TLS ECH DoH h2c: Support verifyPeerCertByName's "fromMitm" (after dialerProxy, in RAW outbound's tlsSettings) (#6246)

https://github.com/XTLS/Xray-core/pull/6246#issuecomment-5850758711

Like https://github.com/XTLS/Xray-core/commit/613c63b165829a0b3e5bfc3a72eff21d96ab4874

---------

Co-authored-by: patterniha <71074308+patterniha@users.noreply.github.com>
This commit is contained in:
j2rong4cn
2026-10-10 04:36:21 +00:00
committed by GitHub
co-authored by patterniha
parent 4c4d319239
commit cf8f11a8db
+12 -7
View File
@@ -17,6 +17,7 @@ import (
utls "github.com/refraction-networking/utls"
"github.com/xtls/xray-core/common/crypto"
"github.com/xtls/xray-core/common/session"
"golang.org/x/net/http2"
"github.com/miekg/dns"
@@ -198,23 +199,27 @@ func dnsQuery(server string, domain string, sockopt *internet.SocketConfig) ([]b
IdleConnTimeout: net.ConnIdleTimeout,
ReadIdleTimeout: net.ChromeH2KeepAlivePeriod,
DialTLSContext: func(ctx context.Context, network, addr string, cfg *tls.Config) (net.Conn, error) {
host, _, err := net.SplitHostPort(addr)
if err != nil {
return nil, err
}
dest, err := net.ParseDestination(network + ":" + addr)
if err != nil {
return nil, err
}
dnsCtx := ctx
if h2c {
dnsCtx = session.ContextWithMitmAlpn11(dnsCtx, false) // for insurance
dnsCtx = session.ContextWithMitmServerName(dnsCtx, host)
}
var conn net.Conn
conn, err = internet.DialSystem(ctx, dest, sockopt)
conn, err = internet.DialSystem(dnsCtx, dest, sockopt)
if err != nil {
return nil, err
}
if !h2c {
u, err := url.Parse(server)
if err != nil {
return nil, err
}
conn = utls.UClient(conn, &utls.Config{ServerName: u.Hostname()}, utls.HelloChrome_Auto)
conn = utls.UClient(conn, &utls.Config{ServerName: host}, utls.HelloChrome_Auto)
if err := conn.(*utls.UConn).HandshakeContext(ctx); err != nil {
return nil, err
}