-
DcRouter v32.6.0
StableRelease / build-and-release (push) Successful in 26m16sreleased this
2026-09-26 17:03:29 +00:00 | 14 commits to main since this release2026-09-26 - 32.6.0
Features
- Report stored routes that cannot be served. Route warnings (
IRouteWarning) gain the typeroute-ingress-disabled: a stored route whose only ingress paths are off (SmartVPN or the RemoteIngress hub not running) is left out of the applied routes and listed with this warning, instead of stopping every other route.
Fixes
- Hold one local mirror row per provider DNS record. Releases before 19.1.0 ran provider-zone syncs, gateway route DNS reconciles and mail DNS reconciles concurrently, so two writers could each mirror the same new provider record;
syncDomain()then refuses the zone withLocal mirror has duplicate provider record id …, and every automated DNS write for that zone fails aszone-unavailableuntil the row is removed.DnsRecordDocnow storesproviderRecordKey(<domainId>:<providerRecordId>), derived in one place (ts/dns/provider-record-key.ts) bycreateSavableObject()and by the ACME and testing mirror writers, and cleared with the provider id when a zone migrates to dcrouter. The sparse unique indexprovider_record_key_uniquemakes a racing second mirror insert fail instead of persisting. The new migration stepreconcile-provider-record-mirror-duplicates(32.0.1to32.6.0) keeps the row that carriesmanagedByownership and deletes its unowned synced copies, keeps the oldest row where none is owned, trims stored ids, backfills the key and then creates the index. It deletes local mirror rows only and never calls the provider. When rows with different owners share one provider record, it refuses by name and changes nothing. The error lists the domain, the provider id, the row ids and the owners. - Start dcrouter when neither SmartVPN nor a RemoteIngress hub runs. Since 17.9.0 every route without an explicit ingress policy, including the generated
dns-over-https-dns-queryroute and email routes, was authorized for SmartVPN, and aremoteIngressroute for the edge tunnel, whether or not that runtime was on. The listener therefore gotinboundProxyProtocoloptionalorrequiredwhile SmartProxy had no trusted proxy, and SmartProxy refused the route set:Route 'dns-over-https-dns-query': inboundProxyProtocol mode optional/required needs trustedProxyIPs or global trustedProxyIPs, a critical startup failure. Ingress origins are now authorized only for the paths whose runtime is on:smartVpnwhenvpnConfig.enabled,trustedProxywhen the RemoteIngress hub is enabled. A listener that only direct traffic reaches getsreject. A route created through the API whose only declared paths are off, for example a VPN-only route on a hub without SmartVPN, is now left out of the applied route set on its own. Every other route is still applied, at startup and on every route application. The route is logged atwarnwhen it is first refused and listed among the route warnings ofgetMergedRoutesand the Ops UI routes view asroute-ingress-disabled. A route from dcrouter's own configuration whose only paths are off still fails startup withRoute '<name>' has no enabled ingress path, because it restates the operator's options.
Downloads
- Report stored routes that cannot be served. Route warnings (