Stash v3.6.0:新增MASQUE/XHTTP/VLESS加密
Stash - Rule Based Proxy 3.6.0
v3.6.0 大幅扩展了代理协议的兼容性与安全性(如 REALITY 多传输支持与 PQC 默认启用),重度依赖 Stash 的用户需立即关注以利用新特性或应对潜在的安全基线变化。
· Protocols and Transports - Added the MASQUE protocol - Added VLESS Encryption: encrypts the stream without TLS underneath, and stacks with Vision flow control - Added the XHTTP transport with HTTP/1.1, HTTP/2 and HTTP/3; upload and download legs can be configured separately - Snell now supports v4, v5 and v6 (v6 in its unsafe-raw / unshaped / default modes) - REALITY is no longer limited to VLESS over TCP: it now works under VLESS WebSocket, H2, gRPC and HTTP-obfuscation transports, and under Trojan and VMess - VLESS and VMess support plaintext gRPC - VMess supports XUDP and packetaddr; VLESS and VMess gain the packet-encoding, xudp and packet-addr keys - TUIC lets you choose the congestion controller (congestion-controller: bbr / cubic / new_reno) - SOCKS5 outbound supports TLS (tls, sni, skip-cert-verify, alpn, server-cert-fingerprint) - SSH supports host-key pinning and host-key-algorithms - WebSocket transport supports Early Data (ws-opts.max-early-data, early-data-header-name, and the ?ed= marker in subscription links)
· 协议与传输 - 新增 MASQUE 协议 - 新增 VLESS 加密:在底层无 TLS 的情况下对数据流进行加密,并与 Vision 流量控制叠加使用 - 新增支持 HTTP/1.1、HTTP/2 和 HTTP/3 的 XHTTP 传输;上传和下载路径可分别配置 - Snell 现支持 v4、v5 和 v6(v6 处于 unsafe-raw / unshaped / default 模式) - REALITY 不再仅限于 TCP 上的 VLESS:它现在可在 VLESS WebSocket、H2、gRPC 和 HTTP 混淆传输下工作,并支持 Trojan 和 VMess - VLESS 和 VMess 支持明文 gRPC - VMess 支持 XUDP 和 packetaddr;VLESS 和 VMess 新增 packet-encoding、xudp 和 packet-addr 键 - TUIC 允许选择拥塞控制器(congestion-controller: bbr / cubic / new_reno) - SOCKS5 出站支持 TLS(tls, sni, skip-cert-verify, alpn, server-cert-fingerprint) - SSH 支持主机密钥固定(host-key pinning)和主机密钥算法(host-key-algorithms) - WebSocket 传输支持 Early Data(ws-opts.max-early-data, early-data-header-name,以及订阅链接中的 ?ed= 标记)
· TLS and Security - Every TLS ClientHello now offers the X25519MLKEM768 post-quantum hybrid key exchange by default; REALITY can enable it with reality-opts.support-x25519mlkem768, and shadow-tls v3 carries it as well - MitM leaf certificates are reused per public suffix, so far fewer certificates are generated
· TLS 与安全 - 每个 TLS ClientHello 默认提供 X25519MLKEM768 后量子混合密钥交换;REALITY 可通过 reality-opts.support-x25519mlkem768 启用它,shadow-tls v3 也携带此功能 - MitM 叶证书按公共后缀复用,因此生成的证书数量大幅减少
· Tailscale - Adding a Tailscale node automatically routes its MagicDNS suffix and every peer address to that node, with no hand-written rules; disable with auto-route-disabled: true - The runtime exit-node choice persists across restarts - The status API shows whether each peer is reached directly or through a DERP relay
· Tailscale - 添加 Tailscale 节点会自动将其 MagicDNS 后缀和所有对等地址路由到该节点,无需手写规则;可通过 auto-route-disabled: true 禁用 - 运行时退出节点的选择在重启后保持不变 - 状态 API 显示每个对等节点是直接可达还是通过 DERP 中继可达
· StashLink - When underlying-proxy is left empty, the relay carrier is chosen automatically from the device's own proxies, and re-chosen after network changes or subscription updates - Device names resolve under the .stash suffix and route to the matching device automatically - The path a StashLink proxy is currently on is visible; direct paths are kept across network changes where possible
· StashLink - 当 underlying-proxy 留空时,中继载体将自动从设备自身的代理中选择,并在网络变化或订阅更新后重新选择 - 设备名称在 .stash 后缀下解析,并自动路由到匹配的设备 - 可查看 StashLink 代理当前所在的路径;在可能的情况下,直接路径在网络变化中得以保留
· Rules and DNS - GEOIP and IP-ASN support UNKNOWN, matching addresses with no database entry - A rule that cannot be parsed is skipped with a warning instead of failing the whole configuration load - fake-ip-filter and nameserver-policy can reference rule-set: and geosite: - A nameserver-policy key can list several matchers separated by commas
· 规则与 DNS - GEOIP 和 IP-ASN 支持 UNKNOWN,用于匹配数据库中无条目的地址 - 无法解析的规则将被跳过并发出警告,而不是导致整个配置加载失败 - fake-ip-filter 和 nameserver-policy 可引用 rule-set: 和 geosite: - nameserver-policy 键可列出多个由逗号分隔的匹配器
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力