MeshMonitor v4.17.0-rc4
Warning
This is a pre-release for testing. It is not tagged latest. Use it on a test install or with a recent backup.
Summary
This release candidate fixes the Windows desktop app, whose landing page loaded white on a cold start: the Windows build shipped without its theme styles. System backups now cover every table and stream the export, so large databases back up again; a backup is now a secret and its download is admin-only. Message notifications get a user-set format with the source shown once, each source keeps its own notification settings, and the Notifications page follows the light theme. MeshCore gains plaintext for channel packets in the Packet Monitor, split or truncated long auto-acknowledge replies, a serial health probe for repeaters, a faster-failing Trace Path, and merged rows in Unified Messages when several sources hear one message. Translation providers each keep their own API key, and OpenAI-compatible base URLs resolve correctly. Traceroutes now read the same way everywhere, and source connection details no longer reach viewers who lack the right grant.
Features
- MeshCore: decrypt GRP_TXT / GRP_DATA in the Packet Decode modal (#5583)
- MeshCore: split or truncate long Auto-Acknowledge replies (#5584)
- MeshCore: map toggle to hide nodes whose latest advert had no position (#5585)
- MeshCore: role, hops and last-heard tokens on node triggers (#5603)
- Map: traceroute-confirmed reciprocal links on the cross-source layer (#5586)
- Unified Messages: one row for a MeshCore message heard by several sources (#5590)
- Notifications: user-set message format and a lighter default (#5605)
- Translation: each provider owns its config fields; one API key per provider (#5600)
- Lint: guardrail against hardcoded colours in inline styles and CSS (#5606)
Bug Fixes
- Build: Windows desktop app ships its theme CSS again (#5599)
- Backup: back up every table, stream the export, allowlist restore on all backends (#5618)
- Sources: tighter config redaction for non-admins (#5619)
- Notifications: a source with no saved preferences uses built-in defaults, not another source's (#5609)
- Notifications: page colours come from theme tokens (#5604)
- Traceroute: every reader gets requester-first rows (#5611)
- MQTT bridge: stop retrying a rejected broker login, per client (#5610)
- MeshCore MQTT ingest: stop login retries after 5 rejections; back up Observer keys; clear key rows on source delete (#5602)
- MeshCore: repeater serial health probe and auto-reconnect (#5581)
- MeshCore: Trace Path waits per the firmware's suggested timeout (#5589)
- MeshCore: Virtual Node relays STATUS and TELEMETRY binary requests (#5598)
- MeshCore: Virtual Node sends the packed path length (#5608)
- MeshCore: ingest page header shows region and broker again (#5607)
- Packet Monitor: "Hide Own Packets" keeps TX rows and shows a hidden count (#5582)
- Translation: endpoint URL resolution for custom and versioned base URLs (#5545), by @Crim
Docs and Tests
- Coverage Report: "Why a survey looks sparse" (#5601)
- Tests: wall-clock and module-load cost taken out of flaky tests (#5617)
Issues Resolved
#5518, #5519, #5558, #5563, #5564, #5567, #5568, #5578, #5579, #5580, #5587, #5588, #5591, #5592, #5593, #5594, #5595, #5597
Upgrade Notes
- Migrations 194–197 run on first start.
- Translation API keys: the stored key moves to the active provider only. Enter keys for any other provider again.
- Translation URLs: a custom URL with a sub-path and no version (for example
http://host/libre) is now used as written; earlier candidates appended the provider path to it. - Backups: a system backup now holds every table, including channel keys in the clear, tokens and encrypted credentials. Store it like a secret. Download is admin-only; new backup files are readable only by the server's user.
- Notifications: each source uses its own saved settings. A source you never saved settings for now notifies for direct messages only; it no longer borrows another source's settings. Message notifications show the source once, and new-node, traceroute and server-event pushes go only to browsers subscribed on that source.
- Traceroutes:
fromNodeNumnow always means the requester in every API response, including v1, and the notification title reads asker → answerer. MQTT sources no longer store in-flight traceroute requests as runs, so they show far fewer traceroutes; old rows age out. - Source details: a signed-in user without
sources:readno longer sees a node's address or a broker host. - MeshCore auto-acknowledge: a reply longer than the message limit is now cut to fit unless "Split long messages" is on.
- MQTT bridge: saving a bridge with an unchanged config no longer restarts it; use Connect to retry.
Thanks
Thanks to @Crim for the translation endpoint work and to @Netwisdom69 for the Virtual Node report.
Full changelog: v4.17.0-rc3...v4.17.0-rc4
🚀 MeshMonitor v4.17.0-rc4
📦 Installation
Docker (recommended):
docker run -d \
--name meshmonitor \
-p 8080:3001 \
-v meshmonitor-data:/data \
ghcr.io/Yeraze/meshmonitor:4.17.0-rc4🧪 Testing
✅ All tests passed
✅ TypeScript checks passed
✅ Docker images built for linux/amd64, linux/arm64, linux/arm/v7
📋 Changes
See commit history for detailed changes.