XC_VM — Release Notes
Overview
This release focuses on cluster reliability, load-balancer lifecycle management, VOD import architecture, module isolation, installation security, and automated testing. It also improves compatibility checks for modules and addresses multiple streaming, connection-tracking, and administration issues.
✨ New Features
Module System and Core Compatibility
- Introduced enforcement of the
requires_coredeclaration when loading, installing, and updating modules. - Added documentation explaining module core-version requirements and their impact on compatibility.
- Extended the module system to allow modules to register Admin API actions.
- Moved Watch-folder functionality out of the core application and into its dedicated module.
- Removed the Plex module from core, continuing the separation of optional integrations from the main application.
VOD Import and DVR Management
- Moved per-file VOD importing into the core application through a dedicated
VodItemImporter. - Added bounded batch processing for Movies and Series imports to improve resource control during large import operations.
- Added core-managed TMDb genre mapping.
- Improved decoding and processing of
vod_import_itempayloads. - Moved DVR recording management into core and improved handling of recording-related stream data.
- Added documentation for the VOD import worker and its data model.
🚀 Improvements
Cluster and Load Balancer Management
- Improved load-balancer installation and update workflows so nodes install and update the same release as MAIN.
- Ensured MAIN keeps the installers it distributes to load balancers up to date.
- Improved node update state tracking, including rollback behavior and release synchronization.
- Fixed cluster API status handling to prevent nodes from incorrectly returning
STARTINGindefinitely or at recurring intervals. - Improved installation preflight checks and stopped installations when required components such as
xcvm_coreare missing. - Added the ability to forget a saved SSH host key when a node has been rebuilt.
- Improved load-balancer diagnostics and file-transfer verification using SHA-256 checks.
- Ensured transferred scripts and files are handled through safer installation workflows.
Installation and System Configuration
- Improved RAM disk and
sysctlconfiguration checks during installation. - Added clearer diagnostics when
sysctl -prejects configuration entries. - Fixed RAM disk mount configuration when
/etc/fstabdoes not end with a newline. - Added checks for requested RAM disk mounts and
sysctl.confsettings instead of assuming they were applied. - Moved root-executed installation operations and archive extraction into private directories.
- Improved server address and port conflict validation during server creation.
- Updated installation safeguards to detect missing prerequisites before starting a load-balancer installation.
Testing and Development Workflow
- Standardized the unit-test environment around MariaDB and the panel's own application stack.
- Rewrote the unit-testing guide to document the MariaDB-based workflow.
- Updated the release checklist.
- Configured static analysis to run on PHP 8.1, the minimum supported PHP version.
- Updated PHPStan dependencies.
- Reduced test output to PHPUnit's own output, making failures and results easier to review.
- Improved end-to-end test synchronization for HLS viewer termination and load-balancer routing.
🛠️ Bug Fixes
Streaming and Connection Tracking
- Fixed connection accounting when a player reconnects through a different node.
- Improved handling of ended connection records so cleanup does not wait unnecessarily for locks.
- Fixed HLS viewers on load balancers whose agents manage viewer state.
- Fixed behavior when a killed HLS viewer on another server continues requesting segments.
- Improved RTMP admission checks so a load balancer refuses viewers it cannot reliably validate.
- Fixed on-demand stream termination to ensure only the stream's own monitor and producer are stopped.
- Fixed the administrative preview for natively remuxed streams.
- Fixed recording scheduling so server-owned database columns are not modified by the recording workflow.
- Improved viewer API behavior on load balancers and corrected debug-mode status reporting.
Security and Process Execution
- Fixed cluster reservation handling so HMAC identities remain intact.
- Improved protection against truncated migration dump copies.
- Restricted migration backup restoration to the dedicated
xc_vm_migratedatabase. - Addressed Semgrep findings in import and recording code.
- Removed shell-based execution from status commands and file-permission operations.
- Improved safety around installation file transfers and root-executed operations.
- Added SHA-256 verification for transferred files and clearer errors when MAIN cannot send an installation script.
Cron, Localization, and Administration
- Fixed MAIN server IP auto-detection to skip loopback addresses.
- Improved English translation fallback when a translation response is incomplete.
- Removed voucher routes whose handlers did not exist.
- Fixed chart tooltips to display local time instead of UTC.
- Improved handling of test-panel errors and nginx worker shutdown behavior.
- Reduced nginx reload-related issues and corrected thread-pool configuration.
- Improved load-balancer state reporting during updates and rollbacks.
🧹 Refactoring and Maintenance
- Removed obsolete
.gitattributes,CONTEXT.md, andDEAD_CODE.mdfiles. - Updated
CLAUDE.mdand subagent documentation to match the current implementation. - Continued moving optional features out of core and into dedicated modules.
- Consolidated VOD import processing and recording ownership in core services.
- Improved separation between core APIs and module-provided functionality.
- Updated testing and release documentation to reflect the current development workflow.
📌 Important Notes
- PHP compatibility: Static analysis now explicitly runs on PHP 8.1, the minimum supported version.
- Database testing: The unit-test suite uses MariaDB and the panel's own application stack.
- Module compatibility: Modules declaring
requires_coreare subject to core-version requirements during loading, installation, and updating. - Load balancers: Installation and updates are designed to keep nodes aligned with MAIN's release.
- VOD imports: Movie and Series imports now use bounded batch processing, and per-file importing is managed by core.
- Optional integrations: Watch-folder and Plex functionality are separated from core, with Watch-folder support provided by its module.
This release continues XC_VM's transition toward a more modular architecture, with safer node management, more predictable streaming behavior, improved testing practices, and better separation of core functionality from optional integrations.