Files
shater/docs-shater
omarandClaude Opus 5 a0de597d69
test / go + panel tests (push) Successful in 4m56s
feat(dns): intercept by default, and bootstrap node addresses off the tunnel
The posture was inverted. A client using the DHCP-supplied resolver — the router
itself — was NOT intercepted: dnsmasq answered and forwarded to the ISP in the
clear, so the filter, the blocklists, the per-device rules and BlockDoH were all
inert for exactly the clients that did nothing wrong. A client that hardcoded
8.8.8.8 to route around us WAS intercepted, by the catch-all. Meanwhile the
docs promised no DNS leaks. The default now matches the promise.

Turning it on crosses a threshold that was already dangerous for anyone with two
resolvers. Above one transport, a node's domain server address stops being
resolved by the transport directly and goes through the client DNS plane
instead — so a blocklist entry, a block_doh NXDOMAIN or any dns_rule can answer
your own node's hostname, and one sloppy line in an ad list stops being an ad
that got through and becomes a tunnel that never comes up.

So the fix is gated on having two or more transports, not on the intercept
toggle: resolver_default plus resolver_fallback always reached that threshold,
long before this change. When no endpoint_resolver is configured the plane now
carries a bootstrap server — the default resolver cloned with its detour
dropped, keeping its type, so a DoH default stays DoH and only the tunnel hop
goes. An explicit endpoint_resolver still wins.

This is not a restore of the previous behaviour and the comment says so: at one
transport the dialer used the default resolver WITH its detour, so a lone
DoH-through-the-tunnel resolver was already a bootstrap loop. It is strictly
better than what came before.

Existing installs keep whatever they set — the config file is a conffile and is
never replaced — and an explicit dns_intercept '0' survives the render-parse
round trip, which a default-true bool otherwise makes easy to lose.

The no-resolver warning stays, and no default resolver is shipped to silence it:
a placeholder would remove the sentence without moving a single query, and the
panel would then say a resolver was configured while nothing was filtered. Its
wording is corrected instead — .lan keeps working through the built-in local
transport, which the old text denied.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-26 04:54:15 +03:00
..

Документация shater

Документация продукта shater (управляемый интернет-шлюз для роутеров на OpenWrt). Лицо репозитория и быстрый старт — в корневом ../README.md.

Документ О чём
CONTEXT.md Начните здесь — контекст проекта, история v0.1→v0.2, решения в кратце, testbed/инфра
INSTALL.md Сборка ship-артефакта (shaterd) и установка apk-фида (25.12+): роллинг или фиксация версии
ARCHITECTURE.md One-binary дизайн, auth-handoff LuCI→панель, data/DNS/apply-потоки (диаграммы)
FEATURES.md Полный список фич с тегами MVP/T1/T2
ROADMAP.md Фазовый план
DECISIONS.md Почему sing-box, почему форк, split панели, лицензия и т.д.
DESIGN.md Визуальная система панели — направление «Faceplate», токены, компоненты
PORTING.md Порт проверенных кусков из v0.1

Документация движка-форка (sing-box-lx) — в его слое: ../docs-lx/ и ../SPECS/.