Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1297 commits
Select commit Hold shift + click to select a range
f72c4c1
Fix rules lock
nekohasekai Apr 9, 2026
32a34ef
Fix darwin local DNS transport
nekohasekai Apr 10, 2026
c80f4ad
tools: Tailscale status
nekohasekai Apr 10, 2026
e80b662
Un-deprecate `ip_accept_any` DNS rule item
nekohasekai Apr 10, 2026
5393025
documentation: Fixes
nekohasekai Apr 10, 2026
49704b4
Add `package_name_regex` route, DNS and headless rule item
nekohasekai Apr 10, 2026
1b5fd56
platform: Wrap command RPC error returns with E.Cause
nekohasekai Apr 10, 2026
34fdc29
Fix lint errors
nekohasekai Apr 10, 2026
00adb23
Add cloudflared inbound
nekohasekai Apr 10, 2026
83c6793
documentation: Fix missing update for `ip_version` and `query_type`
nekohasekai Apr 10, 2026
bf3454e
Fix stun test
nekohasekai Apr 10, 2026
845e94d
Fix darwin cgo DNS again
nekohasekai Apr 10, 2026
d89783b
Fix tailscale error
nekohasekai Apr 11, 2026
ca63351
Add optimistic DNS cache
nekohasekai Apr 11, 2026
a6fd060
oom-killer: Record report before reset network
nekohasekai Apr 14, 2026
4fdfda2
Refactor: HTTP clients, unified HTTP2/QUIC options, Apple engines
nekohasekai Apr 14, 2026
baa5556
Standardize hosts path
nekohasekai Apr 15, 2026
f2cf356
Add TLS spoof support
nekohasekai Apr 15, 2026
6288bb9
Fix legacy rule-set download_detour blocked by empty direct check
nekohasekai Apr 15, 2026
147cc00
Reject pure-IP rule-set references without match_response
nekohasekai Apr 15, 2026
ed2ca07
Fix use-after-free of pooled value buffers in bbolt Batch writes
nekohasekai Apr 15, 2026
78aef89
Fix cloudflared quic
nekohasekai Apr 16, 2026
d1cb61e
Reject IP literal server name with TLS spoof
nekohasekai Apr 16, 2026
031a147
Fix macOS tlsspoof
nekohasekai Apr 17, 2026
594a9cd
Scope HTTP/2 fallback and HTTP/3 broken state per authority
nekohasekai Apr 17, 2026
b9235e9
Bump version
nekohasekai Mar 7, 2026
59126c9
Defer implicit default HTTP client fallback to first use
nekohasekai Apr 17, 2026
e98bf30
Strip EDNS padding from upstream DNS responses
nekohasekai Apr 17, 2026
4c01502
Fix Apple TLS metadata capture
nekohasekai Apr 18, 2026
beaa6bd
Fix tls-spoof
nekohasekai Apr 17, 2026
baaedc7
sing: Fix interface finder
nekohasekai Apr 18, 2026
6ae8461
Bump version
nekohasekai Apr 18, 2026
0bd109d
sing: Fix interface finder
nekohasekai Apr 19, 2026
ca76c56
daemon: Fix registry leak
nekohasekai Apr 19, 2026
3a236d9
fswatch: Fix close
nekohasekai Apr 19, 2026
a80ef94
Fix tailscale endpoint early-start close panic
nekohasekai Apr 19, 2026
fb61987
tun: memmod: be more resilient toward weird PE files
nekohasekai Apr 19, 2026
9b72b35
sing: Fix UoT connect race
nekohasekai Apr 19, 2026
b3606e3
release: fix apk package file ownership
nekohasekai Apr 19, 2026
3124cdd
Fix windows bssid matching
nekohasekai Apr 19, 2026
e4bc459
Skip process search for non-local source addresses
nekohasekai Apr 19, 2026
60dd7ea
Simplify lifecycle logs
nekohasekai Apr 19, 2026
b3523ab
tun: Fix multi include/exclude interfaces
nekohasekai Apr 19, 2026
c3de6a2
documentation: Remove warp ads
nekohasekai Apr 19, 2026
d942ecc
Bump version 1.13.9
nekohasekai Apr 19, 2026
88f640c
new dnstt transport
hiddify-com Feb 9, 2026
3d9d633
fix workflow
hiddify-com Feb 9, 2026
b0e5b76
fix workflow
hiddify-com Feb 9, 2026
2ee1e43
add v2raybuild
hiddify-com Feb 9, 2026
3153bf2
fix
hiddify-com Feb 9, 2026
67f0bc4
fix connection temporary
hiddify-com Feb 10, 2026
c872b3e
add cache timeout
hiddify-com Feb 10, 2026
05b9ed1
add easier replace version management
hiddify-com Feb 12, 2026
fff4d88
fix workflow
hiddify-com Feb 12, 2026
09c4c0e
fix: dependency to cache in monitoring
hiddify-com Feb 12, 2026
dd0989d
fix: set retention days for uploaded builds
hiddify-com Feb 12, 2026
6f13b1a
new: better dependency monitoring, better warp availblity check and b…
hiddify-com Feb 13, 2026
7c16eba
new: ssh inbound with uot support
hiddify-com Feb 15, 2026
74f18f6
new: add multiport support for mieru
hiddify-com Feb 15, 2026
8a7e1a0
disable build of all arch
hiddify-com Feb 15, 2026
d7d6110
add mieru options more compatible with original one
hiddify-com Feb 15, 2026
be7b1c4
faster CI
hiddify-com Feb 15, 2026
7fedc7f
new: use independent outbounds for udp and tcp
hiddify-com Feb 15, 2026
9985da3
better wireguard availblity check
hiddify-com Feb 15, 2026
c0cfc27
fix: issues
hiddify-com Feb 15, 2026
8f52ecb
fix: bug
hiddify-com Feb 15, 2026
b93a104
add MTU support for warp
hiddify-com Feb 19, 2026
161f477
fix: udp connection timeout
hiddify-com Mar 5, 2026
dd90da0
new: add dnstt outbound
hiddify-com Mar 5, 2026
5eec676
new: update to vaydn 0.2.5 with auto search
hiddify-com Mar 29, 2026
6b8e9af
new: dnstt multi resolver
hiddify-com Apr 1, 2026
110f89c
new:default use of multi resolver
hiddify-com Apr 1, 2026
2e42cab
use predefined dns server first then search
hiddify-com Apr 1, 2026
eac533a
Merge upstream sing-box v1.14.0-alpha.14 into extended
QuantIntellect Apr 20, 2026
9ab1be8
fix: remove duplicate Endpoint() method in box.go
QuantIntellect Apr 20, 2026
5a42b25
fix: resolve build errors from upstream merge
QuantIntellect Apr 20, 2026
92130db
fix: add replace directives to test module
QuantIntellect Apr 20, 2026
71f6a2a
Fix process search skipped for TUN
nekohasekai Apr 21, 2026
83d3a6d
Hide lifecycle logs for fast operations
nekohasekai Apr 21, 2026
8947cb2
sing: Fix UoT write race
nekohasekai Apr 21, 2026
a3fc14f
Bump version
nekohasekai Apr 21, 2026
3312b8d
Clean up DNS transports
nekohasekai Apr 22, 2026
f102ef1
Fix process search skipped for Android again
nekohasekai Apr 22, 2026
553cfa1
Bump version
nekohasekai Apr 22, 2026
3e74869
feat(service): add smart_dns_pool — local DNS server fronting many up…
Apr 27, 2026
667e621
chore(deps): bump hmrd_multi_resolver_dns to post-PR#4 main tip
Apr 27, 2026
ddb757a
Reduce built-in certificate store memory
nekohasekai Apr 27, 2026
034dc90
Merge upstream/extended into merge-upstream-v1.14.0-alpha.14
claude Apr 29, 2026
79bfc31
Merge pull request #1 from QuantIntellect/claude/resolve-merge-confli…
QuantIntellect Apr 29, 2026
3ceadb0
Merge pull request #18 from QuantIntellect/merge-upstream-v1.14.0-alp…
hiddify-com Apr 29, 2026
2d8f97b
feat: add GooseRelay outbound under protocol/hiddify/gooserelay
QuantIntellect Apr 29, 2026
6bc48c0
style(constant): re-align //H comment column after adding TypeGooseRelay
QuantIntellect Apr 29, 2026
c7cf64d
refactor(gooserelay): rename defaultHandshakeBudget to defaultDiagnos…
QuantIntellect Apr 29, 2026
8bf7a0a
fix(gooserelay): check tunnel_key length before attempting hex decode
QuantIntellect Apr 29, 2026
25a163d
fix(gooserelay): reject script_keys containing URL separators
QuantIntellect Apr 29, 2026
bccd6e7
feat(dnstt): route resolvers through hmrd_multi_resolver_dns smart pool
QuantIntellect Apr 29, 2026
1a01efb
refactor(gooserelay): use context-aware logger methods
QuantIntellect Apr 29, 2026
63f71e4
fix(gooserelay): tie diagnose probe to runCtx so Close cancels it
QuantIntellect Apr 29, 2026
fbd73fb
feat(gooserelay): probe all script_keys concurrently, ready on first …
QuantIntellect Apr 29, 2026
71acba5
test(gooserelay): add option-validation table tests
QuantIntellect Apr 29, 2026
a73acd5
refactor(gooserelay): switch to upstream's goose SDK package
QuantIntellect Apr 29, 2026
e30f158
Merge pull request #21 from QuantIntellect/claude/inspiring-turing-9e…
hiddify-com Apr 29, 2026
d1c53d2
release: Add replace_macos_standalone make target
nekohasekai May 3, 2026
6548c17
dns: Fix deadline
nekohasekai May 4, 2026
6475a5e
Skip kickWriteHandshake for server first protocols
nekohasekai May 8, 2026
d166f0d
dns: Fix conn pool leak
nekohasekai May 11, 2026
383a182
dns: Refactor reordered pool
nekohasekai May 11, 2026
2f139af
Fix naive inbound close
nekohasekai May 12, 2026
b4c6255
Fix tailscale crash at start
nekohasekai May 12, 2026
76880eb
Update naiveproxy to v148.0.7778.96-1
nekohasekai May 13, 2026
b6f7d62
sing: Update contextjson
nekohasekai May 13, 2026
338aa55
Update golangci-lint configuration
nekohasekai May 13, 2026
5e7fd7a
Fix lint errors
nekohasekai May 13, 2026
2b995ea
Run lint for all platforms in workflow
nekohasekai May 13, 2026
1086ab2
Bump version 1.13.12
nekohasekai May 14, 2026
443bec7
Add MAC and hostname rule items
nekohasekai Mar 3, 2026
9e548cb
Add Android support for MAC and hostname rule items
nekohasekai Mar 4, 2026
d0fd6f6
Add macOS support for MAC and hostname rule items
nekohasekai Mar 6, 2026
f0a057c
documentation: Update descriptions for neighbor rules
nekohasekai Mar 6, 2026
4c6ff22
Refactor ACME support to certificate provider
nekohasekai Mar 23, 2026
914fc9c
Add BBR profile and hop interval randomization for Hysteria2
nekohasekai Mar 30, 2026
17a63d5
platform: Add OOM Report & Crash Report
nekohasekai Apr 2, 2026
01efb67
Also enable certificate store by default on Apple platforms
nekohasekai Apr 7, 2026
6fa641a
Add evaluate DNS rule action and related rule items
nekohasekai Apr 7, 2026
f294557
platform: Fix set local
nekohasekai Apr 7, 2026
b9ac437
Fix deprecated warning double-formatting on localized clients
nekohasekai Apr 7, 2026
3cfbfbb
oom-killer: Free memory on pressure notification and use gradual inte…
nekohasekai Apr 7, 2026
3b5e8c8
tools: Network Quality & STUN
nekohasekai Apr 8, 2026
11b7ffd
platform: Fix darwin signal handler
nekohasekai Apr 9, 2026
7d382fe
tools: Tailscale status
nekohasekai Apr 9, 2026
c5a3e59
Revert "Also enable certificate store by default on Apple platforms"
nekohasekai Apr 9, 2026
1ee527a
Fix rules lock
nekohasekai Apr 9, 2026
775f683
Fix darwin local DNS transport
nekohasekai Apr 10, 2026
972a035
tools: Tailscale status
nekohasekai Apr 10, 2026
825f86a
Un-deprecate `ip_accept_any` DNS rule item
nekohasekai Apr 10, 2026
39dda9f
documentation: Fixes
nekohasekai Apr 10, 2026
0a9d8f9
Add `package_name_regex` route, DNS and headless rule item
nekohasekai Apr 10, 2026
0dc7d6e
platform: Wrap command RPC error returns with E.Cause
nekohasekai Apr 10, 2026
72f8997
Fix lint errors
nekohasekai Apr 10, 2026
0cc5958
Add cloudflared inbound
nekohasekai Apr 10, 2026
9b44e1b
documentation: Fix missing update for `ip_version` and `query_type`
nekohasekai Apr 10, 2026
914a6c5
Fix stun test
nekohasekai Apr 10, 2026
f7cf93e
Fix darwin cgo DNS again
nekohasekai Apr 10, 2026
b207d37
Fix tailscale error
nekohasekai Apr 11, 2026
6f23a96
Add optimistic DNS cache
nekohasekai Apr 11, 2026
04dc9fc
oom-killer: Record report before reset network
nekohasekai Apr 14, 2026
195e129
Refactor: HTTP clients, unified HTTP2/QUIC options, Apple engines
nekohasekai Apr 14, 2026
69f9f02
Standardize hosts path
nekohasekai Apr 15, 2026
227e0ca
Add TLS spoof support
nekohasekai Apr 15, 2026
7fe1f47
Fix legacy rule-set download_detour blocked by empty direct check
nekohasekai Apr 15, 2026
8224f2e
Reject pure-IP rule-set references without match_response
nekohasekai Apr 15, 2026
719a002
Fix use-after-free of pooled value buffers in bbolt Batch writes
nekohasekai Apr 15, 2026
644b9bc
Reject IP literal server name with TLS spoof
nekohasekai Apr 16, 2026
6e59653
Fix macOS tlsspoof
nekohasekai Apr 17, 2026
463d808
Scope HTTP/2 fallback and HTTP/3 broken state per authority
nekohasekai Apr 17, 2026
eedd925
Defer implicit default HTTP client fallback to first use
nekohasekai Apr 17, 2026
596c85a
Strip EDNS padding from upstream DNS responses
nekohasekai Apr 17, 2026
e9bf691
Fix Apple TLS metadata capture
nekohasekai Apr 18, 2026
b656af6
Fix tls-spoof
nekohasekai Apr 17, 2026
6d1803f
Add search domain support for Tailscale DNS
nekohasekai Apr 20, 2026
5f8d846
Log DNS optimistic background refresh outcomes
nekohasekai Apr 21, 2026
a6c4539
Fix Tailscale search domain response name mismatch
nekohasekai Apr 21, 2026
4b9221f
Fix goroutine leak in networkquality tool
nekohasekai Apr 21, 2026
88486da
Add ACME profile support for IP address certificates
nekohasekai Mar 26, 2026
00149d8
Fix ACME HTTP-01 challenge for IPv6 literal addresses
nekohasekai Apr 21, 2026
881736a
platform: Improve oom-killer
nekohasekai Apr 21, 2026
58a318f
Fix darwin cgo DNS again
nekohasekai Apr 22, 2026
77142b6
Fix stderr deprecated manager
nekohasekai Apr 23, 2026
770a0c7
Improve UDP batch support
nekohasekai Apr 24, 2026
d7f4cef
Add Windows TLS engine
nekohasekai Apr 24, 2026
a31244b
tun: Add compatibility with docker bridge
nekohasekai Apr 24, 2026
b268fe0
Preserve comments between formatting
nekohasekai Apr 28, 2026
73fc988
Improve oom-killer
nekohasekai Apr 28, 2026
5d0c132
tun: Add read waiter support for gVisor conn
nekohasekai Apr 28, 2026
19f696d
ssh: Add cipher, MAC, and key exchange configuration
nekohasekai Apr 28, 2026
7b258f2
dns: Add timeout configuration
nekohasekai Apr 28, 2026
3076764
Fix tailscale start dependencies
nekohasekai Apr 28, 2026
d701464
dns: Add neighbor-based hostname resolution to local server
nekohasekai Apr 29, 2026
d02a055
dns: Add preferred_by rule item
nekohasekai Apr 29, 2026
93d3869
dns: Add mDNS server
nekohasekai Apr 30, 2026
ac900b1
Allow customizing TUN DNS mode and hijack interface DNS by default
nekohasekai May 2, 2026
ef06e4c
Add more spoof method
macronut Apr 29, 2026
895bc40
Fix reset network
nekohasekai May 5, 2026
0ce4cbd
Add hysteria2 realm service and support
nekohasekai May 10, 2026
6275582
Update hysteria2 realm
nekohasekai May 11, 2026
5f2bedf
Fix TLS server close
nekohasekai May 12, 2026
81dd85f
realm: Add stun retry and lazy server start
nekohasekai May 12, 2026
588c8ba
Fix hysteria2 realm server
nekohasekai May 12, 2026
21e27a2
Fix lint errors
nekohasekai May 14, 2026
6b07a22
Bump version
nekohasekai Mar 7, 2026
646c7ac
dns: Fix DHCP reset
nekohasekai May 17, 2026
4138054
Rebase wireguard-go to official
nekohasekai May 17, 2026
35cf647
Fix shadowtls handshake
nekohasekai May 17, 2026
27f5835
cronet: Fix vendor package
nekohasekai May 18, 2026
131326f
tun: Fix unprivileged ping conn leak
nekohasekai May 19, 2026
db5fcc6
tun: Fix IPv6 UDP packet leak in system stack
nekohasekai May 19, 2026
0ae672d
oom-killer: Remove log "OOM draft discarded"
nekohasekai May 19, 2026
0a921bb
tun: Handle existing wintun adapter on restart
nekohasekai May 19, 2026
279f815
route: Refetch rule-set when cache restore fails
nekohasekai May 19, 2026
cf06742
process: Fix panic when package manager is unavailable on Android
nekohasekai May 19, 2026
8785b39
tailscale: Revert dialer deprecation and remove control_http_client
nekohasekai May 20, 2026
9f3206d
tailscale: Fix handle peer DNS query
nekohasekai May 20, 2026
bb7405e
gvisor: Fix dialing to self addresses
nekohasekai May 20, 2026
ae9a2a0
realm: Open separate v4 and v6 packet conns on client
nekohasekai May 20, 2026
b5ac202
Update Go to 1.25.10
nekohasekai May 20, 2026
e7891c9
Fix tailscale
nekohasekai May 21, 2026
f3458a9
tailscale: Add runtime exit node API
nekohasekai May 21, 2026
b37b6b1
tailscale: Expose more peer info fields
nekohasekai May 21, 2026
9bc35c4
Fix tailscale dns
nekohasekai May 21, 2026
33dfec2
sing: Fix comment loop
nekohasekai May 22, 2026
812a8fd
Bump version
nekohasekai May 20, 2026
72ce97f
tun: Revert bad changes
nekohasekai May 24, 2026
3488377
daemon: Add Tailssh
nekohasekai May 25, 2026
87c36ab
hysteria2: Add gecko obfs
nekohasekai May 25, 2026
0b5eea7
tools: Fix mising cleanup
nekohasekai May 26, 2026
a99fe60
release: Fix android build
nekohasekai May 26, 2026
b6c416b
Bump version
nekohasekai May 25, 2026
d28365c
Merge branch 'extended' into feat/smart-dns-pool-service
hiddify-com May 28, 2026
2f648d7
Merge pull request #20 from hiddifyafk/feat/smart-dns-pool-service
hiddify-com May 28, 2026
7196f71
Merge branch 'extended' into claude/exciting-williams-e000eb
hiddify-com May 28, 2026
d755577
Merge pull request #22 from hiddifyafk/claude/exciting-williams-e000eb
hiddify-com May 28, 2026
fcde603
merge: integrate SagerNet sing-box testing into hiddify extended fork
hiddify-com May 29, 2026
7d0cda4
fix: restore hiddify constants and sync upstream sing module versions…
hiddify-com May 29, 2026
9ba51e1
fix: restore upstream core platform code lost in merge
hiddify-com May 29, 2026
61de8d9
fix: align connection handler API with upstream sing-box testing
hiddify-com May 29, 2026
15e87a4
fix: sync DNS adapter, certificate store, and local transport with up…
hiddify-com May 29, 2026
766c603
fix: restore Tailscale adapter types and daemon gRPC from upstream
hiddify-com May 29, 2026
820f7b1
fix: restore TLSSpoof inbound context fields from upstream testing
hiddify-com May 29, 2026
b820335
feat: keep hiddify config options after upstream merge
hiddify-com May 29, 2026
9805b32
fix: extend cachefile and traffic stats for hiddify without breaking …
hiddify-com May 29, 2026
ea859ad
Add Snell protocol
reF1nd May 22, 2026
fe61219
Add simple-obfs support for shadowsocks inbound
reF1nd May 22, 2026
cb86e6e
Add vless encryption
shtorm-7 Feb 26, 2026
0dabac4
Update xhttp
shtorm-7 Feb 22, 2026
b56e6cd
Update xhttp examples
shtorm-7 Feb 22, 2026
68751a2
Add examples
shtorm-7 Feb 26, 2026
3020f37
Fix examples
shtorm-7 Feb 26, 2026
324e3bf
feat: add MASQUE outbound protocol from sing-box-extended
hiddify-com May 29, 2026
acc50b4
fix: integrate MASQUE and VLESS merges with hiddify fork APIs
hiddify-com May 29, 2026
b6020d0
chore: add and fix example configs with validation script
hiddify-com May 29, 2026
09088b9
add amnezia, warp with amnezia
hiddify-com May 31, 2026
e3bef92
update sum
hiddify-com May 31, 2026
ec45fbd
feat(firebasetunnel): add option types and outbound constants
hiddifydeveloper Jun 29, 2026
c652783
feat(firebasetunnel): port Firebase REST client and chunk relay core
hiddifydeveloper Jun 29, 2026
6f8c230
feat(firebasetunnel): add client/server endpoints and register them
hiddifydeveloper Jun 29, 2026
6f6dbff
test(firebasetunnel): add unit tests for compress, crypto, and session
hiddifydeveloper Jun 29, 2026
ae45f7e
docs(firebasetunnel): add protocol docs and changelog entry
hiddifydeveloper Jun 29, 2026
19b49e7
security(firebasetunnel): HMAC integrity + session-ID AAD binding
hiddifydeveloper Jun 29, 2026
e4c359a
test(firebasetunnel): SSE fake server, E2E relay tests, fuzz targets
hiddifydeveloper Jun 29, 2026
7378761
refactor(firebasetunnel): merge client/server into single Endpoint type
hiddifydeveloper Jun 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
31 changes: 31 additions & 0 deletions .fpm_openwrt
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
-s dir
--name sing-box
--category net
--license GPL-3.0-or-later
--description "The universal proxy platform."
--url "https://sing-box.sagernet.org/"
--maintainer "nekohasekai <contact-git@sekai.icu>"
--no-deb-generate-changes

--config-files /etc/config/sing-box
--config-files /etc/sing-box/config.json

--depends ca-bundle
--depends kmod-inet-diag
--depends kmod-tun
--depends firewall4
--depends kmod-nft-queue

--before-remove release/config/openwrt.prerm

release/config/config.json=/etc/sing-box/config.json

release/config/openwrt.conf=/etc/config/sing-box
release/config/openwrt.init=/etc/init.d/sing-box
release/config/openwrt.keep=/lib/upgrade/keep.d/sing-box

release/completions/sing-box.bash=/usr/share/bash-completion/completions/sing-box.bash
release/completions/sing-box.fish=/usr/share/fish/vendor_completions.d/sing-box.fish
release/completions/sing-box.zsh=/usr/share/zsh/site-functions/_sing-box

LICENSE=/usr/share/licenses/sing-box/LICENSE
23 changes: 23 additions & 0 deletions .fpm_pacman
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
-s dir
--name sing-box
--category net
--license GPL-3.0-or-later
--description "The universal proxy platform."
--url "https://sing-box.sagernet.org/"
--maintainer "nekohasekai <contact-git@sekai.icu>"
--config-files etc/sing-box/config.json
--after-install release/config/sing-box.postinst

release/config/config.json=/etc/sing-box/config.json

release/config/sing-box.service=/usr/lib/systemd/system/sing-box.service
release/config/sing-box@.service=/usr/lib/systemd/system/sing-box@.service
release/config/sing-box.sysusers=/usr/lib/sysusers.d/sing-box.conf
release/config/sing-box.rules=usr/share/polkit-1/rules.d/sing-box.rules
release/config/sing-box-split-dns.xml=/usr/share/dbus-1/system.d/sing-box-split-dns.conf

release/completions/sing-box.bash=/usr/share/bash-completion/completions/sing-box.bash
release/completions/sing-box.fish=/usr/share/fish/vendor_completions.d/sing-box.fish
release/completions/sing-box.zsh=/usr/share/zsh/site-functions/_sing-box

LICENSE=/usr/share/licenses/sing-box/LICENSE
26 changes: 26 additions & 0 deletions .fpm_systemd
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
-s dir
--name sing-box
--category net
--license GPL-3.0-or-later
--description "The universal proxy platform."
--url "https://sing-box.sagernet.org/"
--vendor SagerNet
--maintainer "nekohasekai <contact-git@sekai.icu>"
--deb-field "Bug: https://github.com/SagerNet/sing-box/issues"
--no-deb-generate-changes
--config-files /etc/sing-box/config.json
--after-install release/config/sing-box.postinst

release/config/config.json=/etc/sing-box/config.json

release/config/sing-box.service=/usr/lib/systemd/system/sing-box.service
release/config/sing-box@.service=/usr/lib/systemd/system/sing-box@.service
release/config/sing-box.sysusers=/usr/lib/sysusers.d/sing-box.conf
release/config/sing-box.rules=usr/share/polkit-1/rules.d/sing-box.rules
release/config/sing-box-split-dns.xml=/usr/share/dbus-1/system.d/sing-box-split-dns.conf

release/completions/sing-box.bash=/usr/share/bash-completion/completions/sing-box.bash
release/completions/sing-box.fish=/usr/share/fish/vendor_completions.d/sing-box.fish
release/completions/sing-box.zsh=/usr/share/zsh/site-functions/_sing-box

LICENSE=/usr/share/licenses/sing-box/LICENSE
1 change: 1 addition & 0 deletions .github/CRONET_GO_VERSION
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
b3eec8134aec1387d850e0671dd8531e2e6140b0
94 changes: 94 additions & 0 deletions .github/build_alpine_apk.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
#!/usr/bin/env bash

set -e -o pipefail

prepare_apk_root() {
# apk mkpkg resolves owner/group names through --root/etc/{passwd,group}.
APK_ROOT_DIR=$(mktemp -d)
mkdir -p "$APK_ROOT_DIR/etc"
cat > "$APK_ROOT_DIR/etc/passwd" <<EOF
root:x:$(id -u):$(id -g):root:/root:/sbin/nologin
EOF
cat > "$APK_ROOT_DIR/etc/group" <<EOF
root:x:$(id -g):root
EOF
}

ARCHITECTURE="$1"
VERSION="$2"
BINARY_PATH="$3"
OUTPUT_PATH="$4"

if [ -z "$ARCHITECTURE" ] || [ -z "$VERSION" ] || [ -z "$BINARY_PATH" ] || [ -z "$OUTPUT_PATH" ]; then
echo "Usage: $0 <architecture> <version> <binary_path> <output_path>"
exit 1
fi

PROJECT=$(cd "$(dirname "$0")/.."; pwd)

# Convert version to APK format:
# 1.13.0-beta.8 -> 1.13.0_beta8-r0
# 1.13.0-rc.3 -> 1.13.0_rc3-r0
# 1.13.0 -> 1.13.0-r0
APK_VERSION=$(echo "$VERSION" | sed -E 's/-([a-z]+)\.([0-9]+)/_\1\2/')
APK_VERSION="${APK_VERSION}-r0"

ROOT_DIR=$(mktemp -d)
prepare_apk_root
trap 'rm -rf "$ROOT_DIR" "$APK_ROOT_DIR"' EXIT

# Binary
install -Dm755 "$BINARY_PATH" "$ROOT_DIR/usr/bin/sing-box"

# Config files
install -Dm644 "$PROJECT/release/config/config.json" "$ROOT_DIR/etc/sing-box/config.json"
install -Dm755 "$PROJECT/release/config/sing-box.initd" "$ROOT_DIR/etc/init.d/sing-box"
install -Dm644 "$PROJECT/release/config/sing-box.confd" "$ROOT_DIR/etc/conf.d/sing-box"

# Service files
install -Dm644 "$PROJECT/release/config/sing-box.service" "$ROOT_DIR/usr/lib/systemd/system/sing-box.service"
install -Dm644 "$PROJECT/release/config/sing-box@.service" "$ROOT_DIR/usr/lib/systemd/system/sing-box@.service"

# Completions
install -Dm644 "$PROJECT/release/completions/sing-box.bash" "$ROOT_DIR/usr/share/bash-completion/completions/sing-box.bash"
install -Dm644 "$PROJECT/release/completions/sing-box.fish" "$ROOT_DIR/usr/share/fish/vendor_completions.d/sing-box.fish"
install -Dm644 "$PROJECT/release/completions/sing-box.zsh" "$ROOT_DIR/usr/share/zsh/site-functions/_sing-box"

# License
install -Dm644 "$PROJECT/LICENSE" "$ROOT_DIR/usr/share/licenses/sing-box/LICENSE"

# APK metadata
PACKAGES_DIR="$ROOT_DIR/lib/apk/packages"
mkdir -p "$PACKAGES_DIR"

# .conffiles
cat > "$PACKAGES_DIR/.conffiles" <<'EOF'
/etc/conf.d/sing-box
/etc/init.d/sing-box
/etc/sing-box/config.json
EOF

# .conffiles_static (sha256 checksums)
while IFS= read -r conffile; do
sha256=$(sha256sum "$ROOT_DIR$conffile" | cut -d' ' -f1)
echo "$conffile $sha256"
done < "$PACKAGES_DIR/.conffiles" > "$PACKAGES_DIR/.conffiles_static"

# .list (all files, excluding lib/apk/packages/ metadata)
(cd "$ROOT_DIR" && find . -type f -o -type l) \
| sed 's|^\./|/|' \
| grep -v '^/lib/apk/packages/' \
| sort > "$PACKAGES_DIR/.list"

# Build APK
apk --root "$APK_ROOT_DIR" mkpkg \
--info "name:sing-box" \
--info "version:${APK_VERSION}" \
--info "description:The universal proxy platform." \
--info "arch:${ARCHITECTURE}" \
--info "license:GPL-3.0-or-later with name use or association addition" \
--info "origin:sing-box" \
--info "url:https://sing-box.sagernet.org/" \
--info "maintainer:nekohasekai <contact-git@sekai.icu>" \
--files "$ROOT_DIR" \
--output "$OUTPUT_PATH"
93 changes: 93 additions & 0 deletions .github/build_openwrt_apk.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
#!/usr/bin/env bash

set -e -o pipefail

prepare_apk_root() {
# apk mkpkg resolves owner/group names through --root/etc/{passwd,group}.
APK_ROOT_DIR=$(mktemp -d)
mkdir -p "$APK_ROOT_DIR/etc"
cat > "$APK_ROOT_DIR/etc/passwd" <<EOF
root:x:$(id -u):$(id -g):root:/root:/sbin/nologin
EOF
cat > "$APK_ROOT_DIR/etc/group" <<EOF
root:x:$(id -g):root
EOF
}

ARCHITECTURE="$1"
VERSION="$2"
BINARY_PATH="$3"
OUTPUT_PATH="$4"

if [ -z "$ARCHITECTURE" ] || [ -z "$VERSION" ] || [ -z "$BINARY_PATH" ] || [ -z "$OUTPUT_PATH" ]; then
echo "Usage: $0 <architecture> <version> <binary_path> <output_path>"
exit 1
fi

PROJECT=$(cd "$(dirname "$0")/.."; pwd)

# Convert version to APK format:
# 1.13.0-beta.8 -> 1.13.0_beta8-r0
# 1.13.0-rc.3 -> 1.13.0_rc3-r0
# 1.13.0 -> 1.13.0-r0
APK_VERSION=$(echo "$VERSION" | sed -E 's/-([a-z]+)\.([0-9]+)/_\1\2/')
APK_VERSION="${APK_VERSION}-r0"

ROOT_DIR=$(mktemp -d)
prepare_apk_root
trap 'rm -rf "$ROOT_DIR" "$APK_ROOT_DIR"' EXIT

# Binary
install -Dm755 "$BINARY_PATH" "$ROOT_DIR/usr/bin/sing-box"

# Config files
install -Dm644 "$PROJECT/release/config/config.json" "$ROOT_DIR/etc/sing-box/config.json"
install -Dm644 "$PROJECT/release/config/openwrt.conf" "$ROOT_DIR/etc/config/sing-box"
install -Dm755 "$PROJECT/release/config/openwrt.init" "$ROOT_DIR/etc/init.d/sing-box"
install -Dm644 "$PROJECT/release/config/openwrt.keep" "$ROOT_DIR/lib/upgrade/keep.d/sing-box"

# Completions
install -Dm644 "$PROJECT/release/completions/sing-box.bash" "$ROOT_DIR/usr/share/bash-completion/completions/sing-box.bash"
install -Dm644 "$PROJECT/release/completions/sing-box.fish" "$ROOT_DIR/usr/share/fish/vendor_completions.d/sing-box.fish"
install -Dm644 "$PROJECT/release/completions/sing-box.zsh" "$ROOT_DIR/usr/share/zsh/site-functions/_sing-box"

# License
install -Dm644 "$PROJECT/LICENSE" "$ROOT_DIR/usr/share/licenses/sing-box/LICENSE"

# APK metadata
PACKAGES_DIR="$ROOT_DIR/lib/apk/packages"
mkdir -p "$PACKAGES_DIR"

# .conffiles
cat > "$PACKAGES_DIR/.conffiles" <<'EOF'
/etc/config/sing-box
/etc/sing-box/config.json
EOF

# .conffiles_static (sha256 checksums)
while IFS= read -r conffile; do
sha256=$(sha256sum "$ROOT_DIR$conffile" | cut -d' ' -f1)
echo "$conffile $sha256"
done < "$PACKAGES_DIR/.conffiles" > "$PACKAGES_DIR/.conffiles_static"

# .list (all files, excluding lib/apk/packages/ metadata)
(cd "$ROOT_DIR" && find . -type f -o -type l) \
| sed 's|^\./|/|' \
| grep -v '^/lib/apk/packages/' \
| sort > "$PACKAGES_DIR/.list"

# Build APK
apk --root "$APK_ROOT_DIR" mkpkg \
--info "name:sing-box" \
--info "version:${APK_VERSION}" \
--info "description:The universal proxy platform." \
--info "arch:${ARCHITECTURE}" \
--info "license:GPL-3.0-or-later" \
--info "origin:sing-box" \
--info "url:https://sing-box.sagernet.org/" \
--info "maintainer:nekohasekai <contact-git@sekai.icu>" \
--info "depends:ca-bundle kmod-inet-diag kmod-tun firewall4 kmod-nft-queue" \
--info "provider-priority:100" \
--script "pre-deinstall:${PROJECT}/release/config/openwrt.prerm" \
--files "$ROOT_DIR" \
--output "$OUTPUT_PATH"
28 changes: 28 additions & 0 deletions .github/deb2ipk.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
#!/usr/bin/env bash
# mod from https://gist.github.com/pldubouilh/c5703052986bfdd404005951dee54683

set -e -o pipefail

PROJECT=$(dirname "$0")/../..
TMP_PATH=`mktemp -d`
cp $2 $TMP_PATH
pushd $TMP_PATH

DEB_NAME=`ls *.deb`
ar x $DEB_NAME

mkdir control
pushd control
tar xf ../control.tar.gz
rm md5sums
sed "s/Architecture:\\ \w*/Architecture:\\ $1/g" ./control -i
cat control
tar czf ../control.tar.gz ./*
popd

DEB_NAME=${DEB_NAME%.deb}
tar czf $DEB_NAME.ipk control.tar.gz data.tar.gz debian-binary
popd

cp $TMP_PATH/$DEB_NAME.ipk $3
rm -r $TMP_PATH
33 changes: 33 additions & 0 deletions .github/detect_track.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
#!/usr/bin/env bash
set -euo pipefail

branches=$(git branch -r --contains HEAD)
if echo "$branches" | grep -q 'origin/stable'; then
track=stable
elif echo "$branches" | grep -q 'origin/testing'; then
track=testing
elif echo "$branches" | grep -q 'origin/oldstable'; then
track=oldstable
else
echo "ERROR: HEAD is not on any known release branch (stable/testing/oldstable)" >&2
exit 1
fi

if [[ "$track" == "stable" ]]; then
tag=$(git describe --tags --exact-match HEAD 2>/dev/null || true)
if [[ -n "$tag" && "$tag" == *"-"* ]]; then
track=beta
fi
fi

case "$track" in
stable) name=sing-box; docker_tag=latest ;;
beta) name=sing-box-beta; docker_tag=latest-beta ;;
testing) name=sing-box-testing; docker_tag=latest-testing ;;
oldstable) name=sing-box-oldstable; docker_tag=latest-oldstable ;;
esac

echo "track=${track} name=${name} docker_tag=${docker_tag}" >&2
echo "TRACK=${track}" >> "$GITHUB_ENV"
echo "NAME=${name}" >> "$GITHUB_ENV"
echo "DOCKER_TAG=${docker_tag}" >> "$GITHUB_ENV"
2 changes: 1 addition & 1 deletion .github/renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
":disableRateLimiting"
],
"baseBranches": [
"dev-next"
"unstable"
],
"golang": {
"enabled": false
Expand Down
45 changes: 45 additions & 0 deletions .github/setup_go_for_macos1013.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
#!/usr/bin/env bash

set -euo pipefail

VERSION="1.25.10"
PATCH_COMMITS=(
"afe69d3cec1c6dcf0f1797b20546795730850070"
"1ed289b0cf87dc5aae9c6fe1aa5f200a83412938"
)
CURL_ARGS=(
-fL
--silent
--show-error
)

if [[ -n "${GITHUB_TOKEN:-}" ]]; then
CURL_ARGS+=(-H "Authorization: Bearer ${GITHUB_TOKEN}")
fi

mkdir -p "$HOME/go"
cd "$HOME/go"
wget "https://dl.google.com/go/go${VERSION}.darwin-arm64.tar.gz"
tar -xzf "go${VERSION}.darwin-arm64.tar.gz"
#cp -a go go_bootstrap
mv go go_osx
cd go_osx

# these patch URLs only work on golang1.25.x
# that means after golang1.26 release it must be changed
# see: https://github.com/SagerNet/go/commits/release-branch.go1.25/
# revert:
# 33d3f603c1: "cmd/link/internal/ld: use 12.0.0 OS/SDK versions for macOS linking"
# 937368f84e: "crypto/x509: change how we retrieve chains on darwin"

for patch_commit in "${PATCH_COMMITS[@]}"; do
curl "${CURL_ARGS[@]}" "https://github.com/SagerNet/go/commit/${patch_commit}.diff" | patch --verbose -p 1
done

# Rebuild is not needed: we build with CGO_ENABLED=1, so Apple's external
# linker handles LC_BUILD_VERSION via MACOSX_DEPLOYMENT_TARGET, and the
# stdlib (crypto/x509) is compiled from patched src automatically.
#cd src
#GOROOT_BOOTSTRAP="$HOME/go/go_bootstrap" ./make.bash
#cd ../..
#rm -rf go_bootstrap "go${VERSION}.darwin-arm64.tar.gz"
Loading