- Extract database layer into model and repo packages
- Split repository into focused modules (control, federation, flow, groups, mutations)
- Remove monolithic db.go and sqlite/repository.go
- Update handlers to use new repository structure
- Migrate contract tests to new patterns
- Add migration plan documentation
Added dual-layer port range enforcement for federation sharing:
Server-side (Provider):
- federationRuntimeApplyRole: validate runtime.Port against share range
- validateFederationCommandPorts: hardened against malformed JSON bypass
- New helpers: validateRemoteNodePort, remoteNodePortRange
Client-side (Consumer):
- prepareTunnelCreateState: pre-check ports for remote nodes
- tunnelCreate type=1: validate targetPort for remote entry
- forwardCreate/Update/BatchChangeTunnel: port range validation
Prevents consumers from using arbitrary ports outside provider's allowed range.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-opencode)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
- Fix Type 1 (port forwarding) tunnels to call applyFederationRuntime
Previously only Type 2 tunnels applied federation runtime, causing
port forwarding tunnels to not be properly configured in federation mode
- Remove incorrect UDP tunnel type override in federationTunnelCreate
UDP tunnels were being incorrectly set to Type 2, which conflicted with
the federation runtime logic that expects Type 1 for port forwarding
These fixes ensure all tunnel types are properly handled in federation mode
with correct runtime configuration applied.
The gcode.hostcentral.cc proxy only supports github.com file downloads,
not api.github.com requests. API calls through the proxy returned 404
HTML pages, causing JSON decode error: invalid character '<'.
Also updates repo name from flux-panel to flvx across upgrade and
install URLs.
1. Refactor speed limit CRUD to sync with agents immediately via WebSocket (AddLimiters/DeleteLimiters).
2. Update unit conversion to match GOST v3 requirements (Mbps -> MB/s).
3. Update service config generation to reference Limiter IDs instead of hardcoded values.
Bridge Java-to-Go runtime behavior by enforcing forward ownership checks, wiring node command dispatch/diagnostics, and adding contract coverage so migrated APIs can run with production semantics.