github yandexru45/netshift 0.9.10

2 hours ago

0.9.10 (Per-device routing, DNS sections and IPv6)

• New "Devices" tab: route a device, not a list.
Every device seen on the LAN can be sent fully through one section (all its
traffic) or directly, ignoring the lists. Stored with Save & Apply, like the
other settings.

• Bypass sing-box: excluded addresses and devices no longer enter the core.
An exclusion section with the new flag, and the devices you mark as direct,
are returned before any mark - the router sends them out itself. Saves CPU,
especially with Global Proxy.

• DNS sections: a section can serve its own DNS server for the domains of the
lists it selects. Any scheme the core knows (doh, doh3, doq, dot, tcp, udp).

• Multiple DNS servers with priority or parallel mode (issue #74).
The main server plus a list of extras, used either as a priority chain (the
next one is tried when the previous fails) or in parallel (the first usable
answer wins). Needs sing-box 1.14 or newer.

• Cascade: connect a section through the outbound of another one (double hop).
If the chain cannot be built, the section's traffic is rejected instead of
silently going out directly.

• IPv6 (issue #38): the v6 TProxy inbound is matched by the same route rules,
DNS gets its own strategy per address family, and the FakeIP v6 range is a
routable global prefix instead of a ULA one.

• Subscription filters by country, plus GeoIP flags for servers whose name has
no flag. For such a server the country is looked up once by its address and
the flag is added, so grouping and the country filters work for it too. The
addresses are sent to api.country.is over HTTPS; results are cached on the
router.

• Priority mode: pick the first working server in list order instead of the
fastest one.

• Dashboard: a plain server list instead of tiles, with sort by ping - switch
between tiles and list per section.

• Latency test URL and the daily update time are configurable now. Point the
test at a URL that is fast in your region, and set the HH:MM of the
subscription refresh instead of the fixed one.

• reality_mlkem: post-quantum key share (X25519MLKEM768) for Reality clients.
Required by servers on Xray-core 26.9.8 or newer, which reject clients
without it. Needs sing-box-extended 2.7.2+ and the chrome fingerprint.

• Xray JSON subscriptions: node names now come from remarks (with the
profile/balancer number), so a node is recognisable instead of a random tag.

• Sections can be turned off: a new "disabled" option removes a section
completely - no outbound, routing, lists, cron or dashboard entry - while
keeping its settings.

• Components can be downloaded through the proxy, for networks where GitHub
is blocked.

• Fixed: after an update the browser no longer sticks to the old interface
(the view directory is versioned now).

• Fixed: "Don't touch DHCP" no longer wipes the DNS redirect after a reboot -
dnsmasq is restored by config ownership instead of that flag.

• Fixed: the httpupgrade transport was lost for nodes that use it (they stayed
in their group, valid, but could never connect).

• Fixed: a section saved with an empty link field no longer aborts the whole
build and leaves the router without a tunnel - such a section is rejected,
and the rest of the config still generates.

• Fixed: "Excluded IPs" (Devices -> Direct) did nothing when the option was
written as a plain value instead of a UCI list.

• Fixed: GeoIP flags on subscriptions that use a shared entry point (one
"mirror" host serving nodes of many countries) - the country stated by the
node name now wins over the address.

• Fixed: .i2p and other numeric TLDs were rejected by the domain validator.

• Faster link parsing and normalization; the diagnostics "Sections" block no
longer hangs on a large subscription.

• Russian translation completed - everything added in this release is
translated.

Restart NetShift after updating (/etc/init.d/netshift restart).
If you use IPv6, enable it in Settings - the new v6 routing works together
with the v4 one.


Telegram Channel Telegram Chat

Don't miss a new netshift release

NewReleases is sending notifications on new releases.