Releases: dalroot/hawal
Releases · dalroot/hawal
Release list
v2.5.1
Full Changelog: v2.4.0...v2.5.1
Full Changelog: v2.4.0...v2.5.1
Full Changelog: v2.4.0...v2.5.1
Full Changelog: v2.4.0...v2.5.1
v2.4.0
v2.3.0: Enterprise Bento UI, Real-time Analytics & Hawal Core v2 TLS Reverse Tunneling
⚡ Hawal Tunnel v2.3.0 — Enterprise Bento UI, Real-time Analytics & Hawal Core v2 Outbound TLS Reverse Tunneling
Welcome to Hawal Tunnel v2.3.0! This milestone delivers a modernized enterprise UI, real-time bandwidth analytics, enhanced DPI-resilient reverse tunneling in Hawal Core v2, cross-architecture CI/CD automation, and integrated GitHub CodeQL security scanning.
🎨 Enterprise UI & Bento Architecture
- Modern Bento Grid Layout: Clean, modular interface designed with dark-mode gradients, smooth micro-interactions, and fully responsive layout for desktop and mobile.
- Server Resource Telemetry Gauges: Real-time circular and linear meters for CPU, RAM, and disk utilization across all connected server nodes.
- Real-Time Bandwidth & Historical Traffic Charts: Instantaneous upload/download throughput meters (MB/s) and historical 24-hour / 30-day cumulative consumption charts powered by Chart.js.
- SPA URL Routing & State Persistence: Hash-based single-page navigation (
#tunnels,#nodes,#traffic,#logs,#settings) supporting direct links and history navigation.
⚡ Hawal Core v2: Outbound Reverse Tunneling & TLS Carrier
- Outbound Reverse Architecture: Foreign servers listen (
mode=server) and domestic nodes initiate connections (mode=client), effortlessly overcoming strict ingress filtering on domestic ISPs. - Perfect Forward Secrecy (PFS): Ephemeral X25519 Diffie-Hellman key exchange, HMAC-SHA256 mutual authentication, and ChaCha20-Poly1305 authenticated encryption.
- Authentic TLS 1.3 Carrier Camouflage: Masks tunnel traffic inside genuine TLS handshakes with customizable SNI, completely removing predictable magic packet headers (
HWL1). - Encrypted Metadata & Length Buckets: Protects stream IDs, frame types, and length headers under AEAD encryption with randomized initial padding (16-48 bytes) to resist ML length fingerprinting.
- Direct Kernel Accounting: Aligned iptables socket counting for multiplexed streams on both ends.
🛡️ Automated CI/CD, CodeQL Security & Multi-Arch Releases
- Multi-Architecture Matrix Compilation: Automated cross-compilation for 4 Linux architectures:
linux/amd64(Standard 64-bit x86 servers)linux/arm64(ARMv8 / AArch64 cloud VPS & Raspberry Pi 4/5)linux/386(Legacy 32-bit x86 servers)linux/armv7(32-bit ARM hardware)
- 32-Bit Arithmetic Hardening: Resolved integer overflow bounds in record codec for seamless 32-bit compilation.
- CodeQL & Gosec Static Analysis: Automated vulnerability and memory safety scanning across Go and Python codebases on every PR and push.
- Community Standards: Added interactive issue templates (
bug_report.yml,feature_request.yml,dpi_network_report.yml), PR template,SECURITY.md, andCONTRIBUTING.md.
🚀 Unified CLI Diagnostics (hawal)
- Zero-dependency CLI terminal utility for operators:
hawal: Interactive menuhawal tunnels: Multi-core tunnel registry tablehawal ping: Real-time RTT benchmarks and upstream target testshawal logs: Stream tunnel logs with ID filteringhawal restart: Clean process group recycling (os.killpg)
📦 Release Assets & Cryptographic Checksums
| Asset Binary | Architecture | Size | SHA-256 Checksum |
|---|---|---|---|
hawal-core-linux-amd64 |
Linux x86_64 | 6.41 MB | Check checksums.txt |
hawal-core-linux-arm64 |
Linux aarch64 | 5.18 MB | Check checksums.txt |
hawal-core-linux-386 |
Linux i386 | 5.42 MB | Check checksums.txt |
hawal-core-linux-armv7 |
Linux armv7 | 5.43 MB | Check checksums.txt |
checksums.txt |
Text | 354 B | Cryptographic validation |
⚡ Quick Install (1-Line Deployment)
# Install Master Panel on Domestic / Management Server
curl -sSL https://raw.githubusercontent.com/dalroot/hawal/master/install-panel.sh | bashFull Changelog: https://github.com/dalroot/hawal/commits/v2.3.0