Files
nx9-wg/CHANGELOG.md
T
2026-08-18 17:32:56 +05:30

3.9 KiB

Changelog

All notable changes to NX9-WG (nx9-wg) are documented here.

[1.0.0] — 2026-08-18

NX9-WG 1.0.0 is the first production release of the native Linux WireGuard + network control plane.

Added

  • Native Linux WireGuard lifecycle management through WireGuard Generic Netlink and RTNETLINK.
  • Native IPv4/IPv6 address and route management without wg, wg-quick, ip, iptables, nft, sysctl, or shell orchestration from production Rust.
  • Native nftables firewall/NAT execution scoped to the managed table inet nx9_wg table.
  • SQLite authoritative desired-state storage with reconciliation and drift correction.
  • Live WireGuard telemetry including learned peer endpoints, handshake timestamps, and RX/TX counters.
  • Correct separation of client-side AllowedIPs from server-side WireGuard Cryptokey Routing AllowedIPs.
  • Road-warrior server peer routing derived from assigned tunnel addresses (/32 and /128) unless an explicit server-side override is configured.
  • Persistent WireGuard server endpoint configuration for client configuration and QR exports.
  • Interface editing through the WebUI with cryptographic identity preservation.
  • WebUI peer lifecycle states: Connected, Awaiting Handshake, Disconnected, Disabled, Expired, and Revoked.
  • Pure Rust client configuration and QR generation.
  • CLI, REST API, WebSocket, embedded SPA, diagnostics, backup/restore, and reconciliation tooling.

Changed

  • Peer API responses now merge fresh kernel telemetry instead of relying solely on cached SQLite values.
  • Handshake timestamps are serialized as explicit UTC/RFC3339 values and parsed defensively by the WebUI.
  • Interface edits preserve interface UUID, private key, public key, and peer associations.
  • Server endpoint resolution prefers explicit export overrides, then persistent server endpoint settings, with controlled fallback behavior.
  • Reconciliation detects and repairs server-side peer AllowedIPs drift.
  • Release documentation and testing documentation are promoted to the v1.0.0 baseline.

Fixed

  • Fixed road-warrior peers incorrectly receiving client full-tunnel AllowedIPs (0.0.0.0/0, ::/0) in the server kernel Cryptokey Routing table.
  • Fixed server-to-peer routing failure caused by missing /32 peer routes in WireGuard peer configuration.
  • Fixed WebUI active peers appearing Disconnected because backend NaiveDateTime values lacked an explicit UTC offset.
  • Fixed stale peer telemetry in REST/WebUI responses.
  • Fixed missing WebUI interface Edit action.
  • Fixed missing persistent server endpoint for QR/config export.
  • Fixed reconciliation convergence after deliberate interface-address drift.

Networking & Firewall

  • IPv4 forwarding is managed through the native Linux networking engine.
  • Outbound masquerading is scoped to the WireGuard client subnet and non-WireGuard egress interfaces.
  • Firewall/NAT state is reconciled atomically within the dedicated NX9 nftables table.
  • Server-side peer routes and cryptokey routing are kept distinct from client routing policy.

Validation

  • Workspace test suite: 162 tests passing at the documented release baseline.
  • Comprehensive CLI suite: 203 passed / 7 skipped.
  • Native integration suite: 19 passed / 1 skipped.
  • Dedicated live-kernel suite: 23 passed / 1 skipped in SAFE mode baseline.
  • Real Android/mobile WireGuard client: operator-verified for VPN connectivity and full-tunnel Internet operation during v1.0.0 acceptance.
  • WebUI interface editing: operator-verified.
  • Live peer telemetry/status: operator-verified with connected mobile client.
  • Final reconciliation: operator-verified with zero drift after convergence.
  • External cellular/WAN road-warrior acceptance and post-reboot physical-client acceptance remain separate operational gates unless explicitly recorded in the release evidence.

[0.8.0]

Previous development release. See repository history for detailed implementation changes.