482 Commits
Author SHA1 Message Date
omar fd698162c9 health plan wave 1: urltest health board, global probe settings, sub cache out of UCI
- S1: History gains LastOK/Delay/LastFail; MarkFailed/Verdict on storage (common/urltest/board_lx.go); StoreURLTestHistory preserves LastFail
- S2: per-group ProbeURL/ProbeInterval removed, globals only; sweep_interval drained as dead option; panel fields dropped
- S5: subscription nodes cached in /etc/shater/subs/<name>.json; UCI keeps manual nodes only; sub update writes cache file; panel PUT split; legacy from_sub migration
2026-07-24 13:33:23 +03:00
omar 057fee8f96 fix(tls): gate the zap-backed ACME log bridge behind with_acme
Upstream defect: acme.go is behind with_acme but acme_logger.go was not,
so go.uber.org/zap linked into every build even with ACME disabled. Only
acme.go references ACMELogWriter/ACMEEncoderConfig, so the twin gate is
behaviour-preserving; a with_acme build still compiles.

Marked lx:acme_logger_gate; upstream-PR candidate (drop the lx block on
rebase once merged). -94 KB on the router shaterd link.
2026-07-23 09:32:38 +03:00
omarandClaude Opus 4.8 28c85a497c feat(daemon+panel): DNS log shows the source device (LAN client or 'router')
LogEntry.Device was always '' — but the client address IS on the DNS
resolution context. dnstrack.QueryEvent gains Client netip.Addr, populated at
all three dns/client_log.go emit sites from adapter.ContextFrom(ctx).Source.Addr
(same context processInfoFromContext already reads). stats deviceLabel: LAN
source (a.lanNets.isLAN) -> DHCP hostname or IP; loopback/non-LAN/unknown ->
'router' (the appliance's own urltest/sub/DoH lookups). Insights DNS log now
shows device -> domain · resolver · action (mirrors the Connections log), with
a dimmed 'router' chip for router-originated lookups; falls back to '—' on
older data.

Verified: root build (dns tree + box, router tags)/vet 0, go test ok
(deviceLabel: LAN+lease/LAN+IP/loopback->router), panel tsc/build clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-18 15:12:43 +03:00
omarandClaude Opus 4.8 a59d2c0d15 feat(shater): live statistics — DNS-query aggregator + /api/stats + Overview (Phase 5)
In-process stats fed by the engine's DNS-query event stream + nft counters.

- engine: DNSQueryManager() accessor; engine.New pre-registers a stable
  *dnstrack.Manager into e.ctx (box.New only creates one when an api/
  clash_api observable is present, which the router config has none of, so
  the manager would be nil — pre-registering keeps the DNS stream alive).
- shater/stats: Aggregator subscribes to dnstrack QueryEvents and maintains
  bounded top-domains, allowed-vs-blocked (blocked = NXDOMAIN / 0.0.0.0 /
  failed), a 60-min timeline, a 200-entry live query-log ring, per-server
  counts; polls netplane.ListClients/ListCounters for per-device + per-rule
  traffic (client IP -> DHCP hostname). Snapshot()/RecentQueries(); re-subs
  on box swap; resilient when the engine is down.
- daemon: creates+starts the aggregator, Resubscribe() after each reconcile,
  Close on SIGTERM; control-socket 'stats' verb returns the real snapshot.
- panel: GET /api/stats (snapshot) + GET /api/stats/log?n= (live log),
  session-gated; Stats type + getStatsLog() in api.ts; Overview QueryLog now
  polls the live log, plus a DNS-filtering module + blocked SegMeter + top-
  blocked list. Honest empty states, no fabricated data.
- upstream (minimal, marked // lx/D15): dnstrack SourceFiltered +
  emitFilteredResponse at the two DNS-filter predefined-block sites in
  dns/router.go — filter blocks now feed the query stream (were invisible).

Verified: stats+panel unit tests; panel tsc+build; VM E2E — DNS traffic
from a netns client produced /api/stats totals (queries 16, blocked 6),
top_domains[blocked-ad.example blocked 6], per-device row, and /api/stats/log
rows with correct block/allow; stream survived a box swap (SIGHUP). Overview
screenshot shows the live query log + blocked stats.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-15 20:11:45 +03:00
Leadaxe 9dc758e43c Merge upstream/testing (L3-forwarding, snell, bridge) into lx-1.14
Merges 14 upstream commits including L3-forwarding support (which bumped
wireguard-go v0.0.3->v0.0.5, already re-grafted in the prior commit),
snell protocol, bridge outbound, flow-tracking/sniff improvements, and
DNS/dialer fixes.

lx conflict resolutions:
- protocol/wireguard/endpoint.go: took upstream's new flow API
  (PreMatchFlow/PortAddresses/PortMTU/AttachReturn/DetachReturn/JudgeFlow),
  dropped our old PrepareConnection/NewDirectRouteConnection. SPEC 020
  idle-suspend wake guard (resumeOnDial) moved to WritePackets — the single
  point every L3-forwarded packet transits, incl. established flows that
  bypass DialContext.
- adapter/outbound.go: kept lx IdleSuspendable/ReachabilityInvalidator,
  restored 'time' import dropped by auto-merge.
- go.mod/go.sum + test/: took upstream dependency bumps (tailscale, sing,
  sing-tun); wireguard-go stays v0.0.5 with local submodule replace.

Green: full sing-box CLI with LX_TAGS (Go 1.24.7), libbox, wireguard/
adapter/dns/daemon packages, transport+protocol/wireguard tests, AWG
config validation.
2026-07-08 15:10:38 +03:00
世界 c9690acdf1 Add windows bridge 2026-07-08 18:22:36 +08:00
世界 f2dd4bfd75 Imrpove flow tracking & sniff action 2026-07-07 18:37:18 +08:00
世界 19bdedec29 dialer: Dial directly when only one interface is available 2026-07-04 22:51:38 +08:00
世界 0a11d45471 tls: Fix read wait buffer sizing 2026-07-04 14:53:03 +08:00
Leadaxe 3505beb6a4 fix(SPEC 018): cleanliness audit — comment helper name + dead SourceRejected
Two nits surfaced by the lx-vs-upstream cleanliness audit (no runtime impact):

- box.go: the dnstrack registration comment said "service.FromContext" — the
  §180 dead-stream signature. The actual readers use PtrFromContext (pairs with
  MustRegisterPtr). Fixed the comment + noted why FromContext[*T] returns nil,
  so a future debugger doesn't "fix" the readers back into §180.
- common/dnstrack/manager.go: removed the unused SourceRejected constant —
  rejected resolutions are folded into SourceFailed at the emit site, so
  "rejected" never reaches the wire. Replaced with a comment to prevent re-adding
  an unreachable client case.

Audit verdict: code clean — no concurrency/wire/behaviour issues; dns/client.go
byte-identical to upstream, emits additive and subscriber-gated.
2026-06-27 01:13:53 +03:00
Leadaxe 3e4c178339 lx(1.14): SPEC 018 — DNS server + outbound in stream, subscriber-gated
LxBox feedback: DnsQuery lacked which DNS server / outbound channel the query went
through. A DNS rule selects a server (matchDNS by action.Server), not an outbound;
the channel is the server's own detour, fixed at config time. Add to DnsQueryEvent:
- dnsServer/dnsServerType = transport.Tag()/Type() (transport is the Exchange param,
  so available on all emit paths incl. failures);
- outbound = the server's detour tag (TransportAdapter.OutboundTag() from
  DialerOptions.Detour), with a selector expanded to its live node via Now()
  server-side (like Connection.Detour), empty on cached/optimistic.

Also gate event construction on HasSubscribers(): with no profiler attached the DNS
hot path builds nothing (no event/answers/outbound lookup) — previously every
resolution built an event just to be dropped for lack of a listener. The Now()
resolution therefore never touches the hot path.

Wire: additive proto fields + OutboundTag() on DNSTransport (embedded adapter
satisfies it). libbox DnsQuery.DNSServer/DNSServerType/Outbound(). Changelog rc.10.
2026-06-27 00:42:29 +03:00
Leadaxe cffbfcbfce lx(1.14): SPEC 018 SubscribeDNSQueries — structured DNS-query stream
Hijacked DNS (the norm on an Android VPN) is answered before a connection becomes
a traffic tracker, so DNS queries never reach the connections stream — the only
egress was the text log, which carries no app attribution. Add common/dnstrack
(a Subscriber[QueryEvent] mirror of trafficcontrol) emitting one event per
resolution from dns/client.go, attributed via adapter.ContextFrom(ctx).ProcessInfo
(same ctx on cache-hit and miss, so cached queries are attributed too).

Failures are first-class: timeout/loopback/rejected-cached/SERVFAIL-reject emit
failed=true + error + rcode=-1 (no response) — without this the stream is blind to
DNS failures, the primary throttling signal. CNAME chains preserved: with
includeAnswers, each event carries the full response.Answer in wire order (CNAME
hops + final A/AAAA, not filtered to IPs).

Wire: rpc SubscribeDNSQueries(SubscribeDNSQueriesRequest) returns (stream
DnsQueryEvent) + DnsAnswer; event-driven server stream (no ticker); libbox
SubscribeDNSQueries(includeAnswers, handler). Tag-less core -> Unimplemented.
Detour/Chain and other streams unchanged.

Docs: SPECS/018, lx-changelog rc.7.
2026-06-26 16:26:09 +03:00
Leadaxe 7804bf9d85 Merge remote-tracking branch 'upstream/testing' into lx-1.14
# Conflicts:
#	box.go
#	cmd/internal/build_libbox/main.go
#	common/certificate/store.go
#	common/trafficcontrol/tracker.go
#	daemon/managed_service.pb.go
#	daemon/managed_service_grpc.pb.go
#	daemon/started_service.pb.go
#	daemon/started_service.proto
#	daemon/started_service_grpc.pb.go
#	docs/changelog.md
#	go.mod
#	go.sum
#	service/oomkiller/service.go
#	service/oomkiller/service_darwin.go
2026-06-26 14:27:59 +03:00
Leadaxe c12ee663b1 lx(1.14): SPEC 017 Connection.Detour — transport detour tail of final outbound
chain omits the final outbound's own detour by design (upstream loop only
unwinds OutboundGroup via Now() and breaks on the first non-group), so a node
detouring through e.g. WARP never shows in the routing chain. Add Detour
[]string to TrackerMetadata, unwound from the final outbound's Dependencies()
(= its detour for a non-group outbound), descending into groups via Now()
against the same atomic snapshot, with a seen-guard against cycles.

Wire: additive 'repeated string detourList = 23' on the Connection proto
message (hand-applied to keep the generated diff minimal — no toolchain churn),
mapped in connectionToProto, surfaced on libbox Connection as Detour()
StringIterator. Chain / Clash-API unchanged.

Docs: SPECS/017, lx-changelog rc.6.
2026-06-26 14:14:34 +03:00
世界 64a0e0ce6b certificate: Replace platform bridge with CGO JNI 2026-06-25 17:39:16 +08:00
世界 7e96370229 Fix group status updates broken by API service
The URL test history update hook and the Clash mode update hook were
single-slot: the API service's attached service overwrote the hook set
by the daemon, so clients stopped receiving group updates. Replace both
with multicast hook lists.

Also share a single URL test history storage via context: Clash API
looked it up under a key nobody registered and fell back to its own
empty storage, so dashboards showed no delay once an API service was
configured. Selector changes now notify through the shared storage,
covering selections made from any API surface.
2026-06-25 17:38:54 +08:00
世界 95c37c138a Add sing-box API service 2026-06-25 17:38:53 +08:00
世界 8218042258 process: Fix panic when package manager is unavailable on Android 2026-06-25 17:38:25 +08:00
世界 2c2e08e608 Fix lint errors 2026-06-25 17:38:13 +08:00
世界 d99fc94fbc Fix TLS server close 2026-06-25 17:38:12 +08:00
macronut c768f248d9 Add more spoof method
Signed-off-by: macronut <4027187+macronut@users.noreply.github.com>
2026-06-25 17:38:11 +08:00
世界 dd454bf0c6 dns: Add timeout configuration 2026-06-25 17:38:08 +08:00
nekohasekai a37fcd59bb Add Windows TLS engine 2026-06-25 17:38:07 +08:00
世界 4cdacb3e63 Improve UDP batch support 2026-06-25 17:38:07 +08:00
世界 6e2c0fa249 Add ACME profile support for IP address certificates 2026-06-25 17:38:05 +08:00
世界 da6ab370df Fix goroutine leak in networkquality tool
Serialize probe rounds in startProber to eliminate unbounded fan-out of
fire-and-forget probe goroutines (up to 100/sec per direction), and close
HTTP/3 transports via transport.Close() in addition to CloseIdleConnections.
2026-06-25 17:38:05 +08:00
世界 4f279bc1e7 Fix tls-spoof 2026-06-25 17:38:04 +08:00
世界 6b07ec3aff Fix Apple TLS metadata capture 2026-06-25 17:38:04 +08:00
世界 6e4f70f155 Defer implicit default HTTP client fallback to first use 2026-06-25 17:38:03 +08:00
世界 16fe1e7ee0 Scope HTTP/2 fallback and HTTP/3 broken state per authority 2026-06-25 17:38:03 +08:00
世界 5ca971aa4d Fix macOS tlsspoof 2026-06-25 17:38:03 +08:00
世界 146f35483d Reject IP literal server name with TLS spoof 2026-06-25 17:38:02 +08:00
世界 b04b235661 Fix legacy rule-set download_detour blocked by empty direct check 2026-06-25 17:38:01 +08:00
世界 3d1d6acbe3 Add TLS spoof support 2026-06-25 17:38:01 +08:00
世界 cfe83a5dcc Refactor: HTTP clients, unified HTTP2/QUIC options, Apple engines 2026-06-25 17:37:59 +08:00
世界 ecd07e2f85 Add optimistic DNS cache 2026-06-25 17:37:59 +08:00
世界 2f62a35e1b Fix stun test 2026-06-25 17:37:58 +08:00
世界 cfe5fdcb79 Fix lint errors 2026-06-25 17:35:31 +08:00
世界 dec919e0ca Add package_name_regex route, DNS and headless rule item 2026-06-25 17:35:30 +08:00
世界 7bac8dc815 tools: Network Quality & STUN 2026-06-25 17:35:27 +08:00
nekohasekai 1d523907cb Refactor ACME support to certificate provider 2026-06-25 17:35:24 +08:00
世界 f0f2617b79 Fix group status updates broken by API service
The URL test history update hook and the Clash mode update hook were
single-slot: the API service's attached service overwrote the hook set
by the daemon, so clients stopped receiving group updates. Replace both
with multicast hook lists.

Also share a single URL test history storage via context: Clash API
looked it up under a key nobody registered and fell back to its own
empty storage, so dashboards showed no delay once an API service was
configured. Selector changes now notify through the shared storage,
covering selections made from any API surface.
2026-06-20 22:24:42 +08:00
世界 3a5d654463 Add sing-box API service 2026-06-20 22:24:42 +08:00
世界 c31db962ee process: Fix panic when package manager is unavailable on Android 2026-06-20 22:23:19 +08:00
世界 806da5f845 Fix lint errors 2026-06-20 22:23:01 +08:00
世界 5b412f19e4 Fix TLS server close 2026-06-20 22:22:52 +08:00
macronut 3609cf660f Add more spoof method
Signed-off-by: macronut <4027187+macronut@users.noreply.github.com>
2026-06-20 22:22:33 +08:00
世界 d880835ac4 dns: Add timeout configuration 2026-06-20 22:22:30 +08:00
nekohasekai 1226d744b7 Add Windows TLS engine 2026-06-20 22:22:28 +08:00
世界 1c3a335d99 Improve UDP batch support 2026-06-20 22:22:28 +08:00