Max Lv:meow-rs 加入可选开启的 ARP 客户端导向与 LuCI 客户端视图,默认关闭且尚未在设备上实测
Max Lv(madeye)在自己提交、目前仍未合并的 meow-rs PR #646(feat(openwrt): TPROXY UDP support, side-router gateway, and LuCI expansion)下,说明新增提交 35c48a3:加入可选开启的 ARP 客户端导向与一个 LuCI「Clients」视图,用来选择旁路由对哪些局域网设备做透明代理,无需逐台设备配置,也不用改主路由的 DHCP。 他同时说明:该做法本质上是 ARP 欺骗,默认关闭且列表为空——在开启导向并勾选设备之前不会触碰任何流量,界面与文档都写明了这一点,并把使用范围限定为「你自己管理、你自己控制的网络里的设备」;docs/openwrt.md 另给出逐设备设置网关/DNS、或在主路由做 DHCP 保留这种不做欺骗的更干净替代方案。新增的 meow-arp procd 服务依据 arp_hijack 这个 UCI 配置段自行决定是否启动,luci-app-meow 现在依赖 arping。 他还说明该功能尚未在设备上实测:目前只做了 shell/JS/JSON 语法等静态检查,执行循环与 Clients 视图都没有在真实硬件或 QEMU/Docker 环境中跑过,依赖它之前值得先在硬件上过一遍,并看一眼与 DAI、端口安全机制的相互作用。
作者原文@madeyeAdded commit
35c48a3: opt-in ARP-based client steering + a LuCI Clients view, for selecting which LAN devices the side router transparently proxies without per-client or main-router DHCP changes.Reviewer notes:
- This is ARP spoofing. It ships off by default and empty — nothing is touched until steering is enabled and a client is ticked — and the UI/docs say so plainly and scope it to "devices you administer on a network you control."
docs/openwrt.mdalso points to per-device gateway/DNS or a main-router DHCP reservation as the cleaner, non-spoofing alternative.- New
meow-arpprocd service self-gates on thearp_hijackUCI section;luci-app-meownow depends onarping.- Not yet tested on a device. Static checks only (shell/JS/JSON syntax); the enforcer loop and the Clients view have not been exercised on real hardware or in the QEMU/Docker harness. Worth a hardware pass (and a look at DAI/port-security interactions) before relying on it.