Fix Hysteria2/QUIC ALPN negotiation failure with ACME#4213
Open
BioniCosmos wants to merge 110 commits into
Open
Fix Hysteria2/QUIC ALPN negotiation failure with ACME#4213BioniCosmos wants to merge 110 commits into
BioniCosmos wants to merge 110 commits into
Conversation
`SecTrustEvaluateWithError` is serial
This reverts commit 62cb06c.
The URL test history update hook and the Clash mode update hook were single-slot: the API service's attached service overwrote the hook set by the daemon, so clients stopped receiving group updates. Replace both with multicast hook lists. Also share a single URL test history storage via context: Clash API looked it up under a key nobody registered and fell back to its own empty storage, so dashboards showed no delay once an API service was configured. Selector changes now notify through the shared storage, covering selections made from any API surface.
f7ca395 to
f27d0e3
Compare
22fe3b6 to
b2d51f6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hysteria2 inbounds using ACME with the default TLS-ALPN-01 challenge fail the QUIC handshake with
CRYPTO_ERROR 0x178 (remote): tls: no application protocolin client side. Manually specifyingcertificate_path/key_path, or using a DNS-01 solver, works around the issue.The key is:
NextProtoscould be reused in multiple stages. However, the current implemention failed to strip the ALPN settings used in the ACME stage, causing issue in the following communication.sing-box/transport/v2rayquic/server.go
Lines 40 to 42 in 8247670
Related issues
#3389
Tested working in v1.13.12.