# Check system check_sys() { local checkType=$1 local value=$2
local release='' local systemPackage=''
if [[ -f /etc/redhat-release ]]; then release="centos" systemPackage="yum" elif grep -Eqi "debian|raspbian" /etc/issue; then release="debian" systemPackage="apt" elif grep -Eqi "ubuntu" /etc/issue; then release="ubuntu" systemPackage="apt" elif grep -Eqi "centos|red hat|redhat" /etc/issue; then release="centos" systemPackage="yum" elif grep -Eqi "debian|raspbian" /proc/version; then release="debian" systemPackage="apt" elif grep -Eqi "ubuntu" /proc/version; then release="ubuntu" systemPackage="apt" elif grep -Eqi "centos|red hat|redhat" /proc/version; then release="centos" systemPackage="yum" fi
if [[ "${checkType}" == "sysRelease" ]]; then if [ "${value}" == "${release}" ]; then return 0 else return 1 fi elif [[ "${checkType}" == "packageManager" ]]; then if [ "${value}" == "${systemPackage}" ]; then return 0 else return 1 fi fi }
check_kernel_version() { local kernel_version=$(uname -r | cut -d- -f1) if version_gt "${kernel_version}" 3.7.0; then return 0 else return 1 fi }
check_kernel_headers() { if check_sys packageManager yum; then if rpm -qa | grep -q headers-$(uname -r); then return 0 else return 1 fi elif check_sys packageManager apt; then if dpkg -s linux-headers-$(uname -r) >/dev/null 2>&1; then return 0 else return 1 fi fi return 1 }
# Get version getversion() { if [[ -s /etc/redhat-release ]]; then grep -oE "[0-9.]+" /etc/redhat-release else grep -oE "[0-9.]+" /etc/issue fi }
# CentOS version centosversion() { if check_sys sysRelease centos; then local code=$1 local version="$(getversion)" local main_ver=${version%%.*} if [ "$main_ver" == "$code" ]; then return 0 else return 1 fi else return 1 fi }
# Pre-installation settings pre_install() { # Check OS system if check_sys sysRelease centos; then # Not support CentOS 5 if centosversion 5; then echo -e "[${red}Error${plain}] Not support CentOS 5, please change to CentOS 6 or 7 and try again." exit 1 fi else echo -e "[${red}Error${plain}] Your OS is not supported to run it, please change OS to CentOS and try again." exit 1 fi
# Check version check_version status=$? if [ ${status} -eq 0 ]; then echo -e "[${green}Info${plain}] Latest version ${green}${shadowsocks_libev_ver}${plain} has already been installed, nothing to do..." exit 0 elif [ ${status} -eq 1 ]; then echo -e "Installed version: ${red}${installed_ver}${plain}" echo -e "Latest version: ${red}${latest_ver}${plain}" echo -e "[${green}Info${plain}] Upgrade shadowsocks libev to latest version..." ps -ef | grep -v grep | grep -i "ss-server" >/dev/null 2>&1 if [ $? -eq 0 ]; then /etc/init.d/shadowsocks stop fi elif [ ${status} -eq 2 ]; then print_info get_latest_version echo -e "[${green}Info${plain}] Latest version: ${green}${shadowsocks_libev_ver}${plain}" echo fi
# Set shadowsocks-libev config password echo"Please enter password for shadowsocks-libev:" read -p "(Default password: teddysun.com):" shadowsockspwd [ -z "${shadowsockspwd}" ] && shadowsockspwd="teddysun.com" echo echo"---------------------------" echo"password = ${shadowsockspwd}" echo"---------------------------" echo
# Set shadowsocks-libev config port whiletrue; do dport=$(shuf -i 9000-19999 -n 1) echo -e "Please enter a port for shadowsocks-libev [1-65535]" read -p "(Default port: ${dport}):" shadowsocksport [ -z "$shadowsocksport" ] && shadowsocksport=${dport} expr "${shadowsocksport}" + 1 &>/dev/null if [ $? -eq 0 ]; then if [ "${shadowsocksport}" -ge 1 ] && [ "${shadowsocksport}" -le 65535 ] && [ "${shadowsocksport:0:1}" != 0 ]; then echo echo"---------------------------" echo"port = ${shadowsocksport}" echo"---------------------------" echo break fi fi echo -e "[${red}Error${plain}] Please enter a correct number [1-65535]" done
# Set shadowsocks config stream ciphers whiletrue; do echo -e "Please select stream cipher for shadowsocks-libev:" for ((i = 1; i <= ${#ciphers[@]}; i++)); do hint="${ciphers[$i - 1]}" echo -e "${green}${i}${plain}) ${hint}" done read -p "Which cipher you'd select(Default: ${ciphers[0]}):" pick [ -z "$pick" ] && pick=1 expr ${pick} + 1 &>/dev/null if [ $? -ne 0 ]; then echo -e "[${red}Error${plain}] Please enter a number" continue fi if [[ "$pick" -lt 1 || "$pick" -gt ${#ciphers[@]} ]]; then echo -e "[${red}Error${plain}] Please enter a number between 1 and ${#ciphers[@]}" continue fi shadowsockscipher=${ciphers[$pick - 1]} echo echo"---------------------------" echo"cipher = ${shadowsockscipher}" echo"---------------------------" echo break done
install_libsodium() { if [ ! -f /usr/lib/libsodium.a ]; then cd"${cur_dir}" || exit tar zxf ${libsodium_file}.tar.gz cd${libsodium_file} || exit ./configure --prefix=/usr && make && make install if [ $? -ne 0 ]; then echo -e "[${red}Error${plain}] ${libsodium_file} install failed." exit 1 fi else echo -e "[${green}Info${plain}] ${libsodium_file} already installed." fi }
install_mbedtls() { if [ ! -f /usr/lib/libmbedtls.a ]; then cd"${cur_dir}" || exit tar zxf "${mbedtls_file}".tar.gz cd"${mbedtls_file}" || exit make SHARED=1 CFLAGS=-fPIC make DESTDIR=/usr install if [ $? -ne 0 ]; then echo -e "[${red}Error${plain}] ${mbedtls_file} install failed." exit 1 fi else echo -e "[${green}Info${plain}] ${mbedtls_file} already installed." fi }
# Config shadowsocks config_shadowsocks() { local server_value="\"0.0.0.0\"" if get_ipv6; then server_value="[\"[::0]\",\"0.0.0.0\"]" fi
if [ ! -d /etc/shadowsocks-libev ]; then mkdir -p /etc/shadowsocks-libev fi cat >/etc/shadowsocks-libev/config.json <<-EOF { "server":${server_value}, "server_port":${shadowsocksport}, "password":"${shadowsockspwd}", "timeout":300, "user":"nobody", "method":"${shadowsockscipher}", "fast_open":false, "nameserver":"1.0.0.1", "mode":"tcp_and_udp" } EOF }
# Firewall set firewall_set() { echo -e "[${green}Info${plain}] firewall set start..." if centosversion 6; then /etc/init.d/iptables status >/dev/null 2>&1 if [ $? -eq 0 ]; then iptables -L -n | grep -i "${shadowsocksport}" >/dev/null 2>&1 if [ $? -ne 0 ]; then iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport "${shadowsocksport}" -j ACCEPT iptables -I INPUT -m state --state NEW -m udp -p udp --dport "${shadowsocksport}" -j ACCEPT /etc/init.d/iptables save /etc/init.d/iptables restart else echo -e "[${green}Info${plain}] port ${shadowsocksport} has been set up." fi else echo -e "[${yellow}Warning${plain}] iptables looks like shutdown or not installed, please manually set it if necessary." fi elif centosversion 7; then systemctl status firewalld >/dev/null 2>&1 if [ $? -eq 0 ]; then default_zone=$(firewall-cmd --get-default-zone) firewall-cmd --permanent --zone="${default_zone}" --add-port="${shadowsocksport}"/tcp firewall-cmd --permanent --zone="${default_zone}" --add-port="${shadowsocksport}"/udp firewall-cmd --reload else echo -e "[${yellow}Warning${plain}] firewalld looks like not running or not installed, please enable port ${shadowsocksport} manually if necessary." fi fi echo -e "[${green}Info${plain}] firewall set completed..." }