From e858ec2f5e69b8a110842746628310c406d31fea Mon Sep 17 00:00:00 2001 From: Arvin <62139570+wnlen@users.noreply.github.com> Date: Wed, 19 Aug 2026 09:37:42 +0800 Subject: [PATCH] Fix TUN status with auto-redirect disabled --- scripts/core/clashctl.sh | 6 +++--- .../dev/check-tun-policy-routing-status.sh | 20 +++++++++++++++---- 2 files changed, 19 insertions(+), 7 deletions(-) diff --git a/scripts/core/clashctl.sh b/scripts/core/clashctl.sh index 6373e44..6391897 100644 --- a/scripts/core/clashctl.sh +++ b/scripts/core/clashctl.sh @@ -2006,7 +2006,7 @@ print_tun_off_feedback() { } tun_resolve_effective_result() { - local result auto_redirect + local result auto_route result="${1:-unknown}" case "$result" in @@ -2020,8 +2020,8 @@ tun_resolve_effective_result() { ;; esac - auto_redirect="$(runtime_config_tun_auto_redirect 2>/dev/null || echo false)" - if [ "${auto_redirect:-false}" = "true" ] && tun_has_policy_routing_evidence 2>/dev/null; then + auto_route="$(runtime_config_tun_auto_route 2>/dev/null || echo false)" + if [ "${auto_route:-false}" = "true" ] && tun_has_policy_routing_evidence 2>/dev/null; then if tun_log_tun_source_line >/dev/null 2>&1; then echo "ok" else diff --git a/scripts/dev/check-tun-policy-routing-status.sh b/scripts/dev/check-tun-policy-routing-status.sh index 871f20b..121ea1a 100755 --- a/scripts/dev/check-tun-policy-routing-status.sh +++ b/scripts/dev/check-tun-policy-routing-status.sh @@ -25,20 +25,24 @@ assert_equal() { echo "ok - $name" } -# Reproduce Issue #303: policy routing sends both direct-looking probes through -# Tun, so comparing their public IPs alone reports traffic-same-as-host. +# Reproduce Issues #303 and #309: policy routing sends both direct-looking +# probes through Tun, so comparing their public IPs alone reports +# traffic-same-as-host. The fallback must follow auto-route, including when +# auto-redirect is disabled. tun_enabled() { printf 'true\n'; } runtime_config_tun_enabled() { printf 'true\n'; } status_is_running() { return 0; } proxy_controller_reachable() { return 0; } tun_public_ip_without_proxy_env() { printf '203.0.113.10\n'; } tun_public_ip_with_current_route() { printf '203.0.113.10\n'; } -runtime_config_tun_auto_redirect() { printf 'true\n'; } +test_auto_route="true" +runtime_config_tun_auto_route() { printf '%s\n' "$test_auto_route"; } +runtime_config_tun_auto_redirect() { printf 'false\n'; } tun_has_policy_routing_evidence() { return 0; } tun_log_tun_source_line() { printf '[TCP] 28.0.0.1:1234 --> example.com:443\n'; } assert_equal \ - "accepts policy routing with observed Tun traffic" \ + "accepts auto-route policy routing when auto-redirect is disabled" \ "ok" \ "$(tun_current_effective_result)" @@ -54,6 +58,14 @@ assert_equal \ "likely-effective" \ "$(status_tun_effective_status)" +# Do not let stale policy-routing evidence override a runtime configuration that +# explicitly disables auto-route. +test_auto_route="false" +assert_equal \ + "requires auto-route before accepting policy routing evidence" \ + "traffic-same-as-host" \ + "$(tun_current_effective_result)" + # Reproduce the restart race: verification must happen only after waiting for # the controller following service_restart. tmp_dir="$(mktemp -d)"