mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-08-29 06:27:14 +00:00
fix(inbound): reject finalmask + REALITY combo (crashes Xray-core) (#5861)
* fix(inbound): reject finalmask configured together with REALITY security finalmask wraps the connection before REALITY's own handshake takes over (TcpmaskManager.WrapListener -> WrapConnServer runs at Accept() time, ahead of reality.Server()). reality.Server() does an unchecked type assertion assuming a raw *net.TCPConn; with finalmask in front, that assertion panics and takes down the entire xray-core process on the very first connection to the inbound - not just that connection. Upstream (XTLS/Xray-core#6453) confirmed this will be documented as unsupported rather than made graceful, so the panel needs to stop this combination from being saved rather than relying on docs. AddInbound/UpdateInbound now reject streamSettings with security=reality and a non-empty finalmask.tcp/udp with a clear error instead of letting it reach Xray. Related: MHSanaei/3x-ui#5857 * fix(inbound): heal legacy rows and narrow the finalmask+REALITY guard Per review feedback on #5861: - Narrow the check to finalmask.tcp only. xray-core's TcpmaskManager (the thing that wraps the TCP listener ahead of REALITY's handshake, the actual cause of the panic) is only constructed when tcp masks are present; a finalmask.udp-only config never touches that accept path and doesn't reproduce the crash, so it shouldn't be rejected. Extracted the shared check into finalMaskRealityTcpMasks() so both the save-time guard and the config-build heal below use one definition of "dangerous". - Heal already-saved bad rows in GetXrayConfig(), the same way liftXhttpSessionIDKeys and HealShadowsocksClientMethods heal other legacy data at config-build time. AddInbound/UpdateInbound only cover the two save paths - a row that already carries this combination (saved before this guard existed, synced from a node, restored from a backup, or edited directly in the DB) would still crash Xray-core on the next restart without this. - Add end-to-end tests exercising AddInbound, UpdateInbound, and GetXrayConfig directly (seeding rows through the real DB) rather than only unit-testing the extracted helper in isolation, so a wiring regression in any of the three call sites gets caught.
This commit is contained in:
@@ -530,6 +530,50 @@ func (s *InboundService) normalizeStreamSettings(inbound *model.Inbound) {
|
||||
}
|
||||
}
|
||||
|
||||
// finalMaskRealityTcpMasks returns the stream's finalmask.tcp masks when the
|
||||
// stream uses REALITY security, or nil otherwise. A non-empty result means
|
||||
// this stream carries the finalmask+REALITY combination that panics
|
||||
// Xray-core (see https://github.com/XTLS/Xray-core/issues/6453): finalmask
|
||||
// wraps the connection before REALITY's handshake ever sees it, and
|
||||
// reality.Server() does an unchecked type assertion assuming a raw
|
||||
// *net.TCPConn, which panics once finalmask is in front of it.
|
||||
//
|
||||
// Only finalmask.tcp matters here — TcpmaskManager (the thing that wraps the
|
||||
// listener ahead of REALITY's handshake, in xray-core's own
|
||||
// transport/internet/memory_settings.go) is only constructed when tcp masks
|
||||
// are present; a finalmask.udp-only config never touches the TCP accept path
|
||||
// REALITY runs on, so it doesn't reproduce this panic and shouldn't be
|
||||
// rejected.
|
||||
func finalMaskRealityTcpMasks(stream map[string]any) []any {
|
||||
if stream["security"] != "reality" {
|
||||
return nil
|
||||
}
|
||||
finalmask, ok := stream["finalmask"].(map[string]any)
|
||||
if !ok {
|
||||
return nil
|
||||
}
|
||||
tcp, _ := finalmask["tcp"].([]any)
|
||||
return tcp
|
||||
}
|
||||
|
||||
// validateFinalMaskRealityCombo rejects finalmask.tcp configured together
|
||||
// with REALITY security at save time. Upstream has confirmed this
|
||||
// combination will be documented as unsupported rather than made graceful,
|
||||
// so the panel must not let it be saved.
|
||||
func validateFinalMaskRealityCombo(streamSettings string) error {
|
||||
if streamSettings == "" {
|
||||
return nil
|
||||
}
|
||||
var stream map[string]any
|
||||
if err := json.Unmarshal([]byte(streamSettings), &stream); err != nil {
|
||||
return nil
|
||||
}
|
||||
if len(finalMaskRealityTcpMasks(stream)) == 0 {
|
||||
return nil
|
||||
}
|
||||
return common.NewError("Finalmask is not supported with REALITY security — it crashes Xray-core on the first connection (see XTLS/Xray-core#6453). Remove the finalmask configuration or switch security to tls/none.")
|
||||
}
|
||||
|
||||
// normalizeMtprotoSecret rebuilds every mtproto client's FakeTLS secret so it is
|
||||
// always valid before the row is persisted, and drops the vestigial inbound-level
|
||||
// secret and adTag: MTProto is multi-client, so mtg and every share link read
|
||||
@@ -659,6 +703,9 @@ func (s *InboundService) normalizeMtprotoXrayPort(inbound *model.Inbound, oldSet
|
||||
func (s *InboundService) AddInbound(inbound *model.Inbound) (*model.Inbound, bool, error) {
|
||||
// Normalize streamSettings based on protocol
|
||||
s.normalizeStreamSettings(inbound)
|
||||
if err := validateFinalMaskRealityCombo(inbound.StreamSettings); err != nil {
|
||||
return inbound, false, err
|
||||
}
|
||||
s.normalizeMtprotoSecret(inbound)
|
||||
if err := s.normalizeMtprotoXrayPort(inbound, ""); err != nil {
|
||||
return inbound, false, err
|
||||
@@ -1082,6 +1129,9 @@ func (s *InboundService) SetInboundEnable(id int, enable bool) (bool, error) {
|
||||
func (s *InboundService) UpdateInbound(inbound *model.Inbound) (*model.Inbound, bool, error) {
|
||||
// Normalize streamSettings based on protocol
|
||||
s.normalizeStreamSettings(inbound)
|
||||
if err := validateFinalMaskRealityCombo(inbound.StreamSettings); err != nil {
|
||||
return inbound, false, err
|
||||
}
|
||||
s.normalizeMtprotoSecret(inbound)
|
||||
inbound.SubSortIndex = normalizeSubSortIndex(inbound.SubSortIndex)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user