Repository navigation
Releases: max3584/rproxy-api
Release list
v0.4.0
追加
- Kubernetes のコントローラ向けの口(#220)。Kubernetes の Gateway API で rproxy を動かすコントローラ rproxy-gateway v0.4.0 と一緒に使えます。
- ルールの組
PUT /rulesets/{name}:持っているルールの全体を 1 回で渡すと、rproxy が差分を当てます。generation・If-Match(etag)・?dry_run=trueが使え、組のルールを個別に変えると409 ownedです。組は作ったトークンのもので、トークンファイルのallow_rulesetsで扱える組の名前を絞れます。 - ルールの
labels(ログ・/metricsに出す印)、conditions(Gateway API の status の形)、GET /readyz。
- ルールの組
- Gateway API 向けの L7・TLS(#237・#239)
headersのadd、リダイレクトのステータス、ルートごとのタイムアウト、replace_host、サーバごとのミドルウェア、retryのステータス、エラーのステータスのサーバ。- 新しいミドルウェア
cors・mirror。 - 転送先への HTTP/2(
h2・h2c・auto、トレーラー)とサービスごとの TLS(CA・SNI・SAN の検証、BackendTLSPolicy)。 tls.routesの複数の宛先。client_auth: optional_no_verifyとX-Client-Verify・X-Forwarded-Client-Cert。
- L4 の送信元ごとの制限と帯域の上限(#219):ルールの
limits(同時接続・新しい接続の速さ)とbandwidth(上り・下り)。利用量の集計のための数(counters_since)。 - 制御 API の守り(#218):クライアント証明書(mTLS)とトークンの結びつけ、トークンの期限の知らせ、認証の失敗が続く送信元の一時停止(
429 locked_out)。 - GeoIP の許可・拒否(#221):MaxMind 形式のデータベースで、国・AS ごとに許可・拒否できます。
- 受け身のヘルスチェック(#221):転送の失敗が続いたサーバを一時的に外します(
outlier_detection)。 - 変更前の差分(#222):
?dry_run=true、POST /config/plan、rproxy-api --check-config --diff。 - API で作ったルールの保存(#222):トークンに
persist: trueを付けると、作ったルールを DB のrproxy_rulesに保存し、再起動の後も戻します(origin: "api")。 - 再起動なしの更新(#223):SIGUSR2 か
POST /admin/upgradeで、接続を切らずに新しいバイナリへ引き継ぎます。同じマイナーの中のパッチは、.deb の更新でも引き継ぎます。 - コンテナの自動更新(#223):入口を
rproxy-api launchにしてRPROXY_UPDATE=autoにすると、同じ X.Y の最新のパッチを取り、minisign の署名を確かめてから入れ替えます。落ちた版は自動で戻します。リリースの鍵は docs/UPGRADE.md。 - performance の設定(#223):
global.performance(workers・udp_shards・cpu_affinity・busy_poll_usecs・splice)。
修正
- クライアントが送ってきた
X-Client-Verify・X-Forwarded-Client-Certを、どのルールでも消すようにしました。tls.client_authのないルールで、偽のクライアント証明書の情報が転送先に届いていました。 mirrorの写しにも、転送先に付けるヘッダ(X-Forwarded-*・証明書)を付けるようにしました。- 転送先が HTTP/2 のとき、ストリームの空きを待ち続けて詰まることがあったのを直しました。
- 自動更新で試していた版を、止めただけで悪い版として扱っていたのを直しました。
- そのほか、セキュリティレビューの指摘を直しました(docs/DESIGN-v0.4.md の 17 節)。
変更
- サービスのユーザーが
rproxyからrproxy-api(主グループrproxy)に変わります。 .deb と install.sh が、uid を変えずに名前だけ変えるので、ファイルの持ち主はそのままです。UI(rproxy-ui)はrproxyグループに入り、グループで読めるファイルを共有できます。 - ルールが指す証明書・鍵・秘密のファイルを確かめるようになりました(
global.files.owner_check: strict、既定)。- 持ち主が rproxy-api のファイルだけを使います。グループや他人が書けるファイル、誰でも読める鍵は断ります。
- おすすめは
rproxy-api:rproxyの 0640 です。certbot の証明書は deploy hook で写してください。 - root が持つファイルを使いたい場所は、
global.files.trusted_dirsかRPROXY_FILES_TRUSTED_DIRSで指定できます(Kubernetes の Secret など)。確認を止めるにはowner_check: off。
- v0.3.x から v0.4.0 への更新は、引き継ぎではなく再起動になります(引き継ぎは同じマイナーの中だけ)。
- 接続の失敗の
target.downのログは、reason: connectからreason: outlierとcause: connectに変わりました。 - v0.4 を入れたことのある機械に v0.3 の .deb を入れ直すと、残った
rproxyグループのせいで失敗します。UI v0.4 と組み合わせるときは、rproxy-api も v0.4 にしてください。
UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0
Added
- Hooks for a Kubernetes controller (#220), used by rproxy-gateway v0.4.0 to run rproxy behind the Kubernetes Gateway API.
- Rule sets
PUT /rulesets/{name}: send the whole set of rules at once and rproxy applies the difference. Supportsgeneration,If-Match(etag) and?dry_run=true; changing a rule of a set on its own gets409 owned. A set belongs to the token that created it, andallow_rulesetsin the token file limits which set names a token may use. - Rule
labels(shown in logs and/metrics),conditions(in the shape of Gateway API status) andGET /readyz.
- Rule sets
- L7 and TLS for the Gateway API (#237, #239)
headersadd, redirect status, per-route timeouts,replace_host, per-server middlewares,retrystatus, error-status servers.- New middlewares
corsandmirror. - HTTP/2 to upstreams (
h2,h2c,auto, with trailers) and per-service TLS (CA, SNI and SAN checks; BackendTLSPolicy). - Several targets in
tls.routes. client_auth: optional_no_verifywithX-Client-VerifyandX-Forwarded-Client-Cert.
- Per-source L4 limits and bandwidth caps (#219): rule
limits(concurrent connections, new-connection rate) andbandwidth(up and down); counters for usage accounting (counters_since). - Control API hardening (#218): tokens bound to client certificates (mTLS), token-expiry notices, and a lockout for sources with repeated auth failures (
429 locked_out). - GeoIP allow and deny (#221) by country and AS, with MaxMind-format databases.
- Passive health checks (#221): servers that keep failing are taken out for a while (
outlier_detection). - Dry runs (#222):
?dry_run=true,POST /config/planandrproxy-api --check-config --diff. - Persistence for API-made rules (#222): with
persist: trueon a token, the rules it creates are saved in therproxy_rulestable and restored after a restart (origin: "api"). - Upgrades without a restart (#223): SIGUSR2 or
POST /admin/upgradehands the sockets over to a new binary without dropping connections. Patches within the same minor are handed over by the .deb upgrade too. - Self-update for containers (#223): with
rproxy-api launchas the entrypoint andRPROXY_UPDATE=auto, rproxy fetches the newest patch of its X.Y, checks its minisign signature and swaps it in; a version that crashes is rolled back. The release key is in docs/en/UPGRADE.md. - Performance settings (#223):
global.performance(workers,udp_shards,cpu_affinity,busy_poll_usecs,splice).
Fixed
X-Client-VerifyandX-Forwarded-Client-Certsent by clients are now removed on every rule; on rules withouttls.client_auth, forged client-certificate details reached upstreams.mirrorcopies now carry the same forwarding headers (X-Forwarded-*, certificate details) as the main request.- HTTP/2 upstreams could stall while waiting for a free stream.
- The self-update no longer marks a version under trial as bad just because it was stopped.
- Other findings of the security review (docs/en/DESIGN-v0.4.md, section 17).
Changed
- The service user changes from
rproxytorproxy-api(primary grouprproxy). The .deb and install.sh rename the user and keep its uid, so file ownership stays valid. The UI user (rproxy-ui) joins therproxygroup and can read group-readable files. - Files that rules point at are now checked (
global.files.owner_check: strict, the default).- Only files owned by rproxy-api are used. Files writable by the group or others, and keys readable by anyone, are refused.
- The recommended mode is
rproxy-api:rproxy0640. Copy certbot's certificates with a deploy hook. - Directories where root-owned files are acceptable (Kubernetes Secrets, for one) can be listed in
global.files.trusted_dirsorRPROXY_FILES_TRUSTED_DIRS.owner_check: offturns the check off.
- Upgrading from v0.3.x to v0.4.0 restarts the service (handover works only within the same minor).
target.downfor connection failures now logsreason: outlierwithcause: connectinstead ofreason: connect.- Installing a v0.3 .deb again on a machine that had v0.4 fails because of the leftover
rproxygroup. With UI v0.4, use rproxy-api v0.4 as well.
UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0
v0.3.21
追加
- ACME で証明書を取り、自動で更新できるようになりました(#208)。設定と使い方は docs/ACME.md。
- challenge:HTTP-01(
httpのルールか、80 番の小さな待ち受けhttp01_listen)、TLS-ALPN-01(terminateのルール)、DNS-01。 - DNS-01 のプロバイダ:PowerDNS の HTTP API、汎用の REST(テンプレート)、RFC 2136(TSIG。応答の署名も確かめる)、acme-dns。
_acme-challengeの CNAME をたどって委任先のゾーンに書く。TXT は必ず消し、消し残しは次の起動で消す。 - 更新:期限の 30 日前(または期間の 3 分の 1)。CA が ARI を出すときはその窓の中。失敗したら間隔を空けて取り直し、その間は今の証明書を使い続ける。
- 設定:
global.acmeのaccounts・dns_providers・resolvers。ルールは今までどおりtls.certificates[]の{acme: <resolver>, domains}。 - API:
GET /acme(状態。秘密は出さない)、POST /acme/renew・/acme/revoke・/acme/accounts/{name}/register・/deactivate(acme:write、既定で Unix ソケットからだけ)。
- challenge:HTTP-01(
- 守り
- DNS の秘密は固定の設定からファイルで指すだけで、API・応答・ログに出さない。
- アカウントと DNS のプロバイダの両方に、発行してよい名前の許可リスト(
allowed_names)。外の名前は 400。ワイルドカードは DNS-01 だけ。 - 新しいスコープ
acme:write。発行の回数の上限(既定 1 時間に 10)。acme.*・auditのログ(秘密なし)。 - 任意で、DNS の秘密を別のユーザーで動く補助プロセス(
rproxy-api acme-helper、rproxy-acme-helper.service)に持たせ、本体は秘密を読まない形にできる(docs/PERMISSIONS.md)。
- Traefik からの変換ツールが
certResolverを rproxy の ACME の設定(秘密は入れない骨組み)に変換するようになりました。
変更
- 「ACME は内蔵しない」方針を変えました。
GET /capabilitiesのfeatures.acmeは true です。 - 前の版の
global.acme(一度も動いていなかった形)は使えません。docs/ACME.md の形で書いてください。 - パッケージに
StateDirectory=rproxy(/var/lib/rproxy。ACME のアカウントの鍵と証明書の置き場所)と、補助プロセス用のrproxy-acmeユーザー・サービス(入れるだけで有効にはしない)を足しました。purge で/var/lib/rproxyと/var/lib/rproxy-acmeを消します。
Added
- Certificates can be obtained and renewed with ACME (#208). See docs/en/ACME.md.
- Challenges: HTTP-01 (an
httprule, or the smallhttp01_listenresponder on port 80), TLS-ALPN-01 (terminaterules), DNS-01. - DNS-01 providers: PowerDNS HTTP API, generic REST templates, RFC 2136 (TSIG, with signed answers verified) and acme-dns. The
_acme-challengeCNAME is followed to the delegated zone; TXT records are always removed, and leftovers are removed at the next start. - Renewal 30 days before expiry (or a third of the lifetime), inside the CA's ARI window when offered. Failures retry with backoff while the current certificate stays in use.
- Config:
accounts,dns_providersandresolversunderglobal.acme. Rules keep{acme: <resolver>, domains}intls.certificates[]. - API:
GET /acme(state, no secrets);POST /acme/renew,/acme/revoke,/acme/accounts/{name}/registerand/deactivate(acme:write, Unix socket only by default).
- Challenges: HTTP-01 (an
- Safeguards
- DNS secrets are only referenced as files in the fixed config, never in the API, responses or logs.
allowed_namesallowlists on both the account and the DNS provider; other names get 400; wildcards need DNS-01.- New scope
acme:write, an issuance rate limit (10 per hour by default),acme.*andauditlog events without secrets. - Optionally, a helper process running as another user (
rproxy-api acme-helper,rproxy-acme-helper.service) holds the DNS secrets so the main process never reads them (docs/en/PERMISSIONS.md).
- The Traefik converter maps
certResolverto an rproxy ACME skeleton (secrets left out).
Changed
- The "no built-in ACME" policy is reversed;
features.acmeinGET /capabilitiesis true. - The old
global.acmeshape (which never worked) is gone; use the shape in docs/en/ACME.md. - The package adds
StateDirectory=rproxy(/var/lib/rproxy, where ACME keys and certificates live) and anrproxy-acmeuser and helper service (installed, not enabled). Purge removes/var/lib/rproxyand/var/lib/rproxy-acme.
v0.3.20
追加
- 状態を API とメトリクスで分かるように(#115)
GET /rulesにall_targets_down(L4 で宛先がすべて down)とdown_services(http のルールで、up の転送先がないサービス)GET /configにcrowdsec(LAPI に今つながっているか・最後に取れた時刻・最後の誤り・判定の数)/metricsにrproxy_rule_all_targets_down・rproxy_http_service_down・rproxy_crowdsec_connected・rproxy_crowdsec_last_success_timestamp_seconds・rproxy_log_suppressed_total
- SIEM・CrowdSec 向けのログ(#167 の一部)
- 制御 API の 401 / 403 を
event=auditに出すようにしました(client=送信元の IP、Unix ソケットからはunix、401 はreason=missing / invalid / expired)。トークンは出しません。ルールの変更と設定の読み直しの audit にもclientが付きます。 http.accessにrefused_by(断ったミドルウェアの種類)・middleware(設定での名前)・user(basic_auth で通ったユーザー)・auth_error(basic_auth で断った理由)。パスワードは出しません。CrowdSec のパーサーもこれらを読みます。
- 制御 API の 401 / 403 を
修正
- UDP で
allow_fromと CrowdSec で断ったときのconn.deniedが debug でしか出ず、既定のログ・CrowdSec の検知・SIEM に届いていなかったのを直しました(info で出します)。ログは送信元ごと(続けて 20 行、その後は 1 秒 1 行)と全体(続けて 200 行、その後は 1 秒 50 行)で間引き、省いた行の数は次の行のsuppressedと/metricsに出します。stats.deniedは今までどおり 1 つずつ数えます。
変更
allow_listen_portsの範囲外で断ったルールの変更の audit のoutcomeがerrorからforbiddenになりました。
Added
- State in the API and metrics (#115)
GET /rulesaddsall_targets_down(all L4 targets down) anddown_services(HTTP services with no healthy backend).GET /configaddscrowdsec(whether LAPI is reachable now, last success, last error, decision count)./metricsaddsrproxy_rule_all_targets_down,rproxy_http_service_down,rproxy_crowdsec_connected,rproxy_crowdsec_last_success_timestamp_secondsandrproxy_log_suppressed_total.
- Logs for SIEM and CrowdSec (part of #167)
- Control-API 401 / 403 responses are logged as
event=auditwithclient(peer IP, orunix) and, for 401,reason(missing / invalid / expired). Tokens are never logged. Rule changes and config reloads also getclient. http.accessaddsrefused_by(which middleware refused),middleware(its configured name),user(the basic_auth user) andauth_error(why basic_auth refused). Passwords are never logged. The CrowdSec parser reads them.
- Control-API 401 / 403 responses are logged as
Fixed
- UDP
conn.deniedforallow_fromand CrowdSec was only logged at debug, so it never reached the default log, CrowdSec detection or a SIEM. It is now info, throttled per source (20 lines, then 1 per second) and overall (200, then 50 per second); the number of skipped lines goes to the next line'ssuppressedand to/metrics.stats.deniedstill counts every datagram.
Changed
- Rule changes refused by
allow_listen_portsnow have auditoutcomeforbiddeninstead oferror.
v0.3.19
変更(速さとメモリの改善)
v0.3.18 と同じマシンで交互に測った負荷テストの結果を添えます(4 vCPU の GitHub のランナー、名前空間の中の仮想の回線。実際の NIC では差が小さくなる見込みです)。
- L4 の TCP の転送を作り直しました。 読めるデータがあるときだけ 32 KiB のバッファを借りるようにし(何もしていない接続はバッファを持たない)、大きな転送が続く向きは splice(2) でカーネルの中だけで受け渡すようにしました(plain の TCP だけ。TLS 終端・STARTTLS・L7 は対象外)。
- TCP 1 本 5.0 → 12.9 Gbit/s、8 本 11.9 → 43.6 Gbit/s。大きな転送の CPU あたりの量は約 7 倍。
- TCP の接続 1 本あたりのメモリ 17.7 / 25.7 KiB(待機中 / 転送中)→ 7.5 KiB。
- 小さなやり取りの遅延・新しい接続の数は変わりません。
- L7(HTTP/2)の CPU を減らしました。 転送先への待機中の接続を多く使い回し(サーバごとに最大 1024 本、4 秒使わなければ閉じる)、リクエストごとの余分な処理を省きました。
- HTTP/2 の小さなリクエスト +50〜60%、HTTP/1.1 +11%。遅延(p50 / p99)も 30% 前後短くなりました。
- HTTP/2 over TLS に高い負荷をかけている間は、ピークのメモリが増えます(負荷が終われば戻ります)。
- UDP をまとめて読み書きするようにしました(recvmmsg / sendmmsg、受信バッファを大きく)。64 バイトの全力の送信で、届く量 +65%、取りこぼし 57% → 21%。セッションあたりのメモリは変わりません。
- メモリのアロケータに mimalloc を選べるようにしました(ビルドで
--features alloc-mimalloc)。既定は今までどおり musl の malloc です。
設定の項目は変わっていません。UDP の待ち受けのソケットの数・splice の切り替えなどの設定の形は v0.4.0 で決めます。
Changed (speed and memory)
Measured against v0.3.18 on the same machine, alternating builds (4-vCPU GitHub runner, virtual links in network namespaces; expect smaller gaps on real NICs).
- L4 TCP forwarding was rebuilt. A 32 KiB buffer is borrowed only while data is ready (idle connections hold no buffer), and directions with sustained large transfers move to splice(2), staying inside the kernel (plain TCP only; not TLS termination, STARTTLS or L7).
- TCP 1 stream 5.0 → 12.9 Gbit/s, 8 streams 11.9 → 43.6 Gbit/s; about 7× more data per CPU on large transfers.
- Memory per TCP connection 17.7 / 25.7 KiB (idle / busy) → 7.5 KiB.
- Small-message latency and new connections per second are unchanged.
- Less CPU for L7 (HTTP/2). More idle upstream connections are reused (up to 1024 per server, closed after 4 s unused) and per-request work was trimmed.
- Small HTTP/2 requests +50–60%, HTTP/1.1 +11%; p50/p99 latency about 30% lower.
- Peak memory is higher while HTTP/2 over TLS is under heavy load (it goes back down afterwards).
- UDP now reads and writes in batches (recvmmsg / sendmmsg, larger receive buffer): at full rate with 64-byte packets, +65% delivered and loss 57% → 21%. Memory per session is unchanged.
- mimalloc can be chosen as the allocator (build with
--features alloc-mimalloc). The default stays musl's malloc.
No settings changed. The shape of settings such as the number of UDP listener sockets and the splice switch will be decided in v0.4.0.
v0.3.18
修正
- メールサーバの EHLO の応答に UTF-8 でないバイトや多バイト文字が混ざると、STARTTLS の接続のタスクが panic で落ちていたのを直しました(ファジングで見つかりました)。
matchの式を深く入れ子にするとスタックがあふれてプロセス全体が落ちていたのを直しました(#180)。入れ子は 32 段まで、1 つの式の条件は 256 個までで、超えると設定の誤り(API は 400、起動・読み直し・--check-configでも誤り)になります。- 時間の値(
rate_limitの期間、タイムアウト、health_check、retry、circuit_breaker、CrowdSec のupdate_intervalなど)にとても大きな値を書くと、あふれて小さな値になったり、プロセスが落ちたりしていたのを直しました。365 日(8760h)を超える値は設定の誤りになります。
追加
GET /capabilitiesが rproxy-api のバージョン(version)を返すようになりました。管理 UI がバージョンを表示し、組み合わせを確かめるのに使います。
変更
- rproxy-api と管理 UI のバージョン番号は、それぞれ別に進めるようにしました(docs/RELEASING.md)。組み合わせは UI の画面で確かめられます。
UI の最新: TCP-UDP-rproxy-ui v0.3.18
Fixed
- A STARTTLS connection task panicked when the mail server's EHLO reply contained non-UTF-8 bytes or multi-byte characters (found by fuzzing).
- Deeply nested
matchexpressions overflowed the stack and aborted the whole process (#180). Nesting is now limited to 32 levels and an expression to 256 matchers; beyond that it is a configuration error (400 from the API, and an error at startup, on reload and from--check-config). - Very large durations (
rate_limitperiods, timeouts,health_check,retry,circuit_breaker, CrowdSecupdate_interval, …) could overflow to small values or crash the process. Durations over 365 days (8760h) are now configuration errors.
Added
GET /capabilitiesnow returns the rproxy-apiversion. The management UI shows it and uses it to check compatibility.
Changed
- rproxy-api and the management UI now have independent version numbers (docs/en/RELEASING.md). The UI shows whether they fit together.
Latest UI: TCP-UDP-rproxy-ui v0.3.18
v0.3.17
修正
- TCP の転送で TCP_NODELAY を設定しておらず、小さなデータのやり取りで約 40 ms 待つことがあったのを直しました(#176)。L4 の TCP、TLS の終端、STARTTLS、SNI、L7(
httpのルール)の受け付けた接続と転送先への接続、forward_auth・OIDC・CrowdSec への通信のすべてが対象です。- 手元の計測では、TLS のハンドシェイクが 41 ms → 0.6 ms、HTTP/2 の同時 32 リクエストが 41 ms → 1 ms、TCP の転送の速さが約 11 倍になりました。
変更
- ソースの構成を役割ごとのフォルダに分けました(
control/・config/・core/・net/・l4/・tls/・l7/)。動きは変わりません。RPROXY_LOG_LEVELをモジュール名で絞り込んでいる場合(例rproxy_api::http=debug)は、新しい名前(rproxy_api::l7=debug)に書き換えてください。 - バックアップと復旧の手順(docs/BACKUP.md)を足しました。
- 動くものが変わったほうだけをリリースする決まりにしました(docs/RELEASING.md)。v0.3.16 は UI だけの版で、rproxy-api は v0.3.15 から v0.3.17 に進みます。
対になる UI: v0.3.17
Fixed
- TCP forwarding did not set TCP_NODELAY, so small exchanges could wait about 40 ms (#176). This covers accepted connections and upstream connections for L4 TCP, TLS termination, STARTTLS, SNI and L7 (
httprules), plus calls to forward_auth, OIDC and CrowdSec.- In our measurements, the TLS handshake went from 41 ms to 0.6 ms, 32 concurrent HTTP/2 requests from 41 ms to 1 ms, and TCP throughput rose about elevenfold.
Changed
- The source is now split into folders by role (
control/,config/,core/,net/,l4/,tls/,l7/). Behavior is unchanged. If you filterRPROXY_LOG_LEVELby module name (e.g.rproxy_api::http=debug), switch to the new name (rproxy_api::l7=debug). - Backup and restore guide (docs/en/BACKUP.md).
- Only the side whose running code changed is released now (docs/en/RELEASING.md). v0.3.16 was UI-only; rproxy-api goes from v0.3.15 to v0.3.17.
Paired with UI v0.3.17.
v0.3.15
追加
- README にバッジ(CI・相互接続・cargo-deny・リリース・apt・ライセンス・Renovate)を付けました。
- docs/RELEASING.md に、バージョンを上げるときは
Cargo.lockも直す手順を書きました。
この版での rproxy-api の動作の変更はありません。管理 UI のスマホ・タブレット対応は TCP-UDP-rproxy-ui v0.3.15 を見てください。
Added
- Badges in the README (CI, interop, cargo-deny, release, apt, license, Renovate).
- docs/RELEASING.md now says to update
Cargo.lockwhen bumping the version.
rproxy-api behaves the same as in v0.3.14. For the admin UI's phone and tablet support, see TCP-UDP-rproxy-ui v0.3.15.
v0.3.14
依存の整理の版です。動きは変わりません。
変更
- 依存のバージョンを
Cargo.lockで固定し、リポジトリに入れた。リリースのバイナリと .deb は、このファイルのとおりのバージョンでビルドする(実際に入っている依存を外から確かめられる) - メンテナンスが終わった
rustls-pemfileをやめ、後継のrustls-pki-typesで証明書と鍵を読む(読める形式とエラーのメッセージは同じ) - 使っていない依存と機能を外した
- 主な依存の版:rustls 0.23.45(RUSTSEC-2026-0285 の修正版)、ring 0.17.14、tokio 1.53.1、hyper 1.11.1、quinn 0.11.12、h3 0.0.8、bcrypt 0.19.3、bytes 1.12.1
組み合わせる UI
Dependency cleanup. No behavior change.
Changed
- Dependency versions are pinned in
Cargo.lock, now committed to the repository; release binaries and .debs are built from it (so the dependencies actually shipped can be checked from outside) - The unmaintained
rustls-pemfilewas replaced byrustls-pki-typesfor reading certificates and keys (same formats and error messages) - Unused dependencies and features were removed
- Key dependency versions: rustls 0.23.45 (the RUSTSEC-2026-0285 fix), ring 0.17.14, tokio 1.53.1, hyper 1.11.1, quinn 0.11.12, h3 0.0.8, bcrypt 0.19.3, bytes 1.12.1
Paired with
v0.3.13
追加
- ドキュメントの英語版(README.en.md、docs/en/)。.deb では
/usr/share/doc/rproxy-api/en/に入る
修正
- docs/API.md のルールの項目の表が、途中から表として表示されていなかった
組み合わせる UI
Added
- English documentation (README.en.md, docs/en/), installed by the .deb under
/usr/share/doc/rproxy-api/en/
Fixed
- Part of the rule-fields table in docs/API.md was not rendered as a table
Paired with
v0.3.12
rproxy-api 側の変更はありません。UI v0.3.12 と組み合わせて使います。
組み合わせる UI
No changes in rproxy-api. Use with UI v0.3.12.