
|
||||||
common.PtrValueOrDefault(options.NTP),
|
|
||||||
options.Inbounds,
|
options.Inbounds,
|
||||||
platformInterface,
|
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, E.Cause(err, "parse route options")
|
return nil, E.Cause(err, "parse route options")
|
||||||
@@ -130,7 +120,6 @@ func New(ctx context.Context, options option.Options, platformInterface platform
|
|||||||
router,
|
router,
|
||||||
logFactory.NewLogger(F.ToString("inbound/", inboundOptions.Type, "[", tag, "]")),
|
logFactory.NewLogger(F.ToString("inbound/", inboundOptions.Type, "[", tag, "]")),
|
||||||
inboundOptions,
|
inboundOptions,
|
||||||
platformInterface,
|
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, E.Cause(err, "parse inbound[", i, "]")
|
return nil, E.Cause(err, "parse inbound[", i, "]")
|
||||||
@@ -213,18 +202,6 @@ func (s *Box) Start() error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (s *Box) start() error {
|
func (s *Box) start() error {
|
||||||
if s.clashServer != nil {
|
|
||||||
err := s.clashServer.Start()
|
|
||||||
if err != nil {
|
|
||||||
return E.Cause(err, "start clash api server")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if s.v2rayServer != nil {
|
|
||||||
err := s.v2rayServer.Start()
|
|
||||||
if err != nil {
|
|
||||||
return E.Cause(err, "start v2ray api server")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
for i, out := range s.outbounds {
|
for i, out := range s.outbounds {
|
||||||
if starter, isStarter := out.(common.Starter); isStarter {
|
if starter, isStarter := out.(common.Starter); isStarter {
|
||||||
err := starter.Start()
|
err := starter.Start()
|
||||||
@@ -255,7 +232,18 @@ func (s *Box) start() error {
|
|||||||
return E.Cause(err, "initialize inbound/", in.Type(), "[", tag, "]")
|
return E.Cause(err, "initialize inbound/", in.Type(), "[", tag, "]")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if s.clashServer != nil {
|
||||||
|
err = s.clashServer.Start()
|
||||||
|
if err != nil {
|
||||||
|
return E.Cause(err, "start clash api server")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if s.v2rayServer != nil {
|
||||||
|
err = s.v2rayServer.Start()
|
||||||
|
if err != nil {
|
||||||
|
return E.Cause(err, "start v2ray api server")
|
||||||
|
}
|
||||||
|
}
|
||||||
s.logger.Info("sing-box started (", F.Seconds(time.Since(s.createdAt).Seconds()), "s)")
|
s.logger.Info("sing-box started (", F.Seconds(time.Since(s.createdAt).Seconds()), "s)")
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -267,43 +255,19 @@ func (s *Box) Close() error {
|
|||||||
default:
|
default:
|
||||||
close(s.done)
|
close(s.done)
|
||||||
}
|
}
|
||||||
var errors error
|
for _, in := range s.inbounds {
|
||||||
for i, in := range s.inbounds {
|
in.Close()
|
||||||
errors = E.Append(errors, in.Close(), func(err error) error {
|
|
||||||
return E.Cause(err, "close inbound/", in.Type(), "[", i, "]")
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
for i, out := range s.outbounds {
|
for _, out := range s.outbounds {
|
||||||
errors = E.Append(errors, common.Close(out), func(err error) error {
|
common.Close(out)
|
||||||
return E.Cause(err, "close inbound/", out.Type(), "[", i, "]")
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
if err := common.Close(s.router); err != nil {
|
return common.Close(
|
||||||
errors = E.Append(errors, err, func(err error) error {
|
s.router,
|
||||||
return E.Cause(err, "close router")
|
s.logFactory,
|
||||||
})
|
s.clashServer,
|
||||||
}
|
s.v2rayServer,
|
||||||
if err := common.Close(s.logFactory); err != nil {
|
common.PtrOrNil(s.logFile),
|
||||||
errors = E.Append(errors, err, func(err error) error {
|
)
|
||||||
return E.Cause(err, "close log factory")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
if err := common.Close(s.clashServer); err != nil {
|
|
||||||
errors = E.Append(errors, err, func(err error) error {
|
|
||||||
return E.Cause(err, "close clash api server")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
if err := common.Close(s.v2rayServer); err != nil {
|
|
||||||
errors = E.Append(errors, err, func(err error) error {
|
|
||||||
return E.Cause(err, "close v2ray api server")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
if s.logFile != nil {
|
|
||||||
errors = E.Append(errors, s.logFile.Close(), func(err error) error {
|
|
||||||
return E.Cause(err, "close log file")
|
|
||||||
})
|
|
||||||
}
|
|
||||||
return errors
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *Box) Router() adapter.Router {
|
func (s *Box) Router() adapter.Router {
|
||||||
|
|||||||
@@ -1,113 +0,0 @@
|
|||||||
package main
|
|
||||||
|
|
||||||
import (
|
|
||||||
"flag"
|
|
||||||
"os"
|
|
||||||
"os/exec"
|
|
||||||
"path/filepath"
|
|
||||||
|
|
||||||
_ "github.com/sagernet/gomobile/event/key"
|
|
||||||
"github.com/sagernet/sing-box/cmd/internal/build_shared"
|
|
||||||
"github.com/sagernet/sing-box/log"
|
|
||||||
"github.com/sagernet/sing/common/rw"
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
debugEnabled bool
|
|
||||||
target string
|
|
||||||
)
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
flag.BoolVar(&debugEnabled, "debug", false, "enable debug")
|
|
||||||
flag.StringVar(&target, "target", "android", "target platform")
|
|
||||||
}
|
|
||||||
|
|
||||||
func main() {
|
|
||||||
flag.Parse()
|
|
||||||
|
|
||||||
build_shared.FindMobile()
|
|
||||||
|
|
||||||
switch target {
|
|
||||||
case "android":
|
|
||||||
buildAndroid()
|
|
||||||
case "ios":
|
|
||||||
buildiOS()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func buildAndroid() {
|
|
||||||
build_shared.FindSDK()
|
|
||||||
|
|
||||||
args := []string{
|
|
||||||
"bind",
|
|
||||||
"-v",
|
|
||||||
"-androidapi", "21",
|
|
||||||
"-javapkg=io.nekohasekai",
|
|
||||||
"-libname=box",
|
|
||||||
}
|
|
||||||
if !debugEnabled {
|
|
||||||
args = append(args,
|
|
||||||
"-trimpath", "-ldflags=-s -w -buildid=",
|
|
||||||
"-tags", "with_gvisor,with_quic,with_wireguard,with_utls,with_clash_api",
|
|
||||||
)
|
|
||||||
} else {
|
|
||||||
args = append(args, "-tags", "with_gvisor,with_quic,with_wireguard,with_utls,with_clash_api,debug")
|
|
||||||
}
|
|
||||||
|
|
||||||
args = append(args, "./experimental/libbox")
|
|
||||||
|
|
||||||
command := exec.Command(build_shared.GoBinPath+"/gomobile", args...)
|
|
||||||
command.Stdout = os.Stdout
|
|
||||||
command.Stderr = os.Stderr
|
|
||||||
err := command.Run()
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
const name = "libbox.aar"
|
|
||||||
copyPath := filepath.Join("..", "sing-box-for-android", "app", "libs")
|
|
||||||
if rw.FileExists(copyPath) {
|
|
||||||
copyPath, _ = filepath.Abs(copyPath)
|
|
||||||
err = rw.CopyFile(name, filepath.Join(copyPath, name))
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
log.Info("copied to ", copyPath)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func buildiOS() {
|
|
||||||
args := []string{
|
|
||||||
"bind",
|
|
||||||
"-v",
|
|
||||||
"-target", "ios,iossimulator,macos",
|
|
||||||
"-libname=box",
|
|
||||||
}
|
|
||||||
if !debugEnabled {
|
|
||||||
args = append(
|
|
||||||
args, "-trimpath", "-ldflags=-s -w -buildid=",
|
|
||||||
"-tags", "with_gvisor,with_utls,with_clash_api,with_conntrack",
|
|
||||||
)
|
|
||||||
} else {
|
|
||||||
args = append(args, "-tags", "with_gvisor,with_utls,with_clash_api,with_conntrack,debug")
|
|
||||||
}
|
|
||||||
|
|
||||||
args = append(args, "./experimental/libbox")
|
|
||||||
|
|
||||||
command := exec.Command(build_shared.GoBinPath+"/gomobile", args...)
|
|
||||||
command.Stdout = os.Stdout
|
|
||||||
command.Stderr = os.Stderr
|
|
||||||
err := command.Run()
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
copyPath := filepath.Join("..", "sing-box-for-ios")
|
|
||||||
if rw.FileExists(copyPath) {
|
|
||||||
targetDir := filepath.Join(copyPath, "Libbox.xcframework")
|
|
||||||
targetDir, _ = filepath.Abs(targetDir)
|
|
||||||
os.RemoveAll(targetDir)
|
|
||||||
os.Rename("Libbox.xcframework", targetDir)
|
|
||||||
log.Info("copied to ", targetDir)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
16
cmd/internal/build_shared/tag.go
Normal file
16
cmd/internal/build_shared/tag.go
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
package build_shared
|
||||||
|
|
||||||
|
import "github.com/sagernet/sing/common/shell"
|
||||||
|
|
||||||
|
func ReadTag() (string, error) {
|
||||||
|
currentTag, err := shell.Exec("git", "describe", "--tags").Read()
|
||||||
|
if err != nil {
|
||||||
|
return currentTag, err
|
||||||
|
}
|
||||||
|
currentTagRev, _ := shell.Exec("git", "describe", "--tags", "--abbrev=0").ReadOutput()
|
||||||
|
if currentTagRev == currentTag {
|
||||||
|
return currentTag[1:], nil
|
||||||
|
}
|
||||||
|
shortCommit, _ := shell.Exec("git", "rev-parse", "--short", "HEAD").ReadOutput()
|
||||||
|
return currentTagRev[1:] + "-" + shortCommit, nil
|
||||||
|
}
|
||||||
21
cmd/internal/read_tag/main.go
Normal file
21
cmd/internal/read_tag/main.go
Normal file
@@ -0,0 +1,21 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
|
||||||
|
"github.com/sagernet/sing-box/cmd/internal/build_shared"
|
||||||
|
"github.com/sagernet/sing-box/log"
|
||||||
|
)
|
||||||
|
|
||||||
|
func main() {
|
||||||
|
currentTag, err := build_shared.ReadTag()
|
||||||
|
if err != nil {
|
||||||
|
log.Error(err)
|
||||||
|
_, err = os.Stdout.WriteString("unknown\n")
|
||||||
|
} else {
|
||||||
|
_, err = os.Stdout.WriteString(currentTag + "\n")
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
log.Error(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -31,10 +31,7 @@ func check() error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
instance, err := box.New(ctx, options, nil)
|
_, err = box.New(ctx, options)
|
||||||
if err == nil {
|
|
||||||
instance.Close()
|
|
||||||
}
|
|
||||||
cancel()
|
cancel()
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,139 +0,0 @@
|
|||||||
package main
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/rand"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/hex"
|
|
||||||
"os"
|
|
||||||
"strconv"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/log"
|
|
||||||
|
|
||||||
"github.com/gofrs/uuid"
|
|
||||||
"github.com/spf13/cobra"
|
|
||||||
"golang.zx2c4.com/wireguard/wgctrl/wgtypes"
|
|
||||||
)
|
|
||||||
|
|
||||||
var commandGenerate = &cobra.Command{
|
|
||||||
Use: "generate",
|
|
||||||
Short: "Generate things",
|
|
||||||
}
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
commandGenerate.AddCommand(commandGenerateUUID)
|
|
||||||
commandGenerate.AddCommand(commandGenerateRandom)
|
|
||||||
commandGenerate.AddCommand(commandGenerateWireGuardKeyPair)
|
|
||||||
commandGenerate.AddCommand(commandGenerateRealityKeyPair)
|
|
||||||
mainCommand.AddCommand(commandGenerate)
|
|
||||||
}
|
|
||||||
|
|
||||||
var (
|
|
||||||
outputBase64 bool
|
|
||||||
outputHex bool
|
|
||||||
)
|
|
||||||
|
|
||||||
var commandGenerateRandom = &cobra.Command{
|
|
||||||
Use: "rand <length>",
|
|
||||||
Short: "Generate random bytes",
|
|
||||||
Args: cobra.ExactArgs(1),
|
|
||||||
Run: func(cmd *cobra.Command, args []string) {
|
|
||||||
err := generateRandom(args)
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
commandGenerateRandom.Flags().BoolVar(&outputBase64, "base64", false, "Generate base64 string")
|
|
||||||
commandGenerateRandom.Flags().BoolVar(&outputHex, "hex", false, "Generate hex string")
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateRandom(args []string) error {
|
|
||||||
length, err := strconv.Atoi(args[0])
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
randomBytes := make([]byte, length)
|
|
||||||
_, err = rand.Read(randomBytes)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
if outputBase64 {
|
|
||||||
_, err = os.Stdout.WriteString(base64.StdEncoding.EncodeToString(randomBytes) + "\n")
|
|
||||||
} else if outputHex {
|
|
||||||
_, err = os.Stdout.WriteString(hex.EncodeToString(randomBytes) + "\n")
|
|
||||||
} else {
|
|
||||||
_, err = os.Stdout.Write(randomBytes)
|
|
||||||
}
|
|
||||||
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
var commandGenerateUUID = &cobra.Command{
|
|
||||||
Use: "uuid",
|
|
||||||
Short: "Generate UUID string",
|
|
||||||
Args: cobra.NoArgs,
|
|
||||||
Run: func(cmd *cobra.Command, args []string) {
|
|
||||||
err := generateUUID()
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateUUID() error {
|
|
||||||
newUUID, err := uuid.NewV4()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
_, err = os.Stdout.WriteString(newUUID.String() + "\n")
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
var commandGenerateWireGuardKeyPair = &cobra.Command{
|
|
||||||
Use: "wg-keypair",
|
|
||||||
Short: "Generate WireGuard key pair",
|
|
||||||
Args: cobra.NoArgs,
|
|
||||||
Run: func(cmd *cobra.Command, args []string) {
|
|
||||||
err := generateWireGuardKey()
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateWireGuardKey() error {
|
|
||||||
privateKey, err := wgtypes.GeneratePrivateKey()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
os.Stdout.WriteString("PrivateKey: " + privateKey.String() + "\n")
|
|
||||||
os.Stdout.WriteString("PublicKey: " + privateKey.PublicKey().String() + "\n")
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var commandGenerateRealityKeyPair = &cobra.Command{
|
|
||||||
Use: "reality-keypair",
|
|
||||||
Short: "Generate reality key pair",
|
|
||||||
Args: cobra.NoArgs,
|
|
||||||
Run: func(cmd *cobra.Command, args []string) {
|
|
||||||
err := generateRealityKey()
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
func generateRealityKey() error {
|
|
||||||
privateKey, err := wgtypes.GeneratePrivateKey()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
publicKey := privateKey.PublicKey()
|
|
||||||
os.Stdout.WriteString("PrivateKey: " + base64.RawURLEncoding.EncodeToString(privateKey[:]) + "\n")
|
|
||||||
os.Stdout.WriteString("PublicKey: " + base64.RawURLEncoding.EncodeToString(publicKey[:]) + "\n")
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
@@ -64,7 +64,7 @@ func create() (*box.Box, context.CancelFunc, error) {
|
|||||||
options.Log.DisableColor = true
|
options.Log.DisableColor = true
|
||||||
}
|
}
|
||||||
ctx, cancel := context.WithCancel(context.Background())
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
instance, err := box.New(ctx, options, nil)
|
instance, err := box.New(ctx, options)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
cancel()
|
cancel()
|
||||||
return nil, nil, E.Cause(err, "create service")
|
return nil, nil, E.Cause(err, "create service")
|
||||||
|
|||||||
@@ -1,51 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net"
|
|
||||||
"runtime/debug"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
type Conn struct {
|
|
||||||
net.Conn
|
|
||||||
element *list.Element[*ConnEntry]
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewConn(conn net.Conn) *Conn {
|
|
||||||
entry := &ConnEntry{
|
|
||||||
Conn: conn,
|
|
||||||
Stack: debug.Stack(),
|
|
||||||
}
|
|
||||||
connAccess.Lock()
|
|
||||||
element := openConnection.PushBack(entry)
|
|
||||||
connAccess.Unlock()
|
|
||||||
return &Conn{
|
|
||||||
Conn: conn,
|
|
||||||
element: element,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) Close() error {
|
|
||||||
if c.element.Value != nil {
|
|
||||||
connAccess.Lock()
|
|
||||||
if c.element.Value != nil {
|
|
||||||
openConnection.Remove(c.element)
|
|
||||||
c.element.Value = nil
|
|
||||||
}
|
|
||||||
connAccess.Unlock()
|
|
||||||
}
|
|
||||||
return c.Conn.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) Upstream() any {
|
|
||||||
return c.Conn
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) ReaderReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *Conn) WriterReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net"
|
|
||||||
"runtime/debug"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
type PacketConn struct {
|
|
||||||
net.PacketConn
|
|
||||||
element *list.Element[*ConnEntry]
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewPacketConn(conn net.PacketConn) *PacketConn {
|
|
||||||
entry := &ConnEntry{
|
|
||||||
Conn: conn,
|
|
||||||
Stack: debug.Stack(),
|
|
||||||
}
|
|
||||||
connAccess.Lock()
|
|
||||||
element := openConnection.PushBack(entry)
|
|
||||||
connAccess.Unlock()
|
|
||||||
return &PacketConn{
|
|
||||||
PacketConn: conn,
|
|
||||||
element: element,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) Close() error {
|
|
||||||
if c.element.Value != nil {
|
|
||||||
connAccess.Lock()
|
|
||||||
if c.element.Value != nil {
|
|
||||||
openConnection.Remove(c.element)
|
|
||||||
c.element.Value = nil
|
|
||||||
}
|
|
||||||
connAccess.Unlock()
|
|
||||||
}
|
|
||||||
return c.PacketConn.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) Upstream() any {
|
|
||||||
return c.PacketConn
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) ReaderReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *PacketConn) WriterReplaceable() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
package conntrack
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
"sync"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
connAccess sync.RWMutex
|
|
||||||
openConnection list.List[*ConnEntry]
|
|
||||||
)
|
|
||||||
|
|
||||||
type ConnEntry struct {
|
|
||||||
Conn io.Closer
|
|
||||||
Stack []byte
|
|
||||||
}
|
|
||||||
|
|
||||||
func Count() int {
|
|
||||||
return openConnection.Len()
|
|
||||||
}
|
|
||||||
|
|
||||||
func List() []*ConnEntry {
|
|
||||||
connAccess.RLock()
|
|
||||||
defer connAccess.RUnlock()
|
|
||||||
connList := make([]*ConnEntry, 0, openConnection.Len())
|
|
||||||
for element := openConnection.Front(); element != nil; element = element.Next() {
|
|
||||||
connList = append(connList, element.Value)
|
|
||||||
}
|
|
||||||
return connList
|
|
||||||
}
|
|
||||||
|
|
||||||
func Close() {
|
|
||||||
connAccess.Lock()
|
|
||||||
defer connAccess.Unlock()
|
|
||||||
for element := openConnection.Front(); element != nil; element = element.Next() {
|
|
||||||
common.Close(element.Value.Conn)
|
|
||||||
element.Value = nil
|
|
||||||
}
|
|
||||||
openConnection = list.List[*ConnEntry]{}
|
|
||||||
}
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
//go:build !with_conntrack
|
|
||||||
|
|
||||||
package conntrack
|
|
||||||
|
|
||||||
const Enabled = false
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
//go:build with_conntrack
|
|
||||||
|
|
||||||
package conntrack
|
|
||||||
|
|
||||||
const Enabled = true
|
|
||||||
@@ -6,7 +6,6 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/common/dialer/conntrack"
|
|
||||||
"github.com/sagernet/sing-box/common/warning"
|
"github.com/sagernet/sing-box/common/warning"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
@@ -14,7 +13,8 @@ import (
|
|||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
N "github.com/sagernet/sing/common/network"
|
N "github.com/sagernet/sing/common/network"
|
||||||
"github.com/sagernet/tfo-go"
|
|
||||||
|
"github.com/database64128/tfo-go/v2"
|
||||||
)
|
)
|
||||||
|
|
||||||
var warnBindInterfaceOnUnsupportedPlatform = warning.New(
|
var warnBindInterfaceOnUnsupportedPlatform = warning.New(
|
||||||
@@ -71,7 +71,15 @@ func NewDefault(router adapter.Router, options option.DialerOptions) *DefaultDia
|
|||||||
dialer.Control = control.Append(dialer.Control, bindFunc)
|
dialer.Control = control.Append(dialer.Control, bindFunc)
|
||||||
listener.Control = control.Append(listener.Control, bindFunc)
|
listener.Control = control.Append(listener.Control, bindFunc)
|
||||||
} else if router.AutoDetectInterface() {
|
} else if router.AutoDetectInterface() {
|
||||||
bindFunc := router.AutoDetectInterfaceFunc()
|
const useInterfaceName = C.IsLinux
|
||||||
|
bindFunc := control.BindToInterfaceFunc(router.InterfaceFinder(), func(network string, address string) (interfaceName string, interfaceIndex int) {
|
||||||
|
remoteAddr := M.ParseSocksaddr(address).Addr
|
||||||
|
if C.IsLinux {
|
||||||
|
return router.InterfaceMonitor().DefaultInterfaceName(remoteAddr), -1
|
||||||
|
} else {
|
||||||
|
return "", router.InterfaceMonitor().DefaultInterfaceIndex(remoteAddr)
|
||||||
|
}
|
||||||
|
})
|
||||||
dialer.Control = control.Append(dialer.Control, bindFunc)
|
dialer.Control = control.Append(dialer.Control, bindFunc)
|
||||||
listener.Control = control.Append(listener.Control, bindFunc)
|
listener.Control = control.Append(listener.Control, bindFunc)
|
||||||
} else if router.DefaultInterface() != "" {
|
} else if router.DefaultInterface() != "" {
|
||||||
@@ -160,30 +168,16 @@ func (d *DefaultDialer) DialContext(ctx context.Context, network string, address
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
if !address.IsIPv6() {
|
if !address.IsIPv6() {
|
||||||
return trackConn(DialSlowContext(&d.dialer4, ctx, network, address))
|
return DialSlowContext(&d.dialer4, ctx, network, address)
|
||||||
} else {
|
} else {
|
||||||
return trackConn(DialSlowContext(&d.dialer6, ctx, network, address))
|
return DialSlowContext(&d.dialer6, ctx, network, address)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (d *DefaultDialer) ListenPacket(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
|
func (d *DefaultDialer) ListenPacket(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
|
||||||
if !destination.IsIPv6() {
|
if !destination.IsIPv6() {
|
||||||
return trackPacketConn(d.udpListener.ListenPacket(ctx, N.NetworkUDP, d.udpAddr4))
|
return d.udpListener.ListenPacket(ctx, N.NetworkUDP, d.udpAddr4)
|
||||||
} else {
|
} else {
|
||||||
return trackPacketConn(d.udpListener.ListenPacket(ctx, N.NetworkUDP, d.udpAddr6))
|
return d.udpListener.ListenPacket(ctx, N.NetworkUDP, d.udpAddr6)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func trackConn(conn net.Conn, err error) (net.Conn, error) {
|
|
||||||
if !conntrack.Enabled || err != nil {
|
|
||||||
return conn, err
|
|
||||||
}
|
|
||||||
return conntrack.NewConn(conn), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func trackPacketConn(conn net.PacketConn, err error) (net.PacketConn, error) {
|
|
||||||
if !conntrack.Enabled || err != nil {
|
|
||||||
return conn, err
|
|
||||||
}
|
|
||||||
return conntrack.NewPacketConn(conn), nil
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -12,7 +12,8 @@ import (
|
|||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
N "github.com/sagernet/sing/common/network"
|
N "github.com/sagernet/sing/common/network"
|
||||||
"github.com/sagernet/tfo-go"
|
|
||||||
|
"github.com/database64128/tfo-go/v2"
|
||||||
)
|
)
|
||||||
|
|
||||||
type slowOpenConn struct {
|
type slowOpenConn struct {
|
||||||
|
|||||||
@@ -24,13 +24,13 @@ func (l *Listener) Accept() (net.Conn, error) {
|
|||||||
bufReader := std_bufio.NewReader(conn)
|
bufReader := std_bufio.NewReader(conn)
|
||||||
header, err := proxyproto.Read(bufReader)
|
header, err := proxyproto.Read(bufReader)
|
||||||
if err != nil && !(l.AcceptNoHeader && err == proxyproto.ErrNoProxyProtocol) {
|
if err != nil && !(l.AcceptNoHeader && err == proxyproto.ErrNoProxyProtocol) {
|
||||||
return nil, &Error{err}
|
return nil, err
|
||||||
}
|
}
|
||||||
if bufReader.Buffered() > 0 {
|
if bufReader.Buffered() > 0 {
|
||||||
cache := buf.NewSize(bufReader.Buffered())
|
cache := buf.NewSize(bufReader.Buffered())
|
||||||
_, err = cache.ReadFullFrom(bufReader, cache.FreeLen())
|
_, err = cache.ReadFullFrom(bufReader, cache.FreeLen())
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, &Error{err}
|
return nil, err
|
||||||
}
|
}
|
||||||
conn = bufio.NewCachedConn(conn, cache)
|
conn = bufio.NewCachedConn(conn, cache)
|
||||||
}
|
}
|
||||||
@@ -42,21 +42,3 @@ func (l *Listener) Accept() (net.Conn, error) {
|
|||||||
}
|
}
|
||||||
return conn, nil
|
return conn, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var _ net.Error = (*Error)(nil)
|
|
||||||
|
|
||||||
type Error struct {
|
|
||||||
error
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *Error) Unwrap() error {
|
|
||||||
return e.error
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *Error) Timeout() bool {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *Error) Temporary() bool {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -6,8 +6,8 @@ import (
|
|||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
F "github.com/sagernet/sing/common/format"
|
F "github.com/sagernet/sing/common/format"
|
||||||
|
"github.com/sagernet/sing/common/shell"
|
||||||
)
|
)
|
||||||
|
|
||||||
var (
|
var (
|
||||||
@@ -26,9 +26,9 @@ func init() {
|
|||||||
|
|
||||||
func runAndroidShell(name string, args ...string) error {
|
func runAndroidShell(name string, args ...string) error {
|
||||||
if !useRish {
|
if !useRish {
|
||||||
return common.Exec(name, args...).Attach().Run()
|
return shell.Exec(name, args...).Attach().Run()
|
||||||
} else {
|
} else {
|
||||||
return common.Exec("sh", rishPath, "-c", F.ToString(name, " ", strings.Join(args, " "))).Attach().Run()
|
return shell.Exec("sh", rishPath, "-c", F.ToString(name, " ", strings.Join(args, " "))).Attach().Run()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -6,9 +6,9 @@ import (
|
|||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-tun"
|
"github.com/sagernet/sing-tun"
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
F "github.com/sagernet/sing/common/format"
|
F "github.com/sagernet/sing/common/format"
|
||||||
|
"github.com/sagernet/sing/common/shell"
|
||||||
"github.com/sagernet/sing/common/x/list"
|
"github.com/sagernet/sing/common/x/list"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -34,13 +34,13 @@ func (p *systemProxy) update(event int) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if p.isMixed {
|
if p.isMixed {
|
||||||
err = common.Exec("networksetup", "-setsocksfirewallproxy", interfaceDisplayName, "127.0.0.1", F.ToString(p.port)).Attach().Run()
|
err = shell.Exec("networksetup", "-setsocksfirewallproxy", interfaceDisplayName, "127.0.0.1", F.ToString(p.port)).Attach().Run()
|
||||||
}
|
}
|
||||||
if err == nil {
|
if err == nil {
|
||||||
err = common.Exec("networksetup", "-setwebproxy", interfaceDisplayName, "127.0.0.1", F.ToString(p.port)).Attach().Run()
|
err = shell.Exec("networksetup", "-setwebproxy", interfaceDisplayName, "127.0.0.1", F.ToString(p.port)).Attach().Run()
|
||||||
}
|
}
|
||||||
if err == nil {
|
if err == nil {
|
||||||
err = common.Exec("networksetup", "-setsecurewebproxy", interfaceDisplayName, "127.0.0.1", F.ToString(p.port)).Attach().Run()
|
err = shell.Exec("networksetup", "-setsecurewebproxy", interfaceDisplayName, "127.0.0.1", F.ToString(p.port)).Attach().Run()
|
||||||
}
|
}
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -51,19 +51,19 @@ func (p *systemProxy) unset() error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if p.isMixed {
|
if p.isMixed {
|
||||||
err = common.Exec("networksetup", "-setsocksfirewallproxystate", interfaceDisplayName, "off").Attach().Run()
|
err = shell.Exec("networksetup", "-setsocksfirewallproxystate", interfaceDisplayName, "off").Attach().Run()
|
||||||
}
|
}
|
||||||
if err == nil {
|
if err == nil {
|
||||||
err = common.Exec("networksetup", "-setwebproxystate", interfaceDisplayName, "off").Attach().Run()
|
err = shell.Exec("networksetup", "-setwebproxystate", interfaceDisplayName, "off").Attach().Run()
|
||||||
}
|
}
|
||||||
if err == nil {
|
if err == nil {
|
||||||
err = common.Exec("networksetup", "-setsecurewebproxystate", interfaceDisplayName, "off").Attach().Run()
|
err = shell.Exec("networksetup", "-setsecurewebproxystate", interfaceDisplayName, "off").Attach().Run()
|
||||||
}
|
}
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
func getInterfaceDisplayName(name string) (string, error) {
|
func getInterfaceDisplayName(name string) (string, error) {
|
||||||
content, err := common.Exec("networksetup", "-listallhardwareports").Read()
|
content, err := shell.Exec("networksetup", "-listallhardwareports").ReadOutput()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import (
|
|||||||
"github.com/sagernet/sing/common"
|
"github.com/sagernet/sing/common"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
F "github.com/sagernet/sing/common/format"
|
F "github.com/sagernet/sing/common/format"
|
||||||
|
"github.com/sagernet/sing/common/shell"
|
||||||
)
|
)
|
||||||
|
|
||||||
var (
|
var (
|
||||||
@@ -27,9 +28,9 @@ func init() {
|
|||||||
|
|
||||||
func runAsUser(name string, args ...string) error {
|
func runAsUser(name string, args ...string) error {
|
||||||
if os.Getuid() != 0 {
|
if os.Getuid() != 0 {
|
||||||
return common.Exec(name, args...).Attach().Run()
|
return shell.Exec(name, args...).Attach().Run()
|
||||||
} else if sudoUser != "" {
|
} else if sudoUser != "" {
|
||||||
return common.Exec("su", "-", sudoUser, "-c", F.ToString(name, " ", strings.Join(args, " "))).Attach().Run()
|
return shell.Exec("su", "-", sudoUser, "-c", F.ToString(name, " ", strings.Join(args, " "))).Attach().Run()
|
||||||
} else {
|
} else {
|
||||||
return E.New("set system proxy: unable to set as root")
|
return E.New("set system proxy: unable to set as root")
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,15 +2,16 @@ package tls
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"crypto/tls"
|
||||||
"net"
|
"net"
|
||||||
"os"
|
"os"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
|
"github.com/sagernet/sing-box/common/badtls"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
M "github.com/sagernet/sing/common/metadata"
|
||||||
N "github.com/sagernet/sing/common/network"
|
N "github.com/sagernet/sing/common/network"
|
||||||
aTLS "github.com/sagernet/sing/common/tls"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func NewDialerFromOptions(router adapter.Router, dialer N.Dialer, serverAddress string, options option.OutboundTLSOptions) (N.Dialer, error) {
|
func NewDialerFromOptions(router adapter.Router, dialer N.Dialer, serverAddress string, options option.OutboundTLSOptions) (N.Dialer, error) {
|
||||||
@@ -30,19 +31,29 @@ func NewClient(router adapter.Router, serverAddress string, options option.Outbo
|
|||||||
}
|
}
|
||||||
if options.ECH != nil && options.ECH.Enabled {
|
if options.ECH != nil && options.ECH.Enabled {
|
||||||
return NewECHClient(router, serverAddress, options)
|
return NewECHClient(router, serverAddress, options)
|
||||||
} else if options.Reality != nil && options.Reality.Enabled {
|
|
||||||
return NewRealityClient(router, serverAddress, options)
|
|
||||||
} else if options.UTLS != nil && options.UTLS.Enabled {
|
} else if options.UTLS != nil && options.UTLS.Enabled {
|
||||||
return NewUTLSClient(router, serverAddress, options)
|
return NewUTLSClient(router, serverAddress, options)
|
||||||
} else {
|
} else {
|
||||||
return NewSTDClient(router, serverAddress, options)
|
return NewSTDClient(serverAddress, options)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func ClientHandshake(ctx context.Context, conn net.Conn, config Config) (Conn, error) {
|
func ClientHandshake(ctx context.Context, conn net.Conn, config Config) (Conn, error) {
|
||||||
|
tlsConn := config.Client(conn)
|
||||||
ctx, cancel := context.WithTimeout(ctx, C.TCPTimeout)
|
ctx, cancel := context.WithTimeout(ctx, C.TCPTimeout)
|
||||||
defer cancel()
|
defer cancel()
|
||||||
return aTLS.ClientHandshake(ctx, conn, config)
|
err := tlsConn.HandshakeContext(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if stdConn, isSTD := tlsConn.(*tls.Conn); isSTD {
|
||||||
|
var badConn badtls.TLSConn
|
||||||
|
badConn, err = badtls.Create(stdConn)
|
||||||
|
if err == nil {
|
||||||
|
return badConn, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return tlsConn, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
type Dialer struct {
|
type Dialer struct {
|
||||||
|
|||||||
@@ -1,25 +1,41 @@
|
|||||||
package tls
|
package tls
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
|
"net"
|
||||||
|
|
||||||
|
"github.com/sagernet/sing-box/adapter"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
aTLS "github.com/sagernet/sing/common/tls"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type (
|
type (
|
||||||
Config = aTLS.Config
|
STDConfig = tls.Config
|
||||||
ConfigCompat = aTLS.ConfigCompat
|
STDConn = tls.Conn
|
||||||
ServerConfig = aTLS.ServerConfig
|
|
||||||
ServerConfigCompat = aTLS.ServerConfigCompat
|
|
||||||
WithSessionIDGenerator = aTLS.WithSessionIDGenerator
|
|
||||||
Conn = aTLS.Conn
|
|
||||||
|
|
||||||
STDConfig = tls.Config
|
|
||||||
STDConn = tls.Conn
|
|
||||||
ConnectionState = tls.ConnectionState
|
|
||||||
)
|
)
|
||||||
|
|
||||||
|
type Config interface {
|
||||||
|
ServerName() string
|
||||||
|
SetServerName(serverName string)
|
||||||
|
NextProtos() []string
|
||||||
|
SetNextProtos(nextProto []string)
|
||||||
|
Config() (*STDConfig, error)
|
||||||
|
Client(conn net.Conn) Conn
|
||||||
|
Clone() Config
|
||||||
|
}
|
||||||
|
|
||||||
|
type ServerConfig interface {
|
||||||
|
Config
|
||||||
|
adapter.Service
|
||||||
|
Server(conn net.Conn) Conn
|
||||||
|
}
|
||||||
|
|
||||||
|
type Conn interface {
|
||||||
|
net.Conn
|
||||||
|
HandshakeContext(ctx context.Context) error
|
||||||
|
ConnectionState() tls.ConnectionState
|
||||||
|
}
|
||||||
|
|
||||||
func ParseTLSVersion(version string) (uint16, error) {
|
func ParseTLSVersion(version string) (uint16, error) {
|
||||||
switch version {
|
switch version {
|
||||||
case "1.0":
|
case "1.0":
|
||||||
|
|||||||
@@ -44,8 +44,8 @@ func (e *ECHClientConfig) Config() (*STDConfig, error) {
|
|||||||
return nil, E.New("unsupported usage for ECH")
|
return nil, E.New("unsupported usage for ECH")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (e *ECHClientConfig) Client(conn net.Conn) (Conn, error) {
|
func (e *ECHClientConfig) Client(conn net.Conn) Conn {
|
||||||
return &echConnWrapper{cftls.Client(conn, e.config)}, nil
|
return &echConnWrapper{cftls.Client(conn, e.config)}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (e *ECHClientConfig) Clone() Config {
|
func (e *ECHClientConfig) Clone() Config {
|
||||||
@@ -76,10 +76,6 @@ func (c *echConnWrapper) ConnectionState() tls.ConnectionState {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *echConnWrapper) Upstream() any {
|
|
||||||
return c.Conn
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewECHClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
func NewECHClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
||||||
var serverName string
|
var serverName string
|
||||||
if options.ServerName != "" {
|
if options.ServerName != "" {
|
||||||
@@ -94,7 +90,6 @@ func NewECHClient(router adapter.Router, serverAddress string, options option.Ou
|
|||||||
}
|
}
|
||||||
|
|
||||||
var tlsConfig cftls.Config
|
var tlsConfig cftls.Config
|
||||||
tlsConfig.Time = router.TimeFunc()
|
|
||||||
if options.DisableSNI {
|
if options.DisableSNI {
|
||||||
tlsConfig.ServerName = "127.0.0.1"
|
tlsConfig.ServerName = "127.0.0.1"
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -11,10 +11,7 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
func GenerateKeyPair(timeFunc func() time.Time, serverName string) (*tls.Certificate, error) {
|
func GenerateKeyPair(serverName string) (*tls.Certificate, error) {
|
||||||
if timeFunc == nil {
|
|
||||||
timeFunc = time.Now
|
|
||||||
}
|
|
||||||
key, err := rsa.GenerateKey(rand.Reader, 2048)
|
key, err := rsa.GenerateKey(rand.Reader, 2048)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
@@ -25,8 +22,8 @@ func GenerateKeyPair(timeFunc func() time.Time, serverName string) (*tls.Certifi
|
|||||||
}
|
}
|
||||||
template := &x509.Certificate{
|
template := &x509.Certificate{
|
||||||
SerialNumber: serialNumber,
|
SerialNumber: serialNumber,
|
||||||
NotBefore: timeFunc().Add(time.Hour * -1),
|
NotBefore: time.Now().Add(time.Hour * -1),
|
||||||
NotAfter: timeFunc().Add(time.Hour),
|
NotAfter: time.Now().Add(time.Hour),
|
||||||
KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature,
|
KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature,
|
||||||
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
|
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
|
||||||
BasicConstraintsValid: true,
|
BasicConstraintsValid: true,
|
||||||
|
|||||||
@@ -1,230 +0,0 @@
|
|||||||
//go:build with_utls
|
|
||||||
|
|
||||||
package tls
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"context"
|
|
||||||
"crypto/aes"
|
|
||||||
"crypto/cipher"
|
|
||||||
"crypto/ed25519"
|
|
||||||
"crypto/hmac"
|
|
||||||
"crypto/sha256"
|
|
||||||
"crypto/sha512"
|
|
||||||
"crypto/tls"
|
|
||||||
"crypto/x509"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/binary"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
mRand "math/rand"
|
|
||||||
"net"
|
|
||||||
"net/http"
|
|
||||||
"reflect"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
"unsafe"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
|
||||||
"github.com/sagernet/sing/common/debug"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
aTLS "github.com/sagernet/sing/common/tls"
|
|
||||||
utls "github.com/sagernet/utls"
|
|
||||||
|
|
||||||
"golang.org/x/crypto/hkdf"
|
|
||||||
"golang.org/x/net/http2"
|
|
||||||
)
|
|
||||||
|
|
||||||
var _ ConfigCompat = (*RealityClientConfig)(nil)
|
|
||||||
|
|
||||||
type RealityClientConfig struct {
|
|
||||||
uClient *UTLSClientConfig
|
|
||||||
publicKey []byte
|
|
||||||
shortID []byte
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewRealityClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (*RealityClientConfig, error) {
|
|
||||||
if options.UTLS == nil || !options.UTLS.Enabled {
|
|
||||||
return nil, E.New("uTLS is required by reality client")
|
|
||||||
}
|
|
||||||
|
|
||||||
uClient, err := NewUTLSClient(router, serverAddress, options)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
publicKey, err := base64.RawURLEncoding.DecodeString(options.Reality.PublicKey)
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "decode public_key")
|
|
||||||
}
|
|
||||||
if len(publicKey) != 32 {
|
|
||||||
return nil, E.New("invalid public_key")
|
|
||||||
}
|
|
||||||
shortID, err := hex.DecodeString(options.Reality.ShortID)
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "decode short_id")
|
|
||||||
}
|
|
||||||
if len(shortID) != 8 {
|
|
||||||
return nil, E.New("invalid short_id")
|
|
||||||
}
|
|
||||||
return &RealityClientConfig{uClient, publicKey, shortID}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) ServerName() string {
|
|
||||||
return e.uClient.ServerName()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) SetServerName(serverName string) {
|
|
||||||
e.uClient.SetServerName(serverName)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) NextProtos() []string {
|
|
||||||
return e.uClient.NextProtos()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) SetNextProtos(nextProto []string) {
|
|
||||||
e.uClient.SetNextProtos(nextProto)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) Config() (*STDConfig, error) {
|
|
||||||
return nil, E.New("unsupported usage for reality")
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) Client(conn net.Conn) (Conn, error) {
|
|
||||||
return ClientHandshake(context.Background(), conn, e)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) ClientHandshake(ctx context.Context, conn net.Conn) (aTLS.Conn, error) {
|
|
||||||
verifier := &realityVerifier{
|
|
||||||
serverName: e.uClient.ServerName(),
|
|
||||||
}
|
|
||||||
uConfig := e.uClient.config.Clone()
|
|
||||||
uConfig.InsecureSkipVerify = true
|
|
||||||
uConfig.SessionTicketsDisabled = true
|
|
||||||
uConfig.VerifyPeerCertificate = verifier.VerifyPeerCertificate
|
|
||||||
uConn := utls.UClient(conn, uConfig, e.uClient.id)
|
|
||||||
verifier.UConn = uConn
|
|
||||||
err := uConn.BuildHandshakeState()
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
hello := uConn.HandshakeState.Hello
|
|
||||||
hello.SessionId = make([]byte, 32)
|
|
||||||
copy(hello.Raw[39:], hello.SessionId)
|
|
||||||
|
|
||||||
var nowTime time.Time
|
|
||||||
if uConfig.Time != nil {
|
|
||||||
nowTime = uConfig.Time()
|
|
||||||
} else {
|
|
||||||
nowTime = time.Now()
|
|
||||||
}
|
|
||||||
binary.BigEndian.PutUint64(hello.SessionId, uint64(nowTime.Unix()))
|
|
||||||
|
|
||||||
hello.SessionId[0] = 1
|
|
||||||
hello.SessionId[1] = 7
|
|
||||||
hello.SessionId[2] = 5
|
|
||||||
copy(hello.SessionId[8:], e.shortID)
|
|
||||||
|
|
||||||
if debug.Enabled {
|
|
||||||
fmt.Printf("REALITY hello.sessionId[:16]: %v\n", hello.SessionId[:16])
|
|
||||||
}
|
|
||||||
|
|
||||||
authKey := uConn.HandshakeState.State13.EcdheParams.SharedKey(e.publicKey)
|
|
||||||
if authKey == nil {
|
|
||||||
return nil, E.New("nil auth_key")
|
|
||||||
}
|
|
||||||
verifier.authKey = authKey
|
|
||||||
_, err = hkdf.New(sha256.New, authKey, hello.Random[:20], []byte("REALITY")).Read(authKey)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
aesBlock, _ := aes.NewCipher(authKey)
|
|
||||||
aesGcmCipher, _ := cipher.NewGCM(aesBlock)
|
|
||||||
aesGcmCipher.Seal(hello.SessionId[:0], hello.Random[20:], hello.SessionId[:16], hello.Raw)
|
|
||||||
copy(hello.Raw[39:], hello.SessionId)
|
|
||||||
if debug.Enabled {
|
|
||||||
fmt.Printf("REALITY hello.sessionId: %v\n", hello.SessionId)
|
|
||||||
fmt.Printf("REALITY uConn.AuthKey: %v\n", authKey)
|
|
||||||
}
|
|
||||||
|
|
||||||
err = uConn.HandshakeContext(ctx)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
if debug.Enabled {
|
|
||||||
fmt.Printf("REALITY Conn.Verified: %v\n", verifier.verified)
|
|
||||||
}
|
|
||||||
|
|
||||||
if !verifier.verified {
|
|
||||||
go realityClientFallback(uConn, e.uClient.ServerName(), e.uClient.id)
|
|
||||||
return nil, E.New("reality verification failed")
|
|
||||||
}
|
|
||||||
|
|
||||||
return &utlsConnWrapper{uConn}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func realityClientFallback(uConn net.Conn, serverName string, fingerprint utls.ClientHelloID) {
|
|
||||||
defer uConn.Close()
|
|
||||||
client := &http.Client{
|
|
||||||
Transport: &http2.Transport{
|
|
||||||
DialTLSContext: func(ctx context.Context, network, addr string, config *tls.Config) (net.Conn, error) {
|
|
||||||
return uConn, nil
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
request, _ := http.NewRequest("GET", "https://"+serverName, nil)
|
|
||||||
request.Header.Set("User-Agent", fingerprint.Client)
|
|
||||||
request.AddCookie(&http.Cookie{Name: "padding", Value: strings.Repeat("0", mRand.Intn(32)+30)})
|
|
||||||
response, err := client.Do(request)
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
_, _ = io.Copy(io.Discard, response.Body)
|
|
||||||
response.Body.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) SetSessionIDGenerator(generator func(clientHello []byte, sessionID []byte) error) {
|
|
||||||
e.uClient.config.SessionIDGenerator = generator
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *RealityClientConfig) Clone() Config {
|
|
||||||
return &RealityClientConfig{
|
|
||||||
e.uClient.Clone().(*UTLSClientConfig),
|
|
||||||
e.publicKey,
|
|
||||||
e.shortID,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
type realityVerifier struct {
|
|
||||||
*utls.UConn
|
|
||||||
serverName string
|
|
||||||
authKey []byte
|
|
||||||
verified bool
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *realityVerifier) VerifyPeerCertificate(rawCerts [][]byte, verifiedChains [][]*x509.Certificate) error {
|
|
||||||
p, _ := reflect.TypeOf(c.Conn).Elem().FieldByName("peerCertificates")
|
|
||||||
certs := *(*([]*x509.Certificate))(unsafe.Pointer(uintptr(unsafe.Pointer(c.Conn)) + p.Offset))
|
|
||||||
if pub, ok := certs[0].PublicKey.(ed25519.PublicKey); ok {
|
|
||||||
h := hmac.New(sha512.New, c.authKey)
|
|
||||||
h.Write(pub)
|
|
||||||
if bytes.Equal(h.Sum(nil), certs[0].Signature) {
|
|
||||||
c.verified = true
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
opts := x509.VerifyOptions{
|
|
||||||
DNSName: c.serverName,
|
|
||||||
Intermediates: x509.NewCertPool(),
|
|
||||||
}
|
|
||||||
for _, cert := range certs[1:] {
|
|
||||||
opts.Intermediates.AddCert(cert)
|
|
||||||
}
|
|
||||||
if _, err := certs[0].Verify(opts); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
@@ -1,192 +0,0 @@
|
|||||||
//go:build with_reality_server
|
|
||||||
|
|
||||||
package tls
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"crypto/tls"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/hex"
|
|
||||||
"net"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/sagernet/reality"
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
|
||||||
"github.com/sagernet/sing-box/common/dialer"
|
|
||||||
"github.com/sagernet/sing-box/log"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
|
||||||
"github.com/sagernet/sing/common/debug"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
M "github.com/sagernet/sing/common/metadata"
|
|
||||||
N "github.com/sagernet/sing/common/network"
|
|
||||||
)
|
|
||||||
|
|
||||||
var _ ServerConfigCompat = (*RealityServerConfig)(nil)
|
|
||||||
|
|
||||||
type RealityServerConfig struct {
|
|
||||||
config *reality.Config
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewRealityServer(ctx context.Context, router adapter.Router, logger log.Logger, options option.InboundTLSOptions) (*RealityServerConfig, error) {
|
|
||||||
var tlsConfig reality.Config
|
|
||||||
|
|
||||||
if options.ACME != nil && len(options.ACME.Domain) > 0 {
|
|
||||||
return nil, E.New("acme is unavailable in reality")
|
|
||||||
}
|
|
||||||
tlsConfig.Time = router.TimeFunc()
|
|
||||||
if options.ServerName != "" {
|
|
||||||
tlsConfig.ServerName = options.ServerName
|
|
||||||
}
|
|
||||||
if len(options.ALPN) > 0 {
|
|
||||||
tlsConfig.NextProtos = append(tlsConfig.NextProtos, options.ALPN...)
|
|
||||||
}
|
|
||||||
if options.MinVersion != "" {
|
|
||||||
minVersion, err := ParseTLSVersion(options.MinVersion)
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "parse min_version")
|
|
||||||
}
|
|
||||||
tlsConfig.MinVersion = minVersion
|
|
||||||
}
|
|
||||||
if options.MaxVersion != "" {
|
|
||||||
maxVersion, err := ParseTLSVersion(options.MaxVersion)
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "parse max_version")
|
|
||||||
}
|
|
||||||
tlsConfig.MaxVersion = maxVersion
|
|
||||||
}
|
|
||||||
if options.CipherSuites != nil {
|
|
||||||
find:
|
|
||||||
for _, cipherSuite := range options.CipherSuites {
|
|
||||||
for _, tlsCipherSuite := range tls.CipherSuites() {
|
|
||||||
if cipherSuite == tlsCipherSuite.Name {
|
|
||||||
tlsConfig.CipherSuites = append(tlsConfig.CipherSuites, tlsCipherSuite.ID)
|
|
||||||
continue find
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return nil, E.New("unknown cipher_suite: ", cipherSuite)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if options.Certificate != "" || options.CertificatePath != "" {
|
|
||||||
return nil, E.New("certificate is unavailable in reality")
|
|
||||||
}
|
|
||||||
if options.Key != "" || options.KeyPath != "" {
|
|
||||||
return nil, E.New("key is unavailable in reality")
|
|
||||||
}
|
|
||||||
|
|
||||||
tlsConfig.SessionTicketsDisabled = true
|
|
||||||
tlsConfig.Type = N.NetworkTCP
|
|
||||||
tlsConfig.Dest = options.Reality.Handshake.ServerOptions.Build().String()
|
|
||||||
|
|
||||||
tlsConfig.ServerNames = map[string]bool{options.ServerName: true}
|
|
||||||
privateKey, err := base64.RawURLEncoding.DecodeString(options.Reality.PrivateKey)
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "decode private key")
|
|
||||||
}
|
|
||||||
if len(privateKey) != 32 {
|
|
||||||
return nil, E.New("invalid private key")
|
|
||||||
}
|
|
||||||
tlsConfig.PrivateKey = privateKey
|
|
||||||
tlsConfig.MaxTimeDiff = time.Duration(options.Reality.MaxTimeDifference)
|
|
||||||
|
|
||||||
tlsConfig.ShortIds = make(map[[8]byte]bool)
|
|
||||||
for i, shortID := range options.Reality.ShortID {
|
|
||||||
var shortIDBytesArray [8]byte
|
|
||||||
decodedLen, err := hex.Decode(shortIDBytesArray[:], []byte(shortID))
|
|
||||||
if err != nil {
|
|
||||||
return nil, E.Cause(err, "decode short_id[", i, "]: ", shortID)
|
|
||||||
}
|
|
||||||
if decodedLen != 8 {
|
|
||||||
return nil, E.New("invalid short_id[", i, "]: ", shortID)
|
|
||||||
}
|
|
||||||
tlsConfig.ShortIds[shortIDBytesArray] = true
|
|
||||||
}
|
|
||||||
|
|
||||||
handshakeDialer := dialer.New(router, options.Reality.Handshake.DialerOptions)
|
|
||||||
tlsConfig.DialContext = func(ctx context.Context, network, addr string) (net.Conn, error) {
|
|
||||||
return handshakeDialer.DialContext(ctx, network, M.ParseSocksaddr(addr))
|
|
||||||
}
|
|
||||||
|
|
||||||
if debug.Enabled {
|
|
||||||
tlsConfig.Show = true
|
|
||||||
}
|
|
||||||
|
|
||||||
return &RealityServerConfig{&tlsConfig}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) ServerName() string {
|
|
||||||
return c.config.ServerName
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) SetServerName(serverName string) {
|
|
||||||
c.config.ServerName = serverName
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) NextProtos() []string {
|
|
||||||
return c.config.NextProtos
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) SetNextProtos(nextProto []string) {
|
|
||||||
c.config.NextProtos = nextProto
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) Config() (*tls.Config, error) {
|
|
||||||
return nil, E.New("unsupported usage for reality")
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) Client(conn net.Conn) (Conn, error) {
|
|
||||||
return ClientHandshake(context.Background(), conn, c)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) Start() error {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) Close() error {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) Server(conn net.Conn) (Conn, error) {
|
|
||||||
return ServerHandshake(context.Background(), conn, c)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) ServerHandshake(ctx context.Context, conn net.Conn) (Conn, error) {
|
|
||||||
tlsConn, err := reality.Server(ctx, conn, c.config)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return &realityConnWrapper{Conn: tlsConn}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *RealityServerConfig) Clone() Config {
|
|
||||||
return &RealityServerConfig{
|
|
||||||
config: c.config.Clone(),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
var _ Conn = (*realityConnWrapper)(nil)
|
|
||||||
|
|
||||||
type realityConnWrapper struct {
|
|
||||||
*reality.Conn
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *realityConnWrapper) ConnectionState() ConnectionState {
|
|
||||||
state := c.Conn.ConnectionState()
|
|
||||||
return tls.ConnectionState{
|
|
||||||
Version: state.Version,
|
|
||||||
HandshakeComplete: state.HandshakeComplete,
|
|
||||||
DidResume: state.DidResume,
|
|
||||||
CipherSuite: state.CipherSuite,
|
|
||||||
NegotiatedProtocol: state.NegotiatedProtocol,
|
|
||||||
NegotiatedProtocolIsMutual: state.NegotiatedProtocolIsMutual,
|
|
||||||
ServerName: state.ServerName,
|
|
||||||
PeerCertificates: state.PeerCertificates,
|
|
||||||
VerifiedChains: state.VerifiedChains,
|
|
||||||
SignedCertificateTimestamps: state.SignedCertificateTimestamps,
|
|
||||||
OCSPResponse: state.OCSPResponse,
|
|
||||||
TLSUnique: state.TLSUnique,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *realityConnWrapper) Upstream() any {
|
|
||||||
return c.Conn
|
|
||||||
}
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
//go:build !with_reality_server
|
|
||||||
|
|
||||||
package tls
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
|
||||||
"github.com/sagernet/sing-box/log"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
)
|
|
||||||
|
|
||||||
func NewRealityServer(ctx context.Context, router adapter.Router, logger log.Logger, options option.InboundTLSOptions) (ServerConfig, error) {
|
|
||||||
return nil, E.New(`reality server is not included in this build, rebuild with -tags with_reality_server`)
|
|
||||||
}
|
|
||||||
@@ -2,28 +2,36 @@ package tls
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"crypto/tls"
|
||||||
"net"
|
"net"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/common/badtls"
|
||||||
C "github.com/sagernet/sing-box/constant"
|
C "github.com/sagernet/sing-box/constant"
|
||||||
"github.com/sagernet/sing-box/log"
|
"github.com/sagernet/sing-box/log"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
aTLS "github.com/sagernet/sing/common/tls"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func NewServer(ctx context.Context, router adapter.Router, logger log.Logger, options option.InboundTLSOptions) (ServerConfig, error) {
|
func NewServer(ctx context.Context, logger log.Logger, options option.InboundTLSOptions) (ServerConfig, error) {
|
||||||
if !options.Enabled {
|
if !options.Enabled {
|
||||||
return nil, nil
|
return nil, nil
|
||||||
}
|
}
|
||||||
if options.Reality != nil && options.Reality.Enabled {
|
return NewSTDServer(ctx, logger, options)
|
||||||
return NewRealityServer(ctx, router, logger, options)
|
|
||||||
} else {
|
|
||||||
return NewSTDServer(ctx, router, logger, options)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func ServerHandshake(ctx context.Context, conn net.Conn, config ServerConfig) (Conn, error) {
|
func ServerHandshake(ctx context.Context, conn net.Conn, config ServerConfig) (Conn, error) {
|
||||||
|
tlsConn := config.Server(conn)
|
||||||
ctx, cancel := context.WithTimeout(ctx, C.TCPTimeout)
|
ctx, cancel := context.WithTimeout(ctx, C.TCPTimeout)
|
||||||
defer cancel()
|
defer cancel()
|
||||||
return aTLS.ServerHandshake(ctx, conn, config)
|
err := tlsConn.HandshakeContext(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if stdConn, isSTD := tlsConn.(*tls.Conn); isSTD {
|
||||||
|
var badConn badtls.TLSConn
|
||||||
|
badConn, err = badtls.Create(stdConn)
|
||||||
|
if err == nil {
|
||||||
|
return badConn, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return tlsConn, nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import (
|
|||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
)
|
)
|
||||||
@@ -36,15 +35,15 @@ func (s *STDClientConfig) Config() (*STDConfig, error) {
|
|||||||
return s.config, nil
|
return s.config, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *STDClientConfig) Client(conn net.Conn) (Conn, error) {
|
func (s *STDClientConfig) Client(conn net.Conn) Conn {
|
||||||
return tls.Client(conn, s.config), nil
|
return tls.Client(conn, s.config)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *STDClientConfig) Clone() Config {
|
func (s *STDClientConfig) Clone() Config {
|
||||||
return &STDClientConfig{s.config.Clone()}
|
return &STDClientConfig{s.config.Clone()}
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewSTDClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
func NewSTDClient(serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
||||||
var serverName string
|
var serverName string
|
||||||
if options.ServerName != "" {
|
if options.ServerName != "" {
|
||||||
serverName = options.ServerName
|
serverName = options.ServerName
|
||||||
@@ -58,7 +57,6 @@ func NewSTDClient(router adapter.Router, serverAddress string, options option.Ou
|
|||||||
}
|
}
|
||||||
|
|
||||||
var tlsConfig tls.Config
|
var tlsConfig tls.Config
|
||||||
tlsConfig.Time = router.TimeFunc()
|
|
||||||
if options.DisableSNI {
|
if options.DisableSNI {
|
||||||
tlsConfig.ServerName = "127.0.0.1"
|
tlsConfig.ServerName = "127.0.0.1"
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
@@ -48,12 +48,12 @@ func (c *STDServerConfig) Config() (*STDConfig, error) {
|
|||||||
return c.config, nil
|
return c.config, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *STDServerConfig) Client(conn net.Conn) (Conn, error) {
|
func (c *STDServerConfig) Client(conn net.Conn) Conn {
|
||||||
return tls.Client(conn, c.config), nil
|
return tls.Client(conn, c.config)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *STDServerConfig) Server(conn net.Conn) (Conn, error) {
|
func (c *STDServerConfig) Server(conn net.Conn) Conn {
|
||||||
return tls.Server(conn, c.config), nil
|
return tls.Server(conn, c.config)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *STDServerConfig) Clone() Config {
|
func (c *STDServerConfig) Clone() Config {
|
||||||
@@ -156,7 +156,7 @@ func (c *STDServerConfig) Close() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewSTDServer(ctx context.Context, router adapter.Router, logger log.Logger, options option.InboundTLSOptions) (ServerConfig, error) {
|
func NewSTDServer(ctx context.Context, logger log.Logger, options option.InboundTLSOptions) (ServerConfig, error) {
|
||||||
if !options.Enabled {
|
if !options.Enabled {
|
||||||
return nil, nil
|
return nil, nil
|
||||||
}
|
}
|
||||||
@@ -175,7 +175,6 @@ func NewSTDServer(ctx context.Context, router adapter.Router, logger log.Logger,
|
|||||||
} else {
|
} else {
|
||||||
tlsConfig = &tls.Config{}
|
tlsConfig = &tls.Config{}
|
||||||
}
|
}
|
||||||
tlsConfig.Time = router.TimeFunc()
|
|
||||||
if options.ServerName != "" {
|
if options.ServerName != "" {
|
||||||
tlsConfig.ServerName = options.ServerName
|
tlsConfig.ServerName = options.ServerName
|
||||||
}
|
}
|
||||||
@@ -231,7 +230,7 @@ func NewSTDServer(ctx context.Context, router adapter.Router, logger log.Logger,
|
|||||||
}
|
}
|
||||||
if certificate == nil && key == nil && options.Insecure {
|
if certificate == nil && key == nil && options.Insecure {
|
||||||
tlsConfig.GetCertificate = func(info *tls.ClientHelloInfo) (*tls.Certificate, error) {
|
tlsConfig.GetCertificate = func(info *tls.ClientHelloInfo) (*tls.Certificate, error) {
|
||||||
return GenerateKeyPair(router.TimeFunc(), info.ServerName)
|
return GenerateKeyPair(info.ServerName)
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if certificate == nil {
|
if certificate == nil {
|
||||||
|
|||||||
@@ -5,7 +5,6 @@ package tls
|
|||||||
import (
|
import (
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
"crypto/x509"
|
"crypto/x509"
|
||||||
"math/rand"
|
|
||||||
"net"
|
"net"
|
||||||
"net/netip"
|
"net/netip"
|
||||||
"os"
|
"os"
|
||||||
@@ -13,8 +12,8 @@ import (
|
|||||||
"github.com/sagernet/sing-box/adapter"
|
"github.com/sagernet/sing-box/adapter"
|
||||||
"github.com/sagernet/sing-box/option"
|
"github.com/sagernet/sing-box/option"
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
E "github.com/sagernet/sing/common/exceptions"
|
||||||
utls "github.com/sagernet/utls"
|
|
||||||
|
|
||||||
|
utls "github.com/refraction-networking/utls"
|
||||||
"golang.org/x/net/http2"
|
"golang.org/x/net/http2"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -46,19 +45,8 @@ func (e *UTLSClientConfig) Config() (*STDConfig, error) {
|
|||||||
return nil, E.New("unsupported usage for uTLS")
|
return nil, E.New("unsupported usage for uTLS")
|
||||||
}
|
}
|
||||||
|
|
||||||
func (e *UTLSClientConfig) Client(conn net.Conn) (Conn, error) {
|
func (e *UTLSClientConfig) Client(conn net.Conn) Conn {
|
||||||
return &utlsConnWrapper{utls.UClient(conn, e.config.Clone(), e.id)}, nil
|
return &utlsConnWrapper{utls.UClient(conn, e.config.Clone(), e.id)}
|
||||||
}
|
|
||||||
|
|
||||||
func (e *UTLSClientConfig) SetSessionIDGenerator(generator func(clientHello []byte, sessionID []byte) error) {
|
|
||||||
e.config.SessionIDGenerator = generator
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e *UTLSClientConfig) Clone() Config {
|
|
||||||
return &UTLSClientConfig{
|
|
||||||
config: e.config.Clone(),
|
|
||||||
id: e.id,
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
type utlsConnWrapper struct {
|
type utlsConnWrapper struct {
|
||||||
@@ -83,11 +71,14 @@ func (c *utlsConnWrapper) ConnectionState() tls.ConnectionState {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *utlsConnWrapper) Upstream() any {
|
func (e *UTLSClientConfig) Clone() Config {
|
||||||
return c.UConn
|
return &UTLSClientConfig{
|
||||||
|
config: e.config.Clone(),
|
||||||
|
id: e.id,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewUTLSClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (*UTLSClientConfig, error) {
|
func NewUTLSClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
||||||
var serverName string
|
var serverName string
|
||||||
if options.ServerName != "" {
|
if options.ServerName != "" {
|
||||||
serverName = options.ServerName
|
serverName = options.ServerName
|
||||||
@@ -101,7 +92,6 @@ func NewUTLSClient(router adapter.Router, serverAddress string, options option.O
|
|||||||
}
|
}
|
||||||
|
|
||||||
var tlsConfig utls.Config
|
var tlsConfig utls.Config
|
||||||
tlsConfig.Time = router.TimeFunc()
|
|
||||||
if options.DisableSNI {
|
if options.DisableSNI {
|
||||||
tlsConfig.ServerName = "127.0.0.1"
|
tlsConfig.ServerName = "127.0.0.1"
|
||||||
} else {
|
} else {
|
||||||
@@ -158,59 +148,28 @@ func NewUTLSClient(router adapter.Router, serverAddress string, options option.O
|
|||||||
}
|
}
|
||||||
tlsConfig.RootCAs = certPool
|
tlsConfig.RootCAs = certPool
|
||||||
}
|
}
|
||||||
id, err := uTLSClientHelloID(options.UTLS.Fingerprint)
|
var id utls.ClientHelloID
|
||||||
if err != nil {
|
switch options.UTLS.Fingerprint {
|
||||||
return nil, err
|
case "chrome", "":
|
||||||
|
id = utls.HelloChrome_Auto
|
||||||
|
case "firefox":
|
||||||
|
id = utls.HelloFirefox_Auto
|
||||||
|
case "edge":
|
||||||
|
id = utls.HelloEdge_Auto
|
||||||
|
case "safari":
|
||||||
|
id = utls.HelloSafari_Auto
|
||||||
|
case "360":
|
||||||
|
id = utls.Hello360_Auto
|
||||||
|
case "qq":
|
||||||
|
id = utls.HelloQQ_Auto
|
||||||
|
case "ios":
|
||||||
|
id = utls.HelloIOS_Auto
|
||||||
|
case "android":
|
||||||
|
id = utls.HelloAndroid_11_OkHttp
|
||||||
|
case "random":
|
||||||
|
id = utls.HelloRandomized
|
||||||
|
default:
|
||||||
|
return nil, E.New("unknown uTLS fingerprint: ", options.UTLS.Fingerprint)
|
||||||
}
|
}
|
||||||
return &UTLSClientConfig{&tlsConfig, id}, nil
|
return &UTLSClientConfig{&tlsConfig, id}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var (
|
|
||||||
randomFingerprint utls.ClientHelloID
|
|
||||||
randomizedFingerprint utls.ClientHelloID
|
|
||||||
)
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
modernFingerprints := []utls.ClientHelloID{
|
|
||||||
utls.HelloChrome_Auto,
|
|
||||||
utls.HelloFirefox_Auto,
|
|
||||||
utls.HelloEdge_Auto,
|
|
||||||
utls.HelloSafari_Auto,
|
|
||||||
utls.HelloIOS_Auto,
|
|
||||||
}
|
|
||||||
randomFingerprint = modernFingerprints[rand.Intn(len(modernFingerprints))]
|
|
||||||
|
|
||||||
weights := utls.DefaultWeights
|
|
||||||
weights.TLSVersMax_Set_VersionTLS13 = 1
|
|
||||||
weights.FirstKeyShare_Set_CurveP256 = 0
|
|
||||||
randomizedFingerprint = utls.HelloRandomized
|
|
||||||
randomizedFingerprint.Seed, _ = utls.NewPRNGSeed()
|
|
||||||
randomizedFingerprint.Weights = &weights
|
|
||||||
}
|
|
||||||
|
|
||||||
func uTLSClientHelloID(name string) (utls.ClientHelloID, error) {
|
|
||||||
switch name {
|
|
||||||
case "chrome", "":
|
|
||||||
return utls.HelloChrome_Auto, nil
|
|
||||||
case "firefox":
|
|
||||||
return utls.HelloFirefox_Auto, nil
|
|
||||||
case "edge":
|
|
||||||
return utls.HelloEdge_Auto, nil
|
|
||||||
case "safari":
|
|
||||||
return utls.HelloSafari_Auto, nil
|
|
||||||
case "360":
|
|
||||||
return utls.Hello360_Auto, nil
|
|
||||||
case "qq":
|
|
||||||
return utls.HelloQQ_Auto, nil
|
|
||||||
case "ios":
|
|
||||||
return utls.HelloIOS_Auto, nil
|
|
||||||
case "android":
|
|
||||||
return utls.HelloAndroid_11_OkHttp, nil
|
|
||||||
case "random":
|
|
||||||
return randomFingerprint, nil
|
|
||||||
case "randomized":
|
|
||||||
return randomizedFingerprint, nil
|
|
||||||
default:
|
|
||||||
return utls.ClientHelloID{}, E.New("unknown uTLS fingerprint: ", name)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -11,7 +11,3 @@ import (
|
|||||||
func NewUTLSClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
func NewUTLSClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
||||||
return nil, E.New(`uTLS is not included in this build, rebuild with -tags with_utls`)
|
return nil, E.New(`uTLS is not included in this build, rebuild with -tags with_utls`)
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewRealityClient(router adapter.Router, serverAddress string, options option.OutboundTLSOptions) (Config, error) {
|
|
||||||
return nil, E.New(`uTLS, which is required by reality client is not included in this build, rebuild with -tags with_utls`)
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -1,8 +0,0 @@
|
|||||||
package constant
|
|
||||||
|
|
||||||
import "time"
|
|
||||||
|
|
||||||
const (
|
|
||||||
DHCPTTL = time.Hour
|
|
||||||
DHCPTimeout = time.Minute
|
|
||||||
)
|
|
||||||
@@ -3,28 +3,13 @@ package constant
|
|||||||
import (
|
import (
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common/rw"
|
"github.com/sagernet/sing/common/rw"
|
||||||
)
|
)
|
||||||
|
|
||||||
const dirName = "sing-box"
|
const dirName = "sing-box"
|
||||||
|
|
||||||
var (
|
var resourcePaths []string
|
||||||
basePath string
|
|
||||||
resourcePaths []string
|
|
||||||
)
|
|
||||||
|
|
||||||
func BasePath(name string) string {
|
|
||||||
if basePath == "" || strings.HasPrefix(name, "/") {
|
|
||||||
return name
|
|
||||||
}
|
|
||||||
return filepath.Join(basePath, name)
|
|
||||||
}
|
|
||||||
|
|
||||||
func SetBasePath(path string) {
|
|
||||||
basePath = path
|
|
||||||
}
|
|
||||||
|
|
||||||
func FindPath(name string) (string, bool) {
|
func FindPath(name string) (string, bool) {
|
||||||
name = os.ExpandEnv(name)
|
name = os.ExpandEnv(name)
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
package constant
|
package constant
|
||||||
|
|
||||||
var Version = "1.2-beta5"
|
var Version = "1.1.6"
|
||||||
|
|||||||
@@ -1,37 +0,0 @@
|
|||||||
<svg width="1027" height="1109" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" xml:space="preserve" overflow="hidden">
|
|
||||||
<defs>
|
|
||||||
<filter id="fx0" x="-10%" y="-10%" width="120%" height="120%" filterUnits="userSpaceOnUse" primitiveUnits="userSpaceOnUse">
|
|
||||||
<feComponentTransfer color-interpolation-filters="sRGB">
|
|
||||||
<feFuncR type="discrete" tableValues="0 0" />
|
|
||||||
<feFuncG type="discrete" tableValues="0 0" />
|
|
||||||
<feFuncB type="discrete" tableValues="0 0" />
|
|
||||||
<feFuncA type="linear" slope="0.4" intercept="0" />
|
|
||||||
</feComponentTransfer>
|
|
||||||
<feGaussianBlur stdDeviation="4.58333 4.58333" />
|
|
||||||
</filter>
|
|
||||||
<clipPath id="clip1">
|
|
||||||
<rect x="692" y="855" width="1027" height="1109" />
|
|
||||||
</clipPath>
|
|
||||||
<clipPath id="clip2">
|
|
||||||
<rect x="-2" y="-2" width="541" height="786" />
|
|
||||||
</clipPath>
|
|
||||||
<clipPath id="clip3">
|
|
||||||
<rect x="0" y="0" width="535" height="782" />
|
|
||||||
</clipPath>
|
|
||||||
</defs>
|
|
||||||
<g clip-path="url(#clip1)" transform="translate(-692 -855)">
|
|
||||||
<path d="M692 1191 692 1575.69C692 1640.41 731.499 1651.19 731.499 1651.19L1148.03 1931.62C1212.66 1974.77 1194.71 1881.29 1194.71 1881.29L1194.71 1528.96 692 1191Z" fill="#37474F" fill-rule="evenodd" />
|
|
||||||
<g clip-path="url(#clip2)" filter="url(#fx0)" transform="translate(1184 1182)">
|
|
||||||
<g clip-path="url(#clip3)">
|
|
||||||
<path d="M520.482 15.4819 520.482 400.176C520.482 464.89 480.983 475.676 480.983 475.676 480.983 475.676 129.086 712.963 64.4523 756.106-0.181814 799.25 17.7721 705.773 17.7721 705.773L17.7721 353.437 520.482 15.4819Z" fill="#455A64" fill-rule="evenodd" />
|
|
||||||
</g>
|
|
||||||
</g>
|
|
||||||
<path d="M1698 1191 1698 1575.69C1698 1640.41 1658.5 1651.19 1658.5 1651.19 1658.5 1651.19 1306.6 1888.48 1241.97 1931.62 1177.34 1974.77 1195.29 1881.29 1195.29 1881.29L1195.29 1528.96 1698 1191Z" fill="#455A64" fill-rule="evenodd" />
|
|
||||||
<path d="M1241.71 868.473C1212.96 850.509 1169.85 850.509 1144.7 868.473L713.557 1163.07C684.814 1181.04 684.814 1213.37 713.557 1231.33L1144.7 1529.53C1173.44 1547.49 1216.56 1547.49 1241.71 1529.53L1676.44 1227.74C1705.19 1209.78 1705.19 1177.44 1676.44 1159.48L1241.71 868.473Z" fill="#546E7A" fill-rule="evenodd" />
|
|
||||||
<path d="M1195 1949C1173.4 1949 1159 1935.19 1159 1917.92L1159 1531.08C1159 1513.82 1173.4 1500 1195 1500 1216.6 1500 1231 1513.82 1231 1531.08L1231 1914.46C1231 1935.19 1216.6 1949 1195 1949Z" fill="#546E7A" fill-rule="evenodd" />
|
|
||||||
<path d="M1553.92 1435.92C1553.92 1471.89 1557.5 1486.27 1518.03 1511.45L1428.32 1568.99C1388.85 1594.17 1374.5 1572.59 1374.5 1540.22L1374.5 1446.71C1374.5 1439.52 1374.5 1435.92 1363.73 1428.73 1270.43 1363.99 911.591 1115.84 847 1069.09L1012.07 954C1058.72 982.772 1399.61 1209.35 1539.56 1306.45 1546.74 1310.05 1550.33 1317.24 1550.33 1320.84L1550.33 1435.92Z" fill="#99AAB5" fill-rule="evenodd" />
|
|
||||||
<path d="M1543.41 1310.21C1399.82 1213.17 1058.79 986.752 1015.72 958L951.103 997.534 847 1069.41C911.615 1116.14 1270.59 1360.53 1363.92 1425.22 1371.1 1428.81 1371.1 1432.41 1371.1 1436L1547 1313.8C1547 1313.8 1547 1310.21 1543.41 1310.21Z" fill="#CCD6DD" fill-rule="evenodd" />
|
|
||||||
<path d="M1554.9 1435.48 1554.9 1324.19C1554.9 1317.01 1551.3 1313.42 1544.11 1309.83 1400.28 1212.89 1058.67 986.721 1015.51 958L940 1008.26C1062.26 1090.83 1389.49 1306.24 1475.79 1367.27 1486.58 1374.45 1486.58 1381.63 1486.58 1385.22L1486.58 1536 1522.54 1510.87C1558.5 1485.74 1554.9 1467.79 1554.9 1435.48Z" fill="#CCD6DD" fill-rule="evenodd" />
|
|
||||||
<path d="M1543.23 1309.95C1399.6 1212.98 1058.49 986.731 1015.4 958L940 1008.28C1062.08 1090.88 1388.83 1306.36 1475.01 1367.41 1475.01 1367.41 1478.6 1371 1478.6 1371L1554 1317.13C1546.82 1313.54 1546.82 1309.95 1543.23 1309.95Z" fill="#E1E8ED" fill-rule="evenodd" />
|
|
||||||
</g>
|
|
||||||
</svg>
|
|
||||||
|
Before Width: | Height: | Size: 3.7 KiB |
@@ -1,21 +1,8 @@
|
|||||||
#### 1.2-beta6
|
#### 1.1.7
|
||||||
|
|
||||||
* Introducing our [new iOS client application](/installation/clients/sfi)
|
* Improve the stability of the VMESS server
|
||||||
* Add [platform options](/configuration/inbound/tun#platform) for tun inbound
|
* Fix `auto_detect_interface` incorrectly identifying the default interface on Windows
|
||||||
* Add custom TLS server support for http based v2ray transports
|
* Fix bugs and update dependencies
|
||||||
* Add generate commands
|
|
||||||
* Enable XUDP by default in VLESS
|
|
||||||
* Update reality server
|
|
||||||
* Update vision protocol
|
|
||||||
* Fixed [user flow in vless server](/configuration/inbound/vless#usersflow)
|
|
||||||
* Bug fixes
|
|
||||||
* Update dependencies
|
|
||||||
|
|
||||||
#### 1.2-beta5
|
|
||||||
|
|
||||||
* Add [VLESS server](/configuration/inbound/vless) and [vision](/configuration/outbound/vless#flow) support
|
|
||||||
* Add [reality TLS](/configuration/shared/tls) support
|
|
||||||
* Fix match private address
|
|
||||||
|
|
||||||
#### 1.1.6
|
#### 1.1.6
|
||||||
|
|
||||||
@@ -27,37 +14,6 @@
|
|||||||
* Disable vmess header protection if transport enabled
|
* Disable vmess header protection if transport enabled
|
||||||
* Update QUIC v2 version number and initial salt
|
* Update QUIC v2 version number and initial salt
|
||||||
|
|
||||||
#### 1.2-beta4
|
|
||||||
|
|
||||||
* Add [NTP service](/configuration/ntp)
|
|
||||||
* Add Add multiple server names and multi-user support for shadowtls
|
|
||||||
* Add strict mode support for shadowtls v3
|
|
||||||
* Add uTLS support for shadowtls v3
|
|
||||||
|
|
||||||
#### 1.2-beta3
|
|
||||||
|
|
||||||
* Update QUIC v2 version number and initial salt
|
|
||||||
* Fix shadowtls v3 implementation
|
|
||||||
|
|
||||||
#### 1.2-beta2
|
|
||||||
|
|
||||||
* Add [ShadowTLS protocol v3](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-v3-en.md)
|
|
||||||
* Add fallback support for v2ray transport
|
|
||||||
* Fix parse hysteria UDP message
|
|
||||||
* Fix socks connect response
|
|
||||||
* Disable vmess header protection if transport enabled
|
|
||||||
|
|
||||||
#### 1.2-beta1
|
|
||||||
|
|
||||||
* Add [DHCP DNS server](/configuration/dns/server) support
|
|
||||||
* Add SSH [host key validation](/configuration/outbound/ssh) support
|
|
||||||
* Add [query_type](/configuration/dns/rule) DNS rule item
|
|
||||||
* Add v2ray [user stats](/configuration/experimental#statsusers) api
|
|
||||||
* Add new clash DNS query api
|
|
||||||
* Improve vmess request
|
|
||||||
* Fix ipv6 redirect on Linux
|
|
||||||
* Fix match geoip private
|
|
||||||
|
|
||||||
#### 1.1.5
|
#### 1.1.5
|
||||||
|
|
||||||
* Add Go 1.20 support
|
* Add Go 1.20 support
|
||||||
|
|||||||
@@ -9,11 +9,6 @@
|
|||||||
"mixed-in"
|
"mixed-in"
|
||||||
],
|
],
|
||||||
"ip_version": 6,
|
"ip_version": 6,
|
||||||
"query_type": [
|
|
||||||
"A",
|
|
||||||
"HTTPS",
|
|
||||||
32768
|
|
||||||
],
|
|
||||||
"network": "tcp",
|
"network": "tcp",
|
||||||
"auth_user": [
|
"auth_user": [
|
||||||
"usera",
|
"usera",
|
||||||
@@ -124,10 +119,6 @@ Tags of [Inbound](/configuration/inbound).
|
|||||||
|
|
||||||
Not limited if empty.
|
Not limited if empty.
|
||||||
|
|
||||||
#### query_type
|
|
||||||
|
|
||||||
DNS query type. Values can be integers or type name strings.
|
|
||||||
|
|
||||||
#### network
|
#### network
|
||||||
|
|
||||||
`tcp` or `udp`.
|
`tcp` or `udp`.
|
||||||
|
|||||||
@@ -9,11 +9,6 @@
|
|||||||
"mixed-in"
|
"mixed-in"
|
||||||
],
|
],
|
||||||
"ip_version": 6,
|
"ip_version": 6,
|
||||||
"query_type": [
|
|
||||||
"A",
|
|
||||||
"HTTPS",
|
|
||||||
32768
|
|
||||||
],
|
|
||||||
"network": "tcp",
|
"network": "tcp",
|
||||||
"auth_user": [
|
"auth_user": [
|
||||||
"usera",
|
"usera",
|
||||||
@@ -123,10 +118,6 @@
|
|||||||
|
|
||||||
默认不限制。
|
默认不限制。
|
||||||
|
|
||||||
#### query_type
|
|
||||||
|
|
||||||
DNS 查询类型。值可以为整数或者类型名称字符串。
|
|
||||||
|
|
||||||
#### network
|
#### network
|
||||||
|
|
||||||
`tcp` 或 `udp`。
|
`tcp` 或 `udp`。
|
||||||
|
|||||||
@@ -30,17 +30,16 @@ The tag of the dns server.
|
|||||||
|
|
||||||
The address of the dns server.
|
The address of the dns server.
|
||||||
|
|
||||||
| Protocol | Format |
|
| Protocol | Format |
|
||||||
|----------|-------------------------------|
|
|----------|-----------------------------|
|
||||||
| `System` | `local` |
|
| `System` | `local` |
|
||||||
| `TCP` | `tcp://1.0.0.1` |
|
| `TCP` | `tcp://1.0.0.1` |
|
||||||
| `UDP` | `8.8.8.8` `udp://8.8.4.4` |
|
| `UDP` | `8.8.8.8` `udp://8.8.4.4` |
|
||||||
| `TLS` | `tls://dns.google` |
|
| `TLS` | `tls://dns.google` |
|
||||||
| `HTTPS` | `https://1.1.1.1/dns-query` |
|
| `HTTPS` | `https://1.1.1.1/dns-query` |
|
||||||
| `QUIC` | `quic://dns.adguard.com` |
|
| `QUIC` | `quic://dns.adguard.com` |
|
||||||
| `HTTP3` | `h3://8.8.8.8/dns-query` |
|
| `HTTP3` | `h3://8.8.8.8/dns-query` |
|
||||||
| `RCode` | `rcode://refused` |
|
| `RCode` | `rcode://refused` |
|
||||||
| `DHCP` | `dhcp://auto` or `dhcp://en0` |
|
|
||||||
|
|
||||||
!!! warning ""
|
!!! warning ""
|
||||||
|
|
||||||
@@ -54,10 +53,6 @@ The address of the dns server.
|
|||||||
|
|
||||||
the RCode transport is often used to block queries. Use with rules and the `disable_cache` rule option.
|
the RCode transport is often used to block queries. Use with rules and the `disable_cache` rule option.
|
||||||
|
|
||||||
!!! warning ""
|
|
||||||
|
|
||||||
DHCP transport is not included by default, see [Installation](/#installation).
|
|
||||||
|
|
||||||
| RCode | Description |
|
| RCode | Description |
|
||||||
|-------------------|-----------------------|
|
|-------------------|-----------------------|
|
||||||
| `success` | `No error` |
|
| `success` | `No error` |
|
||||||
|
|||||||
@@ -30,17 +30,16 @@ DNS 服务器的标签。
|
|||||||
|
|
||||||
DNS 服务器的地址。
|
DNS 服务器的地址。
|
||||||
|
|
||||||
| 协议 | 格式 |
|
| 协议 | 格式 |
|
||||||
|----------|------------------------------|
|
|----------|-----------------------------|
|
||||||
| `System` | `local` |
|
| `System` | `local` |
|
||||||
| `TCP` | `tcp://1.0.0.1` |
|
| `TCP` | `tcp://1.0.0.1` |
|
||||||
| `UDP` | `8.8.8.8` `udp://8.8.4.4` |
|
| `UDP` | `8.8.8.8` `udp://8.8.4.4` |
|
||||||
| `TLS` | `tls://dns.google` |
|
| `TLS` | `tls://dns.google` |
|
||||||
| `HTTPS` | `https://1.1.1.1/dns-query` |
|
| `HTTPS` | `https://1.1.1.1/dns-query` |
|
||||||
| `QUIC` | `quic://dns.adguard.com` |
|
| `QUIC` | `quic://dns.adguard.com` |
|
||||||
| `HTTP3` | `h3://8.8.8.8/dns-query` |
|
| `HTTP3` | `h3://8.8.8.8/dns-query` |
|
||||||
| `RCode` | `rcode://refused` |
|
| `RCode` | `rcode://refused` |
|
||||||
| `DHCP` | `dhcp://auto` 或 `dhcp://en0` |
|
|
||||||
|
|
||||||
!!! warning ""
|
!!! warning ""
|
||||||
|
|
||||||
@@ -54,10 +53,6 @@ DNS 服务器的地址。
|
|||||||
|
|
||||||
RCode 传输层传输层常用于屏蔽请求. 与 DNS 规则和 `disable_cache` 规则选项一起使用。
|
RCode 传输层传输层常用于屏蔽请求. 与 DNS 规则和 `disable_cache` 规则选项一起使用。
|
||||||
|
|
||||||
!!! warning ""
|
|
||||||
|
|
||||||
默认安装不包含 DHCP 传输层,请参阅 [安装](/zh/#_2)。
|
|
||||||
|
|
||||||
| RCode | 描述 |
|
| RCode | 描述 |
|
||||||
|-------------------|----------|
|
|-------------------|----------|
|
||||||
| `success` | `无错误` |
|
| `success` | `无错误` |
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
"external_controller": "127.0.0.1:9090",
|
"external_controller": "127.0.0.1:9090",
|
||||||
"external_ui": "folder",
|
"external_ui": "folder",
|
||||||
"secret": "",
|
"secret": "",
|
||||||
|
"direct_io": false,
|
||||||
"default_mode": "rule",
|
"default_mode": "rule",
|
||||||
"store_selected": false,
|
"store_selected": false,
|
||||||
"cache_file": "cache.db"
|
"cache_file": "cache.db"
|
||||||
@@ -17,15 +18,13 @@
|
|||||||
"listen": "127.0.0.1:8080",
|
"listen": "127.0.0.1:8080",
|
||||||
"stats": {
|
"stats": {
|
||||||
"enabled": true,
|
"enabled": true,
|
||||||
|
"direct_io": false,
|
||||||
"inbounds": [
|
"inbounds": [
|
||||||
"socks-in"
|
"socks-in"
|
||||||
],
|
],
|
||||||
"outbounds": [
|
"outbounds": [
|
||||||
"proxy",
|
"proxy",
|
||||||
"direct"
|
"direct"
|
||||||
],
|
|
||||||
"users": [
|
|
||||||
"sekai"
|
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -59,6 +58,10 @@ Secret for the RESTful API (optional)
|
|||||||
Authenticate by spedifying HTTP header `Authorization: Bearer ${secret}`
|
Authenticate by spedifying HTTP header `Authorization: Bearer ${secret}`
|
||||||
ALWAYS set a secret if RESTful API is listening on 0.0.0.0
|
ALWAYS set a secret if RESTful API is listening on 0.0.0.0
|
||||||
|
|
||||||
|
#### direct_io
|
||||||
|
|
||||||
|
Allows lossless relays like splice without real-time traffic reporting.
|
||||||
|
|
||||||
#### default_mode
|
#### default_mode
|
||||||
|
|
||||||
Default mode in clash, `rule` will be used if empty.
|
Default mode in clash, `rule` will be used if empty.
|
||||||
@@ -95,6 +98,10 @@ Traffic statistics service settings.
|
|||||||
|
|
||||||
Enable statistics service.
|
Enable statistics service.
|
||||||
|
|
||||||
|
#### stats.direct_io
|
||||||
|
|
||||||
|
Allows lossless relays like splice without real-time traffic reporting.
|
||||||
|
|
||||||
#### stats.inbounds
|
#### stats.inbounds
|
||||||
|
|
||||||
Inbound list to count traffic.
|
Inbound list to count traffic.
|
||||||
@@ -102,7 +109,3 @@ Inbound list to count traffic.
|
|||||||
#### stats.outbounds
|
#### stats.outbounds
|
||||||
|
|
||||||
Outbound list to count traffic.
|
Outbound list to count traffic.
|
||||||
|
|
||||||
#### stats.users
|
|
||||||
|
|
||||||
User list to count traffic.
|
|
||||||
@@ -9,6 +9,7 @@
|
|||||||
"external_controller": "127.0.0.1:9090",
|
"external_controller": "127.0.0.1:9090",
|
||||||
"external_ui": "folder",
|
"external_ui": "folder",
|
||||||
"secret": "",
|
"secret": "",
|
||||||
|
"direct_io": false,
|
||||||
"default_mode": "rule",
|
"default_mode": "rule",
|
||||||
"store_selected": false,
|
"store_selected": false,
|
||||||
"cache_file": "cache.db"
|
"cache_file": "cache.db"
|
||||||
@@ -17,15 +18,13 @@
|
|||||||
"listen": "127.0.0.1:8080",
|
"listen": "127.0.0.1:8080",
|
||||||
"stats": {
|
"stats": {
|
||||||
"enabled": true,
|
"enabled": true,
|
||||||
|
"direct_io": false,
|
||||||
"inbounds": [
|
"inbounds": [
|
||||||
"socks-in"
|
"socks-in"
|
||||||
],
|
],
|
||||||
"outbounds": [
|
"outbounds": [
|
||||||
"proxy",
|
"proxy",
|
||||||
"direct"
|
"direct"
|
||||||
],
|
|
||||||
"users": [
|
|
||||||
"sekai"
|
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -57,6 +56,10 @@ RESTful API 的密钥(可选)
|
|||||||
通过指定 HTTP 标头 `Authorization: Bearer ${secret}` 进行身份验证
|
通过指定 HTTP 标头 `Authorization: Bearer ${secret}` 进行身份验证
|
||||||
如果 RESTful API 正在监听 0.0.0.0,请始终设置一个密钥。
|
如果 RESTful API 正在监听 0.0.0.0,请始终设置一个密钥。
|
||||||
|
|
||||||
|
#### direct_io
|
||||||
|
|
||||||
|
允许像 splice 这样的没有实时流量报告的无损中继。
|
||||||
|
|
||||||
#### default_mode
|
#### default_mode
|
||||||
|
|
||||||
Clash 中的默认模式,默认使用 `rule`。
|
Clash 中的默认模式,默认使用 `rule`。
|
||||||
@@ -93,6 +96,10 @@ gRPC API 监听地址。如果为空,则禁用 V2Ray API。
|
|||||||
|
|
||||||
启用统计服务。
|
启用统计服务。
|
||||||
|
|
||||||
|
#### stats.direct_io
|
||||||
|
|
||||||
|
允许像 splice 这样的没有实时流量报告的无损中继。
|
||||||
|
|
||||||
#### stats.inbounds
|
#### stats.inbounds
|
||||||
|
|
||||||
统计流量的入站列表。
|
统计流量的入站列表。
|
||||||
@@ -100,7 +107,3 @@ gRPC API 监听地址。如果为空,则禁用 V2Ray API。
|
|||||||
#### stats.outbounds
|
#### stats.outbounds
|
||||||
|
|
||||||
统计流量的出站列表。
|
统计流量的出站列表。
|
||||||
|
|
||||||
#### stats.users
|
|
||||||
|
|
||||||
统计流量的用户列表。
|
|
||||||
@@ -26,8 +26,6 @@
|
|||||||
| `trojan` | [Trojan](./trojan) | TCP |
|
| `trojan` | [Trojan](./trojan) | TCP |
|
||||||
| `naive` | [Naive](./naive) | X |
|
| `naive` | [Naive](./naive) | X |
|
||||||
| `hysteria` | [Hysteria](./hysteria) | X |
|
| `hysteria` | [Hysteria](./hysteria) | X |
|
||||||
| `shadowtls` | [ShadowTLS](./shadowtls) | TCP |
|
|
||||||
| `vless` | [VLESS](./vless) | TCP |
|
|
||||||
| `tun` | [Tun](./tun) | X |
|
| `tun` | [Tun](./tun) | X |
|
||||||
| `redirect` | [Redirect](./redirect) | X |
|
| `redirect` | [Redirect](./redirect) | X |
|
||||||
| `tproxy` | [TProxy](./tproxy) | X |
|
| `tproxy` | [TProxy](./tproxy) | X |
|
||||||
|
|||||||
@@ -77,11 +77,11 @@ Both if empty.
|
|||||||
|
|
||||||
==Required==
|
==Required==
|
||||||
|
|
||||||
| Method | Password Format |
|
| Method | Password Format |
|
||||||
|---------------|------------------------------------------------|
|
|---------------|-------------------------------------|
|
||||||
| none | / |
|
| none | / |
|
||||||
| 2022 methods | `sing-box generate rand --base64 <Key Length>` |
|
| 2022 methods | `openssl rand -base64 <Key Length>` |
|
||||||
| other methods | any string |
|
| other methods | any string |
|
||||||
|
|
||||||
### Listen Fields
|
### Listen Fields
|
||||||
|
|
||||||
|
|||||||
@@ -77,8 +77,8 @@ See [Listen Fields](/configuration/shared/listen) for details.
|
|||||||
|
|
||||||
==必填==
|
==必填==
|
||||||
|
|
||||||
| 方法 | 密码格式 |
|
| 方法 | 密码格式 |
|
||||||
|---------------|------------------------------------------|
|
|---------------|-------------------------------|
|
||||||
| none | / |
|
| none | / |
|
||||||
| 2022 methods | `sing-box generate rand --base64 <密钥长度>` |
|
| 2022 methods | `openssl rand -base64 <密钥长度>` |
|
||||||
| other methods | 任意字符串 |
|
| other methods | 任意字符串 |
|
||||||
@@ -7,29 +7,14 @@
|
|||||||
|
|
||||||
... // Listen Fields
|
... // Listen Fields
|
||||||
|
|
||||||
"version": 3,
|
"version": 2,
|
||||||
"password": "fuck me till the daylight",
|
"password": "fuck me till the daylight",
|
||||||
"users": [
|
|
||||||
{
|
|
||||||
"name": "sekai",
|
|
||||||
"password": "8JCsPssfgS8tiRwiMlhARg=="
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"handshake": {
|
"handshake": {
|
||||||
"server": "google.com",
|
"server": "google.com",
|
||||||
"server_port": 443,
|
"server_port": 443,
|
||||||
|
|
||||||
... // Dial Fields
|
... // Dial Fields
|
||||||
},
|
}
|
||||||
"handshake_for_server_name": {
|
|
||||||
"example.com": {
|
|
||||||
"server": "example.com",
|
|
||||||
"server_port": 443,
|
|
||||||
|
|
||||||
... // Dial Fields
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"strict_mode": false
|
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -47,35 +32,15 @@ ShadowTLS protocol version.
|
|||||||
|---------------|-----------------------------------------------------------------------------------------|
|
|---------------|-----------------------------------------------------------------------------------------|
|
||||||
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
||||||
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
||||||
| `3` | [ShadowTLS v3](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-v3-en.md) |
|
|
||||||
|
|
||||||
#### password
|
#### password
|
||||||
|
|
||||||
ShadowTLS password.
|
Set password.
|
||||||
|
|
||||||
Only available in the ShadowTLS protocol 2.
|
Only available in the ShadowTLS v2 protocol.
|
||||||
|
|
||||||
|
|
||||||
#### users
|
|
||||||
|
|
||||||
ShadowTLS users.
|
|
||||||
|
|
||||||
Only available in the ShadowTLS protocol 3.
|
|
||||||
|
|
||||||
#### handshake
|
#### handshake
|
||||||
|
|
||||||
==Required==
|
==Required==
|
||||||
|
|
||||||
Handshake server address and [Dial options](/configuration/shared/dial).
|
Handshake server address and [Dial options](/configuration/shared/dial).
|
||||||
|
|
||||||
#### handshake
|
|
||||||
|
|
||||||
Handshake server address and [Dial options](/configuration/shared/dial) for specific server name.
|
|
||||||
|
|
||||||
Only available in the ShadowTLS protocol 2/3.
|
|
||||||
|
|
||||||
#### strict_mode
|
|
||||||
|
|
||||||
ShadowTLS strict mode.
|
|
||||||
|
|
||||||
Only available in the ShadowTLS protocol 3.
|
|
||||||
@@ -7,29 +7,14 @@
|
|||||||
|
|
||||||
... // 监听字段
|
... // 监听字段
|
||||||
|
|
||||||
"version": 3,
|
"version": 2,
|
||||||
"password": "fuck me till the daylight",
|
"password": "fuck me till the daylight",
|
||||||
"users": [
|
|
||||||
{
|
|
||||||
"name": "sekai",
|
|
||||||
"password": "8JCsPssfgS8tiRwiMlhARg=="
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"handshake": {
|
"handshake": {
|
||||||
"server": "google.com",
|
"server": "google.com",
|
||||||
"server_port": 443,
|
"server_port": 443,
|
||||||
|
|
||||||
... // 拨号字段
|
... // 拨号字段
|
||||||
},
|
}
|
||||||
"handshake_for_server_name": {
|
|
||||||
"example.com": {
|
|
||||||
"server": "example.com",
|
|
||||||
"server_port": 443,
|
|
||||||
|
|
||||||
... // 拨号字段
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"strict_mode": false
|
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -47,36 +32,15 @@ ShadowTLS 协议版本。
|
|||||||
|---------------|-----------------------------------------------------------------------------------------|
|
|---------------|-----------------------------------------------------------------------------------------|
|
||||||
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
||||||
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
||||||
| `3` | [ShadowTLS v3](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-v3-en.md) |
|
|
||||||
|
|
||||||
#### password
|
#### password
|
||||||
|
|
||||||
ShadowTLS 密码。
|
设置密码。
|
||||||
|
|
||||||
仅在 ShadowTLS 协议版本 2 中可用。
|
仅在 ShadowTLS v2 协议中可用。
|
||||||
|
|
||||||
#### users
|
|
||||||
|
|
||||||
ShadowTLS 用户。
|
|
||||||
|
|
||||||
仅在 ShadowTLS 协议版本 3 中可用。
|
|
||||||
|
|
||||||
#### handshake
|
#### handshake
|
||||||
|
|
||||||
==必填==
|
==必填==
|
||||||
|
|
||||||
握手服务器地址和 [拨号参数](/zh/configuration/shared/dial/)。
|
握手服务器地址和 [拨号参数](/zh/configuration/shared/dial/)。
|
||||||
|
|
||||||
#### handshake
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
对于特定服务器名称的握手服务器地址和 [拨号参数](/zh/configuration/shared/dial/)。
|
|
||||||
|
|
||||||
仅在 ShadowTLS 协议版本 2/3 中可用。
|
|
||||||
|
|
||||||
#### strict_mode
|
|
||||||
|
|
||||||
ShadowTLS 严格模式。
|
|
||||||
|
|
||||||
仅在 ShadowTLS 协议版本 3 中可用。
|
|
||||||
|
|||||||
@@ -46,15 +46,8 @@
|
|||||||
"exclude_package": [
|
"exclude_package": [
|
||||||
"com.android.captiveportallogin"
|
"com.android.captiveportallogin"
|
||||||
],
|
],
|
||||||
"platform": {
|
...
|
||||||
"http_proxy": {
|
// Listen Fields
|
||||||
"enabled": false,
|
|
||||||
"server": "127.0.0.1",
|
|
||||||
"server_port": 8080
|
|
||||||
}
|
|
||||||
},
|
|
||||||
|
|
||||||
... // Listen Fields
|
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -194,14 +187,6 @@ Limit android packages in route.
|
|||||||
|
|
||||||
Exclude android packages in route.
|
Exclude android packages in route.
|
||||||
|
|
||||||
#### platform
|
|
||||||
|
|
||||||
Platform-specific settings, provided by client applications.
|
|
||||||
|
|
||||||
#### platform.http_proxy
|
|
||||||
|
|
||||||
System HTTP proxy settings.
|
|
||||||
|
|
||||||
### Listen Fields
|
### Listen Fields
|
||||||
|
|
||||||
See [Listen Fields](/configuration/shared/listen) for details.
|
See [Listen Fields](/configuration/shared/listen) for details.
|
||||||
|
|||||||
@@ -46,15 +46,8 @@
|
|||||||
"exclude_package": [
|
"exclude_package": [
|
||||||
"com.android.captiveportallogin"
|
"com.android.captiveportallogin"
|
||||||
],
|
],
|
||||||
"platform": {
|
...
|
||||||
"http_proxy": {
|
// 监听字段
|
||||||
"enabled": false,
|
|
||||||
"server": "127.0.0.1",
|
|
||||||
"server_port": 8080
|
|
||||||
}
|
|
||||||
},
|
|
||||||
|
|
||||||
... // 监听字段
|
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -155,19 +148,19 @@ TCP/IP 栈。
|
|||||||
|
|
||||||
UID 规则仅在 Linux 下被支持,并且需要 `auto_route`。
|
UID 规则仅在 Linux 下被支持,并且需要 `auto_route`。
|
||||||
|
|
||||||
限制被路由的用户。默认不限制。
|
限制被路由的的用户。默认不限制。
|
||||||
|
|
||||||
#### include_uid_range
|
#### include_uid_range
|
||||||
|
|
||||||
限制被路由的用户范围。
|
限制被路由的的用户范围。
|
||||||
|
|
||||||
#### exclude_uid
|
#### exclude_uid
|
||||||
|
|
||||||
排除路由的用户。
|
排除路由的的用户。
|
||||||
|
|
||||||
#### exclude_uid_range
|
#### exclude_uid_range
|
||||||
|
|
||||||
排除路由的用户范围。
|
排除路由的的用户范围。
|
||||||
|
|
||||||
#### include_android_user
|
#### include_android_user
|
||||||
|
|
||||||
@@ -190,14 +183,6 @@ TCP/IP 栈。
|
|||||||
|
|
||||||
排除路由的 Android 应用包名。
|
排除路由的 Android 应用包名。
|
||||||
|
|
||||||
#### platform
|
|
||||||
|
|
||||||
平台特定的设置,由客户端应用提供。
|
|
||||||
|
|
||||||
#### platform.http_proxy
|
|
||||||
|
|
||||||
系统 HTTP 代理设置。
|
|
||||||
|
|
||||||
### 监听字段
|
### 监听字段
|
||||||
|
|
||||||
参阅 [监听字段](/zh/configuration/shared/listen/)。
|
参阅 [监听字段](/zh/configuration/shared/listen/)。
|
||||||
|
|||||||
@@ -1,54 +0,0 @@
|
|||||||
### Structure
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"type": "vless",
|
|
||||||
"tag": "vless-in",
|
|
||||||
|
|
||||||
... // Listen Fields
|
|
||||||
|
|
||||||
"users": [
|
|
||||||
{
|
|
||||||
"name": "sekai",
|
|
||||||
"uuid": "bf000d23-0752-40b4-affe-68f7707a9661",
|
|
||||||
"flow": ""
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"tls": {},
|
|
||||||
"transport": {}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Listen Fields
|
|
||||||
|
|
||||||
See [Listen Fields](/configuration/shared/listen) for details.
|
|
||||||
|
|
||||||
### Fields
|
|
||||||
|
|
||||||
#### users
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
VLESS users.
|
|
||||||
|
|
||||||
#### users.uuid
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
VLESS user id.
|
|
||||||
|
|
||||||
#### users.flow
|
|
||||||
|
|
||||||
VLESS Sub-protocol.
|
|
||||||
|
|
||||||
Available values:
|
|
||||||
|
|
||||||
* `xtls-rprx-vision`
|
|
||||||
|
|
||||||
#### tls
|
|
||||||
|
|
||||||
TLS configuration, see [TLS](/configuration/shared/tls/#inbound).
|
|
||||||
|
|
||||||
#### transport
|
|
||||||
|
|
||||||
V2Ray Transport configuration, see [V2Ray Transport](/configuration/shared/v2ray-transport).
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
### 结构
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"type": "vless",
|
|
||||||
"tag": "vless-in",
|
|
||||||
|
|
||||||
... // 监听字段
|
|
||||||
|
|
||||||
"users": [
|
|
||||||
{
|
|
||||||
"name": "sekai",
|
|
||||||
"uuid": "bf000d23-0752-40b4-affe-68f7707a9661",
|
|
||||||
"flow": ""
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"tls": {},
|
|
||||||
"transport": {}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### 监听字段
|
|
||||||
|
|
||||||
参阅 [监听字段](/zh/configuration/shared/listen/)。
|
|
||||||
|
|
||||||
### 字段
|
|
||||||
|
|
||||||
#### users
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
VLESS 用户。
|
|
||||||
|
|
||||||
#### users.uuid
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
VLESS 用户 ID。
|
|
||||||
|
|
||||||
#### users.flow
|
|
||||||
|
|
||||||
VLESS 子协议。
|
|
||||||
|
|
||||||
可用值:
|
|
||||||
|
|
||||||
* `xtls-rprx-vision`
|
|
||||||
|
|
||||||
#### tls
|
|
||||||
|
|
||||||
TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#inbound)。
|
|
||||||
|
|
||||||
#### transport
|
|
||||||
|
|
||||||
V2Ray 传输配置,参阅 [V2Ray 传输层](/zh/configuration/shared/v2ray-transport)。
|
|
||||||
@@ -8,7 +8,6 @@ sing-box uses JSON for configuration files.
|
|||||||
{
|
{
|
||||||
"log": {},
|
"log": {},
|
||||||
"dns": {},
|
"dns": {},
|
||||||
"ntp": {},
|
|
||||||
"inbounds": [],
|
"inbounds": [],
|
||||||
"outbounds": [],
|
"outbounds": [],
|
||||||
"route": {},
|
"route": {},
|
||||||
@@ -22,7 +21,6 @@ sing-box uses JSON for configuration files.
|
|||||||
|----------------|--------------------------------|
|
|----------------|--------------------------------|
|
||||||
| `log` | [Log](./log) |
|
| `log` | [Log](./log) |
|
||||||
| `dns` | [DNS](./dns) |
|
| `dns` | [DNS](./dns) |
|
||||||
| `ntp` | [NTP](./ntp) |
|
|
||||||
| `inbounds` | [Inbound](./inbound) |
|
| `inbounds` | [Inbound](./inbound) |
|
||||||
| `outbounds` | [Outbound](./outbound) |
|
| `outbounds` | [Outbound](./outbound) |
|
||||||
| `route` | [Route](./route) |
|
| `route` | [Route](./route) |
|
||||||
|
|||||||
@@ -1,50 +0,0 @@
|
|||||||
# NTP
|
|
||||||
|
|
||||||
Built-in NTP client service.
|
|
||||||
|
|
||||||
If enabled, it will provide time for protocols like TLS/Shadowsocks/VMess, which is useful for environments where time
|
|
||||||
synchronization is not possible.
|
|
||||||
|
|
||||||
### Structure
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"ntp": {
|
|
||||||
"enabled": false,
|
|
||||||
"server": "time.apple.com",
|
|
||||||
"server_port": 123,
|
|
||||||
"interval": "30m",
|
|
||||||
|
|
||||||
... // Dial Fields
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
```
|
|
||||||
|
|
||||||
### Fields
|
|
||||||
|
|
||||||
#### enabled
|
|
||||||
|
|
||||||
Enable NTP service.
|
|
||||||
|
|
||||||
#### server
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
NTP server address.
|
|
||||||
|
|
||||||
#### server_port
|
|
||||||
|
|
||||||
NTP server port.
|
|
||||||
|
|
||||||
123 is used by default.
|
|
||||||
|
|
||||||
#### interval
|
|
||||||
|
|
||||||
Time synchronization interval.
|
|
||||||
|
|
||||||
30 minutes is used by default.
|
|
||||||
|
|
||||||
### Dial Fields
|
|
||||||
|
|
||||||
See [Dial Fields](/configuration/shared/dial) for details.
|
|
||||||
@@ -1,49 +0,0 @@
|
|||||||
# NTP
|
|
||||||
|
|
||||||
内建的 NTP 客户端服务。
|
|
||||||
|
|
||||||
如果启用,它将为像 TLS/Shadowsocks/VMess 这样的协议提供时间,这对于无法进行时间同步的环境很有用。
|
|
||||||
|
|
||||||
### 结构
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"ntp": {
|
|
||||||
"enabled": false,
|
|
||||||
"server": "time.apple.com",
|
|
||||||
"server_port": 123,
|
|
||||||
"interval": "30m",
|
|
||||||
|
|
||||||
... // 拨号字段
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
```
|
|
||||||
|
|
||||||
### 字段
|
|
||||||
|
|
||||||
#### enabled
|
|
||||||
|
|
||||||
启用 NTP 服务。
|
|
||||||
|
|
||||||
#### server
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
NTP 服务器地址。
|
|
||||||
|
|
||||||
#### server_port
|
|
||||||
|
|
||||||
NTP 服务器端口。
|
|
||||||
|
|
||||||
默认使用 123。
|
|
||||||
|
|
||||||
#### interval
|
|
||||||
|
|
||||||
时间同步间隔。
|
|
||||||
|
|
||||||
默认使用 30 分钟。
|
|
||||||
|
|
||||||
### 拨号字段
|
|
||||||
|
|
||||||
参阅 [拨号字段](/zh/configuration/shared/dial/)。
|
|
||||||
@@ -28,7 +28,6 @@
|
|||||||
| `hysteria` | [Hysteria](./hysteria) |
|
| `hysteria` | [Hysteria](./hysteria) |
|
||||||
| `shadowsocksr` | [ShadowsocksR](./shadowsocksr) |
|
| `shadowsocksr` | [ShadowsocksR](./shadowsocksr) |
|
||||||
| `vless` | [VLESS](./vless) |
|
| `vless` | [VLESS](./vless) |
|
||||||
| `shadowtls` | [ShadowTLS](./shadowtls) |
|
|
||||||
| `tor` | [Tor](./tor) |
|
| `tor` | [Tor](./tor) |
|
||||||
| `ssh` | [SSH](./ssh) |
|
| `ssh` | [SSH](./ssh) |
|
||||||
| `dns` | [DNS](./dns) |
|
| `dns` | [DNS](./dns) |
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
|
|
||||||
"server": "127.0.0.1",
|
"server": "127.0.0.1",
|
||||||
"server_port": 1080,
|
"server_port": 1080,
|
||||||
"version": 3,
|
"version": 2,
|
||||||
"password": "fuck me till the daylight",
|
"password": "fuck me till the daylight",
|
||||||
"tls": {},
|
"tls": {},
|
||||||
|
|
||||||
@@ -37,13 +37,12 @@ ShadowTLS protocol version.
|
|||||||
|---------------|-----------------------------------------------------------------------------------------|
|
|---------------|-----------------------------------------------------------------------------------------|
|
||||||
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
||||||
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
||||||
| `3` | [ShadowTLS v3](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-v3-en.md) |
|
|
||||||
|
|
||||||
#### password
|
#### password
|
||||||
|
|
||||||
Set password.
|
Set password.
|
||||||
|
|
||||||
Only available in the ShadowTLS v2/v3 protocol.
|
Only available in the ShadowTLS v2 protocol.
|
||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
|
|
||||||
"server": "127.0.0.1",
|
"server": "127.0.0.1",
|
||||||
"server_port": 1080,
|
"server_port": 1080,
|
||||||
"version": 3,
|
"version": 2,
|
||||||
"password": "fuck me till the daylight",
|
"password": "fuck me till the daylight",
|
||||||
"tls": {},
|
"tls": {},
|
||||||
|
|
||||||
@@ -37,13 +37,12 @@ ShadowTLS 协议版本。
|
|||||||
|---------------|-----------------------------------------------------------------------------------------|
|
|---------------|-----------------------------------------------------------------------------------------|
|
||||||
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
| `1` (default) | [ShadowTLS v1](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v1) |
|
||||||
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
| `2` | [ShadowTLS v2](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-en.md#v2) |
|
||||||
| `3` | [ShadowTLS v3](https://github.com/ihciah/shadow-tls/blob/master/docs/protocol-v3-en.md) |
|
|
||||||
|
|
||||||
#### password
|
#### password
|
||||||
|
|
||||||
设置密码。
|
设置密码。
|
||||||
|
|
||||||
仅在 ShadowTLS v2/v3 协议中可用。
|
仅在 ShadowTLS v2 协议中可用。
|
||||||
|
|
||||||
#### tls
|
#### tls
|
||||||
|
|
||||||
|
|||||||
@@ -12,9 +12,6 @@
|
|||||||
"private_key": "",
|
"private_key": "",
|
||||||
"private_key_path": "$HOME/.ssh/id_rsa",
|
"private_key_path": "$HOME/.ssh/id_rsa",
|
||||||
"private_key_passphrase": "",
|
"private_key_passphrase": "",
|
||||||
"host_key": [
|
|
||||||
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdH..."
|
|
||||||
],
|
|
||||||
"host_key_algorithms": [],
|
"host_key_algorithms": [],
|
||||||
"client_version": "SSH-2.0-OpenSSH_7.4p1",
|
"client_version": "SSH-2.0-OpenSSH_7.4p1",
|
||||||
|
|
||||||
@@ -54,10 +51,6 @@ Private key path.
|
|||||||
|
|
||||||
Private key passphrase.
|
Private key passphrase.
|
||||||
|
|
||||||
#### host_key
|
|
||||||
|
|
||||||
Host key. Accept any if empty.
|
|
||||||
|
|
||||||
#### host_key_algorithms
|
#### host_key_algorithms
|
||||||
|
|
||||||
Host key algorithms.
|
Host key algorithms.
|
||||||
|
|||||||
@@ -12,9 +12,6 @@
|
|||||||
"private_key": "",
|
"private_key": "",
|
||||||
"private_key_path": "$HOME/.ssh/id_rsa",
|
"private_key_path": "$HOME/.ssh/id_rsa",
|
||||||
"private_key_passphrase": "",
|
"private_key_passphrase": "",
|
||||||
"host_key": [
|
|
||||||
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdH..."
|
|
||||||
],
|
|
||||||
"host_key_algorithms": [],
|
"host_key_algorithms": [],
|
||||||
"client_version": "SSH-2.0-OpenSSH_7.4p1",
|
"client_version": "SSH-2.0-OpenSSH_7.4p1",
|
||||||
|
|
||||||
@@ -54,10 +51,6 @@ SSH 用户, 默认使用 root。
|
|||||||
|
|
||||||
密钥密码。
|
密钥密码。
|
||||||
|
|
||||||
#### host_key
|
|
||||||
|
|
||||||
主机密钥,留空接受所有。
|
|
||||||
|
|
||||||
#### host_key_algorithms
|
#### host_key_algorithms
|
||||||
|
|
||||||
主机密钥算法。
|
主机密钥算法。
|
||||||
|
|||||||
@@ -8,7 +8,6 @@
|
|||||||
"server": "127.0.0.1",
|
"server": "127.0.0.1",
|
||||||
"server_port": 1080,
|
"server_port": 1080,
|
||||||
"uuid": "bf000d23-0752-40b4-affe-68f7707a9661",
|
"uuid": "bf000d23-0752-40b4-affe-68f7707a9661",
|
||||||
"flow": "xtls-rprx-vision",
|
|
||||||
"network": "tcp",
|
"network": "tcp",
|
||||||
"tls": {},
|
"tls": {},
|
||||||
"packet_encoding": "",
|
"packet_encoding": "",
|
||||||
@@ -18,6 +17,10 @@
|
|||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
!!! warning ""
|
||||||
|
|
||||||
|
The VLESS protocol is architecturally coupled to v2ray and is unmaintained. This outbound is provided for compatibility purposes only.
|
||||||
|
|
||||||
### Fields
|
### Fields
|
||||||
|
|
||||||
#### server
|
#### server
|
||||||
@@ -36,15 +39,7 @@ The server port.
|
|||||||
|
|
||||||
==Required==
|
==Required==
|
||||||
|
|
||||||
VLESS user id.
|
The VLESS user id.
|
||||||
|
|
||||||
#### flow
|
|
||||||
|
|
||||||
VLESS Sub-protocol.
|
|
||||||
|
|
||||||
Available values:
|
|
||||||
|
|
||||||
* `xtls-rprx-vision`
|
|
||||||
|
|
||||||
#### network
|
#### network
|
||||||
|
|
||||||
@@ -60,8 +55,6 @@ TLS configuration, see [TLS](/configuration/shared/tls/#outbound).
|
|||||||
|
|
||||||
#### packet_encoding
|
#### packet_encoding
|
||||||
|
|
||||||
UDP packet encoding, xudp is used by default.
|
|
||||||
|
|
||||||
| Encoding | Description |
|
| Encoding | Description |
|
||||||
|------------|-----------------------|
|
|------------|-----------------------|
|
||||||
| (none) | Disabled |
|
| (none) | Disabled |
|
||||||
|
|||||||
@@ -8,7 +8,6 @@
|
|||||||
"server": "127.0.0.1",
|
"server": "127.0.0.1",
|
||||||
"server_port": 1080,
|
"server_port": 1080,
|
||||||
"uuid": "bf000d23-0752-40b4-affe-68f7707a9661",
|
"uuid": "bf000d23-0752-40b4-affe-68f7707a9661",
|
||||||
"flow": "xtls-rprx-vision",
|
|
||||||
"network": "tcp",
|
"network": "tcp",
|
||||||
"tls": {},
|
"tls": {},
|
||||||
"packet_encoding": "",
|
"packet_encoding": "",
|
||||||
@@ -18,6 +17,10 @@
|
|||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
!!! warning ""
|
||||||
|
|
||||||
|
VLESS 协议与 v2ray 架构耦合且无人维护。 提供此出站仅出于兼容性目的。
|
||||||
|
|
||||||
### 字段
|
### 字段
|
||||||
|
|
||||||
#### server
|
#### server
|
||||||
@@ -38,14 +41,6 @@
|
|||||||
|
|
||||||
VLESS 用户 ID。
|
VLESS 用户 ID。
|
||||||
|
|
||||||
#### flow
|
|
||||||
|
|
||||||
VLESS 子协议。
|
|
||||||
|
|
||||||
可用值:
|
|
||||||
|
|
||||||
* `xtls-rprx-vision`
|
|
||||||
|
|
||||||
#### network
|
#### network
|
||||||
|
|
||||||
启用的网络协议。
|
启用的网络协议。
|
||||||
@@ -60,8 +55,6 @@ TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#outbound)。
|
|||||||
|
|
||||||
#### packet_encoding
|
#### packet_encoding
|
||||||
|
|
||||||
UDP 包编码,默认使用 xudp。
|
|
||||||
|
|
||||||
| 编码 | 描述 |
|
| 编码 | 描述 |
|
||||||
|------------|---------------|
|
|------------|---------------|
|
||||||
| (空) | 禁用 |
|
| (空) | 禁用 |
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ Encryption methods:
|
|||||||
* `none`
|
* `none`
|
||||||
* `zero`
|
* `zero`
|
||||||
* `aes-128-gcm`
|
* `aes-128-gcm`
|
||||||
* `chacha20-poly1305`
|
* `chancha20-poly1305`
|
||||||
|
|
||||||
Legacy encryption methods:
|
Legacy encryption methods:
|
||||||
|
|
||||||
@@ -86,8 +86,6 @@ TLS configuration, see [TLS](/configuration/shared/tls/#outbound).
|
|||||||
|
|
||||||
#### packet_encoding
|
#### packet_encoding
|
||||||
|
|
||||||
UDP packet encoding.
|
|
||||||
|
|
||||||
| Encoding | Description |
|
| Encoding | Description |
|
||||||
|------------|-----------------------|
|
|------------|-----------------------|
|
||||||
| (none) | Disabled |
|
| (none) | Disabled |
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ VMess 用户 ID。
|
|||||||
* `none`
|
* `none`
|
||||||
* `zero`
|
* `zero`
|
||||||
* `aes-128-gcm`
|
* `aes-128-gcm`
|
||||||
* `chacha20-poly1305`
|
* `chancha20-poly1305`
|
||||||
|
|
||||||
旧加密方法:
|
旧加密方法:
|
||||||
|
|
||||||
@@ -86,8 +86,6 @@ TLS 配置, 参阅 [TLS](/zh/configuration/shared/tls/#outbound)。
|
|||||||
|
|
||||||
#### packet_encoding
|
#### packet_encoding
|
||||||
|
|
||||||
UDP 包编码。
|
|
||||||
|
|
||||||
| 编码 | 描述 |
|
| 编码 | 描述 |
|
||||||
|------------|---------------|
|
|------------|---------------|
|
||||||
| (空) | 禁用 |
|
| (空) | 禁用 |
|
||||||
|
|||||||
@@ -26,20 +26,6 @@
|
|||||||
"key_id": "",
|
"key_id": "",
|
||||||
"mac_key": ""
|
"mac_key": ""
|
||||||
}
|
}
|
||||||
},
|
|
||||||
"reality": {
|
|
||||||
"enabled": false,
|
|
||||||
"handshake": {
|
|
||||||
"server": "google.com",
|
|
||||||
"server_port": 443,
|
|
||||||
|
|
||||||
... // Dial Fields
|
|
||||||
},
|
|
||||||
"private_key": "UuMBgl7MXTPx9inmQp2UC7Jcnwc6XYbwDNebonM-FCc",
|
|
||||||
"short_id": [
|
|
||||||
"0123456789abcdef"
|
|
||||||
],
|
|
||||||
"max_time_difference": "1m"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
@@ -67,11 +53,6 @@
|
|||||||
"utls": {
|
"utls": {
|
||||||
"enabled": false,
|
"enabled": false,
|
||||||
"fingerprint": ""
|
"fingerprint": ""
|
||||||
},
|
|
||||||
"reality": {
|
|
||||||
"enabled": false,
|
|
||||||
"public_key": "jNXHt1yRo0vDuchQlIP6Z0ZvjT3KtzVI-T4E7RoLJS0",
|
|
||||||
"short_id": "0123456789abcdef"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
@@ -218,7 +199,6 @@ Available fingerprint values:
|
|||||||
* ios
|
* ios
|
||||||
* android
|
* android
|
||||||
* random
|
* random
|
||||||
* randomized
|
|
||||||
|
|
||||||
Chrome fingerprint will be used if empty.
|
Chrome fingerprint will be used if empty.
|
||||||
|
|
||||||
@@ -295,54 +275,6 @@ The key identifier.
|
|||||||
|
|
||||||
The MAC key.
|
The MAC key.
|
||||||
|
|
||||||
### Reality Fields
|
|
||||||
|
|
||||||
!!! warning ""
|
|
||||||
|
|
||||||
reality server is not included by default, see [Installation](/#installation).
|
|
||||||
|
|
||||||
!!! warning ""
|
|
||||||
|
|
||||||
uTLS, which is required by reality client is not included by default, see [Installation](/#installation).
|
|
||||||
|
|
||||||
#### handshake
|
|
||||||
|
|
||||||
==Server only==
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
Handshake server address and [Dial options](/configuration/shared/dial).
|
|
||||||
|
|
||||||
#### private_key
|
|
||||||
|
|
||||||
==Server only==
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
Private key, generated by `sing-box generate reality-keypair`.
|
|
||||||
|
|
||||||
#### public_key
|
|
||||||
|
|
||||||
==Client only==
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
Public key, generated by `sing-box generate reality-keypair`.
|
|
||||||
|
|
||||||
#### short_id
|
|
||||||
|
|
||||||
==Required==
|
|
||||||
|
|
||||||
A 8-bit hex string.
|
|
||||||
|
|
||||||
#### max_time_difference
|
|
||||||
|
|
||||||
==Server only==
|
|
||||||
|
|
||||||
The maximum time difference between the server and the client.
|
|
||||||
|
|
||||||
Check disabled if empty.
|
|
||||||
|
|
||||||
### Reload
|
### Reload
|
||||||
|
|
||||||
For server configuration, certificate and key will be automatically reloaded if modified.
|
For server configuration, certificate and key will be automatically reloaded if modified.
|
||||||
@@ -26,20 +26,6 @@
|
|||||||
"key_id": "",
|
"key_id": "",
|
||||||
"mac_key": ""
|
"mac_key": ""
|
||||||
}
|
}
|
||||||
},
|
|
||||||
"reality": {
|
|
||||||
"enabled": false,
|
|
||||||
"handshake": {
|
|
||||||
"server": "google.com",
|
|
||||||
"server_port": 443,
|
|
||||||
|
|
||||||
... // 拨号字段
|
|
||||||
},
|
|
||||||
"private_key": "UuMBgl7MXTPx9inmQp2UC7Jcnwc6XYbwDNebonM-FCc",
|
|
||||||
"short_id": [
|
|
||||||
"0123456789abcdef"
|
|
||||||
],
|
|
||||||
"max_time_difference": "1m"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
@@ -67,11 +53,6 @@
|
|||||||
"utls": {
|
"utls": {
|
||||||
"enabled": false,
|
"enabled": false,
|
||||||
"fingerprint": ""
|
"fingerprint": ""
|
||||||
},
|
|
||||||
"reality": {
|
|
||||||
"enabled": false,
|
|
||||||
"public_key": "jNXHt1yRo0vDuchQlIP6Z0ZvjT3KtzVI-T4E7RoLJS0",
|
|
||||||
"short_id": "0123456789abcdef"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
@@ -218,7 +199,6 @@ uTLS 是 "crypto/tls" 的一个分支,它提供了 ClientHello 指纹识别阻
|
|||||||
* ios
|
* ios
|
||||||
* android
|
* android
|
||||||
* random
|
* random
|
||||||
* randomized
|
|
||||||
|
|
||||||
默认使用 chrome 指纹。
|
默认使用 chrome 指纹。
|
||||||
|
|
||||||
@@ -291,52 +271,6 @@ EAB(外部帐户绑定)包含将 ACME 帐户绑定或映射到其他已知
|
|||||||
|
|
||||||
MAC 密钥。
|
MAC 密钥。
|
||||||
|
|
||||||
### Reality 字段
|
|
||||||
|
|
||||||
!!! warning ""
|
|
||||||
|
|
||||||
默认安装不包含 reality 服务器,参阅 [安装](/zh/#_2)。
|
|
||||||
|
|
||||||
!!! warning ""
|
|
||||||
|
|
||||||
默认安装不包含被 reality 客户端需要的 uTLS, 参阅 [安装](/zh/#_2)。
|
|
||||||
|
|
||||||
#### handshake
|
|
||||||
|
|
||||||
==仅服务器==
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
握手服务器地址和 [拨号参数](/zh/configuration/shared/dial/)。
|
|
||||||
|
|
||||||
#### private_key
|
|
||||||
|
|
||||||
==仅服务器==
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
私钥,由 `sing-box generate reality-keypair` 生成。
|
|
||||||
|
|
||||||
#### public_key
|
|
||||||
|
|
||||||
==仅客户端==
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
公钥,由 `sing-box generate reality-keypair` 生成。
|
|
||||||
|
|
||||||
#### short_id
|
|
||||||
|
|
||||||
==必填==
|
|
||||||
|
|
||||||
一个八位十六进制的字符串。
|
|
||||||
|
|
||||||
#### max_time_difference
|
|
||||||
|
|
||||||
服务器与和客户端之间允许的最大时间差。
|
|
||||||
|
|
||||||
默认禁用检查。
|
|
||||||
|
|
||||||
### 重载
|
### 重载
|
||||||
|
|
||||||
对于服务器配置,如果修改,证书和密钥将自动重新加载。
|
对于服务器配置,如果修改,证书和密钥将自动重新加载。
|
||||||
@@ -7,13 +7,8 @@
|
|||||||
"type": "shadowtls",
|
"type": "shadowtls",
|
||||||
"listen": "::",
|
"listen": "::",
|
||||||
"listen_port": 4443,
|
"listen_port": 4443,
|
||||||
"version": 3,
|
"version": 2,
|
||||||
"users": [
|
"password": "fuck me till the daylight",
|
||||||
{
|
|
||||||
"name": "sekai",
|
|
||||||
"password": "8JCsPssfgS8tiRwiMlhARg=="
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"handshake": {
|
"handshake": {
|
||||||
"server": "google.com",
|
"server": "google.com",
|
||||||
"server_port": 443
|
"server_port": 443
|
||||||
@@ -52,15 +47,11 @@
|
|||||||
"tag": "shadowtls-out",
|
"tag": "shadowtls-out",
|
||||||
"server": "127.0.0.1",
|
"server": "127.0.0.1",
|
||||||
"server_port": 4443,
|
"server_port": 4443,
|
||||||
"version": 3,
|
"version": 2,
|
||||||
"password": "8JCsPssfgS8tiRwiMlhARg==",
|
"password": "fuck me till the daylight",
|
||||||
"tls": {
|
"tls": {
|
||||||
"enabled": true,
|
"enabled": true,
|
||||||
"server_name": "google.com",
|
"server_name": "google.com"
|
||||||
"utls": {
|
|
||||||
"enabled": true,
|
|
||||||
"fingerprint": "chrome"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -8,6 +8,44 @@ Welcome to the wiki page for the sing-box project.
|
|||||||
|
|
||||||
The universal proxy platform.
|
The universal proxy platform.
|
||||||
|
|
||||||
|
## Installation
|
||||||
|
|
||||||
|
sing-box requires Golang **1.18.5** or a higher version.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
go install -v github.com/sagernet/sing-box/cmd/sing-box@latest
|
||||||
|
```
|
||||||
|
|
||||||
|
Install with options:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
go install -v -tags with_clash_api github.com/sagernet/sing-box/cmd/sing-box@latest
|
||||||
|
```
|
||||||
|
|
||||||
|
| Build Tag | Description |
|
||||||
|
|------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||||
|
| `with_quic` | Build with QUIC support, see [QUIC and HTTP3 dns transports](./configuration/dns/server), [Naive inbound](./configuration/inbound/naive), [Hysteria Inbound](./configuration/inbound/hysteria), [Hysteria Outbound](./configuration/outbound/hysteria) and [V2Ray Transport#QUIC](./configuration/shared/v2ray-transport#quic). |
|
||||||
|
| `with_grpc` | Build with standard gRPC support, see [V2Ray Transport#gRPC](./configuration/shared/v2ray-transport#grpc). |
|
||||||
|
| `with_wireguard` | Build with WireGuard support, see [WireGuard outbound](./configuration/outbound/wireguard). |
|
||||||
|
| `with_shadowsocksr` | Build with ShadowsocksR support, see [ShadowsocksR outbound](./configuration/outbound/shadowsocksr). |
|
||||||
|
| `with_ech` | Build with TLS ECH extension support for TLS outbound, see [TLS](./configuration/shared/tls#ech). |
|
||||||
|
| `with_utls` | Build with [uTLS](https://github.com/refraction-networking/utls) support for TLS outbound, see [TLS](./configuration/shared/tls#utls). |
|
||||||
|
| `with_acme` | Build with ACME TLS certificate issuer support, see [TLS](./configuration/shared/tls). |
|
||||||
|
| `with_clash_api` | Build with Clash API support, see [Experimental](./configuration/experimental#clash-api-fields). |
|
||||||
|
| `with_v2ray_api` | Build with V2Ray API support, see [Experimental](./configuration/experimental#v2ray-api-fields). |
|
||||||
|
| `with_gvisor` | Build with gVisor support, see [Tun inbound](./configuration/inbound/tun#stack) and [WireGuard outbound](./configuration/outbound/wireguard#system_interface). |
|
||||||
|
| `with_embedded_tor` (CGO required) | Build with embedded Tor support, see [Tor outbound](./configuration/outbound/tor). |
|
||||||
|
| `with_lwip` (CGO required) | Build with LWIP Tun stack support, see [Tun inbound](./configuration/inbound/tun#stack). |
|
||||||
|
|
||||||
|
The binary is built under $GOPATH/bin
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sing-box version
|
||||||
|
```
|
||||||
|
|
||||||
|
It is also recommended to use systemd to manage sing-box service,
|
||||||
|
see [Linux server installation example](./examples/linux-server-installation).
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -8,6 +8,44 @@ description: 欢迎来到该 sing-box 项目的文档页。
|
|||||||
|
|
||||||
通用代理平台。
|
通用代理平台。
|
||||||
|
|
||||||
|
## 安装
|
||||||
|
|
||||||
|
sing-box 需要 Golang **1.18.5** 或更高版本。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
go install -v github.com/sagernet/sing-box/cmd/sing-box@latest
|
||||||
|
```
|
||||||
|
|
||||||
|
自定义安装:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
go install -v -tags with_clash_api github.com/sagernet/sing-box/cmd/sing-box@latest
|
||||||
|
```
|
||||||
|
|
||||||
|
| 构建标志 | 描述 |
|
||||||
|
|------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||||
|
| `with_quic` | 启用 QUIC 支持,参阅 [QUIC 和 HTTP3 DNS 传输层](./configuration/dns/server),[Naive 入站](./configuration/inbound/naive),[Hysteria 入站](./configuration/inbound/hysteria),[Hysteria 出站](./configuration/outbound/hysteria) 和 [V2Ray 传输层#QUIC](./configuration/shared/v2ray-transport#quic)。 |
|
||||||
|
| `with_grpc` | 启用标准 gRPC 支持,参阅 [V2Ray 传输层#gRPC](./configuration/shared/v2ray-transport#grpc)。 |
|
||||||
|
| `with_wireguard` | 启用 WireGuard 支持,参阅 [WireGuard 出站](./configuration/outbound/wireguard)。 |
|
||||||
|
| `with_shadowsocksr` | 启用 ShadowsocksR 支持,参阅 [ShadowsocksR 出站](./configuration/outbound/shadowsocksr)。 |
|
||||||
|
| `with_ech` | 启用 TLS ECH 扩展支持,参阅 [TLS](./configuration/shared/tls#ech)。 |
|
||||||
|
| `with_utls` | 启用 uTLS 支持,参阅 [实验性](./configuration/experimental#clash-api-fields)。 |
|
||||||
|
| `with_acme` | 启用 ACME TLS 证书签发支持,参阅 [TLS](./configuration/shared/tls)。 |
|
||||||
|
| `with_clash_api` | 启用 Clash API 支持,参阅 [实验性](./configuration/experimental#clash-api-fields)。 |
|
||||||
|
| `with_v2ray_api` | 启用 V2Rat API 支持,参阅 [实验性](./configuration/experimental#v2ray-api-fields)。 |
|
||||||
|
| `with_gvisor` | 启用 gVisor 支持,参阅 [Tun 入站](./configuration/inbound/tun#stack) 和 [WireGuard 出站](./configuration/outbound/wireguard#system_interface)。 |
|
||||||
|
| `with_embedded_tor` (需要 CGO) | 启用 嵌入式 Tor 支持,参阅 [Tor 出站](./configuration/outbound/tor)。 |
|
||||||
|
| `with_lwip` (需要 CGO) | 启用 LWIP Tun 栈支持,参阅 [Tun 入站](./configuration/inbound/tun#stack)。 |
|
||||||
|
|
||||||
|
二进制文件将被构建在 `$GOPATH/bin` 下。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sing-box version
|
||||||
|
```
|
||||||
|
|
||||||
|
同时推荐使用 systemd 来管理 sing-box 服务器实例。
|
||||||
|
参阅 [Linux 服务器安装示例](./examples/linux-server-installation)。
|
||||||
|
|
||||||
## 授权
|
## 授权
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -1,21 +0,0 @@
|
|||||||
# SFI
|
|
||||||
|
|
||||||
Experimental official iOS client for sing-box.
|
|
||||||
|
|
||||||
#### Requirements
|
|
||||||
|
|
||||||
* iOS 15.0+
|
|
||||||
* macOS 12.0+ with Apple Silicon
|
|
||||||
|
|
||||||
#### Download
|
|
||||||
|
|
||||||
* [TestFlight](https://testflight.apple.com/join/c6ylui2j)
|
|
||||||
|
|
||||||
#### Limit
|
|
||||||
|
|
||||||
* `system` tun stack not working
|
|
||||||
|
|
||||||
#### Privacy policy
|
|
||||||
|
|
||||||
* SFI did not collect or share personal data.
|
|
||||||
* The data generated by the software is always on your device.
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
# SFI
|
|
||||||
|
|
||||||
实验性的官方 iOS sing-box 客户端。
|
|
||||||
|
|
||||||
#### 要求
|
|
||||||
|
|
||||||
* iOS 15.0+
|
|
||||||
* macOS 12.0+ with Apple Silicon
|
|
||||||
|
|
||||||
#### 下载
|
|
||||||
|
|
||||||
* [TestFlight](https://testflight.apple.com/join/c6ylui2j)
|
|
||||||
|
|
||||||
#### 限制
|
|
||||||
|
|
||||||
* `system` tun stack 不工作
|
|
||||||
|
|
||||||
#### 隐私政策
|
|
||||||
|
|
||||||
* SFI 不收集或共享个人数据。
|
|
||||||
* 软件生成的数据始终在您的设备上。
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
# Install from source
|
|
||||||
|
|
||||||
sing-box requires Golang **1.18.5** or a higher version.
|
|
||||||
|
|
||||||
```bash
|
|
||||||
go install -v github.com/sagernet/sing-box/cmd/sing-box@latest
|
|
||||||
```
|
|
||||||
|
|
||||||
Install with options:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
go install -v -tags with_clash_api github.com/sagernet/sing-box/cmd/sing-box@latest
|
|
||||||
```
|
|
||||||
|
|
||||||
| Build Tag | Description |
|
|
||||||
|------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
|
||||||
| `with_quic` | Build with QUIC support, see [QUIC and HTTP3 DNS transports](./configuration/dns/server), [Naive inbound](./configuration/inbound/naive), [Hysteria Inbound](./configuration/inbound/hysteria), [Hysteria Outbound](./configuration/outbound/hysteria) and [V2Ray Transport#QUIC](./configuration/shared/v2ray-transport#quic). |
|
|
||||||
| `with_grpc` | Build with standard gRPC support, see [V2Ray Transport#gRPC](./configuration/shared/v2ray-transport#grpc). |
|
|
||||||
| `with_dhcp` | Build with DHCP support, see [DHCP DNS transport](./configuration/dns/server). |
|
|
||||||
| `with_wireguard` | Build with WireGuard support, see [WireGuard outbound](./configuration/outbound/wireguard). |
|
|
||||||
| `with_shadowsocksr` | Build with ShadowsocksR support, see [ShadowsocksR outbound](./configuration/outbound/shadowsocksr). |
|
|
||||||
| `with_ech` | Build with TLS ECH extension support for TLS outbound, see [TLS](./configuration/shared/tls#ech). |
|
|
||||||
| `with_utls` | Build with [uTLS](https://github.com/refraction-networking/utls) support for TLS outbound, see [TLS](./configuration/shared/tls#utls). |
|
|
||||||
| `with_reality_server` | Build with reality TLS server support, see [TLS](./configuration/shared/tls). |
|
|
||||||
| `with_acme` | Build with ACME TLS certificate issuer support, see [TLS](./configuration/shared/tls). |
|
|
||||||
| `with_clash_api` | Build with Clash API support, see [Experimental](./configuration/experimental#clash-api-fields). |
|
|
||||||
| `with_v2ray_api` | Build with V2Ray API support, see [Experimental](./configuration/experimental#v2ray-api-fields). |
|
|
||||||
| `with_gvisor` | Build with gVisor support, see [Tun inbound](./configuration/inbound/tun#stack) and [WireGuard outbound](./configuration/outbound/wireguard#system_interface). |
|
|
||||||
| `with_embedded_tor` (CGO required) | Build with embedded Tor support, see [Tor outbound](./configuration/outbound/tor). |
|
|
||||||
| `with_lwip` (CGO required) | Build with LWIP Tun stack support, see [Tun inbound](./configuration/inbound/tun#stack). |
|
|
||||||
|
|
||||||
The binary is built under $GOPATH/bin
|
|
||||||
|
|
||||||
```bash
|
|
||||||
sing-box version
|
|
||||||
```
|
|
||||||
|
|
||||||
It is also recommended to use systemd to manage sing-box service,
|
|
||||||
see [Linux server installation example](./examples/linux-server-installation).
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
# 从源代码安装
|
|
||||||
|
|
||||||
sing-box 需要 Golang **1.18.5** 或更高版本。
|
|
||||||
|
|
||||||
```bash
|
|
||||||
go install -v github.com/sagernet/sing-box/cmd/sing-box@latest
|
|
||||||
```
|
|
||||||
|
|
||||||
自定义安装:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
go install -v -tags with_clash_api github.com/sagernet/sing-box/cmd/sing-box@latest
|
|
||||||
```
|
|
||||||
|
|
||||||
| 构建标志 | 描述 |
|
|
||||||
|------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
|
||||||
| `with_quic` | 启用 QUIC 支持,参阅 [QUIC 和 HTTP3 DNS 传输层](./configuration/dns/server),[Naive 入站](./configuration/inbound/naive),[Hysteria 入站](./configuration/inbound/hysteria),[Hysteria 出站](./configuration/outbound/hysteria) 和 [V2Ray 传输层#QUIC](./configuration/shared/v2ray-transport#quic)。 |
|
|
||||||
| `with_grpc` | 启用标准 gRPC 支持,参阅 [V2Ray 传输层#gRPC](./configuration/shared/v2ray-transport#grpc)。 |
|
|
||||||
| `with_dhcp` | 启用 DHCP 支持,参阅 [DHCP DNS 传输层](./configuration/dns/server)。 |
|
|
||||||
| `with_wireguard` | 启用 WireGuard 支持,参阅 [WireGuard 出站](./configuration/outbound/wireguard)。 |
|
|
||||||
| `with_shadowsocksr` | 启用 ShadowsocksR 支持,参阅 [ShadowsocksR 出站](./configuration/outbound/shadowsocksr)。 |
|
|
||||||
| `with_ech` | 启用 TLS ECH 扩展支持,参阅 [TLS](./configuration/shared/tls#ech)。 |
|
|
||||||
| `with_utls` | 启用 [uTLS](https://github.com/refraction-networking/utls) 支持,参阅 [TLS](./configuration/shared/tls#utls)。 |
|
|
||||||
| `with_reality_server` | 启用 reality TLS 服务器支持,参阅 [TLS](./configuration/shared/tls)。 |
|
|
||||||
| `with_acme` | 启用 ACME TLS 证书签发支持,参阅 [TLS](./configuration/shared/tls)。 |
|
|
||||||
| `with_clash_api` | 启用 Clash API 支持,参阅 [实验性](./configuration/experimental#clash-api-fields)。 |
|
|
||||||
| `with_v2ray_api` | 启用 V2Ray API 支持,参阅 [实验性](./configuration/experimental#v2ray-api-fields)。 |
|
|
||||||
| `with_gvisor` | 启用 gVisor 支持,参阅 [Tun 入站](./configuration/inbound/tun#stack) 和 [WireGuard 出站](./configuration/outbound/wireguard#system_interface)。 |
|
|
||||||
| `with_embedded_tor` (需要 CGO) | 启用 嵌入式 Tor 支持,参阅 [Tor 出站](./configuration/outbound/tor)。 |
|
|
||||||
| `with_lwip` (需要 CGO) | 启用 LWIP Tun 栈支持,参阅 [Tun 入站](./configuration/inbound/tun#stack)。 |
|
|
||||||
|
|
||||||
二进制文件将被构建在 `$GOPATH/bin` 下。
|
|
||||||
|
|
||||||
```bash
|
|
||||||
sing-box version
|
|
||||||
```
|
|
||||||
|
|
||||||
同时推荐使用 systemd 来管理 sing-box 服务器实例。
|
|
||||||
参阅 [Linux 服务器安装示例](./examples/linux-server-installation)。
|
|
||||||
@@ -1,82 +0,0 @@
|
|||||||
package clashapi
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"net/http"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/adapter"
|
|
||||||
C "github.com/sagernet/sing-box/constant"
|
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
|
|
||||||
"github.com/go-chi/chi/v5"
|
|
||||||
"github.com/go-chi/render"
|
|
||||||
"github.com/miekg/dns"
|
|
||||||
)
|
|
||||||
|
|
||||||
func dnsRouter(router adapter.Router) http.Handler {
|
|
||||||
r := chi.NewRouter()
|
|
||||||
r.Get("/query", queryDNS(router))
|
|
||||||
return r
|
|
||||||
}
|
|
||||||
|
|
||||||
func queryDNS(router adapter.Router) func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
return func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
name := r.URL.Query().Get("name")
|
|
||||||
qTypeStr := r.URL.Query().Get("type")
|
|
||||||
if qTypeStr == "" {
|
|
||||||
qTypeStr = "A"
|
|
||||||
}
|
|
||||||
|
|
||||||
qType, exist := dns.StringToType[qTypeStr]
|
|
||||||
if !exist {
|
|
||||||
render.Status(r, http.StatusBadRequest)
|
|
||||||
render.JSON(w, r, newError("invalid query type"))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
ctx, cancel := context.WithTimeout(context.Background(), C.DNSTimeout)
|
|
||||||
defer cancel()
|
|
||||||
|
|
||||||
msg := dns.Msg{}
|
|
||||||
msg.SetQuestion(dns.Fqdn(name), qType)
|
|
||||||
resp, err := router.Exchange(ctx, &msg)
|
|
||||||
if err != nil {
|
|
||||||
render.Status(r, http.StatusInternalServerError)
|
|
||||||
render.JSON(w, r, newError(err.Error()))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
responseData := render.M{
|
|
||||||
"Status": resp.Rcode,
|
|
||||||
"Question": resp.Question,
|
|
||||||
"Server": "internal",
|
|
||||||
"TC": resp.Truncated,
|
|
||||||
"RD": resp.RecursionDesired,
|
|
||||||
"RA": resp.RecursionAvailable,
|
|
||||||
"AD": resp.AuthenticatedData,
|
|
||||||
"CD": resp.CheckingDisabled,
|
|
||||||
}
|
|
||||||
|
|
||||||
rr2Json := func(rr dns.RR) render.M {
|
|
||||||
header := rr.Header()
|
|
||||||
return render.M{
|
|
||||||
"name": header.Name,
|
|
||||||
"type": header.Rrtype,
|
|
||||||
"TTL": header.Ttl,
|
|
||||||
"data": rr.String()[len(header.String()):],
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(resp.Answer) > 0 {
|
|
||||||
responseData["Answer"] = common.Map(resp.Answer, rr2Json)
|
|
||||||
}
|
|
||||||
if len(resp.Ns) > 0 {
|
|
||||||
responseData["Authority"] = common.Map(resp.Ns, rr2Json)
|
|
||||||
}
|
|
||||||
if len(resp.Extra) > 0 {
|
|
||||||
responseData["Additional"] = common.Map(resp.Extra, rr2Json)
|
|
||||||
}
|
|
||||||
|
|
||||||
render.JSON(w, r, responseData)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -42,6 +42,7 @@ type Server struct {
|
|||||||
httpServer *http.Server
|
httpServer *http.Server
|
||||||
trafficManager *trafficontrol.Manager
|
trafficManager *trafficontrol.Manager
|
||||||
urlTestHistory *urltest.HistoryStorage
|
urlTestHistory *urltest.HistoryStorage
|
||||||
|
tcpListener net.Listener
|
||||||
mode string
|
mode string
|
||||||
storeSelected bool
|
storeSelected bool
|
||||||
cacheFilePath string
|
cacheFilePath string
|
||||||
@@ -71,11 +72,6 @@ func NewServer(router adapter.Router, logFactory log.ObservableFactory, options
|
|||||||
if cachePath == "" {
|
if cachePath == "" {
|
||||||
cachePath = "cache.db"
|
cachePath = "cache.db"
|
||||||
}
|
}
|
||||||
if foundPath, loaded := C.FindPath(cachePath); loaded {
|
|
||||||
cachePath = foundPath
|
|
||||||
} else {
|
|
||||||
cachePath = C.BasePath(cachePath)
|
|
||||||
}
|
|
||||||
server.cacheFilePath = cachePath
|
server.cacheFilePath = cachePath
|
||||||
}
|
}
|
||||||
cors := cors.New(cors.Options{
|
cors := cors.New(cors.Options{
|
||||||
@@ -100,11 +96,10 @@ func NewServer(router adapter.Router, logFactory log.ObservableFactory, options
|
|||||||
r.Mount("/script", scriptRouter())
|
r.Mount("/script", scriptRouter())
|
||||||
r.Mount("/profile", profileRouter())
|
r.Mount("/profile", profileRouter())
|
||||||
r.Mount("/cache", cacheRouter())
|
r.Mount("/cache", cacheRouter())
|
||||||
r.Mount("/dns", dnsRouter(router))
|
|
||||||
})
|
})
|
||||||
if options.ExternalUI != "" {
|
if options.ExternalUI != "" {
|
||||||
chiRouter.Group(func(r chi.Router) {
|
chiRouter.Group(func(r chi.Router) {
|
||||||
fs := http.StripPrefix("/ui", http.FileServer(http.Dir(C.BasePath(os.ExpandEnv(options.ExternalUI)))))
|
fs := http.StripPrefix("/ui", http.FileServer(http.Dir(os.ExpandEnv(options.ExternalUI))))
|
||||||
r.Get("/ui", http.RedirectHandler("/ui/", http.StatusTemporaryRedirect).ServeHTTP)
|
r.Get("/ui", http.RedirectHandler("/ui/", http.StatusTemporaryRedirect).ServeHTTP)
|
||||||
r.Get("/ui/*", func(w http.ResponseWriter, r *http.Request) {
|
r.Get("/ui/*", func(w http.ResponseWriter, r *http.Request) {
|
||||||
fs.ServeHTTP(w, r)
|
fs.ServeHTTP(w, r)
|
||||||
@@ -127,6 +122,7 @@ func (s *Server) Start() error {
|
|||||||
return E.Cause(err, "external controller listen error")
|
return E.Cause(err, "external controller listen error")
|
||||||
}
|
}
|
||||||
s.logger.Info("restful api listening at ", listener.Addr())
|
s.logger.Info("restful api listening at ", listener.Addr())
|
||||||
|
s.tcpListener = listener
|
||||||
go func() {
|
go func() {
|
||||||
err = s.httpServer.Serve(listener)
|
err = s.httpServer.Serve(listener)
|
||||||
if err != nil && !errors.Is(err, http.ErrServerClosed) {
|
if err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||||
@@ -139,6 +135,7 @@ func (s *Server) Start() error {
|
|||||||
func (s *Server) Close() error {
|
func (s *Server) Close() error {
|
||||||
return common.Close(
|
return common.Close(
|
||||||
common.PtrOrNil(s.httpServer),
|
common.PtrOrNil(s.httpServer),
|
||||||
|
s.tcpListener,
|
||||||
s.trafficManager,
|
s.trafficManager,
|
||||||
s.cacheFile,
|
s.cacheFile,
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -1,11 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
const (
|
|
||||||
CommandLog int32 = iota
|
|
||||||
CommandStatus
|
|
||||||
CommandServiceStop
|
|
||||||
CommandServiceReload
|
|
||||||
CommandCloseConnections
|
|
||||||
)
|
|
||||||
@@ -1,75 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"net"
|
|
||||||
"path/filepath"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing/common"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
)
|
|
||||||
|
|
||||||
type CommandClient struct {
|
|
||||||
sharedDirectory string
|
|
||||||
handler CommandClientHandler
|
|
||||||
conn net.Conn
|
|
||||||
options CommandClientOptions
|
|
||||||
}
|
|
||||||
|
|
||||||
type CommandClientOptions struct {
|
|
||||||
Command int32
|
|
||||||
StatusInterval int64
|
|
||||||
}
|
|
||||||
|
|
||||||
type CommandClientHandler interface {
|
|
||||||
Connected()
|
|
||||||
Disconnected(message string)
|
|
||||||
WriteLog(message string)
|
|
||||||
WriteStatus(message *StatusMessage)
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewCommandClient(sharedDirectory string, handler CommandClientHandler, options *CommandClientOptions) *CommandClient {
|
|
||||||
return &CommandClient{
|
|
||||||
sharedDirectory: sharedDirectory,
|
|
||||||
handler: handler,
|
|
||||||
options: common.PtrValueOrDefault(options),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func clientConnect(sharedDirectory string) (net.Conn, error) {
|
|
||||||
return net.DialUnix("unix", nil, &net.UnixAddr{
|
|
||||||
Name: filepath.Join(sharedDirectory, "command.sock"),
|
|
||||||
Net: "unix",
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *CommandClient) Connect() error {
|
|
||||||
conn, err := clientConnect(c.sharedDirectory)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
c.conn = conn
|
|
||||||
err = binary.Write(conn, binary.BigEndian, uint8(c.options.Command))
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
switch c.options.Command {
|
|
||||||
case CommandLog:
|
|
||||||
c.handler.Connected()
|
|
||||||
go c.handleLogConn(conn)
|
|
||||||
case CommandStatus:
|
|
||||||
err = binary.Write(conn, binary.BigEndian, c.options.StatusInterval)
|
|
||||||
if err != nil {
|
|
||||||
return E.Cause(err, "write interval")
|
|
||||||
}
|
|
||||||
c.handler.Connected()
|
|
||||||
go c.handleStatusConn(conn)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *CommandClient) Disconnect() error {
|
|
||||||
return common.Close(c.conn)
|
|
||||||
}
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"net"
|
|
||||||
runtimeDebug "runtime/debug"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/common/dialer/conntrack"
|
|
||||||
)
|
|
||||||
|
|
||||||
func ClientCloseConnections(sharedDirectory string) error {
|
|
||||||
conn, err := clientConnect(sharedDirectory)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer conn.Close()
|
|
||||||
return binary.Write(conn, binary.BigEndian, uint8(CommandCloseConnections))
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) handleCloseConnections(conn net.Conn) error {
|
|
||||||
conntrack.Close()
|
|
||||||
go func() {
|
|
||||||
time.Sleep(time.Second)
|
|
||||||
runtimeDebug.FreeOSMemory()
|
|
||||||
}()
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
@@ -1,103 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"encoding/binary"
|
|
||||||
"io"
|
|
||||||
"net"
|
|
||||||
)
|
|
||||||
|
|
||||||
func (s *CommandServer) WriteMessage(message string) {
|
|
||||||
s.subscriber.Emit(message)
|
|
||||||
s.access.Lock()
|
|
||||||
s.savedLines.PushBack(message)
|
|
||||||
if s.savedLines.Len() > 100 {
|
|
||||||
s.savedLines.Remove(s.savedLines.Front())
|
|
||||||
}
|
|
||||||
s.access.Unlock()
|
|
||||||
}
|
|
||||||
|
|
||||||
func readLog(reader io.Reader) ([]byte, error) {
|
|
||||||
var messageLength uint16
|
|
||||||
err := binary.Read(reader, binary.BigEndian, &messageLength)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
data := make([]byte, messageLength)
|
|
||||||
_, err = io.ReadFull(reader, data)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return data, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func writeLog(writer io.Writer, message []byte) error {
|
|
||||||
err := binary.Write(writer, binary.BigEndian, uint16(len(message)))
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
_, err = writer.Write(message)
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) handleLogConn(conn net.Conn) error {
|
|
||||||
var savedLines []string
|
|
||||||
s.access.Lock()
|
|
||||||
savedLines = make([]string, 0, s.savedLines.Len())
|
|
||||||
for element := s.savedLines.Front(); element != nil; element = element.Next() {
|
|
||||||
savedLines = append(savedLines, element.Value)
|
|
||||||
}
|
|
||||||
s.access.Unlock()
|
|
||||||
subscription, done, err := s.observer.Subscribe()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer s.observer.UnSubscribe(subscription)
|
|
||||||
for _, line := range savedLines {
|
|
||||||
err = writeLog(conn, []byte(line))
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
ctx := connKeepAlive(conn)
|
|
||||||
for {
|
|
||||||
select {
|
|
||||||
case <-ctx.Done():
|
|
||||||
return ctx.Err()
|
|
||||||
case message := <-subscription:
|
|
||||||
err = writeLog(conn, []byte(message))
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
case <-done:
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *CommandClient) handleLogConn(conn net.Conn) {
|
|
||||||
for {
|
|
||||||
message, err := readLog(conn)
|
|
||||||
if err != nil {
|
|
||||||
c.handler.Disconnected(err.Error())
|
|
||||||
return
|
|
||||||
}
|
|
||||||
c.handler.WriteLog(string(message))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func connKeepAlive(reader io.Reader) context.Context {
|
|
||||||
ctx, cancel := context.WithCancelCause(context.Background())
|
|
||||||
go func() {
|
|
||||||
for {
|
|
||||||
_, err := readLog(reader)
|
|
||||||
if err != nil {
|
|
||||||
cancel(err)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
return ctx
|
|
||||||
}
|
|
||||||
@@ -1,48 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"net"
|
|
||||||
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
"github.com/sagernet/sing/common/rw"
|
|
||||||
)
|
|
||||||
|
|
||||||
func ClientServiceReload(sharedDirectory string) error {
|
|
||||||
conn, err := clientConnect(sharedDirectory)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer conn.Close()
|
|
||||||
err = binary.Write(conn, binary.BigEndian, uint8(CommandServiceReload))
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
var hasError bool
|
|
||||||
err = binary.Read(conn, binary.BigEndian, &hasError)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if hasError {
|
|
||||||
errorMessage, err := rw.ReadVString(conn)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
return E.New(errorMessage)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) handleServiceReload(conn net.Conn) error {
|
|
||||||
rErr := s.handler.ServiceReload()
|
|
||||||
err := binary.Write(conn, binary.BigEndian, rErr != nil)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if rErr != nil {
|
|
||||||
return rw.WriteVString(conn, rErr.Error())
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
@@ -1,99 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"net"
|
|
||||||
"os"
|
|
||||||
"path/filepath"
|
|
||||||
"sync"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/log"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
"github.com/sagernet/sing/common/observable"
|
|
||||||
"github.com/sagernet/sing/common/x/list"
|
|
||||||
)
|
|
||||||
|
|
||||||
type CommandServer struct {
|
|
||||||
sockPath string
|
|
||||||
listener net.Listener
|
|
||||||
handler CommandServerHandler
|
|
||||||
|
|
||||||
access sync.Mutex
|
|
||||||
savedLines *list.List[string]
|
|
||||||
subscriber *observable.Subscriber[string]
|
|
||||||
observer *observable.Observer[string]
|
|
||||||
}
|
|
||||||
|
|
||||||
type CommandServerHandler interface {
|
|
||||||
ServiceStop() error
|
|
||||||
ServiceReload() error
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewCommandServer(sharedDirectory string, handler CommandServerHandler) *CommandServer {
|
|
||||||
server := &CommandServer{
|
|
||||||
sockPath: filepath.Join(sharedDirectory, "command.sock"),
|
|
||||||
handler: handler,
|
|
||||||
savedLines: new(list.List[string]),
|
|
||||||
subscriber: observable.NewSubscriber[string](128),
|
|
||||||
}
|
|
||||||
server.observer = observable.NewObserver[string](server.subscriber, 64)
|
|
||||||
return server
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) Start() error {
|
|
||||||
os.Remove(s.sockPath)
|
|
||||||
listener, err := net.ListenUnix("unix", &net.UnixAddr{
|
|
||||||
Name: s.sockPath,
|
|
||||||
Net: "unix",
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
s.listener = listener
|
|
||||||
go s.loopConnection(listener)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) Close() error {
|
|
||||||
return s.listener.Close()
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) loopConnection(listener net.Listener) {
|
|
||||||
for {
|
|
||||||
conn, err := listener.Accept()
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
go func() {
|
|
||||||
hErr := s.handleConnection(conn)
|
|
||||||
if hErr != nil && !E.IsClosed(err) {
|
|
||||||
log.Warn("log-server: process connection: ", hErr)
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) handleConnection(conn net.Conn) error {
|
|
||||||
defer conn.Close()
|
|
||||||
var command uint8
|
|
||||||
err := binary.Read(conn, binary.BigEndian, &command)
|
|
||||||
if err != nil {
|
|
||||||
return E.Cause(err, "read command")
|
|
||||||
}
|
|
||||||
switch int32(command) {
|
|
||||||
case CommandLog:
|
|
||||||
return s.handleLogConn(conn)
|
|
||||||
case CommandStatus:
|
|
||||||
return s.handleStatusConn(conn)
|
|
||||||
case CommandServiceStop:
|
|
||||||
return s.handleServiceStop(conn)
|
|
||||||
case CommandServiceReload:
|
|
||||||
return s.handleServiceReload(conn)
|
|
||||||
case CommandCloseConnections:
|
|
||||||
return s.handleCloseConnections(conn)
|
|
||||||
default:
|
|
||||||
return E.New("unknown command: ", command)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,63 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"net"
|
|
||||||
"runtime"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/common/dialer/conntrack"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
)
|
|
||||||
|
|
||||||
type StatusMessage struct {
|
|
||||||
Memory int64
|
|
||||||
Goroutines int32
|
|
||||||
Connections int32
|
|
||||||
}
|
|
||||||
|
|
||||||
func readStatus() StatusMessage {
|
|
||||||
var memStats runtime.MemStats
|
|
||||||
runtime.ReadMemStats(&memStats)
|
|
||||||
var message StatusMessage
|
|
||||||
message.Memory = int64(memStats.StackInuse + memStats.HeapInuse + memStats.HeapIdle - memStats.HeapReleased)
|
|
||||||
message.Goroutines = int32(runtime.NumGoroutine())
|
|
||||||
message.Connections = int32(conntrack.Count())
|
|
||||||
return message
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) handleStatusConn(conn net.Conn) error {
|
|
||||||
var interval int64
|
|
||||||
err := binary.Read(conn, binary.BigEndian, &interval)
|
|
||||||
if err != nil {
|
|
||||||
return E.Cause(err, "read interval")
|
|
||||||
}
|
|
||||||
ticker := time.NewTicker(time.Duration(interval))
|
|
||||||
defer ticker.Stop()
|
|
||||||
ctx := connKeepAlive(conn)
|
|
||||||
for {
|
|
||||||
err = binary.Write(conn, binary.BigEndian, readStatus())
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
select {
|
|
||||||
case <-ctx.Done():
|
|
||||||
return nil
|
|
||||||
case <-ticker.C:
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *CommandClient) handleStatusConn(conn net.Conn) {
|
|
||||||
for {
|
|
||||||
var message StatusMessage
|
|
||||||
err := binary.Read(conn, binary.BigEndian, &message)
|
|
||||||
if err != nil {
|
|
||||||
c.handler.Disconnected(err.Error())
|
|
||||||
return
|
|
||||||
}
|
|
||||||
c.handler.WriteStatus(&message)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,50 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/binary"
|
|
||||||
"net"
|
|
||||||
"runtime/debug"
|
|
||||||
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
"github.com/sagernet/sing/common/rw"
|
|
||||||
)
|
|
||||||
|
|
||||||
func ClientServiceStop(sharedDirectory string) error {
|
|
||||||
conn, err := clientConnect(sharedDirectory)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
defer conn.Close()
|
|
||||||
err = binary.Write(conn, binary.BigEndian, uint8(CommandServiceStop))
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
var hasError bool
|
|
||||||
err = binary.Read(conn, binary.BigEndian, &hasError)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if hasError {
|
|
||||||
errorMessage, err := rw.ReadVString(conn)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
return E.New(errorMessage)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *CommandServer) handleServiceStop(conn net.Conn) error {
|
|
||||||
rErr := s.handler.ServiceStop()
|
|
||||||
err := binary.Write(conn, binary.BigEndian, rErr != nil)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if rErr != nil {
|
|
||||||
return rw.WriteVString(conn, rErr.Error())
|
|
||||||
}
|
|
||||||
debug.FreeOSMemory()
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"github.com/sagernet/sing-box/option"
|
|
||||||
E "github.com/sagernet/sing/common/exceptions"
|
|
||||||
)
|
|
||||||
|
|
||||||
func parseConfig(configContent string) (option.Options, error) {
|
|
||||||
var options option.Options
|
|
||||||
err := options.UnmarshalJSON([]byte(configContent))
|
|
||||||
if err != nil {
|
|
||||||
return option.Options{}, E.Cause(err, "decode config")
|
|
||||||
}
|
|
||||||
return options, nil
|
|
||||||
}
|
|
||||||
@@ -1,148 +0,0 @@
|
|||||||
package procfs
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bufio"
|
|
||||||
"encoding/binary"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"net"
|
|
||||||
"net/netip"
|
|
||||||
"os"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"unsafe"
|
|
||||||
|
|
||||||
N "github.com/sagernet/sing/common/network"
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
netIndexOfLocal = -1
|
|
||||||
netIndexOfUid = -1
|
|
||||||
nativeEndian binary.ByteOrder
|
|
||||||
)
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
var x uint32 = 0x01020304
|
|
||||||
if *(*byte)(unsafe.Pointer(&x)) == 0x01 {
|
|
||||||
nativeEndian = binary.BigEndian
|
|
||||||
} else {
|
|
||||||
nativeEndian = binary.LittleEndian
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func ResolveSocketByProcSearch(network string, source, _ netip.AddrPort) int32 {
|
|
||||||
if netIndexOfLocal < 0 || netIndexOfUid < 0 {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
path := "/proc/net/"
|
|
||||||
|
|
||||||
if network == N.NetworkTCP {
|
|
||||||
path += "tcp"
|
|
||||||
} else {
|
|
||||||
path += "udp"
|
|
||||||
}
|
|
||||||
|
|
||||||
if source.Addr().Is6() {
|
|
||||||
path += "6"
|
|
||||||
}
|
|
||||||
|
|
||||||
sIP := source.Addr().AsSlice()
|
|
||||||
if len(sIP) == 0 {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
var bytes [2]byte
|
|
||||||
binary.BigEndian.PutUint16(bytes[:], source.Port())
|
|
||||||
local := fmt.Sprintf("%s:%s", hex.EncodeToString(nativeEndianIP(sIP)), hex.EncodeToString(bytes[:]))
|
|
||||||
|
|
||||||
file, err := os.Open(path)
|
|
||||||
if err != nil {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
defer file.Close()
|
|
||||||
|
|
||||||
reader := bufio.NewReader(file)
|
|
||||||
|
|
||||||
for {
|
|
||||||
row, _, err := reader.ReadLine()
|
|
||||||
if err != nil {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
fields := strings.Fields(string(row))
|
|
||||||
|
|
||||||
if len(fields) <= netIndexOfLocal || len(fields) <= netIndexOfUid {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
if strings.EqualFold(local, fields[netIndexOfLocal]) {
|
|
||||||
uid, err := strconv.Atoi(fields[netIndexOfUid])
|
|
||||||
if err != nil {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
return int32(uid)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func nativeEndianIP(ip net.IP) []byte {
|
|
||||||
result := make([]byte, len(ip))
|
|
||||||
|
|
||||||
for i := 0; i < len(ip); i += 4 {
|
|
||||||
value := binary.BigEndian.Uint32(ip[i:])
|
|
||||||
|
|
||||||
nativeEndian.PutUint32(result[i:], value)
|
|
||||||
}
|
|
||||||
|
|
||||||
return result
|
|
||||||
}
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
file, err := os.Open("/proc/net/tcp")
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
defer file.Close()
|
|
||||||
|
|
||||||
reader := bufio.NewReader(file)
|
|
||||||
|
|
||||||
header, _, err := reader.ReadLine()
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
columns := strings.Fields(string(header))
|
|
||||||
|
|
||||||
var txQueue, rxQueue, tr, tmWhen bool
|
|
||||||
|
|
||||||
for idx, col := range columns {
|
|
||||||
offset := 0
|
|
||||||
|
|
||||||
if txQueue && rxQueue {
|
|
||||||
offset--
|
|
||||||
}
|
|
||||||
|
|
||||||
if tr && tmWhen {
|
|
||||||
offset--
|
|
||||||
}
|
|
||||||
|
|
||||||
switch col {
|
|
||||||
case "tx_queue":
|
|
||||||
txQueue = true
|
|
||||||
case "rx_queue":
|
|
||||||
rxQueue = true
|
|
||||||
case "tr":
|
|
||||||
tr = true
|
|
||||||
case "tm->when":
|
|
||||||
tmWhen = true
|
|
||||||
case "local_address":
|
|
||||||
netIndexOfLocal = idx + offset
|
|
||||||
case "uid":
|
|
||||||
netIndexOfUid = idx + offset
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
package libbox
|
|
||||||
|
|
||||||
import "github.com/sagernet/sing/common"
|
|
||||||
|
|
||||||
type StringIterator interface {
|
|
||||||
Next() string
|
|
||||||
HasNext() bool
|
|
||||||
}
|
|
||||||
|
|
||||||
var _ StringIterator = (*iterator[string])(nil)
|
|
||||||
|
|
||||||
type iterator[T any] struct {
|
|
||||||
values []T
|
|
||||||
}
|
|
||||||
|
|
||||||
func newIterator[T any](values []T) *iterator[T] {
|
|
||||||
return &iterator[T]{values}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (i *iterator[T]) Next() T {
|
|
||||||
if len(i.values) == 0 {
|
|
||||||
return common.DefaultValue[T]()
|
|
||||||
}
|
|
||||||
nextValue := i.values[0]
|
|
||||||
i.values = i.values[1:]
|
|
||||||
return nextValue
|
|
||||||
}
|
|
||||||
|
|
||||||
func (i *iterator[T]) HasNext() bool {
|
|
||||||
return len(i.values) > 0
|
|
||||||
}
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bufio"
|
|
||||||
"log"
|
|
||||||
"os"
|
|
||||||
)
|
|
||||||
|
|
||||||
type StandardOutput interface {
|
|
||||||
WriteOutput(message string)
|
|
||||||
WriteErrorOutput(message string)
|
|
||||||
}
|
|
||||||
|
|
||||||
func SetOutput(output StandardOutput) {
|
|
||||||
log.SetOutput(logWriter{output})
|
|
||||||
pipeIn, pipeOut, err := os.Pipe()
|
|
||||||
if err != nil {
|
|
||||||
panic(err)
|
|
||||||
}
|
|
||||||
os.Stdout = os.NewFile(pipeOut.Fd(), "stdout")
|
|
||||||
go lineLog(pipeIn, output.WriteOutput)
|
|
||||||
|
|
||||||
pipeIn, pipeOut, err = os.Pipe()
|
|
||||||
if err != nil {
|
|
||||||
panic(err)
|
|
||||||
}
|
|
||||||
os.Stderr = os.NewFile(pipeOut.Fd(), "srderr")
|
|
||||||
go lineLog(pipeIn, output.WriteErrorOutput)
|
|
||||||
}
|
|
||||||
|
|
||||||
type logWriter struct {
|
|
||||||
output StandardOutput
|
|
||||||
}
|
|
||||||
|
|
||||||
func (w logWriter) Write(p []byte) (n int, err error) {
|
|
||||||
w.output.WriteOutput(string(p))
|
|
||||||
return len(p), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func lineLog(f *os.File, output func(string)) {
|
|
||||||
const logSize = 1024 // matches android/log.h.
|
|
||||||
r := bufio.NewReaderSize(f, logSize)
|
|
||||||
for {
|
|
||||||
line, _, err := r.ReadLine()
|
|
||||||
str := string(line)
|
|
||||||
if err != nil {
|
|
||||||
str += " " + err.Error()
|
|
||||||
}
|
|
||||||
output(str)
|
|
||||||
if err != nil {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
package libbox
|
|
||||||
|
|
||||||
import "runtime/debug"
|
|
||||||
|
|
||||||
func SetMemoryLimit() {
|
|
||||||
debug.SetGCPercent(10)
|
|
||||||
debug.SetMemoryLimit(30 * 1024 * 1024)
|
|
||||||
}
|
|
||||||
@@ -1,66 +0,0 @@
|
|||||||
package libbox
|
|
||||||
|
|
||||||
import "github.com/sagernet/sing-box/option"
|
|
||||||
|
|
||||||
type PlatformInterface interface {
|
|
||||||
AutoDetectInterfaceControl(fd int32) error
|
|
||||||
OpenTun(options TunOptions) (int32, error)
|
|
||||||
WriteLog(message string)
|
|
||||||
UseProcFS() bool
|
|
||||||
FindConnectionOwner(ipProtocol int32, sourceAddress string, sourcePort int32, destinationAddress string, destinationPort int32) (int32, error)
|
|
||||||
PackageNameByUid(uid int32) (string, error)
|
|
||||||
UIDByPackageName(packageName string) (int32, error)
|
|
||||||
}
|
|
||||||
|
|
||||||
type TunInterface interface {
|
|
||||||
FileDescriptor() int32
|
|
||||||
Close() error
|
|
||||||
}
|
|
||||||
|
|
||||||
type OnDemandRuleIterator interface {
|
|
||||||
Next() OnDemandRule
|
|
||||||
HasNext() bool
|
|
||||||
}
|
|
||||||
|
|
||||||
type OnDemandRule interface {
|
|
||||||
Target() int32
|
|
||||||
DNSSearchDomainMatch() StringIterator
|
|
||||||
DNSServerAddressMatch() StringIterator
|
|
||||||
InterfaceTypeMatch() int32
|
|
||||||
SSIDMatch() StringIterator
|
|
||||||
ProbeURL() string
|
|
||||||
}
|
|
||||||
|
|
||||||
type onDemandRule struct {
|
|
||||||
option.OnDemandRule
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *onDemandRule) Target() int32 {
|
|
||||||
if r.OnDemandRule.Action == nil {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
return int32(*r.OnDemandRule.Action)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *onDemandRule) DNSSearchDomainMatch() StringIterator {
|
|
||||||
return newIterator(r.OnDemandRule.DNSSearchDomainMatch)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *onDemandRule) DNSServerAddressMatch() StringIterator {
|
|
||||||
return newIterator(r.OnDemandRule.DNSServerAddressMatch)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *onDemandRule) InterfaceTypeMatch() int32 {
|
|
||||||
if r.OnDemandRule.InterfaceTypeMatch == nil {
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
return int32(*r.OnDemandRule.InterfaceTypeMatch)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *onDemandRule) SSIDMatch() StringIterator {
|
|
||||||
return newIterator(r.OnDemandRule.SSIDMatch)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r *onDemandRule) ProbeURL() string {
|
|
||||||
return r.OnDemandRule.ProbeURL
|
|
||||||
}
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
package platform
|
|
||||||
|
|
||||||
import (
|
|
||||||
"io"
|
|
||||||
|
|
||||||
"github.com/sagernet/sing-box/common/process"
|
|
||||||
"github.com/sagernet/sing-box/option"
|
|
||||||
"github.com/sagernet/sing-tun"
|
|
||||||
"github.com/sagernet/sing/common/control"
|
|
||||||
)
|
|
||||||
|
|
||||||
type Interface interface {
|
|
||||||
AutoDetectInterfaceControl() control.Func
|
|
||||||
OpenTun(options tun.Options, platformOptions option.TunPlatformOptions) (tun.Tun, error)
|
|
||||||
process.Searcher
|
|
||||||
io.Writer
|
|
||||||
}
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
//go:build debug
|
|
||||||
|
|
||||||
package libbox
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net"
|
|
||||||
"net/http"
|
|
||||||
_ "net/http/pprof"
|
|
||||||
"strconv"
|
|
||||||
)
|
|
||||||
|
|
||||||
type PProfServer struct {
|
|
||||||
server *http.Server
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewPProfServer(port int) *PProfServer {
|
|
||||||
return &PProfServer{
|
|
||||||
&http.Server{
|
|
||||||
Addr: ":" + strconv.Itoa(port),
|
|
||||||
},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *PProfServer) Start() error {
|
|
||||||
ln, err := net.Listen("tcp", s.server.Addr)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
go s.server.Serve(ln)
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *PProfServer) Close() error {
|
|
||||||
return s.server.Close()
|
|
||||||
}
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user