Compare commits
19
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dc7b598558 | ||
|
|
69f3a355c7 | ||
|
|
db52c06a72 | ||
|
|
4b14b62e74 | ||
|
|
5da91e4099 | ||
|
|
62731cc729 | ||
|
|
5e17ace690 | ||
|
|
b010471a4a | ||
|
|
c4ede96517 | ||
|
|
be06e1a502 | ||
|
|
094f42312c | ||
|
|
da8c3ec193 | ||
|
|
4fdf8e8c58 | ||
|
|
61b5d93b11 | ||
|
|
be06b3ce2b | ||
|
|
f3d96ae2ee | ||
|
|
a4ae375617 | ||
|
|
0646bc4e85 | ||
|
|
0faaf4577f |
@@ -1,5 +1,13 @@
|
|||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
|
## v1.8.11-alpha (2026-09-07)
|
||||||
|
|
||||||
|
- **Cuprate now syncs without burning a core for days.** The app's shipped config now enables Cuprate's checkpoint-backed `fast_sync` path, raises the database cache to 8 GiB, and gives the container a 10 GiB memory limit so the cache has real headroom. A live comparison that motivated the change saw the affected node sit around 45% CPU while the corrected config held near low single digits at the same chain height and block rate. The restricted RPC remains fronted through the safe app gate/Tor path.
|
||||||
|
|
||||||
|
- **OpenWrt Gateway setup is documented from a real install, and two setup bugs are fixed.** The new guide walks a node operator through flashing a GL.iNet AX3000 to stock OpenWrt, pairing it with Archipelago, and installing TollGate pay-as-you-go WiFi. The installer now finds `opkg`/`apk` through the router's actual `PATH` instead of assuming `/usr/bin`, the UI no longer sends an empty password over a saved router connection, and the pinned TollGate package moves to `v0.5.0` with a native `.apk` install path where upstream provides one.
|
||||||
|
|
||||||
|
- **Release publishing now checks the public Gitea download links before a manifest goes live.** The publisher already fetched every artifact back and verified its size and SHA-256; this release adds a second guard for the release page itself, so a bad Gitea `ROOT_URL` or proxy setting cannot publish working files behind broken public HTTPS download links.
|
||||||
|
|
||||||
## v1.8.10-alpha (2026-09-02)
|
## v1.8.10-alpha (2026-09-02)
|
||||||
|
|
||||||
- **Lightning sends work again — v1.8.9's payment switch lost the fee budget.** Moving payments to LND 0.21's supported route (Router.SendPaymentV2) shipped without a fee limit, and the v2 API treats an absent limit as **zero allowed fees**: every real route carries a routing fee, so the pathfinder rejected them all and the wallet answered "No route to the recipient" on every send — all day, on healthy channels with plenty of liquidity. The router debug log made it unambiguous (`fee_limit=0 mSAT` on every failing wallet payment; the same payment succeeded by hand the moment a fee limit was set). Payments now carry lncli's default budget (the payment amount), the wallet's amount handling for zero-value invoices is preserved, and a unit test pins the limit can never be zero again.
|
- **Lightning sends work again — v1.8.9's payment switch lost the fee budget.** Moving payments to LND 0.21's supported route (Router.SendPaymentV2) shipped without a fee limit, and the v2 API treats an absent limit as **zero allowed fees**: every real route carries a routing fee, so the pathfinder rejected them all and the wallet answered "No route to the recipient" on every send — all day, on healthy channels with plenty of liquidity. The router debug log made it unambiguous (`fee_limit=0 mSAT` on every failing wallet payment; the same payment succeeded by hand the moment a fee limit was set). Payments now carry lncli's default budget (the payment amount), the wallet's amount handling for zero-value invoices is preserved, and a unit test pins the limit can never be zero again.
|
||||||
|
|||||||
Generated
+1
-1
@@ -104,7 +104,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "archipelago"
|
name = "archipelago"
|
||||||
version = "1.8.10-alpha"
|
version = "1.8.11-alpha"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"archipelago-container",
|
"archipelago-container",
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "archipelago"
|
name = "archipelago"
|
||||||
version = "1.8.10-alpha"
|
version = "1.8.11-alpha"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
license.workspace = true
|
license.workspace = true
|
||||||
description = "Archipelago Bitcoin Node OS - Native backend"
|
description = "Archipelago Bitcoin Node OS - Native backend"
|
||||||
|
|||||||
@@ -135,7 +135,7 @@ impl RpcHandler {
|
|||||||
// not /usr/bin/tollgate-module-basic-go — that's only the opkg/apk
|
// not /usr/bin/tollgate-module-basic-go — that's only the opkg/apk
|
||||||
// *package* name, never an on-disk filename.
|
// *package* name, never an on-disk filename.
|
||||||
let tollgate_installed = router
|
let tollgate_installed = router
|
||||||
.run("/usr/bin/opkg list-installed 2>/dev/null | grep -q '^tollgate-module-basic-go ' || \
|
.run("opkg list-installed 2>/dev/null | grep -q '^tollgate-module-basic-go ' || \
|
||||||
test -f /usr/bin/tollgate-wrt 2>/dev/null")
|
test -f /usr/bin/tollgate-wrt 2>/dev/null")
|
||||||
.map(|(_, code)| code == 0)
|
.map(|(_, code)| code == 0)
|
||||||
.unwrap_or(false);
|
.unwrap_or(false);
|
||||||
|
|||||||
@@ -377,6 +377,23 @@ async fn write_staged_torrc(content: &str, staging: &str) -> Result<()> {
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod known_service_tests {
|
||||||
|
use super::{is_protocol_service, known_service_port};
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn bitcoin_core_is_a_protocol_service_on_the_p2p_port() {
|
||||||
|
// Regression: apps/bitcoin-core/manifest.yml uses id "bitcoin-core",
|
||||||
|
// distinct from the legacy "bitcoin"/"bitcoin-knots" ids. Missing
|
||||||
|
// here means auto-enrollment silently skips it (known_service_port
|
||||||
|
// returns 0) and, separately, regenerate_torrc falls back to the
|
||||||
|
// web-app HiddenServicePort-80 default instead of forwarding 8333
|
||||||
|
// straight through.
|
||||||
|
assert_eq!(known_service_port("bitcoin-core"), 8333);
|
||||||
|
assert!(is_protocol_service("bitcoin-core"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod torrc_tests {
|
mod torrc_tests {
|
||||||
use super::app_hidden_service_port_line;
|
use super::app_hidden_service_port_line;
|
||||||
@@ -594,7 +611,7 @@ fn is_valid_v3_onion(s: &str) -> bool {
|
|||||||
pub(in crate::api::rpc) fn known_service_port(name: &str) -> u16 {
|
pub(in crate::api::rpc) fn known_service_port(name: &str) -> u16 {
|
||||||
match name {
|
match name {
|
||||||
"archipelago" => 80,
|
"archipelago" => 80,
|
||||||
"bitcoin" | "bitcoin-knots" => 8333,
|
"bitcoin" | "bitcoin-core" | "bitcoin-knots" => 8333,
|
||||||
"electrs" | "electrumx" => 50001,
|
"electrs" | "electrumx" => 50001,
|
||||||
"lnd" => 8080,
|
"lnd" => 8080,
|
||||||
"btcpay" | "btcpay-server" | "btcpayserver" => 23000,
|
"btcpay" | "btcpay-server" | "btcpayserver" => 23000,
|
||||||
@@ -619,7 +636,7 @@ pub(in crate::api::rpc) fn known_service_port(name: &str) -> u16 {
|
|||||||
pub(in crate::api::rpc) fn is_protocol_service(name: &str) -> bool {
|
pub(in crate::api::rpc) fn is_protocol_service(name: &str) -> bool {
|
||||||
matches!(
|
matches!(
|
||||||
name,
|
name,
|
||||||
"bitcoin" | "bitcoin-knots" | "electrs" | "electrumx" | "lnd"
|
"bitcoin" | "bitcoin-core" | "bitcoin-knots" | "electrs" | "electrumx" | "lnd"
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -657,9 +657,19 @@ fn apply_dynamic_metadata(app_id: &str, meta: &mut AppMetadata) {
|
|||||||
/// Map app_id to Tor hidden service directory name.
|
/// Map app_id to Tor hidden service directory name.
|
||||||
/// "archipelago" is the main web UI (nginx port 80).
|
/// "archipelago" is the main web UI (nginx port 80).
|
||||||
/// Supports container names from deploy (archy-*, btcpay-server, etc.).
|
/// Supports container names from deploy (archy-*, btcpay-server, etc.).
|
||||||
|
///
|
||||||
|
/// This must match what enrollment actually names the hidden service dir
|
||||||
|
/// with — both the install-time auto-enroll (`install.rs`) and the manual
|
||||||
|
/// `tor.create-service` RPC write `HiddenServiceDir` using the raw
|
||||||
|
/// `package_id`/`name` verbatim, with no canonicalization. So `bitcoin-core`
|
||||||
|
/// gets its own identity arm rather than folding into the "bitcoin" alias:
|
||||||
|
/// aliasing it here without also canonicalizing the write side would point
|
||||||
|
/// this lookup at `hidden_service_bitcoin`, which never gets created — the
|
||||||
|
/// on-disk dir is always `hidden_service_bitcoin-core` for this app id.
|
||||||
fn tor_service_name(app_id: &str) -> Option<&'static str> {
|
fn tor_service_name(app_id: &str) -> Option<&'static str> {
|
||||||
match app_id {
|
match app_id {
|
||||||
"archipelago" => Some("archipelago"),
|
"archipelago" => Some("archipelago"),
|
||||||
|
"bitcoin-core" => Some("bitcoin-core"),
|
||||||
"bitcoin" | "bitcoin-knots" | "bitcoind" => Some("bitcoin"),
|
"bitcoin" | "bitcoin-knots" | "bitcoind" => Some("bitcoin"),
|
||||||
"electrumx" | "electrs" | "electrum" => Some("electrumx"),
|
"electrumx" | "electrs" | "electrum" => Some("electrumx"),
|
||||||
"lnd" | "lnd-ui" => Some("lnd"),
|
"lnd" | "lnd-ui" => Some("lnd"),
|
||||||
@@ -906,6 +916,28 @@ mod launch_url_port_tests {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tor_service_name_tests {
|
||||||
|
use super::tor_service_name;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn bitcoin_core_resolves_to_its_own_hidden_service_dir() {
|
||||||
|
// Regression: enrollment (install.rs, tor.create-service) writes
|
||||||
|
// HiddenServiceDir/tor-hostnames entries using the raw package_id
|
||||||
|
// verbatim, never canonicalized. Aliasing "bitcoin-core" to the
|
||||||
|
// shared "bitcoin" name here would point reads at a directory
|
||||||
|
// enrollment never creates.
|
||||||
|
assert_eq!(tor_service_name("bitcoin-core"), Some("bitcoin-core"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn legacy_bitcoin_ids_share_the_bitcoin_alias() {
|
||||||
|
assert_eq!(tor_service_name("bitcoin"), Some("bitcoin"));
|
||||||
|
assert_eq!(tor_service_name("bitcoin-knots"), Some("bitcoin"));
|
||||||
|
assert_eq!(tor_service_name("bitcoind"), Some("bitcoin"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod extract_lan_address_tests {
|
mod extract_lan_address_tests {
|
||||||
use super::extract_lan_address;
|
use super::extract_lan_address;
|
||||||
|
|||||||
+19
-15
@@ -15,25 +15,32 @@ pub enum PkgManager {
|
|||||||
impl Router {
|
impl Router {
|
||||||
/// Detect which package manager is available.
|
/// Detect which package manager is available.
|
||||||
///
|
///
|
||||||
/// - If `/usr/bin/opkg` exists → `PkgManager::Opkg` (nothing to do).
|
/// Looks up `opkg`/`apk` via the router's `$PATH` (`command -v`) rather
|
||||||
/// - If `/usr/bin/apk` exists → run `apk update` (switching repos to HTTP
|
/// than a hardcoded `/usr/bin/<tool>` — official OpenWrt images don't all
|
||||||
|
/// symlink `/bin` into `/usr/bin` (e.g. the `glinet_gl-mt3000` 24.10.2
|
||||||
|
/// build keeps them as separate real directories with `opkg` living in
|
||||||
|
/// `/bin`), so a fixed absolute path silently misses a perfectly normal
|
||||||
|
/// install and reports "no package management" (archy-x250-pa3, 2026-09-05).
|
||||||
|
///
|
||||||
|
/// - If `opkg` is on PATH → `PkgManager::Opkg` (nothing to do).
|
||||||
|
/// - If `apk` is on PATH → run `apk update` (switching repos to HTTP
|
||||||
/// first to work around missing CA bundle on fresh images), then try
|
/// first to work around missing CA bundle on fresh images), then try
|
||||||
/// `apk add opkg`. If opkg is in the repos → `Opkg`. If not (OpenWrt
|
/// `apk add opkg`. If opkg is in the repos → `Opkg`. If not (OpenWrt
|
||||||
/// 25.x) → `ApkNative`.
|
/// 25.x) → `ApkNative`.
|
||||||
/// - Neither found → error.
|
/// - Neither found → error.
|
||||||
pub fn opkg_check(&self) -> Result<PkgManager> {
|
pub fn opkg_check(&self) -> Result<PkgManager> {
|
||||||
let (_, code) = self.run("test -x /usr/bin/opkg")?;
|
let (_, code) = self.run("command -v opkg >/dev/null 2>&1")?;
|
||||||
if code == 0 {
|
if code == 0 {
|
||||||
return Ok(PkgManager::Opkg);
|
return Ok(PkgManager::Opkg);
|
||||||
}
|
}
|
||||||
|
|
||||||
let (_, apk_code) = self.run("test -x /usr/bin/apk")?;
|
let (_, apk_code) = self.run("command -v apk >/dev/null 2>&1")?;
|
||||||
if apk_code == 0 {
|
if apk_code == 0 {
|
||||||
info!("[{}] opkg not found — using apk (OpenWrt 25.x+)", self.host);
|
info!("[{}] opkg not found — using apk (OpenWrt 25.x+)", self.host);
|
||||||
// Fresh images ship without a CA bundle; switch repos to HTTP so
|
// Fresh images ship without a CA bundle; switch repos to HTTP so
|
||||||
// apk's wget can reach the package index without TLS verification.
|
// apk's wget can reach the package index without TLS verification.
|
||||||
self.run_ok("sed -i 's|https://|http://|g' /etc/apk/repositories 2>/dev/null || true")?;
|
self.run_ok("sed -i 's|https://|http://|g' /etc/apk/repositories 2>/dev/null || true")?;
|
||||||
let (update_out, update_code) = self.run("/usr/bin/apk update 2>&1")?;
|
let (update_out, update_code) = self.run("apk update 2>&1")?;
|
||||||
if update_code != 0 {
|
if update_code != 0 {
|
||||||
anyhow::bail!(
|
anyhow::bail!(
|
||||||
"apk update failed (exit {}) — router may have no internet access. \
|
"apk update failed (exit {}) — router may have no internet access. \
|
||||||
@@ -43,7 +50,7 @@ impl Router {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
// Try to install opkg (only available on some 25.x builds).
|
// Try to install opkg (only available on some 25.x builds).
|
||||||
let (add_out, add_code) = self.run("/usr/bin/apk add opkg 2>&1")?;
|
let (add_out, add_code) = self.run("apk add opkg 2>&1")?;
|
||||||
if add_code == 0 {
|
if add_code == 0 {
|
||||||
return Ok(PkgManager::Opkg);
|
return Ok(PkgManager::Opkg);
|
||||||
}
|
}
|
||||||
@@ -62,7 +69,7 @@ impl Router {
|
|||||||
}
|
}
|
||||||
|
|
||||||
anyhow::bail!(
|
anyhow::bail!(
|
||||||
"opkg not found at /usr/bin/opkg — this router's firmware may not \
|
"Neither opkg nor apk found on this router's $PATH — its firmware may not \
|
||||||
support package management (TollGate requires a standard OpenWrt build)"
|
support package management (TollGate requires a standard OpenWrt build)"
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
@@ -70,31 +77,28 @@ impl Router {
|
|||||||
/// `opkg update` — refresh package lists.
|
/// `opkg update` — refresh package lists.
|
||||||
pub fn opkg_update(&self) -> Result<()> {
|
pub fn opkg_update(&self) -> Result<()> {
|
||||||
info!("[{}] opkg update", self.host);
|
info!("[{}] opkg update", self.host);
|
||||||
self.run_ok("/usr/bin/opkg update")?;
|
self.run_ok("opkg update")?;
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Install a package, skipping if already installed.
|
/// Install a package, skipping if already installed.
|
||||||
pub fn opkg_install(&self, package: &str) -> Result<()> {
|
pub fn opkg_install(&self, package: &str) -> Result<()> {
|
||||||
// Check if already installed to avoid unnecessary network traffic.
|
// Check if already installed to avoid unnecessary network traffic.
|
||||||
let (_, code) = self.run(&format!(
|
let (_, code) = self.run(&format!("opkg list-installed | grep -q '^{} '", package))?;
|
||||||
"/usr/bin/opkg list-installed | grep -q '^{} '",
|
|
||||||
package
|
|
||||||
))?;
|
|
||||||
if code == 0 {
|
if code == 0 {
|
||||||
info!("[{}] {} already installed", self.host, package);
|
info!("[{}] {} already installed", self.host, package);
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
|
|
||||||
info!("[{}] opkg install {}", self.host, package);
|
info!("[{}] opkg install {}", self.host, package);
|
||||||
self.run_ok(&format!("/usr/bin/opkg install {}", package))?;
|
self.run_ok(&format!("opkg install {}", package))?;
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Remove a package.
|
/// Remove a package.
|
||||||
pub fn opkg_remove(&self, package: &str) -> Result<()> {
|
pub fn opkg_remove(&self, package: &str) -> Result<()> {
|
||||||
info!("[{}] opkg remove {}", self.host, package);
|
info!("[{}] opkg remove {}", self.host, package);
|
||||||
self.run_ok(&format!("/usr/bin/opkg remove {}", package))?;
|
self.run_ok(&format!("opkg remove {}", package))?;
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -121,7 +125,7 @@ impl Router {
|
|||||||
}
|
}
|
||||||
|
|
||||||
info!("[{}] apk add {}", self.host, package);
|
info!("[{}] apk add {}", self.host, package);
|
||||||
self.run_ok(&format!("/usr/bin/apk add {}", package))?;
|
self.run_ok(&format!("apk add {}", package))?;
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,18 +6,53 @@ use crate::Router;
|
|||||||
/// The OpenWrt package name for the TollGate reference implementation.
|
/// The OpenWrt package name for the TollGate reference implementation.
|
||||||
const TOLLGATE_PACKAGE: &str = "tollgate-module-basic-go";
|
const TOLLGATE_PACKAGE: &str = "tollgate-module-basic-go";
|
||||||
|
|
||||||
/// Direct-download fallback URLs by opkg architecture string.
|
/// Pinned upstream release. Was stuck on v0.2.0 (Oct 2025) until 2026-09-05 —
|
||||||
|
/// nine releases behind. v0.5.0's changelog covers exactly the failure modes
|
||||||
|
/// hit live against archy-x250-pa3: a mint with an empty/broken keyset used
|
||||||
|
/// to crash-loop the daemon forever ("graceful degradation when Cashu mints
|
||||||
|
/// fail" in v0.5.0), and the bundled captive-portal build had no CBOR support
|
||||||
|
/// at all, so it could only decode legacy `cashuA` tokens — rejecting the
|
||||||
|
/// `cashuB` (NUT-00 V4) tokens modern wallets like Minibits generate by
|
||||||
|
/// default ("portal improvements" in v0.5.0 include a JS bundle update that
|
||||||
|
/// should carry a current cashu-ts with V4 support). Bump this string to move
|
||||||
|
/// both this crate's URLs and the version baked into the source comments.
|
||||||
|
const TOLLGATE_VERSION: &str = "v0.5.0";
|
||||||
|
|
||||||
|
/// Direct-download fallback URLs by opkg architecture string, for the
|
||||||
|
/// `.ipk` (ar-archive) package format.
|
||||||
/// Used when the package is not in any configured feed.
|
/// Used when the package is not in any configured feed.
|
||||||
/// Source: https://github.com/OpenTollGate/tollgate-module-basic-go/releases/tag/v0.2.0
|
/// Source: https://github.com/OpenTollGate/tollgate-module-basic-go/releases/tag/v0.5.0
|
||||||
fn ipk_url(arch: &str) -> Option<&'static str> {
|
fn ipk_url(arch: &str) -> Option<String> {
|
||||||
match arch {
|
let name = match arch {
|
||||||
"mips_24kc" => Some("https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/v0.2.0/mips_24kc.ipk"),
|
"mips_24kc" => "mips_24kc",
|
||||||
"mipsel_24kc" => Some("https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/v0.2.0/mipsel_24kc.ipk"),
|
"mipsel_24kc" => "mipsel_24kc",
|
||||||
"aarch64_cortex-a53" => Some("https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/v0.2.0/aarch64_cortex-a53.ipk"),
|
"aarch64_cortex-a53" => "aarch64_cortex-a53",
|
||||||
"aarch64_cortex-a72" => Some("https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/v0.2.0/aarch64_cortex-a72.ipk"),
|
"aarch64_cortex-a72" => "aarch64_cortex-a72",
|
||||||
"arm_cortex-a7" => Some("https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/v0.2.0/arm_cortex-a7.ipk"),
|
"arm_cortex-a7" => "arm_cortex-a7",
|
||||||
_ => None,
|
"x86_64" => "x86_64",
|
||||||
}
|
_ => return None,
|
||||||
|
};
|
||||||
|
Some(format!(
|
||||||
|
"https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/{TOLLGATE_VERSION}/tollgate-wrt_{TOLLGATE_VERSION}_{name}.ipk"
|
||||||
|
))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Direct-download URLs for the native Alpine-style `.apk` package format —
|
||||||
|
/// only published for a subset of architectures as of v0.5.0. Where
|
||||||
|
/// available this is strictly better than [`ipk_url`] on an apk-native
|
||||||
|
/// (OpenWrt 25.x+) router: `apk add` installs it directly (dependency
|
||||||
|
/// resolution, postinst, uci-defaults all handled by apk itself), instead of
|
||||||
|
/// the manual `ar`/`tar` extraction dance `install_ipk` has to do to unpack
|
||||||
|
/// an `.ipk` on a router with no `opkg`.
|
||||||
|
fn apk_url(arch: &str) -> Option<String> {
|
||||||
|
let name = match arch {
|
||||||
|
"aarch64_cortex-a53" => "aarch64_cortex-a53",
|
||||||
|
"x86_64" => "x86_64",
|
||||||
|
_ => return None,
|
||||||
|
};
|
||||||
|
Some(format!(
|
||||||
|
"https://github.com/OpenTollGate/tollgate-module-basic-go/releases/download/{TOLLGATE_VERSION}/tollgate-wrt_{TOLLGATE_VERSION}_{name}.apk"
|
||||||
|
))
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Install tollgate-module-basic-go via opkg (OpenWrt ≤24.x).
|
/// Install tollgate-module-basic-go via opkg (OpenWrt ≤24.x).
|
||||||
@@ -34,8 +69,9 @@ pub fn install_tollgate(router: &Router) -> Result<()> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Package not in any feed — download the .ipk directly.
|
// Package not in any feed — download the .ipk directly.
|
||||||
let arch = router
|
let arch = router.run_ok(
|
||||||
.run_ok("/usr/bin/opkg print-architecture | grep -v all | grep -v noarch | tail -1 | awk '{print $2}'")?;
|
"opkg print-architecture | grep -v all | grep -v noarch | tail -1 | awk '{print $2}'",
|
||||||
|
)?;
|
||||||
let arch = arch.trim();
|
let arch = arch.trim();
|
||||||
|
|
||||||
let url = ipk_url(arch).ok_or_else(|| {
|
let url = ipk_url(arch).ok_or_else(|| {
|
||||||
@@ -88,7 +124,7 @@ pub fn install_tollgate_apk_native(router: &Router) -> Result<()> {
|
|||||||
". /etc/openwrt_release 2>/dev/null \
|
". /etc/openwrt_release 2>/dev/null \
|
||||||
&& a=\"${DISTRIB_ARCH:-${OPENWRT_ARCH:-}}\" \
|
&& a=\"${DISTRIB_ARCH:-${OPENWRT_ARCH:-}}\" \
|
||||||
&& [ -n \"$a\" ] && echo \"$a\" \
|
&& [ -n \"$a\" ] && echo \"$a\" \
|
||||||
|| /usr/bin/apk --print-arch 2>/dev/null \
|
|| apk --print-arch 2>/dev/null \
|
||||||
|| uname -m",
|
|| uname -m",
|
||||||
)?;
|
)?;
|
||||||
// Normalise: uname -m returns bare "mipsel"/"mips"; map to 24kc variant
|
// Normalise: uname -m returns bare "mipsel"/"mips"; map to 24kc variant
|
||||||
@@ -103,6 +139,38 @@ pub fn install_tollgate_apk_native(router: &Router) -> Result<()> {
|
|||||||
anyhow::bail!("Could not determine router architecture");
|
anyhow::bail!("Could not determine router architecture");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Prefer a native .apk when the release publishes one for this arch —
|
||||||
|
// `apk add` handles the install itself (deps, postinst, uci-defaults),
|
||||||
|
// skipping the manual ar/tar extraction the .ipk fallback below needs.
|
||||||
|
if let Some(url) = apk_url(arch) {
|
||||||
|
info!(
|
||||||
|
"[{}] Downloading native TollGate .apk for {} from GitHub releases",
|
||||||
|
router.host, arch
|
||||||
|
);
|
||||||
|
let (dl_out, dl_code) = router.run(&format!(
|
||||||
|
"wget --no-check-certificate -O /tmp/tollgate.apk '{}' 2>&1",
|
||||||
|
url
|
||||||
|
))?;
|
||||||
|
if dl_code != 0 {
|
||||||
|
anyhow::bail!("TollGate .apk download failed: {}", dl_out.trim());
|
||||||
|
}
|
||||||
|
let (size_out, _) = router.run("wc -c < /tmp/tollgate.apk 2>/dev/null")?;
|
||||||
|
let size: u64 = size_out.trim().parse().unwrap_or(0);
|
||||||
|
if size < 50_000 {
|
||||||
|
anyhow::bail!(
|
||||||
|
"Downloaded TollGate .apk is only {}B — wget likely captured an error page. \
|
||||||
|
Check router internet access and that the release URL is reachable.",
|
||||||
|
size
|
||||||
|
);
|
||||||
|
}
|
||||||
|
let (add_out, add_code) = router.run("apk add --allow-untrusted /tmp/tollgate.apk 2>&1")?;
|
||||||
|
router.run_ok("rm -f /tmp/tollgate.apk")?;
|
||||||
|
if add_code != 0 {
|
||||||
|
anyhow::bail!("TollGate .apk install failed: {}", add_out.trim());
|
||||||
|
}
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
let url = ipk_url(arch).ok_or_else(|| {
|
let url = ipk_url(arch).ok_or_else(|| {
|
||||||
anyhow::anyhow!(
|
anyhow::anyhow!(
|
||||||
"No pre-built TollGate package for architecture '{}'. \
|
"No pre-built TollGate package for architecture '{}'. \
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ disagree, the code wins and the doc is a bug.
|
|||||||
- [Talking to your node](COMMANDS.md) — the conversational command surface
|
- [Talking to your node](COMMANDS.md) — the conversational command surface
|
||||||
- [Seed Verification](SEED-VERIFICATION.md) — independently verify your 24-word backup
|
- [Seed Verification](SEED-VERIFICATION.md) — independently verify your 24-word backup
|
||||||
- [Troubleshooting](troubleshooting.md) — common problems and how to resolve them
|
- [Troubleshooting](troubleshooting.md) — common problems and how to resolve them
|
||||||
|
- [OpenWrt Gateway Setup](openwrt-gateway-setup.md) — pairing an OpenWrt router and provisioning TollGate pay-as-you-go WiFi
|
||||||
- [Gamepad / Controller Navigation](GAMEPAD-NAV.md) — driving the UI from a controller
|
- [Gamepad / Controller Navigation](GAMEPAD-NAV.md) — driving the UI from a controller
|
||||||
- [Pine voice commands](pine-voice-commands.md) — the voice-satellite phrase surface
|
- [Pine voice commands](pine-voice-commands.md) — the voice-satellite phrase surface
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,299 @@
|
|||||||
|
# OpenWrt Gateway Setup
|
||||||
|
|
||||||
|
How to connect an OpenWrt router to an Archipelago node and, optionally, turn
|
||||||
|
it into a pay-as-you-go WiFi gateway with **TollGate**. Written for a node
|
||||||
|
operator following the UI; a developer-facing RPC/architecture reference is
|
||||||
|
at the bottom.
|
||||||
|
|
||||||
|
This feature manages a **separate physical (or virtual) router** running
|
||||||
|
OpenWrt over SSH/UCI — it is not a containerized app. Archipelago itself does
|
||||||
|
not flash or install OpenWrt; you bring a router that already runs it.
|
||||||
|
|
||||||
|
## What you get
|
||||||
|
|
||||||
|
- **Status dashboard**: hostname, uptime, firmware release, WiFi interfaces,
|
||||||
|
WAN state — polled live from the router.
|
||||||
|
- **WAN/WISP wizard**: point the router's radio at an upstream WiFi network
|
||||||
|
(turns it into a wireless bridge/repeater) with DHCP + NAT configured for
|
||||||
|
you.
|
||||||
|
- **TollGate provisioning** (optional): installs the
|
||||||
|
[TollGate](https://tollgate.me) captive-portal package
|
||||||
|
(`tollgate-module-basic-go`) and stands up an `archipelago` SSID that
|
||||||
|
sells timed internet access for sats, settled against this node's local
|
||||||
|
Cashu mint.
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
1. **A router already flashed with OpenWrt.** Check the
|
||||||
|
[OpenWrt Table of Hardware](https://openwrt.org/toh/start) for your model
|
||||||
|
and follow OpenWrt's own install/flashing instructions — that part is
|
||||||
|
outside Archipelago's scope. See below for a worked example (GL.iNet
|
||||||
|
AX3000).
|
||||||
|
2. **SSH reachable.** Fresh OpenWrt images enable `dropbear` (SSH) on LAN by
|
||||||
|
default, listening as `root` with no password (or the password you set
|
||||||
|
during OpenWrt's first-boot wizard at `192.168.1.1`). Archipelago
|
||||||
|
connects with `ssh2` over a password (key-based auth is supported at the
|
||||||
|
library level but the UI only offers password so far).
|
||||||
|
3. **Same LAN as the Archipelago node**, at least for setup — plug the
|
||||||
|
router's LAN port into the same switch/network segment the node is on.
|
||||||
|
4. **For TollGate**: a running Cashu mint app (`nutshell`/`cashu-mint`) on
|
||||||
|
this node — provisioning defaults `mint_url` to
|
||||||
|
`http://<node-ip>:3338` and TollGate customers must be able to reach that
|
||||||
|
URL from outside the node's loopback.
|
||||||
|
|
||||||
|
## Worked example: flashing a GL.iNet AX3000 to stock OpenWrt
|
||||||
|
|
||||||
|
GL.iNet's "AX3000" travel router is the **Beryl AX (GL-MT3000)** —
|
||||||
|
MediaTek MT7981B (Cortex-A53), OpenWrt target `mediatek/filogic`. It ships
|
||||||
|
running a GL.iNet fork of OpenWrt with its own web UI and LuCI already
|
||||||
|
enabled, but the steps below replace that with stock/vanilla OpenWrt so it
|
||||||
|
matches the prebuilt TollGate `.ipk` architectures exactly
|
||||||
|
(`aarch64_cortex-a53`).
|
||||||
|
|
||||||
|
1. **Download the sysupgrade image** for the current stable release from
|
||||||
|
`https://downloads.openwrt.org/releases/<version>/targets/mediatek/filogic/`
|
||||||
|
— the file you want is
|
||||||
|
`openwrt-<version>-mediatek-filogic-glinet_gl-mt3000-squashfs-sysupgrade.bin`.
|
||||||
|
2. **Verify the checksum** against the `sha256sums` file in that same
|
||||||
|
directory before flashing anything.
|
||||||
|
3. **Flash from the GL.iNet UI**: on the router's default address
|
||||||
|
(`192.168.8.1`), go to **More Settings → Upgrade → Local Upgrade**, or
|
||||||
|
open **Advanced → LuCI** and use **System → Backup / Flash Firmware →
|
||||||
|
Flash new firmware image**.
|
||||||
|
4. Upload the `.bin` file. **Uncheck "Keep Settings"** — going from the
|
||||||
|
GL.iNet fork to stock OpenWrt needs a clean reset, not a config carry-over.
|
||||||
|
5. Confirm and wait ~3–5 minutes without power-cycling the router.
|
||||||
|
6. **After it reboots** you're on stock OpenWrt: LAN at `192.168.1.1`, DHCP
|
||||||
|
on, SSH (dropbear) open as `root` with **no password set yet** — set one
|
||||||
|
via LuCI at `192.168.1.1` or `passwd` over SSH before doing anything else.
|
||||||
|
From here, continue with the Prerequisites/Step 2 flow above to connect
|
||||||
|
it to the Archipelago node.
|
||||||
|
|
||||||
|
> The Archipelago UI's Connect form (Step 2) authenticates *with* a
|
||||||
|
> password — it has no flow for setting the initial one on a fresh,
|
||||||
|
> passwordless router. You have to set it out-of-band first. If you're
|
||||||
|
> working from the node's own local kiosk display rather than a normal
|
||||||
|
> desktop browser, there's no visible tab bar/address bar to open a new
|
||||||
|
> tab from — press **Ctrl+T** to open one anyway, navigate to
|
||||||
|
> `192.168.1.1`, and use LuCI's first-boot prompt to set the root
|
||||||
|
> password. Then switch back to the Archipelago tab and Connect with it.
|
||||||
|
|
||||||
|
**If the flash fails / the router doesn't come back**: filogic devices
|
||||||
|
don't use a reset-button recovery. Instead, connect to the router's LAN
|
||||||
|
port and, during boot, press a key within the first ~2 seconds to enter
|
||||||
|
U-Boot; per the OpenWrt wiki, typing `gl` then `httpd` at the U-Boot prompt
|
||||||
|
brings up a recovery web UI at `192.168.1.2` that accepts a firmware image.
|
||||||
|
|
||||||
|
## Step 1: Open the OpenWrt Gateway panel
|
||||||
|
|
||||||
|
1. In the Archipelago UI, go to **Server**.
|
||||||
|
2. Under the network status list, click **OpenWrt Gateway**
|
||||||
|
(`/dashboard/server/openwrt`).
|
||||||
|
|
||||||
|
If no router has been connected before, you'll land on the connect form.
|
||||||
|
|
||||||
|
## Step 2: Connect the router
|
||||||
|
|
||||||
|
You have two options:
|
||||||
|
|
||||||
|
- **Detect**: click **Detect** — this reads the node's own active wired
|
||||||
|
Ethernet interface, derives its subnet, and probes every host on it for
|
||||||
|
`TCP/22` + a valid `/etc/openwrt_release`. If it finds exactly one router
|
||||||
|
it fills in the host automatically; if it finds several you pick from the
|
||||||
|
list. A `/24` scan can take up to ~2 minutes (255 sequential probes at
|
||||||
|
500 ms each on hosts that don't respond).
|
||||||
|
- **Manual**: type the router's LAN IP (commonly `192.168.1.1` on a router
|
||||||
|
freshly bridged in, or whatever address it has on your network) plus the
|
||||||
|
SSH username (default `root`) and password.
|
||||||
|
|
||||||
|
Click **Connect**. On success the panel switches to the status dashboard and
|
||||||
|
the connection (host + credentials) is persisted server-side — you won't
|
||||||
|
need to re-enter them on future visits or from other views (e.g. the Home
|
||||||
|
dashboard's network tile also polls this without prompting again).
|
||||||
|
|
||||||
|
> Credentials are stored in `router_config.json` under the node's data
|
||||||
|
> directory alongside other node config. There's no separate secrets
|
||||||
|
> vault entry for this yet — treat the router's SSH password like any other
|
||||||
|
> node-local config.
|
||||||
|
|
||||||
|
## Step 3: (Optional) Configure WAN/WISP
|
||||||
|
|
||||||
|
Use this to make the OpenWrt router pull its internet connection from an
|
||||||
|
upstream WiFi network instead of a wired uplink — useful for a
|
||||||
|
battery/off-grid TollGate node or extending coverage from an existing
|
||||||
|
network.
|
||||||
|
|
||||||
|
1. From the status dashboard, start the **WAN setup** wizard.
|
||||||
|
2. **Scan** — the router's radio scans for visible networks (a few seconds
|
||||||
|
of SSH round-trips).
|
||||||
|
3. **Select network** — pick the upstream SSID from the list.
|
||||||
|
4. **Password** — enter the upstream network's WiFi password (encryption
|
||||||
|
defaults to `psk2`; leave blank only for open networks).
|
||||||
|
5. **DHCP / NAT** — review the LAN DHCP pool (default `.100`–`.249`) and
|
||||||
|
whether to enable NAT/masquerade on the WAN zone (leave this on unless
|
||||||
|
you have a specific reason not to).
|
||||||
|
6. **Connect** — this writes a `wwan` STA `wifi-iface` + `network` interface
|
||||||
|
over UCI, enables the radio if it was disabled (OpenWrt ships with
|
||||||
|
`radio0.disabled=1` on a fresh flash), and adds `wwan` to the WAN
|
||||||
|
firewall zone.
|
||||||
|
|
||||||
|
The dashboard's WAN panel shows the resulting association state, assigned
|
||||||
|
IP, and whether the router currently has internet reachability.
|
||||||
|
|
||||||
|
## Step 4: (Optional) Install TollGate
|
||||||
|
|
||||||
|
Once connected (and with a local Cashu mint app running), the dashboard
|
||||||
|
shows a **TollGate: not installed** panel with a single **Install TollGate**
|
||||||
|
button — there's no config form at this stage, it installs with defaults.
|
||||||
|
The panel itself warns: *"Router needs internet access to install TollGate
|
||||||
|
— configure WAN above first"* (Step 3), since the router has to reach the
|
||||||
|
internet to download the package.
|
||||||
|
|
||||||
|
1. Click **Install TollGate**. The button relabels to *"Installing… this
|
||||||
|
may take a few minutes"* while it works.
|
||||||
|
2. Under the hood this installs `tollgate-module-basic-go` on the router
|
||||||
|
(via `opkg` on OpenWrt ≤24.x, or a manual `.ipk` extract on 25.x images
|
||||||
|
where `opkg` isn't available), writes `/etc/tollgate/config.json`, and
|
||||||
|
creates the `archipelago` SSID — all with default pricing (10 sats per
|
||||||
|
1-minute step, minimum 1 step, `mint_url` auto-filled to
|
||||||
|
`http://<node-ip>:3338`, enabled).
|
||||||
|
3. On success you'll see *"TollGate provisioned successfully"* and the
|
||||||
|
panel switches to the installed view (Enabled/Disabled badge, current
|
||||||
|
price/step/mint).
|
||||||
|
|
||||||
|
### Configuring price, step size, or mint (after install)
|
||||||
|
|
||||||
|
The installed-state panel has an **Edit** button — this is the only place
|
||||||
|
you set price/step/mint, and it only appears once TollGate is already
|
||||||
|
installed:
|
||||||
|
|
||||||
|
1. Click **Edit**.
|
||||||
|
2. Set **Price** (sats), **Step size** (minutes — billed as `step_size_ms`
|
||||||
|
under the hood), **Minimum steps** a customer must buy at once, **Mint
|
||||||
|
URL** (leave as the auto-filled node URL unless pointing at an external
|
||||||
|
mint), and the **Enable TollGate** toggle.
|
||||||
|
3. Click **Save**. Changes are pushed to `/etc/tollgate/config.json` and the
|
||||||
|
daemon is restarted to pick them up — it does not hot-reload.
|
||||||
|
|
||||||
|
Anyone who joins the `archipelago` SSID sees TollGate's captive portal and
|
||||||
|
pays sats (via the configured Cashu mint) for timed access.
|
||||||
|
|
||||||
|
## Verifying a successful install
|
||||||
|
|
||||||
|
A clean install (flash → Connect → WAN/WISP → Install TollGate, all through
|
||||||
|
the UI as above) ends in this state — worth checking if you want to confirm
|
||||||
|
everything actually landed correctly rather than trusting the UI's success
|
||||||
|
toast alone:
|
||||||
|
|
||||||
|
- `tollgate-wrt` is running (`/etc/init.d/tollgate-wrt status` → `running`).
|
||||||
|
- nodogsplash's **rendered** config — not just the UCI source — has
|
||||||
|
`GatewayInterface br-tollgate`. Check the actual file the daemon was
|
||||||
|
started with (typically `/tmp/etc/nodogsplash_main.conf`), since that's
|
||||||
|
what's actually enforced, not `uci show nodogsplash`. This matters because
|
||||||
|
provisioning must stop nodogsplash and reconfigure it to gate the
|
||||||
|
`br-tollgate` bridge *before* starting it — installing the package by hand
|
||||||
|
(bypassing the UI/RPC flow) leaves nodogsplash on its default
|
||||||
|
`br-lan`-gating behavior instead, which locks out the router's own
|
||||||
|
admin/SSH access. If you ever see a router become unreachable right after
|
||||||
|
a TollGate install, this is the first thing to check.
|
||||||
|
- The router's own LAN (the interface you manage it over — SSH, ping) is
|
||||||
|
still reachable and untouched by the portal.
|
||||||
|
- TollGate's own log (`logread | grep tollgate-wrt`) shows successful mint
|
||||||
|
probes for each configured mint.
|
||||||
|
|
||||||
|
A `dev build detected (branch=unknown), injecting test mint:
|
||||||
|
https://nofee.testnut.cashu.space` line in that log means the installed
|
||||||
|
build considers itself a dev build and silently adds a test mint alongside
|
||||||
|
your configured one(s) — check the Edit panel's Mint URL afterward if you
|
||||||
|
don't want that test mint accepted.
|
||||||
|
|
||||||
|
### A note on network topology during setup
|
||||||
|
|
||||||
|
If the Archipelago node reaches the router over the same wired interface the
|
||||||
|
router uses as its LAN, expect the router to become the node's default
|
||||||
|
route on that interface once it has its own working WAN/WISP uplink — this
|
||||||
|
is normal and, once WAN is actually configured with internet access, works
|
||||||
|
fine end-to-end (the node's traffic routes out through the router's
|
||||||
|
uplink). It's only a problem *before* WAN is configured: a freshly flashed
|
||||||
|
or freshly factory-reset router has no upstream internet yet, so if it wins
|
||||||
|
the node's default-route race (lowest metric on its own interface) while
|
||||||
|
still offline, it creates a dead-end route and the node loses its own
|
||||||
|
connectivity (including anything tunneled, e.g. a VPN/mesh network the node
|
||||||
|
relies on) until that route is removed or the router gets its uplink
|
||||||
|
working. If you hit this, either wait until WAN/WISP is actually up before
|
||||||
|
letting the router's interface win the route race, or temporarily lower the
|
||||||
|
priority of that route until it is.
|
||||||
|
|
||||||
|
## Reconfiguring or moving to a different router
|
||||||
|
|
||||||
|
Use **Disconnect** on the status dashboard to return to the connect form —
|
||||||
|
this only clears the panel's client-side state, it doesn't delete the
|
||||||
|
persisted `router_config.json`, so reconnecting to the same router needs no
|
||||||
|
re-entry. To point at a *different* router, disconnect and connect with a
|
||||||
|
new host/credentials; the newly connected router becomes the persisted one.
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
- **"No router configured"**: nothing has been connected yet, or the saved
|
||||||
|
config didn't include a host — go through Step 2 again.
|
||||||
|
- **Connect hangs or times out**: the router isn't reachable on `TCP/22`
|
||||||
|
from the node's network, or SSH auth failed. Confirm you can `ssh
|
||||||
|
root@<router-ip>` manually from the node (or a machine on the same LAN)
|
||||||
|
with the same credentials.
|
||||||
|
- **Router "moved networks" / stale saved host**: SSH/status calls are
|
||||||
|
bounded (5s TCP connect, 30s read/write) precisely so an unreachable
|
||||||
|
saved router can't stall other RPCs — but the dashboard will show a
|
||||||
|
connection error until you reconnect with the router's current address.
|
||||||
|
- **TollGate provision fails with "No pre-built TollGate package for
|
||||||
|
architecture..."**: your router's SoC isn't one of the prebuilt
|
||||||
|
`.ipk` targets (`mips_24kc`, `mipsel_24kc`, `aarch64_cortex-a53`,
|
||||||
|
`aarch64_cortex-a72`, `arm_cortex-a7`). You'll need a custom opkg feed or
|
||||||
|
to build `tollgate-module-basic-go` from source for your architecture.
|
||||||
|
- **TollGate download looks like it succeeded but provisioning still
|
||||||
|
fails**: the node sanity-checks the downloaded `.ipk` is at least 50 KB —
|
||||||
|
a smaller file usually means `wget` captured an HTML error page instead
|
||||||
|
(no internet access from the router, or a bad release URL).
|
||||||
|
- **Install fails right after a reboot or a fresh WAN setup** with `apk
|
||||||
|
update failed ... router may have no internet access` even though WAN
|
||||||
|
looks configured: this is usually just timing, not a real problem — the
|
||||||
|
router's WiFi-uplink association (`wwan`/`hakodosh`-style STA interface)
|
||||||
|
can take a few seconds longer to reconnect than the dashboard takes to
|
||||||
|
let you click Install. Wait ~10–15 seconds after WAN shows `sta_state:
|
||||||
|
up` and retry; it should succeed on the next attempt.
|
||||||
|
- **Install fails with `opkg not found at /usr/bin/opkg` (or similar) even
|
||||||
|
though the router clearly has `opkg`/`apk` installed**: fixed as of
|
||||||
|
2026-09-05 — the backend used to hardcode `/usr/bin/opkg`/`/usr/bin/apk`,
|
||||||
|
which some official OpenWrt builds don't symlink into `/bin`. If you're
|
||||||
|
running an Archipelago build from before that fix, update first.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Developer reference
|
||||||
|
|
||||||
|
Backend crate: `core/openwrt` (`archipelago-openwrt`) — SSH/UCI plumbing,
|
||||||
|
WAN/WISP config, WiFi scanning, and TollGate install/config. See
|
||||||
|
[`architecture.md`](architecture.md) for where it sits in the workspace.
|
||||||
|
|
||||||
|
RPC methods (`core/archipelago/src/api/rpc/openwrt.rs`, dispatched in
|
||||||
|
`core/archipelago/src/api/rpc/dispatcher.rs`):
|
||||||
|
|
||||||
|
| Method | Purpose |
|
||||||
|
|---|---|
|
||||||
|
| `openwrt.scan` | Probe a subnet for OpenWrt routers (`subnet`, `prefix`, `ssh_user`, `ssh_password`) |
|
||||||
|
| `openwrt.get-status` | Full status: release, WiFi interfaces, WAN, TollGate state. No params → uses saved `router_config.json`; params with `host` also persist the connection |
|
||||||
|
| `openwrt.configure-wan` | Write WISP/WAN config (`ssid`, `password`, `encryption`, `dhcp_start`, `dhcp_limit`, `masq`) |
|
||||||
|
| `openwrt.scan-wifi` | Radio scan for visible upstream networks |
|
||||||
|
| `openwrt.provision-tollgate` | Install/reconfigure TollGate (`price_sats`, `step_size_ms`, `min_steps`, `mint_url`, `enabled`) |
|
||||||
|
|
||||||
|
Note: these are distinct from the unrelated `router.*` methods
|
||||||
|
(`router.discover`, `router.configure`, `router.list-forwards`, ...), which
|
||||||
|
handle UPnP/NAT-PMP port forwarding on the node's own upstream home router —
|
||||||
|
not the OpenWrt gateway feature described here.
|
||||||
|
|
||||||
|
Frontend: `neode-ui/src/views/server/OpenWrtGateway.vue`, routed at
|
||||||
|
`server/openwrt` (`neode-ui/src/router/index.ts`), linked from
|
||||||
|
`neode-ui/src/views/Server.vue`.
|
||||||
|
|
||||||
|
Persisted connection state: `router_config.json` in the node's data
|
||||||
|
directory (`core/archipelago/src/network/router.rs`:
|
||||||
|
`load_router_config`/`save_router_config`).
|
||||||
Generated
+2
-2
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"version": "1.8.10-alpha",
|
"version": "1.8.11-alpha",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"version": "1.8.10-alpha",
|
"version": "1.8.11-alpha",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@scure/bip39": "^2.2.0",
|
"@scure/bip39": "^2.2.0",
|
||||||
"@types/dompurify": "^3.0.5",
|
"@types/dompurify": "^3.0.5",
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "1.8.10-alpha",
|
"version": "1.8.11-alpha",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"start": "./start-dev.sh",
|
"start": "./start-dev.sh",
|
||||||
|
|||||||
@@ -64,10 +64,10 @@ describe('appSessionConfig', () => {
|
|||||||
configurable: true,
|
configurable: true,
|
||||||
})
|
})
|
||||||
|
|
||||||
// did-wallet's manifest publishes host port 8088 (apps/did-wallet/
|
// searxng's manifest publishes host port 8888 (apps/searxng/
|
||||||
// manifest.yml) — assert against the manifest-generated value, which is
|
// manifest.yml) — assert against the manifest-generated value, which is
|
||||||
// exactly what this test exists to protect.
|
// exactly what this test exists to protect.
|
||||||
expect(resolveAppUrl('did-wallet')).toBe('http://192.0.2.10:8088')
|
expect(resolveAppUrl('searxng')).toBe('http://192.0.2.10:8888')
|
||||||
})
|
})
|
||||||
|
|
||||||
it('does not treat service-only tcp ports as web launch surfaces', () => {
|
it('does not treat service-only tcp ports as web launch surfaces', () => {
|
||||||
|
|||||||
@@ -115,6 +115,24 @@ const showConnectForm = ref(false)
|
|||||||
const connecting = ref(false)
|
const connecting = ref(false)
|
||||||
const connectedParams = ref<Record<string, string> | null>(null)
|
const connectedParams = ref<Record<string, string> | null>(null)
|
||||||
|
|
||||||
|
// Every action below (install/edit TollGate, WiFi scan, WAN configure) needs
|
||||||
|
// host/ssh_user/ssh_password to reach the router. `connectedParams` only gets
|
||||||
|
// set when the Connect form was actually submitted this session (WR-03 above)
|
||||||
|
// — on a normal page load the router reconnects via the server-persisted
|
||||||
|
// config instead, so `sshPassword`/`sshUser`/`host` (the Connect form's own
|
||||||
|
// local refs) sit at their untouched defaults ('', 'root', ''). Falling back
|
||||||
|
// to those refs here used to send an explicit-but-empty ssh_password, which
|
||||||
|
// the backend treats as "the caller provided this" and never falls back to
|
||||||
|
// the real saved password — a real router password then fails auth on every
|
||||||
|
// action even though the status poll (which sends no params at all) keeps
|
||||||
|
// working fine (archy-x250-pa3, 2026-09-05: dropbear logged one bad-password
|
||||||
|
// attempt at the exact moment "Install TollGate" was clicked). Omitting the
|
||||||
|
// fields entirely when there's no explicit connectedParams lets the backend's
|
||||||
|
// own saved-config fallback do the right thing, same as the status poll.
|
||||||
|
function authParams(): Record<string, string> {
|
||||||
|
return connectedParams.value ?? {}
|
||||||
|
}
|
||||||
|
|
||||||
const detecting = ref(false)
|
const detecting = ref(false)
|
||||||
const detectError = ref('')
|
const detectError = ref('')
|
||||||
const detectedCandidates = ref<string[]>([])
|
const detectedCandidates = ref<string[]>([])
|
||||||
@@ -271,11 +289,7 @@ async function provisionTollgate() {
|
|||||||
provisionError.value = ''
|
provisionError.value = ''
|
||||||
provisionSuccess.value = false
|
provisionSuccess.value = false
|
||||||
try {
|
try {
|
||||||
const params: Record<string, unknown> = {
|
const params: Record<string, unknown> = { ...authParams() }
|
||||||
host: connectedParams.value?.host ?? status.value?.host,
|
|
||||||
ssh_user: connectedParams.value?.ssh_user ?? sshUser.value,
|
|
||||||
ssh_password: connectedParams.value?.ssh_password ?? sshPassword.value,
|
|
||||||
}
|
|
||||||
await rpcClient.call({ method: 'openwrt.provision-tollgate', params, timeout: 300000 })
|
await rpcClient.call({ method: 'openwrt.provision-tollgate', params, timeout: 300000 })
|
||||||
provisionSuccess.value = true
|
provisionSuccess.value = true
|
||||||
await load(connectedParams.value ?? undefined)
|
await load(connectedParams.value ?? undefined)
|
||||||
@@ -302,9 +316,7 @@ async function saveTollgateConfig() {
|
|||||||
updateTollgateError.value = ''
|
updateTollgateError.value = ''
|
||||||
try {
|
try {
|
||||||
const params: Record<string, unknown> = {
|
const params: Record<string, unknown> = {
|
||||||
host: connectedParams.value?.host ?? status.value?.host,
|
...authParams(),
|
||||||
ssh_user: connectedParams.value?.ssh_user ?? sshUser.value,
|
|
||||||
ssh_password: connectedParams.value?.ssh_password ?? sshPassword.value,
|
|
||||||
price_sats: editPriceSats.value,
|
price_sats: editPriceSats.value,
|
||||||
step_size_ms: editStepSizeMin.value * 60_000,
|
step_size_ms: editStepSizeMin.value * 60_000,
|
||||||
min_steps: editMinSteps.value,
|
min_steps: editMinSteps.value,
|
||||||
@@ -336,11 +348,7 @@ async function scanWifi() {
|
|||||||
wanStep.value = 'scanning'
|
wanStep.value = 'scanning'
|
||||||
wanError.value = ''
|
wanError.value = ''
|
||||||
try {
|
try {
|
||||||
const params: Record<string, unknown> = {
|
const params: Record<string, unknown> = { ...authParams() }
|
||||||
host: connectedParams.value?.host ?? status.value?.host,
|
|
||||||
ssh_user: connectedParams.value?.ssh_user ?? sshUser.value,
|
|
||||||
ssh_password: connectedParams.value?.ssh_password ?? sshPassword.value,
|
|
||||||
}
|
|
||||||
const result = await rpcClient.call<{ networks: ScannedNetwork[] }>({
|
const result = await rpcClient.call<{ networks: ScannedNetwork[] }>({
|
||||||
method: 'openwrt.scan-wifi',
|
method: 'openwrt.scan-wifi',
|
||||||
params,
|
params,
|
||||||
@@ -367,9 +375,7 @@ async function configureWan() {
|
|||||||
wanError.value = ''
|
wanError.value = ''
|
||||||
try {
|
try {
|
||||||
const params: Record<string, unknown> = {
|
const params: Record<string, unknown> = {
|
||||||
host: connectedParams.value?.host ?? status.value?.host,
|
...authParams(),
|
||||||
ssh_user: connectedParams.value?.ssh_user ?? sshUser.value,
|
|
||||||
ssh_password: connectedParams.value?.ssh_password ?? sshPassword.value,
|
|
||||||
ssid: selectedNetwork.value.ssid,
|
ssid: selectedNetwork.value.ssid,
|
||||||
password: wanPassword.value,
|
password: wanPassword.value,
|
||||||
encryption: selectedNetwork.value.encryption,
|
encryption: selectedNetwork.value.encryption,
|
||||||
|
|||||||
@@ -362,6 +362,18 @@ init()
|
|||||||
</button>
|
</button>
|
||||||
</div>
|
</div>
|
||||||
<div class="overflow-y-auto flex-1 min-h-0 space-y-6 pr-1">
|
<div class="overflow-y-auto flex-1 min-h-0 space-y-6 pr-1">
|
||||||
|
<!-- v1.8.11-alpha -->
|
||||||
|
<div>
|
||||||
|
<div class="flex items-center gap-2 mb-3">
|
||||||
|
<span class="text-xs font-mono px-2 py-0.5 rounded bg-orange-500/20 text-orange-300">v1.8.11-alpha</span>
|
||||||
|
<span class="text-xs text-white/40">September 7, 2026</span>
|
||||||
|
</div>
|
||||||
|
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
||||||
|
<p><strong>Cuprate now syncs without burning a core for days.</strong> The app's shipped config now enables Cuprate's checkpoint-backed fast_sync path, raises the database cache to 8 GiB, and gives the container a 10 GiB memory limit so the cache has real headroom. A live comparison that motivated the change saw the affected node sit around 45% CPU while the corrected config held near low single digits at the same chain height and block rate. The restricted RPC remains fronted through the safe app gate/Tor path.</p>
|
||||||
|
<p><strong>OpenWrt Gateway setup is documented from a real install, and two setup bugs are fixed.</strong> The new guide walks a node operator through flashing a GL.iNet AX3000 to stock OpenWrt, pairing it with Archipelago, and installing TollGate pay-as-you-go WiFi. The installer now finds opkg/apk through the router's actual PATH instead of assuming /usr/bin, the UI no longer sends an empty password over a saved router connection, and the pinned TollGate package moves to v0.5.0 with a native .apk install path where upstream provides one.</p>
|
||||||
|
<p><strong>Release publishing now checks the public Gitea download links before a manifest goes live.</strong> The publisher already fetched every artifact back and verified its size and SHA-256; this release adds a second guard for the release page itself, so a bad Gitea ROOT_URL or proxy setting cannot publish working files behind broken public HTTPS download links.</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
<!-- v1.8.10-alpha -->
|
<!-- v1.8.10-alpha -->
|
||||||
<div>
|
<div>
|
||||||
<div class="flex items-center gap-2 mb-3">
|
<div class="flex items-center gap-2 mb-3">
|
||||||
@@ -369,9 +381,9 @@ init()
|
|||||||
<span class="text-xs text-white/40">September 2, 2026</span>
|
<span class="text-xs text-white/40">September 2, 2026</span>
|
||||||
</div>
|
</div>
|
||||||
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
||||||
<p><strong>Lightning sends work again.</strong> v1.8.9's move to LND 0.21's supported payment route shipped without a fee budget, and the API treats a missing one as zero allowed fees — so every wallet send failed "No route to the recipient" all day, on perfectly healthy channels. Payments now carry a proper fee budget and a test keeps it from ever regressing.</p>
|
<p><strong>Lightning sends work again — v1.8.9's payment switch lost the fee budget.</strong> Moving payments to LND 0.21's supported route (Router.SendPaymentV2) shipped without a fee limit, and the v2 API treats an absent limit as <strong>zero allowed fees</strong>: every real route carries a routing fee, so the pathfinder rejected them all and the wallet answered "No route to the recipient" on every send — all day, on healthy channels with plenty of liquidity. The router debug log made it unambiguous (fee_limit=0 mSAT on every failing wallet payment; the same payment succeeded by hand the moment a fee limit was set). Payments now carry lncli's default budget (the payment amount), the wallet's amount handling for zero-value invoices is preserved, and a unit test pins the limit can never be zero again.</p>
|
||||||
<p><strong>A channel that drops its peer link now heals itself — on every node.</strong> Restarting LND (an app update, a reboot, container churn) can leave a channel's peer connection down for hours while both endpoints keep the channel flagged disabled in the routing graph: the node looks perfectly healthy, the wallet shows balance, and every payment in either direction fails "no route to the recipient". The daemon now watches the channel graph as desired state — every open channel should have a live peer — and reconnects any that don't. Nodes without LND are untouched; an unreachable peer is retried gently.</p>
|
<p><strong>A channel that drops its peer link now heals itself — on every node.</strong> Restarting LND (an app update, a reboot, container churn) can leave a channel's peer connection down for hours while both endpoints keep the channel flagged disabled in the routing graph: the node looks perfectly healthy, the wallet shows balance, and every payment in either direction fails "no route to the recipient". Observed live: a node's only channel sat unroutable for ~17 hours after the LND 0.21.2 update, with no sign of it in any dashboard. The daemon now watches the channel graph as desired state — every open channel should have a live peer — and reconnects any that don't, using the peer's advertised addresses. Nodes without LND are untouched; an unreachable peer is retried gently, not hammered.</p>
|
||||||
<p><strong>The Lightning wallet says what's actually wrong, instead of "you have no channel".</strong> Trying to send while a channel you just opened was still confirming — or when all its balance sits on the far side — produced a modal claiming you had no channel at all, and payment routing failures even showed the receiving copy. The gate now reads your real channel list: a confirming channel gets "it unlocks automatically once confirmed, nothing is needed from you", a far-side balance gets "you can receive, but there's nothing to send right now", and only a genuinely channel-less node is sent to open one.</p>
|
<p><strong>The Lightning wallet states the node's real funding state instead of "you have no channel."</strong> Trying to send while a freshly opened channel was still waiting for on-chain confirmations — or when all its balance sits on the far side — raised a modal that claimed the node had NO channel at all (the outbound sum is legitimately zero in both states), pointed the user at opening a second channel, and — for payment routing failures — even showed the <em>receiving</em> copy. The funding gate now reads the channel list it already fetched: a confirming channel gets "it unlocks automatically once confirmed, nothing is needed from you", a far-side balance gets "you can receive, but there's nothing to send right now", a routing/liquidity payment failure says so instead of claiming channel problems, and only a genuinely channel-less node keeps the open-one guidance.</p>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<!-- v1.8.9-alpha -->
|
<!-- v1.8.9-alpha -->
|
||||||
@@ -381,12 +393,13 @@ init()
|
|||||||
<span class="text-xs text-white/40">September 1, 2026</span>
|
<span class="text-xs text-white/40">September 1, 2026</span>
|
||||||
</div>
|
</div>
|
||||||
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
||||||
<p><strong>Lightning sends work again after the LND 0.21.2 update.</strong> LND 0.21 removed the payment route the node's backend used — every send answered "Not Found". Payments now go through LND's supported v2 router route, slow multi-hop payments are still tracked to completion (never falsely declared failed), failures explain themselves in plain language, and a new test speaks the payment route directly at release-gate time so an image/backend mismatch like this can never ship silently again.</p>
|
<p><strong>Lightning sends work again after the LND 0.21.2 update.</strong> LND 0.21 removed the old synchronous payment route the node's backend paid through (/v1/channels/transactions) — every Lightning send answered the literal "Not Found" and the wallet showed "Payment failed: Not Found". The backend now pays through the supported Router.SendPaymentV2 route, keeps the same settle-then-report behaviour (a slow multi-hop payment is still tracked to completion, never falsely declared failed), and translates LND's failure reasons into plain advice. A new gate test speaks the payment route directly against the running LND, so an image/backend skew like this can never ship silently again.</p>
|
||||||
<p><strong>HTTP and HTTPS both work, and no longer break each other.</strong> The HTTPS listener used to pin a year-long browser policy (HSTS); once your browser had visited HTTPS, it silently rewrote the HTTP dashboard's calls to HTTPS — cross-origin, so everything showed "Failed to fetch"/CORS errors while the node was healthy. The pin is gone, the HTTPS listener now actively clears the stale policy browsers already cached (visit HTTPS once after this update to clear yours), and plain-HTTP access — which is deliberate on nodes whose self-signed certificate you haven't installed — keeps working exactly as before.</p>
|
<p><strong>The node no longer pins HSTS — HTTP access is a supported mode, and it stays working.</strong> The HTTPS listener used to send Strict-Transport-Security: max-age=31536000; includeSubDomains; browsers that visited HTTPS once cached that and then silently upgraded the still-open HTTP dashboard's calls to HTTPS, which is a scheme change — cross-origin — so every request died as "CORS blocked / Failed to fetch" while the node was perfectly healthy. The HTTPS listener now actively clears the cached policy (max-age=0) and port 80 sends no HSTS at all, which is deliberate: the node's certificate is optional and self-signed, and devices that haven't installed the CA must keep plain-HTTP access (that's what Settings → Node certificate is for). If your browser already cached the old policy, visiting the dashboard over HTTPS once after this update clears it; a gate test now refuses any config that reintroduces the pin.</p>
|
||||||
<p><strong>Apps open over HTTPS again, including Mempool, Bitcoin and IndeeHub.</strong> The launcher looked each app's port policy up in the signed catalog under the name you click, but the catalog lists that port under the app that owns it — so Mempool "did not connect", Bitcoin opened a plain-http tab, and Nostr sign-in on IndeeHub silently did nothing over HTTPS. Launches now follow the alias to the owning manifest, the catalog is loaded before the first app you open (not just in the App Store), and the Nostr bridge replies to the app frame's real origin instead of a stale recorded address.</p>
|
<p><strong>App frames open over HTTPS again — including the ones that "did not connect."</strong> The launcher asked the signed catalog for each app's port policy under the name you click ("Mempool Web", "Bitcoin Knots"), but the catalog declares those ports under the manifest that owns them (the Mempool web container, Bitcoin UI). The lookup missed, the launcher handed the iframe an http:// address, and the browser blocked it as mixed content — the app tile went blank or spun forever. Port resolution now follows launch aliases (mempool-web, bitcoin-knots/bitcoin-core, lnd, electrs and friends), falls back to a port-wide catalog scan when the id is unknown, and the catalog is warmed as soon as the dashboard loads rather than only in the App Store, so the very first app you open already knows which ports serve TLS.</p>
|
||||||
<p><strong>Nginx Proxy Manager starts again.</strong> Its manifest was missing two things its image requires — the LetsEncrypt folder mount and the permission to bind low ports — leaving it in an endless restart loop on nodes that had it installed. Both are declared now; your existing certificates are untouched, and the fix arrives via the signed catalog without waiting for this release.</p>
|
<p><strong>Signing in to IndeeHub with Nostr works over HTTPS.</strong> The NIP-07 bridge compared the app frame's origin for exact equality with the recorded http:// app URL — a frame the browser upgraded to HTTPS (or any scheme change) was silently ignored, and replies addressed to the stale origin were refused outright, so Nostr sign-in quietly did nothing. The bridge now matches host and port (scheme intentionally ignored) and always replies to the frame's real origin.</p>
|
||||||
<p><strong>Portainer's first-run token is on the app page, not buried in "server logs".</strong> New Portainer versions hand the first admin a one-time setup token that was only printed in the container logs — on this box, that token now appears with your app's other credentials, with a copy button, and disappears once setup is done.</p>
|
<p><strong>Nginx Proxy Manager starts again.</strong> Converting it to a platform manifest dropped two things its image needs: the /etc/letsencrypt mount its boot script hard-requires, and the NET_BIND_SERVICE capability its internal nginx needs to bind ports 80/443/81 under the orchestrator's --cap-drop=ALL. The result was an endless start/die loop (a node watched it restart 3,176 times). Both are declared in its manifest now, its certs live on unchanged under the same persistent app directory, and the signed catalog carries the fix so installed nodes heal on the next update.</p>
|
||||||
<p><strong>The Lightning wallet says what's actually wrong, instead of "you have no channel".</strong> Trying to send while a channel you just opened was still confirming — or when all its balance sits on the far side — produced a modal claiming you had no channel at all. The gate now looks at your real channel list: a confirming channel gets "it unlocks automatically once confirmed, nothing needed from you", a far-side balance gets "you can receive but there's nothing to send right now", and only a genuinely channel-less node is sent to open one.</p>
|
<p><strong>Portainer's first-run token is in the app page, not buried in "server logs."</strong> New Portainer versions mint a one-time setup token on a fresh install and print it only to the container logs — on an appliance that meant telling the user to go read a server log to get into their own app. The token now appears in the same launch interstitial as app login credentials (with a copy button), only while first-run setup is actually pending; once the admin account exists the card disappears on its own.</p>
|
||||||
|
<p><strong>The Lightning wallet states the node's real funding state instead of "you have no channel."</strong> Trying to send while a freshly opened channel was still waiting for on-chain confirmations — or when all its balance sits on the far side — raised a modal that claimed the node had no channel at all (the outbound sum is legitimately zero in both states). The funding gate now reads the channel list it already fetched: a confirming channel gets "it unlocks automatically once confirmed, nothing is needed from you", a far-side balance gets "you can receive, but there's nothing to send right now", a routing/liquidity payment failure says so instead of pointing at channel setup, and only a genuinely channel-less node is sent to open one.</p>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<!-- v1.8.8-alpha -->
|
<!-- v1.8.8-alpha -->
|
||||||
|
|||||||
+17
-17
@@ -1,29 +1,29 @@
|
|||||||
{
|
{
|
||||||
"changelog": [
|
"changelog": [
|
||||||
"**Lightning sends work again — v1.8.9's payment switch lost the fee budget.** Moving payments to LND 0.21's supported route (Router.SendPaymentV2) shipped without a fee limit, and the v2 API treats an absent limit as **zero allowed fees**: every real route carries a routing fee, so the pathfinder rejected them all and the wallet answered \"No route to the recipient\" on every send — all day, on healthy channels with plenty of liquidity. The router debug log made it unambiguous (`fee_limit=0 mSAT` on every failing wallet payment; the same payment succeeded by hand the moment a fee limit was set). Payments now carry lncli's default budget (the payment amount), the wallet's amount handling for zero-value invoices is preserved, and a unit test pins the limit can never be zero again.",
|
"**Cuprate now syncs without burning a core for days.** The app's shipped config now enables Cuprate's checkpoint-backed `fast_sync` path, raises the database cache to 8 GiB, and gives the container a 10 GiB memory limit so the cache has real headroom. A live comparison that motivated the change saw the affected node sit around 45% CPU while the corrected config held near low single digits at the same chain height and block rate. The restricted RPC remains fronted through the safe app gate/Tor path.",
|
||||||
"**A channel that drops its peer link now heals itself — on every node.** Restarting LND (an app update, a reboot, container churn) can leave a channel's peer connection down for hours while both endpoints keep the channel flagged disabled in the routing graph: the node looks perfectly healthy, the wallet shows balance, and every payment in either direction fails \"no route to the recipient\". Observed live: a node's only channel sat unroutable for ~17 hours after the LND 0.21.2 update, with no sign of it in any dashboard. The daemon now watches the channel graph as desired state — every open channel should have a live peer — and reconnects any that don't, using the peer's advertised addresses. Nodes without LND are untouched; an unreachable peer is retried gently, not hammered.",
|
"**OpenWrt Gateway setup is documented from a real install, and two setup bugs are fixed.** The new guide walks a node operator through flashing a GL.iNet AX3000 to stock OpenWrt, pairing it with Archipelago, and installing TollGate pay-as-you-go WiFi. The installer now finds `opkg`/`apk` through the router's actual `PATH` instead of assuming `/usr/bin`, the UI no longer sends an empty password over a saved router connection, and the pinned TollGate package moves to `v0.5.0` with a native `.apk` install path where upstream provides one.",
|
||||||
"**The Lightning wallet states the node's real funding state instead of \"you have no channel.\"** Trying to send while a freshly opened channel was still waiting for on-chain confirmations — or when all its balance sits on the far side — raised a modal that claimed the node had NO channel at all (the outbound sum is legitimately zero in both states), pointed the user at opening a second channel, and — for payment routing failures — even showed the *receiving* copy. The funding gate now reads the channel list it already fetched: a confirming channel gets \"it unlocks automatically once confirmed, nothing is needed from you\", a far-side balance gets \"you can receive, but there's nothing to send right now\", a routing/liquidity payment failure says so instead of claiming channel problems, and only a genuinely channel-less node keeps the open-one guidance."
|
"**Release publishing now checks the public Gitea download links before a manifest goes live.** The publisher already fetched every artifact back and verified its size and SHA-256; this release adds a second guard for the release page itself, so a bad Gitea `ROOT_URL` or proxy setting cannot publish working files behind broken public HTTPS download links."
|
||||||
],
|
],
|
||||||
"components": [
|
"components": [
|
||||||
{
|
{
|
||||||
"current_version": "1.8.10-alpha",
|
"current_version": "1.8.11-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.10-alpha/archipelago",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.11-alpha/archipelago",
|
||||||
"name": "archipelago",
|
"name": "archipelago",
|
||||||
"new_version": "1.8.10-alpha",
|
"new_version": "1.8.11-alpha",
|
||||||
"sha256": "6c8bd41fed44cd999cb360c00e1b66a2d19d19812cc2b0c8a1677eec2a9579e6",
|
"sha256": "ae569054edd6b2491beb101815f6809bc00c95a7dbe86bd084bcb9a7c36e1853",
|
||||||
"size_bytes": 64178056
|
"size_bytes": 64179264
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"current_version": "1.8.10-alpha",
|
"current_version": "1.8.11-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.10-alpha/archipelago-frontend-1.8.10-alpha.tar.gz",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.11-alpha/archipelago-frontend-1.8.11-alpha.tar.gz",
|
||||||
"name": "archipelago-frontend-1.8.10-alpha.tar.gz",
|
"name": "archipelago-frontend-1.8.11-alpha.tar.gz",
|
||||||
"new_version": "1.8.10-alpha",
|
"new_version": "1.8.11-alpha",
|
||||||
"sha256": "6b25de8a8e1a4f7fe51594f9bbbe21f5820f417af47a8b309c2dbf8f8723b719",
|
"sha256": "192fd0470b6ccf66e78c80b4a4c3af5468882b85d81959362a3bd11f88b9d71d",
|
||||||
"size_bytes": 97736297
|
"size_bytes": 97741740
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"release_date": "2026-09-01",
|
"release_date": "2026-09-07",
|
||||||
"signature": "b69926bcb1851ff7d6a5b24519cd4a8015aab4ed4b588ee989d8ce6e3beaeb2cc0eb38078f522ded0d389fe53b7dbcdbf3f40c534b4bfafa5cf4a2ab2c59e40f",
|
"signature": "6449ce6ef35a4ef4fa6d0923bb58a2bff52ea5430d5532496e8f0af9ed52eaec293f19d7bec272dc9bc1af5fb2cdfa0e46068c827a9a4dd9cbef92d1c5845301",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"version": "1.8.10-alpha"
|
"version": "1.8.11-alpha"
|
||||||
}
|
}
|
||||||
|
|||||||
+3244
-3242
File diff suppressed because one or more lines are too long
+17
-17
@@ -1,29 +1,29 @@
|
|||||||
{
|
{
|
||||||
"changelog": [
|
"changelog": [
|
||||||
"**Lightning sends work again — v1.8.9's payment switch lost the fee budget.** Moving payments to LND 0.21's supported route (Router.SendPaymentV2) shipped without a fee limit, and the v2 API treats an absent limit as **zero allowed fees**: every real route carries a routing fee, so the pathfinder rejected them all and the wallet answered \"No route to the recipient\" on every send — all day, on healthy channels with plenty of liquidity. The router debug log made it unambiguous (`fee_limit=0 mSAT` on every failing wallet payment; the same payment succeeded by hand the moment a fee limit was set). Payments now carry lncli's default budget (the payment amount), the wallet's amount handling for zero-value invoices is preserved, and a unit test pins the limit can never be zero again.",
|
"**Cuprate now syncs without burning a core for days.** The app's shipped config now enables Cuprate's checkpoint-backed `fast_sync` path, raises the database cache to 8 GiB, and gives the container a 10 GiB memory limit so the cache has real headroom. A live comparison that motivated the change saw the affected node sit around 45% CPU while the corrected config held near low single digits at the same chain height and block rate. The restricted RPC remains fronted through the safe app gate/Tor path.",
|
||||||
"**A channel that drops its peer link now heals itself — on every node.** Restarting LND (an app update, a reboot, container churn) can leave a channel's peer connection down for hours while both endpoints keep the channel flagged disabled in the routing graph: the node looks perfectly healthy, the wallet shows balance, and every payment in either direction fails \"no route to the recipient\". Observed live: a node's only channel sat unroutable for ~17 hours after the LND 0.21.2 update, with no sign of it in any dashboard. The daemon now watches the channel graph as desired state — every open channel should have a live peer — and reconnects any that don't, using the peer's advertised addresses. Nodes without LND are untouched; an unreachable peer is retried gently, not hammered.",
|
"**OpenWrt Gateway setup is documented from a real install, and two setup bugs are fixed.** The new guide walks a node operator through flashing a GL.iNet AX3000 to stock OpenWrt, pairing it with Archipelago, and installing TollGate pay-as-you-go WiFi. The installer now finds `opkg`/`apk` through the router's actual `PATH` instead of assuming `/usr/bin`, the UI no longer sends an empty password over a saved router connection, and the pinned TollGate package moves to `v0.5.0` with a native `.apk` install path where upstream provides one.",
|
||||||
"**The Lightning wallet states the node's real funding state instead of \"you have no channel.\"** Trying to send while a freshly opened channel was still waiting for on-chain confirmations — or when all its balance sits on the far side — raised a modal that claimed the node had NO channel at all (the outbound sum is legitimately zero in both states), pointed the user at opening a second channel, and — for payment routing failures — even showed the *receiving* copy. The funding gate now reads the channel list it already fetched: a confirming channel gets \"it unlocks automatically once confirmed, nothing is needed from you\", a far-side balance gets \"you can receive, but there's nothing to send right now\", a routing/liquidity payment failure says so instead of claiming channel problems, and only a genuinely channel-less node keeps the open-one guidance."
|
"**Release publishing now checks the public Gitea download links before a manifest goes live.** The publisher already fetched every artifact back and verified its size and SHA-256; this release adds a second guard for the release page itself, so a bad Gitea `ROOT_URL` or proxy setting cannot publish working files behind broken public HTTPS download links."
|
||||||
],
|
],
|
||||||
"components": [
|
"components": [
|
||||||
{
|
{
|
||||||
"current_version": "1.8.10-alpha",
|
"current_version": "1.8.11-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.10-alpha/archipelago",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.11-alpha/archipelago",
|
||||||
"name": "archipelago",
|
"name": "archipelago",
|
||||||
"new_version": "1.8.10-alpha",
|
"new_version": "1.8.11-alpha",
|
||||||
"sha256": "6c8bd41fed44cd999cb360c00e1b66a2d19d19812cc2b0c8a1677eec2a9579e6",
|
"sha256": "ae569054edd6b2491beb101815f6809bc00c95a7dbe86bd084bcb9a7c36e1853",
|
||||||
"size_bytes": 64178056
|
"size_bytes": 64179264
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"current_version": "1.8.10-alpha",
|
"current_version": "1.8.11-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.10-alpha/archipelago-frontend-1.8.10-alpha.tar.gz",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.11-alpha/archipelago-frontend-1.8.11-alpha.tar.gz",
|
||||||
"name": "archipelago-frontend-1.8.10-alpha.tar.gz",
|
"name": "archipelago-frontend-1.8.11-alpha.tar.gz",
|
||||||
"new_version": "1.8.10-alpha",
|
"new_version": "1.8.11-alpha",
|
||||||
"sha256": "6b25de8a8e1a4f7fe51594f9bbbe21f5820f417af47a8b309c2dbf8f8723b719",
|
"sha256": "192fd0470b6ccf66e78c80b4a4c3af5468882b85d81959362a3bd11f88b9d71d",
|
||||||
"size_bytes": 97736297
|
"size_bytes": 97741740
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"release_date": "2026-09-01",
|
"release_date": "2026-09-07",
|
||||||
"signature": "b69926bcb1851ff7d6a5b24519cd4a8015aab4ed4b588ee989d8ce6e3beaeb2cc0eb38078f522ded0d389fe53b7dbcdbf3f40c534b4bfafa5cf4a2ab2c59e40f",
|
"signature": "6449ce6ef35a4ef4fa6d0923bb58a2bff52ea5430d5532496e8f0af9ed52eaec293f19d7bec272dc9bc1af5fb2cdfa0e46068c827a9a4dd9cbef92d1c5845301",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"version": "1.8.10-alpha"
|
"version": "1.8.11-alpha"
|
||||||
}
|
}
|
||||||
|
|||||||
+85
@@ -0,0 +1,85 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# check-gitea-release-download-links.sh - verify Gitea's public release page
|
||||||
|
# points users at the canonical HTTPS download URLs, not an internal ROOT_URL.
|
||||||
|
#
|
||||||
|
# Usage:
|
||||||
|
# scripts/check-gitea-release-download-links.sh VERSION ASSET_NAME...
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
VERSION="${1:-}"
|
||||||
|
if [ -z "$VERSION" ] || [ "$#" -lt 2 ]; then
|
||||||
|
echo "usage: $0 VERSION ASSET_NAME..." >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
shift
|
||||||
|
|
||||||
|
PUBLIC_BASE="${ARCHY_RELEASE_PUBLIC_BASE:-https://source.archipelago-foundation.org/lfg2025/archy}"
|
||||||
|
page_url="$PUBLIC_BASE/releases/tag/v$VERSION"
|
||||||
|
|
||||||
|
command -v curl >/dev/null 2>&1 || { echo "ERROR: curl required" >&2; exit 2; }
|
||||||
|
command -v python3 >/dev/null 2>&1 || { echo "ERROR: python3 required" >&2; exit 2; }
|
||||||
|
|
||||||
|
tmp="$(mktemp)"
|
||||||
|
trap 'rm -f "$tmp"' EXIT
|
||||||
|
curl -fsSL "$page_url" -o "$tmp"
|
||||||
|
|
||||||
|
python3 - "$tmp" "$PUBLIC_BASE" "$VERSION" "$page_url" "$@" <<'PY'
|
||||||
|
from html.parser import HTMLParser
|
||||||
|
from urllib.parse import quote
|
||||||
|
import sys
|
||||||
|
|
||||||
|
html_path, public_base, version, page_url, *assets = sys.argv[1:]
|
||||||
|
with open(html_path, encoding="utf-8") as f:
|
||||||
|
html = f.read()
|
||||||
|
|
||||||
|
class LinkParser(HTMLParser):
|
||||||
|
def __init__(self):
|
||||||
|
super().__init__()
|
||||||
|
self.hrefs = []
|
||||||
|
|
||||||
|
def handle_starttag(self, tag, attrs):
|
||||||
|
if tag.lower() != "a":
|
||||||
|
return
|
||||||
|
attrs = dict(attrs)
|
||||||
|
href = attrs.get("href")
|
||||||
|
if href:
|
||||||
|
self.hrefs.append(href)
|
||||||
|
|
||||||
|
parser = LinkParser()
|
||||||
|
parser.feed(html)
|
||||||
|
hrefs = set(parser.hrefs)
|
||||||
|
|
||||||
|
bad_internal = sorted(
|
||||||
|
h for h in hrefs
|
||||||
|
if "/releases/download/" in h and h.startswith(("http://", "https://"))
|
||||||
|
and not h.startswith(public_base + "/releases/download/")
|
||||||
|
)
|
||||||
|
|
||||||
|
failures = []
|
||||||
|
for asset in assets:
|
||||||
|
expected = f"{public_base}/releases/download/v{quote(version)}/{quote(asset)}"
|
||||||
|
if expected not in hrefs:
|
||||||
|
matches = sorted(h for h in hrefs if h.endswith("/" + quote(asset)))
|
||||||
|
if matches:
|
||||||
|
failures.append(f"{asset}: expected {expected}, found {matches[0]}")
|
||||||
|
else:
|
||||||
|
failures.append(f"{asset}: expected {expected}, but no matching release-page link was found")
|
||||||
|
|
||||||
|
if bad_internal:
|
||||||
|
failures.append("release page contains non-canonical download href(s):")
|
||||||
|
failures.extend(f" {h}" for h in bad_internal[:10])
|
||||||
|
|
||||||
|
if failures:
|
||||||
|
print(f"FAIL: public release page has broken download links: {page_url}", file=sys.stderr)
|
||||||
|
for failure in failures:
|
||||||
|
print(f" {failure}", file=sys.stderr)
|
||||||
|
print(
|
||||||
|
"Fix the Gitea public URL/proxy configuration so release links are generated "
|
||||||
|
"from the canonical HTTPS origin, then re-run the publish check.",
|
||||||
|
file=sys.stderr,
|
||||||
|
)
|
||||||
|
sys.exit(1)
|
||||||
|
|
||||||
|
print(f"OK: public release page download links use {public_base}")
|
||||||
|
PY
|
||||||
@@ -145,6 +145,11 @@ echo "Verifying public download URLs (full GET + size + sha256)..."
|
|||||||
"$PROJECT_ROOT/scripts/check-release-assets.sh" "$MANIFEST" \
|
"$PROJECT_ROOT/scripts/check-release-assets.sh" "$MANIFEST" \
|
||||||
|| fail "asset verification failed — NOT pushing main. The manifest stays off the branch nodes read, so no node sees a version it cannot fetch. Repair the assets and re-run."
|
|| fail "asset verification failed — NOT pushing main. The manifest stays off the branch nodes read, so no node sees a version it cannot fetch. Repair the assets and re-run."
|
||||||
|
|
||||||
|
"$PROJECT_ROOT/scripts/check-gitea-release-download-links.sh" "$VERSION" \
|
||||||
|
"archipelago" \
|
||||||
|
"archipelago-frontend-${VERSION}.tar.gz" \
|
||||||
|
|| fail "release page download links are not public HTTPS URLs — fix Gitea ROOT_URL/proxy configuration before publishing."
|
||||||
|
|
||||||
# Assets are proven fetchable — only now may the manifest become live. First
|
# Assets are proven fetchable — only now may the manifest become live. First
|
||||||
# incorporate concurrent work, then promote in a dedicated commit. Until the
|
# incorporate concurrent work, then promote in a dedicated commit. Until the
|
||||||
# final push succeeds the remote still serves the previous manifest.
|
# final push succeeds the remote still serves the previous manifest.
|
||||||
@@ -261,4 +266,10 @@ for b in bad:
|
|||||||
sys.exit(1 if bad else 0)
|
sys.exit(1 if bad else 0)
|
||||||
PY
|
PY
|
||||||
|
|
||||||
|
"$PROJECT_ROOT/scripts/check-gitea-release-download-links.sh" "$VERSION" \
|
||||||
|
"$ISO_NAME" \
|
||||||
|
"$ISO_NAME.sha256" \
|
||||||
|
"$ISO_NAME.sha256.json" \
|
||||||
|
|| fail "ISO is uploaded but the release page links are not public HTTPS URLs — fix Gitea ROOT_URL/proxy configuration."
|
||||||
|
|
||||||
echo "ISO for v${VERSION} published and verified on $REMOTE."
|
echo "ISO for v${VERSION} published and verified on $REMOTE."
|
||||||
|
|||||||
Reference in New Issue
Block a user