systemd (verified on Ubuntu 20.04 / systemd 245 with systemd-analyze
verify) treats the quoted value as part of the path and rejects the
unit with: WorkingDirectory= path is not absolute: "/etc/aether-tunnel".
This made aether-tunnel setup fail after a seemingly successful
one-line install, so remote proxy nodes never came online.
WorkingDirectory= takes the rest of the line as the path, so spaces in
the working directory stay intact unquoted; newline/specifier injection
is already rejected by validate_service_unit_path. ExecStart= and
Environment= keep their existing quoting.
Updates #817 (proxy node section; reproduced there with the full
systemd-analyze verify output).
Bound request, stream, queue, and shutdown resource lifetimes. Reduce scheduler and Redis hot-path work and isolate database maintenance. Include regression coverage, load probes, and concurrency audit results.
Share provider DNS policy across WebSocket and connection probes, handle bracketed IPv6 literals, and preserve bounded address sets for outbound clients.
Bound SMTP DNS and TCP setup with multi-address fallback. Add opt-in trusted proxy DNS for tunnel upstreams while retaining default IP ACLs and origin isolation.
Document DNS policy boundaries and verify 809 gateway, tunnel, and HTTP regression tests.
Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change.
Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
Retry pre-response transport failures across candidates with an explicit stop policy, and propagate end-to-end timing into usage records and UI diagnostics.
Remove legacy body, import, cookie, PII, and tunnel replay caps while preserving optional operator-configured gateway limits.