Builds were dominated by re-fetching the ImmortalWrt 25.12 SDK tarball
(~300 MB) every run, and a stalled downloads.immortalwrt.org transfer wedged
the apk job for 40+ min (plain `wget -q`, no timeout — same class as the
elfutils hang).
- New ci/fetch-sdk.sh (runner-side): cache -> our durable `sdk-cache` release
mirror -> upstream with a stall-kill (curl --speed-limit 64K --speed-time 60
--max-time 1800) + 3 retries + zstd-magic/size validation; seeds the mirror
best-effort (github.token, non-fatal) so cold runs never touch upstream again.
A 40-min hang is now impossible; the in-container fallback wget also gets
--timeout=60 --tries=3.
- actions/cache@v3.3.2 (last release on the OLD cache API that Gitea act_runner
implements; v4/v3.4.x use the new GitHub cache service) for: SDK tarball, SDK
dl/ sources (hash of package Makefiles; PKG_HASH re-verified so a stale cache
can't leak a wrong source), Go mod+build (go.sum), npm node_modules
(package-lock.json) with build-shaterd.sh --fast, apt archives, built usign.
Degrades safely if the cache server is off — the SDK mirror is independent.
- concurrency group release-${github.ref} cancel-in-progress so a re-dispatch
cancels the stale run instead of piling up (tags stay isolated).
Signing (usign/apk), both keys, per-arch publish, manual triggers, LOCALMIRROR
and the scoped 4-package collection are unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
shater
A self-hosted internet-control appliance for OpenWrt. One box turns your network into a transparent VPN gateway, a network-wide ad/tracker/malware blocker, per-device parental control, and a live traffic dashboard — configured from a rich web admin panel, all local.
⚠️ v0.2 is under active development on a new foundation. The previous, complete and VM-verified xray-based version lives on the
v0.1branch and still installs from the signed feed.
What v0.2 is
shater v0.2 is built as a fork of sing-box (via sing-box-lx) with our whole product embedded in the one binary: the proxy engine, a control plane, a DNS filter, and a full admin panel. Riding sing-box gives a broad, up-to-date protocol set — VLESS/VMess/Trojan/Shadowsocks, Reality, AmneziaWG 2.0, Hysteria2, TUIC — without reinventing the anti-DPI arms race.
The UI is split for both integration and a great experience: a thin LuCI app (a small dashboard + an "Open panel" button) hands a short-lived token to a standalone admin panel the daemon serves on its own port — so panel auth is bootstrapped from LuCI's existing login, and the real UX is a modern SPA we fully own.
Highlights (planned)
- Transparent TPROXY proxy (TCP+UDP), split by domain/geo/client, no DNS leaks.
- Broad protocols incl. AmneziaWG 2.0, Reality, Hysteria2, TUIC.
- Network-wide DNS blocklists with flexible sources (inline / file / url / geosite) and an efficient matcher for million-entry lists.
- Per-domain, per-client, per-device statistics — fed by the engine's DNS events in-process (no log scraping).
- Per-device control: block a site for one device or everyone; per-device exit/proxy toggles; schedules; alerts.
- Fail-closed kill-switch, atomic apply with commit-confirm rollback, signed opkg feed.
See docs-shater/FEATURES.md for the full list.
Documentation
| Doc | What |
|---|---|
docs-shater/CONTEXT.md |
Start here — project context, v0.1→v0.2 history, decisions in brief, testbed/infra |
docs-shater/ROADMAP.md |
Phased plan (Phase 1 = fork + embedding prototype) |
docs-shater/FEATURES.md |
Full feature list with MVP/T1/T2 tags |
docs-shater/ARCHITECTURE.md |
One-binary design, auth handoff, data/DNS/apply flow (diagrams) |
docs-shater/DECISIONS.md |
Why sing-box, why fork, why the panel split, license, etc. |
docs-shater/DESIGN.md |
Admin-panel visual system — the "Faceplate" direction, tokens, components, north-star prototype |
Status
Foundation reset complete: v0.1 preserved on its branch, main reset for v0.2.
Next is Phase 1 — fork sing-box-lx into main and stand up the embedding
prototype (prove AmneziaWG 2.0, measure binary size). Follow docs-shater/ROADMAP.md.
Hardware
aarch64_cortex-a53 covers Banana Pi BPI-R3 (MT7986/Filogic 830) and BPI-R4
(MT7988/Filogic 880), both the OpenWrt mediatek/filogic target. x86_64 is the
QEMU test VM.
License
GPL-3.0 (sing-box is GPL-3.0). See docs-shater/DECISIONS.md D6.