LxBox v2.25.4
L×Box v2.25.4
A patch on top of v2.25.3.
The core moves to v1.14.2-lx.1. WireGuard and AmneziaWG servers no longer hold
memory until traffic actually goes through them, and two new settings control
this. The Ru internet segment preset now routes Russian apps by package name.
The server list uses two columns on a tablet. A subscription that repeats the
same server no longer shows it twice.
Патч поверх v2.25.3.
Ядро обновлено до v1.14.2-lx.1. Серверы WireGuard и AmneziaWG больше не
держат память, пока через них не пошёл трафик, и этим управляют две новые
настройки. Пресет «Ru internet segment» теперь ведёт российские приложения
по имени пакета. На планшете список серверов идёт в две колонки. Подписка,
повторяющая один и тот же сервер, больше не показывает его дважды.
🇬🇧 English
⚠️ Read before updating
- Duplicate servers in one subscription are collapsed. If a subscription
lists the same server several times under different names, the list keeps
one server per configuration (the first one). The rest are skipped and
markedduplicatewith a “Duplicate of ” note. Only entries inside one
subscription or one import are compared. - At most 5 WireGuard/AmneziaWG tunnels are kept built at a time by default.
A server over the limit may showERRon a latency check while it waits for
a free slot, and the selected server may be torn down to free a slot.
VPN Settings → System → WireGuard connections → Built tunnels limit →
0 (no limit)removes the cap.
✨ Added
- Russian apps by package in the Ru internet segment preset. A fourth rule
set,ru-app-list(by legiz-ru), matches a connection by the Android package
name rather than by domain or IP. Banking and government apps that go through
third-party CDNs or by bare IP used to miss both the domain and the IP sets and
ended up in the tunnel; now they go direct. The checkbox Russian apps by
package is on by default; the set is downloaded when first enabled.
Unchecking it leaves domains and IPs as they are
(#116). - Two columns of servers on wide screens. From 600 dp of window width the
server list on the home screen goes into two columns; narrower screens keep
one. The layout follows rotation and split screen on the fly. Manual sort
stays in one column, since drag and drop only works there
(#134). - Appearance tab in App Settings. Theme, language and Allow rotation
moved here from General. The Layout section also has Two columns on wide
screens (on by default). Changes apply immediately and are included in the
backup. - Per-app summary in the log with Verbose on. When Verbose (TRACE/DEBUG) is
enabled on the Diagnostics tab, each tunnel start writes oneper-app:line
to Logs: allow or deny mode,allow_bypass, the packages applied and the ones
not installed on the device. - Lazy tunnel build and Built tunnels limit. VPN Settings → System →
WireGuard connections. Lazy tunnel build (on by default) builds a
WireGuard/AmneziaWG tunnel on first use. Built tunnels limit sets how many
stay built at once:0 (no limit), 3, 5, 8, 12; default 5. Both need
Suspend idle tunnels on; the limit also needs lazy build. Applied on the
next connect.
🔄 Changed
- Core v1.14.2-lx.1. A network change (Wi-Fi ↔ mobile) no longer resets the
tunnel on every system notification, only on a real interface change: fewer
drops on the move. Thedisabled UDP GSOlines that filled the log of a
working AmneziaWG server are gone; connectivity was never affected
(#95). - WireGuard/AmneziaWG servers take no memory until used. Previously every
WG/AWG server in storage got a device with about 17.5 MB of receive buffers at
tunnel start. Now a server starts unbuilt and is built on first use. On a test
setup with eleven AWG servers the core's live memory fell from 113 MB to
53 MB. The cost is half a second to a second on the first switch to a server.
The Auto group probes all its members at start and builds them, so there the
saving comes from the limit. - WireGuard/AmneziaWG server state in one word. The server row shows
up,
sleepordowninstead of “Node asleep” / “Node not built yet”. The full
core state and idle time are in Endpoint state on the Details screen from
the server menu. - Copy link follows the common scheme format. VLESS always carries
security, includingsecurity=reality(other Xray clients read its absence
as “no encryption”). NaiveProxy keeps port443. AnyTLS writesinsecure
instead ofallowInsecure. Shadowsocks has no trailing=. VLESS drops the
defaultfp=random; other fingerprints are kept. TUIC writes
reduce_rtt=trueinstead ofreduce_rtt=1. Reading has not changed: links
saved earlier or received from other clients parse as before. - The preset “Russian domains & IPs” is renamed “Ru internet segment”. The
preset id is the same, saved rules expand as before.
🩹 Fixes
- Proxy mode no longer asks about another active VPN. In Proxy mode (local
port only, no tunnel) Start showed “Another VPN is active. Switch to L×Box?”,
although the other VPN is not revoked in this mode. The question now appears
only in VPN and VPN+Proxy modes
(#126). - Duplicate servers in one subscription. A subscription sent the same AWG
server twice, as anamneziawg://line and as avpn://link, and the list
showed two identical servers. See the warning above. - An unchecked rule set in the Ru internet segment preset no longer switches
off the whole rule. The GeoIP IP-range fallback and Russian apps by
package checkboxes were only honoured by config build; the Routing screen,
download and background update ignored them. An unchecked set was still
downloaded, and if its file was missing, opening Routing switched off the
whole preset rule. Now all of them follow the checkbox. A rule already
switched off by the old behaviour stays off — turn it on once. - Xray subscriptions parse closer to Xray itself. WebSocket
ed/ehfields
that Xray does not declare there are no longer read; the proxy address is no
longer put into the TLS server name when the author did not set one; the
WebSocket host written as a separate field is no longer lost; negative
keep-alive intervals are read as Xray reads them. An Xray element with a
foreign protocol version no longer yields a server the provider did not send. - VMess Copy link without a transport lost the server address; fixed.
proxy-https://…?security=noneno longer keeps a TLS block and goes out as
a plain HTTP proxy, including in Copy link.
🔧 Under the hood
- Contract with the launcher: 1.1.53. The protocol registry engine runs three
primitives exactly as the reference does; server bodies and identities did not
change. - Debug API
/statereturnsendpoint_states.
🇷🇺 Русский
⚠️ Прочтите до обновления
- Повторы сервера в одной подписке схлопываются. Если подписка перечисляет
один и тот же сервер несколько раз под разными именами, в списке остаётся
по одному серверу на конфигурацию (первый). Остальные отбрасываются и
помечаютсяduplicateс пояснением «Duplicate of <имя>». Сравниваются только
записи внутри одной подписки или одного импорта. - По умолчанию собранными держатся не больше 5 туннелей WireGuard/AmneziaWG.
Сервер сверх лимита, ожидающий слота, может показатьERRпри проверке
задержки, а выбранный сервер может быть разобран ради слота.
VPN Settings → System → WireGuard connections → Built tunnels limit →
0 (no limit)снимает потолок.
✨ Добавлено
- Российские приложения по имени пакета в пресете «Ru internet segment».
Четвёртый набор правил,ru-app-list(автор legiz-ru), сопоставляет
соединение с именем Android-пакета, а не с доменом или IP. Банковские и
государственные приложения, которые ходят через сторонние CDN или по голому
IP, промахивались мимо наборов доменов и IP и уходили в туннель; теперь идут
напрямую. Галка Russian apps by package по умолчанию включена, набор
скачивается при первом включении. Снятая галка не трогает домены и IP
(#116). - Две колонки серверов на широком экране. От 600 dp ширины окна список
серверов на главном экране идёт в две колонки, уже — в одну. Раскладка
меняется на лету при повороте и split-screen. Ручная сортировка остаётся в
одну колонку: перетаскивание работает только в ней
(#134). - Вкладка Appearance в App Settings. Тема, язык и Allow rotation
переехали сюда из General. В секции Layout там же Two columns on wide
screens (по умолчанию включено). Применяется сразу и попадает в бэкап. - Сводка per-app в логе при Verbose. При включённом Verbose (TRACE/DEBUG)
на вкладке Diagnostics каждый подъём туннеля пишет в Logs одну строку
per-app:: режим белого или чёрного списка,allow_bypass, применённые
пакеты и те, что не установлены на устройстве. - Lazy tunnel build и Built tunnels limit. VPN Settings → System →
WireGuard connections. Lazy tunnel build (по умолчанию включён) собирает
туннель WireGuard/AmneziaWG при первом использовании. Built tunnels limit
задаёт, сколько туннелей держать собранными одновременно:0 (no limit), 3,
5, 8, 12; по умолчанию 5. Оба пункта требуют включённого Suspend idle
tunnels, лимит — ещё и ленивой сборки. Применяется при следующем
подключении.
🔄 Изменено
- Ядро v1.14.2-lx.1. Смена сети (Wi-Fi ↔ мобильная) больше не сбрасывает
туннель на каждом системном оповещении — только при настоящей смене
интерфейса: меньше разрывов на ходу. Строкиdisabled UDP GSO, которыми был
забит лог работающего AmneziaWG-сервера, ушли; на связь они не влияли
(#95). - Серверы WireGuard/AmneziaWG не занимают память, пока не используются.
Раньше при старте туннеля каждый WG/AWG-сервер в хранении получал устройство
с приёмными буферами около 17,5 МБ. Теперь сервер стартует разобранным и
собирается при первом обращении. На стенде с одиннадцатью AWG-серверами живая
память ядра упала со 113 до 53 МБ. Плата — полсекунды-секунда на первом
переключении на сервер. Группа Auto при старте проверяет всех членов и этим
их собирает, так что в ней экономию даёт лимит. - Состояние сервера WireGuard/AmneziaWG одним словом. Строка сервера
пишетup,sleepилиdownвместо «Node asleep» / «Node not built yet».
Полное состояние ядра и время простоя — в строке Endpoint state на экране
Details из меню сервера. - Copy link приведён к общему формату схем. VLESS всегда несёт
security,
в том числеsecurity=reality(чужие Xray-клиенты читают его отсутствие как
«без шифрования»). NaiveProxy не опускает порт443. AnyTLS пишетinsecure
вместоallowInsecure. Shadowsocks — без хвостовых=. VLESS не пишет
дефолтныйfp=random, прочие отпечатки остаются. TUIC пишет
reduce_rtt=trueвместоreduce_rtt=1. Чтение не изменилось: ссылки,
сохранённые раньше или присланные другими клиентами, разбираются как прежде. - Пресет «Russian domains & IPs» переименован в «Ru internet segment».
Идентификатор прежний, сохранённые правила разворачиваются как раньше.
🩹 Исправления
- В режиме Proxy приложение больше не спрашивает про другой VPN. В режиме
Proxy (только локальный порт, без туннеля) Start показывал «Another VPN is
active. Switch to L×Box?», хотя соседний VPN в этом режиме не отзывается.
Теперь вопрос задаётся только в режимах VPN и VPN+Proxy
(#126). - Повторы сервера в одной подписке. Подписка присылала один AWG-сервер
дважды — строкойamneziawg://и ссылкойvpn://, и в списке стояли два
одинаковых сервера. См. предупреждение выше. - Снятая галка набора в пресете «Ru internet segment» больше не выключает всё
правило. Галки GeoIP IP-range fallback и Russian apps by package
слушала только сборка конфига; экран Routing, скачивание и фоновое обновление
их не видели. Набор со снятой галкой всё равно скачивался, а если его файла не
было — при открытии Routing выключалось всё правило пресета. Теперь галку
слушают все. Правило, уже выключенное прежним поведением, само не включится —
включите его один раз. - Подписки Xray разбираются ближе к самому Xray. Поля WebSocket
ed/eh,
которых Xray в этом месте не объявляет, больше не читаются; адрес прокси не
подставляется в имя сервера TLS, если автор его не задал; хост WebSocket,
записанный отдельным полем, не теряется; отрицательные интервалы keep-alive
читаются так же, как у Xray. Элемент Xray с чужой версией протокола больше не
даёт сервер, которого провайдер не присылал. - Copy link у VMess без транспорта терял адрес сервера; исправлено.
proxy-https://…?security=noneбольше не сохраняет блок TLS и уходит
обычным HTTP-прокси, в том числе по Copy link.
🔧 Под капотом
- Контракт с лаунчером: 1.1.53. Движок реестра протоколов исполняет три
примитива так же, как эталон; тела и подписи серверов не изменились. - Debug API
/stateотдаётendpoint_states.
Install / Установка
adb install -r LxBox-v2.25.4-arm64-v8a.apkБез uninstall! Поверх существующей установки. Настройки и подписки сохранятся.
No uninstall needed — install over the existing one. Settings and subscriptions
are preserved.
Previous release / Предыдущий релиз: v2.25.3.