Two suspicions, both put to a test rather than to a reading. Both were real, and
neither was the leak the suspicion named — both are objects released while still
in use.
roundTripHTTP3Race ran both racers on one cancellable context and cancelled it
before returning the WINNER. quic-go and net/http reset a request's stream when
its context dies, so the caller got a response whose body stopped mid-read:
H3_REQUEST_CANCELLED (local) (read 2687 of 65536 bytes). That path is taken
whenever there is no cached HTTP/3 connection and the request is replayable —
the first request to every host, and every one after an idle close. Each racer
now has a context of its own; losers are cancelled where everything used to be,
and the winner's cancel travels with its body.
DoH3's Exchange packed the query into a POOLED buffer and released it the moment
RoundTrip returned. But http3 writes the request body on a goroutine of its own
and returns as soon as the response HEADERS arrive — the body is still being
read. With the window held open the query on the wire diverges from the query we
packed at exactly offset 8192, quic-go's copy-buffer size: everything past that
was the next pool user's memory, sent to the resolver. Not a slowdown — a data
race and a small memory-disclosure primitive. The buffer now goes back when the
transport closes the body, which http3 does on every path, and can do twice.
Both files diverge from upstream again, hours after 0a6689b29 made them
byte-identical on purpose. Upstream carries the second defect in
dns/transport/https.go too; that file is outside this audit and is named in D27
so the next person finds it instead of rediscovering it.
sing-quic moves v0.6.2-0.20260525051024 -> v0.6.4-0.20260709034545. quic.go is
byte-identical across the two, so this neither duplicates nor retires the
packet-conn ownership fix — quic-go still does not own the socket. What it does
carry is the other half of the family we took only half of: clientConn.Close in
tuic/, hysteria/ and hysteria2/ now sets a past write deadline, word for word
the fix v2rayquic already had. We ship tuic and hysteria2. Cost, measured:
+256 KiB exactly on the stripped aarch64 binary and six indirect modules for a
realm port-mapping path nothing we generate can reach.
Tests are mutation-checked: reverting each fix makes them fail, with the text
quoted above. The DoH3 test carries its own control — it first proves the pool
does hand a released buffer back and that poisoning it lands, because a clean
result from an instrument that cannot produce a dirty one proves nothing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BHw89tdWddzhjUc4bAH4tS
204 lines
11 KiB
AMPL
204 lines
11 KiB
AMPL
module github.com/sagernet/sing-box
|
|
|
|
go 1.24.7
|
|
|
|
require (
|
|
filippo.io/age v1.3.1
|
|
github.com/anthropics/anthropic-sdk-go v1.26.0
|
|
github.com/anytls/sing-anytls v0.0.11
|
|
github.com/caddyserver/certmagic v0.25.3-0.20260421143802-60d9d8b415d6
|
|
github.com/caddyserver/zerossl v0.1.5
|
|
github.com/coder/websocket v1.8.14
|
|
github.com/creack/pty v1.1.24
|
|
github.com/cretz/bine v0.2.0
|
|
github.com/database64128/tfo-go/v2 v2.3.2
|
|
github.com/go-chi/chi/v5 v5.2.5
|
|
github.com/go-chi/render v1.0.3
|
|
github.com/godbus/dbus/v5 v5.2.2
|
|
github.com/gofrs/uuid/v5 v5.4.0
|
|
github.com/insomniacslk/dhcp v0.0.0-20260220084031-5adc3eb26f91
|
|
github.com/jsimonetti/rtnetlink v1.4.0
|
|
github.com/keybase/go-keychain v0.0.1
|
|
github.com/libdns/acmedns v0.5.0
|
|
github.com/libdns/alidns v1.0.6
|
|
github.com/libdns/cloudflare v0.2.2
|
|
github.com/libdns/libdns v1.1.1
|
|
github.com/logrusorgru/aurora v2.0.3+incompatible
|
|
github.com/mdlayher/netlink v1.9.0
|
|
github.com/metacubex/utls v1.8.4
|
|
github.com/mholt/acmez/v3 v3.1.6
|
|
github.com/miekg/dns v1.1.72
|
|
github.com/openai/openai-go/v3 v3.26.0
|
|
github.com/oschwald/maxminddb-golang v1.13.1
|
|
github.com/pkg/sftp v1.13.10
|
|
github.com/sagernet/asc-go v0.0.0-20241217030726-d563060fe4e1
|
|
github.com/sagernet/bbolt v0.0.0-20231014093535-ea5cb2fe9f0a
|
|
github.com/sagernet/cors v1.2.1
|
|
github.com/sagernet/cronet-go v0.0.0-20260620140045-05ab0dc17597
|
|
github.com/sagernet/cronet-go/all v0.0.0-20260620140045-05ab0dc17597
|
|
github.com/sagernet/fswatch v0.1.2
|
|
github.com/sagernet/gliderssh v0.3.4-0.20260531100337-2194faca5648
|
|
github.com/sagernet/gomobile v0.1.12
|
|
github.com/sagernet/gvisor v0.0.0-20250811.0-sing-box-mod.1
|
|
github.com/sagernet/netlink v0.0.0-20240612041022-b9a21c07ac6a
|
|
github.com/sagernet/nftables v0.3.0-mod.3
|
|
github.com/sagernet/quic-go v0.59.0-sing-box-mod.4
|
|
github.com/sagernet/sing v0.8.12-0.20260702081104-2ded2af32d3d
|
|
github.com/sagernet/sing-cloudflared v0.1.3-0.20260706062323-d9787e794aa3
|
|
github.com/sagernet/sing-mux v0.3.5
|
|
github.com/sagernet/sing-quic v0.6.4-0.20260709034545-e23afe1172dc
|
|
github.com/sagernet/sing-shadowsocks v0.2.8
|
|
github.com/sagernet/sing-shadowsocks2 v0.2.1
|
|
github.com/sagernet/sing-shadowtls v0.2.1
|
|
github.com/sagernet/sing-snell v0.0.0-20260705044717-4e9e73be7814
|
|
github.com/sagernet/sing-tun v0.8.12-0.20260708091449-be1a05a4c962
|
|
github.com/sagernet/sing-usbip v0.0.0-20260616101517-efb91521eddb
|
|
github.com/sagernet/sing-vmess v0.2.8-0.20250909125414-3aed155119a1
|
|
github.com/sagernet/smux v1.5.50-sing-box-mod.1
|
|
github.com/sagernet/tailscale v1.92.4-sing-box-1.13-mod.7.0.20260706062137-ae2dde1295a3
|
|
github.com/sagernet/wireguard-go v0.0.5-0.20260706153856-2c27bbf4f97f
|
|
github.com/sagernet/ws v0.0.0-20231204124109-acfe8907c854
|
|
github.com/spf13/cobra v1.10.2
|
|
github.com/stretchr/testify v1.11.1
|
|
github.com/vishvananda/netns v0.0.5
|
|
go.uber.org/zap v1.27.1
|
|
go4.org/netipx v0.0.0-20231129151722-fdeea329fbba
|
|
golang.org/x/crypto v0.48.0
|
|
golang.org/x/exp v0.0.0-20251219203646-944ab1f22d93
|
|
golang.org/x/mod v0.33.0
|
|
golang.org/x/net v0.50.0
|
|
golang.org/x/sync v0.19.0
|
|
golang.org/x/sys v0.41.0
|
|
golang.zx2c4.com/wireguard/wgctrl v0.0.0-20241231184526-a9ab2273dd10
|
|
google.golang.org/grpc v1.79.1
|
|
google.golang.org/protobuf v1.36.11
|
|
howett.net/plist v1.0.1
|
|
)
|
|
|
|
require (
|
|
filippo.io/edwards25519 v1.1.0 // indirect
|
|
filippo.io/hpke v0.4.0 // indirect
|
|
github.com/ajg/form v1.5.1 // indirect
|
|
github.com/akutz/memconn v0.1.0 // indirect
|
|
github.com/alexbrainman/sspi v0.0.0-20231016080023-1a75b4708caa // indirect
|
|
github.com/andybalholm/brotli v1.1.0 // indirect
|
|
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
|
|
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
|
|
github.com/coreos/go-iptables v0.7.1-0.20240112124308-65c67c9f46e6 // indirect
|
|
github.com/coreos/go-oidc/v3 v3.17.0 // indirect
|
|
github.com/database64128/netx-go v0.1.1 // indirect
|
|
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
|
|
github.com/dblohm7/wingoes v0.0.0-20240119213807-a09d6be7affa // indirect
|
|
github.com/dgrijalva/jwt-go/v4 v4.0.0-preview1 // indirect
|
|
github.com/ebitengine/purego v0.10.0 // indirect
|
|
github.com/florianl/go-nfqueue/v2 v2.0.2 // indirect
|
|
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
|
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
|
|
github.com/gaissmai/bart v0.18.0 // indirect
|
|
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
|
|
github.com/go-json-experiment/json v0.0.0-20250813024750-ebf49471dced // indirect
|
|
github.com/go-ole/go-ole v1.3.0 // indirect
|
|
github.com/gobwas/httphead v0.1.0 // indirect
|
|
github.com/gobwas/pool v0.2.1 // indirect
|
|
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
|
|
github.com/google/btree v1.1.3 // indirect
|
|
github.com/google/go-cmp v0.7.0 // indirect
|
|
github.com/google/go-querystring v1.1.0 // indirect
|
|
github.com/google/gopacket v1.1.19 // indirect
|
|
github.com/google/nftables v0.2.1-0.20240414091927-5e242ec57806 // indirect
|
|
github.com/google/uuid v1.6.0 // indirect
|
|
github.com/hashicorp/yamux v0.1.2 // indirect
|
|
github.com/hdevalence/ed25519consensus v0.2.0 // indirect
|
|
github.com/huin/goupnp v1.2.0 // indirect
|
|
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
|
github.com/jackpal/go-nat-pmp v1.0.2 // indirect
|
|
github.com/klauspost/compress v1.18.0 // indirect
|
|
github.com/klauspost/cpuid/v2 v2.3.0 // indirect
|
|
github.com/koron/go-ssdp v0.0.4 // indirect
|
|
github.com/kr/fs v0.1.0 // indirect
|
|
github.com/libp2p/go-nat v1.0.1-0.20250821073202-01afc089f138 // indirect
|
|
github.com/libp2p/go-netroute v0.2.1 // indirect
|
|
github.com/mdlayher/socket v0.5.1 // indirect
|
|
github.com/mitchellh/go-ps v1.0.0 // indirect
|
|
github.com/philhofer/fwd v1.2.0 // indirect
|
|
github.com/pierrec/lz4/v4 v4.1.21 // indirect
|
|
github.com/pires/go-proxyproto v0.8.1 // indirect
|
|
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
|
|
github.com/prometheus-community/pro-bing v0.4.0 // indirect
|
|
github.com/quic-go/qpack v0.6.0 // indirect
|
|
github.com/safchain/ethtool v0.3.0 // indirect
|
|
github.com/sagernet/cronet-go/lib/android_386 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/android_amd64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/android_arm v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/android_arm64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/darwin_amd64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/darwin_arm64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/ios_amd64_simulator v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/ios_arm64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/ios_arm64_simulator v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_386 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_386_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_amd64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_amd64_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_arm v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_arm64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_arm64_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_arm_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_loong64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_loong64_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_mips64le v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_mipsle v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_mipsle_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_riscv64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/linux_riscv64_musl v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/tvos_amd64_simulator v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/tvos_arm64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/tvos_arm64_simulator v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/windows_amd64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/sagernet/cronet-go/lib/windows_arm64 v0.0.0-20260620135226-def9ff0fb992 // indirect
|
|
github.com/spf13/pflag v1.0.9 // indirect
|
|
github.com/tailscale/certstore v0.1.1-0.20231202035212-d3fa0460f47e // indirect
|
|
github.com/tailscale/go-winio v0.0.0-20231025203758-c4f33415bf55 // indirect
|
|
github.com/tailscale/goupnp v1.0.1-0.20210804011211-c64d0f06ea05 // indirect
|
|
github.com/tailscale/hujson v0.0.0-20221223112325-20486734a56a // indirect
|
|
github.com/tailscale/netlink v1.1.1-0.20240822203006-4d49adab4de7 // indirect
|
|
github.com/tailscale/peercred v0.0.0-20250107143737-35a0c7bd7edc // indirect
|
|
github.com/tailscale/web-client-prebuilt v0.0.0-20250124233751-d4cd19a26976 // indirect
|
|
github.com/tidwall/gjson v1.18.0 // indirect
|
|
github.com/tidwall/match v1.1.1 // indirect
|
|
github.com/tidwall/pretty v1.2.1 // indirect
|
|
github.com/tidwall/sjson v1.2.5 // indirect
|
|
github.com/u-root/uio v0.0.0-20240224005618-d2acac8f3701 // indirect
|
|
github.com/x448/float16 v0.8.4 // indirect
|
|
github.com/zeebo/blake3 v0.2.4 // indirect
|
|
go.uber.org/multierr v1.11.0 // indirect
|
|
go.uber.org/zap/exp v0.3.0 // indirect
|
|
go4.org/mem v0.0.0-20240501181205-ae6ca9944745 // indirect
|
|
golang.org/x/oauth2 v0.34.0 // indirect
|
|
golang.org/x/term v0.40.0 // indirect
|
|
golang.org/x/text v0.34.0 // indirect
|
|
golang.org/x/time v0.11.0 // indirect
|
|
golang.org/x/tools v0.42.0 // indirect
|
|
golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 // indirect
|
|
golang.zx2c4.com/wireguard/windows v0.5.3 // indirect
|
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
|
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
|
lukechampine.com/blake3 v1.3.0 // indirect
|
|
zombiezen.com/go/capnproto2 v2.18.2+incompatible // indirect
|
|
)
|
|
|
|
// lx:begin awg
|
|
// AmneziaWG 2.0: swap the WireGuard implementation for our merged fork
|
|
// (sagernet/wireguard-go base + AmneziaWG obfuscation grafted via 3-way merge),
|
|
// which understands the obfuscation IpcSet keys (jc/jmin/jmax/s1/s2/s3/s4/h1..h4/i1..i5)
|
|
// emitted by transport/wireguard/device_awg.go. The module path stays
|
|
// github.com/sagernet/wireguard-go, so no import edits are needed. The merged
|
|
// fork keeps the sagernet-fork additions sing-box relies on (Send offset contract,
|
|
// InputPacket, conn reserved/control) and neutralizes the 8-byte encapsulating
|
|
// headroom (MessageEncapsulatingTransportSize=0) so obfuscation composes cleanly.
|
|
// Local-path replace for iteration; switch to a pinned Leadaxe/wireguard-go commit
|
|
// for CI/release once validated against a live AWG2 server. See SPECS/003.
|
|
replace github.com/sagernet/wireguard-go => ./submodules/wireguard-go
|
|
|
|
// lx:end awg
|