1
0
mirror of https://github.com/MetaCubeX/mihomo.git synced 2026-10-10 04:03:11 +08:00

chore: change default IP stack mode to mips and support congestion-controller option for tun

This commit is contained in:
wwqgtxx
2026-09-27 09:10:08 +08:00
parent f103639c80
commit 63bd52ec79
9 changed files with 30 additions and 19 deletions
+1 -5
View File
@@ -193,11 +193,7 @@ type ipStack interface {
func newIPStack(option IPStackOption, localAddresses []netip.Prefix, mtu uint32) (ipStack, error) {
mode := option.Mode
if mode == ipStackAuto {
if features.WithGVisor {
mode = ipStackGVisor
} else {
mode = ipStackMips
}
mode = ipStackMips
}
switch mode {
case ipStackGVisor:
+3 -1
View File
@@ -314,6 +314,7 @@ type RawTun struct {
UDPTimeout int64 `yaml:"udp-timeout" json:"udp-timeout,omitempty"`
ICMPTimeout int64 `yaml:"icmp-timeout" json:"icmp-timeout,omitempty"`
DisableICMPForwarding bool `yaml:"disable-icmp-forwarding" json:"disable-icmp-forwarding,omitempty"`
CongestionController string `yaml:"congestion-controller" json:"congestion-controller,omitempty"`
FileDescriptor int `yaml:"file-descriptor" json:"file-descriptor"`
Inet4RouteAddress []netip.Prefix `yaml:"inet4-route-address" json:"inet4-route-address,omitempty"`
@@ -543,7 +544,7 @@ func DefaultRawConfig() *RawConfig {
Tun: RawTun{
Enable: false,
Device: "",
Stack: C.TunGvisor,
Stack: C.TunMips,
DNSHijack: []string{"0.0.0.0:53"}, // default hijack all dns query
AutoRoute: true,
AutoDetectInterface: true,
@@ -1733,6 +1734,7 @@ func parseTun(rawTun RawTun, dns *DNS, general *General) error {
UDPTimeout: rawTun.UDPTimeout,
ICMPTimeout: rawTun.ICMPTimeout,
DisableICMPForwarding: rawTun.DisableICMPForwarding,
CongestionController: rawTun.CongestionController,
FileDescriptor: rawTun.FileDescriptor,
Inet4RouteAddress: rawTun.Inet4RouteAddress,
+9 -7
View File
@@ -133,7 +133,7 @@ profile: # 存储 select 选择记录
# Tun 配置
tun:
enable: false
stack: system # gvisor/mixed/mips
stack: mips # gvisor/mixed/system
dns-hijack:
- 0.0.0.0:53 # 需要劫持的 DNS
# auto-detect-interface: true # 自动识别出口网卡
@@ -144,6 +144,7 @@ tun:
auto-redirect: false # 自动配置 iptables 以重定向 TCP 连接。仅支持 Linux。带有 auto-redirect 的 auto-route 现在可以在路由器上按预期工作,无需干预。
# strict-route: true # 将所有连接路由到 tun 来防止泄漏,但你的设备将无法其他设备被访问
# disable-icmp-forwarding: true # 禁用 ICMP 转发,防止某些情况下的 ICMP 环回问题,ping 将不会显示真实的延迟
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; only effective on mips
route-address-set: # 将指定规则集中的目标 IP CIDR 规则添加到防火墙, 不匹配的流量将绕过路由, 仅支持 Linux,且需要 nftables,`auto-route` 和 `auto-redirect` 已启用。
- ruleset-1
- ruleset-2
@@ -1294,7 +1295,7 @@ proxies: # socks5
# reserved: [209,98,59]
# persistent-keepalive: 0
# ip-stack:
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
# dialer-proxy: "ss1"
@@ -1373,7 +1374,7 @@ proxies: # socks5
# mtu: 1400 # optional local MTU override; cannot exceed the controller MTU
# physical-mtu: 1432 # optional ZeroTier UDP payload MTU (510-10324; default 1432)
# ip-stack:
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
# primary-port: 0 # primary UDP port; 0 selects an available port
# secondary-port: 0 # second UDP port; 0 selects an available port, -1 disables it
@@ -1494,7 +1495,7 @@ proxies: # socks5
# mtu: 1500
udp: true
# ip-stack:
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
# dialer-proxy: "ss1"
@@ -1513,7 +1514,7 @@ proxies: # socks5
mtu: 1280
udp: true
# ip-stack:
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
# dialer-proxy: "ss1"
@@ -1551,7 +1552,7 @@ proxies: # socks5
udp: true
network: h2
# ip-stack:
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
# dialer-proxy: "ss1"
@@ -2797,7 +2798,7 @@ listeners:
type: tun
# rule: sub-rule-name1 # 默认使用 rules,如果未找到 sub-rule 则直接使用 rules
# proxy: proxy # 如果不为空则直接将该入站流量交由指定 proxy 处理 (当 proxy 不为空时,这里的 proxy 名称必须合法,否则会出错)
stack: system # gvisor / mixed / mips
stack: mips # gvisor / mixed / system
dns-hijack:
- 0.0.0.0:53 # 需要劫持的 DNS
# auto-detect-interface: false # 自动识别出口网卡
@@ -2839,6 +2840,7 @@ listeners:
# exclude-package: # 排除被路由的 Android 应用包名
# - com.android.captiveportallogin
# disable-icmp-forwarding: true # 禁用 ICMP 转发,防止某些情况下的 ICMP 环回问题,ping 将不会显示真实的延迟
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; only effective on mips
# 入口配置与 Listener 等价,传入流量将和 socks,mixed 等入口一样按照 mode 所指定的方式进行匹配处理
# shadowsocks,vmess 入口配置(传入流量将和 socks,mixed 等入口一样按照 mode 所指定的方式进行匹配处理)
# ss-config: ss://2022-blake3-aes-256-gcm:vlmpIPSyHH6f4S8WVPdRIHIlzmB+GIRfoH3aNJ/t9Gg=@:23456
+2 -2
View File
@@ -28,7 +28,7 @@ require (
github.com/metacubex/jls-tls v0.0.0-20260723084315-67adc0e2f796
github.com/metacubex/kcp-go v0.0.0-20260105040817-550693377604
github.com/metacubex/mhurl v0.1.0
github.com/metacubex/mipstack v0.0.0-20260924131027-976adac53932
github.com/metacubex/mipstack v0.0.0-20260926151545-332a03e253ef
github.com/metacubex/mlkem v0.1.0
github.com/metacubex/quic-go v0.61.1-0.20260727080200-2548683b76f4
github.com/metacubex/randv2 v0.2.0
@@ -39,7 +39,7 @@ require (
github.com/metacubex/sing-quic v0.0.0-20260904234848-1c242664697a
github.com/metacubex/sing-shadowsocks v0.2.13
github.com/metacubex/sing-shadowsocks2 v0.2.8
github.com/metacubex/sing-tun v0.4.25
github.com/metacubex/sing-tun v0.4.26
github.com/metacubex/sing-vmess v0.2.5
github.com/metacubex/sing-wireguard v0.0.0-20260826105301-c3ae17d19f9e
github.com/metacubex/smux v0.0.0-20260105030934-d0c8756d3141
+4 -4
View File
@@ -135,8 +135,8 @@ github.com/metacubex/kcp-go v0.0.0-20260105040817-550693377604 h1:hJwCVlE3ojViC3
github.com/metacubex/kcp-go v0.0.0-20260105040817-550693377604/go.mod h1:lpmN3m269b3V5jFCWtffqBLS4U3QQoIid9ugtO+OhVc=
github.com/metacubex/mhurl v0.1.0 h1:ZdW4Zxe3j3uJ89gNytOazHu6kbHn5owutN/VfXOI8GE=
github.com/metacubex/mhurl v0.1.0/go.mod h1:2qpQImCbXoUs6GwJrjuEXKelPyoimsIXr07eNKZdS00=
github.com/metacubex/mipstack v0.0.0-20260924131027-976adac53932 h1:AWc8VwR2SI8BZLwdnUZmudp/i5Z1d90MHYLXNae7XGI=
github.com/metacubex/mipstack v0.0.0-20260924131027-976adac53932/go.mod h1:+bbwALZI0pbi2auSG5A3ptdpV2DZ2eLObziXo+P7oj0=
github.com/metacubex/mipstack v0.0.0-20260926151545-332a03e253ef h1:Byx3R7dvNYfBC2Mu3b3n7MY8YF1li0woae6rKGxA4Pw=
github.com/metacubex/mipstack v0.0.0-20260926151545-332a03e253ef/go.mod h1:+bbwALZI0pbi2auSG5A3ptdpV2DZ2eLObziXo+P7oj0=
github.com/metacubex/mlkem v0.1.0 h1:wFClitonSFcmipzzQvax75beLQU+D7JuC+VK1RzSL8I=
github.com/metacubex/mlkem v0.1.0/go.mod h1:amhaXZVeYNShuy9BILcR7P0gbeo/QLZsnqCdL8U2PDQ=
github.com/metacubex/nftables v0.0.0-20260426003805-208c2c1ba2cb h1:wk6mHYPURSUvWcUv72gNP79oiylFsscBSDPJ6ieV6Iw=
@@ -163,8 +163,8 @@ github.com/metacubex/sing-shadowsocks v0.2.13 h1:PKmInHy9+4nY3FLhmKcWdASUBo9WZ/K
github.com/metacubex/sing-shadowsocks v0.2.13/go.mod h1:2e5EIaw0rxKrm1YTRmiMnDulwbGxH9hAFlrwQLQMQkU=
github.com/metacubex/sing-shadowsocks2 v0.2.8 h1:6MoODu7BAcnwIC0w9muq+2LZVz01wWD07L5IRhOty9Q=
github.com/metacubex/sing-shadowsocks2 v0.2.8/go.mod h1:vOEbfKC60txi0ca+yUlqEwOGc3Obl6cnSgx9Gf45KjE=
github.com/metacubex/sing-tun v0.4.25 h1:/dYsAE9EYex20WLWYy+llEJHQLUa4KliqGXZCmvRN7Y=
github.com/metacubex/sing-tun v0.4.25/go.mod h1:+mS6xdBPSbJlujqM7MZ3JFdJ+DoLAbczAkPSFStlkkQ=
github.com/metacubex/sing-tun v0.4.26 h1:3GszRouOvS2gX90J2vUFfaY0gGFVENgvam2kgWUxAoM=
github.com/metacubex/sing-tun v0.4.26/go.mod h1:q3Cb+D3hmlRTFYmVKc8k1FFUpy5+iMxhaXVA5CM/dNA=
github.com/metacubex/sing-vmess v0.2.5 h1:m9Zt5I27lB9fmLMZfism9sH2LcnAfShZfwSkf6/KJoE=
github.com/metacubex/sing-vmess v0.2.5/go.mod h1:AwtlzUgf8COe9tRYAKqWZ+leDH7p5U98a0ZUpYehl8Q=
github.com/metacubex/sing-wireguard v0.0.0-20260826105301-c3ae17d19f9e h1:KGKZt//rrELT/dEwgYcHCqNYEGr3a7uVutlZrzrZZWY=
+4
View File
@@ -98,6 +98,7 @@ type tunSchema struct {
EndpointIndependentNat *bool `yaml:"endpoint-independent-nat" json:"endpoint-independent-nat,omitempty"`
UDPTimeout *int64 `yaml:"udp-timeout" json:"udp-timeout,omitempty"`
ICMPTimeout *int64 `yaml:"icmp-timeout" json:"icmp-timeout,omitempty"`
CongestionController *string `yaml:"congestion-controller" json:"congestion-controller,omitempty"`
FileDescriptor *int `yaml:"file-descriptor" json:"file-descriptor"`
Inet4RouteAddress *[]netip.Prefix `yaml:"inet4-route-address" json:"inet4-route-address,omitempty"`
@@ -264,6 +265,9 @@ func pointerOrDefaultTun(p *tunSchema, def LC.Tun) LC.Tun {
if p.ICMPTimeout != nil {
def.ICMPTimeout = *p.ICMPTimeout
}
if p.CongestionController != nil {
def.CongestionController = *p.CongestionController
}
if p.FileDescriptor != nil {
def.FileDescriptor = *p.FileDescriptor
}
+4
View File
@@ -53,6 +53,7 @@ type Tun struct {
UDPTimeout int64 `yaml:"udp-timeout" json:"udp-timeout,omitempty"`
ICMPTimeout int64 `yaml:"icmp-timeout" json:"icmp-timeout,omitempty"`
DisableICMPForwarding bool `yaml:"disable-icmp-forwarding" json:"disable-icmp-forwarding,omitempty"`
CongestionController string `yaml:"congestion-controller" json:"congestion-controller,omitempty"`
FileDescriptor int `yaml:"file-descriptor" json:"file-descriptor"`
Inet4RouteAddress []netip.Prefix `yaml:"inet4-route-address" json:"inet4-route-address,omitempty"`
@@ -211,6 +212,9 @@ func (t *Tun) Equal(other Tun) bool {
if t.DisableICMPForwarding != other.DisableICMPForwarding {
return false
}
if t.CongestionController != other.CongestionController {
return false
}
if t.FileDescriptor != other.FileDescriptor {
return false
}
+2
View File
@@ -54,6 +54,7 @@ type TunOption struct {
UDPTimeout int64 `inbound:"udp-timeout,omitempty"`
ICMPTimeout int64 `inbound:"icmp-timeout,omitempty"`
DisableICMPForwarding bool `inbound:"disable-icmp-forwarding,omitempty"`
CongestionController string `inbound:"congestion-controller,omitempty"`
FileDescriptor int `inbound:"file-descriptor,omitempty"`
Inet4RouteAddress []netip.Prefix `inbound:"inet4-route-address,omitempty"`
@@ -135,6 +136,7 @@ func NewTun(options *TunOption) (*Tun, error) {
UDPTimeout: options.UDPTimeout,
ICMPTimeout: options.ICMPTimeout,
DisableICMPForwarding: options.DisableICMPForwarding,
CongestionController: options.CongestionController,
FileDescriptor: options.FileDescriptor,
Inet4RouteAddress: options.Inet4RouteAddress,
+1
View File
@@ -497,6 +497,7 @@ func New(options LC.Tun, tunnel C.Tunnel, additions ...inbound.Addition) (l *Lis
Logger: log.SingLogger,
ForwarderBindInterface: forwarderBindInterface,
InterfaceFinder: interfaceFinder,
TCPCongestionControl: options.CongestionController,
EnforceBindInterface: EnforceBindInterface,
}
l.tunIf = tunIf