What's newin version 3.6.0
· Protocols and Transports
- Added the MASQUE protocol
- Added VLESS Encryption: encrypts the stream without TLS underneath, and stacks with Vision flow control
- Added the XHTTP transport with HTTP/1.1, HTTP/2 and HTTP/3; upload and download legs can be configured separately
- Snell now supports v4, v5 and v6 (v6 in its unsafe-raw / unshaped / default modes)
- REALITY is no longer limited to VLESS over TCP: it now works under VLESS WebSocket, H2, gRPC and HTTP-obfuscation transports, and under Trojan and VMess
- VLESS and VMess support plaintext gRPC
- VMess supports XUDP and packetaddr; VLESS and VMess gain the packet-encoding, xudp and packet-addr keys
- TUIC lets you choose the congestion controller (congestion-controller: bbr / cubic / new_reno)
- SOCKS5 outbound supports TLS (tls, sni, skip-cert-verify, alpn, server-cert-fingerprint)
- SSH supports host-key pinning and host-key-algorithms
- WebSocket transport supports Early Data (ws-opts.max-early-data, early-data-header-name, and the ?ed= marker in subscription links)
· TLS and Security
- Every TLS ClientHello now offers the X25519MLKEM768 post-quantum hybrid key exchange by default; REALITY can enable it with reality-opts.support-x25519mlkem768, and shadow-tls v3 carries it as well
- MitM leaf certificates are reused per public suffix, so far fewer certificates are generated
· Tailscale
- Adding a Tailscale node automatically routes its MagicDNS suffix and every peer address to that node, with no hand-written rules; disable with auto-route-disabled: true
- The runtime exit-node choice persists across restarts
- The status API shows whether each peer is reached directly or through a DERP relay
· StashLink
- When underlying-proxy is left empty, the relay carrier is chosen automatically from the device's own proxies, and re-chosen after network changes or subscription updates
- Device names resolve under the .stash suffix and route to the matching device automatically
- The path a StashLink proxy is currently on is visible; direct paths are kept across network changes where possible
· Rules and DNS
- GEOIP and IP-ASN support UNKNOWN, matching addresses with no database entry
- A rule that cannot be parsed is skipped with a warning instead of failing the whole configuration load
- fake-ip-filter and nameserver-policy can reference rule-set: and geosite:
- A nameserver-policy key can list several matchers separated by commas