From 91a4f62068495fbbb0223eb57522088a2474ea62 Mon Sep 17 00:00:00 2001 From: Omar <90123670+mewclouds@users.noreply.github.com> Date: Sat, 19 Sep 2026 18:21:27 -0400 Subject: [PATCH] chore(dns): remove Mullvad DNS providers (#5057) * chore(dns): remove Mullvad DNS providers Mullvad is shutting down its public encrypted DNS servers and sponsoring Quad9 instead, so the six Mullvad profiles would resolve nothing once the servers go dark. Drops the Mullvad entries from config/dns.json, trims them out of the WPFchangedns ComboItems, and removes the matching bullets and the DoH-fallback note from the tweaks guide. Quad9 already ships as a provider, so users have a documented destination. The generated code-reference page for this tweak is left alone; the pre-release workflow regenerates it from config/tweaks.json. * test(dns): use generic fixtures for DoH-only providers The DoH-only and SecondaryDohTemplate paths in Set-WinUtilDNS were covered by fixtures named after Mullvad and carrying its real resolver addresses. Those code paths still exist, so the coverage stays; only the naming was tied to a provider WinUtil no longer ships. Renames the fixtures to DohOnlyProvider and DohOnlyNoSecondary and swaps in RFC 5737 / RFC 3849 documentation addresses and example.com templates, so the tests no longer read as if they exercise a shipped provider. --- config/dns.json | 54 ------------------------- config/tweaks.json | 2 +- docs/src/content/docs/guides/tweaks.mdx | 8 ---- pester/dns.Tests.ps1 | 46 ++++++++++----------- 4 files changed, 24 insertions(+), 86 deletions(-) diff --git a/config/dns.json b/config/dns.json index 5c36a5f6..02499902 100644 --- a/config/dns.json +++ b/config/dns.json @@ -54,59 +54,5 @@ "Primary6": "2a10:50c0::bad1:ff", "Secondary6": "2a10:50c0::bad2:ff", "DohTemplate": "https://family.adguard-dns.com/dns-query" - }, - "Mullvad":{ - "Primary": "194.242.2.2", - "Secondary": "194.242.2.3", - "Primary6": "2a07:e340::2", - "Secondary6": "2a07:e340::3", - "DohOnly": true, - "DohTemplate": "https://dns.mullvad.net/dns-query", - "SecondaryDohTemplate": "https://adblock.dns.mullvad.net/dns-query" - }, - "Mullvad_Ads_Trackers":{ - "Primary": "194.242.2.3", - "Secondary": "194.242.2.2", - "Primary6": "2a07:e340::3", - "Secondary6": "2a07:e340::2", - "DohOnly": true, - "DohTemplate": "https://adblock.dns.mullvad.net/dns-query", - "SecondaryDohTemplate": "https://dns.mullvad.net/dns-query" - }, - "Mullvad_Ads_Trackers_Malware":{ - "Primary": "194.242.2.4", - "Secondary": "194.242.2.3", - "Primary6": "2a07:e340::4", - "Secondary6": "2a07:e340::3", - "DohOnly": true, - "DohTemplate": "https://base.dns.mullvad.net/dns-query", - "SecondaryDohTemplate": "https://adblock.dns.mullvad.net/dns-query" - }, - "Mullvad_Ads_Trackers_Malware_Social":{ - "Primary": "194.242.2.5", - "Secondary": "194.242.2.4", - "Primary6": "2a07:e340::5", - "Secondary6": "2a07:e340::4", - "DohOnly": true, - "DohTemplate": "https://extended.dns.mullvad.net/dns-query", - "SecondaryDohTemplate": "https://base.dns.mullvad.net/dns-query" - }, - "Mullvad_Ads_Trackers_Malware_Adult_Gambling":{ - "Primary": "194.242.2.6", - "Secondary": "194.242.2.5", - "Primary6": "2a07:e340::6", - "Secondary6": "2a07:e340::5", - "DohOnly": true, - "DohTemplate": "https://family.dns.mullvad.net/dns-query", - "SecondaryDohTemplate": "https://extended.dns.mullvad.net/dns-query" - }, - "Mullvad_Ads_Trackers_Malware_Adult_Gambling_Social":{ - "Primary": "194.242.2.9", - "Secondary": "194.242.2.6", - "Primary6": "2a07:e340::9", - "Secondary6": "2a07:e340::6", - "DohOnly": true, - "DohTemplate": "https://all.dns.mullvad.net/dns-query", - "SecondaryDohTemplate": "https://family.dns.mullvad.net/dns-query" } } diff --git a/config/tweaks.json b/config/tweaks.json index 96080560..82e09a03 100644 --- a/config/tweaks.json +++ b/config/tweaks.json @@ -1885,7 +1885,7 @@ "category": "z__Advanced Tweaks - CAUTION", "panel": "1", "Type": "Combobox", - "ComboItems": "Default DHCP Google Cloudflare Cloudflare_Malware Cloudflare_Malware_Adult Open_DNS Quad9 AdGuard_Ads_Trackers AdGuard_Ads_Trackers_Malware_Adult Mullvad Mullvad_Ads_Trackers Mullvad_Ads_Trackers_Malware Mullvad_Ads_Trackers_Malware_Social Mullvad_Ads_Trackers_Malware_Adult_Gambling Mullvad_Ads_Trackers_Malware_Adult_Gambling_Social", + "ComboItems": "Default DHCP Google Cloudflare Cloudflare_Malware Cloudflare_Malware_Adult Open_DNS Quad9 AdGuard_Ads_Trackers AdGuard_Ads_Trackers_Malware_Adult", "link": "https://winutil.christitus.com/code-reference/tweaks/z--advanced-tweaks---caution/changedns" }, "WPFAddUltPerf": { diff --git a/docs/src/content/docs/guides/tweaks.mdx b/docs/src/content/docs/guides/tweaks.mdx index 87d1f551..1c1465e9 100644 --- a/docs/src/content/docs/guides/tweaks.mdx +++ b/docs/src/content/docs/guides/tweaks.mdx @@ -73,14 +73,6 @@ Use the DNS section to switch both IPv4 and IPv6 DNS providers without editing a * [**Quad9**](https://quad9.net/): Focuses on security by blocking known malicious domains. * [**AdGuard_Ads_Trackers**](https://adguard-dns.io/en/welcome.html): AdGuard DNS blocks ads, trackers, and other unwanted DNS requests. Visit the website and sign in for a dashboard, statistics, and additional server-side customization. * [**AdGuard_Ads_Trackers_Malware_Adult**](https://adguard-dns.io/en/welcome.html): AdGuard DNS blocks ads, trackers, malware, and adult content, and enables Safe Search and Safe Mode where possible. -* [**Mullvad**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): Mullvad DNS without content blocking. -* [**Mullvad_Ads_Trackers**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): Blocks ads and trackers. -* [**Mullvad_Ads_Trackers_Malware**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): Blocks ads, trackers, and malware. -* [**Mullvad_Ads_Trackers_Malware_Social**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): Blocks ads, trackers, malware, and social media. -* [**Mullvad_Ads_Trackers_Malware_Adult_Gambling**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): Blocks ads, trackers, malware, adult content, and gambling. -* [**Mullvad_Ads_Trackers_Malware_Adult_Gambling_Social**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): Applies all available Mullvad filters. - -Mullvad profiles require DNS over HTTPS support in Windows. If the selected primary resolver is unavailable, WinUtil uses the closest Mullvad secondary resolver to preserve connectivity; that fallback may use a different filtering level and can be less restrictive. ### Customize Preferences diff --git a/pester/dns.Tests.ps1 b/pester/dns.Tests.ps1 index e1376c6e..e353e1a2 100644 --- a/pester/dns.Tests.ps1 +++ b/pester/dns.Tests.ps1 @@ -53,22 +53,22 @@ Describe "Set-WinUtilDNS" { Secondary6 = "2606:4700:4700::1001" DohTemplate = "https://cloudflare-dns.com/dns-query" } - Mullvad = [pscustomobject]@{ - Primary = "194.242.2.2" - Secondary = "194.242.2.3" - Primary6 = "2a07:e340::2" - Secondary6 = "2a07:e340::3" + DohOnlyProvider = [pscustomobject]@{ + Primary = "192.0.2.1" + Secondary = "192.0.2.2" + Primary6 = "2001:db8::1" + Secondary6 = "2001:db8::2" DohOnly = $true - DohTemplate = "https://dns.mullvad.net/dns-query" - SecondaryDohTemplate = "https://adblock.dns.mullvad.net/dns-query" + DohTemplate = "https://doh.example.com/dns-query" + SecondaryDohTemplate = "https://secondary.doh.example.com/dns-query" } - MullvadNoSecondary = [pscustomobject]@{ - Primary = "194.242.2.2" + DohOnlyNoSecondary = [pscustomobject]@{ + Primary = "192.0.2.1" Secondary = "" - Primary6 = "2a07:e340::2" + Primary6 = "2001:db8::1" Secondary6 = "" DohOnly = $true - DohTemplate = "https://dns.mullvad.net/dns-query" + DohTemplate = "https://doh.example.com/dns-query" } } } @@ -151,58 +151,58 @@ Describe "Set-WinUtilDNS" { } It "filters empty DNS server addresses" { - Set-WinUtilDNS -DNSProvider "MullvadNoSecondary" + Set-WinUtilDNS -DNSProvider "DohOnlyNoSecondary" Should -Invoke -CommandName Set-DnsClientServerAddress -Times 1 -Exactly -ParameterFilter { $InterfaceIndex -eq 7 -and $ServerAddresses.Count -eq 1 -and - $ServerAddresses[0] -eq "194.242.2.2" + $ServerAddresses[0] -eq "192.0.2.1" } Should -Invoke -CommandName Set-DnsClientServerAddress -Times 1 -Exactly -ParameterFilter { $InterfaceIndex -eq 7 -and $ServerAddresses.Count -eq 1 -and - $ServerAddresses[0] -eq "2a07:e340::2" + $ServerAddresses[0] -eq "2001:db8::1" } Should -Invoke -CommandName Add-DnsClientDohServerAddress -Times 2 -Exactly } It "applies the matching DoH template to secondary resolvers" { - Set-WinUtilDNS -DNSProvider "Mullvad" + Set-WinUtilDNS -DNSProvider "DohOnlyProvider" Should -Invoke -CommandName Add-DnsClientDohServerAddress -Times 2 -Exactly -ParameterFilter { - $ServerAddress -in @("194.242.2.2", "2a07:e340::2") -and - $DohTemplate -eq "https://dns.mullvad.net/dns-query" + $ServerAddress -in @("192.0.2.1", "2001:db8::1") -and + $DohTemplate -eq "https://doh.example.com/dns-query" } Should -Invoke -CommandName Add-DnsClientDohServerAddress -Times 2 -Exactly -ParameterFilter { - $ServerAddress -in @("194.242.2.3", "2a07:e340::3") -and - $DohTemplate -eq "https://adblock.dns.mullvad.net/dns-query" + $ServerAddress -in @("192.0.2.2", "2001:db8::2") -and + $DohTemplate -eq "https://secondary.doh.example.com/dns-query" } } It "does not apply a DoH-only provider when DoH is unsupported" { Mock Get-Command { return $null } -ParameterFilter { $Name -eq "Add-DnsClientDohServerAddress" } - $result = Set-WinUtilDNS -DNSProvider "Mullvad" + $result = Set-WinUtilDNS -DNSProvider "DohOnlyProvider" $result | Should -BeFalse Should -Invoke -CommandName Set-DnsClientServerAddress -Times 0 -Exactly Should -Invoke -CommandName Add-DnsClientDohServerAddress -Times 0 -Exactly Should -Invoke -CommandName Write-Warning -Times 1 -Exactly -ParameterFilter { - $Message -eq "DNS provider Mullvad requires DNS over HTTPS, which is not supported on this system." + $Message -eq "DNS provider DohOnlyProvider requires DNS over HTTPS, which is not supported on this system." } } It "does not change adapter DNS when DoH registration fails" { Mock Add-DnsClientDohServerAddress { throw "DoH registration failed" } - $result = Set-WinUtilDNS -DNSProvider "Mullvad" + $result = Set-WinUtilDNS -DNSProvider "DohOnlyProvider" $result | Should -BeFalse Should -Invoke -CommandName Set-DnsClientServerAddress -Times 0 -Exactly Should -Invoke -CommandName Write-WinUtilLog -Times 1 -Exactly -ParameterFilter { $Level -eq "ERROR" -and $Component -eq "DNS" -and - $Message -like "DNS provider Mullvad was not completed: *" + $Message -like "DNS provider DohOnlyProvider was not completed: *" } }