Skip to content

Releases: yyy1mu/ustc-iwan

v26.9.1

Choose a tag to compare

@github-actions github-actions released this 11 Sep 09:14

主要变更

  • 新增 --bind <网卡|IP>:显式指定隧道 UDP 套接字的出口网卡或源地址;不指定时默认绑定当前活跃的物理网卡(有线优先于无线,自动排除 VPN/TUN、docker、veth 等虚拟网卡),连接时打印实际选择。两个客户端(含 ping/auth/proxy/socks/http 子命令)均支持。
  • 平台出口锁定:Linux 按网卡名绑定时额外使用 SO_BINDTODEVICE(需要 CAP_NET_ADMIN,失败时保留源地址绑定并告警),macOS 使用 IP_BOUND_IF,Windows 使用源地址绑定。
  • 修复 Windows 网卡检测:改用 Get-NetAdapter -Physical,在运行 Wintun/TAP/Hyper-V 等虚拟网卡时不会再被误选为出口。
  • 稳定性:损坏或篡改的 servers.json 现在返回清晰错误而不是 panic。
  • 性能:DNS over TLS 的 TLS 配置改为复用,不再每次查询重建;UDP 套接字缓冲区的实际生效值可在 IWAN_DEBUG=1 下查看(README 新增 sysctl 调优说明)。
  • 文档:README 重新组织为「安装 / 连接方式 / 高级选项」并新增目录;补充贡献约定(先 issue 后 PR、不接受与官方客户端重复的功能)。
  • 内部:对本地代理引擎、DNS 与 OIDC 客户端做了不改变行为的大规模重构(模块拆分、消除 panic 路径、纯解析器)。

网络接口绑定

# 默认:活跃物理网卡(有线优先)
./iwan-client-oidc --connect --socks
#   bind en0 (192.168.1.5)

# 显式指定
./iwan-client-oidc --connect --bind eth0          # 按网卡名
./iwan-client-oidc --connect --bind 192.168.1.5   # 按本机 IP
./iwan-client-oidc --connect --bind 0.0.0.0       # 交还内核按路由选择

Full Changelog: v26.9.0...v26.9.1

v26.9.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 11:18

主要变更

  • 新增无 TUN 的 HTTP 代理模式:iwan-client-oidc --connect --http 与 iwan-client http 子命令,支持 CONNECT 隧道和明文 HTTP 转发,默认监听 127.0.0.1:8080,与 SOCKS5 共用 --dns 与 --proxy-mtu。
  • 新增 --server 非交互选择线路:接受线路序号(如 2)或名称关键字(如 电信),适合脚本和 systemd 无人值守启动。
  • 新增 --dns 自定义域名解析器:支持普通 UDP(ip[:port])、DNS over TLS(tls://host[:port])和 DNS over HTTPS(https://...),可在本地 DNS 被 fake-ip 类软件劫持时改用 DoT/DoH 规避。
  • TUN 数据面性能优化:UDP 套接字缓冲区扩大至 16 MB,上行泵改用 poll() 阻塞等待替代固定 sleep,并用 sendmmsg 批量发送;优化后 Linux TUN 隧道上下行吞吐显著提升(实测整形链路 750 Mbps + 15ms RTT:下行 126 → 631 Mbps,上行 84 → 653 Mbps)。
  • MTU 选项完善:新增 --tun-mtu(TUN 模式,默认 1400,上限 2040 并在超限时明确报错)、--proxy-mtu(用户态模式,原 --socks-mtu 仍可用作别名),服务端新增 --mtu 用于设置 TUN 设备,避免下行超长包被丢弃。
  • OIDC 授权链接参数现在按规范进行 percent-encode。
  • --version 在所有平台可用(含 iwan-server 的非 Linux 提示路径),版本号输出 26.9.0。
  • 发布产物统一命名格式 <程序>-<系统>-<架构>[-<libc>],例如 iwan-client-oidc-linux-x86_64-musl、iwan-client-oidc-macos-aarch64。
  • 修复:本地代理在客户端握手前断开时的连接残留泄漏;IPv6 字面量目标现在返回明确的错误响应(SOCKS5 reply 8 / HTTP 501)而不是发起无效解析;TUN 批量发送对 sendmmsg 零进度返回增加防护。

HTTP 代理用法

./iwan-client-oidc --connect --http --http-listen 127.0.0.1:8080
curl -x http://127.0.0.1:8080 https://www.example.com/

限制:仅支持 IPv4 目标,不支持代理认证;明文 HTTP 每个连接处理一个请求(转发时使用 Connection: close)。

致谢

感谢 @Davidasx 贡献的 --server 非交互线路选择与自定义 DNS 解析器(DoT/DoH),以及 @Jerrid-Huang 贡献的 TUN 时延与上行吞吐优化。 感谢 @Yu-Z-H-create 提出的 URL 编码问题 issue。

Full Changelog: v2.2.1...v26.9.0

v2.2.1

Choose a tag to compare

@github-actions github-actions released this 30 Jul 11:41

What's Changed

  • Fixed SOCKS tunnel disconnections caused by using PING_REQ/RSP for session heartbeats. Heartbeats now use the correct ECHO_REQ/RES packet types.
  • Added periodic ECHO_REQ/RES keepalive support for TUN mode to prevent idle sessions from timing out.
  • Improved default log output to retain important connection status and errors while reducing packet-, flow-, and low-level diagnostic noise.
  • Added optional detailed diagnostics through IWAN_DEBUG=1.
  • Stopped printing OIDC access tokens.
  • Silenced expected TUN cleanup errors such as Cannot find device.

Debug Logging

Detailed diagnostic output can be enabled with:

IWAN_DEBUG=1 ./iwan-client-oidc --connect --socks

Acknowledgements

Special thanks to @rrtt217 and @idwts for identifying and analyzing the incorrect heartbeat packet type, and to @rrtt217 and @TioeAre for identifying the missing keepalive support in TUN mode. Thanks to @rrtt217, @idwts, and @TioeAre for their contributions to this release.

Full Changelog: v2.2.0...v2.2.1

v2.2.0

Choose a tag to compare

@github-actions github-actions released this 23 Jul 15:00

Full Changelog: v2.1.3...v2.2.0

Full Changelog: v2.1.3...v2.2.0

Full Changelog: v2.1.3...v2.2.0

v2.1.3

Choose a tag to compare

@github-actions github-actions released this 06 Jul 05:09