Skip to content

v1.6.8

Choose a tag to compare

@github-actions github-actions released this 06 May 06:13
· 157 commits to main since this release

Bugfix and improvements release. Tunnel-stability work on the WebSocket proxy, a one-shot contrib/vault-quickstart.sh to take a fresh box from "no Vault" to "rustguac-ready Vault" in seconds, plus a clutch of small bug fixes from operator reports.

Headline changes

Tunnel stability: ping echo, instruction-boundary alignment, TCP keepalive

The Guacamole client sends an empty-opcode ping instruction every 500ms over the WebSocket to keep its receive timer alive. The Apache reference webapp echoes those pings back to the browser; rustguac was forwarding them straight to guacd, which silently dropped them as unknown opcodes. With nothing inbound to reset the client's 1.5s "unstable" timer, idle sessions logged a constant trickle of [rustguac] tunnel unstable and could close on genuinely quiet sessions after 15s. v1.6.8 mirrors Apache's filter: empty-opcode pings are echoed back, never forwarded.

The first cut of that change introduced a parser race (the browser saw (half-instruction)(ping bytes)(other half) and threw "Element terminator was not ';' nor ','"). The fix is a length-prefix-aware boundary scanner in src/protocol.rs that ensures every Message::Text from rustguac to the browser ends at a true Guacamole instruction boundary, even when an element value contains a literal ; (clipboard text, text streams). 11 new unit tests cover empty buffers, partial frames, embedded ;, multibyte truncation, and trailing garbage.

TCP keepalive (30s idle, 10s probe, 3 retries, ~60s detection) is now applied to the inbound listener (Linux inherits SO_KEEPALIVE to accepted sockets) and to both rustguac→guacd connect sites. Catches silent NAT/firewall path drops within ~60s on either leg of the proxy. None of this fixes a path with sustained packet loss; that remains a network problem.

Vault / OpenBao quickstart helper

New contrib/vault-quickstart.sh with three modes:

Mode Use case
(default) Provision an existing Vault using $VAULT_ADDR + $VAULT_TOKEN
--dev Spawn an in-memory dev-mode server and provision it (demos, throwaway dev)
--local Install Vault or OpenBao as a systemd service with file storage and on-disk auto-unseal

Auto-detects vault vs bao and picks the matching filesystem layout, system user, and service name (vault.service for Vault, openbao.service for OpenBao). The --local mode writes a SECURITY.txt next to the on-disk unseal key explicitly calling out the convenience-over-security trade. Idempotent: re-running detects existing user, mount, policy, AppRole, and systemd unit. The README and docs/integrations.md gain a clearer Requirements story making explicit that Vault or OpenBao is required for the Connections feature, not optional.

Bug fixes

  • #121: OIDC client_secret was a non-Optional struct field in OidcConfig, so a config.toml without a client_secret = "..." line failed TOML parsing before the documented OIDC_CLIENT_SECRET env var override could fill it in. The field is now Option<String> with explicit startup validation when [oidc] is configured.
  • #122: Authentik setup guide was missing the prerequisite step to create a Groups scope mapping under Customisation > Property Mappings (the groups scope does not exist by default in fresh Authentik instances).
  • #123 (parts 2 + 3): Per-session drive cleanup hardcoded retention_secs = 0 and never read cleanup_on_close, so both flags were dead code at end-of-session teardown. The fix routes both values through. Docs gain a "Cleanup behaviour" subsection clarifying that retention_secs only takes effect when cleanup_on_close = true. Items 1 (upload disconnects session) and 4 (drag-drop UX) postponed for further testing under the same issue.

Dependencies

  • rustls 0.23.39 → 0.23.40 (closes #120)
  • russh 0.60.1 → 0.60.2 (closes #119)

Thanks

Thanks to Simon for feedback on the Vault dependency story and the shape of the quickstart script, and to Josh Matthews (@joshsol1) for the careful bug reports against #121, #122, and #123.