diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml index d00b3c5..3d5cddd 100644 --- a/.github/FUNDING.yml +++ b/.github/FUNDING.yml @@ -1,4 +1,4 @@ # These are supported funding model platforms github: ['taamarin'] -custom: ['https://sociabuzz.com/taamarin', 'https://saweria.co/taamarin'] +custom: ['https://paypal.me/MJuwanda02'] diff --git a/.github/taamarinbot.py b/.github/taamarinbot.py index a939a08..6679eb5 100644 --- a/.github/taamarinbot.py +++ b/.github/taamarinbot.py @@ -17,10 +17,10 @@ MSG_TEMPLATE = """ {commit} -[Github](https://github.com/taamarin/box_for_root) +[Github](https://github.com/taamarin/box_for_magisk) [Releases](https://github.com/taamarin/box_for_magisk/releases) -#module #ksu #magisk #bfr #debug +#module #ksu #apatch #magisk #bfr #debug """.strip() def get_caption(): diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7fd8320..60cce38 100755 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -55,7 +55,7 @@ jobs: if: ${{ success() }} env: CHAT_ID: "-1001597117128" - MESSAGE_THREAD_ID: "218356" + MESSAGE_THREAD_ID: "282263" API_ID: ${{ secrets.API_ID }} API_HASH: ${{ secrets.API_HASH }} BOT_TOKEN: ${{ secrets.BOT_TOKEN }} diff --git a/box/scripts/box.iptables b/box/scripts/box.iptables index 22ec9cd..12bb97f 100755 --- a/box/scripts/box.iptables +++ b/box/scripts/box.iptables @@ -3,13 +3,21 @@ scripts_dir="${0%/*}" source /data/adb/box/settings.ini -# Variabel yang digunakan table="223" fwmark="223" pref="100" # disable / enable quic using iptables rules quic="enable" +iptables_version=$(iptables --version | busybox awk '/^iptables/ {print $2}') +if busybox awk -v current_version="$iptables_version" -v required_version="v1.6.1" 'BEGIN { exit !(current_version > required_version) }'; then + IPV="iptables -w 100" + IP6V="ip6tables -w 100" +else + IPV="iptables" + IP6V="ip6tables" +fi + # Looking for value from "fake-ip-range: / listen: / enhanced-mode: / tun-device:" block in YAML / JSON configuration file case "${bin_name}" in "clash") @@ -17,12 +25,12 @@ case "${bin_name}" in clash_enhanced_mode=$(busybox awk '!/^ *#/ && /enhanced-mode: / { print $2;found=1; exit } END{ if(!found) print "fake-ip" }' "${clash_config}" 2>/dev/null) fake_ip_range=$(busybox awk '!/^ *#/ && /fake-ip-range:/ { print $2; found=1; exit } END { if (!found) print "198.18.0.1/16" }' "${clash_config}" 2>/dev/null) clash_dns_port=$(busybox awk '!/^ *#/ && /listen:/ { split($0, arr, ":"); print arr[3]; found=1; exit } END{ if(!found) print "1053" }' "${clash_config}" 2>/dev/null) - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then + if [[ "${network_mode}" == @(mixed|tun) ]]; then tun_device=$(busybox awk '!/^ *#/ && /device: / { print $2;found=1; exit } END{ if(!found) print "utun" }' "${clash_config}" 2>/dev/null) fi ;; "sing-box") - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then + if [[ "${network_mode}" == @(mixed|tun) ]]; then tun_device=$(find "${box_dir}/sing-box/" -maxdepth 1 -type f -name "*.json" -exec busybox grep -oE '"interface_name": "[^"]*' {} + | busybox awk -F'"' '{print $4}' 2>/dev/null | head -n 1) if [ -z "$tun_device" ]; then tun_device="tun0" @@ -32,8 +40,8 @@ case "${bin_name}" in fake_ip6_range=$(find ${box_dir}/sing-box/ -maxdepth 1 -type f -name "*.json" -exec busybox awk -F'"' '/inet6_range/ {print $4}' {} +) ;; "xray" | "v2fly") - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then - log Error "$bin_name does not support proxy_mode: tun or network_mode: mixed" + if [[ "${network_mode}" != "tproxy" ]]; then + log Error "$bin_name does not support network_mode: $network_mode" exit 1 fi ;; @@ -43,15 +51,12 @@ case "${bin_name}" in ;; esac -misc_info() { +box_etc() { case "${bin_name}" in clash) log Debug "enhanced-mode: $clash_enhanced_mode, fake-ip-range: $fake_ip_range, listen-port: $clash_dns_port, mode: $clash_mode" ;; - clash|sing-box) - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then - log Info "tun_device: $tun_device" - fi + sing-box) if [ -n "${fake_ip_range}" ] && [ "${bin_name}" = "sing-box" ]; then log Debug "fake-ip-range: ${fake_ip_range}, ${fake_ip6_range}" fi @@ -60,17 +65,8 @@ misc_info() { true ;; esac -} - -sync_port() { - if [[ "${network_mode}" == "tproxy" && "${proxy_mode}" != "tun" ]]; then - if command -v netstat &> /dev/null; then - netstat -tnulp | grep -q "${tproxy_port}" || log Warning "tproxy_port: ${tproxy_port} out of sync with config" - fi - elif [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then - if command -v ifconfig &> /dev/null; then - ifconfig | grep -q "${tun_device}" || log Warning "tun_device: '${tun_device}' not found" - fi + if [[ "${network_mode}" == @(mixed|tun) ]]; then + log Info "tun_device: $tun_device" fi } @@ -155,7 +151,7 @@ intranet=( 240.0.0.0/4 255.0.0.0/4 255.255.255.0/24 - # 255.255.255.255/32 + 255.255.255.255/32 ) intranet+=($(ip -4 a | busybox awk '/inet/ {print $2}' | busybox grep -vE "^127.0.0.1")) @@ -177,20 +173,20 @@ intranet6=( intranet6+=($(ip -6 a | busybox awk '/inet6/ {print $2}' | busybox grep -vE "^fe80|^::1|^fd00")) forward() { - ${iptables} $1 FORWARD -o "${tun_device}" -j ACCEPT ${iptables} $1 FORWARD -i "${tun_device}" -j ACCEPT + ${iptables} $1 FORWARD -o "${tun_device}" -j ACCEPT } >> /dev/null 2>&1 # box redirect start_redirect() { - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -t nat -N BOX_EXTERNAL ${iptables} -t nat -F BOX_EXTERNAL ${iptables} -t nat -N BOX_LOCAL ${iptables} -t nat -F BOX_LOCAL fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then if [ "${bin_name}" = "clash" ]; then ${iptables} -t nat -A BOX_EXTERNAL -p udp --dport 53 -j REDIRECT --to-ports "${clash_dns_port}" ${iptables} -t nat -A BOX_LOCAL -p udp --dport 53 -j REDIRECT --to-ports "${clash_dns_port}" @@ -222,7 +218,7 @@ start_redirect() { for ap in "${ap_list[@]}"; do ${iptables} -t nat -A BOX_EXTERNAL -p tcp -i "${ap}" -j REDIRECT --to-ports "${redir_port}" done - log Info "${ap_list[*]} transparent proxy." + [ ${network_mode} = "enhance" ] || log Info "${ap_list[*]} transparent proxy." fi ${iptables} -t nat -I PREROUTING -j BOX_EXTERNAL @@ -233,12 +229,12 @@ start_redirect() { for ignore in "${ignore_out_list[@]}"; do ${iptables} -t nat -I BOX_LOCAL -o "${ignore}" -j RETURN done - log Info "${ignore_out_list[*]} ignore transparent proxy." + [ ${network_mode} = "enhance" ] || log Info "${ignore_out_list[*]} ignore transparent proxy." fi fi # check if iptables is not ip6tables - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then # check proxy mode case "${proxy_mode}" in blacklist) @@ -246,7 +242,7 @@ start_redirect() { if [ -z "$(cat "${uid_list[@]}")" ] ; then # Route Everything ${iptables} -t nat -A BOX_LOCAL -p tcp -j REDIRECT --to-ports "${redir_port}" - log Info "Transparent proxy for all apps." + [ ${network_mode} = "enhance" ] || log Info "Transparent proxy for all apps." else # Bypass apps # loop through the UID list @@ -257,21 +253,21 @@ start_redirect() { # Allow !app ${iptables} -t nat -A BOX_LOCAL -p tcp -j REDIRECT --to-ports "${redir_port}" - log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} no transparent proxy." + [ ${network_mode} = "enhance" ] || log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} no transparent proxy." fi if [ "${gid_list}" != "" ] ; then # Bypass gids for gid in ${gid_list[@]} ; do ${iptables} -t nat -I BOX_LOCAL -m owner --gid-owner ${gid} -j RETURN done - [ "${iptables}" = "iptables -w 64" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} no transparent proxy." + [ ${network_mode} = "enhance" ] || [ "${iptables}" = "$IPV" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} no transparent proxy." fi ;; whitelist) if [ -z "$(cat "${uid_list[@]}")" ] ; then # Route Everything ${iptables} -t nat -A BOX_LOCAL -p tcp -j REDIRECT --to-ports "${redir_port}" - log Info "Transparent proxy for all apps." + [ ${network_mode} = "enhance" ] || log Info "Transparent proxy for all apps." else # Route apps to Box # loop through the UID list @@ -282,29 +278,29 @@ start_redirect() { ${iptables} -t nat -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j REDIRECT --to-ports "${redir_port}" ${iptables} -t nat -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j REDIRECT --to-ports "${redir_port}" - log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} transparent proxy." + [ ${network_mode} = "enhance" ] || log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} transparent proxy." fi if [ "${gid_list}" != "" ] ; then # Route gids to Box for gid in ${gid_list[@]} ; do ${iptables} -t nat -A BOX_LOCAL -p tcp -m owner --gid-owner ${gid} -j REDIRECT --to-ports ${redir_port} done - [ "${iptables}" = "iptables -w 64" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} transparent proxy." + [ ${network_mode} = "enhance" ] || [ "${iptables}" = "$IPV" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} transparent proxy." fi ;; *) log Warning "proxy-mode: ${proxy_mode} < error." ${iptables} -t nat -A BOX_LOCAL -p tcp -j REDIRECT --to-ports "${redir_port}" - log Info "Transparent proxy for all apps." + [ ${network_mode} = "enhance" ] || log Info "Transparent proxy for all apps." ;; esac fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -t nat -I OUTPUT -j BOX_LOCAL fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -A OUTPUT -d 127.0.0.1 -p tcp -m owner --uid-owner "${box_user}" --gid-owner "${box_group}" -m tcp --dport "${redir_port}" -j REJECT else ${iptables} -A OUTPUT -d ::1 -p tcp -m owner --uid-owner "${box_user}" --gid-owner "${box_group}" -m tcp --dport "${redir_port}" -j REJECT @@ -312,12 +308,12 @@ start_redirect() { } stop_redirect() { - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -t nat -D PREROUTING -j BOX_EXTERNAL ${iptables} -t nat -D OUTPUT -j BOX_LOCAL fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -D OUTPUT -d 127.0.0.1 -p tcp -m owner --uid-owner "${box_user}" --gid-owner "${box_group}" -m tcp --dport "${redir_port}" -j REJECT ${iptables} -D OUTPUT -d 127.0.0.1 -p tcp -m owner --uid-owner 0:3005 -m tcp --dport "${redir_port}" -j REJECT else @@ -325,7 +321,7 @@ stop_redirect() { ${iptables} -D OUTPUT -d ::1 -p tcp -m owner --uid-owner 0:3005 -m tcp --dport "${redir_port}" -j REJECT fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then # ${iptables} -t nat -D BOX_EXTERNAL -d "${fake_ip_range}" -p icmp -j DNAT --to-destination 127.0.0.1 # ${iptables} -t nat -D BOX_LOCAL -d "${fake_ip_range}" -p icmp -j DNAT --to-destination 127.0.0.1 @@ -338,7 +334,7 @@ stop_redirect() { # box tproxy start_tproxy() { - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ip rule add fwmark "${fwmark}" table "${table}" pref "${pref}" ip route add local default dev lo table "${table}" # ip -6 rule add unreachable pref "${pref}" @@ -351,6 +347,10 @@ start_tproxy() { ${iptables} -t mangle -N BOX_EXTERNAL 2>/dev/null ${iptables} -t mangle -F BOX_EXTERNAL + # TTL + # ${iptables} -t mangle -A BOX_EXTERNAL -m ttl --ttl-lt 32 -j DROP + # ${iptables} -t mangle -D BOX_EXTERNAL -m ttl --ttl-lt 32 -j DROP + # Bypass box itself # ${iptables} -t mangle -A BOX_EXTERNAL -m mark --mark ${routing_mark} -j RETURN @@ -362,13 +362,13 @@ start_tproxy() { # Bypass intranet # Add rules for intranet subnets - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then for subnet in "${intranet[@]}"; do if [ "${bin_name}" = "clash" ]; then ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet}" -j RETURN else ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet}" -p udp ! --dport 53 -j RETURN - ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet}" ! -p udp -j RETURN + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet}" ! -p udp -j RETURN fi done else @@ -378,12 +378,14 @@ start_tproxy() { ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet6}" -j RETURN else ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet6}" -p udp ! --dport 53 -j RETURN - ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet6}" ! -p udp -j RETURN + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_EXTERNAL -d "${subnet6}" ! -p udp -j RETURN fi done fi + # Append the BOX_EXTERNAL chain to the PREROUTING chain + # ${iptables} -t mangle -A PREROUTING -j BOX_EXTERNAL - ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i lo -j TPROXY --on-port "${tproxy_port}" --tproxy-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i lo -j TPROXY --on-port "${tproxy_port}" --tproxy-mark "${fwmark}" ${iptables} -t mangle -A BOX_EXTERNAL -p udp -i lo -j TPROXY --on-port "${tproxy_port}" --tproxy-mark "${fwmark}" # Allow ap interface @@ -393,11 +395,11 @@ start_tproxy() { if [ "${ap_list}" != "" ]; then for ap in ${ap_list[@]} ; do # add iptables rules for TCP traffic - ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i "${ap}" -j TPROXY --on-port "${tproxy_port}" --tproxy-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_EXTERNAL -p tcp -i "${ap}" -j TPROXY --on-port "${tproxy_port}" --tproxy-mark "${fwmark}" # add iptables rules for UDP traffic ${iptables} -t mangle -A BOX_EXTERNAL -p udp -i "${ap}" -j TPROXY --on-port "${tproxy_port}" --tproxy-mark "${fwmark}" done - [ "${iptables}" = "iptables -w 64" ] && log Info "${ap_list[*]} transparent proxy." + [ "${iptables}" = "$IPV" ] && log Info "${ap_list[*]} transparent proxy." fi ${iptables} -t mangle -I PREROUTING -j BOX_EXTERNAL @@ -409,13 +411,13 @@ start_tproxy() { for ignore in ${ignore_out_list[@]} ; do ${iptables} -t mangle -I BOX_LOCAL -o "${ignore}" -j RETURN done - [ "${iptables}" = "iptables -w 64" ] && log Info "${ignore_out_list[*]} ignore transparent proxy." + [ "${iptables}" = "$IPV" ] && log Info "${ignore_out_list[*]} ignore transparent proxy." fi # Bypass intranet Clash if [ "${bin_name}" = "clash" ]; then ${iptables} -t mangle -A BOX_LOCAL -p udp --dport 53 -j RETURN - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then for subnet in "${intranet[@]}"; do ${iptables} -t mangle -A BOX_LOCAL -d "${subnet}" -j RETURN done @@ -425,15 +427,15 @@ start_tproxy() { done fi else - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then for subnet in "${intranet[@]}"; do ${iptables} -t mangle -A BOX_LOCAL -d "${subnet}" -p udp ! --dport 53 -j RETURN - ${iptables} -t mangle -A BOX_LOCAL -d "${subnet}" ! -p udp -j RETURN + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -d "${subnet}" ! -p udp -j RETURN done else for subnet6 in "${intranet6[@]}"; do ${iptables} -t mangle -A BOX_LOCAL -d "${subnet6}" -p udp ! --dport 53 -j RETURN - ${iptables} -t mangle -A BOX_LOCAL -d "${subnet6}" ! -p udp -j RETURN + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -d "${subnet6}" ! -p udp -j RETURN done fi fi @@ -450,9 +452,9 @@ start_tproxy() { blacklist) if [ -z "$(cat "${uid_list[@]}")" ] ; then # Route Everything - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark "${fwmark}" - [ "${iptables}" = "iptables -w 64" ] && log Info "transparent proxy for all apps." + [ "${iptables}" = "$IPV" ] && log Info "transparent proxy for all apps." else # Bypass apps @@ -461,55 +463,55 @@ start_tproxy() { done < "${uid_list[@]}" # Allow !app - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark "${fwmark}" - [ "${iptables}" = "iptables -w 64" ] && log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} no transparent proxy." + [ "${iptables}" = "$IPV" ] && log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} no transparent proxy." fi if [ "${gid_list}" != "" ] ; then # Bypass gids for gid in ${gid_list[@]} ; do ${iptables} -t mangle -I BOX_LOCAL -m owner --gid-owner ${gid} -j RETURN done - [ "${iptables}" = "iptables -w 64" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} no transparent proxy." + [ "${iptables}" = "$IPV" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} no transparent proxy." fi ;; whitelist) if [ -z "$(cat "${uid_list[@]}")" ] ; then # Route Everything - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark "${fwmark}" - [ "${iptables}" = "iptables -w 64" ] && log Info "transparent proxy for all apps." + [ "${iptables}" = "$IPV" ] && log Info "transparent proxy for all apps." else # Route apps to Box # loop through uid list and add iptables rule while read -r appid; do - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner "${appid}" -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner "${appid}" -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner "${appid}" -j MARK --set-mark "${fwmark}" done < "${uid_list[@]}" - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 0 -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 0 -j MARK --set-mark "${fwmark}" # Route dnsmasq to Box - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --uid-owner 1052 -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --uid-owner 1052 -j MARK --set-mark "${fwmark}" # Route DNS request to Box [ "${bin_name}" != "clash" ] && ${iptables} -t mangle -A BOX_LOCAL -p udp --dport 53 -j MARK --set-mark "${fwmark}" - [ "${iptables}" = "iptables -w 64" ] && log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} transparent proxy." + [ "${iptables}" = "$IPV" ] && log Info "proxy-mode: ${proxy_mode}, package ${packages_list[*]} transparent proxy." fi if [ "${gid_list}" != "" ] ; then # Route gids to Box for gid in ${gid_list[@]} ; do - ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --gid-owner ${gid} -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -m owner --gid-owner ${gid} -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -m owner --gid-owner ${gid} -j MARK --set-mark "${fwmark}" done - [ "${iptables}" = "iptables -w 64" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} transparent proxy." + [ "${iptables}" = "$IPV" ] && log Info "proxy mode: ${proxy_mode}, GID ${gid_list[*]} transparent proxy." fi ;; *) log Debug "proxy-mode: ${proxy_mode} < error" - ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -A BOX_LOCAL -p tcp -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A BOX_LOCAL -p udp -j MARK --set-mark "${fwmark}" - [ "${iptables}" = "iptables -w 64" ] && log Info "transparent proxy for all apps." + [ "${iptables}" = "$IPV" ] && log Info "transparent proxy for all apps." ;; esac @@ -520,24 +522,26 @@ start_tproxy() { ${iptables} -t mangle -A DIVERT -j MARK --set-mark "${fwmark}" ${iptables} -t mangle -A DIVERT -j ACCEPT - ${iptables} -t mangle -I PREROUTING -p tcp -m socket -j DIVERT + [ ${network_mode} = "enhance" ] || ${iptables} -t mangle -I PREROUTING -p tcp -m socket -j DIVERT # Disable QUIC if [ "${quic}" = "disable" ]; then - # ${iptables} -A OUTPUT -p udp --dport 443 -j REJECT - # ${iptables} -A OUTPUT -p udp --dport 80 -j REJECT - ${iptables} -A OUTPUT -p udp -m multiport --dport 443,80 -j REJECT - [ "${iptables}" = "iptables -w 64" ] && log Warning "Disabling QUIC" + ${iptables} -A OUTPUT -p udp --dport 443 -j REJECT + ${iptables} -A OUTPUT -p udp --dport 80 -j REJECT + # ${iptables} -A OUTPUT -p udp -m multiport --dport 443,80 -j REJECT + [ "${iptables}" = "$IPV" ] && log Warning "Disabling QUIC" fi +if [ ${network_mode} != "enhance" ]; then # This rule blocks local access to tproxy-port to prevent traffic loopback. - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -A OUTPUT -d 127.0.0.1 -p tcp -m owner --uid-owner "${box_user}" --gid-owner "${box_group}" -m tcp --dport "${tproxy_port}" -j REJECT else ${iptables} -A OUTPUT -d ::1 -p tcp -m owner --uid-owner "${box_user}" --gid-owner "${box_group}" -m tcp --dport "${tproxy_port}" -j REJECT fi +fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then if [ "${bin_name}" = "clash" ]; then # Create and configure CLASH_DNS_EXTERNAL chain ${iptables} -t nat -N CLASH_DNS_EXTERNAL @@ -563,7 +567,7 @@ start_tproxy() { } stop_tproxy() { - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ip rule del fwmark "${fwmark}" table "${table}" pref "${pref}" ip route del local default dev lo table "${table}" ip route flush table "${table}" @@ -597,7 +601,7 @@ stop_tproxy() { ${iptables} -D OUTPUT -p udp --dport 443 -j REJECT ${iptables} -D OUTPUT -p udp --dport 80 -j REJECT - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -D OUTPUT -d 127.0.0.1 -p tcp -m owner --uid-owner "${box_user}" --gid-owner "${box_group}" -m tcp --dport "${tproxy_port}" -j REJECT ${iptables} -D OUTPUT -d 127.0.0.1 -p tcp -m owner --uid-owner 0 --gid-owner 3005 -m tcp --dport "${tproxy_port}" -j REJECT else @@ -605,7 +609,7 @@ stop_tproxy() { ${iptables} -D OUTPUT -d ::1 -p tcp -m owner --uid-owner 0 --gid-owner 3005 -m tcp --dport "${tproxy_port}" -j REJECT fi - if [ "${iptables}" = "iptables -w 64" ]; then + if [ "${iptables}" = "$IPV" ]; then ${iptables} -t nat -D PREROUTING -j CLASH_DNS_EXTERNAL ${iptables} -t nat -D OUTPUT -j CLASH_DNS_LOCAL @@ -626,7 +630,7 @@ stop_tproxy() { } cleanup_iptables() { - for iptables in "iptables -w 64" "ip6tables -w 64"; do + for iptables in "$IPV" "$IP6V"; do iptables="${iptables}" && { stop_redirect stop_tproxy @@ -635,10 +639,11 @@ cleanup_iptables() { done } -if [ "${proxy_mode}" != "tun" ]; then +if [[ "${network_mode}" == @(redirect|mixed|tproxy|enhance) ]]; then case "$1" in enable) - misc_info + box_etc + log Info "$IPV + $IP6V" probe_user_group || log Error "failed to check BOX user group, please make sure ${bin_name} kernel is started." # find uuid apps/game find_packages_uid @@ -648,12 +653,12 @@ if [ "${proxy_mode}" != "tun" ]; then tproxy) log Info "Using Tproxy: tcp + udp." log Info "Creating iptables transparent proxy rules." - iptables="iptables -w 64" + iptables="$IPV" start_tproxy && log Info "Creating iptables transparent proxy rules done." || { log Error "Creating iptables transparent proxy rules failed." && stop_tproxy >> /dev/null 2>&1; } if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" start_tproxy && log Info "Creating ip6tables transparent proxy rules done." || { log Error "Creating ip6tables transparent proxy rules failed." && stop_tproxy >> /dev/null 2>&1; } else disable_ipv6 @@ -663,12 +668,12 @@ if [ "${proxy_mode}" != "tun" ]; then redirect) log Info "Using Redirect: tcp + udp (direct)." log Info "Creating iptables transparent proxy rules." - iptables="iptables -w 64" + iptables="$IPV" start_redirect && log Info "Creating iptables transparent proxy rules done." || { log Error "Creating iptables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" start_redirect && log Info "Creating ip6tables transparent proxy rules done." || { log Error "Creating ip6tables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } else disable_ipv6 @@ -678,13 +683,13 @@ if [ "${proxy_mode}" != "tun" ]; then mixed) log Info "Using Mixed: tcp(redirect) + udp(tun)." log Info "Creating iptables transparent proxy rules." - iptables="iptables -w 64" + iptables="$IPV" forward -I || forward -D >> /dev/null 2>&1 start_redirect && log Info "Creating iptables transparent proxy rules done." || (log Error "Creating iptables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1) if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" forward -I || forward -D >> /dev/null 2>&1 start_redirect && log Info "Creating ip6tables transparent proxy rules done." || (log Error "Creating ip6tables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1) else @@ -692,16 +697,31 @@ if [ "${proxy_mode}" != "tun" ]; then log Warning "Disabling IPv6." fi ;; + enhance) + log Info "Using Enhance: tcp(redirect) + udp(tproxy)" + log Info "Creating iptables transparent proxy rules." + iptables="$IPV" + start_redirect && start_tproxy && log Info "Creating iptables transparent proxy rules done." || { log Error "Creating iptables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } + if [ "${ipv6}" = "true" ]; then + log Debug "Using IPv6." + ipv6_enable + iptables="$IP6V" + start_redirect && start_tproxy && log Info "Creating ip6tables transparent proxy rules done." || { log Error "Creating ip6tables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } + else + disable_ipv6 + log Warning "Disabling IPv6." + fi + ;; *) log Error "network_mode: ${network_mode}, unknown" exit 1 ;; esac - sync_port bin_alive && log Info "${bin_name} connected." ;; renew) - misc_info + box_etc + log Info "$IPV + $IP6V" probe_user_group || log Error "failed to check BOX user group, please make sure ${bin_name} kernel is started." log Warning "cleaning up iptables transparent proxy rules." # find uuid apps/game @@ -712,12 +732,12 @@ if [ "${proxy_mode}" != "tun" ]; then tproxy) log Info "Using Tproxy: tcp + udp." log Info "Creating iptables transparent proxy rules." - iptables="iptables -w 64" + iptables="$IPV" start_tproxy && log Info "Creating iptables transparent proxy rules done." || { log Error "Creating iptables transparent proxy rules failed." && stop_tproxy >> /dev/null 2>&1; } if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" start_tproxy && log Info "Creating ip6tables transparent proxy rules done." || { log Error "Creating ip6tables transparent proxy rules failed." && stop_tproxy >> /dev/null 2>&1; } else disable_ipv6 @@ -727,12 +747,12 @@ if [ "${proxy_mode}" != "tun" ]; then redirect) log Info "Using Redirect: tcp + udp (direct)." log Info "Creating iptables transparent proxy rules." - iptables="iptables -w 64" + iptables="$IPV" start_redirect && log Info "Creating iptables transparent proxy rules done." || { log Error "Creating iptables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" start_redirect && log Info "Creating ip6tables transparent proxy rules done." || { log Error "Creating ip6tables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } else disable_ipv6 @@ -742,13 +762,13 @@ if [ "${proxy_mode}" != "tun" ]; then mixed) log Info "Using Mixed: tcp(redirect) + udp(tun)." log Info "Creating iptables transparent proxy rules." - iptables="iptables -w 64" + iptables="$IPV" forward -I || forward -D >> /dev/null 2>&1 start_redirect && log Info "Creating iptables transparent proxy rules done." || (log Error "Creating iptables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1) if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" forward -I || forward -D >> /dev/null 2>&1 start_redirect && log Info "Creating ip6tables transparent proxy rules done." || (log Error "Creating ip6tables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1) else @@ -756,12 +776,26 @@ if [ "${proxy_mode}" != "tun" ]; then log Warning "Disabling IPv6." fi ;; + enhance) + log Info "Using Enhance: tcp(redirect) + udp(tproxy)" + log Info "Creating iptables transparent proxy rules." + iptables="$IPV" + start_redirect && start_tproxy && log Info "Creating iptables transparent proxy rules done." || { log Error "Creating iptables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } + if [ "${ipv6}" = "true" ]; then + log Debug "Using IPv6." + ipv6_enable + iptables="$IP6V" + start_redirect && start_tproxy && log Info "Creating ip6tables transparent proxy rules done." || { log Error "Creating ip6tables transparent proxy rule failed." && stop_redirect >> /dev/null 2>&1; } + else + disable_ipv6 + log Warning "Disabling IPv6." + fi + ;; *) log Error "network_mode: ${network_mode}, unknown" exit 1 ;; esac - sync_port log Info "restart iptables transparent proxy rules done." bin_alive && log Info "${bin_name} connected." ;; @@ -781,45 +815,45 @@ if [ "${proxy_mode}" != "tun" ]; then else case "$1" in enable) - misc_info + box_etc + log Info "$IPV + $IP6V" log Info "Using Tun: tcp + udp." probe_user_group || log Error "failed to check BOX user group, please make sure ${bin_name} kernel is started." # Cleanup iptables ipv4/6 cleanup_iptables - iptables="iptables -w 64" + iptables="$IPV" forward -I && log Info "Create iptables tun rules done." || { log Error "Create iptables tun rules failed." && forward -D >> /dev/null 2>&1; } if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" forward -I && log Info "Create ip6tables tun rules done." || { log Error "Create ip6tables tun rules failed." && forward -D >> /dev/null 2>&1; } else disable_ipv6 log Warning "Disable IPv6." fi - sync_port bin_alive && log Info "${bin_name} connected." ;; renew) - misc_info + box_etc + log Info "$IPV + $IP6V" log Info "Using Tun: tcp + udp." probe_user_group || log Error "failed to check BOX user group, please make sure ${bin_name} kernel is started." log Warning "Cleaning up tun rules." # Cleanup iptables ipv4/6 cleanup_iptables log Warning "Clean up tun rules done." - iptables="iptables -w 64" + iptables="$IPV" forward -I && log Info "Create iptables tun rules done." || { log Error "Create iptables tun rules failed." && forward -D >> /dev/null 2>&1; } if [ "${ipv6}" = "true" ]; then log Debug "Using IPv6." ipv6_enable - iptables="ip6tables -w 64" + iptables="$IP6V" forward -I && log Info "Create ip6tables tun rules done." || { log Error "Create ip6tables tun rules failed." && forward -D >> /dev/null 2>&1; } else disable_ipv6 log Warning "Disable IPv6." fi - sync_port log Info "Restart iptables tun rules done." bin_alive && log Info "${bin_name} connected." ;; diff --git a/box/scripts/box.service b/box/scripts/box.service index f637417..4c09e7f 100755 --- a/box/scripts/box.service +++ b/box/scripts/box.service @@ -128,15 +128,15 @@ box_create_tun() { if [ ! -c "/dev/net/tun" ]; then log Error "Cannot create /dev/net/tun. Possible reasons:" - log Warning " - Your system does not support the TUN/TAP driver." - log Warning " - Your system kernel version is not compatible with the TUN/TAP driver." + log Warning "Your system does not support the TUN/TAP driver." + log Warning "Your system kernel version is not compatible with the TUN/TAP driver." sed -i 's/network_mode=.*/network_mode="tproxy"/g' "${settings}" exit 1 fi } prepare_singbox() { - # check configuration file + # Check configuration file if ! [ -f "${sing_config}" ]; then log Error "configuration file ${sing_config} not found" exit 1 @@ -144,81 +144,67 @@ prepare_singbox() { log Info "config ${sing_config}" fi - # check yq - yq_command="yq" + # Check yq + yq="yq" if ! command -v yq &>/dev/null; then if [ ! -e "${box_dir}/bin/yq" ]; then log Debug "yq file not found, start to download from github" ${scripts_dir}/box.tool upyq fi - yq_command="${box_dir}/bin/yq" + yq="${box_dir}/bin/yq" fi - # delete Toggle comment, because yq doesn't work, Execute the sed command to uncomment the "/* ... */", "//" line - # sed -i '/\/\*/,/\*\//d; /^[[:space:]]*\/\//d; /^( *\/\/|\/\*.*\*\/)$/d' "${box_dir}/sing-box/"*.json + # Set auto_detect_interface/auto_route + ${yq} '.route.auto_detect_interface = true' -i --output-format=json "${sing_config}" + ${yq} '(.inbounds[] | select(.type == "tun") | .auto_route) |= true' -i --output-format=json "${sing_config}" - # format sing-box configuration + # Format sing-box configuration if ${bin_path} format -w -D "${box_dir}/${bin_name}" -C "${box_dir}/${bin_name}" > "${box_run}/${bin_name}.log" 2>&1; then - # if sed -i '/\/\*/,/\*\//d; /^[[:space:]]*\/\//d; /^( *\/\/|\/\*.*\*\/)$/d' "${box_dir}/sing-box/"*.json 2>&1; then - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then - if grep -q '"type": "tproxy"' "${sing_config}"; then - "${yq_command}" 'del(.inbounds[] | select(.type == "tproxy"))' -i --output-format=json "${sing_config}" - fi - - # Checks if "type" is "tun" in configuration - if grep -q '"type": "tun"' "${sing_config}"; then - log Info "type [Tun] already exists in ${sing_config}" - if ! grep -q '"auto_route": true' "${sing_config}"; then - log Error 'please set/add "auto_route": true in inbounds[tun]' - exit 1 - fi - else + # Set auto_route based on network_mode + if [[ "${network_mode}" == @(mixed|tun) ]]; then + # Check if "type" is "tun" in configuration + if ! busybox grep -q '"type": "tun"' "${sing_config}"; then # Add "tun" configuration if missing - "${yq_command}" '.inbounds += [{"type": "tun","tag": "tun-in","interface_name": "utun","inet4_address": "172.19.0.1/30","inet6_address": "fdfe:dcba:9876::1/126","mtu": 9000,"stack": "system","auto_route": true,"strict_route": false,"inet4_route_exclude_address": ["192.168.0.0/16"],"inet6_route_exclude_address": ["fc00::/7"],"sniff": true,"sniff_override_destination": false,"include_android_user": [0,10],"include_package": [],"exclude_package": []}]' -i --output-format=json "${sing_config}" + ${yq} '.inbounds += [{"type": "tun","tag": "tun-in","interface_name": "utun","inet4_address": "172.19.0.1/30","inet6_address": "fdfe:dcba:9876::1/126","mtu": 9000,"stack": "system","auto_route": true,"strict_route": false,"inet4_route_exclude_address": ["192.168.0.0/16"],"inet6_route_exclude_address": ["fc00::/7"],"sniff": true,"sniff_override_destination": false,"include_android_user": [0,10],"include_package": [],"exclude_package": []}]' -i --output-format=json "${sing_config}" log Debug "[Tun] configuration has been added to ${sing_config}" fi - - # add auto_detect_interface - "${yq_command}" '.route.auto_detect_interface = true' -i --output-format=json "${sing_config}" - - # Checks if "type" is "redirect" in configuration - if [ "${network_mode}" = "mixed" ]; then - if grep -q '"type": "redirect"' "${sing_config}"; then - log Info "type [Redirect] already exists in ${sing_config}" - else - # Add "redirect" configuration if missing - "${yq_command}" '.inbounds += [{"type": "redirect","tag": "redirect-in","listen": "::","listen_port": '"${redir_port}"',"sniff": true,"sniff_override_destination": false}]' -i --output-format=json "${sing_config}" - log Debug "[Redirect] configuration has been added to ${sing_config}" - fi - fi - sed -i 's/"auto_detect_interface": false/"auto_detect_interface": true/g' "${box_dir}/sing-box/"*.json - sed -i 's/auto_route": false/auto_route": true/g' "${box_dir}/sing-box/"*.json else - if grep -q '"type": "tun"' "${sing_config}"; then - "${yq_command}" 'del(.inbounds[] | select(.type == "tun"))' -i --output-format=json "${sing_config}" - fi - if grep -q '"type": "redirect"' "${sing_config}"; then - "${yq_command}" 'del(.inbounds[] | select(.type == "redirect"))' -i --output-format=json "${sing_config}" - fi + # Set auto_route to false for non-"tun" network_mode + sed -i 's/auto_route": true/auto_route": false/g' "${box_dir}/sing-box/"*.json + # Set auto_detect_interface to false + sed -i 's/"auto_detect_interface": true/"auto_detect_interface": false/g' "${box_dir}/sing-box/"*.json - # Checks if "type" is "tproxy" in configuration - if grep -q '"type": "tproxy"' "${sing_config}"; then - log Info "type [Tproxy] already exists in ${sing_config}" - else + # Check if "type" is "tproxy" in configuration + if ! busybox grep -q '"type": "tproxy"' "${sing_config}"; then # Add "tproxy" configuration if missing - "${yq_command}" '.inbounds += [{"type": "tproxy", "tag": "tproxy-in", "listen": "::", "listen_port": '"${tproxy_port}"', "sniff": true, "sniff_override_destination": false}]' -i --output-format=json "${sing_config}" + ${yq} '.inbounds += [{"type": "tproxy", "tag": "tproxy-in", "listen": "::", "listen_port": '"${tproxy_port}"', "sniff": true, "sniff_override_destination": false}]' -i --output-format=json "${sing_config}" log Debug "[Tproxy] configuration has been added to ${sing_config}" fi - # sync tproxy port sing-box, Looping through each JSON file in the directory + # Sync tproxy port sing-box for file in "${box_dir}/sing-box/"*.json; do tproxy=$(sed -n 's/.*"type": "\(tproxy\)".*/\1/p' "${file}") if [ -n "${tproxy}" ]; then - "${yq_command}" -o=json "(.inbounds[]? | select(.type == \"tproxy\") | .listen_port) = ${tproxy_port}" -i --output-format=json "${file}" + ${yq} -o=json "(.inbounds[]? | select(.type == \"tproxy\") | .listen_port) = ${tproxy_port}" -i --output-format=json "${file}" fi done - sed -i 's/"auto_detect_interface": true/"auto_detect_interface": false/g' "${box_dir}/sing-box/"*.json - sed -i 's/auto_route": true/auto_route": false/g' "${box_dir}/sing-box/"*.json + fi + + # add exclude_package/include_package for tun + # "${yq}" '(.inbounds[] | select(.type == "tun") | .include_package) = []' -i --output-format=json "${sing_config}" + # "${yq}" '(.inbounds[] | select(.type == "tun") | .exclude_package) = []' -i --output-format=json "${sing_config}" + # [ ${proxy_mode} = "blacklist" ] && local mode="exclude" || mode="include" + # for package in "${packages_list[@]}"; do + # "${yq}" eval '(.inbounds[] | select(.type == "tun") | .'${mode}'_package) += ["'${package}'"]' -i --output-format=json "${sing_config}" + # done + + # Add "redirect" configuration based on network_mode + if [[ "${network_mode}" == @(mixed|enhance|redirect) ]]; then + if ! busybox grep -q '"type": "redirect"' "${sing_config}"; then + # Add "redirect" configuration if missing + ${yq} '.inbounds += [{"type": "redirect","tag": "redirect-in","listen": "::","listen_port": '"${redir_port}"',"sniff": true,"sniff_override_destination": false}]' -i --output-format=json "${sing_config}" + log Debug "[Redirect] configuration has been added to ${sing_config}" + fi fi else log Error "$(<"${box_run}/${bin_name}.log")" @@ -264,7 +250,7 @@ prepare_clash() { printf "\nredir-port: ${redir_port}" >> "${clash_config}" fi - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then + if [[ "${network_mode}" == @(mixed|tun) ]]; then clash_tun_status=$(busybox awk '!/^ *#/ && /tun:/ { getline; split($0, arr, ": "); print arr[2]; found=1; exit } END{ if (!found) print "" }' "${clash_config}" 2>/dev/null) # write TUN settings, if not in $clash_config if [ -z "${clash_tun_status}" ]; then @@ -272,7 +258,7 @@ prepare_clash() { ' enable: true' \ ' mtu: 9000' \ ' device: utun' \ - ' stack: system # gvisor / system / lwip' \ + ' stack: system # mixed / gvisor / system / lwip' \ ' dns-hijack:' \ ' - any:53' \ ' - tcp://any:53' \ @@ -280,30 +266,33 @@ prepare_clash() { ' strict-route: false' \ ' auto-detect-interface: true' \ ' include-android-user: [0, 10]' \ - ' exclude-package: [] # blacklist' \ - ' include-package: [] # whitelist' \ >> "${clash_config}" + ' exclude-package: []' \ + ' include-package: []' \ >> "${clash_config}" log Debug "[tun] configuration has been added to ${clash_config}" else log Info "type [tun] already exists in ${clash_config}" fi + + # add exclude-package/include-package for tun + # package=$(IFS=","; echo "${packages_list[*]}" | tr ' ' ',') + # list_package="${package:-\"\"}" + # if [ "${proxy_mode}" = "whitelist" ]; then + # mode="include-package" + # elif [ "${proxy_mode}" = "blacklist" ]; then + # mode="exclude-package" + # fi + # sed -i "s/exclude-package:.*/exclude-package: []/g" "${clash_config}" + # sed -i "s/include-package:.*/include-package: []/g" "${clash_config}" + # sed -i "s/${mode}:.*/${mode}: [\"${list_package//,/\",\"}\"]/g" "${clash_config}" + sed -i "/tun:/ {n;s/enable: false/enable: true/}" "${clash_config}" else sed -i "/tun:/ {n;s/enable: true/enable: false/}" "${clash_config}" fi - # Reads the enable value from the tun configuration - clash_tun_status=$(busybox awk -F ': ' '/^tun: *$/{getline; print $2}' "${clash_config}") - if [ "${clash_tun_status}" != "true" ]; then - # sync tproxy port - sed -i -E "s/(tproxy-port: )[0-9]+/\1${tproxy_port}/" "${clash_config}" - sed -i -E "s/(redir-port: )[0-9]+/\1${redir_port}/" "${clash_config}" - else - [ "${proxy_mode}" != "tun" ] && sed -i 's/network_mode=.*/network_mode="mixed"/g' "${settings}" - # remove tproxy port >>> 0 - sed -i -E "s/(tproxy-port: )[0-9]+/\10/" "${clash_config}" - # sync redir port - sed -i -E "s/(redir-port: )[0-9]+/\1${redir_port}/" "${clash_config}" - fi + # sync tproxy/redir port + sed -i -E "s/(tproxy-port: )[0-9]+/\1${tproxy_port}/" "${clash_config}" + sed -i -E "s/(redir-port: )[0-9]+/\1${redir_port}/" "${clash_config}" clash_enhanced_mode=$(busybox awk '!/^ *#/ && /enhanced-mode: / { print $2 }' "${clash_config}" 2>/dev/null) if [ -z "${clash_enhanced_mode}" ]; then @@ -312,7 +301,7 @@ prepare_clash() { log Debug "enhanced-mode: fake-ip add success" fi - if [ "${proxy_mode}" != "tun" ]; then + if [[ "${network_mode}" == @(mixed|tproxy|redirect|enhance) ]]; then if [[ -n "${packages_list[*]}" || -n "${gid_list[*]}" ]] && [ "${clash_enhanced_mode}" = "fake-ip" ]; then log Warning "${proxy_mode} only works in enhanced-mode: redir-host xclash[mihomo]" log Warning "auto replace fake-ip to redir-host" @@ -331,7 +320,7 @@ box_run_bin() { sing-box) prepare_singbox if ${bin_path} check -D "${box_dir}/${bin_name}" -C "${box_dir}/${bin_name}" > "${box_run}/${bin_name}.log" 2>&1; then - nohup busybox setuidgid "${box_user_group}" taskset "${mask_cpuset}" "${bin_path}" run -D "${box_dir}/${bin_name}" -C "${box_dir}/${bin_name}" > "${bin_log}" 2>&1 & + nohup busybox setuidgid "${box_user_group}" "${bin_path}" run -D "${box_dir}/${bin_name}" -C "${box_dir}/${bin_name}" > "${bin_log}" 2>&1 & PID=$! echo -n $PID > "${box_pid}" sleep 1 @@ -344,7 +333,7 @@ box_run_bin() { clash) prepare_clash if ${bin_path} -t -d "${box_dir}/${bin_name}" -f "${clash_config}" > "${box_run}/${bin_name}.log" 2>&1; then - nohup busybox setuidgid "${box_user_group}" taskset "${mask_cpuset}" "${bin_path}" -d "${box_dir}/${bin_name}" -f "${clash_config}" > "${bin_log}" 2>&1 & + nohup busybox setuidgid "${box_user_group}" "${bin_path}" -d "${box_dir}/${bin_name}" -f "${clash_config}" > "${bin_log}" 2>&1 & PID=$! echo -n $PID > "${box_pid}" sleep 1 @@ -356,8 +345,9 @@ box_run_bin() { ;; xray) # set network_mode variable value to "tproxy" - sed -i 's/\(network_mode=\)\"[^\"]*\"/\1"tproxy"/g' ${settings} - [ "${proxy_mode}" = "tun" ] && sed -i 's/\(proxy_mode=\)\"[^\"]*\"/\1"blacklist"/g' ${settings} + if [[ "${network_mode}" != "tproxy" ]]; then + sed -i 's/\(network_mode=\)\"[^\"]*\"/\1"tproxy"/g' ${settings} + fi # sync port # sed -i "s/port = [0-9]*\.[0-9]*/port = ${tproxy_port}.0/" ${box_dir}/$bin_name/config.toml @@ -375,7 +365,7 @@ box_run_bin() { # run xray export XRAY_LOCATION_ASSET="${box_dir}/${bin_name}" if ${bin_path} -test -confdir "${box_dir}/${bin_name}" > "${box_run}/${bin_name}.log" 2>&1; then - nohup busybox setuidgid "${box_user_group}" taskset "${mask_cpuset}" "${bin_path}" run -confdir "${box_dir}/${bin_name}" > "${bin_log}" 2>&1 & + nohup busybox setuidgid "${box_user_group}" "${bin_path}" run -confdir "${box_dir}/${bin_name}" > "${bin_log}" 2>&1 & PID=$! echo -n $PID > "${box_pid}" sleep 1 @@ -387,8 +377,9 @@ box_run_bin() { ;; v2fly) # set network_mode variable value to "tproxy" - sed -i 's/\(network_mode=\)\"[^\"]*\"/\1"tproxy"/g' ${settings} - [ "${proxy_mode}" = "tun" ] && sed -i 's/\(proxy_mode=\)\"[^\"]*\"/\1"blacklist"/g' ${settings} + if [[ "${network_mode}" != "tproxy" ]]; then + sed -i 's/\(network_mode=\)\"[^\"]*\"/\1"tproxy"/g' ${settings} + fi # sync port # sed -i "s/port = [0-9]*\.[0-9]*/port = ${tproxy_port}.0/" ${box_dir}/$bin_name/config.toml @@ -405,7 +396,7 @@ box_run_bin() { # run v2ray export V2RAY_LOCATION_ASSET="${box_dir}/${bin_name}" if ${bin_path} test -d "${box_dir}/${bin_name}" > "${box_run}/${bin_name}.log" 2>&1; then - nohup busybox setuidgid "${box_user_group}" taskset "${mask_cpuset}" "${bin_path}" run -d "${box_dir}/${bin_name}" > "${bin_log}" 2>&1 & + nohup busybox setuidgid "${box_user_group}" "${bin_path}" run -d "${box_dir}/${bin_name}" > "${bin_log}" 2>&1 & PID=$! echo -n $PID > "${box_pid}" sleep 1 @@ -454,9 +445,9 @@ box_bin_status() { fi stack=$(if [ "${bin_name}" != "clash" ]; then find "/data/adb/box/sing-box" -type f -name "*.json" -exec busybox awk -F'"' '/"stack"/{print $4}' {} +; else busybox awk '!/^ *#/ && /stack: / { print $2;found=1; exit}' "${clash_config}"; fi) - TOAST=1 log Info "${bin_name} service is running." - log Info "proxy: ${proxy_mode} | $(if [ "${proxy_mode}" != "tun" ]; then echo network: ${network_mode}; fi) | $(if [[ "${proxy_mode}" == "tun" || ${network_mode} == "mixed" ]]; then echo stack: ${stack}; fi)" + + log Info "proxy: ${proxy_mode} + network: ${network_mode} + $(if [[ "${network_mode}" == @(mixed|tun) ]]; then echo "stack: ${stack}"; fi)" # Get the memory usage of the binary rss=$(grep VmRSS /proc/$PID/status | busybox awk '{ print $2 }') @@ -524,15 +515,17 @@ start_box() { echo -e "${yellow}$(getprop persist.sys.timezone)${normal}" echo -e "${yellow}$(getprop gsm.sim.operator.alpha) / $(getprop gsm.network.type)${normal}" echo -e "${yellow}$(date)${normal}" - echo -e "${yellow}${box_version}, $(getprop ro.product.cpu.abi)${normal}" - echo -e "${white}--------------------------------------------${normal}" + echo -e "${yellow}${box_version}${normal}" + echo -e "${yellow}$(getprop ro.product.cpu.abi)${normal}" + echo -e "${white}━━━━━━━━━━━━━━━━━━${normal}" else { echo "$(getprop persist.sys.timezone)" echo "$(getprop gsm.sim.operator.alpha) / $(getprop gsm.network.type)" echo "$(date)" - echo "${box_version}, $(getprop ro.product.cpu.abi)" - echo "--------------------------------------------" + echo "${box_version}" + echo "$(getprop ro.product.cpu.abi)" + echo "━━━━━━━━━━━━━━━━━━" } | tee -a "${box_log}" > /dev/null 2>&1 fi @@ -572,8 +565,19 @@ start_box() { ;; esac + # apk manager check + versionName=$(dumpsys package xyz.chz.bfm | grep versionName | busybox awk -F '=' '{print $2}' | sed 's/-.*//') + if [[ -n "${versionName}" && $(echo "${versionName}" | busybox awk '{print ($1 < 1.13)}') -eq 1 ]]; then + log Error "Update BFR Manager Apps, Use version 1.13.+" + log Error "current version: ${versionName}" + exit 1 + else + [ -n "${versionName}" ] && log Info "BFR Manager: ${versionName}" + fi + # busybox check busybox_code=$(busybox | head -n 1 | busybox awk '{print $2}' | busybox grep -oE '[0-9.]*') + # busybox_code=$(busybox | head -n 1 | busybox awk '{print $2}' | grep -oE [0-9.]*") if [ "$(echo "${busybox_code}" | busybox awk -F. '{printf "%03d%03d%03d\n", $1, $2, $3}')" -lt "$(echo "1.36.1" | busybox awk -F. '{printf "%03d%03d%03d\n", $1, $2, $3}')" ]; then log Info "Current $(which busybox) v${busybox_code}" log Warning "Please update your busybox to v1.36.1+" @@ -590,7 +594,7 @@ start_box() { box_check_logs # Execute the box_create_tun functions - if [[ "${network_mode}" == "mixed" || "${proxy_mode}" == "tun" ]]; then + if [[ "${network_mode}" == @(mixed|tun) ]]; then box_create_tun fi @@ -634,7 +638,8 @@ stop_box() { fi log Warning "${bin_name} shutting down, service is stopped." TOAST=1 log Warning "${bin_name} disconnected." - [ -t 1 ] && echo -e "${white}--------------------------------------------${normal}" + + [ -t 1 ] && echo -e "${white}━━━━━━━━━━━━━━━━━━${normal}" else log Warning "${bin_name} Not stopped; may still be shutting down or failed to shut down." force_stop diff --git a/box/scripts/box.tool b/box/scripts/box.tool index 9538ddf..bde59e6 100755 --- a/box/scripts/box.tool +++ b/box/scripts/box.tool @@ -254,13 +254,13 @@ upsubs() { enhanced=false update_file_name="${clash_config}" if [ "${renew}" != "true" ]; then - yq_command="yq" + yq="yq" if ! command -v yq &>/dev/null; then if [ ! -e "${box_dir}/bin/yq" ]; then log Debug "yq file not found, start to download from github" ${scripts_dir}/box.tool upyq fi - yq_command="${box_dir}/bin/yq" + yq="${box_dir}/bin/yq" fi enhanced=true update_file_name="${update_file_name}.subscription" @@ -277,16 +277,16 @@ upsubs() { log Info "${update_file_name} saved" # If there is a yq command, extract the proxy information from the yml and output it to the clash_provide_config file if [ "${enhanced}" = "true" ]; then - if ${yq_command} '.proxies' "${update_file_name}" >/dev/null 2>&1; then - "${yq_command}" '.proxies' "${update_file_name}" > "${clash_provide_config}" - "${yq_command}" -i '{"proxies": .}' "${clash_provide_config}" + if ${yq} '.proxies' "${update_file_name}" >/dev/null 2>&1; then + ${yq} '.proxies' "${update_file_name}" > "${clash_provide_config}" + ${yq} -i '{"proxies": .}' "${clash_provide_config}" if [ "${custom_rules_subs}" = "true" ]; then - if ${yq_command} '.rules' "${update_file_name}" >/dev/null 2>&1; then + if ${yq} '.rules' "${update_file_name}" >/dev/null 2>&1; then - "${yq_command}" '.rules' "${update_file_name}" > "${clash_provide_rules}" - "${yq_command}" -i '{"rules": .}' "${clash_provide_rules}" - "${yq_command}" -i 'del(.rules)' "${clash_config}" + ${yq} '.rules' "${update_file_name}" > "${clash_provide_rules}" + ${yq} -i '{"rules": .}' "${clash_provide_rules}" + ${yq} -i 'del(.rules)' "${clash_config}" cat "${clash_provide_rules}" >> "${clash_config}" fi @@ -634,6 +634,18 @@ cgroup_cpuset() { ip_port=$(if [ "${bin_name}" = "clash" ]; then busybox awk '/external-controller:/ {print $2}' "${clash_config}"; else find /data/adb/box/sing-box/ -maxdepth 1 -type f -name "*.json" -exec busybox awk -F':' '/experimental/,/\}/' {} \; | sed -n 's/.*"external_controller": "\(.*\)",/\1/p'; fi;) secret="" +bond1() { + su -mm -c "cmd wifi force-low-latency-mode enabled" + su -mm -c "sysctl -w net.ipv4.tcp_low_latency=1" + su -mm -c "ip link set dev wlan0 txqueuelen 4000" +} + +bond0() { + su -mm -c "cmd wifi force-low-latency-mode disabled" + su -mm -c "sysctl -w net.ipv4.tcp_low_latency=0" + su -mm -c "ip link set dev wlan0 txqueuelen 3000" +} + case "$1" in check) check @@ -655,13 +667,14 @@ case "$1" in ;; esac ;; + bond0|bond1) + $1 + ;; geosub) upsubs upgeox if [ -f "${box_pid}" ]; then - if kill -0 "$(<"${box_pid}" 2>/dev/null)"; then - reload - fi + kill -0 "$(<"${box_pid}" 2>/dev/null)" && reload fi ;; geox|subs) @@ -672,9 +685,7 @@ case "$1" in [ "${bin_name}" != "clash" ] && exit 1 fi if [ -f "${box_pid}" ]; then - if kill -0 "$(<"${box_pid}" 2>/dev/null)"; then - reload - fi + kill -0 "$(<"${box_pid}" 2>/dev/null)" && reload fi ;; upkernel) @@ -701,6 +712,6 @@ case "$1" in ;; *) echo "${red}$0 $1 no found${normal}" - echo "${yellow}usage${normal}: ${green}$0${normal} {${yellow}check|memcg|cpuset|blkio|geosub|geox|subs|upkernel|upxui|upyq|upcurl|reload|all${normal}}" + echo "${yellow}usage${normal}: ${green}$0${normal} {${yellow}check|memcg|cpuset|blkio|geosub|geox|subs|upkernel|upxui|upyq|upcurl|reload|bond0|bond1|all${normal}}" ;; esac \ No newline at end of file diff --git a/box/settings.ini b/box/settings.ini index f5c5eed..5e4a109 100755 --- a/box/settings.ini +++ b/box/settings.ini @@ -32,12 +32,14 @@ bin_name="clash" # This script is used to set the user and group for the BFM core files. box_user_group="root:net_admin" -# redirect: tcp only, -# tproxy: for tcp + udp with tproxy, -# mixed: mode with redirect[tcp] + tun[udp] +# redirect: tcp + udp[direct] +# tproxy: tcp + udp +# mixed: redirect[tcp] + tun[udp] +# enhance: redirect[tcp] + tproxy[udp] +# tun: tcp + udp (auto-route) network_mode="tproxy" -# blacklist / whitelist / tun (only tun auto-route) +# blacklist / whitelist proxy_mode="blacklist" # list of package names to be proxied @@ -58,8 +60,6 @@ memcg_limit="25M" # Set cgroup to cpuset usage cgroup_cpuset="false" -# 0f=0-3 / f0=4-7 / ff=0-7, recommended default: ff -mask_cpuset="ff" # Set cgroup to blkio usage cgroup_blkio="false" diff --git a/customize.sh b/customize.sh index 0d5785d..7207a9b 100644 --- a/customize.sh +++ b/customize.sh @@ -17,12 +17,12 @@ elif [ "$KSU" = true ] && [ "$KSU_VER_CODE" -lt 10670 ]; then abort "-----------------------------------------------------------" fi -if [ "$API" -lt 28 ]; then - ui_print "! Unsupported sdk: $API" - abort "! Minimal supported sdk is 28 (Android 9)" -else - ui_print "- Device sdk: $API" -fi +# if [ "$API" -lt 28 ]; then + # ui_print "! Unsupported sdk: $API" + # abort "! Minimal supported sdk is 28 (Android 9)" +# else + # ui_print "- Device sdk: $API" +# fi service_dir="/data/adb/service.d" if [ "$KSU" = "true" ]; then