mirror of
https://github.com/openwrt/packages.git
synced 2026-05-31 15:02:01 +08:00
ebe149b7f3
Maintainer: me Compile tested: x86_64, Dell EMC Edge620, OpenWrt 25.12.1 Run tested: x86_64, Dell EMC Edge620, OpenWrt 25.12.1 Description:Add nftables notrack for localhost traffic - Removed. License is now included in the main project. net/https-dns-proxy/Makefile: - Bumped PKG_RELEASE to 5. net/https-dns-proxy/files/etc/config/https-dns-proxy: - Added 'option notrack_dns '1'' to the default configuration. net/https-dns-proxy/files/etc/init.d/https-dns-proxy: - Defined NOTRACK_NFT_FILE constant. - Added 'notrack_dns' and 'notrack_ports' variables. - Implemented 'notrack_nft' function to manage nftables rules for notracking local DNS traffic. - Enabled loading of 'notrack_dns' boolean from configuration. - Modified start_instance to collect listen_port into notrack_ports if notrack_dns is enabled. - Modified start_service to call notrack_nft update/remove based on notrack_dns and collected ports. - Modified stop_service to call notrack_nft remove. - Updated service_started and service_stopped to trigger firewall config changes when notrack_dns is enabled. Signed-off-by: Stan Grishin <stangri@melmac.ca>
35 lines
1.0 KiB
Plaintext
35 lines
1.0 KiB
Plaintext
config main 'config'
|
|
option canary_domains_icloud '1'
|
|
option canary_domains_mozilla '1'
|
|
option dnsmasq_config_update '*'
|
|
option force_dns '1'
|
|
option notrack_dns '1'
|
|
list force_dns_port '53'
|
|
list force_dns_port '853'
|
|
# ports listed below are used by some
|
|
# of the dnscrypt-proxy v1 resolvers
|
|
# list force_dns_port '553'
|
|
# list force_dns_port '1443'
|
|
# list force_dns_port '4343'
|
|
# list force_dns_port '4434'
|
|
# list force_dns_port '5443'
|
|
# list force_dns_port '8443'
|
|
list force_dns_src_interface 'lan'
|
|
option procd_trigger_wan6 '0'
|
|
option heartbeat_domain 'heartbeat.melmac.ca'
|
|
option heartbeat_sleep_timeout '10'
|
|
option heartbeat_wait_timeout '10'
|
|
option user 'nobody'
|
|
option group 'nogroup'
|
|
option listen_addr '127.0.0.1'
|
|
|
|
config https-dns-proxy
|
|
option bootstrap_dns '1.1.1.1,1.0.0.1'
|
|
option resolver_url 'https://cloudflare-dns.com/dns-query'
|
|
option listen_port '5053'
|
|
|
|
config https-dns-proxy
|
|
option bootstrap_dns '8.8.8.8,8.8.4.4'
|
|
option resolver_url 'https://dns.google/dns-query'
|
|
option listen_port '5054'
|