Skip to content

Releases: CharlieCarisi/XrayAegis-Releases

XrayAegis v1.1.0-beta.3

Pre-release

Choose a tag to compare

@CharlieCarisi CharlieCarisi released this 26 Sep 02:40

XrayAegis 1.1.0 beta 3

This beta standardizes XrayAegis branding and hardens the Windows installation
path after a Microsoft Defender machine-learning detection was reported against
the previous unsigned installer.

Windows installer replacement

The Windows beta 3 assets were rebuilt after an upgrade-path defect was found:
the original beta 3 Setup could invoke beta 2's older service helper and abort
with “unable to stop existing tunnel service.” The replacement Setup now uses
its own embedded helper, repairs a disabled service during upgrade, and lets the
desktop client restart a stopped service automatically. Existing beta 3
downloads should be replaced with the current files and SHA-256 manifest.

Consistent application icon

  • Android, Windows, Linux, macOS, and iOS now derive their application icon
    from the same iOS production artwork.
  • The Windows runner and installer no longer display Flutter's default icon.
  • Platform-required masks and monochrome treatments are still applied by the
    operating system.

Windows installer hardening

  • Removed the packaged PowerShell service-management script and the hidden
    ExecutionPolicy Bypass installation command.
  • Service installation, upgrades, and removal now use a constrained native
    helper with four fixed operations and no arbitrary command execution.
  • The native service package validates an exact runtime allowlist, copies it to
    an administrator-controlled Program Files directory, applies protected ACLs,
    and registers only the two documented XrayAegis services.
  • Added publisher/product/version metadata to the service and installer.
  • Reduced opaque installer packing and added a Microsoft Defender scan to the
    Windows release workflow when Defender is available on the runner.
  • Installer lifecycle and real Xray/WireGuard adapter smoke tests remain
    mandatory before publication.

Important Windows note

This beta remains unsigned. The changes remove behavior likely to trigger
heuristic antivirus models, but they cannot establish publisher reputation.
Windows can still show SmartScreen or administrator prompts. Users should only
install the file from the official XrayAegis release repository and verify its
published SHA-256 digest. A future production Windows release should use a
consistent trusted Authenticode identity or Microsoft Store distribution.

XrayAegis v1.1.0-beta.2

Pre-release

Choose a tag to compare

@CharlieCarisi CharlieCarisi released this 25 Sep 07:34

XrayAegis 1.1.0 beta 2

This beta replaces the browser-based update handoff on Android, Windows, and
Linux with a staged in-app updater.

Background update flow

  • XrayAegis checks the selected stable or beta channel at most every 12 hours
    while the app is active. Automatic checks and downloads can be disabled in
    Settings > Software updates.
  • Only the installer matching the current platform and Android flavor is
    downloaded. Standard and rooted Android packages cannot be mixed.
  • Downloads stream into private staging storage without blocking the interface.
  • The expected file size and GitHub-published SHA-256 digest are verified after
    download and checked again immediately before installation.
  • Installation never begins without an XrayAegis confirmation prompt.

Platform behavior

  • Android: opens Android's system package installer for the permanently
    signed APK. Android 8 and newer may first ask the user to trust XrayAegis as
    an install source. The system confirmation cannot and should not be bypassed.
  • Windows: starts the downloaded setup program in unattended update mode
    after confirmation. This beta remains unsigned, so Windows can still show a
    SmartScreen or administrator prompt.
  • Linux desktop: uses PolicyKit with dpkg when available, otherwise opens
    the verified DEB in the desktop's package handler. Administrator approval may
    be required.
  • iOS and macOS: continue to use TestFlight/App Store distribution and do
    not contact the GitHub updater.

The privacy notice now describes the optional automatic GitHub check and
download behavior. Existing users will be asked to review the updated notice.

XrayAegis v1.1.0-beta.1

Pre-release

Choose a tag to compare

@CharlieCarisi CharlieCarisi released this 25 Sep 02:14

XrayAegis 1.1.0 beta 1

This beta focuses on smoother browsing and faster recovery when Wi-Fi or
cellular connectivity is weak or changes underneath an active Xray tunnel.

It also introduces editable GeoIP/GeoSite routing backed by checksum-pinned
OpenClash-compatible databases and an opt-in beta update channel on Android,
Windows, and Linux.

Windows notice: this beta is not Authenticode-signed. Windows may show a
SmartScreen warning. Verify the published SHA-256 manifest before running the
installer. Android APKs retain the permanent XrayAegis release signature.

Routing improvements

  • Private-network, advertising, and Mainland China policies now use the bundled
    GeoIP/GeoSite databases rather than short hardcoded domain lists.
  • Every predefined route can be edited, disabled, or reset. Custom rules can
    combine domains, CIDRs, GeoIP/GeoSite tags, ports, protocols, actions, and
    TCP/UDP constraints.
  • Android, iOS, Windows, and Linux package the same checksum-pinned routing
    data. Native runtimes report unavailable if required data is missing.

Beta update channel

  • Android, Windows, and Linux users can enable Receive beta versions under
    Settings > Software updates.
  • Beta checks include prereleases but ignore drafts and choose the highest
    semantic version. Stable checks continue using GitHub's stable-only release
    endpoint.
  • Updates are never installed automatically. The app opens the public release
    page so the user can review notes, checksums, and choose the correct package.
  • Builds published from prerelease tags enable the beta channel by default;
    users can opt out at any time.

Network improvements

  • Weak-network optimization is enabled by default for Xray connections. It
    uses a conservative 1380-byte mobile TUN MTU (1420 on desktop), races
    equivalent DNS resolvers, briefly serves cached DNS while refreshing it, and
    detects stale TCP paths sooner after a Wi-Fi/cellular handoff.
  • The Xray TUN configuration now uses the documented lowercase mtu field, so
    the core and the operating-system interface use the same packet size.
  • Android VPN connections inherit metered/unmetered status from the physical
    network. Apps no longer treat unmetered Wi-Fi as metered just because the VPN
    is active.
  • Android uses one native traffic-statistics stream instead of simultaneously
    streaming and polling the same counters. The native sample interval is two
    seconds, reducing connected-state UI work without affecting the tunnel.
  • Apple and other platforms sample foreground statistics every three seconds;
    background statistics work remains paused while the app UI is inactive.

User control and diagnostics

Settings > Xray now includes Weak-network optimization. Leave it enabled
for phones, moving devices, high-latency links, and networks that occasionally
drop packets. Disable it to restore a 1500-byte MTU and Xray's default DNS and
TCP behavior on a known-good Ethernet-style path.

The redacted diagnostics report now includes whether the optimization is
enabled and the effective Xray MTU. It still excludes profile names, server
addresses, credentials, subscription URLs, and device identifiers.

WireGuard keeps the MTU explicitly supplied by each profile. If a WireGuard
profile does not specify an MTU, WireGuardKit retains its native automatic MTU
selection on Apple platforms.

XrayAegis 1.0.0

Choose a tag to compare

@CharlieCarisi CharlieCarisi released this 18 Sep 13:44

XrayAegis 1.0.0

This is the first official XrayAegis release: a private, ad-free client for
user-supplied Xray/VLESS and WireGuard servers.

Downloads

  • Android: most users should install the standard universal APK. Smaller
    architecture-specific APKs and the standard AAB are also provided. The
    separately identified rooted build adds experimental VPN hotspot sharing.
  • Windows: use the x64 Setup executable for a normal installation or the ZIP
    for a portable package.
  • Linux: desktop and terminal/Ubuntu Server packages are included. Their
    filenames retain preview or testing because privileged networking and
    hotspot behavior still require broader distro and hardware validation.
  • iPhone and iPad: use the App Store/TestFlight build. Apple packages are
    not distributed through this GitHub repository.

Warning

The Windows 1.0.0 files are intentionally not Authenticode-signed. Windows
SmartScreen may show an unknown-publisher warning. Verify the download against
the accompanying .sha256 manifest before running it. Do not install a file
whose checksum does not match.

Highlights

  • Native Xray/VLESS and WireGuard tunnels with bundled, pinned runtimes
  • QR, clipboard, manual, file, 3x-ui, and Clash/Mihomo subscription import
  • Field-by-field profile editing and URL, QR, and file export
  • Rule, global, and direct routing modes with configurable DNS
  • Automatic VPN rules and strict Apple leak protection
  • Live upload/download rates and connection statistics
  • Encrypted configuration backup, including private iCloud recovery on iOS
  • English and Simplified Chinese interfaces
  • Windows and Linux startup support
  • Rooted Android and Linux VPN hotspot/gateway tools

XrayAegis supplies the client only. You must provide a compatible server profile
or subscription. Always protect exported configurations because they can contain
private keys, UUIDs, and subscription credentials.