github Vateron-Media/XC_VM 2.6.2
v2.6.2

pre-release5 hours ago

XC_VM — Release Notes

Overview

This beta release focuses on the cluster API between MAIN and load balancers, account and access security, operations tooling, and performance. New panels now start on the cluster API, and the old load-balancer link is deprecated. It also adds two-factor sign-in, scoped API tokens, an admin audit log, maintenance mode, alerts, off-site backups and Prometheus metrics, and fixes many permission, reseller, player and Ministra issues.

✨ New Features

Cluster API and Load Balancers

  • New panels start on the cluster API: the installer switches it on, new load balancers join directly in mode 2 when the extension allows it, and MAIN's data plane is switched on.
  • Redesigned the Cluster Nodes page in the Manage Servers format: a searchable table, a status dot, flows as one row of toggles, and a row actions menu.
  • Added a Legacy /api calls column: each load balancer reports who still calls its old /api, by action and caller.
  • Added rolling load-balancer updates (one at a time), a guided cutover to mode 1, moving a node to mode 2 from the page, and an optional automatic mode down.
  • New load balancers can join directly in mode 2, and mode 2 works with the Redis connection handler.
  • Load balancers can serve RTMP viewers, with each viewer's line checked by MAIN, including while MAIN is briefly unreachable.
  • Added Viewer Record Proof, settable from the panel, with a card that says when enforce is safe.
  • Added a fleet canary for the binaries every server takes from GitHub, a release pin, and a switch for MAIN's data plane on the Cluster Nodes page.
  • Firewall blocks now live in ipset sets, installed on new servers and with the update; large blocklists sync in parts.
  • Added cluster alerts, and the cluster in /metrics.

Security and Accounts

  • Two-factor sign-in for admins and resellers.
  • Named, scoped API tokens replace the single API key.
  • An audit log of what admins change.

Operations

  • Maintenance mode closes the client APIs and reseller access.
  • Alerts and expiry reminders by Telegram, webhook and e-mail.
  • Off-site backup copies, a sealed recovery bundle and restore tests. The live database is dumped before a restore and before an update.
  • /metrics for Prometheus and /healthz.
  • The dashboard checks every server, adds disk, backup, certificate and cache rows, and warns when a server's clock is off MAIN's. Servers wait for NTP's first synchronisation at boot.

Panel

  • The Modules page is rewritten around module status and the official store, and module actions run as background jobs.
  • The stream form exposes the custom ffmpeg command; the Instant Off grace period is configurable.
  • Line and device lists show notes under the username.

🚀 Improvements

  • Performance: EPG deduplication in one pass with XMLTV rendered once per source set, batched log retention with new indexes, a sharded bouquet map, and broader playlist caching.
  • Subtitles are read from shared mounts instead of over HTTP.
  • Updates report a failed migration and dump MAIN's database first.
  • The installer verifies its downloads and validates certificate host names.

🛠️ Bug Fixes

Security and Permissions

  • Every admin page, action, table and admin API call now asks for the right permission.
  • Resellers are held to their own tree, packages and trials. Credits are atomic, and balances and prices are stored as DECIMAL(16,4).
  • An address that tries many passwords for one username is blocked, and refused sign-ins are counted on every client entry point.
  • Sessions start with hardened cookie settings. The web players have their own session cookie, stay within the line's own content and escape what they print. The image resizer fetches only public addresses.
  • MAG session tokens come from the secure random source.

Ministra

  • A MAG device is served only once the portal has verified it, and its token is kept until get_profile has verified the new one.
  • The Stalker API answers at /server/load.php. Channel and genre fields are sent as strings, and the handshake methods and player prefix are restored.

Streaming, Cron and Administration

  • Record edits keep the fields an edit leaves out.
  • Hanging cron:servers and cron:streams runs end after ten minutes, and a running cron keeps its lock.
  • Streams start from their stored values with complete source cookies.
  • Empty ids are dropped from mass-edit selections, and the leftover rows they left are cleaned up.
  • Dates are shown in the panel timezone.
  • Many cluster fixes: quarantined nodes, credential strips, mode-2 viewer checks and blocklist syncing.

⚠️ Deprecation

The old load-balancer link is deprecated and will be removed in a later major release: a load balancer that is not enrolled in the cluster API, its /api with the stream password, and its access to MAIN's database and Redis. That release will ask every load balancer to be in mode 2 before it updates. The Legacy /api calls column on Cluster Nodes shows what still uses the old /api.

📌 Important Notes

  • Beta: this is a pre-release.
  • New installs start with the cluster API on. Existing panels are not changed: switch it on under Settings → Cluster.
  • Proxies no longer keep the load balancers' legacy /api open.
  • Update order: update MAIN first; load balancers follow.

Don't miss a new XC_VM release

NewReleases is sending notifications on new releases.