Exclave
com.github.dyhkwong.sagernet
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
First release: Feb 11, 2026, 26 total releases.
Most recent release: Sep 6, 2026.
Appears in 0 app stacks.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 6, 2026 0.17.56- Fix VMess and VLESS UUID parsing. For manually-created TUIC or Juicity config, only hex-and-dash format UUID will be accepted now. - Fix h2mux in sing-mux. - Other fixes and improvements.
- Aug 26, 2026 0.17.55- Update Go to 1.27. - Fix traffic statistics for QUIC-related protocols. This release was created manually due to a [GitHub Actions service outage](https://www.githubstatus.com/incidents/y1t7p9fzrlj2).
- Aug 22, 2026 0.17.53- Fix REALITY mldsa65Verify crash. Compiled with Go 1.26.7. This version is a continuation of 0.17.52 rather than 0.17.53-beta.0.
- Aug 20, 2026 0.17.52- Fix TUIC and Juicity broken since 0.17.48. - Workaround 32-bit legacy build crash on Android 5.0 and 5.1.
- Aug 16, 2026 0.17.51- Fix ListPreference title truncated when the text is long. - Fix XHTTP RandConfig crash when `from > to`. - Optimize JSON preprocessing (by @123jjck).
- Aug 15, 2026 0.17.50Fix the import and export of VLESS with encryption and vision and "transport" enabled.
- Aug 14, 2026 0.17.48**Compared to 0.17.47-beta.4:** - Fix Hysteria 2 Chrome parrot not working with mutual TLS or certificate pinning. **Compared to 0.17.47:** - Split the release into default flavor (Android 6.0+) and legacy flavor (Android 5.0+, with some Gradle dependencies pinned to old versions). The legacy flavor is for old devices only and using it on new devices may lead to unexpected behaviors. [^1] - Implement ShadowQUIC in core and remove the previous experimental ShadowQUIC plugin. There is no plan to implement SunnyQUIC and Brutal, and they have been removed. [^2][^3] - Add experimental Snell v4 and Snell v6 support. (by [@Minis233](https://github.com/Minis233)</a>) - Add "Chrome parrot" for Hysteria 2. - Update mieru to 3.35.0 and add low entropy mode. - Third-party breaking change: XHTTP path. (https://github.com/XTLS/Xray-core/commit/1aabe7ea78eca88deedc234a3e668895fa9bc08c)
More…
- "ServerNameToVerify" is extended to other protocols. [^4] - "Pinned peer certificate SHA-256" supports pinning non-leaf certificate. If non-leaf certificates are matched, ServerName will be verified. [^5] [^1]: e.g. https://issuetracker.google.com/issues/519796838. The support for the legacy flavor is on a best-efforts basis and may be ended at any time. [^2]: If you use official ShadowQUIC as the server, you may need to disable `zero-rtt` otherwise connections may fail randomly. Related bug: spongebob888/shadowquic#191. [^3]: The client ALPN must match the server ALPN. For ShadowQUIC in Exclave, if no ALPN is specified, it defaults to no ALPN (rather than `h3`). However, for the official ShadowQUIC, if you don't specify the ALPN (`alpn: null`), it defaults to `h3`; specifying an empty array (`alpn: []`) as the ALPN means no ALPN. [^4]: This is solely for enhancing the interoperability of similar options (e.g. `name-cert-verify` and `verifyPeerCertByName`) in other software. [^5]: This is solely for enhancing the interoperability of similar options (e.g. `fingerprint` and `pinnedPeerCertSha256`) in other software. - Jul 6, 2026 0.17.46**Compared to 0.17.46-beta.3:** - Fix a vulnerability where TrustTunnel `ServerNameToVerify` does not verify the certificate when uTLS is used. (ExclaveNetwork/exclave-core@0b4abfb) - Fix balancer landing proxy and front proxy. (#433) - Fix system stack URL test when the server address is a domain name. **Compared to 0.17.45:** - Fix a vulnerability where TrustTunnel `ServerNameToVerify` does not verify the certificate when uTLS is used. (ExclaveNetwork/exclave-core@0b4abfb) - Fix balancer landing proxy and front proxy. (#433)
More…
- Fix system stack URL test when the server address is a domain name. - Update mieru to 3.34.0 and add padding traffic pattern. - Breaking change: Remove ShadowTLS and reverse proxy. - Bump target SDK to 37. [^1][^2][^3] - Fix system stack TCP NAT source port reuse. (SagerNet/sing-box#4224) - Workaround system stack TCP listener returns "invalid argument" on user switch. (#427) - Third-party breaking change: KCP share link. (XTLS/Xray-core@aba2272 and XTLS/Xray-core@ad2e4cb) - Third-party breaking change: XHTTP session ID. (XTLS/Xray-core@e10347b) [^1]: Android 17 blocks cross-profile loopback traffic for all apps, breaking cross-profile localhost proxy. Unfortunately, it seems there is no way to restore access completely. `INTERACT_ACROSS_USERS` permission is declared so that cross-profile loopback traffic access between Exclave (not applicable to cross-application) can be restored. This permission needs to be granted via ADB. (#430) [^2]: Android 17 blocks apps targeting Android 17 from accessing the LAN, unless `ACCESS_LOCAL_NETWORK` is granted. To restore access, you need to grant the "nearby devices" permission to the app. [^3]: System stack requires a TCP listener accepting incoming connections to private addresses and therefore requires the `ACCESS_LOCAL_NETWORK` permission on Android 17. You need to grant the "nearby devices" permission to the app to use system stack on Android 17. - Jun 13, 2026 0.17.45- Remove v2ray-plugin gRPC mode which does not exist in the official v2ray-plugin. If you need to use the standalone v2ray-plugin, use the v2ray-plugin released [here](https://github.com/ExclaveNetwork/v2ray-plugin-android/releases) instead of the official one. Using other v2ray-plugin forks is on your own. - Fix DNS over QUIC stuck on close.
- Jun 6, 2026 0.17.44- Fix uTLS incorrectly applied to TrustTunnel HTTP/3 mode.
- May 3, 2026 0.17.38- Fix Hysteria 2 port hopping interval. - Fix Hysteria 2 port hopping stuck on close.
- Apr 30, 2026 0.17.37- Replace SimpleMenuPreference with a custom DropDownPreference to resolve various display issues. - Fix Mux.Cool XUDP crash. - Skip Mux.Cool PacketAddr for domain name destination addresses.
- Apr 19, 2026 0.17.34Compared to 0.17.31-beta.1: - Revert the polluted French translation. - Update mieru to 3.31.0. This is a breaking change of the mieru protocol. Old versions of this app will not be able to connect to a server with the updated mieru protocol enforced. - Fix TLS-based protocols unable to connect if SNI is not filled. - Routing rule import and export include package name rules.
- Apr 3, 2026 0.17.30- Fix WireGuard crashes on close.
- Apr 2, 2026 0.17.29- Minor fixes for proxy chain, balancer, front proxy and landing proxy. - Fix XHTTP browser dialer crash.
- Mar 31, 2026 0.17.28- Update Hysteria 2 and add minimum/maximum port hopping interval, BBR profile and "reno" congestion control. - Fix a potential issue that causes TUIC and Juicity stuck on close (by sing-quic). - Update uTLS to the latest commit to avoid outdated fingerprints and add FireFox 148 and Safari 26.3 fingerprints. You may need to disable X25519MLKEM768 for some REALITY profiles. - Update mieru.
- Mar 24, 2026 0.17.27- Fix subscription auto-update stuck on background. - If proxy is not connected, "update all subscriptions" now ignores subscriptions with "update only when connected" enabled.
- Mar 12, 2026 0.17.24- Fix some WireGuard issues. - v2ray-core 5.47.0 changes. - XHTTP changes (XTLS/Xray-core@0ac13bd).
- Mar 7, 2026 0.17.23This release is for updating and testing F-Droid build procedure only. - Found a hack to achieve reproducible build with the stock gomobile and replace gomobile with the stock one.
- Mar 6, 2026 0.17.22- Fix HTTP/1.1 proxy unable to connect to Caddy forwardproxy. [^1] - Fix XHTTP browser dialer unable to connect to non-default port. [^2] - Fix `quic+local://` DNS crash. - Update mieru and add traffic pattern support. [^3] - Enable "interrupt reused connections when network changes" for all users. [^4] [^1]: This dates back to [five years ago](https://github.com/v2fly/v2ray-core/commit/5e99737#diff-095ec0417d653a64d489b665c111c9822390cb1070ce6237bb9fa036bd9f77b2R172). [^2]: This dates back to [one year ago](https://github.com/XTLS/Xray-core/commit/a2b7731#diff-816fed1f7702ac9856d2e5e7ddfe8e92d1189edfafdc411756faf741387c97ddR269). [^3]: Unfortunately this field is a Base64-encoded protobuf message. Please refer to [mieru's documentation](https://github.com/enfein/mieru/blob/v3.28.0/docs/traffic-pattern.md#viewing-and-exporting) for instructions on how to generate it. This field is considered experimental and unstable and the configuration format may change in the future. [^4]: Disable this option will cause protocols that reuse connections stuck when network changes. It is not recommended to disable this option. This option may be enforced and removed in the future.
- Feb 22, 2026 0.17.21- Fix a bug causing battery consumption introduced in 0.17.20.
- Feb 21, 2026 0.17.20- Fix bugs introduced in 0.17.19. 0.17.19 is considered retracted. - Merge v2ray-core 5.46.0 changes except for WireGuard. In the future, the v2ray-core fork used by Exclave may become a dedicated project with its own name and no longer strictly follow the codebase of v2ray-core.
- Feb 19, 2026 0.17.19Compared to 0.17.14 and 0.17.15-beta.1: - Refactor ECH. This is a breaking change for some users. If ECH is enabled but not ECH config is provided, direct DNS will be used to query HTTPS record for ECH config. If ECH config is not found, connection will fail. - Merge the changes from v2ray-core 5.45.0 and 5.45.1. - Fix "interrupt reused connections when network changes" for some protocols. - Add support for [TrustTunnel deep link](https://github.com/TrustTunnel/TrustTunnel/blob/8856e7ba83ae0c9faace78aaf9a95b1b291cd3ed/DEEP_LINK.md). Compared to 0.17.15-beta.1: - Downgrade Go to 1.25. Go 1.26 causes the app to crash on startup on armeabi-v7a or x86 devices with Android version between 8 and 10.
- Feb 16, 2026 0.17.17Compared to 0.17.14 and 0.17.15-beta.1: - Refactor ECH. This is a breaking change for some users. If ECH is enabled but not ECH config is provided, direct DNS will be used to query HTTPS record for ECH config. If ECH config is not found, connection will fail. - Merge the changes from v2ray-core 5.45.0 and 5.45.1. - Fix "interrupt reused connections when network changes" for some protocols. Compared to 0.17.15-beta.1: - Downgrade Go to 1.25. Go 1.26 causes the app to crash on startup on armeabi-v7a or x86 devices with Android version between 8 and 10.
- Feb 16, 2026 0.17.16Compared to 0.17.14 and 0.17.15-beta.1: - Refactor ECH. This is a breaking change for some users. If ECH is enabled but not ECH config is provided, direct DNS will be used to query HTTPS record for ECH config. If ECH config is not found, connection will fail. - Merge the changes from v2ray-core 5.45.0 and 5.45.1. - Fix "interrupt reused connections when network changes" for some protocols. Compared to 0.17.15-beta.1: - Downgrade Go to 1.25. Go 1.26 causes the app to crash on startup on armeabi-v7a or x86 devices with Android version between 8 and 10.
- - Update Go 1.26.0. - Fix "bulkBarrierPreWrite: unaligned arguments" (#51) by updating Go 1.26.0. Notable Go 1.26 changes: - The hybrid `SecP256r1MLKEM768` and `SecP384r1MLKEM1024` post-quantum key exchanges are added to TLS. - Malformed URLs containing colons in the host subcomponent (such as `http://::1/` or `http://localhost:80:80/`) are now rejected by the URL parser. URLs containing bracketed IPv6 addresses, such as `http://[::1]/` are still accepted.