tun on-proxy-off cleared the system proxy block but left the shell restore flag enabled, so new login shells re-injected proxy variables. Disable both persistence layers and retain cleanup errors.\n\nFixes #308
Unify TUN status classification around policy-routing evidence and wait for the controller before post-restart verification. Add a regression check for Issue #303.
- Add kkgithub.com (hostpath) to the default mirror pool alongside the
existing gh-proxy.org / ghfast.top / ghproxy.net entries; all four
verified reachable and capable of proxying GitHub release downloads.
- Add doctor_download_mirrors() section to 'clashctl doctor': shows
whether a custom mirror (CLASH_GH_PROXY / CLASH_GH_PROXY_POOL) is
active or the built-in pool is in use, last successful/failed mirror
URL from the state file, and a one-liner hint for setting a custom
mirror prefix.
- README: add 'GitHub 下载加速' subsection under .env config to explain
that all GitHub assets (kernel, GEO data, yq, subconverter, dashboard)
automatically go through the mirror pool, document CLASH_GH_PROXY and
CLASH_GH_PROXY_POOL env vars with examples, and point users to
ghproxy.link for a live mirror list and 'clashctl doctor' for status.
Problem 1 - can_manage_tun_safely() missed setcap grants:
- Add kernel_binary_has_cap_net_admin(): use getcap to detect file
capability cap_net_admin on the kernel binary, so a user who ran
'setcap cap_net_admin,cap_net_raw+ep mihomo' is allowed through.
- Extend can_manage_tun_safely() to call this check after the existing
capsh (current-shell) check.
- In cmd_tun_on(), add a process-level fallback via the existing
tun_process_has_cap_net_admin() for cases where getcap is unavailable
but the running process already holds the capability.
Problem 2 - sudo clashctl corrupts runtime file ownership:
- Add guard_sudo_on_user_install(): detects root + SUDO_USER +
stored install scope == user, refuses with a clear message and
instructs the user to run as the install user directly.
- Call the guard at the entry of both cmd_tun_on() and cmd_tun_off()
so neither write path can corrupt runtime/ file ownership.
Generalize Tun source-IP detection in doctor log evidence: parse the
TUN adapter CIDR from logs and match traffic against it, while keeping
built-in default Tun ranges (28.x, 198.18.x, 198.19.x). Add offline
check script covering the new detection cases.