Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package netbird for openSUSE:Factory checked 
in at 2026-07-15 16:44:24
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/netbird (Old)
 and      /work/SRC/openSUSE:Factory/.netbird.new.1991 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "netbird"

Wed Jul 15 16:44:24 2026 rev:39 rq:1365779 version:0.74.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/netbird/netbird.changes  2026-07-14 
13:50:50.012845705 +0200
+++ /work/SRC/openSUSE:Factory/.netbird.new.1991/netbird.changes        
2026-07-15 17:02:45.273457790 +0200
@@ -1,0 +2,9 @@
+Tue Jul 14 21:28:48 UTC 2026 - Marcus Rueckert <[email protected]>
+
+- Update to 0.74.5
+  - [proxy] enforce model allowlist for URL-routed providers
+    (Bedrock/Vertex) by @mlsmaycon in #6764
+  - [management] Remove proxy peer stale deduplication logic by
+    @mlsmaycon in #6768
+
+-------------------------------------------------------------------

Old:
----
  netbird-0.74.4.obscpio

New:
----
  netbird-0.74.5.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ netbird.spec ++++++
--- /var/tmp/diff_new_pack.e72vpa/_old  2026-07-15 17:02:54.533772298 +0200
+++ /var/tmp/diff_new_pack.e72vpa/_new  2026-07-15 17:02:54.537772434 +0200
@@ -32,7 +32,7 @@
 %bcond_with stub_config
 
 Name:           netbird
-Version:        0.74.4
+Version:        0.74.5
 Release:        0
 Summary:        Mesh VPN based on WireGuard
 License:        AGPL-3.0-only AND BSD-3-Clause

++++++ _service ++++++
--- /var/tmp/diff_new_pack.e72vpa/_old  2026-07-15 17:02:54.569773521 +0200
+++ /var/tmp/diff_new_pack.e72vpa/_new  2026-07-15 17:02:54.573773657 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/netbirdio/netbird.git</param>
     <param name="scm">git</param>
     <param name="package-meta">yes</param>
-    <param name="revision">refs/tags/v0.74.4</param>
+    <param name="revision">refs/tags/v0.74.5</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">disable</param>

++++++ netbird-0.74.4.obscpio -> netbird-0.74.5.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/FETCH_HEAD 
new/netbird-0.74.5/.git/FETCH_HEAD
--- old/netbird-0.74.4/.git/FETCH_HEAD  2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/FETCH_HEAD  2026-07-14 20:13:00.000000000 +0200
@@ -1,5 +1,5 @@
 3aa6c02b932db503e82f9530dddfe95d5ea212c4       not-for-merge   branch 
'0.74.3-branch' of https://github.com/netbirdio/netbird
-3d87547d952f5ada9df987bbe4f0f6d54372d77c       not-for-merge   branch 
'0.74.4-branch' of https://github.com/netbirdio/netbird
+f0eed7564f3a9138962da1408986e4666d7137b5       not-for-merge   branch 
'0.74.4-branch' of https://github.com/netbirdio/netbird
 37046431d74765914b23ee4c016d475e0c7a7d6d       not-for-merge   branch '0.74.x' 
of https://github.com/netbirdio/netbird
 1e24916daca9d8315064f0047b10cb47297ae16d       not-for-merge   branch 
'account-refactoring' of https://github.com/netbirdio/netbird
 3945d2b170f84b90a9997df77bd7c8889c061de2       not-for-merge   branch 
'add-account-onboarding' of https://github.com/netbirdio/netbird
@@ -39,7 +39,7 @@
 8c5648bb7b522ca79c60d4d1481aa947249a6a92       not-for-merge   branch 
'coderabbitai/docstrings/b7e98ac' of https://github.com/netbirdio/netbird
 cb1eaf9e0d30daf1300dfa005abe9b10fe1a1adc       not-for-merge   branch 
'coderabbitai/utg/8ae8f20' of https://github.com/netbirdio/netbird
 a67d2426181217b55aca7e27c7f5cda620697a3e       not-for-merge   branch 
'components-impl-drop-indexes' of https://github.com/netbirdio/netbird
-d5178416af32040d6a88f461a1fd12efb0e1e11d       not-for-merge   branch 
'components-impl-drop-indexes-use-xids' of https://github.com/netbirdio/netbird
+671a5f11fdefe35b39700a1bc43925f8e8ff6dff       not-for-merge   branch 
'components-impl-drop-indexes-use-xids' of https://github.com/netbirdio/netbird
 572bea6a718be862bfcd6729e510d95e0ad37a6f       not-for-merge   branch 
'conntrack-stats' of https://github.com/netbirdio/netbird
 20a79c5c555b6ab78c7837b4ebf7f80b5967db98       not-for-merge   branch 
'crowdsec-selfhosted' of https://github.com/netbirdio/netbird
 dd301f2691410ab19009c8a004961df43fa31294       not-for-merge   branch 
'daemon-owner' of https://github.com/netbirdio/netbird
@@ -56,8 +56,8 @@
 0cf6ece217c3d2dcf9a05351679b3d71dc081904       not-for-merge   branch 
'debug-keycloak-idp' of https://github.com/netbirdio/netbird
 26ed186111c9d177488900f8237a93bc45a1f281       not-for-merge   branch 
'debug-local-records' of https://github.com/netbirdio/netbird
 24053750d90dbfc381fcbca9c9925443f51a4d8b       not-for-merge   branch 
'debug-user-role' of https://github.com/netbirdio/netbird
-6412cfc2e738578c4d060e7fb7e25eed02c5cb9f       not-for-merge   branch 
'dependabot/github_actions/actions-a940c7c866' of 
https://github.com/netbirdio/netbird
-3b0d193beb49894f2aacf0f2c8dc55ab4e330ac2       not-for-merge   branch 
'dependabot/go_modules/aws-sdk-8f849ebaed' of 
https://github.com/netbirdio/netbird
+51bbe704dca7a1f21c51c50f4a8564afb7ee0116       not-for-merge   branch 
'dependabot/github_actions/actions-a940c7c866' of 
https://github.com/netbirdio/netbird
+a8072f26d1390aab67af45cf5acdc60e552bbe34       not-for-merge   branch 
'dependabot/go_modules/aws-sdk-8f849ebaed' of 
https://github.com/netbirdio/netbird
 f1438f79956a930e3e8958c3327ffbad0e9b6c8a       not-for-merge   branch 
'dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1' of 
https://github.com/netbirdio/netbird
 237a0e709efbb052ebcc2273036df7ef7179cb9e       not-for-merge   branch 
'dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.105.0' of 
https://github.com/netbirdio/netbird
 e26b4808d51e4294d8c673a2a0fb86d5cd270546       not-for-merge   branch 
'dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0' of 
https://github.com/netbirdio/netbird
@@ -70,11 +70,11 @@
 9493b14fd154ad009806d83e70506637d1513ae6       not-for-merge   branch 
'dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0' of 
https://github.com/netbirdio/netbird
 29c752d818966adfe41827593165376559f9f65d       not-for-merge   branch 
'dependabot/go_modules/github.com/pkg/sftp-1.13.10' of 
https://github.com/netbirdio/netbird
 2fdd3bd411297f97f6bf46bb99c8114b88a8f916       not-for-merge   branch 
'dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3' of 
https://github.com/netbirdio/netbird
-0f8dcacde5efcd41a0429879820276bd4908d979       not-for-merge   branch 
'dependabot/go_modules/gorm-2271c8195b' of https://github.com/netbirdio/netbird
-2d095a415dc88bc85aaf77b86caf85ee18482974       not-for-merge   branch 
'dependabot/go_modules/otel-e34c790afd' of https://github.com/netbirdio/netbird
-ac56ddad9c1e368d11d530b1ab5ef20290e6238a       not-for-merge   branch 
'dependabot/go_modules/pion-5f703e1eca' of https://github.com/netbirdio/netbird
-7e75e57bee00f2911a4464f8fc40442d0264e791       not-for-merge   branch 
'dependabot/go_modules/testcontainers-de325c0dd6' of 
https://github.com/netbirdio/netbird
-16195b7eb75da8aaf49cab91b03a4e1118c9b3bf       not-for-merge   branch 
'dependabot/go_modules/wireguard-dbd6b95108' of 
https://github.com/netbirdio/netbird
+0a6aedd99547133cf38f71a6612782c813ae0222       not-for-merge   branch 
'dependabot/go_modules/gorm-2271c8195b' of https://github.com/netbirdio/netbird
+c067346459b74dc01ef0957301e2688ac03dd314       not-for-merge   branch 
'dependabot/go_modules/otel-e34c790afd' of https://github.com/netbirdio/netbird
+d6aef0d65e115208d06a7d37f3ab8de75df1b587       not-for-merge   branch 
'dependabot/go_modules/pion-5f703e1eca' of https://github.com/netbirdio/netbird
+db2bec30c43551af0e127c3fc68fe2060e075ca3       not-for-merge   branch 
'dependabot/go_modules/testcontainers-de325c0dd6' of 
https://github.com/netbirdio/netbird
+bc1d7f43b141d87169f09cd63607dc12b11b064b       not-for-merge   branch 
'dependabot/go_modules/wireguard-dbd6b95108' of 
https://github.com/netbirdio/netbird
 90f6e7efd3c68b259ef1053d0738f4652ab5805f       not-for-merge   branch 
'dependabot/npm_and_yarn/client/ui/frontend/npm_and_yarn-88714b13d0' of 
https://github.com/netbirdio/netbird
 8c44187900ec87c8d484881d4e25ad253d73a168       not-for-merge   branch 
'deploy/peer-performance' of https://github.com/netbirdio/netbird
 93c0172c8afca58da00823e8a0b3ee831e746832       not-for-merge   branch 
'deploy/permissions-account' of https://github.com/netbirdio/netbird
@@ -95,7 +95,7 @@
 7d8700c847554ed94fe8b4fc1e47455913884161       not-for-merge   branch 
'e2e-windows-dns-combined' of https://github.com/netbirdio/netbird
 b78ec082a3178d8a05f865e0c1619f077338be59       not-for-merge   branch 'ebpf' 
of https://github.com/netbirdio/netbird
 d02b8cbc970ee3966d9322a3490d1407ba7ae220       not-for-merge   branch 
'ebpf-debug' of https://github.com/netbirdio/netbird
-fd7bf982c3b16bac8c4d066e9ad121bb12f8ca60       not-for-merge   branch 
'embedded-vnc' of https://github.com/netbirdio/netbird
+152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0       not-for-merge   branch 
'embedded-vnc' of https://github.com/netbirdio/netbird
 f0a8e32c82200608fc33ff6946c0219941535829       not-for-merge   branch 
'enable-release-workflow-on-pr' of https://github.com/netbirdio/netbird
 60a1bfcfc18bbbfcc894d24c3ba9e5a83886cc24       not-for-merge   branch 
'enable-udp-port-for-docker-template' of https://github.com/netbirdio/netbird
 820ea80e689e5f4cbade0e926d0c615710c1c384       not-for-merge   branch 
'ensure-schedule-never-runs-non-positive' of 
https://github.com/netbirdio/netbird
@@ -141,6 +141,7 @@
 829ce6573e9528518bcc23ca97b1ba3f1e381d7f       not-for-merge   branch 
'feature/device-authentication-with-client-secret' of 
https://github.com/netbirdio/netbird
 e28e9854fef34dc04189a53d52b9b58714bb937f       not-for-merge   branch 
'feature/disable-legacy-port' of https://github.com/netbirdio/netbird
 279e96e6b155a31fba73a8bc80b3280cdd917663       not-for-merge   branch 
'feature/disk-encryption-check' of https://github.com/netbirdio/netbird
+03252696b95abb7df8707eac056242153482b3bc       not-for-merge   branch 
'feature/dns-lazy-conn-warmup' of https://github.com/netbirdio/netbird
 213ab7d43e001b03fc7ad08fc78c544cf3c736fe       not-for-merge   branch 
'feature/event-storage' of https://github.com/netbirdio/netbird
 997bb12771ac2c6ac95d2361a3812f88c90d8d11       not-for-merge   branch 
'feature/exclude-terraform-from-rate-limiting' of 
https://github.com/netbirdio/netbird
 55781d1e9dfcc65096b9ec57bf3361bf744fc3f6       not-for-merge   branch 
'feature/expose-has-channel' of https://github.com/netbirdio/netbird
@@ -191,6 +192,7 @@
 1b39bcaedf00dda73c565a3b70e1b3d0e1e3e732       not-for-merge   branch 
'feature/users-roles-endpoint' of https://github.com/netbirdio/netbird
 2f15708d546525832f5e3590a5b3585882a23efc       not-for-merge   branch 
'feature/validate-group-association-debug' of 
https://github.com/netbirdio/netbird
 3613a70c8c71c33dfc502b908ed0d31ede46e683       not-for-merge   branch 
'filter-cache-on-load-account' of https://github.com/netbirdio/netbird
+8e387b5dc5afebefc40abba2d80303be2c7f6eeb       not-for-merge   branch 
'fix-browser-dialog-not-closing' of https://github.com/netbirdio/netbird
 69752b7cb7da156cc4f4b0acfe4c745c9f1541d8       not-for-merge   branch 
'fix-darwin-uninstaller' of https://github.com/netbirdio/netbird
 26ed91652de1337c69dde5a1cf6736a728346b26       not-for-merge   branch 
'fix-install-version' of https://github.com/netbirdio/netbird
 3cdfa11cb83565567163e03074647c852e84d42c       not-for-merge   branch 
'fix-mgmt-cache-bypass-overlay' of https://github.com/netbirdio/netbird
@@ -214,7 +216,6 @@
 56d82a99e15b0e88f4b102725b859210136d0a40       not-for-merge   branch 
'fix/events-key-handling' of https://github.com/netbirdio/netbird
 59a09b0ff30470577deaa3383e3f70dcfcf6c90e       not-for-merge   branch 
'fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall' of 
https://github.com/netbirdio/netbird
 5a4d3770660460620dd25649593f9c74fca869c8       not-for-merge   branch 
'fix/filter-cgnat-cni-ice-candidates' of https://github.com/netbirdio/netbird
-8732d3cd139b04c4d0e101d45e9482397186b7b1       not-for-merge   branch 
'fix/forwarders_exclusion_from_lazy_conn' of 
https://github.com/netbirdio/netbird
 1e630b5d45bfd5fd9fadc776f522de2fc39a0ccf       not-for-merge   branch 
'fix/geo-download' of https://github.com/netbirdio/netbird
 e32ad68f98eb19e9b9ec0adb42d4840bd728e8cc       not-for-merge   branch 
'fix/getting-started' of https://github.com/netbirdio/netbird
 cbb9f9f56275b6f6c7ac343acd4dbb5b7f77a065       not-for-merge   branch 
'fix/go-mod-version' of https://github.com/netbirdio/netbird
@@ -235,6 +236,7 @@
 29d6630686bea0d5fff422e7408786f3bcfc09ee       not-for-merge   branch 
'fix/mysql-setup' of https://github.com/netbirdio/netbird
 0cd22a2f978066b48658653fe505caae681e2b9f       not-for-merge   branch 
'fix/nmap-exitnodes' of https://github.com/netbirdio/netbird
 dae8a86f33648be4adb754ccc8a4526dc7c72905       not-for-merge   branch 
'fix/nmap-fwrules' of https://github.com/netbirdio/netbird
+efad9075e77d034c8a21567dc01d1de90f8bc367       not-for-merge   branch 
'fix/nsis-preserve-autostart-on-upgrade' of https://github.com/netbirdio/netbird
 c92ca4a0dc8a0cad63d3756025b54783d66f5f01       not-for-merge   branch 
'fix/peer_list_notification' of https://github.com/netbirdio/netbird
 d9bcdcf149d45b07d3b7725faf7691c097b50aff       not-for-merge   branch 
'fix/proxy_close' of https://github.com/netbirdio/netbird
 5d403a79ba285d09ee4c132daf6c8c73e885f78e       not-for-merge   branch 
'fix/relay-reconnection' of https://github.com/netbirdio/netbird
@@ -245,6 +247,8 @@
 99a7073592decbbab8283299ac03c462ed721c96       not-for-merge   branch 
'fix/remove-gpo-if-empty' of https://github.com/netbirdio/netbird
 68996a1566837dda26b7106892992c716e8dbc8b       not-for-merge   branch 
'fix/remove-logout-btn' of https://github.com/netbirdio/netbird
 4b5e39c574f874969abbb484423fb72d093bbf24       not-for-merge   branch 
'fix/remove-otel-units' of https://github.com/netbirdio/netbird
+cdde472266fddbf3e18df7e35673eda067f51c69       not-for-merge   branch 
'fix/remove-stale-peers-removal' of https://github.com/netbirdio/netbird
+525a4fb29c43d405b5c50a0081599c8f3ab8d804       not-for-merge   branch 
'fix/remove-stale-proxy-logic' of https://github.com/netbirdio/netbird
 e3c66ced13de40333962f4a1e738b32b4335d2f2       not-for-merge   branch 
'fix/revert-ice-filter' of https://github.com/netbirdio/netbird
 9be7e33a07b501799581d77949a2607fab5bb7c9       not-for-merge   branch 
'fix/route' of https://github.com/netbirdio/netbird
 e22976a89e7f2d6c2a5fa4583be9a24b01c63dbf       not-for-merge   branch 
'fix/routeselector-atomic-exit-node' of https://github.com/netbirdio/netbird
@@ -269,6 +273,8 @@
 4ff5ed756da87f0069f7eada2c89c1e53f84d1b4       not-for-merge   branch 
'increase-sysinfo-timeout' of https://github.com/netbirdio/netbird
 f894da0b11b61e000179520444e39d9ef838a974       not-for-merge   branch 
'job-stream-notify-disconnection-eof' of https://github.com/netbirdio/netbird
 4eeaf95ab80daa0d12e33afe8cfd5d7ffd33a8f0       not-for-merge   branch 
'job-yml-update' of https://github.com/netbirdio/netbird
+99ceb9b7a0c72e5beb94aab9250821080ba4527f       not-for-merge   branch 
'lazy-conn-per-peer' of https://github.com/netbirdio/netbird
+d438db50012b7abeeda0829c373abb0a41f0306e       not-for-merge   branch 
'lazy-conn-rosenpass' of https://github.com/netbirdio/netbird
 acb2b9d619d1b08a0a1fa8973926caf5430d1894       not-for-merge   branch 
'lazyconn-first-packet-fix-v2' of https://github.com/netbirdio/netbird
 4787e28ae3c687b5bb40ab71271868fd210d246a       not-for-merge   branch 
'loadtest-signal' of https://github.com/netbirdio/netbird
 affa8bf348107386d3ab5eabc617ac79350283fd       not-for-merge   branch 
'log-checks' of https://github.com/netbirdio/netbird
@@ -276,7 +282,7 @@
 97ad3307ddb9e07f40a71eaa9489ca74947a6791       not-for-merge   branch 
'log/conn-disconn' of https://github.com/netbirdio/netbird
 a69dc29e7e7e24cf6cf7746632d7b8046c0a70e7       not-for-merge   branch 
'log/getaccount-by-peer' of https://github.com/netbirdio/netbird
 0886b67ce951e5827d87571ac079b6f516027915       not-for-merge   branch 
'logs/peerlogs-addpeer' of https://github.com/netbirdio/netbird
-30d15ecc3d9bf69161f8a8eda597acb78a29b602       not-for-merge   branch 'main' 
of https://github.com/netbirdio/netbird
+c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3       not-for-merge   branch 'main' 
of https://github.com/netbirdio/netbird
 b03343bc4d249af295a4833161289d8339a0052a       not-for-merge   branch 
'manual-peer-logout' of https://github.com/netbirdio/netbird
 b2c5732847ae5c22ab8f526204d9f121df72869e       not-for-merge   branch 
'mdm_integration' of https://github.com/netbirdio/netbird
 6efc1a61fe8568c3ae0704329aa2589c537e801b       not-for-merge   branch 
'merged-fixes' of https://github.com/netbirdio/netbird
@@ -332,6 +338,7 @@
 780890f9e607da27cae8facd37c04d43b043a61c       not-for-merge   branch 
'refactor/nmap' of https://github.com/netbirdio/netbird
 575b176371a8da362094b8b94137076a11b22249       not-for-merge   branch 
'refactor/nmap-limit-buffer' of https://github.com/netbirdio/netbird
 0aeac50803f572040ef23d82867df172359807dd       not-for-merge   branch 
'refactor/optimize-peer-expiration' of https://github.com/netbirdio/netbird
+753925032ab2b604abafc90eadebb44ef16e9e38       not-for-merge   branch 
'refactor/peer-event-bus' of https://github.com/netbirdio/netbird
 9b10d74ab8029410cf63ac3c4c0405d0aa01fd50       not-for-merge   branch 
'refactor/permissions-manager' of https://github.com/netbirdio/netbird
 e4fea16c9f188a105eaee5e4c8c72a300fecdebf       not-for-merge   branch 
'refactor/permissions-no-pat-allowed' of https://github.com/netbirdio/netbird
 6ce67f383e7610ead4404624bcdfda2998d18c33       not-for-merge   branch 
'refactor/reducate-signaling' of https://github.com/netbirdio/netbird
@@ -436,7 +443,6 @@
 485a38a4a86b595bbc3afc2973610d1c61f6c8fe       not-for-merge   branch 
'wasmbuild-test' of https://github.com/netbirdio/netbird
 940367e1c64cb6ebe280c8e35bf182ce6fed4d3a       not-for-merge   branch 
'wg_bind_parallel_processing' of https://github.com/netbirdio/netbird
 d66b425bb674eb69050d27d45a72db049db3de34       not-for-merge   branch 
'wg_conn_fix' of https://github.com/netbirdio/netbird
-5740dd22e6c0ce4d5a27504685bc61709f23be20       not-for-merge   branch 
'wg_watcher_debounce' of https://github.com/netbirdio/netbird
 dd13b8f27eabb649952754071e5165515887d3ee       not-for-merge   branch 
'wgwatcher-test' of https://github.com/netbirdio/netbird
 9157b749459ad64620c36178fb26eac40e9ca805       not-for-merge   branch 
'windows-dns-firewall' of https://github.com/netbirdio/netbird
 e3d1b9ca880ff4f1e6624e306b6957aa6c30e5c1       not-for-merge   branch 
'windows-search-domains' of https://github.com/netbirdio/netbird
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/HEAD new/netbird-0.74.5/.git/HEAD
--- old/netbird-0.74.4/.git/HEAD        2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/HEAD        2026-07-14 20:13:00.000000000 +0200
@@ -1 +1 @@
-3d87547d952f5ada9df987bbe4f0f6d54372d77c
+f0eed7564f3a9138962da1408986e4666d7137b5
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/ORIG_HEAD 
new/netbird-0.74.5/.git/ORIG_HEAD
--- old/netbird-0.74.4/.git/ORIG_HEAD   2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/ORIG_HEAD   2026-07-14 20:13:00.000000000 +0200
@@ -1 +1 @@
-3d87547d952f5ada9df987bbe4f0f6d54372d77c
+f0eed7564f3a9138962da1408986e4666d7137b5
Binary files old/netbird-0.74.4/.git/index and new/netbird-0.74.5/.git/index 
differ
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/logs/HEAD 
new/netbird-0.74.5/.git/logs/HEAD
--- old/netbird-0.74.4/.git/logs/HEAD   2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/logs/HEAD   2026-07-14 20:13:00.000000000 +0200
@@ -36,3 +36,4 @@
 859fe19fff6661ed0ba7904b42ed8b12d72c36f5 
3aa6c02b932db503e82f9530dddfe95d5ea212c4 Marcus Rückert <[email protected]> 
1783104338 +0200 checkout: moving from 859fe19fff6661ed0ba7904b42ed8b12d72c36f5 
to v0.74.2
 3aa6c02b932db503e82f9530dddfe95d5ea212c4 
7cd5c1732bb5374f21005073937c42f4d531e3c5 Marcus Rückert <[email protected]> 
1783537366 +0200 checkout: moving from 3aa6c02b932db503e82f9530dddfe95d5ea212c4 
to v0.74.3
 7cd5c1732bb5374f21005073937c42f4d531e3c5 
3d87547d952f5ada9df987bbe4f0f6d54372d77c Marcus Rückert <[email protected]> 
1783772566 +0200 checkout: moving from 7cd5c1732bb5374f21005073937c42f4d531e3c5 
to v0.74.4
+3d87547d952f5ada9df987bbe4f0f6d54372d77c 
f0eed7564f3a9138962da1408986e4666d7137b5 Marcus Rückert <[email protected]> 
1784064470 +0200 checkout: moving from 3d87547d952f5ada9df987bbe4f0f6d54372d77c 
to v0.74.5
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/0.74.4-branch 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/0.74.4-branch
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/0.74.4-branch      
2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/0.74.4-branch      
2026-07-14 20:13:00.000000000 +0200
@@ -1 +1,2 @@
 0000000000000000000000000000000000000000 
3d87547d952f5ada9df987bbe4f0f6d54372d77c Marcus Rückert <[email protected]> 
1783772549 +0200 pull: storing head
+3d87547d952f5ada9df987bbe4f0f6d54372d77c 
f0eed7564f3a9138962da1408986e4666d7137b5 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: fast-forward
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids
      2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/components-impl-drop-indexes-use-xids
      2026-07-14 20:13:00.000000000 +0200
@@ -1 +1,2 @@
 0000000000000000000000000000000000000000 
d5178416af32040d6a88f461a1fd12efb0e1e11d Marcus Rückert <[email protected]> 
1783772549 +0200 pull: storing head
+d5178416af32040d6a88f461a1fd12efb0e1e11d 
671a5f11fdefe35b39700a1bc43925f8e8ff6dff Marcus Rückert <[email protected]> 
1784064464 +0200 pull: fast-forward
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
       2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
       2026-07-14 20:13:00.000000000 +0200
@@ -1,2 +1,3 @@
 0000000000000000000000000000000000000000 
ab15063b7cda53f8d4074f8f539a37935d254164 Marcus Rückert <[email protected]> 
1783537343 +0200 pull: storing head
 ab15063b7cda53f8d4074f8f539a37935d254164 
6412cfc2e738578c4d060e7fb7e25eed02c5cb9f Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+6412cfc2e738578c4d060e7fb7e25eed02c5cb9f 
51bbe704dca7a1f21c51c50f4a8564afb7ee0116 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
   2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
   2026-07-14 20:13:00.000000000 +0200
@@ -3,3 +3,4 @@
 3d59ab9730ba0c2662901eab4c947e4dcfda0474 
a721675b11767b2771121760ae2dbdc00e67e300 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: forced-update
 a721675b11767b2771121760ae2dbdc00e67e300 
42bdc885bf94e11c7fa2210095afcf8f46ace96c Marcus Rückert <[email protected]> 
1783537343 +0200 pull: forced-update
 42bdc885bf94e11c7fa2210095afcf8f46ace96c 
3b0d193beb49894f2aacf0f2c8dc55ab4e330ac2 Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+3b0d193beb49894f2aacf0f2c8dc55ab4e330ac2 
a8072f26d1390aab67af45cf5acdc60e552bbe34 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
      2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
      2026-07-14 20:13:00.000000000 +0200
@@ -9,3 +9,4 @@
 1d7a2a5ace003824e2cea472b9c815f901b0c15c 
d77d78720c57ac6e1ae613f1f171bc9911e45549 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: forced-update
 d77d78720c57ac6e1ae613f1f171bc9911e45549 
5cb92bc0ba6f7ee0171efd0388d64e372e1624bd Marcus Rückert <[email protected]> 
1783537343 +0200 pull: forced-update
 5cb92bc0ba6f7ee0171efd0388d64e372e1624bd 
0f8dcacde5efcd41a0429879820276bd4908d979 Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+0f8dcacde5efcd41a0429879820276bd4908d979 
0a6aedd99547133cf38f71a6612782c813ae0222 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
      2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
      2026-07-14 20:13:00.000000000 +0200
@@ -9,3 +9,4 @@
 92a949ef5a935af8485de0361c32a682a9c06770 
94e6c40446f8ba80930319cd25fbf15d554272a7 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: forced-update
 94e6c40446f8ba80930319cd25fbf15d554272a7 
0cc6cab8ea7f52499df19c9ee7db70a746490876 Marcus Rückert <[email protected]> 
1783537343 +0200 pull: forced-update
 0cc6cab8ea7f52499df19c9ee7db70a746490876 
2d095a415dc88bc85aaf77b86caf85ee18482974 Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+2d095a415dc88bc85aaf77b86caf85ee18482974 
c067346459b74dc01ef0957301e2688ac03dd314 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
      2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
      2026-07-14 20:13:00.000000000 +0200
@@ -3,3 +3,4 @@
 d8e98f4fb51f476cccbe0e771ea0041954b0bd5d 
5a2660e796bf697dd0c00c09bc0c2338e93c4695 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: forced-update
 5a2660e796bf697dd0c00c09bc0c2338e93c4695 
6d792269cbc7724adbfaca7607d6c96c7c58ce95 Marcus Rückert <[email protected]> 
1783537343 +0200 pull: forced-update
 6d792269cbc7724adbfaca7607d6c96c7c58ce95 
ac56ddad9c1e368d11d530b1ab5ef20290e6238a Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+ac56ddad9c1e368d11d530b1ab5ef20290e6238a 
d6aef0d65e115208d06a7d37f3ab8de75df1b587 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
    2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
    2026-07-14 20:13:00.000000000 +0200
@@ -3,3 +3,4 @@
 f14100f1ab2a1a502a7bfd3b19af6ff6bb8faf1f 
75ac15c52e36877590418a260f31880b75a412a9 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: forced-update
 75ac15c52e36877590418a260f31880b75a412a9 
19b40b509a22fdaeb25880f6b01acf5c0170757d Marcus Rückert <[email protected]> 
1783537343 +0200 pull: forced-update
 19b40b509a22fdaeb25880f6b01acf5c0170757d 
7e75e57bee00f2911a4464f8fc40442d0264e791 Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+7e75e57bee00f2911a4464f8fc40442d0264e791 
db2bec30c43551af0e127c3fc68fe2060e075ca3 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
 2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
 2026-07-14 20:13:00.000000000 +0200
@@ -9,3 +9,4 @@
 af04a89eee82e2b02bd4ae09d41677b89426cd28 
479a88ca9f58cdd095beb7d05bcc393d3d1b7cb1 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: forced-update
 479a88ca9f58cdd095beb7d05bcc393d3d1b7cb1 
d7aa9e97852e8b77592a598e5e4791501ec26e31 Marcus Rückert <[email protected]> 
1783537343 +0200 pull: forced-update
 d7aa9e97852e8b77592a598e5e4791501ec26e31 
16195b7eb75da8aaf49cab91b03a4e1118c9b3bf Marcus Rückert <[email protected]> 
1783772549 +0200 pull: forced-update
+16195b7eb75da8aaf49cab91b03a4e1118c9b3bf 
bc1d7f43b141d87169f09cd63607dc12b11b064b Marcus Rückert <[email protected]> 
1784064464 +0200 pull: forced-update
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/embedded-vnc 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/embedded-vnc
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/embedded-vnc       
2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/embedded-vnc       
2026-07-14 20:13:00.000000000 +0200
@@ -5,3 +5,4 @@
 144dfbc12c09333bb0c912c4678e2f518362a219 
f2c79201b314de93f5b7a8b5ab1fe36ec56c5b91 Marcus Rückert <[email protected]> 
1781122574 +0200 pull: fast-forward
 f2c79201b314de93f5b7a8b5ab1fe36ec56c5b91 
c1eecaac26458f5b1591c6e9bfa937e8f6821d3a Marcus Rückert <[email protected]> 
1781803432 +0200 pull: fast-forward
 c1eecaac26458f5b1591c6e9bfa937e8f6821d3a 
fd7bf982c3b16bac8c4d066e9ad121bb12f8ca60 Marcus Rückert <[email protected]> 
1782940252 +0200 pull: fast-forward
+fd7bf982c3b16bac8c4d066e9ad121bb12f8ca60 
152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: fast-forward
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup   
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/feature/dns-lazy-conn-warmup   
    2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
03252696b95abb7df8707eac056242153482b3bc Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn
    2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn
    1970-01-01 01:00:00.000000000 +0100
@@ -1 +0,0 @@
-0000000000000000000000000000000000000000 
8732d3cd139b04c4d0e101d45e9482397186b7b1 Marcus Rückert <[email protected]> 
1783537343 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
     1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
     2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
efad9075e77d034c8a21567dc01d1de90f8bc367 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal 
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-peers-removal 
    2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
cdde472266fddbf3e18df7e35673eda067f51c69 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic   
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix/remove-stale-proxy-logic   
    2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
525a4fb29c43d405b5c50a0081599c8f3ab8d804 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing
--- 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing 
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/fix-browser-dialog-not-closing 
    2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
8e387b5dc5afebefc40abba2d80303be2c7f6eeb Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-per-peer 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-per-peer
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-per-peer 
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-per-peer 
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
99ceb9b7a0c72e5beb94aab9250821080ba4527f Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-rosenpass 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-rosenpass
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/lazy-conn-rosenpass        
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/lazy-conn-rosenpass        
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
d438db50012b7abeeda0829c373abb0a41f0306e Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/logs/refs/remotes/origin/main 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/main
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/main       2026-07-10 
17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/main       2026-07-14 
20:13:00.000000000 +0200
@@ -33,3 +33,4 @@
 1dfa85a917eb47e23e4dc4c142056e67966a1c03 
3aa6c02b932db503e82f9530dddfe95d5ea212c4 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: fast-forward
 3aa6c02b932db503e82f9530dddfe95d5ea212c4 
488bbcb22bea59f01f3665b528f650d17bce7982 Marcus Rückert <[email protected]> 
1783537343 +0200 pull: fast-forward
 488bbcb22bea59f01f3665b528f650d17bce7982 
30d15ecc3d9bf69161f8a8eda597acb78a29b602 Marcus Rückert <[email protected]> 
1783772549 +0200 pull: fast-forward
+30d15ecc3d9bf69161f8a8eda597acb78a29b602 
c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: fast-forward
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/refactor/peer-event-bus 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/refactor/peer-event-bus
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/refactor/peer-event-bus    
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/refactor/peer-event-bus    
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0000000000000000000000000000000000000000 
753925032ab2b604abafc90eadebb44ef16e9e38 Marcus Rückert <[email protected]> 
1784064464 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/logs/refs/remotes/origin/wg_watcher_debounce 
new/netbird-0.74.5/.git/logs/refs/remotes/origin/wg_watcher_debounce
--- old/netbird-0.74.4/.git/logs/refs/remotes/origin/wg_watcher_debounce        
2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/logs/refs/remotes/origin/wg_watcher_debounce        
1970-01-01 01:00:00.000000000 +0100
@@ -1 +0,0 @@
-0000000000000000000000000000000000000000 
5740dd22e6c0ce4d5a27504685bc61709f23be20 Marcus Rückert <[email protected]> 
1783104333 +0200 pull: storing head
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/objects/info/commit-graphs/commit-graph-chain 
new/netbird-0.74.5/.git/objects/info/commit-graphs/commit-graph-chain
--- old/netbird-0.74.4/.git/objects/info/commit-graphs/commit-graph-chain       
2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/objects/info/commit-graphs/commit-graph-chain       
2026-07-14 20:13:00.000000000 +0200
@@ -1,4 +1,4 @@
 fdfa54f7b964ac9dc39761797c2fb0dfebb92f6e
 21e341b3c265ad9526898e416d4ab365d5ded8d1
 a6642bf4d8a835abc8fa2628838fb66da11b1ea9
-e937f7d3915de101583115ea91c75d659dcf99d2
+2532b695a7ed4462efc610f179dcbc0b23f2b1f3
Binary files 
old/netbird-0.74.4/.git/objects/info/commit-graphs/graph-2532b695a7ed4462efc610f179dcbc0b23f2b1f3.graph
 and 
new/netbird-0.74.5/.git/objects/info/commit-graphs/graph-2532b695a7ed4462efc610f179dcbc0b23f2b1f3.graph
 differ
Binary files 
old/netbird-0.74.4/.git/objects/info/commit-graphs/graph-e937f7d3915de101583115ea91c75d659dcf99d2.graph
 and 
new/netbird-0.74.5/.git/objects/info/commit-graphs/graph-e937f7d3915de101583115ea91c75d659dcf99d2.graph
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.idx
 and 
new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.idx
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.pack
 and 
new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.pack
 differ
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor
 
new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor
--- 
old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor
 1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.promisor
 2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+ef43882de764d6d54f7b819d70f32578c10d7776 
ef43882de764d6d54f7b819d70f32578c10d7776
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.rev
 and 
new/netbird-0.74.5/.git/objects/pack/pack-507b00b7cd914e4f1557ebdeb7ecd8f22190761d.rev
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.idx
 and 
new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.idx
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.pack
 and 
new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.pack
 differ
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor
 
new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor
--- 
old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor
 1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.promisor
 2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1,20 @@
+f0eed7564f3a9138962da1408986e4666d7137b5 refs/heads/0.74.4-branch
+671a5f11fdefe35b39700a1bc43925f8e8ff6dff 
refs/heads/components-impl-drop-indexes-use-xids
+51bbe704dca7a1f21c51c50f4a8564afb7ee0116 
refs/heads/dependabot/github_actions/actions-a940c7c866
+a8072f26d1390aab67af45cf5acdc60e552bbe34 
refs/heads/dependabot/go_modules/aws-sdk-8f849ebaed
+0a6aedd99547133cf38f71a6612782c813ae0222 
refs/heads/dependabot/go_modules/gorm-2271c8195b
+c067346459b74dc01ef0957301e2688ac03dd314 
refs/heads/dependabot/go_modules/otel-e34c790afd
+d6aef0d65e115208d06a7d37f3ab8de75df1b587 
refs/heads/dependabot/go_modules/pion-5f703e1eca
+db2bec30c43551af0e127c3fc68fe2060e075ca3 
refs/heads/dependabot/go_modules/testcontainers-de325c0dd6
+bc1d7f43b141d87169f09cd63607dc12b11b064b 
refs/heads/dependabot/go_modules/wireguard-dbd6b95108
+152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0 refs/heads/embedded-vnc
+03252696b95abb7df8707eac056242153482b3bc 
refs/heads/feature/dns-lazy-conn-warmup
+8e387b5dc5afebefc40abba2d80303be2c7f6eeb 
refs/heads/fix-browser-dialog-not-closing
+efad9075e77d034c8a21567dc01d1de90f8bc367 
refs/heads/fix/nsis-preserve-autostart-on-upgrade
+cdde472266fddbf3e18df7e35673eda067f51c69 
refs/heads/fix/remove-stale-peers-removal
+525a4fb29c43d405b5c50a0081599c8f3ab8d804 
refs/heads/fix/remove-stale-proxy-logic
+99ceb9b7a0c72e5beb94aab9250821080ba4527f refs/heads/lazy-conn-per-peer
+d438db50012b7abeeda0829c373abb0a41f0306e refs/heads/lazy-conn-rosenpass
+c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3 refs/heads/main
+753925032ab2b604abafc90eadebb44ef16e9e38 refs/heads/refactor/peer-event-bus
+f0eed7564f3a9138962da1408986e4666d7137b5 refs/tags/v0.74.5
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.rev
 and 
new/netbird-0.74.5/.git/objects/pack/pack-a9a7d1698b8f5149535a9214fdd8531ee5667e66.rev
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.idx
 and 
new/netbird-0.74.5/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.idx
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.pack
 and 
new/netbird-0.74.5/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.pack
 differ
Binary files 
old/netbird-0.74.4/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.rev
 and 
new/netbird-0.74.5/.git/objects/pack/pack-ad48e0c9673a9312dad3c71a8986231ac0739914.rev
 differ
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/packed-refs 
new/netbird-0.74.5/.git/packed-refs
--- old/netbird-0.74.4/.git/packed-refs 2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/.git/packed-refs 2026-07-14 20:13:00.000000000 +0200
@@ -216,7 +216,6 @@
 56d82a99e15b0e88f4b102725b859210136d0a40 
refs/remotes/origin/fix/events-key-handling
 59a09b0ff30470577deaa3383e3f70dcfcf6c90e 
refs/remotes/origin/fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
 5a4d3770660460620dd25649593f9c74fca869c8 
refs/remotes/origin/fix/filter-cgnat-cni-ice-candidates
-8732d3cd139b04c4d0e101d45e9482397186b7b1 
refs/remotes/origin/fix/forwarders_exclusion_from_lazy_conn
 1e630b5d45bfd5fd9fadc776f522de2fc39a0ccf refs/remotes/origin/fix/geo-download
 e32ad68f98eb19e9b9ec0adb42d4840bd728e8cc 
refs/remotes/origin/fix/getting-started
 cbb9f9f56275b6f6c7ac343acd4dbb5b7f77a065 refs/remotes/origin/fix/go-mod-version
@@ -438,7 +437,6 @@
 485a38a4a86b595bbc3afc2973610d1c61f6c8fe refs/remotes/origin/wasmbuild-test
 940367e1c64cb6ebe280c8e35bf182ce6fed4d3a 
refs/remotes/origin/wg_bind_parallel_processing
 d66b425bb674eb69050d27d45a72db049db3de34 refs/remotes/origin/wg_conn_fix
-5740dd22e6c0ce4d5a27504685bc61709f23be20 
refs/remotes/origin/wg_watcher_debounce
 dd13b8f27eabb649952754071e5165515887d3ee refs/remotes/origin/wgwatcher-test
 9157b749459ad64620c36178fb26eac40e9ca805 
refs/remotes/origin/windows-dns-firewall
 e3d1b9ca880ff4f1e6624e306b6957aa6c30e5c1 
refs/remotes/origin/windows-search-domains
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/0.74.4-branch 
new/netbird-0.74.5/.git/refs/remotes/origin/0.74.4-branch
--- old/netbird-0.74.4/.git/refs/remotes/origin/0.74.4-branch   1970-01-01 
01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/0.74.4-branch   2026-07-14 
20:13:00.000000000 +0200
@@ -0,0 +1 @@
+f0eed7564f3a9138962da1408986e4666d7137b5
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids
 
new/netbird-0.74.5/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/components-impl-drop-indexes-use-xids
   2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+671a5f11fdefe35b39700a1bc43925f8e8ff6dff
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/github_actions/actions-a940c7c866
    2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+51bbe704dca7a1f21c51c50f4a8564afb7ee0116
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
        1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/aws-sdk-8f849ebaed
        2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+a8072f26d1390aab67af45cf5acdc60e552bbe34
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/gorm-2271c8195b
   2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+0a6aedd99547133cf38f71a6612782c813ae0222
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/otel-e34c790afd
   2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+c067346459b74dc01ef0957301e2688ac03dd314
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/pion-5f703e1eca
   2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+d6aef0d65e115208d06a7d37f3ab8de75df1b587
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
 1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/testcontainers-de325c0dd6
 2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+db2bec30c43551af0e127c3fc68fe2060e075ca3
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
      1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/dependabot/go_modules/wireguard-dbd6b95108
      2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+bc1d7f43b141d87169f09cd63607dc12b11b064b
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/embedded-vnc 
new/netbird-0.74.5/.git/refs/remotes/origin/embedded-vnc
--- old/netbird-0.74.4/.git/refs/remotes/origin/embedded-vnc    1970-01-01 
01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/embedded-vnc    2026-07-14 
20:13:00.000000000 +0200
@@ -0,0 +1 @@
+152ba28d9f6bd0b05c40a6f5b5f88cac049b79f0
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup 
new/netbird-0.74.5/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup
--- old/netbird-0.74.4/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup    
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/feature/dns-lazy-conn-warmup    
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+03252696b95abb7df8707eac056242153482b3bc
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
 
new/netbird-0.74.5/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
--- 
old/netbird-0.74.4/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
  1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/.git/refs/remotes/origin/fix/nsis-preserve-autostart-on-upgrade
  2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+efad9075e77d034c8a21567dc01d1de90f8bc367
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-peers-removal 
new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-peers-removal
--- old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-peers-removal  
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-peers-removal  
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+cdde472266fddbf3e18df7e35673eda067f51c69
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-proxy-logic 
new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-proxy-logic
--- old/netbird-0.74.4/.git/refs/remotes/origin/fix/remove-stale-proxy-logic    
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/fix/remove-stale-proxy-logic    
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+525a4fb29c43d405b5c50a0081599c8f3ab8d804
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/fix-browser-dialog-not-closing 
new/netbird-0.74.5/.git/refs/remotes/origin/fix-browser-dialog-not-closing
--- old/netbird-0.74.4/.git/refs/remotes/origin/fix-browser-dialog-not-closing  
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/fix-browser-dialog-not-closing  
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+8e387b5dc5afebefc40abba2d80303be2c7f6eeb
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-per-peer 
new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-per-peer
--- old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-per-peer      
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-per-peer      
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+99ceb9b7a0c72e5beb94aab9250821080ba4527f
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-rosenpass 
new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-rosenpass
--- old/netbird-0.74.4/.git/refs/remotes/origin/lazy-conn-rosenpass     
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/lazy-conn-rosenpass     
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+d438db50012b7abeeda0829c373abb0a41f0306e
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/refs/remotes/origin/main 
new/netbird-0.74.5/.git/refs/remotes/origin/main
--- old/netbird-0.74.4/.git/refs/remotes/origin/main    1970-01-01 
01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/main    2026-07-14 
20:13:00.000000000 +0200
@@ -0,0 +1 @@
+c6bf5fbbfb8324bfd66f787585d6670bc1b5a3f3
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/.git/refs/remotes/origin/refactor/peer-event-bus 
new/netbird-0.74.5/.git/refs/remotes/origin/refactor/peer-event-bus
--- old/netbird-0.74.4/.git/refs/remotes/origin/refactor/peer-event-bus 
1970-01-01 01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/remotes/origin/refactor/peer-event-bus 
2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1 @@
+753925032ab2b604abafc90eadebb44ef16e9e38
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/refs/tags/v0.74.5 
new/netbird-0.74.5/.git/refs/tags/v0.74.5
--- old/netbird-0.74.4/.git/refs/tags/v0.74.5   1970-01-01 01:00:00.000000000 
+0100
+++ new/netbird-0.74.5/.git/refs/tags/v0.74.5   2026-07-14 20:13:00.000000000 
+0200
@@ -0,0 +1 @@
+f0eed7564f3a9138962da1408986e4666d7137b5
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/.git/refs/tags/v0.75.0-rc.6 
new/netbird-0.74.5/.git/refs/tags/v0.75.0-rc.6
--- old/netbird-0.74.4/.git/refs/tags/v0.75.0-rc.6      1970-01-01 
01:00:00.000000000 +0100
+++ new/netbird-0.74.5/.git/refs/tags/v0.75.0-rc.6      2026-07-14 
20:13:00.000000000 +0200
@@ -0,0 +1 @@
+62703ca23e97073869bb723b64a0f738c465d93b
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/e2e/agentnetwork/chat_test.go 
new/netbird-0.74.5/e2e/agentnetwork/chat_test.go
--- old/netbird-0.74.4/e2e/agentnetwork/chat_test.go    2026-07-10 
17:42:06.000000000 +0200
+++ new/netbird-0.74.5/e2e/agentnetwork/chat_test.go    2026-07-14 
20:13:00.000000000 +0200
@@ -91,7 +91,7 @@
                if region == "" {
                        region = "us-east-1"
                }
-               ps = append(ps, providerCase{name: "bedrock", catalogID: 
"bedrock_api", upstream: "https://bedrock-runtime."; + region + 
".amazonaws.com", apiKey: k, model: "us.anthropic.claude-haiku-4-5", kind: 
harness.WireMessages})
+               ps = append(ps, providerCase{name: "bedrock", catalogID: 
"bedrock_api", upstream: "https://bedrock-runtime."; + region + 
".amazonaws.com", apiKey: k, model: "us.anthropic.claude-haiku-4-5", kind: 
harness.WireBedrock})
        }
        return ps
 }
@@ -224,9 +224,12 @@
                                var c int
                                var b string
                                var cerr error
-                               if pc.kind == harness.WireVertex {
+                               switch pc.kind {
+                               case harness.WireVertex:
                                        c, b, cerr = cl.Vertex(ctx, 
settings.Endpoint, proxyIP, pc.project, pc.region, pc.model, "Reply with 
exactly: pong", sessionID)
-                               } else {
+                               case harness.WireBedrock:
+                                       c, b, cerr = cl.Bedrock(ctx, 
settings.Endpoint, proxyIP, pc.model, "Reply with exactly: pong", sessionID)
+                               default:
                                        c, b, cerr = cl.Chat(ctx, 
settings.Endpoint, proxyIP, pc.kind, pc.model, "Reply with exactly: pong", 
sessionID)
                                }
                                if cerr == nil {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/e2e/agentnetwork/guardrail_test.go 
new/netbird-0.74.5/e2e/agentnetwork/guardrail_test.go
--- old/netbird-0.74.4/e2e/agentnetwork/guardrail_test.go       1970-01-01 
01:00:00.000000000 +0100
+++ new/netbird-0.74.5/e2e/agentnetwork/guardrail_test.go       2026-07-14 
20:13:00.000000000 +0200
@@ -0,0 +1,168 @@
+//go:build e2e
+
+package agentnetwork
+
+import (
+       "context"
+       "strings"
+       "testing"
+       "time"
+
+       "github.com/stretchr/testify/assert"
+       "github.com/stretchr/testify/require"
+
+       "github.com/netbirdio/netbird/e2e/harness"
+       "github.com/netbirdio/netbird/shared/management/http/api"
+)
+
+// catalogModel returns the normalized catalog id the proxy stamps for a
+// path-routed provider's configured model — the form the guardrail allowlist 
is
+// compared against (region prefix / @version stripped).
+func catalogModel(pc providerCase) string {
+       switch pc.kind {
+       case harness.WireBedrock:
+               return strings.TrimPrefix(pc.model, "us.")
+       case harness.WireVertex:
+               return strings.SplitN(pc.model, "@", 2)[0]
+       default:
+               return pc.model
+       }
+}
+
+// disallowedModel returns a valid-shaped model id for the provider that is NOT
+// the configured/allowed one, so the guardrail must reject it before the
+// request ever reaches the upstream.
+func disallowedModel(pc providerCase) string {
+       switch pc.kind {
+       case harness.WireBedrock:
+               return "us.anthropic.claude-opus-4-8"
+       case harness.WireVertex:
+               return "claude-opus-4-8@20250101"
+       default:
+               return "unlisted-model"
+       }
+}
+
+// sendModel drives one request for the given model through the provider's 
native
+// wire shape and returns the HTTP status.
+func sendModel(ctx context.Context, t *testing.T, cl *harness.Client, 
endpoint, proxyIP string, pc providerCase, model string) int {
+       t.Helper()
+       var code int
+       var err error
+       switch pc.kind {
+       case harness.WireBedrock:
+               code, _, err = cl.Bedrock(ctx, endpoint, proxyIP, model, "Reply 
with exactly: pong", "")
+       case harness.WireVertex:
+               code, _, err = cl.Vertex(ctx, endpoint, proxyIP, pc.project, 
pc.region, model, "Reply with exactly: pong", "")
+       default:
+               code, _, err = cl.Chat(ctx, endpoint, proxyIP, pc.kind, model, 
"Reply with exactly: pong", "")
+       }
+       require.NoError(t, err, "request must reach the proxy for %s", pc.name)
+       return code
+}
+
+// TestModelAllowlistEnforced provisions a Model Allowlist guardrail limiting 
each
+// path-routed provider (Bedrock, Vertex) to its configured model, then drives
+// requests over the tunnel: the allowed model returns 200 while a model 
outside
+// the allowlist is denied 403 by the guardrail before it reaches the upstream.
+// This is the coverage missing for #6751 — the model for these providers 
travels
+// in the URL path, and the allowlist must be enforced there.
+func TestModelAllowlistEnforced(t *testing.T) {
+       var providers []providerCase
+       for _, pc := range availableProviders() {
+               if pc.kind == harness.WireBedrock || pc.kind == 
harness.WireVertex {
+                       providers = append(providers, pc)
+               }
+       }
+       if len(providers) == 0 {
+               t.Skip("no path-routed provider keys set 
(AWS_BEARER_TOKEN_BEDROCK / GOOGLE_VERTEX_*); source ~/.llm-keys")
+       }
+
+       ctx, cancel := context.WithTimeout(context.Background(), 20*time.Minute)
+       defer cancel()
+
+       grp, err := srv.API().Groups.Create(ctx, 
api.PostApiGroupsJSONRequestBody{Name: "e2e-allowlist"})
+       require.NoError(t, err, "create group")
+       t.Cleanup(func() { _ = srv.API().Groups.Delete(context.Background(), 
grp.Id) })
+
+       ephemeral := false
+       sk, err := srv.API().SetupKeys.Create(ctx, 
api.PostApiSetupKeysJSONRequestBody{
+               Name:       "e2e-allowlist-client",
+               Type:       "reusable",
+               ExpiresIn:  86400,
+               UsageLimit: 0,
+               AutoGroups: []string{grp.Id},
+               Ephemeral:  &ephemeral,
+       })
+       require.NoError(t, err, "mint setup key")
+
+       // Providers with their configured (allowed) models; the first 
bootstraps the cluster.
+       ids := make([]string, 0, len(providers))
+       allowed := make([]string, 0, len(providers))
+       for i, pc := range providers {
+               req := providerRequest(pc)
+               if i == 0 {
+                       req.BootstrapCluster = ptr(harness.AgentNetworkCluster)
+               }
+               prov, perr := srv.CreateProvider(ctx, req)
+               require.NoError(t, perr, "create provider %s", pc.name)
+               id := prov.Id
+               ids = append(ids, id)
+               allowed = append(allowed, catalogModel(pc))
+               t.Cleanup(func() { _ = srv.DeleteProvider(context.Background(), 
id) })
+       }
+
+       // Guardrail allowlisting exactly the configured models.
+       var gr api.AgentNetworkGuardrailRequest
+       gr.Name = "e2e-allowlist"
+       gr.Checks.ModelAllowlist.Enabled = true
+       gr.Checks.ModelAllowlist.Models = allowed
+       guard, err := srv.CreateGuardrail(ctx, gr)
+       require.NoError(t, err, "create guardrail")
+       t.Cleanup(func() { _ = srv.DeleteGuardrail(context.Background(), 
guard.Id) })
+
+       enabled := true
+       pol, err := srv.CreatePolicy(ctx, api.AgentNetworkPolicyRequest{
+               Name:                   "e2e-allowlist",
+               Enabled:                &enabled,
+               SourceGroups:           []string{grp.Id},
+               DestinationProviderIds: ids,
+               GuardrailIds:           &[]string{guard.Id},
+       })
+       require.NoError(t, err, "create policy")
+       t.Cleanup(func() { _ = srv.DeletePolicy(context.Background(), pol.Id) })
+
+       settings, err := srv.GetSettings(ctx)
+       require.NoError(t, err, "read settings for endpoint")
+       require.NotEmpty(t, settings.Endpoint, "agent-network endpoint must be 
assigned")
+
+       proxyToken, err := srv.CreateProxyTokenCLI(ctx, "e2e-proxy-allowlist")
+       require.NoError(t, err, "mint proxy token via CLI")
+       px, err := harness.StartProxy(ctx, srv, proxyToken)
+       require.NoError(t, err, "start proxy")
+       t.Cleanup(func() { _ = px.Terminate(context.Background()) })
+
+       cl, err := harness.StartClient(ctx, srv, sk.Key)
+       require.NoError(t, err, "start client")
+       t.Cleanup(func() { _ = cl.Terminate(context.Background()) })
+
+       require.NoError(t, cl.WaitConnected(ctx, 90*time.Second), "client must 
connect to management")
+       if err := cl.WaitProxyPeer(ctx, 180*time.Second); err != nil {
+               t.Fatalf("client did not see the proxy peer: %v\n=== proxy logs 
===\n%s", err, px.Logs(context.Background()))
+       }
+       proxyIP, err := cl.ResolveProxyIP(ctx, settings.Endpoint)
+       require.NoError(t, err, "resolve agent-network endpoint to proxy IP")
+
+       for _, pc := range providers {
+               pc := pc
+               t.Run(pc.name, func(t *testing.T) {
+                       // The admin's allowlisted model is served end to end.
+                       assert.Equal(t, 200, sendModel(ctx, t, cl, 
settings.Endpoint, proxyIP, pc, pc.model),
+                               "allowlisted model must be permitted for %s", 
pc.name)
+                       // A model outside the allowlist is rejected by the 
guardrail (before
+                       // the upstream), regardless of whether it is a real 
catalog model.
+                       assert.Equal(t, 403, sendModel(ctx, t, cl, 
settings.Endpoint, proxyIP, pc, disallowedModel(pc)),
+                               "model outside the allowlist must be denied for 
%s", pc.name)
+               })
+       }
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/e2e/harness/agentnetwork.go 
new/netbird-0.74.5/e2e/harness/agentnetwork.go
--- old/netbird-0.74.4/e2e/harness/agentnetwork.go      2026-07-10 
17:42:06.000000000 +0200
+++ new/netbird-0.74.5/e2e/harness/agentnetwork.go      2026-07-14 
20:13:00.000000000 +0200
@@ -107,6 +107,17 @@
        return anDelete(ctx, c, "/api/agent-network/policies/"+id)
 }
 
+// CreateGuardrail creates an agent-network guardrail (e.g. a model allowlist)
+// that can then be attached to a policy via its GuardrailIds.
+func (c *Combined) CreateGuardrail(ctx context.Context, req 
api.AgentNetworkGuardrailRequest) (api.AgentNetworkGuardrail, error) {
+       return anRequest[api.AgentNetworkGuardrail](ctx, c, http.MethodPost, 
"/api/agent-network/guardrails", req)
+}
+
+// DeleteGuardrail removes a guardrail by id.
+func (c *Combined) DeleteGuardrail(ctx context.Context, id string) error {
+       return anDelete(ctx, c, "/api/agent-network/guardrails/"+id)
+}
+
 // GetSettings returns the account's agent-network settings row. It exists only
 // after the first provider create bootstraps it.
 func (c *Combined) GetSettings(ctx context.Context) (api.AgentNetworkSettings, 
error) {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/netbird-0.74.4/e2e/harness/client.go 
new/netbird-0.74.5/e2e/harness/client.go
--- old/netbird-0.74.4/e2e/harness/client.go    2026-07-10 17:42:06.000000000 
+0200
+++ new/netbird-0.74.5/e2e/harness/client.go    2026-07-14 20:13:00.000000000 
+0200
@@ -194,6 +194,11 @@
        // WireVertex is the Anthropic-on-Vertex rawPredict shape: the client 
posts
        // the full Vertex model path and the proxy mints the SA OAuth token.
        WireVertex = "vertex"
+       // WireBedrock is the native AWS Bedrock InvokeModel shape: the model id
+       // travels in the URL path (/model/{id}/invoke), not the body, so the 
proxy
+       // routes by path. This is what a Bedrock SDK client sends and the 
shape the
+       // model-allowlist guardrail must enforce.
+       WireBedrock = "bedrock"
 )
 
 // Chat issues a chat-completion POST to the agent-network endpoint over the
@@ -226,6 +231,17 @@
        return cl.post(ctx, endpoint, proxyIP, path, body, withSessionID(nil, 
sessionID))
 }
 
+// Bedrock issues a native AWS Bedrock InvokeModel POST over the tunnel. The
+// model id is carried in the request path (/model/{id}/invoke), so the proxy
+// routes by path; the body uses the bedrock anthropic_version rather than a
+// model field. A non-empty sessionID is sent as the universal x-session-id
+// header the proxy records.
+func (cl *Client) Bedrock(ctx context.Context, endpoint, proxyIP, model, 
prompt, sessionID string) (int, string, error) {
+       path := "/model/" + model + "/invoke"
+       body := 
fmt.Sprintf(`{"anthropic_version":"bedrock-2023-05-31","max_tokens":64,"messages":[{"role":"user","content":%q}]}`,
 prompt)
+       return cl.post(ctx, endpoint, proxyIP, path, body, withSessionID(nil, 
sessionID))
+}
+
 // withSessionID appends the x-session-id header when sessionID is non-empty.
 func withSessionID(headers []string, sessionID string) []string {
        if sessionID == "" {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/management/internals/modules/peers/manager.go 
new/netbird-0.74.5/management/internals/modules/peers/manager.go
--- old/netbird-0.74.4/management/internals/modules/peers/manager.go    
2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/management/internals/modules/peers/manager.go    
2026-07-14 20:13:00.000000000 +0200
@@ -224,30 +224,6 @@
                return nil
        }
 
-       // Dedupe stale embedded peer records for the same (account, cluster).
-       // The proxy generates a fresh WireGuard keypair on every startup
-       // (proxy/internal/roundtrip/netbird.go), so without this sweep the
-       // prior embedded peer would linger forever — holding its CGNAT IP
-       // allocation, polluting other peers' rosters, and (most visibly)
-       // leaving the synth DNS pointing at the dead address. The
-       // (account, cluster) tuple identifies "the embedded peer for this
-       // proxy instance at this cluster"; any record matching that tuple
-       // with a different pubkey is by definition stale and must go.
-       staleIDs, err := m.findStaleEmbeddedProxyPeers(ctx, accountID, cluster, 
peerKey)
-       if err != nil {
-               return fmt.Errorf("scan for stale embedded proxy peers: %w", 
err)
-       }
-       if len(staleIDs) > 0 {
-               // userID="" + checkConnected=false: the deletion is initiated
-               // by management itself on behalf of the freshly-registering
-               // proxy, not by an end user; the stale peer may still be
-               // marked Connected from its prior session, but its session is
-               // dead by definition (its key no longer exists).
-               if err := m.DeletePeers(ctx, accountID, staleIDs, "", false); 
err != nil {
-                       return fmt.Errorf("delete stale embedded proxy peers 
%v: %w", staleIDs, err)
-               }
-       }
-
        name := fmt.Sprintf("proxy-%s", xid.New().String())
        newPeer := &peer.Peer{
                Ephemeral: true,
@@ -273,29 +249,3 @@
 
        return nil
 }
-
-// findStaleEmbeddedProxyPeers returns the peer IDs of embedded proxy peer
-// records in accountID that target the same cluster but carry a different
-// WireGuard pubkey than the freshly-registering one. Used by CreateProxyPeer
-// to garbage-collect stale records left behind when the proxy restarts with a
-// regenerated keypair.
-func (m *managerImpl) findStaleEmbeddedProxyPeers(ctx context.Context, 
accountID, cluster, newKey string) ([]string, error) {
-       account, err := m.store.GetAccount(ctx, accountID)
-       if err != nil {
-               return nil, err
-       }
-       var stale []string
-       for _, p := range account.Peers {
-               if p == nil || !p.ProxyMeta.Embedded {
-                       continue
-               }
-               if p.ProxyMeta.Cluster != cluster {
-                       continue
-               }
-               if p.Key == newKey {
-                       continue
-               }
-               stale = append(stale, p.ID)
-       }
-       return stale, nil
-}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/management/server/agentnetwork_proxypeer_restart_test.go 
new/netbird-0.74.5/management/server/agentnetwork_proxypeer_restart_test.go
--- old/netbird-0.74.4/management/server/agentnetwork_proxypeer_restart_test.go 
2026-07-10 17:42:06.000000000 +0200
+++ new/netbird-0.74.5/management/server/agentnetwork_proxypeer_restart_test.go 
1970-01-01 01:00:00.000000000 +0100
@@ -1,199 +0,0 @@
-package server
-
-import (
-       "context"
-       "testing"
-       "time"
-
-       "github.com/stretchr/testify/assert"
-       "github.com/stretchr/testify/require"
-
-       "github.com/netbirdio/netbird/management/internals/modules/peers"
-       "github.com/netbirdio/netbird/management/internals/modules/agentnetwork"
-       agenttypes 
"github.com/netbirdio/netbird/management/internals/modules/agentnetwork/types"
-       nbpeer "github.com/netbirdio/netbird/management/server/peer"
-       "github.com/netbirdio/netbird/management/server/permissions"
-       "github.com/netbirdio/netbird/management/server/store"
-       "github.com/netbirdio/netbird/management/server/types"
-)
-
-// TestAgentNetwork_ProxyRestart_PropagatesNewPeerAndDropsStale is the no-mock
-// regression guard for the bug the user reported: restarting the proxy creates
-// a fresh embedded peer with a NEW WireGuard public key (the proxy generates
-// the keypair on every startup at proxy/internal/roundtrip/netbird.go:312).
-// The PRIOR embedded peer record is never deleted on management, so the
-// account accumulates a stale peer holding a stale CGNAT IP. Other peers
-// in the account either keep routing to the dead IP, or — if synth DNS
-// picks the wrong record — never see the new IP at all.
-//
-// What this test exercises (no mocks):
-//   - real SQLite test store
-//   - real DefaultAccountManager, network-map controller, peer-update channels
-//   - real peers.Manager.CreateProxyPeer path (the very method the proxy
-//     invokes over gRPC on every startup)
-//   - real agentnetwork.Manager + synth chain so the client receives a
-//     concrete DNS record that must point at the LATEST proxy peer.
-//
-// Pre-fix expected behavior (red): two embedded peers exist after the
-// "restart"; the synth DNS record points at the stale one; the client
-// receives an update reflecting the new peer but the old one lingers.
-// Post-fix expected behavior (green): exactly one embedded peer exists
-// after restart (with the new key) AND the client's network map carries
-// the synth DNS pointing at that new peer's CGNAT IP.
-func TestAgentNetwork_ProxyRestart_PropagatesNewPeerAndDropsStale(t 
*testing.T) {
-       am, updateManager, err := createManager(t)
-       require.NoError(t, err, "createManager must succeed")
-       ctx := context.Background()
-
-       const (
-               accountID   = "an-restart-acct"
-               adminUserID = "an-restart-admin"
-               groupAID    = "an-restart-grp-A"
-               clusterAddr = "eu.proxy.netbird.io"
-               clientKey   = "BhRPtynAAYRDy08+q4HTMsos8fs4plTP4NOSh7C1ry8="
-               // Two different proxy pubkeys — the "before" and "after" of a
-               // proxy-process restart with fresh-keypair generation.
-               proxyKey1 = "Aaaaa1aaaaYRDy08+q4HTMsos8fs4plTP4NOSh7C1ry8="
-               proxyKey2 = "Bbbbb2bbbbYRDy08+q4HTMsos8fs4plTP4NOSh7C1ry8="
-       )
-
-       // --- Account scaffold ---
-       account := newAccountWithId(ctx, accountID, adminUserID, 
"an-restart.test", "", "", false)
-       require.NoError(t, am.Store.SaveAccount(ctx, account))
-
-       clientPeer := &nbpeer.Peer{
-               Key:      clientKey,
-               Name:     "an-restart-client",
-               DNSLabel: "an-restart-client",
-               Meta:     nbpeer.PeerSystemMeta{Hostname: "an-restart-client", 
GoOS: "linux", WtVersion: "development"},
-       }
-       addedClient, _, _, _, err := am.AddPeer(ctx, "", "", adminUserID, 
clientPeer, false)
-       require.NoError(t, err, "AddPeer for client must succeed")
-       require.NoError(t, am.MarkPeerConnected(ctx, clientKey, accountID, 
time.Now().UnixNano(), &types.NetworkMap{}),
-               "MarkPeerConnected for the client peer must succeed 
(affected-peer fan-out skips disconnected peers)")
-
-       // Place the client in group A so the synth policy reaches it.
-       account, err = am.Store.GetAccount(ctx, accountID)
-       require.NoError(t, err)
-       account.Groups[groupAID] = &types.Group{ID: groupAID, Name: "groupA", 
Peers: []string{addedClient.ID}}
-       require.NoError(t, am.Store.SaveAccount(ctx, account), "SaveAccount 
must persist group A")
-
-       // --- Real peers + agent-network managers ---
-       permMgr := permissions.NewManager(am.Store)
-       peersMgr := peers.NewManager(am.Store, permMgr)
-       peersMgr.SetAccountManager(am)
-       peersMgr.SetNetworkMapController(am.networkMapController)
-       agentMgr := agentnetwork.NewManager(am.Store, permMgr, am, nil)
-
-       // Subscribe BEFORE any state-mutating call so we don't lose the update
-       // that contains the synth DNS record.
-       clientCh := updateManager.CreateChannel(ctx, addedClient.ID)
-       t.Cleanup(func() { updateManager.CloseChannel(ctx, addedClient.ID) })
-       drain(clientCh)
-
-       // --- First proxy startup: register peer key K1, then mark it
-       // connected. In production the proxy follows CreateProxyPeer with the
-       // regular sync stream which lands on MarkPeerConnected; the synth DNS
-       // path filters out peers that aren't Connected (types/account.go:323),
-       // so without this step no DNS record would be emitted.
-       require.NoError(t, peersMgr.CreateProxyPeer(ctx, accountID, proxyKey1, 
clusterAddr),
-               "first CreateProxyPeer (proxy startup) must succeed")
-
-       peer1ID, err := am.Store.GetPeerIDByKey(ctx, store.LockingStrengthNone, 
proxyKey1)
-       require.NoError(t, err, "proxy peer for K1 must be persisted after 
CreateProxyPeer")
-       require.NotEmpty(t, peer1ID)
-
-       require.NoError(t, am.MarkPeerConnected(ctx, proxyKey1, accountID, 
time.Now().UnixNano(), &types.NetworkMap{}),
-               "MarkPeerConnected for K1 must succeed")
-
-       account, err = am.Store.GetAccount(ctx, accountID)
-       require.NoError(t, err)
-       proxyIP1 := account.Peers[peer1ID].IP.String()
-       require.NotEmpty(t, proxyIP1, "K1 must have an assigned overlay IP")
-
-       // --- Provider + policy. CreateProvider / CreatePolicy trigger the
-       // agentnetwork reconcile which runs UpdateAccountPeers; the resulting
-       // NetworkMap delivered to the client carries the synth DNS record
-       // pointing at K1's IP. ---
-       provider, err := agentMgr.CreateProvider(ctx, adminUserID, 
&agenttypes.Provider{
-               AccountID:   accountID,
-               ProviderID:  "openai_api",
-               Name:        "openai-test",
-               UpstreamURL: "https://api.openai.com";,
-               APIKey:      "sk-test-key",
-               Enabled:     true,
-               Models:      []agenttypes.ProviderModel{{ID: "gpt-5.4"}},
-       }, clusterAddr)
-       require.NoError(t, err, "CreateProvider must succeed")
-
-       _, err = agentMgr.CreatePolicy(ctx, adminUserID, &agenttypes.Policy{
-               AccountID:              accountID,
-               Name:                   "p1",
-               Enabled:                true,
-               SourceGroups:           []string{groupAID},
-               DestinationProviderIDs: []string{provider.ID},
-       })
-       require.NoError(t, err, "CreatePolicy must succeed")
-
-       settings, err := am.Store.GetAgentNetworkSettings(ctx, 
store.LockingStrengthNone, accountID)
-       require.NoError(t, err)
-       fqdn := settings.Endpoint()
-
-       rdata1 := awaitZoneRData(clientCh, clusterAddr, fqdn, true)
-       require.Equal(t, proxyIP1, rdata1,
-               "client must receive a synth DNS record pointing at K1's 
overlay IP after the synth path runs")
-       drain(clientCh)
-
-       // --- Proxy restart: NEW keypair K2, same account, same cluster ---
-       require.NoError(t, peersMgr.CreateProxyPeer(ctx, accountID, proxyKey2, 
clusterAddr),
-               "second CreateProxyPeer (proxy restart with fresh keypair) must 
succeed")
-
-       peer2ID, err := am.Store.GetPeerIDByKey(ctx, store.LockingStrengthNone, 
proxyKey2)
-       require.NoError(t, err, "proxy peer for K2 must be persisted after 
restart")
-       require.NotEmpty(t, peer2ID)
-
-       require.NoError(t, am.MarkPeerConnected(ctx, proxyKey2, accountID, 
time.Now().UnixNano(), &types.NetworkMap{}),
-               "MarkPeerConnected for K2 must succeed")
-
-       // In production the agent's sync stream pulls a fresh NetworkMap as
-       // part of its normal reconcile cadence; in this isolated test
-       // MarkPeerConnected's affected-peer fan-out can race the channel-side
-       // buffer in a way that swallows the synth-DNS-bearing update before
-       // our await reads it. Trigger an explicit account-wide fan-out so the
-       // assertion below tests what production actually delivers, not the
-       // in-test buffer race.
-       am.UpdateAccountPeers(ctx, accountID, types.UpdateReason{Resource: 
types.UpdateResourcePeer, Operation: types.UpdateOperationUpdate})
-
-       account, err = am.Store.GetAccount(ctx, accountID)
-       require.NoError(t, err)
-       proxyIP2 := account.Peers[peer2ID].IP.String()
-       require.NotEmpty(t, proxyIP2, "K2 must have an assigned overlay IP")
-       require.NotEqual(t, proxyIP1, proxyIP2, "K2 must get a different 
overlay IP than K1 (sanity)")
-
-       // CRITICAL ASSERTION 1: K1 must no longer be in the store. The SqlStore
-       // returns ("", nil) for a missing key rather than NotFound, so assert
-       // on the returned ID being empty.
-       staleID, err := am.Store.GetPeerIDByKey(ctx, store.LockingStrengthNone, 
proxyKey1)
-       require.NoError(t, err, "GetPeerIDByKey for a missing peer must not 
error")
-       assert.Empty(t, staleID,
-               "stale embedded proxy peer K1 must be removed when a new 
embedded peer registers for the same (account, cluster); pre-fix this assertion 
fails because management never cleans up the prior peer record")
-
-       // CRITICAL ASSERTION 2: exactly one embedded proxy peer remains, and it
-       // is K2.
-       account, err = am.Store.GetAccount(ctx, accountID)
-       require.NoError(t, err)
-       embeddedKeys := []string{}
-       for _, p := range account.Peers {
-               if p.ProxyMeta.Embedded {
-                       embeddedKeys = append(embeddedKeys, p.Key)
-               }
-       }
-       assert.Equal(t, []string{proxyKey2}, embeddedKeys,
-               "after a proxy restart exactly one embedded proxy peer should 
remain — the one with the new key K2")
-
-       // CRITICAL ASSERTION 3: the synth DNS record the client receives now
-       // points at K2's IP, not K1's.
-       rdata2 := awaitZoneRData(clientCh, clusterAddr, fqdn, true)
-       assert.Equal(t, proxyIP2, rdata2,
-               "after proxy restart, the client's synth DNS record must point 
at the NEW embedded peer's IP, not the stale K1 IP")
-}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware.go
 
new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware.go
--- 
old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware.go
    2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware.go
    2026-07-14 20:13:00.000000000 +0200
@@ -25,6 +25,14 @@
        denyCodeModel    = "llm_policy.model_blocked"
        denyReasonModel  = "model_blocked"
        denyMessageModel = "model is not in the policy allowlist"
+       // Deny reason used when an allowlist is configured but the request 
model
+       // could not be determined. URL/path-routed providers (AWS Bedrock, 
Google
+       // Vertex, ...) carry the model outside the JSON body, so a request 
shape the
+       // parser does not recognise reaches the guardrail with no model. Such a
+       // request must be denied (fail closed), never waved through.
+       denyCodeModelUnknown    = "llm_policy.model_unknown"
+       denyReasonModelUnknown  = "model_unknown"
+       denyMessageModelUnknown = "request model could not be determined for 
the policy allowlist"
 )
 
 // Middleware enforces the model allowlist and optionally captures the
@@ -108,23 +116,37 @@
        if len(m.cfg.ModelAllowlist) == 0 {
                return nil
        }
-       if !modelPresent {
-               return nil
+       // Fail closed: with an allowlist configured, a request whose model the
+       // upstream parser could not extract (absent or empty) must be denied 
rather
+       // than allowed. This is what enforces the allowlist for URL/path-routed
+       // providers (Bedrock, Vertex, ...) whose model lives outside the JSON 
body.
+       if !modelPresent || normaliseModel(model) == "" {
+               return denyModel("", denyCodeModelUnknown, 
denyMessageModelUnknown, denyReasonModelUnknown)
        }
        if m.modelInAllowlist(model) {
                return nil
        }
+       return denyModel(model, denyCodeModel, denyMessageModel, 
denyReasonModel)
+}
+
+// denyModel builds a 403 deny Output for a model-allowlist rejection. model is
+// included in the details only when non-empty.
+func denyModel(model, code, message, reason string) *middleware.Output {
+       details := map[string]string{}
+       if model != "" {
+               details["model"] = model
+       }
        return &middleware.Output{
                Decision:   middleware.DecisionDeny,
                DenyStatus: 403,
                DenyReason: &middleware.DenyReason{
-                       Code:    denyCodeModel,
-                       Message: denyMessageModel,
-                       Details: map[string]string{"model": model},
+                       Code:    code,
+                       Message: message,
+                       Details: details,
                },
                Metadata: []middleware.KV{
                        {Key: middleware.KeyLLMPolicyDecision, Value: "deny"},
-                       {Key: middleware.KeyLLMPolicyReason, Value: 
denyReasonModel},
+                       {Key: middleware.KeyLLMPolicyReason, Value: reason},
                },
        }
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go
 
new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go
--- 
old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go
       2026-07-10 17:42:06.000000000 +0200
+++ 
new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_guardrail/middleware_test.go
       2026-07-14 20:13:00.000000000 +0200
@@ -102,13 +102,44 @@
        }
 }
 
-func TestAllowlistMissingModelKeyAllows(t *testing.T) {
+func TestAllowlistMissingModelKeyDenies(t *testing.T) {
+       // Fail closed: with an allowlist configured, a request whose model the
+       // parser could not extract (URL/path-routed providers such as Bedrock 
or
+       // Vertex whose shape wasn't recognised) must be denied, not allowed.
        mw := New(Config{ModelAllowlist: []string{"gpt-4o"}})
        out, err := mw.Invoke(context.Background(), newInput())
        require.NoError(t, err)
-       assert.Equal(t, middleware.DecisionAllow, out.Decision, "missing model 
key must allow even with non-empty allowlist")
+       require.NotNil(t, out)
+       assert.Equal(t, middleware.DecisionDeny, out.Decision, "absent model 
must be denied when an allowlist is set")
+       assert.Equal(t, 403, out.DenyStatus, "deny status must be 403")
+       require.NotNil(t, out.DenyReason, "deny reason must be populated")
+       assert.Equal(t, "llm_policy.model_unknown", out.DenyReason.Code, "deny 
code must be model_unknown")
        dec, _ := metaValue(t, out.Metadata, middleware.KeyLLMPolicyDecision)
-       assert.Equal(t, "allow", dec, "decision must be allow when model key is 
absent")
+       assert.Equal(t, "deny", dec, "decision must be deny when model key is 
absent")
+       reason, _ := metaValue(t, out.Metadata, middleware.KeyLLMPolicyReason)
+       assert.Equal(t, "model_unknown", reason, "reason metadata must be 
model_unknown")
+}
+
+func TestAllowlistEmptyModelValueDenies(t *testing.T) {
+       // A present-but-empty model is as undeterminable as an absent one.
+       mw := New(Config{ModelAllowlist: []string{"gpt-4o"}})
+       out, err := mw.Invoke(context.Background(), newInput(
+               middleware.KV{Key: middleware.KeyLLMModel, Value: "   "},
+       ))
+       require.NoError(t, err)
+       require.NotNil(t, out)
+       assert.Equal(t, middleware.DecisionDeny, out.Decision, "empty model 
must be denied when an allowlist is set")
+       require.NotNil(t, out.DenyReason, "deny reason must be populated")
+       assert.Equal(t, "llm_policy.model_unknown", out.DenyReason.Code, "deny 
code must be model_unknown")
+}
+
+func TestAllowlistEmptyListAllowsMissingModel(t *testing.T) {
+       // Without an allowlist there is nothing to enforce, so a missing model 
is
+       // still allowed — the fail-closed rule only applies when a list is set.
+       mw := New(Config{})
+       out, err := mw.Invoke(context.Background(), newInput())
+       require.NoError(t, err)
+       assert.Equal(t, middleware.DecisionAllow, out.Decision, "no allowlist 
must allow even without a model")
 }
 
 func TestPromptCaptureDisabledEmitsNoPrompt(t *testing.T) {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go
 
new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go
--- 
old/netbird-0.74.4/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go
 1970-01-01 01:00:00.000000000 +0100
+++ 
new/netbird-0.74.5/proxy/internal/middleware/builtin/llm_request_parser/guardrail_allowlist_test.go
 2026-07-14 20:13:00.000000000 +0200
@@ -0,0 +1,106 @@
+package llm_request_parser
+
+import (
+       "context"
+       "testing"
+
+       "github.com/stretchr/testify/assert"
+       "github.com/stretchr/testify/require"
+
+       "github.com/netbirdio/netbird/proxy/internal/middleware"
+       
"github.com/netbirdio/netbird/proxy/internal/middleware/builtin/llm_guardrail"
+)
+
+// runParserGuardrail runs the request parser then the model-allowlist 
guardrail
+// in SlotOnRequest order, threading the parser's metadata into the guardrail 
the
+// same way the real chain does. It returns the guardrail decision so tests can
+// assert allowlist enforcement for URL/path-routed providers end to end.
+func runParserGuardrail(t *testing.T, url string, body []byte, allowlist 
[]string) *middleware.Output {
+       t.Helper()
+       parser := newMiddleware(t)
+       parsed, err := parser.Invoke(context.Background(), &middleware.Input{
+               Slot: middleware.SlotOnRequest,
+               URL:  url,
+               Body: body,
+       })
+       require.NoError(t, err, "parser must not error")
+
+       guard := llm_guardrail.New(llm_guardrail.Config{ModelAllowlist: 
allowlist})
+       out, err := guard.Invoke(context.Background(), &middleware.Input{
+               Slot:     middleware.SlotOnRequest,
+               Metadata: parsed.Metadata,
+       })
+       require.NoError(t, err, "guardrail must not error")
+       require.NotNil(t, out, "guardrail must return an output")
+       return out
+}
+
+// TestModelAllowlist_URLRoutedProviders validates that the model allowlist is
+// enforced for providers whose model travels in the URL path (AWS Bedrock,
+// Google Vertex) rather than the JSON body. The "unknown action" case is the
+// regression guard for #6751: a Bedrock request shape the parser cannot map 
to a
+// model must fail closed under an allowlist instead of bypassing it.
+func TestModelAllowlist_URLRoutedProviders(t *testing.T) {
+       const bedrockBody = 
`{"anthropic_version":"bedrock-2023-05-31","messages":[{"role":"user","content":"hi"}]}`
+       const vertexBody = 
`{"anthropic_version":"vertex-2023-10-16","messages":[{"role":"user","content":"hi"}]}`
+
+       tests := []struct {
+               name      string
+               url       string
+               body      string
+               allowlist []string
+               decision  middleware.Decision
+               denyCode  string
+       }{
+               {
+                       name:      "bedrock allowed model passes",
+                       url:       
"https://bedrock-runtime.us-east-1.amazonaws.com/model/us.anthropic.claude-haiku-4-5-v1:0/invoke";,
+                       body:      bedrockBody,
+                       allowlist: []string{"anthropic.claude-haiku-4-5"},
+                       decision:  middleware.DecisionAllow,
+               },
+               {
+                       name:      "bedrock disallowed model denied",
+                       url:       
"https://bedrock-runtime.us-east-1.amazonaws.com/model/us.anthropic.claude-opus-4-8-v1:0/invoke";,
+                       body:      bedrockBody,
+                       allowlist: []string{"anthropic.claude-haiku-4-5"},
+                       decision:  middleware.DecisionDeny,
+                       denyCode:  "llm_policy.model_blocked",
+               },
+               {
+                       name:      "bedrock unknown action fails closed",
+                       url:       
"https://bedrock-runtime.us-east-1.amazonaws.com/model/us.anthropic.claude-opus-4-8-v1:0/some-future-action";,
+                       body:      bedrockBody,
+                       allowlist: []string{"anthropic.claude-haiku-4-5"},
+                       decision:  middleware.DecisionDeny,
+                       denyCode:  "llm_policy.model_unknown",
+               },
+               {
+                       name:      "vertex disallowed model denied",
+                       url:       
"/v1/projects/p/locations/global/publishers/anthropic/models/claude-opus-4-8@20250101:rawPredict",
+                       body:      vertexBody,
+                       allowlist: []string{"claude-haiku-4-5"},
+                       decision:  middleware.DecisionDeny,
+                       denyCode:  "llm_policy.model_blocked",
+               },
+               {
+                       name:      "vertex allowed model passes",
+                       url:       
"/v1/projects/p/locations/global/publishers/anthropic/models/claude-haiku-4-5@20250101:rawPredict",
+                       body:      vertexBody,
+                       allowlist: []string{"claude-haiku-4-5"},
+                       decision:  middleware.DecisionAllow,
+               },
+       }
+
+       for _, tt := range tests {
+               t.Run(tt.name, func(t *testing.T) {
+                       out := runParserGuardrail(t, tt.url, []byte(tt.body), 
tt.allowlist)
+                       assert.Equal(t, tt.decision, out.Decision, "unexpected 
decision for %s", tt.name)
+                       if tt.decision == middleware.DecisionDeny {
+                               require.NotNil(t, out.DenyReason, "deny reason 
must be set for %s", tt.name)
+                               assert.Equal(t, 403, out.DenyStatus, "deny 
status must be 403 for %s", tt.name)
+                               assert.Equal(t, tt.denyCode, 
out.DenyReason.Code, "deny code for %s", tt.name)
+                       }
+               })
+       }
+}

++++++ netbird.obsinfo ++++++
--- /var/tmp/diff_new_pack.e72vpa/_old  2026-07-15 17:02:58.645911959 +0200
+++ /var/tmp/diff_new_pack.e72vpa/_new  2026-07-15 17:02:58.649912095 +0200
@@ -1,5 +1,5 @@
 name: netbird
-version: 0.74.4
-mtime: 1783698126
-commit: 3d87547d952f5ada9df987bbe4f0f6d54372d77c
+version: 0.74.5
+mtime: 1784052780
+commit: f0eed7564f3a9138962da1408986e4666d7137b5
 

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/netbird/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.netbird.new.1991/vendor.tar.zst differ: char 7, 
line 1

Reply via email to