QuickQ on Linux: matching 2.5.0, TUN access for your user, firewall not dropping tun0. Fix permissions with groups, not 777. Scripts only from the download docs.

GUI-as-root lies overnight. Map: guides.

Checklist

ItemPass
Package2.5.0 for this distro
TUNUser in netdev (or equivalent), re-login
Egress1.1.1.1/help IP changed

If smart routing misbehaves, global A/B: mode. Apple contrast: iOS/macOS. Download, FAQ.

Field questions tied to this guide

  • Root works, user does not? Device access, not quota. Group membership, then a real logout.
  • Disable systemd-resolved? Not first. Fix client DNS the same way you would on Windows.
  • Headless CLI? Only if the download page documents it.
  • Firewall? Allow the tun interface and the process. Do not disable the firewall 'to test' on a public VPS and forget.

Change one control, then retest

While working through “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”, write the download-page version, mode, protocol, and node name on the first line of a note. After each toggle, run one check only: 1.1.1.1/help or the exact page that failed. Changing Kill Switch, split rules, and nodes together makes the next failure un-debuggable. Get QuickQ packages only from the download page; permissions and device limits live in the FAQ and guides.

On office or hotel networks, finish captive portals and clear leftover PAC entries before you decide this article’s failure mode applies. A cellular A/B exposes router DNS and parental filters quickly. Avoid hammering login on a second device during the test so session kickouts are not mistaken for radio drops.

Pin the combination that works—SSID, node, protocol—and reuse it on that network instead of starting from Auto every time. Keeping slug qqv-linux-tun-setup as your note title makes the write-up searchable later.

When to stop and change layers

After five identical failures, stop. Recheck the documented build, confirm a single tunnel client, ensure Kill Switch was not blocking a portal, and verify the browser is not Direct in a split list. Stopping is how you escape the wrong layer.

When you ask for help, include time, SSID, mode, protocol, node names, and steps already tried. After recovery, verify egress in a clean browser so cache does not fake success, then write the split list or favorites back into your notes before the next reinstall.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.

Extra pass for “QuickQ on Linux: TUN groups, systemd-resolved, no mystery curl|sh”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging QuickQ.