Commit Graph
100 Commits
Author SHA1 Message Date
ginuerzh eb66804ec8 chore(gost): bump github.com/go-gost/x to v0.17.1 2026-09-12 12:12:22 +08:00
ginuerzh a20999046b chore(gost): bump github.com/go-gost/x to v0.17.0 2026-09-12 10:16:16 +08:00
ginuerzh 36cc266257 chore: anchor gost gitignore rule to repo root
The bare 'gost' pattern also matched the cmd/gost/ directory, forcing
-f to stage tracked files under it.
2026-09-07 17:46:21 +08:00
ginuerzh 074af1b175 program: shut down plugin subprocesses on stop 2026-09-07 17:42:44 +08:00
ginuerzh ee61f28688 test(e2e): add QUIC cipherKey invalid-datagram regression
Add an e2e suite covering go-gost/x#125: a malformed UDP datagram sent
to a cipherKey-enabled QUIC listener must not close the shared transport.
Uses the canonical http-over-quic chaining pattern and verifies the
forward still works after the invalid datagram.

Also bumps go.mod/go.sum (plugin v0.6.1, otel, x/net, etc.).
2026-09-07 14:53:36 +08:00
ginuerzh 27ac16439e bump to v3.3.1, x v0.16.1 2026-08-31 22:54:26 +08:00
ginuerzh d778c031eb test(e2e): transparent whitelist bypass + sniffing (gost#899)
Reproduce the regression where a domain-only whitelist bypass on a red
(transparent) proxy rejected every connection: the pre-sniffing bypass
check ran against the bare destination IP, which is never in a domain
whitelist, before SNI sniffing could match. A privileged container
redirects outbound TCP to the red service; asserts an allowlisted SNI
is forwarded (hello-gost) and a non-allowlisted SNI is rejected.
2026-08-31 22:35:03 +08:00
ginuerzh cb76f63754 e2e: add PROXY protocol test (gost#677), bump core/x deps
ProxyProtoSuite starts gost with metadata.proxyProtocol set and asserts
the HAProxy PROXY header is prepended on outbound connections (v1/v2),
backed by a raw-TCP capture script and configs. Add echo754_repro.py
from the hot-reload EADDRINUSE investigation (gost#754).

Bump github.com/go-gost/core to v0.6.1 and x to v0.16.0.
2026-08-29 09:26:33 +08:00
ginuerzh 76467efc59 test(e2e): regression for Gost-Target destination-policy bypass
Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the
echo server; verifies the control request is 403, a checksum-valid
Gost-Target header naming an allowed authority cannot reach the blocked
backend, and a malformed header is fail-closed. Verified to catch the bug
by reverting the fix (exploit returned the backend response).
2026-08-27 20:16:34 +08:00
ginuerzh 35f7cd912c test(e2e): cover origin-form HTTP proxy request (#679)
Send a raw "GET / HTTP/1.1" + Host header through the http proxy,
mirroring nginx proxy_pass. Dumps container logs on failure.
2026-08-27 00:02:33 +08:00
ginuerzhandClaude 5e40415ac9 e2e: demux testcontainers exec stream, fix mtls proxy flags, add rtcp filter test
- Add ExecOutput helper to demultiplex the raw Docker exec stream so test
  output assertions see clean stdout+stderr instead of framed bytes.
- Wait for container readiness via exposed port or "listening on" log line
  when no ports are exposed.
- Use curl --proxy-* TLS options for the mTLS HTTPS-proxy test.
- Relax the http_cache first-request assertion (shared backend counter).
- Add gost#898 rtcp forwarder filter.host e2e test (multi-service one tunnel).
- Bump x to v0.15.7.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-26 22:27:52 +08:00
ginuerzh ecf14b8459 bump x to v0.15.6 2026-08-25 22:18:31 +08:00
ginuerzh 1f14e72e3c bump x to v0.15.5 2026-08-21 21:52:06 +08:00
ginuerzh aa1565c8b2 bump x to v0.15.4 2026-08-18 23:44:32 +08:00
ginuerzh f7b27a2c8b bump x to v0.15.3 2026-08-17 23:09:43 +08:00
ginuerzh c7d793c619 e2e: add cmd probe recovery test (gost#837)
Verifies dead->alive->dead node transition: a node excluded by a failing cmd
probe resumes carrying traffic once the probe flips healthy, without restart.
2026-08-01 23:23:28 +08:00
ginuerzh f25148f2e0 bump x to v0.15.2 (SSH authorized_keys trailing-newline fix, gost#699) 2026-08-01 23:22:22 +08:00
ginuerzh 960f081e53 e2e: add UDP forward QUIC sniffing test
Add TestUDPForwardQUICSniffing: sends a real captured QUIC v1 Initial packet
through the UDP forward handler (with sniffing enabled) and verifies the
datagram is echoed back. Covers the QUIC ClientHello/ServerHello sniff path
in x/handler/redirect/udp and x/handler/forward/local.
2026-07-30 23:24:35 +08:00
ginuerzh 55bb214a94 chore: bump x to v0.15.1, add e2e tests for chainGroup and sniffing
- Bump github.com/go-gost/x v0.15.0 → v0.15.1
- ChainGroupSuite: matcher routing by host, probe dead-chain pre-marking
- SniffingSuite: SOCKS5+HTTPS w/o SNI, debug-only log on empty SNI
- Add RunHTTPSEchoContainer and https_echo.py test helper
2026-07-29 23:06:15 +08:00
ginuerzh 555dacd244 chore: bump x to v0.15.0 (hopGroup, failCodes fix)
Add e2e regression test for http.failCodes selector bug —
FIFO selector + failCodes=429 on first node proves
node-429 is excluded after first 429 response and all
subsequent requests go to node-good.
2026-07-27 22:13:34 +08:00
ginuerzh f63b212434 chore: bump x to v0.14.2, tls-dissector to v0.3.1, quic-go to v0.60.0, webtransport-go to v0.11.1 2026-07-26 23:03:38 +08:00
ginuerzh 64017bf195 chore: bump x to v0.14.1 2026-07-26 20:17:23 +08:00
ginuerzh 5a1a799848 tests/e2e: add HTTP response cache e2e tests 2026-07-26 18:14:03 +08:00
ginuerzh 5204d6285e chore: bump deps (core v0.6.0, x v0.14.0) 2026-07-26 18:12:57 +08:00
ginuerzh 81108ee0a4 chore: bump deps (core v0.5.5, x v0.13.18) 2026-07-25 18:52:45 +08:00
ginuerzh 122dde8385 chore: go get -u all
- x v0.13.15 → v0.13.16
- tls-dissector v0.2.0 → v0.3.0
- golang.org/x/* bump (crypto, net, sys, text, mod, sync, term, tools)
- oTel v1.41.0 → v1.43.0
- grpc v1.79.3 → v1.82.1
- gonum v0.16.0 → v0.17.0
2026-07-24 23:15:01 +08:00
ginuerzh 9ccb007589 chore: bump deps
- x v0.13.14 → v0.13.15 (MetadataFeature, BodyJSON matcher)
- relay v0.6.2 → v0.7.0
- tls-dissector v0.2.0 → v0.3.0
- add tidwall gjson/match/pretty/sjson (indirect, via x)
2026-07-24 22:34:52 +08:00
ginuerzh 5a01aa4fd2 chore: bump x to v0.13.14 (forwarder probe passthrough fix) 2026-07-16 23:34:22 +08:00
ginuerzh 4cdc5588ff chore: bump core to v0.5.4 (node liveness probe types) 2026-07-16 21:34:33 +08:00
ginuerzh 89f9ea124a chore: bump x to v0.13.13 (Tor SOCKS5 resolve, cmd probe) 2026-07-16 21:24:41 +08:00
ginuerzh e9cf3b4d3f e2e: add cmd probe failover test with true/false command nodes 2026-07-16 20:53:30 +08:00
ginuerzh bef00dffef e2e: add node liveness probe tests
TCP probe + FailFilter: dead node pre-marked, all requests succeed.
LowestLatency strategy: two probed nodes, selector picks fastest.
2026-07-16 20:53:30 +08:00
ginuerzh 1c6fadcb1e test(e2e): add routing matcher module e2e test suite
Verify node-level routing matchers via a two-proxy relay: a forward
proxy whose only chain node carries matcher Host(`tcp-echo`) is only
eligible for a matching Host, so the request is relayed upstream to the
echo server; a non-matching Host is excluded (no eligible node) and never
reaches the echo server. Mirrors the resolver/ingress e2e pattern.
2026-07-16 20:53:30 +08:00
ginuerzh 20f1e4a0b9 test(e2e): add resolver module e2e test suite
Verifies that a configured resolver drives the proxy's outbound DNS
resolution. A gost HTTP proxy uses a resolver whose only nameserver is a
test responder answering echo.test with the real echo server IP and
NXDOMAIN for everything else. A request to echo.test is resolved by the
custom resolver and reaches the echo server; an unmapped host fails to
resolve. Adds a parametrized DNS responder script and container helper.
2026-07-16 20:53:30 +08:00
ginuerzh 1fd69ac704 test(e2e): add ingress module e2e test suite
Verifies hostname→endpoint routing at the reverse-proxy tunnel
entrypoint. A public gost runs a tunnel handler with an ingress
mapping example.local→tunnel-UUID and an HTTP entrypoint; an internal
client binds a reverse tunnel forwarding to the echo server. A request
with a mapped Host is routed through the tunnel to the echo server,
while an unmapped Host matches no ingress rule and is rejected.
2026-07-16 20:53:30 +08:00
ginuerzh 9355607ba7 test(e2e): add hosts module e2e test suite
Verify the static hosts mapping (HostMapper) overrides DNS: a mapped
hostname resolves to the configured IP and reaches the echo server,
while an unmapped hostname fails to resolve.
2026-07-16 20:53:30 +08:00
ginuerzh 6746f556b7 test(e2e): add auth module e2e test suite
Verify HTTP proxy authentication for both inline single-user auth and a
named auther with multiple users. Covers valid credentials, wrong
password, missing credentials, and any-user-in-auther acceptance.
2026-07-16 20:53:30 +08:00
ginuerzh 3119cb43f2 test(e2e): add admission module e2e test suite
Verify service-level admission control gating by client source IP, in
both whitelist and blacklist modes. Contrasts a loopback client (curl
inside the gost container) against an external client (curl inside the
echo container) to exercise both admit and deny paths.
2026-07-16 20:53:30 +08:00
ginuerzh c7ea19ec66 test(e2e): add bypass module e2e test suite
Verify both blacklist and whitelist bypass modes: a matching destination
skips the dead chain node and connects directly to the echo server, while a
non-matching destination is forced through the dead node and never reaches it.
2026-07-16 20:53:30 +08:00
ginuerzh b60c87e47f chore: ignore .claude/ session config 2026-07-16 20:53:30 +08:00
ginuerzh 632282436b chore: ignore build artifacts, codegraph index, python cache
.build/, .codegraph/ (generated multi-hundred-MB db), and __pycache__/
are local artifacts that should not be tracked.
2026-07-16 20:53:30 +08:00
ginuerzh fa815bf4a0 test(e2e): add TLS listener rejectUnknownSNI test suite
Covers rejectUnknownSNI with and without a serverNames allow list,
verifying allowed/unknown/empty SNI handshakes via openssl s_client.
2026-07-16 20:53:30 +08:00
ginuerzhandClaude a8bd4a5f16 test(e2e): consolidate selector tests, add round-robin/fifo/backup failover
Merge parallel_selector_test.go into selector_test.go and add e2e coverage
for the round-robin + fail filter, fifo sticky fallback, and backup filter
strategies. Each test drives requests through a hop with one dead node and
asserts the selector marks and skips it so traffic converges on the live node.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-16 20:53:30 +08:00
ginuerzh 7643e16cca chore: bump go-gost/x to v0.13.12 2026-07-11 22:11:08 +08:00
ginuerzh ccf2989bc0 gost: bump x to v0.13.9, relay to v0.6.2; add PHT e2e tests
- go.mod: x v0.13.8 → v0.13.9, relay v0.6.1 → v0.6.2
- tests/e2e/pht_test.go: 3 test cases (basic tunnel, PHTs, heartbeat)
- tests/e2e/testdata/pht/: client/server and client_phts/server_phts YAML configs
2026-07-06 22:10:15 +08:00
ginuerzh d54a896a81 update go.mod 2026-07-05 21:22:15 +08:00
ginuerzh 6b7dbf08fa chore: bump go-gost/x to v0.13.8, plugin to v0.5.0 2026-07-05 21:19:32 +08:00
ginuerzh dd56308b2e test(mtls): add e2e tests for mTLS client cert identity forwarding
Tests verify: mTLS proxy works with valid client cert, mTLS rejects
connections without client cert, HTTP auth plugin receives client_cn,
client_san, client_cert_fingerprint via PeerCert context propagation.
2026-07-04 19:00:44 +08:00
ginuerzh eb9dbb1807 chore: bump core to v0.5.3 and x to v0.13.7 2026-07-03 20:20:26 +08:00
ginuerzh 02dc900686 chore: bump go-gost/x to v0.13.5 2026-07-02 21:09:46 +08:00
ginuerzh bb912edecc chore: bump go-gost/x to v0.13.3 2026-06-30 20:59:00 +08:00
ginuerzh ffb61cc19f chore: bump go-gost/core to v0.5.2, go-gost/x to v0.13.2 2026-06-30 11:05:02 +08:00
ginuerzh a864cbcfe5 chore: bump go-gost/x to v0.13.1 2026-06-28 20:06:03 +08:00
ginuerzh b139ed5968 chore: bump go-gost/core to v0.5.1, go-gost/x to v0.13.0, go-gost/plugin to v0.4.0 2026-06-27 23:05:22 +08:00
ginuerzhandClaude 43724a5c40 test: add http2 handler e2e suite and tighten host-mapper + idle-timeout tests
Add tests/e2e/http2_test.go covering the http2 handler/listener/connector/dialer
end-to-end through the canonical gost-as-client pattern (8 subtests: forward,
auth, bypass, probeResist/metadata, h2 stream multiplexing). Include
testdata/http2/{server,server_auth,server_bypass,server_proberesist,client,
client_auth}.yaml. Note that h2/h2c listeners pair with the tunnel handler
and only http2 listener pairs with handler http2 (reads r/w from metadata).

Tighten TestDNSHostMapper by pointing the handler at an unreachable upstream
so unmapped names fail at the exchanger, confirming the host-mapper path was
the sole reason mapped names resolved. Fix http_idle_timeout.py to speak HTTP
through the CONNECT tunnel rather than a raw ping, matching the echo backend.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-06-27 20:15:31 +08:00
ginuerzh 0bb9109c71 feat: add comprehensive forward handler e2e tests
Add TCP/UDP forward handler e2e tests covering basic forwarding, alias
(forward/tcp), sniffing, raw pipe, idleTimeout, multi-node protocol
filtering, sniffing bypass (403), stateful UDP, and stateless UDP.

New files:
- forward_test.go: ForwardSuite with 9 test methods
- testdata/forward/: server configs (tcp, udp, stateless, sniffing,
  bypass, multi-node, idleTimeout)
- scripts/tcp_idle_timeout.py, udp_forward_test.py: Python harnesses
  for in-container idle timeout and UDP echo verification
2026-06-27 13:59:22 +08:00
ginuerzh a0427be086 feat: add comprehensive DNS handler e2e tests
Adds 22 DNS e2e subtests across 8 test methods covering: upstream
resolution (A, AAAA, multi-A), TCP mode, bypass rules, host mapper,
exchange failure (graceful error recovery), rate limiter wiring,
invalid query handling, and DNS over TLS (mode: tls).

Includes two authoritative DNS responders (UDP/TCP), a standalone
DNS query client, and a TLS DNS query script.
2026-06-27 00:21:37 +08:00
ginuerzh 590c6f48bd feat: add file handler e2e tests covering GET, PUT, index, auth, and 404
Adds 5 test methods (7 test cases) for the file handler:
GET existing file, GET nonexistent file, GET index.html, PUT upload,
PUT without permission, and auth (no-auth-401, with-auth-success).

Includes test data files and server YAML configs under
tests/e2e/testdata/file/.
2026-06-26 22:19:13 +08:00
ginuerzh 69b561f944 feat: add comprehensive HTTP e2e tests covering connector, TLS, probeResist, idleTimeout, and UDP relay
Adds 12 new HTTP handler test scenarios: HTTP connector (no-auth, auth, TLS
upstream), CONNECT tunnel (no-sniffing, bypass-403), probeResist (host, web,
file, knock), idleTimeout, and UDP relay over HTTP. Introduces
RunGostContainerWithFiles helper for mounting extra files into test containers.
2026-06-26 22:00:35 +08:00
ginuerzh 3c87a8b96e chore(deps): bump go-gost/x to v0.12.5 2026-06-26 20:21:42 +08:00
ginuerzh c9cfc440ad build(deps): bump go-gost/x from v0.12.3 to v0.12.4 2026-06-25 20:50:53 +08:00
ginuerzh c305f93703 chore(deps): bump go-gost/x to v0.12.3 2026-06-23 21:47:44 +08:00
ginuerzh f638d8081f build(deps): bump go-gost/x from v0.12.1 to v0.12.2
x v0.12.2 adds SO_REUSEPORT support for TCP listeners (#654).
2026-06-22 21:46:46 +08:00
ginuerzh 286c1615fd build(deps): bump go-gost/x from v0.12.0 to v0.12.1 2026-06-21 22:55:44 +08:00
ginuerzh b985e5138c fix: use atomic int for multi-worker exit code and clean up cancellation
- Replace bare int with atomic.Int32 to fix data race on ret
- Replace wg.Add/go/defer wg.Done pattern with wg.Go (Go 1.22+)
- Pass context by value instead of pointer
- Add ctx.Err() guard to suppress fatal on cancellation errors
- Add ProcessState nil check before accessing ExitCode
- Move cancel() after wg.Wait() to avoid race where a successful
  worker's deferred cancel kills siblings and triggers log.Fatal
2026-06-21 21:07:37 +08:00
ginuerzh b628475871 fix: enable metrics before loading services
Move xmetrics.Enable(true) from run() to Start(), before loader.Load(),
so that listener wrappers can observe the enabled state at Init time
rather than after wrapper decisions have already been made.
2026-06-21 20:35:19 +08:00
ginuerzh 43dd0a6958 feat: register stdio listener for SSH ProxyCommand support
Adds blank import of x/listener/stdio to register the stdio listener.

Refs go-gost/gost#433
2026-06-21 15:40:41 +08:00
ginuerzh 9d00ad8c8f build(deps): bump go-gost/x from v0.11.1 to v0.12.0 2026-06-20 22:15:57 +08:00
ginuerzh 1bebce0ed7 feat: register utls dialer for TLS ClientHello fingerprint simulation
Blank-import x/dialer/utls to enable the "utls" dialer type via
init() self-registration.

Refs go-gost/gost#31
2026-06-20 20:17:08 +08:00
ginuerzh 1178c4757f feat(cmd): add -R auto-reload flag for periodic config refresh
Introduce -R <duration> flag (e.g., -R 30s, -R 1m) that triggers
periodic config reload. Combined with -C URL support, this enables
centralized fleet management where nodes poll a remote config server.

The reload goroutine reuses the existing SIGHUP reloadConfig path:
parser.Parse() → loader.Load() → p.run(cfg). When -R is zero
(default) behavior is unchanged; SIGHUP still works independently.
2026-06-20 20:12:11 +08:00
ginuerzh 73069f50e3 feat: support multiple -C config files
Change -C flag from string to stringList, allowing:
  gost -C base.yml -C services.yml -C auth.yml

Closes go-gost/gost#150
2026-06-20 18:56:25 +08:00
ginuerzh 06ec0097f9 ci: harden docker/release/nightly GitHub Actions workflows
- buildx: adopt docker/metadata-action for image tags (replaces hand-rolled shell), add gha build cache, concurrency control, explicit checkout, and least-privilege permissions

- release: add explicit permissions and concurrency (no cancel-in-flight); drop dead UPX install step (disabled in .goreleaser.yaml, see #863)

- trigger-nightly: add concurrency, replace archived dev-drprasad/delete-older-releases with native gh, and harden the 24h commit check
2026-06-19 19:11:25 +08:00
ginuerzh 396b0977bd chore: bump x to v0.11.1 2026-06-19 09:29:14 +08:00
ginuerzh 6d80e06ab3 chore: bump x to v0.11.0 2026-06-17 22:32:51 +08:00
ginuerzh e2447ce578 fix(e2e): use host network for Docker image builds in DinD environments
Docker-in-Docker containers cannot reach the internet via the default
bridge network, causing 'apk add' in the Dockerfile to hang indefinitely
and e2e tests to timeout after 10 minutes.

Add BuildOptionsModifier with NetworkMode=host to all FromDockerfile
definitions so the build step uses the host's network stack. This has
no negative impact on non-DinD environments where bridge networking
already works.

Also move GostBinPath flag and init() from main_test.go to utils.go
(non-test file) so the symbol is accessible across the package.
2026-06-06 20:34:24 +08:00
ginuerzh 811420e923 chore: bump x to include stateless UDP forwarding (#853) 2026-06-05 23:27:22 +08:00
ginuerzh 374b46dfe1 bump x to v0.10.10 2026-06-03 23:30:01 +08:00
ginuerzh 22edb92084 bump x to v0.10.10 2026-06-03 23:25:54 +08:00
ginuerzh 78a0a8c734 fix: disable UPX compression in Dockerfile to resolve #863 startup regression 2026-06-03 00:13:58 +08:00
ginuerzh 5639c90e98 bump x to v0.10.9 2026-06-02 23:54:13 +08:00
ginuerzh 36abf9bcd9 bump x to v0.10.8 2026-06-02 20:07:48 +08:00
ginuerzh d584b7ac61 bump x to v0.10.7 2026-05-31 22:49:10 +08:00
ginuerzh 56e2a1c496 fix: disable UPX compression to resolve #863 startup regression
UPX --best/--lzma/--brute adds ~3s startup time on low-spec systems
(linux/arm) due to in-memory decompression on every invocation of gost -V.
Disabled by default; opt in via GORELEASER_UPX=true for release builds
that need it.
2026-05-31 22:25:57 +08:00
ginuerzh b0bea19275 bump x to v0.10.6 2026-05-31 22:13:42 +08:00
ginuerzh cd64f2edd3 bump x to v0.10.5 2026-05-31 19:50:49 +08:00
ginuerzh 5f04c84e32 bump core to v0.4.1 2026-05-31 19:40:28 +08:00
ginuerzh 600a64e611 bump x to v0.10.4 2026-05-31 17:47:52 +08:00
ginuerzh 3d6b16686b bump x to v0.10.3 2026-05-29 00:29:26 +08:00
ginuerzh 44684d40c3 add CLAUDE.md with build, CLI, and lifecycle documentation 2026-05-23 00:00:56 +08:00
ginuerzh 2be36abe75 bump x to v0.10.1, go-shadowsocks2 to v0.1.3; add gost binary to .gitignore 2026-05-22 23:21:30 +08:00
ginuerzh 8db62785fa Merge pull request #862: Add e2e test cases for shadowsocks
Add comprehensive e2e tests covering TCP and UDP shadowsocks
connections with various cipher modes (aes-128-gcm, aes-256-gcm,
chacha20, 2022-blake3-aes-128, 2022-blake3-aes-256, including
multi-PSK variants).
2026-05-22 23:09:42 +08:00
ginuerzh d4c9ef5056 add masque connector, dialer, and handler registrations; update x to v0.10.0 2026-05-21 23:03:49 +08:00
ginuerzh e388426ec6 go1.26 2026-04-21 23:59:31 +08:00
ginuerzh 340ba32ef0 v3.2.6 2025-11-22 22:47:02 +08:00
ginuerzh 96551d5fa5 metrics: fix server conn wrapper (#797) 2025-10-11 22:07:41 +08:00
ginuerzh 8d05a6ed93 add multiple entrypoints for tunnel 2025-10-09 22:33:31 +08:00
ginuerzh 0348a16aa9 fix panic for channel close (#779) 2025-09-20 10:06:15 +08:00
ginuerzh 50934e0978 fix sniffing for websocket 2025-09-04 21:32:34 +08:00
ginuerzh c2ed9c6f07 add service option for plugin 2025-08-29 23:38:29 +08:00
ginuerzh 3b9da4e260 go1.25 2025-08-21 22:53:28 +08:00