Skip to content

Releases: ike-sh/NoBrand-OneClick

NoBrand-OneClick v3.2.6

Choose a tag to compare

@ike-sh ike-sh released this 29 Sep 17:50

NoBrand-OneClick v3.2.6

v3.2.6 是基于 v3.2.4 的维护与可靠性版本,重点改进交互式管理器的生命周期锁范围、已有节点操作体验,以及客户端 Display Endpoint 的域名支持与回归覆盖。

修复

  • 缩小交互式管理菜单的 lifecycle lock 持有范围;停留在主菜单、协议子菜单、节点选择或等待回车时,不再长期阻塞其它 NoBrand 管理会话。
  • 实际安装、修改、修复、卸载等写操作仍使用 lifecycle lock 串行化,并保留 TOCTOU 状态复核、中断恢复与回滚保护。
  • 修复 SSH 会话异常断开后残留菜单进程可能继续阻塞其它 NoBrand 操作的问题。
  • 单实例 Snell、VLESS REALITY 和 TUIC 节点操作支持直接 Enter 使用唯一现有实例;存在多个实例时仍要求明确选择。
  • 加强并发菜单和过期实例选择的状态验证,避免旧菜单覆盖另一会话已完成的修改。

Display Endpoint

  • 在支持客户端 Display Endpoint 的协议中验证 IPv4、IPv6 和合法 DNS hostname。
  • 自定义 hostname 原样持久化并用于节点、URI 和客户端配置导出,不会在保存阶段解析并固化成 IP。
  • Mieru、Snell、Hysteria2、TUIC、VLESS、SSH Tunnel 及 Forward Display Endpoint 的相关持久化与导出路径已完成回归。
  • Display Endpoint 只表示客户端连接入口,不改变 Actual Listener、TLS/SNI、REALITY camouflage、Linux route、policy routing 或服务器实际 egress。

兼容性

  • 支持从 v3.2.4 直接升级到 v3.2.6,无需经过未发布的 v3.2.5,也无需新增 schema migration。
  • 已有节点、Display Endpoint、Ingress、服务配置和防火墙 ownership 保持兼容。
  • Realm Forward target 保持现有 IPv4、IPv6 和 domain 合同;nftables Forward backend target 仍仅支持 IPv4。后端目标与客户端 Display Endpoint 是不同字段。

验证

  • Linux 全量测试与真实 runtime 集成测试。
  • Docker smoke 与 Debian、Ubuntu、Rocky、Alpine 四平台回归。
  • 生命周期并发、中断恢复、Domain Display Endpoint 和 v3.2.4 直接升级测试。
  • 维护者提供的生产服务器 canary 验收结果:PASS。

NoBrand-OneClick v3.2.4

Choose a tag to compare

@ike-sh ike-sh released this 27 Sep 06:00

NoBrand-OneClick v3.2.4

v3.2.4 是基于 v3.2.2 的维护版本,完善 Mieru 新用户创建时的 Display Endpoint 配置,并加强相关校验、回滚与 CI 回归覆盖。

改进与修复

  • Mieru 添加新用户时支持直接选择自动探测或自定义客户端 Display Endpoint。
  • nobrand mieru user-add 支持 --advertise-host / --advertise-port;仅指定 Host 时自动继承该用户的有效展示端口。
  • 自定义 Display Endpoint 仅影响节点信息、分享链接和客户端配置导出,不修改 Mita 实际 listener、Linux route、policy routing 或服务器实际出站源地址。
  • 加强 Endpoint 输入校验,拒绝非法 IPv4 literal-like 地址。
  • 加强用户创建失败时的 firewall / endpoint ownership 回滚。
  • 修复 Alpine CI 缺少 openssh-keygen 导致 SSH 事务测试无法运行的问题,并使用平台实际的 nologin 路径验证策略。
  • 为真实 runtime 测试提供 mount/network namespace 所需权限及 OpenSSH、nftables 等依赖;修复 BusyBox 下卸载顺序测试的管道兼容性。
  • 完成 Linux、Alpine、Docker、跨平台及真实 runtime 回归。

Fixes #1

NoBrand-OneClick v3.2.2

Choose a tag to compare

@ike-sh ike-sh released this 05 Sep 03:01

NoBrand-OneClick v3.2.2

v3.2.2 是基于 v3.2.1 的维护版本,重点改进首次安装、Ingress 交互、生命周期恢复范围和完整卸载流程。

改进与修复

  • 调整首次安装流程,在显示完整管理菜单前先完成 nobrand / nb 管理命令的持久化安装。
  • 支持仅安装 NoBrand 管理器,并在尚未部署具体协议时使用 Ingress、Doctor 等公共管理功能。
  • 修复 Ingress 交互式新增流程在空值或无效输入时泄漏非交互 CLI 参数错误的问题,并改进 Interface / IPv4 默认选择与输入校验。
  • 增加生命周期恢复的组件级 scope,避免 Manager 或 Ingress 中断恢复错误进入 Mieru 或其他无关协议流程。
  • 修复完整卸载成功后仍返回已加载主菜单的问题;完整卸载完成后当前管理进程会直接退出。

兼容性

  • 保持 v3.2.1 的安装、修复和卸载中断恢复能力。
  • 协议行为、Multi-Ingress、Strict Ingress、Forward、REALITY 和 Mieru latest-stable 语义保持不变。

NoBrand-OneClick v3.2.1

Choose a tag to compare

@ike-sh ike-sh released this 03 Sep 02:33

NoBrand-OneClick v3.2.1

这是 v3.2.0 的维护版本,重点改善安装生命周期恢复能力和命令行界面一致性。

修复

  • 修复安装、修复或卸载意外中断后,当前版本残留状态可能被误判为旧版安装的问题。
  • 修复完整卸载过程中配置目录已经不存在时,后续扫描可能导致卸载失败的问题。
  • 改进安装、修复和卸载流程的幂等性,可根据实际剩余状态安全继续处理。
  • 改进部分卸载后的恢复逻辑,可继续卸载或重新修复当前安装。
  • 完成主要菜单、操作项、提示、状态和错误信息的中文化收口。

兼容性

  • 协议功能与 v3.2.0 保持兼容。
  • Multi-Ingress、Strict Ingress、Forward、REALITY 和 Mieru latest-stable 行为未改变。
  • v3.2.0 用户如果遇到安装或卸载中断,可直接使用 v3.2.1 安装器进行恢复。

NoBrand-OneClick v3.2.0

Choose a tag to compare

@ike-sh ike-sh released this 02 Sep 08:56

NoBrand-OneClick 3.2.0 adds Multi-Ingress Profiles and the final protocol feature for this release, VLESS TCP REALITY + Vision.

Highlights:

  • Dual / Multi-Ingress Profiles with Public and Mapped ingress, profile-aware Common Port allocation, derived-tail/custom-range/manual-only policies, permissive/strict enforcement, and cross-entry isolation.
  • VLESS TCP REALITY + xtls-rprx-vision on Xray 26.3.27, with a loopback dokodemo-door defender, exact-host anti-probe routing, server-only minClientVer=0.0.0, raw Xray/Mihomo/sing-box exporters, and no DIRECT client fallback.
  • REALITY camouflage hostname defaults to randomized automatic selection from a release-qualified candidate pool. The selected hostname is persisted per node; restart, read-only operations, export, backup, and restore do not rotate it.
  • Explicit camouflage host and camouflage target-port configuration remain supported independently. The default camouflage target port is 443 and is independent from both the public REALITY listener and internal defender ports.
  • Mieru resolves the official latest stable release from enfein/mieru; the qualified stable at publication time is 3.36.0. Strict-ingress owner cleanup is included.
  • TUIC v5 and SSH Tunnel support.
  • Profile-aware Forward using nftables or Realm, with transactional backend switching and rollback.
  • Backup, restore, uninstall, and v3.1 schema-v3 compatibility hardening.

Release qualification establishes that the embedded REALITY candidates were known-good with the exact publication stack at qualification time. External TLS sites can change, and NoBrand cannot guarantee that a third-party camouflage target will remain compatible forever. Inclusion in the technical candidate pool does not imply that a domain owner endorses, supports, operates, or participates in NoBrand or REALITY.

Known limitations:

  • HY2_LARGE_UDP_STATUS=KNOWN_DEFERRED: normal HTTPS/TCP passes, while some larger proxied SOCKS5 UDP datagrams may experience integrity or timeout issues.
  • FORWARD_EXTERNAL_LARGE_UDP=ENVIRONMENT_PATH_DEPENDENT: the controlled nftables/Realm 1400-byte backend path passes. NoBrand does not fragment or resize application UDP payloads.

NoBrand-OneClick v3.1.0

Choose a tag to compare

@ike-sh ike-sh released this 31 Aug 05:06

NoBrand-OneClick 3.1.0

Added

  • SSH Tunnel with strict host-key-aware client export.
  • TUIC v5 with Mihomo and sing-box client support.
  • Port Forward with nftables and private Realm backends.
  • Transactional backend switching with rollback protection.
  • Forward integration with Common Port, Display Endpoint, backup/restore, Doctor, and unified uninstall.

Protocols

  • Mieru
  • Snell v4
  • Snell v5
  • Hysteria2
  • TUIC v5
  • VLESS + FinalMask/Sudoku
  • SSH Tunnel

Network

  • nftables Forward
  • Realm Forward

Notes

  • Snell v5 remains the recommended/default Snell version.
  • Snell v5 QUIC Proxy Mode remains disabled and not fully verified.
  • VLESS + FinalMask/Sudoku is supported by the reference Xray client; the exact Mihomo and sing-box combination remains unsupported.
  • Protocol feature scope is frozen after 3.1.0.

Installer SHA-256: 9c320c931edbfa7ca2e3085630e31f63c94a83dfb173ca3152a47a1a09872d6d

NoBrand-OneClick 3.0.0

Choose a tag to compare

@ike-sh ike-sh released this 28 Aug 15:55

NoBrand-OneClick 3.0.0

NoBrand-OneClick 3.0.0 is a clean-break release built around one installer, one canonical manager, and one schema-v3 ownership model. It does not automatically migrate legacy users or state.

Highlights

  • One release installer: install-nobrand.sh
  • One canonical manager: nobrand, with nb as its short alias
  • Full Mieru feature and parameter parity, including Profiles, defaults, multi-user instances, quota, tc/rate limits, Display Endpoints, diagnostics, backup, and client exports
  • Snell v5 as the stable, recommended default, with optional official QUIC server exposure; Snell v4 remains available for compatibility
  • Hysteria2 over Xray-core
  • Plain VLESS with FinalMask/Sudoku over TCP and VLESS Encryption disabled
  • Unified nodes, Display Endpoint handling, backup/restore, ownership tracking, and project-wide uninstall
  • Clean schema-v3 state with no automatic legacy-user or legacy-state migration

Snell v1, v2, v3, and v6 are unsupported and have no hidden installation path. The former install-mita.sh and NoBrand management wrappers named mita have been removed; the genuine upstream Mieru runtime continues to use its official mita binary name internally.

Client compatibility

Protocol Verified clients Unsupported or unverified combinations
Mieru Mihomo; official Mieru reference client sing-box unsupported
Snell v4 Mihomo; sing-box —
Snell v5 with public QUIC exposure OFF Mihomo; sing-box Official QUIC-wire Linux E2E not verified
Hysteria2 Mihomo; sing-box —
VLESS FinalMask/Sudoku Xray-core reference client Mihomo and sing-box unsupported

Official Snell v5 QUIC server exposure is supported. This release does not claim verified Mihomo official QUIC-wire interoperability, and sing-box does not support official Snell v5 QUIC Proxy Mode.

Breaking changes

  • State and ownership now require the clean schema-v3 model.
  • Legacy Mieru/NoBrand state is detected and rejected without being imported, converted, modified, or deleted.
  • install-mita.sh and NoBrand mita management compatibility have been removed.
  • nobrand uninstall now removes all resources explicitly owned by NoBrand 3.0 across Mieru, Snell, Hysteria2, VLESS/Sudoku, and common state, while preserving external resources.

Validation

The release passed deterministic builds, syntax and ShellCheck gates, unit and runtime suites, complete Mieru parity gates, four-platform container coverage, ownership and uninstall boundaries, protocol regressions, and non-destructive real-machine health validation.

Known limitations

  1. The Linux client matrix does not provide a verified official Snell v5 QUIC-wire end-to-end implementation.
  2. Mihomo and sing-box do not support VLESS FinalMask/Sudoku; Xray-core is the reference client.
  3. VLESS/Sudoku showed lower upload throughput in the tested lab despite correct connectivity and data integrity.
  4. Snell v5 may require a reasonable connection cadence immediately after a fresh client process starts.

NoBrand-OneClick 1.3.0

Choose a tag to compare

@ike-sh ike-sh released this 28 Aug 02:21

NoBrand-OneClick 1.3.0

NoBrand-OneClick 1.3.0 brings Mieru, Snell, Hysteria2 and VLESS/Sudoku under one management surface while preserving each protocol's established runtime behavior.

Highlights

  • Removed Snell v6 after failed public-path qualification.
  • Added optional Snell v5 same-port QUIC exposure.
  • Added real Mihomo and sing-box client validation.
  • Added real upload/download benchmark evidence.
  • Preserved Mieru, Hysteria2 and VLESS/Sudoku behavior.
  • Unified protocol nodes, status, Doctor, endpoint, port ownership, backup and rollback handling.

Supported protocols

  • Mieru
  • Snell v5 — Stable, Recommended and Default
  • Snell v4 — Compatibility
  • Hysteria2
  • Plain VLESS + FinalMask + Sudoku over TCP

Snell v6 is removed. It is not available from the installer, menu, CLI, runtime resolver, exporter, nodes, status, Doctor or upgrade paths.

Snell v5 and QUIC exposure

Snell v5 can optionally expose same-port UDP for the official QUIC Proxy Mode. The default is OFF.

  • OFF: NoBrand owns TCP only; quic_proxy_enabled=false and managed_udp=false.
  • ON: NoBrand owns TCP and same-number UDP; quic_proxy_enabled=true and managed_udp=true.

Some official Snell v5 runtimes may bind an auxiliary same-port UDP socket even when NoBrand public QUIC ownership is OFF. That socket is upstream runtime behavior and is not reported as QUIC Proxy Mode enabled.

Server exposure is not the same as client QUIC wire verification. Mihomo's official QUIC wire remains NOT VERIFIED. sing-box's official Snell v5 QUIC Proxy Mode remains CLIENT_UNSUPPORTED. Ordinary Snell traffic passing while exposure is ON is not described as QUIC E2E verification.

Client compatibility

Protocol Mihomo sing-box
Mieru Tested Unsupported
Snell v4 Tested Tested
Snell v5, QUIC OFF Tested Tested
Hysteria2 Tested Tested
VLESS/Sudoku Unsupported Unsupported

The reference clients are official Mieru for Mieru and Xray-core for VLESS/Sudoku.

Upgrade notes

The 1.3.0 upgrade path recognizes historical Snell v6 state only for strict, identity-matched cleanup. It removes only matching historical service, state, config, TCP ownership and independent runtime data. Identity mismatches fail closed. Migration does not infer or remove same-number UDP ownership and cannot delete an unrelated UDP rule.

Legacy Snell v4/v5 state without QUIC fields is normalized to explicit false values without inferring user intent from an upstream runtime socket.

The historical annotated v1.2.0 tag remains unchanged; 1.3.0 is published under a new v1.3.0 tag.

Port and endpoint contracts

  • The default-route IPv4 tail-base port xx00 is reserved for outer SSH or management mapping.
  • Automatic proxy allocations use xx01 through xx99.
  • Real Endpoint and Display Endpoint are separate. Changing the client-facing display IP or port does not change the real server listener, service, configuration or firewall ownership.

Validation and benchmark scope

The release includes real IPLC and independent Debian-client evidence using Mihomo, sing-box, official Mieru, Xray-core and official Surge Snell runtimes. Product defaults remain Snell v5 with QUIC exposure OFF and Mihomo as the recommended default client. The most complete conservative lab pairing was Snell v4 with sing-box, including a 137.866 Mbps download median and 53.547 Mbps upload median in that specific lab.

These figures are lab results, not guaranteed speeds or an all-protocol ranking. Some later download runs were blocked by Cloudflare HTTP 429, Mieru encountered a TLS EOF condition, and certain Snell/client combinations showed cold-start sensitivity. The reports preserve FAIL, NOT VERIFIED, CLIENT_UNSUPPORTED and ENVIRONMENT BLOCKED outcomes without promoting them to PASS.

Compatibility and licensing

The Mieru compatibility entry points install-mita and mita remain available. No third-party runtime binary, client bundle, packet capture or credential is included in the repository or release assets.

NoBrand-OneClick is distributed under GPL-3.0. Upstream attribution and component notices are recorded in THIRD_PARTY_NOTICES.md.