2020-09-18 21:09:06 +08:00
#!/bin/sh
2020-08-22 20:08:23 +08:00
# Copyright (C) Juewuy
2023-06-04 12:29:31 +08:00
#初始化目录
[ -d "/etc/storage/clash" ] && clashdir = /etc/storage/clash
[ -d "/jffs/clash" ] && clashdir = /jffs/clash
[ -z " $clashdir " ] && clashdir = $( cat /etc/profile | grep clashdir | awk -F "\"" '{print $2}' )
[ -z " $clashdir " ] && clashdir = $( cat ~/.bashrc | grep clashdir | awk -F "\"" '{print $2}' )
tmpdir = /tmp/clash_$USER && [ ! -f $tmpdir ] && mkdir -p $tmpdir
2020-10-30 16:21:09 +08:00
#脚本内部工具
2020-08-22 20:08:23 +08:00
getconfig( ) {
2020-10-23 19:08:35 +08:00
#加载配置文件
2023-06-03 22:31:33 +08:00
source $clashdir /mark & > /dev/null
2020-10-23 19:08:35 +08:00
#默认设置
2020-10-30 16:21:09 +08:00
[ -z " $bindir " ] && bindir = $clashdir
2020-10-27 09:40:58 +08:00
[ -z " $redir_mod " ] && [ " $USER " = "root" -o " $USER " = "admin" ] && redir_mod = Redir模式
2022-02-06 19:14:05 +08:00
[ -z " $redir_mod " ] && redir_mod = 纯净模式
2020-10-23 19:08:35 +08:00
[ -z " $skip_cert " ] && skip_cert = 已开启
[ -z " $dns_mod " ] && dns_mod = redir_host
2022-12-04 20:54:09 +08:00
[ -z " $ipv6_support " ] && ipv6_support = 已开启
[ -z " $ipv6_redir " ] && ipv6_redir = 未开启
2022-11-25 21:47:03 +08:00
[ -z " $ipv6_dns " ] && ipv6_dns = 已开启
2022-12-21 11:23:23 +08:00
[ -z " $cn_ipv6_route " ] && cn_ipv6_route = 未开启
2020-10-23 19:08:35 +08:00
[ -z " $mix_port " ] && mix_port = 7890
[ -z " $redir_port " ] && redir_port = 7892
2022-11-12 22:54:46 +08:00
[ -z " $tproxy_port " ] && tproxy_port = 7893
2020-10-23 19:08:35 +08:00
[ -z " $db_port " ] && db_port = 9999
[ -z " $dns_port " ] && dns_port = 1053
2023-04-26 21:24:26 +08:00
[ -z " $fwmark " ] && fwmark = $redir_port
2022-11-20 20:12:37 +08:00
[ -z " $sniffer " ] && sniffer = 已开启
2020-10-23 19:08:35 +08:00
#是否代理常用端口
2022-05-12 23:23:18 +08:00
[ -z " $common_ports " ] && common_ports = 已开启
2023-01-08 22:03:36 +08:00
[ -z " $multiport " ] && multiport = '22,53,80,123,143,194,443,465,587,853,993,995,5222,8080,8443'
2020-12-08 20:37:49 +08:00
[ " $common_ports " = "已开启" ] && ports = " -m multiport --dports $multiport "
2022-05-12 23:23:18 +08:00
}
2020-10-30 16:21:09 +08:00
setconfig( ) {
#参数1代表变量名, 参数2代表变量值,参数3即文件路径
[ -z " $3 " ] && configpath = $clashdir /mark || configpath = $3
2020-12-14 16:38:14 +08:00
[ -n " $( grep ${ 1 } $configpath ) " ] && sed -i " s# ${ 1 } =.*# ${ 1 } = ${ 2 } #g " $configpath || echo " ${ 1 } = ${ 2 } " >> $configpath
2020-10-30 16:21:09 +08:00
}
2023-01-15 20:58:15 +08:00
ckcmd( ) {
command -v sh & >/dev/null && command -v $1 & >/dev/null || type $1 & >/dev/null
}
2020-11-07 12:08:31 +08:00
compare( ) {
2020-12-13 16:40:19 +08:00
if [ ! -f $1 -o ! -f $2 ] ; then
return 1
2023-01-15 20:58:15 +08:00
elif ckcmd cmp; then
2020-11-07 12:08:31 +08:00
cmp -s $1 $2
else
[ " $( cat $1 ) " = " $( cat $2 ) " ] && return 0 || return 1
fi
}
2020-10-24 09:54:14 +08:00
logger( ) {
2023-04-12 21:03:18 +08:00
#$1日志内容$2显示颜色$3是否推送
2020-10-30 16:21:09 +08:00
[ -n " $2 " ] && echo -e " \033[ $2 m $1 \033[0m "
2022-12-04 20:54:09 +08:00
log_text = " $( date "+%G-%m-%d_%H:%M:%S" ) ~ $1 "
2023-06-04 12:29:31 +08:00
echo $log_text >> $tmpdir /ShellClash_log
[ " $( wc -l $tmpdir /ShellClash_log | awk '{print $1}' ) " -gt 99 ] && sed -i '1,5d' $tmpdir /ShellClash_log
2022-12-08 20:36:56 +08:00
[ -z " $3 " ] && {
getconfig
2023-04-12 21:03:18 +08:00
[ -n " $device_name " ] && log_text = " $log_text ( $device_name ) "
2023-04-25 20:37:57 +08:00
[ -n " $( pidof clash) " ] && {
2022-12-08 20:36:56 +08:00
[ -n " $authentication " ] && auth = " $authentication @ "
export https_proxy = " http:// ${ auth } 127.0.0.1: $mix_port "
}
[ -n " $push_TG " ] && {
url = https://api.telegram.org/bot${ push_TG } /sendMessage
curl_data = " -d chat_id= $chat_ID &text= $log_text "
wget_data = " --post-data= $chat_ID &text= $log_text "
if curl --version & > /dev/null; then
curl -kfsSl --connect-timeout 3 -d " chat_id= $chat_ID &text= $log_text " " $url " & >/dev/null
else
wget -Y on -q --timeout= 3 -t 1 --post-data= " chat_id= $chat_ID &text= $log_text " " $url "
fi
}
[ -n " $push_bark " ] && {
2023-06-07 13:56:55 +08:00
url = ${ push_bark } /${ log_text } ${ bark_param }
2022-12-08 20:36:56 +08:00
if curl --version & > /dev/null; then
curl -kfsSl --connect-timeout 3 " $url " & >/dev/null
else
wget -Y on -q --timeout= 3 -t 1 " $url "
fi
}
2022-12-09 22:40:11 +08:00
[ -n " $push_Deer " ] && {
url = https://api2.pushdeer.com/message/push?pushkey= ${ push_Deer }
if curl --version & > /dev/null; then
curl -kfsSl --connect-timeout 3 " $url " \& text = " $log_text " & >/dev/null
else
wget -Y on -q --timeout= 3 -t 1 " $url " \& text = " $log_text "
fi
}
2022-12-08 20:36:56 +08:00
[ -n " $push_Po " ] && {
url = https://api.pushover.net/1/messages.json
curl -kfsSl --connect-timeout 3 --form-string " token= $push_Po " --form-string " user= $push_Po_key " --form-string " message= $log_text " " $url " & >/dev/null
}
} &
2020-10-24 09:54:14 +08:00
}
2021-06-25 00:23:32 +08:00
croncmd( ) {
if [ -n " $( crontab -h 2>& 1 | grep '\-l' ) " ] ; then
crontab $1
else
crondir = " $( crond -h 2>& 1 | grep -oE 'Default:.*' | awk -F ":" '{print $2}' ) "
[ ! -w " $crondir " ] && crondir = "/etc/storage/cron/crontabs"
[ ! -w " $crondir " ] && crondir = "/var/spool/cron/crontabs"
[ ! -w " $crondir " ] && crondir = "/var/spool/cron"
2023-02-28 19:45:06 +08:00
[ ! -w " $crondir " ] && echo "你的设备不支持定时任务配置,脚本大量功能无法启用,请尝试使用搜索引擎查找安装方式!"
2021-06-25 00:23:32 +08:00
[ " $1 " = "-l" ] && cat $crondir /$USER 2>/dev/null
[ -f " $1 " ] && cat $1 > $crondir /$USER
fi
}
2020-10-27 09:40:58 +08:00
cronset( ) {
# 参数1代表要移除的关键字,参数2代表要添加的任务语句
2023-06-04 12:29:31 +08:00
tmpcron = $tmpdir /cron_$USER
2021-06-24 23:16:28 +08:00
croncmd -l > $tmpcron
sed -i " / $1 /d " $tmpcron
sed -i '/^$/d' $tmpcron
echo " $2 " >> $tmpcron
croncmd $tmpcron
rm -f $tmpcron
2020-10-27 09:40:58 +08:00
}
2023-05-13 20:43:15 +08:00
get_save( ) {
if curl --version > /dev/null 2>& 1; then
curl -s -H " Authorization: Bearer ${ secret } " -H "Content-Type:application/json" " $1 "
elif [ -n " $( wget --help 2>& 1| grep '\-\-method' ) " ] ; then
wget -q --header= " Authorization: Bearer ${ secret } " --header= "Content-Type:application/json" -O - " $1 "
fi
}
2022-06-06 13:03:42 +08:00
put_save( ) {
if curl --version > /dev/null 2>& 1; then
curl -sS -X PUT -H " Authorization: Bearer ${ secret } " -H "Content-Type:application/json" " $1 " -d " $2 " >/dev/null
elif wget --version > /dev/null 2>& 1; then
wget -q --method= PUT --header= " Authorization: Bearer ${ secret } " --header= "Content-Type:application/json" --body-data= " $2 " " $1 " >/dev/null
fi
}
2020-10-28 11:09:26 +08:00
mark_time( ) {
2023-06-04 12:29:31 +08:00
echo ` date +%s` > $tmpdir /clash_start_time
2022-03-16 15:00:11 +08:00
}
2023-04-02 19:46:08 +08:00
getlanip( ) {
2023-05-13 20:43:15 +08:00
i = 1
while [ " $i " -le "10" ] ; do
host_ipv4 = $( ip a 2>& 1 | grep -w 'inet' | grep 'global' | grep 'br' | grep -v 'iot' | grep -E ' 1(92|0|72)\.' | sed 's/.*inet.//g' | sed 's/br.*$//g' ) #ipv4局域网网段
host_ipv6 = $( ip a 2>& 1 | grep -w 'inet6' | grep -E 'global' | sed 's/.*inet6.//g' | sed 's/scope.*$//g' ) #ipv6公网地址段
[ -n " $host_ipv4 " -a -n " $host_ipv6 " ] && break
2023-06-04 12:29:31 +08:00
[ -f $tmpdir /ShellClash_log ] && break
2023-05-13 20:43:15 +08:00
sleep 2 && i = $(( i+1))
done
2023-04-16 21:27:25 +08:00
#添加自定义ipv4局域网网段
host_ipv4 = " $host_ipv4 $cust_host_ipv4 "
2023-04-02 19:46:08 +08:00
#缺省配置
[ -z " $host_ipv4 " ] && host_ipv4 = '192.168.0.0/16 10.0.0.0/12 172.16.0.0/12'
[ -z " $host_ipv6 " ] && host_ipv6 = 'fe80::/10 fd00::/8'
2023-04-03 21:46:24 +08:00
#获取本机出口IP地址
2023-05-13 20:43:15 +08:00
local_ipv4 = $( ip route 2>& 1 | grep 'src' | grep -Ev 'utun|iot|docker' | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3} $' | sed 's/.*src //g' )
2023-04-04 20:45:35 +08:00
[ -z " $local_ipv4 " ] && local_ipv4 = $( ip route 2>& 1 | grep -Eo 'src.*' | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | sort -u )
2023-04-02 19:46:08 +08:00
#保留地址
reserve_ipv4 = "0.0.0.0/8 10.0.0.0/8 127.0.0.0/8 100.64.0.0/10 169.254.0.0/16 172.16.0.0/12 192.168.0.0/16 224.0.0.0/4 240.0.0.0/4"
reserve_ipv6 = "::/128 ::1/128 ::ffff:0:0/96 64:ff9b::/96 100::/64 2001::/32 2001:20::/28 2001:db8::/32 2002::/16 fc00::/7 fe80::/10 ff00::/8"
2022-04-28 22:03:31 +08:00
}
2020-10-28 11:09:26 +08:00
#配置文件相关
2020-09-18 21:09:06 +08:00
getyaml( ) {
2020-10-27 09:40:58 +08:00
[ -z " $rule_link " ] && rule_link = 1
[ -z " $server_link " ] && server_link = 1
2020-10-23 19:08:35 +08:00
#前后端订阅服务器地址索引,可在此处添加!
Server = ` sed -n "" $server_link "p" <<EOF
2022-01-02 20:39:18 +08:00
https://api.dler.io
2022-12-12 19:23:11 +08:00
https://api.v1.mk
2022-04-10 21:36:58 +08:00
https://sub.xeton.dev
2022-12-12 19:23:11 +08:00
https://v.id9.cc
2022-01-08 20:19:50 +08:00
https://sub.maoxiongnet.com
2023-02-01 10:13:35 +08:00
http://sub2.jwsc.eu.org
2020-10-24 09:54:14 +08:00
EOF`
2020-10-23 19:08:35 +08:00
Config = ` sed -n "" $rule_link "p" <<EOF
2022-01-08 18:12:20 +08:00
https://github.com/juewuy/ShellClash/raw/master/rules/ShellClash.ini
https://github.com/juewuy/ShellClash/raw/master/rules/ShellClash_Mini.ini
2022-01-08 20:19:50 +08:00
https://github.com/juewuy/ShellClash/raw/master/rules/ShellClash_Block.ini
https://github.com/juewuy/ShellClash/raw/master/rules/ShellClash_Nano.ini
https://github.com/juewuy/ShellClash/raw/master/rules/ShellClash_Full.ini
https://github.com/juewuy/ShellClash/raw/master/rules/ShellClash_Full_Block.ini
2020-10-24 09:54:14 +08:00
https://gist.githubusercontent.com/tindy2013/1fa08640a9088ac8652dbd40c5d2715b/raw/lhie1_clash.ini
https://gist.githubusercontent.com/tindy2013/1fa08640a9088ac8652dbd40c5d2715b/raw/lhie1_dler.ini
2023-05-13 20:43:15 +08:00
https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/config/ACL4SSR_Online_Mini_MultiCountry.ini
https://raw.githubusercontent.com/ACL4SSR/ACL4SSR/master/Clash/config/ACL4SSR_BackCN.ini
2020-10-24 09:54:14 +08:00
EOF`
2020-10-23 19:08:35 +08:00
#如果传来的是Url链接则合成Https链接, 否则直接使用Https链接
2023-04-03 21:46:24 +08:00
if [ -z " $Https " ] ; then
[ -n " $( echo $Url | grep -oE 'vless:' ) " -a -z " $retry " ] && Server = 'https://api.v1.mk'
[ -n " $( echo $Url | grep -oE 'hysteria:' ) " -a -z " $retry " ] && Server = 'https://sub.jwsc.eu.org'
2022-01-02 20:39:18 +08:00
Https = " $Server /sub?target=clash&insert=true&new_name=true&scv=true&udp=true&exclude= $exclude &include= $include &url= $Url &config= $Config "
2022-04-10 21:36:58 +08:00
url_type = true
2020-10-23 19:08:35 +08:00
fi
2020-10-24 09:54:14 +08:00
#输出
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2022-12-04 20:54:09 +08:00
logger 正在连接服务器获取配置文件…………
echo -e " 链接地址为:\033[4;32m $Https \033[0m "
2020-10-23 19:08:35 +08:00
echo 可以手动复制该链接到浏览器打开并查看数据是否正常!
#获取在线yaml文件
yaml = $clashdir /config.yaml
2023-06-04 12:29:31 +08:00
yamlnew = $tmpdir /clash_config_$USER .yaml
2020-10-24 09:54:14 +08:00
rm -rf $yamlnew
2022-01-31 14:39:32 +08:00
$0 webget $yamlnew $Https
2021-06-19 15:23:20 +08:00
if [ " $? " = "1" ] ; then
2022-04-10 21:36:58 +08:00
if [ -z " $url_type " ] ; then
2020-10-24 09:54:14 +08:00
echo -----------------------------------------------
2020-10-30 16:21:09 +08:00
logger "配置文件获取失败!" 31
2021-05-31 16:03:30 +08:00
echo -e "\033[31m请尝试使用【在线生成配置文件】功能! \033[0m"
2020-10-24 09:54:14 +08:00
echo -----------------------------------------------
2020-10-10 17:02:53 +08:00
exit 1
else
2023-04-03 21:46:24 +08:00
if [ " $retry " = 4 ] ; then
2020-10-30 16:21:09 +08:00
logger "无法获取配置文件,请检查链接格式以及网络连接状态!" 31
2023-06-04 12:29:31 +08:00
echo -e " \033[32m你也可以尝试使用浏览器下载配置文件后, 使用WinSCP手动上传到 $tmpdir目录 ! \033[0m"
2020-10-23 19:08:35 +08:00
exit 1
2022-11-25 21:47:03 +08:00
elif [ " $retry " = 3 ] ; then
2022-12-04 20:54:09 +08:00
retry = 4
2023-03-17 23:32:30 +08:00
logger "配置文件获取失败! 将尝试使用http协议备用服务器获取! " 31
echo -e "\033[32m如担心数据安全, 请在5s内使用【ctrl+c】退出! \033[0m"
2022-11-25 21:47:03 +08:00
sleep 5
server_link = 6
Https = ""
getyaml
2020-10-23 19:08:35 +08:00
else
retry = $(( retry+1))
2020-10-30 16:21:09 +08:00
logger "配置文件获取失败!" 31
2020-10-23 19:08:35 +08:00
echo -e "\033[32m尝试使用其他服务器获取配置! \033[0m"
2022-12-04 20:54:09 +08:00
logger " 正在重试第 $retry次 /共4次! " 33
2020-10-23 19:08:35 +08:00
if [ " $server_link " -ge 5 ] ; then
server_link = 0
fi
server_link = $(( server_link+1))
2023-01-13 20:36:52 +08:00
setconfig server_link $server_link
2020-10-23 19:08:35 +08:00
Https = ""
getyaml
2020-09-18 21:09:06 +08:00
fi
fi
2020-10-23 19:08:35 +08:00
else
Https = ""
2020-11-15 13:01:29 +08:00
#检测节点或providers
2021-05-29 16:50:55 +08:00
if [ -z " $( cat $yamlnew | grep -E 'server|proxy-providers' | grep -v 'nameserver' | head -n 1) " ] ; then
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2020-10-30 16:21:09 +08:00
logger "获取到了配置文件,但似乎并不包含正确的节点信息!" 31
2020-10-23 19:08:35 +08:00
echo -----------------------------------------------
sed -n '1,30p' $yamlnew
echo -----------------------------------------------
echo -e "\033[33m请检查如上配置文件信息:\033[0m"
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2020-10-23 19:08:35 +08:00
exit 1
fi
#检测旧格式
if cat $yamlnew | grep 'Proxy Group:' >/dev/null; then
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2020-10-30 16:21:09 +08:00
logger "已经停止对旧格式配置文件的支持!!!" 31
2022-01-08 17:21:06 +08:00
echo -e "请使用新格式或者使用【在线生成配置文件】功能!"
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2020-10-23 19:08:35 +08:00
exit 1
2020-10-01 18:45:26 +08:00
fi
2020-10-23 19:08:35 +08:00
#检测不支持的加密协议
2022-11-16 19:49:02 +08:00
if cat $yamlnew | grep 'cipher: chacha20,' >/dev/null; then
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2020-12-11 22:17:29 +08:00
logger "已停止支持chacha20加密, 请更换更安全的节点加密协议! " 31
2020-10-27 16:36:01 +08:00
echo -----------------------------------------------
2020-10-23 19:08:35 +08:00
exit 1
fi
2022-03-26 02:11:09 +08:00
#检测并去除无效节点组
2023-01-15 20:58:15 +08:00
[ -n " $url_type " ] && ckcmd xargs && {
2023-06-04 12:29:31 +08:00
cat $yamlnew | sed '/^rules:/,$d' | grep -A 15 "\- name:" | xargs | sed 's/- name: /\n/g' | sed 's/ type: .*proxies: /#/g' | sed 's/- //g' | grep -E '#DIRECT $|#DIRECT$' | awk -F '#' '{print $1}' > $tmpdir /clash_proxies_$USER
2022-12-07 22:07:37 +08:00
while read line ; do
sed -i " /- $line /d " $yamlnew
sed -i " /- name: $line /,/- DIRECT/d " $yamlnew
2023-06-04 12:29:31 +08:00
done < $tmpdir /clash_proxies_$USER
rm -rf $tmpdir /clash_proxies_$USER
2022-04-10 21:36:58 +08:00
}
2020-12-11 22:17:29 +08:00
#使用核心内置test功能检测
if [ -x $bindir /clash ] ; then
$bindir /clash -t -d $bindir -f $yamlnew >/dev/null
if [ " $? " != "0" ] ; then
logger "配置文件加载失败!请查看报错信息!" 31
$bindir /clash -t -d $bindir -f $yamlnew
echo " $( $bindir /clash -t -d $bindir -f $yamlnew ) " >> $clashdir /log
exit 1
fi
fi
2020-10-27 16:36:01 +08:00
#如果不同则备份并替换文件
if [ -f $yaml ] ; then
2020-11-07 12:08:31 +08:00
compare $yamlnew $yaml
2020-12-11 22:17:29 +08:00
[ " $? " = 0 ] || mv -f $yaml $yaml .bak && mv -f $yamlnew $yaml
2020-10-27 16:36:01 +08:00
else
mv -f $yamlnew $yaml
fi
2020-12-11 22:17:29 +08:00
echo -e "\033[32m已成功获取配置文件! \033[0m"
2020-09-18 21:09:06 +08:00
fi
}
2020-08-22 20:08:23 +08:00
modify_yaml( ) {
##########需要变更的配置###########
2022-05-12 23:23:18 +08:00
[ -z " $dns_nameserver " ] && dns_nameserver = '114.114.114.114, 223.5.5.5'
[ -z " $dns_fallback " ] && dns_fallback = '1.0.0.1, 8.8.4.4'
[ -z " $skip_cert " ] && skip_cert = 已开启
#默认fake-ip过滤列表
fake_ft_df = '"*.lan", "time.windows.com", "time.nist.gov", "time.apple.com", "time.asia.apple.com", "*.ntp.org.cn", "*.openwrt.pool.ntp.org", "time1.cloud.tencent.com", "time.ustc.edu.cn", "pool.ntp.org", "ntp.ubuntu.com", "ntp.aliyun.com", "ntp1.aliyun.com", "ntp2.aliyun.com", "ntp3.aliyun.com", "ntp4.aliyun.com", "ntp5.aliyun.com", "ntp6.aliyun.com", "ntp7.aliyun.com", "time1.aliyun.com", "time2.aliyun.com", "time3.aliyun.com", "time4.aliyun.com", "time5.aliyun.com", "time6.aliyun.com", "time7.aliyun.com", "*.time.edu.cn", "time1.apple.com", "time2.apple.com", "time3.apple.com", "time4.apple.com", "time5.apple.com", "time6.apple.com", "time7.apple.com", "time1.google.com", "time2.google.com", "time3.google.com", "time4.google.com", "music.163.com", "*.music.163.com", "*.126.net", "musicapi.taihe.com", "music.taihe.com", "songsearch.kugou.com", "trackercdn.kugou.com", "*.kuwo.cn", "api-jooxtt.sanook.com", "api.joox.com", "joox.com", "y.qq.com", "*.y.qq.com", "streamoc.music.tc.qq.com", "mobileoc.music.tc.qq.com", "isure.stream.qqmusic.qq.com", "dl.stream.qqmusic.qq.com", "aqqmusic.tc.qq.com", "amobile.music.tc.qq.com", "*.xiami.com", "*.music.migu.cn", "music.migu.cn", "*.msftconnecttest.com", "*.msftncsi.com", "localhost.ptlogin2.qq.com", "*.*.*.srv.nintendo.net", "*.*.stun.playstation.net", "xbox.*.*.microsoft.com", "*.*.xboxlive.com", "proxy.golang.org","*.sgcc.com.cn","*.alicdn.com","*.aliyuncs.com"'
2020-10-23 19:08:35 +08:00
lan = 'allow-lan: true'
log = 'log-level: info'
[ " $ipv6_support " = "已开启" ] && ipv6 = 'ipv6: true' || ipv6 = 'ipv6: false'
2022-12-04 20:54:09 +08:00
[ " $ipv6_dns " = "已开启" ] && dns_v6 = 'ipv6: true' || dns_v6 = 'ipv6: false'
2020-10-23 19:08:35 +08:00
external = " external-controller: 0.0.0.0: $db_port "
[ -d $clashdir /ui ] && db_ui = ui
2022-01-08 17:21:06 +08:00
if [ " $redir_mod " = "混合模式" -o " $redir_mod " = "Tun模式" ] ; then
2022-05-04 22:28:09 +08:00
[ " $clashcore " = 'clash.meta' ] && tun_meta = ', device: utun, auto-route: false'
tun = " tun: {enable: true, stack: system $tun_meta } "
2022-01-08 17:21:06 +08:00
else
tun = 'tun: {enable: false}'
fi
2020-10-23 19:08:35 +08:00
exper = 'experimental: {ignore-resolve-fail: true, interface-name: en0}'
2023-02-28 19:45:06 +08:00
#Meta内核专属配置
[ " $clashcore " = 'clash.meta' ] && {
find_process = 'find-process-mode: "off"'
}
2020-10-23 19:08:35 +08:00
#dns配置
2022-11-20 20:12:37 +08:00
[ -z " $( cat $clashdir /user.yaml 2>/dev/null | grep '^dns:' ) " ] && {
[ " $clashcore " = 'clash.meta' ] && dns_default_meta = ', https://1.0.0.1/dns-query, https://223.5.5.5/dns-query'
dns_default = " 114.114.114.114, 223.5.5.5 $dns_default_meta "
if [ -f $clashdir /fake_ip_filter ] ; then
while read line; do
fake_ft_ad = $fake_ft_ad ,\" $line \"
done < $clashdir /fake_ip_filter
fi
if [ " $dns_mod " = "fake-ip" ] ; then
2022-11-25 21:47:03 +08:00
dns = 'dns: {enable: true, ' $dns_v6 ', listen: 0.0.0.0:' $dns_port ', use-hosts: true, fake-ip-range: 198.18.0.1/16, enhanced-mode: fake-ip, fake-ip-filter: [' ${ fake_ft_df } ${ fake_ft_ad } '], default-nameserver: [' $dns_default ', 127.0.0.1:53], nameserver: [' $dns_nameserver ', 127.0.0.1:53], fallback: [' $dns_fallback '], fallback-filter: {geoip: true}}'
2022-11-20 20:12:37 +08:00
else
dns = 'dns: {enable: true, ' $dns_v6 ', listen: 0.0.0.0:' $dns_port ', use-hosts: true, enhanced-mode: redir-host, default-nameserver: [' $dns_default ', 127.0.0.1:53], nameserver: [' $dns_nameserver $dns_local '], fallback: [' $dns_fallback '], fallback-filter: {geoip: true}}'
fi
}
2023-01-01 20:25:30 +08:00
#域名嗅探配置
2023-04-26 21:24:26 +08:00
[ " $sniffer " = "已启用" ] && [ " $clashcore " = "clash.meta" ] && sniffer_set = "sniffer: {enable: true, skip-domain: [Mijia Cloud], sniff: {tls: {ports: [443, 8443]}, http: {ports: [80, 8080-8880]}}}"
2023-01-01 20:25:30 +08:00
[ " $clashcore " = "clashpre" ] && [ " $dns_mod " = "redir_host" ] && exper = "experimental: {ignore-resolve-fail: true, interface-name: en0, sniff-tls-sni: true}"
2020-10-30 16:21:09 +08:00
#设置目录
2020-10-06 17:56:17 +08:00
yaml = $clashdir /config.yaml
2022-01-30 12:50:25 +08:00
#预读取变量
mode = $( grep "^mode" $yaml | head -1 | awk '{print $2}' )
[ -z " $mode " ] && mode = 'Rule'
2022-12-15 20:49:57 +08:00
#分割配置文件
2023-06-03 22:31:33 +08:00
yaml_char = 'proxies proxy-groups proxy-providers rules rule-providers'
for char in $yaml_char ; do
sed -n " /^ $char :/,/^[a-z]/ { /^[a-z]/d; p; } " $yaml > $tmpdir /${ char } .yaml
done
2020-08-22 20:08:23 +08:00
#跳过本地tls证书验证
2023-06-03 22:31:33 +08:00
[ " $skip_cert " = "已开启" ] && sed -i 's/skip-cert-verify: false/skip-cert-verify: true/' $tmpdir /proxies.yaml || \
sed -i 's/skip-cert-verify: true/skip-cert-verify: false/' $tmpdir /proxies.yaml
#插入自定义策略组
sed -i "/#自定义策略组开始/,/#自定义策略组结束/d" $tmpdir /proxy-groups.yaml
[ -f $clashdir /proxy-groups.yaml ] && {
#获取空格数
space_name = $( grep -E '^ *- name: ' $tmpdir /proxy-groups.yaml | head -n 1 | grep -oE '^ *' )
space_proxy = $( grep -A 1 'proxies:$' $tmpdir /proxy-groups.yaml | grep -E '^ *- ' | head -n 1 | grep -oE '^ *' )
#合并自定义策略组到proxy-groups.yaml
cat $clashdir /proxy-groups.yaml | sed "/^#/d" | sed '1i\ #自定义策略组开始' | sed '$a\ #自定义策略组结束' | sed " s/^ */ ${ space_name } /g " | sed " s/^ *- / ${ space_proxy } - /g " | sed " s/^ *- name: / ${ space_name } - name: /g " > $tmpdir /proxy-groups_add.yaml
cat $tmpdir /proxy-groups.yaml >> $tmpdir /proxy-groups_add.yaml
mv -f $tmpdir /proxy-groups_add.yaml $tmpdir /proxy-groups.yaml
oldIFS = " $IFS "
2023-06-04 12:29:31 +08:00
grep "\- name: " $clashdir /proxy-groups.yaml | sed "/^#/d" | while read line; do #将自定义策略组插入现有的proxy-group
2023-06-03 22:31:33 +08:00
new_group = $( echo $line | grep -Eo '^ *- name:.*#' | cut -d'#' -f1 | sed 's/.*name: //g' )
proxy_groups = $( echo $line | grep -Eo '#.*' | sed "s/#//" )
IFS = "#"
for name in $proxy_groups ; do
line_a = $( grep -n " \- name: $name " $tmpdir /proxy-groups.yaml | awk -F: '{print $1}' ) #获取group行号
line_b = $( grep -A 8 " \- name: $name " $tmpdir /proxy-groups.yaml | grep -n " proxies: $" | awk -F: '{print $1}' ) #获取proxies行号
line_c = $(( line_a + line_b - 1 )) #计算需要插入的行号
space = $( sed -n " $(( line_c + 1 )) p " $tmpdir /proxy-groups.yaml | grep -oE '^ *' ) #获取空格数
sed -i " ${ line_c } a\\ ${ space } - ${ new_group } #自定义策略组 " $tmpdir /proxy-groups.yaml
done
IFS = " $oldIFS "
2023-06-04 12:29:31 +08:00
done
2023-06-03 22:31:33 +08:00
}
#插入自定义代理
sed -i "/#自定义代理/d" $tmpdir /proxies.yaml
[ -f $clashdir /proxies.yaml ] && {
space_proxy = $( cat $tmpdir /proxies.yaml | grep -E '^ *- ' | head -n 1 | grep -oE '^ *' ) #获取空格数
cat $clashdir /proxies.yaml | sed " s/^ *- / ${ space_proxy } - /g " | sed "/^#/d" | sed '$a\' | sed 's/#.*/ #自定义代理/g' >> $tmpdir /proxies.yaml #插入节点
oldIFS = " $IFS "
2023-06-04 12:29:31 +08:00
cat $clashdir /proxies.yaml | sed "/^#/d" | while read line; do #将节点插入proxy-group
2023-06-03 22:31:33 +08:00
proxy_name = $( echo $line | grep -Eo 'name: .+, ' | cut -d',' -f1 | sed 's/name: //g' )
proxy_groups = $( echo $line | grep -Eo '#.*' | sed "s/#//" )
IFS = "#"
for name in $proxy_groups ; do
line_a = $( grep -n " \- name: $name " $tmpdir /proxy-groups.yaml | awk -F: '{print $1}' ) #获取group行号
line_b = $( grep -A 8 " \- name: $name " $tmpdir /proxy-groups.yaml | grep -n " proxies: $" | awk -F: '{print $1}' ) #获取proxies行号
line_c = $(( line_a + line_b - 1 )) #计算需要插入的行号
space = $( sed -n " $(( line_c + 1 )) p " $tmpdir /proxy-groups.yaml | grep -oE '^ *' ) #获取空格数
sed -i " ${ line_c } a\\ ${ space } - ${ proxy_name } #自定义代理 " $tmpdir /proxy-groups.yaml
done
IFS = " $oldIFS "
2023-06-04 12:29:31 +08:00
done
2023-06-03 22:31:33 +08:00
}
2022-12-15 20:49:57 +08:00
#节点绕过功能支持
2023-06-03 22:31:33 +08:00
sed -i "/#节点绕过/d" $tmpdir /rules.yaml
2022-12-15 20:49:57 +08:00
[ " $proxies_bypass " = "已启用" ] && {
2023-06-04 20:10:33 +08:00
cat $tmpdir /proxies.yaml | sed '/^proxy-/,$d' | sed '/^rule-/,$d' | grep -oE '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | awk '!a[$0]++' | sed 's/^/\ -\ IP-CIDR,/g' | sed 's|$|/32,DIRECT #节点绕过|g' >> $tmpdir /proxies_bypass
cat $tmpdir /proxies.yaml | sed '/^proxy-/,$d' | sed '/^rule-/,$d' | grep -vE '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | grep -oE '[a-zA-Z0-9][-a-zA-Z0-9]{0,62}(\.[a-zA-Z0-9][-a-zA-Z0-9]{0,62})+\.?' | awk '!a[$0]++' | sed 's/^/\ -\ DOMAIN,/g' | sed 's/$/,DIRECT #节点绕过/g' >> $tmpdir /proxies_bypass
2023-06-03 22:31:33 +08:00
cat $tmpdir /rules.yaml >> $tmpdir /proxies_bypass
mv -f $tmpdir /proxies_bypass $tmpdir /rules.yaml
2022-12-15 20:49:57 +08:00
}
#插入自定义规则
2023-06-03 22:31:33 +08:00
sed -i "/#自定义规则/d" $tmpdir /rules.yaml
2022-12-15 20:49:57 +08:00
[ -f $clashdir /rules.yaml ] && {
2023-06-03 22:31:33 +08:00
cat $clashdir /rules.yaml | sed 's/^ *-/ -/g' | sed "/^#/d" | sed '$a\' | sed 's/$/ #自定义规则/g' > $tmpdir /rules.add
cat $tmpdir /rules.yaml >> $tmpdir /rules.add
mv -f $tmpdir /rules.add $tmpdir /rules.yaml
2022-12-15 20:49:57 +08:00
}
2020-10-27 09:40:58 +08:00
#添加配置
2020-11-05 20:53:05 +08:00
###################################
2020-10-30 16:21:09 +08:00
cat > $tmpdir /set.yaml <<EOF
2020-10-27 09:40:58 +08:00
mixed-port: $mix_port
redir-port: $redir_port
2022-11-12 22:54:46 +08:00
tproxy-port: $tproxy_port
2020-10-27 09:40:58 +08:00
authentication: [ " $authentication " ]
$lan
2022-01-30 12:50:25 +08:00
mode: $mode
2020-10-27 09:40:58 +08:00
$log
$ipv6
external-controller: :$db_port
external-ui: $db_ui
secret: $secret
$tun
$exper
$dns
2022-04-27 22:31:05 +08:00
$sniffer_set
2021-06-16 18:55:14 +08:00
store-selected: $restore
2023-02-28 19:45:06 +08:00
$find_process
2020-10-27 09:40:58 +08:00
EOF
2020-11-05 20:53:05 +08:00
###################################
2022-02-20 14:40:28 +08:00
#读取本机hosts并生成配置文件
2023-01-13 20:36:52 +08:00
if [ " $hosts_opt " != "未启用" ] && [ -z " $( grep -E '^hosts:' $clashdir /user.yaml 2>/dev/null) " ] ; then
#NTP劫持
cat >> $tmpdir /hosts.yaml <<EOF
hosts:
'time.android.com' : 203.107.6.88
'time.facebook.com' : 203.107.6.88
EOF
2023-05-03 17:26:22 +08:00
#加载本机hosts
sys_hosts = /etc/hosts
[ -f /data/etc/custom_hosts ] && sys_hosts = /data/etc/custom_hosts
2022-02-20 14:40:28 +08:00
while read line; do
2022-06-06 12:11:14 +08:00
[ -n " $( echo " $line " | grep -oE "([0-9]{1,3}[\.]){3}" ) " ] && \
[ -z " $( echo " $line " | grep -oE '^#' ) " ] && \
2022-02-20 14:40:28 +08:00
hosts_ip = $( echo $line | awk '{print $1}' ) && \
hosts_domain = $( echo $line | awk '{print $2}' ) && \
2023-01-08 22:03:36 +08:00
[ -z " $( cat $tmpdir /hosts.yaml | grep -oE " $hosts_domain " ) " ] && \
2022-02-20 14:40:28 +08:00
echo " ' $hosts_domain ': $hosts_ip " >> $tmpdir /hosts.yaml
2023-05-03 17:26:22 +08:00
done < $sys_hosts
2022-02-20 14:40:28 +08:00
fi
2020-11-05 14:54:52 +08:00
#合并文件
2023-06-03 22:31:33 +08:00
[ -s $clashdir /user.yaml ] && yaml_user = $clashdir /user.yaml
for char in $yaml_char ; do
[ -s $tmpdir /${ char } .yaml ] && {
sed -i " 1i\\ ${ char } : " $tmpdir /${ char } .yaml
yaml_add = " $yaml_add $tmpdir / ${ char } .yaml "
}
done
cut -c 1- $tmpdir /set.yaml $yaml_hosts $yaml_user $yaml_add > $tmpdir /config.yaml
2023-04-12 21:03:18 +08:00
#测试自定义配置文件
$bindir /clash -t -d $bindir -f $tmpdir /config.yaml >/dev/null
if [ " $? " != 0 ] ; then
2023-04-17 20:12:25 +08:00
logger " $( $bindir /clash -t -d $bindir -f $tmpdir /config.yaml | grep -Eo 'error.*=.*' ) " 31
2023-04-12 21:03:18 +08:00
logger "自定义配置文件校验失败!将使用基础配置文件启动!" 33
2023-06-03 22:31:33 +08:00
sed -i "/#自定义策略组开始/,/#自定义策略组结束/d" $tmpdir /config.yaml
sed -i "/#自定义/d" $tmpdir /config.yaml
2022-09-16 12:03:43 +08:00
fi
2023-04-26 21:24:26 +08:00
#存档
if [ " $clashdir " = " $bindir " ] ; then
2021-06-25 00:23:32 +08:00
cmp -s $tmpdir /config.yaml $yaml >/dev/null 2>& 1
2020-10-30 16:21:09 +08:00
[ " $? " != 0 ] && mv -f $tmpdir /config.yaml $yaml || rm -f $tmpdir /config.yaml
2023-04-26 21:24:26 +08:00
elif [ " $tmpdir " != " $bindir " ] ; then
mv -f $tmpdir /config.yaml $bindir /config.yaml
2020-10-30 16:21:09 +08:00
fi
2023-06-03 22:31:33 +08:00
#清理缓存
for char in $yaml_char set hosts; do
rm -f $tmpdir /${ char } .yaml
done
2020-08-22 20:08:23 +08:00
}
2020-10-28 11:09:26 +08:00
#设置路由规则
2021-06-13 19:12:57 +08:00
cn_ip_route( ) {
2022-11-16 19:49:02 +08:00
[ ! -f $bindir /cn_ip.txt ] && {
2021-06-13 19:32:43 +08:00
if [ -f $clashdir /cn_ip.txt ] ; then
mv $clashdir /cn_ip.txt $bindir /cn_ip.txt
else
logger "未找到cn_ip列表, 正在下载! " 33
2021-06-18 13:18:19 +08:00
$0 webget $bindir /cn_ip.txt " $update_url /bin/china_ip_list.txt "
2022-11-03 16:12:43 +08:00
[ " $? " = "1" ] && rm -rf $bindir /cn_ip.txt && logger "列表下载失败!" 31
2021-06-13 19:32:43 +08:00
fi
2022-11-16 19:49:02 +08:00
}
2022-12-01 23:10:49 +08:00
[ -f $bindir /cn_ip.txt -a -z " $( echo $redir_mod | grep 'Nft' ) " ] && {
2023-06-04 12:29:31 +08:00
echo "create cn_ip hash:net family inet hashsize 1024 maxelem 65536" > $tmpdir /cn_$USER .ipset
awk '!/^$/&&!/^#/{printf("add cn_ip %s' " " '\n",$0)}' $bindir /cn_ip.txt >> $tmpdir /cn_$USER .ipset
2022-11-16 19:49:02 +08:00
ipset -! flush cn_ip 2>/dev/null
2023-06-04 12:29:31 +08:00
ipset -! restore < $tmpdir /cn_$USER .ipset
2022-11-16 19:49:02 +08:00
rm -rf cn_$USER .ipset
}
2021-06-13 19:12:57 +08:00
}
2022-12-21 11:23:23 +08:00
cn_ipv6_route( ) {
2023-01-01 20:59:56 +08:00
[ ! -f $bindir /cn_ipv6.txt ] && {
if [ -f $clashdir /cn_ipv6.txt ] ; then
mv $clashdir /cn_ipv6.txt $bindir /cn_ipv6.txt
2022-12-21 11:23:23 +08:00
else
logger "未找到cn_ipv6列表, 正在下载! " 33
2023-01-01 20:59:56 +08:00
$0 webget $bindir /cn_ipv6.txt " $update_url /bin/china_ipv6_list.txt "
[ " $? " = "1" ] && rm -rf $bindir /cn_ipv6.txt && logger "列表下载失败!" 31
2022-12-21 11:23:23 +08:00
fi
}
2023-01-01 20:59:56 +08:00
[ -f $bindir /cn_ipv6.txt -a -z " $( echo $redir_mod | grep 'Nft' ) " ] && {
2022-12-21 11:23:23 +08:00
#ipv6
2023-06-04 12:29:31 +08:00
echo "create cn_ip6 hash:net family inet6 hashsize 1024 maxelem 65536" > $tmpdir /cn6_$USER .ipset
awk '!/^$/&&!/^#/{printf("add cn_ip6 %s' " " '\n",$0)}' $bindir /cn_ipv6.txt >> $tmpdir /cn6_$USER .ipset
2022-12-21 11:23:23 +08:00
ipset -! flush cn_ip6 2>/dev/null
2023-06-04 12:29:31 +08:00
ipset -! restore < $tmpdir /cn6_$USER .ipset
2022-12-21 11:23:23 +08:00
rm -rf cn6_$USER .ipset
}
}
2020-08-22 20:08:23 +08:00
start_redir( ) {
2022-05-16 00:57:52 +08:00
#获取局域网host地址
2023-04-02 19:46:08 +08:00
getlanip
#流量过滤
2020-08-22 20:08:23 +08:00
iptables -t nat -N clash
2023-04-02 19:46:08 +08:00
for ip in $host_ipv4 $reserve_ipv4 ; do #跳过目标保留地址及目标本机网段
iptables -t nat -A clash -d $ip -j RETURN
done
2022-11-03 16:12:43 +08:00
#绕过CN_IP
2023-04-02 19:46:08 +08:00
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && \
iptables -t nat -A clash -m set --match-set cn_ip dst -j RETURN 2>/dev/null
#局域网设备过滤
2020-11-03 23:10:57 +08:00
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac白名单
2022-05-03 22:40:21 +08:00
iptables -t nat -A clash -p tcp -m mac --mac-source $mac -j REDIRECT --to-ports $redir_port
2020-11-03 23:10:57 +08:00
done
else
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac黑名单
2020-11-03 23:10:57 +08:00
iptables -t nat -A clash -m mac --mac-source $mac -j RETURN
done
2023-04-02 19:46:08 +08:00
#仅代理本机局域网网段流量
for ip in $host_ipv4 ; do
iptables -t nat -A clash -p tcp -s $ip -j REDIRECT --to-ports $redir_port
done
2020-11-03 23:10:57 +08:00
fi
2022-04-27 22:31:05 +08:00
#将PREROUTING链指向clash链
2022-05-16 00:57:52 +08:00
iptables -t nat -A PREROUTING -p tcp $ports -j clash
2023-04-17 20:12:25 +08:00
[ " $dns_mod " = "fake-ip" -a " $common_ports " = "已开启" ] && iptables -t nat -A PREROUTING -p tcp -d 198.18.0.0/16 -j clash
2020-09-19 16:32:50 +08:00
#设置ipv6转发
2022-12-07 22:07:37 +08:00
if [ " $ipv6_redir " = "已开启" -a -n " $( lsmod | grep 'ip6table_nat' ) " ] ; then
2020-10-01 18:45:26 +08:00
ip6tables -t nat -N clashv6
2023-04-02 19:46:08 +08:00
for ip in $reserve_ipv6 $host_ipv6 ; do #跳过目标保留地址及目标本机网段
ip6tables -t nat -A clashv6 -d $ip -j RETURN
done
#绕过CN_IPV6
[ " $dns_mod " = "redir_host" -a " $cn_ipv6_route " = "已开启" ] && \
ip6tables -t nat -A clashv6 -m set --match-set cn_ip6 dst -j RETURN 2>/dev/null
#局域网设备过滤
2020-11-03 23:10:57 +08:00
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac白名单
ip6tables -t nat -A clashv6 -p tcp -m mac --mac-source $mac -j REDIRECT --to-ports $redir_port
2020-11-03 23:10:57 +08:00
done
else
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac黑名单
2020-11-03 23:10:57 +08:00
ip6tables -t nat -A clashv6 -m mac --mac-source $mac -j RETURN
done
2023-04-02 19:46:08 +08:00
#仅代理本机局域网网段流量
for ip in $host_ipv6 ; do
ip6tables -t nat -A clashv6 -p tcp -s $ip -j REDIRECT --to-ports $redir_port
2022-12-11 22:01:30 +08:00
done
2020-11-03 23:10:57 +08:00
fi
2023-04-02 19:46:08 +08:00
ip6tables -t nat -A PREROUTING -p tcp $ports -j clashv6
2020-08-22 20:08:23 +08:00
fi
2022-12-01 23:10:49 +08:00
return 0
2020-08-22 20:08:23 +08:00
}
2022-12-01 23:10:49 +08:00
start_ipt_dns( ) {
2022-05-04 22:28:09 +08:00
#屏蔽OpenWrt内置53端口转发
2022-12-07 22:07:37 +08:00
[ " $( uci get dhcp.@dnsmasq[ 0] .dns_redirect 2>/dev/null) " = 1 ] && {
uci del dhcp.@dnsmasq[ 0] .dns_redirect
uci commit dhcp.@dnsmasq[ 0]
}
2020-10-28 11:09:26 +08:00
#设置dns转发
iptables -t nat -N clash_dns
2020-11-03 23:10:57 +08:00
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac白名单
2022-04-27 22:31:05 +08:00
iptables -t nat -A clash_dns -p udp -m mac --mac-source $mac -j REDIRECT --to $dns_port
2020-11-03 23:10:57 +08:00
done
else
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac黑名单
2020-11-03 23:10:57 +08:00
iptables -t nat -A clash_dns -m mac --mac-source $mac -j RETURN
done
2022-04-27 22:31:05 +08:00
iptables -t nat -A clash_dns -p udp -j REDIRECT --to $dns_port
2020-11-03 23:10:57 +08:00
fi
2022-05-16 00:57:52 +08:00
iptables -t nat -I PREROUTING -p udp --dport 53 -j clash_dns
2020-10-28 11:09:26 +08:00
#ipv6DNS
2023-03-19 09:42:45 +08:00
if [ -n " $( lsmod | grep 'ip6table_nat' ) " -a -n " $( lsmod | grep 'xt_nat' ) " ] ; then
2020-10-28 11:09:26 +08:00
ip6tables -t nat -N clashv6_dns > /dev/null 2>& 1
2020-11-03 23:10:57 +08:00
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac白名单
2022-04-27 22:31:05 +08:00
ip6tables -t nat -A clashv6_dns -p udp -m mac --mac-source $mac -j REDIRECT --to $dns_port
2020-11-03 23:10:57 +08:00
done
else
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac黑名单
2020-11-03 23:10:57 +08:00
ip6tables -t nat -A clashv6_dns -m mac --mac-source $mac -j RETURN
done
2022-04-27 22:31:05 +08:00
ip6tables -t nat -A clashv6_dns -p udp -j REDIRECT --to $dns_port
2020-11-03 23:10:57 +08:00
fi
2022-05-04 22:28:09 +08:00
ip6tables -t nat -I PREROUTING -p udp --dport 53 -j clashv6_dns
2020-10-28 11:09:26 +08:00
else
2022-12-07 22:30:00 +08:00
ip6tables -I INPUT -p udp --dport 53 -m comment --comment "ShellClash-IPV6_DNS-REJECT" -j REJECT 2>/dev/null
2020-10-28 11:09:26 +08:00
fi
2022-12-01 23:10:49 +08:00
return 0
2022-05-04 22:28:09 +08:00
2020-10-28 11:09:26 +08:00
}
2022-11-03 16:12:43 +08:00
start_tproxy( ) {
2023-04-11 14:25:09 +08:00
#获取局域网host地址
getlanip
2023-04-26 21:24:26 +08:00
modprobe xt_TPROXY & >/dev/null
ip rule add fwmark $fwmark table 100
2023-04-11 14:25:09 +08:00
ip route add local default dev lo table 100
iptables -t mangle -N clash
iptables -t mangle -A clash -p udp --dport 53 -j RETURN
for ip in $host_ipv4 $reserve_ipv4 ; do #跳过目标保留地址及目标本机网段
iptables -t mangle -A clash -d $ip -j RETURN
done
#绕过CN_IP
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && \
iptables -t mangle -A clash -m set --match-set cn_ip dst -j RETURN 2>/dev/null
#tcp&udp分别进代理链
tproxy_set( ) {
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
for mac in $( cat $clashdir /mac) ; do #mac白名单
2023-04-26 21:24:26 +08:00
iptables -t mangle -A clash -p $1 -m mac --mac-source $mac -j TPROXY --on-port $tproxy_port --tproxy-mark $fwmark
2023-04-02 19:46:08 +08:00
done
2023-04-11 14:25:09 +08:00
else
for mac in $( cat $clashdir /mac) ; do #mac黑名单
iptables -t mangle -A clash -m mac --mac-source $mac -j RETURN
done
#仅代理本机局域网网段流量
for ip in $host_ipv4 ; do
2023-04-26 21:24:26 +08:00
iptables -t mangle -A clash -p $1 -s $ip -j TPROXY --on-port $tproxy_port --tproxy-mark $fwmark
2023-04-11 14:25:09 +08:00
done
fi
iptables -t mangle -A PREROUTING -p $1 $ports -j clash
2023-04-17 20:12:25 +08:00
[ " $dns_mod " = "fake-ip" -a " $common_ports " = "已开启" ] && iptables -t mangle -A PREROUTING -p $1 -d 198.18.0.0/16 -j clash
2023-04-11 14:25:09 +08:00
}
[ " $1 " = "all" ] && tproxy_set tcp
tproxy_set udp
#屏蔽QUIC
[ " $quic_rj " = 已启用 ] && {
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && set_cn_ip = '-m set ! --match-set cn_ip dst'
iptables -I INPUT -p udp --dport 443 -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip -j REJECT >/dev/null 2>& 1
}
#设置ipv6转发
[ " $ipv6_redir " = "已开启" ] && {
2023-04-26 21:24:26 +08:00
ip -6 rule add fwmark $fwmark table 101
2023-04-11 14:25:09 +08:00
ip -6 route add local ::/0 dev lo table 101
ip6tables -t mangle -N clashv6
ip6tables -t mangle -A clashv6 -p udp --dport 53 -j RETURN
for ip in $host_ipv6 $reserve_ipv6 ; do #跳过目标保留地址及目标本机网段
ip6tables -t mangle -A clashv6 -d $ip -j RETURN
done
#绕过CN_IPV6
[ " $dns_mod " = "redir_host" -a " $cn_ipv6_route " = "已开启" ] && \
ip6tables -t mangle -A clashv6 -m set --match-set cn_ip6 dst -j RETURN 2>/dev/null
2023-04-02 19:46:08 +08:00
#tcp&udp分别进代理链
2023-04-11 14:25:09 +08:00
tproxy_set6( ) {
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
#mac白名单
for mac in $( cat $clashdir /mac) ; do
2023-04-26 21:24:26 +08:00
ip6tables -t mangle -A clashv6 -p $1 -m mac --mac-source $mac -j TPROXY --on-port $tproxy_port --tproxy-mark $fwmark
2023-04-11 14:25:09 +08:00
done
else
#mac黑名单
for mac in $( cat $clashdir /mac) ; do
ip6tables -t mangle -A clashv6 -m mac --mac-source $mac -j RETURN
done
#仅代理本机局域网网段流量
for ip in $host_ipv6 ; do
2023-04-26 21:24:26 +08:00
ip6tables -t mangle -A clashv6 -p $1 -s $ip -j TPROXY --on-port $tproxy_port --tproxy-mark $fwmark
2023-04-11 14:25:09 +08:00
done
fi
ip6tables -t mangle -A PREROUTING -p $1 $ports -j clashv6
2022-11-12 22:54:46 +08:00
}
2023-04-11 14:25:09 +08:00
[ " $1 " = "all" ] && tproxy_set6 tcp
tproxy_set6 udp
2022-12-08 22:57:32 +08:00
#屏蔽QUIC
2022-12-01 23:10:49 +08:00
[ " $quic_rj " = 已启用 ] && {
2023-04-11 14:25:09 +08:00
[ " $dns_mod " = "redir_host" -a " $cn_ipv6_route " = "已开启" ] && set_cn_ip6 = '-m set ! --match-set cn_ip6 dst'
ip6tables -I INPUT -p udp --dport 443 -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip6 -j REJECT 2>/dev/null
}
2022-11-12 22:54:46 +08:00
}
2020-10-25 10:01:58 +08:00
}
2021-05-15 16:25:18 +08:00
start_output( ) {
2023-04-02 19:46:08 +08:00
#获取局域网host地址
getlanip
2022-05-31 23:21:28 +08:00
#流量过滤
2021-05-15 16:25:18 +08:00
iptables -t nat -N clash_out
2021-05-16 22:28:28 +08:00
iptables -t nat -A clash_out -m owner --gid-owner 7890 -j RETURN
2023-04-02 19:46:08 +08:00
for ip in $local_ipv4 $reserve_ipv4 ; do #跳过目标保留地址及目标本机网段
iptables -t nat -A clash_out -d $ip -j RETURN
done
#绕过CN_IP
2022-05-31 23:21:28 +08:00
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && \
2023-04-02 19:46:08 +08:00
iptables -t nat -A clash_out -m set --match-set cn_ip dst -j RETURN >/dev/null 2>& 1
#仅允许本机流量
for ip in 127.0.0.0/8 $local_ipv4 ; do
iptables -t nat -A clash_out -p tcp -s $ip -j REDIRECT --to-ports $redir_port
done
iptables -t nat -A OUTPUT -p tcp $ports -j clash_out
2021-05-15 16:25:18 +08:00
#设置dns转发
2022-05-31 12:58:37 +08:00
[ " $dns_no " != "已禁用" ] && {
2022-05-31 23:21:28 +08:00
iptables -t nat -N clash_dns_out
iptables -t nat -A clash_dns_out -m owner --gid-owner 7890 -j RETURN
2023-04-02 19:46:08 +08:00
iptables -t nat -A clash_dns_out -p udp -s 127.0.0.0/8 -j REDIRECT --to $dns_port
2022-05-31 23:21:28 +08:00
iptables -t nat -A OUTPUT -p udp --dport 53 -j clash_dns_out
}
#Docker转发
2023-01-15 20:58:15 +08:00
ckcmd docker && {
2022-11-12 22:54:46 +08:00
iptables -t nat -N clash_docker
2023-04-02 19:46:08 +08:00
for ip in $host_ipv4 $reserve_ipv4 ; do #跳过目标保留地址及目标本机网段
iptables -t nat -A clash_docker -d $ip -j RETURN
done
2022-11-12 22:54:46 +08:00
iptables -t nat -A clash_docker -p tcp -j REDIRECT --to-ports $redir_port
iptables -t nat -A PREROUTING -p tcp -s 172.16.0.0/12 -j clash_docker
[ " $dns_no " != "已禁用" ] && iptables -t nat -A PREROUTING -p udp --dport 53 -s 172.16.0.0/12 -j REDIRECT --to $dns_port
2022-05-31 12:58:37 +08:00
}
2021-05-15 16:25:18 +08:00
}
2022-05-03 22:56:16 +08:00
start_tun( ) {
2023-04-26 21:24:26 +08:00
modprobe tun & >/dev/null
2023-04-11 14:25:09 +08:00
#允许流量
iptables -I FORWARD -o utun -j ACCEPT
2023-04-26 21:24:26 +08:00
iptables -I FORWARD -s 198.18.0.0/16 -o utun -j RETURN #防止回环
2023-04-11 14:25:09 +08:00
ip6tables -I FORWARD -o utun -j ACCEPT > /dev/null 2>& 1
#屏蔽QUIC
if [ " $quic_rj " = 已启用 ] ; then
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && set_cn_ip = '-m set ! --match-set cn_ip dst'
iptables -I FORWARD -p udp --dport 443 -o utun -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip -j REJECT >/dev/null 2>& 1
#ip6tables -I FORWARD -p udp --dport 443 -o utun -m comment --comment "ShellClash-QUIC-REJECT" -j REJECT >/dev/null 2>&1
fi
2023-04-26 21:24:26 +08:00
modprobe xt_mark & >/dev/null && {
2023-04-11 14:25:09 +08:00
i = 1
while [ -z " $( ip route list | grep utun) " -a " $i " -le 29 ] ; do
sleep 1
i = $(( i+1))
done
ip route add default dev utun table 100
2023-04-26 21:24:26 +08:00
ip rule add fwmark $fwmark table 100
2023-04-11 14:25:09 +08:00
#获取局域网host地址
getlanip
iptables -t mangle -N clash
iptables -t mangle -A clash -p udp --dport 53 -j RETURN
for ip in $host_ipv4 $reserve_ipv4 ; do #跳过目标保留地址及目标本机网段
iptables -t mangle -A clash -d $ip -j RETURN
done
2023-04-26 21:24:26 +08:00
#防止回环
iptables -t mangle -A clash -s 198.18.0.0/16 -j RETURN
2023-04-11 14:25:09 +08:00
#绕过CN_IP
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && \
iptables -t mangle -A clash -m set --match-set cn_ip dst -j RETURN 2>/dev/null
#局域网设备过滤
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
for mac in $( cat $clashdir /mac) ; do #mac白名单
2023-04-26 21:24:26 +08:00
iptables -t mangle -A clash -m mac --mac-source $mac -j MARK --set-mark $fwmark
2023-04-11 14:25:09 +08:00
done
else
for mac in $( cat $clashdir /mac) ; do #mac黑名单
iptables -t mangle -A clash -m mac --mac-source $mac -j RETURN
2022-12-08 22:57:32 +08:00
done
2023-04-11 14:25:09 +08:00
#仅代理本机局域网网段流量
for ip in $host_ipv4 ; do
2023-04-26 21:24:26 +08:00
iptables -t mangle -A clash -s $ip -j MARK --set-mark $fwmark
2023-04-11 14:25:09 +08:00
done
fi
iptables -t mangle -A PREROUTING -p udp $ports -j clash
[ " $1 " = "all" ] && iptables -t mangle -A PREROUTING -p tcp $ports -j clash
#设置ipv6转发
[ " $ipv6_redir " = "已开启" -a " $clashcore " = "clash.meta" ] && {
ip -6 route add default dev utun table 101
2023-04-26 21:24:26 +08:00
ip -6 rule add fwmark $fwmark table 101
2023-04-11 14:25:09 +08:00
ip6tables -t mangle -N clashv6
ip6tables -t mangle -A clashv6 -p udp --dport 53 -j RETURN
for ip in $host_ipv6 $reserve_ipv6 ; do #跳过目标保留地址及目标本机网段
ip6tables -t mangle -A clashv6 -d $ip -j RETURN
2023-04-02 19:46:08 +08:00
done
2023-04-11 14:25:09 +08:00
#绕过CN_IPV6
[ " $dns_mod " = "redir_host" -a " $cn_ipv6_route " = "已开启" ] && \
ip6tables -t mangle -A clashv6 -m set --match-set cn_ip6 dst -j RETURN 2>/dev/null
2023-04-02 19:46:08 +08:00
#局域网设备过滤
2022-12-08 22:57:32 +08:00
if [ " $macfilter_type " = "白名单" -a -n " $( cat $clashdir /mac) " ] ; then
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac白名单
2023-04-26 21:24:26 +08:00
ip6tables -t mangle -A clashv6 -m mac --mac-source $mac -j MARK --set-mark $fwmark
2022-12-08 22:57:32 +08:00
done
else
2023-04-02 19:46:08 +08:00
for mac in $( cat $clashdir /mac) ; do #mac黑名单
2023-04-11 14:25:09 +08:00
ip6tables -t mangle -A clashv6 -m mac --mac-source $mac -j RETURN
2022-12-08 22:57:32 +08:00
done
2023-04-02 19:46:08 +08:00
#仅代理本机局域网网段流量
2023-04-11 14:25:09 +08:00
for ip in $host_ipv6 ; do
2023-04-26 21:24:26 +08:00
ip6tables -t mangle -A clashv6 -s $ip -j MARK --set-mark $fwmark
2023-04-11 14:25:09 +08:00
done
fi
ip6tables -t mangle -A PREROUTING -p udp $ports -j clashv6
[ " $1 " = "all" ] && ip6tables -t mangle -A PREROUTING -p tcp $ports -j clashv6
}
} &
2022-05-03 22:56:16 +08:00
}
2022-11-03 16:12:43 +08:00
start_nft( ) {
2023-04-02 19:46:08 +08:00
#获取局域网host地址
getlanip
2022-11-13 18:11:22 +08:00
[ " $common_ports " = "已开启" ] && PORTS = $( echo $multiport | sed 's/,/, /g' )
2023-04-11 14:25:09 +08:00
RESERVED_IP = " $( echo $reserve_ipv4 | sed 's/ /, /g' ) "
HOST_IP = " $( echo $host_ipv4 | sed 's/ /, /g' ) "
2022-11-03 16:12:43 +08:00
#设置策略路由
2023-04-26 21:24:26 +08:00
ip rule add fwmark $fwmark table 100
2023-04-04 20:45:35 +08:00
ip route add local default dev lo table 100
2022-12-01 23:10:49 +08:00
[ " $redir_mod " = "Nft基础" ] && \
nft add chain inet shellclash prerouting { type nat hook prerouting priority -100 \; }
2022-11-16 19:49:02 +08:00
[ " $redir_mod " = "Nft混合" ] && {
modprobe nft_tproxy & > /dev/null
2022-12-01 23:10:49 +08:00
nft add chain inet shellclash prerouting { type filter hook prerouting priority 0 \; }
2022-11-16 19:49:02 +08:00
}
2022-11-13 18:11:22 +08:00
[ -n " $( echo $redir_mod | grep Nft) " ] && {
#过滤局域网设备
[ -n " $( cat $clashdir /mac) " ] && {
MAC = $( awk '{printf "%s, ",$1}' $clashdir /mac)
2022-12-01 23:10:49 +08:00
[ " $macfilter_type " = "黑名单" ] && \
2023-04-11 14:25:09 +08:00
nft add rule inet shellclash prerouting ether saddr { $MAC } return || \
nft add rule inet shellclash prerouting ether saddr != { $MAC } return
2022-11-25 21:47:03 +08:00
}
2022-11-13 18:11:22 +08:00
#过滤保留地址
2023-04-11 14:25:09 +08:00
nft add rule inet shellclash prerouting ip daddr { $RESERVED_IP } return
2023-04-02 19:46:08 +08:00
#仅代理本机局域网网段流量
2023-04-11 14:25:09 +08:00
nft add rule inet shellclash prerouting ip saddr != { $HOST_IP } return
2023-04-02 19:46:08 +08:00
#绕过CN-IP
2022-11-13 18:11:22 +08:00
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" -a -f $bindir /cn_ip.txt ] && {
CN_IP = $( awk '{printf "%s, ",$1}' $bindir /cn_ip.txt)
2023-04-11 14:25:09 +08:00
[ -n " $CN_IP " ] && nft add rule inet shellclash prerouting ip daddr { $CN_IP } return
2022-11-13 18:11:22 +08:00
}
#过滤常用端口
2023-04-17 20:12:25 +08:00
[ -n " $PORTS " ] && nft add rule inet shellclash prerouting tcp dport != { $PORTS } ip daddr != { 198.18.0.0/16} return
2022-12-01 23:10:49 +08:00
#ipv6支持
2022-12-04 20:54:09 +08:00
if [ " $ipv6_redir " = "已开启" ] ; then
2023-04-11 14:25:09 +08:00
RESERVED_IP6 = " $( echo " $reserve_ipv6 $host_ipv6 " | sed 's/ /, /g' ) "
HOST_IP6 = " $( echo $host_ipv6 | sed 's/ /, /g' ) "
2023-04-26 21:24:26 +08:00
ip -6 rule add fwmark $fwmark table 101 2> /dev/null
2022-12-01 23:10:49 +08:00
ip -6 route add local ::/0 dev lo table 101 2> /dev/null
2023-04-02 19:46:08 +08:00
#过滤保留地址及本机地址
2023-04-11 14:25:09 +08:00
nft add rule inet shellclash prerouting ip6 daddr { $RESERVED_IP6 } return
2023-04-02 19:46:08 +08:00
#仅代理本机局域网网段流量
2023-04-11 14:25:09 +08:00
nft add rule inet shellclash prerouting ip6 saddr != { $HOST_IP6 } return
2023-04-02 19:46:08 +08:00
#绕过CN_IPV6
2023-01-01 20:59:56 +08:00
[ " $dns_mod " = "redir_host" -a " $cn_ipv6_route " = "已开启" -a -f $bindir /cn_ipv6.txt ] && {
CN_IP6 = $( awk '{printf "%s, ",$1}' $bindir /cn_ipv6.txt)
2023-04-11 14:25:09 +08:00
[ -n " $CN_IP6 " ] && nft add rule inet shellclash prerouting ip6 daddr { $CN_IP6 } return
2022-12-21 11:23:23 +08:00
}
2022-12-01 23:10:49 +08:00
else
nft add rule inet shellclash prerouting meta nfproto ipv6 return
fi
2022-11-13 18:11:22 +08:00
#透明路由
2023-04-26 21:24:26 +08:00
[ " $redir_mod " = "Nft基础" ] && nft add rule inet shellclash prerouting meta l4proto tcp mark set $fwmark redirect to $redir_port
[ " $redir_mod " = "Nft混合" ] && nft add rule inet shellclash prerouting meta l4proto { tcp, udp} mark set $fwmark tproxy to :$tproxy_port
2022-11-03 16:12:43 +08:00
}
2022-11-12 22:54:46 +08:00
#屏蔽QUIC
[ " $quic_rj " = 已启用 ] && {
2022-12-01 23:10:49 +08:00
nft add chain inet shellclash input { type filter hook input priority 0 \; }
2023-04-11 14:25:09 +08:00
[ -n " $CN_IP " ] && nft add rule inet shellclash input ip daddr { $CN_IP } return
[ -n " $CN_IP6 " ] && nft add rule inet shellclash input ip6 daddr { $CN_IP6 } return
2022-12-01 23:10:49 +08:00
nft add rule inet shellclash input udp dport 443 reject comment 'ShellClash-QUIC-REJECT'
2022-11-13 18:11:22 +08:00
}
2022-12-01 23:10:49 +08:00
#代理本机(仅TCP)
2022-11-03 16:12:43 +08:00
[ " $local_proxy " = "已开启" ] && [ " $local_type " = "nftables增强模式" ] && {
2022-11-13 18:11:22 +08:00
#dns
2022-12-01 23:10:49 +08:00
nft add chain inet shellclash dns_out { type nat hook output priority -100 \; }
nft add rule inet shellclash dns_out meta skgid 7890 return && \
2023-04-26 21:24:26 +08:00
nft add rule inet shellclash dns_out udp dport 53 redirect to $dns_port
2022-11-13 18:11:22 +08:00
#output
2022-12-01 23:10:49 +08:00
nft add chain inet shellclash output { type nat hook output priority -100 \; }
nft add rule inet shellclash output meta skgid 7890 return && {
2023-04-11 14:25:09 +08:00
[ -n " $PORTS " ] && nft add rule inet shellclash output tcp dport != { $PORTS } return
nft add rule inet shellclash output ip daddr { $RESERVED_IP } return
2023-04-26 21:24:26 +08:00
nft add rule inet shellclash output meta l4proto tcp mark set $fwmark redirect to $redir_port
2022-11-13 18:11:22 +08:00
}
#Docker
type docker & >/dev/null && {
2023-04-26 21:24:26 +08:00
ip rule add fwmark $fwmark table 102 2> /dev/null
2022-11-13 18:11:22 +08:00
ip route add local 172.16.0.0/12 dev lo table 102 2> /dev/null
}
2022-11-03 16:12:43 +08:00
}
}
2022-12-01 23:10:49 +08:00
start_nft_dns( ) {
nft add chain inet shellclash dns { type nat hook prerouting priority -100 \; }
#过滤局域网设备
[ -n " $( cat $clashdir /mac) " ] && {
MAC = $( awk '{printf "%s, ",$1}' $clashdir /mac)
[ " $macfilter_type " = "黑名单" ] && \
2023-04-11 14:25:09 +08:00
nft add rule inet shellclash dns ether saddr { $MAC } return || \
nft add rule inet shellclash dns ether saddr != { $MAC } return
2022-12-01 23:10:49 +08:00
}
nft add rule inet shellclash dns udp dport 53 redirect to ${ dns_port }
nft add rule inet shellclash dns tcp dport 53 redirect to ${ dns_port }
}
2022-05-16 00:57:52 +08:00
start_wan( ) {
2023-04-02 19:46:08 +08:00
#获取局域网host地址
getlanip
2022-05-16 00:57:52 +08:00
if [ " $public_support " = "已开启" ] ; then
iptables -I INPUT -p tcp --dport $db_port -j ACCEPT
2023-04-03 21:46:24 +08:00
ckcmd ip6tables && ip6tables -I INPUT -p tcp --dport $db_port -j ACCEPT
2023-04-02 19:46:08 +08:00
else
2023-04-16 21:27:25 +08:00
#仅允许非公网设备访问面板
for ip in $reserve_ipv4 ; do
2023-04-02 19:46:08 +08:00
iptables -A INPUT -p tcp -s $ip --dport $db_port -j ACCEPT
done
iptables -A INPUT -p tcp --dport $db_port -j REJECT
2023-04-03 21:46:24 +08:00
ckcmd ip6tables && ip6tables -A INPUT -p tcp --dport $db_port -j REJECT
2022-05-16 00:57:52 +08:00
fi
2023-04-16 21:27:25 +08:00
if [ " $public_mixport " = "已开启" ] ; then
iptables -I INPUT -p tcp --dport $mix_port -j ACCEPT
ckcmd ip6tables && ip6tables -I INPUT -p tcp --dport $mix_port -j ACCEPT
else
#仅允许局域网设备访问混合端口
for ip in $reserve_ipv4 ; do
iptables -A INPUT -p tcp -s $ip --dport $mix_port -j ACCEPT
done
iptables -A INPUT -p tcp --dport $mix_port -j REJECT
ckcmd ip6tables && ip6tables -A INPUT -p tcp --dport $mix_port -j REJECT
fi
2023-04-04 20:45:35 +08:00
iptables -I INPUT -p tcp -d 127.0.0.1 -j ACCEPT #本机请求全放行
2022-05-16 00:57:52 +08:00
}
2022-11-08 22:06:42 +08:00
stop_firewall( ) {
2023-04-02 19:46:08 +08:00
#获取局域网host地址
getlanip
2022-11-12 22:54:46 +08:00
#重置iptables相关规则
2023-01-15 20:58:15 +08:00
ckcmd iptables && {
2022-11-12 22:54:46 +08:00
#redir
iptables -t nat -D PREROUTING -p tcp $ports -j clash 2> /dev/null
2023-04-17 20:12:25 +08:00
iptables -t nat -D PREROUTING -p tcp -d 198.18.0.0/16 -j clash 2> /dev/null
2022-11-12 22:54:46 +08:00
iptables -t nat -F clash 2> /dev/null
iptables -t nat -X clash 2> /dev/null
#dns
iptables -t nat -D PREROUTING -p udp --dport 53 -j clash_dns 2> /dev/null
iptables -t nat -F clash_dns 2> /dev/null
iptables -t nat -X clash_dns 2> /dev/null
#tun
iptables -D FORWARD -o utun -j ACCEPT 2> /dev/null
2022-12-11 22:01:30 +08:00
iptables -D FORWARD -s 198.18.0.0/16 -o utun -j RETURN 2> /dev/null
2022-11-12 22:54:46 +08:00
#屏蔽QUIC
[ " $dns_mod " = "redir_host" -a " $cn_ip_route " = "已开启" ] && set_cn_ip = '-m set ! --match-set cn_ip dst'
2022-12-07 22:07:37 +08:00
iptables -D INPUT -p udp --dport 443 -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip -j REJECT 2> /dev/null
iptables -D FORWARD -p udp --dport 443 -o utun -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip -j REJECT 2> /dev/null
2022-11-12 22:54:46 +08:00
#本机代理
iptables -t nat -D OUTPUT -p tcp -j clash_out 2> /dev/null
iptables -t nat -F clash_out 2> /dev/null
iptables -t nat -X clash_out 2> /dev/null
iptables -t nat -D OUTPUT -p udp --dport 53 -j clash_dns_out 2> /dev/null
iptables -t nat -F clash_dns_out 2> /dev/null
iptables -t nat -X clash_dns_out 2> /dev/null
#docker
iptables -t nat -F clash_docker 2> /dev/null
iptables -t nat -X clash_docker 2> /dev/null
iptables -t nat -D PREROUTING -p tcp -s 172.16.0.0/12 -j clash_docker 2> /dev/null
iptables -t nat -D PREROUTING -p udp --dport 53 -s 172.16.0.0/12 -j REDIRECT --to $dns_port 2> /dev/null
2023-01-01 20:25:30 +08:00
#TPROXY&tun
2022-11-12 22:54:46 +08:00
iptables -t mangle -D PREROUTING -p tcp $ports -j clash 2> /dev/null
iptables -t mangle -D PREROUTING -p udp $ports -j clash 2> /dev/null
2023-04-17 20:12:25 +08:00
iptables -t mangle -D PREROUTING -p tcp -d 198.18.0.0/16 -j clash 2> /dev/null
iptables -t mangle -D PREROUTING -p udp -d 198.18.0.0/16 -j clash 2> /dev/null
2022-11-12 22:54:46 +08:00
iptables -t mangle -F clash 2> /dev/null
iptables -t mangle -X clash 2> /dev/null
#公网访问
2023-04-03 21:46:24 +08:00
for ip in $host_ipv4 $local_ipv4 ; do
2023-04-02 19:46:08 +08:00
iptables -D INPUT -p tcp -s $ip --dport $mix_port -j ACCEPT 2> /dev/null
iptables -D INPUT -p tcp -s $ip --dport $db_port -j ACCEPT 2> /dev/null
done
2023-04-04 20:45:35 +08:00
iptables -D INPUT -p tcp -d 127.0.0.1 -j ACCEPT 2> /dev/null
2022-11-12 22:54:46 +08:00
iptables -D INPUT -p tcp --dport $mix_port -j REJECT 2> /dev/null
iptables -D INPUT -p tcp --dport $mix_port -j ACCEPT 2> /dev/null
2023-04-02 19:46:08 +08:00
iptables -D INPUT -p tcp --dport $db_port -j REJECT 2> /dev/null
2022-11-12 22:54:46 +08:00
iptables -D INPUT -p tcp --dport $db_port -j ACCEPT 2> /dev/null
}
2020-08-22 20:08:23 +08:00
#重置ipv6规则
2023-01-15 20:58:15 +08:00
ckcmd ip6tables && {
2022-11-12 22:54:46 +08:00
#redir
2023-04-02 19:46:08 +08:00
ip6tables -t nat -D PREROUTING -p tcp $ports -j clashv6 2> /dev/null
2022-12-07 22:07:37 +08:00
ip6tables -D INPUT -p udp --dport 53 -m comment --comment "ShellClash-IPV6_DNS-REJECT" -j REJECT 2> /dev/null
2022-11-12 22:54:46 +08:00
ip6tables -t nat -F clashv6 2> /dev/null
ip6tables -t nat -X clashv6 2> /dev/null
#dns
2023-01-23 15:38:07 +08:00
ip6tables -t nat -D PREROUTING -p udp --dport 53 -j clashv6_dns 2>/dev/null
2022-11-12 22:54:46 +08:00
ip6tables -t nat -F clashv6_dns 2> /dev/null
ip6tables -t nat -X clashv6_dns 2> /dev/null
#tun
ip6tables -D FORWARD -o utun -j ACCEPT 2> /dev/null
2023-04-02 19:46:08 +08:00
ip6tables -D FORWARD -p udp --dport 443 -o utun -m comment --comment "ShellClash-QUIC-REJECT" -j REJECT >/dev/null 2>& 1
2022-12-21 11:23:23 +08:00
#屏蔽QUIC
[ " $dns_mod " = "redir_host" -a " $cn_ipv6_route " = "已开启" ] && set_cn_ip6 = '-m set ! --match-set cn_ip6 dst'
iptables -D INPUT -p udp --dport 443 -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip6 -j REJECT 2> /dev/null
iptables -D FORWARD -p udp --dport 443 -o utun -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip6 -j REJECT 2> /dev/null
2022-11-12 22:54:46 +08:00
#公网访问
ip6tables -D INPUT -p tcp --dport $mix_port -j REJECT 2> /dev/null
ip6tables -D INPUT -p tcp --dport $mix_port -j ACCEPT 2> /dev/null
2023-04-02 19:46:08 +08:00
ip6tables -D INPUT -p tcp --dport $db_port -j REJECT 2> /dev/null
2022-11-12 22:54:46 +08:00
ip6tables -D INPUT -p tcp --dport $db_port -j ACCEPT 2> /dev/null
2023-01-01 20:25:30 +08:00
#tproxy&tun
2022-11-12 22:54:46 +08:00
ip6tables -t mangle -D PREROUTING -p tcp $ports -j clashv6 2> /dev/null
2022-12-05 20:46:56 +08:00
ip6tables -t mangle -D PREROUTING -p udp $ports -j clashv6 2> /dev/null
2022-11-12 22:54:46 +08:00
ip6tables -t mangle -F clashv6 2> /dev/null
ip6tables -t mangle -X clashv6 2> /dev/null
2022-12-07 22:07:37 +08:00
ip6tables -D INPUT -p udp --dport 443 -m comment --comment "ShellClash-QUIC-REJECT" $set_cn_ip -j REJECT 2> /dev/null
2022-11-12 22:54:46 +08:00
}
2021-06-13 19:12:57 +08:00
#清理ipset规则
ipset destroy cn_ip >/dev/null 2>& 1
2022-12-21 11:24:06 +08:00
ipset destroy cn_ip6 >/dev/null 2>& 1
2021-12-18 20:14:03 +08:00
#移除dnsmasq转发规则
2022-05-03 23:15:13 +08:00
[ " $dns_redir " = "已开启" ] && {
uci del dhcp.@dnsmasq[ -1] .server >/dev/null 2>& 1
2022-09-17 19:07:14 +08:00
uci set dhcp.@dnsmasq[ 0] .noresolv= 0 2>/dev/null
2022-09-17 18:22:17 +08:00
uci commit dhcp >/dev/null 2>& 1
2022-05-03 23:15:13 +08:00
/etc/init.d/dnsmasq restart >/dev/null 2>& 1
}
2022-11-12 22:54:46 +08:00
#清理路由规则
2023-04-26 21:24:26 +08:00
ip rule del fwmark $fwmark table 100 2> /dev/null
2022-11-08 22:06:42 +08:00
ip route del local default dev lo table 100 2> /dev/null
2023-04-26 21:24:26 +08:00
ip -6 rule del fwmark $fwmark table 101 2> /dev/null
2022-11-12 22:54:46 +08:00
ip -6 route del local ::/0 dev lo table 101 2> /dev/null
2023-04-26 21:24:26 +08:00
ip rule del fwmark $fwmark table 102 2> /dev/null
2022-11-13 18:11:22 +08:00
ip route del local 172.16.0.0/12 dev lo table 102 2> /dev/null
2022-11-08 22:06:42 +08:00
#重置nftables相关规则
2023-01-15 20:58:15 +08:00
ckcmd nft && {
2022-12-01 23:10:49 +08:00
nft flush table inet shellclash >/dev/null 2>& 1
nft delete table inet shellclash >/dev/null 2>& 1
2022-11-12 22:54:46 +08:00
}
2020-08-22 20:08:23 +08:00
}
2020-10-28 11:09:26 +08:00
#面板配置保存相关
2020-10-10 17:02:53 +08:00
web_save( ) {
2020-10-24 20:09:49 +08:00
#使用get_save获取面板节点设置
2023-06-04 12:29:31 +08:00
get_save http://127.0.0.1:${ db_port } /proxies | awk -F "{" '{for(i=1;i<=NF;i++) print $i}' | grep -E '^"all".*"Selector"' > $tmpdir /clash_web_check_$USER
2020-12-13 13:57:37 +08:00
while read line ; do
2021-02-25 21:16:36 +08:00
def = $( echo $line | awk -F "[[,]" '{print $2}' )
2022-03-25 20:25:24 +08:00
now = $( echo $line | grep -oE '"now".*",' | sed 's/"now"://g' | sed 's/"type":.*//g' | sed 's/,//g' )
2023-06-04 12:29:31 +08:00
[ " $def " != " $now " ] && echo $line | grep -oE '"name".*"now".*",' | sed 's/"name"://g' | sed 's/"now"://g' | sed 's/"type":.*//g' | sed 's/"//g' >> $tmpdir /clash_web_save_$USER
done < $tmpdir /clash_web_check_$USER
rm -rf $tmpdir /clash_web_check_$USER
2020-11-07 12:08:31 +08:00
#对比文件,如果有变动且不为空则写入磁盘,否则清除缓存
2023-06-04 12:29:31 +08:00
if [ -s $tmpdir /clash_web_save_$USER ] ; then
compare $tmpdir /clash_web_save_$USER $clashdir /web_save
[ " $? " = 0 ] && rm -rf $tmpdir /clash_web_save_$USER || mv -f $tmpdir /clash_web_save_$USER $clashdir /web_save
2023-04-27 00:05:24 +08:00
else
2023-05-03 17:26:22 +08:00
echo > $clashdir /web_save
2020-12-13 21:22:41 +08:00
fi
2020-10-10 17:02:53 +08:00
}
web_restore( ) {
2022-06-06 13:03:42 +08:00
2020-10-10 17:02:53 +08:00
#设置循环检测clash面板端口
2022-03-26 02:11:09 +08:00
i = 1
2023-05-03 17:26:22 +08:00
while [ -z " $test " -a " $i " -lt 20 ] ; do
2020-10-10 17:02:53 +08:00
sleep 1
2020-10-24 20:09:49 +08:00
if curl --version > /dev/null 2>& 1; then
2023-04-11 14:25:09 +08:00
test = $( curl -s http://127.0.0.1:${ db_port } )
2020-10-24 20:09:49 +08:00
else
2023-04-11 14:25:09 +08:00
test = $( wget -q -O - http://127.0.0.1:${ db_port } )
2020-10-24 20:09:49 +08:00
fi
2022-03-26 02:11:09 +08:00
i = $(( i+1))
2020-10-10 17:02:53 +08:00
done
#发送数据
num = $( cat $clashdir /web_save | wc -l)
2022-04-10 21:36:58 +08:00
i = 1
while [ " $i " -le " $num " ] ; do
2020-10-10 17:02:53 +08:00
group_name = $( awk -F ',' 'NR=="' ${ i } '" {print $1}' $clashdir /web_save | sed 's/ /%20/g' )
now_name = $( awk -F ',' 'NR=="' ${ i } '" {print $2}' $clashdir /web_save)
2023-04-11 14:25:09 +08:00
put_save http://127.0.0.1:${ db_port } /proxies/${ group_name } " {\"name\":\" ${ now_name } \"} "
2022-04-10 21:36:58 +08:00
i = $(( i+1))
2020-10-10 17:02:53 +08:00
done
}
2020-10-28 11:09:26 +08:00
#启动相关
2020-10-30 16:21:09 +08:00
catpac( ) {
2022-05-12 23:23:18 +08:00
#获取本机host地址
2022-05-14 22:30:37 +08:00
[ -n " $host " ] && host_pac = $host
[ -z " $host_pac " ] && host_pac = $( ubus call network.interface.lan status 2>& 1 | grep \" address\" | grep -oE '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' ; )
2022-11-16 19:49:02 +08:00
[ -z " $host_pac " ] && host_pac = $( ip a 2>& 1 | grep -w 'inet' | grep 'global' | grep -E ' 1(92|0|72)\.' | sed 's/.*inet.//g' | sed 's/\/[0-9][0-9].*$//g' | head -n 1)
2023-06-04 12:29:31 +08:00
cat > $tmpdir /clash_pac <<EOF
2022-04-27 22:31:05 +08:00
//如看见此处内容,请重新安装本地面板!
2023-01-13 20:36:52 +08:00
//之后返回上一级页面,清理浏览器缓存并刷新页面!
2020-10-30 16:21:09 +08:00
function FindProxyForURL( url, host) {
if (
isInNet( host, "0.0.0.0" , "255.0.0.0" ) ||
isInNet( host, "10.0.0.0" , "255.0.0.0" ) ||
isInNet( host, "127.0.0.0" , "255.0.0.0" ) ||
isInNet( host, "224.0.0.0" , "224.0.0.0" ) ||
isInNet( host, "240.0.0.0" , "240.0.0.0" ) ||
isInNet( host, "172.16.0.0" , "255.240.0.0" ) ||
isInNet( host, "192.168.0.0" , "255.255.0.0" ) ||
isInNet( host, "169.254.0.0" , "255.255.0.0" )
)
return "DIRECT" ;
else
2022-05-14 13:07:48 +08:00
return " PROXY $host_pac : $mix_port ; DIRECT; SOCKS5 $host_pac : $mix_port "
2020-10-30 16:21:09 +08:00
}
EOF
2023-06-04 12:29:31 +08:00
compare $tmpdir /clash_pac $bindir /ui/pac
[ " $? " = 0 ] && rm -rf $tmpdir /clash_pac || mv -f $tmpdir /clash_pac $bindir /ui/pac
2020-10-30 16:21:09 +08:00
}
bfstart( ) {
2020-11-01 20:15:11 +08:00
#读取配置文件
getconfig
2020-10-30 16:21:09 +08:00
[ ! -d $bindir /ui ] && mkdir -p $bindir /ui
2022-12-01 23:10:49 +08:00
[ -z " $update_url " ] && update_url = https://fastly.jsdelivr.net/gh/juewuy/ShellClash@master
#检查yaml配置文件
if [ ! -f $clashdir /config.yaml ] ; then
if [ -n " $Url " -o -n " $Https " ] ; then
logger "未找到配置文件,正在下载!" 33
getyaml
exit 0
else
logger "未找到配置文件链接,请先导入配置文件!" 31
exit 1
fi
fi
#检测vless/hysteria协议
if [ -n " $( cat $clashdir /config.yaml | grep -oE 'type: vless|type: hysteria' ) " ] && [ " $clashcore " != "clash.meta" ] ; then
echo -----------------------------------------------
logger "检测到vless/hysteria协议! 将改为使用clash.meta核心启动! " 33
rm -rf $bindir /clash
clashcore = clash.meta
setconfig clashcore clash.meta
echo -----------------------------------------------
fi
#检测是否存在高级版规则
if [ " $clashcore " = "clash" -a -n " $( cat $clashdir /config.yaml | grep -E '^script:|proxy-providers|rule-providers|rule-set' ) " ] ; then
echo -----------------------------------------------
2022-12-15 20:49:57 +08:00
logger "检测到高级规则! 将改为使用clash.meta核心启动! " 33
2022-12-01 23:10:49 +08:00
rm -rf $bindir /clash
2022-12-15 20:49:57 +08:00
clashcore = clash.meta
setconfig clashcore clash.meta
2022-12-01 23:10:49 +08:00
echo -----------------------------------------------
fi
2020-10-30 16:21:09 +08:00
#检查clash核心
if [ ! -f $bindir /clash ] ; then
if [ -f $clashdir /clash ] ; then
2023-01-15 20:58:15 +08:00
mv $clashdir /clash $bindir /clash
2020-10-30 16:21:09 +08:00
else
logger "未找到clash核心, 正在下载! " 33
2020-12-11 22:17:29 +08:00
if [ -z " $clashcore " ] ; then
2022-04-10 21:36:58 +08:00
[ " $redir_mod " = "混合模式" -o " $redir_mod " = "Tun模式" ] && clashcore = clashpre || clashcore = clash
2020-12-11 22:17:29 +08:00
fi
2020-10-30 16:21:09 +08:00
[ -z " $cpucore " ] && source $clashdir /getdate.sh && getcpucore
2020-11-01 11:38:26 +08:00
[ -z " $cpucore " ] && logger 找不到设备的CPU信息, 请手动指定处理器架构类型! 31 && setcpucore
2023-01-23 12:06:08 +08:00
[ " $update_url " = "https://jwsc.eu.org:8888" ] && [ " $clashcore " != 'clash' ] && update_url = https://fastly.jsdelivr.net/gh/juewuy/ShellClash@master
2021-06-18 13:18:19 +08:00
$0 webget $bindir /clash " $update_url /bin/ $clashcore /clash-linux- $cpucore "
2023-01-23 17:17:30 +08:00
#校验内核
chmod +x $bindir /clash 2>/dev/null
2023-04-14 21:15:15 +08:00
clashv = $( $bindir /clash -v 2>/dev/null | head -n 1 | sed 's/ linux.*//;s/.* //' )
2023-01-08 22:03:36 +08:00
if [ -z " $clashv " ] ; then
rm -rf $bindir /clash
logger "核心下载失败,请重新运行或更换安装源!" 31
exit 1
else
setconfig clashcore $clashcore
setconfig clashv $clashv
fi
2020-10-30 16:21:09 +08:00
fi
fi
2023-01-15 20:58:15 +08:00
[ ! -x $bindir /clash ] && chmod +x $bindir /clash #检测可执行权限
2020-10-30 16:21:09 +08:00
#检查数据库文件
if [ ! -f $bindir /Country.mmdb ] ; then
if [ -f $clashdir /Country.mmdb ] ; then
mv $clashdir /Country.mmdb $bindir /Country.mmdb
else
logger "未找到GeoIP数据库, 正在下载! " 33
2022-05-29 11:42:48 +08:00
$0 webget $bindir /Country.mmdb $update_url /bin/cn_mini.mmdb
2021-06-19 15:23:20 +08:00
[ " $? " = "1" ] && rm -rf $bindir /Country.mmdb && logger "数据库下载失败,已退出!" 31 && exit 1
2020-12-11 22:17:29 +08:00
Geo_v = $( date +"%Y%m%d" )
setconfig Geo_v $Geo_v
2020-10-30 16:21:09 +08:00
fi
fi
#检查dashboard文件
2022-01-02 23:38:35 +08:00
if [ -f $clashdir /ui/index.html -a ! -f $bindir /ui/index.html ] ; then
2020-10-30 16:21:09 +08:00
cp -rf $clashdir /ui $bindir
fi
2021-06-16 18:55:14 +08:00
#检查curl或wget支持
curl --version > /dev/null 2>& 1
[ " $? " = 1 ] && wget --version > /dev/null 2>& 1
[ " $? " = 1 ] && restore = true || restore = false
#生成pac文件
catpac
2023-01-25 16:35:14 +08:00
#预下载GeoSite数据库
if [ " $clashcore " = "clash.meta" ] && [ ! -f $bindir /GeoSite.dat ] && [ -n " $( cat $clashdir /config.yaml| grep -Ei 'geosite' ) " ] ; then
2023-02-01 10:13:35 +08:00
[ -f $clashdir /geosite.dat ] && mv -f $clashdir /geosite.dat $clashdir /GeoSite.dat
if [ -f $clashdir /GeoSite.dat ] ; then
mv -f $clashdir /GeoSite.dat $bindir /GeoSite.dat
2022-02-06 19:14:05 +08:00
else
logger "未找到geosite数据库, 正在下载! " 33
2023-01-25 16:35:14 +08:00
$0 webget $bindir /GeoSite.dat $update_url /bin/geosite.dat
[ " $? " = "1" ] && rm -rf $bindir /GeoSite.dat && logger "数据库下载失败,已退出!" 31 && exit 1
2022-02-06 19:14:05 +08:00
fi
fi
2021-06-16 18:55:14 +08:00
#本机代理准备
2022-11-12 22:54:46 +08:00
if [ " $local_proxy " = "已开启" -a -n " $( echo $local_type | grep '增强模式' ) " ] ; then
2021-06-16 18:55:14 +08:00
if [ -z " $( id shellclash 2>/dev/null | grep 'root' ) " ] ; then
2023-01-15 20:58:15 +08:00
if ckcmd userdel useradd groupmod; then
2022-05-31 12:58:37 +08:00
userdel shellclash 2>/dev/null
useradd shellclash -u 7890
groupmod shellclash -g 7890
sed -Ei s/7890:7890/0:7890/g /etc/passwd
2022-05-31 23:21:28 +08:00
else
grep -qw shellclash /etc/passwd || echo "shellclash:x:0:7890:::" >> /etc/passwd
2022-05-31 12:58:37 +08:00
fi
2021-06-16 18:55:14 +08:00
fi
if [ " $start_old " != "已开启" ] ; then
2022-05-31 23:21:28 +08:00
[ -w /etc/systemd/system/clash.service ] && servdir = /etc/systemd/system/clash.service
[ -w /usr/lib/systemd/system/clash.service ] && servdir = /usr/lib/systemd/system/clash.service
2022-05-31 12:58:37 +08:00
if [ -w /etc/init.d/clash ] ; then
2022-11-16 19:49:02 +08:00
[ -z " $( grep 'procd_set_param user shellclash' /etc/init.d/clash) " ] && \
2022-05-31 23:21:28 +08:00
sed -i '/procd_close_instance/i\\t\tprocd_set_param user shellclash' /etc/init.d/clash
elif [ -w " $servdir " ] ; then
2022-11-16 19:49:02 +08:00
setconfig ExecStart " /bin/su shellclash -c \" $bindir /clash -d $bindir \" " $servdir
2022-05-31 12:58:37 +08:00
systemctl daemon-reload >/dev/null
fi
2021-06-16 18:55:14 +08:00
fi
fi
2020-10-30 16:21:09 +08:00
}
2020-09-18 21:09:06 +08:00
afstart( ) {
2020-12-08 23:21:50 +08:00
2020-10-28 11:09:26 +08:00
#读取配置文件
getconfig
2022-12-01 23:10:49 +08:00
#延迟启动
2023-06-04 12:29:31 +08:00
[ ! -f $tmpdir /clash_start_time ] && [ -n " $start_delay " ] && [ " $start_delay " -gt 0 ] && {
2023-04-26 21:24:26 +08:00
logger " clash将延迟 $start_delay秒启动 " 31 pushoff
sleep $start_delay
2022-12-01 23:10:49 +08:00
}
2020-10-30 16:21:09 +08:00
$bindir /clash -t -d $bindir >/dev/null
2020-10-27 16:36:01 +08:00
if [ " $? " = 0 ] ; then
2022-11-13 18:11:22 +08:00
#设置DNS转发
2022-11-03 16:12:43 +08:00
start_dns( ) {
[ " $dns_mod " = "redir_host" ] && [ " $cn_ip_route " = "已开启" ] && cn_ip_route
2022-12-21 11:23:23 +08:00
[ " $ipv6_redir " = "已开启" ] && [ " $dns_mod " = "redir_host" ] && [ " $cn_ipv6_route " = "已开启" ] && cn_ipv6_route
2022-11-03 16:12:43 +08:00
if [ " $dns_no " != "已禁用" ] ; then
if [ " $dns_redir " != "已开启" ] ; then
2022-12-01 23:10:49 +08:00
[ -n " $( echo $redir_mod | grep Nft) " ] && start_nft_dns || start_ipt_dns
2022-11-03 16:12:43 +08:00
else
#openwrt使用dnsmasq转发
uci del dhcp.@dnsmasq[ -1] .server >/dev/null 2>& 1
uci delete dhcp.@dnsmasq[ 0] .resolvfile 2>/dev/null
uci add_list dhcp.@dnsmasq[ 0] .server= 127.0.0.1#$dns_port > /dev/null 2>& 1
uci set dhcp.@dnsmasq[ 0] .noresolv= 1 2>/dev/null
uci commit dhcp >/dev/null 2>& 1
/etc/init.d/dnsmasq restart >/dev/null 2>& 1
fi
2021-12-18 20:14:03 +08:00
fi
2023-04-12 21:03:18 +08:00
return 0
2022-11-03 16:12:43 +08:00
}
2022-11-13 18:11:22 +08:00
#设置路由规则
2023-04-04 20:45:35 +08:00
#[ "$ipv6_redir" = "已开启" ] && ipv6_wan=$(ip addr show|grep -A1 'inet6 [^f:]'|grep -oE 'inet6 ([a-f0-9:]+)/'|sed s#inet6\ ##g|sed s#/##g)
2022-11-03 16:12:43 +08:00
[ " $redir_mod " = "Redir模式" ] && start_dns && start_redir
2022-12-08 22:57:32 +08:00
[ " $redir_mod " = "混合模式" ] && start_dns && start_redir && start_tun udp
2022-11-03 16:12:43 +08:00
[ " $redir_mod " = "Tproxy混合" ] && start_dns && start_redir && start_tproxy udp
2022-12-08 22:57:32 +08:00
[ " $redir_mod " = "Tun模式" ] && start_dns && start_tun all
2022-11-03 16:12:43 +08:00
[ " $redir_mod " = "Tproxy模式" ] && start_dns && start_tproxy all
2023-04-04 20:45:35 +08:00
[ -n " $( echo $redir_mod | grep Nft) " -o " $local_type " = "nftables增强模式" ] && {
nft add table inet shellclash #初始化nftables
nft flush table inet shellclash
2022-12-01 23:10:49 +08:00
}
2023-04-04 20:45:35 +08:00
[ -n " $( echo $redir_mod | grep Nft) " ] && start_dns && start_nft
2022-11-13 18:11:22 +08:00
#设置本机代理
2023-03-17 23:32:30 +08:00
[ " $local_proxy " = "已开启" ] && {
[ " $local_type " = "环境变量" ] && $0 set_proxy $mix_port $db_port
[ " $local_type " = "iptables增强模式" ] && start_output
[ " $local_type " = "nftables增强模式" ] && [ " $redir_mod " = "纯净模式" ] && start_nft
}
2023-01-15 20:58:15 +08:00
ckcmd iptables && start_wan
2020-10-27 16:36:01 +08:00
#标记启动时间
mark_time
2021-06-05 19:27:28 +08:00
#加载定时任务
2022-03-16 20:33:59 +08:00
[ -f $clashdir /cron ] && croncmd $clashdir /cron
2020-10-27 16:36:01 +08:00
#启用面板配置自动保存
2023-04-25 20:37:57 +08:00
cronset '#每10分钟保存节点配置' " */10 * * * * test -n \"\$(pidof clash)\" && $clashdir /start.sh web_save #每10分钟保存节点配置 "
2022-03-12 16:21:41 +08:00
[ -f $clashdir /web_save ] && web_restore & #后台还原面板配置
2023-04-04 10:23:19 +08:00
#推送日志
2023-04-26 21:24:26 +08:00
{ sleep 5; logger Clash服务已启动! ; } &
#同步本机时间
{ ckcmd ntpd && ntpd -n -q -p 203.107.6.88 & >/dev/null; exit 0 ; } &
2020-10-27 16:36:01 +08:00
else
2023-04-12 21:03:18 +08:00
logger "Clash服务启动失败! 请查看报错信息! " 33
2023-04-17 20:12:25 +08:00
logger " $( $bindir /clash -t -d $bindir | grep -Eo 'error.*=.*' ) " 31
2020-11-01 20:15:11 +08:00
$0 stop
2020-10-27 16:36:01 +08:00
exit 1
fi
2020-08-22 20:08:23 +08:00
}
2020-10-27 09:40:58 +08:00
start_old( ) {
2020-10-30 16:21:09 +08:00
#使用传统后台执行二进制文件的方式执行
2022-11-12 22:54:46 +08:00
if [ " $local_proxy " = "已开启" -a -n " $( echo $local_type | grep '增强模式' ) " ] ; then
2023-05-13 20:43:15 +08:00
ckcmd su && su = su
$su shellclash -c " $bindir /clash -d $bindir >/dev/null " &
2021-06-16 18:55:14 +08:00
else
2023-01-15 20:58:15 +08:00
ckcmd nohup && nohup = nohup
2022-02-20 14:40:28 +08:00
$nohup $bindir /clash -d $bindir >/dev/null 2>& 1 &
2021-06-16 18:55:14 +08:00
fi
2020-10-27 09:40:58 +08:00
afstart
2022-03-16 20:33:59 +08:00
$0 daemon
2020-10-27 09:40:58 +08:00
}
2020-09-18 21:09:06 +08:00
case " $1 " in
2020-10-30 16:21:09 +08:00
bfstart)
bfstart
; ;
2020-09-18 21:09:06 +08:00
afstart)
afstart
; ;
start)
2023-04-25 20:37:57 +08:00
[ -n " $( pidof clash) " ] && $0 stop #禁止多实例
2020-09-18 21:09:06 +08:00
getconfig
2020-10-30 16:21:09 +08:00
#检测必须文件并下载
bfstart
2022-11-08 22:06:42 +08:00
stop_firewall #清理路由策略
2022-02-20 14:40:28 +08:00
#使用内置规则强行覆盖config配置文件
2023-05-13 20:43:15 +08:00
[ " $disoverride " != "1" ] && modify_yaml
2020-09-18 21:09:06 +08:00
#使用不同方式启动clash服务
if [ " $start_old " = "已开启" ] ; then
2020-10-27 09:40:58 +08:00
start_old
2020-09-18 21:09:06 +08:00
elif [ -f /etc/rc.common ] ; then
/etc/init.d/clash start
2020-10-27 09:40:58 +08:00
elif [ " $USER " = "root" ] ; then
2020-09-18 21:09:06 +08:00
systemctl start clash.service
2020-10-27 09:40:58 +08:00
else
start_old
2020-09-18 21:09:06 +08:00
fi
; ;
stop)
2020-10-06 17:56:17 +08:00
getconfig
2022-12-05 20:46:56 +08:00
logger Clash服务即将关闭……
2023-05-03 17:26:22 +08:00
[ -n " $( pidof clash) " ] && web_save #保存面板配置
2020-10-10 17:02:53 +08:00
#删除守护进程&面板配置自动保存
2020-10-27 09:40:58 +08:00
cronset "clash保守模式守护进程"
cronset "保存节点配置"
2022-02-20 14:40:28 +08:00
cronset "流媒体预解析"
2020-09-18 21:09:06 +08:00
#多种方式结束进程
if [ -f /etc/rc.common ] ; then
2020-09-19 16:32:50 +08:00
/etc/init.d/clash stop >/dev/null 2>& 1
2020-10-27 09:40:58 +08:00
elif [ " $USER " = "root" ] ; then
2020-09-19 16:32:50 +08:00
systemctl stop clash.service >/dev/null 2>& 1
2020-09-18 21:09:06 +08:00
fi
2023-04-25 20:37:57 +08:00
PID = $( pidof clash) && [ -n " $PID " ] && kill -9 $PID >/dev/null 2>& 1
2022-11-08 22:06:42 +08:00
stop_firewall #清理路由策略
2021-06-16 18:55:14 +08:00
$0 unset_proxy #禁用本机代理
2020-09-18 21:09:06 +08:00
; ;
restart)
$0 stop
$0 start
; ;
2021-06-05 12:53:20 +08:00
init)
2023-04-26 21:24:26 +08:00
clashdir = $( cd $( dirname $0 ) ; pwd )
profile = /etc/profile
2021-07-26 16:50:00 +08:00
if [ -d "/etc/storage/clash" ] ; then
clashdir = /etc/storage/clash
2022-03-26 02:11:09 +08:00
i = 1
2023-04-26 21:24:26 +08:00
while [ ! -w /etc/profile -a " $i " -lt 10 ] ; do
2022-09-22 20:36:53 +08:00
sleep 5 && i = $(( i+1))
2022-03-25 20:25:24 +08:00
done
profile = /etc/profile
sed -i '' $profile #将软链接转化为一般文件
2022-11-13 18:33:32 +08:00
elif [ -d "/jffs" ] ; then
2023-04-26 21:24:26 +08:00
sleep 60
2022-09-22 20:36:53 +08:00
if [ -w /etc/profile ] ; then
profile = /etc/profile
else
profile = $( cat /etc/profile | grep -oE '\-f.*jffs.*profile' | awk '{print $2}' )
fi
2021-07-26 16:50:00 +08:00
fi
2022-09-22 20:36:53 +08:00
sed -i "/alias clash/d" $profile
sed -i "/export clashdir/d" $profile
2021-06-05 19:17:26 +08:00
echo " alias clash=\" $clashdir /clash.sh\" " >> $profile
echo " export clashdir=\" $clashdir \" " >> $profile
2022-03-16 16:30:07 +08:00
[ -f $clashdir /.dis_startup ] && cronset "clash保守模式守护进程" || $0 start
2021-06-05 12:53:20 +08:00
; ;
2020-09-18 21:09:06 +08:00
getyaml)
getconfig
2022-12-04 20:54:09 +08:00
getyaml && \
2022-12-05 20:46:56 +08:00
logger ShellClash配置文件更新成功!
2020-09-18 21:09:06 +08:00
; ;
2020-12-12 12:20:22 +08:00
updateyaml)
2022-06-06 13:03:42 +08:00
getconfig
2022-12-04 20:54:09 +08:00
getyaml && \
modify_yaml && \
2023-04-11 14:25:09 +08:00
put_save http://127.0.0.1:${ db_port } /configs " {\"path\":\" ${ clashdir } /config.yaml\"} " && \
2022-12-05 20:46:56 +08:00
logger ShellClash配置文件更新成功!
2020-12-12 12:20:22 +08:00
; ;
2022-12-04 20:54:09 +08:00
logger)
logger $2 $3
; ;
2020-10-30 16:21:09 +08:00
webget)
2022-12-04 20:54:09 +08:00
#设置临时代理
2023-04-25 20:37:57 +08:00
if [ -n " $( pidof clash) " ] ; then
2022-11-25 21:47:03 +08:00
getconfig
2022-12-04 20:54:09 +08:00
[ -n " $authentication " ] && auth = " $authentication @ "
2023-04-28 19:49:11 +08:00
export all_proxy = " http:// ${ auth } 127.0.0.1: $mix_port "
2023-04-26 21:24:26 +08:00
url = $( echo $3 | sed 's#https://fastly.jsdelivr.net/gh/juewuy/ShellClash[@|/]#https://raw.githubusercontent.com/juewuy/ShellClash/#' | sed 's#https://gh.jwsc.eu.org/#https://raw.githubusercontent.com/juewuy/ShellClash/#' )
2022-12-07 22:07:37 +08:00
else
2023-04-26 21:24:26 +08:00
url = $( echo $3 | sed 's#https://raw.githubusercontent.com/juewuy/ShellClash/#https://fastly.jsdelivr.net/gh/juewuy/ShellClash@#' )
2022-12-07 22:07:37 +08:00
fi
2021-06-19 15:23:20 +08:00
#参数【$2】代表下载目录, 【$3】代表在线地址
#参数【$4】代表输出显示, 【$4】不启用重定向
2023-01-23 15:38:07 +08:00
#参数【$6】代表验证证书
2021-06-19 15:23:20 +08:00
if curl --version > /dev/null 2>& 1; then
[ " $4 " = "echooff" ] && progress = '-s' || progress = '-#'
[ " $5 " = "rediroff" ] && redirect = '' || redirect = '-L'
[ " $6 " = "skipceroff" ] && certificate = '' || certificate = '-k'
2023-01-17 19:55:45 +08:00
result = $( curl $agent -w %{ http_code} --connect-timeout 3 $progress $redirect $certificate -o " $2 " " $url " )
2023-04-28 19:49:11 +08:00
[ " $result " != "200" ] && export all_proxy = "" && result = $( curl $agent -w %{ http_code} --connect-timeout 3 $progress $redirect $certificate -o " $2 " " $3 " )
2021-06-19 15:23:20 +08:00
else
if wget --version > /dev/null 2>& 1; then
[ " $4 " = "echooff" ] && progress = '-q' || progress = '-q --show-progress'
[ " $5 " = "rediroff" ] && redirect = '--max-redirect=0' || redirect = ''
[ " $6 " = "skipceroff" ] && certificate = '' || certificate = '--no-check-certificate'
timeout = '--timeout=3 -t 2'
fi
[ " $4 " = "echoon" ] && progress = ''
[ " $4 " = "echooff" ] && progress = '-q'
2022-12-07 22:07:37 +08:00
wget -Y on $agent $progress $redirect $certificate $timeout -O " $2 " " $url "
2021-06-19 15:23:20 +08:00
if [ " $? " != "0" ] ; then
wget -Y off $agent $progress $redirect $certificate $timeout -O " $2 " " $3 "
[ " $? " = "0" ] && result = "200"
else
result = "200"
fi
fi
[ " $result " = "200" ] && exit 0 || exit 1
2020-10-30 16:21:09 +08:00
; ;
2023-05-13 20:43:15 +08:00
get_save)
get_save $2
; ;
2020-10-10 17:02:53 +08:00
web_save)
getconfig
web_save
; ;
2021-01-29 15:11:35 +08:00
web_restore)
getconfig
web_restore
; ;
2020-10-27 16:36:01 +08:00
daemon)
getconfig
2023-04-25 20:37:57 +08:00
cronset '#clash保守模式守护进程' " */1 * * * * test -z \"\$(pidof clash)\" && $clashdir /start.sh restart #clash保守模式守护进程 "
2020-10-27 16:36:01 +08:00
; ;
2020-12-21 11:55:43 +08:00
cronset)
cronset $2 $3
; ;
2020-10-11 21:30:20 +08:00
set_proxy)
2020-10-28 11:09:26 +08:00
getconfig
2021-06-16 18:55:14 +08:00
if [ " $local_type " = "环境变量" ] ; then
2020-10-24 21:13:06 +08:00
[ -w ~/.bashrc ] && profile = ~/.bashrc
[ -w /etc/profile ] && profile = /etc/profile
2020-10-28 11:09:26 +08:00
echo 'export all_proxy=http://127.0.0.1:' " $mix_port " >> $profile
2020-10-24 21:13:06 +08:00
echo 'export ALL_PROXY=$all_proxy' >> $profile
2020-10-23 07:23:38 +08:00
fi
2020-10-11 21:30:20 +08:00
; ;
2021-05-15 16:25:18 +08:00
unset_proxy)
2020-10-28 11:09:26 +08:00
[ -w ~/.bashrc ] && profile = ~/.bashrc
[ -w /etc/profile ] && profile = /etc/profile
sed -i '/all_proxy/' d $profile
sed -i '/ALL_PROXY/' d $profile
2020-10-10 17:02:53 +08:00
; ;
2023-04-02 19:46:08 +08:00
*)
$1 $2 $3 $4 $5 $6 $7
; ;
2023-01-23 17:17:30 +08:00
2020-09-18 21:09:06 +08:00
esac
2020-10-09 19:21:28 +08:00
exit 0