4 Commits
Author SHA1 Message Date
root 520eca9548 fix: output rules 2026-04-15 00:27:26 +04:00
root b0c53fb678 fix: output rules 2026-04-15 00:17:45 +04:00
root b78e53ee23 fix: output routing 2026-04-15 00:11:52 +04:00
root 0553dc8d70 fix: tabulation 2026-04-15 00:10:24 +04:00
2 changed files with 17 additions and 10 deletions
+7 -7
View File
@@ -19,15 +19,15 @@ config xray-list
list ip '1.0.0.1' list ip '1.0.0.1'
config xray-list config xray-list
option name 'pc' option name 'pc'
option direction 'force_src' option direction 'force_src'
list ip '192.168.2.10' list ip '192.168.2.10'
config xray-list config xray-list
option name 'pc_exclude' option name 'pc_exclude'
option direction 'dst' option direction 'dst'
option exclude '1' option exclude '1'
option parent 'pc' option parent 'pc'
list domain 'ifconfig.io' list domain 'ifconfig.io'
config xray-list config xray-list
+10 -3
View File
@@ -79,6 +79,10 @@ _init_vars() {
_validate_config() { _validate_config() {
_log "config: validating uci syntax" "debug" _log "config: validating uci syntax" "debug"
if [ -f "/etc/config/xray-manager" ]; then
sed -i 's/^ \+/ /g' /etc/config/xray-manager
fi
local dns_confdir local dns_confdir
dns_confdir=$(uci -q get dhcp.@dnsmasq[0].confdir) dns_confdir=$(uci -q get dhcp.@dnsmasq[0].confdir)
if [ -z "$dns_confdir" ] || ! echo "$dns_confdir" | grep -q "$DNSMASQ_DIR"; then if [ -z "$dns_confdir" ] || ! echo "$dns_confdir" | grep -q "$DNSMASQ_DIR"; then
@@ -127,13 +131,13 @@ _nft_init() {
nft flush chain ip "$TABLE" prerouting nft flush chain ip "$TABLE" prerouting
nft add rule ip "$TABLE" prerouting fib daddr type local accept nft add rule ip "$TABLE" prerouting fib daddr type local accept
nft add chain ip "$TABLE" output { type filter hook output priority -150 \; policy accept \; } 2>/dev/null nft add chain ip "$TABLE" output { type route hook output priority -150 \; policy accept \; } 2>/dev/null
nft flush chain ip "$TABLE" output nft flush chain ip "$TABLE" output
nft add rule ip "$TABLE" output fib daddr type local accept nft add rule ip "$TABLE" output fib daddr type local accept
local mark_hex=$(printf '0x%x' "$TPROXY_MARK") local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug" _log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
ip route show table $RT_TABLE | grep -q "local default" || ip route add local default dev lo table $RT_TABLE ip route show table $RT_TABLE 2>/dev/null | grep -q "local default" || ip route add local default dev lo table $RT_TABLE
ip rule show | grep -q "fwmark $mark_hex lookup $RT_TABLE" || ip rule add fwmark "$TPROXY_MARK" table $RT_TABLE ip rule show | grep -q "fwmark $mark_hex lookup $RT_TABLE" || ip rule add fwmark "$TPROXY_MARK" table $RT_TABLE
} }
@@ -355,7 +359,10 @@ _run() {
config_foreach _process_section "xray-list" "exclude" config_foreach _process_section "xray-list" "exclude"
_log "main: applying proxy bypass" "debug" _log "main: applying proxy bypass" "debug"
[ -n "$PROXY_SERVERS" ] && nft add rule ip "$TABLE" output ip daddr "@s_proxy_servers" accept 2>/dev/null if [ -n "$PROXY_SERVERS" ]; then
_process_item "proxy_servers" "$PROXY_SERVERS" "ip" "out" "0"
nft add rule ip "$TABLE" output ip daddr "@s_proxy_servers" accept 2>/dev/null
fi
_log "main: applying tproxy rules" "debug" _log "main: applying tproxy rules" "debug"
mode_chain="prerouting"; config_foreach _process_section "xray-list" "main_rules" mode_chain="prerouting"; config_foreach _process_section "xray-list" "main_rules"