12 Commits
Author SHA1 Message Date
omarandClaude Fable 5 c257d6c5cc docs(readme): rewrite root README as Russian shater product face
- README.md: new Russian product README (what/features/architecture
  mermaid/install both feeds/build/repo layout/CI/upstream/docs/license)
- README.en.md: concise English mirror (root readme was previously English)
- README.ru.md: demoted to a pointer stub (was the sing-box-lx fork readme,
  a competing Russian README) -> points to README.md + engine-fork docs
- docs-shater/README.md: folder index

Install commands copied verbatim from docs-shater/INSTALL.md; all links
verified against existing files.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 23:31:06 +03:00
omar d41a685d9b chore: relocate shater meta-docs to docs-shater/ (avoid upstream docs/ collision)
Upstream sing-box-lx already ships a docs/ mkdocs site; keep our project docs
separate and unambiguous in docs-shater/ (parallels upstream's docs-lx/).
Updated all references in README.md, CLAUDE.md, CONTEXT.md, ARCHITECTURE.md.
2026-07-14 14:19:34 +03:00
omar d68b8e7116 docs: add CLAUDE.md (orchestrator rules) + DESIGN.md (Faceplate spec) 2026-07-14 14:17:00 +03:00
omarandClaude Opus 4.8 903f2345f3 chore: reset main for v0.2 (sing-box fork) — full context docs
Foundation pivot. The complete, working, VM-verified xray-based project is
preserved on the `v0.1` branch; `main` is reset to a docs-first scaffold for
v0.2, which will be built as a FORK of sing-box-lx with our control-plane,
DNS filter, stats and admin panel embedded in the one binary.

- Preserve everything on branch v0.1 (pushed).
- Remove the v0.1 implementation + old design docs from main (recoverable from
  v0.1); keep LICENSE, .gitignore, .gitattributes, dist/shater-feed.pub (feed
  signing key 5ac4b177689cb8e0 carries over).
- License -> GPL-3.0 (sing-box is GPL-3.0).
- Add full project context so it survives compaction:
  docs/CONTEXT.md (start here), DECISIONS.md, ARCHITECTURE.md, ROADMAP.md,
  FEATURES.md, and a new README.

Engine/UI decisions (see docs/DECISIONS.md): fork sing-box-lx (AmneziaWG 2.0 +
broad protocols, GPL-3.0, library-first) and embed the whole product for tight
integration; keep the fork maintainable via an additive overlay (shater/, panel/,
openwrt/) rebased on upstream tags. UI = thin LuCI launcher + a separate admin
panel served by the daemon, entered via a short-lived token minted in the
authenticated LuCI session. Do NOT write a proxy engine from scratch.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-14 13:53:15 +03:00
omarandClaude Opus 4.8 972665798f docs: clean up repo — English docs under docs/, proper README (EN+RU), LICENSE
build / aarch64_cortex-a53 (push) Successful in 3m12s
build / x86_64 (push) Successful in 3m6s
build / release (push) Successful in 14s
Repository housekeeping so the tree is clean and navigable:

- Remove 11 stale internal working docs (00-07 planning/audit/design drafts,
  ACCEPTANCE, PROOFS, STATUS) and the architecture.html artifact — history stays
  in git.
- Consolidate docs under docs/: BUILD.md, FEED.md (moved), CONFIG.md (English
  translation of the old Russian CONTRACT.md — full UCI schema + xrayctl/ubus
  interface), ARCHITECTURE.md (distilled English, keeps the Mermaid diagrams).
- Rewrite README.md as a proper English project readme; add a Russian mirror
  README.ru.md. Both cross-link.
- Add LICENSE (GPL-2.0-or-later) and unify PKG_LICENSE across all three package
  Makefiles (was MIT / GPL-2.0 / GPL-2.0-or-later).
- Drop dist/README.md and dist/make-feed.sh (superseded by docs/FEED.md and the
  hardened ci/make-index.sh); keep dist/shater-feed.pub.
- Fix all dangling doc references (CONTRACT.md -> docs/CONFIG.md, dead numbered
  docs) in examples/, shater-core on-device comments, xrayctl/main.go, CI notes.
- Delete build junk from the worktree (shater.zip, xrayctl.exe, out/).

No code behavior change; go build + vet still pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-14 00:18:50 +03:00
omarandClaude Opus 4.8 b4b7324db6 feat(ci): sign the opkg feed with usign (key 5ac4b177689cb8e0)
build / aarch64_cortex-a53 (push) Successful in 3m16s
build / x86_64 (push) Successful in 3m3s
build / release (push) Successful in 27s
The published feed is now usign-signed, so routers keep opkg's signature
verification ON instead of needing --no-check-signature.

- ci/install-usign.sh builds the standalone usign on the runner (the index steps
  run on the bare runner, not in the SDK container).
- ci/make-index.sh signs Packages -> Packages.sig with the secret key from the
  Gitea repo secret KEY_BUILD; it now FAILS the build if KEY_BUILD is set but
  usign is missing/broken, rather than silently shipping an unsigned feed.
- build.yml installs usign in both the per-arch build and the combined-index
  release step, passes KEY_BUILD to the release step, and publishes the public
  key (dist/shater-feed.pub) as the release asset shater-feed.pub.
- Setup is now: install the public key once into /etc/opkg/keys/<fingerprint>,
  then plain opkg update/install/upgrade with check_signature left on.

Verified locally on the VM: usign -S/-V round-trips, and with check_signature=1
and only the signed feed, `opkg update` + `opkg install luci-app-shater` succeed
with no --no-check-signature. FEED.md/README updated (key rotation documented).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-13 14:37:03 +03:00
omarandClaude Opus 4.8 6db5bfbef8 docs(readme): add opkg-feed install/upgrade quick-start + FEED.md link
build / aarch64_cortex-a53 (push) Successful in 3m6s
build / x86_64 (push) Successful in 3m0s
build / release (push) Successful in 5s
Surface the one-line feed install (`opkg install luci-app-shater` from the Gitea
release) right under the status badge, plus the upgrade command and a pointer to
FEED.md in the docs table.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-13 14:24:26 +03:00
omarandClaude Opus 4.8 05920f83ad fix: eliminate reconcile fork-storm (OOM) + resolve UCI config conflict with xray-core
build / aarch64_cortex-a53 (push) Successful in 3m0s
build / x86_64 (push) Successful in 2m59s
Two release-blocking defects found via live 512M OpenWrt VM testing.

1) Fork-storm / OOM (critical). Reconcile() -> reloadXray() ->
   "/etc/init.d/shater reload" -> reload_service -> shater_reconcile ->
   `xrayctl reconcile` -> Reconcile() was an infinite mutual recursion; each
   level blocked on CombinedOutput and spawned a process (854x reconcile +
   853x reload observed), exhausting RAM and pinning both vCPUs -> OOM-killer.
   - Reconcile() no longer calls reloadXray(); procd's file-watch on run.json
     restarts xray. Reconcile runs inside the init lifecycle, so calling the
     init back is the recursion.
   - reloadXray() now runs `/etc/init.d/shater start` (not `reload`); it is only
     invoked from Apply()/Rollback() (LuCI/ubus/CLI), never the init lifecycle.
   - init reload_service() simplified to start/stop (dropped the double reconcile).
   Verified: `xrayctl apply` 0.39s (was >185s hang); 93 procs / load 0.00 stable
   with an active 254-node config on 512M; xray binds :10853 API + :12345 tproxy.

2) UCI config namespace clash. shater shipped /etc/config/xray, which collides
   with the xray-core dependency's own /etc/config/xray (opkg dropped ours to
   /etc/config/xray-opkg, so the schema never took effect). Renamed the UCI
   namespace xray -> shater everywhere (Go uci export/commit, all 11 LuCI views +
   acl, init scripts, hotplug, Makefile conffiles, examples). Runtime paths
   (/etc/xray/run.json, /usr/share/xray), the xray-core package, and the ubus
   object name are intentionally unchanged.

Also: ci/pack-xrayctl.sh (local ipk packer) with a postinst chmod so the binary
is executable regardless of host-tar mode handling; PKG_RELEASE bumped to r3.

Verified end-to-end on a fresh 512M OpenWrt 24.10.3 VM: feed install
(opkg install luci-app-shater pulls xrayctl+shater-core), real LAN client
(netns in br-lan) proxied through a live subscription node -> exit IP changed
(104.156.233.234 vs 45.131.214.140 direct); per-client nft counters + xray
stats API populated. See PROOFS.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-09 11:36:48 +03:00
omar 58f2a6ed3d docs: goal complete — CI green (x86_64 + aarch64_cortex-a53), installed from repo, verified on OpenWrt VM
build / aarch64_cortex-a53 (push) Successful in 3m2s
build / x86_64 (push) Successful in 3m0s
2026-07-09 03:27:40 +03:00
omar 080cbc594d ci: move packages to repo root so gh-action-sdk feed finds them
build / aarch64_cortex-a53 (push) Failing after 2m11s
build / arm_cortex-a7_neon-vfpv4 (push) Failing after 2m19s
build / mipsel_24kc (push) Failing after 1m51s
build / x86_64 (push) Failing after 3m49s
CI failed: 'No feed for package xrayctl found' / 'No rule to make target
package/xrayctl/download' — gh-action-sdk indexes packages at the feed (repo)
ROOT, not a nested package/ dir. Moved xrayctl/, luci-app-shater/, shater-core/
to root; fixed workflow comment and doc paths.
2026-07-09 02:36:22 +03:00
omar 6433de209a docs: contract clarifications (name identity, resolver_fallback, dst_domain forms, fakeip pool, chain layers, src/port formats), STATUS.md with verification evidence, README index + status
build / aarch64_cortex-a53 (push) Failing after 2m22s
build / arm_cortex-a7_neon-vfpv4 (push) Failing after 2m35s
build / mipsel_24kc (push) Failing after 3m12s
build / x86_64 (push) Failing after 2m45s
2026-07-09 00:58:49 +03:00
omar 2f021c1a1a Design blueprint: architecture, feature catalog, data model, ops, roadmap (docs 00-07) 2026-07-08 23:49:28 +03:00