mirror of
https://github.com/MetaCubeX/mihomo.git
synced 2026-10-10 04:03:11 +08:00
chore: change default IP stack mode to mips and support congestion-controller option for tun
This commit is contained in:
@@ -193,11 +193,7 @@ type ipStack interface {
|
||||
func newIPStack(option IPStackOption, localAddresses []netip.Prefix, mtu uint32) (ipStack, error) {
|
||||
mode := option.Mode
|
||||
if mode == ipStackAuto {
|
||||
if features.WithGVisor {
|
||||
mode = ipStackGVisor
|
||||
} else {
|
||||
mode = ipStackMips
|
||||
}
|
||||
mode = ipStackMips
|
||||
}
|
||||
switch mode {
|
||||
case ipStackGVisor:
|
||||
|
||||
+3
-1
@@ -314,6 +314,7 @@ type RawTun struct {
|
||||
UDPTimeout int64 `yaml:"udp-timeout" json:"udp-timeout,omitempty"`
|
||||
ICMPTimeout int64 `yaml:"icmp-timeout" json:"icmp-timeout,omitempty"`
|
||||
DisableICMPForwarding bool `yaml:"disable-icmp-forwarding" json:"disable-icmp-forwarding,omitempty"`
|
||||
CongestionController string `yaml:"congestion-controller" json:"congestion-controller,omitempty"`
|
||||
FileDescriptor int `yaml:"file-descriptor" json:"file-descriptor"`
|
||||
|
||||
Inet4RouteAddress []netip.Prefix `yaml:"inet4-route-address" json:"inet4-route-address,omitempty"`
|
||||
@@ -543,7 +544,7 @@ func DefaultRawConfig() *RawConfig {
|
||||
Tun: RawTun{
|
||||
Enable: false,
|
||||
Device: "",
|
||||
Stack: C.TunGvisor,
|
||||
Stack: C.TunMips,
|
||||
DNSHijack: []string{"0.0.0.0:53"}, // default hijack all dns query
|
||||
AutoRoute: true,
|
||||
AutoDetectInterface: true,
|
||||
@@ -1733,6 +1734,7 @@ func parseTun(rawTun RawTun, dns *DNS, general *General) error {
|
||||
UDPTimeout: rawTun.UDPTimeout,
|
||||
ICMPTimeout: rawTun.ICMPTimeout,
|
||||
DisableICMPForwarding: rawTun.DisableICMPForwarding,
|
||||
CongestionController: rawTun.CongestionController,
|
||||
FileDescriptor: rawTun.FileDescriptor,
|
||||
|
||||
Inet4RouteAddress: rawTun.Inet4RouteAddress,
|
||||
|
||||
+9
-7
@@ -133,7 +133,7 @@ profile: # 存储 select 选择记录
|
||||
# Tun 配置
|
||||
tun:
|
||||
enable: false
|
||||
stack: system # gvisor/mixed/mips
|
||||
stack: mips # gvisor/mixed/system
|
||||
dns-hijack:
|
||||
- 0.0.0.0:53 # 需要劫持的 DNS
|
||||
# auto-detect-interface: true # 自动识别出口网卡
|
||||
@@ -144,6 +144,7 @@ tun:
|
||||
auto-redirect: false # 自动配置 iptables 以重定向 TCP 连接。仅支持 Linux。带有 auto-redirect 的 auto-route 现在可以在路由器上按预期工作,无需干预。
|
||||
# strict-route: true # 将所有连接路由到 tun 来防止泄漏,但你的设备将无法其他设备被访问
|
||||
# disable-icmp-forwarding: true # 禁用 ICMP 转发,防止某些情况下的 ICMP 环回问题,ping 将不会显示真实的延迟
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; only effective on mips
|
||||
route-address-set: # 将指定规则集中的目标 IP CIDR 规则添加到防火墙, 不匹配的流量将绕过路由, 仅支持 Linux,且需要 nftables,`auto-route` 和 `auto-redirect` 已启用。
|
||||
- ruleset-1
|
||||
- ruleset-2
|
||||
@@ -1294,7 +1295,7 @@ proxies: # socks5
|
||||
# reserved: [209,98,59]
|
||||
# persistent-keepalive: 0
|
||||
# ip-stack:
|
||||
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
|
||||
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
|
||||
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
|
||||
# dialer-proxy: "ss1"
|
||||
@@ -1373,7 +1374,7 @@ proxies: # socks5
|
||||
# mtu: 1400 # optional local MTU override; cannot exceed the controller MTU
|
||||
# physical-mtu: 1432 # optional ZeroTier UDP payload MTU (510-10324; default 1432)
|
||||
# ip-stack:
|
||||
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
|
||||
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
|
||||
# primary-port: 0 # primary UDP port; 0 selects an available port
|
||||
# secondary-port: 0 # second UDP port; 0 selects an available port, -1 disables it
|
||||
@@ -1494,7 +1495,7 @@ proxies: # socks5
|
||||
# mtu: 1500
|
||||
udp: true
|
||||
# ip-stack:
|
||||
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
|
||||
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
|
||||
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
|
||||
# dialer-proxy: "ss1"
|
||||
@@ -1513,7 +1514,7 @@ proxies: # socks5
|
||||
mtu: 1280
|
||||
udp: true
|
||||
# ip-stack:
|
||||
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
|
||||
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
|
||||
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
|
||||
# dialer-proxy: "ss1"
|
||||
@@ -1551,7 +1552,7 @@ proxies: # socks5
|
||||
udp: true
|
||||
network: h2
|
||||
# ip-stack:
|
||||
# mode: auto # options: auto, gvisor, mips; auto uses gVisor when compiled in and mihomo IP stack (MIPS) otherwise
|
||||
# mode: auto # options: auto, mips, gvisor; auto uses mihomo IP stack (MIPS), gvisor needs compiled with -tags with_gvisor
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; ignored by gVisor
|
||||
# 一个出站代理的标识。当值不为空时,将使用指定的 proxy 发出连接
|
||||
# dialer-proxy: "ss1"
|
||||
@@ -2797,7 +2798,7 @@ listeners:
|
||||
type: tun
|
||||
# rule: sub-rule-name1 # 默认使用 rules,如果未找到 sub-rule 则直接使用 rules
|
||||
# proxy: proxy # 如果不为空则直接将该入站流量交由指定 proxy 处理 (当 proxy 不为空时,这里的 proxy 名称必须合法,否则会出错)
|
||||
stack: system # gvisor / mixed / mips
|
||||
stack: mips # gvisor / mixed / system
|
||||
dns-hijack:
|
||||
- 0.0.0.0:53 # 需要劫持的 DNS
|
||||
# auto-detect-interface: false # 自动识别出口网卡
|
||||
@@ -2839,6 +2840,7 @@ listeners:
|
||||
# exclude-package: # 排除被路由的 Android 应用包名
|
||||
# - com.android.captiveportallogin
|
||||
# disable-icmp-forwarding: true # 禁用 ICMP 转发,防止某些情况下的 ICMP 环回问题,ping 将不会显示真实的延迟
|
||||
# congestion-controller: cubic # TCP congestion controller: cubic, reno, bbr, or bbr3; only effective on mips
|
||||
# 入口配置与 Listener 等价,传入流量将和 socks,mixed 等入口一样按照 mode 所指定的方式进行匹配处理
|
||||
# shadowsocks,vmess 入口配置(传入流量将和 socks,mixed 等入口一样按照 mode 所指定的方式进行匹配处理)
|
||||
# ss-config: ss://2022-blake3-aes-256-gcm:vlmpIPSyHH6f4S8WVPdRIHIlzmB+GIRfoH3aNJ/t9Gg=@:23456
|
||||
|
||||
@@ -28,7 +28,7 @@ require (
|
||||
github.com/metacubex/jls-tls v0.0.0-20260723084315-67adc0e2f796
|
||||
github.com/metacubex/kcp-go v0.0.0-20260105040817-550693377604
|
||||
github.com/metacubex/mhurl v0.1.0
|
||||
github.com/metacubex/mipstack v0.0.0-20260924131027-976adac53932
|
||||
github.com/metacubex/mipstack v0.0.0-20260926151545-332a03e253ef
|
||||
github.com/metacubex/mlkem v0.1.0
|
||||
github.com/metacubex/quic-go v0.61.1-0.20260727080200-2548683b76f4
|
||||
github.com/metacubex/randv2 v0.2.0
|
||||
@@ -39,7 +39,7 @@ require (
|
||||
github.com/metacubex/sing-quic v0.0.0-20260904234848-1c242664697a
|
||||
github.com/metacubex/sing-shadowsocks v0.2.13
|
||||
github.com/metacubex/sing-shadowsocks2 v0.2.8
|
||||
github.com/metacubex/sing-tun v0.4.25
|
||||
github.com/metacubex/sing-tun v0.4.26
|
||||
github.com/metacubex/sing-vmess v0.2.5
|
||||
github.com/metacubex/sing-wireguard v0.0.0-20260826105301-c3ae17d19f9e
|
||||
github.com/metacubex/smux v0.0.0-20260105030934-d0c8756d3141
|
||||
|
||||
@@ -135,8 +135,8 @@ github.com/metacubex/kcp-go v0.0.0-20260105040817-550693377604 h1:hJwCVlE3ojViC3
|
||||
github.com/metacubex/kcp-go v0.0.0-20260105040817-550693377604/go.mod h1:lpmN3m269b3V5jFCWtffqBLS4U3QQoIid9ugtO+OhVc=
|
||||
github.com/metacubex/mhurl v0.1.0 h1:ZdW4Zxe3j3uJ89gNytOazHu6kbHn5owutN/VfXOI8GE=
|
||||
github.com/metacubex/mhurl v0.1.0/go.mod h1:2qpQImCbXoUs6GwJrjuEXKelPyoimsIXr07eNKZdS00=
|
||||
github.com/metacubex/mipstack v0.0.0-20260924131027-976adac53932 h1:AWc8VwR2SI8BZLwdnUZmudp/i5Z1d90MHYLXNae7XGI=
|
||||
github.com/metacubex/mipstack v0.0.0-20260924131027-976adac53932/go.mod h1:+bbwALZI0pbi2auSG5A3ptdpV2DZ2eLObziXo+P7oj0=
|
||||
github.com/metacubex/mipstack v0.0.0-20260926151545-332a03e253ef h1:Byx3R7dvNYfBC2Mu3b3n7MY8YF1li0woae6rKGxA4Pw=
|
||||
github.com/metacubex/mipstack v0.0.0-20260926151545-332a03e253ef/go.mod h1:+bbwALZI0pbi2auSG5A3ptdpV2DZ2eLObziXo+P7oj0=
|
||||
github.com/metacubex/mlkem v0.1.0 h1:wFClitonSFcmipzzQvax75beLQU+D7JuC+VK1RzSL8I=
|
||||
github.com/metacubex/mlkem v0.1.0/go.mod h1:amhaXZVeYNShuy9BILcR7P0gbeo/QLZsnqCdL8U2PDQ=
|
||||
github.com/metacubex/nftables v0.0.0-20260426003805-208c2c1ba2cb h1:wk6mHYPURSUvWcUv72gNP79oiylFsscBSDPJ6ieV6Iw=
|
||||
@@ -163,8 +163,8 @@ github.com/metacubex/sing-shadowsocks v0.2.13 h1:PKmInHy9+4nY3FLhmKcWdASUBo9WZ/K
|
||||
github.com/metacubex/sing-shadowsocks v0.2.13/go.mod h1:2e5EIaw0rxKrm1YTRmiMnDulwbGxH9hAFlrwQLQMQkU=
|
||||
github.com/metacubex/sing-shadowsocks2 v0.2.8 h1:6MoODu7BAcnwIC0w9muq+2LZVz01wWD07L5IRhOty9Q=
|
||||
github.com/metacubex/sing-shadowsocks2 v0.2.8/go.mod h1:vOEbfKC60txi0ca+yUlqEwOGc3Obl6cnSgx9Gf45KjE=
|
||||
github.com/metacubex/sing-tun v0.4.25 h1:/dYsAE9EYex20WLWYy+llEJHQLUa4KliqGXZCmvRN7Y=
|
||||
github.com/metacubex/sing-tun v0.4.25/go.mod h1:+mS6xdBPSbJlujqM7MZ3JFdJ+DoLAbczAkPSFStlkkQ=
|
||||
github.com/metacubex/sing-tun v0.4.26 h1:3GszRouOvS2gX90J2vUFfaY0gGFVENgvam2kgWUxAoM=
|
||||
github.com/metacubex/sing-tun v0.4.26/go.mod h1:q3Cb+D3hmlRTFYmVKc8k1FFUpy5+iMxhaXVA5CM/dNA=
|
||||
github.com/metacubex/sing-vmess v0.2.5 h1:m9Zt5I27lB9fmLMZfism9sH2LcnAfShZfwSkf6/KJoE=
|
||||
github.com/metacubex/sing-vmess v0.2.5/go.mod h1:AwtlzUgf8COe9tRYAKqWZ+leDH7p5U98a0ZUpYehl8Q=
|
||||
github.com/metacubex/sing-wireguard v0.0.0-20260826105301-c3ae17d19f9e h1:KGKZt//rrELT/dEwgYcHCqNYEGr3a7uVutlZrzrZZWY=
|
||||
|
||||
@@ -98,6 +98,7 @@ type tunSchema struct {
|
||||
EndpointIndependentNat *bool `yaml:"endpoint-independent-nat" json:"endpoint-independent-nat,omitempty"`
|
||||
UDPTimeout *int64 `yaml:"udp-timeout" json:"udp-timeout,omitempty"`
|
||||
ICMPTimeout *int64 `yaml:"icmp-timeout" json:"icmp-timeout,omitempty"`
|
||||
CongestionController *string `yaml:"congestion-controller" json:"congestion-controller,omitempty"`
|
||||
FileDescriptor *int `yaml:"file-descriptor" json:"file-descriptor"`
|
||||
|
||||
Inet4RouteAddress *[]netip.Prefix `yaml:"inet4-route-address" json:"inet4-route-address,omitempty"`
|
||||
@@ -264,6 +265,9 @@ func pointerOrDefaultTun(p *tunSchema, def LC.Tun) LC.Tun {
|
||||
if p.ICMPTimeout != nil {
|
||||
def.ICMPTimeout = *p.ICMPTimeout
|
||||
}
|
||||
if p.CongestionController != nil {
|
||||
def.CongestionController = *p.CongestionController
|
||||
}
|
||||
if p.FileDescriptor != nil {
|
||||
def.FileDescriptor = *p.FileDescriptor
|
||||
}
|
||||
|
||||
@@ -53,6 +53,7 @@ type Tun struct {
|
||||
UDPTimeout int64 `yaml:"udp-timeout" json:"udp-timeout,omitempty"`
|
||||
ICMPTimeout int64 `yaml:"icmp-timeout" json:"icmp-timeout,omitempty"`
|
||||
DisableICMPForwarding bool `yaml:"disable-icmp-forwarding" json:"disable-icmp-forwarding,omitempty"`
|
||||
CongestionController string `yaml:"congestion-controller" json:"congestion-controller,omitempty"`
|
||||
FileDescriptor int `yaml:"file-descriptor" json:"file-descriptor"`
|
||||
|
||||
Inet4RouteAddress []netip.Prefix `yaml:"inet4-route-address" json:"inet4-route-address,omitempty"`
|
||||
@@ -211,6 +212,9 @@ func (t *Tun) Equal(other Tun) bool {
|
||||
if t.DisableICMPForwarding != other.DisableICMPForwarding {
|
||||
return false
|
||||
}
|
||||
if t.CongestionController != other.CongestionController {
|
||||
return false
|
||||
}
|
||||
if t.FileDescriptor != other.FileDescriptor {
|
||||
return false
|
||||
}
|
||||
|
||||
@@ -54,6 +54,7 @@ type TunOption struct {
|
||||
UDPTimeout int64 `inbound:"udp-timeout,omitempty"`
|
||||
ICMPTimeout int64 `inbound:"icmp-timeout,omitempty"`
|
||||
DisableICMPForwarding bool `inbound:"disable-icmp-forwarding,omitempty"`
|
||||
CongestionController string `inbound:"congestion-controller,omitempty"`
|
||||
FileDescriptor int `inbound:"file-descriptor,omitempty"`
|
||||
|
||||
Inet4RouteAddress []netip.Prefix `inbound:"inet4-route-address,omitempty"`
|
||||
@@ -135,6 +136,7 @@ func NewTun(options *TunOption) (*Tun, error) {
|
||||
UDPTimeout: options.UDPTimeout,
|
||||
ICMPTimeout: options.ICMPTimeout,
|
||||
DisableICMPForwarding: options.DisableICMPForwarding,
|
||||
CongestionController: options.CongestionController,
|
||||
FileDescriptor: options.FileDescriptor,
|
||||
|
||||
Inet4RouteAddress: options.Inet4RouteAddress,
|
||||
|
||||
@@ -497,6 +497,7 @@ func New(options LC.Tun, tunnel C.Tunnel, additions ...inbound.Addition) (l *Lis
|
||||
Logger: log.SingLogger,
|
||||
ForwarderBindInterface: forwarderBindInterface,
|
||||
InterfaceFinder: interfaceFinder,
|
||||
TCPCongestionControl: options.CongestionController,
|
||||
EnforceBindInterface: EnforceBindInterface,
|
||||
}
|
||||
l.tunIf = tunIf
|
||||
|
||||
Reference in New Issue
Block a user