diff --git a/Makefile b/Makefile index c8e4a05..83ed40d 100644 --- a/Makefile +++ b/Makefile @@ -44,3 +44,33 @@ vet: clean: rm -f OpenGFW rm -rf $(FRONTEND)/node_modules + +.PHONY: install +install: build + @echo "Installing OpenGFW to /usr/local/bin" + @install -m 755 OpenGFW /usr/local/bin/OpenGFW || (echo "install failed: try running as root or use sudo" && exit 1) + @echo "Installing systemd unit to /etc/systemd/system/opengfw.service" + @printf '%s\n' \ + '[Unit]' \ + 'Description=OpenGFW' \ + 'After=network.target' \ + '' \ + '[Service]' \ + 'ExecStart=/usr/local/bin/OpenGFW -c /etc/opengfw/config.yaml /etc/opengfw/rules.yaml' \ + 'Restart=on-failure' \ + 'User=root' \ + 'Group=root' \ + 'WorkingDirectory=/etc/opengfw' \ + '' \ + '[Install]' \ + 'WantedBy=multi-user.target' \ + > /tmp/opengfw.service || (echo "write failed: try running as root or use sudo" && exit 1) + + @echo "Installing default config to /etc/opengfw/" + @mkdir -p /etc/opengfw || (echo "mkdir failed: try running as root or use sudo" && exit 1) + @install -m 644 config.yaml /etc/opengfw/config.yaml || (echo "copy config failed: try running as root or use sudo" && exit 1) + @install -m 644 rules.yaml /etc/opengfw/rules.yaml || (echo "copy rules failed: try running as root or use sudo" && exit 1) + @mv /tmp/opengfw.service /etc/systemd/system/opengfw.service || (echo "move failed: try running as root or use sudo" && exit 1) + @echo "Reloading systemd daemon and enabling service" + @systemctl daemon-reload || (echo "daemon-reload failed: ensure systemd is available" && exit 1) + @systemctl enable --now opengfw.service || (echo "enabling service failed: try running as root or use sudo" && exit 1) diff --git a/config.yaml b/config.yaml new file mode 100644 index 0000000..422a737 --- /dev/null +++ b/config.yaml @@ -0,0 +1,27 @@ +io: + queueSize: 1024 + queueNum: 100 + table: opengfw + connMarkAccept: 1001 + connMarkDrop: 1002 + rcvBuf: 4194304 + sndBuf: 4194304 + local: true + rst: false + +workers: + count: 4 + queueSize: 64 + tcpMaxBufferedPagesTotal: 65536 + tcpMaxBufferedPagesPerConn: 16 + tcpTimeout: 10m + udpMaxStreams: 4096 + +# 指定的 geoip/geosite 档案路径 +# 如果未设置,将自动从 https://github.com/Loyalsoldier/v2ray-rules-dat 下载 +# ruleset: +# geoip: geoip.dat +# geosite: geosite.dat + +replay: + realtime: false \ No newline at end of file diff --git a/rules.yaml b/rules.yaml new file mode 100644 index 0000000..e69de29