v3.41.2
t8y2/dbxv3.41.2Jul 29, 2026by qdm12
AI Summary
This release introduces a wide range of fixes and improvements for Wireguard, OpenVPN, DNS, and firewall configurations, alongside provider-specific updates. It resolves critical stability issues and enhances the reliability of health checks and DNS over TLS.
Key Highlights
- Comprehensive fixes for Wireguard (IPv6) and OpenVPN (protocol support)
- Enhanced firewall mutex handling and DNS over TLS reliability
- Provider-specific updates including ExpressVPN, PIA, and Privado
New Features
- Added support for IPv6 address formatting in Wireguard configs
- Added new OpenVPN ports (443, 8080, 8443) for Privado and PIA
- PIA now uses AES-GCM encryption for all presets
- Control server now supports both `port` and `ports` for forwarding
- Added TCP protocol support for Privado
Full Release Notes
⚠️ there is a deadlock bug in the port forwarding if you use the up or down command, I will release v3.41.3 shortly
## Fixes
- Wireguard:
- support IPv6 address formatting from config files (#3273)
- ignore empty address strings
- skip tun device checks when using kernelspace
- OpenVPN:
- bundle provider CA certificates in one block (#3258)
- trim spaces in config lines before parsing (#3327)
- fix support for `tcp-client`
- always use `proto tcp-client` when using TCP
- parses `tcp-client` (on top of `tcp`, `tcp4`, `tcp6`) as meaning TCP
- Custom openvpn: restrict custom openvpn config protocol to tcp or udp internally
- Firewall: shared mutex for both iptables and ip6tables to prevent race conditions
- Healthcheck:
- correct behavior when HEALTH_RESTART_VPN=off and startup check fails
- prevent race condition on the healthchecker (#3400)
- DNS:
- skip blocking if block lists download fails
- correct error wrapping for DNS listening address validation
- DNS over TLS pool behavior fixed
- handle timed out connections the same as closed connections
- close connection on TLS handshake failure
- improve mutex handling during connection renewal and retrieval
- VPN port forwarding:
- no longer stuck after failed port forwarding
- handle empty ports without panicing
- Updater: only uses DoH to cloudflare+google
- prevent dns plaintext manipulation both the periodic update and when running in cli mode
- possibly higher reliability on poor connections versus UDP
- drop `-dns` flag in update command
- for now no configuration allowed since it makes everything rather complex
- Control server:
- use `port` and `ports` for both single port and multiple ports forwarded
- authentication: return 404 or 405 depending on route
- Increase global http client timeout to 35s and precise lower timeouts where needed
- Fix DNS blocklists slow downloads
- Leave 35s timeout for updaters
- Set timeouts to 1s for local calls
- Set timeouts to 5s for LAN VPN calls and small external calls
- Set timeouts to 10s external VPN API calls
- Kernel modules: probe searches for features built-in the kernel
- CI: set hash of PR commit instead of synthetic commit in docker build argument
- `internal/command`: fix rare race condition on log line stream at command completion
### Provider specific fixes
- AirVPN: update servers data (#3186)
- ExpressVPN:
- add new CA3 certificate to fix TLS handshake failure (#3184, #3192)
- remove pakistan server
- Privado:
- servers data updated using JSON API
- allow OpenVPN TCP protocol
- allow additional OpenVPN ports 443, 8080 and 8443 for both tcp and udp
- Private Internet Access:
- remove none encryption preset
- use AES-GCM for all presets
- allow ports 501 and 502 as custom ports given they are the defaults
- try x.y.128.1 and x.y.0.1 from the gateway IP to find the API IP address
- fix servers data updater and update servers data
- update default OpenVPN ports: 8080 for UDP, 8443 for TCP (according to https://github.com/pia-foss/manual-connections/commit/8a75e46be81583d17f9ab3570881419b35000969)
- handle "port is busy" messages and retry port forwarding logic
- ProtonVPN: fix updater code
- Vyprvpn: update OpenVPN configs zip URL (#3264)
---
PS:
- No time to make a video or a rant section yet, but will do for v3.42.0 for sure!
- v3.42 probably coming end of August/early September!
- Sorry for the spam, first few v3.41.2 release attempts decided to give me a bunch of surprises in the CI, so here it is again