Releases: yyy1mu/ustc-iwan
Releases · yyy1mu/ustc-iwan
Release list
v26.9.1
主要变更
- 新增
--bind <网卡|IP>:显式指定隧道 UDP 套接字的出口网卡或源地址;不指定时默认绑定当前活跃的物理网卡(有线优先于无线,自动排除 VPN/TUN、docker、veth 等虚拟网卡),连接时打印实际选择。两个客户端(含ping/auth/proxy/socks/http子命令)均支持。 - 平台出口锁定:Linux 按网卡名绑定时额外使用
SO_BINDTODEVICE(需要CAP_NET_ADMIN,失败时保留源地址绑定并告警),macOS 使用IP_BOUND_IF,Windows 使用源地址绑定。 - 修复 Windows 网卡检测:改用
Get-NetAdapter -Physical,在运行 Wintun/TAP/Hyper-V 等虚拟网卡时不会再被误选为出口。 - 稳定性:损坏或篡改的
servers.json现在返回清晰错误而不是 panic。 - 性能:DNS over TLS 的 TLS 配置改为复用,不再每次查询重建;UDP 套接字缓冲区的实际生效值可在
IWAN_DEBUG=1下查看(README 新增 sysctl 调优说明)。 - 文档:README 重新组织为「安装 / 连接方式 / 高级选项」并新增目录;补充贡献约定(先 issue 后 PR、不接受与官方客户端重复的功能)。
- 内部:对本地代理引擎、DNS 与 OIDC 客户端做了不改变行为的大规模重构(模块拆分、消除 panic 路径、纯解析器)。
网络接口绑定
# 默认:活跃物理网卡(有线优先)
./iwan-client-oidc --connect --socks
# bind en0 (192.168.1.5)
# 显式指定
./iwan-client-oidc --connect --bind eth0 # 按网卡名
./iwan-client-oidc --connect --bind 192.168.1.5 # 按本机 IP
./iwan-client-oidc --connect --bind 0.0.0.0 # 交还内核按路由选择Full Changelog: v26.9.0...v26.9.1
v26.9.0
主要变更
- 新增无 TUN 的 HTTP 代理模式:
iwan-client-oidc --connect --http与iwan-client http子命令,支持CONNECT隧道和明文 HTTP 转发,默认监听127.0.0.1:8080,与 SOCKS5 共用--dns与--proxy-mtu。 - 新增
--server非交互选择线路:接受线路序号(如2)或名称关键字(如电信),适合脚本和 systemd 无人值守启动。 - 新增
--dns自定义域名解析器:支持普通 UDP(ip[:port])、DNS over TLS(tls://host[:port])和 DNS over HTTPS(https://...),可在本地 DNS 被 fake-ip 类软件劫持时改用 DoT/DoH 规避。 - TUN 数据面性能优化:UDP 套接字缓冲区扩大至 16 MB,上行泵改用
poll()阻塞等待替代固定 sleep,并用sendmmsg批量发送;优化后 Linux TUN 隧道上下行吞吐显著提升(实测整形链路 750 Mbps + 15ms RTT:下行 126 → 631 Mbps,上行 84 → 653 Mbps)。 - MTU 选项完善:新增
--tun-mtu(TUN 模式,默认 1400,上限 2040 并在超限时明确报错)、--proxy-mtu(用户态模式,原--socks-mtu仍可用作别名),服务端新增--mtu用于设置 TUN 设备,避免下行超长包被丢弃。 - OIDC 授权链接参数现在按规范进行 percent-encode。
--version在所有平台可用(含iwan-server的非 Linux 提示路径),版本号输出26.9.0。- 发布产物统一命名格式
<程序>-<系统>-<架构>[-<libc>],例如iwan-client-oidc-linux-x86_64-musl、iwan-client-oidc-macos-aarch64。 - 修复:本地代理在客户端握手前断开时的连接残留泄漏;IPv6 字面量目标现在返回明确的错误响应(SOCKS5 reply 8 / HTTP 501)而不是发起无效解析;TUN 批量发送对
sendmmsg零进度返回增加防护。
HTTP 代理用法
./iwan-client-oidc --connect --http --http-listen 127.0.0.1:8080
curl -x http://127.0.0.1:8080 https://www.example.com/限制:仅支持 IPv4 目标,不支持代理认证;明文 HTTP 每个连接处理一个请求(转发时使用 Connection: close)。
致谢
感谢 @Davidasx 贡献的 --server 非交互线路选择与自定义 DNS 解析器(DoT/DoH),以及 @Jerrid-Huang 贡献的 TUN 时延与上行吞吐优化。 感谢 @Yu-Z-H-create 提出的 URL 编码问题 issue。
Full Changelog: v2.2.1...v26.9.0
v2.2.1
What's Changed
- Fixed SOCKS tunnel disconnections caused by using
PING_REQ/RSPfor session heartbeats. Heartbeats now use the correctECHO_REQ/RESpacket types. - Added periodic
ECHO_REQ/RESkeepalive support for TUN mode to prevent idle sessions from timing out. - Improved default log output to retain important connection status and errors while reducing packet-, flow-, and low-level diagnostic noise.
- Added optional detailed diagnostics through
IWAN_DEBUG=1. - Stopped printing OIDC access tokens.
- Silenced expected TUN cleanup errors such as
Cannot find device.
Debug Logging
Detailed diagnostic output can be enabled with:
IWAN_DEBUG=1 ./iwan-client-oidc --connect --socksAcknowledgements
Special thanks to @rrtt217 and @idwts for identifying and analyzing the incorrect heartbeat packet type, and to @rrtt217 and @TioeAre for identifying the missing keepalive support in TUN mode. Thanks to @rrtt217, @idwts, and @TioeAre for their contributions to this release.
Full Changelog: v2.2.0...v2.2.1
v2.2.0
v2.1.3
Full Changelog: https://github.com/yyy1mu/ustc-iwan/commits/v2.1.3
Full Changelog: https://github.com/yyy1mu/ustc-iwan/commits/v2.1.3