gen_config.lua 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563
  1. #!/usr/bin/lua
  2. local ucursor = require "luci.model.uci".cursor()
  3. local json = require "luci.jsonc"
  4. local server_section = arg[1]
  5. local proto = arg[2]
  6. local local_port = arg[3] or "0"
  7. local socks_port = arg[4] or "0"
  8. local chain = arg[5] or "0"
  9. local chain_local_port = string.split(chain, "/")[2] or "0"
  10. local server = ucursor:get_all("shadowsocksr", server_section)
  11. local outbound_settings = nil
  12. function vmess_vless()
  13. outbound_settings = {
  14. vnext = {
  15. {
  16. address = server.server,
  17. port = tonumber(server.server_port),
  18. users = {
  19. {
  20. id = server.vmess_id,
  21. alterId = (server.v2ray_protocol == "vmess" or not server.v2ray_protocol) and tonumber(server.alter_id) or nil,
  22. security = (server.v2ray_protocol == "vmess" or not server.v2ray_protocol) and server.security or nil,
  23. encryption = (server.v2ray_protocol == "vless") and server.vless_encryption or nil,
  24. flow = ((server.xtls == '1') or (server.tls == '1') or (server.reality == '1')) and server.tls_flow or nil
  25. }
  26. }
  27. }
  28. }
  29. }
  30. end
  31. function trojan_shadowsocks()
  32. outbound_settings = {
  33. servers = {
  34. {
  35. address = server.server,
  36. port = tonumber(server.server_port),
  37. password = server.password,
  38. method = ((server.v2ray_protocol == "shadowsocks") and server.encrypt_method_ss) or nil,
  39. uot = (server.v2ray_protocol == "shadowsocks") and (server.uot == '1') or nil,
  40. ivCheck = (server.v2ray_protocol == "shadowsocks") and (server.ivCheck == '1') or nil,
  41. }
  42. }
  43. }
  44. end
  45. function socks_http()
  46. outbound_settings = {
  47. version = server.socks_ver or nil,
  48. servers = {
  49. {
  50. address = server.server,
  51. port = tonumber(server.server_port),
  52. users = (server.auth_enable == "1") and {
  53. {
  54. user = server.username,
  55. pass = server.password
  56. }
  57. } or nil
  58. }
  59. }
  60. }
  61. end
  62. function wireguard()
  63. outbound_settings = {
  64. secretKey = server.private_key,
  65. address = server.local_addresses,
  66. peers = {
  67. {
  68. publicKey = server.peer_pubkey,
  69. preSharedKey = server.preshared_key,
  70. endpoint = server.server .. ":" .. server.server_port,
  71. keepAlive = tonumber(server.keepaliveperiod),
  72. allowedIPs = (server.allowedips) or nil,
  73. }
  74. },
  75. kernelMode = (server.kernelmode == "1") and true or false,
  76. reserved = {server.reserved} or nil,
  77. mtu = tonumber(server.mtu)
  78. }
  79. end
  80. local outbound = {}
  81. function outbound:new(o)
  82. o = o or {}
  83. setmetatable(o, self)
  84. self.__index = self
  85. return o
  86. end
  87. function outbound:handleIndex(index)
  88. local switch = {
  89. vmess = function()
  90. vmess_vless()
  91. end,
  92. vless = function()
  93. vmess_vless()
  94. end,
  95. trojan = function()
  96. trojan_shadowsocks()
  97. end,
  98. shadowsocks = function()
  99. trojan_shadowsocks()
  100. end,
  101. socks = function()
  102. socks_http()
  103. end,
  104. http = function()
  105. socks_http()
  106. end,
  107. wireguard = function()
  108. wireguard()
  109. end
  110. }
  111. if switch[index] then
  112. switch[index]()
  113. end
  114. end
  115. local settings = outbound:new()
  116. settings:handleIndex(server.v2ray_protocol)
  117. local Xray = {
  118. log = {
  119. -- error = "/var/ssrplus.log",
  120. loglevel = "warning"
  121. },
  122. -- 传入连接
  123. inbound = (local_port ~= "0") and {
  124. -- listening
  125. port = tonumber(local_port),
  126. protocol = "dokodemo-door",
  127. settings = {network = proto, followRedirect = true},
  128. sniffing = {
  129. enabled = true,
  130. destOverride = {"http", "tls", "quic"},
  131. domainsExcluded = {
  132. "courier.push.apple.com",
  133. "rbsxbxp-mim.vivox.com",
  134. "rbsxbxp.www.vivox.com",
  135. "rbsxbxp-ws.vivox.com",
  136. "rbspsxp.www.vivox.com",
  137. "rbspsxp-mim.vivox.com",
  138. "rbspsxp-ws.vivox.com",
  139. "rbswxp.www.vivox.com",
  140. "rbswxp-mim.vivox.com",
  141. "disp-rbspsp-5-1.vivox.com",
  142. "disp-rbsxbp-5-1.vivox.com",
  143. "proxy.rbsxbp.vivox.com",
  144. "proxy.rbspsp.vivox.com",
  145. "proxy.rbswp.vivox.com",
  146. "rbswp.vivox.com",
  147. "rbsxbp.vivox.com",
  148. "rbspsp.vivox.com",
  149. "rbspsp.www.vivox.com",
  150. "rbswp.www.vivox.com",
  151. "rbsxbp.www.vivox.com",
  152. "rbsxbxp.vivox.com",
  153. "rbspsxp.vivox.com",
  154. "rbswxp.vivox.com",
  155. "Mijia Cloud",
  156. "dlg.io.mi.com"
  157. }
  158. }
  159. } or nil,
  160. -- 开启 socks 代理
  161. inboundDetour = (proto:find("tcp") and socks_port ~= "0") and {
  162. {
  163. -- socks
  164. protocol = "socks",
  165. port = tonumber(socks_port),
  166. settings = {auth = "noauth", udp = true}
  167. }
  168. } or nil,
  169. -- 传出连接
  170. outbound = {
  171. protocol = server.v2ray_protocol,
  172. settings = outbound_settings,
  173. -- 底层传输配置
  174. streamSettings = (server.v2ray_protocol ~= "wireguard") and {
  175. network = server.transport or "tcp",
  176. security = (server.xtls == '1') and "xtls" or (server.tls == '1') and "tls" or (server.reality == '1') and "reality" or nil,
  177. tlsSettings = (server.tls == '1') and (server.tls_host or server.fingerprint) and {
  178. -- tls
  179. alpn = server.tls_alpn,
  180. fingerprint = server.fingerprint,
  181. allowInsecure = (server.insecure == "1"),
  182. serverName = server.tls_host,
  183. certificates = server.certificate and {
  184. usage = "verify",
  185. certificateFile = server.certpath
  186. } or nil,
  187. } or nil,
  188. xtlsSettings = (server.xtls == '1') and server.tls_host and {
  189. -- xtls
  190. allowInsecure = (server.insecure == "1") and true or nil,
  191. serverName = server.tls_host,
  192. minVersion = "1.3"
  193. } or nil,
  194. realitySettings = (server.reality == '1') and {
  195. publicKey = server.reality_publickey,
  196. shortId = server.reality_shortid,
  197. spiderX = server.reality_spiderx,
  198. fingerprint = server.fingerprint,
  199. serverName = server.tls_host
  200. } or nil,
  201. tcpSettings = (server.transport == "tcp" and server.tcp_guise == "http") and {
  202. -- tcp
  203. header = {
  204. type = server.tcp_guise,
  205. request = {
  206. -- request
  207. path = {server.http_path} or {"/"},
  208. headers = {Host = {server.http_host} or {}}
  209. }
  210. }
  211. } or nil,
  212. kcpSettings = (server.transport == "kcp") and {
  213. -- kcp
  214. mtu = tonumber(server.mtu),
  215. tti = tonumber(server.tti),
  216. uplinkCapacity = tonumber(server.uplink_capacity),
  217. downlinkCapacity = tonumber(server.downlink_capacity),
  218. congestion = (server.congestion == "1") and true or false,
  219. readBufferSize = tonumber(server.read_buffer_size),
  220. writeBufferSize = tonumber(server.write_buffer_size),
  221. header = {type = server.kcp_guise},
  222. seed = server.seed or nil
  223. } or nil,
  224. wsSettings = (server.transport == "ws") and (server.ws_path or server.ws_host or server.tls_host) and {
  225. -- ws
  226. headers = (server.ws_host or server.tls_host) and {
  227. -- headers
  228. Host = server.ws_host or server.tls_host
  229. } or nil,
  230. path = server.ws_path,
  231. maxEarlyData = tonumber(server.ws_ed) or nil,
  232. earlyDataHeaderName = server.ws_ed_header or nil
  233. } or nil,
  234. httpupgradeSettings = (server.transport == "httpupgrade") and {
  235. -- httpupgrade
  236. host = (server.httpupgrade_host or server.tls_host) or nil,
  237. path = server.httpupgrade_path or ""
  238. } or nil,
  239. splithttpSettings = (server.transport == "splithttp") and {
  240. -- splithttp
  241. host = (server.splithttp_host or server.tls_host) or nil,
  242. path = server.splithttp_path or ""
  243. } or nil,
  244. httpSettings = (server.transport == "h2") and {
  245. -- h2
  246. path = server.h2_path or "",
  247. host = {server.h2_host} or nil,
  248. read_idle_timeout = tonumber(server.read_idle_timeout) or nil,
  249. health_check_timeout = tonumber(server.health_check_timeout) or nil
  250. } or nil,
  251. quicSettings = (server.transport == "quic") and {
  252. -- quic
  253. security = server.quic_security,
  254. key = server.quic_key,
  255. header = {type = server.quic_guise}
  256. } or nil,
  257. grpcSettings = (server.transport == "grpc") and {
  258. -- grpc
  259. serviceName = server.serviceName or "",
  260. multiMode = (server.grpc_mode == "multi") and true or false,
  261. idle_timeout = tonumber(server.idle_timeout) or nil,
  262. health_check_timeout = tonumber(server.health_check_timeout) or nil,
  263. permit_without_stream = (server.permit_without_stream == "1") and true or nil,
  264. initial_windows_size = tonumber(server.initial_windows_size) or nil
  265. } or nil,
  266. sockopt = {
  267. tcpMptcp = (server.mptcp == "1") and true or false, -- MPTCP
  268. tcpNoDelay = (server.mptcp == "1") and true or false, -- MPTCP
  269. tcpcongestion = server.custom_tcpcongestion -- 连接服务器节点的 TCP 拥塞控制算法
  270. }
  271. } or nil,
  272. mux = (server.v2ray_protocol ~= "wireguard") and {
  273. -- mux
  274. enabled = (server.mux == "1") and true or false, -- Mux
  275. concurrency = tonumber(server.concurrency), -- TCP 最大并发连接数
  276. xudpConcurrency = tonumber(server.xudpConcurrency), -- UDP 最大并发连接数
  277. xudpProxyUDP443 = server.xudpProxyUDP443 -- 对被代理的 UDP/443 流量处理方式
  278. } or nil
  279. }
  280. }
  281. local cipher = "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA"
  282. local cipher13 = "TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384"
  283. local trojan = {
  284. log_level = 3,
  285. run_type = (proto == "nat" or proto == "tcp") and "nat" or "client",
  286. local_addr = "0.0.0.0",
  287. local_port = tonumber(local_port),
  288. remote_addr = server.server,
  289. remote_port = tonumber(server.server_port),
  290. udp_timeout = 60,
  291. -- 传入连接
  292. password = {server.password},
  293. -- 传出连接
  294. ssl = {
  295. verify = (server.insecure == "0") and true or false,
  296. verify_hostname = (server.tls == "1") and true or false,
  297. cert = (server.certificate) and server.certpath or nil,
  298. cipher = cipher,
  299. cipher_tls13 = cipher13,
  300. sni = server.tls_host,
  301. alpn = server.tls_alpn or {"h2", "http/1.1"},
  302. curve = "",
  303. reuse_session = true,
  304. session_ticket = (server.tls_sessionTicket == "1") and true or false
  305. },
  306. udp_timeout = 60,
  307. tcp = {
  308. -- tcp
  309. no_delay = true,
  310. keep_alive = true,
  311. reuse_port = true,
  312. fast_open = (server.fast_open == "1") and true or false,
  313. fast_open_qlen = 20
  314. }
  315. }
  316. local naiveproxy = {
  317. proxy = (server.username and server.password and server.server and server.server_port) and "https://" .. server.username .. ":" .. server.password .. "@" .. server.server .. ":" .. server.server_port,
  318. listen = (proto == "redir") and "redir" .. "://0.0.0.0:" .. tonumber(local_port) or "socks" .. "://0.0.0.0:" .. tonumber(local_port),
  319. ["insecure-concurrency"] = tonumber(server.concurrency) or 1
  320. }
  321. local ss = {
  322. server = (server.kcp_enable == "1") and "127.0.0.1" or server.server,
  323. server_port = tonumber(server.server_port),
  324. local_address = "0.0.0.0",
  325. local_port = tonumber(local_port),
  326. mode = (proto == "tcp,udp") and "tcp_and_udp" or proto .. "_only",
  327. password = server.password,
  328. method = server.encrypt_method_ss,
  329. timeout = tonumber(server.timeout),
  330. fast_open = (server.fast_open == "1") and true or false,
  331. reuse_port = true
  332. }
  333. local hysteria = {
  334. server = (server.server_port and (server.port_range and (server.server .. ":" .. server.server_port .. "," .. server.port_range) or server.server .. ":" .. server.server_port) or (server.port_range and server.server .. ":" .. server.port_range or server.server .. ":443")),
  335. bandwidth = (server.uplink_capacity or server.downlink_capacity) and {
  336. up = tonumber(server.uplink_capacity) and tonumber(server.uplink_capacity) .. " mbps" or nil,
  337. down = tonumber(server.downlink_capacity) and tonumber(server.downlink_capacity) .. " mbps" or nil
  338. },
  339. socks5 = (proto:find("tcp") and tonumber(socks_port) and tonumber(socks_port) ~= 0) and {
  340. listen = "0.0.0.0:" .. tonumber(socks_port),
  341. disable_udp = false
  342. } or nil,
  343. transport = (server.transport_protocol) and {
  344. type = (server.transport_protocol) or udp,
  345. udp = (server.port_range and (server.hopinterval) and {
  346. hopInterval = (server.port_range and (tonumber(server.hopinterval) .. "s") or nil)
  347. } or nil)
  348. } or nil,
  349. --[[
  350. tcpTProxy = (proto:find("tcp") and local_port ~= "0") and {
  351. listen = "0.0.0.0:" .. tonumber(local_port)
  352. } or nil,
  353. ]]--
  354. tcpRedirect = (proto:find("tcp") and local_port ~= "0") and {
  355. listen = "0.0.0.0:" .. tonumber(local_port)
  356. } or nil,
  357. udpTProxy = (proto:find("udp") and local_port ~= "0") and {
  358. listen = "0.0.0.0:" .. tonumber(local_port)
  359. } or nil,
  360. obfs = (server.flag_obfs == "1") and {
  361. type = server.obfs_type,
  362. salamander = { password = server.salamander }
  363. } or nil,
  364. quic = (server.flag_quicparam == "1" ) and {
  365. initStreamReceiveWindow = (server.initstreamreceivewindow and server.initstreamreceivewindow or nil),
  366. maxStreamReceiveWindow = (server.maxstreamseceivewindow and server.maxstreamseceivewindow or nil),
  367. initConnReceiveWindow = (server.initconnreceivewindow and server.initconnreceivewindow or nil),
  368. maxConnReceiveWindow = (server.maxconnreceivewindow and server.maxconnreceivewindow or nil),
  369. maxIdleTimeout = (tonumber(server.maxidletimeout) and tonumber(server.maxidletimeout) .. "s" or nil),
  370. keepAlivePeriod = (tonumber(server.keepaliveperiod) and tonumber(server.keepaliveperiod) .. "s" or nil),
  371. disablePathMTUDiscovery = (server.disablepathmtudiscovery == "1") and true or false
  372. } or nil,
  373. auth = server.hy2_auth,
  374. tls = (server.tls_host) and {
  375. sni = server.tls_host,
  376. --alpn = server.tls_alpn or nil,
  377. insecure = (server.insecure == "1") and true or false,
  378. pinSHA256 = (server.insecure == "1") and server.pinsha256 or nil
  379. } or {
  380. sni = server.server,
  381. insecure = (server.insecure == "1") and true or false
  382. },
  383. fast_open = (server.fast_open == "1") and true or false,
  384. lazy = (server.lazy_mode == "1") and true or false
  385. }
  386. local shadowtls = {
  387. client = {
  388. server_addr = server.server_port and server.server .. ":" .. server.server_port or nil,
  389. listen = "127.0.0.1:" .. tonumber(local_port),
  390. tls_names = server.shadowtls_sni,
  391. password = server.password
  392. },
  393. v3 = (server.shadowtls_protocol == "v3") and true or false,
  394. disable_nodelay = (server.disable_nodelay == "1") and true or false,
  395. fastopen = (server.fastopen == "1") and true or false,
  396. strict = (server.strict == "1") and true or false
  397. }
  398. local chain_sslocal = {
  399. locals = local_port ~= "0" and {
  400. {
  401. local_address = "0.0.0.0",
  402. local_port = (chain_local_port == "0" and tonumber(server.local_port) or tonumber(chain_local_port)),
  403. mode = (proto:find("tcp,udp") and "tcp_and_udp") or proto .. "_only",
  404. protocol = "redir",
  405. tcp_redir = "redirect",
  406. --tcp_redir = "tproxy",
  407. udp_redir = "tproxy"
  408. },
  409. socks_port ~= "0" and {
  410. protocol = "socks",
  411. local_address = "0.0.0.0",
  412. local_port = tonumber(socks_port)
  413. } or nil
  414. } or {{
  415. protocol = "socks",
  416. local_address = "0.0.0.0",
  417. ocal_port = tonumber(socks_port)
  418. }},
  419. servers = {
  420. {
  421. server = "127.0.0.1",
  422. server_port = (tonumber(local_port) == 0 and tonumber(chain_local_port) or tonumber(local_port)),
  423. method = server.sslocal_method,
  424. password = server.sslocal_password
  425. }
  426. }
  427. }
  428. local chain_vmess = {
  429. inbounds = (local_port ~= "0") and {
  430. {
  431. port = (chain_local_port == "0" and tonumber(server.local_port) or tonumber(chain_local_port)),
  432. protocol = "dokodemo-door",
  433. settings = {
  434. network = proto,
  435. followRedirect = true
  436. },
  437. streamSettings = {
  438. sockopt = {tproxy = "redirect"}
  439. },
  440. sniffing = {
  441. enable = true,
  442. destOverride = {"http","tls"}
  443. }
  444. },
  445. (proto:find("tcp") and socks_port ~= "0") and {
  446. protocol = "socks",
  447. port = tonumber(socks_port)
  448. } or nil
  449. } or { protocol = "socks",port = tonumber(socks_port) },
  450. outbound = {
  451. protocol = "vmess",
  452. settings = {
  453. vnext = {{
  454. address = "127.0.0.1",
  455. port = (tonumber(local_port) == 0 and tonumber(chain_local_port) or tonumber(local_port)),
  456. users = {{
  457. id = (server.vmess_uuid),
  458. security = server.vmess_method,
  459. level = 0
  460. }}
  461. }}
  462. }
  463. }
  464. }
  465. local tuic = {
  466. relay = {
  467. server = server.server_port and server.server .. ":" .. server.server_port,
  468. ip = server.tuic_ip,
  469. uuid = server.tuic_uuid,
  470. password = server.tuic_passwd,
  471. certificates = server.certificate and { server.certpath } or nil,
  472. udp_relay_mode = server.udp_relay_mode,
  473. congestion_control = server.congestion_control,
  474. heartbeat = server.heartbeat and server.heartbeat .. "s" or nil,
  475. timeout = server.timeout and server.timeout .. "s" or nil,
  476. gc_interval = server.gc_interval and server.gc_interval .. "s" or nil,
  477. gc_lifetime = server.gc_lifetime and server.gc_lifetime .. "s" or nil,
  478. alpn = server.tls_alpn,
  479. disable_sni = (server.disable_sni == "1") and true or false,
  480. zero_rtt_handshake = (server.zero_rtt_handshake == "1") and true or false,
  481. send_window = tonumber(server.send_window),
  482. receive_window = tonumber(server.receive_window)
  483. },
  484. ["local"] = {
  485. server = tonumber(socks_port) and "[::]:" .. (socks_port == "0" and local_port or tonumber(socks_port)),
  486. dual_stack = (server.tuic_dual_stack == "1") and true or nil,
  487. max_packet_size = tonumber(server.tuic_max_package_size)
  488. }
  489. }
  490. local config = {}
  491. function config:new(o)
  492. o = o or {}
  493. setmetatable(o, self)
  494. self.__index = self
  495. return o
  496. end
  497. function config:handleIndex(index)
  498. local switch = {
  499. ss = function()
  500. ss.protocol = socks_port
  501. if server.plugin and server.plugin ~= "none" then
  502. ss.plugin = server.plugin
  503. ss.plugin_opts = server.plugin_opts or nil
  504. end
  505. print(json.stringify(ss, 1))
  506. end,
  507. ssr = function()
  508. ss.protocol = server.protocol
  509. ss.protocol_param = server.protocol_param
  510. ss.method = server.encrypt_method
  511. ss.obfs = server.obfs
  512. ss.obfs_param = server.obfs_param
  513. print(json.stringify(ss, 1))
  514. end,
  515. v2ray = function()
  516. print(json.stringify(Xray, 1))
  517. end,
  518. trojan = function()
  519. print(json.stringify(trojan, 1))
  520. end,
  521. naiveproxy = function()
  522. print(json.stringify(naiveproxy, 1))
  523. end,
  524. hysteria = function()
  525. print(json.stringify(hysteria, 1))
  526. end,
  527. shadowtls = function()
  528. local chain_switch = {
  529. sslocal = function()
  530. if (chain:find("chain")) then
  531. print(json.stringify(chain_sslocal, 1))
  532. else
  533. print(json.stringify(shadowtls, 1))
  534. end
  535. end,
  536. vmess = function()
  537. if (chain:find("chain")) then
  538. print(json.stringify(chain_vmess, 1))
  539. else
  540. print(json.stringify(shadowtls, 1))
  541. end
  542. end
  543. }
  544. local ChainType = server.chain_type
  545. if chain_switch[ChainType] then
  546. chain_switch[ChainType]()
  547. end
  548. end,
  549. tuic = function()
  550. print(json.stringify(tuic, 1))
  551. end
  552. }
  553. if switch[index] then
  554. switch[index]()
  555. end
  556. end
  557. local f = config:new()
  558. f:handleIndex(server.type)