Compare commits

..

No commits in common. "a07665c01f4b307ebcc7b16b0178ca75cdf534cc" and "b61ae3feacdd7cc1d1d46ae66b995f46436ed0bd" have entirely different histories.

6 changed files with 7 additions and 117 deletions

View File

@ -1,85 +0,0 @@
name: Release source tarball
on:
release:
types: [published]
workflow_dispatch:
permissions:
contents: read
jobs:
tarball:
permissions:
contents: write
id-token: write
attestations: write
name: "source tarball"
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: env
run: |
if [ -f RELEASE ]; then
RELEASE=$(tr -d ' \t\r\n' < RELEASE)
else
RELEASE=$(tr -d ' \t\r\n' < DEVEL)
fi
echo "RELEASE=$RELEASE" >> $GITHUB_ENV
- name: Create tarball
run: |
# git archive is reproducible from the tag: anyone can regenerate the
# tarball and compare it against the published checksum.
git archive --format=tar.gz -9 \
--prefix="3proxy-${{ env.RELEASE }}/" \
-o "3proxy-${{ env.RELEASE }}.tar.gz" HEAD
tar tzf "3proxy-${{ env.RELEASE }}.tar.gz" >/dev/null
ls -l *.tar.gz
- name: Get artifact
uses: actions/upload-artifact@v7
with:
name: "3proxy-${{ env.RELEASE }}-src"
path: "*.tar.gz"
- name: Import signing key
if: github.event_name == 'release'
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
mkdir -p ~/.gnupg && chmod 700 ~/.gnupg
printf 'allow-loopback-pinentry\n' > ~/.gnupg/gpg-agent.conf
gpgconf --kill gpg-agent || true
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
echo "GPG_KEYID=$KEYID" >> $GITHUB_ENV
- name: Checksums and detached signatures
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
sha256sum *.tar.gz > SHA256SUMS-src
for f in *.tar.gz SHA256SUMS-src; do
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$GPG_KEYID" --armor --detach-sign "$f"
done
sha256sum -c SHA256SUMS-src
gpg --verify SHA256SUMS-src.asc SHA256SUMS-src
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v4
with:
subject-path: |
*.tar.gz
- name: Upload to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.tar.gz *.tar.gz.asc SHA256SUMS-src SHA256SUMS-src.asc

View File

@ -15,8 +15,8 @@ For High/Critical patched version is released within 2 weeks
## Verifying downloads ## Verifying downloads
Release binaries and the source tarball are published with SHA256 checksums, an Release binaries are published with SHA256 checksums, an OpenPGP signature and
OpenPGP signature and a GitHub build provenance attestation. a GitHub build provenance attestation.
The release signing key is `3proxy-release-key.asc` in the root of this The release signing key is `3proxy-release-key.asc` in the root of this
repository, an RSA-4096 key: repository, an RSA-4096 key:
@ -40,18 +40,6 @@ gpg --verify SHA256SUMS-x86_64.asc SHA256SUMS-x86_64
sha256sum -c SHA256SUMS-x86_64 sha256sum -c SHA256SUMS-x86_64
``` ```
The source tarball published with each release is signed as well:
```
gpg --verify SHA256SUMS-src.asc SHA256SUMS-src
sha256sum -c SHA256SUMS-src
gpg --verify 3proxy-0.9.9.tar.gz.asc 3proxy-0.9.9.tar.gz
```
Prefer it over the `Source code (tar.gz)` link GitHub generates automatically:
only the published tarball is signed. It is produced with `git archive` from
the release tag, so it can be regenerated and compared byte for byte.
RPM packages are signed, the signature is checked by rpm itself: RPM packages are signed, the signature is checked by rpm itself:
``` ```
@ -72,3 +60,5 @@ verified with the GitHub CLI:
gh attestation verify 3proxy-0.9.9.x86_64.rpm --owner 3proxy gh attestation verify 3proxy-0.9.9.x86_64.rpm --owner 3proxy
gh attestation verify oci://docker.io/3proxy/3proxy:lts --owner 3proxy gh attestation verify oci://docker.io/3proxy/3proxy:lts --owner 3proxy
``` ```
Windows binaries are Authenticode signed in addition to the above.

View File

@ -1471,12 +1471,10 @@ allowed traffic in megabytes (MB). nocountin allows you to set exclusions.
For name resolution and caching, use the commands nserver, nscache / nscache6, and nsrecord. For name resolution and caching, use the commands nserver, nscache / nscache6, and nsrecord.
<pre> <pre>
nserver 192.168.1.2 nserver 192.168.1.2
nserver 192.168.1.3:5353/tcp nserver 192.168.1.3:5353/tcp</pre>
nserver [2001:4860:4860::8844]</pre>
sets DNS resolvers. 192.168.1.3 will be used via TCP/5353 (instead of default UDP/53) sets DNS resolvers. 192.168.1.3 will be used via TCP/5353 (instead of default UDP/53)
only if 192.168.1.2 fails. Up to 5 nservers may be specified. only if 192.168.1.2 fails. Up to 5 nservers may be specified.
If no nserver is configured, default system name resolution functions are used. If no nserver is configured, default system name resolution functions are used.
An IPv6 address has to be written in square brackets.
<pre> <pre>
nscache 65535 nscache 65535
nscache6 65535</pre> nscache6 65535</pre>

View File

@ -1536,13 +1536,11 @@ socks -p1080
nscache и nsrecord. nscache и nsrecord.
<pre> <pre>
nserver 192.168.1.2 nserver 192.168.1.2
nserver 192.168.1.3:5353/tcp nserver 192.168.1.3:5353/tcp</pre>
nserver [2001:4860:4860::8844]</pre>
указывает 3proxy какие машины следует использвоать в качестве серверов указывает 3proxy какие машины следует использвоать в качестве серверов
DNS. Сервер 192.168.1.3 будет использоваться по порту TCP/5353 (вместо дефолтного UDP/53) только при недостижимости DNS. Сервер 192.168.1.3 будет использоваться по порту TCP/5353 (вместо дефолтного UDP/53) только при недостижимости
192.168.1.2. Можно указать до 5 серверов. Если nserver не указан, будут 192.168.1.2. Можно указать до 5 серверов. Если nserver не указан, будут
использованы системные функции разрешения имен. использованы системные функции разрешения имен.
Адрес IPv6 необходимо записывать в квадратных скобках.
<pre> <pre>
nscache 65535 nscache 65535
nscache6 65535</pre> nscache6 65535</pre>

View File

@ -489,11 +489,7 @@ experimental.</p>
Nameserver to use for name resolutions. If none specified Nameserver to use for name resolutions. If none specified
system routines for name resolution is used. Optional port system routines for name resolution is used. Optional port
number may be specified. If optional /tcp is added to IP number may be specified. If optional /tcp is added to IP
address, name resolution is performed over TCP. An IPv6 address address, name resolution is performed over TCP.</p>
has to be enclosed in square brackets: <br>
<b>nserver 1.1.1.1</b> <br>
<b>nserver [2001:4860:4860::8844]</b> <br>
<b>nserver [2001:4860:4860::8844]:5353/tcp</b></p>
<p style="margin-left:6%; margin-top: 1em"><b>authnserver</b> <p style="margin-left:6%; margin-top: 1em"><b>authnserver</b>

View File

@ -514,13 +514,6 @@ system routines for name resolution is
used. Optional port number may be specified. used. Optional port number may be specified.
If optional /tcp is added to IP address, name resolution is If optional /tcp is added to IP address, name resolution is
performed over TCP. performed over TCP.
An IPv6 address has to be enclosed in square brackets:
.br
\fBnserver 1.1.1.1\fR
.br
\fBnserver [2001:4860:4860::8844]\fR
.br
\fBnserver [2001:4860:4860::8844]:5353/tcp\fR
.br .br
.BR authnserver .BR authnserver