Max Lv:欢迎 TrustTunnel 出站 PR,明确实现范围、特性门控与测试要求

在 TrustTunnel 出站功能提议(#727)下回复:接受该 PR,并给出要求。范围与形态——先做 HTTP/2(TCP、_udp2 与 _check)并单独成 PR,H3 后续另开;H3 复用现有 quiche + BoringSSL 栈(同 Hysteria2),不引入第二套 QUIC 或 TLS 库;在 meow-proxy 中以 trusttunnel 特性门控(同 snell、anytls),是否并入默认 full 组合由二进制体积数字决定(ADR-0007 上限);保持 mihomo 字段名与默认值,静态节点与 providers 共用一个解析器,不支持的选项显式报错,有意分歧按 ADR-0002 记录;TLS 走 meow_transport::tls::TlsLayer,BoringSSL 是运行时唯一加密库。测试——框架、流控及所列边界用例的 hermetic 单测很好;互操作需按 restls_e2e / jls_e2e / kcptun_e2e 的模式增加对官方 TrustTunnel 端点的 real-peer e2e:二进制路径来自环境变量、未设置时测试失败(绝不静默跳过),MEOW_*_E2E_ALLOW_SKIP=1 仅限本地运行,CI 构建或获取服务端;提交前跑 CLAUDE.md 的回归清单,并把新测试目标同时加入该清单与 .github/workflows/test.yml。另指出 h2 回归:workspace 当前解析到 h2 0.4.16,请单开 issue 附 empty-DATA 复现,再决定固定版本、绕过还是上报;建议一并报告给 hyperium/h2。若愿意可提前看 draft PR 并给架构反馈。

作者原文

Thanks for the detailed proposal. Yes, a TrustTunnel outbound PR is welcome. A few things will make review go smoothly:

Scope and shape

  • H2 first, in its own PR: TCP, _udp2 and _check. H3 can follow separately. For H3, please reuse the existing quiche + BoringSSL stack (as Hysteria2 does), not a second QUIC or TLS library.
  • Feature-gated: put it behind a trusttunnel feature in meow-proxy, like snell and anytls. Whether it joins the default full bundle can be settled with binary-size numbers (ADR-0007 caps).
  • Mihomo compatibility: keep mihomo's field names and defaults, with one parser shared by static nodes and providers. Make unsupported options explicit errors, and document any intentional divergence per ADR-0002.
  • TLS: go through meow_transport::tls::TlsLayer. BoringSSL is the only crypto library in the runtime.

Tests

  • Hermetic unit tests for framing, flow control and the edge cases you listed are great.
  • For interop, please add a real-peer e2e test against the official TrustTunnel endpoint, following the restls_e2e / jls_e2e / kcptun_e2e pattern:
  • The binary path comes from an env var, and the test fails (it never silently skips) when it's unset.
  • A MEOW_*_E2E_ALLOW_SKIP=1 escape exists for local runs only.
  • CI builds or fetches the server.
  • Run the regression bar in CLAUDE.md before submitting. Add the new test target to both that list and .github/workflows/test.yml.

The h2 0.4.19 regression
The workspace currently resolves h2 0.4.16. Please open a separate issue with the empty-DATA reproducer so we can decide between a pin, a workaround, or an upstream report before relying on it. It would also help to report it upstream to hyperium/h2 if you haven't.

Happy to review a draft PR early if you'd like feedback on the architecture before polishing.