Alexey
fca6506449
Configurable HTTP Methods for Bridge Carriers
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-10-01 23:40:08 +03:00
Alexey
844e41ea34
Races in admission + accounting + publication,+ PID fixed
2026-09-09 22:45:02 +03:00
Alexey
106b26a5b7
Decoy Fasttrack Drafts
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-09-05 21:18:48 +03:00
Alexey
9f023ff9c7
WEB Bounded Bridge Recovery added
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-09-04 19:01:56 +03:00
Alexey
718ce0847e
WEB Carrier Counters + Status
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-08-31 21:39:09 +03:00
Alexey
084834f5ec
API for WEB: bounded lifecycle and overload observability added
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-08-29 16:19:21 +03:00
Alexey
14e8d10ad3
Rustfmt
2026-08-27 00:06:37 +03:00
Alexey
f180057973
Carriers Auto-negotiation Aggressiveness
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-08-26 18:33:56 +03:00
Alexey
923c79796a
Bounded Debugging + Websocket Carriers + Carriers Negotiation
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-08-26 17:00:20 +03:00
Alexey
d2edd90479
WEB: websocket + websocket-lanes as Carrier
2026-08-26 09:16:06 +03:00
Alexey
e774bc8c9a
WEB Debug + Trace
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-08-25 12:59:41 +03:00
Alexey
90c0d65e1b
WEB Carrier: https-lanes
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-08-23 09:04:53 +03:00
Alexey
1029703c2c
WEB
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
Co-Authored-By: John Preston <17900494+john-preston@users.noreply.github.com >
2026-08-23 03:12:53 +03:00
Alexey
fb47ad149c
Rustfmt
2026-08-22 16:31:49 +03:00
Alexey
7f4b87bea4
Redesign runtime w/ include-aware config + Module Split + Listener Lifecycle + Atomic Reload
2026-08-22 16:13:25 +03:00
Alexey
189e10800a
Hardened listener reload + config persistence + SYN Limit startup safety
2026-08-22 13:45:57 +03:00
Alexey
25e76a3afb
Merge pull request #884 from vgrebenschikov/feature/synlimit-pf-support
...
Add PF synlimit backend
2026-08-12 21:17:40 +03:00
Vladimir Grebenshchikov
e2eec67a33
Add PF synlimit backend
...
Implement synlimit = "pf" for PF-based firewalls using per-listener source tracking rules in a Telemt-owned anchor.
PF evaluates max-src-conn-rate through source tracking when creating
tates for completed TCP connections. Telemt installs a rate-limited pass
rule followed by a reject fallback rule in the listener anchor:
- under-limit new connections create PF state and pass;
- over-limit new connections fall through to block return-rst;
- access resumes automatically when the source rate drops below the configured window.
Keep Linux iptables/nftables behavior unchanged.
PF maps synlimit_hitcount / synlimit_seconds to max-src-conn-rate and intentionally has
no direct equivalent for Linux-only burst/hashlimit knobs.
2026-07-20 09:43:46 +02:00
Alexey
61ec46c2db
Merge pull request #871 from xaer981/fix/client-mss-bulk
...
fix(server): client_mss_bulk — fragment only ServerHello, keep bulk MSS from start
2026-07-18 14:02:03 +03:00
Alexey
73afeccae1
Rustfmt
2026-07-13 12:20:24 +03:00
Yaroslav Petrovskikh
5e9d99bb4d
fix(server): fragment only the initial FakeTLS response
2026-07-13 11:26:48 +03:00
Alexey
96425f15c8
Bound Direct relay buffers with an adaptive global memory envelope
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-07-11 20:56:54 +03:00
Alexey
d4c4980e5a
Bound ME writer queues by resident payload bytes
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-07-11 18:43:42 +03:00
Alexey
50538d234e
CidrRateLimitKey with IpNetwork parsing and serialization added
2026-07-04 10:54:55 +03:00
Alexey
558f352a57
Synlimit V2
2026-06-28 12:53:28 +03:00
Alexey
87c82c2a63
Add bounded file logging rotation and retention #832
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-24 00:16:02 +03:00
Alexey
840713a359
Merge pull request #847 from AndreyOsipuk/feat/client-mss-relay
...
feat(server): client_mss_bulk — fragment only the handshake, restore MSS for bulk data (cuts pps)
2026-06-20 22:10:04 +03:00
Andrey Osipuk
50b67a93d6
feat(server): client_mss_bulk — raise MSS after handshake to cut pps
...
client_mss (e.g. "tspu", MSS=92) fragments the whole connection to evade
DPI on the ServerHello, but it also fragments bulk payload, multiplying
outgoing packets-per-second ~10x. On hosts whose abuse detection counts
pps (not bandwidth) this trips packet-flood limits.
Add an optional [server].client_mss_bulk: keep the low client_mss for the
handshake (ServerHello stays fragmented => DPI bypass intact), then raise
the client socket MSS to client_mss_bulk once the connection enters the
post-handshake (bulk transfer) phase, so bulk data uses normal-size
segments and pps drops back to normal. Same preset/int grammar as
client_mss. Opt-in: when unset, the handshake MSS is kept for the whole
connection (unchanged behavior).
Linux-only (setsockopt TCP_MAXSEG via raw fd, mirroring TCP_USER_TIMEOUT);
no-op on other unix. Documented in CONFIG_PARAMS.{en,ru}.
2026-06-19 11:11:01 +03:00
Alexey
37d0184a0b
Implement shared MTProto framing and ME address role separation
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-15 08:50:08 +03:00
Alexey
9a3ff726b2
Use token-bucket SYN limiter backends
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-12 01:27:03 +03:00
Alexey
942882f9de
SYN Limiter interval and hitcount in Config
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-12 00:29:23 +03:00
Alexey
1cbde70a14
Add per-listener SYN limiter for Netfilter control
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-11 23:58:48 +03:00
Alexey
db7ff8737c
Add dynamic SNI mask target mode
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-11 10:36:37 +03:00
Alexey
27a5f5a4ec
MSS Tuning with config
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-06 12:11:05 +03:00
Alexey
462215b53c
Dual-stack fixes for Upstreams by #798
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-01 19:50:26 +03:00
Alexey
2264980926
User Disabler in API by #814 + Consistent Listeners in API by #800
2026-05-31 11:17:18 +03:00
Alexey
98c985091c
Decomposing hot-path modules into focused submodules
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-05-21 18:03:55 +03:00
Alexey
70d02910b7
Fixes for SILENT-mode by #792
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-05-20 10:54:37 +03:00
Alexey
914f141715
Exclusive Mask + Startup Speed-up
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-05-19 22:17:59 +03:00
Alexey
3f9ac87daf
Bounded Rate Bursts + Cancel ME Waits
2026-05-10 13:33:54 +03:00
Alexey
f0f2bc0482
Limit&Quota Saving as File + API
2026-05-08 14:38:24 +03:00
Alexey
658a565cb3
Merge pull request #770 from konstpic/feat/user-source-deny-list
...
feat(access): add per-user source IP deny list checks
2026-05-07 11:56:54 +03:00
Alexey
4995e83236
Config Strict and Validator
2026-05-06 20:38:55 +03:00
Konstantin Pichugin
b859fb95c3
feat(access): add per-user source IP deny list checks
...
Add access.user_source_deny and enforce it in TLS and MTProto handshake paths after successful authentication to fail closed for blocked source IPs.
2026-05-06 19:11:18 +03:00
Alexey
876b74ebf7
Hot-path Cleanup and Timeout Invariants
2026-04-29 23:16:11 +03:00
Alexey
67357310f7
TLS 1.2/1.3 Correctness + Full ServerHello + Rustfmt
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-23 21:29:18 +03:00
Alexey
09310ff284
Unlimited mask_relay_max_bytes
2026-04-21 11:30:58 +03:00
Alexey
926e3aa987
Fairness Regression fixes
2026-04-21 01:11:43 +03:00
lie-must-die
7bbed133ee
Add RejectHandshake variant for TLS configuration
...
Added a new variant 'RejectHandshake' to handle TLS handshake rejection with a specific alert.
2026-04-19 12:40:10 +03:00
Alexey
d72cfd6bc4
Merge branch 'flow' into feature/configurable-proxy-confi-urls
2026-04-17 19:44:46 +03:00