Hako

command module
v1.19.30-hako.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 3, 2026 License: GPL-3.0 Imports: 26 Imported by: 0

README

Hako

Hako

High-performance Adaptive Kernel — Open-source

English · 简体中文

Put a real proxy kernel inside your iOS or macOS app.

Hako packages the proven mihomo (Clash.Meta) proxy engine as Hako.xcframework — a small Swift / Objective-C framework you add to your app. It runs on Apple's official NetworkExtension API, so it's built to pass App Review: no vendored kernel sources, no private hacks. You build the app; Hako moves the traffic.

Use it to ship a Clash / mihomo-compatible VPN app for iPhone, iPad, and Mac. Hako is a fork of a stable mihomo release, tuned to live inside Apple's strict Network Extension limits on memory and battery.

Fast, and it doesn't fall over

iOS only lets a VPN app use about 50 MiB of memory before the system force-quits it (Apple calls this jetsam). Push real traffic through a careless proxy and it blows past that and crashes — a well-known pain point for proxy apps on iPhone and iPad. Hako is built to stay well under the line. Real numbers, all measured on a physical iPad Pro (M2):

  How much of Apple's 50 MiB memory limit Hako actually uses:

  Apple's hard limit (crash)     50.0 MiB  |####################|
  --------------------------------------------------------------
  Hako, 30-min stress test       38.5 MiB  |###############.....|  22% to spare
  Hako, heavy upload + slow peer 39.6 MiB  |################....|  21% to spare
                                           400 connections at once, still never crosses the line
  Real speed, through the tunnel  (iPad Pro M2, on the open internet):

    Speedtest (Ookla)        924 Mbps down  /  545 Mbps up   ping 5 ms
       ...and while doing that, the kernel used just 18.7 MiB of memory
       (of the 50 available). The WiFi / broadband line is the limit here,
       not Hako.

  A 30-minute non-stop stress run -- this is a release gate, not a demo:

    16.49 GB moved   0 disconnects   0 dropped packets   0 crashes   0 memory kills

Uploading hard while the other end reads slowly is the classic way to make an iOS VPN run out of memory and die. Hako slows itself down and keeps the connection alive instead. (Under the hood: a capped receive buffer, and it treats "out of buffer space" as a reason to slow down, not a reason to crash.)

All numbers come from controlled runs on real Apple hardware. Your WiFi and ISP set the top speed, not the kernel. The SDK reports its own live stats — throughput, connections, memory, health — so you can measure your build on your own device.

What's in the box — and what you build

Hako gives you: the proxy engine (the mihomo fork), the bind/hako binding that turns it into an SDK, and the build tooling — shipped as Hako.xcframework with API docs. That's the hard part, and it's done.

You build: the app, its UI, the NEPacketTunnelProvider glue that hands packets to Hako, config and credential storage, and code signing. Hako ships no app, no UI, and no certificates. You link the framework and ship your own product.

Quick start

You'll need Go 1.20+, plus Xcode with gomobile for the Apple framework.

# build the kernel
go build ./...

# build the 3-slice Hako.xcframework (device + simulator + macOS)
make lib_apple

Then, in your app:

  1. Link Hako.xcframework into both the app and the Packet Tunnel extension (it's a static framework — set Embed to Do Not Embed).
  2. Add -lresolv to every target that links Hako (it needs the C resolver, and the flag doesn't carry over on its own).
  3. From your NEPacketTunnelProvider, drive the kernel through the generated Objective-C API and move packets over Apple's public NEPacketTunnelFlow.
  4. Keep your configs, subscription URLs, and credentials on your side. The kernel reads a finished config; it is not a subscription manager and won't fetch or store anything for you.
  5. Sign and ship it.

The public header is identical across all three slices, and its SHA-256 is in the SDK manifest, so you can pin exactly what you shipped.

What the kernel can do

You get the full mihomo data plane, running inside the Packet Tunnel and controlled through the SDK. Here's what works on iOS:

  • Protocols: Shadowsocks, VMess, VLESS, Trojan, Snell, Hysteria / Hysteria2, TUIC, WireGuard, AnyTLS, SSH, and more. Every protocol builds and parses — test the ones you ship against your own servers first.
  • DNS: an in-tunnel resolver with DoH / DoT / DoQ, fake-IP, traffic sniffing, and per-domain nameserver rules.
  • Routing: rules by domain, IP-CIDR, GEOIP / GEOSITE, and RULE-SET, plus logical (AND / OR / NOT) and sub-rules. (Per-app and process rules don't work on iOS — Apple gives no way to tell which app a packet came from, so Hako skips them instead of faking it.)
  • Proxy groups: select, url-test, fallback, and load-balance with health checks, plus remote rule and proxy providers.
  • Runtime control: live status, traffic, connections, proxies, and logs, plus actions like switch proxy, latency test, and close connection — all over a local, app-private channel, never a network-exposed controller.
  • Built for the App Store: Hako talks to iOS only through Apple's public NEPacketTunnelFlow. No private file-descriptor tricks, no undocumented APIs.

Behavior follows upstream mihomo — see the mihomo docs and docs/config.yaml.

Before you ship

This is pre-1.0. The API and interoperability tests are in place. Protocols are verified by parsing and reference tests; testing on a signed device is up to you. Treat any build you cut as a development build until there's a formal v*-hako.* release tag — the repository's release tags are the source of truth for versioning.

Source, credits & license

Hako is a hard fork of MetaCubeX/mihomo, pinned to a specific stable upstream tag (currently v1.19.29) — never an Alpha. It is not affiliated with or endorsed by MetaCubeX or SagerNet. Per mihomo's license, unaffiliated forks can't use the mihomo name, so this one is Hako; the upstream name stays only where GPLv3 attribution needs it.

License: GPL-3.0. Because Hako.xcframework statically links the whole kernel, the framework is a derivative work under GPLv3, and its source is this repository at the released tag. Full attribution is in NOTICE, third-party licenses in THIRD_PARTY_LICENSES.md, and the full text in LICENSE.

Built on the work of MetaCubeX/mihomo, Dreamacro/clash, SagerNet/sing-box, riobard/go-shadowsocks2, v2fly/v2ray-core, and WireGuard/wireguard-go.

Security

Report vulnerabilities privately — see SECURITY.md. Don't open public issues for security problems, and never paste real credentials or subscription URLs into a report.

Documentation

The Go Gopher

There is no documentation for this package.

Directories

Path Synopsis
cmd
build_libbox command
Command build_libbox drives `gomobile bind` to produce Hako.xcframework from the bind/hako nested module.
Command build_libbox drives `gomobile bind` to produce Hako.xcframework from the bind/hako nested module.
gen_config_inventory command
Command gen_config_inventory enumerates the upstream mihomo configuration schema (config.RawConfig) field-by-field straight from source with go/ast — not reflect, not by reading prose docs — and additionally extracts the fields that bind/hako/override.go forces or clears.
Command gen_config_inventory enumerates the upstream mihomo configuration schema (config.RawConfig) field-by-field straight from source with go/ast — not reflect, not by reading prose docs — and additionally extracts the fields that bind/hako/override.go forces or clears.
gen_protocol_inventory command
Command gen_protocol_inventory regenerates the proxy-protocol field inventory that the iOS client's protocol editor decodes, by parsing the Core outbound option structs.
Command gen_protocol_inventory regenerates the proxy-protocol field inventory that the iOS client's protocol editor decodes, by parsing the Core outbound option structs.
package_licenses command
Command package_licenses emits the complete license inventory for every Go module linked into the Apple binding.
Command package_licenses emits the complete license inventory for every Go module linked into the Apple binding.
common
arc
buf
cmd
lru
net
orderedmap
Package orderedmap implements an ordered map, i.e.
Package orderedmap implements an ordered map, i.e.
singleflight
Package singleflight provides a duplicate function call suppression mechanism.
Package singleflight provides a duplicate function call suppression mechanism.
yaml
Package yaml provides a common entrance for YAML marshaling and unmarshalling.
Package yaml provides a common entrance for YAML marshaling and unmarshalling.
component
age
ca
ech
geodata/compiled
Package compiled stores a domain set the way it will be used, instead of the way it was written.
Package compiled stores a domain set the way it will be used, instead of the way it was written.
iface/anet
Package anet fix "route ip+net: netlinkrib: permission denied" on android copy and modify from https://github.com/wlynxg/anet/tree/5501d401a269290292909e6cc75f105571f97cfa
Package anet fix "route ip+net: netlinkrib: permission denied" on android copy and modify from https://github.com/wlynxg/anet/tree/5501d401a269290292909e6cc75f105571f97cfa
memory
Package memory return MemoryInfoStat modify from https://github.com/shirou/gopsutil/tree/v4.25.8/process
Package memory return MemoryInfoStat modify from https://github.com/shirou/gopsutil/tree/v4.25.8/process
nat
pause
Package pause exposes the process-wide device-pause manager.
Package pause exposes the process-wide device-pause manager.
tls
wildcard
Package wildcard modified IGLOU-EU/go-wildcard to support:
Package wildcard modified IGLOU-EU/go-wildcard to support:
hub
hysteria2_realm
Package hysteria2_realm copy and modify from: https://github.com/apernet/hysteria-realm-server/tree/1ec22609705b5896df17d4ae4bfb2a1675cdb606
Package hysteria2_realm copy and modify from: https://github.com/apernet/hysteria-realm-server/tree/1ec22609705b5896df17d4ae4bfb2a1675cdb606
jls
Command go_mobile_api_inventory prints the exported Go surface selected by one target's build constraints.
Command go_mobile_api_inventory prints the exported Go surface selected by one target's build constraints.
transport
gun
jls
kcptun
Package kcptun copy and modify from: https://github.com/xtaci/kcptun/tree/f54f35175bed6ddda4e47aa35c9d7ae8b7e7eb85 adopt for mihomo without SM4,QPP,tcpraw support
Package kcptun copy and modify from: https://github.com/xtaci/kcptun/tree/f54f35175bed6ddda4e47aa35c9d7ae8b7e7eb85 adopt for mihomo without SM4,QPP,tcpraw support
masque
Package masque copy and modify from https://github.com/Diniboy1123/usque/blob/d0eb96e7e5c56cce6cf34a7f8d75abbedba58fef/api/masque.go
Package masque copy and modify from https://github.com/Diniboy1123/usque/blob/d0eb96e7e5c56cce6cf34a7f8d75abbedba58fef/api/masque.go
trusttunnel
Package trusttunnel copy and modify from: https://github.com/xchacha20-poly1305/sing-trusttunnel/tree/v0.1.1 adopt for mihomo
Package trusttunnel copy and modify from: https://github.com/xchacha20-poly1305/sing-trusttunnel/tree/v0.1.1 adopt for mihomo
vless/encryption
Package encryption copy and modify from xray-core https://github.com/XTLS/Xray-core/commit/f61c14e9c63dc41a8a09135db3aea337974f3f37 https://github.com/XTLS/Xray-core/commit/3e19bf9233bdd9bafc073a71c65b737cc1ffba5e https://github.com/XTLS/Xray-core/commit/7ffb555fc8ec51bd1e3e60f26f1d6957984dba80 https://github.com/XTLS/Xray-core/commit/ec1cc35188c1a5f38a2ff75e88b5d043ffdc59da https://github.com/XTLS/Xray-core/commit/5c611420487a92f931faefc01d4bf03869f477f6 https://github.com/XTLS/Xray-core/commit/23d7aad461d232bc5bed52dd6aaa731ecd88ad35 https://github.com/XTLS/Xray-core/commit/3c20bddfcfd8999be5f9a2ac180dc959950e4c61 https://github.com/XTLS/Xray-core/commit/1720be168fa069332c418503d30341fc6e01df7f https://github.com/XTLS/Xray-core/commit/0fd7691d6b28e05922d7a5a9313d97745a51ea63 https://github.com/XTLS/Xray-core/commit/09cc92c61d9067e0d65c1cae9124664ecfc78f43 https://github.com/XTLS/Xray-core/commit/2807ee432a1fbeb301815647189eacd650b12a8b https://github.com/XTLS/Xray-core/commit/bfe4820f2f086daf639b1957eb23dc13c843cad1 https://github.com/XTLS/Xray-core/commit/d1fb48521271251a8c74bd64fcc2fc8700717a3b https://github.com/XTLS/Xray-core/commit/49580705f6029648399304b816a2737f991582a8 https://github.com/XTLS/Xray-core/commit/84835bec7d0d8555d0dd30953ed26a272de814c4 https://github.com/XTLS/Xray-core/commit/373558ed7abdbac3de41745cf30ec04c9adde604 https://github.com/XTLS/Xray-core/commit/38cc306c955c362f044e074049a5e67b6b9fb389 https://github.com/XTLS/Xray-core/commit/b33555cc0a52d0af3c23d2af8fca42f8a685d9af https://github.com/XTLS/Xray-core/commit/ad7140641c44239c9dcdc3d7215ea639b1f0841c https://github.com/XTLS/Xray-core/commit/0199dea39988a1a1b846d0bf8598631bade40902 https://github.com/XTLS/Xray-core/commit/fce1195b60f48ca18a953dbd5c7d991869de9a5e https://github.com/XTLS/Xray-core/commit/b0b220985c9c1bc832665458d5fd6e0c287b67ae https://github.com/XTLS/Xray-core/commit/82ea7a3cc5ff23280b87e3052f0f83b04f0267fa https://github.com/XTLS/Xray-core/commit/e8b02cd6649f14889841e8ab8ee6b2acca71dbe6 https://github.com/XTLS/Xray-core/commit/6768a22f676c9121cfc9dc4f51181a8a07837c8d https://github.com/XTLS/Xray-core/commit/4c6fd94d97159f5a3e740ba6dd2d9b65e3ed320c https://github.com/XTLS/Xray-core/commit/19f890729656bc923ae3dee8426168c93b8ee9c2 https://github.com/XTLS/Xray-core/commit/cbade89ab11af26ba1e480a3688a6c205fa3c3f8
Package encryption copy and modify from xray-core https://github.com/XTLS/Xray-core/commit/f61c14e9c63dc41a8a09135db3aea337974f3f37 https://github.com/XTLS/Xray-core/commit/3e19bf9233bdd9bafc073a71c65b737cc1ffba5e https://github.com/XTLS/Xray-core/commit/7ffb555fc8ec51bd1e3e60f26f1d6957984dba80 https://github.com/XTLS/Xray-core/commit/ec1cc35188c1a5f38a2ff75e88b5d043ffdc59da https://github.com/XTLS/Xray-core/commit/5c611420487a92f931faefc01d4bf03869f477f6 https://github.com/XTLS/Xray-core/commit/23d7aad461d232bc5bed52dd6aaa731ecd88ad35 https://github.com/XTLS/Xray-core/commit/3c20bddfcfd8999be5f9a2ac180dc959950e4c61 https://github.com/XTLS/Xray-core/commit/1720be168fa069332c418503d30341fc6e01df7f https://github.com/XTLS/Xray-core/commit/0fd7691d6b28e05922d7a5a9313d97745a51ea63 https://github.com/XTLS/Xray-core/commit/09cc92c61d9067e0d65c1cae9124664ecfc78f43 https://github.com/XTLS/Xray-core/commit/2807ee432a1fbeb301815647189eacd650b12a8b https://github.com/XTLS/Xray-core/commit/bfe4820f2f086daf639b1957eb23dc13c843cad1 https://github.com/XTLS/Xray-core/commit/d1fb48521271251a8c74bd64fcc2fc8700717a3b https://github.com/XTLS/Xray-core/commit/49580705f6029648399304b816a2737f991582a8 https://github.com/XTLS/Xray-core/commit/84835bec7d0d8555d0dd30953ed26a272de814c4 https://github.com/XTLS/Xray-core/commit/373558ed7abdbac3de41745cf30ec04c9adde604 https://github.com/XTLS/Xray-core/commit/38cc306c955c362f044e074049a5e67b6b9fb389 https://github.com/XTLS/Xray-core/commit/b33555cc0a52d0af3c23d2af8fca42f8a685d9af https://github.com/XTLS/Xray-core/commit/ad7140641c44239c9dcdc3d7215ea639b1f0841c https://github.com/XTLS/Xray-core/commit/0199dea39988a1a1b846d0bf8598631bade40902 https://github.com/XTLS/Xray-core/commit/fce1195b60f48ca18a953dbd5c7d991869de9a5e https://github.com/XTLS/Xray-core/commit/b0b220985c9c1bc832665458d5fd6e0c287b67ae https://github.com/XTLS/Xray-core/commit/82ea7a3cc5ff23280b87e3052f0f83b04f0267fa https://github.com/XTLS/Xray-core/commit/e8b02cd6649f14889841e8ab8ee6b2acca71dbe6 https://github.com/XTLS/Xray-core/commit/6768a22f676c9121cfc9dc4f51181a8a07837c8d https://github.com/XTLS/Xray-core/commit/4c6fd94d97159f5a3e740ba6dd2d9b65e3ed320c https://github.com/XTLS/Xray-core/commit/19f890729656bc923ae3dee8426168c93b8ee9c2 https://github.com/XTLS/Xray-core/commit/cbade89ab11af26ba1e480a3688a6c205fa3c3f8
vless/vision
Package vision implements VLESS flow `xtls-rprx-vision` introduced by Xray-core.
Package vision implements VLESS flow `xtls-rprx-vision` introduced by Xray-core.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL