Skip to content

Releases: zerolabnet/SSClash-Go

v6.5.5

Choose a tag to compare

@zerolabnet zerolabnet released this 29 Sep 11:35

SSClash v6.5.5

Log platform-specific install commands when conntrack or ipset is missing.

  • DoH blocking is reported only when the drop rule is actually installed.

Install conntrack and ipset from the platform package manager.

  • Keenetic and OpenWrt use opkg or apk; Linux gateway installs use apt-get. A missing package warns instead of aborting the installer.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.5.4

Choose a tag to compare

@zerolabnet zerolabnet released this 29 Sep 10:51

SSClash v6.5.4

Harden Keenetic NDMS hook after netfilter rebuilds.

  • Drop fractional sleep that broke BusyBox, restore mangle with ndm-reload when CLASH is gone, and reload when HYBRID/MIXED2 nat redirect chains were removed.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.5.3

Choose a tag to compare

@zerolabnet zerolabnet released this 29 Sep 09:24

SSClash v6.5.3

Pin nat POSTROUTING RETURN before clash-tun on Keenetic TUN modes.

  • NDMS MASQUERADE was rewriting forwarded LAN UDP sources to the tun address; skip masquerade at rule 1 and re-pin on Apply, repair, and NDMS hook.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.5.2

Choose a tag to compare

@zerolabnet zerolabnet released this 29 Sep 06:22

SSClash v6.5.2

Build: Bump CI/release to Go 1.27.x (from Go 1.24.x).

UI: Fix extra spacing in DNS interception after Firewall redirect and dibdot separators.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.5.1

Choose a tag to compare

@zerolabnet zerolabnet released this 29 Sep 05:23

SSClash v6.5.1

Fix UDP loop when replies leave clash-tun (issue #38).

  • Skip re-marking tun ingress in firewall and route iif clash-tun via main at pref 999 so fake-ip replies are not steered back into the tun.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.5.0

Choose a tag to compare

@zerolabnet zerolabnet released this 28 Sep 22:01

SSClash v6.5.0

DNS interception — Block DoT / DoH

  • Added optional Block DoT (port 853) and Block known DoH (dibdot) when Mihomo DNS interception (upstream or firewall redirect) is enabled.
  • Added Block DoH (custom list): user https://host/path lines, resolved to IPv4 on save, merged into the same firewall drop set as dibdot.
  • dibdot list is downloaded at runtime (daily refresh).
  • Custom DoH URLs in a collapsible “Custom DoH list” section with URL count badge and resolved-IPv4 status panel.
  • Hot-update of the DoH ipset/nft set when lists change without a full firewall re-apply where possible.
  • Conntrack flush after DNS intercept repair is more reliable; optional warning if conntrack-tools is missing.

Keenetic — NDMS firewall

  • SSCLASH_LATE chain at the end of mangle PREROUTING re-enters CLASH after Keenetic NDMS overwrites packet marks.
  • Validate/repair ensures the late jump exists and stays last; tests extended.
  • Transparent-proxy loop bypass treats both TPROXY and TunUDP marks consistently.

Web UI — proxy country flags

  • Embedded Twemoji Mozilla flags-only font (~78 KB).
  • Shared typography via --font-ui and --font-mono; mono styling for technical Settings fields.
  • Custom hover tooltip for truncated proxy names and preview dots (native title still shows letter fallbacks like DE on some OSes).

Web UI — Settings

  • dibdot/custom status shown in kv-style panels (pending / ready / warn).

Mihomo kernel — low disk space

  • Web UI download: chooses stage + rename vs in-place replace from free space; stops Mihomo only when the on-disk binary must be replaced; verifies before swap; cleans stale .mihomo-new.* only (does not remove the live binary).
  • Install scripts (Keenetic / OpenWrt / Linux): shared install_checked_bin — same staging/replace logic for Mihomo and SSClash; cleans partial .mihomo-new.* / .ssclash-install.*; Mihomo -v check when the source path is executable.

Config / TUN

  • tun.stack: mips supported in profile transform (pure-Go mipstack) alongside system, gvisor, and mixed.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.4.1

Choose a tag to compare

@zerolabnet zerolabnet released this 11 Sep 13:13

SSClash v6.4.1

Fix Connections virtual scroll and show filtered count chip.

  • Use tbody spacer rows so the full active list scrolls with border-collapse
    tables, and surface a compact "N of M" badge only when filters narrow results.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.4.0

Choose a tag to compare

@zerolabnet zerolabnet released this 11 Sep 11:23

SSClash v6.4.0

Add config editor outline nav and harden Keenetic NDMS firewall repair.

  • Configuration page gets YAML section chips, item jump select, scroll sync,
    and Ctrl/Cmd+Shift+O search palette. Keenetic ndm-hook now logs only
    failures, retries CLASH chain detection, and NdmReload repairs missing
    iptables jumps before falling back to full re-apply.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.3.1

Choose a tag to compare

@zerolabnet zerolabnet released this 10 Sep 17:33

SSClash v6.3.1

Write NDMS hook log to tmpfs and align Connections column labels.

  • Move ndm-hook.log under /tmp/ssclash, cap the hook log at 64 KiB, and rename Source/Destination column headers to match the picker and detail view.

Fix Keenetic NDMS QUIC restore without triggering full firewall re-apply.

  • Match Apply ordering (bypass -I, REJECT -A) in the netfilter hook, repair QUIC inline when intercept is intact, and gate concurrent ndm-reload spawns.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums

v6.3.0

Choose a tag to compare

@zerolabnet zerolabnet released this 02 Sep 19:46

SSClash v6.3.0

Connections: show LAN source as hostname (IP).

  • Resolve names from DHCP leases, dnsmasq/odhcpd hosts, /etc/hosts, and Keenetic hotspot.
  • For IPs still missing, look up PTR via WAN DNS (resolv.conf.auto), skipping loopback/Mihomo so RFC1918 reverse works on OpenWrt that is not the LAN DHCP server. Keep the full PTR FQDN.

Binaries

  • ssclash-linux-<arch> — static SSClash daemon (16 Linux targets)
  • ssclash-openwrt-service.tar.gz — OpenWrt init.d service files
  • ssclash-keenetic-service.tar.gz — Keenetic Entware S99ssclash init script
  • sha256sums.txt — checksums