Skip to content

Fix VPN lifecycle, configuration recovery and TCP DNS - #84

Merged
andre487 merged 6 commits into
mainfrom
fix/review-vpn-dns-lifecycle
Oct 11, 2026
Merged

andre487 merged 6 commits into
mainfrom
fix/review-vpn-dns-lifecycle

Conversation

@andre487

@andre487 andre487 commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

Fixes eight findings from the repository review: an old temporary test could stop a replacement VPN, queued status updates could revive a stopped session, failover could choose unusable profiles, subscription updates during startup could miss the reconnect notification, damaged global settings silently enabled defaults, SSH/MASQUE bypass sockets survived Stop, MASQUE admission waits did not wake on Close, and TCP DNS bypassed DoH.

  • Bind test completion, startup notifications and state publication to the owning VPN generation; serialize temporary native startup with reconnects.
  • Validate effective failover candidates, reject malformed stored settings without rewriting them, and reconcile the started configuration with subscription changes.
  • Close owned bypass sockets and wake blocked SSH/MASQUE callers. Route TCP/53 through the existing DoH fallback and IPv6 policy, with bounded pipelining, deadlines and half-close support.
  • Add Go/JVM regressions and UDP/TCP DNS interception checks to the real TUN emulator scenarios. Update the privacy policy and English/Russian DNS documentation.

Validation:

  • Linux CI: 225 native tests with race detection and 45 integration tests with real GOST/OpenSSH passed (native run); native code is unchanged since that run.
  • Final head: 289 Android JVM tests, lint, debug and unsigned release builds passed.
  • Full independent API 26 and API 35 TUN/JNI scenarios passed, including UDP/TCP DNS, restart, authentication, HTTP/3, Jump, failover, split routing and Keystore process restart (Android run). The DNS probe follows a successful private-origin round trip so Android routing is ready before its single UDP packet; there are no test retries.

The local Colima integration attempt timed out on UDP/QUIC; the complete Linux GOST/OpenSSH integration suite passed.

APK artifacts

Built from commit f6d36dc5 by CI run #303.
Artifacts expire after 14 days. Neither APK uses the MegaProxy release key.

@andre487
andre487 marked this pull request as ready for review October 11, 2026 15:35
@andre487
andre487 merged commit 6ec1b68 into main Oct 11, 2026
14 checks passed
@andre487
andre487 deleted the fix/review-vpn-dns-lifecycle branch October 11, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant