Compare commits

..

117 Commits

Author SHA1 Message Date
renovate[bot]
1c62f8742e
[dependencies] Update golangci/golangci-lint-action action to v8 2025-07-03 14:22:41 +00:00
世界
989034b8f7
documentation: Bump version 2025-07-03 22:20:37 +08:00
世界
fef0a17bf8
release: Fix publish testflight 2025-07-03 21:49:38 +08:00
世界
c54f87e722
Improve darwin tun performance 2025-07-03 21:49:38 +08:00
世界
9bd9e5ab83
Improve nftables rules for openwrt 2025-07-03 21:49:37 +08:00
世界
7eb72226ab
Fixed DoH server recover from conn freezes 2025-07-03 21:49:37 +08:00
世界
1b08cdeb0a
Update libresolv usage 2025-07-03 21:49:37 +08:00
yu
88f989b934
documentation: Update client configuration manual 2025-07-03 21:49:36 +08:00
yanwo
65af6c7cdf
documentation: Fix typo
Signed-off-by: yanwo <ogilvy@gmail.com>
2025-07-03 21:49:36 +08:00
anytinz
7935126887
documentation: Fix wrong SideStore loopback ip 2025-07-03 21:49:36 +08:00
世界
1a78d3d28d
Revert "release: Add IPA build"
After testing, it seems that since extensions are not handled correctly, it cannot be installed by SideStore.
2025-07-03 21:49:36 +08:00
世界
0314c83afd
release: Add IPA build 2025-07-03 21:49:36 +08:00
世界
beb8741925
Add API to dump AdGuard rules 2025-07-03 21:49:35 +08:00
Sukka
74478e5f84
Improve AdGuard rule-set parser 2025-07-03 21:49:35 +08:00
Restia-Ashbell
82b9af7418
Add ECH support for uTLS 2025-07-03 21:49:35 +08:00
世界
3a5e6ee8fd
Improve TLS fragments 2025-07-03 21:49:34 +08:00
世界
cb20c6ec7f
Add cache support for ssm-api 2025-07-03 21:49:34 +08:00
世界
a5aef88073
Fix service will not be closed 2025-07-03 21:49:34 +08:00
世界
ab0af2960d
Add loopback address support for tun 2025-07-03 21:49:34 +08:00
世界
32a081d229
Fix tproxy listener 2025-07-03 21:49:33 +08:00
世界
6b7b1b2eac
Fix systemd package 2025-07-03 21:49:33 +08:00
世界
81364e3294
Fix missing home for derp service 2025-07-03 21:49:33 +08:00
Zero Clover
ee9474dd07
documentation: Fix services 2025-07-03 21:49:32 +08:00
世界
ec6b78d1b6
Fix dns.client_subnet ignored 2025-07-03 21:49:32 +08:00
世界
078fb5555d
documentation: Minor fixes 2025-07-03 21:49:32 +08:00
世界
99ea71119a
Fix tailscale forward 2025-07-03 21:49:31 +08:00
世界
d0ed53dae3
Minor fixes 2025-07-03 21:49:31 +08:00
世界
79deb889b1
Add SSM API service 2025-07-03 21:49:31 +08:00
世界
480d92901e
Add resolved service and DNS server 2025-07-03 21:49:30 +08:00
世界
3510a228e2
Add DERP service 2025-07-03 21:49:30 +08:00
世界
135e8e673f
Add service component type 2025-07-03 21:49:30 +08:00
世界
97fb38d8bf
Fix tproxy tcp control 2025-07-03 21:49:29 +08:00
愚者
f376bf834f
release: Fix build tags for android
Signed-off-by: 愚者 <11926619+FansChou@users.noreply.github.com>
2025-07-03 21:49:29 +08:00
世界
b9f53ec6cc
prevent creation of bind and mark controls on unsupported platforms 2025-07-03 21:49:29 +08:00
PuerNya
9208dd58c2
documentation: Fix description of reject DNS action behavior 2025-07-03 21:49:29 +08:00
Restia-Ashbell
c548a90f4a
Fix TLS record fragment 2025-07-03 21:49:28 +08:00
世界
e57e5f4415
Add missing accept_routes option for Tailscale 2025-07-03 21:49:28 +08:00
世界
63520226a0
Add TLS record fragment support 2025-07-03 21:49:28 +08:00
世界
02aeaca87a
Fix set edns0 client subnet 2025-07-03 21:49:27 +08:00
世界
c00373d930
Update minor dependencies 2025-07-03 21:49:27 +08:00
世界
db8ece9667
Update certmagic and providers 2025-07-03 21:49:27 +08:00
世界
763ca0c3f8
Update protobuf and grpc 2025-07-03 21:49:27 +08:00
世界
d641c152a7
Add control options for listeners 2025-07-03 21:49:26 +08:00
世界
5ccb67f1a5
Update quic-go to v0.52.0 2025-07-03 21:49:26 +08:00
世界
b763a2f178
Update utls to v1.7.2 2025-07-03 21:49:26 +08:00
世界
81a14bb5f2
Handle EDNS version downgrade 2025-07-03 21:49:25 +08:00
世界
5dbc9d2fc5
documentation: Fix anytls padding scheme description 2025-07-03 21:49:25 +08:00
安容
a35c4a6a96
Report invalid DNS address early 2025-07-03 21:49:25 +08:00
世界
ea2d355907
Fix wireguard listen_port 2025-07-03 21:49:24 +08:00
世界
ee58016702
clash-api: Add more meta api 2025-07-03 21:49:24 +08:00
世界
b1dc45898b
Fix DNS lookup 2025-07-03 21:49:24 +08:00
世界
f51c2a4e66
Fix fetch ECH configs 2025-07-03 21:49:24 +08:00
reletor
3cd42b6d37
documentation: Minor fixes 2025-07-03 21:49:23 +08:00
caelansar
9494f2ae21
Fix callback deletion in UDP transport 2025-07-03 21:49:23 +08:00
世界
23c24cace8
documentation: Try to make the play review happy 2025-07-03 21:49:23 +08:00
世界
e225a6476e
Fix missing handling of legacy domain_strategy options 2025-07-03 21:49:23 +08:00
世界
53ea9cb4c7
Improve local DNS server 2025-07-03 21:49:22 +08:00
anytls
7b5eef8ae2
Update anytls
Co-authored-by: anytls <anytls>
2025-07-03 21:49:22 +08:00
世界
ffa70c0288
Fix DNS dialer 2025-07-03 21:49:21 +08:00
世界
1cb605924a
release: Skip override version for iOS 2025-07-03 21:49:21 +08:00
iikira
90320bc80d
Fix UDP DNS server crash
Signed-off-by: iikira <i2@mail.iikira.com>
2025-07-03 21:49:21 +08:00
ReleTor
b4402e27d9
Fix fetch ECH configs 2025-07-03 21:49:20 +08:00
世界
14bcf34f86
Allow direct outbounds without domain_resolver 2025-07-03 21:49:20 +08:00
世界
e41cb6d559
Fix Tailscale dialer 2025-07-03 21:49:20 +08:00
dyhkwong
d90dec5381
Fix DNS over QUIC stream close 2025-07-03 21:49:20 +08:00
anytls
e09aa7ca84
Update anytls
Co-authored-by: anytls <anytls>
2025-07-03 21:49:20 +08:00
Rambling2076
832d37b808
Fix missing with_tailscale in Dockerfile
Signed-off-by: Rambling2076 <Rambling2076@proton.me>
2025-07-03 21:49:19 +08:00
世界
3a70ae7afe
Fail when default DNS server not found 2025-07-03 21:49:19 +08:00
世界
cf1058de4c
Update gVisor to 20250319.0 2025-07-03 21:49:19 +08:00
世界
73e6bbb49a
Explicitly reject detour to empty direct outbounds 2025-07-03 21:49:18 +08:00
世界
329d4bb4c9
Add netns support 2025-07-03 21:49:18 +08:00
世界
b43615ef35
Add wildcard name support for predefined records 2025-07-03 21:49:18 +08:00
世界
e7479dea90
Remove map usage in options 2025-07-03 21:49:17 +08:00
世界
f1f1406eb1
Fix unhandled DNS loop 2025-07-03 21:49:17 +08:00
世界
fe9cc7461b
Add wildcard-sni support for shadow-tls inbound 2025-07-03 21:49:17 +08:00
k9982874
710ca243aa
Add ntp protocol sniffing 2025-07-03 21:49:16 +08:00
世界
a249770e24
option: Fix marshal legacy DNS options 2025-07-03 21:49:16 +08:00
世界
6d2bd2116b
Make domain_resolver optional when only one DNS server is configured 2025-07-03 21:49:16 +08:00
世界
2e1698fa78
Fix DNS lookup context pollution 2025-07-03 21:49:16 +08:00
世界
6946ec37cf
Fix http3 DNS server connecting to wrong address 2025-07-03 21:49:15 +08:00
Restia-Ashbell
25f844ec6d
documentation: Fix typo 2025-07-03 21:49:15 +08:00
anytls
5a5c906fb2
Update sing-anytls
Co-authored-by: anytls <anytls>
2025-07-03 21:49:15 +08:00
k9982874
31c191debb
Fix hosts DNS server 2025-07-03 21:49:15 +08:00
世界
1b02fca33f
Fix UDP DNS server crash 2025-07-03 21:49:14 +08:00
世界
5308c46e07
documentation: Fix missing ip_accept_any DNS rule option 2025-07-03 21:49:14 +08:00
世界
0cfcaf2c62
Fix anytls dialer usage 2025-07-03 21:49:14 +08:00
世界
a2bd384c32
Move predefined DNS server to rule action 2025-07-03 21:49:13 +08:00
世界
3723dd2583
Fix domain resolver on direct outbound 2025-07-03 21:49:13 +08:00
Zephyruso
9bbc3dabc8
Fix missing AnyTLS display name 2025-07-03 21:49:13 +08:00
anytls
6827d67a09
Update sing-anytls
Co-authored-by: anytls <anytls>
2025-07-03 21:49:13 +08:00
Estel
5ae3e97388
documentation: Fix typo
Signed-off-by: Estel <callmebedrockdigger@gmail.com>
2025-07-03 21:49:13 +08:00
TargetLocked
f6d1099b69
Fix parsing legacy DNS options 2025-07-03 21:49:12 +08:00
世界
ca1b5bbcdf
Fix DNS fallback 2025-07-03 21:49:12 +08:00
世界
1c6c48ea8d
documentation: Fix missing hosts DNS server 2025-07-03 21:49:11 +08:00
anytls
0d86d225a3
Add MinIdleSession option to AnyTLS outbound
Co-authored-by: anytls <anytls>
2025-07-03 21:49:11 +08:00
ReleTor
b75e6b88b7
documentation: Minor fixes 2025-07-03 21:49:11 +08:00
libtry486
000f7b1045
documentation: Fix typo
fix typo

Signed-off-by: libtry486 <89328481+libtry486@users.noreply.github.com>
2025-07-03 21:49:11 +08:00
Alireza Ahmadi
b39204f4aa
Fix Outbound deadlock 2025-07-03 21:49:10 +08:00
世界
2b2655ffc7
documentation: Fix AnyTLS doc 2025-07-03 21:49:10 +08:00
anytls
3f9f41caed
Add AnyTLS protocol 2025-07-03 21:49:10 +08:00
世界
0231e3c575
Migrate to stdlib ECH support 2025-07-03 21:49:09 +08:00
世界
918b70b1cc
Add fallback local DNS server for iOS 2025-07-03 21:49:09 +08:00
世界
af4c4d1841
Get darwin local DNS server from libresolv 2025-07-03 21:49:09 +08:00
世界
88e830b5d8
Improve resolve action 2025-07-03 21:49:08 +08:00
世界
7eb14cfe9f
Add back port hopping to hysteria 1 2025-07-03 21:49:08 +08:00
xchacha20-poly1305
e6761fa538
Remove single quotes of raw Moziila certs 2025-07-03 21:49:08 +08:00
世界
485d28ceec
Add Tailscale endpoint 2025-07-03 21:49:07 +08:00
世界
159a2858e2
Build legacy binaries with latest Go 2025-07-03 21:49:07 +08:00
世界
b6691707e9
documentation: Remove outdated icons 2025-07-03 21:49:07 +08:00
世界
38f1736f78
documentation: Certificate store 2025-07-03 21:49:06 +08:00
世界
ff77bf63f5
documentation: TLS fragment 2025-07-03 21:49:06 +08:00
世界
9dad482e70
documentation: Outbound domain resolver 2025-07-03 21:49:06 +08:00
世界
d43791307c
documentation: Refactor DNS 2025-07-03 21:49:05 +08:00
世界
0a82b8a9ad
Add certificate store 2025-07-03 21:49:05 +08:00
世界
7bf91fb2af
Add TLS fragment support 2025-07-03 21:49:05 +08:00
世界
81d2eb5f3f
refactor: Outbound domain resolver 2025-07-03 21:49:05 +08:00
世界
ee731a32c8
refactor: DNS 2025-07-03 21:49:04 +08:00
14 changed files with 48 additions and 70 deletions

View File

@ -16,7 +16,7 @@ release/config/sing-box.service=/usr/lib/systemd/system/sing-box.service
release/config/sing-box@.service=/usr/lib/systemd/system/sing-box@.service
release/config/sing-box.sysusers=/usr/lib/sysusers.d/sing-box.conf
release/config/sing-box.rules=usr/share/polkit-1/rules.d/sing-box.rules
release/config/sing-box-dbus.xml=/usr/share/dbus-1/system.d/sing-box-dbus.conf
release/config/sing-box-split-dns.xml=/usr/share/dbus-1/system.d/sing-box-split-dns.conf
release/completions/sing-box.bash=/usr/share/bash-completion/completions/sing-box.bash
release/completions/sing-box.fish=/usr/share/fish/vendor_completions.d/sing-box.fish

View File

@ -59,8 +59,8 @@ nfpms:
dst: /usr/lib/sysusers.d/sing-box.conf
- src: release/config/sing-box.rules
dst: /usr/share/polkit-1/rules.d/sing-box.rules
- src: release/config/sing-box-dbus.xml
dst: /usr/share/dbus-1/system.d/sing-box-dbus.conf
- src: release/config/sing-box-split-dns.xml
dst: /usr/share/dbus-1/system.d/sing-box-split-dns.conf
- src: release/completions/sing-box.bash
dst: /usr/share/bash-completion/completions/sing-box.bash

View File

@ -140,8 +140,8 @@ nfpms:
dst: /usr/lib/sysusers.d/sing-box.conf
- src: release/config/sing-box.rules
dst: /usr/share/polkit-1/rules.d/sing-box.rules
- src: release/config/sing-box-dbus.xml
dst: /usr/share/dbus-1/system.d/sing-box-dbus.conf
- src: release/config/sing-box-split-dns.xml
dst: /usr/share/dbus-1/system.d/sing-box-split-dns.conf
- src: release/completions/sing-box.bash
dst: /usr/share/bash-completion/completions/sing-box.bash

@ -1 +1 @@
Subproject commit 7f1fa971e3c7bbc504c2bd455f4e813a562990cb
Subproject commit eb2e13a6f9a8c03a35ae672395ccab0a6bdcd954

@ -1 +1 @@
Subproject commit f7883b0f3ec26c449cba26b3b1a692f070f5424d
Subproject commit ae5818ee5a24af965dc91f80bffa16e1e6c109c1

View File

@ -195,13 +195,8 @@ func (c *Client) Exchange(ctx context.Context, transport adapter.DNSTransport, m
}
}*/
if responseChecker != nil {
var rejected bool
if !(response.Rcode == dns.RcodeSuccess || response.Rcode == dns.RcodeNameError) {
rejected = true
} else {
rejected = !responseChecker(MessageToAddresses(response))
}
if rejected {
addr, addrErr := MessageToAddresses(response)
if addrErr != nil || !responseChecker(addr) {
if c.rdrc != nil {
c.rdrc.SaveRDRCAsync(transport.Tag(), question.Name, question.Qtype, c.logger)
}
@ -425,10 +420,7 @@ func (c *Client) lookupToExchange(ctx context.Context, transport adapter.DNSTran
if err != nil {
return nil, err
}
if response.Rcode != dns.RcodeSuccess {
return nil, RcodeError(response.Rcode)
}
return MessageToAddresses(response), nil
return MessageToAddresses(response)
}
func (c *Client) questionCache(question dns.Question, transport adapter.DNSTransport) ([]netip.Addr, error) {
@ -436,10 +428,7 @@ func (c *Client) questionCache(question dns.Question, transport adapter.DNSTrans
if response == nil {
return nil, ErrNotCached
}
if response.Rcode != dns.RcodeSuccess {
return nil, RcodeError(response.Rcode)
}
return MessageToAddresses(response), nil
return MessageToAddresses(response)
}
func (c *Client) loadResponse(question dns.Question, transport adapter.DNSTransport) (*dns.Msg, int) {
@ -516,7 +505,10 @@ func (c *Client) loadResponse(question dns.Question, transport adapter.DNSTransp
}
}
func MessageToAddresses(response *dns.Msg) []netip.Addr {
func MessageToAddresses(response *dns.Msg) ([]netip.Addr, error) {
if response.Rcode != dns.RcodeSuccess {
return nil, RcodeError(response.Rcode)
}
addresses := make([]netip.Addr, 0, len(response.Answer))
for _, rawAnswer := range response.Answer {
switch answer := rawAnswer.(type) {
@ -532,7 +524,7 @@ func MessageToAddresses(response *dns.Msg) []netip.Addr {
}
}
}
return addresses
return addresses, nil
}
func wrapError(err error) error {

View File

@ -3,6 +3,7 @@ package local
import (
"context"
"math/rand"
"net/netip"
"time"
"github.com/sagernet/sing-box/adapter"
@ -90,9 +91,9 @@ func (t *Transport) exchangeParallel(ctx context.Context, systemConfig *dnsConfi
startRacer := func(ctx context.Context, fqdn string) {
response, err := t.tryOneName(ctx, systemConfig, fqdn, message)
if err == nil {
if response.Rcode != mDNS.RcodeSuccess {
err = dns.RcodeError(response.Rcode)
} else if len(dns.MessageToAddresses(response)) == 0 {
var addresses []netip.Addr
addresses, err = dns.MessageToAddresses(response)
if err == nil && len(addresses) == 0 {
err = E.New(fqdn, ": empty result")
}
}

View File

@ -2,19 +2,7 @@
icon: material/alert-decagram
---
#### 1.12.0-beta.33
* Add firewalld compatibility for auto redirect
* Fixes and improvements
### 1.11.15
* Fixes and improvements
_We are temporarily unable to update sing-box apps on the App Store because the reviewer mistakenly found that we
violated the rules (TestFlight users are not affected)._
#### 1.12.0-beta.32
#### 1.12.0-beta.31
* Improve tun performance on Apple platforms **1**
* Fixes and improvements

16
go.mod
View File

@ -28,13 +28,13 @@ require (
github.com/sagernet/gomobile v0.1.7
github.com/sagernet/gvisor v0.0.0-20250325023245-7a9c0f5725fb
github.com/sagernet/quic-go v0.52.0-beta.1
github.com/sagernet/sing v0.6.12-0.20250704043954-da981379f151
github.com/sagernet/sing v0.6.12-0.20250703120903-7081a0c40539
github.com/sagernet/sing-mux v0.3.2
github.com/sagernet/sing-quic v0.5.0-beta.2
github.com/sagernet/sing-shadowsocks v0.2.8
github.com/sagernet/sing-shadowsocks2 v0.2.1
github.com/sagernet/sing-shadowtls v0.2.1-0.20250503051639-fcd445d33c11
github.com/sagernet/sing-tun v0.6.10-0.20250707094843-b2e2674d73e5
github.com/sagernet/sing-tun v0.6.10-0.20250703121732-a0881ada3251
github.com/sagernet/sing-vmess v0.2.4-0.20250605032146-38cc72672c88
github.com/sagernet/smux v1.5.34-mod.2
github.com/sagernet/tailscale v1.80.3-mod.5
@ -45,10 +45,10 @@ require (
github.com/vishvananda/netns v0.0.5
go.uber.org/zap v1.27.0
go4.org/netipx v0.0.0-20231129151722-fdeea329fbba
golang.org/x/crypto v0.39.0
golang.org/x/crypto v0.38.0
golang.org/x/exp v0.0.0-20250506013437-ce4c2cf36ca6
golang.org/x/mod v0.25.0
golang.org/x/net v0.41.0
golang.org/x/mod v0.24.0
golang.org/x/net v0.40.0
golang.org/x/sys v0.33.0
golang.zx2c4.com/wireguard/wgctrl v0.0.0-20241231184526-a9ab2273dd10
google.golang.org/grpc v1.72.0
@ -107,7 +107,7 @@ require (
github.com/quic-go/qpack v0.5.1 // indirect
github.com/safchain/ethtool v0.3.0 // indirect
github.com/sagernet/netlink v0.0.0-20240612041022-b9a21c07ac6a // indirect
github.com/sagernet/nftables v0.3.0-mod.1 // indirect
github.com/sagernet/nftables v0.3.0-beta.4 // indirect
github.com/spf13/pflag v1.0.6 // indirect
github.com/tailscale/certstore v0.1.1-0.20231202035212-d3fa0460f47e // indirect
github.com/tailscale/go-winio v0.0.0-20231025203758-c4f33415bf55 // indirect
@ -123,9 +123,9 @@ require (
go.uber.org/multierr v1.11.0 // indirect
go.uber.org/zap/exp v0.3.0 // indirect
go4.org/mem v0.0.0-20240501181205-ae6ca9944745 // indirect
golang.org/x/sync v0.15.0 // indirect
golang.org/x/sync v0.14.0 // indirect
golang.org/x/term v0.32.0 // indirect
golang.org/x/text v0.26.0 // indirect
golang.org/x/text v0.25.0 // indirect
golang.org/x/time v0.9.0 // indirect
golang.org/x/tools v0.33.0 // indirect
golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 // indirect

32
go.sum
View File

@ -163,13 +163,13 @@ github.com/sagernet/gvisor v0.0.0-20250325023245-7a9c0f5725fb h1:pprQtDqNgqXkRsX
github.com/sagernet/gvisor v0.0.0-20250325023245-7a9c0f5725fb/go.mod h1:QkkPEJLw59/tfxgapHta14UL5qMUah5NXhO0Kw2Kan4=
github.com/sagernet/netlink v0.0.0-20240612041022-b9a21c07ac6a h1:ObwtHN2VpqE0ZNjr6sGeT00J8uU7JF4cNUdb44/Duis=
github.com/sagernet/netlink v0.0.0-20240612041022-b9a21c07ac6a/go.mod h1:xLnfdiJbSp8rNqYEdIW/6eDO4mVoogml14Bh2hSiFpM=
github.com/sagernet/nftables v0.3.0-mod.1 h1:OMe+qoEAx8EipYAQbD2FI5erVvKmTS9+cYhdpg+vezY=
github.com/sagernet/nftables v0.3.0-mod.1/go.mod h1:8kslHG4VvYNihcco+i6uxIX7qbT8A56T0y5q7U44ZaQ=
github.com/sagernet/nftables v0.3.0-beta.4 h1:kbULlAwAC3jvdGAC1P5Fa3GSxVwQJibNenDW2zaXr8I=
github.com/sagernet/nftables v0.3.0-beta.4/go.mod h1:OQXAjvjNGGFxaTgVCSTRIhYB5/llyVDeapVoENYBDS8=
github.com/sagernet/quic-go v0.52.0-beta.1 h1:hWkojLg64zjV+MJOvJU/kOeWndm3tiEfBLx5foisszs=
github.com/sagernet/quic-go v0.52.0-beta.1/go.mod h1:OV+V5kEBb8kJS7k29MzDu6oj9GyMc7HA07sE1tedxz4=
github.com/sagernet/sing v0.6.9/go.mod h1:ARkL0gM13/Iv5VCZmci/NuoOlePoIsW0m7BWfln/Hak=
github.com/sagernet/sing v0.6.12-0.20250704043954-da981379f151 h1:UCiQ1d/t5Y9uKAL9ir3i06+ClqS93OGGG8oqB82RMCE=
github.com/sagernet/sing v0.6.12-0.20250704043954-da981379f151/go.mod h1:ARkL0gM13/Iv5VCZmci/NuoOlePoIsW0m7BWfln/Hak=
github.com/sagernet/sing v0.6.12-0.20250703120903-7081a0c40539 h1:SK4M4FCNdwV4EiYKIUZ9qM4lr/1NQogJe1YoyYw5DV8=
github.com/sagernet/sing v0.6.12-0.20250703120903-7081a0c40539/go.mod h1:ARkL0gM13/Iv5VCZmci/NuoOlePoIsW0m7BWfln/Hak=
github.com/sagernet/sing-mux v0.3.2 h1:meZVFiiStvHThb/trcpAkCrmtJOuItG5Dzl1RRP5/NE=
github.com/sagernet/sing-mux v0.3.2/go.mod h1:pht8iFY4c9Xltj7rhVd208npkNaeCxzyXCgulDPLUDA=
github.com/sagernet/sing-quic v0.5.0-beta.2 h1:j7KAbBuGmsKwSxVAQL5soJ+wDqxim4/llK2kxB0hSKk=
@ -180,8 +180,8 @@ github.com/sagernet/sing-shadowsocks2 v0.2.1 h1:dWV9OXCeFPuYGHb6IRqlSptVnSzOelnq
github.com/sagernet/sing-shadowsocks2 v0.2.1/go.mod h1:RnXS0lExcDAovvDeniJ4IKa2IuChrdipolPYWBv9hWQ=
github.com/sagernet/sing-shadowtls v0.2.1-0.20250503051639-fcd445d33c11 h1:tK+75l64tm9WvEFrYRE1t0YxoFdWQqw/h7Uhzj0vJ+w=
github.com/sagernet/sing-shadowtls v0.2.1-0.20250503051639-fcd445d33c11/go.mod h1:sWqKnGlMipCHaGsw1sTTlimyUpgzP4WP3pjhCsYt9oA=
github.com/sagernet/sing-tun v0.6.10-0.20250707094843-b2e2674d73e5 h1:JHa9vyTie1FbWGofPt4TEpysl7tBeEoiQDtwVK0Scqg=
github.com/sagernet/sing-tun v0.6.10-0.20250707094843-b2e2674d73e5/go.mod h1:c/7Blmaw8GRL4JPvoajBfwUfdzoa2KCMtAnq5Q9AjA0=
github.com/sagernet/sing-tun v0.6.10-0.20250703121732-a0881ada3251 h1:eH9naJXvyF/DZDk0V1SYkL6ypYD+A1tUFWLcT7PRezg=
github.com/sagernet/sing-tun v0.6.10-0.20250703121732-a0881ada3251/go.mod h1:fisFCbC4Vfb6HqQNcwPJi2CDK2bf0Xapyz3j3t4cnHE=
github.com/sagernet/sing-vmess v0.2.4-0.20250605032146-38cc72672c88 h1:0pVm8sPOel+BoiCddW3pV3cKDKEaSioVTYDdTSKjyFI=
github.com/sagernet/sing-vmess v0.2.4-0.20250605032146-38cc72672c88/go.mod h1:IL8Rr+EGwuqijszZkNrEFTQDKhilEpkqFqOlvdpS6/w=
github.com/sagernet/smux v1.5.34-mod.2 h1:gkmBjIjlJ2zQKpLigOkFur5kBKdV6bNRoFu2WkltRQ4=
@ -263,21 +263,21 @@ go4.org/mem v0.0.0-20240501181205-ae6ca9944745/go.mod h1:reUoABIJ9ikfM5sgtSF3Wus
go4.org/netipx v0.0.0-20231129151722-fdeea329fbba h1:0b9z3AuHCjxk0x/opv64kcgZLBseWJUpBw5I82+2U4M=
go4.org/netipx v0.0.0-20231129151722-fdeea329fbba/go.mod h1:PLyyIXexvUFg3Owu6p/WfdlivPbZJsZdgWZlrGope/Y=
golang.org/x/crypto v0.0.0-20210513164829-c07d793c2f9a/go.mod h1:P+XmwS30IXTQdn5tA2iutPOUgjI07+tq3H3K9MVA1s8=
golang.org/x/crypto v0.39.0 h1:SHs+kF4LP+f+p14esP5jAoDpHU8Gu/v9lFRK6IT5imM=
golang.org/x/crypto v0.39.0/go.mod h1:L+Xg3Wf6HoL4Bn4238Z6ft6KfEpN0tJGo53AAPC632U=
golang.org/x/crypto v0.38.0 h1:jt+WWG8IZlBnVbomuhg2Mdq0+BBQaHbtqHEFEigjUV8=
golang.org/x/crypto v0.38.0/go.mod h1:MvrbAqul58NNYPKnOra203SB9vpuZW0e+RRZV+Ggqjw=
golang.org/x/exp v0.0.0-20250506013437-ce4c2cf36ca6 h1:y5zboxd6LQAqYIhHnB48p0ByQ/GnQx2BE33L8BOHQkI=
golang.org/x/exp v0.0.0-20250506013437-ce4c2cf36ca6/go.mod h1:U6Lno4MTRCDY+Ba7aCcauB9T60gsv5s4ralQzP72ZoQ=
golang.org/x/image v0.23.0 h1:HseQ7c2OpPKTPVzNjG5fwJsOTCiiwS4QdsYi5XU6H68=
golang.org/x/image v0.23.0/go.mod h1:wJJBTdLfCCf3tiHa1fNxpZmUI4mmoZvwMCPP0ddoNKY=
golang.org/x/mod v0.25.0 h1:n7a+ZbQKQA/Ysbyb0/6IbB1H/X41mKgbhfv7AfG/44w=
golang.org/x/mod v0.25.0/go.mod h1:IXM97Txy2VM4PJ3gI61r1YEk/gAj6zAHN3AdZt6S9Ww=
golang.org/x/mod v0.24.0 h1:ZfthKaKaT4NrhGVZHO1/WDTwGES4De8KtWO0SIbNJMU=
golang.org/x/mod v0.24.0/go.mod h1:IXM97Txy2VM4PJ3gI61r1YEk/gAj6zAHN3AdZt6S9Ww=
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
golang.org/x/net v0.0.0-20210525063256-abc453219eb5/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
golang.org/x/net v0.41.0 h1:vBTly1HeNPEn3wtREYfy4GZ/NECgw2Cnl+nK6Nz3uvw=
golang.org/x/net v0.41.0/go.mod h1:B/K4NNqkfmg07DQYrbwvSluqCJOOXwUjeb/5lOisjbA=
golang.org/x/net v0.40.0 h1:79Xs7wF06Gbdcg4kdCCIQArK11Z1hr5POQ6+fIYHNuY=
golang.org/x/net v0.40.0/go.mod h1:y0hY0exeL2Pku80/zKK7tpntoX23cqL3Oa6njdgRtds=
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.15.0 h1:KWH3jNZsfyT6xfAfKiz6MRNmd46ByHDYaZ7KSkCtdW8=
golang.org/x/sync v0.15.0/go.mod h1:1dzgHSNfp02xaA81J2MS99Qcpr2w7fw1gpm99rleRqA=
golang.org/x/sync v0.14.0 h1:woo0S4Yywslg6hp4eUFjTVOyKt0RookbpAHG4c1HmhQ=
golang.org/x/sync v0.14.0/go.mod h1:1dzgHSNfp02xaA81J2MS99Qcpr2w7fw1gpm99rleRqA=
golang.org/x/sys v0.0.0-20200217220822-9197077df867/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200728102440-3e129f6d46b1/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
@ -293,8 +293,8 @@ golang.org/x/term v0.32.0 h1:DR4lr0TjUs3epypdhTOkMmuF5CDFJ/8pOnbzMZPQ7bg=
golang.org/x/term v0.32.0/go.mod h1:uZG1FhGx848Sqfsq4/DlJr3xGGsYMu/L5GW4abiaEPQ=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.26.0 h1:P42AVeLghgTYr4+xUnTRKDMqpar+PtX7KWuNQL21L8M=
golang.org/x/text v0.26.0/go.mod h1:QK15LZJUUQVJxhz7wXgxSy/CJaTFjd0G+YLonydOVQA=
golang.org/x/text v0.25.0 h1:qVyWApTSYLk/drJRO5mDlNYskwQznZmkpV2c8q9zls4=
golang.org/x/text v0.25.0/go.mod h1:WEdwpYrmk1qmdHvhkSTNPm3app7v4rsT8F2UD6+VHIA=
golang.org/x/time v0.9.0 h1:EsRrnYcQiGH+5FfbgvV4AP7qEZstoyrHB0DzarOQ4ZY=
golang.org/x/time v0.9.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=

View File

@ -134,8 +134,7 @@ func NewInbound(ctx context.Context, router adapter.Router, logger log.ContextLo
tunMTU := options.MTU
if tunMTU == 0 {
if platformInterface != nil && platformInterface.UnderNetworkExtension() {
// In Network Extension, when MTU exceeds 4064 (4096-UTUN_IF_HEADROOM_SIZE), the performance of tun will drop significantly, which may be a system bug.
tunMTU = 4064
tunMTU = 4000
} else {
tunMTU = 9000
}

View File

@ -1,9 +1,7 @@
polkit.addRule(function(action, subject) {
if ((action.id == "org.freedesktop.resolve1.set-domains" ||
action.id == "org.freedesktop.resolve1.set-default-route" ||
action.id == "org.freedesktop.resolve1.set-dns-servers" ||
action.id == "org.fedoraproject.FirewallD1.all" ||
action.id == "org.fedoraproject.FirewallD1.config") &&
action.id == "org.freedesktop.resolve1.set-dns-servers") &&
subject.user == "sing-box") {
return polkit.Result.YES;
}

View File

@ -277,7 +277,7 @@ func (m *ConnectionManager) connectionCopy(ctx context.Context, source net.Conn,
return
}
}
_, err := bufio.CopyWithCounters(destinationWriter, sourceReader, source, readCounters, writeCounters, bufio.DefaultIncreaseBufferAfter)
_, err := bufio.CopyWithCounters(destinationWriter, sourceReader, source, readCounters, writeCounters)
if err != nil {
common.Close(source, destination)
} else if duplexDst, isDuplex := destination.(N.WriteCloser); isDuplex {