Two important fixes on top of v1.0-build45.
-
In-app Logs falls back to per-process os_log when SharedLogger
silently no-ops (commit 77f3c03)Github issues #7 (sideloaded IPA build 35) and #8 (TestFlight
build 37 on iOS 26.3.1) reported empty stats AND empty Logs UI
simultaneously. The latter is the meta-problem: when the
App Group container is unreachable to the main app, SharedLogger
silently returns "" from every readLogs() call, leaving the
in-app Logs view blank with no way for affected users to share
diagnostics.Every log line ALSO goes to os_log via the C bridge (Go side)
and direct os_log() / NSLog (Swift side), so the data is there
in each process's in-memory ring buffer — just not visible in-app.New OSLogReader (shared between targets) wraps OSLogStore. The
extension answers a new "get_logs" providerMessage with its own
ring buffer; the main app concatenates with its own and shows a
banner "App Group container unavailable — showing os_log fallback"
when SharedLogger is empty. Even when App Group is broken end-to-
end, users can now see and share their logs. -
Active post-wake probe gated on serverProbeable (commit 94e09de)
The active probe path that fires on iOS wake() events would
unconditionally kill conns after 30s of waiting for an echo —
regardless of whether the server actually echoes pings. With a
non-patched server (no PR #168 server-probe-echo capability),
every wake event past the throttle window mass-killed all conns
even though they were healthy. Demonstrated in vpn.wifi.6.log
2026-05-06 21:52:21: 50 conns killed at once on a stable wifi
no-movement session, sentSeq=113-119 per conn, 0 echos received
in 70 minutes.The timer-based zombie killer at proxy.go:1821 already gates on
serverProbeable.Load() — without echos, no kills. The active
post-wake probe was missing the same gate. Now mirrored: with
non-echoing server the probe is skipped (no kills, also no fast
recovery — just the regular tick path); with echoing server,
identical behaviour to before.Backward compatible: identical to build 45 on patched servers,
strictly better on unpatched ones.
Both fixes complement each other: the os_log fallback gives bug
reporters something to share when in-app logs are empty, and the
active-probe gate prevents the spurious mass-kills that the empty-
log users probably also experienced (just couldn't see).
WRAP layer unchanged from build 45. WRAP toggle still default off.