Files
gost/tests/e2e/testdata/red_sniffing/whitelist.yaml
T
ginuerzh d778c031eb test(e2e): transparent whitelist bypass + sniffing (gost#899)
Reproduce the regression where a domain-only whitelist bypass on a red
(transparent) proxy rejected every connection: the pre-sniffing bypass
check ran against the bare destination IP, which is never in a domain
whitelist, before SNI sniffing could match. A privileged container
redirects outbound TCP to the red service; asserts an allowlisted SNI
is forwarded (hello-gost) and a non-allowlisted SNI is rejected.
2026-08-31 22:35:03 +08:00

27 lines
818 B
YAML

# gost#899: whitelist bypass + sniffing on a transparent (red) proxy.
# The whitelist contains only a domain ("https-echo", the docker network alias
# of the HTTPS echo container). A bare destination IP is never in it, so on a
# broken build the pre-sniffing IP bypass check rejects every connection
# before SNI sniffing can match the host. The fix skips that check in
# whitelist mode and lets the sniffer drive the decision from the SNI.
log:
level: debug
services:
- name: transparent-egress
addr: ":12345"
bypass: allowlist
metadata:
so_mark: 114514
handler:
type: red
metadata:
sniffing: true
sniffing.timeout: 5s
sniffing.fallback: true
listener:
type: red
bypasses:
- name: allowlist
whitelist: true
matchers:
- https-echo