Fix lint errors

This commit is contained in:
世界
2026-05-14 22:53:22 +08:00
parent 4b55717612
commit 2c2e08e608
38 changed files with 284 additions and 333 deletions
+3 -7
View File
@@ -5,6 +5,7 @@ package tls
import (
"context"
"crypto/tls"
"slices"
"strings"
"github.com/sagernet/sing-box/adapter"
@@ -70,13 +71,8 @@ func startACME(ctx context.Context, logger logger.Logger, options option.Inbound
Logger: zapLogger,
}
profile := options.Profile
if profile == "" && acmeServer == certmagic.LetsEncryptProductionCA {
for _, domain := range options.Domain {
if certmagic.SubjectIsIP(domain) {
profile = "shortlived"
break
}
}
if profile == "" && acmeServer == certmagic.LetsEncryptProductionCA && slices.ContainsFunc(options.Domain, certmagic.SubjectIsIP) {
profile = "shortlived"
}
acmeConfig := certmagic.ACMEIssuer{
+3 -3
View File
@@ -39,7 +39,7 @@ var (
func TestAppleClientHandshakeAppliesALPNAndVersion(t *testing.T) {
serverCertificate, serverCertificatePEM := newAppleTestCertificate(t, "localhost")
for index := 0; index < appleTLSSuccessHandshakeLoops; index++ {
for index := range appleTLSSuccessHandshakeLoops {
serverResult, serverAddress := startAppleTLSTestServer(t, &stdtls.Config{
Certificates: []stdtls.Certificate{serverCertificate},
MinVersion: stdtls.VersionTLS12,
@@ -201,7 +201,7 @@ func TestAppleClientHandshakeRecoversAfterFailure(t *testing.T) {
for _, testCase := range testCases {
t.Run(testCase.name, func(t *testing.T) {
for index := 0; index < appleTLSFailureRecoveryLoops; index++ {
for index := range appleTLSFailureRecoveryLoops {
failedResult, failedAddress := startAppleTLSTestServer(t, testCase.serverConfig)
failedConn, err := newAppleTestClientConn(t, failedAddress, testCase.clientOptions)
if err == nil {
@@ -271,7 +271,7 @@ func TestAppleClientConfigCloneWithInlineCertificate(t *testing.T) {
t.Fatalf("Clone shares ALPN slice with original: %v", nextProtos)
}
for index := 0; index < appleTLSFailureRecoveryLoops; index++ {
for index := range appleTLSFailureRecoveryLoops {
serverResult, serverAddress := startAppleTLSTestServer(t, &stdtls.Config{
Certificates: []stdtls.Certificate{serverCertificate},
MinVersion: stdtls.VersionTLS12,
-95
View File
@@ -3,79 +3,16 @@ package tls
import (
"context"
"crypto/x509"
"net"
"os"
"strings"
"time"
"github.com/sagernet/sing-box/adapter"
C "github.com/sagernet/sing-box/constant"
"github.com/sagernet/sing-box/option"
E "github.com/sagernet/sing/common/exceptions"
"github.com/sagernet/sing/common/ntp"
"github.com/sagernet/sing/service"
)
type systemTLSConfig struct {
serverName string
nextProtos []string
handshakeTimeout time.Duration
minVersion uint16
maxVersion uint16
insecure bool
anchorOnly bool
certificatePublicKeySHA256 [][]byte
timeFunc func() time.Time
store adapter.CertificateStore
}
func (c *systemTLSConfig) ServerName() string {
return c.serverName
}
func (c *systemTLSConfig) SetServerName(serverName string) {
c.serverName = serverName
}
func (c *systemTLSConfig) NextProtos() []string {
return c.nextProtos
}
func (c *systemTLSConfig) SetNextProtos(nextProto []string) {
c.nextProtos = append([]string(nil), nextProto...)
}
func (c *systemTLSConfig) HandshakeTimeout() time.Duration {
return c.handshakeTimeout
}
func (c *systemTLSConfig) SetHandshakeTimeout(timeout time.Duration) {
c.handshakeTimeout = timeout
}
func (c *systemTLSConfig) STDConfig() (*STDConfig, error) {
return nil, E.New("STDConfig is unsupported for the system TLS engine")
}
func (c *systemTLSConfig) Client(conn net.Conn) (Conn, error) {
return nil, os.ErrInvalid
}
func (c *systemTLSConfig) clone() systemTLSConfig {
return systemTLSConfig{
serverName: c.serverName,
nextProtos: append([]string(nil), c.nextProtos...),
handshakeTimeout: c.handshakeTimeout,
minVersion: c.minVersion,
maxVersion: c.maxVersion,
insecure: c.insecure,
anchorOnly: c.anchorOnly,
certificatePublicKeySHA256: append([][]byte(nil), c.certificatePublicKeySHA256...),
timeFunc: c.timeFunc,
store: c.store,
}
}
type SystemTLSValidated struct {
MinVersion uint16
MaxVersion uint16
@@ -165,38 +102,6 @@ func resolveSystemAnchors(ctx context.Context, options option.OutboundTLSOptions
return nil, store.ExclusiveAnchors(), store, nil
}
func newSystemTLSConfig(ctx context.Context, serverAddress string, options option.OutboundTLSOptions, allowEmptyServerName bool, engineName string) (systemTLSConfig, SystemTLSValidated, error) {
validated, err := ValidateSystemTLSOptions(ctx, options, engineName)
if err != nil {
return systemTLSConfig{}, SystemTLSValidated{}, err
}
var serverName string
if options.ServerName != "" {
serverName = options.ServerName
} else if serverAddress != "" {
serverName = serverAddress
}
if serverName == "" && !options.Insecure && !allowEmptyServerName {
return systemTLSConfig{}, SystemTLSValidated{}, errMissingServerName
}
handshakeTimeout := C.TCPTimeout
if options.HandshakeTimeout > 0 {
handshakeTimeout = options.HandshakeTimeout.Build()
}
return systemTLSConfig{
serverName: serverName,
nextProtos: append([]string(nil), options.ALPN...),
handshakeTimeout: handshakeTimeout,
minVersion: validated.MinVersion,
maxVersion: validated.MaxVersion,
insecure: options.Insecure || len(options.CertificatePublicKeySHA256) > 0,
anchorOnly: validated.Exclusive,
certificatePublicKeySHA256: append([][]byte(nil), options.CertificatePublicKeySHA256...),
timeFunc: ntp.TimeFuncFromContext(ctx),
store: validated.Store,
}, validated, nil
}
func verifySystemTLSPeer(roots *x509.CertPool, serverName string, timeFunc func() time.Time, peerCertificates []*x509.Certificate) error {
if len(peerCertificates) == 0 {
return E.New("no peer certificates")
+108
View File
@@ -0,0 +1,108 @@
//go:build (darwin && cgo) || windows
package tls
import (
"context"
"net"
"os"
"time"
"github.com/sagernet/sing-box/adapter"
C "github.com/sagernet/sing-box/constant"
"github.com/sagernet/sing-box/option"
E "github.com/sagernet/sing/common/exceptions"
"github.com/sagernet/sing/common/ntp"
)
type systemTLSConfig struct {
serverName string
nextProtos []string
handshakeTimeout time.Duration
minVersion uint16
maxVersion uint16
insecure bool
anchorOnly bool
certificatePublicKeySHA256 [][]byte
timeFunc func() time.Time
store adapter.CertificateStore
}
func (c *systemTLSConfig) ServerName() string {
return c.serverName
}
func (c *systemTLSConfig) SetServerName(serverName string) {
c.serverName = serverName
}
func (c *systemTLSConfig) NextProtos() []string {
return c.nextProtos
}
func (c *systemTLSConfig) SetNextProtos(nextProto []string) {
c.nextProtos = append([]string(nil), nextProto...)
}
func (c *systemTLSConfig) HandshakeTimeout() time.Duration {
return c.handshakeTimeout
}
func (c *systemTLSConfig) SetHandshakeTimeout(timeout time.Duration) {
c.handshakeTimeout = timeout
}
func (c *systemTLSConfig) STDConfig() (*STDConfig, error) {
return nil, E.New("STDConfig is unsupported for the system TLS engine")
}
func (c *systemTLSConfig) Client(conn net.Conn) (Conn, error) {
return nil, os.ErrInvalid
}
func (c *systemTLSConfig) clone() systemTLSConfig {
return systemTLSConfig{
serverName: c.serverName,
nextProtos: append([]string(nil), c.nextProtos...),
handshakeTimeout: c.handshakeTimeout,
minVersion: c.minVersion,
maxVersion: c.maxVersion,
insecure: c.insecure,
anchorOnly: c.anchorOnly,
certificatePublicKeySHA256: append([][]byte(nil), c.certificatePublicKeySHA256...),
timeFunc: c.timeFunc,
store: c.store,
}
}
func newSystemTLSConfig(ctx context.Context, serverAddress string, options option.OutboundTLSOptions, allowEmptyServerName bool, engineName string) (systemTLSConfig, SystemTLSValidated, error) {
validated, err := ValidateSystemTLSOptions(ctx, options, engineName)
if err != nil {
return systemTLSConfig{}, SystemTLSValidated{}, err
}
var serverName string
if options.ServerName != "" {
serverName = options.ServerName
} else if serverAddress != "" {
serverName = serverAddress
}
if serverName == "" && !options.Insecure && !allowEmptyServerName {
return systemTLSConfig{}, SystemTLSValidated{}, errMissingServerName
}
handshakeTimeout := C.TCPTimeout
if options.HandshakeTimeout > 0 {
handshakeTimeout = options.HandshakeTimeout.Build()
}
return systemTLSConfig{
serverName: serverName,
nextProtos: append([]string(nil), options.ALPN...),
handshakeTimeout: handshakeTimeout,
minVersion: validated.MinVersion,
maxVersion: validated.MaxVersion,
insecure: options.Insecure || len(options.CertificatePublicKeySHA256) > 0,
anchorOnly: validated.Exclusive,
certificatePublicKeySHA256: append([][]byte(nil), options.CertificatePublicKeySHA256...),
timeFunc: ntp.TimeFuncFromContext(ctx),
store: validated.Store,
}, validated, nil
}
+3 -3
View File
@@ -1110,7 +1110,7 @@ func TestWindowsClientMultipleRoundtrips(t *testing.T) {
clientConn, serverDone := startWindowsEchoServer(t, stdtls.VersionTLS12)
defer clientConn.Close()
for i := 0; i < 100; i++ {
for i := range 100 {
payload := []byte("msg" + string(rune('A'+(i%26))))
_, err := clientConn.Write(payload)
if err != nil {
@@ -1148,7 +1148,7 @@ func TestWindowsClientConcurrentReadWrite(t *testing.T) {
readErr := make(chan error, 1)
readBack := make(chan []byte, messageCount)
go func() {
for i := 0; i < messageCount; i++ {
for range messageCount {
reply := make([]byte, messageSize)
_, err := io.ReadFull(clientConn, reply)
if err != nil {
@@ -1171,7 +1171,7 @@ func TestWindowsClientConcurrentReadWrite(t *testing.T) {
if readResult != nil {
t.Fatal(readResult)
}
for i := 0; i < messageCount; i++ {
for i := range messageCount {
got := <-readBack
if !bytes.Equal(payloads[i], got) {
t.Fatalf("iteration %d: payload mismatch", i)