-
RouterForge 0.8.5-beta.1
Pre-releasereleased this
2026-09-15 21:45:08 +03:00 | -38 commits to main since this releaseRouterForge 0.8.5-beta.1
🇷🇺 Русский
RouterForge 0.8.5-beta.1
Что нового
- PHASE 13 Registry / Manifest Platform завершён: manifest contract hardening, migration legacy integrations и local/private registry сведены в единый защищённый App Center contract.
- Bundled manifest registry теперь является источником истины для интеграций; старый Go fallback удалён и прикрыт постоянным CI sentinel.
- Local/private sources получили namespaced identity и отдельную conservative trust-модель без возможности тихо подменить public ID.
Исправления
- Добавление стороннего источника теперь строго двухшаговое: read-only preview, затем отдельный ADD_SOURCE с точным SHA-256 preview; изменившийся между шагами источник блокируется.
- Detection сторонних источников остаётся пассивным и не изменяет source config/cache; active Core web-probe для user/private src-* запрещён.
- Responsive UI baseline R26 сохраняется замороженным; новый registry workstream не открывает повторный broad UI redesign.
Совместимость
- Все шесть Beta-пакетов выпускаются единым train 0.8.5~beta.1; GitHub release/tag использует 0.8.5-beta.1.
- Stable/main остаётся RouterForge 0.8.0 и этим Beta-выпуском не продвигается.
- Beta публикуется для aarch64-3.10, mips-3.4 и mipsel-3.4: 6 компонентов x 3 target = 18 IPK.
Технические изменения
- P13 completion защищён always-on CI gate Verify private registry completion.
- Public GitHub остаётся текущим CI/release authority; Private Forgejo начинается следующим отдельным P14 workstream.
- Rolling routerforge-beta обновляется транзакционно; дополнительно создаётся immutable routerforge-v0.8.5-beta.1 на exact release SHA.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.8.5~beta.1RouterForge DNS 0.8.5~beta.1RouterForge Control 0.8.5~beta.1RouterForge Monitoring 0.8.5~beta.1Profiling 0.8.5~beta.1Установка
Свежая установка RouterForge Beta:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.8.5-beta.1/routerforge-beta-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.8.5-beta.1 - Архивный релиз:
routerforge-v0.8.5-beta.1 - Коммит:
bfbb2ec - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
🇬🇧 English
RouterForge 0.8.5-beta.1
What's new
- PHASE 13 Registry / Manifest Platform is complete: manifest contract hardening, legacy integration migration, and the local/private registry now share one guarded App Center contract.
- The bundled manifest registry is now the source of truth for integrations; the legacy Go fallback is removed and protected by a permanent CI sentinel.
- Local/private sources use namespaced identities and a conservative trust model that cannot silently replace public IDs.
Fixes
- Third-party source addition is now strictly two-step: read-only preview followed by an explicit ADD_SOURCE action bound to the exact preview SHA-256; stale previews are rejected.
- Third-party source detection remains passive and does not mutate source config/cache; active Core web-probe is denied for user/private src-* sources.
- The accepted R26 responsive UI baseline remains frozen; the registry workstream does not reopen broad UI redesign.
Compatibility
- All six Beta packages use the coherent 0.8.5~beta.1 train; the GitHub release/tag uses 0.8.5-beta.1.
- Stable/main remains RouterForge 0.8.0 and is not promoted by this Beta release.
- Beta is published for aarch64-3.10, mips-3.4, and mipsel-3.4: 6 components x 3 targets = 18 IPKs.
Technical changes
- P13 completion is protected by the always-on Verify private registry completion CI gate.
- Public GitHub remains the current CI/release authority; Private Forgejo starts as the next separate P14 workstream.
- The rolling routerforge-beta alias is updated transactionally and an immutable routerforge-v0.8.5-beta.1 snapshot is created at the exact release SHA.
Current component versions
Component Version RouterForge Core 0.8.5~beta.1RouterForge DNS 0.8.5~beta.1RouterForge Control 0.8.5~beta.1RouterForge Monitoring 0.8.5~beta.1Profiling 0.8.5~beta.1Installation
Fresh RouterForge Beta install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.8.5-beta.1/routerforge-beta-bootstrap.sh | shBuild and verification
- RouterForge release:
0.8.5-beta.1 - Immutable release:
routerforge-v0.8.5-beta.1 - Commit:
bfbb2ec - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge Dev
Pre-releasereleased this
2026-09-15 21:45:08 +03:00 | -38 commits to main since this releaseRolling ARM64 development channel. Plain binaries; test-router use only.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
Source code (ZIP)
-
RouterForge 0.8.0
Stablereleased this
2026-09-14 15:21:20 +03:00 | 0 commits to main since this releaseRouterForge 0.8.0
🇷🇺 Русский
RouterForge 0.8.0
Что нового
- Network Tools впервые входит в Stable как самостоятельный модуль с Network Doctor, Route Inspector, Flow Explorer и Active Probes внутри общего RouterForge shell.
- В общих настройках появился пользовательский порог предупреждения по температуре CPU; значение по умолчанию 75 °C.
Исправления
- Исправлена петля авто-высоты Network Tools, из-за которой страница могла бесконечно расти вниз.
- Management/Admin восстановил корректную высоту длинных вкладок; Файлы и Терминал снова занимают доступную высоту браузера.
- Stable release tooling обновлён с пяти до шести компонентов и валидирует 18 IPK для трёх архитектур.
Совместимость
- routerforge-core, routerforge-dns, routerforge-admin и routerforge-network-tools имеют Stable-версию 0.8.0.
- routerforge-monitoring и routerforge-profiling функционально не менялись относительно текущего Stable и сохраняют версию 0.7.1.
- DNS, Admin и Network Tools требуют Core 0.8.0; Monitoring и Profiling сохраняют min_core_version 0.7.1.
Технические изменения
- Stable 0.8.0 продвигается только из exact Dev SHA после successful FULL RELEASE с publish_beta=false.
- Stable публикует 6 компонентов × 3 target = 18 IPK.
- Перед Stable promotion Beta 0.8.0-beta.1 была установлена и интерактивно принята на текущем аппаратном тестовом роутере.
- После rolling routerforge-stable создаётся immutable routerforge-v0.8.0.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.8.0RouterForge DNS 0.8.0RouterForge Control 0.8.0RouterForge Monitoring 0.7.1Profiling 0.7.1Установка
Свежая установка RouterForge Stable:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.8.0/routerforge-stable-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.8.0 - Архивный релиз:
routerforge-v0.8.0 - Коммит:
89c172f - Release index:
routerforge-stable-index.json - Bootstrap:
routerforge-stable-bootstrap.sh
🇬🇧 English
RouterForge 0.8.0
What's new
- Network Tools enters Stable as a standalone module with Network Doctor, Route Inspector, Flow Explorer, and Active Probes inside the shared RouterForge shell.
- Global settings now expose a user-selectable CPU temperature warning threshold with a 75 °C default.
Fixes
- Fixed the Network Tools auto-height feedback loop that could grow the page indefinitely.
- Management/Admin long views now size correctly; Files and Terminal again fill the available browser workspace.
- Stable release tooling now validates six components and 18 IPKs across three architectures.
Compatibility
- routerforge-core, routerforge-dns, routerforge-admin, and routerforge-network-tools use Stable version 0.8.0.
- routerforge-monitoring and routerforge-profiling are functionally unchanged relative to the current Stable and remain at version 0.7.1.
- DNS, Admin, and Network Tools require Core 0.8.0; Monitoring and Profiling retain min_core_version 0.7.1.
Technical changes
- Stable 0.8.0 is promoted only from an exact Dev SHA after a successful FULL RELEASE with publish_beta=false.
- Stable publishes 6 components × 3 targets = 18 IPKs.
- Before Stable promotion, Beta 0.8.0-beta.1 was installed and interactively accepted on the current hardware test router.
- Immutable routerforge-v0.8.0 is created after the rolling Stable channel is coherent.
Current component versions
Component Version RouterForge Core 0.8.0RouterForge DNS 0.8.0RouterForge Control 0.8.0RouterForge Monitoring 0.7.1Profiling 0.7.1Installation
Fresh RouterForge Stable install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.8.0/routerforge-stable-bootstrap.sh | shBuild and verification
- RouterForge release:
0.8.0 - Immutable release:
routerforge-v0.8.0 - Commit:
89c172f - Release index:
routerforge-stable-index.json - Bootstrap:
routerforge-stable-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.8.0-beta.1 Pre-release
released this
2026-09-14 08:12:34 +03:00 | 1 commits to main since this releaseRouterForge 0.8.0-beta.1
🇷🇺 Русский
RouterForge 0.8.0-beta.1
Что нового
- Network Tools становится самостоятельным Beta-модулем с вкладками Сетевой доктор, Маршруты, Потоки и Активные проверки, русской/английской локализацией и поддержкой тем RouterForge.
- В общие настройки добавлен ручной порог предупреждения по температуре CPU; значение по умолчанию 75 °C, а главная страница и окно состояния используют выбранный пользователем порог.
Исправления
- Исправлена бесконечная петля высоты iframe Network Tools.
- Management/Admin снова корректно растягивает длинные вкладки, а Файлы и Терминал занимают доступную высоту окна вместо фиксированной короткой области.
- Beta release tooling переведён на актуальную топологию из шести компонентов и проверяет 18 IPK для трёх целевых архитектур.
Совместимость
- Функционально изменены Core, Admin/Management, Monitoring integration и новый Network Tools.
- DNS и Profiling функционально не изменялись в этом workstream, но пересобираются с общей версией Beta train для согласованного обновления зависимостей.
- Все шесть пакетов Beta используют opkg-версию 0.8.0~beta.1; GitHub release/tag использует 0.8.0-beta.1.
- Stable/main этим Beta-выпуском не продвигаются.
Технические изменения
- Точка подготовки Beta основана на аппаратно принятом Dev SHA
ea76797272и последующих release-prep изменениях только release tooling/config. - Beta FULL RELEASE публикует Core, DNS, Admin, Monitoring, Network Tools и Profiling для aarch64-3.10, mips-3.4 и mipsel-3.4: 6 компонентов × 3 target = 18 IPK.
- Rolling routerforge-beta остаётся совместимым mutable release anchor; дополнительно создаётся immutable routerforge-v0.8.0-beta.1 на exact release SHA.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.8.0~beta.1RouterForge DNS 0.8.0~beta.1RouterForge Control 0.8.0~beta.1RouterForge Monitoring 0.8.0~beta.1Profiling 0.8.0~beta.1Установка
Свежая установка RouterForge Beta:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.8.0-beta.1/routerforge-beta-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.8.0-beta.1 - Архивный релиз:
routerforge-v0.8.0-beta.1 - Коммит:
b3ec295 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
🇬🇧 English
RouterForge 0.8.0-beta.1
What's new
- Network Tools becomes a standalone Beta module with Network Doctor, Routes, Flows, and Active Probes tabs, Russian/English localization, and RouterForge theme support.
- Global settings now include a user-selectable CPU temperature warning threshold. The default remains 75 °C and the dashboard/status attention logic uses the configured value.
Fixes
- Fixed the Network Tools iframe height feedback loop that could grow the page indefinitely.
- Management/Admin long tabs now expand correctly, while Files and Terminal fill the available browser workspace instead of remaining in a short fixed area.
- Beta release tooling now follows the six-component topology and verifies 18 IPKs across three target architectures.
Compatibility
- Core, Admin/Management, Monitoring integration, and the new Network Tools module are functionally changed.
- DNS and Profiling are functionally unchanged in this workstream, but are rebuilt with the coherent Beta train version for dependency consistency.
- All six Beta packages use opkg version 0.8.0~beta.1; the GitHub release/tag uses 0.8.0-beta.1.
- Stable/main are not promoted by this Beta release.
Technical changes
- Beta preparation starts from hardware-accepted Dev SHA
ea76797272; the release-prep commit changes release configuration/tooling only. - Beta FULL RELEASE publishes Core, DNS, Admin, Monitoring, Network Tools, and Profiling for aarch64-3.10, mips-3.4, and mipsel-3.4: 6 components × 3 targets = 18 IPKs.
- The rolling routerforge-beta release remains the mutable compatibility anchor; immutable routerforge-v0.8.0-beta.1 is also created on the exact release SHA.
Current component versions
Component Version RouterForge Core 0.8.0~beta.1RouterForge DNS 0.8.0~beta.1RouterForge Control 0.8.0~beta.1RouterForge Monitoring 0.8.0~beta.1Profiling 0.8.0~beta.1Installation
Fresh RouterForge Beta install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.8.0-beta.1/routerforge-beta-bootstrap.sh | shBuild and verification
- RouterForge release:
0.8.0-beta.1 - Immutable release:
routerforge-v0.8.0-beta.1 - Commit:
b3ec295 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.7.2 Stable
released this
2026-09-12 14:29:15 +03:00 | 24 commits to main since this releaseRouterForge 0.7.2
🇷🇺 Русский
RouterForge 0.7.2
Что нового
- Stable 0.7.2 — точечный DNS-hotfix: версионно обновляется только routerforge-dns до 0.7.2; Core, Admin, Monitoring и Profiling остаются на 0.7.1.
- DNS получил встроенный каталог базовых DoT/DoH-провайдеров, отключённый по умолчанию и не занимающий secure slots до явного включения.
- UI резолверов разделён на Keenetic / свои, Публичные DNS и Частные DNS с группировкой по провайдерам и сворачиваемыми секциями.
Исправления
- Телеметрия DNS изолирована от повторного использования локального secure-порта: смена semantic resolver identity очищает port-owned counters, rolling history, fallback/error/client attribution и pending state.
- Каталог сокращён до 12 базовых провайдеров × DoT/DoH; semantic endpoint dedup скрывает виртуальный preset, если эквивалентный резолвер уже настроен вручную.
- Отключённые ручные DoT/DoH известных провайдеров классифицируются в Public/Private без превращения в read-only preset; AstraCat распознаётся также по dns.astracat.network, Comss.one относится к Private.
- Сворачивание секций использует прямую Svelte state binding: реакция на клик мгновенная, плавная анимация не зависит от фонового polling.
- На вкладке Resolvers отключён тяжёлый 5-секундный full refresh; первичная загрузка, ручное обновление и refresh после mutations сохранены.
- Статус ОТКЛЮЧЕН для встроенных DNS приведён к общей disabled-семантике и цветовой схеме.
Совместимость
- routerforge-dns 0.7.2 требует RouterForge Core 0.7.1 или новее.
- routerforge-core, routerforge-admin, routerforge-monitoring и routerforge-profiling в Stable 0.7.2 остаются версии 0.7.1.
- ARM64 aarch64-3.10 остаётся production target; MIPS и MIPSel сохраняют experimental status.
- Beta channel этим Stable hotfix не изменяется.
Технические изменения
- DoT port-reuse isolation прошла hardware acceptance на реальном Keenetic без перезапуска routerforge-dns; после возврата исходного resolver на переиспользованный порт cumulative/history начинались с нуля.
- DoH использует тот же общий semantic identity механизм, но отдельный DoH-specific hardware port-reuse сценарий не заявляется как выполненный.
- Stable 0.7.2 собирается из exact validated Dev SHA и продвигается в main только после successful FULL RELEASE с publish_beta=false.
- Immutable routerforge-v0.7.1 не изменяется; 0.7.2 создаётся отдельным immutable snapshot.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.7.1RouterForge DNS 0.7.2RouterForge Control 0.7.1RouterForge Monitoring 0.7.1Profiling 0.7.1Установка
Свежая установка RouterForge Stable:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.2/routerforge-stable-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.7.2 - Архивный релиз:
routerforge-v0.7.2 - Коммит:
f4a67a5 - Release index:
routerforge-stable-index.json - Bootstrap:
routerforge-stable-bootstrap.sh
🇬🇧 English
RouterForge 0.7.2
What's new
- Stable 0.7.2 is a focused DNS hotfix: only routerforge-dns advances to 0.7.2; Core, Admin, Monitoring, and Profiling remain at 0.7.1.
- DNS now includes a curated baseline DoT/DoH provider catalog that is disabled by default and consumes no secure slots until explicitly enabled.
- Resolver UI is split into Keenetic/custom, Public DNS, and Private DNS with provider grouping and collapsible sections.
Fixes
- DNS telemetry is isolated across secure local-port reuse: a semantic resolver identity change clears port-owned counters, rolling history, fallback/error/client attribution, and pending state.
- The catalog is reduced to 12 baseline providers × DoT/DoH; semantic endpoint dedup hides a virtual preset when an equivalent resolver is already configured manually.
- Disabled manual DoT/DoH entries for known providers are classified into Public/Private without becoming read-only presets; AstraCat also recognizes dns.astracat.network and Comss.one is classified as Private.
- Resolver section collapse now uses direct Svelte state bindings, so click response is immediate and smooth animation no longer depends on background polling.
- The heavy 5-second full refresh is disabled on the Resolvers view while initial load, manual refresh, and post-mutation refresh remain intact.
- Built-in disabled resolver status now uses the same disabled semantics and visual treatment as normal disabled resolvers.
Compatibility
- routerforge-dns 0.7.2 requires RouterForge Core 0.7.1 or newer.
- routerforge-core, routerforge-admin, routerforge-monitoring, and routerforge-profiling remain at version 0.7.1 in Stable 0.7.2.
- ARM64 aarch64-3.10 remains the production target; MIPS and MIPSel remain experimental.
- The Beta channel is not changed by this Stable hotfix.
Technical changes
- DoT port-reuse isolation passed hardware acceptance on a real Keenetic without restarting routerforge-dns; when the original resolver returned to a reused port, cumulative/history state restarted from zero.
- DoH uses the same generic semantic identity mechanism, but a separate DoH-specific hardware port-reuse scenario is not claimed as completed.
- Stable 0.7.2 is built from the exact validated Dev SHA and reaches main only after a successful FULL RELEASE with publish_beta=false.
- Immutable routerforge-v0.7.1 is never modified; 0.7.2 is published as a separate immutable snapshot.
Current component versions
Component Version RouterForge Core 0.7.1RouterForge DNS 0.7.2RouterForge Control 0.7.1RouterForge Monitoring 0.7.1Profiling 0.7.1Installation
Fresh RouterForge Stable install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.2/routerforge-stable-bootstrap.sh | shBuild and verification
- RouterForge release:
0.7.2 - Immutable release:
routerforge-v0.7.2 - Commit:
f4a67a5 - Release index:
routerforge-stable-index.json - Bootstrap:
routerforge-stable-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.7.1 Stable
released this
2026-09-11 16:45:00 +03:00 | 41 commits to main since this releaseRouterForge 0.7.1 — полный патчноут
Дата релиза: 11 сентября 2026
Этот документ описывает изменения Stable 0.7.1 относительно Stable 0.6.1.
0.7.1 — большой функциональный релиз. За один цикл RouterForge получил полноценный Management v2, файловый менеджер, два интерактивных терминала, объединённый Monitoring, усиленный DNS runtime, более зрелый Центр приложений, безопасное обнаружение локальных Web UI и более строгую цепочку сборки и публикации релизов.
Note
RouterForge — независимый некоммерческий проект сообщества и не является официальным продуктом Keenetic, Netcraze, Entware или других упомянутых компаний/проектов.
Базовая точка сравнения: Stable 0.6.1
Immutable release
routerforge-v0.6.1содержал следующую основную package topology:Компонент Версия в Stable 0.6.1 routerforge-core0.6.1routerforge-dns0.4.20routerforge-admin0.3.1routerforge-system0.3.1routerforge-thermal0.3.2routerforge-storage0.3.2routerforge-network0.3.3routerforge-profiling0.3.0В Stable 0.7.1 релизный train сведён к пяти пакетам:
routerforge-core routerforge-dns routerforge-admin routerforge-monitoring routerforge-profilingДля этого Stable-релиза все пять пакетов имеют version
0.7.1.Tip
Это выравнивание версий относится именно к релизному train 0.7.1. Архитектура RouterForge по-прежнему допускает независимое версионирование Core и модулей в отдельных component releases.
Главное в 0.7.1
- Management стал полноценной пользовательской областью, а не только read-only helper.
- Появился File Manager с Commander/Explorer, редактором, деревом, томами и guarded mutations.
- Появились Entware Terminal и Keenetic NDM Console.
- Четыре Monitoring-пакета объединены в один
routerforge-monitoring. - DNS получил дополнительные hardening/performance changes и компактные event rings.
- App Center стал полноценной общей точкой управления RouterForge/Integrations/Entware.
- Появилось безопасное обнаружение локальных Web UI без слепого LAN-сканирования.
- Усилены auth/runtime/network boundaries.
- Stable promotion теперь привязан к exact SHA и заранее проверенному promotion artifact.
- ARM64 проходит физические проверки на двух моделях: KN-3811 и KN-1812.
- MIPSel получил частичную физическую проверку на KN-1010.
Сильные стороны RouterForge
Нативная интеграция с Keenetic
RouterForge не ограничивается generic Linux-информацией. Он умеет работать с KeeneticOS/NDMS и использует:
ndmc;- RCI;
- DNS configuration/runtime;
- policy routing;
- сведения об интерфейсах и маршрутах;
- Entware services и OPKG;
- системные данные устройства.
За счёт этого RouterForge может показывать и изменять Keenetic-специфичные сущности, которые универсальная Linux-панель обычно не понимает.
Модульность с единым Web UI
Core остаётся единой пользовательской точкой входа на
:2233.DNS, Management и Monitoring:
- устанавливаются отдельно;
- имеют собственные runtime-модули;
- общаются с Core через root-owned Unix sockets;
- не требуют отдельного внешнего Web-порта.
Ограниченные контракты для привилегированных действий
RouterForge не превращает каждую кнопку в произвольную root-shell строку.
Привилегированные операции используют:
- проверку root-session;
- same-origin boundary;
- whitelists/фиксированные действия;
- точную валидацию цели;
- canonical path containment;
- Core-injected internal markers;
- rollback/readback там, где операция может изменить системную конфигурацию.
Оптимизация под постоянно работающий роутер
0.7.1 продолжает курс на ограниченное потребление ресурсов:
- bounded caches;
- bounded history;
- bounded auth/job state;
- последовательный polling;
- request timeouts;
- failure backoff;
- compact DNS event storage;
- production executable compression;
- отсутствие Node.js в router runtime.
Центр приложений как единая точка управления
Один интерфейс объединяет:
- официальные RouterForge packages;
- Integrations;
- Entware;
- Installed;
- Updates.
Пользователю не требуется вручную собирать состояние из нескольких независимых package/UI surfaces.
Проверяемый supply/release path
Release-index содержит exact versions/assets/URLs/SHA256.
Stable:
- строится для трёх targets;
- проходит CI/QEMU и package validation;
- создаёт отдельный promotion artifact;
- продвигается только тем же exact SHA;
- публикует rolling Stable и versioned snapshot.
1. Management v2
В 0.6.1
routerforge-adminбыл существенно более ранним Management/Control helper. В 0.7.1 он превращён в полноценную пользовательскую capability.Processes
Добавлены защищённые действия над процессами:
TERM HUP INT KILLBackend проверяет конкретную цель. Browser не передаёт произвольную команду оболочки.
Entware Services
Добавлены действия:
start stop restartОни применяются к разрешённым init scripts и требуют live root-session.
Security contract
Для Management mutations используются:
- live Entware-root session;
- same-origin checks;
- confirmation/whitelist;
- Core-injected internal Admin marker.
Это отделяет read-only monitoring от действительно привилегированных действий.
2. File Manager
В 0.7.1 появился полноценный File Manager.
Интерфейс
Реализованы:
- Commander;
- Explorer;
- дерево каталогов;
- список доступных томов;
- навигация;
- UTF-8 editor;
- create directory;
- rename/move;
- download;
- non-recursive delete;
- properties;
- visual
chmod; - responsive/compact toolbar;
- leaf-aware tree navigation.
Filesystem boundary
Разрешённые корни для mutations:
/opt /tmpЗащита включает:
- запрет явного
..; - canonical path resolution;
- symlink containment;
- повторную проверку цели перед destructive operation;
- size/mtime preconditions для edit;
- atomic same-filesystem replacement.
Что намеренно не обещается в Stable 0.7.1
Остаются за пределами заявленного готового набора:
- полноценное recursive directory copy/delete;
- arbitrary binary upload;
- archive/extract;
chown;- произвольный write-доступ по всей системной
/.
3. Entware Terminal
Добавлен полноценный browser terminal для Entware:
- WebSocket;
- PTY;
- фиксированный
/opt/bin/sh -il; - интерактивный resize;
- reconnect/switch semantics.
Terminal использует существующую RouterForge auth boundary.
4. Keenetic NDM Console
В Management добавлена отдельная Keenetic NDM Console.
Backend:
- server-side resolve'ит
ndmc; - запускает фиксированный
ndmc; - не принимает executable или произвольный argv из browser request;
- использует PTY/WebSocket transport.
Browser выбирает только:
mode=entware mode=keeneticАппаратно проверены:
- Entware PTY;
- Keenetic PTY;
ndmc show version;- повторное переключение Entware ↔ Keenetic.
5. Monitoring: миграция 4 → 1
Stable 0.6.1 публиковал четыре отдельных monitoring package:
routerforge-system routerforge-thermal routerforge-storage routerforge-networkStable 0.7.1 использует единый:
routerforge-monitoringОн обслуживает:
- System;
- Thermal;
- Storage;
- Network.
Зачем объединение
- меньше отдельных runtime-процессов;
- один package lifecycle;
- один UI;
- меньше дублирования;
- проще установка и обновление;
- единая точка дальнейшей оптимизации.
Миграция старых установок
routerforge-monitoringиспользуетProvides/Conflicts/Replaces.Post-install logic:
- останавливает старые split services;
- удаляет stale sockets;
- запускает consolidated runtime.
Сохранены intentional compatibility sockets/API для System/Thermal/Storage/Network, поэтому наличие legacy-named socket после migration само по себе не означает, что старый процесс всё ещё работает.
На ARM64 проверены:
- package database cleanup;
- отсутствие старых binaries/init scripts;
- consolidated process;
- expected sockets;
- reboot;
- autostart.
6. DNS: безопасные изменения
routerforge-dnsостаётся отдельным Module ABI v1 runtime.Для resolver mutations используется цепочка:
snapshot -> validation -> mutation -> save -> readback -> semantic compare -> verified rollback при mismatchПоддерживаются:
- plain DNS;
- DoT;
- DoH;
- Add/Edit/Delete;
- временный Disable/Enable;
- logical multi-domain grouping;
- read-only защита DHCP/service entries.
Такая модель важнее обычного «команда вернула 0»: RouterForge проверяет, что Keenetic действительно сохранил ожидаемое состояние.
7. DNS: наблюдаемость и диагностика
В 0.7.1 сохранена и расширена DNS observability:
- запросы и история;
- clients;
- LAN/Wi-Fi attribution;
- domains/QTYPEs;
- upstream/fallback;
- timeout/error;
- latency;
- quality windows;
- error bursts;
- runtime/system health;
- policy-routing-aware upstream diagnostics;
- локальный/cache path.
8. DNS: производительность и hardening
Добавлены/усилены:
- kernel BPF filtering перед userspace processing;
- bounded TTL/last-good caches;
- failure backoff;
- bounded frontend read timeouts;
- compact internal event representation;
- отсутствие постоянной event-записи на flash в горячем пути.
Логическая глубина DNS event history сохранена на 10 000 событий.
Это структурная оптимизация памяти и allocation pressure. Релиз не заявляет неподтверждённую «магическую» цифру экономии RSS.
9. Центр приложений
App Center в 0.7.1 объединяет:
RouterForge Integrations Entware Installed UpdatesLifecycle jobs
Для package actions используются:
- preflight;
- dependencies;
- download/installed sizes;
- guarded async jobs;
- global package-manager lock;
- SSE output;
- timeout;
- cancel;
- post-action refresh;
- installed-version verification;
- bounded completed-job history.
Bulk update
При массовом обновлении:
- обновляются modules;
- Core идёт последним.
Это снижает риск оборвать оставшиеся операции перезапуском Core.
10. Generic Runtime Web UI Discovery
В 0.7.1 local Web UI discovery строится по цепочке:
LISTEN socket -> PID/process -> package -> bounded local HTTP/HTTPS probeRouterForge не сканирует вслепую всю LAN/subnet.
Используются fail-closed boundaries для:
- redirects;
- X-Frame-Options;
- CSP;
- SSRF;
- infrastructure/platform services;
- duplicate known integrations.
11. Core runtime
Один внешний Web listener
Core остаётся единственным пользовательским RouterForge LAN listener:
:2233DNS/Admin/Monitoring работают через root-owned Unix sockets.
Profiling, если установлен, остаётся loopback-only:
127.0.0.1:6061HTTP hardening
Добавлены/уточнены:
- read timeout;
- header timeout;
- idle timeout;
- header-size limit.
Глобальный
WriteTimeoutнамеренно не включён, чтобы не ломать долгоживущие SSE streams.Module proxy
Mutation request bodies ограничиваются до Unix-socket forwarding, чтобы oversized request не превращался в неограниченную нагрузку на privileged module.
12. Frontend и polling
В Core/Admin/Monitoring:
- periodic reads переведены на serial scheduling;
- устранено накопление overlapping async
setInterval; - read requests используют bounded AbortController timeouts;
- slow request не должен бесконечно накапливать следующие.
Для DNS mutation semantics timeout применяется осторожно: потенциально уже выполненная системная мутация не должна ложно объявляться «не выполненной» только из-за frontend timeout.
13. Thermal/Storage/ndmc hot paths
Для дорогих или часто вызываемых collectors используются:
- TTL caches;
- last-good value;
- singleflight;
- stale-while-revalidate;
- failure backoff.
Storage
Statfsразделён по platform-specific implementation для лучшей portability/cross-build дисциплины.14. Auth и bounded state
В 0.7.1:
- failed-login clients имеют ограниченный размер;
- stale entries очищаются;
- tracking rate-limited;
- session token остаётся in-memory;
- password RouterForge не сохраняет;
- cookie использует
HttpOnly+SameSite=Strict.
App Center completed-job history также bounded.
15. UI и визуальная согласованность
Management, Maintenance, File Properties и Terminal приведены к общей semantic RouterForge theme-модели.
Исправлялись:
- поверхности;
- borders;
- muted/text states;
- toolbar density;
- responsive layout;
- terminal presentation;
- active/hover/focus states.
Цель — чтобы standalone modules визуально воспринимались как части одной системы.
16. Release pipeline: Dev, Beta и Stable разделены
Dev
Push в
devпредназначен для development train и rolling Dev.Beta
Beta публикуется только explicit FULL RELEASE на проверенном SHA.
Beta version train имеет fail-closed consistency guard между:
release_version;- component versions;
min_core_version.
Guard появился после обнаружения реального класса ошибки, когда versioned Beta tag мог не совпасть с package train.
Stable
Stable promotion:
- строится на exact Dev SHA;
- проходит полный release validation;
- формирует
routerforge-stable-promotion; - тот же exact SHA продвигается в
main; - main скачивает именно этот promotion artifact;
- artifact повторно проверяется;
- после этого обновляется rolling Stable;
- создаётся versioned release.
17. Stable 0.7.1 multiarch release
Stable 0.7.1 публикует:
- 5 packages;
- 3 targets;
- 15 IPK;
- 3 target release-index;
- SHA256SUMS;
- universal bootstrap;
- target-specific bootstraps.
Targets:
aarch64-3.10 mips-3.4 mipsel-3.4ARM64 — production/hardware-validated target.
MIPSel и MIPS остаются experimental.
18. Аппаратная матрица разработки и релиза
Keenetic Hopper KN-3811 — Dev + Beta
KN-3811 используется как основная ARM64-площадка для:
- текущей разработки;
- функциональных hardware checks;
- rolling Dev;
- Beta validation.
Keenetic Ultra KN-1812 — Beta + Stable
KN-1812 используется для:
- дополнительной/финальной Beta validation;
- проверки релизной версии;
- Stable hardware checks.
Именно на Ultra, в частности, проверялись browser PTY для Entware/Keenetic и переключение режимов терминала.
Keenetic Giga KN-1010 — MIPSel experimental
На KN-1010 есть частичная физическая проверка MIPSel:
- fresh install;
- базовая нормальная работа.
Полная MIPSel matrix — upgrade/rollback/uninstall, полный DNS/Management coverage и resource stress — пока не заявляется закрытой.
MIPS big-endian
Physical hardware validation отсутствует.
Cross-build/QEMU/runtime probes важны, но не приравниваются к реальному hardware PASS.
19. Что изменилось для пользователя 0.6.1 → 0.7.1
Наиболее заметные изменения:
- вместо раннего Control — полноценный Management v2;
- появился File Manager;
- появился browser Entware Terminal;
- появилась Keenetic NDM Console;
- четыре monitoring package заменены одним;
- App Center стал шире и надёжнее;
- DNS runtime получил дополнительные performance/hardening changes;
- multiarch/release pipeline стал строже;
- Beta и Stable проходят более формализованную hardware validation.
20. Обновление с Stable 0.6.1
Рекомендуемый путь:
- Запустить актуальный Stable bootstrap.
- Открыть Центр приложений.
- Нажать «Проверить обновления».
- Обновить установленные RouterForge packages.
- Проверить migration split monitoring →
routerforge-monitoring. - Проверить health Core и нужных modules.
Не рекомендуется вручную удалять старые package-owned monitoring files, чтобы «починить» migration: штатный lifecycle должен сам провести замену.
21. Что сознательно остаётся за пределами обещаний 0.7.1
Stable 0.7.1 не объявляет завершёнными:
- recursive directory copy/delete во всех File Manager сценариях;
- arbitrary binary upload;
- archive/extract;
chown;- MIPS big-endian hardware validation;
- полную MIPSel hardware matrix;
- неподтверждённые RSS-рекорды от DNS compact rings.
22. Итог
По сравнению с Stable 0.6.1 RouterForge 0.7.1 заметно меняет сам класс продукта:
- Management превращается из вспомогательного read-only слоя в реальный инструмент управления;
- Monitoring становится компактнее по topology;
- DNS получает более строгие safety/performance boundaries;
- App Center становится центральной точкой управления пакетами и локальными приложениями;
- терминалы дают доступ и к Entware, и к Keenetic NDM в одном UI;
- релизная цепочка становится exact-SHA и fail-closed;
- hardware validation распределена между KN-3811 и KN-1812, а MIPSel получает отдельную физическую проверку.
Stable 0.7.1 — это уже не просто набор диагностических экранов, а модульная платформа управления и наблюдения для Keenetic/Netcraze с Entware.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.7.1-beta.4 Pre-release
released this
2026-09-11 14:37:21 +03:00 | 43 commits to main since this releaseRouterForge 0.7.1-beta.4
🇷🇺 Русский
RouterForge 0.7.1-beta.4
Что нового
- Management/Admin Terminal теперь включает аппаратно проверенную Keenetic NDM Console: отдельная вкладка запускает фиксированный ndmc через защищённый WebSocket/PTY backend, а переключение Entware ↔ Keenetic проверено на Keenetic Ultra KN-1812.
- Management/Admin получил полноценный Entware Terminal на WebSocket/PTY и переработанный файловый менеджер с Commander, Explorer, деревом каталогов, выбором томов, редактором, свойствами файлов и visual chmod.
- Новый Beta train 0.7.1 переводит системный мониторинг на единый пакет routerforge-monitoring: один read-only runtime и один UI заменяют отдельные system/thermal/storage/network пакеты, сохраняя совместимые API и Unix-socket endpoints.
- Monitoring получил собственный standalone Svelte/Vite UI с разделами System, Thermal, Storage, Network и Profiling; Core теперь выступает shell/host, а не владеет страницей мониторинга.
- RouterForge Control получил standalone UI и Management v2 backend contract для root-session protected process/service mutations. Текущий UI остаётся read-only; mutation API подготовлен и аппаратно проверен отдельно от будущих управляющих кнопок.
- Dev и Beta теперь разведены: каждый push в dev публикует rolling ARM64 Dev train, а Beta выпускается только явным FULL RELEASE на проверенном exact SHA.
- Beta 0.7.1 использует prerelease-safe opkg versions вида 0.7.1~beta.4, тогда как GitHub asset/tag сохраняют читаемую форму 0.7.1-beta.4. Это гарантирует корректный порядок Beta < будущий Stable 0.7.1.
- Получена первая физическая MIPSel-проверка на Keenetic Giga KN-1010: fresh installation и базовая штатная работа RouterForge подтверждены на реальном устройстве.
Исправления
- DNS event rings переведены на компактное внутреннее хранение с сохранением логической глубины retention 10 000 и без изменения публичных FlowEvent/ClientFlowEvent API-контрактов.
- Management theme и Maintenance layout выровнены по семантическим rf-токенам; окно свойств файлов, Terminal и связанные панели корректнее следуют активной теме.
- App Center получил корректное обновление registry после package actions, устойчивый bulk-update без ложных lifecycle errors, раздельную проверку RouterForge, Integrations и Entware, общую проверку обновлений и исправленную адаптивную панель. Статусы модулей унифицированы в ON/OFF/UPDATE.
- Generic Web UI Discovery больше не выполняет произвольные TCP LISTEN probes: probing ограничен обнаруженными локальными application endpoints и сохраняет fail-closed SSRF/XFO/CSP boundary.
- DNS passive capture получил kernel BPF filtering до userspace обработки, уменьшая ненужный packet-processing overhead.
- Обычный GET /api/catalog больше не запускает дорогой active discovery; remote/discovery refresh вынесен в отдельный guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh защищён same-origin проверкой, singleflight и rate limiting, поэтому повторные refresh не размножают дорогостоящую работу.
- Core frontend polling переведён на serial scheduling без async setInterval overlap; сетевые read/write helpers получили AbortController timeout policy и гарантированную очистку timer.
- Standalone Admin и Monitoring UI используют тот же serial polling contract; медленный запрос больше не порождает несколько параллельных периодических циклов.
- Standalone DNS UI получил 12-секундный timeout для GET/HEAD reads, при этом mutation requests намеренно не получают короткий UI timeout, чтобы не сообщать ложный failure после уже применённой router mutation.
- Monitoring thermal path переведён на stale-while-revalidate/singleflight: request path не запускает конкурентные refresh/smartctl операции, а last-good snapshot публикуется без блокировки UI.
- DNS info, resolver auxiliary discovery и Monitoring Keenetic network metadata получили bounded TTL caches/last-good semantics; повторный ndmc polling заметно сокращён.
- DNS background collector получил backoff после ошибок, чтобы failure loop не превращался в горячий polling.
- Monitoring storage Statfs вынесен в platform-specific implementation: Linux сохраняет прежнюю семантику, а non-Linux targets теперь безопасно cross-compile.
- App Center internal async job map получил terminal retention cap; древние завершённые jobs больше не накапливаются бесконечно в памяти Core.
- Core HTTP server получил ReadHeaderTimeout, ReadTimeout, IdleTimeout и MaxHeaderBytes; global WriteTimeout оставлен выключенным специально для долгоживущего SSE.
- Core generic module proxy ограничивает mutation request bodies до downstream contracts: DNS 64 KiB, Admin 8 KiB; oversize отклоняется до Unix-socket forwarding.
- Authentication failed-login tracking получил global stale pruning и строгий cap 1024 clients. Активные блокировки сохраняются приоритетно; lockout policy остаётся 5 ошибок / 5 минут / 30 секунд.
Совместимость
- ARM64 aarch64-3.10 остаётся основным и полностью аппаратно проверенным Beta target.
- MIPSel mipsel-3.4 теперь имеет реальную hardware evidence на Keenetic Giga KN-1010 для fresh installation и базовой штатной работы. Target остаётся experimental до проверки upgrade/rollback/uninstall, полного Module ABI/DNS сценария и resource footprint.
- MIPS mips-3.4 остаётся experimental preview без физической hardware validation; cross-build/QEMU/runtime-probe не считаются аппаратной проверкой.
- routerforge-monitoring Conflicts/Replaces/Provides старые routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network и сохраняет compatibility API для миграции.
- Fresh Beta bootstrap по-прежнему устанавливает только RouterForge Core; optional DNS, Monitoring, Control и Profiling выбираются через Центр приложений.
- Stable 0.6.1 и main не изменяются этим Beta release.
Технические изменения
- ARM64 Dev r287 (
621a060212) прошёл аппаратный gate Management Terminal: exact Admin package установлен на Keenetic Ultra KN-1812, ndmc show version — PASS, браузерные Entware PTY и Keenetic NDM PTY — PASS, переключение между вкладками — PASS. - ARM64 Dev r280 (
90d925d2ad) прошёл аппаратный runtime smoke: Core, Admin, File API, tree metadata и volumes — PASS. RouterForge остаётся единственным LAN listener на :2233. - Beta FULL RELEASE строит и публикует exact multi-arch package set: Core, DNS, Control, Monitoring и Profiling; rolling Beta alias после публикации получает coherent indexes/checksums/bootstrap, затем создаётся immutable routerforge-v0.7.1-beta.4 snapshot.
- Release tooling валидирует exact package order для Beta и проверяет 5 компонентов × 3 target = 15 IPK assets плюс SHA256SUMS и target-specific/universal bootstraps.
- Consolidated Monitoring package contract отдельно проверяется в CI: package metadata обязана объявлять legacy Provides/Conflicts/Replaces, payload не должен содержать старые split binaries/init scripts, а postinst должен останавливать legacy services перед запуском нового runtime.
- Для реального upgrade 4→1 добавлен read-only hardware migration gate: он проверяет package DB, отсутствие старых binaries/init scripts/processes, основной runtime и пять ожидаемых Unix sockets (primary + compatibility).
- routerforge-dev остаётся отдельным mutable ARM64-only каналом с версиями 0.7.1~dev.r. и больше не считается Beta.
- Core и module runtime общаются через root-owned Unix sockets; Core остаётся единственным RouterForge LAN listener на :2233.
- Management v2 mutation path требует POST, same-origin, live root session, exact confirmation, whitelist и Core-injected internal Unix-socket marker; arbitrary shell/path execution отсутствует.
- Core HTTP WriteTimeout=0 сохранён намеренно: SSE /api/events должен жить дольше обычных request read timeouts.
- DNS/Admin module mutation body limits применяются в Core до ReverseProxy, а downstream runtime продолжает собственную validation/JSON limit policy.
- Frontend standalone builds используют общие Core $lib helpers на этапе Vite bundling; Node.js на роутере не требуется.
- Phase 8 runtime audit закрыт на Dev r248 с hardware health evidence. Reboot persistence и destructive auth failure injection сознательно не заявляются как выполненные; MIPSel hardware evidence пока ограничена fresh install/basic operation на KN-1010.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.7.1~beta.4RouterForge DNS 0.7.1~beta.4RouterForge Control 0.7.1~beta.4RouterForge Monitoring 0.7.1~beta.4Profiling 0.7.1~beta.4Установка
Свежая установка RouterForge Beta:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.4/routerforge-beta-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.7.1-beta.4 - Архивный релиз:
routerforge-v0.7.1-beta.4 - Коммит:
4991a58 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
🇬🇧 English
RouterForge 0.7.1-beta.4
What's new
- Management/Admin Terminal now includes a hardware-validated Keenetic NDM Console: a dedicated tab launches fixed ndmc through the guarded WebSocket/PTY backend, and Entware ↔ Keenetic switching was validated on a Keenetic Ultra KN-1812.
- Management/Admin now includes a full Entware Terminal over WebSocket/PTY and a rebuilt file manager with Commander, Explorer, folder tree, volume selection, editor, file properties, and visual chmod.
- The 0.7.1 Beta train consolidates system monitoring into routerforge-monitoring: one read-only runtime and one UI replace the separate system/thermal/storage/network packages while preserving compatible APIs and Unix-socket endpoints.
- Monitoring now has its own standalone Svelte/Vite UI for System, Thermal, Storage, Network, and Profiling; Core acts as the shell/host instead of owning the monitoring page.
- RouterForge Control now has a standalone UI and a Management v2 backend contract for root-session-protected process/service mutations. The current UI remains read-only; mutation APIs are prepared and hardware-validated separately from future control buttons.
- Dev and Beta are now separate release channels: each dev push publishes the rolling ARM64 Dev train, while Beta is published only by an explicit FULL RELEASE on a verified exact SHA.
- Beta 0.7.1 uses prerelease-safe opkg versions such as 0.7.1~beta.4 while GitHub assets/tags keep the readable 0.7.1-beta.4 form, guaranteeing Beta sorts below future Stable 0.7.1.
- The first physical MIPSel validation is now recorded on Keenetic Giga KN-1010: fresh installation and basic normal RouterForge operation were confirmed on real hardware.
Fixes
- DNS event rings now use compact internal storage while preserving the logical retention depth of 10,000 events and keeping the public FlowEvent/ClientFlowEvent API contracts unchanged.
- Management theme and Maintenance layout now consistently use semantic rf tokens; File Properties, Terminal, and related panes follow the active theme more reliably.
- App Center now refreshes registry state correctly after package actions, completes bulk updates without false lifecycle errors, separates RouterForge, Integrations, and Entware update checks, adds a global update check, and fixes narrow-window toolbar layout. Module states are unified as ON/OFF/UPDATE.
- Generic Web UI Discovery no longer performs arbitrary TCP LISTEN probing; probing is limited to discovered local application endpoints while preserving fail-closed SSRF/XFO/CSP boundaries.
- DNS passive capture now applies kernel BPF filtering before userspace processing, reducing unnecessary packet-processing overhead.
- Normal GET /api/catalog no longer triggers expensive active discovery; remote/discovery refresh is isolated behind guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh now has same-origin validation, singleflight, and rate limiting so repeated refreshes cannot multiply expensive work.
- Core frontend polling uses serial scheduling instead of overlapping async setInterval calls; shared request helpers now enforce AbortController timeout policy with reliable timer cleanup.
- Standalone Admin and Monitoring UIs use the same serial polling contract, preventing slow requests from creating multiple concurrent periodic cycles.
- Standalone DNS UI now has a 12-second timeout for GET/HEAD reads, while mutation requests intentionally keep their previous timeout semantics to avoid false failures after a router mutation may already have committed.
- Monitoring thermal collection now uses stale-while-revalidate/singleflight: request paths do not launch concurrent refresh/smartctl work and last-good snapshots can be served without blocking the UI.
- DNS info, resolver auxiliary discovery, and Monitoring Keenetic network metadata now use bounded TTL caches/last-good semantics, substantially reducing repeated ndmc polling.
- The DNS background collector backs off after failures instead of turning an error condition into a hot polling loop.
- Monitoring storage Statfs is split into platform-specific implementations: Linux keeps the existing semantics while non-Linux targets cross-compile safely.
- The App Center async job map now has terminal retention; old completed jobs can no longer accumulate indefinitely in Core memory.
- The Core HTTP server now has ReadHeaderTimeout, ReadTimeout, IdleTimeout, and MaxHeaderBytes; the global WriteTimeout intentionally remains disabled for long-lived SSE.
- The generic Core module proxy bounds mutation bodies to downstream contracts: DNS 64 KiB and Admin 8 KiB, rejecting oversized requests before Unix-socket forwarding.
- Failed-login tracking now has global stale pruning and a strict 1024-client cap. Active blocks are preferred during eviction; lockout policy remains 5 failures / 5 minutes / 30 seconds.
Compatibility
- ARM64 aarch64-3.10 remains the primary fully hardware-validated Beta target.
- MIPSel mipsel-3.4 now has real hardware evidence on Keenetic Giga KN-1010 for fresh installation and basic normal operation. It remains experimental until upgrade/rollback/uninstall, full Module ABI/DNS behavior, and resource footprint are validated.
- MIPS mips-3.4 remains an experimental preview without physical hardware validation; cross-build/QEMU/runtime probes do not count as hardware validation.
- routerforge-monitoring Conflicts/Replaces/Provides the legacy routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network packages and preserves compatibility APIs for migration.
- Fresh Beta bootstrap still installs RouterForge Core only; optional DNS, Monitoring, Control, and Profiling are selected through App Center.
- Stable 0.6.1 and main are unchanged by this Beta release.
Technical changes
- ARM64 Dev r287 (
621a060212) passed the Management Terminal hardware gate on a Keenetic Ultra KN-1812: the exact Admin package installed successfully, ndmc show version passed, both browser Entware PTY and Keenetic NDM PTY passed, and tab switching passed. - ARM64 Dev r280 (
90d925d2ad) passed hardware runtime smoke for Core, Admin, File API, tree metadata, and volumes. RouterForge remains the only LAN listener on :2233. - Beta FULL RELEASE builds and publishes the exact multi-arch package set: Core, DNS, Control, Monitoring, and Profiling. After the rolling Beta alias is coherent, an immutable routerforge-v0.7.1-beta.4 snapshot is created.
- Release tooling validates exact Beta package order and verifies 5 components × 3 targets = 15 IPK assets together with SHA256SUMS and target-specific/universal bootstraps.
- The consolidated Monitoring package contract is checked in CI: package metadata must declare legacy Provides/Conflicts/Replaces, the payload must not contain old split binaries/init scripts, and postinst must stop legacy services before starting the new runtime.
- A read-only hardware migration gate is provided for the real 4→1 upgrade: it checks package DB state, absence of old binaries/init scripts/processes, the primary runtime, and all five expected Unix sockets (primary plus compatibility).
- routerforge-dev remains a separate mutable ARM64-only channel using 0.7.1~dev.r. versions and is no longer documented as Beta.
- Core and module runtimes communicate through root-owned Unix sockets; Core remains the only RouterForge LAN listener on :2233.
- Management v2 mutation paths require POST, same-origin, a live root session, exact confirmation, a whitelist, and a Core-injected internal Unix-socket marker; arbitrary shell/path execution is not exposed.
- Core HTTP WriteTimeout=0 is intentional so SSE /api/events can outlive normal request read timeouts.
- DNS/Admin mutation body limits are enforced in Core before ReverseProxy while downstream runtimes keep their own validation and JSON limits.
- Standalone frontend builds import shared Core $lib helpers at Vite bundle time; Node.js is not required on the router.
- The Phase 8 runtime audit is closed on Dev r248 with hardware health evidence. Reboot persistence and destructive auth-failure injection are explicitly not claimed; MIPSel hardware evidence is currently limited to fresh install/basic operation on KN-1010.
Current component versions
Component Version RouterForge Core 0.7.1~beta.4RouterForge DNS 0.7.1~beta.4RouterForge Control 0.7.1~beta.4RouterForge Monitoring 0.7.1~beta.4Profiling 0.7.1~beta.4Installation
Fresh RouterForge Beta install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.4/routerforge-beta-bootstrap.sh | shBuild and verification
- RouterForge release:
0.7.1-beta.4 - Immutable release:
routerforge-v0.7.1-beta.4 - Commit:
4991a58 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.7.1-beta.3 Pre-release
released this
2026-09-11 14:11:32 +03:00 | 44 commits to main since this releaseRouterForge 0.7.1-beta.3
🇷🇺 Русский
RouterForge 0.7.1-beta.3
Что нового
- Management/Admin Terminal теперь включает аппаратно проверенную Keenetic NDM Console: отдельная вкладка запускает фиксированный ndmc через защищённый WebSocket/PTY backend, а переключение Entware ↔ Keenetic проверено на Keenetic Ultra KN-1812.
- Management/Admin получил полноценный Entware Terminal на WebSocket/PTY и переработанный файловый менеджер с Commander, Explorer, деревом каталогов, выбором томов, редактором, свойствами файлов и visual chmod.
- Новый Beta train 0.7.1 переводит системный мониторинг на единый пакет routerforge-monitoring: один read-only runtime и один UI заменяют отдельные system/thermal/storage/network пакеты, сохраняя совместимые API и Unix-socket endpoints.
- Monitoring получил собственный standalone Svelte/Vite UI с разделами System, Thermal, Storage, Network и Profiling; Core теперь выступает shell/host, а не владеет страницей мониторинга.
- RouterForge Control получил standalone UI и Management v2 backend contract для root-session protected process/service mutations. Текущий UI остаётся read-only; mutation API подготовлен и аппаратно проверен отдельно от будущих управляющих кнопок.
- Dev и Beta теперь разведены: каждый push в dev публикует rolling ARM64 Dev train, а Beta выпускается только явным FULL RELEASE на проверенном exact SHA.
- Beta 0.7.1 использует prerelease-safe opkg versions вида 0.7.1~beta.3, тогда как GitHub asset/tag сохраняют читаемую форму 0.7.1-beta.3. Это гарантирует корректный порядок Beta < будущий Stable 0.7.1.
- Получена первая физическая MIPSel-проверка на Keenetic Giga KN-1010: fresh installation и базовая штатная работа RouterForge подтверждены на реальном устройстве.
Исправления
- DNS event rings переведены на компактное внутреннее хранение с сохранением логической глубины retention 10 000 и без изменения публичных FlowEvent/ClientFlowEvent API-контрактов.
- Management theme и Maintenance layout выровнены по семантическим rf-токенам; окно свойств файлов, Terminal и связанные панели корректнее следуют активной теме.
- App Center получил корректное обновление registry после package actions, устойчивый bulk-update без ложных lifecycle errors, раздельную проверку RouterForge, Integrations и Entware, общую проверку обновлений и исправленную адаптивную панель. Статусы модулей унифицированы в ON/OFF/UPDATE.
- Generic Web UI Discovery больше не выполняет произвольные TCP LISTEN probes: probing ограничен обнаруженными локальными application endpoints и сохраняет fail-closed SSRF/XFO/CSP boundary.
- DNS passive capture получил kernel BPF filtering до userspace обработки, уменьшая ненужный packet-processing overhead.
- Обычный GET /api/catalog больше не запускает дорогой active discovery; remote/discovery refresh вынесен в отдельный guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh защищён same-origin проверкой, singleflight и rate limiting, поэтому повторные refresh не размножают дорогостоящую работу.
- Core frontend polling переведён на serial scheduling без async setInterval overlap; сетевые read/write helpers получили AbortController timeout policy и гарантированную очистку timer.
- Standalone Admin и Monitoring UI используют тот же serial polling contract; медленный запрос больше не порождает несколько параллельных периодических циклов.
- Standalone DNS UI получил 12-секундный timeout для GET/HEAD reads, при этом mutation requests намеренно не получают короткий UI timeout, чтобы не сообщать ложный failure после уже применённой router mutation.
- Monitoring thermal path переведён на stale-while-revalidate/singleflight: request path не запускает конкурентные refresh/smartctl операции, а last-good snapshot публикуется без блокировки UI.
- DNS info, resolver auxiliary discovery и Monitoring Keenetic network metadata получили bounded TTL caches/last-good semantics; повторный ndmc polling заметно сокращён.
- DNS background collector получил backoff после ошибок, чтобы failure loop не превращался в горячий polling.
- Monitoring storage Statfs вынесен в platform-specific implementation: Linux сохраняет прежнюю семантику, а non-Linux targets теперь безопасно cross-compile.
- App Center internal async job map получил terminal retention cap; древние завершённые jobs больше не накапливаются бесконечно в памяти Core.
- Core HTTP server получил ReadHeaderTimeout, ReadTimeout, IdleTimeout и MaxHeaderBytes; global WriteTimeout оставлен выключенным специально для долгоживущего SSE.
- Core generic module proxy ограничивает mutation request bodies до downstream contracts: DNS 64 KiB, Admin 8 KiB; oversize отклоняется до Unix-socket forwarding.
- Authentication failed-login tracking получил global stale pruning и строгий cap 1024 clients. Активные блокировки сохраняются приоритетно; lockout policy остаётся 5 ошибок / 5 минут / 30 секунд.
Совместимость
- ARM64 aarch64-3.10 остаётся основным и полностью аппаратно проверенным Beta target.
- MIPSel mipsel-3.4 теперь имеет реальную hardware evidence на Keenetic Giga KN-1010 для fresh installation и базовой штатной работы. Target остаётся experimental до проверки upgrade/rollback/uninstall, полного Module ABI/DNS сценария и resource footprint.
- MIPS mips-3.4 остаётся experimental preview без физической hardware validation; cross-build/QEMU/runtime-probe не считаются аппаратной проверкой.
- routerforge-monitoring Conflicts/Replaces/Provides старые routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network и сохраняет compatibility API для миграции.
- Fresh Beta bootstrap по-прежнему устанавливает только RouterForge Core; optional DNS, Monitoring, Control и Profiling выбираются через Центр приложений.
- Stable 0.6.1 и main не изменяются этим Beta release.
Технические изменения
- ARM64 Dev r287 (
621a060212) прошёл аппаратный gate Management Terminal: exact Admin package установлен на Keenetic Ultra KN-1812, ndmc show version — PASS, браузерные Entware PTY и Keenetic NDM PTY — PASS, переключение между вкладками — PASS. - ARM64 Dev r280 (
90d925d2ad) прошёл аппаратный runtime smoke: Core, Admin, File API, tree metadata и volumes — PASS. RouterForge остаётся единственным LAN listener на :2233. - Beta FULL RELEASE строит и публикует exact multi-arch package set: Core, DNS, Control, Monitoring и Profiling; rolling Beta alias после публикации получает coherent indexes/checksums/bootstrap, затем создаётся immutable routerforge-v0.7.1-beta.3 snapshot.
- Release tooling валидирует exact package order для Beta и проверяет 5 компонентов × 3 target = 15 IPK assets плюс SHA256SUMS и target-specific/universal bootstraps.
- Consolidated Monitoring package contract отдельно проверяется в CI: package metadata обязана объявлять legacy Provides/Conflicts/Replaces, payload не должен содержать старые split binaries/init scripts, а postinst должен останавливать legacy services перед запуском нового runtime.
- Для реального upgrade 4→1 добавлен read-only hardware migration gate: он проверяет package DB, отсутствие старых binaries/init scripts/processes, основной runtime и пять ожидаемых Unix sockets (primary + compatibility).
- routerforge-dev остаётся отдельным mutable ARM64-only каналом с версиями 0.7.1~dev.r. и больше не считается Beta.
- Core и module runtime общаются через root-owned Unix sockets; Core остаётся единственным RouterForge LAN listener на :2233.
- Management v2 mutation path требует POST, same-origin, live root session, exact confirmation, whitelist и Core-injected internal Unix-socket marker; arbitrary shell/path execution отсутствует.
- Core HTTP WriteTimeout=0 сохранён намеренно: SSE /api/events должен жить дольше обычных request read timeouts.
- DNS/Admin module mutation body limits применяются в Core до ReverseProxy, а downstream runtime продолжает собственную validation/JSON limit policy.
- Frontend standalone builds используют общие Core $lib helpers на этапе Vite bundling; Node.js на роутере не требуется.
- Phase 8 runtime audit закрыт на Dev r248 с hardware health evidence. Reboot persistence и destructive auth failure injection сознательно не заявляются как выполненные; MIPSel hardware evidence пока ограничена fresh install/basic operation на KN-1010.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.7.1~beta.2RouterForge DNS 0.7.1~beta.2RouterForge Control 0.7.1~beta.2RouterForge Monitoring 0.7.1~beta.2Profiling 0.7.1~beta.2Установка
Свежая установка RouterForge Beta:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.3/routerforge-beta-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.7.1-beta.3 - Архивный релиз:
routerforge-v0.7.1-beta.3 - Коммит:
666a068 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
🇬🇧 English
RouterForge 0.7.1-beta.3
What's new
- Management/Admin Terminal now includes a hardware-validated Keenetic NDM Console: a dedicated tab launches fixed ndmc through the guarded WebSocket/PTY backend, and Entware ↔ Keenetic switching was validated on a Keenetic Ultra KN-1812.
- Management/Admin now includes a full Entware Terminal over WebSocket/PTY and a rebuilt file manager with Commander, Explorer, folder tree, volume selection, editor, file properties, and visual chmod.
- The 0.7.1 Beta train consolidates system monitoring into routerforge-monitoring: one read-only runtime and one UI replace the separate system/thermal/storage/network packages while preserving compatible APIs and Unix-socket endpoints.
- Monitoring now has its own standalone Svelte/Vite UI for System, Thermal, Storage, Network, and Profiling; Core acts as the shell/host instead of owning the monitoring page.
- RouterForge Control now has a standalone UI and a Management v2 backend contract for root-session-protected process/service mutations. The current UI remains read-only; mutation APIs are prepared and hardware-validated separately from future control buttons.
- Dev and Beta are now separate release channels: each dev push publishes the rolling ARM64 Dev train, while Beta is published only by an explicit FULL RELEASE on a verified exact SHA.
- Beta 0.7.1 uses prerelease-safe opkg versions such as 0.7.1~beta.3 while GitHub assets/tags keep the readable 0.7.1-beta.3 form, guaranteeing Beta sorts below future Stable 0.7.1.
- The first physical MIPSel validation is now recorded on Keenetic Giga KN-1010: fresh installation and basic normal RouterForge operation were confirmed on real hardware.
Fixes
- DNS event rings now use compact internal storage while preserving the logical retention depth of 10,000 events and keeping the public FlowEvent/ClientFlowEvent API contracts unchanged.
- Management theme and Maintenance layout now consistently use semantic rf tokens; File Properties, Terminal, and related panes follow the active theme more reliably.
- App Center now refreshes registry state correctly after package actions, completes bulk updates without false lifecycle errors, separates RouterForge, Integrations, and Entware update checks, adds a global update check, and fixes narrow-window toolbar layout. Module states are unified as ON/OFF/UPDATE.
- Generic Web UI Discovery no longer performs arbitrary TCP LISTEN probing; probing is limited to discovered local application endpoints while preserving fail-closed SSRF/XFO/CSP boundaries.
- DNS passive capture now applies kernel BPF filtering before userspace processing, reducing unnecessary packet-processing overhead.
- Normal GET /api/catalog no longer triggers expensive active discovery; remote/discovery refresh is isolated behind guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh now has same-origin validation, singleflight, and rate limiting so repeated refreshes cannot multiply expensive work.
- Core frontend polling uses serial scheduling instead of overlapping async setInterval calls; shared request helpers now enforce AbortController timeout policy with reliable timer cleanup.
- Standalone Admin and Monitoring UIs use the same serial polling contract, preventing slow requests from creating multiple concurrent periodic cycles.
- Standalone DNS UI now has a 12-second timeout for GET/HEAD reads, while mutation requests intentionally keep their previous timeout semantics to avoid false failures after a router mutation may already have committed.
- Monitoring thermal collection now uses stale-while-revalidate/singleflight: request paths do not launch concurrent refresh/smartctl work and last-good snapshots can be served without blocking the UI.
- DNS info, resolver auxiliary discovery, and Monitoring Keenetic network metadata now use bounded TTL caches/last-good semantics, substantially reducing repeated ndmc polling.
- The DNS background collector backs off after failures instead of turning an error condition into a hot polling loop.
- Monitoring storage Statfs is split into platform-specific implementations: Linux keeps the existing semantics while non-Linux targets cross-compile safely.
- The App Center async job map now has terminal retention; old completed jobs can no longer accumulate indefinitely in Core memory.
- The Core HTTP server now has ReadHeaderTimeout, ReadTimeout, IdleTimeout, and MaxHeaderBytes; the global WriteTimeout intentionally remains disabled for long-lived SSE.
- The generic Core module proxy bounds mutation bodies to downstream contracts: DNS 64 KiB and Admin 8 KiB, rejecting oversized requests before Unix-socket forwarding.
- Failed-login tracking now has global stale pruning and a strict 1024-client cap. Active blocks are preferred during eviction; lockout policy remains 5 failures / 5 minutes / 30 seconds.
Compatibility
- ARM64 aarch64-3.10 remains the primary fully hardware-validated Beta target.
- MIPSel mipsel-3.4 now has real hardware evidence on Keenetic Giga KN-1010 for fresh installation and basic normal operation. It remains experimental until upgrade/rollback/uninstall, full Module ABI/DNS behavior, and resource footprint are validated.
- MIPS mips-3.4 remains an experimental preview without physical hardware validation; cross-build/QEMU/runtime probes do not count as hardware validation.
- routerforge-monitoring Conflicts/Replaces/Provides the legacy routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network packages and preserves compatibility APIs for migration.
- Fresh Beta bootstrap still installs RouterForge Core only; optional DNS, Monitoring, Control, and Profiling are selected through App Center.
- Stable 0.6.1 and main are unchanged by this Beta release.
Technical changes
- ARM64 Dev r287 (
621a060212) passed the Management Terminal hardware gate on a Keenetic Ultra KN-1812: the exact Admin package installed successfully, ndmc show version passed, both browser Entware PTY and Keenetic NDM PTY passed, and tab switching passed. - ARM64 Dev r280 (
90d925d2ad) passed hardware runtime smoke for Core, Admin, File API, tree metadata, and volumes. RouterForge remains the only LAN listener on :2233. - Beta FULL RELEASE builds and publishes the exact multi-arch package set: Core, DNS, Control, Monitoring, and Profiling. After the rolling Beta alias is coherent, an immutable routerforge-v0.7.1-beta.3 snapshot is created.
- Release tooling validates exact Beta package order and verifies 5 components × 3 targets = 15 IPK assets together with SHA256SUMS and target-specific/universal bootstraps.
- The consolidated Monitoring package contract is checked in CI: package metadata must declare legacy Provides/Conflicts/Replaces, the payload must not contain old split binaries/init scripts, and postinst must stop legacy services before starting the new runtime.
- A read-only hardware migration gate is provided for the real 4→1 upgrade: it checks package DB state, absence of old binaries/init scripts/processes, the primary runtime, and all five expected Unix sockets (primary plus compatibility).
- routerforge-dev remains a separate mutable ARM64-only channel using 0.7.1~dev.r. versions and is no longer documented as Beta.
- Core and module runtimes communicate through root-owned Unix sockets; Core remains the only RouterForge LAN listener on :2233.
- Management v2 mutation paths require POST, same-origin, a live root session, exact confirmation, a whitelist, and a Core-injected internal Unix-socket marker; arbitrary shell/path execution is not exposed.
- Core HTTP WriteTimeout=0 is intentional so SSE /api/events can outlive normal request read timeouts.
- DNS/Admin mutation body limits are enforced in Core before ReverseProxy while downstream runtimes keep their own validation and JSON limits.
- Standalone frontend builds import shared Core $lib helpers at Vite bundle time; Node.js is not required on the router.
- The Phase 8 runtime audit is closed on Dev r248 with hardware health evidence. Reboot persistence and destructive auth-failure injection are explicitly not claimed; MIPSel hardware evidence is currently limited to fresh install/basic operation on KN-1010.
Current component versions
Component Version RouterForge Core 0.7.1~beta.2RouterForge DNS 0.7.1~beta.2RouterForge Control 0.7.1~beta.2RouterForge Monitoring 0.7.1~beta.2Profiling 0.7.1~beta.2Installation
Fresh RouterForge Beta install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.3/routerforge-beta-bootstrap.sh | shBuild and verification
- RouterForge release:
0.7.1-beta.3 - Immutable release:
routerforge-v0.7.1-beta.3 - Commit:
666a068 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.7.1-beta.2 Pre-release
released this
2026-09-10 23:34:59 +03:00 | 50 commits to main since this releaseRouterForge 0.7.1-beta.2
🇷🇺 Русский
RouterForge 0.7.1-beta.2
Что нового
- Management/Admin получил полноценный Entware Terminal на WebSocket/PTY и переработанный файловый менеджер с Commander, Explorer, деревом каталогов, выбором томов, редактором, свойствами файлов и visual chmod.
- Новый Beta train 0.7.1 переводит системный мониторинг на единый пакет routerforge-monitoring: один read-only runtime и один UI заменяют отдельные system/thermal/storage/network пакеты, сохраняя совместимые API и Unix-socket endpoints.
- Monitoring получил собственный standalone Svelte/Vite UI с разделами System, Thermal, Storage, Network и Profiling; Core теперь выступает shell/host, а не владеет страницей мониторинга.
- RouterForge Control получил standalone UI и Management v2 backend contract для root-session protected process/service mutations. Текущий UI остаётся read-only; mutation API подготовлен и аппаратно проверен отдельно от будущих управляющих кнопок.
- Dev и Beta теперь разведены: каждый push в dev публикует rolling ARM64 Dev train, а Beta выпускается только явным FULL RELEASE на проверенном exact SHA.
- Beta 0.7.1 использует prerelease-safe opkg versions вида 0.7.1~beta.1, тогда как GitHub asset/tag сохраняют читаемую форму 0.7.1-beta.1. Это гарантирует корректный порядок Beta < будущий Stable 0.7.1.
- Получена первая физическая MIPSel-проверка на Keenetic Giga KN-1010: fresh installation и базовая штатная работа RouterForge подтверждены на реальном устройстве.
Исправления
- App Center получил корректное обновление registry после package actions, устойчивый bulk-update без ложных lifecycle errors, раздельную проверку RouterForge, Integrations и Entware, общую проверку обновлений и исправленную адаптивную панель. Статусы модулей унифицированы в ON/OFF/UPDATE.
- Generic Web UI Discovery больше не выполняет произвольные TCP LISTEN probes: probing ограничен обнаруженными локальными application endpoints и сохраняет fail-closed SSRF/XFO/CSP boundary.
- DNS passive capture получил kernel BPF filtering до userspace обработки, уменьшая ненужный packet-processing overhead.
- Обычный GET /api/catalog больше не запускает дорогой active discovery; remote/discovery refresh вынесен в отдельный guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh защищён same-origin проверкой, singleflight и rate limiting, поэтому повторные refresh не размножают дорогостоящую работу.
- Core frontend polling переведён на serial scheduling без async setInterval overlap; сетевые read/write helpers получили AbortController timeout policy и гарантированную очистку timer.
- Standalone Admin и Monitoring UI используют тот же serial polling contract; медленный запрос больше не порождает несколько параллельных периодических циклов.
- Standalone DNS UI получил 12-секундный timeout для GET/HEAD reads, при этом mutation requests намеренно не получают короткий UI timeout, чтобы не сообщать ложный failure после уже применённой router mutation.
- Monitoring thermal path переведён на stale-while-revalidate/singleflight: request path не запускает конкурентные refresh/smartctl операции, а last-good snapshot публикуется без блокировки UI.
- DNS info, resolver auxiliary discovery и Monitoring Keenetic network metadata получили bounded TTL caches/last-good semantics; повторный ndmc polling заметно сокращён.
- DNS background collector получил backoff после ошибок, чтобы failure loop не превращался в горячий polling.
- Monitoring storage Statfs вынесен в platform-specific implementation: Linux сохраняет прежнюю семантику, а non-Linux targets теперь безопасно cross-compile.
- App Center internal async job map получил terminal retention cap; древние завершённые jobs больше не накапливаются бесконечно в памяти Core.
- Core HTTP server получил ReadHeaderTimeout, ReadTimeout, IdleTimeout и MaxHeaderBytes; global WriteTimeout оставлен выключенным специально для долгоживущего SSE.
- Core generic module proxy ограничивает mutation request bodies до downstream contracts: DNS 64 KiB, Admin 8 KiB; oversize отклоняется до Unix-socket forwarding.
- Authentication failed-login tracking получил global stale pruning и строгий cap 1024 clients. Активные блокировки сохраняются приоритетно; lockout policy остаётся 5 ошибок / 5 минут / 30 секунд.
Совместимость
- ARM64 aarch64-3.10 остаётся основным и полностью аппаратно проверенным Beta target.
- MIPSel mipsel-3.4 теперь имеет реальную hardware evidence на Keenetic Giga KN-1010 для fresh installation и базовой штатной работы. Target остаётся experimental до проверки upgrade/rollback/uninstall, полного Module ABI/DNS сценария и resource footprint.
- MIPS mips-3.4 остаётся experimental preview без физической hardware validation; cross-build/QEMU/runtime-probe не считаются аппаратной проверкой.
- routerforge-monitoring Conflicts/Replaces/Provides старые routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network и сохраняет compatibility API для миграции.
- Fresh Beta bootstrap по-прежнему устанавливает только RouterForge Core; optional DNS, Monitoring, Control и Profiling выбираются через Центр приложений.
- Stable 0.6.1 и main не изменяются этим Beta release.
Технические изменения
- ARM64 Dev r280 (
90d925d2ad) прошёл аппаратный runtime smoke: Core, Admin, File API, tree metadata и volumes — PASS. RouterForge остаётся единственным LAN listener на :2233. - Beta FULL RELEASE строит и публикует exact multi-arch package set: Core, DNS, Control, Monitoring и Profiling; rolling Beta alias после публикации получает coherent indexes/checksums/bootstrap, затем создаётся immutable routerforge-v0.7.1-beta.1 snapshot.
- Release tooling валидирует exact package order для Beta и проверяет 5 компонентов × 3 target = 15 IPK assets плюс SHA256SUMS и target-specific/universal bootstraps.
- Consolidated Monitoring package contract отдельно проверяется в CI: package metadata обязана объявлять legacy Provides/Conflicts/Replaces, payload не должен содержать старые split binaries/init scripts, а postinst должен останавливать legacy services перед запуском нового runtime.
- Для реального upgrade 4→1 добавлен read-only hardware migration gate: он проверяет package DB, отсутствие старых binaries/init scripts/processes, основной runtime и пять ожидаемых Unix sockets (primary + compatibility).
- routerforge-dev остаётся отдельным mutable ARM64-only каналом с версиями 0.7.1~dev.r. и больше не считается Beta.
- Core и module runtime общаются через root-owned Unix sockets; Core остаётся единственным RouterForge LAN listener на :2233.
- Management v2 mutation path требует POST, same-origin, live root session, exact confirmation, whitelist и Core-injected internal Unix-socket marker; arbitrary shell/path execution отсутствует.
- Core HTTP WriteTimeout=0 сохранён намеренно: SSE /api/events должен жить дольше обычных request read timeouts.
- DNS/Admin module mutation body limits применяются в Core до ReverseProxy, а downstream runtime продолжает собственную validation/JSON limit policy.
- Frontend standalone builds используют общие Core $lib helpers на этапе Vite bundling; Node.js на роутере не требуется.
- Phase 8 runtime audit закрыт на Dev r248 с hardware health evidence. Reboot persistence и destructive auth failure injection сознательно не заявляются как выполненные; MIPSel hardware evidence пока ограничена fresh install/basic operation на KN-1010.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.7.1~beta.2RouterForge DNS 0.7.1~beta.2RouterForge Control 0.7.1~beta.2RouterForge Monitoring 0.7.1~beta.2Profiling 0.7.1~beta.2Установка
Свежая установка RouterForge Beta:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.2/routerforge-beta-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.7.1-beta.2 - Архивный релиз:
routerforge-v0.7.1-beta.2 - Коммит:
b793932 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
🇬🇧 English
RouterForge 0.7.1-beta.2
What's new
- Management/Admin now includes a full Entware Terminal over WebSocket/PTY and a rebuilt file manager with Commander, Explorer, folder tree, volume selection, editor, file properties, and visual chmod.
- The 0.7.1 Beta train consolidates system monitoring into routerforge-monitoring: one read-only runtime and one UI replace the separate system/thermal/storage/network packages while preserving compatible APIs and Unix-socket endpoints.
- Monitoring now has its own standalone Svelte/Vite UI for System, Thermal, Storage, Network, and Profiling; Core acts as the shell/host instead of owning the monitoring page.
- RouterForge Control now has a standalone UI and a Management v2 backend contract for root-session-protected process/service mutations. The current UI remains read-only; mutation APIs are prepared and hardware-validated separately from future control buttons.
- Dev and Beta are now separate release channels: each dev push publishes the rolling ARM64 Dev train, while Beta is published only by an explicit FULL RELEASE on a verified exact SHA.
- Beta 0.7.1 uses prerelease-safe opkg versions such as 0.7.1~beta.1 while GitHub assets/tags keep the readable 0.7.1-beta.1 form, guaranteeing Beta sorts below future Stable 0.7.1.
- The first physical MIPSel validation is now recorded on Keenetic Giga KN-1010: fresh installation and basic normal RouterForge operation were confirmed on real hardware.
Fixes
- App Center now refreshes registry state correctly after package actions, completes bulk updates without false lifecycle errors, separates RouterForge, Integrations, and Entware update checks, adds a global update check, and fixes narrow-window toolbar layout. Module states are unified as ON/OFF/UPDATE.
- Generic Web UI Discovery no longer performs arbitrary TCP LISTEN probing; probing is limited to discovered local application endpoints while preserving fail-closed SSRF/XFO/CSP boundaries.
- DNS passive capture now applies kernel BPF filtering before userspace processing, reducing unnecessary packet-processing overhead.
- Normal GET /api/catalog no longer triggers expensive active discovery; remote/discovery refresh is isolated behind guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh now has same-origin validation, singleflight, and rate limiting so repeated refreshes cannot multiply expensive work.
- Core frontend polling uses serial scheduling instead of overlapping async setInterval calls; shared request helpers now enforce AbortController timeout policy with reliable timer cleanup.
- Standalone Admin and Monitoring UIs use the same serial polling contract, preventing slow requests from creating multiple concurrent periodic cycles.
- Standalone DNS UI now has a 12-second timeout for GET/HEAD reads, while mutation requests intentionally keep their previous timeout semantics to avoid false failures after a router mutation may already have committed.
- Monitoring thermal collection now uses stale-while-revalidate/singleflight: request paths do not launch concurrent refresh/smartctl work and last-good snapshots can be served without blocking the UI.
- DNS info, resolver auxiliary discovery, and Monitoring Keenetic network metadata now use bounded TTL caches/last-good semantics, substantially reducing repeated ndmc polling.
- The DNS background collector backs off after failures instead of turning an error condition into a hot polling loop.
- Monitoring storage Statfs is split into platform-specific implementations: Linux keeps the existing semantics while non-Linux targets cross-compile safely.
- The App Center async job map now has terminal retention; old completed jobs can no longer accumulate indefinitely in Core memory.
- The Core HTTP server now has ReadHeaderTimeout, ReadTimeout, IdleTimeout, and MaxHeaderBytes; the global WriteTimeout intentionally remains disabled for long-lived SSE.
- The generic Core module proxy bounds mutation bodies to downstream contracts: DNS 64 KiB and Admin 8 KiB, rejecting oversized requests before Unix-socket forwarding.
- Failed-login tracking now has global stale pruning and a strict 1024-client cap. Active blocks are preferred during eviction; lockout policy remains 5 failures / 5 minutes / 30 seconds.
Compatibility
- ARM64 aarch64-3.10 remains the primary fully hardware-validated Beta target.
- MIPSel mipsel-3.4 now has real hardware evidence on Keenetic Giga KN-1010 for fresh installation and basic normal operation. It remains experimental until upgrade/rollback/uninstall, full Module ABI/DNS behavior, and resource footprint are validated.
- MIPS mips-3.4 remains an experimental preview without physical hardware validation; cross-build/QEMU/runtime probes do not count as hardware validation.
- routerforge-monitoring Conflicts/Replaces/Provides the legacy routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network packages and preserves compatibility APIs for migration.
- Fresh Beta bootstrap still installs RouterForge Core only; optional DNS, Monitoring, Control, and Profiling are selected through App Center.
- Stable 0.6.1 and main are unchanged by this Beta release.
Technical changes
- ARM64 Dev r280 (
90d925d2ad) passed hardware runtime smoke for Core, Admin, File API, tree metadata, and volumes. RouterForge remains the only LAN listener on :2233. - Beta FULL RELEASE builds and publishes the exact multi-arch package set: Core, DNS, Control, Monitoring, and Profiling. After the rolling Beta alias is coherent, an immutable routerforge-v0.7.1-beta.1 snapshot is created.
- Release tooling validates exact Beta package order and verifies 5 components × 3 targets = 15 IPK assets together with SHA256SUMS and target-specific/universal bootstraps.
- The consolidated Monitoring package contract is checked in CI: package metadata must declare legacy Provides/Conflicts/Replaces, the payload must not contain old split binaries/init scripts, and postinst must stop legacy services before starting the new runtime.
- A read-only hardware migration gate is provided for the real 4→1 upgrade: it checks package DB state, absence of old binaries/init scripts/processes, the primary runtime, and all five expected Unix sockets (primary plus compatibility).
- routerforge-dev remains a separate mutable ARM64-only channel using 0.7.1~dev.r. versions and is no longer documented as Beta.
- Core and module runtimes communicate through root-owned Unix sockets; Core remains the only RouterForge LAN listener on :2233.
- Management v2 mutation paths require POST, same-origin, a live root session, exact confirmation, a whitelist, and a Core-injected internal Unix-socket marker; arbitrary shell/path execution is not exposed.
- Core HTTP WriteTimeout=0 is intentional so SSE /api/events can outlive normal request read timeouts.
- DNS/Admin mutation body limits are enforced in Core before ReverseProxy while downstream runtimes keep their own validation and JSON limits.
- Standalone frontend builds import shared Core $lib helpers at Vite bundle time; Node.js is not required on the router.
- The Phase 8 runtime audit is closed on Dev r248 with hardware health evidence. Reboot persistence and destructive auth-failure injection are explicitly not claimed; MIPSel hardware evidence is currently limited to fresh install/basic operation on KN-1010.
Current component versions
Component Version RouterForge Core 0.7.1~beta.2RouterForge DNS 0.7.1~beta.2RouterForge Control 0.7.1~beta.2RouterForge Monitoring 0.7.1~beta.2Profiling 0.7.1~beta.2Installation
Fresh RouterForge Beta install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.2/routerforge-beta-bootstrap.sh | shBuild and verification
- RouterForge release:
0.7.1-beta.2 - Immutable release:
routerforge-v0.7.1-beta.2 - Commit:
b793932 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
RouterForge 0.7.1-beta.1 Pre-release
released this
2026-09-10 02:40:18 +03:00 | 79 commits to main since this releaseRouterForge 0.7.1-beta.1
🇷🇺 Русский
RouterForge 0.7.1-beta.1
Что нового
- Новый Beta train 0.7.1 переводит системный мониторинг на единый пакет routerforge-monitoring: один read-only runtime и один UI заменяют отдельные system/thermal/storage/network пакеты, сохраняя совместимые API и Unix-socket endpoints.
- Monitoring получил собственный standalone Svelte/Vite UI с разделами System, Thermal, Storage, Network и Profiling; Core теперь выступает shell/host, а не владеет страницей мониторинга.
- RouterForge Control получил standalone UI и Management v2 backend contract для root-session protected process/service mutations. Текущий UI остаётся read-only; mutation API подготовлен и аппаратно проверен отдельно от будущих управляющих кнопок.
- Dev и Beta теперь разведены: каждый push в dev публикует rolling ARM64 Dev train, а Beta выпускается только явным FULL RELEASE на проверенном exact SHA.
- Beta 0.7.1 использует prerelease-safe opkg versions вида 0.7.1~beta.1, тогда как GitHub asset/tag сохраняют читаемую форму 0.7.1-beta.1. Это гарантирует корректный порядок Beta < будущий Stable 0.7.1.
- Получена первая физическая MIPSel-проверка на Keenetic Giga KN-1010: fresh installation и базовая штатная работа RouterForge подтверждены на реальном устройстве.
Исправления
- Generic Web UI Discovery больше не выполняет произвольные TCP LISTEN probes: probing ограничен обнаруженными локальными application endpoints и сохраняет fail-closed SSRF/XFO/CSP boundary.
- DNS passive capture получил kernel BPF filtering до userspace обработки, уменьшая ненужный packet-processing overhead.
- Обычный GET /api/catalog больше не запускает дорогой active discovery; remote/discovery refresh вынесен в отдельный guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh защищён same-origin проверкой, singleflight и rate limiting, поэтому повторные refresh не размножают дорогостоящую работу.
- Core frontend polling переведён на serial scheduling без async setInterval overlap; сетевые read/write helpers получили AbortController timeout policy и гарантированную очистку timer.
- Standalone Admin и Monitoring UI используют тот же serial polling contract; медленный запрос больше не порождает несколько параллельных периодических циклов.
- Standalone DNS UI получил 12-секундный timeout для GET/HEAD reads, при этом mutation requests намеренно не получают короткий UI timeout, чтобы не сообщать ложный failure после уже применённой router mutation.
- Monitoring thermal path переведён на stale-while-revalidate/singleflight: request path не запускает конкурентные refresh/smartctl операции, а last-good snapshot публикуется без блокировки UI.
- DNS info, resolver auxiliary discovery и Monitoring Keenetic network metadata получили bounded TTL caches/last-good semantics; повторный ndmc polling заметно сокращён.
- DNS background collector получил backoff после ошибок, чтобы failure loop не превращался в горячий polling.
- Monitoring storage Statfs вынесен в platform-specific implementation: Linux сохраняет прежнюю семантику, а non-Linux targets теперь безопасно cross-compile.
- App Center internal async job map получил terminal retention cap; древние завершённые jobs больше не накапливаются бесконечно в памяти Core.
- Core HTTP server получил ReadHeaderTimeout, ReadTimeout, IdleTimeout и MaxHeaderBytes; global WriteTimeout оставлен выключенным специально для долгоживущего SSE.
- Core generic module proxy ограничивает mutation request bodies до downstream contracts: DNS 64 KiB, Admin 8 KiB; oversize отклоняется до Unix-socket forwarding.
- Authentication failed-login tracking получил global stale pruning и строгий cap 1024 clients. Активные блокировки сохраняются приоритетно; lockout policy остаётся 5 ошибок / 5 минут / 30 секунд.
Совместимость
- ARM64 aarch64-3.10 остаётся основным и полностью аппаратно проверенным Beta target.
- MIPSel mipsel-3.4 теперь имеет реальную hardware evidence на Keenetic Giga KN-1010 для fresh installation и базовой штатной работы. Target остаётся experimental до проверки upgrade/rollback/uninstall, полного Module ABI/DNS сценария и resource footprint.
- MIPS mips-3.4 остаётся experimental preview без физической hardware validation; cross-build/QEMU/runtime-probe не считаются аппаратной проверкой.
- routerforge-monitoring Conflicts/Replaces/Provides старые routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network и сохраняет compatibility API для миграции.
- Fresh Beta bootstrap по-прежнему устанавливает только RouterForge Core; optional DNS, Monitoring, Control и Profiling выбираются через Центр приложений.
- Stable 0.6.1 и main не изменяются этим Beta release.
Технические изменения
- Beta FULL RELEASE строит и публикует exact multi-arch package set: Core, DNS, Control, Monitoring и Profiling; rolling Beta alias после публикации получает coherent indexes/checksums/bootstrap, затем создаётся immutable routerforge-v0.7.1-beta.1 snapshot.
- Release tooling валидирует exact package order для Beta и проверяет 5 компонентов × 3 target = 15 IPK assets плюс SHA256SUMS и target-specific/universal bootstraps.
- Consolidated Monitoring package contract отдельно проверяется в CI: package metadata обязана объявлять legacy Provides/Conflicts/Replaces, payload не должен содержать старые split binaries/init scripts, а postinst должен останавливать legacy services перед запуском нового runtime.
- Для реального upgrade 4→1 добавлен read-only hardware migration gate: он проверяет package DB, отсутствие старых binaries/init scripts/processes, основной runtime и пять ожидаемых Unix sockets (primary + compatibility).
- routerforge-dev остаётся отдельным mutable ARM64-only каналом с версиями 0.7.1~dev.r. и больше не считается Beta.
- Core и module runtime общаются через root-owned Unix sockets; Core остаётся единственным RouterForge LAN listener на :2233.
- Management v2 mutation path требует POST, same-origin, live root session, exact confirmation, whitelist и Core-injected internal Unix-socket marker; arbitrary shell/path execution отсутствует.
- Core HTTP WriteTimeout=0 сохранён намеренно: SSE /api/events должен жить дольше обычных request read timeouts.
- DNS/Admin module mutation body limits применяются в Core до ReverseProxy, а downstream runtime продолжает собственную validation/JSON limit policy.
- Frontend standalone builds используют общие Core $lib helpers на этапе Vite bundling; Node.js на роутере не требуется.
- Phase 8 runtime audit закрыт на Dev r248 с hardware health evidence. Reboot persistence и destructive auth failure injection сознательно не заявляются как выполненные; MIPSel hardware evidence пока ограничена fresh install/basic operation на KN-1010.
Текущие версии компонентов
Компонент Версия RouterForge Core 0.7.1~beta.1RouterForge DNS 0.7.1~beta.1RouterForge Control 0.7.1~beta.1RouterForge Monitoring 0.7.1~beta.1Profiling 0.7.1~beta.1Установка
Свежая установка RouterForge Beta:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.1/routerforge-beta-bootstrap.sh | shСборка и проверка
- Версия RouterForge:
0.7.1-beta.1 - Архивный релиз:
routerforge-v0.7.1-beta.1 - Коммит:
3b000b3 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
🇬🇧 English
RouterForge 0.7.1-beta.1
What's new
- The 0.7.1 Beta train consolidates system monitoring into routerforge-monitoring: one read-only runtime and one UI replace the separate system/thermal/storage/network packages while preserving compatible APIs and Unix-socket endpoints.
- Monitoring now has its own standalone Svelte/Vite UI for System, Thermal, Storage, Network, and Profiling; Core acts as the shell/host instead of owning the monitoring page.
- RouterForge Control now has a standalone UI and a Management v2 backend contract for root-session-protected process/service mutations. The current UI remains read-only; mutation APIs are prepared and hardware-validated separately from future control buttons.
- Dev and Beta are now separate release channels: each dev push publishes the rolling ARM64 Dev train, while Beta is published only by an explicit FULL RELEASE on a verified exact SHA.
- Beta 0.7.1 uses prerelease-safe opkg versions such as 0.7.1~beta.1 while GitHub assets/tags keep the readable 0.7.1-beta.1 form, guaranteeing Beta sorts below future Stable 0.7.1.
- The first physical MIPSel validation is now recorded on Keenetic Giga KN-1010: fresh installation and basic normal RouterForge operation were confirmed on real hardware.
Fixes
- Generic Web UI Discovery no longer performs arbitrary TCP LISTEN probing; probing is limited to discovered local application endpoints while preserving fail-closed SSRF/XFO/CSP boundaries.
- DNS passive capture now applies kernel BPF filtering before userspace processing, reducing unnecessary packet-processing overhead.
- Normal GET /api/catalog no longer triggers expensive active discovery; remote/discovery refresh is isolated behind guarded POST /api/catalog/refresh.
- POST /api/catalog/refresh now has same-origin validation, singleflight, and rate limiting so repeated refreshes cannot multiply expensive work.
- Core frontend polling uses serial scheduling instead of overlapping async setInterval calls; shared request helpers now enforce AbortController timeout policy with reliable timer cleanup.
- Standalone Admin and Monitoring UIs use the same serial polling contract, preventing slow requests from creating multiple concurrent periodic cycles.
- Standalone DNS UI now has a 12-second timeout for GET/HEAD reads, while mutation requests intentionally keep their previous timeout semantics to avoid false failures after a router mutation may already have committed.
- Monitoring thermal collection now uses stale-while-revalidate/singleflight: request paths do not launch concurrent refresh/smartctl work and last-good snapshots can be served without blocking the UI.
- DNS info, resolver auxiliary discovery, and Monitoring Keenetic network metadata now use bounded TTL caches/last-good semantics, substantially reducing repeated ndmc polling.
- The DNS background collector backs off after failures instead of turning an error condition into a hot polling loop.
- Monitoring storage Statfs is split into platform-specific implementations: Linux keeps the existing semantics while non-Linux targets cross-compile safely.
- The App Center async job map now has terminal retention; old completed jobs can no longer accumulate indefinitely in Core memory.
- The Core HTTP server now has ReadHeaderTimeout, ReadTimeout, IdleTimeout, and MaxHeaderBytes; the global WriteTimeout intentionally remains disabled for long-lived SSE.
- The generic Core module proxy bounds mutation bodies to downstream contracts: DNS 64 KiB and Admin 8 KiB, rejecting oversized requests before Unix-socket forwarding.
- Failed-login tracking now has global stale pruning and a strict 1024-client cap. Active blocks are preferred during eviction; lockout policy remains 5 failures / 5 minutes / 30 seconds.
Compatibility
- ARM64 aarch64-3.10 remains the primary fully hardware-validated Beta target.
- MIPSel mipsel-3.4 now has real hardware evidence on Keenetic Giga KN-1010 for fresh installation and basic normal operation. It remains experimental until upgrade/rollback/uninstall, full Module ABI/DNS behavior, and resource footprint are validated.
- MIPS mips-3.4 remains an experimental preview without physical hardware validation; cross-build/QEMU/runtime probes do not count as hardware validation.
- routerforge-monitoring Conflicts/Replaces/Provides the legacy routerforge-system/routerforge-thermal/routerforge-storage/routerforge-network packages and preserves compatibility APIs for migration.
- Fresh Beta bootstrap still installs RouterForge Core only; optional DNS, Monitoring, Control, and Profiling are selected through App Center.
- Stable 0.6.1 and main are unchanged by this Beta release.
Technical changes
- Beta FULL RELEASE builds and publishes the exact multi-arch package set: Core, DNS, Control, Monitoring, and Profiling. After the rolling Beta alias is coherent, an immutable routerforge-v0.7.1-beta.1 snapshot is created.
- Release tooling validates exact Beta package order and verifies 5 components × 3 targets = 15 IPK assets together with SHA256SUMS and target-specific/universal bootstraps.
- The consolidated Monitoring package contract is checked in CI: package metadata must declare legacy Provides/Conflicts/Replaces, the payload must not contain old split binaries/init scripts, and postinst must stop legacy services before starting the new runtime.
- A read-only hardware migration gate is provided for the real 4→1 upgrade: it checks package DB state, absence of old binaries/init scripts/processes, the primary runtime, and all five expected Unix sockets (primary plus compatibility).
- routerforge-dev remains a separate mutable ARM64-only channel using 0.7.1~dev.r. versions and is no longer documented as Beta.
- Core and module runtimes communicate through root-owned Unix sockets; Core remains the only RouterForge LAN listener on :2233.
- Management v2 mutation paths require POST, same-origin, a live root session, exact confirmation, a whitelist, and a Core-injected internal Unix-socket marker; arbitrary shell/path execution is not exposed.
- Core HTTP WriteTimeout=0 is intentional so SSE /api/events can outlive normal request read timeouts.
- DNS/Admin mutation body limits are enforced in Core before ReverseProxy while downstream runtimes keep their own validation and JSON limits.
- Standalone frontend builds import shared Core $lib helpers at Vite bundle time; Node.js is not required on the router.
- The Phase 8 runtime audit is closed on Dev r248 with hardware health evidence. Reboot persistence and destructive auth-failure injection are explicitly not claimed; MIPSel hardware evidence is currently limited to fresh install/basic operation on KN-1010.
Current component versions
Component Version RouterForge Core 0.7.1~beta.1RouterForge DNS 0.7.1~beta.1RouterForge Control 0.7.1~beta.1RouterForge Monitoring 0.7.1~beta.1Profiling 0.7.1~beta.1Installation
Fresh RouterForge Beta install:
/opt/bin/opkg update && /opt/bin/opkg install curl && /opt/bin/curl -fsSL https://github.com/Fifth-Ace/routerforge/releases/download/routerforge-v0.7.1-beta.1/routerforge-beta-bootstrap.sh | shBuild and verification
- RouterForge release:
0.7.1-beta.1 - Immutable release:
routerforge-v0.7.1-beta.1 - Commit:
3b000b3 - Release index:
routerforge-beta-index.json - Bootstrap:
routerforge-beta-bootstrap.sh
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads