Rename the project to shadowsocks-c while retaining ss-* commands, the embedding ABI, and legacy library/package lookup compatibility.
Replace libev with bundled libuv for IOCP/kqueue event backends, expand asynchronous runtime DNS coverage, and add actionlint/Ruff with strict clang-tidy failure handling. Validate native platforms, static builds, packaging, interoperability, sanitizers, and canonical/legacy consumers.
All 22 hosted checks pass at reviewed head a8493250eb.
Bundle pinned offline dependencies, remove libcork/libipset and submodule requirements, and add portable runtime helpers with relocatable static/shared library installations.
Add Clang static build validation for Linux/musl, macOS and Windows, real TCP/UDP and SIP003 interoperability coverage, and recorded performance tradeoffs. All 21 hosted checks pass at the reviewed PR head 8d504e6218.
Add tests/test_deb_build.sh with four phases:
1. Build .deb packages via dpkg-buildpackage
2. Verify all three packages contain expected files (binaries, man
pages, shared library, headers, pkg-config)
3. Install packages and resolve dependencies
4. Smoke-test installed binaries, ldconfig, and headers
Add a Linux-only CI step in build.yml to run the test.
Statically link the bundled submodule libraries (libcork, libipset,
libbloom) into all targets instead of building them as shared libs.
These are vendored code built from git submodules, not system
libraries, so static linking is correct and eliminates
dpkg-shlibdeps warnings about missing .so files.
Pass -DWITH_STATIC=OFF in debian/rules since debian build-depends
only provide shared library dev packages.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There is a race condition between shadowsocks-libev.service and
systemd-resolved.service after reboot/on boot. The shadowsocks
service tries to start before the dns service is started properly
and fails showing the corresponding errors in the logs.
This commit changes the "method" parameter in the debian/config.json
from "rc4-md5" to "chacha20-ietf-poly1305". rc4-md5 is unsafe and
there is support for a better AEAD ciphersuite.
Commit https://github.com/shadowsocks/shadowsocks-libev/commit/f32ac38c2f7aab09ec25131209954957518de42a
allows to use pwgen to generate the initial password at the first
installation. However it won't work when apg isn't installed because:
* the postinst script has errexit option set ("set -e")
* at the first installation of ss-libev, apg or pwgen will be called to
generate the initial password in config.json
* when apg isn't installed, "pathfind apg" would return 1
* and the postinst script will immediately exit due to "set -e"
This commit temporarily turn off the errexit option for pathfind()
debhelper 10 is available in the following Debian/Ubuntu releases:
- Debian 8.x Jessie (jessie-backports)
- Debian 9.x Stretch / unstable
- Ubuntu 16.04 Xenial (xenial-backports)
- Ubuntu 16.10 Yakkety
debhelper supports dh-autoreconf and dh-systemd by default, so we can
safely remove a few Build-Depends and dh params.
We also sync a few other files under debian/ folder with Debian release
3.0.2+ds-1~exp1.