diff --git a/box/scripts/box.service b/box/scripts/box.service index 72d2b67..9f28375 100755 --- a/box/scripts/box.service +++ b/box/scripts/box.service @@ -69,7 +69,6 @@ check_permission() { chmod 0644 "${data_dir}/${bin_name}"/* # Set ownership of data directory chown -R ${box_user_group} ${data_dir} - nohup="nohup busybox setuidgid ${box_user_group}" log info "Use the kernel located in '${bin_path}'." elif which ${bin_name} | grep -q "/system/bin/"; then box_user=$(echo ${box_user_group} | busybox awk -F ':' '{print $1}') @@ -77,25 +76,26 @@ check_permission() { box_user_id=$(id -u ${box_user}) box_group_id=$(id -g ${box_group}) # Check if box_user and box_group exist - if [[ ${box_user_id} && ${box_group_id} ]]; then - bin_path=$(which ${bin_name}) - # Set ownership and permission of kernel directory - chown ${box_user_group} ${bin_path} - chmod 6755 ${bin_path} - chmod 0644 "${data_dir}/${bin_name}"/* - # Check if user is not root and group is not net_admin - if [[ "${box_user_id}" != "0" || "${box_group_id}" != "3005" ]]; then - # Set capability of kernel directory - if ! setcap 'cap_net_admin,cap_net_raw,cap_net_bind_service+ep' "${bin_path}"; then - box_user_group="root:net_admin" - log error "setcap authorization failed, you may need libcap package." - fi - fi - # Set ownership of data directory - chown -R ${box_user_group} ${data_dir} - nohup="nohup" - log info "Using kernel directory ${bin_name} in ${bin_path}" + if ! [[ ${box_user_id} && ${box_group_id} ]]; then + log error "${box_user_group} error, use root:net_admin instead." + box_user_group="root:net_admin" fi + bin_path=$(which ${bin_name}) + # Set ownership and permission of kernel directory + chown ${box_user_group} ${bin_path} + chmod 6755 ${bin_path} + chmod 0644 "${data_dir}/${bin_name}"/* + # Check if user is not root and group is not net_admin + if [[ "${box_user_id}" != "0" || "${box_group_id}" != "3005" ]]; then + # Set capability of kernel directory + if ! setcap 'cap_net_admin,cap_net_raw,cap_net_bind_service+ep' "${bin_path}"; then + log error "setcap authorization failed, you may need libcap package." + fi + fi + # Set ownership of data directory + box_user_group="root:net_admin" + log info "Using kernel directory ${bin_name} in ${bin_path}" + chown -R ${box_user_group} ${data_dir} else sed -i "s/box_user_group=.*/box_user_group=\"root:net_admin\"/g" ${settings} log error "Kernel '${bin_name}' is missing." @@ -221,7 +221,7 @@ run_box() { sing-box) prepare_singbox if ${bin_path} check -D "${data_dir}/${bin_name}" --config-directory "${data_dir}/sing-box" > "${run_path}/${bin_name}-report.log" 2>&1 ; then - "${nohup}" ${bin_path} run -D "${data_dir}/${bin_name}" --config-directory "${data_dir}/sing-box" > "${run_path}/${bin_name}.log" 2>&1 & + nohup busybox setuidgid ${box_user_group} ${bin_path} run -D "${data_dir}/${bin_name}" --config-directory "${data_dir}/sing-box" > "${run_path}/${bin_name}.log" 2>&1 & echo -n $! > "${pid_file}" else log error "Configuration failed, please check the ${run_path}/${bin_name}-report.log file." @@ -234,7 +234,7 @@ run_box() { clash) prepare_clash if ${bin_path} -t -d "${data_dir}/${bin_name}" -f "${clash_config}" > "${run_path}/${bin_name}-report.log" 2>&1; then - "${nohup}" ${bin_path} -d "${data_dir}/${bin_name}" -f "${clash_config}" > "${run_path}/${bin_name}.log" 2>&1 & + nohup busybox setuidgid ${box_user_group} ${bin_path} -d "${data_dir}/${bin_name}" -f "${clash_config}" > "${run_path}/${bin_name}.log" 2>&1 & echo -n $! > "${pid_file}" else log error "configuration failed, please check the ${run_path}/${bin_name}-report.log file." @@ -253,7 +253,7 @@ run_box() { export XRAY_LOCATION_ASSET="${data_dir}/${bin_name}" export XRAY_LOCATION_CONFDIR="${data_dir}/${bin_name}" if ${bin_path} -test > "${run_path}/${bin_name}-report.log" 2>&1; then - "${nohup}" ${bin_path} > "${run_path}/${bin_name}.log" 2>&1 & + nohup busybox setuidgid ${box_user_group} ${bin_path} > "${run_path}/${bin_name}.log" 2>&1 & echo -n $! > "${pid_file}" else log error "configuration failed, please check the ${run_path}/${bin_name}-report.log file." @@ -272,7 +272,7 @@ run_box() { export V2RAY_LOCATION_ASSET="${data_dir}/${bin_name}" export V2RAY_LOCATION_CONFDIR="${data_dir}/${bin_name}" if (${bin_path} test > "${run_path}/${bin_name}-report.log" 2>&1) ; then - "${nohup}" ${bin_path} run > "${run_path}/${bin_name}.log" 2>&1 & + nohup busybox setuidgid ${box_user_group} ${bin_path} run > "${run_path}/${bin_name}.log" 2>&1 & echo -n $! > ${pid_file} else log error "configuration failed, please check the ${run_path}/${bin_name}-report.log file."