wwqgtxx 5c1b8bfc31 chore: authenticate JLS ServerHello using its wire encoding
JLS authenticates the serialized ServerHello with only the random field zeroed. The previous marshalForJLS implementation reordered extensions to match rustls-jls's internal struct order, even when that order differed from the bytes sent on the wire.

That canonical order is not defined by TLS or the JLS specification and couples this package to a rustls-jls implementation detail. Use the normal marshal output when sending and the original wire bytes when receiving, preserving extension order and leaving the TLS transcript untouched.

This intentionally removes compatibility with rustls-jls clients that re-encode ServerHello extensions before JLS verification.
2026-07-16 09:04:31 +08:00
2026-07-07 10:48:02 +08:00
2026-07-14 17:22:01 +08:00
2024-08-16 14:15:36 +08:00
2023-01-14 18:10:22 +08:00
2023-11-03 21:58:21 +08:00
2022-04-28 14:18:54 +08:00
2025-10-26 11:10:40 +08:00
2022-12-15 13:25:18 +08:00
2023-11-03 21:58:21 +08:00
2019-10-18 11:12:35 +08:00
2021-12-09 17:54:53 +08:00

Meta Kennel
Meta Kernel

Another Mihomo Kernel.

Features

  • Local HTTP/HTTPS/SOCKS server with authentication support
  • VMess, VLESS, Shadowsocks, Trojan, Snell, TUIC, Hysteria protocol support
  • Built-in DNS server that aims to minimize DNS pollution attack impact, supports DoH/DoT upstream and fake IP.
  • Rules based off domains, GEOIP, IPCIDR or Process to forward packets to different nodes
  • Remote groups allow users to implement powerful rules. Supports automatic fallback, load balancing or auto select node based off latency
  • Remote providers, allowing users to get node lists remotely instead of hard-coding in config
  • Netfilter TCP redirecting. Deploy Mihomo on your Internet gateway with iptables.
  • Comprehensive HTTP RESTful API controller

Dashboard

A web dashboard with first-class support for this project has been created; it can be checked out at metacubexd.

Configration example

Configuration example is located at /docs/config.yaml.

Docs

Documentation can be found in mihomo Docs.

For development

Requirements: Go 1.20 or newer

Build mihomo:

git clone https://github.com/MetaCubeX/mihomo.git
cd mihomo && go mod download
go build

Set go proxy if a connection to GitHub is not possible:

go env -w GOPROXY=https://goproxy.io,direct

Build with gvisor tun stack:

go build -tags with_gvisor

IPTABLES configuration

Work on Linux OS which supported iptables

# Enable the TPROXY listener
tproxy-port: 9898

iptables:
  enable: true # default is false
  inbound-interface: eth0 # detect the inbound interface, default is 'lo'

Debugging

Check wiki to get an instruction on using debug API.

Credits

License

This software is released under the GPL-3.0 license.

In addition, any downstream projects not affiliated with MetaCubeX shall not contain the word mihomo in their names.

Languages
Python 100%