The exit-node build of this tree (-tags exitnode, reproducible: -trimpath, -buildvcs=false, -buildid=) pinned by SHA-256 for linux amd64, arm64 and arm; the changelog section becomes 0.2.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
5.6 KiB
Changelog
All notable changes to the OpenFlux core. Format loosely follows Keep a Changelog.
[0.2.0] - 2026-09-28
Every client now behaves alike: peers of different builds and modes find
each other instead of dropping every packet in silence. The node wizard
(desktop and Android) installs this core as node-v1.1.0.
Added
- Classic compatibility inside the Session (
PROTOCOL_NEGOTIATION.md): a classic setup with a key (--transport=X, the apps' classic profiles) runs a Session and speaks classic to an exit that does not answer the handshake, switching once it does; a classic-configured exit serves classic and Session clients.--negotiatestays strict; exits configured as a Session (wizard,.conf,--transports) serve Session clients only. - Codec fallback: the classic codec decodes batch-v2 and legacy frames,
sends what the peer sends, and the client tries the other framing when
the peer is silent.
--codecis a preference now, not a requirement. - KDF context fallback: one rule for the context (
transport.KDFContexts) and alternates for what other builds derive; a record that fails under the current keys is tried under them, the exit answers under the client's context, a silent client cycles through them. mobile/ios: the iOS C library (build_ios.sh) on packagemobile, replacing the rootexport_ios*.go: the calls the iOS app makes, plus Session profiles (OpenFluxShareDecodereturns one ready to start), mode and captcha calls. An app that links this core as a submodule gets the same Session, links and fallbacks as Android.mobile:ShareSessionSpecs,SetInitialCookies,SetLowMemory(Volga's newSlimVolgaConfigfor the iOS extension),ReadTimeout,ConnectionMode.- Links are read and made by the core only.
share.Read/share.Makeanswer every entry point with the same JSON (--parse-link, new--make-link,mobile.ReadShareLink/MakeShareLink, the iOSOpenFluxShareDecode/OpenFluxShareEncode): the configuration and its context, the link, or an errorcode(andparam) that the apps put in their own words.share.Makenormalizes what apps spell differently (the default codec is left out, an encrypted link always names its context, by the one rule when not given), so one configuration gives one link on every client; the node wizard's link, desktop and Android, comes from oneshare.NodeConfig. - Logs a user can act on without
-dd: key or context mismatch, the peer running the other layering, codec and context fallbacks, a second client taking over the exit, carriers failing to start, documents dropping, and a diagnosis when the handshake does not complete.
Fixed
- A classic cupsonline client given the rooms as
--urlderived another key than the exit that created them: nothing got through. - boards sent engine.io pings from the client, which an EIO=4 server answers by closing the socket: the board dropped every 20 seconds.
- A Session client's cupsonline carrier was built as an exit: with no or dead rooms it created rooms of its own and waited in them.
- openflux:// links: base64 padding, the standard alphabet, whitespace and line breaks are accepted; secrets are counted in characters as Kotlin counts them, not bytes.
- Carrier names that differ between the two sides no longer break cookie exchange and exit checks (messages carry the document URL).
- yandex / mailru: a socket whose keepalive failed is closed so the reconnect runs; writes are bounded.
utils.Infofreaches the apps' log screens.- A Session stopped each carrier twice.
[0.1.0] - 2026-09-27
First release from the current main line (encrypted-logging + the
maintainer's multi-transport work folded together) and the first cut by
release.yml instead of a manual build.
Added
mobile/: the Android/iOS gomobile bridge now lives in this repository (moved frommeepo161/openfluxfork, full history and authorship preserved), so building the mobile clients needs only this checkout..github/workflows/release.yml: av*tag cross-compiles the CLI for Linux (amd64/arm/arm64), Windows (386/amd64/arm64) and macOS (amd64/arm64) and publishes it withSHA256SUMS.txt. Replaces the ad-hoc manually-built0.0.xreleases.deploy/node-install.shnow downloads the exit-node core from this repository's ownnode-v*releases instead ofmeepo161/openfluxfork;provision/pin.go's pinned script commit/hash points here too.
Fixed
main.go: bench-send/bench-sink never resolved to the exit-side session role under--negotiate, so a negotiated session between two bench processes hung retrying the handshake and derived encryption keys in the same direction on both sides instead of swapped.main.go: the startup banner still printed the project's pre-rename name (=== Universal Bypass Tool ===) instead of=== OpenFlux ===..github/workflows/node-release.yml: the pinned Go version (1.26.8) had drifted fromgo.mod(1.26.4), so its "reproducible" build didn't actually reproduce the hashesdeploy/node-install.shexpects.
Credits
androidApp/desktopApp/shared for OpenFluxAndroid
and OpenFluxDesktop now
run the Compose Multiplatform app built by @meepo161
in OpenFluxClient, moved into
those repositories with his agreement.
[0.0.1] - [0.0.5]
Manually built and published cross-platform CLI binaries, before this CHANGELOG and the automated release workflow existed.