fix: output rules

This commit is contained in:
root
2026-04-15 00:27:26 +04:00
parent b0c53fb678
commit 520eca9548
+3 -3
View File
@@ -129,15 +129,15 @@ _nft_init() {
_log "$TABLE: setting up base chains" "debug"
nft add chain ip "$TABLE" prerouting { type filter hook prerouting priority mangle \; policy accept \; } 2>/dev/null
nft flush chain ip "$TABLE" prerouting
nft add rule ip "$TABLE" prerouting fib daddr type local accept 2>/dev/null
nft add rule ip "$TABLE" prerouting fib daddr type local accept
nft add chain ip "$TABLE" output { type route hook output priority -150 \; policy accept \; } 2>/dev/null
nft flush chain ip "$TABLE" output
nft add rule ip "$TABLE" output fib daddr type local accept 2>/dev/null
nft add rule ip "$TABLE" output fib daddr type local accept
local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
ip route show table $RT_TABLE | grep -q "local default" || ip route add local default dev lo table $RT_TABLE
ip route show table $RT_TABLE 2>/dev/null | grep -q "local default" || ip route add local default dev lo table $RT_TABLE
ip rule show | grep -q "fwmark $mark_hex lookup $RT_TABLE" || ip rule add fwmark "$TPROXY_MARK" table $RT_TABLE
}