# ZeroBlock Configuration
# UCI config file for OpenWrt

# =============================================================================
# DAEMON SETTINGS (ZeroBlock service)
# =============================================================================
config settings 'settings'
	option schema_version '49'
	option log_level 'warn'
	option show_trace_logs '0'
	option show_soft_matrix_editor '0'
	option soft_decision_matrix_enabled '0'
	option soft_routing_matrix_enabled '0'
	option show_custom_config_editor '0'
	option log_config_proxies '1'
	option log_disable_fakeip '1'
	option log_proxy_orchestrator '1'
	option log_subscription_parser '1'
	option log_xray_generator '1'
	option health_enabled '1'
	option dns_recovery_enabled '1'
	option dns_recovery_mode 'permanent'
	option dns_recovery_main_candidates_enabled '0'
	option dns_recovery_bootstrap_candidates_enabled '0'
	option dns_benchmark_parallelism '8'

	# Health check interval (seconds, daemon mode)
	option health_interval '600'
	option health_dns_check '1'
	option health_clash_api_check '1'
	option health_clash_api_timeout '5'
	option health_generate204_timeout '3'

	# Health monitor ping targets (space-separated IPs)
	option health_ping_ip '77.88.8.8 8.8.8.8'

	# Health monitor Opera check targets (space-separated domains)
	option health_opera_host 'ya.ru google.com'

	# List updates (also covers GeoIP CIDR refresh)
	option update_interval '1d'
	option update_time '09:00'

	# Proxy subscription updates
	option subscription_update_interval '12h'
	option whitelist_bootstrap_dns_type 'udp'
	option whitelist_bootstrap_dns_server '77.88.8.8'
	option whitelist_bootstrap_dns_via_whitelist '0'
	# Optional overrides for whitelist_proxy when it points to a subscription URL
	#option whitelist_subscription_user_agent 'Happ'
	#option whitelist_subscription_device_model 'OpenWrt'
	#option whitelist_subscription_device_os 'openwrt'
	#option whitelist_subscription_os_version '24.10.0'
	#option whitelist_subscription_app_version 'zeroblock/0.8.3'
	#option whitelist_subscription_hwid 'custom-hwid'

	# Dnsmasq restart timeout (seconds)
	option timeout_dnsmasq_restart '15'

	# Xray config validation timeout (seconds)
	option timeout_xray_check '15'

	# Temporary bootstrap DNS probe startup timeout (seconds)
	option timeout_dns_bootstrap_probe_start '3'

	# Temporary bootstrap DNS probe stop timeout (seconds)
	option timeout_dns_bootstrap_probe_stop '1'

	# Skip initial internet (ICMP) and DNS checks at daemon startup
	option disable_startup_check '0'

	# Delay cold startup until a default route appears in table main
	option wait_for_default_route '0'

	# If enabled, ZeroBlock disables standalone xray autostart and manages
	# xray lifecycle itself when xray-backed helpers are needed.
	option manage_xray '1'

# =============================================================================
# ENGINE SETTINGS (sing-box / proxy engine)
# =============================================================================
config engine 'engine'
	# Direct startup generate_204 probe timeout (seconds)
	option startup_direct_probe_timeout '3'
	# Foreign sing-box process stop wait (seconds)
	option foreign_singbox_stop_timeout '5'
	# File descriptor limit inherited by sing-box and proxy helpers
	option nofile_limit '65535'

	# DNS settings (global)
	option dns_type 'doh'
	option dns_server 'dns.google'
	option dns_runtime_fallback_enabled '0'
	option dns_runtime_fallback_strategy 'sequential'
	option dns_runtime_fallback_timeout '3'
	option dns_runtime_fallback_candidates_enabled '0'
	option bootstrap_dns_type 'udp'
	option bootstrap_dns_server '77.88.8.8'
	# Optional override for HTTP bootstrap resolve used by list/subscription/API
	# downloads when hostname resolution must bypass the обычный DNS path.
	# Does not affect startup probes/recovery or runtime DNS graph.
	# Format: IPv4 or IPv4:port
	#option user_custom_bootstrap_dns_server '1.1.1.1:5353'
	option dns_rewrite_ttl '60'
	option dns_strategy 'ipv4_only'
	option use_zeroblock_dns_directly '0'
	option dns_optimistic_cache '0'
	option autoremove_static_lease '1'

	# Clash API
	option clash_api_enabled '1'
	option clash_api_port '9090'
	option clash_ui_panel 'yacd'

	# Mark values (bits 16-18, не конфликтуют с fw4/mwan3)
	option udp_mapping 'endpoint_independent'
	option udp_filtering 'endpoint_independent'
	option udp_nat_max '0'
	option tproxy_mark '0x10000'
	option direct_mark '0x20000'
	option bt_mark '0x40000'
	option ctmark_dns '0x10000'
	option ctmark_bt '0x40000'
	option disable_output_conntrack_rules '0'

	# Exclusions
	option disable_quic '1'
	option block_dot_doq '0'
	option disable_quic_gso '0'
	# Optional sing-box runtime limits:
	#   MemoryMax / MemoryHigh - bytes or K/M/G/T suffixes
	#   ulimit_v               - virtual memory limit in KB (ulimit -v semantics)
	#   GOMEMLIMIT             - Go heap soft limit for sing-box (bytes or K/M/G/T suffixes)
	option MemoryMax '0'
	option MemoryHigh '0'
	option ulimit_v '0'
	option GOMEMLIMIT '0'
	# Native sing-box TLS fragmentation for generated TLS outbounds
	option tls_fragment '0'
	option tls_record_fragment '0'
	option exclude_ipsec '0'
	option desync_mark '0x40000000'

	# Latency testing URL (default: http://www.gstatic.com/generate_204)
	#option testing_url 'http://www.gstatic.com/generate_204'

	# Component command timeouts (seconds)
	option singbox_version_timeout '10'
	option xray_version_timeout '10'
	option trusttunnel_version_timeout '10'
	option naive_version_timeout '10'
	option naive_hash_timeout '10'
	option singbox_transport_check_timeout '10'

	# OpenFlux client helper
	option openflux_path '/usr/bin/universal-bypass-tool'
	option openflux_logging '0'
	option openflux_startup_timeout '8'

# =============================================================================
# AUTO CONFIGURATION
# =============================================================================
config auto_config 'auto_config'
	option happwner_bridge_auto_config '0'
	option amnezia_premium_importer_auto_config '0'
	option fptn_auto_config '0'
	option openflux_auto_config '0'

# =============================================================================
# UI SECTIONS (for LuCI tabs)
# =============================================================================
config dashboard 'dashboard'

config diagnostic 'diagnostic'

# =============================================================================
# ROUTING SECTIONS
# =============================================================================
# Each 'section' defines a routing rule with proxy/vpn/block mode
# Section name (e.g., 'youtube_proxy') is used as identifier
#
# Common fields:
#   enabled              - '0' or '1'
#   connection_type      - 'vpn', 'proxy', or 'block'
#
# DNS settings (per section):
#   dns_type             - 'udp', 'tcp', 'doh', 'dot', 'doq', or 'h3'
#   dns_server           - DNS server address (e.g., '8.8.8.8' or 'dns.alidns.com')
#   bootstrap_dns_type   - 'udp', 'tcp', 'doh', 'dot', 'doq' or 'h3'
#   bootstrap_dns_server - Bootstrap DNS for DoH/DoT/DoQ/H3 (IPv4 or IPv4:port)
#   dns_rewrite_ttl      - DNS cache TTL in seconds
#   disable_fakeip       - '0' or '1' - disable FakeIP for this section
#   per_section_tproxy   - '0' or '1' - dedicated TPROXY port (requires disable_fakeip=1)
#   no_sniff             - '0' or '1' - skip shared sniff for dedicated TPROXY inbound
#
# Network (per section):
#   source_interface     - List of source interfaces (e.g., 'br-lan')
#
# For VPN (connection_type = 'vpn'):
#   interface            - Network interface name (e.g., 'awg0', 'wg0', 'tun0')
#
# For proxy (connection_type = 'proxy'):
#   proxy_config_type    - 'url', 'outbound', or 'urltest'
#   proxy_string         - Proxy URL (vless://, ss://, trojan://, socks5://)
#   outbound_json        - Full sing-box outbound JSON config
#   urltest_proxy_links  - List of proxy URLs for URLTest
#   urltest_check_interval - Check interval (30s, 1m, 3m, 5m)
#   urltest_tolerance    - Latency tolerance in ms (10-1000)
#   urltest_testing_url  - URL for latency testing
#   enable_udp_over_tcp  - '0' or '1'
#
# Routing lists:
#   community_lists      - List of community list keys (youtube, discord, etc.)
#   user_domain_list_type - 'disabled', 'dynamic', or 'text'
#   user_domains         - List of custom domains
#   user_domains_text    - Text block with domains
#   user_subnet_list_type - 'disabled', 'dynamic', or 'text'
#   user_subnets         - List of custom subnets/IPs
#   user_subnets_text    - Text block with subnets
#   user_domain_lists    - List of URLs or local file paths for domain lists
#   user_subnet_lists    - List of URLs or local file paths for subnet lists
#   user_lists           - List of URLs or local paths for mixed domain+IP lists (auto-detect)
#
# Advanced:
#   fully_routed_ips     - List of local IPs to fully route
