Skip to content

LxBox v2.25.8

Latest

Choose a tag to compare

@github-actions github-actions released this 28 Sep 10:17
· 1 commit to main since this release

L×Box v2.25.8

A patch on top of v2.25.7.

Tailscale is now served by a routing preset instead of per-node sections, and a
Tailscale node gets a Network tab with devices and exit node switching on the
fly. Home lists Tailscale nodes without an exit under NETWORKS. A node
written by hand as sing-box JSON goes to the core as written; nodes of a type
the app does not know and openvpn-client endpoints are accepted. The DNS
screen gets cache settings. Core v1.14.2-lx.8, protocol contract 1.1.99.

Google Play last shipped v2.25.5: the section «Since v2.25.5» at the end of
each language lists what v2.25.6 and v2.25.7 brought.

Патч поверх v2.25.7.

Tailscale теперь обслуживает пресет маршрутизации, а не секции узла; у узла
Tailscale появилась вкладка Network с устройствами и сменой exit node на ходу.
Главный экран показывает узлы Tailscale без выхода в NETWORKS. Узел,
записанный вручную как sing-box JSON, уходит в ядро как написан; узлы
незнакомого приложению типа и endpoint openvpn-client принимаются. На экране
DNS появились настройки кэша. Ядро v1.14.2-lx.8, контракт протоколов 1.1.99.

В Google Play последней была v2.25.5: раздел «С v2.25.5» в конце каждого языка
перечисляет, что принесли v2.25.6 и v2.25.7.


🇬🇧 English

⚠️ Read before updating

  • Node sections are gone. A node no longer carries route rules or DNS
    records of its own. The Tailscale bundle that used to live in a node is now
    the Tailscale networks preset, added once to existing installs and on by
    default. A record or a backup with a leftover sections field loads without
    error; the field is dropped
    (§575).
  • A hand-written node is no longer fixed by the app. A sing-box JSON node
    saved as your own server or a folder member goes to the core as written: an
    extra key, an AmneziaWG mtu above 1280, a tls.fragment next to a detour
    stay. The node card still lists each rule, says nothing was changed and what
    to do. Rules the core cannot start with (an unsupported flow, an invalid
    port, TLS fields naive does not take) are still applied
    (§577).
  • A node's source keeps the node only. Saving a sing-box document or an
    array in the node editor keeps the first node and says once that the rest is
    not kept; a document with no node is refused. Records saved earlier this way
    are read as the node's body, the config does not change
    (§576).

✨ Added

  • Tailscale preset. Tailscale networks serves every Tailscale node in
    the config, subscription nodes included: tailnet names go to the node's own
    DNS, addresses and names the node claims (preferred_by) go through the
    node. Deleting the preset keeps it deleted. The preset row on the Routing and
    DNS screens lists the nodes it serves
    (§578).
  • Skip presets on a node. A server or a folder member can opt out of
    presets that serve nodes one by one: the Skip presets switch on the node
    screen, stored in the record and in backups. It shows only when the template
    has such a preset for the node's type.
  • Tailscale node: Network tab. Node state, sign in and log out, this
    device, the network's devices with a ping, and the exit node list. Picking an
    exit node switches it on the fly without touching the node; Save choice
    writes it into the node. From NETWORKS the node opens on this tab
    (task 581).
  • NETWORKS on Home. While the VPN is on, Tailscale nodes without an exit
    node are listed under NETWORKS, the last entry of the Direction list.
    Instead of a delay the row shows the node state: running,
    sign-in needed, stopped or starting
    (task 579).
  • DNS cache settings. Next to Clear DNS cache: DNS cache size (1024 to
    65535 entries, default 4000), Serve stale answers (on by default) and
    Keep DNS cache after restart (on by default). The settings travel in
    backups (task 580).
  • Nodes of a type the app does not know. A sing-box node added by hand
    (Add server, paste, file, folder member, node editor) is accepted even if the
    app has no model for its type; it goes to the core as written with one info
    notice. Subscriptions still drop such entries. Pasted JSON with // and
    /* */ comments is accepted; the comments are removed
    (task 585).
  • OpenVPN endpoints as sing-box JSON. openvpn-client is a known type: it
    is accepted as your own record, inside a document and from a subscription, and
    goes to the core as written. There is no form and no .ovpn import
    (task 586).
  • Home: press back twice to exit. The first press shows
    «Press back again to exit», a second press within 2 seconds closes the app.
    An open menu, dialog or sheet closes on back as before
    (task 583).
  • Template language. A preset can repeat its rules and DNS servers for
    every matching node with for_each, and read the node's tag, record and body
    through @node and #tpl.

🔄 Changed

  • Core v1.14.2-lx.8. Synced with sing-box stable. Idle connections of
    nodes and DNS servers nothing refers to any more are closed, also when the
    device pauses. WireGuard, AmneziaWG and MASQUE inside another tunnel really
    allow fragmentation of the outer UDP datagram on Android; before, oversized
    datagrams were dropped. Hysteria, Hysteria2 and TUIC no longer allow it by
    default, QUIC finds the path MTU itself.
  • MASQUE no longer hangs without an error. vhttp: auto goes back to h3
    when the remembered h2 stops working (before, only a restart helped);
    closing an h2 tunnel does not wait minutes for a stalled write; an h3
    endpoint that never answers no longer holds every dial of the node.
  • XHTTP without xmux. An XHTTP node without an xmux section (or with an
    empty one) keeps at most three connections to the server and shares them
    between streams. Before, every stream opened its own TLS connection: dozens
    to hundreds of parallel connections to one IP, a pattern reported to be cut
    on mobile networks in Russia. An xmux section with any field set is taken as
    written.
  • A hand-written node the core would reject is dropped. A TUIC node with a
    uuid that is not a UUID, or a WireGuard node with invalid peer
    allowed_ips, is dropped with the reason in the list of dropped nodes. A
    REALITY short_id longer than 16 characters is removed; a REALITY block with
    an invalid public_key is removed whole. A MASQUE body without keys is read
    instead of being rejected
    (task 582).
  • Default emoji of a Tailscale node is 🕸️ (was 🪢). Existing node tags do
    not change.

🩹 Fixes

  • Bottom sheet and padding rules in the new screens; waiting for MASQUE
    parsing.

🔧 Under the hood

  • Contract with the launcher: 1.1.99. Which types are endpoints now comes from
    the contract registry.

📦 Since v2.25.5 (for Google Play users)

v2.25.7

  • TLS fragmentation from Xray finalmask.tcp; these fields used to be ignored
    (§573).
  • A node that goes through another node (a chain or a subscription detour) no
    longer carries TLS fragmentation
    (§574).
  • Node notifications with the same code are grouped into one entry; Xray nodes
    show fewer «field not read» notices
    (§572).

v2.25.6

  • Turn a WireGuard/AmneziaWG node off and on without restarting the tunnel
    (§557).
  • Replace a folder or a subscription with a group: Manual, Auto or Both
    (§568).
  • A selector group from a subscription or a backup stays manual and keeps
    its chosen server
    (§565).
  • Wi-Fi rules read the network name the way Android 12+ expects and say why
    the name cannot be read (approximate location, Location off)
    (§567,
    §569).
  • Imported nodes keep what the provider sent: multiplex, udp_over_tcp,
    dial options, WireGuard workers and more
    (§560).
  • A preset rule left without conditions is dropped instead of matching all
    traffic (§571).
  • Dropped subscription entries show in the subscription summary, not on a
    working node (§561).
  • A chain with a REALITY hop saves when uTLS is stripped; links to a chain
    open the chain
    (§556,
    §558).
  • A vpn:// line gives every WireGuard/AmneziaWG container of the profile;
    template variables with a list of values are chips with an optional own value
    (§570).

Full lists: v2.25.6,
v2.25.7.

🇷🇺 Русский

⚠️ Прочтите до обновления

  • Секций узла больше нет. Узел не несёт собственных правил маршрутов и
    записей DNS. Связка Tailscale, которая раньше жила в узле, теперь пресет
    Tailscale networks: в существующие установки он добавляется один раз и
    включён по умолчанию. Запись или бэкап с оставшимся полем sections
    читаются без ошибки, поле отбрасывается
    (§575).
  • Узел, записанный вручную, приложение больше не правит. Узел sing-box
    JSON, сохранённый как свой сервер или член папки, уходит в ядро как написан:
    лишний ключ, mtu AmneziaWG больше 1280, tls.fragment рядом с detour
    остаются. Карточка узла по-прежнему перечисляет каждое правило, пишет, что
    ничего не изменено, и что делать. Правила, без которых ядро не стартует
    (неподдерживаемый flow, неверный порт, поля TLS, которых не принимает
    naive), применяются как раньше
    (§577).
  • Источник узла хранит только узел. При сохранении sing-box документа или
    массива в редакторе узла остаётся первый узел, а приложение один раз говорит,
    что остальное не сохранено; документ без узла отклоняется. Записи,
    сохранённые так раньше, читаются как тело узла, конфиг не меняется
    (§576).

✨ Добавлено

  • Пресет Tailscale. Tailscale networks обслуживает каждый узел Tailscale
    в конфиге, включая узлы подписок: имена tailnet идут в DNS самого узла,
    адреса и имена, которые узел объявляет своими (preferred_by), идут через
    узел. Удалённый пресет остаётся удалённым. Строка пресета на экранах Routing
    и DNS перечисляет обслуживаемые узлы
    (§578).
  • Skip presets на узле. Свой сервер или член папки может отказаться от
    пресетов, которые обслуживают узлы поштучно: переключатель Skip presets на
    экране узла, хранится в записи и в бэкапах. Виден, только если в шаблоне есть
    такой пресет для типа узла.
  • Вкладка Network узла Tailscale. Состояние узла, вход и выход, это
    устройство, устройства сети с пингом и список exit node. Выбор exit node
    переключает его на ходу, не трогая узел; Save choice записывает выбор в
    узел. Из NETWORKS узел открывается сразу на этой вкладке
    (задача 581).
  • NETWORKS на главном экране. При включённом VPN узлы Tailscale без exit
    node перечислены в NETWORKS, последнем пункте списка направлений. Вместо
    задержки строка показывает состояние узла: running, sign-in needed,
    stopped или starting
    (задача 579).
  • Настройки кэша DNS. Рядом с Clear DNS cache: DNS cache size (от 1024
    до 65535 записей, по умолчанию 4000), Serve stale answers (включено) и
    Keep DNS cache after restart (включено). Настройки переносятся в бэкапах
    (задача 580).
  • Узлы незнакомого приложению типа. Узел sing-box, добавленный вручную
    (Add server, вставка, файл, член папки, редактор узла), принимается, даже
    если у приложения нет модели для его типа; он уходит в ядро как написан с
    одним информационным уведомлением. Подписки такие записи по-прежнему
    отбрасывают. Вставленный JSON с комментариями // и /* */ принимается,
    комментарии снимаются
    (задача 585).
  • OpenVPN как sing-box JSON. openvpn-client — известный тип: принимается
    своей записью, внутри документа и из подписки и уходит в ядро как написан.
    Формы и импорта .ovpn нет
    (задача 586).
  • Главный экран: выход двойным «назад». Первое нажатие показывает
    «Press back again to exit», второе в течение 2 секунд закрывает приложение.
    Открытое меню, диалог или лист закрываются как раньше
    (задача 583).
  • Язык шаблонов. Пресет может повторять свои правила и DNS-серверы для
    каждого подходящего узла через for_each и читать тег, запись и тело узла
    через @node и #tpl.

🔄 Изменено

  • Ядро v1.14.2-lx.8. Синхронизировано со stable sing-box.
    Простаивающие соединения узлов и DNS-серверов, на которые больше ничто не
    ссылается, закрываются, в том числе когда устройство засыпает. WireGuard,
    AmneziaWG и MASQUE внутри другого туннеля действительно разрешают
    фрагментацию внешней UDP-датаграммы на Android; раньше слишком большие
    датаграммы терялись. Hysteria, Hysteria2 и TUIC по умолчанию её больше не
    разрешают, QUIC сам находит MTU пути.
  • MASQUE больше не зависает без ошибки. vhttp: auto возвращается к h3,
    когда запомненный h2 перестал работать (раньше помогал только рестарт);
    закрытие h2-туннеля не ждёт минутами зависшую запись; h3-эндпоинт, который
    не отвечает, больше не держит все dial узла.
  • XHTTP без xmux. Узел XHTTP без секции xmux (или с пустой)
    держит не больше трёх соединений с сервером и делит их между потоками.
    Раньше каждый поток открывал своё TLS-соединение: десятки и сотни
    параллельных соединений на один IP, и такой рисунок, по сообщениям, режут в
    мобильных сетях в России. Секция xmux хотя бы с одним полем берётся как
    написана.
  • Ручной узел, который ядро отвергло бы, отбрасывается. Узел TUIC с uuid,
    который не UUID, или WireGuard с неверными allowed_ips пира отбрасывается
    с причиной в списке отброшенных. short_id REALITY длиннее 16 символов
    снимается; блок REALITY с неверным public_key снимается целиком. Тело
    MASQUE без ключей читается, а не отклоняется
    (задача 582).
  • Знак узла Tailscale по умолчанию 🕸️ (был 🪢). Теги существующих узлов не
    меняются.

🩹 Исправления

  • Правила нижнего листа и отступов в новых экранах; ожидание разбора MASQUE.

🔧 Под капотом

  • Контракт с лаунчером: 1.1.99. Какие типы являются endpoint, теперь решает
    реестр контракта.

📦 С v2.25.5 (для пользователей Google Play)

v2.25.7

  • Фрагментация TLS из Xray finalmask.tcp; раньше эти поля не читались
    (§573).
  • Узел, который идёт через другой узел (цепочка или detour подписки), больше
    не несёт фрагментацию TLS
    (§574).
  • Уведомления узла с одним кодом собраны в одну запись; у узлов Xray меньше
    уведомлений «field not read»
    (§572).

v2.25.6

  • Узел WireGuard/AmneziaWG выключается и включается без перезапуска туннеля
    (§557).
  • Папку или подписку можно заменить группой: Manual, Auto или Both
    (§568).
  • Группа selector из подписки или бэкапа остаётся ручной и помнит выбранный
    сервер (§565).
  • Правила по Wi-Fi читают имя сети так, как ждёт Android 12+, и объясняют,
    почему имя не прочитать (приблизительная геолокация, выключенная Location)
    (§567,
    §569).
  • Импортированные узлы сохраняют то, что прислал провайдер: multiplex,
    udp_over_tcp, параметры подключения, workers WireGuard и другое
    (§560).
  • Правило пресета, оставшееся без условий, отбрасывается, а не ловит весь
    трафик (§571).
  • Отброшенные записи подписки видны в сводке подписки, а не на рабочем узле
    (§561).
  • Цепочка с REALITY-хопом сохраняется, когда uTLS снят; ссылка на цепочку
    открывает цепочку
    (§556,
    §558).
  • Строка vpn:// даёт все контейнеры WireGuard/AmneziaWG профиля; переменные
    шаблона со списком значений — чипы с возможностью своего значения
    (§570).

Полные списки: v2.25.6,
v2.25.7.


Install / Установка

adb install -r LxBox-v2.25.8-arm64-v8a.apk

Без uninstall! Поверх существующей установки. Настройки и подписки сохранятся.

No uninstall needed — install over the existing one. Settings and subscriptions
are preserved.


Previous release / Предыдущий релиз: v2.25.7.