diff --git a/scripts/settings.ini b/scripts/settings.ini index 0ca8d95..cf3ace6 100755 --- a/scripts/settings.ini +++ b/scripts/settings.ini @@ -6,6 +6,9 @@ settings="/data/adb/box/settings.ini" # path busybox busybox_path="/data/adb/magisk/busybox" +# true: enable / false: disable Ipv6 +ipv6="false" + # true: for download Kernel meta, / false: Kernel premium # su -c /data/adb/box/scripts/box.tool upcore meta="true" @@ -14,8 +17,8 @@ dev="true" # port detect port_detect="true" -# If you want to change the user or group, you must make the Box core in the /system/bin directory, otherwise the changes will not take effect. -# If you are using Magisk, you can copy the Box core files (sing-box, clash, etc.) to /data/adb/modules/box_for_magisk/system/bin/ and reboot the phone +# If you want to change the user or group, you must make the BFM core in the /system/bin directory, otherwise the changes will not take effect. +# If you are using Magisk, you can copy the BFM core files (sing-box, clash, etc.) to /data/adb/modules/box_for_magisk/system/bin/ and reboot the phone # box_user_group="bin:system" box_user_group="root:net_admin" @@ -28,9 +31,6 @@ bin_list=("${c}" "${x}" "${s}" "${v}") # select client bin_name=$c -# true: enable / false: disable Ipv6 -ipv6="false" - # make sure the port is in sync with the config tproxy_port="9898" redir_port="9797" @@ -59,7 +59,7 @@ update_interval="0 00 * * *" auto_updategeox="true" # only clash subscription url auto_updatesubcript="false" -subcript_url="your link" +subcript_url="http://127.0.0.1:9090/ui/akun.yaml" # cgroup to limit memory usage cgroup_memory="false" @@ -108,11 +108,12 @@ static_dns2="2001:4860:4860::8844" log() { export TZ=Asia/Jakarta - now=$(date +"%I.%M %p") + now=$(date +"%I.%M %p %z") + # now=$(date +"%I.%M %p") case $1 in info)[ -t 1 ] && echo -e "\033[1;34m${now} [info]: $2\033[0m" || echo "${now} [info]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; error)[ -t 1 ] && echo -e "\033[1;31m${now} [error]: $2\033[0m" || echo "${now} [error]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; warn)[ -t 1 ] && echo -e "\033[1;33m${now} [warn]: $2\033[0m" || echo "${now} [warn]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; - *)[ -t 1 ] && echo -e "\033[1;32m${now} [$1]: $2\033[0m" || echo "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; + *)[ -t 1 ] && echo -e "\033[1;35m${now} [$1]: $2\033[0m" || echo "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; esac } \ No newline at end of file diff --git a/scripts/src/box.iptables b/scripts/src/box.iptables index 992be03..1738580 100755 --- a/scripts/src/box.iptables +++ b/scripts/src/box.iptables @@ -4,8 +4,9 @@ scripts=$(realpath $0) scripts_dir=$(dirname ${scripts}) source /data/adb/box/settings.ini -id="233" - +table="222" +fwmark="223" +pref="100" # iptables_version=$(iptables -V | grep -o "v1\.[0-9]") # if [ "${iptables_version}" = "v1.4" ] ; then # iptables_x="iptables" @@ -168,11 +169,11 @@ stop_redirect() { start_tproxy() { if [ "${iptables}" != "ip6tables -w 100" ] ; then - ip rule add fwmark ${id} table ${id} - ip route add local default dev lo table ${id} + ip rule add fwmark ${fwmark} table ${table} pref ${pref} + ip route add local default dev lo table ${table} else - ip -6 rule add fwmark ${id} table ${id} - ip -6 route add local default dev lo table ${id} + ip -6 rule add fwmark ${fwmark} table ${table} pref ${pref} + ip -6 route add local default dev lo table ${table} fi ${iptables} -t mangle -N BOX_EXTERNAL @@ -212,16 +213,16 @@ start_tproxy() { fi fi - ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id} - ${iptables} -t mangle -A BOX_EXTERNAL -p udp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id} + ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark} + ${iptables} -t mangle -A BOX_EXTERNAL -p udp -i lo -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark} # Allow ap interface # Notice: Old android device may only have one wlan interface. # Some new android device have multiple wlan interface like wlan0(for internet), wlan1(for AP). if [ "${ap_list}" != "" ] ; then for ap in ${ap_list[*]} ; do - ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id} - ${iptables} -t mangle -A BOX_EXTERNAL -p udp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${id} + ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark} + ${iptables} -t mangle -A BOX_EXTERNAL -p udp -i ${ap} -j TPROXY --on-port ${tproxy_port} --tproxy-mark ${fwmark} done [ "${iptables}" != "ip6tables -w 100" ] && log info "${ap_list[*]} transparent proxy." fi @@ -275,8 +276,8 @@ start_tproxy() { if [ "${proxy_mode}" = "blacklist" ] ; then if [ "$(cat ${uid_list[*]})" = "" ] ; then # Route Everything - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${id} - ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${id} + ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${fwmark} + ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${fwmark} [ "${iptables}" != "ip6tables -w 100" ] && log info "transparent proxy for all apps." else # Bypass apps @@ -284,30 +285,30 @@ start_tproxy() { ${iptables} -t mangle -I BOX_LOCAL -m owner --uid-owner ${appid} -j RETURN done # Allow !app - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${id} - ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${id} + ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${fwmark} + ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${fwmark} [ "${iptables}" != "ip6tables -w 100" ] && log info "proxy mode: ${proxy_mode}, ${packages_list[*]} no transparent proxy." fi elif [ "${proxy_mode}" = "whitelist" ] ; then # Route apps to Box for appid in $(cat ${uid_list[*]}) ; do - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner ${appid} -j MARK --set-mark ${id} - ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner ${appid} -j MARK --set-mark ${id} + ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner ${appid} -j MARK --set-mark ${fwmark} + ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner ${appid} -j MARK --set-mark ${fwmark} done - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j MARK --set-mark ${id} - ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 0 -j MARK --set-mark ${id} + ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j MARK --set-mark ${fwmark} + ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 0 -j MARK --set-mark ${fwmark} # Route dnsmasq to Box - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j MARK --set-mark ${id} - ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 1052 -j MARK --set-mark ${id} + ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j MARK --set-mark ${fwmark} + ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 1052 -j MARK --set-mark ${fwmark} # Route DNS request to Box - [ "${bin_name}" != "clash" ] && ${iptables} -t mangle -A BOX_LOCAL -p udp --dport 53 -j MARK --set-mark ${id} + [ "${bin_name}" != "clash" ] && ${iptables} -t mangle -A BOX_LOCAL -p udp --dport 53 -j MARK --set-mark ${fwmark} [ "${iptables}" != "ip6tables -w 100" ] && log info "proxy mode: ${proxy_mode}, ${packages_list[*]} transparent proxy." else log debug "proxy mode: ${proxy_mode}, error" - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${id} - ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${id} + ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark ${fwmark} + ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark ${fwmark} [ "${iptables}" != "ip6tables -w 100" ] && log info "transparent proxy for all apps." fi @@ -315,7 +316,7 @@ start_tproxy() { ${iptables} -t mangle -N DIVERT ${iptables} -t mangle -F DIVERT - ${iptables} -t mangle -A DIVERT -j MARK --set-mark ${id} + ${iptables} -t mangle -A DIVERT -j MARK --set-mark ${fwmark} ${iptables} -t mangle -A DIVERT -j ACCEPT ${iptables} -t mangle -I PREROUTING -p tcp -m socket -j DIVERT @@ -352,13 +353,13 @@ start_tproxy() { stop_tproxy() { if [ "${iptables}" != "ip6tables -w 100" ] ; then - ip rule del fwmark ${id} table ${id} - ip route del local default dev lo table ${id} - ip route flush table ${id} + ip rule del fwmark ${fwmark} table ${table} pref ${pref} + ip route del local default dev lo table ${table} + ip route flush table ${table} else - ip -6 rule del fwmark ${id} table ${id} - ip -6 route del local default dev lo table ${id} - ip -6 route flush table ${id} + ip -6 rule del fwmark ${fwmark} table ${table} pref ${pref} + ip -6 route del local default dev lo table ${table} + ip -6 route flush table ${table} fi ${iptables} -t mangle -D PREROUTING -j BOX_EXTERNAL @@ -484,6 +485,7 @@ if [ "${proxy_mode}" != "core" ] ; then iptables="ip6tables -w 100" && stop_redirect >> /dev/null 2>&1 iptables="ip6tables -w 100" && forward -D >> /dev/null 2>&1 log warn "clean up iptables transparent proxy rules done." + find_packages_uid case "${network_mode}" in tproxy) @@ -603,6 +605,7 @@ else iptables="ip6tables -w 100" && stop_redirect >> /dev/null 2>&1 iptables="ip6tables -w 100" && forward -D >> /dev/null 2>&1 log warn "clean up tun rules done." + iptables="iptables -w 100" forward -I && log info "use tun: tcp + udp, stack: ${clash_stack}" || log info "use tun: tcp + udp failed." if [ "${ipv6}" = "true" ] ; then diff --git a/scripts/src/box.service b/scripts/src/box.service index fea3ca4..da91a66 100755 --- a/scripts/src/box.service +++ b/scripts/src/box.service @@ -37,7 +37,7 @@ temporary_config_file() { if [ -f "${data_dir}/template.yml" ] ; then if [ -f "${clash_config}" ] ; then cp -f ${data_dir}/template.yml ${data_dir}/run/config.yaml.temp \ - && echo "\n" >> ${data_dir}/run/config.yaml.temp + && echo "\n" >> ${data_dir}/run/config.yaml.temp sed -n -E '/^proxies:$/,$p' ${clash_config} >> ${data_dir}/run/config.yaml.temp sed -i '/^[ ]*$/d' ${data_dir}/run/config.yaml.temp else @@ -86,14 +86,14 @@ check_permission() { box_user_id=$(id -u ${box_user}) box_group_id=$(id -g ${box_group}) [ ${box_user_id} ] && [ ${box_group_id} ] || \ - (box_user_group="root:net_admin" && log warn "${box_user_group} error, use root:net_admin instead.") + (box_user_group="root:net_admin" && log warn "${box_user_group} error, use root:net_admin instead.") bin_path=$(which ${bin_name}) chown ${box_user_group} ${bin_path} chmod 6755 ${bin_path} if [ "${box_user_id}" != "0" ] || [ "${box_group_id}" != "3005" ] ; then # setcap has been deprecated as it does not support binary outside of the /system/bin directory setcap 'cap_net_admin,cap_net_raw,cap_net_bind_service+ep' ${bin_path} || \ - (box_user_group="root:net_admin" && log error "setcap authorization failed, you may need libcap package.") + (box_user_group="root:net_admin" && log error "setcap authorization failed, you may need libcap package.") fi log info "using kernel directory ${bin_name} in ${bin_path}" chown -R ${box_user_group} ${data_dir} @@ -125,8 +125,11 @@ check_in_bin() { } create_tun() { - mkdir -p /dev/net - [ ! -L /dev/net/tun ] && ln -sf /dev/tun /dev/net/tun + echo 1 > /proc/sys/net/ipv4/ip_forward + [ ! -e "/dev/net/tun" ] && \ + mkdir -p /dev/net && ln -s /dev/tun /dev/net/tun + # mkdir -p /dev/net + # [ ! -L /dev/net/tun ] && ln -sf /dev/tun /dev/net/tun } run_box() { @@ -324,7 +327,7 @@ case "$1" in esac [ $(pidof ${bin_name}) ] \ && bin_usage || log warn "${bin_name} service is stopped" - ;; + ;; reload) if [ "${bin_name}" = "clash" ] ; then temporary_config_file @@ -333,10 +336,10 @@ case "$1" in else log info "only for Clash" fi - (${bin_path} -t -d ${data_dir}/clash -f ${data_dir}/run/config.yaml > "${run_path}/${bin_name}-report.log") \ - && log info "config.yaml passed" || log info "config.yaml ceks failed" + (${bin_path} -t -d ${data_dir}/clash -f ${data_dir}/run/config.yaml > "${run_path}/${bin_name}-report.log") && \ + log info "config.yaml passed" || log info "config.yaml ceks failed" ;; *) - echo "$0: usage: $0 {start|stop|restart|usage|reload}" + echo "$0: usage: $0 {start|testing|stop|restart|usage|reload}" ;; esac diff --git a/scripts/src/box.tool b/scripts/src/box.tool index b9fed59..01620d5 100755 --- a/scripts/src/box.tool +++ b/scripts/src/box.tool @@ -8,14 +8,50 @@ user_agent="${bin_name}" logs() { export TZ=Asia/Jakarta - now=$(date +"%I.%M %p") + now=$(date +"%I.%M %p %z") case $1 in info)[ -t 1 ] && echo -n "\033[1;34m${now} [info]: $2\033[0m" || echo -n "${now} [info]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; port)[ -t 1 ] && echo -n "\033[1;33m$2 \033[0m" || echo -n "$2 " | tee -a ${logs_file} >> /dev/null 2>&1;; - *)[ -t 1 ] && echo -n "\033[1;32m${now} [$1]: $2\033[0m" || echo -n "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; + succes)[ -t 1 ] && echo "\033[1;32m$2 \033[0m" || echo "$2 " | tee -a ${logs_file} >> /dev/null 2>&1;; + failed)[ -t 1 ] && echo "\033[1;31m$2 \033[0m" || echo "$2 " | tee -a ${logs_file} >> /dev/null 2>&1;; + *)[ -t 1 ] && echo -n "\033[1;35m${now} [$1]: $2\033[0m" || echo -n "${now} [$1]: $2" | tee -a ${logs_file} >> /dev/null 2>&1;; esac } +testing () { + logs info "dns: " + for network in $(${data_dir}/bin/mlbox -timeout=5 -dns="-qtype=A -domain=ntp.ntsc.ac.cn" | grep -v 'timeout' | grep -E '[1-9][0-9]{0,2}(\.[0-9]{1,3}){3}') ; do + ntpip=${network} + break + done + if [ -n "${ntpip}" ] ; then + logs succes "done" + logs info "http: " + httpIP=$(${data_dir}/bin/mlbox -timeout=5 -http="http://182.254.116.116/d?dn=qq.com&clientip=1" 2>&1 | grep -Ev 'timeout|httpGetResponse' | grep -E '[1-9][0-9]{0,2}(\.[0-9]{1,3}){3}') + if [ -n "${httpIP}" ] ; then + httpIP="${httpIP#*\|}" + logs succes "done" + else + logs failed "failed" + fi + logs info "https: " + ipInfo=$(${data_dir}/bin/mlbox -timeout=5 -http="https://ip.tool.lu/" 2>&1 | grep -Ev 'timeout|httpGetResponse') + if echo "${ipInfo}" | grep -qi 'IP'; then + logs succes "done" + else + httpsResp=$(${data_dir}/bin/mlbox -timeout=5 -http="https://ip.cn/dns.html" 2>&1 | grep -Ev 'timeout|httpGetResponse' | grep -E '[1-9][0-9]{0,2}(\.[0-9]{1,3}){3}') + [ -n "${httpsResp}" ] && logs succes "done" || \ + logs failed "failed" + fi + logs info "udp: " + currentTime=$(${data_dir}/bin/mlbox -timeout=5 -ntp="${ntpip}" | grep -v 'timeout') + echo "${currentTime}" | grep -qi 'LI:' && \ + logs succes "done" || logs failed "failed" + else + logs failed "failed" + fi +} + ceks_connectivity() { sleep 0.5 if [ -f /system/bin/curl ] ; then @@ -179,7 +215,7 @@ update_kernel() { filename="clash.meta" filename+="-${platform}" filename+="-${arch}" - # filename+="-cgo" + filename+="-cgo" filename+="-${latest_version}" log debug "download ${download_link}/download/${tag}/${filename}.gz" update_file "${data_dir}/${file_kernel}.gz" "${download_link}/download/${tag}/${filename}.gz" @@ -329,6 +365,9 @@ case "$1" in find ${data_dir}/${bin_name} -type f -name "*.db.bak" | xargs rm -f find ${data_dir}/${bin_name} -type f -name "*.dat.bak" | xargs rm -f ;; + testing) + testing + ;; port) port_detection ;; diff --git a/scripts/src/start.sh b/scripts/src/start.sh index 884b00b..5254bbf 100755 --- a/scripts/src/start.sh +++ b/scripts/src/start.sh @@ -9,18 +9,19 @@ scripts_dir="/data/adb/box/scripts" refresh_box() { if [ -f /data/adb/box/run/box.pid ] ; then - ${scripts_dir}/box.service stop - ${scripts_dir}/box.iptables disable + ${scripts_dir}/box.service stop >> /dev/null 2>&1 + ${scripts_dir}/box.iptables disable >> /dev/null 2>&1 fi } start_service() { if [ ! -f /data/adb/box/manual ] ; then - [ -f ${moddir}/disable ] || ${scripts_dir}/box.service start - [ -f /data/adb/box/run/box.pid ] \ - && ${scripts_dir}/box.iptables enable - inotifyd ${scripts_dir}/box.inotify ${moddir} > /dev/null 2>&1 & - echo -n $! > /data/adb/box/run/inotifyd.pid + [ -f ${moddir}/disable ] || \ + ${scripts_dir}/box.service start >> /dev/null 2>&1 + [ -f /data/adb/box/run/box.pid ] && \ + ${scripts_dir}/box.iptables enable >> /dev/null 2>&1 + inotifyd ${scripts_dir}/box.inotify ${moddir} >> /dev/null 2>&1 & + # echo -n $! > /data/adb/box/run/inotifyd.pid fi }