github Leadaxe/singbox-launcher v1.5.2
release v1.5.2

latest release: v1.5.3
4 hours ago

Release v1.5.2

Downloads

macOS (Universal) - Supports both Apple Silicon and Intel

Option 1: Installation Script (Recommended)

Install with a single command (version v1.5.2):

curl -fsSL https://raw.githubusercontent.com/Leadaxe/singbox-launcher/develop/scripts/install-macos.sh | bash -s -- v1.5.2

The script will:

  • Download the release archive
  • Extract and install to /Applications/
  • Fix macOS quarantine attributes and permissions
  • Launch the application automatically

Option 2: Manual Installation

  1. Download: singbox-launcher-v1.5.2-macos.zip
  2. Extract the ZIP file
  3. Remove quarantine attribute (required):
    xattr -cr "singbox-launcher.app" && chmod +x "singbox-launcher.app/Contents/MacOS/singbox-launcher"
  4. Double-click singbox-launcher.app to run
    • If macOS blocks the app, go to System Settings → Privacy & Security and click "Open Anyway"
    • Alternatively, right-click the app and select "Open" (first time only)

Windows (amd64)

  1. Download: singbox-launcher-v1.5.2-win64.zip
  2. Extract the ZIP file to a folder, for example: C:\Program Files\singbox-launcher\
  3. Run singbox-launcher.exe from that folder
    • You may need administrator rights to install to Program Files
    • The launcher will automatically download sing-box and wintun.dll on first launch

Windows 7 (x86, legacy)

  1. Download: singbox-launcher-v1.5.2-win7-32.zip
  2. Extract the ZIP file to a folder and run singbox-launcher-win7-32.exe
    • For Windows 7 / 32-bit or legacy compatibility only

Linux Support

⚠️ Linux build temporarily unavailable - мы ищем тестировщика для ручного тестирования перед включением автоматической сборки.

Checksums

See checksums.txt for SHA256 checksums of all files.

v1.5.2

Node identity moved from content hashes to tags — user marks and chain links
now survive provider rotations and storage-form changes, with automatic state
migration. Plus a reworked server form (types, JSON tab, cloning), network
interface pinning, and a batch of parser/preview fixes.

EN

Highlights

  • Node identity is now the tag, not a content hash (SPEC 112/112-A).
    Disabled-node marks and "chain through this node" (detour) links used to be
    keyed by a sha256 of the node's emitted JSON — so a provider rotating an IP
    or the launcher changing the storage form silently detached marks and broke
    links, dropping dependent sources from the config with no visible reason.
    Identity is now the provider's raw tag, unique within its source; a detour
    link is stored as an object (source id + node tag) and the final config tag
    is computed on every build. Changing a source's tag prefix/mask, renaming a
    source, or editing a node's server/keys/SNI no longer breaks anything.
    Old states and backups migrate automatically on first run.
  • Renaming a node resets links to it — explicitly. Renaming a manual
    server's node tag clears every detour link that pointed at it and shows a
    dialog listing the affected sources. A link that cannot be resolved at build
    time still fails closed (the dependent source is excluded rather than sent
    direct), and the warning now names both sides: the subscription searched and
    the node that was not found.
  • Server form reworked. Server type is picked from a selector (WireGuard,
    SOCKS5, HTTP joined the URI schemes), the form got a JSON tab, a pasted
    sing-box JSON config becomes a source, and sources can be cloned. The node
    tag is separated from the display label — renaming a source no longer
    silently changed the tag under filters and previews (#91).
  • Direction preview now tells the truth. Chains appear in the Direction
    preview, and the preview composition matches the generated config.json
    (#91).
  • Bind to a network interface. Settings can pin the outbound interface
    (with friendly device names on macOS); remote machines report their
    interface list for the same picker.
  • Remote tab: clearer failure diagnosis. A macOS "Local Network"
    permission block is reported as such instead of "machine unreachable";
    saving a config to a remote machine parses subscriptions itself instead of
    refusing.
  • Chains travel in backups. LX Backup carries chains in a root chains[]
    section (schema v1.2, merged by tag) instead of a launcher-private blob.

Technical / Internal

  • Content dedup is gone with the hash: duplicate tags within a source are
    uniquified (X, X-2) in parse order; full copies are no longer collapsed.
    Xray JSON-array ownership (country vs pool) now uses an internal
    parse-scoped connection key scheme|server|port|cred instead of the
    identity hash.
  • Two-pass build invariant (core/config/node_ref.go): pass 1 assigns final
    config tags to all nodes, pass 2 materializes all references through a
    single resolve map — a link target may be listed below the source referring
    to it. Any future reference kind must resolve through the same map.
  • Source ULIDs now travel as a field through the state sync instead of being
    re-derived by URL matching — editing a subscription URL keeps its identity.
  • Contract 0.8.0 → 0.10.0: legacy MASQUE network/server_name reading
    removed (D-078, breaking); orphan lxbox-override audit (257 removed, 81
    classified); IDENTITY.md rewritten normatively for tag identity — the
    Dart (LxBox) mirror is pending, see "Статус зеркала" there.
  • Node labels are no longer taken from URI userinfo (credential leak into
    visible tags); log line timestamps tolerate a zone prefix; #in/#notIn
    template predicates work with any variable type; the stray-core check works
    in daemon mode; xhttp reads nested xmux from extra.

Migration notes

  • State migrates itself: legacy 64-hex disabled keys are re-matched via the
    old hash algorithm on first parse and rewritten to tag keys; a legacy
    detour_node_hash resolves to a full reference, falling back to the stored
    label — this also heals links that had already rotted (the "enabled source
    missing from the selector" case). Backups from v1.5.x import cleanly; the
    old key generation is dropped only after it no longer matches anything.
  • Accepted trade: a provider renaming a node loses its disabled mark (the
    mark expires by TTL instead of jumping to a stranger). Pinned by test.
  • LxBox older than the 0.10.0 mirror will ignore tag-keyed disabled marks in
    backups (harmless — they just don't transfer until LxBox updates).

RU

Основное

  • Идентичность узла — тег, а не хеш содержимого (SPEC 112/112-A).
    Отметки выключенных узлов и ссылки «цепочка через этот узел» (detour)
    раньше жили по sha256 от эмитированного JSON узла: ротация IP у провайдера
    или смена формы хранения молча отвязывала отметки и рвала ссылки, а
    зависимый источник без видимой причины выпадал из конфига. Теперь
    идентичность — сырой тег провайдера, уникальный в рамках источника;
    detour-ссылка хранится объектом (id источника + тег узла), финальный
    конфиговый тег вычисляется на каждой сборке. Смена префикса/маски тегов,
    переименование источника, правка сервера/ключей/SNI узла больше ничего не
    ломают. Старые состояния и бэкапы мигрируют автоматически при первом
    запуске.
  • Переименование узла сбрасывает ссылки на него — явно. Переименовал тег
    ручного сервера — все detour-ссылки на него сбрасываются, диалог показывает
    список затронутых источников. Неразрешившаяся на сборке ссылка по-прежнему
    fail-closed (источник исключается, а не идёт напрямую), но предупреждение
    теперь называет обе стороны: в какой подписке искали и какой узел не нашли.
  • Форма сервера переработана. Тип сервера выбирается селектором
    (к URI-схемам добавились WireGuard, SOCKS5, HTTP), появилась вкладка JSON,
    вставленный sing-box JSON становится источником, источники клонируются.
    Тег узла отделён от подписи — переименование источника больше не меняло
    тег под фильтрами и превью (#91).
  • Превью Направления не врёт. Цепочки попадают в превью, состав превью
    совпадает с собираемым config.json (#91).
  • Привязка к сетевому интерфейсу. В Settings можно закрепить исходящий
    интерфейс (на macOS — с человеческими именами устройств); удалённые машины
    отдают список своих интерфейсов для того же пикера.
  • Вкладка Remote: внятный диагноз. Блокировка macOS «Локальная сеть»
    называется своим именем вместо «машина не отвечает»; сохранение конфига на
    удалённую машину само разбирает подписки, а не отказывает.
  • Цепочки ездят в бэкапах. LX Backup несёт цепочки корневой секцией
    chains[] (схема v1.2, merge по tag) вместо приватного блоба лаунчера.

Техническое / Внутреннее

  • Вместе с хешем снесён контент-дедуп: дубли тегов внутри источника
    уникализируются (X, X-2) в порядке разбора; полные копии больше не
    схлопываются. Xray-ownership («страна» против «пула») переведён на
    внутренний ключ подключения scheme|server|port|cred, живущий только на
    время разбора.
  • Инвариант двухпроходной сборки (core/config/node_ref.go): проход 1 —
    все узлы получают финальные теги, проход 2 — все ссылки материализуются
    через единую карту резолва; цель ссылки вправе стоять в списке ниже
    ссылающегося. Любой будущий вид ссылок обязан ходить той же картой.
  • ULID источника едет полем через синк состояния, а не восстанавливается
    матчингом по URL — правка адреса подписки сохраняет её идентичность.
  • Контракт 0.8.0 → 0.10.0: снос легаси-чтения MASQUE network/server_name
    (D-078, breaking); аудит lxbox-override'ов (257 бесхозных снесено, 81
    классифицирован); IDENTITY.md переписан нормативно под тег-идентичность —
    зеркало Dart (LxBox) ожидается, см. там «Статус зеркала».
  • Метка узла больше не берётся из userinfo URI (утечка учётных данных в
    видимые теги); таймстемпы строк лога терпят префикс зоны; предикаты
    #in/#notIn работают с любым типом переменной; проверка чужого sing-box
    работает и в daemon-режиме; xhttp читает вложенный xmux из extra.

Миграция

  • Состояние мигрирует само: legacy-ключи отметок (64 hex) при первом разборе
    прогоняются старым алгоритмом и переписываются на тег-ключи; legacy
    detour_node_hash разрешается в полную ссылку с fallback'ом на подпись —
    это же лечит уже протухшие ссылки (случай «включённый источник пропал из
    селектора»). Бэкапы v1.5.x импортируются.
  • Принятая цена: провайдерское переименование узла теряет отметку выключения
    (отметка доживает по TTL, на чужой узел не переезжает). Запиновано тестом.
  • LxBox старше зеркала 0.10.0 проигнорирует тег-ключи отметок в бэкапе
    (безвредно — они просто не переедут, пока LxBox не обновится).

Don't miss a new singbox-launcher release

NewReleases is sending notifications on new releases.