omarandClaude Opus 4.8 cb983afee1 perf(ci): stall-proof SDK fetch + caching (SDK/dl/go/npm/apt/usign) + concurrency
Builds were dominated by re-fetching the ImmortalWrt 25.12 SDK tarball
(~300 MB) every run, and a stalled downloads.immortalwrt.org transfer wedged
the apk job for 40+ min (plain `wget -q`, no timeout — same class as the
elfutils hang).

- New ci/fetch-sdk.sh (runner-side): cache -> our durable `sdk-cache` release
  mirror -> upstream with a stall-kill (curl --speed-limit 64K --speed-time 60
  --max-time 1800) + 3 retries + zstd-magic/size validation; seeds the mirror
  best-effort (github.token, non-fatal) so cold runs never touch upstream again.
  A 40-min hang is now impossible; the in-container fallback wget also gets
  --timeout=60 --tries=3.
- actions/cache@v3.3.2 (last release on the OLD cache API that Gitea act_runner
  implements; v4/v3.4.x use the new GitHub cache service) for: SDK tarball, SDK
  dl/ sources (hash of package Makefiles; PKG_HASH re-verified so a stale cache
  can't leak a wrong source), Go mod+build (go.sum), npm node_modules
  (package-lock.json) with build-shaterd.sh --fast, apt archives, built usign.
  Degrades safely if the cache server is off — the SDK mirror is independent.
- concurrency group release-${github.ref} cancel-in-progress so a re-dispatch
  cancels the stale run instead of piling up (tags stay isolated).

Signing (usign/apk), both keys, per-arch publish, manual triggers, LOCALMIRROR
and the scoped 4-package collection are unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-23 21:24:49 +03:00
2026-06-25 16:36:07 +08:00
2026-06-25 17:38:53 +08:00
2026-06-25 17:39:02 +08:00
2026-06-28 11:10:29 +08:00
2026-02-27 14:58:06 +08:00
2026-06-25 17:38:01 +08:00
2025-04-29 20:45:19 +08:00
2023-12-29 18:00:40 +08:00
2023-12-29 18:00:40 +08:00
2026-02-26 14:13:32 +08:00
2026-06-25 19:47:32 +08:00
2026-07-08 00:34:26 +08:00

shater

A self-hosted internet-control appliance for OpenWrt. One box turns your network into a transparent VPN gateway, a network-wide ad/tracker/malware blocker, per-device parental control, and a live traffic dashboard — configured from a rich web admin panel, all local.

License: GPL-3.0 status: v0.2 in development targets: x86_64 · aarch64_cortex-a53

⚠️ v0.2 is under active development on a new foundation. The previous, complete and VM-verified xray-based version lives on the v0.1 branch and still installs from the signed feed.

What v0.2 is

shater v0.2 is built as a fork of sing-box (via sing-box-lx) with our whole product embedded in the one binary: the proxy engine, a control plane, a DNS filter, and a full admin panel. Riding sing-box gives a broad, up-to-date protocol set — VLESS/VMess/Trojan/Shadowsocks, Reality, AmneziaWG 2.0, Hysteria2, TUIC — without reinventing the anti-DPI arms race.

The UI is split for both integration and a great experience: a thin LuCI app (a small dashboard + an "Open panel" button) hands a short-lived token to a standalone admin panel the daemon serves on its own port — so panel auth is bootstrapped from LuCI's existing login, and the real UX is a modern SPA we fully own.

Highlights (planned)

  • Transparent TPROXY proxy (TCP+UDP), split by domain/geo/client, no DNS leaks.
  • Broad protocols incl. AmneziaWG 2.0, Reality, Hysteria2, TUIC.
  • Network-wide DNS blocklists with flexible sources (inline / file / url / geosite) and an efficient matcher for million-entry lists.
  • Per-domain, per-client, per-device statistics — fed by the engine's DNS events in-process (no log scraping).
  • Per-device control: block a site for one device or everyone; per-device exit/proxy toggles; schedules; alerts.
  • Fail-closed kill-switch, atomic apply with commit-confirm rollback, signed opkg feed.

See docs-shater/FEATURES.md for the full list.

Documentation

Doc What
docs-shater/CONTEXT.md Start here — project context, v0.1→v0.2 history, decisions in brief, testbed/infra
docs-shater/ROADMAP.md Phased plan (Phase 1 = fork + embedding prototype)
docs-shater/FEATURES.md Full feature list with MVP/T1/T2 tags
docs-shater/ARCHITECTURE.md One-binary design, auth handoff, data/DNS/apply flow (diagrams)
docs-shater/DECISIONS.md Why sing-box, why fork, why the panel split, license, etc.
docs-shater/DESIGN.md Admin-panel visual system — the "Faceplate" direction, tokens, components, north-star prototype

Status

Foundation reset complete: v0.1 preserved on its branch, main reset for v0.2. Next is Phase 1 — fork sing-box-lx into main and stand up the embedding prototype (prove AmneziaWG 2.0, measure binary size). Follow docs-shater/ROADMAP.md.

Hardware

aarch64_cortex-a53 covers Banana Pi BPI-R3 (MT7986/Filogic 830) and BPI-R4 (MT7988/Filogic 880), both the OpenWrt mediatek/filogic target. x86_64 is the QEMU test VM.

License

GPL-3.0 (sing-box is GPL-3.0). See docs-shater/DECISIONS.md D6.

S
Description
OpenWrt XRAY management plugin � passwall-class, but cleaner. Design + code.
Readme
56 MiB
2026-07-28 07:50:40 -04:00
Languages
Go 77.7%
TypeScript 12.4%
PureBasic 4.2%
Shell 2.5%
CSS 2.1%
Other 1%