XC_VM — Release Notes
Overview
This beta release is mostly fixes. A whole-code review found and closed a set of security and correctness problems in the admin panel, the reseller API and the stream endpoints, and a follow-up review of the Redis connection handler and the file caches removed work that every viewer request was paying for. It also adds IPv4 range blocking, a working MAG Scan settings page, and lets the segment gateway answer an MPEG-TS viewer's first request.
Two fixes matter to anyone running load balancers: a load balancer still on stable 2.3.9 can update to the betas again, and MAIN's connection-limit queue can no longer fill the temporary filesystem.
✨ New Features
- Blocked IPs accepts IPv4 ranges (
/16to/31). A range that holds one of the panel's own addresses, or the administrator's, is refused. - MAG Scan settings: the page now saves its four lists (MACs and IPs, always blocked or never counted) and the bruteforce guard applies them.
- Segment gateway, MPEG-TS first request: in
segments+playlistthe gateway creates a TS viewer's connection itself and serves the stream from fanout, with no PHP request. Needs xc_fanout 0.15.1 or later; an older daemon keeps the first request on PHP. - Native remuxer (xc_fanout 0.15.2): an H.264 source with open GOPs that sets no random-access flag stays native instead of moving to ffmpeg; its recovery points are recognised as keyframes.
- Legacy
panel_api.php(when enabled) lists the line's categories and streams again. - Dashboard: a "Database ports" check warns while MariaDB and Redis on MAIN answer any address, with a pointer to the DB Allowlist setting.
- Watch folders: Auto-Upgrade works for a load balancer's folder scanned from MAIN, and a copy that is kept is logged as
DUPLICATE. - Modules: a module installed or enabled from the panel gets its cron jobs at once, without a restart. A renamed module keeps its install.
🔒 Security
- Admin pages escaped names, notes and titles without their quotes, so a stored value could run script in an administrator's browser. Every page's escaping is fixed.
- A read-only API token no longer receives secret settings (the stream tokens' key, the Redis password, API keys).
- Bulk stream actions, the global search, the category templates, Stream Review and the dashboard graph now follow the admin group's permissions.
- Resellers: a sub-reseller's password and API key are no longer returned, restriction fields need the right to set them, and the guide lists only the streams of the reseller's packages.
- "Restrict same IP" compares subnets for IPv6 too; any two IPv6 addresses counted as the same subnet.
- A watch folder's path can no longer inject options into the scan command (Watch module), and several commands no longer go through a shell.
- Line lookup files in the cache no longer carry the username and password in their name.
- The installer wrote
config.ini(the database password) and its credentials files readable by everyone. They are now private, and an update closesconfig.inion existing panels.
🐛 Fixes
- A load balancer on stable 2.3.9 (or a beta up to 2.4.x) could not update to the betas: since 2.6.0 the setting it reads for its update channel was missing, so it answered "Already up to date" for ever. The setting is back and follows the panel's channel.
- MAIN's connection-limit queue could fill the temporary filesystem on panels with API-mode load balancers: each viewer request of a line with a limit left a file, and when requests outran the loop the files piled up (over a million in one report). The queue now holds one file per viewer, drops old checks, and an admission that ran out no longer closes a viewer for a place nobody takes.
- A mass edit of lines, MAGs or Enigmas with Expiry ticked and no date expired every selected line.
- A backup restore whose database connection dropped mid-migration could reconnect to the live database and clear its tables.
- Reseller REST table actions answered
null; credit transfers were logged with the wrong amount; a package with unredeemed activation codes can no longer be deleted (its codes gave one month whatever was sold). - A per-server Delete in the stream lists removed the stream from every server; a bulk delete left a stream on no server instead of deleting it; a proxy action could disable the main server.
- The M3U review imported only the table page shown. A created channel lost its on-demand servers on edit.
- An alert that became due during the quiet period was never sent.
- A link to a series' episodes listed every series' episodes, and an episode whose file failed showed "On Demand" with a live play button instead of Down.
- A reseller saving a MAG or Enigma device removed the pairing an administrator had made. The admin API's
kill_connectionclosed nothing with the Redis connection handler. - Enigma2 links were always
http://and carried unencoded credentials. - A subtitle name with a space broke a movie's start; deleting a running recording did not stop it; error pages were cached as images.
- Module updates: a successful retry no longer leaves the module Failed, a
.taror.tar.gzarchive is recognised by its content, and a migration that runs DDL no longer fails with "There is no active transaction".
⚡ Performance and stability
- Redis connection handler: a Redis restart no longer ends running TS, VOD and timeshift streams; the connection sweep no longer kills a worker that serves another viewer; a panel with the handler off no longer connects to Redis on every viewer request.
- Stream requests on large panels: the bouquets map is no longer decoded for every segment, key and playlist request, and cached lists are decoded once per process.
- The cache builder reads the lines' directory once instead of three times.
⬆️ Upgrade notes
- Update MAIN first, then the load balancers; keep them on the same version.
- A load balancer stuck on 2.3.9 can be updated once MAIN is on 2.6.5: update it from Servers as usual.
- Watch Auto-Upgrade on a load balancer's folder needs the load balancer on 2.6.5 as well.
- The first cache pass after the update rewrites every line's lookup file under its new name; sign-ins keep working meanwhile.
- A panel using the Redis connection handler keeps its key layout; nodes on mixed versions keep working during the update.
Full Changelog: 2.6.4...2.6.5