github Leadaxe/singbox-launcher v2.3.4
release v2.3.4

4 hours ago

Release v2.3.4

Downloads

macOS (Universal) - Supports both Apple Silicon and Intel

Option 1: Installation Script (Recommended)

Install with a single command (version v2.3.4):

curl -fsSL https://raw.githubusercontent.com/Leadaxe/singbox-launcher/develop/scripts/install-macos.sh | bash -s -- v2.3.4

The script will:

  • Download the release archive
  • Extract and install to /Applications/
  • Fix macOS quarantine attributes and permissions
  • Launch the application automatically

Option 2: Manual Installation

  1. Download: singbox-launcher-v2.3.4-macos.zip
  2. Extract the ZIP file
  3. Remove quarantine attribute (required):
    xattr -cr "singbox-launcher.app" && chmod +x "singbox-launcher.app/Contents/MacOS/singbox-launcher"
  4. Double-click singbox-launcher.app to run
    • If macOS blocks the app, go to System Settings → Privacy & Security and click "Open Anyway"
    • Alternatively, right-click the app and select "Open" (first time only)

Windows (amd64)

Option 1: Installer (Recommended)

  1. Download: singbox-launcher-v2.3.4-win64-setup.exe
  2. Run it and confirm the administrator prompt once. The launcher goes to C:\Program Files\singbox-launcher, your data to %LOCALAPPDATA%\singbox-launcher; sing-box.exe, wintun.dll, the config template and Mesa3D are included, nothing is downloaded on first launch
    • Tasks: desktop shortcut, Start with Windows, software OpenGL (Mesa3D) for RDP / VMs without a GPU
    • Installing over a previous version keeps your data; uninstall from Settings → Apps asks whether to remove the data too
    • The installer is not code-signed yet: if SmartScreen shows "Windows protected your PC", click More info → Run anyway

Option 2: Portable ZIP

  1. Download: singbox-launcher-v2.3.4-win64.zip
    • or singbox-launcher-v2.3.4-win64-full.zip — full bundle: sing-box.exe, wintun.dll, the config template and Mesa3D (mesa3d/, used only when no hardware OpenGL — RDP, VMs) are already inside, nothing is downloaded on first launch
  2. Extract the ZIP file to a folder your account can write to, for example D:\Tools\singbox-launcher\ — settings stay next to the program (portable.txt)
    • Under C:\Program Files\ the launcher keeps its data in %LOCALAPPDATA%\singbox-launcher instead
  3. Run singbox-launcher.exe from that folder — no administrator rights, no UAC prompt
    • TUN needs administrator rights: Start offers Restart as administrator or Switch to proxy mode
    • The regular archive downloads sing-box and wintun.dll on first launch

Windows 7 (x86, legacy)

  1. Download: singbox-launcher-v2.3.4-win7-32.zip
  2. Extract the ZIP file to a folder and run singbox-launcher-win7-32.exe
    • For Windows 7 / 32-bit or legacy compatibility only
    • Runs as administrator (UAC prompt on every start), settings stay next to the program (portable.txt); no installer and no daemon service

Linux Support

⚠️ Linux build temporarily unavailable - мы ищем тестировщика для ручного тестирования перед включением автоматической сборки.

Checksums

See checksums.txt for SHA256 checksums of all files.

Release notes — v2.3.4 (2026-09-29)

EN

A patch release after v2.3.3. Core sing-box-lx 1.14.2-lx.11 (was 1.14.2-lx.4), contract 1.1.107 (was 1.1.84).

New: Tailscale, DNS cache, OpenVPN

  • Nodes no longer carry their own routing and DNS entries ("node sections"). A pasted config or node document now yields only the node; its dns/route are not kept, and the JSON tab says so. Existing node sections are dropped on load; a backup that carries them imports with a warning. Tailscale nodes get their tailnet route and MagicDNS from the new template preset "Tailscale networks": it serves every Tailscale node, subscription nodes included, and turns on by itself once for existing users. A node can opt out with "Skip presets" in its form. On the Rules and DNS tabs the preset row lists the nodes it serves, and its DNS servers appear in the DNS server list; the preset's JSON tab shows its entries for each of those nodes, or "No matching nodes." when there are none.
  • Tailscale nodes without exit_node are now visible on the Servers tab: while the core is running, the group list gets a last item NETWORKS with these nodes. This works on the Local panel and on the Remote panel for the connected machine, whose nodes and state come from its own core. In place of the delay each row shows the node state (starting, running, sign-in needed, stopped); a click opens the node window. There is no node choice, delay test, sorting or filter there, and the config does not change.
  • New Network tab in the Tailscale node window (macOS and other daemon setups, and a connected Remote machine): state, network name, Sign in and Log out (with confirmation), this device, exit node and the devices of the network with a Ping check (delay, direct or relay, region). Choosing an exit node switches it at once without touching the node; when the choice differs from the node, a warning says so and Save choice writes exit_node into your own node and rebuilds the config. On a Remote machine the choice goes into that machine's own node and rebuilds its config, as Save in its Configure window does; the config reaches the machine with Deploy config. Subscription nodes have no Save choice. Opened from the Local panel, the tab shows the local core and its commands go there, even while a Remote machine is connected. The former Tailscale section of the Details tab moved here; traffic per device is no longer shown.
  • A Tailscale node that has no working exit node shows "no exit" instead of a delay, and its window says to check devices on the Network tab. The same holds on the Remote panel.
  • A Tailscale node added with an empty Tag field is now named 🕸️ tailscale, as in LxBox. A tag you type is kept as is; existing nodes keep their tags.
  • DNS cache settings on the DNS tab: "DNS cache size" (4000 answers by default, 1024 to 65535), "Serve stale answers" (answer from cache at once and refresh in the background) and "Keep DNS cache after restart". Both switches are on by default, so the first request to a site after a restart no longer waits for DNS through the tunnel.
  • "Clear DNS cache" button on the DNS tab: while the core is running it drops the cached DNS answers, including those kept in cache.db, without restarting the connection. With the core stopped it says the cache can be cleared only while the core is running.
  • OpenVPN endpoints (openvpn-client) written as sing-box JSON are now accepted: as your own node, inside a document with other nodes, or from a subscription. The node goes to endpoints[] exactly as written, with no field checks and no warnings. There is no form and no .ovpn import. On a core built without with_openvpn the node is left out of the config with a warning.

Nodes and subscriptions

  • A node you wrote by hand as sing-box JSON (your own server or a folder member) now goes to the core as written. The app still lists every rule that would normally fix it, marked "the app changed nothing"; only rules whose violation stops the whole config from starting are still applied. Subscription nodes are fixed as before, including the AmneziaWG MTU cap for sing-box JSON subscriptions.
  • Editing the JSON of your own server or a folder member that came from a share link or a WireGuard config now turns it into a hand-written node: the JSON replaces the link, and the app asks before doing so. The JSON tab also accepts an array of nodes and keeps the first one; if there is more, it says the rest is not kept (the same message as for a node document). A node document with several nodes is accepted too: the first node that is not a service outbound or a group is kept, and the tab says the rest is not kept.
  • A subscription often lists one server many times under different names — different countries or even brands with the same address and keys. The app has always kept one node per server; now that node shows a note with the number of repeats and their names, so it is clear that nothing was lost: for example, a subscription of 114 entries that holds only 5 distinct servers.
  • Xray subscriptions with a balancer: each server of the pool is named remarks tag (a repeated name gets the record number), so it no longer shares the group's name. The group now holds only the servers the balancer's selector picks; the others stay as separate nodes.

Template rules

  • A preset rule written without conditions, such as a bare {"action": "sniff"} or a test rule, now goes into the config as written, with a warning in the build summary that it applies to all traffic or all DNS queries. Before, it was left out. A rule that lost its conditions because the preset's rule set it refers to is switched off or a setting it refers to is empty is still left out, so such a rule does not send all traffic to its outbound.
  • A rule whose rule set has not been downloaded yet is now left out of the config, with a warning in the build summary. Before, only the reference to the missing set was removed and the rest of the rule stayed: the "Russian blocked resources" and "Games" presets then sent all TCP and UDP traffic to their outbound, and rules below them, including the final outbound, never matched; a DNS rule of your own with a rule set sent all DNS queries to its server. This happened on first start before the sets were downloaded, after a failed download or a cleared cache, and on a remote machine without the files. A rule that keeps at least one of its rule sets stays with the ones that are available.
  • A preset rule of type logical is now checked part by part. If one of its inner rules lost its conditions because a setting is empty or its rule set is off or not downloaded, the whole rule is left out with a warning; before, an or rule like that sent all traffic to its outbound. A rule set referenced only inside an inner rule now also gets the preset prefix, and a missing .srs there no longer stops the core from starting.

Fixed

  • Domain rules now work for devices that use this machine as a Tailscale exit node (#139). Sniffing and destination resolution used to run only for connections from tun-in and proxy-in, so traffic from exit-node clients reached the core as a bare IP, skipped every domain rule and went to the final outbound. Both steps now run for TCP and UDP from every inbound and endpoint.
  • macOS classic TUN without the service did not start since 2.1.0 (#138, SPEC 151): the start failed with cannot open …/classic.log, or with configure tun interface: Connect: operation not permitted once the file existed. The privileged start shell lost root because its environment is cleared. The shell is now /bin/bash -p and checks that it runs as root before it touches the log; a refusal names both uids, and a refusal to open classic.log carries the system reason.
  • A node window opened from the Local panel now always talks to the local core. Before, if the main window was switched to Remote with a machine connected, its commands (for example the WireGuard Enable/Disable switch) went to that machine. A node window opened from Remote stays with the machine that was selected when it opened; after you switch machines, its commands report that the core is not available and do not reach the other machine.

Core

  • Core sing-box-lx 1.14.2-lx.11 (was 1.14.2-lx.4); the launcher offers to update it. Tailscale nodes pass traffic to peers over a direct UDP path again: before, TCP connections to a peer on the same network timed out after 15 seconds once the direct path was chosen. A Tailscale node now reaches the coordination server over HTTPS on port 443 from the first connection: behind DPI that freezes port 80, it no longer stays out of contact with the coordination server for about 15 minutes after every start. The core is synced with sing-box stable past v1.14.2: idle connections nothing refers to are closed, and the udp_fragment default really allows fragmentation on Linux, incoming protocol data is checked more strictly, the TUN stack no longer writes a zero UDP checksum (some systems dropped such packets), and on macOS a UDP read no longer spins after the peer is gone. Three cases where a masque node hung without an error are fixed: vhttp: auto stuck on h2 until restart, closing an h2 tunnel behind a stalled write, and an h3 endpoint that accepts the connection but never answers. An XHTTP node without an xmux section now keeps at most three connections to the server instead of opening a new one per stream (the current Xray-core default: a burst of parallel connections to one server gets cut on some networks). An xmux section with any field set is taken as written.

Technical / Internal

  • Contracts 1.1.104–1.1.107: group members in the parse result are node labels; Xray pool server labels and pool membership by selector; the rule-without-conditions gate descends into logical sub-rules.
  • Contract 1.1.103: a preset rule that refers to an undeclared variable counts as broken by a failure — a rule without conditions is dropped instead of sending all traffic to an outbound named after the typo.
  • Contract 1.1.102: registry code duplicates_collapsed (info) on the node that repeats of the same server collapsed into, with their count and names (SPEC 154).
  • Security documents: SECURITY.md (how to report a vulnerability) and docs/SECURITY_MODEL.md (what runs with higher rights, rules for privileged code, accepted risks).
  • Contract 1.1.87: registry attribute core_rejects, warning flag applied, bare-body node source (SPEC 146).
  • Contract 1.1.88: an invalid VLESS flow is removed even on a hand-written node (the core refuses to start with it); new corpus section node_edit; a source test keeps build steps that change a node body behind the single decision point.
  • Contract 1.1.89: node document with several nodes in the node JSON tab keeps the first node; import still creates one record per node.
  • Contract 1.1.90: the DNS rule of the "Tailscale networks" preset names the node's DNS server in preferred_by, not the node itself; the old value kept the core from starting.
  • Contract 1.1.91: 29 more registry rules are marked core_rejects (the core refuses to start with such a value), so they are applied to hand-written nodes too: VLESS encryption, Shadowsocks method, WireGuard keys and peer port, REALITY keys, xhttp placements and others.
  • Contract 1.1.97: an invalid REALITY public_key in a hand-written sing-box JSON node removes the whole reality block, as for other nodes; before, only the key was removed and the core refused the config.
  • Contract 1.1.98: the registry names the core default for XHTTP xmux as max_connections 3 (core lx.6); rules unchanged.
  • Contract 1.1.95: the DNS cache size defaults to 4000 answers.
  • Contract 1.1.94: the DNS cache size upper bound is 65535 (a larger value is not saved); eight authored-body corpus cases shared with LxBox are back.
  • Contract 1.1.93: template variables dns_cache_capacity, dns_optimistic, dns_store_cache (SPEC 147); a saved cache size outside 1024..65535 is not written to the config.
  • Contract 1.1.100: the "rule without conditions" gate (TEMPLATE_LANG §5.1) drops a preset rule only when a failure removed its conditions (all rule_set refs dangling, or a variable in the rule gave no value); otherwise the rule is kept with the new warning template_rule_unconditional (SPEC 152).
  • Contract 1.1.101: a route or DNS rule (preset or user) whose rule sets all did not make it into the config — remote .srs not cached — is dropped whole with template_fragment_dropped, whatever other fields it has (SPEC 153).

RU

Патч-релиз после v2.3.3. Ядро sing-box-lx 1.14.2-lx.11 (было 1.14.2-lx.4), контракт 1.1.107 (было 1.1.84).

Новое: Tailscale, кэш DNS, OpenVPN

  • Узел больше не несёт собственных правил маршрутов и DNS («секции узла»). Из вставленного конфига или документа узла берётся только узел; dns/route не сохраняются, вкладка JSON об этом сообщает. Секции существующих узлов снимаются при загрузке; бэкап с ними импортируется с предупреждением. Маршрут в tailnet и MagicDNS узлы Tailscale получают из нового пресета шаблона «Tailscale networks»: он обслуживает каждый узел Tailscale, включая узлы подписки, и у существующих пользователей включается сам, один раз. Узел можно исключить переключателем «Skip presets» в его форме. На вкладках Rules и DNS строка пресета перечисляет обслуживаемые узлы, а его DNS-серверы видны в списке DNS-серверов; вкладка JSON пресета показывает его записи для каждого из этих узлов или «Нет подходящих узлов.», если их нет.
  • Узлы Tailscale без exit_node видны на вкладке Servers: при работающем ядре в списке групп последним пунктом стоит NETWORKS с этими узлами. Так и на панели Local, и на панели Remote у подключённой машины: узлы и их состояние берутся у её ядра. На месте задержки строка показывает состояние узла (starting, running, sign-in needed, stopped), нажатие открывает окно узла. Выбора узла, замера задержки, сортировки и фильтров там нет, конфиг не меняется.
  • Новая вкладка Network в окне узла Tailscale (macOS и другие установки с демоном, а также подключённая машина Remote): состояние, имя сети, Sign in и Log out (с подтверждением), это устройство, exit node и устройства сети с проверкой Ping (задержка, напрямую или через ретранслятор, регион). Выбор exit node переключает выход сразу и узел не меняет; если выбор расходится с узлом, об этом предупреждает знак, а Save choice пишет exit_node в свой узел и пересобирает конфиг. У машины Remote выбор ложится в её собственный узел и пересобирает её конфиг, как Save в её окне Configure; на машину конфиг уходит кнопкой Deploy config. У узлов подписки Save choice нет. Открытая с панели Local вкладка показывает локальное ядро и отдаёт команды ему, даже при подключённой машине Remote. Прежняя секция Tailscale вкладки Details переехала сюда; трафик по устройствам больше не показывается.
  • Узел Tailscale без действующего exit node показывает «нет выхода» вместо задержки, а его окно предлагает проверить устройства на вкладке Network. Так же и на панели Remote.
  • Узел Tailscale, добавленный с пустым полем Tag, теперь называется 🕸️ tailscale, как в LxBox. Введённый тег сохраняется как есть; теги существующих узлов не меняются.
  • Настройки кэша DNS на вкладке DNS: «DNS cache size» (по умолчанию 4000 ответов, от 1024 до 65535), «Serve stale answers» (ответ из кэша сразу, обновление в фоне) и «Keep DNS cache after restart». Оба переключателя включены по умолчанию: первое обращение к сайту после перезапуска больше не ждёт DNS через туннель.
  • Кнопка «Clear DNS cache» на вкладке DNS: при работающем ядре сбрасывает кэшированные ответы DNS, включая сохранённые в cache.db, без перезапуска соединения. При остановленном ядре сообщает, что очистка возможна только при работающем ядре.
  • Узлы OpenVPN (openvpn-client) в виде sing-box JSON теперь принимаются: своей записью, в документе с другими узлами и из подписки. Узел пишется в endpoints[] как написан, без проверок полей и без предупреждений. Формы и импорта .ovpn нет. На ядре без тега with_openvpn узел исключается из конфига с предупреждением.

Узлы и подписки

  • Узел, написанный вручную в форме sing-box JSON (свой сервер или член папки), уходит в ядро как написан. Приложение по-прежнему показывает каждое правило, которое обычно его поправило бы, с пометкой «приложение ничего не изменило»; применяются только правила, нарушение которых не даёт стартовать всему конфигу. Узлы подписок правятся как раньше, включая потолок MTU AmneziaWG у подписок в sing-box JSON.
  • Правка JSON своего сервера или члена папки, пришедшего из ссылки или конфига WireGuard, делает узел написанным вручную: JSON заменяет ссылку, и приложение спрашивает об этом заранее. Вкладка JSON принимает и массив узлов и сохраняет первый; если есть ещё, сообщает, что остальное не сохранено (то же сообщение, что у документа узла). Принимается и документ с несколькими узлами: сохраняется первый узел, который не служебный и не группа, и вкладка сообщает, что остальное не сохранено.
  • Подписка часто перечисляет один сервер много раз под разными именами — разными странами или даже брендами с тем же адресом и ключами. Приложение и раньше оставляло один узел на сервер; теперь на этом узле пометка с числом повторов и их именами, и видно, что ничего не потерялось: например, подписка на 114 записей, в которой всего 5 разных серверов.
  • Подписки Xray с балансировщиком: каждый сервер пула называется remarks tag (повторённое имя получает номер записи) и больше не совпадает по имени с группой. В группу входят только серверы, которые выбирает selector балансировщика; остальные остаются отдельными узлами.

Правила шаблона

  • Правило пресета, написанное без условий, — например, голый {"action": "sniff"} или тестовое правило, — теперь идёт в конфиг как написано, а в итоге сборки появляется предупреждение, что оно действует на весь трафик или на все DNS-запросы. Раньше такое правило выбрасывалось. Правило, которое потеряло условия из-за того, что набор правил пресета, на который оно ссылается, выключен или настройка, на которую оно ссылается, пуста, по-прежнему не включается: такое правило не отправит весь трафик в свой outbound.
  • Правило, набор правил которого ещё не скачан, теперь не включается в конфиг, а в итоге сборки появляется предупреждение. Раньше снималась только ссылка на недостающий набор, а остальное правило оставалось: пресеты «Russian blocked resources» и «Games» тогда отправляли весь TCP и UDP в свой outbound, и правила ниже, включая final, не срабатывали; собственное DNS-правило с набором отправляло все DNS-запросы на свой сервер. Так бывало при первом запуске до скачивания наборов, после сбоя загрузки или очистки кэша и на удалённой машине без файлов. Правило, у которого остался хоть один из его наборов, остаётся с доступными наборами.
  • Правило пресета типа logical теперь проверяется по частям. Если одно из вложенных правил потеряло условия из-за пустой настройки или выключенного либо не скачанного набора правил, всё правило не включается, а в итоге сборки появляется предупреждение; раньше такое правило с or отправляло весь трафик в свой outbound. Набор правил, на который ссылается только вложенное правило, теперь тоже получает префикс пресета, а не скачанный .srs там больше не мешает ядру стартовать.

Исправлено

  • Правила по доменам работают для устройств, которые используют эту машину как exit node Tailscale (#139). Sniff и resolve адреса назначения раньше выполнялись только для соединений из tun-in и proxy-in, поэтому трафик клиентов exit node приходил в ядро голым IP, не попадал ни под одно правило по доменам и уходил в final. Теперь оба шага выполняются для TCP и UDP из любого inbound и endpoint.
  • Classic TUN без службы на macOS не стартовал с версии 2.1.0 (#138, SPEC 151): старт падал с cannot open …/classic.log, а при готовом файле — с configure tun interface: Connect: operation not permitted. Шелл привилегированного старта терял root из-за очищенного окружения. Теперь шелл — /bin/bash -p, до работы с логом он проверяет, что запущен под root; отказ называет оба uid, а отказ открыть classic.log — системную причину.
  • Окно узла, открытое с панели Local, всегда говорит с локальным ядром. Раньше, если главное окно переключали на Remote с подключённой машиной, его команды (например, выключатель Enable/Disable у WireGuard) уходили на эту машину. Окно узла, открытое с Remote, остаётся за машиной, выбранной при открытии; после переключения на другую машину его команды сообщают, что ядро недоступно, и в другую машину не уходят.

Ядро

  • Ядро sing-box-lx 1.14.2-lx.11 (было 1.14.2-lx.4), лаунчер предложит его обновить. Узлы Tailscale снова передают трафик пирам по прямому UDP-пути: раньше TCP-соединения к пиру в той же сети обрывались через 15 секунд, как только выбирался прямой путь. Узел Tailscale ходит к серверу координации по HTTPS на порт 443 с первого соединения: за DPI, который замораживает порт 80, он больше не теряет связь с координатором примерно на 15 минут после каждого старта. Ядро синхронизировано со stable sing-box после v1.14.2: простаивающие соединения, на которые никто не ссылается, закрываются, дефолт udp_fragment действительно разрешает фрагментацию на Linux, входящие данные протоколов проверяются строже, TUN-стек больше не пишет нулевую контрольную сумму UDP (часть систем такие пакеты отбрасывала), а чтение UDP на macOS не крутится вхолостую после ухода пира. Исправлены три случая, когда узел masque зависал без ошибки: vhttp: auto, застрявший на h2 до перезапуска, закрытие h2-туннеля за зависшей записью и h3-эндпоинт, который принял соединение и не ответил. Узел XHTTP без секции xmux теперь держит к серверу не больше трёх соединений, а не открывает новое на каждый поток (текущий дефолт Xray-core: пачку параллельных соединений к одному серверу в некоторых сетях режут). Секция xmux хотя бы с одним заданным полем берётся как есть.

Техническое / Внутреннее

  • Контракты 1.1.104–1.1.107: члены группы в результате разбора — подписи узлов; подписи серверов пула Xray и состав пула по selector; гейт «правило без условий» заходит в под-правила логического правила.
  • Документы по безопасности: SECURITY.md (как сообщить об уязвимости) и docs/SECURITY_MODEL.ru.md (что исполняется с высокими правами, правила для привилегированного кода, принятые риски).
  • Контракт 1.1.87: атрибут реестра core_rejects, признак предупреждения applied, источник узла — голое тело (SPEC 146).
  • Контракт 1.1.88: недопустимый flow VLESS снимается и у узла, написанного вручную (ядро с ним не стартует); новый раздел корпуса node_edit; тест по исходникам держит шаги сборки, меняющие тело узла, за единой точкой решения.
  • Контракт 1.1.89: документ с несколькими узлами во вкладке JSON узла сохраняет первый узел; импорт по-прежнему создаёт запись на каждый узел.
  • Контракт 1.1.90: DNS-правило пресета «Tailscale networks» указывает в preferred_by DNS-сервер узла, а не сам узел; прежнее значение не давало ядру стартовать.
  • Контракт 1.1.91: ещё 29 правил реестра помечены core_rejects (с таким значением ядро не стартует) и применяются и к узлу, написанному вручную: encryption VLESS, method Shadowsocks, ключи и порт пира WireGuard, ключи REALITY, placement-поля xhttp и другие.
  • Контракт 1.1.97: негодный public_key REALITY в узле, написанном вручную в форме sing-box JSON, снимает весь блок reality, как у остальных узлов; раньше снимался только ключ, и ядро отвергало конфиг.
  • Контракт 1.1.98: реестр называет дефолт ядра для XHTTP xmux — max_connections 3 (ядро lx.6); правила не менялись.
  • Контракт 1.1.95: размер кэша DNS по умолчанию 4000 ответов.
  • Контракт 1.1.94: верхняя граница размера кэша DNS 65535 (значение выше не сохраняется); в корпус authored возвращены восемь кейсов сверки с LxBox.
  • Контракт 1.1.93: переменные шаблона dns_cache_capacity, dns_optimistic, dns_store_cache (SPEC 147); сохранённый размер кэша вне 1024..65535 в конфиг не попадает.
  • Контракт 1.1.100: гейт «правило без условий» (TEMPLATE_LANG §5.1) снимает правило пресета, только если условия убрал сбой (все ссылки rule_set висячие или переменная в правиле не дала значения); иначе правило остаётся с новым предупреждением template_rule_unconditional (SPEC 152).
  • Контракт 1.1.101: правило маршрута или DNS-правило (пресета или пользовательское), все наборы которого не попали в конфиг — remote .srs не скачан, — выпадает целиком с template_fragment_dropped, какие бы поля в нём ни остались (SPEC 153).

Don't miss a new singbox-launcher release

NewReleases is sending notifications on new releases.