Commit Graph

591 Commits

Author SHA1 Message Date
Arvin 10adcc522e Fix reported install, select, and zsh completion bugs 2026-07-02 11:50:04 +08:00
Arvin 10bcbe1ee7 Add install scope selector 2026-06-25 12:06:07 +08:00
Arvin 4539f2c7f2 Default to GEO predownload
Text Encoding / utf8 (push) Failing after 34s
2026-06-25 10:44:06 +08:00
Arvin b1eb86038a Skip GEO predownload by default 2026-06-25 10:34:57 +08:00
Arvin 12b465c02e Fix clashoff stopping runtime 2026-06-25 10:31:49 +08:00
Arvin dd0bcb3999 feat(shell): add auto-restore proxy toggle
Text Encoding / utf8 (push) Failing after 1m40s
2026-06-17 22:37:24 +08:00
Arvin e994cc4c27 test(config): cover runtime port normalization 2026-06-17 22:32:03 +08:00
Larry Hao(郝卓远) 53cff332b9 fix(config): 规范化时剥离 subconverter 注入的 port/socks-port/redir-port,只保留 mixed-port (#276)
* fix(config): drop subconverter-injected port/socks-port/redir-port so only mixed-port is kept

The bundled subconverter base templates hard-code a static listener block
(port/socks-port/redir-port, with socks-port=7891). normalize_runtime_config
only rewrites mixed-port and leaves that block in the generated config, while
resolve_runtime_ports does not know those ports exist. On a busy shared host
where 7890 is already taken, the auto-resolver shifts mixed-port to 7891 and it
collides with the injected socks-port=7891. mihomo then binds socks on 7891 and
silently fails to bind the mixed (http) listener, so the port clashctl exports
as http_proxy has no HTTP handler and every request dies with
"curl: (56) Proxy CONNECT aborted".

Strip the legacy listener keys during normalization so the framework's single
auto-managed mixed-port is the only proxy listener, which is what the default
template already intends.

* refactor(config): consolidate legacy port deletion into a single del() call

Addresses Copilot review feedback on #276. Verified the bundled yq v4.52.4
supports deleting multiple paths in one del() expression.
2026-06-17 22:23:41 +08:00
Arvin e8206046fa Improve GitHub download mirror visibility and pool (#273)
Text Encoding / utf8 (push) Successful in 1m1s
- Add kkgithub.com (hostpath) to the default mirror pool alongside the
  existing gh-proxy.org / ghfast.top / ghproxy.net entries; all four
  verified reachable and capable of proxying GitHub release downloads.

- Add doctor_download_mirrors() section to 'clashctl doctor': shows
  whether a custom mirror (CLASH_GH_PROXY / CLASH_GH_PROXY_POOL) is
  active or the built-in pool is in use, last successful/failed mirror
  URL from the state file, and a one-liner hint for setting a custom
  mirror prefix.

- README: add 'GitHub 下载加速' subsection under .env config to explain
  that all GitHub assets (kernel, GEO data, yq, subconverter, dashboard)
  automatically go through the mirror pool, document CLASH_GH_PROXY and
  CLASH_GH_PROXY_POOL env vars with examples, and point users to
  ghproxy.link for a live mirror list and 'clashctl doctor' for status.
2026-06-16 16:48:42 +08:00
Arvin 2511b1285b Fix tun on: recognize setcap capability and block sudo on user install (#267)
Problem 1 - can_manage_tun_safely() missed setcap grants:
- Add kernel_binary_has_cap_net_admin(): use getcap to detect file
  capability cap_net_admin on the kernel binary, so a user who ran
  'setcap cap_net_admin,cap_net_raw+ep mihomo' is allowed through.
- Extend can_manage_tun_safely() to call this check after the existing
  capsh (current-shell) check.
- In cmd_tun_on(), add a process-level fallback via the existing
  tun_process_has_cap_net_admin() for cases where getcap is unavailable
  but the running process already holds the capability.

Problem 2 - sudo clashctl corrupts runtime file ownership:
- Add guard_sudo_on_user_install(): detects root + SUDO_USER +
  stored install scope == user, refuses with a clear message and
  instructs the user to run as the install user directly.
- Call the guard at the entry of both cmd_tun_on() and cmd_tun_off()
  so neither write path can corrupt runtime/ file ownership.
2026-06-16 16:40:19 +08:00
Arvin 5f30fcdfef Fix multiple shell/container/port bugs (#265 #270 #271 #272 #274 #266)
#265 / #272: systemd_user_available() now requires XDG_RUNTIME_DIR and a
live D-Bus socket before probing systemctl --user, preventing false-positives
in containers (K8s/containerd) where systemctl exists but D-Bus is absent.

#274: Remove 'export' from CLASH_FOR_LINUX_SHELL_LOADED guard in profile.sh
generation so the variable stays local to the sourcing shell and does not
leak into child shells (VSCode terminal, tmux pane, bash subshell), which
was causing alias.sh to be skipped and http_proxy not exported in children.

#270: Ensure compinit is loaded before bashcompinit in the generated zsh
completion script so that compdef is available when bashcompinit registers
completions, fixing 'command not found: compdef' on zsh setups that do not
call compinit themselves.

#271: Extend container_env_type() to detect cgroups v2 + containerd/K8s
environments where /proc/1/cgroup only contains '0::/' and neither
/.dockerenv nor legacy cgroup keywords are present. Detection now also
inspects PID 1 comm and overlay root filesystem as fallbacks.

#266: resolve_runtime_ports() accepts an optional config-file hint; when
MIXED_PORT is not explicitly set in the environment, the port is read from
the config file being normalized. normalize_runtime_config() passes its
target file, so a user's 'mixed-port: 7899' in their subscription YAML is
preserved instead of being silently overwritten with the default 7890.
2026-06-16 16:30:38 +08:00
Arvin f0043d8dcb Ignore OpenClaw control-plane local scaffolding 2026-06-16 16:19:12 +08:00
Arvin a13da0e565 Detect Tun traffic across default and parsed CIDR ranges
Generalize Tun source-IP detection in doctor log evidence: parse the
TUN adapter CIDR from logs and match traffic against it, while keeping
built-in default Tun ranges (28.x, 198.18.x, 198.19.x). Add offline
check script covering the new detection cases.
2026-06-16 16:16:12 +08:00
Arvin 83e8259edc Merge pull request #261 from jawwe/codex-fix-dashboard-tun-proxy
Text Encoding / utf8 (push) Successful in 42s
[codex] fix dashboard and tun proxy controls
2026-05-27 16:42:11 +08:00
Arvin 9e228a546c Update Tun mode installation requirements in README
Text Encoding / utf8 (push) Successful in 57m52s
Clarified the requirement for root installation for Tun mode in both the features and commands sections.
2026-05-25 17:56:55 +08:00
Arvin e795d17d0a Add references and acknowledgments section to README
Added a section for references and acknowledgments regarding the project and its inspirations.
2026-05-25 17:38:02 +08:00
jawwe a488fc6435 fix dashboard and tun proxy controls 2026-05-22 17:28:42 +08:00
Arvin 54b8387099 Update FUNDING.yml
Text Encoding / utf8 (push) Successful in 21s
2026-05-20 23:55:03 +08:00
Arvin 3bcc9fd1a0 Clarify local proxy takeover status
Text Encoding / utf8 (push) Successful in 1m4s
2026-05-15 15:43:39 +08:00
Arvin 58df80fb02 Merge pull request #255 from put-go/master
Text Encoding / utf8 (push) Successful in 44s
删除密钥和订阅应为空
2026-05-08 20:11:12 +08:00
Arvin 30d426c93e Update .env 2026-05-08 20:07:34 +08:00
put-go e8e45986a8 fix: 修复局域网代理开关持久化
clashctl lan off 原本只更新 config/template.yaml,但运行配置生成流程会在规范化之后继续应用 runtime/mixin.yaml。

如果已有 mixin override 将 allow-lan 设为 true,最终生成的 runtime/config.yaml 会被重新覆盖为 true,导致 mihomo 仍监听局域网地址。

现在将同一个 allow-lan 值同步写入 runtime mixin override,确保 lan on/off 能保留到最终合并后的运行配置。
2026-05-08 12:06:48 +08:00
put-go f4a868f723 del 2026-05-08 11:23:26 +08:00
Arvin 9103b0d8c2 Merge pull request #254 from put-go/master
Text Encoding / utf8 (push) Successful in 22s
feat(install): resolve GEO assets via GitHub mirror proxy
2026-05-08 10:35:41 +08:00
put-go 7018217281 feat(install): resolve GEO assets via GitHub mirror proxy
mihomo 默认从 raw.githubusercontent.com 下载 GEO 数据库
(https://github.com/MetaCubeX/mihomo/blob/Meta/config/config.go#L570-L575),
在大部分国内网络环境下无法获取,导致启动失败。

复现方式:

  cat >/tmp/geosite-test.yaml <<'YAML'
  mixed-port: 7890
  allow-lan: false
  mode: rule
  log-level: debug
  proxies: []
  proxy-groups: []
  rules:
    - GEOSITE,cn,DIRECT
  YAML

  /root/clash/runtime/bin/mihomo -t -f /tmp/geosite-test.yaml -d /root/clash/runtime

报错:

  INFO Start initial configuration in progress
  INFO Geodata Loader mode: memconservative
  INFO Geosite Matcher implementation: succinct
  INFO Can't find GeoSite.dat, start download
  ERRO can't initial GeoSite: can't download GeoSite.dat:
       Get "https://release-assets.githubusercontent.com/...": context deadline exceeded
  ERRO rules[0] [GEOSITE,cn,DIRECT] error: can't download GeoSite.dat: context deadline exceeded
  configuration file /tmp/geosite-test.yaml test failed

新增 resolve_geo_assets 在安装阶段通过 GitHub 镜像池预下载全部 GEO 资产
到 RUNTIME_DIR,避免 mihomo 启动时因网络不通而失败。

资产列表对齐 mihomo GeoXUrl 默认值:
  Country.mmdb / geoip.metadb / GeoLite2-ASN.mmdb / GeoIP.dat / GeoSite.dat

- 复用 copy_bundled_asset 优先从 resources/geo/ 复制
- 本地不存在时通过 download_file 走 default_github_mirror_pool 镜像加速
- copy_bundled_asset 增加 $RESOURCE_DIR/$category/$file 搜索路径
2026-05-07 17:51:22 +08:00
Arvin f230876fd5 Merge pull request #251 from put-go/master
Text Encoding / utf8 (push) Successful in 1m6s
Update subconverter release source
2026-05-07 12:52:52 +08:00
Arvin 95c13807db Merge pull request #252 from yangtaowillv/feature/add-LAN
feat: add ALLOW-LAN; command: clashctl lan status/on/off
2026-05-07 12:51:19 +08:00
yangtaowillv ea04c4da23 feat: add ALLOW-LAN; command: clashctl lan status/on/off 2026-05-07 11:06:48 +08:00
put-go e4fd9a60aa Update subconverter release source 2026-05-06 12:09:58 +08:00
Arvin bfab0b2939 Merge pull request #243 from Babylonehy/fix/proxy-sh-bugfixes
Text Encoding / utf8 (push) Successful in 31s
fix(proxy): harden strategy group selection
2026-04-30 09:03:45 +08:00
Xiang Li 25bdb43a80 fix(proxy): harden strategy group selection 2026-04-29 22:53:43 +08:00
Arvin 67a5c498af Merge pull request #242 from wnlen/dev
Text Encoding / utf8 (push) Successful in 41s
fix: block unsafe sudo auto install and prevent doctor from rewriting…
2026-04-29 20:35:09 +08:00
wnlen 30f78ebb17 fix: block unsafe sudo auto install and prevent doctor from rewriting env 2026-04-29 17:58:53 +08:00
Arvin 77f3524c83 Merge pull request #241 from wnlen/dev
Text Encoding / utf8 (push) Successful in 35s
optimize: show fixed progress bar for subscription download
2026-04-29 17:33:44 +08:00
wnlen fae7a75f7d optimize: show fixed progress bar for subscription download 2026-04-29 17:33:26 +08:00
Arvin 4b467fd93d Merge pull request #240 from wnlen/dev
fix: clear persistent system proxy during uninstall
2026-04-29 17:19:22 +08:00
Arvin 3dcf11b259 fix: clear persistent system proxy during uninstall 2026-04-29 17:19:05 +08:00
Arvin 54f3d3a524 Merge pull request #239 from wnlen/dev
Dev
2026-04-29 17:07:16 +08:00
wnlen 8be724ce33 optimize: fast enable proxy when runtime is already running 2026-04-29 17:06:59 +08:00
wnlen 42833b3ccb fix: clear system proxy during uninstall 2026-04-29 16:51:45 +08:00
wnlen f1589ee322 optimize: add fast path for already-enabled clashon 2026-04-29 16:49:09 +08:00
Arvin b08c89de6f Merge pull request #238 from wnlen/dev
Dev
2026-04-29 13:18:29 +08:00
wnlen 9ee524f873 fix: report unsupported Tun state for systemd-user backend 2026-04-29 13:18:11 +08:00
wnlen 3d6a523d90 feat: add single-line progress for subscription add flow 2026-04-29 12:02:07 +08:00
wnlen c7e6421b66 fix: Adjust the command prompt 2026-04-29 11:42:40 +08:00
Arvin a8c98c031f Merge pull request #237 from wnlen/dev
Text Encoding / utf8 (push) Successful in 41s
fix: block WSL installs under Windows mount paths
2026-04-29 11:05:48 +08:00
wnlen 8938aaf06e fix: block WSL installs under Windows mount paths 2026-04-29 11:04:57 +08:00
Arvin 26e1dea7ec Merge pull request #233 from wnlen/dev
Text Encoding / utf8 (push) Successful in 48s
fix(ui): restore utf-8 encoding and remove mojibake in select output
2026-04-25 20:12:57 +08:00
Arvin 659ac556be fix(ui): restore utf-8 encoding and remove mojibake in select output 2026-04-25 20:11:07 +08:00
Arvin 5162269633 Merge pull request #231 from wnlen/dev
Dev
2026-04-24 22:25:00 +08:00