Both routers are past opkg: mini_router runs ImmortalWrt 25.12.1 and main_router OpenWrt 25.12.0, both with apk-tools 3.0.5, and main_router has no `opkg` binary at all. The 24.10 lane was building and signing a feed no device could consume. Removed jobs `build` and `release` with the scripts only they called (ci/build-feed.sh, ci/sdk-build.sh, ci/make-index.sh, ci/install-usign.sh) and the usign trust anchor dist/shater-feed.pub. A committed public key is an instruction: it invites the old install path for a feed that is no longer produced. The key is retired, not revoked -- git history keeps it, KEY_BUILD still holds the secret half, and a usign secret contains its own public half, so the identity is reconstructible if a 24.10 device ever needs serving. D7 is marked SUPERSEDED by the new D22 rather than deleted. Separately: the rolling `apk-latest-<arch>` release was frozen at 0.2.0 from 2026-07-24 while every tag run published its versioned release correctly. The publish loop was an either/or -- `TAG=apk-latest-<arch>` when VER=latest (workflow_dispatch only), ELSE `TAG=apk-<ver>-<arch>` -- so a `v*` tag run never touched the rolling pointer. Asset replacement was never the problem; ci/gitea-release.sh already deletes before recreating. A router pinned to the rolling URL sat on 0.2.0 while `apk update` reported success: silent staleness, the failure mode this repo keeps having to close. The rolling pointer is now published on EVERY run, tag runs included, and a new assert reads the release back over the API afterwards: our three tag-versioned packages at the built version plus the index and the key must be present (exit 13), and no package asset at any other version may survive (exit 14). Same class of check as sdk-build-apk.sh's package-version assert, added for the same reason -- the previous failure mode was silent. KEY_BUILD can now be deleted from the Gitea repo secrets; nothing references it. Docs state plainly that mini_router is deliberately pinned to a versioned URL and that the hand-edit per release is the price of pinning. Known consequence: the x86_64 QEMU testbed is still OpenWrt 24.10.3 and can no longer install our packages. Its 25.12 rebuild is in flight separately. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01H4PcWfrBRyg4eWN58axaGN
100 lines
4.2 KiB
Makefile
100 lines
4.2 KiB
Makefile
#
|
|
# byedpi — ByeDPI (ciadpi), a tiny portable-C SOCKS5/HTTP desync proxy.
|
|
#
|
|
# This is the process behind a Shater egress of `type='byedpi'`: shaterd's
|
|
# `generate` emits a SOCKS5 outbound `egress-<name>` -> 127.0.0.1:<port>, and a
|
|
# `ciadpi` instance supervised by this package listens on that port, applies
|
|
# TCP/TLS desync to the connections passing through it, and goes DIRECT to the
|
|
# target (no tunnel). Kept as a SEPARATE, optional package: a byedpi egress is
|
|
# opt-in — install this only when you want the external desync engine.
|
|
#
|
|
# Compiled C (musl, per target) => NOT PKGARCH:=all. The OpenWrt SDK toolchain
|
|
# cross-compiles ciadpi via its own plain Makefile.
|
|
#
|
|
|
|
include $(TOPDIR)/rules.mk
|
|
|
|
PKG_NAME:=byedpi
|
|
|
|
# DELIBERATELY NOT auto-versioned from our git tag (unlike shaterd/shater-core/
|
|
# luci-app-shater, which take SHATER_PKG_VERSION/SHATER_PKG_RELEASE from
|
|
# ci/version.sh). PKG_VERSION here is THIRD-PARTY UPSTREAM's version — it is what
|
|
# PKG_SOURCE_URL/PKG_HASH pin, and what tells an operator which ByeDPI is
|
|
# actually installed. Stamping our tag on it would be both a lie and a
|
|
# regression: our tags are 0.2.x, and the version comparator (apk-tools 3,
|
|
# verified) reads 0.2.7 < 0.17.3 — component-wise numerically, 2 < 17
|
|
# — so the "new" package would be a DOWNGRADE and routers would refuse it.
|
|
# Bump PKG_RELEASE BY HAND when *our packaging* of it changes (init script, uci
|
|
# defaults, build flags); bump PKG_VERSION+PKG_HASH when upstream releases.
|
|
PKG_VERSION:=0.17.3
|
|
PKG_RELEASE:=1
|
|
|
|
# Pinned upstream release tag v0.17.3 (commit
|
|
# 7efde1b1296eaaa187b70e951894dde17527489c). codeload emits a stable tarball
|
|
# per tag; PKG_HASH is the sha256 of that tarball (build fails on mismatch).
|
|
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
|
|
PKG_SOURCE_URL:=https://codeload.github.com/hufrea/byedpi/tar.gz/refs/tags/v$(PKG_VERSION)?
|
|
PKG_HASH:=0a9cb8585554c68c3e2be88c33c9bf6f99f8e8c7f54b362285adab99e262566c
|
|
|
|
PKG_MAINTAINER:=Shater <maqrota@icloud.com>
|
|
PKG_LICENSE:=MIT
|
|
PKG_LICENSE_FILES:=LICENSE
|
|
|
|
include $(INCLUDE_DIR)/package.mk
|
|
|
|
define Package/byedpi
|
|
SECTION:=net
|
|
CATEGORY:=Network
|
|
TITLE:=ByeDPI (ciadpi) local SOCKS5/HTTP desync proxy
|
|
URL:=https://github.com/hufrea/byedpi
|
|
# Pure C against musl; every target has a C toolchain, so no arch-depends.
|
|
# No runtime library deps beyond libc (static-ish tiny binary).
|
|
DEPENDS:=
|
|
endef
|
|
|
|
define Package/byedpi/description
|
|
ByeDPI is a small local SOCKS5/HTTP proxy that applies TCP/TLS desynchronization
|
|
(split, disorder, fake packets, TLS-record splitting) to the connections passing
|
|
through it and then connects DIRECTLY to the destination — no upstream tunnel.
|
|
Its binary is `ciadpi`. In the Shater stack it is the process behind an egress of
|
|
`type='byedpi'`: shaterd routes selected traffic to a local SOCKS5 outbound
|
|
pointed at ciadpi's 127.0.0.1:<port>. Multi-instance, driven by /etc/config/byedpi.
|
|
endef
|
|
|
|
# ciadpi's upstream Makefile appends its own required flags with `CFLAGS +=`.
|
|
# A CFLAGS set on the make command line CLOBBERS that `+=` (GNU make: a
|
|
# command-line assignment overrides the makefile's append), so we must re-supply
|
|
# ciadpi's own needed flags (-I. -std=c99 and its warning set) alongside
|
|
# $(TARGET_CFLAGS). CPPFLAGS (-D_DEFAULT_SOURCE) is left untouched by not
|
|
# overriding it. The default target `all` builds the `ciadpi` binary; its link
|
|
# rule is `$(CC) -o ciadpi $(OBJ) $(LDFLAGS)`, so $(TARGET_LDFLAGS) reaches the
|
|
# link. Kernel headers (linux/netfilter_ipv4.h) come from the SDK sysroot.
|
|
define Build/Compile
|
|
+$(MAKE) -C $(PKG_BUILD_DIR) \
|
|
CC="$(TARGET_CC)" \
|
|
CFLAGS="$(TARGET_CFLAGS) -I. -std=c99 -Wall -Wno-unused -Wextra -Wno-unused-parameter" \
|
|
LDFLAGS="$(TARGET_LDFLAGS)" \
|
|
all
|
|
endef
|
|
|
|
define Package/byedpi/install
|
|
$(INSTALL_DIR) $(1)/usr/bin
|
|
$(INSTALL_BIN) $(PKG_BUILD_DIR)/ciadpi $(1)/usr/bin/ciadpi
|
|
|
|
$(INSTALL_DIR) $(1)/etc/init.d
|
|
$(INSTALL_BIN) ./files/etc/init.d/byedpi $(1)/etc/init.d/byedpi
|
|
|
|
$(INSTALL_DIR) $(1)/etc/config
|
|
$(INSTALL_CONF) ./files/etc/config/byedpi $(1)/etc/config/byedpi
|
|
|
|
$(INSTALL_DIR) $(1)/etc/uci-defaults
|
|
$(INSTALL_BIN) ./files/etc/uci-defaults/40_byedpi $(1)/etc/uci-defaults/40_byedpi
|
|
endef
|
|
|
|
# /etc/config/byedpi is user-editable desired state -> preserve on upgrade.
|
|
define Package/byedpi/conffiles
|
|
/etc/config/byedpi
|
|
endef
|
|
|
|
$(eval $(call BuildPackage,byedpi))
|