Files
shater/openwrt/byedpi/Makefile
T
omarandClaude Opus 5 a8f2b0f068 ci: derive package versions from the git tag (B4)
PKG_VERSION/PKG_RELEASE were hand-written literals nobody bumped, so
v0.2.2 … v0.2.6 all shipped as `shaterd 0.2.0-r3` with different binaries
inside (v0.2.6's ELF is 5 491 616 B against r2's 5 488 336 B). Both opkg
and apk offer an upgrade only when the feed's version string differs from
the installed one, so `apk update` saw nothing new and the routers could
not be updated through the normal path at all.

ci/version.sh is now the single source of truth. It derives the version
from `git describe`:

    tag `vX.Y.Z`   -> PKG_VERSION=X.Y.Z  PKG_RELEASE=1
    off-tag build  -> nearest tag + PKG_RELEASE=<commits since it> + 1
    no tag/no git  -> 0.0.0-r1 (below everything ever published)

Ordering verified with the real tools, not from memory — apk-tools 3.0.3
(`apk version -t`) and opkg 38eccbb1 (`opkg compare-versions`) agree that
0.2.0-r3 < 0.2.6-r2 < 0.2.6-r10 < 0.2.6-r12 < 0.2.7-r1 < 0.3.0-r1, so a
release always outranks the rolling builds that preceded it and rolling
builds grow monotonically between releases.

The value travels as SHATER_PKG_VERSION/SHATER_PKG_RELEASE in the SDK
build environment of BOTH lanes; the Makefiles keep a literal fallback so
a manual/offline build still works with no CI and no git. Because the
hand-off crosses docker, `su` and make's env import, ci/sdk-build.sh and
ci/sdk-build-apk.sh now ASSERT that the produced .ipk/.apk really carries
that version — the B4 failure mode was a stale version shipping silently,
and that can no longer happen quietly.

The binary agrees with the package: scripts/build-shaterd.sh takes
constant.Version from the same ci/version.sh (vX.Y.Z-rR[-g<sha>]) instead
of its own `git describe`, and the workflow computes it once per job.
Both build jobs now check out with fetch-depth: 0 — `git describe` needs
tags and ancestry, which the default shallow checkout has neither of.

byedpi is deliberately left alone: PKG_VERSION:=0.17.3 is upstream
ByeDPI's own version, what PKG_HASH pins and what tells an operator which
ByeDPI is installed. Stamping our tag on it would also be a downgrade —
every comparator reads 0.2.7 < 0.17.3 (component-wise, 2 < 17), verified.

Docs: INSTALL.md gains §2.1 (the scheme + the ordering evidence), and the
update sections of §5/§6 now explicitly warn against a bare `opkg upgrade`
/ `apk upgrade` and give the targeted form instead, quoting apk-tools 3:
"If list of packages is provided, only those packages are upgraded along
with needed dependencies". README.md and the release bodies match.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25 12:32:38 +03:00

100 lines
4.3 KiB
Makefile

#
# byedpi — ByeDPI (ciadpi), a tiny portable-C SOCKS5/HTTP desync proxy.
#
# This is the process behind a Shater egress of `type='byedpi'`: shaterd's
# `generate` emits a SOCKS5 outbound `egress-<name>` -> 127.0.0.1:<port>, and a
# `ciadpi` instance supervised by this package listens on that port, applies
# TCP/TLS desync to the connections passing through it, and goes DIRECT to the
# target (no tunnel). Kept as a SEPARATE, optional package: a byedpi egress is
# opt-in — install this only when you want the external desync engine.
#
# Compiled C (musl, per target) => NOT PKGARCH:=all. The OpenWrt SDK toolchain
# cross-compiles ciadpi via its own plain Makefile.
#
include $(TOPDIR)/rules.mk
PKG_NAME:=byedpi
# DELIBERATELY NOT auto-versioned from our git tag (unlike shaterd/shater-core/
# luci-app-shater, which take SHATER_PKG_VERSION/SHATER_PKG_RELEASE from
# ci/version.sh). PKG_VERSION here is THIRD-PARTY UPSTREAM's version — it is what
# PKG_SOURCE_URL/PKG_HASH pin, and what tells an operator which ByeDPI is
# actually installed. Stamping our tag on it would be both a lie and a
# regression: our tags are 0.2.x, and every version comparator (apk-tools 3 and
# opkg alike, verified) reads 0.2.7 < 0.17.3 — component-wise numerically, 2 < 17
# — so the "new" package would be a DOWNGRADE and routers would refuse it.
# Bump PKG_RELEASE BY HAND when *our packaging* of it changes (init script, uci
# defaults, build flags); bump PKG_VERSION+PKG_HASH when upstream releases.
PKG_VERSION:=0.17.3
PKG_RELEASE:=1
# Pinned upstream release tag v0.17.3 (commit
# 7efde1b1296eaaa187b70e951894dde17527489c). codeload emits a stable tarball
# per tag; PKG_HASH is the sha256 of that tarball (build fails on mismatch).
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_SOURCE_URL:=https://codeload.github.com/hufrea/byedpi/tar.gz/refs/tags/v$(PKG_VERSION)?
PKG_HASH:=0a9cb8585554c68c3e2be88c33c9bf6f99f8e8c7f54b362285adab99e262566c
PKG_MAINTAINER:=Shater <maqrota@icloud.com>
PKG_LICENSE:=MIT
PKG_LICENSE_FILES:=LICENSE
include $(INCLUDE_DIR)/package.mk
define Package/byedpi
SECTION:=net
CATEGORY:=Network
TITLE:=ByeDPI (ciadpi) local SOCKS5/HTTP desync proxy
URL:=https://github.com/hufrea/byedpi
# Pure C against musl; every target has a C toolchain, so no arch-depends.
# No runtime library deps beyond libc (static-ish tiny binary).
DEPENDS:=
endef
define Package/byedpi/description
ByeDPI is a small local SOCKS5/HTTP proxy that applies TCP/TLS desynchronization
(split, disorder, fake packets, TLS-record splitting) to the connections passing
through it and then connects DIRECTLY to the destination — no upstream tunnel.
Its binary is `ciadpi`. In the Shater stack it is the process behind an egress of
`type='byedpi'`: shaterd routes selected traffic to a local SOCKS5 outbound
pointed at ciadpi's 127.0.0.1:<port>. Multi-instance, driven by /etc/config/byedpi.
endef
# ciadpi's upstream Makefile appends its own required flags with `CFLAGS +=`.
# A CFLAGS set on the make command line CLOBBERS that `+=` (GNU make: a
# command-line assignment overrides the makefile's append), so we must re-supply
# ciadpi's own needed flags (-I. -std=c99 and its warning set) alongside
# $(TARGET_CFLAGS). CPPFLAGS (-D_DEFAULT_SOURCE) is left untouched by not
# overriding it. The default target `all` builds the `ciadpi` binary; its link
# rule is `$(CC) -o ciadpi $(OBJ) $(LDFLAGS)`, so $(TARGET_LDFLAGS) reaches the
# link. Kernel headers (linux/netfilter_ipv4.h) come from the SDK sysroot.
define Build/Compile
+$(MAKE) -C $(PKG_BUILD_DIR) \
CC="$(TARGET_CC)" \
CFLAGS="$(TARGET_CFLAGS) -I. -std=c99 -Wall -Wno-unused -Wextra -Wno-unused-parameter" \
LDFLAGS="$(TARGET_LDFLAGS)" \
all
endef
define Package/byedpi/install
$(INSTALL_DIR) $(1)/usr/bin
$(INSTALL_BIN) $(PKG_BUILD_DIR)/ciadpi $(1)/usr/bin/ciadpi
$(INSTALL_DIR) $(1)/etc/init.d
$(INSTALL_BIN) ./files/etc/init.d/byedpi $(1)/etc/init.d/byedpi
$(INSTALL_DIR) $(1)/etc/config
$(INSTALL_CONF) ./files/etc/config/byedpi $(1)/etc/config/byedpi
$(INSTALL_DIR) $(1)/etc/uci-defaults
$(INSTALL_BIN) ./files/etc/uci-defaults/40_byedpi $(1)/etc/uci-defaults/40_byedpi
endef
# /etc/config/byedpi is user-editable desired state -> preserve on upgrade.
define Package/byedpi/conffiles
/etc/config/byedpi
endef
$(eval $(call BuildPackage,byedpi))