Commit Graph
6 Commits
Author SHA1 Message Date
dependabot[bot] 8ae0ae6db4 Bump actions/setup-python from 6 to 7
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-11 07:22:31 +00:00
Max Lv bdc77408cb Rename to shadowsocks-c with libuv, async DNS and CI lint (#3051)
Rename the project to shadowsocks-c while retaining ss-* commands, the embedding ABI, and legacy library/package lookup compatibility.

Replace libev with bundled libuv for IOCP/kqueue event backends, expand asynchronous runtime DNS coverage, and add actionlint/Ruff with strict clang-tidy failure handling. Validate native platforms, static builds, packaging, interoperability, sanitizers, and canonical/legacy consumers.

All 22 hosted checks pass at reviewed head a8493250eb.
2026-09-11 14:18:37 +08:00
Max Lv 201e70c4bd Modernize C builds with offline dependencies and portable runtime helpers (#3050)
Bundle pinned offline dependencies, remove libcork/libipset and submodule requirements, and add portable runtime helpers with relocatable static/shared library installations.

Add Clang static build validation for Linux/musl, macOS and Windows, real TCP/UDP and SIP003 interoperability coverage, and recorded performance tradeoffs. All 21 hosted checks pass at the reviewed PR head 8d504e6218.
2026-09-11 13:42:11 +08:00
Max LvandClaude Fable 5 dd2704c857 Fix bugs found by clang-tidy triage; ratchet warning budget to zero (#3047)
Real bugs fixed:
- manager.c: kill_server/stop_server checked fscanf() != EOF, so malformed
  pid file content left pid uninitialized and passed it to kill(). Parse
  with fgets + ss_parse_int and require pid > 0.
- utils.c: get_default_conf() crashed on strlen(NULL) when HOME is unset
  (e.g. daemons started by init) and left a dangling static pointer after
  free(), a latent use-after-free on repeated calls. Use a static buffer
  and fall back to the system config when HOME is missing.
- local.c: in UDP_ONLY mode, start_ss_local_server() passed uninitialized
  listen_ctx.fd to the library callback. Initialize it to -1.

Improvements:
- Replace rand()/srand(time(NULL)) upstream-server selection in ss-local,
  ss-redir and ss-tunnel with libsodium randombytes_uniform(): unbiased,
  unpredictable, and no seeding required (cert-msc30/msc32).
- Mark FATAL() noreturn so both the compiler and analyzers understand
  control flow (removes a family of analyzer false positives).
- Drop two dead stores (manager.c restore_sigchld, udprelay.c src_addr_len).

All remaining findings were verified as false positives and carry NOLINT
comments with rationale (uthash macro internals, symmetric back-pointer
cleanup, analyzer-invisible postconditions). clang-tidy-18 on Linux now
reports zero warnings, so MAX_WARNINGS drops from 29 to 0.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-15 13:02:58 +08:00
Max LvandClaude Fable 5 ba7b9ad4cc Add code quality tooling: clang-tidy, sanitizers, coverage (#3046)
- Export compile_commands.json for tooling
- .clang-tidy: clang-analyzer + bugprone + cert checks scoped to src/,
  with stylistic/false-positive-prone checks disabled
- ENABLE_SANITIZERS CMake option (ASan + UBSan)
- ENABLE_COVERAGE CMake option with an lcov/genhtml 'coverage' target
- CI: asan job (ctest + stress test under ASan/UBSan), clang-tidy job
  (warning-count ratchet, baseline 29 with pinned clang-tidy-18),
  coverage job (lcov summary + HTML report artifact)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-15 12:24:57 +08:00
Max Lv 5559eec939 Harden security-sensitive input handling (#3045)
* harden security-sensitive input handling

* enable ctest failure checks in ci

* add valgrind leak smoke tests

* split tests into separate workflow
2026-07-15 11:10:24 +08:00