Update Finalmask docs (version 25.9.9) (#900)

This commit is contained in:
LjhAUMEM
2026-10-03 14:07:19 +08:00
committed by GitHub
parent 5ee08112dd
commit cbc4132383
6 changed files with 204 additions and 27 deletions
+2
View File
@@ -103,6 +103,8 @@ WireGuard 协议保留字节,长度为 3,默认全 0,按需填写。
用于解析被代理目标的域名。列表项必须为 IP。默认值为 `["1.1.1.1", "1.0.0.1", "2606:4700:4700::1111", "2606:4700:4700::1001"]`。
在 `address` 为双栈时优先 IPv4。
不同于其他出站,WireGuard 隧道内的目标地址必须为 IP。当被代理目标为域名时,需要一个 DNS 服务器将域名转化为 IP 地址。这部分 DNS 服务器在这里配置,并且**直接通过这个 WireGuard 隧道发送 DNS 请求**。想将其接入 Xray 内置 DNS 系统请考虑在出站的 [`targetStrategy`](../outbound.md#outboundobject) 提前解析。
### PeersObject
+66 -9
View File
@@ -381,17 +381,31 @@ Salamander 混淆。(来自 Hysteria2)
"type": "xdns",
// [!field focus]
"settings": {
"domains": ["t.example.com"],
"resolvers": ["t.example.com+udp://8.8.8.8:53"]
"domains": [
{
"name": "t.example.com",
"lenLimit": 255, // 0-255
"labelLimit": 63, // 0-63
"types": [1, 5, 16, 28], // 1:A 5:CNAME 16:TXT 28:AAAA
"edns0": 1232 // 0,512-4096
}
],
"resolvers": [
{
"type": "udp",
"settings": {
"addr": "127.0.0.1:53"
}
}
]
}
}
```
`domains`: 服务端使用,域名列表。支持指定查询类型 `domain:method`,method 可为 `txt`、`a`、`aaaa`,不指定则不限制查询类型。
仅可搭配 kcp,推荐设置 tti 200,仅服务端需要配置 mtu,参考 mtu,CNAME 计算比较复杂,一般在 AAAA 与 TXT 之间
`resolvers`: 客户端使用,DNS 解析器列表。格式为 `domain[:method]+udp://server:port`,method 可为 `txt`(默认)、`a`、`aaaa`。
`domains` 与 `resolvers` 至少填写一个。
- edns0 为 512 时,A 39 TXT 215 AAAA 117
- edns0 为 1232 时,A 174 TXT 932 AAAA 492
### xicmp
@@ -408,7 +422,7 @@ Salamander 混淆。(来自 Hysteria2)
`dgram`: 更低的权限,仅客户端 (Linux, Mac, iOS)
`ips`: ips
`ips`: 暂不支持 cidr
### realm
@@ -424,7 +438,13 @@ Salamander 混淆。(来自 Hysteria2)
"stun.nextcloud.com:3478",
"global.stun.twilio.com:3478"
],
"tlsConfig": {} // optional
"tlsConfig": {}, // optional
"ipMode": "dual",
"portMapping": {
"enabled": false,
"timeout": 10,
"lifetime": 600
}
}
}
```
@@ -435,7 +455,44 @@ Salamander 混淆。(来自 Hysteria2)
`tlsConfig`: 同 tlsSettings
连接不通需要 debug 级别日志,可能的影响因素有 stun提供商 realm提供商 punch包影响了quic握手(极小概率)
`ipMode`: 控制 stun 的域名地址解析以及 realm peer 的过滤
`portMapping.enabled`: 启用固定端口映射,更强的入站可达性
`portMapping.timeout`: 单位秒
`portMapping.lifetime`: 单位秒
连接不通需要 debug 级别日志,可能的影响因素有 stun提供商 realm提供商
### udphop
```json
{
"type": "udphop",
// [!field focus]
"settings": {
"mode": "intervallocal,intervalremote", // intervallocal intervalremote perconnremote
"interval": "5-10",
"remoteIPs": [""],
"remotePorts": "20000-50000,443"
}
}
```
`intervallocal`: 仅支持 wireguard hysteria xhttph3
`intervalremote`: 需要搭配 iptables 或 nftables
`perconnremote`: 需要搭配 iptables 或 nftables
`mode`: 逗号分割,一般为 `intervallocal,intervalremote` 或仅 `intervallocal` 或仅 `perconnremote`
`interval`: 单位秒
`remoteIPs`: 仅 mode 含 intervalremote 或 perconnremote 时需要,未填继承上层地址,支持 cidr
`remotePorts`: 仅 mode 含 intervalremote 或 perconnremote 时需要,未填继承上层地址
## quicParams
+2
View File
@@ -103,6 +103,8 @@ List of remote WireGuard peers to connect to.
Used to resolve proxied target domain names. Each item must be an IP address. The default is `["1.1.1.1", "1.0.0.1", "2606:4700:4700::1111", "2606:4700:4700::1001"]`.
Prioritize IPv4 when `address` is dual-stack.
Unlike other outbounds, targets inside a WireGuard tunnel must be IP addresses. When a proxied target is a domain name, a DNS server is required to convert the domain name into an IP address. These DNS servers are configured here and **send DNS requests directly through this WireGuard tunnel**. If you wish to integrate this with Xray's built-in DNS system, consider resolving in advance via the outbound's [`targetStrategy`](../outbound.md#outboundobject).
### PeersObject
+66 -9
View File
@@ -381,17 +381,31 @@ For example, if you own `example.com`, set an A record like `a.example.com` to t
"type": "xdns",
// [!field focus]
"settings": {
"domains": ["t.example.com"],
"resolvers": ["t.example.com+udp://8.8.8.8:53"]
"domains": [
{
"name": "t.example.com",
"lenLimit": 255, // 0-255
"labelLimit": 63, // 0-63
"types": [1, 5, 16, 28], // 1:A 5:CNAME 16:TXT 28:AAAA
"edns0": 1232 // 0,512-4096
}
],
"resolvers": [
{
"type": "udp",
"settings": {
"addr": "127.0.0.1:53"
}
}
]
}
}
```
`domains`: used on the server side. A list of domains. It supports specifying a query type as `domain:method`, where `method` can be `txt`, `a`, or `aaaa`. If omitted, the query type is unrestricted.
Compatible only with kcp; a TTI of 200 is recommended. MTU configuration is required only on the server side (refer to MTU settings). CNAME calculation is relatively complex; values ​​generally fall between those for AAAA and TXT records:
`resolvers`: used on the client side. A list of DNS resolvers. The format is `domain[:method]+udp://server:port`, where `method` can be `txt` (default), `a`, or `aaaa`.
At least one of `domains` and `resolvers` must be set.
- When edns0 is 512: A 39, TXT 215, AAAA 117
- When edns0 is 1232: A 174, TXT 932, AAAA 492
### xicmp
@@ -408,7 +422,7 @@ At least one of `domains` and `resolvers` must be set.
`dgram`: Lower permissions, client-side only (Linux, Mac, iOS)
`ips`: ips
`ips`: CIDR is not currently supported
### realm
@@ -424,7 +438,13 @@ Self-built https://github.com/apernet/hysteria-realm-server
"stun.nextcloud.com:3478",
"global.stun.twilio.com:3478"
],
"tlsConfig": {} // optional
"tlsConfig": {}, // optional
"ipMode": "dual",
"portMapping": {
"enabled": false,
"timeout": 10,
"lifetime": 600
}
}
}
```
@@ -435,7 +455,44 @@ Self-built https://github.com/apernet/hysteria-realm-server
`tlsConfig`: Same as tlsSettings
Connection failures require debug-level logging. Possible contributing factors include the STUN provider, the Realm provider, and punch packets affecting the QUIC handshake (extremely low probability)
`ipMode`: Control STUN domain name resolution and realm peer filtering
`portMapping.enabled`: Enable fixed port mapping for enhanced inbound accessibility
`portMapping.timeout`: seconds
`portMapping.lifetime`: seconds
Connection failures require debug-level logging. Possible contributing factors include the STUN provider, the Realm provider
### udphop
```json
{
"type": "udphop",
// [!field focus]
"settings": {
"mode": "intervallocal,intervalremote", // intervallocal intervalremote perconnremote
"interval": "5-10",
"remoteIPs": [""],
"remotePorts": "20000-50000,443"
}
}
```
`intervallocal`: Supports only WireGuard, Hysteria, and xhttp-h3
`intervalremote`: Requires pairing with iptables or nftables
`perconnremote`: Requires pairing with iptables or nftables
`mode`: Comma-separated; typically `intervallocal,intervalremote`, or just `intervallocal`, or just `perconnremote`
`interval`: seconds
`remoteIPs`: Required only when `mode` includes `intervalremote` or `perconnremote`; if left blank, it inherits the address from the parent level. CIDR notation is supported
`remotePorts`: Required only when `mode` includes `intervalremote` or `perconnremote`; if left blank, it inherits the address from the parent level
## quicParams
+2
View File
@@ -103,6 +103,8 @@ MTU внутренних IP-пакетов в туннеле WireGuard. Знач
Используется для разрешения целевых доменных имён проксируемого трафика. Каждый элемент должен быть IP-адресом. Значение по умолчанию — `["1.1.1.1", "1.0.0.1", "2606:4700:4700::1111", "2606:4700:4700::1001"]`.
Отдавать приоритет IPv4 при использовании dual-stack для `address`.
В отличие от других исходящих подключений, адрес цели внутри туннеля WireGuard обязательно должен быть IP-адресом. Если проксируемая цель является доменным именем, необходим DNS-сервер для преобразования доменного имени в IP-адрес. Эти DNS-серверы настраиваются здесь и **отправляют DNS-запросы напрямую через этот туннель WireGuard**. Если вы хотите подключить встроенную систему DNS Xray, рассмотрите возможность предварительного разрешения через [`targetStrategy`](../outbound.md#outboundobject) исходящего подключения.
### PeersObject
+66 -9
View File
@@ -381,17 +381,31 @@ n-й элемент массива задаёт, сколько ждать по
"type": "xdns",
// [!field focus]
"settings": {
"domains": ["t.example.com"],
"resolvers": ["t.example.com+udp://8.8.8.8:53"]
"domains": [
{
"name": "t.example.com",
"lenLimit": 255, // 0-255
"labelLimit": 63, // 0-63
"types": [1, 5, 16, 28], // 1:A 5:CNAME 16:TXT 28:AAAA
"edns0": 1232 // 0,512-4096
}
],
"resolvers": [
{
"type": "udp",
"settings": {
"addr": "127.0.0.1:53"
}
}
]
}
}
```
`domains`: используется на стороне сервера. Список доменов. Поддерживает указание типа запроса в формате `domain:method`, где `method` может быть `txt`, `a` или `aaaa`. Если `method` не указан, тип запроса не ограничивается.
Совместимо только с kcp; рекомендуется значение TTI, равное 200. Настройка MTU требуется только на стороне сервера (см. раздел настроек MTU). Расчет CNAME относительно сложен; как правило, полученные значения находятся в диапазоне между значениями для записей AAAA и TXT:
`resolvers`: используется на стороне клиента. Список DNS-резолверов. Формат: `domain[:method]+udp://server:port`, где `method` может быть `txt` по умолчанию, `a` или `aaaa`.
Хотя бы одно из `domains` и `resolvers` должно быть заполнено.
- При edns0 = 512: A 39, TXT 215, AAAA 117
- При edns0 = 1232: A 174, TXT 932, AAAA 492
### xicmp
@@ -408,7 +422,7 @@ n-й элемент массива задаёт, сколько ждать по
`dgram`: Более низкие права доступа, только на стороне клиента (Linux, Mac, iOS)
`ips`: ips
`ips`: В настоящее время CIDR не поддерживается
### realm
@@ -424,7 +438,13 @@ n-й элемент массива задаёт, сколько ждать по
"stun.nextcloud.com:3478",
"global.stun.twilio.com:3478"
],
"tlsConfig": {} // optional
"tlsConfig": {}, // optional
"ipMode": "dual",
"portMapping": {
"enabled": false,
"timeout": 10,
"lifetime": 600
}
}
}
```
@@ -435,7 +455,44 @@ n-й элемент массива задаёт, сколько ждать по
`tlsConfig`: То же, что tlsSettings
Для регистрации сбоев соединения требуется уровень отладки. К возможным факторам, способствующим возникновению проблем, относятся поставщик STUN, поставщик Realm и пакеты данных, влияющие на рукопожатие QUIC (вероятность крайне низка)
`ipMode`: Управляйте разрешением доменных имен STUN и фильтрацией одноранговых узлов (peer) в пределах области (realm)
`portMapping.enabled`: Включите фиксированное сопоставление портов для улучшения доступности входящих соединений
`portMapping.timeout`: секунды
`portMapping.lifetime`: секунды
Для регистрации сбоев соединения требуется уровень отладки. К возможным факторам, способствующим возникновению проблем, относятся поставщик STUN, поставщик Realm
### udphop
```json
{
"type": "udphop",
// [!field focus]
"settings": {
"mode": "intervallocal,intervalremote", // intervallocal intervalremote perconnremote
"interval": "5-10",
"remoteIPs": [""],
"remotePorts": "20000-50000,443"
}
}
```
`intervallocal`: Поддерживает только WireGuard, Hysteria и xhttp-h3
`intervalremote`: Требует использования в связке с iptables или nftables
`perconnremote`: Требует использования в связке с iptables или nftables
`mode`: Список, разделенный запятыми; обычно `intervallocal,intervalremote`, либо только `intervallocal`, либо только `perconnremote`
`interval`: секунды
`remoteIPs`: Обязателен только в том случае, если `mode` включает `intervalremote` или `perconnremote`; если поле не заполнено, адрес наследуется с вышестоящего уровня. Поддерживается нотация CIDR.
`remotePorts`: Обязателен только в том случае, если `mode` включает `intervalremote` или `perconnremote`; если поле не заполнено, адрес наследуется с вышестоящего уровня
## quicParams