mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-17 15:47:14 +00:00
d5ab84e8d5
* feat(amneziawg): add AmneziaWG as an outbound protocol - AmneziaWG outbound protocol end-to-end: config schema, socks bridge, netstack, panel UI - Route amneziawg outbounds to HTTP probe in TCP mode (backend + frontend classifiers) with pinning test - Add 2-minute idle read deadline to pumpUDPEgress to reap idle egress sessions - Require SOCKS5 username/password auth on the egress server (reject NO-AUTH with 0xFF) with test - Bound the egress TCP tunnel dial with portForwardDialTimeout (10s), matching portfwd.go - Resolve UDP domain targets off the association's reader loop via deliverUDPDatagram; race-safe getOrDial starts the reply pump at session creation; client passed by value into resolver goroutines (pinned by TestEgressUDPDatagramDomainInterleavedClients) - Reconcile early-returns on an empty desired set and closes the egress listener; EgressBasePort (64900) is reserved against local inbound port conflicts like the internal API port, with pinning tests for both the port reservation (TestCheckPortConflict_EgressPortBlockedLocal) and the Reconcile empty-desired Close/Listen lifecycle (TestOutboundManagerReconcileEmptyDesiredClosesEgress) - Eliminate acceptLoop shutdown race by validating listener != nil and registering to tracked under s.mu before wg.Add; bound pre-auth handshake with deadline (pinned by TestEgressServerCloseDuringConcurrentAccepts) - Support AAAA and dual-stack domain resolution in tunnel DNS resolver with v6 default fallback (DefaultTunnelDNSServerV6); add DNS field to frontend protocol form; avoid unneeded cache flushes on unchanged SetStack ticks * fix(amneziawg): resolve IPv6-only DNS default fallback and validate required keys - Default to IPv6 tunnel DNS on IPv6-only outbounds with blank dns - Require non-empty secretKey and peer publicKey in ValidateAmneziaWGOutbound - Add end-to-end IPv6 tunnel domain resolution test and test empty key rejection - Trim comment blocks exceeding 2 lines across modified files - Fix Storybook test execution on environments with POSIX locale Co-Authored-By: Claude Code <noreply@anthropic.com> --------- Co-authored-by: rqzbeh <rqzbeh@users.noreply.github.com> Co-authored-by: Claude Code <noreply@anthropic.com> Co-authored-by: Sanaei <ho3ein.sanaei@gmail.com>
52 lines
1.3 KiB
Go
52 lines
1.3 KiB
Go
package service
|
|
|
|
import (
|
|
"encoding/json"
|
|
"fmt"
|
|
|
|
"github.com/mhsanaei/3x-ui/v3/internal/amneziawg"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/amneziawgnet"
|
|
json_util "github.com/mhsanaei/3x-ui/v3/internal/util/json_util"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/xray"
|
|
)
|
|
|
|
// transformAmneziaWGOutbounds swaps each template "amneziawg" outbound for
|
|
// its socks bridge; unbridgeable entries fail generation rather than skip.
|
|
func transformAmneziaWGOutbounds(cfg *xray.Config) error {
|
|
if len(cfg.OutboundConfigs) == 0 {
|
|
return nil
|
|
}
|
|
var outbounds []json.RawMessage
|
|
if err := json.Unmarshal(cfg.OutboundConfigs, &outbounds); err != nil {
|
|
return err
|
|
}
|
|
changed := false
|
|
for i, raw := range outbounds {
|
|
if !amneziawg.IsAmneziaWGOutbound(raw) {
|
|
continue
|
|
}
|
|
var probe struct {
|
|
Tag string `json:"tag"`
|
|
}
|
|
tagErr := json.Unmarshal(raw, &probe)
|
|
replacement, ok := amneziawgnet.BuildSocksBridge(raw)
|
|
if !ok {
|
|
if tagErr != nil {
|
|
return fmt.Errorf("amneziawg outbound %d: unreadable tag: %w", i, tagErr)
|
|
}
|
|
return fmt.Errorf("amneziawg outbound %d (%q): cannot bridge: tag must be a non-empty string", i, probe.Tag)
|
|
}
|
|
outbounds[i] = replacement
|
|
changed = true
|
|
}
|
|
if !changed {
|
|
return nil
|
|
}
|
|
bs, err := json.Marshal(outbounds)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
cfg.OutboundConfigs = json_util.RawMessage(bs)
|
|
return nil
|
|
}
|