What's Changed
- Xray-core v26.10.10
- Finalmask: xDNS domain name lists and resolver addresses (Xray-core v26.10.10)
- Outbound TLS:
useSystemCAswitch - MASQUE outbound: Cloudflare WARP settings
- WARP: MASQUE tunnel option next to WireGuard
- Lua script for DNS and routing, DNS server id
- limit xray version to minimum v26.10.10
- update dependencies
Upgrade note: This version needs Xray-core v26.10.10 or later, and older cores are no longer offered in the panel. Saved xDNS masks on inbounds and outbounds are migrated automatically on first start to the new schema (a list of
namesper domain, resolvers asudp://ortcp://addresses). Without that, the new core ignores the old keys and xDNS runs with no domain or resolver. Xray-core now trusts its own built-in root CAs instead of the operating system's: outbounds to servers signed by a private CA need the new Use System CA switch in their TLS settings. Switching WARP between WireGuard and MASQUE enrolls a new key with Cloudflare, so the outbound of the other tunnel stops working until you reset the WARP outbound. Back up/etc/x-ui/x-ui.dbfirst if you may want to roll back.