Compare commits

..
15 Commits
Author SHA1 Message Date
action 7f7cbbe9c8 update 2026-09-16 17:00:28 2026-09-16 17:00:28 +08:00
action f5923596c5 update 2026-09-16 10:57:20 2026-09-16 10:57:20 +08:00
action 1dab9d1364 update 2026-09-16 06:39:05 2026-09-16 06:39:05 +08:00
action d98dc86e1e update 2026-09-16 00:04:48 2026-09-16 00:04:48 +08:00
action b109228443 update 2026-09-15 17:08:00 2026-09-15 17:08:00 +08:00
action bb8ab7ae16 update 2026-09-15 11:00:48 2026-09-15 11:00:48 +08:00
action c323f3b64e update 2026-09-15 01:28:15 2026-09-15 01:28:15 +08:00
action fcd7d31b29 update 2026-09-14 17:28:54 2026-09-14 17:28:54 +08:00
action 87faec277a update 2026-09-14 10:58:48 2026-09-14 10:58:48 +08:00
action d341a782d4 update 2026-09-14 06:01:57 2026-09-14 06:01:57 +08:00
action 205be274cd update 2026-09-14 02:28:52 2026-09-14 02:28:52 +08:00
action 622dd92021 update 2026-09-13 23:28:56 2026-09-13 23:28:56 +08:00
action 141863e6d4 update 2026-09-13 16:42:22 2026-09-13 16:42:22 +08:00
action 2e55e363ac update 2026-09-13 10:43:38 2026-09-13 10:43:38 +08:00
action 86d911baf4 update 2026-09-13 05:53:41 2026-09-13 05:53:41 +08:00
74 changed files with 1375 additions and 1032 deletions
+2 -2
View File
@@ -5,12 +5,12 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=brook
PKG_VERSION:=20260101.0
PKG_VERSION:=20270101
PKG_RELEASE:=1
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_SOURCE_URL:=https://codeload.github.com/txthinking/brook/tar.gz/v$(PKG_VERSION)?
PKG_HASH:=8ddba4ed9ae9d10928e169f8121c6791e0e3c2907fa27d6e0055fe434f6e700e
PKG_HASH:=43d8e5476918daa2d35fc63e8b0c94c0c1df8577f1d09103a3ab0f6141f29c0f
PKG_MAINTAINER:=Tianling Shen <cnsztl@immortalwrt.org>
PKG_LICENSE:=GPL-3.0
+4 -4
View File
@@ -1,8 +1,8 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=clashoo
PKG_SHORT_SHA:=dca26db
PKG_COMMIT_DATE:=2026.09.11
PKG_SHORT_SHA:=fbb6742
PKG_COMMIT_DATE:=2026.09.16
PKG_VERSION:=$(PKG_COMMIT_DATE)~$(PKG_SHORT_SHA)
PKG_RELEASE:=1
@@ -11,8 +11,8 @@ PKG_SOURCE:=$(PKG_NAME)-alpha-$(PKG_SHORT_SHA).tar.gz
PKG_SOURCE_SUBDIR:=$(PKG_NAME)-alpha-$(PKG_SHORT_SHA)
PKG_BUILD_DIR:=$(BUILD_DIR)/$(PKG_NAME)-alpha-$(PKG_SHORT_SHA)
PKG_SOURCE_URL:=https://github.com/kenzok8/openwrt-clashoo/releases/download/mihomo-src
PKG_SOURCE_VERSION:=dca26db017bcde90071f3e16f97b12fafbccfa31
PKG_HASH:=593e53b3aeb52bbd3f49ddf4ae7773ce340bf2e984a9d5634a6385fa3041b5a2
PKG_SOURCE_VERSION:=fbb674227d5cf5a3796a1dd1451849fa1872884a
PKG_HASH:=ecdd7fb1d5847884b350317e09c6d366fe6ea57e96f3ac0cd928df110f541ac8
PKG_BUILD_VERSION:=alpha-$(PKG_SHORT_SHA)
PKG_LICENSE:=GPL3.0+
@@ -939,6 +939,7 @@ set clashoo_china6 {
2402:7240::/32,
2402:72a0::/32,
2402:72c0::/32,
2402:73e0::/32,
2402:7540::/32,
2402:75c0::/32,
2402:7740::/32,
@@ -1246,11 +1247,12 @@ set clashoo_china6 {
2403:6280::/32,
2403:62c0::/32,
2403:6380::/42,
2403:6380:41::/48,
2403:6380:43::/48,
2403:6380:44::/46,
2403:6380:48::/45,
2403:6380:50::/44,
2403:6380:70::/44,
2403:6380:60::/43,
2403:6380:80::/41,
2403:6380:100::/40,
2403:6380:200::/39,
@@ -2036,7 +2038,7 @@ set clashoo_china6 {
2406:840:a18::/45,
2406:840:a20::/44,
2406:840:a30::/48,
2406:840:a32::/47,
2406:840:a33::/48,
2406:840:a34::/46,
2406:840:a38::/45,
2406:840:a40::/42,
@@ -2337,7 +2339,10 @@ set clashoo_china6 {
2406:840:e57f::/48,
2406:840:e580::/41,
2406:840:e610::/44,
2406:840:e620::/43,
2406:840:e622::/47,
2406:840:e624::/46,
2406:840:e628::/45,
2406:840:e630::/44,
2406:840:e640::/43,
2406:840:e660::/46,
2406:840:e664::/47,
@@ -2448,6 +2453,10 @@ set clashoo_china6 {
2406:840:f600::/42,
2406:840:f640::/43,
2406:840:f670::/44,
2406:840:f680::/47,
2406:840:f682::/48,
2406:840:f684::/46,
2406:840:f688::/45,
2406:840:f690::/44,
2406:840:f6a0::/43,
2406:840:f6c0::/42,
@@ -3039,7 +3048,6 @@ set clashoo_china6 {
2408:4008::/29,
2408:4010::/30,
2408:4014::/31,
2408:4016:1::/48,
2408:4016:2::/47,
2408:4016:4::/46,
2408:4016:8::/45,
@@ -920,7 +920,9 @@ set clashoo_china {
59.153.136.0/22,
59.153.152.0/22,
59.153.164.0/22,
59.153.168.0/21,
59.153.168.0/22,
59.153.173.0/24,
59.153.174.0/23,
59.153.176.0/20,
59.153.192.0/22,
59.155.0.0/16,
@@ -951,6 +953,7 @@ set clashoo_china {
61.29.128.0/18,
61.29.192.0/19,
61.29.224.0/20,
61.29.251.0/24,
61.45.128.0/18,
61.45.224.0/20,
61.47.128.0/18,
@@ -2186,6 +2189,7 @@ set clashoo_china {
103.143.132.0/22,
103.143.174.0/23,
103.143.228.0/23,
103.144.41.0/24,
103.144.66.0/23,
103.144.70.0/23,
103.144.72.0/23,
@@ -2341,7 +2345,7 @@ set clashoo_china {
103.176.244.0/23,
103.177.28.0/23,
103.177.44.0/23,
103.177.70.0/23,
103.177.71.0/24,
103.177.162.0/23,
103.178.240.0/23,
103.179.76.0/22,
@@ -2754,6 +2758,7 @@ set clashoo_china {
103.238.24.0/21,
103.238.32.0/21,
103.238.40.0/22,
103.238.46.0/23,
103.238.48.0/21,
103.238.56.0/22,
103.238.88.0/21,
@@ -3224,7 +3229,10 @@ set clashoo_china {
114.112.228.0/24,
114.112.230.0/23,
114.112.234.0/23,
114.112.240.0/20,
114.112.240.0/21,
114.112.248.0/22,
114.112.252.0/23,
114.112.255.0/24,
114.113.0.0/17,
114.113.128.0/21,
114.113.140.0/22,
@@ -3394,7 +3402,9 @@ set clashoo_china {
117.134.128.0/18,
117.134.205.0/24,
117.134.207.0/24,
117.134.208.0/20,
117.134.208.0/23,
117.134.212.0/23,
117.134.216.0/21,
117.134.232.0/21,
117.134.240.0/20,
117.135.0.0/16,
@@ -3746,7 +3756,6 @@ set clashoo_china {
123.49.236.0/24,
123.49.240.0/24,
123.49.242.0/23,
123.49.245.0/24,
123.49.248.0/21,
123.50.160.0/19,
123.52.0.0/14,
@@ -3981,7 +3990,14 @@ set clashoo_china {
140.179.0.0/16,
140.205.0.0/16,
140.206.0.0/15,
140.210.0.0/16,
140.210.0.0/20,
140.210.16.0/21,
140.210.24.0/22,
140.210.28.0/23,
140.210.30.0/24,
140.210.32.0/19,
140.210.64.0/18,
140.210.128.0/17,
140.224.0.0/16,
140.237.0.0/16,
140.240.0.0/16,
@@ -4214,6 +4230,7 @@ set clashoo_china {
163.47.4.0/22,
163.52.28.0/23,
163.52.76.0/23,
163.52.108.0/23,
163.53.0.0/20,
163.53.36.0/22,
163.53.40.0/21,
Binary file not shown.
Binary file not shown.
@@ -301,9 +301,10 @@ package_version_from_url() {
case "$file" in
clashoo_*_"$ARCH".ipk)
v="${file#clashoo_}"
printf '%s\n' "${v%_${ARCH}.ipk}"
v="${v%_${ARCH}.ipk}"
printf '%s\n' "$v" | sed 's/^\([0-9][0-9][0-9][0-9]\.[0-9][0-9]*\.[0-9][0-9]*\)\./\1~/'
;;
clashoo_*.ipk) printf '%s\n' "$file" | sed -n 's/^clashoo_\(.*\)_[^_][^_]*\.ipk$/\1/p' ;;
clashoo_*.ipk) printf '%s\n' "$file" | sed -n 's/^clashoo_\(.*\)_[^_][^_]*\.ipk$/\1/p' | sed 's/^\([0-9][0-9][0-9][0-9]\.[0-9][0-9]*\.[0-9][0-9]*\)\./\1~/' ;;
luci-app-clashoo_*.ipk) printf '%s\n' "$file" | sed -n 's/^luci-app-clashoo_\(.*\)_all\.ipk$/\1/p' ;;
luci-i18n-clashoo-zh-cn_*.ipk) printf '%s\n' "$file" | sed -n 's/^luci-i18n-clashoo-zh-cn_\(.*\)_all\.ipk$/\1/p' ;;
clashoo-*.apk)
+4 -4
View File
@@ -5,13 +5,13 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=dae
PKG_VERSION:=2026.09.06
PKG_RELEASE:=2
PKG_VERSION:=2026.09.12
PKG_RELEASE:=1
PKG_SOURCE:=dae-src-2026.09.06-80525dabf966.tar.gz
PKG_SOURCE:=dae-src-2026.09.12-187058462a1f.tar.gz
PKG_SOURCE_URL:=https://github.com/kenzok8/openwrt-daede/releases/download/dae-src
PKG_SOURCE_SUBDIR:=$(PKG_NAME)-$(PKG_VERSION)
PKG_HASH:=80525dabf966403524f3eac4ca46bb520ae487177b77e4b7b4482d24c2aa923e
PKG_HASH:=187058462a1fd9eeb9885f4971ccf4bc81358533e71730d8509bd7968624c1c7
PKG_LICENSE:=AGPL-3.0-only
PKG_LICENSE_FILE:=LICENSE
+4 -4
View File
@@ -5,13 +5,13 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=daed
PKG_VERSION:=2026.09.06
PKG_RELEASE:=2
PKG_VERSION:=2026.09.12
PKG_RELEASE:=1
PKG_SOURCE:=daed-src-2026.09.06-62f2e24ac52a.tar.gz
PKG_SOURCE:=daed-src-2026.09.12-a0181f729855.tar.gz
PKG_SOURCE_URL:=https://github.com/kenzok8/openwrt-daede/releases/download/daed-src
PKG_SOURCE_SUBDIR:=$(PKG_NAME)-$(PKG_VERSION)
PKG_HASH:=62f2e24ac52a6897633d0a0ed43d5a2419164ae43fa26e5c6fe11b5fe973fa61
PKG_HASH:=a0181f7298552497ed193e683a54b1df77f2d5441524d61989f3e3e3cf6eac51
PKG_LICENSE:=AGPL-3.0-only MIT
PKG_LICENSE_FILES:=LICENSE wing/LICENSE
+83 -4
View File
@@ -1,8 +1,65 @@
#!/bin/sh
# daed-cleanup.sh — reaper for stale daed kernel state.
#
# Removes:
# 1. Processes inside the `daens` netns (SIGTERM, then SIGKILL after 1s)
# 2. The `daens` network namespace itself (ip netns del, with
# umount+rm as fallback for zombie nsfs mounts)
# 3. The `dae0` veth pair in the host netns
#
# daed itself owns TC clsact detach. This opkg-side helper only
# reaps stale daens/dae0 state and never removes /sys/fs/bpf/daed.
# The pin directory is created during normal startup, so it is not
# a reliable leak indicator and must not block service lifecycle.
#
# The function stays sourceable by both init.d/daed and daed-guard.
daed_process_probe() {
if command -v pgrep >/dev/null 2>&1; then
pgrep -f '^/usr/bin/daed([[:space:]]|$)' >/dev/null 2>&1
case "$?" in
0) return 0 ;;
1) return 1 ;;
esac
fi
if command -v pidof >/dev/null 2>&1; then
pidof daed >/dev/null 2>&1
case "$?" in
0) return 0 ;;
1) return 1 ;;
esac
fi
return 2
}
daed_cleanup_runtime() {
local pid
local pid rc=0 probe_rc
# If daed userspace is currently running, do not touch the
# netns, the veth, or the eBPF dataplane. They are in active
# use; removing them would make every connection through dae
# hang.
daed_process_probe
probe_rc=$?
case "$probe_rc" in
0)
if [ "${DAED_GUARD_CLEANUP:-start}" = "start" ]; then
logger -t daed-init "cleanup: pre-start skipped because /usr/bin/daed is still running; refusing a second instance"
return 1
fi
logger -t daed-init "cleanup: post-exit skipped because another /usr/bin/daed instance is still running"
return 0
;;
1) ;;
*)
logger -t daed-init "cleanup: cannot determine whether daed is running; refusing to remove netns/veth"
return 1
;;
esac
# 1. Kill processes inside daens.
for pid in $(ip netns pids daens 2>/dev/null); do
kill "$pid" 2>/dev/null
done
@@ -14,14 +71,36 @@ daed_cleanup_runtime() {
done
fi
# 2. Remove the daens netns. ip netns del can fail if a
# process still references it via /proc/<pid>/ns/net or
# because the umount has already happened. Try the
# umount/rm fallback.
if ! ip netns del daens 2>/dev/null; then
umount -l /run/netns/daens 2>/dev/null
rm -f /run/netns/daens
if [ -e /run/netns/daens ] && ! rm -f /run/netns/daens 2>/dev/null; then
logger -t daed-init "cleanup: failed to remove /run/netns/daens (resource busy); a reboot may be required"
rc=1
fi
fi
ip link del dae0 2>/dev/null || true
# 3. Remove the dae0 veth pair.
if ip link show dae0 >/dev/null 2>&1; then
if ! ip link del dae0 2>/dev/null; then
logger -t daed-init "cleanup: failed to remove dae0 veth pair"
rc=1
fi
fi
# 4. The pin root is normal persistent state. Never remove it or
# make its existence change the cleanup result.
if [ -e /sys/fs/bpf/daed ]; then
logger -t daed-init "cleanup: /sys/fs/bpf/daed exists; leaving normal pin root unchanged"
fi
# Final verification covers only netns and veth state.
[ ! -e /run/netns/daens ] || return 1
! ip netns list 2>/dev/null | awk '$1 == "daens" { found=1 } END { exit !found }' || return 1
! ip netns list 2>/dev/null | grep -Eq '^daens([[:space:]]|$)' || return 1
! ip link show dae0 >/dev/null 2>&1 || return 1
return $rc
}
+118 -16
View File
@@ -1,29 +1,131 @@
#!/bin/sh
# Keep daed as a child so signals can be forwarded and stale netns/veth
# state can be cleaned before start and after exit. daed owns TC detach;
# /sys/fs/bpf/daed is normal persistent state and is never removed here.
. /usr/share/daed/cleanup.sh
# Pre-start cleanup refuses to remove runtime state while another
# daed instance is active, and fails closed if that probe is broken.
DAED_GUARD_CLEANUP=start
if ! daed_cleanup_runtime; then
echo "daed: stale network state could not be removed" >&2
echo "daed: stale /usr/bin/daed or netns state could not be verified or removed; refusing to start. Check process and netns state." >&2
logger -t daed-init "pre-start cleanup failed: refusing to start daed"
exit 1
fi
# Keep daed as a child so a panic or unexpected exit is followed by an
# immediate teardown of all kernel/runtime state before procd can respawn us.
# Keep daed as a child so post-exit cleanup runs before procd can
# respawn it.
child_pid=
cleanup_child() {
[ -n "$child_pid" ] && kill "$child_pid" 2>/dev/null
pending_signal=
shutdown_signal=
shutdown_elapsed=0
forced_kill=0
child_term_timeout=20
forward_signal() {
local sig="$1"
if [ -z "$child_pid" ]; then
pending_signal="$sig"
logger -t daed-init "signal $sig received before daed child started; launch cancelled"
return 0
fi
case "$sig" in
TERM|INT|QUIT)
if [ -z "$shutdown_signal" ]; then
shutdown_signal="$sig"
shutdown_elapsed=0
fi
;;
esac
kill -"$sig" "$child_pid" 2>/dev/null
}
trap cleanup_child TERM INT
/usr/bin/daed "$@" &
child_pid=$!
wait "$child_pid"
status=$?
child_pid=
trap - TERM INT
exit_with_signal() {
local sig="$1"
trap - TERM INT HUP QUIT
kill -"$sig" "$$" 2>/dev/null
exit 1
}
if ! daed_cleanup_runtime; then
echo "daed: runtime cleanup after exit failed" >&2
status=1
child_is_running() {
local state
kill -0 "$child_pid" 2>/dev/null || return 1
state=$(awk '{ print $3 }' "/proc/$child_pid/stat" 2>/dev/null)
[ "$state" != "Z" ]
}
trap 'forward_signal TERM' TERM
trap 'forward_signal INT' INT
trap 'forward_signal HUP' HUP
trap 'forward_signal QUIT' QUIT
start_child() {
local sig
# Keep this check inside the function as well as at the call site:
# it closes the ordinary pre-start window, while the pending-signal
# path below handles a signal arriving during the background fork.
[ -z "$pending_signal" ] || return 125
/usr/bin/daed "$@" &
child_pid=$!
if [ -n "$pending_signal" ]; then
sig="$pending_signal"
pending_signal=
forward_signal "$sig"
fi
}
if [ -n "$pending_signal" ]; then
logger -t daed-init "refusing to start daed after pending signal $pending_signal"
exit_with_signal "$pending_signal"
fi
exit "$status"
# Best-effort OOM preference; failure must not block startup.
if ! echo -16 > /proc/self/oom_score_adj 2>/dev/null; then
logger -t daed-init "warn: failed to set /proc/self/oom_score_adj; continuing without OOM preference"
fi
if ! start_child "$@"; then
logger -t daed-init "refusing to start daed after pending signal $pending_signal"
if [ -n "$pending_signal" ]; then
exit_with_signal "$pending_signal"
fi
exit 1
fi
status=0
reaped=0
while [ "$reaped" -eq 0 ]; do
if [ -n "$shutdown_signal" ] && child_is_running; then
if [ "$shutdown_elapsed" -ge "$child_term_timeout" ]; then
if [ "$forced_kill" -eq 0 ]; then
logger -t daed-init "daed did not exit within ${child_term_timeout}s after $shutdown_signal; sending KILL"
kill -KILL "$child_pid" 2>/dev/null
forced_kill=1
fi
else
sleep 1
shutdown_elapsed=$((shutdown_elapsed + 1))
continue
fi
sleep 1
continue
fi
wait "$child_pid" 2>/dev/null
status=$?
if ! child_is_running; then
reaped=1
fi
done
child_pid=
trap - TERM INT HUP QUIT
# Post-exit cleanup runs after the child is reaped.
DAED_GUARD_CLEANUP=post-exit
cleanup_status=0
daed_cleanup_runtime || cleanup_status=$?
if [ "$cleanup_status" -ne 0 ]; then
echo "daed: runtime cleanup after exit failed" >&2
logger -t daed-init "post-exit cleanup failed; check ip netns / ip link show"
fi
if [ "$status" -ne 0 ]; then
exit "$status"
fi
exit "$cleanup_status"
+37 -13
View File
@@ -1,5 +1,7 @@
#!/bin/sh /etc/rc.common
# Copyright (C) 2023 Tianling Shen <cnsztl@immortalwrt.org>
# daed-guard handles bounded child shutdown and post-exit netns/veth cleanup.
# Keep the log file and a pre-stop state snapshot for diagnostics.
USE_PROCD=1
START=99
@@ -10,18 +12,28 @@ LOG="/var/log/daed/daed.log"
. /usr/share/daed/cleanup.sh
log() {
logger -t daed-init "$@"
}
start_service() {
log "start: begin"
config_load "$CONF"
local enabled
config_get_bool enabled "config" "enabled" "0"
[ "$enabled" -eq "1" ] || return 1
if [ "$enabled" -ne "1" ]; then
log "start: config disabled, exit"
return 1
fi
local listen_addr log_maxbackups log_maxsize
config_get listen_addr "config" "listen_addr" "0.0.0.0:2023"
config_get log_maxbackups "config" "log_maxbackups" "1"
config_get log_maxsize "config" "log_maxsize" "5"
log "start: listen=$listen_addr log_maxbackups=$log_maxbackups log_maxsize=$log_maxsize"
procd_open_instance "$CONF"
procd_set_param env DAE_LOCATION_ASSET="/usr/share/v2ray" TZ="$(uci -q get system.@system[0].zonename)"
procd_set_param command "$PROG" run
@@ -33,25 +45,37 @@ start_service() {
procd_set_param limits core="unlimited"
procd_set_param limits nofile="1000000 1000000"
# Avoid an endless crash/respawn loop which can repeatedly reattach dae's
# data-plane hooks and make the router management plane unreachable.
procd_set_param respawn 3600 5 5
# daed-guard escalates its child after 20 seconds. Leave time for
# reap and post-exit cleanup before procd kills the wrapper.
procd_set_param term_timeout 30
# procd_set_param respawn: arguments are (threshold, timeout, retry).
# threshold = runtime that resets the short-lived exit counter
# timeout = seconds to wait between retries
# retry = maximum short-lived exits before procd gives up
# Reset the counter after one hour of stable runtime; otherwise retry
# after 5 seconds and stop after 10 failures.
procd_set_param respawn 3600 5 10
# daed-guard sets oom_score_adj before forking; procd has no
# oom_adj/oom_score_adj parameter.
# procd_set_param stdout 1
procd_set_param stderr 1
procd_close_instance
log "start: procd_open_instance done"
}
stop_service() {
rm -f "$LOG"
daed_cleanup_runtime
}
restart() {
stop
sleep 1
daed_cleanup_runtime
start
log "stop: begin"
# Cleanup runs in daed-guard after its child exits. Record only a
# pre-stop snapshot here; pin entries do not prove TC attachment.
local pinned="" ns_left=""
if [ -d /sys/fs/bpf/daed ]; then
pinned=$(ls /sys/fs/bpf/daed 2>/dev/null | tr '\n' ' ')
fi
if ip netns list 2>/dev/null | grep -q '^daens'; then
ns_left="daens"
fi
log "stop: pre-stop state — bpf_pin_entries=[${pinned:-none}] netns_left=[${ns_left:-none}]"
}
service_triggers() {
+11 -9
View File
@@ -1,8 +1,6 @@
# SPDX-License-Identifier: GPL-3.0-only
#
# Copyright (C) 2021-2023 sirpdboy <herboy2008@gmail.com>
#
# This is free software, licensed under the Apache License, Version 2.0 .
# Copyright (C) 2021-2026 sirpdboy <herboy2008@gmail.com>
#
include $(TOPDIR)/rules.mk
@@ -10,12 +8,12 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=ddns-go
PKG_VERSION:=6.17.7
PKG_RELEASE:=1
PKG_VERSION:=6.17.7
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_SOURCE_URL:=https://codeload.github.com/jeessy2/ddns-go/tar.gz/v$(PKG_VERSION)?
PKG_HASH:=f7001004e092d9641aad5a94158e0b4cae4a53a7f5c7d96d5c6af3d246c56fcc
PKG_LICENSE:=MIT
PKG_HASH:=f7001004e092d9641aad5a94158e0b4cae4a53a7f5c7d96d5c6af3d246c56fcc
PKG_LICENSE_FILES:=LICENSE
PKG_MAINTAINER:=Tianling Shen <cnsztl@immortalwrt.org>
@@ -44,14 +42,18 @@ define Package/ddns-go/description
support Alidns Dnspod Cloudflare Hicloud Callback Baiducloud porkbun GoDaddy Google Domains.
endef
define Package/ddns-go/conffiles
/etc/config/ddns-go
/etc/ddns-go/ddns-go-config.yaml
endef
define Package/ddns-go/install
$(call GoPackage/Package/Install/Bin,$(1))
$(INSTALL_DIR) $(1)/etc/init.d
$(INSTALL_BIN) $(CURDIR)/file/ddns-go.init $(1)/etc/init.d/ddns-go
$(INSTALL_DIR) $(1)/etc/uci-defaults
$(INSTALL_BIN) $(CURDIR)/file/luci-ddns-go.uci-default $(1)/etc/uci-defaults/luci-ddns-go
$(INSTALL_DIR) $(1)/etc/config
$(INSTALL_BIN) $(CURDIR)/files/ddns-go.init $(1)/etc/init.d/ddns-go
$(INSTALL_CONF) $(CURDIR)/files/ddns-go.conf $(1)/etc/config/ddns-go
endef
$(eval $(call GoBinPackage,ddns-go))
-46
View File
@@ -1,46 +0,0 @@
#!/bin/sh /etc/rc.common
#
# Copyright (C) 2021-2023 sirpdboy <herboy2008@gmail.com> https://github.com/sirpdboy/luci-app-ddns-go
#
# This file is part of ddns-go .
#
# This is free software, licensed under the Apache License, Version 2.0 .
#
START=99
USE_PROCD=1
PROG=/usr/bin/ddns-go
CONFDIR=/etc/ddns-go
CONF=$CONFDIR/ddns-go-config.yaml
get_config() {
config_get_bool enabled $1 enabled 1
config_get_bool logger $1 logger 1
config_get port $1 port 9876
config_get time $1 time 300
}
init_yaml(){
[ -d $CONFDIR ] || mkdir -p $CONFDIR 2>/dev/null
cat /usr/share/ddns-go/ddns-go-default.yaml > $CONF
}
start_service() {
config_load ddns-go
config_foreach get_config basic
[ x$enabled == x1 ] || return 1
[ -s ${CONF} ] || init_yaml
logger -t ddns-go -p warn "ddns-go is start."
echo "ddns-go is start."
procd_open_instance
procd_set_param command $PROG -l :$port -f $time -c "$CONF"
[ "x$logger" == x1 ] && procd_set_param stderr 1
procd_set_param respawn
procd_close_instance
}
service_triggers() {
procd_add_reload_trigger "ddns-go"
}
-7
View File
@@ -1,7 +0,0 @@
#!/bin/sh
[ -s "/etc/ddns-go/localtime" ] && mv -f /etc/ddns-go/localtime /etc/localtime
/etc/init.d/ddns-go enable
/etc/init.d/ddns-go start
rm -f /tmp/luci*
exit 0
+9
View File
@@ -0,0 +1,9 @@
config basic 'config'
option enabled '0'
option logger '1'
option port '9876'
option time '300'
option ctimes '5'
option skipverify '0'
option delay '0'
option dns '223.5.5.5'
+85
View File
@@ -0,0 +1,85 @@
#!/bin/sh /etc/rc.common
#
# Copyright (C) 2021-2026 sirpdboy <herboy2008@gmail.com>
#
# This file is part of ddns-go .
#
# This is free software, licensed under the Apache License, Version 2.0 .
#
START=99
USE_PROCD=1
NAME=ddns-go
PROG=/usr/bin/ddns-go
CONFDIR=/etc/ddns-go
CONF=$CONFDIR/ddns-go-config.yaml
init_yaml() {
[ -d "$CONFDIR" ] || mkdir -p "$CONFDIR"
chown -R ddns-go:ddns-go "$CONFDIR"
chmod 755 "$CONFDIR"
[ -f "$CONF" ] && chmod 644 "$CONF"
}
build_args() {
local cfg="$1"
local args="-c $CONF"
config_get port "$cfg" port '9876'
args="$args -l :$port"
config_get time "$cfg" time '300'
[ -n "$time" ] && args="$args -f $time"
config_get ctimes "$cfg" ctimes '5'
[ -n "$ctimes" ] && args="$args -cacheTimes $ctimes"
config_get dns "$cfg" dns '223.5.5.5'
[ -n "$dns" ] && args="$args -dns $dns"
config_get_bool noweb "$cfg" noweb 0
[ "$noweb" -eq 1 ] && args="$args -noweb"
config_get_bool skipverify "$cfg" skipverify 0
[ "$skipverify" -eq 1 ] && args="$args -skipVerify"
echo "$args"
}
start_instance() {
local cfg="$1"
local logger
config_get_bool enabled "$cfg" enabled 0
[ "$enabled" -eq 0 ] && return 0
config_get delay "$cfg" delay 0
if [ "$delay" -gt 0 ]; then
local uptime=$(awk -F. '{print $1}' /proc/uptime)
[ "$uptime" -lt 120 ] && sleep "$delay"
fi
init_yaml
local args=$(build_args "$cfg")
procd_open_instance
procd_set_param command $PROG $args
config_get_bool logger "$cfg" logger 1
procd_set_param stdout "$logger"
procd_set_param stderr "$logger"
procd_set_param user ddns-go
procd_set_param respawn
procd_close_instance
}
start_service() {
config_load "$NAME"
config_foreach start_instance 'basic'
}
service_triggers() {
procd_add_reload_trigger "$NAME"
}
+2 -2
View File
@@ -1,12 +1,12 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=docker
PKG_VERSION:=29.8.0
PKG_VERSION:=29.8.1
PKG_RELEASE:=1
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_SOURCE_URL:=https://codeload.github.com/docker/cli/tar.gz/v$(PKG_VERSION)?
PKG_HASH:=c5fadbc00c02dbecb1b7c9936e188baf9c80421a9107e7e9ad36a0923a0fc764
PKG_HASH:=55bcae5053f0914118d229658e2ac3a877dbdead6cb2c322e525d0c1e8bf78d2
PKG_BUILD_DIR:=$(BUILD_DIR)/cli-$(PKG_VERSION)
PKG_GIT_SHORT_COMMIT:=$(shell $(CURDIR)/git-short-commit.sh 'github.com/docker/cli' 'v$(PKG_VERSION)' '$(TMP_DIR)/git-short-commit/$(PKG_NAME)-$(PKG_VERSION)')
+2 -2
View File
@@ -1,7 +1,7 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=dockerd
PKG_VERSION:=29.8.0
PKG_VERSION:=29.8.1
PKG_RELEASE:=1
PKG_LICENSE:=Apache-2.0
PKG_LICENSE_FILES:=LICENSE
@@ -10,7 +10,7 @@ PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_GIT_URL:=github.com/moby/moby
PKG_GIT_REF:=docker-v$(PKG_VERSION)
PKG_SOURCE_URL:=https://codeload.$(PKG_GIT_URL)/tar.gz/$(PKG_GIT_REF)?
PKG_HASH:=e75ffb5d2ddc1fd98138fdb5e29f707b59f415ec8697e73b8bbdf8bbbb4be8eb
PKG_HASH:=94be9d6940b613676335fc494e617b4acf98676435b3744f32649ed72114bd58
PKG_GIT_SHORT_COMMIT:=$(shell $(CURDIR)/git-short-commit.sh '$(PKG_GIT_URL)' '$(PKG_GIT_REF)' '$(TMP_DIR)/git-short-commit/$(PKG_NAME)-$(PKG_VERSION)')
PKG_MAINTAINER:=Gerard Ryan <G.M0N3Y.2503@gmail.com>
+3 -3
View File
@@ -9,9 +9,9 @@ PKG_RELEASE:=1
PKG_SOURCE_PROTO:=git
PKG_SOURCE_URL:=https://gn.googlesource.com/gn.git
PKG_SOURCE_DATE:=2026-09-03
PKG_SOURCE_VERSION:=4f6a76b64b8279e98004f541f8e136307efe5e01
PKG_MIRROR_HASH:=933dc8c8d745923437c9e730ab7c2a23a53562144513a4f634ad10381c23be44
PKG_SOURCE_DATE:=2026-09-11
PKG_SOURCE_VERSION:=cfcd774b98f3433e18b722f9a7ff06119825b8eb
PKG_MIRROR_HASH:=d8bea9ac89f9e87f36874601588f0d8d32221bf1ad8488f2fd9775abcddf4860
PKG_LICENSE:=BSD 3-Clause
PKG_LICENSE_FILES:=LICENSE
+2 -2
View File
@@ -3,7 +3,7 @@
#ifndef OUT_LAST_COMMIT_POSITION_H_
#define OUT_LAST_COMMIT_POSITION_H_
#define LAST_COMMIT_POSITION_NUM 2553
#define LAST_COMMIT_POSITION "2553 (4f6a76b64b82)"
#define LAST_COMMIT_POSITION_NUM 2563
#define LAST_COMMIT_POSITION "2563 (cfcd774b98f3)"
#endif // OUT_LAST_COMMIT_POSITION_H_
+1 -1
View File
@@ -2,7 +2,7 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=luci-app-clashoo
PKG_VERSION:=1.30.0
PKG_RELEASE:=13
PKG_RELEASE:=15
PKG_MAINTAINER:=kenzok8
PKG_BUILD_DIR:=$(BUILD_DIR)/$(PKG_NAME)
@@ -143,7 +143,7 @@ const callOverview = rpc.declare({ object: 'luci.clashoo', method: 'ove
const callSmartFlushCache = rpc.declare({ object: 'luci.clashoo', method: 'smart_flush_cache', expect: {} });
const callListSingboxProfiles = rpc.declare({ object: 'luci.clashoo', method: 'list_singbox_profiles', expect: {} });
const callGetSingboxProfile = rpc.declare({ object: 'luci.clashoo', method: 'get_singbox_profile', params: ['name'], expect: {} });
const callSaveSingboxProfile = rpc.declare({ object: 'luci.clashoo', method: 'save_singbox_profile', params: ['name', 'content'], expect: {} });
const callSaveSingboxProfileChunk = rpc.declare({ object: 'luci.clashoo', method: 'save_singbox_profile_chunk', params: ['name', 'content', 'index', 'total'], expect: {} });
const callSetSingboxProfile = rpc.declare({ object: 'luci.clashoo', method: 'set_singbox_profile', params: ['name'], expect: {} });
const callDeleteSingboxProfile = rpc.declare({ object: 'luci.clashoo', method: 'delete_singbox_profile', params: ['name'], expect: {} });
const callCreateSingboxConfig = rpc.declare({ object: 'luci.clashoo', method: 'create_singbox_config', params: ['sub_url', 'name'], expect: {} });
@@ -235,7 +235,23 @@ return baseclass.extend({
listSingboxProfiles: function () { return L.resolveDefault(callListSingboxProfiles(), { profiles: [], active: '' }); },
getSingboxProfile: function (name) { return L.resolveDefault(callGetSingboxProfile(name), {}); },
saveSingboxProfile: function (name, content){ return L.resolveDefault(callSaveSingboxProfile(name, content), {}); },
saveSingboxProfile: function (name, content) {
var chunkSize = 24576;
var total = Math.max(1, Math.ceil((content || '').length / chunkSize));
var index = 0;
function sendNext() {
var chunk = (content || '').slice(index * chunkSize, (index + 1) * chunkSize);
return L.resolveDefault(callSaveSingboxProfileChunk(name, chunk, String(index), String(total)), {}).then(function (r) {
if (!r || !r.success)
return { success: false, error: (r && r.error) || 'upload_failed', message: (r && (r.message || r.error)) || _('Upload failed') };
index++;
return index < total ? sendNext() : r;
});
}
return sendNext();
},
setSingboxProfile: function (name) { return L.resolveDefault(callSetSingboxProfile(name), {}); },
deleteSingboxProfile: function (name) { return L.resolveDefault(callDeleteSingboxProfile(name), {}); },
createSingboxConfig: function (url, name) { return L.resolveDefault(callCreateSingboxConfig(url, name), {}); },
@@ -1135,7 +1135,7 @@ return '_merged_' + s + '__' + t + '.yaml';
}
function template_search_dirs() {
return [TEMPLATE_USER_DIR, TEMPLATE_DIR, '/usr/share/clashoo/config/template'];
return [TEMPLATE_DIR, '/usr/share/clashoo/config/template'];
}
function find_template_path(name) {
@@ -3318,6 +3318,8 @@ call: function(req) {
let tpl_src = trim(req.args?.template_source || '');
let sub_url = trim(req.args?.sub_url || '');
let output_name = ensure_yaml_name(req.args?.output_name || '');
if (!output_name) output_name = 'tpl-rewrite.yaml';
let uniq_name = replace(output_name, /\.(yaml|yml)$/, '');
let set_active = (req.args?.set_active || '') == '1';
if (!tpl_src)
@@ -3361,20 +3363,16 @@ return { success: false, error: 'missing_yq', message: '缺少 yq,无法注入
if (!access(exploded, "r")) {
system("cp -f " + shell_quote(tmp_tpl) + " " + shell_quote(exploded));
}
/* 替换 proxy-providers.urlrule-providers 指向规则集保持原样 */
let inject_cmd = "URL=" + shell_quote(sub_url)
+ " yq e '.[\"proxy-providers\"][].url = env(URL)' "
+ shell_quote(exploded) + " > " + shell_quote(tmp_out);
/* 替换 proxy-providers.url 并把 provider 名改成唯一名(同步 proxy-groups 的 use*/
let inject_cmd = "URL=" + shell_quote(sub_url) + " NAME=" + shell_quote(uniq_name)
+ " yq e '.[\"proxy-providers\"][].url = env(URL) | (.[\"proxy-providers\"] | keys | map({\"key\": ., \"value\": strenv(NAME) + \"-\" + .}) | from_entries) as $rename | .[\"proxy-providers\"] |= with_entries(.key = $rename[.key]) | (.[\"proxy-groups\"][] | select(has(\"use\")) | .use) |= map($rename[.] // .)' "
+ shell_quote(exploded) + " > " + shell_quote(tmp_out);
if (system(inject_cmd) != 0 || !access(tmp_out, "r")) {
system("rm -f " + shell_quote(exploded));
return { success: false, error: "inject_failed", message: "订阅 URL 注入失败" };
}
system("rm -f " + shell_quote(exploded));
if (!output_name) {
output_name = 'tpl-rewrite.yaml';
}
let out_path = out_dir + '/' + output_name;
if (system('mv -f ' + shell_quote(tmp_out) + ' ' + shell_quote(out_path)) != 0)
return { success: false, error: 'write_failed', message: '写入结果文件失败' };
@@ -3382,16 +3380,16 @@ return { success: false, error: 'write_failed', message: '写入结果文件失
/* 删除 respect-rules(模板可能设了但没提供 proxy-server-nameserver */
system("sed -i '/respect-rules/d' " + shell_quote(out_path) + " 2>/dev/null");
system('rm -f ' + shell_quote(tmp_tpl));
/* 替换 直连→DIRECT(兼容不同模板的命名差异) */
system("sed -i 's/直连/DIRECT/g' " + shell_quote(out_path) + " 2>/dev/null");
system("yq e '(.proxy-groups[].proxies) |= sub(\"直连\", \"DIRECT\")' " + shell_quote(out_path) + " -i 2>/dev/null");
/* 只把独立引用项"直连"转成 DIRECT,组名里的"直连"不动 */
system("sed -i 's/^\\( *- *\\)直连$/\\1DIRECT/' " + shell_quote(out_path) + " 2>/dev/null");
system("yq e '(.proxy-groups[] | select(has(\"proxies\")) | .proxies) |= map(sub(\"^直连$\", \"DIRECT\"))' " + shell_quote(out_path) + " -i 2>/dev/null");
/* 用 mixin.uc + yq merge 叠加 UCI 覆盖(端口、routing-mark、dns 等) */
let mixin_script = "/usr/share/clashoo/runtime/mixin.uc";
if (access(mixin_script, "r") && system("command -v yq >/dev/null 2>&1") == 0) {
let mixin_yaml = "/tmp/_clashoo_mixin.yaml";
let merged_out = out_path + ".merged";
system("ucode " + shell_quote(mixin_script) + " 2>/dev/null | yq -M -p json -o yaml > " + shell_quote(mixin_yaml) + " 2>/dev/null");
system("yq -M eval-all '. as $item ireduce ({}; . * $item)' " + shell_quote(out_path) + " " + shell_quote(mixin_yaml) + " > " + shell_quote(merged_out) + " 2>/dev/null");
system("yq -M eval-all '(. as $item ireduce ({}; . * $item)) as $m | [\"port\",\"socks-port\",\"redir-port\",\"tproxy-port\",\"mixed-port\",\"allow-lan\",\"bind-address\",\"mode\",\"log-level\",\"ipv6\",\"interface-name\",\"routing-mark\",\"external-controller\",\"external-ui\",\"secret\",\"tun\",\"listeners\",\"tunnels\",\"dns\",\"hosts\",\"profile\",\"geodata-mode\",\"geodata-loader\",\"geox-url\",\"proxy-providers\",\"proxies\",\"proxy-groups\",\"rule-providers\",\"rules\",\"sub-rules\",\"ntp\",\"authentication\",\"sniffer\",\"experimental\"] as $order | ($order | to_entries | map({\"key\": .value, \"value\": .key}) | from_entries) as $rank | $m | to_entries | sort_by(.key as $k | $rank[$k] // 999) | from_entries' " + shell_quote(out_path) + " " + shell_quote(mixin_yaml) + " > " + shell_quote(merged_out) + " 2>/dev/null");
if (access(merged_out, "r")) {
system("mv -f " + shell_quote(merged_out) + " " + shell_quote(out_path));
}
@@ -3812,6 +3810,50 @@ return { success: true, name };
}
},
save_singbox_profile_chunk: {
args: { name: 'name', content: 'content', index: 'index', total: 'total' },
call: function(req) {
let name = req.args?.name || '';
let content = req.args?.content;
let idx = int(req.args?.index || 0);
let total = int(req.args?.total || 0);
if (!name || index(name, '/') >= 0 || index(name, '..') >= 0)
return { success: false, error: 'invalid name' };
if (!match(name, /\.json$/)) name = name + '.json';
if (type(content) != 'string') return { success: false, error: 'invalid content' };
if (total < 1 || idx < 0 || idx >= total) return { success: false, error: 'invalid chunk' };
if (total == 1 && !content) return { success: false, error: 'empty content' };
let dir = '/usr/share/clashoo/config/singbox';
system('mkdir -p ' + shell_quote(dir) + ' >/dev/null 2>&1');
let tmp = '/tmp/clashoo_sb_upload_' + name;
if (idx == 0) {
if (writefile(tmp, content) === null)
return { success: false, error: 'write_failed', message: '写入文件失败' };
} else {
let fp = open(tmp, 'a');
if (!fp) return { success: false, error: 'write_failed', message: '打开文件失败' };
let ok = fp.write(content);
fp.close();
if (ok === null) return { success: false, error: 'write_failed', message: '写入文件失败' };
}
if (idx + 1 < total)
return { success: true, name, index: idx, total, complete: false };
let binary = find_binary();
if (binary && match(binary, /sing-box/)) {
if (system(shell_quote(binary) + ' check -c ' + shell_quote(tmp) + ' >/dev/null 2>&1') != 0) {
system('rm -f ' + shell_quote(tmp));
return { success: false, error: 'invalid_config', message: 'sing-box 配置验证失败,请检查 JSON 格式' };
}
}
if (system('cp -f ' + shell_quote(tmp) + ' ' + shell_quote(dir + '/' + name) + ' >/dev/null 2>&1') != 0) {
system('rm -f ' + shell_quote(tmp));
return { success: false, error: 'write_failed', message: '写入文件失败' };
}
system('rm -f ' + shell_quote(tmp));
return { success: true, name, index: idx, total, complete: true };
}
},
set_singbox_profile: {
args: { name: 'name' },
call: function(req) {
@@ -72,7 +72,7 @@ function get_adlist() {
let adblock = uci_cursor.get('mosdns', 'config', 'adblock');
if (adblock !== '1') {
mkdir('/etc/mosdns/rule', 0755);
mkdir('/var/mosdns', 0755);
exec_sys('rm -rf /etc/mosdns/rule/adlist /etc/mosdns/rule/.ad_source');
writefile('/var/mosdns/disable-ads.txt', '');
print("/var/mosdns/disable-ads.txt\n");
+1 -1
View File
@@ -7,7 +7,7 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=luci-app-passwall
PKG_VERSION:=26.9.9
PKG_VERSION:=26.9.16
PKG_RELEASE:=1
PKG_PO_VERSION:=$(PKG_VERSION)
@@ -20,7 +20,10 @@ for _, k in ipairs(com.order) do
if k ~= "chinadns-ng" then
o = s:option(Value, k:gsub("%-","_") .. "_file", translatef("%s App Path", v.name))
o.default = v.default_path or ("/usr/bin/" .. k)
o.rmempty = false
o.placeholder = o.default
function o:remove(section)
self:write(section, self.default)
end
end
end
@@ -612,21 +612,46 @@ o:value("info", "Info")
o:value("warn", "Warning")
o:value("error", "Error")
o = s:taboption("log", Flag, "advanced_log_feature", translate("Advanced log feature"), translate("For professionals only."))
o.default = "0"
o = s:taboption("log", Flag, "sys_log", translate("Logging to system log"), translate("Logging to the system log for more advanced functions. For example, send logs to a dedicated log server."))
o:depends("advanced_log_feature", "1")
o.default = "0"
o = s:taboption("log", Value, "persist_log_path", translate("Persist log file directory"), translate("The path to the directory used to store persist log files, the \"/\" at the end can be omitted. Leave it blank to disable this feature."))
o:depends({ ["advanced_log_feature"] = 1, ["sys_log"] = 0 })
o = s:taboption("log", Value, "log_event_filter", translate("Log Event Filter"), translate("Support regular expression."))
o:depends("advanced_log_feature", "1")
o = s:taboption("log", Value, "log_event_cmd", translate("Shell Command"), translate("Shell command to execute, replace log content with %s."))
o:depends("advanced_log_feature", "1")
o = s:taboption("log", DummyValue, "_node_log", translate("Log File"))
o.rawhtml = true
o.cfgvalue = function(t, n)
local log_file = api.TMP_PATH .. "/acl/default/global.log"
local log_url = api.url("get_redir_log") .. "?id=default"
local s = "<code>%s</code>&nbsp;&nbsp;" % log_file
if api.fs.access(log_file) then
local btn = string.format(
'<input class="btn cbi-button cbi-button-apply" type="button" value="%s" onclick="window.open(\'%s\', \'_blank\')" />',
translate("View Log"),
log_url
)
s = s .. btn
end
return s
end
o:depends("log_node", "1")
o = s:taboption("log", Flag, "log_chinadns_ng", translate("Enable") .. " ChinaDNS-NG " .. translate("Log"))
o.default = "0"
o.rmempty = false
o:depends("dns_shunt", "chinadns-ng")
o = s:taboption("log", DummyValue, "_chinadns_ng_log", translate("Log File"))
o.rawhtml = true
o.cfgvalue = function(t, n)
local log_file = api.TMP_PATH .. "/acl/default/chinadns_ng.log"
local log_url = api.url("get_chinadns_log") .. "?flag=default"
local s = "<code>%s</code>&nbsp;&nbsp;" % log_file
if api.fs.access(log_file) then
local btn = string.format(
'<input class="btn cbi-button cbi-button-apply" type="button" value="%s" onclick="window.open(\'%s\', \'_blank\')" />',
translate("View Log"),
log_url
)
s = s .. btn
end
return s
end
o:depends("log_chinadns_ng", "1")
o = s:taboption("log", DummyValue, "_log_tips", " ")
o.rawhtml = true
@@ -707,16 +707,6 @@ o = s:option(Value, "ws_path", translate("WebSocket Path"))
o.placeholder = "/"
o:depends({ transport = "ws" })
o = s:option(Flag, "ws_enableEarlyData", translate("Enable early data"))
o:depends({ transport = "ws" })
o = s:option(Value, "ws_maxEarlyData", translate("Early data length"))
o.default = "1024"
o:depends({ ws_enableEarlyData = true })
o = s:option(Value, "ws_earlyDataHeaderName", translate("Early data header name"), translate("Recommended value: Sec-WebSocket-Protocol"))
o:depends({ ws_enableEarlyData = true })
-- [[ HTTPUpgrade部分 ]]--
o = s:option(Value, "httpupgrade_host", translate("HTTPUpgrade Host"))
o:depends({ transport = "httpupgrade" })
@@ -399,6 +399,10 @@ o:depends({ transport = "ws" })
o = s:option(Value, "ws_path", translate("WebSocket Path"))
o:depends({ transport = "ws" })
o = s:option(Value, "ws_earlyDataHeaderName", translate("Early data header name"), translate("Recommended value: Sec-WebSocket-Protocol"))
o.placeholder = "Sec-WebSocket-Protocol"
o:depends({ transport = "ws" })
-- [[ HTTPUpgrade部分 ]]--
o = s:option(Value, "httpupgrade_host", translate("HTTPUpgrade Host"))
+14 -2
View File
@@ -163,12 +163,16 @@ function sh_uci_commit(config)
exec_call(string.format("uci -q commit %s", config))
end
function del_cache_var(key)
sys.call(string.format('. /usr/share/passwall2/utils.sh ; del_cache_var "%s"', key))
end
function set_cache_var(key, val)
sys.call(string.format('. /usr/share/passwall/utils.sh ; set_cache_var %s "%s"', key, val))
sys.call(string.format('. /usr/share/passwall/utils.sh ; set_cache_var "%s" "%s"', key, val))
end
function get_cache_var(key)
local val = sys.exec(string.format('. /usr/share/passwall/utils.sh ; echo -n $(get_cache_var %s)', key))
local val = sys.exec(string.format('. /usr/share/passwall/utils.sh ; echo -n $(get_cache_var "%s")', key))
if val == "" then val = nil end
return val
end
@@ -2072,3 +2076,11 @@ function gen_wireguard_key()
}
end
end
function get_socks_port_by_cache(node_id)
return get_cache_var("node_%s_socks_port" % { node_id })
end
function set_socks_port_to_cache(node_id, v)
set_cache_var("node_%s_socks_port" % { node_id }, v)
end
@@ -93,43 +93,64 @@ function gen_outbound(flag, node, tag, proxy_table)
end
local remarks = node.remarks
local proxy_tag = nil
local fragment = nil
local record_fragment = nil
local run_socks_instance = true
local proxy_tag, fragment, record_fragment
if proxy_table ~= nil and type(proxy_table) == "table" then
proxy_tag = proxy_table.tag or nil
fragment = (proxy_table.fragment and node.protocol ~= "naive" and not node.hysteria2_realms) and true or nil
record_fragment = (proxy_table.record_fragment and node.protocol ~= "naive" and not node.hysteria2_realms) and true or nil
run_socks_instance = proxy_table.run_socks_instance
end
if node.type ~= "sing-box" then
local relay_port = node.port
local new_port = api.get_new_port()
local config_file = string.format("%s_%s_%s.json", flag, tag, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("%s_%s_%s_%s.json", flag, tag, node_id, new_port)
end
if run_socks_instance then
sys.call(string.format('/usr/share/passwall/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
(proxy_tag and relay_port) and tostring(relay_port) or "" --relay port
if node.type == "Socks" then
node.protocol = "socks"
proxy_tag = "socks <- " .. node_id
else
local new_port
local run_socks_instance = true
if NO_RUN then
TMP_PORT = TMP_PORT and TMP_PORT + 1 or 3001
new_port = TMP_PORT
run_socks_instance = nil
else
local relay_port = (proxy_tag and node.port) and tostring(node.port) or ""
if relay_port == "" then
local cache = api.get_socks_port_by_cache(node_id)
if cache then
new_port = cache
run_socks_instance = nil
end
end
if run_socks_instance then
new_port = api.get_new_port()
local config_file = string.format("nodesocks_%s_%s.json", node_id, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("nodesocks_%s_%s_%s.json", tag, node_id, new_port)
end
sys.call(string.format('/usr/share/passwall/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
relay_port --relay port
)
)
)
)
)
if relay_port == "" then
api.set_socks_port_to_cache(node_id, new_port)
end
end
end
if new_port then
node = {
protocol = "socks",
address = "127.0.0.1",
port = new_port
}
proxy_tag = "socks <- " .. node_id
end
end
node = {
protocol = "socks",
address = "127.0.0.1",
port = new_port
}
proxy_tag = "socks <- " .. node_id
else
if proxy_tag then
node.detour = proxy_tag
@@ -326,9 +347,20 @@ function gen_outbound(flag, node, tag, proxy_table)
Host = node.ws_host,
["User-Agent"] = node.user_agent
} or nil,
max_early_data = tonumber(node.ws_maxEarlyData) or nil,
early_data_header_name = (node.ws_earlyDataHeaderName) and node.ws_earlyDataHeaderName or nil --要与 Xray-core 兼容,请将其设置为 Sec-WebSocket-Protocol。它需要与服务器保持一致。
}
local path = api.UrlDecode(node.ws_path)
local path_dat = api.split(path, "?")
local params = {}
for _, v in pairs(api.split(path_dat[2], '&')) do
local t = api.split(v, '=')
params[t[1]] = t[2]
end
local ed = tonumber(params.ed)
if ed then
v2ray_transport.path = path_dat[1]
v2ray_transport.max_early_data = ed
end
v2ray_transport.early_data_header_name = params.eh or "Sec-WebSocket-Protocol"
end
if node.transport == "httpupgrade" then
@@ -741,7 +773,7 @@ function gen_config_server(node)
type = "ws",
path = node.ws_path or "/",
headers = (node.ws_host ~= nil) and { Host = node.ws_host } or nil,
early_data_header_name = (node.ws_earlyDataHeaderName) and node.ws_earlyDataHeaderName or nil --要与 Xray-core 兼容,请将其设置为 Sec-WebSocket-Protocol。它需要与服务器保持一致。
early_data_header_name = (node.ws_earlyDataHeaderName) and node.ws_earlyDataHeaderName or "Sec-WebSocket-Protocol"
}
end
@@ -913,7 +945,7 @@ function gen_config_server(node)
stream_receive_window = node.hysteria_recv_window_conn and tonumber(node.hysteria_recv_window_conn) or nil,
connection_receive_window = node.hysteria_recv_window_client and tonumber(node.hysteria_recv_window_client) or nil,
max_concurrent_streams = node.hysteria_max_conn_client and tonumber(node.hysteria_max_conn_client) or nil,
disable_path_mtu_discover = (node.hysteria_disable_mtu_discovery == "1") and true or false,
disable_path_mtu_discovery = (node.hysteria_disable_mtu_discovery == "1") and true or false,
tls = tls
}
end
@@ -1140,10 +1172,11 @@ function gen_config(var)
local dns_cache = var["dns_cache"]
local dns_socks_address = var["dns_socks_address"]
local dns_socks_port = var["dns_socks_port"]
local no_run = var["no_run"]
local use_proxy_list = var["use_proxy_list"]
local use_gfw_list = var["use_gfw_list"]
local chn_list = var["chn_list"]
local run_in_global = var["run_in_global"]
NO_RUN = var["no_run"]
local dns_domain_rules = {}
local dns = nil
@@ -1337,7 +1370,9 @@ function gen_config(var)
ut_nodes = _node.urltest_node
end
-- api.log(" - 加载 Sing-Box URLTest 节点【" .. (_node.remarks or "") .. "】,子节点数量:" .. #(ut_nodes or {}))
if not NO_RUN and run_in_global then
api.log(" - 加载 Sing-Box URLTest 节点【" .. (_node.remarks or "") .. "】,子节点数量:" .. #(ut_nodes or {}))
end
local valid_nodes = {}
for i = 1, #(ut_nodes or {}) do
@@ -1352,7 +1387,7 @@ function gen_config(var)
end
end
if is_new_ut_node then
local outboundTag = gen_outbound_get_tag(flag, ut_node_id, ut_node_tag, { fragment = singbox_settings.fragment == "1" or nil, record_fragment = singbox_settings.record_fragment == "1" or nil, run_socks_instance = not no_run })
local outboundTag = gen_outbound_get_tag(flag, ut_node_id, ut_node_tag, { fragment = singbox_settings.fragment == "1" or nil, record_fragment = singbox_settings.record_fragment == "1" or nil })
if outboundTag then
valid_nodes[#valid_nodes + 1] = outboundTag
end
@@ -1455,7 +1490,6 @@ function gen_config(var)
to_node.port = new_port
to_outbound = gen_outbound(node[".name"], to_node, tag, {
tag = tag,
run_socks_instance = not no_run
})
else
to_outbound = gen_outbound(node[".name"], to_node)
@@ -1548,7 +1582,6 @@ function gen_config(var)
local proxy_table = {
fragment = singbox_settings.fragment == "1",
record_fragment = singbox_settings.record_fragment == "1",
run_socks_instance = not no_run,
}
local preproxy_node_id = node[rule_name .. "_proxy_tag"]
if preproxy_node_id == _node_id then preproxy_node_id = nil end
@@ -1832,7 +1865,6 @@ function gen_config(var)
COMMON.default_outbound_tag = gen_outbound_get_tag(flag, node or node_id, nil, {
fragment = singbox_settings.fragment == "1" or nil,
record_fragment = singbox_settings.record_fragment == "1" or nil,
run_socks_instance = not no_run
})
end
@@ -2293,7 +2325,7 @@ function gen_config(var)
routing_mark = 255,
})
for index, value in ipairs(config.outbounds) do
if not value["_flag_proxy_tag"] and not value.detour and value["_id"] and value.server and (value.server_port or value.server_ports) and not no_run then
if not value["_flag_proxy_tag"] and not value.detour and value["_id"] and value.server and (value.server_port or value.server_ports) and not NO_RUN then
sys.call(string.format("echo '%s' >> %s", value["_id"], api.TMP_PATH .. "/direct_node_list"))
end
if not value.detour and not value.bind_interface and value.server then
@@ -2441,7 +2473,7 @@ if arg[1] then
var = jsonc.parse(arg[2])
end
print(func(var))
if (next(GEO_VAR.SITE_TAGS) or next(GEO_VAR.IP_TAGS)) and not no_run then
if (next(GEO_VAR.SITE_TAGS) or next(GEO_VAR.IP_TAGS)) and not NO_RUN then
convert_geofile()
end
end
+73 -56
View File
@@ -12,7 +12,7 @@ local GLOBAL = {
local xray_version = api.get_app_version("xray")
local xray_min_version = "26.3.27"
local xray_min_version = "26.7.11"
local function get_domain_excluded()
local path = string.format("/usr/share/%s/rules/domains_excluded", api.c_config)
@@ -43,46 +43,62 @@ function gen_outbound(flag, node, tag, proxy_table)
end
local remarks = node.remarks
local proxy_tag = nil
local dialer_proxy_tag = nil
local fragment = nil
local noise = nil
local run_socks_instance = true
local proxy_tag, dialer_proxy_tag, fragment, noise
if proxy_table ~= nil and type(proxy_table) == "table" then
proxy_tag = proxy_table.tag or nil
fragment = (proxy_table.fragment and not node.hysteria2_realms) and true or nil
noise = (proxy_table.noise and not node.hysteria2_realms) and true or nil
run_socks_instance = proxy_table.run_socks_instance
end
if node.type ~= "Xray" then
if node.type == "Socks" then
node.protocol = "socks"
node.transport = "tcp"
node.transport = "raw"
else
local relay_port = node.port
local new_port = api.get_new_port()
local config_file = string.format("%s_%s_%s.json", flag, tag, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("%s_%s_%s_%s.json", flag, tag, node_id, new_port)
end
if run_socks_instance then
sys.call(string.format('/usr/share/passwall/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
(proxy_tag and relay_port) and tostring(relay_port) or "" --relay port
local new_port
local run_socks_instance = true
if NO_RUN then
TMP_PORT = TMP_PORT and TMP_PORT + 1 or 3001
new_port = TMP_PORT
run_socks_instance = nil
else
local relay_port = (proxy_tag and node.port) and tostring(node.port) or ""
if relay_port == "" then
local cache = api.get_socks_port_by_cache(node_id)
if cache then
new_port = cache
run_socks_instance = nil
end
end
if run_socks_instance then
new_port = api.get_new_port()
local config_file = string.format("nodesocks_%s_%s.json", node_id, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("nodesocks_%s_%s_%s.json", tag, node_id, new_port)
end
sys.call(string.format('/usr/share/passwall/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
relay_port --relay port
)
)
)
))
if relay_port == "" then
api.set_socks_port_to_cache(node_id, new_port)
end
end
end
if new_port then
node = {}
node.protocol = "socks"
node.transport = "raw"
node.address = "127.0.0.1"
node.port = new_port
end
node = {}
node.protocol = "socks"
node.transport = "tcp"
node.address = "127.0.0.1"
node.port = new_port
end
node.stream_security = "none"
proxy_tag = "socks <- " .. node_id
@@ -156,7 +172,7 @@ function gen_outbound(flag, node, tag, proxy_table)
} or nil,
dialerProxy = dialer_proxy_tag,
},
[(api.compare_versions(xray_version, "<", "26.7.11")) and "network" or "method"] = node.transport, -- Todo: Remove version check and "network"
method = node.transport,
security = node.stream_security,
tlsSettings = (node.stream_security == "tls") and {
serverName = node.tls_serverName,
@@ -675,7 +691,7 @@ function gen_config_server(node)
protocol = node.protocol,
settings = settings,
streamSettings = {
[(api.compare_versions(xray_version, "<", "26.7.11")) and "network" or "method"] = node.transport, -- Todo: Remove version check and "network"
method = node.transport,
security = "none",
tlsSettings = ("1" == node.tls) and {
disableSystemRoot = false,
@@ -857,9 +873,6 @@ function gen_config_server(node)
config.outbounds[index][k] = nil
end
end
if value.protocol == "freedom" and api.compare_versions(xray_version, "<", "26.5.3") then -- Todo is to remove it
value.settings = nil
end
end
return config
@@ -897,10 +910,11 @@ function gen_config(var)
local dns_socks_address = var["dns_socks_address"]
local dns_socks_port = var["dns_socks_port"]
local loglevel = var["loglevel"] or "warning"
local no_run = var["no_run"]
local use_proxy_list = var["use_proxy_list"]
local use_gfw_list = var["use_gfw_list"]
local chn_list = var["chn_list"]
local run_in_global = var["run_in_global"]
NO_RUN = var["no_run"]
local dns_domain_rules = {}
local dns = nil
@@ -1075,7 +1089,9 @@ function gen_config(var)
blc_nodes = _node.balancing_node
end
-- api.log(" - 加载 Xray 负载均衡 节点【" .. (_node.remarks or "") .. "】,子节点数量:" .. #(blc_nodes or {}))
if not NO_RUN and run_in_global then
api.log(" - 加载 Xray 负载均衡 节点【" .. (_node.remarks or "") .. "】,子节点数量:" .. #(blc_nodes or {}))
end
local valid_nodes = {}
for i = 1, #(blc_nodes or {}) do
@@ -1090,7 +1106,7 @@ function gen_config(var)
end
end
if is_new_blc_node then
local outboundTag = gen_outbound_get_tag(flag, blc_node_id, blc_node_tag, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil, run_socks_instance = not no_run })
local outboundTag = gen_outbound_get_tag(flag, blc_node_id, blc_node_tag, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil })
if outboundTag then
valid_nodes[#valid_nodes + 1] = outboundTag
end
@@ -1119,7 +1135,7 @@ function gen_config(var)
local fallback_node = get_node_by_id(fallback_node_id)
if fallback_node then
if fallback_node.protocol ~= "_balancing" then
local outboundTag = gen_outbound_get_tag(flag, fallback_node, fallback_node_id, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil, run_socks_instance = not no_run })
local outboundTag = gen_outbound_get_tag(flag, fallback_node, fallback_node_id, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil })
if outboundTag then
fallback_node_tag = outboundTag
end
@@ -1251,7 +1267,6 @@ function gen_config(var)
})
to_outbound = gen_outbound(node[".name"], to_node, to_node[".name"], {
tag = to_node[".name"],
run_socks_instance = not no_run
})
else
to_outbound = gen_outbound(node[".name"], to_node)
@@ -1316,9 +1331,9 @@ function gen_config(var)
interface = node.iface
}
},
settings = (api.compare_versions(xray_version, ">", "26.4.25")) and { -- Todo: Remove version check
settings = {
finalRules = {{ action = "allow" }}
} or nil
}
}
sys.call(string.format("mkdir -p %s && touch %s/%s", api.TMP_IFACE_PATH, api.TMP_IFACE_PATH, node.iface))
end
@@ -1359,7 +1374,6 @@ function gen_config(var)
local proxy_table = {
fragment = xray_settings.fragment == "1",
noise = xray_settings.noise == "1",
run_socks_instance = not no_run,
}
local preproxy_node_id = node[rule_name .. "_proxy_tag"]
if preproxy_node_id == _node_id then preproxy_node_id = nil end
@@ -1561,7 +1575,6 @@ function gen_config(var)
COMMON.default_outbound_tag = gen_outbound_get_tag(flag, node or node_id, nil, {
fragment = xray_settings.fragment == "1" or nil,
noise = xray_settings.noise == "1" or nil,
run_socks_instance = not no_run
})
if COMMON.default_outbound_tag then
routing = {
@@ -1802,11 +1815,10 @@ function gen_config(var)
sockopt = { dialerProxy = (dns_outbound_tag ~= "blackhole") and dns_outbound_tag or "direct" }
} or nil,
settings = {
address = (chn_list ~= "proxy") and "8.8.8.8" or "223.5.5.5",
port = 53,
network = "tcp",
nonIPQuery = (api.compare_versions(xray_version, "<", "26.4.25")) and "reject" or nil, -- Todo is to remove it
rules = (api.compare_versions(xray_version, ">", "26.4.17")) and {} or nil
rewriteAddress = (chn_list ~= "proxy") and "8.8.8.8" or "223.5.5.5",
rewritePort = 53,
rewriteNetwork = "tcp",
rules = {}
}
}
@@ -2030,9 +2042,9 @@ function gen_config(var)
local direct_outbound = {
protocol = "freedom",
tag = "direct",
settings = (api.compare_versions(xray_version, ">", "26.4.25")) and { -- Todo: Remove version check
settings = {
finalRules = {{ action = "allow" }}
} or nil,
},
streamSettings = {
sockopt = {
mark = 255,
@@ -2058,7 +2070,7 @@ function gen_config(var)
for index, value in ipairs(config.outbounds) do
local pt = value.protocol
local exclude = { blackhole=1, dns=1, freedom=1, loopback=1 }
if not value["_flag_proxy_tag"] and value["_id"] and pt and not exclude[pt] and not no_run then
if not value["_flag_proxy_tag"] and value["_id"] and pt and not exclude[pt] and not NO_RUN then
sys.call(string.format("echo '%s' >> %s", value["_id"], api.TMP_PATH .. "/direct_node_list"))
end
for k, v in pairs(config.outbounds[index]) do
@@ -2136,7 +2148,7 @@ function gen_proto_config(var)
local outbound = {
protocol = server_proto,
streamSettings = {
network = "tcp",
method = "raw",
security = "none"
},
settings = {
@@ -2161,10 +2173,12 @@ function gen_proto_config(var)
table.insert(outbounds, {
protocol = "freedom",
tag = "direct",
settings = (api.compare_versions(xray_version, ">", "26.4.25")) and { -- Todo: Remove version check
settings = {
finalRules = {{ action = "allow" }}
} or nil,
sockopt = {mark = 255}
},
streamSettings = {
sockopt = {mark = 255}
}
})
local config = {
@@ -2176,7 +2190,10 @@ function gen_proto_config(var)
-- 传出连接
outbounds = outbounds,
-- 路由
routing = routing
routing = routing,
version = {
min = xray_min_version
}
}
return jsonc.stringify(config, 1)
end
@@ -249,10 +249,6 @@ local current_node = map:get(section)
if (v_transport === "ws") {
params += opt.query("host", dom_prefix + "ws_host");
params += opt.query("path", dom_prefix + "ws_path");
if (v_type == "sing-box" && opt.get(dom_prefix + "ws_enableEarlyData").checked) {
var ws_maxEarlyData = opt.get(dom_prefix + "ws_maxEarlyData").value;
params += "?ed=" + ws_maxEarlyData;
}
} else if (v_transport === "http") {
params += opt.query("host", dom_prefix + "http_host");
params += opt.query("path", dom_prefix + "http_path");
@@ -371,10 +367,6 @@ local current_node = map:get(section)
if (v_transport === "ws") {
info.host = opt.get(dom_prefix + "ws_host").value;
info.path = opt.get(dom_prefix + "ws_path").value;
if (v_type == "sing-box" && opt.get(dom_prefix + "ws_enableEarlyData").checked) {
var ws_maxEarlyData = opt.get(dom_prefix + "ws_maxEarlyData").value;
info.path = info.path + "?ed=" + ws_maxEarlyData;
}
} else if (v_transport === "http") {
info.host = opt.get(dom_prefix + "http_host").value;
info.path = opt.get(dom_prefix + "http_path").value;
@@ -431,10 +423,6 @@ local current_node = map:get(section)
if (v_transport === "ws") {
params += opt.query("host", dom_prefix + "ws_host");
params += opt.query("path", dom_prefix + "ws_path");
if (v_type == "sing-box" && opt.get(dom_prefix + "ws_enableEarlyData").checked) {
var ws_maxEarlyData = opt.get(dom_prefix + "ws_maxEarlyData").value;
params += encodeURIComponent("?ed=" + ws_maxEarlyData);
}
} else if (v_transport === "http") {
params += opt.query("host", dom_prefix + "http_host");
params += opt.query("path", dom_prefix + "http_path");
@@ -523,10 +511,6 @@ local current_node = map:get(section)
if (v_transport === "ws") {
params += opt.query("host", dom_prefix + "ws_host");
params += opt.query("path", dom_prefix + "ws_path");
if (v_type == "sing-box" && opt.get(dom_prefix + "ws_enableEarlyData").checked) {
var ws_maxEarlyData = opt.get(dom_prefix + "ws_maxEarlyData").value;
params += "?ed=" + ws_maxEarlyData;
}
} else if (v_transport === "http") {
params += opt.query("host", dom_prefix + "http_host");
params += opt.query("path", dom_prefix + "http_path");
@@ -1085,24 +1069,6 @@ local current_node = map:get(section)
} else if (queryParam.type === "ws") {
opt.set(dom_prefix + 'ws_host', queryParam.host || "");
opt.set(dom_prefix + 'ws_path', queryParam.path || "");
if (dom_prefix == "singbox_" && queryParam.path && queryParam.path.length > 1) {
var ws_path_params = {};
var ws_path_dat = queryParam.path.split('?');
var ws_path = ws_path_dat[0];
var ws_path_params = {};
var ws_path_params_array = (ws_path_dat[1] || '').split('&');
for (i = 0; i < ws_path_params_array.length; i++) {
var kv = ws_path_params_array[i].split('=');
ws_path_params[decodeURIComponent(kv[0]).toLowerCase()] = decodeURIComponent(kv[1] || '');
}
if (ws_path_params.ed) {
opt.set(dom_prefix + 'ws_path', ws_path);
opt.set(dom_prefix + 'ws_enableEarlyData', true);
opt.set(dom_prefix + 'ws_maxEarlyData', ws_path_params.ed);
opt.set(dom_prefix + 'ws_earlyDataHeaderName', 'Sec-WebSocket-Protocol');
}
}
} else if (queryParam.type === "http") {
if (dom_prefix == "xray_") {
opt.set(dom_prefix + 'xhttp_mode', "stream-one");
@@ -1232,24 +1198,6 @@ local current_node = map:get(section)
} else if (queryParam.type === "ws") {
opt.set(dom_prefix + 'ws_host', queryParam.host || "");
opt.set(dom_prefix + 'ws_path', queryParam.path || "");
if (dom_prefix == "singbox_" && queryParam.path && queryParam.path.length > 1) {
var ws_path_params = {};
var ws_path_dat = queryParam.path.split('?');
var ws_path = ws_path_dat[0];
var ws_path_params = {};
var ws_path_params_array = (ws_path_dat[1] || '').split('&');
for (i = 0; i < ws_path_params_array.length; i++) {
var kv = ws_path_params_array[i].split('=');
ws_path_params[decodeURIComponent(kv[0]).toLowerCase()] = decodeURIComponent(kv[1] || '');
}
if (ws_path_params.ed) {
opt.set(dom_prefix + 'ws_path', ws_path);
opt.set(dom_prefix + 'ws_enableEarlyData', true);
opt.set(dom_prefix + 'ws_maxEarlyData', ws_path_params.ed);
opt.set(dom_prefix + 'ws_earlyDataHeaderName', 'Sec-WebSocket-Protocol');
}
}
} else if (queryParam.type === "http") {
if (dom_prefix == "xray_") {
opt.set(dom_prefix + 'xhttp_mode', "stream-one");
@@ -1374,24 +1322,6 @@ local current_node = map:get(section)
} else if (ssm.net === "ws") {
opt.set(dom_prefix + 'ws_host', ssm.host);
opt.set(dom_prefix + 'ws_path', ssm.path);
if (dom_prefix == "singbox_" && ssm.path && ssm.path.length > 1) {
var ws_path_params = {};
var ws_path_dat = ssm.path.split('?');
var ws_path = ws_path_dat[0];
var ws_path_params = {};
var ws_path_params_array = (ws_path_dat[1] || '').split('&');
for (i = 0; i < ws_path_params_array.length; i++) {
var kv = ws_path_params_array[i].split('=');
ws_path_params[decodeURIComponent(kv[0]).toLowerCase()] = decodeURIComponent(kv[1] || '');
}
if (ws_path_params.ed) {
opt.set(dom_prefix + 'ws_path', ws_path);
opt.set(dom_prefix + 'ws_enableEarlyData', true);
opt.set(dom_prefix + 'ws_maxEarlyData', ws_path_params.ed);
opt.set(dom_prefix + 'ws_earlyDataHeaderName', 'Sec-WebSocket-Protocol');
}
}
} else if (ssm.net === "http") {
if (dom_prefix == "xray_") {
opt.set(dom_prefix + 'xhttp_mode', "stream-one");
@@ -1517,24 +1447,6 @@ local current_node = map:get(section)
} else if (queryParam.type === "ws") {
opt.set(dom_prefix + 'ws_host', queryParam.host || "");
opt.set(dom_prefix + 'ws_path', queryParam.path || "");
if (dom_prefix == "singbox_" && queryParam.path && queryParam.path.length > 1) {
var ws_path_params = {};
var ws_path_dat = queryParam.path.split('?');
var ws_path = ws_path_dat[0];
var ws_path_params = {};
var ws_path_params_array = (ws_path_dat[1] || '').split('&');
for (i = 0; i < ws_path_params_array.length; i++) {
var kv = ws_path_params_array[i].split('=');
ws_path_params[decodeURIComponent(kv[0]).toLowerCase()] = decodeURIComponent(kv[1] || '');
}
if (ws_path_params.ed) {
opt.set(dom_prefix + 'ws_path', ws_path);
opt.set(dom_prefix + 'ws_enableEarlyData', true);
opt.set(dom_prefix + 'ws_maxEarlyData', ws_path_params.ed);
opt.set(dom_prefix + 'ws_earlyDataHeaderName', 'Sec-WebSocket-Protocol');
}
}
} else if (queryParam.type === "h2" || queryParam.type === "http") {
if (dom_prefix == "xray_") {
opt.set(dom_prefix + 'xhttp_mode', "stream-one");
@@ -1402,6 +1402,7 @@ table td, .table .td {
var node_tr_html = "";
for (var i = 0; i < group_nodes[group].length; i++) {
let o = group_nodes[group][i]
let _port = o["port"] || o["hysteria_hop"] || o["hysteria2_hop"];
var newDom = node_template.cloneNode(true);
newDom.classList.add("cbi-rowstyle-" + (i % 2 + 1));
var innerHTML = newDom.innerHTML;
@@ -1415,17 +1416,15 @@ table td, .table .td {
} else {
innerHTML = innerHTML.split("{{tcping}}").join('<span class="tcping_value" cbiid="{{id}}"><a href="javascript:void(0)" style="color:inherit">---</a></span>');
}
let is_realm = (o.type === "Hysteria2" || o.protocol === 'hysteria2') && o.hysteria2_realms || false;
if (o["protocol"] === '_shunt' || is_realm) {
innerHTML = innerHTML.split("{{url_test}}").join('<span class="ping" cbiid="{{id}}">---</span>');
} else {
if (o["address"] && _port) {
innerHTML = innerHTML.split("{{url_test}}").join('<span class="ping"><a href="javascript:void(0)" onclick="javascript:urltest_node(\'{{id}}\', this)" title="<%:TLS handshake test, latency for reference only%>"><%:Test%></a></span>');
} else {
innerHTML = innerHTML.split("{{url_test}}").join('<span class="ping" cbiid="{{id}}">---</span>');
}
innerHTML = innerHTML.split("{{id}}").join(o[".name"]);
innerHTML = innerHTML.split("{{group}}").join(o["group"] || "");
let node_remarks = get_remarks_name(o);
if (show_node_info == "1") {
let _port = o["port"] || o["hysteria_hop"] || o["hysteria2_hop"];
if (_port) _port = _port.replace(/:/g, '-');
if (o["address"] && _port) {
let _address = o["address"]
-36
View File
@@ -1643,36 +1643,6 @@ msgstr "启用节点日志"
msgid "Log Level"
msgstr "日志等级"
msgid "Advanced log feature"
msgstr "高级日志功能"
msgid "For professionals only."
msgstr "仅限专业人士使用。"
msgid "Persist log file directory"
msgstr "持久性日志文件目录"
msgid "The path to the directory used to store persist log files, the \"/\" at the end can be omitted. Leave it blank to disable this feature."
msgstr "用来存储持久性日志文件的目录路径,末尾的 “/” 可以省略。留空以禁用此功能。"
msgid "Logging to system log"
msgstr "记录到系统日志"
msgid "Logging to the system log for more advanced functions. For example, send logs to a dedicated log server."
msgstr "将日志记录到系统日志,以实现更加高级的功能。例如,把日志发送到专门的日志服务器。"
msgid "Log Event Filter"
msgstr "日志事件过滤器"
msgid "Support regular expression."
msgstr "支持正则表达式。"
msgid "Shell Command"
msgstr "Shell 命令"
msgid "Shell command to execute, replace log content with %s."
msgstr "要执行的 Shell 命令,用 %s 代替日志内容。"
msgid "Not enabled log"
msgstr "未启用日志"
@@ -1745,12 +1715,6 @@ msgstr "XUDP 最大并发连接数"
msgid "Padding"
msgstr "填充"
msgid "Enable early data"
msgstr "启用前置数据"
msgid "Early data length"
msgstr "前置数据最大长度"
msgid "Early data header name"
msgstr "前置数据 HTTP 头名"
@@ -1,17 +1,12 @@
#!/bin/sh
# Devices without a hardware RTC boot with a wrong system clock: sysfixtime can
# only restore the mtime of the newest file under /etc, so the clock is usually
# hours behind after a cold boot. passwall is then started by
# /etc/hotplug.d/iface/98-passwall on ifup, which typically happens before NTP
# has corrected the time, and time-sensitive handshakes (VMess AEAD, TLS) fail.
#
# Nothing restarts passwall once the clock is corrected, so it stays broken
# until the user restarts it manually. Restart once when ntpd reports that the
# time is valid -- the same approach dnsmasq uses for DNSSEC in
# /etc/hotplug.d/ntp/25-dnsmasqsec.
[ "$ACTION" = "step" ] || exit 0
[ "$ACTION" = "stratum" ] || exit 0
offset=${offset#-}
offset=${offset%.*}
# Skip service restart if the time adjustment is less than 120 seconds.
[ "$offset" -lt 120 ] && exit 0
. /usr/share/passwall/utils.sh
@@ -23,5 +18,5 @@ NTP_LOCK_FILE="${LOCK_PATH}/${CONFIG}_ntp.lock"
echo $$ > ${NTP_LOCK_FILE}
/etc/init.d/${CONFIG} restart >/dev/null 2>&1 &
logger -p notice -t network -s "${CONFIG}: restart after NTP time became valid"
logger -p notice -t network -s "${CONFIG}: restart after NTP time step (${offset}s)"
}
@@ -87,7 +87,7 @@ run_ipt2socks() {
run_singbox() {
local flag type node redir_port tcp_proxy_way socks_address socks_port socks_username socks_password http_address http_port http_username http_password
local dns_listen_port direct_dns_query_strategy direct_dns_port direct_dns_udp_server direct_dns_tcp_server remote_dns_protocol remote_dns_udp_server remote_dns_tcp_server remote_dns_doh remote_dns_client_ip remote_fakedns remote_dns_query_strategy remote_rewrite_ttl dns_cache dns_socks_address dns_socks_port
local loglevel log_file config_file server_host server_port no_run use_proxy_list use_gfw_list chn_list
local loglevel log_file config_file server_host server_port no_run use_proxy_list use_gfw_list chn_list run_in_global
eval_set_val "$@"
[ -z "$type" ] && {
type=$(echo $(config_n_get $node type) | tr 'A-Z' 'a-z')
@@ -182,13 +182,17 @@ run_singbox() {
[ "$remote_fakedns" = "1" ] && json_add_string "remote_dns_fake" "1"
[ -n "$remote_rewrite_ttl" ] && json_add_string "remote_rewrite_ttl" "${remote_rewrite_ttl}"
[ -n "$no_run" ] && json_add_string "no_run" "1"
[ -n "$run_in_global" ] && json_add_string "run_in_global" "1"
local _json_arg="$(json_dump)"
lua $UTIL_SINGBOX gen_config "${_json_arg}" > $config_file
[ -n "$no_run" ] && return
local test_log_file=$log_file
local status=0
[ "$test_log_file" = "/dev/null" ] && test_log_file="${TMP_PATH}/${config_file##*/}_test.log"
$SINGBOX_BIN check -c "$config_file" > $test_log_file 2>&1; local status=$?
[ -n "$run_in_global" ] && {
$SINGBOX_BIN check -c "$config_file" > $test_log_file 2>&1; status=$?
}
if [ "${status}" = 0 ]; then
ln_run "$SINGBOX_BIN" "sing-box" "${log_file}" run -c "$config_file"
else
@@ -201,7 +205,7 @@ run_singbox() {
run_xray() {
local flag type node redir_port tcp_proxy_way socks_address socks_port socks_username socks_password http_address http_port http_username http_password
local dns_listen_port direct_dns_query_strategy direct_dns_port direct_dns_udp_server direct_dns_tcp_server remote_dns_protocol remote_dns_udp_server remote_dns_tcp_server remote_dns_doh remote_dns_client_ip remote_fakedns remote_dns_query_strategy dns_cache dns_socks_address dns_socks_port
local loglevel log_file config_file server_host server_port no_run use_proxy_list use_gfw_list chn_list
local loglevel log_file config_file server_host server_port no_run use_proxy_list use_gfw_list chn_list run_in_global
eval_set_val "$@"
[ -z "$type" ] && {
type=$(echo $(config_n_get $node type) | tr 'A-Z' 'a-z')
@@ -278,13 +282,17 @@ run_xray() {
json_add_string "loglevel" "$loglevel"
[ -n "$no_run" ] && json_add_string "no_run" "1"
[ -n "$run_in_global" ] && json_add_string "run_in_global" "1"
local _json_arg="$(json_dump)"
lua $UTIL_XRAY gen_config "${_json_arg}" > $config_file
[ -n "$no_run" ] && return
local test_log_file=$log_file
local status=0
[ "$test_log_file" = "/dev/null" ] && test_log_file="${TMP_PATH}/${config_file##*/}_test.log"
$XRAY_BIN run -test -c "$config_file" > $test_log_file; local status=$?
[ -n "$run_in_global" ] && {
$XRAY_BIN run -test -c "$config_file" > $test_log_file; status=$?
}
if [ "${status}" = 0 ]; then
ln_run "$XRAY_BIN" "xray" "${log_file}" run -c "$config_file"
else
@@ -489,8 +497,6 @@ run_socks() {
;;
esac
set_cache_var "node_${node}_socks_port" "${socks_port}"
# http to socks
[ -z "$http_flag" ] && [ "$http_port" != "0" ] && [ -n "$http_config_file" ] && [ "$type" != "sing-box" ] && [ "$type" != "xray" ] && [ "$type" != "socks" ] && {
json_init
@@ -601,7 +607,7 @@ start_global() {
;;
sing-box)
local _flag="global"
local _args=""
local _args="run_in_global=1"
[ "$on_node_socks" = "1" ] && {
node_socks_flag=1
_args="${_args} socks_address=${node_socks_bind} socks_port=${GLOBAL_SOCKS_port}"
@@ -679,7 +685,7 @@ start_global() {
;;
xray)
local _flag="global"
local _args=""
local _args="run_in_global=1"
[ "$on_node_socks" = "1" ] && {
node_socks_flag=1
_args="${_args} socks_address=${node_socks_bind} socks_port=${GLOBAL_SOCKS_port}"
@@ -829,7 +835,6 @@ start_global() {
set_cache_var "GLOBAL_SOCKS_server" "${GLOBAL_SOCKS_server}"
}
[ "$type" != "sing-box" ] && [ "$type" != "xray" ] && echo "${NODE}" >> $TMP_PATH/direct_node_list
set_cache_var "node_${NODE}_redir_port" "$REDIR_PORT"
set_cache_var "ACL_GLOBAL_node" "$NODE"
set_cache_var "ACL_GLOBAL_redir_port" "$REDIR_PORT"
}
@@ -1570,9 +1575,9 @@ acl_app() {
#dhcp.leases to hosts
$APP_PATH/lease2hosts.sh > /dev/null 2>&1 &
}
local _redir_port=$(get_cache_var "node_${node}_redir_port")
local _socks_port=$(get_cache_var "node_${node}_socks_port")
local _enable_log=$(get_cache_var "node_${node}_enable_log")
local _redir_port=$(get_cache_var "acl_node_${node}_redir_port")
local _socks_port=$(get_cache_var "acl_node_${node}_socks_port")
local _enable_log=$(get_cache_var "acl_node_${node}_enable_log")
local _dns_port
if [ -n "${_socks_port}" ] && [ -n "${_redir_port}" ] && [ "${_enable_log}" != "1" ] && [ "${log}" != "1" ]; then
socks_port=${_socks_port}
@@ -1581,14 +1586,14 @@ acl_app() {
run_dns ${_dns_port}
else
socks_port=$(get_new_port $(expr $socks_port + 1))
set_cache_var "node_${node}_socks_port" "${socks_port}"
set_cache_var "acl_node_${node}_socks_port" "${socks_port}"
redir_port=$(get_new_port $(expr $redir_port + 1))
set_cache_var "node_${node}_redir_port" "${redir_port}"
set_cache_var "acl_node_${node}_redir_port" "${redir_port}"
node_port=$redir_port
local log_file="/dev/null"
[ "${log}" = "1" ] && {
log_file="${TMP_ACL_PATH}/${sid}/node.log"
set_cache_var "node_${node}_enable_log" "1"
set_cache_var "acl_node_${node}_enable_log" "1"
}
if [ "${type}" = "sing-box" ] || [ "${type}" = "xray" ]; then
@@ -88,7 +88,16 @@ local function build_common(node)
if net == "ws" then
local opts = node["ws-opts"]
if opts then
o.transport.path = opts.path
local path = opts.path or "/"
local ed = opts["max-early-data"]
local eh = opts["early-data-header-name"]
if ed then
path = path .. "?ed=" .. ed
end
if eh then
path = path .. (path:find("?", 1, true) and "&eh=" or "?eh=") .. eh
end
o.transport.path = path
o.transport.host = opts.headers and opts.headers.Host
end
@@ -109,20 +109,26 @@ api.uci_foreach_c("haproxy_config", function(t)
t.origin_port = server_port
if health_check_type == "script_logic" then
if server_node.type ~= "Socks" then
local relay_port = server_node.port
local new_port = api.get_new_port()
local config_file = string.format("%s_%s.json", t[".name"], new_port)
sys.call(string.format('/usr/share/%s/app.sh run_socks "%s"> /dev/null',
appname,
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s",
new_port, --flag
server_node[".name"], --node
"127.0.0.1", --bind
new_port, --socks port
config_file --config file
local new_port
local cache = api.get_socks_port_by_cache(server_node[".name"])
if cache then
new_port = cache
else
new_port = api.get_new_port()
local config_file = string.format("%s_%s.json", t[".name"], new_port)
sys.call(string.format('/usr/share/%s/app.sh run_socks "%s"> /dev/null',
appname,
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s",
new_port, --flag
server_node[".name"], --node
"127.0.0.1", --bind
new_port, --socks port
config_file --config file
)
)
)
)
api.set_socks_port_to_cache(server_node[".name"], new_port)
end
server_address = "127.0.0.1"
server_port = new_port
end
@@ -408,16 +408,16 @@ load_acl() {
else
[ -n "${DIRECT_DNSMASQ_PORT}" ] && dns_redirect=${DIRECT_DNSMASQ_PORT}
fi
if [ -n "${dns_redirect}" ]; then
if ([ -n "$tcp_port" ] || [ -n "$udp_port" ]) && [ -n "$dns_redirect" ]; then
$ipt_m -A PSW $(comment "$remarks") -p udp ${_ipt_source} --dport 53 -j RETURN
[ "$_ipv4" != "1" ] && $ip6t_m -A PSW $(comment "$remarks") -p udp ${_ipt_source} --dport 53 -j RETURN 2>/dev/null
$ip6t_m -A PSW $(comment "$remarks") -p udp ${_ipt_source} --dport 53 -j RETURN 2>/dev/null
$ipt_m -A PSW $(comment "$remarks") -p tcp ${_ipt_source} --dport 53 -j RETURN
[ "$_ipv4" != "1" ] && $ip6t_m -A PSW $(comment "$remarks") -p tcp ${_ipt_source} --dport 53 -j RETURN 2>/dev/null
$ip6t_m -A PSW $(comment "$remarks") -p tcp ${_ipt_source} --dport 53 -j RETURN 2>/dev/null
$ipt_n -A PSW_DNS $(comment "$remarks") -p udp ${_ipt_source} --dport 53 -j REDIRECT --to-ports ${dns_redirect}
[ "$_ipv4" != "1" ] && $ip6t_n -A PSW_DNS $(comment "$remarks") -p udp ${_ipt_source} --dport 53 -j REDIRECT --to-ports ${dns_redirect} 2>/dev/null
$ip6t_n -A PSW_DNS $(comment "$remarks") -p udp ${_ipt_source} --dport 53 -j REDIRECT --to-ports ${dns_redirect} 2>/dev/null
$ipt_n -A PSW_DNS $(comment "$remarks") -p tcp ${_ipt_source} --dport 53 -j REDIRECT --to-ports ${dns_redirect}
[ "$_ipv4" != "1" ] && $ip6t_n -A PSW_DNS $(comment "$remarks") -p tcp ${_ipt_source} --dport 53 -j REDIRECT --to-ports ${dns_redirect} 2>/dev/null
[ -z "$(get_cache_var "ACL_${sid}_default")" ] && echolog " - ${msg}节点不同于全局配置,DNS 重定向到专用服务器[${dns_redirect}]"
$ip6t_n -A PSW_DNS $(comment "$remarks") -p tcp ${_ipt_source} --dport 53 -j REDIRECT --to-ports ${dns_redirect} 2>/dev/null
[ -z "$(get_cache_var "ACL_${sid}_default")" ] && echolog " - ${msg}节点不同于全局配置,DNS 重定向到专用服务器[${dns_redirect}]"
fi
[ -n "$tcp_port" ] || [ -n "$udp_port" ] && {
@@ -597,7 +597,7 @@ load_acl() {
[ -n "${DIRECT_DNSMASQ_PORT}" ] && DNS_REDIRECT=${DIRECT_DNSMASQ_PORT}
fi
if [ -n "${DNS_REDIRECT}" ]; then
if ([ -n "${TCP_PROXY_MODE}" ] || [ -n "${UDP_PROXY_MODE}" ]) && [ -n "$DNS_REDIRECT" ]; then
$ipt_m -A PSW $(comment "默认") -p udp --dport 53 -j RETURN
$ip6t_m -A PSW $(comment "默认") -p udp --dport 53 -j RETURN 2>/dev/null
$ipt_m -A PSW $(comment "默认") -p tcp --dport 53 -j RETURN
@@ -606,6 +606,7 @@ load_acl() {
$ip6t_n -A PSW_DNS $(comment "默认") -p udp --dport 53 -j REDIRECT --to-ports ${DNS_REDIRECT} 2>/dev/null
$ipt_n -A PSW_DNS $(comment "默认") -p tcp --dport 53 -j REDIRECT --to-ports ${DNS_REDIRECT}
$ip6t_n -A PSW_DNS $(comment "默认") -p tcp --dport 53 -j REDIRECT --to-ports ${DNS_REDIRECT} 2>/dev/null
echolog " - ${msg}DNS 重定向到专用服务器[${DNS_REDIRECT}]"
fi
[ -n "${TCP_PROXY_MODE}" ] || [ -n "${UDP_PROXY_MODE}" ] && {
@@ -1098,7 +1099,7 @@ add_firewall_rule() {
insert_rule_before "$ipt_m" "PREROUTING" "mwan3" "-j PSW"
# Only TCP, UDP Invalid.
insert_rule_before "$ipt_m" "PREROUTING" "PSW" "-p tcp -m socket -j PSW_DIVERT"
insert_rule_before "$ipt_m" "PREROUTING" "PSW" "-p tcp -m socket --transparent -j PSW_DIVERT"
$ipt_m -N PSW_OUTPUT
$ipt_m -A PSW_OUTPUT $(dst $IPSET_LAN) -j RETURN
@@ -1172,7 +1173,7 @@ add_firewall_rule() {
insert_rule_before "$ip6t_m" "PREROUTING" "mwan3" "-j PSW"
# Only TCP, UDP Invalid.
insert_rule_before "$ip6t_m" "PREROUTING" "PSW" "-p tcp -m socket -j PSW_DIVERT"
insert_rule_before "$ip6t_m" "PREROUTING" "PSW" "-p tcp -m socket --transparent -j PSW_DIVERT"
$ip6t_m -N PSW_OUTPUT
$ip6t_m -A PSW_OUTPUT -m mark --mark 0xff/0xff -j RETURN
@@ -1477,7 +1478,7 @@ gen_include() {
[ -z "${_ipt}" ] && return
echo "*$2"
${_ipt}-save -t $2 | grep "PSW" | grep -v "\-j PSW$" | grep -v "mangle\-OUTPUT\-PSW" | grep -v "socket \-j PSW_DIVERT$" | sed -e "s/^-A \(OUTPUT\|PREROUTING\)/-I \1 1/"
${_ipt}-save -t $2 | grep "PSW" | grep -v "\-j PSW$" | grep -v "mangle\-OUTPUT\-PSW" | grep -v "\-m socket .*\-j PSW_DIVERT$" | sed -e "s/^-A \(OUTPUT\|PREROUTING\)/-I \1 1/"
echo 'COMMIT'
}
local __ipt=""
@@ -1501,7 +1502,7 @@ gen_include() {
[ -z "${is_tproxy}" ] && \$(${MY_PATH} insert_rule_after "$ipt_n" "PREROUTING" "prerouting_rule" "-p tcp -j PSW")
\$(${MY_PATH} insert_rule_before "$ipt_m" "PREROUTING" "mwan3" "-j PSW")
\$(${MY_PATH} insert_rule_before "$ipt_m" "PREROUTING" "PSW" "-p tcp -m socket -j PSW_DIVERT")
\$(${MY_PATH} insert_rule_before "$ipt_m" "PREROUTING" "PSW" "-p tcp -m socket --transparent -j PSW_DIVERT")
EOF
)
}
@@ -1522,7 +1523,7 @@ gen_include() {
[ "$accept_icmpv6" = "1" ] && $ip6t_n -A PREROUTING -p ipv6-icmp -j PSW
\$(${MY_PATH} insert_rule_before "$ip6t_m" "PREROUTING" "mwan3" "-j PSW")
\$(${MY_PATH} insert_rule_before "$ip6t_m" "PREROUTING" "PSW" "-p tcp -m socket -j PSW_DIVERT")
\$(${MY_PATH} insert_rule_before "$ip6t_m" "PREROUTING" "PSW" "-p tcp -m socket --transparent -j PSW_DIVERT")
EOF
)
}
@@ -469,16 +469,15 @@ load_acl() {
else
[ -n "${DIRECT_DNSMASQ_PORT}" ] && dns_redirect=${DIRECT_DNSMASQ_PORT}
fi
if [ -n "${dns_redirect}" ]; then
if ([ -n "$tcp_port" ] || [ -n "$udp_port" ]) && [ -n "$dns_redirect" ]; then
nft "add rule $NFTABLE_NAME PSW_MANGLE ip protocol udp ${_ipt_source} udp dport 53 counter return comment \"$remarks\""
[ "$_ipv4" != "1" ] && nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto udp ${_ipt_source} udp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW_MANGLE ip protocol tcp ${_ipt_source} tcp dport 53 counter return comment \"$remarks\""
[ "$_ipv4" != "1" ] && nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto tcp ${_ipt_source} tcp dport 53 counter return comment \"$remarks\""
#nft "add rule $NFTABLE_NAME PSW_DNS ip protocol udp ${_ipt_source} udp dport 53 counter redirect to :${dns_redirect} comment \"$remarks\""
#nft "add rule $NFTABLE_NAME PSW_DNS ip protocol tcp ${_ipt_source} tcp dport 53 counter redirect to :${dns_redirect} comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW_DNS meta l4proto udp ${_ipt_source} udp dport 53 counter redirect to :${dns_redirect} comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW_DNS meta l4proto tcp ${_ipt_source} tcp dport 53 counter redirect to :${dns_redirect} comment \"$remarks\""
[ -z "$(get_cache_var "ACL_${sid}_default")" ] && echolog " - ${msg}节点不同于全局配置,DNS 重定向到专用服务器[${dns_redirect}]。"
nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto udp ${_ipt_source} udp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto tcp ${_ipt_source} tcp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW_DNS meta l4proto udp ${_ipt_source} udp dport 53 counter redirect to :$dns_redirect comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW_DNS meta l4proto tcp ${_ipt_source} tcp dport 53 counter redirect to :$dns_redirect comment \"$remarks\""
[ -z "$(get_cache_var "ACL_${sid}_default")" ] && echolog " - ${msg}节点不同于全局配置,DNS 重定向到专用服务器[${dns_redirect}]"
fi
[ -n "$tcp_port" ] || [ -n "$udp_port" ] && {
@@ -657,15 +656,14 @@ load_acl() {
[ -n "${DIRECT_DNSMASQ_PORT}" ] && DNS_REDIRECT=${DIRECT_DNSMASQ_PORT}
fi
if [ -n "${DNS_REDIRECT}" ]; then
if ([ -n "${TCP_PROXY_MODE}" ] || [ -n "${UDP_PROXY_MODE}" ]) && [ -n "$DNS_REDIRECT" ]; then
nft "add rule $NFTABLE_NAME PSW_MANGLE ip protocol udp udp dport 53 counter return comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto udp udp dport 53 counter return comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_MANGLE ip protocol tcp tcp dport 53 counter return comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto udp udp dport 53 counter return comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_MANGLE_V6 meta l4proto tcp tcp dport 53 counter return comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_DNS ip protocol udp udp dport 53 counter redirect to :${DNS_REDIRECT} comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_DNS ip protocol tcp tcp dport 53 counter redirect to :${DNS_REDIRECT} comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_DNS meta l4proto udp udp dport 53 counter redirect to :${DNS_REDIRECT} comment \"默认\""
nft "add rule $NFTABLE_NAME PSW_DNS meta l4proto tcp tcp dport 53 counter redirect to :${DNS_REDIRECT} comment \"默认\""
echolog " - ${msg}DNS 重定向到专用服务器[${DNS_REDIRECT}]"
fi
[ -n "${TCP_PROXY_MODE}" ] || [ -n "${UDP_PROXY_MODE}" ] && {
@@ -1310,8 +1308,6 @@ add_firewall_rule() {
if [ -n "$NODE" ] && ([ -n "${LOCALHOST_TCP_PROXY_MODE}" ] || [ -n "${LOCALHOST_UDP_PROXY_MODE}" ]); then
[ -n "$DNS_REDIRECT_PORT" ] && {
nft "add rule $NFTABLE_NAME nat_output ip protocol udp oif lo udp dport 53 counter redirect to :$DNS_REDIRECT_PORT comment \"PSW_DNS\""
nft "add rule $NFTABLE_NAME nat_output ip protocol tcp oif lo tcp dport 53 counter redirect to :$DNS_REDIRECT_PORT comment \"PSW_DNS\""
nft "add rule $NFTABLE_NAME nat_output meta l4proto udp oif lo udp dport 53 counter redirect to :$DNS_REDIRECT_PORT comment \"PSW_DNS\""
nft "add rule $NFTABLE_NAME nat_output meta l4proto tcp oif lo tcp dport 53 counter redirect to :$DNS_REDIRECT_PORT comment \"PSW_DNS\""
}
@@ -183,8 +183,6 @@ test_auto_switch() {
start() {
id=$1
LOCK_FILE=${LOCK_PATH}/${CONFIG}_socks_auto_switch_${id}.lock
LOG_EVENT_FILTER=$(uci -q get "${CONFIG}.global[0].log_event_filter" 2>/dev/null)
LOG_EVENT_CMD=$(uci -q get "${CONFIG}.global[0].log_event_cmd" 2>/dev/null)
main_node=$(config_n_get $id node)
socks_port=$(config_n_get $id port 0)
delay=$(config_n_get $id autoswitch_testing_time 30)
@@ -641,21 +641,6 @@ local function processData(szType, content, add_mode, group, sub_cfg)
if info.net == 'ws' then
result.ws_host = info.host
result.ws_path = info.path
if result.type == "sing-box" and info.path then
local ws_path_dat = split(info.path, "?")
local ws_path = ws_path_dat[1]
local ws_path_params = {}
for _, v in pairs(split(ws_path_dat[2], '&')) do
local t = split(v, '=')
ws_path_params[t[1]] = t[2]
end
if ws_path_params.ed and tonumber(ws_path_params.ed) then
result.ws_path = ws_path
result.ws_enableEarlyData = "1"
result.ws_maxEarlyData = tonumber(ws_path_params.ed)
result.ws_earlyDataHeaderName = "Sec-WebSocket-Protocol"
end
end
end
if info.net == "http" then
if result.type == "Xray" then
@@ -897,21 +882,6 @@ local function processData(szType, content, add_mode, group, sub_cfg)
if params.type == 'ws' then
result.ws_host = params.host
result.ws_path = params.path
if result.type == "sing-box" and params.path then
local ws_path_dat = split(params.path, "%?")
local ws_path = ws_path_dat[1]
local ws_path_params = {}
for _, v in pairs(split(ws_path_dat[2], '&')) do
local t = split(v, '=')
ws_path_params[t[1]] = t[2]
end
if ws_path_params.ed and tonumber(ws_path_params.ed) then
result.ws_path = ws_path
result.ws_enableEarlyData = "1"
result.ws_maxEarlyData = tonumber(ws_path_params.ed)
result.ws_earlyDataHeaderName = "Sec-WebSocket-Protocol"
end
end
end
if params.type == "http" then
if result.type == "sing-box" then
@@ -1124,21 +1094,6 @@ local function processData(szType, content, add_mode, group, sub_cfg)
if params.type == 'ws' then
result.ws_host = params.host
result.ws_path = params.path
if result.type == "sing-box" and params.path then
local ws_path_dat = split(params.path, "%?")
local ws_path = ws_path_dat[1]
local ws_path_params = {}
for _, v in pairs(split(ws_path_dat[2], '&')) do
local t = split(v, '=')
ws_path_params[t[1]] = t[2]
end
if ws_path_params.ed and tonumber(ws_path_params.ed) then
result.ws_path = ws_path
result.ws_enableEarlyData = "1"
result.ws_maxEarlyData = tonumber(ws_path_params.ed)
result.ws_earlyDataHeaderName = "Sec-WebSocket-Protocol"
end
end
end
if params.type == "http" then
if result.type == "sing-box" then
@@ -1266,21 +1221,6 @@ local function processData(szType, content, add_mode, group, sub_cfg)
if params.type == 'ws' then
result.ws_host = params.host
result.ws_path = params.path
if result.type == "sing-box" and params.path then
local ws_path_dat = split(params.path, "%?")
local ws_path = ws_path_dat[1]
local ws_path_params = {}
for _, v in pairs(split(ws_path_dat[2], '&')) do
local t = split(v, '=')
ws_path_params[t[1]] = t[2]
end
if ws_path_params.ed and tonumber(ws_path_params.ed) then
result.ws_path = ws_path
result.ws_enableEarlyData = "1"
result.ws_maxEarlyData = tonumber(ws_path_params.ed)
result.ws_earlyDataHeaderName = "Sec-WebSocket-Protocol"
end
end
end
if params.type == "http" then
if result.type == "sing-box" then
@@ -60,6 +60,63 @@ config_t_get() {
echo "${ret:=${3}}"
}
eval_set_val() {
for i in $@; do
for j in $i; do
eval $j
done
done
}
eval_unset_val() {
for i in $@; do
for j in $i; do
eval unset $j
done
done
}
lua_api() {
local func=${1}
[ -z "${func}" ] && {
echo "nil"
return
}
echo $(lua -e "local api = require 'luci.passwall.api' print(api.${func})")
}
eval_cache_var() {
[ -s "$TMP_PATH/var" ] && eval $(cat "$TMP_PATH/var")
}
del_cache_var() {
local key="${1}"
[ -n "${key}" ] && [ -f "${TMP_PATH}/var" ] && {
sed -i "/${key}=/d" $TMP_PATH/var >/dev/null 2>&1
}
}
set_cache_var() {
local key="${1}"
shift 1
[ -n "${key}" ] && {
del_cache_var ${key}
local val="$@"
[ -n "${val}" ] && {
[ ! -d $TMP_PATH ] && mkdir -p $TMP_PATH
echo "${key}=\"${val}\"" >> $TMP_PATH/var
eval ${key}=\"${val}\"
}
}
}
get_cache_var() {
local key="${1}"
[ -n "${key}" ] && [ -s "$TMP_PATH/var" ] && {
echo $(cat $TMP_PATH/var | grep "^${key}=" | awk -F '=' '{print $2}' | tail -n 1 | awk -F'"' '{print $2}')
}
}
first_type() {
[ "${1#/}" != "$1" ] && [ -x "$1" ] && echo "$1" && return
for p in "/bin/$1" "/usr/bin/$1" "${TMP_BIN_PATH:-/tmp}/$1"; do
@@ -283,53 +340,42 @@ get_new_port() {
local default_start_port=2001
local min_port=1025
local max_port=49151
local port="$1"
local port="$1" # Required parameter; please pass "auto" if you want it to be automatic.
local protocol=$(echo "$2" | tr 'A-Z' 'a-z')
local LOCK_FILE="${LOCK_PATH}/${CONFIG}_get_prot.lock"
while ! mkdir "$LOCK_FILE" 2>/dev/null; do
sleep 0.05
done
local is_auto
if [ "$port" = "auto" ]; then
local now last_time diff last_port
now=$(date +%s 2>/dev/null)
last_time=$(get_cache_var "last_get_new_port_time")
if [ -n "$now" ] && [ -n "$last_time" ]; then
diff=$(expr "$now" - "$last_time")
[ "$diff" -lt 0 ] && diff=$(expr 0 - "$diff")
is_auto=1
local last_get_new_port_auto=$(get_cache_var "last_get_new_port_auto")
if [ -n "$last_get_new_port_auto" ]; then
port=$(expr "$last_get_new_port_auto" + 1)
else
diff=999
fi
if [ "$diff" -gt 10 ]; then
port=$default_start_port
else
last_port=$(get_cache_var "last_get_new_port_auto")
if [ -n "$last_port" ]; then
port=$(expr "$last_port" + 1)
else
port=$default_start_port
fi
fi
fi
[ "$port" -lt $min_port ] || [ "$port" -gt $max_port ] && port=$default_start_port
local start_port="$port"
([ "$port" -lt "$min_port" ] || [ "$port" -gt "$max_port" ]) && port=$default_start_port
while :; do
if [ "$(check_port_exists "$port" "$protocol")" = 0 ]; then
break
local result=$(check_port_exists "$port" "$protocol")
if [ "$is_auto" = "1" ] && [ -n "$(get_cache_var "get_port_${port}")" ]; then
# The port has already been allocated, continue to the next port.
result=1
fi
port=$(expr "$port" + 1)
if [ "$port" -gt $max_port ]; then
port=$min_port
[ "$result" = "0" ] && break
if [ "$port" -lt "$max_port" ]; then
# If the port is smaller than the maximum port, increment by 1 and continue.
port=$(expr "$port" + 1)
elif [ "$port" -gt "$min_port" ]; then
# If the port is greater than the minimum port, decrement by 1 and continue.
port=$(expr "$port" - 1)
else
# Otherwise, reassign the default starting port.
port=$default_start_port
fi
[ "$port" = "$start_port" ] && {
rmdir "$LOCK_FILE" 2>/dev/null
return 1
}
done
if [ "$1" = "auto" ]; then
if [ "$is_auto" = "1" ]; then
# Set cache to prevent the port from being allocated again.
set_cache_var "get_port_${port}" "1"
set_cache_var "last_get_new_port_auto" "$port"
[ -n "$now" ] && set_cache_var "last_get_new_port_time" "$now"
fi
rmdir "$LOCK_FILE" 2>/dev/null
echo "$port"
}
@@ -359,54 +405,6 @@ check_ver() {
echo 255
}
eval_set_val() {
for i in $@; do
for j in $i; do
eval $j
done
done
}
eval_unset_val() {
for i in $@; do
for j in $i; do
eval unset $j
done
done
}
lua_api() {
local func=${1}
[ -z "${func}" ] && {
echo "nil"
return
}
echo $(lua -e "local api = require 'luci.passwall.api' print(api.${func})")
}
set_cache_var() {
local key="${1}"
shift 1
local val="$@"
[ -n "${key}" ] && [ -n "${val}" ] && {
[ ! -d $TMP_PATH ] && mkdir -p $TMP_PATH
sed -i "/${key}=/d" $TMP_PATH/var >/dev/null 2>&1
echo "${key}=\"${val}\"" >> $TMP_PATH/var
eval ${key}=\"${val}\"
}
}
get_cache_var() {
local key="${1}"
[ -n "${key}" ] && [ -s "$TMP_PATH/var" ] && {
echo $(cat $TMP_PATH/var | grep "^${key}=" | awk -F '=' '{print $2}' | tail -n 1 | awk -F'"' '{print $2}')
}
}
eval_cache_var() {
[ -s "$TMP_PATH/var" ] && eval $(cat "$TMP_PATH/var")
}
has_1_65535() {
local val="$1"
val=${val//:/-}
@@ -470,25 +468,9 @@ ln_run() {
echolog " - 找不到 ${ln_name},无法启动..."
return 1
}
[ "${output}" != "/dev/null" ] && [ -n "$(echo "${output}" | grep -E "default|socks_")" ] && [ "${ln_name}" != "chinadns-ng" ] && {
local persist_log_path=$(config_n_get @global[0] persist_log_path)
local sys_log=$(config_n_get @global[0] sys_log "0")
}
if [ -z "$persist_log_path" ] && [ "$sys_log" != "1" ]; then
${file_func:-echolog " - ${ln_name}"} "$@" >${output} 2>&1 &
else
if [ -n "${persist_log_path}" ]; then
mkdir -p ${persist_log_path}
local log_file=${persist_log_path}/passwall_global_${ln_name}_$(date '+%F').log
echolog "记录到持久性日志文件:${log_file}"
${file_func:-echolog " - ${ln_name}"} "$@" >> ${log_file} 2>&1 &
sys_log=0
fi
if [ "${sys_log}" = "1" ]; then
echolog "记录 ${ln_name}_global 到系统日志"
${file_func:-echolog " - ${ln_name}"} "$@" 2>&1 | logger -t PASSWALL_global_${ln_name} &
fi
fi
${file_func:-echolog " - ${ln_name}"} "$@" >${output} 2>&1 &
[ "$NO_REC_PROCESS" = "1" ] && return
process_count=$(ls $TMP_SCRIPT_FUNC_PATH | wc -l)
process_count=$((process_count + 1))
@@ -238,7 +238,7 @@ end
function get_now_use_node()
local e = {}
local node = api.get_cache_var("ACL_GLOBAL_node")
local node = api.get_cache_var(("ACL_${flag}_node"):gsub("${flag}", "acl_default"))
if node then
e["global"] = node
end
@@ -280,7 +280,7 @@ end
function index_status()
local e = {}
e["global_status"] = luci.sys.call("/bin/busybox top -bn1 | grep -v 'grep' | grep '%s/bin/' | grep '/acl/default' >/dev/null" % api.TMP_PATH) == 0
e["global_status"] = luci.sys.call("/bin/busybox top -bn1 | grep -v 'grep' | grep '%s/bin/' | grep '/acl_default\\.json' >/dev/null" % api.TMP_PATH) == 0
http_write_json(e)
end
@@ -14,7 +14,10 @@ local k, v
for k, v in pairs(com) do
o = s:option(Value, k:gsub("%-","_") .. "_file", translatef("%s App Path", v.name))
o.default = v.default_path or ("/usr/bin/" .. k)
o.rmempty = false
o.placeholder = o.default
function o:remove(section)
self:write(section, self.default)
end
end
o = s:option(DummyValue, "tips", " ")
@@ -311,8 +311,8 @@ loglevel:value("error")
o = s:taboption("log", DummyValue, "_log", translate("Log File"))
o.rawhtml = true
o.cfgvalue = function(t, n)
local log_path = api.TMP_PATH .. "/acl/default.log"
local log_url = api.url("get_redir_log") .. "?id=default"
local log_path = api.TMP_PATH .. "/acl/acl_default.log"
local log_url = api.url("get_redir_log") .. "?id=acl_default"
return string.format(
'<code>%s</code>&nbsp;&nbsp;<input class="btn cbi-button cbi-button-apply" type="button" value="%s" onclick="window.open(\'%s\', \'_blank\')" />',
log_path,
+23 -8
View File
@@ -192,12 +192,16 @@ function sh_uci_commit(config)
exec_call(string.format("uci -q commit %s", config))
end
function del_cache_var(key)
sys.call(string.format('. /usr/share/passwall2/utils.sh ; del_cache_var "%s"', key))
end
function set_cache_var(key, val)
sys.call(string.format('. /usr/share/passwall2/utils.sh ; set_cache_var %s "%s"', key, val))
sys.call(string.format('. /usr/share/passwall2/utils.sh ; set_cache_var "%s" "%s"', key, val))
end
function get_cache_var(key)
local val = sys.exec(string.format('. /usr/share/passwall2/utils.sh ; echo -n $(get_cache_var %s)', key))
local val = sys.exec(string.format('. /usr/share/passwall2/utils.sh ; echo -n $(get_cache_var "%s")', key))
if val == "" then val = nil end
return val
end
@@ -288,12 +292,15 @@ end
function curl_proxy(url, file, args)
-- Use the proxy
local socks_server = get_cache_var("GLOBAL_SOCKS_server")
if socks_server and socks_server ~= "" then
if not args then args = {} end
local tmp_args = clone(args)
tmp_args[#tmp_args + 1] = "-x socks5h://" .. socks_server
return curl_base(url, file, tmp_args)
local socks_port = get_cache_var(("ACL_${flag}_node_socks_port"):gsub("${flag}", "acl_default"))
if socks_port then
local socks_server = "127.0.0.1:%s" % socks_port
if socks_server and socks_server ~= "" then
if not args then args = {} end
local tmp_args = clone(args)
tmp_args[#tmp_args + 1] = "-x socks5h://" .. socks_server
return curl_base(url, file, tmp_args)
end
end
return nil, nil
end
@@ -2054,3 +2061,11 @@ function parseDNS(dns)
end
return dns, 53
end
function get_socks_port_by_cache(node_id)
return get_cache_var("node_%s_socks_port" % { node_id })
end
function set_socks_port_to_cache(node_id, v)
set_cache_var("node_%s_socks_port" % { node_id }, v)
end
@@ -111,43 +111,59 @@ function gen_outbound(flag, node, tag, proxy_table)
end
local remarks = node.remarks
local proxy_tag = nil
local fragment = nil
local record_fragment = nil
local run_socks_instance = true
local proxy_tag, fragment, record_fragment
if proxy_table ~= nil and type(proxy_table) == "table" then
proxy_tag = proxy_table.tag or nil
fragment = (proxy_table.fragment and node.protocol ~= "naive" and not node.hysteria2_realms) and true or nil
record_fragment = (proxy_table.record_fragment and node.protocol ~= "naive" and not node.hysteria2_realms) and true or nil
run_socks_instance = proxy_table.run_socks_instance
end
if node.type ~= "sing-box" then
local relay_port = node.port
local new_port = api.get_new_port()
local config_file = string.format("%s_%s_%s.json", flag, tag, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("%s_%s_%s_%s.json", flag, tag, node_id, new_port)
end
if run_socks_instance then
sys.call(string.format('/usr/share/passwall2/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
(proxy_tag and relay_port) and tostring(relay_port) or "" --relay port
local new_port
local run_socks_instance = true
if NO_RUN then
TMP_PORT = TMP_PORT and TMP_PORT + 1 or 3001
new_port = TMP_PORT
run_socks_instance = nil
else
local relay_port = (proxy_tag and node.port) and tostring(node.port) or ""
if relay_port == "" then
local cache = api.get_socks_port_by_cache(node_id)
if cache then
new_port = cache
run_socks_instance = nil
end
end
if run_socks_instance then
new_port = api.get_new_port()
local config_file = string.format("nodesocks_%s_%s.json", node_id, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("nodesocks_%s_%s_%s.json", tag, node_id, new_port)
end
sys.call(string.format('/usr/share/passwall2/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
relay_port --relay port
)
)
)
)
if relay_port == "" then
api.set_socks_port_to_cache(node_id, new_port)
end
end
end
if new_port then
node = {
protocol = "socks",
address = "127.0.0.1",
port = new_port
}
proxy_tag = "socks <- " .. node_id
end
node = {
protocol = "socks",
address = "127.0.0.1",
port = new_port
}
proxy_tag = "socks <- " .. node_id
else
if proxy_tag then
node.detour = proxy_tag
@@ -934,7 +950,7 @@ function gen_config_server(node)
stream_receive_window = node.hysteria_recv_window_conn and tonumber(node.hysteria_recv_window_conn) or nil,
connection_receive_window = node.hysteria_recv_window_client and tonumber(node.hysteria_recv_window_client) or nil,
max_concurrent_streams = node.hysteria_max_conn_client and tonumber(node.hysteria_max_conn_client) or nil,
disable_path_mtu_discover = (node.hysteria_disable_mtu_discovery == "1") and true or false,
disable_path_mtu_discovery = (node.hysteria_disable_mtu_discovery == "1") and true or false,
tls = tls
}
end
@@ -1166,8 +1182,7 @@ function gen_config(var)
local remote_dns_client_ip = var["remote_dns_client_ip"]
local remote_rewrite_ttl = var["remote_rewrite_ttl"] or "30"
local dns_cache = var["dns_cache"]
local tags = var["tags"]
local no_run = var["no_run"]
NO_RUN = var["no_run"]
local dns_domain_rules = {}
local dns = {}
@@ -1390,7 +1405,7 @@ function gen_config(var)
end
end
if is_new_ut_node then
local outboundTag = gen_outbound_get_tag(flag, ut_node_id, ut_node_tag, { fragment = singbox_settings.fragment == "1" or nil, record_fragment = singbox_settings.record_fragment == "1" or nil, run_socks_instance = not no_run })
local outboundTag = gen_outbound_get_tag(flag, ut_node_id, ut_node_tag, { fragment = singbox_settings.fragment == "1" or nil, record_fragment = singbox_settings.record_fragment == "1" or nil })
if outboundTag then
valid_nodes[#valid_nodes + 1] = outboundTag
end
@@ -1493,7 +1508,6 @@ function gen_config(var)
to_node.port = new_port
to_outbound = gen_outbound(node[".name"], to_node, tag, {
tag = tag,
run_socks_instance = not no_run
})
else
to_outbound = gen_outbound(node[".name"], to_node)
@@ -1592,7 +1606,6 @@ function gen_config(var)
local proxy_table = {
fragment = singbox_settings.fragment == "1",
record_fragment = singbox_settings.record_fragment == "1",
run_socks_instance = not no_run,
}
local preproxy_node_id = node[rule_name .. "_proxy_tag"]
if preproxy_node_id == _node_id then preproxy_node_id = nil end
@@ -2269,7 +2282,7 @@ function gen_config(var)
routing_mark = 255,
})
for index, value in ipairs(config.outbounds) do
if not value["_flag_proxy_tag"] and not value.detour and value["_id"] and value.server and value.server_port and not no_run then
if not value["_flag_proxy_tag"] and not value.detour and value["_id"] and value.server and value.server_port and not NO_RUN then
sys.call(string.format("echo '%s' >> %s", value["_id"], api.TMP_PATH .. "/direct_node_list"))
end
if not value.detour and not value.bind_interface and value.server then
@@ -2412,7 +2425,7 @@ if arg[1] then
var = jsonc.parse(arg[2])
end
print(func(var))
if (next(GEO_VAR.SITE_TAGS) or next(GEO_VAR.IP_TAGS)) and not no_run then
if (next(GEO_VAR.SITE_TAGS) or next(GEO_VAR.IP_TAGS)) and not NO_RUN then
convert_geofile()
end
end
@@ -12,7 +12,7 @@ local GLOBAL = {
local xray_version = api.get_app_version("xray")
local xray_min_version = "26.3.27"
local xray_min_version = "26.7.11"
local function get_domain_excluded()
local path = "/usr/share/passwall2/domains_excluded"
@@ -58,45 +58,60 @@ function gen_outbound(flag, node, tag, proxy_table)
end
local remarks = node.remarks
local proxy_tag = nil
local dialer_proxy_tag = nil
local fragment = nil
local noise = nil
local run_socks_instance = true
local proxy_tag, dialer_proxy_tag, fragment, noise
if proxy_table ~= nil and type(proxy_table) == "table" then
proxy_tag = proxy_table.tag or nil
fragment = (proxy_table.fragment and not node.hysteria2_realms) and true or nil
noise = (proxy_table.noise and not node.hysteria2_realms) and true or nil
run_socks_instance = proxy_table.run_socks_instance
end
if node.type ~= "Xray" then
local relay_port = node.port
local new_port = api.get_new_port()
local config_file = string.format("%s_%s_%s.json", flag, tag, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("%s_%s_%s_%s.json", flag, tag, node_id, new_port)
end
if run_socks_instance then
sys.call(string.format('/usr/share/passwall2/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
(proxy_tag and relay_port) and tostring(relay_port) or "" --relay port
local new_port
local run_socks_instance = true
if NO_RUN then
TMP_PORT = TMP_PORT and TMP_PORT + 1 or 3001
new_port = TMP_PORT
run_socks_instance = nil
else
local relay_port = (proxy_tag and node.port) and tostring(node.port) or ""
if relay_port == "" then
local cache = api.get_socks_port_by_cache(node_id)
if cache then
new_port = cache
run_socks_instance = nil
end
end
if run_socks_instance then
new_port = api.get_new_port()
local config_file = string.format("nodesocks_%s_%s.json", node_id, new_port)
if tag and node_id and not tag:find(node_id) then
config_file = string.format("nodesocks_%s_%s_%s.json", tag, node_id, new_port)
end
sys.call(string.format('/usr/share/passwall2/app.sh run_socks "%s"> /dev/null',
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s relay_port=%s",
new_port, --flag
node_id, --node
"127.0.0.1", --bind
new_port, --socks port
config_file, --config file
relay_port --relay port
)
)
)
)
if relay_port == "" then
api.set_socks_port_to_cache(node_id, new_port)
end
end
end
if new_port then
node = {}
node.protocol = "socks"
node.transport = "raw"
node.address = "127.0.0.1"
node.port = new_port
node.stream_security = "none"
proxy_tag = "socks <- " .. node_id
end
node = {}
node.protocol = "socks"
node.transport = "tcp"
node.address = "127.0.0.1"
node.port = new_port
node.stream_security = "none"
proxy_tag = "socks <- " .. node_id
else
dialer_proxy_tag = proxy_tag
end
@@ -166,7 +181,7 @@ function gen_outbound(flag, node, tag, proxy_table)
} or nil,
dialerProxy = dialer_proxy_tag,
},
[(api.compare_versions(xray_version, "<", "26.7.11")) and "network" or "method"] = node.transport, -- Todo: Remove version check and "network"
method = node.transport,
security = node.stream_security,
tlsSettings = (node.stream_security == "tls") and {
serverName = node.tls_serverName,
@@ -650,7 +665,7 @@ function gen_config_server(node)
outbound_node_t = {
type = node.type,
protocol = node.outbound_node:gsub("_", ""),
transport = "tcp",
transport = "raw",
address = node.outbound_node_address,
port = node.outbound_node_port,
username = (node.outbound_node_username and node.outbound_node_username ~= "") and node.outbound_node_username or nil,
@@ -681,7 +696,7 @@ function gen_config_server(node)
protocol = node.protocol,
settings = settings,
streamSettings = {
[(api.compare_versions(xray_version, "<", "26.7.11")) and "network" or "method"] = node.transport, -- Todo: Remove version check and "network"
method = node.transport,
security = "none",
tlsSettings = ("1" == node.tls) and {
disableSystemRoot = false,
@@ -862,9 +877,6 @@ function gen_config_server(node)
config.outbounds[index][k] = nil
end
end
if value.protocol == "freedom" and api.compare_versions(xray_version, "<", "26.5.3") then -- Todo is to remove it
value.settings = nil
end
end
return config
@@ -906,7 +918,7 @@ function gen_config(var)
local remote_dns_query_strategy = var["remote_dns_query_strategy"]
local remote_dns_detour = var["remote_dns_detour"]
local dns_cache = var["dns_cache"]
local no_run = var["no_run"]
NO_RUN = var["no_run"]
local dns_domain_rules = {}
local dns = {}
@@ -1031,7 +1043,7 @@ function gen_config(var)
protocol = "socks",
address = "127.0.0.1",
port = section.port,
transport = "tcp",
transport = "raw",
stream_security = "none"
}
end
@@ -1089,7 +1101,7 @@ function gen_config(var)
end
end
if is_new_blc_node then
local outboundTag = gen_outbound_get_tag(flag, blc_node_id, blc_node_tag, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil, run_socks_instance = not no_run })
local outboundTag = gen_outbound_get_tag(flag, blc_node_id, blc_node_tag, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil })
if outboundTag then
valid_nodes[#valid_nodes + 1] = outboundTag
end
@@ -1118,7 +1130,7 @@ function gen_config(var)
local fallback_node = get_node_by_id(fallback_node_id)
if fallback_node then
if fallback_node.protocol ~= "_balancing" then
local outboundTag = gen_outbound_get_tag(flag, fallback_node, fallback_node_id, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil, run_socks_instance = not no_run })
local outboundTag = gen_outbound_get_tag(flag, fallback_node, fallback_node_id, { fragment = xray_settings.fragment == "1" or nil, noise = xray_settings.noise == "1" or nil })
if outboundTag then
fallback_node_tag = outboundTag
end
@@ -1250,7 +1262,6 @@ function gen_config(var)
})
to_outbound = gen_outbound(node[".name"], to_node, to_node[".name"], {
tag = to_node[".name"],
run_socks_instance = not no_run
})
else
to_outbound = gen_outbound(node[".name"], to_node)
@@ -1321,9 +1332,9 @@ function gen_config(var)
interface = node.iface
}
},
settings = (api.compare_versions(xray_version, ">", "26.4.25")) and { -- Todo: Remove version check
settings = {
finalRules = {{ action = "allow" }}
} or nil
}
}
sys.call(string.format("mkdir -p %s && touch %s/%s", api.TMP_IFACE_PATH, api.TMP_IFACE_PATH, node.iface))
end
@@ -1383,7 +1394,6 @@ function gen_config(var)
local proxy_table = {
fragment = xray_settings.fragment == "1",
noise = xray_settings.noise == "1",
run_socks_instance = not no_run,
}
local preproxy_node_id = node[rule_name .. "_proxy_tag"]
if preproxy_node_id == _node_id then preproxy_node_id = nil end
@@ -1735,12 +1745,10 @@ function gen_config(var)
})
local direct_type_dns = {
settings = {
address = direct_dns_udp_server,
port = tonumber(direct_dns_udp_port) or 53,
network = "udp",
nonIPQuery = (api.compare_versions(xray_version, "<", "26.4.25")) and "skip" or nil, -- Todo is to remove it
blockTypes = (api.compare_versions(xray_version, "<", "26.4.25")) and { 65 } or nil, -- Todo is to remove it
rules = (api.compare_versions(xray_version, ">", "26.4.17")) and {
rewriteAddress = direct_dns_udp_server,
rewritePort = tonumber(direct_dns_udp_port) or 53,
rewriteNetwork = "udp",
rules = {
{
qType = "1,28",
action = "hijack"
@@ -1761,11 +1769,10 @@ function gen_config(var)
}
local remote_type_dns = {
settings = {
address = remote_dns_udp_server,
port = tonumber(remote_dns_udp_port) or 53,
network = _remote_dns_proto or "tcp",
nonIPQuery = (api.compare_versions(xray_version, "<", "26.4.25")) and "reject" or nil, -- Todo is to remove it
rules = (api.compare_versions(xray_version, ">", "26.4.17")) and {
rewriteAddress = remote_dns_udp_server,
rewritePort = tonumber(remote_dns_udp_port) or 53,
rewriteNetwork = _remote_dns_proto or "tcp",
rules = {
{
qType = "1,28",
action = "hijack"
@@ -2043,7 +2050,7 @@ function gen_config(var)
local direct_outbound = {
protocol = "freedom",
tag = "direct",
settings = (api.compare_versions(xray_version, ">", "26.4.25")) and { -- Todo: Remove version check
settings = {
finalRules = {{ action = "allow" }}
} or nil,
streamSettings = {
@@ -2071,7 +2078,7 @@ function gen_config(var)
for index, value in ipairs(config.outbounds) do
local s = value.settings
if not value["_flag_proxy_tag"] and value["_id"] and s and not no_run and
if not value["_flag_proxy_tag"] and value["_id"] and s and not NO_RUN and
((s.vnext and s.vnext[1] and s.vnext[1].address and s.vnext[1].port) or
(s.servers and s.servers[1] and s.servers[1].address and s.servers[1].port) or
(s.peers and s.peers[1] and s.peers[1].endpoint) or
@@ -2153,7 +2160,7 @@ function gen_proto_config(var)
local outbound = {
protocol = server_proto,
streamSettings = {
network = "tcp",
method = "raw",
security = "none"
},
settings = {
@@ -2177,10 +2184,12 @@ function gen_proto_config(var)
table.insert(outbounds, {
protocol = "freedom",
tag = "direct",
settings = (api.compare_versions(xray_version, ">", "26.4.25")) and { -- Todo: Remove version check
settings = {
finalRules = {{ action = "allow" }}
} or nil,
sockopt = {mark = 255}
streamSettings = {
sockopt = {mark = 255}
}
})
local config = {
@@ -2189,7 +2198,10 @@ function gen_proto_config(var)
},
inbounds = inbounds,
outbounds = outbounds,
routing = routing
routing = routing,
version = {
min = xray_min_version
}
}
return jsonc.stringify(config, 1)
end
@@ -127,7 +127,7 @@ local sid = "@global[0]"
const m = cbid.match(/\.node$/);
if (m) {
html += '<a href="#" onclick="window.open(\'' + '<%=api.url("get_redir_log")%>?id=default' + '\', \'_blank\')"><%:Log%></a>';
html += '<a href="#" onclick="window.open(\'' + '<%=api.url("get_redir_log")%>?id=acl_default' + '\', \'_blank\')"><%:Log%></a>';
}
html = '<div class="node-actions" style="display:inline-flex; align-items:center; gap:4px; flex-wrap:wrap; margin-left:4px;">' + html + '</div>'
+28 -25
View File
@@ -2174,23 +2174,8 @@ msgstr "حذف قوانین %s کامل شد."
msgid "%s firewall rules load complete!"
msgstr "بارگذاری قوانین فایروال %s کامل شد!"
msgid "Socks switch detection: Unknown error."
msgstr "تشخیص سوئیچ Socks: خطای ناشناخته."
msgid "Socks switch detection: Unable to connect to the network. Please check if the network is working properly!"
msgstr "تشخیص سوئیچ Socks: عدم توانایی در اتصال به شبکه. لطفاً بررسی کنید که شبکه به درستی کار می‌کند!"
msgid "Socks switch detection: Primary node 【%s: [%s]】 is normal. Switch to the primary node!"
msgstr "تشخیص سوئیچ Socks: گره اولیه 【%s: [%s]】 عادی است. سوئیچ به گره اولیه!"
msgid "Socks switch detection: %s node switch complete!"
msgstr "تشخیص سوئیچ Socks: سوئیچ گره %s کامل شد!"
msgid "Socks switch detection: %s 【%s:[%s]】 normal."
msgstr "تشخیص سوئیچ Socks: %s 【%s:[%s]】 عادی است."
msgid "switch to %s test detect!"
msgstr "سوئیچ به تست تشخیص %s!"
msgid "main node"
msgstr "گره اصلی"
msgid "backup node"
msgstr "گره پشتیبان"
@@ -2198,17 +2183,35 @@ msgstr "گره پشتیبان"
msgid "next backup node"
msgstr "گره پشتیبان بعدی"
msgid "main node"
msgstr "گره اصلی"
msgid "Socks switch detection: Port [%s] try %s [%s:%s]."
msgstr "تشخیص تغییر وضعیت سوئیچ: پورت [%s]، تلاش %s [%s:%s]."
msgid "Socks switch detection: Unknown error."
msgstr "تشخیص سوئیچ Socks: خطای ناشناخته."
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal, switch to this node!"
msgstr "تشخیص تغییر وضعیت سوکت‌ها: پورت [%s] [%s:[%s]] در وضعیت عادی است، تغییر وضعیت به این گره!"
msgid "Socks switch detection: %s 【%s:[%s]】 abnormal, %s"
msgstr "تشخیص سوئیچ Socks: %s 【%s:[%s]】 غیرعادی، %s"
msgid "Socks switch detection: Port [%s] node switch complete!"
msgstr "تشخیص تغییر وضعیت سوکت‌ها: تغییر وضعیت گره در پورت [%s] تکمیل شد!"
msgid "Socks switch detection: %s 【%s:[%s]normal, switch to this node!"
msgstr "تشخیص سوئیچ Socks: %s 【%s:[%s]】 عادی، سوئیچ به این گره!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] abnormal."
msgstr "تشخیص وضعیت سوئیچ: پورت [%s] [%s:[%s]] غیرعادی است."
msgid "Socks switch detection: Port [%s] all nodes are unavailable!"
msgstr "تشخیص تغییر وضعیت سوئیچ: در پورت [%s]، تمام گره‌ها در دسترس نیستند!"
msgid "Socks switch detection: Port [%s] Unknown error."
msgstr "تشخیص وضعیت سوئیچ جوراب: پورت [%s] خطای ناشناخته."
msgid "Socks switch detection: Port [%s] Unable to connect to the network. Please check if the network is working properly!"
msgstr "تشخیص تغییر وضعیت سوکت: پورت [%s]؛ امکان اتصال به شبکه وجود ندارد. لطفاً بررسی کنید که آیا شبکه به‌درستی کار می‌کند یا خیر."
msgid "Socks switch detection: Port [%s] Primary node [%s: [%s]] is normal. Switch to the primary node!"
msgstr "تشخیص تغییر وضعیت سوکت: وضعیت پورت [%s] و گره اصلی [%s: [%s]] عادی است. تغییر وضعیت به گره اصلی!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal."
msgstr "تشخیص وضعیت سوئیچ: پورت [%s] [%s:[%s]] در وضعیت عادی است."
msgid "Socks switch detection: Port [%s] Number of backup nodes: %s"
msgstr "تشخیص سوئیچ سوئیچ شبکه: پورت [%s] تعداد گره‌های پشتیبان: %s"
msgid "Restart dnsmasq service."
msgstr "راه‌اندازی مجدد سرویس dnsmasq."
+29 -23
View File
@@ -2175,23 +2175,8 @@ msgstr "Удаление правил %s завершено."
msgid "%s firewall rules load complete!"
msgstr "Загрузка правил фаервола %s завершена!"
msgid "Socks switch detection: Unknown error."
msgstr "Проверка переключения SOCKS: неизвестная ошибка."
msgid "Socks switch detection: Unable to connect to the network. Please check if the network is working properly!"
msgstr "Проверка переключения SOCKS: не удалось подключиться к сети. Пожалуйста, проверьте работоспособность сети!"
msgid "Socks switch detection: Primary node 【%s: [%s]】 is normal. Switch to the primary node!"
msgstr "Проверка переключения SOCKS: основной сервер 【%s: [%s]】 работает нормально. Переключение на основной сервер!"
msgid "Socks switch detection: %s node switch complete!"
msgstr "Проверка переключения SOCKS: переключение сервера %s завершено!"
msgid "Socks switch detection: %s 【%s:[%s]】 normal."
msgstr "Проверка переключения SOCKS: %s 【%s:[%s]】 работает нормально."
msgid "switch to %s test detect!"
msgstr "Переключение на %s для проверки!"
msgid "main node"
msgstr "основной сервер"
msgid "backup node"
msgstr "резервный сервер"
@@ -2199,14 +2184,35 @@ msgstr "резервный сервер"
msgid "next backup node"
msgstr "следующий резервный сервер"
msgid "main node"
msgstr "основной сервер"
msgid "Socks switch detection: Port [%s] try %s [%s:%s]."
msgstr "Обнаружение переключения кабеля: порт [%s], попытка %s [%s:%s]."
msgid "Socks switch detection: %s 【%s:[%s]】 abnormal, %s"
msgstr "Проверка переключения SOCKS: %s 【%s:[%s]】 не работает, %s"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal, switch to this node!"
msgstr "Обнаружение переключения Socks: порт [%s] [%s:[%s]] в норме, переключение на этот узел!"
msgid "Socks switch detection: %s 【%s:[%s] normal, switch to this node!"
msgstr "Проверка переключения SOCKS: %s 【%s:[%s]】 работает нормально, переключение на этот сервер!"
msgid "Socks switch detection: Port [%s] node switch complete!"
msgstr "Обнаружение переключения соединений: переключение узла на порту [%s] завершено!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] abnormal."
msgstr "Обнаружено переключение Socks: порт [%s] [%s:[%s]] работает некорректно."
msgid "Socks switch detection: Port [%s] all nodes are unavailable!"
msgstr "Обнаружено переключение коммутатора: порт [%s], все узлы недоступны!"
msgid "Socks switch detection: Port [%s] Unknown error."
msgstr "Обнаружение переключения разъема: порт [%s], неизвестная ошибка."
msgid "Socks switch detection: Port [%s] Unable to connect to the network. Please check if the network is working properly!"
msgstr "Обнаружено переключение Socks: порт [%s] — не удалось подключиться к сети. Пожалуйста, проверьте исправность сети!"
msgid "Socks switch detection: Port [%s] Primary node [%s: [%s]] is normal. Switch to the primary node!"
msgstr "Обнаружено переключение: порт [%s], основной узел [%s: [%s]] — состояние нормальное. Переключение на основной узел!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal."
msgstr "Обнаружение переключения Socks: порт [%s] [%s:[%s]] — норма."
msgid "Socks switch detection: Port [%s] Number of backup nodes: %s"
msgstr "Обнаружение переключения коммутатора: порт [%s], количество резервных узлов: %s"
msgid "Restart dnsmasq service."
msgstr "Перезапуск службы dnsmasq."
+28 -25
View File
@@ -2160,23 +2160,8 @@ msgstr "删除 %s 规则完成。"
msgid "%s firewall rules load complete!"
msgstr "%s 防火墙规则加载完成!"
msgid "Socks switch detection: Unknown error."
msgstr "Socks切换检测:未知错误。"
msgid "Socks switch detection: Unable to connect to the network. Please check if the network is working properly!"
msgstr "Socks切换检测:无法连接到网络,请检查网络是否正常!"
msgid "Socks switch detection: Primary node 【%s: [%s]】 is normal. Switch to the primary node!"
msgstr "Socks切换检测:%s 主节点【%s:[%s]】正常,切换到主节点!"
msgid "Socks switch detection: %s node switch complete!"
msgstr "Socks切换检测:%s 节点切换完毕!"
msgid "Socks switch detection: %s 【%s:[%s]】 normal."
msgstr "Socks切换检测:%s 【%s:[%s]】 正常。"
msgid "switch to %s test detect!"
msgstr "切换到 %s 检测!"
msgid "main node"
msgstr "主节点"
msgid "backup node"
msgstr "备用节点"
@@ -2184,17 +2169,35 @@ msgstr "备用节点"
msgid "next backup node"
msgstr "下一个备用节点"
msgid "main node"
msgstr "主节点"
msgid "Socks switch detection: Port [%s] try %s [%s:%s]."
msgstr "Socks切换检测:端口 [%s] 尝试 %s 【%s:%s】。"
msgid "Socks switch detection: Unknown error."
msgstr "Socks切换检测:未知错误。"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal, switch to this node!"
msgstr "Socks切换检测:端口 [%s] 【%s:[%s]】 正常,切换到此节点!"
msgid "Socks switch detection: %s 【%s:[%s]】 abnormal, %s"
msgstr "Socks切换检测:%s 【%s:[%s]】 异常,%s"
msgid "Socks switch detection: Port [%s] node switch complete!"
msgstr "Socks切换检测:端口 [%s] 节点切换完毕!"
msgid "Socks switch detection: %s 【%s:[%s]normal, switch to this node!"
msgstr "Socks切换检测:%s 【%s:[%s]】 正常,切换到此节点!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] abnormal."
msgstr "Socks切换检测:端口 [%s] 异常。"
msgid "Socks switch detection: Port [%s] all nodes are unavailable!"
msgstr "Socks切换检测:端口 [%s] 所有节点均不可用!"
msgid "Socks switch detection: Port [%s] Unknown error."
msgstr "Socks切换检测:端口 [%s] 未知错误。"
msgid "Socks switch detection: Port [%s] Unable to connect to the network. Please check if the network is working properly!"
msgstr "Socks切换检测:端口 [%s] 无法连接到网络,请检查网络是否正常!"
msgid "Socks switch detection: Port [%s] Primary node [%s: [%s]] is normal. Switch to the primary node!"
msgstr "Socks切换检测:端口 [%s] 主节点【%s:[%s]】正常,切换到主节点!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal."
msgstr "Socks切换检测:端口 [%s] 【%s:[%s]】 正常。"
msgid "Socks switch detection: Port [%s] Number of backup nodes: %s"
msgstr "Socks切换检测:端口 [%s] 后备节点数量:%s"
msgid "Restart dnsmasq service."
msgstr "重启 dnsmasq 服务。"
+28 -25
View File
@@ -2166,23 +2166,8 @@ msgstr "刪除 %s 規則完成。"
msgid "%s firewall rules load complete!"
msgstr "%s 防火墙規則加载完成!"
msgid "Socks switch detection: Unknown error."
msgstr "Socks切換檢測:未知錯誤。"
msgid "Socks switch detection: Unable to connect to the network. Please check if the network is working properly!"
msgstr "Socks切換檢測:無法連接到網絡,請檢查網絡是否正常!"
msgid "Socks switch detection: Primary node 【%s: [%s]】 is normal. Switch to the primary node!"
msgstr "Socks切換檢測:%s 主節點【%s:[%s]】正常,切換到主節點!"
msgid "Socks switch detection: %s node switch complete!"
msgstr "Socks切換檢測:%s 節點切換完毕!"
msgid "Socks switch detection: %s 【%s:[%s]】 normal."
msgstr "Socks切換檢測:%s 【%s:[%s]】 正常。"
msgid "switch to %s test detect!"
msgstr "切換到 %s 檢測!"
msgid "main node"
msgstr "主節點"
msgid "backup node"
msgstr "備用節點"
@@ -2190,17 +2175,35 @@ msgstr "備用節點"
msgid "next backup node"
msgstr "下一個備用節點"
msgid "main node"
msgstr "主節點"
msgid "Socks switch detection: Port [%s] try %s [%s:%s]."
msgstr "Socks切換檢測:連接埠 [%s] 嘗試 %s 【%s:%s】。"
msgid "Socks switch detection: Unknown error."
msgstr "Socks切換測:未知錯誤。"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal, switch to this node!"
msgstr "Socks切換測:連接埠 [%s] 【%s:[%s]】 正常,切換到此節點!"
msgid "Socks switch detection: %s 【%s:[%s]】 abnormal, %s"
msgstr "Socks切換測:%s 【%s:[%s]】 异常,%s"
msgid "Socks switch detection: Port [%s] node switch complete!"
msgstr "Socks切換測:連接埠 [%s] 節點切換完畢!"
msgid "Socks switch detection: %s 【%s:[%s]normal, switch to this node!"
msgstr "Socks切換測:%s 【%s:[%s]】 正常,切換到此節點!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] abnormal."
msgstr "Socks切換測:連接埠 [%s] 異常。"
msgid "Socks switch detection: Port [%s] all nodes are unavailable!"
msgstr "Socks切換偵測:連接埠 [%s] 所有節點均不可用!"
msgid "Socks switch detection: Port [%s] Unknown error."
msgstr "Socks切換偵測:連接埠 [%s] 未知錯誤。"
msgid "Socks switch detection: Port [%s] Unable to connect to the network. Please check if the network is working properly!"
msgstr "Socks切換偵測:連接埠 [%s] 無法連接到網絡,請檢查網路是否正常!"
msgid "Socks switch detection: Port [%s] Primary node [%s: [%s]] is normal. Switch to the primary node!"
msgstr "Socks切換偵測:連接埠 [%s] 主節點【%s:[%s]】正常,切換到主節點!"
msgid "Socks switch detection: Port [%s] [%s:[%s]] normal."
msgstr "Socks切換檢測:連接埠 [%s] 【%s:[%s]】 正常。"
msgid "Socks switch detection: Port [%s] Number of backup nodes: %s"
msgstr "Socks切換偵測:連接埠 [%s] 後備節點數量:%s"
msgid "Restart dnsmasq service."
msgstr "重啟 dnsmasq 服務。"
@@ -1,17 +1,12 @@
#!/bin/sh
# Devices without a hardware RTC boot with a wrong system clock: sysfixtime can
# only restore the mtime of the newest file under /etc, so the clock is usually
# hours behind after a cold boot. passwall2 is then started by
# /etc/hotplug.d/iface/98-passwall2 on ifup, which typically happens before NTP
# has corrected the time, and time-sensitive handshakes (VMess AEAD, TLS) fail.
#
# Nothing restarts passwall2 once the clock is corrected, so it stays broken
# until the user restarts it manually. Restart once when ntpd reports that the
# time is valid -- the same approach dnsmasq uses for DNSSEC in
# /etc/hotplug.d/ntp/25-dnsmasqsec.
[ "$ACTION" = "step" ] || exit 0
[ "$ACTION" = "stratum" ] || exit 0
offset=${offset#-}
offset=${offset%.*}
# Skip service restart if the time adjustment is less than 120 seconds.
[ "$offset" -lt 120 ] && exit 0
. /usr/share/passwall2/utils.sh
@@ -23,5 +18,5 @@ NTP_LOCK_FILE="${LOCK_PATH}/${CONFIG}_ntp.lock"
echo $$ > ${NTP_LOCK_FILE}
/etc/init.d/${CONFIG} restart >/dev/null 2>&1 &
logger -p notice -t network -s "${CONFIG}: restart after NTP time became valid"
logger -p notice -t network -s "${CONFIG}: restart after NTP time step (${offset}s)"
}
@@ -855,25 +855,25 @@ acl_node() {
local DNSMASQ_DEFAULT_DNS="${AUTO_DNS}"
local DNSMASQ_LOCAL_DNS="${LOCAL_DNS:-${AUTO_DNS}}"
[ -n "${DIRECT_DNS_DNSMASQ_SERVER}" ] && DNSMASQ_LOCAL_DNS="${DIRECT_DNS_DNSMASQ_SERVER}"
if [ "${flag}" = "default" ]; then
set_cache_var "GLOBAL_SOCKS_server" "127.0.0.1:$socks_port"
set_cache_var "ACL_GLOBAL_node" "$node"
if [ "${flag}" = "acl_default" ]; then
set_cache_var "ACL_${flag}_node" "$node"
set_cache_var "ACL_${flag}_node_socks_port" "$socks_port"
run_new_dnsmasq=$(config_n_get @global[0] dns_redirect 1)
if [ "${run_new_dnsmasq}" != "1" ]; then
#Rewrite the default DNS service configuration
#Modify the default dnsmasq service
lua $APP_PATH/helper_dnsmasq.lua stretch
json_init
json_add_string "FLAG" "default"
json_add_string "TMP_DNSMASQ_PATH" "${GLOBAL_DNSMASQ_CONF_PATH}"
json_add_string "DNSMASQ_CONF_FILE" "${GLOBAL_DNSMASQ_CONF}"
json_add_string "FLAG" "${flag}"
json_add_string "TMP_DNSMASQ_PATH" "${DEFAULT_DNSMASQ_CONF_PATH}"
json_add_string "DNSMASQ_CONF_FILE" "${DEFAULT_DNSMASQ_CONF}"
json_add_string "DEFAULT_DNS" "${DNSMASQ_DEFAULT_DNS}"
json_add_string "LOCAL_DNS" "${DNSMASQ_LOCAL_DNS}"
json_add_string "TUN_DNS" "${DNSMASQ_TUN_DNS}"
json_add_string "NFTFLAG" "${nftflag:-0}"
json_add_string "NO_LOGIC_LOG" "${NO_LOGIC_LOG:-0}"
lua $APP_PATH/helper_dnsmasq.lua add_rule "$(json_dump)"
uci -q add_list dhcp.@dnsmasq[0].addnmount=${GLOBAL_DNSMASQ_CONF_PATH}
uci -q add_list dhcp.@dnsmasq[0].addnmount=${DEFAULT_DNSMASQ_CONF_PATH}
uci -q commit dhcp
lua $APP_PATH/helper_dnsmasq.lua logic_restart
@@ -912,7 +912,7 @@ start() {
check_run_environment
[ -n "$USE_TABLES" ] && {
ACL_JSON=$(lua $APP_PATH/app_acl.lua)
[ ! -f ${TMP_ACL_PATH}/acl_node_default ] && ENABLED_DEFAULT_ACL=0
[ ! -f ${TMP_ACL_PATH}/acl_node_acl_default ] && ENABLED_DEFAULT_ACL=0
local acl_node_num=$(jsonfilter -s "${ACL_JSON}" -e '$.node_order[*]' | wc -l)
if [ "${acl_node_num}" == 0 ]; then
@@ -973,8 +973,8 @@ stop() {
unset XRAY_LOCATION_ASSET
unset SS_SYSTEM_DNS_RESOLVER_FORCE_BUILTIN
stop_crontab
rm -rf $GLOBAL_DNSMASQ_CONF
rm -rf $GLOBAL_DNSMASQ_CONF_PATH
rm -rf $DEFAULT_DNSMASQ_CONF
rm -rf $DEFAULT_DNSMASQ_CONF_PATH
[ "1" = "1" ] && {
#restore logic
bak_dnsmasq_dns_redirect=$(config_n_get @global[0] dnsmasq_dns_redirect)
@@ -985,7 +985,7 @@ stop() {
uci -q commit ${CONFIG}
}
if [ -z "${ACL_default_dns_port}" ] || [ -n "${bak_dnsmasq_dns_redirect}" ]; then
uci -q del_list dhcp.@dnsmasq[0].addnmount="${GLOBAL_DNSMASQ_CONF_PATH}"
uci -q del_list dhcp.@dnsmasq[0].addnmount="${DEFAULT_DNSMASQ_CONF_PATH}"
uci -q commit dhcp
json_init
@@ -1061,8 +1061,8 @@ get_config() {
DNSMASQ_CONF_DIR=${DEFAULT_DNSMASQ_CONF_DIR}
fi
fi
set_cache_var GLOBAL_DNSMASQ_CONF ${DNSMASQ_CONF_DIR}/dnsmasq-${CONFIG}.conf
set_cache_var GLOBAL_DNSMASQ_CONF_PATH ${TMP_ACL_PATH}/default_dnsmasq.d
set_cache_var DEFAULT_DNSMASQ_CONF ${DNSMASQ_CONF_DIR}/dnsmasq-${CONFIG}.conf
set_cache_var DEFAULT_DNSMASQ_CONF_PATH ${TMP_ACL_PATH}/acl_default_dnsmasq.d
QUEUE_RUN=1
}
@@ -24,7 +24,7 @@ end
function init_acl()
if true then
-- Get Default AC
D.flag = "default"
D.flag = "acl_default"
D.remarks = api.i18n.translatef("Default")
D.tcp_no_redir_ports = uci_get("@global_forwarding[0]", "tcp_no_redir_ports")
D.udp_no_redir_ports = uci_get("@global_forwarding[0]", "udp_no_redir_ports")
@@ -109,20 +109,26 @@ api.uci_foreach_c("haproxy_config", function(t)
t.origin_port = server_port
if health_check_type == "script_logic" then
if server_node.type ~= "Socks" then
local relay_port = server_node.port
local new_port = api.get_new_port()
local config_file = string.format("%s_%s.json", t[".name"], new_port)
sys.call(string.format('/usr/share/%s/app.sh run_socks "%s"> /dev/null',
appname,
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s",
new_port, --flag
server_node[".name"], --node
"127.0.0.1", --bind
new_port, --socks port
config_file --config file
local new_port
local cache = api.get_socks_port_by_cache(server_node[".name"])
if cache then
new_port = cache
else
new_port = api.get_new_port()
local config_file = string.format("%s_%s.json", t[".name"], new_port)
sys.call(string.format('/usr/share/%s/app.sh run_socks "%s"> /dev/null',
appname,
string.format("flag=%s node=%s bind=%s socks_port=%s config_file=%s",
new_port, --flag
server_node[".name"], --node
"127.0.0.1", --bind
new_port, --socks port
config_file --config file
)
)
)
)
api.set_socks_port_to_cache(server_node[".name"], new_port)
end
server_address = "127.0.0.1"
server_port = new_port
end
@@ -329,7 +329,7 @@ function add_rule(var)
tinsert(conf_lines, "no-poll")
tinsert(conf_lines, "no-resolv")
if FLAG == "default" then
if FLAG == "acl_default" then
api.set_cache_var("DEFAULT_DNS", DEFAULT_DNS)
end
end
@@ -230,7 +230,7 @@ gen_shunt_list() {
}
[ -n "${_SHUNT_LIST4}" ] && eval ${shunt_list4_var_name}=\"${_SHUNT_LIST4}\"
[ -n "${_SHUNT_LIST6}" ] && eval ${shunt_list6_var_name}=\"${_SHUNT_LIST6}\"
set_cache_var "gen_shunt_list_${node}" "1"
set_cache_var "node_${node}_gen_shunt_list" "1"
}
add_shunt_t_rule() {
@@ -261,7 +261,7 @@ load_acl() {
for sid in $(jsonfilter -s "${ACL_JSON}" -e '$.acl[*].flag'); do
eval local $(cat "${TMP_ACL_PATH}/${sid}/var")
[ -z "$(get_cache_var "gen_shunt_list_${node}")" ] && [ -n "${node}" ] && gen_shunt_list "${node}" shunt_list4 shunt_list6
[ -z "$(get_cache_var "node_${node}_gen_shunt_list")" ] && [ -n "${node}" ] && gen_shunt_list "${node}" shunt_list4 shunt_list6
[ -n "${use}" ] && local dns_redirect_port=$(get_cache_var "ACL_${use}_dns_port")
local ipt_tmp=$ipt_n
@@ -755,8 +755,8 @@ add_firewall_rule() {
$ipt_m -N PSW2
# Socket Only TCP, UDP Invalid.
$ipt_m -A PSW2 -p tcp -m socket -j MARK --set-mark ${FWMARK}
$ipt_m -A PSW2 -p tcp -m socket -j ACCEPT
$ipt_m -A PSW2 -p tcp -m socket --transparent -j MARK --set-mark ${FWMARK}
$ipt_m -A PSW2 -p tcp -m socket --transparent -j ACCEPT
$ipt_m -A PSW2 $(dst $IPSET_VPS) -j RETURN
$ipt_m -A PSW2 $(comment "WAN_IP_RETURN") $(dst $IPSET_WAN) -j RETURN
$ipt_m -A PSW2 -m conntrack --ctdir REPLY -j RETURN
@@ -798,8 +798,8 @@ add_firewall_rule() {
$ip6t_m -N PSW2
# Socket Only TCP, UDP Invalid.
$ip6t_m -A PSW2 -p tcp -m socket -j MARK --set-mark ${FWMARK}
$ip6t_m -A PSW2 -p tcp -m socket -j ACCEPT
$ip6t_m -A PSW2 -p tcp -m socket --transparent -j MARK --set-mark ${FWMARK}
$ip6t_m -A PSW2 -p tcp -m socket --transparent -j ACCEPT
$ip6t_m -A PSW2 $(dst $IPSET_VPS6) -j RETURN
$ip6t_m -A PSW2 $(comment "WAN6_IP_RETURN") $(dst $IPSET_WAN6) -j RETURN
$ip6t_m -A PSW2 -m conntrack --ctdir REPLY -j RETURN
@@ -271,7 +271,7 @@ gen_shunt_list() {
}
[ -n "${_SHUNT_LIST4}" ] && eval ${shunt_list4_var_name}=\"${_SHUNT_LIST4}\"
[ -n "${_SHUNT_LIST6}" ] && eval ${shunt_list6_var_name}=\"${_SHUNT_LIST6}\"
set_cache_var "gen_shunt_list_${node}" "1"
set_cache_var "node_${node}_gen_shunt_list" "1"
}
add_shunt_t_rule() {
@@ -299,7 +299,7 @@ load_acl() {
for sid in $(jsonfilter -s "${ACL_JSON}" -e '$.acl[*].flag'); do
eval $(cat "${TMP_ACL_PATH}/${sid}/var")
[ -z "$(get_cache_var "gen_shunt_list_${node}")" ] && [ -n "${node}" ] && gen_shunt_list "${node}" shunt_list4 shunt_list6
[ -z "$(get_cache_var "node_${node}_gen_shunt_list")" ] && [ -n "${node}" ] && gen_shunt_list "${node}" shunt_list4 shunt_list6
[ -n "${use}" ] && local dns_redirect_port=$(get_cache_var "ACL_${use}_dns_port")
[ "${local_proxy}" = "1" ] && {
@@ -333,10 +333,8 @@ load_acl() {
#nft "add rule $NFTABLE_NAME PSW2_OUTPUT_MANGLE ip protocol tcp tcp dport 53 counter accept"
#nft "add rule $NFTABLE_NAME PSW2_OUTPUT_MANGLE_V6 meta l4proto udp udp dport 53 counter accept"
#nft "add rule $NFTABLE_NAME PSW2_OUTPUT_MANGLE_V6 meta l4proto tcp tcp dport 53 counter accept"
nft "add rule $NFTABLE_NAME nat_output ip protocol udp oif lo udp dport 53 counter redirect to :$dns_redirect_port comment \"PSW2_DNS\""
nft "add rule $NFTABLE_NAME nat_output ip protocol tcp oif lo tcp dport 53 counter redirect to :$dns_redirect_port comment \"PSW2_DNS\""
nft "add rule $NFTABLE_NAME nat_output meta l4proto udp oif lo udp dport 53 counter redirect to :$dns_redirect_port comment \"PSW2_DNS\""
nft "add rule $NFTABLE_NAME nat_output meta l4proto tcp oif lo tcp dport 53 counter redirect to :$dns_redirect_port comment \"PSW2_DNS\""
nft "add rule $NFTABLE_NAME nat_output oif lo meta l4proto udp udp dport 53 counter redirect to :$dns_redirect_port comment \"PSW2_DNS\""
nft "add rule $NFTABLE_NAME nat_output oif lo meta l4proto tcp tcp dport 53 counter redirect to :$dns_redirect_port comment \"PSW2_DNS\""
log 2 "${msg}$(i18n "DNS will redirected to the dedicated DNS server [%s]." "${dns_redirect_port}")"
}
fi
@@ -503,18 +501,14 @@ load_acl() {
if ([ -z "$no_tcp_proxy" ] || [ -z "$no_udp_proxy" ]) && [ -n "$dns_redirect_port" ]; then
nft "add rule $NFTABLE_NAME PSW2_MANGLE ip protocol udp ${_ipt_source} udp dport 53 counter accept"
nft "add rule $NFTABLE_NAME PSW2_MANGLE ip protocol tcp ${_ipt_source} tcp dport 53 counter accept"
nft "add rule $NFTABLE_NAME PSW2_MANGLE_V6 meta l4proto udp ${_ipt_source} udp dport 53 counter accept"
nft "add rule $NFTABLE_NAME PSW2_MANGLE_V6 meta l4proto tcp ${_ipt_source} tcp dport 53 counter accept"
nft "add rule $NFTABLE_NAME PSW2_DNS ip protocol udp ${_ipt_source} udp dport 53 counter redirect to :$dns_redirect_port comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_DNS ip protocol tcp ${_ipt_source} tcp dport 53 counter redirect to :$dns_redirect_port comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_MANGLE_V6 meta l4proto udp ${_ipt_source} udp dport 53 counter accept" 2>/dev/null
nft "add rule $NFTABLE_NAME PSW2_MANGLE_V6 meta l4proto tcp ${_ipt_source} tcp dport 53 counter accept" 2>/dev/null
nft "add rule $NFTABLE_NAME PSW2_DNS meta l4proto udp ${_ipt_source} udp dport 53 counter redirect to :$dns_redirect_port comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_DNS meta l4proto tcp ${_ipt_source} tcp dport 53 counter redirect to :$dns_redirect_port comment \"$remarks\""
log 2 "${msg}$(i18n "DNS will redirected to the dedicated DNS server [%s]." "${dns_redirect_port}")"
else
nft "add rule $NFTABLE_NAME PSW2_DNS ip protocol udp ${_ipt_source} udp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_DNS ip protocol tcp ${_ipt_source} tcp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_DNS meta l4proto udp ${_ipt_source} udp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_DNS meta l4proto tcp ${_ipt_source} tcp dport 53 counter return comment \"$remarks\""
nft "add rule $NFTABLE_NAME PSW2_DNS meta l4proto udp ${_ipt_source} udp dport 53 counter return comment \"$remarks\"" 2>/dev/null
nft "add rule $NFTABLE_NAME PSW2_DNS meta l4proto tcp ${_ipt_source} tcp dport 53 counter return comment \"$remarks\"" 2>/dev/null
fi
[ -z "$no_tcp_proxy" ] && [ -n "$redir_port" ] && {
@@ -819,6 +813,7 @@ add_firewall_rule() {
# jump chains
# Only TCP, UDP Invalid.
nft "add rule $NFTABLE_NAME mangle_prerouting meta nfproto ipv4 meta l4proto tcp socket transparent 1 mark set ${FWMARK} counter accept comment PSW2_SOCKET"
nft "add rule $NFTABLE_NAME mangle_prerouting ip daddr != @$NFTSET_DIRECT ip protocol udp counter jump PSW2_MANGLE"
[ -n "${is_tproxy}" ] && nft "add rule $NFTABLE_NAME mangle_prerouting ip daddr != @$NFTSET_DIRECT ip protocol tcp counter jump PSW2_MANGLE"
@@ -890,9 +885,9 @@ add_firewall_rule() {
[ "$PROXY_IPV6" == "1" ] && {
# Only TCP, UDP Invalid.
nft "add rule $NFTABLE_NAME mangle_prerouting meta nfproto ipv6 meta l4proto tcp socket transparent 1 mark set ${FWMARK} counter accept comment PSW2_SOCKET"
nft "add rule $NFTABLE_NAME mangle_prerouting ip6 daddr != @$NFTSET_DIRECT6 meta nfproto {ipv6} counter jump PSW2_MANGLE_V6"
nft "add rule $NFTABLE_NAME mangle_output ip6 daddr != @$NFTSET_DIRECT6 meta nfproto {ipv6} counter jump PSW2_OUTPUT_MANGLE_V6 comment \"PSW2_OUTPUT_MANGLE\""
nft "add rule $NFTABLE_NAME PSW2_MANGLE_V6 ip6 daddr @$NFTSET_WAN6 counter return comment \"WAN6_IP_RETURN\""
ip -6 rule add fwmark ${FWMARK} table 999 priority 999
@@ -12,13 +12,11 @@ check_process() {
}
test_url() {
local url=$1
local try=1
[ -n "$2" ] && try=$2
local timeout=2
[ -n "$3" ] && timeout=$3
local extra_params=$4
local repeat=$5
local url="$1"
local try="${2:-1}"
local timeout="${3:-2}"
local extra_params="$4"
local repeat="$5"
if [ -z "$curl_retry_all_errors" ]; then
if /usr/bin/curl --help all | grep -q "\-\-retry-all-errors"; then
@@ -29,23 +27,15 @@ test_url() {
local max_time=$((timeout * (try + 1) + try + 3))
curl_test() {
/usr/bin/curl -I -o /dev/null -skL ${extra_params} --max-time ${max_time} --connect-timeout ${timeout} --retry ${try} --retry-delay 1 -w "%{http_code}" "$url"
/usr/bin/curl -skIL -o /dev/null ${extra_params} --max-time ${max_time} --connect-timeout ${timeout} --retry ${try} --retry-delay 1 -w "%{http_code}" "$url"
}
local status=$(curl_test)
case "$status" in
204)
status=200
;;
esac
[ "$status" = "204" ] && status=200
if [ "$status" = "200" ] && [ "$repeat" = "1" ]; then
sleep 3s
status=$(curl_test)
case "$status" in
204)
status=200
;;
esac
[ "$status" = "204" ] && status=200
fi
echo $status
}
@@ -75,7 +65,7 @@ test_node() {
local _type=$(echo $(config_n_get ${node_id} type) | tr 'A-Z' 'a-z')
[ -n "${_type}" ] && {
check_process
local _tmp_port=$(get_new_port 48800)
local _tmp_port=$(get_new_port 48800 tcp,udp)
NO_REC_PROCESS=1 $APP_FILE run_socks flag="test_node_${node_id}" node=${node_id} bind=127.0.0.1 socks_port=${_tmp_port} config_file=test_node_${node_id}.json
sleep 2s
local curlx="socks5h://127.0.0.1:${_tmp_port}"
@@ -92,6 +82,61 @@ test_node() {
return 1
}
try_switch_backup() {
local b_nodes="$1"
local now_node="$2"
local total tried
local new_node msg
local first_node found node
# Only one backup node, alternate with the primary node.
if [ "$backup_node_num" -eq 1 ]; then
b_nodes="$b_nodes $main_node"
fi
total=$(printf "%s\n" "$b_nodes" | wc -w)
tried=0
while [ "$tried" -lt "$total" ]; do
new_node=""
first_node=""
found=""
for node in $b_nodes; do
[ -z "$first_node" ] && first_node="$node" # Record first node.
[ "$found" = "1" ] && { new_node="$node"; break; } # Find the current node and then get the next one.
[ "$node" = "$now_node" ] && found=1 # flag the found current node.
done
# If the current node is not found, or if it is the last node, select the first node.
[ -z "$new_node" ] && new_node="$first_node"
local node_role node_type node_remarks
if [ "$new_node" = "$main_node" ]; then
node_role="$(i18n "main node")"
else
node_role="$(i18n "next backup node")"
fi
node_type=$(config_n_get $new_node type)
node_remarks=$(config_n_get $new_node remarks)
log_i18n 0 "Socks switch detection: Port [%s] try %s [%s:%s]." "${socks_port}" "${node_role}" "${node_type}" "${node_remarks}"
if test_node ${new_node}; then
check_process
log_i18n 0 "Socks switch detection: Port [%s] [%s:[%s]] normal, switch to this node!" "${socks_port}" "${node_type}" "${node_remarks}"
NO_REC_PROCESS=1 $APP_FILE socks_node_switch flag=${id} new_node=${new_node}
[ $? -eq 0 ] && {
log_i18n 0 "Socks switch detection: Port [%s] node switch complete!" "${socks_port}"
}
return 0
fi
log_i18n 0 "Socks switch detection: Port [%s] [%s:[%s]] abnormal." "${socks_port}" "${node_type}" "${node_remarks}"
now_node="$new_node"
tried=$((tried + 1))
done
log_i18n 0 "Socks switch detection: Port [%s] all nodes are unavailable!" "${socks_port}"
return 1
}
test_auto_switch() {
flag=$((flag + 1))
local b_nodes=$1
@@ -100,18 +145,16 @@ test_auto_switch() {
if [ -n "$(get_cache_var "${id}")" ]; then
now_node=$(get_cache_var "${id}")
else
#log_i18n 0 "Socks switch detection: Unknown error."
#log_i18n 0 "Socks switch detection: Port [%s] Unknown error." "${socks_port}"
return 1
fi
}
[ $flag -le 1 ] && {
main_node=$now_node
}
[ $flag -le 1 ] && main_node=$now_node
local status=$(test_proxy)
if [ "$status" = "2" ]; then
log_i18n 0 "Socks switch detection: Unable to connect to the network. Please check if the network is working properly!"
log_i18n 0 "Socks switch detection: Port [%s] Unable to connect to the network. Please check if the network is working properly!" "${socks_port}"
return 2
fi
@@ -121,58 +164,23 @@ test_auto_switch() {
[ $? -eq 0 ] && {
check_process
# The main node is working properly; switch to the main node.
log_i18n 0 "Socks switch detection: Primary node %s: [%s] is normal. Switch to the primary node!" "${id}" "$(config_n_get $main_node type)" "$(config_n_get $main_node remarks)"
$APP_FILE socks_node_switch flag=${id} new_node=${main_node}
log_i18n 0 "Socks switch detection: Port [%s] Primary node [%s: [%s]] is normal. Switch to the primary node!" "${socks_port}" "$(config_n_get $main_node type)" "$(config_n_get $main_node remarks)"
NO_REC_PROCESS=1 $APP_FILE socks_node_switch flag=${id} new_node=${main_node}
[ $? -eq 0 ] && {
log_i18n 0 "Socks switch detection: %s node switch complete!" "${id}"
log_i18n 0 "Socks switch detection: Port [%s] node switch complete!" "${socks_port}"
}
return 0
}
fi
if [ "$status" = "0" ]; then
#log_i18n 0 "Socks switch detection: %s 【%s:[%s] normal." "${id}" "$(config_n_get $now_node type)" "$(config_n_get $now_node remarks)"
[ "$status" = "0" ] && {
#log_i18n 0 "Socks switch detection: Port [%s] [%s:[%s]] normal." "${socks_port}" "$(config_n_get $now_node type)" "$(config_n_get $now_node remarks)"
return 0
elif [ "$status" = "1" ]; then
local new_node msg
if [ "$backup_node_num" -gt 1 ]; then
# When there are multiple backup nodes
local first_node found node
for node in $b_nodes; do
[ -z "$first_node" ] && first_node="$node" # Record the first node.
[ "$found" = "1" ] && { new_node="$node"; break; } # Find the current node and then retrieve the next one.
[ "$node" = "$now_node" ] && found=1 # Mark the current node found.
done
# If the current node is not found, or if the current node is the last node, then take the first node.
[ -z "$new_node" ] && new_node="$first_node"
local msg2="$(i18n "next backup node")"
if [ "$new_node" = "$main_node" ]; then
msg2="$(i18n "main node")"
else
[ "$now_node" = "$main_node" ] && msg2="$(i18n "backup node")"
fi
msg="$(i18n "switch to %s test detect!" "${msg2}")"
else
# When there is only one backup node, poll with the primary node.
new_node=$([ "$now_node" = "$main_node" ] && echo "$b_nodes" || echo "$main_node")
local msg2="$(i18n "main node")"
[ "$now_node" = "$main_node" ] && msg2="$(i18n "backup node")"
msg="$(i18n "switch to %s test detect!" "${msg2}")"
fi
log_i18n 0 "Socks switch detection: %s 【%s:[%s]】 abnormal, %s" "${id}" "$(config_n_get $now_node type)" "$(config_n_get $now_node remarks)" "${msg}"
test_node ${new_node}
if [ $? -eq 0 ]; then
check_process
log_i18n 0 "Socks switch detection: %s 【%s:[%s]】 normal, switch to this node!" "${id}" "$(config_n_get $new_node type)" "$(config_n_get $new_node remarks)"
$APP_FILE socks_node_switch flag=${id} new_node=${new_node}
[ $? -eq 0 ] && {
log_i18n 0 "Socks switch detection: %s node switch complete!" "${id}"
}
return 0
else
test_auto_switch "${b_nodes}" ${new_node}
fi
fi
}
log_i18n 0 "Socks switch detection: Port [%s] [%s:[%s]] abnormal." "${socks_port}" "$(config_n_get $now_node type)" "$(config_n_get $now_node remarks)"
try_switch_backup "$b_nodes" "$now_node"
return $?
}
start() {
@@ -188,6 +196,7 @@ start() {
backup_node=$(lua_api "get_socks_backup_nodes(\"${id}\")")
if [ -n "$backup_node" ]; then
backup_node_num=$(printf "%s\n" "$backup_node" | wc -w)
log_i18n 0 "Socks switch detection: Port [%s] Number of backup nodes: %s" "${socks_port}" "${backup_node_num}"
if [ "$backup_node_num" -eq 1 ]; then
[ "$main_node" = "$backup_node" ] && return
elif [ "$backup_node_num" -gt 1 ]; then
@@ -196,6 +205,7 @@ start() {
}
fi
else
log_i18n 0 "Socks switch detection: Port [%s] Number of backup nodes: %s" "${socks_port}" "0"
return
fi
while [ -n "$backup_node" ]; do
@@ -46,10 +46,10 @@ url_test_node() {
local node_id=$1
local _type=$(echo $(config_n_get ${node_id} type) | tr 'A-Z' 'a-z')
[ -n "${_type}" ] && {
local _tmp_port=$(get_new_port 48900)
local _tmp_port=$(get_new_port 48900 tcp,udp)
NO_REC_PROCESS=1 /usr/share/${CONFIG}/app.sh run_socks flag="url_test_${node_id}" node=${node_id} bind=127.0.0.1 socks_port=${_tmp_port} config_file=url_test_${node_id}.json
sleep 2s
local curlx="socks5h://127.0.0.1:${_tmp_port}"
sleep 2s
local probeUrl=$(config_n_get @global_other[0] url_test_url https://www.google.com/generate_204)
result=$(curl --connect-timeout 3 --max-time 5 -o /dev/null -I -skL -w "%{http_code}:%{time_pretransfer}" -x ${curlx} "${probeUrl}")
# End the SS plugin process
@@ -60,15 +60,24 @@ get_cache_var() {
}
}
del_cache_var() {
local key="${1}"
[ -n "${key}" ] && [ -f "${TMP_PATH}/var" ] && {
sed -i "/${key}=/d" $TMP_PATH/var >/dev/null 2>&1
}
}
set_cache_var() {
local key="${1}"
shift 1
local val="$@"
[ -n "${key}" ] && [ -n "${val}" ] && {
[ ! -d $TMP_PATH ] && mkdir -p $TMP_PATH
sed -i "/${key}=/d" $TMP_PATH/var >/dev/null 2>&1
echo "${key}=\"${val}\"" >> $TMP_PATH/var
eval ${key}=\"${val}\"
[ -n "${key}" ] && {
del_cache_var ${key}
local val="$@"
[ -n "${val}" ] && {
[ ! -d $TMP_PATH ] && mkdir -p $TMP_PATH
echo "${key}=\"${val}\"" >> $TMP_PATH/var
eval ${key}=\"${val}\"
}
}
}
+21 -17
View File
@@ -628,16 +628,6 @@ prepare_clash_runtime_config() {
client_policy_stats=""
client_rules=0
enable_fake_ip="$(uci_get_by_type server_subscribe enable_fake_ip "")"
socks5_auth="$(uci_get_by_type socks5_proxy socks5_auth noauth)"
socks5_user="$(uci_get_by_type socks5_proxy socks5_user "")"
socks5_pass="$(uci_get_by_type socks5_proxy socks5_pass "")"
if [ "$socks5_auth" = "password" ]; then
if [ -z "$socks5_user" ] || [ -z "$socks5_pass" ]; then
echolog "警告:SOCKS5 代理未完整配置用户名或密码,已自动降级为无认证模式 (noauth)。"
socks5_auth="noauth"
fi
fi
[ -s "$cache_file" ] || return 1
@@ -660,14 +650,14 @@ prepare_clash_runtime_config() {
enable: false
EOF
# 根据 enable_fake_ip 决定 enhanced-mode
if [ "$enable_fake_ip" = "1" ]; then
ENHANCED_MODE="fake-ip"
else
ENHANCED_MODE="redir-host"
fi
# 根据 dns_mode 添加不同的 dns 配置
if [ "$dns_mode" = "7" ]; then
# 根据 enable_fake_ip 决定 enhanced-mode
if [ "$enable_fake_ip" = "1" ]; then
ENHANCED_MODE="fake-ip"
else
ENHANCED_MODE="redir-host"
fi
cat >> "$overlay_file" <<-EOF
dns:
enable: true
@@ -678,12 +668,26 @@ prepare_clash_runtime_config() {
else
cat >> "$overlay_file" <<-EOF
dns:
enable: false
enable: true
enhanced-mode: $ENHANCED_MODE
ipv6: $( [ "$dns_ipv4_only" = "1" ] && echo "false" || echo "true" )
EOF
fi
if [ -n "$socks_port" ] && [ "$socks_port" != "0" ]; then
echo "socks-port: $socks_port" >>"$overlay_file"
socks5_auth="$(uci_get_by_type socks5_proxy socks5_auth noauth)"
socks5_user="$(uci_get_by_type socks5_proxy socks5_user "")"
socks5_pass="$(uci_get_by_type socks5_proxy socks5_pass "")"
if [ "$socks5_auth" = "password" ]; then
if [ -z "$socks5_user" ] || [ -z "$socks5_pass" ]; then
echolog "警告:SOCKS5 代理未完整配置用户名或密码,已自动降级为无认证模式 (noauth)"
socks5_auth="noauth"
fi
fi
if [ "$socks5_auth" = "password" ]; then
cat >>"$overlay_file" <<-EOF
authentication:
@@ -653,17 +653,14 @@ local function build_dns_upstreams()
}
end
local function build_dns_section(dns_mode, user_dns, is_external_dns)
local function build_dns_section(dns_mode, user_dns)
local result
local has_user_dns = type(user_dns) == "table" and next(user_dns)
dns_mode = tostring(dns_mode or "0")
if not has_user_dns then
if is_external_dns then
return { enable = false }
end
result = {
enable = true,
listen = "127.0.0.1:5335"
enable = true
}
else
result = clone_table(user_dns)
@@ -699,6 +696,12 @@ local function build_dns_section(dns_mode, user_dns, is_external_dns)
if not result["default-nameserver"] then
result["default-nameserver"] = get_fastest_dns()
end
if not result["direct-nameserver"] then
result["direct-nameserver"] = get_fastest_dns()
end
if result["direct-nameserver-follow-policy"] == nil then
result["direct-nameserver-follow-policy"] = false
end
if result["respect-rules"] == nil then
result["respect-rules"] = true
end
@@ -743,13 +746,15 @@ local function build_dns_section(dns_mode, user_dns, is_external_dns)
result["respect-rules"] = nil
result["fallback-filter"] = nil
result["nameserver-policy"] = nil
result["direct-nameserver"] = nil
result["direct-nameserver-follow-policy"] = nil
end
local upstreams = build_dns_upstreams()
for k, v in pairs(upstreams) do
if k == "proxy-server-nameserver" then
result[k] = v
elseif result[k] == nil then
elseif result[k] == nil and not (k == "respect-rules" and enable_fake_ip ~= "1") then
result[k] = v
end
end
@@ -862,7 +867,8 @@ local function apply_sniffer_config(doc, enable_fake_ip)
["override-destination"] = true,
sniff = {
HTTP = {
ports = { 80, 2052, 2082, 2086, 2095, "8080-8880" }
ports = { 80, 2052, 2082, 2086, 2095, "8080-8880" },
["override-destination"] = true
},
TLS = {
ports = { 443, 2053, 2083, 2087, 2096, 8443 }
@@ -1603,8 +1609,6 @@ end
local function build_single_proxy_runtime_doc(proxy, local_port, socks_port, mode)
local listen_port = tonumber(local_port)
local socks_listen = tonumber(socks_port)
local mode_str = tostring(dns_mode or "")
local is_ext_dns = (mode_str ~= "7")
local doc = {
["allow-lan"] = true,
@@ -1629,8 +1633,9 @@ local function build_single_proxy_runtime_doc(proxy, local_port, socks_port, mod
["store-selected"] = true,
["store-fake-ip"] = true
},
dns = build_dns_section(dns_mode, nil, is_ext_dns)
dns = build_dns_section(dns_mode, nil)
}
apply_sniffer_config(doc, enable_fake_ip)
if mode == "socks" then
doc["socks-port"] = listen_port
@@ -1641,6 +1646,23 @@ local function build_single_proxy_runtime_doc(proxy, local_port, socks_port, mod
doc["socks-port"] = socks_listen
end
end
if doc["socks-port"] and doc["socks-port"] > 0 then
local socks5_auth = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_auth", "noauth")
if socks5_auth == "password" then
local socks5_user = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_user", "")
local socks5_pass = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_pass", "")
if socks5_user == "" or socks5_pass == "" then
io.stderr:write("警告:SOCKS5 代理未完整配置用户名或密码,已自动降级为无认证模式 (noauth)!\n")
else
doc["authentication"] = {
string.format("%s:%s", socks5_user, socks5_pass)
}
end
end
end
return doc
end
@@ -1650,8 +1672,6 @@ local function build_tuic_runtime_doc(sid, local_port, socks_port, mode)
local tuic_ip = get_server_field(sid, "tuic_ip", "")
local tls_host = get_server_field(sid, "tls_host", "")
local ipstack_prefer = get_server_field(sid, "ipstack_prefer", "")
local mode_str = tostring(dns_mode or "")
local is_ext_dns = (mode_str ~= "7")
local proxy = {
name = sid,
@@ -1724,8 +1744,9 @@ local function build_tuic_runtime_doc(sid, local_port, socks_port, mode)
["store-selected"] = true,
["store-fake-ip"] = true
},
dns = build_dns_section(dns_mode, nil, is_ext_dns)
dns = build_dns_section(dns_mode, nil)
}
apply_sniffer_config(doc, enable_fake_ip)
if mode == "socks" then
doc["socks-port"] = listen_port
@@ -1737,6 +1758,22 @@ local function build_tuic_runtime_doc(sid, local_port, socks_port, mode)
end
end
if doc["socks-port"] and doc["socks-port"] > 0 then
local socks5_auth = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_auth", "noauth")
if socks5_auth == "password" then
local socks5_user = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_user", "")
local socks5_pass = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_pass", "")
if socks5_user == "" or socks5_pass == "" then
io.stderr:write("警告:SOCKS5 代理未完整配置用户名或密码,已自动降级为无认证模式 (noauth)!\n")
else
doc["authentication"] = {
string.format("%s:%s", socks5_user, socks5_pass)
}
end
end
end
return doc
end
@@ -1745,8 +1782,7 @@ local function build_shadowsocks_runtime_doc(sid, local_port, socks_port, mode)
local server_port = tonumber(get_server_field(sid, "server_port", "0")) or 0
local method = get_server_field(sid, "encrypt_method_ss", "none")
local password = get_server_field(sid, "password", "")
local mode_str = tostring(dns_mode or "")
local is_ext_dns = (mode_str ~= "7")
local proxy = {
name = sid,
type = "ss",
@@ -1788,8 +1824,9 @@ local function build_shadowsocks_runtime_doc(sid, local_port, socks_port, mode)
["store-selected"] = true,
["store-fake-ip"] = true
},
dns = build_dns_section(dns_mode, nil, is_ext_dns)
dns = build_dns_section(dns_mode, nil)
}
apply_sniffer_config(doc, enable_fake_ip)
local listen_port = tonumber(local_port)
local socks_listen = tonumber(socks_port)
@@ -1803,6 +1840,22 @@ local function build_shadowsocks_runtime_doc(sid, local_port, socks_port, mode)
end
end
if doc["socks-port"] and doc["socks-port"] > 0 then
local socks5_auth = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_auth", "noauth")
if socks5_auth == "password" then
local socks5_user = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_user", "")
local socks5_pass = uci:get_first("shadowsocksr", "socks5_proxy", "socks5_pass", "")
if socks5_user == "" or socks5_pass == "" then
io.stderr:write("警告:SOCKS5 代理未完整配置用户名或密码,已自动降级为无认证模式 (noauth)!\n")
else
doc["authentication"] = {
string.format("%s:%s", socks5_user, socks5_pass)
}
end
end
end
return doc
end
@@ -1988,10 +2041,7 @@ local function prepare(input_path, output_path)
local filled_groups = fill_empty_proxy_groups(doc)
local stripped_rules = strip_incompatible_script_rules(doc)
local dns_config = build_dns_section(dns_mode, user_dns, false)
if dns_config and next(dns_config) then
doc.dns = dns_config
end
doc.dns = build_dns_section(dns_mode, user_dns)
doc.rules = merge_rules_with_direct(doc.rules)
apply_sniffer_config(doc, enable_fake_ip)
@@ -2002,6 +2052,7 @@ local function prepare(input_path, output_path)
if doc["tcp-concurrent"] == nil then
doc["tcp-concurrent"] = true
end
if doc["find-process-mode"] == nil then
doc["find-process-mode"] = "off"
end
@@ -2035,21 +2086,13 @@ local function merge(raw_path, overlay_path, output_path)
strip_runtime_conflicts(raw_doc)
local filled_groups = fill_empty_proxy_groups(raw_doc)
local stripped_rules = strip_incompatible_script_rules(raw_doc)
if user_dns then
if dns_mode ~= "7" then
overlay_doc.dns = nil
end
end
local merged = deep_merge(raw_doc, overlay_doc)
if user_dns then
merged.dns = build_dns_section(dns_mode, user_dns, false)
elseif type(merged.dns) == "table" and next(merged.dns) then
merged.dns = build_dns_section(dns_mode, merged.dns, false)
else
merged.dns = build_dns_section(dns_mode, nil, false)
local target_dns = user_dns
if not target_dns and type(merged.dns) == "table" and next(merged.dns) then
target_dns = merged.dns
end
merged.dns = build_dns_section(dns_mode, target_dns)
merged.rules = merge_rules_with_direct(merged.rules)
apply_sniffer_config(merged, enable_fake_ip)
@@ -2060,6 +2103,7 @@ local function merge(raw_path, overlay_path, output_path)
if merged["tcp-concurrent"] == nil then
merged["tcp-concurrent"] = true
end
if merged["find-process-mode"] == nil then
merged["find-process-mode"] = "off"
end
@@ -1714,7 +1714,7 @@ local function processData(szType, content, cfgid)
result.quic_security = params.quicSecurity or "none"
result.quic_key = params.key
elseif result.transport == "grpc" then
result.serviceName = params.serviceName
result.serviceName = params.servicename
result.grpc_mode = params.mode or "gun"
elseif result.transport == "tcp" or result.transport == "raw" then
result.tcp_guise = params.headerType and params.headerType ~= "" and params.headerType or "none"
+1 -1
View File
@@ -80,7 +80,7 @@ export function load_profile() {
let result = {};
const process = popen('yq -M -p yaml -o json /etc/nikki/run/config.yaml');
if (process) {
result = json(process);
result = json(process.read('all'));
process.close();
}
return result;
+2 -2
View File
@@ -5,12 +5,12 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=sing-box
PKG_VERSION:=1.14.0
PKG_VERSION:=1.14.1
PKG_RELEASE:=1
PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
PKG_SOURCE_URL:=https://codeload.github.com/SagerNet/sing-box/tar.gz/v$(PKG_VERSION)?
PKG_HASH:=87baf6852e37941cbe40bdd94bec81c957c88a56751cecd6bbf0e6108bc69398
PKG_HASH:=1ea41f7d06b0017fe3d3ba7ee30959048aa0ddde31cb0165dab9257edf673321
PKG_LICENSE:=GPL-3.0-or-later
PKG_LICENSE_FILES:=LICENSE
+3 -3
View File
@@ -21,16 +21,16 @@ define Download/geoip
HASH:=1cba1f0982cf62502fa079c66047c3d0c608196da5b3305671e68f60e917a482
endef
GEOSITE_VER:=20260908094002
GEOSITE_VER:=20260914091725
GEOSITE_FILE:=dlc.dat.$(GEOSITE_VER)
define Download/geosite
URL:=https://github.com/v2fly/domain-list-community/releases/download/$(GEOSITE_VER)/
URL_FILE:=dlc.dat
FILE:=$(GEOSITE_FILE)
HASH:=35ed26a24cafa1256bd7261414224b7bcef5c944cea7760e172b030a8b266450
HASH:=4f4df95fee39f8824449f271d773b28eb1f4471aa733d01750209df0dc373091
endef
GEOSITE_IRAN_VER:=202609070121
GEOSITE_IRAN_VER:=202609140147
GEOSITE_IRAN_FILE:=iran.dat.$(GEOSITE_IRAN_VER)
define Download/geosite-ir
URL:=https://github.com/bootmortis/iran-hosted-domains/releases/download/$(GEOSITE_IRAN_VER)/