Clash Verge Rev v2.5.6 (2026-09-26) on Windows is less about new toggles and more about fake failures that burn an afternoon: core will not start as a normal user when the service is missing; isolation rights mis-detected so Service Mode/TUN stay unavailable; leftover service state blocking reinstall; a ~two-minute blank wait when starting with the service already stopped; opaque security-check errors. Release overview: v2.5.6 notes. Builds: download center.
Two base guides already exist: Windows Service Mode (install or skip) and Tun start failed (generic tree). This page does not redo install steps. It answers: is your symptom one of the 2.5.6 fixes; how to verify after upgrade; where to stop so you do not wipe subscriptions by mistake.
Quick triage: symptom → base guide
| Symptom | Check first | Base guide |
|---|---|---|
| Core dead as normal user | Windows service Running? | Service Mode |
| TUN greyed out | Isolation / permission | Tun start failed |
| No Connections rows | Core up vs rules | core communication |
| Groups empty | Subscription fetch | no nodes |
Match the symptom before blaming “all nodes red”
Flaky browsers and all-red latency tests are usually nodes or subscriptions—not the service. These patterns sit on the service/rights layer and match what the Release lists:
| What you see | Likely layer | v2.5.6 angle | Do not do first |
|---|---|---|---|
| Core dead in a normal window; works briefly as admin | Service missing/unhealthy | Core start without service under normal rights | Live on “Run as administrator” |
| Service Mode greyed out / TUN unavailable off corporate images too | Isolation mis-detection | False “cannot use service/TUN” | Format the disk or swap airports |
| Reinstall service fails; old service will not clear | Leftover state | Recognizable leftovers backed up then restored | Delete random services by guesswork |
| Service stopped; UI blank for ~two minutes | Startup timing | Long wait when service already stopped | Spam the installer while waiting |
| Security check failed; message unreadable | Service security check | Clearer copy plus fix docs | Ignore the prompt and over-install thrice |
No rows in Connections while system proxy looks green: separate “core never started” from “core up, rules/nodes mis-route.” Banners: core communication. Empty groups: no nodes.
What v2.5.6 actually changed on Windows
From the GitHub Release v2.5.6 notes:
- No service + normal rights: core-start path fixed. Intent: install the service instead of permanently elevating the GUI.
- Isolation mis-detection: environments wrongly marked unable to install service or enable TUN. After 2.5.6, retry install/TUN before assuming the machine is permanently blocked.
- Leftover service blocking reinstall: recognizable leftovers are backed up, then install resumes—fewer “cannot remove / cannot install” deadlocks.
- Stopped-service startup wait: the old ~two-minute blank window should shrink to something predictable.
- Security-check failures: readable explanations plus a docs link—read before clicking reinstall again.
The same Release also fixes false “update failed” when proxy/rule providers respond slowly. That is the subscription fetch path—keep using subscription update failed as the base guide, and do not mash provider refresh while you are verifying the service.
Before upgrade: three baselines
- Version string in About (still on 2.5.2 / 2.5.5?).
- Whether Service Mode shows installed; whether the matching Windows service is Running.
- Whether TUN toggles on; if not, the exact error or log tokens (permission, driver, isolation, service).
Optional backup via export or WebDAV. Jumping to 2.5.6 also folds in 2.5.5 fixes (shared subscription cache paths, DNS override issues)—see the news post. If in-app update loops, prefer a manual package: app update failed.
After upgrade: verify one layer at a time
- Quit the app; over-install v2.5.6 from the download center; confirm About.
- Launch as a normal user. If the core only lives under admin, repair Service Mode via Service Mode.
- On security-check failure or leftover prompts, follow the new copy/docs; let the client back up recognizable leftovers—do not run two installers at once.
- Only then enable TUN. Failures go to Tun start failed (drivers/VPN), not “maybe the version did not apply.”
- Generate traffic from an app that ignores system proxy; then disable TUN and confirm the browser still works on system proxy—you need that fallback.
Wake-only flakes: sleep/wake offline. AV/firewall: firewall.
Stop rules
- Reinstalled the service twice the same afternoon with no Connections rows: stop and inspect other VPNs/TAP/EDR.
- Do not reset config while TUN is still red—that moves the blast radius into subscriptions/Merge.
- Do not treat “provider update failed” and “service not installed” as one button.
Minimum pass: version 2.5.6; core usable as a normal user; TUN stable with Connections rows when you need it; system proxy still works with TUN off. Install boundaries stay in the Service Mode guide; toggle failures stay in Tun start failed.