Skip to content

v1.4.2-LTS — Telemt Engine 3.5.9, Self-Healing Resilience & Enterprise Hardening

Latest

Choose a tag to compare

@SamNet-dev SamNet-dev released this 29 Sep 18:36

🚀 What's New in v1.4.2-LTS

MTProxyMax v1.4.2-LTS is a major Long-Term Support release delivering the Telemt 3.5.9 core engine upgrade, safe liveness probing and non-destructive auto-healing (#152), universal BusyBox flock portability across Alpine Linux (#146), atomic voucher state transitions (#155), pure-bash civil calendar calculations (#148, #150), and the next-generation interactive Telegram bot control plane (#140–#143).


1. ⚙️ Major Engine Upgrade: Telemt 3.5.9 ("Kostenfaktor") & 3.5.8 ("Kanzlersturz")

  • Multi-call Firewall Binary Support (telemt PR #933): Upgraded telemt to 3.5.9 (e3f62db). System helpers (iptables, ip6tables, iptables-restore, ip6tables-restore) now preserve argv[0]. On distributions where firewall tools are symlinked to xtables-nft-multi or xtables-legacy-multi (Debian, Ubuntu, Alpine), canonicalization previously invoked the multi-call binary with argv[0] == xtables-nft-multi, causing immediate failures. Telemt 3.5.9 sets command.arg0(binary), ensuring 100% reliable conntrack and firewall command dispatch.
  • Transactional Conntrack Reconciler (telemt 3.5.8): Firewall state transitions are now managed by a single process-owned actor using shadow state, capped exponential backoff, and full transactional rollback on failure, plus automatic rule cleanup on shutdown.
  • Fenced Middle-End Lifecycle (telemt 3.5.8): Writer refresh, replacement, refill, and hardswap publication now use explicit transactional ownership. Hardswap commits are fenced by generation, endpoint revision, desired-map identity, DC-family coverage, and configured writer floors, preventing credential leakage and orphan warm writers.
  • Process-Wide User Admission Authority (telemt 3.5.8): User authentication, credentials, and live-session ownership are governed by a process-wide authority. User incarnations isolate delete-and-recreate cycles (preventing old quota or IP resets from affecting new identities), and CAS contention in traffic buckets is bounded.
  • WEB Base Path & Transport Recovery (telemt 3.5.8): Added base_path support in web.vhosts for prefix routing behind reverse proxies; failed WebSocket lane upgrades enter transport recovery rather than leaking reservations.
  • New Engine Tunables in MTProxyMax: Added direct_relay_buffer_budget_max_bytes and conntrack_control to _TUNE_WHITELIST (mtproxymax tune set direct_relay_buffer_budget_max_bytes <bytes>).
  • Real-Time Observability Metrics in mtproxymax info: Added scraping and live dashboard reporting for pending Middle-End hardswaps (telemt_me_hardswap_pending) under ME Health and conntrack rollback events (telemt_conntrack_rule_rollback_total) under Security.
  • Automated Multi-Arch Pipeline: Prebuilt multi-arch Docker images (linux/amd64, linux/arm64) compiled and published via GitHub Container Registry (ghcr.io/samnet-dev/mtproxymax-telemt:3.5.9-e3f62db and latest).

2. 🏥 Safe Liveness Probing & Non-Destructive Auto-Healing (#152)

  • Technology: Multi-attempt non-destructive container liveness evaluation in run_heal and is_proxy_running.
  • Mechanism: Previously, transient Docker daemon hiccups (or high load leading to a momentary docker inspect timeout) caused run_heal to immediately execute docker rm -f mtproxymax and attempt a blind docker run. If the network interface or container state was momentarily locked, the proxy was unrecoverably destroyed.
  • Resolution: is_proxy_running now features retryable probing with backoff. run_heal completely eliminated blind docker rm -f calls, verifying actual container state and delegating recovery cleanly to start_proxy_container with proper error propagation.
  • Unit Test: tests/test_run_heal.sh.

3. 🏔️ BusyBox Flock Portability & 100% Green Alpine Linux (#146)

  • Technology: File-descriptor based locking (exec {_lock_fd}>... ; flock -w ... "$_lock_fd").
  • Mechanism: BusyBox flock (standard on Alpine Linux, OpenRC, and embedded containers) does not support -w with file path arguments (only with numerical file descriptors). Calling flock -w 5 "$lock_file" failed on Alpine.
  • Resolution: Converted all critical locking routines across vouchers, rate limits, and replication to file descriptor locks with fallback, and eliminated fail-open security bypasses on lock failure.
  • Multi-Distro Matrix: Validated 100% green pass rate across Alpine 3.19 under OpenRC and BusyBox.

4. 🎟️ Atomic Voucher State Transitions & Telegram Aliases (#155, #156)

  • Technology: Atomic voucher redemption lock pipeline and unified command dispatching.
  • Mechanism: Eliminates race conditions during voucher redemption, ensuring that vouchers cannot be double-redeemed or leave orphaned accounts if secret creation fails.
  • Telegram Improvements: Unified command aliases (/mp_voucher, /voucher, /vouchers), and displayed owner Telegram chat IDs for reseller accounting.

5. ⚡ Core Portability & Pipeline Resilience (#147, #148, #149, #150, #151)

  • SIGPIPE Elimination (#151): Removed premature grep -q in subshell pipelines that triggered SIGPIPE terminations under set -eo pipefail.
  • Pure-Bash Civil Calendar (#148, #150): Native bash civil calendar arithmetic eliminating dependencies on external GNU date -d or BSD date -v, and fixed sub-second timestamp parsing in _iso_to_epoch.
  • Stale Metrics Scraper Fix (#149): Scraped upstream counter names (telemt_user_octets_*_total) and per-user gauges, restoring accurate bandwidth tracking.
  • Accurate Init Detection (#147): Prevented false systemd detection in non-systemd container environments.
  • Client MSS Test Validation (#145): Hardened client_mss test assertions to verify effective config emission.

6. 🤖 Next-Gen Interactive Telegram Bot (#140, #141, #142, #143)

  • Telegram Bot Command Menu (#140): Automatically registers bot commands via Telegram Bot API setMyCommands, scoped dynamically by user role (public, admin, superadmin).
  • Zero-Dependency High-Throughput Update Parser (#141): Fast pure-bash update ingestion and callback data encoding/decoding (_cb_enc / _cb_dec).
  • Interactive Inline-Keyboard Menus (#142): Full touch-friendly menu navigation for secrets, upstreams, settings, and node telemetry.
  • Traffic History & Analytics (#143): Multi-window hourly and daily traffic aggregation, Unicode sparkline rendering ( ▂▃▄▅▆▇█), and automated periodic executive summaries sent to admins.

7. 🧪 Continuous Integration & Verification (#153)

  • PR Test Pipeline Across Distros & Init Systems (#153): Automated CI matrix across Ubuntu 22.04, Ubuntu 24.04, Debian 12 (bookworm), Alpine 3.19 (OpenRC/BusyBox), Fedora 40, systemd, and OpenRC.
  • 37 dedicated test suites with over 600 assertions verified passing across all platforms.

🛠️ Architecture & Compatibility Summary

Component Status / Version in v1.4.2-LTS Notes
Core Engine Telemt 3.5.9 (e3f62db) Multi-arch Docker (amd64, arm64) with multi-call firewall fix
Middle-End Transactional & generation-fenced Conntrack auto-rollback, hardswap tracking
Init Systems systemd, openrc, standalone Auto-detected with supervised daemons
Locking File-descriptor based (flock -w) 100% portable on BusyBox / Alpine
Self-Healing Non-destructive retryable probes Preserves containers against transient Docker hiccups
Telegram Bot Interactive inline UI + Command Menu Native setMyCommands & sparkline analytics

📥 Quick Upgrade

To update an existing installation to v1.4.2-LTS:

mtproxymax update

Or re-run the universal one-line installer:

bash <(curl -sL https://raw.githubusercontent.com/SamNet-dev/MTProxyMax/main/mtproxymax.sh)