0.23.3 (2026-05-13)
🇷🇺 Что нового (RU)
Что решает этот релиз
v0.23.3 - patch-релиз для fresh install на чистых Debian/Ubuntu хостах, особенно для minimized Debian 12 образов.
На чистой Debian 12 установка могла доходить до скачивания бинарника и генерации config.toml, а затем останавливаться на создании service account:
Failed to create system group 'mtproto'
Failed to spawn command
Корень проблемы был в том, что installer вызывал groupadd / useradd как bare commands. На Debian эти утилиты обычно лежат в /usr/sbin, и при отличающемся PATH процесс мог не найти команду вообще. Из-за этого установка оставляла хост в полусобранном состоянии: бинарник и конфиг уже были в /opt/mtproto-proxy, но пользователя mtproto, владельцев файлов и запущенного systemd service ещё не было.
Во время проверки на живом clean Debian 12 всплыли ещё два слабых места:
mtbuddy setup maskingмог заранее создать/etc/nginx/sites-available/default, а затемaptупирался в conffile prompt при установкеnginx. В non-interactive запуске это оставлялоnginx/nginx-commonв half-configured состоянии и ломало последующую установку build dependencies дляnfqws.mtbuddy setup nfqwsдобавлял kernel rules best-effort и мог продолжить happy path без явной проверки, что IPv4NFQUEUErule реально появился.
Этот релиз делает install path более скучным и предсказуемым: если команда не найдена или package manager не смог завершиться, оператор видит конкретную ошибку, а не ложный успех.
[!NOTE]
Конфиг менять не нужно. Релиз чинит installer/control-plane поведение, а не runtime protocol.
[!TIP]
Если хост уже застрял после старогоFailed to create system group 'mtproto', обновитеmtbuddyдоv0.23.3и повторите установку. Installer сохранит существующий/opt/mtproto-proxy/config.toml.
Что изменено
Account commands теперь устойчивы к /usr/sbin PATH (#258)
- Добавлен общий helper
sys.commandOrPath(). groupadd,useraddиuserdelтеперь сначала ищутся вPATH, затем через fallback paths:/usr/sbin/<cmd>;/sbin/<cmd>.
- Ошибка запуска required command теперь показывает конкретный Zig error name, например
FileNotFound, вместо гологоFailed to spawn command. - Это закрывает сценарий, где Debian-хост имеет нужные системные утилиты, но текущий процесс installer их не видит через
PATH.
Nginx install больше не ломается на conffile prompt (#258)
mtbuddy setup maskingбольше не pre-creates packaged nginx default site до установки пакета.apt-getдля nginx запускается сDEBIAN_FRONTEND=noninteractive.- Добавлены dpkg options:
--force-confdef;--force-confold.
- Ошибки установки nginx теперь логируются как настоящие failed steps, а не маскируются последующим summary.
nfqws setup стал честнее про результат (#258)
- Установка build dependencies для
nfqwsтеперь тоже идёт через noninteractive apt с теми же dpkg conffile options. - IPv4
NFQUEUErule теперь ставится через checked command path. - После установки проверяется, что правило действительно присутствует в
iptables -t mangle -S OUTPUT. - Если rule не появился, setup останавливается с явной ошибкой вместо продолжения к misleading success summary.
Проверено
zig fmt src/ctl/masking.zig src/ctl/nfqws.zig src/ctl/sys.zig src/ctl/install.zig src/ctl/uninstall.ziggit diff --checkzig build -Dtarget=x86_64-linux-musl- Manual clean Debian 12 VPS validation:
mtproto-proxyactive/enabled;nginxactive/enabled;nfqws-mtprotoactive/enabled;mtproto-mask-health.timeractive;- TCP
443reachable externally; - local masking on
127.0.0.1:8443returned HTTP 200; - IPv4/IPv6
TCPMSSandNFQUEUE #200rules present.
🇬🇧 Release notes (EN)
What this release addresses
v0.23.3 is a patch release for fresh installs on clean Debian/Ubuntu hosts, especially minimized Debian 12 images.
On a clean Debian 12 machine, installation could download the proxy binary and generate config.toml, then stop while creating the service account:
Failed to create system group 'mtproto'
Failed to spawn command
The root cause was that the installer invoked groupadd / useradd as bare commands. On Debian these utilities normally live under /usr/sbin, and a different PATH could make the installer fail to spawn them at all. That left the host half-installed: the binary and config existed under /opt/mtproto-proxy, but the mtproto account, ownership, and running systemd service were not set up yet.
A live clean-Debian-12 validation pass also exposed two follow-up installer weaknesses:
mtbuddy setup maskingcould pre-create/etc/nginx/sites-available/default, thenapthit a conffile prompt while installingnginx. In a non-interactive run this leftnginx/nginx-commonhalf-configured and broke the laternfqwsdependency install.mtbuddy setup nfqwsadded kernel rules best-effort and could continue down the happy path without verifying that the IPv4NFQUEUErule was actually present.
This release makes the install path more boring and predictable: if a command is missing or the package manager cannot finish, the operator gets a concrete failure instead of a misleading success path.
[!NOTE]
No config changes are required. This release fixes installer/control-plane behavior, not the runtime protocol.
[!TIP]
If a host is already stuck after the oldFailed to create system group 'mtproto'failure, updatemtbuddytov0.23.3and rerun the install. The installer keeps the existing/opt/mtproto-proxy/config.toml.
What changed
Account commands now tolerate /usr/sbin PATH differences (#258)
- Added a shared
sys.commandOrPath()helper. groupadd,useradd, anduserdelare resolved throughPATHfirst, then fallback paths:/usr/sbin/<cmd>;/sbin/<cmd>.
- Required command spawn failures now include the Zig error name, for example
FileNotFound, instead of onlyFailed to spawn command. - This covers Debian hosts where the system tools exist but the installer process cannot see them through
PATH.
Nginx install no longer trips over conffile prompts (#258)
mtbuddy setup maskingno longer pre-creates nginx's packaged default site before installing the package.- nginx
apt-getruns withDEBIAN_FRONTEND=noninteractive. - Added dpkg options:
--force-confdef;--force-confold.
- nginx install errors are now logged as real failed steps instead of being hidden behind a later summary.
nfqws setup now verifies the important kernel rule (#258)
nfqwsbuild dependency installation also uses noninteractive apt with the same dpkg conffile options.- The IPv4
NFQUEUErule is installed through a checked command path. - Setup verifies that the rule is present in
iptables -t mangle -S OUTPUT. - If the rule is missing, setup stops with a clear error instead of continuing to a misleading success summary.
Verified
zig fmt src/ctl/masking.zig src/ctl/nfqws.zig src/ctl/sys.zig src/ctl/install.zig src/ctl/uninstall.ziggit diff --checkzig build -Dtarget=x86_64-linux-musl- Manual clean Debian 12 VPS validation:
mtproto-proxyactive/enabled;nginxactive/enabled;nfqws-mtprotoactive/enabled;mtproto-mask-health.timeractive;- TCP
443reachable externally; - local masking on
127.0.0.1:8443returned HTTP 200; - IPv4/IPv6
TCPMSSandNFQUEUE #200rules present.