Releases: TwilgateLabs/inhive
Release list
InHive 4.8.7
InHive 4.8.7
Fixed
- CDN lines work again. Since 29 September the CDN edge rejects any request that carries a body, so every "CDN-front" line stopped passing traffic. The core now sends upload data inside request headers (Xray
uplinkDataPlacementparity), and upload failures such as 413/431 are written to the log instead of silently stalling the connection. - Diagnostic export keeps timestamps. With the privacy option on, every
HH:MM:SSwas being mistaken for an IPv6 address and replaced, so an incident timeline could not be rebuilt from the file. Real IPv6 addresses (including compressed and IPv4-mapped forms) are now hidden completely. - WARP: changing the noise preset, port or keys while connected now reaches the core.
- Config editor: "Save and restart" no longer knocks the connection out; a hand-edited config is applied to the live connection through the normal restart path.
- Simple mode: a server picked from the country picker stays picked across list reloads.
- Two server switches in a row no longer lose the second one.
- Server ping no longer fails in debug builds while the VPN state is loaded.
Changed
- One path from settings to the core, one policy for choosing the best server, one path for adding a subscription (QR, clipboard, file,
inhive://links). - Your country is worked out on the device (SIM, then system region) and drives which home-country servers auto-select skips.
- Updates and the About page point at the single public repo
TwilgateLabs/inhive. - Dark theme: warmer palette.
- The core restarts once after this update.
Core (inhive-core v4.8.7)
- xhttp: upload data in headers/cookies (
uplinkDataPlacement,uplinkDataKey,uplinkChunkSize), configurableserverMaxHeaderBytes,scMaxEachPostBytesaccepts any positive value and upload packets are cut to it; failed uploads are logged. - Every engine instance leaked goroutines on stop;
box.logrotates at 5 MB; network resets and memory stats are logged; dead hiddify-era code removed.
Full details: app/CHANGELOG.md and core/CHANGELOG.md [4.8.7].
InHive 4.8.6
Added
- "Local proxy and hotspot" rule. Traffic that enters through the local
proxy port (hotspot clients, a browser or program configured to use
127.0.0.1:) can be sent to a server of your choice via "Choose
config" in traffic splitting — the one thing TUN+Proxy mode could do that
per-domain/per-app rules could not. Applies only while TUN is up; in Proxy
mode every connection already enters through that port, so the rule is not
emitted there. - The local proxy port is now always available in TUN mode. Until now it
existed only in Proxy or TUN+Proxy mode, so hotspot sharing in plain TUN had
nothing to share. - A busy local proxy port is reported by name before the core starts.
Instead of abind: address already in useline buried in the core log,
connecting now stops with "Port 127.0.0.1:12354 is taken by hiddify.exe
(PID 55) — close it or change the local proxy port in Settings"; a second
InHive instance and a listener left over by InHive itself get their own
wording. The port itself never changes on its own: it is what hotspot
clients, browser proxy settings and the system proxy point at, so hopping
to a neighbour would break them silently.
Removed
- TUN+Proxy ("+") mode is gone from the home screen. It offered exactly
two exits; "Choose config" rules offer as many as you like, per site or
per app, in every mode. On first launch an enabled TUN+Proxy setup is
migrated automatically: every "Proxy" rule becomes "→ that server" for the
server that was in the Proxy slot, and a "local proxy and hotspot → that
server" rule is added so hotspot clients keep their exit. If the Proxy
slot had no saved server, the old rules stay visible as "Proxy (outdated)"
so you can reassign them — nothing is dropped silently. - Route any site or app to any server — "Choose config" in traffic
splitting. Every rule (domain, keyword, IP, country, custom list, app) now
has a new destination next to Direct/Block: pick a subscription, then a
server from it (or one of your own configs), and traffic matching that rule
leaves through exactly that server. Each such server is added to the config
as its own exit, so the number of simultaneous exits is no longer limited
to the two of TUN+Proxy mode — one IP per site if you like. Works
identically in TUN and Proxy modes and alongside TUN+Proxy and multi-hop.
If the provider rotates the server's address, the rule follows the
subscription's fresh copy; the snapshot taken at pick time is the fallback,
so the rule survives deleting the subscription. A rule whose server cannot
be built is skipped with a log line rather than crashing the core. Rule
exits do not appear in the server list and are never auto-selected. - Per-subscription client mimicry. Long-press a subscription → its info
page now has "Client mimicry": pick which client this one subscription is
fetched as (Happ, Shadowrocket, sing-box, v2rayNG, Clash Meta, NekoBox,
InHive), or "As in Settings" to follow the global preset. Panels gate by
User-Agent differently — one needs Happ, another sing-box, a third serves
the full list only to an honest InHive — so a single global preset could not
satisfy two subscriptions at once. Own inhive.ru subscriptions are unaffected
and do not show the option. - Diagnostic export now shows what the app was actually doing. The file
from Logs → export gains three sections: the routing settings and rules in
effect (country/domain/app rules, custom and provider rule sets, QUIC/IPv6/
ad-block switches, DNS), the OS network interfaces at export time (a second
VPN client's adapter is visible there), and the last sing-box config that
was handed to the core, with UUIDs, passwords and keys replaced by
<redacted>regardless of the redaction checkbox. The app log also records a
one-line routing summary every time a live config is built. Until now a
report could contain fifteen "routing rules changed" lines and not a single
line saying what they changed to (region-lock report, 2026-09-10).
Fixed
-
A subscription that answers with a web page is now an error, not an empty
list. Some panels and subscription proxies (p.kfwl.lolon 2026-09-11)
gate by User-Agent: a client they do not recognise gets200 OKwith an
HTML "your client is outdated" page instead of the config. The app used to
hand that page to the parser, get zero servers, and show an empty
subscription with no explanation. It now reports "the server returned a web
page instead of a subscription" with a hint to switch the subscription
User-Agent preset in Settings, and logs the response for diagnostics. -
The "Happ" User-Agent preset actually passes Happ version gates. It
advertisedHapp/2.11.0; gates that require Happ 3.24.1 or newer treated it
as an outdated client and served the same HTML page, so choosing the preset
changed nothing. Bumped toHapp/3.24.1, with a test pinning the floor. -
"IPv4 only" and Fake-IP no longer silently cancel each other. With
Fake-IP on, the core hands the server a domain name instead of an address,
and the server picks IPv4 or IPv6 itself, so the "Server without IPv6"
switch had no effect at all. A user with both switches on reached Google
over the exit's IPv6, which geolocates to the wrong country, and Gemini
refused to work while the app looked fully configured (field report,
2026-09-10). The two settings are now mutually exclusive: turning one on
asks to turn the other off and explains why, provider presets cannot
re-enable Fake-IP over IPv4-only, and stored settings with both on are
healed at startup in favour of IPv4-only. The switch is renamed "IPv4 only"
and both descriptions now say what actually happens. -
Server names with a broken emoji no longer leave blank rows. A name whose
emoji was cut in half by the provider's panel, or by our own shortening for
the multi-hop labels, made Flutter refuse to draw the text ("string is not
well-formed UTF-16", nine times in one user's log). Such names are repaired
when the subscription is parsed, and the app now shortens text by visible
characters, never through the middle of an emoji. -
Diagnostic export is readable again. Log tails were decoded as Latin-1,
so every Cyrillic server name in box.log came out as "ð©ðª Ðех". Tails are
now decoded as UTF-8. -
Windows: the app no longer disappears three days after logon. With
autostart enabled, the app is launched by a Task Scheduler task, and that
task carried the scheduler's default "stop the task if it runs longer than
3 days" limit. Exactly 72 hours after signing in, Windows terminated the
app: no error window, nothing in the logs, VPN silently gone (field
diagnostic 2026-09-09). The task is now registered without a time limit and
without the "stop on battery" switches, and it launches the app at normal
process priority instead of the scheduler's below-normal default. Existing
installations fix their task automatically on the next autostart launch, no
UAC prompt involved. -
"Servers updated" no longer appears when nothing was updated. On a mobile
network where the subscription host is unreachable, tapping refresh reported
success while the app kept running on a cached list — six taps, six success
toasts, no update (field diagnostic 2026-09-06: every fetch timed out for a
full day). The refresh verdict was inferred from "no error was recorded",
and the four paths that return early without touching the network recorded
none. Loading a subscription now reports an explicit outcome, a refresh that
arrives while another one is in flight waits for it and reports its real
result instead of the cache, and only a genuine server response counts as
success.
Core: inhive-core v4.8.6 — REALITY works again against Xray 26.9.8+ servers (MLKEM-first ClientHello), XHTTP parity with Xray 26.9.9, sing-box 1.13.21, Windows no longer floods the log on locally closed connections.