NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1042 by repository stars
Last release 3 days ago
04 Oct 2026
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 months old
149 releases · first in 2025
One column per month.
IMPROVED: Overall performance (frontend and backend).
TCP Window Manipulation (--tcp-win-mode) - sends fake packets with manipulated TCP window sizes to confuse stateful DPI. Modes: oscillate (cycling window values), zero (zero-window probe attack), random (randomized windows), escalate (gradually increasing windows).TCP Desync Attack (--tcp-desync-mode) - injects fake TCP control packets (RST/FIN/ACK) with low TTL and corrupted checksums to desynchronize DPI connection tracking. Modes: rst, fin, ack, combo, full.SNI Mutation for ClientHello fingerprint evasion - modifies TLS handshake structure to bypass DPI fingerprinting. Modes: duplicate (inject fake SNIs), grease (add GREASE extensions), padding (add padding extension), reorder (shuffle extensions), full (all mutations combined), advanced (TLS 1.3 features like PSK/key_share).ADDED: Out-of-Band (OOB) data handling with configurable position, reverse order, and character (--frag=oob).
Out-of-Band (OOB) data handling with configurable position, reverse order, and character (--frag=oob).Out-of-Band (OOB) strategies to B4Discovery.TLS Record Splitting fragmentation strategy (--frag=tls) - splits ClientHello into multiple TLS records to bypass DPI expecting single-record handshakes.SACK dropping (--tcp-drop-sack) - strips Selective Acknowledgment options from TCP headers to force full retransmissions and confuse stateful DPI tracking.SNI payload now uses TLS 1.3 ClientHello structure with staticcdn.duckduckgo.com.SNI fragmentation for long domains (>30 bytes). Now splits 12 bytes before SNI end instead of middle, ensuring domain suffixes like googlevideo.com are properly fragmented across packets.Matcher performance with LRU caching for large geosite/geoip categories (70-90% CPU reduction for sets with big data inside).Geodat download workflow - files now immediately available in sets manager without restart, config auto-reloads after download.Fragmentation tab refactored.TCP ConnBytesLimit greater than main set error.--frag-sni-reverse to --frag-reverse and update related configurations.Nothing published for this version
ADDED: Asynchronous packet injection for TCP and UDP traffic. Verdict is now sent to kernel immediately, with packet manipulation performed in paralle
1ms sleep delays when Seg2Delay is set to 0, reducing packet processing latency by up to 6ms per QUIC packet.ADDED: Configuration sets can now be enabled/disabled without deletion.
GeoSite/GeoIP database files directly from Settings UI with preset sources./test page UX - domains are now managed directly on the test page.Discovery presets generation logic and add new test strategies./domains page when adding ASN filters (caused by expensive ASN lookup operations executing on every render).Settings - domains are now managed exclusively on the Test page.ADDED: SYN fake packet functionality for advanced DPI bypass. Sends fake SYN packets with configurable payload length to confuse DPI systems before th
--tcp-syn-fake and --tcp-syn-fake-len flags, or through the TCP settings in Web UI.IPInfo API integration. When IPInfo token is configured in Settings → API, click on any destination IP in /domains monitoring page to view detailed geolocation, ASN, organization, and network information.RIPE Stat integration for network intelligence. View ASN prefix announcements and detailed network information directly from the Web UI. Helps identify IP ranges for precise targeting.ADDED: Select target configuration set when adding domains or IP/CIDR addresses from /domains monitoring page. Allows precise control over which confi
/domains monitoring page. Allows precise control over which configuration set receives the new entry.Discovery test results. Apply the best-performing configuration directly to your configuration list without manual copying.Discovery testing service with improved reliability and performance. Now they should work as expected.ADDED: Click on destination IP addresses in /domains monitoring page to add them to configuration. Modal allows adding either exact IP or CIDR notatio
/domains monitoring page to add them to configuration. Modal allows adding either exact IP or CIDR notation for broader site coverage. This does not require to reload or restart B4, works on the fly./domains monitoring page to view all packets or only those with identified SNI/domain. Useful for monitoring and debugging UDP traffic./test menu. Discovery test results now show individual configuration cards per domain instead of a single recommended configuration, making it easier to see what works best for each specific domain.UDP port filtering now uses a single flexible field instead of separate "from" and "to" fields. Supports comma-separated ports and ranges (e.g., 80,443,2000-3000)./domains menu now only counts packets processed by B4 targets.--udp-dport-min and --udp-dport-max flags with single --udp-dport-filter flag for flexible port filtering.UDP entries are now logged even when UDP packets are configured to be ignored in the configurationUI crash when using filter in /domains monitoring page.HTTP status code. Any HTTP response (including non-200 codes) indicates successful DPI circumvention.ADDED: Configuration Sets - fine-grained bypass control for different targets
geoip.dat support.ADDED: DPI Bypass Test feature to verify that circumvention is working. The feature tests configured domains and measures download speeds to ensure B4
/test page to run tests and /settings/checker to configure test settings (define which domains to test, etc.).Core tab on the Settings page.RESTART B4 BUTTON to the Core tab on the Settings page (under the Core Controls section).flowState struct to track SNI detection and processing status.Entware/OpenWRT/systemctl).P key on the domains and logs pages) interfering with search input.IMPROVED: Intermittent connection failures where blocked sites would randomly fail to load in certain browsers (Safari, Firefox, Chrome). Connections
Safari, Firefox, Chrome). Connections should now be more stable and reliable across all browsers by optimizing packet fragmentation strategy.ADDED: Automatic iptables/nftables rules restoration. B4 now automatically detects this and restores itself without requiring a manual restart.
iptables/nftables rules restoration. B4 now automatically detects this and restores itself without requiring a manual restart.--tables-monitor-interval setting to control how often B4 checks if its rules are still active (default: 10 seconds). Set to 0 to disable automatic monitoring.IMPROVED: Increase TTL and buffer limit for flow state management.
FIXED: Return back missing geosite path field to the settings.
geosite path field to the settings.ADDED: Hotkeys to the /domains and /logs page. Press ctrl+x or Delete keys to clear the entries. Press p or Pause to pause the stram.
/domains and /logs page. Press ctrl+x or Delete keys to clear the entries. Press p or Pause to pause the stram.CHANGED: --skip-iptables and --clear-iptables renamed to --skip-tables and --clear-tables.
nftables support.--skip-iptables and --clear-iptables renamed to --skip-tables and --clear-tables.ADDED: 'RESTART SERVICE` Button in the Settings to perform the B4 restart from the Web UI.
quiet mode and geosite source/destination options to installer script. Use b4install.sh --help to get more information.OUTPUT rule.REMOVED: --conntrack and -gso flags since they both are not used in the project.
Dashboard works again.--conntrack and -gso flags since they both are not used in the project.ADDED: --clear-iptables argument to perform a cleanup of iptable rules.
--clear-iptables argument to perform a cleanup of iptable rules.IPv6 support.--ipv4 (default is true) and --ipv6 (default is false) arguments to control protocol versions.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →