Skip to content

Latest commit

 

History

History
193 lines (161 loc) · 10.4 KB

File metadata and controls

193 lines (161 loc) · 10.4 KB

ssh

← index · diagnosed problems

ssh — an outbound, sing-box type ssh. Accepted from: share link, sing-box JSON.

Schema checked against core 1.14.2-lx.11 · the link fragment (#…) is the node label

Field Value
scheme ssh
singbox_type ssh
kind outbound
sources uri, singbox
Core the schema was checked against 1.14.2-lx.11
URI fragment label

How to read this page

share link          mapper                node body              sanitizer            core config
ssh://…?…           ──▶ link parameter   ──▶  sing-box JSON,    ──▶  checks each     ──▶  what sing-box
                     becomes a body         stored in state        body field's         is actually
                     field                                         value                started with
  • Link parameters — the dictionary of the share link: every parameter this scheme understands, and the body field each one becomes.
  • Body fields — the node body itself: the sing-box JSON kept in the launcher state. The rules here hold for every input alike — a share link, sing-box JSON, Xray JSON or a hand-filled form — because they are checked after the input has already become a body.
  • Diagnosed problems — every warning code a node of this scheme can carry, and the field that raises it.
  • Replacements — what is silently rewritten on the way in: other spellings of the same name, values normalized or substituted, and structural decisions the mapper takes before any value is judged.
  • Degradation — the same rules grouped by outcome: what drops the node, what only drops a field, and what is merely worth knowing.

A bad value never breaks the whole config: the field is dropped, replaced or — at worst — the single node is. Each link parameter says which of the three happens to it, taken from the rule of the body field it maps to.

Link parameters

Everything a link of this scheme can carry. Maps to points at the body field the value lands in; If invalid is that field's own rule.

Common

  • userinfo — user:password of the account.
  • host — The authority of the link: everything before : in scheme://…@host:port.
  • port — The authority of the link: everything after : in scheme://…@host:port.
  • #fragment — The part after #: the name the node is shown under. It is not a body field — it is the node label.

Protocol-specific

  • private_key — Inline private key.
  • private_key_path — Path to the private key file.
  • private_key_passphrase — Passphrase of the private key.
  • host_key — Accepted server host keys.
  • host_key_algorithms — Accepted host key algorithms.
  • client_version — SSH client version string.
    • Supported by the desktop launcher only
    • Type: string
    • Maps to: client_version

Body fields

The node body itself — the sing-box JSON kept in the launcher state. The path is the one used in that body, and the rules below apply to every input alike: a share link, sing-box JSON, Xray JSON or a hand-filled form.

  • server — Server address: domain or IP.
    • Type: string, format host
    • Required: the node is dropped without it
    • Set by link parameter: host
    • If invalid: node dropped → field_missing
  • server_port — Server port.
    • Type: uint16, format port, 1–65535
    • Required: the node is dropped without it
    • Set by link parameter: port
    • If invalid: node dropped → port_invalid
  • user — SSH user name.
    • Type: string, role credential
    • Default: root
    • Set by link parameter: userinfo
    • If absent: filled in with root → ssh_user_default
  • password — SSH password.
    • Type: string, secret
    • Set by link parameter: userinfo
  • private_key — Private key contents, PEM form.
    • Type: listable_string, secret, role private_key
    • Set by link parameter: private_key
  • private_key_path — Path to the private key file.
  • private_key_passphrase — Passphrase of the private key.
  • host_key — Expected server host keys.
    • Type: listable_string
    • Set by link parameter: host_key
  • host_key_algorithms — Accepted host key algorithms.
  • client_version — SSH client version string.
  • cipher — Accepted ciphers.
    • Type: listable_string
  • mac — Accepted MAC algorithms.
    • Type: listable_string
  • kex_algorithm — Accepted key exchange algorithms.
    • Type: listable_string
  • detour — Tag of the outbound this connection is routed through.
    • Type: string, set by config build
  • bind_interface — Network interface the connection is bound to.
    • Type: string
  • inet4_bind_address — Local IPv4 address to bind to.
    • Type: string, format ipv4
    • If invalid: removed → type_invalid
  • inet6_bind_address — Local IPv6 address to bind to.
    • Type: string
  • connect_timeout — Timeout for establishing the connection.
    • Type: duration
  • tcp_fast_open — Use TCP Fast Open.
    • Type: bool
    • Default: false
  • disable_tcp_keep_alive — Disable TCP keepalive on this connection.
    • Type: bool
    • Default: false
  • tcp_keep_alive — Idle time before the first TCP keepalive probe.
    • Type: duration, normalized: duration_bare_seconds
  • tcp_keep_alive_interval — Interval between TCP keepalive probes.
    • Type: duration, normalized: duration_bare_seconds
  • udp_fragment — Allow fragmenting UDP packets.
    • Type: bool, tristate
  • domain_resolver — DNS server tag used to resolve the server domain.
    • Type: string
  • network_strategy — Strategy for picking the outbound network interface. The core judges the value: the launcher passes it through unchecked.
    • Type: string
  • network_type — Interface types allowed for this connection. The core judges the values.
    • Type: listable_string
  • fallback_network_type — Interface types used when the primary ones are unavailable. The core judges the values.
    • Type: listable_string
  • fallback_delay — Delay before falling back to the secondary network type.
    • Type: duration

Diagnosed problems

Every code that can be raised on a node of this scheme, including the ones coming from the shared TLS, transport, multiplex and dialer sub-schemas. Follow a code for what it means and what to do about it.

Replacements

Values. What the sanitizer does to a value before it reaches the node body.

  • user — when absent, filled in with root → ssh_user_default
  • tcp_keep_alive — normalized: duration_bare_seconds
  • tcp_keep_alive_interval — normalized: duration_bare_seconds

Degradation

The node is dropped

  • server_port — invalid value
  • server — invalid value

The field is removed, the node lives on

  • inet4_bind_address — invalid value

The value is replaced, the node lives on

  • user — absent value is filled in with root