• v0.9.2 5e7164c42f

    0.9.2
    All checks were successful
    ci / test (pull_request) Successful in 22s
    ci / test (push) Successful in 24s
    Stable

    mysticalsoap released this 2026-08-28 15:32:48 -04:00 | 26 commits to trunk since this release

    Signed by mysticalsoap
    SSH key fingerprint: SHA256:9YDy/JqlZ87+NCp7H32yS1SJq0eXYhL0fFILx8wQn7g

    Scope: ProtonVPN accounts and WireGuard tunnels. Supported providers
    are Airvpn, Mullvad, ProtonVPN and Windscribe; PIA and AzireVPN are
    dropped (#134). The cli is repaired and supported again (#132).
    Doublehop is broken and out of scope for this release (#179);
    WireGuard carries the main tunnel only -- hop and bypass connections
    stay OpenVPN (#176).

    • [new] ProtonVPN account import: SRP sign-in with 2FA, a browser-opened verification page when Proton demands one, and a persisted session so renewals never re-prompt (#33, #150, #147)
    • [new] WireGuard tunnels, plumbed with wg/ip directly instead of wg-quick, so aqomui stays the only routing manager and bypass keeps working (#152)
    • [new] provider auto-updates run on a schedule in the service, with no gui around (#142)
    • [new] cli selection modes on connect: --random, --random-favourite, --profile (#123)
    • [new] a cleared fallback DNS field means deliberate single-server, so resolved has nowhere to strand a failover (#167)
    • [change] providers are their own package: one module per provider, base configs in code instead of shipped templates, one supported-provider table
    • [change] Mullvad import is WireGuard-only -- Mullvad retired OpenVPN server-side
    • [change] the alternative DNS servers outrank whatever a tunnel config carries, on WireGuard too
    • [change] gui and cli run through one server catalog and one connect/reconnect decision (#123)
    • [change] the pre-fork legacy config layout is dropped (#54)
    • [bugfix] the cli's broken-since-fork commands work again: connect, enable/disable, alt-dns (#132)
    • [bugfix] a WireGuard teardown announces itself, so the gui cannot keep showing a dead connection
    • [bugfix] failed imports surface as a dialog, not a toast the desktop can swallow (#141)
    • [bugfix] imports resolve hostnames with the firewall up, and take their firewall exceptions back down on failure too (#158)
    • [bugfix] deleting a provider persists the protocol table (#139)
    • [bugfix] the bypass comes back after a reboot (#168)
    • [bugfix] no ipv6 bypass route is written on networks without an ipv6 gateway (#160)
    • [bugfix] Proton API sessions pin the plain transport: no DoH discovery against hardcoded public resolvers from the root service (#164)
    • [bugfix] the DNS watchdog backs off when re-pins never stick, instead of flushing caches forever (#166)
    • [bugfix] expected startup states and expected rule misses stopped logging as errors and warnings (#161, #162)
    Downloads
  • v0.9.1 d6a8a1f6ae

    0.9.1
    All checks were successful
    ci / test (pull_request) Successful in 29s
    ci / test (push) Successful in 28s
    Stable

    mysticalsoap released this 2026-08-23 02:38:08 -04:00 | 76 commits to trunk since this release

    Signed by mysticalsoap
    SSH key fingerprint: SHA256:9YDy/JqlZ87+NCp7H32yS1SJq0eXYhL0fFILx8wQn7g

    Scope: unchanged from 0.9.0. The cli has not been tested since the fork
    and is unsupported for now (#132).

    • [new] listed bypass apps are wrapped at launch, so starts from menus, launchers, terminals and autostart all land in bypass (#67)
    • [new] already-running listed apps are swept into bypass at activation (#113)
    • [new] bypass covers forwarded source networks (#116)
    • [change] the service watches the network and reacts itself, so tunnels and bypass recover with no gui running (#111)
    • [change] the service derives routes and the bypass owner itself instead of trusting gui registration (#89)
    • [change] bypass DNS follows the physical network's resolvers, so bypassed apps resolve as if the VPN were off (#60)
    • [change] connection state is read from OpenVPN's management interface; the tunnel device is set in the config, not parsed from the log
    • [change] provider import takes the config files picked, not their whole directory
    • [change] closing the window minimizes to the tray, without asking
    • [change] DNS option labels describe what the options actually do
    • [change] CI runs against a pinned Arch snapshot with a package cache (#115)
    • [bugfix] a leftover bypass cgroup is reconciled at service startup instead of silently sending bypassed apps through the tunnel (#113)
    • [bugfix] bypass over a VPN server works again
    • [bugfix] bypass routes and rules are applied idempotently; stale ones are swept at startup
    • [bugfix] systemd-resolved is steered back to the primary DNS server once it answers again, instead of sticking to the fallback forever (#95)
    • [bugfix] no system-wide DNS writes under systemd-resolved
    • [bugfix] the tray icon turns off when the tunnel dies on its own
    • [bugfix] one bad .desktop file no longer truncates the bypass app list
    • [bugfix] the gui recovers its service connection when the service restarts
    • [bugfix] the connection-timeout watchdog works again
    Downloads
  • v0.9.0 3d895111a3

    0.9.0
    All checks were successful
    ci / test (push) Successful in 26s
    Stable

    mysticalsoap released this 2026-08-19 11:54:24 -04:00 | 132 commits to trunk since this release

    Signed by mysticalsoap
    SSH key fingerprint: SHA256:9YDy/JqlZ87+NCp7H32yS1SJq0eXYhL0fFILx8wQn7g

    The first aqomui release. Forked from qomui via samicrusader's fork; the headline change is app split-tunneling ported from cgroup v1 net_cls to cgroup v2, plus a security pass on the D-Bus service (polkit authorization, server-side input validation, self-updater removed).

    Scope: this release supports Arch Linux and manually imported OpenVPN/WireGuard configs. Provider auto-downloads are inherited but unverified (#32) and ProtonVPN's is known broken (#33).

    See CHANGELOG.md for the full entry.

    Install (Arch): build from packaging/arch/PKGBUILD with makepkg -si.

    Downloads