github Leadaxe/singbox-launcher v2.3.6
release v2.3.6

5 hours ago

Release v2.3.6

Downloads

macOS (Universal) - Supports both Apple Silicon and Intel

Option 1: Installation Script (Recommended)

Install with a single command (version v2.3.6):

curl -fsSL https://raw.githubusercontent.com/Leadaxe/singbox-launcher/develop/scripts/install-macos.sh | bash -s -- v2.3.6

The script will:

  • Download the release archive
  • Extract and install to /Applications/
  • Fix macOS quarantine attributes and permissions
  • Launch the application automatically

Option 2: Manual Installation

  1. Download: singbox-launcher-v2.3.6-macos.zip
  2. Extract the ZIP file
  3. Remove quarantine attribute (required):
    xattr -cr "singbox-launcher.app" && chmod +x "singbox-launcher.app/Contents/MacOS/singbox-launcher"
  4. Double-click singbox-launcher.app to run
    • If macOS blocks the app, go to System Settings → Privacy & Security and click "Open Anyway"
    • Alternatively, right-click the app and select "Open" (first time only)

Windows (amd64)

Option 1: Installer (Recommended)

  1. Download: singbox-launcher-v2.3.6-win64-setup.exe
  2. Run it and confirm the administrator prompt once. The launcher goes to C:\Program Files\singbox-launcher, your data to %LOCALAPPDATA%\singbox-launcher; sing-box.exe, wintun.dll, the config template and Mesa3D are included, nothing is downloaded on first launch
    • Tasks: desktop shortcut, Start with Windows, software OpenGL (Mesa3D) for RDP / VMs without a GPU
    • Installing over a previous version keeps your data; uninstall from Settings → Apps asks whether to remove the data too
    • The installer is not code-signed yet: if SmartScreen shows "Windows protected your PC", click More info → Run anyway

Option 2: Portable ZIP

  1. Download: singbox-launcher-v2.3.6-win64.zip
    • or singbox-launcher-v2.3.6-win64-full.zip — full bundle: sing-box.exe, wintun.dll, the config template and Mesa3D (mesa3d/, used only when no hardware OpenGL — RDP, VMs) are already inside, nothing is downloaded on first launch
  2. Extract the ZIP file to a folder your account can write to, for example D:\Tools\singbox-launcher\ — settings stay next to the program (portable.txt)
    • Under C:\Program Files\ the launcher keeps its data in %LOCALAPPDATA%\singbox-launcher instead
  3. Run singbox-launcher.exe from that folder — no administrator rights, no UAC prompt
    • TUN needs administrator rights: Start offers Restart as administrator or Switch to proxy mode
    • The regular archive downloads sing-box and wintun.dll on first launch

Windows 7 (x86, legacy)

  1. Download: singbox-launcher-v2.3.6-win7-32.zip
  2. Extract the ZIP file to a folder and run singbox-launcher-win7-32.exe
    • For Windows 7 / 32-bit or legacy compatibility only
    • Runs as administrator (UAC prompt on every start), settings stay next to the program (portable.txt); no installer and no daemon service

Linux Support

⚠️ Linux build temporarily unavailable - мы ищем тестировщика для ручного тестирования перед включением автоматической сборки.

Checksums

See checksums.txt for SHA256 checksums of all files.

Release notes — v2.3.6 (2026-10-08)

EN

A patch release after v2.3.5. Core sing-box-lx 1.14.2-lx.12 (was 1.14.2-lx.11), contract 1.1.114 (was 1.1.108).

Tailscale

  • The Network tab shows how each device is reached — direct 1.2.3.4:41641, peer relay or relay fra (DERP region), from the last core status event. Each device takes two lines: who it is on top (● GL-MT2500 100.104.79.7 linux · exit node ⋯), how it is reached below (direct 31.184.97.44:41641, relay ams, or last seen 6d ago · key expired); the MagicDNS name is in the ⋯ menu.
  • Server list: a Tailscale node's subtitle shows its tailnet role and the path to the exit — tailscale ‣ gl-mt2500 · direct 31.184.97.44:41641 (exit node in use: live core status, or the configured exit_node before start), tailscale·exit node (this node advertises itself as an exit), plain tailscale otherwise.
  • The path to a tailnet peer is marked 📶 for direct and ☁ for relay (DERP or peer relay) on the Network tab, in the Tailnet section and in the server list subtitle.
  • The node window's Diagnostics tab has a live "Tailnet" section polled every 3 s while the window is open: core health warnings (no DERP connection, exit node offline…), the exit node with its path and handshake age, and every other device with a chosen path; the exit is not repeated among the devices, devices without traffic are counted in one line. Needs core GetTailscaleStatus (SPEC 115, in 1.14.2-lx.12); an older core shows the Network tab as before and one line on Diagnostics.
  • The node window's Settings tab has a "Tailscale" block — advertise this node as an exit node, pick the exit node to use, keep the local network reachable. The two roles exclude each other, as in the Add server form; changes land in the node body at once and are saved with the window.

WireGuard / AWG

  • Node window (daemon mode and remote machines): the WireGuard section lists the peers, one line each — ● 31.184.97.44:48213 · 36s · ↓361.7 KB ↑14.2 KB with the shortened key on the right and a ⋯ menu to copy the address or the full key. ● = online (a handshake within 3 minutes, or bytes still coming in), ○ = no session (14m ago) or no handshake yet. On a server node it shows which clients are connected and from where. Needs core GetWireGuardStatus (SPEC 114, in 1.14.2-lx.12); an older core shows the state without peers.
  • WireGuard server nodes (peers connect to you: listen_port set, no peer address/port) no longer show "Required field peers[0].address / peers[0].port is missing"; they get an info note "Waits for an incoming connection" instead. A peer with no address on a node with no listen_port is still an error: nobody can start the handshake — a subscription node is dropped, a hand-written one is kept with the error (contract 1.1.109/1.1.110).

Node window

  • Redesign: field rows have no input boxes — the key in grey, the value as plain selectable text; type, section, transport and security share one line (wireguard · endpoint · awg2+). The WireGuard section is one line WireGuard ● up · idle 10s [Disable] (the "until the core restarts" note moved to the button tooltip). The Network tab of a Tailscale node follows suit: status with Log out in one line, This device as plain rows, Exit node with its picker in one line.
  • New Diagnostics tab, as in LxBox — a GET through this node to a fixed endpoint (Cloudflare trace, Cloudflare trace (hostname), IP & location, IP info), with the status, time and raw body. The chain probe by position moved here from Details. A red or yellow dot on the tab marks node errors or warnings. Works in daemon mode and on remote machines (core GetURLViaOutbound); classic mode says so in one line.
  • Origin field: JSON pasted into a node's Origin is now stored as a JSON origin, and Regen rebuilds the node from it. Before, it was recorded as a link and Regen failed with "not a link: no scheme".

Auto-select groups

  • A third mode "hold until it fails" (core mode: failover, sing-box-lx SPEC 116) next to "fastest node" and "spread across a pool", on the Direction's Auto-select tab and on the Group tab of a folded subscription. The group picks the fastest node at the moment of choice and keeps it until it fails; only that node is probed each interval, the others sleep and their latency figures in the list go stale. A manual group test re-probes everyone and re-picks the fastest. Tolerance does not apply in this mode, so its field is hidden and the key is not written. Server list subtitle shows 📌 held, the Info window shows the mode. Needs core 1.14.2-lx.12; an older core rejects the config.

Wizard

  • Final tab: a node that dials through a Direction (or a folder group) by its detour is not taken into that group — otherwise the core rejects the whole config as a dependency loop. Until now this was only a line in the log, and in the wizard it looked like the Direction filter did not work (Liberty subscription with detour "Jump server" and the filter (🔥|🗽) on "Jump server" itself). The build report now says so: one line per source and group, with the node count and the first tags, and the source row gets the usual warning mark (contract 1.1.113, code node_detour_through_group).
  • Final tab: the warnings panel takes all the height left between the hint and the buttons (it used to be a fixed four-line box) and sits on its own framed background. Each warning has two icons on the right instead of the "Show source" text button: ⓘ opens a details card — what happened, why it happens and what you can do, from the registry by the warning code, with "Show source" and "Copy" at the bottom — and a copy icon puts the line on the clipboard.
  • A selector group whose default was dropped (the default node is gone from the group) is reported in the build report with the code group_default_dropped and the group and default tags, instead of plain text (contract 1.1.112).

JSON editor

  • JSON fields now use a real JSON editor: syntax highlighting, line numbers, folding, search (Ctrl/Cmd+F), mouse selection and copy. Covered: node info "Outbound JSON", Add server "JSON", outbound editor "JSON", source window "JSON" (read-only for subscriptions and folders), DNS server and DNS rule dialogs, the raw-JSON mode of the DNS rules list, the routing rule editor (JSON tab and Custom JSON), the bundled DNS preset body, the preset reference preview, the source Overview storage record and the Generated config.json window. Windows 7 builds keep the plain text field.

Fixed

  • No more error popups after wake from sleep: the background Clash API / daemon check (after resume, on tab switch) used to open an error dialog every time, and with the app in the tray they piled up one on top of another. Such errors now go to an error journal — Diagnostics → Errors (N) (newest first, repeats folded as ×N, Copy all, Clear); a red line under the node list (❌ Clash API: no connection ×3 · 03:12 ›, in daemon mode gRPC / Daemon) opens the journal filtered to that topic (All / Clash API only / gRPC and daemon only) and hides once a check succeeds.
  • macOS: subscription fetch (and any other request through the launcher's shared HTTP transport) could fail with malformed HTTP response "\x00\x00\x12\x04…" after some unrelated HTTPS request had been made through a bare http.Client (SRS download, locale, Get Free dialog…). Root cause: the Big Sur root-CA patch handed the same tls.Config to both the shared transport and the http.DefaultTransport clone; the latter enables HTTP/2 and appends h2 to the shared ALPN list in place, so the HTTP/1.1-only shared transport then received HTTP/2 frames. Each transport now has its own config.
  • The wizard window shrinks in height again: the tabs' scroll areas kept the minimum height they had when the window was created.
  • Error mark is now a red ❌ everywhere (server list subtitle, tooltip, Notifications section of the node window); the former ✖ is drawn grey by the emoji font bundled with Fyne, so it did not read as an error.

Core

  • Pinned sing-box-lx 1.14.2-lx.12 (was 1.14.2-lx.11): GetWireGuardStatus (SPEC 114), GetTailscaleStatus (SPEC 115), urltest mode: failover (SPEC 116), upstream sync with the scoped lifecycle (SPEC 117). "Download / Reinstall" on the Core Dashboard installs it.

Technical / Internal

  • New dependency github.com/ideaconnect/go-fyne-pretty-view/v2 behind internal/fynewidget.JSONEditor / JSONView; the file using it carries a go1.26 build constraint, so the Win7 toolchain compiles the Entry-based fallback. go.mod now says go 1.26.0 and replaces pretty-view with the fork Leadaxe@e7b5a0d (Shift+←/→, word jumps) until ideaconnect/go-fyne-pretty-view#131 is merged. CI's go get -modfile=go.win7.mod ./... resolves imports regardless of build tags, so go.win7.mod replaces the module with an empty stub (build/win7stub/go-fyne-pretty-view) — otherwise it would lift fyne to v2.8 and golang.org/x/net past Go 1.20.
  • One rule for the origin kind by text form (subscription.OriginKindOfText): the Origin field, the legacy backup reader (uri carrying JSON) and the single materialization point (materializeServerForMigration) all classify JSON as json; a node document or a body array in the Origin field is reduced to the first body. State load heals a node whose origin is stored as uri but carries JSON: the kind becomes json and the file is re-saved.
  • Contract 1.1.109–1.1.113: optional peer address/port for incoming WireGuard peers, required_unless (conditional required field), auto.mode: failover in direction.schema.json / backup.schema.json / registry group.json with corpus direction/auto_failover_mode (buildTwin emits mode: failover without balancer and drops tolerance; the core's passive_check flag was removed by SPEC 116 and is not supported), build-report codes group_default_dropped and node_detour_through_group.
  • Hand-written AmneziaWG node with MTU above 1280: the MTU notice is no longer marked "not applied" — nothing in the body was to be changed. Raw and cleaned body values are now compared as JSON numbers by value (contract 1.1.114).
  • internal/daemonpb synced to the core tag v1.14.2-lx.12 (stubs unchanged since rc.2).
  • /debug/ui gains a tree of minimum sizes (who holds the window's minimum); unused locale keys removed from ru.json.

RU

Патч-релиз после v2.3.5. Ядро sing-box-lx 1.14.2-lx.12 (было 1.14.2-lx.11), контракт 1.1.114 (было 1.1.108).

Tailscale

  • Вкладка Network показывает, как достижимо каждое устройство — direct 1.2.3.4:41641, peer relay или relay fra (регион DERP), по последнему событию статуса ядра. Устройство занимает две строки: сверху кто это (● GL-MT2500 100.104.79.7 linux · exit node ⋯), снизу как подключено (direct 31.184.97.44:41641, relay ams или last seen 6d ago · key expired); имя MagicDNS — в меню ⋯.
  • Список серверов: подзаголовок узла Tailscale показывает роль в tailnet и путь до выхода — tailscale ‣ gl-mt2500 · direct 31.184.97.44:41641 (через какой выход идёт трафик: живой статус ядра, до запуска — exit_node из конфига), tailscale·выход (узел сам анонсируется выходом), просто tailscale без выхода.
  • Путь до пира tailnet помечен 📶 при прямом соединении и ☁ через relay (DERP или peer relay) — на вкладке Network, в секции Tailnet и в подзаголовке узла в списке серверов.
  • На вкладке Diagnostics окна узла — живая секция «Tailnet», опрашиваемая раз в 3 с, пока окно открыто: предупреждения ядра (нет связи с DERP, exit node offline…), выходной узел с путём и возрастом хендшейка и остальные устройства с выбранным путём; выход среди устройств не повторяется, устройства без трафика — одной строкой счётчиком. Нужен GetTailscaleStatus ядра (SPEC 115, в 1.14.2-lx.12); со старым ядром Network как прежде, на Diagnostics — одна строка.
  • На вкладке Settings окна узла — блок «Tailscale»: анонс узла как выхода, выбор выходного узла и доступ к локальной сети. Роли взаимоисключающие, как в форме добавления; правка сразу попадает в тело узла и сохраняется вместе с окном.

WireGuard / AWG

  • Окно узла (режим демона и удалённые машины): в секции WireGuard появились пиры, по строке на пира — ● 31.184.97.44:48213 · 36s · ↓361.7 KB ↑14.2 KB, справа ключ с вырезанной серединой и меню ⋯ для копирования адреса или полного ключа. ● — на связи (хендшейк не старше 3 минут или идут байты), ○ — нет сессии (14m ago) или хендшейка ещё не было. На серверном узле видно, какие клиенты подключены и откуда. Нужен GetWireGuardStatus ядра (SPEC 114, в 1.14.2-lx.12); со старым ядром — состояние без пиров.
  • Серверный узел WireGuard (к нему подключаются: задан listen_port, у пира нет адреса и порта) больше не показывает «Required field peers[0].address / peers[0].port is missing» — вместо этого пояснение уровня info «Ждёт входящего подключения». Пир без адреса у узла без listen_port — по-прежнему ошибка: рукопожатие не начнёт никто; узел подписки отбрасывается, введённый руками остаётся с ошибкой (контракт 1.1.109/1.1.110).

Окно узла

  • Переделан вид: строки полей без рамок — ключ серым, значение обычным выделяемым текстом; тип, секция, транспорт и защита одной строкой (wireguard · endpoint · awg2+). Секция WireGuard — одна строка WireGuard ● up · idle 10s [Disable] (подсказка «до рестарта ядра» ушла в тултип кнопки). Так же переделана вкладка Network узла Tailscale: статус с Log out в одной строке, This device простыми строками, Exit node с выбором в одной строке.
  • Новая вкладка Diagnostics, как в LxBox — GET через этот узел на заранее заданный адрес (Cloudflare trace, Cloudflare trace (hostname), IP & location, IP info): статус, время и сырое тело ответа. Сюда же переехал замер цепочки по позициям из Details. Красная или жёлтая точка на ярлыке вкладки — ошибки или предупреждения узла. Работает в режиме демона и на удалённых машинах (GetURLViaOutbound ядра); в classic вкладка говорит об этом одной строкой.
  • Поле Origin: вставленный в происхождение узла JSON хранится как JSON-происхождение, и Regen пересобирает из него узел. Раньше он записывался как ссылка, и Regen падал с «not a link: no scheme».

Автогруппы

  • Третий режим «держаться до отказа» (mode: failover ядра, sing-box-lx SPEC 116) рядом с «самый быстрый узел» и «распределять по пулу» — на вкладке «Автовыбор» Направления и на вкладке «Группа» свёрнутой подписки. Группа выбирает самый быстрый узел на момент выбора и держится за него до отказа; каждый интервал пробуется только он, остальные спят, и их цифры задержки в списке стареют. Ручной тест группы пробует всех и перевыбирает самого быстрого. Допуск (tolerance) в режиме не действует: поле прячется, ключ не пишется. Подзаголовок в списке серверов — 📌 удержание, окно Info показывает режим. Нужно ядро 1.14.2-lx.12; старое ядро конфиг отвергнет.

Мастер

  • Вкладка «Итог»: узел, который своим detour ходит через Направление (или группу свёртки папки), в эту группу не берётся — иначе ядро отвергло бы весь конфиг как кольцо зависимостей. До сих пор это было только строкой в логе, а в Мастере выглядело как неработающий фильтр Направления (подписка Liberty с detour «Jump server» и фильтр (🔥|🗽) у самого «Jump server»). Теперь отчёт сборки говорит об этом: одна строка на источник и группу, с числом узлов и первыми тегами, а строка источника получает обычную пометку предупреждения (контракт 1.1.113, код node_detour_through_group).
  • Вкладка «Итог»: панель предупреждений занимает всю высоту между подсказкой и кнопками (раньше — фиксированный блок в четыре строки) и стоит на своей подложке с рамкой. У каждого предупреждения справа два значка вместо текстовой кнопки «Show source»: ⓘ открывает карточку подробностей — что случилось, почему так бывает и что можно сделать, из реестра по коду предупреждения, с кнопками «Show source» и «Copy» внизу, — а значок копирования кладёт строку в буфер.
  • Снятое умолчание selector-группы (узел по умолчанию выпал из группы) попадает в отчёт сборки с кодом group_default_dropped и тегами группы и умолчания, а не голым текстом (контракт 1.1.112).

JSON-редактор

  • JSON-поля переведены на настоящий JSON-редактор: подсветка синтаксиса, номера строк, свёртка, поиск (Ctrl/Cmd+F), выделение мышью и копирование. Охвачены: «Outbound JSON» в сведениях узла, «JSON» в добавлении сервера, в редакторе outbound и в окне источника (у подписки и папки — только просмотр), окна DNS-сервера и DNS-правила, raw-JSON режим списка DNS-правил, редактор правила маршрутизации (вкладка JSON и Custom JSON), тело встроенного DNS-пресета, превью ссылки на пресет, запись хранилища в обзоре источника и окно Generated config.json. Сборки для Windows 7 остаются с обычным текстовым полем.

Исправлено

  • После пробуждения из сна больше нет стопки окон «Ошибка»: фоновая проверка Clash API / демона (после сна, при смене вкладки) открывала диалог на каждый заход, и при работе из трея они копились одно на другом. Теперь такие ошибки пишутся в журнал — Диагностика → Ошибки (N) (новые сверху, повторы свёрнуты в ×N, «Копировать всё», «Очистить»); красная строка под списком узлов (❌ Clash API: нет связи ×3 · 03:12 ›, в режиме демона — gRPC / Демон) открывает журнал с фильтром по этой теме (Все / Только Clash API / Только gRPC и демон) и прячется после успешной проверки.
  • macOS: загрузка подписки (и любой другой запрос через общий HTTP-транспорт лаунчера) могла падать с malformed HTTP response "\x00\x00\x12\x04…" после того, как какой-нибудь посторонний HTTPS-запрос ушёл через голый http.Client (скачивание SRS, локаль, диалог Get Free…). Причина: патч корневых сертификатов для Big Sur отдавал один и тот же tls.Config общему транспорту и клону http.DefaultTransport; тот включает HTTP/2 и дописывает h2 в общий список ALPN на месте, и транспорт, умеющий только HTTP/1.1, получал кадры HTTP/2. Теперь у каждого транспорта свой конфиг.
  • Окно Мастера снова сжимается по высоте: прокрутки вкладок держали минимальную высоту, которая была у окна на момент создания.
  • Знак ошибки теперь везде красный ❌ (подстрока в списке серверов, тултип, раздел «Уведомления» окна узла): прежний ✖ встроенный в Fyne эмодзи-шрифт рисует серым, и ошибкой он не читался.

Ядро

  • Пин sing-box-lx 1.14.2-lx.12 (было 1.14.2-lx.11): GetWireGuardStatus (SPEC 114), GetTailscaleStatus (SPEC 115), режим urltest failover (SPEC 116), синхронизация с upstream и scoped lifecycle (SPEC 117). Ставится кнопкой «Download / Reinstall» в Core Dashboard.

Техническое / Внутреннее

  • Новая зависимость github.com/ideaconnect/go-fyne-pretty-view/v2 за интерфейсами internal/fynewidget.JSONEditor / JSONView; файл с ней помечен ограничением сборки go1.26, поэтому тулчейн Win7 собирает запасной вариант на Entry. В go.mod теперь go 1.26.0 и replace pretty-view на форк Leadaxe@e7b5a0d (Shift+←/→, переход по словам) до слияния ideaconnect/go-fyne-pretty-view#131. Шаг CI go get -modfile=go.win7.mod ./... резолвит импорты независимо от build-тегов, поэтому go.win7.mod подменяет модуль пустой заглушкой (build/win7stub/go-fyne-pretty-view) — иначе он поднял бы fyne до v2.8 и golang.org/x/net за пределы Go 1.20.
  • Одно правило вида происхождения по форме текста (subscription.OriginKindOfText): поле Origin, чтение legacy-бэкапа (JSON в uri) и единая точка материализации (materializeServerForMigration) считают JSON видом json; документ узла и массив тел в поле Origin сводятся к первому телу. Загрузка состояния лечит узел, у которого происхождение записано видом uri, а внутри JSON: вид становится json, файл пересохраняется.
  • Контракт 1.1.109–1.1.113: необязательные адрес и порт входящего пира WireGuard, required_unless (условная обязательность поля), auto.mode: failover в direction.schema.json / backup.schema.json / реестре group.json с корпусом direction/auto_failover_mode (buildTwin эмитит mode: failover без balancer и снимает tolerance; флаг passive_check ядра удалён тем же SPEC 116 и не поддерживается), коды отчёта сборки group_default_dropped и node_detour_through_group.
  • Узел AmneziaWG, написанный руками, с MTU выше 1280: уведомление о MTU больше не помечается «не применено» — в теле нечего было менять. Значения сырого и чистого тела теперь сравниваются как числа JSON, по величине (контракт 1.1.114).
  • internal/daemonpb синхронизирован с тегом ядра v1.14.2-lx.12 (стабы не менялись с rc.2).
  • В /debug/ui добавлено дерево минимальных размеров (кто держит минимум окна); из ru.json сняты неиспользуемые ключи локали.

Don't miss a new singbox-launcher release

NewReleases is sending notifications on new releases.