xray-rust v0.4.1-rc.4
Pre-release
Pre-release
·
59 commits
to main
since this release
- Fixed an XHTTP/2
stream-updeadlock where a concurrent downlink poll could
cancel the uplink's pending flow-control reservation and strand a sustained
upload. Added deterministic split read/write coverage and an 8 MiB live
Xray-core interoperability regression. - Added safe pre-commit HTTP/2 GOAWAY retry handling plus regression coverage
for non-replay after commitment and request/buffer ownership across
cancellation. - Accepted an HTTP/3
H3_NO_ERRORrequest reset only after every declared
fixed-length request byte was delivered, while preserving failure for
unknown-length or premature resets; added transport and full-load interop
regressions. - Added weekly broad pinned Xray-core interoperability and resource gates plus
a warning-only upstream-main compatibility smoke check. - Scoped the RC4 REALITY/Vision comparator omission to the measured stable
sing-box v1.13.20 evidence: Xray-core v26.7.28's defaultminClientVer
26.3.27 rejects that build's REALITYClientVer1.8.1. RC4 records
--skip-sing-boxand publishes xray-rust/Xray-core results only for those
two workloads, while the generic harness retains sing-box REALITY support
for compatible or patched binaries. The fixture and timeout remain
unchanged. - Published fresh five-run RC4 evidence against exact Xray-core v26.7.28 and
stable sing-box v1.13.20: 139 validated series and 695 embedded results with
exact revisions, binary hashes, a deterministic raw-archive digest, and new
dated charts/tables. The publication records the reviewed sing-box
gRPC/full-duplex/32 nondeterministic timeout and Xray-core H3 pressure/32
reset/timeout boundaries without substituting isolated diagnostics. - Made the benchmark publication depth-limit policy test portable across
Python JSON decoders, and constrained JFrog-token secret-scan exemptions to
the two reviewed dated benchmark replay records containing binary SHA-256s. - Corrected roadmap, implementation-status, verification, configuration,
migration, benchmark, and release documentation for RC4. - Routing
ipmatchers are compiled once at load time into a shared sorted
range index (xray-routing::IpRangeSet/IpMatcherSet), also used by DNS
expectedIPs/unexpectedIPsfilters. Outbound selection cost no longer
grows with the size of ageoip:list (route-probe, 16 rules x 5000 CIDRs:
~152 us -> ~0.5 us per selection). - Routing IP matching now follows Xray-core
HeuristicIPMatcherexactly, as
the DNS filters already did: IPv4-mapped IPv6 targets (::ffff:a.b.c.d) are
matched as IPv4; an inverse matcher only applies to targets of an address
family it has networks for, so!10.0.0.0/8no longer matches an IPv6
target; a doubly negated matcher is treated as positive (not expressible in
configuration, so parsed configs are unaffected). - CIDR prefixes longer than the address family width are rejected with an
error at every construction site instead of being clamped. xray-bench route-probe --cidrs-per-rule Ngenerates N distinct
non-merging CIDRs per rule to expose per-matcher routing cost;0is
rejected.