GalleonOS V13 Patch Notes

GalleonOS V13 Patch Notes

GalleonOS Version 13 - Patch Notes


Current Firmware Download: https://firmware.galleonos.io/

Alert
Note:
Only publicly released versions are listed below. 
Versions not shown were used for internal development and testing purposes.

Info
Version 13 #406

Small patch for units incorrectly reporting a failed RAM chip after the 405 update.

This report is designed for the NTS-9000 series unit and should not have triggered on older units.


Info
Version 13 #405

  • SNMP MIB's are now ZIP rather than TAR.GZ

  • Info
    Version 13 #403

  • Cleaned up the PTP config file.

  • Info
    Version 13 #401

  • PTP correctly announces accuracy 0x27 (100 µs)
  • Web UI explains accuracy 0x27 (100 µs)

  • Info
    Version 13 #400

  • Added a descending audible tone for power supply removal
  • Added an ascending audible tone for power supply recovery
  • Bound PTP service to ETH0 and ETH1 as two separate services
  • Added PTP service panels
  • Fully documented NTP configuration
  • Added PTP customisation page
  • Fully documented PTP configuration
  • Updated leap second file
  • Configured NTP watcher to restart NTP after 15 minutes if no working peers are available

  • Info
    Version 13 #382

    Updated the radio clock service to improve identification of connected antenna types (MSF, DCF, WWVB)


    Info
    Version 13 #381

    Rebuilt the NTP watcher service to resolve an NTP bug that blocked further time requests from a server after a bad DNS response


    Info
    Version 13 #376

    Applied tuning tweaks to improve PTP clock quality


    Info
    Version 13 #375

  • Updated Prometheus endpoint metrics
  • Completed first-pass implementation of PTP for the NTS-9000 series
  • Performed SNMP clean-up

  • Info
    Version 13#368

  • Migrated the build system to a newer host operating system
  • Updated multiple build dependencies
  • Completed the first successful rebuild in the new environment

  • Info
    Version 13 #365

    Updated the NTP v4 MIB to support SNMP monitoring and management


    Info
    Version 13 #354

    We have upgraded NGINX to version 1.30.1 to address vulnerabilities in older versions. While prior releases had already received security patches, it was now time to move to the latest stable version for continued protection and improved stability.


    Info
    Version 13 #353

    The new list is available under NTP - Most Recently Used List and provides visibility into devices on the network that are configured to use the time server.

    Please note that the list is not updated in real time. 

    It is generated from the NTP cache, so it may take some time to populate.

    Info
    Version 13 #345

    Added
    Prometheus dashboard page
    Added a new Prometheus page under Logs > Prometheus. This page explains how the Prometheus endpoint works and provides guidance on how to use it.

    Routing Table page
    Added a new Routing Table page under Networking > Routing Table. This page displays the current routing table.

    Improved
    Web interface wording and readability
    Updated wording across the web interface to make it clearer and easier to read.

    Additional interface information
    Added more helpful information to selected areas of the web interface to improve usability and context.

    Info
    Version 13 #336

    Added a notification to alert users when they are using outdated TLS versions, prompting them to update.

    Removed support for TLS 1.0 and TLS 1.1 from the Configure SSL page.

    Added an SSL configuration column to the Configure SSL page to help with debugging current setups.

    This patch prevents browsers that do not support TLS 1.3 from accessing the unit.

    All major modern web browsers support TLS 1.3, which has been widely adopted for several years.


    Info
    Version 13 #331

    Updated the leap second data file.


    Idea
    Version 13 #327

    Added support for 9000 series hardware.

    Updated internal tools used to install firmware.

    Updated internal tools used to test unit calibration.

    Info
    Version 13 #326

    Updated the leap second file.

    Added leap second file expiration details to the Web UI under Administration - Software Versions.

    Info
    Version 13 #324

    Updated syslog remote output to include hostname for RFC 3164 compliance.

    Info
    Version 13 #318

    Updated the UI link for firmware downloads.

    Added a notification indicator when new firmware is available.

    Info
    Version 13 #303

    Added a setup option to the system menu, available when both a keyboard and monitor are connected.

    This feature simplifies first-time setup by allowing users to manually enter IP address, Subnet Mask, and Gateway for both Ethernet ports.

    Designed for networks where DHCP is not available during initial configuration.

    Info
    Version 13 #302

    New Hardware Support:
    Added drivers for additional configurations.

    The firmware is now compatible with the following units:

    NTS-600x Series

    NTS-700x Series

    NTS-900x Series

    This update enhances backward compatibility, ensuring that future firmware updates will continue to support older device models in these series.

    Idea
    Version 13 #289

    Internal tooling

    Added a repartition script that automatically enlarges legacy boot partitions and performs a clean OS reinstall. 

    This ensures older devices with smaller boot partitions have enough space to receive future firmware updates.

    This tool is intended for use by support agents only, as only a handful of very old units require this process to ensure sufficient space for future firmware updates.

    This tool is destructive, no data will be retained, and backups must be made before use.

    Info
    Version 13 #272

    Kernel Update:
    Upgraded Linux kernel from v5.10.223 to v5.19.17
    Includes upstream security fixes and stability improvements
    Notable changes:
    Filesystem reliability enhancements (e.g., ext4 fixes)
    Networking stack improvements
    Scheduler and memory management optimizations
    Updated kernel infrastructure for long-term maintainability
    Applied security patches addressing known vulnerabilities up to v5.19.17

    Info
    Version 13 #224

    Dashboard
    NTS-7000 Series Support: Added support for dual power supplies in the NTS-7000 series. The dashboard now displays the status of both PSUs for improved visibility and diagnostics.

    SNMP
    Improved Default Configuration: The default SNMP configuration has been updated to include clearer comments and more sensible default settings.
    SNMP Disabled by Default: SNMP is now disabled by default to enhance security and reduce unnecessary network exposure.
    Best Practice Note: Using SNMP to check NTP synchronization is not recommended. Instead, use a probe to query the NTP port directly, this verifies both connectivity and synchronization status.

    NTP
    Migrated to ntpsec: The legacy ntpd service has been retired and replaced with ntpsec, enabling support for NTS (Network Time Security).
    NTS Requirements: For NTS to function correctly, ports 123/UDP and 4460/TCP must be accessible. A signed certificate must also be configured on the device.

    Calibration Graph
    Performance Improvement: The calibration graph now loads significantly faster, improving the user experience.

    Logs
    Enhanced Logging: Internal services now output more detailed log information to aid in diagnostics and troubleshooting.

    Firmware
    File Format Validation: The firmware update interface now accepts only .gos files, preventing installation of outdated or incompatible .gfw files.
    Soft Factory Reset: Added a "Clear Settings" option, allowing users to perform a soft factory reset without needing to reinstall the firmware.

    System Information
    Serial Number Display: The system information page now includes the device's serial number, simplifying remote support and inventory management.

    Idea
    Version 13 #191

    This update introduces several improvements aimed at enhancing usability and compatibility:

    Improved Help Text:
    The web interface now includes significantly expanded help text throughout, reducing the need to refer to the physical manual and streamlining the user experience.

    Update Support for Legacy Versions:
    This version includes the necessary software updates to enable seamless patching for users currently on Version 12 #11, bringing them fully up to date with Version 13 #191.

    Version 12 #11 users can use this download to upgrade to version 13: https://www.galleonos.io/firmware-191.gfw

    Info
    Version 13 #172

    Enhancements to NTP Calibration Graph:
    The graph now displays only the last 24 hours of data.
    This change significantly improves performance and prevents long loading times on systems with extended uptime or extensive historical data.
    Introduced color-coded visualization for calibration status:
    Red indicates the system is currently calibrating.
    Green indicates the system is calibrated.
    This visual cue provides at-a-glance insight into synchronization status, improving user experience and system monitoring efficiency

    Info
    Version 13 #165

    New Feature:
    Introduced NTP Calibration Graph, a new diagnostic tool that allows administrators to visually monitor and analyse time synchronization accuracy.
    This feature provides historical graphing of time drift and correction trends, aiding in long-term performance tuning and diagnostics.

    Info
    Version 13 #117

    Security Updates:
    OpenSSH updated to OpenSSH_9.1p1 to improve compatibility and security.
    OpenSSL updated from 1.1.1s to 3.0.14, delivering enhanced cryptographic support, performance improvements, and addressing multiple known vulnerabilities.
    These updates ensure compliance with modern encryption standards and improve overall system security.

    Info
    Version 13 #102

    Web Service Upgrade:
    Nginx upgraded from version 1.20.2 to 1.24.0.
    This update includes improved HTTP/2 handling, bug fixes, and performance enhancements for more stable and efficient web service operation.

    Info
    Version 13 #98

    NTP Service Update:
    Network Time Protocol (NTP) daemon upgraded from 4.2.8p15@1.3728-o to 4.2.8p18@1.4062-o.
    The upgrade brings improved timekeeping accuracy, updated leap second support, and bug fixes for better synchronization reliability.