* docs: add implementation plan for max conn limit
* feat: add CLimiters support for websocket reporter
* feat: add max_conn field to user and forward models
* feat: implement max conn limiter dispatching
* feat: add maxConn to user and forward CRUD API
* feat: add max conn UI to user management and forward rules
* fix: load MaxConn in get forward record and add e2e contract test for max conn limit
- Fix KCP tunnel not reclaimed after deletion: service name was
hardcoded to {id}_tls but services were created as {id}_kcp,
causing DeleteService to never find the actual KCP service.
Now reads tunnel.Protocol from DB and derives correct name.
- Fix KCP diagnosis using TCP ping instead of UDP ping:
tunnel.Protocol was always hardcoded to 'tls' at creation,
so isUDPBasedProtocol() never matched kcp tunnels. Now
stores the actual protocol from entry node configuration.
- Fix addTunnelServiceOnNode to extract service name from
serviceData instead of hardcoding _tls suffix.
- Fix rollbackTunnelRuntime to accept protocol parameter
so retry cleanup uses correct service name.
- UpdateTunnelTx now persists protocol on tunnel updates.
- controlForwardServices: skip offline nodes instead of failing entire operation,
so forward pause/resume/delete works when some entry nodes are offline
- onNodeOnline: always sync forward state on node reconnect (not just post-upgrade),
so forwards that changed status while a node was offline get synced
- add ListForwardIDsByNode repo method to sync all forwards (including paused)
- tunnel edit UI: allow deselecting already-selected offline nodes in
entry/chain/exit selectors, matching the backend's existing tolerance
- KCP: switch from fast3 to fast2 mode, enable FEC (10/3), enable
congestion control (nc=0) for automatic rate adaptation
- go-gost/x: support kcp.nc metadata to override mode-initialized
NoCongestion value in dialer and listener Init()
- Diagnosis: add udpPingViaRemoteNode, fix pingViaRemoteNode to
dispatch based on protocol, add Protocol field to federation
diagnose request structs
Replace read-then-subtract pattern in collectAndReport with atomic
swap-to-zero to eliminate race where AddTraffic increments counters
between snapshot and clearReportedTraffic, causing residual traffic
to accumulate indefinitely and inflate user flow counters.
Also add defensive check in processFlowItem to skip AddFlow when
forward no longer exists, and send DeleteService to clean up orphaned
agent services.
- Pass tunnel protocol through diagnosis work items
- Support protocol-specific ping (TCP/UDP/KCP) via remote nodes
- Add KCP probe support in websocket_reporter for chain hop testing
Allow admins to disable real-time tunnel quality probing from settings so the monitor UI and backend probe loop stop together.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Add missing 'uptime' field to NodeMetricApiItem type definition
- Fix WS message handling: non-UpgradeProgress typed messages now
broadcast via broadcastInfo instead of being silently dropped
- Strengthen looksLikeSystemInfoMessage heuristic to require ≥3
matching keys to avoid false positives
- Fix tab/space indentation inconsistency in admin.tsx useEffect
- Remove duplicate method declarations from merge (repository_control,
mutations)
- Update tunnel_entry_sqlite_test to use renamed Tx suffix function
- Add backend API for tunnel delete rule resolution (allow, deny, confirm)
- Add contract tests for delete resolution endpoint
- Add frontend API types and endpoints for delete resolution
- Add tunnel delete resolution settings UI with resolution mode selector
- Support per-tunnel and global delete resolution configuration
- Fix deadlock when updating tunnel entries with offline nodes
- Add test file for tunnel entry SQLite operations
- Update contract tests for entry port conflict and limiter sync
- Add plan documents for SQLite deadlock fix and contract semantics
- Add NodeMetric/TunnelMetric/ServiceMonitor models and repository methods
- Implement metrics ingestion service with per-minute bucket aggregation
- Add health checker for node connectivity monitoring
- Wire node metrics from WebSocket SystemInfo messages
- Add tunnel metrics ingestion from flow upload endpoint
- Create monitoring REST API endpoints for nodes, tunnels, services
- Implement service monitor CRUD and execution (TCP/ICMP checks)
- Add MonitorPermission for non-admin access control
- Create frontend monitor page with node/tunnel/service views
- Add tunnel metrics ingestion from agent flow reports
- Include schema migration for tunnel_metric unique index
- Fix tunnel entry port conflict validation to use transaction
Entire-Checkpoint: 030821a7c8e3
* fix(dialog): prevent both open and close auto focus to avoid page scroll
Add onOpenAutoFocus handler to prevent Radix Dialog from auto-focusing
content on open, which can cause unwanted scroll behavior.
* fix(dialog): remove onOpenAutoFocus, keep only onCloseAutoFocus
Remove onOpenAutoFocus handler that was causing scroll issues on first open.
Keep onCloseAutoFocus to prevent scroll to trigger element on close.
Key fix: Move {...props} before onCloseAutoFocus to prevent override.
* fix(dialog): prevent scroll to top on modal close
- Move {...props} before onCloseAutoFocus to prevent override
- Simplify handler to just e.preventDefault()
- Apply fix to both dialog.tsx and modal.tsx