mirror of
https://github.com/p1neappleXpress/OpenFlux.git
synced 2026-10-02 05:04:39 +08:00
* utils: status lines reach the app log; count secrets as Kotlin does Infof now also goes to the log sink, so the Android log screen and the iOS ring buffer show the status lines the CLI prints. Throttled rate-limits warnings that would repeat on every packet. SecretChars counts a secret in UTF-16 units: the core counted bytes, accepting a 10-letter Cyrillic secret that Desktop and Android reject. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * transport: one KDF context rule, and fall back when the peer's differs KDFContexts replaces the copies of the context rule that had drifted apart (CLI, Android bridge, Desktop, iOS). A classic cupsonline client given the rooms as --url now derives the placeholder like the exit that created them; it used the room list, and no packet ever decrypted. The context is a public salt, so a peer may try several: alternates are what other or older builds derive. A packet that fails under the current keys is tried under them (derived lazily); the exit answers under the context the client used, a client that hears nothing cycles through them. A mismatch that dropped everything in silence now heals itself, and a key that really differs is reported in the log. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * transport: classic codec that accepts both framings and falls back batched against legacy dropped every packet in silence. CodecTransport decodes both (they differ in the first byte), sends what the peer sends (batched once it has seen a batch frame, including the iOS fork's empty probe), and the client tries the other framing while the peer is silent. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * session: classic compatibility on the same carrier, diagnostics The classic and Session layerings differ in the first byte of a carrier frame, so frameDemux splits one carrier between a Session and a classic pipeline sharing its keys. SetClassic turns it on: a single-carrier client falls back to classic while the exit does not answer the handshake and switches once it does; a classic-configured exit also serves classic clients while no Session client is active. Strict Sessions log classic frames with the fix instead of dropping them silently. Logs: carrier start failures, takeover by another client, mode switches, and a handshake diagnosis (nothing arrived / key differs / exit is classic). The carrier is stopped once instead of twice. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * manager: match the peer's carriers when names differ The apps name carriers after their type (mailru, mailru-2) whatever the exit's .conf or panel called them, so a cookie offer or AuthRequired for an unknown name went nowhere. Cookie messages carry the document URL now, and the name is matched by it, then by type when this side has one carrier of it; what cannot be matched is logged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * cli: classic setups with a key run as a Session with classic fallback --transport=X with a key now builds a Session: a client speaks classic until the exit answers the handshake, an exit also serves classic clients. A single-carrier --transports/.conf client falls back the same way; only --negotiate is strict. Without a key the classic path stays, with the adaptive codec. The context comes from transport.KDFContexts, alternates included, and a cupsonline exit accepts its room list as one. transportFactory takes the role: a Session client's cupsonline carrier was built as an exit and, with no or dead rooms, created rooms of its own. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * mobile: same Session, context and codec fallback as the CLI Classic profiles with a key build a Session with classic fallback, as the CLI does, so a classic profile works against every node; classic direct works too. Single-carrier Session profiles fall back to classic; the node wizard's check stays strict. The context rule is transport.KDFContexts (the link's context first, the derived one as an alternate). SetInitialCookies applies cookies got before the start to Yandex carriers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * share: read links the way every client does; --parse-link Decode accepts what copying and other encoders do to a link: whitespace and line breaks, base64 padding, the standard alphabet, and says what is wrong otherwise. Secrets are counted in characters as Kotlin counts them. --parse-link prints the core's reading of a link as JSON, for apps and debugging; --share also prints the bare link on its own line. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * boards: stop sending client pings; docs: reconnect on dead sockets boards sent engine.io pings from the client, which an EIO=4 server treats as an invalid heartbeat and closes the socket: the board dropped every 20 seconds. The server pings and we answer, as before. yandex and mailru left a socket whose keepalive failed open, so a reader on a half-open connection could wait forever; they close it now, and bound each write. Drops and failures to open the document are logged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * transport: tests for mixed builds (codecs, contexts, classic vs Session) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * ios: the iOS C library on package mobile (mobile/ios) The iOS app carried its own copy of the core (the saharev1/OpenFlux fork): no Session, its own link importer, its own control channel, so it reached no node the wizard or Desktop set up. The root export_ios*.go here were an even older copy of the same. mobile/ios is the app's C API (every call the app makes, same names and signatures) implemented on package mobile, the Android library: an app that links this core as a submodule and builds it with build_ios.sh gets the Session with classic fallback, the one context rule with its alternates, the codec fallback and the core's link reading. New calls: OpenFluxShareDecode returns a Session profile ready for OpenFluxStartSession / OpenFluxStartSessionPacketTunnel; OpenFluxMode, OpenFluxActiveTransport, OpenFluxSetCodec, OpenFluxSetDebugLevel and the captcha calls the app had no equivalent for. The Network Extension runs the carriers on a phone profile (mobile.SetLowMemory, Volga's SlimVolgaConfig) and keeps the fork's local DNS-over-TLS, ICMP refusal for UDP and GeoSite split tunneling. PROTOCOL_NEGOTIATION.md gave the Session's layering in the classic order (AES inside the batch frame); the Session has always encrypted the batch frame. Fixed, with the classic layering, codec and context fallback and the context rule documented. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * session: say how to fix a classic peer at a Session-only exit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * crypto: search the context per pipeline; a gone Session client yields in 15s A client's Session hellos and its classic fallback shared one context search, so while a classic exit ignored the hellos the search moved the classic pipeline off the context that exit uses, and the first classic packets went out under the wrong keys. Keys are still derived once per carrier (keyStore); each pipeline searches on its own (keyRing), and a client's pipelines pass on what they learn. An exit configured classic yielded to a classic client only linkTimeout (30 s) after its Session client was last heard; a live one is heard every keepaliveInterval, so it yields after 15 s. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * build_ios.sh: work from any directory The output directory was made and listed relative to the caller's directory while the library was written under the checkout, so running core/build_ios.sh from an app that links the core as a submodule failed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: p1neappleXpress <a@a.a> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
111 lines
3.4 KiB
Go
111 lines
3.4 KiB
Go
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"strconv"
|
|
"strings"
|
|
|
|
"openflux/transport"
|
|
"openflux/transport/control"
|
|
"openflux/transport/manager"
|
|
)
|
|
|
|
// transportSpec is one entry from --transports plus its per-type URL/params.
|
|
type transportSpec struct {
|
|
Name string
|
|
Type string
|
|
Priority int
|
|
URL string
|
|
Params map[string]interface{}
|
|
}
|
|
|
|
// parseTransportList parses "direct:100,yandex:50,mailru:30".
|
|
// Priority is optional; default is 50.
|
|
func parseTransportList(s string) ([]transportSpec, error) {
|
|
var out []transportSpec
|
|
for _, part := range strings.Split(s, ",") {
|
|
part = strings.TrimSpace(part)
|
|
if part == "" {
|
|
continue
|
|
}
|
|
name, prioStr, hasPrio := strings.Cut(part, ":")
|
|
prio := 50
|
|
if hasPrio {
|
|
v, err := strconv.Atoi(prioStr)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("bad priority %q: %w", prioStr, err)
|
|
}
|
|
prio = v
|
|
}
|
|
out = append(out, transportSpec{
|
|
Name: name,
|
|
Type: name, // by default the name and the type match
|
|
Priority: prio,
|
|
})
|
|
}
|
|
return out, nil
|
|
}
|
|
|
|
// buildTransportSpecs assembles the config for each name in the list, using
|
|
// per-type URL flags (--yandex-url, --mailru-url, ...) and global settings.
|
|
func buildTransportSpecs(specs []transportSpec, urls map[string]string, extra map[string]map[string]interface{}) []transportSpec {
|
|
for i := range specs {
|
|
// Only a flag that was set overrides: the unset ones are "" and
|
|
// would wipe the URL of a .conf [Transport] section.
|
|
if u, ok := urls[specs[i].Type]; ok && u != "" {
|
|
specs[i].URL = u
|
|
}
|
|
if p, ok := extra[specs[i].Type]; ok {
|
|
specs[i].Params = p
|
|
}
|
|
}
|
|
return specs
|
|
}
|
|
|
|
// makeRawTransport builds a raw transport from a spec without the Manager's
|
|
// factory (bootstrap path). The Manager's factory is only used for transports
|
|
// added later via SubtypeTransportStart.
|
|
func makeRawTransport(spec transportSpec, baseCfg transport.TransportConfig, isExit bool) (transport.Transport, error) {
|
|
cfg := &control.TransportConfig{
|
|
Name: spec.Name,
|
|
Type: spec.Type,
|
|
URL: spec.URL,
|
|
Params: spec.Params,
|
|
}
|
|
return transportFactory(baseCfg, isExit)(cfg)
|
|
}
|
|
|
|
// registerBootstrapTransports wires every spec into the manager, and also
|
|
// calls Session.AddTransport with the shared secret/context so the handshake
|
|
// can use any of them. Transports that learn their client address only when
|
|
// running go into rooms by spec name, for --share.
|
|
func registerBootstrapTransports(m *manager.Manager, specs []transportSpec, baseCfg transport.TransportConfig, secret, ctx string, rooms map[string]roomLister) error {
|
|
isExit := m.Session().IsExit()
|
|
for _, spec := range specs {
|
|
raw, err := makeRawTransport(spec, baseCfg, isExit)
|
|
if err != nil {
|
|
return fmt.Errorf("%s: %w", spec.Name, err)
|
|
}
|
|
if r, ok := raw.(roomLister); ok {
|
|
rooms[spec.Name] = r
|
|
}
|
|
var provider manager.CookieProvider
|
|
if p, ok := raw.(manager.CookieProvider); ok {
|
|
provider = p
|
|
}
|
|
|
|
// Session-side: wrap with Encrypted+Batched and register for handshake.
|
|
if err := m.Session().AddTransport(spec.Name, raw, secret, ctx, spec.Priority); err != nil {
|
|
return fmt.Errorf("session add %s: %w", spec.Name, err)
|
|
}
|
|
// Manager-side: keep the raw pointer and its cookie provider.
|
|
if err := m.Add(spec.Name, spec.Type, raw, spec.Priority, provider); err != nil {
|
|
return fmt.Errorf("manager add %s: %w", spec.Name, err)
|
|
}
|
|
if spec.URL != transport.ContextPlaceholder {
|
|
m.SetURL(spec.Name, spec.URL)
|
|
}
|
|
}
|
|
return nil
|
|
}
|