Happy holidays release time đ đ đ
đ If anything doesn't work compared to previous release, please create an issue and revert to using v3.39.1 đ
âšī¸ Life is pretty busy all around currently (moving soon, new job, ill parent) so I might be even slower than usual until summer 2025, I'll do my best!
Features
- VPN: run
WaitForDNSbefore querying the public ip address (partly address #2325) - DNS: replace unbound with qdm12/dns@v2.0.0-rc8 (#1742 & later commits)
- Faster start up
- Clearer error messages
- Allow for more Gluetun-specific customization
- Port forwarding:
VPN_PORT_FORWARDING_UP_COMMANDoption (#2399)VPN_PORT_FORWARDING_DOWN_COMMANDoption
- Config allow irrelevant server filters to be set (see #2337)
- Disallow setting a server filter when there is no choice available
- Allow setting an invalid server filter when there is at least one choice available
- Log at warn level when an invalid server filter is set
- Firewall: support custom ICMP rules
- Healthcheck:
- log out last error when auto healing VPN
- run TLS handshake after TCP dial if address has 443 port
- Public IP:
- retry fetching information when
connection refusederror is encountered (partly address #2325) - support custom API url
echoip#https://...(#2529) - resilient public ip fetcher with backup sources (#2518)
- add
ifconfigcooption andcloudflareoption (#2502) PUBLICIP_ENABLEDreplacesPUBLICIP_PERIODPUBLICIP_ENABLED(on, off) can be set to enable or not public ip data fetching on VPN connectionPUBLICIP_PERIOD=0still works to indicate to disable public ip fetchingPUBLICIP_PERIOD!= 0 means to enable public ip fetching- Warnings logged when using
PUBLICIP_PERIOD
- retry fetching information when
STORAGE_FILEPATHoption (#2416)STORAGE_FILEPATH=disables storing to and reading from a local servers.json fileSTORAGE_FILEPATHdefaults to/gluetun/servers.json
- Netlink: debug rule logs contain the ip family
internal/tun: mention in 'operation not permitted' error the user should specify--device /dev/net/tun(resolves #2606)- Control server role based authentication system (#2434) (part of v3.39.1 as a bugfix)
- Parse toml configuration file, see https://github.com/qdm12/gluetun-wiki/blob/main/setup/advanced/control-server.md#authentication
- Retro-compatible with existing AND documented routes, until after this release
- Log a warning if an unprotected-by-default route is accessed unprotected
- Authentication methods: none, apikey, basic
genkeycommand to generate API keys
- FastestVPN: add
aes-256-gcmto OpenVPN ciphers list - Private Internet Access updater: use v6 API to get servers data
- IPVanish: update servers data
- PrivateVPN: native port forwarding support (#2285)
- Privado: update servers data
format-serverscommand supports the json format option
Fixes
- Wireguard: change default
WIREGUARD_MTUfrom1400to1320(partially address #2533) - OpenVPN: set default mssfix to 1320 for all providers with no default already set (partially address #2533)
- Control server: fix logged wiki authentication section link
- Firewall:
- iptables list uses
-nflag for testing iptables path (#2574) - deduplicate VPN address accept rule for multiple default routes with the same network interface
- deduplicate ipv6 multicast output accept rules
- ipv6 multicast output address value fixed
- log warning if ipv6 nat filter is not supported instead of returning an error (allow to port forward redirect for IPv4 and not IPv6 if IPv6 NAT is not supported and fixed #2503)
- iptables list uses
- Wireguard:
- Point to Kubernetes wiki page when encountering IP rule add file exists error (#2526)
- IPVanish:
- fix openvpn configuration by updating CA value and add
comp-lzooption - update openvpn zip file url for updater
- fix openvpn configuration by updating CA value and add
- Perfect Privacy: update openvpn expired certificates (#2542)
- Public IP: lock settings during entire update to prevent race conditions
Documentation
- Dockerfile
- add missing
OPENVPN_MSSFIXenvironment variable - add missing option definitions
STREAM_ONLYFREE_ONLY
- Document
PORT_FORWARD_ONLYis for both PIA and ProtonVPN
- add missing
Maintenance
Code quality
- Remove github.com/qdm12/golibs dependency
- Implement friendly duration formatting locally
- implement
github.com/qdm12/golibs/commandlocally (#2418)
internal/natpmp: fix determinism for testTest_Client_ExternalAddress- let system handle OS signals after first one to request a program stop
internal/routing: remove redundantrule ip rulein error messagesinternal/netlinkdebug log ip rule commands in netlink instead of routing packageinternal/server: move log middleware tointernal/server/middlewares/log- use
gofumptfor code formatting - Fix gopls govet errors
- Upgrade linter from v1.56.2 to v1.61.0
- Remove no longer needed exclude rules
- Add new exclude rules for printf govet errors
- Remove deprecated linters
execinqueryandexportloopref - Rename linter
goerr113toerr113andgomndtomnd - Add new linters and update codebase:
canonicalheader,copyloopvar,fatcontext,intrange
Dependencies
- Upgrade Go from 1.22 to 1.23
- Bump vishvananda/netlink from v1.2.1-beta.2 to v1.2.1
- Bump github.com/qdm12/gosettings from v0.4.3 to v0.4.4
- Better support for quote expressions especially for commands such as
VPN_PORT_FORWARDING_UP_COMMAND
- Better support for quote expressions especially for commands such as
- Bump github.com/breml/rootcerts from 0.2.18 to 0.2.19 (#2601)
- Bump golang.org/x/net from 0.25.0 to 0.31.0 (#2401, #2578)
- Bump golang.org/x/sys from 0.260.0 to 0.27.0 (#2404, #2573)
- Bump golang.org/x/text from 0.15.0 to 0.17.0 (#2400)
- Bump github.com/klauspost/compress from 1.17.8 to 1.17.11 (#2319, #2550)
- Bump github.com/pelletier/go-toml/v2 from 2.2.2 to 2.2.3 (#2549)
- Bump google.golang.org/protobuf from 1.30.0 to 1.33.0 (#2428)
- Bump github.com/stretchr/testify from 1.9.0 to 1.10.0 (#2600)
CI
- Linting: remove
canonicalheadersince it's not reliable - Use
--device /dev/net/tunfor test container - Bump DavidAnson/markdownlint-cli2-action from 16 to 18 (#2588)
- Bump docker/build-push-action from 5 to 6 (#2324)
Development setup
- dev container
- pin godevcontainer image to tag
:v0.20-alpine - drop requirement for docker-compose and use
devcontainer.jsonsettings directly - readme update
- remove Windows without WSL step
- update 'remote containers extension' to 'dev containers extension'
- remove invalid warning on directories creation
- simplify customizations section
- remove "publish a port" since it can be done at runtime now
- remove "run other services" since it's rather unneeded in this case
- expand documentation on custom welcome script and where to specify the bind mount
- use bullet points instead of subsections headings
- pin godevcontainer image to tag
- Github labels
- change "config problem" to "user error"
- add "performance", "investigation", "servers storage" and "nearly resolved" categories