mirror of
https://github.com/XTLS/Xray-core.git
synced 2026-09-30 21:16:03 +00:00
Windows sends name queries to the DNS servers of all interfaces, and a resolver on the local network (e.g. 192.168.1.1 from DHCP) is reached through its more specific LAN route instead of the TUN, so DNS leaks past it. IPv6 bypasses a TUN that cannot carry it. With autoSystemRoutingTable set, the Windows TUN now adds Windows Filtering Platform filters, all in one transaction and in a dynamic session, so that they are removed when Xray exits, even if it crashes: - DNS (port 53) only goes through the TUN, in both directions: its local address, and the interface it leaves or arrives by, must be the TUN's. - IPv6 is blocked in both directions when the TUN has no IPv6 address or no IPv6 route, except loopback, neighbor and multicast listener discovery, and DHCPv6. - Xray's own traffic is exempt: its connections out with a hard permit, which Windows Firewall rules do not override (like sing-box's strict_route), connections to its inbounds with an ordinary one. If the filters cannot be added, the TUN does not start on Windows 10 and later (only a warning on 7/8). The new `strictRoute` option (true by default) turns them off. Also on Windows: - A warning for `dns` servers outside gateway and autoSystemRoutingTable, as queries to them cannot go through the TUN and are blocked. - While DNS is restricted and autoOutboundsInterface is in use, Xray resolves the names it would ask Windows for itself (Go's resolver on its own sockets). Those lookups and the `localhost` DNS server skip the TUN's DNS servers, unless another interface uses them too, instead of looping back into the TUN. - The DNS cache is flushed when the TUN starts and stops, and DNS registration is turned off on the TUN (through netsh before Windows 10 1809). - Close no longer panics when registering the route or interface change callbacks failed. The README's Windows section describes all of it. Tested on Windows 11, elevated, amd64 and 386: the filters, DNS arriving through a real Wintun adapter and blocked outside it, the IPv6 block, Windows Firewall rules, and a real Xray run. Windows 7/8 and Windows 10 before 1809 are untested. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
210 lines
6.5 KiB
Go
210 lines
6.5 KiB
Go
// Code generated by protoc-gen-go. DO NOT EDIT.
|
|
// versions:
|
|
// protoc-gen-go v1.36.11
|
|
// protoc v6.33.5
|
|
// source: proxy/tun/config.proto
|
|
|
|
package tun
|
|
|
|
import (
|
|
reflect "reflect"
|
|
sync "sync"
|
|
unsafe "unsafe"
|
|
|
|
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
|
|
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
|
|
)
|
|
|
|
const (
|
|
// Verify that this generated code is sufficiently up-to-date.
|
|
_ = protoimpl.EnforceVersion(20 - protoimpl.MinVersion)
|
|
// Verify that runtime/protoimpl is sufficiently up-to-date.
|
|
_ = protoimpl.EnforceVersion(protoimpl.MaxVersion - 20)
|
|
)
|
|
|
|
type Config struct {
|
|
state protoimpl.MessageState `protogen:"open.v1"`
|
|
Name string `protobuf:"bytes,1,opt,name=name,proto3" json:"name,omitempty"`
|
|
MTU uint32 `protobuf:"varint,2,opt,name=MTU,proto3" json:"MTU,omitempty"`
|
|
Gateway []string `protobuf:"bytes,3,rep,name=gateway,proto3" json:"gateway,omitempty"`
|
|
DNS []string `protobuf:"bytes,4,rep,name=DNS,proto3" json:"DNS,omitempty"`
|
|
UserLevel uint32 `protobuf:"varint,5,opt,name=user_level,json=userLevel,proto3" json:"user_level,omitempty"`
|
|
AutoSystemRoutingTable []string `protobuf:"bytes,6,rep,name=auto_system_routing_table,json=autoSystemRoutingTable,proto3" json:"auto_system_routing_table,omitempty"`
|
|
AutoOutboundsInterface string `protobuf:"bytes,7,opt,name=auto_outbounds_interface,json=autoOutboundsInterface,proto3" json:"auto_outbounds_interface,omitempty"`
|
|
Desc string `protobuf:"bytes,8,opt,name=desc,proto3" json:"desc,omitempty"`
|
|
AutoSystemDns bool `protobuf:"varint,9,opt,name=auto_system_dns,json=autoSystemDns,proto3" json:"auto_system_dns,omitempty"`
|
|
StrictRoute *bool `protobuf:"varint,10,opt,name=strict_route,json=strictRoute,proto3,oneof" json:"strict_route,omitempty"`
|
|
unknownFields protoimpl.UnknownFields
|
|
sizeCache protoimpl.SizeCache
|
|
}
|
|
|
|
func (x *Config) Reset() {
|
|
*x = Config{}
|
|
mi := &file_proxy_tun_config_proto_msgTypes[0]
|
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
|
ms.StoreMessageInfo(mi)
|
|
}
|
|
|
|
func (x *Config) String() string {
|
|
return protoimpl.X.MessageStringOf(x)
|
|
}
|
|
|
|
func (*Config) ProtoMessage() {}
|
|
|
|
func (x *Config) ProtoReflect() protoreflect.Message {
|
|
mi := &file_proxy_tun_config_proto_msgTypes[0]
|
|
if x != nil {
|
|
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
|
if ms.LoadMessageInfo() == nil {
|
|
ms.StoreMessageInfo(mi)
|
|
}
|
|
return ms
|
|
}
|
|
return mi.MessageOf(x)
|
|
}
|
|
|
|
// Deprecated: Use Config.ProtoReflect.Descriptor instead.
|
|
func (*Config) Descriptor() ([]byte, []int) {
|
|
return file_proxy_tun_config_proto_rawDescGZIP(), []int{0}
|
|
}
|
|
|
|
func (x *Config) GetName() string {
|
|
if x != nil {
|
|
return x.Name
|
|
}
|
|
return ""
|
|
}
|
|
|
|
func (x *Config) GetMTU() uint32 {
|
|
if x != nil {
|
|
return x.MTU
|
|
}
|
|
return 0
|
|
}
|
|
|
|
func (x *Config) GetGateway() []string {
|
|
if x != nil {
|
|
return x.Gateway
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func (x *Config) GetDNS() []string {
|
|
if x != nil {
|
|
return x.DNS
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func (x *Config) GetUserLevel() uint32 {
|
|
if x != nil {
|
|
return x.UserLevel
|
|
}
|
|
return 0
|
|
}
|
|
|
|
func (x *Config) GetAutoSystemRoutingTable() []string {
|
|
if x != nil {
|
|
return x.AutoSystemRoutingTable
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func (x *Config) GetAutoOutboundsInterface() string {
|
|
if x != nil {
|
|
return x.AutoOutboundsInterface
|
|
}
|
|
return ""
|
|
}
|
|
|
|
func (x *Config) GetDesc() string {
|
|
if x != nil {
|
|
return x.Desc
|
|
}
|
|
return ""
|
|
}
|
|
|
|
func (x *Config) GetAutoSystemDns() bool {
|
|
if x != nil {
|
|
return x.AutoSystemDns
|
|
}
|
|
return false
|
|
}
|
|
|
|
func (x *Config) GetStrictRoute() bool {
|
|
if x != nil && x.StrictRoute != nil {
|
|
return *x.StrictRoute
|
|
}
|
|
return false
|
|
}
|
|
|
|
var File_proxy_tun_config_proto protoreflect.FileDescriptor
|
|
|
|
const file_proxy_tun_config_proto_rawDesc = "" +
|
|
"\n" +
|
|
"\x16proxy/tun/config.proto\x12\x0exray.proxy.tun\"\xe3\x02\n" +
|
|
"\x06Config\x12\x12\n" +
|
|
"\x04name\x18\x01 \x01(\tR\x04name\x12\x10\n" +
|
|
"\x03MTU\x18\x02 \x01(\rR\x03MTU\x12\x18\n" +
|
|
"\agateway\x18\x03 \x03(\tR\agateway\x12\x10\n" +
|
|
"\x03DNS\x18\x04 \x03(\tR\x03DNS\x12\x1d\n" +
|
|
"\n" +
|
|
"user_level\x18\x05 \x01(\rR\tuserLevel\x129\n" +
|
|
"\x19auto_system_routing_table\x18\x06 \x03(\tR\x16autoSystemRoutingTable\x128\n" +
|
|
"\x18auto_outbounds_interface\x18\a \x01(\tR\x16autoOutboundsInterface\x12\x12\n" +
|
|
"\x04desc\x18\b \x01(\tR\x04desc\x12&\n" +
|
|
"\x0fauto_system_dns\x18\t \x01(\bR\rautoSystemDns\x12&\n" +
|
|
"\fstrict_route\x18\n" +
|
|
" \x01(\bH\x00R\vstrictRoute\x88\x01\x01B\x0f\n" +
|
|
"\r_strict_routeBL\n" +
|
|
"\x12com.xray.proxy.tunP\x01Z#github.com/xtls/xray-core/proxy/tun\xaa\x02\x0eXray.Proxy.Tunb\x06proto3"
|
|
|
|
var (
|
|
file_proxy_tun_config_proto_rawDescOnce sync.Once
|
|
file_proxy_tun_config_proto_rawDescData []byte
|
|
)
|
|
|
|
func file_proxy_tun_config_proto_rawDescGZIP() []byte {
|
|
file_proxy_tun_config_proto_rawDescOnce.Do(func() {
|
|
file_proxy_tun_config_proto_rawDescData = protoimpl.X.CompressGZIP(unsafe.Slice(unsafe.StringData(file_proxy_tun_config_proto_rawDesc), len(file_proxy_tun_config_proto_rawDesc)))
|
|
})
|
|
return file_proxy_tun_config_proto_rawDescData
|
|
}
|
|
|
|
var file_proxy_tun_config_proto_msgTypes = make([]protoimpl.MessageInfo, 1)
|
|
var file_proxy_tun_config_proto_goTypes = []any{
|
|
(*Config)(nil), // 0: xray.proxy.tun.Config
|
|
}
|
|
var file_proxy_tun_config_proto_depIdxs = []int32{
|
|
0, // [0:0] is the sub-list for method output_type
|
|
0, // [0:0] is the sub-list for method input_type
|
|
0, // [0:0] is the sub-list for extension type_name
|
|
0, // [0:0] is the sub-list for extension extendee
|
|
0, // [0:0] is the sub-list for field type_name
|
|
}
|
|
|
|
func init() { file_proxy_tun_config_proto_init() }
|
|
func file_proxy_tun_config_proto_init() {
|
|
if File_proxy_tun_config_proto != nil {
|
|
return
|
|
}
|
|
file_proxy_tun_config_proto_msgTypes[0].OneofWrappers = []any{}
|
|
type x struct{}
|
|
out := protoimpl.TypeBuilder{
|
|
File: protoimpl.DescBuilder{
|
|
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
|
RawDescriptor: unsafe.Slice(unsafe.StringData(file_proxy_tun_config_proto_rawDesc), len(file_proxy_tun_config_proto_rawDesc)),
|
|
NumEnums: 0,
|
|
NumMessages: 1,
|
|
NumExtensions: 0,
|
|
NumServices: 0,
|
|
},
|
|
GoTypes: file_proxy_tun_config_proto_goTypes,
|
|
DependencyIndexes: file_proxy_tun_config_proto_depIdxs,
|
|
MessageInfos: file_proxy_tun_config_proto_msgTypes,
|
|
}.Build()
|
|
File_proxy_tun_config_proto = out.File
|
|
file_proxy_tun_config_proto_goTypes = nil
|
|
file_proxy_tun_config_proto_depIdxs = nil
|
|
}
|