From bf46572bacfbf833dc5d023a37d3984befba6c72 Mon Sep 17 00:00:00 2001 From: bol-van Date: Sun, 2 Feb 2020 17:59:59 +0300 Subject: [PATCH] obsolete non-desync nfqws options in scripts --- config | 3 --- init.d/openwrt/functions | 18 ------------------ init.d/openwrt/zapret | 3 --- init.d/sysv/functions | 21 --------------------- 4 files changed, 45 deletions(-) diff --git a/config b/config index ba8de3d..7c2e6fc 100644 --- a/config +++ b/config @@ -20,9 +20,6 @@ IP2NET_OPT6="--prefix-length=56-64 --v6-threshold=5" # custom mode : custom . should modify init script and add your own code MODE=tpws_ipset_https -# CHOOSE NFQWS DAEMON OPTIONS. run "nfq/nfqws --help" for option list -NFQWS_OPT="--wsize=3 --hostspell=HOST" - # CHOOSE NFQWS DAEMON OPTIONS for DPI desync mode. run "nfq/nfqws --help" for option list DESYNC_MARK=0x40000000 NFQWS_OPT_DESYNC="--dpi-desync=fake --dpi-desync-ttl=0 --dpi-desync-fooling=badsum --dpi-desync-fwmark=$DESYNC_MARK" diff --git a/init.d/openwrt/functions b/init.d/openwrt/functions index 8dfd63c..7235a92 100644 --- a/init.d/openwrt/functions +++ b/init.d/openwrt/functions @@ -285,24 +285,6 @@ zapret_apply_firewall() fw_tpws "--dport 80" "--dport 80" $TPPORT_HTTP fw_tpws "--dport 443" "--dport 443" $TPPORT_HTTPS ;; - nfqws_ipset) - fw_nfqws_pre "--sport 80 $synack $ipset_zapret src" "--sport 80 $synack $ipset_zapret6 src" $QNUM - fw_nfqws_post "--dport 80 $ipset_zapret dst" "--dport 80 $ipset_zapret6 dst" $QNUM - ;; - nfqws_ipset_https) - rule="-m multiport --sports 80,443 $synack" - fw_nfqws_pre "$rule $ipset_zapret src" "$rule $ipset_zapret6 src" $QNUM - fw_nfqws_post "--dport 80 $ipset_zapret dst" "--dport 80 $ipset_zapret6 dst" $QNUM - ;; - nfqws_all) - fw_nfqws_pre "--sport 80 $synack" "--sport 80 $synack" $QNUM - fw_nfqws_post "--dport 80" "--dport 80" $QNUM - ;; - nfqws_all_https) - rule="-m multiport --sports 80,443 $synack" - fw_nfqws_pre "$rule" "$rule" $QNUM - fw_nfqws_post "--dport 80" "--dport 80" $QNUM - ;; nfqws_all_desync|nfqws_hostlist_desync) fw_nfqws_post "$desync" "$desync" $QNUM ;; diff --git a/init.d/openwrt/zapret b/init.d/openwrt/zapret index 2b57d6c..a96b745 100755 --- a/init.d/openwrt/zapret +++ b/init.d/openwrt/zapret @@ -74,9 +74,6 @@ start_service() { run_tpws 1 "$TPWS_OPT_BASE_HTTP $TPWS_OPT_HTTP" run_tpws 2 "$TPWS_OPT_BASE_HTTPS $TPWS_OPT_HTTPS" ;; - nfqws_ipset|nfqws_ipset_https|nfqws_all|nfqws_all_https) - run_daemon 1 $NFQWS "$NFQWS_OPT_BASE $NFQWS_OPT" - ;; nfqws_ipset_desync|nfqws_all_desync) run_daemon 1 $NFQWS "$NFQWS_OPT_BASE $NFQWS_OPT_DESYNC" ;; diff --git a/init.d/sysv/functions b/init.d/sysv/functions index 497da7c..48655fd 100644 --- a/init.d/sysv/functions +++ b/init.d/sysv/functions @@ -404,24 +404,6 @@ zapret_do_firewall() fw_tpws $1 "--dport 80" "--dport 80" $TPPORT_HTTP fw_tpws $1 "--dport 443" "--dport 443" $TPPORT_HTTPS ;; - nfqws_ipset) - fw_nfqws_pre $1 "--sport 80 $synack $ipset_zapret src" "--sport 80 $synack $ipset_zapret6 src" $QNUM - fw_nfqws_post $1 "--dport 80 $ipset_zapret dst" "--dport 80 $ipset_zapret6 dst" $QNUM - ;; - nfqws_ipset_https) - rule="-m multiport --sports 80,443 $synack" - fw_nfqws_pre $1 "$rule $ipset_zapret src" "$rule $ipset_zapret6 src" $QNUM - fw_nfqws_post $1 "--dport 80 $ipset_zapret dst" "--dport 80 $ipset_zapret6 dst" $QNUM - ;; - nfqws_all) - fw_nfqws_pre $1 "--sport 80 $synack" "--sport 80 $synack" $QNUM - fw_nfqws_post $1 "--dport 80" "--dport 80" $QNUM - ;; - nfqws_all_https) - rule="-m multiport --sports 80,443 $synack" - fw_nfqws_pre $1 "$rule" "$rule" $QNUM - fw_nfqws_post $1 "--dport 80" "--dport 80" $QNUM - ;; nfqws_all_desync|nfqws_hostlist_desync) fw_nfqws_post $1 "$desync" "$desync" $QNUM ;; @@ -457,9 +439,6 @@ zapret_do_daemons() do_tpws $1 1 "$TPWS_OPT_BASE_HTTP $TPWS_OPT_HTTP" do_tpws $1 2 "$TPWS_OPT_BASE_HTTPS $TPWS_OPT_HTTPS" ;; - nfqws_ipset|nfqws_ipset_https|nfqws_all|nfqws_all_https) - do_nfqws $1 1 "$NFQWS_OPT" - ;; nfqws_ipset_desync|nfqws_all_desync) do_nfqws $1 1 "$NFQWS_OPT_DESYNC" ;;