Skip to content

fix: support secured multi-secret handshakes and warm DC routing - #36

Draft
AndreyOsipuk wants to merge 5 commits into
dolonet:masterfrom
AndreyOsipuk:codex/fix-mtg-tspu-mask-rewind
Draft

fix: support secured multi-secret handshakes and warm DC routing#36
AndreyOsipuk wants to merge 5 commits into
dolonet:masterfrom
AndreyOsipuk:codex/fix-mtg-tspu-mask-rewind

Conversation

@AndreyOsipuk

Copy link
Copy Markdown

Summary

  • classify secured (dd) handshakes before FakeTLS parsing;
  • preserve/replay handshake bytes during protocol detection and mask-host fallback;
  • match multiple configured secrets for secured handshakes;
  • bypass FakeTLS/doppelganger for secured sessions;
  • add a bounded warm Telegram DC pool to absorb route/backoff flaps;
  • keep compatibility with existing FakeTLS (ee) clients.

Validation

  • targeted unit tests for obfuscation, anti-replay, connection rewind, and DC pool pass;
  • full suite reaches only existing external-network failures in httpbin-backed tests (mtglib/TestHTTPSRequest, network/TestRealHTTPRequest).

The production binary built from this branch is deployed to the mtg nodes behind pr5–pr8 relays. DD response shaping remains disabled in production because Android connectivity is faster and stable without the experimental fragmentation layer.

Andrey Osipuk added 5 commits July 23, 2026 11:33
mss-relay (cmd/mss-relay): TCP-релей с двухступенчатым MSS для РФ-плеча mtg.
Слушает с нормальным MSS (клиентский ClientHello доезжает целиком), на время
первого ответа сервера ставит TCP_MAXSEG=92 (анти-DPI для ТСПУ), потом возвращает
полный размер - приём telemt client_mss_bulk, но на уровне релея. Цель - убрать
второй порт и iptables-клейм, свести mtg-плечо к одному порту как :443 у telemt.

ВАЖНО: на живом тесте (pr7, 27.08) сотовый Android по dd НЕ подключился без
постоянного клейма - ему мелкий MSS нужен весь сеанс, а не только на рукопожатие.
iPhone/Windows/ee при этом работали. Бинарь готов и оттестирован, но в проде пока
socat+клейм: релей ждёт решения (двойной шейпинг с MTG_DD_SHAPE или отдельный
порт под ee). 4 теста на порядок переключения MSS и прозрачность данных.

proxy_stats: RejectReason-счётчики (initial_bytes/secured_handshake/client_hello/
replay/welcome) в /stats. Раньше в статистике были только успешные подключения -
клиент с обрезанным рукопожатием (Windows FakeTLS) был невидим, ловили tcpdump'ом.
Теперь отказы видны в JSON, watchdog сможет алертить по росту.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant