mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-07-23 04:56:07 +00:00
fbad71d620
Second-pass review of the 54-commit self-correcting audit. Each item below was confirmed by reading the surrounding source (and, where practical, the pre-fix code) before being changed; regression tests are included for every behavioral fix. Concurrency: - eventbus: Bus.Subscribe called wg.Add with no synchronization against a concurrent Bus.Stop's wg.Wait, a real "WaitGroup misuse" panic risk (e.g. a Telegram-bot settings save racing panel shutdown/restart). Stop now flips a mu-guarded `stopped` flag before waiting, and Subscribe checks it under the same lock, so Add and Wait can no longer race. Security: - login_limiter: evictForRoom's fallback eviction picked an arbitrary map key, including ones still under an active cooldown - an attacker flooding /login with fresh usernames could evict their own (or anyone's) blocked record and reset the lockout. The fallback now skips actively-blocked records, only falling back to an unconditional evict if the map is somehow entirely full of active blocks (preserves the hard memory cap). Subscription-endpoint panics (reachable by any client hitting /sub): - internal/sub/service.go: applyPathAndHostParams/Obj (ws/httpupgrade/xhttp with no path settings object) and the TLS alpn readers in three places used unchecked type assertions - exactly the bug classabab7cd0patched elsewhere in the same switch statements, just not these call sites. - internal/sub/json_service.go, clash_service.go: the externalProxy loops in the JSON and Clash generators used unchecked assertions on a legacy/admin-supplied field (missing "port", non-object entry, etc.). - internal/sub/json_service.go: realityData's shortId/serverName selection could assert a non-string array element. Other correctness: - client_traffic.go: ResetAllTraffics (touched by3eb214d0) still skipped clearing NodeClientTraffic node-sync baselines, unlike its sibling reset paths in the same file - a node's next sync would re-add pre-reset delta on top of the freshly-zeroed counter. - inbound_traffic.go: the traffic-tick tx's Commit/Rollback errors were silently discarded; now logged so a backend-level commit failure (e.g. an aborted Postgres tx from a best-effort helper) doesn't masquerade as a successful tick. - outbound_subscription.go: the new subscriptionFetchClient doc comment was wedged between fetchAndStore's existing comment and fetchAndStore itself, leaving fetchAndStore undocumented and the comment describing the wrong function. Convention cleanup: - Removed narrative // comments added by the audit that violate this repo's no-inline-comment rule (mostly narrating the specific bug/fix rather than a lasting contract, and mostly on new Test functions, which this repo's existing tests never comment) - calibrated against this exact codebase's own pre-existing comment style so legitimate godoc-style doc comments were left alone.
73 lines
2.5 KiB
Go
73 lines
2.5 KiB
Go
package service
|
|
|
|
import (
|
|
"errors"
|
|
"testing"
|
|
|
|
"gorm.io/gorm"
|
|
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/web/runtime"
|
|
)
|
|
|
|
func TestUpdateInboundLocalMtprotoDefersPushUntilCommit(t *testing.T) {
|
|
setupConflictDB(t)
|
|
|
|
mgr := runtime.NewManager(runtime.LocalDeps{APIPort: func() int { return 0 }})
|
|
fake := &fakeNodeRuntime{}
|
|
mgr.SetLocalRuntimeOverride(fake)
|
|
runtime.SetManager(mgr)
|
|
t.Cleanup(func() { runtime.SetManager(nil) })
|
|
|
|
seedInboundConflict(t, "mt-txfail", "", 46150, model.MTProto, "",
|
|
`{"clients":[{"email":"mtx","secret":"`+mtprotoTestSecretA+`","enable":true}]}`)
|
|
seeded := loadInboundByTag(t, "mt-txfail")
|
|
seedClientTraffic(t, seeded.Id, "mtx", true)
|
|
|
|
db := database.GetDB()
|
|
const cbName = "b1-05:fail-inbound-update"
|
|
if err := db.Callback().Update().After("gorm:update").Register(cbName, func(tx *gorm.DB) {
|
|
if tx.Statement != nil && tx.Statement.Table == "inbounds" {
|
|
tx.AddError(errors.New("injected transaction failure"))
|
|
}
|
|
}); err != nil {
|
|
t.Fatalf("register callback: %v", err)
|
|
}
|
|
t.Cleanup(func() { _ = db.Callback().Update().Remove(cbName) })
|
|
|
|
update := *loadInboundByTag(t, "mt-txfail")
|
|
update.Remark = "edited"
|
|
if _, _, err := (&InboundService{}).UpdateInbound(&update); err == nil {
|
|
t.Fatal("UpdateInbound: expected the injected transaction failure")
|
|
}
|
|
|
|
if n := fake.updateInbound.Load(); n != 0 {
|
|
t.Fatalf("the MTProto sidecar push ran %d time(s) inside the failed transaction; it must be deferred until the commit succeeds", n)
|
|
}
|
|
}
|
|
|
|
func TestSetInboundEnableRoutedMtprotoRequestsRestart(t *testing.T) {
|
|
setupConflictDB(t)
|
|
|
|
mgr := runtime.NewManager(runtime.LocalDeps{APIPort: func() int { return 0 }})
|
|
mgr.SetLocalRuntimeOverride(&fakeNodeRuntime{})
|
|
runtime.SetManager(mgr)
|
|
t.Cleanup(func() { runtime.SetManager(nil) })
|
|
|
|
seedInboundConflict(t, "mt-route", "", 46160, model.MTProto, "",
|
|
`{"clients":[{"email":"mtr","secret":"`+mtprotoTestSecretA+`","enable":true}],"routeThroughXray":true,"routeXrayPort":12345}`)
|
|
seeded := loadInboundByTag(t, "mt-route")
|
|
if err := database.GetDB().Model(&model.Inbound{}).Where("id = ?", seeded.Id).Update("enable", false).Error; err != nil {
|
|
t.Fatalf("force disable: %v", err)
|
|
}
|
|
|
|
needRestart, err := (&InboundService{}).SetInboundEnable(seeded.Id, true)
|
|
if err != nil {
|
|
t.Fatalf("SetInboundEnable: %v", err)
|
|
}
|
|
if !needRestart {
|
|
t.Fatal("re-enabling a routed MTProto inbound must request an xray restart to re-inject the egress bridge")
|
|
}
|
|
}
|