Compare commits
4
Commits
819111f953
...
v0.1.25
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
520eca9548 | ||
|
|
b0c53fb678 | ||
|
|
b78e53ee23 | ||
|
|
0553dc8d70 |
@@ -19,15 +19,15 @@ config xray-list
|
|||||||
list ip '1.0.0.1'
|
list ip '1.0.0.1'
|
||||||
|
|
||||||
config xray-list
|
config xray-list
|
||||||
option name 'pc'
|
option name 'pc'
|
||||||
option direction 'force_src'
|
option direction 'force_src'
|
||||||
list ip '192.168.2.10'
|
list ip '192.168.2.10'
|
||||||
|
|
||||||
config xray-list
|
config xray-list
|
||||||
option name 'pc_exclude'
|
option name 'pc_exclude'
|
||||||
option direction 'dst'
|
option direction 'dst'
|
||||||
option exclude '1'
|
option exclude '1'
|
||||||
option parent 'pc'
|
option parent 'pc'
|
||||||
list domain 'ifconfig.io'
|
list domain 'ifconfig.io'
|
||||||
|
|
||||||
config xray-list
|
config xray-list
|
||||||
|
|||||||
+10
-3
@@ -79,6 +79,10 @@ _init_vars() {
|
|||||||
_validate_config() {
|
_validate_config() {
|
||||||
_log "config: validating uci syntax" "debug"
|
_log "config: validating uci syntax" "debug"
|
||||||
|
|
||||||
|
if [ -f "/etc/config/xray-manager" ]; then
|
||||||
|
sed -i 's/^ \+/ /g' /etc/config/xray-manager
|
||||||
|
fi
|
||||||
|
|
||||||
local dns_confdir
|
local dns_confdir
|
||||||
dns_confdir=$(uci -q get dhcp.@dnsmasq[0].confdir)
|
dns_confdir=$(uci -q get dhcp.@dnsmasq[0].confdir)
|
||||||
if [ -z "$dns_confdir" ] || ! echo "$dns_confdir" | grep -q "$DNSMASQ_DIR"; then
|
if [ -z "$dns_confdir" ] || ! echo "$dns_confdir" | grep -q "$DNSMASQ_DIR"; then
|
||||||
@@ -127,13 +131,13 @@ _nft_init() {
|
|||||||
nft flush chain ip "$TABLE" prerouting
|
nft flush chain ip "$TABLE" prerouting
|
||||||
nft add rule ip "$TABLE" prerouting fib daddr type local accept
|
nft add rule ip "$TABLE" prerouting fib daddr type local accept
|
||||||
|
|
||||||
nft add chain ip "$TABLE" output { type filter hook output priority -150 \; policy accept \; } 2>/dev/null
|
nft add chain ip "$TABLE" output { type route hook output priority -150 \; policy accept \; } 2>/dev/null
|
||||||
nft flush chain ip "$TABLE" output
|
nft flush chain ip "$TABLE" output
|
||||||
nft add rule ip "$TABLE" output fib daddr type local accept
|
nft add rule ip "$TABLE" output fib daddr type local accept
|
||||||
|
|
||||||
local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
|
local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
|
||||||
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
|
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
|
||||||
ip route show table $RT_TABLE | grep -q "local default" || ip route add local default dev lo table $RT_TABLE
|
ip route show table $RT_TABLE 2>/dev/null | grep -q "local default" || ip route add local default dev lo table $RT_TABLE
|
||||||
ip rule show | grep -q "fwmark $mark_hex lookup $RT_TABLE" || ip rule add fwmark "$TPROXY_MARK" table $RT_TABLE
|
ip rule show | grep -q "fwmark $mark_hex lookup $RT_TABLE" || ip rule add fwmark "$TPROXY_MARK" table $RT_TABLE
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -355,7 +359,10 @@ _run() {
|
|||||||
config_foreach _process_section "xray-list" "exclude"
|
config_foreach _process_section "xray-list" "exclude"
|
||||||
|
|
||||||
_log "main: applying proxy bypass" "debug"
|
_log "main: applying proxy bypass" "debug"
|
||||||
[ -n "$PROXY_SERVERS" ] && nft add rule ip "$TABLE" output ip daddr "@s_proxy_servers" accept 2>/dev/null
|
if [ -n "$PROXY_SERVERS" ]; then
|
||||||
|
_process_item "proxy_servers" "$PROXY_SERVERS" "ip" "out" "0"
|
||||||
|
nft add rule ip "$TABLE" output ip daddr "@s_proxy_servers" accept 2>/dev/null
|
||||||
|
fi
|
||||||
|
|
||||||
_log "main: applying tproxy rules" "debug"
|
_log "main: applying tproxy rules" "debug"
|
||||||
mode_chain="prerouting"; config_foreach _process_section "xray-list" "main_rules"
|
mode_chain="prerouting"; config_foreach _process_section "xray-list" "main_rules"
|
||||||
|
|||||||
Reference in New Issue
Block a user