Skip to content

Releases: IZKGMD/GMDmucho-core

MuchoCore v1.0.9

Choose a tag to compare

@IZKGMD IZKGMD released this 01 Oct 10:20

v1.0.9 — One-Command Direct VPS Deployment

Direct VPS Deployment & Installer DX

  • made direct VPS HTTPS the default transport, so a normal public VPS no longer requires Cloudflare Tunnel or any third-party tunnel service;
  • reduced a clean MuchoCore deployment to a single remote installer command, with deployment-specific domain and administrator-password prompts;
  • added automatic Caddy exposure for both HTTP and HTTPS on ports 80/443 with managed TLS certificates;
  • added DNS preflight checks, public-origin convergence diagnostics and automatic firewall rules for 80/443 when an existing UFW firewall is active;
  • kept Cloudflare API credentials and Tunnel provisioning optional for NAT/CGNAT deployments or operators who explicitly choose Tunnel mode;
  • validated the complete path on a brand-new VPS: containers healthy, migrations applied, HTTP /health = 1, HTTPS /health = 1, and sudo mucho doctor reports No problems found.

Admin Content Tools

  • added a dedicated Gauntlet & Map Pack Maker to the Admin Panel;
  • create, edit, reorder, enable and delete Gauntlets with exactly five unique levels;
  • create, edit, reorder, enable and delete Map Packs with exactly three unique levels;
  • validate every selected level before a collection is published, rejecting missing, deleted and unlisted levels;
  • added fine-grained RBAC permission contentpacks.manage for custom administrator roles;
  • added persistent MariaDB schema migration for Gauntlets and Map Packs;
  • kept the existing Geometry Dash discovery wire endpoints backed by the same stored collections;
  • added audit events for collection creation, edits and deletion.

Compatibility

  • Gauntlets continue through the existing getGJGauntlets / getGJGauntlets21 routes;
  • Map Packs continue through the existing getGJMapPacks / getGJMapPacks20 / getGJMapPacks21 routes;
  • no client-side protocol changes are required for the new admin maker.

Installer & Operator DX

  • reduced the normal VPS installation to the deployment-specific domain and admin-password prompts;
  • made the all Geometry Dash compatibility profile the default, with --advanced for the interactive profile menu;
  • added a stable-release remote installer bootstrap that resolves the published release before downloading its installer;
  • added domain/DNS and port preflight diagnostics plus contextual installer failure messages;
  • removed the integration-test tenant from the production Compose stack and moved it to docker-compose.test.yml;
  • added operator-first mucho commands for status, logs, restart, repair, update, backup, migration and optional test-stack management;
  • expanded mucho doctor to validate production service state and the Cloud Save secret;
  • updated VPS onboarding and deployment documentation around the new quick-install path.
  • added automatic Cloudflare provisioning: one API token can create/reuse the Tunnel, configure ingress, update DNS, obtain the runtime token and switch the deployment to Tunnel mode when the origin is unreachable.

MuchoCore v1.0.84

Choose a tag to compare

@IZKGMD IZKGMD released this 29 Sep 09:56

v1.0.84 — Worker & Updater Reliability

Runtime Reliability

  • separate worker startup from administrator password bootstrap so background workers no longer require an admin secret they do not use;
  • add a regression contract covering worker secret isolation and admin-bearing service requirements.

Updater Reliability

  • fetch stable release tags without a shallow-history reset before ancestry validation, preventing false non-descendant failures on valid upgrades.

MuchoCore v1.0.83

Choose a tag to compare

@IZKGMD IZKGMD released this 29 Sep 07:57

v1.0.83 — Reliability, Migration & Deployment Hardening

Migration Safety

  • require a fresh, verified target database backup before migration writes;
  • fail closed when the mandatory backup is unavailable, already running, too small, corrupt or has a checksum mismatch;
  • prevent concurrent migration processes from operating on the same MuchoCore target;
  • keep source database access read-only and reject incompatible source schemas before import;
  • retain transactional rollback and deterministic source-to-target mappings for repeatable imports.

Installer & Operator Fixes

  • added an installer prompt to migrate an existing GDPS database immediately after MuchoCore installation;
  • support explicit non-interactive migration mode through MUCHO_MIGRATION_ON_INSTALL;
  • make installer Compose checks and diagnostics work correctly with Cloudflare Tunnel overrides;
  • run Control Center database backups inside the application container where the required runtime tools and credentials exist;
  • fix backup root resolution for direct script usage;
  • show tunnel services in updater status output.

Backup Runtime

  • include the MariaDB client in the application image so verified database backups work from the running MuchoCore container;
  • verify generated backup gzip integrity and SHA-256 immediately after creation;
  • preserve the old database untouched throughout migration.

MuchoCore v1.0.82

Choose a tag to compare

@IZKGMD IZKGMD released this 27 Sep 08:50
c17798e

v1.0.82 — MuchoProtect Hardening & Compatibility Reliability

MuchoProtect

  • added pre-auth identity protection for usernames and email addresses so login and registration abuse cannot be bypassed by simple IP rotation;
  • added stable device/UDID identity throttling for legacy client flows;
  • added explicit rate and burst policies for the complete Clan API surface;
  • added secondary IPv4 /24 and IPv6 /64 endpoint budgets to contain distributed IP rotation without treating a shared network like one client;
  • reused exponential temporary penalties for repeated network-level violations;
  • unified API v2 request throttling with the central MuchoProtect engine;
  • preserved the API v2 JSON 429 contract and the existing music-upload 5-per-15-minute account limit;
  • added bounded stale-state cleanup for rate-limit and penalty storage, with lightweight automatic cleanup and explicit maintenance support.

Clans & Compatibility

  • expanded Clan System v2 with owner-only settings, ownership transfer and disbanding;
  • added invitation revocation and persistent clan bans with transactional membership cleanup;
  • hardened open-clan joins and invitation acceptance with row locking and server-side capacity checks;
  • added clan management audit events and contract coverage;
  • added first-class GD 1.1 compatibility profile and installer support;
  • added first-class GD 1.5 compatibility profile with real build 13 verification;
  • verified GD 1.6 build 16 on the shared early 1.x compatibility path;
  • preserved legacy UDID-based score compatibility for early clients.

Operator & Quality Fixes

  • removed the obsolete v1.0.2 release marker from the tracked tree;
  • fixed the installer summary and password prompt to display the configured administrator username instead of a hard-coded admin;
  • updated account-recovery email copy to the project's English-language standard;
  • refreshed release documentation and security regression coverage for the new protection layers.

MuchoCore v1.0.81

Choose a tag to compare

@IZKGMD IZKGMD released this 27 Sep 04:48
c17798e

v1.0.81 — Migration Safety & Backup Hardening

Migration Safety

  • made a verified MuchoCore target database backup mandatory before migration apply;
  • verify the backup file, gzip integrity and SHA-256 checksum before destination writes begin;
  • block migration completely when the target backup fails or cannot be verified;
  • keep source database access read-only during import;
  • harden source-schema preflight so incompatible required columns fail before destination changes;
  • refuse implicit account merges when a source account conflicts with an existing target username/email;
  • keep destination changes inside a transaction so failed imports roll back cleanly;
  • preserve idempotent re-runs through persistent source-to-target ID mapping;
  • added an end-to-end MariaDB migration test covering successful import, backup failure, idempotent re-run, account conflicts, rollback and incompatible source schema handling;

Backup & Operator Reliability

  • fixed backup credential loading for installations that store DB credentials in MuchoCore runtime environment files;
  • made the backup lock path runtime-configurable and safe for non-root integration environments;
  • kept backup options compatible with the normal application database privileges;
  • clarified that a public GDPS hostname such as ps.fhgdps.com is not automatically a database endpoint; operators must provide the actual source MariaDB/MySQL connection details;

MuchoCore v1.0.8

Choose a tag to compare

@IZKGMD IZKGMD released this 27 Sep 17:28

v1.0.8 — Intelligence & Scale

Level Intelligence

  • added MuchoCore LevelValidator with structural, size, UTF-8 and payload integrity checks;
  • added SHA-256 level payload fingerprints and non-fatal validation warnings;
  • integrated validation into the level upload/update lifecycle without changing legacy protocol response encoding;
  • added compressed level revision history with transactional restore support.

Search & Performance

  • added the derived mucho_level_search_index with normalized creator/name fields and MariaDB full-text support;
  • kept the canonical level repository as the source of truth and retained the legacy SQL search fallback;
  • added short-lived level response caching with database, optional Redis and disabled modes;
  • invalidated level search caches after writes and removals;
  • refreshed creator search index entries after administrator username changes.

Background Operations

  • added the MariaDB-backed mucho_jobs queue with transactional reservation, retries and stale-job recovery;
  • added a dedicated Docker worker for level indexing, webhook delivery and maintenance cleanup;
  • made background failures non-fatal to successful Geometry Dash protocol responses.

Observability & Operations

  • added signed operator webhooks with event filtering and HMAC-SHA256 signatures;
  • unified healthcheck alert creation through AlertService;
  • enriched safe client traces with request IDs, response length, response SHA-256 and latency;
  • added mucho trace inspect and mucho trace diff;
  • added mucho test for database/schema and optional read-only HTTP smoke checks;
  • added mucho backup-verify with gzip, SQL-sample and SHA-256 checks plus verification history;
  • added the Admin Intelligence & Scale dashboard;
  • added interactive cache and webhook settings to sudo mucho.

Deployment & Documentation

  • added the v1.0.8 intelligence/scale migration;
  • added Docker worker configuration and documented all new environment settings;
  • expanded CI with v1.0.8 contracts and required-file checks;
  • preserved the v1.0.7 audit hardening and v1.0.6 integrity/compatibility work underneath the new subsystems.

MuchoCore v1.0.7

Choose a tag to compare

@IZKGMD IZKGMD released this 27 Sep 16:56
242583d

v1.0.7 — Post-v1.0.6 Audit Hardening

Migration Safety

  • made the interactive Migration Center require a verified target database backup before schema preparation or imported-data writes;
  • validate backup existence, minimum size and SHA-256 checksum before the migration can proceed;
  • added regression coverage that enforces the backup-before-schema ordering.

Plugin SDK Privacy

  • lifecycle events now receive sanitized request snapshots with a strict non-secret protocol field allow-list;
  • plugin lifecycle responses expose transport metadata only, not response bodies;
  • plugin failure events expose the exception class name instead of the original exception object or message;
  • documented the lifecycle event privacy contract and added regression coverage.

Runtime Consistency

  • v7.1 now prefers the canonical MuchoCore database connection before legacy adapter fallbacks;
  • API v2 now uses the same canonical database runtime first, while retaining its existing advanced fallback path;
  • removed a duplicate v7.1 canonical connection block introduced during hardening.

Documentation & Release

  • synchronized README and plugin/migration documentation with the actual v1.0.7 behavior;
  • retained the v1.0.6 integrity and compatibility hardening underneath these fixes;
  • validated the release changes with the full Validate, Windows patcher and MariaDB migration integration jobs.

MuchoCore v1.0.6

Choose a tag to compare

@IZKGMD IZKGMD released this 27 Sep 12:42

v1.0.6 — Deep Integrity & Compatibility Hardening

Score Integrity & Concurrency

  • serialized regular and Platformer score writes with database transactions and row locks;
  • eliminated the select-then-insert race that could occur when the same player submitted concurrent results;
  • kept the existing best-score semantics while making failed score writes roll back cleanly;
  • regular score leaderboards now exclude inactive and banned accounts at the database query layer;
  • Platformer score leaderboards now exclude inactive and banned accounts consistently.

Social & Account Data Correctness

  • corrected friend-request deletion, friend removal and unblock operations to report whether a real mutation occurred;
  • kept friend-request read operations idempotent while still rejecting missing requests;
  • fixed numeric player search counts so user-ID searches paginate against the correct total;
  • kept creator leaderboards version-aware for both modern 2.x and legacy 1.x clients;
  • top and creator leaderboards no longer publish inactive or banned accounts.

Regression Coverage

  • added dedicated v1.0.6 hardening contracts for score concurrency structure, leaderboard filtering, search counting and compatibility behavior;
  • retained full validation, migration integration and Windows patcher gates for the release.

MuchoCore v1.0.5

Choose a tag to compare

@IZKGMD IZKGMD released this 27 Sep 09:54
bba2d7f

v1.0.5 — Platform Hardening & Operator Center

Security & Authorization

  • unified MuchoAdminClient authorization with the canonical AdminRbac permission model;
  • preserved legacy rank fields for compatibility while removing numeric-rank enforcement as the API authorization source of truth;
  • protected owner-level game-role escalation behind canonical owner permissions;
  • added configurable trusted proxy CIDRs for safer forwarded client IP handling.

Score Integrity

  • added a persisted quarantined score state behind the existing optional anti-cheat quarantine flag;
  • suspicious regular and Platformer scores are stored as quarantined when the feature is enabled;
  • leaderboards exclude suspicious and quarantined integrity records while quarantine is active;
  • kept the soft-by-default behavior with no automatic account bans.

Shared MuchoProtect Storage

  • added backend interfaces plus MariaDB-backed rate-limit and penalty storage;
  • kept file-backed storage as the default for simple single-instance installations;
  • added migration and regression coverage for shared security state.

Migration & Operator Center

  • added the guided Migration Center with schema detection, read-only source access, dry-run preview and explicit MIGRATE confirmation;
  • added the interactive VPS Control Center via sudo mucho;
  • added database password rotation via sudo muchodb-password;
  • added installer and updater integration for the operator tools.

Release & Update Reliability

  • made GitHub's explicit latest stable release the authoritative stable channel;
  • replaced the semver-only downgrade guard with a Git ancestry check, so release numbering can change without allowing unrelated source rebases;
  • refreshed stable configuration and release documentation for v1.0.5.

Changelog

MuchoCore v1.0.4

Choose a tag to compare

@IZKGMD IZKGMD released this 26 Sep 18:18

v1.0.4 — MuchoCore Discovery & Tenant Isolation

Product Page

  • added the canonical MuchoCore product page at /muchocore/;
  • added machine-readable SoftwareApplication and FAQ structured data;
  • added explicit documentation for compatibility, architecture, Cvolton migration, plugins, security, deployment and administration;
  • added a responsive layout and direct links to source, releases and setup documentation.

Search & AI Discovery

  • added robots.txt with crawler directives for OAI-SearchBot, GPTBot, Googlebot and Google-Extended;
  • added sitemap.xml for the canonical MuchoCore web surface;
  • added llms.txt with canonical sources and project facts;
  • linked the canonical product page from the public project homepage and README.

Tenant Isolation

  • added MUCHOCORE_SITE_HOST as the explicit host allow-list for the public MuchoCore discovery surface;
  • product/discovery paths return 404 on non-canonical GDPS hosts;
  • fresh installations default MUCHOCORE_SITE_HOST to disabled.invalid, so tenant owners do not receive the MuchoCore product page automatically;
  • removed the MuchoCore product-page link from normal GDPS tenant navigation;
  • added the operator-friendly Migration Kit with read-only preflight, target backup, transactional apply, post-migration healthcheck and migration reports;
  • added docs/GETTING_STARTED.md as the shortest installation and migration path;
  • added docs/MIGRATION_KIT.md with migration commands, safety behavior, password handling and current scope;
  • added automated Migration Kit contract checks to release validation.