github 2GT-Media-Group-LLC/mikrotik-manager v0.24.44-beta

latest release: v0.24.45-beta
pre-release2 hours ago

Change Guard covers every management-affecting write (v0.24.44)

Outside review P2-8, P2-7 and S10.

Firewall

  • The input chain is evaluated in order, first match wins, for the
    manager's real connection (new TCP from its address to the API port on
    the management interface). Address lists, interface lists and jumps are
    followed; unmodelled matchers are "maybe" and make the answer "can't
    tell" (auto-revert required). Replaces the rule-shape check, which
    ignored order and flagged RouterOS defconf permanently.
  • Firewall add/edit/toggle/move/delete and address-list writes run under
    Change Guard with a simulated change. The firewall tab's toggle, move
    and delete now show the lockout dialog.

Unguarded twins and the rest

  • Port disable (simulated), MTU/FEC/flow/speed/PoE (flagged on the
    management path), copy-VLANs (simulated as a batch), bond edit.
  • Bond create/delete carry bridge VLAN membership across.
  • NAT, OSPF, BGP, routing tables and filters, WireGuard, hotspot setup and
    servers, wireless interface and security-profile edits/deletes run under
    Change Guard. Disabling or deleting the WireGuard or wireless interface
    the manager uses is predicted.
  • withGuardedChange moved to services/changeGuard/guardedRoute.ts.

One write at a time per device

  • Device write routes take the Change Guard lock for the request (409
    device_busy for a second writer), so a revert can't undo another write.
    A guarded change inside the request recognises the lock as its own.

Fail closed (P2-7)

  • A failed state read fails the analysis (auto-revert required) instead of
    producing an empty model and "safe". Connection tracking stays optional.

Races (S10)

  • Last-site delete under an advisory lock; certificate upload/regenerate
    serialised; command runs and rollouts claimed atomically; credential
    preset updates write only sent fields; template conversion copies and
    marks in one transaction.

Tested on the TEST switch: firewall predictions and guarded writes, port
disable (ether1 refused), bond create/edit/delete keeping VLAN membership,
NAT, routing table, WireGuard, and the busy lock. State compared equal
before and after.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com


Container images (published once CI passes):

  • ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.44-beta
  • ghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.44-beta

Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/

Don't miss a new mikrotik-manager release

NewReleases is sending notifications on new releases.