mirror of
https://github.com/XTLS/Xray-core.git
synced 2026-09-30 13:05:43 +00:00
TUN inbound: Block DNS and IPv6 leaks outside the TUN on Windows; Add strictRoute
Windows sends name queries to the DNS servers of all interfaces, and a resolver on the local network (e.g. 192.168.1.1 from DHCP) is reached through its more specific LAN route instead of the TUN, so DNS leaks past it. IPv6 bypasses a TUN that cannot carry it. With autoSystemRoutingTable set, the Windows TUN now adds Windows Filtering Platform filters, all in one transaction and in a dynamic session, so that they are removed when Xray exits, even if it crashes: - DNS (port 53) only goes through the TUN, in both directions: its local address, and the interface it leaves or arrives by, must be the TUN's. - IPv6 is blocked in both directions when the TUN has no IPv6 address or no IPv6 route, except loopback, neighbor and multicast listener discovery, and DHCPv6. - Xray's own traffic is exempt: its connections out with a hard permit, which Windows Firewall rules do not override (like sing-box's strict_route), connections to its inbounds with an ordinary one. If the filters cannot be added, the TUN does not start on Windows 10 and later (only a warning on 7/8). The new `strictRoute` option (true by default) turns them off. Also on Windows: - A warning for `dns` servers outside gateway and autoSystemRoutingTable, as queries to them cannot go through the TUN and are blocked. - While DNS is restricted and autoOutboundsInterface is in use, Xray resolves the names it would ask Windows for itself (Go's resolver on its own sockets). Those lookups and the `localhost` DNS server skip the TUN's DNS servers, unless another interface uses them too, instead of looping back into the TUN. - The DNS cache is flushed when the TUN starts and stops, and DNS registration is turned off on the TUN (through netsh before Windows 10 1809). - Close no longer panics when registering the route or interface change callbacks failed. The README's Windows section describes all of it. Tested on Windows 11, elevated, amd64 and 386: the filters, DNS arriving through a real Wintun adapter and blocked outside it, the IPv6 block, Windows Firewall rules, and a real Xray run. Windows 7/8 and Windows 10 before 1809 are untested. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
7780db9bbe
commit
2db099b34b
@@ -97,6 +97,9 @@ func New() *Client {
|
||||
r := &net.Resolver{
|
||||
PreferGo: true,
|
||||
Dial: func(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
if internet.IsSkippedDNSServer(address) {
|
||||
return nil, errors.New("skipped DNS server ", address)
|
||||
}
|
||||
return d.DialContext(ctx, network, address)
|
||||
},
|
||||
}
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
package localdns
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/netip"
|
||||
"testing"
|
||||
|
||||
"github.com/xtls/xray-core/transport/internet"
|
||||
)
|
||||
|
||||
func TestSkippedDNSServers(t *testing.T) {
|
||||
internet.SkipDNSServers([]netip.Addr{netip.MustParseAddr("203.0.113.53")})
|
||||
t.Cleanup(func() { internet.SkipDNSServers(nil) })
|
||||
c := New()
|
||||
if _, err := c.r.Dial(context.Background(), "udp", "203.0.113.53:53"); err == nil {
|
||||
t.Error("a skipped DNS server was dialed")
|
||||
}
|
||||
conn, err := c.r.Dial(context.Background(), "udp", "127.0.0.1:53")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
conn.Close()
|
||||
}
|
||||
Reference in New Issue
Block a user