Highlights
- Added an opt-in per-inbound H2MUX
h2muxMaxReadFrameSizesetting. It controls the HTTP/2SETTINGS_MAX_FRAME_SIZEadvertised to H2MUX clients, allowing memory-constrained clients to reduce per-stream upload buffers without changing existing deployments by default. - Hardened VLESS Vision carrier resolution so inbound and outbound direct-copy decisions share one fail-closed classification of recognized TLS, uTLS, REALITY, and VLESS-encryption carriers.
Fork fixes
- Kept the H2MUX frame-size setting isolated per inbound and restricted its consumer to the H2MUX server path. Ordinary SMUX framing and behavior remain unchanged. Invalid nonzero values outside
16384..16777215are rejected; omission or0keeps the Go HTTP/2 default of 1 MiB. - Refactored TLS session resumption into a dedicated module while preserving fingerprint fidelity. Session caches remain isolated by configured TLS context and impersonated fingerprint, with bounded cache ownership and regression coverage.
Upstream changes
- Merged upstream through
cd4ce973(WebSocket client: Avoid panic before real dialing in delayDialConn (#6544)). - Closed Shadowsocks 2022 server connections on outbound early-return paths.
- Fixed a potential HTTP inbound panic while handling
100 Continue. - Included the Linux custom-sockopt formatting correction.
Compatibility notes
smux.h2muxMaxReadFrameSizeaffects only H2MUX carriers accepted by that inbound. Ordinary SMUX continues to use its in-tree SMUX v1 framing with a 32 KiB emitted data-frame size.- Existing configurations are unchanged when the new H2MUX setting is omitted or set to
0. - REALITY client-version bounds remain operator-configurable with no implicit minimum.
- Official release artifacts are limited to Linux amd64 and Linux arm64.
Validation
- GitHub
Tests and Checkingspassed on the stamped release commit, including formatting, protobuf-header, asset, and full Go test jobs. - Targeted unit, race, strict checkptr, and
go vetgates passed for TLS, REALITY, VLESS, SMUX/H2MUX, mux, proxyman, HTTP, Shadowsocks 2022, and WebSocket paths. - The VLESS TLS/REALITY no-flow/Vision process matrix passed 36/36 executions across Xray, sing-box, and Mihomo.
- The SMUX and H2MUX interoperability matrices each passed 40/40 scenarios. The peak reconnect profile passed 24/24 cycles, and the bounded hardening profile passed 400/400 cycles with zero loopback health-counter deltas.
- Clean release-style Linux/amd64 and Linux/arm64 builds succeeded with Go 1.27.0. Performance comparisons ran as harness diagnostics only; native-host release budgets were not asserted.