From the source of truth
Changelog
A static snapshot from the Sagüin repository.
From the source of truth
A static snapshot from the Sagüin repository.
All notable changes to this project are documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning: MAJOR.MINOR.PATCH.
The newest release is listed first. Dates are ISO 8601 (YYYY-MM-DD). Categories: Added, Changed, Deprecated, Removed, Fixed, Security.
A section here means a tag on GitHub. Nothing is recorded before it is
released, so what is in flight lives in git log until it ships under a
version.
The first release. Sagüin is a single-node MQTT broker for edge and small-scale IoT and IIoT deployments. It keeps standard MQTT as the client protocol and adds three durable channel types behind configured topic filters.
Channels and delivery
append channel keeps a
replayable log and a durable position per consumer. A latest channel
keeps one current value per topic. A queue channel offers each record to
one worker at a time, with application acknowledgement, return, visibility
timeout, retry limits, backoff and dead-lettering. A topic no channel
claims stays ordinary MQTT broadcast, with retained messages.append records reach a consumer in offset order. When retention removes
history a consumer has not read, the broker says so rather than serving the
oldest surviving record as if nothing were missing.append and latest topics. Queue workers need MQTT 5, because queue
delivery and acknowledgement use properties and shared subscriptions that
3.1.1 does not have. A queue is offered to its workers at QoS 1.Storage
synchronous=NORMAL, survives a process crash, an OOM kill or kill -9,
and keeps its data in a file ordinary SQLite tools can open.flush_interval sets how often a SQLite provider forces its write-ahead
log to disk: 150 ms by default, from 10 ms to 1 s, and there is no way to
turn it off. A power cut can lose the acknowledged publishes committed in
about the last interval plus one fsync, never a gap below a record that
survives. Measured on a Raspberry Pi 4 with a USB SSD, two power cuts at
the default lost the last 52 ms and 138 ms of acknowledged records, with no
gaps and no duplicates. A failed flush is counted in
saguin_storage_errors_total and logged, never silent.BEGIN IMMEDIATE.What a client is told
broker.session.ack_commit_interval
(200 ms by default), so an unclean stop can send again what was
acknowledged in that window. That is a replay, never a skip.Connections and packets
limits.max_connections counts a connection from the moment its socket
arrives, before CONNECT. Beyond the limit there is one small overflow
budget (the smaller of max_connections and 32): a socket waits up to
50 ms for a slot, the longest-waiting first, and one that gets none is
answered with "Server busy" if it sent a CONNECT, or closed. Every socket
not admitted is closed within 100 ms of arriving. A connection gives its
slot back when the broker decides it ends, so a client that was turned away
or disconnected can reconnect at once.Security and doors
$7$ PBKDF2-HMAC-SHA512, and $6$ files read as
they are), mutual TLS, an ACL file with roles, and per-client publish
limits. Credential files, TLS certificates, WebSocket origins and the log
level are re-read on SIGUSR1; other configuration changes need a restart.saguin --check-config and a plain start agree on door names, socket paths
and addresses, and refuse a clash by name.Bridges
Operations
/health, Prometheus metrics, and
authenticated read-only routes for the resolved configuration, one user's
permissions, consumers, queues, lost positions, refused clients, sessions
and users. The metric saguin_channel_floor_offset against
saguin_channel_consumer_position_min shows when retention has passed a
consumer.saguin --version, --licenses (the licences of everything inside the
binary), --check-config, and the --passwd subcommands.Distribution
ghcr.io/ifnesi/saguin. There is no Windows build: on Windows, run the
container image, or the Linux binary under WSL2.docs/rfcs are the source of truth for
detailed behaviour and refusal codes.A code review is under way before 0.1.0. These findings are known and will be fixed or documented before then.
make check has three test failures that are limits of the
tests, not broker defects: one admission test times a refused connection
from the client's dial rather than the broker's accept, and the
broker-comparison harness reads Linux's /proc. The broker itself behaves
correctly on macOS.