github GeorgeXie2333/usque-app v0.2.8

2 hours ago

Usque v0.2.8 official release / Usque v0.2.8 正式版发布

Usque v0.2.8 is a feature and reliability release that adds custom OpenVPN, WireGuard, and WARP via WireGuard chain exits, and improves cross-platform recovery and release packaging.

Usque v0.2.8 是一个功能与可靠性版本,新增自定义 OpenVPN、WireGuard 和 WARP via WireGuard 链式出口,并改进跨平台恢复与发布打包。

Highlights / 更新亮点 ✨

  • Custom OpenVPN and WireGuard exits — Import files in batches with validation and filename-based names, or paste a configuration in Proxy → Chain proxy. Use the selected exit for VPN, SOCKS5 and HTTP traffic over WARP. An OpenVPN configuration can list up to 16 servers to try while connecting.

    自定义 OpenVPN 与 WireGuard 出口 — 在“代理 → 链式代理”中批量导入文件并校验、以文件名命名,或粘贴配置。所选出口通过 WARP 承载 VPN、SOCKS5 和 HTTP 流量。OpenVPN 配置最多可列出 16 个服务器,建立连接时依次尝试。
  • WARP via WireGuard exit — Generate a separate WARP WireGuard configuration or import one, manually edit its endpoint, and connect with bounded retries that stop on success, cancellation or a terminal failure.

    WARP via WireGuard 出口 — 生成独立的 WARP WireGuard 配置或导入已有配置,手动编辑端点,并通过有界重试建立连接;成功、取消或终止性失败后停止重试。
  • One page for every chain exit — OpenVPN, WireGuard, WARP via WireGuard and VPN Gate share one page with the current connection and an apply bar. Home shows WARP → exit name; clearer form feedback, focus handling and terminology carry across all 21 languages.

    统一的链式出口页面 — OpenVPN、WireGuard、WARP via WireGuard 和 VPN Gate 共用同一页面,显示当前连接并提供应用栏。首页显示“WARP → 出口名称”,并在全部 21 种语言中改进表单反馈、焦点处理和术语一致性。
  • Optional Disable QUIC — Block UDP/443 through the proxy or tunnel from Settings → Advanced network settings → Routing & protection. GEO direct traffic and Usque's own HTTP/3 connection are unaffected, and the change applies without reconnecting.

    可选的禁用 QUIC — 在“设置 → 高级网络设置 → 路由与保护”中拦截经代理或隧道转发的 UDP/443。GEO 直连和 Usque 自身的 HTTP/3 连接不受影响,应用后无需重连。
  • Reconnection after network changes — On Android and in Windows VPN mode, an established connection waits while the device is offline and reconnects once a usable network returns. Android rebuilds the chain after physical-network changes; stalled HTTP/2 connections end within a bounded time so recovery can start.

    网络变化后重新连接 — 在 Android 和 Windows VPN 模式下,已建立的连接会在设备离线时等待,并在可用网络恢复后重新连接。Android 在物理网络变化后重建链路;停滞的 HTTP/2 连接会在限定时间内结束,以便开始恢复。
  • Release packaging improvements — Release APKs compress native libraries, unused icon font variants are removed, and matching Dart debug symbols are archived separately from installable packages. Download size is not installed disk usage.

    发布打包改进 — Release APK 压缩原生库、移除未使用的图标字体变体,并将匹配的 Dart 调试符号独立归档而不放入安装包。下载体积不等于安装后的磁盘占用。

Download / 下载 📥

Important

Download packages only from this release. Do not install Pull Request artifacts, local builds, or files redistributed elsewhere.

请仅从此 Release 下载软件包。不要安装 Pull Request 产物、本地构建或其他渠道转载的文件。

OS / 系统 Requirements / 版本要求 Direct links / 点击直链下载
Android
Android
Android 8.0+ (API 26)
Compatible with Android TV
支持 Android TV
APK ARMv8 (arm64-v8a) APK x64 (x86_64)
APK ARMv7 (armeabi-v7a) APK Universal
Windows
Windows
Windows 10 22H2+ (build 19045)
Build 19045 or later
内部版本 19045 或更高
EXE x64-v2 EXE ARM64

For Windows, use the linked installer EXE. The similarly named MSI assets are
reserved for Usque's verified in-app update flow.

Windows 请下载上方的 EXE 安装程序。名称相近的 MSI 文件仅供应用内更新使用。

Package selection and installation guide / 软件包选择与安装指南

Use the package matching your device architecture. The universal APK contains all three Android ABIs and is larger; use it only when the device ABI is unknown.

请优先下载与设备架构匹配的软件包。Universal APK 包含三种 Android ABI,文件更大,仅在无法确定设备架构时使用。

For complete installation, upgrade, and uninstall guidance, see the installation guide.

完整的安装、升级和卸载说明请参阅安装指南。

Before upgrading / 升级须知

Upgrade behavior and compatibility / 升级行为与兼容性
  • The chain proxy is off by default. An existing VPN Gate choice carries over to the VPN Gate source. Select and apply one exit to use it. A terminal exit failure disconnects the whole chain; there is no automatic WARP-only fallback. On Android, enable system Always-on VPN and Block connections without VPN if apps must stay blocked after the VPN ends. Your explicit direct rules still apply.

    链式代理默认关闭。 已有的 VPN Gate 选择会保留为 VPN Gate 来源。选择并应用一个出口后才会使用。出口无法继续连接时,整条链路都会断开,不会自动退回仅使用 WARP。Android 用户若需要在 VPN 结束后继续阻止应用联网,请开启系统的“始终开启的 VPN”和“阻止未使用 VPN 的连接”。手动设置的直连规则仍然生效。
  • UDP-based exits require non-L4 mode. OpenVPN over UDP, WireGuard and WARP via WireGuard cannot be enabled with experimental L4; the page prompts you to switch to non-L4 mode and apply.

    基于 UDP 的出口需要非 L4 模式。 OpenVPN UDP、WireGuard 和 WARP via WireGuard 不能在实验性 L4 下启用,页面会提示切换为非 L4 模式并应用。
  • The Windows virtual adapter can remain after disconnecting. Usque restores the connection's network settings at disconnect, keeps the adapter for reuse, and attempts to remove it when you fully exit the app. Windows may take time to complete removal, which can affect an immediate restart.

    Windows 断开连接后可能仍显示虚拟网卡。 Usque 会恢复该连接修改的网络设置,保留网卡供下次连接复用,完全退出应用后再尝试移除。Windows 完成删除可能需要时间,因此立即重启应用仍可能受影响。
  • Default connection settings are unchanged. CONNECT-IP with Auto and CUBIC remain the defaults, and Disable QUIC is off. L4 and BBRv3 are experimental; keep that in mind when choosing them. New installations turn on Allow local network; existing saved settings keep their value.

    默认连接设置保持不变。 默认仍使用 CONNECT-IP、Auto 和 CUBIC,“禁用 QUIC”默认关闭。L4 与 BBRv3 仍为实验性选项,请按需选择。新安装默认开启“允许访问局域网”;已保存的设置保持原值。
Technical changes / 技术改动详情
  • Every chain exit connects through WARP, negotiates and authenticates, applies its final network configuration, and only then admits traffic. Exit endpoint names resolve inside WARP and protocol UDP uses WARP's private network stack, so Usque opens no physical socket to the exit server. OpenVPN moves to its next listed server only after DNS, dial, transport-close or timeout failures, within a 120-second candidate budget; authentication, certificate and configuration errors stop immediately. WireGuard accepts one peer and enforces partial AllowedIPs in both directions. With H3, UDP-based exits cap TCP MSS for the nested encapsulation.

    所有链式出口都先经 WARP 连接、完成协商与认证并应用最终网络配置,之后才接收流量。出口服务器域名在 WARP 内解析,协议 UDP 使用 WARP 私有网络栈,Usque 不会为出口服务器打开物理网络套接字。OpenVPN 仅在 DNS、拨号、传输关闭或超时失败时尝试下一个服务器,候选阶段总计最多 120 秒;认证、证书和配置错误会立即停止。WireGuard 支持单个 Peer,并在收发两个方向执行部分 AllowedIPs。使用 H3 时,基于 UDP 的出口会按嵌套封装开销限制 TCP MSS。
  • Imported configurations are encrypted per record with current-user DPAPI on Windows and Android Keystore AES-256-GCM on Android, and are shared by all accounts on the device. WARP via WireGuard registers a separate identity through MASQUE and never converts the outer identity. Generation status is process-local; saved configurations and endpoint overrides remain encrypted. After MASQUE starts, WireGuard attempt limits are 3, 4, 5, 5, 5 and 5 seconds. Each failed session is cleaned up before another attempt; cancellation and the overall deadline still apply. Exhaustion stops the chain without a WARP-only fallback. Custom WireGuard exits retain their existing retry behavior.

    导入的配置逐条加密保存:Windows 使用当前用户 DPAPI,Android 使用 Android Keystore AES-256-GCM,并由设备上的所有账号共用。WARP via WireGuard 经 MASQUE 注册独立身份,不会转换外层身份。生成状态仅保留在当前进程,已保存配置与端点覆盖仍加密保存。MASQUE 建立后,WireGuard 各次尝试的时限依次为 3、4、5、5、5、5 秒。每次失败会话清理后才开始下一次,取消与总截止时间仍然有效;尝试耗尽会停止整条链路,不会回退为仅使用 WARP。自定义 WireGuard 出口保留原有重试行为。
  • Final-exit DNS starts with UDP, adds an alternative after 250 ms, uses TCP when needed, and shares a four-second deadline per question. Remote DNS never falls back to physical DNS. Disable QUIC matches UDP destination port 443 after GEO direct routing and updates a running connection without reconnecting.

    最终出口的 DNS 查询先使用 UDP,250 ms 后启用备用候选,必要时改用 TCP,每个问题共用 4 秒期限。远端 DNS 不会回退到物理 DNS。“禁用 QUIC”在 GEO 直连判断之后按 UDP 目标端口 443 匹配,可在连接中更新而无需重连。
  • Established CONNECT-IP sessions stop automatic reconnection after authentication, identity, configuration, address-assignment and socket-protection failures. Ordinary network failures keep bounded backoff; Android and Windows VPN network observations pause attempts while the device is confirmed offline and start one shortly after a usable network appears. An HTTP/2 PING without a reply ends the session after a 15 to 30 second final deadline.

    已建立的 CONNECT-IP 会话遇到认证、身份、配置、地址分配或套接字保护失败时,停止自动重连。普通网络故障保留有上限的退避重试;Android 和 Windows VPN 的网络观测在确认设备离线时暂停尝试,并在出现可用网络后很快发起连接。HTTP/2 PING 长时间无回复时,会在 15 到 30 秒的最终期限后结束会话。
  • Configuration schema is 18: schema 16 adds Disable QUIC, schema 17 moves the VPN Gate switch into the chain exit setting, and schema 18 adds the optional WARP via WireGuard endpoint override. Agent protocol remains 3, the recovery journal remains schema 3, and sanitized recovery exports remain schema 2. IPC fields are appended only. Sensitive identity and configuration data are excluded from diagnostic exports.

    配置 schema 为 18:schema 16 新增“禁用 QUIC”,schema 17 将 VPN Gate 开关迁移到链式出口设置,schema 18 新增 WARP via WireGuard 可选端点覆盖。Agent 协议仍为 3,恢复日志仍为 schema 3,脱敏恢复导出仍为 schema 2。IPC 字段仅追加。诊断导出排除敏感身份与配置数据。
  • The multilingual Windows EXE installers introduced in v0.2.6 remain the user-facing packages; signed MSIs remain reserved for verified in-app updates. The newer-Agent-first upgrade bridge introduced in v0.2.5 remains in place for v0.2.4 upgrades. Release APKs compress native libraries, which Android extracts at installation, and Dart symbols are kept outside the installable packages. Dependency maintenance includes reviewed Rust, Flutter and Actions updates. No measured performance improvement or real-machine upgrade result is claimed.

    v0.2.6 引入的多语言 Windows EXE 安装程序仍为用户安装入口;签名 MSI 仍仅供经过验证的应用内更新。v0.2.5 引入的新版 Agent 优先安装机制继续为 v0.2.4 升级提供兼容桥接。Release APK 压缩原生库,Android 会在安装时解压;Dart 符号不放入安装包。依赖维护包含经审查的 Rust、Flutter 和 Actions 更新。不宣称已测得性能提升或已完成真实机器升级验证。
DNS privacy, chain exits and L4 behavior / DNS 隐私、链式出口与 L4 行为

DNS privacy / DNS 隐私

GeoSite-matched direct-country queries use the selected direct DNS mode. System (the default) exposes them to the physical DNS provider; DoH or DoT exposes them to the configured encrypted resolver using numeric bootstrap and strict TLS, with no plaintext fallback. Other remote queries use the final tunnel's DNS: WARP, or the selected chain exit (OpenVPN, WireGuard, WARP via WireGuard, or VPN Gate) when the chain proxy is enabled. A WireGuard exit prefers the DNS servers in its configuration. Explicit local/direct DNS choices remain in effect. Apps using their own encrypted DNS hide domains from Usque, so routing falls back to GeoIP classification.

与 GeoSite 匹配的直连国家规则查询会使用所选直连 DNS 模式。System(默认)会将查询发送给当前网络使用的 DNS 服务器。DoH 或 DoT 使用填写的 IP 地址连接加密 DNS 服务器,并校验其 TLS 身份;失败时不改用明文 DNS。其他远端查询使用最终隧道的 DNS:通常为 WARP,启用链式代理后则为所选出口(OpenVPN、WireGuard、WARP via WireGuard 或 VPN Gate)。WireGuard 出口优先使用其配置中的 DNS 服务器。显式本地或直连 DNS 选择仍然生效。应用自行使用加密 DNS 时,Usque 无法获知域名,路由会回退至 GeoIP 分类。

With the chain proxy enabled, the WARP provider carries the exit connection and the selected exit server provides final egress; its operator can observe traffic leaving that tunnel subject to application encryption. VPN Gate directory services also learn directory requests, and VPN Gate exits are public volunteer servers. Existing Geo, CIDR, LAN, system-proxy bypass and Android application exceptions retain their direct behavior. Public node scores and TCP observations are not local end-to-end measurements or promises of availability. No automatic telemetry or diagnostic upload is added. See the chain proxy guide and the VPN Gate guide for the complete boundaries.

启用链式代理后,WARP 提供商承载出口连接,所选出口服务器提供最终出口,其运营方可以看到从该出口发出的流量,但 HTTPS 等应用层加密仍保护其加密内容。VPN Gate 目录服务还可见目录请求,VPN Gate 出口为公共志愿服务器。已有 Geo、CIDR、LAN、系统代理绕过及 Android 应用例外保留直连行为。公共节点评分与 TCP 观测不是本地端到端测量,也不保证可用性。不新增自动遥测或诊断上传。完整边界请参阅链式代理指南和 VPN Gate 指南。

Without a chain exit, experimental L4 remains TCP-only: valid tunneled UDP/53 queries are converted to TCP DNS and preserve the application-selected resolver IP. EdgeResolved for L4 SOCKS5/HTTP sends hostnames to the CONNECT edge without a local lookup; it cannot recover names from TUN IP traffic. An OpenVPN-over-TCP exit, either a custom OpenVPN TCP configuration or a VPN Gate node, can carry application UDP as IP packets inside its OpenVPN TCP connection. Neither mode silently converts failed proxied traffic into direct traffic.

未启用链式出口时,实验性 L4 仍仅支持 TCP:有效的隧道 UDP/53 查询转换为 TCP DNS,并保留应用指定的解析器 IP。L4 SOCKS5/HTTP 的 EdgeResolved 会将域名发送至 CONNECT 边缘节点而不进行本地查询,不能从 TUN IP 流量还原域名。基于 OpenVPN TCP 的出口(自定义 OpenVPN TCP 配置或 VPN Gate 节点)可将应用的 UDP 流量作为 IP 数据包承载于其 OpenVPN TCP 连接。两种模式都不会静默将失败的代理流量转为直连。

Verify before installing / 安装前验证 🔐

Signature checks and release evidence / 签名校验与发布验证材料
  1. Compare the package SHA-256 with both SHA256SUMS and the digest displayed by GitHub.

    将软件包 SHA-256 同时与 SHA256SUMS 及 GitHub 显示的摘要进行比对。
  2. Verify that the package signer matches the fingerprint below. The installation guide has commands and expected fields.

    确认软件包签名者与下方指纹一致。具体命令和需要比较的字段见安装指南。
  3. Stop if the filename, hash, signature, architecture, or version differs.

    如文件名、哈希、签名、架构或版本有任何不一致,请停止安装。
  • Windows Authenticode certificate SHA-256 / Windows Authenticode 证书 SHA-256: 12cecd1302aba36bdd920c86b1541e2dab34a7f5a0e13a990345bb8bc6777f9d
  • Android release certificate SHA-256 / Android Release 证书 SHA-256: 087cce9ace990b160204908a44c3e73808c5567685cf1b9cf0ae3ad033f9901a

[!NOTE]
Before v1.0, Windows packages use a fixed self-signed identity and may show an unknown-publisher warning. Android packages use a fixed project-controlled certificate and are not distributed through Google Play.

v1.0 之前的 Windows 软件包使用固定的自签名身份,系统可能显示“未知发布者”警告。Android 软件包使用由项目管理的固定证书,且不通过 Google Play 分发。

Release evidence: manifest · SHA-256 checksums · per-package SPDX SBOMs attached to this release

发布验证材料:清单 · SHA-256 校验和 · 此 Release 附带的逐包 SPDX SBOM

Feedback / 问题反馈 💬

Reporting guidelines and links / 反馈指南与入口

Detailed, reproducible reports are prioritized. Include the exact version, platform, expected result, actual result, and minimal reproduction steps. Remove credentials, tokens, device identifiers, endpoint pins, and personal addresses from logs and attachments.

信息完整且可复现的报告会被优先处理。请提供准确版本、平台、预期结果、实际结果和最小复现步骤,并从日志与附件中移除凭据、令牌、设备标识符、端点 Pin 和个人地址。

Don't miss a new usque-app release

NewReleases is sending notifications on new releases.