Skip to content

release v2.3.8

Latest

Choose a tag to compare

@github-actions github-actions released this 09 Oct 19:54

Release v2.3.8

Downloads

macOS (Universal) - Supports both Apple Silicon and Intel

Option 1: Installation Script (Recommended)

Install with a single command (version v2.3.8):

curl -fsSL https://raw.githubusercontent.com/Leadaxe/singbox-launcher/develop/scripts/install-macos.sh | bash -s -- v2.3.8

The script will:

  • Download the release archive
  • Extract and install to /Applications/
  • Fix macOS quarantine attributes and permissions
  • Launch the application automatically

Option 2: Manual Installation

  1. Download: singbox-launcher-v2.3.8-macos.zip
  2. Extract the ZIP file
  3. Remove quarantine attribute (required):
    xattr -cr "singbox-launcher.app" && chmod +x "singbox-launcher.app/Contents/MacOS/singbox-launcher"
  4. Double-click singbox-launcher.app to run
    • If macOS blocks the app, go to System Settings → Privacy & Security and click "Open Anyway"
    • Alternatively, right-click the app and select "Open" (first time only)

Windows (amd64)

Option 1: Installer (Recommended)

  1. Download: singbox-launcher-v2.3.8-win64-setup.exe
  2. Run it and confirm the administrator prompt once. The launcher goes to C:\Program Files\singbox-launcher, your data to %LOCALAPPDATA%\singbox-launcher; sing-box.exe, wintun.dll, the config template and Mesa3D are included, nothing is downloaded on first launch
    • Tasks: desktop shortcut, Start with Windows, software OpenGL (Mesa3D) for RDP / VMs without a GPU
    • Installing over a previous version keeps your data; uninstall from Settings → Apps asks whether to remove the data too
    • The installer is not code-signed yet: if SmartScreen shows "Windows protected your PC", click More info → Run anyway

Option 2: Portable ZIP

  1. Download: singbox-launcher-v2.3.8-win64.zip
    • or singbox-launcher-v2.3.8-win64-full.zip — full bundle: sing-box.exe, wintun.dll, the config template and Mesa3D (mesa3d/, used only when no hardware OpenGL — RDP, VMs) are already inside, nothing is downloaded on first launch
  2. Extract the ZIP file to a folder your account can write to, for example D:\Tools\singbox-launcher\ — settings stay next to the program (portable.txt)
    • Under C:\Program Files\ the launcher keeps its data in %LOCALAPPDATA%\singbox-launcher instead
  3. Run singbox-launcher.exe from that folder — no administrator rights, no UAC prompt
    • TUN needs administrator rights: Start offers Restart as administrator or Switch to proxy mode
    • The regular archive downloads sing-box and wintun.dll on first launch

Windows 7 (x86, legacy)

  1. Download: singbox-launcher-v2.3.8-win7-32.zip
  2. Extract the ZIP file to a folder and run singbox-launcher-win7-32.exe
    • For Windows 7 / 32-bit or legacy compatibility only
    • Runs as administrator (UAC prompt on every start), settings stay next to the program (portable.txt); no installer and no daemon service

Linux Support

⚠️ Linux build temporarily unavailable - мы ищем тестировщика для ручного тестирования перед включением автоматической сборки.

Checksums

See checksums.txt for SHA256 checksums of all files.

Release notes — v2.3.8 (2026-10-09)

EN

A patch release after v2.3.7. Core sing-box-lx 1.14.3-lx.14 (was 1.14.2-lx.12), contract 1.1.116 (was 1.1.114).

Fixed

  • XHTTP path keeps its ?query part. A VLESS/XHTTP node whose path is /?proxyip=… (Cloudflare Worker relays such as edgetunnel) used to lose everything after ? on import from a link or Xray JSON, so the relay got no proxyip. The path is now kept as written, like Xray does; the bundled core (SPEC 119) sends the tail to the server as the request query. Shared links encode the ? inside path=. Nodes that differ only in that tail are no longer merged as duplicates. Already imported subscription nodes pick the fix up on the next update; a node added by pasting a link needs to be added again. WebSocket ?ed=N handling is unchanged. Contract 1.1.115.
  • Importing a backup without a rules section no longer wipes your routing rules. A partial LX Backup file — one node, one folder — used to replace the whole rules[] with nothing, silently, with applied.rules: 0 in the reply (incident of 8 Oct 2026 via the debug API). Now a file that does not carry the rules key leaves the rules alone; a file that does (even an empty list) still replaces them, and the import report says how many rules were removed (backup_rules_replaced). To add a single node, use POST /state/servers instead of a backup file. Contract 1.1.116.

New

  • Debug API edits the state like the Configurator does. New single-entry endpoints: GET/POST/DELETE /state/servers (add nodes from links, .conf, vpn:// or sing-box JSON; delete a node together with the references to it), POST/DELETE /state/rules, POST/DELETE /state/dns/servers, POST/DELETE /state/dns/rules, mirrored under /remote/machines/{id}/state/*; the local config.json is rebuilt after each one (config_rebuilt). PATCH /state/dns now requires both servers and rules (an empty list clears on purpose), so a body with one list can no longer wipe the other. Every POST/PATCH/PUT/DELETE to the API leaves one line in the launcher log (method, path, status, start of the reply; request bodies are never logged). If the Configurator window is open for the same configuration, a state change through the API now pops up a prompt there — reload the saved settings or keep the window's own copy — instead of the window silently overwriting the API edit on its next Save. SPEC 160.

Core

  • Core pinned to sing-box-lx 1.14.3-lx.14 (base sing-box v1.14.3; was 1.14.2-lx.12). Needed for the XHTTP path fix above: the core sends the ?… tail as the request query (SPEC 119), an older core glued it into the path (/x?ed=2048 → /x%3Fed=2048, 404). Also new in the core: lx.mtu_align (default clamp) sizes mtu / initial_packet_size of nodes over an IP tunnel via detour or chain (hysteria2 over WARP to an IPv6 server works); MASQUE outer QUIC starts with a larger initial packet; vhttp: auto no longer sticks to h2 after one h3 failure; lx.13: the AmneziaWG QUIC decoy is regenerated per handshake, ib=chrome/ib=firefox send a real browser QUIC ClientHello. Daemon stubs unchanged (SYNC_REV → tag commit d7f11807).

RU

Патч-релиз после v2.3.7. Ядро sing-box-lx 1.14.3-lx.14 (было 1.14.2-lx.12), контракт 1.1.116 (был 1.1.114).

Исправлено

  • Путь XHTTP сохраняет хвост ?query. У узла VLESS/XHTTP с путём /?proxyip=… (релеи Cloudflare Worker, например edgetunnel) при импорте ссылки или Xray JSON терялось всё после ?, и релей не получал proxyip. Теперь путь берётся как написан, как у Xray; ядро этого релиза (SPEC 119) отправляет хвост серверу query запроса. В ссылке «Поделиться» ? внутри path= кодируется. Узлы, различающиеся только этим хвостом, больше не схлопываются как дубли. Уже импортированные узлы подписки исправятся при следующем обновлении; узел, добавленный ссылкой вручную, нужно добавить заново. Обработка ?ed=N у WebSocket не менялась. Контракт 1.1.115.
  • Импорт бэкапа без секции rules больше не стирает правила маршрутизации. Частичный файл LX Backup — один узел, одна папка — замещал весь rules[] пустотой, молча, с applied.rules: 0 в ответе (инцидент 08.10.2026 через debug API). Теперь файл без ключа rules правила не трогает; файл с ключом (даже пустым списком) замещает их, как прежде, а отчёт импорта называет число снятых правил (backup_rules_replaced). Чтобы добавить один узел, берите POST /state/servers, а не файл бэкапа. Контракт 1.1.116.

Новое

  • Debug API правит состояние так же, как Конфигуратор. Новые точки для одной записи: GET/POST/DELETE /state/servers (добавить узлы из ссылок, .conf, vpn:// или JSON sing-box; удалить узел вместе со ссылками на него), POST/DELETE /state/rules, POST/DELETE /state/dns/servers, POST/DELETE /state/dns/rules, с зеркалами под /remote/machines/{id}/state/*; локальный config.json после каждой пересобирается (config_rebuilt). PATCH /state/dns теперь требует оба ключа — servers и rules (пустой список — осознанный сброс), так что тело с одним списком больше не стирает другой. Каждый POST/PATCH/PUT/DELETE к API оставляет одну строку в логе лаунчера (метод, путь, статус, начало ответа; тела запросов не пишутся). Если окно Конфигуратора открыто на той же конфигурации, правка состояния через API теперь показывает в нём попап — перечитать сохранённые настройки или оставить копию окна, — а не молча перезаписывается окном при следующем Save. SPEC 160.

Ядро

  • Ядро — sing-box-lx 1.14.3-lx.14 (база sing-box v1.14.3; было 1.14.2-lx.12). Нужно для правки пути XHTTP выше: ядро шлёт хвост ?… query запроса (SPEC 119), старое клеило его в путь (/x?ed=2048 → /x%3Fed=2048, 404). Ещё в ядре: lx.mtu_align (по умолчанию clamp) подбирает mtu / initial_packet_size узлам поверх IP-туннеля через detour или chain (hysteria2 через WARP на IPv6-сервер работает); внешний QUIC MASQUE стартует с большим начальным пакетом; vhttp: auto больше не залипает на h2 после одного отказа h3; из lx.13 — QUIC-приманка AmneziaWG генерируется заново на каждый хендшейк, ib=chrome/ib=firefox шлют настоящий QUIC-ClientHello браузера. Стабы демона без изменений (SYNC_REV → коммит тега d7f11807).