github DanielLavrushin/b4 v1.85.0

3 hours ago

[1.85.0] - 2026-10-04

  • ADDED: Discovery takes a trusted DNS server, set under Settings, Discovery or for a single run, written as 9.9.9.9, 127.0.0.1:53053, tcp://, tcp+udp:// or an https:// DNS-over-HTTPS URL, and tests a site through pinned addresses, given for a run under Pinned addresses or taken from the set the run is for - the server's answers are the reference for the DNS check, a proposed set gets the server as its DNS when a set can use it and keeps the pins, and a site whose name exists but has no address in DNS is reported as such, with a pointer to pinning, rather than as misspelled. The Fallback UDP DNS servers list and the unused Reference domain setting are gone.
  • ADDED: Download Configuration under Settings, System, Backup saves the running configuration as is, or as a safe copy for sharing when asking for help - the safe copy replaces passwords, tokens, user names, the host names of the router and its relays and credentials inside URLs with [redacted], and b4 refuses to load or save a configuration that still holds these placeholders.
  • ADDED: System Info shows how many routing sets are installed and, while installing them fails, the error, when the failure began and when b4 tries again - the Routing Sets row is under Firewall, and the log warns when no firewall tool on the system can install routing at all.
  • CHANGED: The settings are regrouped: the Core tab has sub-tabs for Packet Engine, Devices, Firewall, DNS and SOCKS5, and a new System tab after it holds Service with logging, Web Server and Backup, which replaced the Backup tab - a sub-tab shows a dot while it has unsaved changes and an icon while a change waits for a restart.
  • CHANGED: The dashboard shows connections per minute in and outside sets, what each set matched in the last hour, and the problems that need attention - Device Activity and Domains Not In Any Set gave way to links into the Traffic page, the Runtime figures moved to System Info, and Reset Stats became Reset counters, with a Clear button of its own on Active Escalations.
  • CHANGED: MCP b4_status and b4_metrics and the metrics API count each connection once, so their fields changed - connections_seen, current_cps, current_pps and memory_percent gave way to per-minute connection counts, cpu_percent and rss_bytes, /api/metrics and /api/ws/metrics carry the new dashboard snapshot, and POST /api/escalations/clear clears escalations.
  • FIXED: Dashboard figures misled: Active flows only grew, Throughput counted only the first packets of each connection, Workers always read all active, Uptime started over at Reset Stats, and Domains Not In Any Set stopped taking new domains - b4 counted every inspected packet as a connection, never recorded a connection ending and evicted each new domain once the list was full.
  • FIXED: Reset Stats on the dashboard also sent every escalated site back to the set that had failed for it - the reset cleared b4's escalations along with the counters.
  • FIXED: Discovery for a domain that does not exist, such as a misspelled one, ran through every strategy for minutes, each test failing with DNS resolution failed (no such host) - the run did not tell a name without any address apart from a site that a strategy might still open.
  • FIXED: Discovery reported No bypass needed for a site whose resolver gave it a wrong address when no DNS server it tried answered honestly, could propose a DNS redirect that gave a wrong address too, and applying its result could switch off the set's Fail closed when the resolver is unreachable - the run reached the site through the address DNS over HTTPS gave without carrying that address into the set, took the first DNS-over-HTTPS server with any answer, on a router with a local resolver tested fragmented DNS against that resolver instead of the server, and wrote its own DNS settings, with that switch off, over the set's.
  • FIXED: After a Discovery run, DNS queries over TCP for sets with a DNS redirect went to the original resolver once b4 next rebuilt its firewall rules, until b4 restarted, and while a run was going the Active Escalations list on the dashboard kept emptying - Discovery's own packet queue published its state in place of b4's main queue: a DNS-over-TCP listener that was down and an empty escalation list.
  • FIXED: A set whose DNS redirect pointed at a resolver on another device in the local network made lookups of its names wait out the query timeout whenever that resolver asked its upstream over plain DNS, and with Fail closed when the resolver is unreachable on they ended in SERVFAIL - b4 sent that resolver's own upstream queries for those names back to it.
  • FIXED: Switching Time Zone back to Auto kept the previously selected zone in log timestamps until b4 restarted - b4 reloaded the zone it had set itself instead of the system's.
  • FIXED: A NAT Masquerade interface that was down or renamed disappeared from the card, which then looked as if masquerading covered every interface while it was limited to the missing one - the card listed only the interfaces present at the moment and left out saved ones that were not.
  • FIXED: Set cards gave target counts such as 1 domains and 1 IPs, and in Russian the longer labels in the panel a set card opens from its Target, Split, Fake, Route, DNS and Escalate tabs ran into their values or wrapped onto a second line - the number was always followed by the same word, and the label column had a fixed width that the longer Russian labels did not fit.
  • FIXED: An update from the web interface failed with Could not fetch the installer: mkdir /tmp/b4update-...: no such file or directory when nothing could be created in /tmp, as seen in a MikroTik container after a restart, and with /tmp mounted noexec the web interface reported the update as started while nothing happened - b4 staged the installer in /tmp and ran it from there, and the installer moved to another directory only when /tmp was short of space.
  • FIXED: A request to /api/system/update with a version such as --remove or --arch=mips removed b4 or installed a binary for another architecture instead of updating - b4 passed the requested version to the installer unchecked, and the installer read it as one of its own options.
  • FIXED: On a kernel that rejects b4's nftables routing table, such as Synology DSM with b4 in Docker, b4 logged a routing error at every start and save and retried it every 10 minutes even when no set used routing - b4 created the routing table before checking whether any set needed it.
  • FIXED: In the Docker image, routing sets failed on a host whose nftables does not work even where the kernel supports ipset, the NFQUEUE engine on such a host left out packet duplication and per-set MSS clamping by address, and the TUN engine gave every packet duplication address a capture rule of its own - the image did not include ipset.

What's Changed

New Contributors

Full Changelog: v1.84.0...v1.85.0

Don't miss a new b4 release

NewReleases is sending notifications on new releases.