Changelog
User-facing changes to the DTVSOL Super Router: the dtvsol CLI, the HTTP API, the daemon dtvsold and the OLT monitor. Newest first. Internal refactoring is left out.
Week of 28 September 2026
Section titled “Week of 28 September 2026”OLT monitor: Settings and Alarms tabs
Section titled “OLT monitor: Settings and Alarms tabs”- Settings tab. It shows the router’s interfaces, bonds, VLANs and IP addresses side by side. Interfaces DTVSOL made are marked as such, and so is anything no part of DTVSOL made.
- Changing the router from the monitor. Admins can make these changes from the Settings tab:
- Interfaces: a port’s state and MTU; a bond’s members, mode, LACP rate, hash policy, link check and MTU. The monitor shows the planned change first. Once applied, the change must be confirmed within 120 seconds, or the router rolls it back on its own.
- VLANs: add, disable, enable and delete.
- IP addresses: add and delete. A delete that could cut the monitor off is refused.
- Protection: the allow-list for the API and the monitor, port forwards, fail2ban (jails, banned addresses, unban), anti-spoofing (on/off, default mode, logging, exempt networks, each interface’s mode) and CGNAT.
- Alarms tab by area. Pick OLT, clients’ ONUs, network, server or services to see that area’s alarms next to its own health readings. All shows one tile per area.
- Wall display (
/wall). A full-screen page for a screen in the support room, readable from across the room. It shows a clock and one status band: ALL OK, N WARNINGS, N CRITICAL, or NO CONTACT WITH THE ROUTER when the router has not answered for a minute. - Roles. A monitor user is either an admin (may change the router’s settings) or a viewer (sees everything, changes nothing). Users created before roles existed are viewers. See
dtvsol monitor user add <name> [admin|viewer]anddtvsol monitor user role <name> admin|viewer. - Wall keys. A wall screen logs in with its own display key:
dtvsol monitor wall add <name>,dtvsol monitor wall del <name>,dtvsol monitor walls.
- New
GET /health[?area=olt|onu|network|server|services]: each area’s readings, to go with its alarms. - New
POST /network/…edits:plan,apply,confirm,rollback, and the VLAN, address and protection operations. See Network configuration. - A server’s BMC USB network link is no longer treated as a router port. It is left out of imports, alarm checks and health readings.
Week of 21 September 2026
Section titled “Week of 21 September 2026”A single daemon, no PHP
Section titled “A single daemon, no PHP”dtvsoldserves the entire HTTP API. That covers every REST resource, the action API (/api?action=…) and the usage answer. The PHP API is no longer started. Answers are byte-for-byte what the PHP API returned, so existing integrations keep working.- The boot sequence, timers and cron jobs run through the daemon (
dtvsold run <command>). These include route, service and shaping restore at boot, prefix-delegation routes, the expiry checks, OLT sync and maintenance, anti-spoofing sync, the OLT collector, traffic sampling, the daily backup and the licence refresh. - The MikroTik-compatible API (TCP 8728), the OLT monitor (HTTPS 8881) and the per-client SNMP agent are also served by the daemon’s binaries.
- The
dtvsolCLI is now a compiled program with the same commands and output. Tab completion works in every interactive bash, including root’s.
Alarms
Section titled “Alarms”- Alarm register. The router checks itself every minute and keeps its alarms, raised and cleared, in its database. It covers the OLT, clients’ ONUs, the network, the server and the services.
- CLI:
dtvsol alarms,dtvsol alarms all,dtvsol alarms history [n] - API:
GET /alarms
- CLI:
- The address-pool and unknown-device checks now look only at networks the router serves through DHCP. Transit links and the OLT management network no longer raise false alarms.
Router network in the database
Section titled “Router network in the database”- The router’s own network (ports, bonds, VLANs, addresses, routes) is stored in the router’s database, and the router writes one netplan file from it. Commands:
dtvsol netcfg show|import|render|diff|apply|confirm|rollback. - An apply is undone after 120 seconds unless you confirm it.
- Nothing already in netplan is lost on import or apply. MAC addresses are kept, and ports and bonds ignore router advertisements.
Services: one VLAN per PON port
Section titled “Services: one VLAN per PON port”- New service model. Each PON port has one customer VLAN, and each ONT gets one fixed address through DHCP Option 82. One call provisions the ONT, VLAN, address and speed. See Services.
- Several routers can share one OLT. Each router has its own S-VLAN, and no router touches another’s objects on the OLT.
- Services are listed with the clients, in one count.
- CGNAT now translates services too.
- Services use only the IPv6 space the upstream routes to the router.
- Compiled OLT driver. A licensed binary is now the only OLT driver. It reads over SNMP first and falls back to the OLT’s CLI. Every write operation was tested live before release.
- OLT collector. Every 5 minutes it records fiber levels, ONT states and port counters. It also keeps traffic graphs per ONT, PON port, uplink and card, stored for 2 years.
- Fiber alerts in
dtvsol alerts:- an ONT offline through fiber loss (a whole PON port offline is critical);
- a receive level too weak, weak or too strong;
- a level more than 2 dB below its 7-day value;
- growing line errors.
- NTP for the OLTs.
dtvsol ntp setupmakes the router the time source for its OLTs’ management links. - Configuration safety:
- Changes are saved to the OLT’s flash after they settle.
- Each saved configuration is backed up with history, and you can compare versions (
/olt/backups,/olt/diff). - Only one session per OLT runs at a time.
- The
execoperation refuses?.
dtvsol doctorchecks the OLT against the router’s records by default.--no-oltskips this check.
OLT monitor
Section titled “OLT monitor”- Live console. It shows every command sent to the OLTs and the reply.
- OLT tab.
- The chassis is drawn from the OLT’s real boards, with every port by state.
- Right-click a port to see its clients and configuration.
- Search for clients across the OLT (MAC, serial, name, contract, IP, fiber problems, offline).
- Each PON port has a fiber-history chart (1 day, 7 days, 90 days, 2 years), and each client has a 7-day sparkline.
- Dark theme by default, with a light theme on a button.
Configuration and backups
Section titled “Configuration and backups”- Saved configurations. The router keeps its configuration in an internal database and saves versions, like a switch’s flash. Use
dtvsol configto list, save, diff, show and restore versions, and to edit a document. - Daily self-backup. The router backs itself up every day and keeps an encrypted copy off the router.
- Licence. The router fetches its 90-day licence from DTVSOL:
dtvsol licence enrol|refresh|status, refreshed daily.
Security fixes
Section titled “Security fixes”- A DNS search domain must now be host names only. Before this fix, crafted text could add DHCP server directives.
- The CGNAT WAN interface must be an interface name, not a path.
- A data file that does not parse is never saved over.
dtvsol doctorreports broken files.
Week of 14 September 2026
Section titled “Week of 14 September 2026”- OLT control. Manage a Huawei OLT through the API and the CLI.
- A registry keeps each OLT with encrypted credentials.
- Speed plans are pushed to every registered OLT.
- A baseline generator prepares a new OLT (
olt init).
- IPTV is unicast, point to point, on its own VLAN. No multicast and no IGMP are needed.
- Services, first version. One call provisioned the OLT and the router for a subscriber, with one VLAN per subscriber. This model was replaced by one VLAN per PON port in the week of 21 September.
- Anti-spoofing. Every subscriber is locked to its MAC address, IP address and VLAN.
- Modes: strict or dynamic, globally and per interface.
- Logging of dropped packets.
- CLI:
dtvsol antispoof. API:/antispoof.
August 2026
Section titled “August 2026”- DHCPv6 prefix delegation. A CPE gets its LAN prefix automatically:
dtvsol pd,/pd. - IPv6 pools. Every VLAN fits in the pool. The router shows who holds which address, and deleted VLANs leave nothing behind.
- Switch a VLAN off and on without losing its settings:
vlan disable|enable,POST /vlans/disable|enable. - Deleting a VLAN now also removes its NAT pool, port forwards and CGNAT entries.
- DNS. One command sets the resolvers served on IPv4 and IPv6. The global setting is a real default, for new and existing VLANs, and it can be cleared again:
dtvsol dns,/dns. - Tab completion for
dtvsol.
July 2026
Section titled “July 2026”- First release (v1.0.0). DHCP management API, CLI and boot persistence.
- Clients. Universal client lookup, a static IP usage view, a client activity view and interface statistics.
- Speed plans and suspension. Bandwidth plans (QoS), client suspend and resume, and traffic graphs. A client with no plan is unlimited.
- Edge features. CGNAT, port forwarding, service end dates, Option 82, alerts and backup.
- fail2ban protects against brute force on the API key and SSH.
- SNMP agent. Router interfaces and per-client data for any network management system.
- MikroTik-compatible API (TCP 8728), so billing systems built for MikroTik can provision the router.
dtvsol doctor. One command audits the configuration and its boot persistence.- Safer addressing:
- Two interfaces can no longer share a subnet.
- Network and broadcast addresses are refused as interface addresses.
- Deleting a VLAN or IPv6 network leaves nothing behind.