mirror of
https://github.com/juewuy/ShellCrash.git
synced 2024-11-16 03:32:34 +08:00
16cf5897c3
~大幅度优化脚本UI及层级 ~增加在线更新脚本功能 ~增加在线更新、替换clash核心功能 ~内置dns增加redir-host支持,解决了部分应用无法连接的bug ~优化了配置文件修饰途径,现在支持通过scp上传任意yaml配置文件 ~增加了直接导入完整订阅链接的选项(待测试) ~增加了更多的订阅后端服务器
120 lines
4.1 KiB
Bash
120 lines
4.1 KiB
Bash
#!/bin/sh /etc/rc.common
|
||
# Example script
|
||
# Copyright (C) 2007 OpenWrt.org
|
||
|
||
USE_PROCD=1
|
||
START=99
|
||
|
||
getconfig(){
|
||
clashdir=/etc/clash
|
||
ccfg=$clashdir/mark
|
||
if [ ! -f "$ccfg" ]; then
|
||
echo mark文件不存在,默认以Redir模式运行!
|
||
cat >$ccfg<<EOF
|
||
#标识clash运行状态的文件,不明勿动!
|
||
EOF
|
||
redir_mod=redir模式
|
||
common_ports=未开启
|
||
dns_mod=redir-host
|
||
fi
|
||
source $ccfg #加载配置文件
|
||
#是否代理常用端口
|
||
if [ "$common_ports" = "已开启" ];then
|
||
ports='-m multiport --dports 22,53,587,465,995,993,143,80,443 '
|
||
fi
|
||
#DNS模式
|
||
if [ "$common_ports" = "已开启" ];then
|
||
ports='-m multiport --dports 22,53,587,465,995,993,143,80,443 '
|
||
fi
|
||
}
|
||
modifyyaml(){
|
||
##########需要变更的配置###########
|
||
redir='redir-port: 7892'
|
||
ipv6='ipv6: true'
|
||
external='external-controller: 0.0.0.0:9999'
|
||
if [ "$dns_mod" = "fake-ip" ];then
|
||
dns='dns: {enable: true, listen: 0.0.0.0:1053, fake-ip-range: 198.18.0.1/16, enhanced-mode: fake-ip, nameserver: [114.114.114.114, 127.0.0.1:53], fallback: [tcp://1.0.0.1, 8.8.4.4]}'
|
||
else
|
||
dns='dns: {enable: true, ipv6: true, listen: 0.0.0.0:1053, enhanced-mode: redir-host, nameserver: [114.114.114.114, 127.0.0.1:53], fallback: [1.0.0.1, 8.8.4.4]}'
|
||
fi
|
||
if [ "$redir_mod" = "Tun模式" ];then
|
||
tun='tun: {enable: true, stack: system}'
|
||
else
|
||
tun='tun: {enable: false}'
|
||
fi
|
||
exper='experimental: {ignore-resolve-fail: true, interface-name: en0}'
|
||
###################################
|
||
#预删除需要添加的项目
|
||
sed -i '/^redir-port:*/'d $clashdir/config.yaml
|
||
sed -i '/^ipv6: true:*/'d $clashdir/config.yaml
|
||
sed -i '/^external-controller:*/'d $clashdir/config.yaml
|
||
sed -i '/^dns:*/'d $clashdir/config.yaml
|
||
sed -i '/^tun:*/'d $clashdir/config.yaml
|
||
sed -i '/^experimental:*/'d $clashdir/config.yaml
|
||
#添加配置
|
||
sed -i "2a$redir" $clashdir/config.yaml
|
||
sed -i "5a$ipv6" $clashdir/config.yaml
|
||
sed -i "6a$external" $clashdir/config.yaml
|
||
sed -i "7a$dns" $clashdir/config.yaml
|
||
sed -i "8a$tun" $clashdir/config.yaml
|
||
sed -i "9a$exper" $clashdir/config.yaml
|
||
if [ "$skip_cert" != "未开启" ];then
|
||
sed -i "10,99s/sni: \S*/\1skip-cert-verify: true}/" $clashdir/config.yaml #跳过trojan本地证书验证
|
||
sed -i '10,99s/}}/}, skip-cert-verify: true}/' $clashdir/config.yaml #跳过v2+ssl本地证书验证
|
||
fi
|
||
sed -i '/rules:/a \ - DOMAIN-SUFFIX,clash.razord.top,🎯 全球直连' $clashdir/config.yaml
|
||
}
|
||
mark_time(){
|
||
start_time=`date +%s`
|
||
sed -i '/start_time*/'d $ccfg
|
||
sed -i "3i\start_time=$start_time" $ccfg
|
||
}
|
||
start_redir(){
|
||
#修改iptables规则使流量进入clash
|
||
iptables -t nat -N clash
|
||
iptables -t nat -A clash -d 0.0.0.0/8 -j RETURN
|
||
iptables -t nat -A clash -d 10.0.0.0/8 -j RETURN
|
||
iptables -t nat -A clash -d 127.0.0.0/8 -j RETURN
|
||
iptables -t nat -A clash -d 169.254.0.0/16 -j RETURN
|
||
iptables -t nat -A clash -d 172.16.0.0/12 -j RETURN
|
||
iptables -t nat -A clash -d 192.168.0.0/16 -j RETURN
|
||
iptables -t nat -A clash -d 224.0.0.0/4 -j RETURN
|
||
iptables -t nat -A clash -d 240.0.0.0/4 -j RETURN
|
||
iptables -t nat -A clash -p tcp $ports-j REDIRECT --to-ports 7892
|
||
iptables -t nat -A PREROUTING -p tcp -j clash
|
||
#ip6tables -t nat -A PREROUTING -p tcp $ports-j REDIRECT --to-ports 7892
|
||
iptables -t nat -A PREROUTING -p udp --dport 53 -j REDIRECT --to 1053
|
||
ip6tables -t nat -A PREROUTING -p udp --dport 53 -j REDIRECT --to 1053
|
||
}
|
||
stop_redir(){
|
||
#重置iptables规则
|
||
iptables -t nat -D PREROUTING -p tcp -j clash > /dev/null 2>&1
|
||
iptables -t nat -F clash > /dev/null 2>&1
|
||
iptables -t nat -X clash > /dev/null 2>&1
|
||
iptables -t nat -D PREROUTING -p udp --dport 53 -j REDIRECT --to 1053 > /dev/null 2>&1
|
||
#ip6tables -t nat -A PREROUTING -p tcp $ports-j REDIRECT --to-ports 7892 > /dev/null 2>&1
|
||
ip6tables -t nat -D PREROUTING -p udp --dport 53 -j REDIRECT --to 1053 > /dev/null 2>&1
|
||
}
|
||
start_tun(){
|
||
#允许tun网卡接受流量
|
||
iptables -I FORWARD -o utun -j ACCEPT
|
||
}
|
||
start_service() {
|
||
getconfig
|
||
modifyyaml
|
||
#创建clash后台进程
|
||
procd_open_instance
|
||
procd_set_param respawn
|
||
procd_set_param stderr 1
|
||
procd_set_param stdout 1
|
||
procd_set_param command $clashdir/clash -d $clashdir
|
||
procd_close_instance
|
||
#修改iptables规则使流量进入clash
|
||
stop_redir
|
||
start_tun
|
||
start_redir
|
||
mark_time
|
||
}
|
||
stop_service() {
|
||
stop_redir
|
||
} |