Tenebra

Divaaaan·Divaaaan.Tenebra

Open-source VPN client for Windows built on sing-box

Tenebra is an open-source VPN client for Windows built on the sing-box core. It provides a simple desktop interface for managing secure network connections.

winget install --id Divaaaan.Tenebra --exact --source winget

Latest 0.6.1·September 16, 2026

Release Notes

Tenebra 0.6.1

This desktop hotfix prevents failures in Tenebra's on-connect, multi-destination node validation from being reported as an all-servers-unreachable result. It also makes failures in the server list's separate direct TCP status checks visible and prevents one incompatible subscription node from invalidating the shared sing-box configuration.

• The on-connect validation reserves a free contiguous block of loopback ports instead of relying on a fixed range that another local process may already own. • Its temporary SOCKS listeners use fresh credentials, and readiness is confirmed with an authenticated SOCKS negotiation. A foreign listener can no longer be accepted as Tenebra's probe merely because it answers on the expected port. • The core watches this validation's probe process throughout startup and measurement. Detected startup failures, bind races and early process exits now stop validation with a local error rather than returning an all-servers-unreachable verdict. • Probe stdout and stderr are retained in a bounded tail for diagnosis and are scrubbed before being logged or returned through the control interface. • Imported VLESS URLs with unsupported stream transports, including xhttp, are excluded before the shared probe or tunnel configuration is built. VLESS nodes using QUIC without its required TLS are excluded for the same reason, while compatible VLESS QUIC nodes remain supported. Other usable nodes in the profile stay available. • Separately, the server list shows whether its direct TCP status checks are in progress, ready or failed and provides a retry action. An earlier successful RTT may remain visible while a refresh runs or fails, but it is marked stale and is not counted or rendered as a current signal-strength result.

Verification scope

Automated tests cover the on-connect validation's probe ownership, lifecycle and port races, authenticated readiness, bounded log capture and the bundled sing-box configuration, builder-level unsupported-transport isolation and compatible VLESS QUIC, plus the server list's direct TCP states. The affected profile reproduced the original failure in a retained Windows VM:one xhttp entry made the bundled sing-box reject the shared configuration with unknown transport type:xhttp, blocking otherwise usable nodes. Native installation, service, ordinary-user UI and tunnel checks of the exact rebuilt signed candidate remain required before publication.

Installer type: nullsoft

x64—FCA08044995FE746F7CA1C97A6019CD1A0C9EF516F47C206CB74F8D32D472E84

Details

Homepage
https://github.com/Divaaaan/tenebra
License
GPL-3.0
Publisher
Divaaaan
Support
https://github.com/Divaaaan/tenebra/issues
Moniker
tenebra

Tags

vpnproxysing-boxnetworkprivacysecuritytunnel

Older versions (10)

0.6.0
x64—23D4F4B4895810F3948E35143E71F27C219EE7CC83FB73264CBCEA2946955F9D
0.5.11
x64—D39A3B0EC1D393F3ECA7DB87F190B50E6F76DC17D2A4E90BD39259BEA0EF527F
0.5.10
x64—E26CB40CD677C2487F71CD4C4AD9AA4A3E6BAC7BB4B081778C01E9525270A91E
0.5.4
x64—72D9EC9435257E7B82C0C02094796F6F1363AA48B2FC07C14DCEF912E042D731
0.5.2
x64—1F7F4ADCF5E4450213D31E0D924047F265707833BD2A273255143603BC6FD557
0.5.1
x64—A71D537A63538225C68622B0E359F30F42D5ACDE2FE1BD6D035873BBB95360F2
0.5.0
x64—0A8DB3A8CFF376B5030F98E370821119BB1F0259CCF0FD0CFA5AD4ADF473B482
0.4.6
x64—51B2B171ADBA901A2E324F9FCF2A3328635F72276394A0EF58F122FB1AAA91F3
0.4.5
x64—A7D77C3C4868BFD5D92B1E8384C3C6F6A22E9D7DC2E7B8CEA0FF2121A59F2D3F
0.3.0
x64—FC36C35F746D214A8EEBF86EADA06FAF336A869620CA22B2F6CA2920C6B0E724