AbdoAhmedElbanaaandDivarion_D 78d7b23212 feat(reseller): trial deep-links, voucher balance card, Host header guard
Safe subset of Rosmi720/XC_VM@8fa1e67f. The dashboard revamp and the sidebar
restructure from that commit are deliberately left out — see below.

- The sidebar's existing `?trial=1` links on Lines / MAG / Enigma now actually
  land on the Trial filter: each page picks the trial value from its own
  $rStatusFilters map (5 for lines, 4 for MAG and Enigma) when no explicit
  ?filter is given.
- Restyle the voucher credit-accounting card in active_code.php onto standard
  Vuexy surface classes instead of a hand-tinted primary panel. Element ids and
  the calculation are untouched, so the existing calculator JS still drives it.
- RequestGuard: fall back to '' for HTTP_HOST. A request can legitimately arrive
  without a Host header, and explode(':', null) is deprecated on PHP 8.
- Add the live_calculator string the new card asks for. Without it Translator
  returns the key itself AND appends it to the ini, so the card would render the
  literal "live_calculator" (which is how the placeholder appeared upstream).
  The Arabic wording is a first pass and welcomes a correction from its author.

Left out of this commit:
- ResellerDashboardController / dashboard.php: three fallbacks drop tenant
  scoping when the scoped query comes back empty — top countries re-queries
  lines_activity server-wide, latest movies and live streams re-run without the
  stream_ids restriction, and series and episodes are never scoped at all. It
  also pins unknown connections to a hardcoded 'EG' country, and moves ~10 raw
  SQL queries into a controller.
- The sidebar restructure: it replaces the LineService::canGenerateTrials()
  check with a plain create_line permission, which would show trial actions to
  resellers that may not generate trials.
- The Redis mGet guard for ResellerTableRenderer::handleLiveConnections, which
  Admin\TableController already carries. The method sits at cc=53 with no
  coverage, so the CRAP ratchet rightly refuses the hardening until it is
  tested — worth doing as its own change.

Verified: 857 tests, make gates, CRAP gate.
2026-09-22 17:00:30 +03:00
2026-09-17 20:48:42 +03:00
2026-09-16 22:04:48 +03:00
2025-07-10 20:01:56 +03:00

Vateron Media Logo

XC_VM IPTV Panel

Open-source, community-driven Xtream Codes panel
Built for modern IPTV workflows – powerful, scalable, and free.


📑 Table of Contents

📘 Contents

🚀 Overview

XC_VM is an open-source IPTV platform based on Xtream Codes. It enables:

  • 📺 Live & VOD streaming
  • 🔀 Load balancing
  • 📊 Full user/reseller control
  • 🎚️ Transcoding & EPG
  • 🔐 Hardened security fixes

✅ 100% free. No license checks. No server locks.


⚠️ Status

BETA SOFTWARE — actively developed


📚 Documentation


🔄 Migration Guide

Migrating from Xtream Codes / XUI.one? Follow the step-by-step migration guide:


🧱 Technology Stack

Component Version Description
PHP 8.1.33 Backend runtime
Nginx 1.24 Web server & reverse proxy
FFmpeg 8.0, 7.1, 4.0 Media transcoding & processing
MariaDB 11.4 SQL database engine
KeyDB 6.3.4 Cache & session storage (Redis)

🐧 Supported Operating Systems

XC_VM supports multiple Linux distributions. Distribution-specific binaries (PHP, Nginx) are downloaded automatically from XC_VM_Binaries during installation.

Ubuntu

Version Codename Status
20.04 Focal Fossa ⚠️ Outdated — installation possible, but some packages may need to be installed manually
22.04 Jammy Jellyfish ✅ Recommended
24.04 Noble Numbat ✅ Recommended

Debian

Version Codename Status
11 Bullseye ✅ Supported
12 Bookworm ✅ Recommended
13 Trixie ✅ Supported

RHEL-compatible (Rocky Linux, AlmaLinux, CentOS, RHEL)

Version Status
8 🚧 Not yet supported
9 🚧 Not yet supported

⚠️ RHEL-family support is planned but not yet available. The installer recognizes these distributions, but pre-built binaries are not provided yet.


💡 Recommendations

For new installations:

  • 🟢 Ubuntu 22.04 / 24.04 LTS
  • 🟢 Debian 12

⚠️ Ubuntu 18.04 is in legacy mode — it works but receives no priority fixes.


📥 Quick Install

✅ Ubuntu 22.04+, Debian 11+

# 1. Update system
sudo apt update && sudo apt full-upgrade -y

# 2. Install dependencies
sudo apt install -y curl wget python3 unzip

# 3. Download latest release
latest_version=$(curl -s https://api.github.com/repos/Vateron-Media/XC_VM/releases/latest | grep '"tag_name":' | cut -d '"' -f 4)
wget "https://github.com/Vateron-Media/XC_VM/releases/download/${latest_version}/XC_VM.zip"

# 4. Unpack and install
unzip XC_VM.zip
sudo python3 install

🧪 Beta Install

To install the latest beta (pre-release) version:

# 1. Update system
sudo apt update && sudo apt full-upgrade -y

# 2. Install dependencies
sudo apt install -y curl wget python3-pip unzip

# 3. Download latest beta release
beta_version=$(curl -s https://api.github.com/repos/Vateron-Media/XC_VM/releases | grep -m1 '"tag_name":' | cut -d '"' -f 4)
wget "https://github.com/Vateron-Media/XC_VM/releases/download/${beta_version}/XC_VM.zip"

# 4. Unpack and install
unzip XC_VM.zip
sudo python3 install

⚠️ Beta versions may contain unstable features. Use on test servers only.


🧰 Service Management

sudo systemctl start xc_vm     # Start
sudo systemctl stop xc_vm      # Stop
sudo systemctl restart xc_vm   # Restart
sudo systemctl status xc_vm    # Status
sudo /home/xc_vm/bin/nginx/sbin/nginx -s reload    # Reload Nginx config
journalctl -u xc_vm -f         # Live logs

🔍 Troubleshooting — Panel Won't Start

If the panel fails to start, check the following logs and commands:

Nginx error log:

cat /home/xc_vm/bin/nginx/logs/error.log

PHP-FPM log:

cat /home/xc_vm/bin/php/var/log/php-fpm.log

Verify PHP binary works:

/home/xc_vm/bin/php/bin/php -v

If PHP fails to run, the panel cannot start at all — fix PHP issues first before investigating Nginx.


📂 Project Structure

├─ docs/        # 📚 Project documentation
├─ lb_configs/  # ⚙️ Configurations for building Load Balancer (LB)
└─ src/         # 💻 Main project code

🧮 Server Requirements & Sizing

🔧 Minimum Specs

Component Recommendation
CPU 6+ cores (Xeon/Ryzen)
RAM 16–32 GB
Disk SSD/NVMe, 480+ GB
Network Dedicated 1 Gbps port
OS Ubuntu 22.04+, Debian 12+ (clean install)

📊 Planning Formulae

  • Bandwidth (Mbps) = Channels × Bitrate
  • Max Users = Bandwidth ÷ Stream Bitrate
Example:
HD bitrate = 4 Mbps
1 Gbps = ~940 usable Mbps

→ Max Channels: 940 ÷ 4 = ~235
→ Max Users:    940 ÷ 4 = ~235

⚠️ 10 users watching the same channel = 10× bandwidth (unless caching or multicast used)


💻 RAM & CPU Usage

Resource Load per Stream
RAM 50–100 MB
CPU (transcoded) ~1 core

✅ Features

  • ✅ No server restrictions
  • ✅ EPG importer
  • ✅ VOD management
  • ✅ User/reseller panel
  • ✅ Security patches
  • ✅ Clean UI

🔧 Known Limitations

  • ❌ Requires Linux knowledge
  • ❌ Community-based support
  • ❌ Some bugs in transcoding module (in progress)

🤝 Contributing

We welcome community help!


XC_VM is an independent software project and is not affiliated with or endorsed by XUI.one.

All backend systems, core logic, and infrastructure of XC_VM have been independently developed without using source code from XUI.one or related projects.

The administrative interface (UI/UX) is inspired by general industry practices and partially by XUI.one in terms of usability concepts only. No proprietary source code or protected assets have been intentionally reused.


📜 License Enforcement (AGPL-3.0)

XC_VM is distributed under the GNU Affero General Public License v3.0 (AGPL-3.0).

Under this license:

  • Redistribution or modification is permitted only under the same license (AGPL-3.0)
  • Any modified version must remain open-source
  • Providing XC_VM as a service requires making the source code available
  • Copyright and attribution must be preserved

Any attempt to redistribute this software under a different license, remove attribution, or obscure the origin of the project constitutes a violation of the license terms.

Attribution-integrity check

As permitted by AGPL-3.0 §7(b) (preservation of author attributions), the panel verifies on each request that its attribution notice — the "Vateron Media · AGPL-3.0" credit shown in the panel footer — is still present. If the notice has been removed, the management UI (admin / reseller / player panels) is locked with an ATTRIBUTION_REMOVED notice until it is restored. The check is fully reversible and non-destructive: no data is modified, the CLI remains available, and restoring the notice unlocks the panel on the next request. End-viewer streaming is not affected by this check.

Each build is also stamped with a unique build identifier (XC_VM_BUILD_ID) for provenance, so a leaked or rebranded copy can be traced back to the build it originated from.

White-label activation (dual-licensing)

Keeping the attribution notice means AGPL-3.0 — free, and everything works, including load-balancer nodes. If the attribution is removed (white-labelling), the panel requires a free, machine-bound activation key to provision load-balancer / cluster nodes; a single-server panel still runs locally without one. Keys are issued free and self-service (one per HWID, shown in Settings → Info and on the dashboard) and are revocable — this is accountability against rebranded resale, not monetization.

What the panel sends (full transparency)

A community install (attribution intact) never contacts the licensing server. A white-label install contacts https://www.xcvm.tech only to: (a) obtain its key (install_id), (b) run a weekly revocation check (jti + nonce), and (c) send one daily check-in (install_id, jti, env_fp, nonce) recording which IP a HWID runs from — evidence against a leaked copy. Every response is Ed25519-signed and verified. No stream data, viewer data, credentials, database or file contents, and no remote command channel are ever involved. Full detail: Licensing & Activation.

⚖️ You are solely responsible for how it is used. We take no responsibility for misuse or illegal deployments.


S
Description
XC_VM - open, transparent, and community-first. IPTV backend tools with integrated runtime environment.
Readme AGPL-3.0
573 MiB
Languages
PHP 76.4%
JavaScript 11%
CSS 9.3%
Python 1.4%
TypeScript 0.9%
Other 0.9%