v3.41.2

passteque/gluetunv3.41.2Jul 29, 2026by qdm12

AI Summary

A comprehensive release focused on stability and bug fixes, addressing critical issues in DNS over TLS, firewall race conditions, and provider-specific configurations, alongside improvements to HTTP timeouts and kernel modules.

Key Highlights

  • Fixes critical deadlock bug in VPN port forwarding (prevents hanging)
  • Improves DNS over TLS handling with better mutex management and connection timeouts
  • Enhances firewall mutex to prevent race conditions between iptables and ip6tables
  • Updates provider configurations (PIA, ExpressVPN) and adds support for new protocols/ports
  • Increases global HTTP client timeout to 35s for better reliability

Breaking Changes

  • Dropped the `-dns` flag in the update command (configuration simplified)

New Features

  • Support for IPv6 address formatting in Wireguard config files
  • Restriction of custom OpenVPN config protocol to TCP or UDP internally
  • Kernel modules now probe for features built-in the kernel

Full Release Notes

⚠️ there is a deadlock bug in the port forwarding if you use the up or down command, I will release v3.41.3 shortly

## Fixes

- Wireguard:
  - support IPv6 address formatting from config files (#3273)
  - ignore empty address strings
  - skip tun device checks when using kernelspace
- OpenVPN:
  - bundle provider CA certificates in one block (#3258)
  - trim spaces in config lines before parsing (#3327)
  - fix support for `tcp-client`
    - always use `proto tcp-client` when using TCP
    - parses `tcp-client` (on top of `tcp`, `tcp4`, `tcp6`) as meaning TCP
- Custom openvpn: restrict custom openvpn config protocol to tcp or udp internally
- Firewall: shared mutex for both iptables and ip6tables to prevent race conditions
- Healthcheck:
  - correct behavior when HEALTH_RESTART_VPN=off and startup check fails
  - prevent race condition on the healthchecker (#3400)
- DNS:
  - skip blocking if block lists download fails
  - correct error wrapping for DNS listening address validation
  - DNS over TLS pool behavior fixed
    - handle timed out connections the same as closed connections
    - close connection on TLS handshake failure
    - improve mutex handling during connection renewal and retrieval
- VPN port forwarding:
  - no longer stuck after failed port forwarding
  - handle empty ports without panicing
- Updater: only uses DoH to cloudflare+google
  - prevent dns plaintext manipulation both the periodic update and when running in cli mode
  - possibly higher reliability on poor connections versus UDP
  - drop `-dns` flag in update command
  - for now no configuration allowed since it makes everything rather complex
- Control server:
  - use `port` and `ports` for both single port and multiple ports forwarded
  - authentication: return 404 or 405 depending on route
- Increase global http client timeout to 35s and precise lower timeouts where needed
  - Fix DNS blocklists slow downloads
  - Leave 35s timeout for updaters
  - Set timeouts to 1s for local calls
  - Set timeouts to 5s for LAN VPN calls and small external calls
  - Set timeouts to 10s external VPN API calls
- Kernel modules: probe searches for features built-in the kernel
- CI: set hash of PR commit instead of synthetic commit in docker build argument
- `internal/command`: fix rare race condition on log line stream at command completion

### Provider specific fixes

- AirVPN: update servers data (#3186)
- ExpressVPN:
  - add new CA3 certificate to fix TLS handshake failure (#3184, #3192)
  - remove pakistan server
- Privado:
  - servers data updated using JSON API
  - allow OpenVPN TCP protocol
  - allow additional OpenVPN ports 443, 8080 and 8443 for both tcp and udp
- Private Internet Access:
  - remove none encryption preset
  - use AES-GCM for all presets
  - allow ports 501 and 502 as custom ports given they are the defaults
  - try x.y.128.1 and x.y.0.1 from the gateway IP to find the API IP address
  - fix servers data updater and update servers data
  - update default OpenVPN ports: 8080 for UDP, 8443 for TCP (according to https://github.com/pia-foss/manual-connections/commit/8a75e46be81583d17f9ab3570881419b35000969)
  - handle "port is busy" messages and retry port forwarding logic
- ProtonVPN: fix updater code
- Vyprvpn: update OpenVPN configs zip URL (#3264)

---

PS:
- No time to make a video or a rant section yet, but will do for v3.42.0 for sure!
- v3.42 probably coming end of August/early September!
- Sorry for the spam, first few v3.41.2 release attempts decided to give me a bunch of surprises in the CI, so here it is again