Release v1.5.2
Downloads
macOS (Universal) - Supports both Apple Silicon and Intel
Option 1: Installation Script (Recommended)
Install with a single command (version v1.5.2):
curl -fsSL https://raw.githubusercontent.com/Leadaxe/singbox-launcher/develop/scripts/install-macos.sh | bash -s -- v1.5.2The script will:
- Download the release archive
- Extract and install to
/Applications/ - Fix macOS quarantine attributes and permissions
- Launch the application automatically
Option 2: Manual Installation
- Download:
singbox-launcher-v1.5.2-macos.zip - Extract the ZIP file
- Remove quarantine attribute (required):
xattr -cr "singbox-launcher.app" && chmod +x "singbox-launcher.app/Contents/MacOS/singbox-launcher"
- Double-click
singbox-launcher.appto run- If macOS blocks the app, go to System Settings → Privacy & Security and click "Open Anyway"
- Alternatively, right-click the app and select "Open" (first time only)
Windows (amd64)
- Download:
singbox-launcher-v1.5.2-win64.zip - Extract the ZIP file to a folder, for example:
C:\Program Files\singbox-launcher\ - Run
singbox-launcher.exefrom that folder- You may need administrator rights to install to Program Files
- The launcher will automatically download
sing-boxandwintun.dllon first launch
Windows 7 (x86, legacy)
- Download:
singbox-launcher-v1.5.2-win7-32.zip - Extract the ZIP file to a folder and run
singbox-launcher-win7-32.exe- For Windows 7 / 32-bit or legacy compatibility only
Linux Support
⚠️ Linux build temporarily unavailable - мы ищем тестировщика для ручного тестирования перед включением автоматической сборки.
Checksums
See checksums.txt for SHA256 checksums of all files.
v1.5.2
Node identity moved from content hashes to tags — user marks and chain links
now survive provider rotations and storage-form changes, with automatic state
migration. Plus a reworked server form (types, JSON tab, cloning), network
interface pinning, and a batch of parser/preview fixes.
EN
Highlights
- Node identity is now the tag, not a content hash (SPEC 112/112-A).
Disabled-node marks and "chain through this node" (detour) links used to be
keyed by a sha256 of the node's emitted JSON — so a provider rotating an IP
or the launcher changing the storage form silently detached marks and broke
links, dropping dependent sources from the config with no visible reason.
Identity is now the provider's raw tag, unique within its source; a detour
link is stored as an object (source id + node tag) and the final config tag
is computed on every build. Changing a source's tag prefix/mask, renaming a
source, or editing a node's server/keys/SNI no longer breaks anything.
Old states and backups migrate automatically on first run. - Renaming a node resets links to it — explicitly. Renaming a manual
server's node tag clears every detour link that pointed at it and shows a
dialog listing the affected sources. A link that cannot be resolved at build
time still fails closed (the dependent source is excluded rather than sent
direct), and the warning now names both sides: the subscription searched and
the node that was not found. - Server form reworked. Server type is picked from a selector (WireGuard,
SOCKS5, HTTP joined the URI schemes), the form got a JSON tab, a pasted
sing-box JSON config becomes a source, and sources can be cloned. The node
tag is separated from the display label — renaming a source no longer
silently changed the tag under filters and previews (#91). - Direction preview now tells the truth. Chains appear in the Direction
preview, and the preview composition matches the generatedconfig.json
(#91). - Bind to a network interface. Settings can pin the outbound interface
(with friendly device names on macOS); remote machines report their
interface list for the same picker. - Remote tab: clearer failure diagnosis. A macOS "Local Network"
permission block is reported as such instead of "machine unreachable";
saving a config to a remote machine parses subscriptions itself instead of
refusing. - Chains travel in backups. LX Backup carries chains in a root
chains[]
section (schema v1.2, merged by tag) instead of a launcher-private blob.
Technical / Internal
- Content dedup is gone with the hash: duplicate tags within a source are
uniquified (X,X-2) in parse order; full copies are no longer collapsed.
Xray JSON-array ownership (country vs pool) now uses an internal
parse-scoped connection keyscheme|server|port|credinstead of the
identity hash. - Two-pass build invariant (
core/config/node_ref.go): pass 1 assigns final
config tags to all nodes, pass 2 materializes all references through a
single resolve map — a link target may be listed below the source referring
to it. Any future reference kind must resolve through the same map. - Source ULIDs now travel as a field through the state sync instead of being
re-derived by URL matching — editing a subscription URL keeps its identity. - Contract 0.8.0 → 0.10.0: legacy MASQUE
network/server_namereading
removed (D-078, breaking); orphan lxbox-override audit (257 removed, 81
classified);IDENTITY.mdrewritten normatively for tag identity — the
Dart (LxBox) mirror is pending, see "Статус зеркала" there. - Node labels are no longer taken from URI userinfo (credential leak into
visible tags); log line timestamps tolerate a zone prefix;#in/#notIn
template predicates work with any variable type; the stray-core check works
in daemon mode; xhttp reads nestedxmuxfromextra.
Migration notes
- State migrates itself: legacy 64-hex disabled keys are re-matched via the
old hash algorithm on first parse and rewritten to tag keys; a legacy
detour_node_hashresolves to a full reference, falling back to the stored
label — this also heals links that had already rotted (the "enabled source
missing from the selector" case). Backups from v1.5.x import cleanly; the
old key generation is dropped only after it no longer matches anything. - Accepted trade: a provider renaming a node loses its disabled mark (the
mark expires by TTL instead of jumping to a stranger). Pinned by test. - LxBox older than the 0.10.0 mirror will ignore tag-keyed disabled marks in
backups (harmless — they just don't transfer until LxBox updates).
RU
Основное
- Идентичность узла — тег, а не хеш содержимого (SPEC 112/112-A).
Отметки выключенных узлов и ссылки «цепочка через этот узел» (detour)
раньше жили по sha256 от эмитированного JSON узла: ротация IP у провайдера
или смена формы хранения молча отвязывала отметки и рвала ссылки, а
зависимый источник без видимой причины выпадал из конфига. Теперь
идентичность — сырой тег провайдера, уникальный в рамках источника;
detour-ссылка хранится объектом (id источника + тег узла), финальный
конфиговый тег вычисляется на каждой сборке. Смена префикса/маски тегов,
переименование источника, правка сервера/ключей/SNI узла больше ничего не
ломают. Старые состояния и бэкапы мигрируют автоматически при первом
запуске. - Переименование узла сбрасывает ссылки на него — явно. Переименовал тег
ручного сервера — все detour-ссылки на него сбрасываются, диалог показывает
список затронутых источников. Неразрешившаяся на сборке ссылка по-прежнему
fail-closed (источник исключается, а не идёт напрямую), но предупреждение
теперь называет обе стороны: в какой подписке искали и какой узел не нашли. - Форма сервера переработана. Тип сервера выбирается селектором
(к URI-схемам добавились WireGuard, SOCKS5, HTTP), появилась вкладка JSON,
вставленный sing-box JSON становится источником, источники клонируются.
Тег узла отделён от подписи — переименование источника больше не меняло
тег под фильтрами и превью (#91). - Превью Направления не врёт. Цепочки попадают в превью, состав превью
совпадает с собираемымconfig.json(#91). - Привязка к сетевому интерфейсу. В Settings можно закрепить исходящий
интерфейс (на macOS — с человеческими именами устройств); удалённые машины
отдают список своих интерфейсов для того же пикера. - Вкладка Remote: внятный диагноз. Блокировка macOS «Локальная сеть»
называется своим именем вместо «машина не отвечает»; сохранение конфига на
удалённую машину само разбирает подписки, а не отказывает. - Цепочки ездят в бэкапах. LX Backup несёт цепочки корневой секцией
chains[](схема v1.2, merge по tag) вместо приватного блоба лаунчера.
Техническое / Внутреннее
- Вместе с хешем снесён контент-дедуп: дубли тегов внутри источника
уникализируются (X,X-2) в порядке разбора; полные копии больше не
схлопываются. Xray-ownership («страна» против «пула») переведён на
внутренний ключ подключенияscheme|server|port|cred, живущий только на
время разбора. - Инвариант двухпроходной сборки (
core/config/node_ref.go): проход 1 —
все узлы получают финальные теги, проход 2 — все ссылки материализуются
через единую карту резолва; цель ссылки вправе стоять в списке ниже
ссылающегося. Любой будущий вид ссылок обязан ходить той же картой. - ULID источника едет полем через синк состояния, а не восстанавливается
матчингом по URL — правка адреса подписки сохраняет её идентичность. - Контракт 0.8.0 → 0.10.0: снос легаси-чтения MASQUE
network/server_name
(D-078, breaking); аудит lxbox-override'ов (257 бесхозных снесено, 81
классифицирован);IDENTITY.mdпереписан нормативно под тег-идентичность —
зеркало Dart (LxBox) ожидается, см. там «Статус зеркала». - Метка узла больше не берётся из userinfo URI (утечка учётных данных в
видимые теги); таймстемпы строк лога терпят префикс зоны; предикаты
#in/#notInработают с любым типом переменной; проверка чужого sing-box
работает и в daemon-режиме; xhttp читает вложенныйxmuxизextra.
Миграция
- Состояние мигрирует само: legacy-ключи отметок (64 hex) при первом разборе
прогоняются старым алгоритмом и переписываются на тег-ключи; legacy
detour_node_hashразрешается в полную ссылку с fallback'ом на подпись —
это же лечит уже протухшие ссылки (случай «включённый источник пропал из
селектора»). Бэкапы v1.5.x импортируются. - Принятая цена: провайдерское переименование узла теряет отметку выключения
(отметка доживает по TTL, на чужой узел не переезжает). Запиновано тестом. - LxBox старше зеркала 0.10.0 проигнорирует тег-ключи отметок в бэкапе
(безвредно — они просто не переедут, пока LxBox не обновится).