Horion is a security-first Windows desktop control plane for the Mihomo proxy core. It is built with Tauri 2, Rust, React, TypeScript, Vite, and Tailwind CSS.
Current version: v0.4.0 — Windows system proxy and TUN. In addition to profiles, subscriptions, and proxy nodes, Horion can safely capture Windows traffic through a transactional system proxy or a temporarily elevated TUN helper.
- Pinned official Mihomo installation or trusted local executable import
- Exact child-process start, stop, restart, health checks, cleanup, and bounded logs
- Local
.yaml/.ymlimport by absolute path or desktop drag-and-drop - HTTPS subscriptions whose complete URLs are stored only in Windows Credential Manager
- Rename, duplicate, delete, and revision-protected YAML editing
- Atomic writes and up to ten backups per managed profile
- Real
mihomo -tvalidation before activation, with content and runtime rollback - Real Controller nodes and policy groups with search, protocol filters, delay sorting, and at most four concurrent single-node tests
- Selector changes and rule/global/direct runtime mode switching
- Windows system-proxy control with custom and LAN bypass lists
- Exact proxy-state restoration after stop, exit, or crash, without overwriting a later manual change
- App-owned TUN stack, routing, interface detection, DNS hijack, strict route, IPv6, MTU, device-name, and excluded-CIDR settings
- A separately elevated helper for TUN; the main UI remains at standard user integrity
- A redesigned light/dark desktop UI with explicit loading, empty, offline, and error states
- Download the latest
Horion_*_x64-setup.exefrom GitHub Releases. - Install the verified official Mihomo core from the dashboard.
- Import a local YAML profile or add a trusted HTTPS subscription.
- Activate the profile and start the core.
- Enable Windows system proxy or configure TUN in Settings. Confirm Windows UAC when starting TUN.
This personal project is not Authenticode-signed, so Windows SmartScreen may warn on first launch. Download only from this repository and compare the installer SHA-256 with the value on the Release page.
v0.4.0 injects a random loopback mixed port for the managed system proxy. A remote profile cannot enable TUN; only validated local UI settings can inject the narrow TUN configuration. Horion does not yet provide:
- Custom inbound servers or LAN sharing
- Live traffic, connection, rule, or memory metrics
- Tray controls or automatic app/core updates
Before execution, Horion removes profile-supplied TUN, custom listeners/tunnels, DNS listeners, TUIC/SS/VMess server settings, external Controllers, Web UI, and user CORS settings from managed profiles. Horion then injects only its validated local TUN settings. Profiles cannot override the authenticated loopback Controller.
Horion v0.4.0 never resolves a mutable latest release. Official installation
uses Mihomo v1.19.29:
| Architecture | Official asset | Archive bytes | SHA-256 |
|---|---|---|---|
| Windows x86_64 | mihomo-windows-amd64-v1-v1.19.29.zip |
17,509,589 | 4a5b4cdf76f1879043cea7488162517fd3fb95d5b7a205d89601f1942791ee39 |
| Windows ARM64 | mihomo-windows-arm64-v1.19.29.zip |
15,430,938 | f71736f9c2a17abb8909a726c69ac55279d0cb43d1d9f2c85afdbb70a0f326a3 |
The network request happens only after the user selects the official-install
action. Horion verifies exact size, SHA-256, the allowlisted ZIP entry, and
mihomo -v before committing the executable. Mihomo remains a separate
GPL-3.0 project and is not embedded in the Horion installer; see
THIRD_PARTY_NOTICES.md.
Requirements are Windows 10/11, WebView2, Node.js 24 LTS, Rust stable with the MSVC host, and Microsoft C++ Build Tools with Desktop development with C++.
npm.cmd install
npm.cmd run tauri:devnpm.cmd run dev is a browser-only preview and cannot access the local core,
profiles, or Controller. See docs/development.md for
the full verification and release flow.
A normal Windows installation stores data below %APPDATA%\io.horion.desktop\:
core\contains the managed Mihomo executable and runtime data.profiles\contains managed YAML, metadata, and up to ten backups.network\settings.jsoncontains non-secret system-proxy and TUN preferences.network\system-proxy-lease.jsonexists only while an exact proxy restoration transaction is active.- Windows Credential Manager stores complete subscription URLs, which may contain tokens.
Each start receives a fresh Controller secret that stays in Rust and is sent to
Mihomo through stdin. Complete subscription URLs, profile content, and the
secret are not put in browser localStorage or ordinary UI logs. Horion contains
no advertising, analytics, or telemetry. See SECURITY.md.
Horion is licensed under the MIT License. Third-party components retain their
own licenses. Mihomo v1.19.29 runs as a separate GPL-3.0 process; its pinned
source and license are recorded in
third_party/mihomo/NOTICE.md.