Add an e2e suite covering go-gost/x#125: a malformed UDP datagram sent
to a cipherKey-enabled QUIC listener must not close the shared transport.
Uses the canonical http-over-quic chaining pattern and verifies the
forward still works after the invalid datagram.
Also bumps go.mod/go.sum (plugin v0.6.1, otel, x/net, etc.).
Reproduce the regression where a domain-only whitelist bypass on a red
(transparent) proxy rejected every connection: the pre-sniffing bypass
check ran against the bare destination IP, which is never in a domain
whitelist, before SNI sniffing could match. A privileged container
redirects outbound TCP to the red service; asserts an allowlisted SNI
is forwarded (hello-gost) and a non-allowlisted SNI is rejected.
ProxyProtoSuite starts gost with metadata.proxyProtocol set and asserts
the HAProxy PROXY header is prepended on outbound connections (v1/v2),
backed by a raw-TCP capture script and configs. Add echo754_repro.py
from the hot-reload EADDRINUSE investigation (gost#754).
Bump github.com/go-gost/core to v0.6.1 and x to v0.16.0.
Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the
echo server; verifies the control request is 403, a checksum-valid
Gost-Target header naming an allowed authority cannot reach the blocked
backend, and a malformed header is fail-closed. Verified to catch the bug
by reverting the fix (exploit returned the backend response).
- Add ExecOutput helper to demultiplex the raw Docker exec stream so test
output assertions see clean stdout+stderr instead of framed bytes.
- Wait for container readiness via exposed port or "listening on" log line
when no ports are exposed.
- Use curl --proxy-* TLS options for the mTLS HTTPS-proxy test.
- Relax the http_cache first-request assertion (shared backend counter).
- Add gost#898 rtcp forwarder filter.host e2e test (multi-service one tunnel).
- Bump x to v0.15.7.
Co-Authored-By: Claude <noreply@anthropic.com>
Verifies dead->alive->dead node transition: a node excluded by a failing cmd
probe resumes carrying traffic once the probe flips healthy, without restart.
Add TestUDPForwardQUICSniffing: sends a real captured QUIC v1 Initial packet
through the UDP forward handler (with sniffing enabled) and verifies the
datagram is echoed back. Covers the QUIC ClientHello/ServerHello sniff path
in x/handler/redirect/udp and x/handler/forward/local.
Add e2e regression test for http.failCodes selector bug —
FIFO selector + failCodes=429 on first node proves
node-429 is excluded after first 429 response and all
subsequent requests go to node-good.
Verify node-level routing matchers via a two-proxy relay: a forward
proxy whose only chain node carries matcher Host(`tcp-echo`) is only
eligible for a matching Host, so the request is relayed upstream to the
echo server; a non-matching Host is excluded (no eligible node) and never
reaches the echo server. Mirrors the resolver/ingress e2e pattern.
Verifies that a configured resolver drives the proxy's outbound DNS
resolution. A gost HTTP proxy uses a resolver whose only nameserver is a
test responder answering echo.test with the real echo server IP and
NXDOMAIN for everything else. A request to echo.test is resolved by the
custom resolver and reaches the echo server; an unmapped host fails to
resolve. Adds a parametrized DNS responder script and container helper.
Verifies hostname→endpoint routing at the reverse-proxy tunnel
entrypoint. A public gost runs a tunnel handler with an ingress
mapping example.local→tunnel-UUID and an HTTP entrypoint; an internal
client binds a reverse tunnel forwarding to the echo server. A request
with a mapped Host is routed through the tunnel to the echo server,
while an unmapped Host matches no ingress rule and is rejected.
Verify the static hosts mapping (HostMapper) overrides DNS: a mapped
hostname resolves to the configured IP and reaches the echo server,
while an unmapped hostname fails to resolve.
Verify HTTP proxy authentication for both inline single-user auth and a
named auther with multiple users. Covers valid credentials, wrong
password, missing credentials, and any-user-in-auther acceptance.
Verify service-level admission control gating by client source IP, in
both whitelist and blacklist modes. Contrasts a loopback client (curl
inside the gost container) against an external client (curl inside the
echo container) to exercise both admit and deny paths.
Verify both blacklist and whitelist bypass modes: a matching destination
skips the dead chain node and connects directly to the echo server, while a
non-matching destination is forced through the dead node and never reaches it.
Merge parallel_selector_test.go into selector_test.go and add e2e coverage
for the round-robin + fail filter, fifo sticky fallback, and backup filter
strategies. Each test drives requests through a hop with one dead node and
asserts the selector marks and skips it so traffic converges on the live node.
Co-Authored-By: Claude <noreply@anthropic.com>
Adds an e2e suite (tests/e2e/utls_test.go + testdata/utls/*)
that exercises the utls dialer in a forward-proxy chain:
curl -> client gost (http proxy :8080)
-> chain node (http connector + utls dialer)
-> server gost (http over TLS listener :8443)
-> tcp-echo
Two cases:
- TestUTLSInsecure: regression for go-gost/gost#887. A utls
dialer with `secure: false` must still complete the handshake
(InsecureSkipVerify must be honoured). The old unsafe cast read
garbage for InsecureSkipVerify and the handshake failed.
- TestUTLSSecureWithCA: exercises the converter's RootCAs /
ServerName path with a CA-signed server cert.
Uses the deterministic `Chrome` fingerprint (not `randomized`, which
randomises the ClientHello and is flaky against a standard Go TLS
server).
Bumps github.com/go-gost/x to v0.13.11, which fixes the
second half of #887: the curve-preference enum divergence between
crypto/tls and utls (Go 1.24+ appends PQC hybrid curves that
utls does not define).
Related: go-gost/gost#887, go-gost/x#111, go-gost/x#112