Commit Graph

49 Commits

Author SHA1 Message Date
Arvin 0ed44117e6 Allow disabling GitHub download mirrors (#320) 2026-09-24 15:19:32 +08:00
Arvin a83d1325d1 Fix LAN disabled boolean handling
Text Encoding / utf8 (push) Successful in 1m7s
2026-08-24 12:02:02 +08:00
Arvin 895689c49c Merge latest master before offline asset support
Text Encoding / utf8 (push) Failing after 36s
2026-07-30 18:01:31 +08:00
Arvin 2de0456ef3 Add strict offline asset bundles 2026-07-30 17:59:35 +08:00
wnlen df806124b3 Fix Hysteria2 and AnyTLS subscription support 2026-07-30 17:34:20 +08:00
Arvin 3be0915a71 Make clash the primary CLI command 2026-07-30 17:25:15 +08:00
Arvin ef59c36521 feat: add routing mode and connectivity commands 2026-07-30 16:38:46 +08:00
Arvin e1c9ee49f0 fix: restore subscription update compatibility
Text Encoding / utf8 (push) Successful in 1m31s
2026-07-17 10:20:31 +08:00
Arvin 715c2a8356 Add Zsh current-shell proxy support
Text Encoding / utf8 (push) Successful in 1m26s
Load shell proxy functions from system-wide Zsh startup files, keep project lookup portable across Bash and Zsh, and cover enable, login restore, disable, and uninstall behavior.\n\nRefs #291\n\nCo-authored-by: Junle Chen <601122452@qq.com>
2026-07-16 17:27:40 +08:00
Arvin 89a2976495 Restore common helpers after profile fix 2026-07-16 17:13:42 +08:00
Arvin 1cea003417 Fix system profile permission errors
Skip sourcing project aliases from the global profile when the system install lives in an unreadable directory such as /root. Add regression coverage for readable and restricted project paths.

Refs #292
2026-07-16 16:51:11 +08:00
Arvin 58706dbe9d Fix download fallback handling 2026-07-04 21:26:30 +08:00
Arvin d9fcb67f43 Fix reported install, select, and zsh completion bugs 2026-07-02 11:51:01 +08:00
Arvin e8206046fa Improve GitHub download mirror visibility and pool (#273)
Text Encoding / utf8 (push) Successful in 1m1s
- Add kkgithub.com (hostpath) to the default mirror pool alongside the
  existing gh-proxy.org / ghfast.top / ghproxy.net entries; all four
  verified reachable and capable of proxying GitHub release downloads.

- Add doctor_download_mirrors() section to 'clashctl doctor': shows
  whether a custom mirror (CLASH_GH_PROXY / CLASH_GH_PROXY_POOL) is
  active or the built-in pool is in use, last successful/failed mirror
  URL from the state file, and a one-liner hint for setting a custom
  mirror prefix.

- README: add 'GitHub 下载加速' subsection under .env config to explain
  that all GitHub assets (kernel, GEO data, yq, subconverter, dashboard)
  automatically go through the mirror pool, document CLASH_GH_PROXY and
  CLASH_GH_PROXY_POOL env vars with examples, and point users to
  ghproxy.link for a live mirror list and 'clashctl doctor' for status.
2026-06-16 16:48:42 +08:00
Arvin 2511b1285b Fix tun on: recognize setcap capability and block sudo on user install (#267)
Problem 1 - can_manage_tun_safely() missed setcap grants:
- Add kernel_binary_has_cap_net_admin(): use getcap to detect file
  capability cap_net_admin on the kernel binary, so a user who ran
  'setcap cap_net_admin,cap_net_raw+ep mihomo' is allowed through.
- Extend can_manage_tun_safely() to call this check after the existing
  capsh (current-shell) check.
- In cmd_tun_on(), add a process-level fallback via the existing
  tun_process_has_cap_net_admin() for cases where getcap is unavailable
  but the running process already holds the capability.

Problem 2 - sudo clashctl corrupts runtime file ownership:
- Add guard_sudo_on_user_install(): detects root + SUDO_USER +
  stored install scope == user, refuses with a clear message and
  instructs the user to run as the install user directly.
- Call the guard at the entry of both cmd_tun_on() and cmd_tun_off()
  so neither write path can corrupt runtime/ file ownership.
2026-06-16 16:40:19 +08:00
Arvin 5f30fcdfef Fix multiple shell/container/port bugs (#265 #270 #271 #272 #274 #266)
#265 / #272: systemd_user_available() now requires XDG_RUNTIME_DIR and a
live D-Bus socket before probing systemctl --user, preventing false-positives
in containers (K8s/containerd) where systemctl exists but D-Bus is absent.

#274: Remove 'export' from CLASH_FOR_LINUX_SHELL_LOADED guard in profile.sh
generation so the variable stays local to the sourcing shell and does not
leak into child shells (VSCode terminal, tmux pane, bash subshell), which
was causing alias.sh to be skipped and http_proxy not exported in children.

#270: Ensure compinit is loaded before bashcompinit in the generated zsh
completion script so that compdef is available when bashcompinit registers
completions, fixing 'command not found: compdef' on zsh setups that do not
call compinit themselves.

#271: Extend container_env_type() to detect cgroups v2 + containerd/K8s
environments where /proc/1/cgroup only contains '0::/' and neither
/.dockerenv nor legacy cgroup keywords are present. Detection now also
inspects PID 1 comm and overlay root filesystem as fallbacks.

#266: resolve_runtime_ports() accepts an optional config-file hint; when
MIXED_PORT is not explicitly set in the environment, the port is read from
the config file being normalized. normalize_runtime_config() passes its
target file, so a user's 'mixed-port: 7899' in their subscription YAML is
preserved instead of being silently overwritten with the default 7890.
2026-06-16 16:30:38 +08:00
jawwe a488fc6435 fix dashboard and tun proxy controls 2026-05-22 17:28:42 +08:00
Arvin 9103b0d8c2 Merge pull request #254 from put-go/master
Text Encoding / utf8 (push) Successful in 22s
feat(install): resolve GEO assets via GitHub mirror proxy
2026-05-08 10:35:41 +08:00
put-go 7018217281 feat(install): resolve GEO assets via GitHub mirror proxy
mihomo 默认从 raw.githubusercontent.com 下载 GEO 数据库
(https://github.com/MetaCubeX/mihomo/blob/Meta/config/config.go#L570-L575),
在大部分国内网络环境下无法获取,导致启动失败。

复现方式:

  cat >/tmp/geosite-test.yaml <<'YAML'
  mixed-port: 7890
  allow-lan: false
  mode: rule
  log-level: debug
  proxies: []
  proxy-groups: []
  rules:
    - GEOSITE,cn,DIRECT
  YAML

  /root/clash/runtime/bin/mihomo -t -f /tmp/geosite-test.yaml -d /root/clash/runtime

报错:

  INFO Start initial configuration in progress
  INFO Geodata Loader mode: memconservative
  INFO Geosite Matcher implementation: succinct
  INFO Can't find GeoSite.dat, start download
  ERRO can't initial GeoSite: can't download GeoSite.dat:
       Get "https://release-assets.githubusercontent.com/...": context deadline exceeded
  ERRO rules[0] [GEOSITE,cn,DIRECT] error: can't download GeoSite.dat: context deadline exceeded
  configuration file /tmp/geosite-test.yaml test failed

新增 resolve_geo_assets 在安装阶段通过 GitHub 镜像池预下载全部 GEO 资产
到 RUNTIME_DIR,避免 mihomo 启动时因网络不通而失败。

资产列表对齐 mihomo GeoXUrl 默认值:
  Country.mmdb / geoip.metadb / GeoLite2-ASN.mmdb / GeoIP.dat / GeoSite.dat

- 复用 copy_bundled_asset 优先从 resources/geo/ 复制
- 本地不存在时通过 download_file 走 default_github_mirror_pool 镜像加速
- copy_bundled_asset 增加 $RESOURCE_DIR/$category/$file 搜索路径
2026-05-07 17:51:22 +08:00
Arvin f230876fd5 Merge pull request #251 from put-go/master
Text Encoding / utf8 (push) Successful in 1m6s
Update subconverter release source
2026-05-07 12:52:52 +08:00
yangtaowillv ea04c4da23 feat: add ALLOW-LAN; command: clashctl lan status/on/off 2026-05-07 11:06:48 +08:00
put-go e4fd9a60aa Update subconverter release source 2026-05-06 12:09:58 +08:00
wnlen 30f78ebb17 fix: block unsafe sudo auto install and prevent doctor from rewriting env 2026-04-29 17:58:53 +08:00
wnlen 3d6a523d90 feat: add single-line progress for subscription add flow 2026-04-29 12:02:07 +08:00
wnlen 8938aaf06e fix: block WSL installs under Windows mount paths 2026-04-29 11:04:57 +08:00
Arvin 631cf35354 feat(completion): add bash and zsh completions 2026-04-24 22:23:47 +08:00
wnlen 80f11383ac fix: install clashon wrappers and clarify post-install shell behavior 2026-04-20 17:04:11 +08:00
Arvin ec3e8741a5 Update common.sh 2026-04-15 00:36:19 +08:00
Arvin f28bf1b7ec Improve install messaging for mixed-port bind denied 2026-04-14 11:36:09 +08:00
Arvin 2eecb201b2 docs: document local file subscriptions and restore progress bar 2026-04-13 23:41:24 +08:00
Arvin c2bfdbc3e9 feat: prefer bundled assets for mihomo runtime deps 2026-04-13 23:18:57 +08:00
Arvin e3d81de323 fix(openwrt): gate bash alias loading in profile 2026-04-12 23:44:09 +08:00
Arvin 8b58d2e2c1 Add relay CLI for multi-hop proxy groups 2026-04-12 21:23:33 +08:00
Arvin 497a7f3d8f Add OpenWrt script-mode compatibility 2026-04-12 20:45:22 +08:00
Arvin 77b454d6b6 feat: refine install flow, TUN experience, and command UX 2026-04-12 18:24:35 +08:00
Arvin b11b3bffef refine clashctl main path UX and runtime config flow 2026-04-12 15:59:06 +08:00
Arvin 9025dfb7ff Fix: Converge the clashctl CLI and address issues with subscriptions, UI, and the proxy main link. 2026-04-12 09:37:59 +08:00
Arvin ceb297aa26 Merge branch 'dev' into codex/establish-codex-bootstrap-document-lictjq 2026-04-10 15:26:10 +08:00
Arvin fa90062971 fix: warn when clashon wrapper cannot persist parent shell env 2026-04-10 15:25:17 +08:00
wnlen 4c471b7a95 Update common.sh 2026-04-10 14:40:17 +08:00
Arvin 01638e4473 fix: restore required env baseline variables 2026-04-10 11:58:29 +08:00
Arvin 440f5fceb1 Update common.sh 2026-04-09 23:16:55 +08:00
wnlen 2b4c869aea Update common.sh 2026-04-09 17:40:38 +08:00
wnlen 7251f2332c Update common.sh 2026-04-09 17:25:00 +08:00
wnlen b9d8437190 Update common.sh 2026-04-09 14:37:53 +08:00
Arvin 0dfc264411 Merge branch 'dev' into codex/refactor-to-active-only-architecture-qpp4w8 2026-04-09 13:58:01 +08:00
Arvin 3a8d460de7 Add configurable mihomo download source overrides 2026-04-09 13:55:05 +08:00
Arvin 2a5cd3da8a refactor(migration): auto-clean legacy subscription and env compat fields 2026-04-09 10:01:51 +08:00
wnlen bc97b0a2cd refactor: rebuild project architecture and codebase 2026-04-08 15:53:52 +08:00