mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-25 16:52:10 +03:00
fix: port the PR #6105 review-round fixes into this fork's own AmneziaWG code
Same 8 findings fixed on upstream-pr/amneziawg, ported here since this fork's internal/amneziawg + related web/service files predate that PR branch's own fix-up commits: 1. hostRulesFingerprint now folds in a peer's IPv4 whenever ForwardedPorts is set, not only when RouteThroughXray is on, so a re-IP forces the bounce needed to move the DNAT rule too. 2. ValidateConfigValue (new, params.go) rejects control characters in server/client keys, email and I1 at save time; sanitizeConfigValue strips them defensively at .conf-render time. 3. checkForwardedPortsConflict now scopes to node_id IS NULL and takes a pre-loaded portConflictContext (loadPortConflictContext), so a port used only on another node isn't a false collision and an inbound with N clients costs one query instead of N. 4. PostDown commands are now best-effort (appendOrTrue) so an external firewall flush can't abort the rest of the teardown chain. 5. The "ip rule list | grep -q" existence check now uses grep -c >/dev/null, avoiding a pipefail/SIGPIPE false negative that could re-add a duplicate rule. 6. route_egress.go's stale "always present, no opt-in" comment corrected to describe the real RouteThroughXray-gated behavior. (This fork's genAmneziaWGLink already emits vpn://, and there's no upstream-facing docs page here, so neither needed the PR branch's Finding 6 docs/link-format changes.) 7. install.sh: Arch's ndppd install uses pacman -Sy, not -Syu, matching every other pacman call in the script; should_install_amneziawg short-circuits to yes when awg is already installed, so `x-ui update` doesn't re-prompt -- this fork's own opt-out-by-default philosophy for should_install_amneziawg is unchanged, only the redundant-reprompt behavior is fixed. 8. CollectTraffic checks pointer identity before writing back a traffic-counter baseline, so a concurrent restart's freshly-reset (empty) baseline can't be clobbered by stale pre-restart counters. sweepOrphansLocked no longer permanently disables itself on a transient os.ReadDir failure. go build/vet/test and frontend typecheck/lint/build/vitest all pass.
This commit is contained in:
+12
-1
@@ -175,7 +175,10 @@ install_ndppd() {
|
||||
dnf install -y ndppd 2>/dev/null || yum install -y ndppd 2>/dev/null || true
|
||||
;;
|
||||
arch | manjaro | parch)
|
||||
pacman -Syu --noconfirm ndppd 2>/dev/null || true
|
||||
# -Sy (not -Syu): every other pacman call in this script only
|
||||
# refreshes the package database, never does a full system
|
||||
# upgrade as a side effect of installing one package.
|
||||
pacman -Sy --noconfirm ndppd 2>/dev/null || true
|
||||
;;
|
||||
esac
|
||||
}
|
||||
@@ -219,11 +222,19 @@ enable_tproxy_support() {
|
||||
# forwarding it brings.
|
||||
#
|
||||
# should_install_amneziawg decides whether to run install_amneziawg at all.
|
||||
# Short-circuits to yes when awg is already on PATH, so `x-ui update` on a
|
||||
# host that already has it doesn't re-prompt an admin who already answered
|
||||
# this once -- install_amneziawg's own case statement would just skip the
|
||||
# actual DKMS/package work again anyway, but the interactive prompt itself
|
||||
# still fired every run, and answering "n" out of habit (since AmneziaWG is
|
||||
# already installed and working) skipped the harmless modprobe/ndppd/sysctl
|
||||
# refresh that same case statement also does unconditionally.
|
||||
# XUI_INSTALL_AMNEZIAWG=true/false answers it outright (for non-interactive/
|
||||
# cloud-init runs); otherwise an interactive install prompts (default: yes),
|
||||
# and a non-interactive one with nothing to answer the prompt defaults to
|
||||
# installing it too.
|
||||
should_install_amneziawg() {
|
||||
command -v awg &>/dev/null && return 0
|
||||
case "${XUI_INSTALL_AMNEZIAWG:-}" in
|
||||
true | TRUE | 1 | yes | y | Y) return 0 ;;
|
||||
false | FALSE | 0 | no | n | N) return 1 ;;
|
||||
|
||||
Reference in New Issue
Block a user