66using System . Net ;
77using System . Net . Quic ;
88using System . Net . Security ;
9+ using System . Runtime . InteropServices ;
910using System . Security . Authentication ;
1011using System . Security . Cryptography . X509Certificates ;
1112
@@ -14,10 +15,10 @@ namespace HiddifyConfigsCLI.src.Checking.Handshakers.Hysteria2
1415 /// <summary>
1516 /// Hysteria2 协议专用握手器(.NET 9 System.Net.Quic 纯实现)
1617 /// 完全遵循官方协议:TLS 1.3 + HTTP/3 /auth + 233 HyOK
17- /// 支持 mport 多端口随机选择、Up/DownMbps 带宽声明、随机 Padding
18- /// 支持 Salamander(BouncyCastle)、cipher 伪装、mport、完整异常处理
19- /// </summary>
20- // 重构:主流程极简清晰,职责完全解耦至 RequestBuilder & ResponseParser
18+ /// 支持: mport 多端口随机选择、Up/DownMbps 带宽声明、随机 Padding
19+ /// 支持: Salamander(BouncyCastle)、cipher 伪装、mport、完整异常处理
20+ /// 重构:主流程解耦至 RequestBuilder & ResponseParser
21+ /// </summary>
2122 internal static class Hysteria2Handshaker
2223 {
2324 /// <summary>
@@ -135,10 +136,40 @@ private static int ResolveTargetPort( Hysteria2Node node )
135136 // OpenSSL 后端:ClientHello 更接近浏览器(cipher order 优化),成功率提升至 70%+
136137 // 支持 node.Fingerprint:chrome (默认,JA3 771,4865-4866-4867,... )、firefox (4865-4866-4867-49195-52393,... )
137138 // GREASE:.NET 9 自动启用(EnabledSslProtocols.Tls13)
139+ // 强制尝试使用 OpenSSL 后端(Linux 有效)
140+ // Windows、macOS 会自动忽略此变量并回退 Schannel
138141 Environment . SetEnvironmentVariable ( "QUIC_TLS" , "openssl" ) ; // 仅连接前设置,fallback Schannel 若 OpenSSL 未安装
139142
140- var cipherPolicy = new CipherSuitesPolicy ( GetCipherSuites ( node . Fingerprint ) ) ; // 自定义 cipher 列表
141-
143+ // var cipherPolicy = new CipherSuitesPolicy(GetCipherSuites(node.Fingerprint)); // 自定义 cipher 列表
144+ CipherSuitesPolicy ? cipherPolicy = null ;
145+ bool cipherPolicySupported = false ;
146+
147+ // 只有在非 Windows 且明确支持 CipherSuitesPolicy 时才尝试自定义
148+ if ( ! RuntimeInformation . IsOSPlatform ( OSPlatform . Windows ) &&
149+ ! RuntimeInformation . IsOSPlatform ( OSPlatform . OSX ) )
150+ {
151+ try
152+ {
153+ // 尝试实例化一次 CipherSuitesPolicy,用于检测当前平台是否真正支持
154+ var testSuites = GetCipherSuites ( node . Fingerprint ) ;
155+ if ( testSuites is { Count : > 0 } )
156+ {
157+ cipherPolicy = new CipherSuitesPolicy ( testSuites ) ;
158+ cipherPolicySupported = true ;
159+ }
160+ }
161+ catch ( PlatformNotSupportedException )
162+ {
163+ // OpenSSL 版本太老或未正确加载,降级
164+ cipherPolicySupported = false ;
165+ LogHelper . Verbose ( "[Hysteria2] 当前平台不支持 CipherSuitesPolicy,降级使用默认 TLS 密码套件顺序" ) ;
166+ }
167+ }
168+ else
169+ {
170+ LogHelper . Verbose ( "[Hysteria2] Windows/macOS 平台不支持 CipherSuitesPolicy,使用系统默认 TLS 策略" ) ;
171+ }
172+
142173 // 原有配置(保留,用于 fallback)
143174 var fallbackOptions = new QuicClientConnectionOptions
144175 {
@@ -153,7 +184,11 @@ private static int ResolveTargetPort( Hysteria2Node node )
153184 ApplicationProtocols = alpnList ,
154185 EnabledSslProtocols = SslProtocols . Tls13 ,
155186 CertificateRevocationCheckMode = X509RevocationMode . NoCheck ,
156- CipherSuitesPolicy = cipherPolicy , // 新增:手动排序 cipher,模拟浏览器优先级
187+
188+ // CipherSuitesPolicy = cipherPolicy, // 新增:手动排序 cipher,模拟浏览器优先级
189+ // 仅在真正支持时才赋值,否则保持 null(系统默认)
190+ CipherSuitesPolicy = cipherPolicySupported ? cipherPolicy : null ,
191+
157192 RemoteCertificateValidationCallback = ( sender , cert , chain , errors ) =>
158193 {
159194 if ( errors == SslPolicyErrors . None )
@@ -169,7 +204,16 @@ private static int ResolveTargetPort( Hysteria2Node node )
169204 }
170205 } ;
171206
172- LogHelper . Verbose ( $ "[Hysteria2] TLS 伪装启用 → OpenSSL + { node . Fingerprint ?? "chrome" } cipher") ;
207+ // 日志提示用户当前实际使用的指纹策略
208+ if ( cipherPolicySupported )
209+ {
210+ LogHelper . Verbose ( $ "[Hysteria2] TLS 伪装启用 → OpenSSL + { node . Fingerprint ?? "chrome" } cipher 自定义顺序") ;
211+ }
212+ else
213+ {
214+ LogHelper . Verbose ( $ "[Hysteria2] TLS 伪装降级 → 使用系统默认 cipher 顺序(连通性优先)") ;
215+ }
216+
173217 return await QuicConnection . ConnectAsync ( fallbackOptions , ct ) . ConfigureAwait ( false ) ;
174218 }
175219
0 commit comments