Repository navigation
Releases: heaprip/xraybar
Release list
XrayBar 0.3.0
The first release with downloadable builds: a .pkg and a .zip, built by CI from this tag
for Apple silicon and Intel, with a provenance attestation. Signed ad hoc, not notarized:
see Install in the README for the one-time Open Anyway.
Security
- Root runs only an Xray installed into a root-owned folder, checked against its SHA-256;
a file in your user folders can no longer be swapped and run as root (D38). Existing
downloads are not reused: choose Xray › Download once more. - Root writes the config's log section itself, so no config can make it write files (D38).
- IPv6 goes through the tunnel when the Mac has a global IPv6 address (D40).
- The DNS override follows a switch to another network service (D41).
- Server credentials (VLESS ids) live in the login keychain; one item, so an update asks once (D45).
Behaviour
- No polling: the session and the app react to events (network changes, process exits, the
stop file); a network change or wake is written to the log (D42). - An outdated root helper is shown loudly and Connect offers to update it first (D43).
- Touch ID once per app run (per login) instead of at every Connect (D44).
- The menu stays responsive while connecting (D39).
Mac conventions
- About XrayBar, VoiceOver label for the menu bar icon, one instance only, unified logging (D46).
- Russian interface; it follows the system language (D47).
After installing: Update Helper (Required) if you use Touch ID, then Xray › Download.
XrayBar 0.2.0
First public version. A menu-bar app that runs Xray-core with its native TUN on macOS: one process, geosite/geoip routing, nothing in between.
What it does
- Connect from a standard macOS menu; Connect at Launch to the last used server
- Servers: VLESS + Reality/TLS. Import a
vless://link or a QR screenshot (⌘⇧⌃4) from the clipboard, or read-only import from v2rayN; share as QR - Routing sets in v2rayN's format; tunnel exclusions (IPv4 CIDRs)
- DNS goes through the tunnel while connected and is restored afterwards, also after a crash or power loss
- Several Xray versions side by side; a new one gets a trial connection with one-click switch back. Xray v26.9.9 is pinned by SHA-256; routing data (runetfreedom or Loyalsoldier) is checksum-verified
- Optional root-owned helper: Touch ID per Connect instead of the password
- Hold Option in the menu: remove items, copy a server link, technical details
Trust
No binaries are attached on purpose: build it yourself with the Command Line Tools (scripts/make-app.sh, ~20 s). ~1,400 lines of Swift in numbered files, ~200 lines of root scripts, a ~110-line helper. scripts/audit.sh and docs/AUDIT.md (usable as an AI review prompt) let you check what it does. See docs/SECURITY.md for the threat model and known limitations.
Requires macOS 15+ (tested on macOS 26). Every design decision is in docs/DECISIONS.md.