跳到主内容
精选85sing-box(GitHub Releases)客户端

sing-box v1.14.0:新增 OpenVPN/OpenConnect/Snell 支持

1.14.0

原文
推荐理由

sing-box 重度用户注意:v1.14.0 是一次大版本能力跃迁,新增 OpenVPN/OpenConnect/Snell 协议支持、API 服务与 Dashboard 远程控制,iOS/tvOS 客户端也换了新应用(旧版需重装)。建议尽快升级并查阅迁移文档。

📝 Release Notes

📝 发布说明

Important changes since 1.13:

自 1.13 以来的重要变更:

  • iOS and tvOS clients are back on the App Store 1
  • Add OpenVPN client and server support 2
  • Add OpenConnect client support 3
  • Add Snell protocol support 4
  • Add L3 forwarding support and bridge outbound 5
  • Add network namespace support 6
  • Introducing sing-box API service, Dashboard and remote control 7
  • Add api command 8
  • Add USB/IP services 9
  • Add Hysteria Realm service and Hysteria2 NAT traversal support 10
  • Add Chrome QUIC fingerprint parroting, BBR profile, hop interval randomization and gecko obfs for Hysteria2 11
  • Add evaluate DNS rule action, Response Match Fields and parallel DNS response evaluation 12
  • ip_version and query_type now also take effect on internal DNS lookups 13
  • Correct undefined rule-set matching semantics 14
  • Add optimistic DNS cache 15
  • Add DNS query timeout options 16
  • Add mDNS DNS server, preferred_by DNS rule item and search domain rule items 17
  • Add source_mac_address and source_hostname rule items 18
  • Allow customizing TUN DNS mode and hijack interface DNS by default 19
  • Add new UDP NAT options 20
  • Add sniff support for pre-match 21
  • Unify HTTP client 22
  • Unify HTTP/2 and QUIC parameters 23
  • Refactor ACME support to certificate provider system 24
  • Add Cloudflare Origin CA and Tailscale certificate providers 25
  • Add TLS spoof 26
  • Add Windows and Apple TLS engines and Apple HTTP engine 27
  • Add Tailscale SSH server and Taildrop support 28
  • Add JSON Schema support 29
  • Add multiple tags and initial_path support to rule-sets 30
  • Add package_name_regex route, DNS and headless rule item
  • Add query_client_subnet and query_dnssec DNS rule items and remove_client_subnet DNS rule action option
  • Add cipher, MAC, and key exchange algorithm options for SSH outbound
  • Add cloudflared inbound
  • Add include_mac_address and exclude_mac_address TUN options
  • Add handshake_timeout TLS option
  • Add listen_port, accept_search_domain options for Tailscale
  • Preserve comments between formatting
  • Remove Deprecated Features by agreement
  • Introducing sing-box for Desktop for Windows and Linux 31
  • Add iOS jailbreak release 32
  • Apple/Android/Desktop: Add JSON editor completion, power report, report export encryption and updater improvements
  • Add beta, testing and oldstable release tracks for Linux packages and Docker 33
  • Drop support for go1.24 34
  • Update quic-go to v0.61.0
  • Update gVisor to 20260727.0
  • Update Tailscale to v1.102.1
  • Update uTLS to v1.8.7
  • Update NaiveProxy to v150.0.7871.63-2
  • iOS 和 tvOS 客户端已重新上架 App Store 1
  • 添加 OpenVPN 客户端和服务器支持 2
  • 添加 OpenConnect 客户端支持 3
  • 添加 Snell 协议支持 4
  • 添加 L3 转发支持和桥接出站 5
  • 添加网络命名空间支持 6
  • 引入 sing-box API 服务、仪表板和远程控制 7
  • 添加 api 命令 8
  • 添加 USB/IP 服务 9
  • 添加 Hysteria Realm 服务和 Hysteria2 NAT 穿透支持 10
  • 添加 Chrome QUIC 指纹模拟、BBR 配置文件、跳变间隔随机化和 Hysteria2 的 gecko 混淆 11
  • 添加评估 DNS 规则操作、响应匹配字段和并行 DNS 响应评估 12
  • ip_version 和 query_type 现在也影响内部 DNS 查询 13
  • 修正未定义的规则集匹配语义 14
  • 添加乐观 DNS 缓存 15
  • 添加 DNS 查询超时选项 16
  • 添加 mDNS DNS 服务器、preferred_by DNS 规则项和搜索域规则项 17
  • 添加 source_mac_address 和 source_hostname 规则项 18
  • 允许自定义 TUN DNS 模式,并默认劫持接口 DNS 19
  • 添加新的 UDP NAT 选项 20
  • 添加对预匹配的嗅探支持 21
  • 统一 HTTP 客户端 22
  • 统一 HTTP/2 和 QUIC 参数 23
  • 重构 ACME 支持为证书提供者系统 24
  • 添加 Cloudflare Origin CA 和 Tailscale 证书提供者 25
  • 添加 TLS 欺骗 26
  • 添加 Windows 和 Apple TLS 引擎以及 Apple HTTP 引擎 27
  • 添加 Tailscale SSH 服务器和 Taildrop 支持 28
  • 添加 JSON Schema 支持 29
  • 为规则集添加多标签和 initial_path 支持 30
  • 添加 package_name_regex 路由、DNS 和无头规则项
  • 添加 query_client_subnet 和 query_dnssec DNS 规则项,以及 remove_client_subnet DNS 规则动作选项
  • 为 SSH 出站添加密码、MAC 和密钥交换算法选项
  • 添加 cloudflared 入站
  • 添加 include_mac_address 和 exclude_mac_address TUN 选项
  • 添加 handshake_timeout TLS 选项
  • 为 Tailscale 添加 listen_port、accept_search_domain 选项
  • 在格式化之间保留注释
  • 按协议移除已弃用的功能
  • 为 Windows 和 Linux 引入 sing-box 桌面版 31
  • 添加 iOS 越狱版本 32
  • Apple/Android/桌面:添加 JSON 编辑器补全、电源报告、报告导出加密和更新器改进
  • 为 Linux 软件包和 Docker 添加 beta、testing 和 oldstable 发布轨道 33
  • 放弃对 go1.24 的支持 34
  • 更新 quic-go 至 v0.61.0
  • 更新 gVisor 至 20260727.0
  • 将 Tailscale 更新至 v1.102.1
  • 将 uTLS 更新至 v1.8.7
  • 将 NaiveProxy 更新至 v150.0.7871.63-2

1:

1:

Apple platform clients migrated to a new Apple developer account, and the iOS and tvOS clients are available on the App Store again as sing-box MT. Users of the previous App Store version (sing-box VT) need to install the new application.

Apple 平台客户端已迁移至新的 Apple 开发者账户,iOS 和 tvOS 客户端再次以 sing-box MT 的形式在 App Store 上提供。之前 App Store 版本(sing-box VT)的用户需要安装新应用。

Due to entitlement restrictions, SFM is no longer offered on the macOS App Store; use the standalone version instead. Its profiles and settings are not inherited from the previous application, see Migration.

由于权限限制,SFM 不再在 macOS App Store 上提供;请改用独立版本。其配置文件和设置不会从之前的应用中继承,请参阅迁移指南。

2:

2:

The new OpenVPN Client and OpenVPN Server endpoints are compatible with standard OpenVPN clients and servers, including static-key mode, legacy ciphers and digests, OpenVPN-compatible certificate checks, and options for tunnel addressing, MSS calculation, replay windows, timers, and TLS renegotiation. The new OpenVPN DNS server uses DNS options pushed by OpenVPN servers. Interactive client authentication is available through the sing-box graphical clients and Dashboard.

新的 OpenVPN 客户端和 OpenVPN 服务端端点与标准 OpenVPN 客户端和服务端兼容,包括静态密钥模式、传统加密算法和摘要算法、兼容 OpenVPN 的证书检查,以及隧道寻址、MSS 计算、重放窗口、定时器和 TLS 重新协商等选项。新的 OpenVPN DNS 服务器使用 OpenVPN 服务器推送的 DNS 选项。交互式客户端认证可通过 sing-box 图形客户端和 Dashboard 进行。

3:

3:

The new OpenConnect Client endpoint supports Cisco AnyConnect, GlobalProtect, Fortinet, F5, Pulse Connect Secure, and Juniper Network Connect VPN servers, with SSO (single sign-on) for AnyConnect, existing authentication sessions, OIDC Bearer authentication, AnyConnect compression, and Fortinet host check via fortinet_host_check. The new OpenConnect DNS server uses pushed split-DNS resolvers. Interactive authentication is available through the sing-box graphical clients and Dashboard.

新的 OpenConnect 客户端端点支持 Cisco AnyConnect、GlobalProtect、Fortinet、F5、Pulse Connect Secure 和 Juniper Network Connect VPN 服务器,支持 AnyConnect 的 SSO(单点登录)、现有认证会话、OIDC Bearer 认证、AnyConnect 压缩以及通过 fortinet_host_check 进行的 Fortinet 主机检查。新的 OpenConnect DNS 服务器使用推送的 split-DNS 解析器。交互式认证可通过 sing-box 图形客户端和 Dashboard 进行。

4:

4:

Surge believes that being closed-source and not proliferated can keep Snell covert, but this is already impossible in 2026; considering that Snell still has advantages that other random-traffic protocols do not possess, such as multiplexing support with complete TCP semantics and traffic-characteristic diversity, we implemented it in Go instead of reinventing the wheel, with all features except the v5 QUIC proxy, behavior as consistent with the official implementation as possible, and performance at least on par with it.

Surge 认为闭源且不广泛传播可以保持 Snell 的隐蔽性,但在 2026 年这已经不可能;考虑到 Snell 仍然具有其他随机流量协议不具备的优势,例如支持完整 TCP 语义的多路复用和流量特征多样性,我们用 Go 实现了它,而不是重新发明轮子,除 v5 QUIC 代理外的所有功能都与官方实现行为尽可能一致,性能至少与官方实现相当。

See Snell Inbound and Snell Outbound.

参见 Snell 入站和 Snell 出站。

5:

5:

Building on the ICMP proxy support introduced in sing-box 1.13.0, TCP and UDP traffic from L3 inbounds (TUN, WireGuard, and Tailscale) can now be forwarded directly to WireGuard and Tailscale endpoints at L3, without going through L3 to L4 translation.

在 sing-box 1.13.0 中引入的 ICMP 代理支持基础上,来自 L3 入站(TUN、WireGuard 和 Tailscale)的 TCP 和 UDP 流量现在可以直接在 L3 层转发到 WireGuard 和 Tailscale 端点,无需经过 L3 到 L4 的转换。

The new bridge outbound is the L3 counterpart of direct: it forwards L3 traffic (TCP, UDP and ICMP) from a TUN or other L3 endpoints directly out of a network interface. It requires privileges and is supported on Linux, macOS, Windows (via WinDivert), rooted Android, and jailbroken iOS. It also works with the preferred_by route rule item.

新的网桥出站是 direct 的 L3 对应物:它将来自 TUN 或其他 L3 端点的 L3 流量(TCP、UDP 和 ICMP)直接转发出网络接口。它需要特权,并支持 Linux、macOS、Windows(通过 WinDivert)、已 root 的 Android 和已越狱的 iOS。它也与 preferred_by 路由规则项配合使用。

See Pre-match.

参见预匹配。

6:

6:

The new network_namespaces option defines Linux network namespaces for inbounds and outbounds, referenced by tag from the new tun netns field and the existing Listen and Dial netns fields.

新的 network_namespaces 选项为入站和出站定义 Linux 网络命名空间,通过新的 tun netns 字段以及现有的 Listen 和 Dial netns 字段中的标签引用。

The unshare type creates the namespace at startup without requiring root privileges: a rootless sing-box can provide a tun (including auto_route and auto_redirect) inside a namespace, which can be entered with nsenter.

unshare 类型在启动时创建命名空间,无需 root 特权:无 root 的 sing-box 可以在命名空间内提供 tun(包括 auto_route 和 auto_redirect),可以使用 nsenter 进入该命名空间。

7:

7:

The new sing-box API service is a gRPC server for observing and controlling the running sing-box instance, exposing the same interface the graphical clients use locally: service status, logs, outbound groups (selection and URL tests), Clash mode, connection tracking, and tools such as network quality tests, STUN tests, and Tailscale operations. It can also download, update and serve sing-box-dashboard directly over its listener via the dashboard option.

新的 sing-box API 服务是一个 gRPC 服务器,用于观察和控制正在运行的 sing-box 实例,暴露图形客户端本地使用的相同接口:服务状态、日志、出站组(选择和 URL 测试)、Clash 模式、连接跟踪,以及网络质量测试、STUN 测试和 Tailscale 操作等工具。它还可以通过 dashboard 选项直接在其监听器上下载、更新和提供 sing-box-dashboard。

The graphical clients can control remote sing-box instances running the API service. sing-box Dashboard is a new web client for the API service, providing almost the same experience as the graphical clients. A public instance is available at http://sing-box-dashboard.sagernet.org (shortcut: dash.sing-box.app).

图形客户端可以控制运行 API 服务的远程 sing-box 实例。sing-box Dashboard 是 API 服务的新 Web 客户端,提供与图形客户端几乎相同的体验。公共实例可在 http://sing-box-dashboard.sagernet.org(快捷方式:dash.sing-box.app)获得。

8:

8:

The new sing-box api command is a CLI client for the API service, providing the same operations available in graphical clients and the Dashboard.

新的 sing-box api 命令是 API 服务的 CLI 客户端,提供与图形客户端和 Dashboard 中相同的操作。

9:

9:

New USB/IP Server and USB/IP Client services export and import USB devices over the USB/IP protocol, built on sing-usbip, which adds hotplug while staying interoperable with standard USB/IP. Exporting config-selected local devices (provider: default) runs via the CLI on Linux, Windows, and macOS and requires elevated privileges (macOS additionally needs a CGO build and disabled System Integrity Protection). With provider: dynamic, devices are instead supplied at runtime through the API service by the graphical clients or the sing-box Dashboard.

新的 USB/IP 服务器和 USB/IP 客户端服务通过 USB/IP 协议导出和导入 USB 设备,基于 sing-usbip 构建,该协议增加了热插拔功能,同时保持与标准 USB/IP 的互操作性。导出配置选择的本地设备(provider: default)通过 CLI 在 Linux、Windows 和 macOS 上运行,需要提升的特权(macOS 还需要 CGO 构建和禁用系统完整性保护)。使用 provider: dynamic 时,设备在运行时通过 API 服务由图形客户端或 sing-box Dashboard 提供。

10:

10:

The new Hysteria Realm service is a rendezvous service for Hysteria2 NAT traversal. A Hysteria2 server behind NAT registers its STUN-discovered public addresses on a stable realm endpoint via the new realm inbound field; clients query the realm via the new realm outbound field to learn the server's current addresses and perform UDP hole-punching to establish a direct QUIC connection. realm.ip_version restricts realm connections to a single IP version, and realm.port_mapping maintains a UDP port mapping on the local gateway via UPnP or NAT-PMP.

新的 Hysteria Realm 服务是 Hysteria2 NAT 穿透的会合服务。位于 NAT 后的 Hysteria2 服务器通过新的 realm 入站字段,在稳定的 realm 端点上注册其通过 STUN 发现的公共地址;客户端通过新的 realm 出站字段查询 realm,以了解服务器的当前地址,并执行 UDP 打洞以建立直接的 QUIC 连接。realm.ip_version 将 realm 连接限制为单一 IP 版本,而 realm.port_mapping 通过 UPnP 或 NAT-PMP 在本地网关上维护 UDP 端口映射。

11:

11:

Hysteria2 client connections now parrot Chrome's QUIC handshake by default, making the traffic harder to identify by handshake fingerprinting. Since Chrome does not declare support for Ed25519, servers using Ed25519 certificates will fail the handshake; see disable_chrome_parrot.

Hysteria2 客户端连接现在默认模仿 Chrome 的 QUIC 握手,使得流量更难通过握手指纹识别。由于 Chrome 不声明支持 Ed25519,使用 Ed25519 证书的服务器将导致握手失败;请参阅 disable_chrome_parrot。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近