github Kobii-git/rackpad v1.8.3-beta.1
Rackpad v1.8.3-beta.1

pre-release3 hours ago

Rackpad v1.8.3-beta.1 combined candidate

This candidate includes the maintenance, stabilization, stacked-switch, routing,
patch-panel, Storage and SNMPv3 changes documented in the retained
beta.0 notes. Stable 1.8.3 requires community acceptance,
seven consecutive days of soak, and final release checks. Docker remains the
supported general deployment; native Proxmox LXC remains experimental.

Repairs since beta.0

  • CodeQL security severity must be a decimal string from 0 through 10. Arrays,
    booleans, null, empty strings, numbers and out-of-range values fail validation
    before suppression or exception handling. Security-tagged rules require a
    score; ordinary unscored quality rules remain supported.
  • Nodemailer moves from 9.0.3 to 9.1.1, the compatible 9.x repair for the
    address-parser denial of service
    and legacy content-resolution guard bypass.
    SMTP settings and credential storage are unchanged.

The beta.0 tag remains at fb7fbcec511e2b95060055103a669cdbc894be3a, the merge
of PR #154. Its publication was canceled before build or release steps after
independent review confirmed the severity-validation defect. No beta.0 GitHub
release or versioned GHCR image was published. The tag must never be moved.

Reviewed CodeQL exceptions

Only js/insufficient-password-hash at server/lib/snmp-v3.ts lines 83 and 90
is eligible, with one primary location confined to its identified line. Owner:
@Kobii-git. Acceptance expires at 2026-11-30 00:00:00 UTC; the exact
boundary rejects the exception.

  • File SHA-256: 4029cff16fe59c2120322cf3340bc543564bd44f12835b57f20f27c2e35b3e63
  • Git server tree: 29b7962b93a62fa05da1e4147afef36a68166827

RFC 3414 requires MD5/SHA password
expansion and localization for interoperable SNMPv3 USM wire keys. These operations
are not application login password storage. Existing credential encryption and
configured MD5/SHA/AES128 interoperability remain intact.

The shared policy requires unchanged tracked server content, no additional server
files, valid Git/source evidence and an unambiguous analyzed source identity.
Native reports without an absolute source-root mapping require embedded complete
source matching the approved hash. Missing evidence disables acceptance. Dates
and hashes are never renewed automatically.

Raw SARIF is schema-validated and retained unchanged alongside an explicit review
summary. Only accepted results are omitted from a separate upload report; all
other findings, fingerprints, severities and analysis identities remain intact.
Failed processing uploads raw analysis and blocks publication. Upload failure
also blocks publication. No new broad suppression or alert dismissal is used.

Upgrade and recovery

Schema remains 51. Published migrations 49 and 50 and stack migration
51 are unchanged; security conversion remains at the schema-50 boundary.
No new public API, environment variable or credential format is introduced.

Before upgrade, retain the previous application plus its pre-upgrade database,
configuration and original encryption key. Preserve RACKPAD_SECRET_KEY exactly.
See the security upgrade guidance for trusted proxy
settings, OIDC role recovery and trap-source reconfiguration. Missing-key legacy
conversion fails atomically; traps remain opt-in.

Rollback restores that entire previous application/database/configuration/key
pair. Older binaries must never open schema-51 data. A current logical backup
cannot replace the pre-upgrade snapshot for downgrade. Test recovery only with
disposable data and reject invalid ownership or newer-schema backups atomically.

Exact-candidate acceptance

Use the full guest and feature checklist
against beta.1's immutable commit and published digests, not beta.0 or a
floating branch/tag. Record version, source commit, both architecture digests,
source-asset hashes, platform/browser versions, UTC timestamps and results.

Issue Required community evidence
#152 Cisco IOS-XE SHA/AES in the reporter's Docker-network scenario: credential testing, monitoring, IF-MIB discovery, idle/engine-time recovery and rejection of wrong credentials.
#153 Firefox over ordinary LAN HTTP with fresh/upgraded Storage data: navigation, section creation/editing, saving and reload; record UUID availability and console errors.
#138 Disposable Debian 13 and Ubuntu 24.04 on PVE 9: install, schema 45/48/49/50 upgrades, reboot, custom ports, discovery modes, exact keys, recovery, injected failures and paired rollback.
#139 Rear/mixed-face continuations, selection, tracing, waypoints and exports. Brush-panel redesign remains outside this fix.
#148 Independent front/rear edits on a custom 24-column descendant: 48 bindings, zero unmapped ports, 24 pass-through pairs, tracing and persistence.
#146 Member metadata/order/MACs, nullable assignments, inherited types, derived height, unmount/undo/redo, loose-room moves, earlier history, genuine conflicts and preserved identities.

Include normal email alert delivery in beta.1 acceptance because Nodemailer is a
runtime dependency change. Automated Net-SNMP and browser checks do not substitute
for community Cisco, Firefox LAN HTTP or Proxmox guest evidence.

After all acceptance criteria pass, record seven consecutive days of soak.
Runtime, security, schema, dependency or OS-package changes require affected
acceptance to repeat and soak to restart. Documentation/version-label changes
alone do not. No community acceptance or soak is claimed by earlier CI results.
All six issues stay open, including after publication. External Community Scripts
listing remains separate from Rackpad's readiness for main.

Validation and publication

Beta.0's final PR commit passed hosted application/browser, Firefox Storage,
Net-SNMP, screenshot determinism, shell/workflow and CodeQL checks. Those results
are historical evidence; beta.1 requires the full hosted pipeline again.

Local beta.1 validation passed npm run check: 344 server tests, 92 client tests,
51 configuration/publication/installer tests, 30 Proxmox fixture scenarios,
documentation checks, lint/types, build and bundle limits. All 17 focused
publication tests and actionlint passed. Independent review verified strict score
strings, every driver/extension descriptor, and mandatory severity for the known
SNMP rule even if its tags are missing; no actionable defect remained.
Replaying both retained native hosted reports still accepted exactly lines 83/90
with raw bytes and all retained metadata unchanged. A refreshed dependency audit
reported zero vulnerabilities after the sole installed-package change to
Nodemailer 9.1.1. Synthetic message/envelope validation passed without sending mail.

Publication additionally requires refreshed scans and smoke tests of the actual
published amd64 and arm64 digests, including authentication/denial, SPA/assets/fonts,
logical/native restore and repeated schema-51 startup with disposable data.
Fixable high/critical vulnerabilities and secret/configuration findings block;
unfixed upstream OS advisories are documented without new broad suppressions.

Integrate via the normal protected beta PR workflow and publish an immutable tag.
Stable/main remains gated on acceptance, soak, final checks and resolved review
conversations. Main publishes latest; no branch protection may be bypassed.

Don't miss a new rackpad release

NewReleases is sending notifications on new releases.