Bypass bridge traffic in TProxy and simplify subscription refresh
Some checks failed
Build and Deploy Gateway / build-and-push (push) Failing after 1m12s
Build and Deploy Gateway / deploy (push) Has been skipped

This commit is contained in:
2026-07-11 19:48:04 +03:00
parent 198669694c
commit 457dd912d1
3 changed files with 3 additions and 6 deletions

View File

@@ -101,6 +101,7 @@ setup_tproxy() {
ipt -t mangle -N "$TPROXY_CHAIN"
ipt -t mangle -A "$TPROXY_CHAIN" -m addrtype --dst-type LOCAL -j RETURN
ipt -t mangle -A "$TPROXY_CHAIN" -m mark --mark "$TPROXY_MARK" -j RETURN
ipt -t mangle -A "$TPROXY_CHAIN" -i 'br-+' -j RETURN
# Private/local destinations stay reachable; every intercepted public packet goes to VPN.
for cidr in $BYPASS_CIDRS; do

View File

@@ -95,12 +95,7 @@ function App() {
}
async function refreshSubscription() {
try {
return await applyMutation(api.subscription.refresh);
} catch (refreshError) {
setError(refreshError.message);
throw refreshError;
}
return applyMutation(api.subscription.refresh);
}
async function forgetSubscription() {

View File

@@ -13,6 +13,7 @@ test('gateway keeps direct forwarding active while TProxy interception is switch
assert.match(entrypoint, /-p udp -j TPROXY --on-port "\$TPROXY_PORT"/);
assert.match(entrypoint, /-I FORWARD 1 -j "\$GATEWAY_FORWARD_CHAIN"/);
assert.match(entrypoint, /-I POSTROUTING 1 -j "\$GATEWAY_NAT_CHAIN"/);
assert.match(entrypoint, /-A "\$TPROXY_CHAIN" -i 'br-\+' -j RETURN/);
assert.doesNotMatch(entrypoint, /-A PREROUTING -j "\$TPROXY_CHAIN"/);
assert.doesNotMatch(entrypoint, /TPROXY_BYPASS_SOURCE_CIDRS|DIRECT_BYPASS_CACHE|ipset/);
});