6 Commits
Author SHA1 Message Date
omarandClaude Opus 4.8 16a47b596b chore(awg): bump wireguard-go submodule 1adc4c7 -> 7d15f33
Fast-forward of the AmneziaWG 2.0 fork (submodules/wireguard-go,
tracked via go.mod replace). Brings 3 commits:
  - fix transport padding buffer overrun + harden AWG config guards
  - gate reserved-byte clear on receive so AmneziaWG magic survives
  - re-graft egress-provider API onto AWG2 base (upstream 6f5e8b1947ae)

Verified: native go build with with_awg compiles clean; sing-box check
passes for awg2_basic / awg2_ranged / xhttp_reality.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-23 15:10:15 +03:00
Leadaxe cdc9eaeda6 build(awg): re-graft AmneziaWG onto wireguard-go v0.0.5
Submodule bumped e5feca7 -> 1adc4c7 (branch lx-awg2-v005): AWG 2.0
obfuscation graft rebased from sagernet/wireguard-go v0.0.3 onto v0.0.5
(2c27bbf4f97f, L3-forwarding). 15/16 graft files applied clean via
3-way; send.go conflicted on one line (upstream queuedOutboundPackets
backpressure vs graft blank line — took upstream). Invariant
MessageEncapsulatingTransportSize=0 preserved; upstream InputPacket/
InputPackets and size-based outbound buffer pool taken verbatim.

go.mod pin: v0.0.3 -> v0.0.5-0.20260706153856-2c27bbf4f97f (matches
upstream/testing; replace stays local submodule).

Builds device/conn/tun on linux/android/windows/darwin; full sing-box
CLI with LX_TAGS; transport/wireguard + protocol/wireguard tests green.
2026-07-08 14:41:32 +03:00
Leadaxe c7f21672ad lx(1.14): bump wireguard-go submodule to AmneziaWG re-graft on v0.0.3
Step 2 of 2 of the 1.14 migration. Points the submodule at e5feca7
(AmneziaWG 2.0 obfuscation re-grafted onto sagernet/wireguard-go v0.0.3).

Verification on lx-1.14:
- full sing-box build with lx tags (with_gvisor/quic/wireguard/utls/clash_api/xhttp/awg): OK
- submodule builds clean for linux/android/windows/darwin (library packages)
- transport/wireguard, protocol/wireguard, protocol/group, route/rule tests: green
- broad test (option/route/transport/common): green; gofmt + go vet clean
- binary runs on 1.14; package_name_regex config validates; awg2_basic + awg2_ranged validate

§010 android UDP_GRO guard dropped (v0.0.3 fixes split-brain at source) — pending
on-device re-verification before any release tag.
2026-06-23 02:34:15 +03:00
Leadaxe 09944c0103 docs(specs): drop type/status from folder names — header + Roadmap only
Folder names were NNN-T-S-NAME, so the status (S) letter forced a rename on
every status change — and refs to the full name went stale each time. One was
already broken in-tree (client.go pointed at 002-F-O-… while the folder was
002-F-C), and the submodule needed a cosmetic commit once already (010 O→C).

Make the number the only stable anchor:
- Rename all 12 folders NNN-T-S-NAME → NNN-NAME (git mv, history preserved).
- Type/status now live in a table header at the top of each SPEC.md (canon),
  aggregated by the Roadmap in SPECS/README.md (added missing 010, 012).
- Fix every ref to the old full name: README(.ru), docs/lx-changelog,
  docs/lx-config, intra-SPECS cross-links, PROBE.md git-apply path,
  TASKS.md titles, and transport/v2rayxhttp/client.go:5 (also un-stales O).
- Rewrite the convention + Workflow in SPECS/README.md and the DoD ritual in
  IMPLEMENTATION_PROMPT.md ("rename folder to …-C-…" → "set status in header
  + Roadmap").
- Bump submodule wireguard-go (0c0c10b): fix comments point at the new folder
  name SPECS/010-WG_ENDPOINT_GRO_SPLIT_BRAIN. Comment-only, no behavior change.

Not touched: gro-probe.patch (historical diagnostic diff artifact; §010 closed,
no longer applied).
2026-06-22 11:36:37 +03:00
Leadaxe 4d4027e4f4 fix(010): WG-endpoint GRO split-brain on android (bump submodule + spec)
No-detour WireGuard-endpoint killed download on android: UDP_GRO was enabled and
rxOffload read true, but the GRO receive dispatcher in bind_std.go is gated on
GOOS=="linux" (android is not "linux") → a coalesced super-packet was read as one
datagram and corrupted the WG stream. Gate UDP_GRO + rxOffload behind !android
(TX/GSO untouched; non-android linux unchanged).

Confirmed on device (CPH2411/Android-15): pre-fix probe rxoffload=true+dispatch=
single; post-fix rxoffload=false, download 0.44→20.7 Mbps, on par with a control
node on the same LTE cell. Candidate #2 (silent handover) not needed.

Bumps wireguard-go submodule pin to 6513629 (fix, no probe). Probe instrumentation
was never on lx — it lived only on the temporary gro-probe-010/*-verify branches.

Closes SPECS/010.
2026-06-21 17:53:26 +03:00
Leadaxe a487671f39 lx(awg): activate AmneziaWG 2.0 — real obfuscation device via merged fork
- replace github.com/sagernet/wireguard-go => ./submodules/wireguard-go
  (Leadaxe/wireguard-go @27290b6: sagernet base + AmneziaWG obfuscation, 3-way merge)
- add S3/S4 padding to option.AmneziaWGOptions + device_awg.go IpcSet emitter
  (AWG 2.x; server config carries s1/s2/s3/s4)

LIVE-VALIDATED against a real AmneziaWG 2.0 server: handshake initiation ->
received handshake response -> keepalive -> traffic egresses via the server.
AWG is now functional, not just config-valid. Secrets never committed.
2026-06-09 16:51:43 +03:00