diff --git a/infra/conf/shadowsocks.go b/infra/conf/shadowsocks.go index 18451ab..49fa7a2 100644 --- a/infra/conf/shadowsocks.go +++ b/infra/conf/shadowsocks.go @@ -3,17 +3,22 @@ package conf import ( "strings" - "github.com/sagernet/sing-shadowsocks/shadowaead_2022" - C "github.com/sagernet/sing/common" "github.com/xtls/xray-core/common/errors" "github.com/xtls/xray-core/common/protocol" "github.com/xtls/xray-core/common/serial" "github.com/xtls/xray-core/common/task" "github.com/xtls/xray-core/proxy/shadowsocks" - "github.com/xtls/xray-core/proxy/shadowsocks_2022" "google.golang.org/protobuf/proto" ) +// isShadowsocks2022Cipher reports whether the cipher names a Shadowsocks +// 2022 suite. This build strips SS2022 (its implementation pulls the +// GPL-3.0 sagernet/sing stack); the check keeps the error explicit +// instead of falling through to the legacy-cipher parser. +func isShadowsocks2022Cipher(c string) bool { + return strings.HasPrefix(strings.ToLower(c), "2022-blake3-") +} + func cipherFromString(c string) shadowsocks.CipherType { switch strings.ToLower(c) { case "aes-128-gcm", "aead_aes_128_gcm": @@ -55,8 +60,8 @@ func (v *ShadowsocksServerConfig) Build() (proto.Message, error) { v.Users = v.Clients } - if C.Contains(shadowaead_2022.List, v.Cipher) { - return buildShadowsocks2022(v) + if isShadowsocks2022Cipher(v.Cipher) { + return nil, errors.New("shadowsocks 2022 is not supported in this build") } config := new(shadowsocks.ServerConfig) @@ -110,72 +115,6 @@ func (v *ShadowsocksServerConfig) Build() (proto.Message, error) { return config, nil } -func buildShadowsocks2022(v *ShadowsocksServerConfig) (proto.Message, error) { - if len(v.Users) == 0 { - config := new(shadowsocks_2022.ServerConfig) - config.Method = v.Cipher - config.Key = v.Password - config.Network = v.NetworkList.Build() - config.Email = v.Email - return config, nil - } - - if v.Cipher == "" { - return nil, errors.New("shadowsocks 2022 (multi-user): missing server method") - } - if !strings.Contains(v.Cipher, "aes") { - return nil, errors.New("shadowsocks 2022 (multi-user): only blake3-aes-*-gcm methods are supported") - } - - if v.Users[0].Address == nil { - config := new(shadowsocks_2022.MultiUserServerConfig) - config.Method = v.Cipher - config.Key = v.Password - config.Network = v.NetworkList.Build() - - config.Users = make([]*protocol.User, len(v.Users)) - processUser := func(idx int) error { - user := v.Users[idx] - if user.Cipher != "" { - return errors.New("shadowsocks 2022 (multi-user): users must have empty method") - } - account := &shadowsocks_2022.Account{ - Key: user.Password, - } - config.Users[idx] = &protocol.User{ - Email: user.Email, - Level: uint32(user.Level), - Account: serial.ToTypedMessage(account), - } - return nil - } - if err := task.ParallelForN(len(v.Users), processUser); err != nil { - return nil, err - } - return config, nil - } - - config := new(shadowsocks_2022.RelayServerConfig) - config.Method = v.Cipher - config.Key = v.Password - config.Network = v.NetworkList.Build() - for _, user := range v.Users { - if user.Cipher != "" { - return nil, errors.New("shadowsocks 2022 (relay): users must have empty method") - } - if user.Address == nil { - return nil, errors.New("shadowsocks 2022 (relay): all users must have relay address") - } - config.Destinations = append(config.Destinations, &shadowsocks_2022.RelayDestination{ - Key: user.Password, - Email: user.Email, - Address: user.Address.Build(), - Port: uint32(user.Port), - }) - } - return config, nil -} - type ShadowsocksServerTarget struct { Address *Address `json:"address"` Port uint16 `json:"port"` @@ -216,30 +155,15 @@ func (v *ShadowsocksClientConfig) Build() (proto.Message, error) { if len(v.Servers) == 1 { server := v.Servers[0] - if C.Contains(shadowaead_2022.List, server.Cipher) { - if server.Address == nil { - return nil, errors.New("Shadowsocks server address is not set.") - } - if server.Port == 0 { - return nil, errors.New("Invalid Shadowsocks port.") - } - if server.Password == "" { - return nil, errors.New("Shadowsocks password is not specified.") - } - - config := new(shadowsocks_2022.ClientConfig) - config.Address = server.Address.Build() - config.Port = uint32(server.Port) - config.Method = server.Cipher - config.Key = server.Password - return config, nil + if isShadowsocks2022Cipher(server.Cipher) { + return nil, errors.New("shadowsocks 2022 is not supported in this build") } } config := new(shadowsocks.ClientConfig) for _, server := range v.Servers { - if C.Contains(shadowaead_2022.List, server.Cipher) { - return nil, errors.New("Shadowsocks 2022 accept no multi servers") + if isShadowsocks2022Cipher(server.Cipher) { + return nil, errors.New("shadowsocks 2022 is not supported in this build") } if server.Address == nil { return nil, errors.New("Shadowsocks server address is not set.")