Skip to content

LxBox v2.25.4

Choose a tag to compare

@github-actions github-actions released this 24 Sep 21:20
· 319 commits to main since this release

L×Box v2.25.4

A patch on top of v2.25.3.

The core moves to v1.14.2-lx.1. WireGuard and AmneziaWG servers no longer hold
memory until traffic actually goes through them, and two new settings control
this. The Ru internet segment preset now routes Russian apps by package name.
The server list uses two columns on a tablet. A subscription that repeats the
same server no longer shows it twice.

Патч поверх v2.25.3.

Ядро обновлено до v1.14.2-lx.1. Серверы WireGuard и AmneziaWG больше не
держат память, пока через них не пошёл трафик, и этим управляют две новые
настройки. Пресет «Ru internet segment» теперь ведёт российские приложения
по имени пакета. На планшете список серверов идёт в две колонки. Подписка,
повторяющая один и тот же сервер, больше не показывает его дважды.


🇬🇧 English

⚠️ Read before updating

  • Duplicate servers in one subscription are collapsed. If a subscription
    lists the same server several times under different names, the list keeps
    one server per configuration (the first one). The rest are skipped and
    marked duplicate with a “Duplicate of ” note. Only entries inside one
    subscription or one import are compared.
  • At most 5 WireGuard/AmneziaWG tunnels are kept built at a time by default.
    A server over the limit may show ERR on a latency check while it waits for
    a free slot, and the selected server may be torn down to free a slot.
    VPN Settings → System → WireGuard connections → Built tunnels limit →
    0 (no limit) removes the cap.

✨ Added

  • Russian apps by package in the Ru internet segment preset. A fourth rule
    set, ru-app-list (by legiz-ru), matches a connection by the Android package
    name rather than by domain or IP. Banking and government apps that go through
    third-party CDNs or by bare IP used to miss both the domain and the IP sets and
    ended up in the tunnel; now they go direct. The checkbox Russian apps by
    package
    is on by default; the set is downloaded when first enabled.
    Unchecking it leaves domains and IPs as they are
    (#116).
  • Two columns of servers on wide screens. From 600 dp of window width the
    server list on the home screen goes into two columns; narrower screens keep
    one. The layout follows rotation and split screen on the fly. Manual sort
    stays in one column, since drag and drop only works there
    (#134).
  • Appearance tab in App Settings. Theme, language and Allow rotation
    moved here from General. The Layout section also has Two columns on wide
    screens
    (on by default). Changes apply immediately and are included in the
    backup.
  • Per-app summary in the log with Verbose on. When Verbose (TRACE/DEBUG) is
    enabled on the Diagnostics tab, each tunnel start writes one per-app: line
    to Logs: allow or deny mode, allow_bypass, the packages applied and the ones
    not installed on the device.
  • Lazy tunnel build and Built tunnels limit. VPN Settings → System →
    WireGuard connections. Lazy tunnel build (on by default) builds a
    WireGuard/AmneziaWG tunnel on first use. Built tunnels limit sets how many
    stay built at once: 0 (no limit), 3, 5, 8, 12; default 5. Both need
    Suspend idle tunnels on; the limit also needs lazy build. Applied on the
    next connect.

🔄 Changed

  • Core v1.14.2-lx.1. A network change (Wi-Fi ↔ mobile) no longer resets the
    tunnel on every system notification, only on a real interface change: fewer
    drops on the move. The disabled UDP GSO lines that filled the log of a
    working AmneziaWG server are gone; connectivity was never affected
    (#95).
  • WireGuard/AmneziaWG servers take no memory until used. Previously every
    WG/AWG server in storage got a device with about 17.5 MB of receive buffers at
    tunnel start. Now a server starts unbuilt and is built on first use. On a test
    setup with eleven AWG servers the core's live memory fell from 113 MB to
    53 MB. The cost is half a second to a second on the first switch to a server.
    The Auto group probes all its members at start and builds them, so there the
    saving comes from the limit.
  • WireGuard/AmneziaWG server state in one word. The server row shows up,
    sleep or down instead of “Node asleep” / “Node not built yet”. The full
    core state and idle time are in Endpoint state on the Details screen from
    the server menu.
  • Copy link follows the common scheme format. VLESS always carries
    security, including security=reality (other Xray clients read its absence
    as “no encryption”). NaiveProxy keeps port 443. AnyTLS writes insecure
    instead of allowInsecure. Shadowsocks has no trailing =. VLESS drops the
    default fp=random; other fingerprints are kept. TUIC writes
    reduce_rtt=true instead of reduce_rtt=1. Reading has not changed: links
    saved earlier or received from other clients parse as before.
  • The preset “Russian domains & IPs” is renamed “Ru internet segment”. The
    preset id is the same, saved rules expand as before.

🩹 Fixes

  • Proxy mode no longer asks about another active VPN. In Proxy mode (local
    port only, no tunnel) Start showed “Another VPN is active. Switch to L×Box?”,
    although the other VPN is not revoked in this mode. The question now appears
    only in VPN and VPN+Proxy modes
    (#126).
  • Duplicate servers in one subscription. A subscription sent the same AWG
    server twice, as an amneziawg:// line and as a vpn:// link, and the list
    showed two identical servers. See the warning above.
  • An unchecked rule set in the Ru internet segment preset no longer switches
    off the whole rule.
    The GeoIP IP-range fallback and Russian apps by
    package
    checkboxes were only honoured by config build; the Routing screen,
    download and background update ignored them. An unchecked set was still
    downloaded, and if its file was missing, opening Routing switched off the
    whole preset rule. Now all of them follow the checkbox. A rule already
    switched off by the old behaviour stays off — turn it on once.
  • Xray subscriptions parse closer to Xray itself. WebSocket ed/eh fields
    that Xray does not declare there are no longer read; the proxy address is no
    longer put into the TLS server name when the author did not set one; the
    WebSocket host written as a separate field is no longer lost; negative
    keep-alive intervals are read as Xray reads them. An Xray element with a
    foreign protocol version no longer yields a server the provider did not send.
  • VMess Copy link without a transport lost the server address; fixed.
  • proxy-https://…?security=none no longer keeps a TLS block and goes out as
    a plain HTTP proxy, including in Copy link.

🔧 Under the hood

  • Contract with the launcher: 1.1.53. The protocol registry engine runs three
    primitives exactly as the reference does; server bodies and identities did not
    change.
  • Debug API /state returns endpoint_states.

🇷🇺 Русский

⚠️ Прочтите до обновления

  • Повторы сервера в одной подписке схлопываются. Если подписка перечисляет
    один и тот же сервер несколько раз под разными именами, в списке остаётся
    по одному серверу на конфигурацию (первый). Остальные отбрасываются и
    помечаются duplicate с пояснением «Duplicate of <имя>». Сравниваются только
    записи внутри одной подписки или одного импорта.
  • По умолчанию собранными держатся не больше 5 туннелей WireGuard/AmneziaWG.
    Сервер сверх лимита, ожидающий слота, может показать ERR при проверке
    задержки, а выбранный сервер может быть разобран ради слота.
    VPN Settings → System → WireGuard connections → Built tunnels limit →
    0 (no limit) снимает потолок.

✨ Добавлено

  • Российские приложения по имени пакета в пресете «Ru internet segment».
    Четвёртый набор правил, ru-app-list (автор legiz-ru), сопоставляет
    соединение с именем Android-пакета, а не с доменом или IP. Банковские и
    государственные приложения, которые ходят через сторонние CDN или по голому
    IP, промахивались мимо наборов доменов и IP и уходили в туннель; теперь идут
    напрямую. Галка Russian apps by package по умолчанию включена, набор
    скачивается при первом включении. Снятая галка не трогает домены и IP
    (#116).
  • Две колонки серверов на широком экране. От 600 dp ширины окна список
    серверов на главном экране идёт в две колонки, уже — в одну. Раскладка
    меняется на лету при повороте и split-screen. Ручная сортировка остаётся в
    одну колонку: перетаскивание работает только в ней
    (#134).
  • Вкладка Appearance в App Settings. Тема, язык и Allow rotation
    переехали сюда из General. В секции Layout там же Two columns on wide
    screens
    (по умолчанию включено). Применяется сразу и попадает в бэкап.
  • Сводка per-app в логе при Verbose. При включённом Verbose (TRACE/DEBUG)
    на вкладке Diagnostics каждый подъём туннеля пишет в Logs одну строку
    per-app:: режим белого или чёрного списка, allow_bypass, применённые
    пакеты и те, что не установлены на устройстве.
  • Lazy tunnel build и Built tunnels limit. VPN Settings → System →
    WireGuard connections. Lazy tunnel build (по умолчанию включён) собирает
    туннель WireGuard/AmneziaWG при первом использовании. Built tunnels limit
    задаёт, сколько туннелей держать собранными одновременно: 0 (no limit), 3,
    5, 8, 12; по умолчанию 5. Оба пункта требуют включённого Suspend idle
    tunnels
    , лимит — ещё и ленивой сборки. Применяется при следующем
    подключении.

🔄 Изменено

  • Ядро v1.14.2-lx.1. Смена сети (Wi-Fi ↔ мобильная) больше не сбрасывает
    туннель на каждом системном оповещении — только при настоящей смене
    интерфейса: меньше разрывов на ходу. Строки disabled UDP GSO, которыми был
    забит лог работающего AmneziaWG-сервера, ушли; на связь они не влияли
    (#95).
  • Серверы WireGuard/AmneziaWG не занимают память, пока не используются.
    Раньше при старте туннеля каждый WG/AWG-сервер в хранении получал устройство
    с приёмными буферами около 17,5 МБ. Теперь сервер стартует разобранным и
    собирается при первом обращении. На стенде с одиннадцатью AWG-серверами живая
    память ядра упала со 113 до 53 МБ. Плата — полсекунды-секунда на первом
    переключении на сервер. Группа Auto при старте проверяет всех членов и этим
    их собирает, так что в ней экономию даёт лимит.
  • Состояние сервера WireGuard/AmneziaWG одним словом. Строка сервера
    пишет up, sleep или down вместо «Node asleep» / «Node not built yet».
    Полное состояние ядра и время простоя — в строке Endpoint state на экране
    Details из меню сервера.
  • Copy link приведён к общему формату схем. VLESS всегда несёт security,
    в том числе security=reality (чужие Xray-клиенты читают его отсутствие как
    «без шифрования»). NaiveProxy не опускает порт 443. AnyTLS пишет insecure
    вместо allowInsecure. Shadowsocks — без хвостовых =. VLESS не пишет
    дефолтный fp=random, прочие отпечатки остаются. TUIC пишет
    reduce_rtt=true вместо reduce_rtt=1. Чтение не изменилось: ссылки,
    сохранённые раньше или присланные другими клиентами, разбираются как прежде.
  • Пресет «Russian domains & IPs» переименован в «Ru internet segment».
    Идентификатор прежний, сохранённые правила разворачиваются как раньше.

🩹 Исправления

  • В режиме Proxy приложение больше не спрашивает про другой VPN. В режиме
    Proxy (только локальный порт, без туннеля) Start показывал «Another VPN is
    active. Switch to L×Box?», хотя соседний VPN в этом режиме не отзывается.
    Теперь вопрос задаётся только в режимах VPN и VPN+Proxy
    (#126).
  • Повторы сервера в одной подписке. Подписка присылала один AWG-сервер
    дважды — строкой amneziawg:// и ссылкой vpn://, и в списке стояли два
    одинаковых сервера. См. предупреждение выше.
  • Снятая галка набора в пресете «Ru internet segment» больше не выключает всё
    правило.
    Галки GeoIP IP-range fallback и Russian apps by package
    слушала только сборка конфига; экран Routing, скачивание и фоновое обновление
    их не видели. Набор со снятой галкой всё равно скачивался, а если его файла не
    было — при открытии Routing выключалось всё правило пресета. Теперь галку
    слушают все. Правило, уже выключенное прежним поведением, само не включится —
    включите его один раз.
  • Подписки Xray разбираются ближе к самому Xray. Поля WebSocket ed/eh,
    которых Xray в этом месте не объявляет, больше не читаются; адрес прокси не
    подставляется в имя сервера TLS, если автор его не задал; хост WebSocket,
    записанный отдельным полем, не теряется; отрицательные интервалы keep-alive
    читаются так же, как у Xray. Элемент Xray с чужой версией протокола больше не
    даёт сервер, которого провайдер не присылал.
  • Copy link у VMess без транспорта терял адрес сервера; исправлено.
  • proxy-https://…?security=none больше не сохраняет блок TLS и уходит
    обычным HTTP-прокси, в том числе по Copy link.

🔧 Под капотом

  • Контракт с лаунчером: 1.1.53. Движок реестра протоколов исполняет три
    примитива так же, как эталон; тела и подписи серверов не изменились.
  • Debug API /state отдаёт endpoint_states.

Install / Установка

adb install -r LxBox-v2.25.4-arm64-v8a.apk

Без uninstall! Поверх существующей установки. Настройки и подписки сохранятся.

No uninstall needed — install over the existing one. Settings and subscriptions
are preserved.


Previous release / Предыдущий релиз: v2.25.3.