v3.41.2

SaschaHeyer/gen-ai-livestreamv3.41.2Jul 29, 2026by qdm12

AI Summary

This release focuses on stabilizing the VPN client with numerous bug fixes across WireGuard, OpenVPN, DNS, and healthchecks. It also introduces improvements to the Updater, Control Server, and HTTP timeouts, alongside provider-specific updates.

Key Highlights

  • Fixes port forwarding deadlock and stuck states after failures
  • Improves OpenVPN support for `tcp-client` and custom protocols
  • Enhances DNS over HTTPS (DoH) reliability and blocklist handling
  • Updates healthcheck logic to prevent race conditions
  • Updates servers data for multiple VPN providers (ExpressVPN, PIA, ProtonVPN, etc.)

Full Release Notes

⚠️ there is a deadlock bug in the port forwarding if you use the up or down command, I will release v3.41.3 shortly

## Fixes

- Wireguard:
  - support IPv6 address formatting from config files (#3273)
  - ignore empty address strings
  - skip tun device checks when using kernelspace
- OpenVPN:
  - bundle provider CA certificates in one block (#3258)
  - trim spaces in config lines before parsing (#3327)
  - fix support for `tcp-client`
    - always use `proto tcp-client` when using TCP
    - parses `tcp-client` (on top of `tcp`, `tcp4`, `tcp6`) as meaning TCP
- Custom openvpn: restrict custom openvpn config protocol to tcp or udp internally
- Firewall: shared mutex for both iptables and ip6tables to prevent race conditions
- Healthcheck:
  - correct behavior when HEALTH_RESTART_VPN=off and startup check fails
  - prevent race condition on the healthchecker (#3400)
- DNS:
  - skip blocking if block lists download fails
  - correct error wrapping for DNS listening address validation
  - DNS over TLS pool behavior fixed
    - handle timed out connections the same as closed connections
    - close connection on TLS handshake failure
    - improve mutex handling during connection renewal and retrieval
- VPN port forwarding:
  - no longer stuck after failed port forwarding
  - handle empty ports without panicing
- Updater: only uses DoH to cloudflare+google
  - prevent dns plaintext manipulation both the periodic update and when running in cli mode
  - possibly higher reliability on poor connections versus UDP
  - drop `-dns` flag in update command
  - for now no configuration allowed since it makes everything rather complex
- Control server:
  - use `port` and `ports` for both single port and multiple ports forwarded
  - authentication: return 404 or 405 depending on route
- Increase global http client timeout to 35s and precise lower timeouts where needed
  - Fix DNS blocklists slow downloads
  - Leave 35s timeout for updaters
  - Set timeouts to 1s for local calls
  - Set timeouts to 5s for LAN VPN calls and small external calls
  - Set timeouts to 10s external VPN API calls
- Kernel modules: probe searches for features built-in the kernel
- CI: set hash of PR commit instead of synthetic commit in docker build argument
- `internal/command`: fix rare race condition on log line stream at command completion

### Provider specific fixes

- AirVPN: update servers data (#3186)
- ExpressVPN:
  - add new CA3 certificate to fix TLS handshake failure (#3184, #3192)
  - remove pakistan server
- Privado:
  - servers data updated using JSON API
  - allow OpenVPN TCP protocol
  - allow additional OpenVPN ports 443, 8080 and 8443 for both tcp and udp
- Private Internet Access:
  - remove none encryption preset
  - use AES-GCM for all presets
  - allow ports 501 and 502 as custom ports given they are the defaults
  - try x.y.128.1 and x.y.0.1 from the gateway IP to find the API IP address
  - fix servers data updater and update servers data
  - update default OpenVPN ports: 8080 for UDP, 8443 for TCP (according to https://github.com/pia-foss/manual-connections/commit/8a75e46be81583d17f9ab3570881419b35000969)
  - handle "port is busy" messages and retry port forwarding logic
- ProtonVPN: fix updater code
- Vyprvpn: update OpenVPN configs zip URL (#3264)

---

PS:
- No time to make a video or a rant section yet, but will do for v3.42.0 for sure!
- v3.42 probably coming end of August/early September!
- Sorry for the spam, first few v3.41.2 release attempts decided to give me a bunch of surprises in the CI, so here it is again