Release 3.0.0: redesigned app, 150-source catalog, desktop builds, pools, schedules and API - #28
Merged
Merged
Conversation
added 22 commits
September 27, 2026 01:29
- Version 3.0.0; CHANGELOG, README (EN/RU) and the landing page describe the new catalog, desktop app, pools, schedules, keys, diagnostics, backups and 12 languages, without links to removed documents. - A saved or system language from a lazy pack is loaded at start; before, ten of twelve languages fell back to English after a restart. - Result rows re-apply the hidden columns after every render, so cells no longer slide under the wrong headers. - Results table text follows the theme instead of a dark-only colour. - Comments no longer point at internal planning documents. - New screenshots on synthetic RFC 5737 data.
The installer's command line shortcuts started the windowed GUI executable with --help, which prints nowhere; they now open a console running the CLI executable. The installer also announces its Path change so new consoles find the command. Windows has no menu bar and the GUI build has no console, so the running app could only be stopped from the Task Manager, and the uninstaller could not remove an executable that was still running. The desktop host now has a --quit command that asks the running instance to quit over its control channel and waits until it has released its data folder. The installer adds a Start menu entry for it and runs it before uninstalling.
The CLI scan opened a second SQLite connection for its job store while the scan kept a write batch open on the first. Every job item claim then waited out the busy timeout with the event loop blocked (about 5 s per result) and left the item pending. The job store now reuses the scan's connection. The adaptive concurrency limit treated a dead proxy as overload, so a mostly dead corpus drove the scan down to one check at a time. The scan now counts only failures without a measurement stage (local trouble) as overload. Descriptor exhaustion (EMFILE and similar) is raised instead of being recorded as an unreachable proxy.
- Write pipeline audit rows again (the adapter shadowed its own writer). - Enforce resource scope named by body or query fields, not only path ones. - Serve event streams: accept the page shape, stream frames on the serve socket, give the system stream a global sequence and a working cursor. - Result listings follow their cursor and apply every declared filter, sort and count; selection accepts host:port; one engine per country filter instead of one database connection per row. - Scoped keys see the members of their own collection; pool members of a missing or hidden pool are 404. - Missing jobs answer 404, validation errors 400, engine ValueError 400. - Source refresh returns a job id; unknown source ids are 404. - Expired idempotency keys accept a new body; PUT answers 405; legacy read-only paths refuse other methods; localhost reaches /v1. - Subscription revoke only revokes subscriptions; half a rate limit and a create-time rotation grace are refused; profile@revision is routable. - Snapshots exported with --min-success 0 are readable again. - The GUI no longer sends the administrator key in a URL.
Write collected addresses in key-sorted batches of set-based statements instead of several statements per address, with a fast path for plain IPv4 lines in the proxy normalizer. A list without country claims no longer clears a country stored by an earlier source or import. Catalog line records now honor their http-fields and text formats and drop trailing inline comments. A source past its own size or candidate limit is reported as a partial read of a working transport and is not backed off or quarantined. Cache validators are stored only with a body that was read whole, and a 304 without validators keeps the stored ones. Next-url pagination keeps the path and query of absolute links.
…keys Collections carry a revision (migration 20), so PATCH and DELETE honour If-Match and PATCH applies archived. Merge copies from_collection_id, replace answers with a job id, member add refuses values that are not proxy addresses and member removal takes the endpoint id. Source comparisons check every named collection against the key scope. Pool creation defaults the profile to the last checked one and refuses an unknown profile; renaming a pool is refused instead of dropped. Schedules refuse an unknown collection. The gateway configuration is stored under a revision with validated transports, and stored bindings are listed with their own revision. Only revoked keys can be deleted. A wildcard or network bind accepts loopback names, the machine name and its routed addresses as Host, and still refuses other names. Audit retention no longer scans the whole table on every insert.
Keep only the newest three generations per source (entries included) and the newest fifty fetch observations, pruned in batches right after each source is committed; the generations the source state names are never pruned. Backup retention previews and removes history left by older versions. A 304 now writes the last good generation into the target collection, restoring missing members without re-dating the ones that are there. A retry after a broken download starts from the counters the attempt started with, so a large list no longer fails its own size limit. JSON pages are parsed once, and a list cut off by the candidate limit reports the page it read.
A stopped or failed CLI scan left its job running, so every later scan was refused with E_CONFLICT_BUSY and left another queued job behind for the background runner. The job is now paused on a stop, a stale running check job is paused under the data lock, and the same command resumes the paused job with the same input instead of measuring finished items again. A job that cannot start is cancelled instead of left queued. Watch rounds reused the first run's closed job, which made every address look finished: a round measured nothing and republished old verdicts. Each round now opens its own job for the passing addresses. Also refuse --speedtest-bytes below the minimum honest sample, which could only ever produce insufficient speed results.
A worker waited for a busy host with the item in hand, so a list with many ports on one address put every worker behind that host while other hosts sat in the queue. An item whose host is busy is now parked for the worker holding that host (bounded by the queue size), and the worker moves on. The stop check is repeated after a host wait, so a reached --want, deadline or budget is not followed by more measurements. hostport.txt lists a port that passes as several protocols once. Tests cover stop and continue, watch rounds, host parking, want on one host, hostport dedupe and the speed test minimum, on local mocks.
…w slow node starts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proxy Workbench 3.0.0
The largest release so far. The full list of changes is in CHANGELOG.md; this is the short version.
What users get
.app/.dmg, Apple Silicon and Intel) and a Windows installer with separate GUI and CLI executables; per-user data folders and an opt-in portable mode./v1for scripts and integrations.Verified before release
--watch.--watch,--want, budgets, judge, speed test, reputation, geo and every export file checked./v1operations called with valid and invalid input and with a scoped key; about 30 defects fixed (audit log, scope bypass through body fields, event streams, paging, status codes, key leak in a URL, collection revisions, merge/replace, gateway settings, network Host handling).Breaking changes
proxy-workbenchwith no arguments starts the desktop app;proxy-workbench guiopens only the web interface.--gateway-token), separate from the API token.Repository cleanup
Internal planning documents and contributor boilerplate were removed; the README, the landing page, screenshots, the demo animation and the social preview were rewritten for 3.0.0.