mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-07-21 20:16:08 +00:00
feat(xray): update xray-core to v26.7.11 and adapt panel
Bump xtls/xray-core to 50231eaf (v26.7.11) and the three binary pins (DockerInit.sh, release.yml x2) in lockstep. Adapt the panel to the upstream changes: - Shadowsocks "none"/"plain" and VMess "none"/"zero" were removed from the core. A migration rewrites stored none/plain SS methods to a supported cipher and none/zero VMess security to "auto" (on both the clients column and inbound settings JSON); the SS build-time heal does the same so a row injected after boot cannot brick startup. The removed values are dropped from every frontend option list, schema and adapter, and coerced to "auto" at the Go link/sub/Clash emit sites and both link importers. Fix the CipherType_NONE sentinel that no longer compiles. - Unencrypted vless/trojan outbounds to a public address are now refused by the core. Validate outbounds through the vendored config loader when saving the xray template and when storing/merging outbound subscriptions, so one such outbound cannot keep the core from starting. - New TCP finalmask type "xmc" (Minecraft mimicry): add it to the sub link allowlist, the frontend enum and the FinalMask form (hostname, usernames, required password), and document it. - streamSettings gained a "method" alias for "network"; canonicalize it to "network" at inbound save time and in the form adapters/schema so a method-keyed config keeps its transport. - New root "env" config key is passed through xray.Config, compared in Equals, and forces a restart in the hot diff. - REALITY now defaults minClientVer to 26.3.27; update the form placeholder.
This commit is contained in:
@@ -503,7 +503,9 @@ func (s *InboundService) getAllEmailSubIDs() (map[string]string, error) {
|
||||
// Only vmess, vless, trojan, shadowsocks, hysteria, wireguard, and tunnel
|
||||
// protocols use streamSettings (wireguard for finalmask UDP masks and sockopt on
|
||||
// its listener; tunnel for sockopt, notably sockopt.tproxy for its TProxy/redirect
|
||||
// mode).
|
||||
// mode). Streams keyed on "method" — xray-core v26.7.11's preferred alias for
|
||||
// "network" — are canonicalized to "network", which every panel reader (link
|
||||
// generation, port-conflict detection, flow eligibility) keys on.
|
||||
func (s *InboundService) normalizeStreamSettings(inbound *model.Inbound) {
|
||||
protocolsWithStream := map[model.Protocol]bool{
|
||||
model.VMESS: true,
|
||||
@@ -517,7 +519,33 @@ func (s *InboundService) normalizeStreamSettings(inbound *model.Inbound) {
|
||||
|
||||
if !protocolsWithStream[inbound.Protocol] {
|
||||
inbound.StreamSettings = ""
|
||||
return
|
||||
}
|
||||
inbound.StreamSettings = canonicalizeStreamNetworkKey(inbound.StreamSettings)
|
||||
}
|
||||
|
||||
// canonicalizeStreamNetworkKey rewrites a streamSettings JSON that names its
|
||||
// transport under "method" to the panel-canonical "network" key. When both
|
||||
// keys are present, "method" wins — matching xray-core's own precedence.
|
||||
func canonicalizeStreamNetworkKey(streamSettings string) string {
|
||||
if streamSettings == "" {
|
||||
return streamSettings
|
||||
}
|
||||
var stream map[string]any
|
||||
if err := json.Unmarshal([]byte(streamSettings), &stream); err != nil {
|
||||
return streamSettings
|
||||
}
|
||||
method, ok := stream["method"].(string)
|
||||
if !ok || method == "" {
|
||||
return streamSettings
|
||||
}
|
||||
stream["network"] = method
|
||||
delete(stream, "method")
|
||||
out, err := json.MarshalIndent(stream, "", " ")
|
||||
if err != nil {
|
||||
return streamSettings
|
||||
}
|
||||
return string(out)
|
||||
}
|
||||
|
||||
// finalMaskRealityTcpMasks returns the stream's finalmask.tcp masks when the
|
||||
|
||||
Reference in New Issue
Block a user