Luna Yao
5f8548d272
make dns Option
2026-04-06 11:54:50 +02:00
Luna Yao
7cb4345e4d
fmt
2026-04-06 11:54:50 +02:00
Luna Yao
ea5e34b6af
Revert "remove hostname from config"
2026-04-06 11:54:50 +02:00
Luna Yao
385ff54b3e
fix magic-dns feature gate
2026-04-06 11:54:50 +02:00
Luna Yao
d5d600a524
remove hostname from config
2026-04-06 11:54:50 +02:00
Luna Yao
0ca5e38dba
log: span
...
log: format
2026-04-06 11:54:50 +02:00
Luna Yao
b0e4808d00
log: add test log init
...
log
2026-04-06 11:54:50 +02:00
Luna Yao
2a34032221
log: refactor
2026-04-06 11:54:50 +02:00
Luna Yao
15cc86c8bc
log: use test writer
2026-04-06 11:54:50 +02:00
Luna Yao
d9d211c5a4
remove old magic-dns
2026-04-06 11:54:47 +02:00
Luna Yao
86871b14d5
store DnsServer in GlobalCtx, load routes from DnsServer in ProxyCidrsMonitor
2026-04-06 11:54:02 +02:00
Luna Yao
f75c35d4a0
add GlobalCtxEvent::PeerInfoUpdated, issue this event in do_sync_route_info
...
fix use in peer_ospf_route.rs
2026-04-06 11:54:02 +02:00
Luna Yao
3f3aec8edd
add DnsConfig and ZoneConfig with proto definitions
2026-04-06 11:54:01 +02:00
KKRainbow
fb59f01058
fix: reconcile webhook-managed configs and make disable_p2p more intelligent ( #2057 )
...
* reconcile infra configs on webhook validate
* make disable_p2p more intelligent
* fix stats
2026-04-04 23:41:57 +08:00
Luna Yao
e91a0da70a
refactor: listener/connector protocol abstraction ( #2026 )
...
* fix listener protocol detection
* replace IpProtocol with IpNextHeaderProtocol
* use an enum to gather all listener schemes
* rename ListenerScheme to TunnelScheme; replace IpNextHeaderProtocols with socket2::Protocol
* move TunnelScheme to tunnel
* add IpScheme, simplify connector creation
* format; fix some typos; remove check_scheme_...;
* remove PROTO_PORT_OFFSET
* rename WSTunnel.. -> WsTunnel.., DNSTunnel.. -> DnsTunnel..
2026-04-04 10:55:58 +08:00
KKRainbow
8c19a2293c
fix(windows): avoid pnet interface enumeration panic ( #2031 )
2026-03-29 23:16:44 +08:00
KKRainbow
bcd75d6ce3
Add instance recv limiter in peer conn ( #2027 )
2026-03-29 10:28:02 +08:00
KKRainbow
e000636d83
feat(stats): add by-instance traffic metrics ( #2011 )
2026-03-26 13:46:33 +08:00
Luna Yao
8e4dc508bb
test: improve test_txt_public_stun_server with timeout and retry mechanism ( #2014 )
2026-03-26 09:32:07 +08:00
Luna Yao
e2684a93de
refactor: use strum on EncryptionAlgorithm, use Xor as default when AesGcm not available ( #1923 )
2026-03-25 18:42:34 +08:00
KKRainbow
1d89ddbb16
Add lazy P2P demand tracking and need_p2p override ( #2003 )
...
- add lazy_p2p so nodes only start background P2P for peers that actually have recent business traffic
- add need_p2p so specific peers can still request eager background P2P even when other nodes enable lazy mode
- cover the new behavior with focused connector/peer-manager tests plus three-node integration tests that verify relay-to-direct route transition
2026-03-23 09:38:57 +08:00
KKRainbow
2bfdd44759
multi_fix: harden peer/session handling, tighten foreign-network trust, and improve web client metadata ( #1999 )
...
* machine-id should be scoped unbder same user-id
* feat: report device os metadata to console
* fix sync root key cause packet loss
* fix tun packet not invalid
* fix faketcp cause lat jitter
* fix some packet not decrypt
* fix peer info patch, improve performance of update self info
* fix foreign credential identity mismatch handling
2026-03-21 21:06:07 +08:00
KKRainbow
8922e7b991
fix: foreign credential handling and trusted key visibility ( #1993 )
...
* fix foreign credential handling
* allow list foreign network trusted keys
* fix(gui): delete removed config-server networks
* fix(web): reset managed instances on first sync
2026-03-16 22:19:31 +08:00
KKRainbow
e6ac31fb20
feat(web): add webhook-managed machine access and multi-instance CLI support ( #1989 )
...
* feat: add webhook-managed access and multi-instance CLI support
* fix(foreign): verify credential of foreign credential peer
2026-03-15 12:08:50 +08:00
KKRainbow
694b8d349d
feat(credential): enforce signed credential distribution across mixed admin/shared topology ( #1972 )
2026-03-10 08:37:33 +08:00
KKRainbow
c4eacf4591
feat(credential): implement credential peer auth and trust propagation ( #1968 )
...
- add credential manager and RPC/CLI for generate/list/revoke
- support credential-based Noise authentication and revocation handling
- propagate trusted credential metadata through OSPF route sync
- classify direct peers by auth level in session maintenance
- normalize sender credential flag for legacy non-secure compatibility
- add unit/integration tests for credential join, relay and revocation
2026-03-07 22:58:15 +08:00
KKRainbow
59d4475743
feat: relay peer end-to-end encryption via Noise IK handshake ( #1960 )
...
Enable encryption for non-direct nodes requiring relay forwarding.
When secure_mode is enabled, peers perform Noise IK handshake to
establish an encrypted PeerSession. Relay packets are encrypted at
the sender and decrypted at the receiver. Intermediate forwarding
nodes cannot read plaintext data.
---------
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com >
Co-authored-by: KKRainbow <5665404+KKRainbow@users.noreply.github.com >
2026-03-07 14:47:22 +08:00
Luna Yao
5f31583a84
refactor: 使用 tracing 输出日志 ( #1856 )
...
* change all println to tracing
2026-03-04 09:52:23 +08:00
Chenx Dust
7a26640c26
feat: support macOS Network Extension ( #1902 )
...
* feat: support macOS Network Extension
* fix: disable macOS NE feature in cargo hack check
2026-02-14 14:54:36 +08:00
KKRainbow
c58140fb47
update rust to 1.93 ( #1865 )
2026-02-04 09:48:43 +08:00
Chenx Dust
e1cbd07d1f
feat: separate zstd and faketcp into features ( #1861 )
...
* feat: separate faketcp into a feature
* fix: no need to initialize out_len
* feat: separate zstd into a feature
* clippy: remove unnecessary cast, because for unix size_t always equals usize
2026-02-03 11:12:33 +08:00
Luna Yao
cd2cf56358
refactor: handle quic proxy internally instead of use external udp port ( #1743 )
...
* deprecate quic_listen_port, add disable_relay_quic and enable_relay_foreign_network_quic
* add set_src_modified to TcpProxyForWrappedSrcTrait
* prioritize quic over kcp
2026-02-02 11:53:40 +08:00
KKRainbow
9e3c9228bb
improve perf of remove_network in foreign net mgr ( #1847 )
2026-01-30 23:04:31 +08:00
KKRainbow
ffe5644ddc
add token bucket limiter on peer conn recv ( #1842 )
...
We should limit peer conn recv to make sure we don't recv too much from peers.
2026-01-29 16:12:26 +08:00
KKRainbow
101f416268
Introduce secure mode (part 1) ( #1808 )
...
Use noise protocol on handshake. Check peer's public key if needed. Also support rekey and replay attack prevention.
E2EE and temporary password will be implemented based on this.
2026-01-25 20:16:51 +08:00
KKRainbow
53264f67bf
fix peer establish direct conn with subnet proxy to one of local interface ( #1782 )
...
* fix peer establish direct conn with subnet proxy to one of local interface
* fix peer mgr ref loop
2026-01-15 01:00:32 +08:00
Chenx Dust
48c5c23f9b
feat: support compile for iOS ( #1777 )
2026-01-11 16:36:58 +08:00
狂男风
88a45d1156
use 80/443 as ws/wss default port ( #1700 )
2026-01-01 01:31:38 +08:00
KKRainbow
4e651a72f7
allow loopback src address in listener ( #1730 )
2026-01-01 00:41:56 +08:00
Mg Pig
18478b7c4b
fix(android): update vpn routes when proxy cidrs change ( #1717 )
2025-12-30 19:26:42 +08:00
KKRainbow
39b056c87a
bump version to v2.5.0 ( #1715 )
2025-12-28 23:19:30 +08:00
KKRainbow
c19cd1bff3
add tcp hole punching ( #1713 )
...
add tcp hole punching and tcp stun test
2025-12-28 21:35:30 +08:00
Tunglies
fe4dff5df0
perf: simplify method signatures and reduce clone across multiple files ( #1663 )
2025-12-09 16:47:57 +08:00
KKRainbow
2bc51daa98
fix whitelist cause packets of other protocal dropped ( #1660 )
2025-12-08 21:56:27 +08:00
Mg Pig
53f279f5ff
feat(core): Support environment variable parsing in config files ( #1640 )
2025-12-02 17:54:31 +08:00
Sijie.Sun
b44053f496
support p2p-only mode ( #1598 )
2025-11-20 08:20:27 +08:00
Mg Pig
1273426009
feat: Enable core to use local config files while being managed via the web ( #1540 )
2025-11-08 20:32:00 +08:00
Tunglies
55b93454dc
fix: clippy errors with stable toolchain and default features ( #1553 )
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-11-07 20:08:39 +08:00
Mg Pig
6bb2fd9a15
feat(core): Refactor IDN and URL handling logic ( #1533 )
...
* feat(core): Refactor IDN and URL handling logic
* feat(tests): add dual_convert option for URL serialization in IDN tests
2025-11-03 22:15:40 +08:00
Sijie.Sun
71679e889a
allow sync conn with conn list when conn bitmap is too large ( #1508 )
2025-10-23 08:11:36 +08:00