mirror of
https://github.com/p1neappleXpress/OpenFlux.git
synced 2026-10-02 05:04:39 +08:00
0 off: status lines only
1 -d packet movement, one line per IPv4 packet:
-> 52 bytes - UDP 10.10.10.2:53000 -> 8.8.8.8:53 len=42 ttl=64
2 -dd plus operational logs (sessions, carriers, crypto, control)
3 -ddd plus hexdumps of packets and ciphertext
--debug=N sets the level directly; a bare --debug means -d. Only a run of
d's counts as the counted flag, so -direct-listen=... and other
single-dash long flags starting with d are no longer turned into
--debug. -d=N is accepted too. --sensetive is accepted as --sensitive,
as the previous commit message promised.
utils:
- Packetf logs at level 1, Debugf at level 2, IsVerbose() means level 3;
- the logger is created once and SetOutput swaps its writer, so the
mobile bridges can flip the level and the output while goroutines of
the previous connection are logging (from OpenFlux-Android 80fc99d);
- SetLogSink mirrors debug and packet lines to an embedding app, as the
Android bridge expects; EnableDebug/SetDebug(true) mean level 2, what
debug meant before levels;
- the unused Redact, Sensitivef and Verbosef are gone.
network.LogPacket is the one place that prints a packet line and, at
level 3, its hexdump. Every packet is logged once per side: the [NIC]
lines duplicated [TUNNEL] and are gone, and the iOS L3 path and
PacketTunnel, which logged nothing, now log too. On both sides "->"
points towards the internet and "<-" back towards the device: the L4
exit used to print them the other way round from L3 and the client, so
one flow now reads the same in both logs.
--sensitive now covers what can reveal a secret:
- key material, as before;
- hexdumps of plaintext frames (crypto plaintext, batch records, control
messages): control messages carry cookie jars, including an account
login, so -ddd alone never dumps them. Packet and ciphertext hexdumps
need only -ddd.
The [KEY] line and the [KEYDUMP] digest no longer print a SHA-256 of the
secret without --sensitive: it let anyone with the log test guesses
without paying for scrypt. The digest keeps the context and derived-key
prefixes, which is enough to compare peers.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>