Compare commits

..

92 Commits

Author SHA1 Message Date
世界
5d73dd617a documentation: Bump version 2025-05-18 16:51:05 +08:00
世界
f399121721 Add SSM API service 2025-05-18 16:50:51 +08:00
世界
bbf7de181b Add resolved service and DNS server 2025-05-18 16:50:51 +08:00
世界
1327c7940e Add DERP service 2025-05-18 16:50:51 +08:00
世界
0771cb5b9e Add service component type 2025-05-18 16:50:50 +08:00
世界
3350896751 Fix tproxy tcp control 2025-05-18 16:50:50 +08:00
愚者
f83abb5cd6 release: Fix build tags for android
Signed-off-by: 愚者 <11926619+FansChou@users.noreply.github.com>
2025-05-18 16:50:50 +08:00
世界
9bdf29c92b prevent creation of bind and mark controls on unsupported platforms 2025-05-18 16:50:50 +08:00
PuerNya
b6546ba9ee documentation: Fix description of reject DNS action behavior 2025-05-18 16:50:50 +08:00
Restia-Ashbell
12b88678cc Fix TLS record fragment 2025-05-18 16:50:50 +08:00
世界
6c71cf88c5 Add missing accept_routes option for Tailscale 2025-05-18 16:50:50 +08:00
世界
eaae1a72e8 Add TLS record fragment support 2025-05-18 16:50:50 +08:00
世界
be8fa753f6 release: Update Go to 1.24.3 2025-05-18 16:50:49 +08:00
世界
9338611506 Fix set edns0 client subnet 2025-05-18 16:50:49 +08:00
世界
dd5e8c2fc3 Update minor dependencies 2025-05-18 16:50:49 +08:00
世界
5f630afabd Update certmagic and providers 2025-05-18 16:50:49 +08:00
世界
afe039b2a0 Update protobuf and grpc 2025-05-18 16:50:49 +08:00
世界
d9dba4c3c2 Add control options for listeners 2025-05-18 16:50:49 +08:00
世界
a6f30adbdf Update quic-go to v0.51.0 2025-05-18 16:50:49 +08:00
世界
86458bf26e Update utls to v1.7.2 2025-05-18 16:50:48 +08:00
世界
381339f6aa Handle EDNS version downgrade 2025-05-18 16:50:48 +08:00
世界
eae10a8342 documentation: Fix anytls padding scheme description 2025-05-18 16:50:48 +08:00
安容
1ec660cc84 Report invalid DNS address early 2025-05-18 16:50:47 +08:00
世界
664b5871f7 Fix wireguard listen_port 2025-05-18 16:50:47 +08:00
世界
5ff8df74b7 clash-api: Add more meta api 2025-05-18 16:50:47 +08:00
世界
79047deed1 Fix DNS lookup 2025-05-18 16:50:47 +08:00
世界
06a5c74470 Fix fetch ECH configs 2025-05-18 16:50:46 +08:00
reletor
3fbc2d8c70 documentation: Minor fixes 2025-05-18 16:50:46 +08:00
caelansar
85fa07a64c Fix callback deletion in UDP transport 2025-05-18 16:50:46 +08:00
世界
8fe4fcb339 documentation: Try to make the play review happy 2025-05-18 16:50:46 +08:00
世界
822dc654b4 Fix missing handling of legacy domain_strategy options 2025-05-18 16:50:45 +08:00
世界
06d32ae5f5 Improve local DNS server 2025-05-18 16:50:45 +08:00
anytls
be03fd8736 Update anytls
Co-authored-by: anytls <anytls>
2025-05-18 16:50:45 +08:00
世界
4f520741d2 Fix DNS dialer 2025-05-18 16:50:45 +08:00
世界
7a0b0141c9 release: Skip override version for iOS 2025-05-18 16:50:44 +08:00
iikira
e88a91ccd1 Fix UDP DNS server crash
Signed-off-by: iikira <i2@mail.iikira.com>
2025-05-18 16:50:44 +08:00
ReleTor
a363096a80 Fix fetch ECH configs 2025-05-18 16:50:44 +08:00
世界
4c1ed5a3c7 Allow direct outbounds without domain_resolver 2025-05-18 16:50:43 +08:00
世界
633203aed7 Fix Tailscale dialer 2025-05-18 16:50:43 +08:00
dyhkwong
f4d997bbfc Fix DNS over QUIC stream close 2025-05-18 16:50:42 +08:00
anytls
86ca81a989 Update anytls
Co-authored-by: anytls <anytls>
2025-05-18 16:50:42 +08:00
Rambling2076
6438029658 Fix missing with_tailscale in Dockerfile
Signed-off-by: Rambling2076 <Rambling2076@proton.me>
2025-05-18 16:50:42 +08:00
世界
5ba910997c Fail when default DNS server not found 2025-05-18 16:50:41 +08:00
世界
df710eccbb Update gVisor to 20250319.0 2025-05-18 16:50:41 +08:00
世界
ca3f70ac53 Explicitly reject detour to empty direct outbounds 2025-05-18 16:50:41 +08:00
世界
833f052f9c Add netns support 2025-05-18 16:50:40 +08:00
世界
51fb60bca6 Add wildcard name support for predefined records 2025-05-18 16:50:40 +08:00
世界
c5e9888f1a Remove map usage in options 2025-05-18 16:50:39 +08:00
世界
e49a589180 Fix unhandled DNS loop 2025-05-18 16:50:38 +08:00
世界
2eefbd8469 Add wildcard-sni support for shadow-tls inbound 2025-05-18 16:50:38 +08:00
k9982874
2f78acef13 Add ntp protocol sniffing 2025-05-18 16:50:38 +08:00
世界
1f677e54ed option: Fix marshal legacy DNS options 2025-05-18 16:50:37 +08:00
世界
63bd625089 Make domain_resolver optional when only one DNS server is configured 2025-05-18 16:50:37 +08:00
世界
cb95f29763 Fix DNS lookup context pollution 2025-05-18 16:50:37 +08:00
世界
696c78604f Fix http3 DNS server connecting to wrong address 2025-05-18 16:50:37 +08:00
Restia-Ashbell
be11352965 documentation: Fix typo 2025-05-18 16:50:36 +08:00
anytls
9756e482a0 Update sing-anytls
Co-authored-by: anytls <anytls>
2025-05-18 16:50:36 +08:00
k9982874
5041e7718a Fix hosts DNS server 2025-05-18 16:50:35 +08:00
世界
c5447e2632 Fix UDP DNS server crash 2025-05-18 16:50:35 +08:00
世界
d81d47b4e4 documentation: Fix missing ip_accept_any DNS rule option 2025-05-18 16:50:35 +08:00
世界
97d0e5542f Fix anytls dialer usage 2025-05-18 16:50:34 +08:00
世界
833971636f Move predefined DNS server to rule action 2025-05-18 16:50:34 +08:00
世界
a6ae909675 Fix domain resolver on direct outbound 2025-05-18 16:50:33 +08:00
Zephyruso
608efa7a7c Fix missing AnyTLS display name 2025-05-18 16:50:33 +08:00
anytls
a35d83f364 Update sing-anytls
Co-authored-by: anytls <anytls>
2025-05-18 16:50:33 +08:00
Estel
4401bedf96 documentation: Fix typo
Signed-off-by: Estel <callmebedrockdigger@gmail.com>
2025-05-18 16:50:32 +08:00
TargetLocked
6edc9485f6 Fix parsing legacy DNS options 2025-05-18 16:50:32 +08:00
世界
cb24b38822 Fix DNS fallback 2025-05-18 16:50:32 +08:00
世界
4217eaf1da documentation: Fix missing hosts DNS server 2025-05-18 16:50:32 +08:00
anytls
8d8a0673d2 Add MinIdleSession option to AnyTLS outbound
Co-authored-by: anytls <anytls>
2025-05-18 16:50:31 +08:00
ReleTor
0746e69907 documentation: Minor fixes 2025-05-18 16:50:31 +08:00
libtry486
a5b941315b documentation: Fix typo
fix typo

Signed-off-by: libtry486 <89328481+libtry486@users.noreply.github.com>
2025-05-18 16:50:31 +08:00
Alireza Ahmadi
9864706a4e Fix Outbound deadlock 2025-05-18 16:50:31 +08:00
世界
c3fdf13da9 documentation: Fix AnyTLS doc 2025-05-18 16:50:30 +08:00
anytls
6355f48a47 Add AnyTLS protocol 2025-05-18 16:50:29 +08:00
世界
6a48e97439 Migrate to stdlib ECH support 2025-05-18 16:50:29 +08:00
世界
8d78d59f7c Add fallback local DNS server for iOS 2025-05-18 16:50:28 +08:00
世界
c4272efe82 Get darwin local DNS server from libresolv 2025-05-18 16:50:28 +08:00
世界
bd0a0aef86 Improve resolve action 2025-05-18 16:50:28 +08:00
世界
ffba6cc930 Add back port hopping to hysteria 1 2025-05-18 16:50:27 +08:00
xchacha20-poly1305
56b1ea212f Remove single quotes of raw Moziila certs 2025-05-18 16:50:26 +08:00
世界
e1f64b9c31 Add Tailscale endpoint 2025-05-18 16:50:26 +08:00
世界
9b185b7c92 Build legacy binaries with latest Go 2025-05-18 16:50:26 +08:00
世界
7afe7abd60 documentation: Remove outdated icons 2025-05-18 16:50:26 +08:00
世界
a9da8fce10 documentation: Certificate store 2025-05-18 16:50:26 +08:00
世界
9d96ba4496 documentation: TLS fragment 2025-05-18 16:50:26 +08:00
世界
f10191d9d0 documentation: Outbound domain resolver 2025-05-18 16:50:25 +08:00
世界
2d9f44269d documentation: Refactor DNS 2025-05-18 16:50:24 +08:00
世界
b0447d54ec Add certificate store 2025-05-18 16:50:24 +08:00
世界
11c58644e1 Add TLS fragment support 2025-05-18 16:50:24 +08:00
世界
1d5f1f32b5 refactor: Outbound domain resolver 2025-05-18 16:50:24 +08:00
世界
3f50776fc3 refactor: DNS 2025-05-18 16:50:23 +08:00
13 changed files with 26 additions and 43 deletions

View File

@@ -1,10 +1,11 @@
NAME = sing-box
COMMIT = $(shell git rev-parse --short HEAD)
TAGS ?= with_gvisor,with_quic,with_dhcp,with_wireguard,with_utls,with_acme,with_clash_api,with_tailscale
TAGS ?= with_gvisor,with_dhcp,with_wireguard,with_clash_api,with_quic,with_utls,with_tailscale
TAGS_TEST ?= with_gvisor,with_quic,with_wireguard,with_grpc,with_utls
GOHOSTOS = $(shell go env GOHOSTOS)
GOHOSTARCH = $(shell go env GOHOSTARCH)
VERSION=$(shell CGO_ENABLED=0 GOOS=$(GOHOSTOS) GOARCH=$(GOHOSTARCH) go run github.com/sagernet/sing-box/cmd/internal/read_tag@latest)
VERSION=$(shell CGO_ENABLED=0 GOOS=$(GOHOSTOS) GOARCH=$(GOHOSTARCH) go run ./cmd/internal/read_tag)
PARAMS = -v -trimpath -ldflags "-X 'github.com/sagernet/sing-box/constant.Version=$(VERSION)' -s -w -buildid="
MAIN_PARAMS = $(PARAMS) -tags "$(TAGS)"

View File

@@ -7,6 +7,7 @@ import (
"strconv"
"time"
"github.com/sagernet/sing-box"
"github.com/sagernet/sing-box/experimental/deprecated"
"github.com/sagernet/sing-box/include"
"github.com/sagernet/sing-box/log"
@@ -67,5 +68,6 @@ func preRun(cmd *cobra.Command, args []string) {
if len(configPaths) == 0 && len(configDirectories) == 0 {
configPaths = append(configPaths, "config.json")
}
globalCtx = include.Context(service.ContextWith(globalCtx, deprecated.NewStderrManager(log.StdLogger())))
globalCtx = service.ContextWith(globalCtx, deprecated.NewStderrManager(log.StdLogger()))
globalCtx = box.Context(globalCtx, include.InboundRegistry(), include.OutboundRegistry(), include.EndpointRegistry(), include.DNSTransportRegistry(), include.ServiceRegistry())
}

View File

@@ -2,15 +2,6 @@
icon: material/alert-decagram
---
#### 1.12.0-beta.18
* Fixes and improvements
#### 1.12.0-beta.17
* Update quic-go to v0.52.0
* Fixes and improvements
#### 1.12.0-beta.15
* Add DERP service **1**

View File

@@ -33,9 +33,7 @@ See [Listen Fields](/configuration/shared/listen/) for details.
==Required==
A mapping Object from HTTP endpoints to [Shadowsocks Inbound](/configuration/inbound/shadowsocks) tags.
Selected Shadowsocks inbounds must be configured with [managed](/configuration/inbound/shadowsocks#managed) enabled.
A mapping Object from HTTP endpoints to Shadowsocks inbound tags.
Example:

8
go.mod
View File

@@ -10,7 +10,6 @@ require (
github.com/cretz/bine v0.2.0
github.com/go-chi/chi/v5 v5.2.1
github.com/go-chi/render v1.0.3
github.com/godbus/dbus/v5 v5.1.1-0.20230522191255-76236955d466
github.com/gofrs/uuid/v5 v5.3.2
github.com/insomniacslk/dhcp v0.0.0-20250417080101-5f8cf70e8c5f
github.com/libdns/alidns v1.0.4-libdns.v1.beta1
@@ -27,10 +26,10 @@ require (
github.com/sagernet/fswatch v0.1.1
github.com/sagernet/gomobile v0.1.6
github.com/sagernet/gvisor v0.0.0-20250325023245-7a9c0f5725fb
github.com/sagernet/quic-go v0.52.0-beta.1
github.com/sagernet/sing v0.6.11-0.20250521033217-30d675ea099b
github.com/sagernet/quic-go v0.51.0-beta.5
github.com/sagernet/sing v0.6.10-0.20250505040842-ba62fee9470f
github.com/sagernet/sing-mux v0.3.2
github.com/sagernet/sing-quic v0.5.0-beta.1
github.com/sagernet/sing-quic v0.4.1-0.20250511050139-d459f561c9c3
github.com/sagernet/sing-shadowsocks v0.2.7
github.com/sagernet/sing-shadowsocks2 v0.2.0
github.com/sagernet/sing-shadowtls v0.2.1-0.20250503051639-fcd445d33c11
@@ -79,6 +78,7 @@ require (
github.com/go-ole/go-ole v1.3.0 // indirect
github.com/gobwas/httphead v0.1.0 // indirect
github.com/gobwas/pool v0.2.1 // indirect
github.com/godbus/dbus/v5 v5.1.1-0.20230522191255-76236955d466 // indirect
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
github.com/google/btree v1.1.3 // indirect
github.com/google/go-cmp v0.6.0 // indirect

12
go.sum
View File

@@ -165,15 +165,15 @@ github.com/sagernet/netlink v0.0.0-20240612041022-b9a21c07ac6a h1:ObwtHN2VpqE0ZN
github.com/sagernet/netlink v0.0.0-20240612041022-b9a21c07ac6a/go.mod h1:xLnfdiJbSp8rNqYEdIW/6eDO4mVoogml14Bh2hSiFpM=
github.com/sagernet/nftables v0.3.0-beta.4 h1:kbULlAwAC3jvdGAC1P5Fa3GSxVwQJibNenDW2zaXr8I=
github.com/sagernet/nftables v0.3.0-beta.4/go.mod h1:OQXAjvjNGGFxaTgVCSTRIhYB5/llyVDeapVoENYBDS8=
github.com/sagernet/quic-go v0.52.0-beta.1 h1:hWkojLg64zjV+MJOvJU/kOeWndm3tiEfBLx5foisszs=
github.com/sagernet/quic-go v0.52.0-beta.1/go.mod h1:OV+V5kEBb8kJS7k29MzDu6oj9GyMc7HA07sE1tedxz4=
github.com/sagernet/quic-go v0.51.0-beta.5 h1:/mME3sJvQ8k/JKP0oC/9XoWrm0znO7hWXviB5yiipJY=
github.com/sagernet/quic-go v0.51.0-beta.5/go.mod h1:OV+V5kEBb8kJS7k29MzDu6oj9GyMc7HA07sE1tedxz4=
github.com/sagernet/sing v0.6.9/go.mod h1:ARkL0gM13/Iv5VCZmci/NuoOlePoIsW0m7BWfln/Hak=
github.com/sagernet/sing v0.6.11-0.20250521033217-30d675ea099b h1:ZjTCYPb5f7aHdf1UpUvE22dVmf7BL8eQ/zLZhjgh7Wo=
github.com/sagernet/sing v0.6.11-0.20250521033217-30d675ea099b/go.mod h1:ARkL0gM13/Iv5VCZmci/NuoOlePoIsW0m7BWfln/Hak=
github.com/sagernet/sing v0.6.10-0.20250505040842-ba62fee9470f h1:lttLhNtFuMItQcTD29QP6aBS8kR1UhG7zZ+pwzTYkFM=
github.com/sagernet/sing v0.6.10-0.20250505040842-ba62fee9470f/go.mod h1:ARkL0gM13/Iv5VCZmci/NuoOlePoIsW0m7BWfln/Hak=
github.com/sagernet/sing-mux v0.3.2 h1:meZVFiiStvHThb/trcpAkCrmtJOuItG5Dzl1RRP5/NE=
github.com/sagernet/sing-mux v0.3.2/go.mod h1:pht8iFY4c9Xltj7rhVd208npkNaeCxzyXCgulDPLUDA=
github.com/sagernet/sing-quic v0.5.0-beta.1 h1:nC0i/s8LhlZB8ev6laZCXF/uiwAE4kRdT4PcDdE4rI4=
github.com/sagernet/sing-quic v0.5.0-beta.1/go.mod h1:SAv/qdeDN+75msGG5U5ZIwG+3Ua50jVIKNrRSY8pkx0=
github.com/sagernet/sing-quic v0.4.1-0.20250511050139-d459f561c9c3 h1:1J+s1yyZ8+YAYaClI+az8YuFgV9NGXUUCZnriKmos6w=
github.com/sagernet/sing-quic v0.4.1-0.20250511050139-d459f561c9c3/go.mod h1:Mv7CdSyLepmqoLT8rd88Qn3QMv5AbsgjEm3DvEhDVNE=
github.com/sagernet/sing-shadowsocks v0.2.7 h1:zaopR1tbHEw5Nk6FAkM05wCslV6ahVegEZaKMv9ipx8=
github.com/sagernet/sing-shadowsocks v0.2.7/go.mod h1:0rIKJZBR65Qi0zwdKezt4s57y/Tl1ofkaq6NlkzVuyE=
github.com/sagernet/sing-shadowsocks2 v0.2.0 h1:wpZNs6wKnR7mh1wV9OHwOyUr21VkS3wKFHi+8XwgADg=

View File

@@ -3,7 +3,6 @@ package include
import (
"context"
"github.com/sagernet/sing-box"
"github.com/sagernet/sing-box/adapter"
"github.com/sagernet/sing-box/adapter/endpoint"
"github.com/sagernet/sing-box/adapter/inbound"
@@ -40,10 +39,6 @@ import (
E "github.com/sagernet/sing/common/exceptions"
)
func Context(ctx context.Context) context.Context {
return box.Context(ctx, InboundRegistry(), OutboundRegistry(), EndpointRegistry(), DNSTransportRegistry(), ServiceRegistry())
}
func InboundRegistry() *inbound.Registry {
registry := inbound.NewRegistry()

View File

@@ -221,14 +221,6 @@ func (t *Endpoint) Start(stage adapter.StartStage) error {
}
ipStack := t.server.ExportNetstack().ExportIPStack()
gErr := ipStack.SetSpoofing(tun.DefaultNIC, true)
if gErr != nil {
return gonet.TranslateNetstackError(gErr)
}
gErr = ipStack.SetPromiscuousMode(tun.DefaultNIC, true)
if gErr != nil {
return gonet.TranslateNetstackError(gErr)
}
ipStack.SetTransportProtocolHandler(tcp.ProtocolNumber, tun.NewTCPForwarder(t.ctx, ipStack, t).HandlePacket)
udpForwarder := tun.NewUDPForwarder(t.ctx, ipStack, t, t.udpTimeout)
ipStack.SetTransportProtocolHandler(udp.ProtocolNumber, udpForwarder.HandlePacket)

View File

@@ -214,6 +214,7 @@ func NewInbound(ctx context.Context, router adapter.Router, logger log.ContextLo
if !loaded {
return nil, E.New("parse route_address_set: rule-set not found: ", routeAddressSet)
}
ruleSet.IncRef()
inbound.routeRuleSet = append(inbound.routeRuleSet, ruleSet)
}
for _, routeExcludeAddressSet := range options.RouteExcludeAddressSet {
@@ -221,6 +222,7 @@ func NewInbound(ctx context.Context, router adapter.Router, logger log.ContextLo
if !loaded {
return nil, E.New("parse route_exclude_address_set: rule-set not found: ", routeExcludeAddressSet)
}
ruleSet.IncRef()
inbound.routeExcludeRuleSet = append(inbound.routeExcludeRuleSet, ruleSet)
}
if options.AutoRedirect {
@@ -310,7 +312,7 @@ func (t *Inbound) Start(stage adapter.StartStage) error {
if len(ipSets) == 0 {
t.logger.Warn("route_address_set: no destination IP CIDR rules found in rule-set: ", routeRuleSet.Name())
}
routeRuleSet.IncRef()
routeRuleSet.DecRef()
t.routeAddressSet = append(t.routeAddressSet, ipSets...)
if t.autoRedirect != nil {
t.routeRuleSetCallback = append(t.routeRuleSetCallback, routeRuleSet.RegisterCallback(t.updateRouteAddressSet))
@@ -322,7 +324,7 @@ func (t *Inbound) Start(stage adapter.StartStage) error {
if len(ipSets) == 0 {
t.logger.Warn("route_address_set: no destination IP CIDR rules found in rule-set: ", routeExcludeRuleSet.Name())
}
routeExcludeRuleSet.IncRef()
routeExcludeRuleSet.DecRef()
t.routeExcludeAddressSet = append(t.routeExcludeAddressSet, ipSets...)
if t.autoRedirect != nil {
t.routeExcludeRuleSetCallback = append(t.routeExcludeRuleSetCallback, routeExcludeRuleSet.RegisterCallback(t.updateRouteAddressSet))

View File

@@ -172,6 +172,8 @@ func (r *Router) RoutePacketConnectionEx(ctx context.Context, conn N.PacketConn,
} else {
r.logger.ErrorContext(ctx, err)
}
} else if onClose != nil {
onClose(nil)
}
}

View File

@@ -58,7 +58,7 @@ func NewService(ctx context.Context, logger log.ContextLogger, tag string, optio
for i, entry := range options.Servers.Entries() {
inbound, loaded := inboundManager.Get(entry.Value)
if !loaded {
return nil, E.New("parse SSM server[", i, "]: inbound ", entry.Value, " not found")
return nil, E.New("parse SSM server[", i, "]: inbound ", entry.Value, "not found")
}
managedServer, isManaged := inbound.(adapter.ManagedSSMServer)
if !isManaged {

View File

@@ -55,7 +55,7 @@ func (m *UserManager) Add(username string, password string) error {
m.access.Lock()
defer m.access.Unlock()
if _, found := m.usersMap[username]; found {
return E.New("user ", username, " already exists")
return E.New("user", username, "already exists")
}
m.usersMap[username] = password
return m.postUpdate()

View File

@@ -32,7 +32,7 @@ func TestMain(m *testing.M) {
var globalCtx context.Context
func init() {
globalCtx = include.Context(context.Background())
globalCtx = box.Context(context.Background(), include.InboundRegistry(), include.OutboundRegistry(), include.EndpointRegistry(), include.DNSTransportRegistry(), include.ServiceRegistry())
}
func startInstance(t *testing.T, options option.Options) *box.Box {