fix(xray): read the last two inboundTag protocol ids like the core (#6530)

The core lowercases an outbound's protocol id before it resolves the handler,
so an outbound spelled "Loopback" still is the loopback outbound. Both
readers that keep a loopback outbound's inboundTag in step with the inbound
it names compared the id exactly, so such an outbound was skipped: renaming
or deleting that inbound left settings.inboundTag pointing at a tag that no
longer exists, and traffic returning through the loopback outbound arrives
under a tag no routing rule can match (infra/conf/loopback.go:15 carries the
tag, proxy/loopback/loopback.go:43 uses it as the inbound identity).

The probe lane's "nothing to test here" gate had the same exact comparison,
so a "Freedom"/"Blackhole" outbound reported the vaguer "No testable
endpoint" where the canonical spelling reports "Outbound has no testable
endpoint" — the two spellings took different paths to the same rejection.

Both readers now compare case-insensitively; the outbound package reuses its
existing equalsAnyFold helper rather than adding a second one. The service
reads the config template an operator edits, so a case variant is reachable
there; server.go's GetDefaultLogOutboundTags scans the embedded config.json
instead, whose protocols are canonical by construction, so it is left as is
and no test can tell a case-insensitive read there from an exact one.
This commit is contained in:
BlindMaster24
2026-09-14 21:18:31 +03:00
committed by GitHub
parent 837addf66e
commit a810f497e6
4 changed files with 102 additions and 3 deletions
+1 -1
View File
@@ -157,7 +157,7 @@ func (s *OutboundService) testOutboundTCP(outboundJSON string) (*TestOutboundRes
}
tag, _ := ob["tag"].(string)
protocol, _ := ob["protocol"].(string)
if protocol == "blackhole" || protocol == "freedom" || tag == "blocked" {
if equalsAnyFold(protocol, "blackhole", "freedom") || tag == "blocked" {
return &TestOutboundResult{Tag: tag, Mode: "tcp", Success: false, Error: "Outbound has no testable endpoint"}, nil
}
@@ -110,6 +110,37 @@ func TestBuildBatchTestConfigReadsTheProtocolIDLikeTheCore(t *testing.T) {
}
}
func TestTestOutboundsRejectsUntestableIDsInAnyCase(t *testing.T) {
tests := []struct {
name string
protocol string
}{
{"canonical freedom", "freedom"},
{"capitalised freedom", "Freedom"},
{"upper freedom", "FREEDOM"},
{"canonical blackhole", "blackhole"},
{"capitalised blackhole", "Blackhole"},
}
const wantErr = "Outbound has no testable endpoint"
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
batch := mustJSON(t, []any{map[string]any{"tag": "t1", "protocol": tt.protocol}})
results, err := (&OutboundService{}).TestOutbounds(batch, "", "", "tcp")
if err != nil {
t.Fatalf("TestOutbounds: %v", err)
}
r := results[0]
if r.Success {
t.Errorf("%q outbound = %+v, want a rejection", tt.protocol, r)
}
if r.Error != wantErr {
t.Errorf("%q error = %q, want %q", tt.protocol, r.Error, wantErr)
}
})
}
}
func TestTestOutboundsTCPLaneReadsProtocolIDCaseInsensitively(t *testing.T) {
l, err := net.Listen("tcp", "127.0.0.1:0")
if err != nil {
@@ -2,6 +2,7 @@ package service
import (
"encoding/json"
"strings"
)
var routingMatcherKeys = []string{
@@ -142,7 +143,7 @@ func replaceInboundTagInOutbounds(outbounds []any, oldTag, newTag string) bool {
continue
}
proto, _ := out["protocol"].(string)
if proto != "loopback" {
if !strings.EqualFold(proto, "loopback") {
continue
}
settings, ok := out["settings"].(map[string]any)
@@ -167,7 +168,7 @@ func removeInboundTagFromOutbounds(outbounds []any, deletedTag string) bool {
continue
}
proto, _ := out["protocol"].(string)
if proto != "loopback" {
if !strings.EqualFold(proto, "loopback") {
continue
}
settings, ok := out["settings"].(map[string]any)
@@ -221,6 +221,73 @@ func TestRemoveInboundTagReferences_RemovesOneTagFromMultiInboundRule(t *testing
}
}
// The core lowercases a protocol id before resolving the handler, so "Loopback"
// is the loopback outbound whose inboundTag has to follow the inbound it names.
func TestReplaceInboundTagInOutbounds_ReadsTheProtocolIDLikeTheCore(t *testing.T) {
tests := []struct {
name string
protocol any
want bool
wantTag any
}{
{"canonical loopback is rewritten", "loopback", true, "new-tag"},
{"capitalised loopback is rewritten", "Loopback", true, "new-tag"},
{"uppercase loopback is rewritten", "LOOPBACK", true, "new-tag"},
{"another protocol keeps its tag", "vmess", false, "old-tag"},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
outbounds := []any{map[string]any{
"protocol": tt.protocol,
"settings": map[string]any{"inboundTag": "old-tag"},
}}
if got := replaceInboundTagInOutbounds(outbounds, "old-tag", "new-tag"); got != tt.want {
t.Errorf("changed = %v, want %v", got, tt.want)
}
settings := outbounds[0].(map[string]any)["settings"].(map[string]any)
if got := settings["inboundTag"]; got != tt.wantTag {
t.Errorf("inboundTag = %v, want %v", got, tt.wantTag)
}
})
}
}
func TestRemoveInboundTagFromOutbounds_ReadsTheProtocolIDLikeTheCore(t *testing.T) {
tests := []struct {
name string
protocol any
want bool
wantTag any
}{
{"canonical loopback is cleared", "loopback", true, nil},
{"capitalised loopback is cleared", "Loopback", true, nil},
{"uppercase loopback is cleared", "LOOPBACK", true, nil},
{"another protocol keeps its tag", "vmess", false, "gone-tag"},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
outbounds := []any{map[string]any{
"protocol": tt.protocol,
"settings": map[string]any{"inboundTag": "gone-tag"},
}}
if got := removeInboundTagFromOutbounds(outbounds, "gone-tag"); got != tt.want {
t.Errorf("changed = %v, want %v", got, tt.want)
}
settings := outbounds[0].(map[string]any)["settings"].(map[string]any)
got, ok := settings["inboundTag"]
if tt.wantTag == nil {
if ok {
t.Errorf("inboundTag = %v, want the key gone", got)
}
return
}
if !ok || got != tt.wantTag {
t.Errorf("inboundTag = %v (present=%v), want %v", got, ok, tt.wantTag)
}
})
}
}
func findRuleByOutbound(t *testing.T, template, outbound string) map[string]any {
t.Helper()
for _, rule := range routingRulesFromTemplate(t, template) {