Most tests opened a throwaway panel DB with database.InitDB, which runs the
full AutoMigrate + seed on an empty file every time: ~230ms, and ~850ms under
-race because GORM's reflection-heavy migration is what the detector slows
most. internal/web/service does this in ~550 of its 830 tests, so the CI race
job spent ~10 of its ~14.6 minutes re-migrating empty databases.
internal/database/dbtest.InitDB migrates once per test process, then hands
each test its own copy of that file (~130ms under -race) and registers the
CloseDB cleanup. The copy then goes through InitDB like a panel restart, so
every test still starts from the state a fresh install has. Tests that reopen
an existing file, migrate a hand-built legacy DB or target Postgres keep
calling database.InitDB.
Locally under -race: internal/web/service 626s (last CI run) -> 114s,
internal/sub 246s -> 35s.
Catch the panel up to the mtg-multi README (v1.14.0):
- Each client can now carry its own 32-hex advertising tag overriding the
inbound-level one. The tag lives on the client (settings JSON is the
source of truth, clients.ad_tag is the UI projection), is rendered into
the fork's [secret-ad-tags] section for active secrets only (mtg rejects
a config whose override names an unknown secret), is pushed per entry
through PUT /secrets, and is part of the reload fingerprint so a tag
edit hot-applies without dropping connections.
- The loopback management API can replace the whole secret set, so every
mtg process now gets a random per-process api-token; the manager sends
it as a bearer token on PUT /secrets and GET /stats and reuses it across
config rewrites, because mtg reads the token only at startup.
- Malformed tags are rejected at every save path and additionally dropped
in InstanceFromInbound: one bad tag would otherwise fail the whole
generated config and take every client of the inbound down with it.
- SyncInbound never copied a re-keyed mtproto secret into the canonical
clients table, so the clients page and subscription links kept serving
the old secret, which mtg then rejects. It is now guarded-copied like
the other credentials.