Skip to content
CAI
Software that uses CAICheck a score

seriyps/mtproto_proxy

54.7

Adequate · 23 September 2026

5.2k

lines of production code

Erlang

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a high-concurrency proxy service built on Erlang/OTP, designed to manage secure, distributed communications between front-end and back-end nodes. It implements a layered codec architecture that handles protocol translation, encryption, and packet formatting for multiple network layers. The system supports split-mode deployments with automated TLS certificate generation for secure inter-node communication, ensuring reliable data encoding and decoding through comprehensive benchmarking and property-based testing.

Features

Added configuration files for split-mode (front/back node) deployment

Added example configuration files for deploying the proxy in a split-mode architecture, separating front-end (client-facing) and back-end (Telegram-facing) nodes. This includes distinct sys.config and vm.args templates for each role, along with systemd service units for the Erlang Port Mapper Daemon (epmd) and the proxy itself, enabling users to run distributed, high-concurrency setups with secure inter-node communication.

config · high confidence

Added script to generate TLS certificates for Erlang distribution

A new shell script, scripts/gen\_dist\_certs.sh, has been added to automate the generation of TLS certificates for Erlang distribution. The script supports a two-step process: an 'init' command to create a Certificate Authority (CA) and a 'back' node certificate, followed by 'add-node' commands to generate certificates for each front server. The script outputs PEM certificates, private keys, and ready-to-use Erlang TLS configuration files (ssl\dist.\.conf) to a specified output directory, simplifying the setup of secure inter-node communication.

scripts · high confidence

Introduces new codec architecture with dedicated modules for each protocol layer

The codebase now implements a layered codec architecture where the central \mtp\_codec\ module orchestrates the pipeline of TLS, crypto, and packet codecs. This change introduces new modules for each layer: \mtp\_abridged\, \mtp\_full\, \mtp\_intermediate\, and \mtp\_secure\ handle packet-level formatting, while \mtp\_aes\_cbc\ handles the encryption layer. Additionally, \mtp\_fake\_tls\ provides a fake TLS implementation for domain fronting, and \mtp\_config\ manages datacenter configuration and secrets. This structure allows for easier maintenance and testing of each protocol component independently.

src · high confidence

Test coverage

Added benchmarking and property-based tests for codecs

Added benchmarking modules (bench\_codec\_decode.erl, bench\_codec\_encode.erl) to measure the performance of various codec implementations including mtp\_fake\_tls, mtp\_intermediate, mtp\_secure, mtp\_full, mtp\_aes\_cbc, and mtp\_obfuscated. Additionally, introduced property-based tests (prop\mtp\\*.erl) to verify the correctness of encoding and decoding for all codec types, ensuring that data can be round-tripped without loss. New test helper modules (mtp\_test\_client, mtp\_test\_middle\_server, mtp\_test\_datacenter, mtp\_test\_echo\_rpc, mtp\_test\_metric, mtp\_test\_reporter\_rpc) and data generators (mtp\_prop\_gen) support these tests.

test · high confidence

Dependencies

Modernize build system and dependencies

The project has been modernized by removing the \lager\ logging library in favor of the native Erlang/OTP logger, and upgrading the \ranch\ dependency from version 1.5.0 to 2.2.0. The \goldrush\ dependency has also been removed. Additionally, a new \erlang\_psq\ dependency was added via Git.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 70 → 55 (-15.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 90 (new)
  • Architecture 100 (new)
  • Maturity 72 → 75 (+2.7)
  • Readiness 64 → 55 (-9.3)
  • Security 85 → 97 (+11.5)
  • Event-Driven 35 (new)
  • Event Sourcing 100 (new)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • The README begins with a legal disclaimers section ('‼️ DON'T USE TELEGRAM...') and ends with an unshown Features list, but the body is clipped mid-paragraph before any of the outlined sections (e.g. 'To run on single port with custom port, secret and ad-tag') appear. (README.md)
  • complexity unreadable for .erl — churn × complexity hotspots could not be measured

New (45)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (7 lines × 2) (src/mtp_down_conn.erl)
  • FileTooLong: src/mtp_down_conn.erl (src/mtp_down_conn.erl)
  • FileTooLong: src/mtp_handler.erl (src/mtp_handler.erl)
  • Floating source dependency: erlang_psq
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/mtp_handler.erl (src/mtp_handler.erl)
  • Hotspot: src/mtproto_proxy_app.erl (src/mtproto_proxy_app.erl)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • No ADRs found
  • Outdated: ranch
  • TodoComment (src/gen_timeout.erl)
  • TodoComment (src/mtp_config.erl)
  • TodoComment (src/mtp_dc_pool.erl)
  • …and 25 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

seriyps/mtproto_proxy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 154a8fb8e6ef85460f502d4b74434a22a5836937 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.