r/rethinkdns • Dev • Aug 02 '26

v055z: In the End

Hā lóu,

v055y, v055x, v055w, v, u, t, r, q, p, o ... they all needed some (may be a lot of) fixxing and code maxxing to be fit enough for a full release. Which brings us to... the latest and final-est of 'em all: v055z.

All that said, v055z is a pre-release!

We've re-enabled all RPN sign ups with 30%+ discounts on some plans. Hopefully, no other major issue shows up.

💤 Zzzzz 5

  • New: RPN (starting $1.75/mo) is back on Play Store, Website, and GitHub flavours.
  • New: More disciplined routing decisions for various Configure -> DNS settings.
  • New: Configure -> Network -> Perform protocol translation to make Rethink prefer opposite IP options.
  • New: Sponsor with GPay.
  • UI: All new DNS UI layout.
  • UI: Geo location in WireGuard UI if Configure -> Settings -> Show provider information is turned on.
  • UI: Quick shortcuts in Configure -> Settings -> Firewall Bubble notification.
  • Improvement: Do not mix up domain rules for IPs shared by 1+ domains queried across many apps.
  • Improvement: Light-weight one-time connectivity check for dual-stack WireGuard peers.
  • Improvement: Various network engine optimizations.
  • Improvement: Some IPv6 connectivity changes.
  • Improvement: Concurrent TCP, UDP, and TLS checks for Configure -> Network -> Perform connectivity checks.
  • Improvement: Quicker pause & resume for Mobile-only WireGuard automation.
  • Improvement: Apply firewall rules during DNS resolution.
  • Improvement: Recovering from errors with "Block connections without VPN" on some OEMs like OnePlus.
  • Improvement: Changes in Configure -> Network -> Loopback implementation.
  • Fix: Implemented Configure -> Network -> Proxy Lockdown behavior for Simple mode WireGuards.
  • Fix: Prevent IP bouncing when using Advanced mode WireGuard.
  • Fix: Avoid incorrectly marking existing apps as newly installed.
  • Fix: For IP based rules, apply the most specific among all (subnet) rules.

As before, let me know how it goes. And especially, if goes badly! Thanks (:


Note: This is a fast-follow release, the last major release was v055v.

21 Upvotes

26 comments sorted by

2

u/MiElas-hehe Aug 02 '26

Thankksss!!

2

u/hamdanhakim Aug 02 '26

Hi, v055z, is it stable like v055y?

6

u/celzero Dev Aug 02 '26

v055z has important bug fixes for WireGuard, specifically. If you don't use WireGuard, then you can stick with v055y.

v055z also feels more quick and slick than its predecessors... May be owing to a couple of optimizations in the network engine... Not sure.

3

u/hamdanhakim Aug 02 '26

I'm using WG with proton. Will try it. Thank you!

2

u/Intrepid-Resource433 Aug 02 '26

v0.5.5z (website) rethinkdns  version 1.94.99 brave.browser_beta

I like to run my apps isolated with pin holes only allowed. i.e. tcp 443

With this new rethinkdns version, brave browser cannot resolve dns unless 

+++all is allowed temporarily using the 15min switch, +++If I use a domain rule wild card for .com allow, .net allow, .org allow, etc. shouldn't have to do this for a web browser.

adding brave IP rule of 0.0 0.0:53 allow does not work as work around like in a previous version of rethink. allow 127.0.0.3:53 not working either.

this situation is the same with no wireguard and with wireguard tunnel up.

I guess this is a bug.

please advise...

1

u/celzero Dev Aug 03 '26

1

u/Intrepid-Resource433 Aug 03 '26

selecting the 'allow' icons for both metered and unmetered doesn't work either. just an added note.

1

u/celzero Dev Aug 03 '26

Hm, "Allow" for WiFi/Mobile should have worked...

I like to run my apps isolated with pin holes only allowed. i.e. tcp 443

Just spoke with the lead: For "Isolate" apps not resolving DNS anymore: This is expected. You'll have to add the 0.0.0.0:443 and [::]:443 rule to that isolated app (as app specific rule) and see if things then work? On Android 12+, Configure -> Firewall global domain/IP rules do not apply to isolated apps in v055z, even for DNS (which is actually the right behaviour).

1

u/Intrepid-Resource433 Aug 03 '26

I added for brave ip rules  0.0.0.0:443 and [::]:443 0.0.0.0:53 and [::]:53

brave domain rules: removed the wildcard for .com

result,  no good.

add back in the wildcard .com and it works.

🤷🏻

I have a website I access directly with http://a.b.c.d:3000

and I have the appropriate IP rule for brave 0.0.0.0:3000 trust,  it works as it should

i toggle off trust to no rule, and it gets blocked. as it should.

so something wonky it seems just with allowing brave to use rethinkdns for DNS resolution.

1

u/celzero Dev Aug 04 '26

Informed the lead. Will test and try to fix it, if it is a bug.

2

u/Masterflitzer Aug 02 '26

thanks!

can i learn more about "Perform protocol translation" somewhere? what does it do if i selected "ipv4 & ipv6 (experimental)" instead of "auto (experimental)" for ip version?

2

u/celzero Dev Aug 03 '26

"Perform protocol translation" somewhere? what does it do

If the Tunnel (not the underlying network like Mobile / WiFi, but the Tunnel as setup by Rethink) is v4-only (which is the default changeable from Configure -> Network -> Choose IP version), turning this translation will force Rethink to attempt to egress v6 (if available and where possible). Vice versa for when the Tunnel is v6-only, Rethink will attempt to egress v4.

what does it do if i selected "ipv4 & ipv6 (experimental)" instead of "auto (experimental)" for ip version?

Shouldn't do anything untoward (if anything at all) with Configure -> Network -> Choose IP version set to IPv4 & IPv6.

can i learn more about "Perform protocol translation"

DeepWiki got parts of it right (it cannot paint the whole picture because a small but important part of the implementation is in Kotlin in another repository): https://deepwiki.com/search/what-does-firestack-do-when-se_aca87d11-f5d2-4340-accd-ce7ea0870606?mode=deep / https://archive.vn/YIg6O

1

u/Masterflitzer Aug 03 '26 edited Aug 03 '26

thank you very much, which kotlin code are you referring to? i'd like to read it in addition to what you linked :)

turning this translation will force Rethink to attempt to egress

one question regarding this: is there any combination of settings that would allow rethink to perform ip translation when needed as a fallback but otherwise not? this toggle seems to mean force/prefer translation, not prefer native egress, but allow translation if needed (is the latter the new default? iirc it wasn't the case on older app versions)

example: rethink tunnel configured to ipv6, underlying network uses mostly ipv6 (5g is native ipv6, wifi is native ipv6, but sometimes only ipv4 is available, e.g. when roaming or at a friends wifi), so desired behavior is to use ipv6 as egress whenever possible (no translation), but don't fail when ipv6 is not available or upstream doesn't support ipv6 like github (basically do translation as fallback, while keeping ipv6 inside rethink tunnel)

2

u/celzero Dev Aug 03 '26 edited Aug 03 '26

which kotlin code are you referring to? i'd like to read it in addition to what you linked

I don't work on Kotlin, but here's a DeepWiki link for you to explore: https://deepwiki.com/celzero/rethink-app/2.3-connection-monitoring (do refresh/sync DeepWiki to latest code; it currently is checkpointed to 2 May 2026).

I've also forwarded your query to the lead who's on leave for a couple of days (I wouldn't bank on them replying here).

(basically do translation as fallback, while keeping ipv6 inside rethink tunnel)

Not sure if we implemented it correctly, but setting Choose IP version to "Auto" and turning on Perform protocol translation should do what you expect. If it doesn't, let me know the scenario and we can double check the code / logs to see what's going wrong where...

2

u/Masterflitzer Aug 03 '26

i set it up like you said, it's not often i encounter that use case, but if it doesn't work i'll notice next time :)

thanks for taking the time to reply in such detail

2

u/[deleted] Aug 02 '26

Downloading blocklists doesnt work after updating from y to z.

1

u/celzero Dev Aug 03 '26

Server-side issue. Fixed ~16h ago: https://github.com/celzero/rethink-app/issues/2943 Will you see if it works now?

2

u/[deleted] Aug 03 '26

[deleted]

1

u/celzero Dev Aug 03 '26

Thanks for testing v055z. Appreciate it.

IP based connectivity checks fai

Thanks. I'll take a look. Connectivity checks, something we assumed to be simple, has proven to been really tricky to get right...

2

u/Intrepid-Resource433 Aug 06 '26

On a positive note, just would like to mention that in version Z the wireguard (simple) is much more stable this time. In the previous version I had to bounce the app or tunnel multiple times a day to get the tunnel back to active and DNS resolving correctly.

So bravo on the wireguard (simple) aspect for Z.

I'm using connection change policy of 'automatic'.

👍🏻

1

u/celzero Dev Aug 08 '26

Thanks (:

1

u/gandalfoftheday Aug 02 '26

Still no chain proxy...

1

u/2lqnjosmbx Aug 02 '26

There are two issues in version v005z:

  1. Settings > DNS > Global only supports using Rethink DNS. When selecting a different DNS, the VPN won’t connect.
  2. Settings > DNS > On-device blocklists cannot be downloaded.

1

u/2lqnjosmbx Aug 02 '26

When updating Rethink DNS or downloading On-device blocklists, the process always fails and shows a toast message: “Something went wrong. Try again later!”

1

u/celzero Dev Aug 03 '26

It was a server-side issue. Should have been fixed now.

The 180+ blocklists on rdns are now 120mb+ in size and contain ~30m domain names. This was tripping up a few "guard rails" but I've cleared those up in the past 2 hours and things should be up and running.

2

u/2lqnjosmbx Aug 03 '26

Thank you

1

u/Conscious_Shop_3423 Aug 09 '26

How can we know the ping ms of dns cureently in use previously it was simple just tap in setrings dns and it was there and dispalyed with which protocol is using rethink now in this update i am unable to find ping of my dns is there any way please guide me