Repository navigation
Releases: DurkaEbanaya/dropshit
Release list
Dropshit v0.1.6
Dropshit 0.1.6: fix Discord voice/video being captured by per-user UDP filtering.
- Exclude UDP destination ports 1541, 19294–19344 and 50000–65535 on IPv4/IPv6, in both strict allowlist and regional blocklist modes. The narrower 50000–50032 range is included. TCP/443 was already unaffected.
- Effective filtered ranges: 12000–19293 and 19345–49999. These exceptions apply to all programs; Overwatch using the exception ports will also bypass Dropshit. Rules still match the whole user, not a specific executable.
- nftables generates only the reduced port ranges; iptables adds a leading RETURN for Discord ports within its owned chain. No ACCEPT rules override the system firewall.
- Status validation detects old rules missing the exception; restart the app after upgrading to automatically replace them with the saved selection. Boot restore also uses the corrected rules. Existing running helper sessions continue using their old binary until closed.
- Isolated kernel tests cover real UDP delivery at every exception boundary, TCP/443, IPv4/IPv6, mode switches, legacy-rule migration and clearing on nftables and iptables.
Packages for Debian 12+/Ubuntu 24.04+, Fedora, openSUSE and Arch (x86_64), corresponding sources and SHA256SUMS are attached. openSUSE: sudo zypper --no-gpg-checks install ./dropshit-0.1.6-1.x86_64.rpm. Run dropshit as your regular desktop user.
Dropshit v0.1.5
Dropshit 0.1.5: automatic strict single-region mode and automatic application.
- Exactly one game region left allowed: permit its networks and Vivox, reject all other destinations for the user's UDP ports 12000–64000, including unlisted relays.
- Two or more game regions left allowed: use the existing regional blocklist.
- Space toggles and automatically applies changes. No separate apply confirmation; a single authenticated helper session handles serial updates.
aremains a retry shortcut after errors. - Mode, single-region code and network data persist; boot restore, backend migration and clearing support both modes. Old blocklists load compatibly and migrate automatically when only one region remains.
- Packet tests exercise IPv4/IPv6, Vivox, unknown endpoints, TCP and UDP boundaries, strict/blocklist/clear transitions on nftables and iptables.
Packages for Debian 12+/Ubuntu 24.04+, Fedora, openSUSE and Arch (x86_64), corresponding sources and SHA256SUMS are attached. openSUSE: sudo zypper --no-gpg-checks install ./dropshit-0.1.5-1.x86_64.rpm. Run dropshit as your regular desktop user.
Dropshit v0.1.4
Dropshit 0.1.4 (x86_64): fix false "saved firewall rules missing" warning with nftables.
nftables automatically merges adjacent CIDRs into larger prefixes or address ranges. Status checks now read structured nft JSON and compare the actual IPv4/IPv6 address coverage instead of searching for the original CIDR strings. The output hook, owner UID, destination sets, UDP port range and rejection rule are checked too. Missing/changed rules still produce a warning. Existing selections and rules are preserved; no reapplication is required just to fix the status display.
Includes 0.1.3's Amsterdam subnet supplements and official Vivox exclusions. Real isolated-kernel regression tests cover merged prefixes, arbitrary ranges, IPv6 and missing/altered rules.
Packages: DEB for Debian 12+/Ubuntu 24.04+, separate RPMs for Fedora and openSUSE, and Arch .pkg.tar.zst. RPMs are unsigned; openSUSE installation: sudo zypper --no-gpg-checks install ./dropshit-0.1.4-1.x86_64.rpm.
Binaries built on Debian 12 (glibc 2.36). Corresponding sources, source RPMs and SHA256SUMS are attached. Run dropshit as your normal desktop user; reopen after upgrading.
Dropshit v0.1.3
Dropshit 0.1.3 (x86_64): regional subnet coverage and Vivox exclusion.
- Replace Amsterdam's exact
66.40.191.240/32supplement with its currently announced Blizzard66.40.191.0/24route. - Add Amsterdam
5.42.168.0/21from MINA's regional list. Regional inference and source limitations are documented. - Remove misclassified
85.236.97.71/32from US east. Official Vivox ranges85.236.96.0/21and85.236.104.0/23are excluded in the data loader and privileged helper, even inside larger CIDRs. - Authenticated startup status and boot restore clean old saved voice blocks. Reopen Dropshit after upgrading and authorize its initial check; press
ato apply expanded regional coverage when prompted.
Packages: dropshit_0.1.3-1_amd64.deb for Debian 12+/Ubuntu 24.04+, dropshit-0.1.3-1.fc.x86_64.rpm for Fedora, dropshit-0.1.3-1.x86_64.rpm for openSUSE, dropshit-0.1.3-1-x86_64.pkg.tar.zst for Arch. RPMs are unsigned; openSUSE installation: sudo zypper --no-gpg-checks install ./dropshit-0.1.3-1.x86_64.rpm.
Binaries built on Debian 12 (glibc 2.36). Corresponding sources, source RPMs and SHA256SUMS are attached. Run dropshit as your normal desktop user.
Dropshit v0.1.2
Dropshit 0.1.2 (x86_64): adds exact user-observed peers missing from the external network feed: 66.40.191.240/32 to Netherlands and 85.236.97.71/32 to US east. IPinfo and ipwho.is report Amsterdam and Boston respectively. Geographic grouping does not verify a game datacenter code; the Unity-owned Boston peer may be voice traffic. Selecting its region blocks that peer's UDP ports 12000–64000 too. Existing saved selections missing new addresses now show an unapplied warning; press a to update rules. See address provenance.
Download the package appropriate for your distribution:
- Debian 12+ / Ubuntu 24.04+:
dropshit_0.1.2-1_amd64.deb - Fedora:
dropshit-0.1.2-1.fc.x86_64.rpm - openSUSE:
dropshit-0.1.2-1.x86_64.rpm(unsigned; install withsudo zypper --no-gpg-checks install ./dropshit-0.1.2-1.x86_64.rpm) - Arch Linux:
dropshit-0.1.2-1-x86_64.pkg.tar.zst
The binaries were built on Debian 12 (glibc 2.36). The source tarball and source RPM, plus SHA256SUMS, are attached. Run dropshit as your normal user. See README for controls and the distinction between HTTPS-region measurements and game UDP latency.
Dropshit v0.1.1
Dropshit 0.1.1 (x86_64): redesigned terminal UI. The region list now fits the terminal width and height without wrapping; HTTPS addresses and game CIDRs are shown on demand with d, and n/b browse the selected region's CIDRs. Redraws occur when data or input changes instead of continuously. HTTPS latency estimates, firewall backends and saved blocks remain available.
Download the package appropriate for your distribution:
- Debian 12+ / Ubuntu 24.04+:
dropshit_0.1.1-1_amd64.deb - Fedora:
dropshit-0.1.1-1.fc.x86_64.rpm - openSUSE:
dropshit-0.1.1-1.x86_64.rpm(unsigned; install withsudo zypper --no-gpg-checks install ./dropshit-0.1.1-1.x86_64.rpm) - Arch Linux:
dropshit-0.1.1-1-x86_64.pkg.tar.zst
The binaries were built on Debian 12 (glibc 2.36). The source tarball and source RPM, plus SHA256SUMS, are attached. Run dropshit as your normal user. See README for controls and the distinction between HTTPS-region measurements and game UDP latency.
Dropshit v0.1.0
First independent Dropshit Linux release (x86_64). Rust terminal UI, regional HTTPS latency measurements without ICMP, visible game-server network selection, per-user nftables/iptables firewall helper, and warnings for missing saved rules.
Download the package appropriate for your distribution:
- Debian 12+ / Ubuntu 24.04+:
dropshit_0.1.0-1_amd64.deb - Fedora:
dropshit-0.1.0-1.fc.x86_64.rpm - openSUSE:
dropshit-0.1.0-1.x86_64.rpm(unsigned; install withsudo zypper --no-gpg-checks install ./dropshit-0.1.0-1.x86_64.rpm) - Arch Linux:
dropshit-0.1.0-1-x86_64.pkg.tar.zst
The binaries were built on Debian 12 (glibc 2.36). The source tarball and source RPM, plus SHA256SUMS, are attached. Run dropshit as your normal user. See README for controls and the distinction between HTTPS-region measurements and game UDP latency.