Bump version

This commit is contained in:
世界
2026-08-30 17:41:47 +08:00
parent 6aecbe2750
commit 384344ead3
2 changed files with 884 additions and 1 deletions
+872 -1
View File
@@ -2,19 +2,102 @@
icon: material/alert-decagram
---
#### 1.14.0-rc.4
* Fixes and improvements
#### 1.13.20
* Fixes and improvements
#### 1.14.0-rc.2
* Migrate Apple platform clients to a new Apple developer account **1**
* Fixes and improvements
**1**:
For the macOS standalone client, profiles and settings are not inherited, see
[Migration](/migration/#migrate-the-macos-standalone-client-data).
#### 1.14.0-rc.1
* Fixes and improvements
#### 1.13.19
* Fixes and improvements
#### 1.14.0-beta.16
* Fixes and improvements
#### 1.14.0-beta.15
* Add `api` command **1**
* Add Taildrop support **2**
* Add `listen_port` option to Tailscale endpoint
* Fixes and improvements
**1**:
The new `sing-box api` command is a CLI client for the
[API service](/configuration/service/api/), providing the same operations
available in graphical clients and the Dashboard.
**2**:
[Tailscale](/configuration/endpoint/tailscale/) endpoints now support
[Taildrop](https://tailscale.com/kb/1106/taildrop), the Tailscale file
sharing feature. Received files are stored in the directory configured by
the new
[`taildrop_directory`](/configuration/endpoint/tailscale/#taildrop_directory)
option (`Taildrop` by default). Files can be sent and managed through the
graphical clients, the Dashboard, or the new `sing-box api` command.
#### 1.14.0-beta.14
* Fixes and improvements
#### 1.13.18
* Update naiveproxy to v150.0.7871.63-1
* Fixes and improvements
#### 1.14.0-beta.10
* Fixes and improvements
#### 1.14.0-beta.7
* Add Hysteria2 Chrome QUIC fingerprint parroting **1**
* Update quic-go to v0.61.0
* Update tailscale to v1.102.1
* Update gvisor to 20260727.0
* Fixes and improvements
**1**:
Hysteria2 client connections now parrot Chrome's QUIC handshake by default,
making the traffic harder to identify by handshake fingerprinting. Since
Chrome does not declare support for Ed25519, servers using Ed25519
certificates will fail the handshake; see
[disable_chrome_parrot](/configuration/outbound/hysteria2/#disable_chrome_parrot).
#### 1.14.0-beta.5
* Remove client metadata from AnyTLS requests by default **1**
* Update naiveproxy to v150.0.7871.63-1
* Fixes and improvements
**1**:
We found that the AnyTLS client implementation uploads metadata that is
**not used by the open-source server**, and there are reports of vendors using
it to profile and discriminate against users. We now leave it empty by default
and allow you to customize it, see
[AnyTLS client metadata](/manual/misc/anytls-client-metadata/).
#### 1.13.16
* Remove client metadata from AnyTLS requests by default **1**
@@ -28,58 +111,793 @@ it to profile and discriminate against users. We now leave it empty by default
and allow you to customize it, see
[AnyTLS client metadata](/manual/misc/anytls-client-metadata/).
#### 1.14.0-beta.4
* Fixes and improvements
#### 1.13.15
* Fixes and improvements
#### 1.14.0-beta.2
* Add [JSON Schema](/configuration/schema/) support **1**
* Fixes and improvements
**1**:
sing-box now provides a JSON Schema for its configuration, enabling completion
and validation in compatible editors. The schema published with the
documentation can be selected with the new top-level `$schema` field, while
the new `sing-box schema` command generates a schema matching the current
binary and its build tags.
We have also improved the JSON editor experience in the graphical clients on
macOS, Android, Windows, and Linux, and added schema-based completion support.
#### 1.14.0-beta.1
* Correct undefined rule-set matching semantics **1**
* Add search domain rule items **2**
* Add parallel DNS response evaluation support **3**
* Fixes and improvements
**1**:
Rule-set matching has always been described as merged matching: fields of
rule-set rules are considered merged into the referencing rule. However, this
description is only intuitive when a rule-set contains only a single `default`
rule without `invert`. Merged matching is now limited to exactly this case;
any other referenced rule-set is matched as an `other field`, which matches
when any of its rules matches on its own.
Since the previous behavior in the corrected cases was effectively undefined,
counterintuitive, and hard to understand, we do not consider this a breaking
change — except for configurations that worked without their author
understanding why.
**2**:
The new DNS rule items
[`domain_label_count`](/configuration/dns/rule/#domain_label_count) and
[`search_domain_available`](/configuration/dns/rule/#search_domain_available)
match the number of labels in the query name and whether a DNS server
currently holds search domains; combined with `racing`, they allow unqualified
name queries to race a server that can expand them against a public resolver.
Additionally, [`preferred_by`](/configuration/dns/rule/#preferred_by) now
matches search domain suffixes and supports `local` and `dhcp` servers.
**3**:
The [`evaluate`](/configuration/dns/rule_action/#evaluate) action can now assign
a `tag` to each response, allowing multiple evaluated responses to coexist and
be selected through tagged
[`match_response`](/configuration/dns/rule/#match_response) rules. The new
[`race`](/configuration/dns/rule_action/#race) field allows response-dependent
rules to compete in parallel, with the first matching rule taking effect and
the remaining queries canceled. The new `speculative` option can start
`evaluate` and `route` queries while race rules are still pending, reducing
latency at the cost of potentially unused queries.
#### 1.14.0-alpha.50
* Improve OpenVPN interoperability **1**
* Improve OpenConnect interoperability **2**
* Add Fortinet host check support **3**
* Fixes and improvements
**1**:
The OpenVPN client and server now interoperate with more existing deployments
through static-key mode, additional legacy ciphers and digests, and
OpenVPN-compatible certificate purpose, key usage, extended key usage, and
certificate profile checks. They also support more OpenVPN options for tunnel
addressing, MSS calculation, replay windows, timers, and TLS renegotiation. The
new [OpenVPN DNS server](/configuration/dns/server/openvpn/) can use both modern
and legacy DNS options pushed by OpenVPN servers, while the sing-box server can
push both forms.
**2**:
The OpenConnect client now supports existing authentication sessions, OIDC
Bearer authentication, additional platform and AnyConnect mobile identity
fields, AnyConnect compression, and controls for MTU, DPD and reconnect timing,
TCP keep alive, and TLS trust and certificate pinning. The new
[OpenConnect DNS server](/configuration/dns/server/openconnect/) can use pushed
split-DNS resolvers and, when enabled, general pushed resolvers.
**3**:
The [OpenConnect Client](/configuration/endpoint/openconnect/) endpoint can now
submit Fortinet host check results using the new
[`fortinet_host_check`](/configuration/endpoint/openconnect/#fortinet_host_check)
option. This behavior is modeled after openfortivpn and is not an OpenConnect
feature. sing-box only submits explicitly configured values when requested by
the Fortinet server and does not collect system information automatically.
#### 1.14.0-alpha.48
* Add SSO support for AnyConnect **1**
* Add Linux support for the [desktop client application](/clients/desktop/) **2**
* Fixes and improvements
**1**:
The [OpenConnect Client](/configuration/endpoint/openconnect/) endpoint now
supports SSO (single sign-on) authentication for Cisco AnyConnect servers,
available through the sing-box graphical clients.
**2**:
The [sing-box for Desktop](/clients/desktop/) client is now available for Linux
(x64 / arm64 / armv7l) from
[GitHub Releases](https://github.com/SagerNet/sing-box/releases).
#### 1.14.0-alpha.47
* Add OpenVPN client and server support **1**
* Add OpenConnect client support **2**
* Fixes and improvements
**1**:
The new [OpenVPN Client](/configuration/endpoint/openvpn-client/) and
[OpenVPN Server](/configuration/endpoint/openvpn-server/) endpoints are
compatible with standard OpenVPN clients and servers. Interactive client
authentication is available through the sing-box graphical clients and
[Dashboard](https://github.com/SagerNet/sing-box-dashboard).
**2**:
The new [OpenConnect Client](/configuration/endpoint/openconnect/) endpoint
supports Cisco AnyConnect, GlobalProtect, Fortinet, F5, Pulse Connect Secure,
and Juniper Network Connect VPN servers. Interactive authentication is
available through the sing-box graphical clients and
[Dashboard](https://github.com/SagerNet/sing-box-dashboard).
#### 1.14.0-alpha.46
* Add multiple tags support to rule-sets **1**
* Add new UDP NAT options **2**
* Fixes and improvements
**1**:
The rule-set [`tag`](/configuration/rule-set/#tag) field now accepts a list of
tags to define multiple rule-sets sharing other options at once, with the
`{tag}` placeholder in `path` or `url` replaced by each tag.
**2**:
The new [UDP NAT](/configuration/shared/udp-nat/) fields
[`udp_mapping`](/configuration/shared/udp-nat/#udp_mapping),
[`udp_filtering`](/configuration/shared/udp-nat/#udp_filtering) and
[`udp_nat_max`](/configuration/shared/udp-nat/#udp_nat_max) configure the NAT
mapping and filtering behaviors and the maximum number of UDP NAT sessions for
TUN and TProxy inbounds and the WireGuard endpoint.
#### 1.14.0-alpha.45
* Improve the Windows client application **1**
* Fixes and improvements
**1**:
The [Windows client](/clients/desktop/) now includes an updater, adds support
for Windows native sharing of sing-box profile and JSON files, and fixes the
Tailscale SSH terminal. The
[Tailscale SSH server](/configuration/endpoint/tailscale/#ssh_server) can now
open sessions for any local user in the graphical client, while the command
line client remains limited to the user sing-box runs as. Additionally,
configurations that use privileges unrelated to networking are now rejected by
default; an insecure mode is available to allow them.
#### 1.14.0-alpha.44
* Introducing our [new Windows client application](/clients/desktop/) **1**
* Fixes and improvements
**1**:
The new [Windows client](/clients/desktop/) provides an experience equal to
other standard sing-box graphical clients, is available for Windows 10+
(x64 / x86 / arm64), and is distributed as an installer from
[GitHub Releases](https://github.com/SagerNet/sing-box/releases)
(`SFW-<version>-<architecture>.exe`).
#### 1.14.0-alpha.43
* Add network namespace support **1**
* Fixes and improvements
**1**:
The new [`network_namespaces`](/configuration/network-namespace/) option defines
Linux network namespaces for inbounds and outbounds, referenced by tag from the
new tun [`netns`](/configuration/inbound/tun/#netns) field and the existing
[Listen](/configuration/shared/listen/#netns) and
[Dial](/configuration/shared/dial/#netns) `netns` fields.
The [`unshare`](/configuration/network-namespace/unshare/) type creates the
namespace at startup without requiring root privileges: a rootless sing-box can
provide a tun (including `auto_route` and `auto_redirect`) inside a namespace,
which can be entered with `nsenter`.
#### 1.14.0-alpha.42
* Fixes and improvements
#### 1.14.0-alpha.41
* Add windows bridge **1**
* Add `preferred_by` support for bridge **2**
* Add hysteria2 realm IP version restriction **3**
* Add hysteria2 realm port mapping **4**
* Fixes and improvements
**1**:
The [`bridge`](/configuration/outbound/bridge/) outbound is now supported on
Windows, implemented via WinDivert and requiring Administrator privileges.
**2**:
The [`bridge`](/configuration/outbound/bridge/) outbound now works with the
[`preferred_by`](/configuration/route/rule/#preferred_by) route rule item.
It is recommended to use `preferred_by` as a gate in the `route` rule: it only
matches in [pre-match](/configuration/shared/pre-match/) and excludes local
addresses that cannot be routed.
**3**:
The new [`realm.ip_version`](/configuration/outbound/hysteria2/#realmip_version)
inbound and outbound field restricts realm connections (STUN, hole punching,
and the resulting QUIC path) to a single IP version.
**4**:
The new [`realm.port_mapping`](/configuration/outbound/hysteria2/#realmport_mapping)
inbound and outbound field maintains a UDP port mapping on the local gateway
via UPnP or NAT-PMP, improving hole-punching reliability behind gateways that
support it.
#### 1.14.0-alpha.40
* Add bridge outbound **1**
* Fixes and improvements
**1**:
The new `bridge` outbound is the L3 counterpart of `direct`: it forwards L3
traffic (TCP, UDP and ICMP) from a TUN or other L3 endpoints directly out of a
network interface, without going through L3 to L4 translation. It requires
privileges and is supported on Linux, macOS, rooted Android, and jailbroken iOS.
See [Bridge](/configuration/outbound/bridge/).
#### 1.14.0-alpha.39
* Add L3 forwarding support **1**
* Fixes and improvements
**1**:
Building on the ICMP proxy support introduced in sing-box 1.13.0, TCP and UDP
traffic from L3 inbounds (TUN, WireGuard, and Tailscale) can now be forwarded
directly to WireGuard and Tailscale endpoints at L3, without going through
L3 to L4 translation.
See [Pre-match](/configuration/shared/pre-match/).
#### 1.14.0-alpha.38
* Add Snell protocol support **1**
* Fixes and improvements
**1**:
Surge believes that being closed-source and not proliferated can keep
[Snell](https://kb.nssurge.com/surge-knowledge-base/release-notes/snell)
covert, but this is already impossible in 2026; considering that Snell still
has advantages that other random-traffic protocols do not possess, such as
multiplexing support with complete TCP semantics and traffic-characteristic
diversity, we [implemented it in Go](https://github.com/SagerNet/sing-snell)
instead of reinventing the wheel, with all features except the v5 QUIC proxy,
behavior as consistent with the official implementation as possible, and
performance at least on par with it.
See [Snell Inbound](/configuration/inbound/snell/) and
[Snell Outbound](/configuration/outbound/snell/).
#### 1.13.14
* Fixes and improvements
#### 1.14.0-alpha.33
* Add iOS jailbreak release **1**
* Fixes and improvements
**1**:
A new jailbreak build of the iOS [sing-box for Apple](/clients/apple/) client is
available, distributed as a `.deb` for rootless iOS 15.0+ from
[GitHub Releases](https://github.com/SagerNet/sing-box/releases)
(`SFI-iphoneos-arm64.deb`). Unlike the App Store and TestFlight builds, it can run
a [Tailscale SSH server](/configuration/endpoint/tailscale/#ssh_server) on the
device and supports [process matching](/configuration/route/rule/#process_name)
(`process_name`, `process_path`, `user`, and so on) in route and DNS rules.
#### 1.14.0-alpha.32
* Add dashboard support for the API service **1**
* Add USB/IP service **2**
* Fixes and improvements
**1**:
The [sing-box API service](/configuration/service/api/) can now download, update
and serve [sing-box-dashboard](https://github.com/SagerNet/sing-box-dashboard)
directly over its listener, configured via the new
[`dashboard`](/configuration/service/api/#dashboard) option.
**2**:
New [USB/IP Server](/configuration/service/usbip-server/) and
[USB/IP Client](/configuration/service/usbip-client/) services export and import
USB devices over the [USB/IP](https://usbip.sourceforge.net/) protocol, built on
[sing-usbip](https://github.com/SagerNet/sing-usbip), which adds hotplug while
staying interoperable with standard USB/IP. Exporting config-selected local
devices (`provider: default`) runs via the CLI on Linux, Windows, and macOS and
requires elevated privileges (macOS additionally needs a CGO build and disabled
System Integrity Protection). With `provider: dynamic`, devices are instead
supplied at runtime through the API service by the graphical clients on macOS and
Android, or the [sing-box Dashboard](https://github.com/SagerNet/sing-box-dashboard).
#### 1.14.0-alpha.31
* Fixes and improvements
#### 1.14.0-alpha.30
* Introducing sing-box API service **1**
* Apple/Android: Introducing remote control **2**
* Introducing sing-box Dashboard **3**
* Fixes and improvements
**1**:
The new [sing-box API service](/configuration/service/api/) is a gRPC
server for observing and controlling the running sing-box instance,
exposing the same interface the graphical clients use locally: service
status, logs, outbound groups (selection and URL tests), Clash mode,
connection tracking, and tools such as network quality tests, STUN
tests, and Tailscale operations.
**2**:
The graphical clients for Apple platforms and Android can now control
remote sing-box instances running the API service. Remote servers (URL
and secret) are managed in settings; the dashboard, logs, connections,
groups, and tools pages can then switch between the local service and
remote instances.
**3**:
[sing-box Dashboard](https://github.com/SagerNet/sing-box-dashboard) is
a new web client for the API service, providing almost the same
experience as the graphical clients. A public instance is available at
http://sing-box-dashboard.sagernet.org (shortcut: dash.sing-box.app).
#### 1.14.0-alpha.29
* Fixes and improvements
#### 1.13.13
* Fixes and improvements
#### 1.14.0-alpha.27
* Add Tailscale SSH server **1**
* Fixes and improvements
**1**:
Adds an [`ssh_server`](/configuration/endpoint/tailscale/#ssh_server) field to
[Tailscale](/configuration/endpoint/tailscale/) endpoints, running a Tailscale SSH
server on tailnet port 22. Access is controlled by the SSH ACL in the Tailscale
admin console, which maps each connection to a local user (behavior varies by
platform; iOS and tvOS are not yet supported). The value may be `true` (equivalent
to `{ "enabled": true }`), or an object that additionally sets
[`disable_pty`](/configuration/endpoint/tailscale/#ssh_serverdisable_pty),
[`disable_sftp`](/configuration/endpoint/tailscale/#ssh_serverdisable_sftp), and
[`disable_forwarding`](/configuration/endpoint/tailscale/#ssh_serverdisable_forwarding).
#### 1.14.0-alpha.26
* Add gecko obfs for Hysteria2 **1**
* Fixes and improvements
**1**:
Adds `gecko` as a new QUIC traffic obfuscation type for
[Hysteria2 inbound](/configuration/inbound/hysteria2/#obfstype) and
[outbound](/configuration/outbound/hysteria2/#obfstype), alongside the
existing `salamander`. Gecko supports configurable
[`min_packet_size`](/configuration/inbound/hysteria2/#obfsmin_packet_size)
(default 512) and
[`max_packet_size`](/configuration/inbound/hysteria2/#obfsmax_packet_size)
(default 1200) fields.
#### 1.14.0-alpha.25
* Revert Tailscale endpoint dial fields deprecation and remove `control_http_client` **1**
* Fixes and improvements
**1**:
The `control_http_client` field on
[Tailscale](/configuration/endpoint/tailscale/) endpoints introduced in
`1.14.0-alpha.13` is removed, and the deprecation of
[Dial Fields](/configuration/endpoint/tailscale/#dial-fields) is reverted.
#### 1.13.12
* Update naiveproxy to v148.0.7778.96-1
* Fixes and improvements
#### 1.14.0-alpha.22
* Add Hysteria Realm service and Hysteria2 NAT traversal support **1**
* Fixes and improvements
**1**:
The new [Hysteria Realm service](/configuration/service/hysteria-realm/)
is a rendezvous service for Hysteria2 NAT traversal. A Hysteria2 server
behind NAT registers its STUN-discovered public addresses on a stable
realm endpoint via the new
[`realm`](/configuration/inbound/hysteria2/#realm) inbound field;
clients query the realm via the new
[`realm`](/configuration/outbound/hysteria2/#realm) outbound field to
learn the server's current addresses and perform UDP hole-punching to
establish a direct QUIC connection. Once hole-punching succeeds, all
proxy traffic flows directly between client and server.
#### 1.14.0-alpha.21
* Allow customizing TUN DNS mode and hijack interface DNS by default **1**
* Add mDNS DNS server **2**
* Add `preferred_by` DNS rule item **3**
* Add neighbor-based hostname resolution for the local DNS server **4**
* Update NaiveProxy to 148.0.7778.96-1
* Add more TLS spoof methods and route rule action support **5**
* Fixes and improvements
**1**:
Adds [`dns_mode`](/configuration/inbound/tun/#dns_mode) and
[`dns_address`](/configuration/inbound/tun/#dns_address) on the TUN inbound.
The default `hijack` mode now sets the platform's native interface DNS
(`systemd-resolved` on Linux, per-interface DNS on Windows and Apple) and
installs platform-level DNS hijacking (an `iproute2` rule on Linux,
nftables DNAT when `auto_redirect` is enabled, WFP filters on Windows when
`strict_route` is enabled). Earlier versions did not touch the interface
DNS or the platform firewall.
**2**:
The new [mDNS DNS server](/configuration/dns/server/mdns/) sends queries via
multicast on the local network. The default
[local DNS server](/configuration/dns/server/local/) also routes queries for
`*.local.` and IPv4/IPv6 link-local reverse zones via mDNS on non-Apple
platforms (and via the system resolver on Apple), so an explicit `mdns`
server is only needed to reference it from
[`preferred_by`](/configuration/dns/rule/#preferred_by) or to use it
standalone.
**3**:
The new [`preferred_by`](/configuration/dns/rule/#preferred_by) DNS rule
item matches domains that the listed DNS servers consider their preferred
names. Supported server types are `hosts`, `local`, `mdns`, `tailscale`, and
`resolved`. The [Tailscale](/configuration/dns/server/tailscale/),
[Hosts](/configuration/dns/server/hosts/) and
[Resolved](/configuration/dns/server/resolved/) example pages have been
updated to use this rule item in place of the previous `evaluate` +
`ip_accept_any` + `respond` pattern.
**4**:
Adds [`neighbor_domain`](/configuration/dns/server/local/#neighbor_domain)
on the local DNS server. Listed suffixes (each starting with `.`) cause
A/AAAA queries for single-label hosts under those suffixes to be answered
from the [neighbor resolver](/configuration/shared/neighbor/) instead of
the upstream (for example `[".", ".lan"]`).
**5**:
Adds `wrong-ack`, `wrong-md5`, and `wrong-timestamp`
[spoof methods](/configuration/shared/tls/#spoof_method), and adds
[`tls_spoof`](/configuration/route/rule_action/#tls_spoof) /
[`tls_spoof_method`](/configuration/route/rule_action/#tls_spoof_method)
to route rule actions for per-rule TLS spoofing without outbound TLS settings.
#### 1.14.0-alpha.20
** Fixes and improvements
#### 1.14.0-alpha.19
* Preserve comments between formatting
* Add cipher, MAC, and key exchange algorithm options for SSH outbound **1**
* Add DNS query timeout options **2**
** Fixes and improvements
**1**:
See [SSH](/configuration/outbound/ssh/#cipher).
**2**:
Adds [`dns.timeout`](/configuration/dns/#timeout), with per-query
overrides via [DNS rule action](/configuration/dns/rule_action/#timeout)
and [`resolve` route rule action](/configuration/route/rule_action/#timeout),
and a `timeout` field on
[`domain_resolver`](/configuration/shared/dial/#domain_resolver).
#### 1.14.0-alpha.18
* Add Windows TLS engine **1**
* Fixes and improvements
**1**:
The new `windows` value for outbound TLS
[`engine`](/configuration/shared/tls/#engine) routes the TLS handshake
through Schannel via SSPI. Only available on Windows build 17763 or
later (Windows 10 version 1809, Windows Server 2019, or newer); TLS 1.3
is only negotiated on Windows 11 or Windows Server 2022 and newer.
#### 1.13.11
* Fix process searcher failure introduced in 1.13.9
* Fixes and improvements
#### 1.14.0-alpha.16
* Add ACME profile support for IP address certificates **1**
* Fixes and improvements
**1**:
See [ACME Certificate Provider](/configuration/shared/certificate-provider/acme/#profile).
#### 1.13.10
* Fix process searcher failure introduced in 1.13.9
#### 1.14.0-alpha.15
* Add search domain support for Tailscale DNS **1**
* Fixes and improvements
**1**:
See [Tailscale DNS Server](/configuration/dns/server/tailscale/#accept_search_domain).
#### 1.13.9
* Fixes and improvements
#### 1.14.0-alpha.13
* Unify HTTP client **1**
* Add Apple HTTP and TLS engines **2**
* Unify HTTP/2 and QUIC parameters **3**
* Add TLS spoof **4**
* Fixes and improvements
**1**:
The new top-level [`http_clients`](/configuration/shared/http-client/)
option defines reusable HTTP clients (engine, version, dialer, TLS,
HTTP/2 and QUIC parameters). Components that make outbound HTTP requests
— remote rule-sets, ACME and Cloudflare Origin CA certificate providers,
DERP `verify_client_url`, and the Tailscale `control_http_client` — now
accept an inline HTTP client object or the tag of an `http_clients`
entry, replacing the dial and TLS fields previously inlined in each
component. When the field is omitted, ACME, Cloudflare Origin CA, DERP
and Tailscale dial direct (their existing default).
Remote rule-sets are the only HTTP-using component whose default for an
omitted `http_client` has historically resolved to the default outbound,
not to direct, and a typical configuration contains many of them. To
avoid repeating the same `http_client` block in every rule-set,
[`route.default_http_client`](/configuration/route/#default_http_client)
selects a default rule-set client by tag and is the only field that
consults it. If `default_http_client` is empty and `http_clients` is
non-empty, the first entry is used automatically. The legacy fallback
(use the default outbound when `http_clients` is empty altogether) is
preserved with a deprecation warning and will be removed in sing-box
1.16.0, together with the legacy `download_detour` remote rule-set
option and the legacy dialer fields on Tailscale endpoints.
**2**:
A new `apple` engine is available on Apple platforms in two independent
places:
* [HTTP client `engine`](/configuration/shared/http-client/#engine) —
routes HTTP requests through `NSURLSession`.
* Outbound TLS [`engine`](/configuration/shared/tls/#engine) — routes
the TLS handshake through `Network.framework` for direct TCP TLS
client connections.
The default remains `go`. Both engines come with additional CGO and
framework memory overhead and platform restrictions documented on each
field.
**3**:
[HTTP/2](/configuration/shared/http2/) and
[QUIC](/configuration/shared/quic/) parameters
(`idle_timeout`, `keep_alive_period`, `stream_receive_window`,
`connection_receive_window`, `max_concurrent_streams`,
`initial_packet_size`, `disable_path_mtu_discovery`) are now shared
across QUIC-based outbounds
([Hysteria](/configuration/outbound/hysteria/),
[Hysteria2](/configuration/outbound/hysteria2/),
[TUIC](/configuration/outbound/tuic/)) and HTTP clients running HTTP/2
or HTTP/3.
This deprecates the Hysteria v1 tuning fields `recv_window_conn`,
`recv_window`, `recv_window_client`, `max_conn_client` and
`disable_mtu_discovery`; they will be removed in sing-box 1.16.0.
**4**:
Added outbound TLS [`spoof`](/configuration/shared/tls/#spoof) and
[`spoof_method`](/configuration/shared/tls/#spoof_method) fields. When
enabled, a forged ClientHello carrying a whitelisted SNI is sent before
the real handshake to fool SNI-filtering middleboxes. Requires
`CAP_NET_RAW` + `CAP_NET_ADMIN` or root on Linux and macOS, and
Administrator privileges on Windows (ARM64 is not supported). IP-literal
server names are rejected.
#### 1.14.0-alpha.12
* Fix fake-ip DNS server should return SUCCESS when address type is not configured
* Fixes and improvements
#### 1.13.8
* Update naiveproxy to v147.0.7727.49-1
* Fix fake-ip DNS server should return SUCCESS when address type is not configured
* Fixes and improvements
#### 1.14.0-alpha.11
* Add optimistic DNS cache **1**
* Update NaiveProxy to 147.0.7727.49
* Fixes and improvements
**1**:
Optimistic DNS cache returns an expired cached response immediately while
refreshing it in the background, reducing tail latency for repeated
queries. Enabled via [`optimistic`](/configuration/dns/#optimistic)
in DNS options, and can be persisted across restarts with the new
[`store_dns`](/configuration/experimental/cache-file/#store_dns) cache
file option. A per-query
[`disable_optimistic_cache`](/configuration/dns/rule_action/#disable_optimistic_cache)
field is also available on DNS rule actions and the `resolve` route rule
action.
This deprecates the `independent_cache` DNS option (the DNS cache now
always keys by transport) and the `store_rdrc` cache file option
(replaced by `store_dns`); both will be removed in sing-box 1.16.0.
See [Migration](/migration/#migrate-independent-dns-cache).
#### 1.14.0-alpha.10
* Add `evaluate` DNS rule action and Response Match Fields **1**
* `ip_version` and `query_type` now also take effect on internal DNS lookups **2**
* Add `package_name_regex` route, DNS and headless rule item **3**
* Add cloudflared inbound **4**
* Fixes and improvements
**1**:
Response Match Fields
([`response_rcode`](/configuration/dns/rule/#response_rcode),
[`response_answer`](/configuration/dns/rule/#response_answer),
[`response_ns`](/configuration/dns/rule/#response_ns),
and [`response_extra`](/configuration/dns/rule/#response_extra))
match the evaluated DNS response. They are gated by the new
[`match_response`](/configuration/dns/rule/#match_response) field and
populated by a preceding
[`evaluate`](/configuration/dns/rule_action/#evaluate) DNS rule action;
the evaluated response can also be returned directly by a
[`respond`](/configuration/dns/rule_action/#respond) action.
This deprecates the Legacy Address Filter Fields (`ip_cidr`,
`ip_is_private` without `match_response`) in DNS rules, the Legacy
`strategy` DNS rule action option, and the Legacy
`rule_set_ip_cidr_accept_empty` DNS rule item; all three will be removed
in sing-box 1.16.0.
See [Migration](/migration/#migrate-address-filter-fields-to-response-matching).
**2**:
`ip_version` and `query_type` in DNS rules, together with `query_type` in
referenced rule-sets, now take effect on every DNS rule evaluation,
including matches from internal domain resolutions that do not target a
specific DNS server (for example a `resolve` route rule action without
`server` set). In earlier versions they were silently ignored in that
path. Combining these fields with any of the legacy DNS fields deprecated
in **1** in the same DNS configuration is no longer supported and is
rejected at startup.
See [Migration](/migration/#ip_version-and-query_type-behavior-changes-in-dns-rules).
**3**:
See [Route Rule](/configuration/route/rule/#package_name_regex),
[DNS Rule](/configuration/dns/rule/#package_name_regex) and
[Headless Rule](/configuration/rule-set/headless-rule/#package_name_regex).
**4**:
See [Cloudflared](/configuration/inbound/cloudflared/).
#### 1.13.7
* Fixes and improvements
* Fixes and improvement
#### 1.13.6
* Fixes and improvements
#### 1.14.0-alpha.8
* Add BBR profile and hop interval randomization for Hysteria2 **1**
* Fixes and improvements
**1**:
See [Hysteria2 Inbound](/configuration/inbound/hysteria2/#bbr_profile) and [Hysteria2 Outbound](/configuration/outbound/hysteria2/#bbr_profile).
#### 1.13.5
* Fixes and improvements
#### 1.14.0-alpha.7
* Fixes and improvements
#### 1.13.4
* Fixes and improvements
#### 1.14.0-alpha.4
* Refactor ACME support to certificate provider system **1**
* Add Cloudflare Origin CA certificate provider **2**
* Add Tailscale certificate provider **3**
* Fixes and improvements
**1**:
See [Certificate Provider](/configuration/shared/certificate-provider/) and [Migration](/migration/#migrate-inline-acme-to-certificate-provider).
**2**:
See [Cloudflare Origin CA](/configuration/shared/certificate-provider/cloudflare-origin-ca).
**3**:
See [Tailscale](/configuration/shared/certificate-provider/tailscale).
#### 1.13.3
* Add OpenWrt and Alpine APK packages to release **1**
@@ -104,6 +922,59 @@ from [SagerNet/go](https://github.com/SagerNet/go).
See [OCM](/configuration/service/ocm).
#### 1.12.24
* Fixes and improvements
#### 1.14.0-alpha.2
* Add OpenWrt and Alpine APK packages to release **1**
* Backport to macOS 10.13 High Sierra **2**
* OCM service: Add WebSocket support for Responses API **3**
* Fixes and improvements
**1**:
Alpine APK files use `linux` in the filename to distinguish from OpenWrt APKs which use the `openwrt` prefix:
- OpenWrt: `sing-box_{version}_openwrt_{architecture}.apk`
- Alpine: `sing-box_{version}_linux_{architecture}.apk`
**2**:
Legacy macOS binaries (with `-legacy-macos-10.13` suffix) now support
macOS 10.13 High Sierra, built using Go 1.25 with patches
from [SagerNet/go](https://github.com/SagerNet/go).
**3**:
See [OCM](/configuration/service/ocm).
#### 1.14.0-alpha.1
* Add `source_mac_address` and `source_hostname` rule items **1**
* Add `include_mac_address` and `exclude_mac_address` TUN options **2**
* Update NaiveProxy to 145.0.7632.159 **3**
* Fixes and improvements
**1**:
New rule items for matching LAN devices by MAC address and hostname via neighbor resolution.
Supported on Linux, macOS, or in graphical clients on Android and macOS.
See [Route Rule](/configuration/route/rule/#source_mac_address), [DNS Rule](/configuration/dns/rule/#source_mac_address) and [Neighbor Resolution](/configuration/shared/neighbor/).
**2**:
Limit or exclude devices from TUN routing by MAC address.
Only supported on Linux with `auto_route` and `auto_redirect` enabled.
See [TUN](/configuration/inbound/tun/#include_mac_address).
**3**:
This is not an official update from NaiveProxy. Instead, it's a Chromium codebase update maintained by Project S.
#### 1.13.2
* Fixes and improvements
+12
View File
@@ -4,6 +4,18 @@ icon: material/arrange-bring-forward
## 1.14.0
### Migrate the macOS standalone client data
Apple platform clients migrated to a new Apple developer account, so the macOS standalone client
is a new application, and profiles and settings are not inherited.
Before starting sing-box 1.14.0-rc.2 or later, they can be migrated using the following command:
```bash
mv ~/Library/Group\ Containers/287TTNZF8L.io.nekohasekai.sfavt \
~/Library/Group\ Containers/P8XK3KHB48.io.nekohasekai.sfamt
```
### Migrate inline ACME to certificate provider
Inline ACME options in TLS are deprecated and can be replaced by certificate providers.