Conversation
- reject uploads of run files and pids <= 1 (kill as root) - graceful HTTP shutdown; no write deadline for file transfers - deb: keep service state on upgrade, add postrm, recommend bngblaster - golangci-lint v2 + CI lint job, testify bump, swagger _overview Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- reject cross-origin state-changing requests (Sec-Fetch-Site/Origin) - add -allowed-hosts Host header allowlist against DNS rebinding - security headers and CSP on every response - bound request bodies, reject uploads larger than free disk space - restrict stream_config to files inside the instance folder - audit log client address for requests and lifecycle changes - systemd unit sandboxing; document in README, swagger and CLAUDE.md Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- interface stats: loss count plus ratio (0.001%), red when > 0 - progress bars: 3 decimals rounded down, so 9999/10000 no longer shows 100%
- serve instance files with Cache-Control: no-cache and fetch config.json with no-store, so the editor no longer reopens the previous version - interface stats: loss count plus ratio (0.001%), red when > 0 - progress bars: 3 decimals rounded down, so 9999/10000 no longer shows 100% Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- stream_config: absolute paths are used as-is again, so stream files kept in home directories work; relative paths must still stay inside the instance folder - systemd: keep home directories readable (ProtectHome=read-only) for stream, BGP and MRT files - uploads and downloads remain confined to the instance folder - update README, swagger and web UI hint Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deduplicate the stream and session pagination handlers into a generic summary endpoint (summary.go), split Start's startup wait and the overview fetch into their own functions, and fix the remaining style findings: FlowID/SessionID naming, min/max and any, test file permissions, request contexts and unused parameters. Allow generic returns in ireturn, as the summary cache necessarily returns its type parameter. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Build golangci-lint v2.14.0 from source in CI, as its prebuilt binaries are built with go 1.26 and refuse to load a module targeting go 1.27. Bump checkout and setup-go to v7, golangci-lint-action to v9 and goreleaser-action to v7. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Run a goreleaser snapshot after build and test and upload the .deb, tarball and checksums as the bngblasterctrl-dev workflow artifact. Snapshot versions are now <next patch>~dev.<commit time>.<commit>, which dpkg sorts below the upcoming release so it upgrades over a dev build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dpkg runs the old package's prerm on upgrade, and the one shipped up to 0.1.3 unconditionally stopped and disabled the service, so try-restart left it stopped and disabled. Those versions always enabled the service on install, so restore that when upgrading from them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR merges
devintomain. It adds an embedded web UI, a set of new read-only REST endpoints that the UI uses, protections for the unauthenticated API, and reworked Debian packaging./. Disable it with-ui=false.-uploadflag now defaults totrue. Disable it with-upload=false.GET /api/v1/interfacescan be disabled with-interfaces-api=false.bngblasterpath changed from/usr/sbin/bngblasterto/usr/bin/bngblaster. Override it with-e.stream_configpaths must stay inside the instance folder. Absolute paths, for example files in home directories, are still used as-is.Sec-Fetch-Site/Origin.Note: The web UI, file upload and the interfaces endpoint are on by default only for the beta. These defaults may change before the final release, so pass the flags explicitly (
-ui,-upload,-interfaces-api) if your setup depends on them.✨ Features
Embedded web UI
go:embed. It has no build step and no framework.New API endpoints
/api/v1/schema-schema)/api/v1/interfaces-interfaces-api)/api/v1/instances/{name}/_overview/api/v1/instances/{name}/_streams/api/v1/instances/{name}/_sessions/api/v1/instances/{name}/_logs/api/v1/instances/{name}/_files/api/v1/instances/{name}/_files/{file_name}/docs/docs/swagger.yamlis extended to cover all new endpoints.New flags
-ui(defaulttrue)-interfaces-api(defaulttrue)-schema(default/usr/share/bngblaster/bngblaster-config.json)-allowed-hosts: comma-separated Host header allowlist against DNS rebinding. IP addresses andlocalhostare always allowed. An empty value allows any host.🔒 Security hardening
-allowed-hostsHost header allowlist.run.pid,run.sock, …) are rejected, as are pids <= 1. This prevents killing arbitrary processes as root.ProtectSystem=full,ProtectHome=read-only,PrivateTmp, kernel/cgroup/clock/hostname protection,RestrictSUIDSGID,LockPersonality.🐛 Fixes
Cache-Control: no-cache, andconfig.jsonis fetched withno-store. The config editor no longer reopens a stale version.📦 Packaging (deb / systemd)
/etc/default/rtbrick-bngblasterctrlwithBNGBLASTERCTRL_OPTSto pass flags to the service.postrmscript is added. The package recommendsbngblaster.prermstopped and disabled it.🛠 Build / CI / maintenance
bngblasterctrl-devartifact. The version scheme is<next patch>~dev.<time>.<commit>, so the next release upgrades over it.summary.go), and lint findings are fixed.CLAUDE.mdadded. README updated for the new flags, defaults and hardening.🤖 Generated with Claude Code