Compare commits
24 Commits
9f85c30526
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
| f5f58daad1 | |||
| 554ac3b8ba | |||
| 3255c5adb3 | |||
| 64e9dcc74a | |||
| 085e4b76c5 | |||
| 2c2617e219 | |||
| 1d09d1d4fa | |||
| 7ad5ce520b | |||
| 3b9d188efa | |||
| 84ee9a6a6c | |||
| 10abd1b7f6 | |||
| 4e11b7f06b | |||
| 5da1c1a918 | |||
| 17a30c454e | |||
| 802c19db0a | |||
| 582ec570d0 | |||
| decead019d | |||
| 83d151f014 | |||
| cb65d0f9e1 | |||
| c038200106 | |||
| 99fb8fd168 | |||
| 4a49e28408 | |||
| 1fbd3af379 | |||
| 88d4536eec |
Generated
+3
@@ -1,4 +1,7 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="Black">
|
||||
<option name="sdkName" value="Python 3.13 (base)" />
|
||||
</component>
|
||||
<component name="ProjectRootManager" version="2" project-jdk-name="Python 3.13 (base)" project-jdk-type="Python SDK" />
|
||||
</project>
|
||||
+92
-37
@@ -1,10 +1,44 @@
|
||||
FROM registry.fedoraproject.org/fedora:43
|
||||
|
||||
# Proxy configuration ARGs
|
||||
ARG HTTP_PROXY=""
|
||||
ARG HTTPS_PROXY=""
|
||||
ARG SOCKS_PROXY=""
|
||||
ARG MAX_JOBS="32"
|
||||
|
||||
# Set environment variables if proxies are provided
|
||||
ENV http_proxy=$HTTP_PROXY
|
||||
ENV https_proxy=$HTTPS_PROXY
|
||||
ENV no_proxy="localhost,127.0.0.1,::1"
|
||||
ENV MAX_JOBS=$MAX_JOBS
|
||||
ENV CMAKE_BUILD_PARALLEL_LEVEL=$MAX_JOBS
|
||||
ENV NINJAFLAGS="-j$MAX_JOBS"
|
||||
|
||||
# Configure DNF proxy if provided
|
||||
RUN if [ -n "$HTTP_PROXY" ]; then \
|
||||
echo "proxy=$HTTP_PROXY" >> /etc/dnf/dnf.conf; \
|
||||
fi
|
||||
|
||||
# Copy proxychains configuration
|
||||
COPY proxychains4.conf /etc/proxychains.conf
|
||||
|
||||
# Update proxychains4.conf if SOCKS_PROXY is provided (format: host:port)
|
||||
RUN if [ -n "$SOCKS_PROXY" ]; then \
|
||||
HOST=$(echo $SOCKS_PROXY | cut -d: -f1); \
|
||||
PORT=$(echo $SOCKS_PROXY | cut -d: -f2); \
|
||||
sed -i "s/socks5.*/socks5 $HOST $PORT/g" /etc/proxychains.conf; \
|
||||
fi
|
||||
|
||||
# Define a proxy wrapper
|
||||
RUN echo '#!/bin/bash' > /usr/local/bin/maybe_proxy && \
|
||||
echo 'if grep -q "^socks5 [0-9]" /etc/proxychains.conf; then if command -v proxychains4 >/dev/null 2>&1; then proxychains4 "$@"; else proxychains "$@"; fi; else "$@"; fi' >> /usr/local/bin/maybe_proxy && \
|
||||
chmod +x /usr/local/bin/maybe_proxy
|
||||
|
||||
# 1. System Base & Build Tools
|
||||
RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
|
||||
python3.13 python3.13-devel git rsync libatomic bash ca-certificates curl \
|
||||
gcc gcc-c++ binutils make ffmpeg-free \
|
||||
cmake ninja-build aria2c tar xz vim nano \
|
||||
cmake ninja-build aria2c tar xz vim nano proxychains-ng \
|
||||
libdrm-devel zlib-devel openssl-devel jq \
|
||||
numactl-devel gperftools-libs procps-ng \
|
||||
&& dnf clean all && rm -rf /var/cache/dnf/*
|
||||
@@ -13,18 +47,26 @@ RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
|
||||
WORKDIR /tmp
|
||||
ARG ROCM_MAJOR_VER=7
|
||||
ARG GFX=gfx120X-all
|
||||
|
||||
# 智能处理:如果 build context 里有 therock.tar.gz 就用本地的,没有就从网络拉取
|
||||
# 注意:Dockerfile 的 COPY 无法直接做条件判断,我们通过 shell 逻辑处理
|
||||
RUN set -euo pipefail; \
|
||||
BASE="https://therock-nightly-tarball.s3.amazonaws.com"; \
|
||||
PREFIX="therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}"; \
|
||||
KEY="$(curl -s "${BASE}?list-type=2&prefix=${PREFIX}" \
|
||||
| tr '<' '\n' \
|
||||
| grep -o "therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}\..*\.tar\.gz" \
|
||||
| sort -V | tail -n1)"; \
|
||||
echo "Downloading Latest Tarball: ${KEY}"; \
|
||||
aria2c -x 16 -s 16 -j 16 --file-allocation=none "${BASE}/${KEY}" -o therock.tar.gz; \
|
||||
mkdir -p /opt/rocm; \
|
||||
tar xzf therock.tar.gz -C /opt/rocm --strip-components=1; \
|
||||
rm therock.tar.gz
|
||||
if [ -f "therock.tar.gz" ]; then \
|
||||
echo "Using local therock.tar.gz from build context."; \
|
||||
else \
|
||||
echo "Local SDK not found, downloading from remote..."; \
|
||||
BASE="https://therock-nightly-tarball.s3.amazonaws.com"; \
|
||||
PREFIX="therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}"; \
|
||||
KEY="$(maybe_proxy curl -s "${BASE}?list-type=2&prefix=${PREFIX}" \
|
||||
| tr '<' '\n' \
|
||||
| grep -o "therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}\..*\.tar\.gz" \
|
||||
| sort -V | tail -n1)"; \
|
||||
echo "Downloading Latest Tarball: ${KEY}"; \
|
||||
maybe_proxy aria2c -x 16 -s 16 -k 1M --file-allocation=none "${BASE}/${KEY}" -o therock.tar.gz; \
|
||||
fi && \
|
||||
mkdir -p /opt/rocm && \
|
||||
tar xzf therock.tar.gz -C /opt/rocm --strip-components=1 && \
|
||||
rm therock.tar.gz
|
||||
|
||||
# 3. Configure Global ROCm Environment
|
||||
RUN export ROCM_PATH=/opt/rocm && \
|
||||
@@ -54,32 +96,54 @@ ENV PIP_NO_CACHE_DIR=1
|
||||
RUN printf 'source /opt/venv/bin/activate\n' > /etc/profile.d/venv.sh
|
||||
RUN python -m pip install --upgrade pip wheel packaging "setuptools<80.0.0"
|
||||
|
||||
# 5. Install PyTorch (TheRock Nightly) and PyYAML
|
||||
RUN python -m pip install \
|
||||
# 5. Install PyTorch (TheRock Nightly)
|
||||
RUN maybe_proxy python -m pip install \
|
||||
--index-url https://rocm.nightlies.amd.com/v2-staging/gfx120X-all/ \
|
||||
--pre torch torchaudio torchvision && \
|
||||
python -m pip install pyyaml
|
||||
maybe_proxy python -m pip install pyyaml
|
||||
|
||||
# Flash-Attention
|
||||
WORKDIR /opt
|
||||
ENV FLASH_ATTENTION_TRITON_AMD_ENABLE="TRUE"
|
||||
ENV ROCM_HOME="/opt/rocm"
|
||||
ENV HIP_PATH="/opt/rocm"
|
||||
ENV PATH="/opt/rocm/bin:/opt/rocm/llvm/bin:$PATH"
|
||||
ENV LD_LIBRARY_PATH="/opt/rocm/lib:/opt/rocm/lib64:/opt/rocm/llvm/lib"
|
||||
|
||||
RUN git clone https://github.com/ROCm/flash-attention.git &&\
|
||||
cd flash-attention &&\
|
||||
git checkout main_perf &&\
|
||||
python setup.py install && \
|
||||
RUN set -euo pipefail; \
|
||||
git config --global http.postBuffer 524288000; \
|
||||
git config --global http.lowSpeedLimit 0; \
|
||||
git config --global http.lowSpeedTime 999999; \
|
||||
git config --global http.version HTTP/1.1; \
|
||||
if [ -n "$SOCKS_PROXY" ]; then \
|
||||
git config --global http.proxy "socks5://$SOCKS_PROXY"; \
|
||||
git config --global https.proxy "socks5://$SOCKS_PROXY"; \
|
||||
fi; \
|
||||
CLONED=0; \
|
||||
for i in 1 2 3 4 5; do \
|
||||
rm -rf /opt/flash-attention; \
|
||||
if maybe_proxy git clone --recursive --branch main_perf --depth 1 --shallow-submodules https://github.com/ROCm/flash-attention.git /opt/flash-attention; then \
|
||||
CLONED=1; \
|
||||
break; \
|
||||
fi; \
|
||||
echo "flash-attention clone failed (attempt ${i}/5), retrying..."; \
|
||||
sleep $((i * 5)); \
|
||||
done; \
|
||||
if [ "${CLONED}" -ne 1 ]; then \
|
||||
echo "flash-attention clone failed after retries"; \
|
||||
exit 1; \
|
||||
fi; \
|
||||
cd /opt/flash-attention; \
|
||||
python setup.py install; \
|
||||
cd /opt && rm -rf /opt/flash-attention
|
||||
|
||||
# 6. Clone vLLM
|
||||
RUN git clone https://github.com/vllm-project/vllm.git /opt/vllm
|
||||
RUN maybe_proxy git clone https://github.com/vllm-project/vllm.git /opt/vllm
|
||||
WORKDIR /opt/vllm
|
||||
|
||||
# --- PATCHING ---
|
||||
# vLLM relies on 'amdsmi' to detect AMD GPUs. If it's missing or fails (common in containers),
|
||||
# vLLM falls back to CPU. We patch it to force ROCm detection.
|
||||
RUN echo "import sys, re" > patch_vllm.py && \
|
||||
echo "from pathlib import Path" >> patch_vllm.py && \
|
||||
# Patch 1: __init__.py - Force is_rocm=True and bypass amdsmi checks
|
||||
echo "p = Path('vllm/platforms/__init__.py')" >> patch_vllm.py && \
|
||||
echo "txt = p.read_text()" >> patch_vllm.py && \
|
||||
echo "txt = txt.replace('import amdsmi', '# import amdsmi')" >> patch_vllm.py && \
|
||||
@@ -88,7 +152,6 @@ RUN echo "import sys, re" > patch_vllm.py && \
|
||||
echo "txt = txt.replace('amdsmi.amdsmi_init()', 'pass')" >> patch_vllm.py && \
|
||||
echo "txt = txt.replace('amdsmi.amdsmi_shut_down()', 'pass')" >> patch_vllm.py && \
|
||||
echo "p.write_text(txt)" >> patch_vllm.py && \
|
||||
# Patch 2: rocm.py - Mock amdsmi and force device name
|
||||
echo "p = Path('vllm/platforms/rocm.py')" >> patch_vllm.py && \
|
||||
echo "txt = p.read_text()" >> patch_vllm.py && \
|
||||
echo "header = 'import sys\nfrom unittest.mock import MagicMock\nsys.modules[\"amdsmi\"] = MagicMock()\n'" >> patch_vllm.py && \
|
||||
@@ -108,11 +171,8 @@ ENV VLLM_TARGET_DEVICE="rocm"
|
||||
ENV PYTORCH_ROCM_ARCH="gfx1201"
|
||||
ENV HIP_ARCHITECTURES="gfx1201"
|
||||
ENV AMDGPU_TARGETS="gfx1201"
|
||||
ENV MAX_JOBS="4"
|
||||
ENV MAX_JOBS=$MAX_JOBS
|
||||
|
||||
# --- FIX FOR SEGFAULT ---
|
||||
# We force the Host Compiler (CC/CXX) to be the ROCm Clang, not Fedora GCC.
|
||||
# This aligns the ABI of the compiled vLLM extensions with PyTorch.
|
||||
ENV CC="/opt/rocm/llvm/bin/clang"
|
||||
ENV CXX="/opt/rocm/llvm/bin/clang++"
|
||||
|
||||
@@ -123,16 +183,14 @@ RUN export HIP_DEVICE_LIB_PATH=$(find /opt/rocm -type d -name bitcode -print -qu
|
||||
python -m pip wheel --no-build-isolation --no-deps -w /tmp/dist -v . && \
|
||||
python -m pip install /tmp/dist/*.whl
|
||||
|
||||
# --- bitsandbytes (ROCm) ---
|
||||
# bitsandbytes
|
||||
WORKDIR /opt
|
||||
RUN git clone -b rocm_enabled_multi_backend https://github.com/ROCm/bitsandbytes.git
|
||||
RUN maybe_proxy git clone -b rocm_enabled_multi_backend https://github.com/ROCm/bitsandbytes.git
|
||||
WORKDIR /opt/bitsandbytes
|
||||
|
||||
# Explicitly set HIP_PLATFORM (Docker ENV, not /etc/profile)
|
||||
ENV HIP_PLATFORM="amd"
|
||||
ENV CMAKE_PREFIX_PATH="/opt/rocm"
|
||||
|
||||
# Force CMake to use the System ROCm Compiler (/opt/rocm/llvm/bin/clang++)
|
||||
RUN cmake -S . \
|
||||
-DGPU_TARGETS="gfx1201" \
|
||||
-DBNB_ROCM_ARCH="gfx1201" \
|
||||
@@ -143,7 +201,7 @@ RUN cmake -S . \
|
||||
make -j$(nproc) && \
|
||||
python -m pip install --no-cache-dir . --no-build-isolation --no-deps
|
||||
|
||||
# 8. Final Cleanup & Runtime
|
||||
# Cleanup
|
||||
WORKDIR /opt
|
||||
RUN chmod -R a+rwX /opt && \
|
||||
find /opt/venv -type f -name "*.so" -exec strip -s {} + 2>/dev/null || true && \
|
||||
@@ -151,11 +209,8 @@ RUN chmod -R a+rwX /opt && \
|
||||
rm -rf /root/.cache/pip || true && \
|
||||
dnf clean all && rm -rf /var/cache/dnf/*
|
||||
|
||||
# Create vLLM configuration directory and model directory
|
||||
RUN mkdir -p /etc/vllm && \
|
||||
mkdir -p /model
|
||||
RUN mkdir -p /etc/vllm && mkdir -p /model
|
||||
|
||||
# Copy necessary scripts
|
||||
COPY scripts/01-rocm-envs.sh /etc/profile.d/01-rocm-envs.sh
|
||||
COPY scripts/99-toolbox-banner.sh /etc/profile.d/99-toolbox-banner.sh
|
||||
COPY scripts/zz-venv-last.sh /etc/profile.d/zz-venv-last.sh
|
||||
|
||||
+74
-1
@@ -82,6 +82,8 @@ show_usage() {
|
||||
echo " -m, --models DIR 指定模型目录路径"
|
||||
echo " -p, --port PORT 指定服务端口"
|
||||
echo " -b, --branch NAME 指定 Git 分支(默认:main)"
|
||||
echo " --http-proxy URL 指定构建时的 HTTP 代理 (例如: http://192.168.0.10:7890)"
|
||||
echo " --socks-proxy HOST:PORT 指定构建时的 SOCKS 代理 (例如: 192.168.0.10:1080)"
|
||||
echo " -h, --help 显示此帮助信息"
|
||||
echo ""
|
||||
echo "示例:"
|
||||
@@ -98,6 +100,8 @@ FORCE_BUILD=false
|
||||
STOP_ONLY=false
|
||||
DETACH=true
|
||||
CUSTOM_CONFIG=""
|
||||
HTTP_PROXY_ARG=""
|
||||
SOCKS_PROXY_ARG=""
|
||||
CUSTOM_MODELS=""
|
||||
CUSTOM_PORT=""
|
||||
|
||||
@@ -107,6 +111,14 @@ while [[ $# -gt 0 ]]; do
|
||||
FORCE_BUILD=true
|
||||
shift
|
||||
;;
|
||||
--http-proxy)
|
||||
HTTP_PROXY_ARG="$2"
|
||||
shift 2
|
||||
;;
|
||||
--socks-proxy)
|
||||
SOCKS_PROXY_ARG="$2"
|
||||
shift 2
|
||||
;;
|
||||
-s|--stop)
|
||||
STOP_ONLY=true
|
||||
shift
|
||||
@@ -258,6 +270,58 @@ has_local_changes() {
|
||||
|
||||
# 构建镜像
|
||||
build_image() {
|
||||
print_step "准备 ROCm SDK..."
|
||||
|
||||
SDK_FILE="therock.tar.gz"
|
||||
if [ ! -f "$SDK_FILE" ]; then
|
||||
print_warning "本地未发现 $SDK_FILE,开始宿主机预下载..."
|
||||
|
||||
# 自动检测 proxychains
|
||||
PROXY_WRAPPER=""
|
||||
if command -v proxychains4 >/dev/null 2>&1; then
|
||||
PROXY_WRAPPER="proxychains4"
|
||||
elif command -v proxychains >/dev/null 2>&1; then
|
||||
PROXY_WRAPPER="proxychains"
|
||||
fi
|
||||
|
||||
# 获取下载地址
|
||||
BASE="https://therock-nightly-tarball.s3.amazonaws.com"
|
||||
PREFIX="therock-dist-linux-gfx120X-all-7"
|
||||
|
||||
print_info "正在获取最新版本信息..."
|
||||
CURL_CMD="curl -s"
|
||||
[ -n "$PROXY_WRAPPER" ] && CURL_CMD="$PROXY_WRAPPER $CURL_CMD"
|
||||
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && CURL_CMD="curl -x $HTTP_PROXY_ARG -s"
|
||||
|
||||
KEY=$($CURL_CMD "${BASE}?list-type=2&prefix=${PREFIX}" \
|
||||
| tr '<' '\n' \
|
||||
| grep -o "therock-dist-linux-gfx120X-all-7\..*\.tar\.gz" \
|
||||
| sort -V | tail -n1)
|
||||
|
||||
if [ -n "$KEY" ]; then
|
||||
DOWNLOAD_URL="${BASE}/${KEY}"
|
||||
print_info "开始下载: $DOWNLOAD_URL"
|
||||
|
||||
# 优先使用 aria2c
|
||||
if command -v aria2c >/dev/null 2>&1; then
|
||||
ARIA2_CMD="aria2c -x 16 -s 16 -k 1M -c"
|
||||
[ -n "$PROXY_WRAPPER" ] && ARIA2_CMD="$PROXY_WRAPPER $ARIA2_CMD"
|
||||
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && ARIA2_CMD="$ARIA2_CMD --all-proxy=$HTTP_PROXY_ARG"
|
||||
$ARIA2_CMD "$DOWNLOAD_URL" -o "$SDK_FILE"
|
||||
else
|
||||
DL_CMD="curl -L -C - "
|
||||
[ -n "$PROXY_WRAPPER" ] && DL_CMD="$PROXY_WRAPPER $DL_CMD"
|
||||
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && DL_CMD="curl -x $HTTP_PROXY_ARG -L -C - "
|
||||
$DL_CMD "$DOWNLOAD_URL" -o "$SDK_FILE"
|
||||
fi
|
||||
else
|
||||
print_error "无法获取 SDK 下载地址,请检查代理设置或手动下载。"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
print_success "发现本地 $SDK_FILE,跳过下载。"
|
||||
fi
|
||||
|
||||
print_step "开始构建 Docker 镜像..."
|
||||
print_info "镜像名称:${IMAGE_NAME}:${IMAGE_TAG}"
|
||||
print_info "构建目录:${PROJECT_DIR}"
|
||||
@@ -265,7 +329,16 @@ build_image() {
|
||||
|
||||
BUILD_START=$(date +%s)
|
||||
|
||||
if docker build -t "${IMAGE_NAME}:${IMAGE_TAG}" .; then
|
||||
# 准备构建参数
|
||||
BUILD_ARGS="--network=host --build-arg MAX_JOBS=${MAX_JOBS:-32}"
|
||||
if [ -n "$HTTP_PROXY_ARG" ]; then
|
||||
BUILD_ARGS="${BUILD_ARGS} --build-arg HTTP_PROXY=${HTTP_PROXY_ARG} --build-arg HTTPS_PROXY=${HTTP_PROXY_ARG}"
|
||||
fi
|
||||
if [ -n "$SOCKS_PROXY_ARG" ]; then
|
||||
BUILD_ARGS="${BUILD_ARGS} --build-arg SOCKS_PROXY=${SOCKS_PROXY_ARG}"
|
||||
fi
|
||||
|
||||
if docker build ${BUILD_ARGS} -t "${IMAGE_NAME}:${IMAGE_TAG}" .; then
|
||||
BUILD_END=$(date +%s)
|
||||
BUILD_TIME=$((BUILD_END - BUILD_START))
|
||||
|
||||
|
||||
@@ -0,0 +1,165 @@
|
||||
# proxychains.conf VER 4.x
|
||||
#
|
||||
# HTTP, SOCKS4a, SOCKS5 tunneling proxifier with DNS.
|
||||
|
||||
|
||||
# The option below identifies how the ProxyList is treated.
|
||||
# only one option should be uncommented at time,
|
||||
# otherwise the last appearing option will be accepted
|
||||
#
|
||||
#dynamic_chain
|
||||
#
|
||||
# Dynamic - Each connection will be done via chained proxies
|
||||
# all proxies chained in the order as they appear in the list
|
||||
# at least one proxy must be online to play in chain
|
||||
# (dead proxies are skipped)
|
||||
# otherwise EINTR is returned to the app
|
||||
#
|
||||
# strict_chain
|
||||
dynamic_chain
|
||||
#
|
||||
# Strict - Each connection will be done via chained proxies
|
||||
# all proxies chained in the order as they appear in the list
|
||||
# all proxies must be online to play in chain
|
||||
# otherwise EINTR is returned to the app
|
||||
#
|
||||
#round_robin_chain
|
||||
#
|
||||
# Round Robin - Each connection will be done via chained proxies
|
||||
# of chain_len length
|
||||
# all proxies chained in the order as they appear in the list
|
||||
# at least one proxy must be online to play in chain
|
||||
# (dead proxies are skipped).
|
||||
# the start of the current proxy chain is the proxy after the last
|
||||
# proxy in the previously invoked proxy chain.
|
||||
# if the end of the proxy chain is reached while looking for proxies
|
||||
# start at the beginning again.
|
||||
# otherwise EINTR is returned to the app
|
||||
# These semantics are not guaranteed in a multithreaded environment.
|
||||
#
|
||||
#random_chain
|
||||
#
|
||||
# Random - Each connection will be done via random proxy
|
||||
# (or proxy chain, see chain_len) from the list.
|
||||
# this option is good to test your IDS :)
|
||||
|
||||
# Make sense only if random_chain or round_robin_chain
|
||||
#chain_len = 2
|
||||
|
||||
# Quiet mode (no output from library)
|
||||
#quiet_mode
|
||||
|
||||
## Proxy DNS requests - no leak for DNS data
|
||||
# (disable all of the 3 items below to not proxy your DNS requests)
|
||||
|
||||
# method 1. this uses the proxychains4 style method to do remote dns:
|
||||
# a thread is spawned that serves DNS requests and hands down an ip
|
||||
# assigned from an internal list (via remote_dns_subnet).
|
||||
# this is the easiest (setup-wise) and fastest method, however on
|
||||
# systems with buggy libcs and very complex software like webbrowsers
|
||||
# this might not work and/or cause crashes.
|
||||
proxy_dns
|
||||
|
||||
# method 2. use the old proxyresolv script to proxy DNS requests
|
||||
# in proxychains 3.1 style. requires `proxyresolv` in $PATH
|
||||
# plus a dynamically linked `dig` binary.
|
||||
# this is a lot slower than `proxy_dns`, doesn't support .onion URLs,
|
||||
# but might be more compatible with complex software like webbrowsers.
|
||||
#proxy_dns_old
|
||||
|
||||
# method 3. use proxychains4-daemon process to serve remote DNS requests.
|
||||
# this is similar to the threaded `proxy_dns` method, however it requires
|
||||
# that proxychains4-daemon is already running on the specified address.
|
||||
# on the plus side it doesn't do malloc/threads so it should be quite
|
||||
# compatible with complex, async-unsafe software.
|
||||
# note that if you don't start proxychains4-daemon before using this,
|
||||
# the process will simply hang.
|
||||
#proxy_dns_daemon 127.0.0.1:1053
|
||||
|
||||
# set the class A subnet number to use for the internal remote DNS mapping
|
||||
# we use the reserved 224.x.x.x range by default,
|
||||
# if the proxified app does a DNS request, we will return an IP from that range.
|
||||
# on further accesses to this ip we will send the saved DNS name to the proxy.
|
||||
# in case some control-freak app checks the returned ip, and denies to
|
||||
# connect, you can use another subnet, e.g. 10.x.x.x or 127.x.x.x.
|
||||
# of course you should make sure that the proxified app does not need
|
||||
# *real* access to this subnet.
|
||||
# i.e. dont use the same subnet then in the localnet section
|
||||
#remote_dns_subnet 127
|
||||
#remote_dns_subnet 10
|
||||
remote_dns_subnet 224
|
||||
|
||||
# Some timeouts in milliseconds
|
||||
tcp_read_time_out 15000
|
||||
tcp_connect_time_out 8000
|
||||
|
||||
### Examples for localnet exclusion
|
||||
## localnet ranges will *not* use a proxy to connect.
|
||||
## note that localnet works only when plain IP addresses are passed to the app,
|
||||
## the hostname resolves via /etc/hosts, or proxy_dns is disabled or proxy_dns_old used.
|
||||
|
||||
## Exclude connections to 192.168.1.0/24 with port 80
|
||||
# localnet 192.168.1.0:80/255.255.255.0
|
||||
|
||||
## Exclude connections to 192.168.100.0/24
|
||||
# localnet 192.168.100.0/255.255.255.0
|
||||
|
||||
## Exclude connections to ANYwhere with port 80
|
||||
# localnet 0.0.0.0:80/0.0.0.0
|
||||
# localnet [::]:80/0
|
||||
|
||||
## RFC6890 Loopback address range
|
||||
## if you enable this, you have to make sure remote_dns_subnet is not 127
|
||||
## you'll need to enable it if you want to use an application that
|
||||
## connects to localhost.
|
||||
# localnet 127.0.0.0/255.0.0.0
|
||||
# localnet ::1/128
|
||||
|
||||
## RFC1918 Private Address Ranges
|
||||
# localnet 10.0.0.0/255.0.0.0
|
||||
# localnet 172.16.0.0/255.240.0.0
|
||||
# localnet 192.168.0.0/255.255.0.0
|
||||
|
||||
### Examples for dnat
|
||||
## Trying to proxy connections to destinations which are dnatted,
|
||||
## will result in proxying connections to the new given destinations.
|
||||
## Whenever I connect to 1.1.1.1 on port 1234 actually connect to 1.1.1.2 on port 443
|
||||
# dnat 1.1.1.1:1234 1.1.1.2:443
|
||||
|
||||
## Whenever I connect to 1.1.1.1 on port 443 actually connect to 1.1.1.2 on port 443
|
||||
## (no need to write :443 again)
|
||||
# dnat 1.1.1.2:443 1.1.1.2
|
||||
|
||||
## No matter what port I connect to on 1.1.1.1 port actually connect to 1.1.1.2 on port 443
|
||||
# dnat 1.1.1.1 1.1.1.2:443
|
||||
|
||||
## Always, instead of connecting to 1.1.1.1, connect to 1.1.1.2
|
||||
# dnat 1.1.1.1 1.1.1.2
|
||||
|
||||
# ProxyList format
|
||||
# type ip port [user pass]
|
||||
# (values separated by 'tab' or 'blank')
|
||||
#
|
||||
# only numeric ipv4 addresses are valid
|
||||
#
|
||||
#
|
||||
# Examples:
|
||||
#
|
||||
# socks5 192.168.67.78 1080 lamer secret
|
||||
# http 192.168.89.3 8080 justu hidden
|
||||
# socks4 192.168.1.49 1080
|
||||
# http 192.168.39.93 8080
|
||||
#
|
||||
#
|
||||
# proxy types: http, socks4, socks5, raw
|
||||
# * raw: The traffic is simply forwarded to the proxy without modification.
|
||||
# ( auth types supported: "basic"-http "user/pass"-socks )
|
||||
#
|
||||
[ProxyList]
|
||||
|
||||
|
||||
# add proxy here ...
|
||||
# meanwile
|
||||
# defaults set to "tor"
|
||||
# socks4 127.0.0.1 9050
|
||||
socks5 192.168.0.11 1080
|
||||
Reference in New Issue
Block a user