From e40b5962e47aa683bb41b708efc52c7d228f5bf4 Mon Sep 17 00:00:00 2001 From: wwqgtxx Date: Mon, 20 Jul 2026 14:51:26 +0800 Subject: [PATCH] feat: add `rate-limit` for restls listener --- docs/config.yaml | 6 ++++++ go.mod | 2 +- go.sum | 4 ++-- listener/config/restls.go | 1 + listener/inbound/restls.go | 2 ++ listener/restls/restls.go | 1 + 6 files changed, 13 insertions(+), 3 deletions(-) diff --git a/docs/config.yaml b/docs/config.yaml index 8d08e3b8..a28cc1d3 100644 --- a/docs/config.yaml +++ b/docs/config.yaml @@ -2040,6 +2040,7 @@ listeners: # restls-script: "" # min-record-len: 0 # proxy: "" + # rate-limit: 0 # fallback 双向转发限速,单位 bit/s;0 表示不限速 # jls-config: # 仅封装 TCP;JLS 认证失败或普通 TLS 连接会透明回落到 dest # enable: false # users: @@ -2101,6 +2102,7 @@ listeners: # enable: false # dest: test.com:443 # password: restls-password + # rate-limit: 0 # fallback 双向转发限速,单位 bit/s;0 表示不限速 # jls-config: # enable: false # users: @@ -2193,6 +2195,7 @@ listeners: # # restls-script: "" # # min-record-len: 0 # # proxy: "" + # # rate-limit: 0 # fallback 双向转发限速,单位 bit/s;0 表示不限速 # 如果填写reality-config则开启reality(注意不可与certificate和private-key同时填写) # reality-config: # dest: test.com:443 @@ -2408,6 +2411,7 @@ listeners: # # restls-script: "" # # min-record-len: 0 # # proxy: "" + # # rate-limit: 0 # fallback 双向转发限速,单位 bit/s;0 表示不限速 ### 注意,对于vless listener, 如果 "allow-insecure" 不为 true, 至少需要填写 “certificate和private-key” 或 “shadow-tls” 或 “res-tls” 或 “jls-config” 或 “reality-config” 或 “decryption” 的其中一项 ### # allow-insecure: false # 是否允许不开启tls加密(注意:仅用于有 nginx, caddy 前置的情况) @@ -2449,6 +2453,7 @@ listeners: # # restls-script: "" # # min-record-len: 0 # # proxy: "" + # # rate-limit: 0 # fallback 双向转发限速,单位 bit/s;0 表示不限速 # jls-config: # JLS 替代普通 TLS;未认证连接回落到 dest # enable: true # users: @@ -2543,6 +2548,7 @@ listeners: # # restls-script: "" # # min-record-len: 0 # # proxy: "" + # # rate-limit: 0 # fallback 双向转发限速,单位 bit/s;0 表示不限速 # jls-config: # JLS 替代普通 TLS;未认证连接回落到 dest # enable: true # users: diff --git a/go.mod b/go.mod index 905dd648..b2b4a912 100644 --- a/go.mod +++ b/go.mod @@ -30,7 +30,7 @@ require ( github.com/metacubex/mlkem v0.1.0 github.com/metacubex/quic-go v0.59.1-0.20260606115121-0662b57ad5bf github.com/metacubex/randv2 v0.2.0 - github.com/metacubex/restls-client-go v0.1.8 + github.com/metacubex/restls-client-go v0.1.9 github.com/metacubex/sevenzip v1.6.4 github.com/metacubex/sing v0.5.7 github.com/metacubex/sing-mux v0.3.10 diff --git a/go.sum b/go.sum index c08b9991..9366f4b0 100644 --- a/go.sum +++ b/go.sum @@ -153,8 +153,8 @@ github.com/metacubex/quic-go v0.59.1-0.20260606115121-0662b57ad5bf h1:WvIp5pF+LL github.com/metacubex/quic-go v0.59.1-0.20260606115121-0662b57ad5bf/go.mod h1:2YEQEvFrZ5V76oynMBDTlN+4fdnSHCa2uNJxv3cm1HU= github.com/metacubex/randv2 v0.2.0 h1:uP38uBvV2SxYfLj53kuvAjbND4RUDfFJjwr4UigMiLs= github.com/metacubex/randv2 v0.2.0/go.mod h1:kFi2SzrQ5WuneuoLLCMkABtiBu6VRrMrWFqSPyj2cxY= -github.com/metacubex/restls-client-go v0.1.8 h1:0kQ699TWnbK3bWLhCPE0oIiBJLN+errOLQ9Z3/P1lbA= -github.com/metacubex/restls-client-go v0.1.8/go.mod h1:BN/U52vPw7j8VTSh2vleD/MnmVKCov84mS5VcjVHH4g= +github.com/metacubex/restls-client-go v0.1.9 h1:QmLKwVFuAjB6rL9lQNKj8CuwHqGMJjV36oskeBPEtVs= +github.com/metacubex/restls-client-go v0.1.9/go.mod h1:BN/U52vPw7j8VTSh2vleD/MnmVKCov84mS5VcjVHH4g= github.com/metacubex/sevenzip v1.6.4 h1:OIL+DeOeSAbKNsjqxcYUMiarRmX6Kaxakb0GT7E9Oik= github.com/metacubex/sevenzip v1.6.4/go.mod h1:FP3X9bzFKj9wPxifGN9B3w2fIEicMjzKYIGIhnu+1pw= github.com/metacubex/sing v0.5.7 h1:8OC+fhKFSv/l9ehEhJRaZZAOuthfZo68SteBVLe8QqM= diff --git a/listener/config/restls.go b/listener/config/restls.go index bfb559fb..e77cdd3d 100644 --- a/listener/config/restls.go +++ b/listener/config/restls.go @@ -8,6 +8,7 @@ type ResTLS struct { Password string RestlsScript string MinRecordLen int + RateLimit uint64 Proxy string } diff --git a/listener/inbound/restls.go b/listener/inbound/restls.go index 01e33e9f..2ca4d1a4 100644 --- a/listener/inbound/restls.go +++ b/listener/inbound/restls.go @@ -10,6 +10,7 @@ type ResTLS struct { Password string `inbound:"password"` RestlsScript string `inbound:"restls-script,omitempty"` MinRecordLen int `inbound:"min-record-len,omitempty"` + RateLimit uint64 `inbound:"rate-limit,omitempty"` Proxy string `inbound:"proxy,omitempty"` } @@ -20,6 +21,7 @@ func (r ResTLS) Build() LC.ResTLS { Password: r.Password, RestlsScript: r.RestlsScript, MinRecordLen: r.MinRecordLen, + RateLimit: r.RateLimit, Proxy: r.Proxy, } } diff --git a/listener/restls/restls.go b/listener/restls/restls.go index 741b246e..08fb565a 100644 --- a/listener/restls/restls.go +++ b/listener/restls/restls.go @@ -23,6 +23,7 @@ func New(config LC.ResTLS, tunnel C.Tunnel) *Builder { Password: config.Password, RestlsScript: config.RestlsScript, MinRecordLen: config.MinRecordLen, + RateLimit: config.RateLimit, DialContext: func(ctx context.Context, network, address string) (net.Conn, error) { return inner.HandleTcp(tunnel, address, config.Proxy) },