Leadaxe:sing-box-lx 移植 AWG 3.x 时按实际上界预留 tailroom,并在 RoutineEncryption 加夹取避免尺寸不匹配崩溃
在 shtorm-7/sing-box-extended issue #158(AmneziaWG 3.0 在 TUN 包且 ContentPaddingAddition > 16 时于 RoutineEncryption 触发 panic)中,Leadaxe 说明其自有 sing-box 下游(sing-box-lx)移植 AWG 3.x 的处理方式,与提案补丁略有不同:①注入元素按实际上界预留 tailroom,而非固定的 MaxMessageSize —— 设置 content_padding_addition 时用 addition.Hi(),随机 trailer 用 DefaultUdpWindow - datagramSize,其余用 PaddingMultiple;②作为安全网,RoutineEncryption 在封包前把所选 addition 夹取到 cap(elem.packet) - len(elem.packet) - Overhead,并原地写入 elem.buffer(不用 slices.Grow),使尺寸不匹配时缩短 padding 而非 panic。给出 tailroom、clamp 两处代码引用;e2e 测试覆盖 content_padding_addition=10-100(经 InputPacket)。并称报告者的修法也正确,夹取只是让该路径对未来尺寸变化更稳健。
作者原文@LeadaxeSame design point came up when we ported AWG 3.x into our sing-box downstream (sing-box-lx). We went slightly differently from the proposed patch, in case it's useful:
- Injected elements reserve tailroom for the actual upper bound instead of a flat
MaxMessageSize:addition.Hi()whencontent_padding_additionis set,DefaultUdpWindow - datagramSizefor random trailers,PaddingMultipleotherwise.- As a safety net,
RoutineEncryptionclamps the chosen addition tocap(elem.packet) - len(elem.packet) - Overheadbefore sealing, and seals in place intoelem.buffer(noslices.Grow). So a sizing mismatch shortens the padding instead of panicking.Ref: tailroom, clamp. An e2e test covers
content_padding_addition=10-100viaInputPacket.The reporter's fix is correct too; the clamp just makes the path robust against future sizing changes.