TUN inbound: Error out when autoSystemWfpBlockLeak or autoSystemDnsToGateway cannot apply

As asked in review, rather than run without them:

- The config is rejected, also by xray -test, for autoSystemWfpBlockLeak
  without autoSystemRoutingTable, or with "dns" but without dns, on
  Windows, and for autoSystemDnsToGateway without gateway on Linux.
- Xray does not start when the filters cannot be added, now on every
  Windows version, or when the system DNS cannot be set on Linux,
  instead of logging it and running without them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
patterniha
2026-09-30 08:46:45 +03:30
co-authored by Claude Opus 5.5
parent 94cd83ccb4
commit 747b153333
6 changed files with 82 additions and 45 deletions
+2 -2
View File
@@ -188,8 +188,8 @@ var verifyDNSRouting = func(ctx context.Context, inboundTag, source, address str
//
// It acts only when the config opts in, and it verifies the data path first:
// unless a query to the advertised address would actually be handled, host-wide
// resolution is left to the OS, which is the documented default. Errors are
// returned to the caller, which treats them as non-fatal.
// resolution is left to the OS and an error returned. The caller does not start
// the TUN on an error, as the system DNS would bypass it.
func (t *LinuxTun) ConfigureSystemDNS(ctx context.Context, inboundTag string) error {
if !t.options.AutoSystemDnsToGateway {
return nil