mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 12:05:46 +00:00
Reproduce the regression where a domain-only whitelist bypass on a red (transparent) proxy rejected every connection: the pre-sniffing bypass check ran against the bare destination IP, which is never in a domain whitelist, before SNI sniffing could match. A privileged container redirects outbound TCP to the red service; asserts an allowlisted SNI is forwarded (hello-gost) and a non-allowlisted SNI is rejected.
27 lines
818 B
YAML
27 lines
818 B
YAML
# gost#899: whitelist bypass + sniffing on a transparent (red) proxy.
|
|
# The whitelist contains only a domain ("https-echo", the docker network alias
|
|
# of the HTTPS echo container). A bare destination IP is never in it, so on a
|
|
# broken build the pre-sniffing IP bypass check rejects every connection
|
|
# before SNI sniffing can match the host. The fix skips that check in
|
|
# whitelist mode and lets the sniffer drive the decision from the SNI.
|
|
log:
|
|
level: debug
|
|
services:
|
|
- name: transparent-egress
|
|
addr: ":12345"
|
|
bypass: allowlist
|
|
metadata:
|
|
so_mark: 114514
|
|
handler:
|
|
type: red
|
|
metadata:
|
|
sniffing: true
|
|
sniffing.timeout: 5s
|
|
sniffing.fallback: true
|
|
listener:
|
|
type: red
|
|
bypasses:
|
|
- name: allowlist
|
|
whitelist: true
|
|
matchers:
|
|
- https-echo |