diff --git a/package/lienol/luci-app-passwall/Makefile b/package/lienol/luci-app-passwall/Makefile index c68d1f9979..2fa4f6ca47 100644 --- a/package/lienol/luci-app-passwall/Makefile +++ b/package/lienol/luci-app-passwall/Makefile @@ -6,8 +6,8 @@ include $(TOPDIR)/rules.mk PKG_NAME:=luci-app-passwall -PKG_VERSION:=3.3 -PKG_RELEASE:=41-20200209 +PKG_VERSION:=3.5.3 +PKG_RELEASE:=20200211 PKG_BUILD_DIR := $(BUILD_DIR)/$(PKG_NAME)-$(PKG_VERSION) @@ -67,6 +67,14 @@ config PACKAGE_$(PKG_NAME)_INCLUDE_pdnsd config PACKAGE_$(PKG_NAME)_INCLUDE_dns2socks bool "Include dns2socks" default y + +config PACKAGE_$(PKG_NAME)_INCLUDE_v2ray-plugin + bool "Include v2ray-plugin (Shadowsocks plugin)" + default n + +config PACKAGE_$(PKG_NAME)_INCLUDE_simple-obfs + bool "Include simple-obfs (Shadowsocks plugin)" + default n endmenu endef @@ -91,7 +99,9 @@ define Package/$(PKG_NAME) +PACKAGE_$(PKG_NAME)_INCLUDE_haproxy:haproxy \ +PACKAGE_$(PKG_NAME)_INCLUDE_ChinaDNS_NG:chinadns-ng \ +PACKAGE_$(PKG_NAME)_INCLUDE_pdnsd:pdnsd-alt \ - +PACKAGE_$(PKG_NAME)_INCLUDE_dns2socks:dns2socks + +PACKAGE_$(PKG_NAME)_INCLUDE_dns2socks:dns2socks \ + +PACKAGE_$(PKG_NAME)_INCLUDE_v2ray-plugin:v2ray-plugin \ + +PACKAGE_$(PKG_NAME)_INCLUDE_simple-obfs:simple-obfs endef define Build/Prepare diff --git a/package/lienol/luci-app-passwall/luasrc/controller/passwall.lua b/package/lienol/luci-app-passwall/luasrc/controller/passwall.lua index 997dbfdf18..314b76fdaa 100644 --- a/package/lienol/luci-app-passwall/luasrc/controller/passwall.lua +++ b/package/lienol/luci-app-passwall/luasrc/controller/passwall.lua @@ -9,6 +9,7 @@ local v2ray = require "luci.model.cbi.passwall.api.v2ray" function index() if not nixio.fs.access("/etc/config/passwall") then return end entry({"admin", "vpn"}, firstchild(), "VPN", 45).dependent = false + entry({"admin", "vpn", "passwall", "reset_config"}, call("reset_config")).leaf = true entry({"admin", "vpn", "passwall", "show"}, call("show_menu")).leaf = true entry({"admin", "vpn", "passwall", "hide"}, call("hide_menu")).leaf = true if nixio.fs.access("/etc/config/passwall") and @@ -37,9 +38,8 @@ function index() entry({"admin", "vpn", "passwall", "rule_list"}, cbi("passwall/rule_list", {autoapply = true}), _("Set Blacklist And Whitelist"), 98).leaf = true - entry({"admin", "vpn", "passwall", "log"}, - cbi("passwall/log", {autoapply = true}), _("Watch Logs"), 99).leaf = - true + entry({"admin", "vpn", "passwall", "log"}, cbi("passwall/log"), + _("Watch Logs"), 99).leaf = true entry({"admin", "vpn", "passwall", "node_config"}, cbi("passwall/node_config")).leaf = true @@ -80,6 +80,11 @@ local function http_write_json(content) http.write_json(content or {code = 1}) end +function reset_config() + luci.sys.call('[ -f "/usr/share/passwall/config.default" ] && cp -f /usr/share/passwall/config.default /etc/config/passwall && /etc/init.d/passwall reload') + luci.http.redirect(luci.dispatcher.build_url("admin", "vpn", "passwall")) +end + function show_menu() luci.sys.call("touch /etc/config/passwall_show") luci.http.redirect(luci.dispatcher.build_url("admin", "vpn", "passwall")) @@ -252,7 +257,7 @@ function check_port() "ms.
" else retstring = retstring .. "" .. - node_name .. " Error.
" + node_name .. " Timeout.
" end ret = "" end diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/acl.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/acl.lua index b97cc00c6a..71d9534629 100644 --- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/acl.lua +++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/acl.lua @@ -81,13 +81,14 @@ o:value("disable", translate("No Proxy")) o:value("global", translate("Global Proxy")) o:value("gfwlist", translate("GFW List")) o:value("chnroute", translate("China WhiteList")) -o:value("gamemode", translate("Game Mode")) +--o:value("gamemode", translate("Game Mode")) o:value("returnhome", translate("Return Home")) ---- TCP Redir Ports o = s:option(Value, "tcp_redir_ports", translate("TCP Redir Ports")) o.default = "default" o:value("default", translate("Default")) +o:value("disable", translate("No Proxy")) o:value("1:65535", translate("All")) o:value("80,443", "80,443") o:value("80:", "80 " .. translate("or more")) @@ -97,6 +98,7 @@ o:value(":443", "443 " .. translate("or less")) o = s:option(Value, "udp_redir_ports", translate("UDP Redir Ports")) o.default = "default" o:value("default", translate("Default")) +o:value("disable", translate("No Proxy")) o:value("1:65535", translate("All")) o:value("53", "53") diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua index 4bc990671f..37cb3b83c3 100644 --- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua +++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua @@ -24,7 +24,8 @@ uci:foreach(appname, "nodes", function(e) n[e[".name"]] = "%s+%s:[%s] %s" % {translate(type), "Kcptun", e.remarks, address} else - n[e[".name"]] = "%s:[%s] %s" % {translate(type), e.remarks, address} + n[e[".name"]] = "%s:[%s] %s" % + {translate(type), e.remarks, address} end end end) @@ -74,7 +75,7 @@ for i = 1, udp_node_num, 1 do translate("For Game Mode or DNS resolution and more.") .. translate("The selected server will not use Kcptun.")) o:value("nil", translate("Close")) - o:value("default", translate("Same as the tcp node")) + o:value("tcp", translate("Same as the tcp node")) else o = s:option(ListValue, "udp_node" .. i, translate("UDP Node") .. " " .. i) @@ -89,11 +90,13 @@ for i = 1, socks5_node_num, 1 do if i == 1 then o = s:option(ListValue, "socks5_node" .. i, translate("Socks5 Node"), translate("The client can use the router's Socks5 proxy.")) + o:value("nil", translate("Close")) + o:value("tcp", translate("Same as the tcp node")) else o = s:option(ListValue, "socks5_node" .. i, translate("Socks5 Node") .. " " .. i) + o:value("nil", translate("Close")) end - o:value("nil", translate("Close")) for _, key in pairs(key_table) do o:value(key, n[key]) end end @@ -191,7 +194,7 @@ o:value("disable", translate("No Proxy")) o:value("global", translate("Global Proxy")) o:value("gfwlist", translate("GFW List")) o:value("chnroute", translate("China WhiteList")) -o:value("gamemode", translate("Game Mode")) +--o:value("gamemode", translate("Game Mode")) o:value("returnhome", translate("Return Home")) ---- Localhost Proxy Mode diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/log.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/log.lua index 25dec067f3..859079e9a1 100644 --- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/log.lua +++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/log.lua @@ -1,3 +1,5 @@ -m = Map("passwall") -m:append(Template("passwall/log/log")) -return m +f = SimpleForm("passwall") +f.reset = false +f.submit = false +f:append(Template("passwall/log/log")) +return f diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/node_config.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/node_config.lua index a81eb76d6d..9a108b191a 100644 --- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/node_config.lua +++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/node_config.lua @@ -187,11 +187,13 @@ tcp_fast_open:depends("type", "Trojan") ss_plugin = s:option(ListValue, "ss_plugin", translate("plugin")) ss_plugin:value("none", translate("none")) if is_finded("v2ray-plugin") then ss_plugin:value("v2ray-plugin") end +if is_finded("obfs-local") then ss_plugin:value("obfs-local") end ss_plugin:depends("type", "SS") -ss_plugin_v2ray_opts = - s:option(Value, "ss_plugin_v2ray_opts", translate("opts")) -ss_plugin_v2ray_opts:depends("ss_plugin", "v2ray-plugin") +ss_plugin_opts = + s:option(Value, "ss_plugin_opts", translate("opts")) +ss_plugin_opts:depends("ss_plugin", "v2ray-plugin") +ss_plugin_opts:depends("ss_plugin", "obfs-local") use_kcp = s:option(Flag, "use_kcp", translate("Use Kcptun"), "" .. translate( diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/other.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/other.lua index 26fb12b43a..8dd494c2b7 100644 --- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/other.lua +++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/other.lua @@ -57,6 +57,7 @@ s.addremove = false ---- TCP Redir Ports o = s:option(Value, "tcp_redir_ports", translate("TCP Redir Ports")) o.default = "80,443" +o:value("disable", translate("No Proxy")) o:value("1:65535", translate("All")) o:value("80,443", "80,443") o:value("80:", "80 " .. translate("or more")) @@ -65,6 +66,7 @@ o:value(":443", "443 " .. translate("or less")) ---- UDP Redir Ports o = s:option(Value, "udp_redir_ports", translate("UDP Redir Ports")) o.default = "1:65535" +o:value("disable", translate("No Proxy")) o:value("1:65535", translate("All")) o:value("53", "53") @@ -159,8 +161,10 @@ o.default = "0" o.rmempty = false ---- Hide Menu -o = s:option(Button, "hide", translate("Hide Menu"), translate( - "After the hidden to the display, type in the address bar enter the admin/vpn/passwall/show.
such as: http://192.168.1.1/cgi-bin/luci/admin/vpn/passwall/show")) +o = s:option(Button, "hide", translate("Hide Menu"), + translate( + "After the hidden to the display, input example in the address bar: ") .. + "http://192.168.1.1/cgi-bin/luci/admin/vpn/passwall/show") o.inputstyle = "remove" function o.write(e, e) luci.http.redirect(luci.dispatcher.build_url("admin", "vpn", "passwall", diff --git a/package/lienol/luci-app-passwall/luasrc/view/passwall/global/tips.htm b/package/lienol/luci-app-passwall/luasrc/view/passwall/global/tips.htm index 75ca4e61ac..e9d114f217 100644 --- a/package/lienol/luci-app-passwall/luasrc/view/passwall/global/tips.htm +++ b/package/lienol/luci-app-passwall/luasrc/view/passwall/global/tips.htm @@ -2,5 +2,7 @@
<%:Tips%>:<%:You can use load balancing for failover.%> +
+ <%:Restore the default configuration method. Input example in the address bar: %>http://192.168.1.1/cgi-bin/luci/admin/vpn/passwall/reset_config
diff --git a/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po b/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po index f27c623476..714f98d234 100644 --- a/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po +++ b/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po @@ -1,5 +1,5 @@ msgid "Pass Wall" -msgstr "正确上网姿势 √" +msgstr "PassWall" msgid "Auto" msgstr "自动" @@ -175,6 +175,9 @@ msgstr "小提示" msgid "You can use load balancing for failover." msgstr "可以使用负载均衡实现故障切换功能。" +msgid "Restore the default configuration method. Input example in the address bar:" +msgstr "恢复默认配置方法,地址栏输入例:" + msgid "dnsbyisp" msgstr "运营商DNS(自动分配)" @@ -787,8 +790,8 @@ msgstr "状态信息显示IP111" msgid "Hide Menu" msgstr "隐藏菜单" -msgid "After the hidden to the display, type in the address bar enter the admin/vpn/passwall/show.
such as: http://192.168.1.1/cgi-bin/luci/admin/vpn/passwall/show" -msgstr "当你隐藏后想再次显示,在地址栏后面输入admin/vpn/passwall/show
例如:http://192.168.1.1/cgi-bin/luci/admin/vpn/passwall/show" +msgid "After the hidden to the display, input example in the address bar: " +msgstr "当你隐藏后想再次显示,地址栏输入例:" msgid "Can't determine ARCH, or ARCH not supported." msgstr "无法确认ARCH架构,或是不支持。" diff --git a/package/lienol/luci-app-passwall/root/etc/config/passwall b/package/lienol/luci-app-passwall/root/etc/config/passwall index f01b8e4a81..a86a5ccca9 100644 --- a/package/lienol/luci-app-passwall/root/etc/config/passwall +++ b/package/lienol/luci-app-passwall/root/etc/config/passwall @@ -8,7 +8,7 @@ config global option up_china_dns 'default' option dns_forward '8.8.4.4' option use_tcp_node_resolve_dns '1' - option dns_53 '0' + option dns_53 '1' option proxy_mode 'chnroute' option localhost_proxy_mode 'gfwlist' diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh index ae26d33941..e7da6cbf38 100755 --- a/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh @@ -157,7 +157,8 @@ for i in $(seq 1 $SOCKS5_NODE_NUM); do eval SOCKS5_NODE$i=$(config_t_get global socks5_node$i nil) done -[ "$UDP_NODE1" == "default" ] && UDP_NODE1=$TCP_NODE1 +[ "$UDP_NODE1" == "tcp" ] && UDP_NODE1=$TCP_NODE1 +[ "$SOCKS5_NODE1" == "tcp" ] && SOCKS5_NODE1=$TCP_NODE1 TCP_NODE1_IP="" UDP_NODE1_IP="" @@ -181,9 +182,7 @@ KCPTUN_REDIR_PORT=$(config_t_get global_forwarding kcptun_port 12948) PROXY_MODE=$(config_t_get global proxy_mode chnroute) load_config() { - [ "$ENABLED" != 1 ] && { - return 1 - } + [ "$ENABLED" != 1 ] && return 1 [ "$TCP_NODE1" == "nil" -a "$UDP_NODE1" == "nil" -a "$SOCKS5_NODE1" == "nil" ] && { echolog "没有选择节点!" return 1 @@ -347,9 +346,9 @@ gen_start_config() { local plugin_params="" local plugin=$(config_n_get $node ss_plugin) if [ "$plugin" != "none" ]; then - [ "$plugin" == "v2ray-plugin" ] && { - local opts=$(config_n_get $node ss_plugin_v2ray_opts) - plugin_params="--plugin v2ray-plugin --plugin-opts $opts" + [ "$plugin" == "v2ray-plugin" -o "$plugin" == "obfs-local" ] && { + local opts=$(config_n_get $node ss_plugin_opts) + plugin_params="--plugin $plugin --plugin-opts $opts" } fi $ss_bin -c $config_file -b 0.0.0.0 -u $plugin_params >/dev/null 2>&1 & @@ -455,9 +454,9 @@ gen_start_config() { local plugin_params="" local plugin=$(config_n_get $node ss_plugin) if [ "$plugin" != "none" ]; then - [ "$plugin" == "v2ray-plugin" ] && { - local opts=$(config_n_get $node ss_plugin_v2ray_opts) - plugin_params="--plugin v2ray-plugin --plugin-opts $opts" + [ "$plugin" == "v2ray-plugin" -o "$plugin" == "obfs-local" ] && { + local opts=$(config_n_get $node ss_plugin_opts) + plugin_params="--plugin $plugin --plugin-opts $opts" } fi $ss_bin -c $config_file -f $RUN_PID_PATH/udp_ss_1_$5 -U $plugin_params >/dev/null 2>&1 & @@ -568,9 +567,9 @@ gen_start_config() { local plugin_params="" local plugin=$(config_n_get $node ss_plugin) if [ "$plugin" != "none" ]; then - [ "$plugin" == "v2ray-plugin" ] && { - local opts=$(config_n_get $node ss_plugin_v2ray_opts) - plugin_params="--plugin v2ray-plugin --plugin-opts $opts" + [ "$plugin" == "v2ray-plugin" -o "$plugin" == "obfs-local" ] && { + local opts=$(config_n_get $node ss_plugin_opts) + plugin_params="--plugin $plugin --plugin-opts $opts" } fi for k in $(seq 1 $process); do @@ -1096,13 +1095,15 @@ force_stop() { } boot() { - local delay=$(config_t_get global_delay start_delay 1) - if [ "$delay" -gt 0 ]; then - echolog "执行启动延时 $delay 秒后再启动!" - sleep $delay && start >/dev/null 2>&1 & - else - start - fi + [ "$ENABLED" == 1 ] && { + local delay=$(config_t_get global_delay start_delay 1) + if [ "$delay" -gt 0 ]; then + echolog "执行启动延时 $delay 秒后再启动!" + sleep $delay && start >/dev/null 2>&1 & + else + start + fi + } return 0 } @@ -1137,7 +1138,7 @@ stop() { done clean_log source $APP_PATH/iptables.sh stop - kill_all brook dns2socks haproxy chinadns-ng ipt2socks v2ray-plugin + kill_all brook dns2socks haproxy chinadns-ng ipt2socks v2ray-plugin obfs-local ps -w | grep -E "$CONFIG_TCP_FILE|$CONFIG_UDP_FILE|$CONFIG_SOCKS5_FILE" | grep -v "grep" | awk '{print $1}' | xargs kill -9 >/dev/null 2>&1 & ps -w | grep -E "$CONFIG_PATH" | grep -v "grep" | awk '{print $1}' | xargs kill -9 >/dev/null 2>&1 & rm -rf $TMP_DNSMASQ_PATH $CONFIG_PATH diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/config.default b/package/lienol/luci-app-passwall/root/usr/share/passwall/config.default new file mode 100644 index 0000000000..a86a5ccca9 --- /dev/null +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/config.default @@ -0,0 +1,63 @@ + +config global + option enabled '0' + option tcp_node1 'nil' + option udp_node1 'nil' + option socks5_node1 'nil' + option dns_mode 'pdnsd' + option up_china_dns 'default' + option dns_forward '8.8.4.4' + option use_tcp_node_resolve_dns '1' + option dns_53 '1' + option proxy_mode 'chnroute' + option localhost_proxy_mode 'gfwlist' + +config global_haproxy + option balancing_enable '0' + +config global_delay + option auto_on '0' + option start_daemon '0' + option start_delay '1' + +config global_forwarding + option process '1' + option tcp_redir_ports '1:65535' + option udp_redir_ports '1:65535' + option socks5_proxy_port '1081' + option proxy_ipv6 '0' + +config global_other + option use_tcping '1' + option auto_ping '1' + option tcp_node_num '1' + option udp_node_num '1' + option socks5_node_num '1' + option status_use_big_icon '1' + option status_show_check_port '0' + option status_show_ip111 '0' + option compact_display_nodes '0' + option show_group '0' + option show_add_mode '0' + +config global_rules + option auto_update '0' + option gfwlist_update '1' + option chnroute_update '1' + option chnlist_update '1' + option gfwlist_version '2019-12-10' + option chnroute_version '2019-12-05' + option chnlist_version '2020-01-06' + +config global_app + option v2ray_file '/usr/bin/v2ray/' + option kcptun_client_file '/usr/bin/kcptun-client' + option brook_file '/usr/bin/brook' + +config global_subscribe + option subscribe_proxy '0' + option auto_update_subscribe '0' + +config auto_switch + option testing_time '3' + option enable '0' diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh index c7e80d53d5..1cd50ba867 100755 --- a/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh @@ -8,10 +8,10 @@ IPSET_CHN="chnroute" IPSET_BLACKLIST="blacklist" IPSET_WHITELIST="whitelist" -iptables_nat="iptables -t nat" -iptables_mangle="iptables -t mangle" -ip6tables_nat="ip6tables -t nat" -iptables_comment="-m comment --comment PassWall" +ipt_n="iptables -t nat" +ipt_m="iptables -t mangle" +ip6t_n="ip6tables -t nat" +ipt_comment="-m comment --comment PassWall" factor() { if [ -z "$1" ] || [ -z "$2" ]; then @@ -142,20 +142,28 @@ load_acl() { fi if [ "$proxy_mode" == "disable" ]; then - $iptables_nat -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp -m comment --comment "$remarks" -j RETURN - $iptables_mangle -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp -m comment --comment "$remarks" -j RETURN + $ipt_n -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp -m comment --comment "$remarks" -j RETURN + $ipt_m -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp -m comment --comment "$remarks" -j RETURN else [ "$TCP_NODE" != "nil" ] && { #local TCP_NODE_TYPE=$(echo $(config_get $TCP_NODE type) | tr 'A-Z' 'a-z') - eval tcp_redir_port=\$TCP_REDIR_PORT$tcp_node - $iptables_nat -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp $(dst $IPSET_BLACKLIST) -m comment --comment "$remarks" -j REDIRECT --to-ports $tcp_redir_port - $iptables_nat -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp $(factor $tcp_redir_ports "-m multiport --dport") -m comment --comment "$remarks" -$(get_jump_mode $proxy_mode) $(get_action_chain $proxy_mode)$tcp_node + if [ "$tcp_redir_ports" != "disable" ]; then + eval tcp_redir_port=\$TCP_REDIR_PORT$tcp_node + $ipt_n -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp $(dst $IPSET_BLACKLIST) -m comment --comment "$remarks" -j REDIRECT --to-ports $tcp_redir_port + $ipt_n -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp $(factor $tcp_redir_ports "-m multiport --dport") -m comment --comment "$remarks" -$(get_jump_mode $proxy_mode) $(get_action_chain $proxy_mode)$tcp_node + else + $ipt_n -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p tcp -m comment --comment "$remarks" -j RETURN + fi } [ "$UDP_NODE" != "nil" ] && { #local UDP_NODE_TYPE=$(echo $(config_get $UDP_NODE type) | tr 'A-Z' 'a-z') - eval udp_redir_port=\$UDP_REDIR_PORT$udp_node - $iptables_mangle -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp $(dst $IPSET_BLACKLIST) -m comment --comment "$remarks" -j TPROXY --on-port $udp_redir_port --tproxy-mark 0x1/0x1 - $iptables_mangle -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp $(factor $udp_redir_ports "-m multiport --dport") -m comment --comment "$remarks" -$(get_jump_mode $proxy_mode) $(get_action_chain $proxy_mode)$udp_node + if [ "$udp_redir_ports" != "disable" ]; then + eval udp_redir_port=\$UDP_REDIR_PORT$udp_node + $ipt_m -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp $(dst $IPSET_BLACKLIST) -m comment --comment "$remarks" -j TPROXY --on-port $udp_redir_port --tproxy-mark 0x1/0x1 + $ipt_m -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp $(factor $udp_redir_ports "-m multiport --dport") -m comment --comment "$remarks" -$(get_jump_mode $proxy_mode) $(get_action_chain $proxy_mode)$udp_node + else + $ipt_m -A PSW_ACL $(factor $ip "-s") $(factor $mac "-m mac --mac-source") -p udp -m comment --comment "$remarks" -j RETURN + fi } fi [ -z "$ip" ] && { @@ -188,8 +196,8 @@ dns_hijack() { dnshijack=$(config_t_get global dns_53) if [ "$dnshijack" = "1" -o "$1" = "force" ]; then echolog "添加DNS劫持规则..." - $iptables_nat -I PSW -p udp --dport 53 -j REDIRECT --to-ports 53 - $iptables_nat -I PSW -p tcp --dport 53 -j REDIRECT --to-ports 53 + $ipt_n -I PSW -p udp --dport 53 -j REDIRECT --to-ports 53 + $ipt_n -I PSW -p tcp --dport 53 -j REDIRECT --to-ports 53 fi } @@ -228,36 +236,36 @@ add_firewall_rule() { # 过滤所有节点IP config_foreach filter_vpsip "nodes" - $iptables_nat -N PSW - $iptables_nat -A PSW $(dst $IPSET_LANIPLIST) -j RETURN - $iptables_nat -A PSW $(dst $IPSET_VPSIPLIST) -j RETURN - $iptables_nat -A PSW $(dst $IPSET_WHITELIST) -j RETURN - $iptables_nat -N PSW_ACL - $iptables_nat -N PSW_OUTPUT + $ipt_n -N PSW + $ipt_n -A PSW $(dst $IPSET_LANIPLIST) -j RETURN + $ipt_n -A PSW $(dst $IPSET_VPSIPLIST) -j RETURN + $ipt_n -A PSW $(dst $IPSET_WHITELIST) -j RETURN + $ipt_n -N PSW_ACL + $ipt_n -N PSW_OUTPUT - $iptables_mangle -N PSW - $iptables_mangle -A PSW $(dst $IPSET_LANIPLIST) -j RETURN - $iptables_mangle -A PSW $(dst $IPSET_VPSIPLIST) -j RETURN - $iptables_mangle -A PSW $(dst $IPSET_WHITELIST) -j RETURN - $iptables_mangle -N PSW_ACL - $iptables_mangle -N PSW_OUTPUT + $ipt_m -N PSW + $ipt_m -A PSW $(dst $IPSET_LANIPLIST) -j RETURN + $ipt_m -A PSW $(dst $IPSET_VPSIPLIST) -j RETURN + $ipt_m -A PSW $(dst $IPSET_WHITELIST) -j RETURN + $ipt_m -N PSW_ACL + $ipt_m -N PSW_OUTPUT if [[ "$TCP_NODE_NUM" -ge 1 ]] || [[ "$UDP_NODE_NUM" -ge 1 ]]; then local max_num=1 [ "$TCP_NODE_NUM" -ge "$UDP_NODE_NUM" ] && max_num=$TCP_NODE_NUM if [ "$max_num" -ge 1 ]; then for i in $(seq 1 $max_num); do - $iptables_nat -N PSW_GLO$i - $iptables_nat -N PSW_GFW$i - $iptables_nat -N PSW_CHN$i - $iptables_nat -N PSW_HOME$i - $iptables_nat -N PSW_GAME$i + $ipt_n -N PSW_GLO$i + $ipt_n -N PSW_GFW$i + $ipt_n -N PSW_CHN$i + $ipt_n -N PSW_HOME$i + $ipt_n -N PSW_GAME$i - $iptables_mangle -N PSW_GLO$i - $iptables_mangle -N PSW_GFW$i - $iptables_mangle -N PSW_CHN$i - $iptables_mangle -N PSW_HOME$i - $iptables_mangle -N PSW_GAME$i + $ipt_m -N PSW_GLO$i + $ipt_m -N PSW_GFW$i + $ipt_m -N PSW_CHN$i + $ipt_m -N PSW_HOME$i + $ipt_m -N PSW_GAME$i ip rule add fwmark 1 lookup 100 ip route add local 0.0.0.0/0 dev lo table 100 @@ -273,7 +281,7 @@ add_firewall_rule() { local address=$(config_get $node address) local SOCKS5_NODE_PORT=$(config_get $node port) local SOCKS5_NODE_IP=$(get_host_ip "ipv4" $address) - [ -n "$SOCKS5_NODE_IP" -a -n "$SOCKS5_NODE_PORT" ] && $iptables_nat -A PSW -p tcp -d $SOCKS5_NODE_IP -m multiport --dports $SOCKS5_NODE_PORT -j RETURN + [ -n "$SOCKS5_NODE_IP" -a -n "$SOCKS5_NODE_PORT" ] && $ipt_n -A PSW -p tcp -d $SOCKS5_NODE_IP -m multiport --dports $SOCKS5_NODE_PORT -j RETURN fi done fi @@ -290,49 +298,51 @@ add_firewall_rule() { local TCP_NODE_PORT=$(config_get $node port) local TCP_NODE_IP=$(get_host_ip "ipv4" $address) local TCP_NODE_TYPE=$(echo $(config_get $node type) | tr 'A-Z' 'a-z') - [ -n "$TCP_NODE_IP" -a -n "$TCP_NODE_PORT" ] && $iptables_nat -A PSW -p tcp -d $TCP_NODE_IP -m multiport --dports $TCP_NODE_PORT -j RETURN + [ -n "$TCP_NODE_IP" -a -n "$TCP_NODE_PORT" ] && $ipt_n -A PSW -p tcp -d $TCP_NODE_IP -m multiport --dports $TCP_NODE_PORT -j RETURN if [ "$TCP_NODE_TYPE" == "brook" ]; then - $iptables_mangle -A PSW_ACL -p tcp -m socket -j MARK --set-mark 1 + $ipt_m -A PSW_ACL -p tcp -m socket -j MARK --set-mark 1 - # $iptables_mangle -A PSW$k -p tcp $(dst $IPSET_BLACKLIST) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + # $ipt_m -A PSW$k -p tcp $(dst $IPSET_BLACKLIST) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 全局模式 - $iptables_mangle -A PSW_GLO$k -p tcp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_GLO$k -p tcp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # GFWLIST模式 - $iptables_mangle -A PSW_GFW$k -p tcp $(dst $IPSET_GFW) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_GFW$k -p tcp $(dst $IPSET_GFW) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 大陆白名单模式 - $iptables_mangle -A PSW_CHN$k -p tcp $(dst $IPSET_CHN) -j RETURN - $iptables_mangle -A PSW_CHN$k -p tcp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_CHN$k -p tcp $(dst $IPSET_CHN) -j RETURN + $ipt_m -A PSW_CHN$k -p tcp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 回国模式 - $iptables_mangle -A PSW_HOME$k -p tcp $(dst $IPSET_CHN) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_HOME$k -p tcp $(dst $IPSET_CHN) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 游戏模式 - $iptables_mangle -A PSW_GAME$k -p tcp $(dst $IPSET_CHN) -j RETURN + $ipt_m -A PSW_GAME$k -p tcp $(dst $IPSET_CHN) -j RETURN # 用于本机流量转发,默认只走router - $iptables_mangle -A PSW -s $lan_ip -p tcp $(dst $IPSET_ROUTER) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port - $iptables_mangle -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1 + $ipt_m -A PSW -s $lan_ip -p tcp $(dst $IPSET_ROUTER) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + if [ "$TCP_REDIR_PORTS" != "disable" ]; then + $ipt_m -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1 + fi else # 全局模式 - $iptables_nat -A PSW_GLO$k -p tcp -j REDIRECT --to-ports $local_port + $ipt_n -A PSW_GLO$k -p tcp -j REDIRECT --to-ports $local_port # GFWLIST模式 - $iptables_nat -A PSW_GFW$k -p tcp $(dst $IPSET_ROUTER) -j REDIRECT --to-ports $local_port - $iptables_nat -A PSW_GFW$k -p tcp $(dst $IPSET_GFW) -j REDIRECT --to-ports $local_port + $ipt_n -A PSW_GFW$k -p tcp $(dst $IPSET_ROUTER) -j REDIRECT --to-ports $local_port + $ipt_n -A PSW_GFW$k -p tcp $(dst $IPSET_GFW) -j REDIRECT --to-ports $local_port # 大陆白名单模式 - $iptables_nat -A PSW_CHN$k -p tcp $(dst $IPSET_CHN) -j RETURN - #$iptables_nat -A PSW_CHN$k -p tcp -m geoip ! --destination-country CN -j REDIRECT --to-ports $local_port - $iptables_nat -A PSW_CHN$k -p tcp -j REDIRECT --to-ports $local_port + $ipt_n -A PSW_CHN$k -p tcp $(dst $IPSET_CHN) -j RETURN + #$ipt_n -A PSW_CHN$k -p tcp -m geoip ! --destination-country CN -j REDIRECT --to-ports $local_port + $ipt_n -A PSW_CHN$k -p tcp -j REDIRECT --to-ports $local_port # 回国模式 - #$iptables_nat -A PSW_HOME$k -p tcp -m geoip --destination-country CN -j REDIRECT --to-ports $local_port - $iptables_nat -A PSW_HOME$k -p tcp $(dst $IPSET_CHN) -j REDIRECT --to-ports $local_port + #$ipt_n -A PSW_HOME$k -p tcp -m geoip --destination-country CN -j REDIRECT --to-ports $local_port + $ipt_n -A PSW_HOME$k -p tcp $(dst $IPSET_CHN) -j REDIRECT --to-ports $local_port # 游戏模式 - $iptables_nat -A PSW_GAME$k -p tcp $(dst $IPSET_CHN) -j RETURN + $ipt_n -A PSW_GAME$k -p tcp $(dst $IPSET_CHN) -j RETURN [ "$k" == 1 ] && { [ "$use_tcp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && { @@ -341,75 +351,81 @@ add_firewall_rule() { local dns_ip=$(echo $dns | awk -F "#" '{print $1}') local dns_port=$(echo $dns | awk -F "#" '{print $2}') [ -z "$dns_port" ] && dns_port=53 - $iptables_nat -I PSW 2 -p tcp -d $dns_ip --dport $dns_port -j REDIRECT --to-ports $local_port + $ipt_n -I PSW 2 -p tcp -d $dns_ip --dport $dns_port -j REDIRECT --to-ports $local_port done } PRE_INDEX=1 - KP_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "KOOLPROXY" | sed -n '$p' | awk '{print $1}') - ADBYBY_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "ADBYBY" | sed -n '$p' | awk '{print $1}') + KP_INDEX=$($ipt_n -L PREROUTING --line-numbers | grep "KOOLPROXY" | sed -n '$p' | awk '{print $1}') + ADBYBY_INDEX=$($ipt_n -L PREROUTING --line-numbers | grep "ADBYBY" | sed -n '$p' | awk '{print $1}') if [ -n "$KP_INDEX" -a -z "$ADBYBY_INDEX" ]; then PRE_INDEX=$(expr $KP_INDEX + 1) elif [ -z "$KP_INDEX" -a -n "$ADBYBY_INDEX" ]; then PRE_INDEX=$(expr $ADBYBY_INDEX + 1) elif [ -z "$KP_INDEX" -a -z "$ADBYBY_INDEX" ]; then - PR_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "prerouting_rule" | sed -n '$p' | awk '{print $1}') + PR_INDEX=$($ipt_n -L PREROUTING --line-numbers | grep "prerouting_rule" | sed -n '$p' | awk '{print $1}') [ -n "$PR_INDEX" ] && { PRE_INDEX=$(expr $PR_INDEX + 1) } fi - $iptables_nat -I PREROUTING $PRE_INDEX -j PSW + $ipt_n -I PREROUTING $PRE_INDEX -j PSW # 用于本机流量转发 - $iptables_nat -A OUTPUT -j PSW_OUTPUT - $iptables_nat -A PSW_OUTPUT $(dst $IPSET_LANIPLIST) -j RETURN + $ipt_n -A OUTPUT -j PSW_OUTPUT + $ipt_n -A PSW_OUTPUT $(dst $IPSET_LANIPLIST) -j RETURN [ "$use_tcp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && { for dns in $DNS_FORWARD do local dns_ip=$(echo $dns | awk -F "#" '{print $1}') local dns_port=$(echo $dns | awk -F "#" '{print $2}') [ -z "$dns_port" ] && dns_port=53 - $iptables_nat -A PSW_OUTPUT -p tcp -d $dns_ip --dport $dns_port -j REDIRECT --to-ports $TCP_REDIR_PORT1 + $ipt_n -A PSW_OUTPUT -p tcp -d $dns_ip --dport $dns_port -j REDIRECT --to-ports $TCP_REDIR_PORT1 done } - $iptables_nat -A PSW_OUTPUT $(dst $IPSET_VPSIPLIST) -j RETURN - $iptables_nat -A PSW_OUTPUT $(dst $IPSET_WHITELIST) -j RETURN - $iptables_nat -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_ROUTER) -j REDIRECT --to-ports $TCP_REDIR_PORT1 - $iptables_nat -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j REDIRECT --to-ports $TCP_REDIR_PORT1 + $ipt_n -A PSW_OUTPUT $(dst $IPSET_VPSIPLIST) -j RETURN + $ipt_n -A PSW_OUTPUT $(dst $IPSET_WHITELIST) -j RETURN + + if [ "$TCP_REDIR_PORTS" != "disable" ]; then + $ipt_n -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_ROUTER) -j REDIRECT --to-ports $TCP_REDIR_PORT1 + $ipt_n -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j REDIRECT --to-ports $TCP_REDIR_PORT1 - [ "$LOCALHOST_PROXY_MODE" == "global" ] && $iptables_nat -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS -j REDIRECT --to-ports $TCP_REDIR_PORT1 - [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $iptables_nat -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_GFW) -j REDIRECT --to-ports $TCP_REDIR_PORT1 - [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && { - $iptables_nat -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j REDIRECT --to-ports $TCP_REDIR_PORT1 - } + [ "$LOCALHOST_PROXY_MODE" == "global" ] && $ipt_n -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS -j REDIRECT --to-ports $TCP_REDIR_PORT1 + [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $ipt_n -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS $(dst $IPSET_GFW) -j REDIRECT --to-ports $TCP_REDIR_PORT1 + [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && { + $ipt_n -A PSW_OUTPUT -p tcp -m multiport --dport $TCP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j REDIRECT --to-ports $TCP_REDIR_PORT1 + } + else + $ipt_n -A PSW_OUTPUT -p tcp $(dst $IPSET_ROUTER) -j RETURN + $ipt_n -A PSW_OUTPUT -p tcp $(dst $IPSET_BLACKLIST) -j RETURN + fi } # 重定所有流量到透明代理端口 - # $iptables_nat -A PSW -p tcp -m ttl --ttl-eq $ttl -j REDIRECT --to $local_port + # $ipt_n -A PSW -p tcp -m ttl --ttl-eq $ttl -j REDIRECT --to $local_port echolog "IPv4 防火墙TCP转发规则加载完成!" fi if [ "$PROXY_IPV6" == "1" ]; then lan_ipv6=$(ip address show br-lan | grep -w "inet6" | awk '{print $2}') #当前LAN IPv6段 - $ip6tables_nat -N PSW - $ip6tables_nat -N PSW_ACL - $ip6tables_nat -A PREROUTING -j PSW + $ip6t_n -N PSW + $ip6t_n -N PSW_ACL + $ip6t_n -A PREROUTING -j PSW [ -n "$lan_ipv6" ] && { for ip in $lan_ipv6; do - $ip6tables_nat -A PSW -d $ip -j RETURN + $ip6t_n -A PSW -d $ip -j RETURN done } - [ "$use_ipv6" == "1" -a -n "$server_ip" ] && $ip6tables_nat -A PSW -d $server_ip -j RETURN - $ip6tables_nat -N PSW_GLO$k - $ip6tables_nat -N PSW_GFW$k - $ip6tables_nat -N PSW_CHN$k - $ip6tables_nat -N PSW_HOME$k - $ip6tables_nat -A PSW_GLO$k -p tcp -j REDIRECT --to $TCP_REDIR_PORT - $ip6tables_nat -A PSW -j PSW_GLO$k - #$ip6tables_nat -I OUTPUT -p tcp -j PSW + [ "$use_ipv6" == "1" -a -n "$server_ip" ] && $ip6t_n -A PSW -d $server_ip -j RETURN + $ip6t_n -N PSW_GLO$k + $ip6t_n -N PSW_GFW$k + $ip6t_n -N PSW_CHN$k + $ip6t_n -N PSW_HOME$k + $ip6t_n -A PSW_GLO$k -p tcp -j REDIRECT --to $TCP_REDIR_PORT + $ip6t_n -A PSW -j PSW_GLO$k + #$ip6t_n -I OUTPUT -p tcp -j PSW echolog "IPv6防火墙规则加载完成!" fi fi done - $iptables_nat -A PSW -j PSW_ACL + $ipt_n -A PSW -j PSW_ACL else echolog "主节点未选择,无法转发TCP!" fi @@ -425,56 +441,61 @@ add_firewall_rule() { local UDP_NODE_PORT=$(config_get $node port) local UDP_NODE_IP=$(get_host_ip "ipv4" $address) local UDP_NODE_TYPE=$(echo $(config_get $node type) | tr 'A-Z' 'a-z') - [ -n "$UDP_NODE_IP" -a -n "$UDP_NODE_PORT" ] && $iptables_mangle -A PSW -p udp -d $UDP_NODE_IP -m multiport --dports $UDP_NODE_PORT -j RETURN - [ "$UDP_NODE_TYPE" == "brook" ] && $iptables_mangle -A PSW_ACL -p udp -m socket -j MARK --set-mark 1 + [ -n "$UDP_NODE_IP" -a -n "$UDP_NODE_PORT" ] && $ipt_m -A PSW -p udp -d $UDP_NODE_IP -m multiport --dports $UDP_NODE_PORT -j RETURN + [ "$UDP_NODE_TYPE" == "brook" ] && $ipt_m -A PSW_ACL -p udp -m socket -j MARK --set-mark 1 # 全局模式 - $iptables_mangle -A PSW_GLO$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_GLO$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # GFWLIST模式 - $iptables_mangle -A PSW_GFW$k -p udp $(dst $IPSET_ROUTER) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port - $iptables_mangle -A PSW_GFW$k -p udp $(dst $IPSET_GFW) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_GFW$k -p udp $(dst $IPSET_ROUTER) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_GFW$k -p udp $(dst $IPSET_GFW) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 大陆白名单模式 - $iptables_mangle -A PSW_CHN$k -p udp $(dst $IPSET_CHN) -j RETURN - $iptables_mangle -A PSW_CHN$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_CHN$k -p udp $(dst $IPSET_CHN) -j RETURN + $ipt_m -A PSW_CHN$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 回国模式 - $iptables_mangle -A PSW_HOME$k -p udp $(dst $IPSET_CHN) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_HOME$k -p udp $(dst $IPSET_CHN) -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port # 游戏模式 - $iptables_mangle -A PSW_GAME$k -p udp $(dst $IPSET_CHN) -j RETURN - $iptables_mangle -A PSW_GAME$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_GAME$k -p udp $(dst $IPSET_CHN) -j RETURN + $ipt_m -A PSW_GAME$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port [ "$k" == 1 ] && { # 用于本机流量转发 - $iptables_mangle -A OUTPUT -j PSW_OUTPUT - $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_LANIPLIST) -j RETURN + $ipt_m -A OUTPUT -j PSW_OUTPUT + $ipt_m -A PSW_OUTPUT -p udp $(dst $IPSET_LANIPLIST) -j RETURN [ "$use_udp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && { for dns in $DNS_FORWARD do local dns_ip=$(echo $dns | awk -F "#" '{print $1}') local dns_port=$(echo $dns | awk -F "#" '{print $2}') [ -z "$dns_port" ] && dns_port=53 - $iptables_mangle -A PSW_OUTPUT -p udp -d $dns_ip --dport $dns_port -j MARK --set-mark 1 - $iptables_mangle -I PSW 2 -p udp -d $dns_ip --dport $dns_port -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + $ipt_m -A PSW_OUTPUT -p udp -d $dns_ip --dport $dns_port -j MARK --set-mark 1 + $ipt_m -I PSW 2 -p udp -d $dns_ip --dport $dns_port -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port done } - $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_VPSIPLIST) -j RETURN - $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_WHITELIST) -j RETURN - $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1 - $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j MARK --set-mark 1 - - [ "$LOCALHOST_PROXY_MODE" == "global" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -j MARK --set-mark 1 - [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_GFW) -j MARK --set-mark 1 - [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && { - $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j MARK --set-mark 1 - } + $ipt_m -A PSW_OUTPUT -p udp $(dst $IPSET_VPSIPLIST) -j RETURN + $ipt_m -A PSW_OUTPUT -p udp $(dst $IPSET_WHITELIST) -j RETURN + + if [ "$UDP_REDIR_PORTS" != "disable" ]; then + $ipt_m -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1 + $ipt_m -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j MARK --set-mark 1 + [ "$LOCALHOST_PROXY_MODE" == "global" ] && $ipt_m -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -j MARK --set-mark 1 + [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $ipt_m -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_GFW) -j MARK --set-mark 1 + [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && { + $ipt_m -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j MARK --set-mark 1 + } + else + $ipt_m -A PSW_OUTPUT -p udp $(dst $IPSET_ROUTER) -j RETURN + $ipt_m -A PSW_OUTPUT -p udp $(dst $IPSET_BLACKLIST) -j RETURN + fi } echolog "IPv4 防火墙UDP转发规则加载完成!" fi done - $iptables_mangle -A PSW -j PSW_ACL + $ipt_m -A PSW -j PSW_ACL else echolog "UDP节点未选择,无法转发UDP!" fi @@ -485,86 +506,94 @@ add_firewall_rule() { do local ip=$(echo $balancing_node | awk -F ":" '{print $1}') local port=$(echo $balancing_node | awk -F ":" '{print $2}') - $iptables_nat -I PSW 2 -p tcp -d $ip --dport $port -j RETURN - $iptables_nat -I PSW_OUTPUT 2 -p tcp -d $ip --dport $port -j RETURN - $iptables_mangle -I PSW 2 -p udp -d $ip --dport $port -j RETURN - $iptables_mangle -I PSW_OUTPUT 2 -p udp -d $ip --dport $port -j RETURN + $ipt_n -I PSW 2 -p tcp -d $ip --dport $port -j RETURN + $ipt_n -I PSW_OUTPUT 2 -p tcp -d $ip --dport $port -j RETURN + $ipt_m -I PSW 2 -p udp -d $ip --dport $port -j RETURN + $ipt_m -I PSW_OUTPUT 2 -p udp -d $ip --dport $port -j RETURN done fi - $iptables_mangle -A PREROUTING -j PSW + $ipt_m -A PREROUTING -j PSW # 加载ACLS config_foreach load_acl "acl_rule" # 加载默认代理模式 if [ "$PROXY_MODE" == "disable" ]; then - [ "$TCP_NODE1" != "nil" ] && $iptables_nat -A PSW_ACL -p tcp -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE) - [ "$UDP_NODE1" != "nil" ] && $iptables_mangle -A PSW_ACL -p udp -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE) + [ "$TCP_NODE1" != "nil" ] && $ipt_n -A PSW_ACL -p tcp -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE) + [ "$UDP_NODE1" != "nil" ] && $ipt_m -A PSW_ACL -p udp -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE) else [ "$TCP_NODE1" != "nil" ] && { - $iptables_nat -A PSW_ACL -p tcp $(dst $IPSET_BLACKLIST) -m comment --comment "Default" -j REDIRECT --to-ports $TCP_REDIR_PORT1 - $iptables_nat -A PSW_ACL -p tcp -m multiport --dport $TCP_REDIR_PORTS -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE)1 + if [ "$UDP_REDIR_PORTS" != "disable" ]; then + $ipt_n -A PSW_ACL -p tcp $(dst $IPSET_BLACKLIST) -m comment --comment "Default" -j REDIRECT --to-ports $TCP_REDIR_PORT1 + $ipt_n -A PSW_ACL -p tcp -m multiport --dport $TCP_REDIR_PORTS -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE)1 + else + $ipt_n -A PSW_ACL -p tcp -m comment --comment "$remarks" -j RETURN + fi } [ "$UDP_NODE1" != "nil" ] && { - $iptables_mangle -A PSW_ACL -p udp $(dst $IPSET_BLACKLIST) -m comment --comment "Default" -j TPROXY --on-port $UDP_REDIR_PORT1 --tproxy-mark 0x1/0x1 - $iptables_mangle -A PSW_ACL -p udp -m multiport --dport $UDP_REDIR_PORTS -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE)1 + if [ "$UDP_REDIR_PORTS" != "disable" ]; then + $ipt_m -A PSW_ACL -p udp $(dst $IPSET_BLACKLIST) -m comment --comment "Default" -j TPROXY --on-port $UDP_REDIR_PORT1 --tproxy-mark 0x1/0x1 + $ipt_m -A PSW_ACL -p udp -m multiport --dport $UDP_REDIR_PORTS -m comment --comment "Default" -j $(get_action_chain $PROXY_MODE)1 + else + $ipt_m -A PSW_ACL -p udp -m comment --comment "$remarks" -j RETURN + fi } fi } del_firewall_rule() { echolog "删除所有防火墙规则..." - ipv6_output_ss_exist=$($ip6tables_nat -L OUTPUT 2>/dev/null | grep -c "PSW") + ipv6_output_ss_exist=$($ip6t_n -L OUTPUT 2>/dev/null | grep -c "PSW") [ -n "$ipv6_output_ss_exist" ] && { until [ "$ipv6_output_ss_exist" = 0 ]; do - rules=$($ip6tables_nat -L OUTPUT --line-numbers | grep "PSW" | awk '{print $1}') + rules=$($ip6t_n -L OUTPUT --line-numbers | grep "PSW" | awk '{print $1}') for rule in $rules; do - $ip6tables_nat -D OUTPUT $rule 2>/dev/null + $ip6t_n -D OUTPUT $rule 2>/dev/null break done ipv6_output_ss_exist=$(expr $ipv6_output_ss_exist - 1) done } - $iptables_nat -D PREROUTING -j PSW 2>/dev/null - $iptables_nat -D OUTPUT -j PSW_OUTPUT 2>/dev/null - $iptables_nat -F PSW 2>/dev/null && $iptables_nat -X PSW 2>/dev/null - $iptables_nat -F PSW_ACL 2>/dev/null && $iptables_nat -X PSW_ACL 2>/dev/null - $iptables_nat -F PSW_OUTPUT 2>/dev/null && $iptables_nat -X PSW_OUTPUT 2>/dev/null + $ipt_n -D PREROUTING -j PSW 2>/dev/null + $ipt_n -D OUTPUT -j PSW_OUTPUT 2>/dev/null + $ipt_n -F PSW 2>/dev/null && $ipt_n -X PSW 2>/dev/null + $ipt_n -F PSW_ACL 2>/dev/null && $ipt_n -X PSW_ACL 2>/dev/null + $ipt_n -F PSW_OUTPUT 2>/dev/null && $ipt_n -X PSW_OUTPUT 2>/dev/null - $iptables_mangle -D PREROUTING -j PSW 2>/dev/null - $iptables_mangle -D OUTPUT -j PSW_OUTPUT 2>/dev/null - $iptables_mangle -F PSW 2>/dev/null && $iptables_mangle -X PSW 2>/dev/null - $iptables_mangle -F PSW_ACL 2>/dev/null && $iptables_mangle -X PSW_ACL 2>/dev/null - $iptables_mangle -F PSW_OUTPUT 2>/dev/null && $iptables_mangle -X PSW_OUTPUT 2>/dev/null + $ipt_m -D PREROUTING -j PSW 2>/dev/null + $ipt_m -D OUTPUT -j PSW_OUTPUT 2>/dev/null + $ipt_m -F PSW 2>/dev/null && $ipt_m -X PSW 2>/dev/null + $ipt_m -F PSW_ACL 2>/dev/null && $ipt_m -X PSW_ACL 2>/dev/null + $ipt_m -F PSW_OUTPUT 2>/dev/null && $ipt_m -X PSW_OUTPUT 2>/dev/null - $ip6tables_nat -D PREROUTING -j PSW 2>/dev/null - $ip6tables_nat -D OUTPUT -j PSW_OUTPUT 2>/dev/null - $ip6tables_nat -F PSW 2>/dev/null && $ip6tables_nat -X PSW 2>/dev/null - $ip6tables_nat -F PSW_ACL 2>/dev/null && $ip6tables_nat -X PSW_ACL 2>/dev/null - $ip6tables_nat -F PSW_OUTPUT 2>/dev/null && $ip6tables_nat -X PSW_OUTPUT 2>/dev/null + $ip6t_n -D PREROUTING -j PSW 2>/dev/null + $ip6t_n -D OUTPUT -j PSW_OUTPUT 2>/dev/null + $ip6t_n -F PSW 2>/dev/null && $ip6t_n -X PSW 2>/dev/null + $ip6t_n -F PSW_ACL 2>/dev/null && $ip6t_n -X PSW_ACL 2>/dev/null + $ip6t_n -F PSW_OUTPUT 2>/dev/null && $ip6t_n -X PSW_OUTPUT 2>/dev/null local max_num=5 if [ "$max_num" -ge 1 ]; then for i in $(seq 1 $max_num); do local k=$i - $iptables_nat -F PSW_GLO$k 2>/dev/null && $iptables_nat -X PSW_GLO$k 2>/dev/null - $iptables_nat -F PSW_GFW$k 2>/dev/null && $iptables_nat -X PSW_GFW$k 2>/dev/null - $iptables_nat -F PSW_CHN$k 2>/dev/null && $iptables_nat -X PSW_CHN$k 2>/dev/null - $iptables_nat -F PSW_GAME$k 2>/dev/null && $iptables_nat -X PSW_GAME$k 2>/dev/null - $iptables_nat -F PSW_HOME$k 2>/dev/null && $iptables_nat -X PSW_HOME$k 2>/dev/null + $ipt_n -F PSW_GLO$k 2>/dev/null && $ipt_n -X PSW_GLO$k 2>/dev/null + $ipt_n -F PSW_GFW$k 2>/dev/null && $ipt_n -X PSW_GFW$k 2>/dev/null + $ipt_n -F PSW_CHN$k 2>/dev/null && $ipt_n -X PSW_CHN$k 2>/dev/null + $ipt_n -F PSW_GAME$k 2>/dev/null && $ipt_n -X PSW_GAME$k 2>/dev/null + $ipt_n -F PSW_HOME$k 2>/dev/null && $ipt_n -X PSW_HOME$k 2>/dev/null - $iptables_mangle -F PSW_GLO$k 2>/dev/null && $iptables_mangle -X PSW_GLO$k 2>/dev/null - $iptables_mangle -F PSW_GFW$k 2>/dev/null && $iptables_mangle -X PSW_GFW$k 2>/dev/null - $iptables_mangle -F PSW_CHN$k 2>/dev/null && $iptables_mangle -X PSW_CHN$k 2>/dev/null - $iptables_mangle -F PSW_GAME$k 2>/dev/null && $iptables_mangle -X PSW_GAME$k 2>/dev/null - $iptables_mangle -F PSW_HOME$k 2>/dev/null && $iptables_mangle -X PSW_HOME$k 2>/dev/null + $ipt_m -F PSW_GLO$k 2>/dev/null && $ipt_m -X PSW_GLO$k 2>/dev/null + $ipt_m -F PSW_GFW$k 2>/dev/null && $ipt_m -X PSW_GFW$k 2>/dev/null + $ipt_m -F PSW_CHN$k 2>/dev/null && $ipt_m -X PSW_CHN$k 2>/dev/null + $ipt_m -F PSW_GAME$k 2>/dev/null && $ipt_m -X PSW_GAME$k 2>/dev/null + $ipt_m -F PSW_HOME$k 2>/dev/null && $ipt_m -X PSW_HOME$k 2>/dev/null - $ip6tables_nat -F PSW_GLO$k 2>/dev/null && $ip6tables_nat -X PSW_GLO$k 2>/dev/null - $ip6tables_nat -F PSW_GFW$k 2>/dev/null && $ip6tables_nat -X PSW_GFW$k 2>/dev/null - $ip6tables_nat -F PSW_CHN$k 2>/dev/null && $ip6tables_nat -X PSW_CHN$k 2>/dev/null - $ip6tables_nat -F PSW_HOME$k 2>/dev/null && $ip6tables_nat -X PSW_HOME$k 2>/dev/null + $ip6t_n -F PSW_GLO$k 2>/dev/null && $ip6t_n -X PSW_GLO$k 2>/dev/null + $ip6t_n -F PSW_GFW$k 2>/dev/null && $ip6t_n -X PSW_GFW$k 2>/dev/null + $ip6t_n -F PSW_CHN$k 2>/dev/null && $ip6t_n -X PSW_CHN$k 2>/dev/null + $ip6t_n -F PSW_HOME$k 2>/dev/null && $ip6t_n -X PSW_HOME$k 2>/dev/null ip_rule_exist=$(ip rule show | grep "from all fwmark 0x1 lookup 100" | grep -c 100) if [ ! -z "$ip_rule_exist" ]; then diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh index 588b5720ca..0d2288ae48 100755 --- a/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh @@ -166,8 +166,8 @@ get_remote_config(){ node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '#' '{print $1}' | awk -F ':' '{print $2}') fi + [ -n "$plugin" -a "$plugin" == "simple-obfs" ] && plugin=obfs-local remarks=$(urldecode $(echo "$decode_link" | awk -F '#' '{print $2}')) - [ "$plugin" == "simple-obfs" -o "$plugin" == "obfs-local" ] && echo "$Date: 不支持simple-obfs插件,订阅节点:$remarks:$node_address失败!" >> $LOG_FILE && return elif [ "$1" == "ssr" ]; then decode_link=$(decode_url_link $2 1) node_address=$(echo "$decode_link" | awk -F ':' '{print $1}') @@ -238,7 +238,7 @@ get_remote_config(){ plugin=$json_plugin plugin_options=$json_plugin_options - [ -n "$plugin" -a "$plugin" == "simple-obfs" ] && echo "$Date: 不支持simple-obfs插件,导入失败!" >> $LOG_FILE && return + [ -n "$plugin" -a "$plugin" == "simple-obfs" ] && plugin=obfs-local if json_get_type Type servers && [ "$Type" == array ] then @@ -325,7 +325,7 @@ add_nodes(){ ${uci_set}timeout=300 ${uci_set}tcp_fast_open=false [ -n "$plugin" ] && ${uci_set}ss_plugin="$plugin" - [ -n "$plugin_options" ] && ${uci_set}ss_plugin_v2ray_opts="$plugin_options" + [ -n "$plugin_options" ] && ${uci_set}ss_plugin_opts="$plugin_options" if [ "$1" == "add" ]; then let addnum_ss+=1