Skip to content

Releases: TwilgateLabs/inhive

InHive 4.8.7

Choose a tag to compare

@twilgate twilgate released this 29 Sep 15:10

InHive 4.8.7

Fixed

  • CDN lines work again. Since 29 September the CDN edge rejects any request that carries a body, so every "CDN-front" line stopped passing traffic. The core now sends upload data inside request headers (Xray uplinkDataPlacement parity), and upload failures such as 413/431 are written to the log instead of silently stalling the connection.
  • Diagnostic export keeps timestamps. With the privacy option on, every HH:MM:SS was being mistaken for an IPv6 address and replaced, so an incident timeline could not be rebuilt from the file. Real IPv6 addresses (including compressed and IPv4-mapped forms) are now hidden completely.
  • WARP: changing the noise preset, port or keys while connected now reaches the core.
  • Config editor: "Save and restart" no longer knocks the connection out; a hand-edited config is applied to the live connection through the normal restart path.
  • Simple mode: a server picked from the country picker stays picked across list reloads.
  • Two server switches in a row no longer lose the second one.
  • Server ping no longer fails in debug builds while the VPN state is loaded.

Changed

  • One path from settings to the core, one policy for choosing the best server, one path for adding a subscription (QR, clipboard, file, inhive:// links).
  • Your country is worked out on the device (SIM, then system region) and drives which home-country servers auto-select skips.
  • Updates and the About page point at the single public repo TwilgateLabs/inhive.
  • Dark theme: warmer palette.
  • The core restarts once after this update.

Core (inhive-core v4.8.7)

  • xhttp: upload data in headers/cookies (uplinkDataPlacement, uplinkDataKey, uplinkChunkSize), configurable serverMaxHeaderBytes, scMaxEachPostBytes accepts any positive value and upload packets are cut to it; failed uploads are logged.
  • Every engine instance leaked goroutines on stop; box.log rotates at 5 MB; network resets and memory stats are logged; dead hiddify-era code removed.

Full details: app/CHANGELOG.md and core/CHANGELOG.md [4.8.7].

InHive 4.8.6

Choose a tag to compare

@twilgate twilgate released this 18 Sep 12:39

Added

  • "Local proxy and hotspot" rule. Traffic that enters through the local
    proxy port (hotspot clients, a browser or program configured to use
    127.0.0.1:) can be sent to a server of your choice via "Choose
    config" in traffic splitting — the one thing TUN+Proxy mode could do that
    per-domain/per-app rules could not. Applies only while TUN is up; in Proxy
    mode every connection already enters through that port, so the rule is not
    emitted there.
  • The local proxy port is now always available in TUN mode. Until now it
    existed only in Proxy or TUN+Proxy mode, so hotspot sharing in plain TUN had
    nothing to share.
  • A busy local proxy port is reported by name before the core starts.
    Instead of a bind: address already in use line buried in the core log,
    connecting now stops with "Port 127.0.0.1:12354 is taken by hiddify.exe
    (PID 55) — close it or change the local proxy port in Settings"; a second
    InHive instance and a listener left over by InHive itself get their own
    wording. The port itself never changes on its own: it is what hotspot
    clients, browser proxy settings and the system proxy point at, so hopping
    to a neighbour would break them silently.

Removed

  • TUN+Proxy ("+") mode is gone from the home screen. It offered exactly
    two exits; "Choose config" rules offer as many as you like, per site or
    per app, in every mode. On first launch an enabled TUN+Proxy setup is
    migrated automatically: every "Proxy" rule becomes "→ that server" for the
    server that was in the Proxy slot, and a "local proxy and hotspot → that
    server" rule is added so hotspot clients keep their exit. If the Proxy
    slot had no saved server, the old rules stay visible as "Proxy (outdated)"
    so you can reassign them — nothing is dropped silently.
  • Route any site or app to any server — "Choose config" in traffic
    splitting.
    Every rule (domain, keyword, IP, country, custom list, app) now
    has a new destination next to Direct/Block: pick a subscription, then a
    server from it (or one of your own configs), and traffic matching that rule
    leaves through exactly that server. Each such server is added to the config
    as its own exit, so the number of simultaneous exits is no longer limited
    to the two of TUN+Proxy mode — one IP per site if you like. Works
    identically in TUN and Proxy modes and alongside TUN+Proxy and multi-hop.
    If the provider rotates the server's address, the rule follows the
    subscription's fresh copy; the snapshot taken at pick time is the fallback,
    so the rule survives deleting the subscription. A rule whose server cannot
    be built is skipped with a log line rather than crashing the core. Rule
    exits do not appear in the server list and are never auto-selected.
  • Per-subscription client mimicry. Long-press a subscription → its info
    page now has "Client mimicry": pick which client this one subscription is
    fetched as (Happ, Shadowrocket, sing-box, v2rayNG, Clash Meta, NekoBox,
    InHive), or "As in Settings" to follow the global preset. Panels gate by
    User-Agent differently — one needs Happ, another sing-box, a third serves
    the full list only to an honest InHive — so a single global preset could not
    satisfy two subscriptions at once. Own inhive.ru subscriptions are unaffected
    and do not show the option.
  • Diagnostic export now shows what the app was actually doing. The file
    from Logs → export gains three sections: the routing settings and rules in
    effect (country/domain/app rules, custom and provider rule sets, QUIC/IPv6/
    ad-block switches, DNS), the OS network interfaces at export time (a second
    VPN client's adapter is visible there), and the last sing-box config that
    was handed to the core, with UUIDs, passwords and keys replaced by
    <redacted> regardless of the redaction checkbox. The app log also records a
    one-line routing summary every time a live config is built. Until now a
    report could contain fifteen "routing rules changed" lines and not a single
    line saying what they changed to (region-lock report, 2026-09-10).

Fixed

  • A subscription that answers with a web page is now an error, not an empty
    list.
    Some panels and subscription proxies (p.kfwl.lol on 2026-09-11)
    gate by User-Agent: a client they do not recognise gets 200 OK with an
    HTML "your client is outdated" page instead of the config. The app used to
    hand that page to the parser, get zero servers, and show an empty
    subscription with no explanation. It now reports "the server returned a web
    page instead of a subscription" with a hint to switch the subscription
    User-Agent preset in Settings, and logs the response for diagnostics.

  • The "Happ" User-Agent preset actually passes Happ version gates. It
    advertised Happ/2.11.0; gates that require Happ 3.24.1 or newer treated it
    as an outdated client and served the same HTML page, so choosing the preset
    changed nothing. Bumped to Happ/3.24.1, with a test pinning the floor.

  • "IPv4 only" and Fake-IP no longer silently cancel each other. With
    Fake-IP on, the core hands the server a domain name instead of an address,
    and the server picks IPv4 or IPv6 itself, so the "Server without IPv6"
    switch had no effect at all. A user with both switches on reached Google
    over the exit's IPv6, which geolocates to the wrong country, and Gemini
    refused to work while the app looked fully configured (field report,
    2026-09-10). The two settings are now mutually exclusive: turning one on
    asks to turn the other off and explains why, provider presets cannot
    re-enable Fake-IP over IPv4-only, and stored settings with both on are
    healed at startup in favour of IPv4-only. The switch is renamed "IPv4 only"
    and both descriptions now say what actually happens.

  • Server names with a broken emoji no longer leave blank rows. A name whose
    emoji was cut in half by the provider's panel, or by our own shortening for
    the multi-hop labels, made Flutter refuse to draw the text ("string is not
    well-formed UTF-16", nine times in one user's log). Such names are repaired
    when the subscription is parsed, and the app now shortens text by visible
    characters, never through the middle of an emoji.

  • Diagnostic export is readable again. Log tails were decoded as Latin-1,
    so every Cyrillic server name in box.log came out as "ð©ðª Ðех". Tails are
    now decoded as UTF-8.

  • Windows: the app no longer disappears three days after logon. With
    autostart enabled, the app is launched by a Task Scheduler task, and that
    task carried the scheduler's default "stop the task if it runs longer than
    3 days" limit. Exactly 72 hours after signing in, Windows terminated the
    app: no error window, nothing in the logs, VPN silently gone (field
    diagnostic 2026-09-09). The task is now registered without a time limit and
    without the "stop on battery" switches, and it launches the app at normal
    process priority instead of the scheduler's below-normal default. Existing
    installations fix their task automatically on the next autostart launch, no
    UAC prompt involved.

  • "Servers updated" no longer appears when nothing was updated. On a mobile
    network where the subscription host is unreachable, tapping refresh reported
    success while the app kept running on a cached list — six taps, six success
    toasts, no update (field diagnostic 2026-09-06: every fetch timed out for a
    full day). The refresh verdict was inferred from "no error was recorded",
    and the four paths that return early without touching the network recorded
    none. Loading a subscription now reports an explicit outcome, a refresh that
    arrives while another one is in flight waits for it and reports its real
    result instead of the cache, and only a genuine server response counts as
    success.


Core: inhive-core v4.8.6 — REALITY works again against Xray 26.9.8+ servers (MLKEM-first ClientHello), XHTTP parity with Xray 26.9.9, sing-box 1.13.21, Windows no longer floods the log on locally closed connections.