๐ Xray-knife v11.3.0 (JOIN THE TELEGRAM CHANNEL)
The proxy now rotates without dropping connections and can fail closed, every failed test tells you why it failed, and new tools find a DPI bypass and export what works. ๐ ๏ธ
โ ๏ธ After upgrading
- ๐ webui: log in again. Sessions are bound to a session epoch now, so tokens from older versions are rejected. Logging out sticks, and changing the password signs every session out.
- ๐ Run
xray-knife subs fetch --allonce. A link that several subscriptions return is now tracked for each of them; until you fetch again, the database only knows the last one. - ๐
proxy --addrmust be an IP (localhoststill means 127.0.0.1). A hostname used to silently become0.0.0.0, an open proxy on your LAN. - โ๏ธ Chain order: in
--chain-links "A|B", A is the entry (dialed from this machine) and B the exit. The xray chain ran the other way, so exit rotation never changed your egress IP. - ๐ With
-z auto, TLS links with--insecure/allowInsecure=1(and nopcspin) run on sing-box, because xray-core cannot skip certificate verification. - ๐
proxy app --shelldrops to the user who ran sudo, unless you pass--shell-as-root. - ๐ข Exit codes are a contract: 0 ok, 1 error, 2 usage, 3 nothing passed, 130 interrupted.
httpexits 3 when no config passes, so scripts that treat any non-zero code as a crash should check for 3.
๐ Rotation no longer drops your connections
proxy used to restart its listener on every rotation, cutting everything that was open. Outbounds are now hot-swapped: the listener stays up, and a replaced outbound keeps serving the connections it already carries for --drain seconds.
xray-knife proxy inbound -f valid.txt --rotate 0 --health-url https://cloudflare.com/cdn-cgi/trace--rotate 0 rotates only when health checks fail.
๐ก๏ธ Kill switch, IPv6 and a real cleanup
- ๐ง
--kill-switch(proxy tun,proxy app) blocks egress that bypasses the tunnel, including traffic forwarded from containers and VMs. It survives a crash on purpose (fail closed). - ๐
proxy tuncaptures IPv6 too (--tun-addr6, ornoneto let IPv6 bypass). - ๐งน
sudo xray-knife proxy restoreremoves leftover kill switches, TUN rules and system proxy settings.tunandappalso clean up after dead instances at startup. - โจ๏ธ Pressing Ctrl+C twice within 5 s lifts the kill switch and restores the OS proxy settings before exiting. Repeated SIGHUP/SIGTERM (an SSH drop, a service manager) never force an exit.
๐ฉบ Every failed test says why
Non-passed http results carry a failure kind from a direct DNS/TCP/TLS check of the server (--diagnose, on by default): dns-poisoned, tcp-timeout, tcp-refused, tls-reset, proxy-auth, โฆ
2 not passed: 2 tcp-refused
Add a trusted resolver to catch a poisoned system DNS with --resolver https://1.1.1.1/dns-query. Kinds are stored in the database and shown by http list-results.
๐งช dpi scan: find a fragment setting that gets through
xray-knife dpi scan -c "vless://..." --mode full --stop-after 3It tests the config as-is and across a grid of TLS fragmentation settings (plus optional --sni overrides), checks the server directly, and recommends a --fragment value. --fragment and --noise work on http, proxy and cfscanner --config.
๐ค Export what works
xray-knife subs export --sub-id 1 --status passed --format clash -o best.yamlFormats: base64, plain, clash, singbox, xray. The web UI can publish the same as a /sub/<token> URL for your client to subscribe to.
Going the other way, subs fetch now imports Clash/mihomo YAML, sing-box JSON and xray JSON subscriptions, which used to be rejected as an invalid format.
๐ New protocols (sing-box)
tuic:// (v5), hysteria:// (v1), anytls:// and ssh://.
๐ฅ๏ธ A new web UI
Rebuilt around a page per tool (HTTP tester, CF scanner, proxy, DPI scan, subscriptions, history, settings), with live logs, export and QR dialogs, and a Persian translation. webui can serve HTTPS (--tls-cert / --tls-key) and stores only a bcrypt hash of the password.
โ๏ธ cfscanner handles big ranges
IPs are planned lazily, so large and IPv6 ranges work: --max-ips (default 2,000,000) and --sample-per-subnet. Progress is checkpointed every 30 s, so --resume works without --save-db. Results export as -x csv|json|jsonl. With -S, IPs rank by download speed, and a failed speed test no longer marks a working IP as failed.
โจ Also new
- ๐ก
httptests MTProto proxy links (tg://proxy,t.me/proxy) with a native probe;--probe-samplesmeasures several round trips and reports min/avg/max/jitter. - ๐๏ธ
xray-knife db stats | prune | vacuum | backup | migrate. The database now opens only when a command needs it. - ๐คซ
--quieton every command. Errors print once, without the usage dump. - ๐
--jsononsubs show,subs list-configs,http list-resultsandcfscanner list-results.net tcpgained-n/--count,--interval,--timeoutand--json. - ๐ฅ
http -i/--stdin(or-f -),-x json|jsonland--speedtest-url. Output streams to<out>.partialand only replaces<out>when the run has results. - ๐ Release zips come with a
SHA256SUMSfile.
๐ฆ Install
Grab a prebuilt binary from the assets below (verify with sha256sum -c --ignore-missing SHA256SUMS), or install with Go. The tags match the release binaries:
go install -tags "with_gvisor,with_quic,with_wireguard,with_utls,with_clash_api,with_grpc" \
github.com/lilendian0x00/xray-knife/v11@latestFull Changelog: v11.2.0...v11.3.0