1. 你这台 Open-Box 跑在「纯 tun(兼容)」模式——「入口模式:纯 tun」「nft 里当前没有旁路集合」、nft list set 报 No such file、meta 里没有 entryMode,都指向这一点。auto_redirect 的 nftables 规则起不来时,面板会自动降级成纯 tun 再起一次(内核卡片应该有一条「auto_redirect 起不来,已改用纯 tun 模式」的警告)。而 v0.1.243 及之前在纯 tun 下把扣过段的旁路集合整份丢掉了——默认分流的 geoip-cn / geoip-private 恰好都是扣过段的,所以一份都没旁路、白名单也不会启用,规则页却还写「已配置」。这是我们的缺陷,v0.1.244 已修:纯 tun 也用扣段后的集合(编进路由表),规则页「业务入口」会写明「路由表」和「纯 tun 只用黑名单」的原因。请先升到 v0.1.244。
For existing profiles in Exclave, rewrite "no ALPN" into ALPN "h2" and "http/1.1".
For newly created profiles in Exclave, "no ALPN" means ALPN "h3".
For exclave-core, accepts one of ALPN "h3", "h2" or "http/1.1" for now (not active-probing resistant). Starting from a future version, only accepts ALPN "h3".
It is unlikely for Shadowsocks v2ray-plugin to receive an update in the near future. Exclave has to always use ALPN "h2" and "http/1.1" for Shadowsocks v2ray-plugin.
For share link, always add the ALPN parameter to avoid implicit and ambiguous default values.
Reported to V2Ray's developer that server side is not fixed and this is a breaking change. V2ray's developer confirmed it is an unexpected breaking change. V2Ray server now accepts one of ALPN "h3", "h2" or "http/1.1" temporarily.
Regarding the TUI naming, I would prefer to keep TCP and UDP as they are.
They represent the proxied flow type, not the underlying carrier and not specifically the SOCKS5 protocol. Naming them SOCKS5 TCP and SOCKS5 UDP would couple the flow statistics to the proxy frontend and could actually make the abstraction less clear.
The intended model is:
TCP / UDP in the TUI = proxied flow type
TLS / QUIC = carrier between Vector and Portal
up / down = carrier selection for each payload direction
So I think keeping these concepts separate is preferable.
MTU 这个我们不打算在面板层固定:65535 是 sing-box 自己给 Linux 选的默认值,tun 上 MTU 越大,走 tun 那条路(纯 tun 模式的 TCP、以及 UDP)每个包越大、系统调用越少;固定成 1500 会让纯 tun 模式变慢,对你现在的 auto_redirect 路径(TCP 在入口 REDIRECT、不经 tun)则没有任何影响。你本地改了也不会坏,只是没收益。
In old http2 implementation, instantly sending multiple requests will only make one TCP dial, this is the expected behavior of http2 run code above with this
go run -tags http2legacy .
And it will return
Total Dial Calls: 1
I understand that HTTP package needs to dial multiple connections because the server HTTP version is unknown, but we have prior knowledge in net/x/http2, and perhaps we can add a config to enable the single flight mechanism in http package (or automatically use when alpn only contains h2?)
在 clash-verge-rev 关于 Global Merge 的 dns 段被「DNS 覆写」开关影响的问题讨论中,wonfen 表示 merge 的 dns 字段被合并属于 bug,已由提交 6a85d03「fix(enhance): replace DNS fields in merge overrides」修复,该提交改为替换 DNS 映射字段与 hosts 而非保留旧条目,同时保留未指定的 DNS 字段、DNS 覆写优先级与显式空值。他同时说明优先级规则:除 `dns.ipv6` 外,其余 dns 键在 GUI 设置里没有开启或留空值时,由 Merge / Script 覆盖 GUI。
Thanks for reporting this. The JSON editor's selection menu was missing from OneXray's integration with re_editor.
We have added Select All, Copy, Cut, and Paste through a long-press menu on mobile and a right-click menu on desktop. The fix applies to Raw JSON, advanced custom routing JSON, and node JSON editors.
The menu behavior is covered by automated widget tests for iOS, Android, and macOS. We have not yet verified it on a physical device running iOS 18.7.8.
The fix will be included in the next release. Closing this issue as fixed.
Poor protocol design and quality. It is only the WireGuard protocol with some easily detectable obfuscation headers. It is not resistant to the firewall at all.
No protocol specification. They did not document the protocol details, so others can only bug-to-bug compatible with them or import their library directly.
Paid premium version endorsement. They can change their attitude at any time towards their free (gratis) version. We don't want to endorse them.
VPN protocol. Exclave is a proxy software with the support for proxy protocols, and is NOT a VPN software. Supporting a VPN protocol requires to proceed a layer3-layer4-layer3 conversion, which will make the performance and user experience pretty poor. What's worse, we can only proxy TCP payload and UDP, and can not handle Layer 3 protocols and other Layer 4 protocols, and can not establish a virtual private network, defeating the purpose of a VPN protocol. Exclave did support WireGuard, but I think supporting WireGuard was a fault, which was only beneficial to Cloudflare WARP abusers. WireGuard is applicable to grandfather clause, but new protocols are not.
In this version, to fix the "security issue", V2Ray changed the default ALPN of QUIC transport from "h2" and "http/1.1" to "h3", without mentioning this is a breaking change.
What's worse, they only changed the client side and forgot to change the server side.
What's worse, even if they need to make some break changes, the should default to no ALPN rather than ALPN "h3". However, due to V2Ray's infrastructure, defaulting to no ALPN is not an easy task.
What's worse, this will also break our Shadowsocks v2ray-plugin implementation.
This is NOT a newly discovered problem. We have documented this in Exclave wiki. Because changing this behavior will break the compatibility with V2Ray, we have never had the chance to change this behavior.
liandu2024 在 Open-Box #157 中说明,sing-box 为跳过 TUN 设置的 0x2024 标记仍会继续匹配 GL.iNet 的 VPN 断网保护黑洞规则,导致内核自身的直连和代理连接全部报 no route to host。临时可关闭 VPN 策略路由或断网保护;Open-Box v0.1.230 起会在更高优先级让该标记查询主路由表,并在停内核时撤销规则。
作者原文 · 预览@liandu2024
找到原因了,你贴的 ip rule 就是答案:
9000: from all fwmark 0x2024 goto 9002 ← sing-box 装的"跳过 tun"
9002: from all nop
9910: not from all fwmark 0/0xf000 blackhole ← GL.iNet 的 VPN 断网保护
9920: from all iif br-lan blackhole
内核自己发出去的流量会打上 0x2024 这个标记,好让策略路由跳过 tun。但 sing-box 装的那条是 goto 一个空规则(9002 nop),查找不终止 —— 接着就撞上你固件的 9910:0x2024 & 0xf000 = 0x2000 ≠ 0,正好命中,整包丢弃。所以日志里直连和代理全部connect: no route to host,连国内 IP 直连都不通。
这两项任一为"拒绝",虚拟机发出来的、源 MAC 不等于网卡自身 MAC 的帧都会被 vSwitch 丢掉 —— obprobe0 的 DHCP 请求正好就是这种帧,所以必然 udhcpc: no lease。要跑这个测试,需要在对应端口组上把 MAC 地址更改 和 伪传输 改成"接受"(混杂模式不是必需的,我们不抓包)。