v2ray/v2ray-core
57.7
Adequate · 24 September 2026
32.6k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a modular proxy and tunneling platform that manages inbound and outbound connections through a pluggable architecture of protocol handlers. It provides comprehensive network routing, traffic statistics, and configurable policy enforcement, while supporting a wide variety of transport and proxy protocols. The system also includes a robust configuration management layer that supports multiple formats and remote loading, alongside extensive tooling for diagnostics and service control.
How it got here
2015–2016 — Core architecture and protocol expansion
53 changes.
This period focused on a comprehensive architectural overhaul, introducing structured configuration loading, a new logging and error handling infrastructure, and a modular proxy interface. It also expanded the project's capabilities by adding support for multiple transport protocols (XTLS, WebSocket, QUIC) and proxy types (Socks, MTProto, BlackHole, Dokodemo), while simultaneously removing obsolete components like the old JSON config unmarshaller and VMess handler.
2017–2018 — API expansion and transport diversification
43 changes.
This period focused on exposing the core's internal capabilities through a new gRPC-based management API, enabling external tools to control proxies and monitor statistics. Simultaneously, the codebase expanded its transport layer to support HTTP/2, QUIC, Domain Sockets, and various header obfuscation techniques, while introducing modular configuration loading and structured logging.
2019–2020 — Protocol and configuration expansion
20 changes.
This period focused on expanding the proxy ecosystem by introducing support for VLESS and Trojan protocols, alongside a new DNS outbound proxy. The team also overhauled the configuration system with JSON support and improved error reporting, while adding diagnostic tools and systemd service units to enhance usability and management.
Features
Add Commander app for external gRPC management
A new Commander app has been added to the app/commander directory, introducing a gRPC-based interface for external clients to manage V2Ray. This feature allows administrators to interact with the core via a configurable set of services, enabling programmatic control and monitoring through a standardized API.
app/commander · high confidence
Add DTLS packet header support for MKCP
The transport layer now supports a DTLS (Datagram Transport Layer Security) header for MKCP. This adds a new header type that serializes epoch, sequence, and length fields into the packet, allowing for improved security or compatibility with DTLS-based protocols. The implementation includes the Go struct, serialization logic, configuration, and corresponding tests.
transport/internet/headers/tls · high confidence
Add Domain Socket transport support
Users can now configure and use Unix domain sockets for local inter-process communication. This change introduces a new transport protocol that supports standard file-system-based sockets, abstract namespace sockets (Linux), socket padding, and PROXY protocol header acceptance. The implementation includes configuration, dialer, and listener components, along with TLS and XTLS encryption support for these connections.
transport/internet/domainsocket · high confidence
Add HTTP transport protocol support
Users can now configure an HTTP transport, allowing traffic to be tunneled over HTTP/2 (with TLS) or H2C (plain TCP). The transport supports a configurable list of host headers and a request path, and automatically selects a random host from the configured list to mimic browser traffic. On the server side, the HTTP transport can listen for incoming connections, supporting both TLS-encrypted and plain-text H2C modes, and correctly parses the X-Forwarded-For header to determine the remote address.
transport/internet/http · high confidence
Add JSON config file and command-line argument support
Users can now load configuration from JSON files or via command-line arguments. The system registers a new 'JSON' config format that supports loading multiple JSON config files by iterating through command-line arguments, or reading from standard input (io.Reader).
main/jsonem · high confidence
Add JSON config loader to main/json package
The main/json package now registers a JSON config loader that supports loading configurations from both command-line arguments and standard input (io.Reader). This enables the application to parse JSON-based configuration files or streams, with error handling integrated via the errorgen tool.
main/json · high confidence
Add MTProto proxy support
Introduces a new MTProto proxy implementation, including server and client components, authentication handling, and configuration structures. This adds the capability to route traffic through MTProto-enabled servers, allowing users to connect to Telegram's infrastructure or similar services using this specific protocol.
proxy/http, proxy/mtproto · high confidence
Add StatsService with GetStats, QueryStats, and GetSysStats RPCs
A new StatsService is introduced in the app/stats/command package, exposing three gRPC methods: GetStats to retrieve a single named counter (with optional reset), QueryStats to fetch multiple counters matching a pattern, and GetSysStats to report system-level metrics such as uptime, memory allocation, and garbage collection stats. The implementation registers the service with the gRPC server and wires it to the core stats manager, enabling external tools or clients to monitor and reset counters or inspect runtime statistics.
app/stats/command · high confidence
Add UTP header support for transport headers
Users can now configure UTP (micro Transport Protocol) headers for transport connections. This change introduces the UTP header implementation, including the configuration schema (config.proto), the Go header struct and serialization logic (utp.go), and corresponding unit tests (utp\_test.go). The UTP header adds a 4-byte header containing a connection ID, header type, and extension fields to the transport layer.
transport/internet/headers/utp, transport/internet/headers/wireguard · high confidence
Add WeChat Video header obfuscation support
Users can now configure the WeChat Video header for transport obfuscation. This change introduces the necessary configuration structures and Go implementation to generate WeChat Video-style headers, including the associated test coverage.
transport/internet/headers/wechat · high confidence
Add channel-based statistics with configurable subscriber limits and blocking behavior
The stats application now supports a new Channel-based statistics system alongside the existing counter system. Users can create named channels that support multiple subscribers, with configurable limits on the number of subscribers and buffer size, as well as the option to enable or disable blocking behavior. The stats manager handles registration, unregistration, and lifecycle management of these channels, allowing for efficient, concurrent statistical data distribution to multiple listeners.
app/stats · high confidence
Add command service for managing inbound and outbound handlers
The app/proxyman/command package now includes a new gRPC-based command service that exposes RPCs to add, remove, and alter inbound and outbound handlers, as well as add and remove users on existing proxies. This introduces the HandlerService with methods for handler lifecycle management and user management, enabling external tools or scripts to dynamically modify proxy configurations at runtime.
app/proxyman/command · high confidence
Add common/dice package for random number generation
A new \common/dice\ package has been introduced to provide common functions for generating random numbers. This includes \Roll\ and \RollUint16\ for general random number generation, as well as \RollDeterministic\ and \NewDeterministicDice\ for scenarios requiring reproducible randomness via a seed. The package also includes a benchmark suite to measure performance against the standard library's \rand.Intn\.
common/dice · high confidence
Add config command for format conversion
A new 'config' command has been added to the CLI, allowing users to convert configuration files between JSON and Protocol Buffer formats. The command reads a JSON configuration from standard input and outputs the equivalent Protocol Buffer encoded data to standard output.
infra/conf/command · high confidence
Add default configuration files and geosite database
The release now includes default configuration files (config.json, vpoint\_socks\_vmess.json, vpoint\_vmess\_freedom.json) and the geosite.dat database. These files provide a pre-configured setup for V2Ray, including a SOCKS proxy on port 1080, a VMess inbound, and routing rules that block private IPs and advertisements using the geosite database.
release/config · high confidence
Add gRPC API for routing service and routing statistics
A new gRPC service, RoutingService, is introduced in the app/router/command package, exposing two main capabilities: TestRoute, which allows manual testing of routing decisions against a given context, and SubscribeRoutingStats, a streaming endpoint that pushes routing statistics (such as inbound tags, network types, IPs, ports, domains, protocols, users, and attributes) to subscribers. The implementation includes the necessary protobuf definitions, Go structs, and gRPC server/client code to support these features.
app/router/command · high confidence
Add local DNS client implementation
A new local DNS client implementation has been added, providing methods to resolve IP addresses for hosts by querying the local system's DNS resolver. The client supports separate lookups for IPv4 and IPv6 addresses, and correctly handles cases where no A or AAAA records exist by returning an empty response error.
features/dns/localdns · high confidence
Add multi-value command-line argument support
The common/cmdarg package now provides an Arg type that allows command-line flags to accept multiple values. Users can now pass repeated flag arguments, which will be collected into a slice of strings, enabling more flexible input handling in the CLI.
common/cmdarg · high confidence
Add remote logger restart capability
A new command module is introduced that exposes a gRPC service allowing remote clients to restart the core's logger. This adds the \LoggerService\ with a \RestartLogger\ RPC, enabling programmatic log management without restarting the entire application.
app/log/command · high confidence
Add retry mechanism with timed and exponential backoff strategies
A new retry package has been added to the common library, providing a Strategy interface for executing functions with automatic retries. The package includes two built-in strategies: Timed, which retries with a fixed delay, and ExponentialBackoff, which increases the delay between attempts. The implementation includes error handling that aggregates multiple errors and returns a specific ErrRetryFailed when all attempts are exhausted. Tests verify the timing and behavior of both strategies.
common/retry · high confidence
Add systemd service units for V2Ray
New systemd unit files (v2ray.service and v2ray@.service) are introduced to manage the V2Ray service. These units configure the service to run as the 'nobody' user with specific network capabilities, start the V2Ray binary with a config file located at /usr/local/etc/v2ray/config.json (or a template instance for the @.service), and include restart policies that prevent restarting on specific exit codes.
release/config/systemd · high confidence
Added DNS protocol package with message I/O utilities
The common/protocol/dns package has been introduced, providing core utilities for DNS message handling. This includes an error handling helper and specific readers and writers for both UDP and TCP transport. The UDP reader implements a thread-safe caching mechanism to handle datagrams, while the TCP reader and writer manage length-prefixed message framing. These components enable the parsing and serialization of DNS messages, supporting the underlying network protocol implementation.
common/protocol/dns · high confidence
Added HTTP header authentication and configuration
Users can now configure HTTP header authentication for transport, allowing them to specify request and response headers, URIs, methods, and status codes to verify or spoof HTTP traffic. This includes a new \http\ header module with configuration for request/response structures and a \noop\ header module for non-authenticated traffic, enabling more flexible network transport options.
transport/internet/headers/http · high confidence
Added SRTP header support for transport encryption
Users can now configure SRTP (Secure Real-time Transport Protocol) headers for transport security. This change introduces the SRTP header implementation, including the protobuf configuration schema (version, padding, extension, csrc\_count, marker, and payload\_type fields) and the Go logic to serialize and manage SRTP headers. A corresponding test ensures the header serializes correctly.
transport/internet/headers/srtp · high confidence
Added TLS sniffing implementation and tests
The \common/protocol/tls\ package now includes \sniff.go\ and \sniff\_test.go\, which implement the logic to parse TLS client hello messages and extract the server name (SNI) for traffic sniffing. This adds the capability to identify TLS connections by their domain name, with comprehensive test cases validating the parsing logic against various TLS payloads.
common/protocol/tls · high confidence
Added XTLS transport support
The transport/internet/xtls package has been added, introducing support for the XTLS protocol. This includes new configuration structures (config.proto and generated Go code) that define certificate handling, server name overrides, ALPN protocols, and session resumption settings. The implementation provides client and server connection wrappers, certificate parsing, and automatic certificate issuance logic, enabling users to configure XTLS-based secure tunnels.
proxy/shadowsocks, transport/internet/xtls · high confidence
Added error generation tool
A new Go program has been added to the codebase to generate the \errors.generated.go\ file, which defines a helper function for creating standardized error objects with path information.
common/errors/errorgen · high confidence
Added filesystem utilities and JSON comment-filtering reader
The platform now provides helper functions for reading and copying files, including support for asset locations, and introduces a new JSON configuration reader that automatically strips single-line, multi-line, and Python-style comments from JSON content before parsing.
common/platform/filesystem, infra/conf/json · high confidence
Added pub/sub messaging service with periodic cleanup
A new pub/sub service has been introduced in the common/signal/pubsub package, providing a mechanism for components to subscribe to named channels and publish messages to them. The service maintains a map of subscribers and includes a periodic cleanup task that runs every 30 seconds to remove closed subscribers and empty channels, ensuring memory efficiency. Tests confirm that messages are delivered to active subscribers and that closed subscribers no longer receive new messages.
common/signal/pubsub · high confidence
Added stack-allocated byte array types
The common/stack package now includes TwoBytes and EightBytes types, which are \[2\]byte and \[8\]byte arrays respectively, marked with //go:notinheap to ensure they are allocated on the stack rather than the heap.
common/stack · high confidence
Added support for the Trojan proxy protocol
Users can now configure and use the Trojan protocol for both inbound and outbound connections. This includes the client implementation for tunneling requests, the server handler for processing incoming Trojan traffic, and the associated configuration structures for users and fallbacks.
proxy/trojan · high confidence
Dispatcher config and stats tracking
The dispatcher module now includes a generated protobuf configuration file (config.pb.go) and a corresponding .proto schema, defining the Config and SessionConfig structures. Additionally, a new SizeStatWriter component has been added to the dispatcher to track uplink and downlink traffic statistics for users, with corresponding unit tests verifying the counter logic.
app/dispatcher · high confidence
Dokodemo door proxy configuration and implementation
The Dokodemo door proxy is now configured via a new Protocol Buffers schema (config.proto) and its generated Go code (config.pb.go), which defines fields for address, port, network list, timeout, and redirect behavior. The core implementation (dokodemo.go) registers the DokodemoDoor, initializes it with policy and socket options, and handles inbound connections by dispatching requests to the router, supporting both standard TCP/UDP forwarding and TPROXY-based UDP redirection.
proxy/dokodemo · high confidence
External configuration loader now supports HTTP/HTTPS and stdin
Users can now load configuration files from remote HTTP/HTTPS URLs or from standard input, in addition to local files. The \ConfigLoader\ function in \main/confloader/external\ has been updated to detect URL schemes and fetch content via \FetchHTTPContent\, while \stdin:\ is also supported. Additionally, an \ExtConfigLoader\ is registered to handle external configuration files via the \ctlcmd\ utility.
main/confloader/external · high confidence
Freedom proxy gains domain resolution strategy and destination override
The Freedom proxy handler now supports configuring how domain names are resolved before connecting. Users can set the 'domain\_strategy' to force IPv4, IPv6, or use the default behavior, and can also override the outbound destination address and port via the 'destination\_override' field. This allows for more flexible network routing and DNS resolution control.
proxy/freedom · high confidence
HTTP protocol support and header parsing
Added HTTP protocol sniffing and header parsing capabilities. The HTTP protocol can now be detected and its headers parsed, including support for the X-Forwarded-For header and removal of hop-by-hop headers. Additionally, a new BitTorrent protocol sniffer has been introduced to identify BitTorrent traffic.
common/protocol/http · high confidence
Introduce BlackHole proxy for blocking and responding to connections
A new BlackHole outbound handler is added, allowing users to configure a proxy that silently discards traffic or returns a predefined HTTP 403 Forbidden response. This feature enables users to block specific traffic or provide a custom response instead of dropping connections silently.
proxy/blackhole · high confidence
Introduce Channel-based stats with Manager interface
The stats feature now supports a Channel-based messaging system alongside existing counters. The diff introduces a new Channel interface that allows broadcasting messages and subscribing to streams, with methods for Publish, Subscribe, and Unsubscribe. The Manager interface is expanded to include RegisterChannel, UnregisterChannel, and GetChannel operations, enabling the creation and management of named channels. A NoopManager implementation is also provided to satisfy the new interface requirements.
features/stats · high confidence
Introduce QUIC transport protocol support
Adds a new QUIC transport implementation, including configuration, connection handling, dialer, listener, and associated tests. This enables users to route traffic over QUIC with optional header obfuscation and encryption (AES-128-GCM or ChaCha20-Poly1305).
transport/internet/quic · high confidence
Introduce UDP packet structure and protocol package
A new 'udp' package has been added to the common/protocol directory, containing a 'Packet' struct that encapsulates a UDP payload along with its source and destination network destinations. This change establishes the foundational data structure for handling UDP traffic within the protocol layer.
common/protocol/udp · high confidence
Introduce UUID generation and parsing utilities
A new UUID package has been added to the common utilities, providing functions to generate random UUIDs, parse them from strings and byte slices, and compare them for equality. This adds a standardized way to create and handle UUIDs within the application.
common/uuid · high confidence
Introduce VLESS protocol support with header and body encoding
Adds the VLESS proxy implementation, including account definitions, a validator for user management, and encoding/decoding logic for headers and body data. This enables VLESS as a new protocol option for both inbound and outbound connections, supporting flow settings and encryption configurations.
proxy/vless/encoding · high confidence
Introduce a new, structured logging system in the common/log package
The application now uses a new logging infrastructure in the common/log package, featuring a structured message system with severity levels (Unknown, Error, Warning, Info, Debug) defined via Protocol Buffers. This change introduces a new API for logging, including a general-purpose logger that supports writing to stdout, stderr, or files, and provides a context-based mechanism for access logs that include details like email and detour information. Users will see logs formatted with severity prefixes and potentially more detailed access log entries.
common/log · high confidence
Introduce common protocol abstractions and server management
The \common/protocol\ package now provides foundational types and interfaces for the proxy system. This includes a generic \User\ and \Account\ interface to standardize user identity and authentication across different protocols. A new \ServerSpec\ and \ServerList\ have been added to manage server configurations, including validation strategies and user assignment. Additionally, the \common/antireplay\ package introduces an anti-replay window mechanism using a cuckoo filter to prevent message replay attacks. These changes establish a unified protocol layer that protocols like VMess can implement or extend.
common/protocol · high confidence
Introduce common utilities for object creation and resource management
Added a new \common\ package providing shared utilities for the application. This includes a global config creator system (\RegisterConfig\/\CreateObject\) that allows registering and instantiating objects based on their configuration types. Additionally, the package introduces standard interfaces for resource management (\Closable\, \Interruptible\, \Runnable\) and helper functions (\Close\, \Interrupt\) to safely release resources. The package also includes environment variable helpers (\GetGOBIN\, \GetGOPATH\, \GetModuleName\) and error generation utilities.
common · high confidence
Introduce configurable logging with support for custom handlers
The logging subsystem has been refactored to support configurable log destinations (Console, File, or None) for both access and error logs, allowing users to specify log paths and severity levels. The system now supports registering custom log handlers via a plugin-like interface, enabling third-party integrations or custom output mechanisms. This change introduces a new \app/log\ package that manages log initialization, handler creation, and lifecycle management, replacing the previous default logger behavior with a more flexible and extensible logging architecture.
app/log · high confidence
Introduce configurable session and system policies
The policy module now supports configurable session policies, allowing users to set timeouts for handshake, connection idle, and uplink/downlink states, as well as per-connection buffer sizes. Additionally, system-level policies can be configured to enable traffic statistics for inbound and outbound uplink and downlink.
app/policy · high confidence
Introduce new buf package for memory allocation and I/O
Added the common/buf package, providing a lightweight memory allocation mechanism with a recyclable Buffer type and a MultiBuffer type for handling multiple buffers. The package includes a Copy function for data transfer between readers and writers, supporting activity updates and size counting. It also introduces a ReadVReader for optimized multi-buffer reads on supported platforms, and a BufferedWriter for efficient buffered writing. Comprehensive tests and benchmarks are included.
common/buf · high confidence
Introduce new crypto primitives and authentication readers
Added new encryption stream functions for AES (CFB, CTR, GCM) and ChaCha20, alongside a new AuthenticationReader and Writer that handle AEAD-based authentication and chunked data streams. This introduces a new mechanism for secure data transmission with built-in authentication and padding support.
common/crypto · high confidence
Introduce platform-specific process control for v2ctl execution
The ctlcmd package now provides a unified interface for executing the v2ctl binary, with platform-specific behavior for process attributes. On Windows, the process is launched with the window hidden, while on other platforms, no special process attributes are applied. The Run function manages the execution of v2ctl, capturing both standard output and error streams, and logs any error output as an info-level log entry.
common/platform/ctlcmd · high confidence
Introduce reverse proxy support with Bridge and Portal components
Added a new reverse proxy feature consisting of a Bridge (server-side) and a Portal (client-side) that establish multiplexed connections between internal and external networks. The Bridge manages outbound connections to a specified domain, while the Portal registers an outbound handler to intercept and route internal traffic through these multiplexed links. Configuration is handled via new Protobuf definitions for BridgeConfig, PortalConfig, and Control states (ACTIVE/DRAIN).
app/reverse · high confidence
Introduce session context and metadata structures
A new \common/session\ package has been added to centralize session management. This includes a \context.go\ file that provides helper functions to store and retrieve session-related data (such as IDs, inbound/outbound metadata, content, and socket options) within Go contexts. Additionally, \session.go\ defines the core data structures: \Inbound\ and \Outbound\ for connection metadata, \Content\ for protocol and sniffing details, and \Sockopt\ for socket configurations. This change enables better tracking of request sessions and associated metadata throughout the application.
common/session · high confidence
Introduce structured configuration loading and Docker support
Users can now load V2Ray configurations via a new extensible loader system that supports multiple formats (e.g., Protobuf) and file extensions. The project also adds a Dockerfile for containerized builds and a .gitignore file to exclude IDE and build artifacts. Additionally, a SECURITY.md file is introduced to outline vulnerability reporting procedures and provide a GPG key for secure communications.
(repo-wide) · high confidence
Introduce structured network address and destination types
The \common/net\ package now provides structured types for network addresses and destinations, including \Address\, \Destination\, \Port\, and \Network\ enums, along with their corresponding Protocol Buffers definitions (\IPOrDomain\, \Endpoint\, \NetworkList\, \PortRange\). This change replaces previous string-based or ad-hoc representations with typed, serializable structures for handling IP addresses, domains, ports, and network protocols (TCP/UDP), enabling more robust configuration and data exchange.
common/net · high confidence
Introduce transport/pipe for internal data passing
A new pipe implementation has been added to the transport layer, providing a buffered channel for passing data between components. The pipe supports configurable size limits and overflow discarding, and exposes Reader and Writer interfaces that integrate with the existing buf package. This change replaces previous channel-based implementations with a more robust, policy-driven buffer mechanism.
transport/pipe · high confidence
Introduce v2ctl binary and Bazel build rules for control commands
Added the v2ctl Go binary entry point and associated Bazel build rules to enable building the control command interface across multiple operating systems and architectures. The new BUILD file and targets.bzl script configure the build to generate v2ctl binaries for various platforms, including specific handling for ARM and MIPS architectures.
infra/control/main · high confidence
Introduce vprotogen tool to automate Protocol Buffers code generation and integration
A new Go-based utility, vprotogen, has been added to the infrastructure tools to automate the generation of Go code from .proto files. This tool scans for .proto files, invokes protoc with the appropriate plugins (gofast, go, go-grpc) using paths derived from the current working directory and environment variables, and then moves the generated .pb.go files into the project's module path. This change simplifies the workflow for developers by handling the compilation and placement of generated code without relying on GOPATH or GOBIN environment variables directly.
infra/vprotogen · high confidence
Introduces VMess AEAD authentication and header encryption
The proxy/vmess/aead package now implements the VMess AEAD protocol, adding new files for key derivation (kdf.go), constants (consts.go), authentication ID handling (authid.go), and header encryption/decryption (encrypt.go). This provides the core cryptographic primitives for VMess AEAD connections, including generating and verifying AuthIDs to prevent replay attacks and encrypting the VMess header. A corresponding set of unit tests (authid\_test.go, encrypt\_test.go) validates the new functionality.
proxy/vmess/aead · high confidence
Introduces a custom error handling library with severity levels and nested error support
The \common/errors\ package has been replaced with a new custom error implementation that supports severity levels (Debug, Info, Warning, Error) and nested error chaining. This allows for more granular logging and better error context propagation throughout the application. The new library provides functions like \New\, \Base\, \Cause\, and \Combine\ to manage error states and aggregate multiple errors.
common/errors · high confidence
Introduces a new bitmask utility for byte values
A new bitmask utility has been added to the common library, providing a \Byte\ type with methods to set, clear, toggle, and check bits. This allows for more readable and structured bitwise operations on byte values throughout the codebase.
common/bitmask · high confidence
Introduces a new transport configuration and dialer system
The transport/internet package now includes a new config.go file that defines a ConfigCreator function and a global cache for transport protocol configurations. This enables a more flexible and extensible way to create and manage transport settings, including support for various protocols like TCP, UDP, HTTP, WebSocket, and DomainSocket. The new system allows for dynamic registration of transport protocols and their associated settings, making it easier to add or modify transport types without hardcoding. Additionally, the dialer.go file introduces a new Dialer interface and a global cache for transport dialers, which simplifies the process of creating outbound connections. The system\_dialer.go and system\_listener.go files provide implementations for system-level dialing and listening, supporting both TCP and UDP connections with configurable socket options. This change enhances the modularity and configurability of the transport layer, allowing for more advanced network configurations and better integration with different network environments.
transport/internet · high confidence
Introduces configurable connection allocation and content sniffing for inbound proxies
The proxyman module now exposes configuration for connection pool management and traffic inspection. Users can control the number of parallel handlers via the new AllocationStrategy (defaulting to 3 concurrent handlers, with a 5-minute refresh interval). Additionally, the ReceiverConfig now supports SniffingConfig, allowing users to enable content sniffing and override destination protocols (HTTP, TLS) for inbound connections, replacing the deprecated domain\_override field.
app/proxyman · high confidence
Introduces configurable default buffer size and timeout policies
The policy feature now includes a new default manager implementation and configurable buffer sizing. Users can adjust the default buffer size via the environment variable v2ray.ray.buffer.size, which allows tuning memory usage per connection. Additionally, default timeout values for connections, handshakes, and idle states are established, with specific defaults for different CPU architectures to optimize performance on low-end devices.
features/policy · high confidence
Introduces new routing condition matchers and balancing strategy
The router app now supports matching on source and destination ports, user emails, and inbound tags, alongside the existing domain, IP, and network conditions. It also introduces a configurable balancing strategy (currently Random) for selecting among multiple outbounds. These changes allow for more granular and flexible routing rules, such as directing traffic based on the client's source port or specific user identities.
app/router · high confidence
Introduction of a byte slice pooling mechanism
A new bytespool package has been added to provide a pool for reusing byte slices. The implementation initializes four internal pools with sizes 2048, 8192, 32768, and 131072 bytes. It exposes three stable API functions: GetPool to retrieve a specific pool, Alloc to get a byte slice from the pool or create a new one if the size is too large, and Free to return a slice to the appropriate pool based on its capacity.
common/bytespool · high confidence
Mux client and server implementation moved to common/mux
The Mux client and server implementations, along with their associated frame handling, session management, and test coverage, have been moved to the common/mux package. This change consolidates the Mux functionality into a shared location, making it available for use by other components within the core library.
common/mux · high confidence
New DNS client interface for domain resolution
A new DNS client interface is introduced, defining how the system resolves domain names to IP addresses. The \Client\ interface provides a \LookupIP\ method for general resolution, while optional \IPv4Lookup\ and \IPv6Lookup\ interfaces allow for querying specific address types. This change establishes the contract for DNS functionality within the application.
features/dns · high confidence
New DNS outbound proxy
Adds a new DNS outbound proxy that intercepts DNS traffic and forwards it to a configured DNS server. The proxy supports both TCP and UDP transport, handles A and AAAA record lookups, and correctly propagates DNS errors (such as non-existent domains) back to the client.
proxy/dns · high confidence
New Inbound Management Interface
A new \features/inbound\ package has been introduced, defining the \Handler\ and \Manager\ interfaces for processing and managing inbound connections. The \Manager\ interface provides methods to retrieve, add, and remove inbound handlers by tag, establishing the core contract for inbound connection handling within the application.
features/inbound · high confidence
New JSON configuration format for core components
The \infra/conf\ package introduces a comprehensive JSON-based configuration system for V2Ray components, including API, DNS, HTTP, Shadowsocks, Socks, and routing rules. This change adds new configuration structures and parsing logic that allow users to define settings like name servers, proxy accounts, and routing rules in JSON format. The diff shows the addition of config builders for blackhole responses, Dokodemo, freedom proxy, log, policy, reverse proxies, and more, each with corresponding test cases to ensure correct parsing and building of the underlying protobuf messages.
infra/conf · high confidence
New TLS certificate generation utility
A new common package for generating TLS certificates has been added to the codebase. This utility allows users to create certificates with configurable options, including setting the organization, DNS names, validity periods, and CA status. It supports automatic issuance from a provided CA and handles various key types (ECDSA, RSA, Ed25519).
common/protocol/tls/cert · high confidence
New UDP transport implementation with platform-specific destination handling
The UDP transport module has been refactored into a new, self-contained package at \transport/internet/udp\. This introduces a new \Config\ type for protocol configuration, a \Hub\ for listening and reading UDP packets, and a \Dispatcher\ for routing outbound requests. A key behavioral addition is the ability to retrieve the original destination address from the operating system (via \IP\_RECVORIGDSTADDR\ on Linux or equivalent mechanisms on FreeBSD), which is critical for transparent proxying scenarios. The implementation is split across platform-specific files (\hub\_linux.go\, \hub\_freebsd.go\, \hub\_other.go\) to handle OS-specific socket options and address retrieval, while shared logic resides in \hub.go\ and \dispatcher.go\.
transport/internet/udp · high confidence
New proxy interface package for inbound and outbound processing
A new 'proxy' package has been introduced to define the core interfaces for inbound and outbound connection processing. The 'Inbound' interface now specifies how connections are processed and potentially dispatched to an outbound, while the 'Outbound' interface handles the processing of connections using a provided dialer. Additionally, a 'UserManager' interface is defined to allow proxies to manage their own users, and getter interfaces are provided to retrieve the underlying Inbound or Outbound implementations.
proxy · high confidence
New routing context and interface definitions
The routing feature now exposes formalized interfaces for routing context, router, and dispatcher, along with a concrete session context implementation. Users can now access structured connection metadata (source/target IPs, ports, domain, protocol, user email, and attributes) via the routing context, enabling more precise routing decisions and outbound dispatching based on connection properties.
features/routing · high confidence
New serial utility package for binary and string serialization
A new \common/serial\ package has been introduced, providing utilities for serializing and deserializing data. This includes \ReadUint16\, \WriteUint16\, and \WriteUint64\ functions for handling binary data using big-endian encoding, as well as \ToString\ and \Concat\ functions for string serialization. The package also introduces a \TypedMessage\ structure, generated from a new \typed\_message.proto\ definition, which wraps a serialized protocol buffer message with its type name, allowing for type-safe message handling. Corresponding tests and benchmarks have been added to verify the behavior of these new serialization tools.
common/serial · high confidence
New signal primitives and improved activity timer
Added new synchronization utilities: a Done type for one-shot completion notifications, a non-blocking Notifier for change signals, and a Semaphore for permit management. The ActivityTimer was refactored to handle zero timeouts immediately and avoid race conditions, ensuring contexts are cancelled promptly after inactivity.
common/signal · high confidence
New string-matching library for domain, full, substring, and regex patterns
A new \strmatcher\ package has been added to the codebase, introducing a unified interface for matching strings against various pattern types: full string, substring, domain suffix, and regular expression. The package provides specialized groups (FullMatcherGroup, DomainMatcherGroup) and a combined MatcherGroup that aggregates matches across all types, returning the IDs of all matching rules. This enables more efficient and structured rule evaluation for network traffic matching.
common/strmatcher · high confidence
New task execution and scheduling utilities
Added new utilities for concurrent task execution and periodic task scheduling. The \Run\ function allows executing multiple tasks in parallel, returning the first error encountered or respecting context cancellation. The \Periodic\ type provides a way to schedule and run tasks at fixed intervals, with proper lifecycle management via \Start\ and \Close\ methods. Tests verify parallel execution, context cancellation, and periodic task behavior.
common/task · high confidence
New v2ctl subcommands for API, certificates, config merging, and diagnostics
The v2ctl CLI now includes several new subcommands: 'api' allows users to call V2Ray services (LoggerService, StatsService) via gRPC with a 3-second timeout; 'cert' generates TLS certificates with options for domain, expiration, and CA mode; 'config' merges multiple JSON configuration files into a single protobuf config; 'tlsping' performs TLS handshakes to diagnose connection issues; and 'verify' checks binary signatures. These additions expand the diagnostic and configuration management capabilities available to users.
infra/control · high confidence
Socks proxy implementation added
The Socks proxy feature is now available, including the client and server implementations, configuration structures, and protocol handling for TCP and UDP traffic.
proxy/socks · high confidence
V2Ray main entry point and build configuration
The V2Ray application's main entry point has been restructured into a new \main\ package, introducing a new command-line interface that supports multiple config files, a \--confdir\ argument for loading all JSON configs from a directory, and environment variable fallbacks for configuration paths. The change also adds a new \errors.generated.go\ file for error handling and updates the Bazel build rules in \main/BUILD\ and \main/targets.bzl\ to generate the \v2ray\ binary for various operating systems and architectures, including Windows GUI variants and MIPS soft-float builds.
main · high confidence
VLESS inbound proxy support for fallbacks and configuration
The VLESS inbound proxy now supports configuring fallbacks, allowing connections to be routed to alternative destinations based on ALPN, path, or type. The inbound handler has been updated to parse the new \Fallback\ configuration structure, which includes fields for \alpn\, \path\, \type\, \dest\, and \xver\. This enables users to define multiple fallback targets in the VLESS inbound configuration, improving flexibility in handling incoming VLESS traffic.
proxy/vless/inbound · high confidence
VLESS outbound handler and configuration support
The VLESS protocol gains a new outbound implementation, introducing a configurable handler that manages server endpoints, supports TCP/UDP/Mux commands, and enables XTLS flow modes for encrypted traffic. This adds the necessary configuration structures and Go implementation to route VLESS traffic through the proxy.
proxy/vless/outbound · high confidence
VMess outbound proxy implementation
The VMess outbound proxy handler has been implemented in the \proxy/vmess/outbound\ package. This adds support for the VMess protocol as an outbound connection handler, including configuration structures, command handling (such as account switching), and the core \Process\ logic for tunneling requests. The implementation includes generated protobuf code for configuration and error handling, enabling users to configure and route traffic through VMess servers.
proxy/vmess/outbound · high confidence
VMess protocol implementation and configuration
The VMess proxy implementation has been added, introducing the core protocol logic including account management, user validation, and error handling. This includes the \MemoryAccount\ struct for handling VMess account data, a \TimedUserValidator\ for managing user authentication and caching, and the corresponding Protocol Buffers definitions for configuration. The change also includes the necessary generated code for errors and protobuf serialization.
proxy/vmess · high confidence
Removals
Removed obsolete JSON and VMess reader implementations
The obsolete JSON configuration unmarshaller (JsonVConfigUnmarshaller) and the VMess reader (VMessReader) have been removed from the io package. Users relying on these legacy components will need to adopt the updated configuration and reader mechanisms provided by the core library.
io · medium confidence
Behavioural changes
5 commits (0 fixes) modifying .dev
A change to existing behaviour in .dev — 5 commits, 3 files.
.dev · medium confidence · unverified
Add script to remove VSign verification
A new shell script, release/mutilate/removeVSign.sh, has been added to the release process. This script removes the VSign verification component (verify.go) and removes the corresponding VSign entry from the Go module dependencies (go.mod). This change allows VSign functionality to be disabled when V2Ray is included in a package, shifting verification responsibility to the package manager.
release/mutilate · medium confidence
Added optimized ChaCha20 stream cipher implementation
The crypto/internal package now includes a new, optimized implementation of the ChaCha20 stream cipher. This includes the core block function (chacha\_core.generated.go), a generator script (chacha\_core\_gen.go) that produces the optimized code, and a stream wrapper (chacha.go) that manages state and keystream generation. This change replaces the previous ChaCha20 implementation with a more efficient version.
common/crypto/internal · high confidence
Centralized module registration for V2Ray core components
The V2Ray core now uses a centralized \all.go\ file to register all available components, including new proxy protocols (VLESS, Trojan), transport protocols (QUIC, WebSocket), and application features (DNS, Router, Stats). This change ensures that all necessary modules are automatically loaded via Go's init functions, simplifying the build process and enabling users to access a wider range of features without manual configuration.
main/distro/all · high confidence
DNS resolution added to routing context
The routing system now supports domain name resolution within the routing context. A new ResolvableContext implementation wraps the standard routing context to automatically resolve domain names to IP addresses when required, falling back to direct IP usage if available. This allows routing decisions to be based on resolved IPs rather than raw domain names.
features/routing/dns · high confidence
DNS server refactored with new configuration schema and domain matching types
The DNS application module has been restructured to support a new configuration schema (config.proto) that introduces four domain matching types: Full, Subdomain, Keyword, and Regex. This allows for more granular control over DNS resolution, including support for dotless domains and static host mappings. The server now handles both traditional UDP and DNS-over-HTTPS (DoH) clients, with improved caching and cleanup mechanisms. Users can now configure prioritized domains for specific name servers and use static IP mappings with pattern matching.
app/dns · high confidence
Enable pprof debugging endpoint on port 6060
The application now exposes a Go pprof HTTP endpoint on port 6060, allowing users to access runtime profiling data for debugging purposes.
main/distro/debug · high confidence
Global transport configuration moved to transport package
The global transport settings, which previously affected all connections through V2Ray, have been moved into the transport package. This change introduces a new Config structure in the transport layer that wraps the underlying internet transport configurations. Users should note that this global configuration is now deprecated in favor of per-connection StreamConfig settings, meaning individual connection configurations should be used instead of the global transport settings.
transport · high confidence
Improved JSON configuration error reporting with line and character positions
The serial configuration loader now provides more precise error messages when parsing JSON configuration files. Instead of generic failure messages, users will see specific line and character positions for syntax errors (e.g., 'line 4 char 6'), making it easier to locate and fix issues in their configuration files. This change affects how configuration errors are reported, improving the debugging experience for users managing their V2Ray configurations.
infra/conf/serial · high confidence
Introduce modular configuration loading with extensible loaders
The application now uses a dedicated \confloader\ package to handle configuration loading, separating the logic into \LoadConfig\ for single files and \LoadExtConfig\ for multiple configurations. This change introduces function pointers (\EffectiveConfigFileLoader\ and \EffectiveExtConfigLoader\) that allow the core to delegate actual loading work to an external module, enabling more flexible configuration handling.
main/confloader · medium confidence
Introduce platform-specific asset and tool location resolution
The platform abstraction layer has been refactored to support platform-specific behavior for locating assets and tools. On non-Windows systems, the system searches for asset files in the executable directory, /usr/local/share/v2ray/, and /usr/share/v2ray/, falling back to the executable directory if not found. Windows systems continue to resolve asset locations relative to the executable directory. Both platforms now utilize environment variables (e.g., V2RAY.location.asset) to override default paths, with normalized environment variable names (e.g., V2RAY\_LOCATION\_ASSET) supported as fallbacks. Additionally, the tool location function now appends the .exe extension on Windows. These changes ensure consistent configuration and asset resolution across different operating systems.
common/platform · high confidence
Introduction of a new features package with a generic Feature interface
A new 'features' package has been introduced, containing a generic 'Feature' interface that all V2Ray features must implement, requiring them to satisfy 'common.HasType' and 'common.Runnable'. The package also includes a generated error helper function and a utility to warn about deprecated features. This change restructures how features are defined and managed within the application.
features · high confidence
Major refactoring and bug fixes for the mKCP transport protocol
The mKCP transport implementation has been significantly refactored to improve performance, stability, and maintainability. Key changes include the introduction of configurable buffer sizes for reading and writing, as well as uplink and downlink capacity settings. The update also adds support for XTLS and TLS encryption layers over KCP, and introduces a new encryption seed feature for packet encryption. Additionally, numerous bug fixes address data races, memory leaks, and logic errors in the sending and receiving windows, while also simplifying the configuration structure and error handling.
transport/internet/kcp · high confidence
Outbound handler refactored with stats counters and improved error handling
The outbound handler implementation has been refactored to include built-in traffic statistics (uplink and downlink counters) when the system policy enables them, allowing users to monitor outbound data usage. The change also introduces a new error generation mechanism for the outbound package and ensures that outbound connections are properly closed or interrupted when processing fails, improving reliability and observability.
app/proxyman/outbound · high confidence
Outbound management interfaces moved to dedicated package
The \outbound\ package now contains the core interfaces for managing outbound connections, including \Handler\, \HandlerSelector\, and \Manager\. This change centralizes the definitions for outbound handler selection and management, providing a stable API for interacting with outbound connections and their lifecycle.
features/outbound · high confidence
Redesign of the WebSocket transport implementation
The WebSocket transport has been refactored to use a new configuration structure that supports custom HTTP headers and PROXY protocol. Users can now configure request headers for the WebSocket connection and enable PROXY protocol support on the server side. Additionally, the implementation has been updated to use the external gorilla/websocket library and includes a test suite to verify connection behavior.
transport/internet/websocket · high confidence
Refactored VMess encoding with AEAD and improved security
The VMess encoding logic has been refactored to support AEAD (Authenticated Encryption with Associated Data) by default, replacing the legacy encryption methods. This includes new authentication mechanisms using FNV hash and SHA3, along with session history tracking to prevent replay attacks. The client and server sessions now handle both legacy and AEAD protocols, with the server draining connections on authentication failures to mitigate security weaknesses.
proxy/vmess/encoding · medium confidence
Refactored inbound handler architecture with dynamic port allocation and improved statistics tracking
The inbound handler implementation has been refactored to support dynamic port allocation via a new \DynamicInboundHandler\ alongside the existing \AlwaysOnInboundHandler\. This change introduces periodic refreshing of worker instances to manage ephemeral ports, while also integrating traffic statistics counters for both uplink and downlink data in the \AlwaysOnInboundHandler\. The \Manager\ has been updated to route configuration to the appropriate handler based on the allocation strategy, and error handling has been standardized using the new error generation utilities.
app/proxyman/inbound · high confidence
Release build and installation scripts updated
The release build system was refactored to use Bazel for generating platform-specific zip packages, adding support for new architectures including Linux ppc64, Linux riscv64, and Linux s390x. The automated release scripts (tagrelease.sh, bleedingrelease.sh) were updated to include these new builds. Additionally, the legacy install-release.sh script was deprecated in favor of the fhs-install-v2ray project.
release · high confidence
Removal of VMessHandler component
The VMessHandler struct and its associated Listen method have been removed from the net package, indicating that the VMess protocol handling capability is no longer supported or required in this network layer.
net · high confidence
TCP transport configuration and implementation refactored to use Protocol Buffers
The TCP transport module has been refactored to use Protocol Buffers for configuration, introducing a new \config.proto\ and its Go bindings (\config.pb.go\) alongside a dedicated \config.go\ for protocol registration. This change introduces a \HeaderSettings\ field for header authentication and an \AcceptProxyProtocol\ boolean to enable PROXY protocol support on the TCP inbound listener. Additionally, the implementation now supports XTLS and standard TLS over TCP, and includes platform-specific socket options for retrieving the original destination on Linux and FreeBSD.
transport/internet/tcp · high confidence
TLS config refactoring and automatic certificate issuing
The TLS transport module has been refactored to support automatic certificate issuance from a provided Certificate Authority (CA). Users can now configure a CA certificate with USAGE set to AUTHORITY\_ISSUE, and the system will automatically generate and serve new certificates for requested server names. The configuration now includes options to disable system root certificates (fixing issue \#1513), disable session resumption, and allow insecure ciphers. Additionally, the codebase has been updated to use the standard Go crypto/tls package instead of the external utls library, and generated protobuf files have been regenerated.
transport/internet/tls · high confidence
VMess inbound configuration and handler refactored
The VMess inbound handler has been restructured to support dynamic user management via email-based caching and detour routing. Configuration is now defined in a dedicated proto file, introducing a DefaultConfig for automatic user creation and a DetourConfig to route traffic to other proxies. The handler also enforces secure encryption only when configured, and manages session history for logging and debugging purposes.
proxy/vmess/inbound · high confidence
Test coverage
Added HTTP server test utility; Added TCP test server utilities; Added UDP test server and port allocation utilities; Added mock implementations for testing; Automated test coverage reporting via Coverall and Codecov; Expanded scenario test coverage for core components.
Dependencies
Updated Go dependencies and build configuration
The project's Go module configuration (go.mod) and dependency manifest (go.sum) have been updated. This includes upgrading the Go version requirement to 1.15 and updating various dependencies such as gRPC, protobuf, and testing libraries to their latest specified versions.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 59 → 58 (-1.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 75 → 84 (+9.2)
- Architecture 100 → 75 (-24.7)
- Maturity 48 → 48 (+0.0)
- Readiness 84 → 65 (-18.7)
- Security 56 → 63 (+7.0)
Resolved (110)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (common/crypto/auth.go)
- Duplicated block (10 lines × 2) (common/mux/client.go)
- Duplicated block (10 lines × 2) (infra/conf/router.go)
- Duplicated block (10 lines × 2) (infra/conf/transport_internet.go)
- Duplicated block (10 lines × 2) (proxy/trojan/server.go)
- Duplicated block (10 lines × 2) (proxy/vless/inbound/inbound.go)
- Duplicated block (11 lines × 2) (common/mux/client.go)
- Duplicated block (11 lines × 2) (infra/conf/router.go)
- Duplicated block (11 lines × 2) (infra/conf/shadowsocks.go)
- Duplicated block (11 lines × 2) (infra/conf/transport_authenticators.go)
- Duplicated block (11 lines × 2) (infra/conf/trojan.go)
- Duplicated block (11 lines × 2) (infra/conf/v2ray.go)
- Duplicated block (11 lines × 2) (proxy/http/client.go)
- Duplicated block (11 lines × 2) (proxy/shadowsocks/client.go)
- Duplicated block (11 lines × 2) (proxy/trojan/client.go)
- Duplicated block (11 lines × 2) (proxy/vmess/encoding/client.go)
- …and 90 more
New (207)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/seiflotfy/cuckoofilter
- Dependency pinned to a stale untagged commit: github.com/xiaokangwang/VSign
- Dependency pinned to a stale untagged commit: github.com/xtls/go
- Dependency pinned to a stale untagged commit: go.starlark.net
- Dependency pinned to a stale untagged commit: golang.org/x/crypto
- Dependency pinned to a stale untagged commit: golang.org/x/net
- Dependency pinned to a stale untagged commit: golang.org/x/sync
- Dependency pinned to a stale untagged commit: golang.org/x/sys
- Deprecated module: github.com/golang/protobuf
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (infra/conf/shadowsocks.go)
- Duplicated block (10 lines × 2) (infra/conf/v2ray.go)
- Duplicated block (10 lines × 2) (proxy/http/server.go)
- Duplicated block (10 lines × 2) (proxy/socks/protocol.go)
- Duplicated block (10 lines × 2) (proxy/vmess/aead/encrypt.go)
- Duplicated block (10 lines × 2) (transport/internet/tls/config.go)
- Duplicated block (10 lines × 2) (transport/internet/tls/tls.go)
- …and 187 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
v2ray/v2ray-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d80440f3d57b45c829dbf513306f7adf9a0f3f76 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.