Change Guard covers every management-affecting write (v0.24.44)
Outside review P2-8, P2-7 and S10.
Firewall
- The input chain is evaluated in order, first match wins, for the
manager's real connection (new TCP from its address to the API port on
the management interface). Address lists, interface lists and jumps are
followed; unmodelled matchers are "maybe" and make the answer "can't
tell" (auto-revert required). Replaces the rule-shape check, which
ignored order and flagged RouterOS defconf permanently. - Firewall add/edit/toggle/move/delete and address-list writes run under
Change Guard with a simulated change. The firewall tab's toggle, move
and delete now show the lockout dialog.
Unguarded twins and the rest
- Port disable (simulated), MTU/FEC/flow/speed/PoE (flagged on the
management path), copy-VLANs (simulated as a batch), bond edit. - Bond create/delete carry bridge VLAN membership across.
- NAT, OSPF, BGP, routing tables and filters, WireGuard, hotspot setup and
servers, wireless interface and security-profile edits/deletes run under
Change Guard. Disabling or deleting the WireGuard or wireless interface
the manager uses is predicted. - withGuardedChange moved to services/changeGuard/guardedRoute.ts.
One write at a time per device
- Device write routes take the Change Guard lock for the request (409
device_busy for a second writer), so a revert can't undo another write.
A guarded change inside the request recognises the lock as its own.
Fail closed (P2-7)
- A failed state read fails the analysis (auto-revert required) instead of
producing an empty model and "safe". Connection tracking stays optional.
Races (S10)
- Last-site delete under an advisory lock; certificate upload/regenerate
serialised; command runs and rollouts claimed atomically; credential
preset updates write only sent fields; template conversion copies and
marks in one transaction.
Tested on the TEST switch: firewall predictions and guarded writes, port
disable (ether1 refused), bond create/edit/delete keeping VLAN membership,
NAT, routing table, WireGuard, and the busy lock. State compared equal
before and after.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.44-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.44-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/