CONNECT-IP (RFC 9484) outbound tunnelling whole IP packets over HTTP/3 and HTTP/2, targeting Cloudflare WARP. One `type: masque` outbound with a `profile` field (cloudflare default | standard) and `network` (h3 | h2). - transport/masque/connectip: vendored connect-ip-go (client subset) ported onto sagernet/quic-go — no second quic-go, no external dependency. - transport/masque: cloudflare/standard profiles (ECDSA pubkey pinning), h3 ConnectTunnel (Extended CONNECT cf-connect-ip + advertiseDefaultRoute), and h2 capsule-DATAGRAM over stdlib net/http (no http fork needed). - protocol/masque: adapter.Outbound reusing transport/wireguard gVisor stackDevice via NewDevice(System:false); lazy tunnel + two IP pumps; DialContext/ListenPacket/Close. - constant/option/include wiring (with_quic + with_gvisor); graceful ErrGVisorNotIncluded without gvisor. Key material (ECDSA priv/pub, ip/ipv6) is taken ready from config — WARP device registration is done client-side (Dart), out of core scope. Unit-tested (profiles, TLS pinning, EC key round-trip, capsule round-trip, IPv4 checksum vector, prefix parsing, config decode via registry). NOT yet device-verified against live WARP (needs real key material). Refs: SPEC 021, SagerNet/sing-box#4000
40 lines
1.2 KiB
Go
40 lines
1.2 KiB
Go
//go:build with_quic
|
|
|
|
package include
|
|
|
|
import (
|
|
"github.com/sagernet/sing-box/adapter/inbound"
|
|
"github.com/sagernet/sing-box/adapter/outbound"
|
|
"github.com/sagernet/sing-box/adapter/service"
|
|
"github.com/sagernet/sing-box/dns"
|
|
"github.com/sagernet/sing-box/dns/transport/quic"
|
|
"github.com/sagernet/sing-box/protocol/hysteria"
|
|
"github.com/sagernet/sing-box/protocol/hysteria2"
|
|
"github.com/sagernet/sing-box/protocol/masque"
|
|
_ "github.com/sagernet/sing-box/protocol/naive/quic"
|
|
"github.com/sagernet/sing-box/protocol/tuic"
|
|
_ "github.com/sagernet/sing-box/transport/v2rayquic"
|
|
)
|
|
|
|
func registerQUICInbounds(registry *inbound.Registry) {
|
|
hysteria.RegisterInbound(registry)
|
|
tuic.RegisterInbound(registry)
|
|
hysteria2.RegisterInbound(registry)
|
|
}
|
|
|
|
func registerQUICOutbounds(registry *outbound.Registry) {
|
|
hysteria.RegisterOutbound(registry)
|
|
tuic.RegisterOutbound(registry)
|
|
hysteria2.RegisterOutbound(registry)
|
|
masque.RegisterOutbound(registry)
|
|
}
|
|
|
|
func registerQUICTransports(registry *dns.TransportRegistry) {
|
|
quic.RegisterTransport(registry)
|
|
quic.RegisterHTTP3Transport(registry)
|
|
}
|
|
|
|
func registerQUICServices(registry *service.Registry) {
|
|
hysteria2.RegisterRealmService(registry)
|
|
}
|