PKG_VERSION/PKG_RELEASE were hand-written literals nobody bumped, so
v0.2.2 … v0.2.6 all shipped as `shaterd 0.2.0-r3` with different binaries
inside (v0.2.6's ELF is 5 491 616 B against r2's 5 488 336 B). Both opkg
and apk offer an upgrade only when the feed's version string differs from
the installed one, so `apk update` saw nothing new and the routers could
not be updated through the normal path at all.
ci/version.sh is now the single source of truth. It derives the version
from `git describe`:
tag `vX.Y.Z` -> PKG_VERSION=X.Y.Z PKG_RELEASE=1
off-tag build -> nearest tag + PKG_RELEASE=<commits since it> + 1
no tag/no git -> 0.0.0-r1 (below everything ever published)
Ordering verified with the real tools, not from memory — apk-tools 3.0.3
(`apk version -t`) and opkg 38eccbb1 (`opkg compare-versions`) agree that
0.2.0-r3 < 0.2.6-r2 < 0.2.6-r10 < 0.2.6-r12 < 0.2.7-r1 < 0.3.0-r1, so a
release always outranks the rolling builds that preceded it and rolling
builds grow monotonically between releases.
The value travels as SHATER_PKG_VERSION/SHATER_PKG_RELEASE in the SDK
build environment of BOTH lanes; the Makefiles keep a literal fallback so
a manual/offline build still works with no CI and no git. Because the
hand-off crosses docker, `su` and make's env import, ci/sdk-build.sh and
ci/sdk-build-apk.sh now ASSERT that the produced .ipk/.apk really carries
that version — the B4 failure mode was a stale version shipping silently,
and that can no longer happen quietly.
The binary agrees with the package: scripts/build-shaterd.sh takes
constant.Version from the same ci/version.sh (vX.Y.Z-rR[-g<sha>]) instead
of its own `git describe`, and the workflow computes it once per job.
Both build jobs now check out with fetch-depth: 0 — `git describe` needs
tags and ancestry, which the default shallow checkout has neither of.
byedpi is deliberately left alone: PKG_VERSION:=0.17.3 is upstream
ByeDPI's own version, what PKG_HASH pins and what tells an operator which
ByeDPI is installed. Stamping our tag on it would also be a downgrade —
every comparator reads 0.2.7 < 0.17.3 (component-wise, 2 < 17), verified.
Docs: INSTALL.md gains §2.1 (the scheme + the ordering evidence), and the
update sections of §5/§6 now explicitly warn against a bare `opkg upgrade`
/ `apk upgrade` and give the targeted form instead, quoting apk-tools 3:
"If list of packages is provided, only those packages are upgraded along
with needed dependencies". README.md and the release bodies match.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
98 lines
4.2 KiB
Makefile
98 lines
4.2 KiB
Makefile
#
|
|
# shater-core — data-plane glue for the Shater transparent-proxy stack (v0.2).
|
|
#
|
|
# Ships the "железно" (rock-solid) static layer that the single Go binary
|
|
# `shaterd` sits under: the procd init that supervises `shaterd run` (which
|
|
# embeds the sing-box engine + control-plane + DNS in-process), the auto-update
|
|
# cron loop, the hotplug hook that re-persists policy routing, the sysctl knobs
|
|
# TPROXY needs, one-time rt_tables seeding, and a minimal inert UCI default.
|
|
#
|
|
# Pure scripts + config => PKGARCH:=all. Nothing is compiled here.
|
|
#
|
|
|
|
include $(TOPDIR)/rules.mk
|
|
|
|
PKG_NAME:=shater-core
|
|
|
|
# Version comes from the git tag via ci/version.sh -> SHATER_PKG_VERSION /
|
|
# SHATER_PKG_RELEASE in the SDK build env (see openwrt/shaterd/Makefile for the
|
|
# full rationale — bug B4: v0.2.2…v0.2.6 all shipped as 0.2.0-r3). The literals
|
|
# are the manual/offline fallback only.
|
|
PKG_VERSION:=$(if $(SHATER_PKG_VERSION),$(SHATER_PKG_VERSION),0.2.0)
|
|
PKG_RELEASE:=$(if $(SHATER_PKG_RELEASE),$(SHATER_PKG_RELEASE),1)
|
|
|
|
PKG_MAINTAINER:=Shater <maqrota@icloud.com>
|
|
PKG_LICENSE:=GPL-2.0-or-later
|
|
|
|
include $(INCLUDE_DIR)/package.mk
|
|
|
|
define Package/shater-core
|
|
SECTION:=net
|
|
CATEGORY:=Network
|
|
TITLE:=Shater transparent-proxy data-plane glue
|
|
URL:=https://github.com/shater
|
|
# v0.2 collapses the old xrayctl + xray-core + dnsmasq-full trio into ONE Go
|
|
# binary, shaterd, which embeds the sing-box engine, the control-plane AND an
|
|
# in-process DNS server. So we no longer depend on:
|
|
# - xrayctl / xray-core -> replaced by shaterd
|
|
# - dnsmasq-full -> the engine owns the :53 hijack listener now
|
|
# We still need the kernel TPROXY modules and ip-full for policy routing:
|
|
# shaterd : the daemon our init supervises (`shaterd run`)
|
|
# kmod-nft-tproxy : kernel TPROXY (shaterd emits the `inet shater` rules)
|
|
# kmod-nft-socket : socket match used by the tproxy divert chain
|
|
# ip-full : `ip rule`/`ip route`/rt_tables for policy routing
|
|
# nftables-json : shaterd shells out to `nft`, and netplane/stats.go
|
|
# parses `nft -j list ...` — the JSON output only exists
|
|
# in the json variant (the -nft variant has no libjansson).
|
|
# fw4 already pulls it on stock images; declare it so a
|
|
# slimmed image cannot silently break counters/sets.
|
|
# ca-bundle : the daemon is CGO_ENABLED=0, so crypto/x509 has no
|
|
# host cert fallback — without /etc/ssl/certs every
|
|
# HTTPS subscription / .srs ruleset fetch fails.
|
|
DEPENDS:=+shaterd +kmod-nft-tproxy +kmod-nft-socket +ip-full +nftables-json +ca-bundle
|
|
PKGARCH:=all
|
|
endef
|
|
|
|
define Package/shater-core/description
|
|
Static data-plane glue for the Shater sing-box-based transparent proxy: procd
|
|
init (supervises `shaterd run`, which owns the engine + nft table `inet shater`
|
|
+ policy routing + in-process DNS), an auto-update cron loop with a dead-engine
|
|
watchdog, an ifup/ifdown hotplug hook that re-persists ip rules & routes,
|
|
TPROXY sysctl settings, a minimal inert UCI default (globals disabled until
|
|
configured), and idempotent first-boot setup. Designed to never break
|
|
connectivity: fully inert until explicitly enabled.
|
|
endef
|
|
|
|
# /etc/config/shater is user-editable desired state -> preserve on upgrade.
|
|
define Package/shater-core/conffiles
|
|
/etc/config/shater
|
|
endef
|
|
|
|
# Nothing to fetch or build.
|
|
define Build/Prepare
|
|
mkdir -p $(PKG_BUILD_DIR)
|
|
endef
|
|
|
|
define Build/Compile
|
|
endef
|
|
|
|
define Package/shater-core/install
|
|
$(INSTALL_DIR) $(1)/etc/init.d
|
|
$(INSTALL_BIN) ./files/etc/init.d/shater $(1)/etc/init.d/shater
|
|
$(INSTALL_BIN) ./files/etc/init.d/shater-cron $(1)/etc/init.d/shater-cron
|
|
|
|
$(INSTALL_DIR) $(1)/etc/hotplug.d/iface
|
|
$(INSTALL_BIN) ./files/etc/hotplug.d/iface/99-shater $(1)/etc/hotplug.d/iface/99-shater
|
|
|
|
$(INSTALL_DIR) $(1)/etc/sysctl.d
|
|
$(INSTALL_DATA) ./files/etc/sysctl.d/99-shater.conf $(1)/etc/sysctl.d/99-shater.conf
|
|
|
|
$(INSTALL_DIR) $(1)/etc/config
|
|
$(INSTALL_CONF) ./files/etc/config/shater $(1)/etc/config/shater
|
|
|
|
$(INSTALL_DIR) $(1)/etc/uci-defaults
|
|
$(INSTALL_BIN) ./files/etc/uci-defaults/30_shater-core $(1)/etc/uci-defaults/30_shater-core
|
|
endef
|
|
|
|
$(eval $(call BuildPackage,shater-core))
|