Commit Graph

617 Commits

Author SHA1 Message Date
Arvin 18e6fb6fb3 Fix yq-incompatible subscription rename (#321)
mikefarah/yq does not support jq-style if/then/else expressions, so every subscription rename failed during expression parsing. Use with(select(...)) for the conditional active-source update and cover active and non-active renames with a real yq regression check.
2026-09-24 15:33:21 +08:00
Arvin 348a36f175 Merge pull request #322 from wnlen/codex/fix-320-disable-github-mirror
Allow disabling GitHub download mirrors (#320)
2026-09-24 15:27:10 +08:00
Arvin 0ed44117e6 Allow disabling GitHub download mirrors (#320) 2026-09-24 15:19:32 +08:00
Arvin a83d1325d1 Fix LAN disabled boolean handling
Text Encoding / utf8 (push) Successful in 1m7s
2026-08-24 12:02:02 +08:00
Arvin 9c740af88f Fix Star History chart embed
Text Encoding / utf8 (push) Successful in 40s
2026-08-20 12:12:53 +08:00
Arvin e858ec2f5e Fix TUN status with auto-redirect disabled
Text Encoding / utf8 (push) Successful in 55s
2026-08-19 09:37:42 +08:00
Arvin bbe2753a02 Fix TUN doctor systemd capability detection
Text Encoding / utf8 (push) Successful in 54s
Use the running Mihomo process capability for systemd doctor warnings while keeping the shell requirement for script backends.\n\nFixes #307
2026-08-16 18:54:57 +08:00
Arvin 712b77a43a Fix TUN proxy-off shell restore state
tun on-proxy-off cleared the system proxy block but left the shell restore flag enabled, so new login shells re-injected proxy variables. Disable both persistence layers and retain cleanup errors.\n\nFixes #308
2026-08-16 17:07:13 +08:00
Arvin d95661f295 Fix TUN policy-routing status detection
Text Encoding / utf8 (push) Failing after 1m44s
Unify TUN status classification around policy-routing evidence and wait for the controller before post-restart verification. Add a regression check for Issue #303.
2026-08-11 17:41:14 +08:00
Arvin 895689c49c Merge latest master before offline asset support
Text Encoding / utf8 (push) Failing after 36s
2026-07-30 18:01:31 +08:00
Arvin 2de0456ef3 Add strict offline asset bundles 2026-07-30 17:59:35 +08:00
wnlen df806124b3 Fix Hysteria2 and AnyTLS subscription support 2026-07-30 17:34:20 +08:00
Arvin 3be0915a71 Make clash the primary CLI command 2026-07-30 17:25:15 +08:00
Arvin ef59c36521 feat: add routing mode and connectivity commands 2026-07-30 16:38:46 +08:00
Arvin e1c9ee49f0 fix: restore subscription update compatibility
Text Encoding / utf8 (push) Successful in 1m31s
2026-07-17 10:20:31 +08:00
Arvin 06697222d1 Clarify dashboard browser egress IP
Text Encoding / utf8 (push) Successful in 2m25s
2026-07-17 09:27:00 +08:00
Arvin 715c2a8356 Add Zsh current-shell proxy support
Text Encoding / utf8 (push) Successful in 1m26s
Load shell proxy functions from system-wide Zsh startup files, keep project lookup portable across Bash and Zsh, and cover enable, login restore, disable, and uninstall behavior.\n\nRefs #291\n\nCo-authored-by: Junle Chen <601122452@qq.com>
2026-07-16 17:27:40 +08:00
Arvin 89a2976495 Restore common helpers after profile fix 2026-07-16 17:13:42 +08:00
Arvin 1cea003417 Fix system profile permission errors
Skip sourcing project aliases from the global profile when the system install lives in an unreadable directory such as /root. Add regression coverage for readable and restricted project paths.

Refs #292
2026-07-16 16:51:11 +08:00
Arvin 57b3ec0c92 Speed up controller failure path
Text Encoding / utf8 (push) Successful in 1m2s
2026-07-04 21:41:22 +08:00
Arvin 58706dbe9d Fix download fallback handling 2026-07-04 21:26:30 +08:00
Arvin 1ed7b86dd2 Merge pull request #289 from wnlen/fix/doctor-stale-systemd-unit
Text Encoding / utf8 (push) Successful in 50s
Detect stale systemd service templates in doctor
2026-07-02 17:32:05 +08:00
Arvin f782fbc7e0 Detect stale systemd service templates in doctor 2026-07-02 17:30:55 +08:00
Arvin df859b0a6d Merge pull request #288 from wnlen/fix/issue-287-systemd-boot
Fix systemd boot runtime supervision
2026-07-02 17:11:33 +08:00
Arvin 9ac17a58c4 Fix systemd boot runtime supervision 2026-07-02 17:10:19 +08:00
Arvin 6abf500713 Merge pull request #286 from wnlen/fix/reported-user-issues
Text Encoding / utf8 (push) Successful in 1m2s
Fix reported install, select, and zsh completion bugs
2026-07-02 11:55:24 +08:00
Arvin d9fcb67f43 Fix reported install, select, and zsh completion bugs 2026-07-02 11:51:01 +08:00
Arvin faed32a6c4 Improve uninstall cleanup flow
Text Encoding / utf8 (push) Failing after 2m58s
2026-06-27 12:14:36 +08:00
Arvin 4539f2c7f2 Default to GEO predownload
Text Encoding / utf8 (push) Failing after 34s
2026-06-25 10:44:06 +08:00
Arvin b1eb86038a Skip GEO predownload by default 2026-06-25 10:34:57 +08:00
Arvin 12b465c02e Fix clashoff stopping runtime 2026-06-25 10:31:49 +08:00
Arvin dd0bcb3999 feat(shell): add auto-restore proxy toggle
Text Encoding / utf8 (push) Failing after 1m40s
2026-06-17 22:37:24 +08:00
Arvin e994cc4c27 test(config): cover runtime port normalization 2026-06-17 22:32:03 +08:00
Larry Hao(郝卓远) 53cff332b9 fix(config): 规范化时剥离 subconverter 注入的 port/socks-port/redir-port,只保留 mixed-port (#276)
* fix(config): drop subconverter-injected port/socks-port/redir-port so only mixed-port is kept

The bundled subconverter base templates hard-code a static listener block
(port/socks-port/redir-port, with socks-port=7891). normalize_runtime_config
only rewrites mixed-port and leaves that block in the generated config, while
resolve_runtime_ports does not know those ports exist. On a busy shared host
where 7890 is already taken, the auto-resolver shifts mixed-port to 7891 and it
collides with the injected socks-port=7891. mihomo then binds socks on 7891 and
silently fails to bind the mixed (http) listener, so the port clashctl exports
as http_proxy has no HTTP handler and every request dies with
"curl: (56) Proxy CONNECT aborted".

Strip the legacy listener keys during normalization so the framework's single
auto-managed mixed-port is the only proxy listener, which is what the default
template already intends.

* refactor(config): consolidate legacy port deletion into a single del() call

Addresses Copilot review feedback on #276. Verified the bundled yq v4.52.4
supports deleting multiple paths in one del() expression.
2026-06-17 22:23:41 +08:00
Arvin e8206046fa Improve GitHub download mirror visibility and pool (#273)
Text Encoding / utf8 (push) Successful in 1m1s
- Add kkgithub.com (hostpath) to the default mirror pool alongside the
  existing gh-proxy.org / ghfast.top / ghproxy.net entries; all four
  verified reachable and capable of proxying GitHub release downloads.

- Add doctor_download_mirrors() section to 'clashctl doctor': shows
  whether a custom mirror (CLASH_GH_PROXY / CLASH_GH_PROXY_POOL) is
  active or the built-in pool is in use, last successful/failed mirror
  URL from the state file, and a one-liner hint for setting a custom
  mirror prefix.

- README: add 'GitHub 下载加速' subsection under .env config to explain
  that all GitHub assets (kernel, GEO data, yq, subconverter, dashboard)
  automatically go through the mirror pool, document CLASH_GH_PROXY and
  CLASH_GH_PROXY_POOL env vars with examples, and point users to
  ghproxy.link for a live mirror list and 'clashctl doctor' for status.
2026-06-16 16:48:42 +08:00
Arvin 2511b1285b Fix tun on: recognize setcap capability and block sudo on user install (#267)
Problem 1 - can_manage_tun_safely() missed setcap grants:
- Add kernel_binary_has_cap_net_admin(): use getcap to detect file
  capability cap_net_admin on the kernel binary, so a user who ran
  'setcap cap_net_admin,cap_net_raw+ep mihomo' is allowed through.
- Extend can_manage_tun_safely() to call this check after the existing
  capsh (current-shell) check.
- In cmd_tun_on(), add a process-level fallback via the existing
  tun_process_has_cap_net_admin() for cases where getcap is unavailable
  but the running process already holds the capability.

Problem 2 - sudo clashctl corrupts runtime file ownership:
- Add guard_sudo_on_user_install(): detects root + SUDO_USER +
  stored install scope == user, refuses with a clear message and
  instructs the user to run as the install user directly.
- Call the guard at the entry of both cmd_tun_on() and cmd_tun_off()
  so neither write path can corrupt runtime/ file ownership.
2026-06-16 16:40:19 +08:00
Arvin 5f30fcdfef Fix multiple shell/container/port bugs (#265 #270 #271 #272 #274 #266)
#265 / #272: systemd_user_available() now requires XDG_RUNTIME_DIR and a
live D-Bus socket before probing systemctl --user, preventing false-positives
in containers (K8s/containerd) where systemctl exists but D-Bus is absent.

#274: Remove 'export' from CLASH_FOR_LINUX_SHELL_LOADED guard in profile.sh
generation so the variable stays local to the sourcing shell and does not
leak into child shells (VSCode terminal, tmux pane, bash subshell), which
was causing alias.sh to be skipped and http_proxy not exported in children.

#270: Ensure compinit is loaded before bashcompinit in the generated zsh
completion script so that compdef is available when bashcompinit registers
completions, fixing 'command not found: compdef' on zsh setups that do not
call compinit themselves.

#271: Extend container_env_type() to detect cgroups v2 + containerd/K8s
environments where /proc/1/cgroup only contains '0::/' and neither
/.dockerenv nor legacy cgroup keywords are present. Detection now also
inspects PID 1 comm and overlay root filesystem as fallbacks.

#266: resolve_runtime_ports() accepts an optional config-file hint; when
MIXED_PORT is not explicitly set in the environment, the port is read from
the config file being normalized. normalize_runtime_config() passes its
target file, so a user's 'mixed-port: 7899' in their subscription YAML is
preserved instead of being silently overwritten with the default 7890.
2026-06-16 16:30:38 +08:00
Arvin f0043d8dcb Ignore OpenClaw control-plane local scaffolding 2026-06-16 16:19:12 +08:00
Arvin a13da0e565 Detect Tun traffic across default and parsed CIDR ranges
Generalize Tun source-IP detection in doctor log evidence: parse the
TUN adapter CIDR from logs and match traffic against it, while keeping
built-in default Tun ranges (28.x, 198.18.x, 198.19.x). Add offline
check script covering the new detection cases.
2026-06-16 16:16:12 +08:00
Arvin 83e8259edc Merge pull request #261 from jawwe/codex-fix-dashboard-tun-proxy
Text Encoding / utf8 (push) Successful in 42s
[codex] fix dashboard and tun proxy controls
2026-05-27 16:42:11 +08:00
Arvin 9e228a546c Update Tun mode installation requirements in README
Text Encoding / utf8 (push) Successful in 57m52s
Clarified the requirement for root installation for Tun mode in both the features and commands sections.
2026-05-25 17:56:55 +08:00
Arvin e795d17d0a Add references and acknowledgments section to README
Added a section for references and acknowledgments regarding the project and its inspirations.
2026-05-25 17:38:02 +08:00
jawwe a488fc6435 fix dashboard and tun proxy controls 2026-05-22 17:28:42 +08:00
Arvin 54b8387099 Update FUNDING.yml
Text Encoding / utf8 (push) Successful in 21s
2026-05-20 23:55:03 +08:00
Arvin 3bcc9fd1a0 Clarify local proxy takeover status
Text Encoding / utf8 (push) Successful in 1m4s
2026-05-15 15:43:39 +08:00
Arvin 58df80fb02 Merge pull request #255 from put-go/master
Text Encoding / utf8 (push) Successful in 44s
删除密钥和订阅应为空
2026-05-08 20:11:12 +08:00
Arvin 30d426c93e Update .env 2026-05-08 20:07:34 +08:00
put-go e8e45986a8 fix: 修复局域网代理开关持久化
clashctl lan off 原本只更新 config/template.yaml,但运行配置生成流程会在规范化之后继续应用 runtime/mixin.yaml。

如果已有 mixin override 将 allow-lan 设为 true,最终生成的 runtime/config.yaml 会被重新覆盖为 true,导致 mihomo 仍监听局域网地址。

现在将同一个 allow-lan 值同步写入 runtime mixin override,确保 lan on/off 能保留到最终合并后的运行配置。
2026-05-08 12:06:48 +08:00
put-go f4a868f723 del 2026-05-08 11:23:26 +08:00
Arvin 9103b0d8c2 Merge pull request #254 from put-go/master
Text Encoding / utf8 (push) Successful in 22s
feat(install): resolve GEO assets via GitHub mirror proxy
2026-05-08 10:35:41 +08:00