Зеркало Leadaxe/sing-tun-lx — сабмодуль ядра sing-box-lx. GPLv3.
REDIRECT in the OUTPUT chain rewrites the destination to 127.0.0.1, then ip_route_me_harder() reroutes with the socket's bound interface constraint (flowi4_oif). Since 127.0.0.1 is only reachable via lo, the routing lookup fails and the packet is silently dropped. Add a fallback routing table with `local 127.0.0.1` entries for each non-loopback interface. When the local table lookup fails due to OIF mismatch, the fallback table provides a matching RTN_LOCAL route. The kernel then overrides dev_out to loopback (route.c:2857), so the packet is delivered locally to the redirect server as intended. This fixes NetworkManager connectivity checks and other tools that use SO_BINDTODEVICE (e.g. curl --interface). |
||
|---|---|---|
| .github | ||
| internal | ||
| ping | ||
| .gitignore | ||
| .golangci.yml | ||
| go.mod | ||
| go.sum | ||
| LICENSE | ||
| Makefile | ||
| monitor.go | ||
| monitor_android.go | ||
| monitor_darwin.go | ||
| monitor_linux.go | ||
| monitor_linux_default.go | ||
| monitor_other.go | ||
| monitor_shared.go | ||
| monitor_windows.go | ||
| nfqueue_linux.go | ||
| packages.go | ||
| packages_android.go | ||
| packages_stub.go | ||
| README.md | ||
| redirect.go | ||
| redirect_iptables.go | ||
| redirect_linux.go | ||
| redirect_nftables.go | ||
| redirect_nftables_exprs.go | ||
| redirect_nftables_rules.go | ||
| redirect_nftables_rules_openwrt.go | ||
| redirect_route_linux.go | ||
| redirect_server.go | ||
| redirect_stub.go | ||
| route_direct.go | ||
| stack.go | ||
| stack_gvisor.go | ||
| stack_gvisor_filter.go | ||
| stack_gvisor_icmp.go | ||
| stack_gvisor_lazy.go | ||
| stack_gvisor_log.go | ||
| stack_gvisor_stub.go | ||
| stack_gvisor_tcp.go | ||
| stack_gvisor_tcpbuf_default.go | ||
| stack_gvisor_tcpbuf_ios.go | ||
| stack_gvisor_udp.go | ||
| stack_mixed.go | ||
| stack_system.go | ||
| stack_system_nat.go | ||
| stack_system_nonwindows.go | ||
| stack_system_packet.go | ||
| stack_system_windows.go | ||
| tun.go | ||
| tun_darwin.go | ||
| tun_darwin_gvisor.go | ||
| tun_linux.go | ||
| tun_linux_flags.go | ||
| tun_linux_gvisor.go | ||
| tun_nondarwin.go | ||
| tun_nonlinux.go | ||
| tun_offload.go | ||
| tun_offload_errors.go | ||
| tun_offload_linux.go | ||
| tun_other.go | ||
| tun_rules.go | ||
| tun_windows.go | ||
| tun_windows_gvisor.go | ||
sing-tun
Simple transparent proxy library.
For Linux, Windows, macOS and iOS.
License
Copyright (C) 2022 by nekohasekai <contact-sagernet@sekai.icu>
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.