vernesong / OpenClash

A Clash Client For OpenWrt
MIT License
16.64k stars 3.08k forks source link

修改配置文件保存提示错误 #3580

Closed asnon closed 8 months ago

asnon commented 10 months ago

Verify Steps

OpenClash Version

v0.45.141-beta

Bug on Environment

Lean

Bug on Platform

Linux-amd64(x86-64)

To Reproduce

只要修改一下配置文件,都无法保存

Describe the Bug

Error Unhandled exception during request dispatching At reading part data, byte offset 102744, the value exceeds the maximum allow size In mimedecode message body(), file /usr/share/ucode/luci/http.uc, line 112, byte 11: called from function parse message body (/usr/share/ucode/luci/http.uc:180:51 called from function [anonymous function] (/usr/share/ucode/luci/http.uc:450:3) called from function anonymous function (/usr/share/ucode/luci/http.uc:374:22 called from function require post security (/usr/share/ucode/luci/dispatcher.uc:680:47) called from function [anonymous function, (/usr/share/ucode/luci/dispatcher.uc:1005:35 called from anonvmous function (/www/cgi-bin/luci:39:12) die(err); Near here

OpenClash Log

OpenClash 调试日志

生成时间: 2023-10-27 08:38:59 插件版本: v0.45.141-244 隐私提示: 上传此日志前请注意检查、屏蔽公网IP、节点、密码等相关敏感信息


#===================== 系统信息 =====================#

主机型号: WeiBu ADL-N
固件版本: OpenWrt 23.05.0 10.14.2023
LuCI版本: 
内核版本: 6.2.16-18-pve
处理器架构: x86_64

#此项有值时,如不使用IPv6,建议到网络-接口-lan的设置中禁用IPV6的DHCP
IPV6-DHCP: 

DNS劫持: Dnsmasq 转发
#DNS劫持为Dnsmasq时,此项结果应仅有配置文件的DNS监听地址
Dnsmasq转发设置: 127.0.0.1#7874

#===================== 依赖检查 =====================#

dnsmasq-full: 已安装
coreutils: 已安装
coreutils-nohup: 已安装
bash: 已安装
curl: 已安装
ca-certificates: 未安装
ipset: 已安装
ip-full: 已安装
libcap: 已安装
libcap-bin: 已安装
ruby: 已安装
ruby-yaml: 已安装
ruby-psych: 已安装
ruby-pstore: 已安装
kmod-tun(TUN模式): 已安装
luci-compat(Luci >= 19.07): 已安装
kmod-inet-diag(PROCESS-NAME): 已安装
unzip: 已安装
iptables-mod-tproxy: 已安装
kmod-ipt-tproxy: 已安装
iptables-mod-extra: 已安装
kmod-ipt-extra: 已安装
kmod-ipt-nat: 已安装

#===================== 内核检查 =====================#

运行状态: 运行中
运行内核:TUN
进程pid: 24547
运行权限: 24547: cap_dac_override,cap_net_bind_service,cap_net_admin,cap_net_raw,cap_sys_ptrace,cap_sys_resource=eip
运行用户: nobody
已选择的架构: linux-amd64

#下方无法显示内核版本号时请确认您的内核版本是否正确或者有无权限
Tun内核版本: 2023.08.17
Tun内核文件: 存在
Tun内核运行权限: 正常

Dev内核版本: v1.15.1-7-g6eee226
Dev内核文件: 存在
Dev内核运行权限: 正常

Meta内核版本: alpha-g3a9fc39
Meta内核文件: 存在
Meta内核运行权限: 正常

#===================== 插件设置 =====================#

当前配置文件: /etc/openclash/config/yiy.yaml
启动配置文件: /etc/openclash/yiy.yaml
运行模式: redir-host-mix
默认代理模式: rule
UDP流量转发(tproxy): 停用
自定义DNS: 启用
IPV6代理: 停用
IPV6-DNS解析: 停用
禁用Dnsmasq缓存: 启用
自定义规则: 停用
仅允许内网: 启用
仅代理命中规则流量: 停用
仅允许常用端口流量: 停用
绕过中国大陆IP: 启用
路由本机代理: 启用

#启动异常时建议关闭此项后重试
混合节点: 停用
保留配置: 停用

#启动异常时建议关闭此项后重试
第三方规则: 停用

#===================== 配置文件 =====================#

mixed-port: 7893
socks-port: 7891
port: 7890
allow-lan: true
mode: rule
log-level: info
external-controller: 0.0.0.0:9090
proxy-groups:
- name: "\U0001F680代理线路"
  type: select
  proxies:
  - "\U0001F504HK香港"
  - "\U0001F504TW台湾"
  - "\U0001F504JP日本"
  - "\U0001F504AM美国"
  - "\U0001F320企业专线"
  - R1-0|香港-NF|粤|负载均衡
  - R1-1|香港-NF|沪|负载均衡
  - R1-2|香港-NF|湘|负载均衡
  - R1-3|香港-NF|HKG|家宽
  - R1-4|香港-NF|AZ-HKT|家宽
  - R2-1|香港-NF|CMHK|家宽
  - R2-2|香港-NF|AzureCN2
  - R2-3|香港-NF|HKBN|家宽
  - R2-4|香港-NF|CMI
  - R2-5|香港-NF|BGP
  - R3-1|香港-NF|HGC|原生
  - R3-2|香港-NF|HKBN|原生
  - R3-3|香港-NF|港区NF|原生
  - R4-1|台湾-NF|家宽|原生
  - R4-2|台湾-NF|家宽|原生
  - R4-3|台湾-NF|家宽|原生
  - R4-4|台湾-NF|家宽|原生
  - R5-1|日本-NF|GMO|原生IP
  - R5-2|日本-NF|KDDI|原生
  - R5-3|日本-NF|BGP|精品
  - R5-4|日本-SoftBank|精品
  - R6-1|美国-INAP线路
  - R6-2|美国-NF|原生IP
  - R6-3|美国-NTT|原生IP
  - R6-4|美国-NF|原生IP
  - R7-1|英国-BBC
  - R7-2|英国-家宽|原生
  - R7-3|英国-原生
  - R8-1|韩国Oracle
  - R8-2|韩国-NF
  - R8-3|俄罗斯-原生IP
  - R8-4|马来西亚-原生IP
  - R8-6|土耳其-原生
  - R8-7|阿根廷-原生|禁视频|x2
  - R8-8|印度
  - R9-1|新加坡-NF|原生IP
  - R9-2|新加坡-NF|FDC
  - V1-1|广新-NF|专线A
  - V1-2|广港-NF|专线B
  - V1-3|广港-NF|专线A
  - V2-1|沪港-NF|CN2|专线C
  - V2-2|皖日-NF|家宽|专线D
  - V2-3|湘港-NF|BGP|专线E
  - IPV6-1线路|美国-V2ray|直连
  - D1-1直连|香港-NF|原生|x0.5
  - D1-2直连|香港-NF|原生|x1
  - D1-3直连|香港-NF|原生|x1
  - 不代理
- name: "✈️墙外网站"
  type: select
  proxies:
  - "\U0001F680代理线路"
- name: "\U0001F41F其他网站"
  type: select
  proxies:
  - "\U0001F680代理线路"
  - 不代理
- name: "\U0001F4E2网站公告"
  type: select
  proxies:
  - "@有效期2024-06-27"
  - "@expire-2024-06-27"
- name: "\U0001F6AB以下用默认"
  type: select
  proxies:
  - DIRECT
- name: "\U0001F504HK香港"
  type: fallback
  url: http://www.google.com
  interval: 600
  proxies:
  - R1-0|香港-NF|粤|负载均衡
  - R1-1|香港-NF|沪|负载均衡
  - R1-2|香港-NF|湘|负载均衡
  - R1-3|香港-NF|HKG|家宽
  - R1-4|香港-NF|AZ-HKT|家宽
  - R2-1|香港-NF|CMHK|家宽
  - R2-2|香港-NF|AzureCN2
  - R2-3|香港-NF|HKBN|家宽
  - R2-4|香港-NF|CMI
  - R2-5|香港-NF|BGP
  - R3-1|香港-NF|HGC|原生
  - R3-2|香港-NF|HKBN|原生
  - R3-3|香港-NF|港区NF|原生
  - V1-2|广港-NF|专线B
  - V1-3|广港-NF|专线A
  - V2-1|沪港-NF|CN2|专线C
  - V2-3|湘港-NF|BGP|专线E
  - D1-1直连|香港-NF|原生|x0.5
  - D1-2直连|香港-NF|原生|x1
  - D1-3直连|香港-NF|原生|x1
- name: "\U0001F504TW台湾"
  type: fallback
  url: http://www.google.com
  interval: 600
  proxies:
  - R4-1|台湾-NF|家宽|原生
  - R4-2|台湾-NF|家宽|原生
  - R4-3|台湾-NF|家宽|原生
  - R4-4|台湾-NF|家宽|原生
- name: "\U0001F504JP日本"
  type: fallback
  url: http://www.google.com
  interval: 600
  proxies:
  - R5-1|日本-NF|GMO|原生IP
  - R5-2|日本-NF|KDDI|原生
  - R5-3|日本-NF|BGP|精品
  - R5-4|日本-SoftBank|精品
  - V2-2|皖日-NF|家宽|专线D
- name: "\U0001F504AM美国"
  type: fallback
  url: http://www.google.com
  interval: 600
  proxies:
  - R6-1|美国-INAP线路
  - R6-2|美国-NF|原生IP
  - R6-3|美国-NTT|原生IP
  - R6-4|美国-NF|原生IP
  - IPV6-1线路|美国-V2ray|直连
- name: "\U0001F320企业专线"
  type: fallback
  url: http://www.google.com
  interval: 600
  proxies:
  - V1-1|广新-NF|专线A
  - V1-2|广港-NF|专线B
  - V1-3|广港-NF|专线A
  - V2-1|沪港-NF|CN2|专线C
  - V2-2|皖日-NF|家宽|专线D
  - V2-3|湘港-NF|BGP|专线E
- name: Ⓜ️微软苹果
  type: select
  proxies:
  - 不代理
  - "\U0001F680代理线路"
- name: "\U0001F6D1广告屏蔽"
  type: select
  proxies:
  - 不代理
  - REJECT
  - "\U0001F680代理线路"
- name: 不代理
  type: select
  proxies:
  - DIRECT
rules:
- DST-PORT,7895,REJECT
- DST-PORT,7892,REJECT
- IP-CIDR,198.18.0.1/16,REJECT,no-resolve
- DOMAIN,app.adjust.com,DIRECT
- DOMAIN,bdtj.tagtic.cn,DIRECT
- DOMAIN,log.mmstat.com,DIRECT
- DOMAIN,sycm.mmstat.com,DIRECT
- DOMAIN-SUFFIX,noxinfluencer.com,✈️墙外网站
- DOMAIN-SUFFIX,smartmailcloud.com,✈️墙外网站
- DOMAIN-SUFFIX,weebly.com,✈️墙外网站
- DOMAIN-SUFFIX,ifixit.com,✈️墙外网站
- DOMAIN-SUFFIX,linkedin.com,✈️墙外网站
- DOMAIN-SUFFIX,mangakakalot.com,✈️墙外网站
- DOMAIN-SUFFIX,shopeemobile.com,✈️墙外网站
- DOMAIN-SUFFIX,sushi.com,✈️墙外网站
- DOMAIN,appleid.apple.com,✈️墙外网站
- DOMAIN,developer.apple.com,✈️墙外网站
- DOMAIN,www.icloud.com,✈️墙外网站
- DOMAIN,ocsp.apple.com,✈️墙外网站
- DOMAIN,cacerts.digicert.com,✈️墙外网站
- DOMAIN,crl3.digicert.com,✈️墙外网站
- DOMAIN,crl4.digicert.com,✈️墙外网站
- DOMAIN,ocsp.digicert.com,✈️墙外网站
- DOMAIN-SUFFIX,inkbunny.net,✈️墙外网站
- DOMAIN-SUFFIX,metapix.net,✈️墙外网站
- DOMAIN-SUFFIX,s3.amazonaws.com,✈️墙外网站
- DOMAIN-SUFFIX,zaobao.com.sg,✈️墙外网站
- DOMAIN,international-gfe.download.nvidia.com,✈️墙外网站
- DOMAIN-SUFFIX,local,DIRECT
- IP-CIDR,192.168.0.0/16,DIRECT,no-resolve
- IP-CIDR,10.0.0.0/8,DIRECT,no-resolve
- IP-CIDR,172.16.0.0/12,DIRECT,no-resolve
- IP-CIDR,127.0.0.0/8,DIRECT,no-resolve
- IP-CIDR,100.64.0.0/10,DIRECT,no-resolve
- IP-CIDR6,::1/128,DIRECT,no-resolve
- IP-CIDR6,fc00::/7,DIRECT,no-resolve
- IP-CIDR6,fe80::/10,DIRECT,no-resolve
- IP-CIDR6,fd00::/8,DIRECT,no-resolve
- GEOIP,CN,DIRECT
- "MATCH,\U0001F41F其他网站"
redir-port: 7892
tproxy-port: 7895
bind-address: "*"
external-ui: "/usr/share/openclash/ui"
ipv6: false
dns:
  enable: true
  ipv6: false
  enhanced-mode: fake-ip
  fake-ip-range: 198.18.0.1/16
  listen: 0.0.0.0:7874
  nameserver:
  - tcp://127.0.0.1:5335
  fallback:
  - 127.0.0.1:5335
  fake-ip-filter:
  - "+.*"
experimental:
  sniff-tls-sni: true
tun:
  enable: true
  stack: system
  auto-route: false
  auto-detect-interface: false
  dns-hijack:
  - tcp://any:53
profile:
  store-selected: true

#===================== 自定义覆写设置 =====================#

#!/bin/sh
. /usr/share/openclash/ruby.sh
. /usr/share/openclash/log.sh
. /lib/functions.sh

# This script is called by /etc/init.d/openclash
# Add your custom overwrite scripts here, they will be take effict after the OpenClash own srcipts

LOG_OUT "Tip: Start Running Custom Overwrite Scripts..."
LOGTIME=$(echo $(date "+%Y-%m-%d %H:%M:%S"))
LOG_FILE="/tmp/openclash.log"
CONFIG_FILE="$1" #config path

#Simple Demo:
    #General Demo
    #1--config path
    #2--key name
    #3--value
    #ruby_edit "$CONFIG_FILE" "['redir-port']" "7892"
    #ruby_edit "$CONFIG_FILE" "['secret']" "123456"
    #ruby_edit "$CONFIG_FILE" "['dns']['enable']" "true"

    #Hash Demo
    #1--config path
    #2--key name
    #3--hash type value
    #ruby_edit "$CONFIG_FILE" "['experimental']" "{'sniff-tls-sni'=>true}"
    #ruby_edit "$CONFIG_FILE" "['sniffer']" "{'sniffing'=>['tls','http']}"

    #Array Demo:
    #1--config path
    #2--key name
    #3--position(start from 0, end with -1)
    #4--value
    #ruby_arr_insert "$CONFIG_FILE" "['dns']['nameserver']" "0" "114.114.114.114"

    #Array Add From Yaml File Demo:
    #1--config path
    #2--key name
    #3--position(start from 0, end with -1)
    #4--value file path
    #5--value key name in #4 file
    #ruby_arr_add_file "$CONFIG_FILE" "['dns']['fallback-filter']['ipcidr']" "0" "/etc/openclash/custom/openclash_custom_fallback_filter.yaml" "['fallback-filter']['ipcidr']"

#Ruby Script Demo:
    #ruby -ryaml -rYAML -I "/usr/share/openclash" -E UTF-8 -e "
    #   begin
    #      Value = YAML.load_file('$CONFIG_FILE');
    #   rescue Exception => e
    #      puts '${LOGTIME} Error: Load File Failed,【' + e.message + '】';
    #   end;

        #General
    #   begin
    #   Thread.new{
    #      Value['redir-port']=7892;
    #      Value['tproxy-port']=7895;
    #      Value['port']=7890;
    #      Value['socks-port']=7891;
    #      Value['mixed-port']=7893;
    #   }.join;

    #   rescue Exception => e
    #      puts '${LOGTIME} Error: Set General Failed,【' + e.message + '】';
    #   ensure
    #      File.open('$CONFIG_FILE','w') {|f| YAML.dump(Value, f)};
    #   end" 2>/dev/null >> $LOG_FILE

exit 0
#===================== 自定义防火墙设置 =====================#

#!/bin/sh
. /usr/share/openclash/log.sh
. /lib/functions.sh

# This script is called by /etc/init.d/openclash
# Add your custom firewall rules here, they will be added after the end of the OpenClash iptables rules

LOG_OUT "Tip: Start Add Custom Firewall Rules..."

exit 0
#===================== IPTABLES 防火墙设置 =====================#

#IPv4 NAT chain

# Generated by iptables-save v1.8.7 on Fri Oct 27 08:39:01 2023
*nat
:PREROUTING ACCEPT [16042:2732756]
:INPUT ACCEPT [8217:570715]
:OUTPUT ACCEPT [13668:873648]
:POSTROUTING ACCEPT [10966:707042]
:MINIUPNPD - [0:0]
:MINIUPNPD-POSTROUTING - [0:0]
:openclash - [0:0]
:openclash_output - [0:0]
:postrouting_lan_rule - [0:0]
:postrouting_rule - [0:0]
:postrouting_wan_rule - [0:0]
:prerouting_lan_rule - [0:0]
:prerouting_rule - [0:0]
:prerouting_wan_rule - [0:0]
:zone_lan_postrouting - [0:0]
:zone_lan_prerouting - [0:0]
:zone_wan_postrouting - [0:0]
:zone_wan_prerouting - [0:0]
-A PREROUTING -p tcp -m comment --comment "OpenClash TCP DNS Hijack" -m tcp --dport 53 -j ACCEPT
-A PREROUTING -p tcp -m tcp --dport 53 -m comment --comment "OpenClash DNS Hijack" -j REDIRECT --to-ports 53
-A PREROUTING -p udp -m udp --dport 53 -m comment --comment "OpenClash DNS Hijack" -j REDIRECT --to-ports 53
-A PREROUTING -m comment --comment "!fw3: Custom prerouting rule chain" -j prerouting_rule
-A PREROUTING -i br-lan -m comment --comment "!fw3" -j zone_lan_prerouting
-A PREROUTING -p tcp -j openclash
-A OUTPUT -j openclash_output
-A POSTROUTING -m comment --comment "!fw3: Custom postrouting rule chain" -j postrouting_rule
-A POSTROUTING -o br-lan -m comment --comment "!fw3" -j zone_lan_postrouting
-A openclash -m set --match-set localnetwork dst -j RETURN
-A openclash -m set --match-set china_ip_route dst -m set ! --match-set china_ip_route_pass dst -j RETURN
-A openclash -p tcp -j REDIRECT --to-ports 7892
-A openclash_output -m set --match-set localnetwork dst -j RETURN
-A openclash_output -m owner ! --uid-owner 65534 -m set --match-set china_ip_route dst -m set ! --match-set china_ip_route_pass dst -j RETURN
-A openclash_output -p tcp -m owner ! --uid-owner 65534 -j REDIRECT --to-ports 7892
-A zone_lan_postrouting -j MINIUPNPD-POSTROUTING
-A zone_lan_postrouting -m comment --comment "!fw3: Custom lan postrouting rule chain" -j postrouting_lan_rule
-A zone_lan_postrouting -m comment --comment "!fw3" -j MASQUERADE
-A zone_lan_prerouting -j MINIUPNPD
-A zone_lan_prerouting -m comment --comment "!fw3: Custom lan prerouting rule chain" -j prerouting_lan_rule
-A zone_wan_postrouting -m comment --comment "!fw3: Custom wan postrouting rule chain" -j postrouting_wan_rule
-A zone_wan_postrouting -m comment --comment "!fw3" -j MASQUERADE
-A zone_wan_prerouting -m comment --comment "!fw3: Custom wan prerouting rule chain" -j prerouting_wan_rule
COMMIT
# Completed on Fri Oct 27 08:39:01 2023

#IPv4 Mangle chain

# Generated by iptables-save v1.8.7 on Fri Oct 27 08:39:01 2023
*mangle
:PREROUTING ACCEPT [2254353:2383408725]
:INPUT ACCEPT [665792:628407123]
:FORWARD ACCEPT [1579849:1753235558]
:OUTPUT ACCEPT [368985:579854692]
:POSTROUTING ACCEPT [1946690:2332740889]
:openclash - [0:0]
:openclash_dns_hijack - [0:0]
:openclash_upnp - [0:0]
-A PREROUTING -p udp -j openclash
-A PREROUTING -p tcp -m tcp --dport 53 -j openclash_dns_hijack
-A openclash -p udp -m udp --sport 500 -j RETURN
-A openclash -p udp -m udp --sport 68 -j RETURN
-A openclash -i utun -j RETURN
-A openclash -m set --match-set localnetwork dst -j RETURN
-A openclash -m set --match-set china_ip_route dst -m set ! --match-set china_ip_route_pass dst -j RETURN
-A openclash -p udp -j openclash_upnp
-A openclash -j MARK --set-xmark 0x162/0xffffffff
-A openclash_dns_hijack -p tcp -m comment --comment "OpenClash TCP DNS Hijack" -m tcp --dport 53 -j MARK --set-xmark 0x162/0xffffffff
COMMIT
# Completed on Fri Oct 27 08:39:01 2023

#IPv4 Filter chain

# Generated by iptables-save v1.8.7 on Fri Oct 27 08:39:01 2023
*filter
:INPUT ACCEPT [136:7024]
:FORWARD ACCEPT [142:10696]
:OUTPUT ACCEPT [0:0]
:MINIUPNPD - [0:0]
:forwarding_lan_rule - [0:0]
:forwarding_rule - [0:0]
:forwarding_wan_rule - [0:0]
:input_lan_rule - [0:0]
:input_rule - [0:0]
:input_wan_rule - [0:0]
:output_lan_rule - [0:0]
:output_rule - [0:0]
:output_wan_rule - [0:0]
:reject - [0:0]
:zone_lan_dest_ACCEPT - [0:0]
:zone_lan_forward - [0:0]
:zone_lan_input - [0:0]
:zone_lan_output - [0:0]
:zone_lan_src_ACCEPT - [0:0]
:zone_wan_dest_ACCEPT - [0:0]
:zone_wan_dest_REJECT - [0:0]
:zone_wan_forward - [0:0]
:zone_wan_input - [0:0]
:zone_wan_output - [0:0]
:zone_wan_src_REJECT - [0:0]
-A INPUT -i lo -m comment --comment "!fw3" -j ACCEPT
-A INPUT -m comment --comment "!fw3: Custom input rule chain" -j input_rule
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
-A INPUT -i br-lan -m comment --comment "!fw3" -j zone_lan_input
-A FORWARD -o utun -p udp -m udp --dport 443 -m comment --comment "OpenClash QUIC REJECT" -m set ! --match-set china_ip_route dst -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -o utun -m comment --comment "OpenClash TUN Forward" -j ACCEPT
-A FORWARD -m comment --comment "!fw3: Custom forwarding rule chain" -j forwarding_rule
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
-A FORWARD -i br-lan -m comment --comment "!fw3" -j zone_lan_forward
-A OUTPUT -o lo -m comment --comment "!fw3" -j ACCEPT
-A OUTPUT -m comment --comment "!fw3: Custom output rule chain" -j output_rule
-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
-A OUTPUT -o br-lan -m comment --comment "!fw3" -j zone_lan_output
-A reject -p tcp -m comment --comment "!fw3" -j REJECT --reject-with tcp-reset
-A reject -m comment --comment "!fw3" -j REJECT --reject-with icmp-port-unreachable
-A zone_lan_dest_ACCEPT -o br-lan -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
-A zone_lan_dest_ACCEPT -o br-lan -m comment --comment "!fw3" -j ACCEPT
-A zone_lan_forward -j MINIUPNPD
-A zone_lan_forward -m comment --comment "!fw3: Custom lan forwarding rule chain" -j forwarding_lan_rule
-A zone_lan_forward -m comment --comment "!fw3: Zone lan to wan forwarding policy" -j zone_wan_dest_ACCEPT
-A zone_lan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
-A zone_lan_forward -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
-A zone_lan_input -m comment --comment "!fw3: Custom lan input rule chain" -j input_lan_rule
-A zone_lan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
-A zone_lan_input -m comment --comment "!fw3" -j zone_lan_src_ACCEPT
-A zone_lan_output -m comment --comment "!fw3: Custom lan output rule chain" -j output_lan_rule
-A zone_lan_output -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
-A zone_lan_src_ACCEPT -i br-lan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
-A zone_wan_forward -m comment --comment "!fw3: Custom wan forwarding rule chain" -j forwarding_wan_rule
-A zone_wan_forward -p esp -m comment --comment "!fw3: Allow-IPSec-ESP" -j zone_lan_dest_ACCEPT
-A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "!fw3: Allow-ISAKMP" -j zone_lan_dest_ACCEPT
-A zone_wan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
-A zone_wan_forward -m comment --comment "!fw3" -j zone_wan_dest_REJECT
-A zone_wan_input -m comment --comment "!fw3: Custom wan input rule chain" -j input_wan_rule
-A zone_wan_input -p udp -m udp --dport 68 -m comment --comment "!fw3: Allow-DHCP-Renew" -j ACCEPT
-A zone_wan_input -p icmp -m icmp --icmp-type 8 -m comment --comment "!fw3: Allow-Ping" -j ACCEPT
-A zone_wan_input -p igmp -m comment --comment "!fw3: Allow-IGMP" -j ACCEPT
-A zone_wan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
-A zone_wan_input -m comment --comment "!fw3" -j zone_wan_src_REJECT
-A zone_wan_output -m comment --comment "!fw3: Custom wan output rule chain" -j output_wan_rule
-A zone_wan_output -m comment --comment "!fw3" -j zone_wan_dest_ACCEPT
COMMIT
# Completed on Fri Oct 27 08:39:01 2023

#IPv6 NAT chain

# Generated by ip6tables-save v1.8.7 on Fri Oct 27 08:39:01 2023
*nat
:PREROUTING ACCEPT [6854:1842545]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [236:19098]
:POSTROUTING ACCEPT [236:19098]
COMMIT
# Completed on Fri Oct 27 08:39:01 2023

#IPv6 Mangle chain

# Generated by ip6tables-save v1.8.7 on Fri Oct 27 08:39:01 2023
*mangle
:PREROUTING ACCEPT [7854:1927163]
:INPUT ACCEPT [132:18584]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [125:18376]
:POSTROUTING ACCEPT [125:18376]
COMMIT
# Completed on Fri Oct 27 08:39:01 2023

#IPv6 Filter chain

# Generated by ip6tables-save v1.8.7 on Fri Oct 27 08:39:01 2023
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [20:1520]
:MINIUPNPD - [0:0]
:forwarding_lan_rule - [0:0]
:forwarding_rule - [0:0]
:forwarding_wan_rule - [0:0]
:input_lan_rule - [0:0]
:input_rule - [0:0]
:input_wan_rule - [0:0]
:output_lan_rule - [0:0]
:output_rule - [0:0]
:output_wan_rule - [0:0]
:reject - [0:0]
:zone_lan_dest_ACCEPT - [0:0]
:zone_lan_forward - [0:0]
:zone_lan_input - [0:0]
:zone_lan_output - [0:0]
:zone_lan_src_ACCEPT - [0:0]
:zone_wan_dest_ACCEPT - [0:0]
:zone_wan_dest_REJECT - [0:0]
:zone_wan_forward - [0:0]
:zone_wan_input - [0:0]
:zone_wan_output - [0:0]
:zone_wan_src_REJECT - [0:0]
-A INPUT -i lo -m comment --comment "!fw3" -j ACCEPT
-A INPUT -m comment --comment "!fw3: Custom input rule chain" -j input_rule
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
-A INPUT -i br-lan -m comment --comment "!fw3" -j zone_lan_input
-A FORWARD -m comment --comment "!fw3: Custom forwarding rule chain" -j forwarding_rule
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
-A FORWARD -i br-lan -m comment --comment "!fw3" -j zone_lan_forward
-A OUTPUT -o lo -m comment --comment "!fw3" -j ACCEPT
-A OUTPUT -m comment --comment "!fw3: Custom output rule chain" -j output_rule
-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
-A OUTPUT -o br-lan -m comment --comment "!fw3" -j zone_lan_output
-A reject -p tcp -m comment --comment "!fw3" -j REJECT --reject-with tcp-reset
-A reject -m comment --comment "!fw3" -j REJECT --reject-with icmp6-port-unreachable
-A zone_lan_dest_ACCEPT -o br-lan -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
-A zone_lan_dest_ACCEPT -o br-lan -m comment --comment "!fw3" -j ACCEPT
-A zone_lan_forward -j MINIUPNPD
-A zone_lan_forward -m comment --comment "!fw3: Custom lan forwarding rule chain" -j forwarding_lan_rule
-A zone_lan_forward -m comment --comment "!fw3: Zone lan to wan forwarding policy" -j zone_wan_dest_ACCEPT
-A zone_lan_forward -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
-A zone_lan_input -m comment --comment "!fw3: Custom lan input rule chain" -j input_lan_rule
-A zone_lan_input -m comment --comment "!fw3" -j zone_lan_src_ACCEPT
-A zone_lan_output -m comment --comment "!fw3: Custom lan output rule chain" -j output_lan_rule
-A zone_lan_output -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
-A zone_lan_src_ACCEPT -i br-lan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
-A zone_wan_forward -m comment --comment "!fw3: Custom wan forwarding rule chain" -j forwarding_wan_rule
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 128 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 129 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 1 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 2 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 3 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 4/0 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p ipv6-icmp -m icmp6 --icmpv6-type 4/1 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Forward" -j ACCEPT
-A zone_wan_forward -p esp -m comment --comment "!fw3: Allow-IPSec-ESP" -j zone_lan_dest_ACCEPT
-A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "!fw3: Allow-ISAKMP" -j zone_lan_dest_ACCEPT
-A zone_wan_forward -m comment --comment "!fw3" -j zone_wan_dest_REJECT
-A zone_wan_input -m comment --comment "!fw3: Custom wan input rule chain" -j input_wan_rule
-A zone_wan_input -p udp -m udp --dport 546 -m comment --comment "!fw3: Allow-DHCPv6" -j ACCEPT
-A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 130/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
-A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 131/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
-A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 132/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
-A zone_wan_input -s fe80::/10 -p ipv6-icmp -m icmp6 --icmpv6-type 143/0 -m comment --comment "!fw3: Allow-MLD" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 128 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 129 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 1 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 2 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 3 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 4/0 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 4/1 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 133 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 135 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 134 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -p ipv6-icmp -m icmp6 --icmpv6-type 136 -m limit --limit 1000/sec -m comment --comment "!fw3: Allow-ICMPv6-Input" -j ACCEPT
-A zone_wan_input -m comment --comment "!fw3" -j zone_wan_src_REJECT
-A zone_wan_output -m comment --comment "!fw3: Custom wan output rule chain" -j output_wan_rule
-A zone_wan_output -m comment --comment "!fw3" -j zone_wan_dest_ACCEPT
COMMIT
# Completed on Fri Oct 27 08:39:01 2023

#===================== IPSET状态 =====================#

Name: localnetwork
Type: hash:net
Revision: 7
Header: family inet hashsize 1024 maxelem 65536 bucketsize 12 initval 0x493a7d89
Size in memory: 888
References: 3
Number of entries: 9

Name: china_ip_route
Type: hash:net
Revision: 7
Header: family inet hashsize 4096 maxelem 1000000 bucketsize 12 initval 0xa8e248e0
Size in memory: 255168
References: 4
Number of entries: 8616

Name: passwall_shuntlist
Type: hash:net
Revision: 7
Header: family inet hashsize 1024 maxelem 1048576 bucketsize 12 initval 0xbd1a7daa
Size in memory: 3528
References: 0
Number of entries: 64

Name: passwall_gfwlist
Type: hash:net
Revision: 7
Header: family inet hashsize 1024 maxelem 1048576 bucketsize 12 initval 0x761f8c1a
Size in memory: 1896
References: 0
Number of entries: 30

Name: passwall_chnroute
Type: hash:net
Revision: 7
Header: family inet hashsize 2048 maxelem 1048576 bucketsize 12 initval 0xbe59936c
Size in memory: 232848
References: 0
Number of entries: 8649

Name: passwall_blacklist
Type: hash:net
Revision: 7
Header: family inet hashsize 1024 maxelem 1048576 bucketsize 12 initval 0x6c3cc48c
Size in memory: 1272
References: 0
Number of entries: 17

Name: china_ip_route_pass
Type: hash:net
Revision: 7
Header: family inet hashsize 1024 maxelem 1000000 bucketsize 12 initval 0xc8666e9c
Size in memory: 456
References: 3
Number of entries: 0

Name: passwall_shuntlist6
Type: hash:net
Revision: 7
Header: family inet6 hashsize 1024 maxelem 1048576 bucketsize 12 initval 0xafad4695
Size in memory: 1888
References: 0
Number of entries: 9

Name: passwall_gfwlist6
Type: hash:net
Revision: 7
Header: family inet6 hashsize 1024 maxelem 1048576 bucketsize 12 initval 0xac43819f
Size in memory: 1240
References: 0
Number of entries: 0

Name: passwall_chnroute6
Type: hash:net
Revision: 7
Header: family inet6 hashsize 1024 maxelem 1048576 bucketsize 12 initval 0x7b10273a
Size in memory: 90664
References: 0
Number of entries: 1983

Name: passwall_blacklist6
Type: hash:net
Revision: 7
Header: family inet6 hashsize 1024 maxelem 1048576 bucketsize 12 initval 0xc665461b
Size in memory: 1600
References: 0
Number of entries: 5

#===================== 路由表状态 =====================#

#IPv4

#route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         192.168.10.1    0.0.0.0         UG    0      0        0 br-lan
192.168.10.0    0.0.0.0         255.255.255.0   U     0      0        0 br-lan
198.18.0.0      0.0.0.0         255.255.0.0     U     0      0        0 utun

#ip route list
default via 192.168.10.1 dev br-lan proto static 
192.168.10.0/24 dev br-lan proto kernel scope link src 192.168.10.5 
198.18.0.0/16 dev utun proto kernel scope link src 198.18.0.1 

#ip rule show
0:  from all lookup local
32765:  from all fwmark 0x162 lookup 354
32766:  from all lookup main
32767:  from all lookup default

#IPv6

#route -A inet6
Kernel IPv6 routing table
Destination                                 Next Hop                                Flags Metric Ref    Use Iface
::/0                                        ::                                      !n    -1     1        0 lo      
fe80::/64                                   ::                                      U     256    1        0 br-lan  
fe80::/64                                   ::                                      U     256    1        0 utun    
::/0                                        ::                                      !n    -1     1        0 lo      
::1/128                                     ::                                      Un    0      6        0 lo      
fe80::/128                                  ::                                      Un    0      5        0 br-lan  
fe80::/128                                  ::                                      Un    0      3        0 utun    
fe80::3c3b:118d:e28c:2802/128               ::                                      Un    0      2        0 utun    
fe80::9087:19ff:fe99:5982/128               ::                                      Un    0      2        0 br-lan  
ff00::/8                                    ::                                      U     256    3        0 br-lan  
ff00::/8                                    ::                                      U     256    1        0 utun    
::/0                                        ::                                      !n    -1     1        0 lo      

#ip -6 route list
fe80::/64 dev br-lan proto kernel metric 256 pref medium
fe80::/64 dev utun proto kernel metric 256 pref medium

#ip -6 rule show
0:  from all lookup local
32766:  from all lookup main

#===================== Tun设备状态 =====================#

utun: tun pi multi_queue filter

#===================== 端口占用状态 =====================#

tcp        0      0 198.18.0.1:7777         0.0.0.0:*               LISTEN      24547/clash
tcp        0      0 :::7895                 :::*                    LISTEN      24547/clash
tcp        0      0 :::7893                 :::*                    LISTEN      24547/clash
tcp        0      0 :::7892                 :::*                    LISTEN      24547/clash
tcp        0      0 :::7891                 :::*                    LISTEN      24547/clash
tcp        0      0 :::7890                 :::*                    LISTEN      24547/clash
tcp        0      0 :::9090                 :::*                    LISTEN      24547/clash
udp        0      0 :::7895                 :::*                                24547/clash
udp        0      0 :::7874                 :::*                                24547/clash
udp        0      0 :::7891                 :::*                                24547/clash
udp        0      0 :::7892                 :::*                                24547/clash
udp        0      0 :::7893                 :::*                                24547/clash

#===================== 测试本机DNS查询(www.baidu.com) =====================#

Server:     127.0.0.1
Address:    127.0.0.1:53

www.baidu.com   canonical name = www.a.shifen.com
Name:   www.a.shifen.com
Address: 14.119.104.189
Name:   www.a.shifen.com
Address: 14.119.104.254

#===================== 测试内核DNS查询(www.instagram.com) =====================#

Status: 0
TC: false
RD: true
RA: true
AD: false
CD: false

Question: 
  Name: www.instagram.com.
  Qtype: 1
  Qclass: 1

Answer: 
  TTL: 1
  data: geo-p42.instagram.com.
  name: www.instagram.com.
  type: 5

  TTL: 1
  data: z-p42-instagram.c10r.instagram.com.
  name: geo-p42.instagram.com.
  type: 5

  TTL: 1
  data: 157.240.199.174
  name: z-p42-instagram.c10r.instagram.com.
  type: 1

Dnsmasq 当前默认 resolv 文件:/tmp/resolv.conf.d/resolv.conf.auto

#===================== /tmp/resolv.conf.d/resolv.conf.auto =====================#

# Interface lan
nameserver 119.29.29.29
nameserver 8.8.8.8

#===================== 测试本机网络连接(www.baidu.com) =====================#

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: private, no-cache, no-store, proxy-revalidate, no-transform
Connection: keep-alive
Content-Length: 277
Content-Type: text/html
Date: Fri, 27 Oct 2023 00:39:01 GMT
Etag: "575e1f65-115"
Last-Modified: Mon, 13 Jun 2016 02:50:13 GMT
Pragma: no-cache
Server: bfe/1.0.8.18

#===================== 测试本机网络下载(raw.githubusercontent.com) =====================#

HTTP/2 404 
content-security-policy: default-src 'none'; style-src 'unsafe-inline'; sandbox
strict-transport-security: max-age=31536000
x-content-type-options: nosniff
x-frame-options: deny
x-xss-protection: 1; mode=block
content-type: text/plain; charset=utf-8
x-github-request-id: E542:24B14A:61A70B:6C9D35:653B06A5
accept-ranges: bytes
date: Fri, 27 Oct 2023 00:39:01 GMT
via: 1.1 varnish
x-served-by: cache-nrt-rjtf7700026-NRT
x-cache: MISS
x-cache-hits: 0
x-timer: S1698367142.772598,VS0,VE204
vary: Authorization,Accept-Encoding,Origin
access-control-allow-origin: *
cross-origin-resource-policy: cross-origin
x-fastly-request-id: cd1280ecd0087e066d7a2b73a13a0a56b559aff4
expires: Fri, 27 Oct 2023 00:44:01 GMT
source-age: 0
content-length: 14

#===================== 最近运行日志(自动切换为Debug模式) =====================#

00:21:40 INF [TCP] connected lAddr=192.168.10.100:57822 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:21:45 INF [TCP] connected lAddr=192.168.10.100:57825 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:21:49 INF [TCP] connected lAddr=192.168.10.100:57827 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:21:54 INF [TCP] connected lAddr=192.168.10.100:57828 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:21:59 INF [TCP] connected lAddr=192.168.10.100:57830 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:03 INF [TCP] connected lAddr=192.168.10.100:57831 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:08 INF [TCP] connected lAddr=192.168.10.100:57832 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:09 INF [TCP] connected lAddr=192.168.10.100:57833 rAddr=fd.api.iris.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:22:11 INF [TCP] connected lAddr=192.168.10.100:57837 rAddr=fp.msedge.net:443 mode=rule rule=DomainSuffix(msedge.net) proxy=Ⓜ️微软苹果[DIRECT]
00:22:13 INF [TCP] connected lAddr=192.168.10.100:57873 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:13 INF [TCP] connected lAddr=192.168.10.5:44284 rAddr=1.1.1.1:853 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:13 INF [TCP] connected lAddr=192.168.10.100:57887 rAddr=a-ring-fallback.msedge.net:443 mode=rule rule=DomainSuffix(msedge.net) proxy=Ⓜ️微软苹果[DIRECT]
00:22:14 INF [TCP] connected lAddr=192.168.10.100:57889 rAddr=jnb23prdapp01-canary-opaph.netmon.azure.com:443 mode=rule rule=DomainSuffix(azure.com) proxy=Ⓜ️微软苹果[DIRECT]
00:22:15 INF [TCP] connected lAddr=192.168.10.100:57900 rAddr=77f3484f5000cfe8d7e34854abb57bbd.azr.footprintdns.com:443 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:18 INF [TCP] connected lAddr=192.168.10.100:57920 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:22 INF [TCP] connected lAddr=192.168.10.100:57946 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:27 INF [TCP] connected lAddr=192.168.10.100:57948 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:32 INF [TCP] connected lAddr=192.168.10.100:57950 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:36 INF [TCP] connected lAddr=192.168.10.100:57958 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:41 INF [TCP] connected lAddr=192.168.10.100:57963 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:42 INF [TCP] connected lAddr=192.168.10.100:57964 rAddr=alive.github.com:443 mode=rule rule=DomainKeyword(github) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:22:45 INF [TCP] connected lAddr=192.168.10.5:53542 rAddr=1.1.1.1:853 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:45 INF [TCP] connected lAddr=192.168.10.100:57989 rAddr=api.webtest.net:443 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:46 INF [TCP] connected lAddr=192.168.10.100:57990 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:50 INF [TCP] connected lAddr=192.168.10.5:39074 rAddr=dns.google:853 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:22:50 INF [TCP] connected lAddr=192.168.10.100:57991 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:22:54 INF [TCP] connected lAddr=192.168.10.100:57992 rAddr=clients4.google.com:443 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:22:55 INF [TCP] connected lAddr=192.168.10.100:57993 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:00 INF [TCP] connected lAddr=192.168.10.100:57995 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:04 INF [TCP] connected lAddr=192.168.10.100:57997 rAddr=api.ipify.org:443 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:04 INF [TCP] connected lAddr=192.168.10.100:57998 rAddr=www.youtube.com:443 mode=rule rule=DomainSuffix(youtube.com) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:23:04 INF [TCP] connected lAddr=192.168.10.100:57999 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:07 INF [TCP] connected lAddr=192.168.10.5:38450 rAddr=1.1.1.1:853 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:08 INF [TCP] connected lAddr=192.168.10.100:58001 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:09 INF [TCP] connected lAddr=192.168.10.100:58014 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:09 INF [TCP] connected lAddr=192.168.10.100:58013 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:10 INF [TCP] connected lAddr=192.168.10.100:58023 rAddr=fd.api.iris.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:10 INF [TCP] connected lAddr=192.168.10.100:58024 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:12 WRN [TCP] dial failed error=dial tcp4 142.250.66.35:443: i/o timeout proxy=DIRECT lAddr=192.168.10.100:58000 rAddr=clientservices.googleapis.com:443 rule=Domain rulePayload=clientservices.googleapis.com
00:23:12 INF [TCP] connected lAddr=192.168.10.100:58030 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:13 INF [TCP] connected lAddr=192.168.10.100:58032 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:14 INF [TCP] connected lAddr=192.168.10.100:58033 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:14 WRN [TCP] dial failed error=dial tcp4 20.42.73.27:443: i/o timeout proxy=Ⓜ️微软苹果 lAddr=192.168.10.100:58015 rAddr=v10.events.data.microsoft.com:443 rule=DomainKeyword rulePayload=microsoft
00:23:15 INF [TCP] connected lAddr=192.168.10.100:58034 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:16 INF [TCP] connected lAddr=192.168.10.100:58035 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:17 WRN [TCP] dial failed error=dial tcp4 142.250.66.35:443: i/o timeout proxy=DIRECT lAddr=192.168.10.100:58031 rAddr=clientservices.googleapis.com:443 rule=Domain rulePayload=clientservices.googleapis.com
00:23:17 INF [TCP] connected lAddr=192.168.10.100:58039 rAddr=settings-win.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:18 INF [TCP] connected lAddr=192.168.10.100:58040 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:22 WRN [TCP] dial failed error=dial tcp4 20.42.73.27:443: i/o timeout proxy=Ⓜ️微软苹果 lAddr=192.168.10.100:58037 rAddr=v10.events.data.microsoft.com:443 rule=DomainKeyword rulePayload=microsoft
00:23:22 WRN [TCP] dial failed error=dial tcp4 142.250.66.67:80: i/o timeout proxy=DIRECT lAddr=192.168.10.100:58038 rAddr=clientservices.googleapis.com:80 rule=Domain rulePayload=clientservices.googleapis.com
00:23:23 INF [TCP] connected lAddr=192.168.10.100:58043 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:28 INF [TCP] connected lAddr=192.168.10.100:58044 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:29 INF [UDP] connected lAddr=192.168.10.104:123 rAddr=time.asia.apple.com:123 mode=rule rule=DomainSuffix(apple.com) proxy=DIRECT
00:23:29 INF [TCP] connected lAddr=192.168.10.104:50634 rAddr=26-courier.push.apple.com:5223 mode=rule rule=DomainSuffix(apple.com) proxy=DIRECT
00:23:29 INF [UDP] connected lAddr=192.168.10.104:62236 rAddr=20.189.79.72:123 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:29 INF [TCP] connected lAddr=192.168.10.104:62176 rAddr=dns.google:853 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:23:29 INF [TCP] connected lAddr=192.168.10.104:62177 rAddr=dns.google:443 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:23:31 INF [TCP] connected lAddr=192.168.10.100:58045 rAddr=v10.events.data.microsoft.com:443 mode=rule rule=DomainKeyword(microsoft) proxy=Ⓜ️微软苹果[DIRECT]
00:23:33 INF [TCP] connected lAddr=192.168.10.100:58046 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:37 INF [TCP] connected lAddr=192.168.10.100:58047 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:42 INF [TCP] connected lAddr=192.168.10.100:58048 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:47 INF [TCP] connected lAddr=192.168.10.100:58051 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:51 INF [TCP] connected lAddr=192.168.10.100:58055 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:23:56 INF [TCP] connected lAddr=192.168.10.100:58059 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:01 INF [TCP] connected lAddr=192.168.10.100:58060 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:02 INF [TCP] connected lAddr=192.168.10.5:43168 rAddr=dns.google:853 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:24:02 INF [TCP] connected lAddr=192.168.10.100:58062 rAddr=content-autofill.googleapis.com:443 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:24:05 INF [TCP] connected lAddr=192.168.10.100:58066 rAddr=api.webtest.net:443 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:05 INF [TCP] connected lAddr=192.168.10.100:58067 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:07 INF [TCP] connected lAddr=192.168.10.5:39946 rAddr=1.1.1.1:853 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:09 INF [TCP] connected lAddr=192.168.10.100:58077 rAddr=content-autofill.googleapis.com:443 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:24:10 INF [TCP] connected lAddr=192.168.10.100:58078 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:12 WRN [TCP] dial failed error=dial tcp4 216.58.200.238:443: i/o timeout proxy=🛑广告屏蔽 lAddr=192.168.10.100:58069 rAddr=www.google-analytics.com:443 rule=DomainSuffix rulePayload=google-analytics.com
00:24:15 INF [TCP] connected lAddr=192.168.10.100:58082 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:16 INF [TCP] connected lAddr=192.168.10.100:58083 rAddr=clients4.google.com:443 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:24:17 WRN [TCP] dial failed error=dial tcp4 216.58.200.238:443: i/o timeout proxy=🛑广告屏蔽 lAddr=192.168.10.100:58079 rAddr=www.google-analytics.com:443 rule=DomainSuffix rulePayload=google-analytics.com
00:24:19 INF [TCP] connected lAddr=192.168.10.100:58085 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:24 INF [TCP] connected lAddr=192.168.10.100:58086 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:29 INF [TCP] connected lAddr=192.168.10.5:40618 rAddr=raw.githubusercontent.com:443 mode=rule rule=DomainKeyword(github) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:24:29 INF [TCP] connected lAddr=192.168.10.100:58087 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:34 INF [TCP] connected lAddr=192.168.10.100:58088 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:36 INF [TCP] connected lAddr=192.168.10.5:41992 rAddr=1.1.1.1:853 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:36 INF [TCP] connected lAddr=192.168.10.5:50786 rAddr=raw.githubusercontent.com:443 mode=rule rule=DomainKeyword(github) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:24:38 DBG [TCP] accept connection lAddr=192.168.10.100:58089 rAddr=pm.youtusoft.com:80 inbound=Redir
00:24:38 DBG [Matcher] resolve success host=pm.youtusoft.com ip=15.197.204.56
00:24:38 INF [TCP] connected lAddr=192.168.10.100:58089 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:43 DBG [TCP] accept connection lAddr=192.168.10.100:58090 rAddr=pm.youtusoft.com:80 inbound=Redir
00:24:43 DBG [Matcher] resolve success host=pm.youtusoft.com ip=3.33.243.145
00:24:43 INF [TCP] connected lAddr=192.168.10.100:58090 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:24:44 DBG [DNS] dns response source=127.0.0.1:5335 qType=A name=alive.github.com. answer=["140.82.113.25"]
00:24:44 DBG [TCP] accept connection lAddr=192.168.10.100:58091 rAddr=alive.github.com:443 inbound=Redir
00:24:44 INF [TCP] connected lAddr=192.168.10.100:58091 rAddr=alive.github.com:443 mode=rule rule=DomainKeyword(github) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:39:03 DBG [TCP] accept connection lAddr=192.168.10.100:58523 rAddr=pm.youtusoft.com:80 inbound=Redir
00:39:03 DBG [Matcher] resolve success host=pm.youtusoft.com ip=3.33.243.145
00:39:03 INF [TCP] connected lAddr=192.168.10.100:58523 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]
00:39:07 DBG [TCP] accept connection lAddr=192.168.10.100:58525 rAddr=clients4.google.com:443 inbound=Redir
00:39:07 INF [TCP] connected lAddr=192.168.10.100:58525 rAddr=clients4.google.com:443 mode=rule rule=DomainKeyword(google) proxy=✈️墙外网站[R1-0|香港-NF|粤|负载均衡]
00:39:07 DBG [TCP] accept connection lAddr=192.168.10.100:58526 rAddr=pm.youtusoft.com:80 inbound=Redir
00:39:07 DBG [Matcher] resolve success host=pm.youtusoft.com ip=15.197.204.56
00:39:08 INF [TCP] connected lAddr=192.168.10.100:58526 rAddr=pm.youtusoft.com:80 mode=rule rule=Match() proxy=🐟其他网站[R1-0|香港-NF|粤|负载均衡]

#===================== 最近运行日志获取完成(自动切换为silent模式) =====================#

#===================== 活动连接信息 =====================#

1. SourceIP:【192.168.10.100】 - Host:【www.youtube.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【youtube.com】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】
2. SourceIP:【192.168.10.100】 - Host:【api.ipify.org】 - DestinationIP:【64.185.227.156】 - Network:【tcp】 - RulePayload:【】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】
3. SourceIP:【192.168.10.100】 - Host:【client.wns.windows.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【windows.com】 - Lastchain:【DIRECT】
4. SourceIP:【192.168.10.5】 - Host:【dns.google】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【google】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】
5. SourceIP:【192.168.10.100】 - Host:【mtalk.google.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【mtalk.google.com】 - Lastchain:【DIRECT】
6. SourceIP:【192.168.10.100】 - Host:【assets.msn.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【msn.com】 - Lastchain:【DIRECT】
7. SourceIP:【192.168.10.100】 - Host:【clients4.google.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【google】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】
8. SourceIP:【192.168.10.100】 - Host:【api.webtest.net】 - DestinationIP:【96.17.70.113】 - Network:【tcp】 - RulePayload:【】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】
9. SourceIP:【192.168.10.100】 - Host:【github.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【github】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】
10. SourceIP:【192.168.10.100】 - Host:【api-ipv4.ip.sb】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【ip.sb】 - Lastchain:【DIRECT】
11. SourceIP:【192.168.10.100】 - Host:【content-autofill.googleapis.com】 - DestinationIP:【】 - Network:【tcp】 - RulePayload:【google】 - Lastchain:【R1-0|香港-NF|粤|负载均衡】

OpenClash Config

No response

Expected Behavior

修复后可以修改配置文件,加入白名单等等

Screenshots

No response

vernesong commented 10 months ago

文件太大了

asnon commented 10 months ago

文件太大了

不过其它固件都没问题呢。。也是奇怪了。。

vernesong commented 10 months ago

sed -i '/HTTP_MAX_CONTENT/c\HTTP_MAX_CONTENT = 10241024*10' /usr/lib/lua/luci/http.lua

github-actions[bot] commented 8 months ago

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 5 days