Skip to content

Releases: feg55/Zarp

v1.3.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 17:54

What's new

Another VPN no longer ruins your results. A search while another VPN (Happ, v2rayN, Clash, ...) is on now asks first, and failures from such a run are never saved, so working strategies are not overwritten. Connecting with a saved strategy still works.

New strategy set (15). Added TLS disorder on SNI points, disorder with seqovl and a gosuslugi fake, QUIC IP fragmentation and a x11 fake, plus WARP endpoint port 8095. Removed the built-in WireGuard strategies and close variants.

More honest results. Quick scan counts only confirmed strategies, and a connection counts only if traffic really goes through WARP. Zarp notices a dropped tunnel within 15 seconds.

Hardening. The WARP installer and warp-cli are checked by the certificate's organization, system tools run from absolute paths, settings are saved atomically with a backup, a failed zapret2 update rolls back, and Windows shutdown is no longer blocked.

Behavior change. --autostart now only starts Zarp in the tray. Connecting on start is controlled by the "Connect when Zarp starts" setting or --connect.

This release is unsigned. Windows SmartScreen may show an unknown-publisher warning.

Zarp.exe SHA-256: 8fa5e2f47f98a9f74a7104e0f370b4e412555950c73b63cd66e0ae9170178514

Check that the file was built by GitHub Actions from this repository:
gh attestation verify Zarp.exe --repo feg55/Zarp

Code signing policy

Full Changelog: v1.2.0...v1.3.0

v1.2.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 15:39

What's new

  • Cloudflare WARP is installed for you. If it is missing, Zarp asks once, downloads the official installer from Cloudflare, checks its signature and installs it, then carries on. No separate setup.
  • Better WARP detection. Zarp now finds WARP via the Windows service, the installed programs list and every drive, and writes what it looked at to the log.
  • If the Cloudflare site is blocked, put Cloudflare_WARP.msi into %LOCALAPPDATA%\Zarp and Zarp installs it after verifying the signature.

This release is unsigned. Windows SmartScreen may show an unknown-publisher warning.

Zarp.exe SHA-256: 524e74281362c7d685ebf03167a0fa7a170dc3dda312bdb80b3cdc241627b528

Check that the file was built by GitHub Actions from this repository:
gh attestation verify Zarp.exe --repo feg55/Zarp

Code signing policy

Full Changelog: v1.1.0...v1.2.0

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 22:51

What's new

  • 8 languages: English, Русский, Español, Português, 中文, हिन्दी, Français, Deutsch. Zarp follows the Windows language (English otherwise); the globe button next to Settings switches it on the fly.
  • Quick scan and Full scan. Quick scan stops after N working strategies (3 by default). Full scan tests every strategy, so nothing is skipped.
  • While a search runs, Cancel takes the place of the scan buttons.
  • Test results are stored language-independently and follow the chosen language.

This release is unsigned. Windows SmartScreen may show an unknown-publisher warning.

Zarp.exe SHA-256: 4b706ffdea213ef0ab40279b7293e9063c8a271ad5a64bf8fe2518160835522a

Check that the file was built by GitHub Actions from this repository:
gh attestation verify Zarp.exe --repo feg55/Zarp

v1.0.3

Choose a tag to compare

@github-actions github-actions released this 24 Sep 21:35

This release is unsigned. Windows SmartScreen may show an unknown-publisher warning.

Zarp.exe SHA-256: 1a66b614dbfd95342d14e8cb7e84245f686c3e7396cc5c8b1c564cad8b51caa1

Check that the file was built by GitHub Actions from this repository:
gh attestation verify Zarp.exe --repo feg55/Zarp

Full Changelog: v1.0.2...v1.0.3

v1.0.1

Choose a tag to compare

@github-actions github-actions released this 24 Sep 20:54

This release is unsigned. Windows SmartScreen may show an unknown-publisher warning.

Zarp.exe SHA-256: d002953089eede39db1f4b0c14018b99ebb4a9350e42525d16d7e42ff2f2dfe7

Check that the file was built by GitHub Actions from this repository:
gh attestation verify Zarp.exe --repo feg55/Zarp

Full Changelog: v1.0.0...v1.0.1

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 20:24

First public release of Zarp: one-click Cloudflare WARP for networks that block it.

Zarp finds a zapret2 strategy that gets the WARP handshake through DPI, remembers it and connects. No config files, no command line.

Download

Zarp.exe (1.7 MB). A single file, no installer. zapret2 v1.0.5.2 is embedded.

Highlights

  • One button. The first click finds the fastest working strategy, later clicks connect instantly.
  • Strategies built for WARP. 17 profiles aimed at the WARP handshake: MASQUE over QUIC, WireGuard and the MASQUE HTTP/2 fallback. The fakes are real QUIC/TLS/STUN packets of services that are not blocked.
  • Honest testing. Each test hits a fresh WARP endpoint and every candidate is checked twice, so a strategy can't pass on the back of a previous connection.
  • Self-healing. If the saved strategy stops working, Zarp tries the other verified ones before searching again.
  • Auto-updates zapret2 in the background. If WARP is connected, the update applies without dropping the tunnel. If the new version fails to start, Zarp rolls back.
  • Low overhead. Only WARP addresses and handshake packets are intercepted. Your other traffic and the tunnel itself never go through zapret.
  • Tray mode, autostart with Windows, custom strategies via strategies.txt.

Requirements

  • Windows 10 or 11, x64
  • Cloudflare WARP installed (winget install Cloudflare.Warp)
  • Administrator rights (required by the WinDivert driver)

Getting started

  1. Run Zarp.exe and accept the UAC prompt.
  2. Press the power button. The first search takes a minute or two.
  3. That's it. The next time you open Zarp, one click connects.

Good to know

  • Turn off other VPNs (Happ, v2rayN, Clash, AmneziaVPN, ...) before searching. WARP traffic would go through their tunnel and no strategy would be found. Zarp warns you if it detects one.
  • Windows Defender may flag WinDivert as a hacktool. This is a known false positive for every zapret build. If it happens, Zarp offers to add its folder to Defender exclusions.
  • Zarp keeps its settings, log and zapret2 files in %LOCALAPPDATA%\Zarp.
  • Zarp changes the WARP tunnel protocol and, during the search, the endpoint. The endpoint goes back to automatic once the search is done.

Credits

zapret2 by bol-van, WinDivert, Cloudflare WARP.