Repository navigation
🚀 What's New in v1.4.2-LTS
MTProxyMax v1.4.2-LTS is a major Long-Term Support release delivering the Telemt 3.5.9 core engine upgrade, safe liveness probing and non-destructive auto-healing (#152), universal BusyBox flock portability across Alpine Linux (#146), atomic voucher state transitions (#155), pure-bash civil calendar calculations (#148, #150), and the next-generation interactive Telegram bot control plane (#140–#143).
1. ⚙️ Major Engine Upgrade: Telemt 3.5.9 ("Kostenfaktor") & 3.5.8 ("Kanzlersturz")
- Multi-call Firewall Binary Support (telemt PR #933): Upgraded telemt to
3.5.9(e3f62db). System helpers (iptables,ip6tables,iptables-restore,ip6tables-restore) now preserveargv[0]. On distributions where firewall tools are symlinked toxtables-nft-multiorxtables-legacy-multi(Debian, Ubuntu, Alpine), canonicalization previously invoked the multi-call binary withargv[0] == xtables-nft-multi, causing immediate failures. Telemt 3.5.9 setscommand.arg0(binary), ensuring 100% reliable conntrack and firewall command dispatch. - Transactional Conntrack Reconciler (telemt 3.5.8): Firewall state transitions are now managed by a single process-owned actor using shadow state, capped exponential backoff, and full transactional rollback on failure, plus automatic rule cleanup on shutdown.
- Fenced Middle-End Lifecycle (telemt 3.5.8): Writer refresh, replacement, refill, and hardswap publication now use explicit transactional ownership. Hardswap commits are fenced by generation, endpoint revision, desired-map identity, DC-family coverage, and configured writer floors, preventing credential leakage and orphan warm writers.
- Process-Wide User Admission Authority (telemt 3.5.8): User authentication, credentials, and live-session ownership are governed by a process-wide authority. User incarnations isolate delete-and-recreate cycles (preventing old quota or IP resets from affecting new identities), and CAS contention in traffic buckets is bounded.
- WEB Base Path & Transport Recovery (telemt 3.5.8): Added
base_pathsupport inweb.vhostsfor prefix routing behind reverse proxies; failed WebSocket lane upgrades enter transport recovery rather than leaking reservations. - New Engine Tunables in MTProxyMax: Added
direct_relay_buffer_budget_max_bytesandconntrack_controlto_TUNE_WHITELIST(mtproxymax tune set direct_relay_buffer_budget_max_bytes <bytes>). - Real-Time Observability Metrics in
mtproxymax info: Added scraping and live dashboard reporting for pending Middle-End hardswaps (telemt_me_hardswap_pending) underME Healthand conntrack rollback events (telemt_conntrack_rule_rollback_total) underSecurity. - Automated Multi-Arch Pipeline: Prebuilt multi-arch Docker images (
linux/amd64,linux/arm64) compiled and published via GitHub Container Registry (ghcr.io/samnet-dev/mtproxymax-telemt:3.5.9-e3f62dbandlatest).
2. 🏥 Safe Liveness Probing & Non-Destructive Auto-Healing (#152)
- Technology: Multi-attempt non-destructive container liveness evaluation in
run_healandis_proxy_running. - Mechanism: Previously, transient Docker daemon hiccups (or high load leading to a momentary
docker inspecttimeout) causedrun_healto immediately executedocker rm -f mtproxymaxand attempt a blinddocker run. If the network interface or container state was momentarily locked, the proxy was unrecoverably destroyed. - Resolution:
is_proxy_runningnow features retryable probing with backoff.run_healcompletely eliminated blinddocker rm -fcalls, verifying actual container state and delegating recovery cleanly tostart_proxy_containerwith proper error propagation. - Unit Test:
tests/test_run_heal.sh.
3. 🏔️ BusyBox Flock Portability & 100% Green Alpine Linux (#146)
- Technology: File-descriptor based locking (
exec {_lock_fd}>... ; flock -w ... "$_lock_fd"). - Mechanism: BusyBox
flock(standard on Alpine Linux, OpenRC, and embedded containers) does not support-wwith file path arguments (only with numerical file descriptors). Callingflock -w 5 "$lock_file"failed on Alpine. - Resolution: Converted all critical locking routines across vouchers, rate limits, and replication to file descriptor locks with fallback, and eliminated fail-open security bypasses on lock failure.
- Multi-Distro Matrix: Validated 100% green pass rate across Alpine 3.19 under OpenRC and BusyBox.
4. 🎟️ Atomic Voucher State Transitions & Telegram Aliases (#155, #156)
- Technology: Atomic voucher redemption lock pipeline and unified command dispatching.
- Mechanism: Eliminates race conditions during voucher redemption, ensuring that vouchers cannot be double-redeemed or leave orphaned accounts if secret creation fails.
- Telegram Improvements: Unified command aliases (
/mp_voucher,/voucher,/vouchers), and displayed owner Telegram chat IDs for reseller accounting.
5. ⚡ Core Portability & Pipeline Resilience (#147, #148, #149, #150, #151)
- SIGPIPE Elimination (#151): Removed premature
grep -qin subshell pipelines that triggered SIGPIPE terminations underset -eo pipefail. - Pure-Bash Civil Calendar (#148, #150): Native bash civil calendar arithmetic eliminating dependencies on external GNU
date -dor BSDdate -v, and fixed sub-second timestamp parsing in_iso_to_epoch. - Stale Metrics Scraper Fix (#149): Scraped upstream counter names (
telemt_user_octets_*_total) and per-user gauges, restoring accurate bandwidth tracking. - Accurate Init Detection (#147): Prevented false systemd detection in non-systemd container environments.
- Client MSS Test Validation (#145): Hardened
client_msstest assertions to verify effective config emission.
6. 🤖 Next-Gen Interactive Telegram Bot (#140, #141, #142, #143)
- Telegram Bot Command Menu (#140): Automatically registers bot commands via Telegram Bot API
setMyCommands, scoped dynamically by user role (public, admin, superadmin). - Zero-Dependency High-Throughput Update Parser (#141): Fast pure-bash update ingestion and callback data encoding/decoding (
_cb_enc/_cb_dec). - Interactive Inline-Keyboard Menus (#142): Full touch-friendly menu navigation for secrets, upstreams, settings, and node telemetry.
- Traffic History & Analytics (#143): Multi-window hourly and daily traffic aggregation, Unicode sparkline rendering (
▂▃▄▅▆▇█), and automated periodic executive summaries sent to admins.
7. 🧪 Continuous Integration & Verification (#153)
- PR Test Pipeline Across Distros & Init Systems (#153): Automated CI matrix across Ubuntu 22.04, Ubuntu 24.04, Debian 12 (bookworm), Alpine 3.19 (OpenRC/BusyBox), Fedora 40, systemd, and OpenRC.
- 37 dedicated test suites with over 600 assertions verified passing across all platforms.
🛠️ Architecture & Compatibility Summary
| Component | Status / Version in v1.4.2-LTS | Notes |
|---|---|---|
| Core Engine | Telemt 3.5.9 (e3f62db) |
Multi-arch Docker (amd64, arm64) with multi-call firewall fix |
| Middle-End | Transactional & generation-fenced | Conntrack auto-rollback, hardswap tracking |
| Init Systems | systemd, openrc, standalone |
Auto-detected with supervised daemons |
| Locking | File-descriptor based (flock -w) |
100% portable on BusyBox / Alpine |
| Self-Healing | Non-destructive retryable probes | Preserves containers against transient Docker hiccups |
| Telegram Bot | Interactive inline UI + Command Menu | Native setMyCommands & sparkline analytics |
📥 Quick Upgrade
To update an existing installation to v1.4.2-LTS:
mtproxymax updateOr re-run the universal one-line installer:
bash <(curl -sL https://raw.githubusercontent.com/SamNet-dev/MTProxyMax/main/mtproxymax.sh)