SB Gateway 1.6.48
Changes
-
Both executable roles use Go 1.27.2 and updated HTTP/2 dependencies. The shared-core build pins compress 1.18.7 rather than the upstream core's older dependency.
-
Apply restores the saved eligible node when it has only an unconfirmed probe failure. Confirmed outages, removed nodes and deliberate priority-order changes retain their normal selection rules.
-
URLTest rejects evidence from a replaced core, health pool or DNS generation. A planned runtime restart pauses probes only while its live, bounded Apply guard is valid. Pending failures before and after the restart are not combined; no post-Apply cooldown is added.
-
Gateway and the pinned patched Xray CLI share one executable, with independent processes, heaps and restart supervision. Health workers reuse immutable catalogs and reverse status uses the existing local API connection.
-
Native encrypted DNS uses bounded deadlines, validates DoH responses, reconnects after failed keep-alive sessions and cancels in-flight work before restart. Unchanged RouterOS DNS settings preserve their cache and transport.
-
Managed IPv4 client queries to RouterOS-local TCP/UDP DNS retain client identity and follow the same policy DNS as their routed traffic, including internal zones and WAN exceptions. The router's own resolver and unmanaged clients remain independent.
-
DNS interception follows the readiness gate. Recovery admits new DNS marking before expiring affected unmanaged router-local DNS flows, so concurrent requests cannot recreate the outage path. Separate conntrack port fields and legacy endpoints are supported without resetting unrelated connections.
-
Separate service cards are available for eWeLink/Sonoff, Xiaomi Home, Tuya/Smart Life, Aqara and Shelly.
-
Routing drafts persist across navigation and global Apply. Failed persistence prevents applying an incomplete draft.
Upgrade
Install the ARM64 image through the normal image-update workflow. If the panel offers Apply Update, run it once to reconcile the new runtime and managed RouterOS scripts; no configuration edit is necessary.
An earlier watchdog that clears DNS flows before admitting the gate also triggers this runtime-update prompt.
Existing memory limits, connection buffers, route-list modes and atomic GeoIP publication are retained. Structural Xray restarts still close established connections; preserving the selected node does not preserve those sockets.
Limits
Router-local DNS interception is IPv4-only. Routing cannot guarantee compatibility or reachability of every external IoT cloud. TLS certificate verification remains enabled, and no automatic plaintext external DNS fallback or additional memory cap is introduced. See Security for dependency and local-control API limitations.