Skip to content

Releases: fosteev/Wayfork

Wayfork 0.10.1 — WireGuard tunnels ready after import

Choose a tag to compare

@fosteev fosteev released this 06 Oct 21:50

A fix for tunnels imported from WireGuard, Shadowsocks and Trojan configs (issue #4) on
both platforms; everything else as in 0.10.0.

Fixed

  • WireGuard, Shadowsocks and Trojan tunnels stuck at "Not ready · … missing" (#4). The
    readiness check looked for every non-OpenVPN tunnel's secret in the VLESS slot, so these
    tunnels showed as missing their key and could not be switched on, although the key was
    stored and routing used it. Each kind is now checked against its own secret, on macOS and
    Windows. Existing tunnels become ready after the update, no re-import needed.

The macOS DMG is not notarized: after copying the app run
xattr -dr com.apple.quarantine /Applications/Wayfork.app (README, "Install").

Wayfork 0.10.0 — TCP only / UDP only rules, first-run guide

Choose a tag to compare

@fosteev fosteev released this 03 Oct 11:38

TCP only / UDP only for app and IP rules (F23, issue #3) on both platforms, and the
first-run guide (F22) on macOS. Pre-release like 0.9.0: covered by the test suites; the
live checks (a Discord call with the rule pair below, the guide on a fresh macOS user) are
still owed.

Added

  • TCP only / UDP only for app and IP rules (F23). An app or address-range rule can be
    narrowed to one transport; site rules stay as they are. Discord → Work plus
    Discord, UDP only → Not via any tunnel sends the client through the tunnel and its
    calls direct, instead of one Direct IP exception per voice server. A narrowed rule beats
    a both-networks rule for the same app or range; Not via any tunnel still beats every
    tunnel. macOS: an inline TCP + UDP / TCP only / UDP only menu in app and IP rows.
    Windows: a Network field in the rule editor, which app rules can now open (Edit,
    double-click; the path stays read-only), and a chip in the row.
    wayforkctl rules add … --network tcp|udp (macOS; it also takes an .app path now) and
    wayforkctl explain --network tcp|udp (Windows).
  • First-run guide (F22, macOS). A fresh install opens a small window that does the real
    setup — allow the helper, add a tunnel, pick the first sites, Turn On, open one of them —
    followed by a dismissible Getting started card in the popover. Replay from
    Settings › General.

Changed

  • Store schema 3, export version 3. Builds before 0.10.0 refuse a store or an export
    written by this one rather than silently routing a narrowed rule's traffic both ways.

Fixed

  • Duplicate app rules after an update (Windows). Two rules written for older builds of
    the same app that both followed it to the newest build are merged into one.
  • wayforkctl rules add --network against an older app fails with a hint to
    wayforkctl revert instead of exiting 0 with a rule for both networks.

Wayfork 0.9.0 — wayforkctl for scripts and assistants

Choose a tag to compare

@fosteev fosteev released this 25 Sep 13:24

wayforkctl for scripts and coding assistants (F21) and the Windows fixes from the Discord
voice session (issues #1, #2). Pre-release like 0.8.0: covered by the test suites only;
the live check of the macOS control socket and the Windows PC run are still owed.

Added

  • wayforkctl for scripts and coding assistants (F21). macOS: logs reads the app's
    log files with --source/--level/--grep/--since/--tail/--json filters and server
    addresses redacted, and works with the app quit. status, failed and rules read
    the running app. rules add|remove and log-level change it through its control
    socket (~/Library/Application Support/Wayfork/control.sock, owner only), and every
    change is undone unless wayforkctl confirm follows within --confirm-within seconds
    (default 60), also across an app crash. reconnect restarts one tunnel. Release
    builds ship the binary in Contents/Resources/bin. Windows: wayforkctl logs with the
    same filters.

  • wayforkctl connections and explain (Windows). Read-only diagnostics on the
    service pipe: connections lists every connection sing-box's Clash API currently
    reports — exit, matched rule, upload/download, and a one-way-UDP flag per connection —
    with --process/--exit/--udp/--one-way filters; explain --process <path> | --host <h> | --ip <a> says which rule the applied plan would take, in route order.
    diagnostics gained --tail N to override its default 200-line log cap (capped at
    5000). Same pipe ACL as every other method; no secrets in the replies.

Fixed

  • App rules survive an auto-update. A rule pointed at a Squirrel or MSIX versioned
    install folder (app-<ver>, WindowsApps\<Name>_<ver>_<arch>__<hash>) stopped matching
    the moment the app updated into a new one (Discord, Slack, …). The rule now matches any
    version of that install, its stored path follows the newest build, and adding the newer
    .exe again is recognized as the same rule (Windows).

Wayfork 0.8.0 — connections by exit

Pre-release

Choose a tag to compare

@fosteev fosteev released this 19 Sep 11:25

Connections by exit on both platforms, and the Can't reach pane made to work on the real sing-box log. Pre-release like 0.7.0: covered by the test suites and a replay of a live log; the visual walks are still owed.

Added

  • Connections by exit — the Logs window (macOS) / Logs page (Windows) gets a second view, Connections: one row per exit (every tunnel, every group, Not via any tunnel, the block list) with connections opened since Turn On, reached, failed and the fail rate; click an exit to see the Can't reach rows behind it. Since Turn On · Last 5 min, Reset, Copy. Opened with ⇧⌘L from the popover footer, from Details on a failing tunnel card, or from the tray menu on Windows. Counts are connections, not requests, and need log detail Normal.

Fixed

  • Can't reach and Connections were empty — the tracker did not read sing-box 1.13's log (coloured connection ids, no match line, info-level failures). Both platforms.
  • VLESS links with REALITY over gRPC import; REALITY over WebSocket stays refused (no server offers it). Both platforms.
  • The popover no longer runs off the screen with many tunnels (macOS).

Install

  • macOS: Wayfork-0.8.0.dmg (signed with an Apple Development identity, not notarized — clear the quarantine flag: xattr -dr com.apple.quarantine /Applications/Wayfork.app). Upgrading from 0.7.0: Settings › General › Reinstall helper once — the daemon changed.
  • Windows: Wayfork-0.8.0-amd64.msi / -arm64.msi or the bundle Wayfork-0.8.0.exe (unsigned — SmartScreen will ask). Attached by the release workflow a few minutes after the tag.

Wayfork 0.7.0 — the F14–F19 wave

Pre-release

Choose a tag to compare

@fosteev fosteev released this 16 Sep 18:14

The F14–F19 wave on both platforms. Pre-release: the code is complete and covered by the test suites; the live checks are still being done.

Added

  • Latency on every card — measured through each tunnel every 10 s, with a 2-minute sparkline; a tunnel that stops answering reads Not reachable with a Retry.
  • Recent — the sites that went the default way in the last 5 minutes, with the app that opened them and a Route via ▾ menu that turns a row into a rule in one click.
  • Tunnel groups — several tunnels behind one name, Fastest or First live; rules and the default exit can point at a group.
  • Local proxy port per tunnel or group — a 127.0.0.1:‹port› SOCKS5/HTTP address that sends any app through that exit without a rule.
  • Block ads and trackers — a bundled, pinned OISD small list compiled into a sing-box rule-set; NXDOMAIN + fast reject, Never block exceptions, Blocked N today.
  • Can't reach — the Logs window/page lists the connections that could not be established (site, app, tries, why, via); a click filters the log to that site.

Changed

  • Wording across the popover/dashboard, Tunnels, Rules and General in the user's words (Connected, Can't connect, N sites, Not via any tunnel, …).

Install

  • macOS: Wayfork-0.7.0.dmg (signed with an Apple Development identity, not notarized — clear the quarantine flag: xattr -dr com.apple.quarantine /Applications/Wayfork.app).
  • Windows: Wayfork-0.7.0-amd64.msi / -arm64.msi or the bundle Wayfork-0.7.0.exe (unsigned — SmartScreen will ask). Attached by the release workflow a few minutes after the tag.

Wayfork 0.6.0 — subscription links

Choose a tag to compare

@fosteev fosteev released this 12 Sep 13:53

Subscription links: paste the URL a VPN service hands out instead of copying its servers
one by one.

Added

  • Subscription URLs, on both platforms. + Add › Add from link… also takes an
    https:// subscription link: Fetch loads it, decodes plain link lines or base64 of
    them, lists every server with a checkbox (servers already added start unchecked) and
    every line it could not use with the reason — an unsupported scheme or a bad link skips
    that line, not the import. One-shot by design: the URL is a bearer token for every
    server on it, so it is never stored, logged or refreshed. http:// is refused.

Wayfork 0.5.0 — four more tunnel kinds

Choose a tag to compare

@fosteev fosteev released this 08 Sep 14:02

Four more tunnel kinds, all native to the bundled sing-box: nothing new runs, nothing new
is installed, and the same rules, default tunnel and traffic view apply to them.

Added

  • Four more tunnel kinds, on both platforms. Next to OpenVPN and VLESS, Wayfork now
    takes a WireGuard .conf (file, drag & drop, or pasted) and ss://, trojan:// and
    vmess:// links. They cost nothing at runtime: like VLESS, each is a few lines in the
    sing-box config — no extra process, no adapter, ready whenever routing is on. WireGuard
    runs inside sing-box's own userspace stack, so it needs no driver and leaves nothing
    behind.
  • One Add-from-link sheet. + Add › Add from link… recognises the scheme itself and
    previews what it parsed, so a pasted link no longer has to match a menu item; + Add ›
    Add WireGuard…
    takes a file or pasted config with the same preview. Every link kind
    offers Copy with its secret masked in the UI and restored from the Keychain / DPAPI.
  • WireGuard resolvers. A WireGuard tunnel gets the same per-tunnel DNS choice OpenVPN
    has: Automatic uses the DNS = line from the conf, and as the default tunnel it
    resolves everything through the tunnel instead of a public DoT server.

Changed

  • A config whose AllowedIPs covers less than everything is imported as written and
    flagged: traffic Wayfork sends into that tunnel outside the list is dropped by the peer.
  • What sing-box would carry but misroute or silently weaken is still refused at import,
    with the reason named: pre-AEAD Shadowsocks ciphers, SIP003 plugin=, VMess alterId
    above 0 and non-V2RayN vmess:// forms.

Fixed

  • Server hostnames are no longer resolved to Wayfork's own fake IPs while it is running —
    a lookup that went through the running tunnel could return an address that routes back
    into the TUN. Only WireGuard peers would have been misconfigured by it, but the fix is in
    the shared resolver.

Install

macOS builds are signed but not notarized, so after copying the app run:

xattr -dr com.apple.quarantine /Applications/Wayfork.app

Windows MSIs are unsigned; SmartScreen warns until the certificate has reputation.

Wayfork 0.4.0 — field hardening

Pre-release

Choose a tag to compare

@fosteev fosteev released this 02 Sep 07:52

Per-domain split tunneling across several VPNs at once. A hardening release for both
platforms, straight from a day of field debugging: a daemon that had died silently, voice
UDP cut at the VPN server, and a poisoned ISP resolver mislabeling traffic.

Downloads

  • Windows 10/11: Wayfork-0.4.0.exe — one installer for x64 and ARM64, it picks the
    right package itself. (Wayfork-0.4.0-amd64.msi / -arm64.msi are there for deployment
    tooling that wants an MSI.)
  • macOS 14+: Wayfork-0.4.0.dmg (universal).

Verify a download against its .sha256 before installing.

What's new

  • A slow TUN bring-up no longer kills a healthy start. The startup check polls for up
    to 12 seconds and retries the start once, instead of one check after 3 seconds that
    could declare a working sing-box failed. Turn Off during a failing start answers
    immediately.
  • A routing engine that cannot start is loud now. The menu bar / tray icon shows the
    error state, one notification per failure streak says Wayfork keeps retrying, and the
    app re-applies on its own with growing backoff (5 s … 5 min) — previously the app could
    look On while everything routed direct.
  • One-way UDP warning. A tunnel whose UDP connections keep sending but have received
    nothing for 10 seconds gets an orange ⚠ next to its traffic rate — the signature of a
    VPN server dropping UDP, which is how broken voice chat and gaming look. The counts are
    logged and included in Export Diagnostics, which now carries a traffic summary.
  • Traffic labels no longer trust a poisoned resolver. reverse_mapping is emitted
    only when a default tunnel needs it for routing, so a spoofed ISP answer for a blocked
    domain can no longer tag unrelated raw-IP connections with that domain.

See CHANGELOG.md for the
full entry and the known limitations.

Signing

Still unsigned by a paid certificate: SmartScreen warns on the Windows installer and on
the first launch ("More info" → "Run anyway"); on macOS clear the quarantine flag as the
README's Install section describes.

Wayfork 0.3.0 — application picker on Windows

Choose a tag to compare

@fosteev fosteev released this 29 Aug 09:56

Per-domain split tunneling across several VPNs at once. A Windows-only release: the macOS
app is unchanged since 0.2.0, so no new .dmg — keep using
0.2.0 there.

Downloads

  • Windows 10/11: Wayfork-0.3.0.exe — one installer for x64 and ARM64, it picks the
    right package itself. (Wayfork-0.3.0-amd64.msi / -arm64.msi are there for deployment
    tooling that wants an MSI.)

Verify a download against its .sha256 before installing.

What's new

  • Pick an application rule from what is running. Rules → + → Application… used to
    open a file dialog, which assumes you know where an app is installed. It now lists the
    applications that are running — the same set as Task Manager's Apps — by their real
    names ("Google Chrome", not "chrome"), with a search box, an optional view of background
    processes, and Browse… still there for an app that is not started. Store apps resolve
    to their own executable rather than to ApplicationFrameHost, and the dozens of
    processes behind Chrome or an Electron app collapse into one entry.
  • Fixed: the service client could throw "Future already completed" when a reconnect
    wait ended at the same moment as Retry or shutdown.

See CHANGELOG.md for the
full entry and the known limitations.

Signing

Still unsigned by a paid certificate: SmartScreen warns on the installer and on the first
launch — "More info" → "Run anyway".

Wayfork 0.2.0 — Windows client preview

Choose a tag to compare

@fosteev fosteev released this 28 Aug 14:10

Per-domain split tunneling across several VPNs at once — now on Windows as well as macOS.

Downloads

  • Windows 10/11: Wayfork-0.2.0.exe — one installer for x64 and ARM64, it picks the
    right package itself. (Wayfork-0.2.0-amd64.msi / -arm64.msi are there for deployment
    tooling that wants an MSI.)
  • macOS 14+: Wayfork-0.2.0.dmg (universal).

Verify a download against its .sha256 before installing.

What's new

  • Windows client (preview): the same feature set — a Fluent UI app in the notification
    area over a LocalSystem service that owns sing-box, the OpenVPN processes, the adapters,
    the routes and the DNS override. Tunnels, rules (domain, application, IP), the default
    tunnel, traffic rates, logs, import/export and Export Diagnostics work as they do on
    macOS; wayfork-export.json carries a configuration between the two, minus the
    application rules, which name a path per platform.

See CHANGELOG.md for the
full entry and the known limitations.

Signing

Neither package is signed by a paid certificate yet, so both operating systems complain on
first run:

  • Windows: SmartScreen warns on the installer and on the first launch — "More info" →
    "Run anyway".
  • macOS: the app is signed with an Apple Development certificate, so clear the quarantine
    flag after installing: xattr -dr com.apple.quarantine /Applications/Wayfork.app
    (README, "Install").