From 07a0437c131dc807364100c98984ca4b83dbd764 Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 10 Oct 2026 17:54:18 +0300 Subject: [PATCH] =?UTF-8?q?fix(3x-ui):=20restore=20reality443Forwarding=20?= =?UTF-8?q?=E2=80=94=20T10=20removal=20broke=20Xray=20REALITY?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Owner: 'reality443Forwarding точно ли стоило удалять? xray по прежнему не работает, несмотря на то, что ssh и pubray1.zeroq.su работают.' T10/C5 decision (б) was WRONG. modules/vds/nginx.nix was never touched and still routes: pubray1.zeroq.su → 127.0.0.1:2049 (panel) pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY) default → 127.0.0.1:15380 (fallback) Removing the container mapping 127.0.0.1:15380:443/tcp made the nginx stream forward TLS to a dead port → Xray REALITY unreachable. SSH and pubray1.zeroq.su kept working because they do NOT depend on 15380. Restored (exact pre-T10 code from 61b3724): - modules/options.nix: reality443Forwarding option - modules/vds/default.nix: reality443Forwarding = true - modules/containers/3x-ui.nix: realityPorts binding + ports = basePorts ++ realityPorts - manifest.json T10 → status 'pending' (reopened with corrected notes) Verified: nix eval .#nixosConfigurations.otreca...3xui_app.ports = [..., '127.0.0.1:15380:443/tcp'] --- .agent/tasks/manifest.json | 4 ++-- modules/containers/3x-ui.nix | 5 ++++- modules/options.nix | 23 +++++++++++++++++++---- modules/vds/default.nix | 7 +++++-- 4 files changed, 30 insertions(+), 9 deletions(-) diff --git a/.agent/tasks/manifest.json b/.agent/tasks/manifest.json index e1ec791..1b21221 100644 --- a/.agent/tasks/manifest.json +++ b/.agent/tasks/manifest.json @@ -175,7 +175,7 @@ "id": "T10", "title": "C5: решить судьбу reality443Forwarding", "type": "decision", - "status": "completed", + "status": "pending", "origin": "user:direct", "depends_on": [], "acceptance_criteria": [ @@ -184,7 +184,7 @@ ], "files": ["modules/vds/default.nix", "modules/options.nix", "modules/containers/3x-ui.nix"], "blocks": [], - "notes": "Решение (б): опция погашена. Удалена из options.nix:66-74, realityPorts из 3x-ui.nix:33-35, reality443Forwarding = true из vds/default.nix:19. ADR-note в options.nix (комментарий на месте удаления) + в 3x-ui.nix + vds/default.nix." + "notes": "REVERTED 2026-10-10. Решение (б) оказалось ОШИБОЧНЫМ: modules/vds/nginx.nix (не тронут) всё ещё маршрутизирует pubrayx1.zeroq.su/default → 127.0.0.1:15380, поэтому после удаления маппинга 127.0.0.1:15380:443/tcp nginx stream смотрит в мёртвый порт и Xray REALITY недоступен (владелец: 'xray по прежнему не работает'). Восстановлено: reality443Forwarding в options.nix, reality443Forwarding=true в vds/default.nix, realityPorts в 3x-ui.nix + ports = basePorts ++ realityPorts. Проверено: nix eval показывает [..., \"127.0.0.1:15380:443/tcp\"]. Решение вернуться к (а): опция нужна, её роль — публикация 15380→443 для nginx stream SNI-routing." }, { "id": "T11", diff --git a/modules/containers/3x-ui.nix b/modules/containers/3x-ui.nix index ba92508..bb9d6d6 100644 --- a/modules/containers/3x-ui.nix +++ b/modules/containers/3x-ui.nix @@ -30,6 +30,9 @@ let "127.0.0.1:2096:2096/tcp" "0.0.0.0:8443:8443/tcp" ]; + # VDS-only: nginx stream forwards host:443 → 127.0.0.1:15380 → + # container:443, so Xray sees its REALITY inbound on port 443. + realityPorts = lib.optional config.host."3x-ui".reality443Forwarding "127.0.0.1:15380:443/tcp"; in { # `host."3x-ui"` options are declared in modules/options.nix: they are set @@ -62,7 +65,7 @@ in log-driver = "journald"; # Adding a new inbound through the 3x-ui panel on a port outside # the 14380-15379 range requires extending basePorts and rebuilding. - ports = basePorts; + ports = basePorts ++ realityPorts; }; }; }; diff --git a/modules/options.nix b/modules/options.nix index c703052..93bf322 100644 --- a/modules/options.nix +++ b/modules/options.nix @@ -58,9 +58,24 @@ container at /root/cert/fullchain.pem and key.pem. ''; }; - # reality443Forwarding was removed (T10/C5, 2026-10-10). The - # option's purpose was lost after the c8d4a12 revert (manifest:177-178); - # nginx stream on otreca still works without it. See ADR-0002 - # in .agent/decisions/ for the decision record. + # Publish host:15380 → container:443. Only nodes that host an + # Xray REALITY inbound on container:443 need this (so nginx + # stream can forward TLS to Xray via 127.0.0.1:15380 while Xray + # itself sees incoming connections on its configured port 443). + # Set false on nodes that only run the 3x-ui panel. + # + # RESTORED 2026-10-10: this option was wrongly removed by T10/C5. + # modules/vds/nginx.nix still routes pubrayx1.zeroq.su/default → + # 127.0.0.1:15380, so without this mapping the nginx stream points + # at a dead port and Xray REALITY is unreachable. + reality443Forwarding = lib.mkOption { + type = lib.types.bool; + default = false; + description = '' + When true, publish host:15380 → container:443 so Xray + inside the container can serve REALITY on its real + configured port 443 (nginx stream forwards 443 → 15380). + ''; + }; }; } diff --git a/modules/vds/default.nix b/modules/vds/default.nix index 27b7e1d..21549ad 100644 --- a/modules/vds/default.nix +++ b/modules/vds/default.nix @@ -14,10 +14,13 @@ ]; # VDS hosts the public-facing Xray REALITY inbound on container:443, # fronted by nginx stream on host:443 → host:15380 → container:443. - # reality443Forwarding removed 2026-10-10 (T10/C5): option's purpose - # was lost after c8d4a12 revert; nginx stream on otreca still works. + # reality443Forwarding MUST stay true here: modules/vds/nginx.nix + # routes pubrayx1.zeroq.su/default → 127.0.0.1:15380, which only + # exists when this mapping is published. (Restored 2026-10-10 after + # T10/C5 wrongly removed it and broke Xray REALITY.) host."3x-ui" = { certDomain = "pubray1.zeroq.su"; + reality443Forwarding = true; }; systemd.tmpfiles.rules = [ (xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")