add testing dns, udp, http, https

This commit is contained in:
llyc
2023-02-13 18:08:59 +07:00
parent 63f174c4b9
commit 1bb0482a71
5 changed files with 104 additions and 57 deletions

View File

@@ -6,6 +6,9 @@ settings="/data/adb/box/settings.ini"
# path busybox
busybox_path="/data/adb/magisk/busybox"
# true: enable / false: disable Ipv6
ipv6="false"
# true: for download Kernel meta, / false: Kernel premium
# su -c /data/adb/box/scripts/box.tool upcore
meta="true"
@@ -14,8 +17,8 @@ dev="true"
# port detect
port_detect="true"
# If you want to change the user or group, you must make the Box core in the /system/bin directory, otherwise the changes will not take effect.
# If you are using Magisk, you can copy the Box core files (sing-box, clash, etc.) to /data/adb/modules/box_for_magisk/system/bin/ and reboot the phone
# If you want to change the user or group, you must make the BFM core in the /system/bin directory, otherwise the changes will not take effect.
# If you are using Magisk, you can copy the BFM core files (sing-box, clash, etc.) to /data/adb/modules/box_for_magisk/system/bin/ and reboot the phone
# box_user_group="bin:system"
box_user_group="root:net_admin"
@@ -28,9 +31,6 @@ bin_list=("${c}" "${x}" "${s}" "${v}")
# select client
bin_name=$c
# true: enable / false: disable Ipv6
ipv6="false"
# make sure the port is in sync with the config
tproxy_port="9898"
redir_port="9797"
@@ -59,7 +59,7 @@ update_interval="0 00 * * *"
auto_updategeox="true"
# only clash subscription url
auto_updatesubcript="false"
subcript_url="your link"
subcript_url="http://127.0.0.1:9090/ui/akun.yaml"
# cgroup to limit memory usage
cgroup_memory="false"
@@ -108,11 +108,12 @@ static_dns2="2001:4860:4860::8844"
log() {
export TZ=Asia/Jakarta
now=$(date +"%I.%M %p")
now=$(date +"%I.%M %p %z")
# now=$(date +"%I.%M %p")
case $1 in
info)[ -t 1 ] && echo -e "\033[1;34m${now} [info]: $2\033[0m" || echo "${now} [info]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
error)[ -t 1 ] && echo -e "\033[1;31m${now} [error]: $2\033[0m" || echo "${now} [error]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
warn)[ -t 1 ] && echo -e "\033[1;33m${now} [warn]: $2\033[0m" || echo "${now} [warn]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
*)[ -t 1 ] && echo -e "\033[1;32m${now} [$1]: $2\033[0m" || echo "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
*)[ -t 1 ] && echo -e "\033[1;35m${now} [$1]: $2\033[0m" || echo "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
esac
}

View File

@@ -4,8 +4,9 @@ scripts=$(realpath $0)
scripts_dir=$(dirname ${scripts})
source /data/adb/box/settings.ini
id="233"
table="222"
fwmark="223"
pref="100"
# iptables_version=$(iptables -V | grep -o "v1\.[0-9]")
# if [ "${iptables_version}" = "v1.4" ] ; then
# iptables_x="iptables"
@@ -168,11 +169,11 @@ stop_redirect() {
start_tproxy() {
if [ "${iptables}" != "ip6tables -w 100" ] ; then
ip rule add fwmark ${id} table ${id}
ip route add local default dev lo table ${id}
ip rule add fwmark ${fwmark} table ${table} pref ${pref}
ip route add local default dev lo table ${table}
else
ip -6 rule add fwmark ${id} table ${id}
ip -6 route add local default dev lo table ${id}
ip -6 rule add fwmark ${fwmark} table ${table} pref ${pref}
ip -6 route add local default dev lo table ${table}
fi
${iptables} -t mangle -N BOX_EXTERNAL
@@ -212,16 +213,16 @@ start_tproxy() {
fi
fi
${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id}
${iptables} -t mangle -A BOX_EXTERNAL -p udp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id}
${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark}
${iptables} -t mangle -A BOX_EXTERNAL -p udp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark}
# Allow ap interface
# Notice: Old android device may only have one wlan interface.
# Some new android device have multiple wlan interface like wlan0(for internet), wlan1(for AP).
if [ "${ap_list}" != "" ] ; then
for ap in ${ap_list[*]} ; do
${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id}
${iptables} -t mangle -A BOX_EXTERNAL -p udp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id}
${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark}
${iptables} -t mangle -A BOX_EXTERNAL -p udp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark}
done
[ "${iptables}" != "ip6tables -w 100" ] && log info "${ap_list[*]} transparent proxy."
fi
@@ -275,8 +276,8 @@ start_tproxy() {
if [ "${proxy_mode}" = "blacklist" ] ; then
if [ "$(cat ${uid_list[*]})" = "" ] ; then
# Route Everything
${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${fwmark}
[ "${iptables}" != "ip6tables -w 100" ] && log info "transparent proxy for all apps."
else
# Bypass apps
@@ -284,30 +285,30 @@ start_tproxy() {
${iptables} -t mangle -I BOX_LOCAL -m owner --uid-owner ${appid} -j RETURN
done
# Allow !app
${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${fwmark}
[ "${iptables}" != "ip6tables -w 100" ] && log info "proxy mode: ${proxy_mode}, ${packages_list[*]} no transparent proxy."
fi
elif [ "${proxy_mode}" = "whitelist" ] ; then
# Route apps to Box
for appid in $(cat ${uid_list[*]}) ; do
${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner ${appid} -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner ${appid} -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner ${appid} -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner ${appid} -j MARK --set-mark ${fwmark}
done
${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 0 -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 0 -j MARK --set-mark ${fwmark}
# Route dnsmasq to Box
${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 1052 -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 1052 -j MARK --set-mark ${fwmark}
# Route DNS request to Box
[ "${bin_name}" != "clash" ] && ${iptables} -t mangle -A BOX_LOCAL -p udp --dport 53 -j MARK --set-mark ${id}
[ "${bin_name}" != "clash" ] && ${iptables} -t mangle -A BOX_LOCAL -p udp --dport 53 -j MARK --set-mark ${fwmark}
[ "${iptables}" != "ip6tables -w 100" ] && log info "proxy mode: ${proxy_mode}, ${packages_list[*]} transparent proxy."
else
log debug "proxy mode: ${proxy_mode}, error"
${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${id}
${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${fwmark}
[ "${iptables}" != "ip6tables -w 100" ] && log info "transparent proxy for all apps."
fi
@@ -315,7 +316,7 @@ start_tproxy() {
${iptables} -t mangle -N DIVERT
${iptables} -t mangle -F DIVERT
${iptables} -t mangle -A DIVERT -j MARK --set-mark ${id}
${iptables} -t mangle -A DIVERT -j MARK --set-mark ${fwmark}
${iptables} -t mangle -A DIVERT -j ACCEPT
${iptables} -t mangle -I PREROUTING -p tcp -m socket -j DIVERT
@@ -352,13 +353,13 @@ start_tproxy() {
stop_tproxy() {
if [ "${iptables}" != "ip6tables -w 100" ] ; then
ip rule del fwmark ${id} table ${id}
ip route del local default dev lo table ${id}
ip route flush table ${id}
ip rule del fwmark ${fwmark} table ${table} pref ${pref}
ip route del local default dev lo table ${table}
ip route flush table ${table}
else
ip -6 rule del fwmark ${id} table ${id}
ip -6 route del local default dev lo table ${id}
ip -6 route flush table ${id}
ip -6 rule del fwmark ${fwmark} table ${table} pref ${pref}
ip -6 route del local default dev lo table ${table}
ip -6 route flush table ${table}
fi
${iptables} -t mangle -D PREROUTING -j BOX_EXTERNAL
@@ -484,6 +485,7 @@ if [ "${proxy_mode}" != "core" ] ; then
iptables="ip6tables -w 100" && stop_redirect >> /dev/null 2>&1
iptables="ip6tables -w 100" && forward -D >> /dev/null 2>&1
log warn "clean up iptables transparent proxy rules done."
find_packages_uid
case "${network_mode}" in
tproxy)
@@ -603,6 +605,7 @@ else
iptables="ip6tables -w 100" && stop_redirect >> /dev/null 2>&1
iptables="ip6tables -w 100" && forward -D >> /dev/null 2>&1
log warn "clean up tun rules done."
iptables="iptables -w 100"
forward -I && log info "use tun: tcp + udp, stack: ${clash_stack}" || log info "use tun: tcp + udp failed."
if [ "${ipv6}" = "true" ] ; then

View File

@@ -37,7 +37,7 @@ temporary_config_file() {
if [ -f "${data_dir}/template.yml" ] ; then
if [ -f "${clash_config}" ] ; then
cp -f ${data_dir}/template.yml ${data_dir}/run/config.yaml.temp \
&& echo "\n" >> ${data_dir}/run/config.yaml.temp
&& echo "\n" >> ${data_dir}/run/config.yaml.temp
sed -n -E '/^proxies:$/,$p' ${clash_config} >> ${data_dir}/run/config.yaml.temp
sed -i '/^[ ]*$/d' ${data_dir}/run/config.yaml.temp
else
@@ -86,14 +86,14 @@ check_permission() {
box_user_id=$(id -u ${box_user})
box_group_id=$(id -g ${box_group})
[ ${box_user_id} ] && [ ${box_group_id} ] || \
(box_user_group="root:net_admin" && log warn "${box_user_group} error, use root:net_admin instead.")
(box_user_group="root:net_admin" && log warn "${box_user_group} error, use root:net_admin instead.")
bin_path=$(which ${bin_name})
chown ${box_user_group} ${bin_path}
chmod 6755 ${bin_path}
if [ "${box_user_id}" != "0" ] || [ "${box_group_id}" != "3005" ] ; then
# setcap has been deprecated as it does not support binary outside of the /system/bin directory
setcap 'cap_net_admin,cap_net_raw,cap_net_bind_service+ep' ${bin_path} || \
(box_user_group="root:net_admin" && log error "setcap authorization failed, you may need libcap package.")
(box_user_group="root:net_admin" && log error "setcap authorization failed, you may need libcap package.")
fi
log info "using kernel directory ${bin_name} in ${bin_path}"
chown -R ${box_user_group} ${data_dir}
@@ -125,8 +125,11 @@ check_in_bin() {
}
create_tun() {
mkdir -p /dev/net
[ ! -L /dev/net/tun ] && ln -sf /dev/tun /dev/net/tun
echo 1 > /proc/sys/net/ipv4/ip_forward
[ ! -e "/dev/net/tun" ] && \
mkdir -p /dev/net && ln -s /dev/tun /dev/net/tun
# mkdir -p /dev/net
# [ ! -L /dev/net/tun ] && ln -sf /dev/tun /dev/net/tun
}
run_box() {
@@ -324,7 +327,7 @@ case "$1" in
esac
[ $(pidof ${bin_name}) ] \
&& bin_usage || log warn "${bin_name} service is stopped"
;;
;;
reload)
if [ "${bin_name}" = "clash" ] ; then
temporary_config_file
@@ -333,10 +336,10 @@ case "$1" in
else
log info "only for Clash"
fi
(${bin_path} -t -d ${data_dir}/clash -f ${data_dir}/run/config.yaml > "${run_path}/${bin_name}-report.log") \
&& log info "config.yaml passed" || log info "config.yaml ceks failed"
(${bin_path} -t -d ${data_dir}/clash -f ${data_dir}/run/config.yaml > "${run_path}/${bin_name}-report.log") && \
log info "config.yaml passed" || log info "config.yaml ceks failed"
;;
*)
echo "$0: usage: $0 {start|stop|restart|usage|reload}"
echo "$0: usage: $0 {start|testing|stop|restart|usage|reload}"
;;
esac

View File

@@ -8,14 +8,50 @@ user_agent="${bin_name}"
logs() {
export TZ=Asia/Jakarta
now=$(date +"%I.%M %p")
now=$(date +"%I.%M %p %z")
case $1 in
info)[ -t 1 ] && echo -n "\033[1;34m${now} [info]: $2\033[0m" || echo -n "${now} [info]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
port)[ -t 1 ] && echo -n "\033[1;33m$2 \033[0m" || echo -n "$2 " | tee -a ${logs_file} >> /dev/null 2>&1;;
*)[ -t 1 ] && echo -n "\033[1;32m${now} [$1]: $2\033[0m" || echo -n "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
succes)[ -t 1 ] && echo "\033[1;32m$2 \033[0m" || echo "$2 " | tee -a ${logs_file} >> /dev/null 2>&1;;
failed)[ -t 1 ] && echo "\033[1;31m$2 \033[0m" || echo "$2 " | tee -a ${logs_file} >> /dev/null 2>&1;;
*)[ -t 1 ] && echo -n "\033[1;35m${now} [$1]: $2\033[0m" || echo -n "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;;
esac
}
testing () {
logs info "dns: "
for network in $(${data_dir}/bin/mlbox -timeout=5 -dns="-qtype=A -domain=ntp.ntsc.ac.cn" | grep -v 'timeout' | grep -E '[1-9][0-9]{0,2}(\.[0-9]{1,3}){3}') ; do
ntpip=${network}
break
done
if [ -n "${ntpip}" ] ; then
logs succes "done"
logs info "http: "
httpIP=$(${data_dir}/bin/mlbox -timeout=5 -http="http://182.254.116.116/d?dn=qq.com&clientip=1" 2>&1 | grep -Ev 'timeout|httpGetResponse' | grep -E '[1-9][0-9]{0,2}(\.[0-9]{1,3}){3}')
if [ -n "${httpIP}" ] ; then
httpIP="${httpIP#*\|}"
logs succes "done"
else
logs failed "failed"
fi
logs info "https: "
ipInfo=$(${data_dir}/bin/mlbox -timeout=5 -http="https://ip.tool.lu/" 2>&1 | grep -Ev 'timeout|httpGetResponse')
if echo "${ipInfo}" | grep -qi 'IP'; then
logs succes "done"
else
httpsResp=$(${data_dir}/bin/mlbox -timeout=5 -http="https://ip.cn/dns.html" 2>&1 | grep -Ev 'timeout|httpGetResponse' | grep -E '[1-9][0-9]{0,2}(\.[0-9]{1,3}){3}')
[ -n "${httpsResp}" ] && logs succes "done" || \
logs failed "failed"
fi
logs info "udp: "
currentTime=$(${data_dir}/bin/mlbox -timeout=5 -ntp="${ntpip}" | grep -v 'timeout')
echo "${currentTime}" | grep -qi 'LI:' && \
logs succes "done" || logs failed "failed"
else
logs failed "failed"
fi
}
ceks_connectivity() {
sleep 0.5
if [ -f /system/bin/curl ] ; then
@@ -179,7 +215,7 @@ update_kernel() {
filename="clash.meta"
filename+="-${platform}"
filename+="-${arch}"
# filename+="-cgo"
filename+="-cgo"
filename+="-${latest_version}"
log debug "download ${download_link}/download/${tag}/${filename}.gz"
update_file "${data_dir}/${file_kernel}.gz" "${download_link}/download/${tag}/${filename}.gz"
@@ -329,6 +365,9 @@ case "$1" in
find ${data_dir}/${bin_name} -type f -name "*.db.bak" | xargs rm -f
find ${data_dir}/${bin_name} -type f -name "*.dat.bak" | xargs rm -f
;;
testing)
testing
;;
port)
port_detection
;;

View File

@@ -9,18 +9,19 @@ scripts_dir="/data/adb/box/scripts"
refresh_box() {
if [ -f /data/adb/box/run/box.pid ] ; then
${scripts_dir}/box.service stop
${scripts_dir}/box.iptables disable
${scripts_dir}/box.service stop >> /dev/null 2>&1
${scripts_dir}/box.iptables disable >> /dev/null 2>&1
fi
}
start_service() {
if [ ! -f /data/adb/box/manual ] ; then
[ -f ${moddir}/disable ] || ${scripts_dir}/box.service start
[ -f /data/adb/box/run/box.pid ] \
&& ${scripts_dir}/box.iptables enable
inotifyd ${scripts_dir}/box.inotify ${moddir} > /dev/null 2>&1 &
echo -n $! > /data/adb/box/run/inotifyd.pid
[ -f ${moddir}/disable ] || \
${scripts_dir}/box.service start >> /dev/null 2>&1
[ -f /data/adb/box/run/box.pid ] && \
${scripts_dir}/box.iptables enable >> /dev/null 2>&1
inotifyd ${scripts_dir}/box.inotify ${moddir} >> /dev/null 2>&1 &
# echo -n $! > /data/adb/box/run/inotifyd.pid
fi
}