Alexey
73afeccae1
Rustfmt
2026-07-13 12:20:24 +03:00
Alexey
ea296bbdc8
Replace per-session pool trimming with pressure hysteresis
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-07-11 21:36:01 +03:00
Alexey
96425f15c8
Bound Direct relay buffers with an adaptive global memory envelope
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-07-11 20:56:54 +03:00
Alexey
d4c4980e5a
Bound ME writer queues by resident payload bytes
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-07-11 18:43:42 +03:00
Alexey
87c82c2a63
Add bounded file logging rotation and retention #832
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-24 00:16:02 +03:00
Alexey
e994ddea00
Accept advertised logging flags in CLI by #848
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-23 23:20:12 +03:00
Alexey
d414c73c9b
Hardened KDF-Tuple + NAT Probing + Paddings
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-14 16:15:41 +03:00
Alexey
2675779915
Fix SYN limiter lifecycle and default burst
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-12 14:40:26 +03:00
Alexey
1cbde70a14
Add per-listener SYN limiter for Netfilter control
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-11 23:58:48 +03:00
Alexey
27a5f5a4ec
MSS Tuning with config
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-06 12:11:05 +03:00
Alexey
462215b53c
Dual-stack fixes for Upstreams by #798
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-06-01 19:50:26 +03:00
Alexey
2264980926
User Disabler in API by #814 + Consistent Listeners in API by #800
2026-05-31 11:17:18 +03:00
Aleksei K
a77aedfd7a
Atomically claim pressure eviction budget in MR
2026-05-29 13:17:47 +03:00
Alexey
31da0a1356
Fixes for Disable Colors
2026-05-26 12:20:28 +03:00
Alexey
98c985091c
Decomposing hot-path modules into focused submodules
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-05-21 18:03:55 +03:00
Alexey
70d02910b7
Fixes for SILENT-mode by #792
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-05-20 10:54:37 +03:00
Alexey
914f141715
Exclusive Mask + Startup Speed-up
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-05-19 22:17:59 +03:00
Alexey
57b2aa0453
Rustfmt
2026-05-10 14:14:52 +03:00
Alexey
eef2a38c75
Type Route Cutovers + Reduce IP Tracker cleanup pressure
2026-05-10 13:55:01 +03:00
Alexey
6cb72b3b6c
Explicit Reasons of Session Fallback Cleanup + ME Close
2026-05-10 13:50:36 +03:00
Alexey
090b2ca636
Stats and Cleanup-proccess beyond Hot-path
2026-05-10 13:43:41 +03:00
Alexey
f0f2bc0482
Limit&Quota Saving as File + API
2026-05-08 14:38:24 +03:00
Alexey
86573be493
Event-driven Wakeup for ME Admission-gate
2026-05-08 13:34:41 +03:00
astronaut808
9f9ca9f270
Add TLS front profile health metrics
2026-05-03 18:07:24 +05:00
Alexey
8520955a5f
Update helpers.rs
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-04-29 15:53:27 +03:00
Alexey
065786b839
TLS Fetcher on multiple tls_domains by #750
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-04-29 11:47:42 +03:00
Alexey
8ef5263fce
Fix WorkingDirectory behavior
...
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
Co-Authored-By: mikhailnov <m@mikhailnov.ru >
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com >
2026-04-28 12:31:21 +03:00
Alexey
67357310f7
TLS 1.2/1.3 Correctness + Full ServerHello + Rustfmt
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-23 21:29:18 +03:00
Alexey
8684378030
Human-readable Peer Close Classification
2026-04-21 15:46:18 +03:00
Alexey
db8d333ed6
Noisy-network peer Close Errors Classification
2026-04-21 15:35:11 +03:00
Alexey
926e3aa987
Fairness Regression fixes
2026-04-21 01:11:43 +03:00
Dmitry Zarva
2a168b2600
feat: make URLS to obtain proxy_secret, getProxyConfig, getProxyConfigV6 files optionally configurable
2026-04-17 13:04:46 +00:00
Alexey
17a966b822
Rustfmt
2026-04-17 10:48:01 +03:00
Alexey
21ca1014ae
Drafting Traffic Control
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-15 13:14:45 +03:00
Alexey
696316f919
Rustfmt
2026-04-15 01:39:47 +03:00
Alexey
d7a0319696
Server.Listeners + Upstream V4/V6
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-15 01:32:49 +03:00
Vladislav Yaroslavlev
abff2fd7fe
fix(maestro): restore Windows build (missing run_inner)
...
The full runtime entry was gated with #[cfg(unix)] while run() still called
run_inner() on non-Unix targets, causing E0425 on Windows (issue #690 ).
Extract shared pipeline into run_telemt_core with a post-bind hook for Unix
privilege dropping; provide cfg-split run_inner wrappers.
Fixes https://github.com/telemt/telemt/issues/690
Made-with: Cursor
2026-04-13 00:21:19 +03:00
sintanial
ddeda8d914
feat: add configurable RST-on-close mode for client sockets
...
Add `rst_on_close` config option (off/errors/always) to control
SO_LINGER(0) behaviour on accepted TCP connections.
- `off` (default): normal FIN on all closes, no behaviour change.
- `errors`: SO_LINGER(0) set on accept, cleared after successful
handshake auth. Pre-handshake failures (scanners, DPI probes,
timeouts) send RST instead of FIN, eliminating FIN-WAIT-1 and
orphan socket accumulation. Authenticated relay sessions still
close gracefully with FIN.
- `always`: SO_LINGER(0) on accept, never cleared — all closes
send RST regardless of handshake outcome.
2026-04-10 05:01:38 +03:00
Alexey
3b717c75da
Memory Hard-bounds + Handshake Budget in Metrics + No mutable in hotpath ConnRegistry
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-07 18:18:47 +03:00
Alexey
fa4e2000a8
Privileges fix
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-06 11:10:41 +03:00
Alexey
5f5582865e
Rustfmt
2026-04-05 17:23:40 +03:00
Alexey
977ee53b72
Config Fallback + Working Directory Setup
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-05 14:40:17 +03:00
Alexey
7f0057acd7
Conntrack Control Method
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-04-04 11:28:32 +03:00
David Osipov
6ea867ce36
Phase 2 implemented with additional guards
2026-04-03 02:08:59 +04:00
Alexey
b8cf596e7d
Admission-timeouts + Global Each TCP Connections
...
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com >
2026-03-31 11:14:55 +03:00
Roman Martynov
618bc7e0b6
Merge branch 'flow' into fix/apply-tg-connect-timeout-upstream
2026-03-28 14:27:47 +03:00
sintanial
d06ac222d6
fix: move tg_connect to general, rustfmt upstream, fix UpstreamManager::new tests
...
- Relocate tg_connect from [timeouts] to [general] with validation and docs updates.
- Apply rustfmt to per-attempt upstream connect timeout expression in upstream.rs.
- Pass tg_connect_timeout_secs in all UpstreamManager::new test call sites.
- Wire hot reload and runtime snapshot to general.tg_connect.
2026-03-28 14:25:18 +03:00
Alexey
567453e0f8
Merge pull request #596 from xaosproxy/fix/listen_backlog
...
feat(server): configurable TCP listen_backlog
2026-03-28 12:28:19 +03:00
sintanial
96ae01078c
feat(server): configurable TCP listen_backlog
...
Add [server].listen_backlog (default 1024) for client-facing listen(2)
queue size; use the same value for metrics HTTP listeners. Hot reload
logs restart-required when this field changes.
2026-03-27 12:49:53 +03:00
sintanial
3b9919fa4d
Apply [timeouts] tg_connect to upstream DC TCP connect attempts
...
Wire config.timeouts.tg_connect into UpstreamManager; per-attempt timeout uses
the same .max(1) pattern as connect_budget_ms.
Reject timeouts.tg_connect = 0 at config load (consistent with
general.upstream_connect_budget_ms and related checks). Default when the key
is omitted remains default_connect_timeout() via serde.
Fixes telemt/telemt#439
2026-03-27 12:45:19 +03:00