mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-17 15:47:14 +00:00
fix: port the PR #6105 review-round fixes into this fork's own AmneziaWG code
Same 8 findings fixed on upstream-pr/amneziawg, ported here since this fork's internal/amneziawg + related web/service files predate that PR branch's own fix-up commits: 1. hostRulesFingerprint now folds in a peer's IPv4 whenever ForwardedPorts is set, not only when RouteThroughXray is on, so a re-IP forces the bounce needed to move the DNAT rule too. 2. ValidateConfigValue (new, params.go) rejects control characters in server/client keys, email and I1 at save time; sanitizeConfigValue strips them defensively at .conf-render time. 3. checkForwardedPortsConflict now scopes to node_id IS NULL and takes a pre-loaded portConflictContext (loadPortConflictContext), so a port used only on another node isn't a false collision and an inbound with N clients costs one query instead of N. 4. PostDown commands are now best-effort (appendOrTrue) so an external firewall flush can't abort the rest of the teardown chain. 5. The "ip rule list | grep -q" existence check now uses grep -c >/dev/null, avoiding a pipefail/SIGPIPE false negative that could re-add a duplicate rule. 6. route_egress.go's stale "always present, no opt-in" comment corrected to describe the real RouteThroughXray-gated behavior. (This fork's genAmneziaWGLink already emits vpn://, and there's no upstream-facing docs page here, so neither needed the PR branch's Finding 6 docs/link-format changes.) 7. install.sh: Arch's ndppd install uses pacman -Sy, not -Syu, matching every other pacman call in the script; should_install_amneziawg short-circuits to yes when awg is already installed, so `x-ui update` doesn't re-prompt -- this fork's own opt-out-by-default philosophy for should_install_amneziawg is unchanged, only the redundant-reprompt behavior is fixed. 8. CollectTraffic checks pointer identity before writing back a traffic-counter baseline, so a concurrent restart's freshly-reset (empty) baseline can't be clobbered by stale pre-restart counters. sweepOrphansLocked no longer permanently disables itself on a transient os.ReadDir failure. go build/vet/test and frontend typecheck/lint/build/vitest all pass.
This commit is contained in:
@@ -189,6 +189,25 @@ func ValidateSubnetIPv4(subnetIP string, subnetCIDR int) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// ValidateConfigValue rejects a value containing a newline, carriage return,
|
||||
// or other control character before it's saved. PrivateKey/PublicKey/I1 on
|
||||
// the server block, and Email/PublicKey/PreSharedKey per client, all get
|
||||
// interpolated verbatim into the generated .conf by generateServerConfig; a
|
||||
// newline in any of them lets a later line re-open a new [Interface]/[Peer]
|
||||
// section, and awg-quick's parser collects a following "PostUp = ..." line
|
||||
// into a hook it executes as root on the next apply — the same class this
|
||||
// package already closes for ExternalInterface/IPv6ExternalInterface (see
|
||||
// ValidateInterfaceName) and SubnetIP (see ValidateSubnetIPv4). field names
|
||||
// the value in the returned error, e.g. "email" or "publicKey".
|
||||
func ValidateConfigValue(field, v string) error {
|
||||
for _, r := range v {
|
||||
if r == '\n' || r == '\r' || r < 0x20 || r == 0x7f {
|
||||
return fmt.Errorf("invalid %s: control characters are not allowed", field)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// validateHValue checks one H parameter: empty, a single uint32, or
|
||||
// "low-high" with 0 <= low <= high <= uint32 max.
|
||||
func validateHValue(v string) error {
|
||||
|
||||
Reference in New Issue
Block a user