Compare commits

..

No commits in common. "a07665c01f4b307ebcc7b16b0178ca75cdf534cc" and "b61ae3feacdd7cc1d1d46ae66b995f46436ed0bd" have entirely different histories.

6 changed files with 7 additions and 117 deletions

View File

@ -1,85 +0,0 @@
name: Release source tarball
on:
release:
types: [published]
workflow_dispatch:
permissions:
contents: read
jobs:
tarball:
permissions:
contents: write
id-token: write
attestations: write
name: "source tarball"
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: env
run: |
if [ -f RELEASE ]; then
RELEASE=$(tr -d ' \t\r\n' < RELEASE)
else
RELEASE=$(tr -d ' \t\r\n' < DEVEL)
fi
echo "RELEASE=$RELEASE" >> $GITHUB_ENV
- name: Create tarball
run: |
# git archive is reproducible from the tag: anyone can regenerate the
# tarball and compare it against the published checksum.
git archive --format=tar.gz -9 \
--prefix="3proxy-${{ env.RELEASE }}/" \
-o "3proxy-${{ env.RELEASE }}.tar.gz" HEAD
tar tzf "3proxy-${{ env.RELEASE }}.tar.gz" >/dev/null
ls -l *.tar.gz
- name: Get artifact
uses: actions/upload-artifact@v7
with:
name: "3proxy-${{ env.RELEASE }}-src"
path: "*.tar.gz"
- name: Import signing key
if: github.event_name == 'release'
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
mkdir -p ~/.gnupg && chmod 700 ~/.gnupg
printf 'allow-loopback-pinentry\n' > ~/.gnupg/gpg-agent.conf
gpgconf --kill gpg-agent || true
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
echo "GPG_KEYID=$KEYID" >> $GITHUB_ENV
- name: Checksums and detached signatures
if: github.event_name == 'release'
env:
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
sha256sum *.tar.gz > SHA256SUMS-src
for f in *.tar.gz SHA256SUMS-src; do
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
-u "$GPG_KEYID" --armor --detach-sign "$f"
done
sha256sum -c SHA256SUMS-src
gpg --verify SHA256SUMS-src.asc SHA256SUMS-src
- name: Attest build provenance
if: github.event_name == 'release'
uses: actions/attest-build-provenance@v4
with:
subject-path: |
*.tar.gz
- name: Upload to release
if: github.event_name == 'release'
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.event.release.tag_name }}
run: gh release upload "$TAG" *.tar.gz *.tar.gz.asc SHA256SUMS-src SHA256SUMS-src.asc

View File

@ -15,8 +15,8 @@ For High/Critical patched version is released within 2 weeks
## Verifying downloads
Release binaries and the source tarball are published with SHA256 checksums, an
OpenPGP signature and a GitHub build provenance attestation.
Release binaries are published with SHA256 checksums, an OpenPGP signature and
a GitHub build provenance attestation.
The release signing key is `3proxy-release-key.asc` in the root of this
repository, an RSA-4096 key:
@ -40,18 +40,6 @@ gpg --verify SHA256SUMS-x86_64.asc SHA256SUMS-x86_64
sha256sum -c SHA256SUMS-x86_64
```
The source tarball published with each release is signed as well:
```
gpg --verify SHA256SUMS-src.asc SHA256SUMS-src
sha256sum -c SHA256SUMS-src
gpg --verify 3proxy-0.9.9.tar.gz.asc 3proxy-0.9.9.tar.gz
```
Prefer it over the `Source code (tar.gz)` link GitHub generates automatically:
only the published tarball is signed. It is produced with `git archive` from
the release tag, so it can be regenerated and compared byte for byte.
RPM packages are signed, the signature is checked by rpm itself:
```
@ -72,3 +60,5 @@ verified with the GitHub CLI:
gh attestation verify 3proxy-0.9.9.x86_64.rpm --owner 3proxy
gh attestation verify oci://docker.io/3proxy/3proxy:lts --owner 3proxy
```
Windows binaries are Authenticode signed in addition to the above.

View File

@ -1471,12 +1471,10 @@ allowed traffic in megabytes (MB). nocountin allows you to set exclusions.
For name resolution and caching, use the commands nserver, nscache / nscache6, and nsrecord.
<pre>
nserver 192.168.1.2
nserver 192.168.1.3:5353/tcp
nserver [2001:4860:4860::8844]</pre>
nserver 192.168.1.3:5353/tcp</pre>
sets DNS resolvers. 192.168.1.3 will be used via TCP/5353 (instead of default UDP/53)
only if 192.168.1.2 fails. Up to 5 nservers may be specified.
If no nserver is configured, default system name resolution functions are used.
An IPv6 address has to be written in square brackets.
<pre>
nscache 65535
nscache6 65535</pre>

View File

@ -1536,13 +1536,11 @@ socks -p1080
nscache и nsrecord.
<pre>
nserver 192.168.1.2
nserver 192.168.1.3:5353/tcp
nserver [2001:4860:4860::8844]</pre>
nserver 192.168.1.3:5353/tcp</pre>
указывает 3proxy какие машины следует использвоать в качестве серверов
DNS. Сервер 192.168.1.3 будет использоваться по порту TCP/5353 (вместо дефолтного UDP/53) только при недостижимости
192.168.1.2. Можно указать до 5 серверов. Если nserver не указан, будут
использованы системные функции разрешения имен.
Адрес IPv6 необходимо записывать в квадратных скобках.
<pre>
nscache 65535
nscache6 65535</pre>

View File

@ -489,11 +489,7 @@ experimental.</p>
Nameserver to use for name resolutions. If none specified
system routines for name resolution is used. Optional port
number may be specified. If optional /tcp is added to IP
address, name resolution is performed over TCP. An IPv6 address
has to be enclosed in square brackets: <br>
<b>nserver 1.1.1.1</b> <br>
<b>nserver [2001:4860:4860::8844]</b> <br>
<b>nserver [2001:4860:4860::8844]:5353/tcp</b></p>
address, name resolution is performed over TCP.</p>
<p style="margin-left:6%; margin-top: 1em"><b>authnserver</b>

View File

@ -514,13 +514,6 @@ system routines for name resolution is
used. Optional port number may be specified.
If optional /tcp is added to IP address, name resolution is
performed over TCP.
An IPv6 address has to be enclosed in square brackets:
.br
\fBnserver 1.1.1.1\fR
.br
\fBnserver [2001:4860:4860::8844]\fR
.br
\fBnserver [2001:4860:4860::8844]:5353/tcp\fR
.br
.BR authnserver