github deposist/s-ui-x v1.5.6-beta8
s-ui v1.5.6-beta8

latest releases: v1.5.10-beta7, v1.5.10-beta6, v1.5.10-beta5...
pre-releaseone month ago

Release Notes: v1.5.6-beta8

Release date: 2026-06-03

Extends the built-in 3x-ui migration (migrate-xui) to proxy outbounds, many
more routing matchers, non-reality TLS certificates and the DNS block.
Follow-up to v1.5.6-beta7. No schema migrations; existing data is preserved.

What changed

  • Proxy outbounds now migrate as s-ui outbounds — previously only WARP
    (WireGuard), freedom and blackhole outbounds were handled; an Xray
    outbounds entry of type vmess, vless, trojan, shadowsocks, socks
    or http was dropped silently, so a chained/proxy outbound disappeared from
    the migrated panel. Each such outbound is now converted to a first-class s-ui
    (sing-box) outbound: server/port, credentials (uuid/password/method/
    user-pass), VLESS flow, the TLS/Reality block (peer public key, short id,
    SNI, uTLS fingerprint) and the transport (ws/grpc/http/httpupgrade)
    are translated from the Xray settings/streamSettings shape. The outbound
    is also registered as a routing target, so a rule that referenced it now
    resolves to the migrated outbound instead of being flagged "requires manual
    review".
  • System outbounds map to their sing-box homefreedomdirect and
    blackholeblock (as before), and a dns outbound now becomes a
    hijack-dns route action (sing-box has no dns outbound). loopback and any
    protocol Xray does not emit (e.g. hysteria) are surfaced as a warning to
    recreate manually rather than dropped silently.
  • No silent loss when routing import is off — proxy/WARP outbounds live in
    the source xrayConfig, which is only read during routing import. When
    routing import is disabled but the source contains outbounds, the plan now
    shows a warning that they were not migrated and how to migrate them, instead
    of omitting them with no trace.
  • Outbounds are created only when new — a re-import or scheduled sync does not
    clobber an operator-edited outbound of the same tag. The import report gains
    an outbounds counter (imported/skipped).
  • Migrated routing and DNS now apply to the live config — they are merged
    into the active sing-box config setting (route rules/rule sets, DNS
    servers/rules), preserving existing rules and de-duplicating rule sets/servers
    by tag. Previously the import wrote them to a separate setting the panel never
    loaded, so imported routing had no effect; it does now.
  • More routing matchers map instead of "manual review"port/sourcePort
    (including ranges), network, protocol, source, inboundTag (→inbound),
    user (→auth_user), and non-geosite domains
    (domain:/full:/keyword:/regexp:/bare → domain_suffix/domain/
    domain_keyword/domain_regex). geosite:/geoip: matches become remote
    rule_sets (MetaCubeX meta-rules-dat), since sing-box 1.12 removed the inline
    geoip/geosite route fields; a source geoip uses
    rule_set_ip_cidr_match_source. attrs and balancerTag still require manual
    review, since sing-box has no equivalent.
  • The Xray dns block is translated to sing-box's format — typed servers
    (udp/tls/https/h3/quic/tcp/local), domain-scoped servers become
    DNS rules, plus final, query strategy and client_subnet. Previously the
    block was copied verbatim, which produced an invalid sing-box DNS config.
    hosts/fakedns and out-of-range ports are flagged.
  • Non-reality TLS certificates migrate — an inbound whose tlsSettings carry
    an inline certificate/key gets a real s-ui TLS record (server certificate +
    client block). A certificate referenced only by a file path is flagged for
    manual upload, because the importer reads only the database, not the source
    host's disk.
  • Smaller fidelity fixes — the WebSocket transport now carries every request
    header (not just Host); packet_encoding (xudp) is set when the source
    used it; a multi-server outbound becomes per-server members plus a urltest
    group; and Xray mux is reported rather than enabled, because sing-box
    multiplex is not wire-compatible with Xray mux.
  • Web admin keeps unsaved edits during the background refresh — the Basics,
    DNS and Routing pages edited the live store config object directly, so the
    10-second background config poll (and WS config_invalidated/reload events)
    ran setNewData(), which replaces that object wholesale and silently reverted
    any in-progress edit. These pages now edit a local clone of the config (the
    same isolation Settings already used) and keep your edits until you press Save.
  • Routing import can no longer produce a config sing-box refuses to load — an
    Xray external geoip reference (ext:<file>:<code>, e.g. ext:geoip_RU.dat:ru)
    and bare IPs were written into ip_cidr verbatim. sing-box parses ip_cidr
    with netip.ParsePrefix, which rejects a value without a mask
    (ipcidr: parse: no '/'), so the migrated config failed to start the core in a
    restart loop. ext: is now mapped to a geoip rule set by its trailing code (a
    custom file is approximated by the standard geoip-<code> set — verify it), a
    bare IP gets a /32//128 host mask, and anything that is neither a geoip code
    nor a valid IP/CIDR is dropped with a warning instead of breaking the config.
  • Migrated DNS no longer stops the core from starting — a DNS server reached
    over a domain (https://dns.google/..., tls://...) was emitted without a
    domain_resolver. sing-box 1.13 builds DNS-server dialers with
    DirectResolver: true, so a domain-addressed server with no per-server
    domain_resolver fails immediately (missing domain resolver for domain server address) — a global default_domain_resolver does not cover it. The
    migration now sets a per-server domain_resolver (a DNS server tag) on every
    domain-addressed server, reusing an IP-addressed server from the migration as
    the bootstrap (or appending a local one), exactly as s-ui's own DNS editor does
    via its Dial control. TLS/HTTP servers also get the tls/headers blocks so a
    migrated server is identical to a natively-created one.
  • A Trojan inbound no longer crashes the core (not migration-specific) — the
    inbound editor wrote a top-level password for Trojan inbounds, but sing-box's
    Trojan inbound has no such field (it authenticates per user via users) and
    rejects the whole config with unknown field "password". The password field is
    now shown only for Trojan outbounds (where it is valid), and the config
    builder drops any leftover top-level password from a Trojan inbound, so
    existing inbounds recover on the next core reload without an edit.

Upgrade

No manual migration; existing data is preserved. Re-run the migration with
routing import enabled (the wizard enables it by default) to bring over proxy
outbounds, routing rules and the DNS block; review anything the report flags as
needing manual recreation (file-path TLS certificates, attrs/balancer rules,
loopback/mux).


Примечания к релизу: v1.5.6-beta8

Дата релиза: 2026-06-03

Расширяет встроенную миграцию 3x-ui (migrate-xui) на прокси-аутбаунды, гораздо
большее число матчеров маршрутизации, не-reality TLS-сертификаты и блок DNS.
Продолжение v1.5.6-beta7. Без миграций схемы; существующие данные сохраняются.

Что изменилось

  • Прокси-аутбаунды теперь мигрируют как аутбаунды s-ui — раньше
    обрабатывались только WARP (WireGuard), freedom и blackhole, а запись
    outbounds Xray типа vmess, vless, trojan, shadowsocks, socks или
    http молча отбрасывалась, поэтому цепочечный/прокси-аутбаунд пропадал из
    перенесённой панели. Теперь каждый такой аутбаунд превращается в полноценный
    аутбаунд s-ui (sing-box): сервер/порт, учётные данные (uuid/password/
    method/логин-пароль), flow для VLESS, блок TLS/Reality (публичный ключ
    пира, short id, SNI, отпечаток uTLS) и транспорт (ws/grpc/http/
    httpupgrade) переводятся из формата Xray settings/streamSettings.
    Аутбаунд также регистрируется как цель маршрутизации, поэтому правило,
    ссылавшееся на него, теперь резолвится в перенесённый аутбаунд вместо пометки
    «требует ручной проверки».
  • Системные аутбаунды сопоставляются со своим аналогом в sing-box
    freedomdirect и blackholeblock (как и раньше), а аутбаунд dns
    теперь превращается в действие маршрута hijack-dns (в sing-box нет
    аутбаунда dns). loopback и любой протокол, которого нет в Xray (например,
    hysteria), выводятся как предупреждение для ручного пересоздания, а не
    отбрасываются молча.
  • Никакой тихой потери при выключенном импорте роутинга — прокси/WARP
    аутбаунды лежат в исходном xrayConfig, который читается только при импорте
    роутинга. Если импорт роутинга выключен, но в источнике есть аутбаунды, план
    теперь показывает предупреждение, что они не перенесены и как их перенести,
    вместо того чтобы опустить их без следа.
  • Аутбаунды создаются только если они новые — повторный импорт или
    запланированная синхронизация не затирают отредактированный оператором
    аутбаунд с тем же тегом. В отчёте об импорте появляется счётчик outbounds
    (импортировано/пропущено).
  • Миграция маршрутизации и DNS теперь применяется к живому конфигу — они
    мерджатся в активную настройку config sing-box (route-правила/rule-set,
    DNS-серверы/правила) с сохранением существующих правил и дедупликацией по тегу.
    Раньше импорт писал их в отдельную настройку, которую панель не загружала,
    поэтому маршрутизация не действовала; теперь действует.
  • Больше матчеров маршрутизации переносится, а не уходит в «ручную проверку»
    port/sourcePort (включая диапазоны), network, protocol, source,
    inboundTag (→inbound), user (→auth_user) и не-geosite домены
    (domain:/full:/keyword:/regexp:/без префикса → domain_suffix/domain/
    domain_keyword/domain_regex). Матчеры geosite:/geoip: становятся remote
    rule_set (MetaCubeX meta-rules-dat), так как sing-box 1.12 удалил инлайновые
    поля geoip/geosite; для source geoip ставится
    rule_set_ip_cidr_match_source. attrs и balancerTag по-прежнему требуют
    ручной проверки — в sing-box нет аналога.
  • Блок dns из Xray переводится в формат sing-box — типизированные серверы
    (udp/tls/https/h3/quic/tcp/local), серверы с привязкой к доменам
    становятся dns-правилами, плюс final, стратегия запросов и client_subnet.
    Раньше блок копировался «как есть», что давало невалидный DNS-конфиг sing-box.
    hosts/fakedns и порты вне диапазона отмечаются.
  • Не-reality TLS-сертификаты мигрируют — инбаунд, у которого в tlsSettings
    лежит inline-сертификат/ключ, получает настоящую TLS-запись s-ui (серверный
    сертификат + клиентский блок). Сертификат, заданный только путём к файлу,
    отмечается для ручной загрузки, так как импортёр читает лишь базу, а не диск
    исходного хоста.
  • Мелкие улучшения точности — WebSocket-транспорт переносит все заголовки
    запроса (не только Host); packet_encoding (xudp) выставляется, если
    источник его использовал; аутбаунд с несколькими серверами превращается в
    членов по-серверно плюс группу urltest; Xray mux сообщается, а не
    включается, так как мультиплекс sing-box несовместим по протоколу с Xray mux.
  • Веб-админка сохраняет несохранённые правки при фоновом обновлении
    страницы Basics, DNS и Routing редактировали живой объект конфига из стора
    напрямую, поэтому 10-секундный фоновый опрос конфига (и события WS
    config_invalidated/reload) вызывали setNewData(), который заменяет этот
    объект целиком и молча откатывал любую правку в процессе. Теперь эти страницы
    редактируют локальную копию конфига (та же изоляция, что уже была в Settings)
    и держат правки до нажатия Save.
  • Импорт маршрутизации больше не создаёт конфиг, который sing-box не загружает
    Xray-ссылка на внешний geoip (ext:<файл>:<код>, напр. ext:geoip_RU.dat:ru)
    и «голые» IP попадали в ip_cidr как есть. sing-box парсит ip_cidr через
    netip.ParsePrefix, который отвергает значение без маски
    (ipcidr: parse: no '/'), поэтому перенесённый конфиг не запускал ядро и оно
    уходило в цикл рестартов. Теперь ext: маппится в geoip rule_set по хвостовому
    коду (кастомный файл приближается стандартным набором geoip-<код> — проверьте),
    голым IP добавляется маска /32//128, а всё, что не geoip-код и не валидный
    IP/CIDR, отбрасывается с предупреждением, а не ломает конфиг.
  • Мигрированный DNS больше не мешает ядру стартовать — DNS-сервер, заданный
    доменом (https://dns.google/..., tls://...), выдавался без domain_resolver.
    sing-box 1.13 строит dialer DNS-серверов с DirectResolver: true, поэтому
    доменный сервер без per-server domain_resolver падает сразу (missing domain resolver for domain server address) — глобальный default_domain_resolver его
    не покрывает. Теперь миграция ставит per-server domain_resolver (тег
    DNS-сервера) каждому доменному серверу, переиспользуя как bootstrap IP-адресный
    сервер из миграции (или добавляя local), ровно как это делает встроенный
    DNS-редактор s-ui через свой Dial. TLS/HTTP-серверам добавляются блоки
    tls/headers, чтобы мигрированный сервер был идентичен созданному вручную.
  • Trojan-инбаунд больше не роняет ядро (не связано с миграцией) — редактор
    инбаунда писал верхнеуровневый password для Trojan-инбаундов, но у sing-box
    такого поля нет (аутентификация по users, по клиентам), и он отвергает весь
    конфиг с unknown field "password". Поле пароля теперь показывается только для
    Trojan-аутбаундов (где оно валидно), а сборщик конфига срезает оставшийся
    верхнеуровневый password у Trojan-инбаунда — так что уже созданные инбаунды
    чинятся на ближайшей перезагрузке ядра без правки.

Обновление

Ручная миграция не нужна, данные сохраняются. Перезапустите миграцию с
включённым импортом роутинга (мастер включает его по умолчанию), чтобы перенести
прокси-аутбаунды, правила маршрутизации и блок DNS; проверьте всё, что отчёт
пометил как требующее ручного пересоздания (TLS-сертификаты по путям к файлам,
правила attrs/балансировки, loopback/mux).

Don't miss a new s-ui-x release

NewReleases is sending notifications on new releases.