set +e V=/www/server/panel/vhost/nginx S=$V/_pending-ai1net echo "=== S2-1 启用前 nginx -t 基线 ===" nginx -t 2>&1 | tail -1 echo "=== S2-2 拷入两份 vhost ===" cp -a "$S/ai1net.com.conf" "$V/ai1net.com.conf" cp -a "$S/relay-direct.ai1net.com.conf" "$V/relay-direct.ai1net.com.conf" ls -l "$V/ai1net.com.conf" "$V/relay-direct.ai1net.com.conf" | awk '{print $5, $9}' echo "=== S2-3 nginx -t(失败即自动回滚) ===" if nginx -t 2>&1 | tail -1 | grep -q successful; then echo "✅ 语法通过 → reload" nginx -s reload 2>&1 | tail -1 else echo "❌ 语法失败 → 立即回滚并保持原状" nginx -t 2>&1 | tail -3 rm -f "$V/ai1net.com.conf" "$V/relay-direct.ai1net.com.conf" nginx -t 2>&1 | tail -1 exit 9 fi sleep 1 echo "=== S2-4 源站侧验收(绕过 CF,直连 47) ===" curl -sk --http1.1 -o /dev/null -w "origin https://ai1net.com/portal.html => %{http_code}\n" -H "Host: ai1net.com" https://127.0.0.1/portal.html curl -sk --http1.1 -o /dev/null -w "origin https://dsh.ai1net.com/ => %{http_code}\n" -H "Host: dsh.ai1net.com" https://127.0.0.1/ echo "--- 源站侧按 SNI 看证书是否已是 ai1net(不再回 alotbuy 那张)---" echo | timeout 8 openssl s_client -connect 127.0.0.1:443 -servername ai1net.com 2>/dev/null | openssl x509 -noout -subject 2>/dev/null echo "=== S2-5 门户旧域未受影响 ===" curl -s -o /dev/null -w "alotbuy.com => %{http_code}\n" -H "Host: alotbuy.com" http://127.0.0.1/