mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-10-03 04:32:08 +03:00
feat(xray): update xray-core to v26.9.30 and adapt panel
Bump xtls/xray-core to b26a91de4f (v26.9.30) and the three binary pins (DockerInit.sh, release.yml Linux + Windows) in lockstep. No deleted symbols; the sing and sing-shadowsocks indirect deps drop out with the SS2022 rewrite. XDNS finalmask (#6718) replaced its string lists with objects: domains are {name, types, edns0, lenLimit, labelLimit} and client resolvers {type, settings.addr}. The loader no longer parses the old lists, so a single stored xdns mask keeps the whole core from starting. The new leaf package internal/util/maskcompat converts them: "name[:type]" becomes a domain and "name[:type]+udp://addr" a domain plus a udp resolver. A bare name maps to TXT, the type legacy clients queried by default, and each converted domain keeps the 1232-byte EDNS0 the old code always used (without it the server caps answers at 512). It runs from: - the XdnsFinalmaskObjectsFix seeder, over inbound streams, hosts, the xray template, the global sub-JSON mask and cached subscription outbounds; - inbound save (normalizeStreamSettings) and GetXrayConfig, for rows that never went through the seeder; - both link importers, since fm= from an older panel carries the lists. The finalmask form edits the object shape (every key needs a registered field, or the finalmask watch drops it on save) and lifts legacy masks on open. The udp-mask golden fixture moves to the object shape, which TestGoldenStreamFixturesBuildInXray now builds through the core. The wire format changed as well, so pre-upgrade clients need the new core. WireGuard outbound (#6771) dropped settings.domainStrategy and the remoteDNS "local" mode. The endpoint lookup now follows sockopt.domainStrategy and in-tunnel targets the outbound's targetStrategy. The old key is silently ignored, which undid the IPv4-first endpoint lookup the WARP outbound depends on (#5205), and "local" now panics the core at startup because remoteDNS goes through netip.MustParseAddr. The WireguardDomainStrategyFix seeder moves a stored family preference to both keys (a value already set wins) and turns "local" into targetStrategy; the outbound form lifts legacy rows the same way and drops its select, the WARP modal writes the new placement, and the inbound form loses a field the server never read. ValidateOutboundConfig now refuses a non-IP remoteDNS entry, which conf.Build() lets through, on template save and for outbound subscriptions. Noise finalmask items accept type "exp" (#6862), a tag expression. The form offers it for noise items only: header-custom items go through the core's PraseByteSlice, which refuses it. TUN gained autoSystemDnsToGateway (Linux) and autoSystemWfpBlockLeak (Windows). Both pass through the settings schema so a value set in JSON survives the next form save. MASQUE (inbound, outbound, transport) and the XDRIVE transport are new protocols the panel does not offer yet; their new loader refusals only cover configs the panel never generates. The FakeDNS IPv6 pool default, the SS2022 rewrite (same gRPC account; emails are now deduped case-insensitively, as the panel already does), the restored udphop interval default and the rest change no panel-facing config.
This commit is contained in:
@@ -115,7 +115,7 @@ jobs:
|
||||
cd x-ui/bin
|
||||
|
||||
# Download dependencies
|
||||
Xray_URL="https://github.com/XTLS/Xray-core/releases/download/v26.9.9/"
|
||||
Xray_URL="https://github.com/XTLS/Xray-core/releases/download/v26.9.30/"
|
||||
if [ "${{ matrix.platform }}" == "amd64" ]; then
|
||||
fetch ${Xray_URL}Xray-linux-64.zip
|
||||
unzip Xray-linux-64.zip
|
||||
@@ -300,7 +300,7 @@ jobs:
|
||||
cd x-ui\bin
|
||||
|
||||
# Download Xray for Windows
|
||||
$Xray_URL = "https://github.com/XTLS/Xray-core/releases/download/v26.9.9/"
|
||||
$Xray_URL = "https://github.com/XTLS/Xray-core/releases/download/v26.9.30/"
|
||||
Invoke-WebRequest @retry -Uri "${Xray_URL}Xray-windows-64.zip" -OutFile "Xray-windows-64.zip"
|
||||
Expand-Archive -Path "Xray-windows-64.zip" -DestinationPath .
|
||||
Remove-Item "Xray-windows-64.zip"
|
||||
|
||||
+1
-1
@@ -33,7 +33,7 @@ if [ -z "$MTG_MULTI_VER" ]; then
|
||||
fi
|
||||
mkdir -p build/bin
|
||||
cd build/bin
|
||||
curl -sfLRO "https://github.com/XTLS/Xray-core/releases/download/v26.9.9/Xray-linux-${ARCH}.zip"
|
||||
curl -sfLRO "https://github.com/XTLS/Xray-core/releases/download/v26.9.30/Xray-linux-${ARCH}.zip"
|
||||
unzip "Xray-linux-${ARCH}.zip"
|
||||
rm -f "Xray-linux-${ARCH}.zip" geoip.dat geosite.dat
|
||||
mv xray "xray-linux-${FNAME}"
|
||||
|
||||
@@ -18,6 +18,7 @@ import type { NamePath } from 'antd/es/form/interface';
|
||||
import { RandomUtil } from '@/utils';
|
||||
import { activateOnKey } from '@/utils/a11y';
|
||||
import { OutboundProtocols, UTLS_FINGERPRINT } from '@/schemas/primitives';
|
||||
import { upgradeLegacyXdnsMasks, XDNS_LEGACY_EDNS0 } from '@/lib/xray/xdns-mask';
|
||||
|
||||
const UTLS_FINGERPRINT_OPTIONS = Object.values(UTLS_FINGERPRINT).map((value) => ({
|
||||
value,
|
||||
@@ -244,28 +245,34 @@ export default function FinalMaskForm({
|
||||
}: FinalMaskFormProps) {
|
||||
const base = asPath(name);
|
||||
|
||||
// Migrate legacy TCP mask shapes once on mount so configs saved before
|
||||
// #6334 (fragment ranges) and #6487 (xmc profiles) render in the list UI.
|
||||
// Migrate legacy mask shapes once on mount so configs saved before #6334 (fragment
|
||||
// ranges), #6487 (xmc profiles) and #6718 (xdns objects) render in the list UI.
|
||||
const migratedRef = useRef(false);
|
||||
useEffect(() => {
|
||||
if (migratedRef.current) return;
|
||||
migratedRef.current = true;
|
||||
const tcp = form.getFieldValue([...base, 'tcp']);
|
||||
if (!Array.isArray(tcp)) return;
|
||||
let anyChanged = false;
|
||||
const next = tcp.map((mask) => {
|
||||
if (!mask || typeof mask !== 'object') return mask;
|
||||
const m = mask as Record<string, unknown>;
|
||||
if (m.type !== 'fragment' && m.type !== 'xmc') return mask;
|
||||
if (!m.settings || typeof m.settings !== 'object') return mask;
|
||||
const settings = m.settings as Record<string, unknown>;
|
||||
const { next: migrated, changed } =
|
||||
m.type === 'fragment' ? migrateFragmentSettings(settings) : migrateXmcSettings(settings);
|
||||
if (!changed) return mask;
|
||||
anyChanged = true;
|
||||
return { ...m, settings: migrated };
|
||||
});
|
||||
if (anyChanged) form.setFieldValue([...base, 'tcp'], next);
|
||||
if (Array.isArray(tcp)) {
|
||||
let anyChanged = false;
|
||||
const next = tcp.map((mask) => {
|
||||
if (!mask || typeof mask !== 'object') return mask;
|
||||
const m = mask as Record<string, unknown>;
|
||||
if (m.type !== 'fragment' && m.type !== 'xmc') return mask;
|
||||
if (!m.settings || typeof m.settings !== 'object') return mask;
|
||||
const settings = m.settings as Record<string, unknown>;
|
||||
const { next: migrated, changed } =
|
||||
m.type === 'fragment' ? migrateFragmentSettings(settings) : migrateXmcSettings(settings);
|
||||
if (!changed) return mask;
|
||||
anyChanged = true;
|
||||
return { ...m, settings: migrated };
|
||||
});
|
||||
if (anyChanged) form.setFieldValue([...base, 'tcp'], next);
|
||||
}
|
||||
const udp = form.getFieldValue([...base, 'udp']);
|
||||
if (Array.isArray(udp)) {
|
||||
const { next, changed } = upgradeLegacyXdnsMasks(udp);
|
||||
if (changed) form.setFieldValue([...base, 'udp'], next);
|
||||
}
|
||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||
}, []);
|
||||
|
||||
@@ -958,11 +965,7 @@ function UdpMaskItem({
|
||||
);
|
||||
}
|
||||
if (type === 'xdns') {
|
||||
return (
|
||||
<Form.Item label="Domains" name={[fieldName, 'settings', 'domains']}>
|
||||
<Select mode="tags" style={{ width: '100%' }} tokenSeparators={[',']} />
|
||||
</Form.Item>
|
||||
);
|
||||
return <XdnsSettings udpFieldName={fieldName} />;
|
||||
}
|
||||
if (type === 'xicmp') {
|
||||
return (
|
||||
@@ -1255,6 +1258,113 @@ function UdpHeaderCustom({
|
||||
);
|
||||
}
|
||||
|
||||
const XDNS_RECORD_TYPE_OPTIONS = [
|
||||
{ value: 16, label: 'TXT' },
|
||||
{ value: 1, label: 'A' },
|
||||
{ value: 28, label: 'AAAA' },
|
||||
{ value: 5, label: 'CNAME' },
|
||||
];
|
||||
|
||||
// Every xdns key needs a registered field: the finalmask watch drops keys without one.
|
||||
// Resolvers and extraPoll are read by clients only; a server keeps them for the share link.
|
||||
function XdnsSettings({ udpFieldName }: { udpFieldName: number }) {
|
||||
const { t } = useTranslation();
|
||||
return (
|
||||
<>
|
||||
<Form.List name={[udpFieldName, 'settings', 'domains']}>
|
||||
{(domains, { add, remove }) => (
|
||||
<>
|
||||
<Form.Item label="Domains">
|
||||
<Button
|
||||
type="primary"
|
||||
size="small"
|
||||
icon={<PlusOutlined />}
|
||||
aria-label={t('add')}
|
||||
onClick={() => add({ name: '', types: [16], edns0: XDNS_LEGACY_EDNS0 })}
|
||||
/>
|
||||
</Form.Item>
|
||||
{domains.map((domain, di) => (
|
||||
<div key={domain.key}>
|
||||
<Divider style={{ margin: 0 }}>
|
||||
Domain {di + 1}
|
||||
<DeleteOutlined
|
||||
className="danger-icon"
|
||||
role="button"
|
||||
tabIndex={0}
|
||||
aria-label={t('remove')}
|
||||
onClick={() => remove(domain.name)}
|
||||
onKeyDown={activateOnKey(() => remove(domain.name))}
|
||||
/>
|
||||
</Divider>
|
||||
<Form.Item label="Name" name={[domain.name, 'name']}>
|
||||
<Input placeholder="t.example.com" />
|
||||
</Form.Item>
|
||||
<Form.Item
|
||||
label="Record Types"
|
||||
name={[domain.name, 'types']}
|
||||
rules={[{ required: true, type: 'array', min: 1 }]}
|
||||
>
|
||||
<Select mode="multiple" options={XDNS_RECORD_TYPE_OPTIONS} />
|
||||
</Form.Item>
|
||||
<Form.Item label="EDNS0" name={[domain.name, 'edns0']}>
|
||||
<InputNumber min={512} max={4096} placeholder="off" />
|
||||
</Form.Item>
|
||||
<Form.Item label="Length Limit" name={[domain.name, 'lenLimit']}>
|
||||
<InputNumber min={0} max={255} placeholder="255" />
|
||||
</Form.Item>
|
||||
<Form.Item label="Label Limit" name={[domain.name, 'labelLimit']}>
|
||||
<InputNumber min={0} max={63} placeholder="63" />
|
||||
</Form.Item>
|
||||
</div>
|
||||
))}
|
||||
</>
|
||||
)}
|
||||
</Form.List>
|
||||
<Form.List name={[udpFieldName, 'settings', 'resolvers']}>
|
||||
{(resolvers, { add, remove }) => (
|
||||
<>
|
||||
<Form.Item label="Resolvers (client)">
|
||||
<Button
|
||||
type="primary"
|
||||
size="small"
|
||||
icon={<PlusOutlined />}
|
||||
aria-label={t('add')}
|
||||
onClick={() => add({ type: 'udp', settings: { addr: '' } })}
|
||||
/>
|
||||
</Form.Item>
|
||||
{resolvers.map((resolver, ri) => (
|
||||
<Form.Item key={resolver.key} label={`Resolver ${ri + 1}`}>
|
||||
<Space.Compact block>
|
||||
<Form.Item name={[resolver.name, 'type']} noStyle>
|
||||
<Select
|
||||
style={{ width: 80 }}
|
||||
options={[
|
||||
{ value: 'udp', label: 'UDP' },
|
||||
{ value: 'tcp', label: 'TCP' },
|
||||
]}
|
||||
/>
|
||||
</Form.Item>
|
||||
<Form.Item name={[resolver.name, 'settings', 'addr']} noStyle>
|
||||
<Input placeholder="8.8.8.8:53" />
|
||||
</Form.Item>
|
||||
<Button
|
||||
icon={<DeleteOutlined />}
|
||||
aria-label={t('remove')}
|
||||
onClick={() => remove(resolver.name)}
|
||||
/>
|
||||
</Space.Compact>
|
||||
</Form.Item>
|
||||
))}
|
||||
</>
|
||||
)}
|
||||
</Form.List>
|
||||
<Form.Item label="Extra Poll (client)" name={[udpFieldName, 'settings', 'extraPoll']}>
|
||||
<InputNumber min={0} max={3} placeholder="0" />
|
||||
</Form.Item>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
function NoiseItems({
|
||||
udpFieldName,
|
||||
form,
|
||||
@@ -1352,6 +1462,8 @@ function ItemEditor({
|
||||
{ value: 'str', label: 'String' },
|
||||
{ value: 'hex', label: 'Hex' },
|
||||
{ value: 'base64', label: 'Base64' },
|
||||
// Only the noise mask parses tag expressions (xray-core 26.9.30, #6862).
|
||||
...(delayMode === 'string' ? [{ value: 'exp', label: 'Expression' }] : []),
|
||||
]}
|
||||
/>
|
||||
</Form.Item>
|
||||
@@ -1420,7 +1532,7 @@ function ItemEditor({
|
||||
}
|
||||
return (
|
||||
<Form.Item label="Packet" name={[fieldName, 'packet']}>
|
||||
<Input placeholder="binary data" />
|
||||
<Input placeholder={type === 'exp' ? '<b 0d0a0d0a><t><rc 20-40>' : 'binary data'} />
|
||||
</Form.Item>
|
||||
);
|
||||
}}
|
||||
|
||||
@@ -18,7 +18,10 @@ import {
|
||||
import type { StreamSettings } from '@/schemas/api/inbound';
|
||||
import type { Sniffing } from '@/schemas/primitives';
|
||||
import type { z } from 'zod';
|
||||
import { normalizeStreamSettingsForWire } from '@/lib/xray/stream-wire-normalize';
|
||||
import {
|
||||
dropEmptyFinalMask,
|
||||
normalizeStreamSettingsForWire,
|
||||
} from '@/lib/xray/stream-wire-normalize';
|
||||
import { canEnableSniffing } from '@/lib/xray/protocol-capabilities';
|
||||
import { tlsCertUsesFiles } from '@/schemas/protocols/security/tls';
|
||||
import { SockoptStreamSettingsSchema } from '@/schemas/protocols/stream/sockopt';
|
||||
@@ -322,25 +325,7 @@ export function dropLegacyOptionalEmpties(
|
||||
if (Array.isArray(fb) && fb.length === 0) delete settings.fallbacks;
|
||||
|
||||
if (stream) {
|
||||
// StreamSettings emits `finalmask` only when at least one transport
|
||||
// mask exists (legacy `hasFinalMask`). Drop the whole block when all
|
||||
// sub-fields are empty; otherwise drop only the empty sub-arrays so
|
||||
// the wire payload doesn't carry a stray `"tcp": []` next to a
|
||||
// populated UDP mask list (and vice versa).
|
||||
const fm = stream.finalmask as
|
||||
| { tcp?: unknown[]; udp?: unknown[]; quicParams?: unknown }
|
||||
| undefined;
|
||||
if (fm && typeof fm === 'object') {
|
||||
const hasTcp = Array.isArray(fm.tcp) && fm.tcp.length > 0;
|
||||
const hasUdp = Array.isArray(fm.udp) && fm.udp.length > 0;
|
||||
const hasQuic = fm.quicParams != null;
|
||||
if (!hasTcp && !hasUdp && !hasQuic) {
|
||||
delete stream.finalmask;
|
||||
} else {
|
||||
if (!hasTcp) delete fm.tcp;
|
||||
if (!hasUdp) delete fm.udp;
|
||||
}
|
||||
}
|
||||
dropEmptyFinalMask(stream);
|
||||
|
||||
// Hysteria's per-client auth lives in settings.clients[*].auth; the
|
||||
// streamSettings.hysteriaSettings.auth slot is a holdover from older
|
||||
|
||||
@@ -1,7 +1,10 @@
|
||||
import { XHttpXmuxSchema } from '@/schemas/protocols/stream/xhttp';
|
||||
import { OutboundDomainStrategySchema } from '@/schemas/protocols/outbound';
|
||||
import { AmneziaWGOutboundSettingsSchema } from '@/schemas/protocols/outbound';
|
||||
import { normalizeStreamSettingsForWire } from '@/lib/xray/stream-wire-normalize';
|
||||
import {
|
||||
dropEmptyFinalMask,
|
||||
normalizeStreamSettingsForWire,
|
||||
} from '@/lib/xray/stream-wire-normalize';
|
||||
import { Wireguard } from '@/utils';
|
||||
import type { Sniffing, SniffingDest } from '@/schemas/primitives';
|
||||
import type { OutboundDomainStrategy } from '@/schemas/protocols/outbound';
|
||||
@@ -258,20 +261,50 @@ function wireguardFromWire(raw: Raw): WireguardOutboundFormSettings {
|
||||
secretKey,
|
||||
pubKey,
|
||||
address: addressArr.join(','),
|
||||
domainStrategy: ((): WireguardOutboundFormSettings['domainStrategy'] => {
|
||||
const allowed = ['ForceIP', 'ForceIPv4', 'ForceIPv4v6', 'ForceIPv6', 'ForceIPv6v4'];
|
||||
const s = asString(raw.domainStrategy);
|
||||
return (allowed.includes(s) ? s : '') as WireguardOutboundFormSettings['domainStrategy'];
|
||||
})(),
|
||||
reserved: reservedArr.join(','),
|
||||
remoteDNS: asArray(raw.remoteDNS)
|
||||
.map((x) => asString(x))
|
||||
.join(','),
|
||||
remoteDNS: isLegacyLocalRemoteDNS(raw.remoteDNS)
|
||||
? ''
|
||||
: asArray(raw.remoteDNS)
|
||||
.map((x) => asString(x))
|
||||
.join(','),
|
||||
peers,
|
||||
noKernelTun: asBool(raw.noKernelTun),
|
||||
};
|
||||
}
|
||||
|
||||
// remoteDNS ["local"] is a mode xray-core 26.9.30 removed; the core now panics parsing
|
||||
// it as an address, so liftLegacyWireguardStrategy carries it over to targetStrategy.
|
||||
function isLegacyLocalRemoteDNS(value: unknown): boolean {
|
||||
const list = asArray(value);
|
||||
return list.length === 1 && list[0] === 'local';
|
||||
}
|
||||
|
||||
const isAsIs = (strategy: OutboundDomainStrategy | '') => strategy === '' || strategy === 'AsIs';
|
||||
|
||||
// xray-core 26.9.30 (#6771) ignores wireguard's settings.domainStrategy: sockopt.domainStrategy
|
||||
// now picks the endpoint's family, targetStrategy the targets'. Mirrors the Go seeder.
|
||||
function liftLegacyWireguardStrategy(
|
||||
settings: Raw,
|
||||
targetStrategy: OutboundDomainStrategy | '',
|
||||
streamSettings: OutboundStreamFormValues | undefined,
|
||||
): { targetStrategy: OutboundDomainStrategy | ''; streamSettings?: OutboundStreamFormValues } {
|
||||
const legacy = targetStrategyFromWire(settings.domainStrategy);
|
||||
const family = legacy.startsWith('ForceIP') && legacy !== 'ForceIP' ? legacy : '';
|
||||
const lifted = family || (isLegacyLocalRemoteDNS(settings.remoteDNS) ? 'ForceIP' : '');
|
||||
let stream = streamSettings;
|
||||
const sockopt = asObject((stream as Raw | undefined)?.sockopt);
|
||||
if (family && isAsIs(targetStrategyFromWire(sockopt.domainStrategy))) {
|
||||
stream = {
|
||||
...(stream ?? {}),
|
||||
sockopt: { ...sockopt, domainStrategy: family },
|
||||
} as OutboundStreamFormValues;
|
||||
}
|
||||
return {
|
||||
targetStrategy: lifted && isAsIs(targetStrategy) ? lifted : targetStrategy,
|
||||
streamSettings: stream,
|
||||
};
|
||||
}
|
||||
|
||||
function hysteriaFromWire(raw: Raw): HysteriaOutboundFormSettings {
|
||||
return {
|
||||
address: asString(raw.address),
|
||||
@@ -604,15 +637,20 @@ export function rawOutboundToFormValues(raw: RawOutboundRow): OutboundFormValues
|
||||
typed = { protocol: 'vless', settings: vlessFromWire(settings) };
|
||||
}
|
||||
|
||||
const placed =
|
||||
protocol === 'wireguard'
|
||||
? liftLegacyWireguardStrategy(settings, targetStrategy, streamSettings)
|
||||
: { targetStrategy, streamSettings };
|
||||
|
||||
return {
|
||||
...typed,
|
||||
tag,
|
||||
sendThrough,
|
||||
// The freedom card owns the strategy for freedom, so the shared root field
|
||||
// stays empty and cannot disagree with what the card is showing.
|
||||
targetStrategy: protocol === 'freedom' ? '' : targetStrategy,
|
||||
targetStrategy: protocol === 'freedom' ? '' : placed.targetStrategy,
|
||||
mux,
|
||||
streamSettings,
|
||||
streamSettings: placed.streamSettings,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -715,7 +753,6 @@ function wireguardToWire(s: WireguardOutboundFormSettings) {
|
||||
.map((x) => x.trim())
|
||||
.filter(Boolean)
|
||||
: [],
|
||||
domainStrategy: s.domainStrategy || undefined,
|
||||
reserved: s.reserved
|
||||
? s.reserved
|
||||
.split(',')
|
||||
@@ -912,14 +949,23 @@ export function formValuesToWirePayload(values: OutboundFormValues): WireOutboun
|
||||
result.targetStrategy = values.targetStrategy;
|
||||
}
|
||||
|
||||
// streamSettings emission gates on canEnableStream — non-stream protocols
|
||||
// still emit just `sockopt` if that key is present (legacy behavior).
|
||||
// Non-stream protocols emit only `sockopt`; wireguard also keeps `finalmask`, which the
|
||||
// core dials its peer through (the one non-stream protocol the mask editor renders for).
|
||||
if (values.streamSettings) {
|
||||
if (STREAM_PROTOCOLS.has(values.protocol)) {
|
||||
result.streamSettings = stripUiOnlyStreamFields(values.streamSettings);
|
||||
} else {
|
||||
const sockopt = (values.streamSettings as { sockopt?: unknown }).sockopt;
|
||||
if (sockopt) result.streamSettings = { sockopt };
|
||||
const { sockopt, finalmask } = values.streamSettings as {
|
||||
sockopt?: unknown;
|
||||
finalmask?: unknown;
|
||||
};
|
||||
const stream: Raw = {};
|
||||
if (sockopt) stream.sockopt = sockopt;
|
||||
if (values.protocol === 'wireguard' && finalmask && typeof finalmask === 'object') {
|
||||
stream.finalmask = { ...(finalmask as Raw) };
|
||||
dropEmptyFinalMask(stream);
|
||||
}
|
||||
if (Object.keys(stream).length > 0) result.streamSettings = stream;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
import { Base64 } from '@/utils';
|
||||
|
||||
import { upgradeLegacyXdnsMasks } from './xdns-mask';
|
||||
|
||||
// Focused share-link parser for the OutboundFormModal's link-import
|
||||
// helper. Each parser returns a wire-shape outbound record (the same
|
||||
// shape OutboundsTab.tsx stores in templateSettings.outbounds[]) or
|
||||
@@ -279,6 +281,7 @@ function applyFinalMaskParam(stream: Raw, params: URLSearchParams): void {
|
||||
const parsed = JSON.parse(fm) as Record<string, unknown>;
|
||||
if (parsed && typeof parsed === 'object') {
|
||||
sanitizeFinalMaskQuicParams(parsed);
|
||||
if (Array.isArray(parsed.udp)) parsed.udp = upgradeLegacyXdnsMasks(parsed.udp).next;
|
||||
stream.finalmask = parsed;
|
||||
}
|
||||
} catch {
|
||||
|
||||
@@ -323,6 +323,21 @@ export function normalizeSockoptForWire(
|
||||
return out;
|
||||
}
|
||||
|
||||
// Emit `finalmask` only when a mask exists (legacy `hasFinalMask`), and drop an empty
|
||||
// sub-array beside a populated one so the payload carries no stray `"tcp": []`.
|
||||
export function dropEmptyFinalMask(stream: Record<string, unknown>): void {
|
||||
const fm = stream.finalmask as { tcp?: unknown[]; udp?: unknown[]; quicParams?: unknown };
|
||||
if (!fm || typeof fm !== 'object') return;
|
||||
const hasTcp = Array.isArray(fm.tcp) && fm.tcp.length > 0;
|
||||
const hasUdp = Array.isArray(fm.udp) && fm.udp.length > 0;
|
||||
if (!hasTcp && !hasUdp && fm.quicParams == null) {
|
||||
delete stream.finalmask;
|
||||
return;
|
||||
}
|
||||
if (!hasTcp) delete fm.tcp;
|
||||
if (!hasUdp) delete fm.udp;
|
||||
}
|
||||
|
||||
export function normalizeStreamSettingsForWire(
|
||||
stream: Record<string, unknown>,
|
||||
opts: { side: StreamWireSide },
|
||||
|
||||
@@ -0,0 +1,81 @@
|
||||
type Raw = Record<string, unknown>;
|
||||
|
||||
/** The EDNS0 payload the pre-26.9.30 xdns always negotiated; without it answers cap at 512. */
|
||||
export const XDNS_LEGACY_EDNS0 = 1232;
|
||||
|
||||
const LEGACY_RECORD_TYPES: Record<string, number> = { '': 16, txt: 16, a: 1, aaaa: 28 };
|
||||
|
||||
function legacyDomain(spec: string): Raw | null {
|
||||
let name = spec.trim();
|
||||
let method = '';
|
||||
const colon = name.lastIndexOf(':');
|
||||
if (colon >= 0) {
|
||||
method = name.slice(colon + 1).toLowerCase();
|
||||
name = name.slice(0, colon);
|
||||
}
|
||||
name = name.replace(/^\.+|\.+$/g, '');
|
||||
const type = LEGACY_RECORD_TYPES[method];
|
||||
if (!name || type === undefined) return null;
|
||||
return { name, types: [type], edns0: XDNS_LEGACY_EDNS0 };
|
||||
}
|
||||
|
||||
// xray-core 26.9.30 (#6718) parses xdns domains/resolvers only as objects. Mirrors
|
||||
// internal/util/maskcompat: a bare name becomes TXT, entries the old core refused are dropped.
|
||||
export function upgradeLegacyXdnsSettings(settings: Raw): { next: Raw; changed: boolean } {
|
||||
const rawDomains = Array.isArray(settings.domains) ? (settings.domains as unknown[]) : [];
|
||||
const rawResolvers = Array.isArray(settings.resolvers) ? (settings.resolvers as unknown[]) : [];
|
||||
const isLegacy = (v: unknown) => typeof v === 'string';
|
||||
if (!rawDomains.some(isLegacy) && !rawResolvers.some(isLegacy)) {
|
||||
return { next: settings, changed: false };
|
||||
}
|
||||
const domains: unknown[] = [];
|
||||
const listed = new Set<string>();
|
||||
const addDomain = (domain: Raw) => {
|
||||
const key = String(domain.name ?? '').toLowerCase();
|
||||
if (key && listed.has(key)) return;
|
||||
listed.add(key);
|
||||
domains.push(domain);
|
||||
};
|
||||
for (const entry of rawDomains) {
|
||||
if (typeof entry === 'string') {
|
||||
const domain = legacyDomain(entry);
|
||||
if (domain) addDomain(domain);
|
||||
} else if (entry && typeof entry === 'object') {
|
||||
addDomain(entry as Raw);
|
||||
}
|
||||
}
|
||||
const resolvers: unknown[] = [];
|
||||
for (const entry of rawResolvers) {
|
||||
if (typeof entry !== 'string') {
|
||||
resolvers.push(entry);
|
||||
continue;
|
||||
}
|
||||
const sep = entry.indexOf('+udp://');
|
||||
const addr = sep >= 0 ? entry.slice(sep + '+udp://'.length).trim() : '';
|
||||
const domain = sep >= 0 ? legacyDomain(entry.slice(0, sep)) : null;
|
||||
if (!addr || !domain) continue;
|
||||
addDomain(domain);
|
||||
resolvers.push({ type: 'udp', settings: { addr } });
|
||||
}
|
||||
const next: Raw = { ...settings, domains };
|
||||
if (resolvers.length > 0) next.resolvers = resolvers;
|
||||
else delete next.resolvers;
|
||||
return { next, changed: true };
|
||||
}
|
||||
|
||||
/** Applies upgradeLegacyXdnsSettings to every xdns entry of a finalmask.udp list. */
|
||||
export function upgradeLegacyXdnsMasks(udp: unknown[]): { next: unknown[]; changed: boolean } {
|
||||
let changed = false;
|
||||
const next = udp.map((entry) => {
|
||||
const mask = entry as Raw | null;
|
||||
if (!mask || typeof mask !== 'object' || String(mask.type).toLowerCase() !== 'xdns') {
|
||||
return entry;
|
||||
}
|
||||
if (!mask.settings || typeof mask.settings !== 'object') return entry;
|
||||
const upgraded = upgradeLegacyXdnsSettings(mask.settings as Raw);
|
||||
if (!upgraded.changed) return entry;
|
||||
changed = true;
|
||||
return { ...mask, settings: upgraded.next };
|
||||
});
|
||||
return { next, changed };
|
||||
}
|
||||
@@ -1,5 +1,5 @@
|
||||
import { useTranslation } from 'react-i18next';
|
||||
import { Button, Form, Input, InputNumber, Select, Space, Switch } from 'antd';
|
||||
import { Button, Form, Input, InputNumber, Space, Switch } from 'antd';
|
||||
import { ReloadOutlined } from '@ant-design/icons';
|
||||
|
||||
import { FormField } from '@/components/form/rhf';
|
||||
@@ -43,21 +43,6 @@ export default function WireguardFields({ wgPubKey, regenInboundWg }: WireguardF
|
||||
>
|
||||
<Switch />
|
||||
</FormField>
|
||||
<FormField
|
||||
name={['settings', 'domainStrategy']}
|
||||
label={t('pages.xray.wireguard.domainStrategy')}
|
||||
>
|
||||
<Select
|
||||
allowClear
|
||||
options={[
|
||||
{ value: 'ForceIP', label: 'ForceIP' },
|
||||
{ value: 'ForceIPv4', label: 'ForceIPv4' },
|
||||
{ value: 'ForceIPv4v6', label: 'ForceIPv4v6' },
|
||||
{ value: 'ForceIPv6', label: 'ForceIPv6' },
|
||||
{ value: 'ForceIPv6v4', label: 'ForceIPv6v4' },
|
||||
]}
|
||||
/>
|
||||
</FormField>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
import { useTranslation } from 'react-i18next';
|
||||
import { Button, Form, Input, InputNumber, Select, Space, Switch } from 'antd';
|
||||
import { Button, Form, Input, InputNumber, Space, Switch } from 'antd';
|
||||
import { DeleteOutlined, MinusOutlined, PlusOutlined, ReloadOutlined } from '@ant-design/icons';
|
||||
import { useFieldArray, useFormContext } from 'react-hook-form';
|
||||
|
||||
@@ -7,7 +7,6 @@ import { Wireguard } from '@/utils';
|
||||
import { activateOnKey } from '@/utils/a11y';
|
||||
import { InputAddon } from '@/components/ui';
|
||||
import { FormField } from '@/components/form/rhf';
|
||||
import { WireguardDomainStrategy } from '@/schemas/primitives';
|
||||
|
||||
function AllowedIPsList({ peerIndex }: { peerIndex: number }) {
|
||||
const { t } = useTranslation();
|
||||
@@ -75,17 +74,6 @@ export default function WireguardFields() {
|
||||
<FormField label={t('pages.inbounds.publicKey')} name={['settings', 'pubKey']}>
|
||||
<Input disabled />
|
||||
</FormField>
|
||||
<FormField
|
||||
label={t('pages.xray.wireguard.domainStrategy')}
|
||||
name={['settings', 'domainStrategy']}
|
||||
>
|
||||
<Select
|
||||
options={[
|
||||
{ value: '', label: `(${t('none')})` },
|
||||
...WireguardDomainStrategy.map((s) => ({ value: s, label: s })),
|
||||
]}
|
||||
/>
|
||||
</FormField>
|
||||
<FormField label="MTU" name={['settings', 'mtu']}>
|
||||
<InputNumber min={0} />
|
||||
</FormField>
|
||||
|
||||
@@ -65,6 +65,34 @@ function reservedFor(clientId?: string): number[] {
|
||||
return out;
|
||||
}
|
||||
|
||||
export function buildWarpOutbound(
|
||||
data: WarpData | null,
|
||||
config: WarpConfig | null,
|
||||
): Record<string, unknown> | null {
|
||||
const cfg = config?.config;
|
||||
if (!cfg?.peers?.length) return null;
|
||||
const peer = cfg.peers[0];
|
||||
return {
|
||||
tag: 'warp',
|
||||
protocol: 'wireguard',
|
||||
// ForceIP may resolve engage.cloudflareclient.com to its AAAA and a half-configured IPv6
|
||||
// host blackholes the handshake silently (#5205); sockopt drives that lookup since 26.9.30.
|
||||
streamSettings: { sockopt: { domainStrategy: 'ForceIPv4v6' } },
|
||||
// Targets inside the tunnel keep the IPv4 preference the removed settings key gave them.
|
||||
targetStrategy: 'ForceIPv4v6',
|
||||
settings: {
|
||||
mtu: 1420,
|
||||
secretKey: data?.private_key,
|
||||
address: addressesFor(cfg.interface?.addresses || {}),
|
||||
reserved: reservedFor(cfg.client_id ?? data?.client_id),
|
||||
peers: [{ publicKey: peer.public_key, endpoint: peer.endpoint?.host }],
|
||||
// Userspace TUN: kernel TUN needs CAP_NET_ADMIN + fwmark routing, fails silently on many
|
||||
// VPS setups, and differs from the connectivity test's path (always noKernelTun=true).
|
||||
noKernelTun: true,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
export function mergeWarpRotation(
|
||||
existing: Record<string, unknown> | undefined,
|
||||
data: WarpData | null,
|
||||
@@ -127,31 +155,8 @@ export default function WarpModal({
|
||||
|
||||
const collectConfig = useCallback(
|
||||
(data: WarpData | null, config: WarpConfig | null): Record<string, unknown> | null => {
|
||||
const cfg = config?.config;
|
||||
if (!cfg?.peers?.length) return null;
|
||||
const peer = cfg.peers[0];
|
||||
const outbound: Record<string, unknown> = {
|
||||
tag: 'warp',
|
||||
protocol: 'wireguard',
|
||||
settings: {
|
||||
mtu: 1420,
|
||||
secretKey: data?.private_key,
|
||||
address: addressesFor(cfg.interface?.addresses || {}),
|
||||
reserved: reservedFor(cfg.client_id ?? data?.client_id),
|
||||
// Prefer IPv4 with IPv6 fallback: plain ForceIP may pick the AAAA
|
||||
// record for engage.cloudflareclient.com, and a host with
|
||||
// half-configured IPv6 then blackholes the handshake with no error
|
||||
// logged (#5205).
|
||||
domainStrategy: 'ForceIPv4v6',
|
||||
peers: [{ publicKey: peer.public_key, endpoint: peer.endpoint?.host }],
|
||||
// Userspace TUN: kernel TUN needs CAP_NET_ADMIN + fwmark routing and
|
||||
// fails silently on many VPS setups, and it is a different data path
|
||||
// than the panel's connectivity test (which always probes with
|
||||
// noKernelTun=true), so "test ok" and "traffic flows" can disagree.
|
||||
noKernelTun: true,
|
||||
},
|
||||
};
|
||||
setStagedOutbound(outbound);
|
||||
const outbound = buildWarpOutbound(data, config);
|
||||
if (outbound) setStagedOutbound(outbound);
|
||||
return outbound;
|
||||
},
|
||||
[],
|
||||
|
||||
@@ -13,7 +13,6 @@ import {
|
||||
FreedomFragmentSchema,
|
||||
FreedomNoiseSchema,
|
||||
OutboundDomainStrategySchema,
|
||||
WireguardDomainStrategySchema,
|
||||
} from '@/schemas/protocols/outbound';
|
||||
|
||||
export const VmessOutboundFormSettingsSchema = z.object({
|
||||
@@ -105,7 +104,6 @@ export const WireguardOutboundFormSettingsSchema = z.object({
|
||||
secretKey: z.string().default(''),
|
||||
pubKey: z.string().default(''),
|
||||
address: z.string().default(''),
|
||||
domainStrategy: z.union([WireguardDomainStrategySchema, z.literal('')]).default(''),
|
||||
reserved: z.string().default(''),
|
||||
remoteDNS: z.string().default(''),
|
||||
peers: z.array(WireguardOutboundFormPeerSchema).default([]),
|
||||
|
||||
@@ -39,14 +39,6 @@ export const MODE_OPTION = Object.freeze({
|
||||
STREAM_ONE: 'stream-one',
|
||||
});
|
||||
|
||||
export const WireguardDomainStrategy = Object.freeze([
|
||||
'ForceIP',
|
||||
'ForceIPv4',
|
||||
'ForceIPv4v6',
|
||||
'ForceIPv6',
|
||||
'ForceIPv6v4',
|
||||
] as const);
|
||||
|
||||
export const Address_Port_Strategy = Object.freeze({
|
||||
NONE: 'none',
|
||||
SRV_PORT_ONLY: 'SrvPortOnly',
|
||||
|
||||
@@ -8,5 +8,8 @@ export const TunInboundSettingsSchema = z.object({
|
||||
userLevel: z.number().int().min(0).default(0),
|
||||
autoSystemRoutingTable: z.array(z.string()).default([]),
|
||||
autoOutboundsInterface: z.string().default('auto'),
|
||||
// xray-core 26.9.30: the first acts on Linux, the second ("dns", "misconfigtun") on Windows.
|
||||
autoSystemDnsToGateway: z.boolean().optional(),
|
||||
autoSystemWfpBlockLeak: z.array(z.string()).optional(),
|
||||
});
|
||||
export type TunInboundSettings = z.infer<typeof TunInboundSettingsSchema>;
|
||||
|
||||
@@ -1,14 +1,5 @@
|
||||
import { z } from 'zod';
|
||||
|
||||
export const WireguardDomainStrategySchema = z.enum([
|
||||
'ForceIP',
|
||||
'ForceIPv4',
|
||||
'ForceIPv4v6',
|
||||
'ForceIPv6',
|
||||
'ForceIPv6v4',
|
||||
]);
|
||||
export type WireguardDomainStrategy = z.infer<typeof WireguardDomainStrategySchema>;
|
||||
|
||||
// AntD InputNumber emits null (not undefined) when the user clears it, and
|
||||
// the form store hands that null straight to safeParse on submit — a bare
|
||||
// .optional() would reject it and block the save.
|
||||
@@ -68,7 +59,6 @@ export const WireguardInboundSettingsSchema = z.object({
|
||||
peers: z.array(WireguardInboundPeerSchema).default([]),
|
||||
clients: z.array(WireguardClientSchema).default([]),
|
||||
noKernelTun: z.boolean().default(false),
|
||||
domainStrategy: WireguardDomainStrategySchema.optional(),
|
||||
// Admin-configurable base subnet new clients are auto-allocated from —
|
||||
// mirrors AmneziaWG's settings.server.subnetIp/subnetCidr. Optional and
|
||||
// left blank by default: an inbound that never sets this keeps the
|
||||
|
||||
@@ -1,14 +1,5 @@
|
||||
import { z } from 'zod';
|
||||
|
||||
export const WireguardDomainStrategySchema = z.enum([
|
||||
'ForceIP',
|
||||
'ForceIPv4',
|
||||
'ForceIPv4v6',
|
||||
'ForceIPv6',
|
||||
'ForceIPv6v4',
|
||||
]);
|
||||
export type WireguardDomainStrategy = z.infer<typeof WireguardDomainStrategySchema>;
|
||||
|
||||
export const WireguardOutboundPeerSchema = z.object({
|
||||
publicKey: z.string().min(1),
|
||||
preSharedKey: z.string().optional(),
|
||||
@@ -22,7 +13,6 @@ export const WireguardOutboundSettingsSchema = z.object({
|
||||
mtu: z.number().int().min(1).optional(),
|
||||
secretKey: z.string().min(1),
|
||||
address: z.array(z.string()).default([]),
|
||||
domainStrategy: WireguardDomainStrategySchema.optional(),
|
||||
reserved: z.array(z.number().int()).optional(),
|
||||
peers: z.array(WireguardOutboundPeerSchema).min(1),
|
||||
noKernelTun: z.boolean().default(false),
|
||||
|
||||
@@ -272,11 +272,28 @@ exports[`FinalMaskStreamSettingsSchema fixtures > parses udp-mask byte-stably 1`
|
||||
{
|
||||
"settings": {
|
||||
"domains": [
|
||||
"example.com:txt",
|
||||
"example.org:a",
|
||||
{
|
||||
"edns0": 1232,
|
||||
"name": "example.com",
|
||||
"types": [
|
||||
16,
|
||||
],
|
||||
},
|
||||
{
|
||||
"edns0": 1232,
|
||||
"name": "example.org",
|
||||
"types": [
|
||||
1,
|
||||
],
|
||||
},
|
||||
],
|
||||
"resolvers": [
|
||||
"example.com:txt+udp://1.1.1.1:53",
|
||||
{
|
||||
"settings": {
|
||||
"addr": "1.1.1.1:53",
|
||||
},
|
||||
"type": "udp",
|
||||
},
|
||||
],
|
||||
},
|
||||
"type": "xdns",
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
import { FinalMaskField } from '@/lib/xray/forms/fields';
|
||||
|
||||
import { listSelectOptions, renderWithProviders } from './test-utils';
|
||||
|
||||
describe('FinalMaskForm item types', () => {
|
||||
// Only the noise mask parses tag expressions; header-custom items go through the
|
||||
// core's PraseByteSlice, which refuses "exp" and fails the whole config load.
|
||||
it('offers the exp type to noise items only', () => {
|
||||
renderWithProviders(
|
||||
<FinalMaskField
|
||||
network="kcp"
|
||||
protocol="vless"
|
||||
value={{
|
||||
tcp: [],
|
||||
udp: [
|
||||
{ type: 'noise', settings: { noise: [{ type: 'array', rand: '1-8', delay: '1-2' }] } },
|
||||
{ type: 'header-custom', settings: { client: [{ type: 'array', rand: 1 }] } },
|
||||
],
|
||||
}}
|
||||
/>,
|
||||
);
|
||||
|
||||
// An opened dropdown stays in the DOM, so read header-custom's before noise's.
|
||||
expect(listSelectOptions('finalmask_udp_1_settings_client_0_type')).not.toContain('Expression');
|
||||
expect(listSelectOptions('finalmask_udp_0_settings_noise_0_type')).toContain('Expression');
|
||||
});
|
||||
});
|
||||
@@ -48,8 +48,11 @@
|
||||
{
|
||||
"type": "xdns",
|
||||
"settings": {
|
||||
"domains": ["example.com:txt", "example.org:a"],
|
||||
"resolvers": ["example.com:txt+udp://1.1.1.1:53"]
|
||||
"domains": [
|
||||
{ "name": "example.com", "types": [16], "edns0": 1232 },
|
||||
{ "name": "example.org", "types": [1], "edns0": 1232 }
|
||||
],
|
||||
"resolvers": [{ "type": "udp", "settings": { "addr": "1.1.1.1:53" } }]
|
||||
}
|
||||
},
|
||||
{
|
||||
|
||||
@@ -58,6 +58,26 @@ describe('inboundFromDb', () => {
|
||||
expect((inbound.streamSettings as { security?: string })?.security).toBe('tls');
|
||||
});
|
||||
|
||||
// The settings parse strips keys the schema does not list, so a TUN option xray-core
|
||||
// 26.9.30 added and an admin entered as JSON would vanish on the next form save.
|
||||
it('keeps the TUN options xray-core 26.9.30 added', () => {
|
||||
const inbound = inboundFromDb({
|
||||
...BASE_DB_FIELDS,
|
||||
protocol: 'tun',
|
||||
settings: {
|
||||
name: 'xray0',
|
||||
gateway: ['10.0.0.1/16'],
|
||||
autoSystemDnsToGateway: true,
|
||||
autoSystemWfpBlockLeak: ['dns', 'misconfigtun'],
|
||||
},
|
||||
streamSettings: '',
|
||||
});
|
||||
expect(inbound.settings).toMatchObject({
|
||||
autoSystemDnsToGateway: true,
|
||||
autoSystemWfpBlockLeak: ['dns', 'misconfigtun'],
|
||||
});
|
||||
});
|
||||
|
||||
it('returns schema-default settings for missing/empty fields without throwing', () => {
|
||||
const raw = {
|
||||
...BASE_DB_FIELDS,
|
||||
|
||||
@@ -312,6 +312,74 @@ describe('outbound-form-adapter: round-trip', () => {
|
||||
expect((unset.settings as { remoteDNS?: string[] }).remoteDNS).toBeUndefined();
|
||||
});
|
||||
|
||||
// xray-core 26.9.30 ignores wireguard's settings.domainStrategy and panics on remoteDNS
|
||||
// "local"; the endpoint lookup reads sockopt.domainStrategy, in-tunnel targets targetStrategy.
|
||||
it('wireguard lifts the removed domainStrategy and remoteDNS local where the core reads them', () => {
|
||||
const settings = {
|
||||
secretKey: 'YFVmTVCBsLxXJCe4i+jK8PgD3S6vUqfZ4Zl0JVNDfHA=',
|
||||
peers: [{ publicKey: 'pk', endpoint: 'engage.cloudflareclient.com:2408' }],
|
||||
};
|
||||
const warp = formValuesToWirePayload(
|
||||
rawOutboundToFormValues({
|
||||
protocol: 'wireguard',
|
||||
settings: { ...settings, domainStrategy: 'ForceIPv4v6' },
|
||||
}),
|
||||
);
|
||||
expect(warp.targetStrategy).toBe('ForceIPv4v6');
|
||||
expect(warp.streamSettings).toEqual({ sockopt: { domainStrategy: 'ForceIPv4v6' } });
|
||||
expect((warp.settings as Record<string, unknown>).domainStrategy).toBeUndefined();
|
||||
|
||||
const local = formValuesToWirePayload(
|
||||
rawOutboundToFormValues({
|
||||
protocol: 'wireguard',
|
||||
settings: { ...settings, remoteDNS: ['local'] },
|
||||
}),
|
||||
);
|
||||
expect(local.targetStrategy).toBe('ForceIP');
|
||||
expect((local.settings as Record<string, unknown>).remoteDNS).toBeUndefined();
|
||||
|
||||
const admin = formValuesToWirePayload(
|
||||
rawOutboundToFormValues({
|
||||
protocol: 'wireguard',
|
||||
targetStrategy: 'UseIPv6',
|
||||
streamSettings: { sockopt: { domainStrategy: 'UseIPv4' } },
|
||||
settings: { ...settings, domainStrategy: 'ForceIPv6' },
|
||||
}),
|
||||
);
|
||||
expect(admin.targetStrategy).toBe('UseIPv6');
|
||||
expect(admin.streamSettings).toEqual({ sockopt: { domainStrategy: 'UseIPv4' } });
|
||||
});
|
||||
|
||||
// The core dials a wireguard peer through its finalmask (noise "exp" was built for WARP),
|
||||
// so saving through the form must keep the masks next to sockopt instead of dropping them.
|
||||
it('wireguard keeps its finalmask on save and drops an empty one', () => {
|
||||
const settings = {
|
||||
secretKey: 'YFVmTVCBsLxXJCe4i+jK8PgD3S6vUqfZ4Zl0JVNDfHA=',
|
||||
peers: [{ publicKey: 'pk', endpoint: 'engage.cloudflareclient.com:2408' }],
|
||||
};
|
||||
const noise = {
|
||||
type: 'noise',
|
||||
settings: { noise: [{ type: 'exp', packet: '<b 0d0a0d0a><t>', delay: '1-3' }] },
|
||||
};
|
||||
const masked = formValuesToWirePayload(
|
||||
rawOutboundToFormValues({
|
||||
protocol: 'wireguard',
|
||||
settings,
|
||||
streamSettings: { sockopt: { mark: 255 }, finalmask: { tcp: [], udp: [noise] } },
|
||||
}),
|
||||
);
|
||||
expect(masked.streamSettings).toEqual({ sockopt: { mark: 255 }, finalmask: { udp: [noise] } });
|
||||
|
||||
const empty = formValuesToWirePayload(
|
||||
rawOutboundToFormValues({
|
||||
protocol: 'wireguard',
|
||||
settings,
|
||||
streamSettings: { sockopt: { mark: 255 }, finalmask: { tcp: [], udp: [] } },
|
||||
}),
|
||||
);
|
||||
expect(empty.streamSettings).toEqual({ sockopt: { mark: 255 } });
|
||||
});
|
||||
|
||||
it('dns rules normalize qType numeric strings, split domains, carry rCode', () => {
|
||||
const wire = {
|
||||
protocol: 'dns',
|
||||
|
||||
@@ -1,12 +1,15 @@
|
||||
import { describe, it, expect, vi } from 'vitest';
|
||||
import { act, fireEvent } from '@testing-library/react';
|
||||
import { act, fireEvent, render } from '@testing-library/react';
|
||||
import { QueryClientProvider } from '@tanstack/react-query';
|
||||
|
||||
import { ThemeProvider } from '@/hooks/useTheme';
|
||||
import OutboundFormModal from '@/pages/xray/outbounds/OutboundFormModal';
|
||||
import {
|
||||
renderWithProviders,
|
||||
fieldLabels,
|
||||
listSelectOptions,
|
||||
chooseSelectOption,
|
||||
makeTestQueryClient,
|
||||
} from './test-utils';
|
||||
|
||||
function renderModal(outbound: Record<string, unknown> | null = null) {
|
||||
@@ -149,4 +152,74 @@ describe('OutboundFormModal', () => {
|
||||
};
|
||||
expect(payload.settings.reverse?.tag).toBe('r1');
|
||||
});
|
||||
|
||||
// xray-core 26.9.30 no longer parses xdns's string lists, so the mask editor lifts
|
||||
// them into objects on open rather than saving a config the core would refuse.
|
||||
it('saves a legacy xdns mask in the object shape', async () => {
|
||||
const onConfirm = vi.fn();
|
||||
const queryClient = makeTestQueryClient();
|
||||
const outbound = {
|
||||
protocol: 'vless',
|
||||
tag: 'dns-tunnel',
|
||||
settings: {
|
||||
vnext: [
|
||||
{
|
||||
address: 'example.com',
|
||||
port: 53,
|
||||
users: [{ id: 'c9f0c2d0-0000-4000-8000-000000000000', encryption: 'none' }],
|
||||
},
|
||||
],
|
||||
},
|
||||
streamSettings: {
|
||||
network: 'kcp',
|
||||
security: 'none',
|
||||
kcpSettings: { mtu: 130, tti: 50 },
|
||||
finalmask: {
|
||||
udp: [{ type: 'xdns', settings: { resolvers: ['t.example.com+udp://8.8.8.8:53'] } }],
|
||||
},
|
||||
},
|
||||
};
|
||||
const tree = (open: boolean) => (
|
||||
<QueryClientProvider client={queryClient}>
|
||||
<ThemeProvider>
|
||||
<OutboundFormModal
|
||||
open={open}
|
||||
outbound={outbound}
|
||||
existingTags={[]}
|
||||
onClose={() => {}}
|
||||
onConfirm={onConfirm}
|
||||
/>
|
||||
</ThemeProvider>
|
||||
</QueryClientProvider>
|
||||
);
|
||||
// The panel keeps the modal mounted and flips `open`; mounting it already open lets
|
||||
// the add-mode transport seed replace the edited outbound's kcp stream with tcp.
|
||||
const { rerender } = render(tree(false));
|
||||
rerender(tree(true));
|
||||
await act(async () => {
|
||||
await new Promise((r) => setTimeout(r, 0));
|
||||
});
|
||||
|
||||
const ok = document.querySelector('.ant-modal-footer .ant-btn-primary') as HTMLElement;
|
||||
await act(async () => {
|
||||
fireEvent.click(ok);
|
||||
});
|
||||
await act(async () => {
|
||||
await new Promise((r) => setTimeout(r, 0));
|
||||
});
|
||||
|
||||
expect(onConfirm).toHaveBeenCalledTimes(1);
|
||||
const payload = onConfirm.mock.calls[0][0] as {
|
||||
streamSettings: { finalmask: { udp: Array<{ type: string; settings: unknown }> } };
|
||||
};
|
||||
expect(payload.streamSettings.finalmask.udp).toEqual([
|
||||
{
|
||||
type: 'xdns',
|
||||
settings: {
|
||||
domains: [{ name: 't.example.com', types: [16], edns0: 1232 }],
|
||||
resolvers: [{ type: 'udp', settings: { addr: '8.8.8.8:53' } }],
|
||||
},
|
||||
},
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -224,6 +224,26 @@ describe('parseVlessLink — XHTTP advanced fields', () => {
|
||||
});
|
||||
|
||||
describe('parseVlessLink', () => {
|
||||
// A panel older than xray-core 26.9.30 shares xdns in the string lists the core no
|
||||
// longer parses, so an outbound imported verbatim would fail the whole config.
|
||||
it('upgrades a legacy xdns fm= mask to the object shape', () => {
|
||||
const fm = encodeURIComponent(
|
||||
JSON.stringify({
|
||||
udp: [{ type: 'xdns', settings: { resolvers: ['t.example.com+udp://8.8.8.8:53'] } }],
|
||||
}),
|
||||
);
|
||||
const out = parseVlessLink(
|
||||
`vless://11111111-2222-4333-8444-555555555555@srv:53?type=kcp&security=none&fm=${fm}#dns`,
|
||||
);
|
||||
const finalmask = (out!.streamSettings as Record<string, unknown>).finalmask as {
|
||||
udp: Array<{ settings: unknown }>;
|
||||
};
|
||||
expect(finalmask.udp[0].settings).toEqual({
|
||||
domains: [{ name: 't.example.com', types: [16], edns0: 1232 }],
|
||||
resolvers: [{ type: 'udp', settings: { addr: '8.8.8.8:53' } }],
|
||||
});
|
||||
});
|
||||
|
||||
it('parses a vless:// link with reality', () => {
|
||||
const link =
|
||||
'vless://11111111-2222-4333-8444-555555555555@srv.example:443' +
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
import { mergeWarpRotation } from '@/pages/xray/overrides/WarpModal';
|
||||
import { buildWarpOutbound, mergeWarpRotation } from '@/pages/xray/overrides/WarpModal';
|
||||
|
||||
const clientId = btoa(String.fromCharCode(1, 2, 3));
|
||||
|
||||
@@ -110,3 +110,14 @@ describe('mergeWarpRotation', () => {
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('buildWarpOutbound', () => {
|
||||
// xray-core 26.9.30 ignores wireguard's settings.domainStrategy, so the IPv4-first
|
||||
// endpoint lookup #5205 depends on has to travel in sockopt, where the core reads it.
|
||||
it('places the IPv4-first strategy where xray-core reads it', () => {
|
||||
const outbound = buildWarpOutbound({ private_key: 'secret' }, rotatedConfig()) ?? {};
|
||||
expect(outbound.streamSettings).toEqual({ sockopt: { domainStrategy: 'ForceIPv4v6' } });
|
||||
expect(outbound.targetStrategy).toBe('ForceIPv4v6');
|
||||
expect(outbound.settings).not.toHaveProperty('domainStrategy');
|
||||
});
|
||||
});
|
||||
|
||||
@@ -26,7 +26,7 @@ require (
|
||||
github.com/skip2/go-qrcode v0.0.0-20200617195104-da1b6568686e
|
||||
github.com/valyala/fasthttp v1.74.0
|
||||
github.com/xlzd/gotp v0.1.0
|
||||
github.com/xtls/xray-core v1.260327.1-0.20260908222543-52a412d9e2f5
|
||||
github.com/xtls/xray-core v1.260327.1-0.20260930074004-b26a91de4f32
|
||||
go.uber.org/atomic v1.12.0
|
||||
golang.org/x/crypto v0.57.0
|
||||
golang.org/x/net v0.59.0
|
||||
@@ -94,8 +94,6 @@ require (
|
||||
github.com/quic-go/qpack v0.6.0 // indirect
|
||||
github.com/quic-go/quic-go v0.63.0 // indirect
|
||||
github.com/rogpeppe/go-internal v1.15.0 // indirect
|
||||
github.com/sagernet/sing v0.9.5 // indirect
|
||||
github.com/sagernet/sing-shadowsocks v0.2.9 // indirect
|
||||
github.com/tklauser/go-sysconf v0.4.0 // indirect
|
||||
github.com/tklauser/numcpus v0.12.0 // indirect
|
||||
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
|
||||
|
||||
@@ -183,10 +183,6 @@ github.com/robfig/cron/v3 v3.0.1 h1:WdRxkvbJztn8LMz/QEvLN5sBU+xKpSqwwUO1Pjr4qDs=
|
||||
github.com/robfig/cron/v3 v3.0.1/go.mod h1:eQICP3HwyT7UooqI/z+Ov+PtYAWygg1TEWWzGIFLtro=
|
||||
github.com/rogpeppe/go-internal v1.15.0 h1:D0RCU5rMAp+SpgkiNdrjfJ+LX4J1M32V2NeCY7EJ6hc=
|
||||
github.com/rogpeppe/go-internal v1.15.0/go.mod h1:DrUVZyrJU+txYW5/1kwtXQSMFio52ZOxX7yM1VHvnxs=
|
||||
github.com/sagernet/sing v0.9.5 h1:BHaElRqhHhkH747xIkxgsqgRJxkIiuAlpnfwiJnu2aY=
|
||||
github.com/sagernet/sing v0.9.5/go.mod h1:K3Owt3xPhHugvlnlPPxZJ/exXdaJfEPOTNorGk4AXjo=
|
||||
github.com/sagernet/sing-shadowsocks v0.2.9 h1:Paep5zCszRKsEn8587O0MnhFWKJwDW1Y4zOYYlIxMkM=
|
||||
github.com/sagernet/sing-shadowsocks v0.2.9/go.mod h1:TE/Z6401Pi8tgr0nBZcM/xawAI6u3F6TTbz4nH/qw+8=
|
||||
github.com/shirou/gopsutil/v4 v4.26.8 h1:YQMTF/1J50B5+Y0vlo1eDRf5DoR7Gk69hY+8wjYkQeo=
|
||||
github.com/shirou/gopsutil/v4 v4.26.8/go.mod h1:5O9FjBiXoTDFatIWjZZosqj4pV0DRtLx598xGbBehzM=
|
||||
github.com/skip2/go-qrcode v0.0.0-20200617195104-da1b6568686e h1:MRM5ITcdelLK2j1vwZ3Je0FKVCfqOLp5zO6trqMLYs0=
|
||||
@@ -227,8 +223,8 @@ github.com/xlzd/gotp v0.1.0 h1:37blvlKCh38s+fkem+fFh7sMnceltoIEBYTVXyoa5Po=
|
||||
github.com/xlzd/gotp v0.1.0/go.mod h1:ndLJ3JKzi3xLmUProq4LLxCuECL93dG9WASNLpHz8qg=
|
||||
github.com/xtls/reality v0.0.0-20260921001439-3c98159dee38 h1:Q5KwiMm+WRyw2kwPW4+fIQxNio1CyrWo/eAEaAHxl/Q=
|
||||
github.com/xtls/reality v0.0.0-20260921001439-3c98159dee38/go.mod h1:/YQ6FwmAtkDuo8K3ujKQH1Br5eGNFauBipdl1gdiebk=
|
||||
github.com/xtls/xray-core v1.260327.1-0.20260908222543-52a412d9e2f5 h1:BsUC2sCXcdVCb09SUh1iWku0ci779t4bUIlKUor1ZRI=
|
||||
github.com/xtls/xray-core v1.260327.1-0.20260908222543-52a412d9e2f5/go.mod h1:obbr2WDmr/cpQ/YLe1k0HTULnFXCO0rTWIeSrHoFk3o=
|
||||
github.com/xtls/xray-core v1.260327.1-0.20260930074004-b26a91de4f32 h1:Bxo6+07IvdWlqxugsn2/sQrFbR7hjrxRRDMjbOInRho=
|
||||
github.com/xtls/xray-core v1.260327.1-0.20260930074004-b26a91de4f32/go.mod h1:FAjlDAzHXXyki7R1BxruCHFx19B3i8TvQGEy+wsqZWU=
|
||||
github.com/xyproto/randomstring v1.0.5 h1:YtlWPoRdgMu3NZtP45drfy1GKoojuR7hmRcnhZqKjWU=
|
||||
github.com/xyproto/randomstring v1.0.5/go.mod h1:rgmS5DeNXLivK7YprL0pY+lTuhNQW3iGxZ18UQApw/E=
|
||||
github.com/yusufpapurcu/wmi v1.2.4 h1:zFUKzehAFReQwLys1b/iSMl+JQGSCSjtVqQn9bBrPo0=
|
||||
|
||||
+234
-1
@@ -23,6 +23,7 @@ import (
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/config"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/crypto"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/maskcompat"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/random"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/xray"
|
||||
|
||||
@@ -1280,7 +1281,7 @@ func runSeeders(isUsersEmpty bool) error {
|
||||
}
|
||||
|
||||
if empty && isUsersEmpty {
|
||||
seeders := []string{"UserPasswordHash", "ClientsTable", "InboundClientsArrayFix", "InboundClientTgIdFix2", "InboundClientSubIdFix", "FreedomFinalRulesReverseFix", "FreedomFinalRulesPrivateEgressBlock", "UppercaseFreedomFinalRulesFix", "InboundRealityFinalmaskTcpStrip", "ApiTokensHash", "LegacyProxySettingsCleanup", "OutboundRemovedKeysFix", "FreedomDomainStrategyFix", "DNSOutboundLegacyKeysFix", "DNSOutboundQTypeZeroFix", "WireguardPeersToClients", "MtprotoSecretsToClients", "NodeInboundsAdopted", "ResetIpLimitNoFail2ban"}
|
||||
seeders := []string{"UserPasswordHash", "ClientsTable", "InboundClientsArrayFix", "InboundClientTgIdFix2", "InboundClientSubIdFix", "FreedomFinalRulesReverseFix", "FreedomFinalRulesPrivateEgressBlock", "UppercaseFreedomFinalRulesFix", "InboundRealityFinalmaskTcpStrip", "ApiTokensHash", "LegacyProxySettingsCleanup", "OutboundRemovedKeysFix", "FreedomDomainStrategyFix", "DNSOutboundLegacyKeysFix", "DNSOutboundQTypeZeroFix", "WireguardDomainStrategyFix", "XdnsFinalmaskObjectsFix", "WireguardPeersToClients", "MtprotoSecretsToClients", "NodeInboundsAdopted", "ResetIpLimitNoFail2ban"}
|
||||
for _, name := range seeders {
|
||||
if err := db.Create(&model.HistoryOfSeeders{SeederName: name}).Error; err != nil {
|
||||
return err
|
||||
@@ -1415,6 +1416,18 @@ func runSeeders(isUsersEmpty bool) error {
|
||||
}
|
||||
}
|
||||
|
||||
if !slices.Contains(seedersHistory, "WireguardDomainStrategyFix") {
|
||||
if err := migrateWireguardDomainStrategy(); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
if !slices.Contains(seedersHistory, "XdnsFinalmaskObjectsFix") {
|
||||
if err := migrateXdnsFinalmaskObjects(); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
if !slices.Contains(seedersHistory, "NodeInboundsAdopted") {
|
||||
if err := seedNodeInboundsAdopted(); err != nil {
|
||||
return err
|
||||
@@ -1815,6 +1828,226 @@ var freedomDomainStrategies = map[string]bool{
|
||||
"forceipv6": true, "forceipv4v6": true, "forceipv6v4": true,
|
||||
}
|
||||
|
||||
func migrateWireguardDomainStrategy() error {
|
||||
var setting model.Setting
|
||||
err := db.Model(model.Setting{}).Where("key = ?", "xrayTemplateConfig").First(&setting).Error
|
||||
if errors.Is(err, gorm.ErrRecordNotFound) {
|
||||
return db.Create(&model.HistoryOfSeeders{SeederName: "WireguardDomainStrategyFix"}).Error
|
||||
}
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
updated, changed, rErr := rewriteWireguardDomainStrategy(setting.Value)
|
||||
if rErr != nil {
|
||||
log.Printf("WireguardDomainStrategyFix: skip (invalid xrayTemplateConfig json): %v", rErr)
|
||||
return db.Create(&model.HistoryOfSeeders{SeederName: "WireguardDomainStrategyFix"}).Error
|
||||
}
|
||||
|
||||
return db.Transaction(func(tx *gorm.DB) error {
|
||||
if changed {
|
||||
if err := tx.Model(&model.Setting{}).Where("key = ?", "xrayTemplateConfig").
|
||||
Update("value", updated).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
return tx.Create(&model.HistoryOfSeeders{SeederName: "WireguardDomainStrategyFix"}).Error
|
||||
})
|
||||
}
|
||||
|
||||
// rewriteWireguardDomainStrategy splits the settings.domainStrategy xray-core 26.9.30 (#6771)
|
||||
// ignores: sockopt.domainStrategy now picks the endpoint's family, targetStrategy the targets'.
|
||||
func rewriteWireguardDomainStrategy(raw string) (string, bool, error) {
|
||||
if strings.TrimSpace(raw) == "" {
|
||||
return raw, false, nil
|
||||
}
|
||||
var cfg map[string]any
|
||||
if err := json.Unmarshal([]byte(raw), &cfg); err != nil {
|
||||
return raw, false, err
|
||||
}
|
||||
outbounds, ok := cfg["outbounds"].([]any)
|
||||
if !ok {
|
||||
return raw, false, nil
|
||||
}
|
||||
changed := false
|
||||
for _, ob := range outbounds {
|
||||
obj, ok := ob.(map[string]any)
|
||||
if !ok {
|
||||
continue
|
||||
}
|
||||
if proto, _ := obj["protocol"].(string); !strings.EqualFold(proto, "wireguard") {
|
||||
continue
|
||||
}
|
||||
settings, _ := obj["settings"].(map[string]any)
|
||||
legacy, hasLegacy := settings["domainStrategy"]
|
||||
remoteDNS, _ := settings["remoteDNS"].([]any)
|
||||
localDNS := len(remoteDNS) == 1 && remoteDNS[0] == "local"
|
||||
if !hasLegacy && !localDNS {
|
||||
continue
|
||||
}
|
||||
delete(settings, "domainStrategy")
|
||||
strategy, _ := legacy.(string)
|
||||
if !wireguardFamilyStrategies[strings.ToLower(strategy)] {
|
||||
strategy = ""
|
||||
}
|
||||
if strategy != "" {
|
||||
if sockopt := outboundSockopt(obj, true); !strategyIsSet(sockopt["domainStrategy"]) {
|
||||
sockopt["domainStrategy"] = strategy
|
||||
}
|
||||
}
|
||||
if localDNS {
|
||||
delete(settings, "remoteDNS")
|
||||
if strategy == "" {
|
||||
strategy = "ForceIP"
|
||||
}
|
||||
}
|
||||
if strategy != "" && !strategyIsSet(obj["targetStrategy"]) {
|
||||
obj["targetStrategy"] = strategy
|
||||
}
|
||||
changed = true
|
||||
}
|
||||
if !changed {
|
||||
return raw, false, nil
|
||||
}
|
||||
out, err := json.MarshalIndent(cfg, "", " ")
|
||||
if err != nil {
|
||||
return raw, false, err
|
||||
}
|
||||
return string(out), true, nil
|
||||
}
|
||||
|
||||
// wireguardFamilyStrategies are the old wireguard values that pinned an address family;
|
||||
// plain ForceIP pinned none, and any other value already failed the old core's load.
|
||||
var wireguardFamilyStrategies = map[string]bool{
|
||||
"forceipv4": true, "forceipv6": true, "forceipv4v6": true, "forceipv6v4": true,
|
||||
}
|
||||
|
||||
func strategyIsSet(value any) bool {
|
||||
s, _ := value.(string)
|
||||
return s != "" && !strings.EqualFold(s, "asis")
|
||||
}
|
||||
|
||||
// migrateXdnsFinalmaskObjects upgrades every stored xdns mask to the object shape
|
||||
// xray-core 26.9.30 requires, wherever the panel keeps a finalmask.
|
||||
func migrateXdnsFinalmaskObjects() error {
|
||||
return db.Transaction(func(tx *gorm.DB) error {
|
||||
var inbounds []model.Inbound
|
||||
if err := tx.Select("id", "stream_settings").Find(&inbounds).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
for _, inbound := range inbounds {
|
||||
if updated, changed := upgradeLegacyXdnsJSON(inbound.StreamSettings, streamFinalmask, false); changed {
|
||||
if err := tx.Model(&model.Inbound{}).Where("id = ?", inbound.Id).
|
||||
Update("stream_settings", updated).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
var hosts []model.Host
|
||||
if err := tx.Select("id", "final_mask").Find(&hosts).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
for _, host := range hosts {
|
||||
if updated, changed := upgradeLegacyXdnsJSON(host.FinalMask, wholeFinalmask, false); changed {
|
||||
if err := tx.Model(&model.Host{}).Where("id = ?", host.Id).
|
||||
Update("final_mask", updated).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
var subs []model.OutboundSubscription
|
||||
if err := tx.Select("id", "last_fetched_outbounds").Find(&subs).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
for _, sub := range subs {
|
||||
if updated, changed := upgradeLegacyXdnsJSON(sub.LastFetchedOutbounds, outboundListFinalmasks, false); changed {
|
||||
if err := tx.Model(&model.OutboundSubscription{}).Where("id = ?", sub.Id).
|
||||
Update("last_fetched_outbounds", updated).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
for _, stored := range []struct {
|
||||
key string
|
||||
locate func(any) []any
|
||||
indent bool
|
||||
}{
|
||||
{"xrayTemplateConfig", templateFinalmasks, true},
|
||||
{"subJsonFinalMask", wholeFinalmask, false},
|
||||
} {
|
||||
var setting model.Setting
|
||||
err := tx.Where("key = ?", stored.key).First(&setting).Error
|
||||
if errors.Is(err, gorm.ErrRecordNotFound) {
|
||||
continue
|
||||
}
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if updated, changed := upgradeLegacyXdnsJSON(setting.Value, stored.locate, stored.indent); changed {
|
||||
if err := tx.Model(&model.Setting{}).Where("key = ?", stored.key).
|
||||
Update("value", updated).Error; err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
return tx.Create(&model.HistoryOfSeeders{SeederName: "XdnsFinalmaskObjectsFix"}).Error
|
||||
})
|
||||
}
|
||||
|
||||
// upgradeLegacyXdnsJSON rewrites the finalmasks locate finds in one stored JSON document,
|
||||
// leaving the document byte-for-byte alone when nothing in it is legacy.
|
||||
func upgradeLegacyXdnsJSON(raw string, locate func(any) []any, indent bool) (string, bool) {
|
||||
if strings.TrimSpace(raw) == "" {
|
||||
return raw, false
|
||||
}
|
||||
var doc any
|
||||
if err := json.Unmarshal([]byte(raw), &doc); err != nil {
|
||||
return raw, false
|
||||
}
|
||||
changed := false
|
||||
for _, mask := range locate(doc) {
|
||||
if maskcompat.UpgradeLegacyXdns(mask) {
|
||||
changed = true
|
||||
}
|
||||
}
|
||||
if !changed {
|
||||
return raw, false
|
||||
}
|
||||
var out []byte
|
||||
var err error
|
||||
if indent {
|
||||
out, err = json.MarshalIndent(doc, "", " ")
|
||||
} else {
|
||||
out, err = json.Marshal(doc)
|
||||
}
|
||||
if err != nil {
|
||||
return raw, false
|
||||
}
|
||||
return string(out), true
|
||||
}
|
||||
|
||||
func wholeFinalmask(doc any) []any { return []any{doc} }
|
||||
|
||||
func streamFinalmask(doc any) []any {
|
||||
stream, _ := doc.(map[string]any)
|
||||
return []any{stream["finalmask"]}
|
||||
}
|
||||
|
||||
func outboundListFinalmasks(doc any) []any {
|
||||
list, _ := doc.([]any)
|
||||
finalmasks := make([]any, 0, len(list))
|
||||
for _, entry := range list {
|
||||
obj, _ := entry.(map[string]any)
|
||||
finalmasks = append(finalmasks, streamFinalmask(obj["streamSettings"])...)
|
||||
}
|
||||
return finalmasks
|
||||
}
|
||||
|
||||
func templateFinalmasks(doc any) []any {
|
||||
cfg, _ := doc.(map[string]any)
|
||||
return append(outboundListFinalmasks(cfg["inbounds"]), outboundListFinalmasks(cfg["outbounds"])...)
|
||||
}
|
||||
|
||||
// migrateDNSOutboundLegacyKeys rewrites stored dns outbounds once, because the
|
||||
// core logs nonIPQuery/blockTypes as deprecated on every config load.
|
||||
func migrateDNSOutboundLegacyKeys() error {
|
||||
|
||||
@@ -0,0 +1,147 @@
|
||||
package database
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/config"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/xray"
|
||||
)
|
||||
|
||||
const wgTestKeys = `"secretKey":"yAnz5TF+lXXJte14tji3zlMNq+hd2rYUIgJBgB3fBmk=","peers":[{"publicKey":"xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=","endpoint":"engage.cloudflareclient.com:2408"}]`
|
||||
|
||||
func TestRewriteWireguardDomainStrategy(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
outbound string
|
||||
wantChanged bool
|
||||
wantRoot string
|
||||
wantSockopt string
|
||||
wantDNS bool
|
||||
}{
|
||||
{
|
||||
name: "the WARP default moves to both places the core now reads",
|
||||
outbound: `{"protocol":"wireguard","tag":"warp","settings":{"domainStrategy":"ForceIPv4v6",` + wgTestKeys + `}}`,
|
||||
wantChanged: true, wantRoot: "ForceIPv4v6", wantSockopt: "ForceIPv4v6",
|
||||
},
|
||||
{
|
||||
name: "values the admin already set win over the legacy key",
|
||||
outbound: `{"protocol":"wireguard","tag":"wg","targetStrategy":"UseIPv6","streamSettings":{"sockopt":{"domainStrategy":"UseIPv4"}},"settings":{"domainStrategy":"forceipv6",` + wgTestKeys + `}}`,
|
||||
wantChanged: true, wantRoot: "UseIPv6", wantSockopt: "UseIPv4",
|
||||
},
|
||||
{
|
||||
name: "plain ForceIP had no family preference, so only the key goes",
|
||||
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"domainStrategy":"ForceIP",` + wgTestKeys + `}}`,
|
||||
wantChanged: true,
|
||||
},
|
||||
{
|
||||
name: "remoteDNS local becomes targetStrategy, which resolves with the built-in DNS",
|
||||
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"domainStrategy":"ForceIPv4","remoteDNS":["local"],` + wgTestKeys + `}}`,
|
||||
wantChanged: true, wantRoot: "ForceIPv4", wantSockopt: "ForceIPv4",
|
||||
},
|
||||
{
|
||||
name: "remoteDNS local without a strategy resolves any family",
|
||||
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"remoteDNS":["local"],` + wgTestKeys + `}}`,
|
||||
wantChanged: true, wantRoot: "ForceIP",
|
||||
},
|
||||
{
|
||||
name: "a strategy the old core refused is dropped rather than moved",
|
||||
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"domainStrategy":"UseIPv4",` + wgTestKeys + `}}`,
|
||||
wantChanged: true,
|
||||
},
|
||||
{
|
||||
name: "IP remoteDNS entries stay",
|
||||
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"remoteDNS":["1.1.1.1"],` + wgTestKeys + `}}`,
|
||||
wantChanged: false, wantDNS: true,
|
||||
},
|
||||
}
|
||||
for _, tc := range tests {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
updated, changed, err := rewriteWireguardDomainStrategy(`{"outbounds":[` + tc.outbound + `]}`)
|
||||
if err != nil {
|
||||
t.Fatalf("rewrite: %v", err)
|
||||
}
|
||||
if changed != tc.wantChanged {
|
||||
t.Fatalf("changed = %v, want %v", changed, tc.wantChanged)
|
||||
}
|
||||
var cfg struct {
|
||||
Outbounds []json.RawMessage `json:"outbounds"`
|
||||
}
|
||||
if err := json.Unmarshal([]byte(updated), &cfg); err != nil || len(cfg.Outbounds) != 1 {
|
||||
t.Fatalf("rewritten template unreadable (%v): %s", err, updated)
|
||||
}
|
||||
var got struct {
|
||||
TargetStrategy string `json:"targetStrategy"`
|
||||
StreamSettings struct {
|
||||
Sockopt struct {
|
||||
DomainStrategy string `json:"domainStrategy"`
|
||||
} `json:"sockopt"`
|
||||
} `json:"streamSettings"`
|
||||
Settings map[string]any `json:"settings"`
|
||||
}
|
||||
if err := json.Unmarshal(cfg.Outbounds[0], &got); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got.TargetStrategy != tc.wantRoot {
|
||||
t.Errorf("targetStrategy = %q, want %q", got.TargetStrategy, tc.wantRoot)
|
||||
}
|
||||
if got.StreamSettings.Sockopt.DomainStrategy != tc.wantSockopt {
|
||||
t.Errorf("sockopt.domainStrategy = %q, want %q", got.StreamSettings.Sockopt.DomainStrategy, tc.wantSockopt)
|
||||
}
|
||||
if _, kept := got.Settings["domainStrategy"]; kept {
|
||||
t.Errorf("settings.domainStrategy survived the rewrite: %s", cfg.Outbounds[0])
|
||||
}
|
||||
if _, kept := got.Settings["remoteDNS"]; kept != tc.wantDNS {
|
||||
t.Errorf("remoteDNS kept = %v, want %v", kept, tc.wantDNS)
|
||||
}
|
||||
if err := xray.ValidateOutboundConfig(cfg.Outbounds[0]); err != nil {
|
||||
t.Fatalf("xray-core refuses the rewritten outbound: %v", err)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestWireguardDomainStrategySeederRewritesStoredTemplateOnce(t *testing.T) {
|
||||
t.Setenv("XUI_DB_FOLDER", t.TempDir())
|
||||
if err := InitDB(config.GetDBPath()); err != nil {
|
||||
if strings.Contains(err.Error(), "CGO_ENABLED=0") {
|
||||
t.Skipf("sqlite needs cgo: %v", err)
|
||||
}
|
||||
t.Fatalf("init db: %v", err)
|
||||
}
|
||||
t.Cleanup(func() { _ = CloseDB() })
|
||||
|
||||
legacy := `{"outbounds":[{"protocol":"wireguard","tag":"warp","settings":{"domainStrategy":"ForceIPv4v6",` + wgTestKeys + `}}]}`
|
||||
seedTemplate(t, legacy)
|
||||
if err := db.Where("seeder_name = ?", "WireguardDomainStrategyFix").
|
||||
Delete(&model.HistoryOfSeeders{}).Error; err != nil {
|
||||
t.Fatalf("clear seeder history: %v", err)
|
||||
}
|
||||
|
||||
if err := runSeeders(false); err != nil {
|
||||
t.Fatalf("runSeeders: %v", err)
|
||||
}
|
||||
var cfg struct {
|
||||
Outbounds []struct {
|
||||
TargetStrategy string `json:"targetStrategy"`
|
||||
Settings map[string]any `json:"settings"`
|
||||
} `json:"outbounds"`
|
||||
}
|
||||
if err := json.Unmarshal([]byte(storedTemplate(t)), &cfg); err != nil || len(cfg.Outbounds) != 1 {
|
||||
t.Fatalf("stored template unreadable (%v)", err)
|
||||
}
|
||||
if _, kept := cfg.Outbounds[0].Settings["domainStrategy"]; kept || cfg.Outbounds[0].TargetStrategy != "ForceIPv4v6" {
|
||||
t.Fatalf("stored outbound was not rewritten: %+v", cfg.Outbounds[0])
|
||||
}
|
||||
|
||||
// The history gate keeps a hand-edited template from being rewritten on every restart.
|
||||
seedTemplate(t, legacy)
|
||||
if err := runSeeders(false); err != nil {
|
||||
t.Fatalf("runSeeders: %v", err)
|
||||
}
|
||||
if got := storedTemplate(t); got != legacy {
|
||||
t.Errorf("a completed seeder rewrote the template again: %s", got)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,116 @@
|
||||
package database
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
||||
)
|
||||
|
||||
const legacyXdnsFinalmask = `{"udp":[{"type":"xdns","settings":{"domains":["t.example.com"]}}]}`
|
||||
|
||||
// assertXdnsUpgraded fails unless the finalmask's xdns domains are objects, the only
|
||||
// shape xray-core 26.9.30 parses.
|
||||
func assertXdnsUpgraded(t *testing.T, where string, finalmask any) {
|
||||
t.Helper()
|
||||
fm, _ := finalmask.(map[string]any)
|
||||
udp, _ := fm["udp"].([]any)
|
||||
if len(udp) != 1 {
|
||||
t.Fatalf("%s: udp masks = %v, want one", where, fm["udp"])
|
||||
}
|
||||
mask, _ := udp[0].(map[string]any)
|
||||
settings, _ := mask["settings"].(map[string]any)
|
||||
domains, _ := settings["domains"].([]any)
|
||||
if len(domains) != 1 {
|
||||
t.Fatalf("%s: domains = %v, want one entry", where, settings["domains"])
|
||||
}
|
||||
domain, ok := domains[0].(map[string]any)
|
||||
if !ok || domain["name"] != "t.example.com" {
|
||||
t.Fatalf("%s: domain = %#v, want an object named t.example.com", where, domains[0])
|
||||
}
|
||||
}
|
||||
|
||||
func TestXdnsFinalmaskSeederUpgradesEveryStoredMask(t *testing.T) {
|
||||
initMigrateDB(t)
|
||||
ib := seedInboundWithStream(t, "xdns-in", 5353,
|
||||
`{"network":"kcp","security":"none","finalmask":`+legacyXdnsFinalmask+`}`)
|
||||
host := &model.Host{InboundId: ib.Id, Remark: "h", Address: "cdn.example.com", Port: 53, FinalMask: legacyXdnsFinalmask}
|
||||
if err := GetDB().Create(host).Error; err != nil {
|
||||
t.Fatalf("create host: %v", err)
|
||||
}
|
||||
seedTemplate(t, `{"outbounds":[{"protocol":"vless","tag":"dns-tunnel","settings":{},"streamSettings":{"network":"kcp","finalmask":`+legacyXdnsFinalmask+`}}]}`)
|
||||
if err := GetDB().Create(&model.Setting{Key: "subJsonFinalMask", Value: legacyXdnsFinalmask}).Error; err != nil {
|
||||
t.Fatalf("seed subJsonFinalMask: %v", err)
|
||||
}
|
||||
sub := &model.OutboundSubscription{
|
||||
Remark: "donor", Url: "https://donor.example.com/sub",
|
||||
LastFetchedOutbounds: `[{"protocol":"vless","tag":"sub-1","settings":{},"streamSettings":{"network":"kcp","finalmask":` + legacyXdnsFinalmask + `}}]`,
|
||||
}
|
||||
if err := GetDB().Create(sub).Error; err != nil {
|
||||
t.Fatalf("create outbound subscription: %v", err)
|
||||
}
|
||||
if err := GetDB().Where("seeder_name = ?", "XdnsFinalmaskObjectsFix").
|
||||
Delete(&model.HistoryOfSeeders{}).Error; err != nil {
|
||||
t.Fatalf("clear seeder history: %v", err)
|
||||
}
|
||||
|
||||
if err := runSeeders(false); err != nil {
|
||||
t.Fatalf("runSeeders: %v", err)
|
||||
}
|
||||
|
||||
var stored model.Inbound
|
||||
if err := GetDB().First(&stored, ib.Id).Error; err != nil {
|
||||
t.Fatalf("reload inbound: %v", err)
|
||||
}
|
||||
var stream map[string]any
|
||||
if err := json.Unmarshal([]byte(stored.StreamSettings), &stream); err != nil {
|
||||
t.Fatalf("inbound stream is not JSON: %v", err)
|
||||
}
|
||||
assertXdnsUpgraded(t, "inbound stream", stream["finalmask"])
|
||||
|
||||
var storedHost model.Host
|
||||
if err := GetDB().First(&storedHost, host.Id).Error; err != nil {
|
||||
t.Fatalf("reload host: %v", err)
|
||||
}
|
||||
var hostMask any
|
||||
if err := json.Unmarshal([]byte(storedHost.FinalMask), &hostMask); err != nil {
|
||||
t.Fatalf("host finalMask is not JSON: %v", err)
|
||||
}
|
||||
assertXdnsUpgraded(t, "host finalMask", hostMask)
|
||||
|
||||
var template struct {
|
||||
Outbounds []struct {
|
||||
StreamSettings struct {
|
||||
Finalmask any `json:"finalmask"`
|
||||
} `json:"streamSettings"`
|
||||
} `json:"outbounds"`
|
||||
}
|
||||
if err := json.Unmarshal([]byte(storedTemplate(t)), &template); err != nil || len(template.Outbounds) != 1 {
|
||||
t.Fatalf("stored template unreadable (%v)", err)
|
||||
}
|
||||
assertXdnsUpgraded(t, "template outbound", template.Outbounds[0].StreamSettings.Finalmask)
|
||||
|
||||
var subMask model.Setting
|
||||
if err := GetDB().Where("key = ?", "subJsonFinalMask").First(&subMask).Error; err != nil {
|
||||
t.Fatalf("reload subJsonFinalMask: %v", err)
|
||||
}
|
||||
var subFinalmask any
|
||||
if err := json.Unmarshal([]byte(subMask.Value), &subFinalmask); err != nil {
|
||||
t.Fatalf("subJsonFinalMask is not JSON: %v", err)
|
||||
}
|
||||
assertXdnsUpgraded(t, "subJsonFinalMask", subFinalmask)
|
||||
|
||||
var storedSub model.OutboundSubscription
|
||||
if err := GetDB().First(&storedSub, sub.Id).Error; err != nil {
|
||||
t.Fatalf("reload outbound subscription: %v", err)
|
||||
}
|
||||
var cached []struct {
|
||||
StreamSettings struct {
|
||||
Finalmask any `json:"finalmask"`
|
||||
} `json:"streamSettings"`
|
||||
}
|
||||
if err := json.Unmarshal([]byte(storedSub.LastFetchedOutbounds), &cached); err != nil || len(cached) != 1 {
|
||||
t.Fatalf("cached subscription outbounds unreadable (%v)", err)
|
||||
}
|
||||
assertXdnsUpgraded(t, "cached subscription outbound", cached[0].StreamSettings.Finalmask)
|
||||
}
|
||||
@@ -15,6 +15,8 @@ import (
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/maskcompat"
|
||||
)
|
||||
|
||||
// Outbound is the minimal shape we emit for each parsed link.
|
||||
@@ -766,6 +768,7 @@ func applyFinalMask(stream map[string]any, p url.Values) {
|
||||
var parsed any
|
||||
if json.Unmarshal([]byte(fm), &parsed) == nil {
|
||||
sanitizeFinalMaskQuicParams(parsed)
|
||||
maskcompat.UpgradeLegacyXdns(parsed)
|
||||
stream["finalmask"] = parsed
|
||||
}
|
||||
}
|
||||
|
||||
@@ -87,6 +87,25 @@ func TestParseVlessLink_FinalMaskQuicParamsSanitized(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// A panel older than xray-core 26.9.30 shares its xdns mask in the string lists the
|
||||
// core no longer parses; imported verbatim, the outbound would fail the whole config.
|
||||
func TestParseLink_UpgradesLegacyXdnsFinalMask(t *testing.T) {
|
||||
fm := url.QueryEscape(`{"udp":[{"type":"xdns","settings":{"resolvers":["t.example.com+udp://8.8.8.8:53"]}}]}`)
|
||||
res, err := ParseLink("vless://uuid@1.2.3.4:53?type=kcp&security=none&fm=" + fm + "#dns")
|
||||
if err != nil {
|
||||
t.Fatalf("parse vless with fm: %v", err)
|
||||
}
|
||||
stream, _ := res.Outbound["streamSettings"].(map[string]any)
|
||||
got, err := json.Marshal(stream["finalmask"])
|
||||
if err != nil {
|
||||
t.Fatalf("marshal finalmask: %v", err)
|
||||
}
|
||||
want := `{"udp":[{"settings":{"domains":[{"edns0":1232,"name":"t.example.com","types":[16]}],"resolvers":[{"settings":{"addr":"8.8.8.8:53"},"type":"udp"}]},"type":"xdns"}]}`
|
||||
if string(got) != want {
|
||||
t.Fatalf("imported finalmask\n got: %s\nwant: %s", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSanitizeFinalMaskQuicParams_ClampsAndRejects(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
|
||||
@@ -0,0 +1,107 @@
|
||||
package maskcompat
|
||||
|
||||
import "strings"
|
||||
|
||||
// legacyXdnsEDNS0 is the EDNS0 payload the pre-26.9.30 xdns always negotiated;
|
||||
// the object shape makes it opt-in and caps every answer at 512 bytes without it.
|
||||
const legacyXdnsEDNS0 = 1232
|
||||
|
||||
var legacyXdnsRecordTypes = map[string]int{"": 16, "txt": 16, "a": 1, "aaaa": 28}
|
||||
|
||||
// UpgradeLegacyXdns rewrites xdns masks from the string lists xray-core 26.9.30
|
||||
// (#6718) no longer parses into its object lists; one legacy mask fails the whole config.
|
||||
func UpgradeLegacyXdns(finalmask any) bool {
|
||||
fm, _ := finalmask.(map[string]any)
|
||||
masks, _ := fm["udp"].([]any)
|
||||
changed := false
|
||||
for _, entry := range masks {
|
||||
mask, _ := entry.(map[string]any)
|
||||
if maskType, _ := mask["type"].(string); !strings.EqualFold(maskType, "xdns") {
|
||||
continue
|
||||
}
|
||||
if settings, ok := mask["settings"].(map[string]any); ok && upgradeLegacyXdnsSettings(settings) {
|
||||
changed = true
|
||||
}
|
||||
}
|
||||
return changed
|
||||
}
|
||||
|
||||
// upgradeLegacyXdnsSettings maps a bare name to TXT, the type legacy clients queried by
|
||||
// default, and drops entries the old core refused instead of keeping them to fail again.
|
||||
func upgradeLegacyXdnsSettings(settings map[string]any) bool {
|
||||
rawDomains, _ := settings["domains"].([]any)
|
||||
rawResolvers, _ := settings["resolvers"].([]any)
|
||||
if !hasLegacyXdnsEntry(rawDomains) && !hasLegacyXdnsEntry(rawResolvers) {
|
||||
return false
|
||||
}
|
||||
domains := make([]any, 0, len(rawDomains)+len(rawResolvers))
|
||||
listed := map[string]bool{}
|
||||
addDomain := func(domain map[string]any) {
|
||||
key, _ := domain["name"].(string)
|
||||
key = strings.ToLower(key)
|
||||
if key != "" && listed[key] {
|
||||
return
|
||||
}
|
||||
listed[key] = true
|
||||
domains = append(domains, domain)
|
||||
}
|
||||
for _, entry := range rawDomains {
|
||||
switch value := entry.(type) {
|
||||
case map[string]any:
|
||||
addDomain(value)
|
||||
case string:
|
||||
if domain, ok := legacyXdnsDomain(value); ok {
|
||||
addDomain(domain)
|
||||
}
|
||||
}
|
||||
}
|
||||
resolvers := make([]any, 0, len(rawResolvers))
|
||||
for _, entry := range rawResolvers {
|
||||
spec, ok := entry.(string)
|
||||
if !ok {
|
||||
resolvers = append(resolvers, entry)
|
||||
continue
|
||||
}
|
||||
head, addr, found := strings.Cut(spec, "+udp://")
|
||||
addr = strings.TrimSpace(addr)
|
||||
domain, valid := legacyXdnsDomain(head)
|
||||
if !found || addr == "" || !valid {
|
||||
continue
|
||||
}
|
||||
addDomain(domain)
|
||||
resolvers = append(resolvers, map[string]any{
|
||||
"type": "udp",
|
||||
"settings": map[string]any{"addr": addr},
|
||||
})
|
||||
}
|
||||
settings["domains"] = domains
|
||||
if len(resolvers) > 0 {
|
||||
settings["resolvers"] = resolvers
|
||||
} else {
|
||||
delete(settings, "resolvers")
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
// legacyXdnsDomain parses the "name[:txt|a|aaaa]" spec both legacy lists used.
|
||||
func legacyXdnsDomain(spec string) (map[string]any, bool) {
|
||||
name, method := strings.TrimSpace(spec), ""
|
||||
if i := strings.LastIndex(name, ":"); i >= 0 {
|
||||
name, method = name[:i], strings.ToLower(name[i+1:])
|
||||
}
|
||||
name = strings.Trim(name, ".")
|
||||
recordType, known := legacyXdnsRecordTypes[method]
|
||||
if name == "" || !known {
|
||||
return nil, false
|
||||
}
|
||||
return map[string]any{"name": name, "types": []any{recordType}, "edns0": legacyXdnsEDNS0}, true
|
||||
}
|
||||
|
||||
func hasLegacyXdnsEntry(values []any) bool {
|
||||
for _, value := range values {
|
||||
if _, ok := value.(string); ok {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
@@ -0,0 +1,101 @@
|
||||
package maskcompat
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
|
||||
"github.com/xtls/xray-core/infra/conf"
|
||||
)
|
||||
|
||||
// buildXdnsSettings runs an xdns mask's settings through conf.XDNS, the loader
|
||||
// the core calls at startup, so the test's verdict is the core's verdict.
|
||||
func buildXdnsSettings(t *testing.T, settings any) error {
|
||||
t.Helper()
|
||||
raw, err := json.Marshal(settings)
|
||||
if err != nil {
|
||||
t.Fatalf("marshal xdns settings: %v", err)
|
||||
}
|
||||
var mask conf.XDNS
|
||||
if err := json.Unmarshal(raw, &mask); err != nil {
|
||||
return err
|
||||
}
|
||||
_, err = mask.Build()
|
||||
return err
|
||||
}
|
||||
|
||||
func TestUpgradeLegacyXdns(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
mask string
|
||||
want string
|
||||
}{
|
||||
{
|
||||
name: "bare server domain becomes TXT with the legacy EDNS0 size",
|
||||
mask: `{"type":"xdns","settings":{"domains":["t.example.com"]}}`,
|
||||
want: `{"domains":[{"edns0":1232,"name":"t.example.com","types":[16]}]}`,
|
||||
},
|
||||
{
|
||||
name: "method suffixes map to their record types",
|
||||
mask: `{"type":"xdns","settings":{"domains":["a.example.com:a","q.example.com:AAAA","t.example.com:txt"]}}`,
|
||||
want: `{"domains":[{"edns0":1232,"name":"a.example.com","types":[1]},{"edns0":1232,"name":"q.example.com","types":[28]},{"edns0":1232,"name":"t.example.com","types":[16]}]}`,
|
||||
},
|
||||
{
|
||||
name: "client resolver splits into its domain and a udp resolver",
|
||||
mask: `{"type":"XDNS","settings":{"resolvers":["t.example.com:a+udp://8.8.8.8:53"]}}`,
|
||||
want: `{"domains":[{"edns0":1232,"name":"t.example.com","types":[1]}],"resolvers":[{"settings":{"addr":"8.8.8.8:53"},"type":"udp"}]}`,
|
||||
},
|
||||
{
|
||||
name: "a resolver for an already listed domain adds no duplicate",
|
||||
mask: `{"type":"xdns","settings":{"domains":["t.example.com"],"resolvers":["T.example.com+udp://1.1.1.1:53"]}}`,
|
||||
want: `{"domains":[{"edns0":1232,"name":"t.example.com","types":[16]}],"resolvers":[{"settings":{"addr":"1.1.1.1:53"},"type":"udp"}]}`,
|
||||
},
|
||||
{
|
||||
name: "entries the old core refused are dropped",
|
||||
mask: `{"type":"xdns","settings":{"domains":["t.example.com","m.example.com:mx"],"resolvers":["1.1.1.1:53"]}}`,
|
||||
want: `{"domains":[{"edns0":1232,"name":"t.example.com","types":[16]}]}`,
|
||||
},
|
||||
}
|
||||
for _, tc := range tests {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
var mask map[string]any
|
||||
if err := json.Unmarshal([]byte(tc.mask), &mask); err != nil {
|
||||
t.Fatalf("unmarshal mask: %v", err)
|
||||
}
|
||||
if err := buildXdnsSettings(t, mask["settings"]); err == nil {
|
||||
t.Fatal("the core accepted the legacy string shape; the upgrade is no longer needed")
|
||||
}
|
||||
finalmask := map[string]any{"udp": []any{mask}}
|
||||
if !UpgradeLegacyXdns(finalmask) {
|
||||
t.Fatal("UpgradeLegacyXdns reported no change for a legacy mask")
|
||||
}
|
||||
got, err := json.Marshal(mask["settings"])
|
||||
if err != nil {
|
||||
t.Fatalf("marshal upgraded settings: %v", err)
|
||||
}
|
||||
if string(got) != tc.want {
|
||||
t.Fatalf("upgraded settings\n got: %s\nwant: %s", got, tc.want)
|
||||
}
|
||||
if err := buildXdnsSettings(t, mask["settings"]); err != nil {
|
||||
t.Fatalf("the core refuses the upgraded settings: %v", err)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestUpgradeLegacyXdnsLeavesCurrentShapeAlone(t *testing.T) {
|
||||
const current = `{"udp":[{"type":"xdns","settings":{"domains":[{"name":"t.example.com","types":[16,28],"edns0":1232}],"resolvers":[{"type":"tcp","settings":{"addr":"8.8.8.8:53"}}],"extraPoll":2}},{"type":"salamander","settings":{"password":"x"}}]}`
|
||||
var finalmask map[string]any
|
||||
if err := json.Unmarshal([]byte(current), &finalmask); err != nil {
|
||||
t.Fatalf("unmarshal finalmask: %v", err)
|
||||
}
|
||||
if UpgradeLegacyXdns(finalmask) {
|
||||
t.Fatal("UpgradeLegacyXdns rewrote a mask that is already in the object shape")
|
||||
}
|
||||
var want map[string]any
|
||||
_ = json.Unmarshal([]byte(current), &want)
|
||||
got, _ := json.Marshal(finalmask)
|
||||
wantJSON, _ := json.Marshal(want)
|
||||
if string(got) != string(wantJSON) {
|
||||
t.Fatalf("finalmask changed\n got: %s\nwant: %s", got, wantJSON)
|
||||
}
|
||||
}
|
||||
@@ -23,6 +23,7 @@ import (
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/mtproto"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/tuic"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/common"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/maskcompat"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/netsafe"
|
||||
wgutil "github.com/mhsanaei/3x-ui/v3/internal/util/wireguard"
|
||||
|
||||
@@ -654,6 +655,27 @@ func (s *InboundService) normalizeStreamSettings(inbound *model.Inbound) {
|
||||
return
|
||||
}
|
||||
inbound.StreamSettings = canonicalizeStreamNetworkKey(inbound.StreamSettings)
|
||||
inbound.StreamSettings = canonicalizeLegacyXdnsMasks(inbound.StreamSettings)
|
||||
}
|
||||
|
||||
// canonicalizeLegacyXdnsMasks stores an xdns mask posted in the pre-26.9.30 string
|
||||
// lists in the object shape the core parses, as GetXrayConfig would heal it anyway.
|
||||
func canonicalizeLegacyXdnsMasks(streamSettings string) string {
|
||||
if streamSettings == "" {
|
||||
return streamSettings
|
||||
}
|
||||
var stream map[string]any
|
||||
if err := json.Unmarshal([]byte(streamSettings), &stream); err != nil {
|
||||
return streamSettings
|
||||
}
|
||||
if !maskcompat.UpgradeLegacyXdns(stream["finalmask"]) {
|
||||
return streamSettings
|
||||
}
|
||||
out, err := json.MarshalIndent(stream, "", " ")
|
||||
if err != nil {
|
||||
return streamSettings
|
||||
}
|
||||
return string(out)
|
||||
}
|
||||
|
||||
// canonicalizeStreamNetworkKey rewrites a streamSettings JSON that names its
|
||||
|
||||
@@ -0,0 +1,91 @@
|
||||
package service
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/database"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
||||
)
|
||||
|
||||
const legacyXdnsStream = `{"network":"kcp","security":"none","kcpSettings":{"mtu":900},"finalmask":{"udp":[{"type":"xdns","settings":{"domains":["t.example.com"]}}]}}`
|
||||
|
||||
func firstXdnsDomain(t *testing.T, stream map[string]any) any {
|
||||
t.Helper()
|
||||
finalmask, _ := stream["finalmask"].(map[string]any)
|
||||
udp, _ := finalmask["udp"].([]any)
|
||||
if len(udp) != 1 {
|
||||
t.Fatalf("finalmask.udp = %v, want one mask", finalmask["udp"])
|
||||
}
|
||||
mask, _ := udp[0].(map[string]any)
|
||||
settings, _ := mask["settings"].(map[string]any)
|
||||
domains, _ := settings["domains"].([]any)
|
||||
if len(domains) != 1 {
|
||||
t.Fatalf("xdns domains = %v, want one", settings["domains"])
|
||||
}
|
||||
return domains[0]
|
||||
}
|
||||
|
||||
// An API client can still post the pre-26.9.30 string lists; stored as sent they would
|
||||
// reach the sub links and the form in a shape the core no longer parses.
|
||||
func TestAddInbound_StoresXdnsMaskInObjectShape(t *testing.T) {
|
||||
setupConflictDB(t)
|
||||
in := &model.Inbound{
|
||||
Tag: "in-45300-kcp", Enable: true, Listen: "0.0.0.0", Port: 45300, Protocol: model.VLESS,
|
||||
Settings: `{"clients":[],"decryption":"none"}`, StreamSettings: legacyXdnsStream,
|
||||
}
|
||||
if _, _, err := (&InboundService{}).AddInbound(in); err != nil {
|
||||
t.Fatalf("AddInbound: %v", err)
|
||||
}
|
||||
|
||||
var stored model.Inbound
|
||||
if err := database.GetDB().Where("tag = ?", "in-45300-kcp").First(&stored).Error; err != nil {
|
||||
t.Fatalf("reload: %v", err)
|
||||
}
|
||||
var stream map[string]any
|
||||
if err := json.Unmarshal([]byte(stored.StreamSettings), &stream); err != nil {
|
||||
t.Fatalf("stored stream is not JSON: %v", err)
|
||||
}
|
||||
domain, ok := firstXdnsDomain(t, stream).(map[string]any)
|
||||
if !ok || domain["name"] != "t.example.com" {
|
||||
t.Fatalf("stored xdns domain = %#v, want an object named t.example.com", firstXdnsDomain(t, stream))
|
||||
}
|
||||
}
|
||||
|
||||
// A row that never went through the save path (restored backup, node sync, direct DB
|
||||
// edit) must still reach the core in a shape it builds, or it keeps every inbound down.
|
||||
func TestGetXrayConfig_UpgradesLegacyXdnsMask(t *testing.T) {
|
||||
setupConflictDB(t)
|
||||
seedInboundConflict(t, "in-45301-kcp", "127.0.0.1", 45301, model.VLESS,
|
||||
legacyXdnsStream, `{"clients":[],"decryption":"none"}`)
|
||||
|
||||
var legacy map[string]any
|
||||
if err := json.Unmarshal([]byte(`{"tag":"in-45301-kcp","listen":"127.0.0.1","port":45301,"protocol":"vless",
|
||||
"settings":{"clients":[],"decryption":"none"},"streamSettings":`+legacyXdnsStream+`}`), &legacy); err != nil {
|
||||
t.Fatalf("decode legacy inbound: %v", err)
|
||||
}
|
||||
if err := buildGoldenInbound(t, legacy); err == nil {
|
||||
t.Fatal("xray-core accepted the legacy xdns lists; the heal is no longer needed")
|
||||
}
|
||||
|
||||
cfg, err := (&XrayService{}).GetXrayConfig()
|
||||
if err != nil {
|
||||
t.Fatalf("GetXrayConfig: %v", err)
|
||||
}
|
||||
for i := range cfg.InboundConfigs {
|
||||
if cfg.InboundConfigs[i].Tag != "in-45301-kcp" {
|
||||
continue
|
||||
}
|
||||
raw, err := json.Marshal(cfg.InboundConfigs[i])
|
||||
if err != nil {
|
||||
t.Fatalf("marshal emitted inbound: %v", err)
|
||||
}
|
||||
var emitted map[string]any
|
||||
if err := json.Unmarshal(raw, &emitted); err != nil {
|
||||
t.Fatalf("decode emitted inbound: %v", err)
|
||||
}
|
||||
assertXrayAccepts(t, "the healed xdns inbound", buildGoldenInbound(t, emitted))
|
||||
return
|
||||
}
|
||||
t.Fatal("inbound in-45301-kcp not found in the generated config")
|
||||
}
|
||||
@@ -17,6 +17,7 @@ import (
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/logger"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/json_util"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/util/maskcompat"
|
||||
"github.com/mhsanaei/3x-ui/v3/internal/xray"
|
||||
|
||||
"go.uber.org/atomic"
|
||||
@@ -366,6 +367,9 @@ func (s *XrayService) GetXrayConfig() (*xray.Config, error) {
|
||||
logger.Warningf("Inbound %q: dropping %d XMC finalmask mask(s) without complete Minecraft profiles — reconfigure them to restore the obfuscation (see XTLS/Xray-core#6487)", inbound.Tag, dropped)
|
||||
}
|
||||
|
||||
// A row that skipped the save path can still carry the pre-26.9.30 xdns lists.
|
||||
maskcompat.UpgradeLegacyXdns(stream["finalmask"])
|
||||
|
||||
// xray-core v26.6.22 (#6258) renamed the XHTTP session keys and
|
||||
// kept no fallback. Lift legacy sessionPlacement/sessionKey onto the
|
||||
// new names here so inbounds stored before the rename keep working
|
||||
|
||||
+28
-2
@@ -9,6 +9,7 @@ import (
|
||||
"fmt"
|
||||
"math"
|
||||
"net"
|
||||
"net/netip"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"regexp"
|
||||
@@ -182,8 +183,33 @@ func ValidateOutboundConfig(outbound []byte) error {
|
||||
if err := json.Unmarshal(outbound, detour); err != nil {
|
||||
return err
|
||||
}
|
||||
_, err := detour.Build()
|
||||
return err
|
||||
built, err := detour.Build()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return validateWireguardRemoteDNS(built.ProxySettings)
|
||||
}
|
||||
|
||||
// validateWireguardRemoteDNS refuses what conf.Build() lets through but the core feeds to
|
||||
// netip.MustParseAddr at startup: a non-IP remoteDNS entry, like "local" before 26.9.30.
|
||||
func validateWireguardRemoteDNS(settings *serial.TypedMessage) error {
|
||||
if settings == nil {
|
||||
return nil
|
||||
}
|
||||
instance, err := settings.GetInstance()
|
||||
if err != nil {
|
||||
return nil
|
||||
}
|
||||
device, ok := instance.(*wireguard.DeviceConfig)
|
||||
if !ok || !device.IsClient {
|
||||
return nil
|
||||
}
|
||||
for _, server := range device.DNS {
|
||||
if _, err := netip.ParseAddr(server); err != nil {
|
||||
return common.NewErrorf("wireguard remoteDNS entry %q is not an IP address", server)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// AddOutbound adds a new outbound configuration to the Xray core via gRPC.
|
||||
|
||||
@@ -40,3 +40,28 @@ func TestValidateOutboundConfig_RejectsUnencryptedPublicVless(t *testing.T) {
|
||||
t.Fatalf("a TLS-secured public vless outbound must stay valid, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// The core feeds remoteDNS to netip.MustParseAddr when it creates the outbound, so a
|
||||
// non-IP entry ("local" until 26.9.30) panics it at startup; conf.Build() lets it through.
|
||||
func TestValidateOutboundConfig_RejectsWireguardRemoteDNSThatIsNotAnIP(t *testing.T) {
|
||||
outbound := func(remoteDNS string) []byte {
|
||||
return []byte(`{
|
||||
"protocol": "wireguard",
|
||||
"settings": {
|
||||
"secretKey": "yAnz5TF+lXXJte14tji3zlMNq+hd2rYUIgJBgB3fBmk=",
|
||||
"address": ["10.0.0.2/32"],
|
||||
"peers": [{"publicKey": "xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=", "endpoint": "162.159.192.1:2408"}],
|
||||
"remoteDNS": ` + remoteDNS + `
|
||||
}
|
||||
}`)
|
||||
}
|
||||
for _, rejected := range []string{`["local"]`, `["1.1.1.1", "dns.google"]`} {
|
||||
err := ValidateOutboundConfig(outbound(rejected))
|
||||
if err == nil || !strings.Contains(err.Error(), "remoteDNS") {
|
||||
t.Errorf("remoteDNS %s: want a remoteDNS refusal, got %v", rejected, err)
|
||||
}
|
||||
}
|
||||
if err := ValidateOutboundConfig(outbound(`["1.1.1.1", "2606:4700:4700::1111"]`)); err != nil {
|
||||
t.Fatalf("IP remoteDNS entries must stay valid, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user