From aa7aa9ad0a045d5dd1231af85f894bb6c3e78d54 Mon Sep 17 00:00:00 2001 From: RPRX <63339210+RPRX@users.noreply.github.com> Date: Sat, 10 Oct 2026 06:01:13 +0000 Subject: [PATCH] MASQUE client: Ignore `publicKey` in `warp` when pcs/vcn exists (domain fronting for WARP) Closes https://github.com/XTLS/Xray-core/issues/7115#issuecomment-6088708005 --- transport/internet/masque/warp.go | 36 +++++++++++++++---------------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/transport/internet/masque/warp.go b/transport/internet/masque/warp.go index f7cc43a56..09054def6 100644 --- a/transport/internet/masque/warp.go +++ b/transport/internet/masque/warp.go @@ -54,25 +54,25 @@ func useWarp(config *Config, tlsConfig *gotls.Config) error { tlsConfig.GetClientCertificate = func(*gotls.CertificateRequestInfo) (*gotls.Certificate, error) { return cert, nil } - if publicKey := config.Warp.PublicKey; len(publicKey) > 0 { - verify := tlsConfig.VerifyPeerCertificate - tlsConfig.InsecureSkipVerify = true - tlsConfig.VerifyPeerCertificate = func(raw [][]byte, chains [][]*x509.Certificate) error { - if len(raw) == 0 { - return errors.New("the WARP endpoint sent no certificate") - } - leaf, err := x509.ParseCertificate(raw[0]) - if err != nil { - return err - } - if !bytes.Equal(leaf.RawSubjectPublicKeyInfo, publicKey) { - return errors.New("the WARP endpoint's key doesn't match \"publicKey\"") - } - if verify != nil { - return verify(raw, chains) - } - return nil + if tlsConfig.InsecureSkipVerify == true { + return nil // pcs or vcn or both + } + if _, err = x509.ParsePKIXPublicKey(config.Warp.PublicKey); err != nil { + return err + } + tlsConfig.InsecureSkipVerify = true + tlsConfig.VerifyPeerCertificate = func(raw [][]byte, chains [][]*x509.Certificate) error { + if len(raw) == 0 { + return errors.New("the WARP endpoint sent no certificate") } + leaf, err := x509.ParseCertificate(raw[0]) + if err != nil { + return err + } + if !bytes.Equal(leaf.RawSubjectPublicKeyInfo, config.Warp.PublicKey) { + return errors.New("the WARP endpoint's key doesn't match \"publicKey\"") + } + return nil } return nil }