add_archive_project

This commit is contained in:
2026-04-04 13:25:49 +04:00
commit 810b3b1372
17 changed files with 642 additions and 0 deletions
+11
View File
@@ -0,0 +1,11 @@
config xray 'enabled'
option enabled '1'
config xray 'config'
option confdir '/etc/xray/config'
#list conffiles '/etc/xray/config.json'
option datadir '/usr/share/xray'
option dialer ''
option format 'json'
+64
View File
@@ -0,0 +1,64 @@
#!/bin/sh /etc/rc.common
USE_PROCD=1
START=99
CONF="xray"
PROG="/usr/bin/xray"
start_service() {
config_load "$CONF"
local enabled
config_get_bool enabled "enabled" "enabled" "0"
[ "$enabled" -eq "1" ] || return 1
local confdir
local conffiles
local datadir
local dialer
local format
config_get confdir "config" "confdir"
config_get conffiles "config" "conffiles"
config_get datadir "config" "datadir" "/usr/share/xray"
config_get dialer "config" "dialer"
config_get format "config" "format" "json"
/etc/xray/main/startup.sh
procd_open_instance "$CONF"
procd_set_param command "$PROG" run
[ -n "$confdir" ] && procd_append_param command -confdir "$confdir"
[ -n "$conffiles" ] && {
for i in $conffiles
do
procd_append_param command -config "$i"
done
}
[ -n "$format" ] && procd_append_param command -format "$format"
[ -n "$dialer" ] && procd_set_param env XRAY_BROWSER_DIALER="$dialer"
procd_set_param env XRAY_LOCATION_ASSET="$datadir"
procd_set_param file $conffiles
procd_set_param limits core="unlimited"
procd_set_param limits nofile="1000000 1000000"
procd_set_param stdout 1
procd_set_param stderr 1
procd_set_param respawn
procd_close_instance
}
stop_service() {
/etc/xray/main/revert.sh
}
reload_service() {
stop
start
}
service_triggers() {
procd_add_reload_trigger "$CONF"
}
+25
View File
@@ -0,0 +1,25 @@
ipset_dir="/etc/xray/ipset"
ipnet_dir="/etc/xray/ipnet"
dnsmasq_dir="/etc/dnsmasq.d"
user_ipset_file="$ipset_dir/xray_ip_user.lst"
user_ipset_whitelist_file="$ipset_dir/xray_ip_user_whitelist.lst"
user_dnsmasq_file="$ipset_dir/xray_domain_user.lst"
user_dnsmasq_whitelist_file="$ipset_dir/xray_domain_user_whitelist.lst"
log_dir="/var/log/xray"
mkdir -p "$ipset_dir" "$ipnet_dir" "$dnsmasq_dir"
[ -f "$user_ipset_file" ] || touch "$user_ipset_file"
[ -f "$user_ipset_whitelist_file" ] || touch "$user_ipset_whitelist_file"
[ -f "$user_dnsmasq_file" ] || touch "$user_dnsmasq_file"
[ -f "$user_dnsmasq_whitelist_file" ] || touch "$user_dnsmasq_whitelist_file"
mkdir -p "$log_dir"
if ! grep -q "mkdir -p $log_dir" /etc/rc.local; then
sed -i "/exit 0/i mkdir -p $log_dir" /etc/rc.local
fi
current_confdir=$(uci get dhcp.@dnsmasq[0].confdir 2>/dev/null)
if [ "$current_confdir" != "$dnsmasq_dir" ]; then
uci set dhcp.@dnsmasq[0].confdir='/etc/dnsmasq.d'
uci commit dhcp
fi
+36
View File
@@ -0,0 +1,36 @@
#!/usr/sbin/nft -f
table ip xray {
set dst_list {
type ipv4_addr
auto-merge
flags interval
}
set dst_exclude {
type ipv4_addr
flags interval
auto-merge
}
set src_list {
type ipv4_addr
flags interval
auto-merge
elements = { 10.1.0.0/24, 10.2.0.0/24 }
}
set src_exclude {
type ipv4_addr
flags interval
auto-merge
elements = { 10.1.0.6/32 }
}
chain prerouting {
type filter hook prerouting priority mangle; policy accept;
ip saddr @src_list ip saddr != @src_exclude ip protocol tcp ip daddr @dst_list ip daddr != @dst_exclude tproxy to 127.0.0.1:61219 meta mark set 10
ip saddr @src_list ip saddr != @src_exclude ip protocol udp ip daddr @dst_list ip daddr != @dst_exclude tproxy to 127.0.0.1:61219 meta mark set 10
}
}
+37
View File
@@ -0,0 +1,37 @@
#!/bin/sh
nft_table="xray"
nft_set="dst_list"
nft_set_exclude="dst_exclude"
ipset_dir="/etc/xray/ipset"
dnsmasq_dir="/etc/dnsmasq.d"
for ipset_file in "$ipset_dir"/xray_domain*; do
ipset_filename=$(basename "$ipset_file")
ipnet_file="$dnsmasq_dir/$ipset_filename"
if echo "$ipset_filename" | grep -qiE "exclude|white"; then
target_set="$nft_set_exclude"
else
target_set="$nft_set"
fi
awk -v t_set="$target_set" -v table="$nft_table" '
/^[[:space:]]*#/ || /^[[:space:]]*$/ { next }
{
sub(/#.*/, "")
gsub(/[[:space:]]/, "")
if ($0 !~ /\./) next
sub(/^[^:]+:/, "", $0)
if ($0 ~ /@cn$/) next
sub(/@[^@]+$/, "", $0)
print "nftset=/" $0 "/4#ip#" table "#" t_set
}
' "$ipset_file" > "$ipnet_file"
if ! dnsmasq --test -C "$ipnet_file" >/dev/null 2>&1; then
logger -t xray-prepare_domain "$dnsmasq_dir/$ipset_filename: validation failed"
fi
done
+41
View File
@@ -0,0 +1,41 @@
#!/bin/sh
nft_table="xray"
nft_set="dst_list"
nft_set_exclude="dst_exclude"
ipset_dir="/etc/xray/ipset"
ipnet_dir="/etc/xray/ipnet"
for ipset_file in "$ipset_dir"/xray_ip*; do
ipset_filename=$(basename "$ipset_file")
ipnet_file="$ipnet_dir/$ipset_filename"
if [ ! -s "$ipset_file" ] || ! grep -q "[^[:space:]]" "$ipset_file"; then
logger -t xray-prepare_net "$ipset_dir/$ipset_filename: file is empty"
continue
fi
if echo "$ipset_filename" | grep -qiE "exclude|white"; then
target_set="$nft_set_exclude"
else
target_set="$nft_set"
fi
{
echo -n "add element ip $nft_table $target_set { "
awk '
/^[[:space:]]*#/ || /^[[:space:]]*$/ { next }
{
val = $0
if (val !~ /\//) val = val "/32"
printf "%s%s", (count++ ? ", " : ""), val
}
' "$ipset_file"
echo " }"
} > "$ipnet_file"
if ! nft -c -f "$ipnet_file" >/dev/null 2>&1; then
logger -t xray-prepare_net "$ipnet_dir/$ipset_filename has errors"
fi
done
+9
View File
@@ -0,0 +1,9 @@
{
"dns": {
"tag": "dns-in",
"servers": [
"localhost"
],
"queryStrategy": "UseIPv4"
}
}
+27
View File
@@ -0,0 +1,27 @@
{
"inbounds": [
{
"port": 61219,
"protocol": "dokodemo-door",
"settings": {
"followRedirect": true,
"network": "tcp,udp"
},
"sniffing": {
"destOverride": [
"http",
"tls",
"quic"
],
"enabled": true,
"routeOnly": true
},
"streamSettings": {
"sockopt": {
"tproxy": "tproxy"
}
},
"tag": "tproxy"
}
]
}
+8
View File
@@ -0,0 +1,8 @@
{
"log": {
"access": "/var/log/xray/xray_access.log",
"error": "/var/log/xray/xray_error.log",
"loglevel": "warning",
"dnsLog": true
}
}
+45
View File
@@ -0,0 +1,45 @@
{
"outbounds": [
{
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "",
"port": 443,
"users": [
{
"id": "",
"encryption": "none"
}
]
}
]
},
"streamSettings": {
"network": "xhttp",
"xhttpSettings": {
"path": "/L4o9ap851y/",
"mode": "stream-one"
},
"security": "tls",
"tlsSettings": {
"alpn": [
"h2",
"h3"
]
}
}
},
{
"tag": "direct",
"protocol": "freedom",
"settings": {}
},
{
"tag": "blocked",
"protocol": "blackhole",
"settings": {}
}
]
}
+9
View File
@@ -0,0 +1,9 @@
{
"policy": {
"levels": {
"0": {
"connIdle": 30
}
}
}
}
+12
View File
@@ -0,0 +1,12 @@
{
"routing": {
"domainStrategy": "IPIfNonMatch",
"rules": [
{
"type": "field",
"inboundTag": "tproxy",
"outboundTag": "vless-tls"
}
]
}
}
+33
View File
@@ -0,0 +1,33 @@
#!/bin/sh
/etc/init.d/xray running 2>/dev/null
if [ $? -ne 0 ]; then
exit 0
fi
ipnet_dir="/etc/xray/ipnet"
dnsmasq_dir="/etc/dnsmasq.d"
nft_table="xray"
nft_sets=$(
nft list table ip "$nft_table" \
| grep 'set ' \
| grep '{' \
| awk '{print $2}'
)
for set in $nft_sets; do
nft list set ip $nft_table $set >/dev/null 2>&1 && nft flush set ip $nft_table $set
done
nft list table ip $nft_table >/dev/null 2>&1 && nft delete table ip $nft_table
ip rule show | grep -q "fwmark 0xa lookup 110" && ip rule del fwmark 10 table 110
ip route show table 110 | grep -q "local default" && ip route del local default dev lo table 110
for f in "$dnsmasq_dir"/xray_domain*; do
[ -f "$f" ] || continue
rm "$f"
done
find "$ipnet_dir" -type f -exec rm -f {} \;
service dnsmasq restart >/dev/null 2>&1
+22
View File
@@ -0,0 +1,22 @@
#!/bin/sh
common_dir="/etc/xray/common"
ipnet_dir="/etc/xray/ipnet"
sh $common_dir/check.sh
nft -f $common_dir/nft.conf
sh $common_dir/prepare_domain.sh
sh $common_dir/prepare_net.sh
for ipnet_file in "$ipnet_dir"/*; do
[ -f "$ipnet_file" ] || continue
if ! nft -f "$ipnet_file"; then
logger -t xray-startup "$ipnet_file: apply failed"
fi
done
ip route show table 110 | grep -q "local default" || ip route add local default dev lo table 110
ip rule show | grep -q "fwmark 0xa lookup 110" || ip rule add fwmark 10 table 110
service dnsmasq restart >/dev/null 2>&1
+76
View File
@@ -0,0 +1,76 @@
#!/bin/sh
ipset_dir="/etc/xray/ipset"
dnsmasq_dir="/etc/dnsmasq.d"
common_dir="/etc/xray/common"
sh $common_dir/check.sh
xray_ip="
https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
"
xray_ip_whitelist=""
xray_domain="
https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
"
xray_domain_whitelist=""
download_lists() {
local urls="$1"
local prefix="$2"
local suffix="$3"
[ -z "$(echo "$urls" | tr -d '[:space:]')" ] && return
for url in $urls; do
[ -z "$url" ] && continue
base_name=$(basename "$url")
clean_name="${base_name%.*}"
filename="${prefix}${clean_name}${suffix}.lst"
target_path="$ipset_dir/$filename"
curl -L -s -o "$target_path.tmp" "$url"
if [ $? -eq 0 ]; then
if echo "$prefix" | grep -q "domain"; then
sed -i -E \
-e '/^regexp:/d' \
-e '/^include:/d' \
-e '/^#/d' \
-e '/^$/d' \
-e '/@cn$/d' \
-e '/@ads$/d' \
-e 's/^full://' \
-e 's/[[:space:]].*//' \
-e '/\./!d' \
"$target_path.tmp"
fi
mv "$target_path.tmp" "$target_path"
else
logger -t xray-updater "$url: failed to download"
fi
done
}
find "$ipset_dir" -type f ! -name "*user*" -exec rm -f {} \;
download_lists "$xray_ip" "xray_ip_" ""
download_lists "$xray_ip_whitelist" "xray_ip_" "_whitelist"
download_lists "$xray_domain" "xray_domain_" ""
download_lists "$xray_domain_whitelist" "xray_domain_" "_whitelist"
if /etc/init.d/xray status >/dev/null 2>&1; then
/etc/init.d/xray restart
else
/etc/init.d/xray start
fi