mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-17 23:57:15 +00:00
c41f97cf86
Each is independently reproducible; fixed together since one review pass found all of them. - manager.go: the shared "ip rule add fwmark" policy route had no existence check, so it duplicated in "ip rule show" on every interface bounce (which hostRulesFingerprint forces on any client add/remove/ re-IP). Now checked via "ip rule list | grep -q ..." first. (Finding 2) - params.go: ExternalInterface, IPv6ExternalInterface, and subnetIp/ subnetCidr are interpolated unescaped into a shell-executed PostUp/ PostDown line, but only obfuscation and the IPv6 subnet were validated before save. Added ValidateInterfaceName (a strict charset+length pattern) and ValidateSubnetIPv4 (netip.ParsePrefix), wired into normalizeAmneziaWGSettings. (Finding 3) - amneziawg_job.go: IsAwgInstalled() existed but nothing ever called it, so a host without awg/awg-quick (the Docker image, RHEL, Arch, a failed install.sh PPA step) logged a reconcile failure every 10s forever. Now checked once an inbound actually needs it, warning once instead of spamming. (Finding 4) - client_inbound_apply.go: the WireGuard/AmneziaWG credential carry-forward (added so a metadata-only client edit doesn't rotate keys) never covered ForwardedPorts, so a partial edit -- an API call or Telegram-bot toggle that omits the field -- silently wiped a client's port-forwarding spec. Carried forward and written back the same way the key fields already are. (Finding 5) - manager.go: hostRulesFingerprint keyed each peer on its IPv4 address only, and structuralFingerprint omitted IPv6Enabled/IPv6ExternalInterface entirely, so an IPv6-only change could pick the syncconf reload path (which never re-runs PostUp, leaving a stale NDP-proxy entry) or be a complete no-op. Both fingerprints now cover the IPv6 fields. (Finding 6) - port_conflict.go: the AmneziaWG egress bridge (injectAmneziawgEgress) binds 127.0.0.1:63100+id with no collision check anywhere, since it isn't a database row the ordinary port-conflict query can see -- same blind spot the reserved Xray API port already has its own check for. Added the equivalent check for the AmneziaWG bridge port. (Finding 7) - install.sh: install_amneziawg ran unconditionally for every install/ update, building a DKMS kernel module and enabling host-wide IPv4/IPv6 forwarding whether or not the feature is ever used. Gated behind a new should_install_amneziawg (XUI_INSTALL_AMNEZIAWG=true/false, or an interactive y/N prompt defaulting to no). Also replaced the deprecated apt-key adv with a dedicated keyring + signed-by= on the Debian branch, and guarded its sources.list appends against duplication on a retried install. (Finding 8) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
89 lines
2.8 KiB
Go
89 lines
2.8 KiB
Go
package job
|
|
|
|
import (
|
|
"github.com/mhsanaei/3x-ui/v3/internal/amneziawg"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/logger"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/web/service"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/xray"
|
|
)
|
|
|
|
// AmneziaWGJob reconciles the running AmneziaWG interfaces against the
|
|
// enabled AmneziaWG inbounds in the database, restarts/reloads any that
|
|
// drifted, and folds the per-peer traffic scraped from `awg show dump` into
|
|
// the usual client and inbound traffic accounting. Mirrors MtprotoJob.
|
|
type AmneziaWGJob struct {
|
|
inboundService service.InboundService
|
|
// warnedMissing tracks whether the "awg/awg-quick not found" warning has
|
|
// already been logged, so a host without the AmneziaWG kernel module
|
|
// (the Docker image, RHEL, Arch, or a failed install.sh PPA step) logs it
|
|
// once instead of every @every-10s tick forever.
|
|
warnedMissing bool
|
|
}
|
|
|
|
// NewAmneziaWGJob creates a new AmneziaWG reconcile/traffic job instance.
|
|
func NewAmneziaWGJob() *AmneziaWGJob {
|
|
return new(AmneziaWGJob)
|
|
}
|
|
|
|
// Run reconciles desired AmneziaWG inbounds with running interfaces and
|
|
// records per-peer traffic deltas and online status.
|
|
func (j *AmneziaWGJob) Run() {
|
|
desired, err := j.inboundService.DesiredAmneziaWGInstances()
|
|
if err != nil {
|
|
logger.Warning("amneziawg job: get desired instances failed:", err)
|
|
return
|
|
}
|
|
|
|
// Only relevant once an admin actually has an AmneziaWG inbound: no
|
|
// point warning about a missing binary the panel never needed to touch.
|
|
if len(desired) > 0 && !amneziawg.IsAwgInstalled() {
|
|
if !j.warnedMissing {
|
|
j.warnedMissing = true
|
|
logger.Warningf("amneziawg job: %d AmneziaWG inbound(s) configured but awg/awg-quick not found on PATH; skipping reconcile until installed", len(desired))
|
|
}
|
|
return
|
|
}
|
|
j.warnedMissing = false
|
|
|
|
activeTags := make([]string, 0, len(desired))
|
|
for _, inst := range desired {
|
|
activeTags = append(activeTags, inst.Tag)
|
|
}
|
|
|
|
mgr := amneziawg.GetManager()
|
|
mgr.Reconcile(desired)
|
|
|
|
deltas, onlineEmails := mgr.CollectTraffic()
|
|
|
|
clientTraffics := make([]*xray.ClientTraffic, 0, len(deltas))
|
|
inboundUp := make(map[string]int64)
|
|
inboundDown := make(map[string]int64)
|
|
for _, d := range deltas {
|
|
clientTraffics = append(clientTraffics, &xray.ClientTraffic{
|
|
Email: d.Email,
|
|
Up: d.Up,
|
|
Down: d.Down,
|
|
})
|
|
inboundUp[d.Tag] += d.Up
|
|
inboundDown[d.Tag] += d.Down
|
|
}
|
|
|
|
traffics := make([]*xray.Traffic, 0, len(inboundUp))
|
|
for tag, up := range inboundUp {
|
|
traffics = append(traffics, &xray.Traffic{
|
|
IsInbound: true,
|
|
Tag: tag,
|
|
Up: up,
|
|
Down: inboundDown[tag],
|
|
})
|
|
}
|
|
|
|
if len(traffics) > 0 || len(clientTraffics) > 0 {
|
|
if _, _, err := j.inboundService.AddTraffic(traffics, clientTraffics); err != nil {
|
|
logger.Warning("amneziawg job: add traffic failed:", err)
|
|
}
|
|
}
|
|
|
|
j.inboundService.RefreshLocalOnlineClients(onlineEmails, activeTags)
|
|
}
|