mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-17 15:47:14 +00:00
fix(amneziawg): resolve 7 Medium findings from the automated PR review
Each is independently reproducible; fixed together since one review pass found all of them. - manager.go: the shared "ip rule add fwmark" policy route had no existence check, so it duplicated in "ip rule show" on every interface bounce (which hostRulesFingerprint forces on any client add/remove/ re-IP). Now checked via "ip rule list | grep -q ..." first. (Finding 2) - params.go: ExternalInterface, IPv6ExternalInterface, and subnetIp/ subnetCidr are interpolated unescaped into a shell-executed PostUp/ PostDown line, but only obfuscation and the IPv6 subnet were validated before save. Added ValidateInterfaceName (a strict charset+length pattern) and ValidateSubnetIPv4 (netip.ParsePrefix), wired into normalizeAmneziaWGSettings. (Finding 3) - amneziawg_job.go: IsAwgInstalled() existed but nothing ever called it, so a host without awg/awg-quick (the Docker image, RHEL, Arch, a failed install.sh PPA step) logged a reconcile failure every 10s forever. Now checked once an inbound actually needs it, warning once instead of spamming. (Finding 4) - client_inbound_apply.go: the WireGuard/AmneziaWG credential carry-forward (added so a metadata-only client edit doesn't rotate keys) never covered ForwardedPorts, so a partial edit -- an API call or Telegram-bot toggle that omits the field -- silently wiped a client's port-forwarding spec. Carried forward and written back the same way the key fields already are. (Finding 5) - manager.go: hostRulesFingerprint keyed each peer on its IPv4 address only, and structuralFingerprint omitted IPv6Enabled/IPv6ExternalInterface entirely, so an IPv6-only change could pick the syncconf reload path (which never re-runs PostUp, leaving a stale NDP-proxy entry) or be a complete no-op. Both fingerprints now cover the IPv6 fields. (Finding 6) - port_conflict.go: the AmneziaWG egress bridge (injectAmneziawgEgress) binds 127.0.0.1:63100+id with no collision check anywhere, since it isn't a database row the ordinary port-conflict query can see -- same blind spot the reserved Xray API port already has its own check for. Added the equivalent check for the AmneziaWG bridge port. (Finding 7) - install.sh: install_amneziawg ran unconditionally for every install/ update, building a DKMS kernel module and enabling host-wide IPv4/IPv6 forwarding whether or not the feature is ever used. Gated behind a new should_install_amneziawg (XUI_INSTALL_AMNEZIAWG=true/false, or an interactive y/N prompt defaulting to no). Also replaced the deprecated apt-key adv with a dedicated keyring + signed-by= on the Debian branch, and guarded its sources.list appends against duplication on a retried install. (Finding 8) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"fmt"
|
||||
"math/big"
|
||||
"net/netip"
|
||||
"regexp"
|
||||
"strconv"
|
||||
"strings"
|
||||
)
|
||||
@@ -140,6 +141,54 @@ func ValidateIPv6Subnet(enabled bool, subnet string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// interfaceNamePattern matches a plausible Linux network interface name:
|
||||
// letters, digits, and the handful of separators seen in real device names
|
||||
// (eth0, wg0, br-lan, eno1.100, eth0:0), capped at 15 bytes (IFNAMSIZ-1).
|
||||
var interfaceNamePattern = regexp.MustCompile(`^[A-Za-z0-9_.@:-]{1,15}$`)
|
||||
|
||||
// ValidateInterfaceName rejects a value that isn't a plausible network
|
||||
// interface name before it's saved. ExternalInterface and
|
||||
// IPv6ExternalInterface are interpolated unescaped into a shell-executed
|
||||
// PostUp/PostDown line by generateServerConfig, so — unlike the client email
|
||||
// (already hashed for exactly this reason, see routeEgressComment) — an
|
||||
// unvalidated value here could carry a shell metacharacter straight into a
|
||||
// root-executed command. A blank value is allowed: it means "auto-detect"
|
||||
// for ExternalInterface, or "reuse ExternalInterface" for
|
||||
// IPv6ExternalInterface.
|
||||
func ValidateInterfaceName(name string) error {
|
||||
if name == "" {
|
||||
return nil
|
||||
}
|
||||
if !interfaceNamePattern.MatchString(name) {
|
||||
return fmt.Errorf("invalid interface name %q: must be 1-15 characters of letters, digits, '.', '_', '@', ':' or '-'", name)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// ValidateSubnetIPv4 rejects a malformed IPv4 tunnel subnet before it's
|
||||
// saved: subnetIP is interpolated into the PostUp/PostDown MASQUERADE rule
|
||||
// the same way ExternalInterface is (see ValidateInterfaceName), so it needs
|
||||
// the same protection against a value that isn't really an address at all.
|
||||
// subnetCIDR <= 0 is treated as unset, mirroring serverAddress's own
|
||||
// default-to-/24 leniency.
|
||||
func ValidateSubnetIPv4(subnetIP string, subnetCIDR int) error {
|
||||
cidr := subnetCIDR
|
||||
if cidr <= 0 {
|
||||
cidr = 24
|
||||
}
|
||||
if cidr > 32 {
|
||||
return fmt.Errorf("invalid subnetCidr %d: must be 0..32", subnetCIDR)
|
||||
}
|
||||
prefix, err := netip.ParsePrefix(fmt.Sprintf("%s/%d", subnetIP, cidr))
|
||||
if err != nil {
|
||||
return fmt.Errorf("invalid subnetIp %q: %w", subnetIP, err)
|
||||
}
|
||||
if !prefix.Addr().Is4() {
|
||||
return fmt.Errorf("invalid subnetIp %q: not an IPv4 address", subnetIP)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// validateHValue checks one H parameter: empty, a single uint32, or
|
||||
// "low-high" with 0 <= low <= high <= uint32 max.
|
||||
func validateHValue(v string) error {
|
||||
|
||||
Reference in New Issue
Block a user