Commit Graph
565 Commits
Author SHA1 Message Date
ginuerzh 11220b15bb chore(gost): bump github.com/go-gost/x to v0.19.5 v3.3.1-nightly.20261003 2026-10-03 23:38:53 +08:00
ginuerzh d7656ef3de tests/e2e: concurrent UDP endpoints must share a reverse tunnel intact
Covers gost#911 at the wire level: four UDP source sockets send through one
RUDP reverse tunnel bound on a relay server, and every datagram must come
back byte-identical to its own endpoint.

A frame torn by an interleaved writer shows up twice — as a corrupted
payload, and as the torn frame leaving half a header in the stream, which the
far end reads as "unexpected EOF" and answers by rebuilding the whole tunnel.
So the suite asserts both: no endpoint sees a corrupted datagram, and no
endpoint sees a receive gap long enough to be a teardown and rebind.

Verified against a binary built before the fix (4 endpoints, 35% loss, 1.4s
gaps, suite fails) and after it (0% loss, no corruption, 0.2s gaps, passes).
2026-10-03 16:27:05 +08:00
iBug e9fab95872 Add back SystemCallFilter=@chown (#907)
Otherwise lumberjack will fail to rotate log files

Ref: https://github.com/natefinch/lumberjack/pull/43/changes#diff-7a80b3353ee34c4b79751e1e47e5010af54e82f393aa112770a4d1a731e70ba2R480
v3.3.1-nightly.20260922
2026-09-22 22:06:55 +08:00
ginuerzh 97bb57230c docs: document DEB/RPM installation
Covers the amd64v3 vs amd64 choice — both packages declare Architecture:
amd64, so the file name is the only way to tell them apart — and the fact
that the packaged systemd service stays inactive until /etc/gost/gost.yml
is created.
2026-09-21 21:23:33 +08:00
ginuerzh bb45b12809 fix(release): use DynamicUser for gost.service
systemd-analyze verify warns "Special user nobody configured, this is not
safe!": nobody is a shared account, so any other service running as it can
read and write /run/gost. DynamicUser= gives the unit its own transient
identity, named gost, without adding a static user to the package.

Verified under a real systemd: the unit starts, binds :80 through the
ambient capabilities, runs as the dynamic user, and is skipped rather than
failed when /etc/gost/gost.yml is absent.
2026-09-21 21:15:33 +08:00
ginuerzh c4e789e2df fix(release): pin capability bounding set in gost.service
CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN,
which leaves the bounding set unrestricted. Pin it to the capabilities the
unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF)
and netlink, neither of which is in that group.
2026-09-21 21:03:43 +08:00
iBug 2a6ba4df85 Add DEB and RPM packages for easier installation (#906)
* Add systemd service file

* Add DEB and RPM packages for amd64, amd64v3 and arm64 architectures

* Remove GOMEMLIMIT from systemd service

* Fix packaged systemd service defaults
2026-09-21 21:01:26 +08:00
ginuerzh ece7770ad7 chore(gost): bump github.com/go-gost/x to v0.17.2 2026-09-13 21:12:53 +08:00
ginuerzh eb66804ec8 chore(gost): bump github.com/go-gost/x to v0.17.1 2026-09-12 12:12:22 +08:00
ginuerzh a20999046b chore(gost): bump github.com/go-gost/x to v0.17.0 2026-09-12 10:16:16 +08:00
Igor Kuzmenkov fe0982b2e4 fix: update go-m1cpu for macOS arm64 (#903) 2026-09-12 10:06:30 +08:00
ginuerzh 36cc266257 chore: anchor gost gitignore rule to repo root
The bare 'gost' pattern also matched the cmd/gost/ directory, forcing
-f to stage tracked files under it.
v3.3.1-nightly.20260907
2026-09-07 17:46:21 +08:00
ginuerzh 074af1b175 program: shut down plugin subprocesses on stop 2026-09-07 17:42:44 +08:00
ginuerzh ee61f28688 test(e2e): add QUIC cipherKey invalid-datagram regression
Add an e2e suite covering go-gost/x#125: a malformed UDP datagram sent
to a cipherKey-enabled QUIC listener must not close the shared transport.
Uses the canonical http-over-quic chaining pattern and verifies the
forward still works after the invalid datagram.

Also bumps go.mod/go.sum (plugin v0.6.1, otel, x/net, etc.).
2026-09-07 14:53:36 +08:00
ginuerzh 27ac16439e bump to v3.3.1, x v0.16.1 2026-08-31 22:54:26 +08:00
ginuerzh d778c031eb test(e2e): transparent whitelist bypass + sniffing (gost#899)
Reproduce the regression where a domain-only whitelist bypass on a red
(transparent) proxy rejected every connection: the pre-sniffing bypass
check ran against the bare destination IP, which is never in a domain
whitelist, before SNI sniffing could match. A privileged container
redirects outbound TCP to the red service; asserts an allowlisted SNI
is forwarded (hello-gost) and a non-allowlisted SNI is rejected.
2026-08-31 22:35:03 +08:00
ginuerzh cb76f63754 e2e: add PROXY protocol test (gost#677), bump core/x deps
ProxyProtoSuite starts gost with metadata.proxyProtocol set and asserts
the HAProxy PROXY header is prepended on outbound connections (v1/v2),
backed by a raw-TCP capture script and configs. Add echo754_repro.py
from the hot-reload EADDRINUSE investigation (gost#754).

Bump github.com/go-gost/core to v0.6.1 and x to v0.16.0.
v3.3.0
2026-08-29 09:26:33 +08:00
ginuerzh 76467efc59 test(e2e): regression for Gost-Target destination-policy bypass
Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the
echo server; verifies the control request is 403, a checksum-valid
Gost-Target header naming an allowed authority cannot reach the blocked
backend, and a malformed header is fail-closed. Verified to catch the bug
by reverting the fix (exploit returned the backend response).
2026-08-27 20:16:34 +08:00
ginuerzh 35f7cd912c test(e2e): cover origin-form HTTP proxy request (#679)
Send a raw "GET / HTTP/1.1" + Host header through the http proxy,
mirroring nginx proxy_pass. Dumps container logs on failure.
2026-08-27 00:02:33 +08:00
ginuerzhandClaude 5e40415ac9 e2e: demux testcontainers exec stream, fix mtls proxy flags, add rtcp filter test
- Add ExecOutput helper to demultiplex the raw Docker exec stream so test
  output assertions see clean stdout+stderr instead of framed bytes.
- Wait for container readiness via exposed port or "listening on" log line
  when no ports are exposed.
- Use curl --proxy-* TLS options for the mTLS HTTPS-proxy test.
- Relax the http_cache first-request assertion (shared backend counter).
- Add gost#898 rtcp forwarder filter.host e2e test (multi-service one tunnel).
- Bump x to v0.15.7.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-26 22:27:52 +08:00
ginuerzh ecf14b8459 bump x to v0.15.6 2026-08-25 22:18:31 +08:00
ginuerzh 1f14e72e3c bump x to v0.15.5 2026-08-21 21:52:06 +08:00
ginuerzh aa1565c8b2 bump x to v0.15.4 2026-08-18 23:44:32 +08:00
ginuerzh f7b27a2c8b bump x to v0.15.3 2026-08-17 23:09:43 +08:00
ginuerzh c7d793c619 e2e: add cmd probe recovery test (gost#837)
Verifies dead->alive->dead node transition: a node excluded by a failing cmd
probe resumes carrying traffic once the probe flips healthy, without restart.
2026-08-01 23:23:28 +08:00
ginuerzh f25148f2e0 bump x to v0.15.2 (SSH authorized_keys trailing-newline fix, gost#699) 2026-08-01 23:22:22 +08:00
ginuerzh 960f081e53 e2e: add UDP forward QUIC sniffing test
Add TestUDPForwardQUICSniffing: sends a real captured QUIC v1 Initial packet
through the UDP forward handler (with sniffing enabled) and verifies the
datagram is echoed back. Covers the QUIC ClientHello/ServerHello sniff path
in x/handler/redirect/udp and x/handler/forward/local.
2026-07-30 23:24:35 +08:00
ginuerzh 55bb214a94 chore: bump x to v0.15.1, add e2e tests for chainGroup and sniffing
- Bump github.com/go-gost/x v0.15.0 → v0.15.1
- ChainGroupSuite: matcher routing by host, probe dead-chain pre-marking
- SniffingSuite: SOCKS5+HTTPS w/o SNI, debug-only log on empty SNI
- Add RunHTTPSEchoContainer and https_echo.py test helper
2026-07-29 23:06:15 +08:00
ginuerzh 555dacd244 chore: bump x to v0.15.0 (hopGroup, failCodes fix)
Add e2e regression test for http.failCodes selector bug —
FIFO selector + failCodes=429 on first node proves
node-429 is excluded after first 429 response and all
subsequent requests go to node-good.
2026-07-27 22:13:34 +08:00
ginuerzh f63b212434 chore: bump x to v0.14.2, tls-dissector to v0.3.1, quic-go to v0.60.0, webtransport-go to v0.11.1 2026-07-26 23:03:38 +08:00
ginuerzh 64017bf195 chore: bump x to v0.14.1 2026-07-26 20:17:23 +08:00
ginuerzh 5a1a799848 tests/e2e: add HTTP response cache e2e tests 2026-07-26 18:14:03 +08:00
ginuerzh 5204d6285e chore: bump deps (core v0.6.0, x v0.14.0) 2026-07-26 18:12:57 +08:00
ginuerzh 81108ee0a4 chore: bump deps (core v0.5.5, x v0.13.18) 2026-07-25 18:52:45 +08:00
ginuerzh 122dde8385 chore: go get -u all
- x v0.13.15 → v0.13.16
- tls-dissector v0.2.0 → v0.3.0
- golang.org/x/* bump (crypto, net, sys, text, mod, sync, term, tools)
- oTel v1.41.0 → v1.43.0
- grpc v1.79.3 → v1.82.1
- gonum v0.16.0 → v0.17.0
2026-07-24 23:15:01 +08:00
ginuerzh 9ccb007589 chore: bump deps
- x v0.13.14 → v0.13.15 (MetadataFeature, BodyJSON matcher)
- relay v0.6.2 → v0.7.0
- tls-dissector v0.2.0 → v0.3.0
- add tidwall gjson/match/pretty/sjson (indirect, via x)
2026-07-24 22:34:52 +08:00
ginuerzh 5a01aa4fd2 chore: bump x to v0.13.14 (forwarder probe passthrough fix) 2026-07-16 23:34:22 +08:00
ginuerzh 4cdc5588ff chore: bump core to v0.5.4 (node liveness probe types) 2026-07-16 21:34:33 +08:00
ginuerzh 89f9ea124a chore: bump x to v0.13.13 (Tor SOCKS5 resolve, cmd probe) 2026-07-16 21:24:41 +08:00
ginuerzh e9cf3b4d3f e2e: add cmd probe failover test with true/false command nodes 2026-07-16 20:53:30 +08:00
ginuerzh bef00dffef e2e: add node liveness probe tests
TCP probe + FailFilter: dead node pre-marked, all requests succeed.
LowestLatency strategy: two probed nodes, selector picks fastest.
2026-07-16 20:53:30 +08:00
ginuerzh 1c6fadcb1e test(e2e): add routing matcher module e2e test suite
Verify node-level routing matchers via a two-proxy relay: a forward
proxy whose only chain node carries matcher Host(`tcp-echo`) is only
eligible for a matching Host, so the request is relayed upstream to the
echo server; a non-matching Host is excluded (no eligible node) and never
reaches the echo server. Mirrors the resolver/ingress e2e pattern.
2026-07-16 20:53:30 +08:00
ginuerzh 20f1e4a0b9 test(e2e): add resolver module e2e test suite
Verifies that a configured resolver drives the proxy's outbound DNS
resolution. A gost HTTP proxy uses a resolver whose only nameserver is a
test responder answering echo.test with the real echo server IP and
NXDOMAIN for everything else. A request to echo.test is resolved by the
custom resolver and reaches the echo server; an unmapped host fails to
resolve. Adds a parametrized DNS responder script and container helper.
2026-07-16 20:53:30 +08:00
ginuerzh 1fd69ac704 test(e2e): add ingress module e2e test suite
Verifies hostname→endpoint routing at the reverse-proxy tunnel
entrypoint. A public gost runs a tunnel handler with an ingress
mapping example.local→tunnel-UUID and an HTTP entrypoint; an internal
client binds a reverse tunnel forwarding to the echo server. A request
with a mapped Host is routed through the tunnel to the echo server,
while an unmapped Host matches no ingress rule and is rejected.
2026-07-16 20:53:30 +08:00
ginuerzh 9355607ba7 test(e2e): add hosts module e2e test suite
Verify the static hosts mapping (HostMapper) overrides DNS: a mapped
hostname resolves to the configured IP and reaches the echo server,
while an unmapped hostname fails to resolve.
2026-07-16 20:53:30 +08:00
ginuerzh 6746f556b7 test(e2e): add auth module e2e test suite
Verify HTTP proxy authentication for both inline single-user auth and a
named auther with multiple users. Covers valid credentials, wrong
password, missing credentials, and any-user-in-auther acceptance.
2026-07-16 20:53:30 +08:00
ginuerzh 3119cb43f2 test(e2e): add admission module e2e test suite
Verify service-level admission control gating by client source IP, in
both whitelist and blacklist modes. Contrasts a loopback client (curl
inside the gost container) against an external client (curl inside the
echo container) to exercise both admit and deny paths.
2026-07-16 20:53:30 +08:00
ginuerzh c7ea19ec66 test(e2e): add bypass module e2e test suite
Verify both blacklist and whitelist bypass modes: a matching destination
skips the dead chain node and connects directly to the echo server, while a
non-matching destination is forced through the dead node and never reaches it.
2026-07-16 20:53:30 +08:00
ginuerzh b60c87e47f chore: ignore .claude/ session config 2026-07-16 20:53:30 +08:00
ginuerzh 632282436b chore: ignore build artifacts, codegraph index, python cache
.build/, .codegraph/ (generated multi-hundred-MB db), and __pycache__/
are local artifacts that should not be tracked.
2026-07-16 20:53:30 +08:00