Skip to content

Add autoSystemWfpBlockLeak - #903

Open
patterniha wants to merge 10 commits into
XTLS:mainfrom
patterniha:strictRoute
Open

patterniha wants to merge 10 commits into
XTLS:mainfrom
patterniha:strictRoute

Conversation

@patterniha

Copy link
Copy Markdown
Contributor

patterniha and others added 4 commits September 29, 2026 13:55
Document the Windows-only `strictRoute` option of the TUN inbound (true
by default), added in XTLS/Xray-core#6853: with autoSystemRoutingTable
set, WFP filters keep DNS (when `dns` is set), and IPv6 when the TUN
cannot carry it, of every program but Xray from leaving outside the TUN.
Setting it to false turns them off. In English, Chinese and Russian.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Follows XTLS/Xray-core#6853, where strictRoute now defaults to false like
sing-box's strict_route: the filters are only added when it is enabled.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Follows XTLS/Xray-core#6853: on Windows 11, Windows Server 2022 and
later, the Windows DNS Client service may only connect through the TUN
interface, so DNS over HTTPS or TLS set up for another interface cannot
leave through it either; name resolution on the local network (LLMNR,
mDNS) stays allowed. Also say why port 53 is blocked for all programs:
Windows sends each interface's queries through that interface whatever
the routes say, and other programs reach a DNS server on the local
network through its more specific LAN route.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Follows XTLS/Xray-core#6853, where the option is now named after what it
sets up in the system, like autoSystemRoutingTable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@patterniha patterniha changed the title Add strictRoute Add autoSystemWFP Sep 29, 2026
Follows XTLS/Xray-core#6853.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@patterniha patterniha changed the title Add autoSystemWFP Add autoSystemWfpBlockLeak Sep 29, 2026
patterniha and others added 3 commits September 30, 2026 03:07
Follows XTLS/Xray-core#6853: an IP version, IPv4 or IPv6, is blocked when
no route of it is in autoSystemRoutingTable, whatever gateway holds, as
Windows gives the TUN link-local addresses of its own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Follows XTLS/Xray-core#6853: Xray assigns no address on Linux, Windows
gives the TUN interface link-local addresses itself, and macOS and
FreeBSD use 169.254.10.1/30.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d `autoSystemDnsToGateway`

Follows XTLS/Xray-core#6853: autoSystemWfpBlockLeak takes
["dns", "misconfig"]. The dns field now explains what Windows does with
the servers and what the other systems do instead, autoSystemDnsToGateway
(Linux) gets its own section, and the old macOS-only note under gateway
is folded into the note for all systems.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
patterniha and others added 2 commits September 30, 2026 07:59
Follows XTLS/Xray-core#6853.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sToGateway` cannot apply

Follows XTLS/Xray-core#6853.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant