All notable changes to this project are documented in this file.
- Added strict support for provider-supplied
pcs/pinnedPeerCertSha256certificate pins andvcn/verifyPeerCertByNameverification names. - Added structured netmon installation, daemon and backend states so helper availability is reported accurately.
- Added sanitized Copy diagnostics, Copy latest error, profile-validation error copy, helper-diagnostics copy and UTF-8 diagnostics report saving.
- Migrated legacy VLESS
allowInsecureimports to normal secure certificate verification with a compatibility warning; the application never fabricates certificate pins. - AppImage now identifies that per-application attribution requires a separately installed helper, while normal proxy operation remains independent of netmon.
- The placeholder netmon backend is accurately labelled non-operational and returns no fabricated application counters.
- Reworked diagnostics actions into an accessible, responsive layout and added category-aware latest-error tracking so successful recovery clears the corresponding stale error.
- Stopped generating the Xray-core 26.3.27-removed
allowInsecurefield and invalidated stale validation state when the generated schema or selected Xray identity changes. - Corrected installed-but-inactive netmon helpers being reported as not installed.
- Corrected Debian helper lifecycle and extracted-artifact verification gaps without enabling or initially starting the opt-in service.
- Closed diagnostic and error-copy privacy gaps by sanitizing sensitive values before display, clipboard placement, report saving and ordinary logging.
- Kept normal TLS certificate verification enabled when migrating legacy profiles; insecure verification bypass and boolean-to-pin conversion are not supported.
- Sanitized Xray, helper and runtime errors through a shared privacy boundary while preserving useful technical context.
- Restricted the optional helper to a dedicated locked account, a group-only Unix socket and a capability-free systemd sandbox while its production eBPF backend remains deferred.
- Enabled privacy redaction by default for diagnostics shown in the UI, copied to the clipboard, saved to disk or written to application logs.
- Prepared a corrective release from the current default branch using the guarded manual release workflow.
- Advanced the canonical application and package version so corrected artifacts can be built and verified without reusing or moving the existing v0.2.2 tag.
- Added a canonical Xray release manifest, verification-only vendor checks, offline GUI self-test, and extracted AppImage/Debian artifact verification.
- Source startup bootstraps the pinned official Xray release unless
V2LINK_SKIP_XRAY_FETCH=1. - All Xray child commands now use a clean host environment with
XRAY_LOCATION_ASSETderived from the selected executable. - Official release artifacts currently target x86-64; ARM64 source discovery remains supported pending native package CI.
- Prevented source discovery from selecting an executable for the wrong CPU architecture.
- Made Xray acquisition checksum-first, retrying, version-validated, and staged so a failed refresh cannot leave a partial vendor directory.
- Added a bounded traffic-storage worker for recurring sample writes, retention cleanup, and session finalisation outside the GUI thread.
- Added bounded aggregate and downsampled query paths for long-session Traffic Monitor views.
- Live stats callbacks now update in-memory counters and labels only; History, Applications, Profiles, and Diagnostics refresh independently when needed.
- Xray Stats API polling now permits at most one in-flight stats-query child and ignores late results from invalidated generations.
- Traffic history sections cache unchanged results, completed session details are reused, and proxy drift reconciliation runs in the background audit worker.
- Hardened application shutdown into an ordered, idempotent flow that stops timers, invalidates late callbacks, persists final counters, finalises the active session, restores session-owned proxy state, and drains storage within bounded waits.
- GUI-owned Xray and temporary stats-query children now run in private process groups and are reaped with bounded TERM-to-KILL escalation without targeting unrelated system Xray or
v2link-netmon.service. - Detailed-sample retention and cleanup now preserve daily, session, and profile summaries while safely reusing SQLite connections.
- Xray access logging is disabled by default,
xray_stdout.logis bounded to 2 MiB with two backups, and detailed bounded diagnostics are opt-in.
- Automatic traffic charts use peak-preserving downsampling and never query or render more than 900 points.
- Long-session history tables avoid full sample scans and reuse unchanged results.
- Recurring stats-query logging and live refresh work are reduced to keep CPU, memory, database, and log growth bounded during long sessions.
- Added cached performance diagnostics for polling, callbacks, storage, refreshes, chart bounds, database/WAL sizes, aggregate counts, owned PIDs, proxy backend, and netmon state without exposing private profile data.
- Added
scripts/diagnose_runtime_performance.sh, a read-only, non-root inspection tool for process, resource, database, log, and service state.
- Added long-session regression coverage for the Traffic Monitor hot path, bounded storage, retention, connection reuse, charts, process ownership, Stats API polling, and repeated shutdown.
- Added packaging-script, logging, diagnostics, Xray configuration, and bundled-Xray locator regression coverage.
- Documented source development, bounded Traffic Monitor operations, runtime performance troubleshooting, logging limits, diagnostics privacy, and lifecycle ownership rules.
- Added a Traffic Monitor backed by local SQLite storage for proxy/session/profile upload and download history.
- Added daily usage aggregation, profile usage totals, CSV export support, and a lightweight in-app daily usage chart.
- Added session-level Traffic Monitor history with date drill-down, session detail panels, speed/cumulative sample charts, and session status reporting for completed, active, crashed, or unknown sessions.
- Added CSV export modes for daily summaries, session summaries, and selected session samples.
- Added traffic diagnostics for the SQLite DB path/access, active proxy session ID, stats API configuration, last stats query, and last traffic-store error.
- Added per-application tracking readiness: app traffic tables, data classes, disabled/mock
v2link-netmonclient abstraction, Applications tab, settings, and diagnostics. - Added the optional
v2link-netmonRust helper scaffold with Unix socket JSON API, process identity resolver, SQLite app-usage schema, systemd service packaging, and graceful eBPF-unavailable diagnostics.
- Added persistent proxy/profile traffic history.
- Added daily and monthly usage summaries.
- Added a Traffic Monitor dashboard with Overview, Applications, Proxy Profiles, History, Settings, and Diagnostics tabs.
- Improved the History tab with range controls, summary cards, stacked daily download/upload bars, daily rows, per-date sessions, and selected-session sample charts.
- Added optional per-application tracking preparation and
v2link-netmonhelper integration. - Added privacy-focused local-only storage and clear helper/root separation.
- Added diagnostics for Xray stats, the traffic database, app-tracking helper state, and kernel/eBPF support.
- Traffic history is local only at
$XDG_DATA_HOME/v2link-client/traffic.sqlite3(or the platform default data directory). - Per-application tracking remains advanced/optional; the GUI does not run as root, and the helper reports unavailable when eBPF support or permissions are insufficient.
- This phase tracks proxy/profile usage via Xray Stats API and prepares for, but does not yet provide, full per-application attribution.
- Packaged builds now launch host-system tools such as
gsettingsandxraywith a sanitized native environment, so Debian-installed sessions no longer inherit PyInstaller runtime library/plugin paths into child processes. - Diagnostics now report runtime packaging mode, executable path, clean-host subprocess mode, exact
gsettingscommand details, and the proxied HTTP/HTTPS probe result used for health reporting. - Runtime builds now bundle and apply the shipped application icon so source runs, AppImage, and Debian packages share the same launcher/window icon.
- Debian-installed runs now preserve system-proxy snapshot creation/restore and GNOME proxy application under packaged execution, matching source-run behavior more closely.
- Xray validation, startup, and traffic-stat commands now use the same clean host subprocess environment as GNOME/system integration calls.
- Replaced the placeholder package icon with the provided application artwork.
- GitHub release update checks in-app (
Check for Updates…) with release asset detection for AppImage and.deb. - Runtime system-proxy drift auditing and auto-reapply flow during active sessions.
- Snapshot ownership metadata for safer system-proxy restore behavior across concurrent/stale sessions.
- Saved-profile validation persistence metadata (
validated,validated_at,validation_fingerprint) with backward-compatible profile loading.
- Main window Help section now includes dedicated
Check UpdatesandAboutbuttons while preserving existing Help menu actions. - About dialog metadata was refreshed with current version, repository URL, and current feature highlights.
- Release tooling now resolves version from
pyproject.tomlby default and exports a single build version to all packaging steps. - GitHub release workflow now verifies pushed tag version matches
pyproject.tomlbefore building artifacts.
- Saved profile validation now survives restart when connection-defining profile data is unchanged.
- Validation invalidation now only occurs when connection data changes; metadata edits (for example, profile name/notes) no longer force revalidation.
- Long validation/status hints no longer force horizontal window growth; hint area remains width-stable with wrapping and tooltip fallback.
- Hardened GNOME System Proxy lifecycle by adding runtime drift audits/reconciliation while Xray is running, so proxy mode/host/port are auto-corrected on mismatch instead of relying on one-time startup apply.
- Added session ownership metadata to system proxy snapshots and ownership-aware restore paths to avoid false restore/no-proxy actions from non-owning sessions, while keeping crash recovery.
- Improved diagnostics to report proxy backend, desired vs actual GNOME proxy state, local HTTP/SOCKS listener reachability, recent Xray traffic signal, last auto-reapply reason/time, and backend warning signals from
gsettings/Gio stderr.
- Saved Profiles for VPN URLs, including support for multiple stored share links.
- Default profile auto-load on startup.
- Profile Manager dialog with add, edit, delete, duplicate, favorite toggle, and set-default actions.
- Validate & Save flow now handles existing URL matches with update-or-save-new choices.
- URL saving UX now prompts for profile details and supports in-dialog validation.
- Profiles are persisted at
$XDG_CONFIG_HOME/v2link-client/profiles.json(fallback:~/.config/v2link-client/profiles.json). - Profile writes are atomic (
temp file + os.replace) and use user-only permissions (0600on Linux/posix).