1067 Commits

Author SHA1 Message Date
eb9cedb10a добавлена поддержка небезопасных подписок
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.6
2026-06-07 01:16:42 +03:00
c860bf195c Убрал неактуальную проверку mangle output из диагностики 2026-06-07 00:33:07 +03:00
cbdc714ab8 фикс проверки версии extended ядра 2026-06-07 00:15:59 +03:00
f92408b136 Доп вкладка для управления компонентами и обновлениями 2026-06-06 22:44:52 +03:00
d391e32f4f Фиксы багов 2026-06-06 21:24:37 +03:00
343f8cc1cd Merge pull request #11 from spgsroot/sync/netshift-port
Синхронизация с netshift
2026-06-06 17:48:02 +03:00
03806d7b10 добавил ipv6 и doh-блокировку 2026-06-06 19:33:48 +08:00
7c7f7b15a0 новая фича: DNS через прокси 2026-06-05 22:47:05 +03:00
7783f3c27d пофиксил диагностику для extended ядра 2026-06-05 21:11:20 +03:00
4c606e3c19 пофиксил валидацию vmess
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.5
2026-06-05 13:29:46 +03:00
c39c66f89c сделал чистку кеша подписки, если возникает dead loop 2026-06-05 12:53:20 +03:00
7b261dbc1e пофиксил чувствительность регистров для фильтра 2026-06-05 12:30:04 +03:00
8c9ef3dbf9 доделал асинхронность на фронтенде 2026-06-05 10:41:44 +03:00
b9cd602216 добавил самовосстановление сети при смене ядер 2026-06-05 09:18:20 +03:00
e293bf5e14 сделал асинхронный фронтенд при перестановке ядер 2026-06-05 08:33:54 +03:00
87694d0db6 added vmess support 2026-06-04 23:22:44 +03:00
7d6b6f81ab фикс кодировки и кракозябр в логах
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.4
2026-06-04 20:35:21 +03:00
fe4dbb978f добавил include/exclude-фильтрацию серверов в подписках по ключевым словам в названии 2026-06-04 19:58:49 +03:00
df7b67781e фоллбеки для подписок xray json + фоллбеки юзер агентов 2026-06-04 18:53:10 +03:00
56f9722b41 добавил документацию + строгие правила агентам, чтобы поддерживать адекватное качество проекта(больше для разработчиков) 2026-06-03 11:37:20 +03:00
0ceaf5e202 chore: release 0.8.3
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.3
2026-06-03 01:23:22 +03:00
5f73eaf528 hotfix: чищу осиротевший tmp перед установкой extended, чтобы backup не падал по нехватке места 2026-06-03 01:23:14 +03:00
f4eb623a2d chore: release 0.8.3 2026-06-03 00:59:11 +03:00
7880473532 hotfix: ставлю extended-ядро через tmpfs, чтобы влезало в маленький overlay
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.1
2026-06-03 00:26:57 +03:00
59fa15275d hotfix: бэкап ядра на постоянную ФС, чтобы не упирался в tmpfs 2026-06-02 23:37:52 +03:00
59a5c5a67f hotfix: больше проверок успешной смены ядра
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.2
2026-06-02 23:10:19 +03:00
b5bd7fc8cf hotfix: пофиксил переход на sing-box extended 2026-06-02 23:07:28 +03:00
11a8d318dc уточнение условий наличия легаси версии 2026-06-02 22:31:30 +03:00
c391aee0ff fix names in fallback subscriptions 2026-06-02 21:47:58 +03:00
d22a93d0e1 ускорение запуска после обновления подписки 2026-06-02 21:31:58 +03:00
abcd071426 docs: render Telegram badges horizontally (HTML in centered <p>)
Some checks failed
Build packages / OpenWrt rootfs smoke tests (push) Has been cancelled
Build packages / Setup build version (push) Has been cancelled
Build packages / Builder for apk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Builder for ipk netshift and luci-app-netshift (push) Has been cancelled
Build packages / Create Release (push) Has been cancelled
0.8.0
2026-06-02 20:19:48 +03:00
b085e47c6c chore: point all self-references to yandexru45/netshift
Repo was renamed podkop-evolution -> netshift. Update every code/docs
reference to the new repo so update checks, package downloads and the
default-config fetch hit netshift directly (podkop-evolution stays only
as a one-time compatibility bridge):
- install.sh: REPO + rate-limit check + raw config URL + banners
- bin/netshift: update-check API + issue URL
- README badges/star-history/config URL; ISSUE_TEMPLATE links
- realign install.sh banner frames after the shorter URL
- add docs/icon.png
2026-06-02 20:14:56 +03:00
07268e2b99 fix(ci): make backend POSIX-clean for ShellCheck + executable smoke entrypoint
CI failed on two independent issues after the rebrand:

1. Differential ShellCheck (severity=error): the git mv podkop->netshift made
   every lib file "new", surfacing pre-existing upstream dash-incompatibilities.
   Fixed all severity=error defects so `shellcheck --shell=ash` is clean:
   - SC2148: add `# shellcheck shell=ash` directive to the 7 sourced libs
     (constants/helpers/logging/nft/rulesets/sing_box_config_manager/facade)
   - SC3014: `[ x == y ]` -> `[ x = y ]` (bin/netshift + facade + logging)
   - SC3010: `[[ ... ]]` / `[[ =~ ]]` -> POSIX (grep -Eq / case / `! cmd`)
     in bin/netshift and helpers (is_ipv4, is_ipv4_cidr, is_domain, ...)
   - SC3060: `${input//,/...}` -> `sed 's/,/","/g'`
   - SC3028: `$RANDOM` in gen_id -> `/dev/urandom` (od-free, busybox-safe)
   - SC3003: `$'\r'` -> `"$(printf '\r')"`
   - SC3036: `echo -e` -> `printf '%b\n'` (logging.sh)

2. Smoke-test job: tests/entrypoint.sh lacked the executable bit (git mode
   100644) -> "permission denied" in the container. Set mode 100755.

README: drop stale podkop.net docs badge.

Verified: shellcheck --severity=error --shell=ash clean (exit 0); smoke suite
44 passed / 0 failed; gen_id still yields 16-hex ids; behavior unchanged.
2026-06-02 19:36:27 +03:00
1ce10e8a71 feat(subscription): fallback parser for base64 / plaintext key lists
Many providers don't honor the sing-box User-Agent (or run legacy panels)
and return a base64-encoded or plaintext list of proxy URIs instead of a
sing-box JSON config. Previously such subscriptions failed validation (rc 13).

Add normalize_subscription_to_singbox() (helpers.sh): when the downloaded
body is not valid sing-box JSON, try to recover it:
- detect & base64-decode a wrapped body (conservative: raw has no '://',
  decoded does; self-pads to len%4 for older coreutils-base64)
- split into lines, skip blank and #comment/metadata lines
- keep known schemes (vless/trojan/ss/hysteria2/hy2/socks4/4a/5)
- build each URI into an outbound by reusing sing_box_cf_add_proxy_outbound,
  isolated in a subshell so one bad/unknown key can't abort the run
- emit {"outbounds":[...]} so the existing validate + merge path is reused

Hook in download_subscription_into_cache (bin/netshift): on validation
failure, attempt the fallback before returning rc 13; covers both the
update and startup download paths.

Smoke tests (tests/entrypoint.sh): extend test_subscription with cases for
plaintext+metadata, base64-wrapped, mixed-with-garbage (one bad key must not
abort), and junk-only (must fall through). Verified in the OpenWrt rootfs
container against real provider samples (base64 -> 10 outbounds; plaintext
-> 43 vless), all validate OK. Suite: 44 passed / 0 failed.
2026-06-02 19:06:51 +03:00
a0ae7c64d9 test: add OpenWrt rootfs Docker smoke-test suite
Port the source-level smoke-test harness from the padkap fork, adapted to
NetShift. Runs the shell/jq/config-generation logic against a real OpenWrt
24.10.6 userland (sing-box, jq, nft) before flashing to a router.

- tests/Dockerfile: alpine downloads official OpenWrt rootfs tarball ->
  FROM scratch; opkg installs sing-box curl jq coreutils-base64 bind-dig nftables
- tests/docker-compose.yml: service netshift-test, bind-mounts netshift/files,
  NET_ADMIN/NET_RAW/SYS_ADMIN caps, host network
- tests/entrypoint.sh: 10 test groups (deps, syntax, config, helpers, jq,
  config-manager, sing-box check, nft, diagnostics, subscription); adapted to
  our config options (dns_type/connection_type/proxy_config_type) and helper
  API (url_is_ipv6_literal); updater.sh added to syntax checks
- .github/workflows/openwrt-smoke-tests.yml: standalone CI on push/PR
- build.yml: smoke-tests job gates the release build (needs: smoke-tests)
- .dockerignore + .gitignore (tests/test-results/)

Verified locally: docker compose run netshift-test all -> 44 passed / 0 failed.
2026-06-02 18:24:23 +03:00
46e3fc5eb7 upd readme 2026-06-02 18:05:15 +03:00
9a677de868 docs: restructure README (header, screenshot, sections per spec)
Layout top-to-bottom: title + badges, divider, screenshot, description,
divider, then sections: Функции, Вещи перед установкой, Установка NetShift,
Project Structure, Build Artifacts, Star History, Credits.
2026-06-02 17:46:18 +03:00
3b4554e61d Revert "docs: redesign README (centered header, badges, structured sections)"
This reverts commit 69c9a69acd.
2026-06-02 17:44:02 +03:00
69c9a69acd docs: redesign README (centered header, badges, structured sections)
Rework README in the style of well-presented project READMEs:
- centered header with NETSHIFT ASCII banner + badges (release, license,
  OpenWrt, docs, DeepWiki)
- one-line tagline + upstream attribution
- checkbox Features list with sub-descriptions
- collapsible <details> for pre-install requirements, migration (0.8.0 /
  0.7.0), UCI example
- Subscription headers as a table
- Acknowledgments + License sections

Content preserved: install one-liner, system requirements, subscription /
HWID docs, extended/xhttp, migration notes, roadmap, upstream links.
2026-06-02 17:37:17 +03:00
897b93664b rebrand: podkop -> NetShift (v0.8.0) with migration
Full project rebrand to reduce association with upstream podkop, per
upstream maintainers' request.

Renames (git mv, history preserved):
- package podkop -> netshift (/usr/bin/netshift, /etc/config/netshift,
  /etc/init.d/netshift, /etc/netshift state dir, /usr/lib/netshift)
- luci-app-podkop -> luci-app-netshift; view namespace view/podkop -> view/netshift
- fe-app-podkop -> fe-app-netshift; TS namespace Podkop -> NetShift
- nft table PodkopTable -> NetShiftTable; rt_table podkop -> netshift
- nft sets, dnsmasq backup keys, cron self-calls, PID/tmp paths
- i18n podkop.pot/po -> netshift.pot/po; web title Podkop -> NetShift
- build-arg PODKOP_VERSION -> NETSHIFT_VERSION; Dockerfiles + CI workflows

Migration (install.sh migrate_from_podkop): on detecting an old podkop
install, stops the old service (clean teardown of nft/dnsmasq/rt_tables),
copies /etc/config/podkop -> /etc/config/netshift (backup at
/etc/config/podkop.bak.pre-netshift), migrates state dir, strips old
cron/rt_tables entries, removes old packages, then installs NetShift.
Config schema is compatible so the VPN keeps working after migration.

Docs: README + TRADEMARK rewritten for NetShift.

Intentionally kept: upstream attribution (itdoginfo/podkop), podkop.net
docs links, *.podkop.fyi check domains, yandexru45/podkop-evolution repo
URL (GitHub repo not renamed yet), maintainer email.

Verified: bash -n clean, yarn lint/test (283) pass, main.js idempotent,
Docker ipk build produces netshift_v0.8.0 / luci-app-netshift_v0.8.0.
2026-06-02 17:34:44 +03:00
3cf321a78b feat: sing-box-extended core switching + xhttp client transport
Add runtime sing-box core switching (stable <-> extended) and xhttp
client outbound support, reimplemented on the fork's jq stack (no ucode).

Backend:
- helpers.sh: is_sing_box_extended() / get_sing_box_version()
- get_system_info exposes sing_box_extended flag
- updater.sh (new): download sing-box-extended from shtorm-7/sing-box-extended
  with arch/musl detection, jq release parsing, backup/extract/validate/rollback;
  install_stable reverts to packaged sing-box; component_action dispatch
- sing_box_config_facade.sh: xhttp transport branch gated on extended
  (path/host/sni/mode), default ALPN h2,http/1.1; subscription xhttp skipped
  when core not extended
- sing_box_config_manager.sh: sing_box_cm_set_xhttp_transport_for_outbound (jq)

Frontend:
- types: sing_box_extended + component action method
- async componentAction via executeShellCommand (long timeout)
- Diagnostics tab: Install extended / Install stable button
- RU locales for new strings

Default install keeps stock sing-box; extended is opt-in via UI.
2026-06-02 16:15:30 +03:00
6c289a055e Merge upstream/main (itdoginfo/podkop) into podkop-evolution
Sync with upstream through de7b73a (~0.7.19+):
- hy2 multi-port outbound + fingerprint fix
- DNS resolve-action route rule
- Discord nft UDP range 19000-20000 (kept fork idempotency guards)
- NFT DNAT-status guard in mangle chain
- hide block/exclusion sections in UI
- version-check refactor, SDK bump to 24.10.6
- docs: README rewrite, TRADEMARK guides

Conflicts resolved in podkop/files/usr/bin/podkop (Discord nft rule)
and README.md (kept fork Subscription/HWID identity).
Regenerated main.js via tsup build; locales distributed.
2026-06-02 13:32:25 +03:00
de7b73af3c Merge pull request #384 from itdoginfo/fix/dnat
fix: skip connections with DNAT status in NFT mangle chain
2026-06-01 12:22:26 +03:00
3c34bd1fd0 fix: skip connections with DNAT status in NFT mangle chain 2026-06-01 14:11:14 +05:00
847895598d Merge pull request #382 from itdoginfo/fix/hy2
Fixes
2026-05-29 17:41:50 +03:00
4146804e5a feat(extra): hide block & exclusion from download_lists_via_proxy_section 2026-05-29 17:03:44 +03:00
daef80b7b8 feat(debug): add debug data for download_lists_via_proxy_section 2026-05-29 17:00:02 +03:00
6e7b8a6be2 feat(exclusion): hide section with type exclusion 2026-05-29 16:53:47 +03:00
1365febaa4 feat(hy2): add port range support for validator 2026-05-29 16:40:44 +03:00
1543d974cc fix: support multiple server ports for hysteria2 outbounds 2026-05-29 17:45:13 +05:00