Free, open-source Xray client for Windows, macOS, Android (experimental), and Linux (GNOME-first)
powered by Xray-core
| Platform | Download | Requirements |
|---|---|---|
| Windows | Latest Release (.exe) | Windows 10+ |
| macOS | Latest Release (.app) | macOS 13+ (Apple Silicon & Intel) |
| Linux | Build from source with ./build.sh |
ALT Linux + GNOME first; also supports Debian/Ubuntu, Fedora/RHEL, openSUSE, and Arch families |
| Android | Latest Release (.apk) | Android 7+ (arm64) |
Invisible Gorilla XRay wraps Xray-core with desktop and mobile clients, shared config management, and platform-specific routing logic.
On Windows and macOS, the project already provides desktop-ready flows. Linux support is available through a GNOME-first Avalonia desktop head that reuses the macOS UI and integrates with Linux desktop services. Android support is present as an experimental Avalonia head with APK packaging groundwork, local proxy workflow, shared config management, and storage/runtime preparation for mobile packaging.
Linux support is GNOME-first and build-script driven.
- The repo includes an
InvisibleGorilla-XRay.Linuxproject built with Avalonia UI 11 and sharedInvisibleGorilla.Corelogic. - The Linux head reuses the macOS Avalonia views and adds Linux-specific handlers for proxy, TUN, notifications, startup, deep links, and app rules metadata.
./build.shis the main Linux entry point. It detects common distro families, installs/fetches required dependencies where possible, builds the Go wrapper aslibXRayCore.so, downloadstun2socksand geo databases, publishes a self-contained Linux GUI, and creates a distributable bundle.- The generated bundle includes
run-igxrayfor direct launch after unpacking, plusinstall.shfor system installation. After install, the app can be launched from the menu or withinvisible-gorilla-xray/igxray. - GNOME system proxy mode uses
gsettings; TUN mode usestun2sockswith privilegedip/DNS steps batched into onepkexec/sudocall per phase (v3.6.0). - Linux app-rules support currently persists the shared app-rules contract as a JSON bridge for future kernel-level enforcement.
- Simply Linux 11.1 / ALT Linux: see docs/linux-simply-linux.md for build, install, and one-time polkit setup (no repeated root password prompts).
Android support is experimental.
- The repo now includes an
InvisibleGorilla-XRay.Androidproject that can be packaged as an APK. - Shared config handling, local Xray listener startup, config import, and Android app-private storage setup are implemented.
- The Android mobile tunnel bridge is not bundled yet, so full
VpnService-backed TUN routing still needs a follow-up native runtime step. proxy modeon Android currently means a local listener on127.0.0.1:<port>rather than desktop-style global system proxy switching.
- Repeated Android connect and disconnect keeps working. OpenFlux no longer dies on the third or fourth cycle with a tunnel-start error and a stopped channel. Closing the tunnel no longer waits on a stuck stack, and a stuck close cannot block the next start.
- The home screen shows the channel state once. The speed bar moves from green through orange to red as throughput drops. A glitch is written to the activity log and marked with a red spot.
- The Goida check on a server card no longer kills the app. It checks the active node over TCP and skips that check while the tunnel is up.
- Desktop OpenFlux no longer dies when the log folder is missing. If the saved Logs path cannot be created, the sidecar writes next to the executable, then in local app data.
- Android STOP no longer takes the process down with a UI fault. Disconnecting OpenFlux or VLESS keeps the app open if the connection card or the hero animation throws.
- OpenFlux turns the tunnel on only after the exit answers. The phone uploads a browser snapshot so the exit can join, then checks the data path before VPN routing starts. If the peer does not answer, the tunnel stays down and the phone keeps its normal connection.
- The OpenFlux card ping measures the exit. The Wi-Fi check on that card is the exit health response, not the document page.
- The Tor card keeps its last check. A successful bridge ping stays on the card after the list refreshes.
- Tor settings live on the Tor profile. The bridge method, lines, and Ask Tor actions open with the Tor card, the same way OpenFlux keeps its document on its card. General settings no longer carry a separate Tor switch.
- The Tor card defaults to the snowflake line that finishes bootstrap on a censored mobile network. Orbot's March 2026 datapacket fronts stalled at 10% there, so they are not the default. Snowflake AMP, obfs4, and meek (Orbot's meek front) stay on that same card. Picking another server turns Tor off.
- Stopping the Android tunnel removes it. A later RUN no longer leaves the previous tun interface behind, which is what made the phone lose connectivity until a reboot.
- OpenFlux shows the real reason when Yandex asks for a check. The home screen says the document login was challenged, and that address is not written into the log.
- A second Android RUN no longer needs a phone reboot. The active config's server address is excluded from the TUN (
/32or/128) before the tunnel comes up, so traffic to the entry stays on Wi-Fi or mobile data. - Windows split tunnel no longer dials itself. sing-box keeps that server off the OS route table, and the adapter DNS is the configured resolver instead of
10.0.236.11.
- The OpenFlux editor hides when a Goida node takes over. Switching servers no longer leaves "Tunnel is up" on the server page after the tunnel has moved on or stopped.
- Android no longer dies when you switch Goida servers. Avalonia 11.0.10's virtualizing list threw during layout about 40 seconds after the tunnel stopped and killed the process. The node list now draws as a plain stack (capped at 250 rows) and updates the same collection in place.
- RUN no longer sits on "Wait for running" for every profile. OpenFlux was waiting on its own log lock, so OpenFlux and VLESS both froze at start. STOP and the next RUN now finish.
- The Android connection card follows the live tunnel. As soon as RUN starts it shows the current mode, then the exit IP. STOP drops the previous exit and type.
- The Android notification shade stays in sync. A new VPN start no longer freezes the panel on Stopped with zero traffic. While the tunnel is up the title says Running and RX/TX keep moving.
- Android hero pulses like a Wi-Fi signal while the tunnel is up. Three rings expand outward from the gorilla and the green disc behind it breathes. Stopped state stays still.
- OpenFlux client refreshes its Yandex login every 3 hours by restarting the sidecar. The exit unit on the server already recycles every 4 hours, so a phone left connected overnight does not sit on a dead session.
- Android connection card clears the exit IP on STOP and ignores a late lookup that would paint the tunnel result after disconnect.
- OpenFlux editor can copy the document URL and the derived key.
- Android no longer freezes on STOP or on the next RUN. The Go tun2socks DNS path called back into managed code to run
VpnService.protect(); that binder call blocked on the system_server VPN lock during teardown and stalled the whole Mono runtime (measured: 26 s of a completely frozen app, followed by an ANR). The app is already excluded from its own TUN in every app-rules mode, so the callback is no longer registered, and it is unbound before teardown on the devices that still need it. Teardown now takes 0.3-2 s with a responsive UI. - OpenFlux home widget shows the exit IP through SOCKS once after RUN (same channel as traffic). City lookup stays off the mux.
- Windows / Linux / macOS ship the same Core: OpenFlux no longer probes ipify at start, YouTube is not prewarmed on the mux, and STOP times each teardown step.
- Android OpenFlux home widget reads the exit IP through SOCKS once after RUN. STOP tears down leftover VPN/OpenFlux so VLESS RUN does not sit on Loading config until timeout.
- Android OpenFlux home widget reads the exit IP through SOCKS once after RUN, then looks up city off-mux. STOP kills leftover OpenFlux without freezing the UI so VLESS can start next.
- Android OpenFlux home widget reads the exit IP through SOCKS once after RUN, then looks up city off-mux. Switching to VLESS waits for OpenFlux/TUN teardown so RUN does not hang.
- Android OpenFlux sidecar matches the live exit again — v3.6.35 rebuilt the client from older source, so SOCKS accepted connections but the document mux never forwarded. Traffic path is the same as the 3.6.27 sidecar that last worked.
- Android OpenFlux no longer pins Chrome to a dead HTTP proxy — VpnService
setHttpProxyto10.0.236.10:18080never reached the TUN fd, so Chrome had no internet while Gorilla showed Running. Traffic now uses the same SOCKS tun2socks path as VLESS. Mux limiting stays.
- Android OpenFlux no longer kills its own mux at RUN — startup does not ipify/YouTube through the single pipe, and the sidecar no longer drops idle streams after 20s. Ping in server settings is the live check; the home IP line is optional.
- Android OpenFlux and VLESS start path restored to v3.6.27 — experimental IP probes after 3.6.27 made OpenFlux dead and VLESS intermittent. Shade RUN/STOP status from 3.6.27 stays.
- Android status in the notification shade follows RUN/STOP — the foreground notification is refreshed with the live state instead of staying on "Preparing…".
- Android STOP/RUN no longer ANRs — VPN start and stop stay off the UI thread.
StopForegroundis not posted to the main looper, so STOP does not freeze 3–4 seconds later or trip FocusEvent when you come back. - App rules Save stays visible, and the overlay no longer covers STOP or the server list.
- Android App rules Save/Cancel stay on screen — they sat under STOP, so the overlay also blocked the server list and settings.
- RUN no longer ANRs on the first tap — VPN start uses a lightweight foreground notification, and the IP widget does not probe during "Wait for running".
- Android no longer ANRs when you come back from Chrome/YouTube after a second VLESS RUN — VPN notification updates no longer block the main looper, and the IP widget waits until window focus is done.
- Android STOP/RUN no longer freezes or ANRs — teardown stays off the UI thread, OpenFlux kill no longer takes the app process group with it, and leaving the app for a site like 2ip.io does not hang the main looper.
- OpenFlux page refresh and video start are less sticky — more parallel SOCKS streams (24) and dials (6), faster idle-socket evict. Xray / Goida / Tor stay on the unlimited path.
- SOCKS5/VLESS connection check works again on Android TUN (session user/pass handshake).
- Android OpenFlux no longer freezes the UI or the channel when you skip videos — idle YouTube sockets are dropped, new CONNECTs are queued two at a time, and live streams are left alone. Xray / Goida / Tor keep the unlimited tun2socks path.
- Dead Volga sockets recover in ~20 seconds instead of sitting silent for a minute.
- OpenFlux is faster on Android, Windows, and Linux — more parallel streams, HTTP CONNECT reuse/prewarm, no extra probe wait before the tunnel starts. Android rejects QUIC immediately so YouTube/Chrome fall back to TCP instead of hanging.
- Android TUN actually browses — browsers use a local HTTP CONNECT proxy on the VPN address. IP widget and real sites both show the Fornex exit.
- Linux ships the OpenFlux sidecar next to the app (
OpenFlux/openflux).
- OpenFlux shows Live only after a real SOCKS probe — if the Yandex document peer is dead, the panel says the exit does not answer instead of Disconnected/Live. User TUN bypass list is kept (
openflux.exeis still excluded). - Android APK (arm64) is in the GitHub release again. The server list now includes OpenFlux / Yandex document like Windows: paste the Disk link, Apply, then RUN.
- OpenFlux honors TUN — if Mode is TUN, traffic goes through the virtual adapter into the local OpenFlux SOCKS. Proxy mode is unchanged (HTTP CONNECT bridge).
- OpenFlux websites work in the browser — Chrome now uses a local HTTP proxy in front of SOCKS5, instead of the Windows
socks=setting that closed connections. - Ping is visible — the OpenFlux line and the IP widget show latency in ms.
- OpenFlux key comes from the Yandex URL — paste the document link, Gorilla shows the key, another client needs only that link.
- Apply checks the document — format, reachability, and ping, then registers the URL on the exit.
- OpenFlux starts without switching modes — TUN is ignored, the app uses system Proxy by itself.
- Apply works while disconnected — the URL is saved and registered on the exit immediately.
- docs.yandex.ru / disk.yandex.ru edit links are treated as the same document.
- OpenFlux (Windows) — connect through a Yandex Document instead of VLESS. Paste the Disk/Volga link, the shared encryption key, and Gorilla starts a local SOCKS sidecar. Changing the link restarts only OpenFlux, not the whole app.
- One document per exit process — the Fornex exit registers each new URL separately, so several clients can use different documents at the same time.
- Windows TUN starts on the first click — the UI waits until the virtual adapter and routes are actually up, instead of showing Connected while wintun is still being created.
- TUN service 0.3.10 — first-time adapter wait is 20s (was 6s), so a cold wintun load no longer skips routes.
- Goida lists stay current — fetch from several mirrors if
raw.githubusercontent.comis blocked, keep the previous list when a download fails, and normalize Base64 / glued URIs the same way AvenCores does. - xhttp / httpupgrade configs work — new VLESS transports from goida-vpn-configs now convert to valid Xray JSON.
- Idle connection check — while disconnected, Goida runs TCP on the list plus a small native VLESS sample so working nodes show real latency.
- Windows: crash while idle — background Goida checks no longer call native
XRayCore.dllwhen the proxy is disconnected. - Windows: lighter idle UI — the public-IP timer runs only while connected, and dispatcher exceptions no longer kill the app.
- Windows: faster IP lookup — disconnected probes reuse one
HttpClientinstead of opening a new connection for every endpoint.
- Windows hotfix over v3.6.8 — keeps the TUN v0.3.9 routing fix and adds native crash hardening plus stale TUN cleanup after abnormal exits.
- Windows TUN: fix traffic not tunneling — resolve the physical default gateway before the virtual adapter is addressed, bind
tun2socksto the uplink NIC (requires InvisibleGorilla-TUN v0.3.9+). - Windows: fixed random
XRayCore.dllcrash — nativeboolparameters are marshaled correctly for the cgo DLL, removing a likely cause of0xc0000005access violations. - Windows: TUN cleanup is safer — shutdown and crash cleanup now disable TUN/routes before stopping native Xray, and startup tries to disable stale TUN state left by an older crashed build.
- Windows: quieter TUN SOCKS listener — local TUN SOCKS auth is disabled on localhost to avoid storms of
invalid username or passwordfrom stale system proxy state.
- Linux: crash on profile select —
Settings.jsonsave no longer crashes when the data folder is root-owned; startup triespkexec chownonce to repair permissions. - Linux: empty VPN server address — TUN bypass route now reads the server host from the on-disk VLESS config (
settings.vnext[0].address), not only the native runtime JSON (which often omits it). - Linux: pkexec every connect —
scripts/linux/install-tun-policy.shis bundled in the tarball for one-time polkit setup.
- Linux: TUN no longer aborts on app-rules file permission errors —
linux-transparent-proxy-config.jsonis optional metadata; write failures (e.g. data folder owned by root aftersudo ./run-igxray) no longer block VLESS/TUN. Startup notifies withchownfix command; fallback write to$XDG_RUNTIME_DIRor/tmp.
- Linux: fix "Failure processing application bundle" —
run-igxraynow setsDOTNET_BUNDLE_EXTRACT_BASE_DIRto a writable cache (~/.cache, bundle folder, or/tmp) so single-file .NET can extract on Simply Linux and similar desktops where the default cache path is unavailable.
- Linux: do not run with sudo — starting via
sudo ./run-igxraybroke TUN setup (pkexec fails under root), Xray stopped, but the UI stayed on "Running" withConnection refused (127.0.0.1:10801). Privilegedip/resolvectlcommands now run directly when already root; the launcher warns against sudo; tunnel setup errors reset the UI and show a desktop notification. - Linux TUN setup validation — creating the tun interface is now checked; a failed setup aborts with a clear message instead of a half-enabled state.
- Fixed Linux/macOS routing loop (socket storm / OOM) — the VPN server now always keeps a direct, non-TUN route. The server address is resolved to its IP (Reality configs can use a hostname) and pinned to the real uplink before the TUN default routes are installed. Previously, if the bypass route was skipped, xray's own outbound to the server re-entered the tunnel and looped, spawning thousands of sockets (
too many open files→Out of memory). If a safe bypass can't be set up, the client now refuses to enable TUN with a clear error instead of looping. - Connection info reliability on Linux — with the loop gone, the local SOCKS listener no longer gets exhausted, so the live IP/location check stops failing with
Cannot assign requested address. - Windows first-launch fix — the wait for the local proxy listener was raised from 5s to 15s so a slow first start (on-access AV scanning the freshly extracted build) no longer surfaces as
The application can't tunnel the system.
- Connection info shows full data over the tunnel — geo-capable lookups (
ipinfo.io,ipwho.is) are queried first so Location/Provider populate instead of just a bare IP (Android/Linux/macOS); IP-only services stay as a last-resort fallback. - Windows layout fix — the main window content is vertically balanced; the status icon no longer slips under the header and the connection card is pinned to the bottom.
- Steadier probing — lookups remain serialized (one at a time) with the post-connect grace period, so there is no request storm right after connect.
- Linux TUN: batched
pkexec/sudo(1–2 prompts per connect/disconnect); optional polkit rule (scripts/linux/install-tun-policy.sh). - Linux app rules: async app list, no freeze on template rename; saving rules does not reconnect VPN.
- Simply Linux 11.1 guide: docs/linux-simply-linux.md.
- Release hygiene: Linux/Windows publish bundles strip
Settings.json,Configs/,Logs/, Goida caches before packaging.
- Linux TUN: one pkexec per phase —
ip/resolvectlcommands are batched; connect/disconnect needs 1–2 password prompts instead of ~10 (optional polkit rule for zero prompts: Simply Linux guide). - Linux app rules UI — app list loads in background; renaming templates no longer freezes the window; saving rules does not force VPN reconnect on Linux.
- Connection info hardening — tunnel stays up when external IP-check services fail.
- Android Goida / connection info — tunnel failover, live IP checks, safer virtualized node list.
- Windows build/publish — user runtime data stripped from release output; auto-install GCC (w64devkit) and download progress in
build.ps1.
- Per-connection app rules (Windows) - the App rules dialog now has an "Apply rules to connection" selector, so you can assign a template and routing mode to any server config (active or not), then switch between them like VLESS keys.
- Cleaner app picker (Windows) - running apps are listed by their friendly product name instead of the current window title (no more giant browser-tab headings), the dialog is resizable, and the app list is taller and easier to scan.
- Tor bridge profiles (Android) - paste a bridge key to create a switchable Tor profile in the server list, check its availability/latency, and see it on the main screen (from v3.5.8).
- Faster bridge fetch + fallback - bridge requests time out in 20s and fall back to built-in obfs4 bridges when the bridge service is unreachable (from v3.5.8).
- Analytics removed - the client never transmits usage data, and the "Send analytics" checkbox is gone on all platforms (from v3.5.8).
- One-click connect on desktop - import config and press Run
- VLESS, VMess, Trojan, Shadowsocks - all major protocols supported
- Tor support - route over the Tor network with built-in or custom obfs4 bridges (Orbot-style); Android exposes Tor bridges as switchable profiles
- Proxy and TUN modes - Windows/macOS desktop routing, Linux GNOME proxy + TUN support, Android groundwork for local proxy and future mobile VPN
- Per-connection app rules - choose all-apps / bypass-selected / only-selected routing per server config with reusable templates (Windows)
- Server management - add, test, switch between multiple servers
- Connection testing - check latency with one click
- Subscription support - auto-update server lists from provider links
- Shared core logic - common config, templates, and Xray wrapper integration across platforms
- Privacy-first - no analytics or telemetry; nothing is sent anywhere
- Diagnostic logging - startup/runtime troubleshooting for both desktop and mobile app roots
- Windows and macOS: use the latest release from the Releases page.
- Linux: build from source with
./build.sh, then rundist-linux/<rid>/InvisibleGorilla-XRay-<rid>/run-igxrayor install the generated bundle. - Android: build the APK from source with
.\build-android.ps1.
Open the app, import a raw JSON config, config link, or subscription, then select the config you want to run.
- Desktop: choose your mode and click Run.
- Linux: use Proxy mode on GNOME for
gsettings-based system proxy, or TUN mode for full-route tunneling through bundledtun2socks. - Android: use the experimental Android head to manage configs and start the local proxy workflow while the mobile tunnel bridge is being finalized.
Windows
git clone https://github.com/hvkeyn/InvisibleGorilla-XRayClient.git
cd InvisibleGorilla-XRayClient
.\build.ps1The script auto-installs Go, GCC, and .NET 7 SDK if missing, then builds everything for Windows.
| Command | Description |
|---|---|
.\build.ps1 |
Full Windows build |
.\build.ps1 -Publish |
Build + single-file executable |
.\build.ps1 -Step GoWrapper |
Only build XRayCore.dll |
.\build.ps1 -Step DotNet |
Only build the .NET desktop app |
macOS
git clone https://github.com/hvkeyn/InvisibleGorilla-XRayClient.git
cd InvisibleGorilla-XRayClient
chmod +x build-macos.sh
./build-macos.shTested on macOS Sequoia 15.7+ (Apple Silicon and Intel). Builds an .app bundle with Avalonia UI.
The raw publish output is written to publish-macos/<rid>/. The runnable bundle is written to dist-macos/<rid>/ and contains InvisibleGorilla-XRay.app, run-igxray, README-MACOS.txt, and a .tar.gz archive. The internal executable is dist-macos/<rid>/InvisibleGorilla-XRay.app/Contents/MacOS/InvisibleGorilla-XRay.Mac.
| Command | Description |
|---|---|
./build-macos.sh |
Full macOS build |
./build-macos.sh --runtime osx-arm64 |
Build Apple Silicon output |
./build-macos.sh --runtime osx-x64 |
Build Intel output |
./build-macos.sh --step go |
Only build XRayCore.dylib |
./build-macos.sh --step bundle |
Only package the .app bundle |
Linux
git clone https://github.com/hvkeyn/InvisibleGorilla-XRayClient.git
cd InvisibleGorilla-XRayClient
chmod +x build.sh
./build.shThe Linux build targets ALT Linux + GNOME first, but the script also covers Debian/Ubuntu, Fedora/RHEL, openSUSE, and Arch package families. It publishes InvisibleGorilla-XRay.Linux for linux-x64 or linux-arm64 and bundles runtime files into dist-linux/<rid>/.
After a successful build:
cd dist-linux/linux-x64/InvisibleGorilla-XRay-linux-x64
./run-igxrayFor system installation:
./install.sh
invisible-gorilla-xray
# or
igxray| Command | Description |
|---|---|
./build.sh |
Full Linux build + distributable bundle |
./build.sh --runtime linux-arm64 |
Build for Linux ARM64 |
./build.sh --skip-deps |
Skip system package installation |
./build.sh --step go |
Only build Libraries/libXRayCore.so |
./build.sh --step tun2socks |
Only fetch bundled tun2socks |
./build.sh --step dotnet |
Only publish the Avalonia Linux GUI |
./build.sh --step bundle |
Only create the dist-linux/<rid>/ bundle |
Android
On Windows, .\build-android.ps1 now installs missing prerequisites automatically on first run. That includes:
- .NET 8 SDK
- .NET Android workload
- JDK 17
- Android command-line tools
- Android SDK platform/build-tools
- Android NDK
- Go 1.23
You still need a working internet connection, and some installers may request elevation depending on local system policy.
git clone https://github.com/hvkeyn/InvisibleGorilla-XRayClient.git
cd InvisibleGorilla-XRayClient
.\build-android.ps1The Android build script:
- checks for missing build dependencies and installs them automatically when possible
- downloads
geoip.datandgeosite.datintoInvisibleGorilla-XRay.Android/Assets/Runtime - builds the Android native bridge from
XRay-Wrapperusing the Android NDK and packages it into runtime assets - publishes
InvisibleGorilla-XRay.Androidas an APK
| Command | Description |
|---|---|
.\build-android.ps1 |
Full Android build + APK publish |
.\build-android.ps1 -SkipNativeBridge |
Reuse the existing Android native bridge runtime asset in Assets/Runtime |
.\build-android.ps1 -SkipGeoFiles |
Reuse existing geo files in Assets/Runtime |
.\build-android.ps1 -NoPublish |
Prepare runtime assets without publishing the APK |
.\build-android.ps1 -KeystorePath <path> -KeyAlias <alias> |
Publish a signed APK using ANDROID_SIGNING_PASSWORD |
| Component | Technology | Platform |
|---|---|---|
| Windows GUI | WPF (.NET 7, C#) | Windows |
| macOS GUI | Avalonia UI 11 (.NET 7, C#) | macOS |
| Linux GUI | Avalonia UI 11 (.NET 7, C#) | Linux |
| Android GUI | Avalonia UI 11 (.NET 8 Android, C#) | Android |
| Shared logic | InvisibleGorilla.Core (.NET class library) |
Cross-platform |
| Proxy engine | Xray-core v25.1.30 | Cross-platform |
| Native bridge | Go 1.23 -> cgo shared library (.dll / .dylib / .so) |
Windows / macOS / Linux / Android |
| Windows tunnel service | InvisibleGorilla-TUN | Windows only |
| Linux tunnel layer | tun2socks, iproute2, pkexec / sudo, GNOME gsettings proxy integration |
Linux |
| Android mobile VPN layer | VpnService groundwork in Android head |
Android |
| Geo routing | v2fly geoip + domain-list | Cross-platform |
| Problem | Solution |
|---|---|
| App shows "Running" but traffic does not change on desktop | Check diagnostic.log in the app folder. Try a different server or protocol. |
| Linux archive was unpacked but the executable is hard to find | Run ./run-igxray from the unpacked bundle root, or run ./install.sh and then start invisible-gorilla-xray / igxray. |
| Linux TUN mode cannot start | Make sure pkexec or passwordless/current-user sudo can run privileged ip/DNS commands. The app fails closed if TUN setup is denied. |
| Linux proxy mode does nothing | GNOME proxy mode depends on gsettings org.gnome.system.proxy; on non-GNOME desktops it may no-op while TUN mode remains available. |
| Android proxy mode starts but apps do not route automatically | Android currently starts a local listener; point apps to 127.0.0.1:<proxy-port> or wait for the follow-up mobile tunnel bridge. |
| Android TUN mode reports an error | This repository now contains the Android groundwork, but the native mobile tunnel bridge is still a follow-up task. |
| Android native bridge asset is missing during packaging | Run .\build-android.ps1 with a valid ANDROID_NDK_ROOT so the wrapper can build and package the Android shared library runtime asset. |
dotnet publish cannot find Android SDK |
Set ANDROID_SDK_ROOT or ANDROID_HOME, or pass -AndroidSdkDirectory to .\build-android.ps1. |
| Desktop proxy stays on after a crash | Restart the app - it cleans up stale proxy settings on startup/shutdown. |
- Report bugs - open an issue
- Add a language - see Language.md
- Submit code - fork, branch, and send a pull request
- InvisibleMan-XRay - original project
- Xray-core - proxy engine
- InvisibleGorilla-TUN - Windows tunnel companion service

