Releases: IZKGMD/GMDmucho-core
Releases · IZKGMD/GMDmucho-core
Release list
MuchoCore v1.0.9
v1.0.9 — One-Command Direct VPS Deployment
Direct VPS Deployment & Installer DX
- made direct VPS HTTPS the default transport, so a normal public VPS no longer requires Cloudflare Tunnel or any third-party tunnel service;
- reduced a clean MuchoCore deployment to a single remote installer command, with deployment-specific domain and administrator-password prompts;
- added automatic Caddy exposure for both HTTP and HTTPS on ports 80/443 with managed TLS certificates;
- added DNS preflight checks, public-origin convergence diagnostics and automatic firewall rules for 80/443 when an existing UFW firewall is active;
- kept Cloudflare API credentials and Tunnel provisioning optional for NAT/CGNAT deployments or operators who explicitly choose Tunnel mode;
- validated the complete path on a brand-new VPS: containers healthy, migrations applied, HTTP /health = 1, HTTPS /health = 1, and sudo mucho doctor reports No problems found.
Admin Content Tools
- added a dedicated Gauntlet & Map Pack Maker to the Admin Panel;
- create, edit, reorder, enable and delete Gauntlets with exactly five unique levels;
- create, edit, reorder, enable and delete Map Packs with exactly three unique levels;
- validate every selected level before a collection is published, rejecting missing, deleted and unlisted levels;
- added fine-grained RBAC permission
contentpacks.managefor custom administrator roles; - added persistent MariaDB schema migration for Gauntlets and Map Packs;
- kept the existing Geometry Dash discovery wire endpoints backed by the same stored collections;
- added audit events for collection creation, edits and deletion.
Compatibility
- Gauntlets continue through the existing
getGJGauntlets/getGJGauntlets21routes; - Map Packs continue through the existing
getGJMapPacks/getGJMapPacks20/getGJMapPacks21routes; - no client-side protocol changes are required for the new admin maker.
Installer & Operator DX
- reduced the normal VPS installation to the deployment-specific domain and admin-password prompts;
- made the
allGeometry Dash compatibility profile the default, with--advancedfor the interactive profile menu; - added a stable-release remote installer bootstrap that resolves the published release before downloading its installer;
- added domain/DNS and port preflight diagnostics plus contextual installer failure messages;
- removed the integration-test tenant from the production Compose stack and moved it to
docker-compose.test.yml; - added operator-first
muchocommands for status, logs, restart, repair, update, backup, migration and optional test-stack management; - expanded
mucho doctorto validate production service state and the Cloud Save secret; - updated VPS onboarding and deployment documentation around the new quick-install path.
- added automatic Cloudflare provisioning: one API token can create/reuse the Tunnel, configure ingress, update DNS, obtain the runtime token and switch the deployment to Tunnel mode when the origin is unreachable.
MuchoCore v1.0.84
v1.0.84 — Worker & Updater Reliability
Runtime Reliability
- separate worker startup from administrator password bootstrap so background workers no longer require an admin secret they do not use;
- add a regression contract covering worker secret isolation and admin-bearing service requirements.
Updater Reliability
- fetch stable release tags without a shallow-history reset before ancestry validation, preventing false non-descendant failures on valid upgrades.
MuchoCore v1.0.83
v1.0.83 — Reliability, Migration & Deployment Hardening
Migration Safety
- require a fresh, verified target database backup before migration writes;
- fail closed when the mandatory backup is unavailable, already running, too small, corrupt or has a checksum mismatch;
- prevent concurrent migration processes from operating on the same MuchoCore target;
- keep source database access read-only and reject incompatible source schemas before import;
- retain transactional rollback and deterministic source-to-target mappings for repeatable imports.
Installer & Operator Fixes
- added an installer prompt to migrate an existing GDPS database immediately after MuchoCore installation;
- support explicit non-interactive migration mode through MUCHO_MIGRATION_ON_INSTALL;
- make installer Compose checks and diagnostics work correctly with Cloudflare Tunnel overrides;
- run Control Center database backups inside the application container where the required runtime tools and credentials exist;
- fix backup root resolution for direct script usage;
- show tunnel services in updater status output.
Backup Runtime
- include the MariaDB client in the application image so verified database backups work from the running MuchoCore container;
- verify generated backup gzip integrity and SHA-256 immediately after creation;
- preserve the old database untouched throughout migration.
MuchoCore v1.0.82
v1.0.82 — MuchoProtect Hardening & Compatibility Reliability
MuchoProtect
- added pre-auth identity protection for usernames and email addresses so login and registration abuse cannot be bypassed by simple IP rotation;
- added stable device/UDID identity throttling for legacy client flows;
- added explicit rate and burst policies for the complete Clan API surface;
- added secondary IPv4 /24 and IPv6 /64 endpoint budgets to contain distributed IP rotation without treating a shared network like one client;
- reused exponential temporary penalties for repeated network-level violations;
- unified API v2 request throttling with the central MuchoProtect engine;
- preserved the API v2 JSON 429 contract and the existing music-upload 5-per-15-minute account limit;
- added bounded stale-state cleanup for rate-limit and penalty storage, with lightweight automatic cleanup and explicit maintenance support.
Clans & Compatibility
- expanded Clan System v2 with owner-only settings, ownership transfer and disbanding;
- added invitation revocation and persistent clan bans with transactional membership cleanup;
- hardened open-clan joins and invitation acceptance with row locking and server-side capacity checks;
- added clan management audit events and contract coverage;
- added first-class GD 1.1 compatibility profile and installer support;
- added first-class GD 1.5 compatibility profile with real build 13 verification;
- verified GD 1.6 build 16 on the shared early 1.x compatibility path;
- preserved legacy UDID-based score compatibility for early clients.
Operator & Quality Fixes
- removed the obsolete v1.0.2 release marker from the tracked tree;
- fixed the installer summary and password prompt to display the configured administrator username instead of a hard-coded admin;
- updated account-recovery email copy to the project's English-language standard;
- refreshed release documentation and security regression coverage for the new protection layers.
MuchoCore v1.0.81
v1.0.81 — Migration Safety & Backup Hardening
Migration Safety
- made a verified MuchoCore target database backup mandatory before migration apply;
- verify the backup file, gzip integrity and SHA-256 checksum before destination writes begin;
- block migration completely when the target backup fails or cannot be verified;
- keep source database access read-only during import;
- harden source-schema preflight so incompatible required columns fail before destination changes;
- refuse implicit account merges when a source account conflicts with an existing target username/email;
- keep destination changes inside a transaction so failed imports roll back cleanly;
- preserve idempotent re-runs through persistent source-to-target ID mapping;
- added an end-to-end MariaDB migration test covering successful import, backup failure, idempotent re-run, account conflicts, rollback and incompatible source schema handling;
Backup & Operator Reliability
- fixed backup credential loading for installations that store DB credentials in MuchoCore runtime environment files;
- made the backup lock path runtime-configurable and safe for non-root integration environments;
- kept backup options compatible with the normal application database privileges;
- clarified that a public GDPS hostname such as
ps.fhgdps.comis not automatically a database endpoint; operators must provide the actual source MariaDB/MySQL connection details;
MuchoCore v1.0.8
v1.0.8 — Intelligence & Scale
Level Intelligence
- added MuchoCore LevelValidator with structural, size, UTF-8 and payload integrity checks;
- added SHA-256 level payload fingerprints and non-fatal validation warnings;
- integrated validation into the level upload/update lifecycle without changing legacy protocol response encoding;
- added compressed level revision history with transactional restore support.
Search & Performance
- added the derived mucho_level_search_index with normalized creator/name fields and MariaDB full-text support;
- kept the canonical level repository as the source of truth and retained the legacy SQL search fallback;
- added short-lived level response caching with database, optional Redis and disabled modes;
- invalidated level search caches after writes and removals;
- refreshed creator search index entries after administrator username changes.
Background Operations
- added the MariaDB-backed mucho_jobs queue with transactional reservation, retries and stale-job recovery;
- added a dedicated Docker worker for level indexing, webhook delivery and maintenance cleanup;
- made background failures non-fatal to successful Geometry Dash protocol responses.
Observability & Operations
- added signed operator webhooks with event filtering and HMAC-SHA256 signatures;
- unified healthcheck alert creation through AlertService;
- enriched safe client traces with request IDs, response length, response SHA-256 and latency;
- added mucho trace inspect and mucho trace diff;
- added mucho test for database/schema and optional read-only HTTP smoke checks;
- added mucho backup-verify with gzip, SQL-sample and SHA-256 checks plus verification history;
- added the Admin Intelligence & Scale dashboard;
- added interactive cache and webhook settings to sudo mucho.
Deployment & Documentation
- added the v1.0.8 intelligence/scale migration;
- added Docker worker configuration and documented all new environment settings;
- expanded CI with v1.0.8 contracts and required-file checks;
- preserved the v1.0.7 audit hardening and v1.0.6 integrity/compatibility work underneath the new subsystems.
MuchoCore v1.0.7
v1.0.7 — Post-v1.0.6 Audit Hardening
Migration Safety
- made the interactive Migration Center require a verified target database backup before schema preparation or imported-data writes;
- validate backup existence, minimum size and SHA-256 checksum before the migration can proceed;
- added regression coverage that enforces the backup-before-schema ordering.
Plugin SDK Privacy
- lifecycle events now receive sanitized request snapshots with a strict non-secret protocol field allow-list;
- plugin lifecycle responses expose transport metadata only, not response bodies;
- plugin failure events expose the exception class name instead of the original exception object or message;
- documented the lifecycle event privacy contract and added regression coverage.
Runtime Consistency
- v7.1 now prefers the canonical MuchoCore database connection before legacy adapter fallbacks;
- API v2 now uses the same canonical database runtime first, while retaining its existing advanced fallback path;
- removed a duplicate v7.1 canonical connection block introduced during hardening.
Documentation & Release
- synchronized README and plugin/migration documentation with the actual v1.0.7 behavior;
- retained the v1.0.6 integrity and compatibility hardening underneath these fixes;
- validated the release changes with the full Validate, Windows patcher and MariaDB migration integration jobs.
MuchoCore v1.0.6
v1.0.6 — Deep Integrity & Compatibility Hardening
Score Integrity & Concurrency
- serialized regular and Platformer score writes with database transactions and row locks;
- eliminated the select-then-insert race that could occur when the same player submitted concurrent results;
- kept the existing best-score semantics while making failed score writes roll back cleanly;
- regular score leaderboards now exclude inactive and banned accounts at the database query layer;
- Platformer score leaderboards now exclude inactive and banned accounts consistently.
Social & Account Data Correctness
- corrected friend-request deletion, friend removal and unblock operations to report whether a real mutation occurred;
- kept friend-request read operations idempotent while still rejecting missing requests;
- fixed numeric player search counts so user-ID searches paginate against the correct total;
- kept creator leaderboards version-aware for both modern 2.x and legacy 1.x clients;
- top and creator leaderboards no longer publish inactive or banned accounts.
Regression Coverage
- added dedicated v1.0.6 hardening contracts for score concurrency structure, leaderboard filtering, search counting and compatibility behavior;
- retained full validation, migration integration and Windows patcher gates for the release.
MuchoCore v1.0.5
v1.0.5 — Platform Hardening & Operator Center
Security & Authorization
- unified MuchoAdminClient authorization with the canonical AdminRbac permission model;
- preserved legacy rank fields for compatibility while removing numeric-rank enforcement as the API authorization source of truth;
- protected owner-level game-role escalation behind canonical owner permissions;
- added configurable trusted proxy CIDRs for safer forwarded client IP handling.
Score Integrity
- added a persisted quarantined score state behind the existing optional anti-cheat quarantine flag;
- suspicious regular and Platformer scores are stored as quarantined when the feature is enabled;
- leaderboards exclude suspicious and quarantined integrity records while quarantine is active;
- kept the soft-by-default behavior with no automatic account bans.
Shared MuchoProtect Storage
- added backend interfaces plus MariaDB-backed rate-limit and penalty storage;
- kept file-backed storage as the default for simple single-instance installations;
- added migration and regression coverage for shared security state.
Migration & Operator Center
- added the guided Migration Center with schema detection, read-only source access, dry-run preview and explicit MIGRATE confirmation;
- added the interactive VPS Control Center via
sudo mucho; - added database password rotation via
sudo muchodb-password; - added installer and updater integration for the operator tools.
Release & Update Reliability
- made GitHub's explicit latest stable release the authoritative stable channel;
- replaced the semver-only downgrade guard with a Git ancestry check, so release numbering can change without allowing unrelated source rebases;
- refreshed stable configuration and release documentation for v1.0.5.
Changelog
MuchoCore v1.0.4
v1.0.4 — MuchoCore Discovery & Tenant Isolation
Product Page
- added the canonical MuchoCore product page at
/muchocore/; - added machine-readable SoftwareApplication and FAQ structured data;
- added explicit documentation for compatibility, architecture, Cvolton migration, plugins, security, deployment and administration;
- added a responsive layout and direct links to source, releases and setup documentation.
Search & AI Discovery
- added
robots.txtwith crawler directives for OAI-SearchBot, GPTBot, Googlebot and Google-Extended; - added
sitemap.xmlfor the canonical MuchoCore web surface; - added
llms.txtwith canonical sources and project facts; - linked the canonical product page from the public project homepage and README.
Tenant Isolation
- added
MUCHOCORE_SITE_HOSTas the explicit host allow-list for the public MuchoCore discovery surface; - product/discovery paths return 404 on non-canonical GDPS hosts;
- fresh installations default
MUCHOCORE_SITE_HOSTtodisabled.invalid, so tenant owners do not receive the MuchoCore product page automatically; - removed the MuchoCore product-page link from normal GDPS tenant navigation;
- added the operator-friendly Migration Kit with read-only preflight, target backup, transactional apply, post-migration healthcheck and migration reports;
- added
docs/GETTING_STARTED.mdas the shortest installation and migration path; - added
docs/MIGRATION_KIT.mdwith migration commands, safety behavior, password handling and current scope; - added automated Migration Kit contract checks to release validation.