Compare commits

..

22 Commits

Author SHA1 Message Date
cjw f5f58daad1 x 2026-03-17 22:02:45 +08:00
cjw 554ac3b8ba x 2026-03-17 00:31:25 +08:00
cjw 3255c5adb3 x 2026-03-15 22:56:20 +08:00
cjw 64e9dcc74a x 2026-03-15 22:50:28 +08:00
cjw 085e4b76c5 x 2026-03-15 22:29:11 +08:00
cjw 2c2617e219 x 2026-03-14 02:51:49 +08:00
cjw 1d09d1d4fa x 2026-03-14 02:44:09 +08:00
cjw 7ad5ce520b x 2026-03-14 02:31:01 +08:00
cjw 3b9d188efa x 2026-03-14 02:01:03 +08:00
cjw 84ee9a6a6c x 2026-03-14 01:53:03 +08:00
cjw 10abd1b7f6 x 2026-03-14 01:49:03 +08:00
cjw 4e11b7f06b X 2026-03-14 01:42:15 +08:00
cjw 5da1c1a918 x 2026-03-14 01:39:59 +08:00
cjw 17a30c454e x 2026-03-14 01:37:08 +08:00
cjw 802c19db0a x 2026-03-14 01:31:47 +08:00
cjw 582ec570d0 x 2026-03-14 01:27:23 +08:00
cjw decead019d x 2026-03-14 01:19:22 +08:00
cjw 83d151f014 x 2026-03-14 01:15:03 +08:00
cjw cb65d0f9e1 x 2026-03-14 01:04:45 +08:00
cjw c038200106 x 2026-03-14 00:52:27 +08:00
cjw 99fb8fd168 x 2026-03-14 00:40:20 +08:00
cjw 4a49e28408 x 2026-03-14 00:28:24 +08:00
3 changed files with 333 additions and 40 deletions
+85 -30
View File
@@ -1,10 +1,44 @@
FROM registry.fedoraproject.org/fedora:43 FROM registry.fedoraproject.org/fedora:43
# Proxy configuration ARGs
ARG HTTP_PROXY=""
ARG HTTPS_PROXY=""
ARG SOCKS_PROXY=""
ARG MAX_JOBS="32"
# Set environment variables if proxies are provided
ENV http_proxy=$HTTP_PROXY
ENV https_proxy=$HTTPS_PROXY
ENV no_proxy="localhost,127.0.0.1,::1"
ENV MAX_JOBS=$MAX_JOBS
ENV CMAKE_BUILD_PARALLEL_LEVEL=$MAX_JOBS
ENV NINJAFLAGS="-j$MAX_JOBS"
# Configure DNF proxy if provided
RUN if [ -n "$HTTP_PROXY" ]; then \
echo "proxy=$HTTP_PROXY" >> /etc/dnf/dnf.conf; \
fi
# Copy proxychains configuration
COPY proxychains4.conf /etc/proxychains.conf
# Update proxychains4.conf if SOCKS_PROXY is provided (format: host:port)
RUN if [ -n "$SOCKS_PROXY" ]; then \
HOST=$(echo $SOCKS_PROXY | cut -d: -f1); \
PORT=$(echo $SOCKS_PROXY | cut -d: -f2); \
sed -i "s/socks5.*/socks5 $HOST $PORT/g" /etc/proxychains.conf; \
fi
# Define a proxy wrapper
RUN echo '#!/bin/bash' > /usr/local/bin/maybe_proxy && \
echo 'if grep -q "^socks5 [0-9]" /etc/proxychains.conf; then if command -v proxychains4 >/dev/null 2>&1; then proxychains4 "$@"; else proxychains "$@"; fi; else "$@"; fi' >> /usr/local/bin/maybe_proxy && \
chmod +x /usr/local/bin/maybe_proxy
# 1. System Base & Build Tools # 1. System Base & Build Tools
RUN dnf -y install --setopt=install_weak_deps=False --nodocs \ RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
python3.13 python3.13-devel git rsync libatomic bash ca-certificates curl \ python3.13 python3.13-devel git rsync libatomic bash ca-certificates curl \
gcc gcc-c++ binutils make ffmpeg-free \ gcc gcc-c++ binutils make ffmpeg-free \
cmake ninja-build aria2c tar xz vim nano proxychains \ cmake ninja-build aria2c tar xz vim nano proxychains-ng \
libdrm-devel zlib-devel openssl-devel jq \ libdrm-devel zlib-devel openssl-devel jq \
numactl-devel gperftools-libs procps-ng \ numactl-devel gperftools-libs procps-ng \
&& dnf clean all && rm -rf /var/cache/dnf/* && dnf clean all && rm -rf /var/cache/dnf/*
@@ -13,17 +47,25 @@ RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
WORKDIR /tmp WORKDIR /tmp
ARG ROCM_MAJOR_VER=7 ARG ROCM_MAJOR_VER=7
ARG GFX=gfx120X-all ARG GFX=gfx120X-all
# 智能处理:如果 build context 里有 therock.tar.gz 就用本地的,没有就从网络拉取
# 注意:Dockerfile 的 COPY 无法直接做条件判断,我们通过 shell 逻辑处理
RUN set -euo pipefail; \ RUN set -euo pipefail; \
if [ -f "therock.tar.gz" ]; then \
echo "Using local therock.tar.gz from build context."; \
else \
echo "Local SDK not found, downloading from remote..."; \
BASE="https://therock-nightly-tarball.s3.amazonaws.com"; \ BASE="https://therock-nightly-tarball.s3.amazonaws.com"; \
PREFIX="therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}"; \ PREFIX="therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}"; \
KEY="$(proxychains curl -s "${BASE}?list-type=2&prefix=${PREFIX}" \ KEY="$(maybe_proxy curl -s "${BASE}?list-type=2&prefix=${PREFIX}" \
| tr '<' '\n' \ | tr '<' '\n' \
| grep -o "therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}\..*\.tar\.gz" \ | grep -o "therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}\..*\.tar\.gz" \
| sort -V | tail -n1)"; \ | sort -V | tail -n1)"; \
echo "Downloading Latest Tarball: ${KEY}"; \ echo "Downloading Latest Tarball: ${KEY}"; \
proxychains aria2c -x 16 -s 16 -j 16 --file-allocation=none "${BASE}/${KEY}" -o therock.tar.gz; \ maybe_proxy aria2c -x 16 -s 16 -k 1M --file-allocation=none "${BASE}/${KEY}" -o therock.tar.gz; \
mkdir -p /opt/rocm; \ fi && \
tar xzf therock.tar.gz -C /opt/rocm --strip-components=1; \ mkdir -p /opt/rocm && \
tar xzf therock.tar.gz -C /opt/rocm --strip-components=1 && \
rm therock.tar.gz rm therock.tar.gz
# 3. Configure Global ROCm Environment # 3. Configure Global ROCm Environment
@@ -54,32 +96,54 @@ ENV PIP_NO_CACHE_DIR=1
RUN printf 'source /opt/venv/bin/activate\n' > /etc/profile.d/venv.sh RUN printf 'source /opt/venv/bin/activate\n' > /etc/profile.d/venv.sh
RUN python -m pip install --upgrade pip wheel packaging "setuptools<80.0.0" RUN python -m pip install --upgrade pip wheel packaging "setuptools<80.0.0"
# 5. Install PyTorch (TheRock Nightly) and PyYAML # 5. Install PyTorch (TheRock Nightly)
RUN proxychains python -m pip install \ RUN maybe_proxy python -m pip install \
--index-url https://rocm.nightlies.amd.com/v2-staging/gfx120X-all/ \ --index-url https://rocm.nightlies.amd.com/v2-staging/gfx120X-all/ \
--pre torch torchaudio torchvision && \ --pre torch torchaudio torchvision && \
proxychains python -m pip install pyyaml maybe_proxy python -m pip install pyyaml
# Flash-Attention # Flash-Attention
WORKDIR /opt WORKDIR /opt
ENV FLASH_ATTENTION_TRITON_AMD_ENABLE="TRUE" ENV FLASH_ATTENTION_TRITON_AMD_ENABLE="TRUE"
ENV ROCM_HOME="/opt/rocm"
ENV HIP_PATH="/opt/rocm"
ENV PATH="/opt/rocm/bin:/opt/rocm/llvm/bin:$PATH"
ENV LD_LIBRARY_PATH="/opt/rocm/lib:/opt/rocm/lib64:/opt/rocm/llvm/lib"
RUN proxychains git clone https://github.com/ROCm/flash-attention.git &&\ RUN set -euo pipefail; \
cd flash-attention &&\ git config --global http.postBuffer 524288000; \
git checkout main_perf &&\ git config --global http.lowSpeedLimit 0; \
python setup.py install && \ git config --global http.lowSpeedTime 999999; \
git config --global http.version HTTP/1.1; \
if [ -n "$SOCKS_PROXY" ]; then \
git config --global http.proxy "socks5://$SOCKS_PROXY"; \
git config --global https.proxy "socks5://$SOCKS_PROXY"; \
fi; \
CLONED=0; \
for i in 1 2 3 4 5; do \
rm -rf /opt/flash-attention; \
if maybe_proxy git clone --recursive --branch main_perf --depth 1 --shallow-submodules https://github.com/ROCm/flash-attention.git /opt/flash-attention; then \
CLONED=1; \
break; \
fi; \
echo "flash-attention clone failed (attempt ${i}/5), retrying..."; \
sleep $((i * 5)); \
done; \
if [ "${CLONED}" -ne 1 ]; then \
echo "flash-attention clone failed after retries"; \
exit 1; \
fi; \
cd /opt/flash-attention; \
python setup.py install; \
cd /opt && rm -rf /opt/flash-attention cd /opt && rm -rf /opt/flash-attention
# 6. Clone vLLM # 6. Clone vLLM
RUN proxychains git clone https://github.com/vllm-project/vllm.git /opt/vllm RUN maybe_proxy git clone https://github.com/vllm-project/vllm.git /opt/vllm
WORKDIR /opt/vllm WORKDIR /opt/vllm
# --- PATCHING --- # --- PATCHING ---
# vLLM relies on 'amdsmi' to detect AMD GPUs. If it's missing or fails (common in containers),
# vLLM falls back to CPU. We patch it to force ROCm detection.
RUN echo "import sys, re" > patch_vllm.py && \ RUN echo "import sys, re" > patch_vllm.py && \
echo "from pathlib import Path" >> patch_vllm.py && \ echo "from pathlib import Path" >> patch_vllm.py && \
# Patch 1: __init__.py - Force is_rocm=True and bypass amdsmi checks
echo "p = Path('vllm/platforms/__init__.py')" >> patch_vllm.py && \ echo "p = Path('vllm/platforms/__init__.py')" >> patch_vllm.py && \
echo "txt = p.read_text()" >> patch_vllm.py && \ echo "txt = p.read_text()" >> patch_vllm.py && \
echo "txt = txt.replace('import amdsmi', '# import amdsmi')" >> patch_vllm.py && \ echo "txt = txt.replace('import amdsmi', '# import amdsmi')" >> patch_vllm.py && \
@@ -88,7 +152,6 @@ RUN echo "import sys, re" > patch_vllm.py && \
echo "txt = txt.replace('amdsmi.amdsmi_init()', 'pass')" >> patch_vllm.py && \ echo "txt = txt.replace('amdsmi.amdsmi_init()', 'pass')" >> patch_vllm.py && \
echo "txt = txt.replace('amdsmi.amdsmi_shut_down()', 'pass')" >> patch_vllm.py && \ echo "txt = txt.replace('amdsmi.amdsmi_shut_down()', 'pass')" >> patch_vllm.py && \
echo "p.write_text(txt)" >> patch_vllm.py && \ echo "p.write_text(txt)" >> patch_vllm.py && \
# Patch 2: rocm.py - Mock amdsmi and force device name
echo "p = Path('vllm/platforms/rocm.py')" >> patch_vllm.py && \ echo "p = Path('vllm/platforms/rocm.py')" >> patch_vllm.py && \
echo "txt = p.read_text()" >> patch_vllm.py && \ echo "txt = p.read_text()" >> patch_vllm.py && \
echo "header = 'import sys\nfrom unittest.mock import MagicMock\nsys.modules[\"amdsmi\"] = MagicMock()\n'" >> patch_vllm.py && \ echo "header = 'import sys\nfrom unittest.mock import MagicMock\nsys.modules[\"amdsmi\"] = MagicMock()\n'" >> patch_vllm.py && \
@@ -108,11 +171,8 @@ ENV VLLM_TARGET_DEVICE="rocm"
ENV PYTORCH_ROCM_ARCH="gfx1201" ENV PYTORCH_ROCM_ARCH="gfx1201"
ENV HIP_ARCHITECTURES="gfx1201" ENV HIP_ARCHITECTURES="gfx1201"
ENV AMDGPU_TARGETS="gfx1201" ENV AMDGPU_TARGETS="gfx1201"
ENV MAX_JOBS="32" ENV MAX_JOBS=$MAX_JOBS
# --- FIX FOR SEGFAULT ---
# We force the Host Compiler (CC/CXX) to be the ROCm Clang, not Fedora GCC.
# This aligns the ABI of the compiled vLLM extensions with PyTorch.
ENV CC="/opt/rocm/llvm/bin/clang" ENV CC="/opt/rocm/llvm/bin/clang"
ENV CXX="/opt/rocm/llvm/bin/clang++" ENV CXX="/opt/rocm/llvm/bin/clang++"
@@ -123,16 +183,14 @@ RUN export HIP_DEVICE_LIB_PATH=$(find /opt/rocm -type d -name bitcode -print -qu
python -m pip wheel --no-build-isolation --no-deps -w /tmp/dist -v . && \ python -m pip wheel --no-build-isolation --no-deps -w /tmp/dist -v . && \
python -m pip install /tmp/dist/*.whl python -m pip install /tmp/dist/*.whl
# --- bitsandbytes (ROCm) --- # bitsandbytes
WORKDIR /opt WORKDIR /opt
RUN proxychains git clone -b rocm_enabled_multi_backend https://github.com/ROCm/bitsandbytes.git RUN maybe_proxy git clone -b rocm_enabled_multi_backend https://github.com/ROCm/bitsandbytes.git
WORKDIR /opt/bitsandbytes WORKDIR /opt/bitsandbytes
# Explicitly set HIP_PLATFORM (Docker ENV, not /etc/profile)
ENV HIP_PLATFORM="amd" ENV HIP_PLATFORM="amd"
ENV CMAKE_PREFIX_PATH="/opt/rocm" ENV CMAKE_PREFIX_PATH="/opt/rocm"
# Force CMake to use the System ROCm Compiler (/opt/rocm/llvm/bin/clang++)
RUN cmake -S . \ RUN cmake -S . \
-DGPU_TARGETS="gfx1201" \ -DGPU_TARGETS="gfx1201" \
-DBNB_ROCM_ARCH="gfx1201" \ -DBNB_ROCM_ARCH="gfx1201" \
@@ -143,7 +201,7 @@ RUN cmake -S . \
make -j$(nproc) && \ make -j$(nproc) && \
python -m pip install --no-cache-dir . --no-build-isolation --no-deps python -m pip install --no-cache-dir . --no-build-isolation --no-deps
# 8. Final Cleanup & Runtime # Cleanup
WORKDIR /opt WORKDIR /opt
RUN chmod -R a+rwX /opt && \ RUN chmod -R a+rwX /opt && \
find /opt/venv -type f -name "*.so" -exec strip -s {} + 2>/dev/null || true && \ find /opt/venv -type f -name "*.so" -exec strip -s {} + 2>/dev/null || true && \
@@ -151,11 +209,8 @@ RUN chmod -R a+rwX /opt && \
rm -rf /root/.cache/pip || true && \ rm -rf /root/.cache/pip || true && \
dnf clean all && rm -rf /var/cache/dnf/* dnf clean all && rm -rf /var/cache/dnf/*
# Create vLLM configuration directory and model directory RUN mkdir -p /etc/vllm && mkdir -p /model
RUN mkdir -p /etc/vllm && \
mkdir -p /model
# Copy necessary scripts
COPY scripts/01-rocm-envs.sh /etc/profile.d/01-rocm-envs.sh COPY scripts/01-rocm-envs.sh /etc/profile.d/01-rocm-envs.sh
COPY scripts/99-toolbox-banner.sh /etc/profile.d/99-toolbox-banner.sh COPY scripts/99-toolbox-banner.sh /etc/profile.d/99-toolbox-banner.sh
COPY scripts/zz-venv-last.sh /etc/profile.d/zz-venv-last.sh COPY scripts/zz-venv-last.sh /etc/profile.d/zz-venv-last.sh
+74 -1
View File
@@ -82,6 +82,8 @@ show_usage() {
echo " -m, --models DIR 指定模型目录路径" echo " -m, --models DIR 指定模型目录路径"
echo " -p, --port PORT 指定服务端口" echo " -p, --port PORT 指定服务端口"
echo " -b, --branch NAME 指定 Git 分支(默认:main)" echo " -b, --branch NAME 指定 Git 分支(默认:main)"
echo " --http-proxy URL 指定构建时的 HTTP 代理 (例如: http://192.168.0.10:7890)"
echo " --socks-proxy HOST:PORT 指定构建时的 SOCKS 代理 (例如: 192.168.0.10:1080)"
echo " -h, --help 显示此帮助信息" echo " -h, --help 显示此帮助信息"
echo "" echo ""
echo "示例:" echo "示例:"
@@ -98,6 +100,8 @@ FORCE_BUILD=false
STOP_ONLY=false STOP_ONLY=false
DETACH=true DETACH=true
CUSTOM_CONFIG="" CUSTOM_CONFIG=""
HTTP_PROXY_ARG=""
SOCKS_PROXY_ARG=""
CUSTOM_MODELS="" CUSTOM_MODELS=""
CUSTOM_PORT="" CUSTOM_PORT=""
@@ -107,6 +111,14 @@ while [[ $# -gt 0 ]]; do
FORCE_BUILD=true FORCE_BUILD=true
shift shift
;; ;;
--http-proxy)
HTTP_PROXY_ARG="$2"
shift 2
;;
--socks-proxy)
SOCKS_PROXY_ARG="$2"
shift 2
;;
-s|--stop) -s|--stop)
STOP_ONLY=true STOP_ONLY=true
shift shift
@@ -258,6 +270,58 @@ has_local_changes() {
# 构建镜像 # 构建镜像
build_image() { build_image() {
print_step "准备 ROCm SDK..."
SDK_FILE="therock.tar.gz"
if [ ! -f "$SDK_FILE" ]; then
print_warning "本地未发现 $SDK_FILE,开始宿主机预下载..."
# 自动检测 proxychains
PROXY_WRAPPER=""
if command -v proxychains4 >/dev/null 2>&1; then
PROXY_WRAPPER="proxychains4"
elif command -v proxychains >/dev/null 2>&1; then
PROXY_WRAPPER="proxychains"
fi
# 获取下载地址
BASE="https://therock-nightly-tarball.s3.amazonaws.com"
PREFIX="therock-dist-linux-gfx120X-all-7"
print_info "正在获取最新版本信息..."
CURL_CMD="curl -s"
[ -n "$PROXY_WRAPPER" ] && CURL_CMD="$PROXY_WRAPPER $CURL_CMD"
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && CURL_CMD="curl -x $HTTP_PROXY_ARG -s"
KEY=$($CURL_CMD "${BASE}?list-type=2&prefix=${PREFIX}" \
| tr '<' '\n' \
| grep -o "therock-dist-linux-gfx120X-all-7\..*\.tar\.gz" \
| sort -V | tail -n1)
if [ -n "$KEY" ]; then
DOWNLOAD_URL="${BASE}/${KEY}"
print_info "开始下载: $DOWNLOAD_URL"
# 优先使用 aria2c
if command -v aria2c >/dev/null 2>&1; then
ARIA2_CMD="aria2c -x 16 -s 16 -k 1M -c"
[ -n "$PROXY_WRAPPER" ] && ARIA2_CMD="$PROXY_WRAPPER $ARIA2_CMD"
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && ARIA2_CMD="$ARIA2_CMD --all-proxy=$HTTP_PROXY_ARG"
$ARIA2_CMD "$DOWNLOAD_URL" -o "$SDK_FILE"
else
DL_CMD="curl -L -C - "
[ -n "$PROXY_WRAPPER" ] && DL_CMD="$PROXY_WRAPPER $DL_CMD"
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && DL_CMD="curl -x $HTTP_PROXY_ARG -L -C - "
$DL_CMD "$DOWNLOAD_URL" -o "$SDK_FILE"
fi
else
print_error "无法获取 SDK 下载地址,请检查代理设置或手动下载。"
exit 1
fi
else
print_success "发现本地 $SDK_FILE,跳过下载。"
fi
print_step "开始构建 Docker 镜像..." print_step "开始构建 Docker 镜像..."
print_info "镜像名称:${IMAGE_NAME}:${IMAGE_TAG}" print_info "镜像名称:${IMAGE_NAME}:${IMAGE_TAG}"
print_info "构建目录:${PROJECT_DIR}" print_info "构建目录:${PROJECT_DIR}"
@@ -265,7 +329,16 @@ build_image() {
BUILD_START=$(date +%s) BUILD_START=$(date +%s)
if DOCKER_BUILDKIT=1 docker build --build-arg MAX_JOBS=32 -t "${IMAGE_NAME}:${IMAGE_TAG}" .; then # 准备构建参数
BUILD_ARGS="--network=host --build-arg MAX_JOBS=${MAX_JOBS:-32}"
if [ -n "$HTTP_PROXY_ARG" ]; then
BUILD_ARGS="${BUILD_ARGS} --build-arg HTTP_PROXY=${HTTP_PROXY_ARG} --build-arg HTTPS_PROXY=${HTTP_PROXY_ARG}"
fi
if [ -n "$SOCKS_PROXY_ARG" ]; then
BUILD_ARGS="${BUILD_ARGS} --build-arg SOCKS_PROXY=${SOCKS_PROXY_ARG}"
fi
if docker build ${BUILD_ARGS} -t "${IMAGE_NAME}:${IMAGE_TAG}" .; then
BUILD_END=$(date +%s) BUILD_END=$(date +%s)
BUILD_TIME=$((BUILD_END - BUILD_START)) BUILD_TIME=$((BUILD_END - BUILD_START))
+165
View File
@@ -0,0 +1,165 @@
# proxychains.conf VER 4.x
#
# HTTP, SOCKS4a, SOCKS5 tunneling proxifier with DNS.
# The option below identifies how the ProxyList is treated.
# only one option should be uncommented at time,
# otherwise the last appearing option will be accepted
#
#dynamic_chain
#
# Dynamic - Each connection will be done via chained proxies
# all proxies chained in the order as they appear in the list
# at least one proxy must be online to play in chain
# (dead proxies are skipped)
# otherwise EINTR is returned to the app
#
# strict_chain
dynamic_chain
#
# Strict - Each connection will be done via chained proxies
# all proxies chained in the order as they appear in the list
# all proxies must be online to play in chain
# otherwise EINTR is returned to the app
#
#round_robin_chain
#
# Round Robin - Each connection will be done via chained proxies
# of chain_len length
# all proxies chained in the order as they appear in the list
# at least one proxy must be online to play in chain
# (dead proxies are skipped).
# the start of the current proxy chain is the proxy after the last
# proxy in the previously invoked proxy chain.
# if the end of the proxy chain is reached while looking for proxies
# start at the beginning again.
# otherwise EINTR is returned to the app
# These semantics are not guaranteed in a multithreaded environment.
#
#random_chain
#
# Random - Each connection will be done via random proxy
# (or proxy chain, see chain_len) from the list.
# this option is good to test your IDS :)
# Make sense only if random_chain or round_robin_chain
#chain_len = 2
# Quiet mode (no output from library)
#quiet_mode
## Proxy DNS requests - no leak for DNS data
# (disable all of the 3 items below to not proxy your DNS requests)
# method 1. this uses the proxychains4 style method to do remote dns:
# a thread is spawned that serves DNS requests and hands down an ip
# assigned from an internal list (via remote_dns_subnet).
# this is the easiest (setup-wise) and fastest method, however on
# systems with buggy libcs and very complex software like webbrowsers
# this might not work and/or cause crashes.
proxy_dns
# method 2. use the old proxyresolv script to proxy DNS requests
# in proxychains 3.1 style. requires `proxyresolv` in $PATH
# plus a dynamically linked `dig` binary.
# this is a lot slower than `proxy_dns`, doesn't support .onion URLs,
# but might be more compatible with complex software like webbrowsers.
#proxy_dns_old
# method 3. use proxychains4-daemon process to serve remote DNS requests.
# this is similar to the threaded `proxy_dns` method, however it requires
# that proxychains4-daemon is already running on the specified address.
# on the plus side it doesn't do malloc/threads so it should be quite
# compatible with complex, async-unsafe software.
# note that if you don't start proxychains4-daemon before using this,
# the process will simply hang.
#proxy_dns_daemon 127.0.0.1:1053
# set the class A subnet number to use for the internal remote DNS mapping
# we use the reserved 224.x.x.x range by default,
# if the proxified app does a DNS request, we will return an IP from that range.
# on further accesses to this ip we will send the saved DNS name to the proxy.
# in case some control-freak app checks the returned ip, and denies to
# connect, you can use another subnet, e.g. 10.x.x.x or 127.x.x.x.
# of course you should make sure that the proxified app does not need
# *real* access to this subnet.
# i.e. dont use the same subnet then in the localnet section
#remote_dns_subnet 127
#remote_dns_subnet 10
remote_dns_subnet 224
# Some timeouts in milliseconds
tcp_read_time_out 15000
tcp_connect_time_out 8000
### Examples for localnet exclusion
## localnet ranges will *not* use a proxy to connect.
## note that localnet works only when plain IP addresses are passed to the app,
## the hostname resolves via /etc/hosts, or proxy_dns is disabled or proxy_dns_old used.
## Exclude connections to 192.168.1.0/24 with port 80
# localnet 192.168.1.0:80/255.255.255.0
## Exclude connections to 192.168.100.0/24
# localnet 192.168.100.0/255.255.255.0
## Exclude connections to ANYwhere with port 80
# localnet 0.0.0.0:80/0.0.0.0
# localnet [::]:80/0
## RFC6890 Loopback address range
## if you enable this, you have to make sure remote_dns_subnet is not 127
## you'll need to enable it if you want to use an application that
## connects to localhost.
# localnet 127.0.0.0/255.0.0.0
# localnet ::1/128
## RFC1918 Private Address Ranges
# localnet 10.0.0.0/255.0.0.0
# localnet 172.16.0.0/255.240.0.0
# localnet 192.168.0.0/255.255.0.0
### Examples for dnat
## Trying to proxy connections to destinations which are dnatted,
## will result in proxying connections to the new given destinations.
## Whenever I connect to 1.1.1.1 on port 1234 actually connect to 1.1.1.2 on port 443
# dnat 1.1.1.1:1234 1.1.1.2:443
## Whenever I connect to 1.1.1.1 on port 443 actually connect to 1.1.1.2 on port 443
## (no need to write :443 again)
# dnat 1.1.1.2:443 1.1.1.2
## No matter what port I connect to on 1.1.1.1 port actually connect to 1.1.1.2 on port 443
# dnat 1.1.1.1 1.1.1.2:443
## Always, instead of connecting to 1.1.1.1, connect to 1.1.1.2
# dnat 1.1.1.1 1.1.1.2
# ProxyList format
# type ip port [user pass]
# (values separated by 'tab' or 'blank')
#
# only numeric ipv4 addresses are valid
#
#
# Examples:
#
# socks5 192.168.67.78 1080 lamer secret
# http 192.168.89.3 8080 justu hidden
# socks4 192.168.1.49 1080
# http 192.168.39.93 8080
#
#
# proxy types: http, socks4, socks5, raw
# * raw: The traffic is simply forwarded to the proxy without modification.
# ( auth types supported: "basic"-http "user/pass"-socks )
#
[ProxyList]
# add proxy here ...
# meanwile
# defaults set to "tor"
# socks4 127.0.0.1 9050
socks5 192.168.0.11 1080