#
# ByeDPI (ciadpi) desync SOCKS proxies (/etc/config/byedpi).
#
# Each `config instance` is one supervised `ciadpi` process bound to
# 127.0.0.1:<port>. Point a Shater egress at it:
#
#   config egress 'bd'
#       option name 'bd'
#       option type 'byedpi'
#       option port '1080'          # must match an enabled instance's `port`
#
# then a rule with `option target 'egress:bd'` routes selected traffic through
# ciadpi, which desyncs it and connects DIRECTLY to the target (no tunnel).
#
# This shipped default is INERT (enabled='0'): installing the package opens no
# listener. Set enabled='1' and apply to bring the proxy up.
#
# This file is a conffile — your edits survive package upgrades.
#

config instance 'default'
	option enabled '0'
	option port '1080'
	# Desync preset (documented ByeDPI example — general RKN/YouTube-busting):
	#   --disorder 1   : split the first segment at offset 1 and send the two
	#                    parts in REVERSE order (TCP desync; defeats naive
	#                    stream reassembly in the DPI).
	#   --auto=torst   : auto mode — if the connection is reset (TCP RST), retry
	#                    with the desync params instead of failing.
	#   --tlsrec 1+s   : re-frame the TLS record boundary at the SNI offset +1,
	#                    so the ClientHello SNI is split across TLS records and
	#                    SNI-based DPI can't match the hostname.
	option args '--disorder 1 --auto=torst --tlsrec 1+s'
