Compare commits

..

17 Commits

Author SHA1 Message Date
mercury 11e34d8c4e unversary path for vpnbot.service 2024-03-06 15:15:45 +04:00
mercury 3e3684eb34 fix service for systemd 2024-03-06 14:46:02 +04:00
mercury 7ee47db8e2 fix short link type 2024-03-06 11:52:09 +04:00
mercury b390fe7dd8 update version 2024-03-06 04:08:45 +04:00
mercury fe0414cc59 fix export ocserv users 2024-03-06 04:03:30 +04:00
mercury 48a1eba67e fix ocserv 2024-03-06 03:44:52 +04:00
mercury 714cff7d76 fix lib for short link 2024-03-06 02:10:11 +04:00
mercury 0e8bab5c4c fix service script 2024-03-06 01:45:31 +04:00
mercury 387e6e4986 short link for amnezia 2024-03-06 01:35:40 +04:00
mercury 6a7af1c30f fix import wg1 2024-03-05 00:14:36 +04:00
mercury 2a17b4f1f3 update version 2024-03-04 23:30:46 +04:00
mercury d005ccc919 fix start wg1 2024-03-04 23:26:09 +04:00
mercury 5df89e7f89 syncport fix 2024-03-04 16:51:18 +04:00
mercury f6d72800cb white ip 2024-03-04 16:38:37 +04:00
mercury 4ff1929a22 improve makefile 2024-03-03 19:53:52 +04:00
mercury 46d54ffeee fix gitignore 2024-03-03 19:45:57 +04:00
mercury 20cde272dd update self 2024-03-03 19:29:21 +04:00
16 changed files with 308 additions and 65 deletions
+2
View File
@@ -16,3 +16,5 @@
.vscode/
.idea/
mirror/.env
update/*
!update/update.sh
+14
View File
@@ -0,0 +1,14 @@
import sys
from PyQt5.QtCore import *
def enc(s):
ba = qCompress(QByteArray(s.encode()))
ba = ba.toBase64(QByteArray.Base64Option.Base64UrlEncoding | QByteArray.Base64Option.OmitTrailingEquals)
print('vpn://' + str(ba, 'utf-8'))
s = ''
for line in sys.stdin:
s += line
s = s.strip()
enc(s)
+108 -19
View File
@@ -4,6 +4,7 @@ class Bot
{
public $input;
public $adguard;
public $update;
public function __construct($key, $i18n)
{
@@ -19,6 +20,7 @@ class Bot
$this->dns = '1.1.1.1, 8.8.8.8';
$this->limit = $this->getPacConf()['limitpage'] ?: 5;
$this->adguard = '/config/AdGuardHome.yaml';
$this->update = '/update/json';
}
public function input()
@@ -131,6 +133,9 @@ class Bot
case preg_match('~^/mtproto$~', $this->input['callback'], $m):
$this->mtproto();
break;
case preg_match('~^/updatebot$~', $this->input['callback'], $m):
$this->updatebot();
break;
case preg_match('~^/getMirror$~', $this->input['callback'], $m):
$this->getMirror();
break;
@@ -1000,15 +1005,20 @@ class Bot
'mtproto' => file_get_contents('/config/mtprotosecret'),
'xray' => json_decode(file_get_contents('/config/xray.json'), true),
'oc' => file_get_contents('/config/ocserv.conf'),
'ocu' => file_get_contents('/config/ocserv.passwd'),
];
return json_encode($conf, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
}
public function exportManual()
public function exportManual($file = false)
{
$json = $this->export();
if (!empty($file)) {
file_put_contents($file, $json);
}
$bot = $this->request('getMyName', [])['result']['name'];
return $this->upload("{$bot}_export_" . date('d_m_Y_H_i') . '.json', $this->export());
return $this->upload("{$bot}_export_" . date('d_m_Y_H_i') . '.json', $json);
}
public function import()
@@ -1027,10 +1037,14 @@ class Bot
];
}
public function importFile()
public function importFile($file = false)
{
$r = $this->request('getFile', ['file_id' => $this->input['file_id']]);
$json = json_decode(file_get_contents($this->file . $r['result']['file_path']), true);
if (!empty($file)) {
$json = json_decode(file_get_contents($file), true);
} else {
$r = $this->request('getFile', ['file_id' => $this->input['file_id']]);
$json = json_decode(file_get_contents($this->file . $r['result']['file_path']), true);
}
if (empty($json) || !is_array($json)) {
$this->answer($this->input['callback_id'], 'error', true);
} else {
@@ -1048,6 +1062,9 @@ class Bot
if ($this->getPacConf()['amnezia'] != $json['pac']['amnezia']) {
$switch_amnezia = 1;
}
if ($this->getPacConf()['wg1_amnezia'] != $json['pac']['wg1_amnezia']) {
$switch_wg1amnezia = 1;
}
$this->setPacConf($json['pac']);
$out[] = 'update naiveproxy';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
@@ -1069,7 +1086,7 @@ class Bot
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->wg = 1;
$this->saveClients($json['wg1']['clients']);
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_amnezia);
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_wg1amnezia);
$this->iptablesWG();
}
// ad
@@ -1113,6 +1130,7 @@ class Bot
if (!empty($json['oc'])) {
$out[] = 'update ocserv';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
file_put_contents('/config/ocserv.passwd', $json['ocu']);
$this->restartOcserv($json['oc']);
}
if (!empty($json['pac']['domain'])) {
@@ -1145,8 +1163,12 @@ class Bot
$out[] = "end import";
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->language = $this->getPacConf()['language'] ?: 'en';
$this->limit = $this->getPacConf()['limitpage'] ?: 5;
sleep(3);
$this->menu();
if (empty($file)) {
$this->menu();
}
}
}
@@ -2210,7 +2232,7 @@ DNS-over-HTTPS with IP:
if (!empty($v['# PublicKey'])) {
$conf['peers'][$k]['online'] = 'off';
} else {
$conf['peers'][$k]['status'] = $this->getStatusPeer($v['PublicKey'], $status['peers']);
$conf['peers'][$k]['status'] = $status ? $this->getStatusPeer($v['PublicKey'], $status['peers']) : 'error';
$conf['peers'][$k]['online'] = preg_match('~^(\d+ seconds|[12] minute)~', $conf['peers'][$k]['status']['latest handshake']) ? 'online' : '';
}
}
@@ -2516,14 +2538,60 @@ DNS-over-HTTPS with IP:
$this->menu('client', "{$k}_$page");
}
public function getAmneziaShortLink($client)
{
$dns = explode(',', $client['interface']['DNS']);
$c = json_encode([
"containers" => [
[
"awg" => [
"isThirdPartyConfig" => True,
"last_config" => json_encode([
"H1" => "{$client['interface']['H1']}",
"H2" => "{$client['interface']['H2']}",
"H3" => "{$client['interface']['H3']}",
"H4" => "{$client['interface']['H4']}",
"Jc" => "{$client['interface']['Jc']}",
"Jmax" => "{$client['interface']['Jmax']}",
"Jmin" => "{$client['interface']['Jmin']}",
"S1" => "{$client['interface']['S1']}",
"S2" => "{$client['interface']['S2']}",
"client_ip" => explode('/', $client['interface']['Address'])[0],
"client_priv_key" => $client['interface']['PrivateKey'],
"client_pub_key" => "0",
"config" => $this->createConfig($client),
"hostName" => $this->ip,
"port" => (int) getenv('WG1PORT'),
"psk_key" => $client['peers'][0]['PresharedKey'],
"server_pub_key" => $client['peers'][0]['PublicKey']
]),
"port" => (int) getenv('WG1PORT'),
"transport_proto" => "udp"
],
"container" => "amnezia-awg"
]
],
"defaultContainer" => "amnezia-awg",
"description" => $client['interface']['## name'],
"dns1" => $dns[0],
"dns2" => $dns[1] ?: '',
"hostName" => $this->ip
]);
exec("echo '$c' | python amnezia.py", $o);
return $o[0];
}
public function getClient($client, $page)
{
$clients = $this->readClients();
if ($clients) {
$name = $this->getName($clients[$client]['interface']);
$conf = $this->createConfig($clients[$client]);
if ($this->getWGType() == 'awg') {
$sl = $this->getAmneziaShortLink($clients[$client]);
}
return [
'text' => "<code>$conf</code>\n\n<b>$name</b> ({$this->getTitleWG()})",
'text' => "<pre>$conf</pre>\n\n<code>$sl</code>\n\n<b>$name</b> ({$this->getTitleWG()})",
'data' => [
[
[
@@ -2942,7 +3010,7 @@ DNS-over-HTTPS with IP:
{
$menu = [
'main' => [
'text' => $this->i18n('menu'),
'text' => 'v' . getenv('VER'),
'data' => [
[
[
@@ -3026,7 +3094,7 @@ DNS-over-HTTPS with IP:
'lang' => $type == 'lang' ? $this->menuLang() : false,
'oc' => $type == 'oc' ? $this->ocMenu() : false,
'naive' => $type == 'naive' ? $this->naiveMenu() : false,
'mirror' => $type == 'mirror' ? $this->mirrorMenu() : false,
'mirror' => $type == 'mirror' ? $this->mirrorMenu() : false,
];
$text = $menu[$type ?: 'main' ]['text'];
@@ -3478,6 +3546,15 @@ DNS-over-HTTPS with IP:
return openssl_x509_parse($c)["validTo_time_t"] ?: false;
}
public function updatebot()
{
$this->exportManual($this->update);
$r = $this->send($this->input['from'], 'update...');
file_put_contents('/update/reload_message', "{$this->input['from']}:{$r['result']['message_id']}");
file_put_contents('/update/pipe', '1');
$this->delete($this->input['from'], $this->input['message_id']);
}
public function configMenu()
{
$conf = $this->getPacConf();
@@ -3588,6 +3665,12 @@ DNS-over-HTTPS with IP:
'callback_data' => "/debug",
],
];
$data[] = [
[
'text' => $this->i18n('update bot'),
'callback_data' => "/updatebot",
],
];
$data[] = [
[
'text' => $this->i18n('back'),
@@ -3797,7 +3880,6 @@ DNS-over-HTTPS with IP:
public function readStatus()
{
// $this->sd([$this->getWGType(), $this->getInstanceWG()]);
$r = $this->ssh($this->getWGType(), $this->getInstanceWG());
$r = explode(PHP_EOL, $r);
$r = array_filter($r);
@@ -3970,14 +4052,21 @@ DNS-over-HTTPS with IP:
public function syncPortClients()
{
$endpoint = $this->ip . ':' . getenv('WGPORT');
$clients = $this->readClients();
foreach ($clients as $k => $v) {
foreach ($v['peers'] as $i => $j) {
$clients[$k]['peers'][$i]['Endpoint'] = $endpoint;
$endpoint = [
$this->ip . ':' . getenv('WGPORT'),
$this->ip . ':' . getenv('WG1PORT'),
];
for ($i=0; $i < 2; $i++) {
$this->wg = $i;
$clients = $this->readClients();
foreach ($clients as $k => $v) {
foreach ($v['peers'] as $i => $j) {
$clients[$k]['peers'][$i]['Endpoint'] = $endpoint[$i];
}
}
$this->saveClients($clients);
}
$this->saveClients($clients);
unset($this->wg);
}
public function saveClients(array $clients)
@@ -4072,7 +4161,7 @@ DNS-over-HTTPS with IP:
if (!empty($r['result']) && $r['result'] == true) {
file_put_contents('/start', 1);
} else {
die('set webhook fail');
die("set webhook fail\n");
}
}
+5 -1
View File
@@ -243,7 +243,7 @@ $i = [
],
'backup' => [
'en' => 'auto backup',
'ru' => 'бэкап',
'ru' => 'автобэкап',
],
'logs' => [
'en' => 'logs',
@@ -301,4 +301,8 @@ $i = [
'en' => 'download',
'ru' => 'скачать',
],
'update bot' => [
'en' => 'update bot',
'ru' => 'обновить бота',
],
];
-6
View File
@@ -11,9 +11,3 @@ $bot = new Bot($c['key'], $i);
$bot->setwebhook();
$bot->setcommands();
$bot->syncPortClients();
if (!empty($c['admin'])) {
$ip = getenv('IP');
foreach ($c['admin'] as $k => $v) {
$bot->send($v, "start $ip");
}
}
+38
View File
@@ -0,0 +1,38 @@
<?php
require __DIR__ . '/timezone.php';
// require __DIR__ . '/debug.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
if (!empty($c['admin'])) {
$ip = getenv('IP');
$rm = explode(':', trim(file_get_contents('/update/reload_message')));
$m = file_get_contents('/update/message');
foreach ($c['admin'] as $k => $v) {
$r = $bot->send($v, "start $ip");
$bot->input['chat'] = $v;
$bot->input['message_id'] = $r['result']['message_id'];
if (file_exists($bot->update)) {
if (!empty($m)) {
$bot->send($v, "<pre>$m</pre>", $v == $rm[0] ? $rm[1] : 0);
}
$r = $bot->send($v, "import settings");
$bot->input['chat'] = $v;
$bot->input['message_id'] = $r['result']['message_id'];
$bot->input['callback_id'] = $r['result']['message_id'];
if (empty($flag)) {
$bot->importFile($bot->update);
unlink($bot->update);
$flag = true;
}
}
}
}
file_put_contents('/update/message', '');
file_put_contents('/update/reload_message', '');
$bot->menu();
+53 -2
View File
@@ -83,7 +83,7 @@ services:
ipv4_address: 10.10.0.2
logging: *default-logging
php:
image: mercurykd/vpnbot-php:1.1
image: mercurykd/vpnbot-php:1.2
build:
dockerfile: dockerfile/php.dockerfile
args:
@@ -101,6 +101,7 @@ services:
- ./version:/version
- ./mirror:/mirror
- ./.env:/mirror/.env
- ./update:/update
environment:
TZ: ${TZ}
IP: ${IP}
@@ -110,6 +111,7 @@ services:
WG1PORT: ${WG1PORT}
SSPORT: ${SSPORT}
TGPORT: ${TGPORT}
VER: ${VER}
hostname: php
container_name: php-${VER}
restart: unless-stopped
@@ -127,6 +129,55 @@ services:
interval: 5s
timeout: 5s
retries: 5
service:
image: mercurykd/vpnbot-php:1.1
build:
dockerfile: dockerfile/php.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/php.ini:/etc/php81/php.ini
- ./config/:/config/
- ./certs/:/certs/
- ./ssh:/ssh
- ./app:/app
- ./logs/:/logs/
- ./update:/update
- ./scripts/start_service.sh:/start_service.sh
environment:
TZ: ${TZ}
IP: ${IP}
ADDRESS: ${WGADDRESS}
WGPORT: ${WGPORT}
WG1ADDRESS: ${WG1ADDRESS}
WG1PORT: ${WG1PORT}
SSPORT: ${SSPORT}
TGPORT: ${TGPORT}
VER: ${VER}
hostname: service
container_name: service-${VER}
# restart: unless-stopped
stop_grace_period: 1s
command: ["/bin/sh", "/start_service.sh"]
working_dir: /app
networks:
default:
ipv4_address: 10.10.0.15
logging: *default-logging
depends_on:
- up
- ng
- php
- proxy
- wg
- wg1
- ad
- ss
- tg
- xr
- oc
- np
proxy:
image: mercurykd/vpnbot-ss:1.1
build:
@@ -345,7 +396,7 @@ services:
ipv4_address: 10.10.0.9
logging: *default-logging
oc:
image: mercurykd/vpnbot-oc:1.1
image: mercurykd/vpnbot-oc:1.2
build:
dockerfile: dockerfile/ocserv.dockerfile
args:
+10 -9
View File
@@ -1,21 +1,22 @@
ARG image
FROM $image
RUN apk add --update openssh iptables \
&& apk add --no-cache --virtual .build-deps \
curl \
g++ \
RUN apk add --update openssh \
iptables \
gnutls-dev \
gpgme \
libev-dev \
libnl3-dev \
libseccomp-dev \
linux-headers \
linux-pam-dev \
lz4-dev \
libseccomp-dev \
&& apk add --no-cache --virtual .build-deps \
xz \
linux-headers \
libnl3-dev \
g++ \
gpgme \
curl \
make \
readline-dev \
tar \
xz \
autoconf \
automake \
gperf \
+1
View File
@@ -19,6 +19,7 @@ RUN apk add --no-cache --update php81 \
openssh \
openssl \
curl \
py3-qt5 \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
&& mv linux-amd64/dnslookup /usr/bin \
+5 -9
View File
@@ -1,8 +1,10 @@
b:
docker compose build
u: # запуск контейнеров
IP=$(shell ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$$|\1|p' | awk '{print $1}' | head -1) VER=$(shell git describe --tags) docker compose up -d --force-recreate
bash ./update/update.sh &
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose up -d --force-recreate
d: # остановка контейнеров
-kill -9 $(shell cat ./update/update_pid) > /dev/null
docker compose down --remove-orphans
dv: # остановка контейнеров
docker compose down -v
@@ -46,17 +48,11 @@ cleanf:
cleanall:
docker image prune -a -f
docker builder prune -a -f
p:
git stash
git pull
git stash pop stash@{0}
update: p r
cn:
docker compose exec ng nginx -t
push:
docker compose push
s:
git status -su
c:
git add config/
git checkout .
git checkout .
git reset
+2 -1
View File
@@ -1,3 +1,4 @@
cp scripts/vpnbot.service /etc/systemd/system/vpnbot.service
path=`pwd`
sed "s|path|$path|g" "$path/scripts/vpnbot.service" > /etc/systemd/system/vpnbot.service
systemctl daemon-reload
systemctl enable vpnbot
+1
View File
@@ -0,0 +1 @@
php service.php
+33 -14
View File
@@ -1,3 +1,7 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
then
@@ -13,21 +17,36 @@ fi
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE
ln -s /etc/wireguard/wg0.conf /etc/amnezia/amneziawg/wg0.conf
if [ $(cat /pac.json | jq .amnezia) -eq 1 ]
if [ "$HOSTNAME" = "wireguard1" ]
then
awg-quick up wg0
if [ $(cat /pac.json | jq .wg1_amnezia) -eq 1 ]
then
awg-quick up wg0
else
wg-quick up wg0
fi
if [ $(cat /pac.json | jq .wg1_blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .wg1_exchange) -eq 1 ]
then
sh /block_exchange.sh
fi
else
wg-quick up wg0
fi
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
if [ $(cat /pac.json | jq .blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .exchange) -eq 1 ]
then
sh /block_exchange.sh
if [ $(cat /pac.json | jq .amnezia) -eq 1 ]
then
awg-quick up wg0
else
wg-quick up wg0
fi
if [ $(cat /pac.json | jq .blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .exchange) -eq 1 ]
then
sh /block_exchange.sh
fi
fi
tail -f /dev/null
+7 -4
View File
@@ -3,10 +3,13 @@ Description=VPN: Docker Compose Application Service
Requires=docker.service
After=docker.service
[Service]
WorkingDirectory=/root/vpnbot
ExecStart=/bin/sh -c "IP=$(ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | awk '{print $1}' | head -1) docker compose up --build --force-recreate"
ExecStop=/usr/bin/docker compose down
Type=oneshot
RemainAfterExit=yes
WorkingDirectory=path
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate"
ExecStartPost=/bin/sh -c "bash ./update/update.sh &"
ExecStop=/bin/sh -c "docker compose down --remove-orphans"
ExecStopPost=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null"
TimeoutStartSec=0
Restart=on-failure
[Install]
WantedBy=multi-user.target
+19
View File
@@ -0,0 +1,19 @@
#!/bin/bash
pwd=`pwd`
> $pwd/update/pipe
echo "$$" > $pwd/update/update_pid
while true
do
cmd=$(cat $pwd/update/pipe)
if [[ -n "$cmd" ]]
then
docker compose down --remove-orphans
git reset --hard
git pull > ./update/message
IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate
bash $pwd/update/update.sh &
exit 0
fi
sleep 1
done
+10
View File
@@ -1,3 +1,13 @@
06.03.2024
- короткие ссылки для амнезии
- фикс работы openconnect
- фикс экспорта пользователей openconnect
- фикс скрипта установки бота как сервиса
04.03.2024
- решение "серого айпи" при запуске
- фикс стартового скрипта второго контейнера wireguard
03.03.2024 возможность обновления бота по кнопке из самого бота
- <code>git pull && make r</code>
02.03.2024 2 сервера wireguard, для возможности один запускать как wireguard а второй как amnezia
- <code>git pull && make r</code>
01.03.2024 фикс блокировок торрентов и обмена между пользователями