github lilendian0x00/xray-knife v11.3.0
Xray-knife v11.3.0

4 hours ago

๐Ÿš€ Xray-knife v11.3.0 (JOIN THE TELEGRAM CHANNEL)

https://t.me/lilendian0x00

The proxy now rotates without dropping connections and can fail closed, every failed test tells you why it failed, and new tools find a DPI bypass and export what works. ๐Ÿ› ๏ธ

โš ๏ธ After upgrading

  • ๐Ÿ” webui: log in again. Sessions are bound to a session epoch now, so tokens from older versions are rejected. Logging out sticks, and changing the password signs every session out.
  • ๐Ÿ” Run xray-knife subs fetch --all once. A link that several subscriptions return is now tracked for each of them; until you fetch again, the database only knows the last one.
  • ๐ŸŒ proxy --addr must be an IP (localhost still means 127.0.0.1). A hostname used to silently become 0.0.0.0, an open proxy on your LAN.
  • โ›“๏ธ Chain order: in --chain-links "A|B", A is the entry (dialed from this machine) and B the exit. The xray chain ran the other way, so exit rotation never changed your egress IP.
  • ๐Ÿ”“ With -z auto, TLS links with --insecure / allowInsecure=1 (and no pcs pin) run on sing-box, because xray-core cannot skip certificate verification.
  • ๐Ÿš proxy app --shell drops to the user who ran sudo, unless you pass --shell-as-root.
  • ๐Ÿ”ข Exit codes are a contract: 0 ok, 1 error, 2 usage, 3 nothing passed, 130 interrupted. http exits 3 when no config passes, so scripts that treat any non-zero code as a crash should check for 3.

๐Ÿ”„ Rotation no longer drops your connections

proxy used to restart its listener on every rotation, cutting everything that was open. Outbounds are now hot-swapped: the listener stays up, and a replaced outbound keeps serving the connections it already carries for --drain seconds.

xray-knife proxy inbound -f valid.txt --rotate 0 --health-url https://cloudflare.com/cdn-cgi/trace

--rotate 0 rotates only when health checks fail.


๐Ÿ›ก๏ธ Kill switch, IPv6 and a real cleanup

  • ๐Ÿšง --kill-switch (proxy tun, proxy app) blocks egress that bypasses the tunnel, including traffic forwarded from containers and VMs. It survives a crash on purpose (fail closed).
  • ๐ŸŒ proxy tun captures IPv6 too (--tun-addr6, or none to let IPv6 bypass).
  • ๐Ÿงน sudo xray-knife proxy restore removes leftover kill switches, TUN rules and system proxy settings. tun and app also clean up after dead instances at startup.
  • โŒจ๏ธ Pressing Ctrl+C twice within 5 s lifts the kill switch and restores the OS proxy settings before exiting. Repeated SIGHUP/SIGTERM (an SSH drop, a service manager) never force an exit.

๐Ÿฉบ Every failed test says why

Non-passed http results carry a failure kind from a direct DNS/TCP/TLS check of the server (--diagnose, on by default): dns-poisoned, tcp-timeout, tcp-refused, tls-reset, proxy-auth, โ€ฆ

2 not passed: 2 tcp-refused

Add a trusted resolver to catch a poisoned system DNS with --resolver https://1.1.1.1/dns-query. Kinds are stored in the database and shown by http list-results.


๐Ÿงช dpi scan: find a fragment setting that gets through

xray-knife dpi scan -c "vless://..." --mode full --stop-after 3

It tests the config as-is and across a grid of TLS fragmentation settings (plus optional --sni overrides), checks the server directly, and recommends a --fragment value. --fragment and --noise work on http, proxy and cfscanner --config.


๐Ÿ“ค Export what works

xray-knife subs export --sub-id 1 --status passed --format clash -o best.yaml

Formats: base64, plain, clash, singbox, xray. The web UI can publish the same as a /sub/<token> URL for your client to subscribe to.

Going the other way, subs fetch now imports Clash/mihomo YAML, sing-box JSON and xray JSON subscriptions, which used to be rejected as an invalid format.


๐Ÿ†• New protocols (sing-box)

tuic:// (v5), hysteria:// (v1), anytls:// and ssh://.


๐Ÿ–ฅ๏ธ A new web UI

Rebuilt around a page per tool (HTTP tester, CF scanner, proxy, DPI scan, subscriptions, history, settings), with live logs, export and QR dialogs, and a Persian translation. webui can serve HTTPS (--tls-cert / --tls-key) and stores only a bcrypt hash of the password.


โ˜๏ธ cfscanner handles big ranges

IPs are planned lazily, so large and IPv6 ranges work: --max-ips (default 2,000,000) and --sample-per-subnet. Progress is checkpointed every 30 s, so --resume works without --save-db. Results export as -x csv|json|jsonl. With -S, IPs rank by download speed, and a failed speed test no longer marks a working IP as failed.


โœจ Also new

  • ๐Ÿ“ก http tests MTProto proxy links (tg://proxy, t.me/proxy) with a native probe; --probe-samples measures several round trips and reports min/avg/max/jitter.
  • ๐Ÿ—„๏ธ xray-knife db stats | prune | vacuum | backup | migrate. The database now opens only when a command needs it.
  • ๐Ÿคซ --quiet on every command. Errors print once, without the usage dump.
  • ๐Ÿ“‹ --json on subs show, subs list-configs, http list-results and cfscanner list-results. net tcp gained -n/--count, --interval, --timeout and --json.
  • ๐Ÿ“ฅ http -i/--stdin (or -f -), -x json|jsonl and --speedtest-url. Output streams to <out>.partial and only replaces <out> when the run has results.
  • ๐Ÿ” Release zips come with a SHA256SUMS file.

๐Ÿ“ฆ Install

Grab a prebuilt binary from the assets below (verify with sha256sum -c --ignore-missing SHA256SUMS), or install with Go. The tags match the release binaries:

go install -tags "with_gvisor,with_quic,with_wireguard,with_utls,with_clash_api,with_grpc" \
  github.com/lilendian0x00/xray-knife/v11@latest

Full Changelog: v11.2.0...v11.3.0

Don't miss a new xray-knife release

NewReleases is sending notifications on new releases.