diff --git a/package/lean/luci-app-ssr-plus/Makefile b/package/lean/luci-app-ssr-plus/Makefile
index 9cca57bd1c..9b3eb648a9 100644
--- a/package/lean/luci-app-ssr-plus/Makefile
+++ b/package/lean/luci-app-ssr-plus/Makefile
@@ -2,7 +2,7 @@ include $(TOPDIR)/rules.mk
PKG_NAME:=luci-app-ssr-plus
PKG_VERSION:=181
-PKG_RELEASE:=1
+PKG_RELEASE:=2
include $(INCLUDE_DIR)/package.mk
@@ -16,10 +16,6 @@ config PACKAGE_$(PKG_NAME)_INCLUDE_V2ray_plugin
bool "Include Shadowsocks V2ray Plugin"
default y if i386||x86_64||arm||aarch64
-config PACKAGE_$(PKG_NAME)_INCLUDE_V2ray
- bool "Include V2ray"
- default y if i386||x86_64||arm||aarch64
-
config PACKAGE_$(PKG_NAME)_INCLUDE_Xray
bool "Include Xray"
default y if i386||x86_64||arm||aarch64
@@ -28,14 +24,18 @@ config PACKAGE_$(PKG_NAME)_INCLUDE_Trojan
bool "Include Trojan"
default y if i386||x86_64||arm||aarch64
+config PACKAGE_$(PKG_NAME)_INCLUDE_Redsocks2
+ bool "Include Redsocks2"
+ default y if i386||x86_64||arm||aarch64
+
config PACKAGE_$(PKG_NAME)_INCLUDE_NaiveProxy
bool "Include NaiveProxy"
depends on !(arc||armeb||mips||mips64||powerpc)
default y if i386||x86_64||arm||aarch64
-config PACKAGE_$(PKG_NAME)_INCLUDE_Redsocks2
- bool "Include Redsocks2"
- default y if i386||x86_64||arm||aarch64
+config PACKAGE_$(PKG_NAME)_INCLUDE_V2ray
+ bool "Include V2ray"
+ default n
config PACKAGE_$(PKG_NAME)_INCLUDE_Kcptun
bool "Include Kcptun"
diff --git a/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client-config.lua b/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client-config.lua
index a75febc4d1..1dae1bb19b 100644
--- a/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client-config.lua
+++ b/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client-config.lua
@@ -103,7 +103,9 @@ local flows = {
"xtls-rprx-origin",
"xtls-rprx-origin-udp443",
"xtls-rprx-direct",
-"xtls-rprx-direct-udp443"
+"xtls-rprx-direct-udp443",
+"xtls-rprx-splice",
+"xtls-rprx-splice-udp443"
}
m = Map(shadowsocksr, translate("Edit ShadowSocksR Server"))
@@ -128,13 +130,10 @@ o:value("ssr", translate("ShadowsocksR"))
if nixio.fs.access("/usr/bin/ss-redir") then
o:value("ss", translate("Shadowsocks New Version"))
end
-if nixio.fs.access("/usr/bin/v2ray/v2ray") or nixio.fs.access("/usr/bin/v2ray") then
+if nixio.fs.access("/usr/bin/xray") or nixio.fs.access("/usr/bin/xray/xray") or nixio.fs.access("/usr/bin/v2ray/v2ray") or nixio.fs.access("/usr/bin/v2ray") then
o:value("v2ray", translate("V2Ray"))
o:value("vless", translate("VLESS"))
end
-if nixio.fs.access("/usr/bin/xray") then
-o:value("xray", translate("XRay"))
-end
if nixio.fs.access("/usr/sbin/trojan") then
o:value("trojan", translate("Trojan"))
end
@@ -163,7 +162,6 @@ o:depends("type", "ssr")
o:depends("type", "ss")
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
o:depends("type", "trojan")
o:depends("type", "naiveproxy")
o:depends("type", "socks5")
@@ -175,7 +173,6 @@ o:depends("type", "ssr")
o:depends("type", "ss")
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
o:depends("type", "trojan")
o:depends("type", "naiveproxy")
o:depends("type", "socks5")
@@ -247,14 +244,12 @@ o.rmempty = true
o.default = uuid
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
-- VLESS Encryption
o = s:option(Value, "vless_encryption", translate("VLESS Encryption"))
o.rmempty = true
o.default = "none"
o:depends("type", "vless")
-o:depends("type", "xray")
-- 加密方式
o = s:option(ListValue, "security", translate("Encrypt Method"))
@@ -272,7 +267,6 @@ o:value("quic", "QUIC")
o.rmempty = true
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
-- [[ TCP部分 ]]--
@@ -389,7 +383,7 @@ o.default = 2
o.rmempty = true
o = s:option(Value, "seed", translate("Obfuscate password (optional)"))
-o:depends("transport", "kcp")
+o:depends({type="vless", transport="kcp"})
o.rmempty = true
o = s:option(Flag, "congestion", translate("Congestion"))
@@ -401,9 +395,8 @@ o = s:option(Flag, "insecure", translate("allowInsecure"))
o.rmempty = false
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
o:depends("type", "trojan")
-o.default = "1"
+o.default = "0"
o.description = translate("If true, allowss insecure connection at TLS client, e.g., TLS server uses unverifiable certificates.")
-- [[ TLS ]]--
o = s:option(Flag, "tls", translate("TLS"))
@@ -411,7 +404,6 @@ o.rmempty = true
o.default = "0"
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
o:depends("type", "trojan")
o = s:option(Value, "tls_host", translate("TLS Host"))
@@ -420,11 +412,12 @@ o:depends("tls", "1")
o.rmempty = true
-- XTLS
+if nixio.fs.access("/usr/bin/xray") or nixio.fs.access("/usr/bin/xray/xray") then
o = s:option(Flag, "xtls", translate("XTLS"))
o.rmempty = true
o.default = "0"
-o:depends({type="vless", tls="1"})
-o:depends({type="xray", tls="1"})
+o:depends({type="vless", tls=true})
+end
-- Flow
o = s:option(Value, "vless_flow", translate("Flow"))
@@ -438,7 +431,7 @@ o = s:option(Flag, "mux", translate("Mux"))
o.rmempty = true
o.default = "0"
o:depends("type", "v2ray")
-o:depends("type", "vless")
+o:depends({type="vless", xtls=false})
o = s:option(Value, "concurrency", translate("Concurrency"))
o.datatype = "uinteger"
@@ -453,7 +446,6 @@ o.default = "0"
o:depends("type", "trojan")
o:depends("type", "v2ray")
o:depends("type", "vless")
-o:depends("type", "xray")
o.description = translate("If you have a self-signed certificate,please check the box")
o = s:option(DummyValue, "upload", translate("Upload"))
diff --git a/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client.lua b/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client.lua
index ba82e488f1..b2e67608bb 100644
--- a/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client.lua
+++ b/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/client.lua
@@ -6,7 +6,7 @@ local m, s, sec, o, kcp_enable
local shadowsocksr = "shadowsocksr"
local uci = luci.model.uci.cursor()
m = Map(shadowsocksr, translate("ShadowSocksR Plus+ Settings"),
- translate("
Support SS/SSR/V2RAY/XRAY/TROJAN/NAIVEPROXY/SOCKS5/TUN etc.
"))
+ translate("Support SS/SSR/V2RAY/TROJAN/NAIVEPROXY/SOCKS5/TUN etc.
"))
m:section(SimpleSection).template = "shadowsocksr/status"
diff --git a/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/control.lua b/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/control.lua
index 166eae0f1a..22443d080d 100644
--- a/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/control.lua
+++ b/package/lean/luci-app-ssr-plus/luasrc/model/cbi/shadowsocksr/control.lua
@@ -2,11 +2,20 @@ require "luci.ip"
require "nixio.fs"
local m, s, o
-m = Map("shadowsocksr", translate("Block and Allow List"))
+m = Map("shadowsocksr")
s = m:section(TypedSection, "access_control")
s.anonymous = true
+-- Interface control
+s:tab("Interface", translate("Interface control"))
+o = s:taboption("Interface", DynamicList, "Interface", translate("Interface"))
+o.template = "cbi/network_netlist"
+o.widget = "checkbox"
+o.nocreate = true
+o.unspecified = true
+o.description = translate("Select the interface that needs to transmit data. If unchecked, all interfaces will pass data by default!")
+
-- Part of WAN
s:tab("wan_ac", translate("WAN IP AC"))
diff --git a/package/lean/luci-app-ssr-plus/po/zh_Hans/ssr-plus.po b/package/lean/luci-app-ssr-plus/po/zh_Hans/ssr-plus.po
index b7e5d0ae0b..2844cf95a4 100644
--- a/package/lean/luci-app-ssr-plus/po/zh_Hans/ssr-plus.po
+++ b/package/lean/luci-app-ssr-plus/po/zh_Hans/ssr-plus.po
@@ -421,8 +421,8 @@ msgstr "GFW列表"
msgid "ShadowSocksR Plus+ Settings"
msgstr "ShadowSocksR Plus+ 设置"
-msgid "Support SS/SSR/V2RAY/XRAY/TROJAN/NAIVEPROXY/SOCKS5/TUN etc.
"
-msgstr "支持 SS/SSR/V2RAY/XRAY/TROJAN/NAIVEPROXY/SOCKS5/TUN 等协议
"
+msgid "Support SS/SSR/V2RAY/TROJAN/NAIVEPROXY/SOCKS5/TUN etc.
"
+msgstr "支持 SS/SSR/V2RAY/TROJAN/NAIVEPROXY/SOCKS5/TUN 等协议
"
msgid "Main Server"
msgstr "主服务器"
@@ -463,8 +463,8 @@ msgstr "更新"
msgid "Server Count"
msgstr "服务器节点数量"
-msgid "Block and Allow List"
-msgstr "禁止/通行名单"
+msgid "Interface control"
+msgstr "接口控制"
msgid "WAN IP AC"
msgstr "WAN IP访问控制"
@@ -687,3 +687,6 @@ msgstr "禁止连接的域名"
msgid "Obfuscate password (optional)"
msgstr "混淆密码(可选)"
+
+msgid "Select the interface that needs to transmit data. If unchecked, all interfaces will pass data by default!"
+msgstr "选择需要传递数据的接口。如果未选择,则默认情况下所有接口都将传递数据!"
diff --git a/package/lean/luci-app-ssr-plus/root/etc/config/shadowsocksr b/package/lean/luci-app-ssr-plus/root/etc/config/shadowsocksr
index 063335cfda..902db1c4cb 100644
--- a/package/lean/luci-app-ssr-plus/root/etc/config/shadowsocksr
+++ b/package/lean/luci-app-ssr-plus/root/etc/config/shadowsocksr
@@ -26,6 +26,7 @@ config access_control
list wan_fw_ips '91.108.4.0/22'
list wan_fw_ips '91.108.56.0/22'
list wan_fw_ips '109.239.140.0/24'
+ list Interface 'lan'
config server_subscribe
option proxy '0'
diff --git a/package/lean/luci-app-ssr-plus/root/etc/init.d/shadowsocksr b/package/lean/luci-app-ssr-plus/root/etc/init.d/shadowsocksr
index dedeff17bb..33c30b657c 100755
--- a/package/lean/luci-app-ssr-plus/root/etc/init.d/shadowsocksr
+++ b/package/lean/luci-app-ssr-plus/root/etc/init.d/shadowsocksr
@@ -114,8 +114,12 @@ find_bin() {
ssr) ret="/usr/bin/ssr-redir" ;;
ssr-local) ret="/usr/bin/ssr-local" ;;
ssr-server) ret="/usr/bin/ssr-server" ;;
- v2ray | vless) ret="/usr/bin/v2ray/v2ray" && [ ! -f "$ret" ] && ret="/usr/bin/v2ray" ;;
- xray) ret="/usr/bin/xray/xray" && [ ! -f "$ret" ] && ret="/usr/bin/xray" ;;
+ v2ray | vless)
+ ret="/usr/bin/xray"
+ [ ! -f "$ret" ] && ret="/usr/bin/xray/xray"
+ [ ! -f "$ret" ] && ret="/usr/bin/v2ray"
+ [ ! -f "$ret" ] && ret="/usr/bin/v2ray/v2ray"
+ ;;
trojan) ret="/usr/sbin/trojan" ;;
naiveproxy) ret="/usr/bin/naive" ;;
socks5 | tun) ret="/usr/sbin/redsocks2" ;;
@@ -188,13 +192,9 @@ gen_config_file() {
EOF
;;
v2ray | vless)
- lua /usr/share/shadowsocksr/gen${type}config.lua $GLOBAL_SERVER tcp $(uci_get_by_name $1 local_port) >/var/etc/v2-ssr-retcp.json
+ lua /usr/share/shadowsocksr/genv2config.lua $GLOBAL_SERVER tcp $(uci_get_by_name $1 local_port) >/var/etc/v2-ssr-retcp.json
sed -i 's/\\//g' /var/etc/v2-ssr-retcp.json
;;
- xray)
- lua /usr/share/shadowsocksr/gen${type}config.lua $GLOBAL_SERVER tcp $(uci_get_by_name $1 local_port) >/var/etc/xray-ssr-retcp.json
- sed -i 's/\\//g' /var/etc/xray-ssr-retcp.json
- ;;
trojan)
lua /usr/share/shadowsocksr/gentrojanconfig.lua $GLOBAL_SERVER nat $(uci_get_by_name $1 local_port) >/var/etc/trojan-ssr-retcp.json
sed -i 's/\\//g' /var/etc/trojan-ssr-retcp.json
@@ -368,10 +368,6 @@ start_redir_tcp() {
$bin -config /var/etc/v2-ssr-retcp.json >/dev/null 2>&1 &
echo "$(date "+%Y-%m-%d %H:%M:%S") Main node:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
;;
- xray)
- $bin -config /var/etc/xray-ssr-retcp.json >/dev/null 2>&1 &
- echo "$(date "+%Y-%m-%d %H:%M:%S") Main node:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
- ;;
trojan)
for i in $(seq 1 $threads); do
$bin --config /var/etc/trojan-ssr-retcp.json >/dev/null 2>&1 &
@@ -422,17 +418,11 @@ start_redir_udp() {
echo "$(date "+%Y-%m-%d %H:%M:%S") UDP TPROXY Relay:$name Started!" >>/tmp/ssrplus.log
;;
v2ray | vless)
- lua /usr/share/shadowsocksr/gen${type}config.lua $UDP_RELAY_SERVER udp $(uci_get_by_name $UDP_RELAY_SERVER local_port) >/var/etc/v2-ssr-reudp.json
+ lua /usr/share/shadowsocksr/genv2config.lua $UDP_RELAY_SERVER udp $(uci_get_by_name $UDP_RELAY_SERVER local_port) >/var/etc/v2-ssr-reudp.json
sed -i 's/\\//g' /var/etc/v2-ssr-reudp.json
$bin -config /var/etc/v2-ssr-reudp.json >/dev/null 2>&1 &
echo "$(date "+%Y-%m-%d %H:%M:%S") UDP TPROXY Relay:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
;;
- xray)
- lua /usr/share/shadowsocksr/gen${type}config.lua $UDP_RELAY_SERVER udp $(uci_get_by_name $UDP_RELAY_SERVER local_port) >/var/etc/xray-ssr-reudp.json
- sed -i 's/\\//g' /var/etc/xray-ssr-reudp.json
- $bin -config /var/etc/xray-ssr-reudp.json >/dev/null 2>&1 &
- echo "$(date "+%Y-%m-%d %H:%M:%S") UDP TPROXY Relay:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
- ;;
trojan)
lua /usr/share/shadowsocksr/gentrojanconfig.lua $GLOBAL_SERVER client 10801 >/var/etc/trojan-ssr-reudp.json
sed -i 's/\\//g' /var/etc/trojan-ssr-reudp.json
@@ -479,19 +469,12 @@ start_shunt() {
echo "$(date "+%Y-%m-%d %H:%M:%S") Netflix shunt:$name Started!" >>/tmp/ssrplus.log
;;
v2ray | vless)
- lua /usr/share/shadowsocksr/gen${type}config.lua $NETFLIX_SERVER tcp 4321 1088 >/var/etc/v2-ssr-netflix.json
+ lua /usr/share/shadowsocksr/genv2config.lua $NETFLIX_SERVER tcp 4321 1088 >/var/etc/v2-ssr-netflix.json
sed -i 's/\\//g' /var/etc/v2-ssr-netflix.json
$bin -config /var/etc/v2-ssr-netflix.json >/dev/null 2>&1 &
dns2socks 127.0.0.1:1088 8.8.8.8:53 127.0.0.1:5555 -q >/dev/null 2>&1 &
echo "$(date "+%Y-%m-%d %H:%M:%S") Netflix shunt:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
;;
- xray)
- lua /usr/share/shadowsocksr/gen${type}config.lua $NETFLIX_SERVER tcp 4321 1088 >/var/etc/xray-ssr-netflix.json
- sed -i 's/\\//g' /var/etc/xray-ssr-netflix.json
- $bin -config /var/etc/xray-ssr-netflix.json >/dev/null 2>&1 &
- dns2socks 127.0.0.1:1088 8.8.8.8:53 127.0.0.1:5555 -q >/dev/null 2>&1 &
- echo "$(date "+%Y-%m-%d %H:%M:%S") Netflix shunt:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
- ;;
trojan)
lua /usr/share/shadowsocksr/gentrojanconfig.lua $NETFLIX_SERVER nat 4321 >/var/etc/trojan-ssr-netflix.json
sed -i 's/\\//g' /var/etc/trojan-ssr-netflix.json
@@ -533,8 +516,8 @@ start_shunt() {
start_local() {
local local_server=$(uci_get_by_type socks5_proxy server nil)
- [ "$local_server" == "nil" ] && return 1
[ "$local_server" == "same" ] && local_server=$GLOBAL_SERVER
+ [ "$local_server" == "nil" ] && return 1
local type=$(uci_get_by_name $local_server type)
local bin=$(find_bin $type)
[ ! -f "$bin" ] && echo "$(date "+%Y-%m-%d %H:%M:%S") Global_Socks5:Can't find $bin program, can't start!" >>/tmp/ssrplus.log && local_enable=0 && return 1
@@ -549,17 +532,11 @@ start_local() {
echo "$(date "+%Y-%m-%d %H:%M:%S") Global_Socks5:$name Started!" >>/tmp/ssrplus.log
;;
v2ray | vless)
- lua /usr/share/shadowsocksr/gen${type}config.lua $local_server tcp 0 $(uci_get_by_type socks5_proxy local_port 1080) >/var/etc/v2-ssr-local.json
+ lua /usr/share/shadowsocksr/genv2config.lua $local_server tcp 0 $(uci_get_by_type socks5_proxy local_port 1080) >/var/etc/v2-ssr-local.json
sed -i 's/\\//g' /var/etc/v2-ssr-local.json
$bin -config /var/etc/v2-ssr-local.json >/dev/null 2>&1 &
echo "$(date "+%Y-%m-%d %H:%M:%S") Global_Socks5:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
;;
- xray)
- lua /usr/share/shadowsocksr/gen${type}config.lua $local_server tcp 0 $(uci_get_by_type socks5_proxy local_port 1080) >/var/etc/xray-ssr-local.json
- sed -i 's/\\//g' /var/etc/xray-ssr-local.json
- $bin -config /var/etc/xray-ssr-local.json >/dev/null 2>&1 &
- echo "$(date "+%Y-%m-%d %H:%M:%S") Global_Socks5:$($bin -version | head -1) Started!" >>/tmp/ssrplus.log
- ;;
trojan)
lua /usr/share/shadowsocksr/gentrojanconfig.lua $local_server client $(uci_get_by_type socks5_proxy local_port 1080) >/var/etc/trojan-ssr-local.json
sed -i 's/\\//g' /var/etc/trojan-ssr-local.json
@@ -724,6 +701,7 @@ start_rules() {
-B "$(uci_get_by_type access_control lan_bp_ips)" \
-p "$(uci_get_by_type access_control lan_fp_ips)" \
-G "$(uci_get_by_type access_control lan_gm_ips)" \
+ -m "$(uci_get_by_type access_control Interface)" \
-D "$proxyport" \
-F "$netflix" \
-N "$netflix_ip" \
diff --git a/package/lean/luci-app-ssr-plus/root/etc/uci-defaults/luci-ssr-plus b/package/lean/luci-app-ssr-plus/root/etc/uci-defaults/luci-ssr-plus
index 5200d52e9b..b0e921f5ef 100755
--- a/package/lean/luci-app-ssr-plus/root/etc/uci-defaults/luci-ssr-plus
+++ b/package/lean/luci-app-ssr-plus/root/etc/uci-defaults/luci-ssr-plus
@@ -56,6 +56,7 @@ add_list shadowsocksr.@access_control[0].wan_fw_ips=67.198.55.0/24
add_list shadowsocksr.@access_control[0].wan_fw_ips=91.108.4.0/22
add_list shadowsocksr.@access_control[0].wan_fw_ips=91.108.56.0/22
add_list shadowsocksr.@access_control[0].wan_fw_ips=109.239.140.0/24
+add_list shadowsocksr.@access_control[0].Interface='lan'
add shadowsocksr socks5_proxy
set shadowsocksr.@socks5_proxy[0].server='nil'
set shadowsocksr.@socks5_proxy[0].local_port='1080'
diff --git a/package/lean/luci-app-ssr-plus/root/usr/bin/ssr-rules b/package/lean/luci-app-ssr-plus/root/usr/bin/ssr-rules
index 8cd67218d4..476314eaf0 100755
--- a/package/lean/luci-app-ssr-plus/root/usr/bin/ssr-rules
+++ b/package/lean/luci-app-ssr-plus/root/usr/bin/ssr-rules
@@ -31,6 +31,7 @@ Valid options are:
-F netflix mode
-N netflix server IP
-M netflix proxy mode
+ -m Interface name
-I a file content is bypassed netflix ip list
-e extra options for iptables
-o apply the rules to the OUTPUT chain
@@ -181,13 +182,19 @@ ac_rule() {
;;
esac
fi
- IFNAME=$(uci -P /var/state get network.lan.ifname 2>/dev/null)
ipset -! -R <<-EOF || return 1
create ss_spec_lan_ac hash:net
$(for ip in ${LAN_AC_IP:1}; do echo "add ss_spec_lan_ac $ip"; done)
EOF
- $IPT -I PREROUTING 1 ${IFNAME:+-i $IFNAME} -p tcp $EXT_ARGS $MATCH_SET \
- -m comment --comment "$TAG" -j SS_SPEC_WAN_AC
+ if [ -z "$Interface" ]; then
+ $IPT -I PREROUTING 1 -p tcp $EXT_ARGS $MATCH_SET -m comment --comment "$TAG" -j SS_SPEC_WAN_AC
+ else
+ for name in $Interface;do
+ local IFNAME=$(uci -P /var/state get network.$name.ifname 2>/dev/null)
+ [ -n "$IFNAME" ] && $IPT -I PREROUTING 1 ${IFNAME:+-i $IFNAME} -p tcp $EXT_ARGS $MATCH_SET -m comment --comment "$TAG" -j SS_SPEC_WAN_AC
+ done
+ fi
+
case "$OUTPUT" in
1)
$IPT -I OUTPUT 1 -p tcp $EXT_ARGS \
@@ -251,8 +258,14 @@ tp_rule() {
$ipt -A SS_SPEC_TPROXY -p udp $PROXY_PORTS -j TPROXY --on-port "$LOCAL_PORT" --tproxy-mark 0x01/0x01
;;
esac
- $ipt -I PREROUTING 1 ${IFNAME:+-i $IFNAME} -p udp $EXT_ARGS $MATCH_SET \
- -m comment --comment "$TAG" -j SS_SPEC_TPROXY
+ if [ -z "$Interface" ]; then
+ $ipt -I PREROUTING 1 -p udp $EXT_ARGS $MATCH_SET -m comment --comment "$TAG" -j SS_SPEC_TPROXY
+ else
+ for name in $Interface;do
+ local IFNAME=$(uci -P /var/state get network.$name.ifname 2>/dev/null)
+ [ -n "$IFNAME" ] && $ipt -I PREROUTING 1 ${IFNAME:+-i $IFNAME} -p udp $EXT_ARGS $MATCH_SET -m comment --comment "$TAG" -j SS_SPEC_TPROXY
+ done
+ fi
return $?
}
@@ -304,8 +317,11 @@ gen_include() {
return 0
}
-while getopts ":s:l:S:L:i:e:a:B:b:w:p:G:D:F:N:M:I:oOuUfgrczh" arg; do
+while getopts ":m:s:l:S:L:i:e:a:B:b:w:p:G:D:F:N:M:I:oOuUfgrczh" arg; do
case "$arg" in
+ m)
+ Interface=$OPTARG
+ ;;
s)
server=$OPTARG
;;
diff --git a/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genvlessconfig.lua b/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genv2config.lua
similarity index 80%
rename from package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genvlessconfig.lua
rename to package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genv2config.lua
index d7aef0eb36..ec19fca71f 100644
--- a/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genvlessconfig.lua
+++ b/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genv2config.lua
@@ -5,17 +5,7 @@ local proto = arg[2]
local local_port = arg[3] or "0"
local socks_port = arg[4] or "0"
local server = ucursor:get_all("shadowsocksr", server_section)
-local outbound_security = "none"
-
-if (server.xtls == '1')
-then
- outbound_security = "xtls"
-elseif (server.tls == '1')
-then
- outbound_security = "tls"
-end
-
-local vless = {
+local Xray = {
log = {
-- error = "/var/ssrplus.log",
loglevel = "warning"
@@ -46,7 +36,7 @@ inboundDetour = (proto == "tcp" and socks_port ~= "0") and {
} or nil,
-- 传出连接
outbound = {
- protocol = "vless",
+ protocol = (server.type == "v2ray") and "vmess" or "vless",
settings = {
vnext = {
{
@@ -55,7 +45,9 @@ outbound = {
users = {
{
id = server.vmess_id,
+ alterId = (server.type == "v2ray") and tonumber(server.alter_id) or nil,
flow = (server.xtls == '1') and (server.vless_flow and server.vless_flow or "xtls-rprx-origin") or nil,
+ security = server.security,
encryption = server.vless_encryption
}
}
@@ -65,9 +57,9 @@ outbound = {
-- 底层传输配置
streamSettings = {
network = server.transport,
- security = outbound_security,
- tlsSettings = (outbound_security == "tls") and {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,} or nil,
- xtlsSettings = (outbound_security == "xtls") and {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,} or nil,
+ security = (server.tls == '1') and (server.xtls == '1') and "xtls" or "tls" or "none",
+ tlsSettings = (server.tls == '1') and {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,} or nil,
+ xtlsSettings = (server.xtls == '1') and {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,} or nil,
tcpSettings = (server.transport == "tcp") and {
header = {
type = server.tcp_guise,
@@ -110,11 +102,11 @@ outbound = {
}
} or nil
},
- mux = {
+ mux = (server.xtls ~= "1") and {
enabled = (server.mux == "1") and true or false,
concurrency = tonumber(server.concurrency)
}
-},
+} or nil,
-- 额外传出连接
outboundDetour = {
{
@@ -124,4 +116,4 @@ outboundDetour = {
}
}
}
-print(json.stringify(vless, 1))
\ No newline at end of file
+print(json.stringify(Xray, 1))
\ No newline at end of file
diff --git a/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genv2rayconfig.lua b/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genv2rayconfig.lua
deleted file mode 100644
index d41a77c648..0000000000
--- a/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genv2rayconfig.lua
+++ /dev/null
@@ -1,116 +0,0 @@
-local ucursor = require "luci.model.uci".cursor()
-local json = require "luci.jsonc"
-local server_section = arg[1]
-local proto = arg[2]
-local local_port = arg[3] or "0"
-local socks_port = arg[4] or "0"
-local server = ucursor:get_all("shadowsocksr", server_section)
-local v2ray = {
-log = {
--- error = "/var/ssrplus.log",
-loglevel = "warning"
-},
--- 传入连接
-inbound = (local_port ~= "0") and {
- port = local_port,
- protocol = "dokodemo-door",
- settings = {
- network = proto,
- followRedirect = true
- },
- sniffing = {
- enabled = true,
- destOverride = { "http", "tls" }
- }
-} or nil,
--- 开启 socks 代理
-inboundDetour = (proto == "tcp" and socks_port ~= "0") and {
- {
- protocol = "socks",
- port = socks_port,
- settings = {
- auth = "noauth",
- udp = true
- }
- }
-} or nil,
--- 传出连接
-outbound = {
- protocol = "vmess",
- settings = {
- vnext = {
- {
- address = server.server,
- port = tonumber(server.server_port),
- users = {
- {
- id = server.vmess_id,
- alterId = tonumber(server.alter_id),
- security = server.security
- }
- }
- }
- }
- },
- -- 底层传输配置
- streamSettings = {
- network = server.transport,
- security = (server.tls == '1') and "tls" or "none",
- tlsSettings = {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,},
- tcpSettings = (server.transport == "tcp") and {
- header = {
- type = server.tcp_guise,
- request = {
- path = server.http_path or {"/"},
- headers = {
- Host = server.http_host or {}
- }
- } or {}
- }
- } or nil,
- kcpSettings = (server.transport == "kcp") and {
- mtu = tonumber(server.mtu),
- tti = tonumber(server.tti),
- uplinkCapacity = tonumber(server.uplink_capacity),
- downlinkCapacity = tonumber(server.downlink_capacity),
- congestion = (server.congestion == "1") and true or false,
- readBufferSize = tonumber(server.read_buffer_size),
- writeBufferSize = tonumber(server.write_buffer_size),
- header = {
- type = server.kcp_guise
- },
- seed = server.seed or nil
- } or nil,
- wsSettings = (server.transport == "ws") and (server.ws_path ~= nil or server.ws_host ~= nil) and {
- path = server.ws_path,
- headers = (server.ws_host ~= nil) and {
- Host = server.ws_host
- } or nil,
- } or nil,
- httpSettings = (server.transport == "h2") and {
- path = server.h2_path,
- host = server.h2_host,
- } or nil,
- quicSettings = (server.transport == "quic") and {
- security = server.quic_security,
- key = server.quic_key,
- header = {
- type = server.quic_guise
- }
- } or nil
- },
- mux = {
- enabled = (server.mux == "1") and true or false,
- concurrency = tonumber(server.concurrency)
- }
-},
--- 额外传出连接
-outboundDetour = {
- {
- protocol = "freedom",
- tag = "direct",
- settings = { keep = "" }
- }
- }
-}
-print(json.stringify(v2ray, 1))
\ No newline at end of file
diff --git a/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genxrayconfig.lua b/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genxrayconfig.lua
deleted file mode 100644
index c60f5136b1..0000000000
--- a/package/lean/luci-app-ssr-plus/root/usr/share/shadowsocksr/genxrayconfig.lua
+++ /dev/null
@@ -1,127 +0,0 @@
-local ucursor = require "luci.model.uci".cursor()
-local json = require "luci.jsonc"
-local server_section = arg[1]
-local proto = arg[2]
-local local_port = arg[3] or "0"
-local socks_port = arg[4] or "0"
-local server = ucursor:get_all("shadowsocksr", server_section)
-local outbound_security = "none"
-
-if (server.xtls == '1')
-then
- outbound_security = "xtls"
-elseif (server.tls == '1')
-then
- outbound_security = "tls"
-end
-
-local vless = {
-log = {
--- error = "/var/ssrplus.log",
-loglevel = "warning"
-},
--- 传入连接
-inbound = (local_port ~= "0") and {
- port = local_port,
- protocol = "dokodemo-door",
- settings = {
- network = proto,
- followRedirect = true
- },
- sniffing = {
- enabled = true,
- destOverride = { "http", "tls" }
- }
-} or nil,
--- 开启 socks 代理
-inboundDetour = (proto == "tcp" and socks_port ~= "0") and {
- {
- protocol = "socks",
- port = socks_port,
- settings = {
- auth = "noauth",
- udp = true
- }
- }
-} or nil,
--- 传出连接
-outbound = {
- protocol = "vless",
- settings = {
- vnext = {
- {
- address = server.server,
- port = tonumber(server.server_port),
- users = {
- {
- id = server.vmess_id,
- flow = (server.xtls == '1') and (server.vless_flow and server.vless_flow or "xtls-rprx-origin") or nil,
- encryption = server.vless_encryption
- }
- }
- }
- }
- },
- -- 底层传输配置
- streamSettings = {
- network = server.transport,
- security = outbound_security,
- tlsSettings = (outbound_security == "tls") and {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,} or nil,
- xtlsSettings = (outbound_security == "xtls") and {allowInsecure = (server.insecure ~= "0") and true or false,serverName=server.tls_host,} or nil,
- tcpSettings = (server.transport == "tcp") and {
- header = {
- type = server.tcp_guise,
- request = {
- path = server.http_path or {"/"},
- headers = {
- Host = server.http_host or {}
- }
- } or {}
- }
- } or nil,
- kcpSettings = (server.transport == "kcp") and {
- mtu = tonumber(server.mtu),
- tti = tonumber(server.tti),
- uplinkCapacity = tonumber(server.uplink_capacity),
- downlinkCapacity = tonumber(server.downlink_capacity),
- congestion = (server.congestion == "1") and true or false,
- readBufferSize = tonumber(server.read_buffer_size),
- writeBufferSize = tonumber(server.write_buffer_size),
- header = {
- type = server.kcp_guise
- },
- seed = server.seed or nil
- } or nil,
- wsSettings = (server.transport == "ws") and (server.ws_path ~= nil or server.ws_host ~= nil) and {
- path = server.ws_path,
- headers = (server.ws_host ~= nil) and {
- Host = server.ws_host
- } or nil,
- } or nil,
- httpSettings = (server.transport == "h2") and {
- path = server.h2_path,
- host = server.h2_host,
- } or nil,
- quicSettings = (server.transport == "quic") and {
- security = server.quic_security,
- key = server.quic_key,
- header = {
- type = server.quic_guise
- }
- } or nil
- },
- mux = {
- enabled = (server.mux == "1") and true or false,
- concurrency = tonumber(server.concurrency)
- }
-},
--- 额外传出连接
-outboundDetour = {
- {
- protocol = "freedom",
- tag = "direct",
- settings = { keep = "" }
- }
- }
-}
-print(json.stringify(vless, 1))