New Features
· Added Snell proxy protocol (v1–v5) with connection reuse pooling, obfs, and ShadowTLS; parses Clash (type: snell) and Surge configs
· Added SSH outbound proxy with password / private key authentication and host key verification
· Added SOCKS5 over TLS protocol
· Added gRPC (Gun) transport for VMess / VLESS, with faster downloads on high-latency links
· Added REALITY to Trojan, AnyTLS, and HTTPS with X25519MLKEM768 post-quantum key exchange; importable from share links and Clash subscriptions
· Added server certificate SHA-256 fingerprint pinning for Trojan, AnyTLS, HTTPS, Hysteria2, TUIC, and VMess (HTTP/2, TLS, WSS)
· All policy group types can now attach subscription URLs directly, mixing static and subscription proxies — no separate external group needed
· Added round-robin algorithm to load balance groups
· Added per-proxy IP version strategy (ip_version) for domain servers: dual stack, IPv4/IPv6 only, or IPv4/IPv6 preferred
· Added "Close Connections on Policy Change" option to close connections still on the old proxy when a group's selection changes
· Added listen-port rule for routing by local HTTP/SOCKS proxy port
· Added DNS over TCP upstreams via tcp://
· Added profile history: automatic snapshots before every edit, update, or overwrite, with preview and one-tap restore
· All-new Storage page with a full usage breakdown of caches, logs, traffic records, GeoIP databases, script data, and more
· Added notification history: every notification is recorded (even suppressed or auto-dismissed ones), viewable in Settings → Notifications
· Added connection deep links with live-refreshing detail
· Connection detail now shows IP info and the matched MITM rule and module
· Widgets can now render SVG vector graphics
· MITM CA certificates can now be installed on other devices
Improvements
· Smart groups now remember real-connection failures: proxies that test fine but don't work are deprioritized, and latency is re-tested right after failover
· Hysteria2 supports TCP Fast Open; AnyTLS can skip TLS certificate verification
· Requests now fail fast when there's no network (e.g. airplane mode) instead of retrying and draining the battery
· Scripts can make far more concurrent HTTP requests, lifting WebView's ~6-per-host connection limit
· Profile errors now point to the exact field and reason instead of an inaccurate line number
· Logs are searchable; DNS forwarding rule sets can be previewed as YAML/text; module icons can be customized via long-press
· Reused HTTP connections show policy, rule, and IP info; traffic now uses binary units (KiB/MiB)
Bug Fixes
· Fixed large uploads stalling on some proxy protocols, and connections not falling back to a working IP when a domain resolves to multiple IPs
· Fixed profile changes and manually updated resources not taking effect immediately
· Fixed DNS hijacking mistakenly capturing non-DNS UDP traffic (e.g. SNTP)
· Fixed logical rules (AND/OR/NOT) with unsupported sub-rules matching all traffic; they are now ignored entirely
· Fixed Hysteria2 skip-cert-verify not applying, occasional false failures in Hysteria2 / TUIC latency tests, and inflated HTTP proxy latency results
· Fixed VLESS encryption: none being dropped from Clash subscriptions, and VLESS / VMess links being misidentified
· Fixed bare keys dropped from INI #!arguments, and YAML module argument placeholders in numeric fields
· Fixed IPv6 availability not updating after switching networks
· Fixed inaccurate protocol, policy, and failed filters on the Connections page
· Fixed very large values (e.g. 999999999999999 for "never update") in interval/timeout fields being silently ignored or breaking YAML profile parsing
· Fixed Show IP Info bypassing proxy DNS for domain proxies, truncated latency labels, and blank space in the editor after backgrounding with the keyboard up