Repository navigation
Releases: fosteev/Wayfork
Release list
Wayfork 0.10.1 — WireGuard tunnels ready after import
A fix for tunnels imported from WireGuard, Shadowsocks and Trojan configs (issue #4) on
both platforms; everything else as in 0.10.0.
Fixed
- WireGuard, Shadowsocks and Trojan tunnels stuck at "Not ready · … missing" (#4). The
readiness check looked for every non-OpenVPN tunnel's secret in the VLESS slot, so these
tunnels showed as missing their key and could not be switched on, although the key was
stored and routing used it. Each kind is now checked against its own secret, on macOS and
Windows. Existing tunnels become ready after the update, no re-import needed.
The macOS DMG is not notarized: after copying the app run
xattr -dr com.apple.quarantine /Applications/Wayfork.app (README, "Install").
Wayfork 0.10.0 — TCP only / UDP only rules, first-run guide
TCP only / UDP only for app and IP rules (F23, issue #3) on both platforms, and the
first-run guide (F22) on macOS. Pre-release like 0.9.0: covered by the test suites; the
live checks (a Discord call with the rule pair below, the guide on a fresh macOS user) are
still owed.
Added
- TCP only / UDP only for app and IP rules (F23). An app or address-range rule can be
narrowed to one transport; site rules stay as they are.Discord → Workplus
Discord, UDP only → Not via any tunnelsends the client through the tunnel and its
calls direct, instead of one Direct IP exception per voice server. A narrowed rule beats
a both-networks rule for the same app or range; Not via any tunnel still beats every
tunnel. macOS: an inline TCP + UDP / TCP only / UDP only menu in app and IP rows.
Windows: a Network field in the rule editor, which app rules can now open (Edit,
double-click; the path stays read-only), and a chip in the row.
wayforkctl rules add … --network tcp|udp(macOS; it also takes an.apppath now) and
wayforkctl explain --network tcp|udp(Windows). - First-run guide (F22, macOS). A fresh install opens a small window that does the real
setup — allow the helper, add a tunnel, pick the first sites, Turn On, open one of them —
followed by a dismissible Getting started card in the popover. Replay from
Settings › General.
Changed
- Store schema 3, export version 3. Builds before 0.10.0 refuse a store or an export
written by this one rather than silently routing a narrowed rule's traffic both ways.
Fixed
- Duplicate app rules after an update (Windows). Two rules written for older builds of
the same app that both followed it to the newest build are merged into one. wayforkctl rules add --networkagainst an older app fails with a hint to
wayforkctl revertinstead of exiting 0 with a rule for both networks.
Wayfork 0.9.0 — wayforkctl for scripts and assistants
wayforkctl for scripts and coding assistants (F21) and the Windows fixes from the Discord
voice session (issues #1, #2). Pre-release like 0.8.0: covered by the test suites only;
the live check of the macOS control socket and the Windows PC run are still owed.
Added
-
wayforkctlfor scripts and coding assistants (F21). macOS:logsreads the app's
log files with--source/--level/--grep/--since/--tail/--jsonfilters and server
addresses redacted, and works with the app quit.status,failedandrulesread
the running app.rules add|removeandlog-levelchange it through its control
socket (~/Library/Application Support/Wayfork/control.sock, owner only), and every
change is undone unlesswayforkctl confirmfollows within--confirm-withinseconds
(default 60), also across an app crash.reconnectrestarts one tunnel. Release
builds ship the binary inContents/Resources/bin. Windows:wayforkctl logswith the
same filters. -
wayforkctl connectionsandexplain(Windows). Read-only diagnostics on the
service pipe:connectionslists every connection sing-box's Clash API currently
reports — exit, matched rule, upload/download, and a one-way-UDP flag per connection —
with--process/--exit/--udp/--one-wayfilters;explain --process <path> | --host <h> | --ip <a>says which rule the applied plan would take, in route order.
diagnosticsgained--tail Nto override its default 200-line log cap (capped at
5000). Same pipe ACL as every other method; no secrets in the replies.
Fixed
- App rules survive an auto-update. A rule pointed at a Squirrel or MSIX versioned
install folder (app-<ver>,WindowsApps\<Name>_<ver>_<arch>__<hash>) stopped matching
the moment the app updated into a new one (Discord, Slack, …). The rule now matches any
version of that install, its stored path follows the newest build, and adding the newer
.exeagain is recognized as the same rule (Windows).
Wayfork 0.8.0 — connections by exit
Connections by exit on both platforms, and the Can't reach pane made to work on the real sing-box log. Pre-release like 0.7.0: covered by the test suites and a replay of a live log; the visual walks are still owed.
Added
- Connections by exit — the Logs window (macOS) / Logs page (Windows) gets a second view, Connections: one row per exit (every tunnel, every group, Not via any tunnel, the block list) with connections opened since Turn On, reached, failed and the fail rate; click an exit to see the Can't reach rows behind it. Since Turn On · Last 5 min, Reset, Copy. Opened with ⇧⌘L from the popover footer, from Details on a failing tunnel card, or from the tray menu on Windows. Counts are connections, not requests, and need log detail Normal.
Fixed
- Can't reach and Connections were empty — the tracker did not read sing-box 1.13's log (coloured connection ids, no match line, info-level failures). Both platforms.
- VLESS links with REALITY over gRPC import; REALITY over WebSocket stays refused (no server offers it). Both platforms.
- The popover no longer runs off the screen with many tunnels (macOS).
Install
- macOS:
Wayfork-0.8.0.dmg(signed with an Apple Development identity, not notarized — clear the quarantine flag:xattr -dr com.apple.quarantine /Applications/Wayfork.app). Upgrading from 0.7.0: Settings › General › Reinstall helper once — the daemon changed. - Windows:
Wayfork-0.8.0-amd64.msi/-arm64.msior the bundleWayfork-0.8.0.exe(unsigned — SmartScreen will ask). Attached by the release workflow a few minutes after the tag.
Wayfork 0.7.0 — the F14–F19 wave
The F14–F19 wave on both platforms. Pre-release: the code is complete and covered by the test suites; the live checks are still being done.
Added
- Latency on every card — measured through each tunnel every 10 s, with a 2-minute sparkline; a tunnel that stops answering reads Not reachable with a Retry.
- Recent — the sites that went the default way in the last 5 minutes, with the app that opened them and a Route via ▾ menu that turns a row into a rule in one click.
- Tunnel groups — several tunnels behind one name, Fastest or First live; rules and the default exit can point at a group.
- Local proxy port per tunnel or group — a
127.0.0.1:‹port›SOCKS5/HTTP address that sends any app through that exit without a rule. - Block ads and trackers — a bundled, pinned OISD small list compiled into a sing-box rule-set; NXDOMAIN + fast reject, Never block exceptions, Blocked N today.
- Can't reach — the Logs window/page lists the connections that could not be established (site, app, tries, why, via); a click filters the log to that site.
Changed
- Wording across the popover/dashboard, Tunnels, Rules and General in the user's words (Connected, Can't connect,
N sites, Not via any tunnel, …).
Install
- macOS:
Wayfork-0.7.0.dmg(signed with an Apple Development identity, not notarized — clear the quarantine flag:xattr -dr com.apple.quarantine /Applications/Wayfork.app). - Windows:
Wayfork-0.7.0-amd64.msi/-arm64.msior the bundleWayfork-0.7.0.exe(unsigned — SmartScreen will ask). Attached by the release workflow a few minutes after the tag.
Wayfork 0.6.0 — subscription links
Subscription links: paste the URL a VPN service hands out instead of copying its servers
one by one.
Added
- Subscription URLs, on both platforms. + Add › Add from link… also takes an
https://subscription link: Fetch loads it, decodes plain link lines or base64 of
them, lists every server with a checkbox (servers already added start unchecked) and
every line it could not use with the reason — an unsupported scheme or a bad link skips
that line, not the import. One-shot by design: the URL is a bearer token for every
server on it, so it is never stored, logged or refreshed.http://is refused.
Wayfork 0.5.0 — four more tunnel kinds
Four more tunnel kinds, all native to the bundled sing-box: nothing new runs, nothing new
is installed, and the same rules, default tunnel and traffic view apply to them.
Added
- Four more tunnel kinds, on both platforms. Next to OpenVPN and VLESS, Wayfork now
takes a WireGuard.conf(file, drag & drop, or pasted) andss://,trojan://and
vmess://links. They cost nothing at runtime: like VLESS, each is a few lines in the
sing-box config — no extra process, no adapter, ready whenever routing is on. WireGuard
runs inside sing-box's own userspace stack, so it needs no driver and leaves nothing
behind. - One Add-from-link sheet. + Add › Add from link… recognises the scheme itself and
previews what it parsed, so a pasted link no longer has to match a menu item; + Add ›
Add WireGuard… takes a file or pasted config with the same preview. Every link kind
offers Copy with its secret masked in the UI and restored from the Keychain / DPAPI. - WireGuard resolvers. A WireGuard tunnel gets the same per-tunnel DNS choice OpenVPN
has: Automatic uses theDNS =line from the conf, and as the default tunnel it
resolves everything through the tunnel instead of a public DoT server.
Changed
- A config whose
AllowedIPscovers less than everything is imported as written and
flagged: traffic Wayfork sends into that tunnel outside the list is dropped by the peer. - What sing-box would carry but misroute or silently weaken is still refused at import,
with the reason named: pre-AEAD Shadowsocks ciphers, SIP003plugin=, VMessalterId
above 0 and non-V2RayNvmess://forms.
Fixed
- Server hostnames are no longer resolved to Wayfork's own fake IPs while it is running —
a lookup that went through the running tunnel could return an address that routes back
into the TUN. Only WireGuard peers would have been misconfigured by it, but the fix is in
the shared resolver.
Install
macOS builds are signed but not notarized, so after copying the app run:
xattr -dr com.apple.quarantine /Applications/Wayfork.appWindows MSIs are unsigned; SmartScreen warns until the certificate has reputation.
Wayfork 0.4.0 — field hardening
Per-domain split tunneling across several VPNs at once. A hardening release for both
platforms, straight from a day of field debugging: a daemon that had died silently, voice
UDP cut at the VPN server, and a poisoned ISP resolver mislabeling traffic.
Downloads
- Windows 10/11:
Wayfork-0.4.0.exe— one installer for x64 and ARM64, it picks the
right package itself. (Wayfork-0.4.0-amd64.msi/-arm64.msiare there for deployment
tooling that wants an MSI.) - macOS 14+:
Wayfork-0.4.0.dmg(universal).
Verify a download against its .sha256 before installing.
What's new
- A slow TUN bring-up no longer kills a healthy start. The startup check polls for up
to 12 seconds and retries the start once, instead of one check after 3 seconds that
could declare a working sing-box failed. Turn Off during a failing start answers
immediately. - A routing engine that cannot start is loud now. The menu bar / tray icon shows the
error state, one notification per failure streak says Wayfork keeps retrying, and the
app re-applies on its own with growing backoff (5 s … 5 min) — previously the app could
look On while everything routed direct. - One-way UDP warning. A tunnel whose UDP connections keep sending but have received
nothing for 10 seconds gets an orange ⚠ next to its traffic rate — the signature of a
VPN server dropping UDP, which is how broken voice chat and gaming look. The counts are
logged and included in Export Diagnostics, which now carries a traffic summary. - Traffic labels no longer trust a poisoned resolver.
reverse_mappingis emitted
only when a default tunnel needs it for routing, so a spoofed ISP answer for a blocked
domain can no longer tag unrelated raw-IP connections with that domain.
See CHANGELOG.md for the
full entry and the known limitations.
Signing
Still unsigned by a paid certificate: SmartScreen warns on the Windows installer and on
the first launch ("More info" → "Run anyway"); on macOS clear the quarantine flag as the
README's Install section describes.
Wayfork 0.3.0 — application picker on Windows
Per-domain split tunneling across several VPNs at once. A Windows-only release: the macOS
app is unchanged since 0.2.0, so no new .dmg — keep using
0.2.0 there.
Downloads
- Windows 10/11:
Wayfork-0.3.0.exe— one installer for x64 and ARM64, it picks the
right package itself. (Wayfork-0.3.0-amd64.msi/-arm64.msiare there for deployment
tooling that wants an MSI.)
Verify a download against its .sha256 before installing.
What's new
- Pick an application rule from what is running. Rules → + → Application… used to
open a file dialog, which assumes you know where an app is installed. It now lists the
applications that are running — the same set as Task Manager's Apps — by their real
names ("Google Chrome", not "chrome"), with a search box, an optional view of background
processes, and Browse… still there for an app that is not started. Store apps resolve
to their own executable rather than toApplicationFrameHost, and the dozens of
processes behind Chrome or an Electron app collapse into one entry. - Fixed: the service client could throw "Future already completed" when a reconnect
wait ended at the same moment as Retry or shutdown.
See CHANGELOG.md for the
full entry and the known limitations.
Signing
Still unsigned by a paid certificate: SmartScreen warns on the installer and on the first
launch — "More info" → "Run anyway".
Wayfork 0.2.0 — Windows client preview
Per-domain split tunneling across several VPNs at once — now on Windows as well as macOS.
Downloads
- Windows 10/11:
Wayfork-0.2.0.exe— one installer for x64 and ARM64, it picks the
right package itself. (Wayfork-0.2.0-amd64.msi/-arm64.msiare there for deployment
tooling that wants an MSI.) - macOS 14+:
Wayfork-0.2.0.dmg(universal).
Verify a download against its .sha256 before installing.
What's new
- Windows client (preview): the same feature set — a Fluent UI app in the notification
area over a LocalSystem service that owns sing-box, the OpenVPN processes, the adapters,
the routes and the DNS override. Tunnels, rules (domain, application, IP), the default
tunnel, traffic rates, logs, import/export and Export Diagnostics work as they do on
macOS;wayfork-export.jsoncarries a configuration between the two, minus the
application rules, which name a path per platform.
See CHANGELOG.md for the
full entry and the known limitations.
Signing
Neither package is signed by a paid certificate yet, so both operating systems complain on
first run:
- Windows: SmartScreen warns on the installer and on the first launch — "More info" →
"Run anyway". - macOS: the app is signed with an Apple Development certificate, so clear the quarantine
flag after installing:xattr -dr com.apple.quarantine /Applications/Wayfork.app
(README, "Install").