Skip to content

Releases: jcltravels/RocketProxy

Rocket Proxy 2.0 for macOS

Choose a tag to compare

@jcltravels jcltravels released this 03 Aug 10:08

Rocket Proxy 2.0 for macOS — free direct download (Developer ID signed, notarised).

What's new

Clash and Stash YAML support. Rocket Proxy now imports Clash and Stash
configurations in full — servers, rules, proxy groups and providers, not just
the server list. Previously a Clash/Stash subscription kept only the servers
and silently dropped every routing policy, which made moving across
impractical. Bring one over by URL, QR code, file, iCloud or clipboard and
keep the routing you already built.

  • Proxy groups with automatic latency probing (select, url-test, fallback, load-balance)
  • Full rule support, including GEOSITE and rule/proxy providers
  • Editable DNS settings
  • Automatic node switching by Wi-Fi network (SSID policy)
  • Apply configuration changes without dropping live connections
  • An import report showing exactly what was imported and what was ignored
  • Read-only YAML viewer with diagnostics mapped to the offending line
  • Localised across 21 languages

Validation

All 36 protocol combinations were tested end-to-end through Chrome against
this exact notarised build, installed from this DMG the way a user installs
it:

  • 36/36 passed
  • 36/36 clean on DNS leaks
  • 36/36 loaded all 6 concurrent tabs, plus a 12-request soak and sustained
    media playback per combination

Verify your download

shasum -a 256 RocketProxy-2.0.dmg
0b4da9dd48200e3dd8fc49520b1dce7534d4fce81c94ed0678aa591b05536f6d

Installing

Open the DMG and drag Rocket Proxy onto Applications in Finder. Don't run
it from the disk image — macOS will start it from a temporary read-only copy
and the network extension will not install.

Rocket Proxy 1.5 for macOS

Choose a tag to compare

@jcltravels jcltravels released this 02 Aug 01:34

Rocket Proxy 1.5 for macOS

This release fixes a DNS privacy leak. If you use WireGuard, AmneziaWG or OpenConnect, please update.

Fixed: DNS leak on WireGuard, AmneziaWG and OpenConnect

When connected over these three protocols, some DNS lookups were sent outside the tunnel, in plaintext, over your normal network connection. Anyone able to observe that connection — an ISP, a network operator, a hostile Wi-Fi — could see the names of the sites being looked up, even while the app reported "connected".

Your traffic itself was always encrypted and tunnelled. What escaped were the lookups, and only on these three of the twelve protocols.

Root cause. On Apple platforms, a network extension's own traffic bypasses its own tunnel by design. These three backends resolved certain hostnames inside the extension process, so those queries went straight out the physical interface. The other protocols use fake-IP mapping and resolve in-tunnel at connect time, which is why they were never affected. It was not a flaw in WireGuard, AmneziaWG or OpenConnect themselves.

Fix. Name resolution for these backends now goes through the tunnel's own network interface — the same path already used when establishing a connection — and falls back to fake-IP mapping rather than to any system resolver. Real IPs are required for WireGuard L3 passthrough (which routes by destination address), so simply suppressing resolution was not an option.

Also hardened. DNS query transaction IDs are now random per query. They had been a hardcoded constant, which makes off-path response spoofing considerably easier than it should be.

Validation

The full 36-combination protocol × transport matrix, exercised through real multi-tab browsing with a packet capture running on the physical interface:

36 / 36 PASS — 0 DNS leaks

macOS: now universal

The 1.4 DMG was Apple-silicon only. 1.5 is a universal build and runs natively on both Apple silicon and Intel Macs (macOS 13 or later).

Verify your download

shasum -a 256 RocketProxy-1.5.dmg
7a9cf47bbb0a27861184fadd1c83070d65f897155a923a4c3e713f5dd3ce3693

Signed with a Developer ID, notarized and stapled by Apple.

Installing

Open the DMG and drag Rocket Proxy onto Applications in Finder. Don't launch it from the disk image — macOS would run it from a temporary copy and the network extension won't install.


iOS, iPadOS and tvOS builds of 1.5 are distributed through the App Store; they cannot be installed from here.

Rocket Proxy 1.4 for macOS

Choose a tag to compare

@jcltravels jcltravels released this 30 Jul 07:07

Free, native macOS client. Signed with a Developer ID, notarized and stapled by
Apple — no App Store account needed, and it installs offline.

Requires macOS 13 or later. Apple silicon.

Install

  1. Open the DMG and drag Rocket Proxy onto the Applications shortcut in the
    same window. Drag it in Finder — don't copy it from a terminal and don't run
    it from the disk image, or macOS will launch it from a temporary read-only
    copy and the network extension won't be able to install.
  2. Launch it from Applications. The first launch shows the usual "downloaded
    from the Internet" prompt — click Open.
  3. macOS will ask you to allow a system extension — approve it in
    System Settings → General → Login Items & Extensions → Network Extensions.
  4. Approve the VPN configuration prompt.

The system extension is what does the work: traffic is handled by our own engine
running as a NetworkExtension provider rather than being shuttled through a
userspace helper.

Protocols

All 36 supported configurations were validated end-to-end on this exact build by
driving a real Chrome window against three live sites (video, a DNS leak check,
and news) and confirming egress identity and DNS resolution on each — not
synthetic probes.

VMess, VLESS, Trojan, Shadowsocks, ShadowsocksR, Snell, Hysteria2, TUIC,
WireGuard, AmneziaWG, OpenConnect, SOCKS5 and HTTP, across TCP, TLS, WebSocket,
HTTP/2, gRPC, HTTPUpgrade, mKCP, QUIC and XHTTP transports, plus REALITY,
ShadowTLS v3, Cloak, kcptun and gost.

Verify the download

shasum -a 256 RocketProxy-1.4.dmg
7149fe18cb578f66eca301e0d6aca3ee840d51b16352e60949781d779b626784

You can confirm Apple notarization yourself once installed:

spctl -a -vv "/Applications/Rocket Proxy.app"

Free, and not crippled

This edition is fully functional: every one of the 36 protocol configurations
above, no account, no registration, no time limit, no ads, and no telemetry.
It is the same engine that ships in the paid apps.

Premium high-speed servers, and the iPhone, iPad and Apple TV versions, are on
the App Store:

https://apps.apple.com/app/id6785291194