Bypass bridge traffic in TProxy and simplify subscription refresh
This commit is contained in:
@@ -101,6 +101,7 @@ setup_tproxy() {
|
||||
ipt -t mangle -N "$TPROXY_CHAIN"
|
||||
ipt -t mangle -A "$TPROXY_CHAIN" -m addrtype --dst-type LOCAL -j RETURN
|
||||
ipt -t mangle -A "$TPROXY_CHAIN" -m mark --mark "$TPROXY_MARK" -j RETURN
|
||||
ipt -t mangle -A "$TPROXY_CHAIN" -i 'br-+' -j RETURN
|
||||
|
||||
# Private/local destinations stay reachable; every intercepted public packet goes to VPN.
|
||||
for cidr in $BYPASS_CIDRS; do
|
||||
|
||||
@@ -95,12 +95,7 @@ function App() {
|
||||
}
|
||||
|
||||
async function refreshSubscription() {
|
||||
try {
|
||||
return await applyMutation(api.subscription.refresh);
|
||||
} catch (refreshError) {
|
||||
setError(refreshError.message);
|
||||
throw refreshError;
|
||||
}
|
||||
return applyMutation(api.subscription.refresh);
|
||||
}
|
||||
|
||||
async function forgetSubscription() {
|
||||
|
||||
@@ -13,6 +13,7 @@ test('gateway keeps direct forwarding active while TProxy interception is switch
|
||||
assert.match(entrypoint, /-p udp -j TPROXY --on-port "\$TPROXY_PORT"/);
|
||||
assert.match(entrypoint, /-I FORWARD 1 -j "\$GATEWAY_FORWARD_CHAIN"/);
|
||||
assert.match(entrypoint, /-I POSTROUTING 1 -j "\$GATEWAY_NAT_CHAIN"/);
|
||||
assert.match(entrypoint, /-A "\$TPROXY_CHAIN" -i 'br-\+' -j RETURN/);
|
||||
assert.doesNotMatch(entrypoint, /-A PREROUTING -j "\$TPROXY_CHAIN"/);
|
||||
assert.doesNotMatch(entrypoint, /TPROXY_BYPASS_SOURCE_CIDRS|DIRECT_BYPASS_CACHE|ipset/);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user