481 lines
15 KiB
Bash
481 lines
15 KiB
Bash
#!/usr/bin/env bash
|
|
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
|
|
export PATH
|
|
#===================================================================#
|
|
# System Required: CentOS 6 or 7 #
|
|
# Description: Install Shadowsocks-libev server for CentOS 6 or 7 #
|
|
# Author: Teddysun <i@teddysun.com> #
|
|
# Thanks: @madeye <https://github.com/madeye> #
|
|
# Intro: https://teddysun.com/357.html #
|
|
#===================================================================#
|
|
|
|
# Current folder
|
|
cur_dir=`pwd`
|
|
|
|
libsodium_file="libsodium-1.0.13"
|
|
libsodium_url="https://github.com/jedisct1/libsodium/releases/download/1.0.13/libsodium-1.0.13.tar.gz"
|
|
|
|
mbedtls_file="mbedtls-2.5.1"
|
|
mbedtls_url="https://tls.mbed.org/download/mbedtls-2.5.1-gpl.tgz"
|
|
|
|
# Make sure only root can run our script
|
|
rootness(){
|
|
if [[ $EUID -ne 0 ]]; then
|
|
echo "Error: This script must be run as root!" 1>&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
# Disable selinux
|
|
disable_selinux(){
|
|
if [ -s /etc/selinux/config ] && grep 'SELINUX=enforcing' /etc/selinux/config; then
|
|
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
|
|
setenforce 0
|
|
fi
|
|
}
|
|
|
|
get_ip(){
|
|
local IP=$( ip addr | egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | egrep -v "^192\.168|^172\.1[6-9]\.|^172\.2[0-9]\.|^172\.3[0-2]\.|^10\.|^127\.|^255\.|^0\." | head -n 1 )
|
|
[ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 ipv4.icanhazip.com )
|
|
[ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 ipinfo.io/ip )
|
|
[ ! -z ${IP} ] && echo ${IP} || echo
|
|
}
|
|
|
|
get_ipv6(){
|
|
local ipv6=$(wget -qO- -t1 -T2 ipv6.icanhazip.com)
|
|
if [ -z ${ipv6} ]; then
|
|
return 1
|
|
else
|
|
return 0
|
|
fi
|
|
}
|
|
|
|
get_char(){
|
|
SAVEDSTTY=`stty -g`
|
|
stty -echo
|
|
stty cbreak
|
|
dd if=/dev/tty bs=1 count=1 2> /dev/null
|
|
stty -raw
|
|
stty echo
|
|
stty $SAVEDSTTY
|
|
}
|
|
|
|
get_latest_version(){
|
|
ver=$(wget --no-check-certificate -qO- https://api.github.com/repos/shadowsocks/shadowsocks-libev/releases/latest | grep 'tag_name' | cut -d\" -f4)
|
|
[ -z ${ver} ] && echo "Error: Get shadowsocks-libev latest version failed" && exit 1
|
|
shadowsocks_libev_ver="shadowsocks-libev-$(echo ${ver} | sed -e 's/^[a-zA-Z]//g')"
|
|
download_link="https://github.com/shadowsocks/shadowsocks-libev/releases/download/${ver}/${shadowsocks_libev_ver}.tar.gz"
|
|
init_script_link="https://raw.githubusercontent.com/teddysun/shadowsocks_install/master/shadowsocks-libev"
|
|
}
|
|
|
|
check_installed(){
|
|
if [ "$(command -v "$1")" ]; then
|
|
return 0
|
|
else
|
|
return 1
|
|
fi
|
|
}
|
|
|
|
check_version(){
|
|
check_installed "ss-server"
|
|
if [ $? -eq 0 ]; then
|
|
installed_ver=$(ss-server -h | grep shadowsocks-libev | cut -d' ' -f2)
|
|
get_latest_version
|
|
latest_ver=$(echo ${ver} | sed -e 's/^[a-zA-Z]//g')
|
|
if [ "${latest_ver}" == "${installed_ver}" ]; then
|
|
return 0
|
|
else
|
|
return 1
|
|
fi
|
|
else
|
|
return 2
|
|
fi
|
|
}
|
|
|
|
print_info(){
|
|
clear
|
|
echo "#############################################################"
|
|
echo "# Install Shadowsocks-libev server for CentOS 6 or 7 #"
|
|
echo "# Intro: https://teddysun.com/357.html #"
|
|
echo "# Author: Teddysun <i@teddysun.com> #"
|
|
echo "# Github: https://github.com/shadowsocks/shadowsocks-libev #"
|
|
echo "#############################################################"
|
|
echo
|
|
}
|
|
|
|
# Check system
|
|
check_sys(){
|
|
local checkType=$1
|
|
local value=$2
|
|
|
|
local release=''
|
|
local systemPackage=''
|
|
|
|
if [[ -f /etc/redhat-release ]]; then
|
|
release="centos"
|
|
systemPackage="yum"
|
|
elif cat /etc/issue | grep -Eqi "debian"; then
|
|
release="debian"
|
|
systemPackage="apt"
|
|
elif cat /etc/issue | grep -Eqi "ubuntu"; then
|
|
release="ubuntu"
|
|
systemPackage="apt"
|
|
elif cat /etc/issue | grep -Eqi "centos|red hat|redhat"; then
|
|
release="centos"
|
|
systemPackage="yum"
|
|
elif cat /proc/version | grep -Eqi "debian"; then
|
|
release="debian"
|
|
systemPackage="apt"
|
|
elif cat /proc/version | grep -Eqi "ubuntu"; then
|
|
release="ubuntu"
|
|
systemPackage="apt"
|
|
elif cat /proc/version | grep -Eqi "centos|red hat|redhat"; then
|
|
release="centos"
|
|
systemPackage="yum"
|
|
fi
|
|
|
|
if [[ ${checkType} == "sysRelease" ]]; then
|
|
if [ "$value" == "$release" ]; then
|
|
return 0
|
|
else
|
|
return 1
|
|
fi
|
|
elif [[ ${checkType} == "packageManager" ]]; then
|
|
if [ "$value" == "$systemPackage" ]; then
|
|
return 0
|
|
else
|
|
return 1
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# Get version
|
|
getversion(){
|
|
if [[ -s /etc/redhat-release ]]; then
|
|
grep -oE "[0-9.]+" /etc/redhat-release
|
|
else
|
|
grep -oE "[0-9.]+" /etc/issue
|
|
fi
|
|
}
|
|
|
|
# CentOS version
|
|
centosversion(){
|
|
if check_sys sysRelease centos; then
|
|
local code=$1
|
|
local version="$(getversion)"
|
|
local main_ver=${version%%.*}
|
|
if [ "$main_ver" == "$code" ]; then
|
|
return 0
|
|
else
|
|
return 1
|
|
fi
|
|
else
|
|
return 1
|
|
fi
|
|
}
|
|
|
|
# Pre-installation settings
|
|
pre_install(){
|
|
# Check OS system
|
|
if check_sys sysRelease centos; then
|
|
# Not support CentOS 5
|
|
if centosversion 5; then
|
|
echo "Not support CentOS 5, please change to CentOS 6 or 7 and try again."
|
|
exit 1
|
|
fi
|
|
else
|
|
echo "Error: Your OS is not supported to run it, please change OS to CentOS and try again."
|
|
exit 1
|
|
fi
|
|
|
|
# Check version
|
|
check_version
|
|
status=$?
|
|
if [ ${status} -eq 0 ]; then
|
|
echo "Latest version ${shadowsocks_libev_ver} has been installed, nothing to do..."
|
|
echo
|
|
exit 0
|
|
elif [ ${status} -eq 1 ]; then
|
|
echo "Installed version: ${installed_ver}"
|
|
echo "Latest version: ${latest_ver}"
|
|
echo "Upgrade shadowsocks libev to latest version..."
|
|
ps -ef | grep -v grep | grep -i "ss-server" > /dev/null 2>&1
|
|
if [ $? -eq 0 ]; then
|
|
/etc/init.d/shadowsocks stop
|
|
fi
|
|
elif [ ${status} -eq 2 ]; then
|
|
print_info
|
|
get_latest_version
|
|
echo "Latest version: ${shadowsocks_libev_ver}"
|
|
echo
|
|
fi
|
|
|
|
# Set shadowsocks-libev config password
|
|
echo "Please input password for shadowsocks-libev"
|
|
read -p "(Default password: teddysun.com):" shadowsockspwd
|
|
[ -z "${shadowsockspwd}" ] && shadowsockspwd="teddysun.com"
|
|
echo
|
|
echo "---------------------------"
|
|
echo "password = ${shadowsockspwd}"
|
|
echo "---------------------------"
|
|
echo
|
|
|
|
# Set shadowsocks-libev config port
|
|
while true
|
|
do
|
|
echo -e "Please input port for shadowsocks-libev [1-65535]"
|
|
read -p "(Default port: 8989):" shadowsocksport
|
|
[ -z "$shadowsocksport" ] && shadowsocksport="8989"
|
|
expr ${shadowsocksport} + 0 &>/dev/null
|
|
if [ $? -eq 0 ]; then
|
|
if [ ${shadowsocksport} -ge 1 ] && [ ${shadowsocksport} -le 65535 ]; then
|
|
echo
|
|
echo "---------------------------"
|
|
echo "port = ${shadowsocksport}"
|
|
echo "---------------------------"
|
|
echo
|
|
break
|
|
else
|
|
echo "Input error, please input correct number"
|
|
fi
|
|
else
|
|
echo "Input error, please input correct number"
|
|
fi
|
|
done
|
|
|
|
echo
|
|
echo "Press any key to start...or press Ctrl+C to cancel"
|
|
char=`get_char`
|
|
#Install necessary dependencies
|
|
yum install -y epel-release
|
|
yum install -y gcc gettext-devel unzip autoconf automake make zlib-devel libtool udns-devel libev-devel
|
|
yum install -y pcre pcre-devel perl perl-devel cpio expat-devel openssl-devel
|
|
}
|
|
|
|
download() {
|
|
local filename=$(basename $1)
|
|
if [ -f ${1} ]; then
|
|
echo "${filename} [found]"
|
|
else
|
|
echo "${filename} not found, download now..."
|
|
wget --no-check-certificate -c -t3 -T60 -O ${1} ${2}
|
|
if [ $? -ne 0 ]; then
|
|
echo "Error: Download ${filename} failed."
|
|
exit 1
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# Download latest shadowsocks-libev
|
|
download_files(){
|
|
cd ${cur_dir}
|
|
|
|
download "${shadowsocks_libev_ver}.tar.gz" "${download_link}"
|
|
download "${libsodium_file}.tar.gz" "${libsodium_url}"
|
|
download "${mbedtls_file}-gpl.tgz" "${mbedtls_url}"
|
|
download "/etc/init.d/shadowsocks" "${init_script_link}"
|
|
}
|
|
|
|
install_libsodium() {
|
|
if [ ! -f /usr/lib/libsodium.a ]; then
|
|
cd ${cur_dir}
|
|
tar zxf ${libsodium_file}.tar.gz
|
|
cd ${libsodium_file}
|
|
./configure --prefix=/usr && make && make install
|
|
if [ $? -ne 0 ]; then
|
|
echo "Error: ${libsodium_file} install failed."
|
|
exit 1
|
|
fi
|
|
else
|
|
echo "Info: ${libsodium_file} already installed."
|
|
fi
|
|
}
|
|
|
|
install_mbedtls() {
|
|
if [ ! -f /usr/lib/libmbedtls.a ]; then
|
|
cd ${cur_dir}
|
|
tar xf ${mbedtls_file}-gpl.tgz
|
|
cd ${mbedtls_file}
|
|
make SHARED=1 CFLAGS=-fPIC
|
|
make DESTDIR=/usr install
|
|
else
|
|
echo "Info: ${mbedtls_file} already installed."
|
|
fi
|
|
}
|
|
|
|
# Config shadowsocks
|
|
config_shadowsocks(){
|
|
local server_value="\"0.0.0.0\""
|
|
if get_ipv6; then
|
|
server_value="[\"[::0]\",\"0.0.0.0\"]"
|
|
fi
|
|
|
|
if [ ! -d /etc/shadowsocks-libev ]; then
|
|
mkdir -p /etc/shadowsocks-libev
|
|
fi
|
|
cat > /etc/shadowsocks-libev/config.json<<-EOF
|
|
{
|
|
"server":${server_value},
|
|
"server_port":${shadowsocksport},
|
|
"local_address":"127.0.0.1",
|
|
"local_port":1080,
|
|
"password":"${shadowsockspwd}",
|
|
"timeout":600,
|
|
"method":"aes-256-cfb"
|
|
}
|
|
EOF
|
|
}
|
|
|
|
# Firewall set
|
|
firewall_set(){
|
|
echo "firewall set start..."
|
|
if centosversion 6; then
|
|
/etc/init.d/iptables status > /dev/null 2>&1
|
|
if [ $? -eq 0 ]; then
|
|
iptables -L -n | grep -i ${shadowsocksport} > /dev/null 2>&1
|
|
if [ $? -ne 0 ]; then
|
|
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport ${shadowsocksport} -j ACCEPT
|
|
iptables -I INPUT -m state --state NEW -m udp -p udp --dport ${shadowsocksport} -j ACCEPT
|
|
/etc/init.d/iptables save
|
|
/etc/init.d/iptables restart
|
|
else
|
|
echo "port ${shadowsocksport} has been set up."
|
|
fi
|
|
else
|
|
echo "WARNING: iptables looks like shutdown or not installed, please manually set it if necessary."
|
|
fi
|
|
elif centosversion 7; then
|
|
systemctl status firewalld > /dev/null 2>&1
|
|
if [ $? -eq 0 ]; then
|
|
firewall-cmd --permanent --zone=public --add-port=${shadowsocksport}/tcp
|
|
firewall-cmd --permanent --zone=public --add-port=${shadowsocksport}/udp
|
|
firewall-cmd --reload
|
|
else
|
|
echo "Firewalld looks like not running, try to start..."
|
|
systemctl start firewalld
|
|
if [ $? -eq 0 ]; then
|
|
firewall-cmd --permanent --zone=public --add-port=${shadowsocksport}/tcp
|
|
firewall-cmd --permanent --zone=public --add-port=${shadowsocksport}/udp
|
|
firewall-cmd --reload
|
|
else
|
|
echo "WARNING: Try to start firewalld failed. please enable port ${shadowsocksport} manually if necessary."
|
|
fi
|
|
fi
|
|
fi
|
|
echo "firewall set completed..."
|
|
}
|
|
|
|
# Install Shadowsocks-libev
|
|
install_shadowsocks(){
|
|
install_libsodium
|
|
install_mbedtls
|
|
|
|
ldconfig
|
|
cd ${cur_dir}
|
|
tar zxf ${shadowsocks_libev_ver}.tar.gz
|
|
cd ${shadowsocks_libev_ver}
|
|
./configure --disable-documentation
|
|
make && make install
|
|
if [ $? -eq 0 ]; then
|
|
chmod +x /etc/init.d/shadowsocks
|
|
# Add run on system start up
|
|
chkconfig --add shadowsocks
|
|
chkconfig shadowsocks on
|
|
# Start shadowsocks
|
|
/etc/init.d/shadowsocks start
|
|
if [ $? -eq 0 ]; then
|
|
echo "Shadowsocks-libev start success!"
|
|
else
|
|
echo "Shadowsocks-libev start failure!"
|
|
fi
|
|
else
|
|
echo
|
|
echo "Shadowsocks-libev install failed! Please visit https://teddysun.com/357.html and contact."
|
|
exit 1
|
|
fi
|
|
|
|
cd ${cur_dir}
|
|
rm -rf ${shadowsocks_libev_ver} ${shadowsocks_libev_ver}.tar.gz
|
|
rm -rf ${libsodium_file} ${libsodium_file}.tar.gz
|
|
|
|
clear
|
|
echo
|
|
echo "Congratulations, Shadowsocks-libev install completed!"
|
|
echo -e "Your Server IP: \033[41;37m $(get_ip) \033[0m"
|
|
echo -e "Your Server Port: \033[41;37m ${shadowsocksport} \033[0m"
|
|
echo -e "Your Password: \033[41;37m ${shadowsockspwd} \033[0m"
|
|
echo -e "Your Local IP: \033[41;37m 127.0.0.1 \033[0m"
|
|
echo -e "Your Local Port: \033[41;37m 1080 \033[0m"
|
|
echo -e "Your Encryption Method: \033[41;37m aes-256-cfb \033[0m"
|
|
echo
|
|
echo "Welcome to visit:https://teddysun.com/357.html"
|
|
echo "Enjoy it!"
|
|
echo
|
|
}
|
|
|
|
# Uninstall Shadowsocks-libev
|
|
uninstall_shadowsocks_libev(){
|
|
print_info
|
|
printf "Are you sure uninstall shadowsocks-libev? (y/n)"
|
|
printf "\n"
|
|
read -p "(Default: n):" answer
|
|
[ -z ${answer} ] && answer="n"
|
|
|
|
if [ "${answer}" == "y" ] || [ "${answer}" == "Y" ]; then
|
|
ps -ef | grep -v grep | grep -i "ss-server" > /dev/null 2>&1
|
|
if [ $? -eq 0 ]; then
|
|
/etc/init.d/shadowsocks stop
|
|
fi
|
|
chkconfig --del shadowsocks
|
|
rm -fr /etc/shadowsocks-libev
|
|
rm -f /usr/local/bin/ss-local
|
|
rm -f /usr/local/bin/ss-tunnel
|
|
rm -f /usr/local/bin/ss-server
|
|
rm -f /usr/local/bin/ss-manager
|
|
rm -f /usr/local/bin/ss-redir
|
|
rm -f /usr/local/bin/ss-nat
|
|
rm -f /usr/local/lib/libshadowsocks-libev.a
|
|
rm -f /usr/local/lib/libshadowsocks-libev.la
|
|
rm -f /usr/local/include/shadowsocks.h
|
|
rm -f /usr/local/lib/pkgconfig/shadowsocks-libev.pc
|
|
rm -f /usr/local/share/man/man1/ss-local.1
|
|
rm -f /usr/local/share/man/man1/ss-tunnel.1
|
|
rm -f /usr/local/share/man/man1/ss-server.1
|
|
rm -f /usr/local/share/man/man1/ss-manager.1
|
|
rm -f /usr/local/share/man/man1/ss-redir.1
|
|
rm -f /usr/local/share/man/man1/ss-nat.1
|
|
rm -f /usr/local/share/man/man8/shadowsocks-libev.8
|
|
rm -fr /usr/local/share/doc/shadowsocks-libev
|
|
rm -f /etc/init.d/shadowsocks
|
|
echo "Shadowsocks-libev uninstall success!"
|
|
else
|
|
echo
|
|
echo "uninstall cancelled, nothing to do..."
|
|
echo
|
|
fi
|
|
}
|
|
|
|
# Install Shadowsocks-libev
|
|
install_shadowsocks_libev(){
|
|
rootness
|
|
disable_selinux
|
|
pre_install
|
|
download_files
|
|
config_shadowsocks
|
|
firewall_set
|
|
install_shadowsocks
|
|
}
|
|
|
|
# Initialization step
|
|
action=$1
|
|
[ -z $1 ] && action=install
|
|
case "$action" in
|
|
install|uninstall)
|
|
${action}_shadowsocks_libev
|
|
;;
|
|
*)
|
|
echo "Arguments error! [${action}]"
|
|
echo "Usage: `basename $0` [install|uninstall]"
|
|
;;
|
|
esac
|