mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-10-04 05:02:06 +03:00
62423cacd1
Bump xtls/xray-core to b26a91de4f (v26.9.30) and the three binary pins (DockerInit.sh, release.yml Linux + Windows) in lockstep. No deleted symbols; the sing and sing-shadowsocks indirect deps drop out with the SS2022 rewrite. XDNS finalmask (#6718) replaced its string lists with objects: domains are {name, types, edns0, lenLimit, labelLimit} and client resolvers {type, settings.addr}. The loader no longer parses the old lists, so a single stored xdns mask keeps the whole core from starting. The new leaf package internal/util/maskcompat converts them: "name[:type]" becomes a domain and "name[:type]+udp://addr" a domain plus a udp resolver. A bare name maps to TXT, the type legacy clients queried by default, and each converted domain keeps the 1232-byte EDNS0 the old code always used (without it the server caps answers at 512). It runs from: - the XdnsFinalmaskObjectsFix seeder, over inbound streams, hosts, the xray template, the global sub-JSON mask and cached subscription outbounds; - inbound save (normalizeStreamSettings) and GetXrayConfig, for rows that never went through the seeder; - both link importers, since fm= from an older panel carries the lists. The finalmask form edits the object shape (every key needs a registered field, or the finalmask watch drops it on save) and lifts legacy masks on open. The udp-mask golden fixture moves to the object shape, which TestGoldenStreamFixturesBuildInXray now builds through the core. The wire format changed as well, so pre-upgrade clients need the new core. WireGuard outbound (#6771) dropped settings.domainStrategy and the remoteDNS "local" mode. The endpoint lookup now follows sockopt.domainStrategy and in-tunnel targets the outbound's targetStrategy. The old key is silently ignored, which undid the IPv4-first endpoint lookup the WARP outbound depends on (#5205), and "local" now panics the core at startup because remoteDNS goes through netip.MustParseAddr. The WireguardDomainStrategyFix seeder moves a stored family preference to both keys (a value already set wins) and turns "local" into targetStrategy; the outbound form lifts legacy rows the same way and drops its select, the WARP modal writes the new placement, and the inbound form loses a field the server never read. ValidateOutboundConfig now refuses a non-IP remoteDNS entry, which conf.Build() lets through, on template save and for outbound subscriptions. Noise finalmask items accept type "exp" (#6862), a tag expression. The form offers it for noise items only: header-custom items go through the core's PraseByteSlice, which refuses it. TUN gained autoSystemDnsToGateway (Linux) and autoSystemWfpBlockLeak (Windows). Both pass through the settings schema so a value set in JSON survives the next form save. MASQUE (inbound, outbound, transport) and the XDRIVE transport are new protocols the panel does not offer yet; their new loader refusals only cover configs the panel never generates. The FakeDNS IPv6 pool default, the SS2022 rewrite (same gRPC account; emails are now deduped case-insensitively, as the panel already does), the restored udphop interval default and the rest change no panel-facing config.
68 lines
2.8 KiB
Go
68 lines
2.8 KiB
Go
package xray
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// TestValidateOutboundConfig_RejectsUnencryptedPublicVless covers xray-core
|
|
// v26.7.11's refusal to build an unencrypted vless outbound to a public
|
|
// address — the check now runs in-process, so the panel can surface it before
|
|
// a config reaches the core and bricks startup. A private-address outbound and
|
|
// a TLS outbound stay valid.
|
|
func TestValidateOutboundConfig_RejectsUnencryptedPublicVless(t *testing.T) {
|
|
publicPlaintext := `{
|
|
"protocol": "vless",
|
|
"settings": {"address": "1.2.3.4", "port": 443, "id": "b831381d-6324-4d53-ad4f-8cda48b30811", "encryption": "none"},
|
|
"streamSettings": {"network": "tcp", "security": "none"}
|
|
}`
|
|
if err := ValidateOutboundConfig([]byte(publicPlaintext)); err == nil {
|
|
t.Fatal("expected a public unencrypted vless outbound to be rejected")
|
|
} else if !strings.Contains(err.Error(), "prohibited") {
|
|
t.Fatalf("expected a prohibition error, got: %v", err)
|
|
}
|
|
|
|
privatePlaintext := `{
|
|
"protocol": "vless",
|
|
"settings": {"address": "10.0.0.1", "port": 443, "id": "b831381d-6324-4d53-ad4f-8cda48b30811", "encryption": "none"},
|
|
"streamSettings": {"network": "tcp", "security": "none"}
|
|
}`
|
|
if err := ValidateOutboundConfig([]byte(privatePlaintext)); err != nil {
|
|
t.Fatalf("a private-address plaintext vless outbound must stay valid, got: %v", err)
|
|
}
|
|
|
|
publicTLS := `{
|
|
"protocol": "vless",
|
|
"settings": {"address": "1.2.3.4", "port": 443, "id": "b831381d-6324-4d53-ad4f-8cda48b30811", "encryption": "none"},
|
|
"streamSettings": {"network": "tcp", "security": "tls", "tlsSettings": {"serverName": "example.com"}}
|
|
}`
|
|
if err := ValidateOutboundConfig([]byte(publicTLS)); err != nil {
|
|
t.Fatalf("a TLS-secured public vless outbound must stay valid, got: %v", err)
|
|
}
|
|
}
|
|
|
|
// The core feeds remoteDNS to netip.MustParseAddr when it creates the outbound, so a
|
|
// non-IP entry ("local" until 26.9.30) panics it at startup; conf.Build() lets it through.
|
|
func TestValidateOutboundConfig_RejectsWireguardRemoteDNSThatIsNotAnIP(t *testing.T) {
|
|
outbound := func(remoteDNS string) []byte {
|
|
return []byte(`{
|
|
"protocol": "wireguard",
|
|
"settings": {
|
|
"secretKey": "yAnz5TF+lXXJte14tji3zlMNq+hd2rYUIgJBgB3fBmk=",
|
|
"address": ["10.0.0.2/32"],
|
|
"peers": [{"publicKey": "xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=", "endpoint": "162.159.192.1:2408"}],
|
|
"remoteDNS": ` + remoteDNS + `
|
|
}
|
|
}`)
|
|
}
|
|
for _, rejected := range []string{`["local"]`, `["1.1.1.1", "dns.google"]`} {
|
|
err := ValidateOutboundConfig(outbound(rejected))
|
|
if err == nil || !strings.Contains(err.Error(), "remoteDNS") {
|
|
t.Errorf("remoteDNS %s: want a remoteDNS refusal, got %v", rejected, err)
|
|
}
|
|
}
|
|
if err := ValidateOutboundConfig(outbound(`["1.1.1.1", "2606:4700:4700::1111"]`)); err != nil {
|
|
t.Fatalf("IP remoteDNS entries must stay valid, got: %v", err)
|
|
}
|
|
}
|