2.14.323 前端 2.14.237原参数目前仍保留
若有脚本需要使用这些参数请尽快修改:
_subName , _collectionName , _resolved , _no-resolve 链接参数说明 脚本使用说明
加入
2.14.323 前端 2.14.237_subName , _collectionName , _resolved , _no-resolve entrance-test.json 是使用 API 请求版entrance-test-internal.json 是使用 GEOIP 数据版 无需网络请求if ($server._domain) $server.server = $server._domaincountryCodeaso 和 countryCode 存在其一即可🇨🇳.*➮(.*)$ => $1 中转SUB_STORE_PRODUCE_CRON, 格式为 0 */2 * * *,sub,a;0 */3 * * *,col,btimeout: 脚本超时时长, 按需调整sub: 自定义需定时处理的单条订阅名, 多个用 , 连接col: 自定义需定时处理的组合订阅名, 多个用 , 连接名称 name 不是 显示名称 displayName 名encodeURIComponent 编码, 请编码后再用 , 连接Produce=type=cron,cronexp="50 */6 * * *",timeout=120,script-path=https://github.com/sub-store-org/Sub-Store/releases/latest/download/cron-sync-artifacts.min.js,argument="sub=sub1,sub2&col=col1,col2"cache, 值设为 true 即可)开启缓存, 可设置持久化缓存 sub-store-csr-expiration-time 的值来自定义默认缓存时长, 默认为 172800000 (48 * 3600 * 1000, 即 48 小时)async function operator() {
scriptResourceCache._cleanup(undefined, 1 * 3600 * 1000);
}use-local-host-item-for-proxy 仅对 IP 映射生效
[General]
use-local-host-item-for-proxy = true
[Host]
githubusercontent.com = server:https://9.9.9.11/dns-query
github.com = server:https://9.9.9.11/dns-query
google.com = server:https://9.9.9.11/dns-queryuse-local-host-item-for-proxy2.14.316User-Agentserver-cert-fingerprinthttps://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-Country.mmdb 至 /data/adb/GeoLite2-Country.mmdbhttps://github.com/P3TERX/GeoLite.mmdb/raw/download/GeoLite2-ASN.mmdb 至 /data/adb/GeoLite2-ASN.mmdb/data/adb/sub_store/scripts/sub_store.configsub_store_mmdb_country_path="/data/adb/GeoLite2-Country.mmdb"
sub_store_mmdb_asn_path="/data/adb/GeoLite2-ASN.mmdb"
sni, 其次节点服务端certificate_public_key_sha256)Trojan-Go : verify_hostname 表示服务端是否校验客户端提供的SNI与服务端设置的一致性 文档Xray : rejectUnknownSni 服务端接收到的 SNI 与证书域名不匹配即拒绝 TLS 握手 文档sing-box: 问了下薄荷佬, 官版没有,server-cert-fingerprint TLS 握手时验证服务器证书 SHA256 指纹 文档server-cert-fingerprint-sha256 文档skip-cert-verify=true :Surge will not verify the server's certificate.
sni=off :turn off SNI completely
sni 为 IP 时, 也不发 sniverifyPeerCertByName, URI 上叫 vcn$server['name-cert-verify'] = 'b.com'bing.com 自签证书:openssl req -x509 -nodes -newkey ec:<(openssl ecparam -name prime256v1) -keyout private.key -out certificate.pem -subj "/CN=bing.com" -days 36500openssl x509 -noout -fingerprint -sha256 -inform pem -in certificate.pemopenssl s_client -connect foo.com:443 -servername foo.com </dev/null 2>/dev/null | openssl x509 -noout -fingerprint -sha256 | cut -d= -f2tls-fingerprint 可自动转其他客户端, 但是 sing-box 的不一样, 没法直接转, 所以开放了字段让你自己设{ "name": "节点名", "type": "anytls", "server": "服务器", "port": 443, "password": "xYbpwdF9vIELWoLmdC", "udp": true, "sni": "a.foo.com", "fingerprint": "SHA256 指纹", "_certificate_public_key_sha256": [ "SHA-256 哈希" ] } openssl x509 -in certificate.pem -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64echo | openssl s_client -servername foo.com -connect foo.com:443 2>/dev/null | openssl x509 -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64$server._certificate_public_key_sha256 = [ "428F7quaQJvBhEr5TclcjPpsl1ryyNQo7oLBGhhC3UU=" ]
,ssm add 1(为方便小白 从 1 开始, 与 subs 列表对应)HTTP-METAntp 用于检测的 NTP 服务器. 默认 time.apple.comhttps://raw.githubusercontent.com/xream/scripts/main/surge/modules/sub-store-scripts/check/http_meta_udp.js#concurrency=10&timeout=5000&retries=1