Repository navigation
Releases: meow-rs/meow-ios
Release list
v1.6.0 (build 2026082201)
meow-rs 0.21.0 + tunnel reliability
Build 2026082201. Engine pin moved from the ios/connect-timeout-0.20.1 side branch to meow-rs v0.21.0.
Engine
- Multiplexing: sing-mux, yamux, h2mux, Mux.Cool
- Fake-IP lookup/store race fixes, atomic UDP NAT claim
- REALITY pre-auth cap and h2 write-path recovery
- Desktop-exported configs with absolute rule-/proxy-provider paths now start on iOS (
prepare_ios_configcontainment rewrite) dns.proxy-server-nameserveris honoured viaResolverHostHook::new_with_proxy_resolver
Tunnel (since 1.5.0)
- Hung DIRECT connects time out in 10s
- TCP waits for the app's first payload before opening a proxy connection (no phantom sessions from port probes)
- One SOCKS5 UDP ASSOCIATE per app source port, so P2P/BitTorrent swarms no longer starve HTTPS
TestFlight: build 2026082201 is uploaded and processing.
v1.3.0 — RSS reductions + stress test harness
Highlights
Memory footprint — NE 50 MiB jetsam cap
A 10-minute VM stress run loading common CN sites surfaced an 8.8× over-cap peak (440 MiB) in the FFI under burst arrival of new TCP flows. This release lands surgical fixes that bring peak under load down to 107 MiB in the same harness (−76%), and exposes a runtime knob so the value can be retuned on-device.
- TCP accept-side cap (default 128, semaphore-bounded). Bounds the number of in-flight
dispatch_tcptasks, which is the dominant factor in burst-time RSS because each carries per-flow Metadata + Box + mihomo outbound dial state + netstack ring buffers. - Per-UDP-session reply buffer 64 KiB → 4 KiB. iOS TUN MTU is 1500 — the 64 KiB sizing covered theoretical max UDP but pinned 64 KiB per concurrent session for its idle lifetime.
- Sweep windows tightened to iOS timescales — TCP idle 90 → 30 s, sweep 30 → 10 s, registry-size watchdog 3600 s/1024 → 60 s/256.
- Per-TCP-accept log line moved INFO → trace; under burst the formatter + oslog writer was non-trivial overhead.
- New FFI exports for the Swift side:
meow_tun_set_accept_cap(int)/meow_tun_accept_cap()— runtime tuning, takes effect on nextmeow_tun_start.meow_resident_bytes()— same mach RSS field jetsam uses; lets PacketTunnel chart its own curve without depending on Instruments.
Stress test infrastructure
core/rust/mihomo-ios-ffi/tests/stress_rss.rs— hermetic cargo integration test (start/stop cycle leak guard + sustained ingest burst).macos-utun-harnessextended with--rss-monitor-interval-secs(periodic sampler) and--stress-target/--stress-conns/--stress-hold-ms/--stress-duration-secsflags for real-flow churn against an existing utun + engine.
Open finding
Under sustained load the new caps successfully bound the peak, but RSS still climbs roughly +0.14 MiB/s through the run — attributed to mihomo internals (resolver cache, NAT entries, rule stats) downstream of the FFI surface. Tracked for follow-up profiling via Instruments / DHAT.
TestFlight
Build 2026051501 was uploaded to App Store Connect and is processing.
Install
meow-ios.ipa attached for Ad Hoc install (release-testing method, signed with the team's distribution profile). Install via:
xcrun devicectl device install app --device <udid> meow-ios.ipa
🤖 Generated with Claude Code
v1.2.1 (build 2026051301)
TestFlight build 2026051301.
What's new
- CN IP-range bypass for fake-IP DNS. For every A / AAAA query the PacketTunnel now consults the engine resolver first (500 ms budget) and, if the upstream answer falls inside an offline-built CN address-range table (APNIC delegated stats — 4,109 v4 intervals + 2,009 v6 intervals shipped in the bundle), the synthesized answer is the real IP. Those connections take mihomo's DIRECT outbound instead of being routed through a proxy via a 28.x.x.x fake address. Non-CN hosts and timeouts fall through to the unchanged fake-IP path.
- Pinned DNS upstream. The engine now uses a fixed nameserver set —
119.29.29.29(DNSPod),223.5.5.5(AliDNS),1.1.1.1(Cloudflare) — regardless of what the subscription'sdns:block contains. User-supplieddns:blocks are stripped before load. - tun2socks: real-IP flows skip the fake-IP reverse-lookup. TCP and UDP dispatch now CIDR-gate the pool mutex. Flows whose destination falls inside the fake-IP CIDR but has no live pool entry (LRU-evicted or TTL-expired) are dropped instead of being routed as a literal 28.x.x.x — the client re-resolves.
- Developer tooling:
core/rust/macos-utun-harness. Standalone Rust binary (meow-utun) that wires the same FFI surface the iOS PacketTunnelProvider drives into a real macOSutundevice. End-to-end packet path against the engine + fake-IP DNS + CN-bypass + tun2socks without needing an iPhone.
Known limitations
- In-TUN TCP/53 traffic is dropped (iOS stub resolver only falls back to TCP/53 for >512 B UDP replies, which fake-IP never produces).
- UDP-to-remote works, but the outbound must support UDP relay server-side. SS / Trojan / VLESS all do when enabled.
Install
The attached meow-ios-1.2.1-adhoc.ipa is an Ad Hoc build for sideloading onto registered test devices. Members of the TestFlight group will get build 2026051301 automatically.
v1.1.6 (build 2026050101)
Build: 2026050101 — Ad Hoc
Highlights since v1.1.4
Memory / stability
- tun2socks: cap burst TCP at 512, idle-evict flows past the soft cap
- Reverted mimalloc global allocator
- Cap TCP/UDP/DoH bursts to avoid NE memory jetsam
- smoltcp window-underflow patch + Rust panic logging
- Bump tokio worker threads from 1 to 2
- Removed soft-cap engine restart at 40 MB footprint
DNS / DoH
- Switch DoH → plain TCP DNS, drive upstreams from Settings
- Split-horizon DNS via trust-china-dns logic
- Persist DoH answer cache in redb across PacketTunnel restarts
- DoH single-flight + h2 pool + reconnect on failure
NE / connectivity
- Auto-reconnect engine on network change
UI
- T4.13: move proxy groups into pushed subview
Distribution
- Firebase Analytics + dual-channel install tracking
- TestFlight upload script
Install (Ad Hoc)
Device UDID must be on the Ad Hoc provisioning profile. Drag the IPA onto a connected device via Finder / Apple Configurator.
v1.1.3 (build 2026042404)
Fixes
-
Network Extension actually starts on AltStore / SideStore sideloads.
VpnManager.configureIfNeededwas settingproto.providerBundleIdentifier = "io.github.madeye.meow.PacketTunnel"verbatim. Re-signers rewrite the extension's bundle id (prepend the installer's team prefix, or swap it outright), so the stored NE configuration pointed at an appex that no longer existed on disk — iOS had nothing to launch,startVPNTunnel()silently snapped back to.disconnected, and the tunnel never came up. Same failure shape as the 1.1.1 / 1.1.2 app-group bug, one layer further down the NE stack.1.1.3 discovers the real PacketTunnel bundle id at runtime by scanning
Bundle.main.builtInPlugInsURLfor*.appexentries whoseNSExtensionPointIdentifieriscom.apple.networkextension.packet-tunnel. App Store builds keep falling through to the authoredio.github.madeye.meow.PacketTunnelconstant.
Install
AltStore / SideStore
Source: https://madeye.github.io/meow-ios/source.json
Existing AltStore installs should pick up 1.1.3 automatically on the next source refresh.
Manual
Download the IPA below and install via your preferred sideloader.
Caveats (unchanged)
Requires a paid Apple Developer account — the PacketTunnel extension uses the Network Extension entitlement, which free Apple IDs cannot sign.
v1.1.2 (build 2026042403)
Fixes
- Actually fix the AltStore / SideStore sideload crash. 1.1.1 tried to resolve the app-group identifier from the embedded provisioning profile, but
String(data:encoding:.ascii)returnednilon the CMS/PKCS7 signature bytes (≥ 0x80) — soresolveIdentifier()silently fell back to the hard-codedauthoredIdentifierand re-signed builds still crashed at launch with "App Group container unavailable". 1.1.2 decodes as.isoLatin1(lossless over 0x00–0xFF), and the embedded plist substring round-trip is safe. SeeMeowShared/Sources/MeowModels/AppGroup.swift.
Install
AltStore / SideStore
Source: https://madeye.github.io/meow-ios/source.json
Manual
Download the IPA below and install via your preferred sideloader.
Caveats (unchanged)
Requires a paid Apple Developer account — the PacketTunnel extension uses the Network Extension entitlement, which free Apple IDs cannot sign.
v1.1.1 (build 2026042402)
Fixes
- Instant crash on AltStore / SideStore sideload. The hard-coded `group.io.github.madeye.meow` lookup in `AppGroup.swift` and `MWAppGroup.m` failed when re-signers rewrote the app-group entitlement with their own team prefix. Now the identifier is resolved at runtime from the embedded provisioning profile, so sideloaders work and App Store builds still hit the authored constant.
Install
AltStore / SideStore
Source: https://madeye.github.io/meow-ios/source.json
Manual
Download the IPA below and install via your preferred sideloader.
Caveats (unchanged)
Requires a paid Apple Developer account — the PacketTunnel extension uses the Network Extension entitlement, which free Apple IDs cannot sign.
v1.1.0 (build 2026042401)
Changes
- Jetsam / memory-growth fix in PacketTunnel (Rust→ObjC rewrite, single tokio worker)
- On-demand VPN enabled, disconnectOnSleep=false for NE reliability
- AppIcon alpha flattened for TestFlight compatibility
- Lower tracing filter + raised tokio worker count
- Build tooling improvements
Install via AltStore / SideStore
Add the source: https://madeye.github.io/meow-ios/source.json
Requires a paid Apple Developer account — free Apple IDs cannot sign the bundled Network Extension.
Artifacts
- `meow-ios-1.1.0-b2026042401-adhoc.ipa` — Ad Hoc IPA for AltStore / SideStore sideloading (min iOS 17.0)
v1.0.0 build 2026041901 (Ad Hoc)
First Ad Hoc distribution build. Corresponds to TestFlight build `2026041901` (in ASC processing).
Install
The attached `.ipa` is signed Ad Hoc against the team `SK4GFF6AHN`. Two paths:
-
Registered devices — if your UDID is in the embedded Ad Hoc provisioning profile (currently Max's iPhone 16 + iPhone 16), install directly via:
```bash
xcrun devicectl device install app --device meow-ios-1.0.0-b2026041901-adhoc.ipa
``` -
Re-sign with your own Apple Developer account via AltStore / Sideloadly / similar. The `packet-tunnel-provider` entitlement survives re-signing as long as your Apple ID has a paid Developer Program membership.
What's in this build
- `fix(ffi): enable mihomo-config default features (ss, trojan, vless, vless-vision)` — resolves the "only Final and Direct proxy groups visible" regression when the subscription uses Shadowsocks. (#67)
- `fix(ffi): strip listener keys via serde_yaml::Value` — preserves `tun:`, `profile:`, `experimental:`, etc. through the FFI load path. (#68)
- `feat(app): DailyTrafficAccumulator` — TrafficView history (today/this-month totals + 7-day chart) now populates. (#69)
- `perf(ffi) + feat(vpn)` — tracing filter TRACE → INFO, tokio workers 2 → 4, on-demand auto-reconnect so iOS extension reclaims recover invisibly. (#70)
- `fix(icon): flatten AppIcon alpha` — App Store Connect 90717. (#71)
Known
- iOS may still reclaim the NE under heavy media playback (Rednote shorts, video streaming). With on-demand enabled the tunnel re-establishes in ~5s without the VPN toggle showing Disconnected.
- First-connect after install prompts for VPN configuration approval — expected.