Repository navigation
v1.6.8
Bugfix and improvements release. Tunnel-stability work on the WebSocket proxy, a one-shot contrib/vault-quickstart.sh to take a fresh box from "no Vault" to "rustguac-ready Vault" in seconds, plus a clutch of small bug fixes from operator reports.
Headline changes
Tunnel stability: ping echo, instruction-boundary alignment, TCP keepalive
The Guacamole client sends an empty-opcode ping instruction every 500ms over the WebSocket to keep its receive timer alive. The Apache reference webapp echoes those pings back to the browser; rustguac was forwarding them straight to guacd, which silently dropped them as unknown opcodes. With nothing inbound to reset the client's 1.5s "unstable" timer, idle sessions logged a constant trickle of [rustguac] tunnel unstable and could close on genuinely quiet sessions after 15s. v1.6.8 mirrors Apache's filter: empty-opcode pings are echoed back, never forwarded.
The first cut of that change introduced a parser race (the browser saw (half-instruction)(ping bytes)(other half) and threw "Element terminator was not ';' nor ','"). The fix is a length-prefix-aware boundary scanner in src/protocol.rs that ensures every Message::Text from rustguac to the browser ends at a true Guacamole instruction boundary, even when an element value contains a literal ; (clipboard text, text streams). 11 new unit tests cover empty buffers, partial frames, embedded ;, multibyte truncation, and trailing garbage.
TCP keepalive (30s idle, 10s probe, 3 retries, ~60s detection) is now applied to the inbound listener (Linux inherits SO_KEEPALIVE to accepted sockets) and to both rustguac→guacd connect sites. Catches silent NAT/firewall path drops within ~60s on either leg of the proxy. None of this fixes a path with sustained packet loss; that remains a network problem.
Vault / OpenBao quickstart helper
New contrib/vault-quickstart.sh with three modes:
| Mode | Use case |
|---|---|
| (default) | Provision an existing Vault using $VAULT_ADDR + $VAULT_TOKEN |
--dev |
Spawn an in-memory dev-mode server and provision it (demos, throwaway dev) |
--local |
Install Vault or OpenBao as a systemd service with file storage and on-disk auto-unseal |
Auto-detects vault vs bao and picks the matching filesystem layout, system user, and service name (vault.service for Vault, openbao.service for OpenBao). The --local mode writes a SECURITY.txt next to the on-disk unseal key explicitly calling out the convenience-over-security trade. Idempotent: re-running detects existing user, mount, policy, AppRole, and systemd unit. The README and docs/integrations.md gain a clearer Requirements story making explicit that Vault or OpenBao is required for the Connections feature, not optional.
Bug fixes
- #121: OIDC
client_secretwas a non-Optional struct field inOidcConfig, so aconfig.tomlwithout aclient_secret = "..."line failed TOML parsing before the documentedOIDC_CLIENT_SECRETenv var override could fill it in. The field is nowOption<String>with explicit startup validation when[oidc]is configured. - #122: Authentik setup guide was missing the prerequisite step to create a Groups scope mapping under Customisation > Property Mappings (the
groupsscope does not exist by default in fresh Authentik instances). - #123 (parts 2 + 3): Per-session drive cleanup hardcoded
retention_secs = 0and never readcleanup_on_close, so both flags were dead code at end-of-session teardown. The fix routes both values through. Docs gain a "Cleanup behaviour" subsection clarifying thatretention_secsonly takes effect whencleanup_on_close = true. Items 1 (upload disconnects session) and 4 (drag-drop UX) postponed for further testing under the same issue.
Dependencies
Thanks
Thanks to Simon for feedback on the Vault dependency story and the shape of the quickstart script, and to Josh Matthews (@joshsol1) for the careful bug reports against #121, #122, and #123.