| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
`build-client.sh` runs `npm ci`, which deletes node_modules wholesale, then
re-extracts Electron's dist. A chrome-sandbox that had been made root-owned
4755 for local development comes back 755 and owned by whoever ran the build.
Running the app straight from node_modules then aborts outright:
FATAL: The SUID sandbox helper binary was found, but is not configured
correctly. Rather than run without sandboxing I'm aborting now.
Chromium refusing to start beats it quietly dropping the sandbox, and that
refusal is baffling if the crash is not connected to a package build run
minutes earlier — the two look unrelated, and the file's own mtime is 1980
either way, so nothing on it points at what happened.
The build now says so, with the command to put it back. Said and not done: a
build script has no business setting a setuid bit behind someone's back, and
this one uses no sudo. The packaged app was never affected —
packaging/deb/meshbay-client/DEBIAN/postinst does the chown+chmod at install
time, which is where it belongs.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014UtzVrzM7e2tG9fSpkR9ML
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Three defects, found while answering whether installing the .deb would land
where the production server was just moved to by hand.
- **The example config was never packaged.** `build-hub.sh` copied
`packaging/conf/hub.toml.example` under `if [ -f ]`, and that path does not
exist in this repo — so every package ever built shipped no example at all
and said nothing about it. The postinst places no config either, on purpose
(a shipped hub.toml is overwritten on upgrade; a shipped secret gets run in
production), which left an installed hub with nothing to copy from. The file
now exists, documents every key `config.py` reads including the captcha
`allowed_hosts` the desktop client needs, and the copy is a hard failure
rather than a silent skip.
- **`/etc/meshbay` was created 0755.** It holds the hub's Ed25519 private key
and its database password. The file modes protect the contents, but a
world-listable config directory tells anyone with a shell what a hub keeps
and where. Now 0750 root:meshbay, in both the deb postinst and the rpm
scriptlet; the service reads it by group.
- **The rpm would have failed to build on the new file.** `%files` claimed
nothing under /etc, and rpmbuild refuses an installed file no line claims.
It now declares the directory and the example, with explicit `%attr` and
`%config` so an operator's edits become .rpmsave rather than vanishing.
Package modes no longer follow the builder's umask either — the same source
tree produced 775/664 on a machine with umask 002 and 755/644 with 022.
`install -m` sets them.
Verified by building: the deb now carries ./etc/meshbay/ at drwxr-x--- with
hub.toml.example at 0644, and the embedded postinst tightens the directory as
belt and braces rather than as the only thing making it right. The rpm path is
unverified — no rpmbuild on this machine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014UtzVrzM7e2tG9fSpkR9ML
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Remove the node daemon's server-rendered admin UI (GET / and /audit, the
_render_* helpers and inline templates) and the `meshbay-node ui` CLI verb.
The loopback control API stays; it is now JSON only, ruff-clean, and 453
lines (was 1074). Also drop three never-wired endpoints (/api/config,
/api/chat/history, /ws/chat, plus broadcast_chat) and the pointless
18000/tcp firewall profiles.
The desktop client's Node page (static/node-page.js) takes over what the
dashboard showed, reorganised into six tabs (Overview, Groups, Roster,
Peers, Audit, Settings):
- Overview: version, node id, QUIC port, hub, index-cache maintenance
- Roster: node-wide view with unpin
- Peers and Audit: auto-load on open, no Load button
- Audit: real usernames and group names (resolved from the roster and
node.toml), Previous/Next pagination newest-first, Export CSV of every
matching row
- Settings: node settings, STUN, ICE, denylist, then Unlink from hub
Backend: audit.get_entries gains `offset`; /api/audit and /api/peers
resolve ids to names via a new _display_names helper; CSP tightened to
default-src 'none' now that no HTML is served. draft-v6 sections 2.11 and
2.12 corrected -- the Node page uses the loopback API, not MNP.
One capability is intentionally dropped: browser-based admin on a headless
server. The CLI covers every operation there.
See docs/refactor-node-ui.md.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MQCaZnde4Bjjdu84dhSuF5
|
|
|
Shared venv architecture: meshbay-common owns the Python venv with all
pip deps pre-installed; hub and node add only their code into it.
Client is a standalone Electron app. No pip runs at install time.
- Add build scripts (packaging/build/) for common, hub, node, client
- Add orchestrator build-packages.sh with deb/rpm auto-detection
- Add .deb control/postinst for all 4 packages
- Add .rpm specs for all 4 packages (replaces python3-meshbay-common)
- Add Gnome .desktop launcher and icon resizing
- Add firewalld services (meshbay-cast, meshbay-node) and UFW profiles
- Update systemd units to use /opt/meshbay-common/venv/bin/ paths
- TMDB token baked into node package at build time via QE/node.env
- Fix package-lock.json sync for protobufjs override
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|