Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0677924a64 | ||
|
|
f12042f194 | ||
|
|
e7cf336665 | ||
|
|
8ca20de82e | ||
|
|
1fa654cb6a | ||
|
|
c993d9dd0d | ||
|
|
33d2b3ce60 | ||
|
|
c7ce35bd43 | ||
|
|
33477f284b |
@@ -2,6 +2,13 @@
|
|||||||
|
|
||||||
## Unreleased
|
## Unreleased
|
||||||
|
|
||||||
|
## v1.8.21-alpha (2026-09-30)
|
||||||
|
|
||||||
|
- Fixed Bitcoin and other containers being forcibly stopped after ten seconds during managed updates and restarts.
|
||||||
|
- Existing installations now receive the same graceful shutdown allowance as new containers, without restarting apps just to apply this setting.
|
||||||
|
- Prevented unnecessary Lightning restarts when Bitcoin has stayed running; dependency restarts now require an observed Bitcoin container change.
|
||||||
|
- Includes the Cashu payment, optional Bitcoin pruning, Lightning readiness, and explorer improvements from 1.8.20.
|
||||||
|
|
||||||
## v1.8.20-alpha (2026-09-29)
|
## v1.8.20-alpha (2026-09-29)
|
||||||
|
|
||||||
- Fixed Cashu file payments rejected despite a shared mint, and preserved the payment amount when mint fees reduce change.
|
- Fixed Cashu file payments rejected despite a shared mint, and preserved the payment amount when mint fees reduce change.
|
||||||
|
|||||||
Generated
+1
-1
@@ -104,7 +104,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "archipelago"
|
name = "archipelago"
|
||||||
version = "1.8.20-alpha"
|
version = "1.8.21-alpha"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"archipelago-container",
|
"archipelago-container",
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "archipelago"
|
name = "archipelago"
|
||||||
version = "1.8.20-alpha"
|
version = "1.8.21-alpha"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
license.workspace = true
|
license.workspace = true
|
||||||
description = "Archipelago Bitcoin Node OS - Native backend"
|
description = "Archipelago Bitcoin Node OS - Native backend"
|
||||||
|
|||||||
@@ -54,13 +54,9 @@ fn paid_content_response(bytes: &[u8], mime: &str, paid_sats: u64) -> serde_json
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
/// FileBrowser owns its files through a rootless UID mapping. Use its authenticated
|
/// File purchases through an atomic no-clobber write in Files' own namespace.
|
||||||
/// API rather than writing host paths with the backend's unrelated UID. Its
|
|
||||||
/// override=false upload atomically refuses existing names, including races.
|
|
||||||
async fn file_purchase_in_files(
|
async fn file_purchase_in_files(
|
||||||
client: &reqwest::Client,
|
data_dir: &std::path::Path,
|
||||||
base_url: &str,
|
|
||||||
token: &str,
|
|
||||||
filename: &str,
|
filename: &str,
|
||||||
mime: &str,
|
mime: &str,
|
||||||
bytes: &[u8],
|
bytes: &[u8],
|
||||||
@@ -72,59 +68,24 @@ async fn file_purchase_in_files(
|
|||||||
} else {
|
} else {
|
||||||
"Documents"
|
"Documents"
|
||||||
};
|
};
|
||||||
let mut folder_url = reqwest::Url::parse(base_url)?;
|
let root = data_dir.join("filebrowser");
|
||||||
folder_url
|
anyhow::ensure!(
|
||||||
.path_segments_mut()
|
tokio::fs::metadata(&root).await?.is_dir(),
|
||||||
.map_err(|_| anyhow::anyhow!("Invalid Files URL"))?
|
"Files storage is unavailable"
|
||||||
.extend(["api", "resources", folder, ""]);
|
);
|
||||||
let response = client
|
let name = std::path::Path::new(filename)
|
||||||
.get(folder_url.clone())
|
|
||||||
.header("X-Auth", token)
|
|
||||||
.send()
|
|
||||||
.await?;
|
|
||||||
if response.status() == reqwest::StatusCode::NOT_FOUND {
|
|
||||||
let response = client
|
|
||||||
.post(folder_url.clone())
|
|
||||||
.header("X-Auth", token)
|
|
||||||
.send()
|
|
||||||
.await?;
|
|
||||||
if response.status() != reqwest::StatusCode::CONFLICT {
|
|
||||||
response.error_for_status()?;
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
response.error_for_status()?;
|
|
||||||
}
|
|
||||||
let base = std::path::Path::new(filename)
|
|
||||||
.file_name()
|
.file_name()
|
||||||
.and_then(|n| n.to_str())
|
.and_then(|n| n.to_str())
|
||||||
.filter(|n| !n.is_empty())
|
.filter(|n| !n.is_empty())
|
||||||
.unwrap_or("download");
|
.unwrap_or("download");
|
||||||
let (stem, extension) = match base.rsplit_once('.') {
|
let path =
|
||||||
Some((stem, ext)) if !stem.is_empty() => (stem, format!(".{ext}")),
|
crate::container::filebrowser::save_new_file(&root.join(folder), name, bytes).await?;
|
||||||
_ => (base, String::new()),
|
Ok(format!(
|
||||||
};
|
"{folder}/{}",
|
||||||
for attempt in 1..=100 {
|
path.file_name()
|
||||||
let name = if attempt == 1 {
|
.and_then(|n| n.to_str())
|
||||||
base.to_string()
|
.context("Invalid Files name")?
|
||||||
} else {
|
))
|
||||||
format!("{stem} ({attempt}){extension}")
|
|
||||||
};
|
|
||||||
let mut url = folder_url.clone();
|
|
||||||
url.path_segments_mut().unwrap().pop_if_empty().push(&name);
|
|
||||||
url.query_pairs_mut().append_pair("override", "false");
|
|
||||||
let response = client
|
|
||||||
.post(url)
|
|
||||||
.header("X-Auth", token)
|
|
||||||
.body(bytes.to_vec())
|
|
||||||
.send()
|
|
||||||
.await?;
|
|
||||||
if response.status() == reqwest::StatusCode::CONFLICT {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
response.error_for_status()?;
|
|
||||||
return Ok(format!("{folder}/{name}"));
|
|
||||||
}
|
|
||||||
anyhow::bail!("Too many existing copies; purchased file remains in the purchase cache")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
impl RpcHandler {
|
impl RpcHandler {
|
||||||
@@ -728,28 +689,8 @@ impl RpcHandler {
|
|||||||
|
|
||||||
// The durable purchased-content cache above is primary. A Files copy
|
// The durable purchased-content cache above is primary. A Files copy
|
||||||
// remains optional: a stopped FileBrowser must not undo a paid download.
|
// remains optional: a stopped FileBrowser must not undo a paid download.
|
||||||
let filed = async {
|
let filed =
|
||||||
let auth = self.handle_filebrowser_token().await?;
|
file_purchase_in_files(&self.config.data_dir, &filename, &mime_type, &bytes).await;
|
||||||
let token = auth
|
|
||||||
.get("token")
|
|
||||||
.and_then(|v| v.as_str())
|
|
||||||
.context("FileBrowser omitted its authentication token")?;
|
|
||||||
let client = reqwest::Client::builder()
|
|
||||||
.no_proxy()
|
|
||||||
.redirect(reqwest::redirect::Policy::none())
|
|
||||||
.timeout(std::time::Duration::from_secs(30))
|
|
||||||
.build()?;
|
|
||||||
file_purchase_in_files(
|
|
||||||
&client,
|
|
||||||
"http://127.0.0.1:8083",
|
|
||||||
token,
|
|
||||||
&filename,
|
|
||||||
&mime_type,
|
|
||||||
&bytes,
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
}
|
|
||||||
.await;
|
|
||||||
match filed {
|
match filed {
|
||||||
Ok(path) => tracing::info!("paid download: filed into Files/{path}"),
|
Ok(path) => tracing::info!("paid download: filed into Files/{path}"),
|
||||||
Err(error) => tracing::warn!(
|
Err(error) => tracing::warn!(
|
||||||
|
|||||||
@@ -1,69 +1,4 @@
|
|||||||
use super::*;
|
use super::*;
|
||||||
use hyper::{
|
|
||||||
service::{make_service_fn, service_fn},
|
|
||||||
Body, Response, Server,
|
|
||||||
};
|
|
||||||
use std::{
|
|
||||||
collections::VecDeque,
|
|
||||||
convert::Infallible,
|
|
||||||
sync::{Arc, Mutex},
|
|
||||||
};
|
|
||||||
|
|
||||||
struct FilesApi {
|
|
||||||
url: String,
|
|
||||||
seen: Arc<Mutex<Vec<(String, String, Vec<u8>)>>>,
|
|
||||||
task: tokio::task::JoinHandle<()>,
|
|
||||||
}
|
|
||||||
impl Drop for FilesApi {
|
|
||||||
fn drop(&mut self) {
|
|
||||||
self.task.abort();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
fn files_api(statuses: Vec<u16>) -> FilesApi {
|
|
||||||
let statuses = Arc::new(Mutex::new(VecDeque::from(statuses)));
|
|
||||||
let seen = Arc::new(Mutex::new(Vec::new()));
|
|
||||||
let history = seen.clone();
|
|
||||||
let server = Server::bind(&([127, 0, 0, 1], 0).into());
|
|
||||||
let address = server.local_addr();
|
|
||||||
let service = make_service_fn(move |_| {
|
|
||||||
let statuses = statuses.clone();
|
|
||||||
let seen = history.clone();
|
|
||||||
async move {
|
|
||||||
Ok::<_, Infallible>(service_fn(move |request: hyper::Request<Body>| {
|
|
||||||
let statuses = statuses.clone();
|
|
||||||
let seen = seen.clone();
|
|
||||||
async move {
|
|
||||||
assert_eq!(request.headers().get("X-Auth").unwrap(), "test-session");
|
|
||||||
let method = request.method().to_string();
|
|
||||||
let uri = request.uri().to_string();
|
|
||||||
let body = hyper::body::to_bytes(request.into_body())
|
|
||||||
.await
|
|
||||||
.unwrap()
|
|
||||||
.to_vec();
|
|
||||||
seen.lock().unwrap().push((method, uri, body));
|
|
||||||
let status = statuses
|
|
||||||
.lock()
|
|
||||||
.unwrap()
|
|
||||||
.pop_front()
|
|
||||||
.expect("unexpected extra Files request");
|
|
||||||
Ok::<_, Infallible>(
|
|
||||||
Response::builder()
|
|
||||||
.status(status)
|
|
||||||
.body(Body::empty())
|
|
||||||
.unwrap(),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}))
|
|
||||||
}
|
|
||||||
});
|
|
||||||
FilesApi {
|
|
||||||
url: format!("http://{address}"),
|
|
||||||
seen,
|
|
||||||
task: tokio::spawn(async move {
|
|
||||||
server.serve(service).await.unwrap();
|
|
||||||
}),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn first_and_cached_paid_downloads_have_the_same_client_payload_contract() {
|
fn first_and_cached_paid_downloads_have_the_same_client_payload_contract() {
|
||||||
@@ -85,80 +20,37 @@ fn first_and_cached_paid_downloads_have_the_same_client_payload_contract() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn files_copy_uses_authenticated_api_and_preserves_existing_names() {
|
async fn files_copy_routes_media_and_sanitizes_the_filename() {
|
||||||
let api = files_api(vec![200, 409, 200]);
|
let dir = tempfile::tempdir().unwrap();
|
||||||
let client = reqwest::Client::new();
|
tokio::fs::create_dir(dir.path().join("filebrowser"))
|
||||||
let path = file_purchase_in_files(
|
|
||||||
&client,
|
|
||||||
&api.url,
|
|
||||||
"test-session",
|
|
||||||
"../my #file?.txt",
|
|
||||||
"text/plain",
|
|
||||||
b"paid bytes",
|
|
||||||
)
|
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
assert_eq!(path, "Documents/my #file? (2).txt");
|
|
||||||
let seen = api.seen.lock().unwrap();
|
|
||||||
assert_eq!(seen[0].0, "GET");
|
|
||||||
assert_eq!(seen[0].1, "/api/resources/Documents/");
|
|
||||||
assert_eq!(seen.len(), 3);
|
|
||||||
for (_, uri, body) in &seen[1..] {
|
|
||||||
assert!(uri.contains("override=false"));
|
|
||||||
assert!(uri.contains("%23file%3F"));
|
|
||||||
assert!(!uri.contains("../"));
|
|
||||||
assert_eq!(body, b"paid bytes");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn files_copy_creates_missing_media_folder() {
|
|
||||||
for (mime, folder) in [
|
for (mime, folder) in [
|
||||||
("image/png", "Photos"),
|
("image/png", "Photos"),
|
||||||
("video/mp4", "Photos"),
|
("video/mp4", "Photos"),
|
||||||
("audio/ogg", "Music"),
|
("audio/mpeg", "Music"),
|
||||||
|
("text/plain", "Documents"),
|
||||||
] {
|
] {
|
||||||
let api = files_api(vec![404, 200, 200]);
|
let relative = file_purchase_in_files(dir.path(), "../name #?.bin", mime, b"paid")
|
||||||
let path = file_purchase_in_files(
|
|
||||||
&reqwest::Client::new(),
|
|
||||||
&api.url,
|
|
||||||
"test-session",
|
|
||||||
"file",
|
|
||||||
mime,
|
|
||||||
b"bytes",
|
|
||||||
)
|
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
assert_eq!(path, format!("{folder}/file"));
|
assert!(relative.starts_with(&format!("{folder}/name #?")));
|
||||||
let seen = api.seen.lock().unwrap();
|
assert_eq!(
|
||||||
assert_eq!(seen[1].0, "POST");
|
tokio::fs::read(dir.path().join("filebrowser").join(relative))
|
||||||
assert!(seen[1].1.ends_with('/'));
|
.await
|
||||||
assert!(seen[1].2.is_empty());
|
.unwrap(),
|
||||||
assert_eq!(seen[2].2, b"bytes");
|
b"paid"
|
||||||
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn files_copy_fails_without_overwriting_or_claiming_success_on_errors() {
|
async fn unavailable_files_storage_is_reported_without_creating_a_fake_installation() {
|
||||||
for statuses in [
|
let dir = tempfile::tempdir().unwrap();
|
||||||
vec![401],
|
assert!(
|
||||||
vec![503],
|
file_purchase_in_files(dir.path(), "name", "text/plain", b"bytes")
|
||||||
vec![404, 500],
|
|
||||||
vec![200, 507],
|
|
||||||
vec![200, 403],
|
|
||||||
] {
|
|
||||||
let expected = statuses.len();
|
|
||||||
let api = files_api(statuses);
|
|
||||||
assert!(file_purchase_in_files(
|
|
||||||
&reqwest::Client::new(),
|
|
||||||
&api.url,
|
|
||||||
"test-session",
|
|
||||||
"file.txt",
|
|
||||||
"text/plain",
|
|
||||||
b"bytes"
|
|
||||||
)
|
|
||||||
.await
|
.await
|
||||||
.is_err());
|
.is_err()
|
||||||
assert_eq!(api.seen.lock().unwrap().len(), expected);
|
);
|
||||||
}
|
assert!(!dir.path().join("filebrowser").exists());
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
//! starting the container with `--config /data/.filebrowser.json`.
|
//! starting the container with `--config /data/.filebrowser.json`.
|
||||||
|
|
||||||
use anyhow::{Context, Result};
|
use anyhow::{Context, Result};
|
||||||
use std::path::PathBuf;
|
use std::path::{Path, PathBuf};
|
||||||
use tokio::fs;
|
use tokio::fs;
|
||||||
|
|
||||||
use crate::update::host_sudo;
|
use crate::update::host_sudo;
|
||||||
@@ -117,6 +117,197 @@ fn shell_quote(s: &str) -> String {
|
|||||||
s.replace('\'', "'\\''")
|
s.replace('\'', "'\\''")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Save a complete purchase without overwriting any existing directory entry.
|
||||||
|
/// Both host and rootless-namespace paths publish with a no-clobber hard link.
|
||||||
|
pub async fn save_new_file(dir: &Path, name: &str, bytes: &[u8]) -> Result<PathBuf> {
|
||||||
|
save_new_file_with(dir, name, bytes, write_via_userns).await
|
||||||
|
}
|
||||||
|
|
||||||
|
fn validate_filename(name: &str) -> Result<()> {
|
||||||
|
anyhow::ensure!(
|
||||||
|
!name.is_empty()
|
||||||
|
&& name != "."
|
||||||
|
&& name != ".."
|
||||||
|
&& !name.contains(['/', '\\', '\0'])
|
||||||
|
&& name.len() <= 255,
|
||||||
|
"Invalid purchased filename"
|
||||||
|
);
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn save_new_file_with<F, Fut>(
|
||||||
|
dir: &Path,
|
||||||
|
name: &str,
|
||||||
|
bytes: &[u8],
|
||||||
|
fallback: F,
|
||||||
|
) -> Result<PathBuf>
|
||||||
|
where
|
||||||
|
F: FnOnce(PathBuf, String, Vec<u8>) -> Fut,
|
||||||
|
Fut: std::future::Future<Output = Result<PathBuf>>,
|
||||||
|
{
|
||||||
|
validate_filename(name)?;
|
||||||
|
// Never follow a user-created destination directory symlink.
|
||||||
|
match fs::symlink_metadata(dir).await {
|
||||||
|
Ok(meta) => anyhow::ensure!(meta.is_dir(), "Files destination is not a directory"),
|
||||||
|
Err(error) if error.kind() == std::io::ErrorKind::NotFound => {}
|
||||||
|
Err(error) => return Err(error.into()),
|
||||||
|
}
|
||||||
|
save_after_direct_result(
|
||||||
|
write_direct(dir, name, bytes).await,
|
||||||
|
dir,
|
||||||
|
name,
|
||||||
|
bytes,
|
||||||
|
fallback,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn save_after_direct_result<F, Fut>(
|
||||||
|
result: std::io::Result<PathBuf>,
|
||||||
|
dir: &Path,
|
||||||
|
name: &str,
|
||||||
|
bytes: &[u8],
|
||||||
|
fallback: F,
|
||||||
|
) -> Result<PathBuf>
|
||||||
|
where
|
||||||
|
F: FnOnce(PathBuf, String, Vec<u8>) -> Fut,
|
||||||
|
Fut: std::future::Future<Output = Result<PathBuf>>,
|
||||||
|
{
|
||||||
|
match result {
|
||||||
|
Ok(path) => Ok(path),
|
||||||
|
Err(error) if error.kind() == std::io::ErrorKind::PermissionDenied => {
|
||||||
|
fallback(dir.to_owned(), name.to_owned(), bytes.to_vec())
|
||||||
|
.await
|
||||||
|
.context("Saving purchase in Files user namespace")
|
||||||
|
}
|
||||||
|
Err(error) => Err(error).context("Saving purchase in Files"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn numbered_name(name: &str, attempt: usize) -> String {
|
||||||
|
if attempt == 1 {
|
||||||
|
return name.to_owned();
|
||||||
|
}
|
||||||
|
match name.rsplit_once('.') {
|
||||||
|
Some((stem, extension)) if !stem.is_empty() => format!("{stem} ({attempt}).{extension}"),
|
||||||
|
_ => format!("{name} ({attempt})"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
struct PendingFile(PathBuf);
|
||||||
|
impl Drop for PendingFile {
|
||||||
|
fn drop(&mut self) {
|
||||||
|
let _ = std::fs::remove_file(&self.0);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn write_direct(dir: &Path, name: &str, bytes: &[u8]) -> std::io::Result<PathBuf> {
|
||||||
|
use std::os::unix::fs::PermissionsExt;
|
||||||
|
use tokio::io::AsyncWriteExt;
|
||||||
|
fs::create_dir_all(dir).await?;
|
||||||
|
let temp_path = dir.join(format!(".archy-saving-{}", uuid::Uuid::new_v4()));
|
||||||
|
let mut file = fs::OpenOptions::new()
|
||||||
|
.write(true)
|
||||||
|
.create_new(true)
|
||||||
|
.mode(0o600)
|
||||||
|
.open(&temp_path)
|
||||||
|
.await?;
|
||||||
|
let temp = PendingFile(temp_path);
|
||||||
|
file.write_all(bytes).await?;
|
||||||
|
file.set_permissions(std::fs::Permissions::from_mode(0o644))
|
||||||
|
.await?;
|
||||||
|
file.sync_all().await?;
|
||||||
|
for attempt in 1..=100 {
|
||||||
|
let target = dir.join(numbered_name(name, attempt));
|
||||||
|
match fs::hard_link(&temp.0, &target).await {
|
||||||
|
Ok(()) => return Ok(target),
|
||||||
|
Err(error) if error.kind() == std::io::ErrorKind::AlreadyExists => continue,
|
||||||
|
Err(error) => return Err(error),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Err(std::io::Error::new(
|
||||||
|
std::io::ErrorKind::AlreadyExists,
|
||||||
|
"Too many existing copies; purchase cache retained",
|
||||||
|
))
|
||||||
|
}
|
||||||
|
|
||||||
|
// Positional arguments carry all user-controlled text. mktemp prevents temp-name
|
||||||
|
// collisions; ln -T refuses files, symlinks and directories, including races.
|
||||||
|
const WRITE_VIA_USERNS: &str = r#"set -eu
|
||||||
|
dir=$1
|
||||||
|
name=$2
|
||||||
|
expected=$3
|
||||||
|
[ ! -L "$dir" ] || exit 1
|
||||||
|
if [ ! -d "$dir" ]; then
|
||||||
|
mkdir -p -- "$dir"
|
||||||
|
chown --reference="$(dirname -- "$dir")" -- "$dir"
|
||||||
|
fi
|
||||||
|
tmp=$(mktemp "$dir/.archy-saving.XXXXXXXXXX")
|
||||||
|
trap 'rm -f -- "$tmp"' EXIT HUP INT TERM
|
||||||
|
cat > "$tmp"
|
||||||
|
[ "$(wc -c < "$tmp")" -eq "$expected" ] || exit 1
|
||||||
|
chown --reference="$dir" -- "$tmp"
|
||||||
|
chmod 0644 -- "$tmp"
|
||||||
|
sync -f -- "$tmp"
|
||||||
|
stem=$name
|
||||||
|
ext=
|
||||||
|
case "$name" in
|
||||||
|
*.*) prefix=${name%.*}; if [ -n "$prefix" ]; then stem=$prefix; ext=.${name##*.}; fi ;;
|
||||||
|
esac
|
||||||
|
n=1
|
||||||
|
while [ "$n" -le 100 ]; do
|
||||||
|
candidate=$name
|
||||||
|
if [ "$n" -gt 1 ]; then candidate="$stem ($n)$ext"; fi
|
||||||
|
dst="$dir/$candidate"
|
||||||
|
if ln -T -- "$tmp" "$dst" 2>/dev/null; then
|
||||||
|
printf '%s' "$candidate"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
# A conflict may be a dangling symlink; never follow it or overwrite it.
|
||||||
|
if [ ! -e "$dst" ] && [ ! -L "$dst" ]; then exit 1; fi
|
||||||
|
n=$((n + 1))
|
||||||
|
done
|
||||||
|
exit 1
|
||||||
|
"#;
|
||||||
|
|
||||||
|
async fn write_via_userns(dir: PathBuf, name: String, bytes: Vec<u8>) -> Result<PathBuf> {
|
||||||
|
use tokio::io::AsyncWriteExt;
|
||||||
|
let mut child = tokio::process::Command::new("podman")
|
||||||
|
.args(["unshare", "sh", "-c", WRITE_VIA_USERNS, "sh"])
|
||||||
|
.arg(&dir)
|
||||||
|
.arg(&name)
|
||||||
|
.arg(bytes.len().to_string())
|
||||||
|
.kill_on_drop(true)
|
||||||
|
.stdin(std::process::Stdio::piped())
|
||||||
|
.stdout(std::process::Stdio::piped())
|
||||||
|
.stderr(std::process::Stdio::piped())
|
||||||
|
.spawn()
|
||||||
|
.context("Starting Files namespace writer")?;
|
||||||
|
let mut stdin = child.stdin.take().context("Files writer stdin missing")?;
|
||||||
|
let operation = async {
|
||||||
|
let fed = stdin.write_all(&bytes).await;
|
||||||
|
drop(stdin);
|
||||||
|
let output = child.wait_with_output().await?;
|
||||||
|
anyhow::ensure!(
|
||||||
|
output.status.success(),
|
||||||
|
"Files namespace writer failed: {}",
|
||||||
|
output.status
|
||||||
|
);
|
||||||
|
fed.context("Sending purchase bytes to Files")?;
|
||||||
|
let chosen =
|
||||||
|
String::from_utf8(output.stdout).context("Files writer returned an invalid name")?;
|
||||||
|
validate_filename(&chosen)?;
|
||||||
|
anyhow::ensure!(
|
||||||
|
(1..=100).any(|n| numbered_name(&name, n) == chosen),
|
||||||
|
"Files writer returned an unexpected name"
|
||||||
|
);
|
||||||
|
Ok(dir.join(chosen))
|
||||||
|
};
|
||||||
|
tokio::time::timeout(std::time::Duration::from_secs(120), operation)
|
||||||
|
.await
|
||||||
|
.context("Files namespace writer timed out")?
|
||||||
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
use super::*;
|
use super::*;
|
||||||
@@ -152,3 +343,231 @@ mod tests {
|
|||||||
assert_eq!(second, EnsureOutcome::Unchanged);
|
assert_eq!(second, EnsureOutcome::Unchanged);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod purchase_write_tests {
|
||||||
|
use super::*;
|
||||||
|
use std::{
|
||||||
|
collections::HashSet,
|
||||||
|
os::unix::fs::{symlink, PermissionsExt},
|
||||||
|
};
|
||||||
|
|
||||||
|
fn no_temps(dir: &Path) {
|
||||||
|
assert!(std::fs::read_dir(dir).unwrap().all(|e| !e
|
||||||
|
.unwrap()
|
||||||
|
.file_name()
|
||||||
|
.to_string_lossy()
|
||||||
|
.starts_with(".archy-saving")));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn direct_write_uses_complete_bytes_and_preserves_originals() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
fs::write(dir.path().join("song.mp3"), b"original")
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
let target = save_new_file(dir.path(), "song.mp3", b"new").await.unwrap();
|
||||||
|
assert_eq!(target.file_name().unwrap(), "song (2).mp3");
|
||||||
|
assert_eq!(fs::read(target).await.unwrap(), b"new");
|
||||||
|
assert_eq!(
|
||||||
|
fs::read(dir.path().join("song.mp3")).await.unwrap(),
|
||||||
|
b"original"
|
||||||
|
);
|
||||||
|
no_temps(dir.path());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn simultaneous_saves_publish_unique_complete_files() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
let mut tasks = Vec::new();
|
||||||
|
for n in 0..24u8 {
|
||||||
|
let dir = dir.path().to_owned();
|
||||||
|
tasks.push(tokio::spawn(async move {
|
||||||
|
let bytes = vec![n; 32768];
|
||||||
|
let path = save_new_file(&dir, "same.bin", &bytes).await.unwrap();
|
||||||
|
assert_eq!(fs::read(&path).await.unwrap(), bytes);
|
||||||
|
path
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
let mut paths = HashSet::new();
|
||||||
|
for task in tasks {
|
||||||
|
assert!(paths.insert(task.await.unwrap()));
|
||||||
|
}
|
||||||
|
assert_eq!(paths.len(), 24);
|
||||||
|
no_temps(dir.path());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn existing_directories_and_dangling_symlinks_are_conflicts() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
fs::create_dir(dir.path().join("name")).await.unwrap();
|
||||||
|
symlink("missing", dir.path().join("name (2)")).unwrap();
|
||||||
|
let path = save_new_file(dir.path(), "name", b"new").await.unwrap();
|
||||||
|
assert_eq!(path.file_name().unwrap(), "name (3)");
|
||||||
|
assert!(dir.path().join("name").is_dir());
|
||||||
|
assert!(fs::symlink_metadata(dir.path().join("name (2)"))
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.is_symlink());
|
||||||
|
no_temps(dir.path());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn invalid_names_and_symlink_destination_are_refused() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
for name in [
|
||||||
|
"",
|
||||||
|
".",
|
||||||
|
"..",
|
||||||
|
"../escape",
|
||||||
|
"/absolute",
|
||||||
|
"a/b",
|
||||||
|
"a\\b",
|
||||||
|
"a\0b",
|
||||||
|
] {
|
||||||
|
assert!(save_new_file(dir.path(), name, b"bytes").await.is_err());
|
||||||
|
}
|
||||||
|
let outside = tempfile::tempdir().unwrap();
|
||||||
|
symlink(outside.path(), dir.path().join("Music")).unwrap();
|
||||||
|
assert!(save_new_file(&dir.path().join("Music"), "song", b"bytes")
|
||||||
|
.await
|
||||||
|
.is_err());
|
||||||
|
assert_eq!(std::fs::read_dir(outside.path()).unwrap().count(), 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn collision_limit_preserves_all_files_and_cleans_temporary_data() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
for n in 1..=100 {
|
||||||
|
fs::write(dir.path().join(numbered_name("a.txt", n)), b"keep")
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
assert!(save_new_file(dir.path(), "a.txt", b"new").await.is_err());
|
||||||
|
for n in 1..=100 {
|
||||||
|
assert_eq!(
|
||||||
|
fs::read(dir.path().join(numbered_name("a.txt", n)))
|
||||||
|
.await
|
||||||
|
.unwrap(),
|
||||||
|
b"keep"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
no_temps(dir.path());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn permission_fallback_is_exercised_without_skipping_as_root() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
let result = save_after_direct_result(
|
||||||
|
Err(std::io::ErrorKind::PermissionDenied.into()),
|
||||||
|
dir.path(),
|
||||||
|
"a",
|
||||||
|
b"abc",
|
||||||
|
|dir, name, bytes| async move {
|
||||||
|
assert_eq!(bytes, b"abc");
|
||||||
|
Ok(dir.join(name))
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(result, dir.path().join("a"));
|
||||||
|
assert!(save_after_direct_result(
|
||||||
|
Err(std::io::ErrorKind::PermissionDenied.into()),
|
||||||
|
dir.path(),
|
||||||
|
"a",
|
||||||
|
b"abc",
|
||||||
|
|_, _, _| async { anyhow::bail!("namespace unavailable") }
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap_err()
|
||||||
|
.to_string()
|
||||||
|
.contains("namespace"));
|
||||||
|
assert!(save_after_direct_result(
|
||||||
|
Err(std::io::ErrorKind::StorageFull.into()),
|
||||||
|
dir.path(),
|
||||||
|
"a",
|
||||||
|
b"abc",
|
||||||
|
|_, _, _| async { panic!("disk full must not trigger permission fallback") }
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.is_err());
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn run_script(
|
||||||
|
dir: &Path,
|
||||||
|
name: &str,
|
||||||
|
bytes: &[u8],
|
||||||
|
expected: usize,
|
||||||
|
) -> std::process::Output {
|
||||||
|
use tokio::io::AsyncWriteExt;
|
||||||
|
let mut child = tokio::process::Command::new("sh")
|
||||||
|
.args(["-c", WRITE_VIA_USERNS, "sh"])
|
||||||
|
.arg(dir)
|
||||||
|
.arg(name)
|
||||||
|
.arg(expected.to_string())
|
||||||
|
.stdin(std::process::Stdio::piped())
|
||||||
|
.stdout(std::process::Stdio::piped())
|
||||||
|
.stderr(std::process::Stdio::piped())
|
||||||
|
.spawn()
|
||||||
|
.unwrap();
|
||||||
|
let mut input = child.stdin.take().unwrap();
|
||||||
|
input.write_all(bytes).await.unwrap();
|
||||||
|
drop(input);
|
||||||
|
child.wait_with_output().await.unwrap()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn namespace_script_preserves_names_bytes_modes_and_existing_entries() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
let folder = dir.path().join("Music");
|
||||||
|
let name = "song ' $() ; #.mp3";
|
||||||
|
for n in 1..=2 {
|
||||||
|
let output = run_script(&folder, name, b"abc", 3).await;
|
||||||
|
assert!(
|
||||||
|
output.status.success(),
|
||||||
|
"{}",
|
||||||
|
String::from_utf8_lossy(&output.stderr)
|
||||||
|
);
|
||||||
|
let chosen = String::from_utf8(output.stdout).unwrap();
|
||||||
|
assert_eq!(chosen, numbered_name(name, n));
|
||||||
|
let path = folder.join(chosen);
|
||||||
|
assert_eq!(fs::read(&path).await.unwrap(), b"abc");
|
||||||
|
assert_eq!(
|
||||||
|
fs::metadata(path).await.unwrap().permissions().mode() & 0o777,
|
||||||
|
0o644
|
||||||
|
);
|
||||||
|
}
|
||||||
|
no_temps(&folder);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn namespace_script_refuses_truncated_input_and_cleans_up() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
let output = run_script(dir.path(), "never.bin", b"partial", 100).await;
|
||||||
|
assert!(!output.status.success());
|
||||||
|
assert!(!dir.path().join("never.bin").exists());
|
||||||
|
no_temps(dir.path());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn namespace_script_does_not_link_inside_existing_directory() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
fs::create_dir(dir.path().join("name")).await.unwrap();
|
||||||
|
symlink("missing", dir.path().join("name (2)")).unwrap();
|
||||||
|
let output = run_script(dir.path(), "name", b"abc", 3).await;
|
||||||
|
assert!(output.status.success());
|
||||||
|
assert_eq!(output.stdout, b"name (3)");
|
||||||
|
assert_eq!(
|
||||||
|
std::fs::read_dir(dir.path().join("name")).unwrap().count(),
|
||||||
|
0
|
||||||
|
);
|
||||||
|
no_temps(dir.path());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn names_keep_extensions_and_dotfiles() {
|
||||||
|
assert_eq!(numbered_name("a.tar.gz", 2), "a.tar (2).gz");
|
||||||
|
assert_eq!(numbered_name(".hidden", 2), ".hidden (2)");
|
||||||
|
assert_eq!(numbered_name("README", 2), "README (2)");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -1174,15 +1174,21 @@ impl ReconcileReport {
|
|||||||
fn cascade_pairs_for_report<'r>(
|
fn cascade_pairs_for_report<'r>(
|
||||||
report: &'r ReconcileReport,
|
report: &'r ReconcileReport,
|
||||||
user_stopped: &std::collections::HashSet<String>,
|
user_stopped: &std::collections::HashSet<String>,
|
||||||
|
changed_backends: &HashSet<String>,
|
||||||
) -> Vec<(&'r str, &'static str)> {
|
) -> Vec<(&'r str, &'static str)> {
|
||||||
let mut pairs = Vec::new();
|
let mut pairs = Vec::new();
|
||||||
for (backend, action) in &report.actions {
|
for (backend, action) in &report.actions {
|
||||||
if !matches!(
|
if !matches!(
|
||||||
action,
|
action,
|
||||||
ReconcileAction::Installed | ReconcileAction::Started
|
ReconcileAction::NoOp | ReconcileAction::Started | ReconcileAction::Installed
|
||||||
) {
|
) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
// A successful systemctl start can be a no-op after a transient
|
||||||
|
// Podman inspect failure. Require a witnessed lifecycle change.
|
||||||
|
if !changed_backends.contains(backend) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
for dep in crate::app_ops::address_caching_dependents(backend) {
|
for dep in crate::app_ops::address_caching_dependents(backend) {
|
||||||
let dep_untouched = report
|
let dep_untouched = report
|
||||||
.actions
|
.actions
|
||||||
@@ -1196,6 +1202,25 @@ fn cascade_pairs_for_report<'r>(
|
|||||||
pairs
|
pairs
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Only positive runtime evidence permits disrupting an address-caching wallet.
|
||||||
|
/// A known absent/stopped backend becoming running, a new container ID, or a
|
||||||
|
/// changed start timestamp qualifies. A failed observation never does.
|
||||||
|
fn backend_instance_changed(before: Option<&ContainerStatus>, after: &ContainerStatus) -> bool {
|
||||||
|
if after.state != ContainerState::Running || after.id.is_empty() {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
let Some(before) = before else {
|
||||||
|
return true;
|
||||||
|
};
|
||||||
|
if before.id.is_empty() {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
if before.id != after.id || before.state != ContainerState::Running {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
matches!((&before.started_at, &after.started_at), (Some(a), Some(b)) if !a.is_empty() && !b.is_empty() && a != b)
|
||||||
|
}
|
||||||
|
|
||||||
#[derive(Debug, Default)]
|
#[derive(Debug, Default)]
|
||||||
pub struct AdoptionReport {
|
pub struct AdoptionReport {
|
||||||
pub adopted: Vec<String>,
|
pub adopted: Vec<String>,
|
||||||
@@ -1909,12 +1934,33 @@ impl ProdContainerOrchestrator {
|
|||||||
_ => 2,
|
_ => 2,
|
||||||
});
|
});
|
||||||
// Live container names (any state), for the same recovery check.
|
// Live container names (any state), for the same recovery check.
|
||||||
let present_containers: std::collections::HashSet<String> = self
|
let listed_containers = self.runtime.list_containers().await.ok();
|
||||||
.runtime
|
let present_containers: HashSet<String> = listed_containers
|
||||||
.list_containers()
|
.as_ref()
|
||||||
.await
|
.map(|cs| cs.iter().map(|c| c.name.clone()).collect())
|
||||||
.map(|cs| cs.into_iter().map(|c| c.name).collect())
|
|
||||||
.unwrap_or_default();
|
.unwrap_or_default();
|
||||||
|
// Keep unknown distinct from confirmed absence. Runtime queries can
|
||||||
|
// fail under load while systemd still has a healthy running backend.
|
||||||
|
let mut backend_before: HashMap<String, Option<ContainerStatus>> = HashMap::new();
|
||||||
|
for lm in &manifests {
|
||||||
|
let id = &lm.manifest.app.id;
|
||||||
|
if crate::app_ops::address_caching_dependents(id).is_empty() {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
let name = compute_container_name(&lm.manifest);
|
||||||
|
match self.runtime.get_container_status(&name).await {
|
||||||
|
Ok(status) => {
|
||||||
|
backend_before.insert(id.clone(), Some(status));
|
||||||
|
}
|
||||||
|
Err(_) if listed_containers.is_some() && !present_containers.contains(&name) => {
|
||||||
|
backend_before.insert(id.clone(), None);
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
tracing::warn!(backend = %id, error = %err,
|
||||||
|
"cannot observe backend before reconcile; will not infer a dependency restart from an action report");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
let mut report = ReconcileReport::default();
|
let mut report = ReconcileReport::default();
|
||||||
let disk_gb = self.disk_gb().await;
|
let disk_gb = self.disk_gb().await;
|
||||||
let bitcoin_pruned = disk_gb < ARCHIVAL_BITCOIN_DISK_GB
|
let bitcoin_pruned = disk_gb < ARCHIVAL_BITCOIN_DISK_GB
|
||||||
@@ -2096,7 +2142,20 @@ impl ProdContainerOrchestrator {
|
|||||||
// state recovery, repair recreate, boot InstallMissing) moves the
|
// state recovery, repair recreate, boot InstallMissing) moves the
|
||||||
// address behind a running dependent's back — §C "restart lnd after
|
// address behind a running dependent's back — §C "restart lnd after
|
||||||
// ANY bitcoin recreate".
|
// ANY bitcoin recreate".
|
||||||
for (backend, dep) in cascade_pairs_for_report(&report, &user_stopped) {
|
let mut changed_backends = HashSet::new();
|
||||||
|
for (backend, before) in &backend_before {
|
||||||
|
let Some(name) = container_name_by_app_id.get(backend) else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
if let Ok(after) = self.runtime.get_container_status(name).await {
|
||||||
|
if backend_instance_changed(before.as_ref(), &after) {
|
||||||
|
changed_backends.insert(backend.clone());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// A user stop during a slow reconcile pass still takes precedence.
|
||||||
|
let user_stopped = crate::crash_recovery::load_user_stopped(&self.data_dir).await;
|
||||||
|
for (backend, dep) in cascade_pairs_for_report(&report, &user_stopped, &changed_backends) {
|
||||||
// Same rule as the RPC cascade: hold the dependent's op lock
|
// Same rule as the RPC cascade: hold the dependent's op lock
|
||||||
// across the restart; skip when a worker is mid-sequence.
|
// across the restart; skip when a worker is mid-sequence.
|
||||||
let lock = crate::app_ops::op_lock(dep);
|
let lock = crate::app_ops::op_lock(dep);
|
||||||
@@ -6409,6 +6468,67 @@ app:
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn backend_cascade_requires_observed_instance_change() {
|
||||||
|
let running = ContainerStatus {
|
||||||
|
id: "container-1".into(),
|
||||||
|
name: "bitcoin-core".into(),
|
||||||
|
state: ContainerState::Running,
|
||||||
|
started_at: Some("start-1".into()),
|
||||||
|
health: None,
|
||||||
|
exit_code: None,
|
||||||
|
image: "bitcoin:1".into(),
|
||||||
|
created: "created-1".into(),
|
||||||
|
ports: vec![],
|
||||||
|
lan_address: None,
|
||||||
|
};
|
||||||
|
assert!(!backend_instance_changed(Some(&running), &running));
|
||||||
|
assert!(backend_instance_changed(None, &running));
|
||||||
|
let mut before = running.clone();
|
||||||
|
before.state = ContainerState::Exited;
|
||||||
|
assert!(backend_instance_changed(Some(&before), &running));
|
||||||
|
before = running.clone();
|
||||||
|
before.id = "old-container".into();
|
||||||
|
assert!(backend_instance_changed(Some(&before), &running));
|
||||||
|
before = running.clone();
|
||||||
|
before.started_at = Some("earlier-start".into());
|
||||||
|
assert!(backend_instance_changed(Some(&before), &running));
|
||||||
|
before.started_at = None;
|
||||||
|
assert!(!backend_instance_changed(Some(&before), &running));
|
||||||
|
before.id.clear();
|
||||||
|
assert!(!backend_instance_changed(Some(&before), &running));
|
||||||
|
let mut after = running.clone();
|
||||||
|
after.state = ContainerState::Exited;
|
||||||
|
assert!(!backend_instance_changed(None, &after));
|
||||||
|
after = running.clone();
|
||||||
|
after.id.clear();
|
||||||
|
assert!(!backend_instance_changed(None, &after));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn cascade_ignores_false_started_report_but_detects_real_exec_drift() {
|
||||||
|
let none = HashSet::new();
|
||||||
|
let mut report = ReconcileReport {
|
||||||
|
actions: vec![
|
||||||
|
("bitcoin-core".into(), ReconcileAction::Started),
|
||||||
|
("lnd".into(), ReconcileAction::NoOp),
|
||||||
|
],
|
||||||
|
failures: vec![],
|
||||||
|
};
|
||||||
|
// systemctl start of an already active unit does not move its address.
|
||||||
|
assert!(cascade_pairs_for_report(&report, &none, &none).is_empty());
|
||||||
|
// A unit exec rewrite can restart Bitcoin while the outer reconcile
|
||||||
|
// action remains NoOp. Runtime evidence still requires LND to reconnect.
|
||||||
|
let changed = ["bitcoin-core".into()].into();
|
||||||
|
report.actions[0].1 = ReconcileAction::NoOp;
|
||||||
|
assert_eq!(
|
||||||
|
cascade_pairs_for_report(&report, &none, &changed),
|
||||||
|
vec![("bitcoin-core", "lnd")]
|
||||||
|
);
|
||||||
|
report.actions[0].1 = ReconcileAction::Left("lifecycle-op-in-flight".into());
|
||||||
|
assert!(cascade_pairs_for_report(&report, &none, &changed).is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn cascade_pairs_cover_backend_recreate_with_running_dependent() {
|
fn cascade_pairs_cover_backend_recreate_with_running_dependent() {
|
||||||
use std::collections::HashSet;
|
use std::collections::HashSet;
|
||||||
@@ -6420,6 +6540,7 @@ app:
|
|||||||
failures: vec![],
|
failures: vec![],
|
||||||
};
|
};
|
||||||
let none = HashSet::new();
|
let none = HashSet::new();
|
||||||
|
let changed: HashSet<String> = ["bitcoin-core".into(), "bitcoin-knots".into()].into();
|
||||||
|
|
||||||
// Backend recreated while lnd sat running (NoOp) → cascade.
|
// Backend recreated while lnd sat running (NoOp) → cascade.
|
||||||
let r = report(vec![
|
let r = report(vec![
|
||||||
@@ -6427,7 +6548,7 @@ app:
|
|||||||
("lnd", ReconcileAction::NoOp),
|
("lnd", ReconcileAction::NoOp),
|
||||||
]);
|
]);
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
cascade_pairs_for_report(&r, &none),
|
cascade_pairs_for_report(&r, &none, &changed),
|
||||||
vec![("bitcoin-knots", "lnd")]
|
vec![("bitcoin-knots", "lnd")]
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -6437,7 +6558,7 @@ app:
|
|||||||
("lnd", ReconcileAction::NoOp),
|
("lnd", ReconcileAction::NoOp),
|
||||||
]);
|
]);
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
cascade_pairs_for_report(&r, &none),
|
cascade_pairs_for_report(&r, &none, &changed),
|
||||||
vec![("bitcoin-core", "lnd")]
|
vec![("bitcoin-core", "lnd")]
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -6446,7 +6567,7 @@ app:
|
|||||||
("bitcoin-knots", ReconcileAction::NoOp),
|
("bitcoin-knots", ReconcileAction::NoOp),
|
||||||
("lnd", ReconcileAction::NoOp),
|
("lnd", ReconcileAction::NoOp),
|
||||||
]);
|
]);
|
||||||
assert!(cascade_pairs_for_report(&r, &none).is_empty());
|
assert!(cascade_pairs_for_report(&r, &none, &none).is_empty());
|
||||||
|
|
||||||
// Dependent itself (re)started this pass → it already resolved the
|
// Dependent itself (re)started this pass → it already resolved the
|
||||||
// fresh address; no cascade.
|
// fresh address; no cascade.
|
||||||
@@ -6454,7 +6575,7 @@ app:
|
|||||||
("bitcoin-knots", ReconcileAction::Installed),
|
("bitcoin-knots", ReconcileAction::Installed),
|
||||||
("lnd", ReconcileAction::Started),
|
("lnd", ReconcileAction::Started),
|
||||||
]);
|
]);
|
||||||
assert!(cascade_pairs_for_report(&r, &none).is_empty());
|
assert!(cascade_pairs_for_report(&r, &none, &changed).is_empty());
|
||||||
|
|
||||||
// User-stopped dependent is never bounced.
|
// User-stopped dependent is never bounced.
|
||||||
let r = report(vec![
|
let r = report(vec![
|
||||||
@@ -6462,14 +6583,14 @@ app:
|
|||||||
("lnd", ReconcileAction::NoOp),
|
("lnd", ReconcileAction::NoOp),
|
||||||
]);
|
]);
|
||||||
let stopped: HashSet<String> = ["lnd".to_string()].into();
|
let stopped: HashSet<String> = ["lnd".to_string()].into();
|
||||||
assert!(cascade_pairs_for_report(&r, &stopped).is_empty());
|
assert!(cascade_pairs_for_report(&r, &stopped, &changed).is_empty());
|
||||||
|
|
||||||
// Non-backend recreates don't cascade anything.
|
// Non-backend recreates don't cascade anything.
|
||||||
let r = report(vec![
|
let r = report(vec![
|
||||||
("grafana", ReconcileAction::Installed),
|
("grafana", ReconcileAction::Installed),
|
||||||
("lnd", ReconcileAction::NoOp),
|
("lnd", ReconcileAction::NoOp),
|
||||||
]);
|
]);
|
||||||
assert!(cascade_pairs_for_report(&r, &none).is_empty());
|
assert!(cascade_pairs_for_report(&r, &none, &changed).is_empty());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
|
|||||||
@@ -184,6 +184,7 @@ pub struct QuadletUnit {
|
|||||||
pub no_new_privileges: bool,
|
pub no_new_privileges: bool,
|
||||||
pub cpu_quota: Option<u32>,
|
pub cpu_quota: Option<u32>,
|
||||||
pub restart_policy: RestartPolicy,
|
pub restart_policy: RestartPolicy,
|
||||||
|
pub stop_grace_secs: Option<u64>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl QuadletUnit {
|
impl QuadletUnit {
|
||||||
@@ -216,6 +217,10 @@ impl QuadletUnit {
|
|||||||
let _ = writeln!(s, "[Container]");
|
let _ = writeln!(s, "[Container]");
|
||||||
let _ = writeln!(s, "ContainerName={}", self.name);
|
let _ = writeln!(s, "ContainerName={}", self.name);
|
||||||
let _ = writeln!(s, "Image={}", self.image);
|
let _ = writeln!(s, "Image={}", self.image);
|
||||||
|
let grace = self
|
||||||
|
.stop_grace_secs
|
||||||
|
.unwrap_or_else(|| archipelago_container::runtime::stop_grace_secs_for(&self.name));
|
||||||
|
let _ = writeln!(s, "StopTimeout={grace}");
|
||||||
// Pull=never: companions are pre-pulled or built. A missing image
|
// Pull=never: companions are pre-pulled or built. A missing image
|
||||||
// must surface as a unit start failure, not a silent retry storm.
|
// must surface as a unit start failure, not a silent retry storm.
|
||||||
let _ = writeln!(s, "Pull=never");
|
let _ = writeln!(s, "Pull=never");
|
||||||
@@ -350,6 +355,15 @@ impl QuadletUnit {
|
|||||||
// the unit stuck in deactivating. Health/status remains app-level state,
|
// the unit stuck in deactivating. Health/status remains app-level state,
|
||||||
// not a systemd start gate.
|
// not a systemd start gate.
|
||||||
let _ = writeln!(s, "TimeoutStartSec=0");
|
let _ = writeln!(s, "TimeoutStartSec=0");
|
||||||
|
let _ = writeln!(s, "TimeoutStopSec={}", grace.saturating_add(15));
|
||||||
|
// Stop explicitly before Quadlet's generated `podman rm -f`. The
|
||||||
|
// existing container may still carry Podman's old 10-second default;
|
||||||
|
// StopTimeout alone only protects containers created after migration.
|
||||||
|
let _ = writeln!(s, "ExecStop=");
|
||||||
|
let _ = writeln!(
|
||||||
|
s,
|
||||||
|
"ExecStop=/usr/bin/podman stop --ignore --time={grace} --cidfile=%t/%N.cid"
|
||||||
|
);
|
||||||
// Restart policy + 10s backoff. RestartSec keeps a crash-loop
|
// Restart policy + 10s backoff. RestartSec keeps a crash-loop
|
||||||
// from saturating the journal. Companions: Always. Backends:
|
// from saturating the journal. Companions: Always. Backends:
|
||||||
// OnFailure (clean stops stay stopped).
|
// OnFailure (clean stops stay stopped).
|
||||||
@@ -525,6 +539,9 @@ impl QuadletUnit {
|
|||||||
// Always, not OnFailure: with quadlet's `--rm`, OnFailure left a
|
// Always, not OnFailure: with quadlet's `--rm`, OnFailure left a
|
||||||
// cleanly-exited app deleted and unrestarted. See RestartPolicy.
|
// cleanly-exited app deleted and unrestarted. See RestartPolicy.
|
||||||
restart_policy: RestartPolicy::Always,
|
restart_policy: RestartPolicy::Always,
|
||||||
|
stop_grace_secs: Some(super::prod_orchestrator::resolve_stop_grace_secs(
|
||||||
|
manifest, name,
|
||||||
|
)),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -792,7 +809,11 @@ pub async fn stop_service(service: &str) -> Result<()> {
|
|||||||
/// corruption — so the orchestrator passes the per-app grace here. Never waits
|
/// corruption — so the orchestrator passes the per-app grace here. Never waits
|
||||||
/// less than `QUADLET_STOP_TIMEOUT`.
|
/// less than `QUADLET_STOP_TIMEOUT`.
|
||||||
pub async fn stop_service_with_timeout(service: &str, timeout: Duration) -> Result<()> {
|
pub async fn stop_service_with_timeout(service: &str, timeout: Duration) -> Result<()> {
|
||||||
let timeout = timeout.max(QUADLET_STOP_TIMEOUT);
|
let name = service.strip_suffix(".service").unwrap_or(service);
|
||||||
|
let body = fs::read_to_string(unit_dir().await?.join(format!("{name}.container")))
|
||||||
|
.await
|
||||||
|
.unwrap_or_default();
|
||||||
|
let timeout = timeout.max(stop_wait_timeout(name, &body));
|
||||||
match systemctl_user_status(&["stop", service], timeout).await {
|
match systemctl_user_status(&["stop", service], timeout).await {
|
||||||
Ok(status) if status.success() => Ok(()),
|
Ok(status) if status.success() => Ok(()),
|
||||||
Ok(status) => Err(anyhow!("systemctl --user stop {service} exited {status}")),
|
Ok(status) => Err(anyhow!("systemctl --user stop {service} exited {status}")),
|
||||||
@@ -813,6 +834,20 @@ pub async fn stop_service_with_timeout(service: &str, timeout: Duration) -> Resu
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// The command waiter must outlive both the container grace and systemd's
|
||||||
|
/// stop deadline. Restart/repair callers must not kill Bitcoin at 45 seconds.
|
||||||
|
fn stop_wait_timeout(name: &str, unit_body: &str) -> Duration {
|
||||||
|
Duration::from_secs(stop_grace_from_unit(name, unit_body).saturating_add(30))
|
||||||
|
.max(QUADLET_STOP_TIMEOUT)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn stop_grace_from_unit(name: &str, unit_body: &str) -> u64 {
|
||||||
|
directive_values(unit_body, "StopTimeout=")
|
||||||
|
.last()
|
||||||
|
.and_then(|value| value.parse::<u64>().ok())
|
||||||
|
.unwrap_or_else(|| archipelago_container::runtime::stop_grace_secs_for(name))
|
||||||
|
}
|
||||||
|
|
||||||
async fn systemctl_user_status(
|
async fn systemctl_user_status(
|
||||||
args: &[&str],
|
args: &[&str],
|
||||||
timeout: Duration,
|
timeout: Duration,
|
||||||
@@ -939,6 +974,10 @@ fn directive_values(unit_body: &str, prefix: &str) -> Vec<String> {
|
|||||||
/// that systemd no longer knows about.
|
/// that systemd no longer knows about.
|
||||||
pub async fn disable_remove(unit_name: &str, dir: &Path) -> Result<()> {
|
pub async fn disable_remove(unit_name: &str, dir: &Path) -> Result<()> {
|
||||||
let svc = format!("{unit_name}.service");
|
let svc = format!("{unit_name}.service");
|
||||||
|
let path = dir.join(format!("{unit_name}.container"));
|
||||||
|
let body = fs::read_to_string(&path).await.unwrap_or_default();
|
||||||
|
let timeout = stop_wait_timeout(unit_name, &body);
|
||||||
|
let grace = stop_grace_from_unit(unit_name, &body).to_string();
|
||||||
// Stop first; ignore failure (unit may already be down). BOUNDED — on
|
// Stop first; ignore failure (unit may already be down). BOUNDED — on
|
||||||
// rootless podman a generated unit can wedge in "deactivating" while
|
// rootless podman a generated unit can wedge in "deactivating" while
|
||||||
// `podman rm -f` hangs underneath it, and an unbounded `systemctl stop`
|
// `podman rm -f` hangs underneath it, and an unbounded `systemctl stop`
|
||||||
@@ -946,13 +985,12 @@ pub async fn disable_remove(unit_name: &str, dir: &Path) -> Result<()> {
|
|||||||
// the package entry is stranded in `Removing` (a ghost in My Apps that also
|
// the package entry is stranded in `Removing` (a ghost in My Apps that also
|
||||||
// blocks reinstall). If the graceful stop times out, escalate to
|
// blocks reinstall). If the graceful stop times out, escalate to
|
||||||
// SIGKILL + reset-failed so teardown always proceeds.
|
// SIGKILL + reset-failed so teardown always proceeds.
|
||||||
if systemctl_user_status(&["stop", &svc], QUADLET_STOP_TIMEOUT)
|
if systemctl_user_status(&["stop", &svc], timeout)
|
||||||
.await
|
.await
|
||||||
.is_err()
|
.is_err()
|
||||||
{
|
{
|
||||||
let _ = kill_and_reset_service(&svc).await;
|
let _ = kill_and_reset_service(&svc).await;
|
||||||
}
|
}
|
||||||
let path = dir.join(format!("{unit_name}.container"));
|
|
||||||
if fs::try_exists(&path).await.unwrap_or(false) {
|
if fs::try_exists(&path).await.unwrap_or(false) {
|
||||||
match fs::remove_file(&path).await {
|
match fs::remove_file(&path).await {
|
||||||
Ok(()) => {}
|
Ok(()) => {}
|
||||||
@@ -965,9 +1003,9 @@ pub async fn disable_remove(unit_name: &str, dir: &Path) -> Result<()> {
|
|||||||
// Bounded so a hung podman store can't re-introduce the stall this function
|
// Bounded so a hung podman store can't re-introduce the stall this function
|
||||||
// exists to avoid.
|
// exists to avoid.
|
||||||
let _ = tokio::time::timeout(
|
let _ = tokio::time::timeout(
|
||||||
QUADLET_STOP_TIMEOUT,
|
timeout,
|
||||||
Command::new("podman")
|
Command::new("podman")
|
||||||
.args(["rm", "-f", unit_name])
|
.args(["rm", "-f", "--ignore", "--time", &grace, unit_name])
|
||||||
.status(),
|
.status(),
|
||||||
)
|
)
|
||||||
.await;
|
.await;
|
||||||
@@ -992,6 +1030,118 @@ mod tests {
|
|||||||
use super::*;
|
use super::*;
|
||||||
use tempfile::tempdir;
|
use tempfile::tempdir;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn shutdown_grace_covers_container_systemd_and_caller() {
|
||||||
|
for (name, grace) in [
|
||||||
|
("bitcoin-core", 600),
|
||||||
|
("bitcoin-knots", 600),
|
||||||
|
("lnd", 330),
|
||||||
|
("electrumx", 300),
|
||||||
|
("other", 30),
|
||||||
|
] {
|
||||||
|
let unit = QuadletUnit {
|
||||||
|
name: name.into(),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
let body = unit.render();
|
||||||
|
assert!(body.contains(&format!("StopTimeout={grace}\n")));
|
||||||
|
assert!(body.contains(&format!("TimeoutStopSec={}\n", grace + 15)));
|
||||||
|
assert!(body.contains(&format!("podman stop --ignore --time={grace} --cidfile=")));
|
||||||
|
assert_eq!(
|
||||||
|
stop_wait_timeout(name, &body),
|
||||||
|
Duration::from_secs(grace + 30)
|
||||||
|
);
|
||||||
|
// Legacy units have no StopTimeout directive yet.
|
||||||
|
assert_eq!(stop_wait_timeout(name, ""), Duration::from_secs(grace + 30));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn custom_stop_grace_survives_render_and_restart_budget() {
|
||||||
|
let manifest: AppManifest = serde_yaml::from_str(
|
||||||
|
r#"
|
||||||
|
app:
|
||||||
|
id: custom-db
|
||||||
|
name: Custom database
|
||||||
|
version: 1.0.0
|
||||||
|
stop_grace_secs: 900
|
||||||
|
container:
|
||||||
|
image: example/db:1
|
||||||
|
"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
let unit = QuadletUnit::from_manifest(&manifest, "custom-db");
|
||||||
|
assert_eq!(unit.stop_grace_secs, Some(900));
|
||||||
|
assert_eq!(
|
||||||
|
stop_wait_timeout("custom-db", &unit.render()),
|
||||||
|
Duration::from_secs(930)
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
stop_wait_timeout("lnd", "StopTimeout=invalid"),
|
||||||
|
Duration::from_secs(360)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn stop_grace_migration_does_not_request_an_execution_restart() {
|
||||||
|
let unit = sample_unit();
|
||||||
|
let new = unit.render();
|
||||||
|
let old = new
|
||||||
|
.lines()
|
||||||
|
.filter(|line| {
|
||||||
|
!line.starts_with("StopTimeout=")
|
||||||
|
&& !line.starts_with("TimeoutStopSec=")
|
||||||
|
&& !line.starts_with("ExecStop=")
|
||||||
|
})
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join("\n");
|
||||||
|
assert!(!exec_changed(&old, &new));
|
||||||
|
assert!(!publish_ports_changed(&old, &new));
|
||||||
|
assert!(!network_aliases_changed(&old, &new));
|
||||||
|
assert!(!health_cmd_changed(&old, &new));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn actual_quadlet_generator_stops_before_forced_removal() {
|
||||||
|
let generator = Path::new("/usr/lib/systemd/system-generators/podman-system-generator");
|
||||||
|
if !generator.exists() {
|
||||||
|
eprintln!(
|
||||||
|
"Quadlet generator unavailable; run this regression on the Linux release host"
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let unit = QuadletUnit {
|
||||||
|
name: "grace-test".into(),
|
||||||
|
image: "localhost/test:latest".into(),
|
||||||
|
stop_grace_secs: Some(600),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
std::fs::write(dir.path().join("grace-test.container"), unit.render()).unwrap();
|
||||||
|
let output = std::process::Command::new(generator)
|
||||||
|
.args(["--user", "--dryrun"])
|
||||||
|
.env("QUADLET_UNIT_DIRS", dir.path())
|
||||||
|
.output()
|
||||||
|
.unwrap();
|
||||||
|
assert!(
|
||||||
|
output.status.success(),
|
||||||
|
"{}",
|
||||||
|
String::from_utf8_lossy(&output.stderr)
|
||||||
|
);
|
||||||
|
let generated = String::from_utf8_lossy(&output.stdout).to_string()
|
||||||
|
+ &String::from_utf8_lossy(&output.stderr);
|
||||||
|
let stop = generated
|
||||||
|
.find("ExecStop=/usr/bin/podman stop --ignore --time=600")
|
||||||
|
.unwrap();
|
||||||
|
let remove = generated.find("ExecStop=/usr/bin/podman rm ").unwrap();
|
||||||
|
assert!(
|
||||||
|
stop < remove,
|
||||||
|
"Legacy container must stop gracefully before removal"
|
||||||
|
);
|
||||||
|
assert!(generated.contains("--stop-timeout 600"));
|
||||||
|
assert!(generated.contains("TimeoutStopSec=615"));
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn render_emits_secret_env_by_reference_never_value() {
|
fn render_emits_secret_env_by_reference_never_value() {
|
||||||
let u = QuadletUnit {
|
let u = QuadletUnit {
|
||||||
|
|||||||
+21
-5
@@ -3,15 +3,31 @@
|
|||||||
Working backlog of forward-looking items not yet scoped into a dedicated plan
|
Working backlog of forward-looking items not yet scoped into a dedicated plan
|
||||||
doc. See [`ROADMAP.md`](ROADMAP.md) for the curated, public-facing direction.
|
doc. See [`ROADMAP.md`](ROADMAP.md) for the curated, public-facing direction.
|
||||||
|
|
||||||
## Blocking incident — before unrelated work
|
## Framework incident — closed with operator acceptance
|
||||||
|
|
||||||
- **OPEN: Framework LND startup / missing Receive address / false zero balance.**
|
- **CLOSED WITH OPERATOR ACCEPTANCE (2026-09-30): Framework LND startup /
|
||||||
User requires investigation and a verified fix on the actual node before later
|
missing Receive address / false zero balance.** Startup, native balances,
|
||||||
unrelated work. Startup and native balances were verified on the actual node;
|
Cashu address and source integration were verified; the operator accepted the
|
||||||
final display confirmation is pending. See the incident record for evidence.
|
remaining display check and authorized release. See the incident record for evidence.
|
||||||
See [incident evidence and closure criteria](incident-framework-lnd-startup.md)
|
See [incident evidence and closure criteria](incident-framework-lnd-startup.md)
|
||||||
and the repository `AGENTS.md` session-start instructions.
|
and the repository `AGENTS.md` session-start instructions.
|
||||||
|
|
||||||
|
## Next release after 1.8.21 — reported 2026-09-30
|
||||||
|
|
||||||
|
- [ ] **ThinkPad X250 kiosk: Bitcoin installation version selector is unreadable
|
||||||
|
and appears underneath the pruning information.** Operator reports white
|
||||||
|
styling with invisible text on the actual kiosk; the same flow works in remote
|
||||||
|
Brave. Reproduce on the X250's kiosk engine and record its version, display
|
||||||
|
scale and resolution. Inspect the native `<select>` in
|
||||||
|
`neode-ui/src/components/InstallVersionModal.vue`, its option colors, and the
|
||||||
|
scroll/stacking behavior in `BaseModal.vue`; these are investigation leads,
|
||||||
|
not a confirmed cause. Fix contrast and popup visibility without changing
|
||||||
|
version selection or pruning behavior. Validate Core and Knots, open/closed
|
||||||
|
and scrolled dropdowns, keyboard/touch selection, and pruning on/off on the
|
||||||
|
actual kiosk, with remote Brave and mobile regression checks. Browser mocks
|
||||||
|
alone do not establish that the kiosk rendering is fixed. Track for the next
|
||||||
|
release; the signed 1.8.21 artifacts remain unchanged.
|
||||||
|
|
||||||
## Current repair and release tasks — 2026-09-29
|
## Current repair and release tasks — 2026-09-29
|
||||||
|
|
||||||
Release is blocked until these pass; see [execution record](repair-release-20260929.md).
|
Release is blocked until these pass; see [execution record](repair-release-20260929.md).
|
||||||
|
|||||||
@@ -257,3 +257,102 @@ Both catalog and OTA signatures verify against the pinned release root. Staged
|
|||||||
artifact hash/size checks and catalog drift/trust checks pass. User accepted the
|
artifact hash/size checks and catalog drift/trust checks pass. User accepted the
|
||||||
remaining Framework display check and explicitly authorized release. Publication
|
remaining Framework display check and explicitly authorized release. Publication
|
||||||
and ISO build may proceed; do not regenerate the signed manifest or artifacts.
|
and ISO build may proceed; do not regenerate the signed manifest or artifacts.
|
||||||
|
|
||||||
|
### Published OTA; ISO withheld after live shutdown defect — 2026-09-30
|
||||||
|
|
||||||
|
Signed 1.8.20 OTA/catalog published to git and ngit, with public asset hashes
|
||||||
|
verified. Catalog rollout triggered a Bitcoin command update at 08:34 UTC.
|
||||||
|
Although the orchestrator allowed a long stop, Quadlet's generated Podman removal
|
||||||
|
still used its ten-second default and killed Bitcoin. Core replayed its block
|
||||||
|
index; LND later lost its connection to the previous Bitcoin container IP.
|
||||||
|
|
||||||
|
Stopped the ISO build and queued boot check; any partial 1.8.20 ISO is invalid
|
||||||
|
and must not be published. Preparing 1.8.21 to supersede the immutable signed OTA.
|
||||||
|
Installed explicit graceful-stop systemd overrides on dev and Shorty without
|
||||||
|
restarting native services. Candidate Quadlet fix adds per-app container, systemd,
|
||||||
|
and command-wait budgets, including existing containers and uninstall fallback.
|
||||||
|
Focused 43 tests pass, including actual Quadlet generator stop-before-remove order.
|
||||||
|
Full tests, disposable slow-stop verification, build and deployment remain pending.
|
||||||
|
|
||||||
|
Disposable live regression passed: started an Alpine container with its legacy
|
||||||
|
ten-second stop setting, rewrote and reloaded its Quadlet with explicit twenty-
|
||||||
|
second graceful stop, verified the same container ID and old internal timeout
|
||||||
|
remained running, then stopped it. Its twelve-second shutdown handler completed
|
||||||
|
in 12.6 seconds, emitted the completion marker, and exited without SIGKILL/137.
|
||||||
|
Fixture had no network or wallet mounts and was removed afterward.
|
||||||
|
|
||||||
|
Core finished index loading and resumed unpruned initial sync. LND automatically
|
||||||
|
unlocked at 08:47 UTC. The existing backend-address cascade then performed a
|
||||||
|
graceful LND restart at 08:57 UTC after Bitcoin reconciliation completed; LND
|
||||||
|
automatically unlocked again and reached chain-sync waiting. No manual wallet
|
||||||
|
unlock or restart was used for this recovery.
|
||||||
|
|
||||||
|
### False dependency restart exposed during monitoring — 09:08 UTC
|
||||||
|
|
||||||
|
The initial 1.8.21 candidate passed all 1,557 isolated backend tests and 1,120
|
||||||
|
frontend tests. Monitoring nevertheless found another managed LND restart at
|
||||||
|
09:08:32 while Bitcoin's container/start timestamp remained unchanged. Management
|
||||||
|
logs explicitly attribute it to the backend-address cascade. This also makes
|
||||||
|
the earlier 08:57 cascade suspect; it must not be described as a proven necessary
|
||||||
|
restart. These service restarts preceded the isolated test executable, whose
|
||||||
|
namespace boundaries remain intact.
|
||||||
|
|
||||||
|
The cascade trusted Started/Installed action reports. A failed runtime inspection
|
||||||
|
followed by successful systemctl start of an already active unit can produce
|
||||||
|
Started without changing Bitcoin. Dependency restarts now require observed
|
||||||
|
container-ID, running-state, or start-time changes. Failed observations remain
|
||||||
|
unknown, not absence; a known absent backend becoming running still qualifies.
|
||||||
|
Actual exec-drift restarts are recognized even when their outer report is NoOp.
|
||||||
|
Stopped/lifecycle-in-flight dependents remain excluded, and user stop markers
|
||||||
|
are re-read after the potentially slow pass. Added runtime-observation and
|
||||||
|
false-action/real-exec-drift regression cases; full isolated rerun pending.
|
||||||
|
Stopped the first optimized build and preparing new artifacts from this correction.
|
||||||
|
|
||||||
|
### Final 1.8.21 artifacts and live verification — 2026-09-30
|
||||||
|
|
||||||
|
Source and frontend/AIUI attribution: c993d9dd. Full isolated backend suite:
|
||||||
|
1,559 passed, zero failed, four existing hardware/live tests ignored. Frontend
|
||||||
|
suite: 1,120 passed; final production type-check/build passed after the last
|
||||||
|
release-note-only edit. Optimized backend built in 13m22s.
|
||||||
|
|
||||||
|
Staged unsigned 1.8.21 OTA manifest and artifacts:
|
||||||
|
- Backend: 64,748,176 bytes; SHA256
|
||||||
|
ff602e85f340aff7e43d9d94f7f84f11f713735c964c0d8ba150e23b065c30eb.
|
||||||
|
- Frontend archive: 97,152,546 bytes; SHA256
|
||||||
|
6c0842ec83a440269a353808a4cf154174f5232c9989b4a5448bc6486e1d0620.
|
||||||
|
|
||||||
|
Artifact validator passed. Actual archive has flat paths, readable root index,
|
||||||
|
and exact fresh AIUI, doctor and LND UI payload bytes. Exact files deployed to
|
||||||
|
dev at 09:32 UTC and Shorty at 09:35 UTC; rollback binaries and dashboards under
|
||||||
|
root-only /var/lib/archipelago/support/release-1821 on each node. Only management
|
||||||
|
services restarted. Existing Bitcoin/Core-or-Knots and native LND container IDs
|
||||||
|
and start times were preserved. Correct generated graceful-stop commands are
|
||||||
|
present before forced removal on both nodes; temporary grace overrides removed.
|
||||||
|
Dev systemd deadlines are 615 seconds for Bitcoin and 345 seconds for LND.
|
||||||
|
|
||||||
|
Desktop/mobile Lightning UI checks passed again: waiting for Bitcoin sync,
|
||||||
|
unknown balance, no unavailable native RPC requests. Served dashboard and AIUI
|
||||||
|
attribution bytes match the release. Native LND states: dev RPC_ACTIVE while
|
||||||
|
Bitcoin syncs; Shorty SERVER_ACTIVE. Dev completed full reconciliation passes
|
||||||
|
at 09:34:21 and 09:36:40 with Bitcoin/LND NoOp, and no dependency restart.
|
||||||
|
Shorty's first full pass completed 09:36:55 with Knots/LND NoOp.
|
||||||
|
|
||||||
|
Final paid-file check on these exact binaries passed: fresh one-sat dev-to-Shorty
|
||||||
|
purchase, exact one-sat refund on underpayment, identical response aliases,
|
||||||
|
correct Files copy, and zero-charge cached repeat. Removed temporary seller
|
||||||
|
entries/files and Files copy; retained purchase audit and owned cache. Total net
|
||||||
|
transfer across all three live payment rounds in this repair session: three sats.
|
||||||
|
|
||||||
|
Remaining: finish Shorty observation and remove temporary diagnostic logging;
|
||||||
|
user-local 1.8.21 OTA signature (existing catalog signature remains valid),
|
||||||
|
publish git/ngit, build/boot-test/sign and publish the raw 1.8.21 ISO.
|
||||||
|
No 1.8.21 release tag or public OTA yet. Do not publish the quarantined partial
|
||||||
|
1.8.20 ISO. The existing 1.8.20 git/ngit release notes now explain the withheld ISO
|
||||||
|
and pending hotfix; signed 1.8.20 assets remain immutable.
|
||||||
|
|
||||||
|
Shorty's second clean full pass completed at 09:38:06 UTC. Removed temporary
|
||||||
|
diagnostic logging on both nodes and restarted only management again; native
|
||||||
|
Bitcoin and LND IDs/start times remained unchanged, with generated stop settings
|
||||||
|
still verified. No temporary graceful-stop overrides remain. Catalog signature
|
||||||
|
verifies against the pinned release root; final 1.8.21 artifact validator passes.
|
||||||
|
The candidate is ready for the user's local OTA signing ceremony.
|
||||||
|
|||||||
Generated
+2
-2
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"version": "1.8.19-alpha",
|
"version": "1.8.21-alpha",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"version": "1.8.19-alpha",
|
"version": "1.8.21-alpha",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@scure/bip39": "^2.2.0",
|
"@scure/bip39": "^2.2.0",
|
||||||
"@types/dompurify": "^3.0.5",
|
"@types/dompurify": "^3.0.5",
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "neode-ui",
|
"name": "neode-ui",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "1.8.20-alpha",
|
"version": "1.8.21-alpha",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"start": "./start-dev.sh",
|
"start": "./start-dev.sh",
|
||||||
|
|||||||
@@ -362,6 +362,19 @@ init()
|
|||||||
</button>
|
</button>
|
||||||
</div>
|
</div>
|
||||||
<div class="overflow-y-auto flex-1 min-h-0 space-y-6 pr-1">
|
<div class="overflow-y-auto flex-1 min-h-0 space-y-6 pr-1">
|
||||||
|
<!-- v1.8.21-alpha -->
|
||||||
|
<div>
|
||||||
|
<div class="flex items-center gap-2 mb-3">
|
||||||
|
<span class="text-xs font-mono px-2 py-0.5 rounded bg-orange-500/20 text-orange-300">v1.8.21-alpha</span>
|
||||||
|
<span class="text-xs text-white/40">September 30, 2026</span>
|
||||||
|
</div>
|
||||||
|
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
|
||||||
|
<p>Fixed Bitcoin and other containers being forcibly stopped after ten seconds during managed updates and restarts.</p>
|
||||||
|
<p>Existing installations now receive the same graceful shutdown allowance as new containers, without restarting apps just to apply this setting.</p>
|
||||||
|
<p>Prevented unnecessary Lightning restarts when Bitcoin has stayed running; dependency restarts now require an observed Bitcoin container change.</p>
|
||||||
|
<p>Includes the Cashu payment, optional Bitcoin pruning, Lightning readiness, and explorer improvements from 1.8.20.</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
<!-- v1.8.20-alpha -->
|
<!-- v1.8.20-alpha -->
|
||||||
<div>
|
<div>
|
||||||
<div class="flex items-center gap-2 mb-3">
|
<div class="flex items-center gap-2 mb-3">
|
||||||
|
|||||||
+18
-17
@@ -1,29 +1,30 @@
|
|||||||
{
|
{
|
||||||
"changelog": [
|
"changelog": [
|
||||||
"Fixed the embedded AIUI chat page painting a second background and dark scrim over Archy’s dashboard background.",
|
"Fixed Bitcoin and other containers being forcibly stopped after ten seconds during managed updates and restarts.",
|
||||||
"Embedded AIUI now stays transparent so the dashboard background appears once.",
|
"Existing installations now receive the same graceful shutdown allowance as new containers, without restarting apps just to apply this setting.",
|
||||||
"AIUI background fixes are now included reliably in OTA updates and fresh installations."
|
"Prevented unnecessary Lightning restarts when Bitcoin has stayed running; dependency restarts now require an observed Bitcoin container change.",
|
||||||
|
"Includes the Cashu payment, optional Bitcoin pruning, Lightning readiness, and explorer improvements from 1.8.20."
|
||||||
],
|
],
|
||||||
"components": [
|
"components": [
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.21-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago",
|
||||||
"name": "archipelago",
|
"name": "archipelago",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.21-alpha",
|
||||||
"sha256": "bb500d02567ad16179179d43138cc6fdafee680835262026eeaa7d1bc8cdd307",
|
"sha256": "ff602e85f340aff7e43d9d94f7f84f11f713735c964c0d8ba150e23b065c30eb",
|
||||||
"size_bytes": 64495784
|
"size_bytes": 64748176
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.21-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago-frontend-1.8.19-alpha.tar.gz",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago-frontend-1.8.21-alpha.tar.gz",
|
||||||
"name": "archipelago-frontend-1.8.19-alpha.tar.gz",
|
"name": "archipelago-frontend-1.8.21-alpha.tar.gz",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.21-alpha",
|
||||||
"sha256": "fbbaa237e2ea4e9e576dda9b15fdcf3c59c40bc55bfee4ebbea303b0172fc49b",
|
"sha256": "6c0842ec83a440269a353808a4cf154174f5232c9989b4a5448bc6486e1d0620",
|
||||||
"size_bytes": 97142031
|
"size_bytes": 97152546
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"release_date": "2026-09-28",
|
"release_date": "2026-09-30",
|
||||||
"signature": "4da9bf766d94c2de6641619a36663106791c7a1d342b729c666662cdde1feabdf11c51994c1cbbe2a0e2b270c316d77763435e976ce22730855b3822bc9d390a",
|
"signature": "2ba21dde08284a13f511f11f0b925f09a56c1b36e40424558601b9ab6beea17edfa316e0baa51474bf084fd4da25429ec35a77d9a831554b309845c8226d4f0d",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"version": "1.8.19-alpha"
|
"version": "1.8.21-alpha"
|
||||||
}
|
}
|
||||||
|
|||||||
+18
-17
@@ -1,29 +1,30 @@
|
|||||||
{
|
{
|
||||||
"changelog": [
|
"changelog": [
|
||||||
"Fixed the embedded AIUI chat page painting a second background and dark scrim over Archy’s dashboard background.",
|
"Fixed Bitcoin and other containers being forcibly stopped after ten seconds during managed updates and restarts.",
|
||||||
"Embedded AIUI now stays transparent so the dashboard background appears once.",
|
"Existing installations now receive the same graceful shutdown allowance as new containers, without restarting apps just to apply this setting.",
|
||||||
"AIUI background fixes are now included reliably in OTA updates and fresh installations."
|
"Prevented unnecessary Lightning restarts when Bitcoin has stayed running; dependency restarts now require an observed Bitcoin container change.",
|
||||||
|
"Includes the Cashu payment, optional Bitcoin pruning, Lightning readiness, and explorer improvements from 1.8.20."
|
||||||
],
|
],
|
||||||
"components": [
|
"components": [
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.21-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago",
|
||||||
"name": "archipelago",
|
"name": "archipelago",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.21-alpha",
|
||||||
"sha256": "bb500d02567ad16179179d43138cc6fdafee680835262026eeaa7d1bc8cdd307",
|
"sha256": "ff602e85f340aff7e43d9d94f7f84f11f713735c964c0d8ba150e23b065c30eb",
|
||||||
"size_bytes": 64495784
|
"size_bytes": 64748176
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"current_version": "1.8.19-alpha",
|
"current_version": "1.8.21-alpha",
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.19-alpha/archipelago-frontend-1.8.19-alpha.tar.gz",
|
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago-frontend-1.8.21-alpha.tar.gz",
|
||||||
"name": "archipelago-frontend-1.8.19-alpha.tar.gz",
|
"name": "archipelago-frontend-1.8.21-alpha.tar.gz",
|
||||||
"new_version": "1.8.19-alpha",
|
"new_version": "1.8.21-alpha",
|
||||||
"sha256": "fbbaa237e2ea4e9e576dda9b15fdcf3c59c40bc55bfee4ebbea303b0172fc49b",
|
"sha256": "6c0842ec83a440269a353808a4cf154174f5232c9989b4a5448bc6486e1d0620",
|
||||||
"size_bytes": 97142031
|
"size_bytes": 97152546
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"release_date": "2026-09-28",
|
"release_date": "2026-09-30",
|
||||||
"signature": "4da9bf766d94c2de6641619a36663106791c7a1d342b729c666662cdde1feabdf11c51994c1cbbe2a0e2b270c316d77763435e976ce22730855b3822bc9d390a",
|
"signature": "2ba21dde08284a13f511f11f0b925f09a56c1b36e40424558601b9ab6beea17edfa316e0baa51474bf084fd4da25429ec35a77d9a831554b309845c8226d4f0d",
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
||||||
"version": "1.8.19-alpha"
|
"version": "1.8.21-alpha"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,34 +0,0 @@
|
|||||||
{
|
|
||||||
"changelog": [
|
|
||||||
"Fixed Cashu file payments rejected despite a shared mint, and preserved the payment amount when mint fees reduce change.",
|
|
||||||
"Payment failures now report whether a refund actually succeeded; missing files and unsupported payment methods are rejected before charging.",
|
|
||||||
"Improved saving paid files into Files and reopening purchases without paying again.",
|
|
||||||
"Bitcoin Core and Knots installation offers optional pruning on larger disks, using the same settings as automatic pruning.",
|
|
||||||
"Fixed false missing-port checks that unnecessarily restarted Bitcoin and LND; recovery now respects managed shutdown timeouts.",
|
|
||||||
"LND explains when it is waiting for Bitcoin installation, startup, or sync, without treating normal synchronization as a restart-worthy failure.",
|
|
||||||
"Bitcoin startup messages explain block-index loading without exposing raw RPC errors, and Lightning keeps known balances clearly marked during outages.",
|
|
||||||
"Changed the public transaction-explorer default to mempool.space while preserving local explorers and custom choices."
|
|
||||||
],
|
|
||||||
"components": [
|
|
||||||
{
|
|
||||||
"current_version": "1.8.20-alpha",
|
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.20-alpha/archipelago",
|
|
||||||
"name": "archipelago",
|
|
||||||
"new_version": "1.8.20-alpha",
|
|
||||||
"sha256": "16a173129672cbb40c250446ec52ba4a9bd1974cbb3a4988f90c6f3187b7a1f7",
|
|
||||||
"size_bytes": 64716656
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"current_version": "1.8.20-alpha",
|
|
||||||
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.20-alpha/archipelago-frontend-1.8.20-alpha.tar.gz",
|
|
||||||
"name": "archipelago-frontend-1.8.20-alpha.tar.gz",
|
|
||||||
"new_version": "1.8.20-alpha",
|
|
||||||
"sha256": "658b78fce0dfa20a627c987dd153b24cbac15adbde905cc6518744c637e12802",
|
|
||||||
"size_bytes": 97152297
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"release_date": "2026-09-29",
|
|
||||||
"signature": "326cab454902abcb4f8037751af67aaae2860ecf00300177ec377a1f223a6a85b6e92d49297e7bc29a73220d501e6f4c83ee23477e2b688e33e19d093c6d210b",
|
|
||||||
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
|
|
||||||
"version": "1.8.20-alpha"
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user