Chute iOS Release Note
Version 1.2.2 (382)
New Features:
- Added proxy chaining: a policy can name an
underlying-proxyand reach its server through it, a policy group can send every member through one upstream, and the new Front Proxy row under Advanced (global-underlying-proxy) does the same for every node that sets no upstream of its own. Every transport except Tailscale can be chained — stream protocols ride the upstream's stream; Hysteria2, TUIC, MASQUE and XHTTP over HTTP/3 ride its UDP relay in fixed 1280-byte packets; WireGuard and AmneziaWG tunnel through it with a 1280-byte inner MTU; SSH and AnyTLS sessions open over it. A chain that loops, nests more than 16 levels deep or names a policy that does not exist is refused, never sent out directly - Added relay groups (
relay, as in Clash and mihomo): the members are chained in the order written — the first is dialled directly, each later one is reached through the ones before it, and the last connects to the destination. The group editor offers Relay, keeps the members in that order and asks for at least two - Added random groups (
random, as in Shadowrocket): every connection picks a member at random, UDP only among the members that carry UDP. A random group has no selection to change, so it is left out wherever you pick a group's policy, and the group editor keeps it a random group - Added the proxy chain to the Dashboard and the web console: the request detail and the UDP list name every hop (
Airport/HK-01 → Landing), and HAR export carries the path - Added Download Via to the rule and proxy provider editors:
policy=fetches that list through the chosen policy, and a policy name that does not exist makes the download fail instead of going out directly - Added UDP over TCP to the Shadowsocks editor —
udp-over-tcp, version 1 or 2 — so a proxy's UDP rides inside its TCP connections and works even through a chain whose upstream carries no UDP - Added UDP to VMess and VLESS: UDP sent to either used to be refused outright (it followed
udp-policy-not-supported-behaviour, REJECT by default); it now travels over one connection per destination, as in mihomo, sing-box and Shadowrocket - Added jq to Body Rewrite:
http-request-jqandhttp-response-jqrun a real jq program over a JSON body, and the editor offers a JQ PROGRAM field; an invalid program is reported and its rule skipped, and a non-JSON body, a program that fails or empty output all leave the body untouched - Added generic scripts: a
type=genericscript has no automatic trigger and runs only on demand — from its editor's Run button, or overGET /api/scriptsandPOST /api/scripts/run. The Script editor also gains an Event Name field: onlynetwork-changedis delivered, so an event script that names any other event never runs - Added dedicated DNS pools:
direct-dns-serverresolves the domains a rule sends DIRECT,proxy-dns-serverresolves your proxy servers' own hostnames, andfallback-dns-serveris asked when the main servers give no answer; each falls back to the global servers, and the DNS editor has a row for each - Added
#proxy/#proxy=<policy>to DNS upstreams, DoQ and DoH3 included: a QUIC resolver rides the policy's UDP relay, a policy that cannot carry UDP skips that server instead of asking it directly, a plain resolver sent through a policy switches to DNS over TCP, and plaintcp://upstreams are accepted for paths that drop DNS over UDP - Added
encrypted-dns-follow-outbound-mode,allow-dns-svcb— HTTPS and SVCB questions are answered empty unless it is on — and per-server#h3,#skip-cert-verify,#disable-ipv4,#disable-ipv6and#disable-qtype= - Added more to Local DNS Mapping: a
[Host]entry keeps every server it lists and queries them in parallel, maps one domain to several addresses, keys on a rule set (RULE-SET:<url>), runs atype=dnsscript for that domain (script:<name>), and acceptsssid:<name>for a per-network mapping - Added rule notifications: any rule, FINAL included, takes
notification-text=andnotification-interval=and posts a notification when it matches, at most once per interval for each rule; notifications follow the app's Allow Notifications switch, and tapping one opens the URL it carries - Added
FINAL,<policy>,dns-failed: when a name cannot be resolved, the connection is opened on the FINAL policy with remote resolution instead of being closed - Added the REJECT family as real policies — REJECT-DROP, REJECT-NO-DROP, REJECT-TINYGIF, REJECT-IMG, REJECT-DICT, REJECT-ARRAY, REJECT-200 and REJECT-VIDEO — each answering an HTTP request with its documented body, with a host rejected more than 50 times in 30 seconds upgraded to REJECT-DROP; the policy picker offers them, writes DIRECT / REJECT / PROXY tokens where a localized label used to be written, and repairs labels an older build left behind
- Added inline rule sets:
[Ruleset Name]sections are listed apart in the configuration editor, edited line by line, and referenced asRULE-SET,<name>, including references between them — up to eight deep, with loops refused - Added the SSID family:
[SSID Setting]DNS overrides apply per network — names,BSSID:,TYPE:WIFI/CELLULAR/WIRED,ROUTER:, quoted and wildcard names — and purge the previous resolver's cache when the network changes;ssidandsubnetpolicy groups pick members from the live network, SUBNET rules match it, andsuspend=truenow stops the tunnel: a network name orTYPE:entry becomes an on-demand disconnect rule, aBSSID:,ROUTER:or wildcard entry is suspended by the extension itself, and the extension says so when Always On would bring the tunnel back - Added DEST-PORT, SRC-PORT and IN-PORT ranges and comparisons (
80-81,>=50000,/lists),HOSTNAME-TYPEvaluesIPv4,IPv6,DOMAINandSIMPLE, and working IN-TYPE, IN-USER and IN-NAME rules, which now match live traffic instead of only a dry run - Added MitM controls: decrypt HTTP/2 (
h2), block QUIC to decrypted hosts so HTTP/3 cannot step around decryption (auto-quic-block), exclude hosts from decryption, and match the Host List keywords<ipv4-address>,<ipv6-address>and<simple-hostname> - Added QUIC routing by domain: the name is read from the client's QUIC Initial, a ClientHello split across several Initials is reassembled, and the flow is held until the name is known, so DOMAIN rules route HTTP/3 connections made to a bare address
- Added
icmp-auto-reply, on by default: a ping inside the tunnel is answered locally, over IPv4 and IPv6, instead of timing out - Added
tun-included-routes: the listed CIDRs join the tunnel's routes after its default route, so a range that the Wi-Fi interface's own subnet or another VPN would otherwise take — the system prefers the more specific route — goes through Chute. Entries that would cut the tunnel off (loopback, the tunnel's own subnets, link-local, multicast, broadcast, a prefix length of 0) are refused and logged, private ranges are accepted with a warning, and an edited list applies on reload without restarting the tunnel - Added import breadth: mihomo GEOSITE and category GEOIP rules expand into rule sets that work,
policy-pathgroups synthesize a provider withupdate-interval, filters and include lists, mihomoSUB-RULEexpands into AND rules, sing-boxdetourand mihomodialer-proxyimport as chaining, WireGuardallowed-ipsis compiled and enforced so a split tunnel no longer swallows every destination, and a policy'sinterface=/allow-other-interface=pins its connections to one network interface - Added script API breadth:
$httpAPIcalls the engine's own routes without opening a socket,$httpClienthonours apolicy,read-etc-hostsfeeds the hosts file to DNS, and$event.namereports the event that actually fired - Added Mock Response controls — the body may be text, a file, base64 or a 1×1 GIF, with a status code and validation — and URL and Header Rewrite type tables, with a regular expression mode for replacing a header's value
Improves:
- Chute now requires iOS 15 or later
- Every structured editor now keeps what it does not show: each builder carries over the keys it does not render — the rest of a rule's options, the sub-rules of AND / OR / NOT, a
[Host]entry's other addresses, a module header's other lines — so opening and saving a configuration no longer rewrites it, and an entry whose type the editor does not know is edited as text - Body Rewrite, Header Rewrite, URL Rewrite, Map Local, Mock and Script editors write what the engine reads: a Script is saved with its
type=, a JSONPath value keeps its kind, and Map Local keepsstatus-code,data-typeand headers - Importing a published profile no longer loses routing:
dns-serveraccepts encrypted DNS URLs, listener lines accept a password, quoted group members survive, sing-box logical rules convert as documented,PASSmembers are dropped instead of becoming REJECT, and an unsupported protocol or group type warns instead of taking its group down — in imported mihomo profiles, rules that can never match went from most of the list to almost none - Rule sets need far less memory: providers download one after another instead of failing outright after the 35th, conversion peaks fell by 62–73%, index connections are capped and released under memory pressure, and a payload too large for the device is refused with the reason shown in the rule set's status
- Resource limits keep an oversized configuration from pushing the tunnel extension past its memory limit: the MitM certificate store, the capture backlog, script size and count, the console's request budget, Tailscale peers and the DNS cache are each capped on iOS
- Latency tests use the right target: a group's
test-urlandtest-timeout, the profile'sproxy-test-urland a member's owntest-urlandexpected-statusall participate, and a chained node is probed through its chain instead of directly - The web console and control API: a rule added at runtime no longer lingers after the same profile is reloaded, log cursors stay monotonic so polling never skips an entry, and the connection detail names the proxy chain
- ShadowTLS now checks the cover site's certificate when
sni=is written, as sing-box does;skip-cert-verify=trueturns the check off (the option used to be ignored, and no certificate was checked at all), and withoutsni=the check is skipped with a warning - Downloads and subscriptions: each download goes to a file of its own and the format is judged by the body, so a refresh no longer re-reads its first download or applies another address's profile; a profile converted from Clash or sing-box lands as
.confand is named the way every Chute app names it; a name in use is numbered instead of saved over - Configuration handling: saving under another name asks first, reloads the tunnel when it writes over the running file, and stops removing the file a configuration was opened from; Sync From iCloud counts the configurations already installed toward the license's limit; hidden policy groups stay out of the Global and select lists while the engine still reaches them; Global always shows the group it is using
- The Wi-Fi upload page keeps the extension of the file it is given, refuses a name already in use with a reason, and sends non-ASCII names as RFC 6266 asks, so
上传的配置.confarrives named that way - New settings, messages and notifications ship in all eight built-in languages, and the tunnel's notifications carry the reason the tunnel stopped
Bug Fixes:
- Fixed Hysteria2 dropping any UDP datagram too large for one QUIC DATAGRAM frame, which kept an app's HTTP/3 from getting through and pushed it back to TCP; large datagrams are now split on the way out and the server's split replies reassembled
- Fixed a restarted tunnel reusing the previous run's first local port and TCP sequence numbers, which a WireGuard peer still holding the old connection answered with resets; the tunnel's TCP stack now seeds itself from the system's random source and picks initial sequence numbers as RFC 6528 describes
- Fixed XHTTP stalling through the tunnel after the app's first write, so a TLS handshake never finished and an upload sent a single chunk; each write now completes in order, and once more than 1 MB is waiting to upload, the next write waits for it to drain
- Fixed
PROTOCOL,TCPandPROTOCOL,UDPnever matching: every inbound now decides its transport, so the usual way to block QUIC with an AND rule works - Fixed
RULE-SETandDOMAIN-SETinside AND / OR / NOT always evaluating false — which madeNOT,((RULE-SET,…))reject domestic traffic too — andSCRIPTinside a logical rule always evaluating true - Fixed
RULE-SET,<name>,<policy>,no-resolvelosingno-resolvewhen written by name, GEOIP and IP-ASNUNKNOWNnever matching, Map Local'sstatus-code=being ignored over HTTP/2, and a response Header Rewrite over plain HTTP matching only the path, so a pattern written against the full URL could never match - Fixed
block-quicaccepting only one of Surge's values, where every other value meant no QUIC blocking at all - Fixed the script API:
$klne.getPolicyGroups()andselectPolicy()no longer throw the first time they are used,reloadConfiguration()reloads,getActiveConnections()reports the real host, port and id,closeConnection()closes, and a before-send script withrequires-bodyfinally receives the body - Fixed
[Replica] keyword-filtercomparing the whole host name instead of checking that it contains the keyword, sokeyword-filter = googledid not coverwww.google.com - Fixed PROCESS-NAME, PROCESS-PATH and PROCESS-NAME-REGEX rules matching browser traffic on iOS, where the name they compared was the browser's product name rather than a process; these rules work only on macOS and no longer match anything on iOS
- Fixed a saved Dashboard profile being read back as the wrong type, which crashed on every tap; rows dragged or deleted in a list that holds duplicates leaving the table out of step with its data; and crashes when a screen that had already closed was called back
- Fixed the subscription auto-refresh blocking the main thread for 30 seconds, which got the app killed by the watchdog when it went to the background mid-refresh; the Control Center switch always failing because the widget lacked permission to control the VPN, Picture in Picture being presented twice, and the widget's continuation being resumed twice
- Fixed downloads and names: a kept download file being re-read by the next refresh, an address answered with another address's profile when both suggested the same name, an import or a copy deleting the file it was read from in iCloud, an upload losing everything after its first dot, a subscription whose address ended in a bare extension being saved as a hidden file, and an edit saved over a readable configuration without asking
- Fixed a
chute://link — from a Shortcuts automation, for example — doing nothing when Chute was not already running; a cold launch now handles it too - Various stability and performance improvements
Version 1.2.0 (351)
New Features:
- Added the web console's address to the Control Panel: the Web Console row shows the host, and tapping it offers Open, Copy Address and Copy Access Token — Open carries the token in the URL, so it signs in without typing it
- Added a Runtime Diagnostic Bundle as the last row of the Control Panel's LOCAL PROXY section: the running engine builds a redacted archive (configuration, health snapshot, this run's events, loaded rules and policies, DNS, traffic and the log shards) and hands it to the share sheet; it needs the tunnel to be connected, but no
external-http-controller - Added an Offline Diagnostic Bundle under Settings → DIAGNOSIS, built by the app with no tunnel running: device and app details, the VPN profile as iOS holds it, a summary of the selected configuration and its parse errors, the three diagnosis pages as text, the redacted head of the configuration, how the previous run ended, the newest session's log tails and any pending crash reports
- Added Share Log to the session view, offering every shard of the session's log
- Added rewrite attribution to the session detail: the POLICY section now names the URL Rewrite, Header Rewrite, Body Rewrite or Mock Response rule that changed a request, beside the rule and policy that routed it
- Added a Network Address Changed notification, replacing Exit IP Changed: it shows this device's own IPv4 and IPv6 on the physical link, one line per family, and marks an IPv4 that sits behind NAT; IPv6 and a routable IPv4 are read locally, and only a NAT-local IPv4 costs a single STUN request
- Added French as a built-in language
- Added a redesigned Wi-Fi upload page in the web console's style, localized in nine languages
- Added Current and History tabs, an inspect view (matched rule, rule source, policy, adapter, DNS source, process, close reason, request and response bodies), a Rules page that shows which rewrite rules have fired, and a Diagnostics page (footprint, CPU, uptime, flows, how the previous run ended, refusal tally, event log, Tailscale snapshot, and ping / DNS / egress / URL-test probes) to the web console, which is now complete in all nine languages
- Added HTTP Control API endpoints:
/api/health,/api/events,/api/tailscale, the/api/diagnostics/probes,/api/connections/export?format=har,/api/diagnostics/bundle, rewrite and MitM host management under/api/rewritesand/api/mitm/hosts,POST /api/rules/matchto dry-run a request against the rule table (both DNS passes reported),GET|PUT /api/loglevelto change the log level and subsystem sections without a reload, andPOST /api/config/validateto check a profile without applying it
Improves:
- The HTTP Control API no longer serves open when the configuration names no
external-http-secret: the engine generates a token, which the Control Panel shows and copies; setexternal-http-secret = noneto keep anonymous access, and a wildcard listen address is no longer treated as loopback - Rule matching is much faster on large lists: RULE-SET and DOMAIN-SET payloads are indexed when downloaded or restored instead of being streamed per connection, and a rule table made only of domain rules is matched through a hashed plan — a 50k-line list goes from about 94 ms to under 2 ms per lookup, at roughly 100 KB of memory per index
- UDP flows are matched once: a flow's decision is remembered for 60 seconds, so repeat datagrams skip both matching passes and the DNS query between them
- Better recovery after a network change: tunnels whose upstream source address no longer exists on any interface are closed instead of hanging apps until the idle timeout, a same-type path change (a cellular reattach) is now noticed, and a path that accepts connections but moves no data is reported as a black hole
- Session logs are written in 8 MB shards (up to eight per run, oldest dropped), each opening with a header that names the run and its start time, so a long session no longer produces one file too large to retrieve; the log viewer loads every shard in order and keeps following the one being written
- The engine keeps a run marker while it runs and, on the next start, reports whether the previous run stopped cleanly or was killed — in the log header,
/api/statusand both diagnostic bundles - HAR export is now built by the engine from the recorded frames, so status codes, timestamps and timings are real, and every entry carries the chosen policy, matched rule and rewrite hits under
_kl; Export as HAR on the Dashboard and the connection detail both use it - Only the three features the purchase page sells require a license — Advanced Server Control, MitM and Traffic Recorder; Protocol Sniffing, Optimus DNS, External Access, HTTP API, Web Console and Purge DNS Cache no longer ask for one
- The Control Panel follows the tunnel: it resets its state when the tunnel stops, re-queries on reconnect, and offers the console address only while the page is actually served
- The configuration editor locks the two listener switches while
allow-wifi-accessis on, since the engine widens both listeners itself, and restores the configured interfaces when the flag is turned off - When Restore IAP Purchase finds nothing, the alert offers View Manual, which opens the cross-platform licensing instructions in the app's language; the purchase notice now says that one purchase covers three iPhone or iPad devices and three Apple TV devices
- The tailnet node list now matches the other lists — inset-grouped, with a No Item row for an empty section — and re-queries node status each time it appears
- At
loglevel = info, a bulk flow that moved at least 1 MiB logs one line at close saying how long it waited on the remote leg and on the app leg - The Diagnosis pages offer Copy only on rows that have something to copy
Bug Fixes:
- Fixed MitM in TUN mode: a host matched by a MitM rule stalled until timeout, so HTTPS Header Rewrite, Body Rewrite, Mock Response and decrypted captures never took effect for app traffic (traffic through the local HTTP/SOCKS5 proxy was unaffected)
- Fixed
allow-wifi-accesshaving no effect: the local HTTP and SOCKS5 listeners stayed on loopback, so nothing on the Wi-Fi could reach them; the flag (and sing-boxallow-lanon import) now widens both listeners, and turning it off rebinds them - Fixed a response Header Rewrite over MitM HTTP/1.1 being recorded as applied while the client received the original header, and never matching a rule written against the full URL
- Fixed Mock Response building its reply from the request header — request line where the status line belongs, request headers carried over, wrong Content-Length — and, on plain HTTP, sending the origin's header in front of it
- Fixed
no-resolveIP rules (IP-CIDR, GEOIP, IP-ASN) skipping a connection made to an IP literal when protocol sniffing had supplied a Host header or a reverse-DNS name for it; a sniffed IP literal no longer matches DOMAIN rules either, so the verdict no longer depends on whether sniffing is on - Fixed RULE-SET payload lines that carry options after the content (
GEOIP,CN,no-resolve,DOMAIN,example.com,force-remote-dns) being dropped or matching nothing, and AND/OR/NOT sub-rules losingno-resolve - Fixed HOSTNAME-TYPE never matching: the record type is now A for a connection dialed over IPv4 and AAAA over IPv6, and the rule editor's placeholder says so
- Fixed a domain routed to a proxy by an AND/OR/NOT rule with a domain sub-rule still being resolved for real by the DNS server, so the DNS answer and the routing decision disagreed
- Fixed a bracketed IPv6 literal in a sniffed Host header (
[2001:db8::1]:8080) being read as the hostname[2001 - Fixed starting the tunnel with a select group set to anything but its first member posting a "policy group switched" notification, and the rebuilds that follow a start tripping the flapping warning; a group with no remembered pick now honours the profile's
default=instead of being forced onto its first member - Fixed the Control Panel freezing the app at 100% CPU with memory climbing when opened after the tunnel had been up for a while
- Fixed HAR export writing wrong status codes and 1970 timestamps, and the connection detail export producing a file no HAR reader could open
- Fixed
[Replica] hide-crashlytics-requestbeing parsed but never applied to captures - Fixed
external-http-controller = *:9090and:::9090— both documented spellings — being rejected, so the controller silently did not start - Fixed
$klne.startURLTest()never triggering a latency test, and a URL test on a policy that does not exist reporting a plausible failure instead of an error - Fixed an occasional crash in the XHTTP transport under load
- Fixed re-serialized HTTP/1.1 responses going out with an empty reason phrase
- Fixed the license screen labelling a tvOS- or Android-issued license as Unknown, and a certificate this app cannot hold as an iOS & macOS & tvOS bundle
- Fixed the dead App Store link on the About screen; Rate now opens the review sheet
- Various stability and performance improvements
Version 1.1.9 (322)
New Features:
- Added XHTTP transport to the policy editor — enable toggle, mode (auto, packet-up, stream-up, stream-one), path, and host — for Trojan, VMess, and VLESS
- Added AEGIS-128L and AEGIS-256 Shadowsocks encryption methods
- Added ECH (Encrypted Client Hello) settings for TLS policies — enable toggle, pinned ECH config (
ech-config), and cover-name override (ech-public-name) - Added client fingerprint (uTLS) per policy, plus a profile-wide default
- Added AmneziaWG protocol support, including a parameter editor for this WireGuard variant with traffic obfuscation
- Added Clash and sing-box profile import from subscription URLs, files, and Wi-Fi uploads
- Added a configuration error report page with copyable contents to replace alerts that block interaction
- Added X25519MLKEM768 post-quantum hybrid key exchange for TLS 1.3
Improves:
- When saving, the policy editor now preserves existing options that are not available for editing (ECH, ALPN, certificate pinning,
test-url,udp-relay)
Bug Fixes:
- Fixed a tunnel crash caused by malformed
IP-CIDRrules - Fixed the SSH
idle-timeoutsetting being written under the wrong key and discarded on save - Fixed onboarding rules placing the policy name after
no-resolve, which could break IP-based rules - Various stability and performance improvements
Version 1.1.8 (300)
New Features:
- Added Tailscale as a built-in proxy type: configure a Tailscale account directly in Chute, join a tailnet, and route traffic through Tailscale nodes — no separate client required
- Added Tailscale section editor: enter the auth key securely, verify the connection, list tailnet nodes, and switch exit nodes from within the app
- Added a Tailscale control panel that shows real-time node status (online/offline, IP, last seen) and lets you switch exit nodes on the fly
- Added system notifications for proxy diagnostics, including egress-IP changes and Tailscale connection events, with per-type toggles in settings
- Added the MASQUE proxy type to the policy editor
Improves:
- Improved TUN throughput on iOS
- Improved Tailscale and WireGuard connection stability and throughput
- Improved UDP tunnel stability and the accuracy of traffic statistics
- Improved stability when stopping the VPN, reducing cases where the system terminates the connection abnormally
- Improved language switching reliability
- Sanitized configuration file names to prevent invalid path characters from causing load failures
Bug Fixes:
- Fixed an issue where on-demand rules could become inconsistent between VPN start and stop
- Fixed a rare crash caused by concurrent language switching
- Fixed network-change handling to avoid unnecessary VPN reconnections
- Various stability and performance improvements
Version 1.1.7 (290)
New Features:
- Added JavaScript Scripting system: run custom scripts for request/response modification, DNS resolution, custom rule matching, and scheduled tasks
- Added Body Rewrite: search and replace HTTP request/response body content using regex (with capture group support) or JSONPath expressions
- Added ShadowTLS protocol support
- Added gRPC transport for VMess and VLESS protocols
- Added DNS-over-QUIC (DoQ) and DNS-over-HTTP/3 (DoH3) support
- Added DNS-over-TLS (DoT) support
- Added HTTP Control API and Web UI for monitoring and controlling the proxy runtime
- Added Module system (.sgmodule) for modular configuration management
- Added Proxy Provider for dynamic proxy list updates
- Added Notification Reporting: detects connection failures, proxy unavailability, traffic surges, config update failures, and policy group switches; dispatches events for system notifications
- Added Mock Response: return mock data to matched requests without reaching the real server
- Added LoadBalance policy group with round-robin, consistent-hashing, and sticky-sessions strategies
- Added URL Rewrite new modes: reject-200, reject-img, reject-dict
- Added Header Rewrite response direction support
- Added PROTOCOL rule type with 10 protocol type values
- Added SCRIPT rule type for JavaScript-based custom matching
- Added extended-matching and requires-resolve options for rules
- Added AnyTLS multi-layer padding scheme
- Added SS2022 encryption methods (2022-blake3-aes-128/256-gcm, chacha20-poly1305)
- Added Managed Configuration support
- Added Replica support for configuration replication
- Added WireGuard configuration UI
- Added interrupt-exist-connections global option
Improves:
- Policy groups now support expected-status, hidden, idle-timeout, and lazy options
- Enhanced URL Rewrite with template variable support in Map Local format
- Improved DNS server with DoQ, DoH3, and DoT protocol support
- Expanded rule system from 6 to 30+ rule types with full coverage
Bug Fixes:
- Fixed IPv6 default value (false → true)
- Fixed log level default value (notify → warning), added none and fatal levels
- Fixed Shadowsocks/ShadowsocksR naming consistency throughout documentation
- Various stability and performance improvements
Version 1.1.6 (256)
New Features:
- Added Hysteria2 protocol support
- Added WireGuard protocol support
- Added VLESS REALITY protocol support
- Added protocol sniffer for TUN traffic
- Added IP-ASN rule support
- Added AND/OR/NOT logical rule support
Bug Fixes:
- Fixed UDP adapter memory issues
- Optimized performance for Rule-Set and Domain-Set matching
- Resolved other minor bugs and stability issues
- Fix license view crash
Version 1.1.5 (245)
New Features:
- Added TUIC protocol support
- Added Shadowsocks 2022 (SS2022) support
- Introduced tunnel configuration
- Improved log display in session
Bug Fixes:
- Fixed UDP adapter issue
- Optimized performance for Rule-Set and Domain-Set matching
- Resolved other minor bugs and stability issues
Version 1.1.2 (231)
New Features:
- iOS 26 UI
Bug Fixes:
- Fix DNS IPv6 response for Gemini App
- RULE-SET with comment content support
- Widget center switch button status fix
Version 1.1.1 (218)
New Features:
- AnyTLS Policy support
- Domain-Set support
- Remote Rule-set support
Improves:
- Tunnel rebuild for better performance
- Full-tested UDP tunnel
Bug Fixes:
- Fix memory leaks
Version 1.1.0 (210)
Bug Fixes:
- Fix some bug
Version 1.0.9 (199)
New Features:
- iOS 18 control center switch button
Bug Fixes:
- TUN with IPv6 now redirect to IPv6 tunnel, to fix some service issues
Version 1.0.8 (188)
New Features:
- SSH Policy support
- Add remote dashboard connect
Improves:
- Change TUN network to 198.18.0.0/15 to avoid IPv4 internal address issue
- Some text updated
Bug Fixes:
- Fix DNS issues
Version 1.0.7 (167)
New Features:
- PIP mode
- iCloud sync for configuration files
- Add remote configuration manager tvOS
Bug Fixes:
- Fix Vmess with Websocket
Version 1.0.6 (160)
New Features
- New UI
- Add upload configuration via Wi-Fi
- Add Network Diagnosis & Proxy Diagnosis
- Add reset VPN configuration function
- Add ICMP(Ping) packet support
- Add VPN status check
Improves:
- Improve configuration edit UI/UX
- Update MTU to 4000
Bug Fixes
- Bug fix
- Fix IPv6 TUN setting
Version 1.0.5 (147)
New Features
- Add VLESS protocol support
- Add XTLS support with VLESS
- Add Session Viewer to review proxy sessions and logs
- You can review your UDP connection with Chute Dashboard macOS application
Improves:
- Improve configuration edit
- Improve local DNS server to avoid DNS pollution
- Improve UDP relay
Bug Fixes
- Fix IPv6 display
- Fix DNS server
Version 1.0.4 (143)
New Features
- Support local HTTP/Socks5 proxy server
- Full IPv6 support
- Add
syslibsupport for DNS server
Improves:
- Improve configuration edit
- Add Optimistic DNS switch
- Improve local DNS server
Bug Fixes
- Fix iOS local proxy server address could stop application to access the network
- Fix DNS server
Version 1.0.3 (138)
New Features
- Fake IP to avoid DNS cache poisoning
- Download configuration file from internet or QR code
Bug Fixes
- Fix FINAL rule edit issue
Version 1.0.2 (130)
New Features
- iPad support
- Support for
chute://scheme &x-callback-url - Dashboard action
- iPhone 12 support
- Rebuild DNS server for better performance & stability
Bug Fixes
- Improve TCP stability
- Rebuild TCP lock to improve performance
- Improve UDP stability
- Configuration crash fix
Version 1.0.1 (111)
- Fix WeChat Share Extension failure
- Fix IPv6 Support
- Update HTTP complete check
Version 1.0.0 (101)
- First release