throne: 1.2.4 -> 1.3.1 (#566708)

This commit is contained in:
Toma
2026-09-30 11:10:10 +00:00
committed by GitHub
6 changed files with 35 additions and 168 deletions

View File

@@ -17645,6 +17645,12 @@
githubId = 85435692;
name = "Maxwell Berg";
};
Mahdi-zarei = {
email = "mahdi.zrei@gmail.com";
github = "Mahdi-zarei";
githubId = 80265960;
name = "Mahdi";
};
mahe = {
email = "matthias.mh.herrmann@gmail.com";
github = "2chilled";

View File

@@ -1,40 +0,0 @@
diff --git a/core/server/server.go b/core/server/server.go
index 4499a6d..4c14d1a 100644
--- a/core/server/server.go
+++ b/core/server/server.go
@@ -24,6 +24,7 @@ import (
"github.com/sagernet/sing-box/experimental/clashapi"
"github.com/sagernet/sing/common"
E "github.com/sagernet/sing/common/exceptions"
+ "golang.org/x/sys/unix"
"github.com/sagernet/sing/service"
"github.com/xtls/xray-core/core"
)
@@ -462,6 +463,27 @@ func (s *server) IsPrivileged(ctx context.Context, _ *gen.EmptyReq) (*gen.IsPriv
}, nil
}
+ if runtime.GOOS == "linux" {
+ caps := unix.CapUserHeader{
+ Version: unix.LINUX_CAPABILITY_VERSION_3,
+ Pid: 0, // current
+ }
+
+ var data [2]unix.CapUserData
+ err := unix.Capget(&caps, &data[0])
+
+ if err != nil {
+ return &gen.IsPrivilegedResponse{
+ HasPrivilege: To(false),
+ }, nil
+ }
+
+ // CAP_NET_ADMIN = 12
+ return &gen.IsPrivilegedResponse{
+ HasPrivilege: To((data[0].Effective & (1 << unix.CAP_NET_ADMIN)) != 0),
+ }, nil
+ }
+
return &gen.IsPrivilegedResponse{HasPrivilege: To(os.Geteuid() == 0)}, nil
}

View File

@@ -1,13 +0,0 @@
diff --git a/core/server/parentcheck/parentcheck.go b/core/server/parentcheck/parentcheck.go
index 0991a7f..58fd32f 100644
--- a/core/server/parentcheck/parentcheck.go
+++ b/core/server/parentcheck/parentcheck.go
@@ -11,6 +11,8 @@ import (
)
func CheckParentProcess() {
+ return
+
parentPath, err := getParentExePath(ParentPID)
if err != nil {
log.Fatalf("parent check: cannot read parent executable: %v", err)

View File

@@ -1,39 +0,0 @@
diff --git a/src/sys/linux/AutoRun.cpp b/src/sys/linux/AutoRun.cpp
index 1fafe35..a32e7fe 100644
--- a/src/sys/linux/AutoRun.cpp
+++ b/src/sys/linux/AutoRun.cpp
@@ -31,18 +31,9 @@ void AutoRun_SetEnabled(bool enable) {
QString desktopFileLocation = userAutoStartPath + appName + QLatin1String(".desktop");
QStringList appCmdList;
- if (QProcessEnvironment::systemEnvironment().contains("APPIMAGE")) {
- appCmdList << QProcessEnvironment::systemEnvironment().value("APPIMAGE");
- } else {
- appCmdList << QApplication::applicationFilePath();
- }
-
+ appCmdList << "Throne";
appCmdList << "-tray";
- if (Configs::dataManager->settingsRepo->flag_use_appdata) {
- appCmdList << "-appdata";
- }
-
if (enable) {
if (!QDir().exists(userAutoStartPath) && !QDir().mkpath(userAutoStartPath)) {
// qCWarning(lcUtility) << "Could not create autostart folder"
diff --git a/src/sys/linux/UrlScheme.cpp b/src/sys/linux/UrlScheme.cpp
index 63e4118..a9d3a42 100644
--- a/src/sys/linux/UrlScheme.cpp
+++ b/src/sys/linux/UrlScheme.cpp
@@ -14,9 +14,7 @@ static const QString kDesktopId = "throne-url-handler.desktop";
// For AppImage the launcher must point at the outer image ($APPIMAGE), not the
// extracted binary inside the mount, which disappears after exit.
static QString execTarget() {
- auto env = QProcessEnvironment::systemEnvironment();
- if (env.contains("APPIMAGE")) return env.value("APPIMAGE");
- return QApplication::applicationFilePath();
+ return "Throne";
}
static QString desktopFilePath() {

View File

@@ -1,51 +0,0 @@
diff --git a/src/global/Configs.cpp b/src/global/Configs.cpp
index 9600a95..ee38aaa 100644
--- a/src/global/Configs.cpp
+++ b/src/global/Configs.cpp
@@ -45,6 +45,12 @@ namespace Configs {
}
QString FindCoreRealPath() {
+ // find in PATH first
+ QString path_for_nixos = QStandardPaths::findExecutable("ThroneCore");
+ if (!path_for_nixos.isEmpty()) {
+ return path_for_nixos;
+ }
+
auto fn = QApplication::applicationDirPath() + "/ThroneCore";
#ifdef Q_OS_WIN
fn += ".exe";
diff --git a/src/ui/mainWindow/mainwindow_setup.cpp b/src/ui/mainWindow/mainwindow_setup.cpp
index 7bec187..0f04cc8 100644
--- a/src/ui/mainWindow/mainwindow_setup.cpp
+++ b/src/ui/mainWindow/mainwindow_setup.cpp
@@ -207,8 +207,7 @@ MainWindow::MainWindow(QWidget *parent) : QMainWindow(parent), ui(new Ui::MainWi
runOnNewThread([=, this] {GetDeviceDetails(); });
// Prepare core
- auto core_path = QApplication::applicationDirPath() + "/";
- core_path += "ThroneCore";
+ auto core_path = Configs::FindCoreRealPath();
bool coreDebugMode = (Configs::dataManager->settingsRepo->log_level == "debug");
diff --git a/src/ui/mainWindow/mainwindow_system.cpp b/src/ui/mainWindow/mainwindow_system.cpp
index f1a7504..efffd4a 100644
--- a/src/ui/mainWindow/mainwindow_system.cpp
+++ b/src/ui/mainWindow/mainwindow_system.cpp
@@ -193,6 +193,15 @@ bool MainWindow::get_elevated_permissions(ExitReason reason) {
return true;
}
if (Configs::IsAdmin()) return true;
+ QMessageBox::critical(
+ GetMessageBoxParent(),
+ tr("Unable to elevate privileges when installed with Nix"),
+ tr("Due to the read-only property of the Nix store, we cannot set suid for ThroneCore. If you are using NixOS, please install Throne via `programs.throne.enable` and then set the `programs.throne.tunMode.enable` option to elevate privileges."),
+ QMessageBox::Ok
+ );
+ return false;
+ // The following code isn't effective, preserve to avoid merge conflict
+
#ifdef Q_OS_LINUX
if (!Linux_HavePkexec()) {
MessageBoxWarning(software_name, "Please install \"pkexec\" first.");

View File

@@ -21,22 +21,24 @@
# To get the latest revision go to the rule-set branch and get the revision of the last commit
# Link: https://github.com/throneproj/routeprofiles/tree/rule-set
throne-srslist-info ? {
rev = "bf5016b114a2dee6a31aa269093de38892fb9df4";
hash = "sha256-RfyFSCecfY1SfvO62nW72+4JLAP7qX8KmmWFGhRrC8I=";
rev = "1aa995b5fc30c26b931a61171aea2ab49c3d1711";
hash = "sha256-jKYUjgxpE1zwcVv+9Fdj8H1QnPZpTzmzVsMfOMOKGFw=";
},
}:
stdenv.mkDerivation (finalAttrs: {
pname = "throne";
version = "1.2.4";
version = "1.3.1";
src = fetchFromGitHub {
owner = "throneproj";
repo = "Throne";
tag = finalAttrs.version;
hash = "sha256-fDaU3xjrpjeW8MePBaj5aNGJ2GrNQ3/M3LhtBoU+I/A=";
hash = "sha256-G1i8nFMabkg7qUbqYq/GYXsREXRcSXtDSO+RgiuulIE=";
};
# NKR_ELEVATION_HINT contains spaces
__structuredAttrs = true;
strictDeps = true;
nativeBuildInputs = [
@@ -51,21 +53,22 @@ stdenv.mkDerivation (finalAttrs: {
qt6Packages.qttools
];
cmakeFlags = [
# use a writable config dir
(lib.cmakeBool "NKR_PACKAGE" true)
# use ThroneCore from PATH first to make use of security wrappers
(lib.cmakeBool "NKR_CORE_IN_PATH" true)
# the Exec field of the auto-run and the scheme-handler .desktop files
(lib.cmakeFeature "NKR_DESKTOP_EXEC" "Throne")
# suid cannot be set on ThroneCore in the Nix store, so point users to the NixOS module instead
(lib.cmakeFeature "NKR_ELEVATION_HINT" "On NixOS, use programs.throne with tunMode.enable.")
];
env.INPUT_VERSION = finalAttrs.version;
# suppress errors in 3rdparty/simple-protobuf
env.NIX_CFLAGS_COMPILE = "-Wno-error=maybe-uninitialized";
patches = [
# disable suid request as it cannot be applied to ThroneCore in nix store
# and prompt users to use NixOS module instead. And use ThroneCore from PATH
# to make use of security wrappers
./nixos-disable-setuid-request.patch
# sets the Exec field of the auto-run and the scheme-handler .desktop files to use the Throne binary from PATH
./fix-desktop-exec.patch
];
preBuild =
let
srslist = fetchurl {
@@ -87,8 +90,7 @@ stdenv.mkDerivation (finalAttrs: {
install -Dm755 Throne -t "$out/share/throne/"
install -Dm644 "$src/res/public/Throne.png" -t "$out/share/icons/hicolor/512x512/apps/"
makeQtWrapper "$out/share/throne/Throne" "$out/bin/Throne" \
--append-flag "-appdata" # use writable config dir
makeQtWrapper "$out/share/throne/Throne" "$out/bin/Throne"
ln -s ${finalAttrs.passthru.core}/bin/ThroneCore "$out/share/throne/ThroneCore"
@@ -110,17 +112,15 @@ stdenv.mkDerivation (finalAttrs: {
passthru.core = buildGoModule {
pname = "throne-core";
inherit (finalAttrs) version src;
modRoot = "./core/server";
modRoot = "./core";
patches = [
# also check cap_net_admin so we don't have to set suid
./core-also-check-capabilities.patch
# skip cmd/schemagen, a development tool
subPackages = [ "." ];
# disable a security check, which hopefully is not too bad
./dont-check-parent.patch
];
# the main package has no tests, checkPhase would only rebuild all deps without -trimpath
doCheck = false;
vendorHash = "sha256-qr45kA/xw3NARNUAj5OMjNE1JUeYQXkEXArsyc9K5jA=";
vendorHash = "sha256-L189eeaYDdDKGJYT5vr412YpTgHptVfC4jpNSjNcyuk=";
nativeBuildInputs = [
protobuf
@@ -163,10 +163,13 @@ stdenv.mkDerivation (finalAttrs: {
"with_utls"
"with_dhcp"
"with_tailscale"
"with_openvpn"
"with_openconnect"
"badlinkname"
"tfogo_checklinkname"
"tfogo_checklinkname0"
"with_naive_outbound"
"with_purego" # use prebuilt .so instead of prebuilt .a files for cronet-go
"noparentcheck" # ThroneCore and its security-wrapper live under a different store path than the GUI
];
};
@@ -186,6 +189,7 @@ stdenv.mkDerivation (finalAttrs: {
maintainers = with lib.maintainers; [
tomasajt
aleksana
Mahdi-zarei
];
platforms = lib.platforms.linux;
sourceProvenance = with lib.sourceTypes; [