mirror of
https://github.com/XTLS/Xray-core.git
synced 2026-09-29 20:46:59 +00:00
XTLS Vision: Suppress outer CloseNotify after switching to direct copy (#6834)
https://github.com/XTLS/Xray-core/pull/6816#issuecomment-5828082031 https://github.com/XTLS/Xray-core/issues/6794#issuecomment-5847200576 https://github.com/XTLS/Xray-core/pull/6834#issuecomment-5860728689 Fixes https://github.com/XTLS/Xray-core/issues/6794#issuecomment-5754894283 Fixes https://github.com/XTLS/Xray-core/issues/6124#issuecomment-4439918073 Fixes https://github.com/XTLS/Xray-core/issues/4878#issuecomment-5754638401 --------- Co-authored-by: Artem Lytkin <146867384+4RH1T3CT0R7@users.noreply.github.com>
This commit is contained in:
@@ -277,6 +277,7 @@ func (w *VisionReader) ReadMultiBuffer() (buf.MultiBuffer, error) {
|
||||
w.ob.CanSpliceCopy = 1
|
||||
}
|
||||
}
|
||||
SuppressOuterCloseNotify(w.conn)
|
||||
readerConn, readCounter, _ := UnwrapRawConn(w.conn)
|
||||
w.directReadCounter = readCounter
|
||||
w.Reader = buf.NewReader(readerConn)
|
||||
@@ -340,6 +341,7 @@ func (w *VisionWriter) WriteMultiBuffer(mb buf.MultiBuffer) error {
|
||||
// w.ob.CanSpliceCopy = 1
|
||||
// }
|
||||
}
|
||||
SuppressOuterCloseNotify(w.conn)
|
||||
rawConn, _, writerCounter := UnwrapRawConn(w.conn)
|
||||
w.Writer = buf.NewWriter(rawConn)
|
||||
w.directWriteCounter = writerCounter
|
||||
@@ -669,6 +671,19 @@ func XtlsFilterTls(buffer buf.MultiBuffer, trafficState *TrafficState, ctx conte
|
||||
}
|
||||
}
|
||||
|
||||
type CloseNotifySuppressor interface {
|
||||
SuppressCloseNotify()
|
||||
}
|
||||
|
||||
// Close our local TLS conn instance might send a incorrect close_notify alert
|
||||
// if the XTLS direct copy mode is enabled and cause TLS BAD_RECORD_MAC on users' browser
|
||||
// Close the underlying connection directly to avoid this issue.
|
||||
func SuppressOuterCloseNotify(conn net.Conn) {
|
||||
if suppressor, ok := stat.TryUnwrapStatsConn(conn).(CloseNotifySuppressor); ok {
|
||||
suppressor.SuppressCloseNotify()
|
||||
}
|
||||
}
|
||||
|
||||
// UnwrapRawConn support unwrap encryption, stats, mask wrappers, tls, utls, reality, proxyproto, uds-wrapper conn and get raw tcp/uds conn from it
|
||||
func UnwrapRawConn(conn net.Conn) (net.Conn, stats.Counter, stats.Counter) {
|
||||
var readCounter, writerCounter stats.Counter
|
||||
|
||||
Reference in New Issue
Block a user