From the source of truth

Changelog

A static snapshot from the Sagüin repository.

PBKDF2-HMAC-SHA512, and `$6 Changelog | Sagüin documentation files read as\n they are), mutual TLS, an ACL file with roles, and per-client publish\n limits. Credential files, TLS certificates, WebSocket origins and the log\n level are re-read on `SIGUSR1`; other configuration changes need a restart.\n- MQTT listens on TCP, WebSocket and Unix-socket doors, several of each if\n named, with door-specific credentials and TLS. The operations listener\n takes TCP and Unix-socket doors. A trusted proxy can pass a client's\n identity (PROXY protocol v2 on an MQTT Unix socket; a header set by the\n proxy on the operations Unix socket).\n- `saguin --check-config` and a plain start agree on door names, socket paths\n and addresses, and refuse a clash by name.\n\n**Bridges**\n\n- Inbound, outbound and bidirectional MQTT bridges carry selected records to\n or from another broker and resume across link outages. A bridge carries\n records, not channel offsets, consumer positions or queue state.\n\n**Operations**\n\n- An HTTP operations listener with `/health`, Prometheus metrics, and\n authenticated read-only routes for the resolved configuration, one user's\n permissions, consumers, queues, lost positions, refused clients, sessions\n and users. The metric `saguin_channel_floor_offset` against\n `saguin_channel_consumer_position_min` shows when retention has passed a\n consumer.\n- `saguin --version`, `--licenses` (the licences of everything inside the\n binary), `--check-config`, and the `--passwd` subcommands.\n\n**Distribution**\n\n- Binaries for Linux (amd64, arm64, armv7) and macOS (amd64, arm64), with\n checksums, and a multi-arch container image (amd64, arm64) at\n `ghcr.io/ifnesi/saguin`. There is no Windows build: on Windows, run the\n container image, or the Linux binary under WSL2.\n\n### Known limits\n\n- One process on one node: no clustering, replication, consensus or\n automatic failover. A bridge is transport, not replication, and queue\n state cannot be copied by one; recovery uses a copy of the SQLite\n database.\n- Sized for thousands of connections, not millions. A SQLite provider has one\n write connection.\n- No exactly-once processing, priority or scheduled delivery, schema\n enforcement, multi-tenancy layer, or web interface inside the broker.\n- A broadcast publish does not prove that any subscriber received it. A\n session's queue is bounded and may discard its oldest owed deliveries when\n full, which the metrics count.\n- Certificate revocation is not implemented in Sagüin.\n- The project is early. The RFCs in `docs/rfcs` are the source of truth for\n detailed behaviour and refusal codes.\n\n### Known issues\n\nA code review is under way before 0.1.0. These findings are known and will be\nfixed or documented before then.\n\n- A channel message delivered after a reconnect, behind messages being\n re-sent, can carry a Message Expiry Interval longer than the time actually\n left (MQTT 5 section 3.3.2-6). No data is lost.\n- A connection that arrives while the broker is shutting down can have its\n socket closed twice. This is harmless and is listed for completeness.\n- A rare connection refusal just after startup was seen once in about 800\n test runs, after the health endpoint had answered. It is not yet diagnosed.\n Clients that retry are unaffected.\n- RFC 0003 does not yet say explicitly that broadcast order is not promised\n across different publishers or QoS levels. MQTT gives no such promise\n either.\n- On macOS, `make check` has three test failures that are limits of the\n tests, not broker defects: one admission test times a refused connection\n from the client's dial rather than the broker's accept, and the\n broker-comparison harness reads Linux's `/proc`. The broker itself behaves\n correctly on macOS.\n"}