Fixes
- Wireguard:
- support IPv6 address formatting from config files (#3273)
- ignore empty address strings
- skip tun device checks when using kernelspace
- OpenVPN:
- Custom openvpn: restrict custom openvpn config protocol to tcp or udp internally
- Firewall: shared mutex for both iptables and ip6tables to prevent race conditions
- Healthcheck:
- correct behavior when HEALTH_RESTART_VPN=off and startup check fails
- prevent race condition on the healthchecker (#3400)
- DNS:
- skip blocking if block lists download fails
- correct error wrapping for DNS listening address validation
- DNS over TLS pool behavior fixed
- handle timed out connections the same as closed connections
- close connection on TLS handshake failure
- improve mutex handling during connection renewal and retrieval
- VPN port forwarding:
- no longer stuck after failed port forwarding
- handle empty ports without panicing
- Updater: only uses DoH to cloudflare+google
- prevent dns plaintext manipulation both the periodic update and when running in cli mode
- possibly higher reliability on poor connections versus UDP
- drop
-dnsflag in update command - for now no configuration allowed since it makes everything rather complex
- Control server:
- use
portandportsfor both single port and multiple ports forwarded - authentication: return 404 or 405 depending on route
- use
- Increase global http client timeout to 35s and precise lower timeouts where needed
- Fix DNS blocklists slow downloads
- Leave 35s timeout for updaters
- Set timeouts to 1s for local calls
- Set timeouts to 5s for LAN VPN calls and small external calls
- Set timeouts to 10s external VPN API calls
- Kernel modules: probe searches for features built-in the kernel
- CI: set hash of PR commit instead of synthetic commit in docker build argument
internal/command: fix rare race condition on log line stream at command completion
Provider specific fixes
- AirVPN: update servers data (#3186)
- ExpressVPN:
- Privado:
- servers data updated using JSON API
- allow OpenVPN TCP protocol
- allow additional OpenVPN ports 443, 8080 and 8443 for both tcp and udp
- Private Internet Access:
- remove none encryption preset
- use AES-GCM for all presets
- allow ports 501 and 502 as custom ports given they are the defaults
- try x.y.128.1 and x.y.0.1 from the gateway IP to find the API IP address
- fix servers data updater and update servers data
- update default OpenVPN ports: 8080 for UDP, 8443 for TCP (according to pia-foss/manual-connections@8a75e46)
- handle "port is busy" messages and retry port forwarding logic
- ProtonVPN: fix updater code
- Vyprvpn: update OpenVPN configs zip URL (#3264)
PS:
- No time to make a video or a rant section yet, but will do for v3.42.0 for sure!
- v3.42 probably coming end of August/early September!
- Sorry for the spam, first few v3.41.2 release attempts decided to give me a bunch of surprises in the CI, so here it is again