fix(inbound): reject finalmask + REALITY combo (crashes Xray-core) (#5861)

* fix(inbound): reject finalmask configured together with REALITY security

finalmask wraps the connection before REALITY's own handshake takes
over (TcpmaskManager.WrapListener -> WrapConnServer runs at Accept()
time, ahead of reality.Server()). reality.Server() does an unchecked
type assertion assuming a raw *net.TCPConn; with finalmask in front,
that assertion panics and takes down the entire xray-core process on
the very first connection to the inbound - not just that connection.

Upstream (XTLS/Xray-core#6453) confirmed this will be documented as
unsupported rather than made graceful, so the panel needs to stop this
combination from being saved rather than relying on docs.

AddInbound/UpdateInbound now reject streamSettings with
security=reality and a non-empty finalmask.tcp/udp with a clear error
instead of letting it reach Xray.

Related: MHSanaei/3x-ui#5857

* fix(inbound): heal legacy rows and narrow the finalmask+REALITY guard

Per review feedback on #5861:

- Narrow the check to finalmask.tcp only. xray-core's TcpmaskManager
  (the thing that wraps the TCP listener ahead of REALITY's handshake,
  the actual cause of the panic) is only constructed when tcp masks
  are present; a finalmask.udp-only config never touches that accept
  path and doesn't reproduce the crash, so it shouldn't be rejected.
  Extracted the shared check into finalMaskRealityTcpMasks() so both
  the save-time guard and the config-build heal below use one
  definition of "dangerous".

- Heal already-saved bad rows in GetXrayConfig(), the same way
  liftXhttpSessionIDKeys and HealShadowsocksClientMethods heal other
  legacy data at config-build time. AddInbound/UpdateInbound only cover
  the two save paths - a row that already carries this combination
  (saved before this guard existed, synced from a node, restored from
  a backup, or edited directly in the DB) would still crash Xray-core
  on the next restart without this.

- Add end-to-end tests exercising AddInbound, UpdateInbound, and
  GetXrayConfig directly (seeding rows through the real DB) rather
  than only unit-testing the extracted helper in isolation, so a
  wiring regression in any of the three call sites gets caught.
This commit is contained in:
mrnickson-hue
2026-07-08 21:29:51 +03:00
committed by GitHub
parent e424cc0f4d
commit 7db92d6318
3 changed files with 219 additions and 0 deletions
+50
View File
@@ -530,6 +530,50 @@ func (s *InboundService) normalizeStreamSettings(inbound *model.Inbound) {
}
}
// finalMaskRealityTcpMasks returns the stream's finalmask.tcp masks when the
// stream uses REALITY security, or nil otherwise. A non-empty result means
// this stream carries the finalmask+REALITY combination that panics
// Xray-core (see https://github.com/XTLS/Xray-core/issues/6453): finalmask
// wraps the connection before REALITY's handshake ever sees it, and
// reality.Server() does an unchecked type assertion assuming a raw
// *net.TCPConn, which panics once finalmask is in front of it.
//
// Only finalmask.tcp matters here — TcpmaskManager (the thing that wraps the
// listener ahead of REALITY's handshake, in xray-core's own
// transport/internet/memory_settings.go) is only constructed when tcp masks
// are present; a finalmask.udp-only config never touches the TCP accept path
// REALITY runs on, so it doesn't reproduce this panic and shouldn't be
// rejected.
func finalMaskRealityTcpMasks(stream map[string]any) []any {
if stream["security"] != "reality" {
return nil
}
finalmask, ok := stream["finalmask"].(map[string]any)
if !ok {
return nil
}
tcp, _ := finalmask["tcp"].([]any)
return tcp
}
// validateFinalMaskRealityCombo rejects finalmask.tcp configured together
// with REALITY security at save time. Upstream has confirmed this
// combination will be documented as unsupported rather than made graceful,
// so the panel must not let it be saved.
func validateFinalMaskRealityCombo(streamSettings string) error {
if streamSettings == "" {
return nil
}
var stream map[string]any
if err := json.Unmarshal([]byte(streamSettings), &stream); err != nil {
return nil
}
if len(finalMaskRealityTcpMasks(stream)) == 0 {
return nil
}
return common.NewError("Finalmask is not supported with REALITY security — it crashes Xray-core on the first connection (see XTLS/Xray-core#6453). Remove the finalmask configuration or switch security to tls/none.")
}
// normalizeMtprotoSecret rebuilds every mtproto client's FakeTLS secret so it is
// always valid before the row is persisted, and drops the vestigial inbound-level
// secret and adTag: MTProto is multi-client, so mtg and every share link read
@@ -659,6 +703,9 @@ func (s *InboundService) normalizeMtprotoXrayPort(inbound *model.Inbound, oldSet
func (s *InboundService) AddInbound(inbound *model.Inbound) (*model.Inbound, bool, error) {
// Normalize streamSettings based on protocol
s.normalizeStreamSettings(inbound)
if err := validateFinalMaskRealityCombo(inbound.StreamSettings); err != nil {
return inbound, false, err
}
s.normalizeMtprotoSecret(inbound)
if err := s.normalizeMtprotoXrayPort(inbound, ""); err != nil {
return inbound, false, err
@@ -1082,6 +1129,9 @@ func (s *InboundService) SetInboundEnable(id int, enable bool) (bool, error) {
func (s *InboundService) UpdateInbound(inbound *model.Inbound) (*model.Inbound, bool, error) {
// Normalize streamSettings based on protocol
s.normalizeStreamSettings(inbound)
if err := validateFinalMaskRealityCombo(inbound.StreamSettings); err != nil {
return inbound, false, err
}
s.normalizeMtprotoSecret(inbound)
inbound.SubSortIndex = normalizeSubSortIndex(inbound.SubSortIndex)