Skip to content

Add opt-in HTTP3, MASQUE profiles and authenticated SOCKS5 - #4

Merged
andre487 merged 1 commit into
mainfrom
feat/proxy-transports
Oct 10, 2026
Merged

andre487 merged 1 commit into
mainfrom
feat/proxy-transports

Conversation

@andre487

Copy link
Copy Markdown
Owner

HTTPS proxies currently expose TCP only, while configuration subscriptions cannot discover provisioned HTTP/3 or SOCKS5 endpoints. Add independent per-host transport options and advertise their capabilities in personalized configurations.

Changes

  • Add opt-in services.https.http3: authenticated GOST MASQUE over UDP on the existing HTTPS port, TLS 1.3, HTTP Datagrams, firewall rules and the capability required for low ports. Keep the existing HTTPS/TCP and masking configuration.
  • Set proxy.preferHttp3 for compatible direct HTTPS profiles. Add separate MASQUE profiles only when services.https.masque_profiles is enabled; require HTTP/3 for that option.
  • Add disabled-by-default services.https.socks5 with authenticated TCP CONNECT, UDP ASSOCIATE, bounded relay ports and validation of UTF-8 credential sizes and port conflicts. Document SOCKS5 as not recommended because it does not encrypt transport or proxy credentials.
  • Include provisioned transports in subscription responses and MegaProxy exports, retain client compatibility filtering, and update pinned shared/Android v8 schemas. Android now receives supported SOCKS5 profiles; Chromium still skips authenticated SOCKS5.
  • Add setup documentation, wizard HTTP/3 options, listener verification and a CI job against GOST 3.3.0 with a pinned release checksum. An independent aioquic client verifies MASQUE interoperability; aioquic is a development dependency only.

Server-side SNI chains remain HTTPS/TCP and never acquire a direct QUIC bypass. GOST 3.3.0's outbound CONNECT-UDP omits the required Extended CONNECT scheme, so this PR enables HTTP/3 on direct endpoints only. Browser API projections retain their compatible HTTPS/SOCKS5 subset.

The private inventory was updated separately as requested: HTTP/3 on px-*, disabled on cpx-*, separate MASQUE profiles only on px-am2, GOST HTTPS masking on every HTTPS host, and SOCKS5 disabled everywhere. No production deployment was performed; private inventory and credentials are excluded from this PR.

Validation

  • pytest -q: 92 passed.
  • Ruff and whitespace checks: passed.
  • Ansible syntax checks for site, bootstrap and verify playbooks: passed.
  • Real GOST 3.3.0: SOCKS5 TCP/UDP, rejection of anonymous/bad credentials, bounded UDP relay ports, MASQUE CONNECT-TCP/CONNECT-UDP, trusted TLS and rejection of an untrusted certificate passed.
  • Real nginx HTTPS integration for configuration subscriptions: passed.

@andre487
andre487 merged commit 0d5d537 into main Oct 10, 2026
10 checks passed
@andre487
andre487 deleted the feat/proxy-transports branch October 10, 2026 21:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant