Rename the project to shadowsocks-c while retaining ss-* commands, the embedding ABI, and legacy library/package lookup compatibility.
Replace libev with bundled libuv for IOCP/kqueue event backends, expand asynchronous runtime DNS coverage, and add actionlint/Ruff with strict clang-tidy failure handling. Validate native platforms, static builds, packaging, interoperability, sanitizers, and canonical/legacy consumers.
All 22 hosted checks pass at reviewed head a8493250eb.
Bundle pinned offline dependencies, remove libcork/libipset and submodule requirements, and add portable runtime helpers with relocatable static/shared library installations.
Add Clang static build validation for Linux/musl, macOS and Windows, real TCP/UDP and SIP003 interoperability coverage, and recorded performance tradeoffs. All 21 hosted checks pass at the reviewed PR head 8d504e6218.
find_library's search order puts CMAKE_PREFIX_PATH ahead of HINTS, so on
a Homebrew machine with both mbedtls (4.x) and the keg-only mbedtls@3,
the headers resolved to mbedtls@3 while the libraries resolved to 4.x.
That is not a link error but memory corruption at runtime:
mbedtls_cipher_context_t grew between the two versions, so every context
allocated with ss_malloc(sizeof(cipher_evp_t)) from the 3.x headers was
overrun by 4.x's mbedtls_cipher_init. It corrupted the heap in every
binary that sets up a cipher, and made the unit tests segfault inside an
unrelated malloc.
Pick a prefix that provides both the headers and libmbedcrypto and pin
every component to it, then verify at configure time that the header
version string matches what the linked library reports, so a mismatch
fails the build instead of corrupting memory.
* Modernize build: switch to CMake, add unit tests, fix man pages
Remove autotools (configure.ac, Makefile.am, m4/, autogen.sh) and make
CMake the sole build system. Enhance CMake with proper Find modules for
MbedTLS, libsodium, PCRE, and c-ares with version/feature detection.
Add support for connmarktos, nftables, stack protector, and MinGW.
Add 10 unit test suites (CTest) covering base64, buffer, cache, crypto,
jconf, json, netutils, ppbloom, rule, and utils modules. Add a Python
stress test measuring bandwidth per cipher with memory leak detection.
Fix man page typos ("Resovle" -> "Resolve"), document missing TCP buffer
options, fix ss-manager duplicate --executable entry, add example section
to ss-tunnel, and document --workdir and --nftables-sets options.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Migrate from PCRE to PCRE2
Replace legacy PCRE (libpcre3) with PCRE2 (libpcre2-8). PCRE1 has been
end-of-life since 2021.
- src/rule.h: use pcre2_code and pcre2_match_data types
- src/rule.c: pcre_compile -> pcre2_compile, pcre_exec -> pcre2_match,
pcre_free -> pcre2_code_free, with proper error message retrieval
- cmake/FindPCRE.cmake -> cmake/FindPCRE2.cmake: find libpcre2-8 via
pkg-config, pcre2-config, or manual search
- Update all CMakeLists.txt, config.h.cmake, configure.cmake, README.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Update Dockerfiles: use CMake build and pcre2-dev
The alpine Dockerfile still used autotools (autogen.sh/configure) which
were removed. Switch to cmake build and replace pcre-dev with pcre2-dev.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix Docker build: disable tests and remove git dep
The tests/ directory is excluded by .dockerignore, so pass
-DBUILD_TESTING=OFF to cmake. Submodules are already checked out
by actions/checkout, no need for git inside the container.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix Docker build: disable static libs (not available in alpine)
Alpine's mbedtls-dev only provides shared libraries. Disable static
build since Docker only needs shared binaries.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Rewrite GitHub Actions: build and test directly on runner
Replace Docker-based CI with direct cmake build on ubuntu-latest and
macos-latest. Install dependencies via apt/brew, build with cmake,
run unit tests with ctest.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix CI: use mbedtls@3 on macOS, disable static build
- macOS: brew's mbedtls is now v4 (incompatible), use mbedtls@3
- Disable static build since CI runners lack static lib packages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix test build on Linux: add stdint.h and link libm
- test_ppbloom.c: add missing #include <stdint.h> for uint8_t
- test_json: link against libm for pow() used in json.c
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix test_ppbloom link: add libm for bloom's log()
On Linux, libbloom uses log() which requires explicit -lm linkage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix Linux build: link libm for test_buffer and test_crypto, fix warnings
Both test_buffer and test_crypto link libbloom.so which uses log() from
libm. Also fix unused variable warnings in test_json.c that would fail
with -Werror.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix Linux build: link libm for test_jconf (json.c uses pow)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* CI: add unit test and stress test steps to GitHub Actions
Split the Test step into separate "Unit tests" (ctest) and "Stress test"
(stress_test.py with 10MB transfer across all AEAD ciphers) steps for
better visibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Replace udns with c-ares
* Get IO loop work
* Clean up
* Avoid initializing nameservers each query
* Add ARES_OPT_SERVERS
* Refine resolv_cancel
* Fix a memory leak
* Replace udns.h with ares.h
* Fix all inet_* fucntions
* Clean up
* Enable servers_ports when VERSION_MINOR >= 11
* Avoid ares_inet_XtoX
* Handle multipe nameservers correctly
* Use ares_set_servers for IPv4 and IPv6 mixed list
* Refine c-ares for udprelay
* Refine ares_set_servers()
* Refine the timer based on ares_timeout
* Avoid resolv_cancel
* Fix an issue of null pointer
* Fix another null pointer issue
* Refine the order of resolv_shutdown
* Fix the corrupted ev io