Conversation
… use external DNS resolution.
luci-app-ssr-plus: Add fake-ip mode and Fix Upload yaml config cannot use external DNS resolution.
luci-app-ssr-plus: Fix YAML line processing pattern.
Signed-off-by: Tianling Shen <i@cnsztl.eu.org>
…imple Signed-off-by: Tianling Shen <i@cnsztl.eu.org>
|
@zxlhhyccc Thanks for publishing this. I reviewed the QUIC commit
Please also test fake-IP UDP with no TPROXY and router-originated UDP after removing the UDP NAT redirects and adding the OUTPUT mark; those paths changed but have no packet-level regression tests in this PR. I have not applied this PR to the production router. |
|
@vsmirn0v I think passing the |
|
@zxlhhyccc Thanks. Yes,
A real UDP-capable server is not needed to test the Mihomo routing decision. #2051 has a synthetic profile with dummy |
|
@vsmirn0v
changing the original rule:
to:
and deleting rules such as:
then, as long as the node supports UDP, UDP/443 will work normally in all cases. If the node does not have UDP enabled, the foreign server's QUIC will be forced through the TCP proxy. Please test: zxlhhyccc@a2bfe58
|
|
@zxlhhyccc I tested the requested Ordinary LAN proxy-selected UDP/443 reaches the transparent UDP listener; China and explicit LAN bypass cases remain direct. However, I reproduced these gaps:
I also ran Mihomo v1.19.31 with a synthetic For reproducible LAN cases, use the packet harness from #2051, setting sudo env SSR_RULES=/path/to/a2bfe58/ssr-rules WAN_BP_IP= WAN_FW_IP= \
unshare --net bash test_udp443_policy.sh --inside iptables proxy router fake-ip-excluded-port
# FAIL: expected proxy, got direct
sudo env SSR_RULES=/path/to/a2bfe58/ssr-rules WAN_BP_IP= WAN_FW_IP= \
unshare --net bash test_udp443_policy.sh --inside iptables reject router no-relay-disabled
# FAIL: expected reject, got directThe router tests add a WAN namespace/UDP echo receiver and use the source functions unchanged; each removal control deletes only the new OUTPUT marking rule. For native nft tests, functions were invoked in conditional lists as in production; the inherited malformed DNS-return expression otherwise stops a |
|
@vsmirn0v Could we discuss this privately one-on-one? Posting here is quite slow, and the meaning can easily get lost in translation. |
|
@zxlhhyccc Thanks—I understand the concern about translation and the pace of the discussion. Which private channel would you prefer? Please suggest a contact method you are comfortable sharing here. Once a channel is agreed, we can keep a short summary of the technical conclusions and test results in the PR for other reviewers. |

No description provided.