feat: introduce DNS intercept mode infrastructure

Add --intercept-mode flag (dns/hard/off) with configuration support,
recovery bypass for captive portals, probe-based interception
verification, VPN DNS coexistence in the proxy layer, and IPv6
loopback listener guard.

Remove standalone mDNSResponder hack files — the port 53 binding
logic is now handled within the intercept mode infrastructure.

Squashed from intercept mode development on v1.0 branch (#497).
This commit is contained in:
Codescribe
2026-03-03 14:26:39 +07:00
committed by Cuong Manh Le
parent 12715e6f24
commit 1e8240bd1c
17 changed files with 1813 additions and 291 deletions
+4 -2
View File
@@ -541,10 +541,12 @@ func TestRebootstrapRace(t *testing.T) {
<-started
var wg sync.WaitGroup
wg.Add(goroutines)
for range goroutines {
wg.Go(func() {
go func() {
defer wg.Done()
uc.ensureSetupTransport()
})
}()
}
wg.Wait()