github Yeraze/meshmonitor v4.17.0-rc5

pre-release4 hours ago

MeshMonitor v4.17.0-rc5

Warning

This is a pre-release for testing. It is not tagged latest. Use it on a test install or with a recent backup.

Summary

This release candidate adds four admin features and closes several gaps found after rc4. Admin Commands gains a Power and reset block: Shut down, Reboot into DFU mode, and two factory resets labelled by what survives, each written to the audit log. Security settings gain a Protection Level picker for the firmware 2.8 packet signature policy (Compatible, Balanced, Strict), on local and remote nodes. A status pill in the header sets the node's status message from a short list of presets. Automations can pass a script's result to later steps in the same run with {{ steps.<name>.output }}, with no variable to define, and a send whose text renders empty is now held back. On the fix side, saving Security settings on a local node no longer resets its packet signature policy, non-admin source editors no longer see stored credentials, MeshCore Repeater nodes open in Node Details and stay on the map, and traceroutes store their position snapshot on every path.

Features

  • Admin: Shut down, Reboot into DFU mode and two factory resets, with audit log (#5638)
  • Security: Protection Level picker for packet_signature_policy (#5642)
  • Status: quick-access status message pill with presets (#5639)
  • Automation: run-scoped step outputs, the empty-send rule, and two variable-store fixes (#5640)

Bug Fixes

  • Security: a local Security save keeps the node's packet signature policy (#5637)
  • Sources: mask credentials in source config for non-admin editors (#5635)
  • MeshCore: Repeater-source nodes open in Node Details and stay on the map (#5634)
  • Traceroute: write the position snapshot on every path; the auto-traceroute picker counts either stored form (#5633)

Dependencies

Issues Resolved

#5612, #5614, #5615, #5616, #5632, #5636

Upgrade Notes

  • No new migrations.
  • Power and reset: Reboot into DFU and both factory resets work on the node MeshMonitor is connected to only. Shut down also works on a remote node, with a typed confirm. Each action sends one admin packet and cannot be undone from MeshMonitor. DFU works on nRF52, RP2040 and STM32 boards; ESP32 ignores it.
  • Protection Level: shown for firmware 2.8.0 and later. For a remote node, run Retrieve Device Metadata first so MeshMonitor knows its firmware. Strict drops every packet that is neither signed nor PKI-encrypted, which can cut a node off from peers older than 2.8; it needs a typed confirm. Saving reboots the node. Each change is written to the audit log.
  • Status pill: needs configuration:write on the source. The status text limit is 79 bytes. Firmware rebroadcasts the status about every 12 hours.
  • Automations: a Send a message, tapback or notification whose text renders empty is now skipped and logged, in every automation. A script step that cannot store its result in the chosen variable now fails the step, so some runs that read "completed" before will read "failed". Node-scoped variables now save on MeshCore triggers.
  • Security saves: a local Security save reads the node's config first. If the node does not answer (for example while it reboots after the last save), the save returns an error and sends nothing; try again.
  • Source config: a non-admin with edit rights sees credential fields masked; leaving a masked field alone keeps the stored value.
  • Node list: MeshCore rows returned by /api/nodes now pass the same permission check as Meshtastic rows.

Full changelog: v4.17.0-rc4...v4.17.0-rc5

๐Ÿš€ MeshMonitor v4.17.0-rc5

๐Ÿ“ฆ Installation

Docker (recommended):

docker run -d \
  --name meshmonitor \
  -p 8080:3001 \
  -v meshmonitor-data:/data \
  ghcr.io/Yeraze/meshmonitor:4.17.0-rc5

๐Ÿงช Testing

โœ… All tests passed
โœ… TypeScript checks passed
โœ… Docker images built for linux/amd64, linux/arm64, linux/arm/v7

๐Ÿ“‹ Changes

See commit history for detailed changes.

Don't miss a new meshmonitor release

NewReleases is sending notifications on new releases.