Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

UDP relay fails with "Operation not permitted (os error 1)" when sending response back to client

未关闭
#2,139 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
38/100
Issue 类型
缺陷
描述清晰度
需要澄清
活跃度
冷清
技术栈
linux, rust
领域
networking

调研方向

未指定源文件或测试。首先使用提供的 ssserver 配置在 Linux/OpenWrt 上复现 UDP relay 失败,然后跟踪从 upstream response 到 client send 的 relay path,并检查 IPv4-mapped client address;完成标准是 UDP responses 在没有 EPERM 的情况下到达 client,并且该行为由 regression test 覆盖。

由索引模型根据 Issue 内容生成。

描述

UDP relay fails with "Operation not permitted (os error 1)" when sending response back to client

Describe the Bug

TCP works normally, but UDP relay does not.

The server successfully receives UDP packets from clients and also receives responses from upstream servers (for example DNS responses from 1.0.0.1:53), but fails when sending the UDP response back to the client.

The log repeatedly shows:

WARN udp failed to send back 43 bytes to client [::ffff:122.96.37.88]:40906, from target 1.0.0.1:53, error: Operation not permitted (os error 1)

From the log, it appears that:

  1. Client → Server UDP traffic succeeds.
  2. Server → Upstream UDP traffic succeeds.
  3. Upstream → Server UDP response succeeds.
  4. Server → Client UDP response fails with EPERM.

TCP traffic works normally.

Steps to reproduce

  1. Start ssserver with UDP enabled.
  2. Connect using a Shadowsocks client with UDP enabled.
  3. Send DNS queries or any UDP traffic through the proxy.
  4. Observe server logs.

Expected behavior

UDP relay should work normally.

The server should forward UDP responses back to the client instead of reporting:

Operation not permitted (os error 1)

Actual behavior

The server receives upstream responses successfully but fails to send them back to the client.

Logs

INFO shadowsocks server 1.24.0

INFO shadowsocks tcp server listening on [::]:9999
INFO shadowsocks udp server listening on [::]:9999

WARN udp failed to send back 43 bytes to client [::ffff:122.96.37.88]:40906, from target 1.0.0.1:53, error: Operation not permitted (os error 1)

WARN udp failed to send back 43 bytes to client [::ffff:122.96.37.88]:13104, from target 1.0.0.1:53, error: Operation not permitted (os error 1)

WARN udp failed to send back 43 bytes to client [::ffff:122.96.37.88]:13105, from target 1.0.0.1:53, error: Operation not permitted (os error 1)

Environment

  • shadowsocks-rust 1.24.0
  • Linux 6.6.110
  • OpenWrt / ImmortalWrt 24.10.4
  • Server mode: TCP + UDP
  • Cipher: chacha20-ietf-poly1305

Configuration:

{
  "server": "::",
  "server_port": 9999,
  "mode": "tcp_and_udp",
  "method": "chacha20-ietf-poly1305"
}

Also tested with:

{
  "server": "0.0.0.0"
}

but the issue remains.

Additional Information

Verified:

  • TCP works correctly.
  • UDP requests reach the server.
  • Upstream DNS responses are received successfully.
  • The process has full capabilities (CAP_NET_ADMIN present).
  • Changing listen address from :: to 0.0.0.0 does not help.
  • Restarting the service does not help.

The issue seems to happen only when ssserver attempts to send the UDP response back to the client.

Is this a known issue with UDP relay on Linux/OpenWrt, or could additional debugging information help identify the cause?

主要语言
Rust
星标
10.9k
派生
1.5k
平均合并
4 天 41 分钟
30 天内合并 PR
9

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

shadowsocks/shadowsocks-rust 的其他 Issue

查看 shadowsocks/shadowsocks-rust 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。