Chute Mac Release Note
Version 1.1.5 (233)
New Features:
- Added proxy chaining: a policy can name an Underlying Proxy (
underlying-proxy) and reach its server through it, a policy group can send every member through one upstream, and the new Front Proxy setting under General → Advanced (global-underlying-proxy) does the same for every node that sets no upstream of its own. Every transport except Tailscale can be chained — stream protocols ride the upstream's stream; Hysteria2, TUIC, MASQUE and XHTTP over HTTP/3 ride its UDP relay in fixed 1280-byte packets; WireGuard and AmneziaWG tunnel through it with a 1280-byte inner MTU; SSH and AnyTLS sessions open over it — and the policy editor offers the field for every one of them. A chain that loops, nests more than 16 levels deep or names a policy that does not exist is refused, never sent out directly - Added relay groups (
relay, as in Clash and mihomo): the members are chained in the order written — the first is dialled directly, each later one is reached through the ones before it, and the last connects to the destination. The group editor offers Relay as a type, keeps the members in that order and asks for at least two - Added random groups (
random, as in Shadowrocket): every connection picks a member at random, UDP only among the members that carry UDP. A random group has no selection to change, so the menu bar and the Proxies page leave it out, and the group editor keeps it a random group - Added the proxy chain to the connection detail window and the web console: every hop is named (
Airport/HK-01 → Landing), Copy Details carries it, the connection search matches it, and HAR export records the path - Added
policy=to rule and proxy providers: the list is downloaded through that policy, and a policy name that does not exist makes the download fail instead of going out directly. The Mac editors have no field for it yet, but saving keeps it - Added UDP over TCP to the Shadowsocks editor —
udp-over-tcp, version 1 or 2 — so a proxy's UDP rides inside its TCP connections and works even through a chain whose upstream carries no UDP - Added UDP to VMess and VLESS: UDP sent to either used to be refused outright (it followed
udp-policy-not-supported-behaviour, REJECT by default); it now travels over one connection per destination, as in mihomo, sing-box and Shadowrocket - Added jq to Body Rewrite:
http-request-jqandhttp-response-jqrun a real jq program over a JSON body, and the editor offers Request jq and Response jq types with a JQ Program field; an invalid program is reported and its rule skipped, and a non-JSON body, a program that fails or empty output all leave the body untouched - Added generic scripts: a
type=genericscript has no automatic trigger and runs only on demand — from the Script editor's Run button, or overGET /api/scriptsandPOST /api/scripts/run. The Script editor also gains an Event Name field: event scripts receivenetwork-changed,engine-startedandprofile-reloaded, and a script that names any other event is noted in the log and never runs - Added dedicated DNS pools:
direct-dns-serverresolves the domains a rule sends DIRECT,proxy-dns-serverresolves your proxy servers' own hostnames, andfallback-dns-serveris asked when the main servers give no answer; each falls back to the global servers, and the DNS settings have a field for each - Added
#proxy/#proxy=<policy>to DNS upstreams, DoQ and DoH3 included: a QUIC resolver rides the policy's UDP relay, a policy that cannot carry UDP skips that server instead of asking it directly, a plain resolver sent through a policy switches to DNS over TCP, and plaintcp://upstreams are accepted for paths that drop DNS over UDP - Added
encrypted-dns-follow-outbound-mode,allow-dns-svcb— HTTPS and SVCB questions are answered empty unless it is on — and per-server#h3,#skip-cert-verify,#disable-ipv4,#disable-ipv6and#disable-qtype= - Added more to Local DNS Mapping: a
[Host]entry keeps every server it lists and queries them in parallel, maps one domain to several addresses, keys on a rule set (RULE-SET:<url>), runs atype=dnsscript for that domain (script:<name>), and acceptsssid:<name>for a per-network mapping; the editor binds a script and keeps every address and server of an entry - Added Read system hosts file under General (
read-etc-hosts, imported from mihomo'suse-system-hosts): the names in/etc/hostsare answered by Chute's DNS - Added rule notifications: any rule, FINAL included, takes
notification-text=andnotification-interval=and posts a notification when it matches, at most once per interval for each rule; the rule editor sets both, and the notifications follow Chute's notification switch - Added
FINAL,<policy>,dns-failed: when a name cannot be resolved, the connection is opened on the FINAL policy with remote resolution instead of being closed; the rule editor offers it - Added the REJECT family as real policies — REJECT-DROP, REJECT-NO-DROP, REJECT-TINYGIF, REJECT-IMG, REJECT-DICT, REJECT-ARRAY, REJECT-200 and REJECT-VIDEO — each answering an HTTP request with its documented body, with a host rejected more than 50 times in 30 seconds upgraded to REJECT-DROP; the rule editor's policy menu lists them, along with PROXY
- Added inline rule sets:
[Ruleset Name]sections are referenced asRULE-SET,<name>, including references between them — up to eight deep, with loops refused - Added the SSID family:
[SSID Setting]DNS overrides apply per network — names,BSSID:,TYPE:WIFI/CELLULAR/WIRED(Ethernet on a Mac),ROUTER:, quoted and wildcard names — and purge the previous resolver's cache when the network changes;ssidandsubnetpolicy groups pick members from the live network, and SUBNET rules match it.suspend=truenow takes effect on the Mac: on that network Chute takes the system proxy off and detaches Enhanced Mode, the menu bar says so, a notification marks both transitions, and switching the proxy by hand ends the hold. The group and [SSID Setting] editors gain a Match by menu (SSID, BSSID, TYPE, ROUTER), keep entries in the order written and show each entry's DNS override. Network changes now reach the engine as they happen instead of on a 60-second tick, and Chute asks once for Location access when the configuration names a Wi-Fi network, which macOS 14 and later require before revealing the network's name - Added DEST-PORT, SRC-PORT and IN-PORT ranges and comparisons (
80-81,>=50000,/lists),HOSTNAME-TYPEvaluesIPv4,IPv6,DOMAINandSIMPLE, and working IN-TYPE and IN-USER rules, which now match live traffic instead of only a dry run - Added MitM controls: decrypt HTTP/2 (
h2), block QUIC to decrypted hosts so HTTP/3 cannot step around decryption (auto-quic-block), exclude hosts from decryption, and match the Host List keywords<ipv4-address>,<ipv6-address>and<simple-hostname>; the first three are in the MitM settings - Added QUIC routing by domain in Enhanced Mode: with protocol sniffing on, the name is read from the client's QUIC Initial, a ClientHello split across several Initials is reassembled, and the flow is held until the name is known, so DOMAIN rules route HTTP/3 connections made to a bare address
- Added
icmp-auto-reply, on by default: in Enhanced Mode a ping is answered locally, over IPv4 and IPv6, instead of timing out - Added import breadth: mihomo GEOSITE and category GEOIP rules expand into rule sets that work,
.mrsand.srsproviders are pointed at their published source lists,policy-pathgroups synthesize a provider withupdate-interval, filters and include lists, mihomoSUB-RULEexpands into AND rules, sing-boxdetourand mihomodialer-proxyimport as chaining, and WireGuardallowed-ipsis compiled and enforced — the WireGuard editor gains an Allowed IPs field — so a split tunnel no longer swallows every destination - Added configuration directives and transports:
#!includeandinclude =pull in other files,#!MACOS-ONLY,#!IOS-ONLYand#!TVOS-ONLYkeep lines to one platform, and both survive a save; Shadowsocks gains the v2ray-plugin WebSocket transport; and a VLESS or VMess id that is not a UUID is mapped to one with UUIDv5, as Xray and mihomo do, instead of taking the engine down - Added Egress Interface and Allow Other Interface to the policy editor (
interface=,allow-other-interface=), which pin a policy's TCP connections to one network interface. They take effect withnetwork-framework = false; under Network.framework, the macOS default, they are not applied yet - Added script API breadth:
$httpAPIcalls the engine's own routes without opening a socket,$httpClienthonours apolicy, and$event.namereports the event that actually fired - Added rewrite options: Map Local takes
data-type,status-codeand headers, Header Rewrite gainsheader-replace-regex, URL Rewrite gainsreject-arrayandreject-tinygif, and one Body Rewrite line can carry several regex/replacement pairs; the editors offer the new types and fields - Added Open Web Console and Copy Web Console Token to the menu bar, shown when the configuration serves the console: Open signs in with the token, Copy is for a browser on another machine, and a disabled item says why when the listener is not running or
external-http-uiis off. The console gains Current and History tabs, an inspect view (matched rule, rule source, policy, adapter, DNS source, process, close reason, request and response bodies), a Rules page that shows which rewrite rules have fired, a Diagnostics page and a list of rule sets that failed to load, and is complete in all nine languages - Added HTTP Control API endpoints:
/api/health,/api/events,/api/tailscale, the/api/diagnostics/probes,/api/connections/export?format=har,/api/diagnostics/bundle,/api/scripts, rewrite and MitM host management under/api/rewritesand/api/mitm/hosts,POST /api/rules/matchto dry-run a request against the rule table,GET|PUT /api/loglevelto change the log level without a reload, andPOST /api/config/validateto check a profile without applying it - Added Save Diagnostic Bundle… to the menu bar: a redacted archive of the configuration, health, this run's events, the loaded rules and policies, DNS, traffic and the log shards, built inside Chute without the control API — and offered after Chute stops too, when the last run's logs are what you need
- Added HAR export, built by the engine from the recorded frames: status codes, timestamps and timings are real, and every entry carries the chosen policy, matched rule and rewrite hits under
_kl; it is in the web console and at/api/connections/export?format=har - Added rewrite attribution to the connection detail window: it names the first URL, Header or Body Rewrite or Mock Response that changed the request and how many fired, Copy Details carries all of them, and Requests & History opens the web console for the bodies and closed connections
- Added a Network Address Changed notification, replacing Exit IP Changed: it shows this Mac's own IPv4 and IPv6, one line per family, and marks an IPv4 that sits behind NAT; only a NAT-local IPv4 costs a single STUN request
- Added a Network Not Carrying Traffic notification, with its own switch, on by default: it reports a link that accepts connections but moves no data, and stays quiet while macOS itself reports the network unreachable
- Added French as a built-in language, and a flag beside each language in the language menu
Improves:
- The HTTP Control API no longer serves open when the configuration names no
external-http-secret: the engine generates a token, which the menu bar copies;external-http-secret = nonekeeps anonymous access only on a loopback address, and a wildcard listen address is no longer treated as loopback - Rule matching is much faster on large lists: a rule table made only of domain rules is matched through a hashed plan, and RULE-SET and DOMAIN-SET payloads that are not preloaded are indexed when downloaded instead of read for each connection
- UDP flows are matched once: a flow's decision is remembered for 60 seconds, so repeat datagrams skip both matching passes and the DNS query between them
- Better recovery after a network change: tunnels whose upstream source address no longer exists on any interface are closed instead of hanging apps until the idle timeout
- Rule providers download one after another instead of being refused once the download queue is full, and converting them takes far less memory
- Logs are written in 8 MB shards (up to eight per run, oldest dropped), each opening with a header that names the run, and the Log tab follows every shard in order; the engine also records whether the previous run stopped cleanly or was killed — in the log header,
/api/statusand the diagnostic bundle — and atloglevel = infoa bulk flow that moved at least 1 MiB logs one line at close saying where it waited - Every structured editor now keeps what it does not show: policy groups keep their providers,
policy-path,include-*, filters and unknown parameters, and leave a defaultedurl=/timeout=blank so the group followsproxy-test-url/test-timeout; rules keep their other options; a[Host]entry keeps every address; a Body Rewrite line keeps its later pairs; scripts keep the keys the form does not show; WireGuard and AmneziaWG sections keep theirs, AmneziaWG's obfuscation parameters included — so opening and saving no longer rewrites a configuration - Effective Rules shows the table the matcher actually walks — front rules, modules, the profile and FINAL — and Test Rule runs the engine's dry run instead of reading a cache
- Importing a published profile no longer loses routing: the format is judged by what the address serves, so a
.confsubscription that serves Clash is converted;dns-serveraccepts encrypted DNS URLs, listener lines accept a password, quoted group members survive,PASSmembers are dropped instead of becoming REJECT, and an unsupported protocol or group type warns instead of taking its group down; a converted profile lands as.conf, and a name already in use is numbered - Latency tests use the right target: a group's
test-urlandtest-timeout, the profile'sproxy-test-urland a member's owntest-urlandexpected-statusall participate, and a chained node is probed through its chain instead of directly - Hidden policy groups stay out of the menu bar and the Proxies page unless they are in use; when the control API points Global at a select group, the menu bar lists and checks it; and reloading a profile drops the rules added at runtime from the web console
- ShadowTLS now checks the cover site's certificate when
sni=is written, as sing-box does;skip-cert-verify=trueturns the check off, and withoutsni=the check is skipped with a warning - PROCESS-NAME written as a path matches that path or bundle prefix, as Surge's manual allows, and mihomo's PROCESS-NAME-WILDCARD and PROCESS-PATH-WILDCARD rules import instead of being dropped
- Large uploads over Network.framework connections no longer keep their data in memory until the main thread gets round to freeing it
- The Allow Wi-Fi Access checkbox now says what it does — both local proxy listeners accept connections on every interface while it is on — and the interface fields show 0.0.0.0 meanwhile, keeping your addresses for when it is turned off
- The Enhanced Mode notices now describe what the engine does: Chute sets the DNS override itself and restores it on stop, UDP is relayed through the matched policy, and a ping gets a local reply
- Updated the built-in updater to Sparkle 2.9.6, which carries the 2.x security fixes; the check at launch now runs only when automatic update checks are on
- Japanese, Korean, German, Thai and Russian no longer show English for about 850 strings, the network extension's approval prompt is translated instead of showing a placeholder, and every language uses the terms of the iOS app and this manual
Bug Fixes:
- Fixed VIF Included Routes (
tun-included-routes) having no effect: with either Enhanced Mode type, Helper utun or PacketTunnel, the listed CIDRs now join the tunnel's routes, so a range that the physical interface's own subnet or another VPN would otherwise take goes through Chute. Entries that would cut the tunnel off — loopback, the tunnel's own subnets, link-local, multicast, broadcast, the current default gateway, a prefix length of 0 — are refused and logged, and private ranges are accepted with a warning. The privileged helper is updated for this, so macOS asks once to approve it - Fixed MitM in Enhanced Mode: a host matched by a MitM rule stalled until timeout, so HTTPS rewrites, Mock Response and decrypted captures never took effect for app traffic; and a decrypted request or response larger than 64 KB hung, through the system proxy too
- Fixed
allow-wifi-accesshaving no effect: the local HTTP and SOCKS5 listeners stayed on loopback, so nothing on the network could reach them; the flag (and sing-boxallow-lanon import) now widens both listeners, and turning it off rebinds them - Fixed rewrites: a response Header Rewrite over MitM HTTP/1.1 was recorded as applied while the client received the original header, and over plain HTTP it matched only the path, so a pattern written against the full URL never matched; Mock Response built its reply from the request header; Map Local's
status-code=was ignored over HTTP/2; and re-serialized HTTP/1.1 responses went out with an empty reason phrase - Fixed rule matching:
no-resolveIP rules skipped a connection made to an IP literal once sniffing had supplied a name for it; RULE-SET payload lines with options after the content were dropped;RULE-SET,<name>,<policy>,no-resolvelostno-resolve; HOSTNAME-TYPE never matched; RULE-SET and DOMAIN-SET inside AND / OR / NOT always evaluated false, and SCRIPT always true; GEOIP and IP-ASNUNKNOWNnever matched; a domain routed to a proxy by a logical rule was still resolved for real; and a bracketed IPv6 literal in a Host header was read as a hostname - Fixed
PROTOCOL,TCPandPROTOCOL,UDPnever matching, so the usual way to block QUIC with an AND rule works;PROTOCOL,HTTPnow also matches plain requests through the local HTTP proxy, which is how system-proxy traffic arrives - Fixed
block-quicaccepting only one of Surge's values, where every other value meant no QUIC blocking at all - Fixed IP-ASN rules never working: GeoLite2 databases in
~/Chute/Contentwere ignored, and Chute shipped no ASN database of its own; it now ships one - Fixed PROCESS-NAME and PROCESS-PATH lines inside a rule set being lowercased, so a rule naming
Chromenever matched - Fixed starting Chute with a select group set to anything but its first member posting a "policy group switched" notification, and later rebuilds tripping the flapping warning; a group with no remembered pick now honours the profile's
default= - Fixed the script API:
$klne.getPolicyGroups()andselectPolicy()no longer throw the first time they are used,reloadConfiguration()reloads,getActiveConnections()reports the real host, port and id,closeConnection()closes,startURLTest()starts a test, and a before-send script withrequires-bodyreceives the body - Fixed
[Replica] hide-crashlytics-requestbeing parsed but never applied,keyword-filtercomparing the whole host name instead of checking that it contains the keyword,external-http-controller = *:9090and:::9090being rejected, andoptimistic-dns = falsestill serving expired records - Fixed XHTTP crashing under load and stalling after the first write, so a TLS handshake through it never finished, and its stream-up padding over HTTP/1.1
- Fixed Hysteria2 dropping any UDP datagram too large for one QUIC DATAGRAM frame, which pushed an app's HTTP/3 back to TCP, and a url-test group with a Hysteria2 member crashing
- Fixed restarting Enhanced Mode reusing the previous run's first local port and TCP sequence numbers, which a WireGuard peer still holding the old connection answered with resets
- Fixed WireGuard crashing when it was started from two places at once, Shadowsocks 2022 losing the end of a response, SSH stalling for 30 seconds and spinning a CPU core while idle, and REALITY / uTLS connections passing on a corrupted download after a bad record instead of closing
- Fixed Tailscale: on a Mac with two interfaces on one network, a handshake answered from the other address never completed, and connections hung after Tailscale stopped
- Fixed both local listeners staying down after a reload — a listener that stops unexpectedly is now restarted — the HTTP proxy not answering an unauthenticated request with 407 and
Proxy-Authenticate, a deadlock in legacy XTLS, and WebSocket transports ignoring Ping and Close - Fixed a crash when the engine started on macOS 10.15
- Fixed script values that hold commas — a cron such as
0 8,20 * * *or a JSON argument — being cut at the first comma when saved from the Script editor, and policy group members whose names hold a space or a comma being saved unquoted - Various stability and performance improvements
Version 1.1.3 (230)
New Features:
- Added a Setup Assistant: a first launch now walks you from nothing to a working configuration — import a subscription or a share link, set up a server by hand, or point at a configuration file you already have — then installs the privileged helper, applies the traffic mode you choose, and verifies the connection before finishing. It can be reopened at any time from the menu
- Added share-link import (
vmess://,ss://,ssr://,trojan://,vless://,hysteria2://,shadowtls://): links are converted locally, and a subscription that returns a list of share links — including base64-wrapped lists — is accepted as well - Added clipboard detection to the import sheet: a link found on the clipboard is offered behind a Use button rather than filled in silently
- Added the
chute://URL scheme, so an import link on a web page opens in Chute; the address is shape-checked and confirmed before anything is fetched - Added AmneziaWG protocol support, including an editor for its obfuscation parameters (Jc/Jmin/Jmax, S1–S4, H1–H4, I1–I5)
- Added XHTTP transport to the policy editor for Trojan, VMess and VLESS — mode, path, host, request headers and padding, the post-size and interval limits, the four XMUX bounds, and a separate download endpoint
- Added gRPC transport to the policy editor, with service name and multi-mode
- Added ECH (Encrypted Client Hello) settings for TLS policies: enable toggle, a pinned
ech-config, and anech-public-namecover-name override - Added a per-policy client fingerprint (uTLS), plus a profile-wide default in General settings
- Added AEGIS-128L and AEGIS-256 Shadowsocks encryption methods
- Added X25519MLKEM768 post-quantum hybrid key exchange for TLS 1.3
- Added the VMess cipher selector, MASQUE certificate-fingerprint pinning, a UDP opt-out on every policy, and multiplexing switches for the HTTP family, Shadowsocks, ShadowsocksR, Trojan, ShadowTLS and Hysteria2
- Added Tailscale exit-node and subnet-router serving: advertise this Mac and the networks behind it, toggle serving from the menu bar, get a notification when an administrator approves it, and optionally keep the Mac awake while it is carrying traffic
- Added profile deletion to the Profiles list: profiles Chute manages are moved to the Trash, while files imported in place are only deregistered and stay where they are
- Added a configuration error report window — a resizable list of line number, severity, message and the original line, with ⌘C on rows and a Copy All button — replacing an alert that could grow taller than the screen
- Added Map Remote to [URL Rewrite]: a
headerrule now rewrites the request line and the upstream host, with capture-group expansion - Added module arguments (
#!arguments), so one module can be reused with different values
Improves:
- Rebuilt the policy editor around per-protocol forms: each protocol now owns its own fields instead of sharing text fields with unrelated protocols, and the type list can grow without renumbering the ones below it
- When saving, the policy editor now preserves options it has no field for (ECH, ALPN, certificate pinning,
test-url,udp-relay,tfo) - Removed the TCP Fast Open switch from TUIC, Hysteria2, MASQUE, AnyTLS and SSH, whose adapters never read it; a policy that already carries
tfokeeps it - Improved import of published Clash, sing-box and Surge profiles, including Surge's MitM/Panel/Ponte sections, REJECT variants, module lines and the [SSID Setting] selector
- Chute now explains what the privileged helper is for before macOS asks for authorization, instead of the system prompt arriving with no context
- Sequenced the first-launch surfaces: the license is read before any window is shown, and the notification-permission prompt waits until the setup assistant closes
- With nothing configured, the menu bar now offers Preferences, the main window and the import entry points instead of a lone file picker; the dashboard toggles say what is missing instead of failing a minute later; and such an install starts in the new main window
- The Profiles empty state and the URL import item now name share links, and the Help window says what actually has to happen before anything is proxied
- Improved relay throughput and CPU use across the data path, rule matching and UDP handling
- Connections are no longer reused across a superseded network path after the Mac changes network
Bug Fixes:
- Fixed a valid license being reported as illegal after a reboot, where a single transient verification failure stopped the proxy and opened the License window
- Fixed the Revoke License confirmation doing nothing when confirmed
- Fixed Cancel on the configuration-error prompt still loading and starting the broken configuration, and the discard action sitting on the default button
- Fixed VLESS
flowbeing dropped whenever REALITY was enabled, and made the client actually speak XTLS Vision framing instead of only advertising it - Fixed a policy whose type the editor cannot display being rewritten as HTTP on save
- Fixed WireGuard and AmneziaWG policies that name a configuration section acquiring a literal port of 0
- Fixed
ws-pathandws-headersbeing written while the WebSocket switch was off - Fixed the Interface settings page not scrolling
- Fixed Shadowsocks
obfs=httpsending a malformed request line, which left the tunnel connected but carrying nothing - Fixed Shadowsocks 2022 losing sync when a payload was split across socket reads, and corrected the chacha20-poly1305 UDP wire format
- Fixed a
[Host]alias never matching, so an A lookup for the aliased name fell through to the upstream and came back NXDOMAIN - Fixed QUIC connection migration slipping past
PROTOCOL,QUICrules and the block-quic option - Fixed WireGuard dropping packets queued while a session was being re-established
- Fixed a module's
#!argumentsdescription line overwriting the argument defaults beside it - Various stability and performance improvements
Version 1.1.2 (210)
New Features:
- Added Tailscale as a built-in proxy type: configure a Tailscale account directly in Chute, join a tailnet, and route traffic through Tailscale nodes — no separate client required
- Added a Tailscale configuration pane: enter the auth key securely, verify the connection, list tailnet nodes, and switch exit nodes
- Added a Tailscale status widget to the dashboard and a menu-bar shortcut for switching exit nodes
- Added system notifications for proxy diagnostics, including dangling policy references, egress-IP changes, and Tailscale events, with per-type toggles in settings
- Added the MASQUE proxy type to the policy editor
- Added a bypass-list table editor with a simple-hostnames default and automatic no_proxy export
- Added grouping of connections by application in the Traffic panel
- Raised the minimum supported macOS version to 10.14 (Mojave)
Improves:
- Improved TUN throughput on macOS
- Improved stability of the privileged helper, system proxy, and DNS/TUN lifecycle
- Improved Tailscale and WireGuard connection stability and throughput
- Improved reliability of the system extension and VPN auto-continue
- Improved license verification to avoid treating transient server errors as revocation
- Sanitized configuration file names to prevent invalid path characters from causing load failures
Bug Fixes:
- Fixed an issue where the helper could re-attach to an already-running VPN tunnel
- Fixed a crash caused by concurrent language switching
- Fixed an issue where the VPN tunnel could fail on the second start
- Fixed the upload-speed sparkline plotting download data instead
- Various stability and performance improvements
Version 1.1.1 (202)
- New Main UI with Dashboard: redesigned 4-tab window (Dashboard, Traffic, Config, Log) featuring glass-morphism design, real-time speed sparkline charts, customizable widget cards, and micro-interaction animations
- New Dashboard widgets: proxy status, TUN mode, uptime, active connections, download/upload throughput, and current configuration profile
- New Profiles management tab for switching and organizing configuration profiles
- Upgraded Traffic Inspector with enhanced session filtering and log viewing
- New VPN Enhanced Mode: PacketTunnel system extension option alongside legacy helper utun, selectable in Preferences
- Migrate privileged helper daemon from SMJobless to SMAppService (macOS 13+)
- Migrate Network Extension to System Extension with OSSystemExtensionRequest activation flow
- Add configuration editors for Body Rewrite, Script, Module, and WireGuard sections
- Add Rules DNS diagnostics tool
- Update KLNEKit kernel with major feature expansion
- Add AnyTLS protocol support with multi-layer padding obfuscation
- Add TUIC protocol support (QUIC-based multiplexed TCP/UDP relay)
- Add Hysteria2 protocol support with Brutal congestion control
- Add WireGuard protocol support (inline and section-based configuration)
- Add ShadowTLS protocol support with TLS fingerprint camouflage
- Add VLESS REALITY anti-censorship support
- Add Shadowsocks 2022 encryption methods (2022-blake3-aes-128/256-gcm, chacha20-poly1305)
- Add gRPC transport for VMess and VLESS protocols
- Add DNS-over-TLS (DoT), DNS-over-QUIC (DoQ), and DNS-over-HTTP/3 (DoH3) support
- Add per-domain DoT/DoQ/DoH3 assignment in Local DNS Mapping
- Add JavaScript Scripting system (7 script types: rule, dns, request, response, generic, scheduled, dns-ttl)
- Add Body Rewrite: search and replace HTTP request/response bodies via regex (with capture groups) or JSONPath
- Add Mock Response: return mock data or Map Local content to matched requests
- Add Protocol Sniffing: detect actual connection protocol and apply rules accordingly
- Add Notification Reporting with 5 event types (connection-failure, proxy-unavailable, traffic-surge, config-update-failure, policy-group-switch)
- Add HTTP Control API and embedded Web UI for runtime monitoring and management
- Add Module system (.sgmodule) for modular configuration management
- Add Proxy Provider for dynamic proxy list updates
- Add LoadBalance policy group with round-robin, consistent-hashing, and sticky-sessions strategies
- Add Fallback policy group support
- Add IP-ASN rule type (built-in MaxMind GeoLite2 ASN database)
- Add Logical Combination rules: AND, OR, NOT
- Add Advanced Matching rules: SUBNET, HOSTNAME-TYPE, IN-TYPE, IN-USER, IN-NAME
- Add new domain-based rule types: DOMAIN-WILDCARD, DOMAIN-REGEX, DOMAIN-SET
- Add PROTOCOL rule type (match by detected protocol: HTTP, HTTPS, TLS, TCP, UDP, QUIC, STUN, DNS, DOH, DOQ)
- Add SCRIPT rule type for JavaScript-based custom matching
- Add new process rule types: PROCESS-PATH, PROCESS-NAME-REGEX
- Add SRC-PORT rule type
- Add extended-matching and requires-resolve options for rules
- Add URL Rewrite reject modes: reject-200, reject-img, reject-dict
- Add Header Rewrite response direction support (header-response-add/del/replace)
- Add URL Rewrite Map Local template variable support
- Add Replica support for selective traffic recording
- Add Managed Configuration support with auto-update interval
- Add exclude-simple-hostnames option
- Add Bypass TUN option for direct-routing specified IP ranges
- Add interrupt-exist-connections global option
- Add network-framework option
- Add disable-db-record option
- Expand policy group options: expected-status, hidden, idle-timeout, lazy
- Expand rule system from 6 to 37 rule types
- Optimize TUN throughput (UTUN_OPT_MAX_PENDING_PACKETS)
- Fix IPv6 default value (false → true)
- Fix log level defaults, add none and fatal levels
- Fix Shadowsocks/ShadowsocksR naming consistency
- Various stability and performance improvements
Version 1.0.7 (163)
- Update KLNEKit
- Add SSH policy support
- Fix UDP issue
- Bug Fixes
Version 1.0.5 (155)
- Update KLNEKit
- Change TUN network to 198.18.0.0/15 to avoid IPv4 internal address issue
- Add help function for menu icon
- Implementate IPv6 support for TUN
- Enable ping support for TUN
- Fix Dock menu disappear issue
- Fix proxy configuraiton not restore after Chute is closed
- Fix TUN network
- Fix app update component
- Bug Fixes
Version 1.0.4 (145)
- Add VLESS protocol support
- Add XTLS for VLESS
- Add display for local IPs
- Add UDP Tunnel support for Chute Dashboard
- Improve build-in DNS server
- Fix FINAL rule process
- Fix UDP Tunnel
- Bug Fixes
Version 1.0.3 (132)
- Support for macOS 10.13 (Without Network.framework Support)
- Fix Config Windows Proxy Section Load
- Fix HTTP Request Error
- Bug Fixes
Version 1.0.2 (102)
- Rebuild DNS Server
- Rebuild Extension installation
- Bug Fixes
Version 1.0.0 (88)
- First release version
- Add TUN support
[Beta] Version 0.4.9 (53)
- Rule order fixed.
- Add support for scan QR code on screen.
- Policy grouop fixed.
[Beta] Version 0.4.5 (32)
- Bug fixes.
[Beta] Version 0.3.5 (25)
- Bug fixes.
[Beta] Version 0.3.0 (20)
- Bug fixes.
[Beta] Version 0.2.0 (8)
- First release.