From c2eade6db582966fa7fc3dd037f952baf3ae1cb5 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Fri, 4 Sep 2026 14:33:33 +0200 Subject: fix(packaging): actually ship the TMDB token, on Linux and Windows default.env was empty in every build, for three independent reasons: 1. build-node.sh read QE/node.env, which does not exist. Even pointed at the real file it would have failed: its `grep MESHBAY_TMDB_DEFAULT_TOKEN=` cannot match QE/tmdb.txt, which is a free-form note, not KEY=VALUE. 2. Nothing consumed default.env. packaging/README.md and build-node.sh both claimed `meshbay-node init` copies it to /node.env; grep found the name in exactly two places, the README and the script that writes it. No code implemented the copy, and `EnvironmentFile=-` hid the absence. 3. build-win.ps1 had no env handling at all, so Windows was empty for a different reason than Linux. Now: the build extracts the v4 read token -- tmdb.py sends `Authorization: Bearer`, so it is the JWT, not the 32-char v3 key beside it in the same file -- matching KEY=VALUE first and then by shape, from MESHBAY_TMDB_TOKEN, MESHBAY_TMDB_TOKEN_FILE, QE/node.env, QE/tmdb.txt. It writes default.env 0600 and *fails the build* if no token resolves; MESHBAY_ALLOW_NO_TMDB=1 opts out. An empty default.env is invisible until a user opens Videos and finds no metadata, which is how this shipped empty on two platforms at once. platform.py gains packaged_default_env()/install_node_env()/load_node_env(). init copies the packaged file once, never overwriting an existing node.env, and the daemon loads node.env itself at startup: systemd does this on Linux via EnvironmentFile, but Windows autostart is a Startup-folder .vbs with no equivalent. Already-set variables always win. Also fixes an UnboundLocalError in main(): `config_dir` was assigned at the top of the init branch, which made it function-local for all of main(), while the reset branch calls `config_dir()` as the imported function. init returns before that line, so `meshbay-node reset` could only ever raise. The local is now cfg_dir. Verified end to end on Linux: token baked (239 chars), init writes /node.env 0600 with it. The PowerShell half is written but unrun -- no pwsh on this machine. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DtfG7z6wHWj8RKHCvxQtY1 --- packages/meshbay-node/src/meshbay_node/daemon.py | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) (limited to 'packages/meshbay-node/src/meshbay_node/daemon.py') diff --git a/packages/meshbay-node/src/meshbay_node/daemon.py b/packages/meshbay-node/src/meshbay_node/daemon.py index b5a249d..37a2472 100644 --- a/packages/meshbay-node/src/meshbay_node/daemon.py +++ b/packages/meshbay-node/src/meshbay_node/daemon.py @@ -1634,9 +1634,15 @@ def _systemctl_user(verb: str, unit: str, *, not_running_hint: str, def main() -> None: import argparse - from meshbay_node.platform import configure_event_loop, force_utf8_stdio + from meshbay_node.platform import (configure_event_loop, force_utf8_stdio, + load_node_env) force_utf8_stdio() configure_event_loop() + # Before anything reads the environment. On Linux systemd has usually loaded + # the same file already via EnvironmentFile=; this is what makes a Windows + # run (Startup-folder .vbs, no systemd) and a bare `meshbay-node` behave the + # same. Already-set variables are left alone, so it cannot undo either. + load_node_env(config_dir()) parser = argparse.ArgumentParser(description="MeshBay Node daemon") parser.add_argument("command", nargs="?", @@ -1698,8 +1704,13 @@ def main() -> None: if args.command == "init": cfg_path = args.config or DEFAULT_CONFIG_PATH - config_dir = cfg_path.parent - config_dir.mkdir(parents=True, exist_ok=True) + cfg_dir = cfg_path.parent + cfg_dir.mkdir(parents=True, exist_ok=True) + + from meshbay_node.platform import install_node_env + env_written = install_node_env(cfg_dir) + if env_written: + print(f"Wrote {env_written} (packaged defaults).") hub_url = args.hub_url username = args.username @@ -1731,7 +1742,7 @@ def main() -> None: else: print(f"Config already exists: {cfg_path}") else: - unlock_file = config_dir / "unlock.key" + unlock_file = cfg_dir / "unlock.key" toml_lines = [ "[hub]", f'url = "{hub_url}"', @@ -1752,7 +1763,7 @@ def main() -> None: chmod_private(cfg_path) print(f"Config written to {cfg_path}") - unlock_file = config_dir / "unlock.key" + unlock_file = cfg_dir / "unlock.key" if not unlock_file.exists(): import secrets key = secrets.token_urlsafe(32) -- cgit v1.2.3