Repository navigation
Colitu VPN for Linux v1.1.2
Pre-release
Pre-release
Colitu VPN for Linux 1.1.2: security and reliability update (full audit of the Linux app).
Fixes
- Updates now refresh the VPN cores and rule files. Package upgrades used to leave the cores of the first installed version in
~/.local/share/ColituVPN/bin. - Signing out: a token renewal in flight can no longer bring the session back, a request started before sign-out can no longer wipe the next sign-in or show a false "session expired"; sign-out also removes the imported server profiles and the sudo password.
- Proxy mode on desktops the proxy script can't configure (Sway, Hyprland, bare window managers) no longer reports "connected"; the app asks for TUN mode.
- The watchdog notices when the root sing-box that holds the TUN adapter dies and reconnects.
- Kill switch: the nftables table is replaced in one transaction and the previous root watcher is stopped first; uninstalling removes a left-over table.
Security
- Data folders in the home directory are owner-only (0700) for packaged installs too, and the app runs with umask 077.
sudo,pkexec, the package managers,xdg-openandnotify-sendare run by absolute path; the root kill script no longer comes from a user-writable file.- The core bundle is pinned to a commit of 2dust/v2rayN-core-bin and verified with SHA-256 (Xray 26.9.30, sing-box 1.14.2).
- Share links reject host names that could inject parameters; pings never dial loopback or private addresses; attachment ids are sanitised and downloads size-limited; support diagnostics mask query secrets, e-mails and URL credentials.
- CI: read-only token outside the release job, actions pinned to commits.
Packages
.debdepends on libssl and the X11 libraries and prefers the newest ICU.
Install
Debian/Ubuntu/Mint: .deb · Fedora/RHEL: .rpm · any distribution: .tar.gz. Also at https://colitu.com/downloads/linux/ · guide: https://colitu.com/download/linux · checksums: SHA256SUMS.
Installed 1.0.0+ apps offer this update by themselves (x64).