mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 03:55:45 +00:00
test(e2e): transparent whitelist bypass + sniffing (gost#899)
Reproduce the regression where a domain-only whitelist bypass on a red (transparent) proxy rejected every connection: the pre-sniffing bypass check ran against the bare destination IP, which is never in a domain whitelist, before SNI sniffing could match. A privileged container redirects outbound TCP to the red service; asserts an allowlisted SNI is forwarded (hello-gost) and a non-allowlisted SNI is rejected.
This commit is contained in:
+27
@@ -0,0 +1,27 @@
|
||||
# gost#899: whitelist bypass + sniffing on a transparent (red) proxy.
|
||||
# The whitelist contains only a domain ("https-echo", the docker network alias
|
||||
# of the HTTPS echo container). A bare destination IP is never in it, so on a
|
||||
# broken build the pre-sniffing IP bypass check rejects every connection
|
||||
# before SNI sniffing can match the host. The fix skips that check in
|
||||
# whitelist mode and lets the sniffer drive the decision from the SNI.
|
||||
log:
|
||||
level: debug
|
||||
services:
|
||||
- name: transparent-egress
|
||||
addr: ":12345"
|
||||
bypass: allowlist
|
||||
metadata:
|
||||
so_mark: 114514
|
||||
handler:
|
||||
type: red
|
||||
metadata:
|
||||
sniffing: true
|
||||
sniffing.timeout: 5s
|
||||
sniffing.fallback: true
|
||||
listener:
|
||||
type: red
|
||||
bypasses:
|
||||
- name: allowlist
|
||||
whitelist: true
|
||||
matchers:
|
||||
- https-echo
|
||||
Reference in New Issue
Block a user