Add udp mask

EN Add udp mask

RU Add udp mask

Prettified Code!
This commit is contained in:
Fangliding
2026-02-01 01:44:50 +08:00
parent 303cbf1879
commit fad0551a49
6 changed files with 353 additions and 129 deletions
+104
View File
@@ -20,6 +20,9 @@ Transport specifies a stable method for data transmission. Generally, both ends
"grpcSettings": {},
"wsSettings": {},
"httpupgradeSettings": {},
"finalmask": {
"udp": []
},
"sockopt": {
"mark": 0,
"tcpMaxSeg": 1440,
@@ -101,6 +104,10 @@ Hysteria configuration for the current connection. Only valid when this connecti
Specific configurations related to transparent proxying.
> `finalmask`: [FinalMaskObject](#finalmaskobject)
FinalMask configuration, used for general traffic obfuscation.
### TLSObject
```json
@@ -888,3 +895,100 @@ E.g., waiting IP queue sorted as 46464646 (set to 1), 44664466 (set to 2).
> `maxConcurrentTry`: number
Max concurrent attempts. Prevents core from making massive connections if many IPs resolve but fail. Default 4. Set to 0 to disable happyEyeballs.
### FinalMaskObject
FinalMask applies a final layer of obfuscation to the traffic after the core has processed transport layer encryption, including TLS/REALITY. Currently, only UDP is supported.
```json
{
"udp": [
{
"type": "header-dns",
"settings": {
"domain": "[www.baidu.com](https://www.baidu.com)"
}
}
]
}
```
> `udp`: \[ list \]
An array representing the list of obfuscations applied to UDP traffic. Multiple obfuscations will be applied sequentially, layer by layer. The `settings` vary depending on the obfuscation type; see below.
> `mkcp-original`
The simple obfuscation that was previously applied by default in mKCP. You may need to configure this to connect to legacy mKCP servers. No additional configuration required.
> `mkcp-aes128gcm`
Corresponds to the original mKCP `seed` feature. Uses AES-128-GCM for obfuscation.
- `settings`:
```json
{
"password": "your-password"
}
```
`password` is the encryption password; it must be consistent between the server and the client.
> `header-dns`
Corresponds to the original mKCP DNS obfuscation.
- `settings`:
```json
{
"domain": "[www.example.com](https://www.example.com)"
}
```
`domain` is the domain name used for obfuscation.
> `header-dtls`
Corresponds to the original mKCP DTLS obfuscation. No additional configuration required.
> `header-srtp`
Corresponds to the original mKCP SRTP obfuscation. No additional configuration required.
> `header-utp`
Corresponds to the original mKCP uTP obfuscation. No additional configuration required.
> `header-wechat`
Corresponds to the original mKCP WeChat Video obfuscation. No additional configuration required.
> `header-wireguard`
Corresponds to the original mKCP WireGuard obfuscation. No additional configuration required.
> `xdns`
Experimental feature. Utilizes DNS queries to transport data (similar to DNSTT). It performs standard DNS TXT queries to transport the payload. Due to technical limitations, the resulting MTU is very small, making it incompatible with QUIC; it is recommended to use it with mKCP. Recommended MTU values: Client 130, Server 900.
- `settings`:
```json
{
"domain": "[www.example.com](https://www.example.com)"
}
```
`domain` is the domain name used for queries. Since the queries performed are standard, they can be forwarded through any UDP DNS server, although efficiency may be very suboptimal. To use this feature, the server needs to listen on port 53, and the proxy protocol should direct the target to a DNS server (e.g., 8.8.8.8:53). Additionally, you must own the domain specified in `domain` and point its NS record to your server.
> `salamander`
Salamander obfuscation (from Hysteria2).
- `settings`:
```json
{
"password": "your-password"
}
```
`password` is the obfuscation password; it must be consistent between the server and the client.
+7 -43
View File
@@ -20,15 +20,16 @@ Please ensure that the firewall configuration on the host is correct.
"downlinkCapacity": 20,
"congestion": false,
"readBufferSize": 1,
"writeBufferSize": 1,
"header": {
"type": "none",
"domain": "example.com"
},
"seed": "Password"
"writeBufferSize": 1
}
```
::: TIP
The `header` and `seed` fields have been removed. Please use [FinalMask](../transport.md#finalmaskobject) for configuration.
Additionally, the previously default mKCP obfuscation has also been removed. To connect to a legacy server, you need to configure `mkcp-original` in FinalMask.
:::
> `mtu`: number
Maximum Transmission Unit.
@@ -91,43 +92,6 @@ When high-speed transmission is required, specifying larger `readBufferSize` and
When the network speed does not exceed 20MB/s, the default value of 1MB can meet the demand; beyond that, you can appropriately increase the values of `readBufferSize` and `writeBufferSize`, and then manually balance the relationship between speed and memory.
:::
> `header`: [HeaderObject](#headerobject)
Packet header camouflage settings.
> `seed`: string
Optional obfuscation password. Uses the AES-128-GCM algorithm to obfuscate traffic data. Must be consistent between the client and the server.
This obfuscation mechanism cannot be used to guarantee the security of communication content, but it may help mitigate some forms of blocking.
> Currently, in test environments, no port blocking phenomena have been observed after enabling this setting compared to the original unobfuscated version.
### HeaderObject
```json
{
"type": "none",
"domain": "example.com"
}
```
> `type`: string
Camouflage type. Optional values are:
- `"none"`: Default value. No camouflage is performed; sent data is a packet without characteristics.
- `"srtp"`: Disguised as SRTP packets, recognized as video call data (e.g., FaceTime).
- `"utp"`: Disguised as uTP packets, recognized as BT download data.
- `"wechat-video"`: Disguised as WeChat video call packets.
- `"dtls"`: Disguised as DTLS 1.2 packets.
- `"wireguard"`: Disguised as WireGuard packets. (Not the real WireGuard protocol).
- `"dns"`: Some campus networks allow DNS queries without logging in. Adding a DNS header to KCP allows traffic to be disguised as DNS requests, potentially bypassing login requirements on some campus networks.
> `domain`: string
Used with the camouflage type `"dns"`. You can fill in any domain name.
## Credits
- [@skywind3000](https://github.com/skywind3000) Invented and implemented the KCP protocol.