github Ati054/sb-gateway v1.6.49
SB Gateway 1.6.49

3 hours ago

SB Gateway 1.6.49

Memory And CPU

  • Linux Go heaps use GODEBUG=disablethp=1 to avoid transparent huge-page inflation. Host kernel settings, memory limits, GC targets and connection buffers are unchanged.
  • Gateway and patched Xray share one executable, with independent processes, heaps and restart supervision.
  • Health workers share immutable catalogs; reverse status reuses the existing local API connection.
  • GeoIP rules use shared, content-addressed binary assets instead of repeated inline CIDR lists.
  • Healthy watchdog cycles verify the known core PID without scanning every process. Other readiness checks are retained.

Routing And Apply

  • URLTest selects by HTTPS latency, not download speed. Speed settings, accumulated penalties, the 600-second return pause and P95 are removed.
  • Planned switches require the configured millisecond advantage and two fresh confirmations. Confirmed outages trigger bounded parallel reserve searches; shared nodes are not probed twice.
  • Apply restores an eligible saved node with only an unconfirmed failure. Probe evidence cannot cross core, pool or DNS generations; planned restarts pause probes only while a bounded live Apply guard is valid.
  • GeoIP publication is atomic, supports hot routing updates and rolls back failed candidates. Obsolete files are removed after confirmation; active, startup and rollback references remain protected.
  • Quality rows show the period median, keep the active node first and sort URLTest reserves by median. Delta, % compares fresh HTTPS samples; failures are labelled HTTPS errors, not packet loss.

DNS And Settings

  • Encrypted DNS uses bounded deadlines, validates DoH responses, reconnects failed keep-alive sessions and cancels work before restart.
  • Managed IPv4 queries to RouterOS-local TCP/UDP DNS retain client identity and follow policy DNS, internal zones and WAN exceptions. Recovery admits DNS marking before expiring affected old flows.
  • Separate service cards cover eWeLink/Sonoff, Xiaomi Home, Tuya/Smart Life, Aqara and Shelly; exchange-card dependencies follow traffic and DNS routes.
  • Routing drafts persist across navigation and global Apply. RouterOS memory-high and memory-max are independently editable with restart confirmation and readback.

Startup And Dependencies

  • RouterOS uses a one-shot storage-aware boot worker: actual root and enabled mount disks, two readiness confirmations, then mount-source checks. Boot never creates replacement folders.
  • Image updates use the storage gate before candidate start and ordinary rollback. Offline recovery keeps a broken predecessor stopped.
  • Appliance shutdown is bounded to 30 seconds after cancellation; a stuck worker or diagnostic logger cannot indefinitely prevent PID 1 from exiting.
  • Both executable roles use Go 1.27.2, updated HTTP/2 dependencies and shared-core compress 1.18.7. See Security for remaining audit limitations.

Upgrade And Limits

Use the normal ARM64 image-update workflow. Saved RouterOS REST credentials enable automatic boot-contract migration after probation; no manual script import is needed. Legacy native autostart needs one controlled restart; an already migrated installation does not restart. Runtime mutations wait for migration to finish. Fresh installs require the matching bundle, including container-startup.rsc.

Storage waiting is limited to 150 checks with two-second gaps; command execution adds time. Missing mount sources refuse startup. Structural runtime restarts still interrupt established connections. Router-local DNS interception is IPv4-only, and external cloud reachability is not guaranteed. Existing policy modes and configured memory budgets are retained.

Don't miss a new sb-gateway release

NewReleases is sending notifications on new releases.