ssh — an outbound, sing-box type ssh. Accepted from: share link, sing-box JSON.
Schema checked against core 1.14.2-lx.11 · the link fragment (#…) is the node label
| Field | Value |
|---|---|
scheme |
ssh |
singbox_type |
ssh |
kind |
outbound |
sources |
uri, singbox |
| Core the schema was checked against | 1.14.2-lx.11 |
| URI fragment | label |
share link mapper node body sanitizer core config
ssh://…?… ──▶ link parameter ──▶ sing-box JSON, ──▶ checks each ──▶ what sing-box
becomes a body stored in state body field's is actually
field value started with
- Link parameters — the dictionary of the share link: every parameter this scheme understands, and the body field each one becomes.
- Body fields — the node body itself: the sing-box JSON kept in the launcher state. The rules here hold for every input alike — a share link, sing-box JSON, Xray JSON or a hand-filled form — because they are checked after the input has already become a body.
- Diagnosed problems — every warning code a node of this scheme can carry, and the field that raises it.
- Replacements — what is silently rewritten on the way in: other spellings of the same name, values normalized or substituted, and structural decisions the mapper takes before any value is judged.
- Degradation — the same rules grouped by outcome: what drops the node, what only drops a field, and what is merely worth knowing.
A bad value never breaks the whole config: the field is dropped, replaced or — at worst — the single node is. Each link parameter says which of the three happens to it, taken from the rule of the body field it maps to.
Everything a link of this scheme can carry. Maps to points at the body field the value lands in; If invalid is that field's own rule.
userinfo— user:password of the account.- Type:
user:password - Maps to:
user,password - If absent: filled in with
root→ssh_user_default
- Type:
host— The authority of the link: everything before:inscheme://…@host:port.- Maps to:
server - If invalid: node dropped →
field_missing
- Maps to:
port— The authority of the link: everything after:inscheme://…@host:port.- Maps to:
server_port - If invalid: node dropped →
port_invalid
- Maps to:
#fragment— The part after#: the name the node is shown under. It is not a body field — it is the nodelabel.
private_key— Inline private key.- Type: string
- Maps to:
private_key
private_key_path— Path to the private key file.- Supported by the desktop launcher only
- Type: string
- Maps to:
private_key_path
private_key_passphrase— Passphrase of the private key.- Type: string
- Maps to:
private_key_passphrase
host_key— Accepted server host keys.- Type: string
- Maps to:
host_key
host_key_algorithms— Accepted host key algorithms.- Type: string
- Maps to:
host_key_algorithms
client_version— SSH client version string.- Supported by the desktop launcher only
- Type: string
- Maps to:
client_version
The node body itself — the sing-box JSON kept in the launcher state. The path is the one used in that body, and the rules below apply to every input alike: a share link, sing-box JSON, Xray JSON or a hand-filled form.
server— Server address: domain or IP.- Type: string, format
host - Required: the node is dropped without it
- Set by link parameter:
host - If invalid: node dropped →
field_missing
- Type: string, format
server_port— Server port.- Type: uint16, format
port,1–65535 - Required: the node is dropped without it
- Set by link parameter:
port - If invalid: node dropped →
port_invalid
- Type: uint16, format
user— SSH user name.- Type: string, role
credential - Default:
root - Set by link parameter:
userinfo - If absent: filled in with
root→ssh_user_default
- Type: string, role
password— SSH password.- Type: string, secret
- Set by link parameter:
userinfo
private_key— Private key contents, PEM form.- Type: listable_string, secret, role
private_key - Set by link parameter:
private_key
- Type: listable_string, secret, role
private_key_path— Path to the private key file.- Type: string, secret
- Set by link parameter:
private_key_path
private_key_passphrase— Passphrase of the private key.- Type: string, secret
- Set by link parameter:
private_key_passphrase
host_key— Expected server host keys.- Type: listable_string
- Set by link parameter:
host_key
host_key_algorithms— Accepted host key algorithms.- Type: listable_string
- Set by link parameter:
host_key_algorithms
client_version— SSH client version string.- Type: string
- Set by link parameter:
client_version
cipher— Accepted ciphers.- Type: listable_string
mac— Accepted MAC algorithms.- Type: listable_string
kex_algorithm— Accepted key exchange algorithms.- Type: listable_string
detour— Tag of the outbound this connection is routed through.- Type: string, set by config build
bind_interface— Network interface the connection is bound to.- Type: string
inet4_bind_address— Local IPv4 address to bind to.- Type: string, format
ipv4 - If invalid: removed →
type_invalid
- Type: string, format
inet6_bind_address— Local IPv6 address to bind to.- Type: string
connect_timeout— Timeout for establishing the connection.- Type: duration
tcp_fast_open— Use TCP Fast Open.- Type: bool
- Default:
false
disable_tcp_keep_alive— Disable TCP keepalive on this connection.- Type: bool
- Default:
false
tcp_keep_alive— Idle time before the first TCP keepalive probe.- Type: duration, normalized:
duration_bare_seconds
- Type: duration, normalized:
tcp_keep_alive_interval— Interval between TCP keepalive probes.- Type: duration, normalized:
duration_bare_seconds
- Type: duration, normalized:
udp_fragment— Allow fragmenting UDP packets.- Type: bool, tristate
domain_resolver— DNS server tag used to resolve the server domain.- Type: string
network_strategy— Strategy for picking the outbound network interface. The core judges the value: the launcher passes it through unchecked.- Type: string
network_type— Interface types allowed for this connection. The core judges the values.- Type: listable_string
fallback_network_type— Interface types used when the primary ones are unavailable. The core judges the values.- Type: listable_string
fallback_delay— Delay before falling back to the secondary network type.- Type: duration
Every code that can be raised on a node of this scheme, including the ones coming from the shared TLS, transport, multiplex and dialer sub-schemas. Follow a code for what it means and what to do about it.
field_missingserver— the value does not fit the field → node dropped
port_invalidserver_port— the value does not fit the field → node dropped
ssh_user_defaultuser— the field is absent → filled in withroot
type_invalidinet4_bind_address— the value does not fit the field → removed
Values. What the sanitizer does to a value before it reaches the node body.
user— when absent, filled in withroot→ssh_user_defaulttcp_keep_alive— normalized:duration_bare_secondstcp_keep_alive_interval— normalized:duration_bare_seconds
The node is dropped
server_port— invalid valueserver— invalid value
The field is removed, the node lives on
inet4_bind_address— invalid value
The value is replaced, the node lives on
user— absent value is filled in withroot