NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #194 by repository stars
Last release 1 months ago
01 Sep 2026
Release timing varies
gaps range from 8 days to 12 months
Some releases are documented
notes for 9 of 30 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
73 releases · first in 2015
Nothing published for this version
Chisel 1.12.0 is a reliability and security release focused on recovering cleanly from network and configuration changes, making failures visible, and…
Chisel 1.12.0 is a reliability and security release focused on recovering
cleanly from network and configuration changes, making failures visible, and
hardening unauthenticated surfaces.
This stable release follows three public release candidates. No 1.12-specific
runtime regressions were reported after rc3. The archive corruption reported
for rc1 was fixed in rc2; release CI now integrity-tests every .gz and
.zip before any asset or image is published.
x/crypto/ssh, bounding keepalive requests, and closing dead connectionssocks5:// client proxy URLs.x/crypto/ssh to v0.55.0 to addressgo install builds and adds useful info-levelopts, including terminal-awarelatest, 1, and 1.12 without rebuilding them.Four changes may require action:
--socks5 and --authfile, users who should retain SOCKS5 access needsocks. The wildcard "" continues to match--fingerprint must use the full SHA256 fingerprint, or the full deprecated--auth values must use <user>:<pass>; values without a colon now fail at--max-retry-count exits non-zero. Cancellation andThe wire protocol remains chisel-v3. Mixed 1.11.x/1.12 deployments continue
to work, with new behavior degrading to the older peer's capabilities.
See Upgrading to 1.12 for
configuration details and the
full 1.12 review
for the complete compatibility analysis.
One column per quarter.
c408126 Harden the 1.12 release changes
1. Breaking changes for existing users
Supersedes v1.12.0-rc1, whose
linux_amd64.gzanddarwin_amd64.gzassets were corrupted by a goreleaser v2.12.7 packaging bug (#610). No chisel code changes — rebuilt with goreleaser v2.17.0, and CI now integrity-tests every archive before a release can ship. All 28 rc2 archives verified.
Release candidate — soaking for community testing before 1.12 becomes latest. Please try it and report anything odd in #610.
Try it:
curl "https://i.jpillora.com/jpillora/chisel@v1.12.0-rc2!" | bashdocker pull jpillora/chisel:1.12.0-rc2 (or ghcr.io/jpillora/chisel:1.12.0-rc2)Upgrading from 1.11.x? Read the Upgrading to 1.12 README section. What follows is from 1.12-changes.md, the verified UX & compatibility review of this line.
--authfile — already on master, branch adds the missing docsEnforcement (UserAddr() → "socks", channel-level ACL gate) shipped in v1.11.7 (927abde), so branch-vs-master this is not a new break — but today's released chisel has an undocumented breaking change: its README/--help say nothing about the socks token. The branch fixes that in five places (server help, client help, README auth section, SOCKS guide, 1.12 changelog) including the migration line "existing authfiles which should allow SOCKS5 must add an entry matching socks". This documentation is arguably the most valuable UX content on the branch.
The original review flagged a diagnosability gap here: a denied user's server-side trace was Debugf("Denied connection to socks (ACL)"), invisible without -v, making "socks stopped working after upgrade" the #1 anticipated support ticket. This is now fixed — commit 3c66f9b raised it to Infof("Denied connection to %s (ACL)", hostPort) (share/tunnel/tunnel_out_ssh.go:57), so operators see socks ACL denials at the default log level.
Master's verifyLegacyFingerprint used strings.HasPrefix, so --fingerprint a5:b3 matched any key with that MD5 prefix (~1-in-65k spoof risk). The branch requires the full 16-octet colon form (client/client.go:248). Affected users fail loudly at connect with Invalid fingerprint (...), and the preceding info line helpfully prints the correct SHA256 fingerprint to migrate to. SHA256 fingerprints were always exact-match — only MD5 stragglers with shorthand configs are affected. Documented in README Security, and the 1.12 changelog now lists it as breaking (added in c4038c3).
--auth without a colon is now a fatal startup error — branch-new, loudOn master, --auth nocolon silently degraded (server: user never registered → effectively no auth; client: empty credentials). That's a security footgun, and the branch turns it into invalid auth string, expected <user>:<pass> at startup on both sides. Anyone hit by this was already running something other than what they believed. Documented in README, and the 1.12 changelog now lists it as breaking (added in c4038c3).
--max-retry-count exhaustion: 0 → non-zero — branch-new, silent for automationclient_connect.go now returns connection attempts exhausted on give-up (ctx-cancel/Ctrl-C still exits 0). Correct behavior, but it's the one change scripts and Restart=on-failure units experience with no error message to notice — the semantics of $? just flip. It is in the 1.12 changelog, which is the right mitigation.
--min-retry-interval). Softer thundering-herd on server restarts; individual reconnects marginally slower.CHISEL_PING_TIMEOUT, default = keepalive interval, so ~50s at defaults vs 15–60 min of kernel retransmit limbo on master). Sleep/wake and NAT-timeout hangs become visible reconnects in logs. Old peers reply to pings, so mixed versions are fine.CHISEL_DIAL_TIMEOUT 30s). Apps see "connection refused/timeout" instead of master's instant-success-then-EOF. Strictly better UX, but tools that measured "connect success" will notice.shutdown(SHUT_WR) traverses the tunnel (share/cio/pipe.go), fixing netcat-style pipelines and rsync. Falls back to full-close against old peers — no hangs, just old behavior.CHISEL_SHUTDOWN_GRACE 5s, under docker's 10s default), second forces exit. Master died instantly on SIGTERM.Open (user=… addr=… remotes=…) / Close (… duration=…) and Login failed for user X (ip) — failed logins are finally fail2ban-able. Two side effects: log parsers keyed on the old debug Closed connection need updating, and tunnel endpoints now appear in default-level logs (mild privacy consideration for shipped logs).--auth user is pinned across reloads and wins name clashes; removed users lose new tunnels but established ones aren't cut (documented). Operators who habitually restart after edits will find edits now apply live..*-style files keep working but get noisy — the warning is doing its job, since unanchored patterns really do over-match.CHISEL_WS_READ_LIMIT, 0 disables) on both sides. Max legit SSH packet is ~35KB, so ~2× headroom; the only tail risk is a pathological config payload (thousands of remotes on one client), and the env knob is the escape hatch.CHISEL_UDP_DEADLINE 15s), so DNS-heavy exit nodes recover instead of wedging.BindRemotes failure now unbinds earlier listeners (no zombie ports); bad --keyfile errors no longer echo raw key material into logs; go install builds report real versions; 3000/UDP uppercase now parses.No compile-breaking signature changes in client, server, or share/.... Additive: client.Config.MinRetryInterval, Client.Ready(ctx), Tunnel.Ready, UserIndex.PinUser. Behavioral: NewServer returns errors where master called log.Fatal inside (a win for embedders), Remote.UserAddr() returns "socks" for forward-socks, L4Proto lowercases — only code depending on those exact outputs would notice.
Protocol string is unchanged (chisel-v3), and no handshake changes were found.
socks5:// proxy scheme is client-local.1. Breaking changes for existing users
⚠️ Superseded by v1.12.0-rc2 — the
linux_amd64.gzanddarwin_amd64.gzassets below are corrupted (goreleaser v2.12.7 packaging bug, #610); their checksums match because the corruption happened at build time. All other assets and the Docker images are intact, but please use rc2 (identical chisel code, rebuilt + integrity-verified assets).
Release candidate — soaking for community testing before 1.12 becomes latest. Please try it and report anything odd in #610.
Try it:
curl "https://i.jpillora.com/jpillora/chisel@v1.12.0-rc1!" | bashdocker pull jpillora/chisel:1.12.0-rc1 (or ghcr.io/jpillora/chisel:1.12.0-rc1)Upgrading from 1.11.x? Read the Upgrading to 1.12 README section. What follows is from 1.12-changes.md, the verified UX & compatibility review of this line.
--authfile — already on master, branch adds the missing docsEnforcement (UserAddr() → "socks", channel-level ACL gate) shipped in v1.11.7 (927abde), so branch-vs-master this is not a new break — but today's released chisel has an undocumented breaking change: its README/--help say nothing about the socks token. The branch fixes that in five places (server help, client help, README auth section, SOCKS guide, 1.12 changelog) including the migration line "existing authfiles which should allow SOCKS5 must add an entry matching socks". This documentation is arguably the most valuable UX content on the branch.
The original review flagged a diagnosability gap here: a denied user's server-side trace was Debugf("Denied connection to socks (ACL)"), invisible without -v, making "socks stopped working after upgrade" the #1 anticipated support ticket. This is now fixed — commit 3c66f9b raised it to Infof("Denied connection to %s (ACL)", hostPort) (share/tunnel/tunnel_out_ssh.go:57), so operators see socks ACL denials at the default log level.
Master's verifyLegacyFingerprint used strings.HasPrefix, so --fingerprint a5:b3 matched any key with that MD5 prefix (~1-in-65k spoof risk). The branch requires the full 16-octet colon form (client/client.go:248). Affected users fail loudly at connect with Invalid fingerprint (...), and the preceding info line helpfully prints the correct SHA256 fingerprint to migrate to. SHA256 fingerprints were always exact-match — only MD5 stragglers with shorthand configs are affected. Documented in README Security, and the 1.12 changelog now lists it as breaking (added in c4038c3).
--auth without a colon is now a fatal startup error — branch-new, loudOn master, --auth nocolon silently degraded (server: user never registered → effectively no auth; client: empty credentials). That's a security footgun, and the branch turns it into invalid auth string, expected <user>:<pass> at startup on both sides. Anyone hit by this was already running something other than what they believed. Documented in README, and the 1.12 changelog now lists it as breaking (added in c4038c3).
--max-retry-count exhaustion: 0 → non-zero — branch-new, silent for automationclient_connect.go now returns connection attempts exhausted on give-up (ctx-cancel/Ctrl-C still exits 0). Correct behavior, but it's the one change scripts and Restart=on-failure units experience with no error message to notice — the semantics of $? just flip. It is in the 1.12 changelog, which is the right mitigation.
--min-retry-interval). Softer thundering-herd on server restarts; individual reconnects marginally slower.CHISEL_PING_TIMEOUT, default = keepalive interval, so ~50s at defaults vs 15–60 min of kernel retransmit limbo on master). Sleep/wake and NAT-timeout hangs become visible reconnects in logs. Old peers reply to pings, so mixed versions are fine.CHISEL_DIAL_TIMEOUT 30s). Apps see "connection refused/timeout" instead of master's instant-success-then-EOF. Strictly better UX, but tools that measured "connect success" will notice.shutdown(SHUT_WR) traverses the tunnel (share/cio/pipe.go), fixing netcat-style pipelines and rsync. Falls back to full-close against old peers — no hangs, just old behavior.CHISEL_SHUTDOWN_GRACE 5s, under docker's 10s default), second forces exit. Master died instantly on SIGTERM.Open (user=… addr=… remotes=…) / Close (… duration=…) and Login failed for user X (ip) — failed logins are finally fail2ban-able. Two side effects: log parsers keyed on the old debug Closed connection need updating, and tunnel endpoints now appear in default-level logs (mild privacy consideration for shipped logs).--auth user is pinned across reloads and wins name clashes; removed users lose new tunnels but established ones aren't cut (documented). Operators who habitually restart after edits will find edits now apply live..*-style files keep working but get noisy — the warning is doing its job, since unanchored patterns really do over-match.CHISEL_WS_READ_LIMIT, 0 disables) on both sides. Max legit SSH packet is ~35KB, so ~2× headroom; the only tail risk is a pathological config payload (thousands of remotes on one client), and the env knob is the escape hatch.CHISEL_UDP_DEADLINE 15s), so DNS-heavy exit nodes recover instead of wedging.BindRemotes failure now unbinds earlier listeners (no zombie ports); bad --keyfile errors no longer echo raw key material into logs; go install builds report real versions; 3000/UDP uppercase now parses.No compile-breaking signature changes in client, server, or share/.... Additive: client.Config.MinRetryInterval, Client.Ready(ctx), Tunnel.Ready, UserIndex.PinUser. Behavioral: NewServer returns errors where master called log.Fatal inside (a win for embedders), Remote.UserAddr() returns "socks" for forward-socks, L4Proto lowercases — only code depending on those exact outputs would notice.
Protocol string is unchanged (chisel-v3), and no handshake changes were found.
socks5:// proxy scheme is client-local.310eec3 Bump golang.org/x/crypto from 0.48.0 to 0.52.0
927abde Improve SOCKS auth: enforce per-user ACL on socks channels
Nothing published for this version
44310b6 Enforce auth ACL on tunnel channels
4df5fcf Update deps and fix crypto/tls vulnerability
Fix CHISEL_KEY environment variable ignored when --keyfile not set by @Copilot in #571
Remove obsolete Windows ARM32 build exclusions from goreleaser
💖 Generated with Crush
Co-Authored-By: Crush crush@charm.land
Nothing published for this version
Nothing published for this version
Nothing published for this version
v1.10.1 Compare # Choose a tag to compare
v1.10.1
Compare
v1.10.0 Compare # Choose a tag to compare
v1.10.0
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →