Skip to content

NoBrand-OneClick v3.2.0

Choose a tag to compare

@ike-sh ike-sh released this 02 Sep 08:56
· 6 commits to main since this release

NoBrand-OneClick 3.2.0 adds Multi-Ingress Profiles and the final protocol feature for this release, VLESS TCP REALITY + Vision.

Highlights:

  • Dual / Multi-Ingress Profiles with Public and Mapped ingress, profile-aware Common Port allocation, derived-tail/custom-range/manual-only policies, permissive/strict enforcement, and cross-entry isolation.
  • VLESS TCP REALITY + xtls-rprx-vision on Xray 26.3.27, with a loopback dokodemo-door defender, exact-host anti-probe routing, server-only minClientVer=0.0.0, raw Xray/Mihomo/sing-box exporters, and no DIRECT client fallback.
  • REALITY camouflage hostname defaults to randomized automatic selection from a release-qualified candidate pool. The selected hostname is persisted per node; restart, read-only operations, export, backup, and restore do not rotate it.
  • Explicit camouflage host and camouflage target-port configuration remain supported independently. The default camouflage target port is 443 and is independent from both the public REALITY listener and internal defender ports.
  • Mieru resolves the official latest stable release from enfein/mieru; the qualified stable at publication time is 3.36.0. Strict-ingress owner cleanup is included.
  • TUIC v5 and SSH Tunnel support.
  • Profile-aware Forward using nftables or Realm, with transactional backend switching and rollback.
  • Backup, restore, uninstall, and v3.1 schema-v3 compatibility hardening.

Release qualification establishes that the embedded REALITY candidates were known-good with the exact publication stack at qualification time. External TLS sites can change, and NoBrand cannot guarantee that a third-party camouflage target will remain compatible forever. Inclusion in the technical candidate pool does not imply that a domain owner endorses, supports, operates, or participates in NoBrand or REALITY.

Known limitations:

  • HY2_LARGE_UDP_STATUS=KNOWN_DEFERRED: normal HTTPS/TCP passes, while some larger proxied SOCKS5 UDP datagrams may experience integrity or timeout issues.
  • FORWARD_EXTERNAL_LARGE_UDP=ENVIRONMENT_PATH_DEPENDENT: the controlled nftables/Realm 1400-byte backend path passes. NoBrand does not fragment or resize application UDP payloads.