sagitchu
3373e5ade9
fix: preserve shared limiters with per-IP rules
2026-04-28 00:18:32 +08:00
sagitchu
46394388b1
feat: sync per-IP runtime limiters
2026-04-27 22:32:35 +08:00
sagitchu
dec337d46b
fix: enforce per-IP speed update permissions
2026-04-27 22:26:34 +08:00
sagitchu
9e8d27d98e
feat: expose per-IP forward limit fields
2026-04-27 22:20:26 +08:00
sagitchu
a2000e4d98
fix: preserve per-IP forward limits during rollback
2026-04-27 22:16:38 +08:00
sagitchu
2b76a9f0be
feat: persist per-IP forward limits
2026-04-27 22:07:04 +08:00
sagit
2ca3849917
fix: apply proxy protocol and max connection settings
2026-04-27 10:54:25 +08:00
sagit
58d2e89147
fix: reduce reconnect redeploy and metrics load ( #476 )
...
* fix: reduce reconnect redeploy and metrics load
Throttle node-online redeploy retries and lower the agent metric cadence so brief reconnect churn no longer fans out into repeated runtime syncs and backend connection pressure.
* docs: add follow-up implementation design notes
Document the planned flow upload batching work and the local remote-address toggle so the next changesets can implement them against an agreed design.
2026-04-26 23:35:35 +08:00
sagit
87a1a34ad5
refactor: batch flow upload processing ( #474 )
...
* test: cover flow upload batch semantics
* refactor: batch flow upload persistence
* refactor: batch flow upload processing
* test: harden flow upload batch regression coverage
2026-04-26 20:45:48 +08:00
sagit
799bb66fe5
feat: add local remote address toggle ( #472 )
2026-04-26 16:30:05 +08:00
sagit
3f374df724
fix: 保留用户/规则高级设置并增强节点运行时恢复 ( #468 )
...
* fix: 用户编辑时 maxConn 字段未正确回填
- User 接口添加 maxConn 类型定义
- handleEdit 中回填 maxConn 值
- normalizeUserItem 添加 maxConn 字段处理
解决编辑用户时最大连接数显示为 0 的问题
* fix: 保留转发设置并增强节点运行时恢复
2026-04-25 18:12:13 +08:00
sagit
c259645227
feat: implement user and forward max connection limit ( #461 )
...
* docs: add implementation plan for max conn limit
* feat: add CLimiters support for websocket reporter
* feat: add max_conn field to user and forward models
* feat: implement max conn limiter dispatching
* feat: add maxConn to user and forward CRUD API
* feat: add max conn UI to user management and forward rules
* fix: load MaxConn in get forward record and add e2e contract test for max conn limit
2026-04-23 17:35:39 +08:00
sagitchu
bdc2c4ecbb
fix(backend): dynamically start/stop tunnel quality prober based on config
2026-04-23 14:14:24 +08:00
sagitchu
a070d0f4d3
fix(backend): allow setting reserved ip addresses as target
...
Only forbid internal networks (loopback and private ips), removing restrictions on reserved addresses like multicast or unspecified.
2026-04-22 19:00:21 +08:00
sagitchu
eecdd62d3a
perf(backend): optimize kcp tunnel parameters for high throughput and low latency
2026-04-22 16:29:02 +08:00
sagitchu
e6d3b847bb
fix(backend): properly identify and clean up orphaned tunnel_%d services
2026-04-22 16:18:57 +08:00
sagitchu
0b49cd720f
fix(backend): use proper protocol for chain hop diagnosis and tcp for external targets
2026-04-22 14:02:59 +08:00
sagitchu
4f488ae7ef
fix(backend): properly implement tunnel_%d cleanup that was lost during revert
2026-04-22 11:32:49 +08:00
sagitchu
efaf920e51
fix: ensure rollbackTunnelRuntime includes tunnel_%d in cleanup
2026-04-22 09:51:35 +08:00
sagitchu
9aff669c0e
fix: ensure tunnel protocol and KCP config are correctly processed and cleaned up
2026-04-22 09:41:41 +08:00
sagitchu
f3d6366471
fix: increase kcp tunnel bandwidth limit and fix modal backgrounds
2026-04-21 20:16:58 +08:00
sagitchu
c431d79403
fix: correct tunnel protocol handling for KCP cleanup and diagnosis
...
- Fix KCP tunnel not reclaimed after deletion: service name was
hardcoded to {id}_tls but services were created as {id}_kcp,
causing DeleteService to never find the actual KCP service.
Now reads tunnel.Protocol from DB and derives correct name.
- Fix KCP diagnosis using TCP ping instead of UDP ping:
tunnel.Protocol was always hardcoded to 'tls' at creation,
so isUDPBasedProtocol() never matched kcp tunnels. Now
stores the actual protocol from entry node configuration.
- Fix addTunnelServiceOnNode to extract service name from
serviceData instead of hardcoding _tls suffix.
- Fix rollbackTunnelRuntime to accept protocol parameter
so retry cleanup uses correct service name.
- UpdateTunnelTx now persists protocol on tunnel updates.
2026-04-21 18:48:11 +08:00
sagitchu
5107f59d94
fix: tolerate offline nodes when controlling forward services and editing tunnels
...
- controlForwardServices: skip offline nodes instead of failing entire operation,
so forward pause/resume/delete works when some entry nodes are offline
- onNodeOnline: always sync forward state on node reconnect (not just post-upgrade),
so forwards that changed status while a node was offline get synced
- add ListForwardIDsByNode repo method to sync all forwards (including paused)
- tunnel edit UI: allow deselecting already-selected offline nodes in
entry/chain/exit selectors, matching the backend's existing tolerance
2026-04-21 16:53:47 +08:00
sagitchu
c1bc795674
fix(kcp): enable congestion control, add FEC, and fix remote node UDP diagnosis
...
- KCP: switch from fast3 to fast2 mode, enable FEC (10/3), enable
congestion control (nc=0) for automatic rate adaptation
- go-gost/x: support kcp.nc metadata to override mode-initialized
NoCongestion value in dialer and listener Init()
- Diagnosis: add udpPingViaRemoteNode, fix pingViaRemoteNode to
dispatch based on protocol, add Protocol field to federation
diagnose request structs
2026-04-21 15:41:32 +08:00
sagitchu
30e1473f06
fix(traffic): fix flow counter inflation from TOCTOU race in agent traffic reporter
...
Replace read-then-subtract pattern in collectAndReport with atomic
swap-to-zero to eliminate race where AddTraffic increments counters
between snapshot and clearReportedTraffic, causing residual traffic
to accumulate indefinitely and inflate user flow counters.
Also add defensive check in processFlowItem to skip AddFlow when
forward no longer exists, and send DeleteService to clean up orphaned
agent services.
2026-04-21 14:32:08 +08:00
sagitchu
e995d70be7
feat(diagnosis): add protocol-aware connectivity diagnosis for tunnel chains
...
- Pass tunnel protocol through diagnosis work items
- Support protocol-specific ping (TCP/UDP/KCP) via remote nodes
- Add KCP probe support in websocket_reporter for chain hop testing
2026-04-21 14:00:02 +08:00
sagitchu
29407c90b6
perf(kcp): optimize tunnel transport defaults for high throughput
...
- Set KCP mode to fast3 (NoDelay:1, Interval:10ms) for lower latency
- Double SndWnd/RcvWnd from 1024 to 2048 for higher BDP
- Disable FEC (datashard:0, parityshard:0) to eliminate 30% overhead
- Disable compression for tunnel transport
- Increase relay mux MaxStreamBuffer to 2MB for better UDP throughput
- Add kcp.datashard/kcp.parityshard metadata keys support
Before: 210Mbps TCP / 35Mbps UDP (93% loss)
After: should approach direct-connection speed (~400Mbps+)
2026-04-21 11:33:41 +08:00
sagitchu
288c5d7152
fix: restore SSRF/security protections after glass UI cherry-pick
2026-04-21 09:20:04 +08:00
sagitchu
96fc790ed7
feat: add global background image setting to config page
2026-04-21 09:19:02 +08:00
sagitchu
630e012ec1
fix(tunnel): resolve UDP stream interruption and add KCP protocol support
...
- Increase UDP listener default TTL from 5s to 30s to prevent idle disconnect
- Add mux keepalive config (15s interval, 45s timeout) to tunnel relay handler
- Add KCP as tunnel chain transport protocol with keepalive and UDP mode default
- Add KCP protocol option to tunnel UI (frontend)
- Remove generic 'tcp' fallback key from KCP metadata to prevent false TCP mode
- Simplify forward service config by removing unused tunnelTLSProtocol parameter
2026-04-20 23:57:43 +08:00
sagitchu
8611748c46
fix(security): patch SSRF and info disclosure vulnerabilities
2026-04-20 11:31:17 +08:00
sagit
9a85363e44
feat: Announcement Popup Notification ( #411 )
...
* docs: add announcement popup design spec
* docs: add announcement popup implementation plan
* feat(api): include update_time in announcement response
* feat(ui): add update_time to AnnouncementData interface
* feat(ui): create AnnouncementModal component
* feat(ui): manage announcement modal state in dashboard hook
* feat(ui): add announcement modal to dashboard layout
2026-04-04 13:00:11 +08:00
sagitchu
1b3ae44940
feat: show license expiry date when commercial license is activated
2026-04-03 17:37:05 +08:00
sagitchu
3da9b14bfe
fix(backend): prevent idle transaction timeout in postgresql during tunnel update
2026-04-03 15:52:48 +08:00
sagit
49ab2915ee
feat: commercial white-label support ( #403 )
...
* fix: increase updateTunnel timeout to 120s
Editing tunnel entry nodes triggers forward sync to all entry nodes.
If nodes are offline or many forwards exist, the sync can exceed
the default 30s timeout. Match the timeout used by other heavy
operations like batchDeleteTunnels.
* docs: add commercial white-label design spec
* docs: add commercial white-label implementation plan
* feat: add license activation endpoint and authorization check for commercial config keys
* feat: add frontend api and update site config state for license
* feat: conditionally hide flvx footer brand
* feat: ui settings for commercial white-label and license activation
* fix: add missing licenseActivateRequest and fix GetConfig in handler.go
* docs: add keygen.sh license integration design spec
* docs: add keygen.sh integration implementation plan
* feat: add machine fingerprint generation
* feat: add keygen.sh api client
* feat: integrate keygen into license activation endpoint
* feat: add periodic license validation job
* fix: remove accidentally leaked dash kernel test codes that caused compilation failures
* fix: correct keygen validation scope and binding logic
* feat: hardcode Keygen.sh account ID
* fix: relax strict validation matching after successful machine activation
2026-04-03 07:23:22 +00:00
sagitchu
608fbf74de
fix(backend): randomize new tunnel relay ports safely
2026-04-01 20:16:31 +08:00
sagit
8b9cdef0e4
feat: add configurable GitHub proxy settings ( #401 )
...
* docs: add GitHub proxy config design spec
* docs: add GitHub proxy config implementation plan
* feat(backend): use configurable github proxy for node upgrades
* feat(backend): use configurable github proxy for node install command
* feat(frontend): add github proxy config settings
* feat(script): support configurable github proxy in installer flows
Honor custom GitHub mirror settings across interactive and env-driven installer/update paths so script downloads match the panel configuration. Add shell regressions to lock down proxy prompting, URL recomputation, and non-interactive fallback behavior.
2026-04-01 15:59:44 +08:00
qimaoww
841d43344a
fix(backend): 修复转发监听 IP 为 IPv6 时报missing port in address ( #397 )
...
* fix(backend): handle IPv6 forward bind IP ports
* test(handler): add IPv6 bindIP test cases for forward service config
---------
Co-authored-by: sagit <36596628+Sagit-chu@users.noreply.github.com >
Co-authored-by: sagitchu <sagitchu@gmail.com >
2026-03-31 03:24:56 +00:00
sagit
5efe790937
fix: 实现用户端口数量限制验证 ( #399 )
...
- 在 ensureUserTunnelForwardAllowed 中添加 User.Num 限制验证
- 在 ensureUserTunnelForwardAllowed 中添加 UserTunnel.Num 限制验证
- 新增 CountActiveForwardsByUser 和 CountActiveForwardsByUserTunnel 函数
- 添加转发数量限制的契约测试
Closes #390
2026-03-31 02:52:49 +00:00
sagit
87722e461c
feat(monitor): hop-by-hop latency metrics for forwarding chain ( #394 )
2026-03-29 18:59:06 +08:00
sagitchu
103290ed35
fix: 节点离线时允许删除隧道关联,但禁止新增隧道 ( #342 )
...
- prepareTunnelCreateState: 更新隧道时允许已关联的离线节点,仅拒绝新增的离线节点
- syncForwardServicesWithWarnings: 离线节点跳过下发并返回警告,不再硬性失败
- applyTunnelRuntime: 所有节点类型均支持离线错误延迟处理
- 前端 validateTunnelForm: 编辑模式下跳过离线节点验证
Closes #342
2026-03-28 19:30:30 +08:00
sagitchu
363e714603
fix: 支持跨版本隧道链路 (v6入v4出 / v4入v6出)
...
问题:selectTunnelDialHost 只检查同版本兼容 (v4->v4, v6->v6),
导致 v6-only 入口节点连接 v4-only 出口节点时报错:
"节点链路不兼容"
修复:在 default 分支增加跨版本支持:
- fromV6 && toV4 → 返回出口 v4 地址
- fromV4 && toV6 → 返回出口 v6 地址
更新测试用例以反映新行为
2026-03-28 10:35:47 +08:00
sagitchu
e69082a596
fix(monitor): add tunnel quality detection toggle
...
Allow admins to disable real-time tunnel quality probing from settings so the monitor UI and backend probe loop stop together.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-26 20:08:40 +08:00
sagitchu
61d95ab5d5
fix(backend): clean up forwards when revoking tunnel permissions
2026-03-25 20:24:27 +08:00
sagitchu
efaffb0475
chore: release 2.1.9-rc8
2026-03-24 09:45:21 +08:00
sagitchu
8475bc27bb
fix: re-assign port automatically if out of range for new tunnel entries ( fixes #373 )
2026-03-23 22:57:49 +08:00
sagit
8ebde9dca9
feat: node OS logo and UI fixes ( #367 )
...
* chore: update AGENTS.md with next release info
* feat: node OS logo, UI rate fix, and monitor trend updates
2026-03-22 05:03:04 +00:00
sagitchu
1580e4ee10
chore: [monitoring] improve tunnel metric ingestion logging
2026-03-21 19:20:23 +08:00
sagitchu
6e3d604618
feat: implement tunnel quality polling and service monitor tuning to 1s/30s intervals
2026-03-21 17:28:52 +08:00
sagitchu
27c13d6c47
chore: release 2.1.9-beta7
2026-03-20 22:15:51 +08:00