Files
3x-ui/internal/database/wireguard_domain_strategy_migration_test.go
T
MHSanaei 62423cacd1 feat(xray): update xray-core to v26.9.30 and adapt panel
Bump xtls/xray-core to b26a91de4f (v26.9.30) and the three binary pins
(DockerInit.sh, release.yml Linux + Windows) in lockstep. No deleted
symbols; the sing and sing-shadowsocks indirect deps drop out with the
SS2022 rewrite.

XDNS finalmask (#6718) replaced its string lists with objects: domains
are {name, types, edns0, lenLimit, labelLimit} and client resolvers
{type, settings.addr}. The loader no longer parses the old lists, so a
single stored xdns mask keeps the whole core from starting. The new leaf
package internal/util/maskcompat converts them: "name[:type]" becomes a
domain and "name[:type]+udp://addr" a domain plus a udp resolver. A bare
name maps to TXT, the type legacy clients queried by default, and each
converted domain keeps the 1232-byte EDNS0 the old code always used
(without it the server caps answers at 512). It runs from:
- the XdnsFinalmaskObjectsFix seeder, over inbound streams, hosts, the
  xray template, the global sub-JSON mask and cached subscription
  outbounds;
- inbound save (normalizeStreamSettings) and GetXrayConfig, for rows
  that never went through the seeder;
- both link importers, since fm= from an older panel carries the lists.
The finalmask form edits the object shape (every key needs a registered
field, or the finalmask watch drops it on save) and lifts legacy masks
on open. The udp-mask golden fixture moves to the object shape, which
TestGoldenStreamFixturesBuildInXray now builds through the core. The
wire format changed as well, so pre-upgrade clients need the new core.

WireGuard outbound (#6771) dropped settings.domainStrategy and the
remoteDNS "local" mode. The endpoint lookup now follows
sockopt.domainStrategy and in-tunnel targets the outbound's
targetStrategy. The old key is silently ignored, which undid the
IPv4-first endpoint lookup the WARP outbound depends on (#5205), and
"local" now panics the core at startup because remoteDNS goes through
netip.MustParseAddr. The WireguardDomainStrategyFix seeder moves a stored
family preference to both keys (a value already set wins) and turns
"local" into targetStrategy; the outbound form lifts legacy rows the same
way and drops its select, the WARP modal writes the new placement, and
the inbound form loses a field the server never read.
ValidateOutboundConfig now refuses a non-IP remoteDNS entry, which
conf.Build() lets through, on template save and for outbound
subscriptions.

Noise finalmask items accept type "exp" (#6862), a tag expression. The
form offers it for noise items only: header-custom items go through the
core's PraseByteSlice, which refuses it.

TUN gained autoSystemDnsToGateway (Linux) and autoSystemWfpBlockLeak
(Windows). Both pass through the settings schema so a value set in JSON
survives the next form save.

MASQUE (inbound, outbound, transport) and the XDRIVE transport are new
protocols the panel does not offer yet; their new loader refusals only
cover configs the panel never generates. The FakeDNS IPv6 pool default,
the SS2022 rewrite (same gRPC account; emails are now deduped
case-insensitively, as the panel already does), the restored udphop
interval default and the rest change no panel-facing config.
2026-10-02 13:54:39 +02:00

148 lines
5.6 KiB
Go

package database
import (
"encoding/json"
"strings"
"testing"
"github.com/mhsanaei/3x-ui/v3/internal/config"
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
"github.com/mhsanaei/3x-ui/v3/internal/xray"
)
const wgTestKeys = `"secretKey":"yAnz5TF+lXXJte14tji3zlMNq+hd2rYUIgJBgB3fBmk=","peers":[{"publicKey":"xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=","endpoint":"engage.cloudflareclient.com:2408"}]`
func TestRewriteWireguardDomainStrategy(t *testing.T) {
tests := []struct {
name string
outbound string
wantChanged bool
wantRoot string
wantSockopt string
wantDNS bool
}{
{
name: "the WARP default moves to both places the core now reads",
outbound: `{"protocol":"wireguard","tag":"warp","settings":{"domainStrategy":"ForceIPv4v6",` + wgTestKeys + `}}`,
wantChanged: true, wantRoot: "ForceIPv4v6", wantSockopt: "ForceIPv4v6",
},
{
name: "values the admin already set win over the legacy key",
outbound: `{"protocol":"wireguard","tag":"wg","targetStrategy":"UseIPv6","streamSettings":{"sockopt":{"domainStrategy":"UseIPv4"}},"settings":{"domainStrategy":"forceipv6",` + wgTestKeys + `}}`,
wantChanged: true, wantRoot: "UseIPv6", wantSockopt: "UseIPv4",
},
{
name: "plain ForceIP had no family preference, so only the key goes",
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"domainStrategy":"ForceIP",` + wgTestKeys + `}}`,
wantChanged: true,
},
{
name: "remoteDNS local becomes targetStrategy, which resolves with the built-in DNS",
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"domainStrategy":"ForceIPv4","remoteDNS":["local"],` + wgTestKeys + `}}`,
wantChanged: true, wantRoot: "ForceIPv4", wantSockopt: "ForceIPv4",
},
{
name: "remoteDNS local without a strategy resolves any family",
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"remoteDNS":["local"],` + wgTestKeys + `}}`,
wantChanged: true, wantRoot: "ForceIP",
},
{
name: "a strategy the old core refused is dropped rather than moved",
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"domainStrategy":"UseIPv4",` + wgTestKeys + `}}`,
wantChanged: true,
},
{
name: "IP remoteDNS entries stay",
outbound: `{"protocol":"wireguard","tag":"wg","settings":{"remoteDNS":["1.1.1.1"],` + wgTestKeys + `}}`,
wantChanged: false, wantDNS: true,
},
}
for _, tc := range tests {
t.Run(tc.name, func(t *testing.T) {
updated, changed, err := rewriteWireguardDomainStrategy(`{"outbounds":[` + tc.outbound + `]}`)
if err != nil {
t.Fatalf("rewrite: %v", err)
}
if changed != tc.wantChanged {
t.Fatalf("changed = %v, want %v", changed, tc.wantChanged)
}
var cfg struct {
Outbounds []json.RawMessage `json:"outbounds"`
}
if err := json.Unmarshal([]byte(updated), &cfg); err != nil || len(cfg.Outbounds) != 1 {
t.Fatalf("rewritten template unreadable (%v): %s", err, updated)
}
var got struct {
TargetStrategy string `json:"targetStrategy"`
StreamSettings struct {
Sockopt struct {
DomainStrategy string `json:"domainStrategy"`
} `json:"sockopt"`
} `json:"streamSettings"`
Settings map[string]any `json:"settings"`
}
if err := json.Unmarshal(cfg.Outbounds[0], &got); err != nil {
t.Fatal(err)
}
if got.TargetStrategy != tc.wantRoot {
t.Errorf("targetStrategy = %q, want %q", got.TargetStrategy, tc.wantRoot)
}
if got.StreamSettings.Sockopt.DomainStrategy != tc.wantSockopt {
t.Errorf("sockopt.domainStrategy = %q, want %q", got.StreamSettings.Sockopt.DomainStrategy, tc.wantSockopt)
}
if _, kept := got.Settings["domainStrategy"]; kept {
t.Errorf("settings.domainStrategy survived the rewrite: %s", cfg.Outbounds[0])
}
if _, kept := got.Settings["remoteDNS"]; kept != tc.wantDNS {
t.Errorf("remoteDNS kept = %v, want %v", kept, tc.wantDNS)
}
if err := xray.ValidateOutboundConfig(cfg.Outbounds[0]); err != nil {
t.Fatalf("xray-core refuses the rewritten outbound: %v", err)
}
})
}
}
func TestWireguardDomainStrategySeederRewritesStoredTemplateOnce(t *testing.T) {
t.Setenv("XUI_DB_FOLDER", t.TempDir())
if err := InitDB(config.GetDBPath()); err != nil {
if strings.Contains(err.Error(), "CGO_ENABLED=0") {
t.Skipf("sqlite needs cgo: %v", err)
}
t.Fatalf("init db: %v", err)
}
t.Cleanup(func() { _ = CloseDB() })
legacy := `{"outbounds":[{"protocol":"wireguard","tag":"warp","settings":{"domainStrategy":"ForceIPv4v6",` + wgTestKeys + `}}]}`
seedTemplate(t, legacy)
if err := db.Where("seeder_name = ?", "WireguardDomainStrategyFix").
Delete(&model.HistoryOfSeeders{}).Error; err != nil {
t.Fatalf("clear seeder history: %v", err)
}
if err := runSeeders(false); err != nil {
t.Fatalf("runSeeders: %v", err)
}
var cfg struct {
Outbounds []struct {
TargetStrategy string `json:"targetStrategy"`
Settings map[string]any `json:"settings"`
} `json:"outbounds"`
}
if err := json.Unmarshal([]byte(storedTemplate(t)), &cfg); err != nil || len(cfg.Outbounds) != 1 {
t.Fatalf("stored template unreadable (%v)", err)
}
if _, kept := cfg.Outbounds[0].Settings["domainStrategy"]; kept || cfg.Outbounds[0].TargetStrategy != "ForceIPv4v6" {
t.Fatalf("stored outbound was not rewritten: %+v", cfg.Outbounds[0])
}
// The history gate keeps a hand-edited template from being rewritten on every restart.
seedTemplate(t, legacy)
if err := runSeeders(false); err != nil {
t.Fatalf("runSeeders: %v", err)
}
if got := storedTemplate(t); got != legacy {
t.Errorf("a completed seeder rewrote the template again: %s", got)
}
}