Merge pull request #844 from midoks/dev

PHP85 openssl bug解决
This commit is contained in:
Mr Chen
2025-12-11 15:43:54 +08:00
committed by GitHub
23 changed files with 608 additions and 18 deletions
+1
View File
@@ -195,3 +195,4 @@ plugins/goedge-happy
/plugins/tools
/plugins/choose-linux-python
*.md5
/bak
+48
View File
@@ -0,0 +1,48 @@
[general]
# 监听地址和端口
listen_addr = "0.0.0.0:8080"
# DoH 路径
path = "/dns-query"
# TLS 配置(如果需要 HTTPS)
# tls_cert_path = "/etc/doh-proxy/cert.pem"
# tls_key_path = "/etc/doh-proxy/key.pem"
# 并发请求限制
max_concurrent_requests = 512
# 日志文件
log_file = "{$SERVER_PATH}/doh/doh-proxy.log"
[upstream]
# 上游 DNS 服务器
upstream_addr = "1.1.1.1:443"
bootstrap_addr = "1.1.1.1:53"
# 上游 DoH 服务器 URL(如果使用标准的 DoH 端点)
# upstream_url = "https://cloudflare-dns.com/dns-query"
# 超时设置
timeout = 10
# 重试次数
tries = 3
# 启用 TCP 保活
tcp_keepalive = 30
[cache]
# 缓存设置
max_entries = 65536
min_ttl = 60
max_ttl = 3600
[network]
# 网络设置
tcp_fastopen = true
reuse_port = true
[log]
# 日志级别:debug, info, warn, error
level = "info"
Binary file not shown.

After

Width:  |  Height:  |  Size: 4.3 KiB

+26
View File
@@ -0,0 +1,26 @@
<style>
.overflow_hide {
overflow: hidden;
text-overflow: ellipsis;
white-space: nowrap;
vertical-align: middle;
}
</style>
<div class="bt-form">
<div class="bt-w-main">
<div class="bt-w-menu">
<p class="bgw" onclick="pluginService('doh');">服务</p>
<p onclick="pluginInitD('doh');">自启动</p>
<p onclick="dohRead();">使用说明</p>
</div>
<div class="bt-w-con pd15">
<div class="soft-man-con"></div>
</div>
</div>
</div>
<script type="text/javascript">
resetPluginWinHeight(530);
$.getScript( "/plugins/file?name=doh&f=js/doh.js",function(){
pluginService('doh');
});
</script>
+248
View File
@@ -0,0 +1,248 @@
# coding: utf-8
import time
import os
import sys
import re
import subprocess
web_dir = os.getcwd() + "/web"
if os.path.exists(web_dir):
sys.path.append(web_dir)
os.chdir(web_dir)
import core.mw as mw
app_debug = False
if mw.isAppleSystem():
app_debug = True
def getPluginName():
return 'doh'
def getPluginDir():
return mw.getPluginDir() + '/' + getPluginName()
def getServerDir():
return mw.getServerDir() + '/' + getPluginName()
def getInitDFile():
if app_debug:
return '/tmp/' + getPluginName()
return '/etc/init.d/' + getPluginName()
def getArgs():
args = sys.argv[2:]
tmp = {}
args_len = len(args)
if args_len == 1:
t = args[0].strip('{').strip('}')
t = t.split(':', 1)
tmp[t[0]] = t[1]
elif args_len > 1:
for i in range(len(args)):
t = args[i].split(':', 1)
tmp[t[0]] = t[1]
return tmp
def checkArgs(data, ck=[]):
for i in range(len(ck)):
if not ck[i] in data:
return (False, mw.returnJson(False, '参数:(' + ck[i] + ')没有!'))
return (True, mw.returnJson(True, 'ok'))
def getInitdConfTpl():
path = getPluginDir() + "/init.d/gitea.tpl"
return path
def getInitdConf():
path = getServerDir() + "/init.d/doh"
return path
if not os.path.exists(path):
return mw.returnJson(False, "请先安装初始化!<br/>默认地址:http://" + mw.getLocalIp() + ":3000")
return path
def getConfTpl():
path = getPluginDir() + "/config/config.toml"
return path
def status():
data = mw.execShell(
"ps -ef|grep " + getPluginName() + " |grep -v grep | grep -v python | awk '{print $2}'")
if data[0] == '':
return 'stop'
return 'start'
def getHomeDir():
if mw.isAppleSystem():
user = mw.execShell(
"who | sed -n '2, 1p' |awk '{print $1}'")[0].strip()
return '/Users/' + user
else:
return 'www'
def contentReplace(content):
service_path = mw.getServerDir()
content = content.replace('{$ROOT_PATH}', mw.getFatherDir())
content = content.replace('{$SERVER_PATH}', service_path)
return content
def initDreplace():
file_tpl = getInitdConfTpl()
service_path = mw.getServerDir()
conf_toml = getServerDir() + '/config.toml'
if not os.path.exists(conf_toml):
conf_tpl = getConfTpl()
content = mw.readFile(conf_tpl)
mw.writeFile(conf_toml, content)
# systemd
systemDir = mw.systemdCfgDir()
systemService = systemDir + '/doh.service'
systemServiceTpl = getPluginDir() + '/init.d/doh.service.tpl'
if os.path.exists(systemDir) and not os.path.exists(systemService):
service_path = mw.getServerDir()
se_content = mw.readFile(systemServiceTpl)
se_content = se_content.replace('{$SERVER_PATH}', service_path)
mw.writeFile(systemService, se_content)
mw.execShell('systemctl daemon-reload')
log_path = getServerDir() + '/log'
if not os.path.exists(log_path):
os.mkdir(log_path)
return ''
def appOp(method):
initDreplace()
if not mw.isAppleSystem():
data = mw.execShell('systemctl ' + method + ' ' + getPluginName())
if data[1] == '':
return 'ok'
return 'fail'
return "fail"
def start():
return appOp('start')
def stop():
return appOp('stop')
def restart():
return appOp('restart')
def reload():
return appOp('reload')
def initdStatus():
if mw.isAppleSystem():
return "Apple Computer does not support"
shell_cmd = 'systemctl status ' + getPluginName() + ' | grep loaded | grep "enabled;"'
data = mw.execShell(shell_cmd)
if data[0] == '':
return 'fail'
return 'ok'
def initdInstall():
if mw.isAppleSystem():
return "Apple Computer does not support"
mw.execShell('systemctl enable ' + getPluginName())
return 'ok'
def initdUinstall():
if mw.isAppleSystem():
return "Apple Computer does not support"
mw.execShell('systemctl disable ' + getPluginName())
return 'ok'
def runLog():
log_path = getServerDir() + '/log/doh.log'
return log_path
def getTotalStatistics():
st = status()
data = {}
if st.strip() == 'start':
list_count = pQuery('select count(id) as num from repository')
count = list_count[0]["num"]
data['status'] = True
data['count'] = count
data['ver'] = mw.readFile(getServerDir() + '/version.pl').strip()
return mw.returnJson(True, 'ok', data)
data['status'] = False
data['count'] = 0
return mw.returnJson(False, 'fail', data)
def uninstallPreInspection():
return 'ok'
if __name__ == "__main__":
func = sys.argv[1]
if func == 'status':
print(status())
elif func == 'start':
print(start())
elif func == 'stop':
print(stop())
elif func == 'restart':
print(restart())
elif func == 'reload':
print(reload())
elif func == 'initd_status':
print(initdStatus())
elif func == 'initd_install':
print(initdInstall())
elif func == 'initd_uninstall':
print(initdUinstall())
elif func == 'uninstall_pre_inspection':
print(uninstallPreInspection())
elif func == 'run_log':
print(runLog())
elif func == 'post_receive_log':
print(postReceiveLog())
elif func == 'conf':
print(getConf())
elif func == 'init_conf':
print(getInitdConf())
elif func == 'get_total_statistics':
print(getTotalStatistics())
else:
print('fail')
+18
View File
@@ -0,0 +1,18 @@
{
"ps": "DNS over HTTPS(DoH)是一种通过HTTPS协议加密域名解析请求的技术!",
"name": "doh",
"title": "DoH",
"versions": ["0.9.15"],
"tip": "soft",
"install_pre_inspection":false,
"uninstall_pre_inspection":true,
"checks": "server/doh",
"path":"server/doh",
"author": "doh",
"date": "2025-11-23",
"home": "https://github.com/DNSCrypt/doh-server",
"type": "doh",
"shell": "install.sh",
"pid": "4",
"sort": 7
}
+21
View File
@@ -0,0 +1,21 @@
[Unit]
Description=DOH(DNS over HTTPS)
After=syslog.target
After=network.target
[Service]
RestartSec=2s
Type=simple
User=www
Group=www
WorkingDirectory={$SERVER_PATH}/doh
# /www/server/doh/doh-proxy -u 127.0.0.1:53 -l 127.0.0.1:3000
# /www/server/doh/doh-proxy -h
ExecStart={$SERVER_PATH}/doh/doh-proxy -u 127.0.0.1:53 -l 127.0.0.1:3000
Restart=always
RemainAfterExit=yes
#AmbientCapabilities=CAP_NET_BIND_SERVICE
#CapabilityBoundingSet=CAP_NET_BIND_SERVICE
[Install]
WantedBy=multi-user.target
+102
View File
@@ -0,0 +1,102 @@
#!/bin/bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
curPath=`pwd`
rootPath=$(dirname "$curPath")
rootPath=$(dirname "$rootPath")
serverPath=$(dirname "$rootPath")
if [ -f ${rootPath}/bin/activate ];then
source ${rootPath}/bin/activate
fi
# cd /www/server/mdserver-web/plugins/doh && bash install.sh install 0.9.15
# /www/server/doh/doh-proxy --config /www/server/doh/config.toml
# /www/server/doh/doh-proxy --config /www/server/doh/config.toml --check
# /www/server/doh/doh-proxy -u 127.0.0.1:53 -l 127.0.0.1:3000
# 详细状态信息
# sudo systemctl status doh -l
# 查看完整日志
# sudo journalctl -u doh -n 100
# 实时日志跟踪
# sudo journalctl -u doh -f
URL_DOWNLOAD=https://github.com/DNSCrypt/doh-server/releases/download
bash ${rootPath}/scripts/getos.sh
OSNAME=`cat ${rootPath}/data/osname.pl`
OSNAME_ID=`cat /etc/*-release | grep VERSION_ID | awk -F = '{print $2}' | awk -F "\"" '{print $2}'`
Install_App()
{
mkdir -p $serverPath/source/doh
echo '正在安装脚本文件...'
version=$1
if [ "macos" == "$OSNAME" ];then
echo "not support!"
exit
else
file=doh-proxy_${version}_linux-x86_64
fi
# https://github.com/DNSCrypt/doh-server/releases/download/0.9.15/doh-proxy_0.9.15_linux-aarch64.tar.bz2
file_xz="${file}.tar.bz2"
echo "wget -O $serverPath/source/doh/$file_xz ${URL_DOWNLOAD}/${version}/${file_xz}"
if [ ! -f $serverPath/source/doh/$file_xz ];then
wget --no-check-certificate -O $serverPath/source/doh/$file_xz ${URL_DOWNLOAD}/${version}/${file_xz}
fi
if [ -f $serverPath/source/doh/$file_xz ];then
cd $serverPath/source/doh && tar -xjf $file_xz
fi
echo "mv $serverPath/source/doh/doh-proxy $serverPath/doh"
if [ -f $serverPath/source/doh/doh-proxy ];then
mv $serverPath/source/doh/doh-proxy $serverPath/doh
fi
if [ -d $serverPath/doh ];then
echo $version > $serverPath/doh/version.pl
cd ${rootPath} && python3 plugins/doh/index.py start
cd ${rootPath} && python3 plugins/doh/index.py initd_install
fi
echo 'install doh success'
}
Uninstall_App()
{
if [ -f /usr/lib/systemd/system/doh.service ];then
systemctl stop doh
systemctl disable doh
rm -rf /usr/lib/systemd/system/doh.service
systemctl daemon-reload
fi
rm -rf $serverPath/doh
echo 'uninstall doh success'
}
action=$1
version=$2
if [ "${1}" == 'install' ];then
Install_App $version
else
Uninstall_App $version
fi
+37
View File
@@ -0,0 +1,37 @@
function dohPost(method,args,callback, title){
var _args = null;
if (typeof(args) == 'string'){
_args = JSON.stringify(toArrayObject(args));
} else {
_args = JSON.stringify(args);
}
var _title = '正在获取...';
if (typeof(title) != 'undefined'){
_title = title;
}
var loadT = layer.msg(_title, { icon: 16, time: 0, shade: 0.3 });
$.post('/plugins/run', {name:'doh', func:method, args:_args}, function(data) {
layer.close(loadT);
if (!data.status){
layer.msg(data.msg,{icon:0,time:2000,shade: [0.3, '#000']});
return;
}
if(typeof(callback) == 'function'){
callback(data);
}
},'json');
}
function dohRead(){
var readme = '<ul class="help-info-text c7">';
readme += '<li>DNS服务</li>';
readme += '</ul>';
$('.soft-man-con').html(readme);
}
+2
View File
@@ -0,0 +1,2 @@
🌐 Custom DoH Proxy
Use /dns-query endpoint
+1 -2
View File
@@ -22,7 +22,7 @@ Install_App()
APP_DIR=${serverPath}/source/haproxy
mkdir -p $APP_DIR
echo $MIN_VERSION > $serverPath/haproxy/version.pl
LOCAL_ADDR=common
cn=$(curl -fsSL -m 10 -s http://ipinfo.io/json | grep "\"country\": \"CN\"")
@@ -59,7 +59,6 @@ Install_App()
cd ${APP_DIR}/haproxy-${VERSION} && make TARGET=linux-glibc && make install PREFIX=$serverPath/haproxy
fi
echo $MIN_VERSION > $serverPath/haproxy/version.pl
echo '安装Haproxy成功'
#Haproxy日志配置
+5
View File
@@ -206,6 +206,11 @@ def confReplace():
if not os.path.exists(a_conf):
mw.writeFile(a_conf, mw.readFile(a_conf_tpl))
# copy resty lib
src_resty_dir = getPluginDir()+'/resty/*'
dst_resty_dir = getServerDir()+'/lualib/resty'
mw.execShell('cp -rf ' + src_resty_dir + ' ' + dst_resty_dir)
def initDreplace():
+1
View File
@@ -9,6 +9,7 @@ serverPath=$(dirname "$rootPath")
sysName=`uname`
# cd /www/server/mdserver-web/plugins/php && bash install.sh install 73
# cd /www/server/mdserver-web/plugins/php && bash install.sh install 85
# https://www.php.net/releases
if id www &> /dev/null ;then
+2 -2
View File
@@ -119,8 +119,8 @@ if [ "$sysName" == "Darwin" ];then
export OPENSSL_CFLAGS="-I${LIB_DEPEND_DIR}/include"
export OPENSSL_LIBS="-L/${LIB_DEPEND_DIR}/lib -lssl -lcrypto -lz"
else
cd ${rootPath}/plugins/php/lib && /bin/bash openssl_30.sh
export PKG_CONFIG_PATH=$PKG_CONFIG_PATH:$serverPath/lib/openssl30/lib/pkgconfig
cd ${rootPath}/plugins/php/lib && /bin/bash openssl_35.sh
export PKG_CONFIG_PATH=$PKG_CONFIG_PATH:$serverPath/lib/openssl35/lib/pkgconfig
OPTIONS="$OPTIONS --with-openssl"
fi
+3 -2
View File
@@ -120,8 +120,9 @@ if [ "$sysName" == "Darwin" ];then
export OPENSSL_CFLAGS="-I${LIB_DEPEND_DIR}/include"
export OPENSSL_LIBS="-L/${LIB_DEPEND_DIR}/lib -lssl -lcrypto -lz"
else
cd ${rootPath}/plugins/php/lib && /bin/bash openssl_30.sh
export PKG_CONFIG_PATH=$PKG_CONFIG_PATH:$serverPath/lib/openssl30/lib/pkgconfig
echo "lib"
cd ${rootPath}/plugins/php/lib && /bin/bash openssl_35.sh
export PKG_CONFIG_PATH=$PKG_CONFIG_PATH:$serverPath/lib/openssl35/lib/pkgconfig
OPTIONS="$OPTIONS --with-openssl"
fi
+5
View File
@@ -21,6 +21,11 @@ if [ "$version" -lt "70" ];then
LIBV=2.2.0
fi
if [ "$version" == "85" ];then
LIBV=3.4.0
fi
LIB_PATH_NAME=lib/php
if [ -d $serverPath/php/${version}/lib64 ];then
LIB_PATH_NAME=lib64
+2 -2
View File
@@ -12,7 +12,7 @@ serverPath=$(dirname "$rootPath")
sourcePath=${serverPath}/source/php
SYS_ARCH=`arch`
LIBNAME=redis
LIBV=6.1.0
LIBV=6.3.0
sysName=`uname`
actionType=$1
version=$2
@@ -24,7 +24,7 @@ elif [ "$version" -lt "70" ];then
elif [ "$version" -lt "80" ];then
LIBV=5.3.7
elif [ "$version" -gt "80" ];then
LIBV=6.1.0
LIBV=6.3.0
else
echo 'ok'
fi
-4
View File
@@ -45,10 +45,6 @@ def send_msg(bot, tag='ad', trigger_time=300):
mw.writeFile(lock_file, json.dumps(lock_data))
# 信号只在一个周期内执行一次|end
keyboard = [
[
types.InlineKeyboardButton(
text="官方收劫持|SEO", url='https://t.me/xiaosi876')
],
[
types.InlineKeyboardButton(
text="高价收一切流量 @caifutong555", url='https://t.me/caifutong555')
@@ -54,16 +54,11 @@ def send_msg(bot, tag='ad', trigger_time=300):
mw.writeFile(lock_file, json.dumps(lock_data))
# 信号只在一个周期内执行一次|end
# 官方收劫持|SEO| 6m | next,2/6 | @tlx104
# https://t.me/gjgzs2022 | 22/m | @GJ_gzs
# 实名认证/过人脸🕵️‍♀️各种账号处理✅ | 30/m| next,12/30 | @nngzs
# 18+资源采集| 4/m | next,1/14 | @liuxingyu123
keyboard = [
[
types.InlineKeyboardButton(
text="官方收劫持|SEO", url='https://t.me/xiaosi876')
],
[
types.InlineKeyboardButton(
text="高价收一切流量 @caifutong555", url='https://t.me/caifutong555')
+5
View File
@@ -0,0 +1,5 @@
location /dns-query {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
+28
View File
@@ -0,0 +1,28 @@
# 在http目录下配置
# lua_shared_dict obf_cache 64m;
# 混淆配置
body_filter_by_lua_block {
local obf = require("resty.obf.obf")
obf.process_response()
}
location / {
#set $close_close 'true'; # 关闭 关闭开关
#set $debug_close 'true'; # 关闭 开始调试
set $obf_js_mode 'inline'; # 解密模式 link:链接, inline:内链模式
set $obf_js_url 'https://cdn.jsdelivr.net/npm/node-forge@1.3.1/dist/forge.min.js?v=1'; # 自定义解密js地址,tips: forge
set $obf_timeout 600; # 缓存时间
set $obf_rand_var 'true'; # 随机变量
set $obf_rand_extra 'true'; # 随机混淆内容
set $obf_uint8_b64 'false'; # 是Uint8Array,否base64
#set $obf_prof 'true'; # 测试时间消耗记录
set $obf_cache_item_max 0; # 缓存多少
set $obf_cache_max_bytes 16777216; # 缓存字节大小
if (!-e $request_filename) {
rewrite ^(.*)$ /index.php/$1 last;
break;
}
}
+38
View File
@@ -0,0 +1,38 @@
# 在http目录下配置
# lua_shared_dict obf_cache 64m;
# 混淆配置-代理
body_filter_by_lua_block {
local obf = require("resty.obf.obf")
obf.process_response()
}
location / {
proxy_pass http://127.0.0.1:8989;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_hide_header Content-Encoding;
#gzip off;
proxy_set_header Accept-Encoding "";
proxy_set_header If-Modified-Since "";
proxy_set_header If-None-Match "";
#set $close_close 'true';
#set $debug_close 'true';
set $obf_js_mode 'inline';
set $obf_js_url '';
set $obf_timeout 600;
set $obf_rand_var 'true';
set $obf_rand_extra 'true';
set $obf_uint8_b64 'true';
set $obf_prof 'true';
set $obf_cache_item_max 0;
set $obf_cache_max_bytes 16777216;
set $obf_kdf_raw 'false';
header_filter_by_lua_block {
ngx.header.content_length = nil
}
}
+15 -1
View File
@@ -2931,7 +2931,21 @@ function rewrite(siteName){
$("#webedit-con").html(webBakHtml);
var editor = CodeMirror.fromTextArea(document.getElementById("rewriteBody"), {
extraKeys: {"Ctrl-Space": "autocomplete"},
extraKeys: {
"Ctrl-Space": "autocomplete",
"Ctrl-F": "findPersistent",
"Ctrl-H": "replaceAll",
"Ctrl-S": function() {
$("#rewriteBody").empty();
$("#rewriteBody").text(editor.getValue());
setRewrite(filename, encodeURIComponent(editor.getValue()));
},
"Cmd-S":function() {
$("#rewriteBody").empty();
$("#rewriteBody").text(editor.getValue());
setRewrite(filename, encodeURIComponent(editor.getValue()));
},
},
lineNumbers: true,
matchBrackets:true,
});