SB Gateway 1.6.49
Memory And CPU
- Linux Go heaps use
GODEBUG=disablethp=1to avoid transparent huge-page inflation. Host kernel settings, memory limits, GC targets and connection buffers are unchanged. - Gateway and patched Xray share one executable, with independent processes, heaps and restart supervision.
- Health workers share immutable catalogs; reverse status reuses the existing local API connection.
- GeoIP rules use shared, content-addressed binary assets instead of repeated inline CIDR lists.
- Healthy watchdog cycles verify the known core PID without scanning every process. Other readiness checks are retained.
Routing And Apply
- URLTest selects by HTTPS latency, not download speed. Speed settings, accumulated penalties, the 600-second return pause and P95 are removed.
- Planned switches require the configured millisecond advantage and two fresh confirmations. Confirmed outages trigger bounded parallel reserve searches; shared nodes are not probed twice.
- Apply restores an eligible saved node with only an unconfirmed failure. Probe evidence cannot cross core, pool or DNS generations; planned restarts pause probes only while a bounded live Apply guard is valid.
- GeoIP publication is atomic, supports hot routing updates and rolls back failed candidates. Obsolete files are removed after confirmation; active, startup and rollback references remain protected.
- Quality rows show the period median, keep the active node first and sort URLTest reserves by median.
Delta, %compares fresh HTTPS samples; failures are labelled HTTPS errors, not packet loss.
DNS And Settings
- Encrypted DNS uses bounded deadlines, validates DoH responses, reconnects failed keep-alive sessions and cancels work before restart.
- Managed IPv4 queries to RouterOS-local TCP/UDP DNS retain client identity and follow policy DNS, internal zones and WAN exceptions. Recovery admits DNS marking before expiring affected old flows.
- Separate service cards cover eWeLink/Sonoff, Xiaomi Home, Tuya/Smart Life, Aqara and Shelly; exchange-card dependencies follow traffic and DNS routes.
- Routing drafts persist across navigation and global Apply. RouterOS
memory-highandmemory-maxare independently editable with restart confirmation and readback.
Startup And Dependencies
- RouterOS uses a one-shot storage-aware boot worker: actual root and enabled mount disks, two readiness confirmations, then mount-source checks. Boot never creates replacement folders.
- Image updates use the storage gate before candidate start and ordinary rollback. Offline recovery keeps a broken predecessor stopped.
- Appliance shutdown is bounded to 30 seconds after cancellation; a stuck worker or diagnostic logger cannot indefinitely prevent PID 1 from exiting.
- Both executable roles use Go 1.27.2, updated HTTP/2 dependencies and shared-core compress 1.18.7. See Security for remaining audit limitations.
Upgrade And Limits
Use the normal ARM64 image-update workflow. Saved RouterOS REST credentials enable automatic boot-contract migration after probation; no manual script import is needed. Legacy native autostart needs one controlled restart; an already migrated installation does not restart. Runtime mutations wait for migration to finish. Fresh installs require the matching bundle, including container-startup.rsc.
Storage waiting is limited to 150 checks with two-second gaps; command execution adds time. Missing mount sources refuse startup. Structural runtime restarts still interrupt established connections. Router-local DNS interception is IPv4-only, and external cloud reachability is not guaranteed. Existing policy modes and configured memory budgets are retained.