Skip to content

Releases: vampywiz17/os-usque

os-usque 0.2_21

Choose a tag to compare

@vampywiz17 vampywiz17 released this 14 Aug 13:40

Plugin-only logging fix. Supervised tunnel processes now receive the standard NO_COLOR=1 environment setting, preventing tracing-subscriber ANSI terminal escape sequences from entering the OPNsense syslog view. Log content and timestamps remain unchanged; usque-rs-bsd was not modified.

The bundled usque-nativetun-0.8.3.pkg is byte-identical to the package from v0.2.20.

SHA256 (os-usque-0.2_21.pkg) = 25efb11be2dc6abb71b84fc0cf9702d30f348a32f92197798fab9d08ec37e1e1
SHA256 (usque-nativetun-0.8.3.pkg) = 85c13e1dc9666bf02d4419353195da40383fb1395992a90445d44723d6f9920f

os-usque 0.2_20

Choose a tag to compare

@vampywiz17 vampywiz17 released this 14 Aug 13:13

Adds OPNsense-native tunnel logging under VPN > usque > Log File, using the standard local3 VPN syslog facility and OPNsense-managed local log rotation. Updates the pinned usque-nativetun 0.8.3 source to include periodic observational QUIC path diagnostics. The tunnel protocol behavior is unchanged.

SHA256 (os-usque-0.2_20.pkg) = 63ff54e508ec9b3f5b31ef14b2b04d88a2825614412b4014846b2e42a75bef42
SHA256 (usque-nativetun-0.8.3.pkg) = 85c13e1dc9666bf02d4419353195da40383fb1395992a90445d44723d6f9920f

os-usque 0.2_19

Choose a tag to compare

@vampywiz17 vampywiz17 released this 09 Aug 01:37

Updates the bundled usque-nativetun port to upstream 0.8.3 at main merge commit a5d87348d86c66cd90d8cc0b838d8dac6871e824. Existing registrations with a known different client version now perform one existing-key registration refresh at process startup, persist the version only after Cloudflare accepts it, and retry on a later start without blocking tunnel operation if the refresh fails. Existing egress client, Mesh node, browser-assisted, legacy, and Access service-token enrollment behavior is preserved. Validation: 38 plugin unit tests, PHP syntax checks, full FreeBSD optimized release build, stage-qa, check-plist, package builds, and package metadata checks.

os-usque 0.2_18

Choose a tag to compare

@vampywiz17 vampywiz17 released this 08 Aug 23:02

Updates the bundled usque-nativetun port to upstream 0.8.2. The running binary version is now reported in Cloudflare request headers and truthful device telemetry instead of retaining an older registration-time client version. Existing egress client, Mesh node, legacy enrollment, and Access service-token enrollment behavior is preserved. Validation: 38 plugin unit tests, FreeBSD stage-qa, check-plist, release build, and package metadata checks.

os-usque 0.2_17

Choose a tag to compare

@vampywiz17 vampywiz17 released this 08 Aug 21:45

Adds a selectable Cloudflare Access service-token enrollment method for egress clients while preserving browser-assisted egress and Mesh registration. The new flow accepts organization, Access Client ID, and Access Client Secret, uses a one-time owner-only handoff and MDM file, and does not persist the service-token credentials in config.xml. The native port is pinned to the reviewed usque-rs-bsd 0.8.1 Access-enrollment commit and includes quick-xml. Validated with 38 enrollment tests, OPNsense plugin packaging, and FreeBSD stage-qa/check-plist.

os-usque 0.2_16

Choose a tag to compare

@vampywiz17 vampywiz17 released this 03 Aug 13:06

The tunnel editor now displays Mesh return-route controls only for ingress Mesh node instances. The controls are hidden for egress clients and update immediately when the Role field changes. Hidden values remain preserved, and backend routing behavior is unchanged. Includes the unchanged usque-nativetun 0.8.1 package.

os-usque 0.2_15

Choose a tag to compare

@vampywiz17 vampywiz17 released this 03 Aug 11:43

Fixes OPNsense template reload after upgrading an existing installation. Legacy tunnel rows do not yet contain the new Mesh return-route fields; the runtime template now applies OPNsense-native default filters for enablement and both default CIDRs. Mesh routing behavior is otherwise unchanged. Includes the unchanged usque-nativetun 0.8.1 package.

os-usque 0.2_14

Choose a tag to compare

@vampywiz17 vampywiz17 released this 03 Aug 11:34

Configurable per-instance Mesh return-route management. Existing and new Mesh nodes default to enabled Cloudflare Device IP return routes (100.96.0.0/12 and 2606:4700:cf1:1000::/64); administrators can disable management, replace either CIDR, or omit one address family. CIDRs are strictly validated before native FreeBSD route(8) operations, and cleanup remains limited to plugin-owned routes. Egress client behavior is unchanged. Includes the unchanged usque-nativetun 0.8.1 package.

os-usque 0.2_13

Choose a tag to compare

@vampywiz17 vampywiz17 released this 01 Aug 23:30

Updates the packaged native tunnel engine to usque-nativetun 0.8.1, including the upstream CONNECT-IP stream-closure recovery fix. Includes os-usque 0.2_13 for OPNsense 26.7 / FreeBSD 15 amd64.

os-usque 0.2_12

Choose a tag to compare

@vampywiz17 vampywiz17 released this 01 Aug 11:44

Updates the packaged native tunnel engine to usque-nativetun 0.8.0. Includes os-usque 0.2_12 for OPNsense 26.7 / FreeBSD 15 amd64.