Compare commits

...

15 Commits

Author SHA1 Message Date
mercury 4998893234 fix autobackup 2024-10-23 21:35:17 +04:00
mercury 95f92791b1 update version 2024-10-23 10:08:32 +04:00
mercury cedfb66ca0 fix autoupdate wireguard crash 2024-10-23 10:05:06 +04:00
mercury 6215836926 fix empty route rules for singbox 2024-10-23 03:01:10 +04:00
mercury 842d76261a update version 2024-10-23 02:45:17 +04:00
mercury 4c63ae669a improve selfupdate 2024-10-23 02:32:19 +04:00
mercury bba1ec9e17 improve selfupdate 2024-10-23 02:25:00 +04:00
mercury a798df0fd3 improve selfupdate 2024-10-23 02:20:16 +04:00
mercury d225e7c039 fix double import after update 2024-10-23 02:06:35 +04:00
mercury 3b9b930b48 - autobackup check formate
- cron status
- fix with sending a backup when there are special characters in the bot name
2024-10-23 01:24:36 +04:00
mercury bd17e5cd14 improve ip detect on start 2024-10-22 23:55:05 +04:00
mercury c3975549db openconnect: isolate-workers = false 2024-10-22 22:42:20 +04:00
mercury 3087bee82d openconnect: expose-iroutes on/off 2024-10-21 22:19:13 +04:00
mercury 96fbf5a3c3 openconnect: limit cpu and memory 2024-10-21 21:09:50 +04:00
mercury b32bd960fa xray: tags for templates 2024-10-21 02:29:19 +04:00
7 changed files with 177 additions and 134 deletions
+141 -131
View File
@@ -271,6 +271,9 @@ class Bot
case preg_match('~^/addOcUser$~', $this->input['callback'], $m):
$this->addOcUser();
break;
case preg_match('~^/changeOcExpose$~', $this->input['callback'], $m):
$this->changeOcExpose();
break;
case preg_match('~^/addXrUser$~', $this->input['callback'], $m):
$this->addXrUser();
break;
@@ -1073,12 +1076,18 @@ class Bot
public function checkBackup()
{
$c = $this->getPacConf();
$now = strtotime(date('Y-m-d H:i'));
if (!empty($c['backup'])) {
$now = strtotime(date('Y-m-d H:i:s'));
[$start, $period] = explode('/', $c['backup']);
$start = strtotime($start);
$period = strtotime($period, 0);
if ($now - $start >= $period && ($now - $start) % $period == 0) {
$start = strtotime(trim($start));
$period = strtotime(trim($period), 0);
if (
!empty($start)
&& !empty($period)
&& empty($this->backup)
&& $now - $start >= $period
&& ($now - $start) % $period < 10
) {
if (!empty($c['pinbackup'])) {
$this->pinAdmin($c['pinbackup'], 1);
}
@@ -1087,6 +1096,12 @@ class Bot
}
}
public function cleanQueue(): void
{
$r = $this->request('deleteWebhook', []);
$r = $this->request('getUpdates', ['offset' => -1]);
}
public function pinAdmin($pin, $unpin = false)
{
require __DIR__ . '/config.php';
@@ -1101,9 +1116,8 @@ class Bot
{
require __DIR__ . '/config.php';
$conf = $this->getPacConf();
$bot = $this->request('getMyName', [])['result']['name'];
$bot = preg_replace('~[\W]~iu', '_', $this->request('getMyName', [])['result']['name']);
$conf['pinbackup'] = $this->upload("{$bot}_export_" . date('d_m_Y_H_i') . '.json', $this->export(), $c['admin'][0])['result']['message_id'];
$conf['backup'] = implode(' / ', [date('Y-m-d H:i'), trim(explode('/', $conf['backup'])[1])]);
$this->setPacConf($conf);
$this->pinAdmin($conf['pinbackup']);
}
@@ -1293,7 +1307,7 @@ class Bot
if (!empty($file)) {
file_put_contents($file, $json);
}
$bot = $this->request('getMyName', [])['result']['name'];
$bot = preg_replace('~[\W]~iu', '_', $this->request('getMyName', [])['result']['name']);
return $this->upload("{$bot}_export_" . date('d_m_Y_H_i') . '.json', $json);
}
@@ -1313,7 +1327,7 @@ class Bot
];
}
public function importFile($file = false)
public function importFile($file = false, $autoupdate = false)
{
if (!empty($file)) {
$json = json_decode(file_get_contents($file), true);
@@ -1353,7 +1367,11 @@ class Bot
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->wg = 0;
$this->saveClients($json['wg']['clients']);
$this->restartWG($this->createConfig($json['wg']['server']), $switch_amnezia);
if (empty($autoupdate)) {
$this->restartWG($this->createConfig($json['wg']['server']), $switch_amnezia);
} else {
file_put_contents('/config/wg0.conf', $this->createConfig($json['wg']['server']));
}
$this->iptablesWG();
}
// wg1
@@ -1362,7 +1380,11 @@ class Bot
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->wg = 1;
$this->saveClients($json['wg1']['clients']);
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_wg1amnezia);
if (empty($autoupdate)) {
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_wg1amnezia);
} else {
file_put_contents('/config/wg1.conf', $this->createConfig($json['wg1']['server']));
}
$this->iptablesWG();
}
// ad
@@ -1445,8 +1467,10 @@ class Bot
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->language = $this->getPacConf()['language'] ?: 'en';
$this->limit = $this->getPacConf()['limitpage'] ?: 5;
sleep(3);
$this->menu();
if (empty($file)) {
sleep(3);
$this->menu();
}
}
}
@@ -1782,11 +1806,18 @@ class Bot
public function sslip()
{
$c = $this->getPacConf();
if (empty($c['domain'])) {
require __DIR__ . '/config.php';
$p = $this->getPacConf();
$ip = getenv('IP');
$r = $this->send($c['admin'][0], "start $ip");
$this->input['chat'] = $c['admin'][0];
$this->input['message_id'] = $r['result']['message_id'];
if (empty($p['domain'])) {
$this->addDomain(str_replace('.', '-', $this->ip) . '.nip.io', 1);
$this->setSSL('letsencrypt');
}
$this->menu();
}
public function comment($text, $tag)
@@ -3840,9 +3871,10 @@ DNS-over-HTTPS with IP:
public function menu($type = false, $arg = false, $return = false)
{
$domain = $this->getPacConf()['domain'] ?: $this->ip;
$cron = exec('pgrep -f cron.php');
$menu = [
'main' => [
'text' => 'v' . getenv('VER'),
'text' => 'v' . getenv('VER') . ($this->dontshowcron ? '' : "\ncron: " . $this->i18n($cron ? 'on' : 'off') . ($cron ? '' : ' show <code>logs/php_error</code>')),
'data' => [
[
[
@@ -4129,7 +4161,9 @@ DNS-over-HTTPS with IP:
preg_match('~^camouflage_secret[^\n]+?"([^"]+)*"~sm', $ocserv, $m);
$cs = $m[1];
preg_match('~^dns = ([^\n]+)~sm', $ocserv, $m);
$dns = $m[1];
$dns = $m[1];
preg_match('~^expose-iroutes = (true)~sm', $ocserv, $m);
$expose = $m[1];
$pass = htmlspecialchars($pac['ocserv']);
$text[] = "Menu -> OpenConnect";
if (!empty($m[1])) {
@@ -4150,6 +4184,12 @@ DNS-over-HTTPS with IP:
'callback_data' => "/changeOcDns",
],
];
$data[] = [
[
'text' => $this->i18n('expose-iroutes') . ' ' . $this->i18n($expose ? 'on' : 'off'),
'callback_data' => "/changeOcExpose",
],
];
$data[] = [
[
'text' => $this->i18n('add peer'),
@@ -4177,6 +4217,15 @@ DNS-over-HTTPS with IP:
];
}
public function changeOcExpose()
{
$c = file_get_contents('/config/ocserv.conf');
preg_match('~^expose-iroutes = ([^\n]+)~sm', $c, $m);
$t = preg_replace('~^expose-iroutes[^\n]+~sm', "expose-iroutes = " . ($m[1] == 'true' ? 'false' : 'true'), $c);
$this->restartOcserv($t);
$this->menu('oc');
}
public function deloc($i)
{
$clients = $this->getClientsOc();
@@ -4829,45 +4878,6 @@ DNS-over-HTTPS with IP:
return $c['domain'] ?: $this->ip;
}
public function v2raySubscription($key, $fs = 0)
{
$pac = $this->getPacConf();
$domain = $this->getDomain();
$xr = $this->getXray();
$flag = true;
foreach ($xr['inbounds'][0]['settings']['clients'] as $k => $v) {
if ($v['id'] == $key) {
if (!empty($fs)) {
return $this->userXr($k);
}
if (empty($v['off'])) {
$flag = false;
}
break;
}
}
if ($flag) {
return;
}
$c = json_decode(file_get_contents('/config/v2ray.json'), true);
$c['outbounds'][0]['settings']['vnext'][0]['address'] = $domain;
$c['outbounds'][0]['settings']['vnext'][0]['users'][0]['id'] = $key;
$c['outbounds'][0]['streamSettings']['realitySettings']['serverName'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
$c['outbounds'][0]['streamSettings']['realitySettings']['publicKey'] = $pac['xray'];
$c['outbounds'][0]['streamSettings']['realitySettings']['shortId'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
$c['routing']['rules'][0]['domain'] = array_keys(array_filter($pac['includelist']));
if (empty($c['routing']['rules'][0]['domain'])) {
unset($c['routing']['rules'][0]);
$c['routing']['rules'] = array_values($c['routing']['rules']);
}
echo json_encode($c);
}
public function subscription()
{
$type = $_GET['t'] == 's' ? 'v2ray' : 'sing';
@@ -4952,9 +4962,9 @@ DNS-over-HTTPS with IP:
switch ($_GET['t']) {
case 's':
$c['outbounds'][0]['settings']['vnext'][0]['address'] = $domain;
$c['outbounds'][0]['settings']['vnext'][0]['address'] = '~domain~';
$c['outbounds'][0]['settings']['vnext'][0]['users'][0] = [
'id' => $uid,
'id' => '~uid~',
'encryption' => 'none',
];
if ($pac['transport'] == 'Websocket') {
@@ -4966,7 +4976,7 @@ DNS-over-HTTPS with IP:
],
"tlsSettings" => [
"allowInsecure" => false,
"serverName" => $domain,
"serverName" => '~domain~',
"fingerprint" => "chrome"
]
];
@@ -4977,10 +4987,10 @@ DNS-over-HTTPS with IP:
"network" => "tcp",
"security" => "reality",
"realitySettings" => [
"serverName" => $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0],
"serverName" => '~server_name~',
"fingerprint" => "chrome",
"publicKey" => $pac['xray'],
"shortId" => $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0],
"publicKey" => '~public_key~',
"shortId" => '~short_id~',
]
];
$c['outbounds'][0]['mux'] = [
@@ -4988,24 +4998,10 @@ DNS-over-HTTPS with IP:
"concurrency" => -1
];
}
foreach ($c['routing']['rules'] as $k => $v) {
if (array_key_exists('domain', $v) && $v['domain'] == '~pac~') {
$c['routing']['rules'][$k]['domain'] = array_keys(array_filter($pac['includelist'] ?: []));
if (empty($c['routing']['rules'][$k]['domain'])) {
unset($c['routing']['rules'][$k]);
}
}
}
$c['routing']['rules'] = array_values($c['routing']['rules']);
break;
case 'si':
if ($c['dns']['servers'][0]['address'] == '~dns~') {
$c['dns']['servers'][0]['address'] = "https://$domain/dns-query/$uid";
}
$c['outbounds'][0]['server'] = $domain;
$c['outbounds'][0]['uuid'] = $uid;
$c['outbounds'][0]['server'] = '~domain~';
$c['outbounds'][0]['uuid'] = '~uid~';
if ($pac['transport'] == 'Websocket') {
unset($c['outbounds'][0]['tls']['reality']);
unset($c['outbounds'][0]['flow']);
@@ -5013,43 +5009,60 @@ DNS-over-HTTPS with IP:
"type" => "ws",
"path" => "/ws"
];
$c['outbounds'][0]['tls']['server_name'] = $domain;
$c['outbounds'][0]['tls']['server_name'] = '~domain~';
} else {
unset($c['outbounds'][0]["transport"]);
$c['outbounds'][0]['flow'] = 'xtls-rprx-vision';
$c['outbounds'][0]['tls']['reality']['public_key'] = $pac['xray'];
$c['outbounds'][0]['tls']['server_name'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
$c['outbounds'][0]['tls']['reality']['short_id'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
$c['outbounds'][0]['tls']['reality']['public_key'] = '~public_key~';
$c['outbounds'][0]['tls']['server_name'] = '~server_name~';
$c['outbounds'][0]['tls']['reality']['short_id'] = '~short_id~';
}
foreach ($c['route']['rules'] as $k => $v) {
if (array_key_exists('domain_suffix', $v) && $v['domain_suffix'] == '~pac~') {
$c['route']['rules'][$k]['domain_suffix'] = array_keys(array_filter($pac['includelist'] ?: []));
if (empty($c['route']['rules'][$k]['domain_suffix'])) {
unset($c['route']['rules'][$k]);
}
}
}
$c['route']['rules'] = array_values($c['route']['rules']);
$c['route'] = $this->addRuleSet($c['route']);
$c['route'] = $this->createRuleSet($c['route'], $uid, $domain);
$c['route'] = $this->clearEmptyRules($c['route']);
$c['route'] = $this->addRuleSet($c['route']);
$c['route'] = $this->createRuleSet($c['route'], $uid, $domain);
break;
}
$json = $this->replaceTags(json_encode($c), [
'"~pac~"' => json_encode(array_keys(array_filter($pac['includelist'] ?: []))),
'~dns~' => "https://$domain/dns-query/$uid",
'~uid~' => $uid,
'~domain~' => $domain,
'~short_id~' => $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0],
'~public_key~' => $pac['xray'],
'~server_name~' => $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0],
]);
$json = $this->clearEmptyRules($json);
header('Content-type: application/json');
echo json_encode($c);
echo $json;
}
public function clearEmptyRules($route)
public function replaceTags($subject, $tags)
{
foreach ($route['rules'] as $k => $v) {
if (count($v) == 1) {
unset($route['rules'][$k]);
return str_replace(array_keys($tags), array_values($tags), $subject);
}
public function clearEmptyRules($json)
{
$json = json_decode($json, 1);
if (!empty($json['routing']['rules'])) {
foreach ($json['routing']['rules'] as $k => $v) {
if (array_key_exists('domain', $v) && empty($v['domain'])) {
unset($json['routing']['rules'][$k]);
}
}
$json['routing']['rules'] = array_values($json['routing']['rules']);
}
$route['rules'] = array_values($route['rules']);
return $route;
if (!empty($json['route']['rules'])) {
foreach ($json['route']['rules'] as $k => $v) {
if (count($v) < 2) {
unset($json['route']['rules'][$k]);
}
}
$json['route']['rules'] = array_values($json['route']['rules']);
}
return json_encode($json);
}
public function addRuleSet($route)
@@ -5589,7 +5602,11 @@ DNS-over-HTTPS with IP:
];
$backup = array_filter(explode('/', $conf['backup']));
if (!empty($backup)) {
$backup = "{$backup[0]} start / {$backup[1]} period";
if (!empty(strtotime($backup[0])) && !empty(strtotime($backup[1]))) {
$backup = "{$backup[0]} start / {$backup[1]} period";
} else {
$backup = $this->i18n('off') . " {$conf['backup']} - wrong format";
}
}
$data[] = [
[
@@ -5736,32 +5753,21 @@ DNS-over-HTTPS with IP:
public function selfUpdate()
{
require __DIR__ . '/config.php';
if (!empty($c['admin'])) {
$ip = getenv('IP');
$rm = explode(':', trim(file_get_contents('/update/reload_message')));
$m = file_get_contents('/update/message');
foreach ($c['admin'] as $k => $v) {
$r = $this->send($v, "start $ip");
$this->input['chat'] = $v;
$this->input['message_id'] = $r['result']['message_id'];
if (file_exists($this->update)) {
if (!empty($m)) {
$this->send($v, "<pre>$m</pre>", $v == $rm[0] ? $rm[1] : 0);
}
$r = $this->send($v, "import settings");
$this->input['chat'] = $v;
$this->input['message_id'] = $r['result']['message_id'];
$this->input['callback_id'] = $r['result']['message_id'];
if (empty($flag)) {
$this->importFile($this->update);
unlink($this->update);
$flag = true;
}
} else {
$this->menu();
}
$ip = getenv('IP');
$rm = explode(':', trim(file_get_contents('/update/reload_message')));
$m = file_get_contents('/update/message');
$this->input['chat'] = $rm[0];
$this->input['message_id'] = $rm[1];
$this->input['callback_id'] = $rm[1];
if (file_exists($this->update)) {
if (!empty($m)) {
$this->send($this->input['chat'], "<pre>$m</pre>", $rm[1]);
}
$r = $this->send($this->input['chat'], "import settings");
$this->input['message_id'] = $r['result']['message_id'];
$this->input['callback_id'] = $r['result']['message_id'];
$this->importFile($this->update, 1);
unlink($this->update);
}
file_put_contents('/update/message', '');
file_put_contents('/update/reload_message', '');
@@ -5899,7 +5905,11 @@ DNS-over-HTTPS with IP:
$c['backup'] = '';
} else {
[$start, $period] = explode('/', $text);
$c['backup'] = implode(' / ', [date('Y-m-d H:i', strtotime($start)), trim($period)]);
if (!empty(strtotime($start)) && !empty(strtotime($period))) {
$c['backup'] = implode(' / ', [date('Y-m-d H:i', strtotime($start)), trim($period)]);
} else {
$this->send($this->input['from'], $this->input['message'] . ' - wrong format');
}
}
if ($c['pinbackup']) {
$this->pinAdmin($c['pinbackup'], 1);
@@ -6017,25 +6027,25 @@ DNS-over-HTTPS with IP:
public function createConfig($data)
{
$pac = $this->getPacConf();
$conf[] = "[Interface]";
if (empty($data['interface']['ListenPort'])) {
if (empty($data['interface']['DNS'])) {
$data['interface']['DNS'] = $this->getPacConf()[$this->getInstanceWG(1) . 'dns'] ?: $this->dns;
$data['interface']['DNS'] = $pac[$this->getInstanceWG(1) . 'dns'] ?: $this->dns;
}
if (empty($data['interface']['MTU'])) {
$data['interface']['MTU'] = $this->getPacConf()[$this->getInstanceWG(1) . 'mtu'] ?: $this->mtu;
$data['interface']['MTU'] = $pac[$this->getInstanceWG(1) . 'mtu'] ?: $this->mtu;
}
}
foreach ($data['interface'] as $k => $v) {
$conf[] = "$k = $v";
}
$pac = $this->getPacConf();
if (!empty($data['peers'])) {
foreach ($data['peers'] as $peer) {
$conf[] = '';
$conf[] = $peer['# PublicKey'] ? '# [Peer]' : '[Peer]';
if (!empty($peer['Endpoint'])) {
$peer['Endpoint'] = ($this->getPacConf()[$this->getInstanceWG(1) . 'endpoint'] ? $this->ip : $this->getDomain()) . ":" . getenv($this->getInstanceWG(1) ? 'WG1PORT' : 'WGPORT');
$peer['Endpoint'] = ($pac[$this->getInstanceWG(1) . 'endpoint'] ? $this->ip : $this->getDomain()) . ":" . getenv($this->getInstanceWG(1) ? 'WG1PORT' : 'WGPORT');
}
foreach ($peer as $k => $v) {
$conf[] = "$k = $v";
+4
View File
@@ -341,4 +341,8 @@ $i = [
'en' => 'fake html',
'ru' => 'фейк заглушка',
],
'expose-iroutes' => [
'en' => 'expose-iroutes',
'ru' => 'изоляция клиентов',
],
];
+1
View File
@@ -10,6 +10,7 @@ if ($c['debug']) {
}
$bot = new Bot($c['key'], $i);
$bot->cleanQueue();
$bot->setwebhook();
$bot->selfUpdate();
$bot->adguardCheckPswd();
+1
View File
@@ -13,5 +13,6 @@ if ($c['debug']) {
$bot = new Bot($c['key'], $i);
$bot->restartTG();
$bot->dontshowcron = 1;
$bot->sslip();
$bot->cleanDocker();
+2 -2
View File
@@ -180,7 +180,7 @@ server-key = /certs/cert_private
# the isolation was tested at. If you get random failures on worker processes, try
# disabling that option and report the failures you, along with system and debugging
# information at: https://gitlab.com/openconnect/ocserv/issues
isolate-workers = true
isolate-workers = false
# A banner to be displayed on clients after connection
#banner = "Welcome"
@@ -584,7 +584,7 @@ route = default
# When set to true, all client's iroutes are made visible to all
# connecting clients except for the ones offering them. This option
# only makes sense if config-per-user is set.
#expose-iroutes = true
expose-iroutes = false
# Groups that a client is allowed to select from.
# A client may belong in multiple groups, and in certain use-cases
+2 -1
View File
@@ -1,9 +1,10 @@
b:
docker compose build
u: # запуск контейнеров
$(eval IP := $(shell curl -s -t 1 2ip.io || curl -s -t 1 ipinfo.io/ip || curl -s -t 1 ifconfig.me))
bash ./update/update.sh &
touch ./override.env
IP=$(shell curl ipinfo.io/ip) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
IP=$(IP) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
d: # остановка контейнеров
-kill -9 $(shell cat ./update/update_pid) > /dev/null
docker compose down --remove-orphans
+26
View File
@@ -1,3 +1,29 @@
23.10.2024 v1.82
- фикс автобэкапа
23.10.2024 v1.81
- фикс краша wireguard после апдейта
23.10.2024 v1.80
- фикс пустых правил для singbox
23.10.2024 v1.79
- улучшение процесса обновления
23.10.2024 v1.78
- фикс двойного импорта при обновлении, когда админов больше одного
- рестарт бота сбрасывает очередь сообщений от телеграма
- при старте статус крона не показывается, т.к он еще не успел запуститься
23.10.2024 v1.77
- вывод статуса cron
- фикс с отправкой бэкапа при спецсимволах в названии бота
- проверка формата времени в автобэкапе
22.10.2024 v1.76
- улучшение определения ip бота при старте
22.10.2024 v1.75
- openconnect: isolate-workers = false
21.10.2024 v1.74
- openconnect: expose-iroutes on/off
21.10.2024 v1.73
- openconnect: ограничение контейнера по цпу и памяти
21.10.2024 v1.72
- xray: теги в кастомных шаблонах
21.10.2024 v1.71
- фикс установки nip.io при первом запуске
- фикс инициализации вебпанели adguardHome при первом запуске