LeadaxeLxBox / sing-box-lx 开发者
GitHub·2026.09.18 08:45:29(UTC+8)

Leadaxe:Linux 默认 TUN 栈改为 gvisor 以避免 system 被静默拦截

Leadaxe 说明缺 auto_redirect 时 system 栈依赖 iproute2,易被 firewalld/nftables 静默拦;mixed 仍含 system TCP 路径,故默认改 gvisor。诊断细节见原文。

作者原文@Leadaxe

Thanks for the unusually thorough diagnostic — the SOCKS-inbound control test is what makes this conclusive.

Confirmed on our side: the launcher's own template hard-defaulted tun_stack to system on Linux, while upstream sing-box built with_gvisor defaults to mixed. So this was the launcher's choice, not a core default. We also do not emit auto_redirect yet, which the sing-box docs recommend on Linux — without it the system stack relies entirely on iproute2 rules, and a firewalld/nftables policy can drop that path silently. mixed would not help here either: it keeps the system stack for TCP, which is exactly what stalls in your report.

What you can do right now: the selector already exists and persists — Wizard → Settings → "TUN stack" → gvisor, then restart the VPN. Your "stack": "gvisor" output is exactly what it produces.

Changed in develop: the Linux default is now gvisor (template, with a note about firewalld/nftables in the setting's help text); it ships with the next release together with the template update. Exposing auto_redirect as a proper option is tracked separately, since that addresses the root cause of the system stack rather than working around it.