Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package netbird for openSUSE:Factory checked in at 2026-07-15 16:44:24 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/netbird (Old) and /work/SRC/openSUSE:Factory/.netbird.new.1991 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "netbird" Wed Jul 15 16:44:24 2026 rev:39 rq:1365779 version:0.74.5 Changes: -------- --- /work/SRC/openSUSE:Factory/netbird/netbird.changes 2026-07-14 13:50:50.012845705 +0200 +++ /work/SRC/openSUSE:Factory/.netbird.new.1991/netbird.changes 2026-07-15 17:02:45.273457790 +0200 @@ -1,0 +2,9 @@ +Tue Jul 14 21:28:48 UTC 2026 - Marcus Rueckert <[email protected]> + +- Update to 0.74.5 + - [proxy] enforce model allowlist for URL-routed providers + (Bedrock/Vertex) by @mlsmaycon in #6764 + - [management] Remove proxy peer stale deduplication logic by + @mlsmaycon in #6768 + +------------------------------------------------------------------- Old: ---- netbird-0.74.4.obscpio New: ---- netbird-0.74.5.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ netbird.spec ++++++ --- /var/tmp/diff_new_pack.e72vpa/_old 2026-07-15 17:02:54.533772298 +0200 +++ /var/tmp/diff_new_pack.e72vpa/_new 2026-07-15 17:02:54.537772434 +0200 @@ -32,7 +32,7 @@ %bcond_with stub_config Name: netbird -Version: 0.74.4 +Version: 0.74.5 Release: 0 Summary: Mesh VPN based on WireGuard License: AGPL-3.0-only AND BSD-3-Clause ++++++ _service ++++++ --- /var/tmp/diff_new_pack.e72vpa/_old 2026-07-15 17:02:54.569773521 +0200 +++ /var/tmp/diff_new_pack.e72vpa/_new 2026-07-15 17:02:54.573773657 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/netbirdio/netbird.git</param> <param name="scm">git</param> <param name="package-meta">yes</param> - <param name="revision">refs/tags/v0.74.4</param> + <param name="revision">refs/tags/v0.74.5</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">disable</param> ++++++ netbird-0.74.4.obscpio -> netbird-0.74.5.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/FETCH_HEAD new/netbird-0.74.5/.git/FETCH_HEAD --- old/netbird-0.74.4/.git/FETCH_HEAD 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/FETCH_HEAD 2026-07-14 20:13:00.000000000 +0200 @@ -1,5 +1,5 @@ 3aa6c02b932db503e82f9530dddfe95d5ea212c4 not-for-merge branch '0.74.3-branch' of https://github.com/netbirdio/netbird -3d87547d952f5ada9df987bbe4f0f6d54372d77c not-for-merge branch '0.74.4-branch' of https://github.com/netbirdio/netbird +f0eed7564f3a9138962da1408986e4666d7137b5 not-for-merge branch '0.74.4-branch' of https://github.com/netbirdio/netbird 37046431d74765914b23ee4c016d475e0c7a7d6d not-for-merge branch '0.74.x' of https://github.com/netbirdio/netbird 1e24916daca9d8315064f0047b10cb47297ae16d not-for-merge branch 'account-refactoring' of https://github.com/netbirdio/netbird 3945d2b170f84b90a9997df77bd7c8889c061de2 not-for-merge branch 'add-account-onboarding' of https://github.com/netbirdio/netbird @@ -39,7 +39,7 @@ 8c5648bb7b522ca79c60d4d1481aa947249a6a92 not-for-merge branch 'coderabbitai/docstrings/b7e98ac' of https://github.com/netbirdio/netbird cb1eaf9e0d30daf1300dfa005abe9b10fe1a1adc not-for-merge branch 'coderabbitai/utg/8ae8f20' of https://github.com/netbirdio/netbird a67d2426181217b55aca7e27c7f5cda620697a3e not-for-merge branch 'components-impl-drop-indexes' of https://github.com/netbirdio/netbird -d5178416af32040d6a88f461a1fd12efb0e1e11d not-for-merge branch 'components-impl-drop-indexes-use-xids' of https://github.com/netbirdio/netbird +671a5f11fdefe35b39700a1bc43925f8e8ff6dff not-for-merge branch 'components-impl-drop-indexes-use-xids' of https://github.com/netbirdio/netbird 572bea6a718be862bfcd6729e510d95e0ad37a6f not-for-merge branch 'conntrack-stats' of https://github.com/netbirdio/netbird 20a79c5c555b6ab78c7837b4ebf7f80b5967db98 not-for-merge branch 'crowdsec-selfhosted' of https://github.com/netbirdio/netbird dd301f2691410ab19009c8a004961df43fa31294 not-for-merge branch 'daemon-owner' of https://github.com/netbirdio/netbird @@ -56,8 +56,8 @@ 0cf6ece217c3d2dcf9a05351679b3d71dc081904 not-for-merge branch 'debug-keycloak-idp' of https://github.com/netbirdio/netbird 26ed186111c9d177488900f8237a93bc45a1f281 not-for-merge branch 'debug-local-records' of https://github.com/netbirdio/netbird 24053750d90dbfc381fcbca9c9925443f51a4d8b not-for-merge branch 'debug-user-role' of https://github.com/netbirdio/netbird -6412cfc2e738578c4d060e7fb7e25eed02c5cb9f not-for-merge branch 'dependabot/github_actions/actions-a940c7c866' of https://github.com/netbirdio/netbird -3b0d193beb49894f2aacf0f2c8dc55ab4e330ac2 not-for-merge branch 'dependabot/go_modules/aws-sdk-8f849ebaed' of https://github.com/netbirdio/netbird +51bbe704dca7a1f21c51c50f4a8564afb7ee0116 not-for-merge branch 'dependabot/github_actions/actions-a940c7c866' of https://github.com/netbirdio/netbird +a8072f26d1390aab67af45cf5acdc60e552bbe34 not-for-merge branch 'dependabot/go_modules/aws-sdk-8f849ebaed' of https://github.com/netbirdio/netbird f1438f79956a930e3e8958c3327ffbad0e9b6c8a not-for-merge branch 'dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1' of https://github.com/netbirdio/netbird 237a0e709efbb052ebcc2273036df7ef7179cb9e not-for-merge branch 'dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.105.0' of https://github.com/netbirdio/netbird e26b4808d51e4294d8c673a2a0fb86d5cd270546 not-for-merge branch 'dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0' of https://github.com/netbirdio/netbird @@ -70,11 +70,11 @@ 9493b14fd154ad009806d83e70506637d1513ae6 not-for-merge branch 'dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0' of https://github.com/netbirdio/netbird 29c752d818966adfe41827593165376559f9f65d not-for-merge branch 'dependabot/go_modules/github.com/pkg/sftp-1.13.10' of https://github.com/netbirdio/netbird 2fdd3bd411297f97f6bf46bb99c8114b88a8f916 not-for-merge branch 'dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3' of https://github.com/netbirdio/netbird -0f8dcacde5efcd41a0429879820276bd4908d979 not-for-merge branch 'dependabot/go_modules/gorm-2271c8195b' of https://github.com/netbirdio/netbird -2d095a415dc88bc85aaf77b86caf85ee18482974 not-for-merge branch 'dependabot/go_modules/otel-e34c790afd' of https://github.com/netbirdio/netbird -ac56ddad9c1e368d11d530b1ab5ef20290e6238a not-for-merge branch 'dependabot/go_modules/pion-5f703e1eca' of https://github.com/netbirdio/netbird -7e75e57bee00f2911a4464f8fc40442d0264e791 not-for-merge branch 'dependabot/go_modules/testcontainers-de325c0dd6' of https://github.com/netbirdio/netbird -16195b7eb75da8aaf49cab91b03a4e1118c9b3bf not-for-merge branch 'dependabot/go_modules/wireguard-dbd6b95108' of https://github.com/netbirdio/netbird +0a6aedd99547133cf38f71a6612782c813ae0222 not-for-merge branch 'dependabot/go_modules/gorm-2271c8195b' of https://github.com/netbirdio/netbird +c067346459b74dc01ef0957301e2688ac03dd314 not-for-merge branch 'dependabot/go_modules/otel-e34c790afd' of https://github.com/netbirdio/netbird +d6aef0d65e115208d06a7d37f3ab8de75df1b587 not-for-merge branch 'dependabot/go_modules/pion-5f703e1eca' of https://github.com/netbirdio/netbird +db2bec30c43551af0e127c3fc68fe2060e075ca3 not-for-merge branch 'dependabot/go_modules/testcontainers-de325c0dd6' of https://github.com/netbirdio/netbird +bc1d7f43b141d87169f09cd63607dc12b11b064b not-for-merge branch 'dependabot/go_modules/wireguard-dbd6b95108' of https://github.com/netbirdio/netbird 90f6e7efd3c68b259ef1053d0738f4652ab5805f not-for-merge branch 'dependabot/npm_and_yarn/client/ui/frontend/npm_and_yarn-88714b13d0' of https://github.com/netbirdio/netbird 8c44187900ec87c8d484881d4e25ad253d73a168 not-for-merge branch 'deploy/peer-performance' of https://github.com/netbirdio/netbird 93c0172c8afca58da00823e8a0b3ee831e746832 not-for-merge branch 'deploy/permissions-account' of https://github.com/netbirdio/netbird @@ -95,7 +95,7 @@ 7d8700c847554ed94fe8b4fc1e47455913884161 not-for-merge branch 'e2e-windows-dns-combined' of https://github.com/netbirdio/netbird b78ec082a3178d8a05f865e0c1619f077338be59 not-for-merge branch 'ebpf' of https://github.com/netbirdio/netbird d02b8cbc970ee3966d9322a3490d1407ba7ae220 not-for-merge branch 'ebpf-debug' of https://github.com/netbirdio/netbird -fd7bf982c3b16bac8c4d066e9ad121bb12f8ca60 not-for-merge branch 'embedded-vnc' of https://github.com/netbirdio/netbird +152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0 not-for-merge branch 'embedded-vnc' of https://github.com/netbirdio/netbird f0a8e32c82200608fc33ff6946c0219941535829 not-for-merge branch 'enable-release-workflow-on-pr' of https://github.com/netbirdio/netbird 60a1bfcfc18bbbfcc894d24c3ba9e5a83886cc24 not-for-merge branch 'enable-udp-port-for-docker-template' of https://github.com/netbirdio/netbird 820ea80e689e5f4cbade0e926d0c615710c1c384 not-for-merge branch 'ensure-schedule-never-runs-non-positive' of https://github.com/netbirdio/netbird @@ -141,6 +141,7 @@ 829ce6573e9528518bcc23ca97b1ba3f1e381d7f not-for-merge branch 'feature/device-authentication-with-client-secret' of https://github.com/netbirdio/netbird e28e9854fef34dc04189a53d52b9b58714bb937f not-for-merge branch 'feature/disable-legacy-port' of https://github.com/netbirdio/netbird 279e96e6b155a31fba73a8bc80b3280cdd917663 not-for-merge branch 'feature/disk-encryption-check' of https://github.com/netbirdio/netbird +03252696b95abb7df8707eac056242153482b3bc not-for-merge branch 'feature/dns-lazy-conn-warmup' of https://github.com/netbirdio/netbird 213ab7d43e001b03fc7ad08fc78c544cf3c736fe not-for-merge branch 'feature/event-storage' of https://github.com/netbirdio/netbird 997bb12771ac2c6ac95d2361a3812f88c90d8d11 not-for-merge branch 'feature/exclude-terraform-from-rate-limiting' of https://github.com/netbirdio/netbird 55781d1e9dfcc65096b9ec57bf3361bf744fc3f6 not-for-merge branch 'feature/expose-has-channel' of https://github.com/netbirdio/netbird @@ -191,6 +192,7 @@ 1b39bcaedf00dda73c565a3b70e1b3d0e1e3e732 not-for-merge branch 'feature/users-roles-endpoint' of https://github.com/netbirdio/netbird 2f15708d546525832f5e3590a5b3585882a23efc not-for-merge branch 'feature/validate-group-association-debug' of https://github.com/netbirdio/netbird 3613a70c8c71c33dfc502b908ed0d31ede46e683 not-for-merge branch 'filter-cache-on-load-account' of https://github.com/netbirdio/netbird +8e387b5dc5afebefc40abba2d80303be2c7f6eeb not-for-merge branch 'fix-browser-dialog-not-closing' of https://github.com/netbirdio/netbird 69752b7cb7da156cc4f4b0acfe4c745c9f1541d8 not-for-merge branch 'fix-darwin-uninstaller' of https://github.com/netbirdio/netbird 26ed91652de1337c69dde5a1cf6736a728346b26 not-for-merge branch 'fix-install-version' of https://github.com/netbirdio/netbird 3cdfa11cb83565567163e03074647c852e84d42c not-for-merge branch 'fix-mgmt-cache-bypass-overlay' of https://github.com/netbirdio/netbird @@ -214,7 +216,6 @@ 56d82a99e15b0e88f4b102725b859210136d0a40 not-for-merge branch 'fix/events-key-handling' of https://github.com/netbirdio/netbird 59a09b0ff30470577deaa3383e3f70dcfcf6c90e not-for-merge branch 'fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall' of https://github.com/netbirdio/netbird 5a4d3770660460620dd25649593f9c74fca869c8 not-for-merge branch 'fix/filter-cgnat-cni-ice-candidates' of https://github.com/netbirdio/netbird -8732d3cd139b04c4d0e101d45e9482397186b7b1 not-for-merge branch 'fix/forwarders_exclusion_from_lazy_conn' of https://github.com/netbirdio/netbird 1e630b5d45bfd5fd9fadc776f522de2fc39a0ccf not-for-merge branch 'fix/geo-download' of https://github.com/netbirdio/netbird e32ad68f98eb19e9b9ec0adb42d4840bd728e8cc not-for-merge branch 'fix/getting-started' of https://github.com/netbirdio/netbird cbb9f9f56275b6f6c7ac343acd4dbb5b7f77a065 not-for-merge branch 'fix/go-mod-version' of https://github.com/netbirdio/netbird @@ -235,6 +236,7 @@ 29d6630686bea0d5fff422e7408786f3bcfc09ee not-for-merge branch 'fix/mysql-setup' of https://github.com/netbirdio/netbird 0cd22a2f978066b48658653fe505caae681e2b9f not-for-merge branch 'fix/nmap-exitnodes' of https://github.com/netbirdio/netbird dae8a86f33648be4adb754ccc8a4526dc7c72905 not-for-merge branch 'fix/nmap-fwrules' of https://github.com/netbirdio/netbird +efad9075e77d034c8a21567dc01d1de90f8bc367 not-for-merge branch 'fix/nsis-preserve-autostart-on-upgrade' of https://github.com/netbirdio/netbird c92ca4a0dc8a0cad63d3756025b54783d66f5f01 not-for-merge branch 'fix/peer_list_notification' of https://github.com/netbirdio/netbird d9bcdcf149d45b07d3b7725faf7691c097b50aff not-for-merge branch 'fix/proxy_close' of https://github.com/netbirdio/netbird 5d403a79ba285d09ee4c132daf6c8c73e885f78e not-for-merge branch 'fix/relay-reconnection' of https://github.com/netbirdio/netbird @@ -245,6 +247,8 @@ 99a7073592decbbab8283299ac03c462ed721c96 not-for-merge branch 'fix/remove-gpo-if-empty' of https://github.com/netbirdio/netbird 68996a1566837dda26b7106892992c716e8dbc8b not-for-merge branch 'fix/remove-logout-btn' of https://github.com/netbirdio/netbird 4b5e39c574f874969abbb484423fb72d093bbf24 not-for-merge branch 'fix/remove-otel-units' of https://github.com/netbirdio/netbird +cdde472266fddbf3e18df7e35673eda067f51c69 not-for-merge branch 'fix/remove-stale-peers-removal' of https://github.com/netbirdio/netbird +525a4fb29c43d405b5c50a0081599c8f3ab8d804 not-for-merge branch 'fix/remove-stale-proxy-logic' of https://github.com/netbirdio/netbird e3c66ced13de40333962f4a1e738b32b4335d2f2 not-for-merge branch 'fix/revert-ice-filter' of https://github.com/netbirdio/netbird 9be7e33a07b501799581d77949a2607fab5bb7c9 not-for-merge branch 'fix/route' of https://github.com/netbirdio/netbird e22976a89e7f2d6c2a5fa4583be9a24b01c63dbf not-for-merge branch 'fix/routeselector-atomic-exit-node' of https://github.com/netbirdio/netbird @@ -269,6 +273,8 @@ 4ff5ed756da87f0069f7eada2c89c1e53f84d1b4 not-for-merge branch 'increase-sysinfo-timeout' of https://github.com/netbirdio/netbird f894da0b11b61e000179520444e39d9ef838a974 not-for-merge branch 'job-stream-notify-disconnection-eof' of https://github.com/netbirdio/netbird 4eeaf95ab80daa0d12e33afe8cfd5d7ffd33a8f0 not-for-merge branch 'job-yml-update' of https://github.com/netbirdio/netbird +99ceb9b7a0c72e5beb94aab9250821080ba4527f not-for-merge branch 'lazy-conn-per-peer' of https://github.com/netbirdio/netbird +d438db50012b7abeeda0829c373abb0a41f0306e not-for-merge branch 'lazy-conn-rosenpass' of https://github.com/netbirdio/netbird acb2b9d619d1b08a0a1fa8973926caf5430d1894 not-for-merge branch 'lazyconn-first-packet-fix-v2' of https://github.com/netbirdio/netbird 4787e28ae3c687b5bb40ab71271868fd210d246a not-for-merge branch 'loadtest-signal' of https://github.com/netbirdio/netbird affa8bf348107386d3ab5eabc617ac79350283fd not-for-merge branch 'log-checks' of https://github.com/netbirdio/netbird @@ -276,7 +282,7 @@ 97ad3307ddb9e07f40a71eaa9489ca74947a6791 not-for-merge branch 'log/conn-disconn' of https://github.com/netbirdio/netbird a69dc29e7e7e24cf6cf7746632d7b8046c0a70e7 not-for-merge branch 'log/getaccount-by-peer' of https://github.com/netbirdio/netbird 0886b67ce951e5827d87571ac079b6f516027915 not-for-merge branch 'logs/peerlogs-addpeer' of https://github.com/netbirdio/netbird -30d15ecc3d9bf69161f8a8eda597acb78a29b602 not-for-merge branch 'main' of https://github.com/netbirdio/netbird +c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3 not-for-merge branch 'main' of https://github.com/netbirdio/netbird b03343bc4d249af295a4833161289d8339a0052a not-for-merge branch 'manual-peer-logout' of https://github.com/netbirdio/netbird b2c5732847ae5c22ab8f526204d9f121df72869e not-for-merge branch 'mdm_integration' of https://github.com/netbirdio/netbird 6efc1a61fe8568c3ae0704329aa2589c537e801b not-for-merge branch 'merged-fixes' of https://github.com/netbirdio/netbird @@ -332,6 +338,7 @@ 780890f9e607da27cae8facd37c04d43b043a61c not-for-merge branch 'refactor/nmap' of https://github.com/netbirdio/netbird 575b176371a8da362094b8b94137076a11b22249 not-for-merge branch 'refactor/nmap-limit-buffer' of https://github.com/netbirdio/netbird 0aeac50803f572040ef23d82867df172359807dd not-for-merge branch 'refactor/optimize-peer-expiration' of https://github.com/netbirdio/netbird +753925032ab2b604abafc90eadebb44ef16e9e38 not-for-merge branch 'refactor/peer-event-bus' of https://github.com/netbirdio/netbird 9b10d74ab8029410cf63ac3c4c0405d0aa01fd50 not-for-merge branch 'refactor/permissions-manager' of https://github.com/netbirdio/netbird e4fea16c9f188a105eaee5e4c8c72a300fecdebf not-for-merge branch 'refactor/permissions-no-pat-allowed' of https://github.com/netbirdio/netbird 6ce67f383e7610ead4404624bcdfda2998d18c33 not-for-merge branch 'refactor/reducate-signaling' of https://github.com/netbirdio/netbird @@ -436,7 +443,6 @@ 485a38a4a86b595bbc3afc2973610d1c61f6c8fe not-for-merge branch 'wasmbuild-test' of https://github.com/netbirdio/netbird 940367e1c64cb6ebe280c8e35bf182ce6fed4d3a not-for-merge branch 'wg_bind_parallel_processing' of https://github.com/netbirdio/netbird d66b425bb674eb69050d27d45a72db049db3de34 not-for-merge branch 'wg_conn_fix' of https://github.com/netbirdio/netbird -5740dd22e6c0ce4d5a27504685bc61709f23be20 not-for-merge branch 'wg_watcher_debounce' of https://github.com/netbirdio/netbird dd13b8f27eabb649952754071e5165515887d3ee not-for-merge branch 'wgwatcher-test' of https://github.com/netbirdio/netbird 9157b749459ad64620c36178fb26eac40e9ca805 not-for-merge branch 'windows-dns-firewall' of https://github.com/netbirdio/netbird e3d1b9ca880ff4f1e6624e306b6957aa6c30e5c1 not-for-merge branch 'windows-search-domains' of https://github.com/netbirdio/netbird diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/HEAD new/netbird-0.74.5/.git/HEAD --- old/netbird-0.74.4/.git/HEAD 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/HEAD 2026-07-14 20:13:00.000000000 +0200 @@ -1 +1 @@ -3d87547d952f5ada9df987bbe4f0f6d54372d77c +f0eed7564f3a9138962da1408986e4666d7137b5 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/ORIG_HEAD new/netbird-0.74.5/.git/ORIG_HEAD --- old/netbird-0.74.4/.git/ORIG_HEAD 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/ORIG_HEAD 2026-07-14 20:13:00.000000000 +0200 @@ -1 +1 @@ -3d87547d952f5ada9df987bbe4f0f6d54372d77c +f0eed7564f3a9138962da1408986e4666d7137b5 Binary files old/netbird-0.74.4/.git/index and new/netbird-0.74.5/.git/index differ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/HEAD new/netbird-0.74.5/.git/logs/HEAD --- old/netbird-0.74.4/.git/logs/HEAD 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/HEAD 2026-07-14 20:13:00.000000000 +0200 @@ -36,3 +36,4 @@ 859fe19fff6661ed0ba7904b42ed8b12d72c36f5 3aa6c02b932db503e82f9530dddfe95d5ea212c4 Marcus Rückert <[email protected]> 1783104338 +0200 checkout: moving from 859fe19fff6661ed0ba7904b42ed8b12d72c36f5 to v0.74.2 3aa6c02b932db503e82f9530dddfe95d5ea212c4 7cd5c1732bb5374f21005073937c42f4d531e3c5 Marcus Rückert <[email protected]> 1783537366 +0200 checkout: moving from 3aa6c02b932db503e82f9530dddfe95d5ea212c4 to v0.74.3 7cd5c1732bb5374f21005073937c42f4d531e3c5 3d87547d952f5ada9df987bbe4f0f6d54372d77c Marcus Rückert <[email protected]> 1783772566 +0200 checkout: moving from 7cd5c1732bb5374f21005073937c42f4d531e3c5 to v0.74.4 +3d87547d952f5ada9df987bbe4f0f6d54372d77c f0eed7564f3a9138962da1408986e4666d7137b5 Marcus Rückert <[email protected]> 1784064470 +0200 checkout: moving from 3d87547d952f5ada9df987bbe4f0f6d54372d77c to v0.74.5 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/0.74.4-branch new/netbird-0.74.5/.git/logs/refs/remotes/origin/0.74.4-branch --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/0.74.4-branch 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/0.74.4-branch 2026-07-14 20:13:00.000000000 +0200 @@ -1 +1,2 @@ 0000000000000000000000000000000000000000 3d87547d952f5ada9df987bbe4f0f6d54372d77c Marcus Rückert <[email protected]> 1783772549 +0200 pull: storing head +3d87547d952f5ada9df987bbe4f0f6d54372d77c f0eed7564f3a9138962da1408986e4666d7137b5 Marcus Rückert <[email protected]> 1784064464 +0200 pull: fast-forward diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids new/netbird-0.74.5/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids 2026-07-14 20:13:00.000000000 +0200 @@ -1 +1,2 @@ 0000000000000000000000000000000000000000 d5178416af32040d6a88f461a1fd12efb0e1e11d Marcus Rückert <[email protected]> 1783772549 +0200 pull: storing head +d5178416af32040d6a88f461a1fd12efb0e1e11d 671a5f11fdefe35b39700a1bc43925f8e8ff6dff Marcus Rückert <[email protected]> 1784064464 +0200 pull: fast-forward diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 2026-07-14 20:13:00.000000000 +0200 @@ -1,2 +1,3 @@ 0000000000000000000000000000000000000000 ab15063b7cda53f8d4074f8f539a37935d254164 Marcus Rückert <[email protected]> 1783537343 +0200 pull: storing head ab15063b7cda53f8d4074f8f539a37935d254164 6412cfc2e738578c4d060e7fb7e25eed02c5cb9f Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +6412cfc2e738578c4d060e7fb7e25eed02c5cb9f 51bbe704dca7a1f21c51c50f4a8564afb7ee0116 Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed 2026-07-14 20:13:00.000000000 +0200 @@ -3,3 +3,4 @@ 3d59ab9730ba0c2662901eab4c947e4dcfda0474 a721675b11767b2771121760ae2dbdc00e67e300 Marcus Rückert <[email protected]> 1783104333 +0200 pull: forced-update a721675b11767b2771121760ae2dbdc00e67e300 42bdc885bf94e11c7fa2210095afcf8f46ace96c Marcus Rückert <[email protected]> 1783537343 +0200 pull: forced-update 42bdc885bf94e11c7fa2210095afcf8f46ace96c 3b0d193beb49894f2aacf0f2c8dc55ab4e330ac2 Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +3b0d193beb49894f2aacf0f2c8dc55ab4e330ac2 a8072f26d1390aab67af45cf5acdc60e552bbe34 Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b 2026-07-14 20:13:00.000000000 +0200 @@ -9,3 +9,4 @@ 1d7a2a5ace003824e2cea472b9c815f901b0c15c d77d78720c57ac6e1ae613f1f171bc9911e45549 Marcus Rückert <[email protected]> 1783104333 +0200 pull: forced-update d77d78720c57ac6e1ae613f1f171bc9911e45549 5cb92bc0ba6f7ee0171efd0388d64e372e1624bd Marcus Rückert <[email protected]> 1783537343 +0200 pull: forced-update 5cb92bc0ba6f7ee0171efd0388d64e372e1624bd 0f8dcacde5efcd41a0429879820276bd4908d979 Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +0f8dcacde5efcd41a0429879820276bd4908d979 0a6aedd99547133cf38f71a6612782c813ae0222 Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd 2026-07-14 20:13:00.000000000 +0200 @@ -9,3 +9,4 @@ 92a949ef5a935af8485de0361c32a682a9c06770 94e6c40446f8ba80930319cd25fbf15d554272a7 Marcus Rückert <[email protected]> 1783104333 +0200 pull: forced-update 94e6c40446f8ba80930319cd25fbf15d554272a7 0cc6cab8ea7f52499df19c9ee7db70a746490876 Marcus Rückert <[email protected]> 1783537343 +0200 pull: forced-update 0cc6cab8ea7f52499df19c9ee7db70a746490876 2d095a415dc88bc85aaf77b86caf85ee18482974 Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +2d095a415dc88bc85aaf77b86caf85ee18482974 c067346459b74dc01ef0957301e2688ac03dd314 Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca 2026-07-14 20:13:00.000000000 +0200 @@ -3,3 +3,4 @@ d8e98f4fb51f476cccbe0e771ea0041954b0bd5d 5a2660e796bf697dd0c00c09bc0c2338e93c4695 Marcus Rückert <[email protected]> 1783104333 +0200 pull: forced-update 5a2660e796bf697dd0c00c09bc0c2338e93c4695 6d792269cbc7724adbfaca7607d6c96c7c58ce95 Marcus Rückert <[email protected]> 1783537343 +0200 pull: forced-update 6d792269cbc7724adbfaca7607d6c96c7c58ce95 ac56ddad9c1e368d11d530b1ab5ef20290e6238a Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +ac56ddad9c1e368d11d530b1ab5ef20290e6238a d6aef0d65e115208d06a7d37f3ab8de75df1b587 Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 2026-07-14 20:13:00.000000000 +0200 @@ -3,3 +3,4 @@ f14100f1ab2a1a502a7bfd3b19af6ff6bb8faf1f 75ac15c52e36877590418a260f31880b75a412a9 Marcus Rückert <[email protected]> 1783104333 +0200 pull: forced-update 75ac15c52e36877590418a260f31880b75a412a9 19b40b509a22fdaeb25880f6b01acf5c0170757d Marcus Rückert <[email protected]> 1783537343 +0200 pull: forced-update 19b40b509a22fdaeb25880f6b01acf5c0170757d 7e75e57bee00f2911a4464f8fc40442d0264e791 Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +7e75e57bee00f2911a4464f8fc40442d0264e791 db2bec30c43551af0e127c3fc68fe2060e075ca3 Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 2026-07-14 20:13:00.000000000 +0200 @@ -9,3 +9,4 @@ af04a89eee82e2b02bd4ae09d41677b89426cd28 479a88ca9f58cdd095beb7d05bcc393d3d1b7cb1 Marcus Rückert <[email protected]> 1783104333 +0200 pull: forced-update 479a88ca9f58cdd095beb7d05bcc393d3d1b7cb1 d7aa9e97852e8b77592a598e5e4791501ec26e31 Marcus Rückert <[email protected]> 1783537343 +0200 pull: forced-update d7aa9e97852e8b77592a598e5e4791501ec26e31 16195b7eb75da8aaf49cab91b03a4e1118c9b3bf Marcus Rückert <[email protected]> 1783772549 +0200 pull: forced-update +16195b7eb75da8aaf49cab91b03a4e1118c9b3bf bc1d7f43b141d87169f09cd63607dc12b11b064b Marcus Rückert <[email protected]> 1784064464 +0200 pull: forced-update diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/embedded-vnc new/netbird-0.74.5/.git/logs/refs/remotes/origin/embedded-vnc --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/embedded-vnc 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/embedded-vnc 2026-07-14 20:13:00.000000000 +0200 @@ -5,3 +5,4 @@ 144dfbc12c09333bb0c912c4678e2f518362a219 f2c79201b314de93f5b7a8b5ab1fe36ec56c5b91 Marcus Rückert <[email protected]> 1781122574 +0200 pull: fast-forward f2c79201b314de93f5b7a8b5ab1fe36ec56c5b91 c1eecaac26458f5b1591c6e9bfa937e8f6821d3a Marcus Rückert <[email protected]> 1781803432 +0200 pull: fast-forward c1eecaac26458f5b1591c6e9bfa937e8f6821d3a fd7bf982c3b16bac8c4d066e9ad121bb12f8ca60 Marcus Rückert <[email protected]> 1782940252 +0200 pull: fast-forward +fd7bf982c3b16bac8c4d066e9ad121bb12f8ca60 152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0 Marcus Rückert <[email protected]> 1784064464 +0200 pull: fast-forward diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup new/netbird-0.74.5/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 03252696b95abb7df8707eac056242153482b3bc Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn 1970-01-01 01:00:00.000000000 +0100 @@ -1 +0,0 @@ -0000000000000000000000000000000000000000 8732d3cd139b04c4d0e101d45e9482397186b7b1 Marcus Rückert <[email protected]> 1783537343 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 efad9075e77d034c8a21567dc01d1de90f8bc367 Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 cdde472266fddbf3e18df7e35673eda067f51c69 Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 525a4fb29c43d405b5c50a0081599c8f3ab8d804 Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 8e387b5dc5afebefc40abba2d80303be2c7f6eeb Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-per-peer new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-per-peer --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-per-peer 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-per-peer 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 99ceb9b7a0c72e5beb94aab9250821080ba4527f Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-rosenpass new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-rosenpass --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-rosenpass 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-rosenpass 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 d438db50012b7abeeda0829c373abb0a41f0306e Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/main new/netbird-0.74.5/.git/logs/refs/remotes/origin/main --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/main 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/main 2026-07-14 20:13:00.000000000 +0200 @@ -33,3 +33,4 @@ 1dfa85a917eb47e23e4dc4c142056e67966a1c03 3aa6c02b932db503e82f9530dddfe95d5ea212c4 Marcus Rückert <[email protected]> 1783104333 +0200 pull: fast-forward 3aa6c02b932db503e82f9530dddfe95d5ea212c4 488bbcb22bea59f01f3665b528f650d17bce7982 Marcus Rückert <[email protected]> 1783537343 +0200 pull: fast-forward 488bbcb22bea59f01f3665b528f650d17bce7982 30d15ecc3d9bf69161f8a8eda597acb78a29b602 Marcus Rückert <[email protected]> 1783772549 +0200 pull: fast-forward +30d15ecc3d9bf69161f8a8eda597acb78a29b602 c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3 Marcus Rückert <[email protected]> 1784064464 +0200 pull: fast-forward diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/refactor/peer-event-bus new/netbird-0.74.5/.git/logs/refs/remotes/origin/refactor/peer-event-bus --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/refactor/peer-event-bus 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/refactor/peer-event-bus 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0000000000000000000000000000000000000000 753925032ab2b604abafc90eadebb44ef16e9e38 Marcus Rückert <[email protected]> 1784064464 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/wg_watcher_debounce new/netbird-0.74.5/.git/logs/refs/remotes/origin/wg_watcher_debounce --- old/netbird-0.74.4/.git/logs/refs/remotes/origin/wg_watcher_debounce 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/wg_watcher_debounce 1970-01-01 01:00:00.000000000 +0100 @@ -1 +0,0 @@ -0000000000000000000000000000000000000000 5740dd22e6c0ce4d5a27504685bc61709f23be20 Marcus Rückert <[email protected]> 1783104333 +0200 pull: storing head diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/objects/info/commit-graphs/commit-graph-chain new/netbird-0.74.5/.git/objects/info/commit-graphs/commit-graph-chain --- old/netbird-0.74.4/.git/objects/info/commit-graphs/commit-graph-chain 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/objects/info/commit-graphs/commit-graph-chain 2026-07-14 20:13:00.000000000 +0200 @@ -1,4 +1,4 @@ fdfa54f7b964ac9dc39761797c2fb0dfebb92f6e 21e341b3c265ad9526898e416d4ab365d5ded8d1 a6642bf4d8a835abc8fa2628838fb66da11b1ea9 -e937f7d3915de101583115ea91c75d659dcf99d2 +2532b695a7ed4462efc610f179dcbc0b23f2b1f3 Binary files old/netbird-0.74.4/.git/objects/info/commit-graphs/graph-2532b695a7ed4462efc610f179dcbc0b23f2b1f3.graph and new/netbird-0.74.5/.git/objects/info/commit-graphs/graph-2532b695a7ed4462efc610f179dcbc0b23f2b1f3.graph differ Binary files old/netbird-0.74.4/.git/objects/info/commit-graphs/graph-e937f7d3915de101583115ea91c75d659dcf99d2.graph and new/netbird-0.74.5/.git/objects/info/commit-graphs/graph-e937f7d3915de101583115ea91c75d659dcf99d2.graph differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.idx and new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.idx differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.pack and new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.pack differ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor --- old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +ef43882de764d6d54f7b819d70f32578c10d7776 ef43882de764d6d54f7b819d70f32578c10d7776 Binary files old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.rev and new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.rev differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.idx and new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.idx differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.pack and new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.pack differ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor --- old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1,20 @@ +f0eed7564f3a9138962da1408986e4666d7137b5 refs/heads/0.74.4-branch +671a5f11fdefe35b39700a1bc43925f8e8ff6dff refs/heads/components-impl-drop-indexes-use-xids +51bbe704dca7a1f21c51c50f4a8564afb7ee0116 refs/heads/dependabot/github_actions/actions-a940c7c866 +a8072f26d1390aab67af45cf5acdc60e552bbe34 refs/heads/dependabot/go_modules/aws-sdk-8f849ebaed +0a6aedd99547133cf38f71a6612782c813ae0222 refs/heads/dependabot/go_modules/gorm-2271c8195b +c067346459b74dc01ef0957301e2688ac03dd314 refs/heads/dependabot/go_modules/otel-e34c790afd +d6aef0d65e115208d06a7d37f3ab8de75df1b587 refs/heads/dependabot/go_modules/pion-5f703e1eca +db2bec30c43551af0e127c3fc68fe2060e075ca3 refs/heads/dependabot/go_modules/testcontainers-de325c0dd6 +bc1d7f43b141d87169f09cd63607dc12b11b064b refs/heads/dependabot/go_modules/wireguard-dbd6b95108 +152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0 refs/heads/embedded-vnc +03252696b95abb7df8707eac056242153482b3bc refs/heads/feature/dns-lazy-conn-warmup +8e387b5dc5afebefc40abba2d80303be2c7f6eeb refs/heads/fix-browser-dialog-not-closing +efad9075e77d034c8a21567dc01d1de90f8bc367 refs/heads/fix/nsis-preserve-autostart-on-upgrade +cdde472266fddbf3e18df7e35673eda067f51c69 refs/heads/fix/remove-stale-peers-removal +525a4fb29c43d405b5c50a0081599c8f3ab8d804 refs/heads/fix/remove-stale-proxy-logic +99ceb9b7a0c72e5beb94aab9250821080ba4527f refs/heads/lazy-conn-per-peer +d438db50012b7abeeda0829c373abb0a41f0306e refs/heads/lazy-conn-rosenpass +c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3 refs/heads/main +753925032ab2b604abafc90eadebb44ef16e9e38 refs/heads/refactor/peer-event-bus +f0eed7564f3a9138962da1408986e4666d7137b5 refs/tags/v0.74.5 Binary files old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.rev and new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.rev differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.idx and new/netbird-0.74.5/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.idx differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.pack and new/netbird-0.74.5/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.pack differ Binary files old/netbird-0.74.4/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.rev and new/netbird-0.74.5/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.rev differ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/packed-refs new/netbird-0.74.5/.git/packed-refs --- old/netbird-0.74.4/.git/packed-refs 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/.git/packed-refs 2026-07-14 20:13:00.000000000 +0200 @@ -216,7 +216,6 @@ 56d82a99e15b0e88f4b102725b859210136d0a40 refs/remotes/origin/fix/events-key-handling 59a09b0ff30470577deaa3383e3f70dcfcf6c90e refs/remotes/origin/fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall 5a4d3770660460620dd25649593f9c74fca869c8 refs/remotes/origin/fix/filter-cgnat-cni-ice-candidates -8732d3cd139b04c4d0e101d45e9482397186b7b1 refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn 1e630b5d45bfd5fd9fadc776f522de2fc39a0ccf refs/remotes/origin/fix/geo-download e32ad68f98eb19e9b9ec0adb42d4840bd728e8cc refs/remotes/origin/fix/getting-started cbb9f9f56275b6f6c7ac343acd4dbb5b7f77a065 refs/remotes/origin/fix/go-mod-version @@ -438,7 +437,6 @@ 485a38a4a86b595bbc3afc2973610d1c61f6c8fe refs/remotes/origin/wasmbuild-test 940367e1c64cb6ebe280c8e35bf182ce6fed4d3a refs/remotes/origin/wg_bind_parallel_processing d66b425bb674eb69050d27d45a72db049db3de34 refs/remotes/origin/wg_conn_fix -5740dd22e6c0ce4d5a27504685bc61709f23be20 refs/remotes/origin/wg_watcher_debounce dd13b8f27eabb649952754071e5165515887d3ee refs/remotes/origin/wgwatcher-test 9157b749459ad64620c36178fb26eac40e9ca805 refs/remotes/origin/windows-dns-firewall e3d1b9ca880ff4f1e6624e306b6957aa6c30e5c1 refs/remotes/origin/windows-search-domains diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/0.74.4-branch new/netbird-0.74.5/.git/refs/remotes/origin/0.74.4-branch --- old/netbird-0.74.4/.git/refs/remotes/origin/0.74.4-branch 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/0.74.4-branch 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +f0eed7564f3a9138962da1408986e4666d7137b5 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids new/netbird-0.74.5/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids --- old/netbird-0.74.4/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +671a5f11fdefe35b39700a1bc43925f8e8ff6dff diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +51bbe704dca7a1f21c51c50f4a8564afb7ee0116 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +a8072f26d1390aab67af45cf5acdc60e552bbe34 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +0a6aedd99547133cf38f71a6612782c813ae0222 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +c067346459b74dc01ef0957301e2688ac03dd314 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +d6aef0d65e115208d06a7d37f3ab8de75df1b587 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +db2bec30c43551af0e127c3fc68fe2060e075ca3 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 --- old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +bc1d7f43b141d87169f09cd63607dc12b11b064b diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/embedded-vnc new/netbird-0.74.5/.git/refs/remotes/origin/embedded-vnc --- old/netbird-0.74.4/.git/refs/remotes/origin/embedded-vnc 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/embedded-vnc 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup new/netbird-0.74.5/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup --- old/netbird-0.74.4/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +03252696b95abb7df8707eac056242153482b3bc diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade new/netbird-0.74.5/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade --- old/netbird-0.74.4/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +efad9075e77d034c8a21567dc01d1de90f8bc367 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-peers-removal new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-peers-removal --- old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-peers-removal 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-peers-removal 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +cdde472266fddbf3e18df7e35673eda067f51c69 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-proxy-logic new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-proxy-logic --- old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-proxy-logic 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-proxy-logic 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +525a4fb29c43d405b5c50a0081599c8f3ab8d804 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/fix-browser-dialog-not-closing new/netbird-0.74.5/.git/refs/remotes/origin/fix-browser-dialog-not-closing --- old/netbird-0.74.4/.git/refs/remotes/origin/fix-browser-dialog-not-closing 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/fix-browser-dialog-not-closing 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +8e387b5dc5afebefc40abba2d80303be2c7f6eeb diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-per-peer new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-per-peer --- old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-per-peer 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-per-peer 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +99ceb9b7a0c72e5beb94aab9250821080ba4527f diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-rosenpass new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-rosenpass --- old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-rosenpass 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-rosenpass 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +d438db50012b7abeeda0829c373abb0a41f0306e diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/main new/netbird-0.74.5/.git/refs/remotes/origin/main --- old/netbird-0.74.4/.git/refs/remotes/origin/main 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/main 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/refactor/peer-event-bus new/netbird-0.74.5/.git/refs/remotes/origin/refactor/peer-event-bus --- old/netbird-0.74.4/.git/refs/remotes/origin/refactor/peer-event-bus 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/remotes/origin/refactor/peer-event-bus 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +753925032ab2b604abafc90eadebb44ef16e9e38 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/tags/v0.74.5 new/netbird-0.74.5/.git/refs/tags/v0.74.5 --- old/netbird-0.74.4/.git/refs/tags/v0.74.5 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/tags/v0.74.5 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +f0eed7564f3a9138962da1408986e4666d7137b5 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/.git/refs/tags/v0.75.0-rc.6 new/netbird-0.74.5/.git/refs/tags/v0.75.0-rc.6 --- old/netbird-0.74.4/.git/refs/tags/v0.75.0-rc.6 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/.git/refs/tags/v0.75.0-rc.6 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1 @@ +62703ca23e97073869bb723b64a0f738c465d93b diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/e2e/agentnetwork/chat_test.go new/netbird-0.74.5/e2e/agentnetwork/chat_test.go --- old/netbird-0.74.4/e2e/agentnetwork/chat_test.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/e2e/agentnetwork/chat_test.go 2026-07-14 20:13:00.000000000 +0200 @@ -91,7 +91,7 @@ if region == "" { region = "us-east-1" } - ps = append(ps, providerCase{name: "bedrock", catalogID: "bedrock_api", upstream: "https://bedrock-runtime." + region + ".amazonaws.com", apiKey: k, model: "us.anthropic.claude-haiku-4-5", kind: harness.WireMessages}) + ps = append(ps, providerCase{name: "bedrock", catalogID: "bedrock_api", upstream: "https://bedrock-runtime." + region + ".amazonaws.com", apiKey: k, model: "us.anthropic.claude-haiku-4-5", kind: harness.WireBedrock}) } return ps } @@ -224,9 +224,12 @@ var c int var b string var cerr error - if pc.kind == harness.WireVertex { + switch pc.kind { + case harness.WireVertex: c, b, cerr = cl.Vertex(ctx, settings.Endpoint, proxyIP, pc.project, pc.region, pc.model, "Reply with exactly: pong", sessionID) - } else { + case harness.WireBedrock: + c, b, cerr = cl.Bedrock(ctx, settings.Endpoint, proxyIP, pc.model, "Reply with exactly: pong", sessionID) + default: c, b, cerr = cl.Chat(ctx, settings.Endpoint, proxyIP, pc.kind, pc.model, "Reply with exactly: pong", sessionID) } if cerr == nil { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/e2e/agentnetwork/guardrail_test.go new/netbird-0.74.5/e2e/agentnetwork/guardrail_test.go --- old/netbird-0.74.4/e2e/agentnetwork/guardrail_test.go 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/e2e/agentnetwork/guardrail_test.go 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1,168 @@ +//go:build e2e + +package agentnetwork + +import ( + "context" + "strings" + "testing" + "time" + + "github.com/stretchr/testify/assert" + "github.com/stretchr/testify/require" + + "github.com/netbirdio/netbird/e2e/harness" + "github.com/netbirdio/netbird/shared/management/http/api" +) + +// catalogModel returns the normalized catalog id the proxy stamps for a +// path-routed provider's configured model — the form the guardrail allowlist is +// compared against (region prefix / @version stripped). +func catalogModel(pc providerCase) string { + switch pc.kind { + case harness.WireBedrock: + return strings.TrimPrefix(pc.model, "us.") + case harness.WireVertex: + return strings.SplitN(pc.model, "@", 2)[0] + default: + return pc.model + } +} + +// disallowedModel returns a valid-shaped model id for the provider that is NOT +// the configured/allowed one, so the guardrail must reject it before the +// request ever reaches the upstream. +func disallowedModel(pc providerCase) string { + switch pc.kind { + case harness.WireBedrock: + return "us.anthropic.claude-opus-4-8" + case harness.WireVertex: + return "claude-opus-4-8@20250101" + default: + return "unlisted-model" + } +} + +// sendModel drives one request for the given model through the provider's native +// wire shape and returns the HTTP status. +func sendModel(ctx context.Context, t *testing.T, cl *harness.Client, endpoint, proxyIP string, pc providerCase, model string) int { + t.Helper() + var code int + var err error + switch pc.kind { + case harness.WireBedrock: + code, _, err = cl.Bedrock(ctx, endpoint, proxyIP, model, "Reply with exactly: pong", "") + case harness.WireVertex: + code, _, err = cl.Vertex(ctx, endpoint, proxyIP, pc.project, pc.region, model, "Reply with exactly: pong", "") + default: + code, _, err = cl.Chat(ctx, endpoint, proxyIP, pc.kind, model, "Reply with exactly: pong", "") + } + require.NoError(t, err, "request must reach the proxy for %s", pc.name) + return code +} + +// TestModelAllowlistEnforced provisions a Model Allowlist guardrail limiting each +// path-routed provider (Bedrock, Vertex) to its configured model, then drives +// requests over the tunnel: the allowed model returns 200 while a model outside +// the allowlist is denied 403 by the guardrail before it reaches the upstream. +// This is the coverage missing for #6751 — the model for these providers travels +// in the URL path, and the allowlist must be enforced there. +func TestModelAllowlistEnforced(t *testing.T) { + var providers []providerCase + for _, pc := range availableProviders() { + if pc.kind == harness.WireBedrock || pc.kind == harness.WireVertex { + providers = append(providers, pc) + } + } + if len(providers) == 0 { + t.Skip("no path-routed provider keys set (AWS_BEARER_TOKEN_BEDROCK / GOOGLE_VERTEX_*); source ~/.llm-keys") + } + + ctx, cancel := context.WithTimeout(context.Background(), 20*time.Minute) + defer cancel() + + grp, err := srv.API().Groups.Create(ctx, api.PostApiGroupsJSONRequestBody{Name: "e2e-allowlist"}) + require.NoError(t, err, "create group") + t.Cleanup(func() { _ = srv.API().Groups.Delete(context.Background(), grp.Id) }) + + ephemeral := false + sk, err := srv.API().SetupKeys.Create(ctx, api.PostApiSetupKeysJSONRequestBody{ + Name: "e2e-allowlist-client", + Type: "reusable", + ExpiresIn: 86400, + UsageLimit: 0, + AutoGroups: []string{grp.Id}, + Ephemeral: &ephemeral, + }) + require.NoError(t, err, "mint setup key") + + // Providers with their configured (allowed) models; the first bootstraps the cluster. + ids := make([]string, 0, len(providers)) + allowed := make([]string, 0, len(providers)) + for i, pc := range providers { + req := providerRequest(pc) + if i == 0 { + req.BootstrapCluster = ptr(harness.AgentNetworkCluster) + } + prov, perr := srv.CreateProvider(ctx, req) + require.NoError(t, perr, "create provider %s", pc.name) + id := prov.Id + ids = append(ids, id) + allowed = append(allowed, catalogModel(pc)) + t.Cleanup(func() { _ = srv.DeleteProvider(context.Background(), id) }) + } + + // Guardrail allowlisting exactly the configured models. + var gr api.AgentNetworkGuardrailRequest + gr.Name = "e2e-allowlist" + gr.Checks.ModelAllowlist.Enabled = true + gr.Checks.ModelAllowlist.Models = allowed + guard, err := srv.CreateGuardrail(ctx, gr) + require.NoError(t, err, "create guardrail") + t.Cleanup(func() { _ = srv.DeleteGuardrail(context.Background(), guard.Id) }) + + enabled := true + pol, err := srv.CreatePolicy(ctx, api.AgentNetworkPolicyRequest{ + Name: "e2e-allowlist", + Enabled: &enabled, + SourceGroups: []string{grp.Id}, + DestinationProviderIds: ids, + GuardrailIds: &[]string{guard.Id}, + }) + require.NoError(t, err, "create policy") + t.Cleanup(func() { _ = srv.DeletePolicy(context.Background(), pol.Id) }) + + settings, err := srv.GetSettings(ctx) + require.NoError(t, err, "read settings for endpoint") + require.NotEmpty(t, settings.Endpoint, "agent-network endpoint must be assigned") + + proxyToken, err := srv.CreateProxyTokenCLI(ctx, "e2e-proxy-allowlist") + require.NoError(t, err, "mint proxy token via CLI") + px, err := harness.StartProxy(ctx, srv, proxyToken) + require.NoError(t, err, "start proxy") + t.Cleanup(func() { _ = px.Terminate(context.Background()) }) + + cl, err := harness.StartClient(ctx, srv, sk.Key) + require.NoError(t, err, "start client") + t.Cleanup(func() { _ = cl.Terminate(context.Background()) }) + + require.NoError(t, cl.WaitConnected(ctx, 90*time.Second), "client must connect to management") + if err := cl.WaitProxyPeer(ctx, 180*time.Second); err != nil { + t.Fatalf("client did not see the proxy peer: %v\n=== proxy logs ===\n%s", err, px.Logs(context.Background())) + } + proxyIP, err := cl.ResolveProxyIP(ctx, settings.Endpoint) + require.NoError(t, err, "resolve agent-network endpoint to proxy IP") + + for _, pc := range providers { + pc := pc + t.Run(pc.name, func(t *testing.T) { + // The admin's allowlisted model is served end to end. + assert.Equal(t, 200, sendModel(ctx, t, cl, settings.Endpoint, proxyIP, pc, pc.model), + "allowlisted model must be permitted for %s", pc.name) + // A model outside the allowlist is rejected by the guardrail (before + // the upstream), regardless of whether it is a real catalog model. + assert.Equal(t, 403, sendModel(ctx, t, cl, settings.Endpoint, proxyIP, pc, disallowedModel(pc)), + "model outside the allowlist must be denied for %s", pc.name) + }) + } +} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/e2e/harness/agentnetwork.go new/netbird-0.74.5/e2e/harness/agentnetwork.go --- old/netbird-0.74.4/e2e/harness/agentnetwork.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/e2e/harness/agentnetwork.go 2026-07-14 20:13:00.000000000 +0200 @@ -107,6 +107,17 @@ return anDelete(ctx, c, "/api/agent-network/policies/"+id) } +// CreateGuardrail creates an agent-network guardrail (e.g. a model allowlist) +// that can then be attached to a policy via its GuardrailIds. +func (c *Combined) CreateGuardrail(ctx context.Context, req api.AgentNetworkGuardrailRequest) (api.AgentNetworkGuardrail, error) { + return anRequest[api.AgentNetworkGuardrail](ctx, c, http.MethodPost, "/api/agent-network/guardrails", req) +} + +// DeleteGuardrail removes a guardrail by id. +func (c *Combined) DeleteGuardrail(ctx context.Context, id string) error { + return anDelete(ctx, c, "/api/agent-network/guardrails/"+id) +} + // GetSettings returns the account's agent-network settings row. It exists only // after the first provider create bootstraps it. func (c *Combined) GetSettings(ctx context.Context) (api.AgentNetworkSettings, error) { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/e2e/harness/client.go new/netbird-0.74.5/e2e/harness/client.go --- old/netbird-0.74.4/e2e/harness/client.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/e2e/harness/client.go 2026-07-14 20:13:00.000000000 +0200 @@ -194,6 +194,11 @@ // WireVertex is the Anthropic-on-Vertex rawPredict shape: the client posts // the full Vertex model path and the proxy mints the SA OAuth token. WireVertex = "vertex" + // WireBedrock is the native AWS Bedrock InvokeModel shape: the model id + // travels in the URL path (/model/{id}/invoke), not the body, so the proxy + // routes by path. This is what a Bedrock SDK client sends and the shape the + // model-allowlist guardrail must enforce. + WireBedrock = "bedrock" ) // Chat issues a chat-completion POST to the agent-network endpoint over the @@ -226,6 +231,17 @@ return cl.post(ctx, endpoint, proxyIP, path, body, withSessionID(nil, sessionID)) } +// Bedrock issues a native AWS Bedrock InvokeModel POST over the tunnel. The +// model id is carried in the request path (/model/{id}/invoke), so the proxy +// routes by path; the body uses the bedrock anthropic_version rather than a +// model field. A non-empty sessionID is sent as the universal x-session-id +// header the proxy records. +func (cl *Client) Bedrock(ctx context.Context, endpoint, proxyIP, model, prompt, sessionID string) (int, string, error) { + path := "/model/" + model + "/invoke" + body := fmt.Sprintf(`{"anthropic_version":"bedrock-2023-05-31","max_tokens":64,"messages":[{"role":"user","content":%q}]}`, prompt) + return cl.post(ctx, endpoint, proxyIP, path, body, withSessionID(nil, sessionID)) +} + // withSessionID appends the x-session-id header when sessionID is non-empty. func withSessionID(headers []string, sessionID string) []string { if sessionID == "" { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/management/internals/modules/peers/manager.go new/netbird-0.74.5/management/internals/modules/peers/manager.go --- old/netbird-0.74.4/management/internals/modules/peers/manager.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/management/internals/modules/peers/manager.go 2026-07-14 20:13:00.000000000 +0200 @@ -224,30 +224,6 @@ return nil } - // Dedupe stale embedded peer records for the same (account, cluster). - // The proxy generates a fresh WireGuard keypair on every startup - // (proxy/internal/roundtrip/netbird.go), so without this sweep the - // prior embedded peer would linger forever — holding its CGNAT IP - // allocation, polluting other peers' rosters, and (most visibly) - // leaving the synth DNS pointing at the dead address. The - // (account, cluster) tuple identifies "the embedded peer for this - // proxy instance at this cluster"; any record matching that tuple - // with a different pubkey is by definition stale and must go. - staleIDs, err := m.findStaleEmbeddedProxyPeers(ctx, accountID, cluster, peerKey) - if err != nil { - return fmt.Errorf("scan for stale embedded proxy peers: %w", err) - } - if len(staleIDs) > 0 { - // userID="" + checkConnected=false: the deletion is initiated - // by management itself on behalf of the freshly-registering - // proxy, not by an end user; the stale peer may still be - // marked Connected from its prior session, but its session is - // dead by definition (its key no longer exists). - if err := m.DeletePeers(ctx, accountID, staleIDs, "", false); err != nil { - return fmt.Errorf("delete stale embedded proxy peers %v: %w", staleIDs, err) - } - } - name := fmt.Sprintf("proxy-%s", xid.New().String()) newPeer := &peer.Peer{ Ephemeral: true, @@ -273,29 +249,3 @@ return nil } - -// findStaleEmbeddedProxyPeers returns the peer IDs of embedded proxy peer -// records in accountID that target the same cluster but carry a different -// WireGuard pubkey than the freshly-registering one. Used by CreateProxyPeer -// to garbage-collect stale records left behind when the proxy restarts with a -// regenerated keypair. -func (m *managerImpl) findStaleEmbeddedProxyPeers(ctx context.Context, accountID, cluster, newKey string) ([]string, error) { - account, err := m.store.GetAccount(ctx, accountID) - if err != nil { - return nil, err - } - var stale []string - for _, p := range account.Peers { - if p == nil || !p.ProxyMeta.Embedded { - continue - } - if p.ProxyMeta.Cluster != cluster { - continue - } - if p.Key == newKey { - continue - } - stale = append(stale, p.ID) - } - return stale, nil -} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/management/server/agentnetwork_proxypeer_restart_test.go new/netbird-0.74.5/management/server/agentnetwork_proxypeer_restart_test.go --- old/netbird-0.74.4/management/server/agentnetwork_proxypeer_restart_test.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/management/server/agentnetwork_proxypeer_restart_test.go 1970-01-01 01:00:00.000000000 +0100 @@ -1,199 +0,0 @@ -package server - -import ( - "context" - "testing" - "time" - - "github.com/stretchr/testify/assert" - "github.com/stretchr/testify/require" - - "github.com/netbirdio/netbird/management/internals/modules/peers" - "github.com/netbirdio/netbird/management/internals/modules/agentnetwork" - agenttypes "github.com/netbirdio/netbird/management/internals/modules/agentnetwork/types" - nbpeer "github.com/netbirdio/netbird/management/server/peer" - "github.com/netbirdio/netbird/management/server/permissions" - "github.com/netbirdio/netbird/management/server/store" - "github.com/netbirdio/netbird/management/server/types" -) - -// TestAgentNetwork_ProxyRestart_PropagatesNewPeerAndDropsStale is the no-mock -// regression guard for the bug the user reported: restarting the proxy creates -// a fresh embedded peer with a NEW WireGuard public key (the proxy generates -// the keypair on every startup at proxy/internal/roundtrip/netbird.go:312). -// The PRIOR embedded peer record is never deleted on management, so the -// account accumulates a stale peer holding a stale CGNAT IP. Other peers -// in the account either keep routing to the dead IP, or — if synth DNS -// picks the wrong record — never see the new IP at all. -// -// What this test exercises (no mocks): -// - real SQLite test store -// - real DefaultAccountManager, network-map controller, peer-update channels -// - real peers.Manager.CreateProxyPeer path (the very method the proxy -// invokes over gRPC on every startup) -// - real agentnetwork.Manager + synth chain so the client receives a -// concrete DNS record that must point at the LATEST proxy peer. -// -// Pre-fix expected behavior (red): two embedded peers exist after the -// "restart"; the synth DNS record points at the stale one; the client -// receives an update reflecting the new peer but the old one lingers. -// Post-fix expected behavior (green): exactly one embedded peer exists -// after restart (with the new key) AND the client's network map carries -// the synth DNS pointing at that new peer's CGNAT IP. -func TestAgentNetwork_ProxyRestart_PropagatesNewPeerAndDropsStale(t *testing.T) { - am, updateManager, err := createManager(t) - require.NoError(t, err, "createManager must succeed") - ctx := context.Background() - - const ( - accountID = "an-restart-acct" - adminUserID = "an-restart-admin" - groupAID = "an-restart-grp-A" - clusterAddr = "eu.proxy.netbird.io" - clientKey = "BhRPtynAAYRDy08+q4HTMsos8fs4plTP4NOSh7C1ry8=" - // Two different proxy pubkeys — the "before" and "after" of a - // proxy-process restart with fresh-keypair generation. - proxyKey1 = "Aaaaa1aaaaYRDy08+q4HTMsos8fs4plTP4NOSh7C1ry8=" - proxyKey2 = "Bbbbb2bbbbYRDy08+q4HTMsos8fs4plTP4NOSh7C1ry8=" - ) - - // --- Account scaffold --- - account := newAccountWithId(ctx, accountID, adminUserID, "an-restart.test", "", "", false) - require.NoError(t, am.Store.SaveAccount(ctx, account)) - - clientPeer := &nbpeer.Peer{ - Key: clientKey, - Name: "an-restart-client", - DNSLabel: "an-restart-client", - Meta: nbpeer.PeerSystemMeta{Hostname: "an-restart-client", GoOS: "linux", WtVersion: "development"}, - } - addedClient, _, _, _, err := am.AddPeer(ctx, "", "", adminUserID, clientPeer, false) - require.NoError(t, err, "AddPeer for client must succeed") - require.NoError(t, am.MarkPeerConnected(ctx, clientKey, accountID, time.Now().UnixNano(), &types.NetworkMap{}), - "MarkPeerConnected for the client peer must succeed (affected-peer fan-out skips disconnected peers)") - - // Place the client in group A so the synth policy reaches it. - account, err = am.Store.GetAccount(ctx, accountID) - require.NoError(t, err) - account.Groups[groupAID] = &types.Group{ID: groupAID, Name: "groupA", Peers: []string{addedClient.ID}} - require.NoError(t, am.Store.SaveAccount(ctx, account), "SaveAccount must persist group A") - - // --- Real peers + agent-network managers --- - permMgr := permissions.NewManager(am.Store) - peersMgr := peers.NewManager(am.Store, permMgr) - peersMgr.SetAccountManager(am) - peersMgr.SetNetworkMapController(am.networkMapController) - agentMgr := agentnetwork.NewManager(am.Store, permMgr, am, nil) - - // Subscribe BEFORE any state-mutating call so we don't lose the update - // that contains the synth DNS record. - clientCh := updateManager.CreateChannel(ctx, addedClient.ID) - t.Cleanup(func() { updateManager.CloseChannel(ctx, addedClient.ID) }) - drain(clientCh) - - // --- First proxy startup: register peer key K1, then mark it - // connected. In production the proxy follows CreateProxyPeer with the - // regular sync stream which lands on MarkPeerConnected; the synth DNS - // path filters out peers that aren't Connected (types/account.go:323), - // so without this step no DNS record would be emitted. - require.NoError(t, peersMgr.CreateProxyPeer(ctx, accountID, proxyKey1, clusterAddr), - "first CreateProxyPeer (proxy startup) must succeed") - - peer1ID, err := am.Store.GetPeerIDByKey(ctx, store.LockingStrengthNone, proxyKey1) - require.NoError(t, err, "proxy peer for K1 must be persisted after CreateProxyPeer") - require.NotEmpty(t, peer1ID) - - require.NoError(t, am.MarkPeerConnected(ctx, proxyKey1, accountID, time.Now().UnixNano(), &types.NetworkMap{}), - "MarkPeerConnected for K1 must succeed") - - account, err = am.Store.GetAccount(ctx, accountID) - require.NoError(t, err) - proxyIP1 := account.Peers[peer1ID].IP.String() - require.NotEmpty(t, proxyIP1, "K1 must have an assigned overlay IP") - - // --- Provider + policy. CreateProvider / CreatePolicy trigger the - // agentnetwork reconcile which runs UpdateAccountPeers; the resulting - // NetworkMap delivered to the client carries the synth DNS record - // pointing at K1's IP. --- - provider, err := agentMgr.CreateProvider(ctx, adminUserID, &agenttypes.Provider{ - AccountID: accountID, - ProviderID: "openai_api", - Name: "openai-test", - UpstreamURL: "https://api.openai.com", - APIKey: "sk-test-key", - Enabled: true, - Models: []agenttypes.ProviderModel{{ID: "gpt-5.4"}}, - }, clusterAddr) - require.NoError(t, err, "CreateProvider must succeed") - - _, err = agentMgr.CreatePolicy(ctx, adminUserID, &agenttypes.Policy{ - AccountID: accountID, - Name: "p1", - Enabled: true, - SourceGroups: []string{groupAID}, - DestinationProviderIDs: []string{provider.ID}, - }) - require.NoError(t, err, "CreatePolicy must succeed") - - settings, err := am.Store.GetAgentNetworkSettings(ctx, store.LockingStrengthNone, accountID) - require.NoError(t, err) - fqdn := settings.Endpoint() - - rdata1 := awaitZoneRData(clientCh, clusterAddr, fqdn, true) - require.Equal(t, proxyIP1, rdata1, - "client must receive a synth DNS record pointing at K1's overlay IP after the synth path runs") - drain(clientCh) - - // --- Proxy restart: NEW keypair K2, same account, same cluster --- - require.NoError(t, peersMgr.CreateProxyPeer(ctx, accountID, proxyKey2, clusterAddr), - "second CreateProxyPeer (proxy restart with fresh keypair) must succeed") - - peer2ID, err := am.Store.GetPeerIDByKey(ctx, store.LockingStrengthNone, proxyKey2) - require.NoError(t, err, "proxy peer for K2 must be persisted after restart") - require.NotEmpty(t, peer2ID) - - require.NoError(t, am.MarkPeerConnected(ctx, proxyKey2, accountID, time.Now().UnixNano(), &types.NetworkMap{}), - "MarkPeerConnected for K2 must succeed") - - // In production the agent's sync stream pulls a fresh NetworkMap as - // part of its normal reconcile cadence; in this isolated test - // MarkPeerConnected's affected-peer fan-out can race the channel-side - // buffer in a way that swallows the synth-DNS-bearing update before - // our await reads it. Trigger an explicit account-wide fan-out so the - // assertion below tests what production actually delivers, not the - // in-test buffer race. - am.UpdateAccountPeers(ctx, accountID, types.UpdateReason{Resource: types.UpdateResourcePeer, Operation: types.UpdateOperationUpdate}) - - account, err = am.Store.GetAccount(ctx, accountID) - require.NoError(t, err) - proxyIP2 := account.Peers[peer2ID].IP.String() - require.NotEmpty(t, proxyIP2, "K2 must have an assigned overlay IP") - require.NotEqual(t, proxyIP1, proxyIP2, "K2 must get a different overlay IP than K1 (sanity)") - - // CRITICAL ASSERTION 1: K1 must no longer be in the store. The SqlStore - // returns ("", nil) for a missing key rather than NotFound, so assert - // on the returned ID being empty. - staleID, err := am.Store.GetPeerIDByKey(ctx, store.LockingStrengthNone, proxyKey1) - require.NoError(t, err, "GetPeerIDByKey for a missing peer must not error") - assert.Empty(t, staleID, - "stale embedded proxy peer K1 must be removed when a new embedded peer registers for the same (account, cluster); pre-fix this assertion fails because management never cleans up the prior peer record") - - // CRITICAL ASSERTION 2: exactly one embedded proxy peer remains, and it - // is K2. - account, err = am.Store.GetAccount(ctx, accountID) - require.NoError(t, err) - embeddedKeys := []string{} - for _, p := range account.Peers { - if p.ProxyMeta.Embedded { - embeddedKeys = append(embeddedKeys, p.Key) - } - } - assert.Equal(t, []string{proxyKey2}, embeddedKeys, - "after a proxy restart exactly one embedded proxy peer should remain — the one with the new key K2") - - // CRITICAL ASSERTION 3: the synth DNS record the client receives now - // points at K2's IP, not K1's. - rdata2 := awaitZoneRData(clientCh, clusterAddr, fqdn, true) - assert.Equal(t, proxyIP2, rdata2, - "after proxy restart, the client's synth DNS record must point at the NEW embedded peer's IP, not the stale K1 IP") -} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware.go new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware.go --- old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware.go 2026-07-14 20:13:00.000000000 +0200 @@ -25,6 +25,14 @@ denyCodeModel = "llm_policy.model_blocked" denyReasonModel = "model_blocked" denyMessageModel = "model is not in the policy allowlist" + // Deny reason used when an allowlist is configured but the request model + // could not be determined. URL/path-routed providers (AWS Bedrock, Google + // Vertex, ...) carry the model outside the JSON body, so a request shape the + // parser does not recognise reaches the guardrail with no model. Such a + // request must be denied (fail closed), never waved through. + denyCodeModelUnknown = "llm_policy.model_unknown" + denyReasonModelUnknown = "model_unknown" + denyMessageModelUnknown = "request model could not be determined for the policy allowlist" ) // Middleware enforces the model allowlist and optionally captures the @@ -108,23 +116,37 @@ if len(m.cfg.ModelAllowlist) == 0 { return nil } - if !modelPresent { - return nil + // Fail closed: with an allowlist configured, a request whose model the + // upstream parser could not extract (absent or empty) must be denied rather + // than allowed. This is what enforces the allowlist for URL/path-routed + // providers (Bedrock, Vertex, ...) whose model lives outside the JSON body. + if !modelPresent || normaliseModel(model) == "" { + return denyModel("", denyCodeModelUnknown, denyMessageModelUnknown, denyReasonModelUnknown) } if m.modelInAllowlist(model) { return nil } + return denyModel(model, denyCodeModel, denyMessageModel, denyReasonModel) +} + +// denyModel builds a 403 deny Output for a model-allowlist rejection. model is +// included in the details only when non-empty. +func denyModel(model, code, message, reason string) *middleware.Output { + details := map[string]string{} + if model != "" { + details["model"] = model + } return &middleware.Output{ Decision: middleware.DecisionDeny, DenyStatus: 403, DenyReason: &middleware.DenyReason{ - Code: denyCodeModel, - Message: denyMessageModel, - Details: map[string]string{"model": model}, + Code: code, + Message: message, + Details: details, }, Metadata: []middleware.KV{ {Key: middleware.KeyLLMPolicyDecision, Value: "deny"}, - {Key: middleware.KeyLLMPolicyReason, Value: denyReasonModel}, + {Key: middleware.KeyLLMPolicyReason, Value: reason}, }, } } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go --- old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go 2026-07-10 17:42:06.000000000 +0200 +++ new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go 2026-07-14 20:13:00.000000000 +0200 @@ -102,13 +102,44 @@ } } -func TestAllowlistMissingModelKeyAllows(t *testing.T) { +func TestAllowlistMissingModelKeyDenies(t *testing.T) { + // Fail closed: with an allowlist configured, a request whose model the + // parser could not extract (URL/path-routed providers such as Bedrock or + // Vertex whose shape wasn't recognised) must be denied, not allowed. mw := New(Config{ModelAllowlist: []string{"gpt-4o"}}) out, err := mw.Invoke(context.Background(), newInput()) require.NoError(t, err) - assert.Equal(t, middleware.DecisionAllow, out.Decision, "missing model key must allow even with non-empty allowlist") + require.NotNil(t, out) + assert.Equal(t, middleware.DecisionDeny, out.Decision, "absent model must be denied when an allowlist is set") + assert.Equal(t, 403, out.DenyStatus, "deny status must be 403") + require.NotNil(t, out.DenyReason, "deny reason must be populated") + assert.Equal(t, "llm_policy.model_unknown", out.DenyReason.Code, "deny code must be model_unknown") dec, _ := metaValue(t, out.Metadata, middleware.KeyLLMPolicyDecision) - assert.Equal(t, "allow", dec, "decision must be allow when model key is absent") + assert.Equal(t, "deny", dec, "decision must be deny when model key is absent") + reason, _ := metaValue(t, out.Metadata, middleware.KeyLLMPolicyReason) + assert.Equal(t, "model_unknown", reason, "reason metadata must be model_unknown") +} + +func TestAllowlistEmptyModelValueDenies(t *testing.T) { + // A present-but-empty model is as undeterminable as an absent one. + mw := New(Config{ModelAllowlist: []string{"gpt-4o"}}) + out, err := mw.Invoke(context.Background(), newInput( + middleware.KV{Key: middleware.KeyLLMModel, Value: " "}, + )) + require.NoError(t, err) + require.NotNil(t, out) + assert.Equal(t, middleware.DecisionDeny, out.Decision, "empty model must be denied when an allowlist is set") + require.NotNil(t, out.DenyReason, "deny reason must be populated") + assert.Equal(t, "llm_policy.model_unknown", out.DenyReason.Code, "deny code must be model_unknown") +} + +func TestAllowlistEmptyListAllowsMissingModel(t *testing.T) { + // Without an allowlist there is nothing to enforce, so a missing model is + // still allowed — the fail-closed rule only applies when a list is set. + mw := New(Config{}) + out, err := mw.Invoke(context.Background(), newInput()) + require.NoError(t, err) + assert.Equal(t, middleware.DecisionAllow, out.Decision, "no allowlist must allow even without a model") } func TestPromptCaptureDisabledEmitsNoPrompt(t *testing.T) { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go --- old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go 1970-01-01 01:00:00.000000000 +0100 +++ new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go 2026-07-14 20:13:00.000000000 +0200 @@ -0,0 +1,106 @@ +package llm_request_parser + +import ( + "context" + "testing" + + "github.com/stretchr/testify/assert" + "github.com/stretchr/testify/require" + + "github.com/netbirdio/netbird/proxy/internal/middleware" + "github.com/netbirdio/netbird/proxy/internal/middleware/builtin/llm_guardrail" +) + +// runParserGuardrail runs the request parser then the model-allowlist guardrail +// in SlotOnRequest order, threading the parser's metadata into the guardrail the +// same way the real chain does. It returns the guardrail decision so tests can +// assert allowlist enforcement for URL/path-routed providers end to end. +func runParserGuardrail(t *testing.T, url string, body []byte, allowlist []string) *middleware.Output { + t.Helper() + parser := newMiddleware(t) + parsed, err := parser.Invoke(context.Background(), &middleware.Input{ + Slot: middleware.SlotOnRequest, + URL: url, + Body: body, + }) + require.NoError(t, err, "parser must not error") + + guard := llm_guardrail.New(llm_guardrail.Config{ModelAllowlist: allowlist}) + out, err := guard.Invoke(context.Background(), &middleware.Input{ + Slot: middleware.SlotOnRequest, + Metadata: parsed.Metadata, + }) + require.NoError(t, err, "guardrail must not error") + require.NotNil(t, out, "guardrail must return an output") + return out +} + +// TestModelAllowlist_URLRoutedProviders validates that the model allowlist is +// enforced for providers whose model travels in the URL path (AWS Bedrock, +// Google Vertex) rather than the JSON body. The "unknown action" case is the +// regression guard for #6751: a Bedrock request shape the parser cannot map to a +// model must fail closed under an allowlist instead of bypassing it. +func TestModelAllowlist_URLRoutedProviders(t *testing.T) { + const bedrockBody = `{"anthropic_version":"bedrock-2023-05-31","messages":[{"role":"user","content":"hi"}]}` + const vertexBody = `{"anthropic_version":"vertex-2023-10-16","messages":[{"role":"user","content":"hi"}]}` + + tests := []struct { + name string + url string + body string + allowlist []string + decision middleware.Decision + denyCode string + }{ + { + name: "bedrock allowed model passes", + url: "https://bedrock-runtime.us-east-1.amazonaws.com/model/us.anthropic.claude-haiku-4-5-v1:0/invoke", + body: bedrockBody, + allowlist: []string{"anthropic.claude-haiku-4-5"}, + decision: middleware.DecisionAllow, + }, + { + name: "bedrock disallowed model denied", + url: "https://bedrock-runtime.us-east-1.amazonaws.com/model/us.anthropic.claude-opus-4-8-v1:0/invoke", + body: bedrockBody, + allowlist: []string{"anthropic.claude-haiku-4-5"}, + decision: middleware.DecisionDeny, + denyCode: "llm_policy.model_blocked", + }, + { + name: "bedrock unknown action fails closed", + url: "https://bedrock-runtime.us-east-1.amazonaws.com/model/us.anthropic.claude-opus-4-8-v1:0/some-future-action", + body: bedrockBody, + allowlist: []string{"anthropic.claude-haiku-4-5"}, + decision: middleware.DecisionDeny, + denyCode: "llm_policy.model_unknown", + }, + { + name: "vertex disallowed model denied", + url: "/v1/projects/p/locations/global/publishers/anthropic/models/claude-opus-4-8@20250101:rawPredict", + body: vertexBody, + allowlist: []string{"claude-haiku-4-5"}, + decision: middleware.DecisionDeny, + denyCode: "llm_policy.model_blocked", + }, + { + name: "vertex allowed model passes", + url: "/v1/projects/p/locations/global/publishers/anthropic/models/claude-haiku-4-5@20250101:rawPredict", + body: vertexBody, + allowlist: []string{"claude-haiku-4-5"}, + decision: middleware.DecisionAllow, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + out := runParserGuardrail(t, tt.url, []byte(tt.body), tt.allowlist) + assert.Equal(t, tt.decision, out.Decision, "unexpected decision for %s", tt.name) + if tt.decision == middleware.DecisionDeny { + require.NotNil(t, out.DenyReason, "deny reason must be set for %s", tt.name) + assert.Equal(t, 403, out.DenyStatus, "deny status must be 403 for %s", tt.name) + assert.Equal(t, tt.denyCode, out.DenyReason.Code, "deny code for %s", tt.name) + } + }) + } +} ++++++ netbird.obsinfo ++++++ --- /var/tmp/diff_new_pack.e72vpa/_old 2026-07-15 17:02:58.645911959 +0200 +++ /var/tmp/diff_new_pack.e72vpa/_new 2026-07-15 17:02:58.649912095 +0200 @@ -1,5 +1,5 @@ name: netbird -version: 0.74.4 -mtime: 1783698126 -commit: 3d87547d952f5ada9df987bbe4f0f6d54372d77c +version: 0.74.5 +mtime: 1784052780 +commit: f0eed7564f3a9138962da1408986e4666d7137b5 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/netbird/vendor.tar.zst /work/SRC/openSUSE:Factory/.netbird.new.1991/vendor.tar.zst differ: char 7, line 1
