diff --git a/package/lienol/luci-app-passwall/Makefile b/package/lienol/luci-app-passwall/Makefile
index a3c685d7de..c68d1f9979 100644
--- a/package/lienol/luci-app-passwall/Makefile
+++ b/package/lienol/luci-app-passwall/Makefile
@@ -7,7 +7,7 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=luci-app-passwall
PKG_VERSION:=3.3
-PKG_RELEASE:=39-20200130
+PKG_RELEASE:=41-20200209
PKG_BUILD_DIR := $(BUILD_DIR)/$(PKG_NAME)-$(PKG_VERSION)
diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua
index c9d988a6ea..4bc990671f 100644
--- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua
+++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua
@@ -100,8 +100,9 @@ end
---- China DNS Server
o = s:option(Value, "up_china_dns", translate("China DNS Server") .. "(UDP)",
translate(
- "Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as smartdns,AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash!"))
-o.default = "223.5.5.5"
+ "If you want to work with other DNS acceleration services, use the default.
Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as SmartDNS, AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash !"))
+o.default = "default"
+o:value("default", translate("default"))
o:value("dnsbyisp", translate("dnsbyisp"))
o:value("223.5.5.5", "223.5.5.5 (" .. translate("Ali") .. "DNS)")
o:value("223.6.6.6", "223.6.6.6 (" .. translate("Ali") .. "DNS)")
@@ -133,7 +134,7 @@ o:value("nonuse", translate("No patterns are used"))
o = s:option(Value, "up_trust_chinadns_ng_dns",
translate("Upstream trust DNS Server for ChinaDNS-NG") .. "(UDP)",
translate(
- "Example: 127.0.0.1#5353 ,such as dns2socks,dns-forwarder...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53."))
+ "You can use other resolving DNS services as trusted DNS, Example: dns2socks, dns-forwarder... 127.0.0.1#5353
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53."))
o.default = "pdnsd"
if is_installed("pdnsd") or is_installed("pdnsd-alt") or is_finded("pdnsd") then
o:value("pdnsd", "pdnsd + " .. translate("Use TCP Node Resolve DNS"))
diff --git a/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po b/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po
index f61c1ac28d..f27c623476 100644
--- a/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po
+++ b/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po
@@ -157,14 +157,14 @@ msgstr "DNS地址"
msgid "China DNS Server"
msgstr "国内DNS服务器"
-msgid "Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as smartdns,AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash!"
-msgstr "例:127.0.0.1#6053 使用本机的6053端口的DNS服务。例:smartdns,AdGuardHome等等。
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。
如果你使用自定义,除非你知道你在做什么,否则设置不当会直接导致卡到崩溃!"
+msgid "If you want to work with other DNS acceleration services, use the default.
Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as SmartDNS, AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash !"
+msgstr "如果你想和其他DNS加速服务一起工作,请使用默认。
例:127.0.0.1#6053 使用本机的6053端口的DNS服务。例:SmartDNS,AdGuardHome等等。
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。
如果你使用自定义,除非你知道你在做什么,否则设置不当会直接导致卡到崩溃!"
msgid "Upstream trust DNS Server for ChinaDNS-NG"
msgstr "ChinaDNS-NG可信DNS"
-msgid "Example: 127.0.0.1#5353 ,such as dns2socks,dns-forwarder...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53."
-msgstr "例:127.0.0.1#5353 例:dns2socks,dns-forwarder等等。
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。"
+msgid "You can use other resolving DNS services as trusted DNS, Example: dns2socks, dns-forwarder... 127.0.0.1#5353
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53."
+msgstr "你可以使用其他解决污染DNS服务作为可信DNS,例:dns2socks,dns-forwarder等等。127.0.0.1#5353
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。"
msgid "The server client can also use this rule to scientifically surf the Internet.
Global and continental whitelist are not recommended for non-special cases!"
msgstr "本机服务器的客户端也可以使用这个代理模式上网。
非特殊情况不推荐使用全局和大陆白名单!"
diff --git a/package/lienol/luci-app-passwall/root/etc/config/passwall b/package/lienol/luci-app-passwall/root/etc/config/passwall
index c13c264acd..f01b8e4a81 100644
--- a/package/lienol/luci-app-passwall/root/etc/config/passwall
+++ b/package/lienol/luci-app-passwall/root/etc/config/passwall
@@ -5,10 +5,10 @@ config global
option udp_node1 'nil'
option socks5_node1 'nil'
option dns_mode 'pdnsd'
- option up_china_dns '114.114.114.114'
+ option up_china_dns 'default'
option dns_forward '8.8.4.4'
option use_tcp_node_resolve_dns '1'
- option dns_53 '1'
+ option dns_53 '0'
option proxy_mode 'chnroute'
option localhost_proxy_mode 'gfwlist'
diff --git a/package/lienol/luci-app-passwall/root/etc/config/passwall_rule/user.conf b/package/lienol/luci-app-passwall/root/etc/config/passwall_rule/user.conf
deleted file mode 100644
index e69de29bb2..0000000000
diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh
index f21ac8dbc5..ae26d33941 100755
--- a/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh
+++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh
@@ -178,7 +178,7 @@ BROOK_UDP_CMD=""
TCP_REDIR_PORTS=$(config_t_get global_forwarding tcp_redir_ports '80,443')
UDP_REDIR_PORTS=$(config_t_get global_forwarding udp_redir_ports '1:65535')
KCPTUN_REDIR_PORT=$(config_t_get global_forwarding kcptun_port 12948)
-PROXY_MODE=$(config_t_get global proxy_mode gfwlist)
+PROXY_MODE=$(config_t_get global proxy_mode chnroute)
load_config() {
[ "$ENABLED" != 1 ] && {
@@ -199,14 +199,15 @@ load_config() {
process=$(config_t_get global_forwarding process)
fi
LOCALHOST_PROXY_MODE=$(config_t_get global localhost_proxy_mode default)
- UP_CHINA_DNS=$(config_t_get global up_china_dns 223.5.5.5,114.114.114.114)
- [ ! -f "$RESOLVFILE" ] && RESOLVFILE=/tmp/resolv.conf.auto
- [ "$UP_CHINA_DNS" == "dnsbyisp" ] && {
+ UP_CHINA_DNS=$(config_t_get global up_china_dns dnsbyisp)
+ [ "$UP_CHINA_DNS" == "default" ] && IS_DEFAULT_CHINA_DNS=1
+ [ ! -f "$RESOLVFILE" -o ! -s "$RESOLVFILE" ] && RESOLVFILE=/tmp/resolv.conf.auto
+ [ "$UP_CHINA_DNS" == "dnsbyisp" -o "$UP_CHINA_DNS" == "default" ] && {
local dns1=$(cat $RESOLVFILE 2>/dev/null | grep -E -o "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+" | grep -v 0.0.0.0 | grep -v 127.0.0.1 | sed -n '1P')
if [ -n "$dns1" ]; then
UP_CHINA_DNS=$dns1
else
- UP_CHINA_DNS="223.5.5.5,114.114.114.114"
+ UP_CHINA_DNS="223.5.5.5"
fi
local dns2=$(cat $RESOLVFILE 2>/dev/null | grep -E -o "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+" | grep -v 0.0.0.0 | grep -v 127.0.0.1 | sed -n '2P')
[ -n "$dns1" -a -n "$dns2" ] && UP_CHINA_DNS="$dns1,$dns2"
@@ -281,7 +282,7 @@ gen_start_config() {
network_type="ipv4"
[ "$use_ipv6" == "1" ] && network_type="ipv6"
server_ip=$(get_host_ip $network_type $server_host)
- echolog "$redir_type节点:$remarks,节点地址端口:${server_ip}:${port}"
+ echolog "$redir_type节点:$remarks,节点:${server_ip}:${port},监听端口:$local_port"
}
if [ "$redir_type" == "SOCKS5" ]; then
@@ -702,10 +703,10 @@ stop_crontab() {
start_dns() {
case "$DNS_MODE" in
nonuse)
- echolog "不使用任何DNS转发模式,将会直接将WAN口DNS给dnsmasq上游!"
+ echolog "DNS:不使用,将会直接使用上级DNS!"
;;
local_7913)
- echolog "运行DNS转发模式:使用本机7913端口DNS服务器解析域名..."
+ echolog "DNS:使用本机7913端口DNS服务器解析域名..."
;;
dns2socks)
if [ -n "$SOCKS5_NODE1" -a "$SOCKS5_NODE1" != "nil" ]; then
@@ -713,10 +714,10 @@ start_dns() {
[ -n "$dns2socks_bin" ] && {
DNS2SOCKS_FORWARD=$(config_t_get global dns2socks_forward 8.8.4.4)
nohup $dns2socks_bin 127.0.0.1:$SOCKS5_PROXY_PORT1 $DNS2SOCKS_FORWARD 127.0.0.1:$DNS_PORT >/dev/null 2>&1 &
- echolog "运行DNS转发模式:dns2socks..."
+ echolog "DNS:dns2socks..."
}
else
- echolog "dns2socks模式需要使用Socks5代理节点,请开启!"
+ echolog "DNS:dns2socks模式需要使用Socks5代理节点,请开启!"
force_stop
fi
;;
@@ -727,7 +728,7 @@ start_dns() {
gen_pdnsd_config $DNS_PORT "cache"
DNS_FORWARD=$(echo $DNS_FORWARD | sed 's/,/ /g')
nohup $pdnsd_bin --daemon -c $pdnsd_dir/pdnsd.conf -d >/dev/null 2>&1 &
- echolog "运行DNS转发模式:pdnsd..."
+ echolog "DNS:pdnsd..."
}
;;
chinadns-ng)
@@ -741,7 +742,7 @@ start_dns() {
up_trust_chinadns_ng_dns=$(config_t_get global up_trust_chinadns_ng_dns "pdnsd")
if [ "$up_trust_chinadns_ng_dns" == "pdnsd" ]; then
if [ -z "$TCP_NODE1" -o "$TCP_NODE1" == "nil" ]; then
- echolog "ChinaDNS-NG + pdnsd 模式需要启用TCP节点!"
+ echolog "DNS:ChinaDNS-NG + pdnsd 模式需要启用TCP节点!"
force_stop
else
use_tcp_node_resolve_dns=1
@@ -751,7 +752,7 @@ start_dns() {
DNS_FORWARD=$(echo $DNS_FORWARD | sed 's/,/ /g')
nohup $pdnsd_bin --daemon -c $pdnsd_dir/pdnsd.conf -d >/dev/null 2>&1 &
nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t 127.0.0.1#$other_port $gfwlist_param $chnlist_param >/dev/null 2>&1 &
- echolog "运行DNS转发模式:ChinaDNS-NG + pdnsd($DNS_FORWARD),国内DNS:$UP_CHINA_DNS"
+ echolog "DNS:ChinaDNS-NG + pdnsd($DNS_FORWARD),国内DNS:$UP_CHINA_DNS"
}
fi
elif [ "$up_trust_chinadns_ng_dns" == "dns2socks" ]; then
@@ -761,22 +762,17 @@ start_dns() {
DNS2SOCKS_FORWARD=$(config_t_get global dns2socks_forward 8.8.4.4)
nohup $dns2socks_bin 127.0.0.1:$SOCKS5_PROXY_PORT1 $DNS2SOCKS_FORWARD 127.0.0.1:$other_port >/dev/null 2>&1 &
nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t 127.0.0.1#$other_port $gfwlist_param $chnlist_param >/dev/null 2>&1 &
- echolog "运行DNS转发模式:ChinaDNS-NG + dns2socks($DNS2SOCKS_FORWARD),国内DNS:$UP_CHINA_DNS"
+ echolog "DNS:ChinaDNS-NG + dns2socks($DNS2SOCKS_FORWARD),国内DNS:$UP_CHINA_DNS"
}
else
- echolog "dns2socks模式需要使用Socks5代理节点,请开启!"
+ echolog "DNS:dns2socks模式需要使用Socks5代理节点,请开启!"
force_stop
fi
else
- if [ -z "$UDP_NODE1" -o "$UDP_NODE1" == "nil" ]; then
- nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t 208.67.222.222#443,208.67.222.222#5353 $gfwlist_param $chnlist_param >/dev/null 2>&1 &
- echolog "运行DNS转发模式:ChinaDNS-NG,国内DNS:$UP_CHINA_DNS,因为你没有使用UDP节点,将使用OpenDNS 443端口或5353端口作为可信DNS。"
- else
- use_udp_node_resolve_dns=1
- DNS_FORWARD=$(echo $up_trust_chinadns_ng_dns | sed 's/,/ /g')
- nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t $up_trust_chinadns_ng_dns $gfwlist_param $chnlist_param >/dev/null 2>&1 &
- echolog "运行DNS转发模式:ChinaDNS-NG,国内DNS:$UP_CHINA_DNS,可信DNS:$up_trust_chinadns_ng_dns"
- fi
+ use_udp_node_resolve_dns=1
+ DNS_FORWARD=$(echo $up_trust_chinadns_ng_dns | sed 's/,/ /g')
+ nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t $up_trust_chinadns_ng_dns $gfwlist_param $chnlist_param >/dev/null 2>&1 &
+ echolog "DNS:ChinaDNS-NG,国内DNS:$UP_CHINA_DNS,可信DNS:$up_trust_chinadns_ng_dns,如果不能使用,请确保UDP节点已打开并且支持UDP转发。"
fi
}
;;
@@ -815,35 +811,28 @@ add_dnsmasq() {
cat $RULE_PATH/router | awk '{print "server=/."$1"/127.0.0.1#'$DNS_PORT'\nipset=/."$1"/router"}' >>$TMP_DNSMASQ_PATH/router.conf
fi
- userconf=$(grep -c "" $RULE_PATH/user.conf)
- if [ "$userconf" -gt 0 ]; then
- ln -s $RULE_PATH/user.conf $TMP_DNSMASQ_PATH/user.conf
- fi
-
- backhome=$(config_t_get global proxy_mode gfwlist)
- if [ "$backhome" == "returnhome" ]; then
- rm -rf $TMP_DNSMASQ_PATH/gfwlist.conf
- rm -rf $TMP_DNSMASQ_PATH/blacklist_host.conf
- rm -rf $TMP_DNSMASQ_PATH/whitelist_host.conf
- fi
-
- server="server=127.0.0.1#$DNS_PORT"
- [ "$DNS_MODE" != "chinadns-ng" ] && {
- local china_dns1=$(echo $UP_CHINA_DNS | awk -F "," '{print $1}')
- local china_dns2=$(echo $UP_CHINA_DNS | awk -F "," '{print $2}')
- [ -n "$china_dns1" ] && server="server=$china_dns1"
- [ -n "$china_dns2" ] && server="${server}\n${server_2}"
- server="${server}\nno-resolv"
- }
- cat <<-EOF > /var/dnsmasq.d/dnsmasq-$CONFIG.conf
+ if [ -z "$IS_DEFAULT_CHINA_DNS" -o "$IS_DEFAULT_CHINA_DNS" == 0 ]; then
+ server="server=127.0.0.1#$DNS_PORT"
+ [ "$DNS_MODE" != "chinadns-ng" ] && {
+ local china_dns1=$(echo $UP_CHINA_DNS | awk -F "," '{print $1}')
+ local china_dns2=$(echo $UP_CHINA_DNS | awk -F "," '{print $2}')
+ [ -n "$china_dns1" ] && server="server=$china_dns1"
+ [ -n "$china_dns2" ] && server="${server}\n${server_2}"
+ server="${server}\nno-resolv"
+ }
+ cat <<-EOF > /var/dnsmasq.d/dnsmasq-$CONFIG.conf
$(echo -e $server)
all-servers
no-poll
- conf-dir=$TMP_DNSMASQ_PATH
+ EOF
+ fi
+
+ cat <<-EOF >> /var/dnsmasq.d/dnsmasq-$CONFIG.conf
+ conf-dir=$TMP_DNSMASQ_PATH
EOF
cp -rf /var/dnsmasq.d/dnsmasq-$CONFIG.conf $DNSMASQ_PATH/dnsmasq-$CONFIG.conf
- echolog "dnsmasq:生成配置文件并重启服务。"
/etc/init.d/dnsmasq restart >/dev/null 2>&1 &
+ echolog "dnsmasq:生成配置文件并重启服务。"
}
gen_redsocks_config() {
@@ -914,7 +903,6 @@ gen_redsocks_config() {
gen_pdnsd_config() {
pdnsd_dir=$CONFIG_PATH/pdnsd
mkdir -p $pdnsd_dir
- touch $pdnsd_dir/pdnsd.cache
chown -R root.nogroup $pdnsd_dir
[ "$2" == "cache" ] && cache_param="perm_cache = 1024;\ncache_dir = \"$pdnsd_dir\";"
cat > $pdnsd_dir/pdnsd.conf <<-EOF
diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh
index e763dfba31..c7e80d53d5 100755
--- a/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh
+++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh
@@ -344,35 +344,22 @@ add_firewall_rule() {
$iptables_nat -I PSW 2 -p tcp -d $dns_ip --dport $dns_port -j REDIRECT --to-ports $local_port
done
}
-
- is_add_prerouting=0
-
- KP_INDEX=$($iptables_nat -L PREROUTING | tail -n +3 | sed -n -e '/^KOOLPROXY/=')
- if [ -n "$KP_INDEX" ]; then
- let KP_INDEX+=1
- #确保添加到KOOLPROXY规则之后
- $iptables_nat -I PREROUTING $KP_INDEX -j PSW
- is_add_prerouting=1
- fi
-
- ADBYBY_INDEX=$($iptables_nat -L PREROUTING | tail -n +3 | sed -n -e '/^ADBYBY/=')
- if [ -n "$ADBYBY_INDEX" ]; then
- let ADBYBY_INDEX+=1
- #确保添加到ADBYBY规则之后
- $iptables_nat -I PREROUTING $ADBYBY_INDEX -j PSW
- is_add_prerouting=1
- fi
-
- if [ "$is_add_prerouting" == 0 ]; then
- #如果去广告没有运行,确保添加到prerouting_rule规则之后
- PR_INDEX=$($iptables_nat -L PREROUTING | tail -n +3 | sed -n -e '/^prerouting_rule/=')
- if [ -z "$PR_INDEX" ]; then
- PR_INDEX=1
- else
- let PR_INDEX+=1
- fi
- $iptables_nat -I PREROUTING $PR_INDEX -j PSW
+
+ PRE_INDEX=1
+ KP_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "KOOLPROXY" | sed -n '$p' | awk '{print $1}')
+ ADBYBY_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "ADBYBY" | sed -n '$p' | awk '{print $1}')
+ if [ -n "$KP_INDEX" -a -z "$ADBYBY_INDEX" ]; then
+ PRE_INDEX=$(expr $KP_INDEX + 1)
+ elif [ -z "$KP_INDEX" -a -n "$ADBYBY_INDEX" ]; then
+ PRE_INDEX=$(expr $ADBYBY_INDEX + 1)
+ elif [ -z "$KP_INDEX" -a -z "$ADBYBY_INDEX" ]; then
+ PR_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "prerouting_rule" | sed -n '$p' | awk '{print $1}')
+ [ -n "$PR_INDEX" ] && {
+ PRE_INDEX=$(expr $PR_INDEX + 1)
+ }
fi
+ $iptables_nat -I PREROUTING $PRE_INDEX -j PSW
+
# 用于本机流量转发
$iptables_nat -A OUTPUT -j PSW_OUTPUT
$iptables_nat -A PSW_OUTPUT $(dst $IPSET_LANIPLIST) -j RETURN
@@ -458,28 +445,30 @@ add_firewall_rule() {
$iptables_mangle -A PSW_GAME$k -p udp $(dst $IPSET_CHN) -j RETURN
$iptables_mangle -A PSW_GAME$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port
- # 用于本机流量转发
- $iptables_mangle -A OUTPUT -j PSW_OUTPUT
- $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_LANIPLIST) -j RETURN
- [ "$use_udp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && {
- for dns in $DNS_FORWARD
- do
- local dns_ip=$(echo $dns | awk -F "#" '{print $1}')
- local dns_port=$(echo $dns | awk -F "#" '{print $2}')
- [ -z "$dns_port" ] && dns_port=53
- $iptables_mangle -A PSW_OUTPUT -p udp -d $dns_ip --dport $dns_port -j MARK --set-mark 1
- $iptables_mangle -I PSW 2 -p udp -d $dns_ip --dport $dns_port -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port
- done
- }
- $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_VPSIPLIST) -j RETURN
- $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_WHITELIST) -j RETURN
- $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1
- $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j MARK --set-mark 1
+ [ "$k" == 1 ] && {
+ # 用于本机流量转发
+ $iptables_mangle -A OUTPUT -j PSW_OUTPUT
+ $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_LANIPLIST) -j RETURN
+ [ "$use_udp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && {
+ for dns in $DNS_FORWARD
+ do
+ local dns_ip=$(echo $dns | awk -F "#" '{print $1}')
+ local dns_port=$(echo $dns | awk -F "#" '{print $2}')
+ [ -z "$dns_port" ] && dns_port=53
+ $iptables_mangle -A PSW_OUTPUT -p udp -d $dns_ip --dport $dns_port -j MARK --set-mark 1
+ $iptables_mangle -I PSW 2 -p udp -d $dns_ip --dport $dns_port -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port
+ done
+ }
+ $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_VPSIPLIST) -j RETURN
+ $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_WHITELIST) -j RETURN
+ $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1
+ $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j MARK --set-mark 1
- [ "$LOCALHOST_PROXY_MODE" == "global" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -j MARK --set-mark 1
- [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_GFW) -j MARK --set-mark 1
- [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && {
- $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j MARK --set-mark 1
+ [ "$LOCALHOST_PROXY_MODE" == "global" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -j MARK --set-mark 1
+ [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_GFW) -j MARK --set-mark 1
+ [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && {
+ $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j MARK --set-mark 1
+ }
}
echolog "IPv4 防火墙UDP转发规则加载完成!"
diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh
index 2f570c6686..588b5720ca 100755
--- a/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh
+++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh
@@ -155,8 +155,19 @@ get_remote_config(){
ss_encrypt_method=$(echo "$decode_link" | awk -F ':' '{print $1}')
password=$(echo "$decode_link" | awk -F ':' '{print $2}' | awk -F '@' '{print $1}')
node_address=$(echo "$decode_link" | awk -F ':' '{print $2}' | awk -F '@' '{print $2}')
- node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '#' '{print $1}' | awk -F ':' '{print $2}')
+
+ plugin_tmp=$(echo "$decode_link" | awk -F '\\/\\?' '{print $2}' | awk -F '#' '{print $1}')
+ if [ "$plugin_tmp" != "" ]; then
+ plugin_tmp=$(urldecode $plugin_tmp)
+ plugin=$(echo "$plugin_tmp" | awk -F 'plugin=' '{print $2}' | awk -F ';' '{print $1}')
+ plugin_options=$(echo "$plugin_tmp" | awk -F "$plugin;" '{print $2}' | awk -F '&' '{print $1}')
+ node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '\\/\\?' '{print $1}' | awk -F ':' '{print $2}')
+ else
+ node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '#' '{print $1}' | awk -F ':' '{print $2}')
+ fi
+
remarks=$(urldecode $(echo "$decode_link" | awk -F '#' '{print $2}'))
+ [ "$plugin" == "simple-obfs" -o "$plugin" == "obfs-local" ] && echo "$Date: 不支持simple-obfs插件,订阅节点:$remarks:$node_address失败!" >> $LOG_FILE && return
elif [ "$1" == "ssr" ]; then
decode_link=$(decode_url_link $2 1)
node_address=$(echo "$decode_link" | awk -F ':' '{print $1}')
@@ -253,6 +264,11 @@ get_remote_config(){
[ -z "$node_address" -o "$node_address" == "" ] && return
[ -z "$remarks" -o "$remarks" == "" ] && remarks="${node_address}:${node_port}"
+ tmp=$(echo $remarks | grep -E "过期时间|剩余流量|QQ群|官网")
+ [ -n "$tmp" ] && {
+ echo "$Date: 丢弃无用节点:$tmp" >> $LOG_FILE
+ return
+ }
# 把全部节点节点写入文件 /usr/share/${CONFIG}/sub/all_onlinenodes
if [ ! -f "/usr/share/${CONFIG}/sub/all_onlinenodes" ]; then
@@ -265,7 +281,6 @@ get_remote_config(){
done
return
fi
-
fi
node_address=$(echo -n $node_address | awk '{print gensub(/[^!-~]/,"","g",$0)}')
@@ -273,6 +288,11 @@ get_remote_config(){
[ -z "$node_address" -o "$node_address" == "" ] && return
[ -z "$remarks" -o "$remarks" == "" ] && remarks="${node_address}:${node_port}"
+ tmp=$(echo $remarks | grep -E "过期时间|剩余流量|QQ群|官网")
+ [ -n "$tmp" ] && {
+ echo "$Date: 丢弃无用节点:$tmp" >> $LOG_FILE
+ return
+ }
# 把全部节点节点写入文件 /usr/share/${CONFIG}/sub/all_onlinenodes
if [ ! -f "/usr/share/${CONFIG}/sub/all_onlinenodes" ]; then
@@ -355,6 +375,7 @@ add_nodes(){
${uci_set}v2ray_ws_path="$json_path"
${uci_set}v2ray_h2_host="$json_host"
${uci_set}v2ray_h2_path="$json_path"
+ ${uci_set}tls_allowInsecure=1
if [ "$1" == "add" ]; then
let addnum_v2ray+=1
@@ -574,4 +595,3 @@ add)
start
;;
esac
-