mirror of
https://github.com/juewuy/ShellCrash.git
synced 2024-11-16 19:55:57 +08:00
v0.9.8
~新增保守方式启动,适配更多设备(小米3HD,以及其他linux系统) ~新增进阶功能菜单 ~修复了geoip数据库偶尔丢失的bug(感谢Pan Peter同学提交bug!) ~UI优化
This commit is contained in:
parent
d090e2d9a9
commit
7971101f16
Binary file not shown.
|
@ -1,2 +1,2 @@
|
||||||
GeoIP_v=20200817
|
GeoIP_v=20200817
|
||||||
versionsh=0.9.7
|
versionsh=0.9.8
|
||||||
|
|
|
@ -24,7 +24,10 @@ source $ccfg
|
||||||
#检查mac地址记录
|
#检查mac地址记录
|
||||||
[ ! -f $clashdir/mac ] && touch $clashdir/mac
|
[ ! -f $clashdir/mac ] && touch $clashdir/mac
|
||||||
#获取自启状态
|
#获取自启状态
|
||||||
if [ -f /etc/rc.d/*clash ];then
|
if [ "$start_old" = "已开启" ];then
|
||||||
|
auto="\033[33m已设置保守模式!\033[0m"
|
||||||
|
auto1="\033[36m设为\033[0m常规模式启动"
|
||||||
|
elif [ -f /etc/rc.d/*clash ];then
|
||||||
auto="\033[32m已设置开机启动!\033[0m"
|
auto="\033[32m已设置开机启动!\033[0m"
|
||||||
auto1="\033[36m禁用\033[0mclash开机启动"
|
auto1="\033[36m禁用\033[0mclash开机启动"
|
||||||
else
|
else
|
||||||
|
@ -144,6 +147,7 @@ echo -e " 3 选取\033[33m代理规则\033[0m模版"
|
||||||
echo -e " 4 选择配置生成服务器"
|
echo -e " 4 选择配置生成服务器"
|
||||||
echo -e " 5 \033[36m还原\033[0m配置文件"
|
echo -e " 5 \033[36m还原\033[0m配置文件"
|
||||||
echo -e " 6 \033[32m手动更新\033[0m订阅"
|
echo -e " 6 \033[32m手动更新\033[0m订阅"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 0 返回上级菜单"
|
echo -e " 0 返回上级菜单"
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [ -z "$num" ];then
|
if [ -z "$num" ];then
|
||||||
|
@ -193,6 +197,7 @@ elif [[ $num == 3 ]];then
|
||||||
echo 6 ACL4SSR通用版无自动测速
|
echo 6 ACL4SSR通用版无自动测速
|
||||||
echo 7 ACL4SSR精简版无自动测速
|
echo 7 ACL4SSR精简版无自动测速
|
||||||
echo 8 ACL4SSR超重度奈飞全量
|
echo 8 ACL4SSR超重度奈飞全量
|
||||||
|
echo -----------------------------------------------
|
||||||
echo 0 返回上级菜单
|
echo 0 返回上级菜单
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [ -z "$num" ];then
|
if [ -z "$num" ];then
|
||||||
|
@ -221,6 +226,7 @@ elif [[ $num == 4 ]];then
|
||||||
echo 5 api.wcc.best
|
echo 5 api.wcc.best
|
||||||
echo 6 skapi.cool
|
echo 6 skapi.cool
|
||||||
echo 7 subconvert.dreamcloud.pw
|
echo 7 subconvert.dreamcloud.pw
|
||||||
|
echo -----------------------------------------------
|
||||||
echo 0 返回上级菜单
|
echo 0 返回上级菜单
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [ -z "$num" ];then
|
if [ -z "$num" ];then
|
||||||
|
@ -305,8 +311,10 @@ echo -e " 3 跳过本地证书验证: \033[36m$skip_cert\033[0m ————
|
||||||
echo -e " 4 只代理常用端口: \033[36m$common_ports\033[0m ————用于屏蔽P2P流量"
|
echo -e " 4 只代理常用端口: \033[36m$common_ports\033[0m ————用于屏蔽P2P流量"
|
||||||
echo -e " 5 过滤局域网mac地址: \033[36m$mac_return\033[0m ————列表内设备不走代理"
|
echo -e " 5 过滤局域网mac地址: \033[36m$mac_return\033[0m ————列表内设备不走代理"
|
||||||
echo -e " 6 不使用本地DNS服务: \033[36m$dns_over\033[0m ————防止redir-host模式的dns污染"
|
echo -e " 6 不使用本地DNS服务: \033[36m$dns_over\033[0m ————防止redir-host模式的dns污染"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 9 \033[32m重启\033[0mclash服务"
|
echo -e " 9 \033[32m重启\033[0mclash服务"
|
||||||
echo -e " 0 返回上级菜单 \033[0m"
|
echo -e " 0 返回上级菜单 \033[0m"
|
||||||
|
echo -----------------------------------------------
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
if [[ $num == 0 ]]; then
|
if [[ $num == 0 ]]; then
|
||||||
|
@ -535,8 +543,10 @@ echo -----------------------------------------------
|
||||||
echo -e " 1 不修饰config.yaml: \033[36m$modify_yaml\033[0m ————用于使用自定义配置"
|
echo -e " 1 不修饰config.yaml: \033[36m$modify_yaml\033[0m ————用于使用自定义配置"
|
||||||
echo -e " 2 启用ipv6支持: \033[36m$ipv6_support\033[0m ————实验性且不兼容Fake_ip"
|
echo -e " 2 启用ipv6支持: \033[36m$ipv6_support\033[0m ————实验性且不兼容Fake_ip"
|
||||||
echo -e " 3 使用保守方式启动: \033[36m$start_old\033[0m ————如正常方式无法启动"
|
echo -e " 3 使用保守方式启动: \033[36m$start_old\033[0m ————如正常方式无法启动"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 9 \033[32m重启\033[0mclash服务"
|
echo -e " 9 \033[32m重启\033[0mclash服务"
|
||||||
echo -e " 0 返回上级菜单 \033[0m"
|
echo -e " 0 返回上级菜单 \033[0m"
|
||||||
|
echo -----------------------------------------------
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
if [[ $num == 0 ]]; then
|
if [[ $num == 0 ]]; then
|
||||||
|
@ -551,6 +561,7 @@ if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
echo -e "\033[0m不明白原理的用户切勿随意开启此选项"
|
echo -e "\033[0m不明白原理的用户切勿随意开启此选项"
|
||||||
echo -e "\033[33m!!!必然会导致上不了网!!!\033[0m"
|
echo -e "\033[33m!!!必然会导致上不了网!!!\033[0m"
|
||||||
modify_yaml=已开启
|
modify_yaml=已开启
|
||||||
|
sleep 3
|
||||||
else
|
else
|
||||||
sed -i "1i\modify_yaml=未开启" $ccfg
|
sed -i "1i\modify_yaml=未开启" $ccfg
|
||||||
echo -e "\033[32m已设为使用脚本内置规则管理config.yaml配置文件!!\033[0m"
|
echo -e "\033[32m已设为使用脚本内置规则管理config.yaml配置文件!!\033[0m"
|
||||||
|
@ -566,6 +577,7 @@ if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
echo -e "\033[33m已开启对ipv6协议的支持!!\033[0m"
|
echo -e "\033[33m已开启对ipv6协议的支持!!\033[0m"
|
||||||
echo -e "Clash对ipv6的支持并不友好,如不能使用请静等修复!"
|
echo -e "Clash对ipv6的支持并不友好,如不能使用请静等修复!"
|
||||||
ipv6_support=已开启
|
ipv6_support=已开启
|
||||||
|
sleep 2
|
||||||
else
|
else
|
||||||
sed -i "1i\ipv6_support=未开启" $ccfg
|
sed -i "1i\ipv6_support=未开启" $ccfg
|
||||||
echo -e "\033[32m已禁用对ipv6协议的支持!!\033[0m"
|
echo -e "\033[32m已禁用对ipv6协议的支持!!\033[0m"
|
||||||
|
@ -579,9 +591,11 @@ if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
if [ "$start_old" = "未开启" ] > /dev/null 2>&1; then
|
if [ "$start_old" = "未开启" ] > /dev/null 2>&1; then
|
||||||
sed -i "1i\start_old=已开启" $ccfg
|
sed -i "1i\start_old=已开启" $ccfg
|
||||||
echo -e "\033[33m改为使用保守方式启动clash服务!!\033[0m"
|
echo -e "\033[33m改为使用保守方式启动clash服务!!\033[0m"
|
||||||
|
echo -e "\033[36m此模式兼容性更好但无法禁用开机启动!!\033[0m"
|
||||||
clashstop
|
clashstop
|
||||||
echo -e "已停止clash服务,请手动启动服务!"
|
echo -e "已停止clash服务,请手动启动服务!"
|
||||||
start_old=已开启
|
start_old=已开启
|
||||||
|
sleep 2
|
||||||
else
|
else
|
||||||
sed -i "1i\start_old=未开启" $ccfg
|
sed -i "1i\start_old=未开启" $ccfg
|
||||||
echo -e "\033[32m改为使用默认方式启动clash服务!!\033[0m"
|
echo -e "\033[32m改为使用默认方式启动clash服务!!\033[0m"
|
||||||
|
@ -615,9 +629,11 @@ echo -e " 1 更新\033[36m管理脚本\033[0m"
|
||||||
echo -e " 2 切换\033[33mclash核心\033[0m"
|
echo -e " 2 切换\033[33mclash核心\033[0m"
|
||||||
echo -e " 3 更新\033[32mGeoIP数据库\033[0m"
|
echo -e " 3 更新\033[32mGeoIP数据库\033[0m"
|
||||||
echo -e " 4 安装本地\033[35mDashboard\033[0m面板"
|
echo -e " 4 安装本地\033[35mDashboard\033[0m面板"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 8 切换\033[36m安装源\033[0m地址"
|
echo -e " 8 切换\033[36m安装源\033[0m地址"
|
||||||
echo -e " 9 \033[31m卸载\033[34mClash for Miwfi\033[0m"
|
echo -e " 9 \033[31m卸载\033[34mClash for Miwfi\033[0m"
|
||||||
echo -e " 0 返回上级菜单"
|
echo -e " 0 返回上级菜单"
|
||||||
|
echo -----------------------------------------------
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
if [[ $num == 0 ]]; then
|
if [[ $num == 0 ]]; then
|
||||||
|
@ -678,8 +694,10 @@ clashcron(){
|
||||||
echo -e " 输入 1-7 对应\033[33m每周相应天\033[0m运行"
|
echo -e " 输入 1-7 对应\033[33m每周相应天\033[0m运行"
|
||||||
echo -e " 输入 8 设为\033[33m每天定时\033[0m运行"
|
echo -e " 输入 8 设为\033[33m每天定时\033[0m运行"
|
||||||
echo -e " 输入 1,3,6 代表\033[36m每周1,3,6\033[0m运行(注意用小写逗号分隔)"
|
echo -e " 输入 1,3,6 代表\033[36m每周1,3,6\033[0m运行(注意用小写逗号分隔)"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 输入 9 \033[31m删除定时任务\033[0m"
|
echo -e " 输入 9 \033[31m删除定时任务\033[0m"
|
||||||
echo -e " 输入 0 返回上级菜单"
|
echo -e " 输入 0 返回上级菜单"
|
||||||
|
echo -----------------------------------------------
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [ -z "$num" ]; then
|
if [ -z "$num" ]; then
|
||||||
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
@ -766,6 +784,7 @@ echo -e " 1 设置\033[33m定时重启\033[0mclash服务"
|
||||||
echo -e " 2 设置\033[31m定时停止\033[0mclash服务"
|
echo -e " 2 设置\033[31m定时停止\033[0mclash服务"
|
||||||
echo -e " 3 设置\033[32m定时开启\033[0mclash服务"
|
echo -e " 3 设置\033[32m定时开启\033[0mclash服务"
|
||||||
echo -e " 4 设置\033[33m定时更新\033[0m订阅链接(实验性,可能不稳定)"
|
echo -e " 4 设置\033[33m定时更新\033[0m订阅链接(实验性,可能不稳定)"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 0 返回上级菜单"
|
echo -e " 0 返回上级菜单"
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [ -z "$num" ]; then
|
if [ -z "$num" ]; then
|
||||||
|
@ -812,6 +831,7 @@ echo -e " 6 导入\033[32m节点/订阅\033[0m链接"
|
||||||
echo -e " 7 clash\033[31m进阶设置\033[0m"
|
echo -e " 7 clash\033[31m进阶设置\033[0m"
|
||||||
echo -e " 8 \033[35m测试菜单\033[0m"
|
echo -e " 8 \033[35m测试菜单\033[0m"
|
||||||
echo -e " 9 \033[36m更新/卸载\033[0m"
|
echo -e " 9 \033[36m更新/卸载\033[0m"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo -e " 0 \033[0m退出脚本\033[0m"
|
echo -e " 0 \033[0m退出脚本\033[0m"
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
|
@ -835,7 +855,12 @@ if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
|
|
||||||
elif [[ $num == 4 ]]; then
|
elif [[ $num == 4 ]]; then
|
||||||
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
if [ -f /etc/rc.d/*clash ]; then
|
if [ "$start_old" = "已开启" ];then
|
||||||
|
sed -i "/start_old*/d" $ccfg
|
||||||
|
sed -i "1i\start_old=未开启" $ccfg
|
||||||
|
echo -e "\033[32m已设为使用默认方式启动clash服务!!\033[0m"
|
||||||
|
start_old=未开启
|
||||||
|
elif [ -f /etc/rc.d/*clash ]; then
|
||||||
/etc/init.d/clash disable
|
/etc/init.d/clash disable
|
||||||
echo -e "\033[33m已禁止Clash开机启动!\033[0m"
|
echo -e "\033[33m已禁止Clash开机启动!\033[0m"
|
||||||
else
|
else
|
||||||
|
@ -864,6 +889,7 @@ if [[ $num -le 9 ]] > /dev/null 2>&1; then
|
||||||
echo " 4 查看iptables端口转发详情"
|
echo " 4 查看iptables端口转发详情"
|
||||||
echo " 5 查看config.yaml前40行"
|
echo " 5 查看config.yaml前40行"
|
||||||
echo " 6 测试代理服务器连通性(google.tw)"
|
echo " 6 测试代理服务器连通性(google.tw)"
|
||||||
|
echo -----------------------------------------------
|
||||||
echo " 0 返回上级目录!"
|
echo " 0 返回上级目录!"
|
||||||
read -p "请输入对应数字 > " num
|
read -p "请输入对应数字 > " num
|
||||||
if [ -z "$num" ]; then
|
if [ -z "$num" ]; then
|
||||||
|
|
|
@ -21,7 +21,6 @@ start_service() {
|
||||||
procd_set_param stdout 1
|
procd_set_param stdout 1
|
||||||
procd_set_param command $clashdir/clash -d $clashdir
|
procd_set_param command $clashdir/clash -d $clashdir
|
||||||
procd_close_instance
|
procd_close_instance
|
||||||
echo $ccfg
|
|
||||||
#修改iptables规则使流量进入clash
|
#修改iptables规则使流量进入clash
|
||||||
stop_iptables
|
stop_iptables
|
||||||
start_dns
|
start_dns
|
||||||
|
|
|
@ -456,8 +456,9 @@ if [ "$res" = '1' ]; then
|
||||||
echo -e "\033[33m下载成功,正在解压文件!\033[0m"
|
echo -e "\033[33m下载成功,正在解压文件!\033[0m"
|
||||||
if cat /proc/mounts | grep -q www ;then
|
if cat /proc/mounts | grep -q www ;then
|
||||||
echo 检测到/www为只读,正在重新挂载!
|
echo 检测到/www为只读,正在重新挂载!
|
||||||
mount -o remount -rw /www
|
mount -o remount -w /www
|
||||||
fi
|
fi
|
||||||
|
chmod 755 /www
|
||||||
mkdir -p /www/clash > /dev/null
|
mkdir -p /www/clash > /dev/null
|
||||||
tar -zxvf '/tmp/clashdb.tar.gz' -C /www/clash > /dev/null
|
tar -zxvf '/tmp/clashdb.tar.gz' -C /www/clash > /dev/null
|
||||||
[ $? -ne 0 ] && echo "文件解压失败!" && exit 1
|
[ $? -ne 0 ] && echo "文件解压失败!" && exit 1
|
||||||
|
|
182
scripts/start.sh
Normal file
182
scripts/start.sh
Normal file
|
@ -0,0 +1,182 @@
|
||||||
|
#!/bin/sh
|
||||||
|
# Copyright (C) Juewuy
|
||||||
|
|
||||||
|
getconfig(){
|
||||||
|
ccfg=$clashdir/mark
|
||||||
|
if [ ! -f "$ccfg" ]; then
|
||||||
|
echo mark文件不存在,默认以Redir模式运行!
|
||||||
|
cat >$ccfg<<EOF
|
||||||
|
#标识clash运行状态的文件,不明勿动!
|
||||||
|
EOF
|
||||||
|
#指定一些默认状态
|
||||||
|
redir_mod=redir模式
|
||||||
|
modify_yaml=未开启
|
||||||
|
fi
|
||||||
|
source $ccfg #加载配置文件
|
||||||
|
#是否代理常用端口
|
||||||
|
[ "$common_ports" = "已开启" ] && ports='-m multiport --dports 22,53,587,465,995,993,143,80,443 '
|
||||||
|
#检测系统端口占用
|
||||||
|
for portx in 1053 7890 7892 9999 ;do
|
||||||
|
[ -n "$(netstat -ntulp |grep :$portx|grep -v clash)" ] && echo -e "检测到端口:\033[30;47m $portx \033[0m被以下进程占用!clash无法启动!" && echo $(netstat -ntulp |grep :$portx) && exit;
|
||||||
|
done
|
||||||
|
}
|
||||||
|
modify_yaml(){
|
||||||
|
##########需要变更的配置###########
|
||||||
|
mix='mixed-port: 7890'
|
||||||
|
redir='redir-port: 7892'
|
||||||
|
lan='allow-lan: true'
|
||||||
|
mode='mode: Rule'
|
||||||
|
log='log-level: info'
|
||||||
|
if [ "$ipv6_support" = "已开启" ];then
|
||||||
|
ipv6='ipv6: true'
|
||||||
|
else
|
||||||
|
ipv6='ipv6: false'
|
||||||
|
fi
|
||||||
|
external='external-controller: 0.0.0.0:9999'
|
||||||
|
if [ "$dns_mod" = "fake-ip" ];then
|
||||||
|
dns='dns: {enable: true, listen: 0.0.0.0:1053, fake-ip-range: 198.18.0.1/16, enhanced-mode: fake-ip, nameserver: [114.114.114.114, 127.0.0.1:53], fallback: [tcp://1.0.0.1, 8.8.4.4]}'
|
||||||
|
elif [ "$dns_over" = "已开启" ];then
|
||||||
|
dns='dns: {enable: true, ipv6: true, listen: 0.0.0.0:1053, enhanced-mode: redir-host, nameserver: [114.114.114.114, 223.5.5.5], fallback: [1.0.0.1, 8.8.4.4]}'
|
||||||
|
else
|
||||||
|
dns='dns: {enable: true, ipv6: true, listen: 0.0.0.0:1053, enhanced-mode: redir-host, nameserver: [114.114.114.114, 223.5.5.5, 127.0.0.1:53], fallback: [1.0.0.1, 8.8.4.4]}'
|
||||||
|
fi
|
||||||
|
if [ "$redir_mod" != "Redir模式" ];then
|
||||||
|
tun='tun: {enable: true, stack: system}'
|
||||||
|
else
|
||||||
|
tun='tun: {enable: false}'
|
||||||
|
fi
|
||||||
|
exper='experimental: {ignore-resolve-fail: true, interface-name: en0}'
|
||||||
|
###################################
|
||||||
|
#预删除需要添加的项目
|
||||||
|
i=$(grep -n "^proxies:" $clashdir/config.yaml | head -1 | cut -d ":" -f 1)
|
||||||
|
i=$(($i-1))
|
||||||
|
sed -i '1,'$i'd' $clashdir/config.yaml
|
||||||
|
#添加配置
|
||||||
|
sed -i "1i$mix" $clashdir/config.yaml
|
||||||
|
sed -i "1a$redir" $clashdir/config.yaml
|
||||||
|
sed -i "2a$lan" $clashdir/config.yaml
|
||||||
|
sed -i "3a$mode" $clashdir/config.yaml
|
||||||
|
sed -i "4a$log" $clashdir/config.yaml
|
||||||
|
sed -i "5a$ipv6" $clashdir/config.yaml
|
||||||
|
sed -i "6a$external" $clashdir/config.yaml
|
||||||
|
sed -i "7a$dns" $clashdir/config.yaml
|
||||||
|
sed -i "8a$tun" $clashdir/config.yaml
|
||||||
|
sed -i "9a$exper" $clashdir/config.yaml
|
||||||
|
#跳过本地tls证书验证
|
||||||
|
if [ "$skip_cert" != "未开启" ];then
|
||||||
|
sed -i "10,99s/sni: \S*/\1skip-cert-verify: true}/" $clashdir/config.yaml #跳过trojan本地证书验证
|
||||||
|
sed -i '10,99s/}}/}, skip-cert-verify: true}/' $clashdir/config.yaml #跳过v2+ssl本地证书验证
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
mark_time(){
|
||||||
|
start_time=`date +%s`
|
||||||
|
sed -i '/start_time*/'d $ccfg
|
||||||
|
sed -i "3i\start_time=$start_time" $ccfg
|
||||||
|
}
|
||||||
|
start_redir(){
|
||||||
|
#修改iptables规则使流量进入clash
|
||||||
|
iptables -t nat -N clash
|
||||||
|
iptables -t nat -A clash -d 0.0.0.0/8 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 10.0.0.0/8 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 127.0.0.0/8 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 169.254.0.0/16 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 172.16.0.0/12 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 192.168.0.0/16 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 224.0.0.0/4 -j RETURN
|
||||||
|
iptables -t nat -A clash -d 240.0.0.0/4 -j RETURN
|
||||||
|
for mac in $(cat $clashdir/mac); do
|
||||||
|
iptables -t nat -A clash -m mac --mac-source $mac -j RETURN
|
||||||
|
done
|
||||||
|
|
||||||
|
iptables -t nat -A clash -p tcp $ports-j REDIRECT --to-ports 7892
|
||||||
|
iptables -t nat -A PREROUTING -p tcp -j clash
|
||||||
|
if [ "$ipv6_support" = "已开启" ];then
|
||||||
|
ip6tables -t nat -N clash
|
||||||
|
for mac in $(cat $clashdir/mac); do
|
||||||
|
ip6tables -t nat -A clash -m mac --mac-source $mac -j RETURN
|
||||||
|
done
|
||||||
|
ip6tables -t nat -A clash -p tcp $ports-j REDIRECT --to-ports 7892
|
||||||
|
ip6tables -t nat -A PREROUTING -p tcp -j clash
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
stop_iptables(){
|
||||||
|
#重置iptables规则
|
||||||
|
iptables -t nat -D PREROUTING -p tcp -j clash > /dev/null 2>&1
|
||||||
|
iptables -t nat -D PREROUTING -p udp -j clash_dns > /dev/null 2>&1
|
||||||
|
iptables -t nat -F clash > /dev/null 2>&1
|
||||||
|
iptables -t nat -X clash > /dev/null 2>&1
|
||||||
|
iptables -t nat -F clash_dns > /dev/null 2>&1
|
||||||
|
iptables -t nat -X clash_dns > /dev/null 2>&1
|
||||||
|
#重置ipv6规则
|
||||||
|
ip6tables -t nat -D PREROUTING -p tcp -j clash > /dev/null 2>&1
|
||||||
|
ip6tables -t nat -D PREROUTING -p udp -j clash_dns > /dev/null 2>&1
|
||||||
|
ip6tables -t nat -F clash > /dev/null 2>&1
|
||||||
|
ip6tables -t nat -X clash > /dev/null 2>&1
|
||||||
|
ip6tables -t nat -F clash_dns > /dev/null 2>&1
|
||||||
|
ip6tables -t nat -X clash_dns > /dev/null 2>&1
|
||||||
|
}
|
||||||
|
start_dns(){
|
||||||
|
#允许tun网卡接受流量
|
||||||
|
iptables -I FORWARD -o utun -j ACCEPT
|
||||||
|
ip6tables -I FORWARD -o utun -j ACCEPT
|
||||||
|
#设置dns转发
|
||||||
|
iptables -t nat -N clash_dns
|
||||||
|
for mac in $(cat $clashdir/mac); do
|
||||||
|
iptables -t nat -A clash_dns -m mac --mac-source $mac -j RETURN
|
||||||
|
done
|
||||||
|
iptables -t nat -A clash_dns -p udp --dport 53 -j REDIRECT --to 1053
|
||||||
|
iptables -t nat -A PREROUTING -p udp -j clash_dns
|
||||||
|
#ipv6DNS
|
||||||
|
ip6tables -t nat -N clash_dns
|
||||||
|
for mac in $(cat $clashdir/mac); do
|
||||||
|
ip6tables -t nat -A clash_dns -m mac --mac-source $mac -j RETURN
|
||||||
|
done
|
||||||
|
ip6tables -t nat -A clash_dns -p udp --dport 53 -j REDIRECT --to 1053
|
||||||
|
ip6tables -t nat -A PREROUTING -p udp -j clash_dns
|
||||||
|
}
|
||||||
|
daemon_old(){
|
||||||
|
#守护进程状态
|
||||||
|
status=$(ps |grep -w 'clash -d'|grep -v grep)
|
||||||
|
[ -z $status ] && $clashdir/clash -d $clashdir && mark_time
|
||||||
|
}
|
||||||
|
checkcron(){
|
||||||
|
if [ -d /etc/crontabs/ ]; then
|
||||||
|
cronpath="/etc/crontabs/root"
|
||||||
|
elif [ -d /var/spool/cron/ ]; then
|
||||||
|
cronpath="/var/spool/cron/root"
|
||||||
|
elif [ -d /var/spool/cron/crontabs/ ]; then
|
||||||
|
cronpath="/var/spool/cron/crontabs/root"
|
||||||
|
else
|
||||||
|
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
echo "找不到定时任务文件,无法添加定时任务!"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
start_old(){
|
||||||
|
#读取配置文件
|
||||||
|
getconfig
|
||||||
|
#使用内置规则强行覆盖config配置文件
|
||||||
|
[ "$modify_yaml" != "已开启" ] && modify_yaml
|
||||||
|
#创建clash后台进程
|
||||||
|
$clashdir/clash -d $clashdir> /dev/null &
|
||||||
|
#修改iptables规则使流量进入clash
|
||||||
|
stop_iptables
|
||||||
|
start_dns
|
||||||
|
[ "$redir_mod" != "Tun模式" ] && start_redir
|
||||||
|
#标记启动时间
|
||||||
|
mark_time
|
||||||
|
#创建守护进程
|
||||||
|
checkcron
|
||||||
|
sed -i /start.sh/d $cronpath
|
||||||
|
echo "*/1 * * * * source /etc/profile && source $clashdir/start.sh && daemon_old >/dev/null 2>&1" >> $cronpath
|
||||||
|
#设定启动方式
|
||||||
|
sed -i /start_old=*/d $ccfg
|
||||||
|
sed -i "1i\start_old=已开启" $ccfg
|
||||||
|
}
|
||||||
|
stop_old(){
|
||||||
|
#删除守护
|
||||||
|
checkcron
|
||||||
|
sed -i /start.sh/d $cronpath
|
||||||
|
#结束进程
|
||||||
|
killall -9 clash &> /dev/null
|
||||||
|
stop_iptables
|
||||||
|
}
|
Loading…
Reference in New Issue
Block a user