From 6aacc89b348e75b1bccfd85ab642071bc9829a55 Mon Sep 17 00:00:00 2001 From: CN_SZTL Date: Mon, 10 Feb 2020 14:34:00 +0800 Subject: [PATCH] passwall : Add ss plugin for subscription (Lienol#217) --- package/lienol/luci-app-passwall/Makefile | 2 +- .../luasrc/model/cbi/passwall/global.lua | 7 +- .../luci-app-passwall/po/zh_Hans/passwall.po | 8 +- .../root/etc/config/passwall | 4 +- .../root/etc/config/passwall_rule/user.conf | 0 .../root/usr/share/passwall/app.sh | 84 ++++++++---------- .../root/usr/share/passwall/iptables.sh | 87 ++++++++----------- .../root/usr/share/passwall/subscription.sh | 26 +++++- 8 files changed, 108 insertions(+), 110 deletions(-) delete mode 100644 package/lienol/luci-app-passwall/root/etc/config/passwall_rule/user.conf diff --git a/package/lienol/luci-app-passwall/Makefile b/package/lienol/luci-app-passwall/Makefile index a3c685d7de..c68d1f9979 100644 --- a/package/lienol/luci-app-passwall/Makefile +++ b/package/lienol/luci-app-passwall/Makefile @@ -7,7 +7,7 @@ include $(TOPDIR)/rules.mk PKG_NAME:=luci-app-passwall PKG_VERSION:=3.3 -PKG_RELEASE:=39-20200130 +PKG_RELEASE:=41-20200209 PKG_BUILD_DIR := $(BUILD_DIR)/$(PKG_NAME)-$(PKG_VERSION) diff --git a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua index c9d988a6ea..4bc990671f 100644 --- a/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua +++ b/package/lienol/luci-app-passwall/luasrc/model/cbi/passwall/global.lua @@ -100,8 +100,9 @@ end ---- China DNS Server o = s:option(Value, "up_china_dns", translate("China DNS Server") .. "(UDP)", translate( - "Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as smartdns,AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash!")) -o.default = "223.5.5.5" + "If you want to work with other DNS acceleration services, use the default.
Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as SmartDNS, AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash !")) +o.default = "default" +o:value("default", translate("default")) o:value("dnsbyisp", translate("dnsbyisp")) o:value("223.5.5.5", "223.5.5.5 (" .. translate("Ali") .. "DNS)") o:value("223.6.6.6", "223.6.6.6 (" .. translate("Ali") .. "DNS)") @@ -133,7 +134,7 @@ o:value("nonuse", translate("No patterns are used")) o = s:option(Value, "up_trust_chinadns_ng_dns", translate("Upstream trust DNS Server for ChinaDNS-NG") .. "(UDP)", translate( - "Example: 127.0.0.1#5353 ,such as dns2socks,dns-forwarder...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.")) + "You can use other resolving DNS services as trusted DNS, Example: dns2socks, dns-forwarder... 127.0.0.1#5353
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.")) o.default = "pdnsd" if is_installed("pdnsd") or is_installed("pdnsd-alt") or is_finded("pdnsd") then o:value("pdnsd", "pdnsd + " .. translate("Use TCP Node Resolve DNS")) diff --git a/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po b/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po index f61c1ac28d..f27c623476 100644 --- a/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po +++ b/package/lienol/luci-app-passwall/po/zh_Hans/passwall.po @@ -157,14 +157,14 @@ msgstr "DNS地址" msgid "China DNS Server" msgstr "国内DNS服务器" -msgid "Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as smartdns,AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash!" -msgstr "例:127.0.0.1#6053 使用本机的6053端口的DNS服务。例:smartdns,AdGuardHome等等。
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。
如果你使用自定义,除非你知道你在做什么,否则设置不当会直接导致卡到崩溃!" +msgid "If you want to work with other DNS acceleration services, use the default.
Example: 127.0.0.1#6053 ,Represents DNS on using 127.0.0.1 the 6053 port. such as SmartDNS, AdGuard Home...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53.
If you use custom, unless you know what you're doing, setting it up incorrectly can cause your stuck to crash !" +msgstr "如果你想和其他DNS加速服务一起工作,请使用默认。
例:127.0.0.1#6053 使用本机的6053端口的DNS服务。例:SmartDNS,AdGuardHome等等。
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。
如果你使用自定义,除非你知道你在做什么,否则设置不当会直接导致卡到崩溃!" msgid "Upstream trust DNS Server for ChinaDNS-NG" msgstr "ChinaDNS-NG可信DNS" -msgid "Example: 127.0.0.1#5353 ,such as dns2socks,dns-forwarder...
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53." -msgstr "例:127.0.0.1#5353 例:dns2socks,dns-forwarder等等。
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。" +msgid "You can use other resolving DNS services as trusted DNS, Example: dns2socks, dns-forwarder... 127.0.0.1#5353
Only use two at most, english comma separation, If you do not fill in the # and the following port, you are using port 53." +msgstr "你可以使用其他解决污染DNS服务作为可信DNS,例:dns2socks,dns-forwarder等等。127.0.0.1#5353
最多使用2个DNS服务器,英文逗号分隔,如果没有填#和后面的端口,则使用53端口。" msgid "The server client can also use this rule to scientifically surf the Internet.
Global and continental whitelist are not recommended for non-special cases!" msgstr "本机服务器的客户端也可以使用这个代理模式上网。
非特殊情况不推荐使用全局和大陆白名单!" diff --git a/package/lienol/luci-app-passwall/root/etc/config/passwall b/package/lienol/luci-app-passwall/root/etc/config/passwall index c13c264acd..f01b8e4a81 100644 --- a/package/lienol/luci-app-passwall/root/etc/config/passwall +++ b/package/lienol/luci-app-passwall/root/etc/config/passwall @@ -5,10 +5,10 @@ config global option udp_node1 'nil' option socks5_node1 'nil' option dns_mode 'pdnsd' - option up_china_dns '114.114.114.114' + option up_china_dns 'default' option dns_forward '8.8.4.4' option use_tcp_node_resolve_dns '1' - option dns_53 '1' + option dns_53 '0' option proxy_mode 'chnroute' option localhost_proxy_mode 'gfwlist' diff --git a/package/lienol/luci-app-passwall/root/etc/config/passwall_rule/user.conf b/package/lienol/luci-app-passwall/root/etc/config/passwall_rule/user.conf deleted file mode 100644 index e69de29bb2..0000000000 diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh index f21ac8dbc5..ae26d33941 100755 --- a/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/app.sh @@ -178,7 +178,7 @@ BROOK_UDP_CMD="" TCP_REDIR_PORTS=$(config_t_get global_forwarding tcp_redir_ports '80,443') UDP_REDIR_PORTS=$(config_t_get global_forwarding udp_redir_ports '1:65535') KCPTUN_REDIR_PORT=$(config_t_get global_forwarding kcptun_port 12948) -PROXY_MODE=$(config_t_get global proxy_mode gfwlist) +PROXY_MODE=$(config_t_get global proxy_mode chnroute) load_config() { [ "$ENABLED" != 1 ] && { @@ -199,14 +199,15 @@ load_config() { process=$(config_t_get global_forwarding process) fi LOCALHOST_PROXY_MODE=$(config_t_get global localhost_proxy_mode default) - UP_CHINA_DNS=$(config_t_get global up_china_dns 223.5.5.5,114.114.114.114) - [ ! -f "$RESOLVFILE" ] && RESOLVFILE=/tmp/resolv.conf.auto - [ "$UP_CHINA_DNS" == "dnsbyisp" ] && { + UP_CHINA_DNS=$(config_t_get global up_china_dns dnsbyisp) + [ "$UP_CHINA_DNS" == "default" ] && IS_DEFAULT_CHINA_DNS=1 + [ ! -f "$RESOLVFILE" -o ! -s "$RESOLVFILE" ] && RESOLVFILE=/tmp/resolv.conf.auto + [ "$UP_CHINA_DNS" == "dnsbyisp" -o "$UP_CHINA_DNS" == "default" ] && { local dns1=$(cat $RESOLVFILE 2>/dev/null | grep -E -o "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+" | grep -v 0.0.0.0 | grep -v 127.0.0.1 | sed -n '1P') if [ -n "$dns1" ]; then UP_CHINA_DNS=$dns1 else - UP_CHINA_DNS="223.5.5.5,114.114.114.114" + UP_CHINA_DNS="223.5.5.5" fi local dns2=$(cat $RESOLVFILE 2>/dev/null | grep -E -o "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+" | grep -v 0.0.0.0 | grep -v 127.0.0.1 | sed -n '2P') [ -n "$dns1" -a -n "$dns2" ] && UP_CHINA_DNS="$dns1,$dns2" @@ -281,7 +282,7 @@ gen_start_config() { network_type="ipv4" [ "$use_ipv6" == "1" ] && network_type="ipv6" server_ip=$(get_host_ip $network_type $server_host) - echolog "$redir_type节点:$remarks,节点地址端口:${server_ip}:${port}" + echolog "$redir_type节点:$remarks,节点:${server_ip}:${port},监听端口:$local_port" } if [ "$redir_type" == "SOCKS5" ]; then @@ -702,10 +703,10 @@ stop_crontab() { start_dns() { case "$DNS_MODE" in nonuse) - echolog "不使用任何DNS转发模式,将会直接将WAN口DNS给dnsmasq上游!" + echolog "DNS:不使用,将会直接使用上级DNS!" ;; local_7913) - echolog "运行DNS转发模式:使用本机7913端口DNS服务器解析域名..." + echolog "DNS:使用本机7913端口DNS服务器解析域名..." ;; dns2socks) if [ -n "$SOCKS5_NODE1" -a "$SOCKS5_NODE1" != "nil" ]; then @@ -713,10 +714,10 @@ start_dns() { [ -n "$dns2socks_bin" ] && { DNS2SOCKS_FORWARD=$(config_t_get global dns2socks_forward 8.8.4.4) nohup $dns2socks_bin 127.0.0.1:$SOCKS5_PROXY_PORT1 $DNS2SOCKS_FORWARD 127.0.0.1:$DNS_PORT >/dev/null 2>&1 & - echolog "运行DNS转发模式:dns2socks..." + echolog "DNS:dns2socks..." } else - echolog "dns2socks模式需要使用Socks5代理节点,请开启!" + echolog "DNS:dns2socks模式需要使用Socks5代理节点,请开启!" force_stop fi ;; @@ -727,7 +728,7 @@ start_dns() { gen_pdnsd_config $DNS_PORT "cache" DNS_FORWARD=$(echo $DNS_FORWARD | sed 's/,/ /g') nohup $pdnsd_bin --daemon -c $pdnsd_dir/pdnsd.conf -d >/dev/null 2>&1 & - echolog "运行DNS转发模式:pdnsd..." + echolog "DNS:pdnsd..." } ;; chinadns-ng) @@ -741,7 +742,7 @@ start_dns() { up_trust_chinadns_ng_dns=$(config_t_get global up_trust_chinadns_ng_dns "pdnsd") if [ "$up_trust_chinadns_ng_dns" == "pdnsd" ]; then if [ -z "$TCP_NODE1" -o "$TCP_NODE1" == "nil" ]; then - echolog "ChinaDNS-NG + pdnsd 模式需要启用TCP节点!" + echolog "DNS:ChinaDNS-NG + pdnsd 模式需要启用TCP节点!" force_stop else use_tcp_node_resolve_dns=1 @@ -751,7 +752,7 @@ start_dns() { DNS_FORWARD=$(echo $DNS_FORWARD | sed 's/,/ /g') nohup $pdnsd_bin --daemon -c $pdnsd_dir/pdnsd.conf -d >/dev/null 2>&1 & nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t 127.0.0.1#$other_port $gfwlist_param $chnlist_param >/dev/null 2>&1 & - echolog "运行DNS转发模式:ChinaDNS-NG + pdnsd($DNS_FORWARD),国内DNS:$UP_CHINA_DNS" + echolog "DNS:ChinaDNS-NG + pdnsd($DNS_FORWARD),国内DNS:$UP_CHINA_DNS" } fi elif [ "$up_trust_chinadns_ng_dns" == "dns2socks" ]; then @@ -761,22 +762,17 @@ start_dns() { DNS2SOCKS_FORWARD=$(config_t_get global dns2socks_forward 8.8.4.4) nohup $dns2socks_bin 127.0.0.1:$SOCKS5_PROXY_PORT1 $DNS2SOCKS_FORWARD 127.0.0.1:$other_port >/dev/null 2>&1 & nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t 127.0.0.1#$other_port $gfwlist_param $chnlist_param >/dev/null 2>&1 & - echolog "运行DNS转发模式:ChinaDNS-NG + dns2socks($DNS2SOCKS_FORWARD),国内DNS:$UP_CHINA_DNS" + echolog "DNS:ChinaDNS-NG + dns2socks($DNS2SOCKS_FORWARD),国内DNS:$UP_CHINA_DNS" } else - echolog "dns2socks模式需要使用Socks5代理节点,请开启!" + echolog "DNS:dns2socks模式需要使用Socks5代理节点,请开启!" force_stop fi else - if [ -z "$UDP_NODE1" -o "$UDP_NODE1" == "nil" ]; then - nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t 208.67.222.222#443,208.67.222.222#5353 $gfwlist_param $chnlist_param >/dev/null 2>&1 & - echolog "运行DNS转发模式:ChinaDNS-NG,国内DNS:$UP_CHINA_DNS,因为你没有使用UDP节点,将使用OpenDNS 443端口或5353端口作为可信DNS。" - else - use_udp_node_resolve_dns=1 - DNS_FORWARD=$(echo $up_trust_chinadns_ng_dns | sed 's/,/ /g') - nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t $up_trust_chinadns_ng_dns $gfwlist_param $chnlist_param >/dev/null 2>&1 & - echolog "运行DNS转发模式:ChinaDNS-NG,国内DNS:$UP_CHINA_DNS,可信DNS:$up_trust_chinadns_ng_dns" - fi + use_udp_node_resolve_dns=1 + DNS_FORWARD=$(echo $up_trust_chinadns_ng_dns | sed 's/,/ /g') + nohup $chinadns_ng_bin -l $DNS_PORT -c $UP_CHINA_DNS -t $up_trust_chinadns_ng_dns $gfwlist_param $chnlist_param >/dev/null 2>&1 & + echolog "DNS:ChinaDNS-NG,国内DNS:$UP_CHINA_DNS,可信DNS:$up_trust_chinadns_ng_dns,如果不能使用,请确保UDP节点已打开并且支持UDP转发。" fi } ;; @@ -815,35 +811,28 @@ add_dnsmasq() { cat $RULE_PATH/router | awk '{print "server=/."$1"/127.0.0.1#'$DNS_PORT'\nipset=/."$1"/router"}' >>$TMP_DNSMASQ_PATH/router.conf fi - userconf=$(grep -c "" $RULE_PATH/user.conf) - if [ "$userconf" -gt 0 ]; then - ln -s $RULE_PATH/user.conf $TMP_DNSMASQ_PATH/user.conf - fi - - backhome=$(config_t_get global proxy_mode gfwlist) - if [ "$backhome" == "returnhome" ]; then - rm -rf $TMP_DNSMASQ_PATH/gfwlist.conf - rm -rf $TMP_DNSMASQ_PATH/blacklist_host.conf - rm -rf $TMP_DNSMASQ_PATH/whitelist_host.conf - fi - - server="server=127.0.0.1#$DNS_PORT" - [ "$DNS_MODE" != "chinadns-ng" ] && { - local china_dns1=$(echo $UP_CHINA_DNS | awk -F "," '{print $1}') - local china_dns2=$(echo $UP_CHINA_DNS | awk -F "," '{print $2}') - [ -n "$china_dns1" ] && server="server=$china_dns1" - [ -n "$china_dns2" ] && server="${server}\n${server_2}" - server="${server}\nno-resolv" - } - cat <<-EOF > /var/dnsmasq.d/dnsmasq-$CONFIG.conf + if [ -z "$IS_DEFAULT_CHINA_DNS" -o "$IS_DEFAULT_CHINA_DNS" == 0 ]; then + server="server=127.0.0.1#$DNS_PORT" + [ "$DNS_MODE" != "chinadns-ng" ] && { + local china_dns1=$(echo $UP_CHINA_DNS | awk -F "," '{print $1}') + local china_dns2=$(echo $UP_CHINA_DNS | awk -F "," '{print $2}') + [ -n "$china_dns1" ] && server="server=$china_dns1" + [ -n "$china_dns2" ] && server="${server}\n${server_2}" + server="${server}\nno-resolv" + } + cat <<-EOF > /var/dnsmasq.d/dnsmasq-$CONFIG.conf $(echo -e $server) all-servers no-poll - conf-dir=$TMP_DNSMASQ_PATH + EOF + fi + + cat <<-EOF >> /var/dnsmasq.d/dnsmasq-$CONFIG.conf + conf-dir=$TMP_DNSMASQ_PATH EOF cp -rf /var/dnsmasq.d/dnsmasq-$CONFIG.conf $DNSMASQ_PATH/dnsmasq-$CONFIG.conf - echolog "dnsmasq:生成配置文件并重启服务。" /etc/init.d/dnsmasq restart >/dev/null 2>&1 & + echolog "dnsmasq:生成配置文件并重启服务。" } gen_redsocks_config() { @@ -914,7 +903,6 @@ gen_redsocks_config() { gen_pdnsd_config() { pdnsd_dir=$CONFIG_PATH/pdnsd mkdir -p $pdnsd_dir - touch $pdnsd_dir/pdnsd.cache chown -R root.nogroup $pdnsd_dir [ "$2" == "cache" ] && cache_param="perm_cache = 1024;\ncache_dir = \"$pdnsd_dir\";" cat > $pdnsd_dir/pdnsd.conf <<-EOF diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh index e763dfba31..c7e80d53d5 100755 --- a/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/iptables.sh @@ -344,35 +344,22 @@ add_firewall_rule() { $iptables_nat -I PSW 2 -p tcp -d $dns_ip --dport $dns_port -j REDIRECT --to-ports $local_port done } - - is_add_prerouting=0 - - KP_INDEX=$($iptables_nat -L PREROUTING | tail -n +3 | sed -n -e '/^KOOLPROXY/=') - if [ -n "$KP_INDEX" ]; then - let KP_INDEX+=1 - #确保添加到KOOLPROXY规则之后 - $iptables_nat -I PREROUTING $KP_INDEX -j PSW - is_add_prerouting=1 - fi - - ADBYBY_INDEX=$($iptables_nat -L PREROUTING | tail -n +3 | sed -n -e '/^ADBYBY/=') - if [ -n "$ADBYBY_INDEX" ]; then - let ADBYBY_INDEX+=1 - #确保添加到ADBYBY规则之后 - $iptables_nat -I PREROUTING $ADBYBY_INDEX -j PSW - is_add_prerouting=1 - fi - - if [ "$is_add_prerouting" == 0 ]; then - #如果去广告没有运行,确保添加到prerouting_rule规则之后 - PR_INDEX=$($iptables_nat -L PREROUTING | tail -n +3 | sed -n -e '/^prerouting_rule/=') - if [ -z "$PR_INDEX" ]; then - PR_INDEX=1 - else - let PR_INDEX+=1 - fi - $iptables_nat -I PREROUTING $PR_INDEX -j PSW + + PRE_INDEX=1 + KP_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "KOOLPROXY" | sed -n '$p' | awk '{print $1}') + ADBYBY_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "ADBYBY" | sed -n '$p' | awk '{print $1}') + if [ -n "$KP_INDEX" -a -z "$ADBYBY_INDEX" ]; then + PRE_INDEX=$(expr $KP_INDEX + 1) + elif [ -z "$KP_INDEX" -a -n "$ADBYBY_INDEX" ]; then + PRE_INDEX=$(expr $ADBYBY_INDEX + 1) + elif [ -z "$KP_INDEX" -a -z "$ADBYBY_INDEX" ]; then + PR_INDEX=$($iptables_nat -L PREROUTING --line-numbers | grep "prerouting_rule" | sed -n '$p' | awk '{print $1}') + [ -n "$PR_INDEX" ] && { + PRE_INDEX=$(expr $PR_INDEX + 1) + } fi + $iptables_nat -I PREROUTING $PRE_INDEX -j PSW + # 用于本机流量转发 $iptables_nat -A OUTPUT -j PSW_OUTPUT $iptables_nat -A PSW_OUTPUT $(dst $IPSET_LANIPLIST) -j RETURN @@ -458,28 +445,30 @@ add_firewall_rule() { $iptables_mangle -A PSW_GAME$k -p udp $(dst $IPSET_CHN) -j RETURN $iptables_mangle -A PSW_GAME$k -p udp -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port - # 用于本机流量转发 - $iptables_mangle -A OUTPUT -j PSW_OUTPUT - $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_LANIPLIST) -j RETURN - [ "$use_udp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && { - for dns in $DNS_FORWARD - do - local dns_ip=$(echo $dns | awk -F "#" '{print $1}') - local dns_port=$(echo $dns | awk -F "#" '{print $2}') - [ -z "$dns_port" ] && dns_port=53 - $iptables_mangle -A PSW_OUTPUT -p udp -d $dns_ip --dport $dns_port -j MARK --set-mark 1 - $iptables_mangle -I PSW 2 -p udp -d $dns_ip --dport $dns_port -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port - done - } - $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_VPSIPLIST) -j RETURN - $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_WHITELIST) -j RETURN - $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1 - $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j MARK --set-mark 1 + [ "$k" == 1 ] && { + # 用于本机流量转发 + $iptables_mangle -A OUTPUT -j PSW_OUTPUT + $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_LANIPLIST) -j RETURN + [ "$use_udp_node_resolve_dns" == 1 -a -n "$DNS_FORWARD" ] && { + for dns in $DNS_FORWARD + do + local dns_ip=$(echo $dns | awk -F "#" '{print $1}') + local dns_port=$(echo $dns | awk -F "#" '{print $2}') + [ -z "$dns_port" ] && dns_port=53 + $iptables_mangle -A PSW_OUTPUT -p udp -d $dns_ip --dport $dns_port -j MARK --set-mark 1 + $iptables_mangle -I PSW 2 -p udp -d $dns_ip --dport $dns_port -j TPROXY --tproxy-mark 0x1/0x1 --on-port $local_port + done + } + $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_VPSIPLIST) -j RETURN + $iptables_mangle -A PSW_OUTPUT -p udp $(dst $IPSET_WHITELIST) -j RETURN + $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_ROUTER) -j MARK --set-mark 1 + $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_BLACKLIST) -j MARK --set-mark 1 - [ "$LOCALHOST_PROXY_MODE" == "global" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -j MARK --set-mark 1 - [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_GFW) -j MARK --set-mark 1 - [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && { - $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j MARK --set-mark 1 + [ "$LOCALHOST_PROXY_MODE" == "global" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -j MARK --set-mark 1 + [ "$LOCALHOST_PROXY_MODE" == "gfwlist" ] && $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS $(dst $IPSET_GFW) -j MARK --set-mark 1 + [ "$LOCALHOST_PROXY_MODE" == "chnroute" ] && { + $iptables_mangle -A PSW_OUTPUT -p udp -m multiport --dport $UDP_REDIR_PORTS -m set ! --match-set $IPSET_CHN dst -j MARK --set-mark 1 + } } echolog "IPv4 防火墙UDP转发规则加载完成!" diff --git a/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh b/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh index 2f570c6686..588b5720ca 100755 --- a/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh +++ b/package/lienol/luci-app-passwall/root/usr/share/passwall/subscription.sh @@ -155,8 +155,19 @@ get_remote_config(){ ss_encrypt_method=$(echo "$decode_link" | awk -F ':' '{print $1}') password=$(echo "$decode_link" | awk -F ':' '{print $2}' | awk -F '@' '{print $1}') node_address=$(echo "$decode_link" | awk -F ':' '{print $2}' | awk -F '@' '{print $2}') - node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '#' '{print $1}' | awk -F ':' '{print $2}') + + plugin_tmp=$(echo "$decode_link" | awk -F '\\/\\?' '{print $2}' | awk -F '#' '{print $1}') + if [ "$plugin_tmp" != "" ]; then + plugin_tmp=$(urldecode $plugin_tmp) + plugin=$(echo "$plugin_tmp" | awk -F 'plugin=' '{print $2}' | awk -F ';' '{print $1}') + plugin_options=$(echo "$plugin_tmp" | awk -F "$plugin;" '{print $2}' | awk -F '&' '{print $1}') + node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '\\/\\?' '{print $1}' | awk -F ':' '{print $2}') + else + node_port=$(echo "$decode_link" | awk -F '@' '{print $2}' | awk -F '#' '{print $1}' | awk -F ':' '{print $2}') + fi + remarks=$(urldecode $(echo "$decode_link" | awk -F '#' '{print $2}')) + [ "$plugin" == "simple-obfs" -o "$plugin" == "obfs-local" ] && echo "$Date: 不支持simple-obfs插件,订阅节点:$remarks:$node_address失败!" >> $LOG_FILE && return elif [ "$1" == "ssr" ]; then decode_link=$(decode_url_link $2 1) node_address=$(echo "$decode_link" | awk -F ':' '{print $1}') @@ -253,6 +264,11 @@ get_remote_config(){ [ -z "$node_address" -o "$node_address" == "" ] && return [ -z "$remarks" -o "$remarks" == "" ] && remarks="${node_address}:${node_port}" + tmp=$(echo $remarks | grep -E "过期时间|剩余流量|QQ群|官网") + [ -n "$tmp" ] && { + echo "$Date: 丢弃无用节点:$tmp" >> $LOG_FILE + return + } # 把全部节点节点写入文件 /usr/share/${CONFIG}/sub/all_onlinenodes if [ ! -f "/usr/share/${CONFIG}/sub/all_onlinenodes" ]; then @@ -265,7 +281,6 @@ get_remote_config(){ done return fi - fi node_address=$(echo -n $node_address | awk '{print gensub(/[^!-~]/,"","g",$0)}') @@ -273,6 +288,11 @@ get_remote_config(){ [ -z "$node_address" -o "$node_address" == "" ] && return [ -z "$remarks" -o "$remarks" == "" ] && remarks="${node_address}:${node_port}" + tmp=$(echo $remarks | grep -E "过期时间|剩余流量|QQ群|官网") + [ -n "$tmp" ] && { + echo "$Date: 丢弃无用节点:$tmp" >> $LOG_FILE + return + } # 把全部节点节点写入文件 /usr/share/${CONFIG}/sub/all_onlinenodes if [ ! -f "/usr/share/${CONFIG}/sub/all_onlinenodes" ]; then @@ -355,6 +375,7 @@ add_nodes(){ ${uci_set}v2ray_ws_path="$json_path" ${uci_set}v2ray_h2_host="$json_host" ${uci_set}v2ray_h2_path="$json_path" + ${uci_set}tls_allowInsecure=1 if [ "$1" == "add" ]; then let addnum_v2ray+=1 @@ -574,4 +595,3 @@ add) start ;; esac -