Mullvad split tunnel doesnt work with flatpak (debian)

Author: NurmagozCreated Sep 3, 2026Updated Sep 6, 2026
LabelsbugLinux

Is it a bug?

  • I know this is an issue with the app, and contacting Mullvad support is not relevant.

I have checked if others have reported this already

  • I have checked the issue tracker to see if others have reported similar issues.

Current Behavior

I have mullvad installed on debian 13 with flatpak apps, the apps installed on user level only (flatpak --user install xxx, not system wide).

What i get when i choose one of the apps from the split tunnel window:

Image
A JavaScript error occurred in the main process 
Uncaught Exception:
Error: spawn mullvad-exclude EACCES
     at Childprocess._handle.onexit (node:internal/child_process:287:19)
     at onErrorNT (node:internal/child_process:508:16)
     at process.processTicksAndRejections (node:internal/process/task_queues:90:21)

Expected Behavior

Apps should be added to exception list easily.

Steps to Reproduce

  1. Install mullvad from the repository on debian 13 trixie on qubes (on admin side (template)/system wide)
  2. Install some flatpak apps with --user (on user side (appvm), not admin)
  3. You should get the same error as mine

Failure Logs

bash
System information:
id: 8fdbbe59-23e7-4898-b38c-2bccbf2dbc05
kernel: 6.18.46-1.qubes.fc41.x86_64
mullvad-product-version: 2026.4
os: Linux Debian GNU/Linux 13 (trixie)
systemd: systemd 257 (257.13-1~deb13u1)
wireguard: 1.0.0

====================
Log: /var/log/mullvad-vpn/daemon.log
====================
[2026-09-02 09:44:07.883]  INFO mullvad_daemon::version: Starting mullvad-daemon - 2026.4 2026-08-17
[2026-09-02 09:44:07.883]  INFO mullvad_daemon: Logging to /var/log/mullvad-vpn/daemon.log
[2026-09-02 09:44:07.929]  INFO mullvad_daemon::settings: Loading settings from /etc/mullvad-vpn/settings.json
[2026-09-02 09:44:07.981]  INFO mullvad_daemon::management_interface: Management interface listening on /var/run/mullvad-vpn
[2026-09-02 09:44:07.981] DEBUG mullvad_api::address_cache: Loading API addresses from /var/cache/mullvad-vpn/api-ip-address.txt
[2026-09-02 09:44:07.981] DEBUG mullvad_api::address_cache: Using API address: [REDACTED]:443
[2026-09-02 09:44:07.987] DEBUG mullvad_api::availability: Pausing background API requests
[2026-09-02 09:44:07.987]  INFO mullvad_daemon::account_history: Opening account history file in /etc/mullvad-vpn/account-history.json
[2026-09-02 09:44:07.989] DEBUG mullvad_daemon::target_state: No cached target state to load
[2026-09-02 09:44:07.996] DEBUG talpid_cgroup::v1: cgroup1 "mullvad-exclusions" created
[2026-09-02 09:44:08.046]  INFO talpid_core::firewall: Resetting firewall policy
[2026-09-02 09:44:08.046] DEBUG talpid_core::firewall::linux: Removing table and chain from netfilter
[2026-09-02 09:44:08.049]  INFO mullvad_daemon::api: Initial offline state - online
[2026-09-02 09:44:08.049] DEBUG mullvad_api::availability: Resuming API requests due to coming online
[2026-09-02 09:44:08.051] DEBUG mullvad_api::access: Fetching access token for an account
[2026-09-02 09:44:08.052] DEBUG mullvad_daemon::version::check: Loading version check cache from /var/cache/mullvad-vpn/version-info.json
[2026-09-02 09:44:08.052] DEBUG mullvad_daemon::geoip: Fetching GeoIpLocation
[2026-09-02 09:44:08.054] DEBUG mullvad_daemon::version::router: Version router started
[2026-09-02 09:44:08.790] DEBUG mullvad_api::availability: Resuming background API requests
[2026-09-02 09:44:09.586] DEBUG mullvad_daemon::relay_list: Writing relays cache to /var/cache/mullvad-vpn/relays.json
[2026-09-02 09:44:09.615] DEBUG mullvad_daemon::management_interface: Broadcasting new relay list
[2026-09-02 09:44:09.628] DEBUG mullvad_daemon: should_update_default_country: false
[2026-09-02 09:44:13.193] DEBUG mullvad_daemon::management_interface: Broadcasting app version info:
Current version supported
[2026-09-02 09:44:13.334] DEBUG mullvad_daemon::management_interface: is_performing_post_upgrade
[2026-09-02 09:44:13.334] DEBUG mullvad_daemon::management_interface: app_upgrade_events_listen
[2026-09-02 09:44:13.347] DEBUG mullvad_daemon::management_interface: get_account_history
[2026-09-02 09:44:13.367] DEBUG mullvad_daemon::management_interface: split_tunnel_is_supported
[2026-09-02 09:44:13.372] DEBUG mullvad_daemon::management_interface: get_tunnel_state
[2026-09-02 09:44:13.396] DEBUG mullvad_daemon::management_interface: get_device
[2026-09-02 09:44:13.408] DEBUG mullvad_daemon::management_interface: get_settings
[2026-09-02 09:44:13.408] DEBUG mullvad_daemon::management_interface: get_account_history
[2026-09-02 09:44:13.408] DEBUG mullvad_daemon::management_interface: get_account_data
[2026-09-02 09:44:13.408] DEBUG mullvad_daemon::management_interface: update_device
[2026-09-02 09:44:13.419] DEBUG mullvad_daemon::management_interface: get_current_api_access_method
[2026-09-02 09:44:13.423] DEBUG mullvad_daemon::management_interface: get_relay_locations
[2026-09-02 09:44:13.503] DEBUG mullvad_daemon::management_interface: get_current_version
[2026-09-02 09:44:13.507] DEBUG mullvad_daemon::management_interface: shadowsocks_ciphers
[2026-09-02 09:44:13.517] DEBUG mullvad_daemon::management_interface: get_version_info
[2026-09-02 09:44:13.518] DEBUG mullvad_daemon::management_interface: connect_tunnel
[2026-09-02 09:44:13.518] DEBUG mullvad_daemon: Target state Unsecured => Secured
[2026-09-02 09:44:13.524]  INFO talpid_core::firewall: Applying firewall policy: Connecting to { [REDACTED]:443/UDP }, Blocking LAN, interface: none. Allowing endpoint [REDACTED]:443/TCP
[2026-09-02 09:44:13.533] DEBUG mullvad_daemon: New tunnel state: Connecting { endpoint: TunnelEndpoint { endpoint: Endpoint { address: [REDACTED]:45814, protocol: Udp }, quantum_resistant: true, obfuscation: Some(Single(ObfuscationEndpoint { endpoint: Endpoint { address: [REDACTED]:443, protocol: Udp }, obfuscation_type: Quic })), entry_endpoint: None, tunnel_interface: None, daita: false }, location: Some(GeoIpLocation { ipv4: None, ipv6: None, country: "Sweden", city: Some("Stockholm"), latitude: 59.3289, longitude: 18.0649, mullvad_exit_ip: true, hostname: Some("se-sto-wg-201"), entry_hostname: None }), feature_indicators: FeatureIndicators(["Dns Content Blocker", "Quantum Resistance", "Quic"]) }
[2026-09-02 09:44:13.533] DEBUG mullvad_daemon: Settings: , wg mtu: unset, wg ip version: IPv4, multihop: off, ipv6 (tun): off, lan: off, pq: on, obfs: quic, dns: ads trackers malware gambling
[2026-09-02 09:44:13.543] DEBUG talpid_wireguard: Tunnel MTU: 1380
[2026-09-02 09:44:13.546] DEBUG talpid_wireguard: Using kernel WireGuard implementation through netlink
[2026-09-02 09:44:13.590]  INFO talpid_core::firewall: Applying firewall policy: Connecting to { [REDACTED]:443/UDP } over "wg0-mullvad" (ip: [REDACTED], v4 gw: [REDACTED], v6 gw: None, allowed in-tunnel traffic: [REDACTED]:1337/TCP), Blocking LAN. Allowing endpoint [REDACTED]:443/TCP
[2026-09-02 09:44:13.600] DEBUG talpid_routing::imp::imp: Adding routes: {RequiredRoute { prefix: V4(Ipv4Network { addr: [REDACTED], prefix: 32 }), node: RealNode(Node { ip: None, device: Some("wg0-mullvad") }), main_table: true, mtu: None }}
[2026-09-02 09:44:13.600] DEBUG talpid_wireguard::ephemeral: Requesting ephemeral peer
[2026-09-02 09:44:13.600] DEBUG talpid_tunnel_config_client: Connecting to relay config service at [REDACTED]
[2026-09-02 09:44:13.600] DEBUG talpid_tunnel_config_client::socket::sys: Tunnel config TCP socket MSS: 496
[2026-09-02 09:44:13.710] DEBUG mullvad_daemon::device: The current device is still valid
[2026-09-02 09:44:13.844] DEBUG mullvad_masque_proxy::client: UDP GSO disabled
[2026-09-02 09:44:14.124] DEBUG talpid_tunnel_config_client: Connected to relay config service at [REDACTED]
[2026-09-02 09:44:14.147] DEBUG mullvad_daemon::management_interface: get_version_info
[2026-09-02 09:44:14.155] DEBUG talpid_tunnel_config_client: Generated quantum-resistant key exchange material in 30 ms
[2026-09-02 09:44:14.778] DEBUG talpid_wireguard::ephemeral: Retrieved ephemeral peer
[2026-09-02 09:44:14.778] DEBUG talpid_tunnel_config_client::socket_sniffer: Tunnel config client connection ended. RX: 16128 bytes, TX: 9145 bytes, duration: 0 s
[2026-09-02 09:44:14.780] DEBUG mullvad_masque_proxy::stats: stats: Stats { rx_packets: 54, tx_packets: 39, rx_bytes: 20460, tx_bytes: 12363, fragmented_tx_bytes: 0, fragmented_rx_bytes: 0, fragmented_tx_packets: 0, fragmented_rx_packets: 0 }
[2026-09-02 09:44:14.804]  INFO talpid_core::firewall: Applying firewall policy: Connecting to { [REDACTED]:443/UDP } over "wg0-mullvad" (ip: [REDACTED], v4 gw: [REDACTED], v6 gw: None, allowed in-tunnel traffic: All), Blocking LAN. Allowing endpoint [REDACTED]:443/TCP
[2026-09-02 09:44:14.824] DEBUG talpid_wireguard::mtu_detection: Starting MTU detection
[2026-09-02 09:44:15.061] DEBUG mullvad_masque_proxy::client: UDP GSO disabled
[2026-09-02 09:44:15.204] DEBUG talpid_routing::imp::imp: Adding routes: {RequiredRoute { prefix: V4(Ipv4Network { addr: [REDACTED], prefix: 0 }), node: RealNode(Node { ip: None, device: Some("wg0-mullvad") }), main_table: false, mtu: None }}
[2026-09-02 09:44:15.204]  INFO talpid_core::firewall: Applying firewall policy: Connected to { [REDACTED]:443/UDP } over "wg0-mullvad" (ip: [REDACTED], v4 gw: [REDACTED], v6 gw: None), Blocking LAN
[2026-09-02 09:44:15.209]  INFO talpid_dns: Setting DNS servers: Tunnel DNS: {[REDACTED]} Non-tunnel DNS: {}
[2026-09-02 09:44:15.210] DEBUG talpid_dns::imp: Can't manage DNS using systemd-resolved: systemd-resolved operation failed
[2026-09-02 09:44:15.210] DEBUG talpid_dns::imp: Can't manage DNS using NetworkManager: Error while communicating over Dbus
[2026-09-02 09:44:15.219] DEBUG talpid_dns::imp: Can't manage DNS using resolveconf: Failed to detect 'resolvconf' program
[2026-09-02 09:44:15.219] DEBUG talpid_dns::imp::static_resolv_conf: No DNS state backup to restore
[2026-09-02 09:44:15.219] DEBUG talpid_dns::imp: Managing DNS via /etc/resolv.conf
[2026-09-02 09:44:15.219] DEBUG mullvad_daemon: New tunnel state: Connected { endpoint: TunnelEndpoint { endpoint: Endpoint { address: [REDACTED]:45814, protocol: Udp }, quantum_resistant: true, obfuscation: Some(Single(ObfuscationEndpoint { endpoint: Endpoint { address: [REDACTED]:443, protocol: Udp }, obfuscation_type: Quic })), entry_endpoint: None, tunnel_interface: Some("wg0-mullvad"), daita: false }, location: Some(GeoIpLocation { ipv4: None, ipv6: None, country: "Sweden", city: Some("Stockholm"), latitude: 59.3289, longitude: 18.0649, mullvad_exit_ip: true, hostname: Some("se-sto-wg-201"), entry_hostname: None }), feature_indicators: FeatureIndicators(["Dns Content Blocker", "Quantum Resistance", "Quic"]) }
[2026-09-02 09:44:15.219] DEBUG mullvad_daemon::geoip: Fetching GeoIpLocation
[2026-09-02 09:44:15.621] DEBUG talpid_wireguard::mtu_detection: MTU 1380 verified to not drop packets
[2026-09-02 09:44:20.220] DEBUG mullvad_daemon::leak_checker: Attempting to leak traffic on interface Name("eth0") to [REDACTED]:45814/UDP
[2026-09-02 09:44:20.220] DEBUG mullvad_leak_checker::traceroute::unix::linux: Binding socket to Name("eth0")
[2026-09-02 09:44:20.220] DEBUG mullvad_leak_checker::traceroute::unix: Sending probe packets (ttl=1..4)
[2026-09-02 09:44:20.220] DEBUG mullvad_leak_checker::traceroute::unix: send_to failed, was probably caught by firewall
[2026-09-02 09:44:25.222] DEBUG mullvad_daemon::leak_checker: No leak detected
[2026-09-02 09:44:36.157] DEBUG mullvad_daemon::management_interface: set_lockdown_mode(true)
[2026-09-02 09:44:36.157] DEBUG mullvad_daemon::settings: Writing settings to /etc/mullvad-vpn/settings.json
[2026-09-02 09:44:36.168] DEBUG mullvad_daemon::management_interface: Broadcasting new settings
[2026-09-02 09:45:21.998] DEBUG mullvad_daemon::management_interface: set_relay_settings
[2026-09-02 09:45:21.998] DEBUG mullvad_types::settings: Changing relay settings:
	from: Tunnel protocol: wireguard
Wireguard constraints: , IPv4,
Location: country se
Provider(s): any
Ownership: any
	to: Tunnel protocol: wireguard
Wireguard constraints: , IPv6,
Location: country se
Provider(s): any
Ownership: any
[2026-09-02 09:45:21.998] DEBUG mullvad_daemon::settings: Writing settings to /etc/mullvad-vpn/settings.json
[2026-09-02 09:45:22.024] DEBUG mullvad_daemon::management_interface: Broadcasting new settings
[2026-09-02 09:45:22.024]  INFO mullvad_daemon: Initiating tunnel restart because the relay settings changed
[2026-09-02 09:45:22.025]  INFO talpid_dns: Resetting DNS
[2026-09-02 09:45:22.025] DEBUG talpid_routing::imp::imp: Clearing routes
[2026-09-02 09:45:22.025] DEBUG mullvad_daemon: New tunnel state: Disconnecting(Reconnect)
[2026-09-02 09:45:22.025] DEBUG talpid_wireguard: Tunnel was closed: Ok(
    Stop,
)
[2026-09-02 09:45:22.181] DEBUG talpid_core::tunnel_state_machine::connecting_state: Tunnel monitor exited with block reason: None
[2026-09-02 09:45:22.181] DEBUG mullvad_masque_proxy::stats: stats: Stats { rx_packets: 72, tx_packets: 108, rx_bytes: 49830, tx_bytes: 48532, fragmented_tx_bytes: 5580, fragmented_rx_bytes: 4266, fragmented_tx_packets: 8, fragmented_rx_packets: 6 }
[2026-09-02 09:45:22.182] ERROR mullvad_daemon::tunnel: Error: Failed to generate tunnel parameters
Caused by: Failed to select a matching relay
Caused by: The requested IP version (IPv6) does not match ip availability
[2026-09-02 09:45:22.182]  INFO talpid_core::firewall: Applying firewall policy: Blocked. Blocking LAN. Allowing endpoint: [REDACTED]:443/TCP
[2026-09-02 09:45:22.185] DEBUG mullvad_daemon: New tunnel state: Error(ErrorState { cause: TunnelParameterError(IpVersionUnavailable { family: V6 }), block_failure: None })
[2026-09-02 09:45:22.185]  INFO mullvad_daemon: Blocking all network connections, reason: Failure to generate tunnel parameters: The requested IP version (IPv6) is not available
[2026-09-02 09:45:44.532] DEBUG mullvad_daemon::management_interface: set_relay_settings
[2026-09-02 09:45:44.532] DEBUG mullvad_types::settings: Changing relay settings:
	from: Tunnel protocol: wireguard
Wireguard constraints: , IPv6,
Location: country se
Provider(s): any
Ownership: any
	to: Tunnel protocol: wireguard
Wireguard constraints: , IPv4,
Location: country se
Provider(s): any
Ownership: any
[2026-09-02 09:45:44.532] DEBUG mullvad_daemon::settings: Writing settings to /etc/mullvad-vpn/settings.json
[2026-09-02 09:45:44.551] DEBUG mullvad_daemon::management_interface: Broadcasting new settings
[2026-09-02 09:45:44.551]  INFO mullvad_daemon: Initiating tunnel restart because the relay settings changed
[2026-09-02 09:45:44.551]  INFO talpid_dns: Resetting DNS
[2026-09-02 09:45:44.553]  INFO talpid_core::firewall: Applying firewall policy: Connecting to { [REDACTED]:443/UDP }, Blocking LAN, interface: none. Allowing endpoint [REDACTED]:443/TCP
[2026-09-02 09:45:44.563] DEBUG mullvad_daemon: New tunnel state: Connecting { endpoint: TunnelEndpoint { endpoint: Endpoint { address: [REDACTED]:43154, protocol: Udp }, quantum_resistant: true, obfuscation: Some(Single(ObfuscationEndpoint { endpoint: Endpoint { address: [REDACTED]:443, protocol: Udp }, obfuscation_type: Quic })), entry_endpoint: None, tunnel_interface: None, daita: false }, location: Some(GeoIpLocation { ipv4: None, ipv6: None, country: "Sweden", city: Some("Stockholm"), latitude: 59.3289, longitude: 18.0649, mullvad_exit_ip: true, hostname: Some("se-sto-wg-209"), entry_hostname: None }), feature_indicators: FeatureIndicators(["Dns Content Blocker", "Lockdown Mode", "Quantum Resistance", "Quic"]) }
[2026-09-02 09:45:44.563] DEBUG mullvad_daemon: Settings: , wg mtu: unset, wg ip version: IPv4, multihop: off, ipv6 (tun): off, lan: off, pq: on, obfs: quic, dns: ads trackers malware gambling
[2026-09-02 09:45:44.564] DEBUG talpid_wireguard: Tunnel MTU: 1380
[2026-09-02 09:45:44.566] DEBUG talpid_wireguard: Using kernel WireGuard implementation through netlink
[2026-09-02 09:45:44.583]  INFO talpid_core::firewall: Applying firewall policy: Connecting to { [REDACTED]:443/UDP } over "wg0-mullvad" (ip: [REDACTED], v4 gw: [REDACTED], v6 gw: None, allowed in-tunnel traffic: [REDACTED]:1337/TCP), Blocking LAN. Allowing endpoint [REDACTED]:443/TCP
[2026-09-02 09:45:44.587] DEBUG talpid_routing::imp::imp: Adding routes: {RequiredRoute { prefix: V4(Ipv4Network { addr: [REDACTED], prefix: 32 }), node: RealNode(Node { ip: None, device: Some("wg0-mullvad") }), main_table: true, mtu: None }}
[2026-09-02 09:45:44.587] DEBUG talpid_wireguard::ephemeral: Requesting ephemeral peer
[2026-09-02 09:45:44.587] DEBUG talpid_tunnel_config_client: Connecting to relay config service at [REDACTED]
[2026-09-02 09:45:44.587] DEBUG talpid_tunnel_config_client::socket::sys: Tunnel config TCP socket MSS: 496
[2026-09-02 09:45:44.868] DEBUG mullvad_masque_proxy::client: UDP GSO disabled
[2026-09-02 09:45:45.165] DEBUG talpid_tunnel_config_client: Connected to relay config service at [REDACTED]
[2026-09-02 09:45:45.178] DEBUG talpid_tunnel_config_client: Generated quantum-resistant key exchange material in 13 ms
[2026-09-02 09:45:45.804] DEBUG talpid_wireguard::ephemeral: Retrieved ephemeral peer
[2026-09-02 09:45:45.804] DEBUG talpid_tunnel_config_client::socket_sniffer: Tunnel config client connection ended. RX: 16128 bytes, TX: 9145 bytes, duration: 0 s
[2026-09-02 09:45:45.804] DEBUG mullvad_masque_proxy::stats: stats: Stats { rx_packets: 52, tx_packets: 39, rx_bytes: 20300, tx_bytes: 12363, fragmented_tx_bytes: 0, fragmented_rx_bytes: 0, fragmented_tx_packets: 0, fragmented_rx_packets: 0 }
[2026-09-02 09:45:45.817]  INFO talpid_core::firewall: Applying firewall policy: Connecting to { [REDACTED]:443/UDP } over "wg0-mullvad" (ip: [REDACTED], v4 gw: [REDACTED], v6 gw: None, allowed in-tunnel traffic: All), Blocking LAN. Allowing endpoint [REDACTED]:443/TCP
[2026-09-02 09:45:45.822] DEBUG talpid_wireguard::mtu_detection: Starting MTU detection
[2026-09-02 09:45:46.092] DEBUG mullvad_masque_proxy::client: UDP GSO disabled
[2026-09-02 09:45:46.243] DEBUG talpid_routing::imp::imp: Adding routes: {RequiredRoute { prefix: V4(Ipv4Network { addr: [REDACTED], prefix: 0 }), node: RealNode(Node { ip: None, device: Some("wg0-mullvad") }), main_table: false, mtu: None }}
[2026-09-02 09:45:46.244]  INFO talpid_core::firewall: Applying firewall policy: Connected to { [REDACTED]:443/UDP } over "wg0-mullvad" (ip: [REDACTED], v4 gw: [REDACTED], v6 gw: None), Blocking LAN
[2026-09-02 09:45:46.253]  INFO talpid_dns: Setting DNS servers: Tunnel DNS: {[REDACTED]} Non-tunnel DNS: {}
[2026-09-02 09:45:46.253] DEBUG talpid_dns::imp: Can't manage DNS using systemd-resolved: systemd-resolved operation failed
[2026-09-02 09:45:46.254] DEBUG talpid_dns::imp: Can't manage DNS using NetworkManager: Error while communicating over Dbus
[2026-09-02 09:45:46.254] DEBUG talpid_dns::imp: Can't manage DNS using resolveconf: Failed to detect 'resolvconf' program
[2026-09-02 09:45:46.254] DEBUG talpid_dns::imp::static_resolv_conf: No DNS state backup to restore
[2026-09-02 09:45:46.254] DEBUG talpid_dns::imp: Managing DNS via /etc/resolv.conf
[2026-09-02 09:45:46.254] DEBUG mullvad_daemon: New tunnel state: Connected { endpoint: TunnelEndpoint { endpoint: Endpoint { address: [REDACTED]:43154, protocol: Udp }, quantum_resistant: true, obfuscation: Some(Single(ObfuscationEndpoint { endpoint: Endpoint { address: [REDACTED]:443, protocol: Udp }, obfuscation_type: Quic })), entry_endpoint: None, tunnel_interface: Some("wg0-mullvad"), daita: false }, location: Some(GeoIpLocation { ipv4: None, ipv6: None, country: "Sweden", city: Some("Stockholm"), latitude: 59.3289, longitude: 18.0649, mullvad_exit_ip: true, hostname: Some("se-sto-wg-209"), entry_hostname: None }), feature_indicators: FeatureIndicators(["Dns Content Blocker", "Lockdown Mode", "Quantum Resistance", "Quic"]) }
[2026-09-02 09:45:46.254] DEBUG mullvad_daemon::geoip: Fetching GeoIpLocatio