Skip to content

v2.7.0

Pre-release
Pre-release

Choose a tag to compare

@KKRainbow KKRainbow released this 06 Oct 13:21
8b7f1f0

EasyTier v2.7.0 Pre-release

本次新增中心化网络管理、多客户端 WireGuard 入口,并改进连接稳定性与性能。

升级注意事项

  • 配置服务器地址必须使用完整 URL。 --config-server 不再接受仅 token 的简写。原来只填写 my-token 的配置应改为实际服务器地址,例如 udp://config-server.easytier.cn:22020/my-token;自建服务请使用自己的地址。#2459
  • 旧版 WireGuard 入口配置需要迁移。 不再接受 wg://host:port/CIDR 或旧的 client_cidr 字段;改用 wg://host:port、专用服务端私钥及具名客户端(--vpn-portal-client NAME=CIDR)。请通过新版 GUI/Web 或 CLI 重新导出客户端配置。#2502
  • Web 管理端新增中心化网络管理及数据库迁移。 升级前备份数据库和配置;如需回退,应同时恢复升级前的数据库备份。#2622

新功能

  • 中心化网络管理控制台:集中创建网络、管理设备和成员、分配地址、配置凭据及 ACL,并查看运行状态;支持 Gateway 和临时成员管理。#2622
  • 多客户端 WireGuard 入口:支持具名客户端、独立状态和流量统计,可在运行时增删客户端;Web 和 GUI 提供配置及管理入口。#2502 #2514 #2537
  • 凭据和 ACL 动态管理:通过 TOML 声明并持久化受管凭据,支持运行时替换 ACL,以及 JSON/TOML 格式的 ACL 输入。#2515 #2513 #2540
  • 连接与部署配置:新增 Linux 底层 socket 的 SO_MARK 支持、可配置 TCP STUN 服务器、WebSocket 监听 URL 路径,以及 Docker 健康检查。#2288 #2314 #1967 #2279
  • Android 与 Magisk:Android 新增 VPN 快捷设置磁贴,Magisk 模块新增 WebUI 配置界面。#2511 #2563
  • 开发者集成:拆分可移植 Core,扩展 FFI/JNI、Go 和 WASI 接口,支持浏览器及 Cloudflare Workers 宿主,并新增独立 WASM 配置生成器和精简原生客户端。相关集成代码见仓库,下载附件仍以本次发布列出的平台包为准。#2451 #2548 #2480 #2479

主要修复与改进

  • 连接与路由稳定性:修复低延迟优先路由、非对称直连恢复、IPv6 多公网地址打洞、OSPF 元数据过期后的同步,以及接收限速时的存活探测;TCP 打洞连接使用每秒心跳维持连接。#2358 #2476 #2387 #2599 #2590 #2632
  • 代理与中继:修复 QUIC 乱序流量导致的连接失败、KCP 控制消息丢失后的恢复、TCP 流隔离、SOCKS5 转发,以及安全中继会话和转发包处理。QUIC 优先协商 ETQ1,将校验绑定到包序号,并支持与旧版本连接时回退;通信双方都升级后才能完整受益。#2565 #2569 #2391 #2393 #2618
  • 访问控制与配置管理:修复双向 ping 绕过入站丢弃规则、Web 会话列表未按当前用户隔离,以及凭据和安全模式配置加载问题。#2570 #2445 #2301 #2562
  • Web 管理连接:改进配置同步、会话替换与路由归属;客户端握手并发处理,避免空闲连接阻塞后续设备接入,并为配置服务器拨号增加超时。#2567 #2522 #2609 #2633 #2461
  • 平台体验:修复 Windows 开机无网络时的 TUN 启动、服务自启动及 UDP 广播回环;修复 macOS 后台服务的 HOME 环境;改进 Android VPN 启动状态、返回键行为和重复通知。macOS GUI 构建流程增加签名和公证。#2500 #2579 #2619 #2509 #2491 #2546 #2559 #2418
  • 性能与资源回收:减少数据路径同步和缓冲区开销,优化 QUIC/WireGuard 缓冲区,改进内存回收,并及时清理已完成的连接处理任务。#2453 #2625 #2626 #2627 #2428 #2598

完整变更记录:v2.6.4 → v2.7.0


English

This release adds central network management and multi-client WireGuard portals, with improvements to connection reliability and performance.

Upgrade notes

  • Use a full config-server URL. Token-only shorthand for --config-server is no longer supported. Replace my-token with the actual endpoint, for example udp://config-server.easytier.cn:22020/my-token, or your self-hosted server URL. #2459
  • Migrate legacy WireGuard portal configuration. URLs of the form wg://host:port/CIDR and the old client_cidr field are rejected. Use wg://host:port, a dedicated server private key and named clients (--vpn-portal-client NAME=CIDR), then export fresh client configurations through the updated GUI/Web or CLI. #2502
  • Back up Web databases and configuration before upgrading. Central network management introduces database migrations; restore the pre-upgrade database backup when rolling back. #2622

Highlights

  • Central network management with device membership, addressing, credentials, ACL policies, Gateways and temporary peers. #2622
  • Multi-client WireGuard portals with runtime client changes, per-client status and traffic metrics, and Web/GUI management. #2502 #2514 #2537
  • Declarative managed credentials and live ACL replacement, including JSON/TOML ACL input. #2515 #2513 #2540
  • Linux socket marks, configurable TCP STUN servers, WebSocket listener paths and Docker health checks. #2288 #2314 #1967 #2279
  • Android VPN quick settings tile and Magisk WebUI configuration. #2511 #2563
  • Portable Core and expanded embedding interfaces, including browser/Workers hosts, a standalone WASM config generator and a compact native client. These integrations are available in the repository; packaged downloads are listed in the release assets. #2451 #2548 #2480 #2479

Fixes and performance

  • More reliable direct connections, routing, IPv6 hole punching and peer liveness; TCP hole-punched connections now keep a one-second heartbeat. #2476 #2599 #2590 #2632
  • Fixes for QUIC packet reordering, KCP recovery, TCP flow isolation, SOCKS5 forwarding and secure relay handling. QUIC now prefers ETQ1, which binds packet checksums to packet numbers, with fallback for legacy peers; upgrade both peers to benefit fully from the fix. #2565 #2569 #2391 #2618
  • Fixes for inbound ICMP ACL bypass and user scoping of Web session lists. #2570 #2445
  • More reliable managed configuration and session replacement, plus concurrent client handshakes and config-server dial timeouts. #2567 #2609 #2633 #2461
  • Windows startup and broadcast-relay fixes, macOS service environment fixes and signed/notarized macOS GUI builds, plus Android VPN lifecycle and notification fixes. #2579 #2619 #2509 #2418 #2491 #2546 #2559
  • Lower packet-processing overhead, improved buffer reuse and memory reclamation, and timely cleanup of completed connection handlers. #2453 #2625 #2626 #2428 #2598

Full changelog: v2.6.4 → v2.7.0